Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 1201–1275

1401 questions total · 19pages · All types, answers revealed

Page 16

Page 17 of 19

Page 18
1201
MCQhard

In MPLS L3VPN, what is the default behavior of BGP auto-summary on Cisco IOS-XE?

A.Auto-summary is enabled by default for all BGP sessions.
B.Auto-summary is disabled by default.
C.Auto-summary is enabled only for iBGP sessions.
D.Auto-summary is disabled for eBGP but enabled for iBGP.
AnswerB

Cisco IOS-XE ships with BGP auto-summary disabled, so classful network summarisation does not occur unless explicitly enabled. This default preserves the exact prefixes advertised across the MPLS L3VPN, satisfying the stem's question about out-of-the-box behaviour rather than configured behaviour.

Why this answer

BGP auto-summary is disabled by default on Cisco IOS-XE. When enabled, it would summarize subnets to their classful boundary, but this is not default.

1202
MCQmedium

A network engineer is troubleshooting an EIGRP adjacency issue between two directly connected routers, R1 and R2. Both routers are configured with the same autonomous system number, but the adjacency fails to come up. The engineer checks the interfaces and verifies that they are up/up. On R1, the output of 'show ip eigrp neighbors' shows nothing. What is the most likely cause of this problem?

A.The interfaces are configured with IP addresses from different subnets.
B.The EIGRP process is shut down on one of the routers.
C.The passive-interface default command is configured under the EIGRP process.
D.The EIGRP router ID is the same on both routers.
AnswerA

EIGRP forms adjacencies only when the primary interface addresses share a common subnet. Mismatched subnets prevent the hello packets from being accepted as valid neighbours, so no adjacency appears despite matching autonomous system numbers and up/up interfaces.

Why this answer

EIGRP requires that directly connected neighbors share a common subnet for their interfaces. If R1 and R2 have IP addresses from different subnets, EIGRP will not form an adjacency because the hello packets sent by one router will be considered invalid by the other due to the subnet mismatch. The 'show ip eigrp neighbors' output is empty because no neighbor has been discovered, which is consistent with this Layer 3 mismatch.

Exam trap

Cisco often tests the requirement that EIGRP neighbors must be on the same subnet, and the trap here is that candidates may overlook this fundamental Layer 3 prerequisite and instead focus on less likely issues like process shutdown or router ID conflicts.

How to eliminate wrong answers

Option B is wrong because if the EIGRP process is shut down on one router, the other router would still see its own neighbors list as empty, but the question states both routers are configured with the same AS number and interfaces are up/up, making a shutdown less likely than a subnet mismatch. Option C is wrong because the 'passive-interface default' command would suppress hello packets on all interfaces, preventing neighbor discovery, but the question does not indicate any such configuration and it would be a less common cause than a subnet mismatch. Option D is wrong because EIGRP routers can have the same router ID without preventing adjacency formation; the router ID is used for routing table stability and loop prevention, not as a requirement for neighbor adjacency.

1203
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 interface tunnel 0 Tunnel0 is up, line protocol is up IPv6 is enabled, link-local address is FE80::1 Global unicast address(es): 2001:DB8:2::1, subnet is 2001:DB8:2::/64 Joined group address(es): FF02::1 FF02::2 ICMP redirects are enabled ICMP unreachables are enabled ND DAD is enabled, number of DAD attempts: 1 ND reachable time is 30000 milliseconds IPv6 uRPF: loose mode (allow default route) Based on this output, what is the uRPF configuration on this interface?

A.uRPF is disabled
B.uRPF is enabled in strict mode
C.uRPF is enabled in loose mode
D.uRPF is enabled but only for IPv4
AnswerC

The output line "IPv6 uRPF: loose mode (allow default route)" explicitly states the configuration. Loose mode verifies only that the source address is reachable via any route, unlike strict mode, which requires the source be reachable through the receiving interface.

Why this answer

The output explicitly shows 'IPv6 uRPF: loose mode (allow default route)', which confirms that unicast Reverse Path Forwarding (uRPF) is enabled in loose mode. In loose mode, the router checks that the source address of an incoming packet has a matching entry in the routing table, but it does not require the incoming interface to match the best return path. This is distinct from strict mode, which requires both a routing table entry and that the incoming interface is the same as the outgoing interface for the return route.

Exam trap

Cisco often tests the distinction between uRPF strict and loose modes by showing output that includes 'loose mode' or 'allow default route', and the trap here is that candidates may confuse 'loose mode' with 'disabled' or incorrectly assume that uRPF only applies to IPv4, ignoring the IPv6-specific output.

How to eliminate wrong answers

Option A is wrong because the output clearly states 'IPv6 uRPF: loose mode', which means uRPF is enabled, not disabled. Option B is wrong because the output specifies 'loose mode', not 'strict mode'; strict mode would require the incoming interface to match the best return path, which is not indicated here. Option D is wrong because the command 'show ipv6 interface tunnel 0' displays IPv6-specific information, and the output explicitly shows 'IPv6 uRPF: loose mode', confirming that uRPF is configured for IPv6, not only for IPv4.

1204
MCQmedium

In DHCPv6, what is the purpose of the SOLICIT message?

A.To request a renewal of an existing lease
B.To confirm a previously allocated prefix
C.To discover available DHCPv6 servers
D.To release an IP address
AnswerC

SOLICIT is the initial DHCPv6 message a client multicasts to locate servers, prompting each to reply with an ADVERTISE. It therefore performs server discovery, the exact function the question asks about, preceding REQUEST and REPLY in the four-message exchange.

Why this answer

In DHCPv6, the SOLICIT message is sent by a client to locate available DHCPv6 servers on the link. This is the first message in the DHCPv6 four-message exchange (Solicit, Advertise, Request, Reply) used for stateful address assignment, as defined in RFC 3315.

Exam trap

Cisco often tests the distinction between the SOLICIT message (server discovery) and the REQUEST message (actual address assignment), leading candidates to confuse the initial discovery phase with the subsequent request phase.

How to eliminate wrong answers

Option A is wrong because lease renewal in DHCPv6 is performed using the RENEW message, not SOLICIT. Option B is wrong because prefix confirmation is handled by the CONFIRM message, which verifies that a previously allocated prefix is still valid. Option D is wrong because releasing an IP address is done via the RELEASE message, not SOLICIT.

1205
MCQmedium

A network engineer is configuring a GRE over IPsec tunnel between two Cisco routers. The engineer wants to ensure that multicast traffic, such as OSPF hello packets, is encrypted and sent over the tunnel. Which statement about the configuration is true?

A.IPsec must be configured in transport mode to preserve the original IP header.
B.The tunnel interface must be configured with the tunnel mode gre multipoint command.
C.The crypto ACL must permit GRE (protocol 47) traffic.
D.The crypto ACL must permit OSPF (protocol 89) traffic.
AnswerC

For GRE over IPsec, the crypto ACL defines which traffic is encrypted. Since GRE encapsulates the multicast traffic, the outer IP packet uses IP protocol 47. Therefore, the crypto ACL must permit GRE traffic between the tunnel endpoints. This ensures that all GRE-encapsulated packets, including multicast, are encrypted by IPsec.

Why this answer

In a GRE over IPsec configuration, GRE encapsulates the multicast traffic, and then IPsec encrypts the GRE packets. The crypto ACL must match the GRE protocol (IP protocol 47) between the tunnel source and destination. This allows multicast and broadcast traffic to be carried over the tunnel because GRE handles the multicast encapsulation, and IPsec provides encryption.

Exam trap

The trap here is thinking that the crypto ACL should match the multicast or routing protocol directly, rather than the GRE encapsulation that carries them.

1206
Multi-Selecthard

Which TWO statements about DHCPv4 option 82 are true? (Choose TWO.)

Select 2 answers
A.Option 82 is inserted by the DHCP client to identify itself to the server.
B.The relay agent must be configured with the 'ip dhcp relay information option' command to insert option 82.
C.The DHCP server can use option 82 to select an IP address from a specific pool based on the circuit ID.
D.Option 82 is only supported in DHCPv6.
E.The 'ip dhcp relay information trusted' command must be configured on the relay agent to insert option 82.
AnswersB, C

Insertion of option 82 is not automatic; the relay agent must enable it with the 'ip dhcp relay information option' command. This satisfies the stem's requirement that the statement describe how the relay agent inserts the circuit ID and remote ID into forwarded DHCPv4 requests.

Why this answer

Option B is correct because on Cisco IOS relay agents, the 'ip dhcp relay information option' command enables the relay agent to insert the DHCPv4 option 82 (Relay Agent Information option) into client messages before forwarding them to the server. Option C is correct because the DHCP server can inspect the sub-options of option 82, such as the Circuit ID and Remote ID, and use them to select an address from a specific pool, enabling location-based address assignment. Option A is incorrect because option 82 is inserted by the relay agent, not by the DHCP client, which typically has no knowledge of the relay agent information.

Option D is incorrect because option 82 is defined for DHCPv4 (RFC 3046); DHCPv6 uses a different relay mechanism with Relay-Forward/Relay-Reply messages and Interface-ID options. Option E is incorrect because 'ip dhcp relay information trusted' is used on the relay agent or a switch port to accept and forward option 82 from untrusted sources without dropping it, not to insert option 82.

Exam trap

Cisco often tests the distinction between the command that inserts option 82 ('ip dhcp relay information option') and the command that trusts incoming option 82 ('ip dhcp relay information trusted'), leading candidates to confuse the two.

1207
Multi-Selectmedium

Which TWO configuration steps are required to enable MPLS on a Cisco IOS-XE router using LDP? (Choose TWO.)

Select 2 answers
A.Configure 'mpls ip' on the desired interfaces.
B.Configure 'mpls label protocol ldp' globally.
C.Configure a routing protocol (e.g., OSPF) to provide IGP reachability between LSRs.
D.Configure 'mpls forwarding-table' to allocate labels.
E.Configure 'mpls ldp router-id' to set the LDP router ID.
AnswersA, C

Enabling 'mpls ip' on an interface activates LDP on that link, triggering label exchange with the adjacent LSR. This is the interface-level step that actually turns on MPLS forwarding and LDP advertisement, satisfying the requirement to enable MPLS on the router's participating links.

Why this answer

To enable MPLS with LDP, you must configure 'mpls ip' on the interface and also enable a routing protocol (like OSPF or IS-IS) to provide reachability. The 'mpls label protocol ldp' command is optional as LDP is the default, and 'mpls ldp router-id' is optional. 'mpls forwarding-table' is not a configuration command.

1208
MCQmedium

A network engineer runs the following command to troubleshoot an EIGRP issue: R1# show ip eigrp topology 10.1.1.0/24 detail IP-EIGRP (AS 100): Topology entry for 10.1.1.0/24 State: Passive, Query origin flag: 1, 1 Successor(s), FD is 131072 Routing Descriptor Blocks: 10.1.2.2 (GigabitEthernet0/0), from 10.1.2.2, Send flag: 0x0 Composite metric: (131072/130816), Route is Internal Vector metric: Minimum bandwidth is 10000 Kbit Total delay is 100 microseconds Reliability is 255/255 Load is 1/255 Minimum MTU is 1500 Hop count is 1 Originating router: 10.1.2.2 External data: Not advertised Protocol: EIGRP Route tag: 0 Extended community: None What does this output indicate?

A.The route is an external EIGRP route redistributed from another protocol.
B.The route is learned from a single neighbor and is in a stable state.
C.The route has multiple successors and is load-balanced.
D.The route is in Active state, meaning a query is in progress.
AnswerB

The "Passive" state confirms no EIGRP queries are outstanding, so the route is stable. A single Routing Descriptor Block with one Successor, reachable via 10.1.2.2 on GigabitEthernet0/0, shows the prefix is learned from just one neighbour, satisfying both the stability and single-neighbour conditions.

Why this answer

The output shows 'State: Passive', '1 Successor(s)', and 'FD is 131072' with a single routing descriptor block, indicating the route is stable and learned from one neighbor. 'Passive' in EIGRP means the route is not undergoing recomputation (not in Active state), and the presence of one successor means no load balancing. The route is internal (not redistributed), so it is a stable, single-path EIGRP route.

Exam trap

300-410 often tests the misconception that 'Passive' means the route is down or inactive — candidates must remember that in EIGRP, Passive means stable and Active means recomputing.

How to eliminate wrong answers

Option A is wrong because the output explicitly states 'Route is Internal' and 'External data: Not advertised', which means the route originated within the EIGRP AS and was not redistributed from another protocol. Option C is wrong because the output shows '1 Successor(s)' — load balancing requires multiple successors with equal feasible distance, which is not the case here. Option D is wrong because the state is 'Passive', not 'Active'; Active state would indicate a query is in progress and the route is being recomputed.

1209
Multi-Selecthard

Which THREE are valid syslog severity levels defined in RFC 5424? (Choose THREE.)

Select 3 answers
A.Emergency (0)
B.Fatal (1)
C.Warning (4)
D.Trace (8)
E.Informational (6)
AnswersA, C, E

RFC 5424 defines eight severity levels numbered 0 to 7. Emergency, value 0, is the highest severity, indicating the system is unusable. It is a valid level alongside Alert (1), Critical (2), Error (3), Warning (4), Notice (5), Informational (6) and Debug (7).

Why this answer

RFC 5424 defines eight syslog severity levels numbered 0 through 7, and Emergency (0) is the highest-severity level, indicating the system is unusable, so option A is correct. Warning (4) is also a defined RFC 5424 severity, representing a condition that should be addressed but is not immediately critical, making option C correct. Informational (6) is likewise a valid RFC 5424 severity used for normal operational messages that require no action, so option E is correct.

Option B is incorrect because the level numbered 1 is Alert, not Fatal, and Fatal is not an RFC 5424 severity name. Option D is incorrect because the highest defined severity number is 7 (Debug), so Trace (8) does not exist in RFC 5424.

Exam trap

The trap is confusing syslog severity names with logging levels from other frameworks — candidates pick 'Fatal' or 'Trace' because those names appear in Python, Java, or other logging systems, but RFC 5424 uses Alert and Debug instead.

1210
MCQmedium

What is the default export interval for NetFlow data when using the 'flow exporter' with UDP as the transport protocol?

A.Every 60 seconds
B.Every 30 seconds
C.Exports are triggered by flow aging or cache fullness, not a fixed interval.
D.Every 10 seconds
AnswerC

NetFlow v9 and IPFIX export on flow expiry events, not a timer: the cache ages out active flows after inactivity, or exports early when the cache fills. This satisfies the stem's UDP transport scenario, where no periodic interval governs transmission.

