Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 226–300

1401 questions total · 19pages · All types, answers revealed

Page 3

Page 4 of 19

Page 5
226
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip dhcp snooping binding MacAddress IpAddress Lease(sec) Type VLAN Interface AA:BB:CC:01:02:03 192.168.1.10 86400 dhcp-snooping 10 GigabitEthernet0/1 AA:BB:CC:01:02:04 192.168.1.11 86400 dhcp-snooping 10 GigabitEthernet0/1 AA:BB:CC:01:02:05 192.168.1.12 86400 dhcp-snooping 10 GigabitEthernet0/2 Based on this output, which statement is correct?

A.DHCP snooping is enabled and has recorded bindings for three clients.
B.DHCP snooping has detected a rogue DHCP server on GigabitEthernet0/1.
C.DHCP snooping is not functioning because the bindings are not trusted.
D.DHCP snooping has a conflict because two clients are on the same interface.
AnswerA

The binding table lists three MAC-to-IP leases, confirming DHCP snooping is active on VLAN 10 and has learned client bindings on GigabitEthernet0/1 and GigabitEthernet0/2. This satisfies the scenario's requirement to verify snooping operation, since populated dhcp-snooping entries only appear when the feature is enabled and processing DHCP traffic.

Why this answer

The output shows three DHCP snooping bindings with MAC addresses, IP addresses, lease times, and associated VLANs and interfaces, which indicates that DHCP snooping is enabled and has successfully recorded these bindings for clients. The 'dhcp-snooping' type confirms these are dynamically learned from DHCP messages, and the presence of multiple clients on the same interface (GigabitEthernet0/1) is valid as long as they are on the same VLAN.

Exam trap

Cisco often tests the misconception that multiple DHCP clients on the same interface indicate a conflict or misconfiguration, but DHCP snooping bindings can legitimately show multiple entries per interface as long as they are in the same VLAN and have unique MAC/IP pairs.

How to eliminate wrong answers

Option B is wrong because the output shows only DHCP snooping bindings, not any information about a rogue DHCP server; a rogue server would be detected via DHCP snooping's 'trusted' and 'untrusted' port configuration, which is not displayed here. Option C is wrong because the bindings are present and valid, indicating DHCP snooping is functioning correctly; the 'trusted' status applies to ports, not bindings, and untrusted ports can still have valid bindings. Option D is wrong because having two clients on the same interface (GigabitEthernet0/1) is not a conflict; DHCP snooping allows multiple bindings per interface as long as they are in the same VLAN and have unique MAC/IP pairs.

227
MCQmedium

A network engineer is troubleshooting a BGP peering issue between two directly connected routers, R1 and R2. R1 is configured with 'neighbor 10.1.1.2 remote-as 65002' and 'neighbor 10.1.1.2 update-source Loopback0', while R2 uses 'neighbor 10.1.1.1 remote-as 65001' and 'neighbor 10.1.1.1 update-source Loopback0'. The loopback interfaces are not advertised into any IGP, and there is no static route for the loopback addresses. The BGP session remains in Idle state. What is the most likely cause?

A.The BGP session is stuck in Idle because the neighbor statements reference loopback interfaces that are not reachable.
B.The BGP session is stuck in Idle because the remote-as values are mismatched.
C.The BGP session is stuck in Idle because the update-source command is not allowed on directly connected interfaces.
D.The BGP session is stuck in Idle because the neighbor statements must use the directly connected interface IP addresses.
AnswerA

BGP uses the update-source address as the TCP source, so each router attempts to reach the peer's loopback. With no IGP advertisement or static route for those loopbacks, the TCP connection cannot be established, leaving the session in Idle.

Why this answer

BGP forms a TCP session between the addresses specified in the neighbor statements. Because update-source Loopback0 is configured, R1 sources its TCP packets from its loopback address and expects to reach R2's loopback (10.1.1.2) as the neighbor. Since the loopbacks are not advertised into any IGP and no static routes exist, neither router has a route to the other's loopback, so the TCP three-way handshake to port 179 never completes and the session stays in Idle.

Exam trap

The trap here is assuming that directly connected routers can always peer regardless of source address — candidates forget that update-source changes the source IP and therefore requires routing to the neighbor's configured address, not just link-level connectivity.

How to eliminate wrong answers

Option B is wrong because the remote-as values are correctly matched (R1 peers with AS 65002 and R2 peers with AS 65001), so there is no AS mismatch. Option C is wrong because update-source is fully supported and commonly used on directly connected interfaces — it is a standard BGP configuration, not a restriction. Option D is wrong because BGP neighbor statements do not have to use directly connected interface IPs; peering over loopbacks is a valid and common design as long as the loopback addresses are reachable.

228
MCQhard

A network engineer configures IP SLA tracking for a static route on a Cisco router. The IP SLA operation is configured with a threshold of 100 ms and a timeout of 5000 ms. The tracked object is configured with a delay of 5 seconds for both up and down transitions. The engineer notices that when the remote host becomes unreachable, the static route is not removed from the routing table immediately. Which is the most likely explanation?

A.The IP SLA operation is still in the 'pending' state and has not yet timed out.
B.The tracked object delay of 5 seconds for down transition causes a 5-second wait before the route is removed.
C.The static route has a higher administrative distance than the IP SLA tracked route, so it remains preferred.
D.The IP SLA operation is configured with a frequency that is too low, causing a delay in detection.
AnswerB

The tracked object's down delay holds the object in the up state for 5 seconds after the SLA operation fails, so the static route stays installed until that timer expires. The 100 ms threshold and 5000 ms timeout govern operation state, not route withdrawal timing.

Why this answer

The IP SLA tracking delay configuration introduces a delay before the tracked object changes state; this is designed to prevent route flapping but can cause the static route to remain in the routing table for the configured delay period after the IP SLA operation fails.

229
MCQhard

An engineer configures OSPF on two routers connected via a serial link. Both routers have 'ip ospf network point-to-point' configured, but the link is actually a Frame Relay multipoint subinterface. The OSPF neighbors remain stuck in EXSTART state. Which is the most likely explanation?

A.The MTU on the serial link is not consistent between the two routers, causing DBD packets to be dropped.
B.The OSPF hello timer is set too high, causing the neighbor to time out.
C.The area ID is different on the two routers.
D.The OSPF router ID is duplicated.
AnswerA

Correct. OSPF uses the interface MTU for DBD packets; mismatch prevents exchange.

Why this answer

When OSPF neighbors are stuck in EXSTART state, it typically indicates a problem with the Database Description (DBD) packet exchange. In this scenario, the 'ip ospf network point-to-point' command overrides the default Frame Relay multipoint behavior, but the actual link is a multipoint subinterface. This mismatch can cause MTU inconsistencies because the multipoint subinterface may have a different MTU than the point-to-point OSPF network type expects.

If the MTU is not consistent between the two routers, DBD packets larger than the smaller MTU will be silently dropped, preventing the neighbors from progressing beyond EXSTART.

Exam trap

Cisco often tests the distinction between neighbor states—specifically that EXSTART is reached only after hello and 2-WAY states are complete, so issues like mismatched area IDs or duplicate router IDs would prevent reaching EXSTART, while MTU mismatches specifically block DBD exchange at EXSTART.

How to eliminate wrong answers

Option B is wrong because a hello timer set too high would cause neighbors to fail to form adjacency or stay in DOWN/INIT state, not get stuck in EXSTART; EXSTART is reached only after hello exchange succeeds. Option C is wrong because mismatched area IDs would prevent the routers from even reaching the 2-WAY state, as OSPF requires matching area IDs for neighbor discovery; they would not reach EXSTART. Option D is wrong because a duplicate OSPF router ID would cause one router to reject the other's hello packets, resulting in a neighbor state of DOWN or INIT, not EXSTART; EXSTART requires successful hello and database description negotiation.

230
Multi-Selecthard

Which THREE symptoms indicate that an administrative distance misconfiguration might be causing routing issues? (Choose THREE.)

Select 3 answers
A.The router prefers a route learned via a less reliable protocol over a more reliable one.
B.Routes are flapping in the routing table due to metric changes.
C.Traffic to a destination takes a suboptimal path.
D.The routing table shows two routes to the same network with different AD values.
E.Connectivity to a remote network is intermittent, depending on which protocol converges first.
AnswersA, C, E

This indicates that the AD for the less reliable protocol is set lower than for the more reliable one.

Why this answer

When AD is misconfigured, the router may prefer a less reliable route, causing suboptimal or intermittent connectivity. Common symptoms include incorrect route selection, flapping routes, and traffic taking unexpected paths. These are all signs that the AD values should be reviewed.

231
MCQeasy

What is the default transport protocol used by NetFlow exporters on Cisco IOS-XE?

A.TCP
B.UDP
C.SCTP
D.ICMP
AnswerB

NetFlow version 9 and IPFIX exporters on Cisco IOS-XE send flow records over UDP to the collector, defaulting to destination port 2055. UDP's connectionless, low-overhead delivery suits high-volume unidirectional telemetry, satisfying the stem's default transport requirement without TCP session state or retransmission delays.

Why this answer

NetFlow exporters on Cisco IOS-XE use UDP as the default transport protocol, typically sending flow records to a collector on UDP port 2055 (or 9995/9996 depending on configuration). UDP is chosen because flow export is high-volume and loss-tolerant — if a flow record is lost, the next one will arrive shortly, so the overhead of TCP's reliability mechanisms is unnecessary.

Exam trap

300-410 often tests the assumption that reliable transport (TCP) is always preferred, but NetFlow's default UDP reflects its loss-tolerant, high-volume nature — candidates who assume TCP get this wrong.

How to eliminate wrong answers

Option A is wrong because TCP is not the default for NetFlow export; while some collectors can be configured for TCP, IOS-XE defaults to UDP. Option C is wrong because SCTP is used in telecom signaling (SS7 over IP, Diameter) and is not a NetFlow transport. Option D is wrong because ICMP is a control and error-reporting protocol, not a data transport for flow records.

232
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 192.168.1.2 1 FULL/DR 00:00:35 10.1.1.2 GigabitEthernet0/0 192.168.2.2 1 2WAY/DROTHER 00:00:32 10.2.2.2 GigabitEthernet0/1 192.168.3.2 1 FULL/BDR 00:00:38 10.3.3.2 GigabitEthernet0/2 Based on this output, what is a potential issue?

A.The neighbor on Gi0/1 is not forming a full adjacency because it is in 2WAY state.
B.The neighbor on Gi0/0 is the DR, which is causing high CPU usage.
C.The neighbor on Gi0/2 is the BDR, which is a problem because it should be the DR.
D.All neighbors are in FULL state, indicating no issues.
AnswerD

The 2WAY/DROTHER state on GigabitEthernet0/1 is normal for a non-DR/BDR router on a broadcast segment, so no adjacency fault exists; the two FULL adjacencies confirm working OSPF relationships, meaning the output shows no actual problem.

Why this answer

The output shows normal OSPF neighbor states on a broadcast multi-access network. The neighbor on Gi0/1 is in the 2WAY/DROTHER state, which is expected for non-DR/BDR routers. The neighbors on Gi0/0 and Gi0/2 are in FULL state (DR and BDR respectively).

All states are valid, so there is no issue.

Exam trap

Candidates often incorrectly assume that any state other than FULL indicates a problem. However, in OSPF broadcast multi-access networks, the 2WAY state between DROTHER routers is normal and does not indicate an issue.

How to eliminate wrong answers

Option B is wrong because the neighbor on Gi0/0 being in FULL/DR state is normal and does not inherently cause high CPU usage; DR election is a standard OSPF process, and high CPU would depend on network size and LSA flooding, not simply the DR role. Option C is wrong because the neighbor on Gi0/2 being in FULL/BDR state is perfectly valid; the BDR is a backup to the DR, and there is no requirement that a specific router should be the DR—election is based on priority and Router ID. Option D is wrong because not all neighbors are in FULL state; the neighbor on Gi0/1 is in 2WAY state, which is not FULL, so stating 'all neighbors are in FULL state' is factually incorrect based on the output.

233
Multi-Selecthard

Which THREE statements about IPv4 access control list sequence numbers are true? (Choose THREE.)

Select 3 answers
A.Sequence numbers allow insertion of new entries between existing ones.
B.Sequence numbers are automatically assigned in increments of 10 for numbered ACLs.
C.Named ACLs support sequence numbers.
D.The ip access-list resequence command can renumber ACL entries.
E.Resequencing an ACL changes the order of evaluation.
AnswersA, C, D

You can specify a sequence number to place an entry at a specific position in the ACL.

Why this answer

Sequence numbers in IPv4 ACLs allow administrators to insert new entries between existing ones without deleting and re-entering the entire ACL. This is because each entry is assigned a unique sequence number, and new entries can be added with a sequence number that falls between two existing numbers, enabling granular control over the order of evaluation.

Exam trap

Cisco often tests the misconception that resequencing an ACL changes the order of evaluation, but in reality, it only renumbers the entries while preserving their original sequence; the trap is confusing sequence number reassignment with rule reordering.

234
MCQhard

A network engineer runs the following command to troubleshoot a BGP Troubleshooting issue: R1# show ip bgp vpnv4 vrf CUSTOMER routes BGP table version is 10, local router ID is 1.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path Route Distinguisher: 100:1 (default for vrf CUSTOMER) *> 10.0.0.0/24 10.1.1.2 0 100 0 65001 i *> 192.168.1.0/24 10.1.1.2 0 100 0 65001 i Total number of prefixes 2 What does this output indicate?

A.The VRF CUSTOMER has two routes, both learned via BGP from AS 65001.
B.The VRF CUSTOMER is not receiving any routes because the RD is incorrect.
C.The VRF CUSTOMER has two routes, but they are not installed in the routing table.
D.The VRF CUSTOMER has two routes, but they are filtered by RT import policy.
AnswerA

Both prefixes carry the next hop 10.1.1.2 with AS path 65001, and the '>' best-path marker confirms they are installed in the VRF CUSTOMER table. The route distinguisher 100:1 identifies this as the default VPNv4 table for that VRF, so both routes were learned from AS 65001.

Why this answer

The output shows two prefixes (10.0.0.0/24 and 192.168.1.0/24) in the VRF CUSTOMER's VPNv4 BGP table, both marked with '*' (valid) and '>' (best), with next hop 10.1.1.2 and AS path 65001. This confirms both routes were learned via eBGP from AS 65001 and are valid and selected as best. The Route Distinguisher 100:1 is the default for the VRF, which is normal and correct.

Exam trap

The trap is misreading status codes — candidates see routes in the BGP table and assume they are installed, or see the RD and assume it is misconfigured, when the '>' marker and default RD label confirm normal operation.

