Courseiva

ENCOR 350-401 (350-401) — Questions 1–75

1923 questions total · 26pages · All types, answers revealed

Page 1 of 26

Page 2
1
Matchingmedium

Drag and drop each NFV management layer on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Lifecycle management of VNF instances (instantiate, scale, terminate)

Orchestration of network services across multiple VNFs and NFVI

Management of compute, storage, and network resources in NFVI

Service assurance, billing, and customer management layers interfacing with NFV

FCAPS management for individual VNFs

Why these pairings

VNFM manages individual VNFs; NFVO orchestrates network services; VIM controls NFVI resources.

2
MCQmedium

Review this IP SLA configuration on Router R1: ip sla 6 icmp-echo 10.6.6.6 frequency 10 ip sla schedule 6 life forever start-time now ip sla reaction-configuration 6 react timeout threshold-type immediate action-type triggerOnly Which statement is true about the 'threshold-type immediate' parameter?

A.It triggers an event immediately when a timeout occurs.
B.It triggers an event after a delay of 10 seconds.
C.It triggers an event only if the timeout persists for 5 consecutive probes.
D.It triggers an event only if the timeout occurs within the first 10 seconds.
AnswerA

With IP SLA reaction-configuration, the 'immediate' threshold type is designed to trigger the event on the very first timeout occurrence, with no dependency on prior probe results. This means a single failed probe immediately generates the configured action (e.g., SNMP trap or track object state change), enabling the fastest possible detection of a failure. It is the default-like behavior for urgent alerting, but it does not consider any subsequent probe outcomes.

Why this answer

The 'threshold-type immediate' parameter in an IP SLA reaction configuration causes the router to trigger the specified action (in this case, 'triggerOnly') as soon as a single probe timeout occurs, without waiting for any additional probes or a delay. This is correct because the configuration explicitly sets the threshold type to immediate, meaning the reaction is instantaneous upon detecting the timeout event.

Exam trap

Cisco often tests the distinction between 'immediate' and 'consecutive' threshold types, and the trap here is that candidates may confuse 'immediate' with a delayed or cumulative condition, assuming it requires multiple failures or a specific time window.

How to eliminate wrong answers

Option B is wrong because 'threshold-type immediate' does not introduce any delay; a delay would require a different threshold type, such as 'threshold-type x' with a specific time value. Option C is wrong because triggering only after 5 consecutive timeouts would require the 'threshold-type consecutive' parameter, not 'immediate'. Option D is wrong because the 'immediate' threshold is not limited to the first 10 seconds; it reacts to any timeout regardless of when it occurs within the probe's frequency interval.

3
Multi-Selecthard

Which three statements about Cisco DNA Center integration with external systems are true? (Choose three.)

Select 3 answers
A.Cisco DNA Center provides a RESTful API that allows external applications to retrieve network inventory and topology data.
B.Cisco DNA Center can forward syslog messages to external SIEM systems for centralized logging and analysis.
C.Cisco DNA Center can synchronize IP address pools with external IPAM solutions such as Infoblox or SolarWinds.
D.Cisco DNA Center establishes BGP peering sessions with external routers to exchange routing information.
E.Cisco DNA Center only supports SNMP traps as the northbound interface for event notifications.
AnswersA, B, C

The RESTful API exposes inventory and topology programmatically, letting external applications pull live device and link data without manual export. This satisfies the integration requirement by providing northbound, standards-based access to Cisco DNA Center's network model.

Why this answer

Option A is correct because Cisco DNA Center exposes a RESTful (HTTPS/JSON) northbound API, including the Intent API, that external applications can call to retrieve inventory, topology, device health, and site data programmatically. Option B is correct because DNA Center can be configured with syslog destinations (external syslog/SIEM servers) so that device and system events are forwarded for centralized logging, correlation, and analysis. Option C is correct because DNA Center supports IP Address Management (IPAM) integration with third-party IPAM systems such as Infoblox and SolarWinds, allowing IP pools and address space to be synchronized via the IPAM API/plugin.

Option D is not correct because DNA Center is a management, automation, and assurance platform; it does not peer with external routers using BGP to exchange routes. Option E is not correct because DNA Center's northbound interfaces include REST APIs, webhooks, and syslog/SNMP trap forwarding, so it is false that SNMP traps are the only event notification interface.

Exam trap

350-401 often tests whether candidates confuse DNA Center's northbound management integrations (REST, syslog, IPAM) with actual data-plane or control-plane routing functions like BGP peering, which DNA Center does not perform.

4
MCQeasy

A network team is designing the underlay for an SD-Access fabric. The design must use a routing protocol that supports fast convergence and is commonly recommended for the fabric underlay. Which routing protocol should be used?

A.IS-IS
B.RIP
C.EIGRP
D.BGP
AnswerA

IS-IS is the recommended underlay routing protocol for Cisco SD-Access because it is a link-state IGP that scales to large campus fabrics, supports both IPv4 and IPv6 natively, and converges rapidly after link or node failures. It runs directly over Layer 2 using CLNS, making it independent of IP addressing, which is valuable during underlay bootstrap. Fabric nodes use IS-IS to build a loop-free physical topology, and it can carry host-specific routes for seamless mobility.

Why this answer

IS-IS is the correct choice because it is a link-state routing protocol that provides fast convergence, is highly scalable, and is the most commonly recommended routing protocol for the underlay of an SD-Access fabric. Cisco SD-Access designs frequently use IS-IS to support the fabric's control plane and data plane requirements, leveraging its ability to handle large, flat network topologies with minimal overhead.

Exam trap

Cisco often tests the misconception that EIGRP is the best choice for fast convergence in Cisco-centric designs, but for SD-Access underlay, the recommended protocol is IS-IS due to its open standard nature and alignment with Cisco's validated fabric architecture.

How to eliminate wrong answers

Option B (RIP) is wrong because RIP is a distance-vector protocol with slow convergence, a maximum hop count of 15, and is not suitable for modern, scalable SD-Access underlays. Option C (EIGRP) is wrong because while EIGRP offers fast convergence, it is a Cisco proprietary protocol that is not recommended for SD-Access underlays; Cisco's validated designs for SD-Access specify IS-IS or OSPF for multi-vendor interoperability and fabric consistency. Option D (BGP) is wrong because BGP is a path-vector protocol designed for inter-domain routing and policy control, not for fast convergence in a single-domain underlay; it is used in SD-Access for the overlay (e.g., LISP/VXLAN) but not as the underlay routing protocol.

5
MCQhard

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against excessive ARP traffic. The engineer applies the following policy: policy-map COPP-POLICY class ARP-CLASS police 8000 conform-action transmit exceed-action drop After applying the service-policy to the control-plane, the engineer notices that legitimate ARP requests are being dropped during peak hours. Which action should the engineer take to resolve this issue while maintaining protection?

A.Add a class-map that matches ARP replies and apply a separate police rate to that class.
B.Increase the police rate to a higher value that accommodates peak ARP traffic while still limiting excessive bursts.
C.Remove the service-policy from the control-plane and apply it to the data plane instead.
D.Change the exceed-action to transmit so that all ARP packets are allowed through.
AnswerB

The police rate of 8000 bps is too low for peak ARP traffic, causing legitimate ARP requests to be dropped. Increasing the rate to a value that matches normal peak traffic while still providing an upper bound protects the control plane without dropping legitimate traffic. This is the correct tuning approach for CoPP.

Why this answer

CoPP police rates must be tuned to allow legitimate control-plane traffic while blocking excess. A rate of 8000 bps is insufficient for ARP during peak hours, so increasing the rate to a realistic peak value resolves drops while preserving protection. Changing exceed-action to transmit removes protection, moving the policy to the data plane is ineffective, and splitting classes without raising the rate does not fix the underlying issue.

Exam trap

The trap here is thinking that any drop means the policy is too strict and should be disabled, rather than tuning the rate to match legitimate traffic patterns.

