Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 451–525

1401 questions total · 19pages · All types, answers revealed

Page 6

Page 7 of 19

Page 8
451
MCQmedium

A network engineer is deploying DMVPN Phase 3 with NHRP and wants spoke-to-spoke traffic to be built directly between spokes without traversing the hub after initial resolution. On the hub router, the engineer issues the command 'ip nhrp redirect' on the tunnel interface and 'ip nhrp shortcut' on each spoke tunnel interface. After configuration, spokes can reach the hub but spoke-to-spoke traffic still hairpins through the hub. Which additional configuration is required on the spoke routers for the shortcut path to be installed?

A.Enable 'ip nhrp map multicast dynamic' on the spoke tunnel interfaces.
B.Enable 'ip nhrp network-id' with the same value on all spoke tunnel interfaces.
C.Ensure the routing protocol on the spokes has a route to the destination spoke's tunnel network, typically via a summary or default from the hub, so traffic triggers NHRP resolution.
D.Configure the tunnel interface with 'ip nhrp nhs <hub-NBMA>' so the spoke registers to the hub.
AnswerC

For NHRP shortcut to install a direct path, the spoke must have a route pointing to the destination prefix through the tunnel, causing the packet to trigger an NHRP resolution request. Without reachability to the destination spoke subnet (often via a hub summary or default route), no resolution is triggered and traffic continues to hairpin through the hub.

Why this answer

DMVPN Phase 3 shortcut switching requires the spoke to have a route covering the remote spoke prefix so that forwarded traffic triggers an NHRP resolution. The hub uses 'ip nhrp redirect' to notify spokes of a better path, and the spoke uses 'ip nhrp shortcut' to act on that notification. Without a route toward the destination spoke network, the spoke never originates the resolution and the shortcut never installs.

Exam trap

The trap here is assuming that enabling 'ip nhrp shortcut' and 'ip nhrp redirect' alone is sufficient, when the spoke still needs a route covering the destination spoke prefix to trigger resolution.

452
Drag & Dropmedium

Drag and drop the steps to enable and verify RESTCONF on IOS-XE into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

RESTCONF requires enabling the HTTPS server first, then the RESTCONF service, followed by authentication configuration, verifying the interface, and finally testing via a REST client.

453
MCQmedium

A network engineer is configuring a Cisco router to support MPLS Layer 3 VPNs. The engineer needs to enable the router to exchange VPNv4 routes with a provider edge (PE) router. Which address family must be configured under the BGP routing process to support this?

A.address-family ipv4 unicast
B.address-family ipv6 unicast
C.address-family vpnv4 unicast
D.address-family ipv4 vrf
AnswerC

The VPNv4 unicast address family is specifically designed to carry MPLS Layer 3 VPN routes. It includes the route distinguisher and route target extended communities necessary for VPN segmentation. Configuring this address family under BGP allows the PE routers to exchange VPNv4 prefixes, enabling MPLS L3VPN functionality. This is the correct address family for this scenario.

Why this answer

MPLS Layer 3 VPNs rely on BGP VPNv4 address family to exchange VPN routes between PE routers. The VPNv4 address family carries the route distinguisher and route target attributes that identify the VPN membership. Other address families serve different purposes, such as IPv4 unicast for global routing or IPv4 VRF for per-VRF routing, but not for PE-to-PE VPN route exchange.

Exam trap

The trap here is confusing the per-VRF IPv4 address family with the VPNv4 address family used for PE-to-PE route exchange.

454
Multi-Selecthard

A network engineer is implementing GET VPN using GDOI on Cisco IOS routers. The key server must distribute the group policy, and the group members must register and receive rekey messages. The engineer needs to verify which components are required for the group members to successfully join the group and decrypt traffic. (Choose two.)

Select 2 answers
A.Group members must be configured with the group identity and a matching GDOI group configuration referencing the key server.
B.Group members must have a static VRF configured to isolate the GET VPN traffic from the global routing table.
C.Group members must be configured with the same ACL as the key server to define interesting traffic for the encryption policy.
D.Group members must have IKEv2 configured with a certificate authority to authenticate to the key server.
E.Group members must successfully complete GDOI registration with the key server to obtain the group's rekey and data encryption keys.
AnswersA, E

Each group member needs a 'crypto gdoi group' configuration that includes the group identity number and the key server address, plus a 'crypto map' or 'crypto gdoi' reference. Without this, the member cannot initiate registration with the key server or match the group policy, so it never receives the group keys and cannot decrypt GET VPN traffic.

Why this answer

GET VPN GDOI group members must be configured with the correct group identity and key server reference, and they must successfully register to receive the KEK and TEK from the key server. These two elements are fundamental: the local group configuration identifies which key server to contact, and successful registration provides the keys needed to decrypt the group's encrypted traffic. Authentication uses IKEv1 rather than IKEv2 with a CA, and the encryption ACL comes from the downloaded policy.

Exam trap

The trap here is assuming GET VPN requires IKEv2 with certificates and manual ACLs, when GDOI actually uses IKEv1 for registration and distributes the policy from the key server.

455
MCQmedium

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast summary BGP router identifier 192.168.1.1, local AS number 65001 BGP table version is 10, main routing table version 10 Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 10.1.1.2 4 65002 1200 1200 10 0 0 01:00:00 5 10.2.2.2 4 65003 0 0 0 0 0 never Active Based on this output, what is the problem with the neighbor 10.2.2.2?

A.The neighbor is not reachable or is not configured to accept BGP connections.
B.The neighbor is in Idle state because of a hold timer expiry.
C.The neighbor has received 5 prefixes, indicating a successful session.
D.The BGP table version is 10, meaning there is a routing loop.
AnswerA

State 'Active' with zero messages received or sent means R1 is repeatedly attempting the TCP session on port 179 but receiving no response. Either the neighbour address is unreachable, or the peer lacks a matching neighbour statement or is not listening for BGP connections.

Why this answer

The 'Active' state in BGP indicates that the router is actively trying to establish a TCP connection to the neighbor but has not yet succeeded. This typically occurs because the neighbor is unreachable (no route to the destination IP), the neighbor is not configured to accept BGP connections (e.g., no BGP process or incorrect ACL), or a firewall is blocking TCP port 179. The output shows 0 messages sent/received and 'never' uptime, confirming no session has ever been established.

Exam trap

Cisco often tests the distinction between 'Idle' and 'Active' states, where candidates mistakenly assume 'Active' means the session is up or that prefixes are being exchanged, when in fact it indicates a failed or pending TCP connection attempt.

How to eliminate wrong answers

Option B is wrong because the 'Idle' state is the initial state before any connection attempt, and hold timer expiry would cause the session to go to 'Idle' after being established, not remain in 'Active' with zero message counts. Option C is wrong because the neighbor 10.2.2.2 has 0 prefixes received (PfxRcd column shows 0), not 5; the 5 prefixes belong to neighbor 10.1.1.2. Option D is wrong because the BGP table version being 10 is a normal operational value indicating the number of changes processed, not an indicator of a routing loop; routing loops are detected via AS-path loop prevention, not table version.

456
MCQhard

An engineer configures a DMVPN Phase 2 network. Spoke routers can communicate with the hub, but spoke-to-spoke traffic does not trigger a direct tunnel. Which is the most likely explanation?

A.The hub router is missing the 'ip nhrp redirect' command.
B.The spoke routers have 'ip nhrp shortcut' configured.
C.The tunnel mode is set to gre multipoint on the spokes.
D.The NHRP authentication is mismatched.
AnswerA

Correct. Redirect is required for Phase 2 spoke-to-spoke.

Why this answer

In a DMVPN Phase 2 network, spoke-to-spoke tunnels are triggered dynamically when a spoke receives an NHRP redirect from the hub. The 'ip nhrp redirect' command on the hub router enables it to send redirect messages to spokes, informing them of a more direct path to another spoke. Without this command, the hub forwards traffic between spokes but never signals the spokes to build a direct tunnel, so spoke-to-spoke traffic continues to traverse the hub.

Exam trap

Cisco often tests the distinction between Phase 2 and Phase 3 DMVPN behaviors, and the trap here is that candidates confuse the spoke's 'ip nhrp shortcut' (which is required for Phase 2) with the hub's 'ip nhrp redirect' (which is also required), assuming that only one of them is necessary for spoke-to-spoke tunnels.

How to eliminate wrong answers

Option B is wrong because 'ip nhrp shortcut' is configured on the spoke routers to enable them to install NHRP-learned direct routes; without it, even if a redirect is received, the spoke won't create the shortcut. Option C is wrong because setting the tunnel mode to 'gre multipoint' on spokes is standard for Phase 2 (and Phase 3) to allow multiple mGRE tunnels; this does not prevent spoke-to-spoke tunnel initiation. Option D is wrong because NHRP authentication mismatch would prevent NHRP registrations and resolutions entirely, breaking all communication (including hub-to-spoke), not just spoke-to-spoke direct tunnels.

457
MCQmedium

Which OSPF LSA type is used to advertise prefixes from other areas into the backbone area?

A.Type 1 (Router LSA)
B.Type 2 (Network LSA)
C.Type 3 (Summary LSA)
D.Type 5 (External LSA)
AnswerC

Type 3 Summary LSAs are generated by ABRs to advertise inter-area prefixes, including networks from non-backbone areas, into the backbone. This flooding of prefixes between areas satisfies the requirement to advertise other-area prefixes into area 0.

Why this answer

Type 3 Summary LSAs are generated by Area Border Routers (ABRs) to advertise inter-area prefixes — networks learned in one area — into other areas, including the backbone (Area 0). When an ABR connects Area 0 to a non-backbone area, it converts Type 1/2 topology information from one area into Type 3 LSAs flooded into the other, enabling prefix reachability across area boundaries. This is the fundamental mechanism of OSPF's two-tier hierarchical design.

Exam trap

The trap here is confusing the LSA types that operate within an area (Type 1 and 2) with those that cross area boundaries (Type 3) and those that cross the OSPF domain boundary (Type 5) — candidates often pick Type 5 because 'external' sounds like 'other areas', but external means outside OSPF entirely.

How to eliminate wrong answers

Option A is wrong because Type 1 Router LSAs are flooded only within a single area and describe a router's links and interface states to that area's topology — they are never used to carry prefixes across area boundaries. Option B is wrong because Type 2 Network LSAs are generated by the DR on multi-access segments and are also scoped to a single area, representing the transit subnet and its attached routers, not inter-area prefix advertisement. Option D is wrong because Type 5 External LSAs are generated by ASBRs to advertise routes redistributed from outside the OSPF domain (or from other protocols), not prefixes from other OSPF areas — those are internal to the OSPF autonomous system.

458
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. Spokes are behind NAT devices and have dynamically assigned public IP addresses. The engineer wants to ensure that spoke-to-spoke traffic can be established directly without traversing the hub. Which technology should be implemented on the hub to achieve this?

A.IPsec tunnel protection
B.NHRP shortcut
C.Multicast replication
D.NHRP redirect
AnswerD

NHRP redirect is a key component of DMVPN Phase 3. The hub sends an NHRP redirect message to the spoke, informing it that a more optimal path exists to the destination spoke. This allows the spoke to initiate a direct tunnel to the other spoke using NHRP resolution, bypassing the hub for data traffic.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to signal spokes about a better path to another spoke. The spoke then uses NHRP shortcut to establish a direct tunnel. The question asks what to implement on the hub, so NHRP redirect is correct.

NHRP shortcut is on the spoke, IPsec tunnel protection is for encryption, and multicast replication is for routing protocol support.

Exam trap

The trap here is confusing the roles of NHRP redirect and NHRP shortcut: redirect is on the hub, shortcut is on the spoke.

459
MCQmedium

A network engineer is troubleshooting a route redistribution issue between RIP and OSPF. Router R1 runs both RIP and OSPF, and redistributes RIP routes into OSPF. The engineer notices that RIP routes are not appearing in the OSPF database on neighboring routers. The show ip ospf database external command on a neighbor shows no external routes from R1. The redistribute rip command is configured under OSPF on R1. What is the most likely cause?

A.The redistribute rip command under OSPF is missing the subnets keyword.
B.RIP has a higher administrative distance than OSPF.
C.The OSPF process on R1 has a distribute-list blocking these routes.
D.The RIP process on R1 is not running.
AnswerA

OSPF redistributes only classful networks unless the subnets keyword is supplied, so RIP routes on subnetted addresses are silently omitted from external LSAs. The empty external database confirms this, since the neighbour receives no type-5 advertisements from R1.

Why this answer

When redistributing routes into OSPF, the subnets keyword is required to include subnetted routes. Without it, only classful network routes are redistributed, so RIP routes that are subnetted (e.g., /24) will not appear as external LSAs in the OSPF database. The symptom of no external routes in the OSPF database on neighbors, despite the redistribute rip command, points directly to the missing subnets keyword.

Exam trap

300-410 often tests the subnets keyword omission as the root cause for missing redistributed routes, and candidates incorrectly blame administrative distance or distribute-lists.

How to eliminate wrong answers

Option B is wrong because administrative distance affects route selection on the local router, not the redistribution of routes into OSPF; it would not prevent external LSAs from being generated. Option C is wrong because a distribute-list blocking routes would typically filter routes from being installed or advertised, but the question states the redistribute command is configured and the issue is missing external routes; a distribute-list could cause this, but it is less likely than the common subnets omission, and the question asks for the most likely cause. Option D is wrong because if RIP were not running, the redistribute command would have no routes to redistribute, but the scenario implies RIP is operational and routes exist; the focus is on OSPF redistribution behavior.

460
MCQhard

What is the default metric for an IPv6 static route redistributed into OSPFv3?

