Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 1351–1401

1401 questions total · 19pages · All types, answers revealed

Page 18

Page 19 of 19

1351
MCQmedium

Consider the following partial configuration on a Cisco IOS-XE router: interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip nat inside ! interface GigabitEthernet0/1 ip address 203.0.113.1 255.255.255.0 ip nat outside ! ip nat inside source list 1 interface GigabitEthernet0/1 overload access-list 1 permit 192.168.1.0 0.0.0.255 What is the effect of this configuration?

A.All traffic from 192.168.1.0/24 is translated to 203.0.113.1 using PAT.
B.Only traffic from 192.168.1.1 is translated to 203.0.113.1 using PAT.
C.Traffic is translated using static NAT to 203.0.113.1.
D.The configuration is incomplete; a NAT pool is required for dynamic translation.
AnswerA

The inside source list matches 192.168.1.0/24, and the overload keyword multiplexes those hosts onto the outside interface address 203.0.113.1 using port address translation. Inside and outside interfaces are correctly designated, so translation occurs for all matching traffic.

Why this answer

The configuration uses an ACL (access-list 1) to match traffic from the 192.168.1.0/24 subnet, and the 'ip nat inside source list 1 interface GigabitEthernet0/1 overload' command translates all matching source IP addresses to the single IP address 203.0.113.1 (the outside interface IP) using Port Address Translation (PAT). This is a classic dynamic NAT overload configuration, where multiple internal hosts share one public IP by multiplexing on source ports.

Exam trap

Cisco often tests the distinction between 'ip nat inside source list <acl> interface <interface> overload' (dynamic PAT using the interface IP) and configurations that require a NAT pool or static mapping, leading candidates to mistakenly think a pool is mandatory for any dynamic translation.

How to eliminate wrong answers

Option B is wrong because the ACL permits the entire 192.168.1.0/24 subnet, not just the router's own interface IP 192.168.1.1; all hosts in that subnet are eligible for translation. Option C is wrong because static NAT requires the 'ip nat inside source static' command, not the 'overload' keyword, and the configuration here uses dynamic translation with PAT. Option D is wrong because when using 'interface' with 'overload', no NAT pool is required; the outside interface IP itself serves as the single translated address, and PAT handles port multiplexing.

1352
MCQmedium

A network engineer is deploying a site-to-site VPN between two Cisco IOS routers. The security policy requires that the peer identities be authenticated with certificates issued by an internal CA, and that the two peers negotiate a fresh keying channel for each new IKEv2 SA without relying on aggressive-mode pre-shared keys. Which IKEv2 configuration element must be present on both routers to satisfy the certificate-based authentication requirement?

A.crypto isakmp policy with authentication pre-share and a matching keyring
B.crypto ikev2 profile with authentication remote rsa-sig and authentication local rsa-sig
C.crypto pki server with grant auto and a registered local RSA keypair
D.crypto ikev2 keyring with a peer entry containing an RSA public key
AnswerB

Under the IKEv2 profile, the authentication local rsa-sig and authentication remote rsa-sig commands instruct the router to use RSA signatures backed by X.509 certificates for both its own identity and the peer's identity. Combined with a pki trustpoint referencing the internal CA, this satisfies the certificate-authentication policy and avoids pre-shared keys entirely.

Why this answer

Certificate-based IKEv2 authentication requires the IKEv2 profile to reference a PKI trustpoint and to specify rsa-sig for both local and remote authentication. The trustpoint supplies the CA chain and the router's own identity certificate, and rsa-sig makes the router present and verify X.509 signatures during the IKE_AUTH exchange. Pre-shared-key constructs, whether IKEv1 policies or IKEv2 keyrings, cannot meet a policy that mandates CA-issued certificates.

Exam trap

The trap here is assuming that because IKEv2 supports pre-shared keys, any IKEv2 authentication command satisfies a certificate requirement, when rsa-sig is what actually binds the profile to PKI credentials.

1353
MCQeasy

Which IPv6 FHS feature uses a 'device tracking' database to maintain reachability information for hosts?

A.RA Guard
B.DHCPv6 Guard
C.Device Tracking
D.PACL
AnswerC

IPv6 First Hop Security's device tracking feature builds and maintains a binding database of host reachability by snooping ND and DHCPv6 traffic, feeding that state to other FHS components such as IPv6 snooping and ND inspection to validate legitimate hosts.

Why this answer

Device Tracking is the correct answer because it is the IPv6 First Hop Security (FHS) feature that maintains a 'device tracking' database to monitor and store reachability information for hosts. This database tracks the IPv6 address, MAC address, and binding state of each host, enabling features like ND Inspection and DHCPv6 Guard to verify host reachability before forwarding traffic.

Exam trap

Cisco often tests the distinction between features that maintain the database (Device Tracking) versus features that use the database (e.g., DHCPv6 Guard, RA Guard), so the trap here is assuming that any FHS feature that interacts with host information must be the one that maintains the tracking database.

How to eliminate wrong answers

Option A is wrong because RA Guard is an IPv6 FHS feature that filters Router Advertisement messages to prevent rogue router attacks, but it does not maintain a device tracking database for host reachability. Option B is wrong because DHCPv6 Guard is an IPv6 FHS feature that filters DHCPv6 messages to block unauthorized DHCP servers, but it relies on the device tracking database rather than maintaining it. Option D is wrong because PACL (Port Access Control List) is a security feature used to filter traffic based on Layer 2 or Layer 3 criteria, but it is not an IPv6 FHS feature and does not maintain a device tracking database.

1354
MCQeasy

Which DHCP message type is used by a client to renew its lease before it expires?

A.DHCPREQUEST
B.DHCPDISCOVER
C.DHCPACK
D.DHCPRELEASE
AnswerA

DHCPREQUEST is sent unicast to the originating server to renew an existing lease at the T1 (50%) timer, before expiry. DHCPDISCOVER only locates new servers, and DHCPINFORM merely requests extra parameters without renewing, so DHCPREQUEST satisfies the pre-expiry renewal constraint.

Why this answer

When a DHCP client wants to renew its existing lease before it expires, it sends a unicast DHCPREQUEST message directly to the DHCP server that originally granted the lease. This is part of the renewal process defined in RFC 2131, where the client transitions from the BOUND state to the RENEWING state and uses the server's IP address to request an extension of the lease time.

Exam trap

Cisco often tests the distinction between the unicast DHCPREQUEST used for lease renewal and the broadcast DHCPREQUEST used during the initial DORA process, leading candidates to mistakenly think DHCPDISCOVER is involved in renewal.

How to eliminate wrong answers

Option B (DHCPDISCOVER) is wrong because it is used by a client to locate available DHCP servers when it has no current lease or is starting from the INIT state, not for renewing an existing lease. Option C (DHCPACK) is wrong because it is a server-to-client response that acknowledges and grants the lease or renewal, not a message sent by the client. Option D (DHCPRELEASE) is wrong because it is used by a client to voluntarily relinquish its IP address lease to the server, not to renew it.

1355
MCQhard

An engineer configures RSPAN VLAN 100 on two switches to monitor traffic across the network. The remote switch shows the RSPAN source as active, but the destination switch receives no mirrored traffic. What is the most likely cause?

A.The RSPAN VLAN is not allowed on a trunk link between the source and destination switches.
B.The RSPAN VLAN is configured as a native VLAN on the trunk, causing VLAN tagging issues.
C.The destination switch has a different RSPAN VLAN ID configured for the session.
D.The source switch has not enabled RSPAN globally with the 'monitor session' command.
AnswerA

RSPAN carries mirrored frames inside the dedicated RSPAN VLAN, so that VLAN must be permitted across every trunk on the path. If it is pruned or absent from the trunk, the destination switch never receives the mirrored traffic despite the source reporting active.

Why this answer

For RSPAN to work, the RSPAN VLAN must be carried across every trunk link between the source switch and the destination switch. If the RSPAN VLAN is not in the allowed VLAN list on an intermediate trunk, the mirrored frames are dropped in transit, so the destination receives nothing even though the source session shows active. This is the classic RSPAN failure mode.

Exam trap

The trap is focusing on the source switch configuration because it reports 'active' — candidates overlook that RSPAN is a multi-switch path and that a missing VLAN on an intermediate trunk silently drops all mirrored traffic.

How to eliminate wrong answers

Option B is wrong because configuring the RSPAN VLAN as native is not a standard cause of total traffic loss — RSPAN VLANs are typically dedicated and untagged handling would not silently drop all mirrored frames in the way described. Option C is wrong because if the destination used a different RSPAN VLAN ID, the session configuration itself would be inconsistent and the source would not report active against the same VLAN. Option D is wrong because RSPAN is enabled per monitor session on the source switch, not via a global 'monitor session' enable command, and the source already shows active.

1356
MCQhard

A network engineer is troubleshooting a DMVPN Phase 3 network using Cisco IOS XE routers. The hub router (Hub1) has a public IP of 203.0.113.1 and is configured with `tunnel mode gre multipoint`. Spoke routers are behind NAT devices. Spoke1 cannot establish a direct spoke-to-spoke tunnel with Spoke2, although both can reach the hub. Which technology must be enabled on the hub to allow spoke-to-spoke direct tunnels in this scenario?

A.NHRP shortcut
B.Multicast routing
C.NHRP redirect
D.IPsec tunnel protection
AnswerC

NHRP redirect allows the hub to inform spokes about a more optimal path to another spoke. When Spoke1 sends traffic to Spoke2 via the hub, the hub sends an NHRP redirect message, prompting Spoke1 to initiate a direct tunnel. This is essential for Phase 3 DMVPN, especially with NAT, as it enables dynamic spoke-to-spoke tunnels without preconfiguration.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to notify spokes of a better path to another spoke. When Spoke1 sends traffic to Spoke2 via the hub, the hub sends an NHRP redirect, and Spoke1 then initiates a direct tunnel using NHRP shortcut. This is critical when spokes are behind NAT, as the hub facilitates the initial resolution and redirect.

Exam trap

The trap here is confusing NHRP redirect (hub) with NHRP shortcut (spoke) and assuming that IPsec or multicast alone can enable spoke-to-spoke tunnels.