How to eliminate wrong answers

Option B is wrong because the RD 100:1 is explicitly shown as the default for VRF CUSTOMER, and routes are present — an incorrect RD would prevent routes from being associated with the VRF, not produce this output. Option C is wrong because the '>' best-path marker indicates the routes were selected and installed in the VRF RIB; if they were not installed, they would show 'r' (RIB-failure) or lack the '>' marker. Option D is wrong because RT import filtering would prevent routes from appearing in the VRF table at all; their presence with valid/best status confirms they passed import policy.

235
MCQmedium

Given the following BGP configuration on router R1: router bgp 65001 bgp router-id 1.1.1.1 neighbor 10.1.1.2 remote-as 65002 neighbor 10.1.1.2 route-map SET-MED out ! route-map SET-MED permit 10 match ip address prefix-list LOOPBACKS set metric 100 ! route-map SET-MED permit 20 ! ip prefix-list LOOPBACKS permit 192.168.0.0/24 What is the effect of this configuration?

A.Only the 192.168.0.0/24 route is advertised to 10.1.1.2, with MED 100.
B.All routes are advertised to 10.1.1.2; the 192.168.0.0/24 route has MED 100, others have no MED.
C.All routes are advertised with MED 100 because the route-map is applied outbound.
D.Only the 192.168.0.0/24 route is advertised with no MED because the set metric is ignored.
AnswerB

The route-map's implicit deny is overridden by sequence 20, which permits all remaining prefixes without a set clause, so every route still advertises. Sequence 10 matches only 192.168.0.0/24 via the prefix-list and stamps MED 100 on it, satisfying the requirement that other routes carry no MED attribute.

Why this answer

The route-map SET-MED has two permit statements: sequence 10 matches the LOOPBACKS prefix-list and sets MED 100, while sequence 20 is an empty permit that matches everything else and applies no metric change. Because route-maps have an implicit deny at the end, the empty permit 20 is essential to allow all other routes through. The result is that all routes are advertised, but only 192.168.0.0/24 carries MED 100.

Exam trap

The trap is forgetting the implicit deny at the end of route-maps — candidates either assume all routes are blocked (missing the empty permit) or assume all routes get the metric (missing that set metric only applies in the matched sequence).

How to eliminate wrong answers

Option A is wrong because the route-map does not filter out other routes — permit 20 allows everything else to pass. Option C is wrong because MED 100 is only set within the sequence 10 match block; sequence 20 has no set metric, so other routes go out with default MED (0 or unset). Option D is wrong because set metric is honored for matched routes, and the route-map does not restrict advertisement to only the prefix-list match.

236
MCQmedium

A network engineer runs the following command to debug NetFlow export: R1# debug ip flow export IP Flow export debugging is on R1# *Mar 1 00:05:23.123: FLOW: export v9 flow 1 with 30 packets *Mar 1 00:05:23.124: FLOW: export v9 flow 2 with 15 packets *Mar 1 00:05:23.125: FLOW: export v9 flow 3 with 22 packets *Mar 1 00:05:23.126: FLOW: export v9 flow 4 with 8 packets *Mar 1 00:05:23.127: FLOW: export v9 flow 5 with 12 packets What does this output indicate?

A.NetFlow export is failing because the flows are too small.
B.NetFlow version 9 export is functioning correctly, exporting multiple flows with their packet counts.
C.Only one flow is being exported at a time.
D.The export is using NetFlow version 5.
AnswerB

The debug output shows flow records exported using NetFlow version 9, each with its packet count, confirming successful export to the collector. No error or retry messages appear, so the export process is operating correctly and the stated constraint of verifying NetFlow export functionality is met.

Why this answer

The debug output shows that NetFlow version 9 export is working, with flows being exported in real time. Each line shows a flow ID and the number of packets in that flow. This indicates that NetFlow is actively exporting flow data.

237
MCQmedium

A network engineer runs the following command to troubleshoot an SNMP issue: R1# debug snmp packets SNMP: Packet received via UDP from 10.1.1.1 on port 161 SNMP: GetRequest, reqid 12345, errstat 0, errindex 0 SNMP: Community string: public SNMP: MIB object: 1.3.6.1.2.1.1.1.0 (sysDescr) SNMP: Value: Cisco IOS Software, C1900 Software (C1900-UNIVERSALK9-M), Version 15.7(3)M SNMP: Packet sent via UDP to 10.1.1.1 on port 161 SNMP: GetResponse, reqid 12345, errstat 0, errindex 0 What does this debug output indicate?

A.The SNMP agent is correctly responding to a GetRequest from the NMS at 10.1.1.1.
B.The SNMP agent is failing to process the request due to a community string mismatch.
C.The SNMP agent is sending a trap to the NMS at 10.1.1.1.
D.The SNMP agent is ignoring the request due to an ACL blocking the NMS.
AnswerA

The debug shows a complete SNMP transaction: the agent received a GetRequest for sysDescr from 10.1.1.1, returned errstat 0, and sent a GetResponse with the correct value. This confirms the agent is functioning and answering the NMS, so no SNMP fault exists on R1.

Why this answer

The debug output shows a complete SNMP GetRequest/GetResponse exchange between the NMS at 10.1.1.1 and the router acting as an SNMP agent. The agent receives a GetRequest for sysDescr (OID 1.3.6.1.2.1.1.1.0), processes it successfully (errstat 0, errindex 0), and sends back a GetResponse containing the system description. This confirms the SNMP agent is functioning correctly and responding to queries from the NMS.

Exam trap

Cisco often tests the distinction between SNMP Get/Set operations (which use UDP 161) and SNMP traps/informs (which use UDP 162), so candidates may mistakenly interpret a GetResponse as a trap if they overlook the direction and port details in the debug output.

How to eliminate wrong answers

Option B is wrong because the debug output shows the community string 'public' is accepted and the request is processed with errstat 0, indicating no authentication failure or mismatch. Option C is wrong because the output shows a GetRequest/GetResponse pair, not a trap; traps are unsolicited messages sent from agent to NMS, not a response to a query. Option D is wrong because the packet is received and processed successfully, with no indication of an ACL drop; if an ACL were blocking the NMS, the packet would not appear in the debug output at all.

238
MCQmedium

A network engineer is configuring OSPF on a Cisco router. The router has three interfaces in Area 0, and the engineer wants to ensure that the router does not become a Designated Router (DR) on any of these interfaces. Which command should be used on each interface?

A.ip ospf priority 255
B.ip ospf network point-to-point
C.ip ospf dr-disable
D.ip ospf priority 0
AnswerD

Setting OSPF priority to 0 on an interface makes the router ineligible to become DR or BDR on that interface. This is the correct method to prevent a router from being elected as DR. The priority value is carried in Hello packets and used in the DR election process; a priority of 0 means the router will not participate in the election.

Why this answer

OSPF DR/BDR election is influenced by interface priority. A priority of 0 makes a router ineligible to become DR or BDR. The other options either do not exist, change the network type unnecessarily, or increase the likelihood of becoming DR.

Therefore, setting priority to 0 on each interface is the correct approach.

Exam trap

The trap here is confusing OSPF priority with other routing protocol metrics or assuming that a non-existent command like 'dr-disable' exists.

239
MCQeasy

A network engineer runs the following command to troubleshoot a Control Plane Policing (CoPP) issue: R1# show ip route summary IP routing table name: Default-IP-Routing-Table (0x0) IP routing table maximum-paths: 32 Route entry limits: 1000000 active, 2000000 total Number of prefixes: 500 Prefixes with memory: 500 Number of paths: 600 Paths with memory: 600 Number of operations: 1200 Number of deleted entries: 0 What does this output indicate?

A.The routing table is empty due to CoPP dropping routing updates.
B.The routing table has 500 prefixes, indicating that routing protocols are functioning and CoPP is not blocking updates.
C.The routing table has too many prefixes, causing CoPP to drop packets.
D.The routing table is not being updated due to a CoPP policy.
AnswerB

The summary confirms 500 active prefixes and 600 paths, so routing protocol adjacencies are exchanging updates normally. Because CoPP polices control-plane traffic rather than data-plane forwarding, this healthy prefix count shows route advertisements are not being dropped, satisfying the stem's CoPP troubleshooting constraint.

Why this answer

The output shows 500 prefixes and 600 paths in the routing table, which indicates that routing protocols are exchanging routes and the routing table is being populated normally. Since CoPP is designed to protect the control plane by rate-limiting or dropping excessive traffic, a healthy routing table with a typical number of prefixes suggests that CoPP is not blocking routing updates. Therefore, option B is correct.

Exam trap

Cisco often tests the misconception that a low or moderate number of prefixes automatically indicates CoPP is dropping updates, when in fact CoPP would cause routing table instability or missing routes, not a static but healthy prefix count.

How to eliminate wrong answers

Option A is wrong because the routing table is not empty; it contains 500 prefixes, proving that routing updates are being received and processed. Option C is wrong because 500 prefixes is not an excessive number; modern routers can handle hundreds of thousands of routes, and CoPP would only drop packets if the control plane were overwhelmed, which is not indicated here. Option D is wrong because the routing table is being updated (as shown by the 500 prefixes and 600 paths), so CoPP is not blocking updates.

240
MCQmedium

Consider the following configuration on router R2: !--- R2 configuration ip prefix-list FILTER seq 5 deny 10.1.0.0/16 le 24 ip prefix-list FILTER seq 10 permit 0.0.0.0/0 le 32 ! route-map BGP-IN permit 10 match ip address prefix-list FILTER ! router bgp 65000 neighbor 192.168.1.1 route-map BGP-IN in ! What is the effect of this configuration?

A.All routes from neighbor 192.168.1.1 are accepted; the prefix-list is not applied correctly because the route-map only has a permit sequence.
B.Routes within 10.1.0.0/16 with mask length 24 or shorter are denied; all other routes are permitted.
C.Only routes with mask length exactly 24 are denied; all other routes are permitted.
D.The configuration is incomplete; a route-map must have a deny statement to filter routes.
AnswerB

Correct. The prefix-list denies 10.1.0.0/16 le 24, which includes /16 to /24 subnets; all other prefixes are permitted.

Why this answer

The prefix-list FILTER denies any prefix within 10.1.0.0/16 with a mask length less than or equal to 24 (i.e., 10.1.0.0/16 through 10.1.255.0/24). The permit statement allows all other prefixes. The route-map BGP-IN calls this prefix-list; since there is only one permit sequence, routes that match the deny statement in the prefix-list are implicitly denied by the route-map.

Therefore, routes like 10.1.0.0/16, 10.1.1.0/24, etc., are filtered out.

241
MCQhard

An experienced network engineer configures mutual redistribution between OSPF and EIGRP on a router. Both protocols have routes to the same prefix, but after redistribution, a routing loop occurs. The engineer did not use route tagging. Which is the most likely explanation?

A.The seed metric for EIGRP was not configured, causing routes to be rejected.
B.The redistribute command without route-map or tag allows routes to be re-advertised back into the source protocol, creating a loop.
C.OSPF has a lower administrative distance than EIGRP, so OSPF routes are always preferred.
D.EIGRP stub configuration on the redistributing router prevents routes from being advertised.
AnswerB

Without tags or a route-map filter, routes learned from OSPF are redistributed into EIGRP and then redistributed straight back into OSPF, and vice versa. Each protocol re-advertises the other's routes as its own, so the same prefix oscillates between domains, producing the mutual redistribution loop described.

Why this answer

When mutual redistribution is configured without route tagging or filtering, routes learned from OSPF can be redistributed into EIGRP and then redistributed back into OSPF (and vice versa). Because each protocol treats the redistributed route as a new external route, the metric and administrative distance can cause the router to prefer the re-injected path, creating a feedback loop. Route tagging (with a route-map that denies routes carrying the tag) is the standard method to prevent this two-way redistribution loop.

Exam trap

300-410 often tests the misconception that redistribution is a simple one-way operation; candidates forget that without route tagging or filtering, routes can be re-advertised back into the source protocol, creating a loop.

How to eliminate wrong answers

Option A is wrong because a missing seed metric causes EIGRP to reject redistributed routes (they won't be installed), which would prevent a loop rather than cause one. Option C is wrong because administrative distance only affects route selection between protocols; it does not by itself create a redistribution loop, and OSPF's AD (110) is actually higher than EIGRP's internal AD (90), so the statement is also factually incorrect. Option D is wrong because EIGRP stub configuration restricts what the router advertises, but it does not inherently prevent mutual redistribution loops and is not the most likely explanation here.

242
MCQhard

An engineer is troubleshooting an issue where a rogue IPv6 router is sending false Router Advertisements on the network, causing hosts to use a malicious default gateway. The switch is configured with IPv6 First Hop Security features. The engineer wants to prevent this attack while allowing the legitimate router to send RAs. What is the correct configuration approach?

A.Configure RA Guard with a policy that sets the legitimate router's port as 'device-role router' and all other ports as 'device-role host', and apply the policy globally.
B.Enable DHCPv6 Guard on all ports to block any DHCPv6 server messages, which will also block RAs.
C.Use IPv6 Source Guard to filter traffic from the rogue router based on its IPv6 address.
D.Configure a static IPv6 neighbor entry for the legitimate router on the switch to override rogue RAs.
AnswerA

RA Guard inspects Router Advertisement and Redirect messages, blocking them on ports marked device-role host while permitting them on the legitimate router's device-role router port. This satisfies the stem's constraint of stopping the rogue router yet allowing the legitimate one.

Why this answer

RA Guard is the correct IPv6 First Hop Security feature to block rogue Router Advertisements (RAs) while allowing legitimate RAs. By configuring a policy that sets the legitimate router's port as 'device-role router' and all other ports as 'device-role host', the switch will forward RAs only from the trusted router port and drop RAs received on host ports. This directly prevents the attack described.

Exam trap

Cisco often tests the distinction between IPv6 First Hop Security features (RA Guard, DHCPv6 Guard, Source Guard, ND Inspection) and expects candidates to know that only RA Guard specifically blocks rogue Router Advertisements based on port role.

How to eliminate wrong answers

Option B is wrong because DHCPv6 Guard blocks DHCPv6 server messages, not Router Advertisements; RAs are sent by routers using ICMPv6, not DHCPv6, so this would not prevent the attack. Option C is wrong because IPv6 Source Guard filters traffic based on source IPv6 address and MAC address binding, but a rogue router can use a legitimate IPv6 address or a different address, and Source Guard does not inspect RA content or device role. Option D is wrong because a static neighbor entry only maps an IPv6 address to a MAC address for neighbor discovery; it does not prevent the switch from forwarding rogue RAs to hosts, and hosts would still process the malicious RA.

243
MCQeasy

A router has a CoPP policy that includes a class-map matching all traffic from a specific source IP address (the management station) and polices it to 100000 bps. The engineer notices that SNMP polls from the management station are timing out. The SNMP traffic uses UDP port 161. The engineer checks the CoPP statistics and sees that the class for the management station has dropped packets. What is the most likely cause?

