Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 301–375

1401 questions total · 19pages · All types, answers revealed

Page 4

Page 5 of 19

Page 6
301
MCQmedium

A network administrator is implementing GET VPN on Cisco IOS routers. The key server is configured with a policy that includes the `rekey` command. Which statement accurately describes the behavior of the rekey mechanism in GET VPN?

A.The rekey mechanism only applies to the control plane and does not affect data plane encryption keys.
B.The key server sends rekey messages to group members to refresh the Group Domain of Interpretation (GDOI) keys.
C.The rekey command is used to manually trigger a key rollover on the key server.
D.The rekey mechanism requires each group member to initiate a new registration with the key server.
AnswerB

In GET VPN, the key server manages the GDOI protocol and distributes encryption keys to group members. The `rekey` command configures the key server to send rekey messages, which contain new keys or policies, to group members. This ensures that group members can update their keys without re-registering, maintaining secure communication.

Why this answer

GET VPN uses GDOI for group key management. The key server sends rekey messages to group members to update encryption keys and policies. This allows scalable key distribution without re-registration.

The rekey command configures the key server's rekey behavior, including algorithms and lifetimes. It directly impacts data plane keys, ensuring secure and efficient key rollover.

Exam trap

The trap here is thinking that rekey requires re-registration or is only for control plane, when it actually pushes new data plane keys to members.

302
MCQeasy

A network administrator is configuring a Cisco IOS XE router to support IPv6. The administrator wants to enable IPv6 routing and assign an IPv6 address to an interface. Which command must be configured globally to enable IPv6 routing?

A.ipv6 address autoconfig
B.ip routing ipv6
C.ipv6 enable
D.ipv6 unicast-routing
AnswerD

The global command 'ipv6 unicast-routing' enables IPv6 unicast routing on the router. Without it, the router can still have IPv6 addresses on interfaces, but it will not forward IPv6 packets or participate in IPv6 routing protocols. This command is required to make the router act as an IPv6 router. It is the correct answer for enabling IPv6 routing globally.

Why this answer

To enable IPv6 routing on a Cisco IOS XE router, the global command 'ipv6 unicast-routing' must be configured. This allows the router to forward IPv6 packets and run IPv6 routing protocols. Interface commands like 'ipv6 enable' or 'ipv6 address autoconfig' are used for address configuration but do not enable global routing.

The command 'ip routing ipv6' is invalid.

Exam trap

The trap here is thinking that configuring an IPv6 address on an interface automatically enables routing; it does not.

303
MCQmedium

Consider the following partial DMVPN configuration on a hub router: interface Tunnel0 ip address 10.0.0.1 255.255.255.0 ip nhrp network-id 100 ip nhrp authentication cisco123 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ip nhrp map multicast dynamic ! What is the effect of this configuration?

A.The hub will dynamically register spoke NHRP addresses and forward multicast traffic to all registered spokes.
B.The hub will only forward multicast traffic to spokes that are statically mapped.
C.The hub will not forward multicast traffic at all because dynamic mapping is not supported.
D.The hub will use broadcast instead of multicast for all traffic.
AnswerA

The ip nhrp map multicast dynamic command lets the hub learn spoke NBMA addresses from registration requests and replicate multicast or broadcast traffic to every registered spoke, while tunnel mode gre multipoint provides the single multipoint GRE interface spokes register against.

Why this answer

The command 'ip nhrp map multicast dynamic' on the hub allows the hub to dynamically learn the multicast mapping for spokes. This means the hub will forward multicast traffic to all registered spokes that have registered via NHRP. The hub does not require static multicast mappings for each spoke.

This is essential for DMVPN phase 2 and 3 where dynamic routing protocols use multicast.

Exam trap

300-410 often tests the confusion between static and dynamic multicast mapping in DMVPN, leading candidates to think dynamic mapping is not supported or requires static entries.

How to eliminate wrong answers

Option B is wrong because the 'dynamic' keyword allows dynamic registration, not static mapping. Option C is wrong because dynamic mapping is supported and is exactly what this command enables. Option D is wrong because the command does not change multicast to broadcast; it enables dynamic multicast forwarding.

304
MCQhard

A network engineer runs the following command on Router R1: R1# show ipv6 interface gigabitethernet 0/0 GigabitEthernet0/0 is up, line protocol is up IPv6 is enabled, link-local address is FE80::1 Global unicast address(es): 2001:DB8:1:1::1, subnet is 2001:DB8:1:1::/64 Joined group address(es): FF02::1 FF02::2 ICMP redirects are enabled ICMP unreachables are enabled ND DAD is enabled, number of DAD attempts: 1 ND reachable time is 30000 milliseconds ND advertised reachable time is 0 milliseconds ND advertised retransmit interval is 1000 milliseconds ND router advertisements are sent every 200 seconds ND router advertisements live for 1800 seconds Hosts use stateless autoconfig for addresses. IPv6 uRPF: strict mode (drop invalid packets) Inbound access list: FILTER-IPv6 Based on this output, which two features are configured on this interface?

A.uRPF in strict mode and inbound IPv6 ACL
B.uRPF in loose mode and outbound IPv6 ACL
C.uRPF disabled and inbound IPv6 ACL
D.uRPF in strict mode and outbound IPv6 ACL
AnswerA

The output explicitly lists "IPv6 uRPF: strict mode (drop invalid packets)" and "Inbound access list: FILTER-IPv6", confirming both features are active on GigabitEthernet0/0. These two lines directly satisfy the question's requirement to identify the configured features.

Why this answer

The output shows 'IPv6 uRPF: strict mode (drop invalid packets)' and 'Inbound access list: FILTER-IPv6', confirming that unicast Reverse Path Forwarding in strict mode and an inbound IPv6 ACL are both configured on the interface. Strict uRPF verifies that the source address of incoming packets has a matching route in the FIB pointing back to the same interface, dropping packets that fail this check. The inbound ACL filters traffic before any routing decision, as indicated by the 'Inbound access list' line.

Exam trap

Cisco often tests the distinction between strict and loose uRPF modes, and the trap here is that candidates may overlook the 'Inbound access list' line and assume the ACL is outbound, or confuse the uRPF mode with the ACL direction.

How to eliminate wrong answers

Option B is wrong because the output explicitly states 'IPv6 uRPF: strict mode', not loose mode, and the ACL is applied inbound, not outbound. Option C is wrong because uRPF is not disabled; it is enabled in strict mode. Option D is wrong because while uRPF is correctly identified as strict mode, the ACL is applied inbound, not outbound.

305
MCQhard

A network engineer runs the following command to verify OSPFv3 database: R1# show ipv6 ospf database router 2.2.2.2 OSPFv3 Router with ID (1.1.1.1) (Process ID 1) Router Link States (Area 0) LS age: 60 LS Type: Router Links Link State ID: 0.0.0.0 Advertising Router: 2.2.2.2 LS Seq Number: 80000003 Checksum: 0x5678 Length: 40 Number of Links: 1 Link connected to: a Transit Network (Link ID) Interface ID: 2 (Link Data) Neighbor Interface ID: 1 Number of TOS metrics: 0 TOS 0 Metrics: 10 What does this output indicate?

A.The LSA shows a link to a stub network with prefix information.
B.The LSA indicates a single transit link with interface IDs, typical for OSPFv3.
C.The advertising router is 1.1.1.1.
D.This is a Type 5 External LSA.
AnswerB

The Router-LSA lists one link of type Transit Network, carrying the interface ID and neighbour interface ID rather than IPv4 addresses. OSPFv3 identifies links by interface ID, so this is normal output for a broadcast segment with a single adjacency.

Why this answer

The output shows an OSPFv3 Router LSA from router 2.2.2.2 with one link to a transit network, using interface IDs instead of IP addresses.

306
MCQhard

A network engineer is implementing MPLS Layer 3 VPN on a Cisco IOS-XE router. The engineer needs to configure the router to exchange VPNv4 routes with a route reflector. The router is already configured with BGP AS 65001 and has established an IBGP session with the route reflector. Which address family must be activated to support VPNv4 route exchange?

A.address-family ipv6 unicast
B.address-family ipv4 vrf
C.address-family ipv4 unicast
D.address-family vpnv4 unicast
AnswerD

The VPNv4 unicast address family is specifically designed to carry MPLS L3VPN routes with route distinguishers and extended communities. Activating it under the BGP configuration enables the exchange of VPNv4 prefixes with the route reflector. This is the correct address family for MPLS L3VPN route distribution.

Why this answer

MPLS L3VPN uses the VPNv4 address family to exchange labeled VPN routes between PE routers. The VPNv4 address family carries the route distinguisher and route target extended communities. Activating it under the BGP routing process on both the PE and route reflector is required.

Without it, VPNv4 prefixes are not propagated.

Exam trap

The trap here is confusing the IPv4 unicast address family with VPNv4; VPNv4 is a separate address family that must be explicitly activated for MPLS L3VPN route exchange.

307
MCQeasy

A network engineer is configuring a static route on a Cisco IOS router to reach the network 192.168.2.0/24 via the next-hop address 10.1.1.2. The engineer enters the command 'ip route 192.168.2.0 255.255.255.0 10.1.1.2'. However, the route does not appear in the routing table. What is the most likely reason?

A.The next-hop address 10.1.1.2 is not reachable.
B.The static route requires the 'permanent' keyword to be installed.
C.The subnet mask is incorrect; it should be 255.255.255.0.
D.The router needs a default route to install any static route.
AnswerA

For a static route to be installed in the routing table, the next-hop address must be reachable via a directly connected interface or another route. If 10.1.1.2 is not reachable, the static route remains inactive and does not appear in the routing table. This is a common issue when the next-hop is not on a directly connected subnet or lacks a route.

Why this answer

A static route is only installed in the routing table if its next-hop address is reachable. The next-hop 10.1.1.2 must be reachable via a directly connected interface or another route. If it is not reachable, the static route remains in the configuration but is not active.

The subnet mask is correct, and no special keywords are needed for basic installation. Thus, the most likely reason is that the next-hop is unreachable.

Exam trap

The trap here is assuming that a static route will always appear in the routing table once configured, ignoring next-hop reachability requirements.

308
MCQeasy

What is the default behavior of LDP when establishing a session between two directly connected routers?

A.LDP sends hellos to the unicast address of each neighbor.
B.LDP uses TCP port 646 for session establishment and UDP port 646 for hellos.
C.LDP hellos are sent to the all-OSPF-routers multicast address 224.0.0.5.
D.LDP sessions are established using UDP for reliability.
AnswerB

LDP satisfies the directly connected constraint by separating discovery from session setup: hellos use UDP port 646 to find link-local peers, then TCP port 646 establishes the session. This matches the stem's requirement for directly connected routers, where UDP hellos are link-scoped and TCP provides reliable session transport.

Why this answer

LDP uses UDP port 646 for the initial Hello discovery messages (sent to multicast 224.0.0.2) and TCP port 646 for the reliable session establishment and label advertisement exchange. This dual-transport design is fundamental to how LDP separates neighbor discovery from session maintenance.

Exam trap

The trap here is confusing LDP's Hello multicast address (224.0.0.2) with OSPF's 224.0.0.5, or assuming LDP uses a single transport protocol for both discovery and session establishment.

How to eliminate wrong answers

Option A is wrong because LDP Hellos are sent to the multicast address 224.0.0.2 (all routers on the subnet), not to unicast addresses of each neighbor. Option C is wrong because 224.0.0.5 is the OSPF AllSPFRouters multicast address, not used by LDP. Option D is wrong because LDP uses TCP (not UDP) for session establishment to ensure reliable, ordered delivery of label bindings.

309
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip bgp 192.168.0.0 255.255.252.0 BGP routing table entry for 192.168.0.0/22, version 5 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 65001 10.1.1.1 from 10.1.1.1 (10.1.1.1) Origin IGP, metric 0, localpref 100, valid, external, best Community: 65001:100 rx pathid: 0, tx pathid: 0x0 Aggregator: 65001, 10.1.1.1 Based on this output, what is true about this route?

A.The route is a summary route aggregated by 10.1.1.1.
B.The route is a learned route from AS 65002.
C.The route is a default route.
D.The route is suppressed.
AnswerA

The Aggregator attribute (65001, 10.1.1.1) confirms the route was aggregated, and the /22 prefix covering 192.168.0.0/22 indicates summarisation. The advertising router 10.1.1.1 performed the aggregation, making this a summary route rather than a specific component prefix.

Why this answer

The presence of 'Aggregator' indicates route summarization (aggregation) was performed by the router with IP 10.1.1.1 in AS 65001.

310
MCQmedium

Which default IPsec transform set is automatically created in Cisco IOS when configuring a site-to-site VPN?

A.esp-aes 256 esp-sha-hmac
B.esp-3des esp-sha-hmac
C.No default transform set is created
D.esp-aes 128 esp-md5-hmac
AnswerC

Cisco IOS never auto-creates a transform set; one must be defined manually with `crypto ipsec transform-set` before the crypto map references it. The stem asks which default exists, and none does, so this satisfies the "default" constraint precisely.

Why this answer

Cisco IOS does not automatically create any default IPsec transform set when configuring a site-to-site VPN. Transform sets must be explicitly defined using the `crypto ipsec transform-set` command, which specifies the encryption and authentication algorithms. The absence of a default ensures that administrators intentionally select the appropriate security parameters for their environment.

Exam trap

Cisco often tests the misconception that a default transform set exists, tempting candidates to select a common algorithm combination like `esp-aes 256 esp-sha-hmac` or `esp-3des esp-sha-hmac` as the default, when in fact no such default is automatically created.

How to eliminate wrong answers

Option A is wrong because `esp-aes 256 esp-sha-hmac` is not a default transform set; it is a valid user-defined transform set but must be manually configured. Option B is wrong because `esp-3des esp-sha-hmac` is also not a default; 3DES is a legacy algorithm that requires explicit configuration. Option D is wrong because `esp-aes 128 esp-md5-hmac` is not a default; MD5 is deprecated for security reasons and must be explicitly chosen if used.

