Courseiva

CCNA Layer 3 Technologies Questions

36 of 111 questions · Page 2/2 · Layer 3 Technologies · Answers revealed

76
MCQmedium

A network engineer is configuring Policy-Based Routing (PBR) on a Cisco IOS XE router. The engineer wants to forward traffic matching a specific ACL to a next-hop IP address, but only if the next-hop is reachable. Which command should be used in the route map to specify the next-hop and enable tracking?

A.set ip next-hop 10.1.1.1
B.set ip default next-hop 10.1.1.1
C.set ip next-hop verify-availability 10.1.1.1 1 track 1
D.set ip next-hop recursive 10.1.1.1
AnswerC

The set ip next-hop verify-availability command allows PBR to verify the reachability of the next-hop using a tracking object. The syntax includes the next-hop IP, a sequence number, and the track keyword followed by the tracking object number. If the tracked object is up, the next-hop is used; if down, the route map is not applied, and normal routing takes over. This meets the requirement of forwarding only if the next-hop is reachable.

Why this answer

To conditionally forward traffic based on next-hop reachability in PBR, the set ip next-hop verify-availability command is used. It references a tracking object that monitors the next-hop. If the track is up, the next-hop is used; if down, the route map is skipped, and normal routing applies.

This provides the required conditional forwarding.

Exam trap

The trap here is assuming that set ip next-hop alone will verify reachability; it does not, and requires the verify-availability keyword with a track object.

77
MCQmedium

A network engineer is configuring OSPFv3 on a dual-stack router. The router must form an adjacency with a neighbor over a link that supports both IPv4 and IPv6. The interface is configured with 'ipv6 ospf 1 area 0' and the router ID is manually set to 10.1.1.1. After applying the configuration, the engineer notices that the OSPFv3 adjacency remains in EXSTART state. What is the most likely cause?

A.The router ID is not unique in the OSPFv3 domain.
B.The OSPFv3 process is not configured with an IPv6 address family.
C.The neighbor router is using a different OSPFv3 process ID.
D.The IPv6 MTU on the interface does not match the neighbor's interface MTU.
AnswerD

In OSPFv3, the EXSTART state is reached after the neighbor is seen in the Hello packet, but before database description packets are exchanged. A mismatch in interface MTU prevents the routers from agreeing on the initial database description sequence, causing the adjacency to remain in EXSTART. This is a common issue when IPv6 MTU is not consistent across the link, especially with tunneling or different link types.

Why this answer

The EXSTART state in OSPFv3 indicates that the routers have exchanged Hello packets and are attempting to negotiate the master/slave relationship for database description exchange. A mismatch in interface MTU prevents the successful exchange of database description packets, leaving the adjacency stuck in EXSTART. Ensuring consistent MTU on both sides resolves the issue.

Exam trap

The trap here is assuming that EXSTART is caused by a router ID conflict or process ID mismatch, when it is typically an MTU mismatch.

78
MCQmedium

A network engineer is troubleshooting a DMVPN Phase 3 deployment on a Cisco IOS XE router. The hub router is configured with 'ip nhrp redirect' and the spoke routers with 'ip nhrp shortcut'. However, spoke-to-spoke traffic is still traversing the hub. Which action should the engineer take to enable direct spoke-to-spoke communication?

A.Configure 'ip nhrp network-id' with the same value on all routers.
B.Configure 'ip nhrp map multicast dynamic' on the hub.
C.Ensure that the spoke routers have a route to the spoke networks via the tunnel interface and that NHRP resolution is working.
D.Enable 'ip nhrp authentication' on all routers.
AnswerC

For DMVPN Phase 3 shortcuts to work, spokes must have a route to the destination spoke network pointing to the tunnel interface, and NHRP must resolve the destination NBMA address. The hub uses redirect messages to inform spokes of a better path, and spokes use shortcut to install a direct NHRP entry. Without proper routing and NHRP, shortcuts fail.

Why this answer

Spoke-to-spoke shortcuts in DMVPN Phase 3 require that spokes have a route to the destination network via the tunnel interface and that NHRP resolution succeeds. The hub uses NHRP redirect to tell the spoke that a better path exists, and the spoke uses NHRP shortcut to install a direct entry. Without these, traffic continues through the hub.

Exam trap

The trap here is assuming that enabling NHRP redirect and shortcut alone is sufficient, without verifying that routing and NHRP resolution are correctly configured.

79
MCQmedium

A network engineer is deploying BGP on a Cisco IOS XE router. The router must advertise the network 10.10.0.0/16 to an external peer, but the engineer notices that the prefix is not being advertised even though the network command is configured. The routing table shows that 10.10.0.0/16 is present as two separate /24 routes via OSPF. What is the most likely cause?

A.The BGP router ID is not reachable, preventing advertisement.
B.The BGP neighbor is configured with a send-community attribute that filters the prefix.
C.The OSPF routes are not being redistributed into BGP.
D.The network command requires an exact match in the routing table.
AnswerD

BGP network statements only advertise a prefix if there is an exact matching route in the IP routing table. Here, only 10.10.1.0/24 and 10.10.2.0/24 exist, not 10.10.0.0/16, so BGP will not originate the aggregate. To advertise the /16, the engineer must either create a summary route (e.g., a static route to Null0) or use the aggregate-address command.

Why this answer

BGP network statements require an exact match in the routing table to originate a prefix. The routing table contains only the more specific /24 routes, so the /16 is not advertised. To resolve this, the engineer must create a matching route, such as a static route to Null0, or use the aggregate-address command with the summary-only option.

The other options do not address the fundamental requirement of an exact match.

Exam trap

The trap here is assuming that a BGP network statement will automatically summarize or advertise a supernet even when only more specific routes exist in the routing table.

80
MCQhard

A network engineer is implementing BGP on a Cisco IOS XE router. The router is peering with an ISP and receives a full BGP table. The engineer wants to influence inbound traffic from the ISP by making a specific prefix more preferred. The engineer has configured a route map that sets the MED to 50 for the prefix 203.0.113.0/24 and applies it outbound to the ISP. However, the ISP still prefers a different path. Which BGP attribute should the engineer manipulate to influence inbound traffic more effectively?

