Courseiva

Cisco CCNP ENARSI 300-410 (300-410) — Questions 601–675

1401 questions total · 19pages · All types, answers revealed

Page 8

Page 9 of 19

Page 10
601
MCQeasy

What is the default OSPF dead interval on a broadcast multi-access network (e.g., Ethernet) when the hello interval is 10 seconds?

A.40 seconds
B.30 seconds
C.20 seconds
D.10 seconds
AnswerA

OSPF derives the dead interval as four times the hello interval. With a hello interval of 10 seconds on a broadcast multi-access Ethernet segment, the default dead interval is 40 seconds, matching the stated scenario parameters exactly.

Why this answer

On broadcast multi-access networks like Ethernet, OSPF defaults to a hello interval of 10 seconds. The dead interval is calculated as 4 times the hello interval, resulting in a default dead interval of 40 seconds. This ensures that a router has multiple missed hello opportunities before being declared dead, providing stability against transient network issues.

Exam trap

The trap here is that candidates often confuse the default dead interval multiplier (thinking it is 3 instead of 4) or mistakenly apply the NBMA dead interval logic to broadcast networks, leading them to select 30 or 20 seconds.

How to eliminate wrong answers

Option B (30 seconds) is wrong because it incorrectly assumes a multiplier of 3, but the OSPF standard (RFC 2328) specifies a multiplier of 4 for broadcast networks. Option C (20 seconds) is wrong because it suggests a multiplier of 2, which is used for NBMA networks (e.g., Frame Relay) where the hello interval is 30 seconds and the dead interval is 120 seconds, not for Ethernet. Option D (10 seconds) is wrong because it confuses the hello interval with the dead interval; the dead interval must be longer to allow for missed hellos.

602
MCQmedium

A network engineer is deploying a new branch office router (Cisco IOS XE) and wants to protect the control plane from routing protocol floods. The router will run OSPF and EIGRP. The engineer must ensure that control plane packets are rate-limited and that the router logs when the rate is exceeded. Which of the following should be configured?

A.Management Plane Protection (MPP) with an ACL that permits only SSH and SNMP.
B.Control Plane Protection (CPPr) with a port-filter policy that drops all non-management traffic.
C.Control Plane Policing (CoPP) using a policy-map that classifies routing protocol traffic and applies police actions with exceeded-action logging.
D.uRPF strict mode on all interfaces facing the service provider.
AnswerC

CoPP allows granular rate-limiting of control plane traffic. By classifying OSPF and EIGRP packets and applying a policer with an exceeded action of transmit and log, the router will rate-limit and log when the rate is exceeded. This meets the requirement to protect the control plane and log violations.

Why this answer

Control Plane Policing (CoPP) is designed to protect the control plane by rate-limiting traffic destined to the router's CPU. By classifying OSPF and EIGRP packets and applying a policer with logging, the engineer can ensure that routing protocol floods are mitigated and that any excess is logged. Other options do not provide both rate-limiting and logging for control plane traffic.

Exam trap

The trap here is confusing Control Plane Policing with Control Plane Protection or Management Plane Protection, which have different purposes and do not provide rate-limiting with logging.

603
MCQeasy

A network engineer is troubleshooting a site-to-site IPsec VPN that fails to establish. The engineer suspects that the pre-shared key is incorrect. Which command can be used to verify the pre-shared key configuration on a Cisco IOS router?

A.show crypto isakmp sa
B.show running-config | include crypto isakmp key
C.show crypto isakmp key
D.show crypto isakmp policy
AnswerB

The command 'show running-config | include crypto isakmp key' filters the running configuration to display lines containing 'crypto isakmp key'. This will show the configured pre-shared key, including the key string and the peer address. This is the most direct way to verify the pre-shared key on a Cisco IOS router. Note that the key is displayed in clear text, so handle with care.

Why this answer

The correct answer is to use the 'show running-config | include crypto isakmp key' command. This command filters the running configuration to show only the lines that contain the pre-shared key configuration. It displays the key and the associated peer address, allowing the engineer to verify if the key matches on both ends.

Other commands like 'show crypto isakmp policy' or 'show crypto isakmp sa' provide information about Phase 1 and Phase 2 parameters but do not reveal the pre-shared key.

Exam trap

The trap here is assuming that there is a dedicated show command for pre-shared keys, when in fact you must inspect the running configuration.

604
MCQeasy

A network administrator needs to configure a Cisco IOS router to send SNMP traps to a management server at 192.168.1.200 using SNMPv2c with the community string 'public'. Which command is required?

A.snmp-server manager
B.snmp-server host 192.168.1.200 version 2c public
C.snmp-server enable traps snmp
D.snmp-server community public ro
AnswerB

This command specifies the SNMP trap recipient at 192.168.1.200 using SNMPv2c and the community string 'public'. It is the correct command to configure the destination for SNMP notifications. The 'version 2c' keyword ensures SNMPv2c is used, and 'public' is the community string for authentication.

Why this answer

The snmp-server host command is used to specify the recipient of SNMP notifications, including traps and informs. By specifying the IP address, SNMP version (2c), and community string, the router is configured to send traps to the management server at 192.168.1.200 using SNMPv2c.

Exam trap

The trap here is confusing the command that defines a community string for SNMP access with the command that specifies a trap destination.

605
Drag & Dropmedium

Drag and drop the steps to verify and validate route summarization operational state into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Begin by checking the routing table on the summarizing router to see the summary route. Then, inspect the OSPF database to confirm the summary LSA. Next, verify that the summary is not causing suboptimal routing by checking for more specific routes.

After that, use show ip protocols to confirm summarization is enabled. Finally, test reachability to a host within the summarized range.

606
MCQmedium

A network engineer runs the following command on Router R1: R1# show ipv6 dhcp binding Client: FE80::A8BB:CCFF:FE01:0200 DUID: 00030001AABBCC010200 Username: unassigned IA NA: IA ID 0x00010001, T1 302400, T2 483840 Address: 2001:DB8:1::1000 Preferred lifetime 604800, valid lifetime 2592000 Expires at Mar 08 2020 12:00 AM (2592000 seconds) Client: FE80::A8BB:CCFF:FE01:0300 DUID: 00030001AABBCC010300 Username: unassigned IA NA: IA ID 0x00010001, T1 302400, T2 483840 Address: 2001:DB8:1::1001 Preferred lifetime 604800, valid lifetime 2592000 Expires at Mar 08 2020 12:00 AM (2592000 seconds) Based on this output, which statement is correct?

A.The DHCPv6 server has assigned duplicate addresses to the clients.
B.The DHCPv6 server is functioning correctly with two active bindings.
C.The DHCPv6 server is not using a pool; addresses are statically assigned.
D.The DHCPv6 server has a DUID conflict.
AnswerB

Two clients hold valid IA_NA bindings with assigned addresses, preferred and valid lifetimes, and future expiry timestamps, confirming the server has leased addresses normally. Nothing indicates a fault, so the bindings are active and correct.

Why this answer

The output shows two DHCPv6 clients with unique link-local addresses and DUIDs, each assigned a distinct IPv6 address from the 2001:DB8:1::/64 prefix. The presence of valid lifetimes and T1/T2 timers indicates the DHCPv6 server is operating normally, maintaining two active bindings. Option B correctly identifies this as proper server behavior.

Exam trap

Cisco often tests the distinction between duplicate addresses and unique addresses in DHCPv6 binding output, where candidates may mistakenly think two different addresses are duplicates because they share the same prefix or IA ID.

How to eliminate wrong answers

Option A is wrong because the addresses 2001:DB8:1::1000 and 2001:DB8:1::1001 are different, not duplicates; duplicate addresses would show the same IPv6 address for both clients. Option C is wrong because the output shows dynamically assigned addresses with lifetimes and timers, which are characteristics of pool-based DHCPv6 assignment, not static configuration. Option D is wrong because each client has a unique DUID (00030001AABBCC010200 vs 00030001AABBCC010300), so there is no DUID conflict.

607
MCQeasy

A network engineer runs the following command on Router R1: R1# show ipv6 access-list DENY-REMOTE IPv6 access list DENY-REMOTE deny ipv6 2001:DB8:2::/48 any sequence 10 permit ipv6 any any sequence 20 Based on this output, what is the effect of this access list when applied to an interface?

A.It permits all IPv6 traffic
B.It denies all IPv6 traffic from 2001:DB8:2::/48 and permits everything else
C.It permits only IPv6 traffic from 2001:DB8:2::/48
D.It denies all IPv6 traffic
AnswerB

The ACL evaluates entries in sequence order: sequence 10 denies the 2001:DB8:2::/48 prefix, and sequence 20 permits all remaining IPv6 traffic. Because the deny matches only that source prefix, traffic from other sources falls through to the permit, giving deny-then-permit behaviour.

Why this answer

The access list DENY-REMOTE explicitly denies IPv6 traffic sourced from the prefix 2001:DB8:2::/48 (sequence 10) and then permits all other IPv6 traffic (sequence 20). When applied to an interface, this results in only traffic from that specific prefix being blocked, while all other IPv6 traffic is allowed. This matches option B.

Exam trap

Cisco often tests the concept that an ACL with an explicit permit any any at the end overrides the implicit deny, so candidates mistakenly think the ACL only denies or only permits based on the first line, ignoring the sequence of entries.

How to eliminate wrong answers

Option A is wrong because the access list does not permit all IPv6 traffic; it specifically denies traffic from 2001:DB8:2::/48. Option C is wrong because the access list denies, not permits, traffic from 2001:DB8:2::/48. Option D is wrong because the access list does not deny all IPv6 traffic; it only denies traffic from the specified prefix and permits everything else.

608
Multi-Selecthard

Which TWO statements about the operation of DMVPN Phase 2 are true? (Choose TWO.)

Select 2 answers
A.Spoke routers can dynamically establish direct tunnels with each other.
B.The hub router must be configured with the 'ip nhrp redirect' command.
C.The hub router must use a point-to-point GRE tunnel interface.
D.All spoke-to-spoke traffic must traverse the hub router.
E.NHRP is not required for Phase 2 operation.
AnswersA, B

DMVPN Phase 2 permits spokes to build direct spoke-to-spoke GRE tunnels on demand, bypassing the hub for data forwarding once NHRP resolution succeeds. Traffic initially traverses the hub, which then signals the shorter path, satisfying the direct-tunnel requirement.

Why this answer

Option A is correct because DMVPN Phase 2 is specifically designed to allow spoke routers to dynamically build direct spoke-to-spoke mGRE tunnels, bypassing the hub for data traffic after NHRP resolution. Option B is correct because the hub must be configured with 'ip nhrp redirect' so that when it forwards a packet from one spoke to another, it sends an NHRP redirect message telling the source spoke to resolve the destination spoke's NBMA address and build a direct tunnel. Option C is incorrect because the hub uses a multipoint GRE (mGRE) tunnel interface, not point-to-point GRE, to support multiple spokes.

Option D is incorrect because in Phase 2, spoke-to-spoke traffic does not have to traverse the hub after the direct tunnel is established. Option E is incorrect because NHRP is essential in Phase 2 for mapping tunnel IP addresses to NBMA addresses and enabling dynamic spoke-to-spoke resolution.

Exam trap

The trap here is confusing DMVPN Phase 1 (hub-only transit, no spoke-to-spoke) with Phase 2 (direct spoke tunnels via NHRP redirect), causing candidates to pick 'all traffic traverses the hub' or to omit the redirect command.

609
MCQeasy

A network engineer runs the following command to verify Flexible NetFlow cache entries: R1# show flow monitor FLOW-MONITOR-1 cache format record Cache entry for flow 1: ipv4 source address: 10.0.0.1 ipv4 destination address: 192.168.1.100 ip protocol: 6 counter bytes: 1500 counter packets: 10 timestamp sys-uptime first: 123456 timestamp sys-uptime last: 123556 Cache entry for flow 2: ipv4 source address: 10.0.0.2 ipv4 destination address: 192.168.1.101 ip protocol: 17 counter bytes: 500 counter packets: 5 timestamp sys-uptime first: 123457 timestamp sys-uptime last: 123557 What does this output indicate?

A.Both flows are TCP connections.
B.The cache shows two flows with source/destination IP, protocol, byte/packet counts, and timestamps.
C.The cache does not include protocol information.
D.The flows are being exported immediately.
AnswerB

The record-format output lists each cached flow with its IPv4 source and destination addresses, IP protocol number, byte and packet counters, and first/last timestamps. This confirms two distinct flows are being tracked with the expected fields.

Why this answer

The output shows two active flows in the Flexible NetFlow cache. Flow 1 is a TCP (protocol 6) flow from 10.0.0.1 to 192.168.1.100 with 1500 bytes and 10 packets. Flow 2 is a UDP (protocol 17) flow from 10.0.0.2 to 192.168.1.101 with 500 bytes and 5 packets.

The timestamps show the first and last packet times.

610
MCQmedium

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 10.2.2.0/24 BGP routing table entry for 10.2.2.0/24, version 5 Paths: (1 available, best #1, table default) Not advertised to any peer Refresh Epoch 1 65002 10.1.12.2 from 10.1.12.2 (10.2.2.2) Origin IGP, metric 0, localpref 100, valid, external, best rx pathid: 0, tx pathid: 0x0 Based on this output, what is a potential issue with this route?

A.The route has a low local preference of 100.
B.The route is not being advertised to any BGP peer, possibly due to outbound filtering.
C.The next hop 10.1.12.2 is unreachable.
D.The route is not installed in the routing table.
AnswerB

The 'Not advertised to any peer' line shows the best path is not being sent to any BGP neighbour, which typically results from outbound route filtering, a missing neighbour advertisement or an unsynchronised peer. This satisfies the stem's request for a potential issue.

