Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 526–600

1401 questions total · 19pages · All types, answers revealed

Page 7

Page 8 of 19

Page 9
526
MCQmedium

A network engineer is configuring a route map for BGP policy. The engineer wants to match routes that originate from AS 65001 and have a community value of 100:200. The route map should then set the local preference to 200. Which configuration snippet accomplishes this?

A.ip as-path access-list 1 permit ^65001$ route-map POLICY permit 10 match as-path 1 set local-preference 200
B.route-map POLICY permit 10 match as-path 1 match community 1 set local-preference 200
C.ip as-path access-list 1 permit ^65001$ ip community-list standard 1 permit 100:200 route-map POLICY permit 10 match as-path 1 match community 1 set local-preference 200
D.ip community-list standard 1 permit 100:200 route-map POLICY permit 10 match community 1 set local-preference 200
AnswerC

This configuration defines an AS-path access list to match routes originating from AS 65001 (using the regular expression ^65001$) and a community list to match the community 100:200. The route map then matches both conditions and sets the local preference to 200. This fully satisfies the requirement.

Why this answer

To match routes from AS 65001 with community 100:200 and set local preference, the configuration must include both an AS-path access list and a community list, and apply both matches in the route map. The correct snippet defines the AS-path access list with the regex ^65001$ to match routes originated in AS 65001, defines a standard community list to match 100:200, and then uses both in the route map with the set clause.

Exam trap

The trap here is forgetting to define the community list or the AS-path access list, or using a regex that matches AS 65001 anywhere in the path rather than as the origin.

527
MCQhard

A network administrator is troubleshooting an OSPFv3 network. Routers R1 and R2 are in the same area and on the same broadcast segment, but they are not forming an adjacency. The administrator verifies that the interfaces are up and IPv6 addresses are configured correctly. Which command should be used to check if OSPFv3 is enabled on the interfaces?

A.show ipv6 protocols
B.show ipv6 ospf neighbor
C.show ipv6 ospf interface
D.show ipv6 ospf database
AnswerC

The command 'show ipv6 ospf interface' displays OSPFv3 interface status, including whether OSPFv3 is enabled on the interface, the area ID, and the state. If OSPFv3 is not enabled, the interface will not appear or will show as passive. This directly answers the question of whether OSPFv3 is enabled on the interfaces.

Why this answer

To verify OSPFv3 interface configuration, the 'show ipv6 ospf interface' command is used. It shows whether OSPFv3 is enabled on the interface, the area, network type, and other parameters. This is the most direct way to confirm OSPFv3 is active on the interfaces.

Exam trap

The trap here is confusing neighbor state with interface configuration; a missing neighbor does not necessarily mean OSPFv3 is not enabled, but checking the interface status is the first step.

528
MCQeasy

Which LDP message type is used to request label bindings from a neighbor?

A.Label Request message
B.Label Mapping message
C.Label Withdraw message
D.Label Release message
AnswerA

The Label Request message is sent by an LSR to ask a neighbour for a label binding for a specific FEC. Label Mapping returns the binding, Label Withdraw removes it, and Label Release acknowledges it, so Label Request is the correct request type.

Why this answer

The Label Request message is sent by an LDP router to request a label binding for a specific FEC from its neighbor.

529
Multi-Selecthard

Which TWO statements correctly describe the behavior of TTL propagation in MPLS networks? (Choose TWO.)

Select 2 answers
A.Disabling TTL propagation prevents traceroute from revealing the internal LSR hops.
B.The command 'no mpls ip propagate-ttl' is used to disable TTL propagation on a Cisco IOS router.
C.The command 'no mpls ip ttl-propagate' is used to disable TTL propagation.
D.When TTL propagation is disabled, traceroute shows every LSR hop in the MPLS core.
E.When TTL propagation is disabled, the TTL value is decremented normally at each LSR hop.
AnswersA, B

Disabling TTL propagation stops the ingress LSR copying the IP TTL into the MPLS header, so transit LSRs decrement a value that never reaches the traceroute probe. Internal hops therefore appear as a single MPLS cloud, satisfying the requirement to conceal provider core topology from customers.

Why this answer

In MPLS, TTL propagation can be disabled for security or to hide the core topology. When disabled, the IP TTL is copied to the MPLS label only at the ingress LSR, and at the egress LSR the MPLS TTL is copied back to the IP header. By default, TTL propagation is enabled.

The command 'no mpls ip propagate-ttl' disables it. Option A is correct because disabling TTL propagation hides the core hops from traceroute. Option B is correct because the command to disable is indeed 'no mpls ip propagate-ttl'.

Option C is false: the command is not 'no mpls ip ttl-propagate'. Option D is false: traceroute shows only the ingress and egress LSRs, not all hops. Option E is false: when disabled, the TTL is not decremented across the MPLS core.

530
MCQmedium

A network engineer is troubleshooting an issue where IPv6 hosts are receiving multiple Router Advertisements from different routers, causing routing instability. The switch is configured with IPv6 First Hop Security features. The engineer wants to ensure that only the primary router's RAs are accepted by hosts. What is the most effective solution?

A.Configure RA Guard with a policy that includes the primary router's MAC address in the allowed list and apply it to all ports.
B.Enable DHCPv6 Guard to block DHCPv6 messages from the secondary router.
C.Use IPv6 Source Guard to filter traffic from the secondary router.
D.Configure the switch to act as a router and send its own RAs with a higher priority to override the secondary router.
AnswerA

RA Guard with a MAC allow-list filters Router Advertisements at Layer 2, permitting only the primary router's frames while dropping rogue RAs on host-facing ports. This directly satisfies the requirement that hosts accept RAs solely from the designated primary router, restoring stable IPv6 default gateway selection.

Why this answer

RA Guard with a policy that includes the primary router's MAC address in the allowed list is the most effective solution because it filters Router Advertisements (RAs) at Layer 2, permitting only RAs from the trusted primary router. This directly addresses the issue of multiple RAs causing routing instability by blocking RAs from any other source, such as the secondary router, without affecting other IPv6 traffic. RA Guard is an IPv6 First Hop Security feature designed specifically to prevent rogue or unwanted RAs from being processed by hosts.

Exam trap

Cisco often tests the distinction between IPv6 First Hop Security features, where candidates confuse RA Guard (which filters RAs) with DHCPv6 Guard (which filters DHCPv6 messages) or IPv6 Source Guard (which prevents address spoofing), leading them to select an option that addresses a different type of attack or instability.

How to eliminate wrong answers

Option B is wrong because DHCPv6 Guard blocks DHCPv6 messages (e.g., DHCPv6 Advertise/Reply), not Router Advertisements (RAs), so it does not prevent hosts from receiving multiple RAs. Option C is wrong because IPv6 Source Guard filters traffic based on source IPv6 address and MAC address bindings to prevent spoofing, but it does not inspect or filter RA messages specifically, so it cannot block unwanted RAs. Option D is wrong because configuring the switch to send its own RAs with a higher priority does not stop the secondary router from sending RAs; hosts would still receive multiple RAs, and the switch's RAs could introduce additional instability rather than resolving the issue.

531
MCQhard

A network administrator is troubleshooting an EIGRP network where a router is not receiving all expected routes from a neighbor. The neighbor relationship is established, and the topology table shows only a subset of routes. Which EIGRP feature could be filtering the routes?

A.EIGRP route filtering using distribute-list
B.EIGRP variance
C.EIGRP authentication mismatch
D.EIGRP stub routing
AnswerA

A distribute-list can filter incoming or outgoing EIGRP routes. If applied inbound on the local router, it can prevent specific routes from being installed in the topology table. This matches the symptom of missing routes despite an established neighbor relationship. The distribute-list can reference an ACL or prefix-list to selectively filter routes based on network numbers or masks.

Why this answer

EIGRP distribute-lists can filter routes either inbound or outbound. An inbound distribute-list applied on the local router can prevent specific routes from entering the topology table, even though the neighbor adjacency is up. This is a common cause of missing routes when the neighbor relationship is healthy.

The distribute-list can use ACLs, prefix-lists, or route-maps to match and filter routes.

Exam trap

The trap here is confusing route filtering with neighbor adjacency issues; a distribute-list can silently drop routes without affecting the neighbor relationship.

532
Multi-Selectmedium

Which TWO commands would a network engineer use to verify that syslog messages are being sent to a remote syslog server? (Choose TWO.)

Select 2 answers
A.show logging
B.debug logging
C.show running-config | include logging
D.ping <syslog-server-ip>
E.show ip route
AnswersA, C

show logging displays the logging configuration plus a live tail of generated messages, including the destination host and severity. This confirms messages are actually being produced and forwarded, satisfying the requirement to verify syslog transmission to the remote server.

Why this answer

Option A, 'show logging', is correct because on Cisco IOS this command displays the local logging configuration (including the syslog server host address set with 'logging host') and the status of logging to that host, confirming whether messages are being sent to the remote syslog server. Option C, 'show running-config | include logging', is correct because it filters the running configuration for all logging-related lines, revealing the configured 'logging host <ip>' and 'logging trap' level that determine whether and where syslog messages are forwarded. Option B, 'debug logging', is not a valid verification command and would only generate additional debug output rather than confirm the syslog destination.

Option D, 'ping <syslog-server-ip>', only tests IP reachability to the server and does not verify that syslog messages are actually being sent or logged. Option E, 'show ip route', merely displays the routing table and provides no information about syslog configuration or message transmission.

533
MCQeasy

A network administrator is configuring AAA on a Cisco IOS router to authenticate administrative SSH users against a TACACS+ server. The administrator wants to ensure that if the TACACS+ server is unreachable, a locally configured user account can still be used for authentication. Which configuration should the administrator apply?

A.aaa authentication login default group tacacs+ none
B.aaa authentication login default group tacacs+ local
C.aaa authentication login default local group tacacs+
D.aaa authentication login default group tacacs+ enable
AnswerB

The 'aaa authentication login default group tacacs+ local' command configures the default login authentication method list to first attempt TACACS+ and then fall back to the local user database if the TACACS+ server does not respond. This provides the required resilience, allowing administrative access even when the TACACS+ server is unreachable, as long as a local username is configured.

Why this answer

The 'aaa authentication login default group tacacs+ local' command creates a method list that tries TACACS+ first and then the local username database. This ensures that if the TACACS+ server is unreachable, administrators can still log in using locally configured credentials. The order of methods is critical: TACACS+ must be primary to maintain centralized authentication, with local as a backup for resiliency.

Exam trap

The trap here is reversing the order of authentication methods or using 'none' as a fallback, which either prioritizes local accounts over TACACS+ or bypasses authentication entirely.

534
MCQmedium

A network engineer is configuring Policy-Based Routing (PBR) on a Cisco IOS-XE router. The engineer wants to route traffic from the 10.1.1.0/24 subnet that is destined for any TCP port 80 to next-hop 192.168.2.1, but only for packets arriving on GigabitEthernet0/1. Other traffic should follow the normal routing table. Which configuration sequence correctly accomplishes this?

A.Create a route-map with a match statement for IP address 10.1.1.0/24 and a set statement for interface GigabitEthernet0/2, then apply it globally with the ip local policy route-map command.
B.Create a standard ACL that permits 10.1.1.0 0.0.0.255, reference it in a route-map match statement, set the next-hop to 192.168.2.1, and apply the route-map to interface GigabitEthernet0/1 with the ip policy route-map command.
C.Create a route-map with a match statement for IP address 10.1.1.0/24 and a set statement for next-hop 192.168.2.1, then apply it to interface GigabitEthernet0/1 using the ip policy route-map command.
D.Create an extended ACL that permits tcp 10.1.1.0 0.0.0.255 any eq 80, reference it in a route-map match statement, set the next-hop to 192.168.2.1, and apply the route-map to interface GigabitEthernet0/1 with the ip policy route-map command.
AnswerD

This correctly matches the source subnet and HTTP destination port using an extended ACL, then sets the next-hop for matching packets. Applying the route-map inbound on GigabitEthernet0/1 ensures only traffic arriving on that interface is policy-routed. This meets all conditions: specific source, specific destination port, and interface restriction.

Why this answer

The correct configuration uses an extended ACL to match both source subnet and destination TCP port 80, references it in a route-map, sets the next-hop, and applies the route-map inbound on the specified interface. This ensures only HTTP traffic from 10.1.1.0/24 arriving on GigabitEthernet0/1 is policy-routed, while other traffic follows normal routing.

Exam trap

The trap here is confusing standard and extended ACLs for matching in route-maps, or applying PBR globally instead of on the ingress interface.

535
MCQhard

Which MPLS label value is reserved for the Explicit NULL label and what is its purpose?

A.Label 0; used for the Explicit NULL label to indicate that the penultimate hop should pop the label.
B.Label 1; used for the Router Alert label.
C.Label 2; used for the Implicit NULL label.
D.Label 3; used for the Implicit NULL label.
AnswerA

Label 0 is the IPv4 Explicit NULL per RFC 3032.

Why this answer

Label value 0 is the IPv4 Explicit NULL label, used to signal the penultimate hop to pop the label stack and forward the packet based on the IP header.

536
MCQmedium

Consider this configuration on Router R5: ``` interface Tunnel0 ipv6 address 2001:DB8:7::1/64 tunnel source 192.168.10.1 tunnel destination 192.168.20.2 tunnel mode ipv6ip tunnel ttl 64 ``` What is the effect?

