Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 376–450

1401 questions total · 19pages · All types, answers revealed

Page 5

Page 6 of 19

Page 7
376
MCQmedium

A network administrator is deploying DMVPN Phase 3 with IKEv2. The hub router is configured with a dynamic multipoint VPN tunnel and is using NHRP. Spoke routers are configured to register with the hub. After configuration, the administrator notices that spoke-to-spoke traffic is still going through the hub instead of directly between spokes. Which configuration change is most likely to resolve this issue?

A.Enable NHRP redirect on the hub and NHRP shortcut on the spokes.
B.Configure the hub as a route reflector for BGP.
C.Enable split horizon on the hub's tunnel interface.
D.Change the tunnel mode from GRE multipoint to GRE point-to-point.
AnswerA

In DMVPN Phase 3, NHRP redirect on the hub allows the hub to inform the spoke that a better path exists directly to another spoke. NHRP shortcut on the spokes allows them to install a direct route to the destination spoke based on the redirect message. Without these, spoke-to-spoke traffic will continue to traverse the hub even if a direct path is available. Enabling these features is essential for Phase 3 direct spoke-to-spoke communication.

Why this answer

DMVPN Phase 3 requires NHRP redirect on the hub and NHRP shortcut on the spokes to enable direct spoke-to-spoke communication. The hub uses NHRP redirect to inform a spoke that a more efficient path exists directly to another spoke. The spoke then uses NHRP shortcut to resolve the destination and establish a direct tunnel.

Without these, traffic will continue to flow through the hub.

Exam trap

The trap here is focusing on control plane routing protocols like BGP route reflection, while the issue is about NHRP data plane optimization.

377
MCQmedium

A network engineer is deploying an MPLS Layer 3 VPN for a customer. The customer requires that the provider edge (PE) routers support a unique route distinguisher (RD) per VRF and that the same customer routes be imported into multiple VRFs. Which configuration on the PE router accomplishes this requirement?

A.Configure a unique RD under each VRF and use route targets (RTs) to control import and export of routes between VRFs.
B.Configure a unique RD per VRF and use OSPF areas to import routes into multiple VRFs.
C.Configure the same RD for all VRFs and rely on BGP extended communities for route distribution.
D.Configure a unique RD per VRF and use BGP confederations to import routes into multiple VRFs.
AnswerA

A unique RD per VRF ensures that identical customer prefixes from different VRFs do not conflict in the MP-BGP table. Route targets then define which VRFs import or export those routes, allowing the same customer routes to be imported into multiple VRFs. This is the standard MPLS L3VPN design for overlapping address spaces and shared services.

Why this answer

A unique route distinguisher per VRF ensures that overlapping customer prefixes remain distinct in the MP-BGP VPNv4 table. Route targets, which are BGP extended communities, define import and export policies so that the same customer routes can be imported into multiple VRFs. This combination is the standard method for shared services and overlapping VPNs.

Exam trap

The trap here is confusing the role of the route distinguisher with that of the route target; the RD makes prefixes unique, while the RT controls import/export.

378
MCQhard

A network engineer is configuring a Cisco IOS XE router for MPLS Layer 3 VPN. The router is a PE connected to a CE via GigabitEthernet0/0. The engineer wants to configure a VRF named CUSTOMER_A and assign the interface to it. The engineer enters the following commands: `vrf definition CUSTOMER_A`, `rd 65000:1`, `address-family ipv4`, `exit`, `exit`. Then, under interface GigabitEthernet0/0, the engineer enters `vrf forwarding CUSTOMER_A`. After entering the command, the engineer notices that the IP address on the interface is removed. What is the most likely reason?

A.The VRF definition must include `address-family ipv4` before the interface can be assigned, and the missing address-family caused the IP removal.
B.The interface must be shut down before assigning it to a VRF, otherwise the IP address is cleared.
C.The VRF definition is missing the `route-target export` and `route-target import` commands.
D.The `vrf forwarding` command removes the IP address because the interface must be reconfigured with an IP address within the VRF.
AnswerD

When you assign an interface to a VRF using `vrf forwarding`, Cisco IOS removes any existing IP address configuration. This is expected behavior because the interface's IP address must be unique within the VRF's routing table. The engineer must re-enter the IP address after assigning the VRF. This is a common operational step that often surprises engineers.

Why this answer

Assigning an interface to a VRF with `vrf forwarding` removes the existing IP address. This is by design because the interface's IP address must be unique within the VRF. The engineer must reconfigure the IP address after the VRF assignment.

The other options describe unrelated VRF configuration steps or incorrect requirements.

Exam trap

The trap here is assuming that the IP address removal indicates a configuration error, when it is actually expected behavior when assigning an interface to a VRF.

379
MCQhard

An engineer configures ERSPAN on a Cisco router to send mirrored traffic to a remote collector via IP. The collector receives the ERSPAN packets, but the payload appears truncated or malformed. What is the most likely cause?

A.The ERSPAN GRE encapsulation adds overhead exceeding the path MTU, causing fragmentation or drop.
B.The collector is not configured to reassemble IP fragments.
C.The ERSPAN session is configured with the wrong source interface, causing incorrect IP headers.
D.The router has IPsec configured on the egress interface, encrypting the ERSPAN packets.
AnswerA

ERSPAN wraps the original frame in a GRE header plus a new IP header, enlarging each packet beyond the original frame size. If this exceeds the path MTU and fragmentation is blocked, the collector receives truncated or malformed payloads.

Why this answer

ERSPAN encapsulates mirrored packets in GRE with an additional ERSPAN header. The MTU of the path between the source and collector must accommodate the extra overhead (typically 50 bytes for GRE + ERSPAN). If the path MTU is too small, packets are fragmented or dropped, causing truncation.

380
MCQmedium

Which DHCPv4 option is used by a client to request a specific IP address in the DHCPREQUEST message?

A.Option 12 (Host Name)
B.Option 50 (Requested IP Address)
C.Option 54 (Server Identifier)
D.Option 51 (IP Address Lease Time)
AnswerB

Option 50 carries the Requested IP Address, letting a client ask the server for a specific address during DHCPREQUEST. This is precisely the field the question targets, distinct from Option 12 (hostname) and Option 54 (server identifier).

Why this answer

DHCPv4 Option 50 (Requested IP Address) is specifically used by a client in the DHCPREQUEST message to request a previously offered IP address or to attempt to renew a specific address. This option allows the client to indicate which IP address it wants to use, ensuring the server can confirm or deny the request based on availability and policy.

Exam trap

Cisco often tests the distinction between Option 50 (Requested IP Address) and Option 54 (Server Identifier), as candidates may confuse the client's request for a specific IP with the server identification used in unicast DHCPREQUEST messages during the selection phase.

How to eliminate wrong answers

Option A is wrong because Option 12 (Host Name) is used to convey the client's hostname to the DHCP server, not to request a specific IP address. Option C is wrong because Option 54 (Server Identifier) is used by the client to identify which DHCP server it is responding to, typically in a DHCPREQUEST sent during the selection phase, but it does not request a specific IP address. Option D is wrong because Option 51 (IP Address Lease Time) is used to request or specify the lease duration for an IP address, not to request a particular IP address itself.

381
MCQmedium

A network engineer runs the following command to troubleshoot DHCPv6 guard: R1# debug ipv6 dhcp guard *Mar 1 00:03:45.678: IPv6-DHCP-Guard: R1, Fa0/0, DHCPv6 SOLICIT from fe80::3, client DUID 00010001abcd1234 *Mar 1 00:03:45.678: IPv6-DHCP-Guard: R1, Fa0/0, DHCPv6 SOLICIT from fe80::3 is allowed by policy DHCP-POLICY *Mar 1 00:03:46.901: IPv6-DHCP-Guard: R1, Fa0/0, DHCPv6 ADVERTISE from fe80::4, server DUID 0001000156789012 *Mar 1 00:03:46.901: IPv6-DHCP-Guard: R1, Fa0/0, DHCPv6 ADVERTISE from fe80::4 is blocked by policy DHCP-POLICY What does this output indicate?

A.DHCPv6 guard is allowing client messages but blocking server messages from untrusted sources, preventing rogue DHCPv6 servers.
B.DHCPv6 guard is blocking all DHCPv6 messages, indicating a misconfiguration.
C.DHCPv6 guard is allowing all messages but logging them for analysis.
D.DHCPv6 guard is not configured; the debug output is from default DHCPv6 behavior.
AnswerA

DHCPv6 guard distinguishes message roles: SOLICIT from the client is permitted, while ADVERTISE from the server is dropped because Fa0/0 is configured as untrusted for server messages. This satisfies the stem's constraint of blocking rogue DHCPv6 servers while still allowing legitimate client requests through the same interface.

Why this answer

The debug output shows that DHCPv6 SOLICIT messages from client fe80::3 are allowed by policy DHCP-POLICY, while DHCPv6 ADVERTISE messages from server fe80::4 are blocked by the same policy. This is the expected behavior of DHCPv6 guard: it permits client messages (SOLICIT, REQUEST, etc.) to reach potential servers, but it blocks server messages (ADVERTISE, REPLY, etc.) from untrusted ports to prevent rogue DHCPv6 servers from assigning malicious configurations. Option A correctly identifies this selective filtering.

Exam trap

Cisco often tests the misconception that DHCPv6 guard blocks all DHCPv6 traffic, when in fact it only blocks server messages from untrusted sources, allowing client messages to pass through.

How to eliminate wrong answers

Option B is wrong because DHCPv6 guard is not blocking all messages; client SOLICIT messages are explicitly allowed, so the configuration is not misconfigured to block everything. Option C is wrong because the debug clearly shows messages are being allowed or blocked based on policy, not merely logged for analysis; DHCPv6 guard enforces actions, not just logging. Option D is wrong because DHCPv6 guard is configured and active (policy DHCP-POLICY is referenced), and the debug output is not from default behavior—default DHCPv6 guard would block all server messages from untrusted ports without a policy, but here a specific policy is applied.

382
MCQhard

An engineer configures an IPsec site-to-site VPN between two routers using iBGP for routing. The BGP session comes up, but routes learned from the remote site are not installed in the routing table. The engineer verifies that the IPsec tunnel is up and that the BGP prefixes are present in the BGP table. What is the most likely explanation?

A.The BGP synchronization rule is enabled, and the IGP does not carry the BGP routes, preventing installation.
B.The next-hop address for the BGP routes is the physical interface IP of the remote router, which is not reachable through the tunnel, so the route is not installed.
C.The IPsec transform set uses SHA-2 authentication, which is incompatible with BGP MD5 authentication.
D.The BGP session is using loopback interfaces, and the IPsec tunnel is not configured to encrypt traffic to the loopback.
AnswerB

iBGP does not change the next hop by default. If the BGP session is over the tunnel, but the next hop is the physical IP, the router cannot reach it unless the IGP or a static route points to the tunnel. The fix is to use next-hop-self on the neighbor.

Why this answer

In iBGP, the next-hop for routes learned from an eBGP peer is not changed by default. When the remote router advertises prefixes, it sets the next-hop to its physical interface IP address. If the IPsec tunnel is configured to encrypt traffic between the two routers' tunnel endpoints (e.g., virtual tunnel interfaces or crypto maps applied to physical interfaces), the physical interface IP of the remote router may not be reachable through the tunnel.

BGP will not install a route in the routing table if the next-hop is not reachable via a valid route in the routing table, even if the BGP session is up and the prefixes are in the BGP table.

Exam trap

Cisco often tests the concept that BGP route installation depends on next-hop reachability, and candidates mistakenly assume that a working BGP session and IPsec tunnel guarantee route installation, ignoring the need for the next-hop to be reachable via the routing table.

How to eliminate wrong answers

Option A is wrong because BGP synchronization is a Cisco IOS default that requires the IGP to carry the same prefix before BGP installs it, but this rule is disabled by default in modern IOS versions and is not the most likely cause when the next-hop is unreachable. Option C is wrong because IPsec transform set authentication (SHA-2) and BGP MD5 authentication are independent mechanisms; SHA-2 is used for IPsec packet integrity, while MD5 is used for BGP TCP session authentication, and they do not conflict. Option D is wrong because using loopback interfaces for the BGP session does not inherently prevent route installation; the IPsec tunnel can be configured to encrypt traffic to loopback addresses, and the issue is specifically about next-hop reachability, not the BGP session source/destination.

383
Drag & Dropmedium

Drag and drop the steps to verify and validate Device Access Control operational state into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, check the AAA server reachability to ensure the backend is accessible. Then verify the active authentication method list applied globally. Next, confirm the authorization method list for exec or commands.

After that, validate the accounting configuration to track access. Finally, test the actual access control by attempting a remote login.

384
MCQmedium

An engineer configures NAT on a router with 'ip nat inside source list 1 interface GigabitEthernet0/0 overload'. The inside hosts are 10.0.0.0/24, and the outside interface is 203.0.113.1. Traffic works for most hosts, but one host at 10.0.0.50 cannot access the internet. 'Show ip nat translations' shows no entry for this host. 'Show access-lists' shows ACL 1 permits 10.0.0.0 0.0.0.255. What is the most likely cause?

A.The host's IP address is statically assigned and conflicts with another device.
B.The host has a misconfigured subnet mask or default gateway.
C.The NAT pool is exhausted.
D.The router's inside interface is administratively down.
AnswerB

The correct answer. If the host's subnet mask is incorrect, it may compute that the router's inside interface is not on the same subnet, and therefore not use it as the next hop; instead, it will ARP for the destination IP directly. Alternatively, if the default gateway is misconfigured (or missing), all out-of-subnet traffic is sent to the wrong device or dropped locally. In either case, the packets never reach the router's inside interface, so the router's NAT process never sees the traffic and creates no translation entry.

Why this answer

The host at 10.0.0.50 is within the ACL 1 permitted range, yet no NAT translation appears, indicating the traffic never reaches the NAT process. A misconfigured subnet mask or default gateway on the host would cause its packets to be sent to the wrong next-hop or be dropped locally, preventing the router from seeing the traffic and creating a translation. Since 'show ip nat translations' shows no entry, the issue is upstream of NAT, pointing to a host-side configuration problem.