A.WEIGHT
B.ORIGIN
C.LOCAL_PREF
D.AS_PATH
AnswerD

AS_PATH is a well-known mandatory attribute that can influence inbound traffic by making the path appear longer. By prepending additional AS numbers to the AS_PATH for a specific prefix, the engineer can make that path less preferred by the ISP. This is a common method to influence inbound traffic when MED is not honored, as MED is optional and often not considered across different autonomous systems.

Why this answer

To influence inbound traffic from an ISP, the most effective method is to manipulate the AS_PATH attribute by prepending additional AS numbers. This makes the path appear longer and less preferred. MED is often not honored by ISPs because it is an optional attribute and is only considered between autonomous systems that agree to use it.

LOCAL_PREF and WEIGHT are used for outbound traffic and are not advertised externally. ORIGIN is not typically used for this purpose.

Exam trap

The trap here is assuming that MED will always influence inbound traffic, but MED is often ignored by ISPs; AS_PATH prepending is more reliable.

81
MCQhard

A network engineer is configuring VRF-lite on a Cisco IOS router to segment traffic for two customers. The engineer creates VRF CUSTA and assigns interface GigabitEthernet0/1 to it. The engineer then configures a static route within VRF CUSTA to reach 10.10.10.0/24 via next-hop 192.168.1.1. However, the route does not appear in the VRF CUSTA routing table. Which command is missing?

A.The `ip route vrf CUSTA 10.10.10.0 255.255.255.0 GigabitEthernet0/1` command must be used to specify the outgoing interface.
B.The `ip route 10.10.10.0 255.255.255.0 192.168.1.1` command must be configured under the VRF configuration mode.
C.The `ip route vrf CUSTA 10.10.10.0 255.255.255.0 192.168.1.1 global` command must be used to leak the route into the global table.
D.The `ip route vrf CUSTA 10.10.10.0 255.255.255.0 192.168.1.1` command must be configured in global configuration mode.
AnswerD

Static routes for a VRF must be configured with the `ip route vrf <vrf-name>` syntax in global configuration mode. Without the `vrf` keyword, the route is installed in the global routing table, not the VRF. This command correctly places the route into the VRF CUSTA routing table.

Why this answer

In VRF-lite, static routes for a VRF must be configured with the `ip route vrf <vrf-name>` command in global configuration mode. Without the `vrf` keyword, the route is placed in the global routing table instead of the VRF. The correct syntax ensures the route is installed in the VRF's routing table.

Exam trap

The trap here is assuming that configuring a static route while in VRF context or using the interface assignment is sufficient, when the `vrf` keyword is mandatory in the global `ip route` command.

82
MCQeasy

A network engineer is configuring a Cisco IOS router to run OSPFv3 for IPv6. The router must form an adjacency with a neighbor on a broadcast network. Which command is required to enable OSPFv3 on an interface?

A.ipv6 ospf 1 area 0
B.ospfv3 1 ipv6 area 0
C.ipv6 ospf area 0
D.ipv6 router ospf 1
AnswerA

This command, issued in interface configuration mode, enables OSPFv3 for IPv6 on the interface and assigns it to area 0. It is the standard method to activate OSPFv3 on an interface in Cisco IOS. Without this command, the interface will not participate in OSPFv3 and no adjacency will form.

Why this answer

To enable OSPFv3 on an interface for IPv6, the command `ipv6 ospf 1 area 0` is used in interface configuration mode. This activates OSPFv3 on the interface and associates it with the specified area. The global command `ipv6 router ospf 1` is also needed to configure the router ID and other parameters, but the interface-level command is essential for adjacency formation.

Exam trap

The trap here is confusing the global OSPFv3 configuration command with the interface-level command that actually enables the protocol on the interface.

83
MCQeasy

A network engineer is configuring a static route on a Cisco IOS router to reach the network 10.1.1.0/24 via the next-hop 192.168.1.1. The engineer wants the route to be removed from the routing table if the next-hop becomes unreachable. Which command should be used?

A.ip route 10.1.1.0 255.255.255.0 192.168.1.1
B.ip route 10.1.1.0 255.255.255.0 192.168.1.1 permanent
C.ip route 10.1.1.0 255.255.255.0 192.168.1.1 track 1
D.ip route 10.1.1.0 255.255.255.0 192.168.1.1 name TRACK
AnswerC

The track keyword associates the static route with a tracked object (in this case, object 1). If the tracked object goes down, the route is removed from the routing table. This provides next-hop reachability tracking. The engineer must also configure a track object to monitor the next-hop, typically using ICMP echo or a route reachability check. This is the correct way to conditionally install a static route based on next-hop availability.

Why this answer

To remove a static route when the next-hop becomes unreachable, the track keyword must be used. It associates the route with a tracked object that monitors the next-hop. The permanent keyword does the opposite, keeping the route installed.

The name keyword only labels the route. A standard static route without tracking remains in the table even if the next-hop fails. Therefore, the track option is correct.

Exam trap

The trap here is confusing the permanent keyword with tracking; permanent keeps the route despite failures, while track removes it based on object state.

84
MCQhard

A network administrator is troubleshooting an OSPFv3 network. Router R1 is not forming an adjacency with Router R2 over a point-to-point link. The administrator verifies that the interfaces are up, IPv6 addresses are configured, and OSPFv3 is enabled on both interfaces. The output of 'show ipv6 ospf interface' on R1 shows that the interface is in the 'LOOPBACK' state. What is the most likely reason for this state?

A.There is a duplicate router ID on the network, and R1 has detected its own router ID in a hello packet from R2.
B.The interface is configured as a passive interface under the OSPFv3 process.
C.The interface is configured as a loopback interface instead of a point-to-point interface.
D.The OSPFv3 process is not enabled on the interface, causing it to be placed in the LOOPBACK state.
AnswerA

In OSPFv3, if a router receives a hello packet with its own router ID, it transitions the interface to the LOOPBACK state to prevent adjacency formation. This typically happens when two routers are misconfigured with the same router ID. The LOOPBACK state is a clear indicator of a duplicate router ID conflict on the link, and the adjacency will not form until the conflict is resolved.

Why this answer

The LOOPBACK state on an OSPFv3 interface indicates that the router has received a hello packet containing its own router ID. This is a safeguard against duplicate router IDs. When two routers on the same link share the same router ID, they will not form an adjacency, and the interface will remain in LOOPBACK state.