1357
MCQhard

A large enterprise network is experiencing intermittent SNMP polling failures from the NMS to router R2. R1 and R2 are connected via a serial link running OSPF. R1 has the following relevant configuration: snmp-server community public RO, snmp-server community private RW, snmp-server trap-source Loopback0, snmp-server enable traps ospf. R2 shows: debug ip packet shows packets from NMS (10.1.1.100) to R2's Loopback0 (10.2.2.2) being dropped with 'access-list violation'. No ACL is applied to any interface on R2. What is the root cause?

A.An ACL is applied to the SNMP community string that does not permit the NMS IP address.
B.OSPF network type mismatch between R1 and R2 causes routing blackhole.
C.The NMS is using SNMPv3 with incorrect credentials, causing authentication failure.
D.R2's loopback interface is not advertised into OSPF, making it unreachable.
AnswerA

When the `snmp-server community` command includes an access-list, the router filters incoming SNMP requests by source IP before processing them. The debug output showing 'access-list violation' (or similar) indicates the SNMP packet from the NMS arrived at R2 but was dropped because the NMS's address is not permitted by that ACL. This directly prevents SNMP polling, even though IP connectivity is intact, making the ACL the root cause.

Why this answer

The debug output on R2 shows packets from the NMS (10.1.1.100) to R2's Loopback0 (10.2.2.2) being dropped with 'access-list violation'. Since no ACL is applied to any interface on R2, the only remaining ACL that could cause this is an SNMP community ACL. The SNMP community string 'public' or 'private' can have an optional ACL applied via the 'snmp-server community <string> [view <view-name>] [ro|rw] [acl-number]' command.

If that ACL does not permit the NMS IP address (10.1.1.100), the router will silently drop SNMP packets from that source, even though no interface ACL exists. This matches the symptom exactly.

Exam trap

Cisco often tests the concept that ACLs can be applied to SNMP community strings (not just interfaces), and candidates mistakenly assume 'no ACL on interfaces' means no ACL is dropping traffic, overlooking the community-string-level ACL as the root cause.

How to eliminate wrong answers

Option B is wrong because an OSPF network type mismatch (e.g., point-to-point vs broadcast) can cause adjacency issues or routing blackholes, but it would not generate an 'access-list violation' debug message; that message is specific to ACL-based drops. Option C is wrong because the NMS is using SNMPv2c (as indicated by the community strings 'public' and 'private' in R1's configuration), not SNMPv3; authentication failures in SNMPv3 would produce different debug messages (e.g., 'authFailure') and would not be described as 'access-list violation'. Option D is wrong because if R2's loopback interface were not advertised into OSPF, the NMS would not be able to reach it at all, resulting in 'destination unreachable' or timeouts, not an 'access-list violation' drop; the debug shows the packet is being received by R2 and then dropped by an ACL, proving reachability is fine.

1358
Multi-Selectmedium

Which TWO statements about IPv6 Neighbor Discovery (ND) Inspection are true? (Choose TWO.)

Select 2 answers
A.It validates Neighbor Solicitation and Neighbor Advertisement messages against the IPv6 snooping binding table.
B.It can be configured to rate-limit ND packets on a per-interface basis.
C.It prevents rogue DHCPv6 servers from assigning malicious addresses.
D.It uses a prefix list to determine which source addresses are allowed.
E.It is enabled globally and cannot be applied on a per-interface basis.
AnswersA, B

Neighbor Discovery Inspection builds a snooping binding table from DHCPv6 or static entries, then filters Neighbor Solicitation and Neighbor Advertisement messages whose source addresses lack a matching binding, blocking spoofed link-layer address claims. This satisfies the stem's requirement for statements accurately describing ND Inspection behaviour on Cisco switches.

Why this answer

Option A is correct because IPv6 ND Inspection builds a binding table (IPv6 address to MAC address mappings learned from DHCPv6 snooping or ND messages) and validates Neighbor Solicitation and Neighbor Advertisement messages against that table, dropping messages whose source link-layer address does not match the binding. Option B is correct because ND Inspection supports per-interface configuration, including the ability to rate-limit ND packets (using the ipv6 nd inspection limit rate command) to mitigate ND flooding and DoS attacks. Option C is not correct because blocking rogue DHCPv6 servers is the function of DHCPv6 Guard, not ND Inspection.

Option D is not correct because ND Inspection relies on the IPv6 snooping binding table rather than a prefix list to validate addresses. Option E is not correct because ND Inspection is configured on a per-interface basis (with a global policy applied to interfaces), not globally only.

Exam trap

Cisco often tests the distinction between IPv6 First Hop Security features, and the trap here is confusing ND Inspection (which validates ND messages) with DHCPv6 Guard (which blocks rogue DHCPv6 servers) or RA Guard (which uses prefix lists).

1359
MCQmedium

Examine this OSPF configuration snippet on router R3: router ospf 1 network 10.1.1.0 0.0.0.255 area 0 default-information originate always What is the effect of the default-information originate always command?

A.R3 will advertise a default route into OSPF only if it has a default route in its routing table.
B.R3 will unconditionally advertise a default route into OSPF as an external LSA type 5.
C.R3 will advertise a default route only if it is an ASBR.
D.The command is invalid because default-information originate requires a route-map.
AnswerB

The always keyword removes the requirement for a default route in R3's routing table. R3 therefore injects a default route into the OSPF domain unconditionally, flooding it as an AS-external LSA type 5 throughout the area.

Why this answer

The 'default-information originate always' command in OSPF causes the router to unconditionally advertise a default route (0.0.0.0/0) into OSPF as an external Type 5 LSA, regardless of whether the router itself has a default route in its routing table. Without the 'always' keyword, the router would only advertise a default route if one exists in its routing table. This command is used to inject a default route into the OSPF domain from an ASBR.

Exam trap

The trap is forgetting the effect of the 'always' keyword; candidates often choose the option that describes the default behavior without 'always', which is conditional advertisement.

How to eliminate wrong answers

Option A is wrong because that describes the behavior without the 'always' keyword; with 'always', the router does not need a default route in its routing table. Option C is wrong because while the router must be an ASBR to originate external LSAs, the command itself does not conditionally advertise based on ASBR status; the ASBR status is a prerequisite, but the effect is unconditional advertisement. Option D is wrong because the command is valid without a route-map; a route-map is optional and can be used to control which routes are advertised, but it is not required.

1360
MCQhard

An engineer configures CoPP on a router running EIGRP. The policy includes a class-map matching EIGRP traffic with a police rate of 1000 pps. After applying the policy, EIGRP neighbors form but occasionally go active and become stuck-in-active (SIA). Which is the most likely explanation?

A.EIGRP uses multicast, and CoPP cannot police multicast traffic.
B.The police rate in pps is too low, causing EIGRP reliable packets (queries/replies) to be dropped, leading to SIA.
C.CoPP only affects incoming traffic, but EIGRP SIA is caused by outgoing packet drops.
D.EIGRP uses TCP, and CoPP only polices UDP.
AnswerB

CoPP polices matched traffic in packets per second. EIGRP relies on reliable transport for queries and replies, so a 1000 pps limit drops those retransmissions under load, preventing acknowledgement and leaving neighbours stuck-in-active. Raising the rate restores reliable delivery.

Why this answer

EIGRP uses RTP (Reliable Transport Protocol) for certain packets like queries and replies. These reliable packets require acknowledgment; if the CoPP police rate of 1000 pps is too low, EIGRP queries or replies may be dropped. Missing acknowledgments cause the neighbor to be declared active, and if the query process is not completed within the active timer, the route becomes stuck-in-active (SIA).

Exam trap

The trap here is that candidates may assume CoPP only affects incoming traffic or that EIGRP uses TCP, but the key is understanding that EIGRP's reliable packets (queries/replies) are sensitive to drops, and a low pps police rate can cause SIA.

How to eliminate wrong answers

Option A is wrong because CoPP can police multicast traffic; EIGRP uses multicast address 224.0.0.10, and CoPP class-maps can match this traffic using access-lists or protocol matching. Option C is wrong because CoPP can police both incoming and outgoing control plane traffic; EIGRP SIA is typically caused by dropped incoming reliable packets (queries/replies) or missing acknowledgments, not solely by outgoing drops. Option D is wrong because EIGRP does not use TCP; it uses its own Reliable Transport Protocol (RTP) over IP protocol 88, and CoPP can police any IP protocol, not just UDP.

1361
MCQhard

A network engineer runs the following command to troubleshoot an MPLS L3VPN issue: R1# show bgp vpnv4 vrf CUSTOMER-A 10.1.1.0/24 Output: BGP routing table entry for 10.1.1.0/24, version 10 Paths: (1 available, best #1, table CUSTOMER-A) Advertised to update-groups: 1 Refresh Epoch 1 Local 0.0.0.0 from 0.0.0.0 (10.0.0.1) Origin incomplete, metric 0, localpref 100, weight 32768, valid, sourced, best Extended Community: RT:100:100 mpls labels in/out nolabel/nolabel What does this output indicate?

A.The route is locally originated and has no MPLS label
B.The route is learned from a BGP peer
C.The route has an MPLS label of 100
D.The route is not best
AnswerA

The path shows weight 32768, origin incomplete and 'Local' with next hop 0.0.0.0, indicating the route was originated on this router rather than learned via MP-BGP. The 'mpls labels in/out nolabel/nolabel' field confirms no label is assigned.

Why this answer

This shows a VPNv4 route for prefix 10.1.1.0/24 in VRF CUSTOMER-A. The path is local (sourced from this router), with next hop 0.0.0.0, and the route is valid and best. The extended community is RT:100:100.

The mpls labels show nolabel/nolabel, meaning no MPLS label is assigned for this prefix, which could indicate a problem if labels are expected.

1362
MCQmedium

A network engineer is configuring OSPF on a Cisco router. The router has two interfaces in Area 0: GigabitEthernet0/0 (10.1.1.1/24) and GigabitEthernet0/1 (10.2.2.1/24). The engineer wants to ensure that the router ID is always 10.1.1.1, regardless of interface status. Which command should be used?

