Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 1126–1200

1401 questions total · 19pages · All types, answers revealed

Page 15

Page 16 of 19

Page 17
1126
MCQhard

Router R10 is configured with SNMP and EEM. An EEM applet is configured to send an SNMP trap when a specific syslog message is generated. The applet uses the 'action snmp-trap' command. However, the NMS receives no trap. The syslog message is generated and logged. The router's show snmp statistics shows TrapsSent: 0. What is the root cause?

A.The EEM applet is configured to send a trap, but the 'snmp-server host' command is missing, so the router has no destination for the trap.
B.The syslog message is not matching the EEM trigger pattern correctly.
C.The EEM applet is not registered due to a syntax error.
D.The SNMP community string is not configured with RW privileges.
AnswerA

Without 'snmp-server host', the router does not know where to send the trap. The EEM action will fail silently.

Why this answer

The EEM applet uses the 'action snmp-trap' command to generate a trap, but without the 'snmp-server host' command, the router has no configured destination to send the trap to. The 'show snmp statistics' output showing TrapsSent: 0 confirms that the trap was generated internally but never transmitted, which is the classic symptom of a missing trap destination. The syslog message being logged and the applet triggering correctly rules out pattern-matching or registration issues.

Exam trap

Cisco often tests the misconception that 'action snmp-trap' alone is sufficient to send a trap, when in fact the 'snmp-server host' command is mandatory to define the trap receiver.

How to eliminate wrong answers

Option B is wrong because the syslog message is generated and logged, indicating the EEM trigger pattern matched correctly; if it didn't match, the applet would not execute at all. Option C is wrong because if the applet had a syntax error, it would not register, and the syslog message would not trigger any action; the fact that the syslog is logged and the applet is expected to run shows registration succeeded. Option D is wrong because SNMP traps are sent using the community string configured under 'snmp-server host', which requires read-only (RO) or read-write (RW) privileges only for SNMP writes to the router, not for trap generation; traps are sent with the community string specified in the 'snmp-server host' command, and RW is irrelevant here.

1127
MCQeasy

What is the default administrative distance for OSPF routes on a Cisco IOS-XE router?

A.90
B.100
C.110
D.120
AnswerC

OSPF's default administrative distance on Cisco IOS-XE is 110, satisfying the stem's request for the default value. Administrative distance ranks route sources by trustworthiness; OSPF's 110 sits above EIGRP's 90 and below RIP's 120, so IOS-XE prefers OSPF over RIP but defers to EIGRP when both advertise the same prefix.

Why this answer

The default administrative distance for OSPF is 110.

1128
MCQmedium

A network engineer is configuring DHCPv6 on a Cisco IOS-XE router. The router must provide IPv6 addresses and other configuration parameters to clients on the LAN. The engineer wants the router to assign addresses using stateless address autoconfiguration (SLAAC) but also provide DNS server information via DHCPv6. Which command set correctly configures the router's LAN interface to achieve this?

A.ipv6 address 2001:DB8:1::1/64 ipv6 nd other-config-flag ipv6 dhcp server POOL
B.ipv6 address 2001:DB8:1::1/64 ipv6 dhcp server POOL ipv6 nd ra-interval 30
C.ipv6 address 2001:DB8:1::1/64 ipv6 nd prefix 2001:DB8:1::/64 ipv6 dhcp server POOL
D.ipv6 address 2001:DB8:1::1/64 ipv6 nd managed-config-flag ipv6 dhcp server POOL
AnswerA

The other-config-flag instructs hosts to use DHCPv6 to obtain other configuration parameters such as DNS, while addresses are still formed via SLAAC. The ipv6 dhcp server command binds the DHCPv6 pool to the interface. This combination meets the requirement of SLAAC for addresses and DHCPv6 for DNS.

Why this answer

The other-config-flag in router advertisements signals hosts to use DHCPv6 for additional configuration parameters, while addresses are still autoconfigured via SLAAC. The ipv6 dhcp server command attaches the DHCPv6 pool to the interface. The managed-config-flag would force hosts to use DHCPv6 for addresses as well, which is not desired.

Other commands like ra-interval or prefix do not control the DHCPv6 usage flags.

Exam trap

The trap here is confusing the managed-config-flag with the other-config-flag; the former forces DHCPv6 for addresses, while the latter only requests other parameters.

1129
MCQmedium

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast summary BGP router identifier 192.168.0.1, local AS number 65001 BGP table version is 10, main routing table version 10 Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 192.168.1.2 4 65002 1002 1000 10 0 0 00:15:30 5 192.168.2.2 4 65003 1005 1003 10 0 0 00:14:20 3 10.10.10.2 4 65004 0 0 0 0 0 00:00:05 Idle Based on this output, what is the problem with neighbor 10.10.10.2?

A.The neighbor is administratively shut down.
B.The BGP session is not established; possible misconfiguration or reachability issue.
C.The neighbor is in the process of establishing the session.
D.The neighbor has sent all its prefixes and is waiting for updates.
AnswerB

The neighbour 10.10.10.2 shows State/PfxRcd as Idle with zero messages received and sent, meaning no BGP session was established. This points to misconfiguration or a reachability problem rather than an established peer, satisfying the stem's diagnostic constraint.

Why this answer

The output shows that neighbor 10.10.10.2 is in the Idle state with zero messages sent or received, indicating the BGP session has never been established. This typically results from a misconfiguration (e.g., wrong neighbor IP, incorrect AS number, missing update-source) or a Layer 3 reachability issue preventing the TCP connection on port 179.

Exam trap

Cisco often tests the distinction between Idle (no session attempt) and Active (session attempt in progress), tricking candidates into thinking Idle means 'waiting' rather than 'not started'.

How to eliminate wrong answers

Option A is wrong because an administratively shut down BGP neighbor would show the state as 'Idle (admin)' or similar, not just 'Idle'. Option C is wrong because a session in the process of establishing would show a state like 'Active' or 'Connect', not 'Idle'. Option D is wrong because the neighbor has sent zero prefixes (PfxRcd is blank) and is in Idle, meaning no prefixes have been exchanged; waiting for updates would occur in the Established state.

1130
MCQhard

An engineer configures iBGP between two routers in the same AS. The BGP table shows the prefix, but it is not installed in the routing table. The IGP does not carry the prefix. Which is the most likely explanation?

A.The BGP synchronization rule is enabled, and the prefix is not in the IGP, so BGP does not install the route.
B.The next-hop is unreachable because of a missing static route.
C.The BGP route is filtered by an inbound route-map.
D.The maximum-paths limit is exceeded.
AnswerA

With BGP synchronization enabled, a route learned via iBGP is not installed in the routing table unless the same prefix exists in the IGP. Since the IGP does not carry it, the route stays in the BGP table only, matching the stem exactly.

Why this answer

When BGP synchronization is enabled (default in older IOS versions), BGP will not install a route learned via iBGP into the routing table unless the same prefix is also present in the IGP. Since the IGP does not carry the prefix, BGP considers the route unsynchronized and does not install it, even though it appears in the BGP table.

Exam trap

Cisco often tests the BGP synchronization rule as a legacy behavior that candidates overlook, assuming that a prefix in the BGP table always implies installation in the routing table, but synchronization can block installation even when the next-hop is reachable.

How to eliminate wrong answers

Option B is wrong because an unreachable next-hop due to a missing static route would cause the BGP route to be marked as invalid or not installed, but the question states the BGP table shows the prefix, implying the next-hop is reachable via the IGP or a connected route. Option C is wrong because an inbound route-map filtering the route would prevent the prefix from appearing in the BGP table entirely, not just from being installed in the routing table. Option D is wrong because exceeding the maximum-paths limit affects load balancing among multiple equal-cost paths, not the installation of a single prefix; a single route would still be installed.

1131
MCQmedium

Which statement correctly describes the default behavior of Dead Peer Detection (DPD) in Cisco IOS for IPsec site-to-site VPN?

A.DPD is enabled by default with a 10-second interval
B.DPD is enabled by default with a 30-second interval
C.DPD is disabled by default
D.DPD is enabled only for IKEv2 by default
AnswerC

Cisco IOS leaves DPD inactive unless configured, so it is disabled by default on IPsec site-to-site peers. This satisfies the stem's constraint that the statement correctly describe default DPD behaviour, not its configured or enabled state.

Why this answer

Dead Peer Detection (DPD) is disabled by default in Cisco IOS for IPsec site-to-site VPNs. This means that without explicit configuration using the 'crypto isakmp keepalive' command, the router will not send DPD messages to verify the liveness of the remote peer. DPD must be manually enabled to detect peer failures and trigger failover or tunnel teardown.

Exam trap

Cisco often tests the misconception that DPD is enabled by default or that it has a fixed interval, when in fact it must be manually configured and the default state is disabled.

How to eliminate wrong answers

Option A is wrong because DPD is not enabled by default with a 10-second interval; DPD is disabled by default, and if enabled, the interval is configurable but not a fixed 10 seconds. Option B is wrong because DPD is not enabled by default with a 30-second interval; again, DPD is disabled by default, and the interval is not preset to 30 seconds. Option D is wrong because DPD is not enabled only for IKEv2 by default; DPD is disabled by default for both IKEv1 and IKEv2, and it must be explicitly configured for either version.

1132
MCQhard

A network engineer is troubleshooting a router that is not executing an EEM applet that is supposed to run when a specific interface goes down. The applet is configured with event syslog pattern 'LINK-3-UPDOWN' and matches the interface with a regex. The engineer checks the syslog and sees the message 'LINK-3-UPDOWN: GigabitEthernet0/1, changed state to down' but the applet does not run. What is the most likely cause?

A.The EEM applet is disabled.
B.The syslog message is not being sent to the EEM server due to logging level restrictions.
C.The regex pattern in the applet does not match the syslog message.
D.The interface is not being monitored because it is a subinterface.
AnswerC

EEM matches the syslog pattern against the raw message text, so the regex must accommodate the actual interface string. If it expects a different format than 'GigabitEthernet0/1', the applet never triggers despite the LINK-3-UPDOWN event firing.

Why this answer

The EEM applet uses a regex pattern to match the syslog message, and if the pattern does not exactly match the interface name or the message format, the applet will not trigger. The syslog message shows 'GigabitEthernet0/1', but the regex might be expecting a different format (e.g., 'Gi0/1' or missing the full name), causing a mismatch. Therefore, the most likely cause is that the regex pattern does not match the syslog message.

Exam trap

The trap is assuming that EEM relies on external syslog servers or logging levels; candidates may overlook that EEM uses internal syslog and that regex must match exactly, including interface naming.

How to eliminate wrong answers

Option A is wrong because if the applet were disabled, it would not run at all, but the question implies it is configured and expected to run; there is no indication it is disabled. Option B is wrong because EEM receives syslog messages internally regardless of logging level restrictions; logging level affects what is sent to syslog servers, not EEM. Option D is wrong because subinterfaces can be monitored by EEM; the issue is not the interface type but the pattern matching.

1133
Drag & Dropmedium

Drag and drop the steps to apply and verify an extended IPv4 ACL on a router interface into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order is: first, create the ACL with permit/deny statements; second, verify the ACL syntax with show access-list; third, apply it inbound on the interface; fourth, verify the interface configuration with show ip interface; fifth, test connectivity with ping or traceroute.

1134
MCQhard

A network engineer is troubleshooting a Cisco IOS XE router that is configured for IPv6 First Hop Security on a user VLAN. Hosts report intermittent connectivity, and the engineer suspects that IPv6 Router Advertisement (RA) messages from an unauthorized device are being accepted. Which feature should be enabled to ensure that only RAs from the legitimate router are processed by hosts?

A.IPv6 Source Guard
B.IPv6 Destination Guard
C.IPv6 RA Guard
D.IPv6 DHCPv6 Guard
AnswerC

RA Guard examines incoming Router Advertisement and Redirect messages on a port and can block or allow them based on a policy. By configuring RA Guard on host-facing ports to block RAs, only the legitimate router's RAs are accepted, preventing rogue RA attacks and restoring stable connectivity.

Why this answer

RA Guard is the IPv6 First Hop Security feature that filters Router Advertisement and Redirect messages on a per-port basis. When configured to block RAs on host-facing ports, it ensures hosts only accept RAs from the authorized router, mitigating rogue RA attacks. The other features address different threats such as rogue DHCPv6 servers or spoofed source addresses.

Exam trap

The trap here is confusing RA Guard with DHCPv6 Guard or Source Guard, but only RA Guard specifically inspects and filters Router Advertisement messages to prevent rogue default router advertisements.

1135
Drag & Dropmedium

Drag and drop the steps to verify and validate the operational state of an IPv6 tunneling technique into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Validation follows a systematic approach: start with checking the tunnel interface status and counters, then verify IPv6 connectivity across the tunnel using ping, examine routing protocol adjacency over the tunnel, validate end-to-end IPv6 reachability to remote networks, and finally confirm traffic flow with traceroute or debug commands.

1136
MCQhard

What is the default value of the 'reachable time' in IPv6 Neighbor Discovery (ND) on Cisco IOS-XE?

A.0 milliseconds (unspecified)
B.30,000 milliseconds
C.60,000 milliseconds
D.10,000 milliseconds
AnswerA

Cisco IOS-XE leaves the reachable time unspecified by default, advertising zero milliseconds in Router Advertisements. Hosts then rely on their own random reachable-time calculation rather than a value dictated by the router, which is the documented default behaviour.

Why this answer

In IPv6 Neighbor Discovery (ND) on Cisco IOS-XE, the default value for the 'reachable time' is 0 milliseconds (unspecified). This means the router does not advertise a specific reachable time in its Router Advertisements (RAs), leaving the receiving hosts to use their own default value (typically 30,000 milliseconds as per RFC 4861). The 'reachable time' is the duration a node considers a neighbor reachable after confirming reachability via Neighbor Solicitation (NS) or Neighbor Advertisement (NA) messages.

Exam trap

Cisco often tests the distinction between the default value advertised by the router (0, meaning unspecified) and the default value used by hosts (30,000 ms), causing candidates to mistakenly select the host default as the router's advertised value.