Exam trap

Cisco often tests the misconception that a missing NAT translation automatically implies a NAT configuration or ACL issue, when in fact the root cause is often a host-side misconfiguration that prevents traffic from reaching the router in the first place.

How to eliminate wrong answers

Option A is wrong because a static IP conflict would cause intermittent connectivity or duplicate IP errors, but the host would still generate traffic that the router would attempt to translate, resulting in at least a partial NAT entry or ARP issues, not a complete absence of translations. Option C is wrong because the NAT pool is not exhausted; the configuration uses PAT (overload) with a single outside interface IP (203.0.113.1), which supports up to 65,535 simultaneous translations per IP, so exhaustion is highly unlikely with a /24 subnet. Option D is wrong because if the router's inside interface were administratively down, no hosts on the 10.0.0.0/24 network would have internet access, but the question states traffic works for most hosts, ruling out a down interface.

385
MCQeasy

What is the default CoPP policer action for packets that exceed the committed information rate (CIR)?

A.Transmit with best-effort
B.Drop
C.Set DSCP to 0
D.Queue for later transmission
AnswerB

CoPP policers are configured with a committed information rate and an associated exceed action; the default exceed action is drop, so traffic above the CIR is discarded rather than marked or transmitted. This satisfies the stem's requirement for the default behaviour.

Why this answer

The default action for a Control Plane Policing (CoPP) policy-map class when traffic exceeds the committed information rate (CIR) is to drop the excess packets. This is because CoPP uses a single-rate, two-color policer by default, where packets conforming to the CIR are marked as 'conform' and transmitted, while packets exceeding the CIR are marked as 'exceed' and dropped. No default 'violate' action exists unless explicitly configured.

Exam trap

Cisco often tests the misconception that CoPP defaults to 'transmit' or 'remark' for excess traffic, but the default exceed action is always 'drop' unless explicitly changed in the policy-map.

How to eliminate wrong answers

Option A is wrong because CoPP does not have a default 'transmit with best-effort' action for excess traffic; that would require an explicit 'transmit' action under the 'exceed' or 'violate' clause in the policy-map. Option C is wrong because setting DSCP to 0 is not a default policer action; it would require an explicit 'set dscp 0' command under the exceed action, and CoPP defaults to drop, not remark. Option D is wrong because CoPP does not queue packets for later transmission; policing is a dropping or remarking mechanism, not a queuing or shaping function.

386
Drag & Drophard

Drag and drop the steps to troubleshoot Device Management adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Troubleshooting starts with checking basic IP connectivity, then verifying the management protocol (e.g., NETCONF/RESTCONF) status, ensuring the correct port is open, checking AAA/authorization, and finally reviewing logs for errors.

387
MCQhard

A network engineer runs the following command on Router R1: R1# show ip eigrp topology 10.50.50.0/24 EIGRP-IPv4 Topology Entry for AS(100)/ID(192.168.1.1) for 10.50.50.0/24 State: Active, Reply status: 0, Originating router: 192.168.1.1 Routing Descriptor Blocks: 10.1.1.2 (GigabitEthernet0/0), from 10.1.1.2, Send flag: 0x0 Composite metric: (4294967295/4294967295), Route is Internal Vector metric: Minimum bandwidth: 100000 Kbit Total delay: 100 microseconds Reliability: 255/255 Load: 1/255 Minimum MTU: 1500 Hop count: 1 Based on this output, what is the problem?

A.The route is in Active state with an infinite metric, indicating that the router has lost the route and is querying for a new path.
B.The route is passive and stable.
C.The metric of 4294967295 is normal for a summary route.
D.The hop count of 1 indicates the route is one hop away and reachable.
AnswerA

The Active state combined with the composite metric of 4294967295 (infinity) confirms R1 has lost its feasible successor and is awaiting replies to EIGRP queries. The zero Reply status shows no outstanding replies yet, so the route remains stuck in Active until neighbours respond or the stuck-in-active timer expires.

Why this answer

The route is in Active state with a composite metric of 4294967295 (the maximum 32-bit value, effectively infinite), which indicates that the router has lost the feasible successor and is actively sending queries to neighbors to find an alternative path. This is a classic sign of an EIGRP query process in progress, meaning the route is not stable or reachable.

Exam trap

Cisco often tests the misconception that a route in Active state with a high metric is still reachable or that the metric value is normal, when in fact the Active state and infinite metric together indicate a route that is being actively queried and is currently unreachable.

How to eliminate wrong answers

Option B is wrong because the route is in Active state, not Passive; a Passive state would indicate stability and convergence. Option C is wrong because a metric of 4294967295 is not normal for any route—it represents an infinite metric (unreachable) in EIGRP, not a summary route. Option D is wrong because a hop count of 1 does not guarantee reachability when the metric is infinite; the route is in Active state and the router is still querying for a valid path.

388
MCQhard

A network administrator is troubleshooting an EIGRP adjacency that is stuck in the ACTIVE state. The adjacency is between two routers, R1 and R2, on a point-to-point link. The administrator notices that R1 is sending queries but not receiving replies. Which of the following is the most likely cause?

A.A stuck-in-active condition is caused by a router not receiving replies to its queries, often due to a unidirectional link or a neighbor that is unable to respond.
B.The autonomous system number is misconfigured on R1.
C.An access list is blocking EIGRP multicast packets on R2's interface.
D.The K values for EIGRP metric calculation are mismatched between R1 and R2.
AnswerA

The ACTIVE state in EIGRP indicates that a route has been lost and the router is actively querying its neighbors for an alternative path. If replies are not received within the active timer (default 3 minutes), the route becomes stuck-in-active. Common causes include unidirectional links, packet loss, or a neighbor that is too busy to respond. In this scenario, R1 is sending queries but not receiving replies, which aligns with a unidirectional link or a neighbor issue.

Why this answer

EIGRP routers enter the ACTIVE state when they lose a route and must query neighbors for an alternative path. If a neighbor does not respond to queries, the route can become stuck-in-active. This is often due to unidirectional link failures, high CPU on the neighbor, or packet filters that allow hellos but block other EIGRP packets.

The symptom of queries being sent but no replies received points directly to a communication issue in one direction.

Exam trap

The trap here is assuming that any EIGRP adjacency issue is due to mismatched parameters like AS number or K values, but those would prevent adjacency formation, not cause a stuck-in-active state.

389
Multi-Selectmedium

Which TWO commands can be used to verify OSPFv2 path selection and cost metrics on a Cisco IOS router? (Choose TWO.)

Select 2 answers
A.show ip ospf interface
B.show ip route ospf
C.show ip ospf neighbor
D.traceroute
E.show ip protocols
AnswersA, B

The show ip ospf interface command displays each interface's OSPF area, cost, timers, and neighbour count, directly revealing the cost metric used in path selection. It confirms the configured or default bandwidth-derived cost per link.

Why this answer

Option A, 'show ip ospf interface', is correct because it displays per-interface OSPFv2 parameters including the interface cost, network type, hello/dead timers, and area, which directly verifies the cost metrics that drive OSPF path selection. Option B, 'show ip route ospf', is correct because it shows the OSPF-learned routes installed in the routing table along with their metric (cost) and next-hop, confirming which paths OSPF selected. Option C, 'show ip ospf neighbor', only verifies adjacency states and neighbor IDs, not path selection or cost.

Option D, 'traceroute', shows the forwarding path taken by packets but does not reveal OSPF cost values or OSPF's internal selection logic. Option E, 'show ip protocols', displays routing protocol parameters such as timers, networks, and administrative distance, but not OSPF interface costs or the resulting OSPF route selection.

Exam trap

The trap is confusing neighbor verification with path verification — candidates pick `show ip ospf neighbor` because it is OSPF-specific, but it does not reveal cost metrics or route selection, which require interface and routing table commands.

390
MCQmedium

A network engineer runs the following command to troubleshoot OSPF route propagation: R1# show ip ospf database router 2.2.2.2 OSPF Router with ID (1.1.1.1) (Process ID 1) Router Link States (Area 0) LS age: 45 Options: (No TOS-capability, DC) LS Type: Router Links Link State ID: 2.2.2.2 Advertising Router: 2.2.2.2 LS Seq Number: 80000005 Checksum: 0x1234 Length: 48 Number of Links: 2 Link connected to: a Transit Network (Link ID) Designated Router address: 10.1.1.2 (Link Data) Router Interface address: 10.1.1.2 Number of TOS metrics: 0 TOS 0 Metrics: 10 Link connected to: a Stub Network (Link ID) Network/subnet number: 192.168.1.0 (Link Data) Network Mask: 255.255.255.0 Number of TOS metrics: 0 TOS 0 Metrics: 10 What does this output indicate?

A.Router 2.2.2.2 is advertising two stub networks.
B.Router 2.2.2.2 has a link to a transit network with DR address 10.1.1.2 and a stub network 192.168.1.0/24.
C.The LSA indicates a Type 5 External LSA from ASBR.
D.The output shows the network LSA for the transit network.
AnswerB

The Router Link States entry for 2.2.2.2 lists two links: one to a transit network whose Designated Router address is 10.1.1.2, and one stub network with subnet 192.168.1.0 and mask 255.255.255.0, confirming both link types.

Why this answer

The output shows a Router LSA (Type 1) for Router ID 2.2.2.2. It lists two links: one connected to a Transit Network with Designated Router address 10.1.1.2, and one connected to a Stub Network with network 192.168.1.0/24. This matches option B.

The LSA is not a Type 5 External LSA (which would be shown differently) nor a Network LSA (Type 2). The router is advertising its links, not two stub networks (only one stub network is listed).

Exam trap

300-410 often tests the ability to interpret OSPF database output. Candidates may confuse Router LSA with Network LSA or misread the link types. The trap is assuming that any link with a network address is a stub network, ignoring the transit network designation.

How to eliminate wrong answers

Option A is wrong because the output shows one stub network and one transit network, not two stub networks. Option C is wrong because Type 5 External LSAs are not shown in the 'show ip ospf database router' command; they appear under 'show ip ospf database external'. Option D is wrong because the output is a Router LSA (Type 1), not a Network LSA (Type 2), which would be displayed with 'show ip ospf database network'.

391
MCQeasy

A network administrator is configuring a Cisco IOS XE router to act as a DHCP relay agent. The router is connected to a client subnet on GigabitEthernet0/0 and to a DHCP server at 192.168.1.100 on GigabitEthernet0/1. The administrator enters the command 'ip helper-address 192.168.1.100' on GigabitEthernet0/0. Which statement is true about the behavior of this configuration?

A.The router will forward DHCP requests from clients to the DHCP server, and the server will reply directly to the clients.
B.The router will forward DHCP requests from clients to the DHCP server, but the server will not be able to assign an address because the router does not have a route to the client subnet.
C.The router will drop DHCP requests because it is not configured as a DHCP server.
D.The router will forward DHCP requests from clients to the DHCP server, and the server will reply to the router, which then forwards the reply to the clients.
AnswerD

This is the correct behavior of a DHCP relay agent. The router receives the DHCP discover message from the client, inserts the giaddr (the router's interface IP on the client subnet), and forwards it to the DHCP server. The server uses the giaddr to determine the correct subnet and sends the DHCP offer back to the router's giaddr. The router then forwards the offer to the client. This process is defined in RFC 2131 and is essential for DHCP to work across subnets.

Why this answer

When a Cisco IOS XE router is configured with 'ip helper-address', it acts as a DHCP relay agent. It forwards DHCP discover messages from clients to the specified DHCP server, inserting its own interface IP address as the giaddr. The DHCP server uses the giaddr to select the correct address pool and sends the DHCP offer back to the relay agent.

The relay agent then forwards the offer to the client. This allows DHCP to function across subnets without requiring a DHCP server on every subnet.

Exam trap

The trap here is assuming that the DHCP server replies directly to the client, which is not possible because the client does not yet have an IP address.

392
MCQmedium

A network administrator is deploying a DMVPN Phase 3 hub-and-spoke topology. Spokes must be able to communicate directly with each other without traffic traversing the hub. The administrator has configured NHRP and IPsec on all routers. Which additional configuration is required on the hub to enable direct spoke-to-spoke communication?

A.Enable NHRP shortcut on the hub.
B.Set the tunnel mode to multipoint GRE on the hub.
C.Enable NHRP redirect on the hub.
D.Configure the hub as a route reflector for BGP.
AnswerC

NHRP redirect is essential for DMVPN Phase 3. When the hub receives a packet from one spoke destined to another spoke, it sends an NHRP redirect message to the source spoke, informing it of a better path. The source spoke then initiates an NHRP resolution for the destination spoke's tunnel IP, allowing direct spoke-to-spoke tunnel establishment. Without NHRP redirect, spokes continue sending traffic through the hub even if a direct path exists.

Why this answer

In DMVPN Phase 3, direct spoke-to-spoke communication is achieved by combining NHRP redirect on the hub and NHRP shortcut on the spokes. The hub uses NHRP redirect to inform a spoke that a better path exists to another spoke. The spoke then uses NHRP shortcut to resolve the destination and build a direct tunnel.

Without redirect on the hub, spokes never learn about the direct path and continue to forward traffic through the hub, defeating the purpose of Phase 3.

Exam trap

The trap here is confusing NHRP redirect and NHRP shortcut, placing shortcut on the hub instead of the spokes.

393
Multi-Selecthard

A network administrator is troubleshooting a DMVPN Phase 3 deployment using mGRE and IPsec. Spoke-to-spoke communication is not working directly; traffic is flowing through the hub. The administrator verifies that NHRP registrations are successful and that the hub has a route to all spokes. Which two actions are required to enable direct spoke-to-spoke communication? (Choose two.)