A.The CoPP police rate of 100000 bps is too low for the SNMP traffic from the management station.
B.The SNMP community string is incorrect on the management station.
C.The CoPP class-map is matching the wrong source IP address.
D.The SNMP agent on the router is not responding due to high CPU.
AnswerA

SNMP polling generates bursts of GET/GETNEXT requests and responses; 100000 bps is insufficient for the management station's polling volume, so the policer drops packets and polls time out. The dropped-packet counter confirms the rate limit is the constraint.

Why this answer

The CoPP policy polices traffic from the management station to 100,000 bps. SNMP polls typically consist of multiple small UDP packets (e.g., get-request, get-response), but the aggregate rate of these polls can exceed 100 kbps if the polling interval is aggressive or multiple OIDs are queried. The dropped packets in the CoPP class statistics confirm that the policer is throttling the SNMP traffic, causing timeouts.

Therefore, the police rate is too low for the actual SNMP traffic volume.

Exam trap

Cisco often tests the misconception that CoPP drops are always due to incorrect classification or CPU issues, but the trap here is that the engineer sees drops in the correct class, so the root cause is simply that the police rate is insufficient for the actual traffic load.

How to eliminate wrong answers

Option B is wrong because an incorrect SNMP community string would cause authentication failures (e.g., 'noSuchName' or timeouts due to access denial), not CoPP drops; the engineer already sees dropped packets in the CoPP class, which points to policing, not authentication. Option C is wrong because if the class-map matched the wrong source IP, the management station's traffic would not be classified into that class, and no drops would be seen for that class; the fact that drops are occurring in the class indicates the traffic is being matched correctly. Option D is wrong because high CPU on the router would cause general packet loss or slow responses, but the CoPP statistics show drops specifically in the management station's class, which is a direct result of the policer, not CPU overload; CoPP drops occur before the packets reach the control plane CPU.

244
MCQeasy

A network technician is configuring a Cisco router to act as a DHCP relay agent. The router's interface Gi0/0 is connected to the DHCP clients, and the DHCP server is reachable via interface Gi0/1. Which command must be configured on interface Gi0/0 to forward DHCP requests to the server at 192.168.1.10?

A.ip forward-protocol udp 192.168.1.10
B.ip dhcp relay 192.168.1.10
C.ip helper-address 192.168.1.10
D.ip dhcp-server 192.168.1.10
AnswerC

The 'ip helper-address' command is used on the interface facing the DHCP clients to forward broadcast DHCP requests to a specific DHCP server. It converts the broadcast to a unicast packet destined for the server. This is the correct command to enable DHCP relay functionality on the client-facing interface.

Why this answer

To configure a Cisco router as a DHCP relay agent, the 'ip helper-address' command is applied on the interface receiving DHCP broadcasts. It forwards these broadcasts as unicasts to the specified DHCP server. This allows clients on one subnet to obtain IP addresses from a server on another subnet.

Other commands like 'ip forward-protocol' are supplementary and do not specify the server.

Exam trap

The trap here is thinking that a dedicated DHCP relay command exists, such as 'ip dhcp relay', when in fact Cisco IOS uses the generic 'ip helper-address' to forward DHCP and other UDP broadcasts.

245
MCQmedium

A network engineer configured the following: monitor session 3 type erspan-source source interface GigabitEthernet0/0/2 rx destination erspan-id 2 ip address 10.0.0.2 origin ip address 10.0.0.1 What traffic will be mirrored?

A.Only traffic received on GigabitEthernet0/0/2.
B.Only traffic transmitted on GigabitEthernet0/0/2.
C.Both received and transmitted traffic on GigabitEthernet0/0/2.
D.All traffic on the router, regardless of interface.
AnswerA

The `rx` keyword restricts the source to ingress traffic only, so frames received on GigabitEthernet0/0/2 are copied to the ERSPAN destination. Egress traffic is excluded, satisfying the stem's mirroring constraint. Without `rx`, both directions would be captured.

Why this answer

The command 'source interface GigabitEthernet0/0/2 rx' specifies that only traffic received (rx) on GigabitEthernet0/0/2 will be mirrored. The 'rx' keyword indicates ingress traffic, so only incoming packets are copied to the ERSPAN destination.

Exam trap

300-410 often tests SPAN/ERSPAN direction keywords, and candidates may confuse 'rx' with 'tx' or 'both'.

How to eliminate wrong answers

Option B is wrong because 'tx' would be used for transmitted traffic, but the configuration uses 'rx'. Option C is wrong because 'both' would be used to mirror both received and transmitted traffic, but only 'rx' is specified. Option D is wrong because the source interface is explicitly defined, so only traffic on that interface is mirrored, not all traffic on the router.

246
MCQeasy

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 10.1.1.0/24 BGP routing table entry for 10.1.1.0/24, version 2 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 Local 10.1.1.1 from 0.0.0.0 (10.1.1.1) Origin IGP, metric 0, localpref 100, weight 32768, valid, sourced, best rx pathid: 0, tx pathid: 0x0 Based on this output, which statement is correct?

A.The route 10.1.1.0/24 was learned from an eBGP peer.
B.The route 10.1.1.0/24 is locally originated and is the best path.
C.The route 10.1.1.0/24 has a weight of 100.
D.The route 10.1.1.0/24 is not being advertised to any peer.
AnswerB

The output shows "Local" origin, weight 32768, and "sourced, best", confirming R1 injected 10.1.1.0/24 itself via the network or aggregate-address command rather than learning it from a peer. The "best" flag satisfies the stem's requirement to identify the selected path.

Why this answer

The output shows the route 10.1.1.0/24 with 'Local' origin, 'sourced' and 'best' flags, and weight 32768. This indicates the route is locally originated (e.g., via a network statement or redistribution) and is the best path. The 'Local' in the path indicates it was locally generated, not learned from a peer.

Exam trap

300-410 often tests the interpretation of BGP show command output; candidates may confuse locally originated routes with eBGP-learned routes or misread the weight value.

How to eliminate wrong answers

Option A is wrong because the route is locally originated, as indicated by 'Local' and 'sourced'; it was not learned from an eBGP peer. Option C is wrong because the weight is 32768, not 100; weight 32768 is the default for locally originated routes. Option D is wrong because the output shows 'Advertised to update-groups: 1', meaning the route is being advertised to peers.

247
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against route processor overload. The engineer creates a class map matching OSPF and BGP traffic and a policy map that polices this traffic to 1 Mbps with a burst of 2000 bytes. After applying the policy map to the control plane, the engineer notices that OSPF adjacencies flap intermittently. Which action should the engineer take to resolve the flapping?

A.Disable OSPF authentication to reduce packet size and processing overhead.
B.Configure a higher priority queue for OSPF traffic in the policy map.
C.Apply the policy map to all interfaces instead of the control plane.
D.Increase the policed rate and burst size to accommodate legitimate routing protocol traffic.
AnswerD

Intermittent OSPF adjacency flapping indicates that legitimate OSPF packets are being dropped due to the policer rate being too low. Increasing the rate and burst size allows the routing protocol traffic to pass without being policed, stabilizing the adjacencies. CoPP policies must be tuned to permit normal control plane traffic while still protecting against attacks.

Why this answer

CoPP policies that are too restrictive can drop legitimate control plane traffic, causing routing protocol adjacencies to flap. In this scenario, the policer rate of 1 Mbps is insufficient for OSPF and BGP traffic, leading to intermittent OSPF drops. Increasing the policed rate and burst size allows normal routing updates to pass while still providing protection against excessive traffic.

Exam trap

The trap here is assuming that any control plane policing is beneficial, without considering that overly aggressive rate limits can disrupt legitimate routing protocol operations.

248
MCQmedium

A network engineer configured IP SLA 30 to monitor the reachability of a server (10.10.10.10) using ICMP echo probes. The IP SLA is linked to a track object that is used in a static default route. The engineer notices that the IP SLA state is 'Active', but the static route is not present in the routing table. The track object shows 'Up'. What should the engineer check first?

A.Verify that the static route includes the 'track' keyword and references the correct track object number.
B.Check if the server is responding to ICMP echo requests.
C.Ensure the IP SLA probe is configured with a timeout value less than the frequency.
D.Reboot the router to clear any routing table inconsistencies.
AnswerA

The track object reports Up, so the SLA and tracking are functioning; the fault lies in the route's binding. Without the 'track' keyword referencing that object, the static route installs unconditionally or not at all, so verifying the route's track association is the logical first check.

Why this answer

The most likely issue is that the static route does not include the 'track' keyword or references the wrong track object number. Even if the IP SLA and track object are up, the route will not be installed if it is not explicitly linked to the track object. The engineer should first verify the static route configuration to ensure it includes 'track <object-number>' and that the number matches the track object.

Exam trap

300-410 often tests the requirement that a static route must explicitly include the 'track' keyword to be affected by IP SLA, causing candidates to overlook this and focus on IP SLA or server issues instead.

How to eliminate wrong answers

Option B is wrong because the track object shows 'Up', which means the IP SLA probe is succeeding and the server is responding to ICMP; checking server responsiveness is redundant. Option C is wrong because the IP SLA state is 'Active' and track is 'Up', indicating the probe is operating correctly; timeout versus frequency would affect probe operation, not the route installation. Option D is wrong because rebooting is a drastic and unnecessary step; routing table inconsistencies are not resolved by reboots, and the issue is likely configuration-related.

249
MCQmedium

Router R2 has the following configuration: ``` interface GigabitEthernet0/2 ip address 10.2.2.2 255.255.255.0 ip policy route-map CHECK ! route-map CHECK permit 10 match ip address 101 set interface GigabitEthernet0/3 ! access-list 101 permit tcp any any eq 80 ``` What is the effect of this configuration?

A.Incoming TCP packets with destination port 80 on G0/2 are forwarded out G0/3, overriding the routing table.
B.Outgoing TCP packets with source port 80 on G0/2 are forwarded out G0/3.
C.All TCP traffic is forwarded out G0/3 regardless of port.
D.The configuration is invalid because 'set interface' cannot be used with a route-map.
AnswerA

The route-map matches TCP port 80 via ACL 101 and sets the output interface to GigabitEthernet0/3. Policy-based routing is evaluated before the routing table, so matching inbound packets are switched out G0/3 regardless of the destination-based route.

Why this answer

The route-map matches TCP traffic with destination port 80 (HTTP) and sets the output interface to GigabitEthernet0/3. This is applied inbound on GigabitEthernet0/2.

250
MCQmedium

A network engineer is configuring OSPF on a router that connects to a broadcast Ethernet segment. The router is connected to a switch that also connects to three other OSPF routers. The engineer wants to ensure that this router does not become the Designated Router (DR) or Backup Designated Router (BDR) on this segment, but still participates in OSPF. Which configuration should the engineer apply on the router's interface?

A.ip ospf database-filter all out
B.ip ospf priority 255
C.ip ospf priority 0
D.ip ospf network point-to-point
AnswerC

Setting the OSPF priority to 0 on the interface prevents the router from being elected as DR or BDR on that segment. It will still form adjacencies and participate in OSPF as a DROTHER. This is the standard method to ensure a router does not take on the DR/BDR role while remaining an active OSPF participant.

Why this answer

The OSPF priority value is used in the DR/BDR election on broadcast and non-broadcast multi-access segments. A priority of 0 makes the router ineligible to become DR or BDR, while still allowing it to form adjacencies and exchange routing information. This is the correct way to keep a router as a DROTHER on a segment where it should not take on a primary role.

Exam trap

The trap here is confusing OSPF priority with other interface parameters, or assuming that a high priority prevents DR election rather than encourages it.

251
MCQmedium

A network engineer is configuring a site-to-site DMVPN Phase 3 hub router. The hub uses a single mGRE tunnel interface with the IP address 10.0.0.1/24. Spoke routers are configured with NHS 10.0.0.1 and are in the same subnet. The engineer wants spoke-to-spoke traffic to bypass the hub after the initial resolution. Which command must be configured on the hub to enable Phase 3 shortcut switching?

A.ip nhrp shortcut
B.ip nhrp network-id 100
C.ip nhrp map multicast dynamic
D.ip nhrp redirect
AnswerD

The ip nhrp redirect command on the hub enables NHRP redirect messages, which inform the originating spoke that a better path exists directly to the destination spoke. This triggers the spoke to send an NHRP resolution request for the destination's NBMA address, allowing the spoke to build a direct tunnel, which is the defining behavior of DMVPN Phase 3.

Why this answer

In DMVPN Phase 3, the hub must be configured with ip nhrp redirect to send redirect messages to spokes when it forwards traffic to another spoke. The spokes must have ip nhrp shortcut to act on those redirects. Together, they allow spoke-to-spoke direct tunnels after initial hub-based resolution.

The hub's role is to redirect, so ip nhrp redirect is the correct command on the hub.

Exam trap

The trap here is confusing the hub-side and spoke-side commands, thinking that ip nhrp shortcut is configured on the hub when it is actually a spoke command.

252
MCQmedium

An engineer is troubleshooting a DMVPN phase 2 network where the hub router is not forming an EIGRP neighbor relationship with a spoke. The spoke's tunnel interface is configured with 'ip nhrp nhs 10.0.0.1' and 'ip nhrp map 10.0.0.1 192.168.1.1'. The hub's tunnel interface IP is 10.0.0.1. The engineer pings the hub's tunnel IP from the spoke and it succeeds. The engineer checks 'show ip eigrp neighbors' on the hub and sees no neighbors. What is the most likely cause?

A.The spoke's tunnel interface is missing the 'ip nhrp map multicast dynamic' command.
B.The hub's tunnel interface has 'no ip nhrp redirect' configured.
C.The spoke's EIGRP AS number does not match the hub's.
D.The hub's tunnel interface has 'ip nhrp authentication' configured but the spoke does not.
AnswerA

Correct because without multicast mapping, the spoke cannot send multicast traffic (including EIGRP hellos) to the hub.

Why this answer

EIGRP neighbor formation over a tunnel requires multicast support. In DMVPN, multicast traffic is sent via NHRP to the hub. If the spoke's tunnel interface does not have 'ip nhrp map multicast dynamic' or a static multicast map, the hub will not receive EIGRP hello packets from the spoke.

253
MCQeasy

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# show ip access-lists 101 Extended IP access list 101 10 permit tcp 192.168.1.0 0.0.0.255 any eq 80 (12 matches) 20 deny tcp any any eq 443 (5 matches) 30 permit ip any any (100 matches) What does this output indicate?

A.The ACL is permitting TCP traffic from 192.168.1.0/24 to any destination on port 80, denying all TCP traffic to port 443, and permitting all other IP traffic.
B.The ACL is denying all traffic because line 20 is an explicit deny.
C.The ACL is applied inbound on an interface and is blocking all traffic to port 443.
D.The ACL has no effect because the match counts are too low.
AnswerA

Sequence numbers 10, 20 and 30 are evaluated top-down: line 10 permits TCP port 80 from 192.168.1.0/24, line 20 denies TCP port 443 from any source, and line 30 permits all remaining IP traffic, with match counters confirming each entry's hits.