Why this answer

The output line 'Not advertised to any peer' means R1 is not sending this prefix to any BGP neighbor, which typically indicates outbound route filtering (e.g., a distribute-list, prefix-list, or route-map applied outbound) or a missing network statement advertisement. The route itself is valid, external, and best, so the issue is advertisement, not reachability or installation. This is a common BGP troubleshooting signal.

Exam trap

The trap is that candidates focus on local preference or next-hop reachability, but the explicit 'Not advertised to any peer' line points to outbound filtering — the exam tests whether you read the status flags rather than assume a path-selection problem.

How to eliminate wrong answers

Option A is wrong because local preference 100 is the default value for eBGP-learned routes and is not inherently a problem — it only matters in best-path selection among multiple paths. Option C is wrong because the route is marked 'valid' and 'best,' meaning the next hop 10.1.12.2 is reachable and the route passed BGP validity checks. Option D is wrong because 'best' indicates the route was selected and installed in the BGP table and, absent a RIB failure, the routing table; the output does not show an RIB-failure flag.

611
MCQmedium

A network engineer runs the following command to troubleshoot an EEM issue: R1# show event manager history applet TRACK-INTERFACE Applet TRACK-INTERFACE: Time Created : Mar 1 00:00:12 2025 Time Last Triggered : Mar 1 00:15:30 2025 Time Last Executed : Mar 1 00:15:30 2025 Trigger Count : 5 Execution Count : 5 Last Event Type : syslog Last Event Detail : OSPF-5-ADJCHG Last Action Executed : show ip route Last Action Result : Success What does this output indicate?

A.The applet 'TRACK-INTERFACE' has been triggered 5 times and executed successfully each time, with the last trigger at 00:15:30.
B.The applet 'TRACK-INTERFACE' has failed to execute 5 times.
C.The applet 'TRACK-INTERFACE' has not been triggered since it was created.
D.The applet 'TRACK-INTERFACE' executed the action 'show ip route' but the output was not captured.
AnswerA

The applet triggered five times and executed successfully on each occasion, confirming the syslog event-detector pattern matched OSPF adjacency changes. Trigger Count and Execution Count both equal 5, so no action failed or was skipped, and Time Last Triggered matches Time Last Executed at 00:15:30, satisfying the stem's request to interpret the history output.

Why this answer

The output shows the history for a specific EEM applet. It includes creation time, last trigger and execution times, trigger and execution counts, the last event that triggered it, the last action executed, and the result. This helps in determining if the applet is being triggered and executing successfully.

612
MCQeasy

What is the default behavior of a route-map when a route does not match any match clause in any sequence?

A.The route is permitted by default.
B.The route is denied by default.
C.The route is processed by the last sequence regardless of match.
D.The route is forwarded to the next route-map if one exists.
AnswerB

A route-map sequence ends with an implicit deny when no match clause is satisfied, so unmatched routes are discarded rather than passed. This differs from an empty route-map, which permits everything; here the presence of match clauses creates the implicit deny.

Why this answer

A route-map consists of sequences with permit or deny actions. If a route does not match any match clause in any sequence, it is implicitly denied. This is similar to an access-list: there is an implicit deny at the end of the route-map.

613
MCQhard

A network engineer is troubleshooting an issue where IPv6 hosts are unable to perform Duplicate Address Detection (DAD) successfully. The switch is configured with IPv6 First Hop Security features including ND Inspection and ND Suppress. The engineer notices that Neighbor Solicitation messages for DAD are being dropped by the switch. What is the most likely cause?

A.ND Inspection is configured to drop Neighbor Solicitations with an unspecified source address (::) because it has no binding for that address.
B.RA Guard is configured to drop all multicast traffic, including Neighbor Solicitations.
C.DHCPv6 Guard is blocking the DAD messages because they are considered DHCPv6 traffic.
D.IPv6 Source Guard is dropping the DAD messages because the source address :: is not in the binding table.
AnswerA

During Duplicate Address Detection, a host sends Neighbor Solicitations from the unspecified address (::) before it owns any address. ND Inspection requires a binding between source address and link-layer address; with no binding for ::, it drops these messages, breaking DAD.

Why this answer

ND Inspection drops Neighbor Solicitations with an unspecified source address (::) because it requires a valid binding for the source address in its binding table. During Duplicate Address Detection (DAD), the source address is :: (RFC 4862), which has no corresponding binding, causing ND Inspection to drop the message and preventing DAD from completing.

Exam trap

Cisco often tests the distinction between ND Inspection and IPv6 Source Guard, where candidates mistakenly think Source Guard drops DAD messages, but it is actually ND Inspection that drops Neighbor Solicitations with an unspecified source address due to missing bindings.

How to eliminate wrong answers

Option B is wrong because RA Guard is designed to block Router Advertisement messages, not multicast traffic like Neighbor Solicitations; it does not affect DAD messages. Option C is wrong because DHCPv6 Guard filters DHCPv6 server messages (e.g., DHCPv6 Advertise/Reply) to prevent rogue DHCP servers, not Neighbor Solicitations used for DAD. Option D is wrong because IPv6 Source Guard checks the source address against the binding table, but DAD uses the unspecified source address (::), which is a legitimate exception; however, ND Inspection specifically drops such messages, not IPv6 Source Guard.

614
MCQmedium

Consider this configuration on router R2: ``` interface GigabitEthernet0/0 ip access-group RESTRICT_ACCESS in ! ip access-list extended RESTRICT_ACCESS permit ip 10.0.0.0 0.255.255.255 any deny ip any any ``` What traffic will be permitted inbound on GigabitEthernet0/0?

A.Only traffic from source 10.0.0.0/24.
B.All traffic from the 10.0.0.0/8 network.
C.All traffic from any source.
D.Only traffic from source 10.0.0.0/16.
AnswerB

The wildcard mask 0.255.255.255 matches any address whose first octet is 10, covering the entire 10.0.0.0/8 range. The permit statement therefore allows all traffic sourced from 10.0.0.0/8 inbound, with everything else denied by the explicit deny.

Why this answer

The access list RESTRICT_ACCESS uses a wildcard mask of 0.255.255.255, which matches the first octet exactly and ignores the remaining three octets. This effectively permits all traffic from the 10.0.0.0/8 network (10.0.0.0 through 10.255.255.255). The explicit deny ip any any at the end blocks all other traffic, so only traffic sourced from the 10.0.0.0/8 range is permitted inbound on GigabitEthernet0/0.

Exam trap

Cisco often tests the distinction between prefix length and wildcard mask, leading candidates to misinterpret 0.255.255.255 as a /24 or /16 mask instead of the correct /8 range.

How to eliminate wrong answers

Option A is wrong because a wildcard mask of 0.255.255.255 matches the entire /8 range, not just the /24 subnet (which would require a wildcard mask of 0.0.0.255). Option C is wrong because the access list ends with a deny ip any any statement, which blocks all traffic not explicitly permitted by earlier entries. Option D is wrong because a /16 prefix would require a wildcard mask of 0.0.255.255, not 0.255.255.255; the given mask matches the full /8 range.

615
MCQhard

When redistributing OSPF into EIGRP, which EIGRP metric components are used to calculate the default metric?

A.Bandwidth and delay only
B.Bandwidth, delay, reliability, load, and MTU
C.No default metric is assigned; redistribution fails unless a metric is configured.
D.The OSPF cost is converted to an EIGRP metric using a default formula.
AnswerC

EIGRP has no default seed metric for redistributed routes. Unlike OSPF, which defaults to 20, redistribution into EIGRP fails unless a seed metric (bandwidth, delay, reliability, load, MTU) is explicitly supplied via the redistribute command.

Why this answer

When redistributing OSPF into EIGRP, no default metric is assigned; redistribution fails unless a metric is explicitly configured. EIGRP requires five metric components (bandwidth, delay, reliability, load, MTU) to calculate its composite metric, and there is no automatic conversion from OSPF cost. Therefore, the administrator must specify a seed metric using the 'default-metric' command or per-redistribution metric.

Exam trap

The trap is assuming that EIGRP will automatically derive a metric from OSPF cost. Candidates might think there is a default conversion, but there is none. The key is to remember that EIGRP requires explicit metric configuration for redistribution, unlike some other protocols that have default seed metrics.

How to eliminate wrong answers

Option A is wrong because EIGRP uses more than just bandwidth and delay; it also uses reliability, load, and MTU, although only bandwidth and delay are used by default in the composite metric calculation. Option B is wrong because while EIGRP uses all five components, they are not automatically derived from OSPF; they must be manually configured. Option D is wrong because there is no default formula to convert OSPF cost to EIGRP metric; OSPF cost is based on bandwidth, but EIGRP requires explicit values for its metric components.

616
MCQmedium

Consider the ERSPAN configuration on a router: monitor session 1 type erspan-source source interface GigabitEthernet0/0/1 both destination erspan-id 1 ip address 192.168.1.100 origin ip address 192.168.1.1 What is the primary purpose of the 'origin ip address' command?

A.It specifies the IP address of the monitoring device.
B.It defines the source IP address used in the ERSPAN GRE encapsulation.
C.It sets the IP address of the interface being monitored.
D.It enables ERSPAN on the specified interface.
AnswerB

The origin IP address sets the source address inside the ERSPAN GRE header, identifying the originating switch to the destination analyser. It satisfies the requirement to define the encapsulation source, distinct from the destination ip address, which is the tunnel endpoint receiving the mirrored frames.

Why this answer

The 'origin ip address' command in ERSPAN configuration specifies the source IP address that will be used in the ERSPAN GRE encapsulation. This IP address is typically the loopback or management interface of the source switch or router, and it identifies the origin of the ERSPAN traffic to the destination monitoring device. It is not the destination IP address, nor the monitored interface IP.

Exam trap

The trap is confusing the origin IP (source of ERSPAN traffic) with the destination IP (monitoring device) or the monitored interface IP.

How to eliminate wrong answers

Option A is wrong because the IP address of the monitoring device is specified by the 'ip address' command under the destination configuration, not by 'origin ip address'. Option C is wrong because the IP address of the interface being monitored is not set by this command; the source interface is defined by the 'source interface' command. Option D is wrong because ERSPAN is enabled by the 'monitor session type erspan-source' command, not by specifying an origin IP address.

617
Multi-Selecthard

Which TWO statements about EEM applet debugging and verification are correct? (Choose TWO.)

Select 2 answers
A.The command 'show event manager policy available' displays all configured EEM applets on the device.
B.The 'debug event manager action cli' command enables debugging output for CLI actions executed by EEM applets.
C.The 'show event manager history events' command displays a log of recent events that have triggered applets.
D.The 'show event manager policy active' command shows all applets that are currently running or have run recently.
E.The 'show event manager applet' command is not a valid IOS command.
AnswersB, C

The `debug event manager action cli` command targets the CLI action handler specifically, producing output each time an applet runs a CLI command. This satisfies the stem's verification requirement by confirming whether the applet's CLI actions execute and what they return, rather than debugging event detection or applet registration.

Why this answer

Option B is correct because 'debug event manager action cli' specifically turns on debug output for CLI actions that EEM applets execute, letting you see the exact commands run and their results. Option C is correct because 'show event manager history events' displays the recent event history, showing which events fired and triggered applets, which is useful for verifying applet triggering. Option A is wrong because 'show event manager policy available' lists the EEM policies/applets available to be registered on the device, not all configured applets.

Option D is wrong because 'show event manager policy active' shows policies that are currently registered and active, not everything that has run recently. Option E is wrong because 'show event manager applet' is not the correct syntax for verifying EEM applets; the valid commands use 'show event manager policy' or 'show event manager history'.

Exam trap

The trap here is confusing 'available' policies with 'registered' policies; many candidates assume 'show event manager policy available' displays configured applets, but it actually lists policies that are available in the system, not those that are actively registered.

618
MCQhard

A network engineer is troubleshooting a VRF-Lite setup where two routers are connected via a serial link. Each router has VRF_SALES configured. The engineer configures EIGRP in VRF_SALES. The 'show ip eigrp vrf VRF_SALES neighbors' shows no neighbors. The 'show ip eigrp vrf VRF_SALES interfaces' shows the serial interface is passive. What is the most likely cause?

A.The 'passive-interface default' command is configured under the EIGRP process for VRF_SALES.
B.The 'network' command for the serial interface's subnet is missing.
C.The 'autonomous-system' number is different on the two routers.
D.The 'metric weights' command is misconfigured.
AnswerA

The serial interface is passive because EIGRP inherits the global `passive-interface default` setting unless overridden per interface. Under address-family configuration for VRF_SALES, the interface must be explicitly activated with `no passive-interface Serial x/y`, otherwise no hellos are sent and no neighbours form.

Why this answer

If 'show ip eigrp vrf VRF_SALES interfaces' shows the serial interface as passive, EIGRP will not send or receive hello packets on it, so no neighbor adjacency can form. The 'passive-interface default' command under the EIGRP VRF process makes all interfaces passive by default, requiring explicit 'no passive-interface' for interfaces that should form adjacencies. This directly explains the passive state and missing neighbors.

Exam trap

The trap is focusing on AS number or network statement mismatches while ignoring the explicit 'passive' flag in the interface output, which is the direct cause of missing EIGRP neighbors.

How to eliminate wrong answers

Option B is wrong because a missing 'network' statement would prevent the interface from being enabled for EIGRP at all, but it would not show the interface as passive in the EIGRP interface output. Option C is wrong because mismatched AS numbers would still allow the interface to be non-passive; the neighbor would simply not form due to AS mismatch, not passivity. Option D is wrong because metric weights affect metric calculation, not neighbor formation or interface passivity.

619
MCQhard

What is the default inter-packet interval (in milliseconds) for an IP SLA UDP Jitter operation?

A.10 ms
B.20 ms
C.50 ms
D.100 ms
AnswerB

IP SLA UDP Jitter operations send packets in bursts, and the default inter-packet interval within each burst is 20 ms, matching the option. This spacing lets the responder measure one-way delay variation (jitter) between consecutive packets, which is the metric the operation exists to report.