The administrator should check the router ID configuration on both routers and ensure they are unique.

Exam trap

The trap here is confusing the LOOPBACK state with the loopback interface type or with a passive interface, rather than recognizing it as a duplicate router ID detection mechanism.

85
MCQeasy

An engineer is configuring a GRE tunnel between two Cisco routers. The tunnel source is a physical interface, and the tunnel destination is the remote router's physical interface. After configuration, the tunnel interface is up, but no traffic passes through it. The engineer verifies that the physical interfaces are up and IP connectivity exists between the tunnel endpoints. What is the most likely cause?

A.There is no route to the remote network through the tunnel.
B.The tunnel destination is not reachable.
C.The tunnel keepalive is misconfigured.
D.The tunnel interface is missing an IP address.
AnswerA

Even if the tunnel interface is up, traffic will not pass unless there is a route directing traffic destined for the remote network out the tunnel interface. Without such a route, packets will follow the default route or be dropped. This is a common oversight: the tunnel is operational, but the routing table lacks an entry pointing to the tunnel for the remote subnets. Thus, no traffic passes.

Why this answer

A GRE tunnel can be up, but without a route directing traffic into the tunnel, no data will traverse it. The tunnel interface's up state only indicates that the tunnel source and destination are reachable and the tunnel is operational. Routing is still required to forward traffic.

Therefore, the absence of a route to the remote network via the tunnel is the most likely cause.

Exam trap

The trap here is assuming that a tunnel being up automatically means traffic will flow, overlooking the need for routing to direct traffic into the tunnel.

86
MCQhard

A network engineer is implementing MPLS Layer 3 VPN on a Cisco IOS-XE router. The engineer needs to configure the PE router to exchange VPNv4 routes with other PE routers. Which address family must be configured under the BGP routing process to enable VPNv4 route exchange?

A.address-family ipv6 vpnv4
B.address-family ipv4 vrf
C.address-family vpnv4
D.address-family ipv4 unicast
AnswerC

The VPNv4 address family is specifically designed for MPLS Layer 3 VPNs. Configuring 'address-family vpnv4' under BGP enables the PE router to exchange VPNv4 routes with other PE routers. These routes include the route distinguisher and route target extended communities, allowing the receiving PE to import the route into the correct VRF.

Why this answer

In MPLS Layer 3 VPN, PE routers exchange VPNv4 routes using the VPNv4 address family under BGP. This address family carries the route distinguisher and extended communities (like route targets) that identify the VPN membership. Configuring 'address-family vpnv4' is essential for the PE routers to exchange customer routes and maintain separate routing tables.

Exam trap

The trap here is confusing the VRF-specific IPv4 address family with the VPNv4 address family; VPNv4 is required for PE-to-PE route exchange.

87
MCQmedium

A network engineer is implementing policy-based routing (PBR) on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (LAN) and GigabitEthernet0/1 (WAN). A route-map named PBR-MAP is applied to GigabitEthernet0/0 with the command `ip policy route-map PBR-MAP`. The route-map contains a match statement for access-list 101, which permits traffic from 10.1.1.0/24 to any destination. The set statement is `set ip next-hop 192.168.2.1`. However, traffic from 10.1.1.0/24 is still being routed according to the routing table instead of being forwarded to 192.168.2.1. Which action should the engineer take to ensure PBR is applied?

A.Enable PBR globally with the command `ip policy route-map PBR-MAP` in global configuration mode.
B.Configure a default route pointing to 192.168.2.1 to force all traffic through that next-hop.
C.Apply the route-map to the outbound direction on GigabitEthernet0/1 instead of inbound on GigabitEthernet0/0.
D.Verify that the access-list 101 is correctly configured and matches the traffic, and that the route-map is applied to the correct interface in the inbound direction.
AnswerD

PBR requires that the route-map be applied to the inbound interface where traffic enters, and the match conditions (e.g., ACL) must correctly identify the traffic. If the ACL is misconfigured or the policy is applied in the wrong direction, PBR will not take effect. Checking these ensures the policy is properly triggered for the specified traffic.

Why this answer

Policy-based routing requires the route-map to be applied to the inbound interface where traffic enters the router. The match conditions, such as an ACL, must correctly identify the traffic to be policy-routed. If the ACL is incorrect or the policy is not applied inbound, PBR will not override the routing table.

Verifying these elements ensures that the policy is triggered and the set action is applied.

Exam trap

The trap here is assuming that PBR can be enabled globally or applied outbound, when it must be applied inbound on the ingress interface.

88
MCQmedium

A network engineer is troubleshooting a flapping OSPFv2 adjacency between two Cisco IOS-XE routers on a broadcast segment. The log shows repeated %OSPF-5-ADJCHG messages with reason 'Dead timer expired'. The engineer confirms that both routers are in Area 0, have identical hello/dead intervals, and are not configured with authentication. Which action most likely resolves the issue?

A.Check for a Layer 2 loop or unidirectional link on the segment, because hellos are being lost in one direction and the dead timer expires.
B.Verify that the OSPF network type matches on both interfaces; a mismatch between broadcast and point-to-point prevents hellos from being processed correctly.
C.Confirm that the OSPF priority is set to 0 on both interfaces, because a priority of 0 prevents the router from sending hellos on broadcast networks.
D.Ensure that both routers have the same OSPF router ID, as duplicate router IDs cause the adjacency to continuously reset.
AnswerA

The 'Dead timer expired' message means hellos are not being received within the dead interval. Since authentication and timers are correct, the most likely cause is that hellos are lost in one direction due to a Layer 2 loop, unidirectional link, or a faulty cable/port. Verifying the Layer 2 path and interface counters will reveal dropped or missing hellos and resolve the flapping.

Why this answer

The repeated 'Dead timer expired' indicates that the router stopped receiving hellos from its neighbor within the dead interval. Since authentication, area, and timers are correct, the issue is at Layer 2—likely a unidirectional link or loop causing hello loss. Checking Layer 2 and interface counters is the correct troubleshooting step.

Other options address issues that would produce different symptoms, such as Init or 2-Way states, not a dead timer expiration.

Exam trap

The trap here is assuming that any adjacency problem is caused by OSPF configuration mismatches, when a dead timer expiration often points to a Layer 2 forwarding issue.