6
MCQmedium

A network engineer is configuring QoS on a Cisco IOS switch. The engineer needs to mark packets coming from a specific server with DSCP EF (46) and ensure that this marking is trusted throughout the network. Which command should be used to trust the DSCP markings on the interface connected to the server?

A.mls qos trust dscp
B.mls qos trust cos
C.mls qos trust ip-precedence
D.mls qos map cos-dscp 0 8 16 24 32 40 48 56
AnswerA

The 'mls qos trust dscp' command configures the interface to trust the DSCP value in incoming packets. This means the switch will use the existing DSCP marking for classification and queuing, rather than overwriting it. This is appropriate when the server is already marking its traffic with DSCP EF, as it preserves the marking and ensures proper treatment across the network.

Why this answer

To trust DSCP markings on an interface, the correct command is 'mls qos trust dscp'. This tells the switch to accept the DSCP value in incoming packets and use it for QoS processing. Since the server is already marking its traffic with DSCP EF, this command ensures that the marking is preserved and honored throughout the network, preventing the switch from re-marking the packets.

Exam trap

The trap here is confusing trust boundaries and assuming that trusting CoS is equivalent to trusting DSCP, even when the server sends untagged frames.

7
MCQmedium

An engineer is configuring a new access switch for a branch office. The switch must support multiple VLANs for different departments: VLAN 10 (Engineering), VLAN 20 (Sales), and VLAN 30 (Management). The uplink to the distribution switch is a trunk. The engineer wants to ensure that only the required VLANs are allowed on the trunk and that the native VLAN is changed from the default to VLAN 99 for security reasons. Which configuration commands should the engineer apply on the access switch's uplink interface?

A.switchport mode trunk; switchport trunk native vlan 99; switchport trunk allowed vlan 10,20,30
B.switchport mode trunk; switchport trunk native vlan 99; switchport trunk allowed vlan except 10,20,30
C.switchport mode dynamic desirable; switchport trunk native vlan 99; switchport trunk allowed vlan 10,20,30
D.switchport trunk encapsulation dot1q; switchport mode trunk; switchport trunk native vlan 99
AnswerA

This configuration statically enables trunking with `switchport mode trunk`, sets the native VLAN to 99 so that untagged frames are mapped to that VLAN, and uses the allowed VLAN list to permit only VLANs 10, 20, and 30 across the trunk. The combination restricts the trunk to the explicitly required VLANs while still allowing the native VLAN to be untagged, which matches the requirement exactly. Without the allowed list, the trunk would carry all active VLANs, so this command is the critical part that scopes the trunk.

Why this answer

It explicitly sets the interface to trunk mode, changes the native VLAN from the default VLAN 1 to VLAN 99 for security, and uses the 'allowed vlan' command to permit only VLANs 10, 20, and 30 on the trunk. This ensures that only the required department VLANs are carried, reducing unnecessary broadcast traffic and preventing VLAN hopping attacks by changing the native VLAN.

Exam trap

Cisco often tests the distinction between 'allowed vlan' and 'allowed vlan except' — candidates may confuse the syntax and select the option that excludes the required VLANs instead of permitting them.

How to eliminate wrong answers

Option B is wrong because 'switchport trunk allowed vlan except 10,20,30' permits all VLANs except 10, 20, and 30, which is the opposite of the requirement. Option C is wrong because 'switchport mode dynamic desirable' uses DTP to negotiate trunking, which is less secure and not a deterministic trunk configuration; the requirement is for a static trunk. Option D is wrong because it omits the 'switchport trunk allowed vlan' command, so all VLANs would be permitted by default, failing to restrict the trunk to only the required VLANs.

8
Multi-Selecthard

Which three statements about telemetry data collection intervals and on-change notifications are true? (Choose three.)

Select 3 answers
A.Periodic telemetry sends data at a configured interval regardless of whether the value has changed.
B.On-change telemetry sends data only when the monitored value changes, reducing network overhead.
C.A single telemetry subscription can include both periodic and on-change sensors.
D.On-change telemetry guarantees that every change, no matter how brief, will be reported.
E.Periodic telemetry is always preferred over on-change for all use cases.
AnswersA, B, C

Periodic telemetry pushes readings on a fixed schedule, so unchanged values are still transmitted. This satisfies the stem's interval-based collection model, in contrast to on-change notifications, which fire only when a monitored value actually differs from its previous state.

Why this answer

Option A is correct because periodic telemetry is interval-driven: the collector pushes the sensor value at the configured period (e.g., every 30 seconds) whether or not the value differs from the previous sample. Option B is correct because on-change telemetry is event-driven, transmitting a sample only when the monitored value crosses or changes from its prior state, which cuts the volume of updates and thus network and processing overhead. Option C is correct because a single subscription (for example, a gNMI/RFC 8641 or NETCONF telemetry subscription) can carry multiple sensor paths with different modes, so periodic and on-change sensors can coexist under one subscription.

Option D is not correct because on-change reporting is not lossless: very brief transitions can be missed between sampling or dampening windows, and some implementations suppress rapid flapping, so no guarantee exists that every transient change is reported. Option E is not correct because neither mode is universally preferable; periodic suits continuous monitoring and trending, while on-change suits state or event monitoring, and the choice depends on the use case.

Exam trap

350-401 often tests the misconception that on-change telemetry captures every single change, but it can miss brief changes due to sampling or dampening.

9
MCQmedium

interface GigabitEthernet0/1 ip address 10.1.1.1 255.255.255.0 mpls ip ! interface GigabitEthernet0/2 ip address 10.2.2.1 255.255.255.0 mpls ip ! router ospf 1 network 10.0.0.0 0.255.255.255 area 0 ! router ldp interface GigabitEthernet0/1 ! What is the effect of this configuration?

A.LDP will only form an adjacency over GigabitEthernet0/1; no label exchange occurs on GigabitEthernet0/2.
B.LDP will automatically enable on GigabitEthernet0/2 because MPLS is enabled there.
C.The configuration will fail because LDP must be enabled on all MPLS interfaces.
D.OSPF will automatically enable LDP on all interfaces in area 0.
AnswerA

LDP hello messages are multicast on interfaces where LDP is explicitly enabled, typically via the 'mpls ldp' configuration. Because GigabitEthernet0/2 lacks this LDP configuration, it does not participate in LDP neighbor discovery or label binding exchange. Consequently, the LDP adjacency is confined to GigabitEthernet0/1, and only that interface exchanges label mappings; MPLS forwarding may still occur on Gi0/2 using labels learned from other sources, but no dynamic LDP labels are exchanged there.

Why this answer

LDP is explicitly enabled only on GigabitEthernet0/1 under the 'router ldp' configuration. Although MPLS IP is enabled on GigabitEthernet0/2, LDP does not automatically form an adjacency or exchange labels on that interface unless it is explicitly configured under the LDP router process. LDP adjacencies are interface-specific and require the 'interface' command under 'router ldp' to be activated.

Exam trap

Cisco often tests the distinction between 'mpls ip' (which enables MPLS forwarding) and LDP configuration (which controls label distribution adjacencies), trapping candidates who assume that enabling MPLS on an interface automatically activates LDP.

How to eliminate wrong answers

Option B is wrong because enabling 'mpls ip' on an interface does not automatically enable LDP; LDP must be explicitly configured under 'router ldp' with the specific interface. Option C is wrong because the configuration will not fail; LDP can be selectively enabled on a subset of MPLS-enabled interfaces, and MPLS forwarding can still occur on other interfaces via static labels or other label distribution protocols. Option D is wrong because OSPF has no mechanism to automatically enable LDP; LDP is a separate protocol that must be configured independently, regardless of the IGP.