A.0
B.1
C.20
D.10
AnswerC

OSPFv3 uses a default metric of 20 for redistributed routes.

Why this answer

When an IPv6 static route is redistributed into OSPFv3, OSPFv3 assigns a default metric of 20 to external routes (type E1 or E2). This is consistent with OSPFv2 behavior, where redistributed routes (including static routes) receive a default metric of 20 unless explicitly overridden with the `metric` keyword under the `redistribute` command. Option C is correct because the default metric for redistributed static routes in OSPFv3 is 20.

Exam trap

The trap here is that candidates often confuse the default metric for OSPFv3 redistributed routes (20) with the default metric for OSPFv3 intra-area routes (1) or with the default metric used by other routing protocols like EIGRP (10), leading them to select the wrong option.

How to eliminate wrong answers

Option A is wrong because a metric of 0 is not the default for redistributed static routes in OSPFv3; a metric of 0 would imply a directly connected route or a special case, but OSPFv3 does not assign 0 to redistributed routes. Option B is wrong because a metric of 1 is the default for OSPFv3 intra-area routes (e.g., for loopback interfaces or directly connected networks), not for redistributed external routes. Option D is wrong because a metric of 10 is the default for redistributed routes in EIGRP, not OSPFv3; OSPFv3 uses 20 as the default for external routes.

461
MCQhard

A network administrator is deploying MPLS Layer 3 VPNs across a service provider backbone. The provider uses OSPF as the IGP and MP-BGP for VPNv4 route distribution. The administrator notices that VPNv4 routes are not being advertised between PE routers. Which configuration step is most likely missing on the PE routers?

A.Configuring MPLS LDP on all interfaces between PE and P routers
B.Enabling OSPF on the PE-CE links with the correct area ID
C.Configuring route reflectors or full mesh iBGP peering between PE routers
D.Activating the VPNv4 address family under the BGP routing process and configuring the PE routers as neighbors
AnswerD

For VPNv4 routes to be exchanged, the BGP process must have the VPNv4 address family activated and the PE routers must be configured as BGP neighbors within that address family. Without this, MP-BGP will not carry VPNv4 NLRIs. This is the fundamental step for MPLS L3VPN route distribution.

Why this answer

MPLS L3VPN relies on MP-BGP to distribute VPNv4 routes between PE routers. The VPNv4 address family must be activated under the BGP process, and PE routers must be configured as neighbors within that address family. Without this, VPNv4 NLRIs are not exchanged, and customer routes cannot be propagated across the provider backbone.

Exam trap

The trap here is assuming that MPLS LDP or OSPF configuration alone is sufficient for VPNv4 route exchange, overlooking the need for BGP address family activation.

462
MCQeasy

What is the default CoPP policy on a Cisco IOS-XE router if no service-policy is applied to the control-plane?

A.All control-plane traffic is rate-limited to 64000 bps.
B.Only management traffic (SSH, Telnet) is rate-limited to 32000 bps.
C.No CoPP policy is applied; all control-plane traffic is processed without rate-limiting.
D.A default policy is applied that drops all traffic exceeding 128000 bps.
AnswerC

Without a control-plane service-policy, IOS-XE applies no CoPP policing, so all traffic destined to the route processor is forwarded to the CPU unpoliced. This satisfies the stem's "no service-policy applied" constraint: no default class-maps or policers exist, leaving control-plane traffic unrate-limited until you attach a policy manually.

Why this answer

C is correct because Cisco IOS-XE routers do not apply any default CoPP policy to the control-plane. Without an explicit 'service-policy' configuration under the 'control-plane' configuration mode, all control-plane traffic (including routing protocols, management traffic, and keepalives) is processed by the route processor without any rate-limiting or filtering. CoPP is an optional feature that must be manually configured to protect the control plane from excessive traffic.

Exam trap

Cisco often tests the misconception that CoPP has a built-in default policy or that management traffic is automatically rate-limited, when in fact no CoPP policy is applied unless explicitly configured under the control-plane with a service-policy.

How to eliminate wrong answers

Option A is wrong because there is no default rate-limit of 64000 bps; CoPP policies are not applied by default, and any such value would require explicit configuration. Option B is wrong because management traffic is not automatically rate-limited to 32000 bps; without a CoPP policy, all traffic, including SSH and Telnet, is processed normally. Option D is wrong because no default policy drops traffic at 128000 bps; CoPP policies must be explicitly defined and applied to enforce any drop or rate-limit behavior.

463
Multi-Selecthard

Which THREE symptoms indicate that route summarization may be causing routing issues in a network? (Choose THREE.)

Select 3 answers
A.Suboptimal routing paths are observed for certain destinations.
B.Traffic to some subnets is dropped (black hole) even though the summary route exists.
C.Routing loops occur due to less specific summary routes pointing to routers that lack the specific subnet.
D.High CPU utilization on routers due to frequent SPF calculations.
E.Duplicate IP addresses are detected in the network.
AnswersA, B, C

Summarisation advertises a less specific aggregate, so routers may forward traffic toward a summary-advertising neighbour that is not on the optimal path to the actual subnet. The specific longer-match information is hidden, producing suboptimal forwarding for those destinations.

Why this answer

Option A is correct because route summarization advertises a single aggregate prefix that hides the individual component subnets, so a router may forward traffic toward the summary's next hop even when a more optimal path exists for a specific destination, producing suboptimal routing paths. Option B is correct because if a summary route (e.g., 10.0.0.0/16) is advertised but one of its constituent subnets (e.g., 10.0.5.0/24) does not actually exist or is not reachable on the advertising router, packets matching the summary are forwarded and then dropped, creating a black hole. Option C is correct because less-specific summary routes can point traffic back toward a router that only has the summary and not the specific subnet, causing packets to bounce between routers and form a routing loop.

Option D is not correct because frequent SPF recalculations and high CPU are typically caused by network instability such as flapping links or adjacencies, not by summarization itself. Option E is not correct because duplicate IP addresses are an addressing/configuration error and are unrelated to route summarization behavior.

Exam trap

300-410 often tests whether candidates can distinguish summarization symptoms (black holes, suboptimal paths, loops) from unrelated symptoms (SPF CPU spikes, duplicate IPs), so picking CPU or duplicate-IP options reflects a misunderstanding of what summarization actually breaks.

464
MCQeasy

Which BGP message type is sent when a fatal error is detected, causing the BGP session to close?

A.OPEN
B.UPDATE
C.NOTIFICATION
D.KEEPALIVE
AnswerC

NOTIFICATION carries the error code and subcode identifying the fatal condition, then the session tears down immediately. It is the only BGP message type designed to report errors and terminate the peering, satisfying the stem's requirement that the session closes on detection of a fatal error.

Why this answer

The BGP NOTIFICATION message is sent when a fatal error is detected, such as a hold timer expiration, a malformed attribute, or a configuration mismatch. Upon sending or receiving a NOTIFICATION, the BGP session is immediately closed. This is defined in RFC 4271.

Exam trap

The trap is confusing KEEPALIVE with NOTIFICATION — candidates may think KEEPALIVE closes the session when it fails, but KEEPALIVE only maintains the session; NOTIFICATION is the explicit error message that triggers closure.

How to eliminate wrong answers

Option A is wrong because the OPEN message is used to initiate a BGP session and negotiate parameters like hold time and BGP identifier; it does not close the session. Option B is wrong because the UPDATE message is used to advertise or withdraw routes, not to signal errors. Option D is wrong because the KEEPALIVE message is sent periodically to maintain the session and reset the hold timer, not to close it.

465
Multi-Selectmedium

A network administrator is troubleshooting an 802.1X deployment on a Cisco switch. Users report that they cannot authenticate and are placed into a guest VLAN. The administrator suspects that the switch is not receiving EAPOL packets from the supplicants. Which two actions should the administrator take to verify that EAPOL packets are being received and processed on the switch? (Choose two.)

Select 2 answers
A.Use the 'show authentication sessions interface' command to view the session status and method.
B.Enable 'debug dot1x all' and observe the debug output for EAPOL packet reception.
C.Use the 'show dot1x interface' command to check the authentication status and EAPOL statistics.
D.Check the 'show mac address-table interface' command to see if the supplicant's MAC address is learned.
E.Use the 'show radius statistics' command to verify RADIUS server reachability.
AnswersB, C

The 'debug dot1x all' command provides real-time debugging information about 802.1X events, including EAPOL packet reception, authentication exchanges, and errors. It is a powerful tool to confirm whether EAPOL packets are being received and processed by the switch.

Why this answer

The two correct actions are using 'show dot1x interface' and enabling 'debug dot1x all'. These commands provide direct visibility into EAPOL packet reception and processing on the switch. The other options either show session information that doesn't confirm EAPOL reception or focus on RADIUS or MAC address tables, which are not specific to verifying EAPOL packets from the supplicant.

Exam trap

The trap here is assuming that seeing the MAC address in the MAC address table means EAPOL is working, but EAPOL frames are not learned in the MAC table.

466
MCQeasy

What is the maximum hop count for a route in RIP?

A.15
B.16
C.255
D.32
AnswerA

RIP defines infinity as 16 hops, so a destination becomes unreachable once its metric reaches that value. This caps valid routes at 15 hops, satisfying the question's constraint by preventing routing loops from counting indefinitely. The 15-hop limit therefore represents the maximum usable hop count.

Why this answer

RIP (Routing Information Protocol) uses a maximum hop count of 15 to prevent routing loops. A route with a hop count of 16 is considered unreachable (infinite metric). This limit is defined in RFC 1058 for RIPv1 and RFC 2453 for RIPv2, ensuring that the network diameter remains small and loop-free.

Exam trap

Cisco often tests the distinction between the maximum hop count (15) and the unreachable metric (16), tricking candidates who think 16 is a valid route metric rather than a poison value.

How to eliminate wrong answers

Option B is wrong because a hop count of 16 in RIP is not a valid route metric; it is used to signify an unreachable route (infinite metric) and triggers route poisoning. Option C is wrong because 255 is the maximum TTL value in IP packets, not the RIP hop count limit; RIP uses a 4-bit metric field, which can only represent values 0–15. Option D is wrong because 32 is the maximum prefix length for IPv4 subnets, not a RIP hop count; RIP metrics are limited to 15 hops.

467
MCQmedium

A network administrator is troubleshooting a site-to-site IPsec VPN between two Cisco IOS routers using IKEv1. Phase 1 completes successfully, but Phase 2 fails with the message 'QM_IDLE' and no IPSec SA is established. The administrator verifies that the transform sets on both peers contain matching encryption and hash algorithms. Which configuration mismatch is the most likely cause of the Phase 2 failure?

A.The ISAKMP policy priority numbers are different on the two peers.
B.The crypto ACLs on the two peers do not mirror each other for the interesting traffic.
C.The IKEv1 aggressive mode is enabled on one peer but not the other.
D.The pre-shared keys on the two peers do not match.
AnswerB

In IKEv1 main mode, the Phase 2 quick mode negotiation uses the crypto ACL to identify the traffic to protect, and the proxy IDs must be mirror images. If the source and destination subnets are reversed or mismatched, the peers cannot agree on the IPSec SA selectors, causing quick mode to fail even though Phase 1 is up and transform sets match.

Why this answer

In IKEv1, Phase 2 quick mode negotiates the IPSec SA using proxy identities derived from the crypto ACLs. These ACLs must be mirror images between peers so that the source and destination selectors align. If they do not mirror each other, quick mode fails and no IPSec SA is created, even though Phase 1 is established and transform sets match.

Exam trap

The trap here is focusing on transform set mismatches or Phase 1 parameters when the symptom of a working Phase 1 with a failing Phase 2 points to proxy identity or ACL mirroring issues.

468
MCQmedium

A network engineer is configuring DMVPN Phase 3 with IKEv2. The hub router is a Cisco IOS XE device, and the goal is to allow spoke-to-spoke traffic to bypass the hub after initial registration. Which command must be configured on the hub to enable NHRP redirects?

A.ip nhrp map multicast dynamic
B.ip nhrp redirect
C.ip nhrp network-id 1
D.ip nhrp shortcut
AnswerB

The 'ip nhrp redirect' command is required on the hub in DMVPN Phase 3 to enable NHRP redirect messages. When a spoke sends traffic to the hub for a destination behind another spoke, the hub replies with an NHRP redirect, allowing the spoke to initiate a direct tunnel to the destination spoke. This is a key component of Phase 3 along with 'ip nhrp shortcut' on the spokes.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirects to inform spokes about a better path to reach another spoke. The 'ip nhrp redirect' command on the hub enables this behavior. Combined with 'ip nhrp shortcut' on the spokes, it allows dynamic direct tunnels.

Without the redirect on the hub, spokes continue to route traffic through the hub even if a direct path exists.

Exam trap

The trap here is confusing the roles of 'ip nhrp redirect' and 'ip nhrp shortcut', placing the spoke-side command on the hub.

469
MCQmedium

A network engineer is deploying MPLS Layer 3 VPNs. The engineer must ensure that the PE routers can forward VPN traffic correctly. The following configuration is applied on a PE router: ip vrf CUSTOMER rd 65000:1 route-target export 65000:1 route-target import 65000:1 ! interface GigabitEthernet0/1 ip vrf forwarding CUSTOMER ip address 192.168.1.1 255.255.255.0 After configuration, the engineer notices that the CE router cannot reach remote sites. The MPLS core is operational, and MP-BGP is configured. What is the most likely missing configuration?