89
MCQhard

A network administrator is troubleshooting an EIGRP named mode configuration on a Cisco IOS XE router. The router is not forming an adjacency with a neighbor. The administrator verifies that the AS number is 100, the K-values are default, and authentication is not configured. Which command should be used to verify the EIGRP hello and hold timers on the interface?

A.show ip eigrp neighbors detail
B.show ip eigrp interfaces detail
C.show ip protocols
D.show ip eigrp topology
AnswerB

The show ip eigrp interfaces detail command displays detailed EIGRP information for each interface, including the hello interval and hold time. This is the correct command to verify the timers, as mismatched timers are a common cause of adjacency failures. It also shows other parameters like split horizon and authentication, making it a comprehensive troubleshooting tool for EIGRP interface settings.

Why this answer

To verify EIGRP hello and hold timers on an interface, the show ip eigrp interfaces detail command is used. It provides per-interface EIGRP parameters, including hello interval and hold time. Other commands like show ip eigrp neighbors detail focus on neighbor state, while show ip protocols gives a global view.

The topology table shows routes, not timers. Therefore, the interfaces detail command is the correct choice for troubleshooting timer mismatches.

Exam trap

The trap here is confusing neighbor status commands with interface parameter commands; the detail keyword on the interfaces command is what reveals timers.

90
MCQhard

A network engineer is troubleshooting a Cisco IOS XE router running OSPFv2. The router is an ABR between Area 0 and Area 1. Area 1 is configured as a Not-So-Stubby Area (NSSA). The engineer notices that a Type-7 LSA originated by an ASBR in Area 1 is not being translated into a Type-5 LSA by the ABR. Which condition would prevent the ABR from performing Type-7 to Type-5 translation?

A.The ABR has a static route to the NSSA ASBR's loopback interface but no OSPF adjacency with the ASBR.
B.The ABR is not configured with the `area 1 nssa translate type7 always` command and there is another ABR with a higher router ID in the NSSA.
C.The Type-7 LSA has the P-bit (Propagate bit) cleared, indicating that the LSA should not be translated by the ABR.
D.The forwarding address in the Type-7 LSA is set to 0.0.0.0 and the ABR has no route to the ASBR's router ID.
AnswerC

In NSSA, the P-bit in the Type-7 LSA options field indicates whether the LSA should be translated into a Type-5 LSA by the ABR. If the P-bit is cleared, the ABR will not translate the LSA. The P-bit is typically set by the ASBR when the LSA is originated, but it can be cleared under certain conditions, such as when the ASBR is also an ABR or when the LSA is redistributed without the proper configuration. This directly prevents translation.

Why this answer

Type-7 to Type-5 translation in an NSSA depends on the P-bit in the Type-7 LSA. If the P-bit is cleared, the ABR will not translate the LSA into a Type-5 LSA, preventing the external route from being propagated into the backbone area. This bit is set by the originating ASBR and can be cleared in specific scenarios.

Exam trap

The trap here is focusing on ABR election or forwarding address issues, when the P-bit in the Type-7 LSA is the direct control for whether translation occurs.

91
MCQmedium

A network engineer is configuring OSPFv3 on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 in Area 0 and GigabitEthernet0/1 in Area 1. The engineer wants to ensure that the router acts as an ABR and that inter-area routes are summarized. Which command must be configured under the OSPFv3 router configuration mode to enable ABR functionality?

A.No additional command is required; ABR is automatic.
B.area 1 range 2001:db8:1::/64
C.router-id 1.1.1.1
D.interface GigabitEthernet0/1
AnswerA

A router becomes an ABR automatically when it has at least two interfaces in different OSPF areas. No specific command enables ABR functionality. The engineer only needs to ensure that the interfaces are correctly assigned to different areas, which is already stated. Thus, no additional command under router configuration mode is needed to make the router an ABR.

Why this answer

ABR status in OSPFv3 is not enabled by a command; it is a role that a router assumes when it has interfaces in multiple areas. The engineer must ensure that the interfaces are assigned to different areas, which is already the case. Commands like area range are used for summarization but do not enable ABR.

The router ID is necessary for OSPFv3 operation but not for ABR functionality. Therefore, no additional command is required to make the router an ABR.

Exam trap

The trap here is assuming that a specific command enables ABR functionality, when in fact ABR status is automatic based on interface area assignments.

92
MCQhard

A network administrator is configuring OSPF on a Cisco router. The router is connected to two different OSPF areas: Area 0 and Area 1. The administrator wants to summarize routes from Area 1 into Area 0. Which command should be used on the Area Border Router (ABR) to accomplish this?

A.summary-address 10.1.0.0 255.255.0.0
B.ip summary-address ospf 1 10.1.0.0 255.255.0.0
C.area 1 range 10.1.0.0 255.255.0.0
D.area 0 range 10.1.0.0 255.255.0.0
AnswerC

The 'area 1 range' command is used on an ABR to summarize inter-area routes from the specified area into other areas. It must be configured on the ABR, and the area specified is the source area (Area 1). This command aggregates routes from Area 1 into a single summary LSA that is advertised into Area 0. It is the correct method for inter-area route summarization in OSPF, reducing the size of the link-state database and routing tables in the backbone.

Why this answer

Inter-area route summarization in OSPF is performed on ABRs using the 'area range' command. The area specified is the source area from which routes are summarized. In this case, routes from Area 1 are summarized before being advertised into Area 0.

This reduces the number of LSAs and routing entries, improving scalability. The other commands either summarize external routes or apply to the wrong area, and thus do not meet the requirement.

Exam trap

The trap here is confusing inter-area summarization with external summarization, leading to the use of 'summary-address' instead of 'area range'.

93
MCQhard

A network administrator is troubleshooting an OSPFv3 network. Router R1 is configured with the following: ipv6 unicast-routing interface GigabitEthernet0/0 ipv6 address 2001:DB8:1::1/64 ipv6 ospf 1 area 0 ipv6 ospf network point-to-point ! router ospf 1 router-id 1.1.1.1 ! R1 is not forming an adjacency with R2, which is configured with: interface GigabitEthernet0/0 ipv6 address 2001:DB8:1::2/64 ipv6 ospf 1 area 0 ipv6 ospf network broadcast ! router ospf 1 router-id 2.2.2.2 What is the most likely reason for the adjacency failure?

