Courseiva

CCNA Layer 3 Technologies Questions

75 of 111 questions · Page 1/2 · Layer 3 Technologies · Answers revealed

1
MCQhard

A network engineer is implementing CoPP on a Cisco router to protect the control plane from DoS attacks. The engineer wants to rate-limit ICMP echo requests destined to the router's management IP address. Which CoPP policy component is responsible for defining the traffic classification?

A.Class map
B.Access control list (ACL)
C.Policy map
D.Service policy
AnswerA

The class map is used to classify traffic by matching specific criteria, such as protocol type, source/destination IP, or port numbers. In this scenario, to rate-limit ICMP echo requests, the engineer would create a class map that matches ICMP echo-request packets. Therefore, the class map is the component that defines the traffic classification for CoPP.

Why this answer

The correct answer is the class map, which defines the traffic classification by matching specific packet characteristics. In CoPP, class maps are used to identify traffic of interest, such as ICMP echo requests. The policy map then applies actions like policing to those classes.

The service policy attaches the policy map to the control plane, and ACLs can be used within class maps for matching but are not the classification component themselves.

Exam trap

The trap here is confusing the role of the class map with that of the policy map, thinking the policy map defines classification when it actually defines actions.

2
MCQmedium

A network engineer is troubleshooting a dual-stack Cisco IOS XE router that runs OSPFv3 for IPv6 and OSPFv2 for IPv4. IPv4 adjacencies form and routes are exchanged, but no OSPFv3 adjacencies form and no IPv6 routes appear. The engineer verifies that the interfaces have IPv6 addresses and that `ipv6 unicast-routing` is enabled. Which configuration step is most likely missing?

A.Configure an IPv6 address on the OSPFv3 process using the `ipv6 address` command under `router ospfv3`.
B.Configure an OSPFv3 router ID with the `router-id` command under the OSPFv3 process.
C.Enable IPv6 unicast routing globally with the `ipv6 unicast-routing` command.
D.Enable OSPFv3 on the interfaces by adding them to an OSPFv3 process with the `ipv6 ospf 1 area 0` interface command.
AnswerD

OSPFv3 does not automatically enable on interfaces when the process is created; each interface must be explicitly enabled with `ipv6 ospf <process-id> area <area-id>` or by using `ipv6 ospf area` under the interface. Without this command, the router will not send or process OSPFv3 hellos, so no adjacency forms even though IPv6 addressing and unicast routing are configured correctly.

Why this answer

OSPFv3 requires explicit interface activation; creating the process and enabling global IPv6 routing are not enough. The `ipv6 ospf <process-id> area <area-id>` interface command enables OSPFv3 on that link and triggers hello packets. Without it, no OSPFv3 neighbor relationships form, even though IPv6 addressing and forwarding are correctly configured.

This is a common oversight when migrating from OSPFv2, where network statements under the process can enable interfaces indirectly.

Exam trap

The trap here is assuming OSPFv3 is enabled on interfaces simply because the OSPFv3 process exists and IPv6 routing is globally enabled.

3
MCQmedium

A network engineer is implementing policy-based routing (PBR) on a Cisco IOS router. The engineer wants to route traffic from the 10.1.1.0/24 subnet to a next-hop of 192.168.1.1, while all other traffic uses the default routing table. Which configuration correctly implements this?

A.route-map PBR permit 10 match ip address 10 set ip next-hop 192.168.1.1 ! interface GigabitEthernet0/0 ip policy route-map PBR ! access-list 10 permit 10.1.1.0 0.0.0.255
B.route-map PBR permit 10 match ip address 10 set ip default next-hop 192.168.1.1 ! interface GigabitEthernet0/0 ip policy route-map PBR ! access-list 10 permit 10.1.1.0 0.0.0.255
C.route-map PBR permit 10 match ip address 10 set ip next-hop 192.168.1.1 ! interface GigabitEthernet0/0 ip route-cache policy ! access-list 10 permit 10.1.1.0 0.0.0.255
D.route-map PBR permit 10 match ip address 10 set interface GigabitEthernet0/1 ! interface GigabitEthernet0/0 ip policy route-map PBR ! access-list 10 permit 10.1.1.0 0.0.0.255
AnswerA

This configuration creates a route map that matches traffic from the 10.1.1.0/24 subnet (via access list 10) and sets the next-hop to 192.168.1.1. The route map is applied to the interface with the ip policy route-map command. This correctly implements policy-based routing for the specified subnet, while other traffic will follow the normal routing table.

Why this answer

Policy-based routing (PBR) allows you to override the normal routing table based on criteria such as source IP address. The correct configuration uses a route map with a match statement for the source subnet and a set statement to define the next-hop. The route map is then applied to the interface with the ip policy route-map command.

The set ip next-hop command ensures that matched traffic is forwarded to the specified next-hop, while other traffic uses the default routing table.

Exam trap

The trap here is confusing set ip next-hop with set ip default next-hop; the latter only applies when there is no explicit route in the routing table.

4
MCQmedium

A network engineer is configuring OSPF on a router with three interfaces: Gi0/0 (10.1.1.1/24), Gi0/1 (10.2.2.1/24), and Gi0/2 (10.3.3.1/24). The engineer wants to prevent OSPF from forming adjacencies on Gi0/2 while still advertising the 10.3.3.0/24 network into OSPF. Which configuration accomplishes this?

A.Configure the Gi0/2 interface with the ip ospf database-filter all out command.
B.Configure the Gi0/2 interface as passive with the passive-interface Gi0/2 command under router ospf.
C.Configure the Gi0/2 interface with the ip ospf network point-to-point command.
D.Configure a distribute-list on Gi0/2 to filter OSPF hellos.
AnswerB

The passive-interface command under router ospf suppresses OSPF hello packets on the specified interface, preventing adjacency formation, but the network connected to that interface is still advertised as a stub network into OSPF. This meets the requirement of no adjacencies while still advertising 10.3.3.0/24. It is the standard method for this scenario and does not affect other interfaces.

Why this answer

The passive-interface command is designed to stop OSPF from sending and processing hello packets on an interface, which prevents neighbor adjacencies. However, the network prefix associated with that interface is still advertised as a stub network into OSPF, allowing other routers to reach it. This exactly matches the requirement to suppress adjacencies while still advertising the subnet.

Exam trap

The trap here is confusing LSA filtering with hello suppression; database-filter and distribute-lists affect LSAs, not hellos, so they do not stop adjacency formation.

5
MCQeasy

A network engineer is configuring a Cisco IOS XE router to support IPv6. The engineer wants to enable IPv6 routing and assign an IPv6 address to an interface. Which command must be configured globally to enable IPv6 routing?

A.ipv6 routing
B.ipv6 unicast-routing
C.ipv6 address autoconfig
D.ipv6 enable
AnswerB

The ipv6 unicast-routing command enables IPv6 unicast routing globally on the router. Without it, the router will not forward IPv6 packets, even if interfaces have IPv6 addresses. This command is essential for any IPv6 routing configuration. It allows the router to participate in IPv6 routing protocols and forward IPv6 traffic between interfaces.

Why this answer

To enable IPv6 routing globally on a Cisco IOS XE router, the engineer must configure the ipv6 unicast-routing command in global configuration mode. This command allows the router to forward IPv6 packets and participate in IPv6 routing protocols. The other options are either interface-level commands or invalid syntax.

Without this command, the router will not route IPv6 traffic, even if interfaces are configured with IPv6 addresses.

Exam trap

The trap here is confusing interface-level IPv6 enabling commands with the global command required to enable IPv6 routing.

6
MCQhard

A network engineer is implementing policy-based routing (PBR) on a Cisco router. The goal is to route traffic from a specific subnet to a next-hop IP address that is not directly connected. Which configuration is required to achieve this?

A.A route map that matches the source subnet and sets the interface to the next-hop interface.
B.A route map that matches the source subnet and sets the next-hop IP address, and a static route to the next-hop IP address.
C.A route map that matches the source subnet and sets the default next-hop IP address.
D.A route map that matches the source subnet and sets the next-hop IP address.
AnswerB

When using PBR with 'set ip next-hop', the next-hop IP address must be reachable via a route in the routing table. If the next-hop is not directly connected, you need a static route to that next-hop. This ensures that the router can forward the packet to the next-hop. Without the static route, the PBR action would fail because the next-hop is not resolvable.

Why this answer

PBR with 'set ip next-hop' requires that the next-hop IP address be reachable. If it is not directly connected, a static route must be present to resolve the next-hop. The other options either do not address the reachability requirement or use incorrect syntax.

Exam trap

The trap here is forgetting that PBR next-hop must be reachable via the routing table, and assuming that PBR can override routing without a route to the next-hop.

7
MCQmedium

A network engineer is implementing policy-based routing (PBR) on a Cisco router. The goal is to forward traffic from a specific subnet to a next-hop IP address that is not directly connected, but reachable via a recursive lookup. The engineer configures a route-map with 'set ip next-hop recursive <IP>'. However, traffic is not being forwarded as expected. Which of the following is the most likely reason?

A.The 'set ip next-hop recursive' command is not supported in PBR.
B.The next-hop IP address is reachable via the default route only.
C.The route-map is not applied to the correct interface.
D.The next-hop IP address is not resolvable via a route in the RIB.
AnswerD

The 'set ip next-hop recursive' command requires that the specified next-hop IP address be resolvable through a route in the routing table (RIB). If there is no route to that next-hop, the recursive lookup fails, and the PBR policy is not applied. The router will then fall back to normal destination-based routing. Thus, the most likely reason is that the next-hop address is not present in the RIB.

Why this answer

For 'set ip next-hop recursive' to work, the specified next-hop address must be resolvable via a route in the routing table. If no such route exists, the recursive lookup fails, and the PBR policy is skipped. The router then uses the normal routing table.

Therefore, the absence of a route to the next-hop is the most likely cause of the failure.

Exam trap

The trap here is assuming that 'set ip next-hop recursive' can resolve any IP address, even if it is not in the routing table, when in fact it requires a RIB entry.

8
MCQmedium

A network engineer is deploying DMVPN Phase 3 with EIGRP as the routing protocol over a hub-and-spoke topology. The hub router is configured with `ip nhrp redirect` on its tunnel interface, and each spoke has `ip nhrp shortcut`. A spoke needs to send traffic to a remote subnet behind another spoke. Which mechanism allows the spoke to install a direct route to the remote spoke's tunnel IP without traversing the hub for every packet?

A.NHRP resolution request triggered by the hub's redirect message, followed by installation of a shortcut entry in the NHRP cache and a /32 route in the RIB.
B.The hub advertises a host route for each spoke's tunnel IP, and the spoke uses that route with the hub as next hop until the NHRP cache is populated by regular traffic.
C.The hub sends an ICMP redirect to the spoke, which then uses the hub's next-hop IP as the gateway for the remote subnet.
D.The spoke performs a recursive lookup on the hub's public IP and automatically derives the remote spoke's tunnel IP from the hub's NHRP database.
AnswerA

With NHRP redirect on the hub, the hub sends an NHRP redirect message to the originating spoke when it forwards traffic out the same tunnel interface. The spoke then sends an NHRP resolution request for the destination NBMA address, receives a resolution reply, installs a shortcut entry in the NHRP cache, and the routing protocol (or NHRP) installs a /32 route, enabling direct spoke-to-spoke forwarding.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to tell a spoke that a better path exists. The spoke then sends an NHRP resolution request for the destination, receives the remote spoke's NBMA address, installs a shortcut entry, and creates a /32 route. This enables direct spoke-to-spoke forwarding without hairpinning through the hub for every packet.

Exam trap

The trap here is assuming that ICMP redirect or a hub-advertised host route can trigger spoke-to-spoke path optimization, when DMVPN specifically relies on NHRP redirect and NHRP resolution to build shortcut entries.

9
MCQhard

A network engineer is configuring a Cisco IOS XE router for DMVPN Phase 3. The hub router is configured with `ip nhrp map multicast dynamic` and `ip nhrp network-id 100`. The spoke routers are configured with `ip nhrp map` and `ip nhrp nhs`. The engineer wants to enable spoke-to-spoke communication without traffic traversing the hub after the initial resolution. Which additional command is required on the hub to support Phase 3 shortcut switching?

A.`ip nhrp redirect` on the hub tunnel interface.
B.`ip nhrp shortcut` on the hub tunnel interface.
C.`ip nhrp network-id 100` on the spoke tunnel interfaces.
D.`ip nhrp map multicast dynamic` on the spoke tunnel interfaces.
AnswerA

In DMVPN Phase 3, the hub must be configured with `ip nhrp redirect` to inform spokes when a better path exists. When the hub receives a packet from a spoke destined to another spoke, it sends an NHRP redirect message to the originating spoke, prompting it to resolve the destination spoke's NBMA address directly. This enables spoke-to-spoke tunnels without traversing the hub for subsequent packets. Without this command, Phase 3 shortcut switching does not occur.