10
MCQhard

An engineer is deploying a new SD-WAN solution using Cisco vManage. The WAN edge routers are connected to two different transport networks: MPLS and Internet. The engineer wants to ensure that voice traffic is always sent over the MPLS link when available, and only fails over to the Internet link if the MPLS link goes down. The engineer has configured a policy to set the preferred color for voice traffic to 'mpls'. However, during a test, voice traffic is still using the Internet link even though the MPLS link is up. What is the most likely cause?

A.The policy is not attached to the correct VPN or site list.
B.The voice traffic is using a different DSCP value than the one defined in the policy.
C.The MPLS link is not in the 'up' state in the vManage overlay.
D.The policy is configured as a local policy instead of a centralized policy.
AnswerA

In vManage, a preferred-color policy is enforced only after it is attached to a specific VPN or site list via the policy's 'Site and VPN' configuration. If the policy is not bound to the VPN that carries voice traffic, the vSmart controller will not inject the corresponding route attributes, leaving the traffic on its default path. Correct attachment is a prerequisite for any centralized policy to take effect, so a policy that is missing from the correct VPN or site list will silently do nothing.

Why this answer

The most likely cause is that the policy is not attached to the correct VPN or site list. In Cisco SD-WAN, a centralized data policy must be applied to a specific VPN (e.g., VPN 0 for transport, VPN 10 for service-side) and/or a site list to take effect. Even if the policy correctly sets the preferred color to 'mpls', it will not influence traffic forwarding unless it is properly associated with the VPN carrying the voice traffic and the site list containing the affected routers.

Exam trap

Cisco often tests the misconception that configuring a policy alone is sufficient, when in fact the policy must be attached to the correct VPN and site list to be activated—candidates overlook the attachment step and assume the policy is automatically applied to all traffic.

How to eliminate wrong answers

Option B is wrong because if the voice traffic uses a different DSCP value than the one defined in the policy, the policy would simply not match that traffic, but the question states the policy is configured to set the preferred color for voice traffic—implying the match condition is correct; the core issue is the policy not being applied. Option C is wrong because the MPLS link being 'up' in vManage is a prerequisite for the policy to work, but the engineer confirmed the MPLS link is up, so this is not the cause. Option D is wrong because a local policy (applied per device) would still affect traffic if attached correctly; the distinction between local and centralized policy affects scope and management, not the fundamental ability to steer traffic—the failure here is due to lack of attachment, not policy type.

11
MCQhard

A network architect is designing a Cisco SD-Access fabric. The customer requires that the fabric support both IPv4 and IPv6 traffic natively without the use of any translation mechanisms. Which statement describes the correct configuration approach?

A.The fabric underlay must be configured with IPv6 only, and the overlay can be dual-stack.
B.IPv6 is not supported in SD-Access; only IPv4 is supported in the overlay.
C.IPv6 traffic must be translated to IPv4 at the fabric edge using NAT64.
D.The fabric overlay can be configured as dual-stack, supporting both IPv4 and IPv6, while the underlay remains IPv4.
AnswerD

Cisco SD-Access supports a dual-stack overlay, meaning that both IPv4 and IPv6 packets can be encapsulated in VXLAN and transported over an IPv4 underlay. This allows native IPv6 communication without translation. The underlay can remain IPv4, as the fabric data plane uses VXLAN with an IPv4 transport. This is the recommended approach for supporting both protocols natively.

Why this answer

Cisco SD-Access supports a dual-stack overlay, allowing both IPv4 and IPv6 to be carried natively over an IPv4 underlay. The VXLAN data plane encapsulates Layer 2 frames, which can carry either IPv4 or IPv6 packets. The underlay can remain IPv4, as it only needs to route the VXLAN tunnel endpoints.

This design meets the requirement for native IPv6 without translation. No translation mechanisms like NAT64 are needed.

Exam trap

The trap here is assuming that native IPv6 support requires an IPv6-only underlay or translation, when in fact the overlay can be dual-stack over an IPv4 underlay.

12
MCQhard

A network engineer is configuring a switch stack with two Catalyst 9300 switches. The engineer wants to ensure that if the active switch fails, the standby switch takes over with minimal disruption. Which statement accurately describes the stack MAC address behavior during a failover?

A.The stack MAC address is a virtual MAC address generated by the stack protocol and never changes.
B.The stack MAC address immediately changes to the new active switch's MAC address upon failover.
C.The stack MAC address is always the MAC address of the switch with the highest priority, regardless of failover.
D.The stack MAC address remains the same as the original active switch's MAC address unless the stack MAC persistence timer expires.
AnswerD

By default, the stack retains the MAC address of the original active switch for a period defined by the stack MAC persistence timer (default 4 minutes). If the failover occurs and the timer has not expired, the new active switch continues using the same stack MAC address, minimizing disruption to neighboring devices and avoiding MAC address table changes.

Why this answer

The stack MAC persistence feature keeps the original active switch's MAC address for a configurable timer (default 4 minutes). During a failover, the standby switch becomes active and continues using that MAC address if the timer has not expired. This minimizes network disruption by avoiding MAC address table updates on neighboring devices.

Exam trap

The trap here is assuming that the stack MAC address changes immediately upon failover, when in fact it is preserved by default for a persistence period.

13
MCQmedium

An enterprise is deploying a leaf-spine architecture in its data center to support high-bandwidth east-west traffic. The design must include QoS to prioritize storage replication traffic (iSCSI) over backup traffic, while ensuring low latency for real-time applications. Where should the architect apply QoS classification and queuing policies in this topology?

A.Apply classification and marking on the leaf switches at ingress, and queuing policies on egress interfaces of both leaf and spine switches.
B.Apply all QoS policies only on the spine switches, since they handle inter-leaf traffic.
C.Configure QoS only on the default gateway router, which is upstream of the leaf-spine fabric.
D.Use a single QoS policy on all interfaces with default settings, relying on hardware buffers.
AnswerA

This is the correct QoS architecture. In a leaf-spine fabric, the leaf switch is the first device to see server-originated traffic, so it must be the trust boundary: classify and mark traffic (e.g., iSCSI as EF or AF4x, backup as AF11) at ingress, using ACLs, class-maps, and policy-maps. Then apply egress queuing policies on both leaf and spine egress interfaces: spines handle inter-leaf traffic and need the same scheduling (strict priority, bandwidth allocation, WRED) based on the already-marked DSCP values, while leaf egress interfaces handle traffic toward servers (including storage targets). Marking at ingress and consistent queuing at every egress hop preserves the PHB (Per-Hop Behavior) across the fabric, so iSCSI latency and loss stay controlled even when backup traffic congests the network.

Why this answer

In a leaf-spine architecture, QoS classification and marking must occur at the ingress of leaf switches (where traffic enters the fabric) to identify iSCSI, backup, and real-time flows. Queuing policies must be applied on egress interfaces of both leaf and spine switches to manage congestion and prioritize latency-sensitive traffic across the entire path, ensuring end-to-end QoS for east-west traffic.

Exam trap

Cisco often tests the misconception that QoS policies should be applied only at the core or spine layer, but the correct approach requires classification at the edge (leaf ingress) and queuing on all egress interfaces to ensure end-to-end treatment across the fabric.

How to eliminate wrong answers

Option B is wrong because applying QoS only on spine switches ignores the need for classification at the network edge (leaf switches) and fails to manage congestion on leaf egress interfaces, where traffic first enters the fabric. Option C is wrong because the default gateway router is upstream of the leaf-spine fabric and does not handle inter-leaf east-west traffic; QoS must be applied within the fabric itself. Option D is wrong because relying on default settings and hardware buffers does not provide the granular classification, marking, and queuing required to differentiate iSCSI, backup, and real-time traffic, leading to potential packet loss and latency issues.

14
Drag & Dropmedium

Drag and drop the steps of hierarchical LAN design implementation phases into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Hierarchical LAN design starts with the access layer for endpoint connectivity, then the distribution layer for policy and aggregation, followed by the core layer for high-speed transport. After physical design, VLANs and trunking are configured, and finally routing protocols are deployed for inter-VLAN communication.