A.The tunnel will not work because the tunnel source is an IP address, not an interface.
B.The tunnel will work, and the TTL field in the outer IPv4 header will be set to 64.
C.The tunnel mode should be 'gre ip' for IPv6 over IPv4.
D.The tunnel will use the IPv6 TTL for the outer header.
AnswerB

The tunnel ttl 64 command sets the Time To Live value in the outer IPv4 header of the encapsulated packets, not the inner IPv6 hop limit. The ipv6ip mode tunnel between the configured IPv4 endpoints therefore forwards traffic normally.

Why this answer

The configuration creates an IPv6-over-IPv4 manual tunnel (tunnel mode ipv6ip). The tunnel source is specified as an IP address, which is valid; the router uses that address as the source of the outer IPv4 header. The 'tunnel ttl 64' command explicitly sets the Time-to-Live field in the outer IPv4 header to 64, overriding the default value.

Exam trap

Cisco often tests the misconception that the tunnel source must be an interface name, or that the outer header's TTL is inherited from the inner packet, leading candidates to incorrectly eliminate the correct answer.

How to eliminate wrong answers

Option A is wrong because the tunnel source can be either an interface name or an IP address; specifying an IP address is perfectly valid and the router will use that address as the source of the outer IPv4 header. Option C is wrong because 'tunnel mode ipv6ip' is the correct mode for IPv6-over-IPv4 manual tunnels (RFC 4213), not 'gre ip', which is used for generic routing encapsulation and does not carry the IPv6 protocol type natively. Option D is wrong because the outer IPv4 header uses its own TTL field, which is set by the 'tunnel ttl' command; the inner IPv6 packet's Hop Limit is not copied to the outer header.

537
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip policy Interface Route-map GigabitEthernet0/0 PBR-TRACK R1# show route-map PBR-TRACK route-map PBR-TRACK, permit, sequence 10 Match clauses: ip address (access-lists): 170 Set clauses: ip next-hop verify-availability 10.0.0.2 10 track 2 Policy routing matches: 100 packets, 8000 bytes R1# show track 2 Track 2 IP SLA 2 reachability Reachability is Up 2 changes, last change 00:01:30 Latest operation return code: ok Tracked by: ROUTE-MAP 0 R1# show ip route 10.0.0.2 Routing entry for 10.0.0.2/32 Known via "eigrp 1", distance 90, metric 28160 Last update from 192.168.1.2 on GigabitEthernet0/1 Based on this output, what is the most likely behavior for packets matching ACL 170?

A.Packets are forwarded to 10.0.0.2.
B.Packets are forwarded using the routing table because the next-hop is not reachable.
C.Packets are dropped because the track object is not configured correctly.
D.Packets are load-balanced between the next-hop and the routing table.
AnswerA

The route-map sets the next hop to 10.0.0.2 with verify-availability tied to track 2, which reports IP SLA reachability as Up. Because the tracked object is up, the set clause remains valid, so matching packets are policy-routed to 10.0.0.2.

Why this answer

The route-map PBR-TRACK sets the next-hop to 10.0.0.2 with verify-availability and track 2. The show track 2 output indicates that IP SLA 2 reachability is Up, meaning the tracked object is available. Therefore, the policy-based routing will forward matching packets to 10.0.0.2.

The route to 10.0.0.2 exists via EIGRP, confirming reachability.

Exam trap

300-410 often tests the interpretation of show track and show route-map outputs, and candidates may incorrectly assume the next-hop is unreachable or that PBR load-balances when only one next-hop is configured.

How to eliminate wrong answers

Option B is wrong because the next-hop is reachable (track is Up and route exists), so the routing table is not used as a fallback. Option C is wrong because the track object is configured correctly and is Up, so packets are not dropped. Option D is wrong because PBR with a single next-hop does not load-balance; it forwards all matching packets to the specified next-hop.

538
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip bgp vpnv4 vrf RED summary BGP router identifier 192.168.0.1, local AS number 65001 BGP table version is 5, main routing table version 5 4 network entries using 576 bytes of memory 4 path entries using 320 bytes of memory 2/1 BGP path/bestpath attribute entries using 320 bytes of memory 0 BGP route-map cache entries using 0 bytes of memory 0 BGP filter-list cache entries using 0 bytes of memory BGP using 1216 total bytes of memory BGP activity 4/0 prefixes, 4/0 paths, scan interval 60 secs Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 10.1.1.2 4 65001 23 25 5 0 0 00:12:34 2 10.1.2.2 4 65002 18 20 5 0 0 00:10:15 1 Based on this output, which statement is correct?

A.Both BGP neighbors are in the Established state.
B.Neighbor 10.1.2.2 is in the Idle state.
C.The local AS number is 65002.
D.Neighbor 10.1.1.2 is in AS 65002.
AnswerA

The State/PfxRcd column shows numeric prefix counts (2 and 1) rather than a state name such as Idle or Active. BGP displays Established as a prefix count, confirming both neighbours completed peering and exchanged routes.

Why this answer

The 'show bgp vpnv4 vrf RED summary' command displays BGP neighbors for VRF RED. It shows two neighbors: 10.1.1.2 (AS 65001) and 10.1.2.2 (AS 65002). Both are in the Established state with prefixes received.

The neighbor 10.1.1.2 has received 2 prefixes, and 10.1.2.2 has received 1 prefix.

539
MCQhard

A network engineer configures CoPP on a router that is a DMVPN hub. The policy includes a class-map to match NHRP traffic and police it. After deployment, spoke-to-spoke tunnels fail to establish, although spoke-to-hub tunnels work. Which is the most likely explanation?

A.The CoPP policy drops IPsec packets, which are used for spoke-to-spoke encryption.
B.The CoPP policy polices NHRP traffic, causing NHRP redirect packets from the hub to be dropped, so spokes cannot learn each other's addresses.
C.The CoPP policy is applied to the tunnel interface, not the control plane.
D.The CoPP policy uses the default class class-default, which blocks NHRP.
AnswerB

NHRP redirect messages let the hub tell spokes to build direct tunnels, and these arrive as unicast IP packets matched by the CoPP class. Policing drops them, so spokes never learn peer NBMA addresses; spoke-to-hub registration still succeeds because that traffic is not redirected.

Why this answer

In a DMVPN hub-and-spoke topology, spoke-to-spoke tunnels rely on NHRP redirect messages from the hub to learn each other's public addresses. If CoPP polices NHRP traffic too aggressively, the hub may drop NHRP redirect packets before they reach the spokes. Without these redirects, spokes cannot initiate direct tunnels, even though spoke-to-hub communication (which uses the hub as a relay) remains functional.

Exam trap

Cisco often tests the distinction between control-plane and data-plane traffic in DMVPN; the trap here is that candidates assume spoke-to-spoke failures are caused by IPsec or tunnel interface issues, when the root cause is actually the policing of NHRP control-plane messages that enable dynamic tunnel establishment.

How to eliminate wrong answers

Option A is wrong because CoPP polices control-plane traffic (like NHRP), not IPsec data-plane packets; spoke-to-spoke tunnels use IPsec for encryption, but the failure is due to missing NHRP redirects, not dropped IPsec packets. Option C is wrong because CoPP is applied to the control plane (via 'control-plane' configuration), not to a tunnel interface; applying a policy to a tunnel interface would affect data-plane forwarding, not control-plane NHRP messages. Option D is wrong because the default class class-default does not block NHRP by default; it matches all unclassified traffic and typically permits it unless explicitly configured to drop, and the question states a class-map specifically matches NHRP traffic.

540
MCQeasy

Which DHCPv4 message type does a client send to request a specific IP address previously offered?

A.DHCPDISCOVER
B.DHCPOFFER
C.DHCPREQUEST
D.DHCPACK
AnswerC

DHCPREQUEST is sent by the client to accept a specific offered address, naming it in the requested-IP option so the server confirms that lease. It is also used to renew existing leases, but the offer-selection scenario in the stem maps directly to this message.

Why this answer

The DHCPREQUEST message is used by the client to formally request the specific IP address that was previously offered by the DHCP server in a DHCPOFFER. This occurs during the DHCP lease selection phase, where the client broadcasts or unicasts a DHCPREQUEST to accept the offered IP address and bind the lease.

Exam trap

Cisco often tests the distinction between DHCPREQUEST used for initial lease selection versus DHCPREQUEST used for lease renewal, where the trap is that candidates confuse the client's request for a specific offered address with the server's acknowledgment (DHCPACK) or the initial discovery (DHCPDISCOVER).

How to eliminate wrong answers

Option A is wrong because DHCPDISCOVER is the initial broadcast sent by the client to locate available DHCP servers, not to request a specific offered address. Option B is wrong because DHCPOFFER is sent by the DHCP server to propose an IP address to the client, not by the client to request it. Option D is wrong because DHCPACK is sent by the server to acknowledge and finalize the lease assignment after receiving the DHCPREQUEST, not by the client.

541
MCQmedium

A network engineer is configuring an IPv6 First Hop Security feature on a Cisco Catalyst switch to prevent rogue devices from sending Router Advertisement messages with a prefix that conflicts with the legitimate prefix. The engineer wants to ensure that only authorized routers can advertise prefixes, while still allowing hosts to perform SLAAC. Which feature should be implemented?

A.IPv6 Source Guard
B.IPv6 DHCP Guard
C.IPv6 Destination Guard
D.IPv6 RA Guard
AnswerD

IPv6 RA Guard filters Router Advertisement and Redirect messages on ports where they are not expected. It can be configured to block RAs from unauthorized devices while allowing legitimate routers. This directly prevents rogue devices from advertising conflicting prefixes and is the correct solution for the stated requirement.

Why this answer

The requirement is to prevent rogue devices from sending Router Advertisement messages with conflicting prefixes while allowing legitimate routers and SLAAC. IPv6 RA Guard is designed specifically to filter RA and Redirect messages on untrusted ports, ensuring only authorized routers can advertise. The other features address different threats such as source spoofing, rogue DHCPv6 servers, or ND cache exhaustion.

Exam trap

The trap here is confusing RA Guard with other IPv6 First Hop Security features like DHCP Guard or Source Guard, which protect against different rogue device behaviors.

542
MCQhard

A network engineer is troubleshooting a BGP routing issue on a Cisco IOS XE router. The router is configured with a route map that sets the local preference for routes learned from a specific neighbor. However, the engineer notices that the local preference is not being applied to routes received from that neighbor. Which BGP configuration command is most likely missing?

A.neighbor 10.1.1.1 route-map LOCAL-PREF in
B.bgp default local-preference 200
C.neighbor 10.1.1.1 send-community
D.neighbor 10.1.1.1 soft-reconfiguration inbound
AnswerA

The neighbor route-map command applies the route map to routes learned from the specified neighbor. For local preference to be set on inbound routes, the route map must be applied in the inbound direction using the in keyword. Without this command, the route map is not applied to incoming updates, so local preference remains at its default value of 100. This is the most likely missing configuration.

Why this answer

To set local preference on routes learned from a specific BGP neighbor, a route map must be created that sets the local preference and then applied to that neighbor in the inbound direction. The correct command is neighbor <ip> route-map <name> in. Without this, the route map is not applied, and local preference remains at the default value.

Exam trap

The trap here is assuming that creating a route map is sufficient; the route map must be explicitly applied to the neighbor in the correct direction.

543
MCQhard

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to ensure that uRPF is applied in a way that allows asymmetric routing. Which uRPF mode should be configured?

A.VLAN mode
B.Feasible path mode
C.Strict mode
D.Loose mode
AnswerD

Loose mode uRPF checks that the source IP address is reachable via any interface in the routing table, not necessarily the incoming interface. This allows asymmetric routing because the return path can be different. It still provides spoofing mitigation by verifying the source is routable. This meets the requirement.

Why this answer

Loose mode uRPF verifies that the source IP address is present in the routing table, but does not require the packet to arrive on the same interface as the route to the source. This allows asymmetric routing while still providing anti-spoofing protection. Strict mode would drop packets in asymmetric environments.

VLAN mode and feasible path mode are not standard uRPF modes that allow asymmetric routing.

Exam trap

The trap here is assuming that strict mode uRPF can be used with asymmetric routing; strict mode requires the reverse path to match the incoming interface, which fails in asymmetric setups.

544
MCQeasy

A network engineer runs the following command to troubleshoot IPsec with route-maps: R1# show crypto ipsec transform-set Transform set combined: { esp-aes 256 esp-sha-hmac } will negotiate = { Transport, } Transform set ESP-AES: { esp-aes 256 esp-sha-hmac } will negotiate = { Tunnel, } What does this output indicate?

A.There are two transform sets configured, one using transport mode and one using tunnel mode.
B.The transform set 'combined' is not valid.
C.IPsec is not configured because no transform set is active.
D.The transform set 'ESP-AES' is used for route-map filtering.
AnswerA

Two transform sets exist: "combined" negotiates transport mode, while "ESP-AES" negotiates tunnel mode. The output lists each set's name, encryption and hash algorithms (esp-aes 256, esp-sha-hmac), and its permitted mode, confirming both transport and tunnel configurations are present simultaneously.

Why this answer

The output shows two IPsec transform sets: 'combined' and 'ESP-AES'. The 'combined' set uses transport mode, while 'ESP-AES' uses tunnel mode. This indicates that different transform sets are configured for different purposes.

545
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 access-list PERMIT-ONLY IPv6 access list PERMIT-ONLY permit ipv6 2001:DB8:3::/48 any sequence 10 Based on this output, what is the effect of this access list when applied to an interface?

A.It permits all IPv6 traffic
B.It permits only IPv6 traffic from 2001:DB8:3::/48 and denies everything else
C.It denies all IPv6 traffic from 2001:DB8:3::/48
D.It permits all IPv6 traffic except from 2001:DB8:3::/48
AnswerB

An IPv6 access list ends with an implicit deny any, so the single permit statement for 2001:DB8:3::/48 means only that prefix is allowed and all other IPv6 traffic is dropped when the list is applied to the interface.