Why this answer

DMVPN Phase 3 enables spoke-to-spoke communication with hub assistance. The hub uses `ip nhrp redirect` to send redirect messages to spokes when it detects that traffic between spokes could take a direct path. Spokes then use `ip nhrp shortcut` to create a direct tunnel.

The hub must have `ip nhrp redirect` configured; otherwise, spokes never receive the redirect and continue to send traffic through the hub.

Exam trap

The trap here is mixing up the roles of `ip nhrp redirect` and `ip nhrp shortcut`; the redirect is on the hub, while the shortcut is on the spokes.

10
MCQeasy

A network engineer is configuring EIGRP on a router. The engineer wants to ensure that the router does not send EIGRP updates out of an interface connected to a non-EIGRP neighbor, but still advertises the connected network into EIGRP. Which configuration command should be used?

A.passive-interface <interface> under router EIGRP configuration
B.no network <network> under router EIGRP configuration
C.distribute-list <acl> out <interface> under router EIGRP configuration
D.ip split-horizon under interface configuration
AnswerA

The 'passive-interface' command under EIGRP configuration suppresses EIGRP hello packets and updates on the specified interface, preventing adjacency formation. However, the connected network is still advertised into EIGRP as long as it is covered by a network statement. This meets the requirement of not sending updates out of the interface while still advertising the subnet.

Why this answer

The passive-interface command under EIGRP configuration stops EIGRP from sending hellos and updates on the specified interface, preventing adjacency formation with non-EIGRP neighbors. Meanwhile, the connected network is still advertised into EIGRP if it falls under a network statement. Other options either do not prevent updates or also stop advertisement of the network.

Exam trap

The trap here is thinking that a distribute-list or split horizon can prevent EIGRP updates from being sent, when they do not stop hello packets or adjacency formation.

11
MCQmedium

A network engineer is troubleshooting a DMVPN Phase 3 network using Cisco IOS-XE routers. The hub router is configured with `ip nhrp redirect` and spoke routers with `ip nhrp shortcut`. A spoke router is unable to establish a direct spoke-to-spoke tunnel for a specific destination. Which action should the engineer take to resolve this?

A.Disable `ip split-horizon` on the hub's tunnel interface.
B.Configure `ip nhrp map multicast dynamic` on the hub.
C.Configure `ip nhrp nhs` on the spoke to point to the hub.
D.Ensure that the spoke routers have a route to the destination network via the hub.
AnswerD

For DMVPN Phase 3 shortcut tunnels to work, the spoke must have a route to the destination network pointing to the hub initially. When traffic is sent to the hub, the hub sends an NHRP redirect, and the spoke can then establish a direct tunnel. Without a route via the hub, the spoke cannot trigger the shortcut process.

Why this answer

DMVPN Phase 3 relies on NHRP redirects from the hub to trigger spoke-to-spoke shortcuts. For the spoke to send initial traffic to the hub and receive a redirect, it must have a route to the destination via the hub. This route is typically learned through the routing protocol running over the DMVPN.

Without it, the spoke cannot initiate the shortcut process.

Exam trap

The trap here is focusing on NHRP or multicast configuration when the missing piece is often the routing table entry on the spoke that points to the hub, which is required to trigger the redirect.

12
MCQmedium

A network engineer is configuring BGP on a Cisco IOS XE router. The router has two eBGP peers: ISP-A and ISP-B. The engineer wants to influence outbound traffic so that the router prefers ISP-A for all destinations unless ISP-A fails. Which BGP attribute should the engineer manipulate, and how?

A.Prepend the AS path for routes learned from ISP-A using a route map with `set as-path prepend`.
B.Set a higher weight for routes learned from ISP-A using the `neighbor weight` command.
C.Set a higher local preference for routes learned from ISP-A using a route map with `set local-preference 200`.
D.Set a lower multi-exit discriminator (MED) for routes learned from ISP-A using a route map with `set metric 50`.
AnswerC

Local preference is the second BGP attribute in the best-path selection process, after weight, and it is used to influence outbound traffic within an autonomous system. By setting a higher local preference for routes learned from ISP-A, the router will prefer those routes over routes from ISP-B for the same prefix. This is the standard method to control outbound path selection when multiple eBGP peers exist.

Why this answer

Local preference is the correct attribute to influence outbound traffic in BGP. It is exchanged within an autonomous system via IBGP and is evaluated before MED and AS path. By assigning a higher local preference to routes from ISP-A, the router will consistently prefer ISP-A for outbound traffic as long as those routes are available.

This provides a deterministic outbound path selection that can be applied network-wide.

Exam trap

The trap here is confusing outbound and inbound traffic engineering, and mixing up attributes like MED and AS path prepending that affect inbound traffic.

13
MCQmedium

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (LAN) and GigabitEthernet0/1 (WAN). The engineer wants all HTTP traffic from the 10.1.1.0/24 subnet to be routed via next-hop 192.168.2.2 instead of the default route. The engineer creates a route map named PBR with sequence 10, matches an ACL that permits TCP port 80 from 10.1.1.0/24, and sets the next-hop to 192.168.2.2. The route map is applied to interface GigabitEthernet0/0 with the command `ip policy route-map PBR`. However, traffic still follows the default route. Which action will fix the problem?

A.Ensure the ACL used in the route map matches the correct source and destination addresses and ports, and that the route map is applied in the correct direction.
B.Configure the `ip local policy route-map PBR` command to apply the route map globally.
C.Apply the route map to the GigabitEthernet0/1 interface instead of GigabitEthernet0/0.
D.Add the `set ip next-hop verify-availability` command to the route map.
AnswerA

Policy-based routing requires that the ACL correctly identifies the traffic to be policy-routed. The ACL must permit TCP port 80 from 10.1.1.0/24 to any destination. Additionally, the route map must be applied to the ingress interface (GigabitEthernet0/0) in the inbound direction, which is the default when using the `ip policy route-map` command. Verifying these elements will resolve the issue.

Why this answer

Policy-based routing (PBR) on Cisco IOS XE requires that the route map is applied to the interface where traffic enters the router and that the ACL matches the intended traffic. Common oversights include misconfigured ACLs (wrong source, destination, or port) or applying the policy to the wrong interface. Ensuring the ACL matches HTTP traffic from 10.1.1.0/24 and that the route map is applied inbound on GigabitEthernet0/0 will make PBR function as intended.

Exam trap

The trap here is assuming that PBR automatically works once the route map is created and applied, without verifying that the ACL matches the traffic correctly.

14
MCQmedium

A network engineer is configuring a Cisco IOS XE router to connect to an ISP via BGP. The engineer wants to influence inbound traffic from the ISP by prepending the router's AS number multiple times to the BGP updates sent to the ISP. Which BGP attribute should the engineer modify to achieve this?

A.Weight
B.AS path
C.Multi-exit discriminator (MED)
D.Local preference
AnswerB

AS path is a well-known mandatory attribute that lists the autonomous systems a route has traversed. By prepending additional AS numbers to the AS path, the engineer makes the route appear longer, which is less preferred by BGP. This influences inbound traffic because the ISP will choose a shorter AS path if available. It is a common method to manipulate inbound traffic.

Why this answer

AS path prepending is the technique of adding multiple instances of the local AS number to the AS path attribute in BGP updates sent to external peers. This makes the route less attractive because a longer AS path is less preferred. It is a standard method to influence inbound traffic from an ISP.

Local preference and weight affect outbound traffic, while MED is an alternative but less forceful method for inbound influence.

Exam trap

The trap here is confusing attributes that influence outbound traffic (local preference, weight) with those that influence inbound traffic (AS path, MED).

15
MCQmedium

A network engineer is troubleshooting a DMVPN Phase 3 hub-and-spoke topology. Spoke routers are Cisco IOS devices running EIGRP as the routing protocol. The engineer wants to ensure that spoke-to-spoke traffic does not go through the hub after the initial path setup, and that spoke routers can dynamically form direct tunnels. Which NHRP command must be configured on the hub to enable this behavior?

A.ip nhrp map multicast dynamic
B.ip nhrp redirect
C.ip nhrp network-id 1
D.ip nhrp shortcut
AnswerB

The 'ip nhrp redirect' command on the hub enables NHRP redirect messages, which inform spokes of a better direct path to another spoke. This allows spoke-to-spoke communication without traversing the hub after initial resolution. It is essential for DMVPN Phase 3 and works with 'ip nhrp shortcut' on spokes.

Why this answer

For DMVPN Phase 3, the hub must be configured with 'ip nhrp redirect' to send redirect messages to spokes, allowing them to establish direct tunnels. Spokes must have 'ip nhrp shortcut' to act on those redirects. Without the hub redirect, spokes would continue sending traffic through the hub even after initial NHRP resolution.

Exam trap

The trap here is confusing the roles of 'ip nhrp redirect' and 'ip nhrp shortcut', mistakenly placing the shortcut command on the hub instead of the spoke.

16
MCQmedium

A network engineer is configuring a Cisco router to authenticate OSPF neighbors using MD5. The router is connected to two OSPF neighbors on the same subnet. The engineer wants to enable MD5 authentication on the interface with a key ID of 1 and a password of 'Cisco123'. Which command sequence correctly accomplishes this?

A.router ospf 1 area 0 authentication ip ospf message-digest-key 1 md5 Cisco123
B.router ospf 1 area 0 authentication message-digest ip ospf message-digest-key 1 md5 Cisco123
C.interface GigabitEthernet0/0 ip ospf authentication-key Cisco123 ip ospf authentication message-digest
D.interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 Cisco123
AnswerD

This sequence enables OSPF MD5 authentication on the interface and configures the key ID and password. The 'ip ospf authentication message-digest' command activates MD5 authentication for OSPF on that interface, and 'ip ospf message-digest-key 1 md5 Cisco123' defines the key. This is the correct method to enable MD5 authentication per interface. Both commands are required; without the first, the key is configured but authentication is not enabled.

Why this answer

To enable OSPF MD5 authentication on a specific interface, you must enter interface configuration mode and issue both 'ip ospf authentication message-digest' to turn on MD5 authentication and 'ip ospf message-digest-key 1 md5 Cisco123' to define the key. This method allows per-interface authentication, which is suitable when only certain interfaces require MD5. The other options either misplace the key command, use plaintext authentication, or configure area-wide authentication incorrectly.

Exam trap

The trap here is confusing interface-level MD5 authentication commands with area-level authentication commands, and misplacing the key configuration under router ospf mode instead of interface mode.

17
MCQmedium

A network engineer is configuring MPLS Layer 3 VPN on a Cisco IOS XE router. The engineer needs to enable the provider edge (PE) router to exchange VPNv4 routes with another PE router. Which address family must be configured under the BGP routing process to achieve this?

A.address-family ipv4 vrf
B.address-family ipv6 unicast
C.address-family ipv4 unicast
D.address-family vpnv4 unicast
AnswerD

This address family is specifically designed to carry VPNv4 routes with MPLS labels between PE routers. It enables the exchange of customer VPN routes along with their associated route targets and MPLS labels. Configuring this address family under BGP is essential for MPLS L3VPN operation.

Why this answer

To exchange VPNv4 routes between PE routers in an MPLS L3VPN environment, the BGP process must be configured with the address-family vpnv4 unicast command. This enables the PE routers to exchange VPNv4 prefixes along with MPLS labels and route targets. The other address families do not support VPNv4 route exchange.

Exam trap

The trap here is confusing the VPNv4 address family with the IPv4 VRF address family, which is used for PE-CE routing.

18
MCQmedium

A network engineer is configuring OSPF on a Cisco router. The router has three interfaces in Area 0, and the engineer wants to ensure that the router does not become a Designated Router (DR) on any of these interfaces. Which command should be used on each interface?

A.ip ospf priority 255
B.ip ospf network point-to-point
C.ip ospf dr-disable
D.ip ospf priority 0
AnswerD

Setting OSPF priority to 0 on an interface makes the router ineligible to become DR or BDR on that interface. This is the correct method to prevent a router from being elected as DR. The priority value is carried in Hello packets and used in the DR election process; a priority of 0 means the router will not participate in the election.

Why this answer

OSPF DR/BDR election is influenced by interface priority. A priority of 0 makes a router ineligible to become DR or BDR. The other options either do not exist, change the network type unnecessarily, or increase the likelihood of becoming DR.

Therefore, setting priority to 0 on each interface is the correct approach.

Exam trap

The trap here is confusing OSPF priority with other routing protocol metrics or assuming that a non-existent command like 'dr-disable' exists.

19
MCQmedium

A network engineer is configuring OSPF on a router that connects to a broadcast Ethernet segment. The router is connected to a switch that also connects to three other OSPF routers. The engineer wants to ensure that this router does not become the Designated Router (DR) or Backup Designated Router (BDR) on this segment, but still participates in OSPF. Which configuration should the engineer apply on the router's interface?