A.router ospf 1 then router-id 10.1.1.1
B.ospf router-id 10.1.1.1
C.router-id 10.1.1.1
D.ip ospf router-id 10.1.1.1
AnswerA

Entering OSPF configuration mode with 'router ospf 1' and then issuing 'router-id 10.1.1.1' explicitly sets the router ID. This method is preferred because it does not depend on interface IP addresses, ensuring the router ID remains 10.1.1.1 even if interfaces change or go down.

Why this answer

The engineer needs a stable OSPF router ID that remains 10.1.1.1 regardless of interface status. The only way to guarantee this is to explicitly configure the router ID under the OSPF process using the 'router-id' command. Relying on interface IP addresses can lead to changes if interfaces are removed or shut down.

Exam trap

The trap here is assuming that the highest loopback or interface IP will always be used as the router ID, but explicit configuration overrides that and ensures persistence.

1363
MCQmedium

A network engineer is configuring a Cisco IOS router to use Policy-Based Routing (PBR) to forward traffic from a specific subnet to a next-hop address. The route-map is named PBR_MAP, and the interface is GigabitEthernet0/0. Which command sequence correctly applies the route-map to the interface for incoming packets?

A.interface GigabitEthernet0/0 ip route-cache policy
B.route-map PBR_MAP permit 10 match ip address 101 set ip next-hop 10.1.1.1 interface GigabitEthernet0/0 ip policy route-map PBR_MAP
C.interface GigabitEthernet0/0 ip route-map PBR_MAP in
D.interface GigabitEthernet0/0 ip policy route-map PBR_MAP
AnswerD

The ip policy route-map command, configured under the interface, enables PBR for packets arriving on that interface. The route-map defines the match and set criteria that determine how packets are handled. This is the correct and standard method to apply PBR on Cisco IOS routers for policy routing of ingress traffic.

Why this answer

To apply PBR on an interface, the ip policy route-map command is used, referencing the route-map name. This command enables policy routing for packets entering the interface. The other options either use incorrect syntax or include unnecessary configuration details.

The correct application is straightforward.

Exam trap

The trap here is confusing the command to apply a route-map for PBR with commands used for other features, or including the route-map definition when only the application command is asked.

1364
MCQmedium

Examine this IP SLA configuration on router R5: ip sla 50 icmp-echo 10.20.20.1 source-ip 192.168.10.1 frequency 10 ip sla schedule 50 life forever start-time now What is the effect of this configuration?

A.It will continuously monitor reachability to 10.20.20.1 from source 192.168.10.1.
B.It will stop after 10 successful replies.
C.It will measure jitter between the two IPs.
D.It will only work if 10.20.20.1 is directly connected.
AnswerA

The icmp-echo probe targets 10.20.20.1 with source 192.168.10.1, and frequency 10 repeats it every ten seconds. Scheduling with life forever and start-time now begins immediately and never expires, so reachability is monitored continuously rather than for a bounded period.

Why this answer

The IP SLA configuration defines an ICMP echo operation (number 50) that sends pings to 10.20.20.1 from source IP 192.168.10.1 every 10 seconds. The 'ip sla schedule 50 life forever start-time now' command starts the operation immediately and keeps it running indefinitely, so it continuously monitors reachability.

Exam trap

The trap is misinterpreting the 'frequency 10' as a limit of 10 probes, or thinking that 'life forever' means it stops after some time, when it actually means indefinite operation.

How to eliminate wrong answers

Option B is wrong because the 'life forever' parameter means the operation never expires, and there is no setting to stop after a number of replies. Option C is wrong because the operation type is 'icmp-echo', which measures reachability and round-trip time, not jitter (jitter requires UDP jitter operations). Option D is wrong because IP SLA ICMP echo can monitor any reachable IP address, not just directly connected ones; routing handles the path.

1365
MCQmedium

A network engineer is configuring a Cisco IOS XE router as a Dynamic Host Configuration Protocol (DHCP) server for a guest wireless subnet. The router must dynamically allocate addresses from the 192.168.50.0/24 pool, but the first 30 addresses must be reserved for static assignment to access points and controllers. Which command must be issued to prevent the DHCP server from offering those addresses?

A.ip dhcp excluded-address 192.168.50.1 192.168.50.30
B.ip dhcp pool GUEST network 192.168.50.0 255.255.255.224
C.ip dhcp excluded-address 192.168.50.1 192.168.50.30 255.255.255.0
D.ip dhcp pool GUEST address 192.168.50.1 192.168.50.30
AnswerA

This command globally excludes the range 192.168.50.1 through 192.168.50.30 from any DHCP pool on the router. In this scenario, it ensures the server never offers those addresses, leaving them available for manual static configuration on access points and controllers while the remaining addresses in 192.168.50.0/24 are dynamically leased.

Why this answer

The ip dhcp excluded-address command with a start and end address prevents the Cisco IOS XE DHCP server from offering that range from any pool. This correctly reserves the first 30 addresses for static assignment while allowing the rest of the /24 to be leased dynamically. Other commands either restrict the pool incorrectly, introduce invalid syntax, or create static bindings instead of exclusions.

Exam trap

The trap here is assuming that a subnet mask can be appended to the ip dhcp excluded-address command or that the pool network statement can exclude addresses.

1366
MCQhard

A network engineer is troubleshooting a DMVPN Phase 3 deployment on a Cisco IOS XE hub. Spokes use NHRP to register with the hub and have working mGRE tunnels to the hub. The design requires that spoke-to-spoke traffic be sent directly between spokes without transiting the hub's data path. The engineer observes that all spoke-to-spoke packets still traverse the hub even though spoke registration and routing are correct. Which configuration change on the hub is required to enable direct spoke-to-spoke forwarding?

A.Configure ip nhrp redirect on the hub so the hub can inform the source spoke that a better path exists, triggering an NHRP resolution for the destination spoke.
B.Configure ip nhrp shortcut on the hub so the hub can cache the destination spoke's NBMA mapping and forward directly.
C.Configure ip nhrp map multicast dynamic on the hub so the hub can dynamically learn the NBMA addresses of all registering spokes.
D.Configure no ip next-hop-self eigrp under the tunnel interface's routing process so the hub does not rewrite the next hop for EIGRP routes.
AnswerA

In DMVPN Phase 3, the hub uses NHRP redirect to notify a source spoke that traffic it sent through the hub could be sent directly. The redirect causes the source spoke to issue an NHRP resolution request for the destination spoke's NBMA address, after which it builds a direct tunnel. Without ip nhrp redirect on the hub, spokes keep forwarding through the hub even though they could shortcut.

Why this answer

DMVPN Phase 3 achieves direct spoke-to-spoke forwarding by combining hub-side NHRP redirect with spoke-side NHRP shortcut. When a spoke sends traffic through the hub, the hub issues an NHRP redirect telling the source spoke a better path exists. The spoke then resolves the destination's NBMA address and installs a shortcut route, allowing direct forwarding.

Without the hub redirect, spokes continue to hairpin traffic through the hub.

Exam trap

The trap here is confusing the hub-side NHRP redirect feature with the spoke-side NHRP shortcut feature, or assuming multicast mapping commands enable direct spoke-to-spoke paths.

1367
MCQhard

An engineer configures iBGP between two routers in the same AS. The engineer notices that routes learned from one iBGP neighbor are not being advertised to another iBGP neighbor, even though the next-hop is reachable. The engineer verifies that the BGP session is established and that the routes are present in the BGP table. Which is the most likely explanation?

A.iBGP split-horizon rule prevents advertising iBGP-learned routes to other iBGP neighbors
B.The next-hop-self command is required for iBGP
C.The BGP synchronization rule is enabled
D.The routes are not valid because the next-hop is not reachable
AnswerA

iBGP enforces split-horizon: a route learned from one iBGP peer is never re-advertised to another iBGP peer within the same AS. This prevents loops, so the second neighbour receives nothing. Routes must be reflected or confederated to propagate.

Why this answer

The most likely explanation is the iBGP split-horizon rule, which states that routes learned from an iBGP neighbor are not advertised to other iBGP neighbors. This is a fundamental rule to prevent routing loops within an AS. Therefore, even though the next-hop is reachable and the session is established, the route will not be propagated to another iBGP peer unless a route reflector or full mesh is used.

Exam trap

300-410 often tests the iBGP split-horizon rule: candidates may incorrectly blame next-hop reachability or synchronization, but the core issue is that iBGP does not re-advertise routes learned from other iBGP peers.

How to eliminate wrong answers

Option B is wrong because next-hop-self is not required for iBGP in general; it is used in specific scenarios (e.g., when the next-hop is not reachable via IGP), but here the next-hop is reachable, so it's not the issue. Option C is wrong because the BGP synchronization rule (which prevents advertising iBGP routes until they are known via IGP) is disabled by default on modern Cisco routers and would not cause this specific symptom if the next-hop is reachable. Option D is wrong because the question states the next-hop is reachable, so the routes are valid; the issue is not validity but advertisement.

1368
MCQmedium

A network administrator is implementing MPLS Layer 3 VPNs. The administrator wants to ensure that customer routes are not leaked between different VRFs on the same PE router. Which mechanism should be used to isolate the VRFs?

A.BGP communities
B.Route distinguishers
C.Route targets
D.MPLS labels
AnswerC

Route targets are extended BGP communities used to control the import and export of routes between VRFs. By assigning unique route targets to each VRF, you ensure that routes from one VRF are not imported into another. This provides the necessary isolation. Without proper route target configuration, routes could leak. Therefore, route targets are the correct mechanism.

Why this answer

Route targets are extended BGP communities that define which VRFs can import and export routes. By configuring distinct route targets for each VRF, you control route distribution and prevent leaking. Route distinguishers only make prefixes unique, MPLS labels are for forwarding, and standard BGP communities are not specific to VRF isolation.

Exam trap

The trap here is confusing route distinguishers with route targets; RDs make prefixes unique, but route targets control import/export.

1369
MCQeasy

A network technician is configuring a static route on a Cisco IOS router. The requirement is to forward all traffic destined to the 192.168.1.0/24 network to the next-hop IP address 10.1.1.1. Which command accomplishes this?