Select 2 answers
A.Configure 'ip nhrp network-id' on all tunnel interfaces.
B.Configure 'ip nhrp shortcut' on the spoke tunnel interfaces.
C.Configure 'ip nhrp redirect' on the hub tunnel interface.
D.Configure 'ip nhrp shortcut' on the hub tunnel interface.
E.Configure 'ip nhrp map' entries for all remote spokes on each spoke.
AnswersB, C

On spoke routers in DMVPN Phase 3, 'ip nhrp shortcut' must be enabled to allow the spoke to install a shortcut route to the destination spoke when it receives an NHRP redirect from the hub. This command enables the spoke to override its default routing and send traffic directly to the destination spoke's NBMA address. Without it, the spoke ignores the redirect and continues to forward traffic through the hub.

Why this answer

DMVPN Phase 3 requires 'ip nhrp redirect' on the hub and 'ip nhrp shortcut' on the spokes to enable direct spoke-to-spoke tunnels. The hub uses redirect to inform the originating spoke of a better path, and the spoke uses shortcut to act on that information and establish a direct tunnel to the destination spoke. Without both, traffic continues to flow through the hub.

Exam trap

The trap here is confusing where to place 'ip nhrp shortcut' and 'ip nhrp redirect'; the redirect goes on the hub, while the shortcut goes on the spokes.

394
MCQeasy

A network engineer is configuring a Cisco IOS router to act as a DHCP relay agent. The router receives DHCP discover messages on interface GigabitEthernet0/1 and must forward them to a DHCP server at 10.1.1.100. Which command is required on the router?

A.ip dhcp relay 10.1.1.100
B.ip forward-protocol udp 67
C.ip helper-address 10.1.1.100
D.ip dhcp server 10.1.1.100
AnswerC

The ip helper-address command is configured on the interface receiving the DHCP broadcasts. It causes the router to forward UDP broadcasts for specific ports, including DHCP, to the specified server. This is the correct and standard way to configure a DHCP relay agent on Cisco IOS. Without it, DHCP discover messages would not reach the server.

Why this answer

To configure a Cisco IOS router as a DHCP relay agent, the ip helper-address command must be applied to the interface where DHCP broadcasts are received. This command forwards the broadcasts as unicast packets to the specified DHCP server. It is the standard and required configuration for this functionality.

Exam trap

The trap here is thinking that a global command like ip forward-protocol udp 67 is sufficient, when the interface-level ip helper-address is what actually directs DHCP requests to a specific server.

395
Multi-Selecthard

A network engineer is deploying MPLS Layer 3 VPNs on Cisco IOS routers. The engineer must ensure that customer routes are properly propagated across the MPLS core and that labels are correctly assigned. Which two protocols are used within the MPLS core to distribute labels and VPNv4 routes? (Choose two.)

Select 2 answers
A.LDP
B.RSVP
C.MP-BGP
D.OSPF
E.BGP-LU
AnswersA, C

LDP (Label Distribution Protocol) is used to distribute labels for internal routes within the MPLS core. It maps IP prefixes to labels, enabling label switching for core routing. In an MPLS L3VPN, LDP is responsible for establishing label-switched paths (LSPs) between PE routers, which is essential for forwarding VPN traffic across the core.

Why this answer

In an MPLS L3VPN, LDP is used to distribute labels for core routing, creating LSPs between PE routers. MP-BGP is used to distribute VPNv4 routes and their associated VPN labels between PE routers. Together, they enable the forwarding of customer traffic across the MPLS core with proper VPN isolation.

OSPF, RSVP, and BGP-LU are not the standard protocols for these specific functions.

Exam trap

The trap here is assuming that any routing protocol that distributes labels, such as RSVP or BGP-LU, is used in MPLS L3VPNs, when in fact LDP and MP-BGP are the standard protocols for label and VPN route distribution.

396
MCQeasy

Which command correctly configures a static route on a Cisco IOS router to reach the network 172.16.0.0/16 via the next-hop address 10.1.1.1?

A.ip route 172.16.0.0 255.255.0.0 interface GigabitEthernet0/0
B.ip route 172.16.0.0 255.255.255.0 10.1.1.1
C.ip route 172.16.0.0/16 10.1.1.1
D.ip route 172.16.0.0 255.255.0.0 10.1.1.1
AnswerD

This command uses the correct syntax for a static route: 'ip route' followed by the destination network, subnet mask, and next-hop address. The subnet mask 255.255.0.0 corresponds to a /16 prefix length, matching the 172.16.0.0/16 network. This is the standard way to configure an IPv4 static route on Cisco IOS.

Why this answer

The correct command is 'ip route 172.16.0.0 255.255.0.0 10.1.1.1'. It specifies the destination network with the proper subnet mask and the next-hop address. Cisco IOS requires the subnet mask in dotted-decimal format, not CIDR notation, and the next-hop address must be provided for a route via a next-hop.

Exam trap

The trap here is using CIDR notation or the wrong subnet mask, which are common mistakes when configuring static routes on Cisco IOS.

397
MCQhard

Examine this configuration on Router R6: router ospf 1 redistribute eigrp 100 subnets default-information originate always What is a likely problem with this configuration?

A.The 'default-information originate always' command is not allowed with redistribution.
B.The router will advertise a default route into OSPF even if it does not have a default route itself, potentially causing blackholing.
C.The 'subnets' keyword is missing for EIGRP redistribution.
D.The redistribution will only work if EIGRP routes have a metric set.
AnswerB

The always keyword forces OSPF to originate a default route unconditionally, even when no default route exists in the routing table. Traffic matching it is forwarded to a next hop that cannot deliver it, producing blackholing. Removing always would require an actual default route first.

Why this answer

The 'default-information originate always' keyword forces OSPF to originate a default route (0.0.0.0/0) into the OSPF domain unconditionally, regardless of whether the router actually has a default route in its routing table. Without the 'always' keyword, OSPF only advertises a default route if one already exists locally. Using 'always' can cause traffic to be forwarded toward R6 and then dropped (blackholed) because R6 has no valid default path.

Exam trap

The trap here is assuming that 'always' is required for the default route to be advertised, when in fact it removes the safety check that prevents advertising a default when none exists — the exact opposite of what most candidates assume.

How to eliminate wrong answers

Option A is wrong because 'default-information originate' is fully compatible with redistribution commands in OSPF; they are independent features. Option C is wrong because the 'subnets' keyword is already present in the redistribution statement ('redistribute eigrp 100 subnets'), so it is not missing. Option D is wrong because EIGRP-to-OSPF redistribution does not require a metric to be set on the OSPF side; OSPF uses default seed metrics (20 for redistributed routes, 1 for connected) unless a metric or metric-type is specified.

398
MCQmedium

A network engineer is configuring a branch router to obtain its WAN interface IPv4 address from an ISP using DHCP. The provider requires the router to send a specific client identifier. Which command must be applied under the interface configuration to meet this requirement?

A.ip dhcp client hostname BRANCH-ROUTER
B.ip dhcp client client-id ascii BRANCH-ROUTER
C.ip dhcp client request client-id
D.ip dhcp pool BRANCH-ROUTER
AnswerB

The ip dhcp client client-id ascii BRANCH-ROUTER command under the interface configuration sets the DHCP client identifier to the ASCII string BRANCH-ROUTER. This allows the ISP to identify the router uniquely, which is often required for address assignment or authentication. Other options either configure server-side parameters or use incorrect syntax for the client identifier.

Why this answer

The ip dhcp client client-id ascii BRANCH-ROUTER command correctly sets the DHCP client identifier to the ASCII string BRANCH-ROUTER. This is necessary when an ISP requires a specific client identifier for address assignment or authentication. The other options either configure server-side settings or request the identifier from the server, which does not meet the requirement.

Exam trap

The trap here is confusing the client identifier (option 61) with the hostname option (option 12), leading to the selection of ip dhcp client hostname instead of the correct client-id command.

399
MCQeasy

A network engineer runs the following command on Router R1: R1# show flow monitor FLOW-MONITOR-1 statistics Monitor: FLOW-MONITOR-1 Record: netflow-original Exporter: EXPORTER-1 Cache size: 1000 Current entries: 0 Flows exported: 0 Packets exported: 0 Sampler: Not configured Flow Monitor is not attached to any interface Based on this output, what action should the engineer take to resolve the issue?

A.Configure a sampler on the flow monitor.
B.Apply the flow monitor to an interface using the 'ip flow monitor FLOW-MONITOR-1 input' command.
C.Increase the cache size to 2000 entries.
D.Change the record type to netflow ipv4 original.
AnswerB

The statistics output states the flow monitor is not attached to any interface, so no packets are monitored or exported. Binding it with ip flow monitor FLOW-MONITOR-1 input on the relevant interface activates monitoring and populates the cache.

Why this answer

The output explicitly states 'Flow Monitor is not attached to any interface'. The solution is to apply the flow monitor to an interface using the 'ip flow monitor' command.

400
MCQhard

A network administrator is troubleshooting a route redistribution issue on a Cisco router running both EIGRP and OSPF. The router is redistributing EIGRP routes into OSPF, but the routes are not appearing in the OSPF domain. The administrator has configured redistribution with a seed metric of 20. Which additional configuration is required to ensure the routes are advertised?

A.Set the metric-type to 1 under the redistribute command.
B.Enable OSPF on the interface connecting to the EIGRP domain.
C.Configure a route map to match the EIGRP routes.
D.Configure the subnets keyword under the redistribute command.
AnswerD

When redistributing routes into OSPF, the subnets keyword is required to include subnetted routes. Without it, only classful networks are redistributed, so routes with subnet masks are not advertised. Since the scenario involves redistributing EIGRP routes, which are often subnetted, the subnets keyword ensures they are included in OSPF LSAs.

Why this answer

The subnets keyword is necessary when redistributing routes into OSPF to include subnetted routes. Without it, only classful networks are redistributed, which is why the EIGRP routes are missing. The seed metric alone does not ensure subnetted routes are advertised.

Metric-type and route maps are unrelated to this requirement.

Exam trap

The trap here is assuming that setting a seed metric is sufficient for redistribution, overlooking the need for the subnets keyword to handle subnetted routes.

401
Drag & Drophard

Drag and drop the steps for troubleshooting MPLS operations adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Start by verifying LDP neighbor state, then check interface MPLS enablement, inspect label bindings, test end-to-end LSP connectivity, and finally validate TTL propagation for troubleshooting.

402
MCQhard

A network engineer is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers. The tunnel fails to establish, and the engineer sees the debug output: 'ISAKMP: Unable to find a valid preshared key'. The engineer verifies that the preshared key is identical on both peers. Which additional configuration is most likely causing the issue?

A.The crypto isakmp key command is configured with the wrong peer address.
B.The crypto map is applied to the wrong interface.
C.The transform set is not configured with the correct encryption algorithm.
D.The ISAKMP policy priority numbers are different on the two peers.
AnswerA

If the preshared key is configured for a peer address that does not match the actual source IP of the remote peer, the router cannot find a valid key for that peer. This results in the 'Unable to find a valid preshared key' error even if the key string is correct. The engineer should verify that the peer address in the 'crypto isakmp key' command matches the remote peer's IP.

Why this answer

The error 'Unable to find a valid preshared key' typically occurs when the router cannot match the preshared key to the peer's IP address. This is often due to the 'crypto isakmp key' command specifying an incorrect peer address, even if the key string itself is correct.

Exam trap

The trap here is assuming that identical key strings are sufficient; the key must also be associated with the correct peer IP address.

403
MCQhard

EIGRP network with routers R1, R2, R3. R1 has: router eigrp 100 network 10.0.0.0 R2 has: router eigrp 100 network 10.0.0.0 R3 has: router eigrp 100 network 10.0.0.0 R1 shows: R1# show ip eigrp topology 10.1.1.0/24 EIGRP-IPv4 Topology Entry for 10.1.1.0/24 State is Passive, Query origin flag is 1, 1 Successor(s), FD is 128256 Routing Descriptor Blocks: 10.2.1.2 (Serial0/0/0), from 10.2.1.2, Send flag is 0x0 Composite metric is (128256/156160), Route is Internal 10.3.1.3 (Serial0/0/1), from 10.3.1.3, Send flag is 0x0 Composite metric is (156160/128256), Route is Internal R1# show ip route 10.1.1.0 Routing entry for 10.1.1.0/24 Known via "eigrp 100", distance 90, metric 128256 Last update from 10.2.1.2 on Serial0/0/0 An engineer expected R1 to use the path via 10.3.1.3 because it appears in the topology table, but R1 is using the path via 10.2.1.2. What is the reason?

A.The path with higher FD is not feasible; EIGRP always selects the lowest FD.
B.An offset-list is applied to the lower FD path, increasing its metric.
C.The route is in active state, causing EIGRP to use a backup path.
D.R1 has a distribute-list blocking the lower FD path.
AnswerA

Correct. EIGRP always selects the path with the lowest feasible distance as the successor. The higher FD path is not feasible as a successor because it has a higher metric. The show ip route output confirms the lower FD path is installed.

Why this answer

The show ip route output confirms that R1 installed the route via 10.2.1.2 with metric 128256, the lowest feasible distance. The path via 10.3.1.3 has a higher local metric (156160) and is not the successor. EIGRP always selects the route with the lowest FD, so the higher-FD path is not used.

Option A is correct.

Exam trap

Candidates may misread the show ip eigrp topology output and assume the path with higher metric is used, but the routing table shows the actual installed route. Always verify with show ip route.

404
Drag & Dropmedium

Drag and drop the steps to verify and validate IPv6 First Hop Security operational state into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Start by checking global IPv6 snooping status. Then display the binding table for learned entries. Verify interface-specific FHS policies.

Check the RA Guard policy counters for drops. Finally, validate the neighbor cache for correct MAC-to-IPv6 mappings.

405
Multi-Selectmedium

A network administrator is configuring a GRE tunnel between two Cisco IOS routers. The tunnel must support multicast traffic and be protected by IPsec. Which two statements about the configuration are true? (Choose two.)

Select 2 answers
A.The tunnel mode must be set to gre multipoint to support multicast.
B.The tunnel interface must be configured with a unique IP subnet that is not used elsewhere.
C.IPsec transport mode is required to encrypt the GRE traffic.
D.Multicast traffic is automatically encrypted by IPsec without additional configuration.
E.The tunnel source and destination must be reachable via the underlying physical interface.
AnswersB, E

A GRE tunnel interface requires an IP address and subnet to route traffic over the tunnel. This subnet should be unique and not overlap with other interfaces to avoid routing conflicts. It is typically a private subnet dedicated to the tunnel, allowing dynamic routing protocols to run over the tunnel and exchange routes between sites.