Why this answer

The ACL explicitly permits TCP traffic from source 192.168.1.0/24 to any destination on port 80 (line 10), denies TCP traffic from any source to any destination on port 443 (line 20), and then permits all other IP traffic (line 30). The match counts confirm that traffic matching each line has been processed, and the implicit deny at the end is never reached because line 30 permits everything else.

Exam trap

Cisco often tests the misconception that an explicit deny statement (like line 20) blocks all traffic, when in fact it only blocks the specific protocol and port, and subsequent permit entries can still allow other traffic.

How to eliminate wrong answers

Option B is wrong because line 20 is an explicit deny for TCP port 443 only, not an implicit deny at the end of the ACL; the ACL continues to line 30 which permits all other IP traffic, so it does not deny all traffic. Option C is wrong because the output does not indicate the direction (inbound or outbound) or the interface where the ACL is applied; the show ip access-lists command only displays the ACL contents and match counters, not its application point. Option D is wrong because match counts are not required to be high for an ACL to have effect; even low counts indicate that traffic has matched, and the ACL is actively filtering based on its entries.

254
MCQeasy

What is the default NHRP holdtime value on a Cisco router?

A.3600 seconds
B.1800 seconds
C.7200 seconds
D.600 seconds
AnswerA

The default NHRP holdtime on Cisco routers is 3600 seconds, matching the stem's request for the default value. This timer governs how long a cached NHRP mapping stays valid before expiry, so 3600 seconds is the correct default figure.

Why this answer

The default NHRP holdtime is 3600 seconds (1 hour). This value can be modified with the 'ip nhrp holdtime' command.

255
MCQmedium

Consider the following partial configuration on router R2: interface GigabitEthernet0/0 ip address 10.0.0.2 255.255.255.0 ip ospf 1 area 0 ! interface GigabitEthernet0/1 ip address 192.168.1.2 255.255.255.0 ip ospf 1 area 0 ! router ospf 1 router-id 2.2.2.2 network 10.0.0.0 0.0.0.255 area 0 network 192.168.1.0 0.0.0.255 area 0 What is the effect of this configuration?

A.OSPF will not form adjacencies because the interface and network commands conflict, causing OSPF to ignore the network statements.
B.OSPF will form adjacencies on both interfaces, but the router-id 2.2.2.2 will be overridden by the highest loopback IP.
C.OSPF will form adjacencies on both interfaces as intended; the configuration is redundant but functional.
D.OSPF will only form adjacency on GigabitEthernet0/1 because the network statement for 10.0.0.0 is incorrect.
AnswerC

Enabling OSPF per interface with 'ip ospf 1 area 0' already advertises both networks, so the router ospf 'network' statements merely duplicate that coverage. Adjacencies still form on both GigabitEthernet interfaces, making the configuration redundant yet fully functional.

Why this answer

The configuration redundantly enables OSPF on both interfaces via both the `ip ospf 1 area 0` interface-level command and the `network` statements under the OSPF process. This is valid and does not cause conflicts; OSPF will form adjacencies on both interfaces as intended. The router-id 2.2.2.2 is explicitly configured and will not be overridden by any loopback IP unless the router-id is not set or is removed.

Exam trap

The trap here is that candidates often think interface-level and network-level OSPF commands conflict or cause redundancy errors, when in fact they are both valid and can coexist without issue.

How to eliminate wrong answers

Option A is wrong because interface and network commands do not conflict; they are both valid ways to enable OSPF on an interface, and OSPF does not ignore network statements when interface commands are present. Option B is wrong because the explicitly configured `router-id 2.2.2.2` takes precedence over any loopback IP; the router-id is only overridden by a higher loopback IP if no explicit router-id is configured. Option D is wrong because the network statement `10.0.0.0 0.0.0.255 area 0` is correct and matches the interface GigabitEthernet0/0; OSPF will form adjacency on both interfaces.

256
MCQmedium

Which of the following statements about MPLS label imposition and disposition is true?

A.The egress LER always performs the label pop operation.
B.The ingress LER performs the label push operation, and the egress LER performs the label pop operation unless PHP is used.
C.The penultimate hop router always pushes an additional label.
D.Label disposition occurs only at the ingress LER.
AnswerB

At the ingress LER, the label push operation imposes an MPLS label on incoming packets; at the egress LER, the label pop operation removes it. With Penultimate Hop Popping, the penultimate router pops the label instead, so the egress LER receives an unlabelled packet.

Why this answer

In MPLS, the ingress Label Edge Router (LER) imposes (pushes) a label onto incoming IP packets, and the egress LER typically removes (pops) the label before forwarding the packet to the destination network. However, with Penultimate Hop Popping (PHP), the penultimate router pops the label so that the egress LER receives an unlabeled packet, reducing its processing load. Thus, statement B is correct.

Exam trap

The 300-410 exam often tests the misconception that the egress LER always pops the label, ignoring PHP, or that the penultimate router pushes labels, confusing imposition with disposition.

How to eliminate wrong answers

Option A is wrong because the egress LER does not always perform the pop; with PHP, the penultimate router does it. Option C is wrong because the penultimate hop router does not push an additional label; it may pop the label if PHP is enabled. Option D is wrong because label disposition (popping) occurs at the egress LER or penultimate router, not only at the ingress LER; the ingress LER performs imposition (pushing).

257
MCQmedium

A network engineer is configuring a Cisco IOS XE router for Zone-Based Policy Firewall (ZPFW) to control traffic between a LAN zone and a WAN zone. The engineer wants to inspect all TCP and UDP traffic initiated from the LAN zone toward the WAN zone, while denying any traffic initiated from the WAN zone toward the LAN zone. The engineer has already created the zones and assigned interfaces. Which configuration step is required to achieve this?

A.Apply an access-list to the WAN interface inbound to block all traffic and an access-list to the LAN interface inbound to permit all traffic.
B.Configure a zone-pair from WAN to LAN and apply a policy-map that inspects all traffic, then configure a zone-pair from LAN to WAN with a policy-map that drops all traffic.
C.Enable Cisco IOS Firewall with the ip inspect command on the LAN interface and apply an inbound access-list on the WAN interface to deny all traffic.
D.Create a class-map that matches all TCP and UDP traffic, define a policy-map with inspect for that class, and apply the policy-map to the zone-pair from LAN to WAN using the service-policy command.
AnswerD

Zone-Based Policy Firewall requires a class-map to identify traffic, a policy-map to specify the action (inspect), and application of the policy-map to a zone-pair using the service-policy command. The zone-pair direction (LAN to WAN) determines the traffic flow to inspect, and by default, traffic not explicitly permitted is dropped, satisfying the requirement to deny WAN-initiated traffic.

Why this answer

To implement Zone-Based Policy Firewall, you must define class-maps to identify traffic, policy-maps to specify actions (such as inspect), and apply the policy-map to a zone-pair with the service-policy command. Inspecting traffic from LAN to WAN allows return traffic while denying unsolicited WAN-initiated traffic, as traffic not explicitly permitted between zones is dropped by default.

Exam trap

The trap here is assuming that a simple access-list can provide stateful inspection or that applying a policy-map in the wrong direction will still meet the requirement.

258
MCQeasy

A network administrator is configuring a GRE tunnel between two Cisco routers to transport IPv6 traffic over an IPv4-only core. The administrator enters the following configuration on Router A: interface Tunnel0 ipv6 address 2001:DB8:100::1/64 tunnel source 10.1.1.1 tunnel destination 10.2.2.2 tunnel mode gre ipv6 However, the tunnel interface remains down. What is the most likely cause?

A.The tunnel source and destination must be IPv6 addresses, not IPv4.
B.The tunnel mode should be gre ipv6, but it is incorrectly set to gre ipv4.
C.The tunnel interface requires an IPv4 address in addition to the IPv6 address to become operational.
D.The physical interface providing the tunnel source address is not operational or there is no route to the tunnel destination.
AnswerD

A GRE tunnel interface remains down if the tunnel source address is not up or if there is no route to the tunnel destination. The administrator must ensure the physical interface with the source address is operational and that a route exists to 10.2.2.2. Without reachability, the tunnel cannot come up.

Why this answer

A GRE tunnel interface will only come up if the tunnel source is operational and there is a route to the tunnel destination. In this scenario, the tunnel source is 10.1.1.1, which must be assigned to an up interface, and the router must have a route to 10.2.2.2. Without these conditions, the tunnel remains down regardless of the tunnel mode or IPv6 configuration.

Exam trap

The trap here is focusing on the tunnel mode or IPv6 addressing while overlooking that the tunnel source interface must be up and the destination must be reachable.

259
MCQhard

A network engineer runs the following command to troubleshoot a VRF-Lite DMVPN issue: R1# show ip nhrp vrf CUSTOMER_G detail Output: 10.6.6.1/32 via 10.6.6.1, Tunnel0 created 00:01:00, expire 01:59:00 Type: dynamic, Flags: used NBMA address: 192.168.1.1 (no-socket) Registration handle: 0x00000001 Cache entries: 1 What does this output indicate?

A.The NHRP mapping is static and was manually configured.
B.The NHRP mapping for 10.6.6.1 is dynamic, with NBMA address 192.168.1.1, and is actively used.
C.The NHRP mapping has expired and needs to be refreshed.
D.The NHRP mapping is for a multicast group address.
AnswerB

The Type field shows dynamic, meaning the mapping was learned via NHRP registration rather than statically configured, and the Flags field shows used, confirming active traffic. The NBMA address 192.168.1.1 maps to the tunnel IP 10.6.6.1.

Why this answer

The 'show ip nhrp vrf detail' command displays NHRP cache entries for a specific VRF. The output shows a dynamic NHRP mapping for destination 10.6.6.1/32, with NBMA address 192.168.1.1, learned via Tunnel0. The entry was created 1 minute ago and will expire in 1 hour 59 minutes.

The 'used' flag indicates the mapping is actively being used.

260
Multi-Selecthard

Which THREE statements about IPv6 Source Guard are true? (Choose THREE.)

Select 3 answers
A.It filters IPv6 traffic based on the source IPv6 address of incoming packets.
B.It relies on the IPv6 snooping binding table, which is populated by DHCPv6 snooping or ND Inspection.
C.It can be configured to allow traffic from specific prefixes using a static prefix list.
D.It filters both incoming and outgoing IPv6 traffic on a port.
E.It requires DHCPv6 snooping to be enabled on the VLAN to function.
AnswersA, B, C

IPv6 Source Guard inspects incoming packets and drops those whose source IPv6 address is not present in the IPv6 snooping binding table, filtering strictly on the source address field rather than destination or traffic type.

Why this answer

Option A is correct because IPv6 Source Guard is a Layer 2 security feature that inspects incoming frames and drops those whose source IPv6 address does not match an entry in the IPv6 snooping binding table. Option B is correct because that binding table is the foundation of the feature, and it is populated dynamically by DHCPv6 snooping (for DHCPv6-assigned addresses) or by IPv6 ND Inspection (for statelessly autoconfigured or manually configured addresses). Option C is correct because IPv6 Source Guard supports a static prefix list, allowing an administrator to permit traffic from specific IPv6 prefixes in addition to the addresses learned in the binding table.

Option D is not correct because IPv6 Source Guard operates only on ingress (incoming) traffic on a port, not on outgoing traffic. Option E is not correct because DHCPv6 snooping is not mandatory; the binding table can also be populated by ND Inspection, so the feature can function without DHCPv6 snooping being enabled on the VLAN.

Exam trap

Cisco often tests the misconception that IPv6 Source Guard filters both inbound and outbound traffic, when in fact it only filters inbound traffic, and the trap here is assuming DHCPv6 snooping is mandatory when ND Inspection can also supply the binding table.

261
MCQeasy

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# show ip sla statistics 10 Round Trip Time (RTT) for Index 10 Latest RTT: 12 ms Latest RTT (milliseconds): 12 Latest RTT (microseconds): 12000 Last operation start time: 12:34:56.789 UTC Mon Mar 1 2021 Last operation return code: OK Number of successes: 100 Number of failures: 0 Operation time to live: Forever What does this output indicate?

A.The IP SLA operation has failed because the RTT is too low.
B.The IP SLA operation is working correctly with no failures.
C.The IP SLA operation has timed out and needs to be reconfigured.
D.The IP SLA operation is not configured for this index.
AnswerB

Latest RTT of 12 ms with return code OK, 100 successes and zero failures confirms the operation completes successfully each cycle. The probe target responds within acceptable latency, so no packet loss or timeout condition exists on this IP SLA operation.

Why this answer

The output shows 'Last operation return code: OK', 100 successes, and 0 failures, indicating the IP SLA operation is functioning correctly. The latest RTT of 12 ms is a normal, healthy round-trip time, not a failure condition.

Exam trap

300-410 often tests whether candidates misinterpret a low RTT as a problem or confuse a healthy return code with a timeout, so they must read the return code and failure counters carefully.

How to eliminate wrong answers

Option A is wrong because a low RTT is desirable, not a failure; IP SLA failures are indicated by return codes other than OK or by failure counters. Option C is wrong because there is no timeout indication — the return code is OK and failures are zero. Option D is wrong because the operation clearly exists for index 10, as evidenced by the statistics displayed.

262
MCQmedium

A network engineer runs the following command on Router R1: R1# show crypto isakmp sa detail Codes: C - IKEv1, I - IKEv2 C-id Local Remote I-VRF Status Encr Hash Auth DH Lifetime Cap 1 10.1.1.1 10.1.1.2 ACTIVE aes sha psk 14 23:59:59 Based on this output, which statement is correct?

A.The IKEv1 SA is established with the peer 10.1.1.2.
B.The IKEv2 SA is established with the peer 10.1.1.2.
C.The ISAKMP SA is not established; status is MM_NO_STATE.
D.The Diffie-Hellman group is group 2.
AnswerA

The "C" code confirms IKEv1, and the ACTIVE status with peer 10.1.1.2 shows the security association is fully established. The DH group 14, AES encryption, SHA hash and pre-shared-key authentication parameters all match, satisfying the stem's requirement to interpret the `show crypto isakmp sa detail` output correctly.

Why this answer

The ISAKMP SA is active, using AES encryption, SHA hash, pre-shared key authentication, and Diffie-Hellman group 14. The lifetime is about 24 hours.

263
MCQhard

A network engineer runs the following command to troubleshoot a Control Plane Policing (CoPP) issue: R1# show policy-map control-plane input class CoPP-Class Class-map: CoPP-Class (match-all) 1500 packets, 120000 bytes 5 minute offered rate 10000 bps, drop rate 5000 bps Match: access-group name CoPP-ACL police: cir 8000 bps, bc 1500 bytes, be 1500 bytes conformed 1000 packets, 80000 bytes; actions: transmit exceeded 500 packets, 40000 bytes; actions: drop conformed 8000 bps, exceed 2000 bps, violated 0 bps What does this output indicate?