A.ip ospf database-filter all out
B.ip ospf priority 255
C.ip ospf priority 0
D.ip ospf network point-to-point
AnswerC

Setting the OSPF priority to 0 on the interface prevents the router from being elected as DR or BDR on that segment. It will still form adjacencies and participate in OSPF as a DROTHER. This is the standard method to ensure a router does not take on the DR/BDR role while remaining an active OSPF participant.

Why this answer

The OSPF priority value is used in the DR/BDR election on broadcast and non-broadcast multi-access segments. A priority of 0 makes the router ineligible to become DR or BDR, while still allowing it to form adjacencies and exchange routing information. This is the correct way to keep a router as a DROTHER on a segment where it should not take on a primary role.

Exam trap

The trap here is confusing OSPF priority with other interface parameters, or assuming that a high priority prevents DR election rather than encourages it.

20
MCQeasy

A network administrator is configuring a GRE tunnel between two Cisco routers to transport IPv6 traffic over an IPv4-only core. The administrator enters the following configuration on Router A: interface Tunnel0 ipv6 address 2001:DB8:100::1/64 tunnel source 10.1.1.1 tunnel destination 10.2.2.2 tunnel mode gre ipv6 However, the tunnel interface remains down. What is the most likely cause?

A.The tunnel source and destination must be IPv6 addresses, not IPv4.
B.The tunnel mode should be gre ipv6, but it is incorrectly set to gre ipv4.
C.The tunnel interface requires an IPv4 address in addition to the IPv6 address to become operational.
D.The physical interface providing the tunnel source address is not operational or there is no route to the tunnel destination.
AnswerD

A GRE tunnel interface remains down if the tunnel source address is not up or if there is no route to the tunnel destination. The administrator must ensure the physical interface with the source address is operational and that a route exists to 10.2.2.2. Without reachability, the tunnel cannot come up.

Why this answer

A GRE tunnel interface will only come up if the tunnel source is operational and there is a route to the tunnel destination. In this scenario, the tunnel source is 10.1.1.1, which must be assigned to an up interface, and the router must have a route to 10.2.2.2. Without these conditions, the tunnel remains down regardless of the tunnel mode or IPv6 configuration.

Exam trap

The trap here is focusing on the tunnel mode or IPv6 addressing while overlooking that the tunnel source interface must be up and the destination must be reachable.

21
MCQmedium

An engineer configures a Cisco IOS router with two static routes to the 10.10.0.0/16 network: one via 192.168.1.1 with administrative distance 1, and another via 192.168.2.1 with administrative distance 200. The route via 192.168.1.1 is installed in the routing table. Later, the interface to 192.168.1.1 goes down. Which statement describes the router's behavior?

A.The router removes both static routes and sends an ICMP redirect to the source.
B.The router keeps the route via 192.168.1.1 in the routing table but marks it as unreachable.
C.The router load-balances traffic between the two next hops because both are configured.
D.The router immediately installs the route via 192.168.2.1 in the routing table.
AnswerD

When the interface for the primary static route fails, the route is removed from the routing table. The router then evaluates the floating static route, which has a higher administrative distance (200) but becomes the best available path. It is installed in the routing table, allowing traffic to use the backup path. This is the intended design of a floating static route for redundancy.

Why this answer

The primary static route via 192.168.1.1 with administrative distance 1 is preferred. When its interface goes down, the route is removed. The floating static route via 192.168.2.1, with administrative distance 200, becomes the best available path and is installed.

This provides redundancy without dynamic routing protocols.

Exam trap

The trap here is assuming that a higher administrative distance route is never used unless there is a failure, but forgetting that it will be used after the primary route is withdrawn.

22
MCQhard

A network architect is designing a BGP routing policy to influence inbound traffic from an ISP. The architect wants to make a specific prefix less preferred by the ISP by prepending the AS path multiple times. Which BGP attribute should be manipulated to achieve this?

A.LOCAL_PREF
B.MED
C.AS_PATH
D.NEXT_HOP
AnswerC

AS_PATH is a well-known mandatory attribute that lists the autonomous systems a route has traversed. By prepending additional AS numbers to the AS_PATH, the path length increases, making the route less preferred by BGP's best path selection process. This is a common method to influence inbound traffic, as the ISP will prefer shorter AS paths.

Why this answer

AS_PATH prepending is a technique where the local AS number is added multiple times to the AS_PATH attribute of a route advertised to external peers. This increases the path length, making the route less attractive to the receiving ISP, as BGP prefers shorter AS paths. This is a standard method for influencing inbound traffic in a multi-homed environment.

Exam trap

The trap here is confusing attributes used for inbound versus outbound traffic influence, or assuming MED is always effective for inbound traffic.

23
MCQmedium

A network engineer is implementing MPLS Layer 3 VPNs. The engineer wants to ensure that customer routes are propagated across the MPLS core. Which protocol is typically used within the provider core to distribute VPNv4 routes?

A.BGP
B.OSPF
C.LDP
D.EIGRP
AnswerA

Multiprotocol BGP (MP-BGP) is used to distribute VPNv4 routes across the MPLS core. It carries the VPNv4 address family and associated MPLS labels (route targets and route distinguishers). Provider edge routers establish iBGP sessions to exchange VPNv4 reachability information, enabling MPLS L3 VPNs.

Why this answer

In MPLS Layer 3 VPNs, Multiprotocol BGP (MP-BGP) is used to distribute VPNv4 routes between provider edge routers. MP-BGP carries the VPNv4 address family, which includes the route distinguisher and route target extended communities, along with MPLS labels. This allows the provider core to forward customer traffic based on labels.

Exam trap

The trap here is confusing the underlay routing protocol (which could be OSPF or EIGRP) with the protocol used for VPNv4 route distribution; MP-BGP is specifically designed for this purpose.

24
MCQeasy

A network technician is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The technician enters the following commands: interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 cisco After applying the configuration, the router does not form an adjacency with its neighbor. What is the most likely reason?

A.The neighbor router is not configured with the same MD5 key ID and key string.
B.The key string must be encrypted using the 'service password-encryption' command.
C.The 'ip ospf authentication message-digest' command must be configured globally, not on the interface.
D.The key ID must be the same on both routers, but the key string can differ.
AnswerA

OSPF MD5 authentication requires that both routers use the same key ID and identical key string on the interface. If the neighbor has a different key ID or key string, the MD5 digest will not match, and OSPF hellos will be rejected, preventing adjacency formation. The most common cause of failure after enabling MD5 is a mismatch in these parameters.

Why this answer

OSPF MD5 authentication requires that both neighbors use the same key ID and key string. When the technician configures MD5 on one router but the neighbor has not been configured with the identical key, the MD5 digest in OSPF hellos will not match, and the routers will not form an adjacency. The technician should verify the neighbor's configuration and ensure both key ID and key string match exactly.

Exam trap

The trap here is assuming that MD5 authentication only requires enabling it on one side, or that the key string can be different, when in fact both key ID and key string must match on both routers.

25
MCQhard

A network engineer is implementing route redistribution between OSPF and EIGRP on a Cisco IOS router. The engineer wants to prevent routing loops and ensure that routes redistributed from OSPF into EIGRP are not redistributed back into OSPF. Which mechanism should be used?

A.Set the administrative distance of EIGRP to a lower value than OSPF.
B.Use the default-metric command under the EIGRP process.
C.Apply a distribute-list to filter OSPF routes from being installed in the routing table.
D.Configure a route map with a tag on OSPF routes and deny tagged routes when redistributing EIGRP into OSPF.
AnswerD

Using route tags is a standard method to prevent feedback loops in mutual redistribution. By tagging routes when redistributing from OSPF into EIGRP, and then denying those tags when redistributing from EIGRP back into OSPF, you prevent the same routes from being reintroduced. This breaks the loop and is a scalable, deterministic solution.

Why this answer

Route tagging is the most effective way to prevent routing loops during mutual redistribution. By assigning a tag to routes when they are redistributed from one protocol into another, you can later match and deny those tagged routes when redistributing back. This ensures that routes do not oscillate between protocols, maintaining a loop-free topology.

Exam trap

The trap here is thinking that administrative distance or default metrics solve redistribution loops, when they only affect route selection or metric seeding, not the feedback of routes between protocols.

26
MCQhard

A network engineer is implementing MPLS Layer 3 VPN on a Cisco IOS-XE router. The engineer needs to configure the router to exchange VPNv4 routes with a route reflector. The router is already configured with BGP AS 65001 and has established an IBGP session with the route reflector. Which address family must be activated to support VPNv4 route exchange?

A.address-family ipv6 unicast
B.address-family ipv4 vrf
C.address-family ipv4 unicast
D.address-family vpnv4 unicast
AnswerD

The VPNv4 unicast address family is specifically designed to carry MPLS L3VPN routes with route distinguishers and extended communities. Activating it under the BGP configuration enables the exchange of VPNv4 prefixes with the route reflector. This is the correct address family for MPLS L3VPN route distribution.

Why this answer

MPLS L3VPN uses the VPNv4 address family to exchange labeled VPN routes between PE routers. The VPNv4 address family carries the route distinguisher and route target extended communities. Activating it under the BGP routing process on both the PE and route reflector is required.

Without it, VPNv4 prefixes are not propagated.

Exam trap

The trap here is confusing the IPv4 unicast address family with VPNv4; VPNv4 is a separate address family that must be explicitly activated for MPLS L3VPN route exchange.

27
MCQeasy

A network engineer is configuring a static route on a Cisco IOS router to reach the network 192.168.2.0/24 via the next-hop address 10.1.1.2. The engineer enters the command 'ip route 192.168.2.0 255.255.255.0 10.1.1.2'. However, the route does not appear in the routing table. What is the most likely reason?

A.The next-hop address 10.1.1.2 is not reachable.
B.The static route requires the 'permanent' keyword to be installed.
C.The subnet mask is incorrect; it should be 255.255.255.0.
D.The router needs a default route to install any static route.
AnswerA

For a static route to be installed in the routing table, the next-hop address must be reachable via a directly connected interface or another route. If 10.1.1.2 is not reachable, the static route remains inactive and does not appear in the routing table. This is a common issue when the next-hop is not on a directly connected subnet or lacks a route.

Why this answer

A static route is only installed in the routing table if its next-hop address is reachable. The next-hop 10.1.1.2 must be reachable via a directly connected interface or another route. If it is not reachable, the static route remains in the configuration but is not active.

The subnet mask is correct, and no special keywords are needed for basic installation. Thus, the most likely reason is that the next-hop is unreachable.

Exam trap

The trap here is assuming that a static route will always appear in the routing table once configured, ignoring next-hop reachability requirements.

28
Multi-Selecthard

A network engineer is configuring MPLS Layer 3 VPN on a Cisco IOS XR router. The engineer needs to ensure that customer routes are properly propagated across the MPLS core. Which two of the following are required to establish the VPNv4 peering between PE routers? (Choose two.)

Select 2 answers
A.Configure OSPF as the IGP for the MPLS core.
B.Enable BGP address-family vpnv4 unicast on the PE routers.
C.Enable LDP for label distribution on the core interfaces.
D.Enable BGP address-family ipv4 unicast for customer routes.
E.Configure a route reflector or full mesh of iBGP sessions between PE routers.
AnswersB, E

To exchange VPNv4 routes between PE routers, BGP must be configured with the VPNv4 address family. This allows the PE routers to carry customer routes with route distinguishers and route targets. Without enabling the VPNv4 address family, the PE routers cannot exchange VPN routing information, and MPLS L3VPN would not function.

Why this answer

To establish VPNv4 peering between PE routers, you must enable the BGP VPNv4 address family and have either a full mesh of iBGP sessions or a route reflector. These two elements allow the exchange of VPNv4 routes with route distinguishers and route targets, which are essential for MPLS L3VPN. LDP and IGP are for transport but not for VPNv4 peering itself.

Exam trap

The trap here is confusing the transport plane (LDP/IGP) with the control plane for VPNs (BGP VPNv4), and thinking that LDP or IGP is required for VPNv4 peering.

29
MCQeasy

A network technician is configuring a static route on a Cisco router. The technician wants to ensure that the static route is only used when the primary route is unavailable. Which type of static route should be configured?

A.Default static route
B.Floating static route
C.Summary static route
D.Recursive static route
AnswerB

A floating static route is a static route with an administrative distance higher than that of the primary route. It is used as a backup and only installed in the routing table when the primary route fails. This matches the requirement of using the static route only when the primary route is unavailable. Configuring a floating static route involves specifying a higher administrative distance than the dynamic routing protocol or the primary static route.

Why this answer

A floating static route is designed to be a backup by assigning it a higher administrative distance than the primary route. When the primary route is present, the floating static route is not installed in the routing table. If the primary route fails, the floating static route becomes active.

This behavior precisely matches the requirement of using the static route only when the primary route is unavailable.

Exam trap

The trap here is confusing a default static route with a floating static route, as both can act as backups, but only the floating static route uses administrative distance to remain inactive until the primary fails.