311
MCQmedium

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-IN Class-map: CoPP-ICMP (match-all) 0 packets, 0 bytes 5 minute offered rate 0000 bps, drop rate 0000 bps Match: access-group 100 police: cir 8000 bps, bc 1500 bytes, be 1500 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: CoPP-SSH (match-all) 0 packets, 0 bytes 5 minute offered rate 0000 bps, drop rate 0000 bps Match: access-group 110 police: cir 16000 bps, bc 3000 bytes, be 3000 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: class-default (match-any) 1250 packets, 75000 bytes 5 minute offered rate 1000 bps, drop rate 0000 bps Match: any Based on this output, which statement is correct?

A.The CoPP policy is dropping all ICMP packets to the control plane.
B.The CoPP policy is not matching any packets for the CoPP-ICMP and CoPP-SSH classes.
C.The CoPP policy is rate-limiting SSH traffic to 16000 bps.
D.The CoPP policy is applied to the output direction.
AnswerB

Both CoPP-ICMP and CoPP-SSH report 0 packets and 0 bytes, while class-default shows 1250 packets. The policers therefore never matched traffic, confirming the access-group match criteria for those two classes are not hitting any packets.

Why this answer

The output shows that the CoPP-ICMP and CoPP-SSH class-maps have zero packets matched (0 packets, 0 bytes), indicating that no traffic has been classified into these classes. This means the policy is not matching any ICMP or SSH packets, likely because the access-lists (100 and 110) are not correctly defined or applied, or the traffic is not reaching the control plane. Option B correctly identifies this lack of matching.

Exam trap

Cisco often tests the distinction between a configured policy and an active policy; candidates see police parameters and assume traffic is being policed, but the zero packet counters reveal that no classification is occurring, so the policy is effectively idle.

How to eliminate wrong answers

Option A is wrong because the CoPP-ICMP class shows 0 packets matched and 0 packets dropped, so no ICMP packets are being dropped; the policy is not affecting ICMP traffic at all. Option C is wrong because the CoPP-SSH class has 0 packets matched, meaning SSH traffic is not being rate-limited; the police cir 16000 bps is configured but never applied to any packets. Option D is wrong because the command 'show policy-map control-plane' and the output line 'Service-policy input: CoPP-IN' explicitly indicate the policy is applied to the input direction, not output.

312
MCQmedium

A network engineer is configuring a GRE over IPsec tunnel between two Cisco IOS routers. The engineer wants to ensure that the GRE tunnel traffic is encrypted by IPsec. Which of the following configurations is required to achieve this?

A.The transform set must include the GRE protocol as the encapsulation mode.
B.The crypto map must be applied to the GRE tunnel interface instead of the physical interface.
C.The crypto ACL must permit IP traffic between the private networks that are routed over the GRE tunnel.
D.The crypto ACL must permit GRE traffic (protocol 47) between the tunnel source and destination IP addresses.
AnswerD

For GRE over IPsec, the crypto ACL must match the GRE packets, which are protocol 47. The ACL should permit GRE between the tunnel source and destination IPs. This ensures that the GRE-encapsulated packets are encrypted by IPsec. Without matching GRE, the tunnel traffic would not be encrypted.

Why this answer

In a GRE over IPsec configuration, the GRE tunnel encapsulates the private traffic, and then IPsec encrypts the GRE packets. Therefore, the crypto ACL must match GRE traffic (protocol 47) between the tunnel endpoints. This ensures that the entire GRE packet, including the original private IP packet, is encrypted.

Permitting the private IP traffic in the crypto ACL would cause IPsec to encrypt the private packets before GRE encapsulation, which is not desired.

Exam trap

The trap here is assuming that the crypto ACL should match the private traffic that traverses the GRE tunnel, but in GRE over IPsec, the crypto ACL must match the GRE protocol itself.

313
MCQmedium

Given this configuration on Router R6: ``` interface Tunnel0 ipv6 address 2001:DB8:8::1/64 tunnel source 2001:DB8:9::1 tunnel destination 2001:DB8:10::2 tunnel mode gre ipv6 tunnel path-mtu-discovery ``` What is the effect?

A.The tunnel will not work because path-mtu-discovery is not supported with GRE.
B.The tunnel will dynamically adjust the MTU based on the path MTU discovery.
C.The tunnel mode should be 'ipv6ip' for IPv6 transport.
D.The tunnel source and destination must be IPv4 addresses.
AnswerB

The `tunnel path-mtu-discovery` command enables PMTUD on the GRE IPv6 tunnel, allowing the tunnel interface to dynamically lower its MTU when ICMPv6 "Packet Too Big" messages report a smaller path MTU along the transit path. This satisfies the stem's requirement for automatic MTU adjustment rather than a fixed value.

Why this answer

The `tunnel path-mtu-discovery` command enables Path MTU Discovery (PMTUD) for the GRE tunnel, which dynamically determines the maximum MTU along the path to the tunnel destination and adjusts the tunnel interface's MTU accordingly. This prevents fragmentation issues by allowing the tunnel to use the smallest MTU in the path. Option B correctly identifies this behavior.

Exam trap

Cisco often tests the misconception that path-mtu-discovery is unsupported with GRE tunnels, but it is actually supported and commonly used to avoid fragmentation in overlay networks.

How to eliminate wrong answers

Option A is wrong because path-mtu-discovery is fully supported with GRE tunnels; it uses the DF bit and ICMPv6 Packet Too Big messages (or ICMPv4 Fragmentation Needed) to discover the path MTU. Option C is wrong because the tunnel mode 'gre ipv6' is correct for transporting IPv6 packets over an IPv6 transport network; 'ipv6ip' is used for IPv6-in-IPv4 tunnels, not for GRE over IPv6. Option D is wrong because the tunnel source and destination are IPv6 addresses (2001:DB8:9::1 and 2001:DB8:10::2), which is valid for a GRE tunnel operating over an IPv6 transport network.

314
MCQmedium

What is the default administrative distance for a route learned via the Border Gateway Protocol (BGP) from an external peer (eBGP)?

A.20
B.200
C.170
D.1
AnswerA

eBGP routes carry a default administrative distance of 20 in Cisco IOS, making them more trusted than internal BGP (200) but less than connected or static routes. This value lets the router prefer eBGP-learned paths over iBGP alternatives when identical prefixes arrive from both sources.

Why this answer

The default administrative distance (AD) for eBGP routes is 20. Administrative distance is a Cisco-proprietary metric used to rank the trustworthiness of routing information sources; lower values are preferred. eBGP is considered highly reliable because it is an exterior gateway protocol used between autonomous systems, so it is assigned a low AD of 20, second only to directly connected (0) and static routes (1).

Exam trap

300-410 often tests the confusion between eBGP and iBGP administrative distances, or between BGP and other protocols like EIGRP or OSPF, so candidates must memorize the exact default values.

How to eliminate wrong answers

Option B is wrong because 200 is the default administrative distance for Internal BGP (iBGP) routes, not eBGP. Option C is wrong because 170 is the default administrative distance for External EIGRP routes, not BGP. Option D is wrong because 1 is the default administrative distance for static routes, not eBGP.

315
MCQeasy

By default in Cisco IOS-XE, what is the behavior of an IPv4 ACL when no entries match and the ACL is applied to an inbound interface?

A.The packet is permitted.
B.The packet is denied.
C.The packet is forwarded based on routing table lookup.
D.The ACL logs the packet and continues.
AnswerB

An IPv4 ACL carries an implicit deny any at its end, so a packet matching no entry is discarded. Applied inbound, this means unmatched traffic is dropped by default, satisfying the stem's question about default behaviour.

Why this answer

By default, Cisco IOS-XE applies an implicit 'deny any' statement at the end of every IPv4 ACL. If no entries match the packet, the implicit deny triggers, and the packet is dropped. This behavior is consistent for ACLs applied to inbound interfaces, ensuring that only explicitly permitted traffic is allowed.

Exam trap

Cisco often tests the implicit deny any behavior by presenting scenarios where an ACL has no matching entries, leading candidates to mistakenly think the packet is permitted or forwarded based on routing.

How to eliminate wrong answers

Option A is wrong because the implicit deny any statement at the end of an ACL causes unmatched packets to be dropped, not permitted. Option C is wrong because ACLs operate independently of the routing table; a packet that is denied by an ACL is discarded before any routing decision is made. Option D is wrong because logging is not enabled by default; it requires the explicit 'log' keyword on an ACL entry, and even then, the packet is still subject to the implicit deny if no match occurs.

316
Multi-Selecthard

A network engineer is implementing MPLS Traffic Engineering (TE) with RSVP-TE. The engineer must ensure that the TE tunnel can be established and that the headend router can signal the path. Which two statements about RSVP-TE operation are true? (Choose two.)

Select 2 answers
A.RSVP-TE uses the Resource Reservation Protocol to reserve bandwidth along the path of a TE tunnel.
B.RSVP-TE automatically computes the shortest path for the tunnel without any explicit configuration.
C.RSVP-TE uses LDP to distribute labels for the TE tunnel.
D.RSVP-TE signaling requires that all routers along the path support RSVP and have it enabled on the relevant interfaces.
E.RSVP-TE reservations are unidirectional, so a separate tunnel is needed for the return traffic.
AnswersA, D

RSVP-TE extends RSVP to support traffic engineering by reserving resources (bandwidth) along the explicit path of a TE tunnel. The headend router sends PATH messages that include the requested bandwidth and other constraints. Each router along the path reserves the requested resources if available and forwards the PATH message. This reservation ensures that the TE tunnel has the required bandwidth, enabling deterministic traffic handling.

Why this answer

RSVP-TE reserves bandwidth along the explicit path of a TE tunnel using PATH and RESV messages. All routers along the path must support and enable RSVP on relevant interfaces for signaling to succeed. RSVP-TE does not use LDP for label distribution; it handles labels itself.

Path computation is done by CSPF on the headend, not automatically by RSVP. Reservations are unidirectional, but a separate return tunnel is not always required.

Exam trap

The trap here is assuming that RSVP-TE relies on LDP for label distribution or that it automatically computes paths without explicit configuration, when in fact RSVP-TE signals labels itself and requires an explicit or CSPF-computed path.

317
Multi-Selectmedium

Which TWO commands can be used to troubleshoot EIGRP route redistribution issues when routes are not appearing in the routing table? (Choose TWO.)

Select 2 answers
A.show ip protocols
B.show ip route
C.show ip eigrp topology all-links
D.show ip ospf database
E.debug ip routing
AnswersA, C

show ip protocols displays the active redistribution sources, seed metrics, and administrative distance applied per routing protocol, exposing misconfigured redistribute statements or missing metric parameters that prevent EIGRP from installing redistributed routes into the routing table.

Why this answer

Option A, 'show ip protocols', is correct because it displays the configured routing protocols, their redistribution settings (including which protocols are redistributed into EIGRP and the associated metrics), and the networks being advertised, allowing you to verify that redistribution is properly configured. Option C, 'show ip eigrp topology all-links', is correct because it shows all EIGRP topology entries, including feasible successors and routes that are not installed in the routing table, helping you determine whether redistributed routes are present in the EIGRP topology database but failing to meet feasibility or administrative distance requirements. Option B, 'show ip route', only shows the final routing table and cannot reveal whether redistribution or EIGRP topology processing is the root cause.

Option D, 'show ip ospf database', is irrelevant because the issue concerns EIGRP, not OSPF. Option E, 'debug ip routing', can show routing table changes but does not specifically verify EIGRP redistribution configuration or topology entries, making it less targeted for this troubleshooting scenario.

Exam trap

Cisco often tests the distinction between 'show ip eigrp topology' and 'show ip eigrp topology all-links', where the latter is necessary to see all routes, including those not selected as best paths, which is critical for troubleshooting redistribution failures.

318
MCQmedium

In BGP, what is the default value of the keepalive timer?

A.30 seconds
B.60 seconds
C.90 seconds
D.180 seconds
AnswerB

BGP's default keepalive timer is 60 seconds, with a default hold timer of 180 seconds — three times the keepalive interval. This satisfies the stem's request for the default keepalive value, as defined in RFC 4271. Neighbours exchange keepalives at this interval to confirm the session remains active.

Why this answer

In BGP, the default keepalive timer is 60 seconds, as specified in RFC 4271. This timer determines how often a BGP speaker sends Keepalive messages to its peer to maintain the session. The hold timer, which is three times the keepalive interval (default 180 seconds), triggers session teardown if no Keepalive or update is received within that period.

Exam trap

Cisco often tests the distinction between the keepalive timer (60 seconds) and the hold timer (180 seconds), and candidates frequently confuse the two or misremember the default as 30 seconds due to familiarity with other routing protocols like EIGRP.

How to eliminate wrong answers

Option A is wrong because 30 seconds is the default keepalive interval for EIGRP, not BGP. Option C is wrong because 90 seconds is not a standard BGP timer value; it might be confused with the OSPF dead interval (which is 40 seconds by default). Option D is wrong because 180 seconds is the default BGP hold timer, not the keepalive timer; the keepalive timer is one-third of the hold timer.

319
Multi-Selecthard

A network engineer is configuring MPLS Layer 3 VPN on a Cisco IOS XR router. The engineer needs to ensure that customer routes are properly propagated across the MPLS core. Which two of the following are required to establish the VPNv4 peering between PE routers? (Choose two.)

Select 2 answers
A.Configure OSPF as the IGP for the MPLS core.
B.Enable BGP address-family vpnv4 unicast on the PE routers.
C.Enable LDP for label distribution on the core interfaces.
D.Enable BGP address-family ipv4 unicast for customer routes.
E.Configure a route reflector or full mesh of iBGP sessions between PE routers.
AnswersB, E

To exchange VPNv4 routes between PE routers, BGP must be configured with the VPNv4 address family. This allows the PE routers to carry customer routes with route distinguishers and route targets. Without enabling the VPNv4 address family, the PE routers cannot exchange VPN routing information, and MPLS L3VPN would not function.