Why this answer

A GRE tunnel requires reachable source and destination addresses for the tunnel to become operational. Additionally, the tunnel interface needs a unique IP subnet to route traffic and run dynamic routing protocols. While IPsec can protect GRE traffic, it is not automatically encrypting multicast, and transport mode is not mandatory.

GRE multipoint is an option for hub-and-spoke but not a requirement for multicast support.

Exam trap

The trap here is assuming that IPsec automatically encrypts multicast traffic and that transport mode is always used with GRE.

406
MCQhard

A network engineer notices that BGP sessions between two directly connected routers are flapping every few minutes. The routers are running IOS-XE 17.3 and have CoPP enabled. The engineer checks the CoPP policy and sees a class-map matching BGP packets with a police rate of 8000 bps. The BGP session uses MD5 authentication and the routers exchange a full BGP table with 500,000 prefixes. What is the most likely cause of the BGP session flapping?

A.The BGP MD5 authentication is causing excessive CPU utilization, triggering CoPP drops.
B.The CoPP police rate of 8000 bps is too low for the BGP keepalive and update traffic, causing packet drops.
C.The CoPP class-map is not matching BGP packets correctly because it uses a wrong access-list.
D.The BGP hold timer is set too low, causing the session to reset before CoPP drops are noticed.
AnswerB

Policing at 8000 bps drops BGP keepalives and update packets once the full 500,000-prefix table and MD5-authenticated exchanges exceed that rate, causing hold-timer expiry and repeated session resets. Raising or exempting the BGP class restores stability.

Why this answer

The CoPP police rate of 8000 bps is insufficient for the BGP traffic generated by exchanging a full BGP table of 500,000 prefixes. BGP updates for such a large table can easily exceed 8000 bps, especially when combined with keepalive messages. When the police rate is exceeded, CoPP drops BGP packets, causing the session to flap as the hold timer expires due to missing keepalives or updates.

Exam trap

Cisco often tests the misconception that MD5 authentication causes CPU spikes leading to CoPP drops, but the real issue is that CoPP police rates must be sized to accommodate the actual BGP traffic volume, especially during full table exchanges.

How to eliminate wrong answers

Option A is wrong because BGP MD5 authentication adds a small amount of CPU overhead for HMAC computation, but it does not directly cause CoPP drops; CoPP drops are based on traffic rate, not CPU utilization. Option C is wrong because the question states that the class-map matches BGP packets, and there is no indication of a misconfigured access-list; the issue is the police rate, not the match criteria. Option D is wrong because the hold timer is not mentioned as being changed; the default hold timer (typically 180 seconds) is sufficient, and the flapping is due to CoPP dropping packets, not a low timer setting.

407
MCQhard

An engineer is troubleshooting an IPv6 connectivity issue where hosts on VLAN 10 cannot reach the internet. The switch is configured with IPv6 First Hop Security features including RA Guard and DHCPv6 Guard. The legitimate router is connected to port Gi1/0/1. The engineer notices that the router is sending RAs, but hosts are not receiving them. The switch shows that RA Guard is dropping packets on port Gi1/0/1. What is the most likely misconfiguration?

A.The RA Guard policy is configured with 'device-role host' on port Gi1/0/1, which causes the switch to drop all RAs received on that port.
B.DHCPv6 Guard is configured on port Gi1/0/1, blocking the router's DHCPv6 server messages.
C.IPv6 Source Guard is enabled on the VLAN, and the router's IPv6 address is not in the binding table.
D.The switch has IPv6 unicast-routing enabled, and it is sending its own RAs, causing a conflict.
AnswerA

RA Guard classifies each port by device role. Marking the router's port Gi1/0/1 as 'device-role host' tells the switch that no legitimate router RA should arrive there, so the guard drops the router advertisements. Setting the port to 'device-role router' would permit them, restoring IPv6 connectivity.

Why this answer

RA Guard drops Router Advertisements (RAs) on ports where the policy's 'device-role' is set to 'host'. On port Gi1/0/1, the legitimate router is connected, but if the RA Guard policy incorrectly assigns 'device-role host' to that port, the switch will treat the router as a host and drop all incoming RAs, preventing hosts on VLAN 10 from receiving them. This matches the symptom where the router sends RAs but hosts do not receive them, and the switch reports RA Guard dropping packets on that port.

Exam trap

Cisco often tests the specific behavior of RA Guard's 'device-role' setting, where candidates mistakenly think RA Guard only blocks RAs from unauthorized routers, but the trap is that setting 'device-role host' on a port will drop all RAs, including those from the legitimate router, because the switch treats that port as a host port.

How to eliminate wrong answers

Option B is wrong because DHCPv6 Guard blocks DHCPv6 server messages, not Router Advertisements (RAs), and the issue is specifically about RAs being dropped, not DHCPv6 traffic. Option C is wrong because IPv6 Source Guard filters traffic based on the IPv6 source address and binding table, but it does not drop RAs; RA Guard is the feature responsible for dropping RAs, and the symptom points to RA Guard, not Source Guard. Option D is wrong because if the switch had IPv6 unicast-routing enabled and sent its own RAs, it would not cause RA Guard to drop the router's RAs on port Gi1/0/1; instead, it might cause a conflict with the router's RAs, but the switch's RA Guard policy would still need to be misconfigured to drop the router's RAs, and the symptom explicitly shows RA Guard dropping packets on that port.

408
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 mld interface tunnel 0 Tunnel0 is up, line protocol is up Internet address is FE80::1 MLD is enabled on interface Current MLD version is 2 MLD query interval is 125 seconds MLD querier timeout is 255 seconds MLD max query response time is 10 seconds Last member query response interval is 1 second MLD activity: 0 joins, 0 leaves MLD querying router is FE80::1 (this system) Based on this output, what can be concluded?

A.MLD is disabled on this interface.
B.This router is not the MLD querier.
C.There are no multicast listeners on this tunnel interface.
D.MLD version 1 is in use.
AnswerC

The MLD activity counters show zero joins and zero leaves, meaning no hosts have sent membership reports on Tunnel0. The router itself is the querier, so no downstream listeners exist; multicast traffic forwarded here would have no receivers.

Why this answer

The output shows 'MLD activity: 0 joins, 0 leaves', indicating that no multicast listeners have joined any multicast group on this tunnel interface. Since MLD (Multicast Listener Discovery) is used to track group membership, zero joins means there are no active listeners. Therefore, option C is correct.

Exam trap

Cisco often tests the distinction between 'MLD enabled' and 'active listeners' — candidates may mistakenly think that MLD being enabled implies there are active group members, but the 'joins' counter directly reveals listener activity.

How to eliminate wrong answers

Option A is wrong because the output explicitly states 'MLD is enabled on interface', so MLD is not disabled. Option B is wrong because the output states 'MLD querying router is FE80::1 (this system)', confirming that this router is the MLD querier. Option D is wrong because the output shows 'Current MLD version is 2', not version 1.

409
Multi-Selectmedium

Which TWO configuration steps are required to enable VRF-Lite on a Cisco IOS-XE router for a customer with two separate routing domains? (Choose TWO.)

Select 2 answers
A.Create the VRF using the 'vrf definition <vrf-name>' command and assign a route distinguisher with the 'rd' command.
B.Assign the VRF to an interface using the 'vrf forwarding <vrf-name>' command under interface configuration.
C.Configure route target import/export statements under the VRF.
D.Apply an import map and export map to control route redistribution.
E.Enable BGP to exchange routes between VRFs.
AnswersA, B

This defines the VRF and its route distinguisher, which is mandatory for VRF-Lite.

Why this answer

The two essential steps are: creating the VRF with a route distinguisher using 'vrf definition <name>' and 'rd <value>', and assigning interfaces to the VRF with 'vrf forwarding <name>' under the interface. The other options are incorrect: 'ip vrf <name>' is legacy syntax but still works; however, 'rd' is required. Route targets are for MPLS VPN, not VRF-Lite.

Import/export maps are optional. BGP is not mandatory.

410
MCQmedium

Which OSPF LSA type is used to advertise a summary route for a network outside the area but within the same OSPF domain?

A.Type 1
B.Type 2
C.Type 3
D.Type 5
AnswerC

Type 3 LSAs are generated by ABRs to advertise inter-area routes, including summary routes for networks in other areas of the same OSPF domain. Type 5 handles external routes, so Type 3 matches the scenario.

Why this answer

OSPF Type 3 LSAs (Summary LSAs) are generated by Area Border Routers (ABRs) to advertise networks from one area into another area within the same OSPF domain. They describe inter-area routes, which are routes to networks outside the local area but still within the OSPF autonomous system. Therefore, a summary route for a network outside the area but within the same OSPF domain is advertised via Type 3 LSA.

Exam trap

The trap is confusing Type 3 with Type 5: candidates may think that any route outside the local area is 'external' and thus Type 5, but Type 5 is only for routes outside the OSPF domain (e.g., redistributed from EIGRP).

How to eliminate wrong answers

Option A is wrong because Type 1 LSAs (Router LSAs) are generated by every router to describe its own links within a single area, not to advertise summary routes between areas. Option B is wrong because Type 2 LSAs (Network LSAs) are generated by the Designated Router on multi-access segments to describe the subnet and attached routers, again within a single area. Option D is wrong because Type 5 LSAs (AS External LSAs) are used to advertise routes external to the OSPF domain, such as routes redistributed from other protocols, not for inter-area summaries.

411
Multi-Selecthard

Which THREE symptoms indicate that Control Plane Policing (CoPP) might be misconfigured or causing connectivity issues? (Choose THREE.)

Select 3 answers
A.OSPF or BGP neighbors are flapping, with log messages indicating adjacency timeouts.
B.SSH or Telnet sessions to the device are intermittent or time out.
C.CPU utilization remains high despite CoPP being configured.
D.CPU utilization is consistently low, and all control plane traffic is passing without drops.
E.Throughput on data interfaces increases significantly.
AnswersA, B, C

If CoPP drops routing protocol hello packets, neighbors may flap, indicating misclassification or overly restrictive policing.

Why this answer

CoPP is designed to protect the control plane by rate-limiting traffic. If CoPP is misconfigured with overly restrictive policies, it can drop OSPF or BGP hello packets, causing neighbor adjacencies to time out and flap. Log messages showing adjacency timeouts directly point to control plane packet loss, a classic symptom of CoPP misconfiguration.

Exam trap

Cisco often tests the misconception that CoPP only affects management traffic (SSH/Telnet), but candidates forget that routing protocol packets (OSPF, BGP) are also control plane traffic and can be dropped by CoPP, causing neighbor flapping.

412
MCQmedium

A network administrator is building a FlexVPN hub-and-spoke deployment using IKEv2 on a Cisco IOS router. The hub must accept connections from many spokes that use dynamically assigned public addresses, and the administrator wants the hub to authorize each spoke and assign it an address from a pool after authentication. Which IKEv2 configuration element on the hub provides the address assignment to authenticated spokes?

A.An IKEv2 authorization policy that references a local or DHCP address pool
B.A transform set with the esp-aes esp-sha256-hmac algorithms applied to the virtual template
C.An NHRP map entry for each spoke pointing to the hub's tunnel address
D.A crypto map with the set peer dynamic command on the hub
AnswerA

In FlexVPN, the IKEv2 authorization policy defines what an authenticated peer is allowed to receive, including the address pool used to assign an IP address to the spoke's virtual access interface. The hub references this policy in the IKEv2 profile so that after successful authentication the spoke is authorized and receives an address. This is the correct element for post-authentication address assignment.

Why this answer

FlexVPN uses IKEv2 profiles and authorization policies to control what authenticated peers receive. The authorization policy references an address pool, either local or external via DHCP, and the hub assigns each spoke an address for its virtual access interface after authentication succeeds. This is the mechanism that provides dynamic addressing to spokes in a hub-and-spoke FlexVPN deployment.

Exam trap

The trap here is confusing DMVPN mechanisms such as NHRP or legacy crypto map options with FlexVPN's IKEv2 authorization policy, which is what actually assigns addresses to authenticated spokes.

413
MCQhard

A network engineer is troubleshooting a DMVPN Phase 3 network using EIGRP as the routing protocol. Spoke routers are unable to establish direct spoke-to-spoke tunnels. The engineer verifies that NHRP registration is successful and that the hub has routes to all spokes. Which action is most likely to resolve the issue?

A.Ensure that the tunnel interfaces on all routers are configured with the same tunnel key.
B.Verify that the hub is configured with ip nhrp redirect and the spokes with ip nhrp shortcut.
C.Change the EIGRP network type on the tunnel interfaces to point-to-multipoint.
D.Configure EIGRP stub routing on the spoke routers.
AnswerB

In DMVPN Phase 3, the hub must have ip nhrp redirect to inform spokes of a better path, and spokes must have ip nhrp shortcut to install shortcut routes. Without these, spoke-to-spoke tunnels will not be established. This is a common misconfiguration that prevents direct spoke communication.

Why this answer

In DMVPN Phase 3, spoke-to-spoke tunnels require ip nhrp redirect on the hub and ip nhrp shortcut on the spokes. These commands allow the hub to redirect traffic and the spokes to create shortcut routes. Without them, spokes will continue to route through the hub, even if NHRP registration is successful.

Exam trap

The trap here is focusing on EIGRP or tunnel configuration when the issue is actually NHRP Phase 3 specific commands.

414
MCQmedium

A network engineer is configuring EIGRP on a Cisco router. The router has two paths to the same destination network with different metrics. The engineer wants to enable unequal-cost load balancing. Which command must be configured to allow EIGRP to use the higher-cost path?

A.traffic-share balanced
B.metric weights 0 1 1 1 1 1
C.variance 2
D.maximum-paths 2
AnswerC

The 'variance' command under the EIGRP routing process enables unequal-cost load balancing. The value (multiplier) determines which feasible successor routes can be used. A variance of 2 means that any feasible successor with a metric up to twice the successor's metric will be used for load balancing. This allows the higher-cost path to be utilized.