A.The router-id must be the same on both routers for an adjacency to form.
B.OSPFv3 requires the use of link-local addresses for adjacency formation, and they are not configured.
C.OSPFv3 requires the router-id to be configured under the interface, not under the router ospf process.
D.The network type mismatch (point-to-point vs. broadcast) prevents the routers from forming an adjacency.
AnswerD

OSPF network types must match on both sides of a link for an adjacency to form. R1 is configured as point-to-point, while R2 is broadcast. This mismatch causes hello packets to be interpreted differently, and the adjacency will not form. Both routers must use the same network type, either point-to-point or broadcast.

Why this answer

OSPF network types must be consistent on both ends of a link for an adjacency to form. R1 is configured with ipv6 ospf network point-to-point, while R2 uses broadcast. This mismatch leads to differing hello packet handling and prevents the adjacency.

To resolve, configure both interfaces with the same network type, either point-to-point or broadcast.

Exam trap

The trap here is assuming that OSPFv3 automatically negotiates network type or that link-local addresses must be manually configured, when the real issue is the mismatch in network type.

94
MCQeasy

A network engineer is configuring a Cisco IOS-XE router for DMVPN Phase 3. The engineer wants to ensure that spoke-to-spoke traffic flows directly between spokes without traversing the hub. Which technology should be used to achieve this?

A.NHRP redirect and NHRP shortcut
B.NHRP shortcut only
C.NHRP redirect only
D.Multicast NHRP mapping
AnswerA

In DMVPN Phase 3, NHRP redirect is configured on the hub to inform spokes of a better path, and NHRP shortcut is configured on the spokes to allow them to dynamically build direct tunnels to other spokes. This combination enables spoke-to-spoke traffic to bypass the hub, reducing latency and hub load. This is the correct solution for the scenario.

Why this answer

DMVPN Phase 3 uses NHRP redirect on the hub and NHRP shortcut on the spokes to enable direct spoke-to-spoke tunnels. Redirect informs spokes of a better path, and shortcut allows them to establish direct tunnels. Both are required to achieve the desired traffic flow without traversing the hub.

Exam trap

The trap here is thinking that NHRP redirect alone or shortcut alone can enable direct spoke-to-spoke communication, when both are needed in Phase 3.

95
MCQmedium

A network engineer is deploying DMVPN Phase 3 with OSPF over the tunnel interface. The hub router must summarize all spoke routes into a single /24 prefix before advertising them into the corporate OSPF domain. The engineer configures `area 0 range 10.10.0.0 255.255.255.0` on the hub's ABR. After applying the configuration, spoke routes are still advertised individually. Which action resolves the issue?

A.Configure `ip ospf database-filter all out` on the hub tunnel interface to suppress individual LSAs and allow the summary to propagate.
B.Configure the `area 0 range 10.10.0.0 255.255.255.0` command on the hub router's tunnel interface instead of the global OSPF process.
C.Change the OSPF network type on the hub tunnel interface to point-to-multipoint and reapply the `area 0 range` command.
D.Ensure the hub router is an ABR by placing the tunnel interface in a different area than the corporate domain, then apply the `area X range` command for that area.
AnswerD

OSPF area summarization is performed by an ABR on routes entering the backbone. If the tunnel interface belongs to the same area as the corporate domain, the hub is not an ABR and cannot generate summary LSAs. Placing the tunnel in a separate area makes the hub an ABR, allowing `area X range` to summarize spoke routes before advertising them.

Why this answer

Inter-area route summarization in OSPF requires the router to be an ABR, meaning it must have interfaces in at least two areas. The `area range` command only takes effect on an ABR for routes from the specified area. If the hub's tunnel and corporate interfaces are in the same area, no summary LSA is generated, so the spoke routes are advertised individually.

Exam trap

The trap here is assuming that the `area range` command works on any router regardless of its ABR status, when it only generates summary LSAs on a router that is an ABR for the specified area.

96
MCQeasy

A network technician is configuring a static route on a Cisco router to reach a remote network. The technician wants the route to be used only if the primary path fails. Which type of static route should be configured?

A.Floating static route
B.Directly connected static route
C.Recursive static route
D.Default static route
AnswerA

A floating static route is configured with a higher administrative distance than the primary route, so it is only installed in the routing table if the primary route fails. This makes it ideal as a backup path. The technician can specify an administrative distance greater than that of the dynamic routing protocol or the primary static route.

Why this answer

A floating static route uses a higher administrative distance to remain inactive until the primary route is lost. This allows it to serve as a backup. Default, recursive, and directly connected static routes do not provide this conditional failover behavior.

The floating static route is the correct choice for a backup path.

Exam trap

The trap here is confusing a floating static route with a default static route, thinking that a default route automatically acts as a backup.

97
MCQmedium

A network engineer is troubleshooting an OSPFv3 network. Router R1 is an ABR connected to Area 0 and Area 1. Area 1 is configured as a totally stubby area. R1 is not injecting a default route into Area 1, and routers in Area 1 cannot reach external destinations. Which command should the engineer verify on R1 to ensure that a default route is generated into Area 1?

A.`summary-address` under the OSPFv3 process.
B.`area 1 stub no-summary` under the OSPFv3 process.
C.`default-information originate` under the OSPFv3 process.
D.`area 1 nssa no-summary` under the OSPFv3 process.
AnswerB

To configure a totally stubby area in OSPFv3, the ABR must have the `area 1 stub no-summary` command. This setting prevents the ABR from flooding type 3 summary LSAs into the area and automatically generates a default route (inter-area-prefix LSA) into the stub area. If this command is missing, the ABR will not inject a default route, and routers in Area 1 will lack a path to external destinations.

Why this answer

In OSPFv3, a totally stubby area is configured on the ABR with the `area <area-id> stub no-summary` command. This command blocks type 3 summary LSAs and causes the ABR to inject a default route (inter-area-prefix LSA) into the area. Without it, routers in the area have no default route and cannot reach external networks.

The engineer should verify that this command is present on R1.

Exam trap

The trap here is confusing stub area default route generation with the `default-information originate` command, which is used for external default routes, not intra-area default routes in stub areas.

