Courseiva

300-410 · domain

troubleshooting

Practise Cisco CCNP ENARSI 300-410 troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

1401 questions241 easy703 medium457 hard

Focused practice

Practice troubleshooting questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about troubleshooting

troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common troubleshooting exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All troubleshooting questions (1401)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO statements about NetFlow version 9 and Flexible NetFlow are true? (Choose TWO.)

Medium
2

Which TWO configuration steps are required to apply an IPv4 extended access list to an interface in Cisco IOS? (Choose TWO.)

Medium
3

A network engineer runs the following command on Router R1: R1# show ip policy Interface Route-map GigabitEthernet0/0 PBR-TEST R1# show route-map PBR-TEST route-map PBR-TEST, permit, sequence 10 Match clauses: ip address (access-lists): 110 Set clauses: ip next-hop 192.168.100.1 Policy routing matches: 0 packets, 0 bytes R1# show access-lists 110 Extended IP access list 110 10 permit tcp 10.0.0.0 0.255.255.255 any eq 80 20 permit tcp 10.0.0.0 0.255.255.255 any eq 443 R1# show ip route 192.168.100.1 Routing entry for 192.168.100.1/32 Known via "ospf 1", distance 110, metric 20 Last update from 10.1.1.2 on GigabitEthernet0/1 Based on this output, what is the most likely reason for zero policy routing matches?

Medium
4

A network engineer runs the following command on Router R1: R1# show ip eigrp topology 10.10.10.0/24 EIGRP-IPv4 Topology Entry for AS(100)/ID(192.168.1.1) for 10.10.10.0/24 State: Passive, Reply status: 0, Originating router: 192.168.1.1 Routing Descriptor Blocks: 0.0.0.0 (Null0) from 0.0.0.0, Send flag: 0x0 Composite metric: (2560000000/0), Route is Internal Vector metric: Minimum bandwidth: 100000 Kbit Total delay: 100 microseconds Reliability: 255/255 Load: 1/255 Minimum MTU: 1500 Hop count: 0 Based on this output, what is the problem?

Hard
5

A network engineer is configuring a Cisco IOS XE router to act as a DHCPv6 relay agent. The router is connected to a LAN segment with DHCPv6 clients and must forward DHCPv6 messages to a DHCPv6 server at 2001:DB8::100. The engineer has configured the interface with ipv6 address 2001:DB8:1::1/64 and ipv6 enable. Which command is required to enable DHCPv6 relay on the interface?

Hard
6

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer enters the following commands: interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 C1sco123 After applying the configuration, the OSPF neighbor relationship fails to form. Which action must the engineer take to resolve the issue?

Medium
7

Drag and drop the steps to troubleshoot suboptimal routing due to incorrect Administrative Distance values into the correct order, from first to last.

Medium
8

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 connecting to the internet (untrusted) and GigabitEthernet0/1 connecting to the internal network (trusted). The engineer wants to enable strict uRPF on the untrusted interface. Which command should be applied to GigabitEthernet0/0?

Medium
9

A network administrator is deploying a site-to-site VPN using Cisco IOS GET VPN (Group Encrypted Transport VPN) on a service provider MPLS network. The administrator must ensure that the group members can communicate securely while maintaining any-to-any connectivity and minimizing tunnel overhead. Which two statements about GET VPN are true? (Choose two.)

Hard
10

Which BGP message type is used to advertise, withdraw, and update routes?

Easy
11

A network engineer is troubleshooting an OSPFv2 issue where a router R1 is not receiving a specific route for 10.0.0.0/8 from a neighbor R2. The adjacency is FULL, and 'show ip ospf database' on R1 shows the LSA for 10.0.0.0/8 as a type 5 LSA. However, the route is not in the routing table. 'show ip route 10.0.0.0' shows no route. What is the most likely cause?

Hard
12

A network engineer is implementing CoPP on a Cisco router to protect the control plane from DoS attacks. The engineer wants to rate-limit ICMP echo requests destined to the router's management IP address. Which CoPP policy component is responsible for defining the traffic classification?

Hard
13

A network engineer is configuring a Cisco IOS router to authenticate a branch office VPN client with a digital certificate. The certificate is issued by an external CA, and the engineer must ensure that the router can validate the certificate chain. Which command is required to install the CA certificate?

Medium
14

What is the default timeout value (in milliseconds) for an IP SLA operation?

Easy
15

Which TWO configuration steps are required to enable IPv6 RA Guard on a Cisco switch interface? (Choose TWO.)

Hard
16

A network engineer runs the following command on Router R1: R1# show snmp statistics SNMP packets input: 150 Bad SNMP version errors: 0 Unknown community name: 25 Illegal operation for community name: 0 Encoding errors: 0 Number of requested variables: 300 Number of altered variables: 0 Get-request PDUs: 120 Get-next PDUs: 30 Set-request PDUs: 0 SNMP packets output: 200 Too big errors: 0 No such name errors: 10 Bad values errors: 0 General errors: 0 Response PDUs: 200 Trap PDUs: 0 Based on this output, which statement is correct?

Hard
17

A large enterprise network uses EIGRP with route summarization. Router R1 has the following configuration: interface GigabitEthernet0/0, ip summary-address eigrp 100 10.0.0.0 255.255.252.0. Router R2 shows: show ip route eigrp includes 10.0.0.0/22 but not 10.0.3.0/24. What is the root cause?

Hard
18

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 10.5.5.0/24 BGP routing table entry for 10.5.5.0/24, version 12 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 65007 10.1.17.7 from 10.1.17.7 (10.7.7.7) Origin IGP, metric 0, localpref 100, valid, external, best rx pathid: 0, tx pathid: 0x0 Based on this output, what does the 'r' in the status codes indicate if present? (Not shown here, but the engineer notices a similar route with 'r' status.)

Medium
19

Which TWO statements about MPLS label imposition (push) are true? (Choose TWO.)

Medium
20

A network engineer is implementing Zone-Based Policy Firewall (ZPFW) on a Cisco IOS router. The router has three interfaces: inside, outside, and DMZ. The engineer wants to allow HTTP traffic from the inside zone to the DMZ zone, and block all other traffic from inside to DMZ. Which configuration is required?

Medium
21

In BGP, what is the default administrative distance for eBGP routes?

Easy
22

A network engineer runs the following command on Router R1: R1# show ip ospf database summary 172.16.0.0 OSPF Router with ID (1.1.1.1) (Process ID 1) Summary Net Link States (Area 0) LS age: 100 Options: (No TOS-capability, DC) LS Type: Summary Links(Network) Link State ID: 172.16.0.0 (Summary Network Number) Advertising Router: 2.2.2.2 LS Seq Number: 80000001 Checksum: 0x1234 Length: 28 Network Mask: /20 TOS: 0 Metric: 10 Based on this output, what does this LSA represent?

Medium
23

A network engineer runs the following command on Router R1: R1# show ip access-lists Extended IP access list 170 10 permit icmp any any echo (100 matches) 20 permit icmp any any echo-reply (80 matches) 30 deny ip any any (10 matches) Based on this output, which statement is correct?

Medium
24

A network engineer runs the following command on Router R1: R1# show ip sla statistics 1 IPSLAs Latest Operation Statistics IPSLA operation id: 1 Type of operation: icmp-echo Latest RTT: 10 milliseconds Latest operation start time: 00:15:30 UTC Mon Mar 1 2021 Latest operation return code: OK Number of successes: 100 Number of failures: 0 Operation time to live: Forever Based on this output, which statement is correct?

Easy
25

A network engineer runs the following command on Router R1: R1# show mpls ldp neighbor Peer LDP Ident: 192.168.2.2:0, Local LDP Ident: 192.168.1.1:0 TCP connection: 10.1.1.2.646 - 10.1.1.1.646 State: Oper; Msgs sent/rcvd: 100/100; Downstream Up time: 00:45:00 LDP discovery sources: GigabitEthernet0/0, Src IP addr: 10.1.1.2 Addresses bound to peer LDP Ident: 10.1.1.2 192.168.2.2 Based on this output, what is the state of the LDP session?

Medium
26

A network engineer is configuring an MPLS L3VPN on a Cisco IOS XE PE router. The customer edge (CE) router uses eBGP to peer with the PE router. The engineer wants to ensure that the CE can advertise its routes to the PE and that the PE can propagate them to other PE routers via MP-BGP. The engineer has configured the VRF, the PE-CE eBGP session, and MP-BGP on the PE. However, the routes from the CE are not appearing in the MP-BGP table. Which configuration step is most likely missing on the PE router?

Hard
27

Consider the following EIGRP configuration on Router R1: router eigrp 100 network 10.0.0.0 passive-interface default no passive-interface GigabitEthernet0/0 What is the effect of this configuration?

Medium
28

A network engineer runs the following command to verify BFD operation: R1# show bfd neighbors detail IPv4 Sessions NeighAddr LD/RD RH/RS State Int 10.1.1.2 1/2 Up Up Gi0/0 Session state is UP and not using echo function. Session type: single-hop Local Diag: 0, Demand mode: 0, Poll bit: 0 MinTxInt: 1000000, MinRxInt: 1000000, Multiplier: 3 Received MinRxInt: 1000000, Received Multiplier: 3 Holddown (hits): 0 (0), Hello (hits): 1000/5 Rx Count: 1000, Rx Interval (ms) min/max/avg: 900/1100/1000 Tx Count: 1000, Tx Interval (ms) min/max/avg: 900/1100/1000 What does this output indicate?

Medium
29

A network engineer is configuring a Cisco IOS XE router to support First Hop Redundancy Protocol (FHRP) for a group of hosts on VLAN 10. The design requires that the virtual IP address and virtual MAC address remain the same even if the active router changes. The engineer decides to use Virtual Router Redundancy Protocol (VRRP) version 2. Which statement about VRRPv2 is true?

Medium
30

A network engineer is troubleshooting a dual-stack Cisco IOS XE router that runs OSPFv3 for IPv6 and OSPFv2 for IPv4. IPv4 adjacencies form and routes are exchanged, but no OSPFv3 adjacencies form and no IPv6 routes appear. The engineer verifies that the interfaces have IPv6 addresses and that `ipv6 unicast-routing` is enabled. Which configuration step is most likely missing?

Medium
31

What is the default behavior of an IPv4 access control list (ACL) when no explicit permit or deny statement matches a packet?

Easy
32

A network engineer is implementing policy-based routing (PBR) on a Cisco IOS router. The engineer wants to route traffic from the 10.1.1.0/24 subnet to a next-hop of 192.168.1.1, while all other traffic uses the default routing table. Which configuration correctly implements this?

Medium
33

A network engineer is troubleshooting a route redistribution issue between OSPF and EIGRP. Routers R1 (OSPF) and R2 (EIGRP) are redistributing routes into each other. The engineer notices that some OSPF external routes are not appearing in the EIGRP topology table on R2, although the redistribution is configured. The show ip eigrp topology command on R2 does not list the missing prefixes. What is the most likely cause?

Medium
34

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on an interface. Traffic from a legitimate source IP is being dropped. The network has asymmetric routing. Which is the most likely explanation?

Hard
35

A network engineer is configuring a Cisco IOS XE router as a Dynamic Multipoint VPN (DMVPN) Phase 3 hub. The hub must support spoke-to-spoke direct tunnels while allowing the hub to remain in the data path for initial spoke-to-spoke communication. The engineer has configured the tunnel interface with 'ip nhrp redirect' on the hub. Which additional command must be configured on the spoke routers to enable them to dynamically create direct tunnels to other spokes?

Medium
36

A network engineer runs the following command to troubleshoot a BGP Troubleshooting issue: R1# show bgp neighbors 10.1.1.2 received-routes BGP table version is 14, local router ID is 1.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.0.0.0/24 10.1.1.2 0 100 0 65001 i *> 192.168.1.0/24 10.1.1.2 0 100 0 65001 i Total number of prefixes 2 What does this output indicate?

Medium
37

What is the default maximum hop count for RIP routes in Cisco IOS?

Easy
38

Which of the following is a valid 'set' action in a PBR route-map?

Easy
39

An engineer is troubleshooting a network where R1 and R2 are running iBGP, and R1 learns the prefix 192.168.1.0/24 from R2 with an AD of 200. R1 also learns the same prefix via OSPF from R3 with AD 110. The engineer notices that R1 uses the iBGP route. What configuration change would cause this?

Medium
40

In EIGRP, what is the default behavior of auto-summary in IOS-XE versions 15.0 and later?

Medium
41

A network engineer is troubleshooting an issue where IPv6 traffic is being forwarded incorrectly on a switch. The switch is configured with IPv6 Source Guard on access ports. A legitimate host on port Fa0/1 with IPv6 address 2001:db8:1::10 is unable to send traffic to the default gateway. The engineer checks the IPv6 binding table and sees that the host's entry is missing. What is the most likely cause?

Medium
42

A network engineer runs the following command on Router PE3: PE3# show ip vrf interfaces Interface IP-Address VRF Protocol Gi0/0 10.1.1.1 CUSTOMER_C up Gi0/1 10.2.2.1 CUSTOMER_D up Based on this output, which statement is correct?

Easy
43

DMVPN network with hub R1 and spoke R2. R1 has: interface Tunnel0 ip address 172.16.1.1 255.255.255.0 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ip nhrp network-id 1 ip nhrp authentication cisco123 R2 has: interface Tunnel0 ip address 172.16.1.2 255.255.255.0 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ip nhrp network-id 1 ip nhrp nhs 172.16.1.1 ip nhrp authentication cisco123 R2 shows: R2# show dmvpn Legend: Attrb -> S: Static, D: Dynamic, I: Incomplete NHRP domain: 1 Interface: Tunnel0, IPv4 NHRP Details Type:Spoke, NHC:172.16.1.2, NBMA:10.2.2.2 (no NHRP mappings) R2# ping 172.16.1.1 source 172.16.1.2 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 172.16.1.1, timeout is 2 seconds: ..... Success rate is 0 percent (0/5) What is the root cause?

Hard
44

What is missing from this RSPAN configuration on a switch? monitor session 1 source interface GigabitEthernet1/0/1 both monitor session 1 destination remote vlan 100 Assume VLAN 100 exists but is not configured as an RSPAN VLAN.

Medium
45

What is the default EIGRP hello interval on a point-to-point serial interface with bandwidth 1544 Kbps?

Easy
46

Which statement correctly describes the behavior of PBR when the next-hop specified in a 'set ip next-hop' command is unreachable?

Medium
47

An EIGRP network is experiencing a stuck-in-active (SIA) condition for a route 192.168.1.0/24. R1 has the following configuration: router eigrp 100 network 10.0.0.0 distribute-list prefix PL-FILTER in. R2 shows: 'show ip eigrp topology 192.168.1.0/24' is in active state, and 'show ip eigrp events' shows that R1 sent a query but never received a reply. R1's prefix-list PL-FILTER permits only 10.0.0.0/8. What is the root cause?

Hard
48

MPLS network: LDP neighbors are down between R1 and R2. R1 shows: show mpls ldp neighbor includes nothing. R2 has: interface GigabitEthernet0/0, mpls ip, but R1 has no mpls ip on its interface. What is the root cause?

Hard
49

A network engineer is troubleshooting PBR on a Cisco router where traffic from subnet 172.16.1.0/24 should be forwarded to next-hop 10.10.10.2. The route map 'PBR-172' is applied to interface GigabitEthernet0/0. The engineer notices that the PBR policy is not working at all. The engineer checks the route map configuration and sees 'match ip address 110' and 'set ip next-hop 10.10.10.2'. The engineer also checks the ACL 110 and confirms it matches 172.16.1.0/24. The engineer then checks the interface configuration and sees 'ip policy route-map PBR-172' applied. What should the engineer do next to isolate the issue?

Medium
50

Which loop prevention mechanism is used by default in RIP within a VRF-Lite configuration?

Medium
51

In OSPFv3, what is the purpose of the link-local address in the neighbor adjacency process?

Medium
52

A router has the following BFD configuration for a static route: ip route 10.0.0.0 255.255.255.0 192.168.1.2 bfd map 192.168.1.2 10.0.0.0 255.255.255.0 interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 bfd interval 100 min_rx 100 multiplier 3 ! What is the purpose of the 'bfd map' command in this context?

Medium
53

An engineer configured IP SLA 40 with a UDP echo probe to monitor a remote server port 80. The IP SLA is used in a track object for a backup static route. The engineer observes that the IP SLA state is 'Timeout' even though the server is reachable via ping from the router. What is the most likely cause?

Hard
54

A network engineer is configuring OSPF on a router with three interfaces: Gi0/0 (10.1.1.1/24), Gi0/1 (10.2.2.1/24), and Gi0/2 (10.3.3.1/24). The engineer wants to prevent OSPF from forming adjacencies on Gi0/2 while still advertising the 10.3.3.0/24 network into OSPF. Which configuration accomplishes this?

Medium
55

A router has CoPP configured with a class-map that matches OSPF traffic and polices it to 2000 pps. The router is also configured with an OSPF distribute-list in to filter routes. After applying CoPP, OSPF neighbors form, but routes from a specific neighbor are missing. The distribute-list permits all routes. Which is the most likely explanation?

Hard
56

What is the problem with this NAT configuration? interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip nat inside ! interface GigabitEthernet0/1 ip address 203.0.113.1 255.255.255.0 ! ip nat inside source list 1 interface GigabitEthernet0/1 overload access-list 1 permit 192.168.1.0 0.0.0.255

Medium
57

A company has a Cisco IOS XE router configured with IP SLA and Object Tracking to monitor the reachability of a primary ISP. The router should fail over to a backup ISP when the primary path becomes unreachable. The engineer wants to ensure that the failover occurs quickly and that the primary path is restored when it becomes available again. Which configuration element is required to achieve this behavior?

Medium
58

An engineer applies a CoPP policy to a router to protect the control plane from a DDoS attack. The policy includes a class-map matching UDP traffic to port 123 (NTP) and polices it to 1000 bps. After the policy is applied, the engineer notices that the router's clock is not synchronizing with its NTP server. The NTP server is reachable via ping. What is the most likely cause?

Easy
59

A network engineer runs the following command to verify DHCPv4 server bindings on router R1: R1# show ip dhcp binding Output: Bindings from all pools not associated with VRF: IP address Client-ID/ Lease expiration Type Hardware address/ User name 192.168.1.10 0050.7966.6800 Mar 01 2025 12:00 PM Automatic 192.168.1.11 0063.6973.636f.2d30 Mar 01 2025 01:00 PM Automatic 192.168.1.12 0100.1a.2b.3c.4d.5e Mar 01 2025 02:00 PM Automatic What does this output indicate?

Easy
60

A network engineer is troubleshooting a Cisco IOS router that is configured for AAA authorization. The engineer notices that users are not being authorized for certain commands even though the TACACS+ server is reachable and the user is authenticated. The configuration includes 'aaa authorization exec default group tacacs+ local' and 'aaa authorization commands 15 default group tacacs+ local'. Which issue is most likely causing the problem?

Hard
61

A network engineer is configuring a Cisco IOS XE router to support IPv6. The engineer wants to enable IPv6 routing and assign an IPv6 address to an interface. Which command must be configured globally to enable IPv6 routing?

Easy
62

A network administrator is configuring a point-to-point GRE tunnel between two Cisco routers. The administrator wants to verify that the tunnel is operational and that the correct encapsulation is being used. Which command should be used to display the tunnel interface status, including the encapsulation and tunnel source/destination?

Easy
63

A network engineer runs the following command to verify IPv6 uRPF on an interface: R1# show ipv6 interface GigabitEthernet0/0 | include verify|suppress IPv6 verify source: strict IPv6 verify source suppress: disabled What does this output indicate?

Medium
64

A network engineer configures the following on a router: ``` router eigrp 100 distance 150 10.0.0.0 0.255.255.255 ``` What is the intended effect?

Medium
65

What is the default EIGRP hold time multiplier relative to the hello interval?

Medium
66

A network engineer runs the following command to troubleshoot SNMP access lists: R1# show snmp access Access-list: 10 Community: public View: v1default Access-list: 20 Community: private View: v1default What does this output indicate?

Medium
67

A network engineer configures an IPv6 over IPv4 GRE tunnel with IPsec using a crypto map. The tunnel works for unicast traffic, but OSPFv3 over the tunnel fails to form adjacency. The engineer checks the crypto map and sees that it only matches traffic with a specific access-list. What is the most likely explanation?

Hard
68

What is the default administrative distance for a route learned via the Enhanced Interior Gateway Routing Protocol (EIGRP) summary route?

Medium
69

A router is configured with uRPF (Unicast Reverse Path Forwarding) in strict mode on an interface that belongs to a VRF. The network uses asymmetric routing for load balancing. The engineer notices that legitimate traffic from a customer is being dropped. Which is the most likely explanation?

Hard
70

A network engineer enables IPv6 First Hop Security with 'ipv6 dhcp guard' on a switch port connected to a legitimate DHCPv6 server. Clients on other ports receive DHCPv6 replies, but the server's port is being err-disabled repeatedly. The engineer checks the logs and sees DHCPv6 server advertisements being dropped. What is the most likely cause?

Hard
71

A network engineer runs the following command to troubleshoot a BGP prefix issue: R1# show bgp ipv4 unicast 192.168.10.0/24 BGP routing table entry for 192.168.10.0/24, version 5 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 Local 10.1.1.2 from 10.1.1.2 (2.2.2.2) Origin IGP, metric 0, localpref 100, valid, external, best rx pathid: 0, tx pathid: 0x0 What does this output indicate?

Easy
72

A network engineer is implementing policy-based routing (PBR) on a Cisco router. The goal is to route traffic from a specific subnet to a next-hop IP address that is not directly connected. Which configuration is required to achieve this?

Hard
73

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which type of ACL should be used in the crypto map to match this traffic?

Medium
74

A network engineer runs the following command to troubleshoot an EEM issue: R1# show event manager policy active No. Class Type Version Time Created Name 1 applet system 1.0 Mar 1 00:00:12 2025 TRACK-INTERFACE Event Type: syslog (pattern OSPF-5-ADJCHG) Action: cli command 'show ip route' What does this output indicate?

Medium
75

A network engineer is implementing policy-based routing (PBR) on a Cisco router. The goal is to forward traffic from a specific subnet to a next-hop IP address that is not directly connected, but reachable via a recursive lookup. The engineer configures a route-map with 'set ip next-hop recursive <IP>'. However, traffic is not being forwarded as expected. Which of the following is the most likely reason?

Medium
76

A network engineer is implementing FlexVPN with IKEv2 between a hub and multiple spokes. The hub uses a single IKEv2 profile and a single IPsec profile. The engineer wants to ensure that each spoke can authenticate using a unique pre-shared key. Which IKEv2 keyring configuration should be used on the hub?

Hard
77

An engineer configures Control Plane Policing (CoPP) on a router running OSPF. After applying the policy, OSPF neighbors intermittently drop and recover. The CoPP policy includes a class-map matching OSPF traffic with a police rate of 64000 bps. The router has multiple OSPF neighbors and the link utilization is normal. Which is the most likely explanation?

Hard
78

A company is deploying IPv6 and wants to use stateful DHCPv6 to assign addresses to clients. The network administrator configures the router with the 'ipv6 dhcp pool' command and sets the 'address prefix' and 'dns-server' options. However, clients are not receiving IPv6 addresses. Which additional configuration is required on the client-facing interface to enable stateful DHCPv6?

Hard
79

A network administrator is deploying FlexVPN between a Cisco IOS headend and several remote spokes. The design requires that each spoke be assigned a unique virtual IP address from a pool on the headend, and that the headend pushes a specific DNS server address to each spoke during IKEv2 negotiation. Which configuration element on the headend provides the DNS server address to the spokes?

Hard
80

A network engineer is configuring a Cisco IOS router to support IPv6 OSPFv3. The engineer wants to enable OSPFv3 on an interface and ensure that it forms adjacencies with neighbors. Which command must be used to enable OSPFv3 on an interface?

Easy
81

Examine the following partial configuration on Router R1: ``` interface Tunnel0 ipv6 address 2001:DB8:1::1/64 tunnel source GigabitEthernet0/0 tunnel destination 2001:DB8:2::2 tunnel mode ipv6ip ``` What is the effect of this configuration?

Medium
82

A network engineer is troubleshooting a route redistribution issue between EIGRP and OSPF. Routers R1 (EIGRP) and R2 (OSPF) are redistributing routes. The engineer notices that some EIGRP external routes (redistributed into EIGRP from another protocol) are not appearing in the OSPF database on R2. The show ip ospf database external command on R2 does not list these prefixes. What is the most likely cause?

Medium
83

What is the default behavior of EEM when multiple policies are registered for the same event?

Hard
84

A network engineer runs the following debug command to troubleshoot a DHCPv4 issue on router R1: R1# debug ip dhcp server events Output: DHCPD: DHCPDISCOVER received from 0050.7966.6800 on interface GigabitEthernet0/0 DHCPD: Sending DHCPOFFER to 0050.7966.6800 via GigabitEthernet0/0 DHCPD: DHCPREQUEST received from 0050.7966.6800 DHCPD: No binding found for client 0050.7966.6800 DHCPD: Adding binding for client 0050.7966.6800 DHCPD: Sending DHCPACK to 0050.7966.6800 via GigabitEthernet0/0 DHCPD: DHCPINFORM received from 0050.7966.6800 DHCPD: Sending DHCPACK to 0050.7966.6800 via GigabitEthernet0/0 What does this output indicate?

Medium
85

Which statement correctly describes the default authentication behavior for EEM policy files stored in flash?

Hard
86

A network engineer runs the following command on Router R7: R7# show logging | include %SYS-2-MALLOCFAIL *Mar 1 00:05:10.123: %SYS-2-MALLOCFAIL: Memory allocation failed for size 1024, from process 0x12345678, pool Processor *Mar 1 00:06:20.456: %SYS-2-MALLOCFAIL: Memory allocation failed for size 2048, from process 0x12345678, pool Processor *Mar 1 00:07:30.789: %SYS-2-MALLOCFAIL: Memory allocation failed for size 512, from process 0x12345678, pool Processor Based on this output, what is the most likely problem?

Hard
87

Which THREE statements about MPLS label operations (push, swap, pop) are true? (Choose THREE.)

Hard
88

A network engineer runs the following command on Router R1: R1# show ip sla statistics 3 Round Trip Time (RTT) for Index 3 Latest RTT: 150 ms Latest RTT (milliseconds): 150 Latest RTT (microseconds): 150000 Number of successes: 80 Number of failures: 20 Operation time to live: Forever Output: OK R1# show track 1 Track 1 IP SLA 3 reachability Reachability is Up 2 changes, last change 00:00:10 Latest operation return code: OK Latest RTT (milliseconds): 150 Tracked by: ip route 0.0.0.0 0.0.0.0 192.168.1.1 track 1 Based on this output, which statement is correct?

Hard
89

Drag and drop the steps to verify and validate Route Maps and Route Filtering operational state into the correct order, from first to last.

Medium
90

Given the following partial DMVPN configuration on a hub router: interface Tunnel0 ip address 10.0.0.1 255.255.255.0 ip nhrp network-id 100 ip nhrp authentication cisco123 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ip nhrp map multicast dynamic ip nhrp redirect ! What is the purpose of the 'ip nhrp redirect' command?

Medium
91

A network engineer is deploying DMVPN Phase 3 with EIGRP as the routing protocol over a hub-and-spoke topology. The hub router is configured with `ip nhrp redirect` on its tunnel interface, and each spoke has `ip nhrp shortcut`. A spoke needs to send traffic to a remote subnet behind another spoke. Which mechanism allows the spoke to install a direct route to the remote spoke's tunnel IP without traversing the hub for every packet?

Medium
92

An engineer configures OSPF on two routers connected via a point-to-point link. The routers are stuck in EXSTART state. 'show ip ospf neighbor' shows neighbor state EXSTART/EXCHANGE. Which is the most likely explanation?

Hard
93

A network engineer is troubleshooting PBR on a Cisco router where traffic from subnet 192.168.50.0/24 should be forwarded to next-hop 10.50.50.2. The route map 'PBR-50' is configured with 'match ip address 160' and 'set ip next-hop 10.50.50.2'. The engineer applies the route map to interface GigabitEthernet0/0. The engineer notices that PBR works for traffic from 192.168.50.0/24, but the router is also policy-routing traffic from other subnets that should not be affected. The engineer checks the ACL 160 and confirms it only matches 192.168.50.0/24. What is the most likely cause?

Hard
94

snmp-server enable traps\nsnmp-server host 192.168.1.100 traps version 2c public\nsnmp-server host 192.168.1.200 informs version 2c public What is the effect of this configuration?

Medium
95

A network administrator is implementing policy-based routing (PBR) on a Cisco IOS router. The goal is to route traffic from a specific subnet (192.168.1.0/24) through a next-hop of 10.1.1.2 instead of the default route. The administrator has created a route map named PBR-MAP and configured a match statement for the subnet. Which action must be configured in the route map to set the next-hop?

Easy
96

Router R5 has this DHCP configuration: ip dhcp pool POOL3 network 172.16.0.0 255.255.255.0 default-router 172.16.0.1 option 150 ip 10.10.10.10 ! interface GigabitEthernet0/0 ip address 172.16.0.1 255.255.255.0 no shutdown What is the purpose of the option 150 command?

Medium
97

A network administrator is troubleshooting an IPsec VPN between two Cisco routers. Phase 1 completes successfully, but Phase 2 fails. The administrator sees the log message 'QM FSM error' on the initiator. Which configuration mismatch is the most likely cause?

Hard
98

What is the default BGP administrative distance for routes learned from an external peer (eBGP) in Cisco IOS-XE?

Medium
99

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to allow traffic from a multihomed customer that uses asymmetric routing. Which uRPF mode should the engineer configure?

Easy
100

A network engineer runs the following command to troubleshoot a Policy-Based Routing (PBR) issue: R1# show route-map PBR-MAP route-map PBR-MAP, permit, sequence 10 Match clauses: ip address (access-lists): 101 Set clauses: ip next-hop 10.1.1.2 Policy routing matches: 50 packets, 6000 bytes What does this output indicate?

Easy
101

A network engineer is configuring a Cisco IOS XE router to support MPLS Layer 3 VPNs. The engineer has enabled MPLS IP on the core interfaces and configured OSPF as the IGP. Which additional configuration is required on the PE routers to exchange VPNv4 routes with other PE routers?

Easy
102

A network engineer is troubleshooting a PBR route-map that is supposed to set the next-hop for traffic from a specific source to a different next-hop. The route-map is applied to the incoming interface, and the ACL matches the traffic. However, the engineer notices that the traffic is still being forwarded using the routing table. The engineer checks the route-map and sees that the 'set ip next-hop' command points to an IP address that is not reachable. What is the most likely result?

Hard
103

Which TWO configuration steps are required to enable SNMPv3 with authentication and encryption on a Cisco router? (Choose TWO.)

Hard
104

When troubleshooting SNMPv3 authentication failures, which default HMAC algorithm is used if the user is configured with "auth md5"?

Medium
105

A network engineer is configuring a Cisco IOS router to act as a Dynamic Host Configuration Protocol (DHCP) relay agent. The router receives DHCP broadcast requests on interface GigabitEthernet0/1 and must forward them to a DHCP server at 10.1.1.100. Which command is required to enable this functionality?

Medium
106

What is the default administrative distance for a route learned via the Intermediate System-to-Intermediate System (IS-IS) protocol?

Medium
107

Drag and drop the steps to troubleshoot IPv6 First Hop Security adjacency or connectivity failures into the correct order, from first to last.

Hard
108

A network engineer is configuring a Cisco IOS XE router for DMVPN Phase 3. The hub router is configured with `ip nhrp map multicast dynamic` and `ip nhrp network-id 100`. The spoke routers are configured with `ip nhrp map` and `ip nhrp nhs`. The engineer wants to enable spoke-to-spoke communication without traffic traversing the hub after the initial resolution. Which additional command is required on the hub to support Phase 3 shortcut switching?

Hard
109

A network engineer is configuring EIGRP on a router. The engineer wants to ensure that the router does not send EIGRP updates out of an interface connected to a non-EIGRP neighbor, but still advertises the connected network into EIGRP. Which configuration command should be used?

Easy
110

A network engineer is troubleshooting a routing issue in an EIGRP network. Router R1 is not learning a specific route from its neighbor R2, even though R2 has the route in its routing table. The engineer checks the EIGRP topology table on R1 and does not see the route. The output of 'show ip eigrp neighbors' shows that R1 and R2 are adjacent. What should the engineer check next?

Medium
111

An engineer configures OSPF on two routers connected via a serial link. The MTU on one side is 1500 and on the other is 1400. The OSPF adjacency forms but stays stuck in EXSTART state. Which is the most likely explanation?

Hard
112

A network engineer is configuring AAA on a Cisco IOS router. The engineer wants to authenticate administrative users against a TACACS+ server and ensure that if the server is unreachable, a local username and password can be used as a fallback. Which configuration achieves this?

Easy
113

A network engineer runs the following command to troubleshoot a VRF-Lite MPLS LDP issue: R1# show mpls ldp bindings vrf CUSTOMER_F Output: lib entry: 10.4.4.0/24, rev 2 local binding: label: 16 remote binding: lsr: 2.2.2.2:0, label: 20 lib entry: 10.5.5.0/24, rev 3 local binding: label: 17 remote binding: lsr: 2.2.2.2:0, label: 21 What does this output indicate?

Medium
114

A network engineer runs the following command to troubleshoot an MPLS L3VPN issue: R1# debug ip bgp updates Output: *Mar 1 00:01:23.456: BGP(0): 10.0.0.2 UPDATE out w/ attr: nexthop 10.0.0.1, origin i, metric 0, path 65000, extended community RT:100:100 *Mar 1 00:01:23.456: BGP(0): 10.0.0.2 UPDATE out for 10.1.1.0/24 *Mar 1 00:01:23.456: BGP(0): 10.0.0.2 UPDATE run, update group 1 What does this output indicate?

Medium
115

Which BGP attribute is considered 'well-known mandatory' and must be present in all BGP update messages?

Hard
116

A network engineer is troubleshooting a DMVPN Phase 3 network using Cisco IOS-XE routers. The hub router is configured with `ip nhrp redirect` and spoke routers with `ip nhrp shortcut`. A spoke router is unable to establish a direct spoke-to-spoke tunnel for a specific destination. Which action should the engineer take to resolve this?

Medium
117

Which NetFlow version introduced the concept of templates to support variable-length flow records?

Easy
118

A network engineer configures SNMPv3 with authentication only (no privacy) on a router. The NMS can poll the router successfully. Later, the engineer adds the 'priv' option to the user configuration. The NMS now fails to poll the router. Which is the most likely explanation?

Hard
119

A network engineer is configuring BGP on a Cisco IOS XE router. The router has two eBGP peers: ISP-A and ISP-B. The engineer wants to influence outbound traffic so that the router prefers ISP-A for all destinations unless ISP-A fails. Which BGP attribute should the engineer manipulate, and how?

Medium
120

A network engineer runs the following command to troubleshoot an Administrative Distance issue: R1# show ip route summary Route Source Networks Subnets Overhead Memory (bytes) connected 2 0 0 512 static 1 0 0 256 eigrp 100 3 0 0 768 ospf 1 2 0 0 512 bgp 65001 1 0 0 256 internal 1 0 0 256 Total 10 0 0 2560 What does this output indicate?

Easy
121

Which TWO statements about the syslog message format and its fields are correct? (Choose TWO.)

Hard
122

A network administrator is configuring a router to authenticate with a TACACS+ server for administrative access. The administrator enters the command `aaa authentication login default group tacacs+ local` on the router. Which statement describes the authentication behavior when the TACACS+ server is reachable but rejects the user's credentials?

Medium
123

When using an extended ACL to filter traffic, which fields can be matched? (Choose the most complete answer.)

Medium
124

A network engineer is troubleshooting a BGP route summarization issue. Router R1 is configured with the 'aggregate-address 192.168.0.0 255.255.252.0' command without any keywords. The engineer notices that the ISP neighbor is receiving both the aggregate route and the more specific routes (192.168.0.0/24, 192.168.1.0/24, etc.), causing the ISP to prefer the specific routes. What should the engineer do to ensure the aggregate route is preferred?

Medium
125

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on an interface. After the configuration, legitimate traffic from a customer network is being dropped. The engineer verifies that the customer's IP prefix is in the routing table. Which is the most likely explanation?

Hard
126

Drag and drop the steps to troubleshoot route redistribution adjacency or connectivity failures into the correct order, from first to last.

Medium
127

Examine the following OSPF configuration on router R1: router ospf 1 network 10.0.0.0 0.255.255.255 area 0 network 192.168.1.0 0.0.0.255 area 1 What is the effect of this configuration?

Medium
128

Examine this partial configuration on Router R3: router ospf 1 redistribute rip subnets metric-type 1 metric 50 What is the effect of the 'metric-type 1' keyword?

Medium
129

A network engineer is configuring SNMPv3 on a Cisco IOS router. The requirement is to authenticate and encrypt SNMP messages using the user 'admin' with SHA authentication and AES encryption. Which command correctly configures the SNMPv3 user?

Medium
130

Which TWO commands can be used to verify the configured logging destinations on a Cisco IOS-XE device? (Choose TWO.)

Easy
131

A network engineer is configuring a Cisco router as a Dynamic Host Configuration Protocol (DHCP) server for a remote subnet. The router's interface that connects to the remote subnet is GigabitEthernet0/1 with IP address 10.10.10.1/24. The engineer wants the router to assign addresses from the 10.10.10.0/24 pool to clients on that subnet. Which command must be issued in DHCP pool configuration mode to specify the default gateway that clients will receive?

Medium
132

A network engineer runs the following command on Router R1: R1# show ip route vrf BLUE Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2 i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP a - application route + - replicated route, % - next hop override Gateway of last resort is not set 10.0.0.0/8 is variably subnetted, 3 subnets, 2 masks C 10.1.1.0/24 is directly connected, GigabitEthernet0/0 C 10.1.2.0/24 is directly connected, GigabitEthernet0/1 O 10.2.0.0/16 [110/20] via 10.1.1.2, 00:00:15, GigabitEthernet0/0 Based on this output, what is the problem?

Hard
133

A network engineer runs the following command to verify crypto engine connections on a DMVPN spoke: R2# show crypto engine connections active Crypto Engine Connections ID Type Algorithm Encrypt Decrypt LastSeqN IP-Address 1 IPsec AES256-SHA 100 100 100 192.168.1.2 What does this output indicate?

Medium
134

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-IN Class-map: CoPP-BGP (match-all) 500 packets, 30000 bytes 5 minute offered rate 1000 bps, drop rate 500 bps Match: access-group 120 police: cir 8000 bps, bc 1500 bytes, be 1500 bytes conformed 300 packets, 18000 bytes; actions: transmit exceeded 100 packets, 6000 bytes; actions: drop violated 100 packets, 6000 bytes; actions: drop Based on this output, which statement is correct?

Medium
135

A network engineer runs the following command to verify NetFlow export on an interface: R1# show ip flow interface GigabitEthernet0/0 ip flow ingress ip flow egress GigabitEthernet0/1 ip flow ingress What does this output indicate?

Easy
136

A network engineer is troubleshooting an issue where IPv6 traffic from a host is being dropped by the switch. The switch has IPv6 Source Guard enabled. The host has a static IPv6 address 2001:db8:2::20. The engineer sees that the binding table does not contain an entry for this host. What should the engineer do to resolve the issue without disabling IPv6 Source Guard?

Medium
137

A network engineer runs the following command to troubleshoot a route filtering issue: R1# debug ip bgp updates BGP(0): 10.1.1.2 rcvd UPDATE w/ attr: nexthop 10.1.1.2, origin i, metric 0, path 65001 65002 BGP(0): 10.1.1.2 rcvd UPDATE about 192.168.100.0/24 -- DENIED due to: community no-export; What does this output indicate?

Medium
138

A network engineer is configuring a Cisco IOS router to support MPLS L3VPN. The router will act as a PE router and needs to assign a unique identifier to each customer VRF to allow overlapping address spaces. Which MPLS L3VPN component provides this function?

Easy
139

A network engineer is configuring a Cisco IOS XE router to support a DMVPN Phase 3 hub-and-spoke topology. The hub router must be able to redirect spoke-to-spoke traffic without requiring the spokes to have a direct route to each other. Which technology should be implemented on the hub to enable the hub to inform the originating spoke of the optimal spoke-to-spoke path?

Medium
140

What is the default administrative distance for a route learned via the Routing Information Protocol next generation (RIPng)?

Hard
141

Which statement about CoPP and IPv6 control plane traffic is correct?

Hard
142

Router R1 has an ACL applied to interface Gig0/0 in VRF-A that permits only specific management traffic. The ACL is: access-list 100 permit udp any any eq snmp, access-list 100 permit tcp any any eq ssh, access-list 100 deny ip any any. The router's SNMP and SSH services are configured globally. Management stations in the global table cannot reach the router's VRF interface IP. What is the root cause?

Hard
143

A network engineer is configuring a Cisco IOS router to authenticate login users against an external TACACS+ server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used as a fallback. Which command set correctly configures this behavior on the router?

Medium
144

What is the default SNMPv3 security level for a user configured with the "snmp-server user username groupname v3 auth sha password" command?

Medium
145

A network engineer is troubleshooting an IPv6 connectivity issue on a router that is using a tunnel interface (IPv6 over IPv4). The engineer notices that traffic is not passing through the tunnel. The engineer checks the tunnel interface and finds an inbound IPv6 ACL that permits only certain IPv6 traffic. The engineer also sees that uRPF is enabled on the tunnel interface in strict mode. The tunnel source and destination are IPv4 addresses. The IPv6 traffic sourced from a network behind the tunnel is being dropped. What is the most likely cause?

Hard
146

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (LAN) and GigabitEthernet0/1 (WAN). The engineer wants all HTTP traffic from the 10.1.1.0/24 subnet to be routed via next-hop 192.168.2.2 instead of the default route. The engineer creates a route map named PBR with sequence 10, matches an ACL that permits TCP port 80 from 10.1.1.0/24, and sets the next-hop to 192.168.2.2. The route map is applied to interface GigabitEthernet0/0 with the command `ip policy route-map PBR`. However, traffic still follows the default route. Which action will fix the problem?

Medium
147

A network administrator is configuring a Cisco IOS router to use NAT overload (PAT) for a small office. The inside network is 192.168.1.0/24, and the router's outside interface is GigabitEthernet0/0 with IP address 203.0.113.5. The administrator enters the following commands: access-list 1 permit 192.168.1.0 0.0.0.255 ip nat inside source list 1 interface GigabitEthernet0/0 overload interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ip nat inside interface GigabitEthernet0/0 ip address 203.0.113.5 255.255.255.0 ip nat outside However, hosts on the inside network cannot access the Internet. Which command is missing?

Easy
148

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# show crypto isakmp policy Global IKE policy Protection suite of priority 10 encryption algorithm: AES - Advanced Encryption Standard (256 bit keys). hash algorithm: Secure Hash Standard authentication method: Pre-Shared Key Diffie-Hellman group: #5 (1536 bit) lifetime: 86400 seconds, no volume limit Default protection suite encryption algorithm: DES - Data Encryption Standard (56 bit keys). hash algorithm: Secure Hash Standard authentication method: Pre-Shared Key Diffie-Hellman group: #1 (768 bit) lifetime: 86400 seconds, no volume limit What does this output indicate?

Medium
149

Which TWO commands would a network engineer use to verify OSPFv2 neighbor state and adjacency issues on a Cisco IOS router? (Choose TWO.)

Medium
150

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# show ip sla monitor configuration 10 IP SLAs Monitor, Infrastructure Engine-II. Entry number: 10 Owner: Tag: Type of operation to perform: icmp-echo Target address: 192.168.1.1 Type Of Service parameter: 0x0 Request size (ARR data portion): 28 Operation timeout (milliseconds): 5000 Frequency (seconds): 60 Next Scheduled Start Time: Start Time already occurred Group Scheduled : FALSE Life (seconds): Forever Entry Ageout (seconds): never Recurring (Starting Everyday): FALSE Status of entry (SNMP RowStatus): Active Threshold (milliseconds): 5000 Distribution Statistics: Number of history intervals kept: 0 Number of history buckets kept: 15 History Statistics: Number of history Lives kept: 0 What does this output indicate?

Medium
151

Which TWO actions will prevent a BGP route from being installed in the routing table (RIB) while still being present in the BGP table? (Choose TWO.)

Hard
152

In a VRF-Lite setup using RIP, what is the default update timer value?

Medium
153

A network engineer runs the following command to verify NetFlow data export format: R1# show flow exporter EXPORTER-1 Flow Exporter: EXPORTER-1 Transport Configuration: Destination IP address: 192.168.1.100 Source IP address: 10.0.0.1 Transport Protocol: UDP Destination Port: 2055 Source Port: 51234 DSCP: 0x00 TTL: 255 Output Features: Used Export Protocol: NetFlow Version 9 Template Data Export Timeout: 1800 seconds Option Data Export Timeout: 1800 seconds Option Data Configured: application-table sub-application-table application-attributes What does this output indicate?

Medium
154

A network engineer runs the following command on Router R8: R8# show logging | include %LDP-5-NBRCHG *Mar 1 00:01:10.123: %LDP-5-NBRCHG: LDP Neighbor 10.0.0.2:0 (1) is UP *Mar 1 00:02:20.456: %LDP-5-NBRCHG: LDP Neighbor 10.0.0.2:0 (1) is DOWN *Mar 1 00:03:30.789: %LDP-5-NBRCHG: LDP Neighbor 10.0.0.2:0 (1) is UP *Mar 1 00:04:40.012: %LDP-5-NBRCHG: LDP Neighbor 10.0.0.2:0 (1) is DOWN Based on this output, what is the most likely problem?

Medium
155

Drag and drop the steps to create and register an EEM applet for syslog events into the correct order, from first to last.

Medium
156

A network engineer runs the following command on Router R1: R1# show ip dhcp conflict IP address Detection method Detection time VRF 192.168.1.20 Ping Mar 01 2020 01:00 AM 192.168.1.21 Gratuitous ARP Mar 01 2020 01:05 AM Based on this output, what is the problem?

Medium
157

What is the default port number used by syslog servers to receive UDP syslog messages?

Easy
158

Drag and drop the steps to negotiate an IKEv2 IPsec site-to-site tunnel into the correct order, from first to last.

Medium
159

A network security engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS router to protect against denial-of-service attacks. The engineer wants to ensure that CoPP policies are applied correctly and that the router's control plane is protected. Which two statements about CoPP configuration are true? (Choose two.)

Hard
160

A network engineer runs the following command on Router R1: R1# show event manager policy registered No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 BGP_Neighbor_Down R1# show bgp summary BGP router identifier 10.0.0.1, local AS number 65001 BGP table version is 1, main routing table version 1 Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 192.168.1.2 4 65002 5 5 1 0 0 00:02:00 Established Based on this output, which statement is correct?

Medium
161

An engineer configures an RSPAN session on a Cisco switch to monitor traffic from VLAN 30 and send it to a remote switch. The engineer creates RSPAN VLAN 200 on both switches and configures the trunk to allow VLAN 200. On the remote switch, the engineer configures the destination port as GigabitEthernet0/4 in VLAN 200. The engineer notices that the destination port is forwarding traffic, but the traffic is not from the source VLAN 30; instead, it is broadcast traffic from other VLANs. What is the most likely cause?

Hard
162

A network engineer runs the following command on Router R1: R1# show ip sla statistics IPSLAs Latest Statistics: Round Trip Time (RTT) for Index 1 Latest RTT: 10 ms Latest RTT (milliseconds): 10 Number of successes: 100 Number of failures: 0 Operation time to live: 3000 Operation frequency: 60 seconds Next operation start time: 00:00:45 Based on this output, what is the status of the IP SLA operation?

Easy
163

A network engineer runs the following command to troubleshoot SNMPv3 group configuration: R1# show snmp group group name: admin-group security model: v3 auth priv read view: v1default write view: v1default notify view: v1default Group name: monitor-group security model: v3 auth no priv read view: v1default write view: none notify view: v1default What does this output indicate?

Hard
164

A network engineer runs the following command to troubleshoot an ERSPAN issue: R1# show monitor session 6 detail Session 6 --------- Type : ERSPAN Source Session Source VLANs : Both : 10-20 Destination IP : 10.1.1.3 ERSPAN ID : 200 What does this output indicate?

Hard
165

A network engineer runs the following command on Router PE5: PE5# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 10.0.0.7 1 FULL/DR 00:00:32 10.1.1.7 GigabitEthernet0/0 10.0.0.8 1 FULL/BDR 00:00:35 10.2.2.8 GigabitEthernet0/1 Based on this output, which statement is correct?

Easy
166

A network engineer is configuring a Cisco IOS XE router to connect to an ISP via BGP. The engineer wants to influence inbound traffic from the ISP by prepending the router's AS number multiple times to the BGP updates sent to the ISP. Which BGP attribute should the engineer modify to achieve this?

Medium
167

An engineer configures mutual redistribution between EIGRP and OSPF on a router. EIGRP routes are redistributed into OSPF with a route-map that sets metric-type type-1, and OSPF routes are redistributed into EIGRP with default metric 10000 100 255 1 1500. Unexpectedly, the router starts flapping routes between the two protocols, causing instability. Which is the most likely explanation?

Hard
168

A network engineer runs the following command on Router R1: R1# show ipv6 bgp summary BGP router identifier 192.168.1.1, local AS number 65001 BGP table version is 10, main routing table version 10 5 network entries using 720 bytes of memory 5 path entries using 400 bytes of memory 3/2 BGP path/bestpath attribute entries using 456 bytes of memory 1 BGP AS-PATH entries using 24 bytes of memory 0 BGP route-map cache entries using 0 bytes of memory 0 BGP filter-list cache entries using 0 bytes of memory BGP using 1600 total bytes of memory BGP activity 10/5 prefixes, 10/5 paths, scan interval 60 secs Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 2001:DB8::2 4 65002 100 99 10 0 0 00:45:12 3 Based on this output, which statement is correct?

Medium
169

A network engineer runs the following command on Router R1: R1# show flow interface GigabitEthernet0/1 Interface GigabitEthernet0/1 FNF: monitor Monitor: FLOW-MONITOR-1 direction: Input traffic-statistics: enabled Based on this output, what can be concluded?

Easy
170

What is the default behavior of a local SPAN session if no direction (rx, tx, both) is specified?

Easy
171

A network engineer runs the following command on Router R1: R1# show flow exporter EXPORTER-1 statistics Flow Exporter: EXPORTER-1 Packet send statistics (last 30 seconds): Packets sent: 0 Packets dropped: 0 Packets unsent: 0 Client send statistics: Packets sent: 0 Packets dropped: 0 Packets unsent: 0 Export statistics: Number of Flows exported: 0 Number of Packets exported: 0 Number of Source IP address unreachable: 0 Number of Packets dropped (no route): 0 Number of Packets dropped (queue full): 0 Based on this output, what is the most likely cause of no exports?

Medium
172

Which statement about administrative distance is true regarding the selection of routes in a routing table?

Hard
173

A network engineer runs the following command on Router R1: R1# show ipv6 dhcp interface Gi0/0/0 Gi0/0/0 is in server mode Uses prefix 2001:DB8:1::/64 Rapid-Commit is disabled Preference value: 0 Information refresh option: 86400 DNS server: 2001:DB8::1 Domain name: example.com Active clients: 5 Pool: DHCP_POOL Based on this output, which statement is correct?

Medium
174

A network engineer runs the following command to troubleshoot IPsec on a DMVPN tunnel: R1# debug crypto isakmp ISAKMP: received peer 192.168.1.2, port 500, local 192.168.1.1 ISAKMP: SA created, initiating IKE Main Mode ISAKMP: sent MM_SA proposal to 192.168.1.2 ISAKMP: received MM_SA response from 192.168.1.2 ISAKMP: Main Mode complete, starting Quick Mode ISAKMP: sent QM_SA request to 192.168.1.2 ISAKMP: received QM_SA response from 192.168.1.2 ISAKMP: Quick Mode done, IPsec SA established What does this output indicate?

Medium
175

A network engineer runs the following command on Router R1: R1# show bgp neighbors 10.1.12.2 advertised-routes BGP table version is 15, local router ID is 10.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.1.1.0/24 0.0.0.0 0 32768 i *> 10.2.2.0/24 10.1.12.2 0 0 65002 i Total number of prefixes 2 Based on this output, what can be concluded about the route 10.2.2.0/24?

Medium
176

Router R1 and R2 are iBGP peers in the same AS. R1 learns a route 172.16.1.0/24 from an eBGP peer with AS_PATH 100 200. R2 learns the same prefix from another eBGP peer with AS_PATH 100. Both routers redistribute the route into OSPF with default administrative distance. R3, an OSPF internal router, sees two OSPF external routes for 172.16.1.0/24: one from R1 (type-5, metric 20) and one from R2 (type-5, metric 30). R3's 'show ip route 172.16.1.0' shows the route via R1. What is the root cause of R3 preferring the route via R1?

Hard
177

A network engineer is configuring a Cisco IOS XE router to authenticate OSPFv3 neighbors. The engineer applies the following configuration under the OSPFv3 process: `area 0 authentication ipsec spi 256 sha1 0123456789ABCDEF0123456789ABCDEF01234567`. The engineer then verifies the neighbor relationship and sees that it remains in EXSTART state. Which action should the engineer take to resolve the issue?

Medium
178

Which IP SLA operation type is specifically designed to measure one-way delay, jitter, and packet loss using UDP packets with sequence numbers and timestamps?