Why this answer

The 'variance' command is required to enable unequal-cost load balancing in EIGRP. It sets a multiplier that determines which feasible successor routes, with metrics higher than the successor, can be used. The higher-cost path must also be a feasible successor (satisfy the feasibility condition) to be considered.

Once variance is set, EIGRP can install multiple paths with different metrics.

Exam trap

The trap here is confusing maximum-paths with variance; maximum-paths only affects equal-cost paths, while variance is needed for unequal-cost load balancing.

415
MCQhard

A network engineer is implementing MPLS Layer 3 VPNs. The engineer needs to configure a PE router to exchange VPNv4 routes with other PE routers. Which BGP configuration is required to enable the exchange of VPNv4 routes?

A.address-family vpnv4
B.address-family ipv6 unicast
C.address-family ipv4 unicast
D.address-family ipv4 vrf CUSTOMER
AnswerA

The address-family vpnv4 command is used to enter the VPNv4 address family configuration mode. Within this mode, you can activate BGP neighbors to exchange VPNv4 routes. This is required for PE routers to exchange VPNv4 prefixes, which include the route distinguisher and VPN label. Without this address family, PE routers cannot exchange VPN routing information.

Why this answer

In MPLS Layer 3 VPNs, PE routers use Multiprotocol BGP (MP-BGP) to exchange VPNv4 routes. The VPNv4 address family is specifically designed for this purpose. Configuring address-family vpnv4 and activating neighbors under it enables the exchange of VPNv4 prefixes, which include the route distinguisher and label information.

Other address families like ipv4 unicast or ipv4 vrf are used for different purposes.

Exam trap

The trap here is confusing the VRF address family with the VPNv4 address family, and thinking that configuring the VRF address family enables VPNv4 route exchange.

416
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip eigrp neighbors EIGRP-IPv4 Neighbors for AS(100) H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 10.1.1.2 Gi0/0 13 00:12:34 1 200 0 45 1 10.2.2.2 Gi0/1 12 00:11:20 2 200 0 67 2 10.3.3.2 Gi0/2 10 00:10:15 1 200 0 89 Based on this output, which statement is correct?

A.All EIGRP neighbors are fully operational with no issues.
B.The neighbor on Gi0/2 is experiencing packet loss because its hold timer is 10 seconds.
C.The neighbor on Gi0/0 has a high SRTT, indicating congestion.
D.The neighbor on Gi0/1 has a sequence number of 67, which is higher than others, indicating a routing loop.
AnswerA

The queue count is zero for every neighbour, confirming no EIGRP packets are awaiting transmission, and each adjacency has been up for over ten minutes with stable sequence numbers. The hold timers remain well above zero, so no peer is expiring. This satisfies the stem's requirement of identifying a healthy, converged EIGRP topology.

Why this answer

The output shows all three EIGRP neighbors with hold timers above 0, low SRTT values (1-2 ms), RTO at 200 ms, and a Q count of 0, indicating no queued packets. These metrics confirm that the neighbors are fully operational and stable, with no packet loss, congestion, or routing issues.

Exam trap

Cisco often tests the misconception that a lower hold timer or a higher sequence number indicates a problem, when in fact these values are normal operational metrics that do not imply faults unless they deviate significantly from expected baselines.

How to eliminate wrong answers

Option B is wrong because a hold timer of 10 seconds is within the default EIGRP hold time range (15 seconds by default, but can be lower if configured), and it does not indicate packet loss; packet loss would be reflected by a high SRTT or RTO, or a non-zero Q count. Option C is wrong because the SRTT for Gi0/0 is 1 ms, which is very low, not high; a high SRTT would indicate congestion or delay. Option D is wrong because the sequence number (67) is simply the last packet received from that neighbor and does not indicate a routing loop; a routing loop would be detected via EIGRP's DUAL algorithm and would show in the topology table, not in the neighbor sequence number.

417
Multi-Selecthard

Which THREE symptoms indicate a problem with route redistribution causing suboptimal routing or routing loops? (Choose THREE.)

Select 3 answers
A.Routing loops occur where packets traverse multiple routers repeatedly.
B.Traffic from one area takes a longer path than expected, even though a shorter path exists within the same routing domain.
C.CPU utilization on the redistribution router is consistently below 50%.
D.Some networks are not reachable from certain parts of the network, even though they are present in the routing table of the redistribution router.
E.The routing table on all routers is stable and converges quickly after a topology change.
AnswersA, B, D

Routing loops arise when redistributed routes re-enter the source routing domain, so packets circulate between routers indefinitely. This directly satisfies the stem's requirement for a redistribution-induced symptom, since mismatched metrics or missing administrative distance controls let prefixes leak bidirectionally, producing the repeated multi-router traversal described.

Why this answer

Route redistribution problems manifest in specific, observable ways. Option A is correct because a routing loop caused by mutual redistribution (for example, redistributing routes back and forth between OSPF and EIGRP without proper filtering or administrative distance/tagging) makes packets traverse multiple routers repeatedly until the TTL expires. Option B is correct because suboptimal routing occurs when a redistributed route's metric or administrative distance makes a longer path appear preferable to a shorter path that already exists within the same routing domain.

Option D is correct because missing reachability to networks that exist in the redistribution router's table typically indicates a redistribution filter, missing redistribute statement, or a seed metric problem preventing those prefixes from being advertised into the target protocol. Option C is not a symptom of redistribution issues since low CPU utilization is normal and healthy, not indicative of loops or suboptimal paths. Option E is not a symptom either, because stable and fast-converging routing tables describe correct operation rather than a redistribution fault.

418
MCQmedium

A network engineer is troubleshooting a BGP route reachability issue. R1 learns the prefix 10.1.1.0/24 via eBGP from R2 with an AD of 20, and via OSPF from R3 with an AD of 110. The engineer notices that R1 installs the OSPF route in the routing table instead of the eBGP route, even though the eBGP route is preferred by default. What is the most likely cause of this behavior?

A.The OSPF route has a lower metric than the eBGP route.
B.The distance bgp 20 200 200 command is configured under the BGP process, increasing the AD of eBGP routes to 200.
C.The OSPF route is an inter-area route, which has a lower AD than intra-area routes.
D.The eBGP route is not the best path because the next-hop is unreachable.
AnswerB

This command sets the AD for eBGP routes to 200, making OSPF (AD 110) preferred.

Why this answer

The default administrative distance for eBGP is 20, and for OSPF is 110, so eBGP should be preferred. However, if the distance command is applied to the eBGP neighbor or the BGP process, it can increase the AD of eBGP routes, making them less preferred than OSPF.

419
MCQeasy

Which IP SLA operation type is used to monitor the availability of a TCP-based service by attempting a three-way handshake?

A.UDP Jitter
B.TCP Connect
C.ICMP Echo
D.HTTP
AnswerB

TCP Connect performs a full three-way handshake (SYN, SYN-ACK, ACK) to the target port, confirming the TCP service is genuinely listening and accepting connections. This distinguishes it from operations that only measure round-trip latency without verifying service availability.

Why this answer

The TCP Connect operation (type 5) attempts to establish a TCP connection to a specified port. Success indicates the service is reachable; failure indicates a problem.

420
Drag & Drophard

Drag and drop the steps to troubleshoot IPv4 ACL adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Start by confirming the ACL is applied to the correct interface and direction; then check for implicit deny blocking traffic; verify sequence numbers and order; examine log entries for hits; finally, adjust ACL by inserting a permit statement before the deny.

421
MCQmedium

Consider the following CoPP configuration: access-list 150 permit tcp any any eq 179 access-list 150 permit udp any any eq 646 ! class-map match-all COPP-CORE match access-group 150 ! policy-map COPP-POLICY class COPP-CORE police 64000 conform-action transmit exceed-action drop class class-default police 128000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP-POLICY What is missing from this configuration to also protect against ICMP-based control-plane attacks?

A.Add 'permit icmp any any' to access-list 150 to include ICMP in the COPP-CORE class.
B.Change the class-default police rate to 64000 bps to match the COPP-CORE rate.
C.Add a second class-map for ICMP and apply a separate policer.
D.The configuration is complete; ICMP is not a significant control-plane threat.
AnswerA

Adding 'permit icmp any any' to access-list 150 causes the COPP-CORE class-map to match ICMP packets, which are currently not classified and thus fall into class-default. This minimal, targeted change subjects ICMP traffic to the 64000 bps policer, protecting the control plane from ping floods while leaving all other control-plane traffic unaffected. It directly addresses the missing classification and is the simplest correct fix.

Why this answer

The current CoPP configuration only matches BGP (TCP port 179) and LDP (UDP port 646) traffic in the COPP-CORE class. ICMP-based control-plane attacks (e.g., ICMP floods, Smurf attacks) are not matched by any explicit class, so they fall into class-default, which has a higher police rate (128 kbps) and may allow excessive ICMP traffic to reach the control plane. Adding 'permit icmp any any' to access-list 150 ensures ICMP packets are classified into COPP-CORE and subjected to the more restrictive 64 kbps policer, protecting the control plane from ICMP-based attacks.

Exam trap

Cisco often tests the misconception that class-default alone is sufficient for all unmatched traffic, but the trap here is that ICMP is a direct control-plane threat that must be explicitly classified and rate-limited, not left to the default catch-all policer which may be too permissive.

How to eliminate wrong answers

Option B is wrong because reducing the class-default police rate to 64 kbps would not specifically protect against ICMP attacks; it would indiscriminately rate-limit all unmatched traffic, potentially dropping legitimate non-ICMP traffic (e.g., ARP, routing protocol hellos) that should be handled separately. Option C is wrong because while adding a separate class-map for ICMP is a valid design approach, the question asks what is missing from the given configuration to protect against ICMP-based attacks, and the simplest missing element is including ICMP in the existing COPP-CORE class; a separate class-map is not strictly required and would add unnecessary complexity. Option D is wrong because ICMP is a significant control-plane threat—ICMP floods, echo request storms, and unreachable messages can overwhelm the route processor, causing CPU spikes and network instability; Cisco recommends explicit CoPP policies for ICMP traffic.

422
MCQeasy

A network engineer runs the following command on Router R1: R1# show crypto ipsec transform-set Transform set ESP-AES256-SHA: { esp-256-aes esp-sha256-hmac } will negotiate = { Tunnel, }, Transform set ESP-AES128-SHA: { esp-aes esp-sha256-hmac } will negotiate = { Tunnel, }, Based on this output, which statement is correct?

A.Both transform sets use tunnel mode; ESP-AES256-SHA uses stronger encryption.
B.The transform sets use transport mode.
C.The transform sets use MD5 for hashing.
D.The transform sets are not compatible with IKEv2.
AnswerA

The output shows both transform sets negotiating Tunnel mode, and ESP-AES256-SHA pairs 256-bit AES with SHA-256 HMAC, giving stronger encryption than ESP-AES128-SHA's 128-bit AES. Both use identical SHA-256 integrity, so encryption strength is the only axis of difference.

Why this answer

The output shows two transform sets configured. The first uses AES-256 with SHA256 HMAC, the second uses AES-128 with SHA256 HMAC. Both use tunnel mode.

423
MCQmedium

A network engineer runs the following command to verify IPv6 ND inspection policy: R1# show ipv6 nd inspection policy INSPECT Policy: INSPECT Status: Active Device role: node Trusted ports: none Untrusted ports: Fa0/0 ND inspection: enabled Validation: - Source MAC address: verify - Destination MAC address: verify - IPv6 source address: verify - IPv6 destination address: verify - Nonce: disabled - Timestamp: disabled What does this output indicate?

A.The policy INSPECT validates source and destination MAC and IPv6 addresses on untrusted port Fa0/0.
B.The policy INSPECT only validates source MAC addresses on trusted ports.
C.The policy INSPECT disables ND inspection and logs all ND messages.
D.The policy INSPECT is inactive and not applied to any interface.
AnswerA

The output confirms that policy INSPECT is active and enforces validation of source and destination MAC addresses alongside IPv6 source and destination addresses. Because Fa0/0 is untrusted, all four checks apply to traffic arriving there, satisfying the requirement to verify ND packets on that interface.

Why this answer

The output shows that the policy INSPECT is active, with ND inspection enabled and validation configured for source MAC, destination MAC, IPv6 source, and IPv6 destination addresses. The 'Untrusted ports: Fa0/0' indicates that these validations are applied to that untrusted port, which is the standard behavior for IPv6 ND inspection to prevent spoofing attacks on untrusted interfaces.

Exam trap

Cisco often tests the distinction between trusted and untrusted ports in IPv6 ND inspection, where candidates may mistakenly think validation occurs on trusted ports or that the policy is inactive when it is actually active on untrusted ports.

How to eliminate wrong answers

Option B is wrong because the output shows 'Trusted ports: none', meaning no trusted ports are configured, and ND inspection validates addresses on untrusted ports, not trusted ports. Option C is wrong because the output explicitly states 'ND inspection: enabled', not disabled, and there is no indication of logging all ND messages; logging is a separate feature. Option D is wrong because the output clearly shows 'Status: Active', indicating the policy is active and applied to interface Fa0/0 as an untrusted port.

424
MCQhard

A network engineer is troubleshooting a DMVPN Phase 3 network using Cisco IOS XE routers. Spoke routers are unable to establish direct spoke-to-spoke tunnels. The hub router is configured with 'ip nhrp redirect', and spokes are configured with 'ip nhrp shortcut'. The engineer notices that spoke routers are not receiving NHRP redirect messages from the hub. Which action should be taken to resolve this issue?

A.Configure 'ip nhrp map multicast dynamic' on the spoke routers.
B.Enable 'ip nhrp shortcut' on the hub router.
C.Change the tunnel mode from GRE multipoint to GRE point-to-point.
D.Ensure that the hub router has a route to the spoke networks and that NHRP resolution is working.
AnswerD

For the hub to send NHRP redirect messages, it must have a route to the destination spoke network and be able to perform NHRP resolution. If the hub lacks a route or NHRP resolution fails, it cannot generate redirects. The engineer should verify that the hub has routes to all spoke networks, that NHRP entries are correct, and that the hub can resolve spoke NBMA addresses. This is a common cause of missing redirects in DMVPN Phase 3.