15
Multi-Selecthard

Which TWO statements are correct about Cisco SD-Access architecture? (Choose two.)

Select 2 answers
A.VXLAN encapsulation is used for data plane traffic within the fabric.
B.Control plane nodes host the LISP mapping database.
C.Wireless access points must be directly connected to the fabric edge switches.
D.Fabric edge nodes are responsible for connecting the fabric to external networks.
E.The fabric uses VLANs to isolate tenant traffic.
AnswersA, B

VXLAN is the encapsulation used to carry Layer 2 frames over Layer 3 fabric.

Why this answer

VXLAN is the encapsulation protocol used in the Cisco SD-Access fabric to carry data plane traffic between fabric edge nodes. VXLAN provides a Layer 2 overlay over a Layer 3 underlay, enabling scalable segmentation and mobility without VLAN limitations.

Exam trap

Cisco often tests the misconception that VLANs are used for fabric segmentation, but the correct answer is VXLAN VNIs; similarly, candidates may confuse the roles of fabric edge and border nodes, thinking edges handle external connectivity.

16
MCQmedium

An engineer is configuring an IPsec site-to-site VPN between two Cisco IOS XE routers. Phase 1 completes successfully, but Phase 2 fails and no interesting traffic is encrypted. The engineer confirms that the ACLs on both peers mirror each other correctly. Which configuration element should be verified next to resolve the Phase 2 failure?

A.Verify that the Diffie-Hellman group in the ISAKMP policy matches the group used in the transform set.
B.Verify that the crypto map sequence number is higher on the responding peer than on the initiating peer.
C.Verify that the ISAKMP policy on both peers uses the same pre-shared key for Phase 1 authentication.
D.Verify that the transform set on both peers specifies matching encryption and integrity algorithms for Phase 2.
AnswerD

Phase 2 negotiation uses the transform set to define encryption and integrity algorithms for the IPsec SA. If the transform sets differ between peers, the quick mode negotiation fails even though Phase 1 succeeded. Matching transform sets on both routers is essential to complete Phase 2 and establish the data-protection tunnel.

Why this answer

IPsec Phase 2 negotiation, also called quick mode, relies on matching transform sets that define the encryption and integrity algorithms for the data SA. When Phase 1 succeeds but Phase 2 fails, mismatched transform sets are a common cause. Verifying that both peers use identical transform set definitions resolves the negotiation failure.

Exam trap

The trap here is revisiting Phase 1 parameters such as the pre-shared key after Phase 1 has already succeeded, instead of focusing on Phase 2 elements like the transform set.

17
MCQhard

A network engineer is configuring CoPP on a Cisco Nexus 9000 switch to protect the control plane from a potential DoS attack. The engineer creates a class-map that matches traffic with a specific DSCP value (AF41) and applies a police rate of 10 Mbps. After applying the policy, the engineer notices that legitimate traffic with DSCP AF41 is being dropped even though the traffic rate is only 5 Mbps. What is the most likely cause?

A.The CoPP policy has a conform-action of drop, which drops all traffic matching the class.
B.The police rate is too low, and the traffic is being dropped due to exceeding the rate.
C.The DSCP value AF41 is not supported on Nexus switches.
D.The CoPP policy is applied to the wrong queue, causing all traffic to be dropped.
AnswerA

In Control-Plane Policing (CoPP) on Nexus switches, the police command defines separate actions for packets that conform to, exceed, or violate the configured rate. If the conform-action is set to 'drop', the policer drops every packet matching that class map, regardless of its instantaneous rate or whether it falls within the committed burst. Since the observed 5 Mbps is below the 10 Mbps police rate, the traffic is conforming; yet it is still dropped, which precisely matches a conform-action of drop rather than the common 'transmit' conform-action. This effectively turns the class into an unconditional drop filter for control-plane traffic.

Why this answer

The CoPP policy's conform-action of drop explicitly instructs the switch to discard all packets that match the class-map, regardless of the traffic rate. Even though the traffic rate is only 5 Mbps (below the 10 Mbps police rate), the drop action overrides the policing logic, causing legitimate AF41 traffic to be dropped. This is a common misconfiguration where the engineer sets the action to 'drop' instead of 'transmit' for conforming traffic.

Exam trap

Cisco often tests the distinction between the police rate and the police action, trapping candidates who assume that a rate below the configured limit automatically allows traffic, without checking the conform-action parameter.

How to eliminate wrong answers

Option B is wrong because the traffic rate of 5 Mbps is below the configured police rate of 10 Mbps, so traffic should not be dropped due to exceeding the rate; the issue is the action, not the rate. Option C is wrong because DSCP AF41 (decimal value 34) is fully supported on Nexus 9000 switches as part of the standard DiffServ code point set defined in RFC 2474. Option D is wrong because CoPP policies are applied to the control-plane interface globally, not to a specific queue; queue-based dropping would involve QoS policies, not CoPP.

18
MCQhard

A network engineer is implementing VXLAN with an EVPN control plane in a Cisco Nexus data center. The requirement is to provide Layer 2 extension over a Layer 3 underlay while maintaining optimal forwarding and avoiding unknown unicast flooding. Which statement describes the role of the EVPN control plane in this VXLAN fabric?

A.EVPN uses PIM-SM to build multicast trees for BUM traffic, and MAC addresses are learned only through data plane flooding.
B.EVPN uses a centralized SDN controller to distribute MAC addresses, and VTEPs must query the controller for every unknown destination.
C.EVPN relies on OSPF to flood MAC address updates to all VTEPs, ensuring that unknown unicast traffic is replicated across the fabric.
D.EVPN uses MP-BGP to distribute MAC and IP reachability information, enabling the VTEPs to learn remote MAC addresses and suppress unknown unicast flooding.
AnswerD

EVPN acts as the control plane for VXLAN, using MP-BGP to advertise MAC and IP addresses (Type 2 and Type 5 routes) to other VTEPs. This allows each VTEP to build a forwarding table for remote hosts, eliminating the need for flooding to learn MAC addresses and enabling optimal forwarding across the Layer 3 underlay.

Why this answer

EVPN with MP-BGP provides a scalable control plane for VXLAN by advertising MAC and IP reachability, which enables remote MAC learning and eliminates unknown unicast flooding. This improves efficiency and allows for optimal forwarding. The other options misattribute the control protocol or describe mechanisms that do not provide EVPN's benefits.

Exam trap

The trap here is confusing the underlay multicast mechanism (PIM-SM) with the overlay control plane (EVPN), or assuming a centralized controller is required for EVPN.

19
MCQhard

A network engineer is troubleshooting a Cisco SD-WAN deployment. The engineer notices that a branch site's vEdge router is not establishing control connections to the vSmart controller. The vEdge has the correct system IP and organization name. Which action should the engineer take first to verify connectivity?

A.Check the vEdge's configuration for the correct vBond IP address and ensure UDP port 12346 is open.
B.Ensure that the vEdge's WAN interface has a public IP address and can reach the internet.
C.Verify that the vSmart controller has the correct certificate and is in the whitelist.
D.Check the vManage GUI for the vEdge's serial number and ensure it is listed in the authorized devices.
AnswerA

The vEdge must first connect to the vBond orchestrator to learn about vSmart and vManage. The vBond IP address must be correctly configured, and UDP port 12346 must be open for the DTLS control connection. If the vEdge cannot reach vBond, it will not obtain the vSmart information and cannot establish control connections. This is the first step in troubleshooting.

Why this answer

In Cisco SD-WAN, a vEdge router must first establish a control connection to the vBond orchestrator. This requires the vBond IP address to be configured and UDP port 12346 to be open. Once the vEdge authenticates with vBond, it receives the list of vSmart controllers and can then establish control connections to them.

Therefore, the first troubleshooting step is to verify vBond reachability.

Exam trap

The trap here is focusing on vSmart or vManage configuration before verifying the initial vBond connection, which is the prerequisite for all other control connections.