A.The route-target must be configured under the interface GigabitEthernet0/1.
B.The PE router must have a route distinguisher configured under the BGP process.
C.The PE router must have a loopback interface configured and used for BGP peering.
D.The BGP process must be configured with address-family ipv4 vrf CUSTOMER and the necessary redistribution or network statements.
AnswerD

For MPLS L3 VPN, the PE router must have a BGP address-family for each VRF to exchange routes with other PEs. Without address-family ipv4 vrf CUSTOMER, the PE will not advertise or receive VPN routes for that customer, preventing connectivity. The VRF configuration alone is insufficient.

Why this answer

In MPLS L3 VPN, the PE router must have a BGP address-family ipv4 vrf for each VRF to exchange VPN routes with other PE routers. The VRF definition and interface assignment are necessary but not sufficient. Without the address-family configuration and route redistribution or network statements, the PE will not advertise the customer routes, and remote sites will be unreachable.

Exam trap

The trap here is focusing on the VRF and interface configuration while overlooking the need for a BGP address-family per VRF to exchange VPN routes.

470
MCQeasy

A network engineer runs the following command to verify DHCPv4 pool configuration on router R1: R1# show ip dhcp pool DHCP_POOL Output: Pool DHCP_POOL : Utilization mark (high/low) : 100 / 0 Subnet size (first/next) : 0 / 0 Total addresses : 254 Leased addresses : 100 Pending event : none 1 subnet is currently in the pool : Current index IP address range Leased addresses 192.168.1.1 192.168.1.1 - 192.168.1.254 100 What does this output indicate?

A.The DHCP pool has 254 addresses available, and 100 are currently leased.
B.The DHCP pool is exhausted because 100 addresses are leased.
C.The DHCP server is using a database agent to store leases.
D.The DHCP pool has a utilization mark of 100%, meaning it is full.
AnswerA

The pool spans 192.168.1.1–192.168.1.254, giving 254 usable host addresses, of which 100 are leased. This directly satisfies the stem's request to interpret the "Total addresses" and "Leased addresses" counters, confirming current utilisation without indicating exhaustion or conflict.

Why this answer

The output shows 'Total addresses: 254' and 'Leased addresses: 100', meaning the pool contains 254 total addresses (the /24 subnet) and 100 are currently leased, leaving 154 available. The 'Utilization mark (high/low): 100 / 0' indicates the thresholds for alerts, not actual usage, and the pool is not exhausted.

Exam trap

Cisco often tests the distinction between the 'Utilization mark' (a configurable threshold for alerts) and actual pool utilization, causing candidates to misinterpret the 100% high mark as meaning the pool is full.

How to eliminate wrong answers

Option B is wrong because the pool is not exhausted; only 100 of 254 addresses are leased, so 154 are still available. Option C is wrong because the output does not show any database agent configuration; the 'Pending event: none' line refers to pending DHCP events, not database agent status. Option D is wrong because the utilization mark of 100% is the high watermark threshold for alerts, not the actual utilization percentage; the actual utilization is 100/254 ≈ 39.4%.

471
MCQeasy

A network engineer is troubleshooting a VRF-Lite deployment where a router is configured with VRF_ORANGE. The engineer attempts to configure a static route in VRF_ORANGE using the command 'ip route vrf VRF_ORANGE 192.168.10.0 255.255.255.0 10.1.1.1', but the route does not appear in the routing table. The 'show ip route vrf VRF_ORANGE' does not show the static route. What is the most likely cause?

A.The next-hop IP address 10.1.1.1 is not reachable in VRF_ORANGE.
B.The 'ip classless' command is disabled.
C.The static route is missing the 'permanent' keyword.
D.The router has 'no ip routing' configured.
AnswerA

Cisco IOS installs a VRF static route only when its next hop resolves within that same VRF's routing table. Because 10.1.1.1 has no connected or learned route inside VRF_ORANGE, the route is rejected and never appears in `show ip route vrf`.

Why this answer

In VRF-Lite, a static route configured inside a VRF is only installed if the next-hop address is resolvable within that same VRF's routing table. If 10.1.1.1 is not reachable via an interface assigned to VRF_ORANGE (or via a route learned in that VRF), the static route remains inactive and does not appear in 'show ip route vrf VRF_ORANGE'.

Exam trap

300-410 often tests that VRF-Lite static routes require next-hop reachability within the same VRF — candidates assume the route is broken due to a syntax or keyword issue rather than a recursive-lookup failure.

How to eliminate wrong answers

Option B is wrong because 'ip classless' affects how the router handles traffic destined to subnets not present in the routing table (falling back to the default route or classful behavior); it does not prevent a static route with an explicit next-hop from being installed. Option C is wrong because the 'permanent' keyword only keeps a static route in the table when the outgoing interface goes down — it is not required for a next-hop-based static route to be installed. Option D is wrong because 'no ip routing' would disable IP routing globally, which would prevent ALL routes (not just this one) from appearing and would also break the VRF configuration entirely.

472
Multi-Selectmedium

Which THREE symptoms indicate a DHCP IPv4 starvation attack or address pool exhaustion? (Choose THREE.)

Select 3 answers
A.Legitimate clients fail to obtain an IP address via DHCP.
B.The DHCP pool shows 100% utilization with many unknown MAC addresses.
C.The DHCP server's binding table contains a large number of leases from spoofed MAC addresses.
D.Client devices experience high CPU utilization due to DHCP processing.
E.Duplicate IP address detection (DAD) failures are reported on all clients.
AnswersA, B, C

Pool exhaustion means no free leases remain, so the DHCP server has nothing to offer and legitimate clients receive no address, timing out during DORA. This is the direct, client-visible symptom of a starvation attack consuming all available addresses.

Why this answer

Option A is correct because DHCP starvation attacks consume all available addresses in the scope, so legitimate clients sending DHCPDISCOVER receive no DHCPOFFER and fail to obtain a lease. Option B is correct because the defining symptom of pool exhaustion is the DHCP scope showing 100% utilization, often with leases bound to numerous unknown or randomized MAC addresses generated by the attack tool. Option C is correct because starvation tools such as Yersinia or dhcpstarv request leases using spoofed/changing MAC addresses, so the DHCP server's binding table fills with many leases tied to spoofed MAC addresses.

Option D is not a recognized symptom of DHCP starvation; high CPU on clients is unrelated to DHCP pool exhaustion. Option E is not a symptom of starvation either, since DAD failures typically indicate duplicate IP addressing or rogue DHCP servers, not exhaustion of the DHCP pool.

Exam trap

Cisco often tests the distinction between DHCP starvation symptoms and unrelated network issues like DAD failures or client CPU load, expecting candidates to recognize that only server-side indicators (pool exhaustion, spoofed MACs, client failure) are valid.

473
MCQhard

An engineer is troubleshooting a router that is configured as an NTP client. The router's clock is not synchronizing with the NTP server at 192.168.1.1. 'show ntp status' shows 'clock is unsynchronized', and 'show ntp associations' shows the server as '.INIT.' with no reachability. The engineer can ping the NTP server. What is the most likely cause?

A.The NTP server is not configured to respond to NTP requests from this client.
B.The router's 'ntp source' command is missing, causing NTP packets to use an incorrect source IP.
C.The router's clock is set too far in the future, causing NTP to reject the server's time.
D.The router has 'ntp authenticate' enabled without the proper key.
AnswerA

NTP operates over UDP port 123, which is distinct from ICMP echo used by ping. The server may have the NTP service disabled, a firewall rule blocking source/destination UDP 123, or an access-class restriction that denies this client's IP address. Without a reply to the NTP request, the router's association remains in the 'unreachable' state and never synchronizes, even though basic IP connectivity exists. This directly matches the observed lack of reachability in 'show ntp associations'.

Why this answer

The '.INIT.' state in 'show ntp associations' indicates that the client has sent NTP packets to the server but has not received any valid NTP responses. Since the engineer can ping the server, Layer 3 connectivity is fine, ruling out network issues. The most likely cause is that the NTP server is not configured to respond to requests from this client, either due to an access control list (ACL) on the server, a 'restrict' statement denying the client, or the server not being configured as an NTP server at all.

Exam trap

Cisco often tests the distinction between client-side and server-side issues; the trap here is that candidates assume a reachable ping means NTP should work, but NTP uses a different protocol (UDP 123) and can be filtered or restricted independently of ICMP.

How to eliminate wrong answers

Option B is wrong because a missing 'ntp source' command would cause NTP packets to use the IP of the egress interface, which might still be reachable; it would not result in a complete lack of response ('.INIT.') unless the server specifically filters based on source IP, but that is a server-side issue, not a client-side misconfiguration. Option C is wrong because NTP uses a stratum-based hierarchy and timestamps; a client clock set too far in the future would still allow the client to receive NTP packets and update its clock (though it might take longer to synchronize), but it would not prevent the server from responding. Option D is wrong because if 'ntp authenticate' were enabled without the proper key, the client would still receive NTP packets from the server, but they would be discarded; 'show ntp associations' would show the server as '.AUTH.' or similar, not '.INIT.'.

474
MCQeasy

A network engineer runs the following command on Router R1: R1# show ip route ospf Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2 i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP a - application route + - replicated route, % - next hop override Gateway of last resort is not set O 10.2.2.0/24 [110/20] via 192.168.12.2, 00:12:34, GigabitEthernet0/0 O IA 10.3.3.0/24 [110/30] via 192.168.13.3, 00:10:21, GigabitEthernet0/1 Based on this output, what can be determined?

A.The route to 10.2.2.0/24 is an external OSPF route.
B.The route to 10.3.3.0/24 is learned from a different area.
C.Router R1 has a default route configured.
D.Both routes have the same administrative distance.
AnswerD

Both routes show administrative distance 110 (the number in brackets before the cost), indicating they are learned via OSPF which uses AD 110.

Why this answer

Both routes are OSPF routes and have an OSPF administrative distance of 110, as shown in the brackets. Option D is correct. Option A is incorrect because 10.2.2.0/24 is an intra-area route (O), not external.

Option C is incorrect because the output shows 'Gateway of last resort is not set', so no default route is configured.

475
MCQmedium

Which authentication method is supported by default for GRE tunnels in Cisco IOS-XE?

A.MD5 authentication
B.SHA-256 authentication
C.No authentication by default
D.Plain-text password authentication
AnswerC

GRE tunnels in Cisco IOS-XE carry no authentication mechanism unless explicitly configured, so traffic passes without peer verification. This satisfies the stem's "by default" constraint: IPsec or tunnel key configuration must be added manually for any authentication to occur.

Why this answer

GRE tunnels in Cisco IOS-XE do not include any built-in authentication mechanism by default. The GRE protocol (RFC 2784) defines a simple encapsulation method without authentication or encryption; any security features must be added externally, such as using IPsec to protect the tunnel traffic. Therefore, the correct answer is that no authentication is enabled by default.

Exam trap

Cisco often tests the misconception that the GRE key field provides authentication, but it is only an optional identifier and does not offer any security; candidates may incorrectly assume that a key or password is required or that GRE has built-in authentication.

How to eliminate wrong answers

Option A is wrong because MD5 authentication is not a default feature of GRE tunnels; while Cisco supports a GRE key option (which is not authentication) and IPsec can provide MD5-based HMAC, the base GRE tunnel itself has no authentication. Option B is wrong because SHA-256 authentication is not supported natively by GRE; it would require IPsec or another security protocol to be applied to the tunnel. Option D is wrong because plain-text password authentication is not a feature of GRE; GRE does not support any form of password or authentication in its standard implementation.

476
MCQeasy

What is the default authentication type for NHRP in a DMVPN configuration?

A.Plaintext password
B.MD5 hash
C.No authentication
D.IPsec
AnswerC

NHRP requires no authentication unless explicitly configured, so DMVPN tunnels establish without credential exchange by default. The authentication type defaults to none, meaning spokes and hubs accept registration requests without verifying a password or key.

Why this answer

By default, NHRP does not use any authentication. Authentication can be configured using the 'ip nhrp authentication' command, but it is disabled by default.

477
MCQmedium

Consider the following partial configuration on router R1: ``` interface GigabitEthernet0/1 ip access-group MY_ACL in ! ip access-list extended MY_ACL permit tcp 10.1.1.0 0.0.0.255 any eq 80 permit icmp any any echo deny ip any any ``` What is the effect of this ACL when applied inbound on GigabitEthernet0/1?

A.It permits HTTP requests from 10.1.1.0/24 and ICMP Echo requests from any source; all other IP traffic is denied.
B.It permits HTTP requests from 10.1.1.0/24 and all ICMP traffic; all other IP traffic is denied.
C.It permits HTTP requests from any source to 10.1.1.0/24 and ICMP Echo requests; all other traffic is denied.
D.It permits HTTP requests from 10.1.1.0/24 and ICMP Echo replies; all other IP traffic is denied.
AnswerA

The extended ACL permits TCP port 80 sourced from 10.1.1.0/24, permits ICMP echo from any source, then denies all remaining IP traffic. Applied inbound, it filters packets entering GigabitEthernet0/1 before routing, so only those two traffic classes pass.

Why this answer

The ACL is applied inbound on GigabitEthernet0/1. The first permit statement allows TCP traffic from source network 10.1.1.0/24 to any destination on port 80 (HTTP). The second permit statement allows ICMP Echo requests (type 8) from any source.

The final deny statement blocks all other IP traffic. Therefore, only HTTP requests from 10.1.1.0/24 and ICMP Echo requests from any source are permitted; all other IP traffic is denied.

Exam trap

Cisco often tests the distinction between ICMP Echo request and Echo reply, and the trap here is that the 'echo' keyword in an ACL permits only Echo requests, not all ICMP traffic or Echo replies.

