Courseiva

CCNA Infrastructure Services Questions

31 of 106 questions · Page 2/2 · Infrastructure Services topic · Answers revealed

76
MCQmedium

A network engineer is configuring a DMVPN Phase 3 hub router. Spoke routers are behind dynamic NAT and cannot receive inbound connections. The engineer needs to ensure that spoke-to-spoke traffic flows directly without traversing the hub. Which technology must be enabled on the hub to achieve this?

A.IPsec transport mode
B.NHRP redirect
C.NHRP shortcut
D.Multipoint GRE with dynamic routing
AnswerB

NHRP redirect allows the hub to inform the originating spoke that a shorter path exists to the destination spoke, enabling direct spoke-to-spoke tunnels. When the hub receives a packet from one spoke destined to another, it sends an NHRP redirect message to the source spoke, which then initiates an NHRP resolution for the destination spoke's public address and builds a direct tunnel. This is a key feature of DMVPN Phase 3.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to notify a spoke that a better path exists to another spoke. The spoke then uses NHRP shortcut to resolve the destination's public address and establish a direct tunnel. Without NHRP redirect on the hub, spokes continue to send traffic through the hub even if they are capable of direct communication.

Exam trap

The trap here is confusing NHRP shortcut with NHRP redirect; shortcut is configured on spokes, but redirect must be enabled on the hub to trigger the process.

77
MCQhard

A network engineer is configuring a Cisco IOS router for IPv6 First Hop Security. The requirement is to prevent rogue DHCPv6 servers from assigning addresses to clients on a VLAN. The engineer has already enabled IPv6 snooping on the VLAN. Which additional feature should be configured to meet this requirement?

A.IPv6 ND Inspection
B.IPv6 DHCPv6 Guard
C.IPv6 Destination Guard
D.IPv6 Source Guard
AnswerB

DHCPv6 Guard filters DHCPv6 server messages on untrusted ports, allowing only authorized servers to respond to client requests. Enabling it on the VLAN prevents rogue DHCPv6 servers from assigning addresses. Since IPv6 snooping is already enabled, adding DHCPv6 Guard provides the necessary protection against rogue servers, fulfilling the requirement.

Why this answer

DHCPv6 Guard is specifically designed to block DHCPv6 server messages on untrusted ports, ensuring that only authorized DHCPv6 servers can assign addresses. With IPv6 snooping already enabled, configuring DHCPv6 Guard on the VLAN provides the necessary protection against rogue servers. Other First Hop Security features address different threats and do not fulfill this requirement.

Exam trap

The trap here is confusing DHCPv6 Guard with other IPv6 First Hop Security features like Source Guard or ND Inspection, which address different attack vectors.

78
MCQhard

A network engineer is troubleshooting an MPLS L3VPN where customer routes are not being advertised between PE routers. The engineer verifies that the VRFs are configured correctly and that MPLS forwarding is operational. Which MP-BGP configuration is required to exchange VPNv4 routes between PE routers?

A.neighbor x.x.x.x activate
B.address-family ipv4 unicast
C.address-family vpnv4 unicast
D.neighbor x.x.x.x send-community extended
AnswerC

The address-family vpnv4 unicast configuration under BGP enables the exchange of VPNv4 routes between PE routers. This address family carries the VPN label and route targets, allowing PEs to import and export routes into VRFs. Without activating this address family, BGP will not advertise VPNv4 prefixes, and customer routes will not be propagated across the MPLS core.

Why this answer

To exchange VPNv4 routes between PE routers, MP-BGP must be configured with the address-family vpnv4 unicast. This address family carries the VPN-specific attributes, including route targets and the VPN label. Once activated, BGP can advertise and receive VPNv4 prefixes, allowing PEs to import routes into the correct VRFs.

The other options are either for different address families or are supporting commands that do not by themselves enable VPNv4 route exchange.

Exam trap

The trap here is assuming that standard IPv4 BGP or just neighbor activation is sufficient, without configuring the specific VPNv4 address family.

79
MCQhard

A network administrator is implementing MPLS Layer 3 VPNs. The customer edge (CE) router is connected to the provider edge (PE) router via a single link and runs OSPF with the PE. The administrator wants to prevent the customer's OSPF routes from being redistributed into the provider's IGP and to keep the customer's OSPF topology separate. Which OSPF process configuration on the PE router achieves this?

A.Configure a separate OSPF process for the customer VRF and use distribute-list to filter routes.
B.Configure OSPF with the capability vrf-lite command under the routing process.
C.Configure the OSPF process within the VRF and do not redistribute it into the provider's OSPF process.
D.Configure OSPF with the domain-id command to match the provider's OSPF domain.
AnswerC

In MPLS L3VPN, the PE router maintains separate OSPF processes for each VRF. By not redistributing the customer's OSPF routes into the provider's global OSPF process, the customer's routes remain isolated. The PE redistributes them into MP-BGP for transport across the MPLS core. This separation prevents the customer's OSPF topology from mixing with the provider's IGP.

Why this answer

To keep the customer's OSPF separate, the PE router runs a VRF-specific OSPF process that is not redistributed into the provider's global OSPF. Customer routes are instead redistributed into MP-BGP for VPNv4 transport. This ensures isolation and prevents the customer's routes from entering the provider's IGP.

Exam trap

The trap here is thinking that filtering with distribute-list or using domain-id prevents redistribution; in reality, the key is to not redistribute the VRF OSPF into the provider's OSPF at all.