Why this answer

To establish VPNv4 peering between PE routers, you must enable the BGP VPNv4 address family and have either a full mesh of iBGP sessions or a route reflector. These two elements allow the exchange of VPNv4 routes with route distinguishers and route targets, which are essential for MPLS L3VPN. LDP and IGP are for transport but not for VPNv4 peering itself.

Exam trap

The trap here is confusing the transport plane (LDP/IGP) with the control plane for VPNs (BGP VPNv4), and thinking that LDP or IGP is required for VPNv4 peering.

320
MCQmedium

A network engineer is deploying an MPLS L3VPN using BGP as the PE-CE routing protocol. The customer requires that the PE router accept only routes with a specific BGP community and set a local preference of 200 for those routes. Which configuration on the PE router accomplishes this requirement?

A.Configure a route-map that matches the community and sets local preference, then apply it as an outbound route-map under the BGP neighbor configuration for the CE.
B.Configure a distribute-list with an extended ACL that matches the community and sets local preference under the BGP process.
C.Configure a route-map that matches the community and sets local preference, then apply it as an inbound route-map under the BGP neighbor configuration for the CE.
D.Use the BGP network command with a backdoor route to inject the routes with the desired local preference.
AnswerC

Applying an inbound route-map on the PE-CE BGP session allows matching the community and setting local preference before the route is installed in the VRF BGP table. This ensures only desired routes are accepted with the correct preference.

Why this answer

Inbound route-maps on the PE-CE BGP session are the correct tool to match BGP communities and modify attributes such as local preference. They allow granular control over which routes are accepted and how they are treated within the VRF. Outbound route-maps affect advertisements, distribute-lists cannot set attributes, and the network command does not provide community-based filtering.

Exam trap

The trap here is confusing inbound and outbound route-map directions, leading to applying policy on the wrong side of the BGP session.

321
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate login users against a TACACS+ server. The administrator wants to ensure that if the TACACS+ server is unreachable, the router falls back to the local username database for authentication. Which configuration should be applied?

A.aaa authentication login default group tacacs+
B.aaa authentication login default group tacacs+ local
C.aaa authentication login default local group tacacs+
D.aaa authentication login default group radius local
AnswerB

This command configures the default login authentication method list to first attempt TACACS+ and then fall back to the local database if the server is unreachable. The 'group tacacs+' keyword specifies the TACACS+ server group, and 'local' provides the backup. This meets the requirement of fallback to local authentication.

Why this answer

The correct configuration must specify TACACS+ as the primary authentication method and local as the fallback. The order of methods in the AAA authentication list determines the sequence: the router tries each method in turn until one succeeds or all fail. Placing 'group tacacs+' before 'local' ensures TACACS+ is attempted first, and if unreachable, local authentication is used.

Exam trap

The trap here is confusing the order of authentication methods in the AAA list, assuming that 'local' should come first to ensure fallback.

322
MCQeasy

A network technician is configuring a static route on a Cisco router. The technician wants to ensure that the static route is only used when the primary route is unavailable. Which type of static route should be configured?

A.Default static route
B.Floating static route
C.Summary static route
D.Recursive static route
AnswerB

A floating static route is a static route with an administrative distance higher than that of the primary route. It is used as a backup and only installed in the routing table when the primary route fails. This matches the requirement of using the static route only when the primary route is unavailable. Configuring a floating static route involves specifying a higher administrative distance than the dynamic routing protocol or the primary static route.

Why this answer

A floating static route is designed to be a backup by assigning it a higher administrative distance than the primary route. When the primary route is present, the floating static route is not installed in the routing table. If the primary route fails, the floating static route becomes active.

This behavior precisely matches the requirement of using the static route only when the primary route is unavailable.

Exam trap

The trap here is confusing a default static route with a floating static route, as both can act as backups, but only the floating static route uses administrative distance to remain inactive until the primary fails.

323
MCQhard

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The VPN tunnel is up, but traffic from the local subnet to the remote subnet is not passing. The administrator checks the crypto ACL and finds that it matches the traffic. Which of the following is the most likely cause of the problem?

A.There is no route for the remote subnet pointing to the tunnel interface or next-hop.
B.The crypto map is applied to the wrong interface.
C.The crypto ACL is configured with the wrong source and destination addresses.
D.The transform set is mismatched between peers.
AnswerA

Even if the IPsec tunnel is up, traffic will not pass if the router does not have a route to the remote subnet via the tunnel. The crypto ACL defines interesting traffic, but without a proper route, packets are either dropped or sent via the default route, not encrypted. This is a common oversight in site-to-site VPN configurations.

Why this answer

In an IPsec site-to-site VPN, the tunnel can be up due to traffic from other sources or because the peers established it, but for specific traffic to pass, the router must have a route to the remote subnet pointing to the tunnel or the next-hop. Without this route, packets are not sent through the tunnel and may be dropped or routed elsewhere. The crypto ACL matching is necessary but not sufficient; routing is equally important.

Exam trap

The trap here is focusing solely on the crypto ACL and IPsec parameters while overlooking the need for a routing entry that directs traffic into the tunnel.

324
MCQmedium

Which of the following is the default EIGRP network type on a Frame Relay point-to-point subinterface?

A.NBMA
B.Point-to-point
C.Broadcast
D.Point-to-multipoint
AnswerB

EIGRP treats a Frame Relay point-to-point subinterface as a point-to-point network by default, since each subinterface maps to a single remote peer over a dedicated PVC. This satisfies the stem's constraint: no DR/BDR election or multicast adjacency handling is needed, so EIGRP forms adjacencies directly without altering the default network type.

Why this answer

On a Frame Relay point-to-point subinterface, the default EIGRP network type is point-to-point. This is because each point-to-point subinterface creates a separate logical connection to a single remote router, eliminating the need for NBMA-specific mechanisms like split horizon or next-hop-self adjustments. The point-to-point network type enables EIGRP to use multicast hello packets (224.0.0.10) and form a single adjacency over the link.

Exam trap

Cisco often tests the misconception that Frame Relay always defaults to NBMA, but candidates must remember that point-to-point subinterfaces override this default to point-to-point, while only physical interfaces or multipoint subinterfaces retain the NBMA default.

How to eliminate wrong answers

Option A is wrong because NBMA is the default EIGRP network type on a Frame Relay physical interface or multipoint subinterface, not on a point-to-point subinterface. Option C is wrong because broadcast is a network type used on Ethernet or other multiaccess broadcast media, and it is not the default on any Frame Relay subinterface. Option D is wrong because point-to-multipoint is a network type that must be manually configured on a Frame Relay multipoint subinterface, and it is not the default on a point-to-point subinterface.

325
MCQeasy

What is the default administrative distance for OSPF routes in a VRF-Lite environment on Cisco IOS-XE?

A.90
B.110
C.120
D.170
AnswerB

OSPF retains administrative distance 110 inside a VRF-Lite instance; VRF segmentation changes routing table separation, not the protocol's default preference. This matches the stem's IOS-XE VRF-Lite constraint, where the value stays identical to global OSPF.

Why this answer

OSPF's default administrative distance on Cisco IOS-XE is 110, and this value is unchanged in a VRF-Lite environment. VRF-Lite simply creates separate routing tables per VRF on the same physical router; it does not alter the administrative distance of the routing protocols running inside each VRF. Therefore, OSPF routes in a VRF still have an AD of 110.

Exam trap

The trap is thinking VRF-Lite changes protocol defaults; candidates sometimes assume isolation implies different AD values, but VRF-Lite only isolates routing tables, not administrative distances.

How to eliminate wrong answers

Option A is wrong because 90 is the default administrative distance for EIGRP internal routes, not OSPF. Option C is wrong because 120 is the default administrative distance for RIP, not OSPF. Option D is wrong because 170 is the default administrative distance for EIGRP external routes (or for BGP in some contexts), not OSPF.

326
MCQmedium

A network engineer runs the following command to troubleshoot a VRF-Lite issue: R1# show ip eigrp vrf CUSTOMER_B topology 10.1.1.0/24 Output: IP-EIGRP (AS 100): Topology entry for 10.1.1.0/24 for VRF CUSTOMER_B State is Passive, Query origin flag is 1, 1 Successor(s), FD is 131072 Routing Descriptor Blocks: 10.1.1.1 (GigabitEthernet0/1), from 10.1.1.1, Send flag is 0x0 Composite metric is (131072/128256), Route is Internal Vector metric: Minimum bandwidth is 100000 Kbit Total delay is 100 microseconds Reliability is 255/255 Load is 1/255 Minimum MTU is 1500 Hop count is 1 What does this output indicate?

A.The route 10.1.1.0/24 is in Active state, indicating an EIGRP query is in progress.
B.The route 10.1.1.0/24 has one successor with a feasible distance of 131072 and is learned via 10.1.1.1.
C.The route 10.1.1.0/24 is an external EIGRP route redistributed into the VRF.
D.The route 10.1.1.0/24 has multiple successors due to equal-cost paths.
AnswerB

The topology entry shows state Passive with one successor and a feasible distance of 131072, reached through 10.1.1.1 on GigabitEthernet0/1. The reported composite metric (131072/128256) confirms the successor's distance and advertised distance for that route.

Why this answer

The output shows 'State is Passive' (no query in progress), '1 Successor(s)', and 'FD is 131072', with the successor learned via 10.1.1.1 on GigabitEthernet0/1. The composite metric (131072/128256) shows the feasible distance and reported distance, and 'Route is Internal' confirms it is a native EIGRP route, not redistributed. This is a healthy, stable EIGRP topology entry.

Exam trap

The trap is misreading 'Passive' as a problem — in EIGRP, Passive means stable and converged, while Active means a query is in progress; candidates who think Passive is bad pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because the state is Passive, not Active — Active would indicate an outstanding query and an unreachable destination. Option C is wrong because the output explicitly says 'Route is Internal', meaning it originated within EIGRP AS 100, not redistributed as an external route. Option D is wrong because the output shows '1 Successor(s)', not multiple successors, so there is no equal-cost multipath.

327
MCQeasy

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that only specific traffic from the local subnet to the remote subnet is encrypted, while other traffic is sent in clear text. Which IPsec component is used to define the interesting traffic?

A.Crypto ACL
B.ISAKMP policy
C.Transform set
D.Crypto map
AnswerA

A crypto ACL (access control list) is used to define which traffic is protected by IPsec. It specifies the source and destination addresses and ports that should be encrypted. Traffic matching the ACL is sent through the IPsec tunnel, while traffic not matching is sent in clear text. This is the standard method to identify interesting traffic in Cisco IOS IPsec configurations.

Why this answer

The crypto ACL is the component that specifies the traffic to be encrypted by IPsec. It acts as a filter, and only packets permitted by the ACL are protected. The crypto map then references this ACL to apply the IPsec policy.

Other components like transform set and ISAKMP policy handle encryption algorithms and key negotiation, not traffic selection.

Exam trap

The trap here is confusing the role of the crypto map with the crypto ACL; the crypto map applies the policy, but the ACL defines the interesting traffic.

328
MCQmedium

When redistributing routes between OSPF and EIGRP, which of the following is a recommended best practice to prevent routing loops?

A.Use the same administrative distance for both protocols.
B.Apply route filtering using route-maps or prefix-lists to control which routes are redistributed.
C.Increase the default metric to a high value to discourage redistribution.
D.Disable route summarization on both protocols.
AnswerB

Route-maps or prefix-lists filter which routes cross the redistribution boundary, preventing routes learned from one protocol being fed back into it. This satisfies the stem's loop-prevention requirement by controlling redistribution at the boundary rather than relying on administrative distance alone.

Why this answer

Applying route filtering using route-maps or prefix-lists is a best practice to control which routes are redistributed between OSPF and EIGRP. This prevents routing loops by ensuring that only intended routes are advertised and avoids feedback of routes back into the original protocol. It also allows for granular control over route attributes.

Exam trap

300-410 often tests redistribution best practices. Candidates might think that changing administrative distance or metrics prevents loops, but the key is filtering. The trap is selecting an option that only affects path preference rather than preventing the loop entirely.

How to eliminate wrong answers

Option A is wrong because using the same administrative distance for both protocols can cause inconsistent path selection and does not prevent loops; in fact, it can exacerbate them. Option C is wrong because increasing the default metric to a high value only makes redistributed routes less preferred, but does not prevent loops; it might even cause suboptimal routing. Option D is wrong because disabling route summarization does not prevent loops; summarization can actually help reduce the size of routing tables and limit loop propagation if configured correctly.

329
MCQmedium

A network engineer is configuring a Cisco IOS XE router as a DHCP relay agent. The router is connected to a LAN segment with DHCP clients and must forward DHCP requests to a DHCP server at 10.1.1.100. Which command must be configured on the LAN interface to enable DHCP relay?

A.ip helper-address 10.1.1.100
B.ip dhcp pool 10.1.1.100
C.ip forward-protocol udp 67
D.ip dhcp relay 10.1.1.100
AnswerA

The ip helper-address command is used on an interface to forward UDP broadcasts, including DHCP requests, to a specified server. Configuring it with the DHCP server's IP address enables the router to relay DHCP requests from clients on that interface to the server. This is the correct command to enable DHCP relay functionality on the LAN interface.

Why this answer

To enable DHCP relay on a Cisco IOS XE router, the engineer must configure the ip helper-address command on the interface facing the DHCP clients, specifying the DHCP server's IP address. This command causes the router to forward DHCP broadcast requests as unicast packets to the server. The other options are either invalid commands or serve different purposes, such as configuring a DHCP server or modifying forwarded protocols.

Exam trap

The trap here is confusing the command to configure a DHCP server with the command to relay DHCP requests to an external server.