How to eliminate wrong answers

Option B is wrong because 30,000 milliseconds is the default reachable time used by hosts (RFC 4861) when the router advertises an unspecified value, not the default value advertised by Cisco IOS-XE routers. Option C is wrong because 60,000 milliseconds is not a standard default for reachable time; it might be confused with the default 'retrans timer' (which is 0 unspecified, but hosts use 1000 ms). Option D is wrong because 10,000 milliseconds is a common user-configured value but is not the default; Cisco IOS-XE defaults to 0 (unspecified) to allow host-side defaults.

1137
Drag & Dropmedium

Drag and drop the steps to configure Flexible NetFlow with a custom flow record into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order follows Cisco IOS-XE configuration logic: first define the flow record with match fields, then define the flow exporter with destination and source, then define the flow monitor binding record and exporter, then apply the monitor to an interface in the ingress direction, and finally verify with 'show flow monitor'.

1138
MCQhard

A network administrator is configuring OSPF on a Cisco router. The router is connected to two different OSPF areas: Area 0 and Area 1. The administrator wants to summarize routes from Area 1 into Area 0. Which command should be used on the Area Border Router (ABR) to accomplish this?

A.summary-address 10.1.0.0 255.255.0.0
B.ip summary-address ospf 1 10.1.0.0 255.255.0.0
C.area 1 range 10.1.0.0 255.255.0.0
D.area 0 range 10.1.0.0 255.255.0.0
AnswerC

The 'area 1 range' command is used on an ABR to summarize inter-area routes from the specified area into other areas. It must be configured on the ABR, and the area specified is the source area (Area 1). This command aggregates routes from Area 1 into a single summary LSA that is advertised into Area 0. It is the correct method for inter-area route summarization in OSPF, reducing the size of the link-state database and routing tables in the backbone.

Why this answer

Inter-area route summarization in OSPF is performed on ABRs using the 'area range' command. The area specified is the source area from which routes are summarized. In this case, routes from Area 1 are summarized before being advertised into Area 0.

This reduces the number of LSAs and routing entries, improving scalability. The other commands either summarize external routes or apply to the wrong area, and thus do not meet the requirement.

Exam trap

The trap here is confusing inter-area summarization with external summarization, leading to the use of 'summary-address' instead of 'area range'.

1139
MCQmedium

An engineer is troubleshooting a router that is not sending syslog messages to the syslog server at 192.168.1.10. The configuration includes 'logging host 192.168.1.10' and 'logging trap informational'. The engineer can ping the syslog server from the router. 'show logging' shows that the logging buffer is filling with messages. What is the most likely cause?

A.The syslog server is not listening on UDP port 514.
B.The 'logging source-interface' command is missing, causing syslog messages to use an incorrect source IP.
C.The 'logging on' command is not configured.
D.The syslog server's IP address is incorrect in the configuration.
AnswerB

Without the 'logging source-interface' command, syslog messages are sourced from the IP address of the interface used to route the packet to the syslog server. If that interface's address is not statically permitted on the server's logging access-list, or if the address is a private or non-routable IP from an unexpected segment, the server will drop the packets even though the configuration contains the correct server IP. Configuring a loopback or management interface as the source for logging ensures a consistent, expected source IP and is the standard fix for this symptom.

Why this answer

The router can ping the syslog server and the logging buffer is filling, which confirms network reachability and that the router is generating syslog messages. However, without the 'logging source-interface' command, syslog packets use the IP address of the egress interface, which may not be reachable from the server (e.g., due to ACLs or routing asymmetry). This causes the server to drop the packets, even though the router can reach the server.

The 'logging host' and 'logging trap informational' commands are correctly configured, so the issue lies in the source IP selection.

Exam trap

Cisco often tests the misconception that a successful ping implies full bidirectional communication, but syslog uses UDP and the server may drop packets if the source IP is unexpected or not reachable in the return path.

How to eliminate wrong answers

Option A is wrong because the syslog server not listening on UDP port 514 would cause a different symptom: the router would still send messages, but the server would not receive them; however, the router can ping the server, and the buffer fills, indicating the server is reachable and the router is generating logs. Option C is wrong because 'logging on' is enabled by default; if it were disabled, the logging buffer would not fill with messages. Option D is wrong because the IP address is correct (the router can ping 192.168.1.10), and the configuration explicitly includes 'logging host 192.168.1.10'.

1140
MCQhard

An engineer configures SPAN on a Cisco switch to monitor traffic from a VLAN, but the VLAN includes a voice VLAN. The mirrored traffic shows only data traffic, not voice. What is the most likely explanation?

A.The SPAN source is configured for the data VLAN only, not the voice VLAN.
B.Voice traffic uses a different CoS value, which SPAN ignores.
C.The voice VLAN is configured as a native VLAN, which SPAN does not capture.
D.The switch has a security ACL that blocks voice traffic from being mirrored.
AnswerA

SPAN mirrors only the interfaces or VLANs named as sources. A voice VLAN is a separate VLAN, so its traffic is never copied unless explicitly added as an additional source. The data VLAN alone therefore explains the missing voice packets.

Why this answer

Voice VLANs are often configured as separate VLANs (e.g., VLAN 100 for voice, VLAN 10 for data). If the SPAN source is a single VLAN, it only captures traffic on that VLAN. To capture both, the SPAN session must include both VLANs or use a port-based source that includes both.

1141
MCQhard

A network administrator is deploying IPv6 First Hop Security (FHS) on a Cisco Catalyst switch to mitigate rogue Router Advertisement (RA) attacks. The switch is running Cisco IOS Software and is configured with the command ipv6 nd raguard policy POLICY1. Which additional step is required to activate RA guard on an interface?

A.Configure the interface as trusted using ipv6 nd raguard trust.
B.Apply the policy to the interface using ipv6 nd raguard attach-policy POLICY1.
C.Enable IPv6 unicast routing globally with ipv6 unicast-routing.
D.Enable DHCPv6 snooping globally with ipv6 dhcp snooping.
AnswerB

After creating an RA guard policy, you must attach it to the desired interface with the ipv6 nd raguard attach-policy command. This activates the policy on that interface, allowing it to filter rogue RAs. Without attaching the policy, the configuration exists but is not enforced on any port, leaving the network vulnerable.

Why this answer

RA guard requires two steps: creating a policy that defines the filtering rules, and attaching that policy to an interface. The attach-policy command activates the policy on the specified interface. Other options are either unrelated features or modify trust settings, but they do not activate the policy on an interface.

Exam trap

The trap here is assuming that creating the policy is sufficient, or confusing the trust command with the attach-policy command.

1142
MCQmedium

A network engineer runs the following command to troubleshoot BFD with OSPF: R1# show ip ospf interface gigabitethernet 0/0 GigabitEthernet0/0 is up, line protocol is up Internet Address 10.1.1.1/24, Area 0 Process ID 1, Router ID 1.1.1.1, Network Type BROADCAST, Cost: 1 Transmit Delay is 1 sec, State DR, Priority 1 Designated Router (ID) 1.1.1.1, Interface address 10.1.1.1 Backup Designated router (ID) 2.2.2.2, Interface address 10.1.1.2 Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5 oob-resync timeout 40 Hello due in 00:00:03 Supports Link-local Signaling (LLS) Cisco NSF helper support enabled IETF NSF helper support enabled Index 1/1/1, flood queue length 0 Next 0x0(0)/0x0(0)/0x0(0) Last flood scan length is 1, maximum is 25 Last flood scan time is 0 msec, maximum is 0 msec Neighbor Count is 1, Adjacent neighbor count is 1 Adjacent with neighbor 2.2.2.2 (Backup Designated Router) Suppress hello for 0 neighbor(s) BFD enabled, BFD interval 100 msec, BFD multiplier 3 What does this output indicate?

A.OSPF is using BFD with a 100 ms interval and multiplier 3, enabling sub-second failure detection.
B.BFD is disabled on this OSPF interface.
C.BFD interval is set to 10 seconds, matching OSPF hello.
D.BFD session is down, causing OSPF to use dead timer.
AnswerA

The interface output explicitly reports BFD enabled with a 100 msec interval and multiplier 3, so detection occurs in roughly 300 ms — well below one second. This satisfies the sub-second failure detection requirement by tightening OSPF's adjacency teardown beyond default hello/dead timers.

Why this answer

The output shows that BFD is enabled on the OSPF interface with an interval of 100 ms and multiplier of 3. This provides fast failure detection for OSPF adjacency.

1143
MCQeasy

A network technician is configuring SSH access on a Cisco IOS router. The technician wants to ensure that only SSH version 2 is allowed and that the RSA key pair is generated with a modulus of 2048 bits. Which commands are required?

A.crypto key generate rsa general-keys modulus 2048 ip ssh version 1
B.ip ssh version 2 crypto key generate rsa modulus 4096
C.crypto key generate rsa modulus 1024 ip ssh version 2
D.crypto key generate rsa modulus 2048 ip ssh version 2
AnswerD

The 'crypto key generate rsa modulus 2048' command generates an RSA key pair with a 2048-bit modulus, which is required for SSH. The 'ip ssh version 2' command restricts SSH to version 2 only, enhancing security. Together, these commands meet the requirements. The key generation must be done before SSH can operate, and version 2 is preferred over version 1 due to vulnerabilities.

Why this answer

The correct answer generates a 2048-bit RSA key and sets SSH to version 2. This satisfies both the key size and protocol version requirements. The other options either use the wrong key size or configure SSH version 1, which is insecure.

It is important to generate the key before enabling SSH, and version 2 should be enforced for security.

Exam trap

The trap here is selecting a larger key size or forgetting to enforce SSH version 2; the requirement specifies exactly 2048 bits and version 2 only.

1144
MCQmedium

A network engineer is troubleshooting a PBR (Policy-Based Routing) issue on router R5. The engineer configured a route-map to set the next-hop for traffic from a specific source subnet. The route-map is applied to the incoming interface, but traffic from the source subnet is still being forwarded using the regular routing table. The engineer verifies that the ACL matches the traffic correctly. What is the most likely cause?

A.The route-map is missing a 'set ip next-hop' command, or the next-hop is not reachable.
B.The route-map is applied outbound instead of inbound on the interface.
C.The ACL is using a standard ACL, which cannot match source subnet correctly.
D.The route-map has a 'set default interface' command that overrides the next-hop.
AnswerA

Policy-based routing only diverts traffic when the route-map both matches via the ACL and executes a set clause. Without a reachable 'set ip next-hop', the route-map permits the packet and normal destination-based forwarding via the routing table continues, exactly as observed.

Why this answer

For PBR to actually change forwarding, the route-map must contain a 'set' clause (such as 'set ip next-hop' or 'set interface') that matches the ACL; if the set clause is missing or the specified next-hop is unreachable, the route-map matches but does nothing, and traffic falls back to the normal routing table. The scenario states the ACL matches correctly, so the failure is in the action, not the match.

Exam trap

The trap is that candidates focus on the ACL match (which the question says is fine) and overlook that a route-map without a valid 'set' action silently does nothing — the exam expects you to know that matching alone does not change forwarding behavior.

How to eliminate wrong answers

Option B is wrong because the question explicitly states the route-map is applied to the incoming interface, and PBR is correctly applied inbound on the interface where traffic enters — applying it outbound would be a different (and less common) design, but it is not the stated condition. Option C is wrong because standard ACLs can match source subnet fine (they match source only, which is exactly what the scenario needs); extended ACLs are only required when matching destination or ports. Option D is wrong because 'set default interface' is only used when there is no explicit next-hop match and does not override an existing 'set ip next-hop' — and the scenario does not indicate such a command is present.

1145
MCQhard

A network administrator is configuring DMVPN Phase 3 with a hub-and-spoke topology. The administrator wants to enable spoke-to-spoke communication directly without traversing the hub. Which command must be configured on the hub router to allow spoke-to-spoke tunnels?

A.ip nhrp network-id 1
B.ip nhrp redirect
C.ip nhrp shortcut
D.ip nhrp map multicast dynamic
AnswerB

The 'ip nhrp redirect' command on the hub enables DMVPN Phase 3 functionality. When a spoke sends traffic to another spoke via the hub, the hub sends an NHRP redirect message to the originating spoke, informing it of a better path directly to the destination spoke. This allows the originating spoke to initiate a direct tunnel to the destination spoke, bypassing the hub for subsequent packets. This is a key component of DMVPN Phase 3.

Why this answer

The correct answer is 'ip nhrp redirect' on the hub. In DMVPN Phase 3, the hub uses NHRP redirect messages to inform spokes about a better direct path to other spokes. When a spoke receives a redirect, it can establish a direct tunnel to the destination spoke, reducing latency and hub load.

This command is essential on the hub to enable this behavior. The spoke routers must also have 'ip nhrp shortcut' configured to act on the redirects.

Exam trap

The trap here is confusing the roles of 'ip nhrp redirect' and 'ip nhrp shortcut', and misplacing them on the wrong routers (hub vs. spoke).

1146
MCQeasy

A network engineer runs the following command to verify DHCPv4 server conflict detection on router R1: R1# show ip dhcp conflict Output: IP address Detection method Detection time VRF 192.168.1.50 Ping Mar 01 2025 10:00 AM default 192.168.1.75 Gratuitous ARP Mar 01 2025 11:00 AM default What does this output indicate?

A.The DHCP server has detected two IP address conflicts on the network.
B.The DHCP server has successfully assigned IP addresses 192.168.1.50 and 192.168.1.75.
C.The DHCP server uses only ping to detect conflicts.
D.The DHCP server has cleared all conflicts from the database.
AnswerA

Each entry in the conflict table represents an address the server detected as already in use, via Ping or Gratuitous ARP probes, and has quarantined from allocation. Two entries therefore indicate two detected conflicts, satisfying the stem's question about the output's meaning.

Why this answer

The 'show ip dhcp conflict' command displays IP addresses that the DHCP server has detected as conflicting with another device on the network. The output shows two entries, each with a detection method (Ping or Gratuitous ARP), indicating that the DHCP server identified conflicts for 192.168.1.50 and 192.168.1.75. This confirms that two IP address conflicts have been detected and logged in the DHCP conflict database.

Exam trap

Cisco often tests the distinction between 'show ip dhcp conflict' (which logs detected conflicts) and 'show ip dhcp binding' (which shows successfully leased addresses), leading candidates to mistakenly think conflict output indicates successful assignments.

How to eliminate wrong answers

Option B is wrong because the output shows conflicts, not successful assignments; successful assignments are tracked via 'show ip dhcp binding', not 'show ip dhcp conflict'. Option C is wrong because the output explicitly shows two detection methods: Ping and Gratuitous ARP, proving the server uses both, not only ping. Option D is wrong because the output lists two unresolved conflicts, indicating the database has not been cleared; a cleared database would show no entries.