30
MCQmedium

A network engineer is configuring a Cisco IOS XE router as a DHCP relay agent. The router is connected to a LAN segment with DHCP clients and must forward DHCP requests to a DHCP server at 10.1.1.100. Which command must be configured on the LAN interface to enable DHCP relay?

A.ip helper-address 10.1.1.100
B.ip dhcp pool 10.1.1.100
C.ip forward-protocol udp 67
D.ip dhcp relay 10.1.1.100
AnswerA

The ip helper-address command is used on an interface to forward UDP broadcasts, including DHCP requests, to a specified server. Configuring it with the DHCP server's IP address enables the router to relay DHCP requests from clients on that interface to the server. This is the correct command to enable DHCP relay functionality on the LAN interface.

Why this answer

To enable DHCP relay on a Cisco IOS XE router, the engineer must configure the ip helper-address command on the interface facing the DHCP clients, specifying the DHCP server's IP address. This command causes the router to forward DHCP broadcast requests as unicast packets to the server. The other options are either invalid commands or serve different purposes, such as configuring a DHCP server or modifying forwarded protocols.

Exam trap

The trap here is confusing the command to configure a DHCP server with the command to relay DHCP requests to an external server.

31
Multi-Selectmedium

A network engineer is configuring policy-based routing (PBR) on a Cisco router. The router has two interfaces: GigabitEthernet0/0 (LAN) and GigabitEthernet0/1 (WAN). The engineer wants to route traffic from the 192.168.1.0/24 subnet to a next-hop of 10.1.1.2, and all other traffic should follow the default routing table. Which two steps are required to implement this? (Choose two.)

Select 2 answers
A.Apply the route map to the GigabitEthernet0/0 interface using the ip policy route-map command.
B.Configure a default route pointing to 10.1.1.2.
C.Create a route map that matches the source subnet 192.168.1.0/24 and sets the next-hop to 10.1.1.2.
D.Create an ACL that permits traffic from 192.168.1.0/24 and apply it to the GigabitEthernet0/0 interface inbound.
E.Enable PBR globally using the ip policy route-map command in global configuration mode.
AnswersA, C

PBR is applied to the interface where traffic enters the router. In this scenario, traffic from the 192.168.1.0/24 subnet arrives on GigabitEthernet0/0 (LAN). Therefore, you must apply the route map to that interface using the ip policy route-map command in interface configuration mode. This activates PBR for incoming packets on that interface, allowing the route map to be evaluated.

Why this answer

To implement PBR, you must define a route map that matches the traffic (using an ACL) and sets the next-hop. Then, you apply that route map to the ingress interface using the ip policy route-map command. The other options are incorrect: a default route would affect all traffic, PBR is not enabled globally, and applying an ACL directly to the interface would filter rather than route.

Exam trap

The trap here is confusing PBR with ACL filtering or default routing, and forgetting that PBR must be applied to the ingress interface.

32
MCQmedium

A network engineer is configuring OSPF on a router. The router has an interface with IP address 10.1.1.1/24 and another interface with IP address 192.168.1.1/24. The engineer wants to enable OSPF on both interfaces using a single network command under router ospf 1. Which command accomplishes this?

A.network 10.0.0.0 0.255.255.255 area 0
B.network 0.0.0.0 255.255.255.255 area 0
C.network 10.1.1.0 0.0.0.255 area 0 and network 192.168.1.0 0.0.0.255 area 0
D.network 10.1.1.0 0.0.0.255 area 0
AnswerB

This command uses a wildcard mask of 255.255.255.255, which matches any IP address. It enables OSPF on all interfaces of the router, including both the 10.1.1.1/24 and 192.168.1.1/24 interfaces, achieving the goal with a single network statement.

Why this answer

The network command in OSPF uses a wildcard mask to match interface IP addresses. To enable OSPF on all interfaces with one command, use network 0.0.0.0 255.255.255.255 area 0, which matches any IP address. This activates OSPF on both the 10.1.1.1/24 and 192.168.1.1/24 interfaces, satisfying the requirement.

Exam trap

The trap here is assuming that a network command with a wildcard mask must match the subnet exactly, but a wildcard mask of 255.255.255.255 matches all addresses regardless of subnet.

33
MCQeasy

A network engineer is configuring a static route on a Cisco IOS router. The engineer wants the route to be used only if the primary route fails. Which command should be used to configure a floating static route?

A.ip route 0.0.0.0 0.0.0.0 192.168.1.1 200
B.ip route 0.0.0.0 0.0.0.0 192.168.1.1 track 1
C.ip route 0.0.0.0 0.0.0.0 192.168.1.1 name BACKUP
D.ip route 0.0.0.0 0.0.0.0 192.168.1.1 permanent
AnswerA

A floating static route is configured with an administrative distance higher than that of the primary route. The command `ip route 0.0.0.0 0.0.0.0 192.168.1.1 200` sets the administrative distance to 200, which is higher than the default administrative distance of most dynamic routing protocols (e.g., OSPF is 110, EIGRP is 90). This ensures the static route is only used if the primary route is not in the routing table.

Why this answer

A floating static route is a static route with an administrative distance higher than the primary route, so it is only installed in the routing table when the primary route is unavailable. The command `ip route 0.0.0.0 0.0.0.0 192.168.1.1 200` sets the administrative distance to 200, making it less preferred than dynamic routes. This is the standard method to configure a floating static route.

Exam trap

The trap here is confusing the `permanent` or `track` keywords with floating static routes, when the key is administrative distance.

34
Multi-Selecthard

A network administrator is troubleshooting a DMVPN Phase 3 network using OSPF as the routing protocol. Spoke routers are not learning routes from other spokes. Which two actions should be taken to resolve this issue? (Choose two.)

Select 2 answers
A.Configure the hub as a route reflector for BGP.
B.Configure the spoke routers with 'ip nhrp shortcut' on their tunnel interfaces.
C.Ensure that the hub router is configured with 'ip nhrp redirect' on its tunnel interface.
D.Disable split horizon on the hub's tunnel interface.
E.Change the OSPF network type to point-to-multipoint on all routers.
AnswersB, C

On spoke routers in DMVPN Phase 3, 'ip nhrp shortcut' allows them to install shortcut routes to other spokes based on NHRP redirect messages from the hub. Without this, spokes will not create direct tunnels and will continue to send traffic through the hub. This command is necessary for the spokes to dynamically learn the NBMA addresses of other spokes and establish direct connections. It is a key component of Phase 3 operation.

Why this answer

In DMVPN Phase 3, spoke-to-spoke communication requires the hub to send NHRP redirect messages and the spokes to support NHRP shortcuts. The hub must have 'ip nhrp redirect' configured, and each spoke must have 'ip nhrp shortcut' configured. These commands enable the spokes to dynamically discover and establish direct tunnels to other spokes, bypassing the hub.

Without them, spokes will not learn the specific routes to other spokes and will continue to route traffic through the hub, which is inefficient.

Exam trap

The trap here is confusing DMVPN Phase 3 with other phases or protocols, and assuming that OSPF network type changes or split horizon adjustments are needed, when the core issue is NHRP redirect and shortcut configuration.

35
MCQhard

A network engineer is configuring a Cisco IOS XE router for MPLS Layer 3 VPN. The router is a PE connected to a CE via GigabitEthernet0/0. The engineer wants to configure a VRF named CUSTOMER_A and assign the interface to it. The engineer enters the following commands: `vrf definition CUSTOMER_A`, `rd 65000:1`, `address-family ipv4`, `exit`, `exit`. Then, under interface GigabitEthernet0/0, the engineer enters `vrf forwarding CUSTOMER_A`. After entering the command, the engineer notices that the IP address on the interface is removed. What is the most likely reason?

A.The VRF definition must include `address-family ipv4` before the interface can be assigned, and the missing address-family caused the IP removal.
B.The interface must be shut down before assigning it to a VRF, otherwise the IP address is cleared.
C.The VRF definition is missing the `route-target export` and `route-target import` commands.
D.The `vrf forwarding` command removes the IP address because the interface must be reconfigured with an IP address within the VRF.
AnswerD

When you assign an interface to a VRF using `vrf forwarding`, Cisco IOS removes any existing IP address configuration. This is expected behavior because the interface's IP address must be unique within the VRF's routing table. The engineer must re-enter the IP address after assigning the VRF. This is a common operational step that often surprises engineers.

Why this answer

Assigning an interface to a VRF with `vrf forwarding` removes the existing IP address. This is by design because the interface's IP address must be unique within the VRF. The engineer must reconfigure the IP address after the VRF assignment.

The other options describe unrelated VRF configuration steps or incorrect requirements.

Exam trap

The trap here is assuming that the IP address removal indicates a configuration error, when it is actually expected behavior when assigning an interface to a VRF.

36
MCQhard

A network administrator is troubleshooting an EIGRP adjacency that is stuck in the ACTIVE state. The adjacency is between two routers, R1 and R2, on a point-to-point link. The administrator notices that R1 is sending queries but not receiving replies. Which of the following is the most likely cause?

A.A stuck-in-active condition is caused by a router not receiving replies to its queries, often due to a unidirectional link or a neighbor that is unable to respond.
B.The autonomous system number is misconfigured on R1.
C.An access list is blocking EIGRP multicast packets on R2's interface.
D.The K values for EIGRP metric calculation are mismatched between R1 and R2.
AnswerA

The ACTIVE state in EIGRP indicates that a route has been lost and the router is actively querying its neighbors for an alternative path. If replies are not received within the active timer (default 3 minutes), the route becomes stuck-in-active. Common causes include unidirectional links, packet loss, or a neighbor that is too busy to respond. In this scenario, R1 is sending queries but not receiving replies, which aligns with a unidirectional link or a neighbor issue.

Why this answer

EIGRP routers enter the ACTIVE state when they lose a route and must query neighbors for an alternative path. If a neighbor does not respond to queries, the route can become stuck-in-active. This is often due to unidirectional link failures, high CPU on the neighbor, or packet filters that allow hellos but block other EIGRP packets.

The symptom of queries being sent but no replies received points directly to a communication issue in one direction.

Exam trap

The trap here is assuming that any EIGRP adjacency issue is due to mismatched parameters like AS number or K values, but those would prevent adjacency formation, not cause a stuck-in-active state.

37
Multi-Selecthard

A network administrator is troubleshooting a DMVPN Phase 3 deployment using mGRE and IPsec. Spoke-to-spoke communication is not working directly; traffic is flowing through the hub. The administrator verifies that NHRP registrations are successful and that the hub has a route to all spokes. Which two actions are required to enable direct spoke-to-spoke communication? (Choose two.)

Select 2 answers
A.Configure 'ip nhrp network-id' on all tunnel interfaces.
B.Configure 'ip nhrp shortcut' on the spoke tunnel interfaces.
C.Configure 'ip nhrp redirect' on the hub tunnel interface.
D.Configure 'ip nhrp shortcut' on the hub tunnel interface.
E.Configure 'ip nhrp map' entries for all remote spokes on each spoke.
AnswersB, C

On spoke routers in DMVPN Phase 3, 'ip nhrp shortcut' must be enabled to allow the spoke to install a shortcut route to the destination spoke when it receives an NHRP redirect from the hub. This command enables the spoke to override its default routing and send traffic directly to the destination spoke's NBMA address. Without it, the spoke ignores the redirect and continues to forward traffic through the hub.

Why this answer

DMVPN Phase 3 requires 'ip nhrp redirect' on the hub and 'ip nhrp shortcut' on the spokes to enable direct spoke-to-spoke tunnels. The hub uses redirect to inform the originating spoke of a better path, and the spoke uses shortcut to act on that information and establish a direct tunnel to the destination spoke. Without both, traffic continues to flow through the hub.

Exam trap

The trap here is confusing where to place 'ip nhrp shortcut' and 'ip nhrp redirect'; the redirect goes on the hub, while the shortcut goes on the spokes.

38
MCQeasy

Which command correctly configures a static route on a Cisco IOS router to reach the network 172.16.0.0/16 via the next-hop address 10.1.1.1?

A.ip route 172.16.0.0 255.255.0.0 interface GigabitEthernet0/0
B.ip route 172.16.0.0 255.255.255.0 10.1.1.1
C.ip route 172.16.0.0/16 10.1.1.1
D.ip route 172.16.0.0 255.255.0.0 10.1.1.1
AnswerD

This command uses the correct syntax for a static route: 'ip route' followed by the destination network, subnet mask, and next-hop address. The subnet mask 255.255.0.0 corresponds to a /16 prefix length, matching the 172.16.0.0/16 network. This is the standard way to configure an IPv4 static route on Cisco IOS.

Why this answer

The correct command is 'ip route 172.16.0.0 255.255.0.0 10.1.1.1'. It specifies the destination network with the proper subnet mask and the next-hop address. Cisco IOS requires the subnet mask in dotted-decimal format, not CIDR notation, and the next-hop address must be provided for a route via a next-hop.