Why this answer

An IPv6 access list, like its IPv4 counterpart, has an implicit deny all at the end. The single permit entry for source 2001:DB8:3::/48 allows only traffic from that prefix; all other IPv6 traffic is denied by the implicit deny ipv6 any any rule.

Exam trap

Cisco often tests the implicit deny any any behavior in IPv6 ACLs, tricking candidates into thinking that a single permit entry allows all traffic or that the ACL only filters the specified prefix without affecting other traffic.

How to eliminate wrong answers

Option A is wrong because the access list does not permit all IPv6 traffic; it only permits traffic from 2001:DB8:3::/48, and the implicit deny blocks everything else. Option C is wrong because the permit action explicitly allows traffic from 2001:DB8:3::/48, not denies it. Option D is wrong because the access list permits only the specified prefix, not all traffic except that prefix; the implicit deny blocks all other traffic, including traffic from 2001:DB8:3::/48 is permitted, not denied.

546
MCQhard

An engineer configures an IPsec site-to-site VPN. The tunnel comes up, but no traffic passes. The engineer checks the crypto map and access-lists. Which is the most likely explanation?

A.The crypto map is applied to the wrong interface, causing the traffic to bypass encryption.
B.The access-list defining interesting traffic is missing the 'permit' statement for the actual traffic flow.
C.The IPsec transform set uses ESP with no encryption, so traffic is sent in clear.
D.The IKE phase 1 policy uses aggressive mode, which is incompatible with the crypto map.
AnswerB

An IPsec crypto map uses an extended access-list to define interesting traffic; only packets explicitly permitted by that ACL are protected by the tunnel. If the actual source/destination flow lacks a permit statement, the router forwards it in clear text (or drops it if crypto map drop-on-fail is set) even while the tunnel remains up for other traffic. This exactly matches the symptom of traffic bypassing encryption despite an active tunnel.

Why this answer

The access-list defining interesting traffic for the crypto map must explicitly include a 'permit' statement for the traffic that should be encrypted. Without this permit, the router will not classify the traffic as interesting, so IPsec will not attempt to encrypt it, and the traffic will be dropped or sent in clear depending on the crypto map configuration. The tunnel can still come up because IKE and IPsec SA negotiation is triggered by interesting traffic, but if the access-list is missing the permit, no traffic triggers the SA establishment, and existing SAs may remain idle.

Exam trap

Cisco often tests the misconception that a crypto map applied to an interface automatically encrypts all traffic, when in reality the access-list must explicitly permit the traffic to be encrypted, and a missing permit causes the tunnel to appear up but pass no traffic.

How to eliminate wrong answers

Option A is wrong because if the crypto map is applied to the wrong interface, the tunnel would likely not come up at all, or traffic on the correct interface would not be encrypted, but the question states the tunnel comes up, indicating the crypto map is correctly applied to at least one interface. Option C is wrong because an IPsec transform set using ESP with no encryption (ESP-NULL) still provides authentication and integrity, but the traffic would be sent in clear only if encryption is disabled; however, the tunnel coming up and no traffic passing is not explained by this, as traffic would still pass (in clear) if the transform set were misconfigured. Option D is wrong because IKE phase 1 aggressive mode is compatible with crypto maps; it is a negotiation mode that exchanges more information in fewer packets, but it does not prevent traffic from passing once the tunnel is established.

547
MCQhard

A network administrator is deploying DMVPN Phase 3 with IKEv2 between a hub and two spokes. The hub is configured with a dynamic multipoint VPN tunnel and uses NHRP. Spoke1 can reach Spoke2 via the hub, but direct spoke-to-spoke communication fails. The administrator verifies that NHRP registrations are successful and that the hub has routes to both spokes. Which action is most likely to enable direct spoke-to-spoke communication?

A.Configure the hub as a route reflector for BGP.
B.Disable split horizon on the hub's tunnel interface.
C.Enable NHRP redirect on the hub and NHRP shortcut on the spokes.
D.Configure the spokes to use the hub as the next-hop for all routes.
AnswerC

DMVPN Phase 3 requires NHRP redirect on the hub to inform spokes of a better path, and NHRP shortcut on the spokes to dynamically create direct tunnels. Without these, spokes continue to route through the hub. Enabling both features allows the spoke to resolve the remote spoke's NBMA address and build a direct GRE tunnel.

Why this answer

In DMVPN Phase 3, direct spoke-to-spoke tunnels are established through NHRP. The hub must be configured with 'ip nhrp redirect' to send redirect messages to spokes, and each spoke must have 'ip nhrp shortcut' to intercept traffic and initiate NHRP resolution for the destination spoke. Without these, spokes will continue to forward traffic through the hub even though NHRP registrations succeed.

Exam trap

The trap here is confusing DMVPN Phase 2 and Phase 3 requirements; Phase 3 specifically needs NHRP redirect on the hub and NHRP shortcut on the spokes to enable direct spoke-to-spoke tunnels.

548
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip policy Interface Route-map GigabitEthernet0/0 PBR-DEFAULT R1# show route-map PBR-DEFAULT route-map PBR-DEFAULT, permit, sequence 10 Match clauses: ip address (access-lists): 150 Set clauses: ip next-hop 10.0.0.2 Policy routing matches: 0 packets, 0 bytes route-map PBR-DEFAULT, deny, sequence 20 Match clauses: Set clauses: Policy routing matches: 0 packets, 0 bytes R1# show access-lists 150 Extended IP access list 150 10 permit ip 192.168.1.0 0.0.0.255 any R1# show ip route 10.0.0.2 Routing entry for 10.0.0.2/32 Known via "ospf 1", distance 110, metric 20 Last update from 10.1.1.2 on GigabitEthernet0/1 Based on this output, what is the most likely problem?

A.The deny sequence 20 is blocking all traffic from being policy-routed.
B.No traffic matching ACL 150 is arriving on GigabitEthernet0/0.
C.The next-hop 10.0.0.2 is unreachable.
D.The route map is missing a permit statement.
AnswerB

The route-map and ACL are configured correctly, yet policy routing matches zero packets, meaning no traffic has hit the interface. The next-hop 10.0.0.2 is reachable via OSPF, so the fault lies in traffic not arriving, not in the policy itself.

Why this answer

The most likely problem is that no traffic matching ACL 150 is arriving on GigabitEthernet0/0. The route map PBR-DEFAULT has a match clause for ACL 150, but the policy routing matches count is 0 packets, indicating that no packets have matched the ACL. Since the ACL permits traffic from 192.168.1.0/24, it suggests that no such traffic is being received on the interface.

Exam trap

The trap is assuming that the deny sequence or next-hop reachability is the issue, when the zero match count clearly indicates no matching traffic. Candidates must interpret the 'Policy routing matches' counter correctly.

How to eliminate wrong answers

Option A is wrong because the deny sequence 20 is a default deny for unmatched traffic, but it is not blocking traffic that matches sequence 10; the issue is that no traffic is matching sequence 10. Option C is wrong because the next-hop 10.0.0.2 is reachable via OSPF, as shown in the routing table. Option D is wrong because the route map does have a permit statement (sequence 10), so it is not missing a permit.

549
MCQeasy

In IPsec site-to-site VPN, what is the default lifetime for ISAKMP (IKE phase 1) security associations on Cisco IOS routers?

A.3600 seconds (1 hour)
B.86400 seconds (24 hours)
C.28800 seconds (8 hours)
D.1800 seconds (30 minutes)
AnswerB

Cisco IOS sets the ISAKMP (IKE phase 1) security association default lifetime to 86400 seconds, matching the stem's request for the default value. Phase 1 SAs renegotiate after this interval unless configured otherwise via the crypto isakmp policy lifetime command, which accepts 60 to 86400 seconds.

Why this answer

The default lifetime for ISAKMP (IKE phase 1) security associations on Cisco IOS routers is 86400 seconds (24 hours). This is defined in the Cisco IOS default configuration for the `crypto isakmp policy` and is the recommended value to balance security and performance by reducing the frequency of re-authentication and Diffie-Hellman key exchanges.

Exam trap

Cisco often tests the distinction between IKE phase 1 and IPsec phase 2 default lifetimes, so the trap here is confusing the 86400-second (24-hour) default for ISAKMP with the 3600-second (1-hour) default for IPsec SAs.

How to eliminate wrong answers

Option A is wrong because 3600 seconds (1 hour) is the default lifetime for IPsec (IKE phase 2) security associations, not for ISAKMP phase 1. Option C is wrong because 28800 seconds (8 hours) is a common user-configured value but is not the Cisco IOS default for ISAKMP. Option D is wrong because 1800 seconds (30 minutes) is too short for phase 1 and is typically used for aggressive rekeying scenarios, not the default.

550
MCQmedium

What is the default value for the 'active flow timeout' in a Flexible NetFlow monitor on Cisco IOS-XE?

A.15 minutes
B.30 minutes
C.60 minutes
D.5 minutes
AnswerB

Flexible NetFlow's active timeout defaults to 30 minutes, flushing a flow cache entry after that interval regardless of ongoing traffic. This satisfies the stem's request for the default value, distinguishing it from the inactive timeout, which defaults to 15 seconds and triggers only when no packets arrive.

Why this answer

The default active flow timeout is 30 minutes, after which long-lived flows are exported regardless of activity.

551
MCQmedium

A network engineer is troubleshooting a manual IPv6-in-IPv4 tunnel between two Cisco routers. The tunnel is up, and both routers can ping each other's tunnel IPv6 addresses. However, traffic from a host behind Router A to a host behind Router B fails. The engineer notices that Router A has a route to the remote IPv6 prefix via the tunnel, but Router B does not have a route to the local IPv6 prefix. What is the most likely cause?

A.Router B is missing a static route pointing the local IPv6 prefix to the tunnel interface.
B.The tunnel mode is set to 'ipv6ip 6to4' instead of 'ipv6ip'.
C.The tunnel source on Router B is misconfigured with the wrong IPv4 address.
D.The IPv6 access-list on Router B is blocking incoming traffic from the local prefix.
AnswerA

Manual tunnels are stateless, so each router needs its own static route to the remote IPv6 prefix via the tunnel interface. Router B lacks that route, so return traffic cannot be encapsulated, satisfying the stem's asymmetric routing symptom.

Why this answer

The tunnel is up and both routers can ping each other's tunnel IPv6 addresses, confirming that the tunnel itself is operational. However, traffic from a host behind Router A to a host behind Router B fails because Router B lacks a route back to the local IPv6 prefix (the network behind Router A). For bidirectional communication, both routers must have a route to the remote IPv6 prefix pointing to the tunnel interface.

Since Router B is missing this static route, it cannot forward return traffic into the tunnel, causing the failure.

Exam trap

Cisco often tests the distinction between tunnel reachability (Layer 3 connectivity between tunnel endpoints) and prefix reachability (routing of actual user networks), leading candidates to overlook the missing static route on the return path.

How to eliminate wrong answers

Option B is wrong because 'ipv6ip 6to4' is a 6to4 tunnel mode that uses an automatic addressing scheme (2002::/16) and requires a different configuration; the question describes a manual IPv6-in-IPv4 tunnel, which uses 'tunnel mode ipv6ip' (or 'tunnel mode ipv6ip [ipv4]'). Option C is wrong because if the tunnel source on Router B were misconfigured with the wrong IPv4 address, the tunnel would not be up and the routers could not ping each other's tunnel IPv6 addresses. Option D is wrong because the problem states that Router B does not have a route to the local IPv6 prefix; an IPv6 access-list blocking traffic would cause a different symptom (e.g., packets dropped at the interface) but the routing table would still contain the route.

552
MCQmedium

A network engineer runs the following command on Router R1: R1# show flow monitor FLOW-MONITOR-1 cache format table Cache type: Normal Cache size: 1000 Current entries: 0 High Watermark: 0 Flows added: 0 Flows aged: 0 - Active timeout (1800 secs) 0 - Inactive timeout (15 secs) 0 - Event aged 0 - Watermark aged 0 - Emergency aged 0 Based on this output, what is the most likely problem?

A.The cache size is too small at 1000 entries.
B.The flow monitor is not applied to any interface.
C.The active timeout is too long at 1800 seconds.
D.The cache type is Normal, which requires a sampler.
AnswerB

Zero flows added with an empty cache indicates the monitor is not receiving traffic, because it is not bound to any interface. Applying the flow monitor to an interface via the flow monitor command populates the cache, satisfying the stem's diagnosis of the missing binding.

Why this answer

The output shows 'Current entries: 0', 'Flows added: 0', and all aging counters at 0, which means the flow monitor cache is not receiving any flow data. The most likely cause is that the flow monitor (or its associated flow exporter/record) has not been applied to any interface, so no traffic is being monitored. If the monitor were applied, even with no matching traffic, you would typically see some cache activity or at least the monitor would be active; zero flows added across all counters strongly indicates the monitor is not attached to an interface.

Exam trap

The trap is focusing on cache size or timeout values as the cause; the exam expects you to recognize that zero flows added across all counters points to the monitor not being applied to an interface, not to a configuration parameter being wrong.

How to eliminate wrong answers

Option A is wrong because a cache size of 1000 entries is a normal default and would not prevent flows from being added; the cache would simply age out entries if it filled, but it would still show flows added. Option C is wrong because the active timeout of 1800 seconds is the default and does not prevent flow creation; it only controls how long an active flow stays in cache before being exported. Option D is wrong because the Normal cache type does not require a sampler; sampled NetFlow uses a different cache type (e.g., 'Sampled'), and Normal caches work without any sampler configured.