1147
MCQhard

An engineer configures mutual redistribution between OSPF and EIGRP. After a few minutes, the network becomes unstable with routing loops. The engineer checks the routing tables and notices that the same prefix is being learned from both protocols with different administrative distances. Which is the most likely explanation?

A.Routes are redistributed back and forth between OSPF and EIGRP without any filtering or tagging
B.The seed metric for OSPF redistribution into EIGRP is not configured
C.The administrative distance of OSPF is lower than EIGRP, causing OSPF routes to be preferred
D.The redistribute command is missing the subnets keyword under OSPF
AnswerA

Mutual redistribution without route tagging or filtering lets each protocol re-advertise prefixes learned from the other, so OSPF and EIGRP keep feeding routes back and forth. Administrative distance only breaks ties between protocols; it cannot stop the feedback loop, which is why the network destabilises and loops.

Why this answer

Mutual redistribution without route filtering or tagging causes routes to be fed from OSPF into EIGRP and then back from EIGRP into OSPF (and vice versa), creating a feedback loop. This results in inconsistent routing information, flapping, and potential loops. The fix is to use route maps with tags or distribute-lists to prevent re-advertisement of routes learned from the other protocol.

Exam trap

The trap is blaming administrative distance or missing metrics; the exam expects you to recognize that mutual redistribution without loop prevention (tags/filters) is the root cause of instability.

How to eliminate wrong answers

Option B is wrong because a missing seed metric would prevent redistribution entirely (routes wouldn't be injected), not cause loops — the symptom would be missing routes, not instability. Option C is wrong because administrative distance differences are normal and expected; AD is used for route selection, not a cause of redistribution loops. Option D is wrong because the 'subnets' keyword affects whether subnetted routes are redistributed into OSPF, but its absence would cause missing routes, not loops.

1148
MCQmedium

In MPLS, what is the default behavior of a Cisco IOS-XE router regarding the 'auto-summary' command for BGP routes?

A.Auto-summary is disabled by default for BGP.
B.Auto-summary is enabled by default for BGP.
C.Auto-summary is enabled by default only for directly connected routes.
D.Auto-summary is disabled by default for BGP but enabled for OSPF.
AnswerA

Cisco IOS-XE disables BGP auto-summary by default, so no configuration is needed to advertise subnet routes rather than classful summaries. This default satisfies the stem's requirement to identify out-of-the-box behaviour, unlike RIP or EIGRP, where auto-summary is enabled by default.

Why this answer

In Cisco IOS and IOS-XE, BGP auto-summary is disabled by default. Unlike older Interior Gateway Protocols such as RIP or EIGRP (where auto-summary was historically enabled by default), BGP does not automatically summarize routes to their classful network boundaries unless explicitly configured with the 'auto-summary' command under the BGP router configuration. This default behavior ensures that BGP advertises the exact prefixes it learns, which is essential for precise routing in modern classless networks.

Exam trap

300-410 often tests the contrast between classful protocol defaults (RIP/EIGRP auto-summary on) and BGP's classless default (auto-summary off), catching candidates who assume all routing protocols behave the same way.

How to eliminate wrong answers

Option B is wrong because BGP auto-summary is not enabled by default; it must be manually configured. Option C is wrong because auto-summary is not a feature that applies only to directly connected routes; it is a BGP router-level command that affects redistribution and network statements. Option D is wrong because while OSPF does not use auto-summary in the same way (OSPF summarizes only at ABRs/ASBRs with the 'area range' or 'summary-address' commands), the statement incorrectly claims BGP auto-summary is disabled but OSPF auto-summary is enabled by default, which is not accurate.

1149
MCQmedium

A network engineer runs the following command to troubleshoot a VRF-Lite issue: R1# show ip route vrf CUSTOMER_A summary Output: IP routing table name: CUSTOMER_A (0x00000001) IP routing table maximum-paths: 32 Route Source Networks Subnets Replicates Overhead Memory (bytes) connected 2 0 0 0 576 static 1 0 0 0 288 eigrp 100 3 0 0 0 864 Internal 3 0 0 0 864 External 0 0 0 0 0 ospf 200 0 0 0 0 0 Intra-area 0 0 0 0 0 Inter-area 0 0 0 0 0 External-1 0 0 0 0 0 External-2 0 0 0 0 0 NSSA-1 0 0 0 0 0 NSSA-2 0 0 0 0 0 bgp 65000 0 0 0 0 0 Internal 0 0 0 0 0 External 0 0 0 0 0 Total 6 0 0 0 1728 What does this output indicate?

A.The VRF CUSTOMER_A has 6 routes, with EIGRP 100 providing 3 internal routes.
B.The VRF CUSTOMER_A has 6 routes, all redistributed from BGP 65000.
C.The VRF CUSTOMER_A has 6 routes, with OSPF 200 providing 3 external routes.
D.The VRF CUSTOMER_A has 6 routes, all from connected and static only.
AnswerA

The summary confirms VRF CUSTOMER_A holds six routes in total, sourced from connected (2), static (1) and EIGRP 100 (3). The EIGRP entries are all internal, with zero external, while OSPF 200 and BGP 65000 contribute nothing — indicating those protocols are configured but not yet exchanging routes within this VRF.

Why this answer

The summary shows 6 total routes in VRF CUSTOMER_A: 2 connected, 1 static, and 3 internal EIGRP 100 routes. OSPF 200 and BGP 65000 contribute zero routes. This matches option A exactly, confirming EIGRP is the only dynamic protocol populating the VRF.

Exam trap

The trap is skimming the summary and assuming all listed protocols contribute routes — candidates must read the Networks column carefully, since protocols with 0 entries are listed but contribute nothing.

How to eliminate wrong answers

Option B is wrong because BGP 65000 shows 0 networks in the output — no routes are redistributed from BGP. Option C is wrong because OSPF 200 shows 0 intra-area, 0 inter-area, and 0 external routes; it contributes nothing to the table. Option D is wrong because the table includes 3 EIGRP routes in addition to connected and static, so it's not 'only' connected and static.

1150
Multi-Selectmedium

Which TWO statements about the 'match ip address' command within a route-map are true? (Choose TWO.)

Select 2 answers
A.It can reference a standard access-list, extended access-list, or prefix-list.
B.It matches the source IP address of the route.
C.It can only be used in a route-map sequence with a 'permit' clause.
D.If multiple access-lists are listed in the same match command, they are evaluated with a logical OR.
E.The command 'match ip address prefix-list' is not valid.
AnswersA, D

The command accepts access-list numbers/names and prefix-list names.

Why this answer

The 'match ip address' command can reference either a standard or extended access-list, or a prefix-list. It matches the destination network of the route. It cannot match source address (that would be 'match ip next-hop' or 'match ip route-source').

The command can be used in both permit and deny sequences. A single route-map sequence can have multiple match commands, but they are logically ANDed only if under the same match statement type.

1151
MCQhard

A network engineer is configuring a Cisco IOS XE router to act as a DHCP relay agent. The router receives DHCP discover messages on interface GigabitEthernet0/1 and must forward them to a DHCP server at 10.1.1.100. The engineer configures the command 'ip helper-address 10.1.1.100' on GigabitEthernet0/1. However, the DHCP server is not receiving the requests. Which additional configuration is required to ensure that DHCP relay works correctly?

A.Configure 'ip forward-protocol udp 67' globally.
B.Configure 'ip dhcp relay information option' globally.
C.Enable 'service dhcp' globally on the router.
D.Ensure that the interface facing the DHCP server has an IP address and that routing is configured to reach 10.1.1.100.
AnswerD

This is correct. For the DHCP relay agent to forward requests to the server, the router must have a route to the DHCP server's IP address. The helper address itself only specifies the destination; the router must be able to reach that destination via its routing table. If the interface facing the server is down or lacks an IP address, or if there is no route to 10.1.1.100, the relayed packets will be dropped. This is a common oversight when configuring DHCP relay.

Why this answer

The DHCP relay agent uses the 'ip helper-address' command to forward broadcast DHCP requests to a unicast address. However, the router must have a valid route to that unicast address. If the interface toward the DHCP server is not configured with an IP address or is down, or if there is no route to the server, the relayed packets cannot be sent.

Therefore, ensuring IP connectivity to the DHCP server is essential. The other options are either default behaviors or optional features not required for basic relay operation.

Exam trap

The trap here is focusing on DHCP-specific commands like 'service dhcp' or relay information options, while overlooking the fundamental requirement of IP reachability to the DHCP server.

1152
MCQmedium

A network engineer is deploying a GET VPN solution across an MPLS VPN WAN. The group members must encrypt traffic between any pair of sites without establishing point-to-point tunnels, and the key server must distribute a common encryption policy to all members. The engineer has configured the key server with a rekey policy but group members are not receiving rekeys. Which action must be taken on the key server to enable successful rekey transmission?

A.Change the key server to use a different group identity (GDOI group ID) that matches the members.
B.Configure the group members with the rekey retransmit timer set to a lower value.
C.Configure the key server to use IKEv2 for rekey authentication instead of IKEv1.
D.Enable unicast rekey on the key server so that rekeys are sent directly to each group member.
AnswerD

By default, GET VPN key servers send rekeys via multicast to the group address. If the underlay network does not support multicast or the group members are not receiving multicast rekeys, enabling unicast rekey ensures each member receives the rekey directly. This is a common requirement in MPLS VPN or non-multicast-capable transport networks.

Why this answer

GET VPN key servers typically send rekeys using multicast to the group address. In networks that do not support multicast or where multicast is not enabled on the transport, group members will not receive rekeys. Enabling unicast rekey on the key server forces rekeys to be sent directly to each registered group member's unicast address, ensuring they receive the updated policy.

This is a standard configuration adjustment for non-multicast underlays.

Exam trap

The trap here is assuming that rekey delivery is always multicast and that multicast is available on all transport networks, when in fact unicast rekey may be required for non-multicast-capable underlays.

1153
MCQmedium

A network engineer runs the following command to troubleshoot a Route Redistribution issue: R1# show ip ospf database external And sees the following output: OSPF Router with ID (1.1.1.1) (Process ID 1) Type-5 AS External Link States LS age: 360 Options: (No TOS-capability, DC) LS Type: AS External Link Link State ID: 192.168.10.0 (External Network Number ) Advertising Router: 2.2.2.2 LS Seq Number: 80000001 Checksum: 0x1234 Length: 36 Network Mask: /24 Metric Type: 2 (Larger than any link state path) TOS: 0 Metric: 20 Forward Address: 0.0.0.0 External Route Tag: 100 What does this output indicate?

A.The route 192.168.10.0/24 is an OSPF internal route.
B.The route is redistributed into OSPF with a metric of 20 and a route tag of 100.
C.The forward address is 0.0.0.0, meaning the route is not reachable.
D.The route is a default route redistributed into OSPF.
AnswerB

The route is redistributed but it is a default route, not a specific network route. The metric and tag are correct, but the route type is default.

Why this answer

The output shows a Type-5 AS External LSA for 192.168.10.0/24, which means the route was redistributed into OSPF. The LSA has Metric: 20 and External Route Tag: 100, so the route is redistributed into OSPF with a metric of 20 and a route tag of 100. The forward address 0.0.0.0 indicates that the advertising ASBR is the next hop, not that the route is unreachable, and the Link State ID and network mask identify a specific /24 route, not the default route.

1154
MCQmedium

A network engineer is troubleshooting a VRF-Lite configuration where a router is using RIP as the routing protocol in VRF_BLUE. The engineer notices that RIP routes are not being learned from a neighbor router. The 'show ip rip database vrf VRF_BLUE' shows no entries. The 'show ip vrf interfaces VRF_BLUE' shows the correct interface. What is the most likely cause?

A.The 'network' command is configured under the global RIP process, not under the VRF address-family.
B.The 'version 2' command is missing under the VRF address-family.
C.The 'no auto-summary' command is missing.
D.The 'timers basic' command is set to a very low value.
AnswerA

For RIP to operate in a VRF, the network command must be under the VRF address-family.

Why this answer

RIP in VRF-Lite requires that the RIP process be associated with the VRF and that the network command is issued under the VRF context. Missing the 'address-family ipv4 vrf VRF_BLUE' configuration is a common oversight.

1155
MCQhard

An engineer configures Control Plane Policing (CoPP) on a router. After applying the policy, OSPF neighbors go down. The engineer checks the policy and sees that OSPF packets are not explicitly matched. Which is the most likely explanation?

A.The class-default is set to 'drop', and OSPF packets fall into class-default because they are not matched by any other class.
B.The CoPP policy uses 'police' in bps, but OSPF packets are small and exceed the rate limit.
C.The CoPP policy is applied to the input direction, but OSPF packets are processed in the output direction.
D.The CoPP policy uses 'police' in pps, but OSPF hello packets are sent every 10 seconds, so they are not rate-limited.
AnswerA

In Cisco CoPP, the control-plane policy processes packets by matching them against the configured classes in order. Since OSPF (IP protocol 89) is not matched by any higher-priority class in this scenario, it is classified into class-default. If class-default is set to 'drop,' all OSPF hello, database descriptor, link-state, and other control packets are silently discarded, preventing the router from maintaining or forming OSPF adjacency. This direct classification into a drop class is the definitive cause of OSPF neighbor loss.

Why this answer

When Control Plane Policing (CoPP) is configured, traffic is classified into classes based on match criteria. If OSPF packets are not explicitly matched by any configured class, they fall into the default class (class-default). If the policy-map sets class-default to 'drop', all unmatched traffic, including OSPF hello packets (which use IP protocol 89), will be dropped.

This causes OSPF neighbors to go down because the router stops receiving or sending OSPF control packets.

Exam trap

Cisco often tests the concept that class-default in CoPP can be set to 'drop', and candidates may overlook that OSPF or other routing protocols are not explicitly matched, leading to neighbor loss.

How to eliminate wrong answers

Option B is wrong because CoPP policies use 'police' in bps or pps, but the issue here is not rate-limiting; it is that OSPF packets are not matched and are dropped by class-default. Option C is wrong because CoPP is applied to the control plane, which processes both inbound and outbound control traffic; OSPF packets are sent and received via the control plane, and the input direction is the correct direction for incoming OSPF packets. Option D is wrong because even if OSPF hello packets are sent every 10 seconds, they would still be subject to rate-limiting if matched; the problem is that they are not matched at all and fall into class-default.