Exam trap

The trap here is using CIDR notation or the wrong subnet mask, which are common mistakes when configuring static routes on Cisco IOS.

39
MCQhard

A network administrator is troubleshooting a route redistribution issue on a Cisco router running both EIGRP and OSPF. The router is redistributing EIGRP routes into OSPF, but the routes are not appearing in the OSPF domain. The administrator has configured redistribution with a seed metric of 20. Which additional configuration is required to ensure the routes are advertised?

A.Set the metric-type to 1 under the redistribute command.
B.Enable OSPF on the interface connecting to the EIGRP domain.
C.Configure a route map to match the EIGRP routes.
D.Configure the subnets keyword under the redistribute command.
AnswerD

When redistributing routes into OSPF, the subnets keyword is required to include subnetted routes. Without it, only classful networks are redistributed, so routes with subnet masks are not advertised. Since the scenario involves redistributing EIGRP routes, which are often subnetted, the subnets keyword ensures they are included in OSPF LSAs.

Why this answer

The subnets keyword is necessary when redistributing routes into OSPF to include subnetted routes. Without it, only classful networks are redistributed, which is why the EIGRP routes are missing. The seed metric alone does not ensure subnetted routes are advertised.

Metric-type and route maps are unrelated to this requirement.

Exam trap

The trap here is assuming that setting a seed metric is sufficient for redistribution, overlooking the need for the subnets keyword to handle subnetted routes.

40
MCQhard

A network engineer is troubleshooting a DMVPN Phase 3 network using EIGRP as the routing protocol. Spoke routers are unable to establish direct spoke-to-spoke tunnels. The engineer verifies that NHRP registration is successful and that the hub has routes to all spokes. Which action is most likely to resolve the issue?

A.Ensure that the tunnel interfaces on all routers are configured with the same tunnel key.
B.Verify that the hub is configured with ip nhrp redirect and the spokes with ip nhrp shortcut.
C.Change the EIGRP network type on the tunnel interfaces to point-to-multipoint.
D.Configure EIGRP stub routing on the spoke routers.
AnswerB

In DMVPN Phase 3, the hub must have ip nhrp redirect to inform spokes of a better path, and spokes must have ip nhrp shortcut to install shortcut routes. Without these, spoke-to-spoke tunnels will not be established. This is a common misconfiguration that prevents direct spoke communication.

Why this answer

In DMVPN Phase 3, spoke-to-spoke tunnels require ip nhrp redirect on the hub and ip nhrp shortcut on the spokes. These commands allow the hub to redirect traffic and the spokes to create shortcut routes. Without them, spokes will continue to route through the hub, even if NHRP registration is successful.

Exam trap

The trap here is focusing on EIGRP or tunnel configuration when the issue is actually NHRP Phase 3 specific commands.

41
MCQmedium

A network engineer is configuring EIGRP on a Cisco router. The router has two paths to the same destination network with different metrics. The engineer wants to enable unequal-cost load balancing. Which command must be configured to allow EIGRP to use the higher-cost path?

A.traffic-share balanced
B.metric weights 0 1 1 1 1 1
C.variance 2
D.maximum-paths 2
AnswerC

The 'variance' command under the EIGRP routing process enables unequal-cost load balancing. The value (multiplier) determines which feasible successor routes can be used. A variance of 2 means that any feasible successor with a metric up to twice the successor's metric will be used for load balancing. This allows the higher-cost path to be utilized.

Why this answer

The 'variance' command is required to enable unequal-cost load balancing in EIGRP. It sets a multiplier that determines which feasible successor routes, with metrics higher than the successor, can be used. The higher-cost path must also be a feasible successor (satisfy the feasibility condition) to be considered.

Once variance is set, EIGRP can install multiple paths with different metrics.

Exam trap

The trap here is confusing maximum-paths with variance; maximum-paths only affects equal-cost paths, while variance is needed for unequal-cost load balancing.

42
MCQhard

A network engineer is implementing MPLS Layer 3 VPNs. The engineer needs to configure a PE router to exchange VPNv4 routes with other PE routers. Which BGP configuration is required to enable the exchange of VPNv4 routes?

A.address-family vpnv4
B.address-family ipv6 unicast
C.address-family ipv4 unicast
D.address-family ipv4 vrf CUSTOMER
AnswerA

The address-family vpnv4 command is used to enter the VPNv4 address family configuration mode. Within this mode, you can activate BGP neighbors to exchange VPNv4 routes. This is required for PE routers to exchange VPNv4 prefixes, which include the route distinguisher and VPN label. Without this address family, PE routers cannot exchange VPN routing information.

Why this answer

In MPLS Layer 3 VPNs, PE routers use Multiprotocol BGP (MP-BGP) to exchange VPNv4 routes. The VPNv4 address family is specifically designed for this purpose. Configuring address-family vpnv4 and activating neighbors under it enables the exchange of VPNv4 prefixes, which include the route distinguisher and label information.

Other address families like ipv4 unicast or ipv4 vrf are used for different purposes.

Exam trap

The trap here is confusing the VRF address family with the VPNv4 address family, and thinking that configuring the VRF address family enables VPNv4 route exchange.

43
MCQhard

A network engineer is troubleshooting a DMVPN Phase 3 network using Cisco IOS XE routers. Spoke routers are unable to establish direct spoke-to-spoke tunnels. The hub router is configured with 'ip nhrp redirect', and spokes are configured with 'ip nhrp shortcut'. The engineer notices that spoke routers are not receiving NHRP redirect messages from the hub. Which action should be taken to resolve this issue?

A.Configure 'ip nhrp map multicast dynamic' on the spoke routers.
B.Enable 'ip nhrp shortcut' on the hub router.
C.Change the tunnel mode from GRE multipoint to GRE point-to-point.
D.Ensure that the hub router has a route to the spoke networks and that NHRP resolution is working.
AnswerD

For the hub to send NHRP redirect messages, it must have a route to the destination spoke network and be able to perform NHRP resolution. If the hub lacks a route or NHRP resolution fails, it cannot generate redirects. The engineer should verify that the hub has routes to all spoke networks, that NHRP entries are correct, and that the hub can resolve spoke NBMA addresses. This is a common cause of missing redirects in DMVPN Phase 3.

Why this answer

In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to inform spokes of a better path to a destination. For the hub to send redirects, it must have a route to the destination network and be able to resolve the destination's NBMA address via NHRP. If the hub lacks a route or NHRP resolution fails, no redirects are sent, and spokes cannot establish direct tunnels.

Verifying hub routing and NHRP operation is essential for troubleshooting this issue.

Exam trap

The trap here is assuming that enabling 'ip nhrp shortcut' on the hub is necessary, when it is actually a spoke-side command.

44
MCQmedium

A network engineer is configuring OSPFv3 on a Cisco router. The router has two interfaces in Area 0: GigabitEthernet0/0 (IPv6 address 2001:db8:1::1/64) and GigabitEthernet0/1 (IPv6 address 2001:db8:2::1/64). After enabling IPv6 unicast routing and configuring OSPFv3 with the router-id 1.1.1.1, the engineer notices that no OSPFv3 neighbors are forming. Which action is most likely to resolve the issue?

A.Assign IPv6 addresses from the same subnet to both interfaces.
B.Enable OSPFv3 on the interfaces using the ipv6 ospf 1 area 0 command.
C.Set the OSPFv3 network type to point-to-point on both interfaces.
D.Configure a 64-bit router ID using the router-id command under the OSPFv3 process.
AnswerB

OSPFv3 is enabled per interface, unlike OSPFv2 which can be enabled under router configuration. Without the ipv6 ospf 1 area 0 interface command, the interfaces do not participate in OSPFv3, so no hellos are sent or received. This command activates OSPFv3 on the interface and associates it with Area 0. Thus, neighbors will form once the interfaces are enabled.

Why this answer

OSPFv3 requires enabling the protocol on each interface using the ipv6 ospf process-id area area-id command. Without this, the interface does not participate in OSPFv3, and no hellos are sent or received. The router ID and network type are secondary.

Assigning IPv6 addresses from the same subnet is irrelevant because OSPFv3 uses link-local addresses for neighbor discovery.

Exam trap

The trap here is assuming that OSPFv3 is enabled globally under router configuration like OSPFv2, when in fact it must be enabled per interface.

45
MCQmedium

A network engineer is configuring Policy-Based Routing (PBR) on a Cisco router. The goal is to forward all HTTP traffic (TCP port 80) from the 10.1.1.0/24 subnet to next-hop 192.168.2.1. Which configuration sequence is correct?

A.Create a route-map with a match statement for TCP port 80 and a set statement for next-hop 192.168.2.1, then apply it globally with the ip policy route-map command.
B.Create a standard ACL that permits 10.1.1.0/24, reference it in a route-map with a match ip address statement, set the next-hop to 192.168.2.1, and apply the route-map to the outgoing interface with the ip policy route-map command.
C.Create a route-map with a match statement for IP address 10.1.1.0/24 and a set statement for next-hop 192.168.2.1, then apply it to the incoming interface with the ip policy route-map command.
D.Create an extended ACL that permits TCP port 80 from 10.1.1.0/24 to any, reference it in a route-map with a match ip address statement, set the next-hop to 192.168.2.1, and apply the route-map to the incoming interface with the ip policy route-map command.
AnswerD

This sequence correctly identifies HTTP traffic using an extended ACL, matches it in a route-map, sets the next-hop, and applies the route-map to the incoming interface. PBR uses route-maps with match statements based on ACLs to classify traffic, and the ip policy route-map command enables PBR on the interface. This meets the requirement precisely.

Why this answer

PBR requires an ACL to classify traffic based on source, destination, and port. An extended ACL can match TCP port 80. The route-map then matches the ACL and sets the next-hop.

Finally, the route-map is applied to the incoming interface with the ip policy route-map command. The other options either match all traffic, use a standard ACL that cannot match ports, or attempt to match ports directly in a route-map, which is not supported.

Exam trap

The trap here is using a standard ACL or trying to match ports directly in a route-map; PBR requires an extended ACL to match port numbers, and it is applied inbound on the interface.

46
MCQhard

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS router. The engineer wants to route traffic from subnet 10.1.1.0/24 to a specific next-hop 192.168.1.1, while all other traffic uses the default route. The engineer configures a route map named PBR with a match statement for the subnet and a set statement for the next-hop, and applies it to the inbound interface of the subnet. However, traffic from 10.1.1.0/24 is still following the default route. What is the most likely reason?

A.The next-hop 192.168.1.1 is not reachable, so PBR is ignored.
B.The route map must be applied to the outbound interface instead of the inbound interface.
C.The route map is missing a 'permit' statement, causing all traffic to be denied.
D.The 'ip policy route-map' command is missing on the interface.
AnswerD

To enable PBR, the route map must be applied to the interface using the 'ip policy route-map' command. Without this command, the route map is not used, and traffic follows the normal routing table. The engineer configured the route map but may have forgotten to apply it to the interface, which is a common oversight.

Why this answer

Policy-based routing requires the route map to be applied to an interface using the 'ip policy route-map' command. Without this command, the route map is not evaluated, and traffic follows the standard routing table. The engineer created the route map but likely did not apply it to the interface.

Applying it to the inbound interface is correct for matching traffic from the subnet. The next-hop reachability is important but not the primary cause if PBR is not enabled.

Exam trap

The trap here is assuming that simply creating a route map is enough; it must be explicitly applied to an interface with 'ip policy route-map'.

47
MCQmedium

A network engineer is deploying MPLS Layer 3 VPNs. The engineer must ensure that the PE routers can forward VPN traffic correctly. The following configuration is applied on a PE router: ip vrf CUSTOMER rd 65000:1 route-target export 65000:1 route-target import 65000:1 ! interface GigabitEthernet0/1 ip vrf forwarding CUSTOMER ip address 192.168.1.1 255.255.255.0 After configuration, the engineer notices that the CE router cannot reach remote sites. The MPLS core is operational, and MP-BGP is configured. What is the most likely missing configuration?

A.The route-target must be configured under the interface GigabitEthernet0/1.
B.The PE router must have a route distinguisher configured under the BGP process.
C.The PE router must have a loopback interface configured and used for BGP peering.
D.The BGP process must be configured with address-family ipv4 vrf CUSTOMER and the necessary redistribution or network statements.
AnswerD

For MPLS L3 VPN, the PE router must have a BGP address-family for each VRF to exchange routes with other PEs. Without address-family ipv4 vrf CUSTOMER, the PE will not advertise or receive VPN routes for that customer, preventing connectivity. The VRF configuration alone is insufficient.

Why this answer

In MPLS L3 VPN, the PE router must have a BGP address-family ipv4 vrf for each VRF to exchange VPN routes with other PE routers. The VRF definition and interface assignment are necessary but not sufficient. Without the address-family configuration and route redistribution or network statements, the PE will not advertise the customer routes, and remote sites will be unreachable.