Medium
179

Examine the following partial MPLS configuration on a Cisco IOS-XE router: interface GigabitEthernet0/0 ip address 10.0.1.1 255.255.255.252 mpls ip mpls label protocol ldp ! router ospf 1 network 10.0.1.0 0.0.0.3 area 0 ! mpls ldp router-id Loopback0 force What is the effect of this configuration?

Medium
180

A network engineer runs the following command to debug MPLS LDP errors: R1# debug mpls ldp errors Output: *Mar 1 00:01:23.456: LDP: Received malformed hello from 10.0.0.2 *Mar 1 00:01:23.789: LDP: Received malformed initialization from 10.0.0.2 *Mar 1 00:01:24.012: LDP: Session with 10.0.0.2:0 (0x1234) is DOWN What does this output indicate?

Hard
181

Drag and drop the steps to verify and validate EEM operational state into the correct order, from first to last.

Medium
182

A network engineer runs the following command to troubleshoot an MPLS Operations issue: R1# debug mpls ldp transport 10.1.1.1 Output: *Mar 1 00:01:23.456: LDP: Sent hello to 10.1.1.1 (UDP 646) on GigabitEthernet0/0 *Mar 1 00:01:23.789: LDP: Received hello from 10.1.1.1 (UDP 646) on GigabitEthernet0/0 *Mar 1 00:01:24.012: LDP: Opened TCP connection to 10.1.1.1:646 *Mar 1 00:01:24.345: LDP: Initialization msg sent to 10.1.1.1 *Mar 1 00:01:24.678: LDP: Initialization msg received from 10.1.1.1 *Mar 1 00:01:25.001: LDP: Session with 10.1.1.1:0 (0x1234) is UP What does this output indicate?

Medium
183

A network administrator is configuring AAA on a Cisco IOS router. The administrator wants to authenticate administrative users against a TACACS+ server and ensure that if the TACACS+ server is unreachable, the router falls back to local authentication. The administrator has configured the TACACS+ server and local user accounts. Which additional configuration is required to achieve this?

Easy
184

Drag and drop the steps to troubleshoot NAT and PAT adjacency or connectivity failures into the correct order, from first to last.

Hard
185

Which of the following is a limitation of local SPAN on a Cisco switch?

Medium
186

Which TWO conditions must be met for a BGP route to be considered the best path and installed in the routing table? (Choose TWO.)

Hard
187

A network engineer runs the following command to verify CoPP (Control Plane Policing) with route-maps: R1# show policy-map control-plane input class class-default Control Plane Service-policy input: CoPP Class-map: class-default (match-any) 12234 packets, 1234567 bytes 5 minute offered rate 1000 bps, drop rate 0 bps Match: any police: cir 8000 bps, bc 1500 bytes, be 1500 bytes conformed 12234 packets, 1234567 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop What does this output indicate?

Medium
188

Drag and drop the steps to troubleshoot route summarization adjacency or connectivity failures into the correct order, from first to last.

Hard
189

What is the default OSPF dead interval on an Ethernet broadcast network?

Easy
190

A network engineer runs the following command to troubleshoot route redistribution: R1# debug ip routing IP: route table insert (10.10.10.0/24 via 192.168.1.1, ospf 1) metric [110/20] IP: route table insert (10.10.10.0/24 via 10.1.1.2, eigrp 100) metric [90/158720] IP: route table delete (10.10.10.0/24 via 192.168.1.1, ospf 1) metric [110/20] IP: route table insert (10.10.10.0/24 via 10.1.1.2, eigrp 100) metric [90/158720] What does this output indicate?

Medium
191

A network engineer runs the following command on Router R1: R1# show ip dhcp database URL : flash:/dhcpdb Read/write : Read/Write Last updated : Mar 01 2020 00:00:00 Status : Last read succeeded. Next write scheduled in 0 seconds. Based on this output, which statement is correct?

Medium
192

A network engineer runs the following command to verify MPLS LDP discovery sources: R1# show mpls ldp discovery detail Output: Local LDP Identifier: 10.0.0.1:0 Discovery Sources: Interfaces: GigabitEthernet0/0 (hello interval 5 s, targeted hello interval 10 s) LDP Id: 10.0.0.2:0, transport address: 10.0.0.2 Hold time: 15 s (local: 15, peer: 15) GigabitEthernet0/1 (hello interval 5 s, targeted hello interval 10 s) LDP Id: 10.0.0.3:0, transport address: 10.0.0.3 Hold time: 15 s (local: 15, peer: 15) What does this output indicate?

Medium
193

A network engineer is troubleshooting an IPsec site-to-site VPN between two Cisco IOS routers. Phase 1 is up, but Phase 2 fails to establish. The engineer suspects a mismatch in the IPsec proposal. Which command would show the configured IPsec transform set and the algorithms being used?

Medium
194

Consider the following partial configuration on router R6: flow exporter EXPORTER-3 destination 192.168.2.200 source Loopback0 transport udp 2055 template data timeout 120 ! flow monitor MONITOR-6 exporter EXPORTER-3 record netflow ipv4 original-input ! interface GigabitEthernet0/6 ip flow monitor MONITOR-6 input ! What is the effect of the 'template data timeout 120' command?

Medium
195

Which TWO commands would a network engineer use to verify the BGP next-hop reachability issue when a route is not being installed in the routing table? (Choose TWO.)

Medium
196

In MPLS LDP, what is the default label retention mode on Cisco IOS-XE routers?

Medium
197

Two routers are configured with EIGRP and have a neighbor relationship. One router has a route to 192.168.1.0/24 with metric 100. The other router has a route to the same prefix with metric 200. An engineer configures an offset-list on the first router to increase the metric of 192.168.1.0/24 by 50, expecting the second router to prefer its own route. Unexpectedly, the second router still prefers the first router's route after the offset. Which is the most likely explanation?

Hard
198

Consider the following partial configuration on router R4: flow exporter EXPORTER-2 destination 10.10.10.1 source Loopback0 transport udp 9996 option interface-table option sampler-table ! flow monitor MONITOR-4 exporter EXPORTER-2 record netflow ipv4 original-input ! interface GigabitEthernet0/4 ip flow monitor MONITOR-4 input ! What is the purpose of the 'option interface-table' and 'option sampler-table' commands under the exporter?

Medium
199

What is the default OSPF hello interval on a Cisco IOS-XE router for a broadcast network type?

Easy
200

A network engineer is troubleshooting NAT for a VoIP phone that uses SIP. The phone is at 192.168.2.10, and the router performs PAT to the outside interface 198.51.100.1. The phone can register with the SIP server, but calls fail after 30 seconds. The engineer notices that the SIP signaling includes the phone's private IP in the SDP body. What is the most likely cause?

Hard
201

A network engineer is configuring a DMVPN Phase 3 hub router. The hub must dynamically discover spoke-to-spoke tunnels while still using the hub for initial registration. Which technology allows the hub to redirect spoke traffic directly to another spoke?

Medium
202

Drag and drop the steps to verify and validate the EIGRP operational state into the correct order, from first to last.

Medium
203

A network engineer is configuring a VRF-aware IPsec VPN. The engineer needs to ensure that the IPsec tunnel traffic is forwarded within the correct VRF on the router. Which command must be configured under the crypto map to bind the IPsec tunnel to a specific VRF?

Medium
204

A network engineer is troubleshooting a DHCP relay configuration on a Cisco IOS router. The router is configured with the ip helper-address 10.1.1.1 command on interface GigabitEthernet0/0, but clients on the 192.168.1.0/24 subnet are not receiving IP addresses from the DHCP server at 10.1.1.1. The engineer verifies that the DHCP server is operational and has a pool for 192.168.1.0/24. What is the most likely cause?

Hard
205

A network engineer is troubleshooting an OSPFv2 adjacency issue between two routers across a Frame Relay network. R1 and R2 are connected via a point-to-point subinterface. The engineer configures 'ip ospf network point-to-point' on both subinterfaces. However, the adjacency does not form. 'show ip ospf interface' on R1 shows the interface is up and OSPF is enabled, but no neighbors are seen. What is the most likely cause?

Hard
206

A network engineer runs the following command to troubleshoot a Device Access Control issue: R1# show mpls ldp bindings 10.10.10.0 24 lib entry: 10.10.10.0/24, rev 2 local binding: label: 101 remote binding: lsr: 10.1.1.2:0, label: 102 remote binding: lsr: 10.1.2.2:0, label: 103 What does this output indicate?

Medium
207

A network administrator is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers that uses IKEv2. Phase 1 is up, but Phase 2 fails. The administrator reviews the configuration and notices that the transform set on one router includes esp-aes 256 esp-sha256-hmac, while the other router has esp-aes 256 esp-sha512-hmac. The administrator wants to ensure the Phase 2 SA is established. Which action should the administrator take?

Medium
208

Which BFD session state indicates that the session is fully established and operational?

Easy
209

An EIGRP network is experiencing stuck-in-active (SIA) routes after a link failure. Router R1 has the following relevant configuration: router eigrp 100 network 10.0.0.0 0.255.255.255 Router R2 shows: show ip eigrp topology 10.1.1.0/24 IP-EIGRP topology entry for 10.1.1.0/24 State: Active, 00:01:30, Reply status 10.2.2.2, 10.3.3.3 What is the root cause?

Hard
210

A network engineer is troubleshooting a DMVPN Phase 3 hub-and-spoke topology. Spoke routers are Cisco IOS devices running EIGRP as the routing protocol. The engineer wants to ensure that spoke-to-spoke traffic does not go through the hub after the initial path setup, and that spoke routers can dynamically form direct tunnels. Which NHRP command must be configured on the hub to enable this behavior?

Medium
211

A network engineer configures mutual redistribution between EIGRP and OSPF on a DMVPN hub router. The EIGRP domain includes the DMVPN tunnel network, and OSPF includes a corporate backbone. Unexpectedly, after a few minutes, the routing table on the hub shows oscillating routes between EIGRP and OSPF for the same prefix, causing intermittent connectivity. Which is the most likely explanation?

Hard
212

An engineer configures a site-to-site IPsec VPN between two routers using OSPF as the routing protocol. The OSPF neighbor becomes stuck in EXSTART state. The engineer verifies that the IPsec tunnel is up and that both routers can ping each other's tunnel interfaces. What is the most likely cause of the OSPF adjacency issue?

Hard
213

A network engineer is configuring a Cisco router to authenticate OSPF neighbors using MD5. The router is connected to two OSPF neighbors on the same subnet. The engineer wants to enable MD5 authentication on the interface with a key ID of 1 and a password of 'Cisco123'. Which command sequence correctly accomplishes this?

Medium
214

A network engineer is configuring MPLS Layer 3 VPN on a Cisco IOS XE router. The engineer needs to enable the provider edge (PE) router to exchange VPNv4 routes with another PE router. Which address family must be configured under the BGP routing process to achieve this?

Medium
215

Which TWO statements about BFD echo mode are true? (Choose TWO.)

Hard
216

A service provider network uses OSPF with route summarization on Area Border Routers (ABRs). Router R1 (ABR) has the configuration: router ospf 1 area 1 range 10.1.0.0 255.255.240.0 area 1 range 10.1.16.0 255.255.240.0 Router R2 (internal to area 1) shows: R2# show ip route ospf 10.1.0.0/20 is subnetted, 1 subnets O IA 10.1.0.0/20 [110/2] via 10.2.1.1, 00:00:15, Serial0/0/0 10.1.16.0/20 is subnetted, 1 subnets O IA 10.1.16.0/20 [110/2] via 10.2.1.1, 00:00:10, Serial0/0/0 10.1.32.0/20 [110/3] via 10.2.1.2, 00:00:05, Serial0/0/1 R2 is missing a route to 10.1.48.0/20. What is the root cause?

Hard
217

A network engineer runs the following command to troubleshoot a VRF route issue: R1# show ip route vrf CUSTOMER summary IP routing table name is CUSTOMER (0x1) IP routing table maximum-paths is 32 Route Source Networks Subnets Overhead Memory (bytes) connected 2 0 0 320 static 1 0 0 160 eigrp 100 3 0 0 480 Internal 3 Total 6 0 0 960 What does this output indicate?

Easy
218

A network engineer runs the following command on Router R1: R1# show ip policy Interface Route-map GigabitEthernet0/1 PBR-MAP R1# show route-map PBR-MAP route-map PBR-MAP, permit, sequence 10 Match clauses: ip address (access-lists): 101 Set clauses: ip next-hop verify-availability 10.1.1.2 10 track 1 Policy routing matches: 150 packets, 12000 bytes R1# show track 1 Track 1 IP SLA 1 reachability Reachability is Down 1 change, last change 00:05:20 Latest operation return code: timeout Tracked by: ROUTE-MAP 0 Based on this output, what is the most likely outcome?

Medium
219

A network administrator is configuring a Cisco IOS router to authenticate SSH users against an external TACACS+ server. The TACACS+ server is reachable at 10.10.10.5, and the shared secret is 'Cisco123'. The administrator wants to ensure that if the TACACS+ server is unreachable, a local user account 'backup' with privilege level 15 is used for authentication. Which configuration sequence correctly achieves this?

Medium
220

A network engineer runs the following command to verify BFD with EIGRP: R1# show ip eigrp 100 topology 10.2.2.0/24 EIGRP-IPv4 Topology Entry for AS(100)/ID(10.2.2.0/24) State: Passive, Query origin flag: 1, 1 Successor(s), FD is 131072 Descriptor Blocks: 10.1.1.2 (GigabitEthernet0/0), from 10.1.1.2, Send flag: 0x0 Composite metric: (131072/130816), Route is Internal Vector metric: Minimum bandwidth is 100000 Kbit Total delay is 100 microseconds Reliability is 255/255 Load is 1/255 Minimum MTU is 1500 Hop count is 1 Originating router is 2.2.2.2 BFD enabled, BFD state: UP What does this output indicate?

Medium
221

Consider the following partial configuration on router R6: router bgp 65001 bgp router-id 6.6.6.6 neighbor 10.0.0.2 remote-as 65002 neighbor 10.0.0.2 route-map SET-MED out ! route-map SET-MED permit 10 set metric 50 What is the effect of this configuration?

Medium
222

Consider the following BGP configuration on router R2: router bgp 65002 bgp router-id 2.2.2.2 neighbor 10.2.2.1 remote-as 65001 neighbor 10.2.2.1 route-map FILTER in ! route-map FILTER deny 10 match ip address prefix-list BLOCKED ! route-map FILTER permit 20 ! ip prefix-list BLOCKED permit 10.0.0.0/8 le 32 Which statement is true about routes received from 10.2.2.1?

Medium
223

Which SNMP version introduced the use of a User-based Security Model (USM) and View-based Access Control Model (VACM)?

Medium
224

An engineer is troubleshooting a BGP peering problem between two routers, R1 (AS 65001) and R2 (AS 65002), connected via a firewall. The BGP session is flapping every few seconds. The engineer notices that the TCP connection is established, but BGP OPEN messages are not exchanged. The firewall logs show that TCP port 179 is allowed, but packets with the BGP marker (0xFFFFFFFF) are being dropped. What is the most likely cause?

Hard
225

Which TWO statements about the 'show ip bgp vpnv4 vrf <vrf-name>' command output are correct? (Choose TWO.)

Hard
226

A network engineer runs the following command on Router R1: R1# show ip dhcp snooping binding MacAddress IpAddress Lease(sec) Type VLAN Interface AA:BB:CC:01:02:03 192.168.1.10 86400 dhcp-snooping 10 GigabitEthernet0/1 AA:BB:CC:01:02:04 192.168.1.11 86400 dhcp-snooping 10 GigabitEthernet0/1 AA:BB:CC:01:02:05 192.168.1.12 86400 dhcp-snooping 10 GigabitEthernet0/2 Based on this output, which statement is correct?

Medium
227

A network engineer is troubleshooting a BGP peering issue between two directly connected routers, R1 and R2. R1 is configured with 'neighbor 10.1.1.2 remote-as 65002' and 'neighbor 10.1.1.2 update-source Loopback0', while R2 uses 'neighbor 10.1.1.1 remote-as 65001' and 'neighbor 10.1.1.1 update-source Loopback0'. The loopback interfaces are not advertised into any IGP, and there is no static route for the loopback addresses. The BGP session remains in Idle state. What is the most likely cause?

Medium
228

A network engineer configures IP SLA tracking for a static route on a Cisco router. The IP SLA operation is configured with a threshold of 100 ms and a timeout of 5000 ms. The tracked object is configured with a delay of 5 seconds for both up and down transitions. The engineer notices that when the remote host becomes unreachable, the static route is not removed from the routing table immediately. Which is the most likely explanation?

Hard
229

An engineer configures OSPF on two routers connected via a serial link. Both routers have 'ip ospf network point-to-point' configured, but the link is actually a Frame Relay multipoint subinterface. The OSPF neighbors remain stuck in EXSTART state. Which is the most likely explanation?

Hard
230

Which THREE symptoms indicate that an administrative distance misconfiguration might be causing routing issues? (Choose THREE.)

Hard
231

What is the default transport protocol used by NetFlow exporters on Cisco IOS-XE?

Easy
232

A network engineer runs the following command on Router R1: R1# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 192.168.1.2 1 FULL/DR 00:00:35 10.1.1.2 GigabitEthernet0/0 192.168.2.2 1 2WAY/DROTHER 00:00:32 10.2.2.2 GigabitEthernet0/1 192.168.3.2 1 FULL/BDR 00:00:38 10.3.3.2 GigabitEthernet0/2 Based on this output, what is a potential issue?

Medium
233

Which THREE statements about IPv4 access control list sequence numbers are true? (Choose THREE.)

Hard
234

A network engineer runs the following command to troubleshoot a BGP Troubleshooting issue: R1# show ip bgp vpnv4 vrf CUSTOMER routes BGP table version is 10, local router ID is 1.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path Route Distinguisher: 100:1 (default for vrf CUSTOMER) *> 10.0.0.0/24 10.1.1.2 0 100 0 65001 i *> 192.168.1.0/24 10.1.1.2 0 100 0 65001 i Total number of prefixes 2 What does this output indicate?

Hard
235

Given the following BGP configuration on router R1: router bgp 65001 bgp router-id 1.1.1.1 neighbor 10.1.1.2 remote-as 65002 neighbor 10.1.1.2 route-map SET-MED out ! route-map SET-MED permit 10 match ip address prefix-list LOOPBACKS set metric 100 ! route-map SET-MED permit 20 ! ip prefix-list LOOPBACKS permit 192.168.0.0/24 What is the effect of this configuration?

Medium
236

A network engineer runs the following command to debug NetFlow export: R1# debug ip flow export IP Flow export debugging is on R1# *Mar 1 00:05:23.123: FLOW: export v9 flow 1 with 30 packets *Mar 1 00:05:23.124: FLOW: export v9 flow 2 with 15 packets *Mar 1 00:05:23.125: FLOW: export v9 flow 3 with 22 packets *Mar 1 00:05:23.126: FLOW: export v9 flow 4 with 8 packets *Mar 1 00:05:23.127: FLOW: export v9 flow 5 with 12 packets What does this output indicate?

Medium
237

A network engineer runs the following command to troubleshoot an SNMP issue: R1# debug snmp packets SNMP: Packet received via UDP from 10.1.1.1 on port 161 SNMP: GetRequest, reqid 12345, errstat 0, errindex 0 SNMP: Community string: public SNMP: MIB object: 1.3.6.1.2.1.1.1.0 (sysDescr) SNMP: Value: Cisco IOS Software, C1900 Software (C1900-UNIVERSALK9-M), Version 15.7(3)M SNMP: Packet sent via UDP to 10.1.1.1 on port 161 SNMP: GetResponse, reqid 12345, errstat 0, errindex 0 What does this debug output indicate?

Medium
238

A network engineer is configuring OSPF on a Cisco router. The router has three interfaces in Area 0, and the engineer wants to ensure that the router does not become a Designated Router (DR) on any of these interfaces. Which command should be used on each interface?

Medium
239

A network engineer runs the following command to troubleshoot a Control Plane Policing (CoPP) issue: R1# show ip route summary IP routing table name: Default-IP-Routing-Table (0x0) IP routing table maximum-paths: 32 Route entry limits: 1000000 active, 2000000 total Number of prefixes: 500 Prefixes with memory: 500 Number of paths: 600 Paths with memory: 600 Number of operations: 1200 Number of deleted entries: 0 What does this output indicate?

Easy
240

Consider the following configuration on router R2: !--- R2 configuration ip prefix-list FILTER seq 5 deny 10.1.0.0/16 le 24 ip prefix-list FILTER seq 10 permit 0.0.0.0/0 le 32 ! route-map BGP-IN permit 10 match ip address prefix-list FILTER ! router bgp 65000 neighbor 192.168.1.1 route-map BGP-IN in ! What is the effect of this configuration?

Medium
241

An experienced network engineer configures mutual redistribution between OSPF and EIGRP on a router. Both protocols have routes to the same prefix, but after redistribution, a routing loop occurs. The engineer did not use route tagging. Which is the most likely explanation?

Hard
242

An engineer is troubleshooting an issue where a rogue IPv6 router is sending false Router Advertisements on the network, causing hosts to use a malicious default gateway. The switch is configured with IPv6 First Hop Security features. The engineer wants to prevent this attack while allowing the legitimate router to send RAs. What is the correct configuration approach?

Hard
243

A router has a CoPP policy that includes a class-map matching all traffic from a specific source IP address (the management station) and polices it to 100000 bps. The engineer notices that SNMP polls from the management station are timing out. The SNMP traffic uses UDP port 161. The engineer checks the CoPP statistics and sees that the class for the management station has dropped packets. What is the most likely cause?

Easy
244

A network technician is configuring a Cisco router to act as a DHCP relay agent. The router's interface Gi0/0 is connected to the DHCP clients, and the DHCP server is reachable via interface Gi0/1. Which command must be configured on interface Gi0/0 to forward DHCP requests to the server at 192.168.1.10?

Easy
245

A network engineer configured the following: monitor session 3 type erspan-source source interface GigabitEthernet0/0/2 rx destination erspan-id 2 ip address 10.0.0.2 origin ip address 10.0.0.1 What traffic will be mirrored?

Medium
246

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 10.1.1.0/24 BGP routing table entry for 10.1.1.0/24, version 2 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 Local 10.1.1.1 from 0.0.0.0 (10.1.1.1) Origin IGP, metric 0, localpref 100, weight 32768, valid, sourced, best rx pathid: 0, tx pathid: 0x0 Based on this output, which statement is correct?

Easy
247

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against route processor overload. The engineer creates a class map matching OSPF and BGP traffic and a policy map that polices this traffic to 1 Mbps with a burst of 2000 bytes. After applying the policy map to the control plane, the engineer notices that OSPF adjacencies flap intermittently. Which action should the engineer take to resolve the flapping?

Hard
248

A network engineer configured IP SLA 30 to monitor the reachability of a server (10.10.10.10) using ICMP echo probes. The IP SLA is linked to a track object that is used in a static default route. The engineer notices that the IP SLA state is 'Active', but the static route is not present in the routing table. The track object shows 'Up'. What should the engineer check first?

Medium
249

Router R2 has the following configuration: ``` interface GigabitEthernet0/2 ip address 10.2.2.2 255.255.255.0 ip policy route-map CHECK ! route-map CHECK permit 10 match ip address 101 set interface GigabitEthernet0/3 ! access-list 101 permit tcp any any eq 80 ``` What is the effect of this configuration?

Medium
250

A network engineer is configuring OSPF on a router that connects to a broadcast Ethernet segment. The router is connected to a switch that also connects to three other OSPF routers. The engineer wants to ensure that this router does not become the Designated Router (DR) or Backup Designated Router (BDR) on this segment, but still participates in OSPF. Which configuration should the engineer apply on the router's interface?

Medium
251

A network engineer is configuring a site-to-site DMVPN Phase 3 hub router. The hub uses a single mGRE tunnel interface with the IP address 10.0.0.1/24. Spoke routers are configured with NHS 10.0.0.1 and are in the same subnet. The engineer wants spoke-to-spoke traffic to bypass the hub after the initial resolution. Which command must be configured on the hub to enable Phase 3 shortcut switching?

Medium
252

An engineer is troubleshooting a DMVPN phase 2 network where the hub router is not forming an EIGRP neighbor relationship with a spoke. The spoke's tunnel interface is configured with 'ip nhrp nhs 10.0.0.1' and 'ip nhrp map 10.0.0.1 192.168.1.1'. The hub's tunnel interface IP is 10.0.0.1. The engineer pings the hub's tunnel IP from the spoke and it succeeds. The engineer checks 'show ip eigrp neighbors' on the hub and sees no neighbors. What is the most likely cause?

Medium
253

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# show ip access-lists 101 Extended IP access list 101 10 permit tcp 192.168.1.0 0.0.0.255 any eq 80 (12 matches) 20 deny tcp any any eq 443 (5 matches) 30 permit ip any any (100 matches) What does this output indicate?

Easy
254

What is the default NHRP holdtime value on a Cisco router?

Easy
255

Consider the following partial configuration on router R2: interface GigabitEthernet0/0 ip address 10.0.0.2 255.255.255.0 ip ospf 1 area 0 ! interface GigabitEthernet0/1 ip address 192.168.1.2 255.255.255.0 ip ospf 1 area 0 ! router ospf 1 router-id 2.2.2.2 network 10.0.0.0 0.0.0.255 area 0 network 192.168.1.0 0.0.0.255 area 0 What is the effect of this configuration?

Medium
256

Which of the following statements about MPLS label imposition and disposition is true?

Medium
257

A network engineer is configuring a Cisco IOS XE router for Zone-Based Policy Firewall (ZPFW) to control traffic between a LAN zone and a WAN zone. The engineer wants to inspect all TCP and UDP traffic initiated from the LAN zone toward the WAN zone, while denying any traffic initiated from the WAN zone toward the LAN zone. The engineer has already created the zones and assigned interfaces. Which configuration step is required to achieve this?

Medium
258

A network administrator is configuring a GRE tunnel between two Cisco routers to transport IPv6 traffic over an IPv4-only core. The administrator enters the following configuration on Router A: interface Tunnel0 ipv6 address 2001:DB8:100::1/64 tunnel source 10.1.1.1 tunnel destination 10.2.2.2 tunnel mode gre ipv6 However, the tunnel interface remains down. What is the most likely cause?

Easy
259

A network engineer runs the following command to troubleshoot a VRF-Lite DMVPN issue: R1# show ip nhrp vrf CUSTOMER_G detail Output: 10.6.6.1/32 via 10.6.6.1, Tunnel0 created 00:01:00, expire 01:59:00 Type: dynamic, Flags: used NBMA address: 192.168.1.1 (no-socket) Registration handle: 0x00000001 Cache entries: 1 What does this output indicate?

Hard
260

Which THREE statements about IPv6 Source Guard are true? (Choose THREE.)

Hard
261

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# show ip sla statistics 10 Round Trip Time (RTT) for Index 10 Latest RTT: 12 ms Latest RTT (milliseconds): 12 Latest RTT (microseconds): 12000 Last operation start time: 12:34:56.789 UTC Mon Mar 1 2021 Last operation return code: OK Number of successes: 100 Number of failures: 0 Operation time to live: Forever What does this output indicate?

Easy
262

A network engineer runs the following command on Router R1: R1# show crypto isakmp sa detail Codes: C - IKEv1, I - IKEv2 C-id Local Remote I-VRF Status Encr Hash Auth DH Lifetime Cap 1 10.1.1.1 10.1.1.2 ACTIVE aes sha psk 14 23:59:59 Based on this output, which statement is correct?

Medium
263

A network engineer runs the following command to troubleshoot a Control Plane Policing (CoPP) issue: R1# show policy-map control-plane input class CoPP-Class Class-map: CoPP-Class (match-all) 1500 packets, 120000 bytes 5 minute offered rate 10000 bps, drop rate 5000 bps Match: access-group name CoPP-ACL police: cir 8000 bps, bc 1500 bytes, be 1500 bytes conformed 1000 packets, 80000 bytes; actions: transmit exceeded 500 packets, 40000 bytes; actions: drop conformed 8000 bps, exceed 2000 bps, violated 0 bps What does this output indicate?

Hard
264

Examine the following configuration: logging host 10.1.1.1 logging host 10.1.1.2 logging host 10.1.1.3 logging origin-id hostname logging facility local7 What is the purpose of the 'logging origin-id hostname' command?

Medium
265

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against DoS attacks. The administrator wants to rate-limit ARP traffic destined to the route processor. Which configuration correctly applies a CoPP policy to ARP traffic?

Medium
266

A network engineer runs the following command on Router R9: R9# show ip route 192.168.50.0 Routing entry for 192.168.50.0/24 Known via "ospf 1", distance 110, metric 20 Redistributing via ospf 1 Last update from 10.0.0.1 on GigabitEthernet0/0, 00:00:10 ago Routing Descriptor Blocks: * 10.0.0.1, from 10.0.0.1, 00:00:10 ago, via GigabitEthernet0/0 Route metric is 20, traffic share count is 1 R9 also has an EIGRP route for the same prefix with distance 90 and metric 28160. Which route will be installed?

Easy
267

An engineer configures a Cisco IOS router with two static routes to the 10.10.0.0/16 network: one via 192.168.1.1 with administrative distance 1, and another via 192.168.2.1 with administrative distance 200. The route via 192.168.1.1 is installed in the routing table. Later, the interface to 192.168.1.1 goes down. Which statement describes the router's behavior?

Medium
268

A network engineer is deploying a GET VPN solution across a service provider MPLS network. The company requires that all group members use the same encryption keys and that any group member can decrypt traffic from any other group member. Which key distribution method should the engineer configure?

Medium
269

A network engineer is configuring a Cisco IOS router to authenticate SSH users against a TACACS+ server. The engineer wants to ensure that if the TACACS+ server is unreachable, the router will fall back to using the local username and password configured on the router. Which command set correctly configures this fallback behavior?

Medium
270

A network engineer runs the following command to troubleshoot OSPF route redistribution: R1# show ip ospf database external 5.5.5.5 OSPF Router with ID (1.1.1.1) (Process ID 1) Type-5 AS External Link States LS age: 120 Options: (No TOS-capability, DC, Upward) LS Type: AS External Link Link State ID: 5.5.5.5 (External Network Number) Advertising Router: 3.3.3.3 LS Seq Number: 80000001 Checksum: 0xABCD Length: 36 Network Mask: /32 Metric Type: 2 (Larger than any link state path) TOS: 0 Metric: 20 Forward Address: 0.0.0.0 External Route Tag: 0 What does this output indicate?

Hard
271

A network architect is designing a BGP routing policy to influence inbound traffic from an ISP. The architect wants to make a specific prefix less preferred by the ISP by prepending the AS path multiple times. Which BGP attribute should be manipulated to achieve this?

Hard
272

What is the maximum number of IPv6 over IPv4 tunnels that can be configured on a Cisco IOS router?

Easy
273

What is the default BGP hold timer value in Cisco IOS-XE?

Easy
274

An engineer is troubleshooting a DHCPv6 prefix delegation scenario. The router (R1) is a DHCPv6 client on its WAN interface and is supposed to receive a /48 prefix from the ISP's DHCPv6 server to delegate to LAN interfaces. The WAN interface is configured with 'ipv6 address dhcp' and 'ipv6 dhcp client pd ISP-PREFIX'. The LAN interfaces have 'ipv6 address ISP-PREFIX 0:0:0:1::/64 eui-64'. The engineer sees that the WAN interface gets a global IPv6 address, but the LAN interfaces do not get any IPv6 address. What is the most likely cause?

Hard
275

A network engineer is implementing MPLS Layer 3 VPNs. The engineer wants to ensure that customer routes are propagated across the MPLS core. Which protocol is typically used within the provider core to distribute VPNv4 routes?

Medium
276

A network engineer is troubleshooting a route filtering problem with prefix-lists. Router R6 is using a prefix-list to filter routes from a BGP neighbor. The prefix-list is configured to permit only 192.168.0.0/16 and 192.168.1.0/24, but routes with prefix 192.168.2.0/24 are also being accepted. The engineer checks the prefix-list configuration and sees only two permit statements. What is the most likely cause?

Hard
277

A network engineer runs the following command on Router R3: R3# show logging | include %OSPF-5-ADJCHG *Mar 1 00:05:10.123: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from LOADING to FULL, Loading Done *Mar 1 00:06:20.456: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from FULL to DOWN, Neighbor Down: Dead timer expired *Mar 1 00:07:30.789: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from DOWN to INIT, Received Hello *Mar 1 00:08:40.012: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from INIT to EXSTART, Event: start *Mar 1 00:09:50.345: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from EXSTART to EXCHANGE, Event: Negotiation Done *Mar 1 00:10:00.678: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from EXCHANGE to LOADING, Event: Exchange Done *Mar 1 00:11:10.901: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from LOADING to FULL, Loading Done *Mar 1 00:12:20.234: %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.1 on GigabitEthernet0/0 from FULL to DOWN, Neighbor Down: Dead timer expired Based on this output, what is the most likely problem?

Hard
278

Consider the following configuration on R5: !--- R5 configuration ip prefix-list PL-2 seq 5 permit 10.0.0.0/8 ge 16 le 24 ! route-map RMAP permit 10 match ip address prefix-list PL-2 set community 100:100 ! router bgp 65200 neighbor 192.168.1.2 route-map RMAP out ! What is the effect of this configuration?

Medium
279

Router R3 has the following configuration: ``` interface GigabitEthernet0/4 ip address 10.3.3.3 255.255.255.0 ip policy route-map PBR-IN ! route-map PBR-IN permit 10 match ip address 102 set ip next-hop verify-availability 192.168.2.1 10 track 1 ! access-list 102 permit ip 10.3.3.0 0.0.0.255 any ``` What is the effect of the 'set ip next-hop verify-availability' command?

Medium
280

Examine the RSPAN configuration: vlan 100 name RSPAN_VLAN remote-span ! monitor session 1 source interface GigabitEthernet1/0/1 both monitor session 1 destination remote vlan 100 What is the purpose of the 'remote-span' command under VLAN 100?

Medium
281

Which BGP loop prevention mechanism relies on the AS_PATH attribute?

Medium
282

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. The hub router must advertise a default route to all spokes, but the spokes should not use the hub as the next hop for spoke-to-spoke traffic; instead, they should dynamically discover a direct path to other spokes. Which NHRP configuration on the hub is required to support this behavior?

Hard
283

A network technician is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The technician enters the following commands: interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 cisco After applying the configuration, the router does not form an adjacency with its neighbor. What is the most likely reason?

Easy
284

A network engineer configures an RSPAN session on Switch A to monitor traffic from interface GigabitEthernet0/1 and sends it to Switch B. The engineer creates RSPAN VLAN 50 on both switches and configures the trunk between them to allow VLAN 50. On Switch B, the engineer configures the destination port as GigabitEthernet0/2 in VLAN 50. The engineer notices that the destination port is not forwarding any traffic. What should the engineer check first?

Hard
285

A network engineer runs the following command on Router R1: R1# show ip sla statistics 6 Round Trip Time (RTT) for Index 6 Latest RTT: 0 ms Latest RTT (milliseconds): 0 Latest RTT (microseconds): 0 Number of successes: 0 Number of failures: 100 Operation time to live: Forever Output: No connection R1# show track 4 Track 4 IP SLA 6 reachability Reachability is Down 3 changes, last change 00:05:00 Latest operation return code: No connection Latest RTT (milliseconds): 0 Tracked by: ip route 0.0.0.0 0.0.0.0 192.168.4.1 track 4 R1# show ip route 0.0.0.0 0.0.0.0 % Network not in table Based on this output, which statement is correct?

Medium
286

A network technician is configuring a GRE tunnel between two Cisco routers. The tunnel interface is up, but no traffic is passing. Which command should be used to verify that the tunnel source and destination are reachable?

Easy
287

An engineer configures Control Plane Policing (CoPP) on a router to protect the control plane. After applying the policy, the router becomes unreachable via SSH and SNMP. The engineer checks the policy and confirms that the class-map for SSH and SNMP traffic is set to 'permit'. What is the most likely explanation?

Hard
288

Which THREE symptoms indicate that IPv6 unicast RPF is misconfigured or failing on an interface? (Choose THREE.)

Hard
289

A network engineer runs the following command on Router R1: R1# show dmvpn Legend: Attrb -> S: Static, D: Dynamic, I: Incomplete N: NATed, L: Local, X: No Socket # Entries: 2 Interface: Tunnel0, IPv4 NHRP Details Type: Hub, NHRP Peers: 2, # Ent Peer NBMA Addr Peer Tunnel Addr State UpDn Tm Attrb ----- --------------- --------------- ----- -------- ----- 1 192.168.1.2 10.0.0.2 UP 00:15:30 D 2 192.168.2.2 10.0.0.3 UP 00:14:20 D Based on this output, which statement is correct?

Medium
290

A network engineer runs the following command on Router R1: R1# show event manager history events Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog OSPF_Neighbor_Down 2 00:01:31 UTC Mar 1 syslog OSPF_Neighbor_Up 3 00:01:32 UTC Mar 1 syslog OSPF_Neighbor_Down 4 00:01:33 UTC Mar 1 syslog OSPF_Neighbor_Up Based on this output, which statement is correct?

Medium
291

A network engineer runs the following command on Router R1: R1# show ipv6 ospf neighbor Neighbor ID Pri State Dead Time Address Interface 192.168.1.2 1 FULL/DR 00:00:32 FE80::2 Tunnel0 192.168.1.3 1 FULL/BDR 00:00:35 FE80::3 Tunnel0 Based on this output, which statement is correct?

Medium
292

A network engineer runs the following command on Router R1: R1# show ip route 10.0.0.0 255.255.252.0 longer-prefixes Routing entry for 10.0.0.0/22 Known via "eigrp 100", distance 90, metric 2172416, type internal Last update from 192.168.1.2 on GigabitEthernet0/0, 00:00:10 ago Routing Descriptor Blocks: * 192.168.1.2, from 192.168.1.2, 00:00:10 ago, via GigabitEthernet0/0 Route metric is 2172416, traffic share count is 1 Routing entry for 10.0.1.0/24 Known via "eigrp 100", distance 90, metric 2812416, type internal Last update from 192.168.1.2 on GigabitEthernet0/0, 00:00:10 ago Routing Descriptor Blocks: * 192.168.1.2, from 192.168.1.2, 00:00:10 ago, via GigabitEthernet0/0 Route metric is 2812416, traffic share count is 1 Based on this output, what is the effect of the summary route 10.0.0.0/22?

Hard
293

An engineer configures AS path prepending on an eBGP route to influence inbound traffic. However, traffic from a specific iBGP neighbor still prefers the prepended path. What is the most likely explanation?

Hard
294

Examine the following partial configuration on R1: !--- R1 configuration route-map RMAP permit 10 match ip address prefix-list PL-1 set metric 100 ! route-map RMAP permit 20 set metric 200 ! router eigrp 100 network 10.0.0.0 redistribute ospf 1 metric 1000 100 255 1 1500 route-map RMAP ! What is the effect of this configuration?

Medium
295

Which TWO statements about IP SLA ICMP echo operations are true? (Choose TWO.)

Medium
296

A network engineer is implementing route redistribution between OSPF and EIGRP on a Cisco IOS router. The engineer wants to prevent routing loops and ensure that routes redistributed from OSPF into EIGRP are not redistributed back into OSPF. Which mechanism should be used?

Hard
297

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer wants to ensure that the authentication key is not sent in clear text and that the key can be changed without disrupting the adjacency. Which command should be used to configure the key on the interface?

Medium
298

A network engineer configures a Cisco IOS router as a DHCP relay agent. The router interface connected to the DHCP clients is configured with 'ip helper-address 192.168.1.10'. Which type of traffic will be forwarded to the DHCP server at 192.168.1.10 by default?

Easy
299

snmp-server community public RO\nsnmp-server community private RW\nsnmp-server location DataCenter\nsnmp-server contact admin@example.com What is the effect of this configuration?

Medium
300

Examine this BGP configuration on router R3: router bgp 65001 neighbor 10.1.1.1 remote-as 65002 address-family ipv4 network 192.168.0.0 mask 255.255.252.0 aggregate-address 192.168.0.0 255.255.252.0 summary-only What is the effect of the 'aggregate-address' command with the 'summary-only' keyword?

Medium
301

A network administrator is implementing GET VPN on Cisco IOS routers. The key server is configured with a policy that includes the `rekey` command. Which statement accurately describes the behavior of the rekey mechanism in GET VPN?

Medium
302

A network administrator is configuring a Cisco IOS XE router to support IPv6. The administrator wants to enable IPv6 routing and assign an IPv6 address to an interface. Which command must be configured globally to enable IPv6 routing?

Easy
303

Consider the following partial DMVPN configuration on a hub router: interface Tunnel0 ip address 10.0.0.1 255.255.255.0 ip nhrp network-id 100 ip nhrp authentication cisco123 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ip nhrp map multicast dynamic ! What is the effect of this configuration?

Medium
304

A network engineer runs the following command on Router R1: R1# show ipv6 interface gigabitethernet 0/0 GigabitEthernet0/0 is up, line protocol is up IPv6 is enabled, link-local address is FE80::1 Global unicast address(es): 2001:DB8:1:1::1, subnet is 2001:DB8:1:1::/64 Joined group address(es): FF02::1 FF02::2 ICMP redirects are enabled ICMP unreachables are enabled ND DAD is enabled, number of DAD attempts: 1 ND reachable time is 30000 milliseconds ND advertised reachable time is 0 milliseconds ND advertised retransmit interval is 1000 milliseconds ND router advertisements are sent every 200 seconds ND router advertisements live for 1800 seconds Hosts use stateless autoconfig for addresses. IPv6 uRPF: strict mode (drop invalid packets) Inbound access list: FILTER-IPv6 Based on this output, which two features are configured on this interface?

Hard
305

A network engineer runs the following command to verify OSPFv3 database: R1# show ipv6 ospf database router 2.2.2.2 OSPFv3 Router with ID (1.1.1.1) (Process ID 1) Router Link States (Area 0) LS age: 60 LS Type: Router Links Link State ID: 0.0.0.0 Advertising Router: 2.2.2.2 LS Seq Number: 80000003 Checksum: 0x5678 Length: 40 Number of Links: 1 Link connected to: a Transit Network (Link ID) Interface ID: 2 (Link Data) Neighbor Interface ID: 1 Number of TOS metrics: 0 TOS 0 Metrics: 10 What does this output indicate?

Hard
306

A network engineer is implementing MPLS Layer 3 VPN on a Cisco IOS-XE router. The engineer needs to configure the router to exchange VPNv4 routes with a route reflector. The router is already configured with BGP AS 65001 and has established an IBGP session with the route reflector. Which address family must be activated to support VPNv4 route exchange?

Hard
307

A network engineer is configuring a static route on a Cisco IOS router to reach the network 192.168.2.0/24 via the next-hop address 10.1.1.2. The engineer enters the command 'ip route 192.168.2.0 255.255.255.0 10.1.1.2'. However, the route does not appear in the routing table. What is the most likely reason?

Easy
308

What is the default behavior of LDP when establishing a session between two directly connected routers?

Easy
309

A network engineer runs the following command on Router R1: R1# show ip bgp 192.168.0.0 255.255.252.0 BGP routing table entry for 192.168.0.0/22, version 5 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 65001 10.1.1.1 from 10.1.1.1 (10.1.1.1) Origin IGP, metric 0, localpref 100, valid, external, best Community: 65001:100 rx pathid: 0, tx pathid: 0x0 Aggregator: 65001, 10.1.1.1 Based on this output, what is true about this route?

Medium
310

Which default IPsec transform set is automatically created in Cisco IOS when configuring a site-to-site VPN?

Medium
311

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-IN Class-map: CoPP-ICMP (match-all) 0 packets, 0 bytes 5 minute offered rate 0000 bps, drop rate 0000 bps Match: access-group 100 police: cir 8000 bps, bc 1500 bytes, be 1500 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: CoPP-SSH (match-all) 0 packets, 0 bytes 5 minute offered rate 0000 bps, drop rate 0000 bps Match: access-group 110 police: cir 16000 bps, bc 3000 bytes, be 3000 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: class-default (match-any) 1250 packets, 75000 bytes 5 minute offered rate 1000 bps, drop rate 0000 bps Match: any Based on this output, which statement is correct?

Medium
312

A network engineer is configuring a GRE over IPsec tunnel between two Cisco IOS routers. The engineer wants to ensure that the GRE tunnel traffic is encrypted by IPsec. Which of the following configurations is required to achieve this?

Medium
313

Given this configuration on Router R6: ``` interface Tunnel0 ipv6 address 2001:DB8:8::1/64 tunnel source 2001:DB8:9::1 tunnel destination 2001:DB8:10::2 tunnel mode gre ipv6 tunnel path-mtu-discovery ``` What is the effect?

Medium
314

What is the default administrative distance for a route learned via the Border Gateway Protocol (BGP) from an external peer (eBGP)?

Medium
315

By default in Cisco IOS-XE, what is the behavior of an IPv4 ACL when no entries match and the ACL is applied to an inbound interface?

Easy
316

A network engineer is implementing MPLS Traffic Engineering (TE) with RSVP-TE. The engineer must ensure that the TE tunnel can be established and that the headend router can signal the path. Which two statements about RSVP-TE operation are true? (Choose two.)

Hard
317

Which TWO commands can be used to troubleshoot EIGRP route redistribution issues when routes are not appearing in the routing table? (Choose TWO.)

Medium
318

In BGP, what is the default value of the keepalive timer?

Medium
319

A network engineer is configuring MPLS Layer 3 VPN on a Cisco IOS XR router. The engineer needs to ensure that customer routes are properly propagated across the MPLS core. Which two of the following are required to establish the VPNv4 peering between PE routers? (Choose two.)

Hard
320

A network engineer is deploying an MPLS L3VPN using BGP as the PE-CE routing protocol. The customer requires that the PE router accept only routes with a specific BGP community and set a local preference of 200 for those routes. Which configuration on the PE router accomplishes this requirement?

Medium
321

A network administrator is configuring a Cisco IOS router to authenticate login users against a TACACS+ server. The administrator wants to ensure that if the TACACS+ server is unreachable, the router falls back to the local username database for authentication. Which configuration should be applied?

Medium
322

A network technician is configuring a static route on a Cisco router. The technician wants to ensure that the static route is only used when the primary route is unavailable. Which type of static route should be configured?

Easy
323

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The VPN tunnel is up, but traffic from the local subnet to the remote subnet is not passing. The administrator checks the crypto ACL and finds that it matches the traffic. Which of the following is the most likely cause of the problem?

Hard
324

Which of the following is the default EIGRP network type on a Frame Relay point-to-point subinterface?

Medium
325

What is the default administrative distance for OSPF routes in a VRF-Lite environment on Cisco IOS-XE?

Easy
326

A network engineer runs the following command to troubleshoot a VRF-Lite issue: R1# show ip eigrp vrf CUSTOMER_B topology 10.1.1.0/24 Output: IP-EIGRP (AS 100): Topology entry for 10.1.1.0/24 for VRF CUSTOMER_B State is Passive, Query origin flag is 1, 1 Successor(s), FD is 131072 Routing Descriptor Blocks: 10.1.1.1 (GigabitEthernet0/1), from 10.1.1.1, Send flag is 0x0 Composite metric is (131072/128256), Route is Internal Vector metric: Minimum bandwidth is 100000 Kbit Total delay is 100 microseconds Reliability is 255/255 Load is 1/255 Minimum MTU is 1500 Hop count is 1 What does this output indicate?

Medium
327

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that only specific traffic from the local subnet to the remote subnet is encrypted, while other traffic is sent in clear text. Which IPsec component is used to define the interesting traffic?

Easy
328

When redistributing routes between OSPF and EIGRP, which of the following is a recommended best practice to prevent routing loops?

Medium
329

A network engineer is configuring a Cisco IOS XE router as a DHCP relay agent. The router is connected to a LAN segment with DHCP clients and must forward DHCP requests to a DHCP server at 10.1.1.100. Which command must be configured on the LAN interface to enable DHCP relay?

Medium
330

A network engineer runs the following command to verify IPv6 uRPF operation: R1# show ipv6 interface GigabitEthernet0/0 | include verify IPv6 verify source: strict What does this output indicate?

Medium
331

A network engineer is configuring a Cisco IOS XE router to support MPLS Traffic Engineering (TE) with RSVP-TE. The engineer has enabled MPLS TE globally and on the interfaces. The engineer wants to ensure that the router can signal an LSP with a specific bandwidth requirement of 100 Mbps. Which command is required to enable RSVP-TE signaling on the interface?

Medium
332

Which CoPP mechanism prevents the CPU from being overwhelmed by control plane traffic?

Easy
333

A network engineer is configuring Zone-Based Policy Firewall on a Cisco IOS XE router. The company requires that all traffic from the internal LAN zone to the untrusted Internet zone be inspected, but traffic from the Internet to the internal LAN must be blocked unless it is return traffic. The engineer has already defined zone pairs with 'zone-pair security IN-TO-OUT source LAN destination INTERNET' and applied an inspect policy-map. What must the engineer do to complete the configuration?

Medium
334

An engineer configures OSPF area range on an ABR to summarize routes. After configuration, some routes are still being advertised as individual LSAs into the backbone. Which is the most likely explanation?

Hard
335

A network engineer is deploying MPLS Layer 3 VPNs on a Cisco IOS XE PE router. The customer VRF CUST_A uses OSPF as the PE-CE routing protocol. The engineer must ensure that OSPF routes from the customer are redistributed into MP-BGP and that the OSPF domain ID is preserved across the MPLS backbone. Which configuration step is required on the PE router?

Hard
336

Drag and drop the steps to verify and validate syslog operational state into the correct order, from first to last.

Medium
337

A network engineer runs the following command to verify IPv6 device tracking: R1# show ipv6 device-tracking database Interface MAC Address VLAN IPv6 Address State Age Policy Fa0/0 0011.2233.4455 10 2001:db8::1 ACTIVE 10 TRUSTED Fa0/0 00aa.bbcc.ddee 10 2001:db8::2 ACTIVE 5 INSPECT Fa0/0 1111.2222.3333 10 2001:db8::3 VERIFY 0 - What does this output indicate?

Medium
338

A service provider is deploying MPLS Traffic Engineering (TE) with RSVP-TE to guarantee bandwidth for critical traffic. The network uses OSPF as the IGP with TE extensions enabled. An engineer notices that a TE tunnel fails to establish because the path computation cannot find a path with sufficient bandwidth, even though the physical links have enough capacity. Which action should the engineer take to ensure that RSVP-TE can reserve bandwidth on the links?

Hard
339

A network engineer runs the following command to troubleshoot an IPv6 traffic filtering issue: R1# show ipv6 access-list FILTER IPv6 access list FILTER permit ipv6 2001:DB8:1::/48 any sequence 10 deny ipv6 2001:DB8:2::/48 any sequence 20 permit ipv6 any any sequence 30 What does this output indicate?

Medium
340

Given the partial configuration: crypto isakmp policy 10 encryption aes 256 authentication pre-share group 14 ! crypto isakmp key cisco123 address 0.0.0.0 0.0.0.0 ! crypto ipsec transform-set TSET esp-aes 256 esp-sha-hmac mode tunnel ! crypto map CMAP 10 ipsec-isakmp set peer 192.168.1.2 set transform-set TSET match address 101 ! interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 crypto map CMAP ! access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255 What is the effect of the 'crypto isakmp key' command with address 0.0.0.0 0.0.0.0?

Medium
341

A network engineer is configuring policy-based routing (PBR) on a Cisco router. The router has two interfaces: GigabitEthernet0/0 (LAN) and GigabitEthernet0/1 (WAN). The engineer wants to route traffic from the 192.168.1.0/24 subnet to a next-hop of 10.1.1.2, and all other traffic should follow the default routing table. Which two steps are required to implement this? (Choose two.)

Medium
342

A network engineer is configuring OSPF on a router. The router has an interface with IP address 10.1.1.1/24 and another interface with IP address 192.168.1.1/24. The engineer wants to enable OSPF on both interfaces using a single network command under router ospf 1. Which command accomplishes this?

Medium
343

In an MPLS L3VPN environment using MP-BGP, what is the default value of the BGP keepalive timer on Cisco IOS-XE?

Easy
344

A network engineer runs the following command to troubleshoot a VRF-Lite redistribution issue: R1# debug ip routing vrf CUSTOMER_E Output: RT: add 10.3.3.0/24 via 10.1.1.2, ospf 200 metric [110/20] RT: add 10.3.3.0/24 via 10.1.1.2, eigrp 100 metric [90/131072] tag 0 RT: closer admin distance for 10.3.3.0/24, adding via eigrp 100 RT: add 10.3.3.0/24 to routing table, via eigrp 100 What does this output indicate?

Hard
345

A network engineer runs the following command on Router R1: R1# show ipv6 traffic IPv6 statistics: Rcvd: 1000 total, 800 unicast, 200 multicast Sent: 900 total, 700 unicast, 200 multicast Errors: 0 Dropped: 0 ND statistics: NS: 50 received, 40 sent NA: 30 received, 20 sent RS: 10 received, 5 sent RA: 2 received, 8 sent Redirect: 0 received, 0 sent Based on this output, which statement is correct?

Medium
346

A network engineer runs the following command on Router R1: R1# show ip nhrp 10.0.0.2/32 via 10.0.0.2, Tunnel0 created 00:15:30, expire 01:44:30 Type: dynamic, Flags: used NBMA address: 192.168.1.2 10.0.0.3/32 via 10.0.0.3, Tunnel0 created 00:10:20, expire 01:49:40 Type: dynamic, Flags: used NBMA address: 192.168.1.3 Based on this output, which statement is correct?