80
MCQhard

A network administrator is troubleshooting an OSPFv3 network. Routers R1 and R2 are directly connected on a point-to-point link. R1 is configured with OSPFv3 area 0, and R2 is configured with OSPFv3 area 1. The administrator notices that no OSPFv3 adjacency forms between them. What is the most likely cause?

A.The OSPFv3 area numbers do not match on the link.
B.The OSPFv3 router IDs are not unique.
C.The OSPFv3 process is not enabled on the interfaces.
D.The OSPFv3 network type is mismatched.
AnswerA

OSPFv3, like OSPFv2, requires that routers on the same link be in the same area to form an adjacency. Since R1 is in area 0 and R2 is in area 1, the hello packets will not be accepted, and the adjacency will not form. This is the most likely cause of the problem described.

Why this answer

For OSPFv3 to form an adjacency, both routers on a common link must be configured in the same OSPF area. In this scenario, R1 is in area 0 and R2 is in area 1, which violates this requirement. The hello packets will be ignored, and no adjacency will form.

Other potential issues like duplicate router IDs or interface configuration are not indicated by the symptoms.

Exam trap

The trap here is focusing on advanced OSPFv3 features like router ID uniqueness while overlooking the fundamental requirement that area numbers must match on a link.

81
MCQeasy

A network engineer is configuring a Cisco IOS XE router to act as a DHCP server for a subnet. The router must assign IP addresses from the 192.168.100.0/24 pool, but the first 10 addresses and the last address in the range must be excluded from dynamic assignment. Which command accomplishes this requirement?

A.ip dhcp excluded-address 192.168.100.1 192.168.100.10 192.168.100.254
B.ip dhcp excluded-address 192.168.100.1 192.168.100.10 and ip dhcp excluded-address 192.168.100.254
C.Two separate commands: ip dhcp excluded-address 192.168.100.1 192.168.100.10 and ip dhcp excluded-address 192.168.100.254
D.ip dhcp excluded-address 192.168.100.1 192.168.100.10
AnswerC

The ip dhcp excluded-address command can be entered multiple times to exclude different ranges or individual addresses. To exclude the first 10 addresses and the last address, you need two commands: one for the range 192.168.100.1 to 192.168.100.10, and another for the single address 192.168.100.254. This correctly meets all requirements.

Why this answer

The Cisco IOS DHCP server uses the ip dhcp excluded-address command to specify addresses that should not be assigned dynamically. You can configure multiple excluded addresses or ranges by entering the command multiple times. In this scenario, the first 10 addresses and the last address must be excluded, so two separate commands are needed: one for the range and one for the individual address.

Combining them into a single command with multiple arguments or using 'and' is not valid syntax.

Exam trap

The trap here is thinking that a single ip dhcp excluded-address command can exclude multiple non-contiguous ranges or that you can use 'and' to combine them, when in fact each exclusion requires its own command.

82
MCQeasy

A network administrator is configuring a Cisco IOS XE router for MPLS Traffic Engineering (TE). The administrator wants to ensure that the router can signal an MPLS TE tunnel using RSVP. Which protocol must be enabled on the interfaces along the path to reserve bandwidth and distribute labels?

A.BGP
B.LDP
D.RSVP
AnswerD

RSVP (Resource Reservation Protocol) is the signaling protocol used for MPLS Traffic Engineering. It reserves bandwidth along the path and distributes labels for the TE tunnel. RSVP-TE extends RSVP to support traffic engineering by adding objects for explicit routes, bandwidth, and label requests. It must be enabled on all interfaces that the TE tunnel traverses to ensure resource reservation and label distribution.

Why this answer

MPLS Traffic Engineering requires RSVP to signal TE tunnels and reserve bandwidth along the path. RSVP-TE is an extension of RSVP that carries additional objects for traffic engineering, such as explicit route objects and label requests. It must be enabled on all interfaces that the tunnel traverses.

While OSPF or IS-IS with TE extensions are used to advertise link attributes, and BGP may be used for routing, RSVP is the protocol that performs the actual signaling and resource reservation.

Exam trap

The trap here is confusing the role of OSPF-TE, which advertises TE information, with RSVP, which actually signals and reserves resources for the tunnel.

83
MCQhard

A network administrator is configuring a Cisco IOS router to authenticate users via TACACS+ using a TACACS+ server at 10.1.1.50. The administrator wants to ensure that if the TACACS+ server is unreachable, the router will fall back to using the local username database. Which command set achieves this?

A.aaa authentication login default group tacacs+ local
B.aaa authentication login default group tacacs+ none
C.aaa authentication login default group tacacs+ enable
D.aaa authentication login default local group tacacs+
AnswerA

This command configures the default login authentication method list to first try TACACS+ and then fall back to the local database if the TACACS+ server is unreachable. The 'local' keyword ensures that local authentication is attempted only if the TACACS+ servers do not respond, providing redundancy and preventing lockout.

Why this answer

The aaa authentication login default group tacacs+ local command sets TACACS+ as the primary authentication method and local as the fallback. This ensures that if the TACACS+ server is unreachable, the router will use its local username database, maintaining administrative access without compromising security.

Exam trap

The trap here is reversing the order of authentication methods, which would cause the router to check local credentials first and only use TACACS+ if local fails, contrary to the desired primary-backup relationship.