20
MCQmedium

A network engineer is using a Python script to retrieve the operational status of all interfaces on a Cisco IOS XE device via RESTCONF. The script sends a GET request to https://10.1.1.1/restconf/data/ietf-interfaces:interfaces-state but receives an HTTP 401 Unauthorized response. The engineer can successfully ping the device and has verified that the RESTCONF feature is enabled with 'restconf' in global configuration. Which action will resolve the issue?

A.Configure a local username with privilege level 15 and ensure the script includes valid Basic Authentication credentials.
B.Configure an ACL to permit TCP port 830 on the device to allow RESTCONF traffic.
C.Enable the 'ip http secure-server' command to allow HTTPS access to the RESTCONF API.
D.Add the 'restconf' command under the interface configuration mode for the management interface.
AnswerA

RESTCONF on Cisco IOS XE requires HTTP authentication. A 401 Unauthorized indicates missing or invalid credentials. Creating a local user with sufficient privilege and including the credentials in the Authorization header (Basic Auth) allows the request to be authenticated. This is the standard method for RESTCONF access when no AAA server is configured.

Why this answer

The 401 Unauthorized response indicates that the HTTP request lacks valid authentication credentials. RESTCONF on Cisco IOS XE uses HTTP Basic Authentication by default when no AAA is configured. The engineer must create a local user with appropriate privileges and include the credentials in the request.

Enabling HTTPS or adjusting ACLs does not address authentication.

Exam trap

The trap here is assuming that a 401 error is caused by a transport or feature configuration issue rather than missing or incorrect authentication credentials.

21
Multi-Selecthard

Which two statements about DMVPN Phase 3 are true? (Choose two.)

Select 2 answers
A.In DMVPN Phase 3, the hub router must always be in the data path for all traffic between spokes.
B.Spokes register their physical (non-NBMA) addresses with the NHRP server (hub) to enable dynamic tunnel establishment.
C.NHRP redirect messages are sent by the hub to inform a spoke that a better path exists directly to another spoke.
D.DMVPN Phase 3 uses point-to-point GRE tunnels for spoke-to-spoke connections.
E.DMVPN Phase 3 supports dynamic spoke-to-spoke tunnel establishment using NHRP and mGRE.
AnswersC, E

In DMVPN Phase 3, the hub sends NHRP redirect messages telling a spoke that a superior direct path to another spoke exists. The spoke then resolves the target's NBMA address and builds a direct tunnel, bypassing the hub.

Why this answer

Option C is correct because in DMVPN Phase 3 the hub uses NHRP redirect messages to tell a spoke that a more optimal direct path to the destination spoke exists, prompting the spoke to resolve the destination's NBMA address and build a direct tunnel. Option E is correct because Phase 3 retains mGRE interfaces and NHRP so spokes can dynamically establish direct spoke-to-spoke tunnels, while the hub only handles initial resolution and redirects rather than remaining in the data path. Option A is wrong because Phase 3 specifically enables spoke-to-spoke traffic to bypass the hub after NHRP resolution, so the hub is not always in the data path.

Option B is wrong because spokes registering their physical NBMA addresses with the NHRP server is characteristic of DMVPN in general (including Phase 1/2), not a Phase 3-specific truth. Option D is wrong because DMVPN uses mGRE (multipoint GRE) with NHRP, not point-to-point GRE tunnels, for spoke-to-spoke connections.

Exam trap

The trap is confusing DMVPN Phase 1, 2, and 3 behaviors — especially the hub's role in the data path and the tunnel type — so candidates must remember that Phase 3 uses NHRP redirect plus mGRE for dynamic spoke-to-spoke shortcuts.

22
Multi-Selecteasy

Which TWO of the following are benefits of using network virtualization with VXLAN? (Choose two.)

Select 2 answers
A.Enables Layer 2 extension across Layer 3 boundaries.
B.Eliminates the need for STP by using a centralized controller.
C.Uses only multicast for control plane learning.
D.Supports up to 16 million logical networks.
E.Provides native encryption for data in transit.
AnswersA, D

VXLAN tunnels Layer 2 over Layer 3.

Why this answer

VXLAN encapsulates Layer 2 frames in UDP packets over IP, allowing Layer 2 segments to be stretched across Layer 3 networks. This enables virtual machine mobility and multi-tenant environments without being constrained by physical network boundaries.

Exam trap

Cisco often tests the misconception that VXLAN eliminates STP or provides native encryption, but VXLAN is an overlay technology that still relies on the underlay network's STP and does not include encryption by default.

23
MCQeasy

A network engineer is configuring a new Cisco Catalyst switch for a small branch office. The engineer needs to ensure that the switch can be managed remotely via SSH and that only encrypted management traffic is allowed. The management VLAN is VLAN 10, and the switch's management IP address will be 10.10.10.2/24. Which command must be entered to assign the management IP address to the switch?

A.ip default-gateway 10.10.10.2
B.management ip address 10.10.10.2 255.255.255.0
C.interface gigabitethernet0/1 -> ip address 10.10.10.2 255.255.255.0
D.interface vlan 10 -> ip address 10.10.10.2 255.255.255.0
AnswerD

To assign an IP address for management on a Cisco switch, you create an SVI for the management VLAN and assign the IP address under that interface. This is the correct method because it allows the switch to be reachable on VLAN 10. The command sequence is entered in global configuration mode: interface vlan 10, then ip address 10.10.10.2 255.255.255.0. This enables SSH management when combined with proper default gateway and SSH configuration.

Why this answer

On Cisco switches, management IP addresses are assigned to a switched virtual interface (SVI) representing the management VLAN. The correct command sequence is to enter interface configuration mode for the management VLAN and assign the IP address and subnet mask. This allows the switch to be managed via SSH on that VLAN.

The other options either assign an IP to a physical interface (not typical for switches), set a default gateway without an IP, or use an invalid command.

Exam trap

The trap here is confusing the method for assigning management IPs on switches (SVI) with routers (physical interface), or thinking a default gateway command assigns an IP.

24
MCQmedium

An enterprise network uses a Cisco Catalyst 9300 switch as a distribution layer device. The network team notices that ICMP echo requests from a monitoring server (192.168.1.100) to the switch's management IP are being dropped intermittently. The switch has a CoPP policy that includes a class-map matching ICMP traffic. The engineer checks the CoPP statistics and sees that ICMP packets from the monitoring server are being dropped by the policy. What is the most likely cause of this issue?

A.The CoPP policy is policing ICMP traffic to a rate that is too low for the monitoring server's traffic.
B.An ACL applied to the management interface is blocking ICMP from the monitoring server.
C.The monitoring server is sending ICMP packets with a TTL of 1, causing them to be dropped.
D.The switch's CPU is overloaded, causing CoPP to drop all packets.
AnswerA

CoPP (Control Plane Policing) uses an MQC policy with policers to rate-limit traffic destined to the switch CPU. A monitoring server’s ICMP packets (e.g., ping to the management IP) are classified into a class that matches ICMP; if the configured police rate (e.g., committed information rate) is too low, packets exceeding the burst are immediately dropped. The drop counters in 'show policy-map control-plane' confirm that the traffic was admitted to the control plane but then policed, not blocked earlier.

Why this answer

The CoPP policy is policing ICMP traffic to a rate that is too low for the monitoring server's traffic. CoPP (Control Plane Policing) protects the switch's CPU by rate-limiting control plane traffic, including ICMP. When the policer rate is set too low, even legitimate ICMP echo requests from the monitoring server are dropped, causing intermittent reachability issues.

Exam trap

The trap here is that candidates may assume CoPP drops are always due to CPU overload or a misconfigured ACL, but the key clue is the intermittent nature and the specific class-map match, pointing directly to an overly restrictive policer rate.