Medium
347

A DMVPN network uses PBR to route traffic from spoke routers to specific hubs based on source IP. After a hub failure, traffic from spoke 1 (source 192.168.1.0/24) is being sent to a backup hub, but the backup hub drops the traffic. Router R1 (spoke) shows: 'show ip policy' shows PBR applied, 'debug ip policy' shows traffic being forwarded to next-hop 10.1.1.2 (backup hub). Router R2 (backup hub) shows: 'show ip route 192.168.1.0' returns no route. What is the root cause?

Hard
348

An engineer configures OSPF on a link between two routers with MTU 1500 on one side and MTU 1400 on the other. The adjacency forms but is stuck in EXSTART. Which is the most likely explanation?

Hard
349

Drag and drop the steps to configure a Control Plane Policing (CoPP) policy into the correct order, from first to last.

Medium
350

What is the default role of an interface in IPv6 Neighbor Discovery Inspection when no policy is explicitly applied?

Easy
351

A network engineer is configuring a static route on a Cisco IOS router. The engineer wants the route to be used only if the primary route fails. Which command should be used to configure a floating static route?

Easy
352

A network administrator is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers using IKEv2. Phase 1 is up, but Phase 2 fails to establish. The administrator runs 'show crypto ipsec sa' and sees no active SAs. Which action should the administrator take to resolve the issue?

Hard
353

Which THREE statements about PBR and route-map sequence numbers are true? (Choose THREE.)

Hard
354

A network administrator is troubleshooting a DMVPN Phase 3 network using OSPF as the routing protocol. Spoke routers are not learning routes from other spokes. Which two actions should be taken to resolve this issue? (Choose two.)

Hard
355

An engineer configures Control Plane Policing (CoPP) with a policy that denies all traffic in class-default. After applying the policy, BGP sessions to the router fail. What is the most likely explanation?

Hard
356

Drag and drop the steps to troubleshoot Control Plane Policing (CoPP) adjacency or connectivity failures into the correct order, from first to last.

Hard
357

Router R1 is configured with ip nat inside source list 100 interface Loopback0 overload. Internal hosts at 192.168.1.0/24 can access the internet, but external hosts cannot initiate connections to an internal server at 10.1.1.10 that is also behind NAT. The server is supposed to be reachable via static NAT. Configuration: ip nat inside source static tcp 10.1.1.10 80 interface Loopback0 80. Router R1 shows: show ip nat translations: Pro Inside global Inside local Outside local Outside global tcp 10.1.1.10:80 10.1.1.10:80 --- ---. External users get connection timeouts. What is the root cause?

Hard
358

A network engineer runs the following command to troubleshoot a BFD issue: R1# debug bfd event *Mar 1 00:12:34.567: BFD: [R1-to-R2] state DOWN -> UP (async) *Mar 1 00:12:34.568: BFD: [R1-to-R2] echo mode enabled, min-echo-rx-interval 50 ms *Mar 1 00:12:34.569: BFD: [R1-to-R2] starting echo timer, interval 50 ms *Mar 1 00:12:34.570: BFD: [R1-to-R2] sending async packet, state UP, interval 300 ms What does this output indicate?

Medium
359

What is the default action for a packet that does not match any route-map entry in a PBR policy?

Easy
360

A network engineer runs the following command on Router R1: R1# show ipv6 access-list FILTER-IPv6 IPv6 access list FILTER-IPv6 permit ipv6 2001:DB8:1::/48 any sequence 10 deny ipv6 any any sequence 20 Based on this output, what is the effect of this access list when applied to an interface?

Easy
361

A network engineer is configuring a GRE tunnel between two Cisco routers. The tunnel interface is up, but the engineer cannot ping the remote tunnel endpoint. The physical interfaces are up, and there is a route to the remote physical address. Which command should be used to verify that the tunnel source and destination are correctly configured?

Medium
362

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. The hub router must dynamically learn spoke-to-spoke routes without requiring a full mesh of tunnels. Which technology should be implemented on the hub to allow spoke routers to resolve next-hop addresses directly?

Medium
363

A network technician is configuring a Cisco IOS router to authenticate administrative users via TACACS+ using a centralized server. The requirement is that if the TACACS+ server is unreachable, the router should use the local username database for authentication. Which command sequence correctly configures this fallback behavior?

Easy
364

What is the default uRPF mode when 'ipv6 verify unicast source reachable-via' is configured without any keyword?

Easy
365

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent through the tunnel, while all other traffic is sent unencrypted. The engineer creates an extended ACL named VPN_TRAFFIC and applies it to the crypto map. However, after testing, the engineer finds that traffic from 192.168.1.0/24 is not being encrypted. Which action should the engineer take to correct the issue?

Hard
366

A network engineer configures EEM to monitor BGP prefix limits on R1. R1 has: event manager applet BGP-PREFIX event syslog pattern "%BGP-3-PREFIX_LIMIT" action 1.0 cli command "enable" action 2.0 cli command "clear ip bgp 10.1.1.2" action 3.0 syslog msg "Cleared BGP session". Router R2 shows: BGP session with R1 is flapping, and logs show repeated prefix limit warnings. What is the root cause?

Hard
367

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. The engineer also wants to use a pre-shared key for authentication. Which configuration element is required to define the interesting traffic?

Hard
368

Consider the following configuration on router R1: crypto isakmp policy 10 encryption aes 256 authentication pre-share group 14 lifetime 86400 ! crypto isakmp key cisco123 address 192.168.1.2 ! crypto ipsec transform-set TSET esp-aes 256 esp-sha-hmac mode tunnel ! crypto map CMAP 10 ipsec-isakmp set peer 192.168.1.2 set transform-set TSET match address 101 ! interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 crypto map CMAP ! access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255 If the remote peer has an ISAKMP policy with encryption 3des, what will happen?

Medium
369

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 10.3.3.0/24 BGP routing table entry for 10.3.3.0/24, version 10 Paths: (2 available, best #2, table default) Advertised to update-groups: 1 Refresh Epoch 1 65003 65004 10.1.13.3 from 10.1.13.3 (10.3.3.3) Origin IGP, metric 0, localpref 100, valid, external rx pathid: 0, tx pathid: 0 Refresh Epoch 1 65005 10.1.15.5 from 10.1.15.5 (10.5.5.5) Origin IGP, metric 0, localpref 200, valid, external, best rx pathid: 0, tx pathid: 0x0 Based on this output, why is the path via 10.1.15.5 chosen as best?

Medium
370

According to Cisco IOS default behavior, if a router learns the same route via both RIP and OSPF, which route will be installed in the routing table?

Easy
371

Which statement correctly describes the behavior of ISATAP tunneling regarding host configuration?

Medium
372

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to ensure that packets are dropped if the source IP address is not reachable via the same interface they arrived on. The engineer configures 'ip verify unicast source reachable-via rx' on interface GigabitEthernet0/0. However, some legitimate traffic from a secondary path is being dropped. What is the most likely cause?

Medium
373

Which TWO statements about the interaction between administrative distance and floating static routes are true? (Choose TWO.)

Hard
374

A network engineer is configuring MPLS Traffic Engineering (TE) with RSVP-TE on a Cisco IOS XE router to provide bandwidth guarantees for delay-sensitive traffic. The engineer must ensure that the TE tunnel can signal the required bandwidth and that the path is computed based on available resources. Which two statements about the configuration are true? (Choose two.)

Hard
375

Drag and drop the steps to verify and validate the MPLS L3VPN operational state into the correct order, from first to last.

Medium
376

A network administrator is deploying DMVPN Phase 3 with IKEv2. The hub router is configured with a dynamic multipoint VPN tunnel and is using NHRP. Spoke routers are configured to register with the hub. After configuration, the administrator notices that spoke-to-spoke traffic is still going through the hub instead of directly between spokes. Which configuration change is most likely to resolve this issue?

Medium
377

A network engineer is deploying an MPLS Layer 3 VPN for a customer. The customer requires that the provider edge (PE) routers support a unique route distinguisher (RD) per VRF and that the same customer routes be imported into multiple VRFs. Which configuration on the PE router accomplishes this requirement?

Medium
378

A network engineer is configuring a Cisco IOS XE router for MPLS Layer 3 VPN. The router is a PE connected to a CE via GigabitEthernet0/0. The engineer wants to configure a VRF named CUSTOMER_A and assign the interface to it. The engineer enters the following commands: `vrf definition CUSTOMER_A`, `rd 65000:1`, `address-family ipv4`, `exit`, `exit`. Then, under interface GigabitEthernet0/0, the engineer enters `vrf forwarding CUSTOMER_A`. After entering the command, the engineer notices that the IP address on the interface is removed. What is the most likely reason?

Hard
379

An engineer configures ERSPAN on a Cisco router to send mirrored traffic to a remote collector via IP. The collector receives the ERSPAN packets, but the payload appears truncated or malformed. What is the most likely cause?

Hard
380

Which DHCPv4 option is used by a client to request a specific IP address in the DHCPREQUEST message?

Medium
381

A network engineer runs the following command to troubleshoot DHCPv6 guard: R1# debug ipv6 dhcp guard *Mar 1 00:03:45.678: IPv6-DHCP-Guard: R1, Fa0/0, DHCPv6 SOLICIT from fe80::3, client DUID 00010001abcd1234 *Mar 1 00:03:45.678: IPv6-DHCP-Guard: R1, Fa0/0, DHCPv6 SOLICIT from fe80::3 is allowed by policy DHCP-POLICY *Mar 1 00:03:46.901: IPv6-DHCP-Guard: R1, Fa0/0, DHCPv6 ADVERTISE from fe80::4, server DUID 0001000156789012 *Mar 1 00:03:46.901: IPv6-DHCP-Guard: R1, Fa0/0, DHCPv6 ADVERTISE from fe80::4 is blocked by policy DHCP-POLICY What does this output indicate?

Medium
382

An engineer configures an IPsec site-to-site VPN between two routers using iBGP for routing. The BGP session comes up, but routes learned from the remote site are not installed in the routing table. The engineer verifies that the IPsec tunnel is up and that the BGP prefixes are present in the BGP table. What is the most likely explanation?

Hard
383

Drag and drop the steps to verify and validate Device Access Control operational state into the correct order, from first to last.

Medium
384

An engineer configures NAT on a router with 'ip nat inside source list 1 interface GigabitEthernet0/0 overload'. The inside hosts are 10.0.0.0/24, and the outside interface is 203.0.113.1. Traffic works for most hosts, but one host at 10.0.0.50 cannot access the internet. 'Show ip nat translations' shows no entry for this host. 'Show access-lists' shows ACL 1 permits 10.0.0.0 0.0.0.255. What is the most likely cause?

Medium
385

What is the default CoPP policer action for packets that exceed the committed information rate (CIR)?

Easy
386

Drag and drop the steps to troubleshoot Device Management adjacency or connectivity failures into the correct order, from first to last.

Hard
387

A network engineer runs the following command on Router R1: R1# show ip eigrp topology 10.50.50.0/24 EIGRP-IPv4 Topology Entry for AS(100)/ID(192.168.1.1) for 10.50.50.0/24 State: Active, Reply status: 0, Originating router: 192.168.1.1 Routing Descriptor Blocks: 10.1.1.2 (GigabitEthernet0/0), from 10.1.1.2, Send flag: 0x0 Composite metric: (4294967295/4294967295), Route is Internal Vector metric: Minimum bandwidth: 100000 Kbit Total delay: 100 microseconds Reliability: 255/255 Load: 1/255 Minimum MTU: 1500 Hop count: 1 Based on this output, what is the problem?

Hard
388

A network administrator is troubleshooting an EIGRP adjacency that is stuck in the ACTIVE state. The adjacency is between two routers, R1 and R2, on a point-to-point link. The administrator notices that R1 is sending queries but not receiving replies. Which of the following is the most likely cause?

Hard
389

Which TWO commands can be used to verify OSPFv2 path selection and cost metrics on a Cisco IOS router? (Choose TWO.)

Medium
390

A network engineer runs the following command to troubleshoot OSPF route propagation: R1# show ip ospf database router 2.2.2.2 OSPF Router with ID (1.1.1.1) (Process ID 1) Router Link States (Area 0) LS age: 45 Options: (No TOS-capability, DC) LS Type: Router Links Link State ID: 2.2.2.2 Advertising Router: 2.2.2.2 LS Seq Number: 80000005 Checksum: 0x1234 Length: 48 Number of Links: 2 Link connected to: a Transit Network (Link ID) Designated Router address: 10.1.1.2 (Link Data) Router Interface address: 10.1.1.2 Number of TOS metrics: 0 TOS 0 Metrics: 10 Link connected to: a Stub Network (Link ID) Network/subnet number: 192.168.1.0 (Link Data) Network Mask: 255.255.255.0 Number of TOS metrics: 0 TOS 0 Metrics: 10 What does this output indicate?

Medium
391

A network administrator is configuring a Cisco IOS XE router to act as a DHCP relay agent. The router is connected to a client subnet on GigabitEthernet0/0 and to a DHCP server at 192.168.1.100 on GigabitEthernet0/1. The administrator enters the command 'ip helper-address 192.168.1.100' on GigabitEthernet0/0. Which statement is true about the behavior of this configuration?

Easy
392

A network administrator is deploying a DMVPN Phase 3 hub-and-spoke topology. Spokes must be able to communicate directly with each other without traffic traversing the hub. The administrator has configured NHRP and IPsec on all routers. Which additional configuration is required on the hub to enable direct spoke-to-spoke communication?

Medium
393

A network administrator is troubleshooting a DMVPN Phase 3 deployment using mGRE and IPsec. Spoke-to-spoke communication is not working directly; traffic is flowing through the hub. The administrator verifies that NHRP registrations are successful and that the hub has a route to all spokes. Which two actions are required to enable direct spoke-to-spoke communication? (Choose two.)

Hard
394

A network engineer is configuring a Cisco IOS router to act as a DHCP relay agent. The router receives DHCP discover messages on interface GigabitEthernet0/1 and must forward them to a DHCP server at 10.1.1.100. Which command is required on the router?

Easy
395

A network engineer is deploying MPLS Layer 3 VPNs on Cisco IOS routers. The engineer must ensure that customer routes are properly propagated across the MPLS core and that labels are correctly assigned. Which two protocols are used within the MPLS core to distribute labels and VPNv4 routes? (Choose two.)

Hard
396

Which command correctly configures a static route on a Cisco IOS router to reach the network 172.16.0.0/16 via the next-hop address 10.1.1.1?

Easy
397

Examine this configuration on Router R6: router ospf 1 redistribute eigrp 100 subnets default-information originate always What is a likely problem with this configuration?

Hard
398

A network engineer is configuring a branch router to obtain its WAN interface IPv4 address from an ISP using DHCP. The provider requires the router to send a specific client identifier. Which command must be applied under the interface configuration to meet this requirement?

Medium
399

A network engineer runs the following command on Router R1: R1# show flow monitor FLOW-MONITOR-1 statistics Monitor: FLOW-MONITOR-1 Record: netflow-original Exporter: EXPORTER-1 Cache size: 1000 Current entries: 0 Flows exported: 0 Packets exported: 0 Sampler: Not configured Flow Monitor is not attached to any interface Based on this output, what action should the engineer take to resolve the issue?

Easy
400

A network administrator is troubleshooting a route redistribution issue on a Cisco router running both EIGRP and OSPF. The router is redistributing EIGRP routes into OSPF, but the routes are not appearing in the OSPF domain. The administrator has configured redistribution with a seed metric of 20. Which additional configuration is required to ensure the routes are advertised?

Hard
401

Drag and drop the steps for troubleshooting MPLS operations adjacency or connectivity failures into the correct order, from first to last.

Hard
402

A network engineer is troubleshooting an IPsec VPN tunnel between two Cisco IOS routers. The tunnel fails to establish, and the engineer sees the debug output: 'ISAKMP: Unable to find a valid preshared key'. The engineer verifies that the preshared key is identical on both peers. Which additional configuration is most likely causing the issue?

Hard
403

EIGRP network with routers R1, R2, R3. R1 has: router eigrp 100 network 10.0.0.0 R2 has: router eigrp 100 network 10.0.0.0 R3 has: router eigrp 100 network 10.0.0.0 R1 shows: R1# show ip eigrp topology 10.1.1.0/24 EIGRP-IPv4 Topology Entry for 10.1.1.0/24 State is Passive, Query origin flag is 1, 1 Successor(s), FD is 128256 Routing Descriptor Blocks: 10.2.1.2 (Serial0/0/0), from 10.2.1.2, Send flag is 0x0 Composite metric is (128256/156160), Route is Internal 10.3.1.3 (Serial0/0/1), from 10.3.1.3, Send flag is 0x0 Composite metric is (156160/128256), Route is Internal R1# show ip route 10.1.1.0 Routing entry for 10.1.1.0/24 Known via "eigrp 100", distance 90, metric 128256 Last update from 10.2.1.2 on Serial0/0/0 An engineer expected R1 to use the path via 10.3.1.3 because it appears in the topology table, but R1 is using the path via 10.2.1.2. What is the reason?

Hard
404

Drag and drop the steps to verify and validate IPv6 First Hop Security operational state into the correct order, from first to last.

Medium
405

A network administrator is configuring a GRE tunnel between two Cisco IOS routers. The tunnel must support multicast traffic and be protected by IPsec. Which two statements about the configuration are true? (Choose two.)

Medium
406

A network engineer notices that BGP sessions between two directly connected routers are flapping every few minutes. The routers are running IOS-XE 17.3 and have CoPP enabled. The engineer checks the CoPP policy and sees a class-map matching BGP packets with a police rate of 8000 bps. The BGP session uses MD5 authentication and the routers exchange a full BGP table with 500,000 prefixes. What is the most likely cause of the BGP session flapping?

Hard
407

An engineer is troubleshooting an IPv6 connectivity issue where hosts on VLAN 10 cannot reach the internet. The switch is configured with IPv6 First Hop Security features including RA Guard and DHCPv6 Guard. The legitimate router is connected to port Gi1/0/1. The engineer notices that the router is sending RAs, but hosts are not receiving them. The switch shows that RA Guard is dropping packets on port Gi1/0/1. What is the most likely misconfiguration?

Hard
408

A network engineer runs the following command on Router R1: R1# show ipv6 mld interface tunnel 0 Tunnel0 is up, line protocol is up Internet address is FE80::1 MLD is enabled on interface Current MLD version is 2 MLD query interval is 125 seconds MLD querier timeout is 255 seconds MLD max query response time is 10 seconds Last member query response interval is 1 second MLD activity: 0 joins, 0 leaves MLD querying router is FE80::1 (this system) Based on this output, what can be concluded?

Medium
409

Which TWO configuration steps are required to enable VRF-Lite on a Cisco IOS-XE router for a customer with two separate routing domains? (Choose TWO.)

Medium
410

Which OSPF LSA type is used to advertise a summary route for a network outside the area but within the same OSPF domain?

Medium
411

Which THREE symptoms indicate that Control Plane Policing (CoPP) might be misconfigured or causing connectivity issues? (Choose THREE.)

Hard
412

A network administrator is building a FlexVPN hub-and-spoke deployment using IKEv2 on a Cisco IOS router. The hub must accept connections from many spokes that use dynamically assigned public addresses, and the administrator wants the hub to authorize each spoke and assign it an address from a pool after authentication. Which IKEv2 configuration element on the hub provides the address assignment to authenticated spokes?

Medium
413

A network engineer is troubleshooting a DMVPN Phase 3 network using EIGRP as the routing protocol. Spoke routers are unable to establish direct spoke-to-spoke tunnels. The engineer verifies that NHRP registration is successful and that the hub has routes to all spokes. Which action is most likely to resolve the issue?

Hard
414

A network engineer is configuring EIGRP on a Cisco router. The router has two paths to the same destination network with different metrics. The engineer wants to enable unequal-cost load balancing. Which command must be configured to allow EIGRP to use the higher-cost path?

Medium
415

A network engineer is implementing MPLS Layer 3 VPNs. The engineer needs to configure a PE router to exchange VPNv4 routes with other PE routers. Which BGP configuration is required to enable the exchange of VPNv4 routes?

Hard
416

A network engineer runs the following command on Router R1: R1# show ip eigrp neighbors EIGRP-IPv4 Neighbors for AS(100) H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 10.1.1.2 Gi0/0 13 00:12:34 1 200 0 45 1 10.2.2.2 Gi0/1 12 00:11:20 2 200 0 67 2 10.3.3.2 Gi0/2 10 00:10:15 1 200 0 89 Based on this output, which statement is correct?

Medium
417

Which THREE symptoms indicate a problem with route redistribution causing suboptimal routing or routing loops? (Choose THREE.)

Hard
418

A network engineer is troubleshooting a BGP route reachability issue. R1 learns the prefix 10.1.1.0/24 via eBGP from R2 with an AD of 20, and via OSPF from R3 with an AD of 110. The engineer notices that R1 installs the OSPF route in the routing table instead of the eBGP route, even though the eBGP route is preferred by default. What is the most likely cause of this behavior?

Medium
419

Which IP SLA operation type is used to monitor the availability of a TCP-based service by attempting a three-way handshake?

Easy
420

Drag and drop the steps to troubleshoot IPv4 ACL adjacency or connectivity failures into the correct order, from first to last.

Hard
421

Consider the following CoPP configuration: access-list 150 permit tcp any any eq 179 access-list 150 permit udp any any eq 646 ! class-map match-all COPP-CORE match access-group 150 ! policy-map COPP-POLICY class COPP-CORE police 64000 conform-action transmit exceed-action drop class class-default police 128000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP-POLICY What is missing from this configuration to also protect against ICMP-based control-plane attacks?

Medium
422

A network engineer runs the following command on Router R1: R1# show crypto ipsec transform-set Transform set ESP-AES256-SHA: { esp-256-aes esp-sha256-hmac } will negotiate = { Tunnel, }, Transform set ESP-AES128-SHA: { esp-aes esp-sha256-hmac } will negotiate = { Tunnel, }, Based on this output, which statement is correct?

Easy
423

A network engineer runs the following command to verify IPv6 ND inspection policy: R1# show ipv6 nd inspection policy INSPECT Policy: INSPECT Status: Active Device role: node Trusted ports: none Untrusted ports: Fa0/0 ND inspection: enabled Validation: - Source MAC address: verify - Destination MAC address: verify - IPv6 source address: verify - IPv6 destination address: verify - Nonce: disabled - Timestamp: disabled What does this output indicate?

Medium
424

A network engineer is troubleshooting a DMVPN Phase 3 network using Cisco IOS XE routers. Spoke routers are unable to establish direct spoke-to-spoke tunnels. The hub router is configured with 'ip nhrp redirect', and spokes are configured with 'ip nhrp shortcut'. The engineer notices that spoke routers are not receiving NHRP redirect messages from the hub. Which action should be taken to resolve this issue?

Hard
425

Examine the following configuration on a PE router: ip vrf CUSTOMER-C rd 200:1 ! interface GigabitEthernet0/3 ip vrf forwarding CUSTOMER-C ip address 10.2.2.1 255.255.255.252 ! router ospf 1 vrf CUSTOMER-C network 10.2.2.0 0.0.0.3 area 0 ! router bgp 65000 address-family ipv4 vrf CUSTOMER-C redistribute ospf 1 exit-address-family What is missing from this configuration?

Medium
426

What is the default active flow timeout value in Cisco IOS Flexible NetFlow?

Easy
427

An engineer configures Flexible NetFlow with a user-defined flow record that includes 'match ipv4 source address' and 'collect counter bytes'. Which TWO additional statements about this configuration are true? (Choose TWO.)

Hard
428

Which TWO statements about NAT overload (PAT) are true? (Choose TWO.)

Medium
429

A network engineer is troubleshooting an intermittent BGP session failure between two routers. The BGP session drops every few hours and recovers after a few seconds. The engineer checks the logs and sees that an EEM applet is triggered just before each failure. The applet is configured to run a script that clears the BGP session when a specific syslog message is generated. What is the most likely cause of the BGP session failure?

Medium
430

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS XE router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 (WAN, connected to ISP) and GigabitEthernet0/1 (LAN, connected to internal network). The engineer wants to apply strict uRPF on the WAN interface to drop packets with spoofed source addresses, but the internal network uses asymmetric routing, with some return traffic going out a different interface. The engineer applies the following configuration: interface GigabitEthernet0/0 ip address 203.0.113.1 255.255.255.0 ip verify unicast source reachable-via rx After applying this, the engineer notices that some legitimate traffic from the internal network is being dropped. Which action should the engineer take to resolve the issue while maintaining spoofing protection?

Hard
431

A network engineer is configuring OSPFv3 on a Cisco router. The router has two interfaces in Area 0: GigabitEthernet0/0 (IPv6 address 2001:db8:1::1/64) and GigabitEthernet0/1 (IPv6 address 2001:db8:2::1/64). After enabling IPv6 unicast routing and configuring OSPFv3 with the router-id 1.1.1.1, the engineer notices that no OSPFv3 neighbors are forming. Which action is most likely to resolve the issue?

Medium
432

A network engineer is configuring a Cisco IOS router as a DHCP server for a subnet. The router must exclude the address 10.10.10.1 from being assigned to clients. Which command correctly accomplishes this?

Easy
433

Which TWO commands can be used to verify DHCP IPv4 server operation and address pool utilization on a Cisco IOS router? (Choose TWO.)

Medium
434

A network engineer runs the following command on Router R1: R1# show ip dhcp server statistics Memory usage 26140 Address conflicts 0 Pool statistics Pool IP addresses Requests Offers Acks Naks Declines Releases POOL1 10-20 50 45 40 5 2 3 Based on this output, which statement is correct?

Hard
435

Which BGP attribute is used for loop prevention in eBGP?

Easy
436

A network engineer runs the following command to troubleshoot IPv6 ND inspection: R1# debug ipv6 nd inspection *Mar 1 00:02:34.567: IPv6-ND-Inspection: R1, Fa0/0, NS from fe80::1 to ff02::1, target 2001:db8::1, options: SLLA 0011.2233.4455 *Mar 1 00:02:34.567: IPv6-ND-Inspection: R1, Fa0/0, NS from fe80::1 to ff02::1, target 2001:db8::1, SLLA 0011.2233.4455 is allowed by policy INSPECT *Mar 1 00:02:35.890: IPv6-ND-Inspection: R1, Fa0/0, NA from fe80::2 to fe80::1, target 2001:db8::2, options: TLLA 00aa.bbcc.ddee *Mar 1 00:02:35.890: IPv6-ND-Inspection: R1, Fa0/0, NA from fe80::2 to fe80::1, target 2001:db8::2, TLLA 00aa.bbcc.ddee is blocked by policy INSPECT What does this output indicate?

Hard
437

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# show crypto map Crypto Map "CMAP" 10 ipsec-isakmp Peer = 192.168.2.2 Extended IP access list 101 access-list 101 permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255 Current peer: 192.168.2.2 Security association lifetime: 4608000 kilobytes/3600 seconds PFS (Y/N): N Transform sets={myset, } Interfaces using crypto map CMAP: Tunnel0 What does this output indicate?

Easy
438

Given the following partial configuration on router R5: interface GigabitEthernet0/0 ip address 10.1.1.1 255.255.255.0 ip pim sparse-mode ! interface GigabitEthernet0/1 ip address 10.2.2.1 255.255.255.0 ip pim sparse-mode ! router ospf 1 router-id 5.5.5.5 network 10.0.0.0 0.255.255.255 area 0 What is the effect of this configuration?

Medium
439

A network engineer runs the following command on Router R1: R1# show snmp mib ifmib ifindex ifIndex: 1 Interface: GigabitEthernet0/0 Description: GigabitEthernet0/0 ifIndex: 2 Interface: GigabitEthernet0/1 Description: GigabitEthernet0/1 ifIndex: 3 Interface: Loopback0 Description: Loopback0 ifIndex: 10 Interface: Tunnel0 Description: Tunnel0 Based on this output, which statement is correct?

Easy
440

What is the default DHCPv4 server lease time on a Cisco IOS-XE router configured as a DHCP server?

Hard
441

A network engineer is configuring Policy-Based Routing (PBR) on a Cisco router. The goal is to forward all HTTP traffic (TCP port 80) from the 10.1.1.0/24 subnet to next-hop 192.168.2.1. Which configuration sequence is correct?

Medium
442

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP class-map: MANAGEMENT (match-all) 100 packets, 10000 bytes 5 minute offered rate 0 bps police: cir 8000 bps, bc 1500 bytes conformed 100 packets, 10000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop conformed 0 bps, exceed 0 bps Based on this output, which statement is correct?

Medium
443

An engineer configures mutual redistribution between OSPF and EIGRP on a PE router in an MPLS L3VPN. The engineer does not configure any route tagging or filtering. After a few minutes, the OSPF and EIGRP domains become unstable, with routes flapping and high CPU usage. What is the most likely explanation?

Hard
444

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS router. The engineer wants to route traffic from subnet 10.1.1.0/24 to a specific next-hop 192.168.1.1, while all other traffic uses the default route. The engineer configures a route map named PBR with a match statement for the subnet and a set statement for the next-hop, and applies it to the inbound interface of the subnet. However, traffic from 10.1.1.0/24 is still following the default route. What is the most likely reason?

Hard
445

A network engineer is configuring DMVPN Phase 3 on a hub router. The hub must forward traffic directly between spokes without traversing the hub. Which command is required on the hub to enable this behavior?

Medium
446

Which NetFlow version is the default export format when using Flexible NetFlow with the 'record netflow ipv4 original-input' command?

Easy
447

A network administrator is configuring AAA on a Cisco IOS router using TACACS+. The requirement is that if the TACACS+ server is unreachable, the router should allow administrative access using the local username and password configured on the router. Which configuration accomplishes this?

Hard
448

A network administrator is configuring a Cisco IOS router to act as a DHCP server for a LAN segment. The administrator wants to exclude a range of IP addresses from being assigned to clients because those addresses are statically assigned to servers and printers. Which command should be used to accomplish this?

Easy
449

Given the following partial configuration on router R1: ip sla 10 icmp-echo 192.168.1.1 source-ip 10.0.0.1 frequency 10 ip sla schedule 10 life forever start-time now Which statement best describes the effect of this configuration?

Medium
450

A network engineer runs the following command on Router R1: R1# show ip dhcp relay information trusted Interface Trusted GigabitEthernet0/1 Yes GigabitEthernet0/2 No Based on this output, which statement is correct?

Easy
451

A network engineer is deploying DMVPN Phase 3 with NHRP and wants spoke-to-spoke traffic to be built directly between spokes without traversing the hub after initial resolution. On the hub router, the engineer issues the command 'ip nhrp redirect' on the tunnel interface and 'ip nhrp shortcut' on each spoke tunnel interface. After configuration, spokes can reach the hub but spoke-to-spoke traffic still hairpins through the hub. Which additional configuration is required on the spoke routers for the shortcut path to be installed?

Medium
452

Drag and drop the steps to enable and verify RESTCONF on IOS-XE into the correct order, from first to last.

Medium
453

A network engineer is configuring a Cisco router to support MPLS Layer 3 VPNs. The engineer needs to enable the router to exchange VPNv4 routes with a provider edge (PE) router. Which address family must be configured under the BGP routing process to support this?

Medium
454

A network engineer is implementing GET VPN using GDOI on Cisco IOS routers. The key server must distribute the group policy, and the group members must register and receive rekey messages. The engineer needs to verify which components are required for the group members to successfully join the group and decrypt traffic. (Choose two.)

Hard
455

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast summary BGP router identifier 192.168.1.1, local AS number 65001 BGP table version is 10, main routing table version 10 Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 10.1.1.2 4 65002 1200 1200 10 0 0 01:00:00 5 10.2.2.2 4 65003 0 0 0 0 0 never Active Based on this output, what is the problem with the neighbor 10.2.2.2?

Medium
456

An engineer configures a DMVPN Phase 2 network. Spoke routers can communicate with the hub, but spoke-to-spoke traffic does not trigger a direct tunnel. Which is the most likely explanation?

Hard
457

Which OSPF LSA type is used to advertise prefixes from other areas into the backbone area?

Medium
458

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. Spokes are behind NAT devices and have dynamically assigned public IP addresses. The engineer wants to ensure that spoke-to-spoke traffic can be established directly without traversing the hub. Which technology should be implemented on the hub to achieve this?

Medium
459

A network engineer is troubleshooting a route redistribution issue between RIP and OSPF. Router R1 runs both RIP and OSPF, and redistributes RIP routes into OSPF. The engineer notices that RIP routes are not appearing in the OSPF database on neighboring routers. The show ip ospf database external command on a neighbor shows no external routes from R1. The redistribute rip command is configured under OSPF on R1. What is the most likely cause?

Medium
460

What is the default metric for an IPv6 static route redistributed into OSPFv3?

Hard
461

A network administrator is deploying MPLS Layer 3 VPNs across a service provider backbone. The provider uses OSPF as the IGP and MP-BGP for VPNv4 route distribution. The administrator notices that VPNv4 routes are not being advertised between PE routers. Which configuration step is most likely missing on the PE routers?

Hard
462

What is the default CoPP policy on a Cisco IOS-XE router if no service-policy is applied to the control-plane?

Easy
463

Which THREE symptoms indicate that route summarization may be causing routing issues in a network? (Choose THREE.)

Hard
464

Which BGP message type is sent when a fatal error is detected, causing the BGP session to close?

Easy
465

A network administrator is troubleshooting an 802.1X deployment on a Cisco switch. Users report that they cannot authenticate and are placed into a guest VLAN. The administrator suspects that the switch is not receiving EAPOL packets from the supplicants. Which two actions should the administrator take to verify that EAPOL packets are being received and processed on the switch? (Choose two.)

Medium
466

What is the maximum hop count for a route in RIP?

Easy
467

A network administrator is troubleshooting a site-to-site IPsec VPN between two Cisco IOS routers using IKEv1. Phase 1 completes successfully, but Phase 2 fails with the message 'QM_IDLE' and no IPSec SA is established. The administrator verifies that the transform sets on both peers contain matching encryption and hash algorithms. Which configuration mismatch is the most likely cause of the Phase 2 failure?

Medium
468

A network engineer is configuring DMVPN Phase 3 with IKEv2. The hub router is a Cisco IOS XE device, and the goal is to allow spoke-to-spoke traffic to bypass the hub after initial registration. Which command must be configured on the hub to enable NHRP redirects?

Medium
469

A network engineer is deploying MPLS Layer 3 VPNs. The engineer must ensure that the PE routers can forward VPN traffic correctly. The following configuration is applied on a PE router: ip vrf CUSTOMER rd 65000:1 route-target export 65000:1 route-target import 65000:1 ! interface GigabitEthernet0/1 ip vrf forwarding CUSTOMER ip address 192.168.1.1 255.255.255.0 After configuration, the engineer notices that the CE router cannot reach remote sites. The MPLS core is operational, and MP-BGP is configured. What is the most likely missing configuration?

Medium
470

A network engineer runs the following command to verify DHCPv4 pool configuration on router R1: R1# show ip dhcp pool DHCP_POOL Output: Pool DHCP_POOL : Utilization mark (high/low) : 100 / 0 Subnet size (first/next) : 0 / 0 Total addresses : 254 Leased addresses : 100 Pending event : none 1 subnet is currently in the pool : Current index IP address range Leased addresses 192.168.1.1 192.168.1.1 - 192.168.1.254 100 What does this output indicate?

Easy
471

A network engineer is troubleshooting a VRF-Lite deployment where a router is configured with VRF_ORANGE. The engineer attempts to configure a static route in VRF_ORANGE using the command 'ip route vrf VRF_ORANGE 192.168.10.0 255.255.255.0 10.1.1.1', but the route does not appear in the routing table. The 'show ip route vrf VRF_ORANGE' does not show the static route. What is the most likely cause?

Easy
472

Which THREE symptoms indicate a DHCP IPv4 starvation attack or address pool exhaustion? (Choose THREE.)

Medium
473

An engineer is troubleshooting a router that is configured as an NTP client. The router's clock is not synchronizing with the NTP server at 192.168.1.1. 'show ntp status' shows 'clock is unsynchronized', and 'show ntp associations' shows the server as '.INIT.' with no reachability. The engineer can ping the NTP server. What is the most likely cause?

Hard
474

A network engineer runs the following command on Router R1: R1# show ip route ospf Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2 i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP a - application route + - replicated route, % - next hop override Gateway of last resort is not set O 10.2.2.0/24 [110/20] via 192.168.12.2, 00:12:34, GigabitEthernet0/0 O IA 10.3.3.0/24 [110/30] via 192.168.13.3, 00:10:21, GigabitEthernet0/1 Based on this output, what can be determined?

Easy
475

Which authentication method is supported by default for GRE tunnels in Cisco IOS-XE?

Medium
476

What is the default authentication type for NHRP in a DMVPN configuration?

Easy
477

Consider the following partial configuration on router R1: ``` interface GigabitEthernet0/1 ip access-group MY_ACL in ! ip access-list extended MY_ACL permit tcp 10.1.1.0 0.0.0.255 any eq 80 permit icmp any any echo deny ip any any ``` What is the effect of this ACL when applied inbound on GigabitEthernet0/1?

Medium
478

A network technician is configuring a Cisco router to act as a DHCP relay agent. The router's interface GigabitEthernet0/0 is connected to a subnet where clients need to obtain IP addresses from a DHCP server located on a different subnet. Which command is required on the router to enable DHCP relay?

Easy
479

Given the following configuration snippet on Router R5: router eigrp 400 network 10.1.1.0 0.0.0.255 What is wrong with this configuration?

Medium
480

What is the default administrative distance for a route installed by Policy-Based Routing (PBR) using the 'set ip next-hop' command?

Medium
481

Which TWO statements about IPv4 extended access control lists are true? (Choose TWO.)

Medium
482

A network engineer runs the following command to verify NAT on a VRF: R1# show ip nat translations vrf CUSTOMER Pro Inside global Inside local Outside local Outside global --- 10.2.2.2 10.1.1.1 192.168.1.1 192.168.1.1 What is the purpose of the 'vrf CUSTOMER' parameter?

Medium
483

Drag and drop the steps to troubleshoot SPAN, RSPAN, and ERSPAN adjacency or connectivity failures into the correct order, from first to last.

Hard
484

Examine the partial BFD configuration on a router: interface GigabitEthernet0/0 bfd interval 100 min_rx 100 multiplier 3 ! interface GigabitEthernet0/1 bfd interval 200 min_rx 200 multiplier 3 ! router ospf 1 bfd all-interfaces ! The router has OSPF neighbors on both interfaces. Which statement is true?

Medium
485

Which TWO commands can be used to verify OSPFv3 interface parameters and troubleshoot adjacency issues? (Choose TWO.)

Hard
486

A network engineer is configuring a GRE tunnel over an IPsec VPN to support multicast traffic between two sites. The engineer notices that multicast traffic is not passing through the tunnel, although unicast traffic works. Which of the following is the most likely reason?

Medium
487

A network engineer runs the following command to troubleshoot a Policy-Based Routing (PBR) issue: R1# debug ip policy Policy routing debugging is on R1# *Mar 1 00:10:45.456: IP: s=172.16.1.5 (FastEthernet0/0), d=8.8.8.8, len 64, policy match *Mar 1 00:10:45.456: IP: s=172.16.1.5 (FastEthernet0/0), d=8.8.8.8, len 64, policy routed *Mar 1 00:10:45.456: IP: FastEthernet0/0 to Serial0/0 10.1.1.2 What does this output indicate?

Medium
488

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# show ip sla configuration 10 IP SLAs, Infrastructure Engine-II. Entry number: 10 Owner: Tag: Type of operation to perform: icmp-echo Target address: 192.168.1.1 Type Of Service parameter: 0x0 Request size (ARR data portion): 28 Operation timeout (milliseconds): 5000 Frequency (seconds): 60 Next Scheduled Start Time: Start Time already occurred Group Scheduled : FALSE Life (seconds): Forever Entry Ageout (seconds): never Recurring (Starting Everyday): FALSE Status of entry (SNMP RowStatus): Active Threshold (milliseconds): 5000 Distribution Statistics: Number of history intervals kept: 0 Number of history buckets kept: 15 History Statistics: Number of history Lives kept: 0 What does this output indicate?

Medium
489

A network engineer is configuring object tracking to influence a static default route on a Cisco IOS router. The engineer wants the default route to be removed from the routing table if the tracked object (a reachability test to 192.0.2.1) goes down. The engineer enters the following configuration: track 1 ip route 192.0.2.1 255.255.255.255 reachability ip route 0.0.0.0 0.0.0.0 203.0.113.1 track 1 After the link to 203.0.113.1 fails, the default route remains in the routing table. What is the most likely reason?

Hard
490

A network technician is configuring a Cisco router to forward traffic to a remote network. The technician enters the command 'ip route 172.16.0.0 255.255.0.0 10.0.0.1'. However, the router does not install the route in its routing table. What is the most likely reason?

Easy
491

When using 'set ip next-hop verify-availability', what mechanism does the router use to determine if the next-hop is reachable?

Medium
492

An engineer is troubleshooting a BGP route selection issue. Router R1 receives two paths for prefix 10.0.0.0/8: one from eBGP peer R2 (AS 65002) with weight 0, local preference 100, and AS path 65002; and another from eBGP peer R3 (AS 65003) with weight 0, local preference 200, and AS path 65003 65004. R1's BGP table shows the path from R3 as the best route. The engineer wants the path from R2 to be preferred. What should the engineer do?

Medium
493

Drag and drop the steps to configure IPv6 RA Guard on a switch into the correct order, from first to last.

Medium
494

A network technician is configuring a GRE tunnel between two routers. The tunnel source is a physical interface, and the tunnel destination is a loopback interface on the remote router. The technician notices that the tunnel interface is up, but line protocol is down. What is the most likely cause?

Easy
495

Which statement accurately describes the default behavior of auto-summary in EIGRP on Cisco IOS-XE?

Medium
496

A network engineer configures SNMP traps on router R3 to monitor BGP events. R3 is an iBGP route reflector with multiple clients. The configuration includes: snmp-server enable traps bgp, snmp-server host 192.168.1.100 version 2c public. However, the NMS receives no BGP traps. R3's show snmp pending shows no pending traps. show snmp statistics shows TrapsSent: 0. The NMS can poll R3 successfully via SNMP. What is the root cause?

Hard
497

A network engineer is configuring a Cisco router to support Network Address Translation (NAT) for a small office. The engineer wants to translate internal private addresses to a single public address using Port Address Translation (PAT). Which command enables PAT by allowing the router to use the interface's IP address for translation?

Medium
498

According to RFC 3164, which facility code is used by default for Cisco IOS syslog messages?

Medium
499

Given this partial configuration: ip nat pool MYPOOL 203.0.113.10 203.0.113.20 netmask 255.255.255.0 ip nat inside source list 1 pool MYPOOL access-list 1 permit 192.168.1.0 0.0.0.255 What is the effect?

Medium
500

What is the default BGP keepalive timer value in Cisco IOS-XE?

Easy
501

Drag and drop the steps to troubleshoot EEM adjacency or connectivity failures into the correct order, from first to last.

Hard
502

In Cisco IOS, what is the default encryption algorithm for IKEv1 phase 1 if not specified in the ISAKMP policy?

Hard
503

A network engineer is configuring EIGRP on a Cisco IOS XE router. The router is connected to two different autonomous systems: AS 100 and AS 200. The engineer wants to redistribute routes from AS 100 into AS 200. Which two statements are true regarding EIGRP redistribution? (Choose two.)

Medium
504

Drag and drop the steps to verify and validate IP SLA operational state into the correct order, from first to last.

Medium
505

Which TWO statements correctly describe the behavior of EIGRP route summarization when using the 'summary-address' command under an interface? (Choose TWO.)

Hard
506

An engineer configures DHCPv4 on a router with multiple pools for different subnets. Clients in subnet A receive addresses correctly, but clients in subnet B receive addresses from subnet A's pool. The router has 'ip dhcp relay' configured. Which is the most likely explanation?

Hard
507

Which TWO commands would a network engineer use to verify SNMP agent configuration and connectivity on a Cisco IOS router? (Choose TWO.)

Medium
508

In an MPLS L3VPN environment, what is the default maximum number of routes that can be installed from a single BGP peer?

Hard
509

OSPF network type mismatch on a multi-access link is causing route summarization issues. Router R1 and R2 are connected via Ethernet, but R1 has: interface GigabitEthernet0/0 ip address 10.0.0.1 255.255.255.0 ip ospf network point-to-point ip ospf 1 area 0 ! Router R2 has default OSPF network type (broadcast). R1 is configured with: router ospf 1 area 0 range 10.0.0.0 255.255.255.0 ! R2 shows: R2# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 10.0.0.1 0 FULL/ - 00:00:30 10.0.0.1 GigabitEthernet0/0 But R2 does not have the summary route in its routing table. What is the root cause?

Hard
510

A network engineer runs the following command on Router R1: R1# show crypto isakmp sa dst src state conn-id slot status 10.1.1.2 10.1.1.1 QM_IDLE 1 0 ACTIVE Based on this output, which statement is correct?

Easy
511

A network engineer is implementing 802.1X authentication on a Cisco Catalyst switch. The engineer wants to ensure that if the RADIUS server is unavailable, the switch will place the port in a restricted VLAN for guest access. Which command must be configured on the switch port?

Hard
512

A network engineer runs the following command to debug IPv6 uRPF: R1# debug ipv6 verify IPv6 verify debugging is on *Mar 1 00:02:34.567: IPv6 verify: source 2001:DB8:4::1 on GigabitEthernet0/0 *Mar 1 00:02:34.567: no route to source What does this output indicate?

Hard
513

A network engineer runs the following command on Router PE2: PE2# show ip bgp vpnv4 vrf CUSTOMER_A 10.10.10.0 24 BGP routing table entry for 10.10.10.0/24, version 15 Paths: (1 available, best #1, table CUSTOMER_A) Advertised to update-groups: 1 Refresh Epoch 1 Local, imported path from 10.10.10.0/24 10.1.1.1 (metric 20) from 10.1.1.1 (10.1.1.1) Origin incomplete, metric 0, localpref 100, valid, internal, best Extended Community: RT:100:100 mpls labels in/out 18/19 Based on this output, what is the problem?

Medium
514

A network engineer runs the following command on Router R1: R1# show ip dhcp pool POOL1 Pool POOL1 : Utilization mark (high/low) : 100 / 0 Subnet size (first/next) : 0 / 0 Total addresses : 10 Leased addresses : 10 Pending event : none 1 subnet is currently in the pool : Current index IP address range Leased addresses 192.168.1.11 192.168.1.10 - 192.168.1.19 10 Based on this output, which statement is correct?

Medium
515

Which TWO commands can be used to verify the operational status of a manually configured IPv6 tunnel on a Cisco IOS router? (Choose TWO.)

Medium
516

An engineer configures iBGP between two routers in the same AS. The BGP table shows the prefix, but it is not installed in the routing table. The next-hop is reachable via an IGP route. Which is the most likely explanation?

Hard
517

Which THREE commands are used to troubleshoot VRF-Lite connectivity issues on a Cisco IOS-XE router? (Choose THREE.)

Hard
518

A network engineer is troubleshooting a router that is sending duplicate SNMP traps for interface state changes. The engineer finds two EEM applets that both trigger on the same syslog pattern 'LINK-3-UPDOWN' and both send SNMP traps. What should the engineer do to resolve the duplicate traps?

Easy
519

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# debug ip sla monitor trace IP SLAs Monitor trace debugging is on *Mar 1 12:34:56.789: IP SLAs Monitor: Starting operation 10 *Mar 1 12:34:56.789: IP SLAs Monitor: Sending ICMP echo request to 192.168.1.1 *Mar 1 12:34:56.790: IP SLAs Monitor: Received ICMP echo reply from 192.168.1.1 *Mar 1 12:34:56.790: IP SLAs Monitor: RTT = 12 ms *Mar 1 12:34:56.790: IP SLAs Monitor: Operation 10 completed successfully *Mar 1 12:35:56.789: IP SLAs Monitor: Starting operation 10 *Mar 1 12:35:56.789: IP SLAs Monitor: Sending ICMP echo request to 192.168.1.1 *Mar 1 12:35:56.790: IP SLAs Monitor: Received ICMP echo reply from 192.168.1.1 *Mar 1 12:35:56.790: IP SLAs Monitor: RTT = 14 ms *Mar 1 12:35:56.790: IP SLAs Monitor: Operation 10 completed successfully What does this output indicate?

Medium
520

A network engineer runs the following command on Router R1: R1# show ip bgp neighbors 10.2.2.2 advertised-routes BGP table version is 10, local router ID is 1.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.1.1.0/24 0.0.0.0 0 32768 i *> 10.2.2.0/24 0.0.0.0 0 32768 i Total number of prefixes 2 Based on this output, what is the problem?

Hard
521

A network engineer is troubleshooting an MPLS L3VPN where customer routes are not being advertised from one PE to another. The engineer verifies that the VRFs are configured correctly, the IGP is converged, and the PE routers have established an MP-BGP session. Which command should the engineer use to verify that the VPNv4 prefixes are being exchanged correctly?

Medium
522

Router R1 and R2 are running OSPF in area 0. R1 has a loopback interface with IP 192.168.1.1/32 advertised into OSPF. R2 learns this route as an intra-area route (AD 110). R2 also runs RIP and learns the same prefix from R3 with AD 120. R2's 'show ip route 192.168.1.1' shows the RIP route. What is the root cause?

Hard
523

An engineer configures an IPv4 ACL on a router's interface to permit only HTTP traffic (TCP port 80) from a specific subnet. The ACL is applied inbound. After applying, the router's web interface (HTTPS) becomes unreachable from the same subnet. What is the most likely explanation?

Hard
524

Consider the following configuration on a PE router: ip vrf CUSTOMER-B rd 100:1 route-target export 100:1 route-target import 100:2 ! interface GigabitEthernet0/2 ip vrf forwarding CUSTOMER-B ip address 192.168.2.1 255.255.255.252 What is the effect of this configuration?

Medium
525

Which EIGRP packet type is used to confirm receipt of an update during reliable transport?

Medium
526

A network engineer is configuring a route map for BGP policy. The engineer wants to match routes that originate from AS 65001 and have a community value of 100:200. The route map should then set the local preference to 200. Which configuration snippet accomplishes this?

Medium
527

A network administrator is troubleshooting an OSPFv3 network. Routers R1 and R2 are in the same area and on the same broadcast segment, but they are not forming an adjacency. The administrator verifies that the interfaces are up and IPv6 addresses are configured correctly. Which command should be used to check if OSPFv3 is enabled on the interfaces?

Hard
528

Which LDP message type is used to request label bindings from a neighbor?

Easy
529

Which TWO statements correctly describe the behavior of TTL propagation in MPLS networks? (Choose TWO.)

Hard
530

A network engineer is troubleshooting an issue where IPv6 hosts are receiving multiple Router Advertisements from different routers, causing routing instability. The switch is configured with IPv6 First Hop Security features. The engineer wants to ensure that only the primary router's RAs are accepted by hosts. What is the most effective solution?

Medium
531

A network administrator is troubleshooting an EIGRP network where a router is not receiving all expected routes from a neighbor. The neighbor relationship is established, and the topology table shows only a subset of routes. Which EIGRP feature could be filtering the routes?

Hard
532

Which TWO commands would a network engineer use to verify that syslog messages are being sent to a remote syslog server? (Choose TWO.)

Medium
533

A network administrator is configuring AAA on a Cisco IOS router to authenticate administrative SSH users against a TACACS+ server. The administrator wants to ensure that if the TACACS+ server is unreachable, a locally configured user account can still be used for authentication. Which configuration should the administrator apply?

Easy
534

A network engineer is configuring Policy-Based Routing (PBR) on a Cisco IOS-XE router. The engineer wants to route traffic from the 10.1.1.0/24 subnet that is destined for any TCP port 80 to next-hop 192.168.2.1, but only for packets arriving on GigabitEthernet0/1. Other traffic should follow the normal routing table. Which configuration sequence correctly accomplishes this?

Medium
535

Which MPLS label value is reserved for the Explicit NULL label and what is its purpose?

Hard
536

Consider this configuration on Router R5: ``` interface Tunnel0 ipv6 address 2001:DB8:7::1/64 tunnel source 192.168.10.1 tunnel destination 192.168.20.2 tunnel mode ipv6ip tunnel ttl 64 ``` What is the effect?

Medium
537

A network engineer runs the following command on Router R1: R1# show ip policy Interface Route-map GigabitEthernet0/0 PBR-TRACK R1# show route-map PBR-TRACK route-map PBR-TRACK, permit, sequence 10 Match clauses: ip address (access-lists): 170 Set clauses: ip next-hop verify-availability 10.0.0.2 10 track 2 Policy routing matches: 100 packets, 8000 bytes R1# show track 2 Track 2 IP SLA 2 reachability Reachability is Up 2 changes, last change 00:01:30 Latest operation return code: ok Tracked by: ROUTE-MAP 0 R1# show ip route 10.0.0.2 Routing entry for 10.0.0.2/32 Known via "eigrp 1", distance 90, metric 28160 Last update from 192.168.1.2 on GigabitEthernet0/1 Based on this output, what is the most likely behavior for packets matching ACL 170?