84
MCQhard

A network engineer is configuring a Cisco IOS XE router as a LISP ITR. The router must encapsulate traffic from local EIDs to remote RLOCs. Which command is required to enable LISP functionality and allow the router to act as an ITR?

A.router lisp
B.lisp itr enable
C.feature lisp
D.ipv4 lisp
AnswerA

The router lisp command enters LISP configuration mode, where you can enable ITR functionality, define EID-to-RLOC database mappings, and configure map-resolvers. Without this global command, LISP processes are not activated, and the router cannot encapsulate or decapsulate LISP traffic. It is the foundational step for any LISP role.

Why this answer

On Cisco IOS XE, LISP is enabled by entering the router lisp global configuration command. This mode allows you to configure the router as an ITR, ETR, or both, and to define EID-to-RLOC mappings and map-resolvers. The other commands are either invalid in this context or belong to different platforms, so they would not enable LISP functionality.

Exam trap

The trap here is confusing the IOS XE command with NX-OS feature commands or assuming that the ITR enable command can be issued globally, when the correct entry point is the router lisp submode.

85
MCQhard

A network engineer is configuring MPLS Traffic Engineering (TE) with RSVP-TE on a Cisco IOS XE router. The engineer wants to establish a TE tunnel from Router A to Router D. The path must be explicitly defined to go through Router B and then Router C. The engineer has configured the tunnel interface with the destination and an explicit path. However, the tunnel is not coming up. Which command is required to enable RSVP-TE on the core interfaces of Router A, B, C, and D?

A.mpls ldp router-id Loopback0 force
B.mpls traffic-eng tunnels
C.ip rsvp bandwidth
D.mpls traffic-eng tunnel-te 1
AnswerC

The ip rsvp bandwidth command must be configured on each core interface that will participate in RSVP-TE. This command enables RSVP on the interface and allocates a percentage or absolute amount of bandwidth for TE reservations. Without it, RSVP messages are not sent or processed on that interface, and the TE tunnel cannot be signaled. Therefore, this is the required interface-level command to enable RSVP-TE on the core links.

Why this answer

For RSVP-TE to signal a TE tunnel, RSVP must be enabled on every interface along the path. This is done with the ip rsvp bandwidth command, which also allocates bandwidth for reservations. While global MPLS TE commands and tunnel interface configuration are necessary, they do not activate RSVP on the physical links.

The tunnel will remain down if RSVP is not enabled on the core interfaces. Therefore, the correct answer is the interface-level command that enables RSVP and sets the reservable bandwidth.

Exam trap

The trap here is assuming that enabling MPLS TE globally or configuring the tunnel interface is enough, but RSVP signaling requires explicit interface-level enablement with bandwidth allocation.

86
MCQmedium

A network engineer is configuring DHCPv6 on a Cisco IOS-XE router. The router must provide IPv6 addresses and other configuration parameters to clients on the LAN. The engineer wants the router to assign addresses using stateless address autoconfiguration (SLAAC) but also provide DNS server information via DHCPv6. Which command set correctly configures the router's LAN interface to achieve this?

A.ipv6 address 2001:DB8:1::1/64 ipv6 nd other-config-flag ipv6 dhcp server POOL
B.ipv6 address 2001:DB8:1::1/64 ipv6 dhcp server POOL ipv6 nd ra-interval 30
C.ipv6 address 2001:DB8:1::1/64 ipv6 nd prefix 2001:DB8:1::/64 ipv6 dhcp server POOL
D.ipv6 address 2001:DB8:1::1/64 ipv6 nd managed-config-flag ipv6 dhcp server POOL
AnswerA

The other-config-flag instructs hosts to use DHCPv6 to obtain other configuration parameters such as DNS, while addresses are still formed via SLAAC. The ipv6 dhcp server command binds the DHCPv6 pool to the interface. This combination meets the requirement of SLAAC for addresses and DHCPv6 for DNS.

Why this answer

The other-config-flag in router advertisements signals hosts to use DHCPv6 for additional configuration parameters, while addresses are still autoconfigured via SLAAC. The ipv6 dhcp server command attaches the DHCPv6 pool to the interface. The managed-config-flag would force hosts to use DHCPv6 for addresses as well, which is not desired.

Other commands like ra-interval or prefix do not control the DHCPv6 usage flags.

Exam trap

The trap here is confusing the managed-config-flag with the other-config-flag; the former forces DHCPv6 for addresses, while the latter only requests other parameters.

87
MCQhard

A network engineer is troubleshooting a Cisco IOS XE router that is configured for IPv6 First Hop Security on a user VLAN. Hosts report intermittent connectivity, and the engineer suspects that IPv6 Router Advertisement (RA) messages from an unauthorized device are being accepted. Which feature should be enabled to ensure that only RAs from the legitimate router are processed by hosts?

A.IPv6 Source Guard
B.IPv6 Destination Guard
C.IPv6 RA Guard
D.IPv6 DHCPv6 Guard
AnswerC

RA Guard examines incoming Router Advertisement and Redirect messages on a port and can block or allow them based on a policy. By configuring RA Guard on host-facing ports to block RAs, only the legitimate router's RAs are accepted, preventing rogue RA attacks and restoring stable connectivity.