98
MCQeasy

A network technician is configuring a Cisco IOS router to authenticate EIGRP neighbors using MD5. The router is running EIGRP AS 10. Which command enables MD5 authentication for EIGRP on an interface?

A.ip authentication mode eigrp 10 md5
B.authentication mode eigrp 10 md5
C.ip eigrp authentication md5
D.ip authentication key-chain eigrp 10 md5
AnswerA

This command, entered in interface configuration mode, enables MD5 authentication for EIGRP AS 10 on that interface. It specifies that EIGRP packets must be authenticated using MD5. After enabling this, you must also configure a key chain and apply it with ip authentication key-chain eigrp 10. This is the correct first step to enable MD5 authentication for EIGRP on an interface.

Why this answer

To enable MD5 authentication for EIGRP on an interface, you must use the ip authentication mode eigrp AS-number md5 command in interface configuration mode. This sets the authentication mode to MD5. You must also configure a key chain with keys and apply it using ip authentication key-chain eigrp AS-number key-chain-name.

Both sides of the link must have matching key configurations.

Exam trap

The trap here is confusing the command to set the authentication mode with the command to apply the key chain, or omitting the ip prefix.

99
MCQhard

A network engineer is configuring OSPFv2 on a multiaccess segment. The engineer wants to ensure that the designated router (DR) election is deterministic and that a specific router becomes the DR. The router has the highest OSPF priority on the segment, but it is not becoming the DR. What could be the reason?

A.The router is configured with a higher OSPF priority but is not the DR because of a mismatch in OSPF network types.
B.The router's OSPF priority is set to 0.
C.The router is not the first to be powered on, and a DR has already been elected.
D.The router's router ID is lower than another router's router ID.
AnswerC

OSPF DR election is not preemptive. Once a DR is elected, it remains DR until it fails or the OSPF process is restarted. If another router was elected DR first, the router with the highest priority will not take over even if it comes online later. To force a new election, you must restart the OSPF process or shut down the interfaces. Thus, this is the most likely reason.

Why this answer

OSPF DR election is non-preemptive. Once a DR is elected, it retains the role until it fails or the OSPF process restarts. Even if a router with a higher priority joins the segment later, it will not preempt the existing DR.

Therefore, the most likely reason is that a DR was already elected before this router became active. To force a new election, the OSPF process must be restarted or the interfaces reset.

Exam trap

The trap here is assuming that OSPF DR election is preemptive based on priority, when in fact it is not; a new higher-priority router will not become DR unless the current DR fails.

100
MCQmedium

A network engineer is configuring OSPF on a router that connects to a service provider via a WAN link. The provider requires that the link be treated as a point-to-point connection without DR/BDR election, and the OSPF network type must be explicitly set to achieve this. Which command should be applied to the interface?

A.ip ospf network broadcast
B.ip ospf network point-to-multipoint
C.ip ospf network point-to-point
D.ip ospf network non-broadcast
AnswerC

This command sets the OSPF network type to point-to-point, which eliminates DR/BDR election and allows immediate adjacency formation. It is appropriate for a WAN link where the provider expects point-to-point behavior. By default, point-to-point networks send Hellos every 10 seconds and have no DR/BDR, reducing overhead and speeding convergence.

Why this answer

The requirement is to treat the WAN link as a point-to-point connection without DR/BDR election. The ip ospf network point-to-point command achieves this by setting the OSPF network type to point-to-point, which disables DR/BDR election and allows direct adjacency formation. This is the standard configuration for point-to-point WAN links in OSPF.

Exam trap

The trap here is assuming that any network type without DR/BDR election (like point-to-multipoint) is suitable, but only point-to-point matches the provider's requirement for a single point-to-point link.

101
MCQmedium

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (10.1.1.1/24) and GigabitEthernet0/1 (10.2.2.1/24). The engineer wants traffic from the 10.1.1.0/24 subnet destined to 192.168.1.0/24 to be forwarded out GigabitEthernet0/1 instead of following the routing table, which points to GigabitEthernet0/0. Which configuration sequence correctly implements this requirement?

A.Create a route map that matches the source subnet and sets the next-hop to 10.2.2.2, then apply it to interface GigabitEthernet0/0 with the ip policy route-map command.
B.Create an access list that permits the source subnet, apply it to interface GigabitEthernet0/1 with the ip access-group command, and set the default gateway to 10.2.2.2.
C.Configure a static route for 192.168.1.0/24 pointing to 10.2.2.2 with a lower administrative distance, and redistribute it into the routing protocol.
D.Enable PBR globally with the ip policy route-map command in global configuration mode, and reference a route map that sets the interface to GigabitEthernet0/1.
AnswerA

This is correct because PBR requires a route map to define match criteria (source subnet) and set actions (next-hop). Applying it inbound on the ingress interface GigabitEthernet0/0 ensures packets from 10.1.1.0/24 are policy-routed before the routing table is consulted. The next-hop 10.2.2.2 must be reachable via the interface the packet is forwarded out, which is GigabitEthernet0/1.

Why this answer

Policy-based routing allows the engineer to override the destination-based routing table by matching source addresses and setting a next-hop. The route map must be applied inbound on the interface where traffic enters the router. The set next-hop must point to a device reachable via the desired egress interface.

This ensures only the specified source subnet is policy-routed, while other traffic follows normal routing.

Exam trap

The trap here is assuming that an access list or static route can achieve source-based forwarding; PBR specifically requires a route map applied to an interface.

102
Multi-Selectmedium

A network engineer is troubleshooting a DMVPN Phase 3 network using Cisco IOS XE routers. The hub router is configured with a multipoint GRE tunnel and NHRP. Spoke routers are unable to establish direct spoke-to-spoke tunnels. Which two statements describe the correct operation of DMVPN Phase 3 that could explain the issue? (Choose two.)

Select 2 answers
A.Spokes must be configured with the ip nhrp network-id command matching the hub.
B.The hub must be configured with the ip nhrp map multicast dynamic command.
C.The hub must be configured with the ip nhrp redirect command to support Phase 3.
D.The hub must be configured with the ip nhrp authentication command.
E.Spokes must be configured with the ip nhrp shortcut command to support Phase 3.
AnswersC, E

In DMVPN Phase 3, the hub must have ip nhrp redirect configured to inform spokes when a better path exists. When the hub receives a packet from a spoke and forwards it to another spoke, it sends an NHRP redirect message to the originating spoke, prompting it to initiate a direct tunnel. Without this command, spokes will not receive the redirect and will continue to route through the hub, preventing direct spoke-to-spoke tunnels.