How to eliminate wrong answers

Option B is wrong because it states 'all ICMP traffic' is permitted, but the ACL only permits ICMP Echo requests (type 8), not other ICMP types like Echo replies (type 0) or destination unreachable. Option C is wrong because it reverses the source and destination for HTTP traffic; the ACL permits HTTP from 10.1.1.0/24 to any, not from any to 10.1.1.0/24. Option D is wrong because it specifies ICMP Echo replies, but the ACL permits ICMP Echo requests (the 'echo' keyword in Cisco ACLs matches Echo requests, not replies).

478
MCQeasy

A network technician is configuring a Cisco router to act as a DHCP relay agent. The router's interface GigabitEthernet0/0 is connected to a subnet where clients need to obtain IP addresses from a DHCP server located on a different subnet. Which command is required on the router to enable DHCP relay?

A.ip dhcp pool
B.ip dhcp relay
C.ip helper-address
D.ip forward-protocol udp
AnswerC

The 'ip helper-address' command is used on the interface facing the DHCP clients to forward DHCP broadcast requests to a specified DHCP server. It converts the broadcast to a unicast packet destined to the server's IP address. This is the standard method for DHCP relay on Cisco IOS routers and is essential for clients on remote subnets to obtain addresses from a centralized server.

Why this answer

To configure a Cisco router as a DHCP relay agent, the 'ip helper-address' command must be applied to the interface receiving the DHCP broadcasts. This command specifies the IP address of the DHCP server. The router then forwards the DHCP requests as unicasts to that server.

Other commands like 'ip forward-protocol' or 'ip dhcp pool' serve different purposes and are not used to enable relay.

Exam trap

The trap here is confusing the DHCP relay command with other DHCP-related commands like 'ip dhcp pool' or 'ip forward-protocol'.

479
MCQmedium

Given the following configuration snippet on Router R5: router eigrp 400 network 10.1.1.0 0.0.0.255 What is wrong with this configuration?

A.The wildcard mask should be 255.255.255.0.
B.The network address should be the classful network 10.0.0.0.
C.The configuration is correct as shown.
D.The AS number 400 is invalid; EIGRP AS numbers must be between 1 and 65535.
AnswerC

The snippet is valid: EIGRP named-mode syntax is not required, and `network 10.1.1.0 0.0.0.255` correctly enables EIGRP on interfaces within that subnet using a wildcard mask. No autonomous-system mismatch or missing `no auto-summary` fault exists here, so the configuration satisfies the stem's requirement without error.

Why this answer

The configuration uses a valid EIGRP AS number (400) and a correct wildcard mask (0.0.0.255) to match the 10.1.1.0/24 subnet. In EIGRP, the network command uses a wildcard mask to specify the exact interfaces to advertise, and 0.0.0.255 is the proper inverse of the subnet mask 255.255.255.0.

Exam trap

Cisco often tests the distinction between wildcard masks and subnet masks, leading candidates to incorrectly assume that a subnet mask (like 255.255.255.0) should be used in the EIGRP network command instead of the correct wildcard mask.

How to eliminate wrong answers

Option A is wrong because the wildcard mask 0.0.0.255 is correct; using 255.255.255.0 would be a subnet mask, not a wildcard mask, and would not match the intended network. Option B is wrong because EIGRP allows specifying a subnet with a wildcard mask, and using the classful network 10.0.0.0 would enable EIGRP on all interfaces in the 10.0.0.0/8 range, which is not required and could cause unnecessary neighbor relationships. Option D is wrong because EIGRP AS numbers can range from 1 to 65535, and 400 falls within that valid range.

480
MCQmedium

What is the default administrative distance for a route installed by Policy-Based Routing (PBR) using the 'set ip next-hop' command?

A.0
B.1
C.The administrative distance of the routing protocol that learned the route.
D.120
AnswerC

Policy-Based Routing forwards matching traffic using the configured next hop, but the route retains the administrative distance of the routing protocol that originally learned it. PBR does not assign its own AD value, so the underlying protocol's distance governs preference.

Why this answer

Policy-Based Routing does not install routes into the routing table with its own administrative distance. When PBR uses 'set ip next-hop', the router must resolve the next-hop address via the routing table; the resulting forwarding entry inherits the administrative distance of whatever routing protocol or static route provided that next-hop resolution. PBR itself has no independent AD value.

Exam trap

The trap is assuming PBR has its own administrative distance like a routing protocol, when in reality PBR borrows the AD of the route used to resolve the next-hop.

How to eliminate wrong answers

Option A is wrong because AD 0 is reserved for connected interfaces, not PBR. Option B is wrong because AD 1 is used by static routes, not by PBR-installed entries. Option D is wrong because AD 120 is the default for RIP, which is unrelated to PBR next-hop resolution.

481
Multi-Selectmedium

Which TWO statements about IPv4 extended access control lists are true? (Choose TWO.)

Select 2 answers
A.They can filter based on source and destination IP addresses.
B.They are typically placed as close to the source as possible.
C.They use a wildcard mask only for the destination address.
D.They can be named using numbers only.
E.They automatically log all matched packets.
AnswersA, B

Extended ACLs can specify both source and destination addresses in the permit/deny statement.

Why this answer

IPv4 extended ACLs can filter traffic based on both source and destination IP addresses, as well as protocol type, port numbers, and other parameters. This is defined in the access-list command syntax (e.g., access-list 100 permit tcp 10.0.0.0 0.255.255.255 192.168.1.0 0.0.0.255 eq 80), which allows granular control beyond standard ACLs that only filter on source IP.

Exam trap

Cisco often tests the misconception that extended ACLs can only be numbered, but they support named ACLs as well, and that wildcard masks apply only to one address field, whereas they apply to both source and destination.

482
MCQmedium

A network engineer runs the following command to verify NAT on a VRF: R1# show ip nat translations vrf CUSTOMER Pro Inside global Inside local Outside local Outside global --- 10.2.2.2 10.1.1.1 192.168.1.1 192.168.1.1 What is the purpose of the 'vrf CUSTOMER' parameter?

A.It filters translations for a specific VRF, allowing per-customer NAT.
B.It shows all translations across all VRFs.
C.It enables NAT on the VRF interface.
D.It creates a new VRF for NAT.
AnswerA

The vrf CUSTOMER keyword scopes the translation table to that VRF, so only NAT entries belonging to the CUSTOMER routing instance are displayed. This satisfies the per-customer NAT requirement by isolating address translation between VRFs on the same router.

Why this answer

The 'vrf CUSTOMER' parameter filters the output of 'show ip nat translations' to display only the NAT entries associated with the specified VRF (CUSTOMER). This allows per-customer NAT visibility in MPLS VPN or multi-VRF environments, where each VRF maintains its own separate NAT translation table. Without this parameter, the command would show all NAT translations across all VRFs, which is not the intended behavior.

Exam trap

Cisco often tests the distinction between filtering output and enabling a feature; the trap here is that candidates may think the 'vrf' parameter enables NAT on the VRF or creates a VRF, when in fact it only filters the display of existing translations.

How to eliminate wrong answers

Option B is wrong because 'show ip nat translations vrf CUSTOMER' does not show all translations across all VRFs; it specifically filters to show only translations for the VRF named CUSTOMER. Option C is wrong because the 'vrf' parameter in this command is used for filtering output, not for enabling NAT on a VRF interface; NAT is enabled on an interface using the 'ip nat inside' or 'ip nat outside' commands under the interface configuration, optionally within a VRF. Option D is wrong because the 'vrf' parameter does not create a new VRF; VRFs are created using the 'vrf definition' or 'ip vrf' command in global configuration mode.

483
Drag & Drophard

Drag and drop the steps to troubleshoot SPAN, RSPAN, and ERSPAN adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Begin by checking the SPAN/RSPAN/ERSPAN session status with show commands. Then, verify that the source and destination VLANs or interfaces are up. Next, confirm that any intermediate switches support the required encapsulation.

After that, test IP connectivity for ERSPAN destinations using ping. Finally, review ACLs or filters that might block mirrored traffic.

484
MCQmedium

Examine the partial BFD configuration on a router: interface GigabitEthernet0/0 bfd interval 100 min_rx 100 multiplier 3 ! interface GigabitEthernet0/1 bfd interval 200 min_rx 200 multiplier 3 ! router ospf 1 bfd all-interfaces ! The router has OSPF neighbors on both interfaces. Which statement is true?

A.Both BFD sessions will use the same timer values because OSPF is configured with 'bfd all-interfaces'.
B.The BFD session on GigabitEthernet0/0 will detect failures in 300 ms, and on GigabitEthernet0/1 in 600 ms.
C.The BFD session on GigabitEthernet0/1 will not form because the interval is too high.
D.The router will use the minimum interval across all interfaces for consistency.
AnswerB

BFD detection time equals the multiplier times the slower of interval and min_rx. Gi0/0 gives 3 × 100 ms = 300 ms; Gi0/1 gives 3 × 200 ms = 600 ms, matching the configured per-interface timers.

Why this answer

BFD timers are configured per interface. Each BFD session independently uses the timers configured on its respective interface. The multiplier is applied per session.

485
Multi-Selecthard

Which TWO commands can be used to verify OSPFv3 interface parameters and troubleshoot adjacency issues? (Choose TWO.)

Select 2 answers
A.show ipv6 ospf interface
B.debug ipv6 ospf hello
C.show ip ospf interface
D.debug ip ospf adj
E.show ipv6 ospf database
AnswersA, B

`show ipv6 ospf interface` displays per-interface OSPFv3 parameters — area ID, network type, hello and dead intervals, DR/BDR state and neighbour count — directly satisfying the stem's requirement to verify interface parameters and diagnose adjacency failures caused by mismatched timers or network types.

Why this answer

Option A, 'show ipv6 ospf interface', is correct because it displays OSPFv3-specific interface parameters such as area ID, interface state, hello/dead intervals, network type, and DR/BDR roles, which are essential for verifying that neighbors agree on these values before an adjacency can form. Option B, 'debug ipv6 ospf hello', is correct because it dynamically shows the OSPFv3 hello packets being sent and received, including hello/dead timers, area ID, and neighbor lists, which directly helps diagnose why an adjacency is stuck (e.g., mismatched timers or area IDs). Option C, 'show ip ospf interface', is not correct because it is an OSPFv2 (IPv4) command and does not display OSPFv3 interface information.

Option D, 'debug ip ospf adj', is not correct because it debugs OSPFv2 adjacency events, not OSPFv3. Option E, 'show ipv6 ospf database', is not correct because it displays the OSPFv3 link-state database rather than interface parameters or hello-level adjacency troubleshooting information.

Exam trap

The trap is that candidates pick IPv4 OSPF commands (show ip ospf interface, debug ip ospf adj) for an OSPFv3 question, forgetting that OSPFv3 uses the 'ipv6' keyword in show/debug commands.

486
MCQmedium

A network engineer is configuring a GRE tunnel over an IPsec VPN to support multicast traffic between two sites. The engineer notices that multicast traffic is not passing through the tunnel, although unicast traffic works. Which of the following is the most likely reason?

A.The IPsec transform set does not support multicast traffic.
B.The IPsec ACL is not permitting multicast traffic.
C.The GRE tunnel interface is not configured with a tunnel source and destination.
D.Multicast routing is not enabled on the tunnel interfaces or the physical interfaces.
AnswerD

For multicast traffic to traverse a GRE tunnel, multicast routing must be enabled on the tunnel interface and the physical interface carrying the tunnel. Additionally, an appropriate multicast routing protocol (e.g., PIM) must be configured. Without enabling multicast routing, the router will not forward multicast packets into or out of the tunnel, even though unicast works. This is the most likely cause.

Why this answer

Multicast traffic over a GRE tunnel requires multicast routing to be enabled on both the tunnel interface and the physical interface. Additionally, a multicast routing protocol like PIM must be configured. Without these, the router will not forward multicast packets, even though unicast traffic works.

The IPsec ACL typically permits GRE, so it does not need to match multicast directly.

Exam trap

The trap here is assuming that IPsec or the ACL is blocking multicast, when the real issue is the lack of multicast routing configuration on the tunnel and physical interfaces.

487
MCQmedium

A network engineer runs the following command to troubleshoot a Policy-Based Routing (PBR) issue: R1# debug ip policy Policy routing debugging is on R1# *Mar 1 00:10:45.456: IP: s=172.16.1.5 (FastEthernet0/0), d=8.8.8.8, len 64, policy match *Mar 1 00:10:45.456: IP: s=172.16.1.5 (FastEthernet0/0), d=8.8.8.8, len 64, policy routed *Mar 1 00:10:45.456: IP: FastEthernet0/0 to Serial0/0 10.1.1.2 What does this output indicate?

A.The packet was successfully policy-routed to 10.1.1.2 via Serial0/0.
B.The packet was dropped due to no matching route.
C.The next-hop 10.1.1.2 is unreachable.
D.The route-map is misconfigured with wrong ACL.
AnswerA

The debug lines show a policy match, then policy routed, then the forwarding decision FastEthernet0/0 to Serial0/0 with next hop 10.1.1.2. This confirms the route-map matched the packet and forwarded it via the PBR next hop rather than the routing table.

Why this answer

The debug shows a packet from 172.16.1.5 to 8.8.8.8 that matched the policy and was routed out of Serial0/0 to next-hop 10.1.1.2. This indicates successful PBR operation.

488
MCQmedium

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# show ip sla configuration 10 IP SLAs, Infrastructure Engine-II. Entry number: 10 Owner: Tag: Type of operation to perform: icmp-echo Target address: 192.168.1.1 Type Of Service parameter: 0x0 Request size (ARR data portion): 28 Operation timeout (milliseconds): 5000 Frequency (seconds): 60 Next Scheduled Start Time: Start Time already occurred Group Scheduled : FALSE Life (seconds): Forever Entry Ageout (seconds): never Recurring (Starting Everyday): FALSE Status of entry (SNMP RowStatus): Active Threshold (milliseconds): 5000 Distribution Statistics: Number of history intervals kept: 0 Number of history buckets kept: 15 History Statistics: Number of history Lives kept: 0 What does this output indicate?