Why this answer

RA Guard is the IPv6 First Hop Security feature that filters Router Advertisement and Redirect messages on a per-port basis. When configured to block RAs on host-facing ports, it ensures hosts only accept RAs from the authorized router, mitigating rogue RA attacks. The other features address different threats such as rogue DHCPv6 servers or spoofed source addresses.

Exam trap

The trap here is confusing RA Guard with DHCPv6 Guard or Source Guard, but only RA Guard specifically inspects and filters Router Advertisement messages to prevent rogue default router advertisements.

88
MCQhard

A network administrator is deploying IPv6 First Hop Security (FHS) on a Cisco Catalyst switch to mitigate rogue Router Advertisement (RA) attacks. The switch is running Cisco IOS Software and is configured with the command ipv6 nd raguard policy POLICY1. Which additional step is required to activate RA guard on an interface?

A.Configure the interface as trusted using ipv6 nd raguard trust.
B.Apply the policy to the interface using ipv6 nd raguard attach-policy POLICY1.
C.Enable IPv6 unicast routing globally with ipv6 unicast-routing.
D.Enable DHCPv6 snooping globally with ipv6 dhcp snooping.
AnswerB

After creating an RA guard policy, you must attach it to the desired interface with the ipv6 nd raguard attach-policy command. This activates the policy on that interface, allowing it to filter rogue RAs. Without attaching the policy, the configuration exists but is not enforced on any port, leaving the network vulnerable.

Why this answer

RA guard requires two steps: creating a policy that defines the filtering rules, and attaching that policy to an interface. The attach-policy command activates the policy on the specified interface. Other options are either unrelated features or modify trust settings, but they do not activate the policy on an interface.

Exam trap

The trap here is assuming that creating the policy is sufficient, or confusing the trust command with the attach-policy command.

89
MCQhard

A network engineer is configuring a Cisco IOS XE router to act as a DHCP relay agent. The router receives DHCP discover messages on interface GigabitEthernet0/1 and must forward them to a DHCP server at 10.1.1.100. The engineer configures the command 'ip helper-address 10.1.1.100' on GigabitEthernet0/1. However, the DHCP server is not receiving the requests. Which additional configuration is required to ensure that DHCP relay works correctly?

A.Configure 'ip forward-protocol udp 67' globally.
B.Configure 'ip dhcp relay information option' globally.
C.Enable 'service dhcp' globally on the router.
D.Ensure that the interface facing the DHCP server has an IP address and that routing is configured to reach 10.1.1.100.
AnswerD

This is correct. For the DHCP relay agent to forward requests to the server, the router must have a route to the DHCP server's IP address. The helper address itself only specifies the destination; the router must be able to reach that destination via its routing table. If the interface facing the server is down or lacks an IP address, or if there is no route to 10.1.1.100, the relayed packets will be dropped. This is a common oversight when configuring DHCP relay.

Why this answer

The DHCP relay agent uses the 'ip helper-address' command to forward broadcast DHCP requests to a unicast address. However, the router must have a valid route to that unicast address. If the interface toward the DHCP server is not configured with an IP address or is down, or if there is no route to the server, the relayed packets cannot be sent.

Therefore, ensuring IP connectivity to the DHCP server is essential. The other options are either default behaviors or optional features not required for basic relay operation.

Exam trap

The trap here is focusing on DHCP-specific commands like 'service dhcp' or relay information options, while overlooking the fundamental requirement of IP reachability to the DHCP server.

90
Multi-Selecthard

A network administrator is deploying a DMVPN Phase 3 hub-and-spoke topology using Cisco IOS routers. The hub router is configured with a multipoint GRE (mGRE) interface and NHRP. Spokes are configured with mGRE and NHRP as well. The administrator wants to ensure that spoke-to-spoke traffic flows directly without traversing the hub after initial registration. Which two statements about DMVPN Phase 3 operation are true? (Choose two.)

Select 2 answers
A.The hub must be configured with 'ip nhrp redirect' to enable spoke-to-spoke direct communication.
B.The hub must be configured with 'ip nhrp nhs' pointing to itself to act as the next-hop server.
C.Spokes must be configured with 'ip nhrp shortcut' to dynamically create direct tunnels to other spokes.
D.The hub must be configured with 'ip nhrp map multicast dynamic' to enable spoke-to-spoke multicast traffic.
E.Spokes must be configured with 'ip nhrp network-id' that matches the hub's network-id to form the NHRP domain.
AnswersA, C

'ip nhrp redirect' on the hub allows the hub to send a redirect message to the spoke when it detects that traffic is being routed through the hub to another spoke. This enables the spoke to initiate an NHRP resolution for the destination spoke's NBMA address and establish a direct tunnel.

Why this answer

In DMVPN Phase 3, direct spoke-to-spoke communication is enabled by configuring 'ip nhrp redirect' on the hub and 'ip nhrp shortcut' on the spokes. The hub uses NHRP redirect to inform the spoke that a better path exists, and the spoke uses NHRP shortcut to dynamically create a direct tunnel to the destination spoke.

Exam trap

The trap here is assuming that basic NHRP commands like network-id or NHS configuration are Phase 3 specific, when they are common to all DMVPN phases.

91
MCQmedium

A network engineer is troubleshooting a DMVPN Phase 3 network. Spoke-to-spoke tunnels are not being established directly; traffic between spokes is going through the hub. The hub is configured with 'ip nhrp redirect' and spokes with 'ip nhrp shortcut'. Which additional configuration is required on the spokes to enable direct spoke-to-spoke communication?