A.The CoPP policy is dropping all traffic because the CIR is too low.
B.The CoPP policy is causing packet loss for traffic that exceeds the 8 kbps rate, which may impact legitimate control plane traffic.
C.The CoPP policy is not applied correctly because the drop rate is higher than the conform rate.
D.The CoPP policy is working as intended with no issues.
AnswerB

The police statement enforces a committed information rate of 8000 bps, and the exceeded counter shows 500 packets dropped once traffic surpassed that threshold. Because CoPP polices traffic destined to the route processor, this loss can discard legitimate routing protocol and management packets, degrading adjacency stability and remote access.

Why this answer

The output shows that the CoPP policy uses a CIR of 8000 bps with a conformed rate of 8000 bps and an exceed rate of 2000 bps. The drop rate of 5000 bps indicates that traffic exceeding the CIR is being dropped, which can include legitimate control plane traffic (e.g., routing protocol packets) if they are classified under the CoPP-Class. This confirms that the policy is causing packet loss for traffic that exceeds the 8 kbps rate, potentially impacting critical control plane operations.

Exam trap

Cisco often tests the misinterpretation of CoPP output statistics, where candidates confuse the 'drop rate' with the 'exceed rate' or assume that a high drop rate always indicates a misconfiguration, rather than recognizing that it shows the policer is actively dropping traffic that exceeds the CIR, which may be intentional or problematic depending on the traffic class.

How to eliminate wrong answers

Option A is wrong because the policy is not dropping all traffic; it drops only exceeded traffic (500 packets) while conformed traffic (1000 packets) is transmitted, so the CIR is not too low for all traffic. Option C is wrong because the drop rate (5000 bps) being higher than the conform rate (8000 bps) is not an indication of incorrect application; CoPP uses a single-rate policer where exceeded traffic is dropped, and the drop rate can be lower than the conform rate as seen here. Option D is wrong because the policy is not working as intended; the drop rate of 5000 bps indicates packet loss, which may affect legitimate control plane traffic if the CoPP-ACL matches such traffic.

264
MCQmedium

Examine the following configuration: logging host 10.1.1.1 logging host 10.1.1.2 logging host 10.1.1.3 logging origin-id hostname logging facility local7 What is the purpose of the 'logging origin-id hostname' command?

A.It causes the syslog messages to include the router's hostname as the origin, overriding the default IP address.
B.It sets the syslog message format to include the hostname in the timestamp field.
C.It configures the router to send syslog messages only when the hostname changes.
D.It is used to authenticate syslog messages using the hostname as a key.
AnswerA

The origin-id hostname setting replaces the default source IP address in syslog message headers with the device's configured hostname, letting the three logging hosts at 10.1.1.1–10.1.1.3 identify which router sent each message. This satisfies the need to distinguish the originating device when multiple routers forward to shared collectors.

Why this answer

The logging origin-id hostname command changes the origin identifier in syslog messages from the default (the source IP address of the sending interface) to the router's configured hostname. This makes it easier for the syslog server to identify which device sent the message, especially when the source IP changes or is NATed. It does not affect timestamps, message filtering, or authentication.

Exam trap

300-410 often tests the confusion between origin-id (hostname field in syslog header) and timestamp formatting or message filtering — candidates assume origin-id affects timestamps or authentication, which it does not.

How to eliminate wrong answers

Option B is wrong because the timestamp field is controlled by logging timestamps commands (e.g., logging timestamp datetime), not origin-id. Option C is wrong because origin-id does not filter or condition message sending on hostname changes; it simply sets the origin identifier. Option D is wrong because syslog authentication is not provided by origin-id — syslog is inherently unauthenticated unless you use TLS (syslog over TLS) or IPsec.

265
MCQmedium

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against DoS attacks. The administrator wants to rate-limit ARP traffic destined to the route processor. Which configuration correctly applies a CoPP policy to ARP traffic?

A.class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! interface Control-Plane service-policy input COPP_POLICY
B.class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! control-plane host service-policy input COPP_POLICY
C.class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY
D.class-map match-all ARP_CLASS match access-group name ARP_ACL ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! interface GigabitEthernet0/0 service-policy input COPP_POLICY
AnswerC

This configuration defines a class-map that matches ARP protocol traffic, a policy-map that applies policing to that class, and then attaches the policy to the control-plane interface using 'service-policy input'. The 'match protocol arp' command is valid for classifying ARP packets. This correctly implements CoPP for ARP.

Why this answer

Control Plane Policing (CoPP) is configured by defining class-maps to match traffic, policy-maps to define actions, and then attaching the policy to the control plane using the 'control-plane' global configuration mode with 'service-policy input'. The class-map must match ARP traffic using 'match protocol arp'. This setup rate-limits ARP packets destined to the route processor, protecting it from DoS attacks.

Exam trap

The trap here is applying the CoPP policy to a physical interface instead of the control plane.

266
MCQeasy

A network engineer runs the following command on Router R9: R9# show ip route 192.168.50.0 Routing entry for 192.168.50.0/24 Known via "ospf 1", distance 110, metric 20 Redistributing via ospf 1 Last update from 10.0.0.1 on GigabitEthernet0/0, 00:00:10 ago Routing Descriptor Blocks: * 10.0.0.1, from 10.0.0.1, 00:00:10 ago, via GigabitEthernet0/0 Route metric is 20, traffic share count is 1 R9 also has an EIGRP route for the same prefix with distance 90 and metric 28160. Which route will be installed?

A.The OSPF route will be installed because it has a lower metric.
B.The EIGRP route will be installed because it has a lower administrative distance.
C.Both routes will be installed for load balancing.
D.Neither route will be installed due to a conflict.
AnswerB

Cisco IOS selects routes by lowest administrative distance before comparing metrics. EIGRP's AD of 90 beats OSPF's 110, so the EIGRP path enters the routing table despite its higher metric of 28160, satisfying the stem's selection criteria.

Why this answer

EIGRP internal routes have a default administrative distance of 90, which is lower than OSPF's default distance of 110. Therefore, the EIGRP route will be preferred and installed in the routing table.

267
MCQmedium

An engineer configures a Cisco IOS router with two static routes to the 10.10.0.0/16 network: one via 192.168.1.1 with administrative distance 1, and another via 192.168.2.1 with administrative distance 200. The route via 192.168.1.1 is installed in the routing table. Later, the interface to 192.168.1.1 goes down. Which statement describes the router's behavior?

A.The router removes both static routes and sends an ICMP redirect to the source.
B.The router keeps the route via 192.168.1.1 in the routing table but marks it as unreachable.
C.The router load-balances traffic between the two next hops because both are configured.
D.The router immediately installs the route via 192.168.2.1 in the routing table.
AnswerD

When the interface for the primary static route fails, the route is removed from the routing table. The router then evaluates the floating static route, which has a higher administrative distance (200) but becomes the best available path. It is installed in the routing table, allowing traffic to use the backup path. This is the intended design of a floating static route for redundancy.

Why this answer

The primary static route via 192.168.1.1 with administrative distance 1 is preferred. When its interface goes down, the route is removed. The floating static route via 192.168.2.1, with administrative distance 200, becomes the best available path and is installed.

This provides redundancy without dynamic routing protocols.

Exam trap

The trap here is assuming that a higher administrative distance route is never used unless there is a failure, but forgetting that it will be used after the primary route is withdrawn.

268
MCQmedium

A network engineer is deploying a GET VPN solution across a service provider MPLS network. The company requires that all group members use the same encryption keys and that any group member can decrypt traffic from any other group member. Which key distribution method should the engineer configure?

A.Configure FlexVPN with IKEv2 and a single IPsec profile on the hub.
B.Configure DMVPN with NHRP and IPsec profiles on all routers.
C.Configure IKEv2 with a single pre-shared key on all group members.
D.Configure GDOI with a key server that distributes the Group Encryption Key and Group Anti-Replay key.
AnswerD

GDOI is the Group Domain of Interpretation protocol used by GET VPN. The key server distributes the Group Encryption Key (used for traffic encryption) and the Group Anti-Replay key to all group members, enabling any group member to decrypt traffic from any other member without direct IPsec tunnels between them.

Why this answer

GET VPN uses GDOI to distribute group keys from a key server to all group members. This allows any member to encrypt and decrypt traffic for any other member using the same Group Encryption Key and Group Anti-Replay key, without building point-to-point IPsec tunnels. IKEv2, DMVPN, and FlexVPN do not provide this group key distribution model.

Exam trap

The trap here is assuming that any IPsec keying protocol can distribute group keys, when only GDOI is designed for GET VPN group key management.

269
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate SSH users against a TACACS+ server. The engineer wants to ensure that if the TACACS+ server is unreachable, the router will fall back to using the local username and password configured on the router. Which command set correctly configures this fallback behavior?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default group tacacs+ enable
C.aaa authentication login default local group tacacs+
D.aaa authentication login default group tacacs+ none
AnswerA

This command configures the default login authentication method list to first try TACACS+ and then fall back to the local username database if the server is unavailable. The 'local' keyword ensures local authentication is attempted only if the TACACS+ group fails or is unreachable, providing the desired fallback.

Why this answer

The correct command is 'aaa authentication login default group tacacs+ local'. The order of methods in the AAA authentication list is significant: the router tries each method in sequence until one succeeds. Placing 'group tacacs+' first ensures TACACS+ is preferred, and 'local' second ensures fallback to the local user database if the server is unreachable or rejects the credentials.

Exam trap

The trap here is assuming that the order of methods in the AAA authentication list does not matter or that 'local' must come first to be used as fallback.

270
MCQhard

A network engineer runs the following command to troubleshoot OSPF route redistribution: R1# show ip ospf database external 5.5.5.5 OSPF Router with ID (1.1.1.1) (Process ID 1) Type-5 AS External Link States LS age: 120 Options: (No TOS-capability, DC, Upward) LS Type: AS External Link Link State ID: 5.5.5.5 (External Network Number) Advertising Router: 3.3.3.3 LS Seq Number: 80000001 Checksum: 0xABCD Length: 36 Network Mask: /32 Metric Type: 2 (Larger than any link state path) TOS: 0 Metric: 20 Forward Address: 0.0.0.0 External Route Tag: 0 What does this output indicate?

A.The prefix 5.5.5.5/32 is a network inside the OSPF domain.
B.The route was redistributed into OSPF by router 3.3.3.3 with a metric of 20.
C.The forward address indicates the next-hop is 5.5.5.5.
D.This is a Type 4 Summary ASBR LSA.
AnswerB

The Type-5 AS External Link State Advertised by Advertising Router 3.3.3.3 confirms that router originated the redistribution, while Metric Type 2 with Metric 20 shows the external cost assigned. The Forward Address of 0.0.0.0 means traffic reaches 5.5.5.5 via the advertising router itself, satisfying the stem's redistribution query.

Why this answer

The output shows a Type-5 AS External LSA for 5.5.5.5/32, advertised by router 3.3.3.3, with Metric Type 2 and a metric of 20. This means 3.3.3.3 (an ASBR) redistributed the external prefix into OSPF, and the cost of 20 is the external metric carried in the LSA. The Forward Address of 0.0.0.0 indicates the route should be reached via the advertising ASBR itself.

Exam trap

The trap is misreading the Forward Address field — candidates often assume 0.0.0.0 means the destination itself, when it actually means 'use the advertising ASBR as next-hop,' and they may also confuse Type-5 external LSAs with Type-4 ASBR summary LSAs.

How to eliminate wrong answers

Option A is wrong because a Type-5 AS External LSA represents a prefix external to the OSPF domain (redistributed from another protocol or static), not an internal OSPF network — internal networks use Type 1 and Type 2 LSAs. Option C is wrong because a Forward Address of 0.0.0.0 means the forwarding address is not set, so traffic goes through the advertising ASBR (3.3.3.3), not through 5.5.5.5; a non-zero forward address would indicate an alternate next-hop. Option D is wrong because Type 4 LSAs are Summary ASBR LSAs generated by ABRs to describe how to reach an ASBR in another area — this output is explicitly a Type-5 AS External Link State.

271
MCQhard

A network architect is designing a BGP routing policy to influence inbound traffic from an ISP. The architect wants to make a specific prefix less preferred by the ISP by prepending the AS path multiple times. Which BGP attribute should be manipulated to achieve this?

A.LOCAL_PREF
B.MED
C.AS_PATH
D.NEXT_HOP
AnswerC

AS_PATH is a well-known mandatory attribute that lists the autonomous systems a route has traversed. By prepending additional AS numbers to the AS_PATH, the path length increases, making the route less preferred by BGP's best path selection process. This is a common method to influence inbound traffic, as the ISP will prefer shorter AS paths.

Why this answer

AS_PATH prepending is a technique where the local AS number is added multiple times to the AS_PATH attribute of a route advertised to external peers. This increases the path length, making the route less attractive to the receiving ISP, as BGP prefers shorter AS paths. This is a standard method for influencing inbound traffic in a multi-homed environment.

Exam trap

The trap here is confusing attributes used for inbound versus outbound traffic influence, or assuming MED is always effective for inbound traffic.

272
MCQeasy

What is the maximum number of IPv6 over IPv4 tunnels that can be configured on a Cisco IOS router?

A.256
B.1024
C.Platform-dependent, no fixed maximum.
D.64
AnswerC

Cisco IOS imposes no fixed protocol-level ceiling on IPv6 over IPv4 tunnel interfaces; the practical limit depends on the platform's memory, interface capacity and hardware resources. The maximum is therefore platform-dependent rather than a universal number.

Why this answer

C is correct because the maximum number of IPv6 over IPv4 tunnels on a Cisco IOS router is platform-dependent and limited by available system resources such as CPU and memory, not by a fixed software limit. Cisco IOS does not impose a hard-coded maximum; the actual number depends on the router model, the type of tunnel (e.g., manual, 6to4, ISATAP, GRE), and the configuration complexity.

Exam trap

Cisco often tests the misconception that there is a fixed numerical limit (like 256, 1024, or 64) for IPv6 over IPv4 tunnels, when in fact the correct answer is that the limit is platform-dependent and resource-driven.

How to eliminate wrong answers

Option A is wrong because 256 is not a universal limit; while some older platforms might have had lower practical limits, modern Cisco IOS routers can support far more tunnels. Option B is wrong because 1024 is a common misconception based on a default limit for certain tunnel types (e.g., 6to4) in some IOS versions, but it is not a fixed maximum and can be exceeded with proper resource allocation. Option D is wrong because 64 is too low and does not reflect the scalability of Cisco IOS; it might be confused with the maximum number of tunnels in a specific legacy feature or a different protocol context.