1156
MCQmedium

Examine this configuration: interface GigabitEthernet0/4 ipv6 address 2001:db8:2::1/64 ipv6 verify unicast source reachable-via any What is the effect of the 'ipv6 verify unicast source reachable-via any' command?

A.The router performs strict uRPF: the source address must be reachable via the same interface the packet arrived on.
B.The router performs loose uRPF: the source address must be reachable via any route in the FIB.
C.The router drops all packets with source addresses not in the same subnet as the interface.
D.The command is invalid because 'ipv6 verify unicast' requires a route-map.
AnswerB

The `any` keyword selects loose unicast RPF, so the router checks the FIB for any route back to the source rather than requiring the packet's ingress interface to match the best return path. This satisfies the stem's constraint: source reachability verification without strict path symmetry.

Why this answer

The command 'ipv6 verify unicast source reachable-via any' enables loose unicast Reverse Path Forwarding (uRPF) for IPv6. In loose mode, the router checks that the source address of an incoming packet is reachable via any route in the Forwarding Information Base (FIB), not necessarily through the receiving interface. This is the correct behavior described in option B.

Exam trap

Cisco often tests the distinction between 'any' (loose) and 'rx' (strict) keywords in uRPF configuration, and candidates commonly confuse 'reachable-via any' with strict uRPF or assume it requires a route-map.

How to eliminate wrong answers

Option A is wrong because it describes strict uRPF, which requires the source address to be reachable via the exact interface the packet arrived on, but the command uses 'any' (loose mode), not 'rx' (strict mode). Option C is wrong because uRPF does not drop packets based on subnet matching; it checks reachability in the FIB, and loose mode allows any valid route regardless of subnet. Option D is wrong because the command is valid without a route-map; the 'ipv6 verify unicast' command can use 'reachable-via any' or 'reachable-via rx' directly, and a route-map is optional for advanced filtering.

1157
MCQmedium

Given this partial configuration on router R6: router bgp 65000 neighbor 192.168.1.1 remote-as 65001 address-family ipv4 network 172.16.0.0 mask 255.255.0.0 aggregate-address 172.16.0.0 255.255.0.0 What is missing if the administrator wants to ensure that only the aggregate route is advertised to neighbor 192.168.1.1?

A.The 'summary-only' keyword is missing from the aggregate-address command.
B.The 'network' command should be removed.
C.The 'synchronization' command must be enabled.
D.The 'neighbor 192.168.1.1 route-map' command is needed.
AnswerA

Without the summary-only keyword, the aggregate-address command advertises both the aggregate 172.16.0.0/16 and its more-specific component routes. Adding summary-only suppresses those specifics, leaving only the aggregate sent to neighbour 192.168.1.1, satisfying the requirement that solely the aggregate be advertised.

Why this answer

The 'aggregate-address' command without the 'summary-only' keyword advertises both the aggregate and the more-specific routes. To advertise only the aggregate, the 'summary-only' keyword must be added. The network statement is needed to inject the component route into BGP.

Exam trap

The trap is thinking that removing the network statement or using a route-map is necessary; candidates overlook the built-in 'summary-only' keyword that directly solves the problem.

How to eliminate wrong answers

Option B is wrong because removing the network command would remove the component route from the BGP table, and the aggregate would not be generated (aggregate-address requires at least one more-specific). Option C is wrong because synchronization is an obsolete BGP feature (disabled by default in modern IOS) and does not affect summarization. Option D is wrong because a route-map on the neighbor could filter routes, but it is not the direct or intended method to achieve summary-only behavior; the aggregate-address command has a built-in keyword for this.

1158
MCQhard

OSPF is configured on a multi-access link between R1 and R2. R1 has: interface GigabitEthernet0/0, ip ospf network point-to-point. R2 has default broadcast network type. R1 shows: show ip ospf neighbor includes R2 in FULL state, but R2 shows: show ip ospf neighbor includes R1 in INIT state. What is the root cause?

A.R1's OSPF process ID does not match R2's.
B.The network type mismatch causes R1 to use unicast hellos, while R2 expects multicast.
C.R1 has a higher router ID, preventing adjacency.
D.R2's interface is passive, blocking OSPF hellos.
AnswerB

Point-to-point uses unicast; broadcast uses multicast, leading to one-way communication.

Why this answer

When R1 is configured with 'ip ospf network point-to-point' on a multi-access link, it changes its OSPF behavior to use unicast hellos to the neighbor's IP address instead of the standard multicast address 224.0.0.5. R2, with the default broadcast network type, expects to receive OSPF hellos on the multicast address. Because R1 sends unicast hellos, R2 never receives them, so R2's neighbor state for R1 remains INIT.

R1, however, receives R2's multicast hellos and can form a full adjacency from its perspective, leading to the asymmetric state.

Exam trap

Cisco often tests the asymmetric neighbor state (FULL on one side, INIT on the other) as a signature symptom of OSPF network type mismatch, tempting candidates to blame mismatched process IDs or passive interfaces instead.

How to eliminate wrong answers

Option A is wrong because OSPF process IDs are locally significant and do not need to match between routers for adjacency formation. Option C is wrong because a higher router ID does not prevent adjacency; the router ID is used for DR/BDR election in broadcast networks, but with a point-to-point network type on R1, no DR/BDR election occurs, and a higher router ID would not block adjacency. Option D is wrong because a passive interface would suppress all OSPF hellos, causing both sides to show no neighbor or only INIT state, not the asymmetric FULL/INIT state described.

1159
MCQhard

A network uses route summarization to reduce routing table size. After enabling Flexible NetFlow, some routes that were previously summarized are now being advertised individually. Router R1 has: interface GigabitEthernet0/0 ip summary-address eigrp 100 10.0.0.0 255.0.0.0. The flow monitor is applied to the same interface. show ip route eigrp | include (10.0.0.0/8) shows the summary route, but also shows more specific routes like 10.1.0.0/16. What is the root cause?

A.The flow monitor is configured with a sampler that causes the router to process packets in software, and the software path learns more specific routes from routing updates that are not summarized.
B.The flow monitor is using a flow record that includes the 'ipv4 destination prefix' field, causing the router to install a route for each destination.
C.The summary route is not configured correctly; it should be a range of /8, but the more specific routes are from a different EIGRP process.
D.The flow exporter is sending the more specific routes to the collector, which then redistributes them back.
AnswerA

When a sampler is used, packets are punted to the CPU for sampling, and the CPU may process routing updates that contain more specific routes, which are then installed in the routing table, bypassing the summary.

Why this answer

Flexible NetFlow can cause the router to process packets differently, but it should not affect route summarization. However, if the flow monitor is configured with a flow record that includes the 'ipv4 source prefix' or 'ipv4 destination prefix' fields, it might cause the router to install more specific routes in the routing table due to the way the router handles flow cache entries. The correct answer is that the flow monitor is using a flow record that includes the 'ipv4 destination prefix' field, and the router is using that to create a route cache that overrides the summary route.

But this is not standard behavior. The more likely root cause is that the summary route is configured on the interface, but the flow monitor is applied in the input direction, and the router's CEF (Cisco Express Forwarding) is affected by the flow monitor, causing it to punt packets to the CPU, which then learns more specific routes via the routing protocol. Actually, the correct answer is that the flow monitor is configured with a sampler that causes the router to process packets in software, and the software path learns more specific routes from the routing updates that are not summarized.

1160
MCQmedium

Examine the following partial configuration on router R1: flow record RECORD-1 match ipv4 source address match ipv4 destination address match ipv4 protocol collect counter bytes collect counter packets ! flow monitor MONITOR-1 record RECORD-1 cache timeout active 60 ! interface GigabitEthernet0/1 ip flow monitor MONITOR-1 input ! Which statement about this configuration is true?

A.The flow monitor will export flow records every 60 seconds regardless of whether the flow is still active.
B.The flow monitor will only export flows that have been idle for 60 seconds.
C.The flow record is missing the 'collect transport tcp-flags' command to be valid.
D.The flow monitor will not export any data because no exporter has been configured.
AnswerD

Flexible NetFlow requires a flow exporter referenced by the flow monitor to transmit records to a collector. This configuration defines a record and monitor but no exporter, so cached flows age out and are discarded locally, producing no exported data.

Why this answer

The configuration defines a flow record, a flow monitor referencing that record, and applies the monitor to an interface, but it never defines a flow exporter or references one under the flow monitor with the 'exporter' command. Without an exporter, the flow monitor has no destination to send the collected flow data to, so no records will be exported off the device. The 'cache timeout active 60' only controls how long an active flow stays in the cache before being flushed to the exporter — it does not create an export path by itself.

Exam trap

300-410 often tests whether candidates conflate the flow monitor's cache timers with the export mechanism, causing them to pick an answer about 60-second exports instead of recognizing the missing flow exporter.

How to eliminate wrong answers

Option A is wrong because 'cache timeout active 60' controls the active flow cache aging timer, not a periodic export interval — it flushes long-lived flows to the exporter, it does not export every 60 seconds regardless of flow state. Option B is wrong because idle timeout is controlled by 'cache timeout inactive' (default 15 seconds), and no such command is present here; 'active 60' refers to active flows, not idle ones. Option C is wrong because 'collect transport tcp-flags' is optional — a flow record is valid with just match/collect statements for IPv4 addresses, protocol, bytes, and packets; it is not a required field.

1161
MCQmedium

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# debug ip packet 100 detail IP packet debugging is on for access list 100 *Mar 1 00:12:34.567: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto UDP, flags 0x0, sport 12345, dport 80, access list 100: matched line 10 permit udp host 10.1.1.1 host 10.2.2.2 eq 80 *Mar 1 00:12:35.123: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto TCP, flags 0x2, sport 12346, dport 443, access list 100: matched line 20 deny tcp host 10.1.1.1 host 10.2.2.2 eq 443 *Mar 1 00:12:35.124: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto TCP, flags 0x10, sport 12346, dport 443, access list 100: matched line 20 deny tcp host 10.1.1.1 host 10.2.2.2 eq 443 What does this output indicate?

A.The ACL is applied inbound on GigabitEthernet0/0 and is permitting UDP traffic to port 80 while denying TCP traffic to port 443.
B.The ACL is applied outbound on GigabitEthernet0/0 and is permitting all traffic.
C.The ACL is misconfigured because TCP traffic to port 443 should be permitted.
D.The ACL is not applied to any interface because debug ip packet shows only the ACL number.
AnswerA

The debug output shows that UDP traffic to port 80 matches line 10 (permit) and TCP traffic to port 443 matches line 20 (deny).

Why this answer

The debug output shows packets entering GigabitEthernet0/0 (source interface) and matching ACL 100. The first packet (UDP to port 80) matches line 10 (permit), while subsequent TCP packets to port 443 match line 20 (deny). Since the source interface is the inbound interface, the ACL is applied inbound.

This confirms Option A: the ACL permits UDP to port 80 and denies TCP to port 443.

Exam trap

Cisco often tests the ability to distinguish inbound vs. outbound ACL application by interpreting the source and destination IP addresses in debug output, where the trap is that candidates mistakenly assume the ACL is outbound because the destination IP is different, ignoring that the source interface reveals the direction.

How to eliminate wrong answers

Option B is wrong because the debug output explicitly shows packets being denied (matched line 20 deny), not permitted, and the source interface indicates inbound, not outbound, application. Option C is wrong because the ACL is not misconfigured; it is functioning as designed by denying TCP to port 443, and there is no requirement that TCP to port 443 must be permitted. Option D is wrong because the debug output includes the interface (GigabitEthernet0/0) in the source field, confirming the ACL is applied to that interface; the 'debug ip packet' command with an ACL number only filters packets matching that ACL, but the interface is still shown in the debug message.

1162
MCQmedium

A network engineer configures BGP on router R4: router bgp 65004 bgp router-id 4.4.4.4 neighbor 10.4.4.3 remote-as 65003 neighbor 10.4.4.3 password BGPsecret ! What is the effect of the password command?

A.It encrypts the BGP updates using the password as a key.
B.It enables MD5 authentication for the TCP session; the neighbor must also have the same password.
C.It sets a simple password that is sent in clear text with each BGP update.
D.It has no effect unless the neighbor is configured with the same password.
AnswerB

The password command enables TCP MD5 signature authentication for the BGP session, protecting against spoofed TCP segments. Both peers must configure the identical password, otherwise the MD5 digest mismatches and the session fails to establish.

Why this answer

The 'neighbor ... password' command in Cisco IOS BGP enables MD5 authentication for the TCP session between BGP peers. The password is used to generate an MD5 hash that is included in TCP segments, and both neighbors must be configured with the same password for the session to establish. This prevents unauthorized BGP peering and protects against TCP reset attacks.

Exam trap

300-410 often tests the misconception that the BGP password encrypts routing updates, so candidates must remember it only provides MD5 TCP session authentication, not payload encryption.

How to eliminate wrong answers

Option A is wrong because the password does not encrypt BGP update contents; it only authenticates the TCP session via MD5. Option C is wrong because the password is not sent in clear text with each update — it is used to compute an MD5 digest, and the password itself is never transmitted. Option D is wrong because the command does have an effect even if the neighbor is not configured with the same password — in that case, the BGP session will fail to establish due to authentication mismatch, which is a definite effect.

1163
MCQeasy

Which protocol should be used to dynamically distribute encryption keys for a GET VPN deployment?

A.GDOI
B.IKEv2
C.ISAKMP
D.IPsec
AnswerA

GDOI (Group Domain of Interpretation) is the protocol used in GET VPN to distribute group keys and policies from the key server to group members. It enables the key server to push encryption keys, rekey messages, and ACL policies to all group members, facilitating secure any-to-any communication without point-to-point tunnels.

Why this answer

GET VPN uses the Group Domain of Interpretation (GDOI) protocol for group key management. The key server uses GDOI to distribute encryption keys, rekey messages, and security policies to all group members. This allows members to encrypt traffic to each other without establishing point-to-point tunnels, preserving the any-to-any nature of the underlying network.

Exam trap

The trap here is confusing GDOI with IKE; while IKE is used for point-to-point VPNs, GDOI is specifically designed for group key distribution in GET VPN.