A.The IP SLA operation is configured as an HTTP GET request to 192.168.1.1.
B.The IP SLA operation is configured as an ICMP echo probe to 192.168.1.1 with a 60-second frequency.
C.The IP SLA operation has a timeout of 60 seconds and a frequency of 5 seconds.
D.The IP SLA operation is in a 'Pending' state and not yet active.
AnswerB

The output confirms an icmp-echo probe targeting 192.168.1.1, satisfying the stem's requirement to identify the configured operation type and destination. The Frequency value of 60 seconds establishes the recurring interval between probes, while the Active status shows the entry is enabled and scheduled.

Why this answer

The output shows 'Type of operation to perform: icmp-echo' with 'Target address: 192.168.1.1' and 'Frequency (seconds): 60', which directly indicates an ICMP echo probe to 192.168.1.1 every 60 seconds. The status is 'Active', confirming the operation is running. These three fields match option B exactly.

Exam trap

300-410 often tests the distinction between 'Frequency' and 'Operation timeout' in IP SLA output, so candidates who skim the values and see 5000 and 60 pick the option that swaps them.

How to eliminate wrong answers

Option A is wrong because the operation type is icmp-echo, not HTTP GET — there is no HTTP operation configured in the output. Option C is wrong because it reverses the values: the output shows timeout 5000 milliseconds (5 seconds) and frequency 60 seconds, not timeout 60 seconds and frequency 5 seconds. Option D is wrong because the status line reads 'Status of entry (SNMP RowStatus): Active', not Pending, so the operation is active and running.

489
MCQhard

A network engineer is configuring object tracking to influence a static default route on a Cisco IOS router. The engineer wants the default route to be removed from the routing table if the tracked object (a reachability test to 192.0.2.1) goes down. The engineer enters the following configuration: track 1 ip route 192.0.2.1 255.255.255.255 reachability ip route 0.0.0.0 0.0.0.0 203.0.113.1 track 1 After the link to 203.0.113.1 fails, the default route remains in the routing table. What is the most likely reason?

A.The tracked object uses a reachability test to 192.0.2.1, which may still be reachable via an alternate path, so the object remains up.
B.The static route must be configured with a administrative distance lower than the default to be removed by tracking.
C.The 'track 1 ip route' command requires a delay before the object goes down, so the route removal is delayed indefinitely.
D.The 'track' keyword on the static route must reference the track object by number, but the syntax requires 'track 1' to be placed before the route.
AnswerA

The track object tests reachability to 192.0.2.1, not the status of the 203.0.113.1 interface. If 192.0.2.1 remains reachable through another route (e.g., a backup link), the tracked object stays up and the static default route is not removed. This is the most likely reason the route persists despite the primary link failure.

Why this answer

Object tracking removes a static route only when the tracked object transitions to a down state. The reachability test to 192.0.2.1 may succeed via an alternate path even after the primary link fails, keeping the object up. The track keyword placement, administrative distance, and delay parameters do not explain the persistent route in this scenario.

Exam trap

The trap here is confusing interface line-protocol tracking with IP reachability tracking; a reachability probe can succeed over a backup path and keep the object up.

490
MCQeasy

A network technician is configuring a Cisco router to forward traffic to a remote network. The technician enters the command 'ip route 172.16.0.0 255.255.0.0 10.0.0.1'. However, the router does not install the route in its routing table. What is the most likely reason?

A.The administrative distance of the static route is too high.
B.The subnet mask is incorrect.
C.The static route is missing the 'permanent' keyword.
D.The next-hop address 10.0.0.1 is not reachable.
AnswerD

For a static route to be installed in the routing table, the next-hop address must be reachable via a valid route. If 10.0.0.1 is not reachable, the static route remains in the configuration but is not installed. This is a common issue when the next-hop is not directly connected or no route to it exists.

Why this answer

A static route is only installed in the routing table if its next-hop address is reachable. If the next-hop 10.0.0.1 is not reachable (e.g., no route to it, or interface down), the route will not be installed. The default administrative distance is low, the mask is correct, and the 'permanent' keyword is not required for installation.

Therefore, the most likely cause is an unreachable next-hop.

Exam trap

The trap here is assuming that a static route is always installed regardless of next-hop reachability, when in fact the router must have a valid path to the next-hop.

491
MCQmedium

When using 'set ip next-hop verify-availability', what mechanism does the router use to determine if the next-hop is reachable?

A.It sends an ICMP echo request to the next-hop every 10 seconds.
B.It checks the ARP table for the next-hop MAC address.
C.It uses a tracked object that can be based on IP SLA, interface state, or other criteria.
D.It performs a recursive routing table lookup to see if the next-hop is reachable.
AnswerC

Verify-availability does not rely on ARP or routing-table presence alone; it binds the next hop to a tracked object. That object's state derives from IP SLA probes, interface line protocol, or other track criteria, so the route is withdrawn when the tracked condition fails.

Why this answer

The 'verify-availability' option uses a tracked object (configured with the 'track' command) which can be based on IP SLA, interface line-protocol, or other criteria. It does not use ARP or ICMP by default.

492
MCQmedium

An engineer is troubleshooting a BGP route selection issue. Router R1 receives two paths for prefix 10.0.0.0/8: one from eBGP peer R2 (AS 65002) with weight 0, local preference 100, and AS path 65002; and another from eBGP peer R3 (AS 65003) with weight 0, local preference 200, and AS path 65003 65004. R1's BGP table shows the path from R3 as the best route. The engineer wants the path from R2 to be preferred. What should the engineer do?

A.Configure a route-map on R1 to set local preference 150 for routes from R2.
B.Configure a route-map on R1 to set local preference 250 for routes from R2.
C.Configure a route-map on R1 to prepend two additional AS numbers to the AS path from R3.
D.Configure a route-map on R1 to set weight 100 for routes from R2.
AnswerD

Setting weight 100 makes R2's path have higher weight than R3's default weight 0. Weight is compared first, so R2 becomes the best path. Correct.

Why this answer

BGP path selection compares weight first. Setting weight 100 for routes from R2 makes the R2 path preferred over the R3 path (both have default weight 0). Option B setting local preference 250 would also make R2 preferred, but weight is compared earlier and is the more direct single-answer action.

Option A sets local preference 150, still lower than R3's 200, so R3 remains preferred. Option C prepends AS numbers to the R3 path, but local preference 200 vs 100 is evaluated before AS path length, so R3 still wins unless weight is changed.

493
Drag & Dropmedium

Drag and drop the steps to configure IPv6 RA Guard on a switch into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, globally enable IPv6 snooping. Then define an RA Guard policy with the trusted or untrusted role. Apply the policy to the desired interface.

Verify the configuration with show commands. Finally, test the RA Guard operation by sending RAs from unauthorized ports.

494
MCQeasy

A network technician is configuring a GRE tunnel between two routers. The tunnel source is a physical interface, and the tunnel destination is a loopback interface on the remote router. The technician notices that the tunnel interface is up, but line protocol is down. What is the most likely cause?

A.The tunnel mode is set to GRE multipoint.
B.The tunnel source interface is shutdown.
C.The tunnel destination is not reachable.
D.The tunnel keepalive is misconfigured.
AnswerC

If the tunnel destination IP address is not reachable, the tunnel interface will show up/down. The tunnel source is up, so the interface state is up, but without a route to the destination, the line protocol remains down. This is a common issue when the destination is a loopback that is not advertised or when there is no route to it.

Why this answer

A GRE tunnel interface will be in up/down state if the tunnel source is operational but the destination is unreachable. The router brings up the tunnel interface because the source is up, but the line protocol remains down until a route to the destination is available. Ensuring reachability to the tunnel destination resolves the issue.

Exam trap

The trap here is assuming that a shutdown source interface would cause up/down, but that would cause down/down; the up/down state specifically points to destination unreachability.

495
MCQmedium

Which statement accurately describes the default behavior of auto-summary in EIGRP on Cisco IOS-XE?

A.Auto-summary is enabled by default, causing EIGRP to summarize at classful boundaries.
B.Auto-summary is disabled by default, and EIGRP advertises subnets without automatic summarization.
C.Auto-summary is enabled by default but only for external routes.
D.Auto-summary is disabled by default unless the network is configured with a classful mask.
AnswerB

Cisco IOS-XE ships with EIGRP auto-summary disabled, so classful boundary summarisation never occurs unless explicitly enabled with the auto-summary command. Subnets are therefore advertised individually with their configured masks, matching the stem's requirement for accurate default behaviour.

Why this answer

In Cisco IOS-XE, EIGRP auto-summary is disabled by default. This means that EIGRP advertises subnets without automatically summarizing them at classful boundaries, allowing for more granular route advertisement and preventing routing issues in discontiguous networks.

Exam trap

Cisco often tests the misconception that auto-summary is still enabled by default in EIGRP on modern IOS-XE, when in fact it was changed to disabled by default starting from IOS 15.0(1)M and later.

How to eliminate wrong answers

Option A is wrong because auto-summary is not enabled by default on Cisco IOS-XE; it was enabled by default in older IOS versions but is now disabled. Option C is wrong because auto-summary, when enabled, applies to all routes, not just external routes; there is no such distinction in the default behavior. Option D is wrong because auto-summary is disabled by default regardless of whether the network is configured with a classful mask; the classful mask configuration does not re-enable auto-summary.

496
MCQhard

A network engineer configures SNMP traps on router R3 to monitor BGP events. R3 is an iBGP route reflector with multiple clients. The configuration includes: snmp-server enable traps bgp, snmp-server host 192.168.1.100 version 2c public. However, the NMS receives no BGP traps. R3's show snmp pending shows no pending traps. show snmp statistics shows TrapsSent: 0. The NMS can poll R3 successfully via SNMP. What is the root cause?

A.The BGP process is not configured to send traps to the SNMP agent; the command 'snmp-server enable traps bgp' is insufficient on some IOS versions without also enabling 'bgp snmp trap' under the BGP router configuration.
B.The NMS is using SNMPv3 but the router is configured for v2c, causing trap rejection.
C.An ACL on the NMS is blocking UDP port 162 from the router.
D.The router's SNMP trap queue is full, causing traps to be dropped.
AnswerA

The root cause is a known IOS inconsistency: 'snmp-server enable traps bgp' globally permits the SNMP agent to send BGP traps to configured hosts, but on many IOS releases the BGP process itself must also be instructed to notify the agent of state changes. The command 'bgp snmp trap' (under router bgp) enables BGP notification generation for the agent to forward. Without this BGP-level command, the router will not generate BGP trap events, resulting in TrapsSent: 0 despite correct host configuration.

Why this answer

On many Cisco IOS versions, the command `snmp-server enable traps bgp` only enables the SNMP agent to send BGP traps, but the BGP process itself must be explicitly configured to generate those traps using the `bgp snmp trap` command under the BGP router configuration. Without this, the BGP process never sends trap notifications to the SNMP agent, resulting in zero traps sent despite the SNMP trap configuration being otherwise correct.

Exam trap

Cisco often tests the misconception that `snmp-server enable traps bgp` alone is sufficient, when in fact the BGP process requires the additional `bgp snmp trap` command to generate the trap events.

How to eliminate wrong answers

Option B is wrong because the NMS can successfully poll R3 via SNMP, indicating SNMP communication works; if the NMS were using SNMPv3 and the router only v2c, polling would also fail due to version mismatch, not just traps. Option C is wrong because an ACL blocking UDP 162 would prevent traps from reaching the NMS, but the router's `show snmp statistics` shows TrapsSent: 0, meaning the router never attempted to send any traps, so the issue is before the network layer. Option D is wrong because `show snmp pending` shows no pending traps, indicating the trap queue is empty, not full; a full queue would show pending traps that are queued but not yet sent.

497
MCQmedium

A network engineer is configuring a Cisco router to support Network Address Translation (NAT) for a small office. The engineer wants to translate internal private addresses to a single public address using Port Address Translation (PAT). Which command enables PAT by allowing the router to use the interface's IP address for translation?

A.ip nat inside source list 1 interface GigabitEthernet0/0
B.ip nat inside source static 10.1.1.1 203.0.113.1
C.ip nat inside source list 1 interface GigabitEthernet0/0 overload
D.ip nat inside source list 1 pool PUBLIC_POOL overload
AnswerC

This command configures PAT by referencing an access list (list 1) that defines the internal traffic to be translated and using the interface GigabitEthernet0/0's IP address as the public address. The overload keyword enables PAT, allowing multiple internal hosts to share the single public IP address by using different source ports. This is the correct command for the scenario.

Why this answer

PAT is enabled by using the overload keyword with the ip nat inside source command. When translating to an interface address, the syntax includes the interface keyword and overload. The correct command references the access list defining inside traffic, specifies the outside interface, and includes overload.

Other options either use a pool, perform static translation, or omit overload, so they do not achieve PAT using the interface address.

Exam trap

The trap here is forgetting the overload keyword, which is required for PAT, and confusing interface-based PAT with pool-based PAT.

498
MCQmedium

According to RFC 3164, which facility code is used by default for Cisco IOS syslog messages?

A.Local0
B.Local7
C.User
D.Syslog
AnswerB

RFC 3164 defines facility codes where local7 corresponds to decimal 23. Cisco IOS uses this facility by default when generating syslog messages, so messages are tagged with local7 unless the administrator overrides it with the logging facility command.