553
MCQmedium

Consider this partial configuration: ip nat inside source list 1 interface GigabitEthernet0/1 overload access-list 1 permit 192.168.1.0 0.0.0.255 ! interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip nat inside ! interface GigabitEthernet0/1 ip address 203.0.113.1 255.255.255.0 ip nat outside ! interface GigabitEthernet0/2 ip address 172.16.0.1 255.255.255.0 ip nat inside What is true about traffic from the 172.16.0.0/24 network?

A.It is translated using PAT to 203.0.113.1.
B.It is not translated and will be forwarded with its original source IP.
C.It is dropped because NAT is required for all inside interfaces.
D.It is translated using a different pool because it is on a separate inside interface.
AnswerB

Access-list 1 permits only 192.168.1.0/24, so 172.16.0.0/24 traffic fails the match and bypasses NAT translation entirely. Because GigabitEthernet0/2 is marked ip nat inside but no corresponding permit statement exists, packets retain their original 172.16.0.x source address when routed out GigabitEthernet0/1.

Why this answer

The NAT configuration uses an access-list (list 1) that only matches traffic from the 192.168.1.0/24 network. Traffic sourced from the 172.16.0.0/24 network does not match this access-list, so it is not subject to NAT translation. As a result, the router forwards packets from 172.16.0.0/24 with their original source IP address unchanged.

Exam trap

Cisco often tests the misconception that all traffic on an interface marked 'ip nat inside' is automatically translated, but in reality, translation only occurs for traffic that matches the access-list referenced in the NAT command.

How to eliminate wrong answers

Option A is wrong because PAT translation to 203.0.113.1 only applies to traffic that matches access-list 1, which permits only 192.168.1.0/24, not 172.16.0.0/24. Option C is wrong because NAT is not mandatory for all inside interfaces; only traffic matching the NAT rule is translated, and unmatched traffic is forwarded normally. Option D is wrong because there is no separate NAT pool or rule configured for the 172.16.0.0/24 network; the single 'ip nat inside source list 1' command applies only to the specified access-list, and a different inside interface does not automatically create a different translation behavior.

554
MCQhard

A network uses PBR to route traffic from a specific subnet (172.16.1.0/24) through a WAN link (next-hop 10.10.10.2). After a routing change, traffic from this subnet is being sent to the WAN link but is not reaching the destination. Router R1 shows: 'show route-map' shows the route-map is applied, 'debug ip policy' shows traffic being forwarded to 10.10.10.2, but 'show ip route' on R1 shows a route to the destination via a different next-hop (10.20.20.2). What is the root cause?

A.The next-hop 10.10.10.2 does not have a route to the destination, causing traffic to be dropped. Ensure the next-hop has a route to the destination or use a next-hop that does.
B.The route-map on R1 is missing a 'set ip next-hop verify-availability' command, causing PBR to use an unreachable next-hop.
C.The routing table on R1 has a better route to the destination via 10.20.20.2, but PBR is overriding it incorrectly.
D.The ACL in the route-map is matching traffic from the wrong subnet, causing PBR to be applied to the wrong traffic.
AnswerA

PBR forwards traffic to the set next-hop, but if that next-hop does not have a route to the destination, the traffic will be dropped. This is a common issue when PBR is used to steer traffic through a specific path that does not have full routing information.

Why this answer

PBR forwards matching traffic to the configured next-hop (10.10.10.2) regardless of the routing table, but the next-hop router must itself have a valid route to the destination to forward the packet onward. If 10.10.10.2 lacks a route to the destination, it drops the traffic — which matches the symptom of PBR forwarding correctly but packets never arriving.

Exam trap

The trap is assuming PBR failure means a local misconfiguration on R1 — the exam tests whether you recognize that PBR only controls the first hop and the downstream next-hop must have its own route to the destination.

How to eliminate wrong answers

Option B is wrong because 'set ip next-hop verify-availability' only checks that the next-hop is reachable via a tracked object; it does not fix a next-hop that is reachable but has no route to the destination. Option C is wrong because PBR intentionally overrides the routing table — the presence of a better route via 10.20.20.2 is expected and not the cause of the failure. Option D is wrong because 'debug ip policy' confirms the ACL is matching the intended subnet and forwarding to 10.10.10.2, so the ACL is not misconfigured.

555
MCQmedium

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers. The customer requires that traffic for the 10.1.1.0/24 subnet be encrypted, but all other traffic must be sent unencrypted. The engineer applies a crypto map to the outside interface. Which additional configuration is required to meet this requirement?

A.Configure an extended ACL that permits IP traffic from 10.1.1.0/24 to the remote subnet and apply it to the crypto map as the match address.
B.Configure a standard ACL that permits the 10.1.1.0/24 subnet and apply it to the crypto map as the match address.
C.Configure a route map that matches the 10.1.1.0/24 subnet and apply it to the crypto map as the match address.
D.Configure an extended ACL that denies IP traffic from 10.1.1.0/24 to the remote subnet and apply it as the match address.
AnswerA

The match address in a crypto map references an extended ACL that defines the traffic to be encrypted. Permitting only traffic from the local 10.1.1.0/24 to the remote subnet ensures that only that traffic is protected, while other traffic is sent unencrypted because it does not match the ACL.

Why this answer

The match address in a crypto map must reference an extended ACL that permits the traffic to be encrypted. Only traffic permitted by this ACL will be protected; all other traffic is sent unencrypted. Therefore, an extended ACL permitting the desired subnet is required.

Exam trap

The trap here is confusing standard ACLs with extended ACLs for crypto map match address, or reversing the permit/deny logic.

556
MCQmedium

A network engineer is configuring an MPLS L3VPN. The PE router is running OSPF with the CE router in VRF CUSTOMER. The engineer notices that routes from the customer are being redistributed into the provider's global OSPF process, causing instability. Which configuration change on the PE router will prevent this redistribution while still allowing customer routes to be advertised across the MPLS core?

A.Configure a distribute-list to filter the customer routes from being redistributed.
B.Configure the OSPF process with the capability vrf-lite command.
C.Change the OSPF domain-id to a unique value.
D.Remove the redistribution of the VRF OSPF into the global OSPF process.
AnswerD

The instability is caused by redistributing the customer's OSPF routes into the provider's global OSPF. Removing this redistribution stops the customer routes from entering the provider's IGP. The customer routes can still be advertised across the MPLS core by redistributing them into MP-BGP, which is the correct method for L3VPN route propagation.

Why this answer

The root cause is the redistribution of the VRF OSPF into the provider's global OSPF. Removing that redistribution prevents customer routes from entering the provider's IGP, while MP-BGP can still carry the customer routes across the MPLS core as VPNv4 prefixes. This maintains customer connectivity without affecting the provider's routing stability.

Exam trap

The trap here is thinking that filtering with distribute-list or changing domain-id solves the problem, but the actual fix is to remove the incorrect redistribution into the global OSPF process.

557
MCQhard

An engineer configures mutual redistribution between OSPF and EIGRP on a router that is part of an IPsec site-to-site VPN. After the configuration, routing loops occur intermittently. The engineer has not used any route tagging. What is the most likely cause of the routing loops?

A.The seed metric for EIGRP redistribution is set to a low value, causing EIGRP routes to be preferred over OSPF routes.
B.Routes redistributed from OSPF into EIGRP are re-distributed back into OSPF because there is no route tagging to identify them as OSPF-originated.
C.The IPsec tunnel is using transport mode, which causes routing protocol packets to be dropped.
D.The OSPF process has a higher administrative distance than EIGRP, causing route flapping.
AnswerB

Without route tagging, EIGRP cannot distinguish OSPF-originated routes from its own native entries, so it advertises them back into OSPF during mutual redistribution. OSPF then reinstalls them, creating a feedback loop between the two protocols. Tagging each domain's routes with distinct administrative tags prevents this redistribution cycle.

Why this answer

Without route tagging, routes redistributed from OSPF into EIGRP are not marked as OSPF-originated. When EIGRP redistributes these routes back into OSPF, OSPF accepts them as external routes, creating a mutual redistribution loop. This occurs because OSPF has no mechanism to distinguish between its own routes and those learned from EIGRP without explicit tagging (e.g., using a route-map with a tag).

Exam trap

Cisco often tests the concept that mutual redistribution without route tagging or filtering is the primary cause of routing loops, and candidates mistakenly focus on metric or administrative distance differences instead of the re-injection mechanism.

How to eliminate wrong answers

Option A is wrong because the seed metric for EIGRP redistribution affects route selection within EIGRP, not the cause of routing loops in mutual redistribution; loops arise from re-injection, not metric preference. Option C is wrong because IPsec transport mode does not drop routing protocol packets; transport mode only affects the IP header encapsulation and is unrelated to routing loop formation. Option D is wrong because administrative distance differences influence route preference but do not directly cause routing loops; route flapping is a symptom, not the root cause, and the scenario describes intermittent loops, not flapping.

558
MCQmedium

A network engineer is troubleshooting an IPsec VPN between two Cisco IOS routers. The tunnel is up, but traffic is not passing. The engineer runs `show crypto ipsec sa` and notices that the encaps/decaps counters are incrementing, but the inbound and outbound packets are being dropped. The ACL used for the VPN is `permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255`. What is the most likely cause of the dropped packets?

A.There is a routing issue or reverse path forwarding (RPF) check failure for the decapsulated packets.
B.The IPsec SA is using the wrong transform set.
C.The crypto map is applied to the wrong interface.
D.The ACL is too restrictive and does not match the actual traffic.
AnswerA

When encaps/decaps counters increment but packets are dropped, the router is successfully decrypting the packets. However, if there is no route back to the source or if Unicast RPF fails, the router drops the packets. This is a common issue where the decrypted packet's source is not reachable via the same interface it arrived on, triggering RPF drop.

Why this answer

When IPsec encaps/decaps counters increment but packets are dropped, the router is encrypting and decrypting successfully. The drop likely occurs after decryption due to a routing or RPF check failure. The decrypted packet's source address must be reachable via the interface it arrived on; if not, Unicast RPF drops it.

This is a common troubleshooting scenario in IPsec VPNs.

Exam trap

The trap here is focusing on the ACL or transform set when the counters indicate encryption/decryption is working, overlooking post-decryption routing or RPF issues.

559
MCQeasy

What is the default IKE (ISAKMP) lifetime value in Cisco IOS for IPsec Site-to-Site VPN?

A.3600 seconds (1 hour)
B.86400 seconds (24 hours)
C.28800 seconds (8 hours)
D.180 seconds (3 minutes)
AnswerB

Cisco IOS sets the default ISAKMP security association lifetime to 86,400 seconds, matching the stem's request for the IKE Phase 1 default. This value applies to the management tunnel itself, distinct from the shorter IPsec Phase 2 lifetime, so configuring site-to-site VPNs without explicit lifetime commands inherits this 24-hour default.

Why this answer

The default IKE (ISAKMP) lifetime in Cisco IOS for IPsec Site-to-Site VPN is 86400 seconds (24 hours). This value is defined in the ISAKMP policy and controls how long the IKE Phase 1 security association (SA) remains active before requiring re-authentication. A longer lifetime reduces the overhead of re-establishing the Phase 1 tunnel, balancing security with performance.

Exam trap

Cisco often tests the distinction between IKE Phase 1 and IPsec Phase 2 default lifetimes, and the trap here is that candidates confuse the 3600-second default of IPsec SA (Phase 2) with the 86400-second default of IKE SA (Phase 1).

How to eliminate wrong answers

Option A is wrong because 3600 seconds (1 hour) is the default IPsec (Phase 2) SA lifetime, not the IKE (Phase 1) lifetime. Option C is wrong because 28800 seconds (8 hours) is a common custom value but not the Cisco IOS default for IKE. Option D is wrong because 180 seconds (3 minutes) is far too short and would cause excessive rekeying overhead, and it is not a default for any phase in Cisco IOS.

560
MCQmedium

Which of the following protocols has the lowest default administrative distance on a Cisco router?

A.eBGP
B.OSPF
C.Connected
D.EIGRP internal
AnswerC

Connected routes carry a default administrative distance of 0, lower than static (1), eBGP (20), EIGRP internal (90) and OSPF (110). Directly attached interfaces are therefore preferred over any dynamically or manually configured route to the same destination.

Why this answer

Connected routes have an AD of 0, which is the lowest. Static routes are 1, eBGP is 20, EIGRP internal is 90.

561
MCQmedium

Given the following partial configuration on router R1: crypto isakmp policy 10 encryption aes 256 authentication pre-share group 14 lifetime 86400 ! crypto isakmp key cisco123 address 192.168.1.2 ! crypto ipsec transform-set TSET esp-aes 256 esp-sha-hmac mode tunnel ! crypto map CMAP 10 ipsec-isakmp set peer 192.168.1.2 set transform-set TSET match address 101 ! interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 crypto map CMAP ! access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255 What is the effect of this configuration?

A.IPsec tunnel is established when traffic from 10.1.1.0/24 to 10.2.2.0/24 triggers it.
B.The tunnel will only be established if the peer initiates first.
C.The transform set uses AES 256 with MD5 authentication, which is incorrect.
D.ISAKMP lifetime is set to 86400 seconds, which is too short for a site-to-site VPN.
AnswerA

The crypto map CMAP applies to GigabitEthernet0/1, and access-list 101 defines interesting traffic from 10.1.1.0/24 to 10.2.2.0/24. Because the map uses ipsec-isakmp with a pre-shared key and peer 192.168.1.2, matching packets trigger IKE negotiation, establishing the tunnel on demand rather than permanently.