330
MCQmedium

A network engineer runs the following command to verify IPv6 uRPF operation: R1# show ipv6 interface GigabitEthernet0/0 | include verify IPv6 verify source: strict What does this output indicate?

A.Strict uRPF is enabled, so the router will drop packets if the source address is not in the routing table or if the best return path is not through the receiving interface.
B.Strict uRPF is enabled, but it only checks if the source address is in the routing table, regardless of interface.
C.Loose uRPF is enabled, which only checks if the source address is in the routing table.
D.uRPF is disabled on this interface.
AnswerA

Strict uRPF verifies the source against the routing table and confirms the best return path exits the receiving interface. Packets failing either check are dropped, satisfying the stem's requirement to interpret the 'IPv6 verify source: strict' output.

Why this answer

The output 'IPv6 verify source: strict' indicates that strict unicast Reverse Path Forwarding (uRPF) is enabled on the interface. Strict uRPF verifies that the source IPv6 address of an incoming packet is reachable via the routing table AND that the best return path to that source uses the same interface on which the packet was received. If either condition fails, the packet is dropped.

This matches option A exactly.

Exam trap

Cisco often tests the distinction between strict and loose uRPF by showing the 'verify source' output and expecting candidates to remember that 'strict' requires both a routing table match and the correct incoming interface, while 'loose' only requires the source to be in the routing table.

How to eliminate wrong answers

Option B is wrong because it describes a loose uRPF behavior, where only the source address must exist in the routing table, regardless of the incoming interface; strict uRPF additionally checks that the best return path is through the receiving interface. Option C is wrong because the output explicitly shows 'strict', not 'loose'; loose uRPF would display 'IPv6 verify source: loose' and only checks the routing table for the source address. Option D is wrong because the output clearly indicates that uRPF is enabled (strict mode), not disabled; a disabled state would show no 'verify' line or 'IPv6 verify source: none'.

331
MCQmedium

A network engineer is configuring a Cisco IOS XE router to support MPLS Traffic Engineering (TE) with RSVP-TE. The engineer has enabled MPLS TE globally and on the interfaces. The engineer wants to ensure that the router can signal an LSP with a specific bandwidth requirement of 100 Mbps. Which command is required to enable RSVP-TE signaling on the interface?

A.ip rsvp bandwidth 100000
B.mpls traffic-eng tunnels
C.mpls traffic-eng bandwidth 100000
D.mpls rsvp-te bandwidth 100000
AnswerA

This command enables RSVP-TE signaling on the interface and reserves 100,000 kbps (100 Mbps) of bandwidth for RSVP-TE LSPs. It is required to signal an LSP with a specific bandwidth requirement. The bandwidth value is specified in kilobits per second, so 100 Mbps equals 100,000 kbps. This command allows the interface to participate in RSVP-TE signaling and reserve the requested bandwidth.

Why this answer

To enable RSVP-TE signaling on an interface, the 'ip rsvp bandwidth' command must be configured. This command reserves bandwidth for RSVP-TE LSPs and allows the interface to participate in RSVP signaling. The bandwidth value is specified in kilobits per second, so 100 Mbps is 100,000 kbps.

Without this command, the router cannot signal an LSP with the required bandwidth, even if MPLS TE is enabled globally and on the interface.

Exam trap

The trap here is confusing the global MPLS TE command with the interface-level RSVP-TE bandwidth command.

332
MCQeasy

Which CoPP mechanism prevents the CPU from being overwhelmed by control plane traffic?

A.Shaping
B.Policing
C.Queuing
D.Compression
AnswerB

Policing enforces a rate limit on control plane traffic destined for the CPU, dropping or remarking excess packets before they reach the route processor. This satisfies the requirement to prevent CPU overload, unlike queuing or shaping which buffer rather than discard.

Why this answer

CoPP (Control Plane Policing) uses policing to rate-limit control plane traffic destined to the CPU, preventing overload from excessive or malicious packets. Policing drops or marks packets that exceed the configured rate, protecting the route processor. This is the mechanism that directly prevents CPU overwhelm.

Exam trap

300-410 often tests the distinction between policing (drops excess) and shaping (buffers excess) — candidates pick shaping because it sounds gentler, but CoPP specifically uses policing to protect the CPU.

How to eliminate wrong answers

Option A is wrong because shaping buffers excess traffic and delays it rather than dropping it, which does not protect the CPU from a flood and can add latency. Option C is wrong because queuing schedules packets but does not limit the rate of control plane traffic to the CPU. Option D is wrong because compression reduces bandwidth usage, not control plane traffic volume, and is unrelated to CoPP.

333
MCQmedium

A network engineer is configuring Zone-Based Policy Firewall on a Cisco IOS XE router. The company requires that all traffic from the internal LAN zone to the untrusted Internet zone be inspected, but traffic from the Internet to the internal LAN must be blocked unless it is return traffic. The engineer has already defined zone pairs with 'zone-pair security IN-TO-OUT source LAN destination INTERNET' and applied an inspect policy-map. What must the engineer do to complete the configuration?

A.Configure a class-map matching all traffic and apply it to the zone pair with the 'inspect' action.
B.Assign the interfaces to the LAN and INTERNET zones using the 'zone-member security' command.
C.Enable 'ip inspect' globally on the router to activate stateful inspection for all zones.
D.Apply the inspect policy-map directly to the inside interface using the 'service-policy type inspect' command.
AnswerB

Zone-Based Policy Firewall requires interfaces to be assigned to zones before any zone-pair policy takes effect. The 'zone-member security' interface command binds each interface to its zone, enabling the inspect policy-map to be applied to traffic traversing the LAN-to-INTERNET zone pair. Without this binding, the zone-pair policy is dormant and no inspection occurs.

Why this answer

Zone-Based Policy Firewall operates by grouping interfaces into security zones and defining policies between zone pairs. The inspect policy-map applied to the LAN-to-INTERNET zone pair only functions when the involved interfaces are assigned to their respective zones with 'zone-member security'. Until interfaces are bound to zones, the zone-pair policy remains inactive, so no stateful inspection or implicit return traffic handling occurs.

Exam trap

The trap here is assuming that applying a policy-map to a zone pair is sufficient, when interfaces must first be assigned to zones for the policy to take effect.

334
MCQhard

An engineer configures OSPF area range on an ABR to summarize routes. After configuration, some routes are still being advertised as individual LSAs into the backbone. Which is the most likely explanation?

A.The area range command does not summarize external routes redistributed into OSPF.
B.The ABR is not configured with the summary-address command.
C.The area range is configured on the wrong ABR.
D.The OSPF process needs to be cleared to apply the area range.
AnswerA

Area range summarises only intra-area routes (type 3 LSAs) between areas. External routes redistributed into OSPF remain type 5 LSAs flooded domain-wide, so they continue appearing individually in the backbone. The stem's leftover individual LSAs are therefore external prefixes, which require the separate ASBR summary-range mechanism instead.

Why this answer

The OSPF 'area range' command only summarizes intra-area (Type 1 and Type 2) LSAs at an ABR; it does not affect external routes redistributed into OSPF as Type 5 (or Type 7) LSAs. External routes must be summarized with the 'summary-address' command on the ASBR (or NSSA ABR for Type 7). That is why some routes continue to be advertised individually after area range is configured.

Exam trap

300-410 often tests the distinction between 'area range' (intra-area Type 1/2 summarization at ABR) and 'summary-address' (external Type 5/7 summarization at ASBR), catching candidates who assume area range summarizes everything.

How to eliminate wrong answers

Option B is wrong because 'summary-address' is indeed the correct command for external routes, but the question asks for the explanation of why routes are still individual — the answer is that area range does not cover external LSAs, not that summary-address is missing (though it would be the fix). Option C is wrong because if area range were on the wrong ABR, no summarization would occur at all, but the symptom is partial summarization. Option D is wrong because OSPF applies area range changes dynamically without requiring a process clear; clearing is not the issue.

335
MCQhard

A network engineer is deploying MPLS Layer 3 VPNs on a Cisco IOS XE PE router. The customer VRF CUST_A uses OSPF as the PE-CE routing protocol. The engineer must ensure that OSPF routes from the customer are redistributed into MP-BGP and that the OSPF domain ID is preserved across the MPLS backbone. Which configuration step is required on the PE router?

A.Configure the OSPF process with the capability vrf-lite command and redistribute connected routes into BGP.
B.Configure a route target export and import under the VRF and enable OSPF as the provider core routing protocol.
C.Configure a sham link between PE routers and set the OSPF network type to point-to-point on the PE-CE link.
D.Configure route redistribution from OSPF into BGP under the VRF address family and set a domain ID under router ospf with the same value on all PE routers.
AnswerD

To preserve the OSPF domain ID across the MPLS backbone, the PE router must redistribute OSPF into MP-BGP and use the domain ID feature. Configuring the same domain ID under router ospf for the VRF on all PE routers ensures that OSPF routes retain their domain identity, preventing loops and allowing proper route redistribution into BGP.

Why this answer

Preserving the OSPF domain ID requires redistributing OSPF into MP-BGP and configuring a consistent domain ID under the OSPF process on all PE routers. This ensures that routes carry the domain identifier, which prevents routing loops and maintains OSPF route integrity across the MPLS VPN. Other options either misapply features or do not address domain ID preservation.

Exam trap

The trap here is confusing route targets or sham links with the OSPF domain ID mechanism, which is a specific OSPF process parameter.

336
Drag & Dropmedium

Drag and drop the steps to verify and validate syslog operational state into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, check the logging status with show logging. Then, verify that syslog messages are being sent to the configured server. Next, confirm the severity level of logged messages.

After that, validate that the syslog server is receiving messages. Finally, test by generating a test log message.

337
MCQmedium

A network engineer runs the following command to verify IPv6 device tracking: R1# show ipv6 device-tracking database Interface MAC Address VLAN IPv6 Address State Age Policy Fa0/0 0011.2233.4455 10 2001:db8::1 ACTIVE 10 TRUSTED Fa0/0 00aa.bbcc.ddee 10 2001:db8::2 ACTIVE 5 INSPECT Fa0/0 1111.2222.3333 10 2001:db8::3 VERIFY 0 - What does this output indicate?

A.Device tracking shows two devices in ACTIVE state and one in VERIFY state, indicating ongoing ND verification for the third device.
B.All devices are in ACTIVE state, indicating stable tracking.
C.Device tracking is disabled, and the database is empty.
D.Device tracking only tracks IPv4 addresses.
AnswerA

The database lists three entries: two with policy TRUSTED and INSPECT in ACTIVE state, and one in VERIFY state with no policy, showing device tracking is still confirming reachability of the third device via ND.

Why this answer

The output shows three entries: two in ACTIVE state (indicating successful ND verification) and one in VERIFY state (meaning the device is currently undergoing Neighbor Discovery verification). The VERIFY state with age 0 indicates that the device has been recently discovered and is being validated before transitioning to ACTIVE. This confirms that device tracking is actively monitoring IPv6 devices, with ongoing ND verification for the third device.

Exam trap

Cisco often tests the distinction between ACTIVE and VERIFY states in IPv6 device tracking, where candidates mistakenly assume all entries are stable (ACTIVE) or that VERIFY indicates a failure, rather than recognizing it as a normal transitional state during ND verification.

How to eliminate wrong answers

Option B is wrong because not all devices are in ACTIVE state; the third device is in VERIFY state, which indicates ongoing verification, not stable tracking. Option C is wrong because the database is not empty; it contains three entries, and device tracking is clearly enabled as shown by the populated output. Option D is wrong because device tracking supports IPv6 addresses, as evidenced by the IPv6 Address column containing IPv6 addresses (2001:db8::1, etc.), not IPv4 addresses.

338
MCQhard

A service provider is deploying MPLS Traffic Engineering (TE) with RSVP-TE to guarantee bandwidth for critical traffic. The network uses OSPF as the IGP with TE extensions enabled. An engineer notices that a TE tunnel fails to establish because the path computation cannot find a path with sufficient bandwidth, even though the physical links have enough capacity. Which action should the engineer take to ensure that RSVP-TE can reserve bandwidth on the links?

A.Enable MPLS TE on the physical interfaces and configure the ip rsvp bandwidth command with the appropriate reservable bandwidth.
B.Enable MPLS LDP on all interfaces to ensure label distribution for the TE tunnel.
C.Configure the mpls traffic-eng tunnels command under the OSPF process to advertise TE metrics.
D.Configure the ip rsvp bandwidth command under the OSPF process to allow RSVP to reserve bandwidth.
AnswerA

For RSVP-TE to reserve bandwidth, MPLS TE must be enabled on the interface, and the ip rsvp bandwidth command must be configured to define the amount of reservable bandwidth. Without this, the TE tunnel cannot signal reservations, and path computation will fail because no bandwidth is available for reservation, even if the physical link has capacity.

Why this answer

RSVP-TE requires that MPLS TE be enabled on the physical interface and that the interface be configured with the ip rsvp bandwidth command to specify the reservable bandwidth. Without this interface-level configuration, the TE tunnel cannot signal a reservation, and path computation fails due to lack of available bandwidth. OSPF TE extensions are already enabled, so the missing piece is the interface configuration.

Exam trap

The trap here is assuming that enabling OSPF TE extensions or MPLS LDP is sufficient for RSVP-TE bandwidth reservation, when in fact the interface-level RSVP bandwidth configuration is required.

339
MCQmedium

A network engineer runs the following command to troubleshoot an IPv6 traffic filtering issue: R1# show ipv6 access-list FILTER IPv6 access list FILTER permit ipv6 2001:DB8:1::/48 any sequence 10 deny ipv6 2001:DB8:2::/48 any sequence 20 permit ipv6 any any sequence 30 What does this output indicate?