Medium
538

A network engineer runs the following command on Router R1: R1# show ip bgp vpnv4 vrf RED summary BGP router identifier 192.168.0.1, local AS number 65001 BGP table version is 5, main routing table version 5 4 network entries using 576 bytes of memory 4 path entries using 320 bytes of memory 2/1 BGP path/bestpath attribute entries using 320 bytes of memory 0 BGP route-map cache entries using 0 bytes of memory 0 BGP filter-list cache entries using 0 bytes of memory BGP using 1216 total bytes of memory BGP activity 4/0 prefixes, 4/0 paths, scan interval 60 secs Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 10.1.1.2 4 65001 23 25 5 0 0 00:12:34 2 10.1.2.2 4 65002 18 20 5 0 0 00:10:15 1 Based on this output, which statement is correct?

Medium
539

A network engineer configures CoPP on a router that is a DMVPN hub. The policy includes a class-map to match NHRP traffic and police it. After deployment, spoke-to-spoke tunnels fail to establish, although spoke-to-hub tunnels work. Which is the most likely explanation?

Hard
540

Which DHCPv4 message type does a client send to request a specific IP address previously offered?

Easy
541

A network engineer is configuring an IPv6 First Hop Security feature on a Cisco Catalyst switch to prevent rogue devices from sending Router Advertisement messages with a prefix that conflicts with the legitimate prefix. The engineer wants to ensure that only authorized routers can advertise prefixes, while still allowing hosts to perform SLAAC. Which feature should be implemented?

Medium
542

A network engineer is troubleshooting a BGP routing issue on a Cisco IOS XE router. The router is configured with a route map that sets the local preference for routes learned from a specific neighbor. However, the engineer notices that the local preference is not being applied to routes received from that neighbor. Which BGP configuration command is most likely missing?

Hard
543

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to ensure that uRPF is applied in a way that allows asymmetric routing. Which uRPF mode should be configured?

Hard
544

A network engineer runs the following command to troubleshoot IPsec with route-maps: R1# show crypto ipsec transform-set Transform set combined: { esp-aes 256 esp-sha-hmac } will negotiate = { Transport, } Transform set ESP-AES: { esp-aes 256 esp-sha-hmac } will negotiate = { Tunnel, } What does this output indicate?

Easy
545

A network engineer runs the following command on Router R1: R1# show ipv6 access-list PERMIT-ONLY IPv6 access list PERMIT-ONLY permit ipv6 2001:DB8:3::/48 any sequence 10 Based on this output, what is the effect of this access list when applied to an interface?

Medium
546

An engineer configures an IPsec site-to-site VPN. The tunnel comes up, but no traffic passes. The engineer checks the crypto map and access-lists. Which is the most likely explanation?

Hard
547

A network administrator is deploying DMVPN Phase 3 with IKEv2 between a hub and two spokes. The hub is configured with a dynamic multipoint VPN tunnel and uses NHRP. Spoke1 can reach Spoke2 via the hub, but direct spoke-to-spoke communication fails. The administrator verifies that NHRP registrations are successful and that the hub has routes to both spokes. Which action is most likely to enable direct spoke-to-spoke communication?

Hard
548

A network engineer runs the following command on Router R1: R1# show ip policy Interface Route-map GigabitEthernet0/0 PBR-DEFAULT R1# show route-map PBR-DEFAULT route-map PBR-DEFAULT, permit, sequence 10 Match clauses: ip address (access-lists): 150 Set clauses: ip next-hop 10.0.0.2 Policy routing matches: 0 packets, 0 bytes route-map PBR-DEFAULT, deny, sequence 20 Match clauses: Set clauses: Policy routing matches: 0 packets, 0 bytes R1# show access-lists 150 Extended IP access list 150 10 permit ip 192.168.1.0 0.0.0.255 any R1# show ip route 10.0.0.2 Routing entry for 10.0.0.2/32 Known via "ospf 1", distance 110, metric 20 Last update from 10.1.1.2 on GigabitEthernet0/1 Based on this output, what is the most likely problem?

Medium
549

In IPsec site-to-site VPN, what is the default lifetime for ISAKMP (IKE phase 1) security associations on Cisco IOS routers?

Easy
550

What is the default value for the 'active flow timeout' in a Flexible NetFlow monitor on Cisco IOS-XE?

Medium
551

A network engineer is troubleshooting a manual IPv6-in-IPv4 tunnel between two Cisco routers. The tunnel is up, and both routers can ping each other's tunnel IPv6 addresses. However, traffic from a host behind Router A to a host behind Router B fails. The engineer notices that Router A has a route to the remote IPv6 prefix via the tunnel, but Router B does not have a route to the local IPv6 prefix. What is the most likely cause?

Medium
552

A network engineer runs the following command on Router R1: R1# show flow monitor FLOW-MONITOR-1 cache format table Cache type: Normal Cache size: 1000 Current entries: 0 High Watermark: 0 Flows added: 0 Flows aged: 0 - Active timeout (1800 secs) 0 - Inactive timeout (15 secs) 0 - Event aged 0 - Watermark aged 0 - Emergency aged 0 Based on this output, what is the most likely problem?

Medium
553

Consider this partial configuration: ip nat inside source list 1 interface GigabitEthernet0/1 overload access-list 1 permit 192.168.1.0 0.0.0.255 ! interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip nat inside ! interface GigabitEthernet0/1 ip address 203.0.113.1 255.255.255.0 ip nat outside ! interface GigabitEthernet0/2 ip address 172.16.0.1 255.255.255.0 ip nat inside What is true about traffic from the 172.16.0.0/24 network?

Medium
554

A network uses PBR to route traffic from a specific subnet (172.16.1.0/24) through a WAN link (next-hop 10.10.10.2). After a routing change, traffic from this subnet is being sent to the WAN link but is not reaching the destination. Router R1 shows: 'show route-map' shows the route-map is applied, 'debug ip policy' shows traffic being forwarded to 10.10.10.2, but 'show ip route' on R1 shows a route to the destination via a different next-hop (10.20.20.2). What is the root cause?

Hard
555

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers. The customer requires that traffic for the 10.1.1.0/24 subnet be encrypted, but all other traffic must be sent unencrypted. The engineer applies a crypto map to the outside interface. Which additional configuration is required to meet this requirement?

Medium
556

A network engineer is configuring an MPLS L3VPN. The PE router is running OSPF with the CE router in VRF CUSTOMER. The engineer notices that routes from the customer are being redistributed into the provider's global OSPF process, causing instability. Which configuration change on the PE router will prevent this redistribution while still allowing customer routes to be advertised across the MPLS core?

Medium
557

An engineer configures mutual redistribution between OSPF and EIGRP on a router that is part of an IPsec site-to-site VPN. After the configuration, routing loops occur intermittently. The engineer has not used any route tagging. What is the most likely cause of the routing loops?

Hard
558

A network engineer is troubleshooting an IPsec VPN between two Cisco IOS routers. The tunnel is up, but traffic is not passing. The engineer runs `show crypto ipsec sa` and notices that the encaps/decaps counters are incrementing, but the inbound and outbound packets are being dropped. The ACL used for the VPN is `permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255`. What is the most likely cause of the dropped packets?

Medium
559

What is the default IKE (ISAKMP) lifetime value in Cisco IOS for IPsec Site-to-Site VPN?

Easy
560

Which of the following protocols has the lowest default administrative distance on a Cisco router?

Medium
561

Given the following partial configuration on router R1: crypto isakmp policy 10 encryption aes 256 authentication pre-share group 14 lifetime 86400 ! crypto isakmp key cisco123 address 192.168.1.2 ! crypto ipsec transform-set TSET esp-aes 256 esp-sha-hmac mode tunnel ! crypto map CMAP 10 ipsec-isakmp set peer 192.168.1.2 set transform-set TSET match address 101 ! interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 crypto map CMAP ! access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255 What is the effect of this configuration?

Medium
562

A network engineer is troubleshooting a BGP route advertisement issue. Router R1 (AS 65001) has an eBGP session with R2 (AS 65002). R1 is advertising the prefix 192.168.1.0/24 to R2. On R2, the route appears in the BGP table but is not installed in the routing table. The output of 'show ip bgp 192.168.1.0/24' on R2 shows the route as valid, best, but with the 'r' flag (RIB-failure). The routing table on R2 shows a static route for 192.168.1.0/24 with administrative distance 1. What is the most likely cause?

Easy
563

A network engineer is deploying DMVPN Phase 3 with IPsec protection. The hub router is configured with a multipoint GRE tunnel interface and NHRP. Which two statements are true regarding the configuration that must be applied to the spoke routers to enable direct spoke-to-spoke communication? (Choose two.)

Medium
564

A network engineer is troubleshooting a Cisco IOS XE router that is configured with a route map for policy-based routing (PBR). The route map is applied to the ingress interface with `ip policy route-map PBR`. The engineer wants to verify that the PBR is matching traffic and setting the next-hop correctly. Which command provides the most detailed information about PBR matches and actions?

Hard
565

Drag and drop the steps to troubleshoot Administrative Distance adjacency or connectivity failures into the correct order, from first to last.

Medium
566

A network administrator is configuring a Cisco IOS router to authenticate login users against an external TACACS+ server. The administrator wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used as a fallback. The TACACS+ server has been configured with the IP address 10.1.1.100 and the shared secret key 'cisco123'. Which set of commands correctly implements this requirement?

Medium
567

Drag and drop the steps to configure and schedule an IP SLA ICMP-echo operation into the correct order, from first to last.

Medium
568

A network engineer runs the following command on Router R1: R1# show ip sla statistics 5 Round Trip Time (RTT) for Index 5 Latest RTT: 50 ms Latest RTT (milliseconds): 50 Latest RTT (microseconds): 50000 Number of successes: 100 Number of failures: 0 Operation time to live: Forever Output: OK R1# show track 3 Track 3 IP SLA 5 reachability Reachability is Up 1 change, last change 00:10:00 Latest operation return code: OK Latest RTT (milliseconds): 50 Tracked by: ip route 0.0.0.0 0.0.0.0 192.168.3.1 track 3 R1# show ip route 0.0.0.0 0.0.0.0 Routing entry for 0.0.0.0/0, supernet Known via "static", distance 1, metric 0, candidate default path Last update from 192.168.3.1 on GigabitEthernet0/0 Routing Descriptor Blocks: * 192.168.3.1, via GigabitEthernet0/0 Route metric is 0, traffic share count is 1 Based on this output, which statement is correct?

Medium
569

A network engineer is configuring OSPF on a router with three interfaces: GigabitEthernet0/0 (10.1.1.1/24), GigabitEthernet0/1 (10.2.2.1/24), and Loopback0 (192.168.1.1/24). The engineer wants to ensure that the router ID is 192.168.1.1 and that it remains stable even if the Loopback0 interface flaps. Which command should be applied?

Medium
570

Which TWO commands would a network engineer use to verify the results of route redistribution from OSPF into EIGRP? (Choose TWO.)

Easy
571

What is the default frequency (in seconds) for an IP SLA operation if not explicitly configured?

Easy
572

A network engineer runs the following command to troubleshoot an EEM issue: R1# debug event manager action syslog EEM Action Syslog debugging is on R1# Mar 1 00:20:45.789: %HA_EM-6-ACTION: applet TRACK-INTERFACE: action syslog msg: 'OSPF adjacency change detected' What does this output indicate?

Medium
573

Which of the following is true regarding the use of prefix-lists versus access-lists for route filtering?

Medium
574

A network engineer is configuring a Cisco IOS XE router to authenticate VPN users against a Microsoft Active Directory server. The router must use RADIUS and send the user's original username without modification. Which command set correctly configures the router to use the AD server at 10.1.1.50 with the shared secret 'Cisco123'?

Medium
575

Which DHCPv6 message is used by a server to respond to a SOLICIT with available configuration parameters?

Easy
576

A network engineer is deploying OSPFv3 in an IPv6 network. The engineer wants to enable OSPFv3 on a router and ensure that it can form adjacencies with neighbors. Which two commands are required on the router to enable OSPFv3 globally and on an interface? (Choose two.)

Hard
577

A network engineer is troubleshooting an MPLS L3VPN where CE1 (10.1.1.0/24) cannot reach CE2 (10.2.2.0/24). The PE routers are using eBGP with the CEs. On PE1, the show ip bgp vpnv4 vrf CUSTOMER command shows the route for 10.2.2.0/24 with a next-hop of 192.168.1.2, and the show ip route vrf CUSTOMER command shows the route. However, traffic from CE1 to CE2 fails. The show ip bgp vpnv4 vrf CUSTOMER 10.2.2.0/24 command on PE1 shows the route is received and best, but the show ip bgp vpnv4 vrf CUSTOMER 10.2.2.0/24 command on PE1 also shows the route has the 'r' flag (RIB-failure). What is the most likely cause?

Hard
578

A network engineer is configuring a Cisco IOS XE router for MPLS L3VPN. The router is a PE device with a VRF named CUSTOMER. The engineer wants to redistribute routes from the VRF into MP-BGP so they can be advertised to a remote PE. The engineer has configured the VRF and assigned interfaces. Which command sequence correctly redistributes the connected routes from the VRF into BGP?

Medium
579

A router experiences high CPU utilization due to SSH login attempts from an external attacker. The network engineer implements a CoPP policy to rate-limit SSH traffic to 10000 bps. After applying the policy, the engineer notices that legitimate SSH sessions from the management network are also being dropped intermittently. The CoPP policy uses a class-map that matches TCP port 22 traffic. What should the engineer do to fix this issue?

Medium
580

R1 and R2 have an IPsec VPN tunnel between their physical interfaces. They are running BGP over the tunnel interface. R1's show ip bgp summary shows the BGP session with R2 as established, but R1's show ip bgp shows no routes from R2. R2's show ip bgp shows routes from R1. What is the root cause?

Hard
581

A network engineer runs the following command on Router R6: R6# show logging | include %SEC-6-IPACCESSLOGP *Mar 1 00:01:15.123: %SEC-6-IPACCESSLOGP: list ACL_INBOUND denied tcp 10.0.0.100(12345) -> 192.168.1.1(80), 1 packet *Mar 1 00:01:20.456: %SEC-6-IPACCESSLOGP: list ACL_INBOUND denied tcp 10.0.0.100(12346) -> 192.168.1.1(80), 1 packet *Mar 1 00:01:25.789: %SEC-6-IPACCESSLOGP: list ACL_INBOUND denied tcp 10.0.0.100(12347) -> 192.168.1.1(80), 1 packet *Mar 1 00:01:30.012: %SEC-6-IPACCESSLOGP: list ACL_INBOUND denied tcp 10.0.0.100(12348) -> 192.168.1.1(80), 1 packet Based on this output, what is the most likely problem?

Medium
582

A network engineer runs the following command on Router R1: R1# show ip route summary IP routing table maximum-paths: 32 IP routing table has 15 routes, using 900 bytes of memory Number of prefixes: /8: 1, /16: 2, /20: 3, /24: 9 Route types: Connected: 4, Static: 1, OSPF: 10 Route sources: OSPF: 10, Connected: 4, Static: 1 Based on this output, what is a potential issue regarding route summarization?

Hard
583

Drag and drop the steps to verify and validate VRF-Lite operational state into the correct order, from first to last.

Medium
584

Which statement correctly describes the default behavior of the Embedded Event Manager (EEM) when an event occurs and no action is explicitly defined?

Easy
585

A network engineer runs the following command to troubleshoot a Network Logging and Syslog issue: R1# show policy-map control-plane input class class-default Output: Class-map: class-default (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any police: cir 1000000 bps, bc 31250 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop What does this output indicate?

Medium
586

A router is configured with PBR using a route-map that sets the next-hop to 10.0.0.2 for traffic matching ACL 100. The engineer also configures 'set ip default next-hop 10.0.0.3' in the same route-map sequence. Traffic that matches ACL 100 is forwarded to 10.0.0.2, but traffic that does not match ACL 100 is forwarded to 10.0.0.3 only if there is no route in the routing table. However, the engineer expects all unmatched traffic to go to 10.0.0.3 regardless of the routing table. What is the misunderstanding?

Hard
587

Which TWO statements about MPLS label imposition, disposition, and swapping are true? (Choose TWO.)

Hard
588

Which IP SLA operation type is used to measure one-way delay, jitter, and packet loss?

Medium
589

A network engineer is troubleshooting PBR on a Cisco router where traffic from VLAN 100 (192.168.10.0/24) should be forwarded to next-hop 10.10.10.2 via a route map named 'VLAN100-PBR'. The engineer has applied the route map to interface GigabitEthernet0/0.100 (subinterface) using 'ip policy route-map VLAN100-PBR'. The engineer verifies that the route map is correctly configured with 'match ip address 100' and 'set ip next-hop 10.10.10.2', and the access list 100 matches the source subnet. However, traffic from VLAN 100 is still forwarded using the routing table. What is the most likely cause?

Medium
590

Which THREE commands can be used to verify the operational state and configuration of an IPv6 tunnel? (Choose THREE.)

Hard
591

An engineer configures IPsec between two routers using a site-to-site VPN with IKEv1. The configuration uses `crypto isakmp policy 10` with authentication pre-share and encryption aes. On the peer, the policy is configured with authentication pre-share and encryption 3des. Unexpectedly, the IKE phase 1 negotiation fails. Which is the most likely explanation?

Hard
592

Drag and drop the steps to apply a route-map to filter BGP prefix advertisements into the correct order, from first to last.

Medium
593

A network administrator is deploying a DMVPN Phase 2 network with EIGRP as the routing protocol. The hub router is configured with a multipoint GRE interface and NHRP. Spokes are configured with tunnel interfaces and are registering with the hub. However, the administrator notices that spoke routers are not forming EIGRP neighbor adjacencies with the hub. Which command is most likely missing on the hub's mGRE interface?

Easy
594

An engineer is troubleshooting a router that is generating syslog messages with incorrect timestamps. The router has 'service timestamps log datetime msec' configured, but the timestamps show the wrong time zone. The router's clock is set correctly via NTP. What is the most likely cause?

Medium
595

Which TWO commands verify the application and content of an IPv4 access control list on a Cisco IOS router? (Choose TWO.)

Medium
596

Drag and drop the steps to troubleshoot DHCP (IPv4 and IPv6) adjacency or connectivity failures into the correct order, from first to last.

Hard
597

An engineer is troubleshooting a BGP peering issue between two routers, R1 and R2, connected via a serial link. The BGP session is established, but routes are not being exchanged. The engineer checks the BGP configuration and sees that both routers have the 'neighbor' commands correctly configured. The output of 'show ip bgp summary' shows the session is in the Established state, but the prefix counts are zero. What is the most likely cause?

Medium
598

A network engineer is configuring route redistribution between EIGRP and OSPF on a Cisco IOS-XE router. The engineer wants to prevent routing loops and ensure that only specific EIGRP routes are redistributed into OSPF. Which combination of tools should the engineer use?

Hard
599

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS router. The engineer wants traffic from a specific subnet to be routed via a next-hop IP address that is not directly connected. Which command is required under the route-map configuration?

Hard
600

A network engineer is configuring a GRE tunnel between two routers. The tunnel interface is up, but OSPF neighbors are not forming. The engineer suspects a Layer 3 issue. Which command should be used to verify that the tunnel endpoints are reachable?

Medium
601

What is the default OSPF dead interval on a broadcast multi-access network (e.g., Ethernet) when the hello interval is 10 seconds?

Easy
602

A network engineer is deploying a new branch office router (Cisco IOS XE) and wants to protect the control plane from routing protocol floods. The router will run OSPF and EIGRP. The engineer must ensure that control plane packets are rate-limited and that the router logs when the rate is exceeded. Which of the following should be configured?

Medium
603

A network engineer is troubleshooting a site-to-site IPsec VPN that fails to establish. The engineer suspects that the pre-shared key is incorrect. Which command can be used to verify the pre-shared key configuration on a Cisco IOS router?

Easy
604

A network administrator needs to configure a Cisco IOS router to send SNMP traps to a management server at 192.168.1.200 using SNMPv2c with the community string 'public'. Which command is required?

Easy
605

Drag and drop the steps to verify and validate route summarization operational state into the correct order, from first to last.

Medium
606

A network engineer runs the following command on Router R1: R1# show ipv6 dhcp binding Client: FE80::A8BB:CCFF:FE01:0200 DUID: 00030001AABBCC010200 Username: unassigned IA NA: IA ID 0x00010001, T1 302400, T2 483840 Address: 2001:DB8:1::1000 Preferred lifetime 604800, valid lifetime 2592000 Expires at Mar 08 2020 12:00 AM (2592000 seconds) Client: FE80::A8BB:CCFF:FE01:0300 DUID: 00030001AABBCC010300 Username: unassigned IA NA: IA ID 0x00010001, T1 302400, T2 483840 Address: 2001:DB8:1::1001 Preferred lifetime 604800, valid lifetime 2592000 Expires at Mar 08 2020 12:00 AM (2592000 seconds) Based on this output, which statement is correct?

Medium
607

A network engineer runs the following command on Router R1: R1# show ipv6 access-list DENY-REMOTE IPv6 access list DENY-REMOTE deny ipv6 2001:DB8:2::/48 any sequence 10 permit ipv6 any any sequence 20 Based on this output, what is the effect of this access list when applied to an interface?

Easy
608

Which TWO statements about the operation of DMVPN Phase 2 are true? (Choose TWO.)

Hard
609

A network engineer runs the following command to verify Flexible NetFlow cache entries: R1# show flow monitor FLOW-MONITOR-1 cache format record Cache entry for flow 1: ipv4 source address: 10.0.0.1 ipv4 destination address: 192.168.1.100 ip protocol: 6 counter bytes: 1500 counter packets: 10 timestamp sys-uptime first: 123456 timestamp sys-uptime last: 123556 Cache entry for flow 2: ipv4 source address: 10.0.0.2 ipv4 destination address: 192.168.1.101 ip protocol: 17 counter bytes: 500 counter packets: 5 timestamp sys-uptime first: 123457 timestamp sys-uptime last: 123557 What does this output indicate?

Easy
610

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 10.2.2.0/24 BGP routing table entry for 10.2.2.0/24, version 5 Paths: (1 available, best #1, table default) Not advertised to any peer Refresh Epoch 1 65002 10.1.12.2 from 10.1.12.2 (10.2.2.2) Origin IGP, metric 0, localpref 100, valid, external, best rx pathid: 0, tx pathid: 0x0 Based on this output, what is a potential issue with this route?

Medium
611

A network engineer runs the following command to troubleshoot an EEM issue: R1# show event manager history applet TRACK-INTERFACE Applet TRACK-INTERFACE: Time Created : Mar 1 00:00:12 2025 Time Last Triggered : Mar 1 00:15:30 2025 Time Last Executed : Mar 1 00:15:30 2025 Trigger Count : 5 Execution Count : 5 Last Event Type : syslog Last Event Detail : OSPF-5-ADJCHG Last Action Executed : show ip route Last Action Result : Success What does this output indicate?

Medium
612

What is the default behavior of a route-map when a route does not match any match clause in any sequence?

Easy
613

A network engineer is troubleshooting an issue where IPv6 hosts are unable to perform Duplicate Address Detection (DAD) successfully. The switch is configured with IPv6 First Hop Security features including ND Inspection and ND Suppress. The engineer notices that Neighbor Solicitation messages for DAD are being dropped by the switch. What is the most likely cause?

Hard
614

Consider this configuration on router R2: ``` interface GigabitEthernet0/0 ip access-group RESTRICT_ACCESS in ! ip access-list extended RESTRICT_ACCESS permit ip 10.0.0.0 0.255.255.255 any deny ip any any ``` What traffic will be permitted inbound on GigabitEthernet0/0?

Medium
615

When redistributing OSPF into EIGRP, which EIGRP metric components are used to calculate the default metric?

Hard
616

Consider the ERSPAN configuration on a router: monitor session 1 type erspan-source source interface GigabitEthernet0/0/1 both destination erspan-id 1 ip address 192.168.1.100 origin ip address 192.168.1.1 What is the primary purpose of the 'origin ip address' command?

Medium
617

Which TWO statements about EEM applet debugging and verification are correct? (Choose TWO.)

Hard
618

A network engineer is troubleshooting a VRF-Lite setup where two routers are connected via a serial link. Each router has VRF_SALES configured. The engineer configures EIGRP in VRF_SALES. The 'show ip eigrp vrf VRF_SALES neighbors' shows no neighbors. The 'show ip eigrp vrf VRF_SALES interfaces' shows the serial interface is passive. What is the most likely cause?

Hard
619

What is the default inter-packet interval (in milliseconds) for an IP SLA UDP Jitter operation?

Hard
620

What is the default OSPF reference bandwidth used in the metric calculation on Cisco IOS-XE?

Hard
621

A network administrator is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 connects to the internet, and GigabitEthernet0/1 connects to the internal network. The administrator wants to ensure that packets arriving on GigabitEthernet0/0 are dropped if their source address is not reachable via that interface. However, the administrator also wants to allow asymmetric routing where return traffic may use a different path. Which uRPF mode should be configured on GigabitEthernet0/0?

Medium
622

A network engineer runs the following command on Router R1: R1# show ip eigrp interfaces detail GigabitEthernet0/0 IP-EIGRP interfaces for process 100 Interface Peers Xmit Queue Mean Pacing Time Multicast Pending Un/Reliable SRTT Un/Reliable Flow Timer Routes Gi0/0 1 0/0 10 0/10 50 0 Hello interval: 5 sec, Hold time: 15 sec Split horizon is enabled Summary address: 10.0.0.0/8 Next xmit serial <none> Un/reliable mcasts: 0/0 Un/reliable ucasts: 0/0 Mcast exceptions: 0 CR packets: 0 ACKs suppressed: 0 Retransmissions: 0 Retry timer: 15 Hello packets sent: 100, received: 99 Based on this output, what is the purpose of the summary address configured on this interface?

Medium
623

An engineer configures OSPFv2 with a virtual link to connect a non-backbone area to area 0. The virtual link is not coming up, and routes from the non-backbone area are not being advertised into area 0. Which is the most likely explanation?

Hard
624

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on the ingress interface of a PE router in an MPLS L3VPN. The router is receiving VPN traffic from a customer edge (CE) router. The engineer notices that some legitimate traffic is being dropped by uRPF. The engineer verifies that the CE router has a route back to the source address in its routing table. What is the most likely explanation?

Hard
625

Which syslog severity level is used for informational messages that are not errors but may be useful for monitoring?

Easy
626

An MPLS network uses OSPF as the IGP. After redistributing BGP routes into OSPF, some MPLS forwarding failures occur for the redistributed prefixes. Router R1 config: router ospf 1 redistribute bgp 65001 subnets ! router bgp 65001 redistribute ospf 1 R1# show mpls ldp neighbor Peer LDP Ident: 10.1.1.2:0, Local LDP Ident: 10.1.1.1:0 TCP connection: 10.1.1.2.646 - 10.1.1.1.646 State: Oper, Msg sent: 100, Msg rcvd: 80 Downstream on demand R2# show mpls ldp neighbor Peer LDP Ident: 10.1.1.1:0, Local LDP Ident: 10.1.1.2:0 TCP connection: 10.1.1.1.646 - 10.1.1.2.646 State: Oper, Msg sent: 80, Msg rcvd: 100 What is the root cause?

Hard
627

A network engineer runs the following command on Router R1: R1# show ip route ospf Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2 i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP a - application route + - replicated route, % - next hop override Gateway of last resort is not set 10.0.0.0/8 is variably subnetted, 5 subnets, 2 masks O 10.1.1.0/24 [110/20] via 192.168.1.2, 00:15:30, GigabitEthernet0/0 O 10.2.2.0/24 [110/30] via 192.168.1.2, 00:15:30, GigabitEthernet0/0 Based on this output, which statement is correct?

Easy
628

A network engineer runs the following command on Router R1: R1# show ip interface GigabitEthernet0/1 GigabitEthernet0/1 is up, line protocol is up Internet address is 10.1.1.1/24 Broadcast address is 255.255.255.255 Address determined by non-volatile memory MTU is 1500 bytes Helper address is not set Directed broadcast forwarding is disabled Outgoing access list is 101 Inbound access list is not set Based on this output, which statement is correct?

Easy
629

A network engineer runs the following command to troubleshoot an EEM issue: R1# show event manager policy registered No. Class Type Version Time Created Name 1 applet system 1.0 Mar 1 00:00:12 2025 TRACK-INTERFACE 2 applet system 1.0 Mar 1 00:00:15 2025 BGP-RESET 3 applet user 1.0 Mar 1 00:02:30 2025 LOG-ERROR What does this output indicate?

Medium
630

A network engineer runs the following command on Router PE4: PE4# show bgp vpnv4 unicast all summary BGP router identifier 10.0.0.4, local AS number 65001 BGP table version is 25, main routing table version 25 5 network prefixes using 640 bytes of memory 5 path entries using 400 bytes of memory 3/3 BGP path/bestpath attribute entries using 360 bytes of memory 1 BGP AS-PATH entries using 24 bytes of memory 0 BGP route-map cache entries using 0 bytes of memory 0 BGP filter-list cache entries using 0 bytes of memory BGP using 1424 total bytes of memory BGP activity 15/10 prefixes, 20/15 paths, scan interval 60 secs Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 10.0.0.5 4 65001 1020 1015 25 0 0 00:12:34 5 10.0.0.6 4 65002 500 495 25 0 0 00:06:20 0 Based on this output, what is the problem?

Hard
631

A network engineer runs the following command to troubleshoot SNMP statistics: R1# show snmp statistics 0 SNMP packets input 0 Bad SNMP version errors 0 Unknown community name 0 Illegal operation for community name supplied 0 Encoding errors 0 Number of requested variables 0 Number of altered variables 0 Get-request PDUs 0 Get-next PDUs 0 Set-request PDUs 0 Input queue drops 0 SNMP packets output 0 Too big errors 0 No such name errors 0 Bad values errors 0 General errors 0 Get-response PDUs 0 SNMP trap PDUs What does this output indicate?

Hard
632

An engineer is troubleshooting a network where IPv6 hosts on VLAN 20 are unable to communicate with each other. The switch is configured with IPv6 First Hop Security features including Private VLAN (PVLAN) and IPv6 Source Guard. The hosts are in the same VLAN but cannot ping each other. What is the most likely cause?

Medium
633

What is the default hello interval for the Label Distribution Protocol (LDP) on a Cisco IOS-XE router?

Medium
634

A network engineer is implementing CoPP (Control Plane Policing) on a Cisco IOS router to protect the route processor from excessive traffic. The engineer wants to limit ICMP echo requests destined to the router itself to 100 kbps. Which action must be taken to ensure that CoPP applies only to traffic destined to the control plane?

Medium
635

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against a flood of OSPF hello packets. The engineer wants to ensure that OSPF hellos are rate-limited to 1000 packets per second (pps) with a burst of 2000 packets, while allowing all other traffic without policing. The engineer applies the following configuration: class-map match-any OSPF_HELLO match access-group name OSPF_HELLO_ACL ! policy-map COPP_POLICY class OSPF_HELLO police 1000 2000 conform-action transmit exceed-action drop class class-default police 1000000 2000000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY After applying the policy, the engineer notices that OSPF adjacencies are flapping. Which action should the engineer take to resolve the issue?

Hard
636

A network security engineer is configuring a Cisco IOS router to support Zone-Based Policy Firewall (ZPF). The engineer has created zones INSIDE and OUTSIDE, assigned interfaces to them, and now needs to allow HTTP traffic from INSIDE to OUTSIDE while inspecting return traffic. Which configuration step is required to achieve this?

Medium
637

A network engineer is configuring a GRE tunnel between two Cisco routers across an ISP network. The tunnel source is GigabitEthernet0/0 (IP 203.0.113.1) and the tunnel destination is 203.0.113.2. The engineer notices that the tunnel interface is up, but no traffic is passing through it. The engineer suspects a routing issue. Which command should be used to verify that the tunnel endpoint is reachable?

Hard
638

Which THREE statements about NAT and PAT behavior in Cisco IOS are true? (Choose THREE.)

Hard
639

Which statement is true about the implicit deny any at the end of an IPv4 ACL?

Easy
640

What is the default hello interval for OSPFv3 on a broadcast network type in Cisco IOS-XE?

Easy
641

An engineer enables uRPF (strict mode) on an interface facing the Internet. Legitimate traffic from a customer network is being dropped. The customer network uses asymmetric routing where return traffic takes a different path. Which is the most likely explanation?

Hard
642

A network engineer runs the following command to troubleshoot BFD with BGP: R1# show bgp ipv4 unicast 10.3.3.0/24 BGP routing table entry for 10.3.3.0/24, version 2 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 Local 10.1.1.2 from 10.1.1.2 (2.2.2.2) Origin IGP, metric 0, localpref 100, valid, external, best rx pathid: 0, tx pathid: 0x0 BFD enabled, BFD state: UP What does this output indicate?

Medium
643

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. Spoke routers are behind dynamic NAT and cannot be reached directly. The engineer wants spoke-to-spoke traffic to bypass the hub after initial resolution. Which NHRP command on the spoke routers enables this behavior?

Medium
644

Drag and drop the steps to configure SSH access with local AAA on a Cisco router into the correct order, from first to last.

Medium
645

snmp-server community public RO\nsnmp-server community private RW\nsnmp-server community secret RW What is wrong with this configuration?

Medium
646

Which TWO statements about route summarization in BGP are true? (Choose TWO.)

Medium
647

Router R1 is leaking a summary route 10.0.0.0/8 from VRF-A into the global routing table, but hosts in the global table cannot reach subnet 10.1.1.0/24 within VRF-A. R1 configuration: ip vrf VRF-A, rd 100:1, route-target export 100:1, route-target import 100:1. Interface Gig0/0 in VRF-A has ip address 10.1.1.1 255.255.255.0. The leaking is done via route-map: route-map LEAK permit 10, match ip address prefix-list SUMMARY, set global. Prefix-list SUMMARY permits 10.0.0.0/8. What is the root cause?

Hard
648

A network engineer runs the following command on Router R1: R1# show crypto isakmp sa dst src state conn-id slot status 10.1.1.2 10.1.1.1 MM_ACTIVE 1 0 ACTIVE 10.1.1.3 10.1.1.1 MM_ACTIVE 2 0 ACTIVE Based on this output, which statement is correct?

Medium
649

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on an interface facing the Internet. Legitimate traffic from a customer network is being dropped. The traffic has a source IP that belongs to the customer's prefix, which is reachable via a different interface on the router. Which is the most likely explanation?

Hard
650

A network administrator is deploying MPLS Layer 3 VPNs on Cisco IOS routers. The administrator must ensure that customer routes are exchanged between PE routers without requiring customer involvement. Which two protocols or features are required to accomplish this? (Choose two.)

Hard
651

Which TWO statements about EIGRP stub routing are true when troubleshooting a hub-and-spoke topology? (Choose TWO.)

Hard
652

Which THREE symptoms indicate that an IPv4 access control list may be misconfigured or not applied correctly? (Choose THREE.)

Hard
653

A network engineer is configuring a site-to-site DMVPN Phase 3 hub-and-spoke topology. Spokes must be able to communicate directly without traffic traversing the hub. Which command must be configured on the hub to enable spoke-to-spoke direct tunnels?

Medium
654

A network engineer runs the following command on Router R1: R1# show ip nhrp nhs NHS: 172.16.0.1 Tunnel0 status: registered NHS: 172.16.0.2 Tunnel0 status: not registered Based on this output, what is the problem?

Hard
655

A network engineer configures a Cisco IOS router with the following commands: ip access-list extended BLOCK_TELNET deny tcp any any eq 23 permit ip any any ! interface GigabitEthernet0/0 ip access-group BLOCK_TELNET in After applying the configuration, the engineer notices that Telnet traffic from the local router to a remote device is still successful. What is the cause of this issue?

Medium
656

A network engineer runs the following command on Router R1: R1# show snmp mib MIB: IF-MIB MIB: SNMPv2-MIB MIB: IP-MIB MIB: CISCO-CONFIG-MAN-MIB MIB: ENTITY-MIB Based on this output, which statement is correct?

Easy
657

Which of the following statements about BFD echo mode is true?

Medium
658

A network engineer runs the following command on Router R1: R1# show ip ospf virtual-links Virtual Link OSPF_VL0 to router 10.1.1.3 is up Run as demand circuit DoNotAge LSA allowed. Transit area 1, via interface GigabitEthernet0/0, Cost of using 10 Transmit Delay is 1 sec, State POINT_TO_POINT, Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5 Hello due in 00:00:08 Adjacency State FULL Based on this output, what can be concluded?

Medium
659

What is the default administrative distance for routes redistributed into BGP from an IGP?

Medium
660

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. The hub router is a Cisco IOS XE device with the tunnel source as a physical interface and tunnel mode gre multipoint. Spoke routers are configured with dynamic NHRP mappings. The engineer notices that spoke-to-spoke traffic initially goes through the hub, but after the first packet, the spokes establish a direct tunnel. Which NHRP feature is responsible for this behavior?

Medium
661

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The administrator wants to rate-limit ICMP echo requests destined to the router itself to 64 kbps, while allowing all other traffic to the control plane without restriction. Which configuration snippet correctly achieves this?

Hard
662

A network engineer is configuring a GRE tunnel between two Cisco IOS XE routers, R1 and R2, to transport IPv6 traffic over an IPv4 network. The tunnel source is R1's GigabitEthernet0/0 interface (IPv4 address 10.1.1.1) and the tunnel destination is R2's GigabitEthernet0/0 interface (IPv4 address 10.2.2.2). The engineer configures the tunnel interface with IPv6 address 2001:DB8:1::1/64 and enables OSPFv3 on the tunnel interface. However, OSPFv3 adjacencies are not forming. What is the most likely cause?

Medium
663

Examine the following configuration on R3: !--- R3 configuration access-list 10 permit 192.168.0.0 0.0.255.255 access-list 10 deny any ! route-map OSPF-REDIST permit 10 match ip address 10 set metric-type type-1 ! router ospf 1 redistribute eigrp 100 subnets route-map OSPF-REDIST ! What is the effect of this configuration?

Medium
664

A network technician is configuring a Cisco IOS router to act as a DHCP server for a subnet. The technician wants the router to exclude a range of addresses from being assigned to clients. Which command should be used to exclude the addresses?

Easy
665

A network administrator is troubleshooting a DMVPN Phase 3 network using OSPF. Spoke routers are not learning routes from other spokes despite having a full mesh of tunnels. The hub is configured with 'ip nhrp redirect' and spokes with 'ip nhrp shortcut'. Which action is most likely to resolve the issue?

Hard
666

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-IN Class-map: CoPP-OSPF (match-all) 1000 packets, 60000 bytes 5 minute offered rate 2000 bps, drop rate 0000 bps Match: access-group 140 police: cir 64000 bps, bc 12000 bytes, be 12000 bytes conformed 1000 packets, 60000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Based on this output, which statement is correct?

Easy
667

A network engineer runs the following command on Router R1: R1# show ip nat translations Pro Inside global Inside local Outside local Outside global --- 192.0.2.10 10.0.0.10 --- --- R1# show ip nat statistics Total active translations: 1 (1 static, 0 dynamic; 0 extended) Outside interfaces: GigabitEthernet0/1 Inside interfaces: GigabitEthernet0/0 Hits: 5 Misses: 0 CEF Translated packets: 5, CEF Punted packets: 0 Expired translations: 0 Based on this output, which statement is correct?

Easy
668

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# show ip route 192.168.2.0 Routing entry for 192.168.2.0/24 Known via "eigrp 100", distance 90, metric 2684416, type internal Redistributing via eigrp 100 Last update from 10.0.0.2 on Tunnel0, 00:00:23 ago Routing Descriptor Blocks: * 10.0.0.2, from 10.0.0.2, via Tunnel0 Route metric is 2684416, traffic share count is 1 Total delay is 20000 microseconds, minimum bandwidth is 100000 Kbit Reliability 255/255, minimum MTU 1500 bytes Loading 1/255, Hops 1 What does this output indicate?

Medium
669

An engineer configures uRPF (Unicast Reverse Path Forwarding) in strict mode on a router interface facing the Internet. After configuration, legitimate traffic from customers is being dropped. The engineer verifies that the routing table has a route back to the source IP address. Which is the most likely explanation?

Hard
670

When redistributing routes into OSPF, which OSPF metric value is assigned by default if none is specified?

Easy
671

An EIGRP network with multiple routers is experiencing frequent stuck-in-active (SIA) events for prefix 10.10.10.0/24. The network topology includes a slow WAN link between R1 and R2. R1's show ip eigrp topology 10.10.10.0/24 shows the route in active state with a query outstanding to R2. R2's show ip eigrp topology shows the same prefix in passive state. The EIGRP timers are default. What is the root cause?

Hard
672

An engineer is troubleshooting an MPLS L3VPN where CE1 (10.1.1.0/24) cannot reach CE2 (10.2.2.0/24). The PE routers have MP-BGP peering and the VRF is configured with route-target import 100:100. On PE1, the show ip bgp vpnv4 vrf CUSTOMER command shows the route for 10.2.2.0/24 with a next-hop of 192.168.1.2 (the PE2 loopback), but the show ip route vrf CUSTOMER command does not have this route. The show mpls forwarding-table on PE1 does not show a label for 192.168.1.2. What is the most likely cause?

Hard
673

Drag and drop the steps to troubleshoot Route Maps and Route Filtering adjacency or connectivity failures into the correct order, from first to last.

Hard
674

A network engineer runs the following command to troubleshoot a Route Summarization issue: R1# debug ip routing IP: route table change: 10.0.0.0/16 via 10.1.1.2, Serial0/0/0, distance 90, metric 128576 IP: route table change: 10.0.1.0/24 via 10.1.1.2, Serial0/0/0, distance 90, metric 128576 IP: route table change: 10.0.2.0/24 via 10.1.1.2, Serial0/0/0, distance 90, metric 128576 What does this output indicate?

Medium
675

A network engineer is configuring a Cisco router to act as a DHCP server for a remote subnet. The router's interface connected to the remote subnet is configured with the `ip helper-address` command pointing to the DHCP server. However, clients on the remote subnet are not receiving IP addresses. The engineer verifies that the DHCP server is operational and has a valid pool for the remote subnet. What is the most likely cause of the problem?

Easy
676

Which TWO configuration steps are required to implement Policy-Based Routing (PBR) on a Cisco router? (Choose TWO.)

Easy
677

A network engineer is configuring a Cisco IOS XE router to act as an IPv6 DHCP server for a LAN segment. The router must provide IPv6 addresses and other configuration parameters to hosts. Which two tasks must the engineer perform to enable stateful DHCPv6 operation on the router? (Choose two.)

Medium
678

Which EEM action type is used to modify the configuration of the device?

Easy
679

A network engineer runs the following command to verify MPLS forwarding: R1# show mpls forwarding-table 192.168.1.0 255.255.255.0 detail Output: Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 101 201 192.168.1.0/24 0 Gi0/0 10.0.0.2 MAC/Encaps: 14/18, MTU: 1500, Label Stack {201} No output feature configured What does this output indicate?

Medium
680

In a standard IPv4 ACL, what is the default wildcard mask if none is explicitly configured?

Medium
681

An engineer is troubleshooting a route redistribution issue between OSPF and EIGRP. R1 runs both protocols and redistributes OSPF into EIGRP. The engineer notices that OSPF routes redistributed into EIGRP have an AD of 170, but some routes from OSPF are not being redistributed. What is the most likely cause?

Medium
682

Which OSPF packet type is used to send link-state advertisements (LSAs) and is acknowledged by the receiver?

Easy
683

An engineer configures a DMVPN Phase 2 network. Spoke-to-spoke tunnels are established, but traffic between spokes is not using the direct tunnel. What is the most likely explanation?

Hard
684

A network engineer runs the following command on Router R6: R6# show ip route 10.0.0.0 Routing entry for 10.0.0.0/8 Known via "eigrp 100", distance 90, metric 28160 Redistributing via eigrp 100 Last update from 192.168.1.1 on GigabitEthernet0/0, 00:00:10 ago Routing Descriptor Blocks: * 192.168.1.1, from 192.168.1.1, 00:00:10 ago, via GigabitEthernet0/0 Route metric is 28160, traffic share count is 1 Additionally, an OSPF route for the same prefix is learned with distance 110. Which route will be installed in the routing table?

Easy
685

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 (WAN) and GigabitEthernet0/1 (LAN). The engineer wants to apply strict mode uRPF on the WAN interface and loose mode uRPF on the LAN interface. Which two commands are required to accomplish this? (Choose two.)

Medium
686

A network administrator is configuring a Cisco IOS router as a DHCP server. The router has two interfaces: GigabitEthernet0/0 with IP 192.168.1.1/24 and GigabitEthernet0/1 with IP 10.0.0.1/24. The administrator wants the router to assign addresses from the 192.168.1.0/24 subnet to clients on GigabitEthernet0/0. Which command must be configured in the DHCP pool to ensure that the router only assigns addresses from the correct subnet?

Hard
687

A network engineer runs the following command to troubleshoot a SPAN issue: R1# show monitor session 1 detail Session 1 --------- Type : Local Session Source Ports : Both : Gi0/0 Destination Ports : Gi0/1 Encapsulation : Native Ingress : Disabled What does this output indicate?

Medium
688

A network engineer runs the following command on Router R1: R1# show mpls ldp neighbor Peer LDP Ident: 10.0.0.2:0; Local LDP Ident 10.0.0.1:0 TCP connection: 10.0.0.2.646 - 10.0.0.1.52868 State: Oper; Msgs sent/rcvd: 123/120; Downstream Up time: 02:15:30 LDP discovery sources: GigabitEthernet0/0, Src IP addr: 192.168.1.2 Addresses bound to peer LDP Ident: 10.0.0.2 192.168.1.2 Based on this output, which statement is correct?

Medium
689

Which THREE symptoms indicate a problem with SNMP trap delivery from a Cisco router? (Choose THREE.)

Medium
690

A network engineer runs the following command to verify OSPF SPF calculations: R1# show ip ospf statistics OSPF Router with ID (1.1.1.1) (Process ID 1) Area 0: SPF algorithm executed 12 times SPF calculation time (in msec): Total: 12, Average: 1.0 Minimum: 0, Maximum: 2 Last SPF due to: LSA change Number of LSA changes: 5 Number of LSA deletions: 2 Number of LSA additions: 3 Number of LSA updates: 0 Area 1: SPF algorithm executed 3 times SPF calculation time (in msec): Total: 3, Average: 1.0 Minimum: 0, Maximum: 1 Last SPF due to: LSA change Number of LSA changes: 2 Number of LSA deletions: 0 Number of LSA additions: 2 Number of LSA updates: 0 What does this output indicate?

Hard
691

Which EIGRP packet type is used to confirm receipt of an update during reliable transport in a VRF-Lite configuration?

Medium
692

A network administrator is setting up a site-to-site VPN between two Cisco routers using IPsec. The administrator wants to ensure that the VPN tunnel uses strong encryption and hashing algorithms. Which of the following should be configured to define the encryption and hashing algorithms used for the IPsec SA?

Easy
693

Which TWO symptoms indicate that syslog messages are not being sent to the remote syslog server? (Choose TWO.)

Medium
694

A network engineer runs the following command to verify Flexible NetFlow record configuration: R1# show flow record FLOW-RECORD-1 flow record FLOW-RECORD-1 match ipv4 source address match ipv4 destination address match ip protocol collect counter bytes collect counter packets collect timestamp sys-uptime first collect timestamp sys-uptime last What does this output indicate?

Easy
695

Router R4 has the following DHCPv6 configuration: ipv6 dhcp pool DHCP6_POOL2 address prefix 2001:db8:2::/64 dns-server 2001:db8::1 ! interface GigabitEthernet0/1 ipv6 address 2001:db8:2::1/64 ipv6 dhcp server DHCP6_POOL2 ipv6 nd managed-config-flag no shutdown What is the effect of this configuration?

Medium
696

A network engineer runs the following command to verify IPv6 uRPF drops: R1# show ipv6 traffic | include verify 0 verify source drops, 0 verify source suppressed drops What does this output indicate?

Medium
697

Which statement correctly describes the behavior of the 'logging synchronous' command on a Cisco IOS device?

Medium
698

A network engineer is configuring a site-to-site IPsec VPN between two Cisco routers. The engineer wants to use a pre-shared key for authentication. Which command is used to configure the pre-shared key on the router?

Easy
699

A network engineer is configuring EIGRP on a Cisco router. The router has two interfaces: GigabitEthernet0/0 with IP address 10.1.1.1/24 and GigabitEthernet0/1 with IP address 10.2.2.1/24. The engineer wants to advertise both networks into EIGRP AS 100. Which configuration command is required to enable EIGRP on the interfaces?

Easy
700

Examine this OSPF configuration on router R5: router ospf 1 network 10.0.0.0 0.255.255.255 area 0 passive-interface default no passive-interface GigabitEthernet0/0 What is the effect of the passive-interface default command?

Medium
701

A network engineer runs the following command on Router R1: R1# show mpls ldp neighbor Peer LDP Ident: 192.168.1.2:0, Local LDP Ident: 192.168.0.1:0 TCP connection: 192.168.1.2.646 - 192.168.0.1.49876 State: Oper; Msgs sent/rcvd: 100/105; Downstream on demand Up time: 00:10:30 LDP discovery sources: GigabitEthernet0/0, Src IP addr: 192.168.1.2 Addresses bound to peer LDP Ident: 192.168.1.2 10.1.1.2 Based on this output, what is the state of the LDP session?

Medium
702

A network engineer runs the following command to troubleshoot a VRF-Lite CoPP issue: R1# show policy-map control-plane input class CoPP-ACL vrf CUSTOMER_I Output: Class-map: CoPP-ACL (match-all) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: access-group 100 police: cir 8000 bps, bc 1500 bytes, be 1500 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop What does this output indicate?

Hard
703

A network engineer runs the following command to troubleshoot an Administrative Distance issue: R1# show ip route 172.16.0.0 255.255.0.0 Routing entry for 172.16.0.0/16 Known via "ospf 1", distance 110, metric 20, type intra area Last update from 10.1.1.2 on GigabitEthernet0/0, 00:00:05 ago Routing Descriptor Blocks: * 10.1.1.2, from 2.2.2.2, 00:00:05 ago, via GigabitEthernet0/0 Route metric is 20, traffic share count is 1 What does this output indicate?

Easy
704

In a standard IPv4 ACL, what is the range of valid numbers for the access-list number?

Easy
705

Which TWO configuration steps are required to successfully redistribute OSPF routes into EIGRP on a Cisco router? (Choose TWO.)

Medium
706

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco IOS routers. The tunnel is up, but traffic is not passing. The administrator suspects a routing issue. Which command should be used to verify that the crypto ACL matches the traffic being sent?

Hard
707

A network engineer is configuring a static route on a Cisco IOS router to reach a remote network. The engineer wants the route to be used only if the primary path fails and to be removed from the routing table when the primary path is available. Which type of static route should be configured?

Easy
708

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP class-map: MANAGEMENT (match-all) 100 packets, 5000 bytes 5 minute offered rate 0 bps police: 8000 bps, 1500 limit, 1500 extended limit conformed 95 packets, 4750 bytes; action: transmit exceeded 5 packets, 250 bytes; action: drop conformed 0 bps, exceed 0 bps class-map: ROUTING (match-all) 200 packets, 10000 bytes 5 minute offered rate 0 bps police: 16000 bps, 3000 limit, 3000 extended limit conformed 200 packets, 10000 bytes; action: transmit exceeded 0 packets, 0 bytes; action: drop conformed 0 bps, exceed 0 bps Based on this output, what is happening to traffic matching the MANAGEMENT class?

Hard
709

Which of the following is true regarding the default behavior of NAT in Cisco IOS when handling ICMP traffic?

Medium
710

A network engineer is troubleshooting an IPv6 connectivity issue between two sites connected via a 6to4 tunnel. The tunnel is configured on both routers and shows as up/up, but the engineer cannot ping the IPv6 address of the remote tunnel endpoint. The engineer checks the routing table and sees no route to the remote IPv6 prefix. What is the most likely cause of this problem?

Medium
711

A network administrator is configuring a Cisco IOS XE router to support MPLS L3VPN. The administrator needs to enable MPLS forwarding on an interface that connects to the service provider core. Which command should be applied to the interface?

Easy
712

Which TWO statements about Flexible NetFlow flow monitors and flow exporters are true? (Choose TWO.)

Hard
713

Examine the following configuration on a PE router: ip vrf CUSTOMER-E rd 400:1 route-target export 400:1 route-target import 400:2 ! interface GigabitEthernet0/5 ip vrf forwarding CUSTOMER-E ip address 10.4.4.1 255.255.255.252 ! router bgp 65000 neighbor 10.0.0.1 remote-as 65000 neighbor 10.0.0.1 update-source Loopback0 ! address-family vpnv4 neighbor 10.0.0.1 activate neighbor 10.0.0.1 send-community extended exit-address-family ! address-family ipv4 vrf CUSTOMER-E neighbor 10.4.4.2 remote-as 65003 neighbor 10.4.4.2 activate neighbor 10.4.4.2 route-map SET-COMMUNITY in exit-address-family ! route-map SET-COMMUNITY permit 10 set community 100:100 What is the effect of the route-map on the incoming routes from the CE?

Medium
714

A network engineer is configuring OSPFv3 on a router that connects to an IPv6 network. The router must form an adjacency with a neighbor on the same segment, but the engineer notices that the router is not sending any OSPFv3 Hello packets. The interface is up, and IPv6 unicast routing is enabled globally. Which of the following is the most likely cause?

Medium
715

What is the default SNMP trap queue length on Cisco IOS?

Medium
716

In OSPF, what is the default hello interval on a point-to-point network type?

Easy
717

Consider this IP SLA configuration on router R6: ip sla 60 udp-echo 203.0.113.1 2000 source-ip 198.51.100.1 frequency 20 ip sla schedule 60 life forever start-time now What is the purpose of this configuration?