A.Configure 'ip nhrp network-id' with the same value on all spokes and the hub.
B.Ensure that the spokes have a route to the destination spoke's tunnel network via the hub, and that they are not using a default route that prevents shortcut switching.
C.Configure 'ip nhrp shortcut' on the hub tunnel interface.
D.Configure 'ip nhrp map multicast dynamic' on the hub tunnel interface.
AnswerB

For spoke-to-spoke shortcut tunnels to form, the spoke must have a specific route to the destination network that points to the tunnel interface, not a default route. If a default route is used, the spoke will not attempt NHRP resolution for the specific destination and will continue sending traffic via the hub. The spoke needs a more specific route (e.g., a /24 for the remote spoke's LAN) to trigger the shortcut. This is a common oversight in DMVPN Phase 3 deployments.

Why this answer

In DMVPN Phase 3, spoke-to-spoke shortcut tunnels require that the spoke has a specific route to the destination network pointing to the tunnel interface. If the spoke uses a default route, it will not perform NHRP resolution for the specific destination, and traffic will continue to flow through the hub. Therefore, ensuring that spokes have specific routes (not just a default) is essential for direct spoke-to-spoke communication.

Exam trap

The trap here is focusing on NHRP commands like 'ip nhrp redirect' and 'ip nhrp shortcut' while overlooking the routing table requirement for specific routes to trigger shortcut switching.

92
MCQmedium

A network engineer is configuring a Cisco IOS XE router to support MPLS L3VPN. The router is a PE device with a VRF named CUSTOMER. The engineer wants to ensure that the PE router can forward traffic for the CUSTOMER VRF using MPLS labels. Which command must be configured on the PE router's core-facing interface to enable MPLS forwarding?

A.mpls label protocol ldp
B.mpls ldp router-id Loopback0
C.mpls ldp discovery transport-address interface
D.mpls ip
AnswerD

The mpls ip command enables MPLS forwarding on an interface. On the core-facing interface of a PE router, this command is required to allow the interface to send and receive MPLS-labeled packets. Without it, the interface will not process MPLS labels, and traffic for the CUSTOMER VRF will not be forwarded correctly across the MPLS backbone.

Why this answer

To enable MPLS forwarding on a Cisco IOS XE router interface, the mpls ip command must be configured. This command instructs the interface to process MPLS labels and forward labeled packets. On a PE router, the core-facing interface must have mpls ip enabled to send and receive MPLS traffic for VPNs.

While other MPLS-related commands configure label distribution or router IDs, they do not enable the actual forwarding of MPLS packets on the interface.

Exam trap

The trap here is confusing commands that configure MPLS label distribution (like mpls label protocol ldp) with the command that actually enables MPLS forwarding on an interface (mpls ip).

93
MCQeasy

A network engineer is configuring a Cisco router to act as a DHCP relay agent. The DHCP server is located on a different subnet. Which command is required on the router's interface to forward DHCP requests to the server?

A.ip helper-address <server-ip>
B.ip forward-protocol udp 67
C.ip dhcp pool <name>
D.ip dhcp relay <server-ip>
AnswerA

The ip helper-address command configured on the router interface enables DHCP relay by forwarding UDP broadcasts (including DHCP DISCOVER) to the specified server IP address. This allows clients on a subnet without a local DHCP server to obtain addresses from a centralized server. It is the standard method for DHCP relay in Cisco IOS.

Why this answer

The ip helper-address command on an interface enables the router to forward DHCP broadcast requests to a specified DHCP server on another subnet. This is essential when clients and the DHCP server are on different broadcast domains. The command also forwards other UDP broadcasts by default, but DHCP relay is the primary use case here.

Exam trap

The trap here is confusing the DHCP relay command with DHCP server configuration commands; ip helper-address is for relay, while ip dhcp pool is for local server.

94
MCQmedium

A network administrator is configuring a Cisco IOS router to support MPLS Layer 3 VPNs. The router is a PE device that must exchange VPNv4 routes with other PE routers. The administrator has enabled MPLS LDP on the core-facing interfaces and configured BGP with the address-family vpnv4. Which additional configuration is required on the PE router to properly forward MPLS VPN traffic?

A.Configure BGP route reflectors to distribute VPNv4 routes.
B.Configure a VRF on the PE router and assign the customer-facing interface to it.
C.Enable MPLS TE on all core interfaces to establish traffic-engineered tunnels.
D.Enable OSPF as the IGP and configure it to carry MPLS labels.
AnswerB

In an MPLS Layer 3 VPN, the PE router must have a VRF configured for each customer, and the customer-facing interface must be assigned to that VRF. This separates customer routing tables and allows the PE to advertise customer routes into MP-BGP with the appropriate route target. Without a VRF, the PE cannot distinguish customer traffic or apply the correct label stack, so VPN traffic would not be forwarded correctly.

Why this answer

MPLS L3 VPN requires the PE router to have VRFs configured for each customer, with customer interfaces assigned to those VRFs. This enables the PE to maintain separate routing tables, advertise routes via MP-BGP with route targets, and impose the correct label stack for VPN traffic. Without VRFs, the PE cannot differentiate customer traffic or forward it properly.

Exam trap

The trap here is focusing on advanced features like MPLS TE or route reflectors, while overlooking the fundamental requirement of VRF configuration on the PE router for MPLS L3 VPN.