Why this answer

The configuration uses a crypto map with 'match address 101' referencing an ACL that permits traffic from 10.1.1.0/24 to 10.2.2.0/24. This triggers IPsec SA negotiation via ISAKMP (IKEv1) only when interesting traffic is detected. The tunnel is established dynamically upon matching traffic, which is the standard behavior for a site-to-site VPN using a crypto map.

Exam trap

Cisco often tests the misconception that a crypto map tunnel requires the peer to initiate first, but the default behavior is that the local router initiates when interesting traffic is sent, unless 'responder-only' is configured.

How to eliminate wrong answers

Option B is wrong because the configuration does not include 'set passive' or 'responder-only' mode; the crypto map is applied to the interface, so R1 will actively initiate the tunnel when interesting traffic is sent, not wait for the peer. Option C is wrong because the transform set 'TSET' uses 'esp-sha-hmac', which specifies SHA (HMAC variant) for authentication, not MD5; MD5 would be 'esp-md5-hmac'. Option D is wrong because an ISAKMP lifetime of 86400 seconds (24 hours) is a standard and valid default for site-to-site VPNs; it is not too short and is commonly used.

562
MCQeasy

A network engineer is troubleshooting a BGP route advertisement issue. Router R1 (AS 65001) has an eBGP session with R2 (AS 65002). R1 is advertising the prefix 192.168.1.0/24 to R2. On R2, the route appears in the BGP table but is not installed in the routing table. The output of 'show ip bgp 192.168.1.0/24' on R2 shows the route as valid, best, but with the 'r' flag (RIB-failure). The routing table on R2 shows a static route for 192.168.1.0/24 with administrative distance 1. What is the most likely cause?

A.The BGP route is not installed because a static route with a lower administrative distance exists for the same prefix.
B.The BGP route is not installed because the next-hop is unreachable.
C.The BGP route is not installed because BGP synchronization is enabled.
D.The BGP route is not installed because the prefix length is too long.
AnswerA

The 'r' flag indicates RIB-failure: BGP selected the route as valid and best, but installation failed because a static route with administrative distance 1 is preferred over eBGP's distance of 20 for the same prefix.

Why this answer

RIB-failure occurs when BGP tries to install a route but a route with a lower administrative distance already exists. Here, the static route (AD 1) is preferred over the eBGP route (AD 20).

563
Multi-Selectmedium

A network engineer is deploying DMVPN Phase 3 with IPsec protection. The hub router is configured with a multipoint GRE tunnel interface and NHRP. Which two statements are true regarding the configuration that must be applied to the spoke routers to enable direct spoke-to-spoke communication? (Choose two.)

Select 2 answers
A.The spoke must have NHRP redirect configured on its tunnel interface.
B.The spoke must have the ip nhrp map multicast dynamic command configured.
C.The spoke must have a route to the destination spoke's tunnel network via the tunnel interface.
D.The spoke must have NHRP shortcut configured on its tunnel interface.
E.The spoke must use a different IPsec profile than the hub to avoid SA conflicts.
AnswersC, D

For the spoke to build a direct tunnel, it must have a route to the destination spoke's tunnel IP address pointing out the tunnel interface. This is usually achieved through a dynamic routing protocol running over the DMVPN cloud. Without such a route, the spoke cannot forward traffic directly even if it has the NHRP mapping.

Why this answer

For DMVPN Phase 3 spoke-to-spoke communication, each spoke must have NHRP shortcut enabled to process redirect messages, and it must have a route to the destination spoke's tunnel network via the tunnel interface, typically learned through a routing protocol. These two elements allow the spoke to initiate a direct tunnel when needed.

Exam trap

The trap here is assuming that NHRP redirect is needed on spokes or that multicast mapping commands are required on spokes; those are hub-side configurations.

564
MCQhard

A network engineer is troubleshooting a Cisco IOS XE router that is configured with a route map for policy-based routing (PBR). The route map is applied to the ingress interface with `ip policy route-map PBR`. The engineer wants to verify that the PBR is matching traffic and setting the next-hop correctly. Which command provides the most detailed information about PBR matches and actions?

A.show route-map PBR
B.debug ip policy
C.show ip policy
D.show ip route
AnswerB

The `debug ip policy` command provides real-time detailed output about PBR processing, including which route map sequence is matched, the packet's source and destination, and the resulting action such as setting the next-hop or interface. It is the most detailed troubleshooting tool for PBR, showing exactly how packets are handled. However, it can be CPU-intensive and should be used with caution in production.

Why this answer

For detailed PBR troubleshooting, `debug ip policy` is the most informative command. It logs each packet's match against route map sequences and shows the set actions applied, such as next-hop or interface. While `show route-map` provides configuration and some counters, it lacks the per-packet detail. `show ip policy` only confirms attachment.

Thus, the debug command is the correct choice for verifying matches and next-hop settings.

Exam trap

The trap here is assuming that `show route-map` displays full PBR match and action details, when it only shows configuration and basic counters.

565
Drag & Dropmedium

Drag and drop the steps to troubleshoot Administrative Distance adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, verify the physical connectivity and layer 1/2 status, then check the routing protocol neighbor adjacency, next examine the AD values of the routes learned from the neighbor, then review any route filtering or redistribution policies, and finally test end-to-end connectivity to confirm the fix.

566
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate login users against an external TACACS+ server. The administrator wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used as a fallback. The TACACS+ server has been configured with the IP address 10.1.1.100 and the shared secret key 'cisco123'. Which set of commands correctly implements this requirement?

A.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key cisco123 aaa authentication login default group tacacs+ line vty 0 4 login authentication default
B.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key cisco123 aaa authentication login default group tacacs+ enable line vty 0 4 login authentication default
C.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key cisco123 aaa authentication login default group tacacs+ local line vty 0 4 login authentication default
D.aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key cisco123 aaa authentication login default group tacacs+ local line vty 0 4 login authentication TAC1
AnswerC

This configuration enables AAA, defines a TACACS+ server with the correct IP and key, and sets the default authentication method list to try TACACS+ first and then fall back to local. Applying the method list to the VTY lines ensures remote login uses this sequence. This meets the fallback requirement.

Why this answer

The correct configuration enables AAA, defines the TACACS+ server with the proper address and key, and sets the default authentication method list to use TACACS+ with local fallback. Applying this method list to the VTY lines ensures remote login attempts use the intended sequence. The 'local' keyword is essential for fallback when the server is unreachable.

Exam trap

The trap here is forgetting to include the 'local' keyword in the AAA authentication method list, which is required to enable local authentication as a fallback.

567
Drag & Dropmedium

Drag and drop the steps to configure and schedule an IP SLA ICMP-echo operation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order begins by entering IP SLA configuration mode, then defining the ICMP-echo operation with target and source, setting optional parameters like frequency, scheduling the operation to start immediately or at a specific time, and finally verifying the configuration with show commands.

568
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip sla statistics 5 Round Trip Time (RTT) for Index 5 Latest RTT: 50 ms Latest RTT (milliseconds): 50 Latest RTT (microseconds): 50000 Number of successes: 100 Number of failures: 0 Operation time to live: Forever Output: OK R1# show track 3 Track 3 IP SLA 5 reachability Reachability is Up 1 change, last change 00:10:00 Latest operation return code: OK Latest RTT (milliseconds): 50 Tracked by: ip route 0.0.0.0 0.0.0.0 192.168.3.1 track 3 R1# show ip route 0.0.0.0 0.0.0.0 Routing entry for 0.0.0.0/0, supernet Known via "static", distance 1, metric 0, candidate default path Last update from 192.168.3.1 on GigabitEthernet0/0 Routing Descriptor Blocks: * 192.168.3.1, via GigabitEthernet0/0 Route metric is 0, traffic share count is 1 Based on this output, which statement is correct?

A.The static route is not installed because the track is up.
B.The IP SLA operation is failing, causing the track to go down.
C.The static route is active and reachable via 192.168.3.1.
D.The IP SLA operation has a threshold violation.
AnswerC

Track 3 reports reachability Up with return code OK, and the default static route via 192.168.3.1 is installed in the routing table as the candidate default path. This satisfies the stem's requirement that the tracked route is both active and reachable.

Why this answer

The track is up, and the static route is present in the routing table. The IP SLA has 100% success. This indicates everything is working correctly.

569
MCQmedium

A network engineer is configuring OSPF on a router with three interfaces: GigabitEthernet0/0 (10.1.1.1/24), GigabitEthernet0/1 (10.2.2.1/24), and Loopback0 (192.168.1.1/24). The engineer wants to ensure that the router ID is 192.168.1.1 and that it remains stable even if the Loopback0 interface flaps. Which command should be applied?

A.interface GigabitEthernet0/0 ip ospf priority 1
B.interface Loopback0 ip ospf 1 area 0
C.router ospf 1 router-id 192.168.1.1
D.router ospf 1 network 192.168.1.0 0.0.0.255 area 0
AnswerC

The router-id command under router ospf explicitly sets the OSPF router ID to 192.168.1.1. This value is used regardless of interface status, so the router ID remains stable even if Loopback0 flaps. Without this command, the router ID is dynamically selected based on highest loopback or active interface IP, which could change if the loopback fails.

Why this answer

The router-id command under the OSPF process explicitly sets the OSPF router ID and ensures it remains stable regardless of interface state. Dynamic selection could change if the loopback flaps, leading to OSPF adjacency resets. The other options either enable OSPF on an interface or advertise a network, which do not control the router ID.

Exam trap

The trap here is assuming that configuring a loopback interface with the desired IP automatically sets the OSPF router ID permanently, but dynamic selection can change if the interface goes down.

570
Multi-Selecteasy

Which TWO commands would a network engineer use to verify the results of route redistribution from OSPF into EIGRP? (Choose TWO.)

Select 2 answers
A.show ip route eigrp
B.show ip ospf database
C.show ip protocols
D.show ip eigrp topology
E.show ip eigrp traffic
AnswersA, D

`show ip route eigrp` lists only EIGRP-learned routes in the Routing Information Base, so any redistributed OSPF prefixes appear with an "D EX" code and their advertising router. This directly confirms the redistribution succeeded, satisfying the stem's requirement to verify OSPF-to-EIGRP route injection.

Why this answer

Option A, 'show ip route eigrp', is correct because it displays the EIGRP-learned routes in the routing table, so the engineer can confirm that redistributed OSPF routes actually appear as EIGRP routes (marked with D or D EX) and were installed. Option D, 'show ip eigrp topology', is correct because it shows the EIGRP topology table, including all routes EIGRP has received via redistribution, their feasible distance, reported distance, and successor/feasible successor status, verifying that the redistributed prefixes were accepted into EIGRP. Option B, 'show ip ospf database', only displays OSPF link-state advertisements and does not show whether those routes were redistributed into EIGRP.

Option C, 'show ip protocols', shows redistribution configuration parameters but not the actual redistributed route entries, so it is not the best verification of results. Option E, 'show ip eigrp traffic', only displays EIGRP packet counters and statistics, not route redistribution results.

Exam trap

The trap is selecting 'show ip protocols' as it shows redistribution configuration, but it does not display the actual redistributed routes. Candidates must distinguish between configuration and operational verification.

571
MCQeasy

What is the default frequency (in seconds) for an IP SLA operation if not explicitly configured?

A.60 seconds
B.10 seconds
C.30 seconds
D.120 seconds
AnswerA

Without an explicit frequency argument, an IP SLA operation defaults to transmitting one probe every 60 seconds. This default satisfies the stem's request for the unconfigured interval value, since the frequency parameter governs how often each probe cycle repeats.

Why this answer

The default frequency for IP SLA operations is 60 seconds. This means probes are sent every 60 seconds unless overridden with the frequency command.

572
MCQmedium

A network engineer runs the following command to troubleshoot an EEM issue: R1# debug event manager action syslog EEM Action Syslog debugging is on R1# Mar 1 00:20:45.789: %HA_EM-6-ACTION: applet TRACK-INTERFACE: action syslog msg: 'OSPF adjacency change detected' What does this output indicate?

A.The EEM applet 'TRACK-INTERFACE' executed a syslog action and generated the message 'OSPF adjacency change detected'.
B.The EEM applet 'TRACK-INTERFACE' received a syslog message 'OSPF adjacency change detected'.
C.The debug output shows the configuration of the syslog action for applet 'TRACK-INTERFACE'.
D.The syslog message was generated by the system, not by the EEM applet.
AnswerA

The debug output confirms the EEM applet TRACK-INTERFACE triggered its syslog action, emitting the message 'OSPF adjacency change detected'. This demonstrates the applet's action executed successfully, satisfying the stem's troubleshooting of EEM action syslog behaviour.

Why this answer

The debug output shows that the EEM applet named 'TRACK-INTERFACE' executed a syslog action, which generated the message 'OSPF adjacency change detected'. The log line %HA_EM-6-ACTION indicates that an Embedded Event Manager (EEM) action was triggered, and the action was to send a syslog message with that specific text. This confirms that the applet performed the action.

Exam trap

300-410 often tests the interpretation of EEM debug output; candidates may confuse whether the applet is generating or receiving a syslog message, but the debug tag clearly indicates the action performed.

How to eliminate wrong answers

Option B is wrong because the applet did not receive a syslog message; it generated one. The debug output is from the EEM action, not from syslog reception. Option C is wrong because the debug output shows the execution of the action, not the configuration.