Why this answer

The default inter-packet interval for UDP Jitter is 20 milliseconds. This is the delay between sending successive packets within a single probe.

620
MCQhard

What is the default OSPF reference bandwidth used in the metric calculation on Cisco IOS-XE?

A.100 Mbps
B.1000 Mbps
C.10 Mbps
D.10000 Mbps
AnswerA

Cisco IOS-XE calculates OSPF cost as reference bandwidth divided by interface bandwidth, and the default reference is 100 Mbps. Any interface at or above 100 Mbps therefore yields a cost of 1, which is why Gigabit and faster links become indistinguishable without manually raising the reference bandwidth.

Why this answer

Cisco IOS-XE uses a default OSPF reference bandwidth of 100 Mbps (10^8), which is the historical default inherited from early OSPF implementations. The OSPF cost is calculated as reference bandwidth divided by interface bandwidth, so a 100 Mbps interface has a cost of 1, and faster interfaces (1 Gbps, 10 Gbps) all default to cost 1 unless the reference bandwidth is changed. This is why modern networks often raise the reference bandwidth to 1000 or 10000 Mbps.

Exam trap

The trap is confusing the default reference bandwidth (100 Mbps) with the commonly recommended modern value (1000 or 10000 Mbps) — candidates who have configured 'auto-cost reference-bandwidth 1000' in labs often pick 1000 Mbps as the default.

How to eliminate wrong answers

Option B is wrong because 1000 Mbps (1 Gbps) is a common manually configured reference bandwidth on modern networks, but it is not the Cisco IOS-XE default. Option C is wrong because 10 Mbps was the reference bandwidth in very old OSPF implementations (RFC 1247 era) but is not the IOS-XE default. Option D is wrong because 10000 Mbps (10 Gbps) is a value administrators set to differentiate high-speed interfaces, not a default.

621
MCQmedium

A network administrator is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 connects to the internet, and GigabitEthernet0/1 connects to the internal network. The administrator wants to ensure that packets arriving on GigabitEthernet0/0 are dropped if their source address is not reachable via that interface. However, the administrator also wants to allow asymmetric routing where return traffic may use a different path. Which uRPF mode should be configured on GigabitEthernet0/0?

A.ip verify unicast source reachable-via rx
B.ip verify unicast source reachable-via any
C.ip verify unicast reverse-path
D.ip verify unicast source reachable-via tx
AnswerB

The any keyword enables loose uRPF, which checks that the source address is reachable via any interface in the routing table. This allows asymmetric routing because the return path can be different, while still dropping packets with spoofed source addresses that are not in the routing table. This meets the requirement.

Why this answer

Loose uRPF, configured with ip verify unicast source reachable-via any, checks the routing table for the source address but does not require the source to be reachable via the incoming interface. This allows asymmetric routing while still providing spoofing mitigation. Strict uRPF (rx) would drop packets in asymmetric scenarios, and the other options are either invalid or equivalent to strict mode.

Exam trap

The trap here is confusing strict and loose uRPF modes, or using outdated syntax, when the requirement to allow asymmetric routing points to loose mode.

622
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip eigrp interfaces detail GigabitEthernet0/0 IP-EIGRP interfaces for process 100 Interface Peers Xmit Queue Mean Pacing Time Multicast Pending Un/Reliable SRTT Un/Reliable Flow Timer Routes Gi0/0 1 0/0 10 0/10 50 0 Hello interval: 5 sec, Hold time: 15 sec Split horizon is enabled Summary address: 10.0.0.0/8 Next xmit serial <none> Un/reliable mcasts: 0/0 Un/reliable ucasts: 0/0 Mcast exceptions: 0 CR packets: 0 ACKs suppressed: 0 Retransmissions: 0 Retry timer: 15 Hello packets sent: 100, received: 99 Based on this output, what is the purpose of the summary address configured on this interface?

A.It filters all routes in the 10.0.0.0/8 range.
B.It advertises a summary route 10.0.0.0/8 to neighbors.
C.It redistributes connected routes.
D.It disables split horizon.
AnswerB

The summary address line under an EIGRP interface confirms that 10.0.0.0/8 is the summarised prefix generated for that interface. EIGRP advertises this aggregate to neighbours rather than the individual component subnets, which is exactly what the output indicates.

Why this answer

The 'Summary address: 10.0.0.0/8' line shows that a manual summary route is configured on this interface, which will be advertised to EIGRP neighbors.

623
MCQhard

An engineer configures OSPFv2 with a virtual link to connect a non-backbone area to area 0. The virtual link is not coming up, and routes from the non-backbone area are not being advertised into area 0. Which is the most likely explanation?

A.The virtual link is configured only on one router.
B.The transit area is a stub area.
C.The OSPF process is configured with 'no-virtual-link' command.
D.The router IDs are not reachable via the transit area.
AnswerB

Correct. A virtual link through a stub area is invalid in OSPF. The transit area must be a standard area or an NSSA, not a stub area.

Why this answer

In OSPF, virtual links cannot be configured through stub areas. If the transit area is a stub area, the virtual link will not function correctly, and routes from the non-backbone area will not be advertised into area 0. Even if the virtual link appears to be up (e.g., due to misconfiguration or software bug), route propagation is blocked because stub areas do not allow virtual links or type 5 LSAs.

Therefore, the most likely explanation is that the transit area is a stub area.

Exam trap

Candidates often overlook that virtual links cannot traverse stub areas. This question tests that rule.

624
MCQhard

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on the ingress interface of a PE router in an MPLS L3VPN. The router is receiving VPN traffic from a customer edge (CE) router. The engineer notices that some legitimate traffic is being dropped by uRPF. The engineer verifies that the CE router has a route back to the source address in its routing table. What is the most likely explanation?

A.Asymmetric routing is causing the return path to use a different interface, violating the strict uRPF check.
B.The uRPF 'allow-default' option is not configured, so default routes are not considered.
C.The CE router is not advertising the source network to the PE via BGP.
D.The uRPF mode is set to 'loose' instead of 'strict', causing all traffic to be dropped.
AnswerA

Strict uRPF verifies the packet's source is reachable via the same interface it arrived on. With asymmetric routing the return path differs, so the check fails even though the CE holds a valid route, dropping legitimate traffic.

Why this answer

Strict uRPF requires that the source IP of an incoming packet be reachable via the exact same interface on which the packet arrived. In an MPLS L3VPN, the PE router performs the uRPF lookup in the VRF routing table, and if the return path to the source uses a different interface (asymmetric routing), the strict check fails and the packet is dropped. The CE having a route back to the source is irrelevant because uRPF is enforced on the PE's ingress interface, not on the CE.

Exam trap

The trap here is assuming that because the CE has a route back to the source, uRPF should pass; candidates forget that strict uRPF checks the PE's own return path interface, not the CE's routing table.

How to eliminate wrong answers

Option B is wrong because 'allow-default' only permits the default route to satisfy the uRPF check; it does not address the asymmetric routing issue described, and the question does not indicate a default route is involved. Option C is wrong because the CE advertising the source network to the PE via BGP would actually help uRPF, not cause drops; the problem is on the PE's return path lookup, not the CE's advertisement. Option D is wrong because loose mode is less strict than strict mode and would not cause all traffic to be dropped; in fact, loose mode only checks reachability via any interface, so it would not drop legitimate traffic due to asymmetry.

625
MCQeasy

Which syslog severity level is used for informational messages that are not errors but may be useful for monitoring?

A.Severity 5 (Notice)
B.Severity 6 (Informational)
C.Severity 7 (Debug)
D.Severity 0 (Emergency)
AnswerB

Syslog severity 6 designates informational messages, covering normal operational events that are not errors but remain useful for monitoring. This matches the stem's requirement precisely, distinguishing it from severity 5 (Notice) and severity 7 (Debug).

Why this answer

Syslog severity level 6 is Informational, used for messages that are not errors but provide useful monitoring information. This matches the question's description exactly. Severity 5 is Notice, which is more significant than informational, and severity 7 is Debug, which is more verbose.

Exam trap

300-410 often tests the numeric mapping of syslog severities — candidates confuse Notice (5) with Informational (6) or assume Debug (7) is the default monitoring level.

How to eliminate wrong answers

Option A (Severity 5, Notice) is wrong because Notice indicates a condition that is not an error but is more significant than informational, often requiring attention. Option C (Severity 7, Debug) is wrong because Debug is used for detailed debugging messages, which are more verbose and lower priority than informational. Option D (Severity 0, Emergency) is wrong because Emergency indicates the system is unusable, the highest severity, not informational.

626
MCQhard

An MPLS network uses OSPF as the IGP. After redistributing BGP routes into OSPF, some MPLS forwarding failures occur for the redistributed prefixes. Router R1 config: router ospf 1 redistribute bgp 65001 subnets ! router bgp 65001 redistribute ospf 1 R1# show mpls ldp neighbor Peer LDP Ident: 10.1.1.2:0, Local LDP Ident: 10.1.1.1:0 TCP connection: 10.1.1.2.646 - 10.1.1.1.646 State: Oper, Msg sent: 100, Msg rcvd: 80 Downstream on demand R2# show mpls ldp neighbor Peer LDP Ident: 10.1.1.1:0, Local LDP Ident: 10.1.1.2:0 TCP connection: 10.1.1.1.646 - 10.1.1.2.646 State: Oper, Msg sent: 80, Msg rcvd: 100 What is the root cause?

A.The redistributed BGP routes have a higher administrative distance, causing them to not be installed in the routing table, breaking LDP label binding.
B.The LDP router-id is misconfigured, causing neighbor failure.
C.The OSPF process is missing the mpls ldp autoconfig command.
D.The BGP redistribution is missing the route-map to set the metric.
AnswerA

LDP uses the routing table; if the route is not installed, LDP cannot assign a label.

Why this answer

The show commands display an operational LDP session; however, the issue is that redistributed BGP routes become OSPF external routes with administrative distance 110. If the same prefix is also learned via eBGP (AD 20), the eBGP route is preferred and installed in the routing table. LDP requires the route to be in the routing table to assign a label.

Since the OSPF external route is not installed, LDP does not assign a label for that prefix, which can cause MPLS forwarding failures for those prefixes. The LDP neighbor relationships themselves remain up, but label binding for the redistributed prefixes is broken. To fix, either adjust administrative distances (e.g., use `distance bgp 120 120 120` to make BGP less preferred) or use route filtering to avoid creating duplicate routes.

627
MCQeasy

A network engineer runs the following command on Router R1: R1# show ip route ospf Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2 i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP a - application route + - replicated route, % - next hop override Gateway of last resort is not set 10.0.0.0/8 is variably subnetted, 5 subnets, 2 masks O 10.1.1.0/24 [110/20] via 192.168.1.2, 00:15:30, GigabitEthernet0/0 O 10.2.2.0/24 [110/30] via 192.168.1.2, 00:15:30, GigabitEthernet0/0 Based on this output, which statement is correct?

A.The router has a default route via OSPF.
B.The router has two OSPF routes to different subnets.
C.The OSPF neighbor is down.
D.The metric for 10.2.2.0/24 is 20.
AnswerB

The output lists two OSPF entries, 10.1.1.0/24 and 10.2.2.0/24, each with a distinct destination prefix, confirming separate subnets. Both were learned via 192.168.1.2 on GigabitEthernet0/0, with administrative distance 110 and metrics 20 and 30 respectively. This satisfies the stem's requirement of two OSPF routes to different subnets.

Why this answer

The output shows two OSPF-learned routes: 10.1.1.0/24 with metric 20 and 10.2.2.0/24 with metric 30, both via 192.168.1.2 on GigabitEthernet0/0. These are two distinct OSPF routes to different subnets, which matches option B. The 'O' code confirms intra-area OSPF routes, and the timers (00:15:30) indicate the routes have been stable for over 15 minutes.

Exam trap

300-410 often tests whether candidates can read the [AD/metric] bracket correctly and distinguish OSPF route codes, tempting them to misread the metric or assume a default route exists.

How to eliminate wrong answers

Option A is wrong because the output explicitly states 'Gateway of last resort is not set' and there is no 'O*E2' or 'O*IA' default route entry. Option C is wrong because the presence of OSPF routes with recent timers and a valid next hop indicates the neighbor adjacency is up; a down neighbor would remove the routes. Option D is wrong because the metric for 10.2.2.0/24 is 30, not 20 — 20 is the metric for 10.1.1.0/24.

628
MCQeasy

A network engineer runs the following command on Router R1: R1# show ip interface GigabitEthernet0/1 GigabitEthernet0/1 is up, line protocol is up Internet address is 10.1.1.1/24 Broadcast address is 255.255.255.255 Address determined by non-volatile memory MTU is 1500 bytes Helper address is not set Directed broadcast forwarding is disabled Outgoing access list is 101 Inbound access list is not set Based on this output, which statement is correct?

A.ACL 101 filters traffic entering the interface.
B.ACL 101 filters traffic leaving the interface.
C.The interface has no ACL applied.
D.ACL 101 is applied in both directions.
AnswerB

The line "Outgoing access list is 101" confirms ACL 101 is applied in the outbound direction, filtering packets leaving GigabitEthernet0/1. The inbound line reads "not set", so the ACL affects egress traffic only, matching the statement.

Why this answer

The command output shows 'Outgoing access list is 101', which indicates that ACL 101 is applied to filter traffic leaving the GigabitEthernet0/1 interface. This is confirmed by the absence of an 'Inbound access list' entry, meaning no ACL is applied to incoming traffic. Therefore, ACL 101 filters traffic leaving the interface.

Exam trap

Cisco often tests the distinction between inbound and outbound ACL application by showing only one direction in the output, leading candidates to assume no ACL is applied or that it applies to both directions.