95
MCQeasy

A network administrator is configuring a Cisco IOS router to provide first-hop redundancy for a group of hosts on VLAN 10. The design requires that the virtual IP address be 10.1.10.1 and that the router with the highest priority become the active gateway. The administrator has configured the interface with 'standby 10 ip 10.1.10.1' and 'standby 10 priority 150'. Which additional command is required to ensure that the router preempts and becomes the active gateway if it reboots?

A.standby 10 authentication md5 key-string cisco
B.standby 10 timers 1 3
C.standby 10 preempt
D.standby 10 track 1 decrement 20
AnswerC

The 'standby 10 preempt' command enables the router to take over as the active gateway if it has a higher priority than the current active router. Without preemption, a router that reboots and comes back online will not become active even if its priority is higher; it will remain in standby. This command ensures the intended active router assumes the role.

Why this answer

In HSRP, preemption must be explicitly enabled with the 'standby preempt' command. Without it, a router with a higher priority that comes online after the active router is already elected will not become active. The priority alone does not trigger preemption.

Therefore, to ensure the router becomes active after a reboot, the preempt command is necessary.

Exam trap

The trap here is assuming that a higher priority automatically causes a router to take over as active, when in fact preemption must be configured.

96
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP server for a remote subnet. The router interface connected to that subnet is configured with the address 10.10.10.1/24. The engineer wants the router to assign addresses from the 10.10.10.0/24 range and also provide the default gateway and DNS server information to clients. Which configuration is required on the router to accomplish this?

A.ip dhcp excluded-address 10.10.10.1 10.10.10.10, ip dhcp pool LAN, network 10.10.10.0 255.255.255.0, default-router 10.10.10.254
B.ip dhcp pool LAN, network 10.10.10.0 255.255.255.0, default-router 10.10.10.1, dns-server 8.8.8.8, lease 0 0 10
C.ip dhcp pool LAN, network 10.10.10.0 255.255.255.0, default-router 10.10.10.1, dns-server 8.8.8.8, domain-name example.com
D.ip dhcp pool LAN, network 10.10.10.0 255.255.255.0, default-router 10.10.10.1, dns-server 8.8.8.8
AnswerD

This configuration creates a DHCP pool named LAN, defines the subnet 10.10.10.0/24 from which addresses are allocated, and specifies the default gateway and DNS server for clients. The router interface address 10.10.10.1 is used as the gateway. This is the standard Cisco IOS DHCP server configuration for a directly connected subnet.

Why this answer

The correct configuration must include a DHCP pool with the network statement, default-router set to the router's interface IP (10.10.10.1), and dns-server for DNS. The other options either omit DNS, use an incorrect gateway, or add unnecessary parameters. The router's interface address is the appropriate default gateway for clients on that subnet.

Exam trap

The trap here is assuming that the default-router must be the highest or lowest address in the subnet, rather than the router's actual interface address.

97
MCQmedium

A network engineer is configuring a Cisco IOS XE router to act as a Dynamic Host Configuration Protocol (DHCP) client on its WAN interface. The service provider requires the router to send a specific client identifier in its DHCP requests. Which command accomplishes this?

A.ip dhcp client class-id <string>
B.ip dhcp client request <option>
C.ip dhcp client client-id <string>
D.ip dhcp client hostname <name>
AnswerC

This command, configured on the interface, specifies a custom client identifier that the router includes in its DHCP requests. The service provider can use this identifier to assign a specific lease or apply policies. It must be applied to the interface acting as the DHCP client, and the identifier can be a string or hexadecimal value.

Why this answer

The ip dhcp client client-id command allows the router to send a custom client identifier in its DHCP requests, which the service provider can use for lease assignment. The other commands set different DHCP options, such as hostname, class identifier, or requested options, and do not fulfill the requirement for a specific client identifier.

Exam trap

The trap here is confusing the DHCP client identifier with the hostname or class-id options; each serves a distinct purpose in DHCP message construction.

98
MCQhard

A network administrator is troubleshooting an MPLS L3VPN where customer routes are not being propagated between PE routers. The PE routers are Cisco IOS-XE devices running MP-BGP. Which address family must be configured on the PE routers to exchange VPNv4 prefixes?

A.address-family ipv4 multicast
B.address-family ipv4 vrf
C.address-family vpnv4
D.address-family ipv4 unicast
AnswerC

The address-family vpnv4 command under BGP configuration enables the exchange of VPNv4 prefixes between PE routers. It carries the route distinguisher and route target extended communities, which are essential for MPLS L3VPN. Without this address family activated on both PE routers, customer routes will not be propagated across the MPLS core, breaking connectivity between sites.

Why this answer

In MPLS L3VPN, PE routers exchange customer routes using MP-BGP with the VPNv4 address family. This address family supports the route distinguisher and route target extended communities that identify the VPN membership. Configuring address-family vpnv4 under BGP and activating it with the neighbor command allows the PE routers to exchange these prefixes, enabling end-to-end connectivity for the customer VRFs.

Exam trap

The trap here is assuming that the global IPv4 unicast address family can carry VPNv4 routes, or confusing VRF address family with VPNv4 address family.

99
MCQmedium

A network engineer is deploying a DMVPN Phase 3 hub-and-spoke topology. The hub router must dynamically learn spoke-to-spoke routes and allow direct spoke-to-spoke tunnels. Which technology should be implemented on the hub to achieve this?

