Courseiva

CCNA Infrastructure Services Questions

75 of 106 questions · Page 1/2 · Infrastructure Services topic · Answers revealed

1
MCQhard

A network engineer is configuring a Cisco IOS XE router to act as a DHCPv6 relay agent. The router is connected to a LAN segment with DHCPv6 clients and must forward DHCPv6 messages to a DHCPv6 server at 2001:DB8::100. The engineer has configured the interface with ipv6 address 2001:DB8:1::1/64 and ipv6 enable. Which command is required to enable DHCPv6 relay on the interface?

A.ipv6 dhcp server 2001:DB8::100
B.ipv6 helper-address 2001:DB8::100
C.ipv6 nd managed-config-flag
D.ipv6 dhcp relay destination 2001:DB8::100
AnswerD

The ipv6 dhcp relay destination command configures the interface as a DHCPv6 relay agent and specifies the destination DHCPv6 server address. This command is applied to the interface facing the clients. The router will then forward DHCPv6 messages from clients to the specified server and relay responses back. Without this command, the router will not relay DHCPv6 messages, and clients will not receive addresses from the remote server.

Why this answer

To configure a Cisco IOS XE router as a DHCPv6 relay agent, you must use the ipv6 dhcp relay destination command on the interface facing the clients. This command specifies the DHCPv6 server address to which client messages are forwarded. It is the direct analog to the IPv4 ip helper-address command, but with IPv6-specific syntax.

Without it, the router will not relay DHCPv6 messages, and clients will not receive addresses from the remote server. The other options either configure the router as a server or set RA flags, neither of which enables relay.

Exam trap

The trap here is assuming the IPv6 relay command follows the IPv4 ip helper-address pattern, but Cisco IOS XE uses ipv6 dhcp relay destination instead.

2
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate a branch office VPN client with a digital certificate. The certificate is issued by an external CA, and the engineer must ensure that the router can validate the certificate chain. Which command is required to install the CA certificate?

A.crypto pki authenticate name
B.crypto pki import name certificate
C.crypto pki enroll name
D.crypto pki trustpoint name
AnswerA

The crypto pki authenticate command retrieves and installs the CA certificate, which is necessary for the router to validate client certificates. It authenticates the CA by obtaining its self-signed certificate and installing it into the router's certificate store. This step is mandatory before the router can trust certificates issued by that CA, enabling proper certificate chain validation for the VPN client.

Why this answer

To validate certificates issued by an external CA, the router must first obtain the CA's own certificate. The crypto pki authenticate command performs this by retrieving the CA certificate and installing it as a trusted certificate. This step is a prerequisite for any PKI operations that rely on that CA, such as verifying client certificates during VPN authentication.

Exam trap

The trap here is confusing authentication with enrollment, assuming that requesting a router certificate also installs the CA certificate.

3
MCQhard

A network engineer is configuring an MPLS L3VPN on a Cisco IOS XE PE router. The customer edge (CE) router uses eBGP to peer with the PE router. The engineer wants to ensure that the CE can advertise its routes to the PE and that the PE can propagate them to other PE routers via MP-BGP. The engineer has configured the VRF, the PE-CE eBGP session, and MP-BGP on the PE. However, the routes from the CE are not appearing in the MP-BGP table. Which configuration step is most likely missing on the PE router?

A.The PE router must be configured with 'neighbor <CE-IP> remote-as <AS>' under the global BGP configuration.
B.The PE router must be configured with 'router bgp <AS>' and 'address-family vpnv4 unicast' to enable MP-BGP.
C.The PE router must have 'ip vrf forwarding CUSTOMER' applied to the interface facing the CE.
D.The VRF must be enabled for IPv4 unicast address family under the BGP router configuration.
AnswerD

In Cisco IOS XE, when using MP-BGP for MPLS L3VPN, each VRF must have an address family configured under the BGP process. Specifically, the 'address-family ipv4 vrf CUSTOMER' command must be present, and the eBGP neighbor must be activated within that address family. Without this, BGP will not exchange routes for that VRF, even if the global BGP session is up.

Why this answer

In MPLS L3VPN, the PE router must configure a separate BGP address family for each VRF to exchange routes with CE routers. The 'address-family ipv4 vrf CUSTOMER' command under 'router bgp' activates the VRF context, and the eBGP neighbor must be activated within that address family. Without this, routes from the CE are not imported into BGP and thus not propagated via MP-BGP to other PEs.

Exam trap

The trap here is focusing on the global BGP neighbor configuration or the VPNv4 address family, while overlooking the necessity of the per-VRF IPv4 address family for CE peering.

4
MCQmedium

A network engineer is configuring a Cisco IOS XE router to support First Hop Redundancy Protocol (FHRP) for a group of hosts on VLAN 10. The design requires that the virtual IP address and virtual MAC address remain the same even if the active router changes. The engineer decides to use Virtual Router Redundancy Protocol (VRRP) version 2. Which statement about VRRPv2 is true?

A.VRRPv2 allows preemption to be disabled only on the master router.
B.VRRPv2 supports IPv6 natively without any additional configuration.
C.VRRPv2 uses multicast address 224.0.0.2 for hello packets.
D.VRRPv2 uses a virtual MAC address of 0000.0c07.acXX, where XX is the group ID in hexadecimal.
AnswerD

VRRPv2 uses a virtual MAC address derived from the VRRP group ID. The format is 0000.0c07.acXX, where XX is the group ID in hexadecimal. This ensures that the virtual MAC remains consistent regardless of which router is the master. The virtual IP and MAC are maintained during failover, providing seamless redundancy. This is a key characteristic of VRRP, distinguishing it from HSRP, which uses a different MAC format.

Why this answer

VRRPv2 uses the virtual MAC address 0000.0c07.acXX, where XX is the VRRP group ID in hexadecimal. This ensures a consistent virtual MAC for hosts, regardless of which physical router is master. The other statements are incorrect: VRRPv2 does not support IPv6 (that requires VRRPv3), it uses multicast 224.0.0.18 (not 224.0.0.2), and preemption can be disabled on any router, not just the master.

Exam trap

The trap here is mixing up VRRPv2 details with HSRP, such as the multicast address and MAC address format.

5
MCQmedium

A network engineer is configuring a Cisco IOS XE router as a Dynamic Multipoint VPN (DMVPN) Phase 3 hub. The hub must support spoke-to-spoke direct tunnels while allowing the hub to remain in the data path for initial spoke-to-spoke communication. The engineer has configured the tunnel interface with 'ip nhrp redirect' on the hub. Which additional command must be configured on the spoke routers to enable them to dynamically create direct tunnels to other spokes?

A.ip nhrp map multicast dynamic
B.ip nhrp holdtime 300
C.ip nhrp shortcut
D.ip nhrp network-id 100
AnswerC

The ip nhrp shortcut command on the spoke enables it to intercept transit traffic that the hub redirects. When the hub sends an NHRP redirect message, the spoke creates a shortcut entry in its NHRP mapping table and can then establish a direct tunnel to the destination spoke. Without this command, the spoke continues to forward all traffic through the hub.

Why this answer

In DMVPN Phase 3, the hub uses ip nhrp redirect to inform a spoke that a better path exists. The spoke must have ip nhrp shortcut configured to act on that redirect, install a shortcut route, and initiate a direct tunnel to the destination spoke. This combination allows dynamic spoke-to-spoke tunnels while the hub remains involved only for initial resolution.

Exam trap

The trap here is confusing hub-side commands like ip nhrp redirect with spoke-side commands needed to create shortcuts, or assuming that basic NHRP configuration alone enables Phase 3 behavior.

6
MCQmedium

A company has a Cisco IOS XE router configured with IP SLA and Object Tracking to monitor the reachability of a primary ISP. The router should fail over to a backup ISP when the primary path becomes unreachable. The engineer wants to ensure that the failover occurs quickly and that the primary path is restored when it becomes available again. Which configuration element is required to achieve this behavior?

A.A floating static route with a higher administrative distance to the backup ISP
B.A route map that matches the primary ISP's next-hop and sets the local preference
C.An IP SLA operation with a track object that is referenced by a static route to the primary ISP
D.A static route with a lower administrative distance pointing to the backup ISP
AnswerC

IP SLA operations can monitor reachability by sending probes such as ICMP echoes. The track object tracks the state of the SLA operation. When the tracked object goes down, any static route referencing that object is removed from the routing table, allowing the backup route to be used. When the SLA recovers, the primary route is reinstalled. This provides fast failover and automatic restoration, meeting the requirements.

Why this answer

IP SLA with object tracking allows the router to monitor the primary ISP's reachability. The track object is referenced in the static route to the primary ISP, so when the SLA fails, the route is removed and the backup route (which could be a floating static or a default route) takes over. When the SLA recovers, the primary route is reinstated.

This provides the required fast failover and automatic restoration.

Exam trap

The trap here is thinking that a floating static route alone provides reachability-based failover; it does not without tracking.

7
MCQhard

A company is deploying IPv6 and wants to use stateful DHCPv6 to assign addresses to clients. The network administrator configures the router with the 'ipv6 dhcp pool' command and sets the 'address prefix' and 'dns-server' options. However, clients are not receiving IPv6 addresses. Which additional configuration is required on the client-facing interface to enable stateful DHCPv6?

A.ipv6 nd managed-config-flag
B.ipv6 address autoconfig
C.ipv6 nd other-config-flag
D.ipv6 dhcp server DHCP_POOL
AnswerA

The 'ipv6 nd managed-config-flag' command sets the Managed Address Configuration flag in Router Advertisement messages, instructing clients to use DHCPv6 for address assignment. Without this flag, clients will use stateless autoconfiguration and ignore DHCPv6 for addresses. This is required for stateful DHCPv6 operation.

Why this answer

For stateful DHCPv6, the router must set the Managed Address Configuration flag in Router Advertisements. This is done with 'ipv6 nd managed-config-flag' on the client-facing interface. It tells clients to obtain addresses via DHCPv6.

The other-config-flag only indicates other parameters are available via DHCPv6, and the DHCP server command alone does not force clients to use DHCPv6 for addresses.

Exam trap

The trap here is assuming that configuring the DHCPv6 pool and enabling the DHCPv6 server on the interface is enough, but the managed-config-flag in RA is required to direct clients to use stateful DHCPv6.

8
MCQeasy

A network engineer is configuring a Cisco IOS router to support IPv6 OSPFv3. The engineer wants to enable OSPFv3 on an interface and ensure that it forms adjacencies with neighbors. Which command must be used to enable OSPFv3 on an interface?

A.ipv6 ospf 1 area 0
B.router ospfv3 1
C.ospfv3 1 ipv6 area 0
D.ipv6 router ospf 1
AnswerA

The command ipv6 ospf 1 area 0 is used in interface configuration mode to enable OSPFv3 on an interface and assign it to area 0. This command activates OSPFv3 for IPv6 on that interface, allowing it to form adjacencies. It is the correct way to enable OSPFv3 on a per-interface basis.

Why this answer

To enable OSPFv3 on a specific interface for IPv6, the interface configuration command ipv6 ospf 1 area 0 is used. This command assigns the interface to OSPFv3 process 1 and area 0, allowing it to form adjacencies. Global configuration commands only create the OSPFv3 process; interface activation is required for adjacency formation.

Exam trap

The trap here is confusing global OSPFv3 process creation with interface-level activation, leading to the selection of a global command.

9
MCQeasy

A network administrator is implementing policy-based routing (PBR) on a Cisco IOS router. The goal is to route traffic from a specific subnet (192.168.1.0/24) through a next-hop of 10.1.1.2 instead of the default route. The administrator has created a route map named PBR-MAP and configured a match statement for the subnet. Which action must be configured in the route map to set the next-hop?

A.set interface Null0
B.set ip default next-hop 10.1.1.2
C.set ip precedence 5
D.set ip next-hop 10.1.1.2
AnswerD

The 'set ip next-hop' command in a route map specifies the next-hop IP address for policy-based routing. When applied to an interface, it overrides the normal routing table for matching traffic. This is the correct action to direct traffic from 192.168.1.0/24 to 10.1.1.2. It is the standard method for PBR next-hop configuration.

Why this answer

Policy-based routing uses route maps to match traffic and set actions. The 'set ip next-hop' command is the correct action to specify the next-hop IP address for matching packets. It overrides the routing table for those packets.

The other options either set a default next-hop (used only when no route exists), discard traffic, or mark packets, none of which achieve the goal.

Exam trap

The trap here is confusing 'set ip next-hop' with 'set ip default next-hop', which only applies when no explicit route exists.