A.ip route 192.168.1.0 255.255.255.0 10.1.1.1 name STATIC
B.ip route 192.168.1.0 255.255.255.0 10.1.1.1 255
C.ip route 192.168.1.0 255.255.255.0 10.1.1.1 1
D.ip route 192.168.1.0 255.255.255.0 10.1.1.1
AnswerD

This command correctly configures a static route for the 192.168.1.0/24 network with a next-hop of 10.1.1.1. The subnet mask 255.255.255.0 corresponds to /24, and the next-hop is specified as an IP address. This is the standard syntax for a static route on Cisco IOS.

Why this answer

The standard syntax for a static route on Cisco IOS is 'ip route prefix mask next-hop'. The command 'ip route 192.168.1.0 255.255.255.0 10.1.1.1' correctly specifies the destination network, subnet mask, and next-hop IP address. Adding a distance metric or name is optional and not required for basic functionality.

Exam trap

The trap here is overcomplicating the command by adding unnecessary parameters like a distance metric or name when the basic syntax suffices.

1370
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 dhcp binding Client: FE80::1 DUID: 0003000100AABBCCDDEE Username: unknown IA NA: IA ID 0x00010001, T1 302400, T2 483840 Address: 2001:DB8:1::100/128 Preferred lifetime 604800, valid lifetime 2592000 Expires at Sep 15 2024 12:00 PM (2592000 seconds) Based on this output, which statement is correct?

A.The client has been assigned an IPv6 address via DHCPv6.
B.The client is using SLAAC instead of DHCPv6.
C.The client's lease has expired.
D.The client is not authorized.
AnswerA

The `show ipv6 dhcp binding` output confirms stateful DHCPv6 address assignment: the server holds a binding for client FE80::1, with DUID, IA NA, and a leased address (2001:DB8:1::100/128) plus T1/T2 timers and lifetimes. Stateless DHCPv6 supplies only options, never address bindings, so the constraint of an assigned address is satisfied.

Why this answer

The output shows a DHCPv6 binding entry with an IA NA (Identity Association for Non-temporary Addresses) containing an assigned IPv6 address (2001:DB8:1::100/128) along with preferred and valid lifetimes. This confirms that the client with DUID 0003000100AABBCCDDEE successfully obtained an IPv6 address via stateful DHCPv6, not through SLAAC or any other method.

Exam trap

Cisco often tests the distinction between stateful DHCPv6 and SLAAC by showing a DHCPv6 binding output, leading candidates to mistakenly think SLAAC is in use when the presence of an IA NA and assigned address clearly indicates DHCPv6.

How to eliminate wrong answers

Option B is wrong because the output explicitly shows a DHCPv6 binding with an IA NA and assigned address, which is not present in SLAAC (Stateless Address Autoconfiguration) where addresses are derived from router advertisements and no DHCPv6 binding exists. Option C is wrong because the lease has not expired; the output shows a valid lifetime of 2592000 seconds with an expiration date of Sep 15 2024, indicating the lease is still active. Option D is wrong because the binding entry exists with an assigned address, meaning the client is authorized; an unauthorized client would not have a binding entry or would show a different status.

1371
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip sla statistics 1 Round Trip Time (RTT) for Index 1 Latest RTT: 200 ms Latest RTT (milliseconds): 200 Latest RTT (microseconds): 200000 Number of successes: 50 Number of failures: 10 Operation time to live: Forever Output: Over threshold Based on this output, which statement is correct?

A.The IP SLA operation has failed due to a timeout.
B.The latest RTT has exceeded the configured threshold value.
C.The IP SLA operation is not reachable and has been disabled.
D.The IP SLA responder is not configured on the target device.
AnswerB

The statistics show 'Output: Over threshold', meaning the measured latest RTT of 200 ms exceeded the configured threshold value for that IP SLA operation. Successes and failures alone do not trigger this status; the threshold breach does.

Why this answer

The 'Output: Over threshold' line indicates that the latest RTT exceeded the configured threshold. The number of failures (10) suggests some probes failed, but the key clue is the threshold violation. This does not necessarily mean the operation is down; it means a threshold event occurred.

1372
MCQmedium

A network engineer runs the following command to verify NetFlow export destination: R1# show ip flow export Flow export v9 is enabled for main cache Export source and destination details : VRF ID : Default Destination(1) 192.168.1.100 (2055) Source IP 10.0.0.1 Origin AS 65000 Peer AS 65001 Mask for source 255.255.255.255 Mask for destination 255.255.255.255 Version 9 flow records 1234 flows exported in 567 udp datagrams 0 flows failed due to lack of export packet 0 export packets were sent up to process level 0 export packets were dropped due to no fib 0 export packets were dropped due to adjacency issues 0 export packets were dropped due to fragmentation failures 0 export packets were dropped due to encapsulation fixup failures What does this output indicate?

A.NetFlow export is failing due to adjacency issues.
B.NetFlow export is successful with 1234 flows exported and no errors.
C.NetFlow is using version 5 export.
D.The export destination is not configured.
AnswerB

The counters confirm 1234 flows exported in 567 UDP datagrams with zero failures across every error category, including no-fib, adjacency, fragmentation and encapsulation drops. This demonstrates the NetFlow v9 export to 192.168.1.100 on port 2055 is functioning without loss.

Why this answer

The output shows '1234 flows exported in 567 udp datagrams' and all error counters are zero, indicating successful export. The destination is 192.168.1.100 on port 2055, and version 9 is used. Therefore, NetFlow export is working without errors.

Exam trap

300-410 often tests reading show command output; candidates may misinterpret the counters or overlook that all error counters are zero.

How to eliminate wrong answers

Option A is wrong because the output shows '0 export packets were dropped due to adjacency issues'. Option C is wrong because the output states 'Flow export v9 is enabled'. Option D is wrong because the destination is clearly configured as 192.168.1.100 (2055).

1373
MCQhard

A network engineer is troubleshooting IPv6 DMVPN phase 2 spoke-to-spoke tunnel failures. Spoke routers are able to communicate with the hub, but direct spoke-to-spoke traffic is not working. Router R1 (spoke) has the following relevant configuration: interface Tunnel0 ipv6 address 2001:DB8:1::1/64 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ipv6 nhrp network-id 1 ipv6 nhrp nhs 2001:DB8:1::2 ipv6 nhrp map multicast dynamic ! Router R2 (hub) shows: show ipv6 nhrp brief output indicates that both spokes are registered. What is the root cause?

A.The tunnel mode is multipoint, but the spokes need to be configured with 'tunnel mode gre ip' for direct communication.
B.The hub is missing the 'ipv6 nhrp redirect' command, and the spokes are missing 'ipv6 nhrp shortcut'.
C.The spokes have different NHRP network IDs, preventing registration.
D.The IPv6 addresses on the tunnel interfaces are in different subnets.
AnswerB

Phase 2 spoke-to-spoke tunnels require the hub to send NHRP redirects and spokes to install shortcuts. Without 'ipv6 nhrp redirect' on the hub and 'ipv6 nhrp shortcut' on spokes, spokes cannot learn direct paths, so traffic remains hub-routed.

Why this answer

In DMVPN Phase 2, spoke-to-spoke traffic requires the hub to send NHRP redirect messages and the spokes to use NHRP shortcuts. Without 'ipv6 nhrp redirect' on the hub and 'ipv6 nhrp shortcut' on the spokes, the spokes will forward all inter-spoke traffic through the hub instead of establishing a direct tunnel. The hub's NHRP brief shows both spokes are registered, confirming NHRP registration works, but the missing redirect/shortcut mechanism prevents direct spoke-to-spoke communication.

Exam trap

Cisco often tests the distinction between DMVPN phases, and the trap here is that candidates assume NHRP registration alone enables spoke-to-spoke communication, overlooking the mandatory redirect/shortcut commands for Phase 2.

How to eliminate wrong answers

Option A is wrong because 'tunnel mode gre multipoint' is correct for DMVPN Phase 2 spokes; changing to 'tunnel mode gre ip' would disable multipoint and prevent dynamic spoke-to-spoke tunnels. Option B is correct as explained. Option C is wrong because the spokes are registered with the hub, which requires matching NHRP network IDs; different network IDs would prevent registration entirely.

Option D is wrong because the tunnel interfaces share the same /64 subnet (2001:DB8:1::/64), and IPv6 addressing is not the issue since spoke-to-hub communication works.

1374
MCQmedium

A network engineer is configuring a GRE tunnel between two Cisco IOS-XE routers to transport multicast traffic. The engineer notices that multicast packets are not being forwarded through the tunnel. Which action should the engineer take to enable multicast over the GRE tunnel?

A.Increase the tunnel MTU to accommodate multicast packets, as fragmentation prevents multicast forwarding.
B.Configure the tunnel mode to gre multipoint to support multicast.
C.Enable IP multicast routing globally and configure PIM on the tunnel interface and the physical interface.
D.Set the tunnel interface to ip pim sparse-dense-mode and enable ip multicast-routing on the physical interface only.
AnswerC

GRE tunnels can carry multicast traffic if multicast routing is enabled. You must enable ip multicast-routing globally and configure PIM (e.g., PIM sparse-mode) on both the tunnel interface and the underlying physical interface. This allows multicast packets to be encapsulated and forwarded through the tunnel. Without PIM on the tunnel, multicast traffic will not be routed.

Why this answer

To transport multicast over a GRE tunnel, multicast routing must be enabled globally, and PIM must be configured on both the tunnel interface and the physical interface. This allows the router to forward multicast packets into the tunnel and out the physical interface. The other options either misconfigure PIM, use an unnecessary tunnel mode, or address an unrelated MTU issue.

Exam trap

The trap here is assuming that GRE tunnels automatically carry multicast traffic, when in fact multicast routing and PIM must be explicitly enabled on both the tunnel and physical interfaces.

1375
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip eigrp topology all-links EIGRP-IPv4 Topology Table for AS(100)/ID(192.168.1.1) Codes: P - Passive, A - Active, U - Update, Q - Query, R - Reply, r - reply Status, s - sia Status P 10.10.10.0/24, 1 successors, FD is 28160, Qos: 0 via 10.1.1.2 (28160/28160), GigabitEthernet0/0 via 10.2.2.2 (28672/28160), GigabitEthernet0/1 P 10.20.20.0/24, 1 successors, FD is 28160, Qos: 0 via 10.2.2.2 (28160/28160), GigabitEthernet0/1 via 10.3.3.2 (28672/28160), GigabitEthernet0/2 Based on this output, which statement is correct?