Exam trap

The trap here is focusing on the VRF and interface configuration while overlooking the need for a BGP address-family per VRF to exchange VPN routes.

48
MCQeasy

A network technician is configuring a Cisco router to forward traffic to a remote network. The technician enters the command 'ip route 172.16.0.0 255.255.0.0 10.0.0.1'. However, the router does not install the route in its routing table. What is the most likely reason?

A.The administrative distance of the static route is too high.
B.The subnet mask is incorrect.
C.The static route is missing the 'permanent' keyword.
D.The next-hop address 10.0.0.1 is not reachable.
AnswerD

For a static route to be installed in the routing table, the next-hop address must be reachable via a valid route. If 10.0.0.1 is not reachable, the static route remains in the configuration but is not installed. This is a common issue when the next-hop is not directly connected or no route to it exists.

Why this answer

A static route is only installed in the routing table if its next-hop address is reachable. If the next-hop 10.0.0.1 is not reachable (e.g., no route to it, or interface down), the route will not be installed. The default administrative distance is low, the mask is correct, and the 'permanent' keyword is not required for installation.

Therefore, the most likely cause is an unreachable next-hop.

Exam trap

The trap here is assuming that a static route is always installed regardless of next-hop reachability, when in fact the router must have a valid path to the next-hop.

49
Multi-Selectmedium

A network engineer is configuring EIGRP on a Cisco IOS XE router. The router is connected to two different autonomous systems: AS 100 and AS 200. The engineer wants to redistribute routes from AS 100 into AS 200. Which two statements are true regarding EIGRP redistribution? (Choose two.)

Select 2 answers
A.A seed metric must be specified using the `default-metric` command or in the redistribute statement.
B.The `redistribute eigrp 100` command must be configured under router eigrp 200.
C.The `redistribute eigrp 100` command must be configured under router eigrp 100.
D.Redistribution between different EIGRP autonomous systems requires the `redistribute connected` command.
E.The `default-metric` command is optional and only needed for OSPF redistribution.
AnswersA, B

When redistributing routes into EIGRP, a seed metric is required because EIGRP uses a composite metric (bandwidth, delay, load, reliability, MTU). If no seed metric is provided, the routes will not be redistributed. You can specify the metric in the `redistribute` command using the `metric` keyword or set a default metric with the `default-metric` command under the EIGRP process.

Why this answer

To redistribute routes from EIGRP AS 100 into EIGRP AS 200, you must configure the `redistribute eigrp 100` command under the EIGRP AS 200 process. Additionally, a seed metric must be provided, either within the redistribute command or via the `default-metric` command, because EIGRP requires specific metric parameters. Without these, redistribution will not occur.

Exam trap

The trap here is confusing the direction of redistribution; the command must be placed under the target EIGRP process, not the source, and a seed metric is mandatory.

50
MCQmedium

A network engineer is configuring a route map for BGP policy. The engineer wants to match routes that originate from AS 65001 and have a community value of 100:200. The route map should then set the local preference to 200. Which configuration snippet accomplishes this?

A.ip as-path access-list 1 permit ^65001$ route-map POLICY permit 10 match as-path 1 set local-preference 200
B.route-map POLICY permit 10 match as-path 1 match community 1 set local-preference 200
C.ip as-path access-list 1 permit ^65001$ ip community-list standard 1 permit 100:200 route-map POLICY permit 10 match as-path 1 match community 1 set local-preference 200
D.ip community-list standard 1 permit 100:200 route-map POLICY permit 10 match community 1 set local-preference 200
AnswerC

This configuration defines an AS-path access list to match routes originating from AS 65001 (using the regular expression ^65001$) and a community list to match the community 100:200. The route map then matches both conditions and sets the local preference to 200. This fully satisfies the requirement.

Why this answer

To match routes from AS 65001 with community 100:200 and set local preference, the configuration must include both an AS-path access list and a community list, and apply both matches in the route map. The correct snippet defines the AS-path access list with the regex ^65001$ to match routes originated in AS 65001, defines a standard community list to match 100:200, and then uses both in the route map with the set clause.

Exam trap

The trap here is forgetting to define the community list or the AS-path access list, or using a regex that matches AS 65001 anywhere in the path rather than as the origin.

51
MCQhard

A network administrator is troubleshooting an OSPFv3 network. Routers R1 and R2 are in the same area and on the same broadcast segment, but they are not forming an adjacency. The administrator verifies that the interfaces are up and IPv6 addresses are configured correctly. Which command should be used to check if OSPFv3 is enabled on the interfaces?

A.show ipv6 protocols
B.show ipv6 ospf neighbor
C.show ipv6 ospf interface
D.show ipv6 ospf database
AnswerC

The command 'show ipv6 ospf interface' displays OSPFv3 interface status, including whether OSPFv3 is enabled on the interface, the area ID, and the state. If OSPFv3 is not enabled, the interface will not appear or will show as passive. This directly answers the question of whether OSPFv3 is enabled on the interfaces.

Why this answer

To verify OSPFv3 interface configuration, the 'show ipv6 ospf interface' command is used. It shows whether OSPFv3 is enabled on the interface, the area, network type, and other parameters. This is the most direct way to confirm OSPFv3 is active on the interfaces.

Exam trap

The trap here is confusing neighbor state with interface configuration; a missing neighbor does not necessarily mean OSPFv3 is not enabled, but checking the interface status is the first step.

52
MCQhard

A network administrator is troubleshooting an EIGRP network where a router is not receiving all expected routes from a neighbor. The neighbor relationship is established, and the topology table shows only a subset of routes. Which EIGRP feature could be filtering the routes?

A.EIGRP route filtering using distribute-list
B.EIGRP variance
C.EIGRP authentication mismatch
D.EIGRP stub routing
AnswerA

A distribute-list can filter incoming or outgoing EIGRP routes. If applied inbound on the local router, it can prevent specific routes from being installed in the topology table. This matches the symptom of missing routes despite an established neighbor relationship. The distribute-list can reference an ACL or prefix-list to selectively filter routes based on network numbers or masks.

Why this answer

EIGRP distribute-lists can filter routes either inbound or outbound. An inbound distribute-list applied on the local router can prevent specific routes from entering the topology table, even though the neighbor adjacency is up. This is a common cause of missing routes when the neighbor relationship is healthy.

The distribute-list can use ACLs, prefix-lists, or route-maps to match and filter routes.

Exam trap

The trap here is confusing route filtering with neighbor adjacency issues; a distribute-list can silently drop routes without affecting the neighbor relationship.

53
MCQmedium

A network engineer is configuring Policy-Based Routing (PBR) on a Cisco IOS-XE router. The engineer wants to route traffic from the 10.1.1.0/24 subnet that is destined for any TCP port 80 to next-hop 192.168.2.1, but only for packets arriving on GigabitEthernet0/1. Other traffic should follow the normal routing table. Which configuration sequence correctly accomplishes this?

A.Create a route-map with a match statement for IP address 10.1.1.0/24 and a set statement for interface GigabitEthernet0/2, then apply it globally with the ip local policy route-map command.
B.Create a standard ACL that permits 10.1.1.0 0.0.0.255, reference it in a route-map match statement, set the next-hop to 192.168.2.1, and apply the route-map to interface GigabitEthernet0/1 with the ip policy route-map command.
C.Create a route-map with a match statement for IP address 10.1.1.0/24 and a set statement for next-hop 192.168.2.1, then apply it to interface GigabitEthernet0/1 using the ip policy route-map command.
D.Create an extended ACL that permits tcp 10.1.1.0 0.0.0.255 any eq 80, reference it in a route-map match statement, set the next-hop to 192.168.2.1, and apply the route-map to interface GigabitEthernet0/1 with the ip policy route-map command.
AnswerD

This correctly matches the source subnet and HTTP destination port using an extended ACL, then sets the next-hop for matching packets. Applying the route-map inbound on GigabitEthernet0/1 ensures only traffic arriving on that interface is policy-routed. This meets all conditions: specific source, specific destination port, and interface restriction.

Why this answer

The correct configuration uses an extended ACL to match both source subnet and destination TCP port 80, references it in a route-map, sets the next-hop, and applies the route-map inbound on the specified interface. This ensures only HTTP traffic from 10.1.1.0/24 arriving on GigabitEthernet0/1 is policy-routed, while other traffic follows normal routing.

Exam trap

The trap here is confusing standard and extended ACLs for matching in route-maps, or applying PBR globally instead of on the ingress interface.

54
MCQhard

A network engineer is troubleshooting a BGP routing issue on a Cisco IOS XE router. The router is configured with a route map that sets the local preference for routes learned from a specific neighbor. However, the engineer notices that the local preference is not being applied to routes received from that neighbor. Which BGP configuration command is most likely missing?

A.neighbor 10.1.1.1 route-map LOCAL-PREF in
B.bgp default local-preference 200
C.neighbor 10.1.1.1 send-community
D.neighbor 10.1.1.1 soft-reconfiguration inbound
AnswerA

The neighbor route-map command applies the route map to routes learned from the specified neighbor. For local preference to be set on inbound routes, the route map must be applied in the inbound direction using the in keyword. Without this command, the route map is not applied to incoming updates, so local preference remains at its default value of 100. This is the most likely missing configuration.

Why this answer

To set local preference on routes learned from a specific BGP neighbor, a route map must be created that sets the local preference and then applied to that neighbor in the inbound direction. The correct command is neighbor <ip> route-map <name> in. Without this, the route map is not applied, and local preference remains at the default value.

Exam trap

The trap here is assuming that creating a route map is sufficient; the route map must be explicitly applied to the neighbor in the correct direction.

55
MCQhard

A network engineer is troubleshooting a Cisco IOS XE router that is configured with a route map for policy-based routing (PBR). The route map is applied to the ingress interface with `ip policy route-map PBR`. The engineer wants to verify that the PBR is matching traffic and setting the next-hop correctly. Which command provides the most detailed information about PBR matches and actions?

A.show route-map PBR
B.debug ip policy
C.show ip policy
D.show ip route
AnswerB

The `debug ip policy` command provides real-time detailed output about PBR processing, including which route map sequence is matched, the packet's source and destination, and the resulting action such as setting the next-hop or interface. It is the most detailed troubleshooting tool for PBR, showing exactly how packets are handled. However, it can be CPU-intensive and should be used with caution in production.

Why this answer

For detailed PBR troubleshooting, `debug ip policy` is the most informative command. It logs each packet's match against route map sequences and shows the set actions applied, such as next-hop or interface. While `show route-map` provides configuration and some counters, it lacks the per-packet detail. `show ip policy` only confirms attachment.

Thus, the debug command is the correct choice for verifying matches and next-hop settings.

Exam trap

The trap here is assuming that `show route-map` displays full PBR match and action details, when it only shows configuration and basic counters.

56
MCQmedium

A network engineer is configuring OSPF on a router with three interfaces: GigabitEthernet0/0 (10.1.1.1/24), GigabitEthernet0/1 (10.2.2.1/24), and Loopback0 (192.168.1.1/24). The engineer wants to ensure that the router ID is 192.168.1.1 and that it remains stable even if the Loopback0 interface flaps. Which command should be applied?

A.interface GigabitEthernet0/0 ip ospf priority 1
B.interface Loopback0 ip ospf 1 area 0
C.router ospf 1 router-id 192.168.1.1
D.router ospf 1 network 192.168.1.0 0.0.0.255 area 0
AnswerC

The router-id command under router ospf explicitly sets the OSPF router ID to 192.168.1.1. This value is used regardless of interface status, so the router ID remains stable even if Loopback0 flaps. Without this command, the router ID is dynamically selected based on highest loopback or active interface IP, which could change if the loopback fails.

Why this answer

The router-id command under the OSPF process explicitly sets the OSPF router ID and ensures it remains stable regardless of interface state. Dynamic selection could change if the loopback flaps, leading to OSPF adjacency resets. The other options either enable OSPF on an interface or advertise a network, which do not control the router ID.

Exam trap

The trap here is assuming that configuring a loopback interface with the desired IP automatically sets the OSPF router ID permanently, but dynamic selection can change if the interface goes down.

57
Multi-Selecthard

A network engineer is deploying OSPFv3 in an IPv6 network. The engineer wants to enable OSPFv3 on a router and ensure that it can form adjacencies with neighbors. Which two commands are required on the router to enable OSPFv3 globally and on an interface? (Choose two.)

Select 2 answers
A.ipv6 ospf 1 area 0
B.ipv6 router ospf 1
C.ipv6 unicast-routing
D.router ospf 1
E.ipv6 enable
AnswersA, B

The 'ipv6 ospf 1 area 0' command is used under an interface to enable OSPFv3 on that interface and assign it to area 0. This is required for the interface to participate in OSPFv3 and form adjacencies. Without it, the interface will not send or receive OSPFv3 hello packets. Thus, it is a necessary command.