10
MCQeasy

A network engineer is configuring a Cisco IOS XE router to support MPLS Layer 3 VPNs. The engineer has enabled MPLS IP on the core interfaces and configured OSPF as the IGP. Which additional configuration is required on the PE routers to exchange VPNv4 routes with other PE routers?

A.Enable BGP with the `address-family vpnv4` configuration and activate neighbors.
B.Enable `mpls ip` on all PE-CE interfaces.
C.Configure `mpls ldp router-id Loopback0` to ensure LDP uses the loopback interface.
D.Configure a route reflector for the IGP to distribute routes between PE routers.
AnswerA

MPLS Layer 3 VPNs require MP-BGP to exchange VPNv4 routes between PE routers. The `address-family vpnv4` configuration enables the VPNv4 address family, and neighbors must be activated within that address family. This allows the PE routers to advertise customer routes with route targets and VPN labels. Without this, VPNv4 routes cannot be exchanged, and the VPN will not function.

Why this answer

MPLS Layer 3 VPNs rely on MP-BGP to distribute VPNv4 routes among PE routers. Enabling the VPNv4 address family and activating neighbors under that address family is mandatory for exchanging customer VPN routes with the associated route targets and labels. Without this BGP configuration, PE routers cannot learn each other's VPN routes, and the VPN will not operate.

Exam trap

The trap here is assuming that MPLS LDP or IGP configurations are sufficient for VPN route exchange, when MP-BGP is the key component.

11
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a Dynamic Host Configuration Protocol (DHCP) relay agent. The router receives DHCP broadcast requests on interface GigabitEthernet0/1 and must forward them to a DHCP server at 10.1.1.100. Which command is required to enable this functionality?

A.ip helper-address 10.1.1.100
B.ip dhcp pool 10.1.1.100
C.ip dhcp relay 10.1.1.100
D.ip forward-protocol udp 10.1.1.100
AnswerA

The ip helper-address command, configured on the interface receiving the DHCP broadcasts, forwards these UDP broadcasts (ports 67 and 68) to the specified server as unicast packets. This allows a single DHCP server to service multiple subnets without being directly attached to each. It is the correct and standard method for DHCP relay on Cisco IOS.

Why this answer

To configure a Cisco IOS router as a DHCP relay agent, you must enable the forwarding of DHCP broadcasts to a specific server. The ip helper-address command on the ingress interface accomplishes this by converting broadcast DHCP requests into unicast packets destined for the configured server. Other options either configure local DHCP server functionality or are invalid commands.

Exam trap

The trap here is confusing the DHCP relay command with the DHCP server pool configuration command, or assuming that ip forward-protocol alone can specify a server address.

12
MCQmedium

A network engineer is configuring SNMPv3 on a Cisco IOS router. The requirement is to authenticate and encrypt SNMP messages using the user 'admin' with SHA authentication and AES encryption. Which command correctly configures the SNMPv3 user?

A.snmp-server user admin group auth sha authpass priv sha privpass
B.snmp-server user admin group auth md5 authpass priv des privpass
C.snmp-server user admin group auth sha authpass priv aes 128 privpass
D.snmp-server user admin group auth sha authpass priv 3des privpass
AnswerC

This command creates an SNMPv3 user 'admin' with SHA authentication and AES 128-bit encryption. The 'auth sha' specifies SHA authentication, and 'priv aes 128' specifies AES encryption with a 128-bit key. This meets the requirement for both authentication and encryption.

Why this answer

The snmp-server user command with 'auth sha' and 'priv aes 128' correctly configures SNMPv3 with SHA authentication and AES encryption. This provides both message integrity and confidentiality, meeting the security requirements for the SNMPv3 user.

Exam trap

The trap here is mixing up authentication and encryption algorithms, such as using a hash function like SHA for privacy, which is not a valid encryption method.

13
MCQmedium

A network engineer is configuring a Cisco router as a Dynamic Host Configuration Protocol (DHCP) server for a remote subnet. The router's interface that connects to the remote subnet is GigabitEthernet0/1 with IP address 10.10.10.1/24. The engineer wants the router to assign addresses from the 10.10.10.0/24 pool to clients on that subnet. Which command must be issued in DHCP pool configuration mode to specify the default gateway that clients will receive?

A.default-router 10.10.10.1
B.ip default-gateway 10.10.10.1
C.default-gateway 10.10.10.1
D.gateway 10.10.10.1
AnswerA

The default-router command in DHCP pool configuration mode specifies the default gateway address that DHCP clients receive. In this scenario, the router's interface on the remote subnet is 10.10.10.1, so this is the correct gateway. This command is essential for clients to reach other networks, and it is a standard part of Cisco IOS DHCP server configuration. Without it, clients would lack a default route.

Why this answer

In Cisco IOS DHCP server configuration, the default-router command within the DHCP pool defines the default gateway address provided to clients. Since the router's interface on the remote subnet is 10.10.10.1, that address is the correct gateway. The other commands either apply to the router's own gateway or are invalid, so they would not fulfill the requirement.

Exam trap

The trap here is confusing the router's own default gateway configuration with the DHCP server's client gateway assignment.

14
MCQeasy

A network engineer is configuring a Cisco IOS router to support MPLS L3VPN. The router will act as a PE router and needs to assign a unique identifier to each customer VRF to allow overlapping address spaces. Which MPLS L3VPN component provides this function?

A.Route Target
B.VPN Label
C.BGP Extended Community
D.Route Distinguisher
AnswerD

The Route Distinguisher (RD) is an 8-byte value prepended to an IPv4 prefix to make it unique within the MPLS L3VPN domain. It allows different customers to use the same address space without conflict. Each VRF is assigned an RD, which is used in MP-BGP VPNv4 updates. Without an RD, overlapping customer prefixes would be ambiguous in the provider's BGP table.

Why this answer

The Route Distinguisher (RD) is the MPLS L3VPN component that provides a unique identifier for each customer VRF, allowing overlapping IPv4 address spaces. By prepending the RD to customer prefixes, MP-BGP creates VPNv4 routes that are globally unique. This enables the service provider to carry multiple customers' routes without conflict.

The RD is configured under the VRF definition and is essential for MPLS L3VPN operation.

Exam trap

The trap here is confusing the Route Distinguisher with the Route Target, as both are BGP attributes used in MPLS L3VPN but serve different purposes.

15
MCQmedium

A network engineer is configuring a Cisco IOS XE router to support a DMVPN Phase 3 hub-and-spoke topology. The hub router must be able to redirect spoke-to-spoke traffic without requiring the spokes to have a direct route to each other. Which technology should be implemented on the hub to enable the hub to inform the originating spoke of the optimal spoke-to-spoke path?

A.Multipoint GRE (mGRE)
B.NHRP redirect
C.IPsec tunnel protection
D.Next Hop Resolution Protocol (NHRP) shortcut
AnswerB

NHRP redirect is a DMVPN Phase 3 feature that enables the hub to send an NHRP redirect message to the originating spoke when it detects traffic being routed through the hub to another spoke. The redirect instructs the spoke to initiate an NHRP resolution request for the destination spoke's NBMA address, allowing the spoke to build a direct tunnel. This reduces latency and hub load, and it is the correct mechanism for the hub to inform the spoke of the optimal path.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to notify the originating spoke that a better path exists directly to the destination spoke. The spoke then sends an NHRP resolution request for the destination spoke's NBMA address and, upon receiving a reply, establishes a direct tunnel. This optimizes traffic flow and reduces hub load.

NHRP shortcut on the spoke caches the direct path, but the hub's redirect is the trigger.

Exam trap

The trap here is confusing NHRP shortcut with NHRP redirect; shortcut is on the spoke, redirect is on the hub.

16
MCQeasy

A network administrator is configuring a Cisco IOS router to use NAT overload (PAT) for a small office. The inside network is 192.168.1.0/24, and the router's outside interface is GigabitEthernet0/0 with IP address 203.0.113.5. The administrator enters the following commands: access-list 1 permit 192.168.1.0 0.0.0.255 ip nat inside source list 1 interface GigabitEthernet0/0 overload interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ip nat inside interface GigabitEthernet0/0 ip address 203.0.113.5 255.255.255.0 ip nat outside However, hosts on the inside network cannot access the Internet. Which command is missing?

A.ip nat inside source list 1 pool overload
B.ip nat inside source static 192.168.1.0 203.0.113.5
C.ip route 0.0.0.0 0.0.0.0 203.0.113.1
D.ip nat pool overload 203.0.113.5 203.0.113.5 netmask 255.255.255.0
AnswerC

The router needs a default route to forward traffic to the Internet. Without it, the router does not know where to send packets destined for outside networks. The NAT configuration only translates addresses; it does not provide routing. Adding a default route via the next-hop ISP router (203.0.113.1) enables the router to forward translated packets, allowing inside hosts to reach the Internet.

Why this answer

The NAT configuration correctly translates inside addresses to the outside interface address using PAT. However, the router lacks a default route to reach the Internet. Without a default route pointing to the ISP's next-hop address, the router cannot forward packets beyond its directly connected networks, so inside hosts cannot access external destinations.

Exam trap

The trap here is focusing on NAT configuration details when the actual problem is the absence of a default route, which is a common oversight in NAT troubleshooting.

17
MCQhard

A network engineer is troubleshooting a DHCP relay configuration on a Cisco IOS router. The router is configured with the ip helper-address 10.1.1.1 command on interface GigabitEthernet0/0, but clients on the 192.168.1.0/24 subnet are not receiving IP addresses from the DHCP server at 10.1.1.1. The engineer verifies that the DHCP server is operational and has a pool for 192.168.1.0/24. What is the most likely cause?

A.The DHCP relay agent is not enabled globally with the service dhcp command.
B.The DHCP server does not have a route back to the 192.168.1.0/24 subnet.
C.The ip helper-address command must be configured with the subnet mask of the DHCP server.
D.The ip helper-address command is configured on the wrong interface.
AnswerB

For DHCP relay to work, the DHCP server must have a route back to the client subnet to send the DHCPOFFER. If the server lacks a route to 192.168.1.0/24, it cannot deliver the offer, and clients will not receive addresses. This is a common oversight when the server is on a different subnet and no default gateway or static route is configured.

Why this answer

The most likely cause is that the DHCP server does not have a route back to the 192.168.1.0/24 subnet. Without a return route, the server cannot send DHCPOFFER messages to the relay agent, so clients never receive an address. The other options are either incorrect syntax or not applicable because the relay agent is typically enabled by default and the helper address is on the correct interface.

Exam trap

The trap here is assuming that the DHCP relay configuration is at fault when the issue is actually on the DHCP server side, specifically the lack of a return route to the client subnet.

18
MCQeasy

A network technician is configuring a Cisco router to act as a DHCP relay agent. The router's interface Gi0/0 is connected to the DHCP clients, and the DHCP server is reachable via interface Gi0/1. Which command must be configured on interface Gi0/0 to forward DHCP requests to the server at 192.168.1.10?

A.ip forward-protocol udp 192.168.1.10
B.ip dhcp relay 192.168.1.10
C.ip helper-address 192.168.1.10
D.ip dhcp-server 192.168.1.10
AnswerC

The 'ip helper-address' command is used on the interface facing the DHCP clients to forward broadcast DHCP requests to a specific DHCP server. It converts the broadcast to a unicast packet destined for the server. This is the correct command to enable DHCP relay functionality on the client-facing interface.

Why this answer

To configure a Cisco router as a DHCP relay agent, the 'ip helper-address' command is applied on the interface receiving DHCP broadcasts. It forwards these broadcasts as unicasts to the specified DHCP server. This allows clients on one subnet to obtain IP addresses from a server on another subnet.

Other commands like 'ip forward-protocol' are supplementary and do not specify the server.

Exam trap

The trap here is thinking that a dedicated DHCP relay command exists, such as 'ip dhcp relay', when in fact Cisco IOS uses the generic 'ip helper-address' to forward DHCP and other UDP broadcasts.

19
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer wants to ensure that the authentication key is not sent in clear text and that the key can be changed without disrupting the adjacency. Which command should be used to configure the key on the interface?

A.area 0 authentication message-digest
B.ip ospf authentication message-digest
C.ip ospf message-digest-key <key-id> md5 <key>
D.ip ospf authentication-key <key>
AnswerC

The 'ip ospf message-digest-key' command with the 'md5' keyword configures an MD5 key for OSPFv2 authentication on an interface. The key is not sent in clear text; instead, an MD5 hash is used. Multiple keys can be configured with different key IDs, allowing for graceful key rollover without disrupting the adjacency. This meets both requirements.