Why this answer

The default export interval is based on flow cache timeout; there is no fixed interval—exports occur when flows age out or cache is full.

1211
MCQmedium

A network engineer runs the following command on Router R1: R1# show mpls l2transport vc 100 detail Local interface: Gi0/0/0 up, line protocol up Destination: 10.0.0.2, VC ID: 100, VC status: down Last error: No remote LDP session Based on this output, what is the most likely cause of the VC being down?

A.The local interface Gi0/0/0 is administratively down.
B.The remote router 10.0.0.2 is not reachable via IP.
C.The LDP session between the routers is not established.
D.The VC ID 100 is mismatched on the remote router.
AnswerC

The "No remote LDP session" error directly indicates that the targeted LDP session carrying the VC label binding has not formed between the PE routers. AToM pseudowires require a targeted LDP session to exchange VC labels, so without it the VC remains down regardless of interface state.

Why this answer

The output explicitly states 'Last error: No remote LDP session,' which means the local router cannot establish an LDP session with the remote PE (10.0.0.2). In AToM (Any Transport over MPLS) / L2VPN pseudowire setups, the VC status depends on an operational LDP session between the two PEs to exchange VC labels. Without that LDP session, the VC cannot come up regardless of interface or VC ID configuration.

Exam trap

300-410 often tests whether candidates can read the 'Last error' field literally — the trap is picking 'IP unreachable' because LDP depends on IP, but the output names the LDP session itself as the missing component.

How to eliminate wrong answers

Option A is wrong because the output shows 'Local interface: Gi0/0/0 up, line protocol up' — the interface is operational, so it is not administratively down. Option B is wrong because while IP reachability is a prerequisite for LDP, the output specifically identifies the missing LDP session as the last error; IP reachability alone does not guarantee LDP is running or configured. Option D is wrong because a VC ID mismatch would produce a different error (e.g., 'VC ID mismatch' or 'remote VC ID mismatch'), not 'No remote LDP session' — the LDP session must be up before VC ID negotiation can even occur.

1212
MCQmedium

Which BFD packet type is used for initial session establishment and carries the discriminator values?

A.BFD Echo packets
B.BFD Control packets
C.BFD Poll packets
D.BFD Hello packets
AnswerB

BFD Control packets carry the My Discriminator and Your Discriminator fields, which identify each session endpoint during the handshake. Echo packets lack these fields, so only Control packets can establish the session and bind the discriminators between the two routers.

Why this answer

BFD Control packets are used for session establishment, carrying local and remote discriminator values, and are sent periodically to maintain the session.

1213
MCQhard

An engineer redistributes OSPF routes into EIGRP. The OSPF routes have a metric of 20. After redistribution, the EIGRP topology table shows the routes but they are not installed in the routing table. The 'show ip eigrp topology' shows the route in active state. Which is the most likely explanation?

A.The 'default-metric' command was not configured, so the routes are redistributed with an infinite metric.
B.The EIGRP neighbor is stuck-in-active because a query was sent but no reply was received due to a unidirectional link.
C.The OSPF routes are external type 2, which are not redistributed by default.
D.The 'route-map' used for redistribution has a 'match ip address' that does not match the OSPF routes.
AnswerB

A route stuck in active state means EIGRP sent queries but received no reply within the active timer. A unidirectional link prevents replies from returning, so the neighbour never responds, leaving the route unresolved and excluded from the routing table.

Why this answer

A route stuck in EIGRP active state means the router sent a query for that destination and is waiting for a reply; if a reply never arrives (often due to a unidirectional link or broken neighbor adjacency), the route remains active and is never installed in the routing table. The redistribution itself succeeded — the route is in the topology table — so the problem is with query/reply propagation, not with metrics or route-maps.

Exam trap

300-410 often tests the distinction between 'route not redistributed' (missing default-metric or route-map filter) and 'route redistributed but stuck active' — candidates who see 'not in routing table' and jump to redistribution configuration miss the active-state clue that points to a query/reply failure.

How to eliminate wrong answers

Option A is wrong because if default-metric were missing, the routes would be redistributed with an infinite metric and would not appear in the topology table as feasible successors at all; they would be rejected at redistribution, not stuck active. Option C is wrong because OSPF external type 2 routes are redistributed by default into EIGRP just like any other OSPF route; there is no automatic exclusion of E2 routes. Option D is wrong because if a route-map filtered the routes, they would not appear in the EIGRP topology table at all — the fact that they are present but active rules out a redistribution filter problem.

1214
MCQmedium

A network engineer runs the following command to troubleshoot a Control Plane Policing (CoPP) issue: R1# show ip access-lists CoPP-ACL Extended IP access list CoPP-ACL 10 permit tcp host 10.1.1.1 any eq bgp (100 matches) 20 permit udp any any eq 67 (50 matches) 30 permit icmp any any echo (200 matches) 40 deny ip any any (500 matches) What does this output indicate?

A.The ACL is blocking all BGP traffic from 10.1.1.1.
B.The ACL is permitting DHCP and ICMP echo traffic, but dropping all other traffic.
C.The ACL is applied to the control plane interface and is dropping all traffic.
D.The ACL has a misconfiguration because the deny statement should be at the top.
AnswerB

Lines 20 and 30 permit DHCP and ICMP echo, while line 40 denies everything else, which is typical for CoPP to protect the control plane.

Why this answer

The ACL shows that lines 10, 20, and 30 have match counts, indicating that BGP from 10.1.1.1, DHCP (UDP port 67), and ICMP echo are being permitted. Line 40 is a deny all with 500 matches, meaning all other traffic is being dropped. This confirms that the ACL is permitting only the specified traffic (DHCP and ICMP echo) while dropping everything else, making option B correct.

Exam trap

Cisco often tests the ability to interpret ACL match counts to determine actual traffic behavior, leading candidates to mistakenly think a deny all at the end means all traffic is dropped, when in fact the permit lines above it are allowing specific traffic.

How to eliminate wrong answers

Option A is wrong because the ACL line 10 shows 100 matches for permit tcp host 10.1.1.1 any eq bgp, meaning BGP traffic from 10.1.1.1 is being permitted, not blocked. Option C is wrong because the ACL is not dropping all traffic; it permits DHCP, ICMP echo, and BGP from 10.1.1.1, as shown by the match counts on permit lines. Option D is wrong because there is no misconfiguration; the deny statement at the bottom is standard for an ACL that permits specific traffic and denies everything else, and the order of entries is correct for CoPP where you want to permit desired control plane traffic first.

1215
Multi-Selectmedium

A network engineer is deploying a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP, and wants spokes to reach other spokes directly without routing through the hub for every packet. The engineer must configure the hub so that it advertises a default route to the spokes while still allowing spoke-to-spoke shortcut tunnels. (Choose two.)

Select 2 answers
A.Disable split horizon on the hub's mGRE interface to allow spoke routes to be re-advertised.
B.Enable NHRP redirect on the hub so it can inform spokes of a better path to the destination.
C.Configure the hub with a default route pointing to the provider and redistribute it into the routing protocol with a metric that spokes accept.
D.Configure the spokes with a static route for every remote spoke subnet pointing at the hub.
E.Configure NHRP shortcut on each spoke to allow it to install and use a direct route learned from the redirect.
AnswersB, E

NHRP redirect is a Phase 3 feature that lets the hub inspect traffic arriving on its mGRE interface and send a redirect message to the originating spoke when a shorter path exists. The spoke then resolves the destination NBMA address and builds a direct tunnel to the target spoke. Without redirect, spokes keep sending all inter-spoke traffic through the hub, so this is required for shortcut behavior.

Why this answer

DMVPN Phase 3 achieves spoke-to-spoke shortcuts through two cooperating NHRP features. The hub enables NHRP redirect so it can tell a spoke that a better path exists, and each spoke enables NHRP shortcut so it can resolve the destination and install a temporary direct route. Together these allow direct tunnels while the hub still advertises a summarizable default route to all spokes.

Exam trap

The trap here is thinking that distributing a default route or adjusting split horizon enables shortcuts, when Phase 3 specifically depends on NHRP redirect on the hub and NHRP shortcut on the spokes.

1216
MCQmedium

In a 6to4 tunnel, how is the tunnel destination address determined?

A.It is manually configured.
B.It is derived from the IPv6 destination address using the 2002::/16 prefix.
C.It is obtained via DNS.
D.It is the same as the tunnel source.
AnswerB

6to4 embeds the IPv4 tunnel endpoint inside the IPv6 address itself: the 2002::/16 prefix is followed by the 32-bit IPv4 address. The router extracts those bits from the packet's IPv6 destination to determine the tunnel endpoint, requiring no explicit destination configuration.

Why this answer

In a 6to4 tunnel, the tunnel destination address is automatically derived from the IPv6 destination address by extracting the IPv4 address embedded in the 2002::/16 prefix. Specifically, the first 16 bits of the IPv6 destination are 2002, and the next 32 bits represent the IPv4 address of the remote 6to4 router. This allows the tunnel to be dynamically established without manual configuration of each destination.

Exam trap

Cisco often tests the distinction between automatic 6to4 tunnels and manually configured tunnels, where candidates mistakenly think all tunnels require manual destination configuration, but 6to4 uniquely derives it from the IPv6 address.

How to eliminate wrong answers

Option A is wrong because 6to4 is designed as an automatic tunneling mechanism; manually configuring the tunnel destination would defeat its purpose and is characteristic of manually configured tunnels (e.g., IPv6IP tunnels). Option C is wrong because DNS is not used to resolve the tunnel destination; the IPv4 address is directly embedded in the IPv6 prefix 2002::/16, not obtained via name resolution. Option D is wrong because the tunnel destination is not the same as the tunnel source; the source is the local IPv4 address, while the destination is derived from the remote IPv6 address's embedded IPv4 address.

1217
MCQmedium

An engineer is troubleshooting a DHCPv4 issue where a Cisco router acting as a DHCP client on interface Gi0/0 is not receiving an IP address from an ISP modem. The router has 'ip address dhcp' on the interface. The engineer sees that the interface is up/up, but no IP address is assigned. Debug shows that the router is sending DHCP DISCOVER messages but receives no OFFER. The ISP modem is known to work with other devices. What is the most likely cause?

A.The router needs the 'ip dhcp client broadcast-flag' command.
B.The router is sending the client identifier as the MAC address in a non-standard format; the modem expects the client identifier to be the MAC address only.
C.The router's interface is in a VRF, and the DHCP client needs VRF awareness.
D.The ISP modem requires DHCP Option 82 to be present.
AnswerB

Correct because Cisco routers by default send the client identifier as the MAC address with a type byte (0x01), while some modems expect only the MAC address; configuring 'ip dhcp client client-id' with the correct format resolves the issue.

Why this answer

The router is sending DHCP DISCOVER messages but receiving no OFFER, indicating the ISP modem is ignoring the requests. By default, Cisco routers send the client identifier in DHCP packets as a concatenation of the hardware type (1 for Ethernet) and the MAC address (e.g., '0100.1122.3344'). Many ISP modems expect the client identifier to be just the MAC address (without the hardware type prefix), or they may not use client identifier matching at all.

The 'ip dhcp client client-id' command can be used to override this behavior, making the router send only the MAC address as the client identifier, which resolves the incompatibility.

Exam trap

Cisco often tests the subtle default behavior of the DHCP client identifier format, where candidates assume the MAC address alone is sent, but the router prepends a hardware type byte, causing incompatibility with non-Cisco servers.

How to eliminate wrong answers

Option A is wrong because the 'ip dhcp client broadcast-flag' command forces the DHCP server to send replies as broadcasts, but the issue is that no OFFER is received at all, not that the reply is unicast and not processed. Option C is wrong because if the interface were in a VRF, the DHCP client would need VRF awareness (via 'ip vrf forwarding' under the interface), but the debug shows DISCOVER messages are being sent, and the interface is up/up, so VRF misconfiguration would typically prevent sending or receiving DHCP messages, not cause the modem to ignore valid DISCOVERs. Option D is wrong because DHCP Option 82 (Relay Agent Information) is typically inserted by a DHCP relay agent, not by a DHCP client; the ISP modem as a DHCP server does not require Option 82 from a directly connected client, and the absence of Option 82 would not cause the server to ignore DISCOVER messages.

1218
Multi-Selecthard

An engineer is troubleshooting an MPLS LDP session that fails to establish between two directly connected routers. Which TWO commands can be used to verify LDP operation? (Choose TWO.)

Select 2 answers
A.show mpls ldp neighbor
B.show mpls ldp discovery
C.show mpls ldp bindings
D.show mpls ldp session
E.show ip route
AnswersA, B

Correct. This command displays LDP neighbors and the session state (e.g., OPERATIONAL).

Why this answer

LDP session establishment can be verified using 'show mpls ldp neighbor' to see the state of the session and 'show mpls ldp discovery' to see if LDP hello packets are being exchanged. Option A is correct: 'show mpls ldp neighbor' shows the LDP session state (e.g., OPERATIONAL). Option B is correct: 'show mpls ldp discovery' shows LDP hello adjacency details.

Option C is false: 'show mpls ldp bindings' shows label bindings, not session state. Option D is false: there is no 'show mpls ldp session' command; the correct command is 'show mpls ldp neighbor'. Option E is false: 'show ip route' does not show LDP information.

1219
MCQhard

A switch is configured with RSPAN to monitor traffic from VLAN 50 to a remote switch via VLAN 200. The source switch has: monitor session 1 source vlan 50 rx monitor session 1 destination remote vlan 200. The remote switch has: monitor session 2 source remote vlan 200 monitor session 2 destination interface Gi0/2. The intermediate switches have VLAN 200 configured with 'remote-span'. The network uses VTP transparent mode. The analyzer connected to Gi0/2 sees intermittent traffic. The RSPAN VLAN 200 is also used as a native VLAN on some trunk ports. What is the likely cause of intermittent traffic?

A.The RSPAN VLAN 200 is also the native VLAN on some trunks, causing the mirrored frames to be sent untagged and possibly dropped.
B.VTP transparent mode prevents RSPAN from working correctly.
C.The source VLAN 50 is not allowed on the trunk ports.
D.The monitor session 2 is missing the 'no shutdown' command.
AnswerA

RSPAN traffic must remain tagged with the dedicated RSPAN VLAN across every trunk; using VLAN 200 as a native VLAN strips that tag on those links, so intermediate switches cannot identify the frames as RSPAN and drop them, producing the intermittent capture. The RSPAN VLAN must be reserved and never used as a native VLAN.