A.The network has redundant paths with feasible successors for both routes.
B.The route to 10.20.20.0/24 has no feasible successor.
C.The FD for 10.10.10.0/24 is 28672.
D.The route to 10.10.10.0/24 is in Active state.
AnswerB

This is correct. The feasibility condition requires RD < FD. For 10.20.20.0/24, both paths have RD = 28160 equal to FD, so they are not feasible successors. Thus there is no feasible successor.

Why this answer

The EIGRP feasibility condition requires the reported distance (RD) to be strictly less than the feasible distance (FD) for a path to be a feasible successor. In the output, for route 10.20.20.0/24, the FD is 28160, and both paths have an RD of 28160, which equals the FD, not less. Therefore, no feasible successor exists for this route.

Option A is incorrect because neither route has a feasible successor. Option C is incorrect because the FD for 10.10.10.0/24 is 28160, not 28672. Option D is incorrect because the route is marked 'Passive', not 'Active'.

Exam trap

Cisco tests the EIGRP feasibility condition: a path is a feasible successor only if its reported distance (RD) is strictly less than the feasible distance (FD). A path with RD equal to FD is not a feasible successor, even though it appears as an alternate path in 'show ip eigrp topology all-links'.

How to eliminate wrong answers

Option B is wrong because the route to 10.20.20.0/24 has a feasible successor via 10.3.3.2 (reported distance 28160 is less than the FD of 28160, satisfying the feasibility condition). Option C is wrong because the FD for 10.10.10.0/24 is 28160, not 28672 (the 28672 value is the composite metric of the second path, not the FD). Option D is wrong because the route to 10.10.10.0/24 is marked with 'P' (Passive), not 'A' (Active), indicating it is in a stable state, not performing route recomputation.

1376
MCQhard

What is the default CoPP aggregate policer rate for control plane traffic on a Cisco IOS-XE device?

A.32000 bps
B.75000 bps
C.No default rate; CoPP is disabled by default
D.128000 bps
AnswerC

Cisco IOS-XE ships with no default CoPP aggregate policer rate because control plane policing is disabled until explicitly configured. The aggregate policer only exists once an administrator defines a policy-map and attaches it to the control plane.

Why this answer

Cisco IOS-XE does not enable Control Plane Policing (CoPP) by default; it must be explicitly configured using the 'control-plane' command followed by 'service-policy' to attach a policy map. The absence of a default aggregate policer rate means that without CoPP configuration, the control plane is unprotected from traffic storms or DoS attacks. Options A, B, and D are incorrect because they suggest predefined rates that do not exist as defaults in Cisco IOS-XE.

Exam trap

Cisco often tests the misconception that CoPP has a built-in default policer rate, leading candidates to confuse it with the default hardware rate limits for control plane queues (e.g., on Catalyst switches) or with default values from other QoS features.

How to eliminate wrong answers

Option A is wrong because 32000 bps is not a default CoPP aggregate policer rate; CoPP has no default rate, and this value might be confused with a typical low-rate policer used in custom configurations. Option B is wrong because 75000 bps is not a default CoPP aggregate policer rate; this value is often associated with the default CoPP rate on some Cisco IOS (non-XE) platforms, but not on IOS-XE. Option D is wrong because 128000 bps is not a default CoPP aggregate policer rate; this value might be mistaken for the default hardware rate limit for certain control plane queues on some Catalyst switches, but it is not a CoPP default.

1377
MCQmedium

A network engineer runs the following command on router R2: R2# show monitor session 4 Session 4 --------- Type : ERSPAN Source Session Status : Admin Enabled Source Ports : Both : Gi0/0 Destination IP : 192.168.1.10 Origin IP : 10.0.0.2 ERSPAN ID : 100 Based on this output, which statement is correct?

A.The ERSPAN session is mirroring traffic from Gi0/0 to IP address 192.168.1.10 using ERSPAN ID 100.
B.The ERSPAN session is mirroring traffic from IP 192.168.1.10 to Gi0/0.
C.The ERSPAN session is using RSPAN encapsulation.
D.The ERSPAN session is disabled because the status is 'Admin Enabled'.
AnswerA

The session is an ERSPAN source, so it encapsulates mirrored frames from Gi0/0 into GRE and forwards them to the destination IP 192.168.1.10, tagged with ERSPAN ID 100. This satisfies the stem's requirement to identify the mirroring direction and destination, since source sessions transmit rather than receive traffic.

Why this answer

The output shows an ERSPAN Source Session with Source Port Gi0/0 and Destination IP 192.168.1.10, meaning traffic from Gi0/0 is mirrored to the destination IP using ERSPAN ID 100. ERSPAN encapsulates mirrored traffic in GRE and sends it to a remote destination IP, which matches this output.

Exam trap

The trap is misreading the direction of the mirror — candidates see the destination IP and assume traffic flows from that IP to the port, but ERSPAN source sessions mirror from the source port to the destination IP.

How to eliminate wrong answers

Option B is wrong because it reverses the direction — the source port is Gi0/0 and the destination is the IP, not the other way around. Option C is wrong because the session type is explicitly ERSPAN, not RSPAN; RSPAN uses VLAN-based remote mirroring, not GRE encapsulation to an IP. Option D is wrong because 'Admin Enabled' means the session is administratively enabled, not disabled.

1378
MCQmedium

A network engineer runs the following command to troubleshoot a Control Plane Policing (CoPP) issue: R1# show policy-map control-plane input class class-default Class-map: class-default (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any police: cir 1000000 bps, bc 31250 bytes, be 31250 bytes conformed 0 packets, 0 bytes; actions: transmit violated 0 packets, 0 bytes; actions: drop conformed 0 bps, exceed 0 bps, violated 0 bps What does this output indicate?

A.The CoPP policy is dropping all traffic due to a misconfigured CIR.
B.The CoPP policy is not matching any traffic, indicating a possible ACL or class-map misconfiguration.
C.The CoPP policy is working correctly and policing traffic at 1 Mbps.
D.The CoPP policy is only applied to the output direction.
AnswerB

Zero packets and zero bytes across all counters, with match-any, shows the policy-map is attached but no traffic reaches it. This indicates the class-map or its referenced ACL is not matching, consistent with the stem's CoPP troubleshooting scenario.

Why this answer

The output shows zero packets matched in class-default, meaning no traffic is being classified by the CoPP policy. This indicates a possible misconfiguration in the ACL or class-map that defines the traffic to be policed, causing the policy to be effectively inactive. A correctly configured CoPP policy would show non-zero packet counts for matched traffic.

Exam trap

Cisco often tests the misconception that zero packet counts in a CoPP policy indicate the policy is working correctly (e.g., no traffic is being dropped), when in fact it indicates a classification failure, such as a missing ACL or incorrect class-map configuration.

How to eliminate wrong answers

Option A is wrong because the CIR is configured at 1 Mbps and the policy is not dropping any traffic (violated 0 packets), so there is no evidence of a misconfigured CIR causing drops. Option C is wrong because the policy is not policing any traffic at all (0 packets matched), so it is not working correctly. Option D is wrong because the command 'show policy-map control-plane input' explicitly shows the input direction, and the output does not indicate any application to the output direction.

1379
MCQmedium

A network engineer configures a Flexible NetFlow monitor to capture traffic on a router's WAN interface. The flow record includes 'match ipv4 source address', 'match ipv4 destination address', and 'collect counter bytes'. After applying the monitor, 'show flow monitor name MONITOR cache' shows flows, but the collector receives no data. 'show flow exporter name EXPORTER statistics' shows 'Export packets sent: 0'. What is the most likely cause?

A.The flow exporter is configured with the wrong destination IP address.
B.The flow monitor is not associated with any flow exporter.
C.The flow exporter is missing the 'source' interface command.
D.The flow cache is full, preventing new exports.
AnswerB

Export packets sent: 0 means the monitor's cache never reaches an exporter, because no exporter is attached to the monitor. The 'flow exporter' command must be added under the monitor configuration; without that association, cached flows are never exported to the collector.

Why this answer

The flow exporter statistics showing 'Export packets sent: 0' while the monitor cache contains flows indicates the monitor is collecting data but never invoking the exporter. In Flexible NetFlow, the flow monitor must reference a flow exporter via the 'exporter EXPORTER' command under flow monitor configuration; without that association, the monitor has no destination to send records to. This is the most direct cause of zero exports despite a populated cache.

Exam trap

300-410 often tests the three-component Flexible NetFlow model, and candidates frequently blame the exporter's destination or source settings when the real issue is that the monitor never references the exporter at all.

How to eliminate wrong answers

Option A is wrong because a wrong destination IP would still increment 'Export packets sent' (the packets would just go to the wrong place), so zero sent packets rules this out. Option C is wrong because a missing source interface affects the source IP of exported packets, not whether exports occur at all. Option D is wrong because a full flow cache causes entries to age out or be overwritten, but exports would still be sent — and the cache showing flows means it is not blocking exports.

1380
MCQeasy

A network engineer runs the following command on Router R1: R1# show bgp neighbors 10.1.12.2 received-routes BGP table version is 15, local router ID is 10.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.2.2.0/24 10.1.12.2 0 0 65002 i Total number of prefixes 1 Based on this output, what can be inferred about the BGP session?

A.The BGP session is not established.
B.The BGP session is established and the neighbor is advertising one prefix.
C.The BGP session is in Active state.
D.The BGP session is in Idle state.
AnswerB

The received-routes output displays one prefix, 10.2.2.0/24, marked valid and best, which is only possible when the TCP session reached Established state and the neighbour sent an UPDATE. A non-established session would return no received prefixes.

Why this answer

The output shows that R1 has received one prefix (10.2.2.0/24) from neighbor 10.1.12.2. The prefix is valid and best. This indicates the BGP session is established and exchanging routes.

1381
MCQmedium

Router R6 has the following configuration: ``` interface GigabitEthernet0/7 ip address 10.6.6.6 255.255.255.0 ! route-map PBR-MISS permit 10 match ip address 104 set ip next-hop 192.168.4.1 ! access-list 104 permit ip 10.6.6.0 0.0.0.255 192.168.0.0 0.0.255.255 ``` What is missing in this configuration?