Why this answer

To enable OSPFv3, you must start the OSPFv3 process with 'ipv6 router ospf 1' and then enable it on an interface with 'ipv6 ospf 1 area 0'. The other commands are either for OSPFv2, general IPv6 routing, or interface IPv6 enabling, which are not the specific OSPFv3 enabling commands.

Exam trap

The trap here is confusing OSPFv3 commands with OSPFv2 commands; OSPFv3 uses 'ipv6 router ospf' and 'ipv6 ospf' instead of 'router ospf' and 'ip ospf'.

58
MCQhard

A network engineer is configuring route redistribution between EIGRP and OSPF on a Cisco IOS-XE router. The engineer wants to prevent routing loops and ensure that only specific EIGRP routes are redistributed into OSPF. Which combination of tools should the engineer use?

A.Use a route map with a prefix list to match specific routes, and set a tag on redistributed routes to prevent them from being redistributed back into EIGRP.
B.Configure OSPF as a stub area to prevent external routes from being injected, and redistribute only connected routes into EIGRP.
C.Use a distribute-list on the OSPF process to filter routes, and rely on OSPF's built-in loop prevention mechanisms.
D.Set the administrative distance of EIGRP to a lower value than OSPF, and use passive interfaces to control updates.
AnswerA

A route map with a prefix list provides granular control over which EIGRP routes are redistributed into OSPF. Setting a tag on those routes allows EIGRP to deny routes with that tag when redistributing back, preventing loops. This is a standard best practice for mutual redistribution, ensuring only intended routes are advertised and loop prevention is enforced.

Why this answer

To control redistribution and prevent loops, a route map with a prefix list filters which EIGRP routes enter OSPF, while route tagging marks those routes so EIGRP can deny them if they are redistributed back. This combination is the most precise and scalable method. The other options either do not filter properly, break connectivity, or rely on mechanisms that do not prevent loops during mutual redistribution.

Exam trap

The trap here is thinking that a distribute-list alone can prevent loops during mutual redistribution, when route tagging is required to identify and block redistributed routes from re-entering the original protocol.

59
MCQhard

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS router. The engineer wants traffic from a specific subnet to be routed via a next-hop IP address that is not directly connected. Which command is required under the route-map configuration?

A.set ip next-hop 10.1.1.1
B.set interface GigabitEthernet0/1
C.set ip default next-hop 10.1.1.1
D.set ip next-hop recursive 10.1.1.1
AnswerD

The 'set ip next-hop recursive' command allows the router to recursively resolve the next-hop IP address through the routing table, even if it is not directly connected. This enables PBR to forward traffic to a next-hop that is multiple hops away. This is the correct command to use when the next-hop is not directly connected.

Why this answer

PBR with a non-directly connected next-hop requires the 'set ip next-hop recursive' command. This allows the router to recursively look up the next-hop in the routing table to find a directly connected next-hop. Without the 'recursive' keyword, the router expects the next-hop to be directly connected and will not install the policy route if it is not.

Exam trap

The trap here is assuming that 'set ip next-hop' can be used with any IP address; it only works for directly connected next-hops unless the 'recursive' keyword is added.

60
MCQmedium

A network engineer is configuring a GRE tunnel between two routers. The tunnel interface is up, but OSPF neighbors are not forming. The engineer suspects a Layer 3 issue. Which command should be used to verify that the tunnel endpoints are reachable?

A.show ip interface brief
B.ping <remote tunnel endpoint IP>
C.traceroute <remote tunnel endpoint IP>
D.show ip ospf neighbor
AnswerB

Pinging the remote tunnel endpoint IP address tests reachability to the physical interface or loopback used as the tunnel destination. If the ping fails, the tunnel cannot pass traffic, and OSPF neighbors will not form. This command directly verifies Layer 3 connectivity to the endpoint, which is essential for a GRE tunnel to operate. It helps isolate whether the problem is in the underlay network or in the tunnel configuration itself.

Why this answer

To verify that the tunnel endpoints are reachable, the engineer should ping the remote tunnel endpoint IP address. This tests the underlay network connectivity, which is required for the GRE tunnel to carry traffic. If the ping fails, the tunnel will not pass traffic even if the tunnel interface is up.

Other commands like show ip interface brief only show interface status, show ip ospf neighbor shows adjacency state, and traceroute is more for path analysis. The ping is the most direct and effective method.

Exam trap

The trap here is assuming that an 'up' tunnel interface means the tunnel is operational, when in fact the underlay reachability must be verified separately.

61
MCQhard

A network engineer is configuring a GRE tunnel between two Cisco routers across an ISP network. The tunnel source is GigabitEthernet0/0 (IP 203.0.113.1) and the tunnel destination is 203.0.113.2. The engineer notices that the tunnel interface is up, but no traffic is passing through it. The engineer suspects a routing issue. Which command should be used to verify that the tunnel endpoint is reachable?

A.ping 203.0.113.2 source 203.0.113.1
B.show interface tunnel 0
C.traceroute 203.0.113.2
D.show ip interface brief
AnswerA

This command sends an ICMP echo request to the tunnel destination (203.0.113.2) using the tunnel source address (203.0.113.1) as the source. If the ping succeeds, the tunnel endpoint is reachable, and the underlying transport network is working. If it fails, there is a routing or connectivity issue between the endpoints, which would prevent the tunnel from passing traffic. This is the correct way to test reachability to the tunnel destination.

Why this answer

To verify reachability to the tunnel destination, you should ping the destination IP address using the tunnel source address as the source. This tests the underlying transport network and ensures that the tunnel endpoint is reachable. Other commands like show ip interface brief or show interface tunnel only show local status, and traceroute may not use the correct source address.

Exam trap

The trap here is assuming that a tunnel interface being up/up guarantees end-to-end connectivity, when in fact the tunnel can be up even if the destination is unreachable, especially without keepalives.

62
MCQmedium

A network engineer is configuring a GRE tunnel between two Cisco IOS XE routers, R1 and R2, to transport IPv6 traffic over an IPv4 network. The tunnel source is R1's GigabitEthernet0/0 interface (IPv4 address 10.1.1.1) and the tunnel destination is R2's GigabitEthernet0/0 interface (IPv4 address 10.2.2.2). The engineer configures the tunnel interface with IPv6 address 2001:DB8:1::1/64 and enables OSPFv3 on the tunnel interface. However, OSPFv3 adjacencies are not forming. What is the most likely cause?

A.The tunnel interface must be configured with the `tunnel mode gre ipv6` command.
B.OSPFv3 requires the tunnel interface to be in the same area as the physical interfaces.
C.The tunnel interface must have an IPv4 address configured for OSPFv3 to work.
D.The tunnel source and destination must be reachable via IPv4, and the tunnel interface must be up.
AnswerD

For a GRE tunnel to be operational, the tunnel source and destination IPv4 addresses must be reachable. If the underlying IPv4 network cannot route between 10.1.1.1 and 10.2.2.2, the tunnel interface will remain down, and OSPFv3 will not form an adjacency. Additionally, the tunnel interface must be in an up/up state for OSPFv3 to run over it.

Why this answer

GRE tunnels require that the source and destination addresses are reachable via the transport network (IPv4 in this case). If the IPv4 network cannot route between the tunnel endpoints, the tunnel interface will be down, and no IPv6 traffic, including OSPFv3 hellos, will pass. The tunnel interface must be up and have the correct IPv6 address and OSPFv3 configuration.

Exam trap

The trap here is overlooking the underlying transport reachability; the tunnel cannot come up if the IPv4 source and destination cannot communicate.

63
MCQhard

A network administrator is troubleshooting a DMVPN Phase 3 network using OSPF. Spoke routers are not learning routes from other spokes despite having a full mesh of tunnels. The hub is configured with 'ip nhrp redirect' and spokes with 'ip nhrp shortcut'. Which action is most likely to resolve the issue?

A.Ensure that the hub is configured with 'ip nhrp map multicast dynamic' and spokes with 'ip nhrp map multicast <hub>'.
B.Configure 'ip ospf network broadcast' on all tunnel interfaces.
C.Verify that the spoke routers have a route to the other spokes' tunnel endpoints via the hub, and that NHRP resolution is working.
D.Enable OSPF point-to-multipoint network type on all tunnel interfaces.
AnswerC

In DMVPN Phase 3, spokes initially use the hub for communication. When traffic to another spoke is detected, the spoke sends an NHRP resolution request. If the spoke lacks a route to the other spoke's tunnel endpoint (NBMA address) or NHRP resolution fails, the shortcut cannot be established. Ensuring NHRP resolution and routing to the NBMA address is critical.

Why this answer

In DMVPN Phase 3, spoke-to-spoke communication relies on NHRP shortcut resolution. For this to work, spokes must have a route to the other spokes' NBMA addresses (typically via the hub) and NHRP must be able to resolve their IP addresses. If NHRP resolution fails or there is no route to the NBMA address, the shortcut tunnel is not built, and traffic continues via the hub.

Thus, verifying NHRP resolution and routing is essential.

Exam trap

The trap here is focusing on OSPF network type or multicast configuration when the real issue is NHRP shortcut resolution and reachability to the NBMA address.

64
MCQeasy

A network engineer is configuring EIGRP on a Cisco router. The router has two interfaces: GigabitEthernet0/0 with IP address 10.1.1.1/24 and GigabitEthernet0/1 with IP address 10.2.2.1/24. The engineer wants to advertise both networks into EIGRP AS 100. Which configuration command is required to enable EIGRP on the interfaces?

A.network 10.1.1.0 0.0.0.255 and network 10.2.2.0 0.0.0.255
B.network 10.0.0.0
C.ipv6 eigrp 100 on each interface
D.network 10.0.0.0 0.255.255.255
AnswerA

EIGRP uses the network command with a wildcard mask to specify which interfaces participate in EIGRP. To advertise both 10.1.1.0/24 and 10.2.2.0/24, you need two network statements: one for each subnet. The wildcard mask 0.0.0.255 matches the /24 subnet. This configuration enables EIGRP on both interfaces and advertises the connected networks. This is the correct and specific way to achieve the goal.

Why this answer

To enable EIGRP for IPv4 on interfaces, you use the network command under router eigrp with a wildcard mask. Each network statement specifies a range of addresses; the wildcard mask 0.0.0.255 matches a /24 subnet. Two statements are needed to cover both 10.1.1.0/24 and 10.2.2.0/24.

The other options are either too broad, invalid syntax, or for IPv6.

Exam trap

The trap here is using a single network statement with a classful mask or no wildcard mask, which either enables EIGRP on too many interfaces or is invalid syntax.

65
MCQeasy

A network engineer is configuring a static route on a Cisco IOS router to reach a remote network. The engineer wants the route to be used only if the primary path fails and to be removed from the routing table when the primary path is available. Which type of static route should be configured?

A.Default static route
B.Recursive static route
C.Floating static route
D.Directly connected static route
AnswerC

A floating static route is configured with a higher administrative distance than the primary route, so it is only installed in the routing table when the primary route fails. This makes it a backup path. It is commonly used for redundancy in WAN links, where a secondary link should only be used if the primary goes down.

Why this answer

A floating static route is designed to be a backup by setting a higher administrative distance than the primary route. It remains inactive until the primary route is removed from the routing table, at which point it becomes active. This provides redundancy without manual intervention, exactly matching the scenario's requirement.

Exam trap

The trap here is confusing a floating static route with a default static route; the default route is always used as a last resort, while a floating static route is conditional on the primary route's failure.

66
MCQmedium

A network engineer is configuring OSPFv3 on a router that connects to an IPv6 network. The router must form an adjacency with a neighbor on the same segment, but the engineer notices that the router is not sending any OSPFv3 Hello packets. The interface is up, and IPv6 unicast routing is enabled globally. Which of the following is the most likely cause?

A.The OSPFv3 process is not enabled on the interface.
B.The interface is configured as passive.
C.The OSPFv3 network type is set to point-to-multipoint.
D.The OSPFv3 router ID is not configured.
AnswerA

OSPFv3 requires that the interface be explicitly enabled for OSPFv3 using the 'ipv6 ospf <process-id> area <area-id>' interface configuration command. Without this, the router will not send Hello packets on that interface even if the OSPFv3 process is running. Other options are incorrect because they either do not prevent Hello generation or are not applicable.

Why this answer

For OSPFv3 to operate on an interface, the interface must be explicitly enabled for OSPFv3 using the 'ipv6 ospf' command under interface configuration. Simply enabling IPv6 unicast routing and configuring an OSPFv3 process is not sufficient. Without interface enablement, no Hello packets are sent, and no adjacency can form.

This is a common oversight when transitioning from OSPFv2, where network statements are used.

Exam trap

The trap here is assuming that enabling IPv6 unicast routing and creating an OSPFv3 process automatically enables OSPFv3 on all interfaces, as OSPFv2 does with network statements.

67
MCQhard

A network administrator is configuring MPLS Layer 3 VPN on a Cisco IOS XE router. The router is a PE device connected to two CE routers in different VRFs. The administrator wants to prevent routes from one VRF from being leaked into another VRF. Which configuration step is essential to maintain VRF separation?