Why this answer

When the RSPAN VLAN is also configured as the native VLAN on a trunk, mirrored frames are sent untagged on that trunk. Intermediate switches may treat untagged frames as belonging to the native VLAN rather than the RSPAN VLAN, causing them to be forwarded incorrectly or dropped, resulting in intermittent traffic at the destination.

Exam trap

300-410 often tests the interaction between RSPAN and native VLAN configuration — candidates focus on VTP mode or trunk allowed VLANs but miss that using the RSPAN VLAN as a native VLAN breaks tagging and causes intermittent mirroring.

How to eliminate wrong answers

Option B is wrong because VTP transparent mode does not prevent RSPAN from working — RSPAN VLANs must be manually configured in transparent mode, but that is a configuration requirement, not a cause of intermittent traffic. Option C is wrong because if VLAN 50 were not allowed on the trunks, no traffic would be mirrored at all, not intermittent traffic. Option D is wrong because monitor sessions do not have a 'no shutdown' command; that is an interface-level command and is not applicable here.

1220
MCQmedium

A network administrator is configuring a Cisco IOS router to support MPLS Layer 3 VPNs. The router is a PE device that must exchange VPNv4 routes with other PE routers. The administrator has enabled MPLS LDP on the core-facing interfaces and configured BGP with the address-family vpnv4. Which additional configuration is required on the PE router to properly forward MPLS VPN traffic?

A.Configure BGP route reflectors to distribute VPNv4 routes.
B.Configure a VRF on the PE router and assign the customer-facing interface to it.
C.Enable MPLS TE on all core interfaces to establish traffic-engineered tunnels.
D.Enable OSPF as the IGP and configure it to carry MPLS labels.
AnswerB

In an MPLS Layer 3 VPN, the PE router must have a VRF configured for each customer, and the customer-facing interface must be assigned to that VRF. This separates customer routing tables and allows the PE to advertise customer routes into MP-BGP with the appropriate route target. Without a VRF, the PE cannot distinguish customer traffic or apply the correct label stack, so VPN traffic would not be forwarded correctly.

Why this answer

MPLS L3 VPN requires the PE router to have VRFs configured for each customer, with customer interfaces assigned to those VRFs. This enables the PE to maintain separate routing tables, advertise routes via MP-BGP with route targets, and impose the correct label stack for VPN traffic. Without VRFs, the PE cannot differentiate customer traffic or forward it properly.

Exam trap

The trap here is focusing on advanced features like MPLS TE or route reflectors, while overlooking the fundamental requirement of VRF configuration on the PE router for MPLS L3 VPN.

1221
Multi-Selecthard

A network engineer is implementing a DMVPN Phase 3 network with NHRP and mGRE on the hub. The design requires that spoke-to-spoke traffic be able to bypass the hub after resolution, and that the hub not be required to advertise specific routes to the spokes. Which two configuration elements are required to achieve shortcut switching and default-route-only behavior on the spokes? (Choose two.)

Select 2 answers
A.Disable NHRP shortcut on the spokes so they always forward through the hub first.
B.Configure the hub to summarize or advertise a default route to the spokes, and configure the spokes to use the hub as their default gateway.
C.Enable NHRP redirect on the hub so it can inform spokes when a better path to the destination exists.
D.Configure the spokes with a static NHRP map for every other spoke in the topology.
E.Configure the hub with a route map that tags the default route so spokes prefer the hub path over shortcuts.
AnswersB, C

Phase 3 shortcut switching relies on the spokes having a default route pointing to the hub so they forward all unknown traffic to the hub initially. The hub advertises a default route rather than specific prefixes, which keeps the spoke routing tables small. When a spoke needs to reach another spoke, NHRP resolves the destination and installs a shortcut route, allowing traffic to bypass the hub while the default route remains for everything else.

Why this answer

DMVPN Phase 3 combines a hub-advertised default route with NHRP redirect and shortcut switching. The spokes point their default route at the hub, so unknown destinations initially go through the hub. When the hub sees traffic that could take a better path, NHRP redirect tells the source spoke to resolve the destination, and NHRP shortcut installs a direct route.

This yields small spoke routing tables plus optimized spoke-to-spoke paths.

Exam trap

The trap here is thinking Phase 3 shortcut switching works without NHRP redirect, when redirect is what prompts the spoke to resolve a direct path.

1222
MCQeasy

A network administrator is configuring a Cisco IOS router to provide first-hop redundancy for a group of hosts on VLAN 10. The design requires that the virtual IP address be 10.1.10.1 and that the router with the highest priority become the active gateway. The administrator has configured the interface with 'standby 10 ip 10.1.10.1' and 'standby 10 priority 150'. Which additional command is required to ensure that the router preempts and becomes the active gateway if it reboots?

A.standby 10 authentication md5 key-string cisco
B.standby 10 timers 1 3
C.standby 10 preempt
D.standby 10 track 1 decrement 20
AnswerC

The 'standby 10 preempt' command enables the router to take over as the active gateway if it has a higher priority than the current active router. Without preemption, a router that reboots and comes back online will not become active even if its priority is higher; it will remain in standby. This command ensures the intended active router assumes the role.

Why this answer

In HSRP, preemption must be explicitly enabled with the 'standby preempt' command. Without it, a router with a higher priority that comes online after the active router is already elected will not become active. The priority alone does not trigger preemption.

Therefore, to ensure the router becomes active after a reboot, the preempt command is necessary.

Exam trap

The trap here is assuming that a higher priority automatically causes a router to take over as active, when in fact preemption must be configured.

1223
MCQmedium

A network engineer runs the following command to verify DHCPv4 server statistics on router R1: R1# show ip dhcp server statistics Output: Memory usage: 12345 Address pools: 2 Database agents: 0 Automatic bindings: 150 Manual bindings: 5 Expired bindings: 10 Malformed messages: 0 Message Received BOOTREQUEST 0 DHCPDISCOVER 200 DHCPREQUEST 180 DHCPDECLINE 2 DHCPRELEASE 5 DHCPINFORM 10 What does this output indicate?

A.The DHCP server has 150 active automatic bindings and 5 manual bindings.
B.The DHCP server has received 200 DHCPREQUEST messages.
C.The DHCP server has 10 malformed messages, indicating a configuration issue.
D.The DHCP server has 2 database agents configured.
AnswerA

The statistics counters confirm the binding state directly: 150 automatic bindings show addresses leased dynamically from the pools, while 5 manual bindings reflect statically pre-assigned host entries. Both figures match the output, satisfying the question's requirement to interpret the binding counts.

Why this answer

The 'Automatic bindings: 150' and 'Manual bindings: 5' fields directly indicate the number of active leases assigned dynamically (via DHCP) and statically (via manual configuration), respectively. These represent the current active bindings on the DHCP server, with no other interpretation needed.

Exam trap

Cisco often tests the ability to distinguish between message types in the 'Received' table, specifically confusing DHCPDISCOVER with DHCPREQUEST counts, as candidates may misread the output under time pressure.

How to eliminate wrong answers

Option B is wrong because the output shows 200 DHCPDISCOVER messages received, not 200 DHCPREQUEST messages; DHCPREQUEST messages are listed as 180. Option C is wrong because the 'Malformed messages: 0' field indicates no malformed messages were received, so there is no indication of a configuration issue from that value. Option D is wrong because the 'Database agents: 0' field explicitly shows that zero database agents are configured, not two.

1224
Drag & Drophard

Drag and drop the steps to troubleshoot an IPsec site-to-site VPN adjacency failure into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Start by verifying basic IP connectivity between peers, then check that the crypto isakmp policy and IKE proposals match. Next, confirm tunnel interface configuration and ACLs, then inspect IKE and IPsec SA states. Finally, enable debugs to isolate the specific failure.

1225
MCQhard

A network engineer is troubleshooting a VRF-Lite deployment where two routers are connected via a trunk link. Each router has two VRFs (VRF_A and VRF_B). The engineer configures subinterfaces on the trunk link, assigning each subinterface to a different VRF. However, traffic between the two routers for VRF_A is not working. The 'show vrf' command shows the VRFs are active. What is the most likely issue?

A.The subinterface on Router1 is configured with 'encapsulation dot1q 10', but the subinterface on Router2 is configured with 'encapsulation dot1q 20'.
B.The 'ip vrf forwarding VRF_A' command is missing on the main interface.
C.The 'no ip routing' command is configured globally.
D.The 'mtu' command is set differently on the two subinterfaces.
AnswerA

VRF-Lite over a trunk requires matching 802.1Q VLAN tags on both ends of each subinterface pair. Mismatched encapsulation dot1q values place the two subinterfaces in different broadcast domains, so VRF_A traffic never reaches its peer despite both VRFs showing active.

Why this answer

For VRF-Lite over a trunk, the subinterfaces on both ends of the link must use the same 802.1Q VLAN ID for the same VRF. If Router1 uses dot1q 10 for VRF_A and Router2 uses dot1q 20, the frames are tagged with different VLANs and each router will drop the other's traffic because the VLANs do not match. This is the most likely cause of the VRF_A traffic failure.

Exam trap

The trap here is that candidates see 'show vrf' output showing active VRFs and assume the VRF configuration is correct, overlooking the Layer 2 VLAN mismatch on the trunk subinterfaces.

How to eliminate wrong answers

Option B is wrong because 'ip vrf forwarding' is applied to subinterfaces, not the main interface, in a VRF-Lite trunk configuration; applying it to the main interface would actually break the trunk. Option C is wrong because 'no ip routing' would disable all routing on the router, affecting all VRFs and not just VRF_A. Option D is wrong because an MTU mismatch would cause fragmentation or dropped large packets, but it would not completely prevent traffic; it is a less likely cause than a VLAN mismatch.

1226
MCQhard

A network engineer is troubleshooting MPLS traffic where packets are being forwarded without a label (IP forwarding) instead of being label-switched. The engineer runs show mpls forwarding-table and sees that the FEC for the destination prefix has a valid label. However, show ip cef shows that the outgoing interface is not MPLS-enabled. What is the most likely cause?

A.The outgoing interface is missing the mpls ip command.
B.The CEF is disabled globally.
C.The mpls label protocol ldp command is missing on the interface.
D.The interface is a loopback interface.
AnswerA

MPLS forwarding requires the outgoing interface to be MPLS-enabled. Without the mpls ip command, Cisco Express Forwarding shows that interface as non-MPLS, so labelled packets fall back to IP forwarding despite a valid label existing in the forwarding table.

Why this answer

For MPLS label switching to occur on an interface, the interface must have MPLS enabled with the 'mpls ip' command (or 'mpls ldp' depending on platform). If 'show ip cef' shows the outgoing interface is not MPLS-enabled, the router falls back to IP forwarding even though a label exists in the LFIB. Enabling MPLS on the interface restores label imposition and forwarding.

Exam trap

The trap is assuming that a valid label in the LFIB is sufficient for label switching — candidates overlook that the outgoing interface must also be MPLS-enabled for the data plane to forward labeled packets.

How to eliminate wrong answers

Option B is wrong because if CEF were disabled globally, the router would not have a CEF table at all and 'show ip cef' would error out, not show a non-MPLS interface. Option C is wrong because 'mpls label protocol ldp' configures the label distribution protocol on an already MPLS-enabled interface; without 'mpls ip' first, LDP does not run. Option D is wrong because loopback interfaces are not used for MPLS forwarding of transit traffic; the issue is the data-plane interface lacking MPLS.

1227
MCQmedium

A network engineer runs the following command to verify BFD with MPLS LDP: R1# show mpls ldp neighbor 10.6.6.2 detail Peer LDP Ident: 10.6.6.2:0, Local LDP Ident: 10.6.6.1:0 TCP connection: 10.6.6.2.646 - 10.6.6.1.53456 State: Oper; Msgs sent/rcvd: 100/100; Downstream Up time: 00:10:00 LDP discovery sources: GigabitEthernet0/2, hello interval: 5 s, hello hold: 15 s Addresses bound to peer LDP ident: 10.6.6.2 10.7.7.2 BFD enabled, BFD state: UP What does this output indicate?

A.BFD is enabled for LDP, allowing faster LDP session failure detection.
B.BFD is disabled for this LDP session.
C.LDP is using BFD only for IPv6.
D.BFD state is DOWN, so LDP uses its own hello timers.
AnswerA

The line 'BFD enabled, BFD state: UP' confirms Bidirectional Forwarding Detection is bound to this LDP session, so sub-second failure detection replaces reliance on TCP or hello timers. LDP hellos only detect peer loss slowly; BFD provides rapid link failure notification for the MPLS forwarding path.

Why this answer

The output shows 'BFD enabled, BFD state: UP', indicating that BFD is operational for this LDP session, which allows faster failure detection than LDP hello timers alone.

Exam trap

300-410 often tests the confusion between LDP hello timers and BFD, leading candidates to think BFD is disabled if not explicitly configured in the output.

How to eliminate wrong answers

Option B is wrong because the output explicitly states BFD is enabled and UP. Option C is wrong because there is no indication of IPv6; the addresses shown are IPv4. Option D is wrong because BFD state is UP, not DOWN.

1228
MCQeasy

What is the default administrative distance for a route learned via the Routing Information Protocol (RIP)?

A.100
B.110
C.120
D.130
AnswerC

RIP's default administrative distance is 120, making it less trusted than static routes, eBGP, EIGRP and OSPF. Cisco routers therefore prefer those sources over RIP when multiple protocols advertise the same prefix, which is the value tested here.

Why this answer

RIP routes have a default administrative distance of 120.

1229
MCQhard

An engineer configures OSPF on two routers connected via a serial link. Both routers show the neighbor state as EXSTART/EXSTART, and no LSAs are exchanged. The engineer verifies that the OSPF process IDs are the same, areas match, and authentication is correct. Which is the most likely explanation?

A.MTU mismatch between the two routers
B.OSPF network type mismatch (e.g., point-to-point vs broadcast)
C.OSPF hello interval mismatch
D.OSPF dead interval mismatch
AnswerA

OSPF routers exchange DBD packets in ExStart to elect master/slave and agree on the initial sequence number. An MTU mismatch prevents the DBD exchange from completing, leaving both neighbours stuck in ExStart with no LSAs exchanged, despite matching areas and authentication.

Why this answer

OSPF neighbors stuck in EXSTART/EXSTART indicate a failure during database description (DBD) packet exchange, most commonly caused by an MTU mismatch on the interface. The master/slave negotiation cannot complete because the routers cannot agree on the initial DBD sequence, often due to differing MTU values. The fix is to match MTU on both interfaces or use 'ip ospf mtu-ignore'.