How to eliminate wrong answers

Option A is wrong because the output shows 'Inbound access list is not set', meaning ACL 101 is not applied to incoming traffic; it is applied to outgoing traffic. Option C is wrong because the output explicitly shows 'Outgoing access list is 101', indicating an ACL is applied. Option D is wrong because the output shows ACL 101 is only applied to outgoing traffic, not inbound, so it is not applied in both directions.

629
MCQmedium

A network engineer runs the following command to troubleshoot an EEM issue: R1# show event manager policy registered No. Class Type Version Time Created Name 1 applet system 1.0 Mar 1 00:00:12 2025 TRACK-INTERFACE 2 applet system 1.0 Mar 1 00:00:15 2025 BGP-RESET 3 applet user 1.0 Mar 1 00:02:30 2025 LOG-ERROR What does this output indicate?

A.Three EEM applets are registered, including two system-defined and one user-defined.
B.Three EEM applets are registered, all user-defined.
C.Three EEM applets are registered, all system-defined.
D.The output shows the EEM applets that are currently executing.
AnswerA

The Class column shows three applets, and the Type column marks two as system and one as user. That combination confirms three registered EEM applets comprising two system-defined and one user-defined policy, exactly as the option describes.

Why this answer

The 'show event manager policy registered' output lists three EEM applets: TRACK-INTERFACE and BGP-RESET are of class 'applet' and type 'system', meaning they are system-defined (built-in) applets, while LOG-ERROR is of type 'user', meaning it was created by an administrator. Therefore, the output indicates two system-defined and one user-defined applet.

Exam trap

300-410 often tests the ability to interpret EEM output fields — candidates may misread the 'Type' column (system vs. user) and incorrectly count the number of user-defined applets.

How to eliminate wrong answers

Option B is wrong because the output clearly shows two applets with type 'system', not all user-defined. Option C is wrong because one applet (LOG-ERROR) has type 'user', so not all are system-defined. Option D is wrong because the command displays registered policies, not currently executing applets — EEM does not show running applets in this output; execution status would require different commands or logs.

630
MCQhard

A network engineer runs the following command on Router PE4: PE4# show bgp vpnv4 unicast all summary BGP router identifier 10.0.0.4, local AS number 65001 BGP table version is 25, main routing table version 25 5 network prefixes using 640 bytes of memory 5 path entries using 400 bytes of memory 3/3 BGP path/bestpath attribute entries using 360 bytes of memory 1 BGP AS-PATH entries using 24 bytes of memory 0 BGP route-map cache entries using 0 bytes of memory 0 BGP filter-list cache entries using 0 bytes of memory BGP using 1424 total bytes of memory BGP activity 15/10 prefixes, 20/15 paths, scan interval 60 secs Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 10.0.0.5 4 65001 1020 1015 25 0 0 00:12:34 5 10.0.0.6 4 65002 500 495 25 0 0 00:06:20 0 Based on this output, what is the problem?

A.Neighbor 10.0.0.5 is not exchanging prefixes.
B.Neighbor 10.0.0.6 is not sending any prefixes.
C.Both neighbors are in the Idle state.
D.The BGP table is empty.
AnswerB

The State/PfxRcd column for 10.0.0.6 shows 0, meaning the session is Established but no VPNv4 prefixes have been received from that peer. Since the stem asks what the output reveals, the zero prefix count is the fault: PE4 has no routes from AS 65002.

Why this answer

The output shows neighbor 10.0.0.6 with a PfxRcd count of 0, meaning zero prefixes have been received from that neighbor, while the session is Established (Up/Down 00:06:20). Neighbor 10.0.0.5 shows 5 prefixes received, so it is exchanging prefixes normally. The problem is that 10.0.0.6 is not advertising any VPNv4 prefixes to PE4.

Exam trap

The trap is misreading the State/PfxRcd column — candidates see '0' and assume the session is down or the table is empty, when in fact the session is Established and the zero means no prefixes were received from that specific neighbor.

How to eliminate wrong answers

Option A is wrong because neighbor 10.0.0.5 shows PfxRcd of 5, indicating it is actively exchanging prefixes. Option C is wrong because both neighbors show an Up/Down timer and a PfxRcd value, which means they are in the Established state, not Idle. Option D is wrong because the BGP table version is 25 and the header states '5 network prefixes,' so the table is not empty.

631
MCQhard

A network engineer runs the following command to troubleshoot SNMP statistics: R1# show snmp statistics 0 SNMP packets input 0 Bad SNMP version errors 0 Unknown community name 0 Illegal operation for community name supplied 0 Encoding errors 0 Number of requested variables 0 Number of altered variables 0 Get-request PDUs 0 Get-next PDUs 0 Set-request PDUs 0 Input queue drops 0 SNMP packets output 0 Too big errors 0 No such name errors 0 Bad values errors 0 General errors 0 Get-response PDUs 0 SNMP trap PDUs What does this output indicate?

A.No SNMP traffic has been processed, which may indicate a configuration or connectivity issue.
B.SNMP is working correctly with many successful requests.
C.The router is sending many SNMP traps.
D.There are errors due to bad community names.
AnswerA

Every counter reads zero, including input, output, PDUs and traps, so the router has processed no SNMP traffic at all. This points to a configuration or connectivity fault rather than malformed requests, since even errors would otherwise increment.

Why this answer

The output shows all counters at zero, including SNMP packets input and output, which means the router has not processed any SNMP traffic. This typically indicates that SNMP is either not configured, the community strings are mismatched, or there is a network connectivity issue preventing SNMP messages from reaching the router. A correctly functioning SNMP agent would show non-zero counters for received requests or sent responses.

Exam trap

Cisco often tests the misconception that zero error counters mean SNMP is working fine, when in fact zero counters for all input/output packets indicate no SNMP communication at all, not a healthy state.

How to eliminate wrong answers

Option B is wrong because the output shows zero packets input and output, not many successful requests; successful SNMP operations would increment counters like Get-request PDUs and Get-response PDUs. Option C is wrong because the output shows zero SNMP trap PDUs, indicating no traps are being sent, not many. Option D is wrong because the output shows zero Unknown community name errors, which means no requests with bad community names have been received; errors from bad community names would increment that specific counter.

632
MCQmedium

An engineer is troubleshooting a network where IPv6 hosts on VLAN 20 are unable to communicate with each other. The switch is configured with IPv6 First Hop Security features including Private VLAN (PVLAN) and IPv6 Source Guard. The hosts are in the same VLAN but cannot ping each other. What is the most likely cause?

A.The switch has Private VLAN configured on VLAN 20, and the hosts are on isolated ports, which prevents direct communication.
B.IPv6 Source Guard is blocking inter-host traffic because the hosts' bindings are not in the binding table.
C.RA Guard is blocking Neighbor Advertisements between hosts.
D.DHCPv6 Guard is blocking DHCPv6 messages between hosts.
AnswerA

Private VLAN isolated ports permit communication only with promiscuous ports, not with each other. Hosts on isolated ports within VLAN 20 therefore cannot exchange traffic despite sharing a subnet, which explains the failed pings; IPv6 Source Guard would instead filter spoofed source addresses.

Why this answer

Private VLAN (PVLAN) on VLAN 20 isolates ports within the same VLAN, preventing direct communication between hosts on isolated ports. Even though the hosts share the same VLAN, PVLAN restricts traffic so that isolated ports can only communicate with a promiscuous port (e.g., a router uplink), not with each other. This directly explains why IPv6 hosts on VLAN 20 cannot ping each other.

Exam trap

Cisco often tests the misconception that IPv6 Source Guard or RA Guard blocks all inter-host traffic, when in fact Private VLAN is the feature specifically designed to isolate hosts within the same VLAN at Layer 2.

How to eliminate wrong answers

Option B is wrong because IPv6 Source Guard filters traffic based on the source IPv6 address and MAC address binding table, but it does not block inter-host traffic within the same VLAN if the bindings are valid; it prevents spoofing, not peer-to-peer communication. Option C is wrong because RA Guard blocks Router Advertisements from unauthorized sources, not Neighbor Advertisements (which are used for ND and DAD) between hosts. Option D is wrong because DHCPv6 Guard blocks unauthorized DHCPv6 server messages, not client-to-client communication; hosts do not exchange DHCPv6 messages directly.

633
MCQmedium

What is the default hello interval for the Label Distribution Protocol (LDP) on a Cisco IOS-XE router?

A.5 seconds
B.10 seconds
C.15 seconds
D.3 seconds
AnswerA

LDP sends hello messages every 5 seconds by default on Cisco IOS-XE, with a 15-second hold time. This interval maintains session adjacency detection, so neighbours are declared down after three missed hellos rather than waiting longer.

Why this answer

LDP hello messages are sent every 5 seconds by default on Cisco IOS-XE routers to discover and maintain adjacencies.

634
MCQmedium

A network engineer is implementing CoPP (Control Plane Policing) on a Cisco IOS router to protect the route processor from excessive traffic. The engineer wants to limit ICMP echo requests destined to the router itself to 100 kbps. Which action must be taken to ensure that CoPP applies only to traffic destined to the control plane?

A.Apply the service policy to the control-plane interface.
B.Apply the service policy to all physical interfaces.
C.Configure an ACL to match ICMP echo requests and apply it inbound on the WAN interface.
D.Enable IP source guard on all interfaces.
AnswerA

CoPP is implemented by attaching a service policy to the control-plane interface (control-plane). This interface represents the route processor's traffic. By applying the policy there, you can filter and rate-limit traffic destined to the control plane, such as ICMP echo requests to the router's IP addresses. This ensures that only traffic intended for the router itself is policed, not transit traffic.

Why this answer

CoPP is implemented by creating a traffic class that matches control-plane traffic, defining a policy map with a policer, and attaching the policy to the control-plane interface. This interface is a virtual interface that represents traffic destined to the route processor. Applying the policy elsewhere, such as physical interfaces, would not selectively target control-plane traffic and could impact transit traffic.

Exam trap

The trap here is applying the CoPP policy to physical interfaces instead of the dedicated control-plane interface.

635
MCQhard

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against a flood of OSPF hello packets. The engineer wants to ensure that OSPF hellos are rate-limited to 1000 packets per second (pps) with a burst of 2000 packets, while allowing all other traffic without policing. The engineer applies the following configuration: class-map match-any OSPF_HELLO match access-group name OSPF_HELLO_ACL ! policy-map COPP_POLICY class OSPF_HELLO police 1000 2000 conform-action transmit exceed-action drop class class-default police 1000000 2000000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY After applying the policy, the engineer notices that OSPF adjacencies are flapping. Which action should the engineer take to resolve the issue?

A.Increase the police rate for the OSPF_HELLO class to 5000 pps to accommodate normal OSPF hello traffic.
B.Verify that the OSPF_HELLO_ACL matches OSPF hello packets by permitting IP protocol 89 and the correct multicast destination address, and adjust the ACL if necessary.
C.Modify the class-default policer to transmit all traffic without policing by using police 1000000 2000000 conform-action transmit exceed-action transmit.
D.Apply the CoPP policy to the control plane using the service-policy output command instead of input.
AnswerB

OSPF hellos are sent to multicast address 224.0.0.5 (AllSPFRouters) using IP protocol 89. If the ACL does not correctly match these parameters, OSPF hellos fall into class-default and may be dropped if the class-default policer is exceeded. Ensuring the ACL matches protocol 89 and destination 224.0.0.5 (and possibly source addresses) will correctly classify hellos into the OSPF_HELLO class, where they are policed at a higher rate, preventing flapping.

Why this answer

OSPF hellos are multicast to 224.0.0.5 with IP protocol 89. If the ACL used in the class-map does not match these specifics, hellos are classified into class-default and may be dropped when the class-default policer is exceeded, causing adjacencies to flap. The engineer must verify the ACL matches protocol 89 and the correct multicast destination, and adjust it so hellos are policed by the dedicated class with a higher rate.

Exam trap

The trap here is focusing on the police rate values while overlooking that the class-map may not actually match OSPF hellos due to an incorrect ACL, leading to hellos being policed by class-default and dropped.

636
MCQmedium

A network security engineer is configuring a Cisco IOS router to support Zone-Based Policy Firewall (ZPF). The engineer has created zones INSIDE and OUTSIDE, assigned interfaces to them, and now needs to allow HTTP traffic from INSIDE to OUTSIDE while inspecting return traffic. Which configuration step is required to achieve this?

A.Create a policy-map with inspect action for HTTP, apply it to both INSIDE and OUTSIDE interfaces using `service-policy type inspect` in the inbound direction.
B.Create an ACL that permits HTTP from INSIDE to OUTSIDE, apply it to the INSIDE interface with `ip access-group` in the outbound direction, and enable `ip inspect` on the OUTSIDE interface.
C.Create a zone-pair from INSIDE to OUTSIDE, define a policy-map with inspect action for HTTP, and apply the policy-map to the zone-pair using `service-policy type inspect`.
D.Create a class-map that matches HTTP traffic, define a policy-map with inspect action, and apply the policy-map to the INSIDE zone using `service-policy type inspect`.
AnswerC

This is correct because ZPF requires traffic policies to be applied to zone pairs. The zone-pair defines the direction (INSIDE to OUTSIDE). The policy-map, containing a class-map that matches HTTP and an inspect action, is applied to the zone-pair with `service-policy type inspect`. This allows HTTP traffic and inspects return traffic, creating a stateful firewall.

Why this answer

Zone-Based Policy Firewall (ZPF) uses zone pairs to apply traffic policies between zones. To allow HTTP from INSIDE to OUTSIDE and inspect return traffic, you must create a zone-pair from INSIDE to OUTSIDE, define a policy-map with an inspect action for HTTP, and apply that policy-map to the zone-pair using `service-policy type inspect`. This creates a stateful inspection allowing return traffic.

Applying policies directly to zones or interfaces is not correct for ZPF.