A.The access list will permit traffic from 2001:DB8:1::/48 and deny traffic from 2001:DB8:2::/48, but permit all other IPv6 traffic.
B.The access list will permit traffic from 2001:DB8:1::/48 and deny traffic from 2001:DB8:2::/48, and implicitly deny all other IPv6 traffic.
C.The access list will deny all traffic because of the deny statement.
D.The access list is invalid because IPv6 access lists require implicit deny at the end.
AnswerA

Sequential evaluation stops at the first match, so 2001:DB8:1::/48 is permitted by sequence 10, 2001:DB8:2::/48 is denied by sequence 20, and everything else falls through to the sequence 30 permit any any. The implicit deny never applies because that final entry matches all remaining IPv6 traffic.

Why this answer

The output shows an IPv6 access list with three explicit entries. Sequence 10 permits traffic from source 2001:DB8:1::/48 to any destination, sequence 20 denies traffic from 2001:DB8:2::/48 to any destination, and sequence 30 permits all other IPv6 traffic. Because sequence 30 explicitly permits any any, traffic not matching the first two entries is permitted, overriding the default implicit deny at the end of the list.

Exam trap

Cisco often tests the interaction between explicit permit entries and the implicit deny, where candidates mistakenly assume the implicit deny applies even when a later explicit permit any any exists.

How to eliminate wrong answers

Option B is wrong because it states that all other IPv6 traffic is implicitly denied, but the explicit permit any any entry at sequence 30 permits all remaining traffic, so the implicit deny is never reached. Option C is wrong because the deny statement only blocks traffic from 2001:DB8:2::/48; the permit entries allow other traffic, so the list does not deny all traffic. Option D is wrong because IPv6 access lists do have an implicit deny at the end, but the list is not invalid; the explicit permit any any entry is valid and overrides the implicit deny for unmatched traffic.

340
MCQmedium

Given the partial configuration: crypto isakmp policy 10 encryption aes 256 authentication pre-share group 14 ! crypto isakmp key cisco123 address 0.0.0.0 0.0.0.0 ! crypto ipsec transform-set TSET esp-aes 256 esp-sha-hmac mode tunnel ! crypto map CMAP 10 ipsec-isakmp set peer 192.168.1.2 set transform-set TSET match address 101 ! interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 crypto map CMAP ! access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255 What is the effect of the 'crypto isakmp key' command with address 0.0.0.0 0.0.0.0?

A.The key will be used only for peer 192.168.1.2 because the crypto map specifies that peer.
B.The key will be accepted from any peer, creating a security vulnerability.
C.The configuration will fail because the key must specify a specific peer address.
D.The key will be ignored because there is no ISAKMP policy with a lifetime.
AnswerB

The wildcard address 0.0.0.0 0.0.0.0 matches every peer, so the preshared key is offered to any device initiating IKE. This removes peer authentication by address, allowing an unauthorised host to complete phase 1 and establishing a genuine security weakness.

Why this answer

The `crypto isakmp key` command with address `0.0.0.0 0.0.0.0` acts as a wildcard, meaning the pre-shared key will be accepted from any peer IP address during IKE Phase 1 authentication. This effectively disables peer-specific validation, allowing any device that knows the key to establish an ISAKMP SA, which is a significant security vulnerability.

Exam trap

Cisco often tests the misconception that the crypto map's `set peer` command restricts which peers can authenticate with the pre-shared key, but in reality, the ISAKMP key wildcard overrides that restriction at the IKE layer.

How to eliminate wrong answers

Option A is wrong because the crypto map's peer specification only controls which peer is used for IPsec SA negotiation, not which peer is allowed to authenticate with the pre-shared key; the wildcard key overrides any peer restriction at the IKE level. Option C is wrong because the configuration is valid; Cisco IOS allows a wildcard address (0.0.0.0 0.0.0.0) for the ISAKMP key, and it will not cause a configuration failure. Option D is wrong because the ISAKMP key is not dependent on a lifetime being configured in the ISAKMP policy; the key is used regardless of whether a lifetime is explicitly set.

341
Multi-Selectmedium

A network engineer is configuring policy-based routing (PBR) on a Cisco router. The router has two interfaces: GigabitEthernet0/0 (LAN) and GigabitEthernet0/1 (WAN). The engineer wants to route traffic from the 192.168.1.0/24 subnet to a next-hop of 10.1.1.2, and all other traffic should follow the default routing table. Which two steps are required to implement this? (Choose two.)

Select 2 answers
A.Apply the route map to the GigabitEthernet0/0 interface using the ip policy route-map command.
B.Configure a default route pointing to 10.1.1.2.
C.Create a route map that matches the source subnet 192.168.1.0/24 and sets the next-hop to 10.1.1.2.
D.Create an ACL that permits traffic from 192.168.1.0/24 and apply it to the GigabitEthernet0/0 interface inbound.
E.Enable PBR globally using the ip policy route-map command in global configuration mode.
AnswersA, C

PBR is applied to the interface where traffic enters the router. In this scenario, traffic from the 192.168.1.0/24 subnet arrives on GigabitEthernet0/0 (LAN). Therefore, you must apply the route map to that interface using the ip policy route-map command in interface configuration mode. This activates PBR for incoming packets on that interface, allowing the route map to be evaluated.

Why this answer

To implement PBR, you must define a route map that matches the traffic (using an ACL) and sets the next-hop. Then, you apply that route map to the ingress interface using the ip policy route-map command. The other options are incorrect: a default route would affect all traffic, PBR is not enabled globally, and applying an ACL directly to the interface would filter rather than route.

Exam trap

The trap here is confusing PBR with ACL filtering or default routing, and forgetting that PBR must be applied to the ingress interface.

342
MCQmedium

A network engineer is configuring OSPF on a router. The router has an interface with IP address 10.1.1.1/24 and another interface with IP address 192.168.1.1/24. The engineer wants to enable OSPF on both interfaces using a single network command under router ospf 1. Which command accomplishes this?

A.network 10.0.0.0 0.255.255.255 area 0
B.network 0.0.0.0 255.255.255.255 area 0
C.network 10.1.1.0 0.0.0.255 area 0 and network 192.168.1.0 0.0.0.255 area 0
D.network 10.1.1.0 0.0.0.255 area 0
AnswerB

This command uses a wildcard mask of 255.255.255.255, which matches any IP address. It enables OSPF on all interfaces of the router, including both the 10.1.1.1/24 and 192.168.1.1/24 interfaces, achieving the goal with a single network statement.

Why this answer

The network command in OSPF uses a wildcard mask to match interface IP addresses. To enable OSPF on all interfaces with one command, use network 0.0.0.0 255.255.255.255 area 0, which matches any IP address. This activates OSPF on both the 10.1.1.1/24 and 192.168.1.1/24 interfaces, satisfying the requirement.

Exam trap

The trap here is assuming that a network command with a wildcard mask must match the subnet exactly, but a wildcard mask of 255.255.255.255 matches all addresses regardless of subnet.

343
MCQeasy

In an MPLS L3VPN environment using MP-BGP, what is the default value of the BGP keepalive timer on Cisco IOS-XE?

A.30 seconds
B.60 seconds
C.90 seconds
D.180 seconds
AnswerB

Cisco IOS-XE MP-BGP uses a default keepalive timer of 60 seconds, with the hold timer defaulting to 180 seconds (three times keepalive). This applies to the BGP session carrying VPNv4 routes in the MPLS L3VPN environment, independent of any address-family configuration.

Why this answer

The default BGP keepalive timer is 60 seconds, as defined in RFC 4271 and implemented in Cisco IOS-XE.

344
MCQhard

A network engineer runs the following command to troubleshoot a VRF-Lite redistribution issue: R1# debug ip routing vrf CUSTOMER_E Output: RT: add 10.3.3.0/24 via 10.1.1.2, ospf 200 metric [110/20] RT: add 10.3.3.0/24 via 10.1.1.2, eigrp 100 metric [90/131072] tag 0 RT: closer admin distance for 10.3.3.0/24, adding via eigrp 100 RT: add 10.3.3.0/24 to routing table, via eigrp 100 What does this output indicate?

A.The route 10.3.3.0/24 is added from OSPF 200 because it has a lower metric.
B.The route 10.3.3.0/24 is added from EIGRP 100 because it has a lower administrative distance than OSPF.
C.The route 10.3.3.0/24 is added from both OSPF and EIGRP, creating an equal-cost path.
D.The route 10.3.3.0/24 is not added to the routing table due to a tag mismatch.
AnswerB

EIGRP's administrative distance of 90 beats OSPF's 110, so the router installs the EIGRP 100 path for 10.3.3.0/24 despite OSPF 200 learning it first. The debug line "closer admin distance" confirms this selection within the CUSTOMER_E VRF, satisfying the stem's requirement to explain the redistribution outcome.

Why this answer

The debug output shows EIGRP 100 winning the route selection because the router compares administrative distance (AD) before metrics when routes come from different routing protocols. EIGRP's default AD of 90 is lower than OSPF's 110, so the EIGRP path is installed even though OSPF's metric of 20 looks numerically smaller. The line 'closer admin distance for 10.3.3.0/24, adding via eigrp 100' confirms this AD-based decision.

Exam trap

The trap here is confusing metric with administrative distance — candidates see OSPF's metric [110/20] and assume the lower number wins, forgetting that 110 is the AD, not the metric, and that AD decides across protocols.

How to eliminate wrong answers

Option A is wrong because metrics are only compared between paths from the same protocol; across protocols, AD is the tiebreaker, and OSPF's metric of 20 is irrelevant against EIGRP's AD of 90. Option C is wrong because equal-cost multipath requires identical AD and metric from the same protocol — OSPF and EIGRP cannot form an ECMP pair. Option D is wrong because the tag value of 0 is simply the default EIGRP tag and does not prevent installation; the route was in fact added to the RIB.

345
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 traffic IPv6 statistics: Rcvd: 1000 total, 800 unicast, 200 multicast Sent: 900 total, 700 unicast, 200 multicast Errors: 0 Dropped: 0 ND statistics: NS: 50 received, 40 sent NA: 30 received, 20 sent RS: 10 received, 5 sent RA: 2 received, 8 sent Redirect: 0 received, 0 sent Based on this output, which statement is correct?

A.The router is not sending any Router Advertisements.
B.The router is receiving more Neighbor Solicitations than it is sending, which is expected.
C.There is a high number of errors in IPv6 traffic.
D.The router is dropping many packets.
AnswerB

Receiving more Neighbor Solicitations than it sends is normal: hosts unicast NS to resolve a router's link-layer address, while the router replies with Neighbor Advertisements, not NS. The 50 received versus 40 sent reflects many hosts soliciting one router, satisfying the stem's ND statistics.

Why this answer

In IPv6, Neighbor Solicitations (NS) are used for address resolution and duplicate address detection. A router typically receives more NS messages than it sends, as hosts send NS to resolve the router's link-layer address, while the router sends NS primarily for DAD or to verify neighbor reachability. The output shows 50 NS received versus 40 sent, which aligns with this expected behavior.

Exam trap

Cisco often tests the expected asymmetry in Neighbor Solicitation counts between routers and hosts, where candidates mistakenly think a router should send more NS than it receives, but in practice, routers receive more NS from hosts performing address resolution.

How to eliminate wrong answers

Option A is wrong because the router has sent 8 Router Advertisements (RA) and received 2, indicating it is actively sending RAs, not failing to do so. Option C is wrong because the output explicitly shows 'Errors: 0', meaning no errors in IPv6 traffic. Option D is wrong because the output shows 'Dropped: 0', indicating no packets are being dropped.

346
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip nhrp 10.0.0.2/32 via 10.0.0.2, Tunnel0 created 00:15:30, expire 01:44:30 Type: dynamic, Flags: used NBMA address: 192.168.1.2 10.0.0.3/32 via 10.0.0.3, Tunnel0 created 00:10:20, expire 01:49:40 Type: dynamic, Flags: used NBMA address: 192.168.1.3 Based on this output, which statement is correct?

A.Both NHRP entries are static.
B.Both NHRP entries are active and dynamically learned.
C.The NHRP entries have expired.
D.The NBMA addresses are IPv6 addresses.
AnswerB

Both entries show Type: dynamic and Flags: used, meaning NHRP learned them from registration or resolution replies and they are currently valid. The remaining expiry timers confirm the mappings are active, so both next-hop entries are dynamically learned and in use.

Why this answer

The output shows two NHRP entries with Type: dynamic and Flags: used, indicating they were dynamically learned via NHRP registration/resolution and are currently active (not expired). The expire timers (01:44:30 and 01:49:40) confirm they are valid.

Exam trap

The trap is misreading the Type field or assuming entries with expire timers are expired; candidates must recognize that future expire times mean active entries.

How to eliminate wrong answers

Option A is wrong because the Type field explicitly says 'dynamic', not 'static'. Option C is wrong because the entries have future expire times, meaning they are active, not expired. Option D is wrong because the NBMA addresses (192.168.1.2, 192.168.1.3) are IPv4 addresses, not IPv6.

347
MCQhard

A DMVPN network uses PBR to route traffic from spoke routers to specific hubs based on source IP. After a hub failure, traffic from spoke 1 (source 192.168.1.0/24) is being sent to a backup hub, but the backup hub drops the traffic. Router R1 (spoke) shows: 'show ip policy' shows PBR applied, 'debug ip policy' shows traffic being forwarded to next-hop 10.1.1.2 (backup hub). Router R2 (backup hub) shows: 'show ip route 192.168.1.0' returns no route. What is the root cause?

A.The backup hub does not have a route to the source subnet, causing it to drop traffic. Add a static route or enable routing protocol on the backup hub for the spoke subnet.
B.The PBR route-map on the spoke is missing a 'set ip next-hop verify-availability' command, causing it to use the backup hub even when it is not fully reachable.
C.The spoke's routing table has a better route to the destination via the backup hub, overriding PBR.
D.The backup hub has a route to the source subnet but with a higher administrative distance, causing it to be ignored.
AnswerA

PBR successfully forwards spoke traffic to the backup hub, but that hub has no route for 192.168.1.0/24, so it drops the packets. Adding a static route or enabling a routing protocol on the backup hub restores reachability to the source subnet.