273
MCQeasy

What is the default BGP hold timer value in Cisco IOS-XE?

A.90 seconds
B.120 seconds
C.180 seconds
D.240 seconds
AnswerC

Cisco IOS-XE negotiates a default BGP hold time of 180 seconds, with the keepalive interval derived as one third of that value, 60 seconds. Timers are carried in OPEN messages, so peers must agree before the session establishes.

Why this answer

Cisco IOS-XE uses a default BGP hold timer of 180 seconds, with the keepalive timer defaulting to 60 seconds (one-third of the hold time). These defaults follow RFC 4271, which specifies a hold time of 90 seconds or greater, and Cisco's implementation standardizes on 180/60. The hold timer is reset each time a KEEPALIVE or UPDATE message is received; if it expires, the session is torn down.

Exam trap

The trap is confusing the RFC 4271 minimum hold time (90 seconds) with Cisco's default (180 seconds); candidates who memorize the RFC value pick 90 and miss the vendor-specific default.

How to eliminate wrong answers

Option A is wrong because 90 seconds is the RFC 4271 minimum recommended hold time, not Cisco's default — candidates often confuse the RFC floor with the implementation default. Option B is wrong because 120 seconds is not a standard Cisco BGP default; it may appear in some non-default configurations but is not the out-of-the-box value. Option D is wrong because 240 seconds exceeds Cisco's default and is not used unless explicitly configured; it is a distractor based on doubling the correct value.

274
MCQhard

An engineer is troubleshooting a DHCPv6 prefix delegation scenario. The router (R1) is a DHCPv6 client on its WAN interface and is supposed to receive a /48 prefix from the ISP's DHCPv6 server to delegate to LAN interfaces. The WAN interface is configured with 'ipv6 address dhcp' and 'ipv6 dhcp client pd ISP-PREFIX'. The LAN interfaces have 'ipv6 address ISP-PREFIX 0:0:0:1::/64 eui-64'. The engineer sees that the WAN interface gets a global IPv6 address, but the LAN interfaces do not get any IPv6 address. What is the most likely cause?

A.The LAN interfaces are missing the 'ipv6 enable' command.
B.The ISP's DHCPv6 server is not configured to delegate a prefix.
C.The 'ipv6 dhcp client pd' command should be 'ipv6 dhcp client pd ISP-PREFIX hint ::/48'.
D.The WAN interface needs the 'ipv6 nd other-config-flag' command.
AnswerB

Prefix delegation requires the ISP's DHCPv6 server to include IA_PD in its reply. The WAN interface obtaining a global address proves basic DHCPv6 works, but LAN interfaces remain unaddressed because no delegated prefix was returned.

Why this answer

The WAN interface successfully obtains a global IPv6 address via DHCPv6, but the LAN interfaces lack IPv6 addresses because the DHCPv6 client process on R1 has not received a delegated prefix. The 'ipv6 dhcp client pd ISP-PREFIX' command requests a prefix delegation from the ISP's DHCPv6 server; if the server is not configured to delegate prefixes (e.g., missing the 'prefix-delegation' pool or 'ipv6 dhcp server' with prefix assignment), the client never receives a prefix to assign to LAN interfaces. This is the most likely cause given the symptom.

Exam trap

Cisco often tests the distinction between DHCPv6 address assignment (IA_NA) and prefix delegation (IA_PD), trapping candidates who assume that obtaining a WAN address automatically implies a delegated prefix is also received.

How to eliminate wrong answers

Option A is wrong because 'ipv6 enable' is not required on LAN interfaces when they already have an explicit 'ipv6 address' command; the address configuration implicitly enables IPv6. Option C is wrong because the 'hint' keyword is optional and not required for prefix delegation to work; the client can request a prefix without a hint, and the server may still delegate one. Option D is wrong because 'ipv6 nd other-config-flag' is used to tell hosts to obtain other configuration (e.g., DNS) via DHCPv6, not to enable prefix delegation on the client or server side.

275
MCQmedium

A network engineer is implementing MPLS Layer 3 VPNs. The engineer wants to ensure that customer routes are propagated across the MPLS core. Which protocol is typically used within the provider core to distribute VPNv4 routes?

A.BGP
B.OSPF
C.LDP
D.EIGRP
AnswerA

Multiprotocol BGP (MP-BGP) is used to distribute VPNv4 routes across the MPLS core. It carries the VPNv4 address family and associated MPLS labels (route targets and route distinguishers). Provider edge routers establish iBGP sessions to exchange VPNv4 reachability information, enabling MPLS L3 VPNs.

Why this answer

In MPLS Layer 3 VPNs, Multiprotocol BGP (MP-BGP) is used to distribute VPNv4 routes between provider edge routers. MP-BGP carries the VPNv4 address family, which includes the route distinguisher and route target extended communities, along with MPLS labels. This allows the provider core to forward customer traffic based on labels.

Exam trap

The trap here is confusing the underlay routing protocol (which could be OSPF or EIGRP) with the protocol used for VPNv4 route distribution; MP-BGP is specifically designed for this purpose.

276
MCQhard

A network engineer is troubleshooting a route filtering problem with prefix-lists. Router R6 is using a prefix-list to filter routes from a BGP neighbor. The prefix-list is configured to permit only 192.168.0.0/16 and 192.168.1.0/24, but routes with prefix 192.168.2.0/24 are also being accepted. The engineer checks the prefix-list configuration and sees only two permit statements. What is the most likely cause?

A.The prefix-list is not applied to the BGP neighbor; the neighbor is using a different filter or no filter.
B.The prefix-list has an implicit permit at the end for all routes.
C.The prefix-list is using 'ge 24' which permits any prefix with a mask >= 24, including 192.168.2.0/24.
D.The BGP neighbor is configured with 'soft-reconfiguration inbound' which overrides prefix-list filtering.
AnswerA

An unapplied prefix-list cannot filter anything, so the neighbour's inbound or outbound route map, distribute-list or default behaviour governs what is accepted. Since 192.168.2.0/24 passes despite the two permit statements, the filter is evidently not bound to that BGP session, satisfying the stem's requirement that only the listed prefixes be permitted.

Why this answer

If routes with prefix 192.168.2.0/24 are being accepted despite a prefix-list that only permits 192.168.0.0/16 and 192.168.1.0/24, the most likely cause is that the prefix-list is not actually applied to the BGP neighbor. Without an inbound filter, the neighbor accepts all routes, including 192.168.2.0/24.

Exam trap

300-410 often tests whether candidates verify that filters are actually applied; the trap is assuming the prefix-list logic is wrong when the real issue is that it was never attached to the neighbor.

How to eliminate wrong answers

Option B is wrong because prefix-lists have an implicit deny at the end, not an implicit permit. Option C is wrong because the scenario states only two permit statements and does not mention 'ge 24'; if 'ge 24' were used, it would permit more specific prefixes, but that is not the case here. Option D is wrong because 'soft-reconfiguration inbound' stores received routes for policy changes but does not override prefix-list filtering.

277
MCQhard

A network engineer runs the following command on Router R3: R3# show logging | include %OSPF-5-ADJCHG *Mar 1 00:05:10.123: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from LOADING to FULL, Loading Done *Mar 1 00:06:20.456: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from FULL to DOWN, Neighbor Down: Dead timer expired *Mar 1 00:07:30.789: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from DOWN to INIT, Received Hello *Mar 1 00:08:40.012: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from INIT to EXSTART, Event: start *Mar 1 00:09:50.345: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from EXSTART to EXCHANGE, Event: Negotiation Done *Mar 1 00:10:00.678: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from EXCHANGE to LOADING, Event: Exchange Done *Mar 1 00:11:10.901: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from LOADING to FULL, Loading Done *Mar 1 00:12:20.234: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from FULL to DOWN, Neighbor Down: Dead timer expired Based on this output, what is the most likely problem?

A.The OSPF process is misconfigured with mismatched area IDs.
B.There is a Layer 1 or Layer 2 issue causing intermittent connectivity on GigabitEthernet0/0.
C.The OSPF dead timer is set too high, causing slow convergence.
D.The router is running out of memory, causing OSPF process restarts.
AnswerB

The dead timer expiration indicates that hello packets are not received in time, which is often due to flapping interfaces or high error rates.

Why this answer

The log shows the OSPF neighbor repeatedly reaching FULL and then dropping with 'Dead timer expired,' which means the router stopped receiving Hello packets from the neighbor within the dead interval (default 40 seconds, 4× the 10-second Hello). This pattern — adjacency forms, then dies, then re-forms — is characteristic of intermittent Layer 1 or Layer 2 connectivity (flapping link, bad cable, duplex mismatch, or a flaky switch port) rather than a configuration mismatch. A config mismatch would prevent the adjacency from reaching FULL in the first place.

Exam trap

300-410 often tests whether candidates can distinguish configuration mismatches (which block adjacency formation) from physical/link issues (which cause established adjacencies to flap), so candidates who see 'OSPF' and jump to area ID mismatch miss that the neighbor already reached FULL.

How to eliminate wrong answers

Option A is wrong because mismatched area IDs would prevent the neighbor from progressing past INIT or 2-WAY; the log shows it reaching FULL, so area IDs match. Option C is wrong because a dead timer set too high would delay detection of a real failure, but the log shows the timer expiring repeatedly, indicating actual Hello loss, not a misconfigured timer. Option D is wrong because memory exhaustion would cause process restarts or 'OSPF process restart' messages, not a clean FULL-to-DOWN transition with 'Dead timer expired.'

278
MCQmedium

Consider the following configuration on R5: !--- R5 configuration ip prefix-list PL-2 seq 5 permit 10.0.0.0/8 ge 16 le 24 ! route-map RMAP permit 10 match ip address prefix-list PL-2 set community 100:100 ! router bgp 65200 neighbor 192.168.1.2 route-map RMAP out ! What is the effect of this configuration?

A.Only routes with prefix 10.0.0.0/8 and mask length between 16 and 24 are sent to neighbor with community 100:100.
B.All routes with prefix 10.0.0.0/8 are sent to neighbor; routes with mask length between 16 and 24 get community 100:100.
C.Routes that match the prefix-list are sent with community 100:100; all other routes are sent without any community.
D.The configuration is invalid because the prefix-list uses ge and le together; only one can be used.
AnswerA

The prefix-list matches 10.0.0.0/8 with mask lengths from /16 to /24 inclusive, so only those more-specific subnets satisfy the route-map's match clause. Routes passing it are advertised to 192.168.1.2 with community 100:100 set; the /8 itself and anything outside that range is denied.

Why this answer

The prefix-list PL-2 permits 10.0.0.0/8 with a mask length between 16 and 24 (ge 16 le 24). The route-map RMAP matches this prefix-list and sets community 100:100. Since the route-map is applied outbound to neighbor 192.168.1.2, only routes that match the prefix-list are permitted by the route-map (implicit deny at the end of the route-map), and those matching routes are sent with community 100:100.

Therefore, only routes with prefix 10.0.0.0/8 and mask length between 16 and 24 are sent, and they are tagged with community 100:100.

Exam trap

The trap here is assuming that a route-map with a match clause only sets attributes on matching routes but still permits all routes; however, a route-map used as a filter implicitly denies unmatched routes, so only matching routes are sent.

How to eliminate wrong answers

Option B is wrong because it states all routes with prefix 10.0.0.0/8 are sent, but the prefix-list filters based on mask length (ge 16 le 24), so only a subset of 10.0.0.0/8 routes are permitted; others are denied by the implicit deny in the route-map. Option C is wrong because it implies non-matching routes are still sent without community, but the route-map has an implicit deny, so non-matching routes are dropped, not sent. Option D is wrong because using ge and le together in a prefix-list is valid and commonly used to specify a range of mask lengths.

279
MCQmedium

Router R3 has the following configuration: ``` interface GigabitEthernet0/4 ip address 10.3.3.3 255.255.255.0 ip policy route-map PBR-IN ! route-map PBR-IN permit 10 match ip address 102 set ip next-hop verify-availability 192.168.2.1 10 track 1 ! access-list 102 permit ip 10.3.3.0 0.0.0.255 any ``` What is the effect of the 'set ip next-hop verify-availability' command?

A.The next-hop 192.168.2.1 is used only if track object 1 is up; otherwise, normal routing applies.
B.The next-hop 192.168.2.1 is always used regardless of track status.
C.The router pings 192.168.2.1 every 10 seconds to verify reachability.
D.The configuration is invalid because 'verify-availability' requires a sequence number.
AnswerA

The `verify-availability` keyword ties next-hop reachability to tracked object 1, so policy-based routing via 192.168.2.1 only occurs while that track is up. If the track fails, the route-map clause no longer sets the next hop, and the packet falls through to the routing table, satisfying the requirement for automatic failover to normal forwarding.

Why this answer

The command 'set ip next-hop verify-availability 192.168.2.1 10 track 1' in a route-map specifies that the next-hop 192.168.2.1 should be used only if the tracked object (track 1) is in the 'up' state. The number 10 is the sequence number for this next-hop entry, allowing multiple next-hops to be tried in order. If track 1 is down, the policy-based routing (PBR) action for that sequence is skipped, and the router falls back to the normal routing table to forward the packet.

Thus, option A correctly describes this conditional behavior.

Exam trap

The trap here is confusing the sequence number (10) with a timer or interval, leading candidates to pick option C, or assuming that 'verify-availability' requires a sequence number, leading to option D. The key is to recognize that 'track 1' makes the next-hop conditional on the track object's state, and the number is just an ordering sequence.

How to eliminate wrong answers

Option B is wrong because it ignores the 'track 1' keyword, which explicitly makes the next-hop conditional on the track object's state; without tracking, the next-hop would be used unconditionally, but here it is not. Option C is wrong because the '10' in the command is a sequence number for ordering multiple next-hops, not a timer; verification is done via the track object, which may use its own polling interval, but the command itself does not ping every 10 seconds. Option D is wrong because 'verify-availability' does not require a sequence number; the sequence number is optional and defaults to 10 if omitted, but its presence here is valid and not an error.

280
MCQmedium

Examine the RSPAN configuration: vlan 100 name RSPAN_VLAN remote-span ! monitor session 1 source interface GigabitEthernet1/0/1 both monitor session 1 destination remote vlan 100 What is the purpose of the 'remote-span' command under VLAN 100?

A.It allows VLAN 100 to be used for RSPAN traffic across multiple switches.
B.It enables spanning tree on VLAN 100.
C.It prevents VLAN 100 from being used for user data traffic.
D.It configures VLAN 100 as a native VLAN.
AnswerA

The remote-span command designates VLAN 100 as an RSPAN VLAN, allowing source-port traffic to be carried in that VLAN across trunk links between switches to a destination session on a remote device. Without it, the VLAN cannot transport RSPAN traffic.

Why this answer

The 'remote-span' command under a VLAN configuration designates that VLAN as an RSPAN VLAN, which is used to carry mirrored traffic across multiple switches in an RSPAN session. This allows the destination port to be on a different switch than the source.