How to eliminate wrong answers

Option B is wrong because an ACL applied to the management interface would block ICMP consistently, not intermittently, and the CoPP statistics explicitly show drops from the policy, not ACL hits. Option C is wrong because ICMP packets with a TTL of 1 would be dropped by routers along the path, not by the destination switch's CoPP policy; the monitoring server typically sends TTL values of 64 or 128. Option D is wrong because an overloaded CPU would cause CoPP to drop all packets indiscriminately, but the scenario states only ICMP packets from the monitoring server are being dropped, indicating a specific rate-limit issue rather than general CPU exhaustion.

25
MCQeasy

A network engineer runs the following command on Router R9: R9# show mpls ldp bindings 10.9.9.0 255.255.255.0 lib entry: 10.9.9.0/24, rev 10 local binding: label: 22 remote binding: lsr: 10.9.9.1:0, label: 23 remote binding: lsr: 10.9.9.2:0, label: 24 remote binding: lsr: 10.9.9.3:0, label: 25 Based on this output, how many remote LDP peers have advertised a label for the prefix 10.9.9.0/24?

A.1
B.2
C.3
D.4
AnswerC

This is the correct answer. The MPLS LDP binding output lists exactly three remote label bindings, each originating from a different LSR: 10.9.9.1:0, 10.9.9.2:0, and 10.9.9.3:0. These are remote because they are label bindings learned from peer LSRs via LDP, as opposed to the local binding the router itself advertises. The count of three remote entries directly answers the question, so option 3 is correct.

Why this answer

The output shows three remote bindings, each from a different LSR (10.9.9.1:0, 10.9.9.2:0, and 10.9.9.3:0), advertising a label for the prefix 10.9.9.0/24. The local binding (label 22) is not a remote peer, so only the three remote entries count. Therefore, the correct answer is 3.

Exam trap

The trap here is that candidates often mistakenly count the local binding as a remote peer, leading them to select 4 instead of 3, because they overlook the distinction between 'local binding' and 'remote binding' in the command output.

How to eliminate wrong answers

Option A is wrong because there are three remote bindings, not one; a single remote binding would show only one 'remote binding' line. Option B is wrong because two remote bindings would appear if only two LSRs were listed, but the output clearly shows three distinct LSRs. Option D is wrong because the local binding is not a remote peer, so counting it as a fourth remote peer is incorrect; only the three remote LSRs are valid.

26
MCQmedium

Given this telemetry configuration on a Cisco IOS-XE device: telemetry ietf subscription 400 encoding encode-kvgpb filter xpath /interfaces/interface/state stream yang-push update-policy periodic 1000 receiver ip address 10.1.1.1 50000 protocol grpc source-interface Loopback0 What is the effect of the source-interface Loopback0 command?

A.It forces the telemetry receiver to listen on Loopback0.
B.It uses the IP address of Loopback0 as the source for telemetry packets to the receiver.
C.It restricts the telemetry data to only Loopback0 interface counters.
D.It changes the update policy to on-change for Loopback0.
AnswerB

Loopback0's IP address becomes the source address in the telemetry packet headers, ensuring the gRPC receiver sees a stable, routable source rather than a transient physical interface address. This satisfies the need for deterministic telemetry source identification.

Why this answer

The source-interface command ensures that all telemetry packets sent to the receiver use the IP address of Loopback0 as the source.

27
Drag & Dropmedium

Drag and drop the steps of BGP graceful restart negotiation steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Graceful restart begins with the restarting router sending an OPEN message with the graceful restart capability, followed by the peer acknowledging, then the restarting router marking routes as stale, and finally the peer sending End-of-RIB markers.

28
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor. The engineer wants to rate-limit ICMP echo requests destined to the router itself while ensuring that transit traffic passing through the router is not affected. Which classification approach should the engineer use in the CoPP policy?

A.Apply a policy map with police rate to the management VRF interface only.
B.Match ICMP in a class map applied to the ingress interface with the service-policy command.
C.Configure an ingress ACL on all interfaces that denies ICMP echo requests to the router.
D.Use a class map with match access-group referencing an ACL that permits ICMP echo to the router's interface addresses, then attach the policy map to the control-plane interface.
AnswerD

CoPP operates by attaching a service policy to the control-plane interface (control-plane global configuration), which only sees traffic punted to the route processor. Matching ICMP echo requests destined to the router's own addresses in a class map, then applying the policy to control-plane, rate-limits only router-bound ICMP while transit traffic is untouched. This is the standard CoPP design pattern for protecting the route processor.

Why this answer

CoPP works by attaching a service policy to the control-plane interface, which only processes traffic destined to the route processor. Classifying ICMP echo requests to the router's own addresses and policing them there protects the CPU without affecting transit traffic. Interface-level policies or ACLs either affect transit traffic or block rather than rate-limit, so the control-plane attachment with an ACL-based class map is correct.

Exam trap

The trap here is confusing interface-level policing with control-plane policing, when only the control-plane attachment isolates router-bound traffic from transit traffic.

29
Multi-Selecthard

Which two statements about DHCP snooping are true? (Choose two.)

Select 2 answers
A.DHCP snooping treats all ports as untrusted by default, except those explicitly configured as trusted.
B.The ip dhcp snooping trust command is applied on ports connected to DHCP clients.
C.DHCP snooping builds a binding database that maps client MAC addresses, IP addresses, VLAN, and port information.
D.DHCP snooping can be configured globally without enabling it on specific VLANs.
E.DHCP snooping drops all DHCP packets that contain option 82 information from untrusted ports.
AnswersA, C

DHCP snooping's default trust model marks every switch port untrusted, so DHCP server replies arriving on access ports are dropped; only uplinks or server-facing ports are explicitly trusted. This satisfies the stem's requirement for a true statement about DHCP snooping.

Why this answer

Option A is correct because DHCP snooping's default security posture is to treat every port as untrusted, so only ports explicitly configured with the ip dhcp snooping trust command (typically uplinks toward the legitimate DHCP server) are allowed to carry server-originated DHCP messages such as OFFER, ACK, and NAK. Option C is correct because DHCP snooping inspects DHCP traffic and populates a binding table that records the client MAC address, leased IP address, VLAN, lease time, and ingress switch port, which is later used by features like Dynamic ARP Inspection and IP Source Guard. Option B is incorrect because the ip dhcp snooping trust command is applied to ports facing the trusted DHCP server or uplink, not to ports connected to DHCP clients, which must remain untrusted.

Option D is incorrect because DHCP snooping must be enabled per VLAN with the ip dhcp snooping vlan command after the global ip dhcp snooping command; global enablement alone does not activate snooping on any VLAN. Option E is incorrect because DHCP snooping does not drop all packets containing option 82 from untrusted ports; it typically strips or replaces option 82 information on untrusted ports and can be configured to allow or drop such packets, so a blanket drop is not accurate.

Exam trap

Cisco often tests the direction of trust — candidates instinctively trust the client-facing port (where the user is) instead of the server-facing uplink, which inverts the entire security model.

30
MCQmedium

A network engineer runs the following command on Router R7: R7# show ip nat translations verbose Pro Inside global Inside local Outside local Outside global --- 192.0.2.10 10.0.0.10 --- --- create: 03/01/2025 09:00:00, use: 03/01/2025 09:05:00 timeout: never, flags: static --- 192.0.2.11 10.0.0.11 --- --- create: 03/01/2025 09:00:00, use: 03/01/2025 09:06:00 timeout: never, flags: static Based on this output, what can be concluded?

A.These translations will expire after a configurable timeout.
B.The translations are dynamic and will be removed after idle timeout.
C.The router is performing PAT for these addresses.
D.The translations are static and will remain until manually removed.
AnswerD

The `flags: static` and `timeout: never` fields confirm permanent one-to-one mappings, so these entries persist indefinitely rather than expiring like dynamic NAT translations. Because no outside local or global addresses appear, the entries are simple static mappings awaiting traffic. They remain until the engineer manually clears them with `clear ip nat translation`.