A.Configure route targets (RTs) for import and export on each VRF.
B.Enable OSPF as the PE-CE routing protocol and use different process IDs.
C.Assign a unique route distinguisher (RD) to each VRF.
D.Configure BGP neighbor statements with different autonomous system numbers.
AnswerA

Route targets control which routes are imported into and exported from a VRF. By assigning distinct RTs for import and export on each VRF, you ensure that routes from one VRF are not imported into another. This maintains VRF separation. Without proper RT configuration, routes could be leaked between VRFs if RTs are shared.

Why this answer

In MPLS Layer 3 VPN, VRF separation is achieved through the use of route targets (RTs). Each VRF is configured with import and export RTs. When a route is exported from a VRF, it is tagged with the export RT.

The receiving PE imports the route into a VRF only if the route's RT matches the VRF's import RT. Therefore, to prevent leaking, each VRF must have unique RTs that are not shared with other VRFs.

Exam trap

The trap here is confusing the role of the route distinguisher with that of the route target; the RD only makes prefixes unique, while RTs control import/export into VRFs.

68
MCQmedium

A network administrator is configuring EIGRP on a router and wants to ensure that only a specific subnet is advertised out of an interface. The router has the following configuration: 'router eigrp 100', 'network 10.0.0.0', 'passive-interface GigabitEthernet0/0'. The administrator wants to advertise 10.1.1.0/24 out of GigabitEthernet0/0 while preventing other subnets from being advertised. Which configuration achieves this?

A.Remove the passive-interface command and configure a distribute-list outbound on GigabitEthernet0/0 to permit only 10.1.1.0/24.
B.Keep the passive-interface command and configure a distribute-list outbound on GigabitEthernet0/0 to permit only 10.1.1.0/24.
C.Remove the passive-interface command and configure a distribute-list inbound on GigabitEthernet0/0 to permit only 10.1.1.0/24.
D.Remove the passive-interface command and configure 'network 10.1.1.0 0.0.0.255' under router EIGRP.
AnswerA

Removing passive-interface allows EIGRP to send and receive Hellos on the interface, forming adjacencies. An outbound distribute-list filters which routes are advertised, permitting only the desired subnet. This combination ensures only 10.1.1.0/24 is advertised out of GigabitEthernet0/0 while other subnets are suppressed.

Why this answer

To advertise a specific subnet out of an interface while suppressing others, the interface must not be passive so that EIGRP can form adjacencies and send updates. Then, an outbound distribute-list can filter the advertised routes, permitting only the desired subnet. This approach gives granular control over which routes are sent out of the interface, meeting the administrator's requirement.

Exam trap

The trap here is confusing inbound and outbound distribute-lists, or forgetting that a passive interface cannot advertise at all.

69
MCQmedium

A network engineer is configuring EIGRP for IPv6 on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (2001:DB8:1::1/64) and GigabitEthernet0/1 (2001:DB8:2::1/64). The engineer wants to enable EIGRP for IPv6 on both interfaces and ensure that the router forms adjacencies. Which configuration is required?

A.Enable IPv6 unicast routing globally, configure an EIGRP for IPv6 routing process, and use the network command under the routing process to advertise the interfaces.
B.Enable IPv6 unicast routing globally, create an EIGRP for IPv6 routing process, and enable EIGRP on each interface with the ipv6 eigrp command.
C.Enable IPv6 unicast routing globally, configure EIGRP for IPv6 with the no shutdown command under the routing process, and assign IPv6 addresses to interfaces.
D.Enable IPv6 unicast routing globally, configure EIGRP for IPv6, and enable EIGRP on interfaces using the ipv6 router eigrp command under each interface.
AnswerB

EIGRP for IPv6 requires IPv6 unicast routing to be enabled globally. The routing process is created with ipv6 router eigrp AS number, and then EIGRP must be enabled on each interface using ipv6 eigrp AS number. This allows the interfaces to participate in EIGRP for IPv6 and form adjacencies with neighbors.

Why this answer

EIGRP for IPv6 requires IPv6 unicast routing to be enabled globally, creation of an EIGRP for IPv6 routing process, and explicit enabling of EIGRP on each interface using the ipv6 eigrp command. Unlike IPv4 EIGRP, there is no network command; interfaces must be enabled individually. This ensures the router can form adjacencies and exchange IPv6 routing information.

Exam trap

The trap here is assuming EIGRP for IPv6 uses the network command like IPv4 EIGRP; it does not, and interfaces must be enabled individually.

70
MCQmedium

A network engineer is implementing MPLS Layer 3 VPN on a Cisco IOS XE router. The engineer wants to ensure that customer routes are advertised with the correct route distinguisher (RD) and route target (RT) extended communities. Which BGP address family must be configured to exchange VPNv4 routes between PE routers?

A.address-family ipv4 vrf CUSTOMER
B.address-family ipv4 multicast
C.address-family ipv4 unicast
D.address-family vpnv4 unicast
AnswerD

The address-family vpnv4 unicast is used on PE routers to exchange VPNv4 routes with other PE routers. It carries the RD and RT extended communities along with the customer prefixes. This address family must be activated on the PE-PE BGP session to propagate MPLS VPN routing information. Without it, VPNv4 routes are not exchanged, and MPLS VPN connectivity fails.

Why this answer

MPLS Layer 3 VPN uses BGP VPNv4 address family to exchange customer routes between PE routers. The VPNv4 address family carries the RD and RT extended communities that identify the VPN and control import/export. It must be activated on the PE-PE BGP session.

The VRF address family is used for PE-CE routing and for assigning RDs and RTs, but not for exchanging VPNv4 routes.

Exam trap

The trap here is confusing the VRF address family, used for PE-CE routing, with the VPNv4 address family, used for PE-PE route exchange.

71
MCQhard

A network engineer is configuring MPLS Layer 3 VPN on a Cisco IOS XE router. The engineer wants to enable the router to distribute VPNv4 prefixes to its PE peers. Which command must be configured under the BGP routing process to enable the address family?

A.address-family ipv4 vrf
B.address-family ipv4 unicast
C.address-family vpnv6
D.address-family vpnv4
AnswerD

The address-family vpnv4 command enters the VPNv4 address family configuration mode. Within this mode, the engineer can activate neighbors and configure other VPNv4-specific parameters. Without this, the router cannot exchange VPNv4 prefixes with other PE routers. This is the correct command to enable the address family for MPLS L3VPN.

Why this answer

To enable the distribution of VPNv4 prefixes in MPLS L3VPN, the engineer must configure the address-family vpnv4 command under the BGP routing process. This enters the VPNv4 address family configuration mode, where neighbors can be activated and other parameters set. The other address families do not handle VPNv4 prefixes: ipv4 vrf is for VRF-specific routing, ipv4 unicast is for global IPv4, and vpnv6 is for IPv6 VPNs.

Exam trap

The trap here is confusing the VRF-specific IPv4 address family with the VPNv4 address family that is used between PE routers.

72
MCQmedium

A network engineer is configuring MPLS Layer 3 VPN on a Cisco router. The engineer wants to ensure that the PE router can forward VPN traffic to the correct CE router based on the route target. Which of the following is required on the PE router?

A.A static route to the CE router with a next-hop of the CE interface.
B.A route reflector client configured for the VPNv4 address family.
C.An IGP configured with multiprotocol BGP extensions.
D.A VRF instance with a route distinguisher and route target configured.
AnswerD

On a PE router, an MPLS L3VPN requires a VRF instance per VPN. The VRF must have a route distinguisher (RD) to make the VPN routes unique, and one or more route targets (RT) to control import and export of routes into and out of the VRF. This allows the PE to forward traffic to the correct CE based on the RT. Without these, VPN routing and forwarding would not work.

Why this answer

MPLS L3VPN relies on VRFs to separate customer routing tables. Each VRF must have a route distinguisher to make prefixes unique and route targets to control import/export of routes. The PE router uses these to forward traffic to the correct CE.

Without a VRF with RD and RT, the PE cannot maintain separate VPN routing or forward based on VPN membership.

Exam trap

The trap here is focusing on BGP or IGP configurations while overlooking the fundamental VRF configuration with RD and RT.

73
MCQmedium

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS XE router. The engineer wants traffic from subnet 10.1.1.0/24 to be forwarded to next-hop 192.168.2.1, while all other traffic uses the default routing table. The engineer configures a route map and applies it to the ingress interface with `ip policy route-map PBR`. However, traffic from 10.1.1.0/24 is still following the default route. Which action should the engineer take to ensure PBR is applied?

A.Verify that the route map contains a match statement for the source subnet and a set statement for the next-hop, and that the route map is applied with the `ip policy route-map` command on the correct interface.
B.Enable `ip local policy route-map PBR` globally to apply the policy to all interfaces.
C.Apply the route map to the egress interface with the `ip policy route-map` command.
D.Configure a default route with a next-hop of 192.168.2.1 to override the existing default route.
AnswerA

PBR requires a route map with at least one match statement (e.g., `match ip address` referencing an ACL for 10.1.1.0/24) and a set statement (e.g., `set ip next-hop 192.168.2.1`). The route map must be applied to the ingress interface with `ip policy route-map PBR`. If the match or set is missing, or if applied to the wrong interface, PBR will not take effect. This option correctly identifies the necessary configuration elements.

Why this answer

PBR requires a route map with proper match and set statements, and it must be applied to the ingress interface where the traffic enters. If the route map lacks a match for the source subnet or a set for the next-hop, or if it is applied incorrectly, PBR will not override the default routing. Verifying these elements ensures that traffic from 10.1.1.0/24 is forwarded to 192.168.2.1 as intended.

Exam trap

The trap here is assuming that simply applying a route map is sufficient, without verifying the match/set statements and the correct ingress interface application.

74
Multi-Selecthard

A network engineer is troubleshooting an MPLS Layer 3 VPN on Cisco IOS XE routers. A customer edge (CE) router is not receiving routes from the provider edge (PE) router. The engineer suspects a VRF configuration issue. Which two commands should the engineer use to verify the VRF routing table and the BGP VPNv4 address family? (Choose two.)

Select 2 answers
A.show vrf detail
B.show ip bgp summary
C.show bgp vpnv4 unicast all
D.show ip route vrf CUSTOMER
E.show mpls ldp neighbor
AnswersC, D

The `show bgp vpnv4 unicast all` command displays the BGP VPNv4 table, which contains routes from all VRFs. It shows the VPNv4 prefixes, their attributes, and the associated route distinguishers and route targets. This is critical to verify that the PE is receiving and advertising VPNv4 routes correctly. If routes are missing here, the issue may be with BGP configuration or route targets.

Why this answer

To troubleshoot MPLS L3VPN route propagation, the engineer must check both the VRF routing table and the BGP VPNv4 table. The `show ip route vrf CUSTOMER` command reveals whether routes are installed in the VRF, while `show bgp vpnv4 unicast all` shows the VPNv4 routes exchanged between PEs. Together, they help isolate whether the issue is with VRF configuration, route targets, or BGP VPNv4 peering.

Exam trap

The trap here is focusing on MPLS LDP or global BGP commands, which do not show VRF-specific or VPNv4 routing information needed for this issue.

75
MCQmedium

A network engineer is implementing Policy-Based Routing (PBR) on a Cisco IOS router. The engineer wants to route traffic from subnet 10.10.10.0/24 to a next-hop of 192.168.2.2, but only for HTTP traffic (TCP port 80). Which configuration sequence is required?

A.Create a route-map with a match statement for the source subnet and a set statement for the next-hop, then apply it globally with ip policy route-map.
B.Create a route-map with a match statement for the source subnet and a set statement for the next-hop, then apply it to the interface with ip policy route-map.
C.Create a standard ACL that permits the subnet, create a route-map that matches the ACL and sets the next-hop, then apply the route-map to the interface with ip policy route-map.
D.Create an extended ACL that permits TCP port 80 from the subnet, create a route-map that matches the ACL and sets the next-hop, then apply the route-map to the interface with ip policy route-map.
AnswerD

This sequence correctly implements PBR for HTTP traffic. The extended ACL matches source subnet and destination TCP port 80. The route-map uses match ip address to reference the ACL and set ip next-hop to specify the next-hop. Applying the route-map to the ingress interface with ip policy route-map activates PBR. This ensures only HTTP traffic from the subnet is policy-routed, while other traffic follows normal routing.

Why this answer

PBR requires an extended ACL to match traffic based on source, destination, and port. The route-map then matches the ACL and sets the next-hop. Finally, the route-map is applied to the ingress interface with ip policy route-map.

A standard ACL cannot match port numbers, and global application is not supported. Therefore, the sequence with an extended ACL and interface application is correct.

Exam trap

The trap here is forgetting that PBR matching for ports requires an extended ACL, and that the route-map must be applied to an interface, not globally.

Page 1 of 2 · 111 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Layer 3 Technologies questions.