Why this answer

In DMVPN Phase 3, the hub must be configured with ip nhrp redirect, and spokes must be configured with ip nhrp shortcut. The redirect command allows the hub to notify spokes of a better path, while the shortcut command enables spokes to act on those notifications and establish direct tunnels. Without these, spoke-to-spoke traffic will continue to traverse the hub, even if other NHRP settings are correct.

Exam trap

The trap here is assuming that any NHRP configuration error would cause the same symptom, when in fact Phase 3 requires specific commands on both hub and spokes.

103
MCQmedium

A network engineer at a branch office is configuring OSPFv3 on a dual-stack router. The router must form an adjacency with a neighboring router that is also running OSPFv3. The engineer notices that the neighbor relationship remains in EXSTART state. Which command should be used to verify the OSPFv3 interface parameters that could cause this issue?

A.show ipv6 ospf interface
B.show ipv6 protocols
C.show ipv6 ospf neighbor
D.show ipv6 ospf database
AnswerA

This command displays OSPFv3 interface parameters such as network type, hello interval, dead interval, and MTU, which are critical for adjacency formation. In this scenario, a mismatch in MTU or network type can cause the neighbor to stall in EXSTART. Therefore, this command is the correct choice to verify those parameters.

Why this answer

The correct answer is the command that displays OSPFv3 interface parameters. EXSTART state issues in OSPFv3 are commonly caused by MTU mismatches or network type mismatches. The 'show ipv6 ospf interface' command provides these details, allowing the engineer to compare and correct the configuration.

Other commands show neighbor status, database, or protocol summary but lack interface parameter details.

Exam trap

The trap here is assuming that 'show ipv6 ospf neighbor' provides enough detail to diagnose EXSTART issues, when it only shows the state without the interface parameters causing the problem.

104
MCQhard

A network engineer is implementing policy-based routing (PBR) on a Cisco router. The goal is to forward traffic from a specific source subnet to a next-hop that is not the default gateway. The engineer configures a route map with a match statement for the source subnet and a set statement for the next-hop. However, the traffic is still following the default route. What is the most likely reason?

A.The set statement is using an incorrect next-hop address.
B.The route map is missing a permit statement.
C.The ip policy route-map command is not configured on the ingress interface.
D.The route map is not applied to the correct interface.
AnswerC

For PBR to work, the route map must be applied to the ingress interface using the ip policy route-map command. If this command is missing, the route map will not be evaluated, and traffic will be forwarded based on the routing table. This is a common oversight. The engineer must enter interface configuration mode and apply the route map to the interface where traffic enters the router. Without this step, PBR will not function.

Why this answer

Policy-based routing requires the route map to be applied to the ingress interface with the ip policy route-map command. Without this command, the route map is not evaluated, and traffic is forwarded using the normal routing table, which explains why traffic follows the default route. Other issues, such as an incorrect next-hop or missing permit statement, would cause different symptoms, such as traffic being dropped or sent to the wrong next-hop, but not reverting to the default route.

Exam trap

The trap here is assuming that configuring the route map alone is sufficient for PBR, when actually it must be explicitly applied to an interface.

105
MCQhard

A network engineer is troubleshooting a DMVPN Phase 3 network using OSPF. Spoke routers are unable to form OSPF adjacencies with each other directly, even though they can reach the hub. The engineer wants to enable direct spoke-to-spoke communication. Which configuration is required on the hub?

A.ip nhrp redirect
B.ip nhrp shortcut
C.ip nhrp map multicast dynamic
D.ip nhrp network-id 1
AnswerA

In DMVPN Phase 3, the hub must be configured with ip nhrp redirect to send NHRP redirect messages to spokes when it receives traffic that could be sent directly between spokes. This allows the hub to inform the originating spoke of a better path, enabling direct spoke-to-spoke tunnels. Without this, spokes continue to route through the hub.

Why this answer

In DMVPN Phase 3, the hub must have ip nhrp redirect to send redirect messages to spokes, enabling them to establish direct tunnels. Spokes require ip nhrp shortcut to act on those redirects. The other options are either configured on spokes or are basic NHRP settings not specific to enabling spoke-to-spoke communication.

Exam trap

The trap here is confusing the roles of ip nhrp redirect and ip nhrp shortcut, placing shortcut on the hub instead of the spokes.

106
MCQhard

A network engineer is troubleshooting a DMVPN Phase 3 network using Cisco IOS XE routers. The hub router (Hub1) has a public IP of 203.0.113.1 and is configured with `tunnel mode gre multipoint`. Spoke routers are behind NAT devices. Spoke1 cannot establish a direct spoke-to-spoke tunnel with Spoke2, although both can reach the hub. Which technology must be enabled on the hub to allow spoke-to-spoke direct tunnels in this scenario?

A.NHRP shortcut
B.Multicast routing
C.NHRP redirect
D.IPsec tunnel protection
AnswerC

NHRP redirect allows the hub to inform spokes about a more optimal path to another spoke. When Spoke1 sends traffic to Spoke2 via the hub, the hub sends an NHRP redirect message, prompting Spoke1 to initiate a direct tunnel. This is essential for Phase 3 DMVPN, especially with NAT, as it enables dynamic spoke-to-spoke tunnels without preconfiguration.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to notify spokes of a better path to another spoke. When Spoke1 sends traffic to Spoke2 via the hub, the hub sends an NHRP redirect, and Spoke1 then initiates a direct tunnel using NHRP shortcut. This is critical when spokes are behind NAT, as the hub facilitates the initial resolution and redirect.

Exam trap

The trap here is confusing NHRP redirect (hub) with NHRP shortcut (spoke) and assuming that IPsec or multicast alone can enable spoke-to-spoke tunnels.

107
MCQmedium

A network engineer is configuring OSPF on a Cisco router. The router has two interfaces in Area 0: GigabitEthernet0/0 (10.1.1.1/24) and GigabitEthernet0/1 (10.2.2.1/24). The engineer wants to ensure that the router ID is always 10.1.1.1, regardless of interface status. Which command should be used?