Medium
718

A network engineer runs the following command on Router R1: R1# show event manager history events Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog EIGRP_Neighbor_Down 2 00:01:31 UTC Mar 1 syslog OSPF_Neighbor_Flap 3 00:01:32 UTC Mar 1 syslog EIGRP_Neighbor_Down 4 00:01:33 UTC Mar 1 syslog OSPF_Neighbor_Flap Based on this output, what is the most likely problem?

Hard
719

A network administrator is configuring MPLS Layer 3 VPN on a Cisco IOS XE router. The router is a PE device connected to two CE routers in different VRFs. The administrator wants to prevent routes from one VRF from being leaked into another VRF. Which configuration step is essential to maintain VRF separation?

Hard
720

An engineer is troubleshooting a DMVPN phase 2 deployment with IPv6 over mGRE tunnels. The spoke routers can ping the hub's tunnel IPv6 address, but cannot reach IPv6 networks behind other spokes. The engineer verifies that NHRP is configured and that the hub has a route to the spoke's internal networks. What is the most likely cause?

Hard
721

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology on Cisco IOS routers. The hub router must dynamically learn spoke-to-spoke routes and allow direct spoke-to-spoke tunnels. Which command must be configured on the hub's tunnel interface to enable Phase 3 behavior?

Medium
722

Which IPv6 access-list entry will deny traffic from any source to the destination prefix 2001:db8:1::/48?

Medium
723

In BGP, what is the default administrative distance for routes learned from an eBGP peer?

Hard
724

A network engineer is configuring a Cisco IOS XE router to send syslog messages to a remote server for security auditing. The engineer wants to ensure that the syslog messages are protected from eavesdropping and tampering. The router already has a CA trustpoint configured. Which command should the engineer use to enable secure syslog?

Medium
725

A network administrator is configuring EIGRP on a router and wants to ensure that only a specific subnet is advertised out of an interface. The router has the following configuration: 'router eigrp 100', 'network 10.0.0.0', 'passive-interface GigabitEthernet0/0'. The administrator wants to advertise 10.1.1.0/24 out of GigabitEthernet0/0 while preventing other subnets from being advertised. Which configuration achieves this?

Medium
726

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The engineer has created a class map named 'CRITICAL' that matches BGP traffic and a policy map named 'COPP-POLICY' that applies a police rate of 1000000 bps with a conform-action transmit and exceed-action drop. After applying the policy map to the control plane, the engineer notices that BGP sessions are flapping. Which action should the engineer take to resolve the issue?

Hard
727

A network administrator is troubleshooting a DMVPN Phase 3 hub-and-spoke deployment where the hub uses mGRE and spokes use mGRE. Spoke-to-spoke traffic works, but the administrator notices that the spokes are installing host routes for other spokes in their routing tables. Which DMVPN Phase 3 feature is responsible for adding these specific host routes?

Medium
728

In BGP, what is the effect of using a route-map with a set community command but without the additive keyword?

Medium
729

R1 and R2 are eBGP peers. R1 advertises a summary route 10.0.0.0/8 via aggregate-address 10.0.0.0 255.0.0.0 summary-only. R2 receives the summary but also expects to receive more specific routes (e.g., 10.1.0.0/16) for traffic engineering. R2's BGP table shows only the summary, and the more specific routes are missing. R1's configuration includes: router bgp 65001, network 10.1.0.0 mask 255.255.0.0, and aggregate-address 10.0.0.0 255.0.0.0 summary-only. What is the root cause?

Hard
730

A network engineer runs the following command on Router R1: R1# show ip sla statistics IPSLAs Latest Operation Statistics IPSLA operation id: 1 Type of operation: icmp-echo Latest RTT: 20 milliseconds Latest operation start time: 12:00:00 UTC Mon Mar 1 2021 Latest operation return code: OK Number of successes: 100 Number of failures: 0 Based on this output, which statement is correct?

Medium
731

Which default administrative distance is assigned to a directly connected interface route?

Easy
732

A network engineer runs the following command to troubleshoot Control Plane Policing (CoPP): R1# show policy-map control-plane input class class-default Class-map: class-default (match-any) 140091 packets, 12345678 bytes 5 minute offered rate 1000 bps, drop rate 0 bps Match: any police: cir 8000 bps, bc 1500 bytes conformed 140091 packets, 12345678 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop What does this output indicate?

Medium
733

A network engineer is configuring a Cisco IOS router to act as a DHCP relay agent. The router interface GigabitEthernet0/0 is connected to a subnet with DHCP clients, and the DHCP server is located at 192.168.100.10. Which command must be applied to the interface to forward DHCP requests to the server?

Medium
734

Drag and drop the steps to verify and validate route redistribution operational state into the correct order, from first to last.

Medium
735

Drag and drop the steps to configure an ERSPAN session for remote traffic capture into the correct order, from first to last.

Medium
736

An engineer applies an IPv6 ACL to filter traffic between two VLANs on a switch using a router-on-a-stick configuration. The ACL is applied inbound on the subinterface. Traffic from VLAN 10 to VLAN 20 is permitted, but return traffic from VLAN 20 to VLAN 10 is dropped. Which is the most likely explanation?

Hard
737

Which TWO statements about MPLS label stack operations in a Layer 3 VPN (L3VPN) are true? (Choose TWO.)

Hard
738

A network engineer runs the following command to verify OSPF database on a DMVPN hub: R1# show ip ospf database router 2.2.2.2 OSPF Router with ID (1.1.1.1) (Process ID 1) Router Link States (Area 0) LS age: 100 Options: (No TOS-capability, DC) LS Type: Router Links Link State ID: 2.2.2.2 Advertising Router: 2.2.2.2 LS Seq Number: 80000001 Checksum: 0x1234 Length: 48 Number of Links: 1 Link connected to: a Transit Network (Link ID) Designated Router address: 10.0.0.1 (Link Data) Router Interface address: 10.0.0.2 Number of MTID metrics: 0 TOS 0 Metrics: 10 What does this output indicate?

Hard
739

A network engineer is configuring a Cisco IOS router to authenticate administrative SSH logins against an external TACACS+ server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, a locally configured fallback account can still be used. The TACACS+ server IP is 10.1.1.100 and the shared key is 'Cisco123'. Which configuration snippet correctly implements this requirement?

Medium
740

A network engineer is configuring a GRE tunnel between two Cisco routers. The tunnel source is a physical interface, and the tunnel destination is a loopback interface on the remote router. The engineer notices that the tunnel interface is up, but line protocol is down. What is the most likely cause?

Easy
741

Which MPLS label is used for the Router Alert function, and what is its purpose?

Medium
742

A network engineer runs the following command to troubleshoot an EEM issue: R1# show event manager history events Event History: Event Type : syslog Time : Mar 1 00:05:23 Pattern : OSPF-5-ADJCHG Trigger count : 1 Event Type : timer Time : Mar 1 00:06:00 Timer Type : absolute Timer Name : MY-TIMER Trigger count : 1 What does this output indicate?

Medium
743

What is the default administrative distance for OSPFv3 internal routes?

Easy
744

A network administrator is deploying DMVPN Phase 3 with IKEv2 IPsec protection. The hub router is configured with a multipoint GRE tunnel interface and NHRP. Spoke routers register with the hub and can communicate directly with each other. The administrator wants to ensure that spoke-to-spoke traffic is encrypted. Which statement about the IPsec configuration is true?

Hard
745

Consider the following DHCPv6 configuration on router R2: ipv6 dhcp pool DHCP6_POOL dns-server 2001:db8::1 domain-name example.com ! interface GigabitEthernet0/0 ipv6 address 2001:db8:1::1/64 ipv6 dhcp server DHCP6_POOL ipv6 nd other-config-flag no shutdown What is the effect of this configuration?

Medium
746

A network engineer is configuring EIGRP for IPv6 on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (2001:DB8:1::1/64) and GigabitEthernet0/1 (2001:DB8:2::1/64). The engineer wants to enable EIGRP for IPv6 on both interfaces and ensure that the router forms adjacencies. Which configuration is required?

Medium
747

A network engineer is implementing MPLS Layer 3 VPN on a Cisco IOS XE router. The engineer wants to ensure that customer routes are advertised with the correct route distinguisher (RD) and route target (RT) extended communities. Which BGP address family must be configured to exchange VPNv4 routes between PE routers?

Medium
748

A network engineer runs the following command on Router P1: P1# show mpls ldp neighbor Peer LDP Ident: 10.0.0.2:0, Local LDP Ident: 10.0.0.1:0 TCP connection: 10.0.0.2.646 - 10.0.0.1.48632 State: Oper, Msgs sent/rcvd: 120/118, Downstream Up time: 00:12:34 LDP discovery sources: GigabitEthernet0/0, Src IP addr: 10.1.1.2 Addresses bound to peer LDP Ident: 10.0.0.2 192.168.1.1 Based on this output, which statement is correct?

Medium
749

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# show ip access-lists 130 Extended IP access list 130 10 deny ip host 10.1.1.1 host 10.2.2.2 20 permit ip any any Then the engineer runs: R1# debug ip packet 130 IP packet debugging is on for access list 130 *Mar 1 00:20:10.123: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto ICMP, access list 130: matched line 10 deny ip host 10.1.1.1 host 10.2.2.2 What does this output indicate?

Medium
750

A network engineer is troubleshooting an MPLS L3 VPN where OSPF is used as the PE-CE routing protocol. The customer reports that routes from one site are not being learned at another site. The engineer checks the PE routers and finds that the OSPF routes are present in the VRF routing table but not in the MP-BGP table. What is the most likely cause?

Hard
751

A network engineer runs the following command to troubleshoot a Policy-Based Routing (PBR) issue: R1# show ip local policy Interface Route-map local PBR-LOCAL What does this output indicate?

Easy
752

A network engineer is configuring MPLS Layer 3 VPN on a Cisco IOS XE router. The engineer wants to enable the router to distribute VPNv4 prefixes to its PE peers. Which command must be configured under the BGP routing process to enable the address family?

Hard
753

A network engineer configures an EEM applet to monitor redistribution events using the event syslog pattern 'IP-4-ROUTING'. The applet is intended to log when a route is redistributed from OSPF into EIGRP. The redistribution is configured without a seed metric for EIGRP, and the route is not redistributed. The EEM applet does not trigger. Which is the most likely explanation?

Hard
754

A network engineer runs the following command to troubleshoot an EIGRP issue: R1# show ip eigrp topology 10.1.1.0/24 IP-EIGRP (AS 100): Topology entry for 10.1.1.0/24 State: Passive, Query origin flag: 1, 1 Successor(s), FD is 131072 Routing Descriptor Blocks: 10.1.2.2 (GigabitEthernet0/0), from 10.1.2.2, Send flag: 0x0 Composite metric: (131072/130816), Route is Internal Vector metric: Minimum bandwidth is 10000 Kbit Total delay is 100 microseconds Reliability is 255/255 Load is 1/255 Minimum MTU is 1500 Hop count is 1 10.1.3.3 (GigabitEthernet0/1), from 10.1.3.3, Send flag: 0x0 Composite metric: (131328/131072), Route is Internal Vector metric: Minimum bandwidth is 10000 Kbit Total delay is 200 microseconds Reliability is 255/255 Load is 1/255 Minimum MTU is 1500 Hop count is 2 What does this output indicate?

Medium
755

In OSPFv3, which authentication method is supported by default?

Hard
756

Given the following configuration on Router R2: router eigrp 200 redistribute ospf 1 metric 10000 100 255 1 1500 default-metric 10000 100 255 1 1500 What is the effect of having both the 'metric' keyword in the redistribute command and the 'default-metric' command?

Medium
757

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet is encrypted and sent over the VPN, while all other traffic is sent unencrypted. Which configuration element defines the traffic to be encrypted?

Medium
758

Which statement about PBR and the 'set interface' command is correct?

Medium
759

Examine this configuration: interface GigabitEthernet0/0 ip address 10.0.0.1 255.255.255.0 ip nat inside ! interface GigabitEthernet0/1 ip address 198.51.100.1 255.255.255.0 ip nat outside ! ip nat inside source static tcp 10.0.0.10 80 198.51.100.10 8080 extendable Which statement is true?

Medium
760

BGP is used between two ISPs. Router R1 has: neighbor 10.0.0.2 route-map SET-MED in, route-map SET-MED permit 10, set metric 50. Router R2 shows: show ip bgp 172.16.0.0 includes MED 50 but the path is not preferred. What is the root cause?

Hard
761

A network engineer is configuring MPLS Layer 3 VPN on a Cisco router. The engineer wants to ensure that the PE router can forward VPN traffic to the correct CE router based on the route target. Which of the following is required on the PE router?

Medium
762

Drag and drop the steps to configure and verify Policy-Based Routing (PBR) into the correct order, from first to last.

Medium
763

Which TWO commands would a network engineer use to verify NAT translations and their statistics on a Cisco IOS router? (Choose TWO.)

Medium
764

An engineer configures PBR on a router to route traffic from subnet 10.1.1.0/24 to next-hop 192.168.1.2. The route-map is applied inbound on interface GigabitEthernet0/0. The engineer also configures 'ip policy route-map' on the same interface. However, the engineer notices that PBR is not working for multicast traffic from that subnet. What is the most likely explanation?

Hard
765

A network administrator is troubleshooting a site-to-site IPsec VPN between two Cisco IOS routers. IKEv1 Phase 1 completes and the peer is authenticated, but the administrator sees that no IPsec SA is installed and interesting traffic is dropped. The administrator confirms the transform sets, ACLs, and pre-shared keys match on both sides. Which configuration element should the administrator verify next on both routers?

Hard
766

A network engineer runs the following command on Router R1: R1# show ipv6 dhcp interface GigabitEthernet0/1 GigabitEthernet0/1 is in server mode Using pool: POOL6 Preference value: 0 Hint from client: ignored Rapid-Commit: disabled Based on this output, which statement is correct?

Easy
767

Consider the following configuration: ipv6 access-list BLOCK-ICMP deny icmp any any echo-request deny icmp any any echo-reply permit ipv6 any any interface GigabitEthernet0/2 ipv6 traffic-filter BLOCK-ICMP in Which statement is true?

Medium
768

Given this configuration on router R1: crypto isakmp policy 10 encryption aes 256 authentication pre-share group 14 lifetime 86400 ! crypto isakmp key cisco123 address 192.168.1.2 ! crypto ipsec transform-set TSET esp-aes 256 esp-sha-hmac mode tunnel ! crypto map CMAP 10 ipsec-isakmp set peer 192.168.1.2 set transform-set TSET match address 101 ! interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ! access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255 What will happen when traffic from 10.1.1.0/24 to 10.2.2.0/24 is generated?

Medium
769

A network engineer runs the following command on Router R1: R1# show ipv6 snooping binding IPv6 Address MAC Address VLAN Interface State 2001:DB8:1::100 aaaa.bbbb.cccc 10 Gi0/0/0 ACTIVE 2001:DB8:1::101 aaaa.bbbb.cccd 10 Gi0/0/0 ACTIVE 2001:DB8:1::102 aaaa.bbbb.ccce 10 Gi0/0/1 ACTIVE 2001:DB8:1::103 aaaa.bbbb.cccf 10 Gi0/0/1 ACTIVE Based on this output, which statement is correct?

Medium
770

A network engineer runs the following command on Router R1: R1# show ip vrf CUSTOMER Name Default RD Interfaces CUSTOMER 65001:100 Gi0/0.100 Gi0/1.100 Based on this output, which statement is correct?

Medium
771

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS XE router. The engineer wants traffic from subnet 10.1.1.0/24 to be forwarded to next-hop 192.168.2.1, while all other traffic uses the default routing table. The engineer configures a route map and applies it to the ingress interface with `ip policy route-map PBR`. However, traffic from 10.1.1.0/24 is still following the default route. Which action should the engineer take to ensure PBR is applied?

Medium
772

Which statement accurately describes the behavior of the ip nat inside source static command when configuring static NAT for a single inside host?

Easy
773

A network engineer is troubleshooting an IPsec site-to-site VPN that stopped working after a recent configuration change. The engineer runs 'show crypto isakmp sa' and sees an active IKE SA, but 'show crypto ipsec sa' shows no IPsec SAs. What is the most likely cause?

Medium
774

An engineer configures iBGP between two routers in the same AS. The BGP session comes up, but the routes learned from the eBGP neighbor are not installed in the routing table. The IGP does not carry the BGP next-hop address. Which is the most likely explanation?

Hard
775

What is the default administrative distance for routes learned via OSPF in Cisco IOS?

Easy
776

Consider the following BGP configuration with BFD: router bgp 65000 neighbor 10.1.1.2 remote-as 65001 neighbor 10.1.1.2 fall-over bfd ! interface GigabitEthernet0/0 ip address 10.1.1.1 255.255.255.252 bfd interval 200 min_rx 200 multiplier 4 ! What is the effect of the 'neighbor fall-over bfd' command?

Medium
777

Interface GigabitEthernet0/1 is configured as shown: interface GigabitEthernet0/1 ipv6 address 2001:db8:1::1/64 ipv6 nd raguard ipv6 nd prefix default no-autoconfig What is the effect of this configuration?

Medium
778

Which THREE symptoms indicate that NAT is misconfigured or failing on a Cisco router? (Choose THREE.)

Hard
779

A network engineer runs the following command on Router R1: R1# show event manager policy registered No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 EIGRP_Neighbor_Down R1# show event manager history events Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog EIGRP_Neighbor_Down Based on this output, which statement is correct?

Easy
780

A network engineer is troubleshooting an MPLS Layer 3 VPN on Cisco IOS XE routers. A customer edge (CE) router is not receiving routes from the provider edge (PE) router. The engineer suspects a VRF configuration issue. Which two commands should the engineer use to verify the VRF routing table and the BGP VPNv4 address family? (Choose two.)

Hard
781

A network administrator is deploying 802.1X on a Cisco Catalyst switch. The switch is configured as an authenticator, and a RADIUS server is used for authentication. The administrator wants to ensure that if the RADIUS server becomes unreachable, endpoints are placed into a guest VLAN with limited access. Which command must be configured on the switch to enable this behavior?

Hard
782

A network engineer runs the following command to troubleshoot an MPLS L3VPN issue: R1# debug mpls ldp transport Output: *Mar 1 00:01:23.456: mpls_ldp_transport: LDP transport connection from 10.0.0.2:646 to 10.0.0.1:1025 *Mar 1 00:01:23.456: mpls_ldp_transport: LDP transport connection from 10.0.0.2:646 to 10.0.0.1:1025 is accepted *Mar 1 00:01:23.456: mpls_ldp_transport: LDP transport connection from 10.0.0.2:646 to 10.0.0.1:1025 is established *Mar 1 00:01:23.456: mpls_ldp_transport: LDP transport connection from 10.0.0.2:646 to 10.0.0.1:1025 is up What does this output indicate?

Medium
783

A network engineer runs the following command on Router R2: R2# show logging | include %SYS-5-CONFIG_I *Mar 1 00:10:15.123: %SYS-5-CONFIG_I: Configured from console by console *Mar 1 00:12:45.678: %SYS-5-CONFIG_I: Configured from console by console *Mar 1 00:15:30.001: %SYS-5-CONFIG_I: Configured from console by console *Mar 1 00:20:00.999: %SYS-5-CONFIG_I: Configured from console by console Based on this output, what is the most likely problem?

Medium
784

A network administrator is troubleshooting a DMVPN Phase 3 hub-and-spoke network using mGRE and NHRP. Spoke-to-spoke communication is failing, but spoke-to-hub communication works. The administrator verifies that NHRP registrations are successful and that the hub is configured with 'ip nhrp redirect'. What is the most likely cause of the spoke-to-spoke failure?

Hard
785

A network engineer is troubleshooting a DHCPv4 issue where a router configured as a DHCP server is not assigning addresses to clients on a subnet that is reachable via a different router (relay). The relay router (R2) has 'ip helper-address 10.1.1.1' on its client-facing interface, and the DHCP server is at 10.1.1.1 (R1). The engineer sees that R2 is sending DHCP DISCOVER messages with giaddr set to the client-facing interface IP, but R1 is not responding. R1 has a DHCP pool for the client subnet. The engineer pings 10.1.1.1 from R2 successfully. What is the most likely cause?

Medium
786

Which of the following is a limitation of NAT as defined in RFC 2663?

Hard
787

Which SNMPv2c PDU type is used by the manager to request a large amount of data efficiently, such as an entire routing table?

Easy
788

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that traffic from the 10.1.1.0/24 subnet is encrypted when going to the 10.2.2.0/24 subnet, but all other traffic should be sent unencrypted. Which configuration element is required to match this traffic?

Medium
789

A network engineer is configuring a DMVPN Phase 3 spoke router. The spoke must establish a direct tunnel to another spoke when traffic requires it. The hub is already configured with 'ip nhrp redirect'. Which additional command must be configured on the spoke to enable it to request and receive shortcut replies from the hub?

Medium
790

Drag and drop the steps for MPLS LDP label discovery and distribution into the correct order, from first to last.

Medium
791

Given this configuration: ip nat pool GLOBAL 203.0.113.1 203.0.113.10 prefix-length 28 ip nat inside source list 10 pool GLOBAL overload access-list 10 permit 10.0.0.0 0.255.255.255 What is the effect?

Medium
792

A network engineer runs the following command to troubleshoot IPv6 source guard: R1# debug ipv6 source-guard *Mar 1 00:04:56.789: IPv6-Source-Guard: R1, Fa0/0, IPv6 packet from 2001:db8::5, src MAC 0011.2233.4455, dst 2001:db8::1 *Mar 1 00:04:56.789: IPv6-Source-Guard: R1, Fa0/0, Binding lookup: 2001:db8::5 not found in binding table *Mar 1 00:04:56.789: IPv6-Source-Guard: R1, Fa0/0, Packet dropped: source 2001:db8::5 not allowed What does this output indicate?

Medium
793

Router R6 is configured to send SNMP inform requests to the NMS at 192.168.1.1. Configuration: snmp-server host 192.168.1.1 informs version 2c public, snmp-server enable traps. The NMS receives no informs. R6's show snmp statistics shows InformRequestsSent: 0, and show snmp pending shows no pending. The NMS can poll R6 successfully. The network has a firewall between R6 and the NMS that allows UDP 162. What is the root cause?

Hard
794

snmp-server ifindex persist What is the effect of this configuration?

Medium
795

Which IP SLA operation type uses ICMP Echo Request/Reply packets to measure round-trip time?

Easy
796

A network engineer runs the following command on Router R1: R1# show ip sla summary IPSLAs Latest Operation Summary Codes: * active, ^ inactive, ~ pending ID Type Destination Stats Return Code Last 1 icmp-echo 192.168.1.1 RTT=50ms OK 1s ago 2 icmp-echo 192.168.1.2 RTT=2000ms Over threshold 2s ago 3 icmp-echo 192.168.1.3 RTT=100ms OK 3s ago Based on this output, which statement is correct?

Medium
797

A network engineer is troubleshooting a router that is not generating any syslog messages at all, even for critical events like interface flaps. The 'show logging' output shows 'Syslog logging: disabled'. What is the most likely cause?

Easy
798

A network engineer runs the following command on Router R1: R1# show ipv6 eigrp neighbors IPv6-EIGRP neighbors for process 100 H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 FE80::A8BB:CCFF:FE00:2 Tunnel0 13 00:23:45 10 200 0 12 1 FE80::A8BB:CCFF:FE00:3 Tunnel1 12 00:22:10 15 200 0 15 Based on this output, which statement is correct?

Medium
799

Router R4 has the following configuration: ``` interface GigabitEthernet0/5 ip address 10.4.4.4 255.255.255.0 ip policy route-map PBR-DEFAULT ! route-map PBR-DEFAULT permit 10 set ip default next-hop 192.168.3.1 ``` What is the effect of this configuration?

Medium
800

A network engineer runs the following command on router R4: R4# show monitor session 9 Session 9 --------- Type : ERSPAN Source Session Status : Admin Disabled Source Ports : Both : Gi0/2 Destination IP : 192.168.2.20 Origin IP : 10.0.0.3 ERSPAN ID : 200 Based on this output, which statement is correct?

Medium
801

What is the default timer value for the EEM environment variable 'timer watchdog'?

Medium
802

A network engineer is implementing Policy-Based Routing (PBR) on a Cisco IOS router. The engineer wants to route traffic from subnet 10.10.10.0/24 to a next-hop of 192.168.2.2, but only for HTTP traffic (TCP port 80). Which configuration sequence is required?

Medium
803

A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. The administrator has configured the crypto ACL as follows: 'access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255'. However, after applying the crypto map, the administrator notices that all traffic, including traffic to other destinations, is being dropped. What is the most likely cause?

Medium
804

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# debug crypto isakmp *Mar 1 00:01:23.456: ISAKMP (0:0): received packet from 192.168.1.2 dport 500 sport 500 Global (N) NEW SA *Mar 1 00:01:23.457: ISAKMP: Created a peer struct for 192.168.1.2, peer port 500 *Mar 1 00:01:23.457: ISAKMP: New peer created peer = 0x12345678 peer_handle = 0x80000001 *Mar 1 00:01:23.457: ISAKMP: Locking peer struct 0x12345678, refcount 1 for crypto_isakmp_process_block *Mar 1 00:01:23.457: ISAKMP (0:0): SA request profile is (default) *Mar 1 00:01:23.457: ISAKMP: local port 500, remote port 500 *Mar 1 00:01:23.458: ISAKMP (0:0): found peer pre-shared-key matching 192.168.1.2 *Mar 1 00:01:23.458: ISAKMP (0:0): constructed NAT-T vendor ID *Mar 1 00:01:23.458: ISAKMP (0:0): sending packet to 192.168.1.2 my_port 500 peer_port 500 (I) MM_NO_STATE *Mar 1 00:01:23.458: ISAKMP (0:0): received packet from 192.168.1.2 dport 500 sport 500 Global (I) MM_NO_STATE *Mar 1 00:01:23.459: ISAKMP (0:0): processing SA payload. message ID = 0 *Mar 1 00:01:23.459: ISAKMP (0:0): Checking ISAKMP transform 1 against priority 1 policy *Mar 1 00:01:23.459: ISAKMP: encryption DES-CBC *Mar 1 00:01:23.459: ISAKMP: hash SHA *Mar 1 00:01:23.459: ISAKMP: default group 2 *Mar 1 00:01:23.459: ISAKMP: auth pre-share *Mar 1 00:01:23.459: ISAKMP (0:0): atts are not acceptable. Next transforms are not acceptable *Mar 1 00:01:23.460: ISAKMP (0:0): no offers accepted! What does this output indicate?

Medium
805

A network engineer runs the following command on Router R1: R1# show flow exporter EXPORTER-1 Flow Exporter EXPORTER-1: Description: Exports to collector Export protocol: NetFlow Version 9 Transport Configuration: Destination IP address: 192.168.1.100 Source IP address: 10.0.0.1 Transport Protocol: UDP Destination Port: 2055 Source Port: 0 Collector Configuration: VRFs: Default Options Configuration: Sampler: Not configured Export Statistics: Number of Flows exported: 0 Number of Packets exported: 0 Number of Source IP address unreachable: 0 Number of Packets dropped: 0 Based on this output, what is the most likely reason that no flows are being exported?

Medium
806

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# show ip sla statistics 10 detail Round Trip Time (RTT) for Index 10 Latest RTT: 12 ms Latest RTT (milliseconds): 12 Latest RTT (microseconds): 12000 Last operation start time: 12:34:56.789 UTC Mon Mar 1 2021 Last operation return code: OK Number of successes: 100 Number of failures: 0 Operation time to live: Forever Last operation response time: 12 ms Latest operation start time: 12:34:56.789 UTC Mon Mar 1 2021 Latest operation return code: OK Over thresholds occurred: FALSE Threshold (milliseconds): 5000 RTT Values: RTTAvg: 12 RTTMin: 10 RTTMax: 15 RTTNum: 100 RTTStdDev: 1 What does this output indicate?

Medium
807

A network engineer runs the following command on Router R1: R1# show event manager policy registered No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 BGP_Neighbor_Down R1# show bgp neighbors 192.168.1.2 BGP neighbor is 192.168.1.2, remote AS 65002, external link BGP version 4, remote router ID 10.0.0.2 BGP state = Idle Last read 00:00:05, hold time is 180, keepalive interval is 60 seconds Neighbor sessions: 1 active, is not multisession capable Based on this output, what is the most likely conclusion?

Hard
808

Which two OSPF network types default to a hello interval of 30 seconds and a dead interval of 120 seconds on Cisco IOS? (Choose two.)

Medium
809

A network engineer runs the following command to troubleshoot an EIGRP issue: R1# show ip eigrp traffic IP-EIGRP Traffic Statistics for process 100 Hellos sent/received: 500/495 Updates sent/received: 10/8 Queries sent/received: 2/1 Replies sent/received: 1/2 Acks sent/received: 8/10 Input queue high water mark: 2, Input queue depth: 0 Total packets sent: 521, received: 516 What does this output indicate?

Easy
810

A network engineer runs the following command on Router R1: R1# show ip eigrp interfaces detail Gi0/0 EIGRP-IPv4 Interfaces for AS(100) Interface: GigabitEthernet0/0 Peers: 1 Xmit Queue Un/Reliable: 0/0 Mean SRTT: 12 Pacing Time Un/Reliable: 0/10 Multicast Flow Timer: 50 Pending Routes: 0 Hello interval: 5 Hold time: 15 Split horizon: Enabled Next multicast: 0.0.0.0 Next broadcast: 0.0.0.0 Based on this output, what is the problem?

Medium
811

Which THREE symptoms indicate a potential issue with NHRP registration in a DMVPN network? (Choose THREE.)

Medium
812

Examine the following partial configuration on a PE router: interface GigabitEthernet0/1 ip vrf forwarding CUSTOMER-A ip address 10.1.1.1 255.255.255.252 ! router bgp 65000 neighbor 192.168.1.1 remote-as 65000 neighbor 192.168.1.1 update-source Loopback0 ! address-family ipv4 vrf CUSTOMER-A neighbor 10.1.1.2 remote-as 65001 neighbor 10.1.1.2 activate exit-address-family What is the effect of this configuration?

Medium
813

Which statement correctly describes the behavior of the 'default-information originate' command in OSPF?

Medium
814

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The VPN tunnel is up, but traffic from the local LAN to the remote LAN is not passing. The administrator verifies that the crypto ACLs match on both peers and that routing is correct. Which of the following is the most likely cause?

Hard
815

A network engineer runs the following command on Router R1: R1# show ip sla statistics 2 Round Trip Time (RTT) for Index 2 Latest RTT: No connection Latest RTT (milliseconds): No connection Latest RTT (microseconds): No connection Number of successes: 0 Number of failures: 100 Operation time to live: Forever Output: No connection Based on this output, which statement is correct?

Medium
816

Management traffic is being dropped. Router R1 has: access-list 100 deny ip any any log, applied to VTY lines. Remote access via SSH fails, but console works. What is the root cause?

Hard
817

Router R4 has the following configuration: !--- R4 configuration route-map SETTAG permit 10 match tag 100 set tag 200 ! route-map SETTAG permit 20 ! router bgp 65100 neighbor 10.0.0.1 route-map SETTAG in ! What is the effect of this configuration?

Medium
818

A network engineer runs the following command on Router R1: R1# show route-map TEST route-map TEST, permit, sequence 10 Match clauses: ip address (access-lists): 10 Set clauses: metric 50 route-map TEST, deny, sequence 20 Match clauses: ip address (access-lists): 20 Set clauses: Based on this output, what is the effect of this route-map when applied to a redistribution command?

Easy
819

What is the default number of packets sent per IP SLA UDP Jitter operation?

Hard
820

A network engineer runs the following command on Router R1: R1# show crypto ipsec sa peer 10.1.1.2 interface: Tunnel0 Crypto map tag: VPN-MAP, local addr 10.1.1.1 protected vrf: (none) local ident (addr/mask/prot/port): (10.1.1.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port): (192.168.1.0/255.255.255.0/0/0) current_peer 10.1.1.2 port 500 PERMIT, flags={origin_is_acl,} #pkts encaps: 100, #pkts encrypt: 100, #pkts digest: 100 #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0 #send errors 0, #recv errors 0 Based on this output, what is the problem?

Medium
821

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on the outside interface of a router that terminates an IPsec site-to-site VPN. After the configuration, the VPN tunnel establishes, but traffic from the remote site is not forwarded correctly. The engineer verifies that the IPsec tunnel is up and that the routing table has the correct routes. What is the most likely explanation?

Hard
822

A network engineer runs the following command on Router R1: R1# show ip bgp neighbors 10.1.1.1 advertised-routes BGP table version is 10, local router ID is 1.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.0.0.0/8 0.0.0.0 0 32768 i *> 10.1.0.0/16 0.0.0.0 0 32768 i *> 10.1.1.0/24 0.0.0.0 0 32768 i *> 10.1.2.0/24 0.0.0.0 0 32768 i Based on this output, what is a problem with the BGP advertisements?

Hard
823

A network engineer runs the following command to troubleshoot a Flexible NetFlow issue: R1# show flow monitor FLOW-MONITOR-1 cache format table Cache type: Normal Cache size: 1000 Current entries: 25 High Watermark: 50 Flows added: 1234 Flows aged: 1209 - Active timeout ( 1800 secs): 100 - Inactive timeout ( 15 secs): 1100 - Event aged: 9 - Watermark aged: 0 - Emergency aged: 0 What does the output indicate?

Medium
824

A network administrator is configuring a Cisco IOS router to support MPLS Layer 3 VPN. The administrator needs to enable the provider edge (PE) router to exchange VPNv4 routes with other PE routers. Which two configurations are required on the PE router to enable MP-BGP for VPNv4? (Choose two.)

Medium
825

What is the default OSPF hello interval on a point-to-point serial interface?

Easy
826

A network engineer is troubleshooting a router that is experiencing intermittent packet loss. The engineer checks the logs and sees that an EEM applet is being triggered frequently. The applet is configured to run a script that modifies the routing table. The engineer suspects the applet is causing the packet loss. What should the engineer do to verify the root cause?

Medium
827

Drag and drop the steps to troubleshoot VRF-Lite adjacency or connectivity failures into the correct order, from first to last.

Hard
828

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS-XE router to protect the route processor from excessive traffic. The administrator creates a class-map to match all management traffic (SSH, SNMP, TACACS+) and a policy-map to police that traffic to 1 Mbps. After applying the service-policy to the control-plane, the administrator notices that some legitimate SNMP polling is being dropped. Which two actions can the administrator take to resolve this issue while maintaining protection against DoS attacks? (Choose two.)

Hard
829

A network engineer runs the following command on Router R1: R1# show ipv6 nd raguard policy Interface Policy Role State Gi0/0/0 RA_GUARD router ACTIVE Gi0/0/1 RA_GUARD host ACTIVE Gi0/0/2 (default) host ACTIVE Based on this output, which statement is correct?

Medium
830

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# show crypto isakmp sa detail IPv4 Crypto ISAKMP SA C-id Local Remote I-VRF Status Encr Hash Auth DH Lifetime Cap. 1001 192.168.1.1 192.168.2.2 ACTIVE des sha pre 2 23:59:21 1002 192.168.1.1 192.168.2.2 ACTIVE 3des sha pre 2 23:58:15 IPv6 Crypto ISAKMP SA What does this output indicate?

Easy
831

Which OSPF LSA type is used to advertise external routes and is flooded throughout the entire OSPF domain?

Medium
832

A network engineer is configuring Policy-Based Routing (PBR) on a Cisco IOS XE router. The engineer wants to forward traffic matching a specific ACL to a next-hop IP address, but only if the next-hop is reachable. Which command should be used in the route map to specify the next-hop and enable tracking?

Medium
833

A network engineer runs the following command to troubleshoot DHCPv6 relay on router R1: R1# debug ipv6 dhcp relay Output: IPv6 DHCP relay: Received SOLICIT message from FE80::1 on GigabitEthernet0/0 IPv6 DHCP relay: Forwarding SOLICIT to server 2001:DB8:2::1 via GigabitEthernet0/1 IPv6 DHCP relay: Received ADVERTISE message from server 2001:DB8:2::1 via GigabitEthernet0/1 IPv6 DHCP relay: Forwarding ADVERTISE to client FE80::1 via GigabitEthernet0/0 IPv6 DHCP relay: Received REQUEST message from FE80::1 on GigabitEthernet0/0 IPv6 DHCP relay: Forwarding REQUEST to server 2001:DB8:2::1 via GigabitEthernet0/1 IPv6 DHCP relay: Received REPLY message from server 2001:DB8:2::1 via GigabitEthernet0/1 IPv6 DHCP relay: Forwarding REPLY to client FE80::1 via GigabitEthernet0/0 What does this output indicate?

Medium
834

A network engineer is configuring OSPFv3 on a dual-stack router. The router must form an adjacency with a neighbor over a link that supports both IPv4 and IPv6. The interface is configured with 'ipv6 ospf 1 area 0' and the router ID is manually set to 10.1.1.1. After applying the configuration, the engineer notices that the OSPFv3 adjacency remains in EXSTART state. What is the most likely cause?

Medium
835

A network engineer configures a Cisco IOS router with the command 'ip dhcp excluded-address 10.10.10.1 10.10.10.20'. The DHCP pool is defined as 'ip dhcp pool LAN' with network 10.10.10.0 /24. Which statement accurately describes the effect of the excluded-address command?

Medium
836

A network engineer is troubleshooting an MPLS L3VPN where customer routes are not being propagated between PE routers. The engineer verifies that the MP-BGP session between the PEs is established and that VRFs are configured correctly. Which of the following is the most likely cause for the missing routes?

Hard
837

An engineer configures mutual redistribution between OSPF and EIGRP on a router. After a few minutes, the router's CPU spikes and routes start flapping. Which is the most likely explanation?

Hard
838

A network engineer runs the following command to troubleshoot an EIGRP issue: R1# show ip eigrp neighbors detail IP-EIGRP neighbors for process 100 H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 10.1.2.2 Gi0/0 13 00:12:34 12 200 0 145 Version 12.4/1.2, Retrans: 0, Retries: 0, Prefixes: 5 Topology-ids from peer - 0 Stub Peer Advertising (CONNECTED STATIC) Routes Suppressing queries What does this output indicate?

Medium
839

Router R8 is configured with SNMP and IP SLA. The IP SLA operation sends SNMP traps to the NMS when a threshold is crossed. The configuration includes: ip sla 1, icmp-echo 192.168.1.1, threshold 100, timeout 1000, frequency 10, ip sla schedule 1 life forever start-time now, snmp-server enable traps ip sla. However, the NMS receives no traps when the threshold is crossed. The IP SLA operation shows 'Over threshold' in show ip sla statistics. What is the root cause?

Hard
840

Consider the following partial configuration on router R4: interface GigabitEthernet0/0 ip address 192.168.2.1 255.255.255.0 ipv6 address 2001:db8:1::1/64 ipv6 ospf 1 area 0 ! interface GigabitEthernet0/1 ip address 10.0.0.1 255.255.255.0 ipv6 address 2001:db8:2::1/64 ipv6 ospf 1 area 0 ! ipv6 router ospf 1 router-id 4.4.4.4 What is the effect of this configuration?

Medium
841

Which THREE symptoms indicate a BGP route dampening issue that is causing routes to be suppressed? (Choose THREE.)

Hard
842

A network engineer runs the following command to troubleshoot a Route Redistribution issue: R1# show ip route summary And sees the following output: Route Source Networks Subnets Replicates Overhead Memory (bytes) connected 2 0 0 0 512 static 1 0 0 0 256 ospf 1 5 0 0 0 1280 eigrp 100 3 0 0 0 768 bgp 65000 2 0 0 0 512 internal 1 0 0 0 256 Total 14 0 0 0 3584 What does this output indicate?

Easy
843

A network administrator is deploying IPv6 First Hop Security features on a Cisco Catalyst switch. The goal is to prevent rogue DHCPv6 servers from assigning addresses to clients. The administrator configures DHCPv6 Guard on the switch. Which additional configuration is necessary to ensure that DHCPv6 Guard operates correctly?

Hard
844

An engineer configures a DMVPN Phase 2 network with IPsec protection. Spoke-to-spoke tunnels form, but traffic between spokes is not being forwarded directly; it still goes through the hub. The engineer verifies that NHRP registrations are successful and that the spoke-to-spoke IPsec sessions are established. What is the most likely explanation?

Hard
845

A network engineer is configuring uRPF on a Cisco IOS router. The router has two interfaces: GigabitEthernet0/0 (WAN) and GigabitEthernet0/1 (LAN). The engineer wants to prevent spoofed packets from entering the WAN interface while allowing asymmetric routing. Which uRPF mode should be configured on GigabitEthernet0/0?

Medium
846

A network engineer is configuring a Cisco IOS router to use IPsec VPN with IKEv2. The engineer wants to ensure that the router prefers a specific transform set that includes AES-256 encryption and SHA-256 hashing for integrity. Which command correctly defines the IKEv2 proposal with these parameters?

Easy
847

Which RFC defines the IPv6 Neighbor Discovery Protocol that is the basis for many First Hop Security features?

Easy
848

A network engineer is configuring a Cisco IOS router to authenticate administrative SSH logins against an external TACACS+ server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used as a fallback. Which configuration accomplishes this?

Medium
849

A network engineer configures Flexible NetFlow on a router to monitor traffic on a trunk interface with multiple VLANs. The flow monitor is applied to the physical interface. The engineer notices that all flows show the same VLAN ID in the collector, even though traffic from different VLANs is present. What is the most likely cause?

Hard
850

Which TWO commands would a network engineer use to verify the NHRP registration status of a spoke router in a DMVPN Phase 2 network? (Choose TWO.)

Medium
851

Which TWO statements are true regarding the use of VRF-Lite in a Cisco Enterprise network? (Choose TWO.)

Medium
852

A network administrator is deploying 802.1X on a Cisco Catalyst switch. The switch is configured as an authenticator, and the RADIUS server is reachable. However, some devices such as printers do not support 802.1X supplicant software. The administrator wants these devices to be automatically placed into a restricted VLAN with limited access. Which feature should be configured on the switch ports to achieve this?

Hard
853

A network engineer runs the following command to troubleshoot a Route Redistribution issue: R1# show ip bgp vpnv4 vrf CUSTOMER routes And sees the following output: Network Next Hop Metric LocPrf Weight Path Route Distinguisher: 100:1 (default for vrf CUSTOMER) *> 192.168.10.0/24 10.1.1.2 0 100 0 65001 i *> 192.168.20.0/24 10.1.1.2 0 100 0 65001 i What does this output indicate?

Hard
854

Which statement about PBR and the 'set ip precedence' command is correct?

Easy
855

Which of the following is true about the SPAN source interface configuration?

Easy
856

A network engineer is implementing DMVPN Phase 3 with IPsec tunnel protection. The hub router must be configured to support NHRP redirect. Which command is required on the hub's tunnel interface?

Hard
857

A network engineer is troubleshooting IPv6 BGP path selection on Router R1. Router R1 is receiving a prefix from two different BGP peers, but it is not selecting the expected best path. Router R1 has the following relevant configuration: router bgp 65000 address-family ipv6 unicast neighbor 2001:DB8:1::2 route-map SET_LOCAL_PREF in neighbor 2001:DB8:2::2 route-map SET_MED in ! route-map SET_LOCAL_PREF permit 10 set local-preference 200 ! route-map SET_MED permit 10 set metric 50 ! The output of show bgp ipv6 unicast 2001:DB8:3::/64 on Router R1 indicates that the path from 2001:DB8:1::2 has local preference 200, but the path from 2001:DB8:2::2 is selected. What is the root cause?

Hard
858

Examine the following CoPP configuration on a Cisco IOS-XE router: !--- ACL to match traffic access-list 100 permit tcp any any eq 22 access-list 100 permit tcp any any eq 23 access-list 100 permit icmp any any echo ! !--- Class-map class-map match-all COPP-MGMT match access-group 100 ! !--- Policy-map policy-map COPP-POLICY class COPP-MGMT police 8000 conform-action transmit exceed-action drop class class-default police 64000 conform-action transmit exceed-action drop ! !--- Apply to control-plane control-plane service-policy input COPP-POLICY What is the effect of this configuration?

Medium
859

Examine this configuration snippet: ``` router rip distance 120 ``` Which statement is true about the effect of this command?

Medium
860

Given this configuration on Router R3: ``` interface Tunnel0 no ip address ipv6 address 2001:DB8:5::1/64 tunnel source 192.168.1.1 tunnel destination 192.168.2.2 tunnel mode ipv6ip ``` What is missing or incorrect?

Medium
861

Which TWO statements correctly describe the behavior of Control Plane Policing (CoPP) when applied to a Cisco IOS router? (Choose TWO.)

Hard
862

Which statement about PBR and the 'match ip address' command is correct?

Easy
863

Which statement about the SPAN destination port behavior is correct?

Medium
864

A network engineer runs the following command on Router R1: R1# show flow monitor FLOW-MONITOR-1 cache format table Cache type: Normal Cache size: 1000 Current entries: 0 High Watermark: 0 Flows added: 0 Flows aged: 0 - Active timeout (1800 secs) 0 - Inactive timeout (15 secs) 0 - Event aged 0 - Watermark aged 0 - Emergency aged 0 R1# show flow interface GigabitEthernet0/1 Interface GigabitEthernet0/1 FNF: monitor Monitor: FLOW-MONITOR-1 direction: Input traffic-statistics: enabled Based on both outputs, what is the most likely problem?

Hard
865

Which TWO statements about IPsec transform sets and security associations (SAs) are true? (Choose TWO.)

Hard
866

A network engineer runs the following command to verify DMVPN tunnel status: R1# show ip nhrp detail 10.0.0.2/32 via Tunnel0 Created: 00:10:15, Expire: 01:49:45 Type: dynamic, Flags: unique registered NBMA: 192.168.1.2 (no socket) What does this output indicate?

Medium
867

An engineer configures an EEM applet to monitor DMVPN tunnel events using the event syslog pattern 'NHRP-3-REGISTRATION'. The applet is supposed to send an email when a spoke registers with the NHS. The DMVPN network uses Phase 2 with spoke-to-spoke tunnels. A spoke registers successfully, but the EEM applet does not trigger. Which is the most likely explanation?

Hard
868

A network engineer runs the following command to troubleshoot DHCPv6 address assignment on router R1: R1# show ipv6 dhcp binding Output: Client: FE80::21A:2BFF:FE3C:4D01 DUID: 0003000121A2B3C4D5E6 Username: unassigned VRF: default IA NA: IA ID 0x00040001, T1 302400, T2 483840 Address: 2001:DB8:1::100 Preferred lifetime 604800, valid lifetime 2592000 Expires at Mar 01 2025 12:00 PM (2592000 seconds) IA PD: IA ID 0x00040002, T1 302400, T2 483840 Prefix: 2001:DB8:1::/48 Preferred lifetime 604800, valid lifetime 2592000 Expires at Mar 01 2025 12:00 PM (2592000 seconds) What does this output indicate?

Medium
869

What is the default behavior of an IPv4 ACL regarding the order of evaluation when multiple entries match a packet?

Medium
870

What is the default retransmission timeout for SNMP informs on a Cisco IOS device?

Hard
871

Given the following partial configuration on a router: ip access-list standard FILTER_SNMP permit 192.168.1.0 0.0.0.255 deny any ! snmp-server community public RO FILTER_SNMP snmp-server location DataCenter snmp-server contact admin@example.com What is the effect of this configuration?

Medium
872

A network engineer is deploying a GET VPN solution using Cisco IOS routers. The key server must be configured to rekey group members. Which protocol does GET VPN use to distribute encryption keys and policies to group members?

Hard
873

A router configured as a DHCPv4 server uses a pool with 'bootfile' and 'next-server' options for PXE boot. Clients receive the DHCP offer with the correct bootfile, but they fail to download it. Which is the most likely explanation?

Hard
874

A network engineer runs the following command to troubleshoot Flexible NetFlow cache usage: R1# show flow monitor FLOW-MONITOR-1 statistics Cache type: Normal Cache size: 1000 Current entries: 900 High Watermark: 950 Flows added: 50000 Flows aged: 49100 - Active timeout ( 1800 secs): 40000 - Inactive timeout ( 15 secs): 9000 - Event aged: 100 - Watermark aged: 0 - Emergency aged: 0 What does this output indicate?

Hard
875

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# show crypto ipsec transform-set Transform set combined-des-sha: { esp-des esp-sha-hmac } will negotiate = { Tunnel, }, Transform set myset: { esp-3des esp-sha-hmac } will negotiate = { Tunnel, }, Transform set strong: { esp-aes 256 esp-sha-hmac } will negotiate = { Tunnel, }, What does this output indicate?

Easy
876

An engineer configures a route-map to filter OSPF routes using a distribute-list. The distribute-list is applied inbound on an OSPF interface. Unexpectedly, the router still installs the filtered routes. Which is the most likely explanation?

Hard
877

Analyze the following partial configuration: access-list 101 permit tcp any any eq 179 access-list 101 permit udp any any eq 646 access-list 101 permit ospf any any ! class-map match-all COPP-BGP match access-group 101 ! policy-map COPP-POLICY class COPP-BGP police 48000 conform-action transmit exceed-action drop class class-default police 128000 conform-action transmit exceed-action drop ! interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ! control-plane service-policy input COPP-POLICY Which statement is true?

Medium
878

A network engineer is troubleshooting an IPsec site-to-site VPN between two routers. The tunnel interface is up/up, but traffic from the local LAN to the remote LAN is not passing. The engineer checks the crypto map and sees it is applied to the outside interface. What is the most likely cause of the traffic failure?

Medium
879

Which statement correctly describes the behavior of the 'subnets' keyword when redistributing into OSPF?

Medium
880

In IPsec site-to-site VPN, what is the purpose of the 'match address' command under a crypto map?

Easy
881

What is the default OSPF network type for a serial interface configured with HDLC encapsulation on Cisco routers?

Hard
882

A network engineer runs the following command on Router R1: R1# show ipv6 interface tunnel 0 Tunnel0 is up, line protocol is up IPv6 is enabled, link-local address is FE80::A8BB:CCFF:FE00:1 No global unicast address is configured Joined group address(es): FF02::1 FF02::2 FF02::1:FF00:1 MTU is 1480 bytes ICMP error messages limited to one every 100 milliseconds ICMP redirects are enabled ICMP unreachables are sent ND DAD is enabled, number of DAD attempts: 1 ND reachable time is 30000 milliseconds ND advertised reachable time is 0 milliseconds ND advertised retransmit interval is 0 milliseconds ND router advertisements are sent every 200 seconds ND router advertisements live for 1800 seconds Hosts use stateless autoconfiguration for addresses. Based on this output, what is a likely problem?

Medium
883

A network engineer runs the following command to troubleshoot a Route Summarization issue: R1# show ip bgp 10.0.0.0/16 BGP routing table entry for 10.0.0.0/16, version 2 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 Local, (aggregated by 65000 1.1.1.1) 10.1.1.2 from 10.1.1.2 (2.2.2.2) Origin IGP, metric 0, localpref 100, valid, external, best Atomic-aggregate What does this output indicate?

Medium
884

A network engineer runs the following command to verify IPv6 access-list hits: R1# show ipv6 access-list FILTER | include matches permit ipv6 2001:DB8:1::/48 any sequence 10 (10 matches) deny ipv6 2001:DB8:2::/48 any sequence 20 (5 matches) permit ipv6 any any sequence 30 (100 matches) What does this output indicate?

Medium
885

What is the default LDP keepalive timer value on Cisco IOS-XE routers?

Medium
886

A network engineer is troubleshooting a DMVPN phase 2 network where the hub router is not learning the loopback interface routes from the spokes via EIGRP. The spokes have EIGRP configured on the tunnel interface and are advertising their loopback0 interface. The hub's EIGRP neighbor relationship with the spokes is established. However, the hub's routing table does not contain the loopback routes. The engineer checks the spoke's EIGRP configuration and sees that the loopback interface is not included in any network statement. What is the most likely cause?

Medium
887

A network engineer runs the following command on Router R1: R1# show crypto map Crypto Map "VPN-MAP" 10 ipsec-isakmp Peer = 10.1.1.2 Extended IP access list 100 access-list 100 permit ip 10.1.1.0 0.0.0.255 192.168.1.0 0.0.0.255 Current peer: 10.1.1.2 Security association lifetime: 4608000 kilobytes/3600 seconds PFS (Y/N): N Transform sets={ESP-AES256-SHA,} Interfaces using crypto map VPN-MAP: Tunnel0 Based on this output, which statement is correct?

Medium
888

An engineer must configure a Cisco IOS router to log messages to a syslog server at 192.168.1.100 with a severity level of 3 (errors) and above, while also ensuring that console messages are limited to severity 5 (notifications) and above. Which TWO configuration changes are required? (Choose TWO.)

Hard
889

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. The hub router is a Cisco IOS XE device running a recent release. The engineer notices that spoke-to-spoke traffic is still traversing the hub even though the spokes have established direct tunnels. Which technology must be enabled on the hub to allow spoke routers to dynamically discover a direct path to other spokes?

Medium
890

A network engineer is configuring a Cisco IOS router to act as a DHCP server for a subnet 10.10.10.0/24. The engineer wants to ensure that the router provides the default gateway, DNS server, and domain name to DHCP clients. Which three commands must be configured in the DHCP pool? (Choose three.)

Medium
891

A network administrator is troubleshooting an IPsec VPN between two Cisco routers. The VPN tunnel is up, but only small pings succeed; larger packets fail. The administrator suspects an MTU or fragmentation issue. Which action is most likely to resolve the problem while maintaining security?