1164
Drag & Drophard

Drag and drop the steps to troubleshoot IPv6 over IPv4 tunnel adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The troubleshooting process follows a logical progression: first verify the tunnel interface is up/up, then check the IPv6 routing table for the destination prefix, inspect the tunnel source and destination IPs for correctness, verify IPv4 reachability to the tunnel destination, and finally examine ACLs or firewall rules that might block GRE protocol 47 traffic.

1165
MCQmedium

Router R1 has the following configuration: ``` interface GigabitEthernet0/1 ip address 10.1.1.1 255.255.255.0 ip policy route-map PBR-OUT ! route-map PBR-OUT permit 10 match ip address 100 set ip next-hop 192.168.1.1 ! access-list 100 permit ip host 10.1.1.100 any ``` What is the effect of this configuration?

A.Packets received on GigabitEthernet0/1 from source 10.1.1.100 are forwarded to next-hop 192.168.1.1.
B.Packets transmitted out of GigabitEthernet0/1 to destination 10.1.1.100 are forwarded to next-hop 192.168.1.1.
C.All packets from 10.1.1.100 are dropped because the route-map does not have a permit statement.
D.The configuration is invalid because the ACL must match destination, not source.
AnswerA

Policy-based routing matches access-list 100, which permits only source 10.1.1.100, and the route map sets next-hop 192.168.1.1. Traffic arriving on GigabitEthernet0/1 from that host is therefore forwarded to 192.168.1.1 rather than following the routing table.

Why this answer

The route-map PBR-OUT is applied as an inbound policy on interface GigabitEthernet0/1 using the 'ip policy route-map' command. The access-list 100 matches packets with source IP 10.1.1.100, and the route-map sets the next-hop to 192.168.1.1. Therefore, packets received on that interface from that source are policy-routed to the specified next-hop.

Exam trap

300-410 often tests the direction of PBR application (inbound vs. outbound) and the matching criteria (source vs. destination), causing candidates to misapply the policy to outbound traffic or expect destination-based matching.

How to eliminate wrong answers

Option B is wrong because the 'ip policy route-map' command on an interface applies to inbound packets, not outbound; outbound policy routing would use 'ip policy route-map' under global configuration with 'ip local policy' or interface output, but here it's inbound. Option C is wrong because the route-map has a permit statement (permit 10) that matches the ACL, so packets are not dropped; they are forwarded. Option D is wrong because ACLs in route-maps can match source IP addresses; there is no requirement to match destination.

1166
MCQhard

A network administrator configures 'ipv6 dhcp guard' on a switch and sets the policy to 'allow only' for a specific DHCPv6 server. However, clients are still receiving DHCPv6 replies from a rogue server on the same VLAN. The engineer verifies that the rogue server's port is not trusted. What is the most likely reason the rogue server's advertisements are not being blocked?

A.IPv6 snooping is not enabled globally, so DHCPv6 Guard cannot inspect DHCPv6 messages.
B.The rogue server is using a different UDP port for DHCPv6.
C.The 'allow only' policy only works for DHCPv6 requests, not replies.
D.The rogue server is on a trunk port, and DHCPv6 Guard does not apply to trunk ports.
AnswerA

DHCPv6 Guard relies on IPv6 snooping to build the binding table and inspect messages; without it enabled globally, guard policies cannot classify or drop rogue DHCPv6 replies, so the untrusted port's advertisements pass through unchecked.

Why this answer

DHCPv6 Guard relies on IPv6 snooping (also known as DHCPv6 snooping) to inspect DHCPv6 messages and enforce policies. If IPv6 snooping is not enabled globally on the switch, DHCPv6 Guard has no binding database or inspection mechanism to identify and block rogue DHCPv6 replies, even if the policy is configured and the rogue port is untrusted. The 'ipv6 dhcp guard' command alone is insufficient without the underlying snooping framework.

Exam trap

Cisco often tests the prerequisite dependency between IPv6 snooping and DHCPv6 Guard, trapping candidates who assume that configuring the guard policy alone is sufficient to block rogue servers.

How to eliminate wrong answers

Option B is wrong because DHCPv6 uses fixed UDP ports 546 (client) and 547 (server); a rogue server cannot use a different UDP port for standard DHCPv6 communication, and DHCPv6 Guard inspects the standard ports. Option C is wrong because the 'allow only' policy applies to both DHCPv6 requests and replies; it restricts which server can send replies, not just requests. Option D is wrong because DHCPv6 Guard does apply to trunk ports; the feature operates on VLANs and inspects traffic regardless of port mode, so a trunk port is not automatically exempt.

1167
MCQmedium

Which BGP attribute is used as the first tie-breaker when multiple paths are available for the same prefix, assuming default settings?

A.Local preference
B.AS-path length
C.Weight
D.MED (Multi-Exit Discriminator)
AnswerC

Weight is Cisco-proprietary and locally significant, so it is evaluated before all other attributes in the best-path algorithm. With default settings, the path with the highest weight wins, making it the first tie-breaker for the same prefix. Microsoft Entra ID is unrelated here; this concerns Cisco IOS BGP path selection.

Why this answer

C is correct because, under default BGP settings, the Weight attribute is the first tie-breaker when multiple paths exist for the same prefix. Weight is a Cisco-proprietary attribute that is locally significant to the router and is evaluated before any other BGP path selection criteria, including Local Preference and AS-path length.

Exam trap

Cisco often tests the order of BGP path selection attributes, and the trap here is that candidates mistakenly remember Local Preference as the first tie-breaker because it is the first global attribute, but Weight (which is local to the router) actually takes precedence.

How to eliminate wrong answers

Option A is wrong because Local Preference is the second tie-breaker in the BGP best-path selection process, not the first; it is evaluated after Weight. Option B is wrong because AS-path length is the fourth tie-breaker, used only after Weight, Local Preference, and locally originated routes have been compared. Option D is wrong because MED (Multi-Exit Discriminator) is the fifth tie-breaker, considered only after Weight, Local Preference, locally originated routes, and AS-path length have been evaluated.

1168
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip route 10.1.1.0 Routing entry for 10.1.1.0/24 Known via "eigrp 100", distance 170, metric 30720 Redistributing via eigrp 100 Last update from 192.168.1.2 on GigabitEthernet0/0, 00:00:05 ago Routing Descriptor Blocks: * 192.168.1.2, from 192.168.1.2, 00:00:05 ago, via GigabitEthernet0/0 Route metric is 30720, traffic share count is 1 Based on this output, which statement is correct?

A.The route 10.1.1.0/24 is an EIGRP internal route.
B.The route 10.1.1.0/24 is an EIGRP external route, likely redistributed.
C.The route 10.1.1.0/24 is learned via OSPF and redistributed into EIGRP.
D.The administrative distance of 170 is non-default and must have been manually configured.
AnswerB

The administrative distance of 170 is the default for EIGRP external routes, confirming redistribution.

Why this answer

The output shows an EIGRP route with an administrative distance of 170, which is the default distance for EIGRP external routes. This indicates the route was redistributed into EIGRP from another protocol or process. The metric of 30720 is the default for a redistributed connected route.

1169
Multi-Selectmedium

Which TWO statements about RSPAN are true? (Choose TWO.)

Select 2 answers
A.RSPAN uses a dedicated VLAN to carry monitored traffic between switches.
B.The RSPAN VLAN must be allowed on all trunk links between the source and destination switches.
C.RSPAN encapsulates traffic in GRE headers for transport across Layer 3 networks.
D.RSPAN requires a dedicated monitoring server at the source switch.
E.RSPAN can only be configured on a single switch.
AnswersA, B

RSPAN carries mirrored frames across switches inside a dedicated VLAN, which transports the traffic over trunk links between source and destination switches. This VLAN isolates monitored traffic from normal user data, satisfying the requirement for inter-switch monitoring.

Why this answer

Option A is correct because RSPAN (Remote Switched Port Analyzer) works by defining a special RSPAN VLAN that carries the mirrored traffic across the network from the source switch to the destination switch, unlike local SPAN which stays within one device. Option B is correct because that RSPAN VLAN must be permitted on every trunk link along the path between the source and destination switches, otherwise the monitored frames cannot traverse the interswitch links and reach the destination port. Option C is incorrect because RSPAN does not use GRE encapsulation; GRE-based mirroring is associated with ERSPAN, which transports mirrored traffic over Layer 3 networks.

Option D is incorrect because RSPAN does not require a dedicated monitoring server at the source switch; the source switch simply copies traffic into the RSPAN VLAN, and analysis is typically done at the destination switch. Option E is incorrect because RSPAN is specifically designed to extend SPAN across multiple switches, not to be limited to a single switch.

1170
MCQmedium

A network engineer is configuring a site-to-site DMVPN Phase 3 hub-and-spoke topology. The hub router is configured with tunnel mode gre multipoint. Spokes are unable to dynamically form tunnels with each other when the hub is reachable. Which additional configuration on the hub enables spoke-to-spoke direct tunnels in Phase 3?

A.Enable NHRP shortcut on the hub tunnel interface.
B.Set the tunnel interface to multipoint GRE on all spokes.
C.Enable NHRP redirect on the hub tunnel interface.
D.Configure a unique NHRP network ID on each spoke.
AnswerC

NHRP redirect is a Phase 3 feature that allows the hub to inform spokes of a better path to another spoke. When the hub receives a packet from one spoke destined to another, it sends an NHRP redirect message to the originating spoke, which then resolves the destination NBMA address and builds a direct tunnel. Without NHRP redirect, spokes continue to route through the hub, defeating the purpose of Phase 3.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to notify a spoke that a more optimal path exists to another spoke. The spoke then uses NHRP shortcut to resolve the destination and establish a direct tunnel. Configuring NHRP redirect on the hub is essential to enable spoke-to-spoke communication without traversing the hub for every packet.

Exam trap

The trap here is confusing where NHRP redirect and NHRP shortcut are configured: redirect goes on the hub, shortcut on the spokes.

1171
MCQmedium

A network engineer is troubleshooting a router that is not responding to SNMP polls from the NMS at 10.1.1.100. The SNMP configuration includes 'snmp-server community public RO' and 'snmp-server community private RW'. The engineer can ping the router from the NMS. 'show snmp' shows SNMP is enabled. What is the most likely cause?

A.The NMS is using the wrong SNMP version.
B.An ACL is applied to the SNMP community that denies the NMS IP.
C.The router's SNMP agent is disabled due to high CPU.
D.The NMS is using the wrong community string.
AnswerB

An ACL bound to the community string filters incoming SNMP requests by source address, so a deny entry for 10.1.1.100 silently drops polls despite ICMP succeeding and SNMP being enabled. This satisfies the stem's constraint that reachability is proven yet polling fails, isolating the fault to community-level access control rather than transport or service state.

Why this answer

The NMS can ping the router, confirming IP reachability, and 'show snmp' confirms SNMP is enabled. The most likely cause is an ACL applied to the SNMP community that denies the NMS IP address (10.1.1.100). Cisco IOS allows an access-list to be attached to an SNMP community string using the 'snmp-server community <string> [RO|RW] <acl-number>' command, which filters SNMP requests based on source IP.

Since the NMS can ping but not poll, the ACL is blocking SNMP traffic while permitting ICMP.

Exam trap

Cisco often tests the distinction between reachability (ping working) and SNMP-specific filtering (ACL on community), leading candidates to incorrectly blame community string mismatch or SNMP version when the real issue is an access-list silently dropping SNMP packets.

How to eliminate wrong answers

Option A is wrong because the SNMP version is not specified in the configuration; the 'snmp-server community' command defaults to SNMPv1/v2c, and if the NMS were using a different version (e.g., SNMPv3), the router would still respond to SNMPv1/v2c polls unless explicitly disabled, and the question does not indicate version mismatch. Option C is wrong because 'show snmp' shows SNMP is enabled; high CPU might cause delayed responses but does not disable the SNMP agent entirely, and the router still responds to pings, indicating it is not overwhelmed. Option D is wrong because the configuration includes both 'public' (RO) and 'private' (RW) community strings; if the NMS were using the wrong string, it would receive an authentication failure (noSuchName) error, but the question states the router is 'not responding' at all, which points to an ACL block rather than a community mismatch.

1172
Multi-Selecthard

Which TWO statements about SNMPv3 configuration on Cisco IOS XE are true? (Choose TWO.)

Select 2 answers
A.The 'snmp-server group' command creates a group and assigns a username to it.
B.The 'snmp-server user' command can specify an authentication and privacy password for a user.
C.The engine ID is automatically generated and cannot be manually configured.
D.The 'snmp-server host' command for SNMPv3 requires a username to be specified when sending traps or informs.
E.SNMPv3 supports only the authPriv security level.
AnswersB, D

The snmp-server user command accepts authentication and privacy keywords, allowing separate auth and priv passwords to be set for a user, which supports SNMPv3 authPriv security level. This is valid syntax on Cisco IOS XE.

Why this answer

Option B is correct because the 'snmp-server user' command on Cisco IOS XE allows you to configure a user with authentication (auth) and privacy (priv) passwords, e.g., 'snmp-server user user1 group1 v3 auth sha authpass priv aes 128 privpass', which sets both the authentication and encryption credentials. Option D is correct because when configuring SNMPv3 traps or informs with 'snmp-server host', you must specify the username (and optionally the security level) so the device knows which SNMPv3 user credentials to use when sending notifications, e.g., 'snmp-server host 192.0.2.1 traps version 3 priv user1'. Option A is incorrect because 'snmp-server group' creates an SNMPv3 group and associates it with a security model and access level, but it does not assign a username; users are assigned to groups via the 'snmp-server user' command.

Option C is incorrect because the SNMP engine ID is automatically generated by default, but it can be manually configured using the 'snmp-server engineID local' command. Option E is incorrect because SNMPv3 supports three security levels: noAuthNoPriv, authNoPriv, and authPriv, not only authPriv.

Exam trap

Cisco often tests the misconception that the engine ID is immutable and cannot be manually configured, leading candidates to incorrectly select option C as true.