Why this answer

In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to inform spokes of a better path to a destination. For the hub to send redirects, it must have a route to the destination network and be able to resolve the destination's NBMA address via NHRP. If the hub lacks a route or NHRP resolution fails, no redirects are sent, and spokes cannot establish direct tunnels.

Verifying hub routing and NHRP operation is essential for troubleshooting this issue.

Exam trap

The trap here is assuming that enabling 'ip nhrp shortcut' on the hub is necessary, when it is actually a spoke-side command.

425
MCQmedium

Examine the following configuration on a PE router: ip vrf CUSTOMER-C rd 200:1 ! interface GigabitEthernet0/3 ip vrf forwarding CUSTOMER-C ip address 10.2.2.1 255.255.255.252 ! router ospf 1 vrf CUSTOMER-C network 10.2.2.0 0.0.0.3 area 0 ! router bgp 65000 address-family ipv4 vrf CUSTOMER-C redistribute ospf 1 exit-address-family What is missing from this configuration?

A.The VRF is missing route-target export and import commands.
B.The OSPF network command should use a wildcard mask of 0.0.0.0.
C.The BGP neighbor must be configured under the VRF address-family.
D.The VRF must have a route distinguisher that matches the route-target.
AnswerA

Without route-target export and import commands under the VRF, BGP cannot populate the VPNv4 route-target extended community, so no routes are exchanged between VRFs. The stem's configuration lacks these, preventing the OSPF-redistributed routes from being imported into CUSTOMER-C.

Why this answer

In MPLS L3VPN, a VRF requires route-target export and import commands to control the distribution of VPN routes via MP-BGP. Without these, the VRF cannot import or export routes, and the VPN will not function. The configuration shows a VRF with RD but no route-targets, so they are missing.

Exam trap

300-410 often tests the misconception that RD and RT are the same or that RTs are optional. Candidates must remember that RTs are mandatory for VRF route import/export.

How to eliminate wrong answers

Option B is wrong because the OSPF network command with wildcard 0.0.0.3 is correct for a /30 subnet; it matches the interface IP. Option C is wrong because the BGP neighbor is not required under the VRF address-family for redistribution of OSPF into BGP; the neighbor would be for peering, but the question is about missing configuration for the VRF to work. Option D is wrong because the RD and route-target do not need to match; they serve different purposes: RD makes routes unique, RT controls import/export.

426
MCQeasy

What is the default active flow timeout value in Cisco IOS Flexible NetFlow?

A.60 seconds
B.1800 seconds
C.300 seconds
D.30 seconds
AnswerB

Cisco IOS Flexible NetFlow uses a default active timeout of 1800 seconds, flushing long-lived flows every 30 minutes. Inactive timeout defaults to 15 seconds. This value applies unless overridden with the cache timeout active command.

Why this answer

Cisco IOS Flexible NetFlow uses a default active timeout of 1800 seconds (30 minutes), after which an active flow entry is exported even if traffic is still ongoing. This ensures long-lived flows are periodically reported rather than held indefinitely. The inactive timeout default is 15 seconds.

Exam trap

300-410 often tests the distinction between the active timeout default (1800 s) and the inactive timeout default (15 s), and candidates frequently swap them or pick the legacy NetFlow value of 300 s.

How to eliminate wrong answers

Option A is wrong because 60 seconds is not the default active timeout — it is a commonly configured custom value but not the IOS default. Option C is wrong because 300 seconds (5 minutes) is a typical NetFlow v9/legacy cache active timeout in some platforms, not the Flexible NetFlow default. Option D is wrong because 30 seconds is far too short and is not a default for active flow timeout in Flexible NetFlow.

427
Multi-Selecthard

An engineer configures Flexible NetFlow with a user-defined flow record that includes 'match ipv4 source address' and 'collect counter bytes'. Which TWO additional statements about this configuration are true? (Choose TWO.)

Select 2 answers
A.The flow record must be applied directly to an interface using the 'ip flow record' command.
B.The 'match ipv4 source address' command defines a key field that is used to uniquely identify flows.
C.The 'collect counter bytes' command causes the router to count the total number of bytes for each unique flow.
D.If no 'match' commands are configured, the router will use the default match fields from the 'netflow-original' record.
E.The flow record can be used by both IPv4 and IPv6 traffic simultaneously without additional configuration.
AnswersB, C

Correct. Match fields are key fields; flows are differentiated based on their values. Here, only the source IP is used as a key.

Why this answer

In Flexible NetFlow, the 'match' fields define the flow key; flows are uniquely identified by the combination of all match fields. The 'collect' fields define non-key data that is aggregated per flow. The flow record must be referenced by a flow monitor, which is then applied to an interface.

The default flow record is 'netflow-original', which includes many default keys. The 'match' fields cannot be omitted; at least one match field is required. The 'collect' fields are optional and can include counters, timestamps, etc.

428
Multi-Selectmedium

Which TWO statements about NAT overload (PAT) are true? (Choose TWO.)

Select 2 answers
A.PAT allows multiple inside hosts to share a single public IP address by using unique source port numbers.
B.PAT is only supported with a single public IP address configured on the outside interface.
C.PAT is also known as NAT overload and is defined in RFC 2663.
D.PAT cannot translate traffic for protocols that use static port numbers, such as DNS or HTTP.
E.PAT requires the ip nat inside source list command with the overload keyword.
AnswersA, C

PAT multiplexes many inside local addresses onto one inside global address, differentiating sessions by rewriting the source port to a unique value. This satisfies the constraint of conserving public IPv4 addresses while supporting simultaneous connections from multiple hosts.

Why this answer

Option A is correct because PAT (Port Address Translation) multiplexes many inside local addresses onto one inside global address by translating the source port (and IP) so each session is uniquely identified in the NAT translation table. Option C is correct because PAT is commonly called NAT overload and is formally described in RFC 2663 as 'Network Address Port Translation' (NAPT). Option B is wrong because PAT can use a pool of public addresses, not only a single outside-interface address.

Option D is wrong because PAT handles well-known/static ports fine; it translates the source port of the initiating host, and static mappings can be used for inbound services like HTTP or DNS. Option E is wrong as a general truth because the overload keyword appears with 'ip nat inside source list ... interface ... overload' or '... pool ... overload', but the statement omits the required interface or pool argument, so it is not a complete/valid command.

Exam trap

Cisco often tests the misconception that PAT requires a single public IP address or that it cannot handle protocols with fixed port numbers, when in fact PAT can use a pool of addresses and translates the source port regardless of the destination port.

429
MCQmedium

A network engineer is troubleshooting an intermittent BGP session failure between two routers. The BGP session drops every few hours and recovers after a few seconds. The engineer checks the logs and sees that an EEM applet is triggered just before each failure. The applet is configured to run a script that clears the BGP session when a specific syslog message is generated. What is the most likely cause of the BGP session failure?

A.The BGP session is failing due to a physical layer issue.
B.The EEM applet is clearing the BGP session as part of its configured action.
C.The BGP session is failing due to a routing loop.
D.The EEM applet is causing a memory leak that crashes the BGP process.
AnswerB

The EEM applet is configured to run a script that clears the BGP session whenever a specific syslog message appears. That scripted clear command is the direct trigger, explaining the periodic drops and immediate recovery, rather than any underlying transport or timer issue.

Why this answer

The logs show an EEM applet is triggered just before each BGP failure, and the applet is explicitly configured to clear the BGP session when a specific syslog message appears. This is a direct cause-and-effect: the applet's action (clearing BGP) is what is tearing down the session, not an underlying network fault.

Exam trap

300-410 often tests the tendency to blame the network (physical layer, routing loop) when the logs explicitly show an automated tool (EEM) performing the disruptive action.

How to eliminate wrong answers

Option A is wrong because a physical layer issue would produce interface up/down events and CRC errors, not a syslog-triggered EEM applet clearing BGP. Option C is wrong because a routing loop would cause instability in routing tables and high CPU, not a clean, periodic BGP clear correlated with an EEM trigger. Option D is wrong because a memory leak would cause a crash or reload, not a graceful BGP session clear; the applet is explicitly configured to clear the session, so no leak is needed to explain the symptom.

430
MCQhard

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS XE router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 (WAN, connected to ISP) and GigabitEthernet0/1 (LAN, connected to internal network). The engineer wants to apply strict uRPF on the WAN interface to drop packets with spoofed source addresses, but the internal network uses asymmetric routing, with some return traffic going out a different interface. The engineer applies the following configuration: interface GigabitEthernet0/0 ip address 203.0.113.1 255.255.255.0 ip verify unicast source reachable-via rx After applying this, the engineer notices that some legitimate traffic from the internal network is being dropped. Which action should the engineer take to resolve the issue while maintaining spoofing protection?

A.Configure uRPF with an access list to allow specific internal subnets that are subject to asymmetric routing, while keeping strict mode for other traffic.
B.Enable uRPF in loose mode with an access list that denies known spoofed prefixes, and apply it to the WAN interface.
C.Disable uRPF on the WAN interface and instead implement IP Source Guard on the LAN interfaces to prevent spoofing.
D.Change the uRPF mode to loose mode by using the ip verify unicast source reachable-via any command on the WAN interface.
AnswerA

Cisco IOS XE supports uRPF with an access list (ip verify unicast source reachable-via rx allow-self-ping acl) to exempt certain source addresses from the strict check. By creating an ACL that permits the internal subnets experiencing asymmetric routing, the engineer can maintain strict uRPF for all other traffic, preserving spoofing protection while allowing legitimate asymmetric flows. This is the recommended approach for handling exceptions without weakening overall security.

Why this answer

Strict uRPF drops packets if the source address is not reachable via the incoming interface. Asymmetric routing causes legitimate return traffic to arrive on an interface different from the one used to reach the source, triggering drops. Cisco IOS XE allows an access list with strict uRPF to exempt specific source addresses from the check.

By permitting the internal subnets that use asymmetric routing in the ACL, the engineer maintains strict uRPF for all other traffic, preserving spoofing protection while allowing legitimate flows.

Exam trap

The trap here is thinking that loose mode is the only way to handle asymmetric routing, when in fact strict mode with an exception ACL can maintain stronger security for most traffic.

431
MCQmedium

A network engineer is configuring OSPFv3 on a Cisco router. The router has two interfaces in Area 0: GigabitEthernet0/0 (IPv6 address 2001:db8:1::1/64) and GigabitEthernet0/1 (IPv6 address 2001:db8:2::1/64). After enabling IPv6 unicast routing and configuring OSPFv3 with the router-id 1.1.1.1, the engineer notices that no OSPFv3 neighbors are forming. Which action is most likely to resolve the issue?

A.Assign IPv6 addresses from the same subnet to both interfaces.
B.Enable OSPFv3 on the interfaces using the ipv6 ospf 1 area 0 command.
C.Set the OSPFv3 network type to point-to-point on both interfaces.
D.Configure a 64-bit router ID using the router-id command under the OSPFv3 process.
AnswerB

OSPFv3 is enabled per interface, unlike OSPFv2 which can be enabled under router configuration. Without the ipv6 ospf 1 area 0 interface command, the interfaces do not participate in OSPFv3, so no hellos are sent or received. This command activates OSPFv3 on the interface and associates it with Area 0. Thus, neighbors will form once the interfaces are enabled.

Why this answer

OSPFv3 requires enabling the protocol on each interface using the ipv6 ospf process-id area area-id command. Without this, the interface does not participate in OSPFv3, and no hellos are sent or received. The router ID and network type are secondary.

Assigning IPv6 addresses from the same subnet is irrelevant because OSPFv3 uses link-local addresses for neighbor discovery.

Exam trap

The trap here is assuming that OSPFv3 is enabled globally under router configuration like OSPFv2, when in fact it must be enabled per interface.

432
MCQeasy

A network engineer is configuring a Cisco IOS router as a DHCP server for a subnet. The router must exclude the address 10.10.10.1 from being assigned to clients. Which command correctly accomplishes this?

A.ip dhcp excluded-address 10.10.10.1
B.ip dhcp excluded-address 10.10.10.1 10.10.10.1
C.ip dhcp excluded-address 10.10.10.0 10.10.10.255
D.ip dhcp pool POOL; excluded-address 10.10.10.1
AnswerA

The 'ip dhcp excluded-address' command is used in global configuration mode to prevent the DHCP server from assigning specific IP addresses. Specifying a single address excludes only that address. This is the correct syntax to exclude 10.10.10.1 from the DHCP pool, ensuring it is not offered to clients.

Why this answer

The correct way to exclude a single IP address from a Cisco IOS DHCP server is to use the global command 'ip dhcp excluded-address' followed by the specific address. This prevents the DHCP server from assigning that address to any client. The command must be entered in global configuration mode, not within the DHCP pool.

Exam trap

The trap here is placing the exclusion command inside the DHCP pool configuration mode, where it is not valid, or excluding an entire range instead of a single address.

433
Multi-Selectmedium

Which TWO commands can be used to verify DHCP IPv4 server operation and address pool utilization on a Cisco IOS router? (Choose TWO.)

Select 2 answers
A.show ip dhcp binding
B.show ip dhcp pool
C.show ip dhcp conflict
D.debug ip dhcp server events
E.show ip interface
AnswersA, B

Lists active leases with client MAC, assigned IP, lease expiry and type, directly confirming the server has allocated addresses. This satisfies the address pool utilisation check by revealing how many bindings exist against pool capacity.

Why this answer

Option A, 'show ip dhcp binding', is correct because it displays the DHCP bindings table on the Cisco IOS router, listing each leased IPv4 address along with its associated client identifier (MAC address), lease expiration time, and binding type, which directly verifies that the DHCP server is actively assigning addresses from the pool. Option B, 'show ip dhcp pool', is correct because it reports per-pool utilization statistics, including the total number of addresses in the pool, the number of leased addresses, and the number of available addresses, which is exactly what is needed to assess address pool utilization. Option C, 'show ip dhcp conflict', only lists addresses that the server has detected as conflicting (via ping or ARP) and does not show active leases or pool utilization, so it does not satisfy the requirement.