Why this answer

The backup hub (R2) has no route to the source subnet 192.168.1.0/24, as confirmed by 'show ip route 192.168.1.0' returning no route. Even though PBR on the spoke correctly forwards traffic to the backup hub, the backup hub cannot return traffic to the source subnet, so it drops the packets. Adding a static route or enabling a routing protocol on the backup hub for the spoke subnet resolves the issue.

Exam trap

300-410 often tests the misconception that fixing the spoke's PBR configuration will resolve the issue, when the real problem is the return path on the hub — candidates must check both directions of traffic flow.

How to eliminate wrong answers

Option B is wrong because 'set ip next-hop verify-availability' is used to verify next-hop reachability before forwarding, but the debug output shows traffic is already being forwarded to the backup hub, so the issue is not PBR next-hop verification. Option C is wrong because PBR takes precedence over the routing table for matched traffic, so a better route in the routing table would not override PBR. Option D is wrong because the output explicitly shows no route exists on the backup hub, not a route with higher administrative distance.

348
MCQhard

An engineer configures OSPF on a link between two routers with MTU 1500 on one side and MTU 1400 on the other. The adjacency forms but is stuck in EXSTART. Which is the most likely explanation?

A.The router with the larger MTU sends DBD packets that exceed the smaller MTU, causing them to be dropped silently.
B.The router with the smaller MTU cannot process OSPF hello packets from the larger MTU side.
C.The adjacency is stuck because OSPF network type mismatch prevents DBD exchange.
D.The router with the larger MTU must have 'ip ospf mtu-ignore' configured to bypass the MTU check.
AnswerA

OSPF DBD packets are sized based on the outgoing interface MTU. If the packet is larger than the receiving interface MTU, it is dropped, preventing the exchange of LSAs.

Why this answer

When OSPF routers have mismatched MTUs, the router with the larger MTU (1500) will send Database Description (DBD) packets that include the full MTU size in the interface MTU field. The router with the smaller MTU (1400) will reject these packets because they exceed its MTU, causing them to be silently dropped. This prevents the DBD exchange from completing, leaving the adjacency stuck in EXSTART state.

Exam trap

Cisco often tests the specific state where the adjacency gets stuck (EXSTART) to distinguish between MTU mismatch and other OSPF issues, and the trap here is that candidates may incorrectly attribute the problem to hello packet failures or network type mismatches rather than the silent dropping of DBD packets due to MTU mismatch.

How to eliminate wrong answers

Option B is wrong because OSPF hello packets are small (typically 44 bytes) and will not be dropped due to MTU mismatch; the issue is with DBD packets, not hello packets. Option C is wrong because a network type mismatch would typically prevent the adjacency from forming at all or cause it to be stuck in INIT/2WAY, not EXSTART; EXSTART specifically indicates the DBD exchange phase has begun but cannot complete. Option D is wrong because the 'ip ospf mtu-ignore' command is used to bypass the MTU check on the router receiving the DBD packets, but it is not a requirement for the larger MTU side; the command should be configured on the router with the smaller MTU to allow larger DBD packets to be accepted.

349
Drag & Dropmedium

Drag and drop the steps to configure a Control Plane Policing (CoPP) policy into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts by identifying traffic with a class-map, then grouping classes in a policy-map, applying actions (e.g., drop), attaching the policy to the control-plane, and finally verifying the configuration. This follows the standard MQC (Modular QoS CLI) workflow.

350
MCQeasy

What is the default role of an interface in IPv6 Neighbor Discovery Inspection when no policy is explicitly applied?

A.Untrusted
B.Trusted
C.Server
D.Host
AnswerA

IPv6 Neighbor Discovery Inspection treats every interface as untrusted until a trust policy is explicitly bound to it, so no Neighbor Advertisement or Neighbor Solicitation messages are inspected or permitted by default. This default-deny stance satisfies the stem's condition of no policy being applied.

Why this answer

In IPv6 Neighbor Discovery Inspection (NDI), an interface is considered untrusted by default when no policy is explicitly applied. This default ensures that all incoming Neighbor Discovery (ND) messages are subject to validation against the binding table, preventing attacks such as Neighbor Advertisement spoofing and Duplicate Address Detection (DAD) exploitation. Only interfaces explicitly configured with a trust policy bypass this inspection.

Exam trap

Cisco often tests the misconception that all interfaces start as trusted or that a 'host' or 'server' role exists, when in fact the default is untrusted and only two roles (untrusted and trusted) are defined for NDI.

How to eliminate wrong answers

Option B is wrong because a trusted interface would bypass ND inspection entirely, which is not the default behavior; trust must be explicitly configured. Option C is wrong because 'Server' is not a valid role for an interface in IPv6 NDI; it refers to a DHCPv6 server role in other contexts. Option D is wrong because 'Host' is not a defined interface role in IPv6 NDI; the roles are only untrusted (default) and trusted (explicit).

351
MCQeasy

A network engineer is configuring a static route on a Cisco IOS router. The engineer wants the route to be used only if the primary route fails. Which command should be used to configure a floating static route?

A.ip route 0.0.0.0 0.0.0.0 192.168.1.1 200
B.ip route 0.0.0.0 0.0.0.0 192.168.1.1 track 1
C.ip route 0.0.0.0 0.0.0.0 192.168.1.1 name BACKUP
D.ip route 0.0.0.0 0.0.0.0 192.168.1.1 permanent
AnswerA

A floating static route is configured with an administrative distance higher than that of the primary route. The command `ip route 0.0.0.0 0.0.0.0 192.168.1.1 200` sets the administrative distance to 200, which is higher than the default administrative distance of most dynamic routing protocols (e.g., OSPF is 110, EIGRP is 90). This ensures the static route is only used if the primary route is not in the routing table.

Why this answer

A floating static route is a static route with an administrative distance higher than the primary route, so it is only installed in the routing table when the primary route is unavailable. The command `ip route 0.0.0.0 0.0.0.0 192.168.1.1 200` sets the administrative distance to 200, making it less preferred than dynamic routes. This is the standard method to configure a floating static route.

Exam trap

The trap here is confusing the `permanent` or `track` keywords with floating static routes, when the key is administrative distance.

352
MCQhard

A network administrator is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers using IKEv2. Phase 1 is up, but Phase 2 fails to establish. The administrator runs 'show crypto ipsec sa' and sees no active SAs. Which action should the administrator take to resolve the issue?

A.Verify that the IKEv2 proposal matches on both peers.
B.Verify that the IPsec transform set or profile matches on both peers.
C.Ensure that the crypto ACL or IPsec profile matches the traffic to be encrypted.
D.Check that the IKEv2 keyring contains the correct pre-shared key.
AnswerB

Phase 2 failure often results from a mismatch in the IPsec transform set or profile, which defines the encryption and integrity algorithms for the data plane. If the transform sets do not match, the peers cannot agree on the IPsec SA parameters, and Phase 2 fails. Checking and aligning the transform set or profile on both routers is a critical troubleshooting step for this scenario.

Why this answer

Phase 2 failure with no active SAs typically indicates a mismatch in the IPsec transform set or profile. Since Phase 1 is up, IKEv2 parameters like the proposal and pre-shared key are correct. The crypto ACL defines interesting traffic but does not prevent SA establishment.

Therefore, verifying the transform set or profile match is the correct action.

Exam trap

The trap here is focusing on Phase 1 parameters like the IKEv2 proposal or keyring when Phase 1 is already established; Phase 2 failures usually stem from transform set mismatches.

353
Multi-Selecthard

Which THREE statements about PBR and route-map sequence numbers are true? (Choose THREE.)

Select 3 answers
A.If a packet matches a route-map sequence with a 'permit' keyword, the set actions are applied, and no further sequences are evaluated.
B.If a packet matches a route-map sequence with a 'deny' keyword, the packet is dropped immediately.
C.The 'match ip address' command in a PBR route map can reference a named or numbered ACL, but not a prefix list.
D.If no sequence in a PBR route map matches a packet, the packet is forwarded using the routing table (normal routing).
E.The 'set ip next-hop' command can be used in a route-map sequence with a 'deny' keyword to override the default behavior.
AnswersA, C, D

If a packet matches a route-map sequence with a 'permit' keyword, the set actions are applied, and no further sequences are evaluated. This is correct.

Why this answer

Route maps used for PBR are evaluated in sequence number order. Each sequence can have match and set statements. If a packet matches a permit sequence, the set actions are applied and evaluation stops.

A deny sequence does not drop the packet; it causes the router to skip to the next sequence. If no sequence matches, the packet is forwarded using normal routing (implicit deny). In PBR, the 'match ip address' command can reference a named or numbered ACL, but not a prefix list.

To match a prefix list, you must use the 'match ip address prefix-list' command separately.

354
Multi-Selecthard

A network administrator is troubleshooting a DMVPN Phase 3 network using OSPF as the routing protocol. Spoke routers are not learning routes from other spokes. Which two actions should be taken to resolve this issue? (Choose two.)

Select 2 answers
A.Configure the hub as a route reflector for BGP.
B.Configure the spoke routers with 'ip nhrp shortcut' on their tunnel interfaces.
C.Ensure that the hub router is configured with 'ip nhrp redirect' on its tunnel interface.
D.Disable split horizon on the hub's tunnel interface.
E.Change the OSPF network type to point-to-multipoint on all routers.
AnswersB, C

On spoke routers in DMVPN Phase 3, 'ip nhrp shortcut' allows them to install shortcut routes to other spokes based on NHRP redirect messages from the hub. Without this, spokes will not create direct tunnels and will continue to send traffic through the hub. This command is necessary for the spokes to dynamically learn the NBMA addresses of other spokes and establish direct connections. It is a key component of Phase 3 operation.

Why this answer

In DMVPN Phase 3, spoke-to-spoke communication requires the hub to send NHRP redirect messages and the spokes to support NHRP shortcuts. The hub must have 'ip nhrp redirect' configured, and each spoke must have 'ip nhrp shortcut' configured. These commands enable the spokes to dynamically discover and establish direct tunnels to other spokes, bypassing the hub.

Without them, spokes will not learn the specific routes to other spokes and will continue to route traffic through the hub, which is inefficient.

Exam trap

The trap here is confusing DMVPN Phase 3 with other phases or protocols, and assuming that OSPF network type changes or split horizon adjustments are needed, when the core issue is NHRP redirect and shortcut configuration.

355
MCQhard

An engineer configures Control Plane Policing (CoPP) with a policy that denies all traffic in class-default. After applying the policy, BGP sessions to the router fail. What is the most likely explanation?

A.The class-default has an explicit 'drop' action, which overrides the implicit permit and drops all unmatched traffic, including BGP packets.
B.The CoPP policy was applied to the wrong interface, so BGP packets are dropped by the interface ACL.
C.The BGP packets are matched by another class with a 'drop' action, but the class-default is irrelevant.
D.The CoPP policy uses 'rate-limit' in bps instead of pps, causing BGP packets to be dropped due to rate limiting.
AnswerA

CoPP class-default carries an implicit permit, so configuring an explicit drop overrides it and discards every packet not matched by an earlier class. BGP keepalives and updates arrive unmatched, so the sessions to the router fail. The stem's deny-all class-default is therefore the direct cause.

Why this answer

In a CoPP policy-map, class-default normally has an implicit permit, but if an explicit drop action is configured, it overrides that implicit behavior and drops all traffic not matched by earlier classes. BGP packets (TCP 179) that are not explicitly matched by a permit class therefore fall into class-default and are dropped, causing session failures. This is the most likely explanation given the described configuration.

Exam trap

The trap is assuming class-default always permits unmatched traffic; candidates forget that an explicit drop action overrides the implicit permit, causing control-plane protocol failures.

How to eliminate wrong answers

Option B is wrong because CoPP is applied to the control plane via service-policy input under control-plane configuration, not to interfaces — interface ACLs are a separate mechanism and would not be the cause described. Option C is wrong because the scenario explicitly states class-default denies all traffic; if BGP were matched by another class, the symptom would depend on that class's action, but the question points to class-default as the culprit. Option D is wrong because CoPP uses policer rates in pps or bps depending on configuration, but rate limiting would cause partial drops and degradation, not the total BGP failure described by an explicit deny in class-default.

356
Drag & Drophard

Drag and drop the steps to troubleshoot Control Plane Policing (CoPP) adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Troubleshooting CoPP failures starts by checking if the control-plane policy is applied, then verifying the class-map matches the correct protocol, checking for dropped packets, temporarily disabling CoPP to test, and finally adjusting the policy to permit the necessary traffic. This systematic approach isolates the issue without disrupting the network.

357
MCQhard

Router R1 is configured with ip nat inside source list 100 interface Loopback0 overload. Internal hosts at 192.168.1.0/24 can access the internet, but external hosts cannot initiate connections to an internal server at 10.1.1.10 that is also behind NAT. The server is supposed to be reachable via static NAT. Configuration: ip nat inside source static tcp 10.1.1.10 80 interface Loopback0 80. Router R1 shows: show ip nat translations: Pro Inside global Inside local Outside local Outside global tcp 10.1.1.10:80 10.1.1.10:80 --- ---. External users get connection timeouts. What is the root cause?

A.The static NAT should use a specific global IP address instead of the interface; configure ip nat inside source static tcp 10.1.1.10 80 203.0.113.10 80.
B.The access-list 100 is blocking inbound traffic.
C.The Loopback0 interface is not in the routing table.
D.The static NAT entry is missing the 'add-route' option.
AnswerA

Using the interface IP for static NAT is not supported; a specific global IP must be defined.