1173
MCQhard

A network administrator is troubleshooting an OSPFv3 network. Router R1 is configured with the following: ipv6 unicast-routing interface GigabitEthernet0/0 ipv6 address 2001:DB8:1::1/64 ipv6 ospf 1 area 0 ipv6 ospf network point-to-point ! router ospf 1 router-id 1.1.1.1 ! R1 is not forming an adjacency with R2, which is configured with: interface GigabitEthernet0/0 ipv6 address 2001:DB8:1::2/64 ipv6 ospf 1 area 0 ipv6 ospf network broadcast ! router ospf 1 router-id 2.2.2.2 What is the most likely reason for the adjacency failure?

A.The router-id must be the same on both routers for an adjacency to form.
B.OSPFv3 requires the use of link-local addresses for adjacency formation, and they are not configured.
C.OSPFv3 requires the router-id to be configured under the interface, not under the router ospf process.
D.The network type mismatch (point-to-point vs. broadcast) prevents the routers from forming an adjacency.
AnswerD

OSPF network types must match on both sides of a link for an adjacency to form. R1 is configured as point-to-point, while R2 is broadcast. This mismatch causes hello packets to be interpreted differently, and the adjacency will not form. Both routers must use the same network type, either point-to-point or broadcast.

Why this answer

OSPF network types must be consistent on both ends of a link for an adjacency to form. R1 is configured with ipv6 ospf network point-to-point, while R2 uses broadcast. This mismatch leads to differing hello packet handling and prevents the adjacency.

To resolve, configure both interfaces with the same network type, either point-to-point or broadcast.

Exam trap

The trap here is assuming that OSPFv3 automatically negotiates network type or that link-local addresses must be manually configured, when the real issue is the mismatch in network type.

1174
MCQmedium

Review this configuration: route-map RMAP permit 10 match ipv6 address prefix-list PREFIX set interface null0 ! ipv6 prefix-list PREFIX seq 5 permit 2001:db8:5::/48 ! interface GigabitEthernet0/6 ipv6 verify unicast source reachable-via any allow-default What is the purpose of the 'allow-default' keyword?

A.It allows uRPF to use the default route as a valid path for source reachability.
B.It allows the router to accept packets with source addresses from the default prefix.
C.It disables uRPF for packets matching the default route.
D.It is used to allow multicast traffic through uRPF.
AnswerA

Unicast RPF normally discards packets whose source has no specific route in the RIB. The allow-default keyword permits the default route to satisfy the reachability check, so sources reachable only via the default route pass verification rather than being dropped.

Why this answer

The 'allow-default' keyword in the 'ipv6 verify unicast source reachable-via any' command modifies Unicast Reverse Path Forwarding (uRPF) behavior. By default, uRPF checks the FIB for a matching route to the source address, but it excludes the default route. Adding 'allow-default' permits uRPF to consider the default route (::/0) as a valid path for source reachability, ensuring that traffic with source addresses that only match the default route is not dropped.

Exam trap

The trap here is that candidates often confuse 'allow-default' with allowing default source addresses or disabling uRPF, when in fact it simply includes the default route in the uRPF source reachability check.

How to eliminate wrong answers

Option B is wrong because 'allow-default' does not relate to accepting packets with source addresses from a default prefix; it controls whether the default route is used in the uRPF reachability check for any source address. Option C is wrong because it does not disable uRPF for packets matching the default route; instead, it enables uRPF to use the default route as a valid path, keeping uRPF active. Option D is wrong because uRPF is designed for unicast traffic only, and multicast traffic is not subject to uRPF checks; the 'allow-default' keyword has no impact on multicast.

1175
MCQhard

A network engineer runs the following command on Router R8: R8# show ip route 10.2.2.0 Routing entry for 10.2.2.0/24 Known via "eigrp 100", distance 90, metric 28160 Redistributing via eigrp 100 Last update from 192.168.2.1 on GigabitEthernet0/0, 00:00:05 ago Routing Descriptor Blocks: * 192.168.2.1, from 192.168.2.1, 00:00:05 ago, via GigabitEthernet0/0 Route metric is 28160, traffic share count is 1 R8 also has a static route to 10.2.2.0/24 with next-hop 192.168.3.1 configured with distance 95. Which route will be used?

A.The static route will be used because it is manually configured.
B.The EIGRP route will be used because it has a lower administrative distance.
C.Both routes will be used for load balancing.
D.Neither route will be used due to a routing loop.
AnswerB

Administrative distance breaks the tie between routing sources: EIGRP's 90 beats the static route's 95, so the EIGRP path via 192.168.2.1 is installed. The stem's distance values confirm this ordering, making the static route inactive for 10.2.2.0/24.

Why this answer

Cisco IOS selects routes by comparing administrative distance (AD) first; EIGRP's internal AD is 90, while the static route was configured with AD 95. Since 90 < 95, the EIGRP-learned route wins and is installed in the routing table, regardless of the fact that the static route was manually configured.

Exam trap

The trap is assuming 'manually configured static routes always win' — candidates must remember that administrative distance, not configuration method, determines route selection.

How to eliminate wrong answers

Option A is wrong because manual configuration does not override AD — a static route with a higher AD than a dynamic protocol loses to that protocol. Option C is wrong because load balancing (equal-cost multipath) requires routes with identical AD and metric; here ADs differ (90 vs 95), so only one route is installed. Option D is wrong because there is no routing loop indicated — the output shows a single valid next-hop via GigabitEthernet0/0, and the static route is simply less preferred.

1176
Multi-Selecthard

A network administrator is deploying a DMVPN Phase 3 hub-and-spoke topology using Cisco IOS routers. The hub router is configured with a multipoint GRE (mGRE) interface and NHRP. Spokes are configured with mGRE and NHRP as well. The administrator wants to ensure that spoke-to-spoke traffic flows directly without traversing the hub after initial registration. Which two statements about DMVPN Phase 3 operation are true? (Choose two.)

Select 2 answers
A.The hub must be configured with 'ip nhrp redirect' to enable spoke-to-spoke direct communication.
B.The hub must be configured with 'ip nhrp nhs' pointing to itself to act as the next-hop server.
C.Spokes must be configured with 'ip nhrp shortcut' to dynamically create direct tunnels to other spokes.
D.The hub must be configured with 'ip nhrp map multicast dynamic' to enable spoke-to-spoke multicast traffic.
E.Spokes must be configured with 'ip nhrp network-id' that matches the hub's network-id to form the NHRP domain.
AnswersA, C

'ip nhrp redirect' on the hub allows the hub to send a redirect message to the spoke when it detects that traffic is being routed through the hub to another spoke. This enables the spoke to initiate an NHRP resolution for the destination spoke's NBMA address and establish a direct tunnel.

Why this answer

In DMVPN Phase 3, direct spoke-to-spoke communication is enabled by configuring 'ip nhrp redirect' on the hub and 'ip nhrp shortcut' on the spokes. The hub uses NHRP redirect to inform the spoke that a better path exists, and the spoke uses NHRP shortcut to dynamically create a direct tunnel to the destination spoke.

Exam trap

The trap here is assuming that basic NHRP commands like network-id or NHS configuration are Phase 3 specific, when they are common to all DMVPN phases.

1177
Multi-Selectmedium

Which TWO configuration steps are required to implement manual route summarization in OSPF on an ABR? (Choose TWO.)

Select 2 answers
A.Configure the 'area area-id range network mask' command under router OSPF configuration.
B.Ensure the summary address is a supernet of the networks being summarized.
C.Use the 'summary-address network mask' command under router OSPF configuration.
D.Apply the 'ip summary-address ospf' command under the interface connecting to the backbone.
E.Configure a 'network' statement that matches the summary address.
AnswersA, B

Manual summarisation on an ABR requires the 'area area-id range network mask' command under router OSPF configuration, which instructs the ABR to advertise a single Type 3 summary LSA for the specified prefix range instead of individual component routes.

Why this answer

Option A is correct because on an ABR, manual route summarization for inter-area routes is configured with the 'area area-id range network mask' command under router OSPF configuration, which aggregates Type 3 summary LSAs for the specified area's networks. Option B is correct because the summary address must be a supernet that encompasses all the component networks being summarized, ensuring the range covers every prefix it is meant to represent. Option C is wrong because 'summary-address network mask' is used on an ASBR to summarize external routes redistributed into OSPF, not for ABR inter-area summarization.

Option D is wrong because 'ip summary-address ospf' is an EIGRP interface command, not an OSPF ABR configuration step. Option E is wrong because a 'network' statement only enables OSPF on matching interfaces; it does not create a summary route.

1178
MCQmedium

Examine this configuration: ``` router ospf 1 distance ospf intra-area 150 inter-area 160 external 170 ``` What is the effect of this command?

A.It sets the administrative distance for all OSPF routes to 150.
B.It sets the administrative distance for intra-area OSPF routes to 150, inter-area to 160, and external to 170.
C.It sets the administrative distance for OSPF routes to 150, but only for routes learned from area 1.
D.It sets the administrative distance for OSPF external routes to 170 and leaves intra-area and inter-area at default.
AnswerB

The distance ospf command overrides default administrative distances per route type: intra-area 110, inter-area 110, external 110. Here intra-area becomes 150, inter-area 160 and external 170, so OSPF routes are less preferred than other sources, altering route selection accordingly.

Why this answer

This command sets different administrative distances for different OSPF route types: intra-area to 150, inter-area to 160, external to 170.

1179
MCQeasy

A network administrator is configuring a site-to-site IPsec VPN between two Cisco IOS XE routers. The administrator wants to ensure that the VPN tunnel only encrypts traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet. Which configuration element defines the traffic to be encrypted?

A.transform set
B.ISAKMP policy
C.crypto ACL
D.crypto map
AnswerC

The crypto ACL (extended access list) defines which traffic is interesting and should be protected by the IPsec VPN. In this scenario, an ACL permitting traffic from 10.1.1.0/24 to 10.2.2.0/24 and vice versa would be referenced by the crypto map. This ACL is the element that specifies the traffic to be encrypted.

Why this answer

In a site-to-site IPsec VPN, the crypto ACL (an extended access list) is used to define interesting traffic that should be encrypted and sent through the tunnel. The crypto map references this ACL to match packets. The transform set and ISAKMP policy define how to protect the traffic and negotiate the tunnel, but they do not select the traffic.

Exam trap

The trap here is confusing the role of the crypto ACL with the crypto map or transform set, which are used to apply protection but do not define the traffic itself.

1180
MCQmedium

A network engineer is troubleshooting a DMVPN Phase 3 network. Spoke-to-spoke tunnels are not being established directly; traffic between spokes is going through the hub. The hub is configured with 'ip nhrp redirect' and spokes with 'ip nhrp shortcut'. Which additional configuration is required on the spokes to enable direct spoke-to-spoke communication?

A.Configure 'ip nhrp network-id' with the same value on all spokes and the hub.
B.Ensure that the spokes have a route to the destination spoke's tunnel network via the hub, and that they are not using a default route that prevents shortcut switching.
C.Configure 'ip nhrp shortcut' on the hub tunnel interface.
D.Configure 'ip nhrp map multicast dynamic' on the hub tunnel interface.
AnswerB

For spoke-to-spoke shortcut tunnels to form, the spoke must have a specific route to the destination network that points to the tunnel interface, not a default route. If a default route is used, the spoke will not attempt NHRP resolution for the specific destination and will continue sending traffic via the hub. The spoke needs a more specific route (e.g., a /24 for the remote spoke's LAN) to trigger the shortcut. This is a common oversight in DMVPN Phase 3 deployments.

Why this answer

In DMVPN Phase 3, spoke-to-spoke shortcut tunnels require that the spoke has a specific route to the destination network pointing to the tunnel interface. If the spoke uses a default route, it will not perform NHRP resolution for the specific destination, and traffic will continue to flow through the hub. Therefore, ensuring that spokes have specific routes (not just a default) is essential for direct spoke-to-spoke communication.

Exam trap

The trap here is focusing on NHRP commands like 'ip nhrp redirect' and 'ip nhrp shortcut' while overlooking the routing table requirement for specific routes to trigger shortcut switching.

1181
MCQmedium

Review the following configuration: ipv6 access-list FILTER permit tcp 2001:db8:1::/48 any eq 80 permit tcp 2001:db8:1::/48 any eq 443 deny ipv6 any any interface GigabitEthernet0/3 ipv6 traffic-filter FILTER out What is the effect of this configuration?

A.Only HTTP and HTTPS traffic from 2001:db8:1::/48 is permitted outbound; all other traffic is denied.
B.All traffic from 2001:db8:1::/48 is permitted because the ACL does not specify destination prefix.
C.The ACL is misconfigured because 'out' should be 'in' for source-based filtering.
D.The ACL permits all traffic because the deny statement is implicit.
AnswerA

The outbound IPv6 ACL permits TCP port 80 and 443 sourced from 2001:db8:1::/48, then the implicit-final deny ipv6 any any drops everything else leaving GigabitEthernet0/3. It satisfies the stem by restricting egress to those two web ports from that prefix only.

Why this answer

The IPv6 ACL named FILTER explicitly permits TCP traffic from source prefix 2001:db8:1::/48 to any destination on ports 80 (HTTP) and 443 (HTTPS), and then denies all other IPv6 traffic. Applied as an outbound traffic filter on GigabitEthernet0/3, this configuration restricts outbound traffic to only HTTP and HTTPS sessions originating from the specified prefix.

Exam trap

Cisco often tests the misconception that an ACL without a destination prefix permits all traffic from the source, but in reality, the permit statement still requires the specified protocol and ports to match, and the explicit deny blocks everything else.

How to eliminate wrong answers

Option B is wrong because the ACL does not permit all traffic from 2001:db8:1::/48; it only permits TCP traffic to ports 80 and 443, and the explicit deny ipv6 any any blocks all other traffic. Option C is wrong because applying the ACL outbound is valid for filtering traffic leaving the interface; the direction 'out' is appropriate when the source prefix is the local network, and there is no requirement to use 'in' for source-based filtering. Option D is wrong because the ACL includes an explicit deny ipv6 any any statement, so the implicit deny at the end of the ACL is redundant but does not permit all traffic; the explicit deny still blocks everything not matched by the permit statements.

1182
MCQmedium

A network engineer is troubleshooting an IPsec site-to-site VPN that uses a GRE tunnel over IPsec. The GRE tunnel is up/up, but the routing protocol (EIGRP) running over the GRE tunnel is not forming an adjacency. The engineer checks the tunnel configuration and sees that the tunnel source and destination are correct. What is the most likely cause?