Configuration would be shown with show event manager policy or similar. Option D is wrong because the syslog message was generated by the EEM applet, as indicated by the %HA_EM-6-ACTION tag, not by the system independently.

573
MCQmedium

Which of the following is true regarding the use of prefix-lists versus access-lists for route filtering?

A.Access-lists can match on prefix length using the 'ge' and 'le' keywords.
B.Prefix-lists can match on both network address and prefix length, while access-lists match only on network address.
C.Access-lists are more efficient than prefix-lists for route filtering.
D.Prefix-lists can only be used with BGP, while access-lists can be used with any protocol.
AnswerB

Prefix-lists use the ge and le operators to test both the network address and the prefix length of a route, permitting precise subnet-range filtering. Standard access-lists match only the network address, so they cannot distinguish between different prefix lengths.

Why this answer

Prefix-lists are designed specifically for route filtering and can match both the network address and the prefix length (subnet mask) using the 'ge' (greater than or equal) and 'le' (less than or equal) keywords. Access-lists, when used for route filtering, can only match the network address portion of a route and cannot filter based on prefix length. This makes prefix-lists more precise and flexible for controlling routing updates.

Exam trap

300-410 often tests the misconception that access-lists can match prefix length using 'ge' and 'le', confusing them with prefix-lists.

How to eliminate wrong answers

Option A is wrong because access-lists do not support the 'ge' and 'le' keywords for matching prefix length; those are exclusive to prefix-lists. Option C is wrong because access-lists are not inherently more efficient than prefix-lists for route filtering; prefix-lists are optimized for this purpose and provide more granular control. Option D is wrong because prefix-lists are not limited to BGP; they can be used with other routing protocols like OSPF and EIGRP for route filtering, and access-lists are also not restricted to any single protocol.

574
MCQmedium

A network engineer is configuring a Cisco IOS XE router to authenticate VPN users against a Microsoft Active Directory server. The router must use RADIUS and send the user's original username without modification. Which command set correctly configures the router to use the AD server at 10.1.1.50 with the shared secret 'Cisco123'?

A.aaa authentication login default group tacacs+ local tacacs server AD-SERVER address ipv4 10.1.1.50 key Cisco123
B.aaa authentication login default group radius local radius server AD-SERVER address ipv4 10.1.1.50 auth-port 1812 acct-port 1813 key Cisco123 username-case lower
C.aaa authentication login default group radius local radius server AD-SERVER address ipv4 10.1.1.50 auth-port 1645 acct-port 1646 key Cisco123
D.aaa authentication login default group radius local radius server AD-SERVER address ipv4 10.1.1.50 auth-port 1812 acct-port 1813 key Cisco123
AnswerD

This configuration defines a RADIUS server group named AD-SERVER with the correct IPv4 address and standard ports 1812/1813, sets the shared key, and applies it to the default login authentication list. The username is sent as entered because no stripping or manipulation is configured. This meets all requirements for authenticating VPN users against Active Directory via RADIUS.

Why this answer

The correct configuration must use RADIUS with the standard authentication and accounting ports 1812 and 1813, and must not alter the username. The option that defines a RADIUS server group with the correct address, ports, and key, and applies it to the default login authentication list, satisfies all requirements. Other options either use the wrong protocol, legacy ports, or modify the username.

Exam trap

The trap here is assuming that legacy RADIUS ports 1645/1646 are still acceptable for modern Active Directory integration, or that TACACS+ can be used interchangeably with RADIUS for VPN authentication.

575
MCQeasy

Which DHCPv6 message is used by a server to respond to a SOLICIT with available configuration parameters?

A.REPLY
B.ADVERTISE
C.RECONFIGURE
D.INFORMATION-REQUEST
AnswerB

ADVERTISE is the server's reply to a client's SOLICIT, carrying available configuration parameters such as DNS servers and prefixes. It satisfies the stem's requirement for the server response message, preceding REQUEST, REPLY and any CONFIRM exchange in the DHCPv6 four-message sequence.

Why this answer

In DHCPv6, when a client sends a SOLICIT message to discover available DHCPv6 servers, each server that can provide configuration parameters responds with an ADVERTISE message. This ADVERTISE message contains the server's preference and available configuration options, allowing the client to select the appropriate server. This process is defined in RFC 8415 and mirrors the DHCPv4 OFFER step.

Exam trap

Cisco often tests the distinction between DHCPv6 message types, and the trap here is confusing ADVERTISE with REPLY, as candidates may incorrectly assume the server directly sends configuration parameters (REPLY) in response to a SOLICIT, overlooking the two-step discovery process.

How to eliminate wrong answers

Option A is wrong because a REPLY message is used by the server to respond to a REQUEST (or RENEW/REBIND) to deliver final configuration parameters, not to a SOLICIT. Option C is wrong because a RECONFIGURE message is sent by the server to a client to trigger a configuration update, not in response to a SOLICIT. Option D is wrong because an INFORMATION-REQUEST message is sent by a client to obtain configuration parameters without address assignment (e.g., stateless DHCPv6), and the server responds with a REPLY, not an ADVERTISE.

576
Multi-Selecthard

A network engineer is deploying OSPFv3 in an IPv6 network. The engineer wants to enable OSPFv3 on a router and ensure that it can form adjacencies with neighbors. Which two commands are required on the router to enable OSPFv3 globally and on an interface? (Choose two.)

Select 2 answers
A.ipv6 ospf 1 area 0
B.ipv6 router ospf 1
C.ipv6 unicast-routing
D.router ospf 1
E.ipv6 enable
AnswersA, B

The 'ipv6 ospf 1 area 0' command is used under an interface to enable OSPFv3 on that interface and assign it to area 0. This is required for the interface to participate in OSPFv3 and form adjacencies. Without it, the interface will not send or receive OSPFv3 hello packets. Thus, it is a necessary command.

Why this answer

To enable OSPFv3, you must start the OSPFv3 process with 'ipv6 router ospf 1' and then enable it on an interface with 'ipv6 ospf 1 area 0'. The other commands are either for OSPFv2, general IPv6 routing, or interface IPv6 enabling, which are not the specific OSPFv3 enabling commands.

Exam trap

The trap here is confusing OSPFv3 commands with OSPFv2 commands; OSPFv3 uses 'ipv6 router ospf' and 'ipv6 ospf' instead of 'router ospf' and 'ip ospf'.

577
MCQhard

A network engineer is troubleshooting an MPLS L3VPN where CE1 (10.1.1.0/24) cannot reach CE2 (10.2.2.0/24). The PE routers are using eBGP with the CEs. On PE1, the show ip bgp vpnv4 vrf CUSTOMER command shows the route for 10.2.2.0/24 with a next-hop of 192.168.1.2, and the show ip route vrf CUSTOMER command shows the route. However, traffic from CE1 to CE2 fails. The show ip bgp vpnv4 vrf CUSTOMER 10.2.2.0/24 command on PE1 shows the route is received and best, but the show ip bgp vpnv4 vrf CUSTOMER 10.2.2.0/24 command on PE1 also shows the route has the 'r' flag (RIB-failure). What is the most likely cause?

A.There is a static route in the VRF for 10.2.2.0/24 with a lower administrative distance.
B.The route-target import on PE1 is misconfigured.
C.The MP-BGP session is not using the loopback interface.
D.The VRF on PE1 has a different route-target export.
AnswerA

The 'r' flag means BGP selected the prefix as best but failed to install it in the VRF routing table. A static route with a lower administrative distance already occupies that prefix, so the BGP path is rejected despite being valid.

Why this answer

A RIB-failure indicates that the route is received and best in BGP but is not installed in the routing table because another route with a lower administrative distance exists. This could be due to a static route or an IGP route for the same prefix in the VRF.

578
MCQmedium

A network engineer is configuring a Cisco IOS XE router for MPLS L3VPN. The router is a PE device with a VRF named CUSTOMER. The engineer wants to redistribute routes from the VRF into MP-BGP so they can be advertised to a remote PE. The engineer has configured the VRF and assigned interfaces. Which command sequence correctly redistributes the connected routes from the VRF into BGP?

A.router bgp 65000 address-family ipv4 vrf CUSTOMER redistribute connected
B.router bgp 65000 redistribute connected
C.router bgp 65000 address-family ipv4 vrf CUSTOMER network 10.0.0.0 mask 255.255.255.0
D.router bgp 65000 address-family vpnv4 unicast redistribute connected
AnswerA

To redistribute routes from a VRF into MP-BGP, you must enter the VRF address family under router bgp and use the redistribute command. This injects the connected routes from that VRF into BGP, where they are then advertised as VPNv4 prefixes to remote PEs. The address-family ipv4 vrf CUSTOMER command is the correct context for redistribution. Without this, the routes are not advertised.

Why this answer

To advertise VRF routes via MP-BGP, you must redistribute them within the VRF address family under the BGP routing process. The address-family ipv4 vrf CUSTOMER context allows you to redistribute connected, static, or IGP routes from that VRF into BGP. These routes are then converted into VPNv4 prefixes with the appropriate route distinguisher and route target.

Redistributing in the global BGP instance or in the VPNv4 address family does not work because those contexts do not have access to the VRF routing table.

Exam trap

The trap here is confusing the VPNv4 address family with the VRF address family; redistribution must occur in the VRF-specific address family, not in the VPNv4 address family.

579
MCQmedium

A router experiences high CPU utilization due to SSH login attempts from an external attacker. The network engineer implements a CoPP policy to rate-limit SSH traffic to 10000 bps. After applying the policy, the engineer notices that legitimate SSH sessions from the management network are also being dropped intermittently. The CoPP policy uses a class-map that matches TCP port 22 traffic. What should the engineer do to fix this issue?

A.Increase the police rate for the SSH class to 100000 bps to allow all SSH traffic.
B.Modify the class-map to match only SSH traffic from the attacker's source IP addresses using an access-list.
C.Create a separate class for legitimate SSH traffic from the management network with a higher police rate, and police the attacker's traffic more aggressively.
D.Remove the CoPP policy and implement an ACL on the interface to block the attacker's IP address.
AnswerC

Creating a separate class for legitimate SSH traffic sourced from the management network allows the engineer to assign a higher police rate to trusted sessions, ensuring they are not dropped during an attack. Simultaneously, the attacker’s SSH traffic can be placed in a separate class with a much lower police rate or explicit drop action, thereby protecting the control-plane CPU without affecting administrative access. This granular, class-based approach is the standard CoPP best practice because it balances availability and security.

Why this answer

It uses a granular CoPP design: legitimate SSH traffic from the management network is placed in a separate class with a higher police rate, while the attacker's traffic is policed more aggressively. This preserves control-plane resources for authorized sessions without dropping them, addressing the root cause of the problem—overly broad rate-limiting of all TCP port 22 traffic.

Exam trap

Cisco often tests the misconception that simply increasing the police rate or blocking a single attacker IP is sufficient, when the correct solution requires differentiated treatment of trusted versus untrusted traffic within the same protocol class.

How to eliminate wrong answers

Option A is wrong because simply increasing the police rate to 100000 bps would allow the attacker's traffic to consume even more control-plane CPU, potentially worsening the high CPU utilization issue. Option B is wrong because matching only the attacker's source IP addresses in the class-map would block the attacker but still leave legitimate SSH traffic unprotected from other potential attacks; more importantly, the attacker's IP can change, making this approach brittle and requiring constant ACL updates. Option D is wrong because removing CoPP and implementing an ACL on the interface only blocks a single IP address, leaving the router vulnerable to other attacks and failing to provide scalable, policy-based control-plane protection.

580
MCQhard

R1 and R2 have an IPsec VPN tunnel between their physical interfaces. They are running BGP over the tunnel interface. R1's show ip bgp summary shows the BGP session with R2 as established, but R1's show ip bgp shows no routes from R2. R2's show ip bgp shows routes from R1. What is the root cause?

A.R1 has a route-map applied to the BGP neighbor inbound that denies all routes.
B.BGP next-hop-self is missing on R2.
C.The IPsec tunnel is not encrypting BGP traffic.
D.R2 is not advertising any networks.
AnswerA

An inbound route-map on R1 denying all prefixes filters every route R2 advertises, so the BGP session stays Established while R1's BGP table remains empty. R2 still receives R1's routes because its own inbound policy is unaffected.

Why this answer

R1's BGP session is established (TCP port 179 is up), but no routes are received from R2. This indicates that an inbound route-map on R1 is filtering all incoming BGP updates. The route-map is applied to the neighbor inbound direction, which matches the symptom: R1 sees the session as established but has zero routes from R2, while R2 sees routes from R1 (since outbound filtering on R2 is not the issue).

Exam trap

Cisco often tests the distinction between a BGP session being established (TCP state) and routes being exchanged (NLRI processing), so candidates may incorrectly assume that an established session guarantees route exchange, overlooking inbound route-map filtering.

How to eliminate wrong answers

Option B is wrong because missing next-hop-self on R2 would cause R1 to reject routes due to an unreachable next-hop (if the next-hop is not reachable via the tunnel), but the session would still show routes in the BGP table (they would be hidden, not absent). Option C is wrong because the IPsec tunnel not encrypting BGP traffic would not prevent BGP routes from being received; BGP would still exchange routes over the unencrypted link, and the session would likely flap or fail due to mismatched security policies, not silently drop routes. Option D is wrong because R2's show ip bgp shows routes from R1, proving R2 is advertising networks (otherwise R2's table would be empty for those prefixes).

