Courseiva

300-410 · topic practice

Infrastructure Services practice questions

Infrastructure Services covers Cisco IOS/IOS-XE features that provide secure connectivity and network services: DMVPN Phase 3, IPv6 First Hop Security, and AAA with TACACS+. Questions present a configuration goal or symptom and ask for the exact command, feature behavior, or verification output needed to meet it.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Infrastructure Services

What the exam tests

What to know about Infrastructure Services

Be able to select and apply the exact IOS commands that enable DMVPN Phase 3 spoke-to-spoke forwarding, IPv6 First Hop Security filtering, and TACACS+ AAA with fallback. The single most important thing is knowing which command goes on the hub versus the spoke.

DMVPN Phase 3 hub commands: ip nhrp redirect and ip nhrp shortcut for spoke-to-spoke tunnels

IPv6 First Hop Security features including DHCPv6 Guard, RA Guard, and IPv6 snooping

TACACS+ authentication, authorization, and accounting configuration with fallback behavior

Verification and troubleshooting of NHRP mappings, DHCPv6 Guard policy, and AAA server reachability

Watch out for

Common Infrastructure Services exam traps

  • ▸Assuming ip nhrp redirect alone enables spoke-to-spoke tunnels; the spoke also needs ip nhrp shortcut and a route to the destination spoke.
  • ▸Confusing DHCPv6 Guard with RA Guard; DHCPv6 Guard filters DHCPv6 server and client messages, not router advertisements.
  • ▸Forgetting that TACACS+ fallback requires configuring the aaa authentication command with a local or none fallback method after the server group.

Practice set

Infrastructure Services questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Review the full OSPF breakdown →

An engineer is configuring MPLS L3VPN on a Cisco IOS XE router. The customer edge (CE) router uses OSPF and the provider edge (PE) router must redistribute OSPF routes into MP-BGP. Which configuration is required on the PE to prevent routing loops and ensure proper route propagation?

Question 2mediummultiple choice
Open the full VLAN trunking answer →

A network engineer is configuring a Cisco IOS router to provide first-hop redundancy for a group of hosts on VLAN 10. The design requires that the virtual IP address be the same as the real IP address of the active router, and that the standby router preempts immediately when it becomes available. Which First Hop Redundancy Protocol (FHRP) should be implemented to meet these requirements?

Question 3mediummultiple choice
Study the full IPv6 explanation →

A network administrator is configuring IPv6 addressing on a Cisco router. The router must automatically generate a link-local address and use EUI-64 format for interface identifiers. Which command enables this behavior on an interface?

Question 4hardmultiple choice
Review the full OSPF breakdown →

A network administrator is deploying MPLS Layer 3 VPNs with OSPF as the PE-CE routing protocol. The customer requires that OSPF routes learned from one site be redistributed into BGP with the correct extended community to prevent routing loops and ensure proper propagation. Which BGP extended community must be attached to the redistributed routes?

Question 5hardmulti select
Read the full VPN explanation →

A network engineer is troubleshooting a DMVPN Phase 2 deployment where spoke-to-spoke tunnels are not forming. The hub is configured correctly. Which two actions should be taken on the spokes to enable direct spoke-to-spoke communication? (Choose two.)

Question 6hardmultiple choice
Open the full VLAN trunking answer →

A network administrator is implementing IPv6 First Hop Security on a Cisco Catalyst switch. The goal is to prevent rogue DHCPv6 servers from assigning addresses to clients on a VLAN. Which feature should be enabled on the VLAN to achieve this?

Question 7mediummultiple choice
Read the full VPN explanation →

A network administrator is implementing a DMVPN Phase 3 hub-and-spoke topology using Cisco IOS routers. The hub router is configured with a multipoint GRE interface and NHRP. Spoke routers register with the hub, and the hub has a mapping for each spoke. However, when a spoke attempts to reach another spoke's LAN subnet, the traffic goes through the hub instead of directly between spokes. Which additional configuration is required on the hub to enable spoke-to-spoke direct communication?

Question 8hardmulti select
Read the full MPLS explanation →

A network administrator is configuring a Cisco IOS router to support MPLS Layer 3 VPNs. The router will act as a Provider Edge (PE) device. Which two tasks are required to enable MPLS VPN functionality on the PE router? (Choose two.)

Question 9mediummultiple choice
Read the full DHCP explanation →

A network engineer is configuring a Cisco IOS XE router to act as a DHCP relay. The router interface GigabitEthernet0/0 is connected to a subnet where DHCP clients reside, and the DHCP server is at 10.1.1.10. The engineer enters the command 'ip helper-address 10.1.1.10' on interface GigabitEthernet0/0. However, clients are not receiving IP addresses. Which additional configuration is required to allow DHCP relay to function?