Option D, 'debug ip dhcp server events', is a real-time debugging command that generates verbose event output rather than a verification/status display, and it is not typically used to check pool utilization. Option E, 'show ip interface', displays interface IP configuration and status but provides no DHCP server lease or pool information, so it is irrelevant here.

Exam trap

Cisco often tests the distinction between verification commands (show) and troubleshooting/debugging commands (debug), leading candidates to mistakenly select 'debug ip dhcp server events' as a verification tool when it is actually a real-time diagnostic command that can impact router performance.

434
MCQhard

A network engineer runs the following command on Router R1: R1# show ip dhcp server statistics Memory usage 26140 Address conflicts 0 Pool statistics Pool IP addresses Requests Offers Acks Naks Declines Releases POOL1 10-20 50 45 40 5 2 3 Based on this output, which statement is correct?

A.The DHCP server is operating without any issues.
B.The DHCP server is rejecting requests (Naks) and clients are declining offers, indicating possible pool exhaustion or address conflicts.
C.The DHCP server has a memory problem.
D.The DHCP server has no address conflicts.
AnswerB

Five Naks and two Declines in the pool statistics show the server refused some requests and clients rejected offered addresses. Combined with 40 Acks from 11 addresses, this points to pool exhaustion or conflicting addresses, matching the stated interpretation of the counters.

Why this answer

The output shows 5 NAKs and 2 Declines, indicating that the DHCP server is rejecting requests (NAKs) and clients are declining offers (Declines). NAKs typically occur when a client requests an IP address that is no longer valid or available, while Declines happen when a client detects an address conflict via ARP. This combination strongly suggests pool exhaustion or address conflicts, making option B correct.

Exam trap

Cisco often tests the distinction between server-tracked address conflicts (shown in the 'Address conflicts' counter) and client-detected conflicts (shown as Declines), leading candidates to incorrectly assume zero conflicts means no issues.

How to eliminate wrong answers

Option A is wrong because the presence of NAKs and Declines indicates issues, so the server is not operating without any issues. Option C is wrong because the memory usage of 26140 is not specified as problematic, and no memory-related errors or warnings are shown in the output. Option D is wrong because while the 'Address conflicts' counter is 0, the 2 Declines indicate that clients are detecting address conflicts on their own, which is a separate issue from server-tracked conflicts.

435
MCQeasy

Which BGP attribute is used for loop prevention in eBGP?

A.NEXT_HOP
B.LOCAL_PREF
C.AS_PATH
D.MED
AnswerC

AS_PATH records every autonomous system a route traverses, so a router discards any advertisement containing its own AS number, preventing eBGP loops. This satisfies the stem's loop-prevention requirement directly, unlike weight or local preference, which influence path selection locally and never detect routing loops between autonomous systems.

Why this answer

The AS_PATH attribute contains the list of AS numbers a route has traversed. If a BGP router receives a route with its own AS number in the AS_PATH, it discards the route to prevent loops.

436
MCQhard

A network engineer runs the following command to troubleshoot IPv6 ND inspection: R1# debug ipv6 nd inspection *Mar 1 00:02:34.567: IPv6-ND-Inspection: R1, Fa0/0, NS from fe80::1 to ff02::1, target 2001:db8::1, options: SLLA 0011.2233.4455 *Mar 1 00:02:34.567: IPv6-ND-Inspection: R1, Fa0/0, NS from fe80::1 to ff02::1, target 2001:db8::1, SLLA 0011.2233.4455 is allowed by policy INSPECT *Mar 1 00:02:35.890: IPv6-ND-Inspection: R1, Fa0/0, NA from fe80::2 to fe80::1, target 2001:db8::2, options: TLLA 00aa.bbcc.ddee *Mar 1 00:02:35.890: IPv6-ND-Inspection: R1, Fa0/0, NA from fe80::2 to fe80::1, target 2001:db8::2, TLLA 00aa.bbcc.ddee is blocked by policy INSPECT What does this output indicate?

A.ND inspection is allowing NS messages but blocking NA messages from fe80::2, likely due to a MAC address mismatch or policy violation.
B.ND inspection is blocking all NS and NA messages, indicating a misconfiguration.
C.ND inspection is allowing all messages but logging them for analysis.
D.ND inspection is not configured; the debug output is from default ND behavior.
AnswerA

The debug shows the NS from fe80::1 permitted, while the NA from fe80::2 is blocked by policy INSPECT. ND inspection validates the source link-layer address against the binding table, so a mismatch between the advertised MAC and the recorded entry triggers the drop.

Why this answer

The debug output shows that the Neighbor Solicitation (NS) from fe80::1 is allowed by policy INSPECT, while the Neighbor Advertisement (NA) from fe80::2 is blocked by the same policy. This indicates that IPv6 ND inspection is selectively permitting NS messages but denying NA messages from fe80::2, likely due to a MAC address mismatch (the TLLA in the NA does not match the expected binding) or a policy violation, making option A correct.

Exam trap

Cisco often tests the distinction between NS and NA handling in ND inspection, where candidates may assume both messages are treated identically, but the policy can allow one and block the other based on binding table validation.

How to eliminate wrong answers

Option B is wrong because the output clearly shows NS messages are allowed, not all messages blocked, so it is not a complete misconfiguration. Option C is wrong because the NA message is explicitly blocked, not just logged; the debug shows a blocking action, not mere logging. Option D is wrong because the debug output references 'policy INSPECT', which confirms ND inspection is configured and actively enforcing policies, not default ND behavior.

437
MCQeasy

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# show crypto map Crypto Map "CMAP" 10 ipsec-isakmp Peer = 192.168.2.2 Extended IP access list 101 access-list 101 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255 Current peer: 192.168.2.2 Security association lifetime: 4608000 kilobytes/3600 seconds PFS (Y/N): N Transform sets={myset, } Interfaces using crypto map CMAP: Tunnel0 What does this output indicate?

A.The crypto map is misconfigured because it uses an extended ACL with source and destination subnets.
B.The crypto map is correctly configured for a site-to-site VPN with the peer 192.168.2.2.
C.The crypto map is missing the transform set.
D.The crypto map should be applied to the physical interface instead of the tunnel.
AnswerB

The crypto map names peer 192.168.2.2, matches the site-to-site traffic via access list 101, references transform set myset, and is bound to Tunnel0. All required elements are present and consistent, indicating a correctly configured site-to-site VPN.

Why this answer

The output shows a properly configured IPsec site-to-site VPN crypto map. It includes a peer (192.168.2.2), an extended ACL (101) that correctly matches the local and remote subnets (192.168.1.0/24 and 192.168.2.0/24), a transform set (myset), and is applied to Tunnel0, which is typical for a site-to-site VPN. The security association lifetime and PFS settings are also present, confirming a valid configuration.

Exam trap

Cisco often tests the misconception that an extended ACL in a crypto map is a misconfiguration, when in fact it is required for site-to-site VPNs to define the traffic to be encrypted.

How to eliminate wrong answers

Option A is wrong because using an extended ACL with source and destination subnets is correct for a site-to-site VPN; it defines which traffic should be encrypted, not a misconfiguration. Option C is wrong because the output explicitly shows 'Transform sets={myset,}', indicating a transform set is configured. Option D is wrong because applying the crypto map to a tunnel interface (Tunnel0) is valid and common for site-to-site VPNs; it does not need to be on the physical interface.

438
MCQmedium

Given the following partial configuration on router R5: interface GigabitEthernet0/0 ip address 10.1.1.1 255.255.255.0 ip pim sparse-mode ! interface GigabitEthernet0/1 ip address 10.2.2.1 255.255.255.0 ip pim sparse-mode ! router ospf 1 router-id 5.5.5.5 network 10.0.0.0 0.255.255.255 area 0 What is the effect of this configuration?

A.OSPF will not form adjacencies because PIM sparse-mode is enabled on the interfaces.
B.OSPF will form adjacencies on both interfaces, and PIM sparse-mode will operate normally; the configuration is valid.
C.OSPF will only form adjacency on GigabitEthernet0/0 because the network statement does not match GigabitEthernet0/1.
D.PIM sparse-mode will not work because there is no rendezvous point (RP) configured.
AnswerB

PIM sparse-mode requires a unicast routing table entry to build its RPF neighbour, and OSPF supplies that by advertising both 10.1.1.0/24 and 10.2.2.0/24 into area 0 via the single classful network statement. With router-id 5.5.5.5 set, adjacencies form and multicast forwarding operates normally.

Why this answer

The configuration is valid because OSPF and PIM sparse-mode operate independently on an interface. OSPF uses multicast address 224.0.0.5/6 for hello packets and forms adjacencies regardless of PIM sparse-mode being enabled. PIM sparse-mode requires an RP to function, but its presence does not affect OSPF adjacency formation.

The network statement 10.0.0.0 0.255.255.255 matches both interfaces (10.1.1.1 and 10.2.2.1), so OSPF will form adjacencies on both.

Exam trap

Cisco often tests the misconception that enabling PIM sparse-mode on an interface disrupts OSPF adjacency formation, when in fact they operate at different layers (OSPF at Layer 3 routing, PIM at multicast routing) and do not interfere with each other.

How to eliminate wrong answers

Option A is wrong because PIM sparse-mode does not interfere with OSPF adjacency formation; OSPF uses its own multicast addresses (224.0.0.5/6) and is unaffected by PIM configuration. Option C is wrong because the network statement 10.0.0.0 0.255.255.255 is a wildcard mask that matches all addresses starting with 10.x.x.x, which includes both 10.1.1.1 and 10.2.2.1, so OSPF will enable on both interfaces. Option D is wrong because PIM sparse-mode can be enabled on interfaces without an RP configured; the RP is required only for actual multicast forwarding, not for PIM to be enabled or for OSPF to operate.

439
MCQeasy

A network engineer runs the following command on Router R1: R1# show snmp mib ifmib ifindex ifIndex: 1 Interface: GigabitEthernet0/0 Description: GigabitEthernet0/0 ifIndex: 2 Interface: GigabitEthernet0/1 Description: GigabitEthernet0/1 ifIndex: 3 Interface: Loopback0 Description: Loopback0 ifIndex: 10 Interface: Tunnel0 Description: Tunnel0 Based on this output, which statement is correct?

A.The ifIndex for Loopback0 is 3.
B.The ifIndex values are assigned sequentially starting from 0.
C.GigabitEthernet0/0 has ifIndex 2.
D.Tunnel0 has ifIndex 3.
AnswerA

The output lists each interface with its assigned ifIndex, and Loopback0 is explicitly shown as ifIndex 3. This directly satisfies the question's requirement to identify the correct mapping from the `show snmp mib ifmib ifindex` command, confirming the persistent index used for SNMP polling of that interface.

Why this answer

The output of 'show snmp mib ifmib ifindex' displays the ifIndex values assigned to each interface by the SNMP agent. The table clearly shows Loopback0 with ifIndex 3, making option A correct. ifIndex values are not guaranteed to be sequential or start from 0; they are assigned dynamically and can have gaps, as seen with Tunnel0 having ifIndex 10.

Exam trap

Cisco often tests the misconception that ifIndex values are assigned sequentially starting from 0 or 1 without gaps, but the output shows non-sequential values (e.g., Tunnel0 with ifIndex 10) to trap candidates who assume a simple 1-to-1 order.

How to eliminate wrong answers

Option B is wrong because ifIndex values are not assigned sequentially starting from 0; they typically start from 1 and can have gaps (e.g., Tunnel0 has ifIndex 10, not 4). Option C is wrong because GigabitEthernet0/0 has ifIndex 1, not 2. Option D is wrong because Tunnel0 has ifIndex 10, not 3.

440
MCQhard

What is the default DHCPv4 server lease time on a Cisco IOS-XE router configured as a DHCP server?

A.3600 seconds (1 hour)
B.43200 seconds (12 hours)
C.86400 seconds (1 day)
D.604800 seconds (7 days)
AnswerC

Cisco IOS-XE assigns a default DHCPv4 lease of 86400 seconds (24 hours) when no lease duration is specified in the pool configuration. This satisfies the stem's requirement for the out-of-box default, distinguishing it from the configurable `lease` command values an administrator might set.

Why this answer

The default DHCPv4 lease time on a Cisco IOS-XE router configured as a DHCP server is 86400 seconds (1 day). This is defined in the Cisco IOS DHCP server configuration and is the standard default value used when no lease duration is explicitly specified in the DHCP pool configuration.

Exam trap

Cisco often tests the default lease time to catch candidates who confuse common enterprise practices (like 12 hours or 7 days) with the actual IOS default of 1 day.

How to eliminate wrong answers

Option A is wrong because 3600 seconds (1 hour) is not the default; it is a common lease time for high-turnover environments like public Wi-Fi, but not Cisco's default. Option B is wrong because 43200 seconds (12 hours) is a typical lease time for some enterprise networks but is not the Cisco IOS-XE DHCP server default. Option D is wrong because 604800 seconds (7 days) is a longer lease time often used for stable networks with few changes, but it is not the default on Cisco IOS-XE.

441
MCQmedium

A network engineer is configuring Policy-Based Routing (PBR) on a Cisco router. The goal is to forward all HTTP traffic (TCP port 80) from the 10.1.1.0/24 subnet to next-hop 192.168.2.1. Which configuration sequence is correct?

A.Create a route-map with a match statement for TCP port 80 and a set statement for next-hop 192.168.2.1, then apply it globally with the ip policy route-map command.
B.Create a standard ACL that permits 10.1.1.0/24, reference it in a route-map with a match ip address statement, set the next-hop to 192.168.2.1, and apply the route-map to the outgoing interface with the ip policy route-map command.
C.Create a route-map with a match statement for IP address 10.1.1.0/24 and a set statement for next-hop 192.168.2.1, then apply it to the incoming interface with the ip policy route-map command.
D.Create an extended ACL that permits TCP port 80 from 10.1.1.0/24 to any, reference it in a route-map with a match ip address statement, set the next-hop to 192.168.2.1, and apply the route-map to the incoming interface with the ip policy route-map command.
AnswerD

This sequence correctly identifies HTTP traffic using an extended ACL, matches it in a route-map, sets the next-hop, and applies the route-map to the incoming interface. PBR uses route-maps with match statements based on ACLs to classify traffic, and the ip policy route-map command enables PBR on the interface. This meets the requirement precisely.