581
MCQmedium

A network engineer runs the following command on Router R6: R6# show logging | include %SEC-6-IPACCESSLOGP *Mar 1 00:01:15.123: %SEC-6-IPACCESSLOGP: list ACL_INBOUND denied tcp 10.0.0.100(12345) -> 192.168.1.1(80), 1 packet *Mar 1 00:01:20.456: %SEC-6-IPACCESSLOGP: list ACL_INBOUND denied tcp 10.0.0.100(12346) -> 192.168.1.1(80), 1 packet *Mar 1 00:01:25.789: %SEC-6-IPACCESSLOGP: list ACL_INBOUND denied tcp 10.0.0.100(12347) -> 192.168.1.1(80), 1 packet *Mar 1 00:01:30.012: %SEC-6-IPACCESSLOGP: list ACL_INBOUND denied tcp 10.0.0.100(12348) -> 192.168.1.1(80), 1 packet Based on this output, what is the most likely problem?

A.The ACL ACL_INBOUND is permitting traffic from 10.0.0.100 to 192.168.1.1 on port 80.
B.A host at 10.0.0.100 is attempting to access a web server at 192.168.1.1 and is being blocked by the ACL.
C.The router is experiencing a DoS attack from 192.168.1.1.
D.The ACL ACL_INBOUND is not configured on any interface.
AnswerB

The ACL_INBOUND list is denying TCP traffic from 10.0.0.100 to 192.168.1.1 on port 80, with incrementing source ports indicating repeated connection attempts. This confirms the host is blocked from reaching the web server by the inbound ACL.

Why this answer

The output shows repeated denied packets from source 10.0.0.100 to destination 192.168.1.1 on port 80 (HTTP). This indicates that a host at 10.0.0.100 is trying to access a web server at 192.168.1.1 but is being blocked by ACL ACL_INBOUND. The pattern suggests a possible scan or attack, or a legitimate access that is being denied due to misconfiguration.

582
MCQhard

A network engineer runs the following command on Router R1: R1# show ip route summary IP routing table maximum-paths: 32 IP routing table has 15 routes, using 900 bytes of memory Number of prefixes: /8: 1, /16: 2, /20: 3, /24: 9 Route types: Connected: 4, Static: 1, OSPF: 10 Route sources: OSPF: 10, Connected: 4, Static: 1 Based on this output, what is a potential issue regarding route summarization?

A.The routing table is too small.
B.There are too many /24 prefixes, suggesting poor summarization.
C.There are too many OSPF routes.
D.The routing table is empty.
AnswerB

Nine /24 prefixes dominate the table, each advertised individually rather than aggregated into larger blocks. This proliferation of small classless entries signals weak summarisation, since contiguous subnets could be combined into fewer, shorter-prefix routes, reducing table size and update churn.

Why this answer

The routing table has many /24 prefixes (9), indicating that route summarization is not being used effectively, leading to a larger routing table.

583
Drag & Dropmedium

Drag and drop the steps to verify and validate VRF-Lite operational state into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Begin by listing all configured VRFs. Then confirm which interfaces belong to each VRF. Next, check the VRF-specific routing table for expected routes.

After that, test reachability to a remote destination within the VRF. Finally, validate end-to-end connectivity with extended ping or traceroute using the VRF.

584
MCQeasy

Which statement correctly describes the default behavior of the Embedded Event Manager (EEM) when an event occurs and no action is explicitly defined?

A.EEM will generate a syslog message by default.
B.EEM will execute the default action of reloading the device.
C.EEM will take no action and the event is silently ignored.
D.EEM will send an SNMP trap by default.
AnswerC

An EEM applet requires at least one action to do anything; without an explicitly defined action, the event triggers the applet but no command runs, so the event is silently ignored. No default logging or fallback action occurs.

Why this answer

EEM applets consist of an event detector and one or more actions. If an event is registered but no action is defined, EEM simply logs the event internally and takes no further action — the event is silently ignored from an operational standpoint. There is no implicit default action such as reload, syslog, or SNMP trap unless explicitly configured.

Exam trap

300-410 often tests the misconception that EEM has implicit default behaviors (syslog, SNMP trap, reload), when in fact EEM requires explicit action statements and otherwise does nothing.

How to eliminate wrong answers

Option A is wrong because EEM does not automatically emit a syslog message for an event unless an 'action syslog' is configured in the applet. Option B is wrong because reloading the device is never a default action; it must be explicitly configured with 'action reload' and is dangerous enough that Cisco requires confirmation. Option D is wrong because SNMP traps require an explicit 'action snmp-trap' statement; EEM does not send traps by default.

585
MCQmedium

A network engineer runs the following command to troubleshoot a Network Logging and Syslog issue: R1# show policy-map control-plane input class class-default Output: Class-map: class-default (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any police: cir 1000000 bps, bc 31250 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop What does this output indicate?

A.The CoPP policy is policing control plane traffic at 1 Mbps, but no packets have been matched yet.
B.The CoPP policy is dropping all control plane traffic.
C.The CoPP policy is not applied to the control plane.
D.The CoPP policy is using a class-map that matches all traffic.
AnswerA

The police stanza shows a committed information rate of 1,000,000 bps with conformed, exceeded and violated counters all at zero packets and bytes, confirming the class-default CoPP policy is actively policing at 1 Mbps but has not yet matched any control plane traffic.

Why this answer

The output shows a CoPP (Control Plane Policing) policy applied to the control plane input, policing at 1,000,000 bps (1 Mbps) with a 31,250-byte burst, and all counters (conformed, exceeded, violated) are zero with '0 packets, 0 bytes' matched. This means the policy is active and configured, but no control plane traffic has matched it yet.

Exam trap

300-410 often tests whether candidates read counters correctly — the trap is assuming 'drop' actions mean traffic is being dropped, when zero counters prove nothing is matched.

How to eliminate wrong answers

Option B is wrong because the drop actions are defined but the counters show zero exceeded/violated packets — nothing is being dropped. Option C is wrong because the policy is clearly applied to the control plane input (the command itself shows 'control-plane input'), and the police stanza is present. Option D is wrong because while class-default matches any traffic, the question asks what the output indicates — the key fact is that no packets have matched, not merely that the class matches all.

586
MCQhard

A router is configured with PBR using a route-map that sets the next-hop to 10.0.0.2 for traffic matching ACL 100. The engineer also configures 'set ip default next-hop 10.0.0.3' in the same route-map sequence. Traffic that matches ACL 100 is forwarded to 10.0.0.2, but traffic that does not match ACL 100 is forwarded to 10.0.0.3 only if there is no route in the routing table. However, the engineer expects all unmatched traffic to go to 10.0.0.3 regardless of the routing table. What is the misunderstanding?

A.The 'set ip default next-hop' command overrides the routing table only when no route exists; the engineer wants unconditional forwarding.
B.The route-map sequence order is incorrect; the default next-hop should be in a separate sequence.
C.The ACL 100 is blocking all traffic, so no traffic matches the set commands.
D.The 'set ip default next-hop' command requires a 'set interface' command to work.
AnswerA

'Set ip default next-hop' applies only when the routing table lacks a matching route, acting as a fallback. Because a route exists for unmatched traffic, the router forwards it normally, ignoring 10.0.0.3. Unconditional forwarding requires 'set ip next-hop', which overrides the routing table regardless.

Why this answer

The 'set ip default next-hop' command is used only when the packet does not have a matching route in the routing table. If a route exists (even a default route), the packet follows the routing table. The engineer should use 'set ip next-hop' instead of 'set ip default next-hop' to force all unmatched traffic to the next-hop.

587
Multi-Selecthard

Which TWO statements about MPLS label imposition, disposition, and swapping are true? (Choose TWO.)

Select 2 answers
A.Penultimate Hop Popping (PHP) reduces the processing load on the egress LSR by having the penultimate LSR pop the label.
B.An intermediate LSR performs a label swap operation: it replaces the incoming label with an outgoing label.
C.The egress LSR performs label imposition (push) before forwarding the IP packet to the destination.
D.PHP is enabled only when the egress LSR is not directly connected to the penultimate LSR.
E.By default, PHP is disabled on Cisco IOS routers and must be explicitly configured.
AnswersA, B

PHP offloads the egress LSR: the penultimate router pops the transport label so the egress receives an unlabelled packet and performs a single IP lookup instead of a label lookup followed by an IP lookup, reducing its forwarding burden.

Why this answer

Option A is correct because Penultimate Hop Popping (PHP) lets the penultimate LSR pop the MPLS label before forwarding the packet to the egress LSR, so the egress LSR receives a plain IP packet and avoids an extra label lookup, reducing its processing load. Option B is correct because a core/intermediate LSR performs the label swap operation, replacing the incoming label value with the outgoing label value from its LFIB (LIB) entry before forwarding the frame. Option C is wrong because label imposition (push) is performed by the ingress LSR (ingress edge LER), not the egress LSR, which performs disposition (pop) or receives an already-popped packet.

Option D is wrong because PHP is a normal behavior between adjacent LSRs and does not require the egress LSR to be non-adjacent to the penultimate LSR. Option E is wrong because PHP is enabled by default on Cisco IOS routers (the implicit null label is advertised), not disabled by default requiring explicit configuration.

Exam trap

The trap is confusing the roles of ingress, intermediate, and egress LSRs, and assuming PHP requires explicit configuration when it is actually enabled by default.

588
MCQmedium

Which IP SLA operation type is used to measure one-way delay, jitter, and packet loss?

A.udp-jitter
B.icmp-echo
C.udp-echo
D.tcp-connect
AnswerA

The udp-jitter operation sends UDP packets at a defined interval and measures round-trip latency, one-way delay, jitter and packet loss, satisfying the stem's requirement for all three metrics. ICMP echo measures reachability and round-trip time only.

Why this answer

The udp-jitter IP SLA operation sends a stream of UDP packets with sequence numbers and timestamps to measure round-trip latency, one-way delay (via timestamp fields), inter-packet jitter, and packet loss. It is the only IP SLA operation type specifically designed to produce jitter and one-way delay statistics, making it the correct answer for voice/video quality monitoring.

Exam trap

300-410 often tests whether candidates confuse udp-echo (RTT/loss only) with udp-jitter (RTT + jitter + one-way delay) — assuming any UDP-based SLA measures jitter is the classic mistake.

How to eliminate wrong answers

Option B is wrong because icmp-echo measures only basic reachability and round-trip time (RTT) using ICMP — it does not calculate jitter or one-way delay. Option C is wrong because udp-echo measures round-trip latency and packet loss but does not compute jitter statistics or one-way delay the way udp-jitter does. Option D is wrong because tcp-connect measures TCP handshake time to a target port, useful for application reachability, but provides no jitter, delay, or loss metrics.

589
MCQmedium

A network engineer is troubleshooting PBR on a Cisco router where traffic from VLAN 100 (192.168.10.0/24) should be forwarded to next-hop 10.10.10.2 via a route map named 'VLAN100-PBR'. The engineer has applied the route map to interface GigabitEthernet0/0.100 (subinterface) using 'ip policy route-map VLAN100-PBR'. The engineer verifies that the route map is correctly configured with 'match ip address 100' and 'set ip next-hop 10.10.10.2', and the access list 100 matches the source subnet. However, traffic from VLAN 100 is still forwarded using the routing table. What is the most likely cause?

A.The traffic is arriving on the physical interface GigabitEthernet0/0 instead of the subinterface GigabitEthernet0/0.100.
B.The access list 100 is missing the 'permit' keyword; PBR only processes permit statements.
C.The 'set ip next-hop' command must be followed by 'force' to override the routing table.
D.The route map must be applied to the VLAN interface (SVI) instead of the subinterface.
AnswerA

PBR applies only to traffic entering the interface where the policy is attached. If VLAN 100 traffic is routed via the physical GigabitEthernet0/0 rather than the subinterface, the route map never triggers, so packets fall through to the routing table.

Why this answer

PBR is applied on the interface where traffic enters the router. If VLAN 100 traffic is arriving on the physical interface GigabitEthernet0/0 (for example, because the subinterface is not properly configured for 802.1Q encapsulation or the switch is sending untagged frames), the policy applied to GigabitEthernet0/0.100 will never be evaluated. The route map is correct, so the most likely cause is that the ingress interface does not match where the policy is attached.

Exam trap

300-410 often tests the assumption that applying PBR to a subinterface automatically covers all traffic from that VLAN — candidates overlook that PBR matches on the actual ingress interface, not the logical VLAN.

How to eliminate wrong answers

Option B is wrong because access lists in route maps do require 'permit' statements to match, but the question states the ACL is correctly configured and matches the source subnet — so this is not the cause. Option C is wrong because 'set ip next-hop' does not require a 'force' keyword; the correct syntax is simply 'set ip next-hop <address>', and PBR automatically overrides the routing table for matched traffic. Option D is wrong because PBR can be applied to a subinterface; applying it to an SVI is also valid, but the subinterface is not inherently incorrect — the real issue is where the traffic actually ingresses.

590
Multi-Selecthard

Which THREE commands can be used to verify the operational state and configuration of an IPv6 tunnel? (Choose THREE.)

Select 3 answers
A.show interfaces tunnel 0
B.show ipv6 interface tunnel 0
C.show running-config interface tunnel 0
D.show ip route
E.show ipv6 route
AnswersA, B, C

`show interfaces tunnel 0` reports line and protocol status, tunnel source and destination addresses, and encapsulation, directly confirming the operational state and configuration of the IPv6 tunnel interface. It satisfies the stem's verification requirement by exposing both the tunnel's current state and its configured parameters in a single command.