Question 10mediummulti select
Study the full IPv6 explanation →

A network engineer is implementing IPv6 First Hop Security on a Cisco switch to mitigate rogue router advertisements. Which two features should be enabled to prevent rogue RA messages from being processed by hosts? (Choose two.)

Question 11mediummultiple choice
Review the full OSPF breakdown →

A network engineer is configuring a Cisco router to authenticate OSPF neighbors using MD5. The engineer wants to ensure that only routers with the correct key can form adjacencies. Which command is required on the interface to enable OSPF MD5 authentication?

Question 12mediummulti select
Review the full OSPF breakdown →

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke network with OSPF as the routing protocol. The engineer wants to ensure that spoke-to-spoke communication can occur directly when needed, and that the hub can send redirects to spokes. Which two commands are required on the hub router to support this functionality? (Choose two.)

Question 13mediummulti select
Open the full VLAN trunking answer →

A network engineer is troubleshooting a DHCP relay configuration on a Cisco IOS router. The router is not forwarding DHCP requests from clients on VLAN 10 to the DHCP server at 10.1.1.100. The interface VLAN 10 is up and has an IP address. Which two commands should the engineer verify are configured correctly on the router? (Choose two.)

Question 14mediummultiple choice
Read the full VPN explanation →

A network engineer is configuring a DMVPN Phase 3 hub with dual ISPs for redundancy. The hub router has two WAN interfaces, both participating in the same mGRE tunnel interface. The engineer wants to ensure that spoke-to-spoke traffic can be dynamically redirected by the hub, and that the hub can advertise a single public IP address to all spokes. Which technology should be implemented on the hub to achieve this?

Question 15mediummultiple choice
Read the full VPN explanation →

A network engineer is configuring a DMVPN Phase 3 hub-and-spoke topology using mGRE and IPsec. The hub router is Cisco IOS XE. The engineer wants to ensure that spoke-to-spoke traffic flows directly without traversing the hub, even when the spokes are in different DMVPN networks. Which NHRP command must be configured on the hub to support this?

Question 16hardmultiple choice
Review the full OSPF breakdown →

A network engineer is deploying DMVPN Phase 2 with OSPF as the routing protocol. The hub router is configured as a broadcast network, and spokes are configured as non-broadcast. OSPF adjacencies are not forming between spokes and the hub. Which configuration change is required on the spoke routers to allow OSPF neighbor formation?

Question 17hardmulti select
Study the full AAA explanation →

A network engineer is configuring a Cisco IOS router to use TACACS+ for authorization of EXEC commands. The engineer wants to ensure that if the TACACS+ server is unavailable, the router will allow users to execute EXEC commands with privilege level 1. Which two commands are required to achieve this? (Choose two.)

Question 18hardmultiple choice
Read the full VPN explanation →

A network administrator is configuring DMVPN Phase 3 with IKEv2 on a hub router. The spoke routers must be able to dynamically establish direct spoke-to-spoke tunnels when needed. Which configuration on the hub is required to support this behavior?

Question 19hardmultiple choice
Review the full OSPF breakdown →

A company deploys MPLS Layer 3 VPNs with OSPF as the PE-CE routing protocol. The customer requires that routes learned from one site be redistributed into BGP with specific community attributes for traffic engineering. Which configuration step is necessary on the PE router to ensure that OSPF routes are redistributed with the correct BGP extended community for VPNv4?

Question 20mediummultiple choice
Read the full MPLS explanation →

A network administrator is configuring a Cisco IOS router for MPLS L3VPN. The router is a PE device with a VRF named CUSTOMER. The administrator wants to ensure that routes from the CUSTOMER VRF are exported with the correct route target and that routes from other VRFs are not imported into CUSTOMER. Which configuration is required to accomplish this?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Infrastructure Services sessions

Start a Infrastructure Services only practice session

Every question in these sessions is drawn from the Infrastructure Services domain — nothing else.

Related practice questions

Related 300-410 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 300-410 exam test about Infrastructure Services?
Be able to select and apply the exact IOS commands that enable DMVPN Phase 3 spoke-to-spoke forwarding, IPv6 First Hop Security filtering, and TACACS+ AAA with fallback. The single most important thing is knowing which command goes on the hub versus the spoke.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Infrastructure Services questions in a focused session?
Yes — the session launcher on this page draws every question from the Infrastructure Services domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 300-410 topics?
Use the topic links above to move to related areas, or go back to the 300-410 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 300-410 exam covers. They are not copied from any real exam or dump site.