Exam trap

300-410 often tests the specific purpose of the 'remote-span' command. Candidates might confuse it with spanning tree or native VLAN configuration, or think it prevents user traffic, but its primary role is to designate the VLAN for RSPAN use.

How to eliminate wrong answers

Option B is wrong because spanning tree is enabled by default on VLANs and is not affected by the remote-span command. Option C is wrong because while RSPAN VLANs should not carry user data, the command itself does not explicitly prevent it; it's a recommended practice but not enforced by the command. Option D is wrong because native VLAN is configured with 'switchport trunk native vlan', not remote-span.

281
MCQmedium

Which BGP loop prevention mechanism relies on the AS_PATH attribute?

A.Split horizon
B.AS_PATH loop detection
C.TTL expiration
D.Route poisoning
AnswerB

Each BGP speaker prepends its own AS number to AS_PATH when advertising routes. On receipt, the router checks whether its own AS already appears in AS_PATH; if so, the update is discarded, preventing loops between autonomous systems.

Why this answer

BGP's primary loop prevention mechanism is AS_PATH loop detection: when a router receives an UPDATE, it checks whether its own AS number appears in the AS_PATH attribute. If it does, the route is rejected as a loop. This works because each AS prepends its AS number when advertising routes to eBGP peers, so a route that has traversed an AS will carry that AS in the path.

Exam trap

The trap is confusing BGP loop prevention with distance-vector mechanisms like split horizon or route poisoning; candidates who generalize from IGP behavior pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because split horizon is a distance-vector (RIP, EIGRP) mechanism that prevents advertising a route back out the interface it was learned from — BGP does not use split horizon for loop prevention. Option C is wrong because TTL expiration is a general IP forwarding safeguard (and the basis of GTSM for BGP security), not a BGP loop-prevention attribute-based mechanism. Option D is wrong because route poisoning is a distance-vector technique that sets a metric to infinity to mark a route unreachable; BGP does not use route poisoning.

282
MCQhard

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. The hub router must advertise a default route to all spokes, but the spokes should not use the hub as the next hop for spoke-to-spoke traffic; instead, they should dynamically discover a direct path to other spokes. Which NHRP configuration on the hub is required to support this behavior?

A.ip nhrp shortcut
B.ip nhrp redirect
C.ip nhrp network-id 1
D.ip nhrp map multicast dynamic
AnswerB

In DMVPN Phase 3, the hub uses ip nhrp redirect to inform a spoke that a better path exists directly to the destination spoke. When the hub receives a packet from one spoke destined to another, it sends an NHRP redirect message to the source spoke, which then initiates an NHRP resolution for the destination spoke's NBMA address. This enables spoke-to-spoke direct tunnels while the hub still advertises a default route, exactly as required.

Why this answer

DMVPN Phase 3 requires the hub to be configured with ip nhrp redirect on its mGRE interface. This allows the hub to send NHRP redirect messages to spokes when it forwards traffic between them, prompting the source spoke to resolve the destination spoke's NBMA address and build a direct tunnel. The spokes must also be configured with ip nhrp shortcut to use the redirect information.

This combination allows the hub to advertise a default route while still enabling dynamic spoke-to-spoke direct paths.

Exam trap

The trap here is reversing the roles of ip nhrp redirect and ip nhrp shortcut, placing the spoke-side command on the hub.

283
MCQeasy

A network technician is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The technician enters the following commands: interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 cisco After applying the configuration, the router does not form an adjacency with its neighbor. What is the most likely reason?

A.The neighbor router is not configured with the same MD5 key ID and key string.
B.The key string must be encrypted using the 'service password-encryption' command.
C.The 'ip ospf authentication message-digest' command must be configured globally, not on the interface.
D.The key ID must be the same on both routers, but the key string can differ.
AnswerA

OSPF MD5 authentication requires that both routers use the same key ID and identical key string on the interface. If the neighbor has a different key ID or key string, the MD5 digest will not match, and OSPF hellos will be rejected, preventing adjacency formation. The most common cause of failure after enabling MD5 is a mismatch in these parameters.

Why this answer

OSPF MD5 authentication requires that both neighbors use the same key ID and key string. When the technician configures MD5 on one router but the neighbor has not been configured with the identical key, the MD5 digest in OSPF hellos will not match, and the routers will not form an adjacency. The technician should verify the neighbor's configuration and ensure both key ID and key string match exactly.

Exam trap

The trap here is assuming that MD5 authentication only requires enabling it on one side, or that the key string can be different, when in fact both key ID and key string must match on both routers.

284
MCQhard

A network engineer configures an RSPAN session on Switch A to monitor traffic from interface GigabitEthernet0/1 and sends it to Switch B. The engineer creates RSPAN VLAN 50 on both switches and configures the trunk between them to allow VLAN 50. On Switch B, the engineer configures the destination port as GigabitEthernet0/2 in VLAN 50. The engineer notices that the destination port is not forwarding any traffic. What should the engineer check first?

A.Verify that the RSPAN VLAN is configured with the 'remote-span' command on both switches.
B.Check that the destination port is not in a shutdown state.
C.Ensure that the source interface is not configured with 'no monitor session'.
D.Confirm that the trunk between switches is configured as a dot1q trunk.
AnswerA

The RSPAN VLAN must be defined as a remote-span VLAN on every participating switch; otherwise the destination port stays inactive and forwards nothing. Verifying the 'remote-span' command under VLAN 50 configuration on both switches is the first check.

Why this answer

The most likely issue is that the RSPAN VLAN is not properly configured with the 'remote-span' command on both switches. Without this command, the VLAN is treated as a normal VLAN, and the destination port will not forward the mirrored traffic. The 'remote-span' command designates the VLAN as an RSPAN VLAN, enabling it to carry mirrored traffic across trunk links.

Exam trap

300-410 often tests RSPAN configuration details, and candidates frequently overlook the need for the 'remote-span' command on the RSPAN VLAN, assuming that creating the VLAN and allowing it on trunks is sufficient.

How to eliminate wrong answers

Option B is wrong because if the destination port were shutdown, it would not forward any traffic, but the question states the port is configured and the engineer is checking why it's not forwarding; a shutdown state would be an obvious check, but the primary issue in RSPAN is often the VLAN configuration. Option C is wrong because 'no monitor session' would remove the monitor session entirely, but the session is configured; the issue is likely with the RSPAN VLAN setup. Option D is wrong because the trunk is already configured to allow VLAN 50, so dot1q encapsulation is likely correct; the missing 'remote-span' command is a more specific and common oversight.

285
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip sla statistics 6 Round Trip Time (RTT) for Index 6 Latest RTT: 0 ms Latest RTT (milliseconds): 0 Latest RTT (microseconds): 0 Number of successes: 0 Number of failures: 100 Operation time to live: Forever Output: No connection R1# show track 4 Track 4 IP SLA 6 reachability Reachability is Down 3 changes, last change 00:05:00 Latest operation return code: No connection Latest RTT (milliseconds): 0 Tracked by: ip route 0.0.0.0 0.0.0.0 192.168.4.1 track 4 R1# show ip route 0.0.0.0 0.0.0.0 % Network not in table Based on this output, which statement is correct?

A.The static route is still present because the track is down.
B.The IP SLA operation is successful, but the track is misconfigured.
C.The target 192.168.4.1 is unreachable, causing the IP SLA to fail and the static route to be removed.
D.The IP SLA operation has a threshold violation, but the route is still active.
AnswerC

Zero successes against 100 failures, with return code "No connection", shows the probe cannot reach 192.168.4.1. Track 4 is Down, and because the default static route is bound to that track, it is withdrawn from the routing table, hence "Network not in table".

Why this answer

The track is down due to 'No connection', and the static route is not in the routing table. This indicates that the IP SLA probe cannot reach the target, and the tracked route has been removed.

286
MCQeasy

A network technician is configuring a GRE tunnel between two Cisco routers. The tunnel interface is up, but no traffic is passing. Which command should be used to verify that the tunnel source and destination are reachable?

A.show ip route
B.traceroute <tunnel destination IP>
C.ping <tunnel destination IP>
D.show interface tunnel 0
AnswerC

Pinging the tunnel destination IP verifies reachability to the remote tunnel endpoint's physical interface. If the ping fails, the tunnel cannot pass traffic because the underlying transport is down. This is the first step to confirm connectivity before troubleshooting the tunnel itself.

Why this answer

Pinging the tunnel destination IP is the most direct way to verify that the remote endpoint is reachable. If the ping succeeds, the underlying transport is working, and further troubleshooting can focus on the tunnel configuration. If it fails, the issue is in the transport network, not the tunnel itself.

Exam trap

The trap here is relying on the tunnel interface status to assume connectivity, when the tunnel can be up even if the destination is unreachable due to routing or filtering issues.

287
MCQhard

An engineer configures Control Plane Policing (CoPP) on a router to protect the control plane. After applying the policy, the router becomes unreachable via SSH and SNMP. The engineer checks the policy and confirms that the class-map for SSH and SNMP traffic is set to 'permit'. What is the most likely explanation?

A.The class-default is set to 'drop', causing all unmatched traffic to be dropped, including SSH and SNMP if they are not correctly classified.
B.The 'rate-limit' is configured in bps instead of pps, causing excessive policing.
C.The 'service-policy' is applied to the control-plane input direction, but SSH and SNMP are output traffic.
D.The class-map for SSH and SNMP uses a 'match-all' condition, but the access-list has multiple entries that are ORed.
AnswerA

In CoPP, the class-default is the default class for all traffic not matched by other classes. If it is set to drop, any traffic that does not match the explicit classes will be dropped. If SSH or SNMP traffic is not correctly matched by the class-map (e.g., due to a typo in the access-list), it will fall into class-default and be dropped.

Why this answer

In CoPP, the class-default class defines the action for traffic that does not match any of the defined classes. If class-default is set to 'drop', then any traffic not explicitly matched by a permit class will be dropped. Even though the class-map for SSH and SNMP is set to 'permit', if the traffic is not correctly classified (e.g., due to an incorrect ACL or match condition), it falls into class-default and is dropped.

This would cause SSH and SNMP to become unreachable.

Exam trap

The trap is to focus on the SSH/SNMP class-map being 'permit' and overlook the class-default action; candidates must remember that unmatched traffic is handled by class-default, which can drop traffic if configured to do so.

How to eliminate wrong answers

Option B is wrong because rate-limit in bps instead of pps might cause incorrect policing rates, but it would not necessarily drop all SSH and SNMP traffic if the rate is sufficient; also, the question states the class-map is set to 'permit', implying no policing. Option C is wrong because CoPP is applied to the control-plane input direction, which is correct for traffic destined to the router; SSH and SNMP are input traffic from the router's perspective. Option D is wrong because a 'match-all' condition with multiple ACL entries that are ORed is normal; it would not cause the traffic to be dropped if the ACL matches correctly.

288
Multi-Selecthard

Which THREE symptoms indicate that IPv6 unicast RPF is misconfigured or failing on an interface? (Choose THREE.)

Select 3 answers
A.Traffic from a valid source IP is being dropped on the interface.
B.The router logs 'IPv6 unicast RPF drop' messages.
C.The command 'ipv6 verify unicast source reachable-via any' is present in the running config.
D.High CPU utilization is observed due to RPF processing.
E.The 'show ipv6 interface' output shows an increasing 'RPF drops' counter.
AnswersA, B, E

uRPF drops packets when the source IP is not reachable via the incoming interface, even if the IP is valid.

Why this answer

IPv6 unicast RPF (uRPF) drops traffic when the source address is not reachable via the incoming interface according to the FIB. If a valid source IP is being dropped, it indicates that the RPF check is failing, often due to asymmetric routing or a missing route in the FIB for that source prefix.

Exam trap

Cisco often tests the distinction between strict and loose mode RPF, and the trap here is that candidates may incorrectly assume that the presence of the 'ipv6 verify unicast source reachable-via any' command itself is a symptom of misconfiguration, when in fact it is a legitimate configuration for loose mode.

289
MCQmedium

A network engineer runs the following command on Router R1: R1# show dmvpn Legend: Attrb -> S: Static, D: Dynamic, I: Incomplete N: NATed, L: Local, X: No Socket # Entries: 2 Interface: Tunnel0, IPv4 NHRP Details Type: Hub, NHRP Peers: 2, # Ent Peer NBMA Addr Peer Tunnel Addr State UpDn Tm Attrb ----- --------------- --------------- ----- -------- ----- 1 192.168.1.2 10.0.0.2 UP 00:15:30 D 2 192.168.2.2 10.0.0.3 UP 00:14:20 D Based on this output, which statement is correct?

A.The DMVPN tunnel is not functioning because there are only two peers.
B.Both spoke routers have established dynamic NHRP registrations with the hub.
C.The hub router has static NHRP entries for the spokes.
D.The spokes are not able to communicate with each other.
AnswerB

The hub's NHRP peer table lists two entries with the D (Dynamic) attribute, confirming both spokes registered dynamically rather than through static mappings. State UP with non-zero uptime shows the registrations are active, satisfying the requirement that each spoke's tunnel address maps to its NBMA address.

Why this answer

The output shows two dynamic (D) NHRP entries for peers 10.0.0.2 and 10.0.0.3, each with an NBMA address of 192.168.1.2 and 192.168.2.2 respectively. The 'D' attribute indicates these registrations were established dynamically via NHRP registration requests from the spoke routers to the hub, confirming that both spokes have successfully registered with the hub. This is the expected behavior for a DMVPN Phase 2 or Phase 3 hub, where spokes dynamically register their tunnel and NBMA addresses.

Exam trap

Cisco often tests the distinction between the NHRP 'Attrb' column attributes (S, D, I, N, L, X) to trick candidates into misinterpreting dynamic registrations as static or assuming that a hub output showing only hub-spoke entries implies a lack of spoke-to-spoke connectivity.

How to eliminate wrong answers

Option A is wrong because having two peers is normal for a DMVPN hub with two spokes; the number of peers does not indicate a malfunction. Option C is wrong because the 'D' attribute in the Attrb column explicitly indicates dynamic NHRP entries, not static (S). Option D is wrong because the output only shows hub-to-spoke relationships; spoke-to-spoke communication is possible in DMVPN Phase 2/3 via dynamic NHRP resolution and does not require direct hub involvement for data traffic, so the absence of spoke-to-spoke entries in this hub output does not imply they cannot communicate.

290
MCQmedium

A network engineer runs the following command on Router R1: R1# show event manager history events Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog OSPF_Neighbor_Down 2 00:01:31 UTC Mar 1 syslog OSPF_Neighbor_Up 3 00:01:32 UTC Mar 1 syslog OSPF_Neighbor_Down 4 00:01:33 UTC Mar 1 syslog OSPF_Neighbor_Up Based on this output, which statement is correct?