Why this answer

Option A, 'show interfaces tunnel 0', is correct because it displays the operational state (up/down) of the tunnel interface along with encapsulation, line protocol status, and packet counters, which directly verifies the tunnel's operational state. Option B, 'show ipv6 interface tunnel 0', is correct because it shows the IPv6-specific configuration and status of the tunnel interface, including the IPv6 address, link-local address, and whether IPv6 is enabled on that interface. Option C, 'show running-config interface tunnel 0', is correct because it displays the configured tunnel parameters such as tunnel source, tunnel destination, tunnel mode (e.g., ipv6ip), and other interface settings, verifying the tunnel's configuration.

Option D, 'show ip route', is not correct because it only displays the IPv4 routing table and does not provide tunnel-specific operational or configuration details. Option E, 'show ipv6 route', is not correct because it only shows the IPv6 routing table and does not verify the tunnel interface's state or configuration.

Exam trap

Cisco often tests that candidates confuse general routing table commands (show ip route, show ipv6 route) with interface-specific verification commands, leading them to select options that show reachability but not the tunnel's operational state or configuration.

591
MCQhard

An engineer configures IPsec between two routers using a site-to-site VPN with IKEv1. The configuration uses `crypto isakmp policy 10` with authentication pre-share and encryption aes. On the peer, the policy is configured with authentication pre-share and encryption 3des. Unexpectedly, the IKE phase 1 negotiation fails. Which is the most likely explanation?

A.The encryption algorithms (AES vs 3DES) do not match, causing IKE phase 1 to fail.
B.The pre-shared key must be configured globally, not under the policy.
C.The IKE policy must have the same priority number on both ends.
D.The authentication method must be `rsa-sig` for site-to-site VPNs.
AnswerA

IKEv1 phase 1 requires both peers to agree on the same encryption algorithm within a matching policy. AES on one peer and 3DES on the other produce no common proposal, so the ISAKMP security association negotiation fails before phase 2 begins.

Why this answer

IKE phase 1 (ISAKMP SA) negotiation requires both peers to agree on a matching transform set: encryption algorithm, hash algorithm, authentication method, and Diffie-Hellman group. Here the local policy uses AES while the peer uses 3DES, so no common encryption proposal exists and the ISAKMP SA cannot be built. The mismatch causes the negotiation to fail before phase 2 (IPsec SA) is even attempted.

Exam trap

The trap here is assuming that IKE policy priority numbers must match between peers, or that the pre-shared key lives inside the policy — both are common misconceptions that distract from the real requirement that the transform attributes (encryption, hash, auth, DH group) must match.

How to eliminate wrong answers

Option B is wrong because the pre-shared key is configured with the global 'crypto isakmp key <key> address <peer>' command, not inside the policy — but a missing/mismatched PSK would produce an authentication failure, not an encryption proposal mismatch. Option C is wrong because IKE policy priority numbers are locally significant only; they determine the order in which a router offers its own policies, and the two peers do not need matching priority values. Option D is wrong because rsa-sig is only one valid authentication method; pre-share is fully supported for site-to-site IKEv1 VPNs and is not the cause of this failure.

592
Drag & Dropmedium

Drag and drop the steps to apply a route-map to filter BGP prefix advertisements into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, define the route-map with a permit or deny clause and match criteria. Second, configure the set actions to modify attributes. Third, apply the route-map to the BGP neighbor using the neighbor route-map command.

Fourth, clear the BGP session to activate the filter. Finally, verify the filtered prefixes using show ip bgp.

593
MCQeasy

A network administrator is deploying a DMVPN Phase 2 network with EIGRP as the routing protocol. The hub router is configured with a multipoint GRE interface and NHRP. Spokes are configured with tunnel interfaces and are registering with the hub. However, the administrator notices that spoke routers are not forming EIGRP neighbor adjacencies with the hub. Which command is most likely missing on the hub's mGRE interface?

A.ip nhrp redirect
B.ip nhrp map multicast dynamic
C.ip nhrp network-id 1
D.ip nhrp shortcut
AnswerB

Without ip nhrp map multicast dynamic, the hub cannot replicate multicast packets (such as EIGRP hellos) to all registered spokes. EIGRP uses multicast to discover and maintain neighbors. If the hub does not forward these multicasts, spokes will not receive hellos and adjacencies will not form. This command is essential for dynamic routing protocols over DMVPN.

Why this answer

For EIGRP to form adjacencies over a DMVPN, the hub must be able to forward multicast hellos to all spokes. The command ip nhrp map multicast dynamic enables the hub to replicate multicast packets to all registered spokes. Without it, spokes do not receive EIGRP hellos, and neighbor relationships fail.

This is a common oversight in DMVPN configurations. The other commands are either for Phase 3 or basic NHRP settings that are already working.

Exam trap

The trap here is assuming that NHRP registration alone is sufficient for routing protocol adjacencies, overlooking the need for multicast replication.

594
MCQmedium

An engineer is troubleshooting a router that is generating syslog messages with incorrect timestamps. The router has 'service timestamps log datetime msec' configured, but the timestamps show the wrong time zone. The router's clock is set correctly via NTP. What is the most likely cause?

A.The 'clock timezone' command is not configured on the router.
B.The NTP server is not providing timezone information.
C.The 'service timestamps log' command should use 'localtime' instead of 'datetime'.
D.The syslog server is overwriting the timestamps with its own.
AnswerA

The 'service timestamps log datetime msec' command formats timestamps but does not set the zone. Without 'clock timezone', the router displays UTC despite NTP synchronising the clock correctly, producing timestamps in the wrong local zone.

Why this answer

The 'service timestamps log datetime msec' command tells the router to timestamp syslog messages with the date and time, including milliseconds. However, 'datetime' uses the router's configured time zone, which is set by the 'clock timezone' command. If 'clock timezone' is not configured, the router defaults to UTC, so the timestamps appear in UTC even though NTP has set the clock correctly.

Therefore, the most likely cause is that the time zone has not been explicitly configured.

Exam trap

The trap here is assuming that NTP provides timezone information, but NTP only synchronizes UTC; the router's timezone must be set separately with 'clock timezone'.

How to eliminate wrong answers

Option B is wrong because NTP does not provide timezone information; it only synchronizes UTC time, and the router must be manually configured with the correct timezone offset. Option C is wrong because 'localtime' is not a valid keyword for the 'service timestamps log' command; the correct syntax uses 'datetime' or 'uptime', and 'datetime' is appropriate when you want date and time. Option D is wrong because syslog servers typically do not overwrite timestamps; they may add their own or leave the original timestamp intact, and the issue is on the router's timestamp generation, not the server's handling.

595
Multi-Selectmedium

Which TWO commands verify the application and content of an IPv4 access control list on a Cisco IOS router? (Choose TWO.)

Select 2 answers
A.show ip interface
B.show access-lists
C.show running-config | include access-list
D.show ip route
E.debug ip packet
AnswersA, B

`show ip interface` displays the ACL name and direction (inbound or outbound) applied per interface, confirming the ACL is bound and filtering traffic as intended. This directly satisfies the stem's requirement to verify ACL application, complementing `show ip access-lists`, which confirms content.

Why this answer

The 'show ip interface' command displays the access lists applied to an interface, including the direction (inbound/outbound) and the specific ACL name or number. The 'show access-lists' command shows the detailed content of all ACLs, including the exact permit/deny statements, sequence numbers, and hit counts, verifying both the application and the rules.

Exam trap

Cisco often tests the distinction between commands that verify ACL application (show ip interface) versus content (show access-lists), and candidates mistakenly choose 'show running-config | include access-list' thinking it shows both, but it only shows the configuration lines without interface binding or hit counts.

596
Drag & Drophard

Drag and drop the steps to troubleshoot DHCP (IPv4 and IPv6) adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Begin by checking the DHCP client's interface for an IP address and DHCP state. Then, verify that the relay agent is configured and reachable. Next, confirm that the DHCP server is reachable from the relay.

After that, inspect access lists or firewall rules that might block DHCP traffic. Finally, review debug output to isolate the failure point.

597
MCQmedium

An engineer is troubleshooting a BGP peering issue between two routers, R1 and R2, connected via a serial link. The BGP session is established, but routes are not being exchanged. The engineer checks the BGP configuration and sees that both routers have the 'neighbor' commands correctly configured. The output of 'show ip bgp summary' shows the session is in the Established state, but the prefix counts are zero. What is the most likely cause?

A.Neither router has any network statements or redistribution commands configured to inject prefixes into BGP.
B.The BGP session is using MD5 authentication, but the passwords do not match.
C.The routers have mismatched BGP versions.
D.The update-source command is missing, causing the session to use the wrong interface.
AnswerA

With the session Established, TCP and capability negotiation succeeded, so the zero prefix counts point to the local RIB being empty. BGP only advertises what is injected via network statements, redistribution or aggregation; without any of these, no NLRI exists to send.

Why this answer

A BGP session can reach the Established state purely through neighbor configuration and TCP/179 connectivity, but no prefixes will be exchanged unless routes are injected into BGP via network statements, redistribution, or aggregation. Zero prefix counts in 'show ip bgp summary' with an Established session is the classic signature of a missing route injection configuration. The session itself is healthy; the routing table is simply empty of BGP-advertised routes.

Exam trap

The trap is assuming that an Established BGP session implies routes are being exchanged — candidates overlook that session establishment and route injection are independent, and pick authentication or version issues that would actually break the session.

How to eliminate wrong answers

Option B is wrong because MD5 authentication mismatches prevent the BGP session from reaching Established in the first place — the session would be stuck in Idle or Active, not Established. Option C is wrong because BGP version mismatches (BGP-4 vs older) also prevent session establishment, not route exchange after establishment. Option D is wrong because a missing update-source command typically causes the session to fail or flap when the wrong interface is used for TCP, but the question states the session is Established, so this is not the cause.

598
MCQhard

A network engineer is configuring route redistribution between EIGRP and OSPF on a Cisco IOS-XE router. The engineer wants to prevent routing loops and ensure that only specific EIGRP routes are redistributed into OSPF. Which combination of tools should the engineer use?

A.Use a route map with a prefix list to match specific routes, and set a tag on redistributed routes to prevent them from being redistributed back into EIGRP.
B.Configure OSPF as a stub area to prevent external routes from being injected, and redistribute only connected routes into EIGRP.
C.Use a distribute-list on the OSPF process to filter routes, and rely on OSPF's built-in loop prevention mechanisms.
D.Set the administrative distance of EIGRP to a lower value than OSPF, and use passive interfaces to control updates.
AnswerA

A route map with a prefix list provides granular control over which EIGRP routes are redistributed into OSPF. Setting a tag on those routes allows EIGRP to deny routes with that tag when redistributing back, preventing loops. This is a standard best practice for mutual redistribution, ensuring only intended routes are advertised and loop prevention is enforced.

Why this answer

To control redistribution and prevent loops, a route map with a prefix list filters which EIGRP routes enter OSPF, while route tagging marks those routes so EIGRP can deny them if they are redistributed back. This combination is the most precise and scalable method. The other options either do not filter properly, break connectivity, or rely on mechanisms that do not prevent loops during mutual redistribution.

Exam trap

The trap here is thinking that a distribute-list alone can prevent loops during mutual redistribution, when route tagging is required to identify and block redistributed routes from re-entering the original protocol.

599
MCQhard

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS router. The engineer wants traffic from a specific subnet to be routed via a next-hop IP address that is not directly connected. Which command is required under the route-map configuration?

A.set ip next-hop 10.1.1.1
B.set interface GigabitEthernet0/1
C.set ip default next-hop 10.1.1.1
D.set ip next-hop recursive 10.1.1.1
AnswerD

The 'set ip next-hop recursive' command allows the router to recursively resolve the next-hop IP address through the routing table, even if it is not directly connected. This enables PBR to forward traffic to a next-hop that is multiple hops away. This is the correct command to use when the next-hop is not directly connected.

Why this answer

PBR with a non-directly connected next-hop requires the 'set ip next-hop recursive' command. This allows the router to recursively look up the next-hop in the routing table to find a directly connected next-hop. Without the 'recursive' keyword, the router expects the next-hop to be directly connected and will not install the policy route if it is not.

Exam trap

The trap here is assuming that 'set ip next-hop' can be used with any IP address; it only works for directly connected next-hops unless the 'recursive' keyword is added.

600
MCQmedium

A network engineer is configuring a GRE tunnel between two routers. The tunnel interface is up, but OSPF neighbors are not forming. The engineer suspects a Layer 3 issue. Which command should be used to verify that the tunnel endpoints are reachable?

A.show ip interface brief
B.ping <remote tunnel endpoint IP>
C.traceroute <remote tunnel endpoint IP>
D.show ip ospf neighbor
AnswerB

Pinging the remote tunnel endpoint IP address tests reachability to the physical interface or loopback used as the tunnel destination. If the ping fails, the tunnel cannot pass traffic, and OSPF neighbors will not form. This command directly verifies Layer 3 connectivity to the endpoint, which is essential for a GRE tunnel to operate. It helps isolate whether the problem is in the underlay network or in the tunnel configuration itself.

Why this answer

To verify that the tunnel endpoints are reachable, the engineer should ping the remote tunnel endpoint IP address. This tests the underlay network connectivity, which is required for the GRE tunnel to carry traffic. If the ping fails, the tunnel will not pass traffic even if the tunnel interface is up.

Other commands like show ip interface brief only show interface status, show ip ospf neighbor shows adjacency state, and traceroute is more for path analysis. The ping is the most direct and effective method.

Exam trap

The trap here is assuming that an 'up' tunnel interface means the tunnel is operational, when in fact the underlay reachability must be verified separately.

Page 7

Page 8 of 19

Page 9