Exam trap

The trap here is applying the policy-map to a zone or interface instead of a zone-pair, which is the correct attachment point in ZPF.

637
MCQhard

A network engineer is configuring a GRE tunnel between two Cisco routers across an ISP network. The tunnel source is GigabitEthernet0/0 (IP 203.0.113.1) and the tunnel destination is 203.0.113.2. The engineer notices that the tunnel interface is up, but no traffic is passing through it. The engineer suspects a routing issue. Which command should be used to verify that the tunnel endpoint is reachable?

A.ping 203.0.113.2 source 203.0.113.1
B.show interface tunnel 0
C.traceroute 203.0.113.2
D.show ip interface brief
AnswerA

This command sends an ICMP echo request to the tunnel destination (203.0.113.2) using the tunnel source address (203.0.113.1) as the source. If the ping succeeds, the tunnel endpoint is reachable, and the underlying transport network is working. If it fails, there is a routing or connectivity issue between the endpoints, which would prevent the tunnel from passing traffic. This is the correct way to test reachability to the tunnel destination.

Why this answer

To verify reachability to the tunnel destination, you should ping the destination IP address using the tunnel source address as the source. This tests the underlying transport network and ensures that the tunnel endpoint is reachable. Other commands like show ip interface brief or show interface tunnel only show local status, and traceroute may not use the correct source address.

Exam trap

The trap here is assuming that a tunnel interface being up/up guarantees end-to-end connectivity, when in fact the tunnel can be up even if the destination is unreachable, especially without keepalives.

638
Multi-Selecthard

Which THREE statements about NAT and PAT behavior in Cisco IOS are true? (Choose THREE.)

Select 3 answers
A.PAT allows multiple inside hosts to share a single public IP address by using unique source port numbers.
B.The NAT translation table for PAT includes the inside global IP and port, and the outside global IP and port.
C.The command 'ip nat inside source list 1 interface GigabitEthernet0/0 overload' enables PAT using the interface IP.
D.The 'ip nat inside source static' command automatically enables PAT when multiple inside hosts are configured.
E.The 'ip nat pool' command is required for all PAT configurations.
AnswersA, B, C

Correct. PAT multiplexes many inside addresses to one outside address by differentiating TCP/UDP ports.

Why this answer

PAT (Port Address Translation) extends NAT by using unique source port numbers to multiplex multiple inside hosts over a single public IP address. This allows many internal devices to share one external IP, with the router tracking each session by the combination of inside global IP and port.

Exam trap

Cisco often tests the distinction between static NAT and PAT, where candidates mistakenly think 'ip nat inside source static' can automatically perform PAT, but it only creates a fixed one-to-one mapping without port multiplexing.

639
MCQeasy

Which statement is true about the implicit deny any at the end of an IPv4 ACL?

A.It can be overridden by adding a permit any at the end.
B.It is invisible and applies only to TCP traffic.
C.It is always present and cannot be removed or overridden.
D.It denies all traffic not explicitly permitted and is always present.
AnswerD

Every IPv4 ACL concludes with an invisible deny any statement, so any packet not matched by an explicit permit is dropped. This implicit deny is automatically appended and cannot be removed, meaning traffic must be explicitly permitted to pass.

Why this answer

Every IPv4 ACL has an implicit deny any statement at the end that denies all traffic not explicitly permitted by earlier entries. This implicit rule is always present and cannot be removed, ensuring that only traffic matching a permit entry is allowed through the ACL.

Exam trap

Cisco often tests the misconception that the implicit deny any can be removed or that it only applies to specific protocols, when in fact it is a permanent, protocol-agnostic rule that denies all unmatched traffic.

How to eliminate wrong answers

Option A is wrong because the implicit deny any cannot be overridden; adding a permit any at the end explicitly permits all traffic, effectively negating the implicit deny, but the implicit rule itself remains in the ACL logic. Option B is wrong because the implicit deny any applies to all IP traffic, not just TCP; it covers UDP, ICMP, and any other IP protocol. Option C is wrong because while the implicit deny any is always present and cannot be removed, it can be overridden by a permit any statement placed before it in the ACL; the statement 'cannot be overridden' is incorrect.

640
MCQeasy

What is the default hello interval for OSPFv3 on a broadcast network type in Cisco IOS-XE?

A.10 seconds
B.30 seconds
C.40 seconds
D.5 seconds
AnswerA

OSPFv3 uses a 10-second hello interval on broadcast and point-to-point network types, matching OSPFv2's default. This satisfies the stem's broadcast network constraint, where hellos are sent every 10 seconds; NBMA and point-to-multipoint interfaces instead default to 30 seconds.

Why this answer

OSPFv3 uses the same default hello interval as OSPFv2 for broadcast and point-to-point network types, which is 10 seconds. This is defined in RFC 5340 and is the default on Cisco IOS-XE for OSPFv3 on broadcast networks.

Exam trap

Cisco often tests the default hello interval for OSPFv3 by making candidates confuse it with OSPFv2 defaults or with the dead interval; the trap here is assuming OSPFv3 uses a different default than OSPFv2 for broadcast networks, when in fact both use 10 seconds.

How to eliminate wrong answers

Option B (30 seconds) is wrong because 30 seconds is the default hello interval for OSPFv3 on non-broadcast multi-access (NBMA) networks, not broadcast. Option C (40 seconds) is wrong because 40 seconds is the default dead interval (4 times the hello interval) for broadcast networks, not the hello interval itself. Option D (5 seconds) is wrong because 5 seconds is not a default OSPFv3 hello interval; it is sometimes used in OSPFv2 for faster convergence on certain interface types but is not the default for OSPFv3 broadcast.

641
MCQhard

An engineer enables uRPF (strict mode) on an interface facing the Internet. Legitimate traffic from a customer network is being dropped. The customer network uses asymmetric routing where return traffic takes a different path. Which is the most likely explanation?

A.The uRPF strict mode requires that the source IP's best path is out the same interface; asymmetric routing violates this.
B.The uRPF loose mode should be used instead, as it only requires a route to the source IP in the FIB.
C.The customer network is using private IP addresses that are not routable.
D.The uRPF allow-default option is missing, which is required for default routes.
AnswerA

Strict uRPF checks that the packet's source address is reachable via the same interface it arrived on. Asymmetric routing sends return traffic by a different path, so the reverse-path lookup fails and legitimate customer traffic is dropped.

Why this answer

Strict uRPF checks that the source IP of incoming packets has a route in the FIB pointing back to the same interface. With asymmetric routing, the return path may use a different interface, causing the check to fail and the packet to be dropped.

642
MCQmedium

A network engineer runs the following command to troubleshoot BFD with BGP: R1# show bgp ipv4 unicast 10.3.3.0/24 BGP routing table entry for 10.3.3.0/24, version 2 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 Local 10.1.1.2 from 10.1.1.2 (2.2.2.2) Origin IGP, metric 0, localpref 100, valid, external, best rx pathid: 0, tx pathid: 0x0 BFD enabled, BFD state: UP What does this output indicate?

A.BGP is using BFD with state UP, enabling sub-second failure detection for this prefix.
B.BFD is disabled for this BGP neighbor.
C.BFD state is DOWN, so BGP uses its own timers.
D.BGP is using BFD only for IPv6 prefixes.
AnswerA

The line "BFD enabled, BFD state: UP" confirms the BGP peer is actively using Bidirectional Forwarding Detection, so link failures for this prefix are detected in sub-second time rather than waiting for BGP hold timers to expire.

Why this answer

The output shows that BFD is enabled for the BGP session and the BFD state is UP, indicating fast failure detection for the BGP neighbor.

643
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. Spoke routers are behind dynamic NAT and cannot be reached directly. The engineer wants spoke-to-spoke traffic to bypass the hub after initial resolution. Which NHRP command on the spoke routers enables this behavior?

A.ip nhrp redirect
B.ip nhrp map multicast dynamic
C.ip nhrp network-id 1
D.ip nhrp shortcut
AnswerD

The ip nhrp shortcut command is configured on spoke routers in a DMVPN Phase 3 topology. When a spoke receives an NHRP redirect from the hub, the shortcut command allows it to dynamically create a direct mGRE tunnel to the destination spoke, bypassing the hub for subsequent packets. Without this command, the spoke would continue sending traffic through the hub even after receiving the redirect.

Why this answer

In DMVPN Phase 3, the hub uses ip nhrp redirect to inform a spoke that a better path exists directly to another spoke. The spoke must have ip nhrp shortcut enabled to act on that redirect and install a direct tunnel. Together, these commands allow spoke-to-spoke traffic to bypass the hub after the initial packet flow, reducing latency and hub load.

Exam trap

The trap here is confusing the hub-side command ip nhrp redirect with the spoke-side command ip nhrp shortcut; both are required, but they are applied on different routers.

644
Drag & Dropmedium

Drag and drop the steps to configure SSH access with local AAA on a Cisco router into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, a hostname and domain name must be set to generate the RSA key pair. Then the RSA key pair is generated with the crypto key generate rsa command. Next, local AAA authentication is enabled with aaa new-model and aaa authentication login default local.

The VTY lines are then configured to use SSH transport and the local login authentication. Finally, the SSH version is set to 2 for enhanced security.

645
MCQmedium

snmp-server community public RO\nsnmp-server community private RW\nsnmp-server community secret RW What is wrong with this configuration?

A.There is no access list to restrict SNMP access.
B.The community strings must be at least 8 characters.
C.Only one read-write community is allowed.
D.The 'public' community should be read-write.
AnswerA

Each snmp-server community entry lacks an access list argument, so any host that knows the community string can query or modify the device; restricting SNMP access to management hosts requires appending an ACL to each community statement.

Why this answer

The configuration lacks an access control list (ACL) to restrict which SNMP managers can use the community strings. Without an ACL, any device that can reach the router can query or modify the SNMP agent using the 'public' or 'private' strings, creating a severe security vulnerability. Cisco SNMP best practices mandate that each community string should be paired with an ACL to limit source IP addresses.

Exam trap

Cisco often tests the misconception that multiple RW communities are invalid or that community strings have a minimum length, when the real issue is the missing ACL to enforce source-based security.

How to eliminate wrong answers

Option B is wrong because SNMP community strings have no minimum length requirement in RFC 1157 or Cisco IOS; they can be as short as one character. Option C is wrong because Cisco IOS allows multiple read-write community strings; the configuration shown has two RW communities ('private' and 'secret'), which is perfectly valid. Option D is wrong because the 'public' community is correctly configured as read-only (RO) for monitoring purposes; making it read-write would violate the principle of least privilege and is not required.

646
Multi-Selectmedium

Which TWO statements about route summarization in BGP are true? (Choose TWO.)

Select 2 answers
A.The 'aggregate-address' command creates a summary route in the BGP table.
B.The 'summary-only' keyword can be used with 'aggregate-address' to suppress more specific routes.
C.The 'network' command is used to create a summary route in BGP.
D.BGP summarization requires a route-map to suppress more specific routes.
E.Route summarization in BGP can only be configured on route reflectors.
AnswersA, B

The aggregate-address command injects a summary prefix into the BGP table, provided at least one more specific component route exists in the table; it does not by itself suppress those components unless summary-only is added.

Why this answer

Option A is correct because the Cisco IOS 'aggregate-address <prefix> <mask>' command under the BGP router configuration creates an aggregate (summary) entry in the BGP table, provided at least one more-specific route from the same AS exists in the BGP table. Option B is correct because adding the 'summary-only' keyword to 'aggregate-address' advertises only the aggregate and suppresses the more-specific component routes to all neighbors, which is the standard way to prevent the specifics from being advertised. Option C is wrong because the 'network' command injects an exact prefix into BGP (it does not perform summarization or create an aggregate).

Option D is wrong because suppression of more-specifics is achieved with the 'summary-only' keyword (or with 'suppress-map' for selective suppression), not by a route-map requirement. Option E is wrong because route summarization via 'aggregate-address' can be configured on any BGP speaker, not only on route reflectors.

647
MCQhard

Router R1 is leaking a summary route 10.0.0.0/8 from VRF-A into the global routing table, but hosts in the global table cannot reach subnet 10.1.1.0/24 within VRF-A. R1 configuration: ip vrf VRF-A, rd 100:1, route-target export 100:1, route-target import 100:1. Interface Gig0/0 in VRF-A has ip address 10.1.1.1 255.255.255.0. The leaking is done via route-map: route-map LEAK permit 10, match ip address prefix-list SUMMARY, set global. Prefix-list SUMMARY permits 10.0.0.0/8. What is the root cause?

A.The summary route 10.0.0.0/8 is being installed in the global table, but the more specific route 10.1.1.0/24 is not leaked, causing traffic to be dropped.
B.The route-map should use match ip address prefix-list SPECIFIC instead of SUMMARY.
C.The VRF must have a default route to reach the global table.
D.The prefix-list should permit 10.1.1.0/24 only.
AnswerA

The global table only receives the /8 summary, which is not a valid forwarding path for 10.1.1.0/24 inside VRF-A; the /24 is never leaked, so return traffic has no matching global entry and is dropped.

Why this answer

The prefix-list SUMMARY only permits 10.0.0.0/8, so only the aggregate is leaked into the global table. The more specific 10.1.1.0/24 remains inside VRF-A and is never exported, so global-table hosts match the /8 and forward traffic toward R1, but R1 has no /24 in the global RIB and drops the packets. Leaking a summary without the constituent specifics creates a black hole for every subnet inside the aggregate.

Exam trap

The trap is assuming that leaking a summary route automatically carries the more-specific subnets with it — in IOS, each prefix must independently match the export route-map, so a /8 leak does not include a /24.

How to eliminate wrong answers

Option B is wrong because there is no 'SPECIFIC' prefix-list defined in the scenario, and the fix is to add the specific prefixes to the leak policy, not swap to a non-existent list. Option C is wrong because VRF-to-global leaking does not require a default route — the issue is missing specific prefixes, not reachability of the global table. Option D is wrong because permitting only 10.1.1.0/24 would leak one subnet but defeat the purpose of the summary and still leave other subnets unreachable; the correct fix is to leak both the summary and the specifics.