Exam trap

The trap is picking hello/dead interval mismatches because they are common OSPF issues; however, those cause failures earlier in the adjacency process, while EXSTART specifically points to MTU or DBD exchange problems.

How to eliminate wrong answers

Option B is wrong because a network type mismatch (point-to-point vs broadcast) would typically prevent neighbors from forming at all (stuck in INIT or not forming), not specifically EXSTART. Option C is wrong because a hello interval mismatch would prevent the neighbor relationship from progressing past INIT — hellos would not be accepted. Option D is wrong because a dead interval mismatch would cause the neighbor to be torn down after the dead timer expires, not stuck in EXSTART.

1230
Multi-Selectmedium

A network engineer is configuring a DMVPN Phase 3 network with mGRE and NHRP. The hub router must be able to dynamically learn spoke routes and advertise them to other spokes. Which two statements are true regarding the configuration of the hub to support spoke-to-spoke communication in DMVPN Phase 3? (Choose two.)

Select 2 answers
A.The hub must have 'ip nhrp shortcut' configured on its tunnel interface.
B.The hub must have a route to all spoke networks, either through a routing protocol or summary route.
C.The hub must have 'ip nhrp redirect' configured on its tunnel interface.
D.The hub must have 'ip nhrp network-id' configured with the same value as the spokes.
E.The hub must have 'ip nhrp map multicast dynamic' configured to support multicast traffic.
AnswersB, C

In DMVPN Phase 3, the hub still needs to know how to reach all spoke networks to provide initial connectivity and to forward traffic when a direct tunnel is not yet established. This is typically achieved by running a routing protocol on the hub and spokes, or by configuring a summary route on the hub. Without this, the hub cannot route traffic to the correct spoke, and spoke-to-spoke communication may fail.

Why this answer

In DMVPN Phase 3, the hub must be configured with 'ip nhrp redirect' to inform spokes of a better direct path, and it must have a route to all spoke networks to provide initial connectivity and forwarding. The spokes require 'ip nhrp shortcut' to act on redirects. The other options are either not specific to Phase 3 or are configured on spokes.

Exam trap

The trap here is confusing where 'ip nhrp shortcut' is configured; it belongs on the spokes, not the hub, and is essential for them to use the redirect messages.

1231
Multi-Selectmedium

Which TWO configuration steps are required to implement static NAT on a Cisco IOS router? (Choose TWO.)

Select 2 answers
A.Configure ip nat inside source static <inside-local> <inside-global> in global configuration mode.
B.Apply the ip nat inside command on the interface facing the internal network.
C.Apply the ip nat outside command on the interface facing the internal network.
D.Configure an access list to match the inside local addresses for translation.
E.Enable the ip nat service command globally to activate NAT.
AnswersA, B

Static NAT requires the global-configuration mapping that pairs the inside local address with its inside global address. This command creates that fixed one-to-one entry, which is the defining configuration element of static NAT on Cisco IOS.

Why this answer

Option A is correct because static NAT is created with the global configuration command ip nat inside source static <inside-local> <inside-global>, which permanently maps one inside local address to one inside global address. Option B is correct because the router must know which interface is the internal side, and that is done by entering the interface configuration and issuing the ip nat inside command on the interface facing the internal network. Option C is wrong because ip nat outside must be applied to the external-facing interface, not the internal one.

Option D is wrong because an access list is used for dynamic NAT or PAT with the pool/overload syntax, not for a static one-to-one mapping. Option E is wrong because there is no global ip nat service command required to activate NAT on Cisco IOS; NAT is enabled by the inside/outside interface designations and the translation statements themselves.

Exam trap

Cisco often tests the misconception that static NAT requires an access list (like dynamic NAT) or that a global 'ip nat service' command must be enabled, when in fact static NAT only needs the static mapping and the correct interface designations (inside/outside).

1232
MCQmedium

A network engineer runs the following command to troubleshoot a DMVPN spoke not registering with the hub: R2# debug nhrp NHRP: Send Registration Request via Tunnel0 10.0.0.2, target 10.0.0.1 NHRP: Receive Registration Reply via Tunnel0 10.0.0.1, src 10.0.0.1, dst 10.0.0.2 NHRP: Registration successful for 10.0.0.2/32 via Tunnel0 What does this output indicate?

A.The spoke is unable to reach the hub; the registration request is being sent but no reply is received.
B.The spoke has successfully registered its tunnel IP 10.0.0.2/32 with the hub at 10.0.0.1.
C.The spoke is sending a registration request to 10.0.0.1 but the hub is not responding, causing a timeout.
D.The spoke is attempting to register with the wrong hub IP address.
AnswerB

The debug output shows the spoke sending a Registration Request to the hub at 10.0.0.1, receiving a Registration Reply, and confirming "Registration successful for 10.0.0.2/32". This directly satisfies the stem's constraint: the spoke's tunnel IP is now registered in the hub's NHRP cache, resolving the registration failure.

Why this answer

The debug output shows the spoke sent a Registration Request to the hub at 10.0.0.1 and received a Registration Reply, followed by 'Registration successful for 10.0.0.2/32 via Tunnel0.' This confirms the NHRP registration completed successfully and the spoke's tunnel IP is now known to the hub. There is no timeout or failure in the output.

Exam trap

300-410 often tests whether candidates can read debug output literally — the trap is picking a 'failure' answer when the output clearly shows a successful registration reply.

How to eliminate wrong answers

Option A is wrong because the output explicitly shows a Registration Reply was received, contradicting the claim that no reply is received. Option C is wrong because the hub did respond — the 'Receive Registration Reply' line proves it, and there is no timeout message. Option D is wrong because the target 10.0.0.1 matches the hub's tunnel IP and the registration succeeded, so the hub address is correct.

1233
Multi-Selecthard

An engineer is troubleshooting BGP convergence issues. Which THREE commands can be used to verify BGP path selection and best path criteria? (Choose THREE.)

Select 3 answers
A.show ip bgp <prefix>
B.show ip route bgp
C.show ip bgp neighbors <neighbor> routes
D.show ip bgp
E.show ip bgp community <community>
AnswersA, C, D

show ip bgp <prefix> displays every path for that prefix with the attributes BGP uses for best-path selection, including weight, local preference, AS-path length, origin and MED. This satisfies the stem's requirement to verify path selection and best-path criteria.

Why this answer

Option A, `show ip bgp <prefix>`, is correct because it displays all BGP paths for a specific prefix along with the best-path marker (`>`), the locally generated marker (`*`), and the BGP attributes (weight, local preference, AS path, origin, MED) used in the best-path selection algorithm. Option C, `show ip bgp neighbors <neighbor> routes`, is correct because it lists the routes advertised by or received from a specific neighbor, letting the engineer verify which paths that neighbor is contributing to the BGP table and how they factor into path selection. Option D, `show ip bgp`, is correct because it dumps the entire BGP table with best-path indicators and attributes, which is the primary command for inspecting path selection and best-path criteria across all prefixes.

Option B, `show ip route bgp`, only shows the BGP routes already installed in the routing table (post-selection), so it does not reveal the candidate paths or the attributes used to choose the best path. Option E, `show ip bgp community <community>`, filters the BGP table by community value and is useful for community-based policy verification, but it does not directly show best-path criteria or path selection details.

1234
MCQeasy

Consider the configuration snippet: logging 192.168.1.10 vrf Mgmt-intf logging source-interface Vlan1 logging trap 6 What is the effect of the 'logging trap 6' command?

A.Only messages of severity 6 are sent to the syslog server.
B.Messages of severity 0 through 6 are sent to the syslog server.
C.Messages of severity 6 through 7 are sent to the syslog server.
D.The number 6 is invalid; only named levels are accepted.
AnswerB

The `logging trap 6` command sets the syslog severity threshold to level 6 (informational), so all messages from severity 0 (emergencies) up to and including 6 are forwarded to the server at 192.168.1.10. This satisfies the stem's requirement to determine which severities reach the syslog host.

Why this answer

The 'logging trap 6' command sets the syslog severity threshold for messages sent to remote syslog servers. Because syslog severity numbers are inverted (0 is most severe, 7 is least), specifying level 6 means all messages with severity 0 through 6 (emergencies through informational) are sent, while level 7 (debugging) messages are suppressed.

Exam trap

The trap is forgetting that syslog severity numbers are inverted — candidates who think '6 means only level 6' or '6 through 7' pick the wrong answer, when the correct interpretation is that the threshold includes all numerically lower (more severe) levels.

How to eliminate wrong answers

Option A is wrong because 'logging trap 6' is a threshold, not a filter for a single level — it includes all severities numerically less than or equal to 6. Option C is wrong because it reverses the logic: severity 6 through 7 would mean only informational and debug messages, which is the opposite of how the threshold works. Option D is wrong because Cisco IOS accepts both numeric and named severity levels in the logging trap command (e.g., 'logging trap informational' is equivalent to 'logging trap 6').

1235
MCQhard

An engineer configures OSPFv3 with a filter-list on an ABR to filter prefixes. After configuration, the routes are still being advertised. Which is the most likely explanation?

A.The filter-list only filters inter-area prefixes, not external routes.
B.The filter-list is applied to the wrong area.
C.The filter-list uses an incorrect prefix-list.
D.The OSPFv3 process needs to be restarted.
AnswerA

OSPFv3 filter-lists applied to an ABR restrict prefixes exchanged between areas, so they only affect inter-area (type 3) LSAs. External prefixes redistributed into OSPFv3 are carried in type 5 or 7 LSAs, which the filter-list does not examine, leaving them advertised unchanged.

Why this answer

OSPFv3 filter-lists applied with the 'area filter-list' command only filter inter-area (Type 3) LSAs, not external (Type 5/7) routes. If the engineer is trying to filter external prefixes redistributed into OSPFv3, the filter-list will have no effect, which explains why routes are still advertised.

Exam trap

300-410 often tests the LSA-type scope of OSPF filter-lists—candidates assume filter-list filters all routes, but it only affects inter-area (Type 3) LSAs, not external routes.

How to eliminate wrong answers

Option B is wrong because applying the filter-list to the wrong area would typically cause no filtering at all or filter the wrong inter-area prefixes, but the question states routes are still advertised—the more precise cause is the LSA type limitation. Option C is wrong because an incorrect prefix-list would usually result in either no filtering or unexpected filtering, but the scenario implies the filter-list is correctly configured yet ineffective for the route type. Option D is wrong because OSPFv3 does not require a process restart for filter-lists to take effect; they are applied dynamically.

1236
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate administrative SSH access using TACACS+ with a backup local user account. The TACACS+ server is reachable, but the engineer wants to ensure that if the TACACS+ server becomes unreachable, the router falls back to local authentication for users who are not defined on the TACACS+ server. Which AAA configuration accomplishes this?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default group tacacs+ none
C.aaa authentication login default group tacacs+ if-needed
D.aaa authentication login default group tacacs+ enable
AnswerA

The 'aaa authentication login default group tacacs+ local' command configures the default method list to try TACACS+ first, then fall back to the local username database if the TACACS+ server does not respond. This meets the requirement of using local authentication as a backup when the server is unreachable.

Why this answer

The correct configuration uses the 'group tacacs+ local' method list, which attempts TACACS+ authentication first and then falls back to the local username database if the TACACS+ server is unreachable. This ensures that administrators can still log in with locally defined credentials during a TACACS+ outage, maintaining access without compromising security.

Exam trap

The trap here is confusing the 'none' fallback method with 'local'; 'none' allows any user without authentication, while 'local' checks the local username database.

1237
MCQmedium

A network administrator is configuring a Cisco IOS router for site-to-site VPN using DMVPN Phase 3. The administrator wants to ensure that spoke-to-spoke traffic flows directly between spokes without traversing the hub, and that the hub is only used for initial registration and route resolution. Which technology must be enabled on the spokes to achieve direct spoke-to-spoke communication?

A.IPsec tunnel protection on the hub only
B.NHRP redirect on the spokes and NHRP shortcut on the hub
C.NHRP redirect on the hub and NHRP shortcut on the spokes
D.OSPF broadcast network type on all spokes
AnswerC

In DMVPN Phase 3, the hub uses NHRP redirect to inform spokes of a more optimal path, and the spokes use NHRP shortcut to install a direct route to the destination spoke. This enables direct spoke-to-spoke tunnels without traversing the hub for data traffic.

Why this answer

DMVPN Phase 3 enables direct spoke-to-spoke communication through NHRP redirect on the hub and NHRP shortcut on the spokes. The hub sends NHRP redirect messages to spokes when it detects traffic that could be sent directly, and the spokes use NHRP shortcut to resolve the destination and build a direct tunnel. This reduces latency and hub load.

Exam trap

The trap here is confusing the roles of NHRP redirect and shortcut; redirect is on the hub, shortcut is on the spokes.

1238
MCQeasy

A network engineer is configuring SSH access on a Cisco IOS router. The engineer wants to restrict SSH access to only the management subnet 192.168.1.0/24 and ensure that only SSH version 2 is used. Which set of commands accomplishes this?

A.ip ssh version 2 access-list 10 permit 192.168.1.0 0.0.0.255 line vty 0 4 transport input ssh access-class 10 out
B.ip ssh version 2 access-list 10 permit 192.168.1.0 0.0.0.255 line vty 0 4 transport input all access-class 10 in
C.ip ssh version 2 access-list 10 permit 192.168.1.0 0.0.0.255 line vty 0 4 transport input ssh access-class 10 in
D.ip ssh version 1 access-list 10 permit 192.168.1.0 0.0.0.255 line vty 0 4 transport input ssh access-class 10 in
AnswerC

This configuration sets SSH to version 2, creates an ACL permitting the management subnet, applies the ACL to inbound VTY lines, and restricts transport input to SSH only. This meets both requirements: restrict SSH access to the management subnet and use only SSH version 2.

Why this answer

The correct configuration must set SSH version 2, create an ACL for the management subnet, apply the ACL inbound on the VTY lines, and restrict transport input to SSH only. The other options either allow other protocols, use SSH version 1, or apply the ACL in the wrong direction.

Exam trap

The trap here is misapplying the access-class direction; it must be 'in' to filter incoming SSH connections, not 'out', and ensuring 'transport input ssh' restricts to SSH only.

1239
Multi-Selecthard

Which TWO statements about DHCP IPv6 (DHCPv6) operation are true? (Choose TWO.)