Why this answer

To configure an MD5 key for OSPFv2 authentication on an interface, the 'ip ospf message-digest-key' command is used. The key is hashed and not sent in clear text. By configuring multiple keys with different key IDs, you can change the key without disrupting the adjacency.

The other options either configure plaintext authentication or enable authentication without setting the key.

Exam trap

The trap here is confusing the command that enables MD5 authentication with the command that actually configures the MD5 key, leading to incomplete authentication setup.

20
MCQeasy

A network engineer configures a Cisco IOS router as a DHCP relay agent. The router interface connected to the DHCP clients is configured with 'ip helper-address 192.168.1.10'. Which type of traffic will be forwarded to the DHCP server at 192.168.1.10 by default?

A.Only unicast packets destined to the DHCP server's IP address.
B.Only UDP broadcasts for DHCP (ports 67 and 68).
C.UDP broadcasts for DHCP, TFTP, DNS, NetBIOS, and several other services.
D.All IP broadcasts, including DHCP, TFTP, DNS, and NetBIOS.
AnswerC

By default, the 'ip helper-address' command forwards UDP broadcasts for a predefined set of services, including DHCP (ports 67/68), TFTP (69), DNS (53), NetBIOS (137/138), and others like BOOTP and TACACS. This allows clients to reach servers on different subnets without additional configuration.

Why this answer

The 'ip helper-address' command forwards UDP broadcasts for a default set of services, including DHCP, TFTP, DNS, NetBIOS, and others. This allows clients to communicate with servers on different subnets. The command is not limited to DHCP, nor does it forward all broadcasts.

Exam trap

The trap here is assuming that the helper address only forwards DHCP broadcasts, when in fact it forwards a broader set of UDP services by default.

21
MCQeasy

A network administrator is configuring a Cisco IOS XE router to support IPv6. The administrator wants to enable IPv6 routing and assign an IPv6 address to an interface. Which command must be configured globally to enable IPv6 routing?

A.ipv6 address autoconfig
B.ip routing ipv6
C.ipv6 enable
D.ipv6 unicast-routing
AnswerD

The global command 'ipv6 unicast-routing' enables IPv6 unicast routing on the router. Without it, the router can still have IPv6 addresses on interfaces, but it will not forward IPv6 packets or participate in IPv6 routing protocols. This command is required to make the router act as an IPv6 router. It is the correct answer for enabling IPv6 routing globally.

Why this answer

To enable IPv6 routing on a Cisco IOS XE router, the global command 'ipv6 unicast-routing' must be configured. This allows the router to forward IPv6 packets and run IPv6 routing protocols. Interface commands like 'ipv6 enable' or 'ipv6 address autoconfig' are used for address configuration but do not enable global routing.

The command 'ip routing ipv6' is invalid.

Exam trap

The trap here is thinking that configuring an IPv6 address on an interface automatically enables routing; it does not.

22
Multi-Selecthard

A network engineer is implementing MPLS Traffic Engineering (TE) with RSVP-TE. The engineer must ensure that the TE tunnel can be established and that the headend router can signal the path. Which two statements about RSVP-TE operation are true? (Choose two.)

Select 2 answers
A.RSVP-TE uses the Resource Reservation Protocol to reserve bandwidth along the path of a TE tunnel.
B.RSVP-TE automatically computes the shortest path for the tunnel without any explicit configuration.
C.RSVP-TE uses LDP to distribute labels for the TE tunnel.
D.RSVP-TE signaling requires that all routers along the path support RSVP and have it enabled on the relevant interfaces.
E.RSVP-TE reservations are unidirectional, so a separate tunnel is needed for the return traffic.
AnswersA, D

RSVP-TE extends RSVP to support traffic engineering by reserving resources (bandwidth) along the explicit path of a TE tunnel. The headend router sends PATH messages that include the requested bandwidth and other constraints. Each router along the path reserves the requested resources if available and forwards the PATH message. This reservation ensures that the TE tunnel has the required bandwidth, enabling deterministic traffic handling.

Why this answer

RSVP-TE reserves bandwidth along the explicit path of a TE tunnel using PATH and RESV messages. All routers along the path must support and enable RSVP on relevant interfaces for signaling to succeed. RSVP-TE does not use LDP for label distribution; it handles labels itself.

Path computation is done by CSPF on the headend, not automatically by RSVP. Reservations are unidirectional, but a separate return tunnel is not always required.

Exam trap

The trap here is assuming that RSVP-TE relies on LDP for label distribution or that it automatically computes paths without explicit configuration, when in fact RSVP-TE signals labels itself and requires an explicit or CSPF-computed path.

23
MCQmedium

A network engineer is deploying an MPLS L3VPN using BGP as the PE-CE routing protocol. The customer requires that the PE router accept only routes with a specific BGP community and set a local preference of 200 for those routes. Which configuration on the PE router accomplishes this requirement?

A.Configure a route-map that matches the community and sets local preference, then apply it as an outbound route-map under the BGP neighbor configuration for the CE.
B.Configure a distribute-list with an extended ACL that matches the community and sets local preference under the BGP process.
C.Configure a route-map that matches the community and sets local preference, then apply it as an inbound route-map under the BGP neighbor configuration for the CE.
D.Use the BGP network command with a backdoor route to inject the routes with the desired local preference.
AnswerC

Applying an inbound route-map on the PE-CE BGP session allows matching the community and setting local preference before the route is installed in the VRF BGP table. This ensures only desired routes are accepted with the correct preference.

Why this answer

Inbound route-maps on the PE-CE BGP session are the correct tool to match BGP communities and modify attributes such as local preference. They allow granular control over which routes are accepted and how they are treated within the VRF. Outbound route-maps affect advertisements, distribute-lists cannot set attributes, and the network command does not provide community-based filtering.

Exam trap

The trap here is confusing inbound and outbound route-map directions, leading to applying policy on the wrong side of the BGP session.

24
MCQmedium

A network engineer is configuring a Cisco IOS XE router to support MPLS Traffic Engineering (TE) with RSVP-TE. The engineer has enabled MPLS TE globally and on the interfaces. The engineer wants to ensure that the router can signal an LSP with a specific bandwidth requirement of 100 Mbps. Which command is required to enable RSVP-TE signaling on the interface?

A.ip rsvp bandwidth 100000
B.mpls traffic-eng tunnels
C.mpls traffic-eng bandwidth 100000
D.mpls rsvp-te bandwidth 100000
AnswerA

This command enables RSVP-TE signaling on the interface and reserves 100,000 kbps (100 Mbps) of bandwidth for RSVP-TE LSPs. It is required to signal an LSP with a specific bandwidth requirement. The bandwidth value is specified in kilobits per second, so 100 Mbps equals 100,000 kbps. This command allows the interface to participate in RSVP-TE signaling and reserve the requested bandwidth.

Why this answer

To enable RSVP-TE signaling on an interface, the 'ip rsvp bandwidth' command must be configured. This command reserves bandwidth for RSVP-TE LSPs and allows the interface to participate in RSVP signaling. The bandwidth value is specified in kilobits per second, so 100 Mbps is 100,000 kbps.

Without this command, the router cannot signal an LSP with the required bandwidth, even if MPLS TE is enabled globally and on the interface.

Exam trap

The trap here is confusing the global MPLS TE command with the interface-level RSVP-TE bandwidth command.

25
MCQhard

A network engineer is deploying MPLS Layer 3 VPNs on a Cisco IOS XE PE router. The customer VRF CUST_A uses OSPF as the PE-CE routing protocol. The engineer must ensure that OSPF routes from the customer are redistributed into MP-BGP and that the OSPF domain ID is preserved across the MPLS backbone. Which configuration step is required on the PE router?

A.Configure the OSPF process with the capability vrf-lite command and redistribute connected routes into BGP.
B.Configure a route target export and import under the VRF and enable OSPF as the provider core routing protocol.
C.Configure a sham link between PE routers and set the OSPF network type to point-to-point on the PE-CE link.
D.Configure route redistribution from OSPF into BGP under the VRF address family and set a domain ID under router ospf with the same value on all PE routers.
AnswerD

To preserve the OSPF domain ID across the MPLS backbone, the PE router must redistribute OSPF into MP-BGP and use the domain ID feature. Configuring the same domain ID under router ospf for the VRF on all PE routers ensures that OSPF routes retain their domain identity, preventing loops and allowing proper route redistribution into BGP.

Why this answer

Preserving the OSPF domain ID requires redistributing OSPF into MP-BGP and configuring a consistent domain ID under the OSPF process on all PE routers. This ensures that routes carry the domain identifier, which prevents routing loops and maintains OSPF route integrity across the MPLS VPN. Other options either misapply features or do not address domain ID preservation.

Exam trap

The trap here is confusing route targets or sham links with the OSPF domain ID mechanism, which is a specific OSPF process parameter.

26
MCQhard

A service provider is deploying MPLS Traffic Engineering (TE) with RSVP-TE to guarantee bandwidth for critical traffic. The network uses OSPF as the IGP with TE extensions enabled. An engineer notices that a TE tunnel fails to establish because the path computation cannot find a path with sufficient bandwidth, even though the physical links have enough capacity. Which action should the engineer take to ensure that RSVP-TE can reserve bandwidth on the links?

A.Enable MPLS TE on the physical interfaces and configure the ip rsvp bandwidth command with the appropriate reservable bandwidth.
B.Enable MPLS LDP on all interfaces to ensure label distribution for the TE tunnel.
C.Configure the mpls traffic-eng tunnels command under the OSPF process to advertise TE metrics.
D.Configure the ip rsvp bandwidth command under the OSPF process to allow RSVP to reserve bandwidth.
AnswerA

For RSVP-TE to reserve bandwidth, MPLS TE must be enabled on the interface, and the ip rsvp bandwidth command must be configured to define the amount of reservable bandwidth. Without this, the TE tunnel cannot signal reservations, and path computation will fail because no bandwidth is available for reservation, even if the physical link has capacity.

Why this answer

RSVP-TE requires that MPLS TE be enabled on the physical interface and that the interface be configured with the ip rsvp bandwidth command to specify the reservable bandwidth. Without this interface-level configuration, the TE tunnel cannot signal a reservation, and path computation fails due to lack of available bandwidth. OSPF TE extensions are already enabled, so the missing piece is the interface configuration.

Exam trap

The trap here is assuming that enabling OSPF TE extensions or MPLS LDP is sufficient for RSVP-TE bandwidth reservation, when in fact the interface-level RSVP bandwidth configuration is required.

27
Multi-Selecthard

A network engineer is configuring MPLS Traffic Engineering (TE) with RSVP-TE on a Cisco IOS XE router to provide bandwidth guarantees for delay-sensitive traffic. The engineer must ensure that the TE tunnel can signal the required bandwidth and that the path is computed based on available resources. Which two statements about the configuration are true? (Choose two.)

Select 2 answers
A.The ip explicit-path command is used to define a dynamic path that can change based on network conditions.
B.The tunnel mpls traffic-eng bandwidth command specifies the bandwidth to be reserved for the TE tunnel.
C.The mpls traffic-eng tunnels command is only needed on the tunnel headend and not on transit routers.
D.The ip rsvp bandwidth command must be configured on each physical interface along the TE path to enable RSVP reservations.
E.The tunnel destination command is optional if the path is explicitly specified with a dynamic path option.
AnswersB, D

The tunnel mpls traffic-eng bandwidth command under the tunnel interface sets the bandwidth value that RSVP-TE signals along the path. This reservation ensures that the required resources are available on each link. Without it, the tunnel may not receive the necessary guarantees for delay-sensitive traffic, making it a critical configuration step.

Why this answer

To configure MPLS TE with RSVP-TE, the tunnel interface must have the bandwidth reservation set with tunnel mpls traffic-eng bandwidth, and each physical interface along the path must have RSVP enabled with ip rsvp bandwidth. These two steps ensure that the tunnel can signal its bandwidth requirements and that network resources are reserved. Other statements misrepresent the requirements for transit routers, destination configuration, or path types.

Exam trap

The trap here is assuming that RSVP or TE commands are only needed on the headend, or confusing explicit paths with dynamic path computation.

28
MCQmedium

A network administrator is deploying DMVPN Phase 3 with IKEv2. The hub router is configured with a dynamic multipoint VPN tunnel and is using NHRP. Spoke routers are configured to register with the hub. After configuration, the administrator notices that spoke-to-spoke traffic is still going through the hub instead of directly between spokes. Which configuration change is most likely to resolve this issue?