Why this answer

The static NAT configuration uses 'interface Loopback0' as the global address, which means it relies on the interface's dynamically assigned IP address. However, the overload rule (PAT) is also using the same interface, and the static NAT entry shown in 'show ip nat translations' displays the inside local address as the inside global address (10.1.1.10:80), indicating that the static translation is not being applied correctly. The root cause is that static NAT requires a specific global IP address (e.g., 203.0.113.10) to map the internal server, not the interface keyword, because the interface keyword is used for PAT and does not create a fixed one-to-one mapping for inbound connections.

Exam trap

Cisco often tests the distinction between using 'interface' for dynamic PAT and a specific IP for static NAT, trapping candidates who think 'interface' can serve both purposes without understanding that static NAT requires a fixed global address for inbound reachability.

How to eliminate wrong answers

Option B is wrong because access-list 100 is used only for the dynamic NAT overload rule (ip nat inside source list 100 interface Loopback0 overload) and does not affect inbound traffic for static NAT; static NAT bypasses ACLs for translation. Option C is wrong because the Loopback0 interface must be in the routing table for the router to have a route to the internet, and the scenario states internal hosts can access the internet, confirming the interface is operational and reachable. Option D is wrong because the 'add-route' option is not a valid parameter for the 'ip nat inside source static' command; it is used with 'ip nat outside source static' or in some IOS versions for route injection, but it is not required for basic static NAT to function.

358
MCQmedium

A network engineer runs the following command to troubleshoot a BFD issue: R1# debug bfd event *Mar 1 00:12:34.567: BFD: [R1-to-R2] state DOWN -> UP (async) *Mar 1 00:12:34.568: BFD: [R1-to-R2] echo mode enabled, min-echo-rx-interval 50 ms *Mar 1 00:12:34.569: BFD: [R1-to-R2] starting echo timer, interval 50 ms *Mar 1 00:12:34.570: BFD: [R1-to-R2] sending async packet, state UP, interval 300 ms What does this output indicate?

A.BFD session is flapping between DOWN and UP states.
B.BFD session is established and echo mode is active.
C.BFD session is down due to echo failure.
D.BFD async interval is misconfigured at 300 ms.
AnswerB

The debug trace confirms the session transitioned from DOWN to UP in asynchronous mode, then negotiated echo mode with a 50 ms echo timer. Echo packets are looped back by the neighbour, so the stated establishment and active echo function match the logged events precisely.

Why this answer

The debug output shows BFD session transitioning from DOWN to UP, with echo mode enabled and the async interval set to 300 ms. This indicates a successful BFD session establishment.

359
MCQeasy

What is the default action for a packet that does not match any route-map entry in a PBR policy?

A.The packet is dropped.
B.The packet is forwarded using the routing table.
C.The packet is sent to the CPU for processing.
D.The router sends an ICMP unreachable message.
AnswerB

Policy-based routing evaluates route-map entries sequentially; if no entry matches the packet, PBR yields and normal destination-based forwarding resumes. The packet is therefore routed via the routing table, which is the default behaviour when no policy statement applies.

Why this answer

Policy-Based Routing (PBR) via route-maps uses an implicit deny at the end of the route-map, but 'deny' in a route-map used for PBR means 'do not policy-route this packet' — the packet is then forwarded normally using the routing table. This differs from route-maps used for route redistribution, where an implicit deny means the route is not redistributed. The key distinction is the context: PBR route-maps fall through to normal destination-based forwarding.

Exam trap

The trap is conflating the implicit deny behavior of route-maps in redistribution (where unmatched routes are filtered) with PBR (where unmatched packets fall through to normal routing) — candidates who assume 'implicit deny = drop' pick option A.

How to eliminate wrong answers

Option A is wrong because the implicit deny in a PBR route-map does not drop the packet — it simply means no policy action is applied, so the packet is routed normally. Option C is wrong because PBR does not punt unmatched packets to the CPU; that behavior is associated with features like ARP or control-plane policing, not route-map fall-through. Option D is wrong because ICMP unreachable is generated when there is no route to the destination in the routing table, not when a PBR route-map entry does not match.

360
MCQeasy

A network engineer runs the following command on Router R1: R1# show ipv6 access-list FILTER-IPv6 IPv6 access list FILTER-IPv6 permit ipv6 2001:DB8:1::/48 any sequence 10 deny ipv6 any any sequence 20 Based on this output, what is the effect of this access list when applied to an interface?

A.It permits all IPv6 traffic
B.It denies all IPv6 traffic from 2001:DB8:1::/48
C.It permits only IPv6 traffic from 2001:DB8:1::/48 and denies everything else
D.It permits all IPv6 traffic except from 2001:DB8:1::/48
AnswerC

Sequence 10 permits the prefix, sequence 20 denies all other traffic.

Why this answer

The access list FILTER-IPv6 has two entries: a permit statement for source 2001:DB8:1::/48 to any destination (sequence 10), followed by an implicit deny all (sequence 20). When applied to an interface, only traffic matching the permit entry is allowed; all other IPv6 traffic is denied by the implicit deny rule at the end of the list. This results in permitting only traffic from the specified prefix and denying everything else.

Exam trap

Cisco often tests the implicit deny all at the end of an access list, and the trap here is that candidates may overlook the deny ipv6 any any entry (sequence 20) or assume it is not present, leading them to incorrectly think the ACL permits all traffic (Option A) or permits all except the specified prefix (Option D).

How to eliminate wrong answers

Option A is wrong because the access list includes an explicit deny ipv6 any any (sequence 20), which blocks all traffic not matching the permit statement, so it does not permit all IPv6 traffic. Option B is wrong because the permit statement allows traffic from 2001:DB8:1::/48, not deny it; the deny statement applies to all other traffic. Option D is wrong because the permit statement allows traffic from 2001:DB8:1::/48, not deny it, and the deny statement blocks all other traffic, so the effect is the opposite of what is described.

361
MCQmedium

A network engineer is configuring a GRE tunnel between two Cisco routers. The tunnel interface is up, but the engineer cannot ping the remote tunnel endpoint. The physical interfaces are up, and there is a route to the remote physical address. Which command should be used to verify that the tunnel source and destination are correctly configured?

A.show ip route
B.show ip interface brief
C.show interfaces tunnel 0
D.show crypto session
AnswerC

'show interfaces tunnel 0' displays the tunnel interface status, including the source and destination addresses, and the tunnel protocol. It verifies that the tunnel source and destination are correctly configured and that the tunnel is up. If the tunnel is up but pings fail, it could be a routing issue over the tunnel.

Why this answer

The 'show interfaces tunnel 0' command displays detailed information about the tunnel interface, including the configured source and destination addresses, and the tunnel status. It is the most direct way to verify that the tunnel endpoints are correctly configured. Other commands do not show the tunnel source and destination.

Exam trap

The trap here is assuming that 'show ip interface brief' provides enough detail to verify tunnel endpoints, when it only shows the interface IP address (which may be the tunnel IP, not the source/destination).

362
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. The hub router must dynamically learn spoke-to-spoke routes without requiring a full mesh of tunnels. Which technology should be implemented on the hub to allow spoke routers to resolve next-hop addresses directly?

A.Configure OSPF network type as point-to-multipoint on all routers.
B.Implement IPsec tunnel protection on the hub only.
C.Enable NHRP redirect on the hub and NHRP shortcut on the spokes.
D.Use BGP route reflectors to distribute spoke routes.
AnswerC

NHRP redirect on the hub and NHRP shortcut on the spokes enable Phase 3 DMVPN. The hub sends redirect messages to spokes when traffic is received on the same tunnel interface, allowing the spoke to dynamically build a direct tunnel to the destination spoke. This reduces latency and hub load.

Why this answer

NHRP redirect on the hub and NHRP shortcut on the spokes are the defining features of DMVPN Phase 3. The hub uses redirect messages to inform spokes of a better path, and spokes use shortcut to create direct tunnels. This enables dynamic spoke-to-spoke communication without a full mesh, reducing latency and hub resource consumption.

Exam trap

The trap here is confusing DMVPN Phase 2 with Phase 3, assuming that any dynamic routing protocol or IPsec configuration alone can enable spoke-to-spoke tunnels without NHRP redirect and shortcut.

363
MCQeasy

A network technician is configuring a Cisco IOS router to authenticate administrative users via TACACS+ using a centralized server. The requirement is that if the TACACS+ server is unreachable, the router should use the local username database for authentication. Which command sequence correctly configures this fallback behavior?

A.aaa authentication login default group tacacs+ none
B.aaa authentication login default group tacacs+ local
C.aaa authentication login default group tacacs+ enable
D.aaa authentication login default local group tacacs+
AnswerB

This command configures AAA authentication for login to first use TACACS+ group and then fall back to the local database if the TACACS+ servers are unreachable. The order of methods is important: group tacacs+ is tried first, then local. This meets the requirement of fallback to local authentication.

Why this answer

The correct command is aaa authentication login default group tacacs+ local. This configures the router to attempt authentication via TACACS+ first, and if the TACACS+ server is unreachable, it falls back to the local username database. The order of methods is critical: the first method is tried, and subsequent methods are used only if the previous method fails or is unreachable.

Exam trap

The trap here is reversing the order of authentication methods, which would cause the router to use local authentication first and never query TACACS+ unless local fails.

364
MCQeasy

What is the default uRPF mode when 'ipv6 verify unicast source reachable-via' is configured without any keyword?

A.Loose mode (any)
B.Strict mode (rx)
C.No uRPF is applied
D.Only default routes are allowed
AnswerB

Configuring ipv6 verify unicast source reachable-via without a keyword enables strict mode, equivalent to the rx keyword. The router checks that the source is reachable via the same interface the packet arrived on, dropping packets that fail this reverse-path check.

Why this answer

When 'ipv6 verify unicast source reachable-via' is configured without any keyword, the default mode is strict (rx). In strict mode, the router checks that the source address of an incoming IPv6 packet is reachable via the exact interface on which the packet was received, using the FIB. This prevents source address spoofing by ensuring the return path matches the ingress interface.

Exam trap

Cisco often tests the default behavior of commands without keywords, and the trap here is that candidates mistakenly assume 'ipv6 verify unicast source reachable-via' defaults to loose mode or requires an explicit keyword to enable uRPF, when in fact strict mode is the default.

How to eliminate wrong answers

Option A is wrong because loose mode (any) requires the explicit 'any' keyword; without it, the default is strict, not loose. Option C is wrong because the command explicitly applies uRPF; omitting a keyword does not disable uRPF but defaults to strict mode. Option D is wrong because uRPF strict mode does not allow only default routes; it checks reachability via the FIB for any route, not just default routes.

365
MCQhard

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent through the tunnel, while all other traffic is sent unencrypted. The engineer creates an extended ACL named VPN_TRAFFIC and applies it to the crypto map. However, after testing, the engineer finds that traffic from 192.168.1.0/24 is not being encrypted. Which action should the engineer take to correct the issue?

A.Apply the ACL to the outside interface with 'ip access-group VPN_TRAFFIC out'.
B.Ensure the ACL permits traffic from 192.168.1.0/24 to the remote subnet, and that the crypto map references this ACL.
C.Enable 'crypto ipsec transform-set' with the correct encapsulation mode.
D.Configure a route map to match the traffic and apply it to the crypto map.
AnswerB

For IPsec to encrypt traffic, the ACL used in the crypto map must permit the interesting traffic. If the ACL does not permit traffic from 192.168.1.0/24 to the remote subnet, the router will not encrypt it. The engineer must verify that the ACL entries match the source and destination subnets and that the crypto map correctly references the ACL.

Why this answer

The crypto map uses an extended ACL to identify interesting traffic that should be encrypted. If the ACL does not permit traffic from 192.168.1.0/24 to the remote subnet, that traffic will not be encrypted. The engineer must ensure the ACL entries match the desired source and destination and that the crypto map references the correct ACL.

This is a common misconfiguration when defining VPN traffic.

Exam trap

The trap here is confusing the ACL used for crypto map interesting traffic with an interface ACL, leading to applying the ACL to an interface instead of ensuring it is correctly referenced in the crypto map.

366
MCQhard

A network engineer configures EEM to monitor BGP prefix limits on R1. R1 has: event manager applet BGP-PREFIX event syslog pattern "%BGP-3-PREFIX_LIMIT" action 1.0 cli command "enable" action 2.0 cli command "clear ip bgp 10.1.1.2" action 3.0 syslog msg "Cleared BGP session". Router R2 shows: BGP session with R1 is flapping, and logs show repeated prefix limit warnings. What is the root cause?

A.The EEM applet clears the BGP session, which resets the prefix count but does not prevent the neighbor from re-sending the same prefixes.
B.The syslog pattern is incorrect; it should be %BGP-4-PREFIX_LIMIT.
C.The clear command should be 'clear ip bgp *' to reset all sessions.
D.The BGP session is flapping due to a keepalive timer mismatch.
AnswerA

The applet reacts to the prefix-limit syslog by clearing the BGP session, which resets the prefix counter but leaves the underlying cause untouched. R2 immediately re-advertises the same prefixes, so the limit is exceeded again and the session flaps repeatedly.

Why this answer

The EEM applet is triggered by the %BGP-3-PREFIX_LIMIT syslog message and responds by clearing the BGP session with the neighbor. Clearing the session resets the prefix counter, but the neighbor immediately re-establishes the session and re-advertises the same set of prefixes, which again exceeds the configured maximum-prefix limit. This creates an endless flap loop rather than solving the underlying issue of too many prefixes being advertised.

Exam trap

The trap here is assuming that clearing the BGP session 'fixes' the prefix-limit violation, when in fact it only resets the counter and the neighbor immediately re-sends the same prefixes, causing a persistent flap loop.

How to eliminate wrong answers

Option B is wrong because the syslog pattern %BGP-3-PREFIX_LIMIT is the correct facility/severity format for the maximum-prefix warning; changing the severity digit to 4 would not match the actual message and would prevent the applet from triggering. Option C is wrong because 'clear ip bgp *' would reset all BGP sessions on the router, which is broader than needed and still does not prevent the neighbor from re-sending the same prefixes. Option D is wrong because a keepalive timer mismatch would produce different log messages (e.g., hold timer expired) and would not be correlated with repeated prefix-limit warnings.