Select 2 answers
A.DHCPv6 servers listen on UDP port 547.
B.Stateless DHCPv6 is used to provide DNS server information to clients that obtain their IPv6 address via SLAAC.
C.DHCPv6 can only be used in stateless mode.
D.DHCPv6 uses UDP ports 67 and 68, just like DHCPv4.
E.DHCPv6 relies on ARP to discover DHCPv6 servers.
AnswersA, B

DHCPv6 servers bind UDP port 547 to receive client messages, while clients use port 546, satisfying the stem's requirement for a true operational statement. This server-side port assignment is fixed by RFC 8415, so any DHCPv6 relay or server deployment must permit inbound UDP 547 traffic to function.

Why this answer

Option A is correct because DHCPv6 servers receive client messages on UDP port 547, while DHCPv6 clients listen on UDP port 546, so the server-side port is indeed 547. Option B is correct because stateless DHCPv6 (configured via the M and O flags in Router Advertisement, with O=1 and M=0) is specifically designed to supply additional configuration such as DNS server addresses (RFC 3646) to hosts that already obtained their IPv6 address through SLAAC. Option C is wrong because DHCPv6 supports both stateful mode (address assignment, M flag set) and stateless mode (other configuration only).

Option D is wrong because UDP ports 67 and 68 belong to DHCPv4; DHCPv6 uses 546 and 547. Option E is wrong because IPv6 does not use ARP—DHCPv6 servers are discovered via the multicast address FF02::1:2 (All_DHCP_Relay_Agents_and_Servers) and ICMPv6 Neighbor Discovery instead.

Exam trap

Cisco often tests the misconception that DHCPv6 uses the same UDP ports as DHCPv4 (67/68) or that it can only run in stateless mode, leading candidates to incorrectly select options D or C.

1240
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate management users via TACACS+ using the server at 10.1.1.100 with the shared key 'Cisco123'. The engineer wants to ensure that if the TACACS+ server becomes unreachable, the router will fall back to local authentication using the local username 'admin' with password 'AdminPass'. Which configuration correctly achieves this?

A.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123 aaa authentication login default group tacacs+ aaa authorization exec default group tacacs+ line vty 0 4 login authentication default username admin privilege 15 secret AdminPass
B.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123 aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local line vty 0 4 login authentication default username admin privilege 15 secret AdminPass
C.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123 aaa authentication login default local group tacacs+ aaa authorization exec default local group tacacs+ line vty 0 4 login authentication default username admin privilege 15 secret AdminPass
D.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123 aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local line vty 0 4 login authentication TAC1 username admin privilege 15 secret AdminPass
AnswerB

This configuration enables AAA with 'aaa new-model', defines a TACACS+ server, and sets authentication and authorization to use TACACS+ first, then local as fallback. The local username is created, and the VTY lines reference the default authentication list. This meets the requirement of falling back to local authentication if the server is unreachable.

Why this answer

The correct configuration enables AAA, defines the TACACS+ server, and configures the default authentication and authorization method lists to try TACACS+ first and then local. The VTY lines must reference the correct method list, and a local username must exist for fallback. The other options either omit fallback, reverse the order, or reference an invalid method list.

Exam trap

The trap here is confusing the TACACS+ server group name with an AAA method list name, leading to incorrect VTY line configuration.

1241
MCQmedium

A network engineer runs the following command on Router R1: R1# show flow interface GigabitEthernet0/0 Interface GigabitEthernet0/0 FNF: enabled Ingress IPV4/IPV6 flow monitoring: enabled Exporter: EXPORTER1 Monitor: MONITOR1 Egress IPV4/IPV6 flow monitoring: disabled Ingress MPLS flow monitoring: disabled Egress MPLS flow monitoring: disabled Based on this output, what is the state of NetFlow on this interface?

A.NetFlow is fully enabled for both ingress and egress traffic.
B.NetFlow is only monitoring incoming traffic on this interface.
C.NetFlow is not configured on this interface.
D.NetFlow is only monitoring MPLS traffic.
AnswerB

Ingress IPv4/IPv6 flow monitoring is enabled and bound to EXPORTER1 and MONITOR1, while egress IPv4/IPv6 and both MPLS directions are disabled. Flexible NetFlow therefore records only traffic arriving on GigabitEthernet0/0, satisfying the stem's requirement to identify the interface's actual monitoring state.

Why this answer

The output shows that ingress IPv4/IPv6 flow monitoring is enabled with an exporter and monitor configured, while egress IPv4/IPv6 flow monitoring is disabled. This means NetFlow is only monitoring incoming traffic on the interface, not outgoing traffic. The FNF (Flexible NetFlow) status confirms NetFlow is operational, but only for ingress direction.

Exam trap

The trap here is that candidates see 'FNF: enabled' and assume full bidirectional NetFlow, missing the specific ingress/egress status lines that reveal only one direction is active.

How to eliminate wrong answers

Option A is wrong because egress IPv4/IPv6 flow monitoring is explicitly disabled, so NetFlow is not fully enabled for both directions. Option C is wrong because the output clearly shows FNF is enabled and ingress flow monitoring is active, indicating NetFlow is configured. Option D is wrong because both ingress and egress MPLS flow monitoring are disabled, so NetFlow is not monitoring MPLS traffic at all.

1242
Drag & Dropmedium

Drag and drop the steps to perform mutual redistribution between OSPF and EIGRP into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order ensures that route filtering is applied before redistribution to prevent routing loops, and that redistribution is configured on both protocols symmetrically. First, identify the routing domains and interfaces. Second, configure route filtering using distribute-lists or route-maps to control which routes are exchanged.

Third, configure redistribution of EIGRP into OSPF. Fourth, configure redistribution of OSPF into EIGRP. Finally, verify the redistribution using show commands to confirm routes are exchanged correctly.

1243
Multi-Selecthard

Which TWO statements correctly describe the behavior of OSPFv3 when troubleshooting neighbor adjacency issues on a Cisco IOS-XE router? (Choose TWO.)

Select 2 answers
A.OSPFv3 neighbor adjacencies are formed using the link-local IPv6 address of the neighbor.
B.The OSPFv3 router ID is a 128-bit value derived from the highest loopback IPv6 address.
C.The 'ipv6 router ospf' command is used to enable OSPFv3 on an interface.
D.The 'show ipv6 ospf neighbor' command displays the link-local address of each neighbor.
E.OSPFv3 uses the network type configured under the OSPFv3 process globally, not per interface.
AnswersA, D

OSPFv3 runs directly over IPv6 and uses each interface's link-local address as the source and destination for Hello packets, so adjacency formation depends on those link-local addresses rather than global addresses. This is why neighbours must share a common link, satisfying the troubleshooting scenario.

Why this answer

Option A is correct because OSPFv3 forms neighbor adjacencies over IPv6 link-local addresses, which are used as the source and next-hop for Hello packets on the link. Option D is correct because the 'show ipv6 ospf neighbor' command output includes the neighbor's link-local address, which is essential when troubleshooting adjacency issues. Option B is incorrect because the OSPFv3 router ID is a 32-bit value, not 128-bit, and is typically derived from an IPv4 address or manually configured.

Option C is incorrect because OSPFv3 is enabled on an interface with the 'ipv6 ospf <process-id> area <area-id>' command, while 'ipv6 router ospf' enters the OSPFv3 process configuration mode. Option E is incorrect because OSPFv3 network type is configured per interface, not globally under the OSPFv3 process.

Exam trap

300-410 often tests OSPFv3 specifics: candidates may think the router ID is 128-bit or that network type is global, but it's 32-bit and per-interface.

1244
MCQhard

A network engineer runs the following command to debug IPv6 uRPF with detailed information: R1# debug ipv6 verify detail IPv6 verify debugging is on (detail) *Mar 1 00:03:45.678: IPv6 verify: source 2001:DB8:5::1 on GigabitEthernet0/0 *Mar 1 00:03:45.678: route to source via GigabitEthernet0/1, not same as input interface What does this output indicate?

A.The packet will be dropped because strict uRPF requires the return path to be through the same interface.
B.The packet will be forwarded because a route exists.
C.The packet will be forwarded because uRPF is loose.
D.The router will change the route to use GigabitEthernet0/0.
AnswerA

Strict uRPF checks that the source address is reachable via the same interface the packet arrived on. Here the route to 2001:DB8:5::1 points to GigabitEthernet0/1, not the input GigabitEthernet0/0, so the packet fails the check and is dropped.

Why this answer

The debug output shows that the source address 2001:DB8:5::1 is reachable via GigabitEthernet0/1, but the packet arrived on GigabitEthernet0/0. With strict unicast Reverse Path Forwarding (uRPF), the router verifies that the best return route to the source uses the same interface on which the packet was received. Since the interfaces do not match, the router drops the packet to prevent spoofing.

Exam trap

Cisco often tests the distinction between strict and loose uRPF modes, and the trap here is that candidates assume any valid route means the packet is forwarded, ignoring the critical interface match requirement for strict mode.

How to eliminate wrong answers

Option B is wrong because the existence of a route alone does not satisfy strict uRPF; the return path must exit via the same interface as the ingress interface. Option C is wrong because the debug output does not indicate loose mode; loose uRPF only requires any route to the source, regardless of interface, and would not generate the 'not same as input interface' message. Option D is wrong because uRPF does not modify routing tables; it only performs a forwarding decision based on existing routes.

1245
MCQhard

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 10.4.4.0/24 BGP routing table entry for 10.4.4.0/24, version 8 Paths: (1 available, best #1, table default) Not advertised to any peer Refresh Epoch 1 65006 10.1.16.6 from 10.1.16.6 (10.6.6.6) Origin IGP, metric 0, localpref 100, valid, external, best rx pathid: 0, tx pathid: 0x0 Based on this output, what is the most likely reason the route is not advertised to any peer?

A.The route has a local preference of 100, which is too low.
B.There is an outbound route-map or prefix-list filtering the route.
C.The BGP session to the neighbor is down.
D.The route is not in the routing table.
AnswerB

The entry shows valid, external, best with no filter flags, so the route exists in the BGP table but is withheld from all peers. An outbound route-map or prefix-list applied to the neighbour suppresses advertisement, which the Not advertised to any peer line confirms.

Why this answer

The 'Not advertised to any peer' line in the BGP table entry indicates that R1 is not sending this prefix to any of its BGP neighbors, even though the route is valid and marked as best. Since the session is up (the route was received from 10.1.16.6) and the route is in the BGP table, the most likely cause is an outbound filter — a route-map, prefix-list, or distribute-list applied in the outbound direction on the neighbor statement — that is suppressing advertisement. Local preference of 100 is the default and has no bearing on whether a route is advertised.

Exam trap

The trap here is assuming that a route marked 'best' and 'valid' is automatically advertised — candidates forget that outbound policy is evaluated separately and can silently suppress a perfectly valid best path.

How to eliminate wrong answers

Option A is wrong because local preference 100 is the Cisco default value and only influences outbound path selection within the local AS, not whether a prefix is advertised to peers. Option C is wrong because the output shows the route was successfully received from neighbor 10.1.16.6, proving the session is established and up. Option D is wrong because the route is marked 'valid' and 'best' in the BGP table, meaning it is present and usable — if it were missing from the routing table, the BGP entry would show 'inaccessible' or not be marked valid.

1246
MCQhard

A network engineer is troubleshooting a Cisco IOS FlexVPN IKEv2 hub that terminates many spokes using a single IKEv2 profile. A new spoke fails to complete IKEv2 authentication even though the same pre-shared key is configured on both peers. The hub logs show the failure occurs during IKE_AUTH. The spoke is not sending a certificate and there is no local AAA authentication configured on the hub for IKEv2. Which configuration change on the hub is most likely to resolve the authentication failure?

A.Add the spoke's identity to the IKEv2 keyring as a peer entry with the matching pre-shared key
B.Configure a local AAA authorization list on the IKEv2 profile to authorize the spoke's group policy
C.Bind the IKEv2 profile to a virtual template interface used for the spoke's virtual access interface
D.Enable RSA signature authentication on the IKEv2 profile so the hub can validate the spoke without a keyring
AnswerA

IKEv2 pre-shared key authentication on Cisco IOS requires the hub to match the peer's identity against an entry in the IKEv2 keyring, where the pre-shared key is defined per peer or per subnet. Without a matching keyring peer entry, the hub cannot retrieve the pre-shared key during IKE_AUTH even though the profile exists, and the exchange fails. Adding the spoke identity with the correct key resolves the failure.

Why this answer

Cisco IOS IKEv2 pre-shared key authentication relies on the IKEv2 keyring to look up the key associated with the peer's identity. The IKEv2 profile references the keyring, but the key itself must exist in a peer or subnet entry that matches the spoke. Because no AAA authentication is configured, the keyring is the only source of the key, so adding the spoke identity with the matching key fixes the IKE_AUTH failure.

Exam trap

The trap here is believing that configuring the same pre-shared key under the IKEv2 profile is sufficient, when the key must be defined in an IKEv2 keyring entry that matches the peer's identity.

1247
MCQeasy

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The engineer wants to ensure that only traffic from the 10.1.1.0/24 network to the 10.2.2.0/24 network is encrypted. Which type of ACL must be used in the crypto map to define the interesting traffic?

A.A standard ACL that permits the 10.1.1.0/24 network.
B.An extended ACL that denies IP traffic from 10.1.1.0/24 to 10.2.2.0/24.
C.An extended ACL that permits IP traffic from 10.1.1.0/24 to 10.2.2.0/24.
D.A named ACL that permits all IP traffic.
AnswerC

For IPsec site-to-site VPNs, the crypto map ACL must be an extended ACL that defines the interesting traffic. It should permit IP traffic from the local subnet to the remote subnet. This ACL is used to match packets that need encryption. A standard ACL cannot specify destination addresses or protocols, so it is insufficient.

Why this answer

In Cisco IPsec configuration, the crypto map references an extended ACL to identify interesting traffic. The ACL must permit IP traffic from the local subnet to the remote subnet. This ensures that only packets matching those criteria are encrypted and sent through the VPN tunnel.

Standard ACLs or overly broad ACLs are incorrect.

Exam trap

The trap here is using a standard ACL or a deny statement, misunderstanding that the crypto ACL must be an extended ACL that permits the specific traffic.

1248
MCQmedium

A network engineer is deploying DMVPN Phase 3 with OSPF over the tunnel interface. The hub router must summarize all spoke routes into a single /24 prefix before advertising them into the corporate OSPF domain. The engineer configures `area 0 range 10.10.0.0 255.255.255.0` on the hub's ABR. After applying the configuration, spoke routes are still advertised individually. Which action resolves the issue?