Why this answer

RFC 3164 defines syslog facility codes, and Cisco IOS devices use facility local7 (code 23) by default for logging messages. This means when a Cisco router or switch sends syslog messages to a server, they are tagged with the local7 facility unless explicitly changed. The default is set in the logging configuration and can be verified with the show logging command, which displays 'Syslog logging: enabled (0 messages dropped, 0 flushes, 0 overruns)' and includes the facility.

Local7 is chosen to allow administrators to separate Cisco device logs from other system logs on a syslog server.

Exam trap

300-410 often tests the default syslog facility for Cisco IOS, and candidates frequently confuse it with local0 or user because those are common in other systems or are configurable options, but the default is local7.

How to eliminate wrong answers

Option A is wrong because local0 (facility code 16) is not the default for Cisco IOS; it is one of the configurable local facilities but not the default. Option C is wrong because 'user' is a facility code (code 1) used by user-level processes, not the default for Cisco IOS syslog messages. Option D is wrong because 'syslog' is not a facility code; it is the protocol or the daemon name, and there is no facility named 'syslog' in RFC 3164.

499
MCQmedium

Given this partial configuration: ip nat pool MYPOOL 203.0.113.10 203.0.113.20 netmask 255.255.255.0 ip nat inside source list 1 pool MYPOOL access-list 1 permit 192.168.1.0 0.0.0.255 What is the effect?

A.Inside hosts are translated to addresses in the pool using PAT.
B.Inside hosts are dynamically mapped to a pool address; if the pool is exhausted, new translations fail.
C.The router uses the pool address as the source for all outbound traffic, regardless of ACL.
D.This configuration requires the 'ip nat outside' interface command to function.
AnswerB

The inside source list maps permitted hosts to the MYPOOL range dynamically, one global address per host, since overload is absent. Once all eleven pool addresses are allocated, further translations fail until existing entries expire.

Why this answer

The configuration uses a standard ACL to match inside hosts (192.168.1.0/24) and dynamically assigns them a unique address from the pool 203.0.113.10–203.0.113.20. Because no 'overload' keyword is present, PAT is not enabled; each translation consumes a pool address, and once all 11 addresses are used, new translations fail until an existing translation times out or is cleared.

Exam trap

Cisco often tests the distinction between dynamic NAT and PAT by omitting the 'overload' keyword, leading candidates to assume PAT is always used with a pool when in fact it must be explicitly configured.

How to eliminate wrong answers

Option A is wrong because PAT requires the 'overload' keyword on the 'ip nat inside source list 1 pool MYPOOL' command; without it, the router performs dynamic one-to-one NAT, not port address translation. Option C is wrong because the ACL restricts which inside hosts are eligible for translation; traffic from hosts not matching the ACL (or from outside interfaces) is not translated using the pool. Option D is wrong because while 'ip nat outside' is required on the egress interface for NAT to function, the statement says 'requires the ip nat outside interface command to function' as if it were the only missing piece, but the configuration is incomplete without both 'ip nat inside' and 'ip nat outside' on the respective interfaces; the question's phrasing implies a misunderstanding that only the outside command is needed.

500
MCQeasy

What is the default BGP keepalive timer value in Cisco IOS-XE?

A.30 seconds
B.60 seconds
C.90 seconds
D.180 seconds
AnswerB

Cisco IOS-XE advertises a default BGP keepalive interval of 60 seconds, paired with a 180-second hold time. This satisfies the stem's request for the default keepalive value, since the timer is negotiated as one-third of the hold time unless explicitly overridden with the **neighbor timers** command.

Why this answer

The default BGP keepalive timer is 60 seconds, as defined in RFC 4271 and implemented in Cisco IOS-XE.

501
Drag & Drophard

Drag and drop the steps to troubleshoot EEM adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Start by verifying the EEM policy is registered and enabled, then check for any connectivity issues using ping or traceroute, review syslog or debug output for event triggers, examine the policy logic for errors, and finally test the policy manually to confirm resolution.

502
MCQhard

In Cisco IOS, what is the default encryption algorithm for IKEv1 phase 1 if not specified in the ISAKMP policy?

A.AES 256
B.3DES
C.DES
D.AES 128
AnswerC

Cisco IOS applies DES as the default IKEv1 phase 1 encryption when no encryption keyword is configured in the ISAKMP policy. DES provides only 56-bit symmetric encryption, so explicit configuration of AES is required for stronger phase 1 protection.

Why this answer

In Cisco IOS, when an IKEv1 ISAKMP policy is configured without specifying an encryption algorithm, the default encryption algorithm is DES (Data Encryption Standard). This is because Cisco IOS defaults to DES for IKEv1 phase 1 if no encryption is explicitly defined in the ISAKMP policy, as per the default policy parameters. DES uses a 56-bit key and is considered weak by modern standards, but it remains the default for backward compatibility.

Exam trap

Cisco often tests the default encryption algorithm for IKEv1 phase 1, and the trap here is that candidates assume a stronger algorithm like AES or 3DES is the default, but Cisco IOS defaults to the weaker DES for backward compatibility.

How to eliminate wrong answers

Option A is wrong because AES 256 is not the default encryption algorithm for IKEv1 phase 1; it must be explicitly configured using the 'encryption aes 256' command under the ISAKMP policy. Option B is wrong because 3DES is not the default; it is a stronger alternative that must be specified with 'encryption 3des' in the ISAKMP policy. Option D is wrong because AES 128 is not the default; it requires explicit configuration via 'encryption aes 128' in the ISAKMP policy.

503
Multi-Selectmedium

A network engineer is configuring EIGRP on a Cisco IOS XE router. The router is connected to two different autonomous systems: AS 100 and AS 200. The engineer wants to redistribute routes from AS 100 into AS 200. Which two statements are true regarding EIGRP redistribution? (Choose two.)

Select 2 answers
A.A seed metric must be specified using the `default-metric` command or in the redistribute statement.
B.The `redistribute eigrp 100` command must be configured under router eigrp 200.
C.The `redistribute eigrp 100` command must be configured under router eigrp 100.
D.Redistribution between different EIGRP autonomous systems requires the `redistribute connected` command.
E.The `default-metric` command is optional and only needed for OSPF redistribution.
AnswersA, B

When redistributing routes into EIGRP, a seed metric is required because EIGRP uses a composite metric (bandwidth, delay, load, reliability, MTU). If no seed metric is provided, the routes will not be redistributed. You can specify the metric in the `redistribute` command using the `metric` keyword or set a default metric with the `default-metric` command under the EIGRP process.

Why this answer

To redistribute routes from EIGRP AS 100 into EIGRP AS 200, you must configure the `redistribute eigrp 100` command under the EIGRP AS 200 process. Additionally, a seed metric must be provided, either within the redistribute command or via the `default-metric` command, because EIGRP requires specific metric parameters. Without these, redistribution will not occur.

Exam trap

The trap here is confusing the direction of redistribution; the command must be placed under the target EIGRP process, not the source, and a seed metric is mandatory.

504
Drag & Dropmedium

Drag and drop the steps to verify and validate IP SLA operational state into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Begin by checking the overall IP SLA configuration to confirm the operation is defined, then review the latest statistics for RTT and success rate, examine the reaction configuration if tracking is used, verify the tracking object status, and finally confirm that tracked objects are influencing routing or policy.

505
Multi-Selecthard

Which TWO statements correctly describe the behavior of EIGRP route summarization when using the 'summary-address' command under an interface? (Choose TWO.)

Select 2 answers
A.A summary route is advertised with the metric equal to the best metric among the component routes.
B.The summary route is automatically assigned an administrative distance of 90 by default.
C.A local discard route (null0) is automatically installed for the summary prefix to prevent routing loops.
D.The 'summary-address' command also summarizes connected routes that fall within the summary range.
E.More specific routes are still advertised out the same interface even after the summary is configured.
AnswersA, C

The summary route inherits the minimum, or best, metric among its component routes. EIGRP advertises this single metric for the aggregate, so downstream routers reach all covered subnets through the summarising router, matching the stated metric behaviour.

Why this answer

Option A is correct because when EIGRP advertises a summary route configured with the interface-level summary-address command, the summary inherits the minimum (best) metric among the component routes it covers, so the advertised metric reflects the most favorable path. Option C is correct because EIGRP automatically installs a discard route pointing to Null0 for the summary prefix on the summarizing router, which prevents the router from forwarding traffic for unallocated subnets within the summary and thus avoids routing loops. Option B is incorrect because administrative distance is a local routing-table preference (EIGRP internal is 90) and is not assigned to an advertised summary route by the summary-address command.

Option D is incorrect because the interface summary-address command summarizes EIGRP-learned routes, not connected routes, which must be redistributed into EIGRP to be summarized. Option E is incorrect because, by default, the more specific component routes are suppressed from being advertised out the interface where the summary is configured.

Exam trap

300-410 often tests the misconception that EIGRP summarization advertises component routes alongside the summary, when in fact the summary suppresses the more specific routes out that interface.

506
MCQhard

An engineer configures DHCPv4 on a router with multiple pools for different subnets. Clients in subnet A receive addresses correctly, but clients in subnet B receive addresses from subnet A's pool. The router has 'ip dhcp relay' configured. Which is the most likely explanation?

A.The DHCP server selects the pool based on the giaddr; if the relay agent does not set the giaddr correctly, the server may use the first matching pool.
B.The pools are configured in the wrong order; the server uses the first pool that matches the client's MAC address.
C.The router has 'ip dhcp smart-relay' enabled, which overrides pool selection.
D.The DHCP server is configured with 'network' statements that overlap.
AnswerA

The DHCP server's pool selection for relayed requests hinges on the giaddr field. When a client broadcast is relayed, the relay agent must set giaddr to the IP address of the interface facing the client, and the server then matches that address against the network statements of its pools. If the giaddr is missing or set incorrectly—for example, because 'ip helper-address' is applied on the wrong interface or omitted—the server cannot identify subnet B and may select the first pool whose network range loosely matches, resulting in subnet A addresses.

Why this answer

When a DHCP relay agent forwards a client's request to the server, it inserts its own IP address (the interface address on the client's subnet) into the giaddr (gateway IP address) field. The DHCP server uses this giaddr to select the appropriate pool. If the relay agent fails to set the giaddr correctly—for example, due to misconfiguration or the relay interface not being on the correct subnet—the server may receive a giaddr of 0.0.0.0 or an incorrect address, causing it to fall back to the first configured pool that matches, which in this case is subnet A's pool.

Exam trap

Cisco often tests the misconception that DHCP pool selection is based on pool order or client MAC address, when in fact it relies on the giaddr set by the relay agent.

How to eliminate wrong answers

Option B is wrong because DHCP pool selection is not based on the order of pools or the client's MAC address; the server selects a pool based on the giaddr or the subnet of the receiving interface, not MAC address. Option C is wrong because 'ip dhcp smart-relay' is a Cisco feature that allows the relay agent to insert a giaddr when the client's broadcast is received on an interface without an IP address; it does not override pool selection but rather enables relaying in scenarios where the giaddr would otherwise be missing. Option D is wrong because overlapping 'network' statements would cause an ambiguous pool selection error or lease assignment failure, not a consistent misassignment to a different subnet's pool.

507
Multi-Selectmedium

Which TWO commands would a network engineer use to verify SNMP agent configuration and connectivity on a Cisco IOS router? (Choose TWO.)

Select 2 answers
A.show snmp
B.show snmp host
C.show snmp group
D.show snmp user
E.debug snmp packets
AnswersA, B

Displays SNMP agent statistics, community strings, and trap status.

Why this answer

The `show snmp` command displays the overall SNMP agent configuration, including contact, location, community strings, and SNMP version. The `show snmp host` command lists the configured SNMP notification receivers (trap or inform destinations) and verifies that the router is correctly configured to send SNMP messages to the management station. Together, these two commands confirm both the agent's operational state and its connectivity to remote hosts.

Exam trap

Cisco often tests the distinction between verification commands (show) and troubleshooting commands (debug), and the trap here is that candidates mistakenly choose `debug snmp packets` as a verification tool when it is actually a high-overhead diagnostic command that should only be used after initial configuration checks fail.

508
MCQhard

In an MPLS L3VPN environment, what is the default maximum number of routes that can be installed from a single BGP peer?

A.1000
B.Unlimited
C.10000
D.5000
AnswerB

Cisco IOS and IOS XE impose no default limit on routes installed from a single BGP peer; the maximum-prefix threshold is unset until an administrator configures it. This satisfies the scenario's constraint that the default value, absent explicit configuration, permits unlimited prefixes.

Why this answer

By default, Cisco IOS/IOS-XE does not impose a maximum prefix limit on routes received from a BGP peer — the default is unlimited. A limit is only enforced if the administrator explicitly configures 'neighbor x.x.x.x maximum-prefix <n>'. Therefore, absent any configuration, the peer can install an unlimited number of routes.

Exam trap

300-410 often tests default values — candidates assume a numeric default exists for BGP maximum-prefix, when in fact IOS imposes no limit unless explicitly configured.

How to eliminate wrong answers

Option A is wrong because 1000 is not a default BGP prefix limit; it would only apply if explicitly configured. Option C is wrong because 10000 is a common administrator-chosen value, not a Cisco default. Option D is wrong because 5000 is likewise an arbitrary configured value, not a platform default.

None of these numbers are imposed automatically by IOS.

509
MCQhard

OSPF network type mismatch on a multi-access link is causing route summarization issues. Router R1 and R2 are connected via Ethernet, but R1 has: interface GigabitEthernet0/0 ip address 10.0.0.1 255.255.255.0 ip ospf network point-to-point ip ospf 1 area 0 ! Router R2 has default OSPF network type (broadcast). R1 is configured with: router ospf 1 area 0 range 10.0.0.0 255.255.255.0 ! R2 shows: R2# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 10.0.0.1 0 FULL/ - 00:00:30 10.0.0.1 GigabitEthernet0/0 But R2 does not have the summary route in its routing table. What is the root cause?