A.Enable NHRP redirect on the hub and NHRP shortcut on the spokes.
B.Configure the hub as a route reflector for BGP.
C.Enable split horizon on the hub's tunnel interface.
D.Change the tunnel mode from GRE multipoint to GRE point-to-point.
AnswerA

In DMVPN Phase 3, NHRP redirect on the hub allows the hub to inform the spoke that a better path exists directly to another spoke. NHRP shortcut on the spokes allows them to install a direct route to the destination spoke based on the redirect message. Without these, spoke-to-spoke traffic will continue to traverse the hub even if a direct path is available. Enabling these features is essential for Phase 3 direct spoke-to-spoke communication.

Why this answer

DMVPN Phase 3 requires NHRP redirect on the hub and NHRP shortcut on the spokes to enable direct spoke-to-spoke communication. The hub uses NHRP redirect to inform a spoke that a more efficient path exists directly to another spoke. The spoke then uses NHRP shortcut to resolve the destination and establish a direct tunnel.

Without these, traffic will continue to flow through the hub.

Exam trap

The trap here is focusing on control plane routing protocols like BGP route reflection, while the issue is about NHRP data plane optimization.

29
MCQmedium

A network engineer is deploying an MPLS Layer 3 VPN for a customer. The customer requires that the provider edge (PE) routers support a unique route distinguisher (RD) per VRF and that the same customer routes be imported into multiple VRFs. Which configuration on the PE router accomplishes this requirement?

A.Configure a unique RD under each VRF and use route targets (RTs) to control import and export of routes between VRFs.
B.Configure a unique RD per VRF and use OSPF areas to import routes into multiple VRFs.
C.Configure the same RD for all VRFs and rely on BGP extended communities for route distribution.
D.Configure a unique RD per VRF and use BGP confederations to import routes into multiple VRFs.
AnswerA

A unique RD per VRF ensures that identical customer prefixes from different VRFs do not conflict in the MP-BGP table. Route targets then define which VRFs import or export those routes, allowing the same customer routes to be imported into multiple VRFs. This is the standard MPLS L3VPN design for overlapping address spaces and shared services.

Why this answer

A unique route distinguisher per VRF ensures that overlapping customer prefixes remain distinct in the MP-BGP VPNv4 table. Route targets, which are BGP extended communities, define import and export policies so that the same customer routes can be imported into multiple VRFs. This combination is the standard method for shared services and overlapping VPNs.

Exam trap

The trap here is confusing the role of the route distinguisher with that of the route target; the RD makes prefixes unique, while the RT controls import/export.

30
MCQeasy

A network administrator is configuring a Cisco IOS XE router to act as a DHCP relay agent. The router is connected to a client subnet on GigabitEthernet0/0 and to a DHCP server at 192.168.1.100 on GigabitEthernet0/1. The administrator enters the command 'ip helper-address 192.168.1.100' on GigabitEthernet0/0. Which statement is true about the behavior of this configuration?

A.The router will forward DHCP requests from clients to the DHCP server, and the server will reply directly to the clients.
B.The router will forward DHCP requests from clients to the DHCP server, but the server will not be able to assign an address because the router does not have a route to the client subnet.
C.The router will drop DHCP requests because it is not configured as a DHCP server.
D.The router will forward DHCP requests from clients to the DHCP server, and the server will reply to the router, which then forwards the reply to the clients.
AnswerD

This is the correct behavior of a DHCP relay agent. The router receives the DHCP discover message from the client, inserts the giaddr (the router's interface IP on the client subnet), and forwards it to the DHCP server. The server uses the giaddr to determine the correct subnet and sends the DHCP offer back to the router's giaddr. The router then forwards the offer to the client. This process is defined in RFC 2131 and is essential for DHCP to work across subnets.

Why this answer

When a Cisco IOS XE router is configured with 'ip helper-address', it acts as a DHCP relay agent. It forwards DHCP discover messages from clients to the specified DHCP server, inserting its own interface IP address as the giaddr. The DHCP server uses the giaddr to select the correct address pool and sends the DHCP offer back to the relay agent.

The relay agent then forwards the offer to the client. This allows DHCP to function across subnets without requiring a DHCP server on every subnet.

Exam trap

The trap here is assuming that the DHCP server replies directly to the client, which is not possible because the client does not yet have an IP address.

31
MCQmedium

A network administrator is deploying a DMVPN Phase 3 hub-and-spoke topology. Spokes must be able to communicate directly with each other without traffic traversing the hub. The administrator has configured NHRP and IPsec on all routers. Which additional configuration is required on the hub to enable direct spoke-to-spoke communication?

A.Enable NHRP shortcut on the hub.
B.Set the tunnel mode to multipoint GRE on the hub.
C.Enable NHRP redirect on the hub.
D.Configure the hub as a route reflector for BGP.
AnswerC

NHRP redirect is essential for DMVPN Phase 3. When the hub receives a packet from one spoke destined to another spoke, it sends an NHRP redirect message to the source spoke, informing it of a better path. The source spoke then initiates an NHRP resolution for the destination spoke's tunnel IP, allowing direct spoke-to-spoke tunnel establishment. Without NHRP redirect, spokes continue sending traffic through the hub even if a direct path exists.

Why this answer

In DMVPN Phase 3, direct spoke-to-spoke communication is achieved by combining NHRP redirect on the hub and NHRP shortcut on the spokes. The hub uses NHRP redirect to inform a spoke that a better path exists to another spoke. The spoke then uses NHRP shortcut to resolve the destination and build a direct tunnel.

Without redirect on the hub, spokes never learn about the direct path and continue to forward traffic through the hub, defeating the purpose of Phase 3.

Exam trap

The trap here is confusing NHRP redirect and NHRP shortcut, placing shortcut on the hub instead of the spokes.

32
MCQeasy

A network engineer is configuring a Cisco IOS router to act as a DHCP relay agent. The router receives DHCP discover messages on interface GigabitEthernet0/1 and must forward them to a DHCP server at 10.1.1.100. Which command is required on the router?

A.ip dhcp relay 10.1.1.100
B.ip forward-protocol udp 67
C.ip helper-address 10.1.1.100
D.ip dhcp server 10.1.1.100
AnswerC

The ip helper-address command is configured on the interface receiving the DHCP broadcasts. It causes the router to forward UDP broadcasts for specific ports, including DHCP, to the specified server. This is the correct and standard way to configure a DHCP relay agent on Cisco IOS. Without it, DHCP discover messages would not reach the server.

Why this answer

To configure a Cisco IOS router as a DHCP relay agent, the ip helper-address command must be applied to the interface where DHCP broadcasts are received. This command forwards the broadcasts as unicast packets to the specified DHCP server. It is the standard and required configuration for this functionality.

Exam trap

The trap here is thinking that a global command like ip forward-protocol udp 67 is sufficient, when the interface-level ip helper-address is what actually directs DHCP requests to a specific server.

33
Multi-Selecthard

A network engineer is deploying MPLS Layer 3 VPNs on Cisco IOS routers. The engineer must ensure that customer routes are properly propagated across the MPLS core and that labels are correctly assigned. Which two protocols are used within the MPLS core to distribute labels and VPNv4 routes? (Choose two.)

Select 2 answers
A.LDP
B.RSVP
C.MP-BGP
E.BGP-LU
AnswersA, C

LDP (Label Distribution Protocol) is used to distribute labels for internal routes within the MPLS core. It maps IP prefixes to labels, enabling label switching for core routing. In an MPLS L3VPN, LDP is responsible for establishing label-switched paths (LSPs) between PE routers, which is essential for forwarding VPN traffic across the core.

Why this answer

In an MPLS L3VPN, LDP is used to distribute labels for core routing, creating LSPs between PE routers. MP-BGP is used to distribute VPNv4 routes and their associated VPN labels between PE routers. Together, they enable the forwarding of customer traffic across the MPLS core with proper VPN isolation.

OSPF, RSVP, and BGP-LU are not the standard protocols for these specific functions.

Exam trap

The trap here is assuming that any routing protocol that distributes labels, such as RSVP or BGP-LU, is used in MPLS L3VPNs, when in fact LDP and MP-BGP are the standard protocols for label and VPN route distribution.

34
MCQmedium

A network engineer is configuring a branch router to obtain its WAN interface IPv4 address from an ISP using DHCP. The provider requires the router to send a specific client identifier. Which command must be applied under the interface configuration to meet this requirement?

A.ip dhcp client hostname BRANCH-ROUTER
B.ip dhcp client client-id ascii BRANCH-ROUTER
C.ip dhcp client request client-id
D.ip dhcp pool BRANCH-ROUTER
AnswerB

The ip dhcp client client-id ascii BRANCH-ROUTER command under the interface configuration sets the DHCP client identifier to the ASCII string BRANCH-ROUTER. This allows the ISP to identify the router uniquely, which is often required for address assignment or authentication. Other options either configure server-side parameters or use incorrect syntax for the client identifier.

Why this answer

The ip dhcp client client-id ascii BRANCH-ROUTER command correctly sets the DHCP client identifier to the ASCII string BRANCH-ROUTER. This is necessary when an ISP requires a specific client identifier for address assignment or authentication. The other options either configure server-side settings or request the identifier from the server, which does not meet the requirement.

Exam trap

The trap here is confusing the client identifier (option 61) with the hostname option (option 12), leading to the selection of ip dhcp client hostname instead of the correct client-id command.

35
Multi-Selectmedium

A network administrator is configuring a GRE tunnel between two Cisco IOS routers. The tunnel must support multicast traffic and be protected by IPsec. Which two statements about the configuration are true? (Choose two.)

Select 2 answers
A.The tunnel mode must be set to gre multipoint to support multicast.
B.The tunnel interface must be configured with a unique IP subnet that is not used elsewhere.
C.IPsec transport mode is required to encrypt the GRE traffic.
D.Multicast traffic is automatically encrypted by IPsec without additional configuration.
E.The tunnel source and destination must be reachable via the underlying physical interface.
AnswersB, E

A GRE tunnel interface requires an IP address and subnet to route traffic over the tunnel. This subnet should be unique and not overlap with other interfaces to avoid routing conflicts. It is typically a private subnet dedicated to the tunnel, allowing dynamic routing protocols to run over the tunnel and exchange routes between sites.

Why this answer

A GRE tunnel requires reachable source and destination addresses for the tunnel to become operational. Additionally, the tunnel interface needs a unique IP subnet to route traffic and run dynamic routing protocols. While IPsec can protect GRE traffic, it is not automatically encrypting multicast, and transport mode is not mandatory.

GRE multipoint is an option for hub-and-spoke but not a requirement for multicast support.

Exam trap

The trap here is assuming that IPsec automatically encrypts multicast traffic and that transport mode is always used with GRE.

36
MCQeasy

A network engineer is configuring a Cisco IOS router as a DHCP server for a subnet. The router must exclude the address 10.10.10.1 from being assigned to clients. Which command correctly accomplishes this?

A.ip dhcp excluded-address 10.10.10.1
B.ip dhcp excluded-address 10.10.10.1 10.10.10.1
C.ip dhcp excluded-address 10.10.10.0 10.10.10.255
D.ip dhcp pool POOL; excluded-address 10.10.10.1
AnswerA

The 'ip dhcp excluded-address' command is used in global configuration mode to prevent the DHCP server from assigning specific IP addresses. Specifying a single address excludes only that address. This is the correct syntax to exclude 10.10.10.1 from the DHCP pool, ensuring it is not offered to clients.

Why this answer

The correct way to exclude a single IP address from a Cisco IOS DHCP server is to use the global command 'ip dhcp excluded-address' followed by the specific address. This prevents the DHCP server from assigning that address to any client. The command must be entered in global configuration mode, not within the DHCP pool.

Exam trap

The trap here is placing the exclusion command inside the DHCP pool configuration mode, where it is not valid, or excluding an entire range instead of a single address.

37
MCQmedium

A network engineer is configuring DMVPN Phase 3 on a hub router. The hub must forward traffic directly between spokes without traversing the hub. Which command is required on the hub to enable this behavior?

A.ip nhrp map multicast dynamic
B.ip nhrp network-id 1
C.ip nhrp shortcut
D.ip nhrp redirect
AnswerD

The ip nhrp redirect command is essential for DMVPN Phase 3. It allows the hub to send NHRP redirect messages to spokes, informing them of a more optimal path directly to the destination spoke. Without this, spokes continue sending traffic through the hub, defeating the purpose of Phase 3. This command works in conjunction with ip nhrp shortcut on the spokes.