A.Configure `ip ospf database-filter all out` on the hub tunnel interface to suppress individual LSAs and allow the summary to propagate.
B.Configure the `area 0 range 10.10.0.0 255.255.255.0` command on the hub router's tunnel interface instead of the global OSPF process.
C.Change the OSPF network type on the hub tunnel interface to point-to-multipoint and reapply the `area 0 range` command.
D.Ensure the hub router is an ABR by placing the tunnel interface in a different area than the corporate domain, then apply the `area X range` command for that area.
AnswerD

OSPF area summarization is performed by an ABR on routes entering the backbone. If the tunnel interface belongs to the same area as the corporate domain, the hub is not an ABR and cannot generate summary LSAs. Placing the tunnel in a separate area makes the hub an ABR, allowing `area X range` to summarize spoke routes before advertising them.

Why this answer

Inter-area route summarization in OSPF requires the router to be an ABR, meaning it must have interfaces in at least two areas. The `area range` command only takes effect on an ABR for routes from the specified area. If the hub's tunnel and corporate interfaces are in the same area, no summary LSA is generated, so the spoke routes are advertised individually.

Exam trap

The trap here is assuming that the `area range` command works on any router regardless of its ABR status, when it only generates summary LSAs on a router that is an ABR for the specified area.

1249
MCQmedium

A network engineer runs the following command to verify IPv6 traffic filtering with logging: R1# show logging | include FILTER *Mar 1 00:04:56.789: %IPV6_ACL-6-ACCESSLOGDP: list FILTER denied tcp 2001:DB8:2::1(12345) -> 2001:DB8:3::1(80), 1 packet What does this output indicate?

A.A TCP packet from 2001:DB8:2::1 to destination 2001:DB8:3::1 port 80 was denied by the access list.
B.A TCP packet was permitted by the access list.
C.The access list is not applied to any interface.
D.The packet was dropped due to uRPF.
AnswerA

The log entry confirms the IPv6 access list named FILTER matched and dropped a TCP segment, evidenced by the ACCESSLOGDP message and "denied" keyword. Source 2001:DB8:2::1 port 12345 to destination 2001:DB8:3::1 port 80 satisfies the stem's requirement to verify filtering with logging, proving the ACL denies rather than permits.

Why this answer

The log message shows an IPv6 ACL (named FILTER) logging a denied TCP packet from source 2001:DB8:2::1 port 12345 to destination 2001:DB8:3::1 port 80. The keyword 'denied' in the log entry confirms the packet was blocked by the access list, making option A correct.

Exam trap

Cisco often tests the ability to distinguish between ACL deny/permit actions in log messages, where the trap is that candidates misread 'denied' as 'permitted' or confuse ACL logging with other features like uRPF or interface statistics.

How to eliminate wrong answers

Option B is wrong because the log explicitly states 'denied', not 'permitted', so the packet was not allowed through. Option C is wrong because the log entry shows the ACL is actively logging and filtering traffic, which only occurs when the ACL is applied to an interface; an unapplied ACL would generate no such log. Option D is wrong because uRPF (unicast Reverse Path Forwarding) drops packets based on source address reachability checks, not ACL filtering, and the log message specifically references the IPv6 ACL (IPV6_ACL-6-ACCESSLOGDP), not uRPF.

1250
MCQhard

An engineer configures IPv6 uRPF strict mode on an interface that is used for both IPv6 traffic and OSPFv3 routing. The router is an ABR with multiple areas. OSPFv3 adjacencies form correctly, but some IPv6 data traffic is dropped. The show ipv6 interface command shows uRPF is enabled. Which is the most likely explanation?

A.The router has a default route pointing to a different interface, and uRPF strict mode without 'allow-default' drops packets whose source address is reachable via the default route.
B.OSPFv3 adjacencies use link-local addresses, which are not checked by uRPF, but data traffic uses global addresses that are incorrectly filtered by the OSPFv3 process.
C.The router has 'ipv6 uRPF allow-default' configured, but the default route is not installed, causing all traffic to be dropped.
D.The interface has an IPv6 ACL that denies traffic from certain prefixes, overriding uRPF.
AnswerA

Strict uRPF checks that the source is reachable via the same interface the packet arrived on. A default route pointing elsewhere makes many legitimate sources fail that check, so traffic is dropped unless allow-default is configured to permit default-route reachability.

Why this answer

URPF strict mode on an interface checks that the source address of incoming packets is reachable via the same interface. If the router has a default route pointing to a different interface, packets sourced from addresses that are only reachable via that default route will fail the RPF check and be dropped. The 'allow-default' keyword is required to exempt packets whose source is reachable via a default route from this check.

Exam trap

Cisco often tests the nuance that uRPF strict mode drops traffic when a default route points out a different interface, and candidates forget that the 'allow-default' keyword is necessary to permit such traffic.

How to eliminate wrong answers

Option B is wrong because OSPFv3 adjacencies use link-local addresses, which are not subject to uRPF checks, but data traffic using global addresses is filtered by uRPF, not by the OSPFv3 process. Option C is wrong because if 'ipv6 uRPF allow-default' is configured but the default route is not installed, uRPF would still operate normally for non-default routes; the 'allow-default' keyword only affects behavior when a default route exists. Option D is wrong because an IPv6 ACL overriding uRPF is not a standard behavior; uRPF and ACLs operate independently, and the question states uRPF is enabled and dropping traffic, not an ACL.

1251
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP server for a remote subnet. The router interface connected to that subnet is configured with the address 10.10.10.1/24. The engineer wants the router to assign addresses from the 10.10.10.0/24 range and also provide the default gateway and DNS server information to clients. Which configuration is required on the router to accomplish this?

A.ip dhcp excluded-address 10.10.10.1 10.10.10.10, ip dhcp pool LAN, network 10.10.10.0 255.255.255.0, default-router 10.10.10.254
B.ip dhcp pool LAN, network 10.10.10.0 255.255.255.0, default-router 10.10.10.1, dns-server 8.8.8.8, lease 0 0 10
C.ip dhcp pool LAN, network 10.10.10.0 255.255.255.0, default-router 10.10.10.1, dns-server 8.8.8.8, domain-name example.com
D.ip dhcp pool LAN, network 10.10.10.0 255.255.255.0, default-router 10.10.10.1, dns-server 8.8.8.8
AnswerD

This configuration creates a DHCP pool named LAN, defines the subnet 10.10.10.0/24 from which addresses are allocated, and specifies the default gateway and DNS server for clients. The router interface address 10.10.10.1 is used as the gateway. This is the standard Cisco IOS DHCP server configuration for a directly connected subnet.

Why this answer

The correct configuration must include a DHCP pool with the network statement, default-router set to the router's interface IP (10.10.10.1), and dns-server for DNS. The other options either omit DNS, use an incorrect gateway, or add unnecessary parameters. The router's interface address is the appropriate default gateway for clients on that subnet.

Exam trap

The trap here is assuming that the default-router must be the highest or lowest address in the subnet, rather than the router's actual interface address.

1252
MCQeasy

A network engineer runs the following command on Router R1: R1# show dmvpn Legend: Attrb -> S: Static, D: Dynamic, I: Incomplete N: NATed, L: Local, X: No Socket # Ent -> Number of NHRP entries with same NBMA peer NHS Status: E => Expecting Replies, R => Responding, W => Waiting UpDn Time -> Up or Down Time for a Tunnel ========================================================================== Interface: Tunnel0, IPv4 NHRP Details Type:Hub, NHRP Peers:2, # Ent Peer NBMA Addr Peer Tunnel Add State UpDn Tm Attrb ----- --------------- --------------- ----- -------- ----- 1 192.168.1.2 10.0.0.2 UP 00:15:30 D 1 192.168.1.3 10.0.0.3 UP 00:10:20 D Based on this output, what is the role of Router R1?

A.Router R1 is a DMVPN spoke.
B.Router R1 is a DMVPN hub.
C.Router R1 is a DMVPN server.
D.Router R1 is a DMVPN client.
AnswerB

The output shows "Type:Hub" for Tunnel0, confirming R1 terminates the DMVPN tunnels. Both peers are dynamically learned (Attrb D), meaning spokes registered their NBMA addresses with R1 via NHRP. This satisfies the scenario's requirement to identify R1's role from the show dmvpn command.

Why this answer

The 'show dmvpn' output shows 'Type:Hub' for Tunnel0, which explicitly identifies Router R1 as the DMVPN hub. Additionally, R1 has two NHRP peers (the spokes) with dynamic (D) attributes, which is the expected view from the hub. A spoke would show 'Type:Spoke' and typically list the hub as its peer.

Exam trap

The trap is that candidates may not know the exact 'Type:' field in 'show dmvpn' output and may guess based on the number of peers; the output explicitly states 'Type:Hub'.

How to eliminate wrong answers

Option A is wrong because a DMVPN spoke would display 'Type:Spoke' and would show the hub as its NHRP peer, not two dynamic peers. Option C is wrong because 'DMVPN server' is not a Cisco term; the correct roles are hub and spoke. Option D is wrong because 'DMVPN client' is also not a Cisco term; the client-side role is called a spoke.

1253
MCQhard

An engineer configures an IPsec site-to-site VPN between two routers. The tunnel comes up, but traffic is not encrypted. Which is the most likely explanation?

A.The crypto ACL does not match the traffic that is being sent.
B.The transform set uses ESP with null encryption.
C.The ISAKMP policy has the wrong authentication method.
D.The pre-shared key is incorrect.
AnswerA

Crypto ACLs define which traffic is protected by the IPsec transform set. If the ACL's permit entries do not match the actual source and destination subnets traversing the tunnel, packets are routed unencrypted via the crypto map's implicit deny, so the tunnel stays up while data flows in clear text.

Why this answer

The most likely reason traffic is not encrypted despite the tunnel being up is that the crypto ACL (access-list) applied to the IPsec configuration does not match the actual traffic being sent. The crypto ACL defines which traffic should be protected by IPsec; if the ACL does not permit the specific source/destination or protocol/port of the traffic, the router will not attempt to encrypt it, even though the IKE and IPsec security associations (SAs) are established.

Exam trap

Cisco often tests the misconception that a tunnel being up guarantees traffic encryption, but the crypto ACL is the gatekeeper for which traffic gets encrypted, and candidates may overlook this distinction.

How to eliminate wrong answers

Option B is wrong because ESP with null encryption would still encrypt the packet (ESP provides encryption by default; null encryption is rarely used and would be a deliberate configuration, not a common cause of no encryption). Option C is wrong because the ISAKMP policy authentication method (e.g., pre-shared key, RSA signatures) affects Phase 1 authentication, not the encryption of data traffic; if the tunnel is up, Phase 1 has succeeded. Option D is wrong because an incorrect pre-shared key would prevent the tunnel from coming up at all (IKE Phase 1 would fail), so the tunnel being up rules out this cause.

1254
MCQhard

An engineer configures IPsec between two routers using transform-set esp-aes 256 esp-sha-hmac. The tunnel fails to establish. Debug shows 'transform set proposal mismatch'. Which is the most likely explanation?

A.The other router uses 'esp-aes' without specifying the key length, defaulting to 128-bit, causing a mismatch.
B.The transform-set uses SHA-1, which is not supported by the other router.
C.The IPsec proposal includes both esp-aes and esp-3des, causing confusion.
D.The transform-set is missing the authentication header.
AnswerA

The transform-set keyword 'esp-aes' alone negotiates the default 128-bit AES key, whereas 'esp-aes 256' requires 256-bit. Since IPsec proposals must match exactly on encryption algorithm and key length, the differing AES strengths cause the proposal mismatch.

Why this answer

The debug output 'transform set proposal mismatch' indicates that the IPsec transform sets on the two peers do not match. When 'esp-aes 256' is configured on one router, the other router must explicitly specify 'esp-aes 256' as well; if it only uses 'esp-aes' without specifying a key length, Cisco IOS defaults to AES-128. This mismatch in encryption algorithm strength (256-bit vs. 128-bit) causes the IKE phase 2 negotiation to fail.

Exam trap

Cisco often tests the default behavior of 'esp-aes' (which defaults to 128-bit) versus explicit 'esp-aes 256', trapping candidates who assume that 'esp-aes' implies 256-bit or that the key length is negotiated automatically.

How to eliminate wrong answers

Option B is wrong because SHA-1 (esp-sha-hmac) is widely supported on Cisco routers and is not the cause of a transform set mismatch; the issue is the encryption algorithm, not the hash. Option C is wrong because the transform-set in the question contains only 'esp-aes 256' and 'esp-sha-hmac', not both esp-aes and esp-3des; a transform set can only contain one encryption algorithm, so this option describes an invalid configuration that would not be accepted by the CLI. Option D is wrong because the transform-set already includes an authentication header via 'esp-sha-hmac', which provides integrity; the absence of AH is irrelevant since ESP provides both encryption and authentication in this setup.

1255
MCQhard

An engineer configures an IPv6 ACL on a router interface to permit only specific ICMPv6 types (e.g., echo request and echo reply) and deny all other IPv6 traffic. After applying the ACL inbound, the router stops forming IPv6 neighbor discoveries (ND) and the interface loses IPv6 connectivity. Which is the most likely explanation?

A.The ACL denies ICMPv6 types 133-137, which are required for Neighbor Discovery, causing the router to fail to resolve neighbors.
B.The ACL must be applied outbound, not inbound, to allow ND packets to be sent.
C.The router needs to have 'ipv6 nd suppress' configured to bypass ACL filtering for ND packets.
D.The ACL should use 'permit ipv6 any any' before the deny statements to allow ND, but the engineer placed it after.
AnswerA

Denying ICMPv6 types 133–137 blocks Router Solicitation, Router Advertisement, Neighbor Solicitation, Neighbor Advertisement and Redirect, which Neighbor Discovery depends on for address resolution and router discovery. The ACL's implicit deny-all therefore severs ND, so the interface cannot resolve neighbours or maintain IPv6 connectivity.

Why this answer

The ACL denies ICMPv6 types 133-137, which are essential for Neighbor Discovery (ND) processes such as Router Solicitation (133), Router Advertisement (134), Neighbor Solicitation (135), Neighbor Advertisement (136), and Redirect (137). Without permitting these types, the router cannot resolve IPv6 neighbors or maintain IPv6 connectivity, as ND is fundamental to IPv6 operation.