Hard
892

A network engineer runs the following command to troubleshoot an EIGRP issue: R1# debug eigrp packets hello *Mar 1 00:05:23.123: EIGRP: received packet with MD5 authentication, key id = 1 *Mar 1 00:05:23.123: EIGRP: int GigabitEthernet0/0, src 10.1.1.2 dst 224.0.0.10, seq 0, ttl 1, opcode = 1 (Hello) *Mar 1 00:05:23.123: EIGRP: authentication failed for packet from 10.1.1.2, key id = 1, integrity check failed What does this output indicate?

Medium
893

An engineer configures a distribute-list on an OSPF router to filter routes. However, the routes are still being advertised to neighbors. Which is the most likely explanation?

Hard
894

Which TWO statements about DHCPv6 stateless autoconfiguration (SLAAC) are true? (Choose TWO.)

Hard
895

Which EIGRP packet type is used to acknowledge receipt of a reliable packet?

Easy
896

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-IN Class-map: CoPP-EIGRP (match-all) 200 packets, 12000 bytes 5 minute offered rate 1000 bps, drop rate 0000 bps Match: access-group 150 police: cir 16000 bps, bc 3000 bytes, be 3000 bytes conformed 200 packets, 12000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop R1# show ip eigrp neighbors EIGRP-IPv4 neighbors for process 100 H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 10.1.1.2 Gi0/0 13 00:10:00 1 200 0 5 Based on this output, which statement is correct?

Medium
897

A network administrator is configuring IPsec VPN on a Cisco IOS router using IKEv2. The administrator wants to ensure that the IKEv2 proposal includes encryption and integrity algorithms that are considered secure. Which two algorithms should be included in the IKEv2 proposal? (Choose two.)

Medium
898

What is the default action for a CoPP policy-map class that does not have an explicit 'police' command?

Medium
899

A network engineer is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The engineer wants to ensure that the VPN tunnel only comes up when there is interesting traffic matching an extended ACL. The ACL is defined as: access-list 100 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255. The crypto map is applied to interface GigabitEthernet0/0. Which command is required to complete the configuration so that the router considers traffic matching the ACL as interesting?

Medium
900

A network engineer runs the following command to verify MPLS L3VPN operation: R1# show ip route vrf CUSTOMER-A summary Output: Route Source Networks Subnets Overhead Memory (bytes) connected 2 0 48 288 static 1 0 24 144 ospf 100 5 2 168 1008 bgp 65000 10 3 312 1872 External: 10, Internal: 0, Local: 0 Total 18 5 552 3312 What does this output indicate?

Medium
901

A network engineer is troubleshooting a DMVPN Phase 3 network where spoke-to-spoke communication is not working. The hub is configured with ip nhrp redirect, and spokes are configured with ip nhrp shortcut. The routing protocol is OSPF, and the hub is configured with ip nhrp map multicast dynamic. The engineer notices that when a spoke pings another spoke's LAN IP, the first few pings fail, but subsequent pings succeed. However, the engineer wants to eliminate the initial packet loss. Which of the following is the most likely cause of the initial packet loss?

Hard
902

A network administrator is troubleshooting a DMVPN Phase 3 configuration on a Cisco IOS router. The hub router is configured with a multipoint GRE tunnel interface and NHRP. Spoke routers are unable to establish direct spoke-to-spoke tunnels; all traffic between spokes is going through the hub. The administrator verifies that NHRP registration is successful and that the hub has a mapping for each spoke. Which configuration change on the hub is required to enable spoke-to-spoke direct communication?

Hard
903

A router is configured to send syslog messages to two servers: 10.1.1.100 and 10.1.1.200. The engineer notices that only server 10.1.1.100 is receiving messages. The configuration shows 'logging host 10.1.1.100' and 'logging host 10.1.1.200'. Both servers are reachable via ping. What is the most likely cause?

Medium
904

A network engineer is configuring a Cisco router to act as a DHCPv6 server for a dual-stack network. The engineer wants to provide IPv6 addresses to clients and also supply them with DNS server addresses. Which DHCPv6 message type should the server use to send the DNS server information to the clients?

Easy
905

Consider the following configuration on a router running BGP and OSPF: ``` router bgp 65000 distance bgp 20 200 200 ``` What is the effect of this command?

Medium
906

A network engineer is troubleshooting a DMVPN Phase 3 deployment on a Cisco IOS XE router. The hub router is configured with 'ip nhrp redirect' and the spoke routers with 'ip nhrp shortcut'. However, spoke-to-spoke traffic is still traversing the hub. Which action should the engineer take to enable direct spoke-to-spoke communication?

Medium
907

Which TWO statements correctly describe the behavior of BGP conditional route injection? (Choose TWO.)

Hard
908

A network engineer runs the following command to debug MPLS LDP label advertisements: R1# debug mpls ldp labels Output: *Mar 1 00:01:23.456: LDP: Sent label mapping for 192.168.1.0/24, label 101 *Mar 1 00:01:23.789: LDP: Received label mapping for 192.168.2.0/24, label 201 *Mar 1 00:01:24.012: LDP: Sent label mapping for 10.0.0.0/8, label 102 *Mar 1 00:01:24.345: LDP: Received label mapping for 10.0.0.0/8, label 202 What does this output indicate?

Medium
909

A network engineer runs the following command on Router R1: R1# show ip eigrp traffic EIGRP-IPv4 Traffic Statistics for AS(100) Hellos sent/received: 5000/4995 Updates sent/received: 150/148 Queries sent/received: 10/8 Replies sent/received: 8/10 Acks sent/received: 300/298 Input queue high water mark: 10 Input queue drops: 0 SIA-Queries sent/received: 0/0 SIA-Replies sent/received: 0/0 Hello process ID: 123 PDM process ID: 124 Socket queue: 0/2000/10/0 (current/max/highest/drops) Input queue: 0/2000/10/0 (current/max/highest/drops) Based on this output, which statement is correct?

Medium
910

What is the default CoPP behavior for traffic that does not match any class in the policy-map?

Medium
911

A network engineer runs the following command to troubleshoot BFD with static routes: R1# show ip route 10.8.8.0/24 Routing entry for 10.8.8.0/24 Known via "static", distance 1, metric 0 Routing Descriptor Blocks: * 10.9.9.2, via GigabitEthernet0/3 Route metric is 0, traffic share count is 1 BFD enabled, BFD state: UP What does this output indicate?

Medium
912

A network engineer runs the following command to verify MPLS L3VPN operation: R1# show bgp ipv4 unicast 10.1.1.0/24 Output: BGP routing table entry for 10.1.1.0/24, version 10 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 Local 0.0.0.0 from 0.0.0.0 (10.0.0.1) Origin incomplete, metric 0, localpref 100, weight 32768, valid, sourced, best What does this output indicate?

Medium
913

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 192.168.1.0/24 subnet to the 10.0.0.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which configuration element is used to define this traffic?

Hard
914

A network engineer runs the following command to troubleshoot an MPLS LDP issue: R1# debug mpls ldp transport LDP: Transport connection to 2.2.2.2:0 via TCP (passive) LDP: Connection from 2.2.2.2:0 to 1.1.1.1:646 LDP: Transport connection to 2.2.2.2:0 via TCP (active) LDP: Connection from 1.1.1.1:646 to 2.2.2.2:0 LDP: Hold timer expired for peer 2.2.2.2:0 LDP: Closing transport connection to 2.2.2.2:0 What does this output indicate?

Hard
915

A network engineer is deploying BGP on a Cisco IOS XE router. The router must advertise the network 10.10.0.0/16 to an external peer, but the engineer notices that the prefix is not being advertised even though the network command is configured. The routing table shows that 10.10.0.0/16 is present as two separate /24 routes via OSPF. What is the most likely cause?

Medium
916

A network engineer notices that IPv6 hosts on a segment are not receiving Router Advertisements, even though Router R1 has IPv6 unicast-routing enabled and an IPv6 address on the interface. Router R1 has the following relevant configuration: interface GigabitEthernet0/0 ipv6 address 2001:DB8:1::1/64 ipv6 nd suppress-ra ! Router R2, connected to the same segment, shows: no IPv6 neighbors in the neighbor cache for R1's link-local address. What is the root cause?

Hard
917

A network engineer runs the following command on Router R1: R1# show bfd neighbors detail IPv4 Sessions NeighborAddr LD/RD Int State Holdown(mult) Intf 10.1.1.2 1/3 Gi0/0 Up 1500(3) Gi0/0 Session state is UP and not using echo function. OurAddr: 10.1.1.1 Handle: 1 Local Diag: 0, Demand mode: 0, Poll bit: 0 MinTxInt: 1000000, MinRxInt: 1000000, Multiplier: 3 Received MinRxInt: 1000000, Received Multiplier: 3 Holddown (hits): 1500(0) Rx Count: 120, Tx Count: 150 Based on this output, which statement is correct?

Medium
918

A service provider is deploying MPLS Traffic Engineering (TE) with RSVP-TE to ensure bandwidth guarantees for critical traffic. The network engineer has configured an MPLS TE tunnel on a Cisco IOS XE router. The tunnel must be able to signal an explicit path that includes a specific link with a reserved bandwidth of 50 Mbps. Which RSVP-TE object is used to carry the explicit route information in the Path message?

Hard
919

What is the default maximum number of NAT translations that can be created in Cisco IOS?

Medium
920

A network engineer is troubleshooting PAT (overload) on a Cisco router. The inside network uses 192.168.1.0/24, and the outside interface has IP 198.51.100.1. The engineer configured 'ip nat inside source list 1 interface GigabitEthernet0/0 overload'. Traffic from inside hosts works initially, but after a few minutes, new connections fail. 'Show ip nat translations' shows many entries with the same outside global IP but different ports. 'Show ip nat statistics' indicates that the number of translations is near 500. What is the most likely cause?

Medium
921

Which BGP attribute is used as the first tie-breaker when selecting the best path in a VRF-Lite environment?

Medium
922

A network engineer is configuring a Cisco IOS router to send syslog messages to a remote syslog server at 10.1.1.100. The router's loopback0 interface is 192.168.1.1. The engineer wants syslog messages to be sourced from the loopback0 interface. Which command must be configured?

Medium
923

A network engineer is configuring a Cisco IOS XE router as a DHCPv6 server for a dual-stack network. The router must provide IPv6 addresses and other configuration parameters to clients on VLAN 20. The engineer has configured a DHCPv6 pool named POOL1 with the address prefix 2001:DB8:20::/64 and the DNS server 2001:DB8::53. The clients are not receiving IPv6 addresses. Which additional configuration is required on the router's VLAN 20 interface to ensure DHCPv6 clients can obtain addresses?

Medium
924

Which statement about the Next Hop Resolution Protocol (NHRP) in DMVPN is correct regarding the purpose of NHRP Registration Request packets?

Easy
925

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP. Spokes are behind dynamic NAT and register with the hub using their public IP addresses. The engineer wants to ensure that spoke-to-spoke traffic can be established directly without traversing the hub. Which NHRP configuration is required on the hub to support this?

Medium
926

An engineer applies the following configuration to an interface: interface GigabitEthernet0/5 ipv6 dhcp guard attach-policy DHCP_GUARD ipv6 snooping database file nvram:ipv6-snoop.db Which statement is true?

Medium
927

A network administrator is configuring a Cisco IOS router to use AAA authorization for administrative commands. The administrator wants to ensure that users are authorized for specific commands based on their user role. The TACACS+ server is configured with command authorization sets. Which AAA authorization method should the administrator configure to enforce command authorization?

Hard
928

Which TWO configuration steps are required to implement Control Plane Policing (CoPP) on a Cisco IOS-XE router? (Choose TWO.)

Hard
929

A network engineer configures a DMVPN spoke with the following: interface Tunnel0 ip address 10.0.0.3 255.255.255.0 ip nhrp network-id 100 ip nhrp nhs 10.0.0.1 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ip nhrp map 10.0.0.1 192.168.1.1 ip nhrp map multicast 192.168.1.1 ! What will happen when the spoke tries to send traffic to another spoke (10.0.0.4)?

Medium
930

A network engineer runs the following command on Router R1: R1# show snmp trap SNMP Trap: enabled Trap receiver: 192.168.1.100 Community: PUBLIC Version: 2c UDP port: 162 Enable traps: snmp, interface, bgp Trap receiver: 192.168.1.200 Community: PRIVATE Version: 2c UDP port: 162 Enable traps: snmp, ospf Based on this output, which statement is correct?

Medium
931

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-IN Class-map: CoPP-ICMP (match-all) 100 packets, 6000 bytes 5 minute offered rate 500 bps, drop rate 500 bps Match: access-group 100 police: cir 8000 bps, bc 1500 bytes, be 1500 bytes conformed 50 packets, 3000 bytes; actions: transmit exceeded 25 packets, 1500 bytes; actions: drop violated 25 packets, 1500 bytes; actions: drop Based on this output, what is the most likely impact on the router?

Medium
932

What is the default BGP hold timer value in an MPLS L3VPN deployment on Cisco IOS-XE?

Easy
933

A network administrator is configuring a Cisco IOS router to authenticate administrative logins using TACACS+ with a fallback to local authentication. The TACACS+ server is reachable, but the administrator wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used. The router currently has the following configuration: aaa new-model aaa authentication login default group tacacs+ local tacacs server TAC1 address ipv4 10.1.1.1 key cisco What additional configuration is required to ensure that the router falls back to local authentication when the TACACS+ server does not respond?

Medium
934

A network engineer runs the following command on Router R1: R1# show event manager policy registered No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 EIGRP_Neighbor_Down R1# show ip eigrp neighbors IP-EIGRP neighbors for process 100 H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 192.168.1.2 Gi0/0 13 00:02:00 40 200 0 5 Based on this output, what is the most likely problem?

Hard
935

A network engineer configures CoPP to protect the control plane, but after redistributing routes, some legitimate routing updates are dropped. Router R1 config: control-plane service-policy input COPP ! class-map match-all ROUTING match access-group name ROUTING ! policy-map COPP class ROUTING police 100000 15000 15000 conform-action transmit exceed-action drop ! access-list ROUTING permit tcp any any eq bgp access-list ROUTING permit udp any any eq 520 access-list ROUTING permit ospf any any R1# show policy-map control-plane input Class-map: ROUTING (match-all) 100 packets, 10000 bytes 5 minute offered rate 0 bps drop rate 0 bps Match: access-group name ROUTING police: cir 100000 bps, bc 15000 bytes, be 15000 bytes conformed 90 packets, 9000 bytes; actions: transmit exceeded 10 packets, 1000 bytes; actions: drop What is the root cause?

Hard
936

In BFD multihop sessions, what is the default value for the TTL (or hop limit) in outgoing BFD Control packets on Cisco IOS-XE?

Hard
937

A network engineer runs the following command on Router R1: R1# show event manager policy registered No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 OSPF_Neighbor_Down R1# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 10.1.1.2 1 FULL/DR 00:00:36 192.168.1.2 GigabitEthernet0/0 Based on this output, what is the most likely conclusion?

Medium
938

A network engineer runs the following command on Router R1: R1# show dmvpn Legend: Attrb -> S: Static, D: Dynamic, I: Incomplete N: NATed, L: Local, X: No Socket #Ent -> Number of NHRP entries with same NBMA peer NHS Status: E => Expecting Replies, R => Responding, W => Waiting UpDn Time -> Up or Down Time for a Tunnel ========================================================================== Interface: Tunnel0, IPv4 NHRP Details Type:Hub, NHRP Peers:2, # Ent Peer NBMA Addr Peer Tunnel Addr State UpDn Tm Attrb ----- --------------- ---------------- ----- -------- ----- 1 10.1.1.2 172.16.0.2 UP 00:02:15 D 1 10.1.1.3 172.16.0.3 UP 00:01:45 D Based on this output, which statement is correct?

Medium
939

A network engineer runs the following command to troubleshoot an MPLS L3VPN issue: R1# show bgp neighbors 10.0.0.2 advertised-routes Output: BGP table version is 10, local router ID is 10.0.0.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.1.1.0/24 0.0.0.0 0 32768 i *> 10.2.2.0/24 0.0.0.0 0 32768 i Total number of prefixes 2 What does this output indicate?

Medium
940

Which default administrative distance is assigned to routes learned via the Open Shortest Path First (OSPF) protocol?

Easy
941

A network engineer runs the following command on Router R1: R1# show bfd neighbors detail IPv4 Sessions NeighborAddr LD/RD Int State Holdown(mult) Intf 10.1.1.2 1/3 Gi0/0 Up 3000(3) Gi0/0 Session state is UP and not using echo function. OurAddr: 10.1.1.1 Handle: 1 Local Diag: 0, Demand mode: 0, Poll bit: 0 MinTxInt: 1000000, MinRxInt: 1000000, Multiplier: 3 Received MinRxInt: 1000000, Received Multiplier: 3 Holddown (hits): 3000(0) Rx Count: 100, Tx Count: 100 Based on this output, what is the BFD session's local discriminator?

Easy
942

A network engineer runs the following command to troubleshoot a BGP Troubleshooting issue: R1# show bgp neighbors 10.1.1.2 advertised-routes BGP table version is 14, local router ID is 1.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.0.0.0/24 0.0.0.0 0 32768 i *> 192.168.1.0/24 0.0.0.0 0 32768 i Total number of prefixes 2 What does this output indicate?

Medium
943

Examine the following EIGRP configuration on Router R6: interface GigabitEthernet0/2 ip hello-interval eigrp 100 15 ip hold-time eigrp 100 45 What is the effect of these commands?

Medium
944

An engineer is troubleshooting an EIGRP issue where a router is not learning any routes from a neighbor, but the neighbor adjacency is up. The engineer checks the EIGRP topology table on the local router and sees that the neighbor is listed, but no routes from that neighbor are present. The engineer also verifies that the neighbor has routes to advertise. What is the most likely cause?

Medium
945

A network administrator is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The administrator wants to ensure that uRPF is applied in strict mode on an interface that connects to an ISP. Which command correctly enables strict uRPF on the interface?

Easy
946

A large enterprise network is experiencing intermittent BGP session resets between R1 and R2. R1 has the following relevant configuration: event manager applet BGP-MONITOR event syslog pattern "%BGP-3-NOTIFICATION" action 1.0 cli command "enable" action 2.0 cli command "clear ip bgp *" action 3.0 syslog msg "BGP session cleared by EEM". Router R2 shows: BGP neighbor 10.1.1.1 has been up for 0:00:05, state Established. What is the root cause?

Hard
947

A network engineer is troubleshooting an IPv4 Network Address Translation (NAT) configuration on a Cisco IOS router. The router is configured with NAT overload (PAT) using the command ip nat inside source list 1 interface GigabitEthernet0/0 overload. Inside hosts cannot reach the Internet. The engineer verifies that interface GigabitEthernet0/0 is up and has an IP address, and that access list 1 permits the inside subnet. Which additional configuration is most likely missing?

Medium
948

A network engineer is configuring a GRE tunnel between two Cisco routers. The tunnel source is GigabitEthernet0/0 on Router A with IP 192.168.1.1, and the tunnel destination is 192.168.2.1 on Router B. After configuration, the tunnel interface is up, but no traffic passes through. What is the most likely cause?

Easy
949

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# show ip interface GigabitEthernet0/1 | include access list Outgoing access list is 140 Inbound access list is not set Then the engineer runs: R1# show ip access-lists 140 Extended IP access list 140 10 deny icmp any any 20 permit ip any any What does this output indicate?

Easy
950

A network engineer runs the following command to troubleshoot an ERSPAN issue: R1# show monitor session 3 detail Session 3 --------- Type : ERSPAN Source Session Source Ports : Both : Gi0/0 Destination IP : 10.1.1.1 ERSPAN ID : 100 What does this output indicate?

Medium
951

Examine the following EEM applet configuration: !--- event manager applet BACKUP_CONFIG event timer watchdog time 86400 action 1.0 cli command "enable" action 2.0 cli command "copy running-config tftp://192.168.1.100/backup.cfg" !--- What is the effect of this configuration?

Medium
952

A network engineer is configuring a Cisco IOS router to support a new branch office that requires dynamic IPv4 addressing for clients. The router is already configured with a DHCP pool named BRANCH_POOL. The engineer notices that clients are not receiving IP addresses. Which command, when applied globally, is required to enable the DHCP service on the router?

Medium
953

Which TWO statements about the 'show policy-map control-plane' command output are true? (Choose TWO.)

Hard
954

Router R6 has the following DHCPv6 configuration: ipv6 dhcp pool DHCP6_POOL3 address prefix 2001:db8:3::/64 lifetime 3600 600 dns-server 2001:db8::1 ! interface GigabitEthernet0/2 ipv6 address 2001:db8:3::1/64 ipv6 dhcp server DHCP6_POOL3 ipv6 nd managed-config-flag no shutdown What is the effect of the lifetime parameters 3600 and 600?

Medium
955

An engineer is troubleshooting an EIGRP issue where a router is not learning a specific route from a neighbor, but other routes from the same neighbor are being learned. The engineer checks the EIGRP topology table and sees that the route is not present. The engineer also checks the neighbor's routing table and confirms that the route exists. What is the most likely cause?

Easy
956

What is the default behavior of BGP synchronization in Cisco IOS-XE?

Hard
957

Drag and drop the steps to configure a GRE tunnel for IPv6 over IPv4 into the correct order, from first to last.

Medium
958

A router running Cisco IOS XE has a VRF-aware DMVPN phase 3 tunnel interface. The network administrator wants to ensure that spoke-to-spoke traffic is switched directly between spokes when a route to the destination is present in the NHRP database. Which configuration on the hub is required to enable this behavior?

Medium
959

A network engineer is implementing BGP on a Cisco IOS XE router. The router is peering with an ISP and receives a full BGP table. The engineer wants to influence inbound traffic from the ISP by making a specific prefix more preferred. The engineer has configured a route map that sets the MED to 50 for the prefix 203.0.113.0/24 and applies it outbound to the ISP. However, the ISP still prefers a different path. Which BGP attribute should the engineer manipulate to influence inbound traffic more effectively?

Hard
960

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# show crypto engine connections active Crypto Engine Connections ID Type Algorithm Encrypt Decrypt LastSeqNo 1 IPsec ESP-3DES+SHA 0 0 0 2 IPsec ESP-3DES+SHA 0 0 0 3 IPsec ESP-AES+SHA 0 0 0 What does this output indicate?

Easy
961

Which TWO commands verify the operational status of a local SPAN session on a Cisco IOS-XE switch? (Choose TWO.)

Medium
962

What is the default OSPF reference bandwidth used in the cost calculation formula on Cisco IOS?

Easy
963

A network administrator is deploying MPLS Layer 3 VPNs with Cisco IOS XE routers. The administrator wants to ensure that customer routes are not leaked into the global routing table and that each VPN instance maintains separate routing and forwarding tables. Which of the following must be configured on the PE routers to achieve this isolation?

Hard
964

A network engineer is configuring VRF-lite on a Cisco IOS router to segment traffic for two customers. The engineer creates VRF CUSTA and assigns interface GigabitEthernet0/1 to it. The engineer then configures a static route within VRF CUSTA to reach 10.10.10.0/24 via next-hop 192.168.1.1. However, the route does not appear in the VRF CUSTA routing table. Which command is missing?

Hard
965

A network engineer is configuring a Cisco IOS router to run OSPFv3 for IPv6. The router must form an adjacency with a neighbor on a broadcast network. Which command is required to enable OSPFv3 on an interface?

Easy
966

A network engineer is troubleshooting a BGP route advertisement issue. Router R1 (AS 65001) is an eBGP peer of R2 (AS 65002). R1 is advertising the prefix 10.0.0.0/8 to R2. R2 has an iBGP session with R3 (AS 65002). R3's BGP table shows the prefix 10.0.0.0/8 with next-hop 10.1.1.1 (R1's interface). However, R3 does not install this route in its routing table. The output of 'show ip route 10.0.0.0' on R3 shows no route. The engineer checks the routing table on R3 and sees that the interface connected to 10.1.1.0/24 is down. What is the most likely cause?

Easy
967

An engineer configures iBGP between two PE routers in an MPLS L3VPN. The PE routers are in the same AS and are directly connected. The engineer configures 'neighbor x.x.x.x next-hop-self' on the route reflector (RR) but notices that the RR is not sending the VPNv4 routes to the client PE with the next-hop set to itself. The client PE receives the routes but the next-hop remains the original PE. What is the most likely explanation?

Hard
968

An engineer configures a route map to filter OSPF routes using a distribute-list in OSPF process 1. The distribute-list references a prefix-list that permits only the 10.0.0.0/8 network. After applying the distribute-list in, the engineer notices that the OSPF neighbor state remains stuck in EXSTART/EXCHANGE. Which is the most likely explanation?

Hard
969

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 connected to the Internet, and GigabitEthernet0/1 connected to the internal network. The engineer wants to ensure that packets coming from the Internet are dropped if their source IP address is not reachable via the same interface. However, the internal network uses asymmetric routing, so strict uRPF cannot be used on the internal interface. Which configuration should be applied to GigabitEthernet0/0 to achieve the goal?

Hard
970

A network engineer is configuring a static route on a Cisco IOS router to reach the network 10.1.1.0/24 via the next-hop 192.168.1.1. The engineer wants the route to be removed from the routing table if the next-hop becomes unreachable. Which command should be used?

Easy
971

What is the maximum hop count for a route in RIPv2 by default?

Easy
972

Which DHCPv6 option carries the DNS recursive name server information?

Easy
973

A network architect is designing a FlexVPN solution using IKEv2 between a hub and multiple spokes. The hub must authenticate spokes using certificates, and spokes must authenticate the hub. The architect wants to ensure that the hub can verify the revocation status of spoke certificates in real time. Which mechanism should be implemented?

Hard
974

A network engineer runs the following command on Router R1: R1# show snmp host Host: 192.168.1.100 Port: 162 Timeout: 1.5 seconds Retries: 3 Version: 2c Community: PUBLIC Host: 192.168.1.200 Port: 162 Timeout: 3 seconds Retries: 5 Version: 3 User: admin Security level: authPriv Based on this output, which statement is correct?

Medium
975

A network engineer configures NetFlow on a router using the legacy 'ip flow-export' commands. After applying 'ip route-cache flow' on an interface, 'show ip flow export' shows packets being sent, but the collector reports that all flows have a source IP of the router's management interface instead of the actual source IPs. What is the most likely cause?

Medium
976

What is the default behavior of an EEM applet when a 'set' action modifies a variable that is used in a subsequent 'if' condition?

Easy
977

A network engineer runs the following command on Router R1: R1# show ip nat translations Pro Inside global Inside local Outside local Outside global tcp 192.0.2.10:80 10.0.0.10:80 203.0.113.5:12345 203.0.113.5:12345 tcp 192.0.2.10:80 10.0.0.11:80 203.0.113.5:67890 203.0.113.5:67890 R1# show ip nat statistics Total active translations: 2 (0 static, 2 dynamic; 2 extended) Outside interfaces: GigabitEthernet0/1 Inside interfaces: GigabitEthernet0/0 Hits: 50 Misses: 0 CEF Translated packets: 50, CEF Punted packets: 0 Expired translations: 0 Dynamic mappings: -- Inside Source [Id] ip nat inside source list ACL1 interface GigabitEthernet0/1 overload refcount 2 Based on this output, what is the problem?

Hard
978

R1 and R2 are iBGP peers. R1 has: neighbor 10.1.1.2 route-map RM_SET in. The route-map RM_SET sets community 100:100. R2 advertises a prefix 172.16.1.0/24 with community 200:200. R1 receives the prefix and the community is changed to 100:100. However, R1's BGP table shows the prefix with community 100:100, but R1 does not propagate this prefix to its other iBGP peer R3. R3 has no special configuration. What is the root cause?

Hard
979

A network engineer runs the following command to troubleshoot SNMPv3: R1# show snmp user User name: admin Engine ID: 800000090300001122334455 Storage-type: nonvolatile Authentication Protocol: SHA Privacy Protocol: AES128 Group: admin-group User name: monitor Engine ID: 800000090300001122334455 Storage-type: nonvolatile Authentication Protocol: MD5 Privacy Protocol: DES Group: monitor-group What does this output indicate?

Hard
980

A network engineer runs the following command on Router R1: R1# show crypto isakmp sa dst src state conn-id slot status 10.1.1.2 10.1.1.1 MM_NO_STATE 1 0 ACTIVE Based on this output, what is the problem?

Medium
981

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# show ip sla history 10 Point by Point History Entry = 10 Life = 1 Time of Event = 12:34:56.789 UTC Mon Mar 1 2021 Start Time = 12:34:56.789 UTC Mon Mar 1 2021 Completion Time = 12:34:57.001 UTC Mon Mar 1 2021 Return Code = OK RTT = 12 ms Life = 2 Time of Event = 12:35:56.789 UTC Mon Mar 1 2021 Start Time = 12:35:56.789 UTC Mon Mar 1 2021 Completion Time = 12:35:57.001 UTC Mon Mar 1 2021 Return Code = OK RTT = 14 ms Life = 3 Time of Event = 12:36:56.789 UTC Mon Mar 1 2021 Start Time = 12:36:56.789 UTC Mon Mar 1 2021 Completion Time = 12:36:57.001 UTC Mon Mar 1 2021 Return Code = OK RTT = 11 ms What does this output indicate?

Medium
982

A network engineer runs the following command on Router R1: R1# show bfd neighbors detail IPv4 Sessions NeighborAddr LD/RD Int State Holdown(mult) Intf 10.1.1.2 1/3 Gi0/0 Up 3000(3) Gi0/0 Session state is UP and not using echo function. OurAddr: 10.1.1.1 Handle: 1 Local Diag: 0, Demand mode: 0, Poll bit: 0 MinTxInt: 1000000, MinRxInt: 1000000, Multiplier: 3 Received MinRxInt: 1000000, Received Multiplier: 3 Holddown (hits): 3000(0) Rx Count: 100, Tx Count: 100 Based on this output, what is the BFD session's detection time?

Medium
983

Which TWO statements about the behavior of administrative distance in Cisco IOS are correct? (Choose TWO.)

Hard
984

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. Spokes should be able to communicate directly with each other without traffic traversing the hub. The hub router interface is already configured with 'ip nhrp network-id 1' and 'ip nhrp map multicast dynamic'. Which additional command must be configured on the hub to allow spoke-to-spoke direct tunnels?

Medium
985

A network engineer configures EEM to monitor memory usage on R1. R1 has: event manager applet MEM-MONITOR event snmp oid 1.3.6.1.4.1.9.9.48.1.1.1.6.1 get-type exact entry-op gt entry-val 90 poll-interval 10 action 1.0 cli command "enable" action 2.0 cli command "show processes memory" action 3.0 syslog msg "High memory usage detected". After a few days, the engineer notices that the applet never triggers, even though memory usage exceeds 90%. Router R2 shows: memory usage is at 95%, but no syslog from EEM. What is the root cause?

Hard
986

Drag and drop the steps to establish a DMVPN Phase 2 spoke-to-spoke tunnel into the correct order, from first to last.

Medium
987

Which of the following statements about MPLS L3VPN label operations is true?

Medium
988

In a VRF-Lite scenario with OSPF, what is the default network type on a physical Ethernet interface?

Easy
989

A network engineer is troubleshooting a router that has been running for 200 days. The router experiences a sudden reboot, and after reload, the configuration is missing. 'show startup-config' returns 'startup-config is not present'. The engineer checks the boot variable: 'boot system flash:ios-image.bin'. What is the most likely cause of the configuration loss?

Hard
990

Which BGP attribute is considered the highest priority (most preferred) in the BGP best path selection process?

Medium
991

A network engineer runs the following command on Router R1: R1# show ip access-lists Extended IP access list 150 10 permit ip 10.0.0.0 0.255.255.255 any (500 matches) 20 deny ip any any (100 matches) Based on this output, which statement is correct?

Easy
992

In MPLS, what is the default label distribution control mode for LDP on Cisco IOS-XE?

Hard
993

A network engineer runs the following command on Router R1: R1# show ip route vrf RED 192.168.1.0 Routing entry for 192.168.1.0/24 Known via "connected", distance 0, metric 0 (connected, via interface) Routing Descriptor Blocks: * directly connected, via GigabitEthernet0/2 Route metric is 0, traffic share count is 1 Based on this output, which statement is correct?

Easy
994

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent through the tunnel, while other traffic is sent unencrypted. Which configuration element is required to define the interesting traffic?

Medium
995

Which TWO statements about IPsec site-to-site VPN troubleshooting using 'show crypto session' and 'show crypto ipsec sa' are correct? (Choose TWO.)

Hard
996

What is the default administrative distance for OSPF routes in Cisco IOS?

Easy
997

A network engineer is configuring a Cisco IOS XE router to mitigate spoofed source addresses on a WAN-facing interface using Unicast Reverse Path Forwarding. The WAN provider uses asymmetric routing, where return traffic from the provider occasionally arrives on a different interface than the one used for outbound traffic. The engineer wants to avoid dropping legitimate packets while still providing anti-spoofing protection. Which uRPF mode should the engineer configure on the WAN interface?

Medium
998

A network engineer is configuring a DMVPN Phase 3 hub router. Spoke routers are behind dynamic NAT and cannot receive inbound connections. The engineer needs to ensure that spoke-to-spoke traffic flows directly without traversing the hub. Which technology must be enabled on the hub to achieve this?

Medium
999

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# debug ip packet 110 IP packet debugging is on for access list 110 *Mar 1 00:15:22.345: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto TCP, flags 0x2, sport 12345, dport 23, access list 110: matched line 10 deny tcp host 10.1.1.1 host 10.2.2.2 eq 23 *Mar 1 00:15:22.346: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto TCP, flags 0x10, sport 12345, dport 23, access list 110: matched line 10 deny tcp host 10.1.1.1 host 10.2.2.2 eq 23 What does this output indicate?

Medium
1000

A network engineer is configuring a Cisco IOS router to authenticate management users via TACACS+ against an ISE server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, the router will fall back to using the local username database for authentication. The TACACS+ server is already configured with the address 10.1.1.100 and a shared secret. Which additional configuration is required on the router to achieve this fallback?

Medium
1001

A network engineer runs the following command to troubleshoot IPsec IKE phase 1: R1# debug crypto isakmp ISAKMP: (0:0:N/A:0) Starting aggressive mode exchange ISAKMP: (0:0:N/A:0) processing SA payload ISAKMP: (0:0:N/A:0) Checking ISAKMP transform 1 against priority 1 policy ISAKMP: (0:0:N/A:0) encryption 3DES ISAKMP: (0:0:N/A:0) hash SHA ISAKMP: (0:0:N/A:0) group 2 ISAKMP: (0:0:N/A:0) auth pre-share ISAKMP: (0:0:N/A:0) life type in seconds ISAKMP: (0:0:N/A:0) life duration (basic) of 86400 ISAKMP: (0:0:N/A:0) atts are not acceptable What does this output indicate?

Hard
1002

In EIGRP, what is the default administrative distance of a summary route created with the 'ip summary-address eigrp' command?

Easy
1003

What is the maximum number of actions that can be configured in a single EEM applet?

Easy
1004

An engineer is troubleshooting why the NMS is receiving duplicate SNMP traps from router R9 for the same event. The router has two 'snmp-server host' commands pointing to the same NMS IP address but with different community strings: 'public' and 'private'. The NMS is configured to process traps from both communities. What is the most likely cause?

Medium
1005

When an SNMP agent sends an InformRequest, what is the default behavior regarding acknowledgment?

Medium
1006

A network engineer runs the following command to troubleshoot BFD session flapping: R1# debug bfd packet *Mar 1 00:15:23.456: BFD: [R1-to-R3] received async packet from 10.5.5.2, state UP, diag 0 *Mar 1 00:15:23.457: BFD: [R1-to-R3] sending async packet, state UP *Mar 1 00:15:23.458: BFD: [R1-to-R3] received echo packet from 10.5.5.2, state UP *Mar 1 00:15:23.459: BFD: [R1-to-R3] echo packet lost, no echo received for 300 ms *Mar 1 00:15:23.460: BFD: [R1-to-R3] state UP -> DOWN (echo failure) What does this output indicate?

Hard
1007

Consider the following EIGRP configuration on Router R4: router eigrp 300 variance 2 network 172.16.0.0 What is the purpose of the variance command?

Medium
1008

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on an interface connected to a service provider. The router has a default route pointing to the ISP. Traffic from the ISP is being dropped by uRPF. Which is the most likely explanation?

Hard
1009

Which IP SLA operation type uses ICMP to discover the path (hops) between source and destination?

Easy
1010

A network engineer is troubleshooting an IPsec site-to-site VPN between two Cisco routers. Phase 1 is up, but Phase 2 fails to establish. The engineer suspects a mismatch in the transform set. Which command should be used to verify the transform set configured for the crypto map on the local router?

Medium
1011

Which TWO configuration steps are required to enable a Cisco IOS router as a stateful DHCPv6 server for clients on interface GigabitEthernet0/0? (Choose TWO.)

Hard
1012

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against DoS attacks. The engineer has created a class-map to match malicious traffic and a policy-map to police it. Which two statements are true regarding the application and behavior of CoPP? (Choose two.)

Hard
1013

A network administrator is configuring a site-to-site VPN on a Cisco IOS router using IPsec. The administrator wants to ensure that only traffic from the 192.168.1.0/24 subnet is encrypted and sent over the VPN tunnel. Which configuration component is used to define the interesting traffic?

Easy
1014

A network engineer is configuring a site-to-site IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which crypto ACL configuration achieves this?

Medium
1015

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against DoS attacks. The engineer wants to rate-limit ARP packets destined to the route processor to 1000 packets per second, with a burst of 2000 packets. Which CoPP policy configuration accomplishes this?

Hard
1016

An engineer is troubleshooting an EIGRP network where routes from router R1 are not being installed in the routing table of router R2, although R2 sees them in the EIGRP topology table. Which TWO configuration issues could cause this problem? (Choose TWO.)

Hard
1017

Examine the following EEM applet configuration: !--- event manager applet LOGIN_ALERT event syslog occurs 1 period 60 action 1.0 syslog msg "Login event detected" !--- What is the problem with this configuration?

Medium
1018

Which statement about the default behavior of 'auto-summary' in EIGRP for DMVPN tunnel interfaces in IOS-XE is correct?

Hard
1019

A router has CoPP configured with a class-map that matches BGP traffic (TCP port 179) and polices it to 500 pps. The router has multiple iBGP peers. After applying the policy, some BGP sessions flap, but others remain stable. The flapping peers are those with higher latency. Which is the most likely explanation?

Hard
1020

A network administrator is troubleshooting an OSPFv3 network. Router R1 is not forming an adjacency with Router R2 over a point-to-point link. The administrator verifies that the interfaces are up, IPv6 addresses are configured, and OSPFv3 is enabled on both interfaces. The output of 'show ipv6 ospf interface' on R1 shows that the interface is in the 'LOOPBACK' state. What is the most likely reason for this state?

Hard
1021

A network engineer runs the following command to troubleshoot a BGP Troubleshooting issue: R1# show bgp ipv4 unicast 192.168.1.0/24 BGP routing table entry for 192.168.1.0/24, version 12 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 65001, (received & used) 10.1.1.2 from 10.1.1.2 (10.1.1.2) Origin IGP, metric 0, localpref 100, valid, external, best Community: 100:200 What does this output indicate?

Medium
1022

Which TWO statements about BGP route reflectors are true? (Choose TWO.)

Hard
1023

A network engineer runs the following command to troubleshoot a Device Access Control issue: R1# show policy-map control-plane input class class-default Class-map: class-default (match-any) 140225 packets, 12345678 bytes 5 minute offered rate 1000 bps, drop rate 0 bps Match: any police: cir 1000000 bps, bc 31250 bytes conformed 140225 packets, 12345678 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop What does this output indicate?

Medium
1024

A network engineer runs the following command on Router R1: R1# show ip eigrp topology 10.0.0.0 255.255.252.0 IP-EIGRP (AS 100): Topology entry for 10.0.0.0/22 State: Passive, Origin: Internal, Metric [90/2172416], Tag 0 Number of successors: 1 FD is 2172416, Serno: 5 Route is Summary Advertised by R2 (via Serial0/0/0) Reply status: 0 Based on this output, what is true about the route 10.0.0.0/22?

Medium
1025

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive control-plane traffic. After applying the CoPP policy, the administrator notices that OSPF adjacencies are flapping and that SNMP polling from the management station is failing. The administrator wants to correct the CoPP policy without disabling protection entirely. Which two actions should the administrator take? (Choose two.)

Hard
1026

A network engineer is configuring a Cisco IOS router for IPv6 First Hop Security. The requirement is to prevent rogue DHCPv6 servers from assigning addresses to clients on a VLAN. The engineer has already enabled IPv6 snooping on the VLAN. Which additional feature should be configured to meet this requirement?

Hard
1027

An engineer enables unicast RPF (uRPF) in strict mode on an interface. Afterward, some legitimate traffic from a BGP neighbor is dropped. The neighbor has two paths to the router, and traffic may arrive on a different interface than the return path. What is the most likely explanation?

Hard
1028

A network engineer is troubleshooting BGP route summarization on a border router that advertises a summary route 172.16.0.0/16 to an ISP neighbor. The engineer notices that the ISP is receiving the summary route but also receiving the more specific routes (172.16.1.0/24, 172.16.2.0/24), causing suboptimal routing. What should the engineer do to ensure only the summary route is advertised?

Medium
1029

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# show ip access-lists 160 Extended IP access list 160 10 permit tcp 10.0.0.0 0.255.255.255 any eq 22 20 permit tcp 172.16.0.0 0.15.255.255 any eq 22 30 permit tcp 192.168.0.0 0.0.255.255 any eq 22 40 deny ip any any What does this output indicate?

Medium
1030

Drag and drop the steps to verify and validate the operational state of Control Plane Policing (CoPP) into the correct order, from first to last.

Medium
1031

Which EIGRP packet type is used to confirm receipt of a reliable update?

Easy
1032

A network engineer runs the following command to troubleshoot a Route Summarization issue: R1# show ip ospf database summary 10.0.0.0 OSPF Router with ID (1.1.1.1) (Process ID 1) Summary Net Link States (Area 0) LS age: 100 Options: (No TOS-capability, DC) LS Type: Summary Links(Network) Link State ID: 10.0.0.0 (summary Network Number) Advertising Router: 2.2.2.2 LS Seq Number: 80000001 Checksum: 0x1234 Length: 28 Network Mask: /16 TOS: 0 Metric: 20 What does this output indicate?

Medium
1033

An engineer is configuring a GRE tunnel between two Cisco routers. The tunnel source is a physical interface, and the tunnel destination is the remote router's physical interface. After configuration, the tunnel interface is up, but no traffic passes through it. The engineer verifies that the physical interfaces are up and IP connectivity exists between the tunnel endpoints. What is the most likely cause?

Easy
1034

Which statement about IPv6 uRPF loose mode is true?

Medium
1035

Which statement correctly describes the behavior of IPv6 Unicast Reverse Path Forwarding (uRPF) in strict mode?

Medium
1036

A network engineer is implementing MPLS Layer 3 VPN on a Cisco IOS-XE router. The engineer needs to configure the PE router to exchange VPNv4 routes with other PE routers. Which address family must be configured under the BGP routing process to enable VPNv4 route exchange?

Hard
1037

A network engineer is troubleshooting an MPLS L3VPN where customer routes are not being advertised between PE routers. The engineer verifies that the VRFs are configured correctly and that MPLS forwarding is operational. Which MP-BGP configuration is required to exchange VPNv4 routes between PE routers?

Hard
1038

A network administrator is implementing MPLS Layer 3 VPNs. The customer edge (CE) router is connected to the provider edge (PE) router via a single link and runs OSPF with the PE. The administrator wants to prevent the customer's OSPF routes from being redistributed into the provider's IGP and to keep the customer's OSPF topology separate. Which OSPF process configuration on the PE router achieves this?

Hard
1039

An engineer configures OSPFv3 with multiple areas. On the ABR, routes from area 1 are not being advertised into area 0. Which is the most likely explanation?

Hard
1040

Which TWO configuration steps are required to implement IPv6 traffic filtering using a named ACL on a Cisco router? (Choose TWO.)

Medium
1041

Which TWO statements about the use of 'mpls ldp autoconfig' in an MPLS L3VPN environment are true? (Choose TWO.)

Hard
1042

A network engineer runs the following command on Router CE1: CE1# show ip route vrf CUSTOMER_B 10.20.20.0 24 Routing Table: CUSTOMER_B Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2 i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route Gateway of last resort is not set 10.0.0.0/24 is subnetted, 1 subnets B 10.20.20.0 [20/0] via 10.1.1.2, 00:02:34 Based on this output, what is the problem?

Medium
1043

A network security engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against denial-of-service attacks. The engineer wants to classify and police traffic destined to the route processor. Which two types of traffic should be considered for policing? (Choose two.)

Medium
1044

An engineer configures DMVPN Phase 2 with spoke-to-spoke tunnels. Spokes can ping each other's physical interfaces, but cannot establish a direct tunnel. NHRP registration is successful. Which is the most likely explanation?

Hard
1045

An engineer configures CoPP on a router that is a route reflector for iBGP. The policy includes a class-map matching BGP traffic and polices it to 500 pps. After deployment, some iBGP prefixes are missing from the route reflector's table, but the BGP sessions are up. Which is the most likely explanation?

Hard
1046

A network engineer runs the following command to verify MPLS LDP route filtering: R1# show mpls ldp bindings 192.168.10.0 255.255.255.0 lib entry: 192.168.10.0/24, rev 6 local binding: label: 21 remote binding: lsr: 2.2.2.2:0, label: 22 remote binding: lsr: 3.3.3.3:0, label: 23 What does this output indicate?

Medium
1047

snmp-server community MyCommunity RO 10\naccess-list 10 permit 192.168.1.0 0.0.0.255 What is the effect of this configuration?

Medium
1048

A network engineer runs the following command on Router R2: R2# show ip route 192.168.10.0 Routing entry for 192.168.10.0/24 Known via "ospf 1", distance 110, metric 20 Redistributing via ospf 1 Last update from 10.0.0.1 on GigabitEthernet0/1, 00:00:10 ago Routing Descriptor Blocks: * 10.0.0.1, from 10.0.0.1, 00:00:10 ago, via GigabitEthernet0/1 Route metric is 20, traffic share count is 1 Based on this output, what is the most likely origin of this route?

Medium
1049

A network engineer is deploying a GET VPN solution across an MPLS L3VPN service provider network. The design requires that all group members use identical encryption keys and that the key server remain the single point of rekey distribution. The engineer must choose the protocol the key server uses to push rekey messages to group members. Which protocol should be configured for this purpose?

Medium
1050

A network engineer runs the following command on Router R1: R1# show ipv6 dhcp guard policy Interface Policy Role State Gi0/0/0 DHCP_GUARD server ACTIVE Gi0/0/1 DHCP_GUARD client ACTIVE Gi0/0/2 (default) client ACTIVE Based on this output, which statement is correct?

Medium
1051

A network engineer runs the following command to verify NAT translations: R1# show ip nat translations verbose Pro Inside global Inside local Outside local Outside global --- 10.2.2.2 10.1.1.1 192.168.1.1 192.168.1.1 create 00:00:15, use 00:00:05, flags: extended, timing-out What does the 'extended' flag indicate?

Medium
1052

Consider the following partial configuration on a Cisco IOS-XE router: ``` router eigrp 100 network 10.0.0.0 distance eigrp 90 170 ``` What is the effect of the `distance eigrp 90 170` command?

Medium
1053

A network engineer runs the following command to troubleshoot a Network Logging and Syslog issue: R1# debug ip ospf adj Output: OSPF: 2 Way Communication to 10.0.0.2 on GigabitEthernet0/0, state 2WAY OSPF: Send hello to 224.0.0.5 on GigabitEthernet0/0 OSPF: Rcv DBD from 10.0.0.2 on GigabitEthernet0/0 seq 0x1E opt 0x52 flag 0x7 len 32 OSPF: NBR negotiation done. We are the SLAVE OSPF: Exchange done with 10.0.0.2 on GigabitEthernet0/0 OSPF: Build router LSA for area 0, router ID 10.0.0.1 What does this output indicate?

Medium
1054

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# show ip sla application IP Service Level Agreements Version: 2.0 IP SLAs Responder: Disabled IP SLAs Low Memory: Disabled IP SLAs ICMP Echo: Enabled IP SLAs ICMP Jitter: Enabled IP SLAs HTTP: Disabled IP SLAs FTP: Disabled IP SLAs UDP Jitter: Enabled IP SLAs TCP Connect: Enabled IP SLAs DNS: Disabled IP SLAs DHCP: Disabled IP SLAs DLSw: Disabled IP SLAs VoIP: Disabled IP SLAs Metro Ethernet: Disabled IP SLAs Video: Disabled IP SLAs LSP: Disabled IP SLAs LSP Group: Disabled IP SLAs VPLS: Disabled IP SLAs MPLS: Disabled IP SLAs MPLS Group: Disabled IP SLAs LDP: Disabled IP SLAs LDP Group: Disabled IP SLAs BFD: Disabled What does this output indicate?

Easy
1055

A network engineer is troubleshooting a DHCPv6 prefix delegation issue on router R1 and runs the following command: R1# debug ipv6 dhcp detail Output: IPv6 DHCP: Received SOLICIT message from FE80::21A:2BFF:FE3C:4D01 on GigabitEthernet0/0 IPv6 DHCP: Using interface pool DHCP_POOL IPv6 DHCP: Sending ADVERTISE message to FE80::21A:2BFF:FE3C:4D01 IPv6 DHCP: Received REQUEST message from FE80::21A:2BFF:FE3C:4D01 IPv6 DHCP: Client requests prefix 2001:DB8:1::/48 IPv6 DHCP: Prefix 2001:DB8:1::/48 not available in pool DHCP_POOL IPv6 DHCP: Sending REPLY message with Status Code NoPrefixAvail What does this output indicate?

Hard
1056

A network engineer runs the following command to verify MPLS LDP label bindings: R1# show mpls ldp bindings 192.168.1.0 255.255.255.0 Output: lib entry: 192.168.1.0/24, rev 8 local binding: label: 101 remote binding: lsr: 10.0.0.2:0, label: 201 remote binding: lsr: 10.0.0.3:0, label: 301 What does this output indicate?

Medium
1057

A network engineer is implementing policy-based routing (PBR) on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (LAN) and GigabitEthernet0/1 (WAN). A route-map named PBR-MAP is applied to GigabitEthernet0/0 with the command `ip policy route-map PBR-MAP`. The route-map contains a match statement for access-list 101, which permits traffic from 10.1.1.0/24 to any destination. The set statement is `set ip next-hop 192.168.2.1`. However, traffic from 10.1.1.0/24 is still being routed according to the routing table instead of being forwarded to 192.168.2.1. Which action should the engineer take to ensure PBR is applied?

Medium
1058

An engineer configures OSPFv2 on two routers with a direct Ethernet link. The routers are stuck in the EXSTART state. Which is the most likely explanation?

Hard
1059

Which TWO statements about Control Plane Policing (CoPP) are true? (Choose TWO.)

Medium
1060

What is the default maximum number of paths that BGP can install in the routing table using the 'maximum-paths' command in Cisco IOS?

Hard
1061

A network engineer runs the following command on Router R4: R4# show logging | include %BGP-3-NOTIFICATION *Mar 1 00:01:05.123: %BGP-3-NOTIFICATION: sent to neighbor 10.0.0.2 4/0 (Hold Timer Expired) 0 bytes *Mar 1 00:02:10.456: %BGP-3-NOTIFICATION: received from neighbor 10.0.0.2 4/0 (Hold Timer Expired) 0 bytes *Mar 1 00:03:15.789: %BGP-3-NOTIFICATION: sent to neighbor 10.0.0.2 4/0 (Hold Timer Expired) 0 bytes Based on this output, what is the most likely problem?

Medium
1062

A network engineer is troubleshooting an IPsec site-to-site VPN where the tunnel is not coming up. The engineer runs 'show crypto isakmp sa' and sees no active IKE SAs. The peer IP address is correctly configured. What should the engineer check first?

Medium
1063

Which THREE symptoms indicate a misconfigured RSPAN session on a Cisco switch? (Choose THREE.)

Hard
1064

A network engineer is troubleshooting a flapping OSPFv2 adjacency between two Cisco IOS-XE routers on a broadcast segment. The log shows repeated %OSPF-5-ADJCHG messages with reason 'Dead timer expired'. The engineer confirms that both routers are in Area 0, have identical hello/dead intervals, and are not configured with authentication. Which action most likely resolves the issue?

Medium
1065

Drag and drop the steps to troubleshoot an MPLS L3VPN adjacency or connectivity failure into the correct order, from first to last.

Hard
1066

A network engineer is troubleshooting an IPv6 connectivity problem across an IPv4 MPLS network using 6PE. The 6PE routers have MP-BGP sessions to exchange IPv6 prefixes, and the tunnel between them is up. However, a customer edge router behind one 6PE router cannot reach an IPv6 prefix behind the other 6PE router. The engineer checks the 6PE router's BGP table and sees the prefix, but the routing table shows the next-hop as unreachable. What is the most likely cause?

Hard
1067

In ERSPAN, what is the default encapsulation type used for transporting mirrored packets across an IP network?

Easy
1068

A network administrator is troubleshooting an OSPFv3 network. Routers R1 and R2 are directly connected on a point-to-point link. R1 is configured with OSPFv3 area 0, and R2 is configured with OSPFv3 area 1. The administrator notices that no OSPFv3 adjacency forms between them. What is the most likely cause?