Why this answer

The output shows two NAT entries with the flag 'static' and a timeout of 'never'. Static NAT translations are manually configured and persist indefinitely in the translation table until explicitly removed by an administrator. This is why option D is correct.

Exam trap

Cisco often tests the distinction between static and dynamic NAT by hiding the 'flags' field or using the 'timeout' value; candidates may incorrectly assume all NAT entries have a timeout or that the presence of 'use' timestamps implies dynamic behavior.

How to eliminate wrong answers

Option A is wrong because the timeout is set to 'never', meaning these translations will not expire after any configurable timeout. Option B is wrong because the flags field shows 'static', not 'dynamic', and dynamic translations would have an idle timeout and be removed automatically. Option C is wrong because there is no port information in the output (no 'Pro' protocol column with TCP/UDP and port numbers), which is required for PAT (Port Address Translation); this is a static one-to-one NAT.

31
MCQmedium

A network engineer is deploying Cisco SD-Access and needs to ensure that fabric edge nodes can register with the fabric control plane node. Which protocol is used for this registration and for endpoint location mapping?

A.BGP
B.VXLAN
C.LISP
D.IS-IS
AnswerC

LISP (Locator/ID Separation Protocol) is used in Cisco SD-Access for endpoint location mapping. Fabric edge nodes register endpoint EIDs with the control plane node, which maintains a mapping of EIDs to RLOCs. This allows the fabric to route traffic based on endpoint identity. LISP is the correct protocol for this function.

Why this answer

In Cisco SD-Access, LISP is the control plane protocol that enables fabric edge nodes to register endpoints with the control plane node. The control plane node maintains a mapping database of endpoint identifiers to routing locators. VXLAN, BGP, and IS-IS serve other roles in the fabric, such as data plane encapsulation and underlay routing.

Exam trap

The trap here is confusing the data plane protocol (VXLAN) with the control plane protocol (LISP), assuming that the encapsulation protocol also handles registration.

32
Drag & Dropmedium

Drag and drop the steps of NAT overload (PAT) packet translation process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

PAT translates private source IPs to a public IP with unique port numbers. The host sends a packet, the router creates a translation entry, replaces the source IP and port, forwards the packet, and reverses the process on the return.

33
MCQhard

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using SHA-256 HMAC cryptographic authentication on an interface. Which command sequence correctly enables this authentication?

A.ip ospf authentication key-chain <name> and configure a key chain with key 1 using cryptographic-algorithm hmac-sha-256
B.ip ospf authentication followed by ip ospf authentication-key <password>
C.ip ospf authentication null
D.ip ospf authentication message-digest followed by ip ospf message-digest-key 1 md5 <key>
AnswerA

This sequence correctly enables OSPFv2 SHA-256 HMAC authentication. The interface command ip ospf authentication key-chain references a key chain, which must be defined globally with a key that specifies the cryptographic algorithm hmac-sha-256 and a password. This provides stronger security than MD5. The key chain allows for key rollover and multiple keys with different lifetimes, which is essential for operational flexibility.

Why this answer

OSPFv2 supports SHA-256 HMAC authentication through key chains. The interface command ip ospf authentication key-chain <name> references a key chain configured with key 1 and cryptographic-algorithm hmac-sha-256. This provides cryptographic authentication with stronger hashing than MD5.

Simple authentication and MD5 do not meet the SHA-256 requirement, and null disables authentication.

Exam trap

The trap here is assuming that MD5 message-digest authentication is equivalent to SHA-256 HMAC, when MD5 uses a different and weaker algorithm.

34
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and SNMP. The engineer wants to ensure that BGP keepalives are not dropped during a control plane overload, while still rate-limiting SSH and SNMP. The engineer creates a class-map matching BGP, SSH, and SNMP traffic, then applies a policy-map with a single policer of 1000 pps to that class. After applying the service-policy to the control plane, BGP sessions flap during high CPU utilization. What is the most likely cause?

A.CoPP cannot be applied to BGP traffic; it only supports management protocols like SSH and SNMP.
B.The service-policy must be applied to the data plane instead of the control plane for BGP to be protected.
C.The policer rate is too low for BGP keepalives, and all matched traffic is treated equally.
D.The policer should be configured with 'police cir' instead of 'police pps' to properly rate-limit BGP.
AnswerC

A single policer applied to a class that matches BGP, SSH, and SNMP treats all three protocols identically. During high CPU, BGP keepalives may exceed the 1000 pps rate along with other traffic, causing drops. BGP requires a separate class with a higher rate or priority to ensure keepalives are not dropped. The design flaw is the lack of granularity.

Why this answer

CoPP requires granular classification to protect critical protocols. When BGP, SSH, and SNMP are matched in the same class and policed together, BGP keepalives compete with other traffic and may be dropped during high CPU. BGP should be placed in its own class with a higher rate or priority to prevent flapping.

The single policer approach lacks the necessary differentiation.

Exam trap

The trap here is assuming that a single policer can adequately protect all control plane protocols, when in fact BGP requires separate treatment to avoid keepalive drops during congestion.

35
MCQeasy

What is the maximum number of active member links supported in a single EtherChannel on Cisco Catalyst switches?

A.4
B.8
C.16
D.32
AnswerB

Correct. A single EtherChannel supports up to eight active member links in Cisco IOS and IOS-XE implementations. This limit applies to the actual forwarding links, regardless of whether the channel is formed statically, with PAgP, or with LACP. While some platforms extend the total to 16 by adding standby links via LACP, only eight can be actively forwarding at any given time.

Why this answer

Cisco Catalyst switches support a maximum of 8 active member links in a single EtherChannel. This limit is defined by the IEEE 802.3ad standard and Cisco's implementation, ensuring that the load-balancing algorithm distributes traffic effectively across all links. The 8-link limit applies to both PAgP and LACP modes.

Exam trap

Cisco often tests the distinction between the maximum number of configured ports (16 with LACP) versus the maximum number of active ports (8), leading candidates to mistakenly choose 16.

How to eliminate wrong answers

Option A is wrong because 4 is the maximum number of links supported in a port channel on some older or lower-end platforms, but not on modern Catalyst switches for a single EtherChannel. Option C is wrong because 16 is the maximum number of links that can be configured in an EtherChannel when using LACP in active/passive mode, but only 8 can be active at a time; the remaining 8 are placed in hot-standby state. Option D is wrong because 32 is not a supported limit for active member links in any standard EtherChannel implementation; it may be confused with the total number of ports in a switch stack or the maximum number of EtherChannels per switch.

36
MCQhard

Refer to the exhibit. A switch has IP Source Guard (IPSG) and port-security enabled on interface GigabitEthernet0/1. A host with IP 10.1.1.1 and MAC 00:1A:2B:3C:4D:5E is connected and tries to access a web server at 192.168.1.100. What will happen?

A.The traffic is blocked because the host is not using DHCP, so IPSG drops all non-DHCP traffic.
B.The traffic is permitted only if the destination is also in the 10.0.0.0/8 range.
C.The traffic is blocked because IP Source Guard requires a static binding for the host.
D.The traffic is permitted because the host's IP is within the allowed subnet and the MAC is valid according to port-security.
AnswerC

Correct. Without DHCP or a static IP-source binding, IPSG blocks the traffic.

Why this answer

IP Source Guard (IPSG) validates the source IP address of traffic using DHCP snooping bindings or static IP-source bindings. In this scenario, no DHCP snooping binding exists (host is not using DHCP) and no static binding has been configured, so IPSG will drop the traffic from the host. Port-security ensures the source MAC is valid, but does not provide the IP-MAC binding required by IPSG.

Therefore, the traffic is blocked.

Exam trap

The trap is that many candidates assume port-security alone satisfies IPSG requirements, but IPSG needs a separate IP-MAC binding from DHCP snooping or static configuration.