648
MCQmedium

A network engineer runs the following command on Router R1: R1# show crypto isakmp sa dst src state conn-id slot status 10.1.1.2 10.1.1.1 MM_ACTIVE 1 0 ACTIVE 10.1.1.3 10.1.1.1 MM_ACTIVE 2 0 ACTIVE Based on this output, which statement is correct?

A.IKE phase 1 is complete for both peers.
B.IKE phase 2 is complete for both peers.
C.The IPsec tunnels are established.
D.The peers are not responding.
AnswerA

MM_ACTIVE is the main mode state indicating IKE phase 1 security associations are established. Both peer entries show this state, confirming phase 1 completed for each peer; phase 2 quick mode is a separate negotiation.

Why this answer

The show crypto isakmp sa command shows IKE phase 1 security associations. The state MM_ACTIVE indicates that IKE phase 1 is complete and active. The output shows two active SAs with the local router (10.1.1.1) and two remote peers (10.1.1.2 and 10.1.1.3).

649
MCQhard

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on an interface facing the Internet. Legitimate traffic from a customer network is being dropped. The traffic has a source IP that belongs to the customer's prefix, which is reachable via a different interface on the router. Which is the most likely explanation?

A.The 'ip verify unicast source reachable-via any' command was used instead of 'rx'.
B.The router has a default route pointing out the same interface, causing uRPF to pass all traffic.
C.The customer traffic is arriving on an interface where the return path to the source is via a different interface, violating strict uRPF.
D.The 'ip urpf allow-default' command is missing, causing default routes to be ignored.
AnswerC

Strict uRPF checks that the source is reachable via the same interface the packet arrived on. Because the customer prefix routes back through a different interface, the check fails and legitimate traffic is dropped, exactly as the stem describes.

Why this answer

Strict uRPF requires that the source IP of an incoming packet be reachable via the same interface on which the packet arrived. In this scenario, the customer's source prefix is reachable via a different interface, so strict uRPF drops the legitimate traffic. This is the expected behavior of strict mode when routing is asymmetric.

Exam trap

The trap here is confusing strict and loose uRPF modes, or assuming that uRPF automatically adapts to asymmetric routing; candidates may overlook that strict mode requires the return path to be via the same interface.

How to eliminate wrong answers

Option A is wrong because using 'ip verify unicast source reachable-via any' (loose mode) would actually allow the traffic, as it only checks if the source is reachable via any interface, not necessarily the incoming one. Option B is wrong because a default route pointing out the same interface would cause uRPF to pass traffic only if the source is not found in the routing table and the default route is used, but strict uRPF does not consider default routes unless explicitly allowed; moreover, the issue is asymmetric routing, not a default route. Option D is wrong because 'ip urpf allow-default' is not a valid Cisco command; the correct command to allow default routes in uRPF is 'ip verify unicast source reachable-via rx allow-default', but the problem is not about default routes.

650
Multi-Selecthard

A network administrator is deploying MPLS Layer 3 VPNs on Cisco IOS routers. The administrator must ensure that customer routes are exchanged between PE routers without requiring customer involvement. Which two protocols or features are required to accomplish this? (Choose two.)

Select 2 answers
A.OSPF as the PE-CE routing protocol
B.Route targets configured under VRFs
C.RSVP-TE for traffic engineering
D.MP-BGP with VPNv4 address family
E.LDP for label distribution
AnswersB, D

Route targets are extended BGP communities used to control import and export of routes between VRFs. They are required to define which VPN routes are accepted into which VRF on remote PEs. Without route targets, MP-BGP would not know which customer routes to import, and VPN connectivity would fail. They are a fundamental part of MPLS Layer 3 VPN configuration.

Why this answer

MPLS Layer 3 VPNs rely on MP-BGP with the VPNv4 address family to exchange customer routes between PE routers. Route targets, implemented as extended BGP communities, are used to control import and export of these routes into VRFs. Together, they enable the PE routers to maintain separate routing tables and forward customer traffic correctly across the shared MPLS core.

Exam trap

The trap here is assuming that LDP or RSVP-TE is needed for VPN route exchange, when they only handle label distribution for core routes, not customer VPN prefixes.

651
Multi-Selecthard

Which TWO statements about EIGRP stub routing are true when troubleshooting a hub-and-spoke topology? (Choose TWO.)

Select 2 answers
A.A stub router advertises only connected and summary routes to its neighbors.
B.The stub feature is configured on the spoke router to limit queries from the hub.
C.A stub router will send a query to its neighbors if it loses a route.
D.Stub routers do not advertise any connected routes unless specifically configured.
E.The hub router must have the stub command configured to accept stub advertisements.
AnswersA, B

This is the core definition of EIGRP stub routing: it filters out all other routes from advertisements.

Why this answer

By default, an EIGRP stub router advertises only its connected and summary routes to its neighbors, which prevents it from being used as a transit router and limits query propagation in a hub-and-spoke topology. The stub feature is configured on the spoke router, not the hub; the hub detects the stub status and limits queries toward that spoke. Options C, D, and E are incorrect: a stub router's neighbors do not query it, connected routes are advertised by default, and the hub does not need the stub command to accept stub advertisements.

Therefore, the two true statements are A and B.

Exam trap

Cisco often tests the misconception that the stub feature is configured on the hub router to limit queries from spokes, but in reality, it is configured on the spoke router to prevent it from being queried.

652
Multi-Selecthard

Which THREE symptoms indicate that an IPv4 access control list may be misconfigured or not applied correctly? (Choose THREE.)

Select 3 answers
A.Traffic that should be permitted is being blocked.
B.The interface is flapping up and down.
C.High CPU utilization on the router due to ACL processing.
D.ACL hit counts are not incrementing for expected traffic.
E.Routing protocol neighbors are dropping.
AnswersA, C, D

This indicates the ACL may have an incorrect deny statement or order.

Why this answer

A primary symptom of a misconfigured or incorrectly applied ACL is that it blocks traffic that should be permitted. This typically occurs when the ACL's sequence of permit and deny statements does not match the intended policy, or when the ACL is applied in the wrong direction (inbound vs. outbound) on an interface. The router processes ACL entries sequentially, so a deny statement placed before a permit statement for the same traffic will cause legitimate packets to be dropped.

Exam trap

Cisco often tests the distinction between direct symptoms of ACL misconfiguration (blocking permitted traffic, no hit counts, high CPU) and indirect or unrelated issues (interface flapping, neighbor drops) that candidates might incorrectly associate with ACLs due to a superficial understanding of ACL behavior.

653
MCQmedium

A network engineer is configuring a site-to-site DMVPN Phase 3 hub-and-spoke topology. Spokes must be able to communicate directly without traffic traversing the hub. Which command must be configured on the hub to enable spoke-to-spoke direct tunnels?

A.ip nhrp network-id 1
B.ip nhrp redirect
C.ip nhrp map multicast dynamic
D.ip nhrp shortcut
AnswerB

The ip nhrp redirect command on the hub enables NHRP redirect messages that inform spokes of a better path to reach another spoke directly. When a spoke sends traffic to the hub for a destination behind another spoke, the hub sends an NHRP redirect, prompting the spoke to initiate a direct tunnel. This is a key requirement for DMVPN Phase 3 spoke-to-spoke communication.

Why this answer

In DMVPN Phase 3, the hub must be configured with ip nhrp redirect to send NHRP redirect messages to spokes when it receives traffic destined for another spoke. The spokes must also have ip nhrp shortcut to act on those redirects and establish direct tunnels. The redirect on the hub is essential for signaling the availability of a better path.

Exam trap

The trap here is confusing the hub and spoke roles, thinking that ip nhrp shortcut is configured on the hub when it is actually a spoke-side command.

654
MCQhard

A network engineer runs the following command on Router R1: R1# show ip nhrp nhs NHS: 172.16.0.1 Tunnel0 status: registered NHS: 172.16.0.2 Tunnel0 status: not registered Based on this output, what is the problem?

A.Router R1 is not registered with the second NHS, indicating a registration failure.
B.Both NHS are registered successfully.
C.The tunnel interface is down.
D.The NHS addresses are swapped.
AnswerA

The second NHS at 172.16.0.2 shows "not registered", meaning R1's NHRP registration request to that next-hop server failed or was never acknowledged. This directly satisfies the stem's requirement to identify the problem: R1 has no valid registration with the second NHS, so it cannot resolve mappings through it.

Why this answer

The 'show ip nhrp nhs' output lists each Next Hop Server and its registration state. The second NHS (172.16.0.2) shows 'not registered', meaning R1 failed to register with that NHS — typically due to mismatched network-id, missing 'ip nhrp map' entries, or unreachable NHS.

Exam trap

The trap is assuming that because the tunnel interface is up and one NHS registered, both must be fine — candidates overlook that NHRP registration is per-NHS and can fail independently for one server while succeeding for another.

How to eliminate wrong answers

Option B is wrong because the output explicitly shows one NHS as 'not registered', so both are not successful. Option C is wrong because the tunnel interface is clearly up — NHRP registration output would not appear if Tunnel0 were down. Option D is wrong because there is no evidence the NHS addresses are swapped; the output simply reflects two configured NHS entries with different registration states.

655
MCQmedium

A network engineer configures a Cisco IOS router with the following commands: ip access-list extended BLOCK_TELNET deny tcp any any eq 23 permit ip any any ! interface GigabitEthernet0/0 ip access-group BLOCK_TELNET in After applying the configuration, the engineer notices that Telnet traffic from the local router to a remote device is still successful. What is the cause of this issue?

A.The access list is applied in the inbound direction, which only filters traffic entering the interface, not traffic originated by the router.
B.The implicit deny at the end of the access list is blocking the Telnet traffic, but the 'permit ip any any' statement overrides it.
C.The access list must be applied with the 'ip access-group BLOCK_TELNET out' command on the same interface to filter locally generated traffic.
D.The 'deny tcp any any eq 23' statement is incorrect because Telnet uses TCP port 22, not port 23.
AnswerA

The access list is applied inbound on GigabitEthernet0/0, so it filters only packets entering that interface. Locally generated Telnet traffic from the router does not pass through the inbound access-group; it is subject to outbound filtering on the egress interface or to a VTY access-class. Therefore, the Telnet session succeeds despite the deny statement.

Why this answer

Access lists applied to an interface with the ip access-group command filter only traffic that passes through that interface in the specified direction. They do not filter traffic originated by the router itself. To control Telnet access to or from the router, an access-class must be applied under the VTY lines.

Since the ACL is applied inbound on an interface, it does not affect locally generated Telnet packets, so the Telnet session succeeds.

Exam trap

The trap here is assuming that an interface ACL applied inbound will also filter traffic generated by the router itself.

656
MCQeasy

A network engineer runs the following command on Router R1: R1# show snmp mib MIB: IF-MIB MIB: SNMPv2-MIB MIB: IP-MIB MIB: CISCO-CONFIG-MAN-MIB MIB: ENTITY-MIB Based on this output, which statement is correct?

A.The router supports monitoring of configuration changes via SNMP.
B.The router does not support the IF-MIB.
C.The router only supports Cisco proprietary MIBs.
D.The ENTITY-MIB is used for entity authentication.
AnswerA

CISCO-CONFIG-MAN-MIB is present in the MIB list, and that MIB exposes configuration change and event objects. Its presence confirms the router can report configuration modifications through SNMP, satisfying the monitoring requirement implied by the command output.

Why this answer

The output of 'show snmp mib' lists the MIBs that the router supports. The presence of CISCO-CONFIG-MAN-MIB indicates that the router supports the Cisco Configuration Management MIB, which allows SNMP to monitor and manage configuration changes, such as when a configuration is saved or modified. Therefore, option A is correct.

Exam trap

Cisco often tests the misconception that 'show snmp mib' lists only Cisco proprietary MIBs, but the output includes standard MIBs like IF-MIB and SNMPv2-MIB, so candidates must recognize that both standard and proprietary MIBs can be supported.

How to eliminate wrong answers

Option B is wrong because the output explicitly lists IF-MIB, so the router does support it. Option C is wrong because the output includes standard MIBs like IF-MIB, SNMPv2-MIB, and IP-MIB, not only Cisco proprietary MIBs. Option D is wrong because ENTITY-MIB is used for managing physical and logical entities (e.g., chassis, modules) and has nothing to do with entity authentication; authentication is handled by SNMPv3 security models or community strings.

657
MCQmedium

Which of the following statements about BFD echo mode is true?

A.Echo mode increases the load on the remote router because it must process echo packets.
B.Echo mode is disabled by default and must be explicitly enabled.
C.Echo mode uses the same timer values as the BFD control packets.
D.Echo mode allows the local router to detect failures without requiring the remote router to send BFD control packets.
AnswerD

Echo mode decouples failure detection from the peer's control-plane: the local router sends echo packets that the remote system loops back, so loss of return traffic triggers detection even if the neighbour stops transmitting BFD control packets.

Why this answer

In BFD echo mode, the local router sends echo packets that the remote router simply loops back (typically by forwarding to the same interface) without processing them as BFD control packets. This lets the local system detect forwarding-path failures on its own, without requiring the remote router to run BFD control-packet logic or maintain BFD state. The remote device only needs to forward the echo packets, which reduces its BFD processing burden.

Exam trap

300-410 often tests the misconception that echo mode increases remote router load — the opposite is true; the trap is confusing echo mode with asynchronous control-packet mode.