Hard
1069

A network administrator is troubleshooting an EIGRP named mode configuration on a Cisco IOS XE router. The router is not forming an adjacency with a neighbor. The administrator verifies that the AS number is 100, the K-values are default, and authentication is not configured. Which command should be used to verify the EIGRP hello and hold timers on the interface?

Hard
1070

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-IN Class-map: CoPP-SNMP (match-all) 0 packets, 0 bytes 5 minute offered rate 0000 bps, drop rate 0000 bps Match: access-group 130 police: cir 32000 bps, bc 6000 bytes, be 6000 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop R1# show access-lists 130 Extended IP access list 130 10 permit udp any any eq snmp 20 permit udp any any eq snmptrap Based on this output, what is the most likely reason that no packets are matching the CoPP-SNMP class?

Hard
1071

A network engineer runs the following command to troubleshoot a VRF-Lite OSPF adjacency issue: R1# debug ip ospf adj vrf CUSTOMER_C Output: OSPF: 2 Way state received from 10.1.1.2 on interface GigabitEthernet0/1, address 10.1.1.2 OSPF: Neighbor 10.1.1.2 is eligible for DR election on interface GigabitEthernet0/1 OSPF: DR election: 10.1.1.1 (pri 1) is DR, 10.1.1.2 (pri 1) is BDR OSPF: Build router LSA for area 0, router ID 1.1.1.1, seq 0x80000001 OSPF: Neighbor 10.1.1.2 is FULL, state changed from LOADING to FULL What does this output indicate?

Hard
1072

In Policy-Based Routing (PBR), what is the default action for packets that do not match any route-map sequence?

Easy
1073

A network engineer is configuring a Cisco IOS router to authenticate management access using TACACS+. The TACACS+ server is reachable at 10.1.1.100. The engineer wants to ensure that if the TACACS+ server becomes unavailable, the router will fall back to using the local username database for authentication. Which command sequence correctly configures this fallback?

Medium
1074

A network engineer is configuring a Cisco IOS XE router to act as a DHCP server for a subnet. The router must assign IP addresses from the 192.168.100.0/24 pool, but the first 10 addresses and the last address in the range must be excluded from dynamic assignment. Which command accomplishes this requirement?

Easy
1075

A router is configured with PBR using a route-map that sets the next-hop to 10.0.0.2 for traffic from subnet 192.168.1.0/24. The route-map is applied inbound on interface GigabitEthernet0/0. The engineer also configures 'ip policy route-map' on the same interface. The engineer notices that PBR is working for TCP traffic but not for UDP traffic from the same subnet. What is the most likely cause?

Hard
1076

A network uses PBR to route traffic from a specific VLAN (10.10.10.0/24) through a firewall (next-hop 192.168.1.1). After a firewall policy change, traffic from this VLAN is being dropped. Router R1 shows: 'show ip policy' shows PBR applied, 'debug ip policy' shows traffic being forwarded to 192.168.1.1, but 'debug ip packet' on R1 shows packets being sent to 192.168.1.1 and no response. Router R2 (firewall) shows: 'show ip route 10.10.10.0' returns a route via 192.168.2.1, but 'show access-lists' on the firewall shows an ACL that denies traffic from 10.10.10.0/24. What is the root cause?

Hard
1077

A network uses PBR to load-balance traffic from two subnets (10.1.1.0/24 and 10.2.2.0/24) across two ISPs (next-hops 100.64.1.1 and 100.64.2.2). After a routing change, traffic from 10.1.1.0/24 is being sent to both ISPs intermittently. Router R1 shows: 'show route-map' shows the route-map with two match clauses, 'debug ip policy' shows traffic from 10.1.1.0/24 being sent to both next-hops. What is the root cause?

Hard
1078

An engineer configures an EEM applet to react to BGP prefix changes using the event syslog pattern 'BGP-5-ADJCHANGE'. The applet sends a custom SNMP trap. The BGP session between two routers is established, but when a route is withdrawn due to next-hop-self requirement for iBGP, the EEM applet does not trigger. Which is the most likely explanation?

Hard
1079

A network engineer runs the following command to troubleshoot an MPLS L3VPN issue: R1# show bgp neighbors 10.0.0.2 received-routes Output: BGP table version is 10, local router ID is 10.0.0.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.3.3.0/24 10.0.0.2 0 100 0 65000 i *> 10.4.4.0/24 10.0.0.2 0 100 0 65000 i Total number of prefixes 2 What does this output indicate?

Medium
1080

A network engineer runs the following command on router R3: R3# show monitor session 5 Session 5 --------- Type : ERSPAN Destination Session Status : Admin Enabled Source IP : 10.0.0.2 Destination Ports : Gi0/1 Encapsulation : Native Ingress : Disabled ERSPAN ID : 100 Based on this output, which statement is correct?

Medium
1081

A network engineer runs the following command on Router R1: R1# show bfd neighbors detail IPv4 Sessions NeighborAddr LD/RD Int State Holdown(mult) Intf 10.1.1.2 1/3 Gi0/0 Down 0(0) Gi0/0 Session state is DOWN OurAddr: 10.1.1.1 Handle: 1 Local Diag: 1, Demand mode: 0, Poll bit: 0 MinTxInt: 1000000, MinRxInt: 1000000, Multiplier: 3 Received MinRxInt: 1000000, Received Multiplier: 3 Holddown (hits): 0(0) Rx Count: 0, Tx Count: 50 Based on this output, what is the most likely cause of the BFD session being down?

Hard
1082

A network engineer runs the following command on switch SW1: SW1# show monitor session 1 Session 1 --------- Type : Local Session Source Ports : Both : Gi0/1, Gi0/2 Destination Ports : Gi0/3 Encapsulation : Native Ingress : Disabled Based on this output, which statement is correct?

Medium
1083

Which of the following is true regarding the placement of an IPv4 ACL to filter traffic between two internal subnets?

Easy
1084

Given the following partial configuration on router R1: router eigrp 100 network 10.0.0.0 0.255.255.255 network 192.168.1.0 0.0.0.255 ! interface GigabitEthernet0/0 ip address 10.1.1.1 255.255.255.0 ! interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ! interface GigabitEthernet0/2 ip address 172.16.1.1 255.255.255.0 What is the effect of this configuration?

Medium
1085

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The engineer wants to limit ICMP echo requests destined to the router to 100 packets per second, while allowing other traffic. Which configuration snippet correctly applies CoPP for this purpose?

Medium
1086

An engineer configures mutual redistribution between OSPF and EIGRP. After a few minutes, routing loops occur. The engineer did not use route tagging. Which is the most likely explanation?

Hard
1087

A network engineer runs the following command on Router R1: R1# show flow monitor FLOW-MONITOR-1 cache format table Cache type: Normal Cache size: 1000 Current entries: 1000 High Watermark: 1000 Flows added: 50000 Flows aged: 49000 - Active timeout (1800 secs) 40000 - Inactive timeout (15 secs) 8000 - Event aged 0 - Watermark aged 1000 - Emergency aged 0 Based on this output, what is the most likely issue?

Hard
1088

A network engineer runs the following command to troubleshoot SNMP traps: R1# show snmp host Host: 10.1.1.2 Port: 162 Timeout: 30 Retries: 3 Community: trap-public Version: 2c Filter: none Host: 10.1.1.3 Port: 162 Timeout: 30 Retries: 3 Community: trap-public Version: 2c Filter: none What does this output indicate?

Medium
1089

A network administrator is configuring a Cisco IOS XE router for MPLS Traffic Engineering (TE). The administrator wants to ensure that the router can signal an MPLS TE tunnel using RSVP. Which protocol must be enabled on the interfaces along the path to reserve bandwidth and distribute labels?

Easy
1090

A network engineer is deploying GET VPN across an MPLS L3VPN service provider network. The key server is reachable by all group members, and the engineer wants to avoid rekeying storms when many group members reboot simultaneously after a power outage. Which mechanism should the engineer configure on the key server to spread rekey retransmissions over a period of time?

Medium
1091

An engineer configures PBR with a route-map that sets the next-hop to 10.0.0.2 for traffic matching ACL 100. The route-map is applied inbound on interface GigabitEthernet0/1. Traffic from a host on that interface is forwarded via 10.0.0.2, but the engineer notices that packets with destination IP 10.0.0.2 itself are also being redirected, causing a loop. Why does this happen?

Hard
1092

According to RFC 5424, which syslog severity level corresponds to 'Critical' conditions?

Easy
1093

A network administrator is configuring a Cisco IOS router to authenticate users via TACACS+ using a TACACS+ server at 10.1.1.50. The administrator wants to ensure that if the TACACS+ server is unreachable, the router will fall back to using the local username database. Which command set achieves this?

Hard
1094

Which statement correctly describes the default behavior of the 'flow monitor' in Flexible NetFlow regarding the collection of BGP next-hop information?

Hard
1095

A network engineer runs the following command to verify IPv6 binding table: R1# show ipv6 neighbors binding IPv6 Address Age Link-layer Addr State Interface VLAN Policy 2001:db8::1 10 0011.2233.4455 REACH Fa0/1 10 TRUSTED 2001:db8::2 5 00aa.bbcc.ddee STALE Fa0/0 10 INSPECT 2001:db8::3 0 1111.2222.3333 INCOMP Fa0/0 10 - What does this output indicate?

Medium
1096

A network engineer runs the following command to debug MPLS LDP session establishment: R1# debug mpls ldp session Output: *Mar 1 00:01:23.456: LDP: Session with 10.0.0.2:0 (0x1234) is UP *Mar 1 00:01:24.567: LDP: Session with 10.0.0.2:0 (0x1234) is DOWN *Mar 1 00:01:25.678: LDP: Session with 10.0.0.2:0 (0x1234) is UP *Mar 1 00:01:26.789: LDP: Session with 10.0.0.2:0 (0x1234) is DOWN What does this output indicate?

Hard
1097

An engineer enables uRPF (unicast Reverse Path Forwarding) in strict mode on an interface connected to a DMVPN spoke. The spoke has multiple tunnels and receives traffic from the hub with a source IP that is not the best reverse path. Unexpectedly, the spoke drops all traffic from the hub, even though the hub is reachable via the tunnel. Which is the most likely explanation?

Hard
1098

A network engineer runs the following command to troubleshoot a Control Plane Policing (CoPP) issue: R1# show bgp neighbors 10.1.1.2 advertised-routes BGP table version is 10, local router ID is 10.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.2.2.0/24 0.0.0.0 0 32768 i Total number of prefixes 1 What does this output indicate?

Medium
1099

A network engineer is configuring DMVPN Phase 3 on a hub router. The hub has a public IP address and is reachable. Spokes are behind NAT devices and have dynamic public IP addresses. Which technology allows spokes to communicate directly without routing traffic through the hub?

Medium
1100

What is the default BFD multiplier (detection time multiplier) on Cisco IOS-XE?

Easy
1101

A network engineer runs the following command on Router R1: R1# show ipv6 snooping policy Interface Policy Role State Gi0/0/0 GUARD_POLICY device-guard ACTIVE Gi0/0/1 GUARD_POLICY device-guard ACTIVE Gi0/0/2 (default) host ACTIVE Based on this output, which statement is correct?

Medium
1102

Drag and drop the steps to configure a DHCP pool and relay agent on a Cisco router into the correct order, from first to last.

Medium
1103

What is the default maximum number of labels that can be imposed in the MPLS label stack on a Cisco IOS-XE router?

Hard
1104

What is the default frequency (in seconds) for an IP SLA operation when no frequency is explicitly configured?

Medium
1105

A network engineer configures SNMPv3 with authentication and privacy on a router. The NMS polls the router via the management interface. The engineer then adds a loopback interface and configures the router to send SNMP traps sourced from the loopback IP. The NMS stops receiving traps. Which is the most likely explanation?

Hard
1106

A network engineer is troubleshooting a Cisco IOS XE router running OSPFv2. The router is an ABR between Area 0 and Area 1. Area 1 is configured as a Not-So-Stubby Area (NSSA). The engineer notices that a Type-7 LSA originated by an ASBR in Area 1 is not being translated into a Type-5 LSA by the ABR. Which condition would prevent the ABR from performing Type-7 to Type-5 translation?

Hard
1107

Router R9 is configured with SNMP and NetFlow. The NMS uses SNMP to poll NetFlow statistics. The configuration includes: snmp-server community public RO, snmp-server enable traps netflow. However, the NMS cannot poll NetFlow MIB objects. The router's show snmp mib shows that the NetFlow MIB is not loaded. What is the root cause?

Hard
1108

In the context of NAT and PAT, what is the purpose of the ip nat translation timeout command?

Easy
1109

A network engineer runs the following command to verify redistribution with route-maps: R1# show ip route 10.10.10.0 255.255.255.0 Routing entry for 10.10.10.0/24 Known via "eigrp 100", distance 170, metric 2560002816 Tag 100, type internal Last update from 10.1.1.2 on GigabitEthernet0/0, 00:00:45 ago Routing Descriptor Blocks: * 10.1.1.2, from 10.1.1.2, 00:00:45 ago, via GigabitEthernet0/0 Route metric is 2560002816, traffic share count is 1 Total delay is 2000 microseconds, minimum bandwidth is 100000 Kbit Reliability 255/255, minimum MTU 1500 bytes Loading 1/255, Hops 1 What does the 'Tag 100' indicate?

Medium
1110

Which of the following best describes the behavior of BGP when an 'aggregate-address' command is used without the 'summary-only' keyword?

Medium
1111

A network engineer is configuring OSPFv3 on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 in Area 0 and GigabitEthernet0/1 in Area 1. The engineer wants to ensure that the router acts as an ABR and that inter-area routes are summarized. Which command must be configured under the OSPFv3 router configuration mode to enable ABR functionality?

Medium
1112

A network engineer runs the following command on Router R1: R1# show ip nat translations Pro Inside global Inside local Outside local Outside global --- 192.0.2.10 10.0.0.10 203.0.113.5 203.0.113.5 --- 192.0.2.11 10.0.0.11 203.0.113.5 203.0.113.5 R1# show ip nat statistics Total active translations: 2 (0 static, 2 dynamic; 0 extended) Outside interfaces: GigabitEthernet0/1 Inside interfaces: GigabitEthernet0/0 Hits: 20 Misses: 0 CEF Translated packets: 20, CEF Punted packets: 0 Expired translations: 0 Dynamic mappings: -- Inside Source [Id] ip nat pool POOL1 192.0.2.10 192.0.2.20 netmask 255.255.255.240 refcount 2 map-id 1 [Id] ip nat inside source list ACL1 pool POOL1 refcount 2 Based on this output, which statement is correct?

Medium
1113

A large enterprise network is experiencing intermittent reachability to a subnet 10.1.1.0/24 from the rest of the network. Router R1 has the following relevant configuration: router eigrp 100 redistribute ospf 1 metric 10000 100 255 1 1500 ! router ospf 1 redistribute eigrp 100 subnets summary-address 10.0.0.0 255.255.0.0 ! interface GigabitEthernet0/0 ip summary-address eigrp 100 10.0.0.0 255.255.0.0 5 Router R2 shows: R2# show ip route 10.1.1.0 Routing entry for 10.0.0.0/16, supernet Known via "eigrp 100", distance 90, metric 128256 Redistributing via eigrp 100 Last update from 10.10.10.1 on GigabitEthernet0/1 What is the root cause?

Hard
1114

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# show access-lists 120 Extended IP access list 120 10 permit tcp 192.168.1.0 0.0.0.255 any eq 80 20 permit tcp 192.168.2.0 0.0.0.255 any eq 443 30 deny ip any any log What does this output indicate?

Easy
1115

A network engineer is configuring a Cisco IOS XE router as a LISP ITR. The router must encapsulate traffic from local EIDs to remote RLOCs. Which command is required to enable LISP functionality and allow the router to act as an ITR?

Hard
1116

A network engineer runs the following command on Router R1: R1# show ip vrf interfaces Interface VRF IP Address Protocol GigabitEthernet0/0 BLUE 10.1.1.1 up GigabitEthernet0/1 BLUE 10.1.2.1 up GigabitEthernet0/2 RED 192.168.1.1 up Loopback0 BLUE 10.0.0.1 up Loopback1 RED 192.168.0.1 up Based on this output, which statement is correct?

Medium
1117

Drag and drop the steps to troubleshoot a BFD adjacency or connectivity failure into the correct order, from first to last.

Hard
1118

A network engineer is deploying GET VPN with Cisco IOS routers to provide any-to-any encrypted communication over a private MPLS WAN. The design requires that a router joining the group automatically receives the current group security policy from the group controller without any manual pre-shared key configuration on the member. Which protocol should the engineer configure to dynamically distribute the group encryption keys from the key server to the group members?

Medium
1119

In IPv6 First Hop Security, what is the purpose of the 'device-role' command in a DHCP guard policy?

Medium
1120

A network engineer runs the following command to troubleshoot an EEM issue: R1# show event manager environment all No. Variable Name Value 1 _exit_status 1 2 _event_type syslog 3 _syslog_msg %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.2 on GigabitEthernet0/0 from LOADING to FULL, Loading Done 4 _syslog_severity 5 5 _syslog_facility OSPF 6 _syslog_mnemonic ADJCHG What does this output indicate?

Hard
1121

Which EIGRP packet type is used to confirm receipt of a route update during reliable transport?

Medium
1122

Which TWO statements correctly describe the use of IKEv2 for IPsec site-to-site VPNs? (Choose TWO.)

Hard
1123

A network engineer runs the following command to troubleshoot OSPF route filtering: R1# show ip ospf database router 2.2.2.2 OSPF Router with ID (1.1.1.1) (Process ID 1) Router Link States (Area 0) LS age: 300 Options: (No TOS-capability, DC) LS Type: Router Links Link State ID: 2.2.2.2 Advertising Router: 2.2.2.2 LS Seq Number: 80000004 Checksum: 0x1234 Length: 48 Number of Links: 2 Link connected to: a Stub Network (Link ID) Network/subnet number: 10.1.1.0 (Link Data) Network Mask: 255.255.255.0 Number of TOS metrics: 0 TOS 0 Metrics: 10 Link connected to: a Transit Network (Link ID) Designated Router address: 10.1.1.2 (Link Data) Router Interface address: 10.1.1.1 Number of TOS metrics: 0 TOS 0 Metrics: 10 What does this output indicate?

Medium
1124

A network administrator is deploying a GET VPN using Cisco IOS routers. The key server is configured with a cooperative key server (COOP) for redundancy. The administrator notices that some group members are not registering with the primary key server. Which protocol and port must be allowed through the firewall for the group members to register with the key server?

Hard
1125

A network engineer is configuring MPLS Traffic Engineering (TE) with RSVP-TE on a Cisco IOS XE router. The engineer wants to establish a TE tunnel from Router A to Router D. The path must be explicitly defined to go through Router B and then Router C. The engineer has configured the tunnel interface with the destination and an explicit path. However, the tunnel is not coming up. Which command is required to enable RSVP-TE on the core interfaces of Router A, B, C, and D?

Hard
1126

Router R10 is configured with SNMP and EEM. An EEM applet is configured to send an SNMP trap when a specific syslog message is generated. The applet uses the 'action snmp-trap' command. However, the NMS receives no trap. The syslog message is generated and logged. The router's show snmp statistics shows TrapsSent: 0. What is the root cause?

Hard
1127

What is the default administrative distance for OSPF routes on a Cisco IOS-XE router?

Easy
1128

A network engineer is configuring DHCPv6 on a Cisco IOS-XE router. The router must provide IPv6 addresses and other configuration parameters to clients on the LAN. The engineer wants the router to assign addresses using stateless address autoconfiguration (SLAAC) but also provide DNS server information via DHCPv6. Which command set correctly configures the router's LAN interface to achieve this?

Medium
1129

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast summary BGP router identifier 192.168.0.1, local AS number 65001 BGP table version is 10, main routing table version 10 Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 192.168.1.2 4 65002 1002 1000 10 0 0 00:15:30 5 192.168.2.2 4 65003 1005 1003 10 0 0 00:14:20 3 10.10.10.2 4 65004 0 0 0 0 0 00:00:05 Idle Based on this output, what is the problem with neighbor 10.10.10.2?

Medium
1130

An engineer configures iBGP between two routers in the same AS. The BGP table shows the prefix, but it is not installed in the routing table. The IGP does not carry the prefix. Which is the most likely explanation?

Hard
1131

Which statement correctly describes the default behavior of Dead Peer Detection (DPD) in Cisco IOS for IPsec site-to-site VPN?

Medium
1132

A network engineer is troubleshooting a router that is not executing an EEM applet that is supposed to run when a specific interface goes down. The applet is configured with event syslog pattern 'LINK-3-UPDOWN' and matches the interface with a regex. The engineer checks the syslog and sees the message 'LINK-3-UPDOWN: GigabitEthernet0/1, changed state to down' but the applet does not run. What is the most likely cause?

Hard
1133

Drag and drop the steps to apply and verify an extended IPv4 ACL on a router interface into the correct order, from first to last.

Medium
1134

A network engineer is troubleshooting a Cisco IOS XE router that is configured for IPv6 First Hop Security on a user VLAN. Hosts report intermittent connectivity, and the engineer suspects that IPv6 Router Advertisement (RA) messages from an unauthorized device are being accepted. Which feature should be enabled to ensure that only RAs from the legitimate router are processed by hosts?

Hard
1135

Drag and drop the steps to verify and validate the operational state of an IPv6 tunneling technique into the correct order, from first to last.

Medium
1136

What is the default value of the 'reachable time' in IPv6 Neighbor Discovery (ND) on Cisco IOS-XE?

Hard
1137

Drag and drop the steps to configure Flexible NetFlow with a custom flow record into the correct order, from first to last.

Medium
1138

A network administrator is configuring OSPF on a Cisco router. The router is connected to two different OSPF areas: Area 0 and Area 1. The administrator wants to summarize routes from Area 1 into Area 0. Which command should be used on the Area Border Router (ABR) to accomplish this?

Hard
1139

An engineer is troubleshooting a router that is not sending syslog messages to the syslog server at 192.168.1.10. The configuration includes 'logging host 192.168.1.10' and 'logging trap informational'. The engineer can ping the syslog server from the router. 'show logging' shows that the logging buffer is filling with messages. What is the most likely cause?

Medium
1140

An engineer configures SPAN on a Cisco switch to monitor traffic from a VLAN, but the VLAN includes a voice VLAN. The mirrored traffic shows only data traffic, not voice. What is the most likely explanation?

Hard
1141

A network administrator is deploying IPv6 First Hop Security (FHS) on a Cisco Catalyst switch to mitigate rogue Router Advertisement (RA) attacks. The switch is running Cisco IOS Software and is configured with the command ipv6 nd raguard policy POLICY1. Which additional step is required to activate RA guard on an interface?

Hard
1142

A network engineer runs the following command to troubleshoot BFD with OSPF: R1# show ip ospf interface gigabitethernet 0/0 GigabitEthernet0/0 is up, line protocol is up Internet Address 10.1.1.1/24, Area 0 Process ID 1, Router ID 1.1.1.1, Network Type BROADCAST, Cost: 1 Transmit Delay is 1 sec, State DR, Priority 1 Designated Router (ID) 1.1.1.1, Interface address 10.1.1.1 Backup Designated router (ID) 2.2.2.2, Interface address 10.1.1.2 Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5 oob-resync timeout 40 Hello due in 00:00:03 Supports Link-local Signaling (LLS) Cisco NSF helper support enabled IETF NSF helper support enabled Index 1/1/1, flood queue length 0 Next 0x0(0)/0x0(0)/0x0(0) Last flood scan length is 1, maximum is 25 Last flood scan time is 0 msec, maximum is 0 msec Neighbor Count is 1, Adjacent neighbor count is 1 Adjacent with neighbor 2.2.2.2 (Backup Designated Router) Suppress hello for 0 neighbor(s) BFD enabled, BFD interval 100 msec, BFD multiplier 3 What does this output indicate?

Medium
1143

A network technician is configuring SSH access on a Cisco IOS router. The technician wants to ensure that only SSH version 2 is allowed and that the RSA key pair is generated with a modulus of 2048 bits. Which commands are required?

Easy
1144

A network engineer is troubleshooting a PBR (Policy-Based Routing) issue on router R5. The engineer configured a route-map to set the next-hop for traffic from a specific source subnet. The route-map is applied to the incoming interface, but traffic from the source subnet is still being forwarded using the regular routing table. The engineer verifies that the ACL matches the traffic correctly. What is the most likely cause?

Medium
1145

A network administrator is configuring DMVPN Phase 3 with a hub-and-spoke topology. The administrator wants to enable spoke-to-spoke communication directly without traversing the hub. Which command must be configured on the hub router to allow spoke-to-spoke tunnels?

Hard
1146

A network engineer runs the following command to verify DHCPv4 server conflict detection on router R1: R1# show ip dhcp conflict Output: IP address Detection method Detection time VRF 192.168.1.50 Ping Mar 01 2025 10:00 AM default 192.168.1.75 Gratuitous ARP Mar 01 2025 11:00 AM default What does this output indicate?

Easy
1147

An engineer configures mutual redistribution between OSPF and EIGRP. After a few minutes, the network becomes unstable with routing loops. The engineer checks the routing tables and notices that the same prefix is being learned from both protocols with different administrative distances. Which is the most likely explanation?

Hard
1148

In MPLS, what is the default behavior of a Cisco IOS-XE router regarding the 'auto-summary' command for BGP routes?

Medium
1149

A network engineer runs the following command to troubleshoot a VRF-Lite issue: R1# show ip route vrf CUSTOMER_A summary Output: IP routing table name: CUSTOMER_A (0x00000001) IP routing table maximum-paths: 32 Route Source Networks Subnets Replicates Overhead Memory (bytes) connected 2 0 0 0 576 static 1 0 0 0 288 eigrp 100 3 0 0 0 864 Internal 3 0 0 0 864 External 0 0 0 0 0 ospf 200 0 0 0 0 0 Intra-area 0 0 0 0 0 Inter-area 0 0 0 0 0 External-1 0 0 0 0 0 External-2 0 0 0 0 0 NSSA-1 0 0 0 0 0 NSSA-2 0 0 0 0 0 bgp 65000 0 0 0 0 0 Internal 0 0 0 0 0 External 0 0 0 0 0 Total 6 0 0 0 1728 What does this output indicate?

Medium
1150

Which TWO statements about the 'match ip address' command within a route-map are true? (Choose TWO.)

Medium
1151

A network engineer is configuring a Cisco IOS XE router to act as a DHCP relay agent. The router receives DHCP discover messages on interface GigabitEthernet0/1 and must forward them to a DHCP server at 10.1.1.100. The engineer configures the command 'ip helper-address 10.1.1.100' on GigabitEthernet0/1. However, the DHCP server is not receiving the requests. Which additional configuration is required to ensure that DHCP relay works correctly?

Hard
1152

A network engineer is deploying a GET VPN solution across an MPLS VPN WAN. The group members must encrypt traffic between any pair of sites without establishing point-to-point tunnels, and the key server must distribute a common encryption policy to all members. The engineer has configured the key server with a rekey policy but group members are not receiving rekeys. Which action must be taken on the key server to enable successful rekey transmission?

Medium
1153

A network engineer runs the following command to troubleshoot a Route Redistribution issue: R1# show ip ospf database external And sees the following output: OSPF Router with ID (1.1.1.1) (Process ID 1) Type-5 AS External Link States LS age: 360 Options: (No TOS-capability, DC) LS Type: AS External Link Link State ID: 192.168.10.0 (External Network Number ) Advertising Router: 2.2.2.2 LS Seq Number: 80000001 Checksum: 0x1234 Length: 36 Network Mask: /24 Metric Type: 2 (Larger than any link state path) TOS: 0 Metric: 20 Forward Address: 0.0.0.0 External Route Tag: 100 What does this output indicate?

Medium
1154

A network engineer is troubleshooting a VRF-Lite configuration where a router is using RIP as the routing protocol in VRF_BLUE. The engineer notices that RIP routes are not being learned from a neighbor router. The 'show ip rip database vrf VRF_BLUE' shows no entries. The 'show ip vrf interfaces VRF_BLUE' shows the correct interface. What is the most likely cause?

Medium
1155

An engineer configures Control Plane Policing (CoPP) on a router. After applying the policy, OSPF neighbors go down. The engineer checks the policy and sees that OSPF packets are not explicitly matched. Which is the most likely explanation?

Hard
1156

Examine this configuration: interface GigabitEthernet0/4 ipv6 address 2001:db8:2::1/64 ipv6 verify unicast source reachable-via any What is the effect of the 'ipv6 verify unicast source reachable-via any' command?

Medium
1157

Given this partial configuration on router R6: router bgp 65000 neighbor 192.168.1.1 remote-as 65001 address-family ipv4 network 172.16.0.0 mask 255.255.0.0 aggregate-address 172.16.0.0 255.255.0.0 What is missing if the administrator wants to ensure that only the aggregate route is advertised to neighbor 192.168.1.1?

Medium
1158

OSPF is configured on a multi-access link between R1 and R2. R1 has: interface GigabitEthernet0/0, ip ospf network point-to-point. R2 has default broadcast network type. R1 shows: show ip ospf neighbor includes R2 in FULL state, but R2 shows: show ip ospf neighbor includes R1 in INIT state. What is the root cause?

Hard
1159

A network uses route summarization to reduce routing table size. After enabling Flexible NetFlow, some routes that were previously summarized are now being advertised individually. Router R1 has: interface GigabitEthernet0/0 ip summary-address eigrp 100 10.0.0.0 255.0.0.0. The flow monitor is applied to the same interface. show ip route eigrp | include (10.0.0.0/8) shows the summary route, but also shows more specific routes like 10.1.0.0/16. What is the root cause?

Hard
1160

Examine the following partial configuration on router R1: flow record RECORD-1 match ipv4 source address match ipv4 destination address match ipv4 protocol collect counter bytes collect counter packets ! flow monitor MONITOR-1 record RECORD-1 cache timeout active 60 ! interface GigabitEthernet0/1 ip flow monitor MONITOR-1 input ! Which statement about this configuration is true?

Medium
1161

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# debug ip packet 100 detail IP packet debugging is on for access list 100 *Mar 1 00:12:34.567: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto UDP, flags 0x0, sport 12345, dport 80, access list 100: matched line 10 permit udp host 10.1.1.1 host 10.2.2.2 eq 80 *Mar 1 00:12:35.123: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto TCP, flags 0x2, sport 12346, dport 443, access list 100: matched line 20 deny tcp host 10.1.1.1 host 10.2.2.2 eq 443 *Mar 1 00:12:35.124: IP: s=10.1.1.1 (GigabitEthernet0/0), d=10.2.2.2, len 100, proto TCP, flags 0x10, sport 12346, dport 443, access list 100: matched line 20 deny tcp host 10.1.1.1 host 10.2.2.2 eq 443 What does this output indicate?

Medium
1162

A network engineer configures BGP on router R4: router bgp 65004 bgp router-id 4.4.4.4 neighbor 10.4.4.3 remote-as 65003 neighbor 10.4.4.3 password BGPsecret ! What is the effect of the password command?

Medium
1163

Which protocol should be used to dynamically distribute encryption keys for a GET VPN deployment?

Easy
1164

Drag and drop the steps to troubleshoot IPv6 over IPv4 tunnel adjacency or connectivity failures into the correct order, from first to last.

Hard
1165

Router R1 has the following configuration: ``` interface GigabitEthernet0/1 ip address 10.1.1.1 255.255.255.0 ip policy route-map PBR-OUT ! route-map PBR-OUT permit 10 match ip address 100 set ip next-hop 192.168.1.1 ! access-list 100 permit ip host 10.1.1.100 any ``` What is the effect of this configuration?

Medium
1166

A network administrator configures 'ipv6 dhcp guard' on a switch and sets the policy to 'allow only' for a specific DHCPv6 server. However, clients are still receiving DHCPv6 replies from a rogue server on the same VLAN. The engineer verifies that the rogue server's port is not trusted. What is the most likely reason the rogue server's advertisements are not being blocked?

Hard
1167

Which BGP attribute is used as the first tie-breaker when multiple paths are available for the same prefix, assuming default settings?

Medium
1168

A network engineer runs the following command on Router R1: R1# show ip route 10.1.1.0 Routing entry for 10.1.1.0/24 Known via "eigrp 100", distance 170, metric 30720 Redistributing via eigrp 100 Last update from 192.168.1.2 on GigabitEthernet0/0, 00:00:05 ago Routing Descriptor Blocks: * 192.168.1.2, from 192.168.1.2, 00:00:05 ago, via GigabitEthernet0/0 Route metric is 30720, traffic share count is 1 Based on this output, which statement is correct?

Medium
1169

Which TWO statements about RSPAN are true? (Choose TWO.)

Medium
1170

A network engineer is configuring a site-to-site DMVPN Phase 3 hub-and-spoke topology. The hub router is configured with tunnel mode gre multipoint. Spokes are unable to dynamically form tunnels with each other when the hub is reachable. Which additional configuration on the hub enables spoke-to-spoke direct tunnels in Phase 3?

Medium
1171

A network engineer is troubleshooting a router that is not responding to SNMP polls from the NMS at 10.1.1.100. The SNMP configuration includes 'snmp-server community public RO' and 'snmp-server community private RW'. The engineer can ping the router from the NMS. 'show snmp' shows SNMP is enabled. What is the most likely cause?

Medium
1172

Which TWO statements about SNMPv3 configuration on Cisco IOS XE are true? (Choose TWO.)

Hard
1173

A network administrator is troubleshooting an OSPFv3 network. Router R1 is configured with the following: ipv6 unicast-routing interface GigabitEthernet0/0 ipv6 address 2001:DB8:1::1/64 ipv6 ospf 1 area 0 ipv6 ospf network point-to-point ! router ospf 1 router-id 1.1.1.1 ! R1 is not forming an adjacency with R2, which is configured with: interface GigabitEthernet0/0 ipv6 address 2001:DB8:1::2/64 ipv6 ospf 1 area 0 ipv6 ospf network broadcast ! router ospf 1 router-id 2.2.2.2 What is the most likely reason for the adjacency failure?

Hard
1174

Review this configuration: route-map RMAP permit 10 match ipv6 address prefix-list PREFIX set interface null0 ! ipv6 prefix-list PREFIX seq 5 permit 2001:db8:5::/48 ! interface GigabitEthernet0/6 ipv6 verify unicast source reachable-via any allow-default What is the purpose of the 'allow-default' keyword?

Medium
1175

A network engineer runs the following command on Router R8: R8# show ip route 10.2.2.0 Routing entry for 10.2.2.0/24 Known via "eigrp 100", distance 90, metric 28160 Redistributing via eigrp 100 Last update from 192.168.2.1 on GigabitEthernet0/0, 00:00:05 ago Routing Descriptor Blocks: * 192.168.2.1, from 192.168.2.1, 00:00:05 ago, via GigabitEthernet0/0 Route metric is 28160, traffic share count is 1 R8 also has a static route to 10.2.2.0/24 with next-hop 192.168.3.1 configured with distance 95. Which route will be used?

Hard
1176

A network administrator is deploying a DMVPN Phase 3 hub-and-spoke topology using Cisco IOS routers. The hub router is configured with a multipoint GRE (mGRE) interface and NHRP. Spokes are configured with mGRE and NHRP as well. The administrator wants to ensure that spoke-to-spoke traffic flows directly without traversing the hub after initial registration. Which two statements about DMVPN Phase 3 operation are true? (Choose two.)

Hard
1177

Which TWO configuration steps are required to implement manual route summarization in OSPF on an ABR? (Choose TWO.)

Medium
1178

Examine this configuration: ``` router ospf 1 distance ospf intra-area 150 inter-area 160 external 170 ``` What is the effect of this command?

Medium
1179

A network administrator is configuring a site-to-site IPsec VPN between two Cisco IOS XE routers. The administrator wants to ensure that the VPN tunnel only encrypts traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet. Which configuration element defines the traffic to be encrypted?

Easy
1180

A network engineer is troubleshooting a DMVPN Phase 3 network. Spoke-to-spoke tunnels are not being established directly; traffic between spokes is going through the hub. The hub is configured with 'ip nhrp redirect' and spokes with 'ip nhrp shortcut'. Which additional configuration is required on the spokes to enable direct spoke-to-spoke communication?

Medium
1181

Review the following configuration: ipv6 access-list FILTER permit tcp 2001:db8:1::/48 any eq 80 permit tcp 2001:db8:1::/48 any eq 443 deny ipv6 any any interface GigabitEthernet0/3 ipv6 traffic-filter FILTER out What is the effect of this configuration?

Medium
1182

A network engineer is troubleshooting an IPsec site-to-site VPN that uses a GRE tunnel over IPsec. The GRE tunnel is up/up, but the routing protocol (EIGRP) running over the GRE tunnel is not forming an adjacency. The engineer checks the tunnel configuration and sees that the tunnel source and destination are correct. What is the most likely cause?

Medium
1183

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# show crypto ipsec sa detail interface: Tunnel0 Crypto map tag: CMAP, local addr 192.168.1.1 protected vrf: (none) local ident (addr/mask/prot/port): (192.168.1.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port): (192.168.2.0/255.255.255.0/0/0) current_peer 192.168.2.2 port 500 PERMIT, flags={origin_is_acl,} #pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0 #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0 #pkts compressed: 0, #pkts decompressed: 0 #pkts not compressed: 0, #pkts compr. failed: 0 #pkts not decompressed: 0, #pkts decompress failed: 0 #send errors 0, #recv errors 0 local crypto endpt.: 192.168.1.1, remote crypto endpt.: 192.168.2.2 path mtu 1500, ip mtu 1500, ip mtu idb Serial0/0/0 current outbound spi: 0x0(0) PFS (Y/N): N, DH group: none inbound esp sas: spi: 0x0(0) transform: esp-3des esp-sha-hmac , in use settings ={Tunnel, } conn id: 0, flow_id: 0, sibling_flags 80000000, crypto map: CMAP sa timing: remaining key lifetime (k/sec): (0/0) IV size: 8 bytes replay detection support: N outbound esp sas: spi: 0x0(0) transform: esp-3des esp-sha-hmac , in use settings ={Tunnel, } conn id: 0, flow_id: 0, sibling_flags 80000000, crypto map: CMAP sa timing: remaining key lifetime (k/sec): (0/0) IV size: 8 bytes replay detection support: N What does this output indicate?

Medium
1184

A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The tunnel is up, but traffic is not passing. The administrator runs show crypto ipsec sa and notices that the inbound and outbound ESP SAs are present, but the packet counters are not incrementing. The ACL used for the crypto map is permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255. Which action is most likely to resolve the issue?

Hard
1185

Consider the following partial configuration on a Cisco IOS-XE switch: monitor session 1 source interface GigabitEthernet1/0/1 both monitor session 1 destination interface GigabitEthernet1/0/2 What is the effect of this configuration?

Medium
1186

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on an interface connected to a network with asymmetric routing. Users report intermittent connectivity issues. Which is the most likely explanation?

Hard
1187

Two OSPF routers R1 and R2 are connected via a GigabitEthernet link in area 0. R1 has interface GigabitEthernet0/0 ip ospf network point-to-point, while R2 has the default OSPF network type broadcast. R1's show ip ospf neighbor shows R2 in FULL state, but R2's show ip ospf neighbor shows R1 in FULL state. However, routes from R1 are not appearing in R2's routing table. Show ip ospf database on R2 shows the router LSA from R1 but not the network LSA. What is the root cause?

Hard
1188

A service provider network is experiencing MPLS label distribution failures between R1 and R2. R1 has: event manager applet LDP-MONITOR event syslog pattern "%LDP-4-ERROR" action 1.0 cli command "enable" action 2.0 cli command "clear mpls ldp neighbor *" action 3.0 syslog msg "Cleared LDP neighbors". Router R2 shows: LDP session is down, and logs show repeated LDP errors. What is the root cause?

Hard
1189

A network engineer runs the following command to troubleshoot a Route Redistribution issue: R1# debug ip ospf adj And sees the following output: *Mar 1 00:20:11.456: OSPF: Rcv pkt from 10.1.1.2, Serial0/0/0 : Mismatch Authentication type. Input packet specified type 0, we use type 1 *Mar 1 00:20:11.457: OSPF: Rcv pkt from 10.1.1.2, Serial0/0/0 : Mismatch Authentication type. Input packet specified type 0, we use type 1 What does this output indicate?

Easy
1190

A network engineer is configuring a Cisco IOS XE router to support MPLS L3VPN. The router is a PE device with a VRF named CUSTOMER. The engineer wants to ensure that the PE router can forward traffic for the CUSTOMER VRF using MPLS labels. Which command must be configured on the PE router's core-facing interface to enable MPLS forwarding?

Medium
1191

In VRF-Lite, which routing protocols can be used within a VRF?

Medium
1192

Drag and drop the steps to troubleshoot BGP adjacency or connectivity failures into the correct order, from first to last.

Hard
1193

A network engineer runs the following command on Router R1: R1# show ip nat translations Pro Inside global Inside local Outside local Outside global udp 192.0.2.10:10000 10.0.0.10:10000 203.0.113.5:53 203.0.113.5:53 udp 192.0.2.10:10001 10.0.0.11:10000 203.0.113.5:53 203.0.113.5:53 udp 192.0.2.10:10002 10.0.0.12:10000 203.0.113.5:53 203.0.113.5:53 R1# show ip nat statistics Total active translations: 3 (0 static, 3 dynamic; 3 extended) Outside interfaces: GigabitEthernet0/1 Inside interfaces: GigabitEthernet0/0 Hits: 150 Misses: 0 CEF Translated packets: 150, CEF Punted packets: 0 Expired translations: 0 Dynamic mappings: -- Inside Source [Id] ip nat inside source list ACL1 interface GigabitEthernet0/1 overload refcount 3 Based on this output, which statement is correct?

Easy
1194

What is the default administrative distance for OSPF routes in a VRF when OSPF is used as the PE-CE routing protocol in MPLS L3VPN?

Medium
1195

A network engineer runs the following command to troubleshoot a Policy-Based Routing (PBR) issue: R1# show ip policy Interface Route-map FastEthernet0/0 PBR-MAP What does this output indicate?

Easy
1196

A network engineer runs the following command to troubleshoot an EEM issue: R1# show event manager policy configuration TRACK-INTERFACE Applet TRACK-INTERFACE event syslog pattern "OSPF-5-ADJCHG" action 1.0 cli command "show ip route" action 2.0 cli command "show ip ospf neighbor" action 3.0 syslog msg "OSPF adjacency change detected" What does this output indicate?

Medium
1197

Drag and drop the steps to troubleshoot EIGRP neighbor adjacency formation into the correct order, from first to last.

Medium
1198

A network engineer runs the following command on Router R1: R1# show ipv6 neighbors IPv6 Address Age Link-layer Addr State Interface 2001:DB8:1::1 0 aaaa.bbbb.cccc REACH Gi0/0/0 2001:DB8:1::2 10 aaaa.bbbb.cccd STALE Gi0/0/0 2001:DB8:1::3 - aaaa.bbbb.ccce DELAY Gi0/0/1 FE80::1 0 aaaa.bbbb.cccf REACH Gi0/0/0 Based on this output, which statement is correct?

Medium
1199

A network engineer is configuring a Cisco IOS-XE router for DMVPN Phase 3. The engineer wants to ensure that spoke-to-spoke traffic flows directly between spokes without traversing the hub. Which technology should be used to achieve this?

Easy
1200

A network engineer is configuring a Cisco router to act as a DHCP relay agent. The DHCP server is located on a different subnet. Which command is required on the router's interface to forward DHCP requests to the server?

Easy
1201

In MPLS L3VPN, what is the default behavior of BGP auto-summary on Cisco IOS-XE?

Hard
1202

A network engineer is troubleshooting an EIGRP adjacency issue between two directly connected routers, R1 and R2. Both routers are configured with the same autonomous system number, but the adjacency fails to come up. The engineer checks the interfaces and verifies that they are up/up. On R1, the output of 'show ip eigrp neighbors' shows nothing. What is the most likely cause of this problem?

Medium
1203

A network engineer runs the following command on Router R1: R1# show ipv6 interface tunnel 0 Tunnel0 is up, line protocol is up IPv6 is enabled, link-local address is FE80::1 Global unicast address(es): 2001:DB8:2::1, subnet is 2001:DB8:2::/64 Joined group address(es): FF02::1 FF02::2 ICMP redirects are enabled ICMP unreachables are enabled ND DAD is enabled, number of DAD attempts: 1 ND reachable time is 30000 milliseconds IPv6 uRPF: loose mode (allow default route) Based on this output, what is the uRPF configuration on this interface?

Medium
1204

In DHCPv6, what is the purpose of the SOLICIT message?

Medium
1205

A network engineer is configuring a GRE over IPsec tunnel between two Cisco routers. The engineer wants to ensure that multicast traffic, such as OSPF hello packets, is encrypted and sent over the tunnel. Which statement about the configuration is true?

Medium
1206

Which TWO statements about DHCPv4 option 82 are true? (Choose TWO.)

Hard
1207

Which TWO configuration steps are required to enable MPLS on a Cisco IOS-XE router using LDP? (Choose TWO.)

Medium
1208

A network engineer runs the following command to troubleshoot an EIGRP issue: R1# show ip eigrp topology 10.1.1.0/24 detail IP-EIGRP (AS 100): Topology entry for 10.1.1.0/24 State: Passive, Query origin flag: 1, 1 Successor(s), FD is 131072 Routing Descriptor Blocks: 10.1.2.2 (GigabitEthernet0/0), from 10.1.2.2, Send flag: 0x0 Composite metric: (131072/130816), Route is Internal Vector metric: Minimum bandwidth is 10000 Kbit Total delay is 100 microseconds Reliability is 255/255 Load is 1/255 Minimum MTU is 1500 Hop count is 1 Originating router: 10.1.2.2 External data: Not advertised Protocol: EIGRP Route tag: 0 Extended community: None What does this output indicate?

Medium
1209

Which THREE are valid syslog severity levels defined in RFC 5424? (Choose THREE.)

Hard
1210

What is the default export interval for NetFlow data when using the 'flow exporter' with UDP as the transport protocol?

Medium
1211

A network engineer runs the following command on Router R1: R1# show mpls l2transport vc 100 detail Local interface: Gi0/0/0 up, line protocol up Destination: 10.0.0.2, VC ID: 100, VC status: down Last error: No remote LDP session Based on this output, what is the most likely cause of the VC being down?

Medium
1212

Which BFD packet type is used for initial session establishment and carries the discriminator values?

Medium
1213

An engineer redistributes OSPF routes into EIGRP. The OSPF routes have a metric of 20. After redistribution, the EIGRP topology table shows the routes but they are not installed in the routing table. The 'show ip eigrp topology' shows the route in active state. Which is the most likely explanation?

Hard
1214

A network engineer runs the following command to troubleshoot a Control Plane Policing (CoPP) issue: R1# show ip access-lists CoPP-ACL Extended IP access list CoPP-ACL 10 permit tcp host 10.1.1.1 any eq bgp (100 matches) 20 permit udp any any eq 67 (50 matches) 30 permit icmp any any echo (200 matches) 40 deny ip any any (500 matches) What does this output indicate?

Medium
1215

A network engineer is deploying a DMVPN Phase 3 hub-and-spoke topology using mGRE and NHRP, and wants spokes to reach other spokes directly without routing through the hub for every packet. The engineer must configure the hub so that it advertises a default route to the spokes while still allowing spoke-to-spoke shortcut tunnels. (Choose two.)

Medium
1216

In a 6to4 tunnel, how is the tunnel destination address determined?

Medium
1217

An engineer is troubleshooting a DHCPv4 issue where a Cisco router acting as a DHCP client on interface Gi0/0 is not receiving an IP address from an ISP modem. The router has 'ip address dhcp' on the interface. The engineer sees that the interface is up/up, but no IP address is assigned. Debug shows that the router is sending DHCP DISCOVER messages but receives no OFFER. The ISP modem is known to work with other devices. What is the most likely cause?

Medium
1218

An engineer is troubleshooting an MPLS LDP session that fails to establish between two directly connected routers. Which TWO commands can be used to verify LDP operation? (Choose TWO.)

Hard
1219

A switch is configured with RSPAN to monitor traffic from VLAN 50 to a remote switch via VLAN 200. The source switch has: monitor session 1 source vlan 50 rx monitor session 1 destination remote vlan 200. The remote switch has: monitor session 2 source remote vlan 200 monitor session 2 destination interface Gi0/2. The intermediate switches have VLAN 200 configured with 'remote-span'. The network uses VTP transparent mode. The analyzer connected to Gi0/2 sees intermittent traffic. The RSPAN VLAN 200 is also used as a native VLAN on some trunk ports. What is the likely cause of intermittent traffic?

Hard
1220

A network administrator is configuring a Cisco IOS router to support MPLS Layer 3 VPNs. The router is a PE device that must exchange VPNv4 routes with other PE routers. The administrator has enabled MPLS LDP on the core-facing interfaces and configured BGP with the address-family vpnv4. Which additional configuration is required on the PE router to properly forward MPLS VPN traffic?

Medium
1221

A network engineer is implementing a DMVPN Phase 3 network with NHRP and mGRE on the hub. The design requires that spoke-to-spoke traffic be able to bypass the hub after resolution, and that the hub not be required to advertise specific routes to the spokes. Which two configuration elements are required to achieve shortcut switching and default-route-only behavior on the spokes? (Choose two.)

Hard
1222

A network administrator is configuring a Cisco IOS router to provide first-hop redundancy for a group of hosts on VLAN 10. The design requires that the virtual IP address be 10.1.10.1 and that the router with the highest priority become the active gateway. The administrator has configured the interface with 'standby 10 ip 10.1.10.1' and 'standby 10 priority 150'. Which additional command is required to ensure that the router preempts and becomes the active gateway if it reboots?

Easy
1223

A network engineer runs the following command to verify DHCPv4 server statistics on router R1: R1# show ip dhcp server statistics Output: Memory usage: 12345 Address pools: 2 Database agents: 0 Automatic bindings: 150 Manual bindings: 5 Expired bindings: 10 Malformed messages: 0 Message Received BOOTREQUEST 0 DHCPDISCOVER 200 DHCPREQUEST 180 DHCPDECLINE 2 DHCPRELEASE 5 DHCPINFORM 10 What does this output indicate?

Medium
1224

Drag and drop the steps to troubleshoot an IPsec site-to-site VPN adjacency failure into the correct order, from first to last.

Hard
1225

A network engineer is troubleshooting a VRF-Lite deployment where two routers are connected via a trunk link. Each router has two VRFs (VRF_A and VRF_B). The engineer configures subinterfaces on the trunk link, assigning each subinterface to a different VRF. However, traffic between the two routers for VRF_A is not working. The 'show vrf' command shows the VRFs are active. What is the most likely issue?

Hard
1226

A network engineer is troubleshooting MPLS traffic where packets are being forwarded without a label (IP forwarding) instead of being label-switched. The engineer runs show mpls forwarding-table and sees that the FEC for the destination prefix has a valid label. However, show ip cef shows that the outgoing interface is not MPLS-enabled. What is the most likely cause?

Hard
1227

A network engineer runs the following command to verify BFD with MPLS LDP: R1# show mpls ldp neighbor 10.6.6.2 detail Peer LDP Ident: 10.6.6.2:0, Local LDP Ident: 10.6.6.1:0 TCP connection: 10.6.6.2.646 - 10.6.6.1.53456 State: Oper; Msgs sent/rcvd: 100/100; Downstream Up time: 00:10:00 LDP discovery sources: GigabitEthernet0/2, hello interval: 5 s, hello hold: 15 s Addresses bound to peer LDP ident: 10.6.6.2 10.7.7.2 BFD enabled, BFD state: UP What does this output indicate?

Medium
1228

What is the default administrative distance for a route learned via the Routing Information Protocol (RIP)?

Easy
1229

An engineer configures OSPF on two routers connected via a serial link. Both routers show the neighbor state as EXSTART/EXSTART, and no LSAs are exchanged. The engineer verifies that the OSPF process IDs are the same, areas match, and authentication is correct. Which is the most likely explanation?

Hard
1230

A network engineer is configuring a DMVPN Phase 3 network with mGRE and NHRP. The hub router must be able to dynamically learn spoke routes and advertise them to other spokes. Which two statements are true regarding the configuration of the hub to support spoke-to-spoke communication in DMVPN Phase 3? (Choose two.)

Medium
1231

Which TWO configuration steps are required to implement static NAT on a Cisco IOS router? (Choose TWO.)

Medium
1232

A network engineer runs the following command to troubleshoot a DMVPN spoke not registering with the hub: R2# debug nhrp NHRP: Send Registration Request via Tunnel0 10.0.0.2, target 10.0.0.1 NHRP: Receive Registration Reply via Tunnel0 10.0.0.1, src 10.0.0.1, dst 10.0.0.2 NHRP: Registration successful for 10.0.0.2/32 via Tunnel0 What does this output indicate?

Medium
1233

An engineer is troubleshooting BGP convergence issues. Which THREE commands can be used to verify BGP path selection and best path criteria? (Choose THREE.)

Hard
1234

Consider the configuration snippet: logging 192.168.1.10 vrf Mgmt-intf logging source-interface Vlan1 logging trap 6 What is the effect of the 'logging trap 6' command?

Easy
1235

An engineer configures OSPFv3 with a filter-list on an ABR to filter prefixes. After configuration, the routes are still being advertised. Which is the most likely explanation?