A.The OSPF neighbor is stable.
B.The OSPF neighbor is flapping.
C.The EEM policy is not configured.
D.The OSPF neighbor is down permanently.
AnswerB

The repeated Down/Up pairs one second apart show the adjacency repeatedly failing and re-forming, which is the definition of flapping. The event history records syslog events triggered by the Embedded Event Manager, confirming the neighbour state changes occurred rather than a single transient drop.

Why this answer

The event history shows the OSPF neighbor transitioning Down → Up → Down → Up within a four-second window, which is the textbook signature of an unstable adjacency. Rapid repeated state changes indicate the neighbor relationship is flapping rather than being stable or permanently down.

Exam trap

The trap is reading the alternating Down/Up entries as two separate stable events rather than recognizing the rapid oscillation pattern that defines flapping.

How to eliminate wrong answers

Option A is wrong because a stable neighbor would show a single Up transition with no subsequent Down events. Option C is wrong because the presence of logged EEM events (syslog type entries with named events) proves the EEM policy is configured and firing. Option D is wrong because the neighbor is not permanently down — it repeatedly comes back Up, which is the definition of flapping, not a hard failure.

291
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 ospf neighbor Neighbor ID Pri State Dead Time Address Interface 192.168.1.2 1 FULL/DR 00:00:32 FE80::2 Tunnel0 192.168.1.3 1 FULL/BDR 00:00:35 FE80::3 Tunnel0 Based on this output, which statement is correct?

A.OSPFv3 is not running on this router.
B.The router with Neighbor ID 192.168.1.3 is the Designated Router.
C.OSPFv3 adjacencies are fully established over the tunnel.
D.The tunnel is using IPv4 transport.
AnswerC

Both neighbours show FULL state on Tunnel0, confirming that OSPFv3 database synchronisation completed successfully across the tunnel interface. The DR/BDR roles are also elected, which only occurs after two-way communication and adjacency formation. This satisfies the stem's requirement of verifying established OSPFv3 adjacencies over the tunnel.

Why this answer

The output shows two OSPFv3 neighbors in the FULL state, which indicates that the adjacency process has completed successfully and the routers are exchanging link-state advertisements. The presence of the FULL state for both neighbors confirms that OSPFv3 adjacencies are fully established over the Tunnel0 interface, making option C correct.

Exam trap

Cisco often tests the distinction between OSPFv2 and OSPFv3, and the trap here is that candidates may assume the presence of IPv4-like neighbor IDs (192.168.1.x) implies IPv4 transport, but OSPFv3 uses a 32-bit Router ID (often derived from an IPv4 address) regardless of the underlying IPv6 transport.

How to eliminate wrong answers

Option A is wrong because the 'show ipv6 ospf neighbor' command itself proves that OSPFv3 is running on this router; if it were not, the command would return no output or an error. Option B is wrong because the neighbor with Neighbor ID 192.168.1.3 is listed as BDR (Backup Designated Router), not DR; the DR is 192.168.1.2, as indicated by the 'FULL/DR' state. Option D is wrong because the output shows IPv6 link-local addresses (FE80::2 and FE80::3) and the command is specific to IPv6 OSPF (OSPFv3), which operates natively over IPv6; the tunnel could be using IPv6 transport, and there is no evidence of IPv4 transport in this output.

292
MCQhard

A network engineer runs the following command on Router R1: R1# show ip route 10.0.0.0 255.255.252.0 longer-prefixes Routing entry for 10.0.0.0/22 Known via "eigrp 100", distance 90, metric 2172416, type internal Last update from 192.168.1.2 on GigabitEthernet0/0, 00:00:10 ago Routing Descriptor Blocks: * 192.168.1.2, from 192.168.1.2, 00:00:10 ago, via GigabitEthernet0/0 Route metric is 2172416, traffic share count is 1 Routing entry for 10.0.1.0/24 Known via "eigrp 100", distance 90, metric 2812416, type internal Last update from 192.168.1.2 on GigabitEthernet0/0, 00:00:10 ago Routing Descriptor Blocks: * 192.168.1.2, from 192.168.1.2, 00:00:10 ago, via GigabitEthernet0/0 Route metric is 2812416, traffic share count is 1 Based on this output, what is the effect of the summary route 10.0.0.0/22?

A.The summary route is working correctly and suppressing all specifics.
B.The summary route is not suppressing the more specific route 10.0.1.0/24.
C.The summary route has a better metric than the specific route.
D.The summary route is not installed in the routing table.
AnswerB

EIGRP advertises the 10.0.0.0/22 summary alongside the component 10.0.1.0/24, which remains in the routing table as a separate entry. The summary is not suppressing that more specific route, so both prefixes appear in the output.

Why this answer

The presence of both the summary route (10.0.0.0/22) and a more specific route (10.0.1.0/24) in the routing table indicates that the summary route is not suppressing the more specific routes, possibly due to a configuration issue or because the summary is not configured as a discard route.

293
MCQhard

An engineer configures AS path prepending on an eBGP route to influence inbound traffic. However, traffic from a specific iBGP neighbor still prefers the prepended path. What is the most likely explanation?

A.AS path prepending only affects eBGP path selection; iBGP routers ignore AS path length when comparing paths from different eBGP routers.
B.The prepending was applied with 'set as-path prepend last-as 1', which only prepends the last AS, not the full path.
C.The iBGP neighbor has 'bgp bestpath as-path ignore' configured, which ignores AS path length entirely.
D.The prepending was done on a route reflector, and the client does not see the prepended AS path.
AnswerC

This would make all paths equal, but the issue is that prepending is not considered.

Why this answer

AS path prepending normally increases the AS path length, and BGP does consider AS path length during best-path selection. However, if the iBGP neighbor has 'bgp bestpath as-path ignore' configured, it skips the AS path length step, so prepending will not be considered and that neighbor may prefer the prepended path based on other attributes such as local preference or IGP metric. Option A is incorrect because iBGP does not ignore AS path length by default.

294
MCQmedium

Examine the following partial configuration on R1: !--- R1 configuration route-map RMAP permit 10 match ip address prefix-list PL-1 set metric 100 ! route-map RMAP permit 20 set metric 200 ! router eigrp 100 network 10.0.0.0 redistribute ospf 1 metric 1000 100 255 1 1500 route-map RMAP ! What is the effect of this configuration?

A.Only routes matching prefix-list PL-1 are redistributed into EIGRP with metric 100; all other OSPF routes are denied.
B.Routes matching prefix-list PL-1 are redistributed with metric 100; all other OSPF routes are redistributed with metric 200.
C.The route-map is missing a deny statement; without it, all routes are permitted with default metric.
D.The route-map is applied to redistribution, but the metric values are ignored because redistribute command also specifies metric.
AnswerB

Route-map RMAP is evaluated sequentially: permit sequence 10 matches prefix-list PL-1 and sets metric 100, while sequence 20 has no match clause, so it permits all remaining OSPF routes and sets metric 200. Both sequences redistribute into EIGRP 100.

Why this answer

The route-map RMAP has two permit sequences. The first matches prefix-list PL-1 and sets metric to 100. The second is a catch-all permit with no match, setting metric to 200.

All redistributed OSPF routes will match either sequence and have their metric set accordingly. If a route matches the first sequence, its metric is set to 100; otherwise, it matches the second and gets metric 200. There is no deny sequence, so no routes are filtered.

295
Multi-Selectmedium

Which TWO statements about IP SLA ICMP echo operations are true? (Choose TWO.)

Select 2 answers
A.It measures round-trip time (RTT) between the source and destination.
B.It measures jitter in the network path.
C.The operation must be scheduled using the 'ip sla schedule' command.
D.The destination can be specified as a hostname without any additional configuration.
E.The operation runs continuously by default after configuration.
AnswersA, C

ICMP echo operations send echo requests and await replies, timing the interval between transmission and receipt. That interval is the round-trip time between source and destination, which the operation reports as its core latency metric.

Why this answer

Option A is correct because an IP SLA ICMP echo operation sends ICMP echo requests to a target and computes the round-trip time (RTT) between the source and destination, which is the core metric it reports. Option C is correct because after configuring the operation with the 'ip sla <number>' and 'icmp-echo' commands, you must activate it with the 'ip sla schedule <number> start-time ... life ...' command, otherwise the operation never runs. Option B is not correct because jitter measurement is provided by UDP jitter operations (e.g., 'udp-jitter'), not by ICMP echo.

Option D is not correct because the destination must be specified as an IP address or a resolvable name, and using a hostname requires DNS resolution to be configured on the device. Option E is not correct because the operation does not run continuously by default; it only runs once it is explicitly scheduled with 'ip sla schedule' and within the configured life/start-time parameters.

296
MCQhard

A network engineer is implementing route redistribution between OSPF and EIGRP on a Cisco IOS router. The engineer wants to prevent routing loops and ensure that routes redistributed from OSPF into EIGRP are not redistributed back into OSPF. Which mechanism should be used?

A.Set the administrative distance of EIGRP to a lower value than OSPF.
B.Use the default-metric command under the EIGRP process.
C.Apply a distribute-list to filter OSPF routes from being installed in the routing table.
D.Configure a route map with a tag on OSPF routes and deny tagged routes when redistributing EIGRP into OSPF.
AnswerD

Using route tags is a standard method to prevent feedback loops in mutual redistribution. By tagging routes when redistributing from OSPF into EIGRP, and then denying those tags when redistributing from EIGRP back into OSPF, you prevent the same routes from being reintroduced. This breaks the loop and is a scalable, deterministic solution.

Why this answer

Route tagging is the most effective way to prevent routing loops during mutual redistribution. By assigning a tag to routes when they are redistributed from one protocol into another, you can later match and deny those tagged routes when redistributing back. This ensures that routes do not oscillate between protocols, maintaining a loop-free topology.

Exam trap

The trap here is thinking that administrative distance or default metrics solve redistribution loops, when they only affect route selection or metric seeding, not the feedback of routes between protocols.

297
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer wants to ensure that the authentication key is not sent in clear text and that the key can be changed without disrupting the adjacency. Which command should be used to configure the key on the interface?

A.area 0 authentication message-digest
B.ip ospf authentication message-digest
C.ip ospf message-digest-key <key-id> md5 <key>
D.ip ospf authentication-key <key>
AnswerC

The 'ip ospf message-digest-key' command with the 'md5' keyword configures an MD5 key for OSPFv2 authentication on an interface. The key is not sent in clear text; instead, an MD5 hash is used. Multiple keys can be configured with different key IDs, allowing for graceful key rollover without disrupting the adjacency. This meets both requirements.

Why this answer

To configure an MD5 key for OSPFv2 authentication on an interface, the 'ip ospf message-digest-key' command is used. The key is hashed and not sent in clear text. By configuring multiple keys with different key IDs, you can change the key without disrupting the adjacency.

The other options either configure plaintext authentication or enable authentication without setting the key.

Exam trap

The trap here is confusing the command that enables MD5 authentication with the command that actually configures the MD5 key, leading to incomplete authentication setup.

298
MCQeasy

A network engineer configures a Cisco IOS router as a DHCP relay agent. The router interface connected to the DHCP clients is configured with 'ip helper-address 192.168.1.10'. Which type of traffic will be forwarded to the DHCP server at 192.168.1.10 by default?

A.Only unicast packets destined to the DHCP server's IP address.
B.Only UDP broadcasts for DHCP (ports 67 and 68).
C.UDP broadcasts for DHCP, TFTP, DNS, NetBIOS, and several other services.
D.All IP broadcasts, including DHCP, TFTP, DNS, and NetBIOS.
AnswerC

By default, the 'ip helper-address' command forwards UDP broadcasts for a predefined set of services, including DHCP (ports 67/68), TFTP (69), DNS (53), NetBIOS (137/138), and others like BOOTP and TACACS. This allows clients to reach servers on different subnets without additional configuration.

Why this answer

The 'ip helper-address' command forwards UDP broadcasts for a default set of services, including DHCP, TFTP, DNS, NetBIOS, and others. This allows clients to communicate with servers on different subnets. The command is not limited to DHCP, nor does it forward all broadcasts.

Exam trap

The trap here is assuming that the helper address only forwards DHCP broadcasts, when in fact it forwards a broader set of UDP services by default.

299
MCQmedium

snmp-server community public RO\nsnmp-server community private RW\nsnmp-server location DataCenter\nsnmp-server contact admin@example.com What is the effect of this configuration?

A.SNMPv3 is enabled with authentication.
B.SNMPv2c is enabled with read-only community 'public' and read-write community 'private'.
C.Only read-only access is allowed using the 'private' community.
D.SNMP traps are enabled to the location DataCenter.
AnswerB

SNMPv2c communities are defined by these commands: 'public' grants read-only access and 'private' grants read-write access, satisfying the stem's requirement to identify the resulting SNMP version and community permissions. The location and contact lines set device metadata only, so they do not alter access levels.

Why this answer

The configuration uses SNMPv2c community strings 'public' (read-only) and 'private' (read-write), which are plain-text authentication mechanisms. SNMPv2c is enabled by default when community strings are configured, and the 'RO' and 'RW' keywords explicitly define the access levels. This matches option B exactly.

Exam trap

Cisco often tests the distinction between SNMP versions by hiding the version keyword; candidates assume SNMPv3 is in use when they see 'community', but community strings are exclusive to SNMPv1/v2c.

How to eliminate wrong answers

Option A is wrong because SNMPv3 requires 'snmp-server group' and 'snmp-server user' commands with authentication/hash parameters, not community strings. Option C is wrong because the 'private' community is configured with RW (read-write) access, not read-only. Option D is wrong because 'snmp-server location' sets the sysLocation MIB object, not trap destinations; traps require 'snmp-server host' and 'snmp-server enable traps' commands.

300
MCQmedium

Examine this BGP configuration on router R3: router bgp 65001 neighbor 10.1.1.1 remote-as 65002 address-family ipv4 network 192.168.0.0 mask 255.255.252.0 aggregate-address 192.168.0.0 255.255.252.0 summary-only What is the effect of the 'aggregate-address' command with the 'summary-only' keyword?

A.It advertises the aggregate 192.168.0.0/22 and suppresses all more specific routes from being advertised to neighbor 10.1.1.1.
B.It advertises both the aggregate and all more specific routes.
C.It creates a static route for the aggregate.
D.It removes all more specific routes from the BGP table.
AnswerA

The `summary-only` keyword suppresses all component routes within 192.168.0.0/22, so only the aggregate is advertised to neighbour 10.1.1.1. This satisfies the stem's requirement to reduce the BGP table by hiding more-specific prefixes while still announcing the summarised /22 to the remote AS 65002 peer.

Why this answer

The aggregate-address command creates an aggregate route in BGP. The summary-only keyword suppresses more specific routes from being advertised.

Page 3

Page 4 of 19

Page 5