Exam trap

Cisco often tests the candidate's awareness that IPv6 Neighbor Discovery uses specific ICMPv6 types (133-137) which must be explicitly permitted in ACLs, as they are not automatically allowed like in IPv4 ARP.

How to eliminate wrong answers

Option B is wrong because applying the ACL outbound would not fix the issue; ND packets must be received inbound to process neighbor discovery, and the ACL is applied inbound to filter incoming traffic. Option C is wrong because 'ipv6 nd suppress' is used to suppress ND on an interface, not to bypass ACL filtering; it would actually worsen the problem by disabling ND. Option D is wrong because using 'permit ipv6 any any' before deny statements would permit all IPv6 traffic, including unwanted types, defeating the ACL's purpose; the correct approach is to permit specific ICMPv6 types (including ND types) before denying others.

1256
MCQmedium

A network engineer runs the following command to troubleshoot a Control Plane Policing (CoPP) issue: R1# show ip ospf interface detail FastEthernet0/0 is up, line protocol is up Internet Address 10.1.1.1/24, Area 0.0.0.0, Attached via Network Statement Process ID 1, Router ID 10.1.1.1, Network Type BROADCAST, Cost: 1 Topology-MTID Cost Disabled Shutdown Topology Name 0 1 no no Base Transmit Delay is 1 sec, State DR, Priority 1 Designated Router (ID) 10.1.1.1, Interface address 10.1.1.1 Backup Designated router (ID) 10.1.1.2, Interface address 10.1.1.2 Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5 oob-resync timeout 40 Hello due in 00:00:03 Supports Link-local Signaling (LLS) Index 1/1, flood queue length 0 Next 0x0(0)/0x0(0) Last flood scan length is 1, maximum is 25 Last flood scan time is 0 msec, maximum is 4 msec Neighbor Count is 1, Adjacent neighbor count is 1 Adjacent with neighbor 10.1.1.2 (Backup Designated Router) Suppress hello for 0 neighbor(s) What does this output indicate?

A.OSPF is not forming adjacencies due to CoPP dropping Hello packets.
B.OSPF is operating normally with one neighbor, suggesting CoPP is not impacting OSPF.
C.OSPF is experiencing DR/BDR election issues due to CoPP.
D.OSPF is not receiving Hello packets due to CoPP.
AnswerB

The output shows a full adjacency with one neighbour, a stable DR/BDR relationship, and Hello timers of 10/40 seconds, confirming OSPF control packets are traversing the interface unimpeded. Since CoPP drops would disrupt Hello exchange and prevent adjacency formation, the healthy neighbour count and adjacency state demonstrate that CoPP is not filtering OSPF traffic here.

Why this answer

The output shows that OSPF has formed a full adjacency with neighbor 10.1.1.2, which is the Backup Designated Router. The neighbor count is 1 and the adjacent neighbor count is 1, indicating that OSPF is operating normally on this interface. Therefore, CoPP is not impacting OSPF Hello or adjacency formation.

Exam trap

Cisco often tests the misconception that any CoPP configuration automatically disrupts OSPF, but the trap here is that the 'show ip ospf interface detail' output explicitly shows a working adjacency, proving CoPP is not the issue.

How to eliminate wrong answers

Option A is wrong because the output clearly shows an OSPF adjacency has been formed (neighbor count 1, adjacent neighbor count 1), so CoPP is not dropping Hello packets. Option C is wrong because the DR/BDR election is complete: R1 is the DR (State DR) and 10.1.1.2 is the BDR, with no election issues indicated. Option D is wrong because the adjacency exists, meaning Hello packets are being received and processed; CoPP is not blocking them.

1257
MCQeasy

A network administrator is setting up a site-to-site VPN between two Cisco IOS routers and wants to use IKEv2 with certificate-based authentication. The administrator has already installed the identity certificate and the CA certificate on both routers. Which additional configuration is required on each router so that IKEv2 can validate the peer's certificate during the IKE_AUTH exchange?

A.Configure a pre-shared key on both routers as a fallback in case certificate validation fails.
B.Configure the IKEv2 profile with the authentication local rsa-sig command only, without referencing a trustpoint.
C.Reference the PKI trustpoint in the IKEv2 profile using the pki trustpoint command so the router knows which CA to use for validation.
D.Enable the crypto pki server on both routers so each can issue certificates to the other.
AnswerC

For certificate authentication in IKEv2, the router must know which trustpoint to use for its own certificate and for validating the peer certificate chain. Referencing the trustpoint in the IKEv2 profile with the pki trustpoint command supplies that binding. Without it, the router cannot select the correct CA chain or send the proper certificate during IKE_AUTH, so the negotiation fails even though certificates are installed.

Why this answer

IKEv2 certificate authentication requires the router to select a trustpoint that identifies its own certificate and the CA chain used to validate the peer. The pki trustpoint command under the IKEv2 profile provides that binding. With the trustpoint referenced, the router can present its identity certificate and verify the peer's certificate during IKE_AUTH, completing authentication even though the certificates were already installed.

Exam trap

The trap here is believing that installing certificates is sufficient, when IKEv2 also needs an explicit trustpoint reference in the profile to know which CA chain to use.

1258
MCQeasy

A network engineer is configuring AAA authorization on a Cisco IOS router. The engineer wants to limit which commands a user can execute after logging in via SSH. The user should be allowed to run show commands but not configuration commands. Which AAA authorization method should be used?

A.aaa authentication login default group tacacs+
B.aaa authorization network default group tacacs+
C.aaa authorization commands 15 default group tacacs+
D.aaa authorization exec default group tacacs+
AnswerC

Authorization for commands at privilege level 15 allows the AAA server to authorize each command the user attempts to execute at that privilege level. By configuring this, the engineer can define a command set on the TACACS+ server that permits show commands and denies configuration commands. This is the correct method to restrict specific commands.

Why this answer

AAA authorization for commands allows the network access server to consult the AAA server for each command entered by the user. By specifying privilege level 15, the engineer can restrict commands for users at that privilege level. The TACACS+ server can then be configured with a command set that permits show commands and denies configuration commands, achieving the desired restriction.

Exam trap

The trap here is confusing authentication with authorization, or thinking that exec authorization controls command execution, when actually command authorization is required to restrict specific CLI commands.

1259
MCQmedium

Examine this configuration on Router R4: ``` interface Tunnel0 ip address 10.0.0.1 255.255.255.252 ipv6 address 2001:DB8:6::1/64 tunnel source GigabitEthernet0/0 tunnel destination 172.16.1.2 tunnel mode gre ip ``` What will be the effect?

A.The tunnel will only carry IPv4 traffic because the mode is 'gre ip'.
B.The tunnel will successfully encapsulate both IPv4 and IPv6 payloads over IPv4.
C.The tunnel will fail because the tunnel source is an interface, not an IP address.
D.The tunnel mode should be 'ipv6ip' to carry IPv6 traffic.
AnswerB

GRE with tunnel mode gre ip carries any passenger protocol, so IPv4 and IPv6 packets are both encapsulated inside the outer IPv4 header defined by the tunnel source and destination. The dual-stack addresses on Tunnel0 confirm both families are intended.

Why this answer

The 'tunnel mode gre ip' command creates a generic routing encapsulation (GRE) tunnel over IPv4. GRE is protocol-agnostic and can encapsulate any Layer 3 protocol, including IPv4 and IPv6. The IPv6 address configured on the tunnel interface allows IPv6 traffic to be routed into the tunnel, where it is encapsulated in IPv4 packets and sent to the tunnel destination.

Therefore, the tunnel will successfully carry both IPv4 and IPv6 payloads.

Exam trap

Cisco often tests the misconception that 'tunnel mode gre ip' only supports IPv4 traffic, when in fact GRE is protocol-agnostic and can carry IPv6, IPX, or other Layer 3 protocols as payload.

How to eliminate wrong answers

Option A is wrong because 'gre ip' mode does not restrict the tunnel to only IPv4 payloads; GRE can encapsulate multiple protocols, including IPv6. Option C is wrong because the tunnel source can be specified as an interface (e.g., GigabitEthernet0/0), and the router will use that interface's primary IP address as the source; this is a valid configuration. Option D is wrong because 'ipv6ip' mode is a specific tunnel type for IPv6-in-IPv4 encapsulation without GRE overhead, but GRE is fully capable of carrying IPv6 traffic and is often preferred for its flexibility and support for additional features like multipoint or encryption.

1260
MCQhard

An engineer configures mutual redistribution between OSPF and EIGRP on a router. After a few minutes, the router's CPU spikes and routing loops occur. Which is the most likely explanation?

A.The seed metric for EIGRP was not configured, causing the route to be redistributed with an infinite metric.
B.The administrative distance of the redistributed routes is lower than the original, causing them to be preferred.
C.Routes redistributed from OSPF into EIGRP are then redistributed back into OSPF, creating a feedback loop.
D.The OSPF process ID must match on all routers; otherwise, redistribution fails.
AnswerC

Mutual redistribution without filtering or tag-based deny causes prefixes learned from OSPF to re-enter OSPF via EIGRP, so each protocol treats the other's routes as external and re-advertises them endlessly, inflating the topology table and CPU.

Why this answer

Mutual redistribution without route tagging or filtering can cause a routing loop. A route redistributed from OSPF into EIGRP can be redistributed back into OSPF, creating a feedback loop. This is a classic redistribution loop.

1261
MCQeasy

A network engineer runs the following command to troubleshoot an EIGRP issue: R1# show ip eigrp interfaces detail Interface GigabitEthernet0/0 EIGRP interface state: Enabled, Up Hello interval: 5 sec, Hold time: 15 sec Split horizon: Enabled Next multicast: 0.0.0.0, Next update: 0.0.0.0 Bandwidth: 10000 Kbit, Delay: 100 us Reliability: 255/255, Load: 1/255, MTU: 1500 Packets sent: 100, received: 95 Authentication: MD5, key chain: EIGRP-KEY Passive interface: No What does this output indicate?

A.EIGRP is using MD5 authentication with key chain EIGRP-KEY, and the interface is actively sending and receiving EIGRP packets.
B.EIGRP is configured as a passive interface, so no hellos are sent.
C.Split horizon is disabled, allowing route advertisement back to the source.
D.The interface is using plain-text authentication.
AnswerA

The output lists "Authentication: MD5, key chain: EIGRP-KEY" and shows packets sent and received, confirming MD5 authentication is active and the interface is exchanging EIGRP traffic. This satisfies the stem's requirement to verify authentication and interface activity.

Why this answer

The output shows the interface is enabled and up, with MD5 authentication configured using key chain EIGRP-KEY. The 'Packets sent: 100, received: 95' indicates active packet exchange, and 'Passive interface: No' confirms hellos are being sent. This means EIGRP is actively sending and receiving packets with MD5 authentication.

Exam trap

Cisco often tests the distinction between 'Passive interface: No' (meaning hellos are sent) and the passive-interface command (which suppresses hellos), leading candidates to incorrectly assume a passive interface when it is not explicitly stated.

How to eliminate wrong answers

Option B is wrong because the output explicitly shows 'Passive interface: No', meaning the interface is not passive and hellos are being sent. Option C is wrong because the output shows 'Split horizon: Enabled', not disabled, so route advertisement back to the source is prevented. Option D is wrong because the output shows 'Authentication: MD5', not plain-text authentication.

1262
MCQeasy

In MPLS L3VPN, what is the default behavior when a PE router receives a VPNv4 route with a Route Target that does not match any import RT on any VRF?

A.The route is stored in the BGP table but not installed in any VRF routing table.
B.The route is discarded and not stored in the BGP table.
C.The route is installed in the global routing table.
D.The route is advertised to all other PEs.
AnswerA

Route Target import matching controls VRF installation, not BGP propagation. A VPNv4 route whose RT matches no VRF's import target remains valid in the BGP table but is never imported into any VRF routing table, so it is not used for forwarding.

Why this answer

In MPLS L3VPN, a PE router receives VPNv4 routes via MP-BGP and evaluates the Route Target (RT) extended community against the import RTs configured on each VRF. If no VRF has a matching import RT, the route remains in the BGP table (the VPNv4 RIB) but is not imported into any VRF routing table, so it is not used for forwarding. This is the default behavior: the route is not discarded, but it is also not installed anywhere.

Exam trap

The trap here is confusing 'not installed in a VRF' with 'discarded'; candidates often assume that an unmatched RT causes the route to be dropped entirely, when in fact it remains in the BGP table.

How to eliminate wrong answers

Option B is wrong because the route is not discarded; it is retained in the BGP table and can still be advertised to other PE routers (unless additional outbound filtering is applied). Option C is wrong because VPNv4 routes are not installed in the global routing table; they are only imported into VRFs based on matching import RTs. Option D is wrong because the route is not automatically advertised to all other PEs; VPNv4 route advertisement is controlled by BGP policies and the route reflector/client relationships, and the lack of a matching import RT does not trigger re-advertisement.

1263
MCQmedium

A network engineer is configuring a Cisco IOS XE router to act as a Dynamic Host Configuration Protocol (DHCP) client on its WAN interface. The service provider requires the router to send a specific client identifier in its DHCP requests. Which command accomplishes this?

A.ip dhcp client class-id <string>
B.ip dhcp client request <option>
C.ip dhcp client client-id <string>
D.ip dhcp client hostname <name>
AnswerC

This command, configured on the interface, specifies a custom client identifier that the router includes in its DHCP requests. The service provider can use this identifier to assign a specific lease or apply policies. It must be applied to the interface acting as the DHCP client, and the identifier can be a string or hexadecimal value.

Why this answer

The ip dhcp client client-id command allows the router to send a custom client identifier in its DHCP requests, which the service provider can use for lease assignment. The other commands set different DHCP options, such as hostname, class identifier, or requested options, and do not fulfill the requirement for a specific client identifier.

Exam trap

The trap here is confusing the DHCP client identifier with the hostname or class-id options; each serves a distinct purpose in DHCP message construction.

1264
MCQhard

A network administrator is troubleshooting an MPLS L3VPN where customer routes are not being propagated between PE routers. The PE routers are Cisco IOS-XE devices running MP-BGP. Which address family must be configured on the PE routers to exchange VPNv4 prefixes?

A.address-family ipv4 multicast
B.address-family ipv4 vrf
C.address-family vpnv4
D.address-family ipv4 unicast
AnswerC

The address-family vpnv4 command under BGP configuration enables the exchange of VPNv4 prefixes between PE routers. It carries the route distinguisher and route target extended communities, which are essential for MPLS L3VPN. Without this address family activated on both PE routers, customer routes will not be propagated across the MPLS core, breaking connectivity between sites.