367
MCQhard

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. The engineer also wants to use a pre-shared key for authentication. Which configuration element is required to define the interesting traffic?

A.access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
B.crypto isakmp policy 10 authentication pre-share
C.crypto map MYMAP 10 ipsec-isakmp set peer 203.0.113.2 set transform-set MYSET match address 101
D.crypto ipsec transform-set MYSET esp-aes esp-sha-hmac
AnswerA

The extended ACL defines the interesting traffic that should be encrypted by the IPsec VPN. In this case, it permits IP traffic from 10.1.1.0/24 to 10.2.2.0/24. This ACL is then referenced in the crypto map with 'match address 101'. Without this ACL, the router would not know which traffic to encrypt, making it the essential element for defining interesting traffic.

Why this answer

The interesting traffic is defined by an extended ACL that matches the source and destination subnets. This ACL is then referenced in the crypto map using the 'match address' command. The ACL specifies which packets are encrypted and sent through the VPN tunnel, while all other traffic is sent unencrypted.

The other options are part of the IPsec configuration but do not define the traffic to be encrypted.

Exam trap

The trap here is confusing the crypto map's 'match address' command with the ACL itself; the ACL is the actual definition of interesting traffic.

368
MCQmedium

Consider the following configuration on router R1: crypto isakmp policy 10 encryption aes 256 authentication pre-share group 14 lifetime 86400 ! crypto isakmp key cisco123 address 192.168.1.2 ! crypto ipsec transform-set TSET esp-aes 256 esp-sha-hmac mode tunnel ! crypto map CMAP 10 ipsec-isakmp set peer 192.168.1.2 set transform-set TSET match address 101 ! interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 crypto map CMAP ! access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255 If the remote peer has an ISAKMP policy with encryption 3des, what will happen?

A.The tunnel will use 3DES because the remote peer's policy is accepted.
B.IKE phase 1 will fail due to encryption algorithm mismatch.
C.The router will automatically adjust to use 3DES.
D.The tunnel will establish but use AES 256 anyway.
AnswerB

IKE phase 1 requires both peers to agree on the encryption algorithm within their ISAKMP policies. R1 offers aes 256 while the remote peer offers 3des only, so no matching proposal exists and main mode negotiation fails.

Why this answer

IKE phase 1 requires both peers to have a matching ISAKMP policy, including the encryption algorithm. Since R1 is configured with AES 256 and the remote peer uses 3DES, there is no common proposal, causing phase 1 to fail. Cisco IOS does not automatically negotiate or fall back to a different encryption algorithm; the mismatch results in a failed IKE SA.

Exam trap

Cisco often tests the misconception that IKE will automatically negotiate or fall back to a weaker algorithm, but in reality, IKE phase 1 requires an exact match of all policy parameters, and a mismatch causes the entire VPN to fail.

How to eliminate wrong answers

Option A is wrong because IKE phase 1 does not simply accept the remote peer's policy; both peers must have a matching proposal, and a mismatch causes failure. Option C is wrong because Cisco IOS does not automatically adjust encryption algorithms; each peer must have a compatible policy configured. Option D is wrong because the tunnel cannot establish if IKE phase 1 fails; no IPsec SA can be created without a successful IKE SA.

369
MCQmedium

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 10.3.3.0/24 BGP routing table entry for 10.3.3.0/24, version 10 Paths: (2 available, best #2, table default) Advertised to update-groups: 1 Refresh Epoch 1 65003 65004 10.1.13.3 from 10.1.13.3 (10.3.3.3) Origin IGP, metric 0, localpref 100, valid, external rx pathid: 0, tx pathid: 0 Refresh Epoch 1 65005 10.1.15.5 from 10.1.15.5 (10.5.5.5) Origin IGP, metric 0, localpref 200, valid, external, best rx pathid: 0, tx pathid: 0x0 Based on this output, why is the path via 10.1.15.5 chosen as best?

A.Because it has a shorter AS path (65005 vs 65003 65004).
B.Because it has a higher local preference of 200.
C.Because it has a lower metric (0 vs 0).
D.Because it was learned from a lower neighbor IP address.
AnswerB

BGP best-path selection compares local preference before AS path length, so the higher value wins. The path via 10.1.15.5 carries localpref 200 against 100 for the 65003 65004 path, making it best despite the longer AS path, which would only matter at a later tie-break step.

Why this answer

BGP best path selection prefers the path with the highest local preference value. In the output, the path via 10.1.15.5 has a local preference of 200, while the path via 10.1.13.3 has 100. Since local preference is evaluated before AS path length, the higher local preference wins, making the 10.1.15.5 path best.

Exam trap

The 300-410 exam often tests the order of BGP best path selection, and candidates may incorrectly choose AS path length as the first criterion, forgetting that local preference is evaluated earlier.

How to eliminate wrong answers

Option A is wrong because although the path via 10.1.15.5 has a shorter AS path (65005 vs 65003 65004), local preference is checked first in the BGP best path algorithm, so the higher local preference takes precedence. Option C is wrong because both paths have a metric of 0, so metric is not a differentiator. Option D is wrong because BGP does not use neighbor IP address as a tiebreaker in the best path selection process.

370
MCQeasy

According to Cisco IOS default behavior, if a router learns the same route via both RIP and OSPF, which route will be installed in the routing table?

A.The RIP route, because RIP has a lower metric.
B.The OSPF route, because OSPF has a lower administrative distance.
C.Both routes are installed, and load balancing occurs.
D.Neither route is installed; the router will use a default route.
AnswerB

Cisco IOS compares administrative distance before metric when selecting routes from different protocols. OSPF's default administrative distance of 110 is lower than RIP's 120, so the OSPF route wins and is installed in the routing table.

Why this answer

Cisco IOS selects routes based on administrative distance (AD) before metric when routes come from different routing protocols. OSPF has a default AD of 110, while RIP has a default AD of 120. Because lower AD is preferred, the OSPF route is installed in the routing table, even if RIP's metric is numerically lower.

Exam trap

300-410 often tests the misconception that lower metric wins across protocols; candidates forget that administrative distance is the first tiebreaker when routes come from different sources.

How to eliminate wrong answers

Option A is wrong because metric comparison only occurs within the same routing protocol; across protocols, administrative distance is the tiebreaker, and RIP's higher AD (120) loses to OSPF's 110. Option C is wrong because load balancing across different protocols with different ADs does not occur by default; only routes with equal AD and equal metric are load-balanced. Option D is wrong because the router will install the OSPF route, not fall back to a default route, since a valid route exists.

371
MCQmedium

Which statement correctly describes the behavior of ISATAP tunneling regarding host configuration?

A.ISATAP requires manual configuration of the entire IPv6 address on each host.
B.ISATAP uses the prefix 2002::/16 for global addresses.
C.ISATAP embeds the IPv4 address into the interface identifier (last 64 bits) of the IPv6 address.
D.ISATAP is only used for site-to-site tunnels.
AnswerC

ISATAP forms the interface identifier by encoding the host's IPv4 address in the low-order 32 bits, prefixed with 0000:5EFE, so the final 64 bits carry the IPv4 address, enabling automatic IPv6 address derivation across an IPv4-only underlay.

Why this answer

ISATAP (Intra-Site Automatic Tunnel Addressing Protocol) automatically generates the IPv6 address by embedding the host's IPv4 address into the interface identifier (the last 64 bits of the IPv6 address). This allows hosts to obtain a complete IPv6 address without manual configuration of the full 128-bit address, as the IPv4 address is used to form the unique interface ID. Option C correctly describes this behavior.

Exam trap

Cisco often tests the distinction between ISATAP and 6to4 tunneling, and the trap here is confusing the 2002::/16 prefix (used by 6to4) with ISATAP's use of a site-specific prefix and the embedded IPv4 address in the interface ID.

How to eliminate wrong answers

Option A is wrong because ISATAP does not require manual configuration of the entire IPv6 address; it automatically derives the interface identifier from the IPv4 address, and the prefix can be obtained via router discovery or DHCPv6. Option B is wrong because the prefix 2002::/16 is used by 6to4 tunneling, not ISATAP; ISATAP typically uses a site-specific unicast prefix (e.g., a global or unique local prefix) advertised by an ISATAP router. Option D is wrong because ISATAP is designed for host-to-router and host-to-host tunnels within a site, not exclusively for site-to-site tunnels; site-to-site tunnels are typically implemented with manual IPv6-in-IPv4 tunnels or GRE tunnels.

372
MCQmedium

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to ensure that packets are dropped if the source IP address is not reachable via the same interface they arrived on. The engineer configures 'ip verify unicast source reachable-via rx' on interface GigabitEthernet0/0. However, some legitimate traffic from a secondary path is being dropped. What is the most likely cause?

A.The interface must be configured with 'ip verify unicast source reachable-via any' to allow asymmetric routing.
B.The uRPF feature requires CEF to be enabled, and CEF is not enabled on the router.
C.The router uses loose uRPF, which only checks if the source is reachable via any interface, so it should not drop legitimate traffic.
D.The router uses strict uRPF, which requires the source to be reachable via the same interface; asymmetric routing causes legitimate packets to be dropped.
AnswerD

The 'reachable-via rx' option enables strict uRPF, which checks that the source IP is reachable via the same interface the packet arrived on. In asymmetric routing scenarios, where return traffic takes a different path, legitimate packets can be dropped. This is the most likely cause of the dropped traffic.

Why this answer

The 'reachable-via rx' option enables strict uRPF, which drops packets if the source IP is not reachable via the ingress interface. In networks with asymmetric routing, legitimate traffic may arrive on an interface that is not the best path back to the source, causing drops. Switching to loose uRPF ('reachable-via any') would alleviate this but reduce spoofing protection.

CEF is typically enabled by default, so it is not the issue.

Exam trap

The trap here is confusing strict and loose uRPF modes; 'rx' means strict, which is sensitive to asymmetric routing, while 'any' means loose.

373
Multi-Selecthard

Which TWO statements about the interaction between administrative distance and floating static routes are true? (Choose TWO.)

Select 2 answers
A.A floating static route must have an administrative distance higher than the primary route's AD to serve as a backup.
B.The default administrative distance for a static route is 0.
C.A floating static route will be installed in the routing table immediately after the primary route is removed, even if the next-hop is unreachable.
D.The 'ip route' command can be used to configure a floating static route by specifying an administrative distance value.
E.A floating static route can only be used with OSPF as the primary routing protocol.
AnswersA, D

A floating static route is deliberately given a higher administrative distance than the primary route, so it stays out of the routing table while the primary remains reachable and only installs when the primary fails. This satisfies the backup requirement in the stem.

Why this answer

Option A is correct because a floating static route is designed to stay out of the routing table while the primary route is active, so its administrative distance must be higher than the primary route's AD (for example, a static route with AD 200 backing up an OSPF route with AD 110). Option D is correct because the Cisco 'ip route' command accepts an optional administrative distance argument at the end of the syntax (e.g., 'ip route 192.168.2.0 255.255.255.0 10.1.1.2 200'), which is exactly how a floating static route is configured. Option B is incorrect because the default administrative distance for a static route is 1, not 0 (0 is used for directly connected interfaces).

Option C is incorrect because a route is only installed if its next hop is resolvable/reachable; an unreachable next hop prevents installation. Option E is incorrect because floating static routes can back up any routing protocol (OSPF, EIGRP, RIP, BGP, etc.) or even another static route, not just OSPF.

374
Multi-Selecthard

A network engineer is configuring MPLS Traffic Engineering (TE) with RSVP-TE on a Cisco IOS XE router to provide bandwidth guarantees for delay-sensitive traffic. The engineer must ensure that the TE tunnel can signal the required bandwidth and that the path is computed based on available resources. Which two statements about the configuration are true? (Choose two.)

Select 2 answers
A.The ip explicit-path command is used to define a dynamic path that can change based on network conditions.
B.The tunnel mpls traffic-eng bandwidth command specifies the bandwidth to be reserved for the TE tunnel.
C.The mpls traffic-eng tunnels command is only needed on the tunnel headend and not on transit routers.
D.The ip rsvp bandwidth command must be configured on each physical interface along the TE path to enable RSVP reservations.
E.The tunnel destination command is optional if the path is explicitly specified with a dynamic path option.
AnswersB, D

The tunnel mpls traffic-eng bandwidth command under the tunnel interface sets the bandwidth value that RSVP-TE signals along the path. This reservation ensures that the required resources are available on each link. Without it, the tunnel may not receive the necessary guarantees for delay-sensitive traffic, making it a critical configuration step.

Why this answer

To configure MPLS TE with RSVP-TE, the tunnel interface must have the bandwidth reservation set with tunnel mpls traffic-eng bandwidth, and each physical interface along the path must have RSVP enabled with ip rsvp bandwidth. These two steps ensure that the tunnel can signal its bandwidth requirements and that network resources are reserved. Other statements misrepresent the requirements for transit routers, destination configuration, or path types.

Exam trap

The trap here is assuming that RSVP or TE commands are only needed on the headend, or confusing explicit paths with dynamic path computation.

375
Drag & Dropmedium

Drag and drop the steps to verify and validate the MPLS L3VPN operational state into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Start by checking the VRF routing table with 'show ip route vrf <name>' to confirm CE routes are present. Then verify that VPNv4 routes are installed using 'show bgp vpnv4 unicast all'. Next, confirm the MPLS forwarding entry for a specific prefix with 'show mpls forwarding-table'.

After that, test end-to-end connectivity with a ping from the CE to a remote CE. Finally, validate that the label stack is correctly imposed using 'show ip cef vrf <name> <prefix>'.

Page 4

Page 5 of 19

Page 6