A.The crypto map access list does not match GRE protocol (47) traffic.
B.The EIGRP hello timer is set too high.
C.The tunnel interface is not configured with an IP address.
D.The IPsec transform set does not include ESP encryption.
AnswerA

Correct because GRE uses protocol 47; if the crypto map's access list only matches IP traffic between the LAN subnets, the GRE packets themselves are not encrypted and are dropped, causing the GRE tunnel to appear up but the routing protocol to fail.

Why this answer

In a GRE over IPsec configuration, the crypto map's ACL must permit GRE (IP protocol 47) traffic between the tunnel endpoints. If the ACL only matches other traffic (e.g., TCP/UDP), the GRE packets are not encrypted and the IPsec tunnel does not carry them, so EIGRP hellos never reach the peer and the adjacency fails even though the GRE tunnel shows up/up.

Exam trap

300-410 often tests the interaction between GRE and IPsec ACLs; candidates focus on EIGRP timers or tunnel IPs and miss that the crypto ACL must explicitly permit protocol 47 (GRE) between the tunnel endpoints.

How to eliminate wrong answers

Option B is wrong because EIGRP hello timers default to 5 seconds on most interfaces; an incorrectly high timer would slow adjacency formation but not prevent it entirely, and it is not the most likely cause given the GRE/IPsec context. Option C is wrong because a tunnel interface without an IP address would keep the line protocol down, not up/up; the question states the tunnel is up/up. Option D is wrong because a transform set without ESP encryption would cause IPsec to fail entirely, and the GRE tunnel would not come up over IPsec; also, ESP encryption is not strictly required (ESP-null or AH could be used), but the symptom would be different.

1183
MCQmedium

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# show crypto ipsec sa detail interface: Tunnel0 Crypto map tag: CMAP, local addr 192.168.1.1 protected vrf: (none) local ident (addr/mask/prot/port): (192.168.1.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port): (192.168.2.0/255.255.255.0/0/0) current_peer 192.168.2.2 port 500 PERMIT, flags={origin_is_acl,} #pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0 #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0 #pkts compressed: 0, #pkts decompressed: 0 #pkts not compressed: 0, #pkts compr. failed: 0 #pkts not decompressed: 0, #pkts decompress failed: 0 #send errors 0, #recv errors 0 local crypto endpt.: 192.168.1.1, remote crypto endpt.: 192.168.2.2 path mtu 1500, ip mtu 1500, ip mtu idb Serial0/0/0 current outbound spi: 0x0(0) PFS (Y/N): N, DH group: none inbound esp sas: spi: 0x0(0) transform: esp-3des esp-sha-hmac , in use settings ={Tunnel, } conn id: 0, flow_id: 0, sibling_flags 80000000, crypto map: CMAP sa timing: remaining key lifetime (k/sec): (0/0) IV size: 8 bytes replay detection support: N outbound esp sas: spi: 0x0(0) transform: esp-3des esp-sha-hmac , in use settings ={Tunnel, } conn id: 0, flow_id: 0, sibling_flags 80000000, crypto map: CMAP sa timing: remaining key lifetime (k/sec): (0/0) IV size: 8 bytes replay detection support: N What does this output indicate?

A.The IPsec SA is fully established and encrypting traffic.
B.The IPsec SA is in a pending state; the SPI is 0, meaning the SA negotiation is incomplete or the SA has been deleted.
C.The IPsec SA is using PFS, which is causing the SA to be rekeyed frequently.
D.The crypto map is not applied to the interface, so the SA is not used.
AnswerB

An outbound SPI of 0x0 with zeroed inbound and outbound ESP SAs shows Phase 2 never completed, leaving the SA pending or deleted. This satisfies the stem's constraint of diagnosing an incomplete or torn-down IPsec SA.

Why this answer

The output shows SPI values of 0x0 for both inbound and outbound ESP SAs, with zero packet encapsulation and encryption counts. This indicates that the IPsec Security Association (SA) negotiation is incomplete or the SA has been deleted, as a valid SA would have a non-zero SPI and active packet counters. The 'current_peer' and crypto map are present, but the SA is not operational.

Exam trap

Cisco often tests the misconception that a crypto map present in the output means the SA is active, but the SPI of 0x0 and zero packet counters are the definitive indicators of an incomplete or deleted SA.

How to eliminate wrong answers

Option A is wrong because the SPI of 0x0 and zero packet counters clearly show the IPsec SA is not established or encrypting traffic; a fully established SA would have non-zero SPIs and increasing packet counts. Option C is wrong because the output explicitly shows 'PFS (Y/N): N, DH group: none', indicating PFS is not enabled, so it cannot be causing frequent rekeying. Option D is wrong because the crypto map tag 'CMAP' is listed under interface Tunnel0, confirming the crypto map is applied to the interface, but the SA is not active.

1184
MCQhard

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The tunnel is up, but traffic is not passing. The administrator runs show crypto ipsec sa and notices that the inbound and outbound ESP SAs are present, but the packet counters are not incrementing. The ACL used for the crypto map is permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255. Which action is most likely to resolve the issue?

A.Confirm that the transform set matches on both peers.
B.Ensure that the preshared key is identical on both peers.
C.Check the routing table to ensure that the remote protected subnet is reachable via the tunnel interface or that the next hop is correct.
D.Verify that the crypto ACL on the remote peer is a mirror image of the local ACL.
AnswerC

If the IPsec SAs are established but packet counters are not incrementing, the router is not forwarding interesting traffic into the tunnel. This often occurs when the route to the remote protected subnet points out of the physical interface instead of the tunnel interface, or when there is no route at all. Correcting the routing ensures that packets matching the crypto ACL are sent through the VPN.

Why this answer

When IPsec SAs are up but packet counters remain at zero, the router is not identifying or routing traffic into the VPN. The most common cause is a routing issue: the remote subnet is not reachable via the tunnel, or a more specific route directs traffic elsewhere. Verifying the routing table and ensuring the tunnel interface is the next hop for the protected subnet resolves the problem.

Exam trap

The trap here is assuming that an ACL mismatch is the culprit because it's a common VPN issue, but with SAs established, the problem is more likely routing or interesting traffic not being matched.

1185
MCQmedium

Consider the following partial configuration on a Cisco IOS-XE switch: monitor session 1 source interface GigabitEthernet1/0/1 both monitor session 1 destination interface GigabitEthernet1/0/2 What is the effect of this configuration?

A.It copies all traffic received and transmitted on GigabitEthernet1/0/1 to GigabitEthernet1/0/2.
B.It copies only ingress traffic from GigabitEthernet1/0/1 to GigabitEthernet1/0/2.
C.It copies only egress traffic from GigabitEthernet1/0/1 to GigabitEthernet1/0/2.
D.It copies traffic from GigabitEthernet1/0/2 to GigabitEthernet1/0/1.
AnswerA

The `both` keyword makes the source interface capture ingress and egress frames, satisfying the requirement to mirror bidirectional traffic. SPAN then replicates those frames out the destination port, GigabitEthernet1/0/2, so every packet received and transmitted on GigabitEthernet1/0/1 is copied there.

Why this answer

The 'both' keyword in the source interface command instructs the switch to mirror traffic in both directions — ingress (received) and egress (transmitted) — from the source port. The destination interface command directs that mirrored copy to GigabitEthernet1/0/2, so all traffic in and out of Gi1/0/1 is duplicated to Gi1/0/2. This is the standard SPAN (Switched Port Analyzer) configuration used for packet capture and IDS monitoring.

Exam trap

The trap here is confusing the direction keywords 'both', 'rx', and 'tx' — candidates often assume 'both' means both source and destination ports, when it actually means both directions of traffic on the source port.

How to eliminate wrong answers

Option B is wrong because 'ingress' or 'rx' would be the keyword for receive-only mirroring, not 'both'. Option C is wrong because 'egress' or 'tx' would be the keyword for transmit-only mirroring, not 'both'. Option D is wrong because it reverses the direction — the source is Gi1/0/1 and the destination is Gi1/0/2, so traffic flows from source to destination, not the other way around.

1186
MCQhard

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on an interface connected to a network with asymmetric routing. Users report intermittent connectivity issues. Which is the most likely explanation?

A.Asymmetric routing causes packets to arrive on an interface that is not the best return path, so uRPF drops them.
B.The uRPF configuration is missing the 'allow-default' option.
C.The routing table does not have a route for the source IP.
D.The interface has multiple IP addresses.
AnswerA

Strict uRPF checks that the source address is reachable via the same interface the packet arrived on. With asymmetric routing, return traffic uses a different path, so the incoming interface fails the reverse-path lookup and legitimate packets are dropped, causing intermittent connectivity.

Why this answer

Unicast Reverse Path Forwarding (uRPF) in strict mode checks that the source IP address of an incoming packet has a route in the routing table pointing back out the same interface on which the packet arrived. In an asymmetric routing scenario, packets may arrive on an interface that is not the best return path, causing the uRPF check to fail and the packet to be dropped. This explains the intermittent connectivity issues reported by users.

Exam trap

Cisco often tests the misconception that uRPF drops packets only when there is no route for the source IP, but the real trap is that strict mode requires the reverse path to use the exact same interface, which fails under asymmetric routing even when a valid route exists.

How to eliminate wrong answers

Option B is wrong because the 'allow-default' option is used to permit uRPF to use a default route for the reverse path check, but it does not resolve the fundamental issue of asymmetric routing causing packets to arrive on a non-optimal interface. Option C is wrong because the routing table likely does have a route for the source IP; the problem is not the absence of a route but that the route points out a different interface than the one the packet arrived on. Option D is wrong because having multiple IP addresses on an interface does not inherently cause uRPF to drop packets in an asymmetric routing scenario; uRPF checks the source IP against the routing table, not the interface's IP addresses.

1187
MCQhard

Two OSPF routers R1 and R2 are connected via a GigabitEthernet link in area 0. R1 has interface GigabitEthernet0/0 ip ospf network point-to-point, while R2 has the default OSPF network type broadcast. R1's show ip ospf neighbor shows R2 in FULL state, but R2's show ip ospf neighbor shows R1 in FULL state. However, routes from R1 are not appearing in R2's routing table. Show ip ospf database on R2 shows the router LSA from R1 but not the network LSA. What is the root cause?

A.The OSPF network type mismatch causes R1 to not generate a network LSA, and R2 cannot install routes that rely on that LSA.
B.The OSPF adjacency is stuck in EXSTART state due to MTU mismatch.
C.R2 has a firewall blocking Type 2 LSAs.
D.R1's router LSA has an incorrect metric, causing R2 to ignore it.
AnswerA

R1's point-to-point network type does not elect a DR or generate Type 2 LSAs, so R2 lacks the necessary topology information for transit.

Why this answer

When R1 has the OSPF network type set to point-to-point on the GigabitEthernet link, it does not elect a DR/BDR and therefore does not generate a Type 2 (Network) LSA. R2, with the default broadcast network type, expects a Network LSA to build complete routing information for the segment. Although the adjacency reaches FULL and R2 receives R1's Type 1 (Router) LSA, the missing Network LSA prevents R2 from installing routes that depend on that LSA, such as those for networks advertised by R1 that are not directly connected to the link.

Exam trap

Cisco often tests the misconception that a FULL adjacency guarantees full route exchange, but the trap here is that OSPF network type mismatch can break route installation even when neighbor state is FULL and Router LSAs are exchanged.

How to eliminate wrong answers

Option B is wrong because the adjacency is already in FULL state, not EXSTART, so an MTU mismatch is not the issue. Option C is wrong because a firewall blocking Type 2 LSAs would not affect the adjacency state or the presence of the Router LSA in the database; the problem is a missing Network LSA due to network type mismatch, not a filter. Option D is wrong because the Router LSA from R1 is present in R2's database, and there is no indication of an incorrect metric; OSPF does not ignore LSAs based solely on metric values.

1188
MCQhard

A service provider network is experiencing MPLS label distribution failures between R1 and R2. R1 has: event manager applet LDP-MONITOR event syslog pattern "%LDP-4-ERROR" action 1.0 cli command "enable" action 2.0 cli command "clear mpls ldp neighbor *" action 3.0 syslog msg "Cleared LDP neighbors". Router R2 shows: LDP session is down, and logs show repeated LDP errors. What is the root cause?

A.The EEM applet clears all LDP neighbors upon any LDP error, preventing the session from stabilizing.
B.The LDP router-id is misconfigured on R1.
C.The syslog pattern matches only severity 4, but LDP errors are severity 3.
D.The MPLS label range is exhausted on R1.
AnswerA

The EEM applet triggers on any %LDP-4-ERROR syslog message and immediately clears all LDP neighbours. Each error therefore tears down the session before it can re-establish, creating the repeated failures and permanent down state on R2.

Why this answer

The EEM applet is configured to trigger on the syslog pattern '%LDP-4-ERROR' and immediately execute 'clear mpls ldp neighbor *', which tears down all LDP sessions on R1. Each time LDP tries to re-establish and logs another error, the applet fires again, creating a loop that prevents the LDP session from ever stabilizing. The root cause is the overly aggressive automated remediation, not an LDP configuration issue on R2.

Exam trap

300-410 often tests EEM applet side effects — candidates focus on the LDP error itself and overlook that the applet's 'clear mpls ldp neighbor *' action is the actual cause of the persistent session down, mistaking the symptom for the root cause.

How to eliminate wrong answers

Option B is wrong because a misconfigured LDP router-id would cause session establishment failures with specific error messages about router-id mismatch, and the question does not indicate that — the logs show repeated LDP errors triggered by the applet's clearing action. Option C is wrong because the syslog pattern '%LDP-4-ERROR' matches severity level 4 (warning) messages, and the pattern is matching correctly — the problem is what the applet does when it matches, not the severity matching. Option D is wrong because label range exhaustion would produce a specific 'no label available' error and would not be remedied by clearing neighbors; the question gives no indication of label exhaustion.

1189
MCQeasy

A network engineer runs the following command to troubleshoot a Route Redistribution issue: R1# debug ip ospf adj And sees the following output: *Mar 1 00:20:11.456: OSPF: Rcv pkt from 10.1.1.2, Serial0/0/0 : Mismatch Authentication type. Input packet specified type 0, we use type 1 *Mar 1 00:20:11.457: OSPF: Rcv pkt from 10.1.1.2, Serial0/0/0 : Mismatch Authentication type. Input packet specified type 0, we use type 1 What does this output indicate?