Why this answer

For DMVPN Phase 3, the hub must be configured with ip nhrp redirect to inform spokes about superior paths. When a spoke sends traffic to the hub for a destination reachable via another spoke, the hub responds with an NHRP redirect, prompting the originating spoke to initiate a direct tunnel. The spoke must have ip nhrp shortcut to act on the redirect.

Together, these commands enable dynamic direct spoke-to-spoke tunnels.

Exam trap

The trap here is confusing the roles of ip nhrp redirect and ip nhrp shortcut, placing the spoke command on the hub or vice versa.

38
MCQeasy

A network administrator is configuring a Cisco IOS router to act as a DHCP server for a LAN segment. The administrator wants to exclude a range of IP addresses from being assigned to clients because those addresses are statically assigned to servers and printers. Which command should be used to accomplish this?

A.ip dhcp pool LAN network 192.168.1.0 255.255.255.0 excluded-address 192.168.1.10 192.168.1.20
B.ip dhcp excluded-address 192.168.1.10 192.168.1.20 255.255.255.0
C.ip dhcp excluded-address 192.168.1.10 192.168.1.20
D.ip dhcp pool STATIC host 192.168.1.10 255.255.255.0
AnswerC

The 'ip dhcp excluded-address' command specifies a range of IP addresses that the DHCP server will not assign to clients. This is the correct way to reserve addresses for static devices such as servers and printers, ensuring they are not dynamically allocated.

Why this answer

To prevent the DHCP server from assigning a specific range of addresses, the 'ip dhcp excluded-address' command must be used in global configuration mode. This command takes a start and end IP address (or a single IP) and ensures those addresses are not offered to clients. The other options either use incorrect syntax or place the command in the wrong configuration mode.

Exam trap

The trap here is confusing the global 'ip dhcp excluded-address' command with the pool-level 'host' command or misplacing the exclusion within the pool configuration.

39
MCQmedium

A network engineer is configuring a Cisco router to support MPLS Layer 3 VPNs. The engineer needs to enable the router to exchange VPNv4 routes with a provider edge (PE) router. Which address family must be configured under the BGP routing process to support this?

A.address-family ipv4 unicast
B.address-family ipv6 unicast
C.address-family vpnv4 unicast
D.address-family ipv4 vrf
AnswerC

The VPNv4 unicast address family is specifically designed to carry MPLS Layer 3 VPN routes. It includes the route distinguisher and route target extended communities necessary for VPN segmentation. Configuring this address family under BGP allows the PE routers to exchange VPNv4 prefixes, enabling MPLS L3VPN functionality. This is the correct address family for this scenario.

Why this answer

MPLS Layer 3 VPNs rely on BGP VPNv4 address family to exchange VPN routes between PE routers. The VPNv4 address family carries the route distinguisher and route target attributes that identify the VPN membership. Other address families serve different purposes, such as IPv4 unicast for global routing or IPv4 VRF for per-VRF routing, but not for PE-to-PE VPN route exchange.

Exam trap

The trap here is confusing the per-VRF IPv4 address family with the VPNv4 address family used for PE-to-PE route exchange.

40
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology. Spokes are behind NAT devices and have dynamically assigned public IP addresses. The engineer wants to ensure that spoke-to-spoke traffic can be established directly without traversing the hub. Which technology should be implemented on the hub to achieve this?

A.IPsec tunnel protection
B.NHRP shortcut
C.Multicast replication
D.NHRP redirect
AnswerD

NHRP redirect is a key component of DMVPN Phase 3. The hub sends an NHRP redirect message to the spoke, informing it that a more optimal path exists to the destination spoke. This allows the spoke to initiate a direct tunnel to the other spoke using NHRP resolution, bypassing the hub for data traffic.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to signal spokes about a better path to another spoke. The spoke then uses NHRP shortcut to establish a direct tunnel. The question asks what to implement on the hub, so NHRP redirect is correct.

NHRP shortcut is on the spoke, IPsec tunnel protection is for encryption, and multicast replication is for routing protocol support.

Exam trap

The trap here is confusing the roles of NHRP redirect and NHRP shortcut: redirect is on the hub, shortcut is on the spoke.

41
MCQhard

A network administrator is deploying MPLS Layer 3 VPNs across a service provider backbone. The provider uses OSPF as the IGP and MP-BGP for VPNv4 route distribution. The administrator notices that VPNv4 routes are not being advertised between PE routers. Which configuration step is most likely missing on the PE routers?

A.Configuring MPLS LDP on all interfaces between PE and P routers
B.Enabling OSPF on the PE-CE links with the correct area ID
C.Configuring route reflectors or full mesh iBGP peering between PE routers
D.Activating the VPNv4 address family under the BGP routing process and configuring the PE routers as neighbors
AnswerD

For VPNv4 routes to be exchanged, the BGP process must have the VPNv4 address family activated and the PE routers must be configured as BGP neighbors within that address family. Without this, MP-BGP will not carry VPNv4 NLRIs. This is the fundamental step for MPLS L3VPN route distribution.

Why this answer

MPLS L3VPN relies on MP-BGP to distribute VPNv4 routes between PE routers. The VPNv4 address family must be activated under the BGP process, and PE routers must be configured as neighbors within that address family. Without this, VPNv4 NLRIs are not exchanged, and customer routes cannot be propagated across the provider backbone.

Exam trap

The trap here is assuming that MPLS LDP or OSPF configuration alone is sufficient for VPNv4 route exchange, overlooking the need for BGP address family activation.

42
MCQeasy

A network technician is configuring a Cisco router to act as a DHCP relay agent. The router's interface GigabitEthernet0/0 is connected to a subnet where clients need to obtain IP addresses from a DHCP server located on a different subnet. Which command is required on the router to enable DHCP relay?

A.ip dhcp pool
B.ip dhcp relay
C.ip helper-address
D.ip forward-protocol udp
AnswerC

The 'ip helper-address' command is used on the interface facing the DHCP clients to forward DHCP broadcast requests to a specified DHCP server. It converts the broadcast to a unicast packet destined to the server's IP address. This is the standard method for DHCP relay on Cisco IOS routers and is essential for clients on remote subnets to obtain addresses from a centralized server.

Why this answer

To configure a Cisco router as a DHCP relay agent, the 'ip helper-address' command must be applied to the interface receiving the DHCP broadcasts. This command specifies the IP address of the DHCP server. The router then forwards the DHCP requests as unicasts to that server.

Other commands like 'ip forward-protocol' or 'ip dhcp pool' serve different purposes and are not used to enable relay.

Exam trap

The trap here is confusing the DHCP relay command with other DHCP-related commands like 'ip dhcp pool' or 'ip forward-protocol'.

43
MCQeasy

A network technician is configuring a GRE tunnel between two routers. The tunnel source is a physical interface, and the tunnel destination is a loopback interface on the remote router. The technician notices that the tunnel interface is up, but line protocol is down. What is the most likely cause?

A.The tunnel mode is set to GRE multipoint.
B.The tunnel source interface is shutdown.
C.The tunnel destination is not reachable.
D.The tunnel keepalive is misconfigured.
AnswerC

If the tunnel destination IP address is not reachable, the tunnel interface will show up/down. The tunnel source is up, so the interface state is up, but without a route to the destination, the line protocol remains down. This is a common issue when the destination is a loopback that is not advertised or when there is no route to it.

Why this answer

A GRE tunnel interface will be in up/down state if the tunnel source is operational but the destination is unreachable. The router brings up the tunnel interface because the source is up, but the line protocol remains down until a route to the destination is available. Ensuring reachability to the tunnel destination resolves the issue.

Exam trap

The trap here is assuming that a shutdown source interface would cause up/down, but that would cause down/down; the up/down state specifically points to destination unreachability.

44
MCQmedium

A network engineer is configuring a Cisco router to support Network Address Translation (NAT) for a small office. The engineer wants to translate internal private addresses to a single public address using Port Address Translation (PAT). Which command enables PAT by allowing the router to use the interface's IP address for translation?

A.ip nat inside source list 1 interface GigabitEthernet0/0
B.ip nat inside source static 10.1.1.1 203.0.113.1
C.ip nat inside source list 1 interface GigabitEthernet0/0 overload
D.ip nat inside source list 1 pool PUBLIC_POOL overload
AnswerC

This command configures PAT by referencing an access list (list 1) that defines the internal traffic to be translated and using the interface GigabitEthernet0/0's IP address as the public address. The overload keyword enables PAT, allowing multiple internal hosts to share the single public IP address by using different source ports. This is the correct command for the scenario.

Why this answer

PAT is enabled by using the overload keyword with the ip nat inside source command. When translating to an interface address, the syntax includes the interface keyword and overload. The correct command references the access list defining inside traffic, specifies the outside interface, and includes overload.

Other options either use a pool, perform static translation, or omit overload, so they do not achieve PAT using the interface address.

Exam trap

The trap here is forgetting the overload keyword, which is required for PAT, and confusing interface-based PAT with pool-based PAT.

45
MCQmedium

A network engineer is troubleshooting an MPLS L3VPN where customer routes are not being advertised from one PE to another. The engineer verifies that the VRFs are configured correctly, the IGP is converged, and the PE routers have established an MP-BGP session. Which command should the engineer use to verify that the VPNv4 prefixes are being exchanged correctly?

A.show mpls forwarding-table
B.show ip bgp vpnv4 all
C.show ip route vrf <vrf-name>
D.show ip bgp summary
AnswerB

The show ip bgp vpnv4 all command displays the VPNv4 routing table, including all prefixes learned from other PE routers. It shows the route targets, MPLS labels, and next-hops, which are crucial for verifying that VPNv4 prefixes are exchanged correctly. This is the primary command for troubleshooting MPLS L3VPN route propagation.

Why this answer

To verify that VPNv4 prefixes are being exchanged between PE routers, the engineer should use show ip bgp vpnv4 all. This command displays the VPNv4 BGP table, showing all VPNv4 routes, their next-hops, labels, and route targets. It is the most direct way to confirm that MP-BGP is propagating customer VPN routes correctly.

Exam trap

The trap here is relying on show ip bgp summary or show ip route vrf, which confirm session state or local VRF routes but do not show the actual VPNv4 prefix exchange.

46
MCQmedium

A network engineer is configuring an MPLS L3VPN. The PE router is running OSPF with the CE router in VRF CUSTOMER. The engineer notices that routes from the customer are being redistributed into the provider's global OSPF process, causing instability. Which configuration change on the PE router will prevent this redistribution while still allowing customer routes to be advertised across the MPLS core?

A.Configure a distribute-list to filter the customer routes from being redistributed.
B.Configure the OSPF process with the capability vrf-lite command.
C.Change the OSPF domain-id to a unique value.
D.Remove the redistribution of the VRF OSPF into the global OSPF process.
AnswerD

The instability is caused by redistributing the customer's OSPF routes into the provider's global OSPF. Removing this redistribution stops the customer routes from entering the provider's IGP. The customer routes can still be advertised across the MPLS core by redistributing them into MP-BGP, which is the correct method for L3VPN route propagation.

Why this answer

The root cause is the redistribution of the VRF OSPF into the provider's global OSPF. Removing that redistribution prevents customer routes from entering the provider's IGP, while MP-BGP can still carry the customer routes across the MPLS core as VPNv4 prefixes. This maintains customer connectivity without affecting the provider's routing stability.

Exam trap

The trap here is thinking that filtering with distribute-list or changing domain-id solves the problem, but the actual fix is to remove the incorrect redistribution into the global OSPF process.

47
Multi-Selectmedium

A network engineer is deploying DMVPN Phase 3 with IPsec protection. The hub router is configured with a multipoint GRE tunnel interface and NHRP. Which two statements are true regarding the configuration that must be applied to the spoke routers to enable direct spoke-to-spoke communication? (Choose two.)

Select 2 answers
A.The spoke must have NHRP redirect configured on its tunnel interface.
B.The spoke must have the ip nhrp map multicast dynamic command configured.
C.The spoke must have a route to the destination spoke's tunnel network via the tunnel interface.
D.The spoke must have NHRP shortcut configured on its tunnel interface.
E.The spoke must use a different IPsec profile than the hub to avoid SA conflicts.
AnswersC, D

For the spoke to build a direct tunnel, it must have a route to the destination spoke's tunnel IP address pointing out the tunnel interface. This is usually achieved through a dynamic routing protocol running over the DMVPN cloud. Without such a route, the spoke cannot forward traffic directly even if it has the NHRP mapping.