A.router ospf 1 then router-id 10.1.1.1
B.ospf router-id 10.1.1.1
C.router-id 10.1.1.1
D.ip ospf router-id 10.1.1.1
AnswerA

Entering OSPF configuration mode with 'router ospf 1' and then issuing 'router-id 10.1.1.1' explicitly sets the router ID. This method is preferred because it does not depend on interface IP addresses, ensuring the router ID remains 10.1.1.1 even if interfaces change or go down.

Why this answer

The engineer needs a stable OSPF router ID that remains 10.1.1.1 regardless of interface status. The only way to guarantee this is to explicitly configure the router ID under the OSPF process using the 'router-id' command. Relying on interface IP addresses can lead to changes if interfaces are removed or shut down.

Exam trap

The trap here is assuming that the highest loopback or interface IP will always be used as the router ID, but explicit configuration overrides that and ensures persistence.

108
MCQmedium

A network administrator is implementing MPLS Layer 3 VPNs. The administrator wants to ensure that customer routes are not leaked between different VRFs on the same PE router. Which mechanism should be used to isolate the VRFs?

A.BGP communities
B.Route distinguishers
C.Route targets
D.MPLS labels
AnswerC

Route targets are extended BGP communities used to control the import and export of routes between VRFs. By assigning unique route targets to each VRF, you ensure that routes from one VRF are not imported into another. This provides the necessary isolation. Without proper route target configuration, routes could leak. Therefore, route targets are the correct mechanism.

Why this answer

Route targets are extended BGP communities that define which VRFs can import and export routes. By configuring distinct route targets for each VRF, you control route distribution and prevent leaking. Route distinguishers only make prefixes unique, MPLS labels are for forwarding, and standard BGP communities are not specific to VRF isolation.

Exam trap

The trap here is confusing route distinguishers with route targets; RDs make prefixes unique, but route targets control import/export.

109
MCQeasy

A network technician is configuring a static route on a Cisco IOS router. The requirement is to forward all traffic destined to the 192.168.1.0/24 network to the next-hop IP address 10.1.1.1. Which command accomplishes this?

A.ip route 192.168.1.0 255.255.255.0 10.1.1.1 name STATIC
B.ip route 192.168.1.0 255.255.255.0 10.1.1.1 255
C.ip route 192.168.1.0 255.255.255.0 10.1.1.1 1
D.ip route 192.168.1.0 255.255.255.0 10.1.1.1
AnswerD

This command correctly configures a static route for the 192.168.1.0/24 network with a next-hop of 10.1.1.1. The subnet mask 255.255.255.0 corresponds to /24, and the next-hop is specified as an IP address. This is the standard syntax for a static route on Cisco IOS.

Why this answer

The standard syntax for a static route on Cisco IOS is 'ip route prefix mask next-hop'. The command 'ip route 192.168.1.0 255.255.255.0 10.1.1.1' correctly specifies the destination network, subnet mask, and next-hop IP address. Adding a distance metric or name is optional and not required for basic functionality.

Exam trap

The trap here is overcomplicating the command by adding unnecessary parameters like a distance metric or name when the basic syntax suffices.

110
MCQmedium

A network engineer is configuring a GRE tunnel between two Cisco IOS-XE routers to transport multicast traffic. The engineer notices that multicast packets are not being forwarded through the tunnel. Which action should the engineer take to enable multicast over the GRE tunnel?

A.Increase the tunnel MTU to accommodate multicast packets, as fragmentation prevents multicast forwarding.
B.Configure the tunnel mode to gre multipoint to support multicast.
C.Enable IP multicast routing globally and configure PIM on the tunnel interface and the physical interface.
D.Set the tunnel interface to ip pim sparse-dense-mode and enable ip multicast-routing on the physical interface only.
AnswerC

GRE tunnels can carry multicast traffic if multicast routing is enabled. You must enable ip multicast-routing globally and configure PIM (e.g., PIM sparse-mode) on both the tunnel interface and the underlying physical interface. This allows multicast packets to be encapsulated and forwarded through the tunnel. Without PIM on the tunnel, multicast traffic will not be routed.

Why this answer

To transport multicast over a GRE tunnel, multicast routing must be enabled globally, and PIM must be configured on both the tunnel interface and the physical interface. This allows the router to forward multicast packets into the tunnel and out the physical interface. The other options either misconfigure PIM, use an unnecessary tunnel mode, or address an unrelated MTU issue.

Exam trap

The trap here is assuming that GRE tunnels automatically carry multicast traffic, when in fact multicast routing and PIM must be explicitly enabled on both the tunnel and physical interfaces.

111
MCQeasy

A network engineer is configuring a Cisco IOS router as a DHCP relay agent. The router's interface GigabitEthernet0/0 is connected to a client subnet, and the DHCP server is located at 10.1.1.100. The engineer wants the router to forward DHCP requests from clients to the server and ensure that the server can assign addresses from the correct pool. Which command is required on the router?

A.`ip helper-address 10.1.1.100` on interface GigabitEthernet0/0
B.`ip dhcp relay information option` globally
C.`ip forward-protocol udp 67` on interface GigabitEthernet0/0
D.`ip dhcp pool CLIENT` and `network 192.168.1.0 /24`
AnswerA

The `ip helper-address` command configures the router to forward UDP broadcasts, including DHCP requests (UDP port 67), to the specified server. This allows the DHCP server to receive the request and assign an address from the appropriate pool based on the gateway address (giaddr) set by the router. This is the correct and standard way to configure a DHCP relay agent on Cisco IOS.

Why this answer

To configure a Cisco IOS router as a DHCP relay agent, the `ip helper-address` command must be applied on the interface facing the DHCP clients. This command forwards DHCP broadcast requests to the specified DHCP server, allowing the server to assign addresses from the correct pool based on the incoming interface's IP address. Without this command, DHCP requests would not reach the server, and clients would not obtain IP addresses.

Exam trap

The trap here is confusing the DHCP relay agent configuration with DHCP server or Option 82 commands, which are not required for basic relay functionality.

← PreviousPage 2 of 2 · 111 questions total

Ready to test yourself?

Try a timed practice session using only Layer 3 Technologies questions.