How to eliminate wrong answers

Option A is wrong because echo mode is specifically designed to reduce, not increase, the remote router's BFD processing load — the remote just loops packets back at the forwarding layer. Option B is wrong because BFD echo mode is not disabled by default in the sense implied; on many platforms echo mode is enabled by default once BFD is configured, and it can be disabled with the no bfd echo command, so the blanket 'disabled by default' claim is inaccurate. Option C is wrong because echo mode uses its own echo transmit interval (often derived from the slow/fast timers) and does not simply reuse the control-packet timer values; echo packets are sent at a separate, typically faster rate.

658
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip ospf virtual-links Virtual Link OSPF_VL0 to router 10.1.1.3 is up Run as demand circuit DoNotAge LSA allowed. Transit area 1, via interface GigabitEthernet0/0, Cost of using 10 Transmit Delay is 1 sec, State POINT_TO_POINT, Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5 Hello due in 00:00:08 Adjacency State FULL Based on this output, what can be concluded?

A.The virtual link is using area 0 as the transit area.
B.The virtual link is functioning correctly and the adjacency is full.
C.Router R1 is not receiving hello packets on the virtual link.
D.The virtual link has a cost of 1.
AnswerB

The output shows OSPF_VL0 in state up with Adjacency State FULL, confirming the virtual link traversing transit area 1 has successfully formed an adjacency with router 10.1.1.3. Hello and Dead timers match, and the demand circuit and DoNotAge LSA flags indicate normal operation, satisfying the requirement for area 0 connectivity through the transit area.

Why this answer

The output shows 'Virtual Link OSPF_VL0 to router 10.1.1.3 is up' and 'Adjacency State FULL', which means the virtual link has successfully formed an OSPF adjacency across the transit area. The transit area is explicitly listed as area 1, not area 0, and the cost is 10, confirming the link is operational and correctly configured.

Exam trap

The trap is misreading the output: candidates see 'Transit area 1' and assume it should be area 0, or confuse the Transmit Delay value (1 sec) with the link cost (10).

How to eliminate wrong answers

Option A is wrong because the output explicitly states 'Transit area 1' — area 0 is the backbone that the virtual link logically extends, not the transit area it traverses. Option C is wrong because the adjacency is FULL and 'Hello due in 00:00:08' shows hellos are being exchanged normally. Option D is wrong because the output shows 'Cost of using 10', not 1; the '1 sec' value refers to Transmit Delay, a common misread.

659
MCQmedium

What is the default administrative distance for routes redistributed into BGP from an IGP?

A.20
B.110
C.170
D.200
AnswerD

200 is the default distance for local BGP routes, which includes routes redistributed into BGP from an IGP.

Why this answer

When routes are redistributed into BGP from an IGP, they become local BGP routes, not eBGP. The default administrative distance for local BGP routes is 200, as configured by the `distance bgp` command: `distance bgp 20 200 200` (external, internal, local). Therefore, redistributed routes, which are considered local, have an AD of 200.

660
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. The hub router is a Cisco IOS XE device with the tunnel source as a physical interface and tunnel mode gre multipoint. Spoke routers are configured with dynamic NHRP mappings. The engineer notices that spoke-to-spoke traffic initially goes through the hub, but after the first packet, the spokes establish a direct tunnel. Which NHRP feature is responsible for this behavior?

A.NHRP holdtime and registration
B.NHRP redirect and shortcut switching
C.NHRP server-only and client-only configuration
D.NHRP authentication and mapping
AnswerB

NHRP redirect allows the hub to inform the source spoke that a better path exists, and shortcut switching enables the spoke to build a direct tunnel to the destination spoke. This is the core of DMVPN Phase 3, where the hub sends a redirect message and the spoke initiates an NHRP resolution for the destination, creating a direct spoke-to-spoke tunnel.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to notify a spoke that a more optimal path exists to the destination. The spoke then sends an NHRP resolution request for the destination spoke's NBMA address and, upon receiving a reply, builds a direct mGRE tunnel. This reduces latency and hub load by allowing direct spoke-to-spoke traffic.

Exam trap

The trap here is confusing NHRP authentication or registration with the mechanisms that enable direct spoke-to-spoke tunnels, when redirect and shortcut switching are the actual features.

661
MCQhard

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The administrator wants to rate-limit ICMP echo requests destined to the router itself to 64 kbps, while allowing all other traffic to the control plane without restriction. Which configuration snippet correctly achieves this?

A.class-map match-any ICMP match access-group name ICMP_ACL ! policy-map COPP class ICMP police 64000 class class-default police 8000 ! control-plane service-policy input COPP
B.class-map match-any ICMP match access-group name ICMP_ACL ! policy-map COPP class ICMP police 64000 class class-default police 8000000 ! control-plane service-policy input COPP
C.class-map match-any ICMP match access-group name ICMP_ACL ! policy-map COPP class ICMP police 64000 conform-action transmit exceed-action drop class class-default police 64000 ! control-plane service-policy output COPP
D.class-map match-any ICMP match access-group name ICMP_ACL ! policy-map COPP class ICMP police 64000 class class-default ! control-plane service-policy input COPP
AnswerD

This configuration correctly applies a 64 kbps policer to ICMP traffic matching the ACL, while the class-default has no policer, allowing all other control plane traffic to pass without restriction. The control-plane service-policy applies the policy map to the control plane interface.

Why this answer

The correct configuration creates a class map matching ICMP traffic via an ACL, a policy map that polices that class to 64 kbps, and leaves the class-default without a policer. Applying the policy map to the control-plane in the input direction enforces the rate limit on ICMP traffic destined to the router while allowing all other control plane traffic unrestricted.

Exam trap

The trap here is assuming that class-default must always have a policer; in CoPP, if no policer is configured for class-default, traffic in that class is not rate-limited.

662
MCQmedium

A network engineer is configuring a GRE tunnel between two Cisco IOS XE routers, R1 and R2, to transport IPv6 traffic over an IPv4 network. The tunnel source is R1's GigabitEthernet0/0 interface (IPv4 address 10.1.1.1) and the tunnel destination is R2's GigabitEthernet0/0 interface (IPv4 address 10.2.2.2). The engineer configures the tunnel interface with IPv6 address 2001:DB8:1::1/64 and enables OSPFv3 on the tunnel interface. However, OSPFv3 adjacencies are not forming. What is the most likely cause?

A.The tunnel interface must be configured with the `tunnel mode gre ipv6` command.
B.OSPFv3 requires the tunnel interface to be in the same area as the physical interfaces.
C.The tunnel interface must have an IPv4 address configured for OSPFv3 to work.
D.The tunnel source and destination must be reachable via IPv4, and the tunnel interface must be up.
AnswerD

For a GRE tunnel to be operational, the tunnel source and destination IPv4 addresses must be reachable. If the underlying IPv4 network cannot route between 10.1.1.1 and 10.2.2.2, the tunnel interface will remain down, and OSPFv3 will not form an adjacency. Additionally, the tunnel interface must be in an up/up state for OSPFv3 to run over it.

Why this answer

GRE tunnels require that the source and destination addresses are reachable via the transport network (IPv4 in this case). If the IPv4 network cannot route between the tunnel endpoints, the tunnel interface will be down, and no IPv6 traffic, including OSPFv3 hellos, will pass. The tunnel interface must be up and have the correct IPv6 address and OSPFv3 configuration.

Exam trap

The trap here is overlooking the underlying transport reachability; the tunnel cannot come up if the IPv4 source and destination cannot communicate.

663
MCQmedium

Examine the following configuration on R3: !--- R3 configuration access-list 10 permit 192.168.0.0 0.0.255.255 access-list 10 deny any ! route-map OSPF-REDIST permit 10 match ip address 10 set metric-type type-1 ! router ospf 1 redistribute eigrp 100 subnets route-map OSPF-REDIST ! What is the effect of this configuration?

A.All EIGRP routes are redistributed into OSPF as type-1 external routes.
B.Only EIGRP routes in the 192.168.0.0/16 range are redistributed into OSPF as type-1 external routes.
C.EIGRP routes in 192.168.0.0/16 are redistributed as type-2 by default; the set metric-type is ignored.
D.The configuration is invalid because the route-map uses an ACL that ends with deny any; a prefix-list must be used instead.
AnswerB

Access list 10 permits 192.168.0.0/16 and denies everything else, and the route map applies it to redistribution, so only matching EIGRP routes enter OSPF. The set metric-type type-1 clause marks them as E1 external routes.

Why this answer

The route-map OSPF-REDIST uses ACL 10 to match routes. ACL 10 permits 192.168.0.0/16 (with wildcard 0.0.255.255) and denies all else. The route-map then sets metric-type type-1 for matched routes.

Therefore, only EIGRP routes within 192.168.0.0/16 are redistributed into OSPF as type-1 external routes. The implicit deny at the end of the ACL means other routes are not redistributed.

Exam trap

300-410 often tests the assumption that an ACL with 'deny any' at the end invalidates the route-map, but it is standard and only affects unmatched routes.

How to eliminate wrong answers

Option A is wrong because the route-map filters routes; not all EIGRP routes are redistributed. Option C is wrong because the set metric-type type-1 is applied and not ignored; type-1 is used for matched routes. Option D is wrong because the configuration is valid; an ACL with deny any is common and does not invalidate the route-map.

664
MCQeasy

A network technician is configuring a Cisco IOS router to act as a DHCP server for a subnet. The technician wants the router to exclude a range of addresses from being assigned to clients. Which command should be used to exclude the addresses?

A.ip dhcp pool <name> excluded-address <start-ip> <end-ip>
B.ip dhcp excluded-address <start-ip> <end-ip> inside the interface configuration
C.ip dhcp exclude <start-ip> <end-ip>
D.ip dhcp excluded-address <start-ip> <end-ip>
AnswerD

The 'ip dhcp excluded-address' command is used in global configuration mode to specify a range of IP addresses that the DHCP server should not assign to clients. This is typically used for addresses that are statically assigned to servers, printers, or routers. The command takes a start and end IP address to define the exclusion range.

Why this answer

The correct command to exclude IP addresses from DHCP assignment is 'ip dhcp excluded-address' configured in global configuration mode. This command specifies a range of addresses that the DHCP server will not lease to clients. Other variations either do not exist or are configured in the wrong mode.

Exam trap

The trap here is assuming that address exclusions are configured within the DHCP pool, when in fact they are configured globally.

665
MCQhard

A network administrator is troubleshooting a DMVPN Phase 3 network using OSPF. Spoke routers are not learning routes from other spokes despite having a full mesh of tunnels. The hub is configured with 'ip nhrp redirect' and spokes with 'ip nhrp shortcut'. Which action is most likely to resolve the issue?

A.Ensure that the hub is configured with 'ip nhrp map multicast dynamic' and spokes with 'ip nhrp map multicast <hub>'.
B.Configure 'ip ospf network broadcast' on all tunnel interfaces.
C.Verify that the spoke routers have a route to the other spokes' tunnel endpoints via the hub, and that NHRP resolution is working.
D.Enable OSPF point-to-multipoint network type on all tunnel interfaces.
AnswerC

In DMVPN Phase 3, spokes initially use the hub for communication. When traffic to another spoke is detected, the spoke sends an NHRP resolution request. If the spoke lacks a route to the other spoke's tunnel endpoint (NBMA address) or NHRP resolution fails, the shortcut cannot be established. Ensuring NHRP resolution and routing to the NBMA address is critical.

Why this answer

In DMVPN Phase 3, spoke-to-spoke communication relies on NHRP shortcut resolution. For this to work, spokes must have a route to the other spokes' NBMA addresses (typically via the hub) and NHRP must be able to resolve their IP addresses. If NHRP resolution fails or there is no route to the NBMA address, the shortcut tunnel is not built, and traffic continues via the hub.

Thus, verifying NHRP resolution and routing is essential.

Exam trap

The trap here is focusing on OSPF network type or multicast configuration when the real issue is NHRP shortcut resolution and reachability to the NBMA address.

666
MCQeasy

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-IN Class-map: CoPP-OSPF (match-all) 1000 packets, 60000 bytes 5 minute offered rate 2000 bps, drop rate 0000 bps Match: access-group 140 police: cir 64000 bps, bc 12000 bytes, be 12000 bytes conformed 1000 packets, 60000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Based on this output, which statement is correct?

A.OSPF packets are being dropped due to exceeding the police rate.
B.OSPF traffic is being transmitted without any drops.
C.The police rate is set to 32000 bps.
D.The class-default is matching OSPF traffic.
AnswerB

The CoPP-OSPF class shows 1000 conformed packets transmitted with zero exceeded and zero violated packets, and a drop rate of 0000 bps. OSPF traffic therefore passes the control-plane policer untouched, well within the 64000 bps committed rate.

Why this answer

The output shows that under the CoPP-OSPF class, 1000 packets have been conformed and transmitted, with zero exceeded or violated packets. This means all OSPF traffic matched by access-group 140 has been within the police rate of 64000 bps, so no packets have been dropped. Therefore, OSPF traffic is being transmitted without any drops.

Exam trap

Cisco often tests the interpretation of the 'conformed', 'exceeded', and 'violated' counters in police output, where candidates mistakenly assume that any policing configuration implies drops are occurring, even when the counters show zero drops.

How to eliminate wrong answers

Option A is wrong because the output shows 0 exceeded and 0 violated packets, indicating no OSPF packets have been dropped due to policing. Option C is wrong because the police rate is explicitly shown as cir 64000 bps, not 32000 bps. Option D is wrong because the class-map is CoPP-OSPF (match-all), not class-default; class-default would only match traffic not classified by other class maps.

667
MCQeasy

A network engineer runs the following command on Router R1: R1# show ip nat translations Pro Inside global Inside local Outside local Outside global --- 192.0.2.10 10.0.0.10 --- --- R1# show ip nat statistics Total active translations: 1 (1 static, 0 dynamic; 0 extended) Outside interfaces: GigabitEthernet0/1 Inside interfaces: GigabitEthernet0/0 Hits: 5 Misses: 0 CEF Translated packets: 5, CEF Punted packets: 0 Expired translations: 0 Based on this output, which statement is correct?