Why this answer

For DMVPN Phase 3 spoke-to-spoke communication, each spoke must have NHRP shortcut enabled to process redirect messages, and it must have a route to the destination spoke's tunnel network via the tunnel interface, typically learned through a routing protocol. These two elements allow the spoke to initiate a direct tunnel when needed.

Exam trap

The trap here is assuming that NHRP redirect is needed on spokes or that multicast mapping commands are required on spokes; those are hub-side configurations.

48
MCQmedium

A network engineer is configuring a Cisco IOS XE router to authenticate VPN users against a Microsoft Active Directory server. The router must use RADIUS and send the user's original username without modification. Which command set correctly configures the router to use the AD server at 10.1.1.50 with the shared secret 'Cisco123'?

A.aaa authentication login default group tacacs+ local tacacs server AD-SERVER address ipv4 10.1.1.50 key Cisco123
B.aaa authentication login default group radius local radius server AD-SERVER address ipv4 10.1.1.50 auth-port 1812 acct-port 1813 key Cisco123 username-case lower
C.aaa authentication login default group radius local radius server AD-SERVER address ipv4 10.1.1.50 auth-port 1645 acct-port 1646 key Cisco123
D.aaa authentication login default group radius local radius server AD-SERVER address ipv4 10.1.1.50 auth-port 1812 acct-port 1813 key Cisco123
AnswerD

This configuration defines a RADIUS server group named AD-SERVER with the correct IPv4 address and standard ports 1812/1813, sets the shared key, and applies it to the default login authentication list. The username is sent as entered because no stripping or manipulation is configured. This meets all requirements for authenticating VPN users against Active Directory via RADIUS.

Why this answer

The correct configuration must use RADIUS with the standard authentication and accounting ports 1812 and 1813, and must not alter the username. The option that defines a RADIUS server group with the correct address, ports, and key, and applies it to the default login authentication list, satisfies all requirements. Other options either use the wrong protocol, legacy ports, or modify the username.

Exam trap

The trap here is assuming that legacy RADIUS ports 1645/1646 are still acceptable for modern Active Directory integration, or that TACACS+ can be used interchangeably with RADIUS for VPN authentication.

49
MCQmedium

A network engineer is configuring a Cisco IOS XE router for MPLS L3VPN. The router is a PE device with a VRF named CUSTOMER. The engineer wants to redistribute routes from the VRF into MP-BGP so they can be advertised to a remote PE. The engineer has configured the VRF and assigned interfaces. Which command sequence correctly redistributes the connected routes from the VRF into BGP?

A.router bgp 65000 address-family ipv4 vrf CUSTOMER redistribute connected
B.router bgp 65000 redistribute connected
C.router bgp 65000 address-family ipv4 vrf CUSTOMER network 10.0.0.0 mask 255.255.255.0
D.router bgp 65000 address-family vpnv4 unicast redistribute connected
AnswerA

To redistribute routes from a VRF into MP-BGP, you must enter the VRF address family under router bgp and use the redistribute command. This injects the connected routes from that VRF into BGP, where they are then advertised as VPNv4 prefixes to remote PEs. The address-family ipv4 vrf CUSTOMER command is the correct context for redistribution. Without this, the routes are not advertised.

Why this answer

To advertise VRF routes via MP-BGP, you must redistribute them within the VRF address family under the BGP routing process. The address-family ipv4 vrf CUSTOMER context allows you to redistribute connected, static, or IGP routes from that VRF into BGP. These routes are then converted into VPNv4 prefixes with the appropriate route distinguisher and route target.

Redistributing in the global BGP instance or in the VPNv4 address family does not work because those contexts do not have access to the VRF routing table.

Exam trap

The trap here is confusing the VPNv4 address family with the VRF address family; redistribution must occur in the VRF-specific address family, not in the VPNv4 address family.

50
MCQeasy

A network administrator is deploying a DMVPN Phase 2 network with EIGRP as the routing protocol. The hub router is configured with a multipoint GRE interface and NHRP. Spokes are configured with tunnel interfaces and are registering with the hub. However, the administrator notices that spoke routers are not forming EIGRP neighbor adjacencies with the hub. Which command is most likely missing on the hub's mGRE interface?

A.ip nhrp redirect
B.ip nhrp map multicast dynamic
C.ip nhrp network-id 1
D.ip nhrp shortcut
AnswerB

Without ip nhrp map multicast dynamic, the hub cannot replicate multicast packets (such as EIGRP hellos) to all registered spokes. EIGRP uses multicast to discover and maintain neighbors. If the hub does not forward these multicasts, spokes will not receive hellos and adjacencies will not form. This command is essential for dynamic routing protocols over DMVPN.

Why this answer

For EIGRP to form adjacencies over a DMVPN, the hub must be able to forward multicast hellos to all spokes. The command ip nhrp map multicast dynamic enables the hub to replicate multicast packets to all registered spokes. Without it, spokes do not receive EIGRP hellos, and neighbor relationships fail.

This is a common oversight in DMVPN configurations. The other commands are either for Phase 3 or basic NHRP settings that are already working.

Exam trap

The trap here is assuming that NHRP registration alone is sufficient for routing protocol adjacencies, overlooking the need for multicast replication.

51
MCQeasy

A network administrator needs to configure a Cisco IOS router to send SNMP traps to a management server at 192.168.1.200 using SNMPv2c with the community string 'public'. Which command is required?

A.snmp-server manager
B.snmp-server host 192.168.1.200 version 2c public
C.snmp-server enable traps snmp
D.snmp-server community public ro
AnswerB

This command specifies the SNMP trap recipient at 192.168.1.200 using SNMPv2c and the community string 'public'. It is the correct command to configure the destination for SNMP notifications. The 'version 2c' keyword ensures SNMPv2c is used, and 'public' is the community string for authentication.

Why this answer

The snmp-server host command is used to specify the recipient of SNMP notifications, including traps and informs. By specifying the IP address, SNMP version (2c), and community string, the router is configured to send traps to the management server at 192.168.1.200 using SNMPv2c.

Exam trap

The trap here is confusing the command that defines a community string for SNMP access with the command that specifies a trap destination.

52
MCQmedium

A network engineer is implementing CoPP (Control Plane Policing) on a Cisco IOS router to protect the route processor from excessive traffic. The engineer wants to limit ICMP echo requests destined to the router itself to 100 kbps. Which action must be taken to ensure that CoPP applies only to traffic destined to the control plane?

A.Apply the service policy to the control-plane interface.
B.Apply the service policy to all physical interfaces.
C.Configure an ACL to match ICMP echo requests and apply it inbound on the WAN interface.
D.Enable IP source guard on all interfaces.
AnswerA

CoPP is implemented by attaching a service policy to the control-plane interface (control-plane). This interface represents the route processor's traffic. By applying the policy there, you can filter and rate-limit traffic destined to the control plane, such as ICMP echo requests to the router's IP addresses. This ensures that only traffic intended for the router itself is policed, not transit traffic.

Why this answer

CoPP is implemented by creating a traffic class that matches control-plane traffic, defining a policy map with a policer, and attaching the policy to the control-plane interface. This interface is a virtual interface that represents traffic destined to the route processor. Applying the policy elsewhere, such as physical interfaces, would not selectively target control-plane traffic and could impact transit traffic.

Exam trap

The trap here is applying the CoPP policy to physical interfaces instead of the dedicated control-plane interface.

53
Multi-Selecthard

A network administrator is deploying MPLS Layer 3 VPNs on Cisco IOS routers. The administrator must ensure that customer routes are exchanged between PE routers without requiring customer involvement. Which two protocols or features are required to accomplish this? (Choose two.)

Select 2 answers
A.OSPF as the PE-CE routing protocol
B.Route targets configured under VRFs
C.RSVP-TE for traffic engineering
D.MP-BGP with VPNv4 address family
E.LDP for label distribution
AnswersB, D

Route targets are extended BGP communities used to control import and export of routes between VRFs. They are required to define which VPN routes are accepted into which VRF on remote PEs. Without route targets, MP-BGP would not know which customer routes to import, and VPN connectivity would fail. They are a fundamental part of MPLS Layer 3 VPN configuration.

Why this answer

MPLS Layer 3 VPNs rely on MP-BGP with the VPNv4 address family to exchange customer routes between PE routers. Route targets, implemented as extended BGP communities, are used to control import and export of these routes into VRFs. Together, they enable the PE routers to maintain separate routing tables and forward customer traffic correctly across the shared MPLS core.

Exam trap

The trap here is assuming that LDP or RSVP-TE is needed for VPN route exchange, when they only handle label distribution for core routes, not customer VPN prefixes.

54
MCQeasy

A network technician is configuring a Cisco IOS router to act as a DHCP server for a subnet. The technician wants the router to exclude a range of addresses from being assigned to clients. Which command should be used to exclude the addresses?

A.ip dhcp pool <name> excluded-address <start-ip> <end-ip>
B.ip dhcp excluded-address <start-ip> <end-ip> inside the interface configuration
C.ip dhcp exclude <start-ip> <end-ip>
D.ip dhcp excluded-address <start-ip> <end-ip>
AnswerD

The 'ip dhcp excluded-address' command is used in global configuration mode to specify a range of IP addresses that the DHCP server should not assign to clients. This is typically used for addresses that are statically assigned to servers, printers, or routers. The command takes a start and end IP address to define the exclusion range.

Why this answer

The correct command to exclude IP addresses from DHCP assignment is 'ip dhcp excluded-address' configured in global configuration mode. This command specifies a range of addresses that the DHCP server will not lease to clients. Other variations either do not exist or are configured in the wrong mode.

Exam trap

The trap here is assuming that address exclusions are configured within the DHCP pool, when in fact they are configured globally.

55
MCQeasy

A network engineer is configuring a Cisco router to act as a DHCP server for a remote subnet. The router's interface connected to the remote subnet is configured with the `ip helper-address` command pointing to the DHCP server. However, clients on the remote subnet are not receiving IP addresses. The engineer verifies that the DHCP server is operational and has a valid pool for the remote subnet. What is the most likely cause of the problem?

A.The `ip helper-address` command is applied to the wrong interface.
B.The router's interface connected to the remote subnet is down.
C.The DHCP server is configured with a different subnet mask than the clients.
D.The DHCP server does not have a route back to the remote subnet.
AnswerD

For DHCP to work across subnets, the DHCP server must have a route to the remote subnet to send the DHCPOFFER and DHCPACK messages. If the server lacks a route, it cannot respond to the client's request. The `ip helper-address` forwards the initial DHCPDISCOVER, but the server's reply must be routable back to the client's subnet. Thus, a missing route on the server is a common cause.

Why this answer

When using `ip helper-address` to forward DHCP requests to a server on a different subnet, the DHCP server must have a route back to the client subnet. The server uses this route to send DHCPOFFER and DHCPACK messages. Without it, the server cannot reach the clients, and they will not receive IP addresses.

Ensuring the server has a route to the remote subnet resolves the issue.

Exam trap

The trap here is focusing on the router configuration and overlooking the need for a return route on the DHCP server.

56
Multi-Selectmedium

A network engineer is configuring a Cisco IOS XE router to act as an IPv6 DHCP server for a LAN segment. The router must provide IPv6 addresses and other configuration parameters to hosts. Which two tasks must the engineer perform to enable stateful DHCPv6 operation on the router? (Choose two.)

Select 2 answers
A.Enable IPv6 unicast routing globally with the ipv6 unicast-routing command.
B.Configure an IPv6 DHCP pool with the address prefix and other parameters.
C.Configure a DHCPv6 relay destination on the interface pointing to itself.
D.Configure a static IPv6 address on the interface using the eui-64 keyword.
E.Enable the DHCPv6 server functionality with the ipv6 dhcp server command on the interface.
AnswersB, E

A DHCPv6 pool defines the address prefix, DNS servers, domain name, and other options that clients receive. Without a pool, the router has no address space or parameters to assign, so stateful DHCPv6 cannot function. This is a fundamental configuration step for a DHCPv6 server.

Why this answer

To enable stateful DHCPv6 on a Cisco IOS XE router, you must create a DHCPv6 pool that defines the address prefix and options, and then enable the DHCPv6 server on the interface with the ipv6 dhcp server command referencing that pool. These two steps allow the router to assign addresses and parameters to clients. The other options are either unrelated or would not contribute to server functionality.