Hard
1236

A network engineer is configuring a Cisco IOS router to authenticate administrative SSH access using TACACS+ with a backup local user account. The TACACS+ server is reachable, but the engineer wants to ensure that if the TACACS+ server becomes unreachable, the router falls back to local authentication for users who are not defined on the TACACS+ server. Which AAA configuration accomplishes this?

Medium
1237

A network administrator is configuring a Cisco IOS router for site-to-site VPN using DMVPN Phase 3. The administrator wants to ensure that spoke-to-spoke traffic flows directly between spokes without traversing the hub, and that the hub is only used for initial registration and route resolution. Which technology must be enabled on the spokes to achieve direct spoke-to-spoke communication?

Medium
1238

A network engineer is configuring SSH access on a Cisco IOS router. The engineer wants to restrict SSH access to only the management subnet 192.168.1.0/24 and ensure that only SSH version 2 is used. Which set of commands accomplishes this?

Easy
1239

Which TWO statements about DHCP IPv6 (DHCPv6) operation are true? (Choose TWO.)

Hard
1240

A network engineer is configuring a Cisco IOS router to authenticate management users via TACACS+ using the server at 10.1.1.100 with the shared key 'Cisco123'. The engineer wants to ensure that if the TACACS+ server becomes unreachable, the router will fall back to local authentication using the local username 'admin' with password 'AdminPass'. Which configuration correctly achieves this?

Medium
1241

A network engineer runs the following command on Router R1: R1# show flow interface GigabitEthernet0/0 Interface GigabitEthernet0/0 FNF: enabled Ingress IPV4/IPV6 flow monitoring: enabled Exporter: EXPORTER1 Monitor: MONITOR1 Egress IPV4/IPV6 flow monitoring: disabled Ingress MPLS flow monitoring: disabled Egress MPLS flow monitoring: disabled Based on this output, what is the state of NetFlow on this interface?

Medium
1242

Drag and drop the steps to perform mutual redistribution between OSPF and EIGRP into the correct order, from first to last.

Medium
1243

Which TWO statements correctly describe the behavior of OSPFv3 when troubleshooting neighbor adjacency issues on a Cisco IOS-XE router? (Choose TWO.)

Hard
1244

A network engineer runs the following command to debug IPv6 uRPF with detailed information: R1# debug ipv6 verify detail IPv6 verify debugging is on (detail) *Mar 1 00:03:45.678: IPv6 verify: source 2001:DB8:5::1 on GigabitEthernet0/0 *Mar 1 00:03:45.678: route to source via GigabitEthernet0/1, not same as input interface What does this output indicate?

Hard
1245

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 10.4.4.0/24 BGP routing table entry for 10.4.4.0/24, version 8 Paths: (1 available, best #1, table default) Not advertised to any peer Refresh Epoch 1 65006 10.1.16.6 from 10.1.16.6 (10.6.6.6) Origin IGP, metric 0, localpref 100, valid, external, best rx pathid: 0, tx pathid: 0x0 Based on this output, what is the most likely reason the route is not advertised to any peer?

Hard
1246

A network engineer is troubleshooting a Cisco IOS FlexVPN IKEv2 hub that terminates many spokes using a single IKEv2 profile. A new spoke fails to complete IKEv2 authentication even though the same pre-shared key is configured on both peers. The hub logs show the failure occurs during IKE_AUTH. The spoke is not sending a certificate and there is no local AAA authentication configured on the hub for IKEv2. Which configuration change on the hub is most likely to resolve the authentication failure?

Hard
1247

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The engineer wants to ensure that only traffic from the 10.1.1.0/24 network to the 10.2.2.0/24 network is encrypted. Which type of ACL must be used in the crypto map to define the interesting traffic?

Easy
1248

A network engineer is deploying DMVPN Phase 3 with OSPF over the tunnel interface. The hub router must summarize all spoke routes into a single /24 prefix before advertising them into the corporate OSPF domain. The engineer configures `area 0 range 10.10.0.0 255.255.255.0` on the hub's ABR. After applying the configuration, spoke routes are still advertised individually. Which action resolves the issue?

Medium
1249

A network engineer runs the following command to verify IPv6 traffic filtering with logging: R1# show logging | include FILTER *Mar 1 00:04:56.789: %IPV6_ACL-6-ACCESSLOGDP: list FILTER denied tcp 2001:DB8:2::1(12345) -> 2001:DB8:3::1(80), 1 packet What does this output indicate?

Medium
1250

An engineer configures IPv6 uRPF strict mode on an interface that is used for both IPv6 traffic and OSPFv3 routing. The router is an ABR with multiple areas. OSPFv3 adjacencies form correctly, but some IPv6 data traffic is dropped. The show ipv6 interface command shows uRPF is enabled. Which is the most likely explanation?

Hard
1251

A network engineer is configuring a Cisco IOS router to act as a DHCP server for a remote subnet. The router interface connected to that subnet is configured with the address 10.10.10.1/24. The engineer wants the router to assign addresses from the 10.10.10.0/24 range and also provide the default gateway and DNS server information to clients. Which configuration is required on the router to accomplish this?

Medium
1252

A network engineer runs the following command on Router R1: R1# show dmvpn Legend: Attrb -> S: Static, D: Dynamic, I: Incomplete N: NATed, L: Local, X: No Socket # Ent -> Number of NHRP entries with same NBMA peer NHS Status: E => Expecting Replies, R => Responding, W => Waiting UpDn Time -> Up or Down Time for a Tunnel ========================================================================== Interface: Tunnel0, IPv4 NHRP Details Type:Hub, NHRP Peers:2, # Ent Peer NBMA Addr Peer Tunnel Add State UpDn Tm Attrb ----- --------------- --------------- ----- -------- ----- 1 192.168.1.2 10.0.0.2 UP 00:15:30 D 1 192.168.1.3 10.0.0.3 UP 00:10:20 D Based on this output, what is the role of Router R1?

Easy
1253

An engineer configures an IPsec site-to-site VPN between two routers. The tunnel comes up, but traffic is not encrypted. Which is the most likely explanation?

Hard
1254

An engineer configures IPsec between two routers using transform-set esp-aes 256 esp-sha-hmac. The tunnel fails to establish. Debug shows 'transform set proposal mismatch'. Which is the most likely explanation?

Hard
1255

An engineer configures an IPv6 ACL on a router interface to permit only specific ICMPv6 types (e.g., echo request and echo reply) and deny all other IPv6 traffic. After applying the ACL inbound, the router stops forming IPv6 neighbor discoveries (ND) and the interface loses IPv6 connectivity. Which is the most likely explanation?

Hard
1256

A network engineer runs the following command to troubleshoot a Control Plane Policing (CoPP) issue: R1# show ip ospf interface detail FastEthernet0/0 is up, line protocol is up Internet Address 10.1.1.1/24, Area 0.0.0.0, Attached via Network Statement Process ID 1, Router ID 10.1.1.1, Network Type BROADCAST, Cost: 1 Topology-MTID Cost Disabled Shutdown Topology Name 0 1 no no Base Transmit Delay is 1 sec, State DR, Priority 1 Designated Router (ID) 10.1.1.1, Interface address 10.1.1.1 Backup Designated router (ID) 10.1.1.2, Interface address 10.1.1.2 Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5 oob-resync timeout 40 Hello due in 00:00:03 Supports Link-local Signaling (LLS) Index 1/1, flood queue length 0 Next 0x0(0)/0x0(0) Last flood scan length is 1, maximum is 25 Last flood scan time is 0 msec, maximum is 4 msec Neighbor Count is 1, Adjacent neighbor count is 1 Adjacent with neighbor 10.1.1.2 (Backup Designated Router) Suppress hello for 0 neighbor(s) What does this output indicate?

Medium
1257

A network administrator is setting up a site-to-site VPN between two Cisco IOS routers and wants to use IKEv2 with certificate-based authentication. The administrator has already installed the identity certificate and the CA certificate on both routers. Which additional configuration is required on each router so that IKEv2 can validate the peer's certificate during the IKE_AUTH exchange?

Easy
1258

A network engineer is configuring AAA authorization on a Cisco IOS router. The engineer wants to limit which commands a user can execute after logging in via SSH. The user should be allowed to run show commands but not configuration commands. Which AAA authorization method should be used?

Easy
1259

Examine this configuration on Router R4: ``` interface Tunnel0 ip address 10.0.0.1 255.255.255.252 ipv6 address 2001:DB8:6::1/64 tunnel source GigabitEthernet0/0 tunnel destination 172.16.1.2 tunnel mode gre ip ``` What will be the effect?

Medium
1260

An engineer configures mutual redistribution between OSPF and EIGRP on a router. After a few minutes, the router's CPU spikes and routing loops occur. Which is the most likely explanation?

Hard
1261

A network engineer runs the following command to troubleshoot an EIGRP issue: R1# show ip eigrp interfaces detail Interface GigabitEthernet0/0 EIGRP interface state: Enabled, Up Hello interval: 5 sec, Hold time: 15 sec Split horizon: Enabled Next multicast: 0.0.0.0, Next update: 0.0.0.0 Bandwidth: 10000 Kbit, Delay: 100 us Reliability: 255/255, Load: 1/255, MTU: 1500 Packets sent: 100, received: 95 Authentication: MD5, key chain: EIGRP-KEY Passive interface: No What does this output indicate?

Easy
1262

In MPLS L3VPN, what is the default behavior when a PE router receives a VPNv4 route with a Route Target that does not match any import RT on any VRF?

Easy
1263

A network engineer is configuring a Cisco IOS XE router to act as a Dynamic Host Configuration Protocol (DHCP) client on its WAN interface. The service provider requires the router to send a specific client identifier in its DHCP requests. Which command accomplishes this?

Medium
1264

A network administrator is troubleshooting an MPLS L3VPN where customer routes are not being propagated between PE routers. The PE routers are Cisco IOS-XE devices running MP-BGP. Which address family must be configured on the PE routers to exchange VPNv4 prefixes?

Hard
1265

Given this configuration on router R2: ``` ip vrf CUSTOMER_D rd 100:1 ! interface GigabitEthernet0/0 ip vrf forwarding CUSTOMER_D ip address 192.168.2.1 255.255.255.0 ! router ospf 1 vrf CUSTOMER_D network 192.168.2.0 0.0.0.255 area 0 ``` What will happen when this configuration is applied?

Medium
1266

Drag and drop the steps to verify and validate NetFlow and Flexible NetFlow operational state into the correct order, from first to last.

Medium
1267

Which statement correctly describes the default 'match' direction in a Flexible NetFlow flow record?

Hard
1268

A network engineer runs the following command to troubleshoot SNMP access: R1# show snmp community Community name: public Community Index: public Storage-Type: nonvolatile Access: read-only View: v1default Community name: private Community Index: private Storage-Type: nonvolatile Access: read-write View: v1default What does this output indicate?

Medium
1269

A network engineer is troubleshooting a router that is not generating any EEM applet actions even though the applets are configured and enabled. The engineer checks the 'show event manager status' command and sees that the EEM server is running. The engineer also checks the syslog and sees that the trigger events are occurring. What is the most likely cause?

Hard
1270

A network technician is configuring a Cisco IOS router to use SSH for remote management. The technician generates an RSA key pair with 2048 bits, configures a local username and password, and enables SSH version 2. However, when attempting to connect via SSH, the connection is refused. Which additional configuration is required on the VTY lines to allow SSH access?

Easy
1271

A network technician is configuring a static route on a Cisco router to reach a remote network. The technician wants the route to be used only if the primary path fails. Which type of static route should be configured?

Easy
1272

A network engineer configured IP SLA 70 to monitor a remote site's LAN gateway (172.16.1.1) using ICMP echo. The IP SLA is linked to a track object that is used in a static route for a backup link. The engineer notices that the IP SLA state is 'Active', but the backup static route is installed in the routing table even when the primary route is available. What is the most likely cause?

Medium
1273

A network engineer is troubleshooting an OSPFv3 network. Router R1 is an ABR connected to Area 0 and Area 1. Area 1 is configured as a totally stubby area. R1 is not injecting a default route into Area 1, and routers in Area 1 cannot reach external destinations. Which command should the engineer verify on R1 to ensure that a default route is generated into Area 1?

Medium
1274

A network engineer runs the following command on Router R1: R1# show route-map route-map FILTER_OSPF, permit, sequence 10 Match clauses: ip address prefix-list OSPF_ROUTES Set clauses: Policy routing matches: 0 packets, 0 bytes route-map FILTER_OSPF, deny, sequence 20 Match clauses: Set clauses: Policy routing matches: 0 packets, 0 bytes Based on this output, which statement is correct?

Medium
1275

A network engineer runs the following command to troubleshoot a VRF-Lite IPsec issue: R1# show crypto ipsec transform-set vrf CUSTOMER_H Output: Transform set combined: { esp-aes 256 esp-sha-hmac } will negotiate = { Tunnel, } What does this output indicate?

Medium
1276

What is the default behavior of PBR when a 'set ip next-hop' and a 'set ip default next-hop' are both configured in the same route-map entry?

Hard
1277

A network uses PBR to route traffic from a specific VLAN (10.10.10.0/24) through a firewall (next-hop 192.168.1.1). After a firewall replacement, traffic from this VLAN is being dropped. Router R1 shows: 'show route-map' shows the route-map is applied, 'show ip policy' shows the policy on the VLAN interface, but 'debug ip packet' shows packets being sent to 192.168.1.1 and no response. Router R2 (firewall) shows: 'show ip route 10.10.10.0' returns a route via 192.168.2.1, but the firewall is configured to drop traffic from 10.10.10.0/24. What is the root cause?

Hard
1278

A network engineer runs the following command to troubleshoot a Policy-Based Routing (PBR) issue: R1# show ip policy Interface Route-map FastEthernet0/0 PBR-MAP Serial0/0 PBR-MAP What does this output indicate?

Medium
1279

A network engineer is configuring a Cisco IOS XE router to authenticate administrative SSH users against a TACACS+ server. The engineer wants to ensure that if the TACACS+ server is unreachable, a locally configured fallback account can still be used to log in. The engineer also wants to ensure that the fallback account is not used when the TACACS+ server is reachable but rejects the credentials. Which AAA configuration should the engineer apply?

Medium
1280

Which TWO statements about the limitations of local SPAN are correct? (Choose TWO.)

Hard
1281

Drag and drop the steps to verify and validate the operational state of an IPsec site-to-site VPN into the correct order, from first to last.

Medium
1282

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP class-map: MANAGEMENT (match-all) 5 packets, 500 bytes 5 minute offered rate 0 bps police: cir 8000 bps, bc 1500 bytes conformed 5 packets, 500 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop conformed 0 bps, exceed 0 bps class-map: ATTACK (match-all) 100 packets, 10000 bytes 5 minute offered rate 0 bps police: cir 8000 bps, bc 1500 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 100 packets, 10000 bytes; actions: drop conformed 0 bps, exceed 0 bps Based on this output, what is happening to traffic matching class ATTACK?

Medium
1283

A network technician is configuring a Cisco IOS router to authenticate EIGRP neighbors using MD5. The router is running EIGRP AS 10. Which command enables MD5 authentication for EIGRP on an interface?

Easy
1284

Which TWO statements about AAA authentication on Cisco IOS-XE are true? (Choose TWO.)

Hard
1285

What is the default administrative distance for routes redistributed into EIGRP from another protocol?

Medium
1286

What is the default SNMP community string on a Cisco IOS device that has not been configured with any SNMP commands?

Hard
1287

A network engineer configures BGP synchronization on an iBGP router. The IGP (OSPF) does not carry the BGP routes. Unexpectedly, the router does not advertise these iBGP routes to eBGP neighbors. What is the most likely explanation?

Hard
1288

A network engineer runs the following command to troubleshoot a BGP Troubleshooting issue: R1# show bgp ipv4 unicast summary BGP router identifier 1.1.1.1, local AS number 65000 BGP table version is 15, main routing table version 15 2 network entries using 288 bytes of memory 2 path entries using 160 bytes of memory 2/2 BGP path/bestpath attribute entries using 296 bytes of memory 1 BGP AS-PATH entries using 24 bytes of memory 0 BGP route-map cache entries using 0 bytes of memory 0 BGP filter-list cache entries using 0 bytes of memory Bitfield cache entries: current 1 (at peak 1) using 32 bytes of memory BGP using 800 total bytes of memory BGP activity 6/0 prefixes, 6/0 paths, scan interval 60 secs Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 10.1.1.2 4 65001 15 15 15 0 0 00:12:34 2 10.2.2.2 4 65002 10 12 15 0 0 00:08:21 0 What does this output indicate?

Medium
1289

Drag and drop the steps to configure SNMPv3 with auth-priv and verify traps into the correct order, from first to last.

Medium
1290

In IPv6 FHS, which protocol is used to secure Neighbor Discovery messages with cryptographic authentication?

Medium
1291

A network engineer is configuring OSPFv2 on a multiaccess segment. The engineer wants to ensure that the designated router (DR) election is deterministic and that a specific router becomes the DR. The router has the highest OSPF priority on the segment, but it is not becoming the DR. What could be the reason?

Hard
1292

What is the default behavior of EIGRP auto-summary in IOS-XE 15.x and later?

Medium
1293

Which THREE commands would a network engineer use to troubleshoot an MPLS L3VPN issue where a CE router cannot reach a remote CE? (Choose THREE.)

Hard
1294

A network engineer runs the following command on Router R1: R1# show ip policy Interface Route-map GigabitEthernet0/0 PBR-VOICE R1# show route-map PBR-VOICE route-map PBR-VOICE, permit, sequence 10 Match clauses: ip address (access-lists): 130 Set clauses: ip next-hop 192.168.10.1 Policy routing matches: 0 packets, 0 bytes R1# show access-lists 130 Extended IP access list 130 10 permit udp any any range 16384 32767 R1# show interfaces GigabitEthernet0/0 GigabitEthernet0/0 is up, line protocol is up Internet address is 10.1.1.1/24 R1# show ip route 192.168.10.1 % Network not in routing table Based on this output, what is the most likely problem?

Medium
1295

Consider the following BGP configuration on router R5: router bgp 65005 bgp router-id 5.5.5.5 neighbor 10.5.5.6 remote-as 65006 neighbor 10.5.5.6 route-map SET-LP in ! route-map SET-LP permit 10 set local-preference 150 ! What is the result of this configuration?

Medium
1296

Which TWO statements about PBR and the 'set ip next-hop recursive' command are true? (Choose TWO.)

Hard
1297

A network engineer is troubleshooting an IPv6 over IPv4 tunnel that is used to connect two remote sites. The tunnel is configured with a tunnel source that is a loopback interface. The tunnel is up, but the engineer cannot ping the remote tunnel endpoint IPv6 address. The engineer checks the routing table and sees a route to the remote loopback's IPv4 address via a default route. What is the most likely cause?

Medium
1298

A network administrator is configuring AAA on a Cisco IOS router. The administrator wants to use a RADIUS server for authentication and authorization, but wants to use local authentication as a fallback if the RADIUS server is unreachable. Which command should be used to configure the fallback?

Easy
1299

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to ensure that uRPF is applied correctly and does not drop legitimate traffic. Which uRPF mode should the engineer use to allow asymmetric routing while still providing some protection?

Medium
1300

A network engineer is troubleshooting a redistribution issue between OSPF and EIGRP. Router R3 is redistributing OSPF routes into EIGRP, but some OSPF external routes are not appearing in the EIGRP topology table. The engineer checks the redistribute command under EIGRP and sees a route-map named RM-OSPF that uses a prefix-list to match specific prefixes. The missing routes are permitted by the prefix-list. What is the most likely cause?

Hard
1301

According to RFC 2663, what is the term for the process of translating both the source and destination IP addresses in a packet?

Medium
1302

Examine this CoPP configuration: ip access-list extended PROTECT-ACL permit tcp any any eq 22 permit tcp any any eq 23 permit tcp any any eq 179 ! class-map match-all PROTECT-CLASS match access-group name PROTECT-ACL ! policy-map PROTECT-POLICY class PROTECT-CLASS police 16000 conform-action transmit exceed-action drop class class-default police 64000 conform-action transmit exceed-action drop ! control-plane service-policy input PROTECT-POLICY What will happen to SSH traffic that exceeds 16000 bps?

Medium
1303

What is the default administrative distance for internal EIGRP routes?

Easy
1304

A network engineer runs the following command on Router R1: R1# show event manager policy registered No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 BGP_Session_Reset R1# show event manager history events Event History: No. Time Type Name 1 00:02:00 UTC Mar 1 syslog BGP_Session_Reset 2 00:02:05 UTC Mar 1 syslog BGP_Session_Reset 3 00:02:10 UTC Mar 1 syslog BGP_Session_Reset Based on this output, which statement is correct?

Medium
1305

A network engineer is configuring OSPF on a router that connects to a service provider via a WAN link. The provider requires that the link be treated as a point-to-point connection without DR/BDR election, and the OSPF network type must be explicitly set to achieve this. Which command should be applied to the interface?

Medium
1306

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 connecting to an ISP (untrusted) and GigabitEthernet0/1 connecting to the internal network. The engineer wants to ensure that uRPF is applied only to traffic entering from the ISP. Which configuration mode and command should be used?

Hard
1307

A network engineer runs the following command on Router R4: R4# show ip route 10.10.10.0 Routing entry for 10.10.10.0/24 Known via "connected", distance 0, metric 0 (connected) Redistributing via eigrp 100 Last update from 10.10.10.1 on GigabitEthernet0/0, 00:00:00 ago Routing Descriptor Blocks: * 10.10.10.1, via GigabitEthernet0/0 Route metric is 0, traffic share count is 1 Based on this output, which statement is true?

Easy
1308

A network engineer runs the following command to troubleshoot a Policy-Based Routing (PBR) issue: R1# debug ip policy Policy routing debugging is on R1# *Mar 1 00:15:30.789: IP: s=10.0.0.1 (FastEthernet0/0), d=20.0.0.1, len 100, policy match *Mar 1 00:15:30.789: IP: s=10.0.0.1 (FastEthernet0/0), d=20.0.0.1, len 100, policy rejected *Mar 1 00:15:30.789: IP: s=10.0.0.2 (FastEthernet0/0), d=20.0.0.2, len 100, policy match *Mar 1 00:15:30.789: IP: s=10.0.0.2 (FastEthernet0/0), d=20.0.0.2, len 100, policy routed *Mar 1 00:15:30.789: IP: FastEthernet0/0 to GigabitEthernet0/1 192.168.1.1 What does this output indicate?

Hard
1309

What is the maximum number of VRFs that can be configured on a Cisco IOS router?

Easy
1310

An engineer is troubleshooting an MPLS L3VPN where CE1 (10.1.1.0/24) cannot reach CE2 (10.2.2.0/24). The PE routers have MP-BGP peering and the VRF is configured with route-target import 100:100. On PE1, the show ip bgp vpnv4 vrf CUSTOMER command shows the route for 10.2.2.0/24 with a next-hop of 192.168.1.2, but the show ip route vrf CUSTOMER command does not have this route. The show ip bgp vpnv4 all 10.2.2.0/24 command on PE1 shows the route is received but not best. What is the most likely cause?

Hard
1311

Which statement correctly describes the default behavior of EIGRP auto-summary on Cisco IOS-XE?

Easy
1312

Which TWO commands can be used to verify the NHRP shortcut route creation in a DMVPN Phase 3 network? (Choose TWO.)

Medium
1313

A network engineer runs the following command on Router R1: R1# show ipv6 traffic | include tunnel 0 tunnel packets received 0 tunnel packets sent 0 tunnel packets dropped Based on this output, what can be concluded?

Medium
1314

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (10.1.1.1/24) and GigabitEthernet0/1 (10.2.2.1/24). The engineer wants traffic from the 10.1.1.0/24 subnet destined to 192.168.1.0/24 to be forwarded out GigabitEthernet0/1 instead of following the routing table, which points to GigabitEthernet0/0. Which configuration sequence correctly implements this requirement?

Medium
1315

A network engineer runs the following command on Router R1: R1# show ip eigrp interfaces EIGRP-IPv4 Interfaces for AS(100) Xmit Queue Mean Pacing Time Multicast Pending Interface Peers Un/Reliable SRTT Un/Reliable Flow Timer Routes Gi0/0 1 0/0 12 0/10 50 0 Gi0/1 1 0/0 15 0/10 50 0 Gi0/2 1 0/0 18 0/10 50 0 Gi0/3 1 0/0 20 0/10 50 0 Gi0/4 0 0/0 0 0/10 50 0 Based on this output, which statement is correct?

Medium
1316

In an extended IPv4 ACL, what is the default action if only a source and destination are specified without a protocol?

Medium
1317

A network engineer is troubleshooting a DMVPN Phase 3 network using Cisco IOS XE routers. The hub router is configured with a multipoint GRE tunnel and NHRP. Spoke routers are unable to establish direct spoke-to-spoke tunnels. Which two statements describe the correct operation of DMVPN Phase 3 that could explain the issue? (Choose two.)

Medium
1318

A network engineer runs the following command on Router R1: R1# show ip eigrp vrf RED neighbors EIGRP-IPv4 Neighbors for AS(100) VRF RED H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 192.168.1.2 Gi0/2 13 00:15:30 12 200 0 45 1 192.168.2.2 Gi0/3 12 00:14:20 15 200 0 32 Based on this output, what is the problem?

Hard
1319

Examine this BGP configuration on router R6: router bgp 65006 bgp router-id 6.6.6.6 neighbor 10.6.6.7 remote-as 65007 neighbor 10.6.6.7 weight 200 ! What is the effect of the weight command?

Medium
1320

Which of the following is a mandatory condition for a route to be considered a feasible successor in EIGRP?

Medium
1321

A network engineer runs the following command on Router R5: R5# show logging | include %LINEPROTO-5-UPDOWN *Mar 1 00:00:10.123: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to up *Mar 1 00:00:20.456: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to down *Mar 1 00:00:30.789: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to up *Mar 1 00:00:40.012: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to down *Mar 1 00:00:50.345: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to up *Mar 1 00:01:00.678: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to down Based on this output, what is the most likely problem?

Easy
1322

Examine the following IPv6 ACL applied to an interface: ipv6 access-list FILTER permit ipv6 any any fragments deny ipv6 any any interface GigabitEthernet0/1 ipv6 traffic-filter FILTER in What is the effect of this configuration?

Medium
1323

An engineer configures SNMPv2c with a read-only community string 'public' on a router. The NMS can poll interface statistics, but when trying to poll OSPF neighbor states, the NMS receives no response. Which is the most likely explanation?

Hard
1324

A network engineer at a branch office is configuring OSPFv3 on a dual-stack router. The router must form an adjacency with a neighboring router that is also running OSPFv3. The engineer notices that the neighbor relationship remains in EXSTART state. Which command should be used to verify the OSPFv3 interface parameters that could cause this issue?

Medium
1325

Given this IP SLA configuration on router R4: ip sla 40 icmp-echo 10.10.10.1 source-ip 172.16.1.1 frequency 15 ip sla schedule 40 life forever start-time now Which statement is true?

Medium
1326

Which TWO statements about the 'ip domain-lookup' and DNS configuration on a Cisco IOS router are true? (Choose TWO.)

Hard
1327

A network engineer runs the following command on Router R1: R1# show ipv6 interface gigabitethernet 0/0 GigabitEthernet0/0 is up, line protocol is up IPv6 is enabled, link-local address is FE80::1 Global unicast address(es): 2001:DB8:1:1::1, subnet is 2001:DB8:1:1::/64 Joined group address(es): FF02::1 FF02::2 ICMP redirects are enabled ICMP unreachables are enabled ND DAD is enabled, number of DAD attempts: 1 ND reachable time is 30000 milliseconds ND advertised reachable time is 0 milliseconds ND advertised retransmit interval is 1000 milliseconds ND router advertisements are sent every 200 seconds ND router advertisements live for 1800 seconds Hosts use stateless autoconfig for addresses. IPv6 uRPF: strict mode (drop invalid packets) Based on this output, what is the operational state of uRPF on this interface?

Medium
1328

A network administrator is troubleshooting a DMVPN Phase 3 network. Spokes register with the hub, and routing adjacencies are up. However, spoke-to-spoke traffic is not taking the optimal path; it still goes through the hub. The hub is configured with `ip nhrp redirect` and `ip nhrp map multicast dynamic`. The administrator verifies that the spokes have `ip nhrp shortcut` configured. What is the most likely cause?

Hard
1329

A network engineer runs the following command to troubleshoot an OSPF adjacency issue: R1# debug ip ospf adj OSPF: Interface GigabitEthernet0/0 going Up OSPF: Send with youngest orig age 0 OSPF: Rcv DBD from 2.2.2.2 seq 0x1A opt 0x52 flag 0x7 len 32 mtu 1500 state INIT OSPF: First DBD and we are not SLAVE OSPF: Rcv DBD from 2.2.2.2 seq 0x1A opt 0x52 flag 0x7 len 32 mtu 1500 state EXSTART OSPF: Nbr 2.2.2.2 has larger interface MTU What does this output indicate?

Medium
1330

Consider the following configuration on Router R4: router eigrp 100 redistribute ospf 1 metric 10000 100 255 1 1500 router ospf 1 redistribute eigrp 100 metric 20 metric-type 1 subnets What is a potential issue with this configuration?

Hard
1331

Examine the following partial configuration: username admin privilege 15 secret 5 $1$abcdefg$hashedvalue username operator privilege 1 password cisco ! line console 0 login local ! line vty 0 4 login local transport input ssh What is a potential security issue with this configuration?

Medium
1332

A network engineer is deploying a DMVPN Phase 3 hub-and-spoke topology. The hub router must dynamically learn spoke-to-spoke routes and allow direct spoke-to-spoke tunnels. Which technology should be implemented on the hub to achieve this?

Medium
1333

Which TWO statements about MPLS Traffic Engineering (MPLS-TE) are true? (Choose TWO.)

Hard
1334

In MPLS, what is the purpose of the TTL propagation feature?

Medium
1335

Drag and drop the steps to set up a PE-CE BGP session in an MPLS L3VPN into the correct order, from first to last.

Medium
1336

A network engineer is implementing policy-based routing (PBR) on a Cisco router. The goal is to forward traffic from a specific source subnet to a next-hop that is not the default gateway. The engineer configures a route map with a match statement for the source subnet and a set statement for the next-hop. However, the traffic is still following the default route. What is the most likely reason?

Hard
1337

An enterprise network uses EIGRP with route summarization. Router R1 has the following configuration: interface GigabitEthernet0/0 ip summary-address eigrp 100 10.1.0.0 255.255.252.0. Router R2, connected to R1 via GigabitEthernet0/0, shows: 'show ip route eigrp' includes 10.1.0.0/22 but not the more specific route 10.1.1.0/24. Hosts in subnet 10.1.1.0/24 are unreachable from R2. What is the root cause?

Hard
1338

A network engineer is troubleshooting a DMVPN Phase 3 network using OSPF. Spoke routers are unable to form OSPF adjacencies with each other directly, even though they can reach the hub. The engineer wants to enable direct spoke-to-spoke communication. Which configuration is required on the hub?

Hard
1339

Which TWO statements about SNMPv3 security models are true? (Choose TWO.)

Hard
1340

What is the default severity level for syslog messages sent to the console on a Cisco IOS device?

Easy
1341

A network engineer is troubleshooting an IPsec site-to-site VPN between two Cisco routers. The VPN tunnel is up, but traffic is not passing through it. The engineer suspects a routing issue. Which command should be used to verify that the remote subnet is being routed through the tunnel interface?

Easy
1342

A network engineer runs the following command to troubleshoot a Control Plane Policing (CoPP) issue: R1# show bgp neighbors 10.1.1.2 received-routes BGP table version is 10, local router ID is 10.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.3.3.0/24 10.1.1.2 0 100 0 i Total number of prefixes 1 What does this output indicate?

Medium
1343

A network engineer runs the following command to troubleshoot an IPv4 Access Control Lists issue: R1# show ip interface GigabitEthernet0/0 | include access list Outgoing access list is 102 Inbound access list is not set Then the engineer checks: R1# show ip access-lists 102 Extended IP access list 102 10 deny tcp any any eq 23 20 permit ip any any What does this output indicate?

Easy
1344

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# debug ip sla trace IP SLAs trace debugging is on *Mar 1 12:34:56.789: IP SLAs: Starting operation 10 *Mar 1 12:34:56.789: IP SLAs: Sending ICMP echo request to 192.168.1.1 *Mar 1 12:34:56.790: IP SLAs: Received ICMP echo reply from 192.168.1.1 *Mar 1 12:34:56.790: IP SLAs: RTT = 12 ms *Mar 1 12:34:56.790: IP SLAs: Operation 10 completed successfully *Mar 1 12:35:56.789: IP SLAs: Starting operation 10 *Mar 1 12:35:56.789: IP SLAs: Sending ICMP echo request to 192.168.1.1 *Mar 1 12:35:56.790: IP SLAs: Received ICMP echo reply from 192.168.1.1 *Mar 1 12:35:56.790: IP SLAs: RTT = 14 ms *Mar 1 12:35:56.790: IP SLAs: Operation 10 completed successfully What does this output indicate?

Medium
1345

A network engineer runs the following command to troubleshoot an IPsec Site-to-Site VPN issue: R1# debug crypto ipsec *Mar 1 00:02:34.567: IPSEC(sa_request): , (key eng. msg.) src=10.0.0.1, dst=10.0.0.2, src_proxy=192.168.1.0/255.255.255.0/0/0, dst_proxy=192.168.2.0/255.255.255.0/0/0, *Mar 1 00:02:34.567: IPSEC(validate_proposal): transform proposal (esp-3des esp-sha-hmac) not supported for proxy 192.168.1.0/255.255.255.0/0/0 *Mar 1 00:02:34.567: IPSEC(validate_proposal): proposal doesn't match! *Mar 1 00:02:34.568: IPSEC(create_sa): SA created with (0x1234, 0x5678) but no inbound or outbound SPI What does this output indicate?

Medium
1346

Drag and drop the steps to troubleshoot Policy-Based Routing (PBR) adjacency or connectivity failures into the correct order, from first to last.

Hard
1347

A network engineer is configuring a Cisco IOS router to support MPLS Traffic Engineering (TE). The engineer has enabled MPLS TE globally and on the interfaces, and has configured a TE tunnel. However, the tunnel is not coming up. The engineer verifies that the IGP (OSPF) is advertising TE information. Which additional configuration is required to establish the TE tunnel?

Medium
1348

Which of the following EEM event types can be used to trigger an applet based on a specific IOS command being entered?

Easy
1349

DMVPN spoke-to-spoke tunnel is not forming between two spokes. Hub router R1 has the following relevant configuration: interface Tunnel0 ip address 10.0.0.1 255.255.255.0 ip nhrp network-id 1 ip nhrp map multicast dynamic ip ospf 1 area 0 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint Spoke R2 shows: show dmvpn Legend: Attrb -> S: Static, D: Dynamic, I: Incomplete Interface: Tunnel0, IPv4 NHRP Details Type:Spoke, NHRP Peers: 1 # Ent Peer NBMA Addr Peer Tunnel Add State UpDn Tm Attrb 1 192.168.1.1 10.0.0.1 UP 00:10:00 D Spoke R3 shows similar, but no spoke-to-spoke tunnel. What is the root cause?

Hard
1350

A network administrator is implementing IPsec VPN between two Cisco routers. The administrator wants to ensure that only specific traffic, defined by an extended access list, is encrypted and sent through the tunnel, while all other traffic is sent unencrypted. Which IPsec configuration element is used to define this traffic?

Hard
1351

Consider the following partial configuration on a Cisco IOS-XE router: interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip nat inside ! interface GigabitEthernet0/1 ip address 203.0.113.1 255.255.255.0 ip nat outside ! ip nat inside source list 1 interface GigabitEthernet0/1 overload access-list 1 permit 192.168.1.0 0.0.0.255 What is the effect of this configuration?

Medium
1352

A network engineer is deploying a site-to-site VPN between two Cisco IOS routers. The security policy requires that the peer identities be authenticated with certificates issued by an internal CA, and that the two peers negotiate a fresh keying channel for each new IKEv2 SA without relying on aggressive-mode pre-shared keys. Which IKEv2 configuration element must be present on both routers to satisfy the certificate-based authentication requirement?

Medium
1353

Which IPv6 FHS feature uses a 'device tracking' database to maintain reachability information for hosts?

Easy
1354

Which DHCP message type is used by a client to renew its lease before it expires?

Easy
1355

An engineer configures RSPAN VLAN 100 on two switches to monitor traffic across the network. The remote switch shows the RSPAN source as active, but the destination switch receives no mirrored traffic. What is the most likely cause?

Hard
1356

A network engineer is troubleshooting a DMVPN Phase 3 network using Cisco IOS XE routers. The hub router (Hub1) has a public IP of 203.0.113.1 and is configured with `tunnel mode gre multipoint`. Spoke routers are behind NAT devices. Spoke1 cannot establish a direct spoke-to-spoke tunnel with Spoke2, although both can reach the hub. Which technology must be enabled on the hub to allow spoke-to-spoke direct tunnels in this scenario?

Hard
1357

A large enterprise network is experiencing intermittent SNMP polling failures from the NMS to router R2. R1 and R2 are connected via a serial link running OSPF. R1 has the following relevant configuration: snmp-server community public RO, snmp-server community private RW, snmp-server trap-source Loopback0, snmp-server enable traps ospf. R2 shows: debug ip packet shows packets from NMS (10.1.1.100) to R2's Loopback0 (10.2.2.2) being dropped with 'access-list violation'. No ACL is applied to any interface on R2. What is the root cause?

Hard
1358

Which TWO statements about IPv6 Neighbor Discovery (ND) Inspection are true? (Choose TWO.)

Medium
1359

Examine this OSPF configuration snippet on router R3: router ospf 1 network 10.1.1.0 0.0.0.255 area 0 default-information originate always What is the effect of the default-information originate always command?

Medium
1360

An engineer configures CoPP on a router running EIGRP. The policy includes a class-map matching EIGRP traffic with a police rate of 1000 pps. After applying the policy, EIGRP neighbors form but occasionally go active and become stuck-in-active (SIA). Which is the most likely explanation?

Hard
1361

A network engineer runs the following command to troubleshoot an MPLS L3VPN issue: R1# show bgp vpnv4 vrf CUSTOMER-A 10.1.1.0/24 Output: BGP routing table entry for 10.1.1.0/24, version 10 Paths: (1 available, best #1, table CUSTOMER-A) Advertised to update-groups: 1 Refresh Epoch 1 Local 0.0.0.0 from 0.0.0.0 (10.0.0.1) Origin incomplete, metric 0, localpref 100, weight 32768, valid, sourced, best Extended Community: RT:100:100 mpls labels in/out nolabel/nolabel What does this output indicate?

Hard
1362

A network engineer is configuring OSPF on a Cisco router. The router has two interfaces in Area 0: GigabitEthernet0/0 (10.1.1.1/24) and GigabitEthernet0/1 (10.2.2.1/24). The engineer wants to ensure that the router ID is always 10.1.1.1, regardless of interface status. Which command should be used?

Medium
1363

A network engineer is configuring a Cisco IOS router to use Policy-Based Routing (PBR) to forward traffic from a specific subnet to a next-hop address. The route-map is named PBR_MAP, and the interface is GigabitEthernet0/0. Which command sequence correctly applies the route-map to the interface for incoming packets?

Medium
1364

Examine this IP SLA configuration on router R5: ip sla 50 icmp-echo 10.20.20.1 source-ip 192.168.10.1 frequency 10 ip sla schedule 50 life forever start-time now What is the effect of this configuration?

Medium
1365

A network engineer is configuring a Cisco IOS XE router as a Dynamic Host Configuration Protocol (DHCP) server for a guest wireless subnet. The router must dynamically allocate addresses from the 192.168.50.0/24 pool, but the first 30 addresses must be reserved for static assignment to access points and controllers. Which command must be issued to prevent the DHCP server from offering those addresses?

Medium
1366

A network engineer is troubleshooting a DMVPN Phase 3 deployment on a Cisco IOS XE hub. Spokes use NHRP to register with the hub and have working mGRE tunnels to the hub. The design requires that spoke-to-spoke traffic be sent directly between spokes without transiting the hub's data path. The engineer observes that all spoke-to-spoke packets still traverse the hub even though spoke registration and routing are correct. Which configuration change on the hub is required to enable direct spoke-to-spoke forwarding?

Hard
1367

An engineer configures iBGP between two routers in the same AS. The engineer notices that routes learned from one iBGP neighbor are not being advertised to another iBGP neighbor, even though the next-hop is reachable. The engineer verifies that the BGP session is established and that the routes are present in the BGP table. Which is the most likely explanation?

Hard
1368

A network administrator is implementing MPLS Layer 3 VPNs. The administrator wants to ensure that customer routes are not leaked between different VRFs on the same PE router. Which mechanism should be used to isolate the VRFs?

Medium
1369

A network technician is configuring a static route on a Cisco IOS router. The requirement is to forward all traffic destined to the 192.168.1.0/24 network to the next-hop IP address 10.1.1.1. Which command accomplishes this?

Easy
1370

A network engineer runs the following command on Router R1: R1# show ipv6 dhcp binding Client: FE80::1 DUID: 0003000100AABBCCDDEE Username: unknown IA NA: IA ID 0x00010001, T1 302400, T2 483840 Address: 2001:DB8:1::100/128 Preferred lifetime 604800, valid lifetime 2592000 Expires at Sep 15 2024 12:00 PM (2592000 seconds) Based on this output, which statement is correct?

Medium
1371

A network engineer runs the following command on Router R1: R1# show ip sla statistics 1 Round Trip Time (RTT) for Index 1 Latest RTT: 200 ms Latest RTT (milliseconds): 200 Latest RTT (microseconds): 200000 Number of successes: 50 Number of failures: 10 Operation time to live: Forever Output: Over threshold Based on this output, which statement is correct?

Medium
1372

A network engineer runs the following command to verify NetFlow export destination: R1# show ip flow export Flow export v9 is enabled for main cache Export source and destination details : VRF ID : Default Destination(1) 192.168.1.100 (2055) Source IP 10.0.0.1 Origin AS 65000 Peer AS 65001 Mask for source 255.255.255.255 Mask for destination 255.255.255.255 Version 9 flow records 1234 flows exported in 567 udp datagrams 0 flows failed due to lack of export packet 0 export packets were sent up to process level 0 export packets were dropped due to no fib 0 export packets were dropped due to adjacency issues 0 export packets were dropped due to fragmentation failures 0 export packets were dropped due to encapsulation fixup failures What does this output indicate?

Medium
1373

A network engineer is troubleshooting IPv6 DMVPN phase 2 spoke-to-spoke tunnel failures. Spoke routers are able to communicate with the hub, but direct spoke-to-spoke traffic is not working. Router R1 (spoke) has the following relevant configuration: interface Tunnel0 ipv6 address 2001:DB8:1::1/64 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ipv6 nhrp network-id 1 ipv6 nhrp nhs 2001:DB8:1::2 ipv6 nhrp map multicast dynamic ! Router R2 (hub) shows: show ipv6 nhrp brief output indicates that both spokes are registered. What is the root cause?

Hard
1374

A network engineer is configuring a GRE tunnel between two Cisco IOS-XE routers to transport multicast traffic. The engineer notices that multicast packets are not being forwarded through the tunnel. Which action should the engineer take to enable multicast over the GRE tunnel?

Medium
1375

A network engineer runs the following command on Router R1: R1# show ip eigrp topology all-links EIGRP-IPv4 Topology Table for AS(100)/ID(192.168.1.1) Codes: P - Passive, A - Active, U - Update, Q - Query, R - Reply, r - reply Status, s - sia Status P 10.10.10.0/24, 1 successors, FD is 28160, Qos: 0 via 10.1.1.2 (28160/28160), GigabitEthernet0/0 via 10.2.2.2 (28672/28160), GigabitEthernet0/1 P 10.20.20.0/24, 1 successors, FD is 28160, Qos: 0 via 10.2.2.2 (28160/28160), GigabitEthernet0/1 via 10.3.3.2 (28672/28160), GigabitEthernet0/2 Based on this output, which statement is correct?

Medium
1376

What is the default CoPP aggregate policer rate for control plane traffic on a Cisco IOS-XE device?

Hard
1377

A network engineer runs the following command on router R2: R2# show monitor session 4 Session 4 --------- Type : ERSPAN Source Session Status : Admin Enabled Source Ports : Both : Gi0/0 Destination IP : 192.168.1.10 Origin IP : 10.0.0.2 ERSPAN ID : 100 Based on this output, which statement is correct?

Medium
1378

A network engineer runs the following command to troubleshoot a Control Plane Policing (CoPP) issue: R1# show policy-map control-plane input class class-default Class-map: class-default (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any police: cir 1000000 bps, bc 31250 bytes, be 31250 bytes conformed 0 packets, 0 bytes; actions: transmit violated 0 packets, 0 bytes; actions: drop conformed 0 bps, exceed 0 bps, violated 0 bps What does this output indicate?

Medium
1379

A network engineer configures a Flexible NetFlow monitor to capture traffic on a router's WAN interface. The flow record includes 'match ipv4 source address', 'match ipv4 destination address', and 'collect counter bytes'. After applying the monitor, 'show flow monitor name MONITOR cache' shows flows, but the collector receives no data. 'show flow exporter name EXPORTER statistics' shows 'Export packets sent: 0'. What is the most likely cause?

Medium
1380

A network engineer runs the following command on Router R1: R1# show bgp neighbors 10.1.12.2 received-routes BGP table version is 15, local router ID is 10.1.1.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter, x best-external, a additional-path, c RIB-compressed, Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 10.2.2.0/24 10.1.12.2 0 0 65002 i Total number of prefixes 1 Based on this output, what can be inferred about the BGP session?

Easy
1381

Router R6 has the following configuration: ``` interface GigabitEthernet0/7 ip address 10.6.6.6 255.255.255.0 ! route-map PBR-MISS permit 10 match ip address 104 set ip next-hop 192.168.4.1 ! access-list 104 permit ip 10.6.6.0 0.0.0.255 192.168.0.0 0.0.255.255 ``` What is missing in this configuration?

Medium
1382

A network engineer runs the following command on Router R1: R1# show ipv6 interface gigabitethernet 0/0 | include uRPF IPv6 uRPF: strict mode Based on this output, which statement is true?

Medium
1383

A network engineer runs the following command to troubleshoot an OSPF adjacency issue: R1# debug ip ospf adj *Mar 1 00:12:34.567: OSPF-1 ADJ RtrA: Interface GigabitEthernet0/0 going Up *Mar 1 00:12:34.568: OSPF-1 ADJ RtrA: 2 Way Communication to 10.1.1.2 on GigabitEthernet0/0, state 2WAY *Mar 1 00:12:34.570: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Our router ID 1.1.1.1, his router ID 2.2.2.2 *Mar 1 00:12:34.571: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Neighbor is not DR, state 2WAY *Mar 1 00:12:34.572: OSPF-1 ADJ RtrA: NBR 10.1.1.2: DR is 10.1.1.2, BDR is 10.1.1.1 *Mar 1 00:12:34.573: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Build the Start DBD *Mar 1 00:12:34.574: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Master/Slave negotiation done *Mar 1 00:12:34.576: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Exchange done, loading started *Mar 1 00:12:34.578: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Loading done *Mar 1 00:12:34.580: OSPF-1 ADJ RtrA: NBR 10.1.1.2: Full What does this output indicate?

Medium
1384

A network engineer is configuring a GRE tunnel between two Cisco IOS routers to transport multicast traffic. The engineer notices that multicast packets are not being forwarded over the tunnel. Which command is required on the tunnel interface to enable multicast forwarding?

Easy
1385

A network engineer runs the following command on Router R1: R1# show ip ospf interface GigabitEthernet0/0 GigabitEthernet0/0 is up, line protocol is up Internet Address 192.168.12.1/24, Area 0 Process ID 1, Router ID 10.1.1.1, Network Type BROADCAST, Cost: 10 Transmit Delay is 1 sec, State BDR, Priority 1 Designated Router (ID) 10.1.1.2, Interface address 192.168.12.2 Backup Designated router (ID) 10.1.1.1, Interface address 192.168.12.1 Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5 oob-resync timeout 40 Hello due in 00:00:03 Neighbor Count is 1, Adjacent neighbor count is 1 Adjacent with neighbor 10.1.1.2 (Designated Router) Suppress hello for 0 neighbor(s) Based on this output, which statement is correct?

Medium
1386

Given the following configuration on a router: ``` router ospf 1 distance 150 ``` What is the effect of this configuration?

Medium
1387

A network engineer runs the following command to troubleshoot an IP SLA issue: R1# show ip sla monitor statistics 10 Round Trip Time (RTT) for Index 10 Latest RTT: 12 ms Latest RTT (milliseconds): 12 Latest RTT (microseconds): 12000 Last operation start time: 12:34:56.789 UTC Mon Mar 1 2021 Last operation return code: OK Number of successes: 100 Number of failures: 0 Operation time to live: Forever What does this output indicate?

Easy
1388

Which LSA type is used by OSPF to advertise prefixes from other routing protocols (redistribution) and has a default metric of 20?

Medium
1389

A network engineer is deploying DMVPN Phase 3 with IPsec protection on a Cisco IOS router acting as a hub. The engineer wants to ensure that spoke-to-spoke traffic is encrypted and that spoke routers can dynamically establish direct tunnels. Which two statements are true about this deployment? (Choose two.)

Hard
1390

A network engineer configures a DMVPN spoke with OSPF as the routing protocol: interface Tunnel0 ip address 10.0.0.2 255.255.255.0 ip nhrp network-id 100 ip nhrp nhs 10.0.0.1 tunnel source GigabitEthernet0/0 tunnel mode gre multipoint ip nhrp map 10.0.0.1 192.168.1.1 ip nhrp map multicast 192.168.1.1 ! router ospf 1 network 10.0.0.0 0.0.0.255 area 0 ! What is a common issue with OSPF in this DMVPN Phase 2 configuration?

Medium
1391

A network engineer is configuring a Cisco IOS router to support MPLS Layer 3 VPNs. The engineer needs to enable the provider edge (PE) router to exchange VPNv4 routes with other PE routers. Which protocol is used to distribute VPNv4 routes between PE routers?

Easy
1392

A network engineer is configuring a Cisco IOS router as a DHCP relay agent. The router's interface GigabitEthernet0/0 is connected to a client subnet, and the DHCP server is located at 10.1.1.100. The engineer wants the router to forward DHCP requests from clients to the server and ensure that the server can assign addresses from the correct pool. Which command is required on the router?

Easy
1393

A network engineer runs the following command on Router R1: R1# show ip sla statistics 4 Round Trip Time (RTT) for Index 4 Latest RTT: 300 ms Latest RTT (milliseconds): 300 Latest RTT (microseconds): 300000 Number of successes: 45 Number of failures: 55 Operation time to live: Forever Output: Over threshold R1# show track 2 Track 2 IP SLA 4 reachability Reachability is Down 5 changes, last change 00:00:05 Latest operation return code: Over threshold Latest RTT (milliseconds): 300 Tracked by: ip route 0.0.0.0 0.0.0.0 192.168.2.1 track 2 Based on this output, which statement is correct?

Hard
1394

A network engineer runs the following command on Router R1: R1# show ip vrf detail RED VRF RED (VRF Id = 1); default RD <not set> Interfaces: GigabitEthernet0/2 Loopback1 Address family IPV4 (Table ID = 1): No Export VPN route-target communities No Import VPN route-target communities No import route-map No export route-map VRF label distribution protocol: not configured Address family IPV6 (Table ID = 0x1E000001): No Export VPN route-target communities No Import VPN route-target communities No import route-map No export route-map VRF label distribution protocol: not configured Based on this output, which statement is correct?

Medium
1395

In OSPF, what is the default behavior for auto-summary on Cisco IOS-XE?

Hard
1396

An engineer is troubleshooting a network where R1 and R2 are running EIGRP, and R2 redistributes a static route for 192.168.1.0/24 into EIGRP. R1 also learns the same prefix via OSPF from R3 with an AD of 110. The engineer observes that R1 prefers the EIGRP external route (AD 170) over the OSPF route. What configuration change would cause this behavior?

Hard
1397

A network engineer runs the following command to troubleshoot an RSPAN issue: R1# show monitor session 4 detail Session 4 --------- Type : Remote Destination Session Source RSPAN VLAN : 100 Destination Ports : Gi0/2 Encapsulation : Native Ingress : Disabled What does this output indicate?

Medium
1398

A network engineer runs the following command to troubleshoot an EEM issue: R1# debug event manager action cli EEM Action CLI debugging is on R1# Mar 1 00:10:15.123: %HA_EM-6-ACTION: applet TRACK-INTERFACE: action cli command: 'show ip int brief' executed Mar 1 00:10:15.456: %HA_EM-6-ACTION: applet TRACK-INTERFACE: action cli output: 'Interface IP-Address OK? Method Status Protocol GigabitEthernet0/0 192.168.1.1 YES NVRAM up up GigabitEthernet0/1 10.0.0.1 YES NVRAM up up Loopback0 1.1.1.1 YES NVRAM up up' What does this output indicate?

Hard
1399

What is the default DHCPv4 renewal time (T1) as a percentage of the lease time?

Medium
1400

In MPLS L3VPN, what is the purpose of the Route Distinguisher (RD)?

Easy
1401

In IPv6 First Hop Security, which feature is used to prevent duplicate address detection (DAD) attacks by snooping Neighbor Discovery (ND) messages?

Medium

Frequently asked questions

What does the troubleshooting domain cover on the 300-410 exam?
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 1401 troubleshooting questions in the 300-410 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only troubleshooting questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.