A.Static NAT is configured for host 10.0.0.10 to 192.0.2.10.
B.Dynamic NAT is configured with overload.
C.The NAT pool is exhausted.
D.PAT is translating multiple hosts to the same global address.
AnswerA

The statistics line reports 1 static and 0 dynamic translations, and the table shows a one-to-one mapping between inside local 10.0.0.10 and inside global 192.0.2.10 with no outside entries, which is the signature of static NAT.

Why this answer

The output shows a single static NAT translation from inside local address 10.0.0.10 to inside global address 192.0.2.10. The 'show ip nat statistics' confirms '1 static' translation with no dynamic entries, and the NAT table lacks a port number, indicating a one-to-one static mapping rather than PAT. Therefore, static NAT is correctly configured for host 10.0.0.10 to 192.0.2.10.

Exam trap

Cisco often tests the distinction between static NAT and dynamic NAT with overload (PAT) by showing a translation table without port numbers—candidates mistakenly assume PAT is in use because they see a global address, but the absence of protocol/port fields and the '1 static' count in statistics clearly indicate static NAT.

How to eliminate wrong answers

Option B is wrong because dynamic NAT with overload (PAT) would show multiple translations with port numbers in the 'Pro' column (e.g., TCP/UDP) and '0 dynamic' in the statistics, which is not the case. Option C is wrong because the NAT pool is not exhausted; there is exactly one static translation active, and no dynamic translations are attempted or failing—misses are 0. Option D is wrong because PAT translates multiple inside hosts to a single global address using unique port numbers, but the output shows only one translation with no protocol or port, and the statistics indicate a static translation, not PAT.

668
MCQmedium

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# show ip route 192.168.2.0 Routing entry for 192.168.2.0/24 Known via "eigrp 100", distance 90, metric 2684416, type internal Redistributing via eigrp 100 Last update from 10.0.0.2 on Tunnel0, 00:00:23 ago Routing Descriptor Blocks: * 10.0.0.2, from 10.0.0.2, via Tunnel0 Route metric is 2684416, traffic share count is 1 Total delay is 20000 microseconds, minimum bandwidth is 100000 Kbit Reliability 255/255, minimum MTU 1500 bytes Loading 1/255, Hops 1 What does this output indicate?

A.The route to the remote LAN is not present, indicating a routing issue.
B.The IPsec tunnel is up and EIGRP is exchanging routes over the tunnel.
C.The route is using a static route, not a dynamic routing protocol.
D.The tunnel interface is down, causing the route to be unreachable.
AnswerB

The route to 192.168.2.0/24 is learned via EIGRP 100 through Tunnel0, with a valid next hop of 10.0.0.2 and a recent update timestamp. This confirms the IPsec tunnel is passing traffic and EIGRP adjacencies are exchanging routes across it.

Why this answer

The output shows a route to 192.168.2.0/24 learned via EIGRP (distance 90) with the next hop 10.0.0.2 reachable through Tunnel0. The last update was 23 seconds ago, confirming the tunnel is up and EIGRP is actively exchanging routing information over the IPsec tunnel. This indicates the IPsec Site-to-Site VPN is functioning and dynamic routing is working correctly.

Exam trap

Cisco often tests the misconception that a route learned via a tunnel interface implies the tunnel is down or that dynamic routing is not functioning, but the presence of a recent update and valid next hop confirms the tunnel is operational.

How to eliminate wrong answers

Option A is wrong because the route is present in the routing table, as shown by the 'Routing entry for 192.168.2.0/24' line, so there is no missing route. Option C is wrong because the route is learned via EIGRP (dynamic routing protocol), not a static route, as indicated by 'Known via "eigrp 100"'. Option D is wrong because the tunnel interface is up and operational; the route is reachable via Tunnel0 with a recent update, and the next hop is valid.

669
MCQhard

An engineer configures uRPF (Unicast Reverse Path Forwarding) in strict mode on a router interface facing the Internet. After configuration, legitimate traffic from customers is being dropped. The engineer verifies that the routing table has a route back to the source IP address. Which is the most likely explanation?

A.Asymmetric routing causes the return path to use a different interface
B.The uRPF allow-default option is not configured
C.The source IP address is not in the routing table
D.uRPF strict mode requires CEF to be disabled
AnswerA

Strict uRPF requires the source's return path to match the ingress interface. With asymmetric routing, the best route back to the source exits a different interface, so the check fails and legitimate packets are dropped despite the route existing in the table.

Why this answer

Strict uRPF checks that the source IP of an incoming packet is reachable via the same interface the packet arrived on. If the return route to the source points out a different interface (asymmetric routing), the check fails and the packet is dropped — even though a route to the source exists in the RIB.

Exam trap

300-410 often tests the assumption that 'route exists = uRPF passes' — the trap is forgetting that strict uRPF requires the route to point out the SAME interface, making asymmetric routing the classic failure cause.

How to eliminate wrong answers

Option B is wrong because allow-default only permits traffic when the source matches the default route; the scenario already states a specific route exists, so allow-default is not the missing piece. Option C is wrong because the engineer explicitly verified the source IP is in the routing table — restating the verified fact as the cause is a distractor. Option D is wrong because uRPF strict mode actually requires CEF (Cisco Express Forwarding) to be enabled, not disabled; disabling CEF would break uRPF entirely.

670
MCQeasy

When redistributing routes into OSPF, which OSPF metric value is assigned by default if none is specified?

A.1
B.10
C.20
D.100
AnswerC

OSPF assigns the default seed metric of 20 to routes redistributed from all sources except BGP, which uses 1. Without an explicit metric or default-metric command, this value satisfies the stem's constraint of no specified metric, so redistributed routes enter the OSPF domain with a metric of 20.

Why this answer

When redistributing routes into OSPF without specifying a metric, Cisco IOS assigns a default metric of 20. This default value is used for routes redistributed from all sources except BGP, which has a default of 1. The metric is used as the OSPF cost for the external route and is critical for path selection.

Exam trap

The 300-410 exam often tests the default seed metric for redistribution, and candidates may confuse the default for BGP (1) with the default for other protocols (20), leading to incorrect answers.

How to eliminate wrong answers

Option A is wrong because 1 is the default metric for redistributed BGP routes, not for other protocols. Option B is wrong because 10 is not a default metric for any common redistribution scenario in OSPF. Option D is wrong because 100 is a common manual metric or the default cost for certain interface types, but it is not the default redistribution metric.

671
MCQhard

An EIGRP network with multiple routers is experiencing frequent stuck-in-active (SIA) events for prefix 10.10.10.0/24. The network topology includes a slow WAN link between R1 and R2. R1's show ip eigrp topology 10.10.10.0/24 shows the route in active state with a query outstanding to R2. R2's show ip eigrp topology shows the same prefix in passive state. The EIGRP timers are default. What is the root cause?

A.The active timer on R1 is too short for the slow WAN link; it should be increased to accommodate query propagation delays.
B.R2 has a query outstanding to a neighbor over a slow link, preventing it from replying to R1 within the active timer.
C.The EIGRP hello timer mismatch between R1 and R2 is causing neighbor flapping.
D.The prefix 10.10.10.0/24 is being summarized, causing the query to be sent for the summary instead.
AnswerB

This is the classic SIA cause: R1 sends a query to R2 for the prefix, and R2 must propagate that query to all its neighbors and wait for every reply before it can formulate an answer to R1. If one of R2's downstream neighbors is over a slow or unreliable link and delays its reply, R2's response to R1 is held up beyond R1's active timer. That delay triggers the 'Stuck In Active' condition on R1.

Why this answer

R2 has the prefix in passive state, meaning it has not yet received a reply from one of its own neighbors over a slow link. Since R2 cannot reply to R1 until it gets that reply, R1's active timer expires, causing a stuck-in-active (SIA) event. This is a classic scenario where the query propagation delay exceeds the default active timer (3 minutes) due to a slow WAN link downstream from R2.

Exam trap

Cisco often tests the misconception that the SIA is caused by the directly connected slow link (between R1 and R2), when in fact the root cause is a slow link further downstream on R2, preventing R2 from replying in time.

How to eliminate wrong answers

Option A is wrong because the active timer on R1 is not the issue; R1's active timer is default (3 minutes), and the problem is that R2 is waiting for a reply from its own neighbor over a slow link, not that R1's timer is too short. Option C is wrong because EIGRP hello timer mismatch does not cause SIA events; it would cause neighbor flapping or adjacency loss, which is not indicated here since R1 and R2 remain neighbors (R1 has a query outstanding to R2). Option D is wrong because summarization would cause queries to be sent for the summary route, not the specific prefix, and the question states the prefix is 10.10.10.0/24, with no evidence of summarization; SIA events are not typically caused by summarization alone.

672
MCQhard

An engineer is troubleshooting an MPLS L3VPN where CE1 (10.1.1.0/24) cannot reach CE2 (10.2.2.0/24). The PE routers have MP-BGP peering and the VRF is configured with route-target import 100:100. On PE1, the show ip bgp vpnv4 vrf CUSTOMER command shows the route for 10.2.2.0/24 with a next-hop of 192.168.1.2 (the PE2 loopback), but the show ip route vrf CUSTOMER command does not have this route. The show mpls forwarding-table on PE1 does not show a label for 192.168.1.2. What is the most likely cause?

A.The VRF route-target import is missing on PE2.
B.LDP is not enabled on the core-facing interfaces of PE1 or the P routers.
C.The MP-BGP session is not using the loopback interface.
D.The VRF on PE1 has the wrong route-target export.
AnswerB

Without LDP on core-facing interfaces, no transport label exists for PE2's loopback, so the VPNv4 route's next hop is unresolvable and BGP cannot install it into the VRF table. The missing MPLS forwarding entry confirms this.

Why this answer

The most likely cause is that LDP is not enabled on the core-facing interfaces of PE1 or the P routers. For an MPLS L3VPN, the transport label (outer label) is distributed via LDP. Without LDP, PE1 cannot learn a label for the next-hop 192.168.1.2 (PE2's loopback), so the BGP VPNv4 route cannot be installed in the VRF routing table because there is no valid label stack.

The show mpls forwarding-table confirms the absence of a label for that next-hop.

Exam trap

The trap is assuming that MP-BGP alone is sufficient for L3VPN; candidates forget that an MPLS LSP (via LDP or RSVP-TE) is required for the transport label, and without it, VPN routes are not installed.

How to eliminate wrong answers

Option A is wrong because if the route-target import were missing on PE2, PE1 would not receive the route at all, but the show ip bgp vpnv4 shows the route is present. Option C is wrong because if MP-BGP were not using the loopback, the next-hop would be different, but the next-hop is the loopback, indicating it is using it. Option D is wrong because the route-target export on PE1 affects what PE1 advertises to PE2, not what it receives; the issue is with receiving and installing the route.

673
Drag & Drophard

Drag and drop the steps to troubleshoot Route Maps and Route Filtering adjacency or connectivity failures into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Start by verifying BGP neighbor state with show ip bgp summary. Next, examine the route-map configuration for syntax errors using show route-map. Then, check if the route-map is applied correctly to the neighbor with show running-config.

After that, use debug ip bgp updates to see if prefixes are being filtered. Finally, adjust the route-map sequence or match criteria to resolve the issue.

674
MCQmedium

A network engineer runs the following command to troubleshoot a Route Summarization issue: R1# debug ip routing IP: route table change: 10.0.0.0/16 via 10.1.1.2, Serial0/0/0, distance 90, metric 128576 IP: route table change: 10.0.1.0/24 via 10.1.1.2, Serial0/0/0, distance 90, metric 128576 IP: route table change: 10.0.2.0/24 via 10.1.1.2, Serial0/0/0, distance 90, metric 128576 What does this output indicate?

A.Both the summary route 10.0.0.0/16 and more specific /24 routes are being installed, which could indicate that summarization is not properly filtering the specific routes.
B.Only the summary route is being installed, and the /24 routes are being ignored.
C.The summary route is being replaced by the more specific routes.
D.The routes are being learned via different routing protocols.
AnswerA

The debug output lists the /16 summary alongside the individual /24 prefixes, all installed via the same next hop. Their simultaneous presence shows the specific routes were not suppressed, so summarisation is not filtering them as intended.

Why this answer

The debug output shows that multiple routes (a /16 and two /24s) are being installed into the routing table via the same next hop. This indicates that both the summary route and more specific routes are present, which may be a sign of inconsistent summarization or a leak of more specific routes.

675
MCQeasy

A network engineer is configuring a Cisco router to act as a DHCP server for a remote subnet. The router's interface connected to the remote subnet is configured with the `ip helper-address` command pointing to the DHCP server. However, clients on the remote subnet are not receiving IP addresses. The engineer verifies that the DHCP server is operational and has a valid pool for the remote subnet. What is the most likely cause of the problem?

A.The `ip helper-address` command is applied to the wrong interface.
B.The router's interface connected to the remote subnet is down.
C.The DHCP server is configured with a different subnet mask than the clients.
D.The DHCP server does not have a route back to the remote subnet.
AnswerD

For DHCP to work across subnets, the DHCP server must have a route to the remote subnet to send the DHCPOFFER and DHCPACK messages. If the server lacks a route, it cannot respond to the client's request. The `ip helper-address` forwards the initial DHCPDISCOVER, but the server's reply must be routable back to the client's subnet. Thus, a missing route on the server is a common cause.

Why this answer

When using `ip helper-address` to forward DHCP requests to a server on a different subnet, the DHCP server must have a route back to the client subnet. The server uses this route to send DHCPOFFER and DHCPACK messages. Without it, the server cannot reach the clients, and they will not receive IP addresses.

Ensuring the server has a route to the remote subnet resolves the issue.

Exam trap

The trap here is focusing on the router configuration and overlooking the need for a return route on the DHCP server.

Page 8

Page 9 of 19

Page 10