Exam trap

The trap here is thinking that enabling IPv6 unicast routing or configuring an eui-64 address is required for DHCPv6 server operation, when the essential steps are defining a pool and activating the server on the interface.

57
MCQhard

A network administrator is configuring a Cisco IOS router as a DHCP server. The router has two interfaces: GigabitEthernet0/0 with IP 192.168.1.1/24 and GigabitEthernet0/1 with IP 10.0.0.1/24. The administrator wants the router to assign addresses from the 192.168.1.0/24 subnet to clients on GigabitEthernet0/0. Which command must be configured in the DHCP pool to ensure that the router only assigns addresses from the correct subnet?

A.network 192.168.1.0 255.255.255.0
B.ip dhcp pool 192.168.1.0
C.default-router 192.168.1.1
D.ip dhcp excluded-address 10.0.0.1 10.0.0.254
AnswerA

The network command in DHCP pool configuration specifies the subnet and mask for the pool. This ensures that the router only assigns addresses from the 192.168.1.0/24 range to clients on that segment. Without this command, the pool would not know which addresses to offer, and the DHCP server would not function correctly for that subnet.

Why this answer

The network command is essential in a DHCP pool to define the subnet and mask from which addresses are assigned. It ensures that the router only offers addresses from the 192.168.1.0/24 range. The other options either set client parameters, exclude irrelevant addresses, or create a pool without defining its subnet.

Exam trap

The trap here is thinking that naming the pool after the subnet or excluding other subnets will define the address range, when the network command is the only one that specifies the pool's subnet.

58
MCQeasy

A network administrator is configuring a Cisco IOS XE router to support MPLS L3VPN. The administrator needs to enable MPLS forwarding on an interface that connects to the service provider core. Which command should be applied to the interface?

A.tag-switching ip
B.mpls ip
C.mpls label protocol ldp
D.mpls ldp router-id loopback0
AnswerB

The 'mpls ip' command enables MPLS forwarding on the interface, allowing it to send and receive labeled packets. This is essential for the interface to participate in the MPLS core. It is the correct command to enable MPLS on a core-facing interface in an MPLS L3VPN deployment.

Why this answer

The 'mpls ip' command is the standard way to enable MPLS forwarding on an interface in Cisco IOS XE. It allows the interface to forward labeled packets, which is required for MPLS L3VPN. The other commands either set global parameters or use deprecated syntax, and do not directly enable MPLS forwarding on the interface.

Exam trap

The trap here is selecting 'tag-switching ip' as an alternative to 'mpls ip'; while functionally similar, it is deprecated and not the correct command for current Cisco IOS XE.

59
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP relay agent. The router interface GigabitEthernet0/0 is connected to a subnet with DHCP clients, and the DHCP server is located at 192.168.100.10. Which command must be applied to the interface to forward DHCP requests to the server?

A.ip dhcp relay information option
B.ip dhcp pool RELAY_POOL
C.ip forward-protocol udp 67
D.ip helper-address 192.168.100.10
AnswerD

The 'ip helper-address' command configures the interface to forward UDP broadcasts, including DHCP requests, to the specified server address. It is the standard method for DHCP relay. When applied to the client-facing interface, the router will relay DHCP Discover messages to the server, allowing clients on that subnet to obtain addresses.

Why this answer

The 'ip helper-address' command on the client-facing interface is required to relay DHCP requests to a remote server. It forwards UDP broadcasts (including DHCP) to the specified IP address. Other commands either modify relay behavior or are for server configuration.

This command is the fundamental step for DHCP relay.

Exam trap

The trap here is thinking that enabling option 82 or specifying UDP forwarding alone is sufficient, but the 'ip helper-address' command is what actually forwards the requests.

60
MCQhard

A network engineer is troubleshooting an MPLS L3 VPN where OSPF is used as the PE-CE routing protocol. The customer reports that routes from one site are not being learned at another site. The engineer checks the PE routers and finds that the OSPF routes are present in the VRF routing table but not in the MP-BGP table. What is the most likely cause?

A.The route target configuration is incorrect.
B.The OSPF process is not configured with the correct VRF.
C.The OSPF routes are not being redistributed into BGP.
D.The BGP router ID is not unique.
AnswerC

For OSPF routes from a VRF to be advertised across the MPLS VPN to other PEs, they must be redistributed into MP-BGP. If redistribution is not configured, the routes remain only in the VRF routing table and are not exported as VPNv4 routes. This is the most likely cause when routes are present in the VRF but missing from MP-BGP.

Why this answer

When OSPF routes are present in the VRF routing table but not in MP-BGP, the most likely cause is that redistribution from OSPF into BGP is not configured. MP-BGP only advertises routes that are explicitly redistributed or network statements are used. Without redistribution, the routes remain local to the VRF and are not propagated as VPNv4 routes.

Other issues like route target or VRF configuration would manifest differently.

Exam trap

The trap here is assuming a route target or VRF misconfiguration when the routes are missing from MP-BGP; the first step is to check redistribution into BGP.

61
MCQmedium

A network engineer is configuring a DMVPN Phase 3 spoke router. The spoke must establish a direct tunnel to another spoke when traffic requires it. The hub is already configured with 'ip nhrp redirect'. Which additional command must be configured on the spoke to enable it to request and receive shortcut replies from the hub?

A.ip nhrp shortcut
B.ip nhrp redirect
C.ip nhrp network-id 100
D.ip nhrp map multicast dynamic
AnswerA

On a DMVPN Phase 3 spoke, 'ip nhrp shortcut' enables the spoke to intercept traffic and send an NHRP resolution request to the hub for a remote spoke. The hub replies with a redirect, and the spoke installs a shortcut route, allowing direct spoke-to-spoke communication. Without this command, the spoke continues to forward traffic through the hub even if the hub is configured with 'ip nhrp redirect'.

Why this answer

In DMVPN Phase 3, the hub uses 'ip nhrp redirect' to notify spokes of a better path. The spoke must be configured with 'ip nhrp shortcut' to send NHRP resolution requests and install shortcut routes. This combination allows direct spoke-to-spoke tunnels, reducing latency and hub load.

Other commands like 'ip nhrp map multicast dynamic' are hub-side multicast features and do not enable shortcut switching.

Exam trap

The trap here is confusing the hub-side 'ip nhrp redirect' with the spoke-side 'ip nhrp shortcut', assuming that enabling redirect on the hub automatically enables shortcut switching on spokes.

62
Multi-Selectmedium

A network administrator is configuring a Cisco IOS router to support MPLS Layer 3 VPN. The administrator needs to enable the provider edge (PE) router to exchange VPNv4 routes with other PE routers. Which two configurations are required on the PE router to enable MP-BGP for VPNv4? (Choose two.)

Select 2 answers
A.Enable MPLS LDP on the core-facing interfaces.
B.Configure a route target (RT) under the VRF definition.
C.Configure a route distinguisher (RD) under the VRF definition.
D.Activate the VPNv4 address family with 'address-family vpnv4' and activate the neighbor.
E.Enable BGP with the 'router bgp' command and configure the remote PE as a neighbor.
AnswersD, E

In Cisco IOS, to exchange VPNv4 routes, you must enter the VPNv4 address family configuration mode using 'address-family vpnv4' and then activate the neighbor with 'neighbor <ip> activate'. This enables the BGP session to carry VPNv4 routes, which include the route distinguisher and extended communities.

Why this answer

To enable MP-BGP for VPNv4 on a PE router, you must first configure a BGP session with the remote PE using 'router bgp' and 'neighbor' commands. Then, you must activate the VPNv4 address family with 'address-family vpnv4' and activate the neighbor. These two steps allow the exchange of VPNv4 routes.

Other configurations like RD, RT, and LDP are important for MPLS VPN but not for enabling MP-BGP itself.

Exam trap

The trap here is confusing the steps to enable MP-BGP with the overall MPLS VPN configuration, such as RD, RT, or LDP, which are not part of the MP-BGP enabling process.

63
MCQmedium

A network engineer configures a Cisco IOS router with the command 'ip dhcp excluded-address 10.10.10.1 10.10.10.20'. The DHCP pool is defined as 'ip dhcp pool LAN' with network 10.10.10.0 /24. Which statement accurately describes the effect of the excluded-address command?

A.The router will reserve addresses 10.10.10.1 through 10.10.10.20 for DHCP clients only, preventing static assignment on other devices.
B.The router will exclude the entire 10.10.10.0 /24 subnet from DHCP, so no addresses will be assigned from that pool.
C.The router will not assign addresses 10.10.10.1 through 10.10.10.20 to DHCP clients, but those addresses can still be manually configured on other devices.
D.The router will assign addresses 10.10.10.1 through 10.10.10.20 only to clients that match a specific MAC address in a manual binding.
AnswerC

The excluded-address range prevents the DHCP server from offering those specific IP addresses in the pool. It does not reserve them for any particular device; they remain available for static assignment. This is commonly used to avoid conflicts with gateways, servers, or printers that are manually configured.

Why this answer

The excluded-address command removes a range of addresses from dynamic DHCP allocation, ensuring they are not offered to clients. Those addresses can still be statically configured on other devices, such as routers, switches, or servers. This prevents IP address conflicts while allowing manual assignment where needed.

Exam trap

The trap here is assuming that excluded addresses are reserved for DHCP clients or that they become unavailable for static configuration.

64
MCQhard

A network engineer is troubleshooting an MPLS L3VPN where customer routes are not being propagated between PE routers. The engineer verifies that the MP-BGP session between the PEs is established and that VRFs are configured correctly. Which of the following is the most likely cause for the missing routes?

A.The route targets are not properly configured for import/export.
B.The MPLS LDP session between the PEs is down.
C.The PE routers are not configured with unique route distinguishers.
D.The BGP session is not configured with the correct address-family.
AnswerA

In MPLS L3VPN, route targets (RTs) control the import and export of VPNv4 routes between VRFs. If the export RT on one PE does not match the import RT on the remote PE, the routes will not be imported into the remote VRF, even though the MP-BGP session is up and the routes are exchanged. This is a common misconfiguration and directly causes missing customer routes.

Why this answer

In MPLS L3VPN, route targets are extended BGP communities that determine which VRFs import and export routes. For a route to be installed in a remote VRF, the export RT attached to the route by the originating PE must match an import RT configured on the receiving PE's VRF. If they do not match, the route is discarded.

This is a frequent issue when VRFs are newly configured or when RTs are changed. Verifying RT configuration on both PEs is essential.

Exam trap

The trap here is assuming that an established MP-BGP session and correct VRF configuration guarantee route propagation, overlooking the role of route targets.

65
MCQhard

A network administrator is deploying IPv6 First Hop Security features on a Cisco Catalyst switch. The goal is to prevent rogue DHCPv6 servers from assigning addresses to clients. The administrator configures DHCPv6 Guard on the switch. Which additional configuration is necessary to ensure that DHCPv6 Guard operates correctly?

A.Apply an IPv6 access list to block DHCPv6 server traffic.
B.Enable RA Guard on all switch ports.
C.Enable IPv6 snooping globally.
D.Configure a DHCPv6 relay agent on the switch.
AnswerC

DHCPv6 Guard relies on IPv6 snooping to function. IPv6 snooping builds a binding table that tracks legitimate DHCPv6 servers and clients. Without IPv6 snooping enabled, DHCPv6 Guard cannot inspect DHCPv6 messages or enforce policies. Therefore, enabling IPv6 snooping globally is a prerequisite for DHCPv6 Guard to operate correctly and block rogue servers.

Why this answer

DHCPv6 Guard requires IPv6 snooping to be enabled because it uses the snooping binding table to validate DHCPv6 server messages. Without IPv6 snooping, DHCPv6 Guard cannot inspect or filter DHCPv6 packets. The other options either do not address the requirement or are unrelated features.

Thus, enabling IPv6 snooping globally is the necessary additional configuration.

Exam trap

The trap here is assuming that DHCPv6 Guard can operate independently, when it actually depends on IPv6 snooping.

66
Multi-Selectmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP server for a subnet 10.10.10.0/24. The engineer wants to ensure that the router provides the default gateway, DNS server, and domain name to DHCP clients. Which three commands must be configured in the DHCP pool? (Choose three.)

Select 3 answers
A.dns-server 8.8.8.8
B.lease 0 8
C.network 10.10.10.0 255.255.255.0
D.default-router 10.10.10.1
E.domain-name example.com
AnswersA, D, E

The dns-server command in DHCP pool configuration provides the IP address of the DNS server to clients. This is necessary for name resolution. The scenario explicitly requires the router to provide the DNS server address, so this command must be configured. Multiple DNS servers can be specified in a single command.