Why this answer

PBR requires an ACL to classify traffic based on source, destination, and port. An extended ACL can match TCP port 80. The route-map then matches the ACL and sets the next-hop.

Finally, the route-map is applied to the incoming interface with the ip policy route-map command. The other options either match all traffic, use a standard ACL that cannot match ports, or attempt to match ports directly in a route-map, which is not supported.

Exam trap

The trap here is using a standard ACL or trying to match ports directly in a route-map; PBR requires an extended ACL to match port numbers, and it is applied inbound on the interface.

442
MCQmedium

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP class-map: MANAGEMENT (match-all) 100 packets, 10000 bytes 5 minute offered rate 0 bps police: cir 8000 bps, bc 1500 bytes conformed 100 packets, 10000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop conformed 0 bps, exceed 0 bps Based on this output, which statement is correct?

A.All management traffic has been transmitted without any drops.
B.Management traffic is being dropped because the police rate is too low.
C.The CoPP policy is not applied because the control plane is not specified.
D.The class-map MANAGEMENT is not matching any traffic.
AnswerA

The police counters show 100 conformed packets transmitted and zero exceeded packets dropped, confirming every management packet stayed within the 8000 bps committed rate. The zero exceed rate and zero dropped bytes directly evidence that no management traffic was discarded, satisfying the stem's requirement to interpret the CoPP statistics accurately.

Why this answer

The output shows that all 100 packets matched by the MANAGEMENT class-map were conformed (100 packets, 10000 bytes) and the action for conformed traffic is 'transmit', with zero exceeded packets. This indicates that the policing rate of 8000 bps (CIR) was sufficient for the offered traffic, and no packets were dropped. The 'exceeded 0 packets' field confirms no drops occurred.

Exam trap

Cisco often tests the misconception that a low police rate automatically implies drops, but the trap here is that the output must be read carefully—'exceeded 0 packets' proves no drops occurred, regardless of the configured CIR.

How to eliminate wrong answers

Option B is wrong because the police rate of 8000 bps is not causing drops; the output shows 0 exceeded packets, meaning the traffic rate is within the CIR. Option C is wrong because the command 'show policy-map control-plane' explicitly displays the policy applied to the control plane, and the output confirms 'Service-policy input: CoPP' is active. Option D is wrong because the class-map MANAGEMENT is matching traffic, as evidenced by the 100 packets and 10000 bytes counted under that class.

443
MCQhard

An engineer configures mutual redistribution between OSPF and EIGRP on a PE router in an MPLS L3VPN. The engineer does not configure any route tagging or filtering. After a few minutes, the OSPF and EIGRP domains become unstable, with routes flapping and high CPU usage. What is the most likely explanation?

A.The mutual redistribution creates a routing loop because routes are redistributed back into the original protocol without any loop-prevention mechanism.
B.The OSPF and EIGRP administrative distances conflict, causing the router to prefer the wrong route.
C.The 'default-information originate' command is missing, so the redistributed routes are not advertised.
D.The 'subnets' keyword is missing in the OSPF redistribution command, causing only classful routes to be advertised.
AnswerA

Without tags or distribute-lists, each protocol's routes are fed into the other and then advertised straight back, so prefixes oscillate between domains. This mutual feedback loop causes continuous route flapping and elevated CPU until filtering or tagging breaks the cycle.

Why this answer

Mutual redistribution without route tagging or filtering can cause a routing loop. When OSPF routes are redistributed into EIGRP, and then those EIGRP routes are redistributed back into OSPF, the same prefixes can be learned from both protocols. Without a route tag or a filter to prevent re-redistribution, the router will continuously re-advertise the same routes, causing route flapping and high CPU.

This is a classic edge case in redistribution. The solution is to use route tags and filtering to prevent loops.

444
MCQhard

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS router. The engineer wants to route traffic from subnet 10.1.1.0/24 to a specific next-hop 192.168.1.1, while all other traffic uses the default route. The engineer configures a route map named PBR with a match statement for the subnet and a set statement for the next-hop, and applies it to the inbound interface of the subnet. However, traffic from 10.1.1.0/24 is still following the default route. What is the most likely reason?

A.The next-hop 192.168.1.1 is not reachable, so PBR is ignored.
B.The route map must be applied to the outbound interface instead of the inbound interface.
C.The route map is missing a 'permit' statement, causing all traffic to be denied.
D.The 'ip policy route-map' command is missing on the interface.
AnswerD

To enable PBR, the route map must be applied to the interface using the 'ip policy route-map' command. Without this command, the route map is not used, and traffic follows the normal routing table. The engineer configured the route map but may have forgotten to apply it to the interface, which is a common oversight.

Why this answer

Policy-based routing requires the route map to be applied to an interface using the 'ip policy route-map' command. Without this command, the route map is not evaluated, and traffic follows the standard routing table. The engineer created the route map but likely did not apply it to the interface.

Applying it to the inbound interface is correct for matching traffic from the subnet. The next-hop reachability is important but not the primary cause if PBR is not enabled.

Exam trap

The trap here is assuming that simply creating a route map is enough; it must be explicitly applied to an interface with 'ip policy route-map'.

445
MCQmedium

A network engineer is configuring DMVPN Phase 3 on a hub router. The hub must forward traffic directly between spokes without traversing the hub. Which command is required on the hub to enable this behavior?

A.ip nhrp map multicast dynamic
B.ip nhrp network-id 1
C.ip nhrp shortcut
D.ip nhrp redirect
AnswerD

The ip nhrp redirect command is essential for DMVPN Phase 3. It allows the hub to send NHRP redirect messages to spokes, informing them of a more optimal path directly to the destination spoke. Without this, spokes continue sending traffic through the hub, defeating the purpose of Phase 3. This command works in conjunction with ip nhrp shortcut on the spokes.

Why this answer

For DMVPN Phase 3, the hub must be configured with ip nhrp redirect to inform spokes about superior paths. When a spoke sends traffic to the hub for a destination reachable via another spoke, the hub responds with an NHRP redirect, prompting the originating spoke to initiate a direct tunnel. The spoke must have ip nhrp shortcut to act on the redirect.

Together, these commands enable dynamic direct spoke-to-spoke tunnels.

Exam trap

The trap here is confusing the roles of ip nhrp redirect and ip nhrp shortcut, placing the spoke command on the hub or vice versa.

446
MCQeasy

Which NetFlow version is the default export format when using Flexible NetFlow with the 'record netflow ipv4 original-input' command?

A.NetFlow version 5
B.NetFlow version 9
C.IPFIX (NetFlow version 10)
D.NetFlow version 1
AnswerB

Flexible NetFlow exports records in version 9 format by default, which is template-based and extensible. Version 5 is fixed-format and only applies to traditional NetFlow, so it cannot carry the flexible record's custom field definitions.

Why this answer

Flexible NetFlow's 'record netflow ipv4 original-input' uses the predefined 'netflow ipv4 original-input' record, which exports in NetFlow version 9 format by default on Cisco IOS/IOS-XE platforms. Version 9 is template-based and is the native export for Flexible NetFlow; IPFIX must be explicitly configured with 'export-protocol ipfix'.

Exam trap

300-410 often tests the assumption that Flexible NetFlow defaults to IPFIX because it is newer — candidates must remember v9 is the default and IPFIX requires explicit configuration.

How to eliminate wrong answers

Option A is wrong because NetFlow v5 is a fixed-format legacy export used by traditional (non-flexible) NetFlow and cannot carry the extensible fields of Flexible NetFlow records. Option C is wrong because IPFIX (NetFlow v10) is not the default — it requires the explicit 'export-protocol ipfix' command under the flow exporter configuration. Option D is wrong because NetFlow v1 is an obsolete, fixed-format version that predates Flexible NetFlow and is not supported as its export default.

447
MCQhard

A network administrator is configuring AAA on a Cisco IOS router using TACACS+. The requirement is that if the TACACS+ server is unreachable, the router should allow administrative access using the local username and password configured on the router. Which configuration accomplishes this?

A.aaa authentication login default group tacacs+ enable
B.aaa authentication login default group tacacs+ local
C.aaa authentication login default group tacacs+ if-needed
D.aaa authentication login default group tacacs+ none
AnswerB

This command configures the default method list for login authentication to first attempt TACACS+ and then fall back to the local username database if the TACACS+ server is unreachable. The 'local' keyword ensures that local authentication is used as a backup, satisfying the requirement.

Why this answer

To configure AAA authentication with TACACS+ and a fallback to the local username database, you use the 'aaa authentication login default group tacacs+ local' command. The 'local' keyword specifies that the router should use its local username and password configuration if the TACACS+ server does not respond. This provides a secure fallback method, ensuring administrative access is not lost during server outages.

Exam trap

The trap here is confusing the 'local' keyword with 'enable' or 'none' for fallback authentication.

448
MCQeasy

A network administrator is configuring a Cisco IOS router to act as a DHCP server for a LAN segment. The administrator wants to exclude a range of IP addresses from being assigned to clients because those addresses are statically assigned to servers and printers. Which command should be used to accomplish this?

A.ip dhcp pool LAN network 192.168.1.0 255.255.255.0 excluded-address 192.168.1.10 192.168.1.20
B.ip dhcp excluded-address 192.168.1.10 192.168.1.20 255.255.255.0
C.ip dhcp excluded-address 192.168.1.10 192.168.1.20
D.ip dhcp pool STATIC host 192.168.1.10 255.255.255.0
AnswerC

The 'ip dhcp excluded-address' command specifies a range of IP addresses that the DHCP server will not assign to clients. This is the correct way to reserve addresses for static devices such as servers and printers, ensuring they are not dynamically allocated.

Why this answer

To prevent the DHCP server from assigning a specific range of addresses, the 'ip dhcp excluded-address' command must be used in global configuration mode. This command takes a start and end IP address (or a single IP) and ensures those addresses are not offered to clients. The other options either use incorrect syntax or place the command in the wrong configuration mode.

Exam trap

The trap here is confusing the global 'ip dhcp excluded-address' command with the pool-level 'host' command or misplacing the exclusion within the pool configuration.

449
MCQmedium

Given the following partial configuration on router R1: ip sla 10 icmp-echo 192.168.1.1 source-ip 10.0.0.1 frequency 10 ip sla schedule 10 life forever start-time now Which statement best describes the effect of this configuration?

A.It sends ICMP echo requests from 10.0.0.1 to 192.168.1.1 every 10 seconds.
B.It sends ICMP echo requests from 192.168.1.1 to 10.0.0.1 every 10 seconds.
C.It sends ICMP echo requests every 10 seconds but only after the first successful reply.
D.It sends ICMP echo requests only once and then stops.
AnswerA

The `icmp-echo` operation targets 192.168.1.1, while `source-ip 10.0.0.1` forces the probe's source address, so each echo request originates from 10.0.0.1. The `frequency 10` interval repeats the probe every ten seconds, and `start-time now` with `life forever` begins it immediately and indefinitely.

Why this answer

The ip sla 10 configuration defines an ICMP echo operation with destination 192.168.1.1 and source-ip 10.0.0.1, with a frequency of 10 seconds. The ip sla schedule 10 life forever start-time now activates it immediately and indefinitely, so R1 sends ICMP echo requests from 10.0.0.1 to 192.168.1.1 every 10 seconds.

Exam trap

300-410 often tests source/destination direction in ip sla icmp-echo — candidates reverse them (B) because the command syntax places the destination first and source-ip second, which is counterintuitive to some readers.

How to eliminate wrong answers

Option B is wrong because it reverses the source and destination — the icmp-echo command specifies the destination (192.168.1.1) and source-ip specifies the source (10.0.0.1), not the other way around. Option C is wrong because the frequency timer starts immediately upon scheduling, not after the first successful reply; there is no dependency on reply success for initiating probes. Option D is wrong because 'life forever' explicitly makes the operation run indefinitely, not once.

450
MCQeasy

A network engineer runs the following command on Router R1: R1# show ip dhcp relay information trusted Interface Trusted GigabitEthernet0/1 Yes GigabitEthernet0/2 No Based on this output, which statement is correct?

A.DHCP relay information is trusted on GigabitEthernet0/1, so option 82 packets are accepted on that interface.
B.DHCP relay information is trusted on both interfaces.
C.DHCP relay information is not configured on any interface.
D.DHCP relay information is trusted on GigabitEthernet0/2, so option 82 packets are dropped.
AnswerA

Trusted interfaces accept DHCP packets carrying option 82 relay agent information; untrusted ones discard them. GigabitEthernet0/1 shows Trusted Yes, so option 82 packets arriving there are accepted and forwarded, satisfying the stem's requirement. GigabitEthernet0/2, marked No, would drop such packets instead.

Why this answer

The command 'show ip dhcp relay information trusted' displays the trust status of each interface for DHCP relay information (option 82). When an interface is marked as 'Yes' under the Trusted column, it means the router will accept and forward DHCP packets that already contain option 82 information from that interface. Therefore, on GigabitEthernet0/1, option 82 packets are accepted.

Exam trap

Cisco often tests the misconception that 'trusted' means the interface is trusted to send DHCP requests, when in fact it means the interface is trusted to receive and forward packets that already contain option 82 information.

How to eliminate wrong answers

Option B is wrong because the output clearly shows that GigabitEthernet0/2 is marked as 'No', indicating it is not trusted, so both interfaces are not trusted. Option C is wrong because the output explicitly shows that DHCP relay information is configured and trusted on at least one interface (GigabitEthernet0/1). Option D is wrong because GigabitEthernet0/2 is not trusted (marked 'No'), and on untrusted interfaces, option 82 packets are dropped, not accepted; the statement incorrectly says option 82 packets are dropped on a trusted interface.

Page 5

Page 6 of 19

Page 7