A.OSPF adjacency is forming successfully with authentication.
B.OSPF authentication is misconfigured; the neighbor is not using authentication while this router is.
C.OSPF is redistributing routes correctly but authentication is failing.
D.The OSPF process is using MD5 authentication and the neighbor is using plaintext.
AnswerB

The debug output shows the neighbour's packet carrying authentication type 0 (none) while this router expects type 1 (plain text), confirming an authentication mismatch where the local interface enforces authentication the neighbour does not send.

Why this answer

The debug output shows 'Mismatch Authentication type. Input packet specified type 0, we use type 1'. In OSPF, authentication type 0 means no authentication, while type 1 is plaintext password authentication.

This indicates that the local router is configured for plaintext authentication, but the neighbor is not using authentication, causing a mismatch and preventing adjacency formation.

Exam trap

300-410 often tests the interpretation of OSPF authentication type codes, where candidates may confuse type 0 with plaintext or MD5, leading to misdiagnosis of the mismatch.

How to eliminate wrong answers

Option A is wrong because the mismatch prevents adjacency from forming successfully. Option C is wrong because the issue is authentication, not route redistribution; the debug is about adjacency, not redistribution. Option D is wrong because type 1 is plaintext, not MD5 (which is type 2); the neighbor is using type 0 (no auth), not plaintext.

1190
MCQmedium

A network engineer is configuring a Cisco IOS XE router to support MPLS L3VPN. The router is a PE device with a VRF named CUSTOMER. The engineer wants to ensure that the PE router can forward traffic for the CUSTOMER VRF using MPLS labels. Which command must be configured on the PE router's core-facing interface to enable MPLS forwarding?

A.mpls label protocol ldp
B.mpls ldp router-id Loopback0
C.mpls ldp discovery transport-address interface
D.mpls ip
AnswerD

The mpls ip command enables MPLS forwarding on an interface. On the core-facing interface of a PE router, this command is required to allow the interface to send and receive MPLS-labeled packets. Without it, the interface will not process MPLS labels, and traffic for the CUSTOMER VRF will not be forwarded correctly across the MPLS backbone.

Why this answer

To enable MPLS forwarding on a Cisco IOS XE router interface, the mpls ip command must be configured. This command instructs the interface to process MPLS labels and forward labeled packets. On a PE router, the core-facing interface must have mpls ip enabled to send and receive MPLS traffic for VPNs.

While other MPLS-related commands configure label distribution or router IDs, they do not enable the actual forwarding of MPLS packets on the interface.

Exam trap

The trap here is confusing commands that configure MPLS label distribution (like mpls label protocol ldp) with the command that actually enables MPLS forwarding on an interface (mpls ip).

1191
MCQmedium

In VRF-Lite, which routing protocols can be used within a VRF?

A.Only static routing is supported in VRF-Lite.
B.OSPF, EIGRP, RIP, and BGP can all be configured per VRF.
C.Only OSPF and EIGRP are supported in VRF-Lite.
D.BGP cannot be used within a VRF in VRF-Lite.
AnswerB

VRF-Lite maintains separate routing and forwarding tables per VRF, so each instance runs its own OSPF, EIGRP, RIP, or BGP process independently. This satisfies the requirement that multiple protocols coexist per VRF without leaking between them.

Why this answer

VRF-Lite supports running any standard routing protocol independently within each VRF, including OSPF, EIGRP, RIP, and BGP. Each VRF maintains its own routing table and protocol instance, so you configure the protocol under the VRF address family or with the 'vrf' keyword. This per-VRF isolation is the core value of VRF-Lite — multiple virtual routing domains on one physical router.

Exam trap

300-410 often tests the misconception that VRF-Lite is limited to static routing or a subset of protocols, when in fact it supports the full suite of dynamic routing protocols per VRF.

How to eliminate wrong answers

Option A is wrong because VRF-Lite is not limited to static routing — dynamic protocols are fully supported per VRF. Option C is wrong because it arbitrarily excludes RIP and BGP; all four protocols (OSPF, EIGRP, RIP, BGP) can run per VRF. Option D is wrong because BGP is fully supported within a VRF (using address-family ipv4 vrf <name> under router bgp), and is in fact commonly used for MPLS-less VRF-Lite peering.

1192
Drag & Drophard

Drag and drop the steps to troubleshoot BGP adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, check interface IP connectivity with ping; then verify BGP neighbor reachability and TCP port 179; next inspect BGP configuration for AS number mismatches; then examine BGP timers and update-source; finally use debug ip bgp to see session state transitions.

1193
MCQeasy

A network engineer runs the following command on Router R1: R1# show ip nat translations Pro Inside global Inside local Outside local Outside global udp 192.0.2.10:10000 10.0.0.10:10000 203.0.113.5:53 203.0.113.5:53 udp 192.0.2.10:10001 10.0.0.11:10000 203.0.113.5:53 203.0.113.5:53 udp 192.0.2.10:10002 10.0.0.12:10000 203.0.113.5:53 203.0.113.5:53 R1# show ip nat statistics Total active translations: 3 (0 static, 3 dynamic; 3 extended) Outside interfaces: GigabitEthernet0/1 Inside interfaces: GigabitEthernet0/0 Hits: 150 Misses: 0 CEF Translated packets: 150, CEF Punted packets: 0 Expired translations: 0 Dynamic mappings: -- Inside Source [Id] ip nat inside source list ACL1 interface GigabitEthernet0/1 overload refcount 3 Based on this output, which statement is correct?

A.PAT is working correctly; multiple inside hosts share the same global address with unique ports.
B.The NAT pool is exhausted because all addresses are used.
C.Static NAT is configured for DNS traffic.
D.The inside and outside interfaces are swapped.
AnswerA

Unique source ports (10000–10002) map three inside locals onto one global address, confirming PAT overload. The `overload` keyword on the inside source list, combined with three extended dynamic translations, satisfies the requirement that multiple hosts share 192.0.2.10. Distinct port allocation, not address pooling, is the mechanism.

Why this answer

The output shows three dynamic NAT translations, all using the same inside global address 192.0.2.10 with unique source ports (10000, 10001, 10002). This is the hallmark of Port Address Translation (PAT) or NAT overload, where multiple inside hosts (10.0.0.10, 10.0.0.11, 10.0.0.12) share a single public IP address by differentiating sessions via layer-4 port numbers. The 'overload' keyword in the dynamic mapping confirms PAT is active and working correctly.

Exam trap

Cisco often tests the distinction between PAT (overload) and basic NAT (pool without overload), and candidates may mistakenly think that multiple translations to the same destination (203.0.113.5:53) indicate a pool exhaustion or static NAT, when in fact the unique source ports confirm PAT is functioning correctly.

How to eliminate wrong answers

Option B is wrong because the NAT pool is not exhausted; PAT allows many inside hosts to share a single global address, and the output shows only 3 active translations with plenty of port space remaining. Option C is wrong because there are no static NAT entries (the count shows 0 static, 3 dynamic), and the translations are for UDP/53 (DNS) but are dynamically created via PAT, not static configuration. Option D is wrong because the interfaces are correctly assigned: GigabitEthernet0/1 is the outside interface (where the global address 192.0.2.10 resides) and GigabitEthernet0/0 is the inside interface; swapping them would prevent NAT from working and the translations would not appear.

1194
MCQmedium

What is the default administrative distance for OSPF routes in a VRF when OSPF is used as the PE-CE routing protocol in MPLS L3VPN?

A.90
B.110
C.115
D.120
AnswerB

OSPF carries an administrative distance of 110 regardless of whether it runs in a global routing table or inside a VRF. The VRF context changes route isolation, not the protocol's default preference, so 110 remains the value PE-CE OSPF routes receive.

Why this answer

OSPF routes have a default administrative distance of 110, which applies both in the global table and within a VRF.

1195
MCQeasy

A network engineer runs the following command to troubleshoot a Policy-Based Routing (PBR) issue: R1# show ip policy Interface Route-map FastEthernet0/0 PBR-MAP What does this output indicate?

A.PBR is enabled on FastEthernet0/0 with route-map PBR-MAP.
B.The route-map PBR-MAP is not configured.
C.PBR is applied globally and on the interface.
D.The route-map is applied to all interfaces.
AnswerA

The show ip policy output maps interface FastEthernet0/0 to route-map PBR-MAP, confirming that policy-based routing is applied to inbound traffic on that interface. This directly satisfies the stem's requirement to identify where PBR is enabled and which route-map governs it.

Why this answer

The output shows that PBR is applied on FastEthernet0/0 using route-map PBR-MAP. This confirms the interface-level configuration.

1196
MCQmedium

A network engineer runs the following command to troubleshoot an EEM issue: R1# show event manager policy configuration TRACK-INTERFACE Applet TRACK-INTERFACE event syslog pattern "OSPF-5-ADJCHG" action 1.0 cli command "show ip route" action 2.0 cli command "show ip ospf neighbor" action 3.0 syslog msg "OSPF adjacency change detected" What does this output indicate?

A.The applet 'TRACK-INTERFACE' is configured to trigger on syslog message 'OSPF-5-ADJCHG' and execute three actions in order: show ip route, show ip ospf neighbor, and send a syslog message.
B.The applet 'TRACK-INTERFACE' is currently executing and has run the first two actions.
C.The applet 'TRACK-INTERFACE' has a syntax error because the actions are not numbered correctly.
D.The applet 'TRACK-INTERFACE' will only execute the first action because the others are commented out.
AnswerA

The configuration shows one syslog event watching for the OSPF-5-ADJCHG pattern, with three numbered actions executed sequentially: two CLI show commands then a syslog message. This matches the applet's trigger and ordered action list exactly.

Why this answer

The output shows the configuration of a specific EEM applet. It displays the event trigger and the actions in order. Each action has a step number (e.g., 1.0) that determines the order of execution.

This is useful for verifying the applet configuration.

1197
Drag & Dropmedium

Drag and drop the steps to troubleshoot EIGRP neighbor adjacency formation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order ensures that you first verify the physical and data link layer, then check IP connectivity, confirm EIGRP is enabled on the correct interfaces, verify the autonomous system number matches, and finally check for any passive interface configuration that might block adjacency.

1198
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 neighbors IPv6 Address Age Link-layer Addr State Interface 2001:DB8:1::1 0 aaaa.bbbb.cccc REACH Gi0/0/0 2001:DB8:1::2 10 aaaa.bbbb.cccd STALE Gi0/0/0 2001:DB8:1::3 - aaaa.bbbb.ccce DELAY Gi0/0/1 FE80::1 0 aaaa.bbbb.cccf REACH Gi0/0/0 Based on this output, which statement is correct?

A.All neighbors are in a stable state.
B.The neighbor 2001:DB8:1::3 is in DELAY state, meaning a Neighbor Solicitation will be sent soon.
C.The neighbor 2001:DB8:1::2 is unreachable.
D.The link-local address FE80::1 is not valid.
AnswerB

DELAY state means a NS is pending after a delay timer.

Why this answer

The DELAY state in IPv6 Neighbor Discovery (ND) indicates that a neighbor has not been confirmed reachable within the last 5 seconds, and the router will send a Neighbor Solicitation (NS) message after the DELAY timer expires (default 5 seconds) to verify reachability. The entry for 2001:DB8:1::3 shows a hyphen in the Age column, meaning it was just created or refreshed, and it is in DELAY, so an NS will be sent soon.

Exam trap

Cisco often tests the misconception that STALE means unreachable or that DELAY is a failure state, when in fact STALE is a normal aging state and DELAY is a brief waiting period before probing.

How to eliminate wrong answers

Option A is wrong because not all neighbors are in a stable state; the neighbor 2001:DB8:1::3 is in DELAY (transient state) and 2001:DB8:1::2 is in STALE (needs verification), so the table includes unstable entries. Option C is wrong because the STALE state for 2001:DB8:1::2 does not mean unreachable; it means the entry is still valid but reachability has not been confirmed within the last 30 minutes, and the router will not actively probe it until traffic is sent. Option D is wrong because the link-local address FE80::1 is valid and in REACH state, indicating it is reachable and has been confirmed via Neighbor Advertisement; link-local addresses are always valid on the local link.

1199
MCQeasy

A network engineer is configuring a Cisco IOS-XE router for DMVPN Phase 3. The engineer wants to ensure that spoke-to-spoke traffic flows directly between spokes without traversing the hub. Which technology should be used to achieve this?

A.NHRP redirect and NHRP shortcut
B.NHRP shortcut only
C.NHRP redirect only
D.Multicast NHRP mapping
AnswerA

In DMVPN Phase 3, NHRP redirect is configured on the hub to inform spokes of a better path, and NHRP shortcut is configured on the spokes to allow them to dynamically build direct tunnels to other spokes. This combination enables spoke-to-spoke traffic to bypass the hub, reducing latency and hub load. This is the correct solution for the scenario.

Why this answer

DMVPN Phase 3 uses NHRP redirect on the hub and NHRP shortcut on the spokes to enable direct spoke-to-spoke tunnels. Redirect informs spokes of a better path, and shortcut allows them to establish direct tunnels. Both are required to achieve the desired traffic flow without traversing the hub.

Exam trap

The trap here is thinking that NHRP redirect alone or shortcut alone can enable direct spoke-to-spoke communication, when both are needed in Phase 3.

1200
MCQeasy

A network engineer is configuring a Cisco router to act as a DHCP relay agent. The DHCP server is located on a different subnet. Which command is required on the router's interface to forward DHCP requests to the server?

A.ip helper-address <server-ip>
B.ip forward-protocol udp 67
C.ip dhcp pool <name>
D.ip dhcp relay <server-ip>
AnswerA

The ip helper-address command configured on the router interface enables DHCP relay by forwarding UDP broadcasts (including DHCP DISCOVER) to the specified server IP address. This allows clients on a subnet without a local DHCP server to obtain addresses from a centralized server. It is the standard method for DHCP relay in Cisco IOS.

Why this answer

The ip helper-address command on an interface enables the router to forward DHCP broadcast requests to a specified DHCP server on another subnet. This is essential when clients and the DHCP server are on different broadcast domains. The command also forwards other UDP broadcasts by default, but DHCP relay is the primary use case here.

Exam trap

The trap here is confusing the DHCP relay command with DHCP server configuration commands; ip helper-address is for relay, while ip dhcp pool is for local server.

Page 15

Page 16 of 19

Page 17