Why this answer

The correct commands are default-router, dns-server, and domain-name. These respectively provide the default gateway, DNS server address, and domain name to DHCP clients. The network command defines the pool's subnet but does not supply those options, and the lease command sets lease duration, which is not requested.

Exam trap

The trap here is selecting the network command because it is essential for the pool, but the question specifically asks for the commands that provide the gateway, DNS, and domain name, not the subnet definition.

67
MCQhard

A network engineer is troubleshooting a DMVPN Phase 3 network where spoke-to-spoke communication is not working. The hub is configured with ip nhrp redirect, and spokes are configured with ip nhrp shortcut. The routing protocol is OSPF, and the hub is configured with ip nhrp map multicast dynamic. The engineer notices that when a spoke pings another spoke's LAN IP, the first few pings fail, but subsequent pings succeed. However, the engineer wants to eliminate the initial packet loss. Which of the following is the most likely cause of the initial packet loss?

A.The hub is not configured with no ip next-hop-self for OSPF, causing the spokes to use the hub as the next hop and delaying direct tunnel establishment.
B.The hub is not configured with ip nhrp redirect, so the first packets are dropped while NHRP resolution occurs.
C.The spokes are not configured with ip nhrp shortcut, so they cannot build direct tunnels.
D.The initial packet loss is expected because the spoke must first send an NHRP resolution request and receive a reply before building the direct tunnel.
AnswerD

In DMVPN Phase 3, when a spoke needs to reach another spoke's network, it initially sends packets to the hub. The hub forwards them and sends an NHRP redirect to the source spoke. The source spoke then sends an NHRP resolution request for the destination spoke's NBMA address, waits for a reply, and then builds a direct tunnel. During this process, the first few packets may be dropped or delayed. This is a normal behavior and not a configuration error.

Why this answer

The initial packet loss in DMVPN Phase 3 spoke-to-spoke communication is a normal occurrence. When a spoke first attempts to reach another spoke, it does not have a direct tunnel. It sends packets to the hub, which forwards them and simultaneously sends an NHRP redirect to the source spoke.

The source spoke then initiates NHRP resolution to learn the destination spoke's NBMA address. Until the resolution completes and the direct tunnel is built, packets may be dropped or delayed. This is inherent to the on-demand nature of Phase 3.

The other options suggest configuration errors that would prevent direct tunnels from working at all, but the scenario indicates they eventually work.

Exam trap

The trap here is assuming that initial packet loss indicates a misconfiguration, when it is actually expected behavior in DMVPN Phase 3.

68
MCQeasy

A network engineer is configuring a Cisco router to act as a DHCPv6 server for a dual-stack network. The engineer wants to provide IPv6 addresses to clients and also supply them with DNS server addresses. Which DHCPv6 message type should the server use to send the DNS server information to the clients?

A.Solicit
B.Advertise
C.Information-request
D.Reply
AnswerD

The Reply message is used by the DHCPv6 server to provide configuration information, including IPv6 addresses and DNS server addresses, to the client. It is sent in response to a Request, Renew, Rebind, or Information-request message. This is the correct message type for delivering DNS server information.

Why this answer

In DHCPv6, the server uses the Reply message to deliver configuration parameters, including DNS server addresses, to clients. Clients request this information via Information-request or as part of address assignment, and the server responds with a Reply. The other message types serve different purposes in the DHCPv6 protocol exchange.

Exam trap

The trap here is confusing the Information-request message, which is sent by the client, with the Reply message, which is sent by the server to deliver the requested information.

69
MCQhard

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that only traffic from the 192.168.1.0/24 subnet to the 10.0.0.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which configuration element is used to define this traffic?

A.transform set
B.ISAKMP policy
C.ACL
D.crypto map
AnswerC

An extended ACL is used to define the interesting traffic that should be encrypted by IPsec. In this scenario, the ACL would permit IP traffic from 192.168.1.0/24 to 10.0.0.0/24. This ACL is referenced in the crypto map. Traffic matching the ACL is encrypted; traffic not matching is sent unencrypted. Thus, the ACL is the configuration element that defines the traffic.

Why this answer

In Cisco IOS IPsec configuration, an extended ACL is used to identify the traffic that should be encrypted. The ACL specifies the source and destination addresses and ports. This ACL is then referenced in the crypto map, which applies the IPsec policies to matching traffic.

Traffic that does not match the ACL is not encrypted and is routed normally. Therefore, the ACL is the configuration element that defines the traffic to be protected.

Exam trap

The trap here is confusing the ACL with the crypto map; while the crypto map references the ACL, it is the ACL that actually defines the traffic selection.

70
MCQhard

A service provider is deploying MPLS Traffic Engineering (TE) with RSVP-TE to ensure bandwidth guarantees for critical traffic. The network engineer has configured an MPLS TE tunnel on a Cisco IOS XE router. The tunnel must be able to signal an explicit path that includes a specific link with a reserved bandwidth of 50 Mbps. Which RSVP-TE object is used to carry the explicit route information in the Path message?

A.LABEL_REQUEST object
B.RSVP_HOP object
C.SESSION object
D.EXPLICIT_ROUTE object
AnswerD

The EXPLICIT_ROUTE object (ERO) is used in RSVP-TE Path messages to specify the explicit path that the TE tunnel should take. It contains a list of hops (usually IP addresses or autonomous system numbers) that the tunnel must traverse. In this scenario, the engineer needs to include a specific link in the path, and the ERO is the correct object to carry that information.

Why this answer

In RSVP-TE, the EXPLICIT_ROUTE object (ERO) is used to specify the explicit path for a TE tunnel. It is included in the Path message and contains the list of hops that the tunnel must traverse. The SESSION object identifies the session, the RSVP_HOP object provides previous hop information, and the LABEL_REQUEST object requests label bindings.

Only the EXPLICIT_ROUTE object carries the explicit route information needed to signal a path that includes a specific link.

Exam trap

The trap here is confusing the LABEL_REQUEST object, which requests labels, with the EXPLICIT_ROUTE object, which actually carries the explicit path information in the Path message.

71
MCQmedium

A network engineer is configuring a Cisco IOS router to send syslog messages to a remote syslog server at 10.1.1.100. The router's loopback0 interface is 192.168.1.1. The engineer wants syslog messages to be sourced from the loopback0 interface. Which command must be configured?

A.logging host 10.1.1.100 transport udp port 514
B.logging source-interface loopback0
C.logging origin-id ip
D.logging facility local6
AnswerB

This command sets the source IP address for syslog messages to the loopback0 interface's IP address. It ensures that the syslog server sees a consistent and stable source address, which is especially useful for logging correlation and filtering. The loopback interface is always up, so the source address remains reachable even if physical interfaces flap.

Why this answer

The logging source-interface command configures the router to use the specified interface's IP address as the source for syslog packets. Using loopback0 provides a stable, always-up source address, which simplifies syslog server configuration and ensures logs are consistently attributed to the router regardless of which physical interface sends the traffic.

Exam trap

The trap here is confusing the command that sets the source IP address in the packet header with the command that only adds origin information to the message payload.

72
MCQmedium

A network engineer is configuring a Cisco IOS XE router as a DHCPv6 server for a dual-stack network. The router must provide IPv6 addresses and other configuration parameters to clients on VLAN 20. The engineer has configured a DHCPv6 pool named POOL1 with the address prefix 2001:DB8:20::/64 and the DNS server 2001:DB8::53. The clients are not receiving IPv6 addresses. Which additional configuration is required on the router's VLAN 20 interface to ensure DHCPv6 clients can obtain addresses?

A.ipv6 address dhcp
B.ipv6 nd managed-config-flag
C.ipv6 dhcp server POOL1
D.ipv6 nd other-config-flag
AnswerC

To enable the router to act as a DHCPv6 server on an interface, the ipv6 dhcp server <pool-name> command must be configured on that interface. This binds the DHCPv6 pool to the interface and allows the router to respond to DHCPv6 solicit messages from clients. Without this command, the router will not process DHCPv6 requests on VLAN 20, even though the pool exists. This is the missing piece to make the server operational.

Why this answer

To make a Cisco IOS XE router act as a DHCPv6 server on an interface, you must bind the DHCPv6 pool to that interface using the ipv6 dhcp server command. The pool configuration alone defines the parameters, but the interface must be explicitly enabled to serve DHCPv6. Without this command, the router will not listen for or respond to DHCPv6 client requests on VLAN 20.

Therefore, the correct answer is the interface-level command that activates the server function.

Exam trap

The trap here is confusing the router's role as a DHCPv6 server with a DHCPv6 client; the ipv6 address dhcp command is for client operation, not for serving addresses.

73
MCQmedium

A network engineer is troubleshooting an IPv4 Network Address Translation (NAT) configuration on a Cisco IOS router. The router is configured with NAT overload (PAT) using the command ip nat inside source list 1 interface GigabitEthernet0/0 overload. Inside hosts cannot reach the Internet. The engineer verifies that interface GigabitEthernet0/0 is up and has an IP address, and that access list 1 permits the inside subnet. Which additional configuration is most likely missing?

A.The ip nat inside command on the LAN interface and ip nat outside on the WAN interface.
B.The ip nat inside source static command to create a static translation.
C.The ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/0 command to provide a default route.
D.The ip nat pool command to define a pool of public addresses.
AnswerA

For NAT to function, interfaces must be designated as inside or outside using the ip nat inside and ip nat outside commands. Without these, the router does not know which interfaces to translate. Even if the NAT statement and access list are correct, missing interface designations will prevent translation, causing connectivity failure.

Why this answer

NAT requires interfaces to be marked as inside or outside. Without these designations, the router cannot determine which traffic to translate. The NAT statement and access list alone are insufficient.

The other options are either unnecessary for PAT or not directly related to the NAT configuration issue.

Exam trap

The trap here is focusing on the NAT statement and access list while overlooking the fundamental requirement of interface designations.

74
MCQmedium

A network engineer is configuring a Cisco IOS router to support a new branch office that requires dynamic IPv4 addressing for clients. The router is already configured with a DHCP pool named BRANCH_POOL. The engineer notices that clients are not receiving IP addresses. Which command, when applied globally, is required to enable the DHCP service on the router?

A.ip helper-address 10.1.1.1
B.ip dhcp pool BRANCH_POOL
C.ip dhcp relay information option
D.service dhcp
AnswerD

The 'service dhcp' command in global configuration mode enables the DHCP server and relay agent functionality on the router. By default, this service is enabled, but it may have been disabled. Without it, the router will not process DHCP requests even if a pool is configured. This command is essential to activate the DHCP service.

Why this answer

The DHCP service on a Cisco IOS router must be enabled globally with the 'service dhcp' command. Although it is enabled by default, it can be disabled, preventing the router from responding to DHCP requests. Configuring a pool alone is insufficient.

The correct command activates the service, allowing the router to lease addresses from the configured pool.

Exam trap

The trap here is assuming that configuring a DHCP pool automatically enables the DHCP service, but the service must be globally enabled with 'service dhcp'.

75
MCQhard

A network administrator is deploying MPLS Layer 3 VPNs with Cisco IOS XE routers. The administrator wants to ensure that customer routes are not leaked into the global routing table and that each VPN instance maintains separate routing and forwarding tables. Which of the following must be configured on the PE routers to achieve this isolation?

A.BGP route reflectors with confederation
B.OSPF sham links with domain ID
C.MPLS LDP with explicit-null and penultimate hop popping
D.VRF definition with route distinguisher (RD) and route target (RT) import/export policies
AnswerD

A VRF (Virtual Routing and Forwarding) instance creates separate routing and forwarding tables per VPN. The route distinguisher (RD) makes the customer prefix unique within the MPLS domain, while route targets (RTs) control import and export of routes between VRFs. This combination ensures isolation and proper route leaking only where intended. Without VRFs, customer routes would mix with the global table or with other customers' routes, violating the isolation requirement.

Why this answer

To isolate customer routes in MPLS L3VPN, the PE router must have VRF instances. Each VRF has its own routing table, and the RD makes prefixes unique. RTs control which routes are imported into which VRF, enabling controlled route leaking.

This architecture ensures that customer routes remain separate from the global table and from other customers. The other options are related to MPLS or BGP scaling but do not provide the required isolation.

Exam trap

The trap here is assuming that MPLS LDP or BGP route reflectors alone provide VPN isolation; they do not, VRFs are required.

Page 1 of 2 · 106 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Infrastructure Services questions.