A.The interface is missing the 'ip policy route-map PBR-MISS' command.
B.The route-map is missing a 'set interface' command.
C.The ACL is missing a 'deny any any' statement.
D.The route-map sequence number must be 1.
AnswerA

The route-map PBR-MISS and matching ACL exist, but policy-based routing only activates when applied to the ingress interface. Without 'ip policy route-map PBR-MISS' under GigabitEthernet0/7, matching traffic is forwarded normally rather than to next-hop 192.168.4.1.

Why this answer

The configuration is missing the 'ip policy route-map PBR-MISS' command on the interface. Policy-Based Routing (PBR) requires the route-map to be applied to the ingress interface using this command. Without it, the route-map is defined but not active, so packets will not be policy-routed.

Exam trap

The 300-410 exam often tests the oversight of applying the route-map to the interface, as candidates focus on the route-map definition and forget the activation command.

How to eliminate wrong answers

Option B is wrong because the route-map uses 'set ip next-hop', which is valid; 'set interface' is an alternative but not required. Option C is wrong because ACLs used in route-maps have an implicit deny at the end; an explicit 'deny any any' is not necessary and would actually prevent matching other traffic if placed incorrectly. Option D is wrong because route-map sequence numbers can be any number; 10 is commonly used but not mandatory.

1382
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 interface gigabitethernet 0/0 | include uRPF IPv6 uRPF: strict mode Based on this output, which statement is true?

A.uRPF is disabled
B.uRPF is enabled in strict mode
C.uRPF is enabled in loose mode
D.uRPF is enabled but only for multicast
AnswerB

The output states IPv6 uRPF: strict mode, confirming unicast reverse path forwarding is enabled in strict mode. Strict mode drops packets unless the source address is reachable via the same interface they arrived on, satisfying the verification shown in the command output.

Why this answer

The command output explicitly shows 'IPv6 uRPF: strict mode', which confirms that unicast Reverse Path Forwarding (uRPF) is enabled and operating in strict mode. In strict mode, the router verifies that the source address of an incoming packet matches a route in the FIB and that the incoming interface is the same as the outgoing interface for that route. This prevents spoofed traffic from entering the network.

Exam trap

Cisco often tests the distinction between strict and loose uRPF modes, and the trap here is that candidates might confuse the 'strict mode' output with 'loose mode' or assume uRPF is disabled when the output line is present.

How to eliminate wrong answers

Option A is wrong because the output clearly states 'strict mode', which indicates uRPF is enabled, not disabled. Option C is wrong because the output specifies 'strict mode', not 'loose mode'; loose mode only checks that a route exists for the source address, regardless of the incoming interface. Option D is wrong because uRPF applies to unicast traffic, not multicast; multicast uses Reverse Path Forwarding (RPF) as part of protocols like PIM, but uRPF is specifically for unicast source address verification.

1383
MCQmedium

A network engineer runs the following command to troubleshoot an OSPF adjacency issue: R1# debug ip ospf adj *Mar 1 00:12:34.567: OSPF-1 ADJ RtrA: Interface GigabitEthernet0/0 going Up *Mar 1 00:12:34.568: OSPF-1 ADJ RtrA: 2 Way Communication to 10.1.1.2 on GigabitEthernet0/0, state 2WAY *Mar 1 00:12:34.570: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Our router ID 1.1.1.1, his router ID 2.2.2.2 *Mar 1 00:12:34.571: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Neighbor is not DR, state 2WAY *Mar 1 00:12:34.572: OSPF-1 ADJ RtrA: NBR 10.1.1.2: DR is 10.1.1.2, BDR is 10.1.1.1 *Mar 1 00:12:34.573: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Build the Start DBD *Mar 1 00:12:34.574: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Master/Slave negotiation done *Mar 1 00:12:34.576: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Exchange done, loading started *Mar 1 00:12:34.578: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Loading done *Mar 1 00:12:34.580: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Full What does this output indicate?

A.The adjacency failed due to a mismatch in the DR election.
B.The adjacency formed successfully, and the neighbor is in Full state.
C.The adjacency is stuck in Exstart state due to MTU mismatch.
D.The neighbor is not the DR, so the adjacency will not form.
AnswerB

The debug trace shows the neighbour progressing through 2WAY, Exchange, Loading and finally Full, confirming the OSPF adjacency completed successfully. The stem's troubleshooting goal is satisfied: no mismatch, area or MTU fault blocked the exchange, so the routers now share a synchronised link-state database.

Why this answer

The debug output shows the OSPF adjacency progressing through states: Down, Init, 2-Way, ExStart, Exchange, Loading, and finally Full. The last line indicates 'Full', meaning the adjacency formed successfully. The neighbor is in Full state, which is the normal operational state for OSPF neighbors.

Exam trap

The trap is that candidates might misinterpret 'Neighbor is not DR' as a problem, but it is not; the adjacency can still form if the local router is DR or BDR. The exam tests understanding of OSPF states and DR/BDR roles.

How to eliminate wrong answers

Option A is wrong because the output shows the DR election completed (DR is 10.1.1.2, BDR is 10.1.1.1) and the adjacency reached Full, so there was no failure due to DR mismatch. Option C is wrong because the adjacency progressed past ExStart to Exchange and Loading, and reached Full; an MTU mismatch would cause it to stick in ExStart or Exchange. Option D is wrong because the neighbor not being DR does not prevent adjacency formation; in fact, the output shows the neighbor is not DR but the adjacency still reached Full.

1384
MCQeasy

A network engineer is configuring a GRE tunnel between two Cisco IOS routers to transport multicast traffic. The engineer notices that multicast packets are not being forwarded over the tunnel. Which command is required on the tunnel interface to enable multicast forwarding?

A.keepalive 10 3
B.ip mtu 1400
C.tunnel mode gre multipoint
D.ip pim sparse-mode
AnswerD

To forward multicast traffic over a GRE tunnel, the tunnel interface must have IP PIM enabled. The ip pim sparse-mode command enables PIM on the interface, allowing it to participate in multicast routing. Without PIM on the tunnel interface, multicast packets will not be forwarded, even if the tunnel is up.

Why this answer

Multicast forwarding over a GRE tunnel requires PIM to be enabled on the tunnel interface. The ip pim sparse-mode command activates PIM on the interface, allowing it to send and receive multicast traffic. Without this, the tunnel will not forward multicast packets, regardless of other tunnel settings.

Exam trap

The trap here is focusing on tunnel mode or MTU settings while overlooking the need for PIM on the tunnel interface to enable multicast.

1385
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip ospf interface GigabitEthernet0/0 GigabitEthernet0/0 is up, line protocol is up Internet Address 192.168.12.1/24, Area 0 Process ID 1, Router ID 10.1.1.1, Network Type BROADCAST, Cost: 10 Transmit Delay is 1 sec, State BDR, Priority 1 Designated Router (ID) 10.1.1.2, Interface address 192.168.12.2 Backup Designated router (ID) 10.1.1.1, Interface address 192.168.12.1 Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5 oob-resync timeout 40 Hello due in 00:00:03 Neighbor Count is 1, Adjacent neighbor count is 1 Adjacent with neighbor 10.1.1.2 (Designated Router) Suppress hello for 0 neighbor(s) Based on this output, which statement is correct?

A.Router R1 is the Designated Router on this segment.
B.Router R1 has a priority of 0, preventing it from becoming DR.
C.The dead timer is set to 40 seconds and is functioning correctly.
D.Router R1 is not receiving hello packets from the DR.
AnswerC

The Dead interval of 40 seconds matches four times the Hello interval of 10 seconds, the default ratio for broadcast networks, so the timer is operating as expected. The stem's BROADCAST network type confirms these defaults apply, and the adjacency with the DR shows the timer is not expiring prematurely.

Why this answer

The output shows 'Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5', confirming the dead timer is 40 seconds (4× the hello interval), which is the default and functioning correctly. R1 is BDR (Backup Designated Router), not DR, and its priority is 1, not 0.

Exam trap

300-410 often tests reading OSPF interface output carefully — candidates see 'Designated Router (ID) 10.1.1.2' and assume R1 is the DR, missing the 'State BDR' line and the 'Backup Designated router (ID) 10.1.1.1' line that identifies R1 as BDR.

How to eliminate wrong answers

Option A is wrong because the output states 'State BDR' and identifies the DR as 10.1.1.2 with interface address 192.168.12.2 — R1 is the backup, not the DR. Option B is wrong because the output shows 'Priority 1', not 0; a priority of 0 would prevent DR election, but that is not the case here. Option D is wrong because the output shows 'Neighbor Count is 1, Adjacent neighbor count is 1' and 'Adjacent with neighbor 10.1.1.2 (Designated Router)', proving R1 is receiving hellos and is fully adjacent with the DR.

1386
MCQmedium

Given the following configuration on a router: ``` router ospf 1 distance 150 ``` What is the effect of this configuration?

A.It sets the administrative distance for OSPF routes to 150, but only for intra-area routes.
B.It sets the administrative distance for OSPF routes to 150, overriding the default of 110.
C.It sets the administrative distance for OSPF external routes to 150.
D.It sets the administrative distance for OSPF routes to 150, but only for routes learned from a specific neighbor.
AnswerB

The distance 150 command under router ospf 1 changes OSPF's administrative distance from its default 110 to 150 for routes learned via that process. Lower values are preferred, so OSPF routes become less trusted than before in the routing table selection.

Why this answer

This command sets the administrative distance for all OSPF routes to 150, overriding the default of 110.

1387
MCQeasy

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# show ip sla monitor statistics 10 Round Trip Time (RTT) for Index 10 Latest RTT: 12 ms Latest RTT (milliseconds): 12 Latest RTT (microseconds): 12000 Last operation start time: 12:34:56.789 UTC Mon Mar 1 2021 Last operation return code: OK Number of successes: 100 Number of failures: 0 Operation time to live: Forever What does this output indicate?

A.The IP SLA monitor operation has failed because the return code is 'OK'.
B.The IP SLA monitor operation is functioning correctly with no failures.
C.The IP SLA monitor operation is not configured for index 10.
D.The IP SLA monitor operation has a timeout of 12 ms.
AnswerB

The statistics confirm the operation is healthy: 100 successes against zero failures, a 12 ms latest RTT, and a return code of OK. This satisfies the stem's troubleshooting goal by showing the probe completes successfully, so no fault exists in the monitored path.