A.Configure NHRP authentication and NHRP map entries on all routers.
B.Implement IPsec tunnel protection with IKEv2 and enable QoS pre-classify.
C.Use OSPF broadcast network type on all tunnel interfaces and enable split horizon.
D.Enable NHRP redirect on the hub and NHRP shortcut on the spokes.
AnswerD

NHRP redirect on the hub and NHRP shortcut on the spokes enable Phase 3 DMVPN. The hub sends NHRP redirect messages to spokes when it receives traffic that could go directly between them, and spokes use NHRP shortcut to resolve the destination spoke's NBMA address and build a direct tunnel, reducing hub load and latency.

Why this answer

In DMVPN Phase 3, the hub uses NHRP redirect to inform spokes that a more optimal path exists directly to another spoke. Spokes then use NHRP shortcut to resolve the destination's NBMA address and establish a direct tunnel. This reduces hub transit and latency.

The other options are valid DMVPN features but do not provide the dynamic spoke-to-spoke capability required.

Exam trap

The trap here is assuming that any NHRP configuration (like authentication or static maps) enables Phase 3 behavior, when actually only redirect and shortcut do.

100
MCQmedium

A network engineer is configuring a Cisco IOS router to support MPLS Traffic Engineering (TE). The engineer has enabled MPLS TE globally and on the interfaces, and has configured a TE tunnel. However, the tunnel is not coming up. The engineer verifies that the IGP (OSPF) is advertising TE information. Which additional configuration is required to establish the TE tunnel?

A.Configure the tunnel mode to mpls traffic-eng on all routers.
B.Enable LDP on the TE tunnel interface.
C.Enable RSVP on the interfaces along the path.
D.Configure CSPF on all routers in the path.
AnswerC

RSVP is the signaling protocol used by MPLS TE to reserve resources and establish label-switched paths. Even if the IGP advertises TE information, without RSVP enabled on the interfaces, the TE tunnel cannot signal the path and reserve bandwidth. Enabling RSVP on all interfaces along the intended path is essential for the tunnel to come up.

Why this answer

For MPLS TE tunnels to be established, RSVP must be enabled on all interfaces that the tunnel traverses. RSVP handles the signaling and resource reservation. While the IGP advertises TE information, without RSVP the headend cannot signal the path.

Therefore, enabling RSVP on the relevant interfaces is the required additional configuration.

Exam trap

The trap here is assuming that IGP TE extensions alone are sufficient for TE tunnel establishment, overlooking the need for RSVP signaling.

101
MCQhard

A network administrator is implementing IPsec VPN between two Cisco routers. The administrator wants to ensure that only specific traffic, defined by an extended access list, is encrypted and sent through the tunnel, while all other traffic is sent unencrypted. Which IPsec configuration element is used to define this traffic?

A.transform set
B.ISAKMP policy
C.crypto access list
D.crypto map
AnswerC

The crypto access list, configured with an extended access list and referenced in the crypto map, defines which traffic is encrypted and sent through the IPsec tunnel. Traffic permitted by the access list is encrypted, while denied traffic is sent unencrypted. This is the correct element for specifying the interesting traffic in an IPsec VPN configuration on Cisco routers.

Why this answer

In Cisco IOS IPsec configuration, the crypto access list (an extended ACL) specifies the traffic that should be encrypted and tunneled. The crypto map then references this access list to apply the IPsec policies. Other components like transform sets and ISAKMP policies handle protection and negotiation, not traffic selection.

Exam trap

The trap here is assuming that the crypto map itself defines the encrypted traffic, when it only references the access list that does so.

102
MCQmedium

A network engineer is configuring a Cisco IOS router to use Policy-Based Routing (PBR) to forward traffic from a specific subnet to a next-hop address. The route-map is named PBR_MAP, and the interface is GigabitEthernet0/0. Which command sequence correctly applies the route-map to the interface for incoming packets?

A.interface GigabitEthernet0/0 ip route-cache policy
B.route-map PBR_MAP permit 10 match ip address 101 set ip next-hop 10.1.1.1 interface GigabitEthernet0/0 ip policy route-map PBR_MAP
C.interface GigabitEthernet0/0 ip route-map PBR_MAP in
D.interface GigabitEthernet0/0 ip policy route-map PBR_MAP
AnswerD

The ip policy route-map command, configured under the interface, enables PBR for packets arriving on that interface. The route-map defines the match and set criteria that determine how packets are handled. This is the correct and standard method to apply PBR on Cisco IOS routers for policy routing of ingress traffic.

Why this answer

To apply PBR on an interface, the ip policy route-map command is used, referencing the route-map name. This command enables policy routing for packets entering the interface. The other options either use incorrect syntax or include unnecessary configuration details.

The correct application is straightforward.

Exam trap

The trap here is confusing the command to apply a route-map for PBR with commands used for other features, or including the route-map definition when only the application command is asked.

103
MCQmedium

A network engineer is configuring a Cisco IOS XE router as a Dynamic Host Configuration Protocol (DHCP) server for a guest wireless subnet. The router must dynamically allocate addresses from the 192.168.50.0/24 pool, but the first 30 addresses must be reserved for static assignment to access points and controllers. Which command must be issued to prevent the DHCP server from offering those addresses?