A.R1 is not an ABR (only area 0), so the area range command does not generate a summary route.
B.The network type mismatch causes OSPF to not exchange LSAs correctly, preventing the summary.
C.The summary route is suppressed because the interface is point-to-point.
D.R2 has a static route that overrides the summary.
AnswerA

The area range command only generates a summary LSA when the router is an ABR with interfaces in multiple areas. R1 has only area 0, so it is an internal router and cannot originate a type-3 summary into another area.

Why this answer

The area range command is used on an Area Border Router (ABR) to summarize Type-3 LSAs between areas. R1 is only in area 0 (backbone), so it is not an ABR and cannot generate inter-area summary routes. Therefore, the area range command has no effect, and R2 will not receive a summary route.

The network type mismatch does not prevent LSA exchange because the neighbor relationship is FULL, as shown in the output.

Exam trap

The trap here is assuming that any router can perform area summarization with the area range command, when in fact only ABRs can generate inter-area summary routes; candidates may be distracted by the network type mismatch and incorrectly attribute the missing summary to that.

How to eliminate wrong answers

Option B is wrong because the neighbor state is FULL, indicating that LSAs are being exchanged correctly despite the network type mismatch; the mismatch affects DR/BDR election and hello timers, but not the summarization capability. Option C is wrong because point-to-point network type does not suppress summary routes; summarization is controlled by area range on ABRs, not by interface network type. Option D is wrong because there is no evidence of a static route on R2, and a static route would not prevent the summary from being generated by R1; the issue is that R1 cannot generate the summary at all.

510
MCQeasy

A network engineer runs the following command on Router R1: R1# show crypto isakmp sa dst src state conn-id slot status 10.1.1.2 10.1.1.1 QM_IDLE 1 0 ACTIVE Based on this output, which statement is correct?

A.IKE phase 1 is complete; the ISAKMP SA is established.
B.IKE phase 2 is complete; the IPsec SA is active.
C.The ISAKMP SA is in MM_NO_STATE; negotiation has failed.
D.The tunnel is down; the SA is in a dead state.
AnswerA

QM_IDLE with status ACTIVE confirms IKE phase 1 completed successfully and the ISAKMP SA is established between the peers. Quick Mode is idle because no phase 2 negotiation is currently in progress, not because phase 1 failed.

Why this answer

QM_IDLE indicates that IKE phase 1 (ISAKMP) is complete and the SA is idle, waiting for phase 2 negotiation. This is the normal state for an established ISAKMP SA.

511
MCQhard

A network engineer is implementing 802.1X authentication on a Cisco Catalyst switch. The engineer wants to ensure that if the RADIUS server is unavailable, the switch will place the port in a restricted VLAN for guest access. Which command must be configured on the switch port?

A.authentication event no-response action authorize vlan 100
B.authentication event server dead action authorize vlan 100
C.authentication event fail action authorize vlan 100
D.authentication fallback vlan 100
AnswerB

This command configures the switch to authorize the port into VLAN 100 when the RADIUS server is detected as dead. This provides a fallback mechanism for guest access when the authentication server is unreachable, exactly as required. The VLAN must be configured and allowed on the port.

Why this answer

The correct command to place a port in a restricted VLAN when the RADIUS server is dead is 'authentication event server dead action authorize vlan 100'. This event is triggered when the switch determines the server is unresponsive after multiple retries. The 'fail' event is for authentication failures, and 'no-response' is for individual request timeouts, not the server being declared dead.

Exam trap

The trap here is confusing the 'server dead' event with 'no-response' or 'fail' events, which trigger under different conditions.

512
MCQhard

A network engineer runs the following command to debug IPv6 uRPF: R1# debug ipv6 verify IPv6 verify debugging is on *Mar 1 00:02:34.567: IPv6 verify: source 2001:DB8:4::1 on GigabitEthernet0/0 *Mar 1 00:02:34.567: no route to source What does this output indicate?

A.The packet will be dropped because uRPF cannot find a route to the source address.
B.The packet will be forwarded because uRPF only checks the destination.
C.The packet will be forwarded because the source is on the same interface.
D.The router will add a route to the source address.
AnswerA

The debug line "no route to source" means the FIB lookup for 2001:DB8:4::1 failed, so strict uRPF cannot validate the return path and discards the packet. This satisfies the stem's requirement of identifying the drop cause directly from the verify output.

Why this answer

The debug output shows that uRPF (unicast Reverse Path Forwarding) checked the source address 2001:DB8:4::1 on the incoming interface GigabitEthernet0/0 and found no route to that source in the IPv6 routing table. When uRPF is enabled and a packet arrives on an interface, the router performs a reverse path lookup: it checks whether the best return route to the source address points back to the same interface. If no route exists at all, the lookup fails, and uRPF considers the source as unreachable, causing the packet to be dropped.

This is a strict-mode uRPF behavior, and the debug message 'no route to source' confirms the packet will be discarded.

Exam trap

Cisco often tests the misconception that uRPF checks the destination address or that it only verifies the source is on the same interface without requiring a route, but the key trap here is that 'no route to source' means the packet is dropped, not forwarded, because uRPF cannot validate the source without a matching route in the routing table.

How to eliminate wrong answers

Option B is wrong because uRPF checks the source address, not the destination; it verifies that the source is reachable via the incoming interface, which is a reverse-path check. Option C is wrong because the debug output explicitly states 'no route to source', meaning the router cannot find any route to the source address, so it cannot confirm the source is on the same interface; if it were, a route would exist pointing back to that interface. Option D is wrong because uRPF does not add routes; it only performs a lookup and either permits or drops the packet based on the existence and correctness of the reverse path.

513
MCQmedium

A network engineer runs the following command on Router PE2: PE2# show ip bgp vpnv4 vrf CUSTOMER_A 10.10.10.0 24 BGP routing table entry for 10.10.10.0/24, version 15 Paths: (1 available, best #1, table CUSTOMER_A) Advertised to update-groups: 1 Refresh Epoch 1 Local, imported path from 10.10.10.0/24 10.1.1.1 (metric 20) from 10.1.1.1 (10.1.1.1) Origin incomplete, metric 0, localpref 100, valid, internal, best Extended Community: RT:100:100 mpls labels in/out 18/19 Based on this output, what is the problem?

A.The route is not being advertised to any BGP peer.
B.The route is missing the required Route Target community.
C.The route is functioning correctly with no issues.
D.The route has an incorrect label binding.
AnswerC

The output shows a valid, best path with the correct RT:100:100 extended community and MPLS label bindings, imported into the CUSTOMER_A VRF. No error, missing route or label mismatch appears, so the VPNv4 route is operating normally.

Why this answer

The output shows a valid BGP VPNv4 route in the VRF CUSTOMER_A. The route is marked as 'best' and has the extended community RT:100:100, which is the route target. It is advertised to update-groups, and MPLS labels are present.

There is no indication of a problem; the route is functioning correctly.

Exam trap

The trap is assuming a problem exists when the output actually shows a healthy route; candidates might misread the extended community or label information.

How to eliminate wrong answers

Option A is wrong because the output shows 'Advertised to update-groups: 1', indicating it is being advertised. Option B is wrong because the extended community RT:100:100 is present, which is the route target. Option D is wrong because the MPLS labels in/out are shown (18/19), and there is no indication of incorrect label binding.

514
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip dhcp pool POOL1 Pool POOL1 : Utilization mark (high/low) : 100 / 0 Subnet size (first/next) : 0 / 0 Total addresses : 10 Leased addresses : 10 Pending event : none 1 subnet is currently in the pool : Current index IP address range Leased addresses 192.168.1.11 192.168.1.10 - 192.168.1.19 10 Based on this output, which statement is correct?

A.The DHCP pool has available addresses for new clients.
B.The DHCP pool is fully utilized; no more addresses are available.
C.The DHCP pool is configured with a /24 subnet.
D.The DHCP server has a pending event causing address allocation to fail.
AnswerB

The pool's ten addresses are all leased, matching the total address count, so no free leases remain for new clients. The current index at 192.168.1.11 confirms the server has cycled through the 192.168.1.10–192.168.1.19 range. Any further DHCP DISCOVER requesting this pool will receive no offer until a lease expires or is released.

Why this answer

The output shows that all 10 addresses in the pool (192.168.1.10–192.168.1.19) are leased, and the current index is 192.168.1.11, which is beyond the first address. This means no free addresses remain, so the pool is fully utilized. Option B correctly states this condition.

Exam trap

The trap here is that candidates often misinterpret the 'Current index' as the next available address, but it merely indicates the last allocation point; the true indicator of exhaustion is the 'Leased addresses' equaling 'Total addresses'.

How to eliminate wrong answers

Option A is wrong because the 'Leased addresses' count equals the 'Total addresses' (10), indicating zero available addresses for new clients. Option C is wrong because the IP address range 192.168.1.10–192.168.1.19 contains only 10 addresses, which corresponds to a /28 subnet mask (255.255.255.240), not a /24. Option D is wrong because the 'Pending event' field shows 'none', meaning there is no pending event causing allocation failures.

515
Multi-Selectmedium

Which TWO commands can be used to verify the operational status of a manually configured IPv6 tunnel on a Cisco IOS router? (Choose TWO.)

Select 2 answers
A.show interfaces tunnel 0
B.show ipv6 interface tunnel 0
C.show ipv6 route
D.show ipv6 tunnel 0
E.show running-config interface tunnel 0
AnswersA, B

`show interfaces tunnel 0` reports line protocol and tunnel status, directly confirming whether the manually configured IPv6 tunnel is up or down. It satisfies the stem's requirement to verify operational status, exposing encapsulation, source, and destination details alongside interface counters.

Why this answer

Option A, `show interfaces tunnel 0`, is correct because it displays the operational state (up/up or down/down) of the tunnel interface, along with line protocol status, encapsulation type, and packet counters, directly verifying whether the manually configured tunnel is functioning. Option B, `show ipv6 interface tunnel 0`, is correct because it confirms the tunnel interface's IPv6 configuration and operational status, including the link-local address, global IPv6 address, and whether IPv6 is enabled and up on that interface. Option C, `show ipv6 route`, only displays the IPv6 routing table and does not confirm the tunnel interface's operational state.

Option D, `show ipv6 tunnel 0`, is not a valid Cisco IOS command for verifying tunnel status. Option E, `show running-config interface tunnel 0`, only shows the configured commands in the running configuration and does not reflect the current operational status of the tunnel.

Exam trap

Cisco often tests the distinction between configuration verification commands (like 'show running-config') and operational status commands (like 'show interfaces' and 'show ipv6 interface'), leading candidates to mistakenly choose 'show running-config interface tunnel 0' as a verification tool for operational status.

516
MCQhard

An engineer configures iBGP between two routers in the same AS. The BGP table shows the prefix, but it is not installed in the routing table. The next-hop is reachable via an IGP route. Which is the most likely explanation?

A.BGP synchronization is enabled, and the prefix is not present in the IGP.
B.The next-hop-self command is missing on the iBGP peer.
C.The prefix is filtered by an inbound route-map.
D.The maximum-paths limit is exceeded.
AnswerA

With BGP synchronisation enabled, iBGP-learned routes are not installed unless the same prefix exists in the IGP. The prefix sits in the BGP table but is withheld from the routing table until IGP convergence provides it.

Why this answer

When BGP synchronization is enabled, the router will not install an iBGP-learned prefix into the routing table unless the same prefix is also present in the IGP (e.g., OSPF or EIGRP). Since the next-hop is reachable via IGP but the prefix itself is not in the IGP, the synchronization rule blocks the route from being installed. This is a classic scenario where the BGP table shows the prefix, but it is missing from the routing table.

Exam trap

Cisco often tests the BGP synchronization rule as a subtle cause of routes being in the BGP table but not in the routing table, leading candidates to mistakenly focus on next-hop reachability or filtering issues.

How to eliminate wrong answers

Option B is wrong because the next-hop-self command affects the next-hop attribute of routes advertised to iBGP peers, but the issue here is that the next-hop is already reachable via IGP, so missing next-hop-self would not prevent installation. Option C is wrong because if the prefix were filtered by an inbound route-map, it would not appear in the BGP table at all, yet the question states the prefix is present in the BGP table. Option D is wrong because exceeding the maximum-paths limit would affect load balancing, not the installation of a single route; the router would still install one best path.

517
Multi-Selecthard

Which THREE commands are used to troubleshoot VRF-Lite connectivity issues on a Cisco IOS-XE router? (Choose THREE.)

Select 3 answers
A.show ip route vrf <vrf-name>
B.ping vrf <vrf-name> <destination>
C.show vrf
D.traceroute <destination>
E.show ip cef
AnswersA, B, C

Displays the VRF-specific routing table, confirming whether the target prefix was learned and installed within that VRF's RIB. This satisfies the stem's VRF-Lite troubleshooting need by separating per-VRF routing state from the global table, exposing missing or incorrect routes.

Why this answer

These three commands provide essential troubleshooting information: 'show ip route vrf' displays the VRF routing table, 'ping vrf' tests connectivity from within a VRF, and 'show vrf' shows VRF status and interfaces. The other options: 'traceroute' without VRF context may not work correctly, and 'show ip cef' without VRF shows global CEF, not VRF-specific.

518
MCQeasy

A network engineer is troubleshooting a router that is sending duplicate SNMP traps for interface state changes. The engineer finds two EEM applets that both trigger on the same syslog pattern 'LINK-3-UPDOWN' and both send SNMP traps. What should the engineer do to resolve the duplicate traps?