Why this answer

The output shows 'Number of successes: 100' and 'Number of failures: 0', with a latest RTT of 12 ms and return code 'OK'. This indicates the IP SLA operation is functioning correctly and meeting its objectives. The return code 'OK' means the operation completed successfully, not that it failed.

Exam trap

The trap here is misinterpreting 'OK' as a failure indicator, or confusing RTT with timeout. Candidates might think 'OK' means something is wrong, but it actually confirms success.

How to eliminate wrong answers

Option A is wrong because a return code of 'OK' indicates success, not failure. Option C is wrong because the command explicitly displays statistics for index 10, proving it is configured. Option D is wrong because the 12 ms is the round-trip time, not a timeout value; timeouts are configured separately and would be shown as failures if exceeded.

1388
MCQmedium

Which LSA type is used by OSPF to advertise prefixes from other routing protocols (redistribution) and has a default metric of 20?

A.Type 1 LSA (Router LSA)
B.Type 3 LSA (Summary LSA)
C.Type 4 LSA (ASBR Summary LSA)
D.Type 5 LSA (AS-external LSA)
AnswerD

Type 5 AS-external LSAs carry redistributed prefixes from other routing protocols throughout the OSPF domain. Their default metric of 20 applies to E2 routes unless the metric is changed, and they are flooded across area boundaries by ABRs.

Why this answer

Type 5 LSAs (AS-external LSAs) are generated by an ASBR to advertise routes redistributed from other routing protocols or static routes into OSPF. They are flooded throughout the OSPF domain (except stub areas) and carry an external metric with a default value of 20 for redistributed routes.

Exam trap

300-410 often tests LSA types and their specific roles; candidates confuse Type 4 (ASBR location) with Type 5 (external prefixes) or assume Type 3 handles redistribution, but only Type 5 (and Type 7 in NSSA) carries external routes.

How to eliminate wrong answers

Option A is wrong because Type 1 LSAs (Router LSAs) are generated by every OSPF router to describe its links and are not used for redistribution. Option B is wrong because Type 3 LSAs (Summary LSAs) are generated by ABRs to advertise inter-area routes within the same OSPF domain, not external routes. Option C is wrong because Type 4 LSAs (ASBR Summary LSAs) are generated by ABRs to advertise the location of an ASBR, not the external prefixes themselves.

1389
Multi-Selecthard

A network engineer is deploying DMVPN Phase 3 with IPsec protection on a Cisco IOS router acting as a hub. The engineer wants to ensure that spoke-to-spoke traffic is encrypted and that spoke routers can dynamically establish direct tunnels. Which two statements are true about this deployment? (Choose two.)

Select 2 answers
A.The hub must be configured with 'ip nhrp redirect' to signal spokes about a better path.
B.The hub must be configured with 'ip nhrp map multicast dynamic' to support dynamic multicast mapping.
C.Spoke routers must have a static crypto map entry for each possible destination spoke.
D.The hub must use a crypto map with 'ipsec-isakmp' to encrypt all GRE traffic.
E.Spoke routers must be configured with 'ip nhrp shortcut' to install shortcut routes for direct spoke-to-spoke tunnels.
AnswersA, E

In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to inform the spoke that a more optimal path exists to the destination. This allows the spoke to initiate a direct tunnel to the other spoke. Without redirect, spoke-to-spoke traffic would continue to go through the hub.

Why this answer

In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to notify spokes of a better path, and spokes use 'ip nhrp shortcut' to install shortcut routes for direct spoke-to-spoke tunnels. These two features work together to enable dynamic spoke-to-spoke communication. IPsec protection is typically implemented using IPsec profiles, not static crypto maps, and multicast mapping is separate from this functionality.

Exam trap

The trap here is confusing DMVPN Phase 3 requirements with Phase 2 or assuming that static crypto maps are needed; Phase 3 uses NHRP redirect and shortcut for dynamic spoke-to-spoke tunnels.

1390
MCQmedium

A network engineer configures a DMVPN spoke with OSPF as the routing protocol: interface Tunnel0 ip address 10.0.0.2 255.255.255.0 ip nhrp network-id 100 ip nhrp nhs 10.0.0.1 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ip nhrp map 10.0.0.1 192.168.1.1 ip nhrp map multicast 192.168.1.1 ! router ospf 1 network 10.0.0.0 0.0.0.255 area 0 ! What is a common issue with OSPF in this DMVPN Phase 2 configuration?

A.OSPF will elect a DR/BDR on the hub, which can cause suboptimal routing and adjacency issues.
B.OSPF will not form adjacencies because of NHRP authentication.
C.OSPF will use point-to-point network type by default.
D.OSPF will automatically adjust to the DMVPN environment.
AnswerA

On a multipoint tunnel, OSPF treats the interface as broadcast, electing a DR and BDR. The hub usually becomes DR, so all spoke routes funnel through it, producing suboptimal paths and preventing direct spoke-to-spoke adjacencies in Phase 2.

Why this answer

In a DMVPN Phase 2 configuration, the tunnel interface is a multipoint GRE (mGRE) interface, which by default is treated as a broadcast network by OSPF. On a broadcast network, OSPF elects a DR and BDR, and in DMVPN the hub typically becomes the DR while spokes become DROTHERs. This causes spokes to form full adjacencies only with the hub, and inter-spoke traffic must transit the hub, producing suboptimal routing and potential adjacency or next-hop issues.

Exam trap

300-410 often tests the misconception that OSPF automatically adapts to DMVPN topologies, when in fact the default broadcast network type causes DR/BDR election problems that must be manually corrected.

How to eliminate wrong answers

Option B is wrong because NHRP authentication is not enabled in the configuration shown (no 'ip nhrp authentication' command), and even when enabled it does not prevent OSPF adjacencies from forming — it only authenticates NHRP registration. Option C is wrong because OSPF does not default to point-to-point on an mGRE tunnel; the default network type on a multipoint tunnel is broadcast, which is precisely why DR/BDR election occurs. Option D is wrong because OSPF does not automatically adapt to the DMVPN environment; the network type must be manually changed (e.g., to point-to-multipoint or point-to-point with 'ip ospf network' commands) to avoid DR/BDR issues.

1391
MCQeasy

A network engineer is configuring a Cisco IOS router to support MPLS Layer 3 VPNs. The engineer needs to enable the provider edge (PE) router to exchange VPNv4 routes with other PE routers. Which protocol is used to distribute VPNv4 routes between PE routers?

A.RSVP-TE
B.OSPFv2
C.LDP
D.BGP with the VPNv4 address family
AnswerD

Multiprotocol BGP (MP-BGP) with the VPNv4 address family is used to distribute VPNv4 routes between PE routers in an MPLS L3VPN environment. It carries the route targets and route distinguishers as extended communities, enabling proper VPN membership and route separation. BGP is the only protocol that supports the necessary address family and attributes for VPNv4 route exchange, making it the correct choice.

Why this answer

MP-BGP with the VPNv4 address family is the standard protocol for exchanging VPNv4 routes between PE routers in MPLS L3VPN deployments. It carries the necessary extended communities (route targets, route distinguishers) to support multiple VPNs. Other protocols like OSPF, LDP, and RSVP-TE serve different purposes and cannot distribute VPNv4 routes.

Exam trap

The trap here is confusing the protocol used for label distribution (LDP) with the protocol used for VPN route distribution (MP-BGP).

1392
MCQeasy

A network engineer is configuring a Cisco IOS router as a DHCP relay agent. The router's interface GigabitEthernet0/0 is connected to a client subnet, and the DHCP server is located at 10.1.1.100. The engineer wants the router to forward DHCP requests from clients to the server and ensure that the server can assign addresses from the correct pool. Which command is required on the router?

A.`ip helper-address 10.1.1.100` on interface GigabitEthernet0/0
B.`ip dhcp relay information option` globally
C.`ip forward-protocol udp 67` on interface GigabitEthernet0/0
D.`ip dhcp pool CLIENT` and `network 192.168.1.0 /24`
AnswerA

The `ip helper-address` command configures the router to forward UDP broadcasts, including DHCP requests (UDP port 67), to the specified server. This allows the DHCP server to receive the request and assign an address from the appropriate pool based on the gateway address (giaddr) set by the router. This is the correct and standard way to configure a DHCP relay agent on Cisco IOS.

Why this answer

To configure a Cisco IOS router as a DHCP relay agent, the `ip helper-address` command must be applied on the interface facing the DHCP clients. This command forwards DHCP broadcast requests to the specified DHCP server, allowing the server to assign addresses from the correct pool based on the incoming interface's IP address. Without this command, DHCP requests would not reach the server, and clients would not obtain IP addresses.

Exam trap

The trap here is confusing the DHCP relay agent configuration with DHCP server or Option 82 commands, which are not required for basic relay functionality.

1393
MCQhard

A network engineer runs the following command on Router R1: R1# show ip sla statistics 4 Round Trip Time (RTT) for Index 4 Latest RTT: 300 ms Latest RTT (milliseconds): 300 Latest RTT (microseconds): 300000 Number of successes: 45 Number of failures: 55 Operation time to live: Forever Output: Over threshold R1# show track 2 Track 2 IP SLA 4 reachability Reachability is Down 5 changes, last change 00:00:05 Latest operation return code: Over threshold Latest RTT (milliseconds): 300 Tracked by: ip route 0.0.0.0 0.0.0.0 192.168.2.1 track 2 Based on this output, which statement is correct?

A.The IP SLA operation is failing because the target is unreachable.
B.The tracked static route is active because the IP SLA has successes.
C.The IP SLA threshold has been exceeded, causing the track to go down and the static route to be removed.
D.The IP SLA operation has a 55% failure rate, but the track is still up.
AnswerC

The IP SLA operation's RTT of 300 ms breaches its configured threshold, so the return code reads "Over threshold". Track 2, bound to IP SLA 4 reachability, transitions to Down, and the tracked static default route via 192.168.2.1 is withdrawn from the routing table.