A.ip dhcp excluded-address 192.168.50.1 192.168.50.30
B.ip dhcp pool GUEST network 192.168.50.0 255.255.255.224
C.ip dhcp excluded-address 192.168.50.1 192.168.50.30 255.255.255.0
D.ip dhcp pool GUEST address 192.168.50.1 192.168.50.30
AnswerA

This command globally excludes the range 192.168.50.1 through 192.168.50.30 from any DHCP pool on the router. In this scenario, it ensures the server never offers those addresses, leaving them available for manual static configuration on access points and controllers while the remaining addresses in 192.168.50.0/24 are dynamically leased.

Why this answer

The ip dhcp excluded-address command with a start and end address prevents the Cisco IOS XE DHCP server from offering that range from any pool. This correctly reserves the first 30 addresses for static assignment while allowing the rest of the /24 to be leased dynamically. Other commands either restrict the pool incorrectly, introduce invalid syntax, or create static bindings instead of exclusions.

Exam trap

The trap here is assuming that a subnet mask can be appended to the ip dhcp excluded-address command or that the pool network statement can exclude addresses.

104
MCQhard

A network engineer is troubleshooting a DMVPN Phase 3 deployment on a Cisco IOS XE hub. Spokes use NHRP to register with the hub and have working mGRE tunnels to the hub. The design requires that spoke-to-spoke traffic be sent directly between spokes without transiting the hub's data path. The engineer observes that all spoke-to-spoke packets still traverse the hub even though spoke registration and routing are correct. Which configuration change on the hub is required to enable direct spoke-to-spoke forwarding?

A.Configure ip nhrp redirect on the hub so the hub can inform the source spoke that a better path exists, triggering an NHRP resolution for the destination spoke.
B.Configure ip nhrp shortcut on the hub so the hub can cache the destination spoke's NBMA mapping and forward directly.
C.Configure ip nhrp map multicast dynamic on the hub so the hub can dynamically learn the NBMA addresses of all registering spokes.
D.Configure no ip next-hop-self eigrp under the tunnel interface's routing process so the hub does not rewrite the next hop for EIGRP routes.
AnswerA

In DMVPN Phase 3, the hub uses NHRP redirect to notify a source spoke that traffic it sent through the hub could be sent directly. The redirect causes the source spoke to issue an NHRP resolution request for the destination spoke's NBMA address, after which it builds a direct tunnel. Without ip nhrp redirect on the hub, spokes keep forwarding through the hub even though they could shortcut.

Why this answer

DMVPN Phase 3 achieves direct spoke-to-spoke forwarding by combining hub-side NHRP redirect with spoke-side NHRP shortcut. When a spoke sends traffic through the hub, the hub issues an NHRP redirect telling the source spoke a better path exists. The spoke then resolves the destination's NBMA address and installs a shortcut route, allowing direct forwarding.

Without the hub redirect, spokes continue to hairpin traffic through the hub.

Exam trap

The trap here is confusing the hub-side NHRP redirect feature with the spoke-side NHRP shortcut feature, or assuming multicast mapping commands enable direct spoke-to-spoke paths.

105
MCQeasy

A network engineer is configuring a GRE tunnel between two Cisco IOS routers to transport multicast traffic. The engineer notices that multicast packets are not being forwarded over the tunnel. Which command is required on the tunnel interface to enable multicast forwarding?

A.keepalive 10 3
B.ip mtu 1400
C.tunnel mode gre multipoint
D.ip pim sparse-mode
AnswerD

To forward multicast traffic over a GRE tunnel, the tunnel interface must have IP PIM enabled. The ip pim sparse-mode command enables PIM on the interface, allowing it to participate in multicast routing. Without PIM on the tunnel interface, multicast packets will not be forwarded, even if the tunnel is up.

Why this answer

Multicast forwarding over a GRE tunnel requires PIM to be enabled on the tunnel interface. The ip pim sparse-mode command activates PIM on the interface, allowing it to send and receive multicast traffic. Without this, the tunnel will not forward multicast packets, regardless of other tunnel settings.

Exam trap

The trap here is focusing on tunnel mode or MTU settings while overlooking the need for PIM on the tunnel interface to enable multicast.

106
MCQeasy

A network engineer is configuring a Cisco IOS router to support MPLS Layer 3 VPNs. The engineer needs to enable the provider edge (PE) router to exchange VPNv4 routes with other PE routers. Which protocol is used to distribute VPNv4 routes between PE routers?

A.RSVP-TE
B.OSPFv2
C.LDP
D.BGP with the VPNv4 address family
AnswerD

Multiprotocol BGP (MP-BGP) with the VPNv4 address family is used to distribute VPNv4 routes between PE routers in an MPLS L3VPN environment. It carries the route targets and route distinguishers as extended communities, enabling proper VPN membership and route separation. BGP is the only protocol that supports the necessary address family and attributes for VPNv4 route exchange, making it the correct choice.

Why this answer

MP-BGP with the VPNv4 address family is the standard protocol for exchanging VPNv4 routes between PE routers in MPLS L3VPN deployments. It carries the necessary extended communities (route targets, route distinguishers) to support multiple VPNs. Other protocols like OSPF, LDP, and RSVP-TE serve different purposes and cannot distribute VPNv4 routes.

Exam trap

The trap here is confusing the protocol used for label distribution (LDP) with the protocol used for VPN route distribution (MP-BGP).

← PreviousPage 2 of 2 · 106 questions total

Ready to test yourself?

Try a timed practice session using only Infrastructure Services questions.