Why this answer

In MPLS L3VPN, PE routers exchange customer routes using MP-BGP with the VPNv4 address family. This address family supports the route distinguisher and route target extended communities that identify the VPN membership. Configuring address-family vpnv4 under BGP and activating it with the neighbor command allows the PE routers to exchange these prefixes, enabling end-to-end connectivity for the customer VRFs.

Exam trap

The trap here is assuming that the global IPv4 unicast address family can carry VPNv4 routes, or confusing VRF address family with VPNv4 address family.

1265
MCQmedium

Given this configuration on router R2: ``` ip vrf CUSTOMER_D rd 100:1 ! interface GigabitEthernet0/0 ip vrf forwarding CUSTOMER_D ip address 192.168.2.1 255.255.255.0 ! router ospf 1 vrf CUSTOMER_D network 192.168.2.0 0.0.0.255 area 0 ``` What will happen when this configuration is applied?

A.OSPF will run on GigabitEthernet0/0 and form adjacencies within VRF CUSTOMER_D.
B.OSPF will fail because the OSPF process must be configured globally, not under the VRF.
C.OSPF will run on all interfaces, including those not in VRF CUSTOMER_D.
D.The network command is invalid because it uses a wildcard mask instead of a subnet mask.
AnswerA

The interface is bound to VRF CUSTOMER_D via ip vrf forwarding, and OSPF process 1 is likewise VRF-scoped, so its network statement activates OSPF on GigabitEthernet0/0. Adjacencies form only with neighbours inside that VRF, isolating customer routing.

Why this answer

The OSPF process is tied to VRF CUSTOMER_D, so it only runs on interfaces that belong to that VRF. The network command matches the interface, so OSPF will form adjacencies on that interface within the VRF.

1266
Drag & Dropmedium

Drag and drop the steps to verify and validate NetFlow and Flexible NetFlow operational state into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Verification starts with checking that the flow monitor is active on the interface, then confirming flow records are being generated, then checking exporter statistics for sent packets, then validating the collector receives the data, and finally comparing flow counts to interface counters for accuracy.

1267
MCQhard

Which statement correctly describes the default 'match' direction in a Flexible NetFlow flow record?

A.The default match direction is 'output' (egress).
B.The default match direction is 'both' (input and output).
C.The default match direction is 'input' (ingress).
D.There is no default direction; it must always be specified.
AnswerC

In a Flexible NetFlow flow record, the match direction defaults to input, meaning the record matches fields on ingress traffic. Egress matching must be configured explicitly, so the default behaviour captures inbound packets unless changed.

Why this answer

In a Flexible NetFlow flow record, the default match direction is 'input' (ingress). This means that by default, the flow record matches on fields in the ingress direction. If you need to match on egress fields, you must explicitly configure the 'match direction output' command.

Exam trap

The trap is assuming that the default match direction is 'both' or that it must always be specified; in reality, it defaults to 'input'.

How to eliminate wrong answers

Option A is wrong because 'output' is not the default; it must be explicitly configured. Option B is wrong because 'both' is not a valid single default; you can configure separate records for input and output. Option D is wrong because there is a default direction, which is input.

1268
MCQmedium

A network engineer runs the following command to troubleshoot SNMP access: R1# show snmp community Community name: public Community Index: public Storage-Type: nonvolatile Access: read-only View: v1default Community name: private Community Index: private Storage-Type: nonvolatile Access: read-write View: v1default What does this output indicate?

A.The router has two SNMP communities: 'public' for read-only and 'private' for read-write access.
B.The router only allows SNMP writes with the 'public' community.
C.The router is not configured for SNMP because no community strings are shown.
D.The router uses SNMPv3 and these communities are for backward compatibility.
AnswerA

The 'show snmp community' output lists two configured community strings: 'public' mapped to read-only access and 'private' mapped to read-write access. Both use the default v1default view, so the distinction is purely the permitted operation level.

Why this answer

The output shows two SNMP community strings configured on the router: 'public' with read-only access and 'private' with read-write access. This is a standard SNMPv1/v2c configuration where the community string acts as a password for access control, and the 'Access' field explicitly defines the permissions. Therefore, option A correctly interprets the output.

Exam trap

Cisco often tests the distinction between SNMPv1/v2c community strings and SNMPv3 user-based security, so candidates may mistakenly assume that any community output implies SNMPv3 backward compatibility.

How to eliminate wrong answers

Option B is wrong because the 'public' community has 'Access: read-only', so it cannot be used for SNMP writes; only the 'private' community has read-write access. Option C is wrong because the output clearly lists two community strings, indicating SNMP is configured. Option D is wrong because the output shows SNMPv1/v2c communities (with 'v1default' view), not SNMPv3; SNMPv3 uses usernames and authentication/encryption parameters, not community strings.

1269
MCQhard

A network engineer is troubleshooting a router that is not generating any EEM applet actions even though the applets are configured and enabled. The engineer checks the 'show event manager status' command and sees that the EEM server is running. The engineer also checks the syslog and sees that the trigger events are occurring. What is the most likely cause?

A.The EEM applets are not registered due to a syntax error in the configuration.
B.The EEM server is not listening for syslog events.
C.The router's logging level is set to emergencies only.
D.The EEM applets are configured with 'event none' and need manual triggering.
AnswerA

EEM applets with configuration syntax errors fail to register with the EEM server, so no actions fire despite the server running and trigger events appearing in syslog. Registration failure is the specific mechanism that explains silent applets, distinguishing it from a stopped server or missing event detectors.

Why this answer

If EEM applets are configured and enabled but not triggering despite events occurring, the most likely cause is that the applets failed to register due to a syntax error in the configuration. EEM applets must be successfully parsed and registered with the EEM server; a syntax error prevents registration, so the applet never runs. The engineer should check 'show event manager policy registered' to confirm.

Exam trap

The trap is assuming the EEM server or logging is at fault; the exam tests whether you know that syntax errors silently prevent applet registration, so you must verify with 'show event manager policy registered'.

How to eliminate wrong answers

Option B is wrong because the EEM server is confirmed running and the trigger events are occurring, so it is listening. Option C is wrong because if the logging level were set to emergencies only, the syslog events would not be generated at all, but the question states trigger events are occurring. Option D is wrong because 'event none' applets are manually triggered, but the question implies the applets are configured with event triggers (since events are occurring) — and 'event none' would not cause a failure to act on those events.

1270
MCQeasy

A network technician is configuring a Cisco IOS router to use SSH for remote management. The technician generates an RSA key pair with 2048 bits, configures a local username and password, and enables SSH version 2. However, when attempting to connect via SSH, the connection is refused. Which additional configuration is required on the VTY lines to allow SSH access?

A.login local
B.transport input all
C.transport input ssh
D.exec-timeout 0 0
AnswerC

The 'transport input ssh' command on the VTY lines restricts incoming connections to SSH only, which is the secure method. If no transport input is configured, the router may not accept any remote connections, causing the SSH connection to be refused. This command explicitly enables SSH and disables Telnet, satisfying the requirement.

Why this answer

To enable SSH on a Cisco IOS router, you must generate an RSA key pair, configure a local username and password, enable SSH version 2, and apply 'transport input ssh' on the VTY lines. Without this transport command, the router may not accept SSH connections, resulting in a refused connection. The other options either enable insecure protocols or do not address the transport mechanism.

Exam trap

The trap here is assuming that generating RSA keys and enabling SSH version 2 automatically enables SSH on the VTY lines; you must explicitly allow SSH transport.

1271
MCQeasy

A network technician is configuring a static route on a Cisco router to reach a remote network. The technician wants the route to be used only if the primary path fails. Which type of static route should be configured?

A.Floating static route
B.Directly connected static route
C.Recursive static route
D.Default static route
AnswerA

A floating static route is configured with a higher administrative distance than the primary route, so it is only installed in the routing table if the primary route fails. This makes it ideal as a backup path. The technician can specify an administrative distance greater than that of the dynamic routing protocol or the primary static route.

Why this answer

A floating static route uses a higher administrative distance to remain inactive until the primary route is lost. This allows it to serve as a backup. Default, recursive, and directly connected static routes do not provide this conditional failover behavior.

The floating static route is the correct choice for a backup path.

Exam trap

The trap here is confusing a floating static route with a default static route, thinking that a default route automatically acts as a backup.

1272
MCQmedium

A network engineer configured IP SLA 70 to monitor a remote site's LAN gateway (172.16.1.1) using ICMP echo. The IP SLA is linked to a track object that is used in a static route for a backup link. The engineer notices that the IP SLA state is 'Active', but the backup static route is installed in the routing table even when the primary route is available. What is the most likely cause?

A.The static route is configured without the 'track' keyword, so it is always installed regardless of the IP SLA state.
B.The IP SLA probe is failing intermittently, causing the track object to flap.
C.The primary route has a higher administrative distance than the static route.
D.The track object is configured with a delay that causes the static route to be installed prematurely.
AnswerA

Without the 'track' keyword binding the static route to the track object, the route is installed unconditionally; the IP SLA and track state are never consulted, so the backup route remains present even when the primary path is up.

Why this answer

If the static route is configured without the 'track' keyword, the track object has no effect on that route — the route is installed unconditionally whenever its administrative distance is lower than competing routes. The IP SLA being 'Active' only confirms the probe is running, not that the route is bound to it. The most likely cause is that the track was never attached to the static route statement.

Exam trap

300-410 often tests whether candidates realize that configuring IP SLA and a track object alone does nothing unless the static route explicitly references the track with the 'track' keyword.

How to eliminate wrong answers

Option B is wrong because an intermittent probe failure would show the IP SLA state flapping between Active and Inactive, and the question states the state is 'Active'. Option C is wrong because a higher administrative distance on the primary route would cause the backup to be preferred, but the scenario says the primary route is available and the backup is also installed — the issue is the backup being installed at all, not path preference. Option D is wrong because a track delay affects when the track transitions state, not whether the static route is bound to the track object in the first place.

1273
MCQmedium

A network engineer is troubleshooting an OSPFv3 network. Router R1 is an ABR connected to Area 0 and Area 1. Area 1 is configured as a totally stubby area. R1 is not injecting a default route into Area 1, and routers in Area 1 cannot reach external destinations. Which command should the engineer verify on R1 to ensure that a default route is generated into Area 1?

A.`summary-address` under the OSPFv3 process.
B.`area 1 stub no-summary` under the OSPFv3 process.
C.`default-information originate` under the OSPFv3 process.
D.`area 1 nssa no-summary` under the OSPFv3 process.
AnswerB

To configure a totally stubby area in OSPFv3, the ABR must have the `area 1 stub no-summary` command. This setting prevents the ABR from flooding type 3 summary LSAs into the area and automatically generates a default route (inter-area-prefix LSA) into the stub area. If this command is missing, the ABR will not inject a default route, and routers in Area 1 will lack a path to external destinations.

Why this answer

In OSPFv3, a totally stubby area is configured on the ABR with the `area <area-id> stub no-summary` command. This command blocks type 3 summary LSAs and causes the ABR to inject a default route (inter-area-prefix LSA) into the area. Without it, routers in the area have no default route and cannot reach external networks.

The engineer should verify that this command is present on R1.

Exam trap

The trap here is confusing stub area default route generation with the `default-information originate` command, which is used for external default routes, not intra-area default routes in stub areas.

1274
MCQmedium

A network engineer runs the following command on Router R1: R1# show route-map route-map FILTER_OSPF, permit, sequence 10 Match clauses: ip address prefix-list OSPF_ROUTES Set clauses: Policy routing matches: 0 packets, 0 bytes route-map FILTER_OSPF, deny, sequence 20 Match clauses: Set clauses: Policy routing matches: 0 packets, 0 bytes Based on this output, which statement is correct?

A.The route-map will permit all routes that match the prefix-list OSPF_ROUTES and deny all others.
B.The route-map will permit all routes because sequence 20 has no match clause.
C.The route-map is used for policy-based routing and has matched 0 packets.
D.The route-map will deny only routes matching the prefix-list OSPF_ROUTES.
AnswerA

The implicit deny at sequence 20 rejects every route failing the prefix-list match, so only prefixes listed in OSPF_ROUTES are redistributed. The zero match counters merely reflect that no redistribution has occurred yet, not a configuration fault. This satisfies the stem's requirement to identify the route-map's filtering behaviour.

Why this answer

The route-map FILTER_OSPF has a permit sequence 10 matching prefix-list OSPF_ROUTES, followed by a deny sequence 20 with no match clause. In Cisco IOS, a route-map sequence with no match clause matches everything, so sequence 20 acts as an implicit deny-all for any route not matched by sequence 10. Therefore, routes matching OSPF_ROUTES are permitted, and all others are denied.

Exam trap

The trap here is confusing the 'Policy routing matches' counter (which applies only to PBR) with route-map filtering behavior, and misreading an empty deny sequence as a permit-all instead of a deny-all.

How to eliminate wrong answers

Option B is wrong because sequence 20 has no match clause, which means it matches all routes — combined with the deny action, it denies everything not already permitted by sequence 10. Option C is wrong because the 'Policy routing matches: 0 packets' counter refers to policy-based routing (PBR) via route-map on an interface, not to route redistribution or filtering — the route-map here is used for filtering, so the PBR counter is irrelevant. Option D is wrong because it inverts the logic: sequence 10 permits matching routes, and sequence 20 denies non-matching routes, not the other way around.

1275
MCQmedium

A network engineer runs the following command to troubleshoot a VRF-Lite IPsec issue: R1# show crypto ipsec transform-set vrf CUSTOMER_H Output: Transform set combined: { esp-aes 256 esp-sha-hmac } will negotiate = { Tunnel, } What does this output indicate?

A.The transform set uses ESP with AES 256 and SHA-HMAC in transport mode.
B.The transform set uses ESP with AES 256 and SHA-HMAC in tunnel mode.
C.The transform set uses AH with AES 256 and MD5.
D.The transform set does not specify any encryption or authentication.
AnswerB

Correct. The transform set includes esp-aes 256 and esp-sha-hmac, and will negotiate tunnel mode.

Why this answer

The 'show crypto ipsec transform-set vrf' command displays the IPsec transform set for a specific VRF. The output shows a transform set named 'combined' that uses ESP with AES 256-bit encryption and SHA-HMAC authentication. It will negotiate a tunnel mode (as opposed to transport mode).

Page 16

Page 17 of 19

Page 18