A.Disable syslog logging for interface state changes.
B.Remove one of the duplicate EEM applets.
C.Change the SNMP trap destination to a different host for one applet.
D.Increase the SNMP trap queue size.
AnswerB

Both EEM applets match the same LINK-3-UPDOWN syslog pattern and each fires an SNMP trap, so the duplication stems from redundant applet definitions. Removing one applet eliminates the second trap source while preserving the remaining applet's notification behaviour.

Why this answer

Duplicate SNMP traps are being generated because two EEM applets are both triggered by the same syslog pattern and both execute an SNMP trap action. Removing one of the duplicate applets eliminates the redundant trigger and restores a single trap per event. This is the direct, root-cause fix.

Exam trap

The trap is that candidates try to suppress symptoms (disable logging, change destination, increase queue) instead of identifying the root cause — two EEM applets triggering on the same syslog pattern.

How to eliminate wrong answers

Option A is wrong because disabling syslog logging for interface state changes would suppress the trigger event entirely, breaking both applets and losing visibility rather than fixing duplication. Option C is wrong because changing the trap destination for one applet would still send two traps (to two different hosts), not resolve the duplication. Option D is wrong because increasing the SNMP trap queue size only affects buffering of outbound traps and does nothing to stop duplicate generation.

519
MCQmedium

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# debug ip sla monitor trace IP SLAs Monitor trace debugging is on *Mar 1 12:34:56.789: IP SLAs Monitor: Starting operation 10 *Mar 1 12:34:56.789: IP SLAs Monitor: Sending ICMP echo request to 192.168.1.1 *Mar 1 12:34:56.790: IP SLAs Monitor: Received ICMP echo reply from 192.168.1.1 *Mar 1 12:34:56.790: IP SLAs Monitor: RTT = 12 ms *Mar 1 12:34:56.790: IP SLAs Monitor: Operation 10 completed successfully *Mar 1 12:35:56.789: IP SLAs Monitor: Starting operation 10 *Mar 1 12:35:56.789: IP SLAs Monitor: Sending ICMP echo request to 192.168.1.1 *Mar 1 12:35:56.790: IP SLAs Monitor: Received ICMP echo reply from 192.168.1.1 *Mar 1 12:35:56.790: IP SLAs Monitor: RTT = 14 ms *Mar 1 12:35:56.790: IP SLAs Monitor: Operation 10 completed successfully What does this output indicate?

A.The IP SLA monitor operation is failing because the RTT values are increasing.
B.The IP SLA monitor operation is successfully sending and receiving ICMP echo probes.
C.The IP SLA monitor operation is not configured because no configuration is shown.
D.The IP SLA monitor operation is timing out because no reply is received.
AnswerB

Each cycle shows operation 10 sending an ICMP echo request to 192.168.1.1, receiving the echo reply, and reporting an RTT of 12–14 ms before completing successfully. That confirms the probe path is working, so the monitor is actively sending and receiving ICMP echoes as configured.

Why this answer

The debug output shows IP SLA operation 10 successfully sending ICMP echo requests to 192.168.1.1 and receiving echo replies, with round-trip times of 12 ms and 14 ms, and each operation completing successfully. This confirms the IP SLA probe is functioning correctly and the target is reachable. The slight RTT variation between probes is normal jitter, not a failure condition.

Exam trap

The trap is misreading normal RTT variation as degradation or failure — candidates must recognize that successful send/receive pairs with stable RTTs indicate a healthy probe, and that only missing replies or threshold breaches constitute failure.

How to eliminate wrong answers

Option A is wrong because a 12 ms to 14 ms RTT change is normal network jitter and does not indicate failure — IP SLA thresholds, not raw RTT deltas, determine pass/fail. Option C is wrong because the debug output explicitly shows operation 10 running and completing, which proves the operation is configured and active. Option D is wrong because the log clearly shows 'Received ICMP echo reply from 192.168.1.1' for both probes, so there is no timeout.

520
MCQhard

A network engineer runs the following command on Router R1: R1# show ip bgp neighbors 10.2.2.2 advertised-routes BGP table version is 10, local router ID is 1.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.1.1.0/24 0.0.0.0 0 32768 i *> 10.2.2.0/24 0.0.0.0 0 32768 i Total number of prefixes 2 Based on this output, what is the problem?

A.The routes are correctly advertised with next hop 0.0.0.0, which is normal for locally originated routes.
B.The routes are not being advertised to eBGP peers because the next hop is 0.0.0.0, which is invalid for eBGP.
C.The routes are being advertised to iBGP peers only, as indicated by the next hop 0.0.0.0.
D.The routes are redistributed from an IGP into BGP, and the next hop is correctly set to 0.0.0.0.
AnswerA

Advertising locally originated networks shows next hop 0.0.0.0, weight 32768 and an empty path — exactly what R1's output displays for both prefixes. The stem's constraint, identifying why the advertisement looks unusual, is satisfied because this is expected BGP behaviour for networks injected via the network command, not a fault.

Why this answer

The output shows two locally originated BGP routes (weight 32768, origin IGP) with next hop 0.0.0.0, which is the standard representation for networks that the local router itself originated into BGP via the network command. The 'advertised-routes' keyword confirms these prefixes are being sent to neighbor 10.2.2.2, so there is no advertisement problem at all. Next hop 0.0.0.0 in the local BGP table simply means 'this router is the origin of the route.'

Exam trap

The trap here is misinterpreting next hop 0.0.0.0 as an error or as evidence that routes are not being advertised, when in fact it is the normal representation for locally originated BGP routes.

How to eliminate wrong answers

Option B is wrong because 0.0.0.0 as a next hop in the local BGP table is not transmitted as-is to eBGP peers — the router rewrites the next hop to its own outgoing interface address when advertising to an eBGP neighbor, so eBGP advertisement is unaffected. Option C is wrong because the next hop value 0.0.0.0 does not indicate iBGP-only advertisement; it indicates local origination, and the 'advertised-routes' output is per-neighbor regardless of iBGP/eBGP. Option D is wrong because weight 32768 and origin code 'i' indicate locally originated routes (via the network command), not redistributed routes — redistributed routes would typically show origin '?' or 'e' and no weight of 32768.

521
MCQmedium

A network engineer is troubleshooting an MPLS L3VPN where customer routes are not being advertised from one PE to another. The engineer verifies that the VRFs are configured correctly, the IGP is converged, and the PE routers have established an MP-BGP session. Which command should the engineer use to verify that the VPNv4 prefixes are being exchanged correctly?

A.show mpls forwarding-table
B.show ip bgp vpnv4 all
C.show ip route vrf <vrf-name>
D.show ip bgp summary
AnswerB

The show ip bgp vpnv4 all command displays the VPNv4 routing table, including all prefixes learned from other PE routers. It shows the route targets, MPLS labels, and next-hops, which are crucial for verifying that VPNv4 prefixes are exchanged correctly. This is the primary command for troubleshooting MPLS L3VPN route propagation.

Why this answer

To verify that VPNv4 prefixes are being exchanged between PE routers, the engineer should use show ip bgp vpnv4 all. This command displays the VPNv4 BGP table, showing all VPNv4 routes, their next-hops, labels, and route targets. It is the most direct way to confirm that MP-BGP is propagating customer VPN routes correctly.

Exam trap

The trap here is relying on show ip bgp summary or show ip route vrf, which confirm session state or local VRF routes but do not show the actual VPNv4 prefix exchange.

522
MCQhard

Router R1 and R2 are running OSPF in area 0. R1 has a loopback interface with IP 192.168.1.1/32 advertised into OSPF. R2 learns this route as an intra-area route (AD 110). R2 also runs RIP and learns the same prefix from R3 with AD 120. R2's 'show ip route 192.168.1.1' shows the RIP route. What is the root cause?

A.R2's OSPF process has 'distance 130' configured, making OSPF routes have AD 130, which is higher than RIP's AD 120.
B.The RIP route has a better metric than the OSPF route.
C.R2 has a static route with AD 1 that overrides both.
D.The OSPF route is an external route with AD 170 due to redistribution.
AnswerA

The 'distance 130' command under the OSPF process raises OSPF's administrative distance to 130, above RIP's 120. R2 therefore prefers the RIP route for 192.168.1.1/32 despite OSPF being intra-area, explaining the unexpected 'show ip route' output.

Why this answer

Administrative distance (AD) is the tiebreaker when two routing protocols offer the same prefix; lower AD wins. By default, OSPF has AD 110 and RIP has AD 120, so OSPF should win. The fact that RIP appears in the routing table means OSPF's AD was raised above 120 — the 'distance 130' configuration under the OSPF process does exactly that, making OSPF (130) lose to RIP (120).

This is the only option consistent with the observed outcome.

Exam trap

300-410 often tests the misconception that the lowest-metric route always wins — candidates forget that administrative distance is compared before metrics across different routing protocols.

How to eliminate wrong answers

Option B is wrong because metric comparison only happens within the same protocol; across protocols, AD is compared first, so RIP's metric is irrelevant unless ADs tie. Option C is wrong because the question states the RIP route is installed, not a static route — and a static route with AD 1 would appear as 'S' in the routing table, not 'R'. Option D is wrong because the question explicitly says R2 learns the prefix as an intra-area OSPF route (AD 110), not an external route (AD 170); external OSPF routes would be O E1/O E2 and would indeed lose to RIP, but that contradicts the given intra-area status.

523
MCQhard

An engineer configures an IPv4 ACL on a router's interface to permit only HTTP traffic (TCP port 80) from a specific subnet. The ACL is applied inbound. After applying, the router's web interface (HTTPS) becomes unreachable from the same subnet. What is the most likely explanation?

A.The ACL denies HTTPS traffic because it is not explicitly permitted.
B.The ACL is applied outbound, filtering traffic to the web server.
C.The router's web server uses HTTP, not HTTPS.
D.The ACL is blocking TCP port 80 due to a typo.
AnswerA

An ACL applied inbound ends with an implicit deny any. Because only TCP port 80 is permitted, HTTPS (TCP 443) traffic from that subnet is dropped, making the router's web interface unreachable from those hosts.

Why this answer

The ACL is applied inbound on the router interface and only permits TCP port 80 (HTTP). HTTPS uses TCP port 443, which is not explicitly permitted. Since IPv4 ACLs end with an implicit deny any, all traffic not matching a permit statement, including HTTPS, is denied.

This causes the router's web interface (HTTPS) to become unreachable from the subnet.

Exam trap

Cisco often tests the implicit deny any behavior of ACLs and the fact that management protocols (like HTTPS, SSH, SNMP) use different ports than the permitted traffic, causing candidates to overlook the need to explicitly permit those ports.

How to eliminate wrong answers

Option B is wrong because the ACL is explicitly stated as applied inbound, not outbound; an outbound ACL would filter traffic leaving the interface, not traffic entering from the subnet. Option C is wrong because the router's web interface is accessed via HTTPS (TCP 443), not HTTP (TCP 80), and the question confirms it is HTTPS. Option D is wrong because the issue is not a typo on port 80; the ACL correctly permits HTTP, but HTTPS is blocked by the implicit deny, not by a misconfiguration of the permit statement.

524
MCQmedium

Consider the following configuration on a PE router: ip vrf CUSTOMER-B rd 100:1 route-target export 100:1 route-target import 100:2 ! interface GigabitEthernet0/2 ip vrf forwarding CUSTOMER-B ip address 192.168.2.1 255.255.255.252 What is the effect of this configuration?

A.The PE will export routes from VRF CUSTOMER-B with RT 100:1 and import routes with RT 100:2.
B.The PE will export routes with RT 100:2 and import routes with RT 100:1.
C.The VRF will not work because the RD and RT must be identical.
D.The VRF will not work because route-target import and export must be configured under the BGP VRF address-family.
AnswerA

The route-target export 100:1 attaches RT 100:1 to routes leaving VRF CUSTOMER-B, while route-target import 100:2 accepts routes carrying RT 100:2 into that VRF. The route distinguisher 100:1 only makes prefixes unique, not controls import or export.

Why this answer

The VRF has a route distinguisher and route-targets. The export RT is 100:1, meaning routes from this VRF are exported with that RT. The import RT is 100:2, so only routes with RT 100:2 are imported.

This is a common setup for hub-and-spoke or inter-AS options.

525
MCQmedium

Which EIGRP packet type is used to confirm receipt of an update during reliable transport?

A.Hello
B.Update
C.ACK
D.Query
AnswerC

EIGRP uses the ACK packet to confirm receipt of updates, queries, and replies during reliable transport, satisfying the reliable delivery requirement. Unlike Hello packets, which are unreliable and need no acknowledgement, ACKs carry no data and are sent as unicast to the originating router, confirming that specific update was received.

Why this answer

C is correct because EIGRP uses a reliable transport protocol (RTP) to ensure delivery of certain packets like Updates, Queries, and Replies. The ACK packet is a lightweight, unreliable packet sent to explicitly acknowledge receipt of a reliable packet, confirming that the update was received without needing a full retransmission.

Exam trap

The trap here is that candidates confuse the purpose of Hello packets (which are also small and frequent) with ACK packets, forgetting that Hellos are used for neighbor discovery and keepalive, not for reliable transport acknowledgment.

How to eliminate wrong answers

Option A is wrong because Hello packets are used for neighbor discovery and keepalive, not for acknowledging reliable updates; they are sent unreliably via multicast. Option B is wrong because Update packets carry routing information and are themselves sent reliably, requiring an ACK in response rather than serving as an acknowledgment. Option D is wrong because Query packets are sent reliably to request routing information from neighbors and, like Updates, require an ACK to confirm receipt, not to acknowledge other packets.

Page 6

Page 7 of 19

Page 8