Why this answer

The track shows 'Down' because the IP SLA return code is 'Over threshold'. This means the threshold was exceeded, and the track has brought down the static route. The failures (55) are high, but the key is that the track is down due to the threshold violation.

1394
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip vrf detail RED VRF RED (VRF Id = 1); default RD <not set> Interfaces: GigabitEthernet0/2 Loopback1 Address family IPV4 (Table ID = 1): No Export VPN route-target communities No Import VPN route-target communities No import route-map No export route-map VRF label distribution protocol: not configured Address family IPV6 (Table ID = 0x1E000001): No Export VPN route-target communities No Import VPN route-target communities No import route-map No export route-map VRF label distribution protocol: not configured Based on this output, which statement is correct?

A.The VRF RED has a Route Distinguisher configured.
B.The VRF RED includes two interfaces: GigabitEthernet0/2 and Loopback1.
C.The VRF RED has an export route-map configured.
D.The VRF RED is configured for MPLS label distribution.
AnswerB

The `show ip vrf detail RED` output explicitly lists GigabitEthernet0/2 and Loopback1 under the Interfaces section for VRF RED, confirming both are assigned to that routing table. This directly satisfies the stem's requirement to identify the interfaces bound to the VRF, independent of the unset RD and route-target values.

Why this answer

The output explicitly lists 'Interfaces: GigabitEthernet0/2, Loopback1' under VRF RED, confirming that both interfaces are assigned to this VRF. The other statements are contradicted by the output: default RD is '<not set>', there are no export route-maps, and label distribution protocol is 'not configured'.

Exam trap

The trap is misreading the output: candidates might assume an RD is present because it's common, but the output clearly says '<not set>', so careful reading is essential.

How to eliminate wrong answers

Option A is wrong because the output shows 'default RD <not set>', indicating no RD is configured. Option C is wrong because the output states 'No export route-map'. Option D is wrong because the output says 'VRF label distribution protocol: not configured'.

1395
MCQhard

In OSPF, what is the default behavior for auto-summary on Cisco IOS-XE?

A.Auto-summary is enabled by default
B.Auto-summary is disabled by default
C.Auto-summary is only enabled for external routes
D.Auto-summary is enabled only for inter-area routes
AnswerB

Cisco IOS-XE disables OSPF auto-summary by default, so no automatic summarisation of redistributed subnets occurs at classful boundaries. Summarisation only happens when explicitly configured with the 'summary-address' command under the OSPF routing process, or via 'auto-summary' where supported.

Why this answer

Cisco IOS-XE has auto-summary disabled by default for OSPF, meaning that redistributed routes are not summarized to their classful boundaries unless explicitly configured.

1396
MCQhard

An engineer is troubleshooting a network where R1 and R2 are running EIGRP, and R2 redistributes a static route for 192.168.1.0/24 into EIGRP. R1 also learns the same prefix via OSPF from R3 with an AD of 110. The engineer observes that R1 prefers the EIGRP external route (AD 170) over the OSPF route. What configuration change would cause this behavior?

A.The OSPF route is a type 5 LSA, which has a higher AD than type 3 LSAs.
B.The engineer applied the distance eigrp 90 100 command under EIGRP, lowering the AD for external routes to 100.
C.The OSPF route has a metric of 20, while the EIGRP route has a metric of 2560.
D.The static route was redistributed with a route-map that sets the EIGRP metric to 1.
AnswerB

Lowering the external EIGRP administrative distance to 100 via the distance eigrp 90 100 command makes the redistributed static route (AD 100) beat the OSPF route (AD 110), explaining R1's preference for the EIGRP external path.

Why this answer

By default, EIGRP external routes have an AD of 170, and OSPF has AD 110, so OSPF should be preferred. If the EIGRP external route is preferred, the AD must have been lowered, likely via the distance command under EIGRP.

1397
MCQmedium

A network engineer runs the following command to troubleshoot an RSPAN issue: R1# show monitor session 4 detail Session 4 --------- Type : Remote Destination Session Source RSPAN VLAN : 100 Destination Ports : Gi0/2 Encapsulation : Native Ingress : Disabled What does this output indicate?

A.The session is correctly configured as an RSPAN destination session.
B.The session is misconfigured because the source must be a port, not a VLAN.
C.The session is misconfigured because the destination port must have ingress enabled.
D.The session is misconfigured because the RSPAN VLAN must be the same as the source VLAN.
AnswerA

The output confirms a Remote Destination Session sourced from RSPAN VLAN 100, with Gi0/2 as the destination port and native encapsulation. This matches a valid RSPAN destination configuration, so the session is operating correctly and the monitored traffic should egress the destination port.

Why this answer

The output shows an RSPAN destination session with source RSPAN VLAN 100 and destination port Gi0/2. This is the destination side of an RSPAN configuration.

1398
MCQhard

A network engineer runs the following command to troubleshoot an EEM issue: R1# debug event manager action cli EEM Action CLI debugging is on R1# Mar 1 00:10:15.123: %HA_EM-6-ACTION: applet TRACK-INTERFACE: action cli command: 'show ip int brief' executed Mar 1 00:10:15.456: %HA_EM-6-ACTION: applet TRACK-INTERFACE: action cli output: 'Interface IP-Address OK? Method Status Protocol GigabitEthernet0/0 192.168.1.1 YES NVRAM up up GigabitEthernet0/1 10.0.0.1 YES NVRAM up up Loopback0 1.1.1.1 YES NVRAM up up' What does this output indicate?

A.The EEM applet 'TRACK-INTERFACE' executed the command 'show ip int brief' and the output was displayed.
B.The EEM applet 'TRACK-INTERFACE' failed to execute the command 'show ip int brief'.
C.The debug output shows the EEM applet configuration for 'TRACK-INTERFACE'.
D.The command 'show ip int brief' was executed manually by the engineer.
AnswerA

The debug output confirms the applet ran its CLI action: the command 'show ip int brief' executed and returned interface status. This verifies the EEM action CLI mechanism works, satisfying the engineer's need to confirm the applet's command execution and captured output.

Why this answer

The debug output shows the execution of CLI actions within an EEM applet. It displays the applet name, the CLI command being executed, and the output of that command. This is useful for verifying that CLI actions are working correctly and seeing the exact output returned.

1399
MCQmedium

What is the default DHCPv4 renewal time (T1) as a percentage of the lease time?

A.25%
B.50%
C.75%
D.87.5%
AnswerB

DHCPv4 clients renew at T1, which defaults to 50% of the lease duration, unicasting a REQUEST to the original server. This satisfies the stem's percentage constraint; T2 defaults to 87.5% and triggers rebinding broadcast if renewal fails.

Why this answer

(50%) because RFC 2131 defines the DHCPv4 renewal time (T1) as 50% of the lease duration. When the T1 timer expires, the client attempts to renew its lease by sending a unicast DHCPREQUEST to the server that originally granted the lease.

Exam trap

Cisco often tests the distinction between T1 (renewal at 50%) and T2 (rebinding at 87.5%), and the trap here is that candidates confuse the two percentages or assume the renewal time is a higher value like 75%.

How to eliminate wrong answers

Option A (25%) is wrong because 25% is not defined as any DHCP timer in RFC 2131; it is a common distractor that might be confused with the rebinding time (T2), which defaults to 87.5%. Option C (75%) is wrong because 75% is not a standard DHCP timer value; it is often mistakenly thought to be the renewal time due to a misunderstanding of the rebinding percentage. Option D (87.5%) is wrong because 87.5% is the default rebinding time (T2), not the renewal time (T1); T2 is the point at which the client broadcasts to any available DHCP server if renewal with the original server fails.

1400
MCQeasy

In MPLS L3VPN, what is the purpose of the Route Distinguisher (RD)?

A.To make IPv4 prefixes unique across different VRFs in the MPLS network.
B.To control which VRFs import routes from other PEs.
C.To specify the VPN label that is used for forwarding.
D.To identify the VRF on the local PE router.
AnswerA

The RD prepends an 8-byte value to the IPv4 prefix, forming a VPNv4 address. This guarantees uniqueness across VRFs even when different tenants use identical IPv4 ranges, satisfying the constraint that overlapping customer prefixes must remain distinguishable within the MPLS L3VPN.

Why this answer

The RD is an 8-byte value prepended to an IPv4 prefix to create a unique VPNv4 prefix. This allows overlapping IPv4 addresses from different VRFs to be carried in the same BGP table without conflict.

1401
MCQmedium

In IPv6 First Hop Security, which feature is used to prevent duplicate address detection (DAD) attacks by snooping Neighbor Discovery (ND) messages?

A.RA Guard
B.DHCPv6 Guard
C.ND Snooping
D.Source Guard
AnswerC

ND Snooping inspects Neighbor Discovery messages and builds a binding table of IPv6 address-to-MAC mappings, letting the switch drop spoofed Neighbor Solicitation and Advertisement packets. This directly satisfies the stem's constraint: blocking duplicate address detection attacks by snooping ND traffic at the access layer.

Why this answer

C is correct because ND Snooping (Neighbor Discovery Snooping) is the IPv6 First Hop Security feature that prevents duplicate address detection (DAD) attacks by inspecting Neighbor Solicitation (NS) and Neighbor Advertisement (NA) messages. It builds a binding table of valid IPv6-to-MAC address mappings and drops any NS messages that attempt to claim an address already in use by another device, thereby blocking DAD-based spoofing attacks.

Exam trap

The trap here is that candidates often confuse ND Snooping with RA Guard or DHCPv6 Guard, thinking any 'Guard' feature handles DAD attacks, but only ND Snooping directly inspects Neighbor Discovery messages used in the DAD process.

How to eliminate wrong answers

Option A is wrong because RA Guard (Router Advertisement Guard) is designed to block unauthorized Router Advertisement messages to prevent rogue router attacks, not to prevent DAD attacks. Option B is wrong because DHCPv6 Guard filters DHCPv6 server messages to prevent rogue DHCPv6 servers, and does not inspect Neighbor Discovery messages for DAD protection. Option D is wrong because Source Guard (IPv6 Source Guard) filters traffic based on the source IPv6 address against the ND Snooping binding table, but it does not directly prevent DAD attacks; it prevents source address spoofing after the binding is established.

Page 18

Page 19 of 19