How to eliminate wrong answers

Option A is wrong because IPSG does not drop all non-DHCP traffic; it filters based on IP-to-MAC bindings from DHCP snooping or static entries, not the source of the IP assignment. Option B is wrong because IPSG does not restrict traffic based on the destination IP address; it only validates the source IP and MAC of the host. Option C is wrong because IPSG does not require a static binding for the host; it can use dynamic DHCP snooping bindings, and in this case, port-security provides an alternative validation mechanism.

37
MCQeasy

An engineer is troubleshooting a site-to-site VPN that uses IPsec with IKEv1. The tunnel is established, but traffic is intermittently dropped. The engineer checks the 'show crypto ipsec sa' output and sees that the number of packets that failed anti-replay check is increasing. What is the most likely cause of this issue?

A.The IPsec SA is using a weak encryption algorithm.
B.The IPsec SA is using ESP in tunnel mode with authentication only.
C.The traffic is taking multiple paths, causing packets to arrive out of order.
D.The IPsec SA lifetime is too short, causing frequent rekeying.
AnswerC

IPsec anti-replay protection relies on monotonically increasing sequence numbers and a receiver-side sliding window, typically 64 packets wide. If traffic is load-balanced across multiple paths with different latency, packets can arrive out of order; a legitimate packet whose sequence number falls below the left edge of the window is treated as a replay and discarded. This is a well-known cause of intermittent IPsec drops, especially with unequal-cost multipath or ECMP routing.

Why this answer

The anti-replay check in IPsec uses sequence numbers to protect against replay attacks. When packets arrive out of order, the anti-replay window (default size 64 or 1024 packets) may reject packets that fall outside the window, causing the counter to increment. This is typical when traffic takes multiple paths, as packets can be reordered before reaching the peer.

Exam trap

Cisco often tests the anti-replay mechanism by linking it to packet reordering from asymmetric routing or multi-path forwarding, leading candidates to mistakenly blame rekeying or encryption settings instead of the actual cause of out-of-order delivery.

How to eliminate wrong answers

Option A is wrong because a weak encryption algorithm does not cause anti-replay failures; it affects confidentiality, not packet ordering. Option B is wrong because ESP in tunnel mode with authentication only (no encryption) still uses sequence numbers for anti-replay; the mode or encryption choice does not cause out-of-order delivery. Option D is wrong because a short IPsec SA lifetime causes frequent rekeying, which may drop traffic during rekey but does not increment the anti-replay failure counter; rekeying creates new SAs with fresh sequence numbers, not out-of-order packets.

38
MCQhard

An engineer configures IP SLA 100 to monitor the jitter and latency of a VoIP call path between two branch routers. The configuration uses UDP jitter with a target of 192.168.2.2 on port 16384. The engineer notices that the IP SLA operation shows 'State: Active' but no jitter or latency statistics are collected. The router is generating the probe packets, but the remote router does not respond. What is the most likely reason?

A.The IP SLA operation must be configured with a 'request-data-size' value to match the remote router's MTU.
B.The remote router must have an IP SLA responder configured to process the UDP jitter probes.
C.The source router needs a 'frequency' setting that matches the remote router's response interval.
D.The firewall on the remote router is blocking the UDP port 16384, preventing the probe from reaching the target.
AnswerB

UDP jitter is a connectionless probe that depends on the remote router actively running the IP SLA responder service. The responder listens on a designated UDP port, timestamps each received packet, and echoes it back to the source so that one-way delay and jitter can be computed. Without this responder, there is no process bound to the destination port, so the probe packets are dropped or answered with an ICMP port unreachable rather than a valid IP SLA response.

Why this answer

For UDP jitter IP SLA operations to collect jitter and latency statistics, the remote router must be configured as an IP SLA responder. The responder processes the probe packets and sends back time-stamped responses, which are essential for calculating jitter and one-way delay. Without the responder, the source router can send probes (showing 'Active' state) but cannot compute meaningful statistics because it never receives the required response packets.

Exam trap

Cisco often tests the misconception that simply sending probes (State: Active) is enough to collect statistics, when in fact the IP SLA responder is mandatory for UDP jitter and other advanced operations that require two-way time-stamped communication.

How to eliminate wrong answers

Option A is wrong because the 'request-data-size' parameter controls the payload size of the probe, but it does not affect whether the remote router responds; mismatched MTU would cause fragmentation or drops, not a lack of response. Option C is wrong because the 'frequency' setting on the source router defines how often probes are sent, and it does not need to match any interval on the remote router; the responder simply replies to each probe it receives. Option D is wrong because if a firewall were blocking UDP port 16384, the source router would likely see the operation as 'Timeout' or 'Inactive', not 'Active'; the 'Active' state indicates the source is successfully sending probes, but the lack of response points to the absence of a responder, not a firewall.

39
MCQeasy

A network engineer needs to secure management access to a Cisco IOS XE router. The requirement is to encrypt all management traffic, including SNMP, and to authenticate administrators against a centralized server. Which combination of features should be implemented?

A.HTTPS for CLI access, SNMPv3 with noAuthNoPriv, and TACACS+ for authentication.
B.SSH for CLI access, SNMPv3 with authPriv, and TACACS+ for authentication.
C.SSH for CLI access, SNMPv2c with an ACL, and local authentication.
D.Telnet for CLI access, SNMPv2c with a community string, and RADIUS for authentication.
AnswerB

SSH encrypts CLI sessions, SNMPv3 with authPriv provides both authentication and encryption for SNMP, and TACACS+ centralizes administrator authentication with per-command authorization. This combination meets the requirement to encrypt all management traffic and authenticate against a central server. It is the standard secure management baseline for Cisco IOS XE devices.

Why this answer

SSH, SNMPv3 authPriv, and TACACS+ together provide encrypted CLI access, authenticated and encrypted SNMP, and centralized administrator authentication. The other options either use clear-text protocols like Telnet or SNMPv2c, or rely on local authentication, failing the encryption and centralization requirements.

Exam trap

The trap here is assuming SNMPv2c with an ACL is secure, when only SNMPv3 authPriv encrypts SNMP traffic.

40
Matchingmedium

Drag and drop each Ansible component on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Defines the list of managed hosts and groups

YAML file containing ordered tasks to execute

Structured directory for reusable variables, tasks, and handlers

Executable code that performs a specific configuration or operational task

Special task triggered only when notified by another task

Why these pairings

Each component has a distinct role: Inventory defines managed nodes, Playbook is the execution blueprint, Role organizes content, Module is the execution unit, and Handler reacts to changes.

41
MCQeasy

A network administrator is configuring a Cisco Nexus 9000 switch to participate in a VXLAN EVPN fabric. The administrator needs to define the source IP address used for VXLAN tunnels. Which interface should be configured as the source for the VXLAN tunnel?

A.A switched virtual interface (SVI) for the management VLAN
B.A physical uplink interface
C.A port-channel interface
D.A loopback interface with a /32 mask
AnswerD

VXLAN tunnels use a loopback interface as the source to ensure high availability and stability. A /32 loopback is always up and not tied to a physical port, so the tunnel source remains reachable even if a link fails. This is the recommended design for VTEPs in a VXLAN EVPN fabric.

Why this answer

The VXLAN tunnel source should be a loopback interface with a /32 mask. This ensures a stable, always-up source IP address that is independent of physical link failures. Using a physical interface, SVI, or port-channel can cause tunnel instability if the underlying links or VLANs go down.

Exam trap

The trap here is choosing a port-channel or physical interface for redundancy, but a loopback is still the best practice for VTEP source because it is not tied to physical ports.

42
Drag & Dropmedium

Drag and drop the steps of PPPoE session establishment into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

PPPoE session establishment begins with the Discovery stage: the client sends a PADI to find a server, the server responds with a PADO, the client selects a server and sends a PADR, the server assigns a session ID via PADS. Finally, the PPP link is negotiated using LCP and authentication.

43
MCQhard

A network engineer is troubleshooting a BGP issue where a router is not installing a specific prefix in its routing table, even though the prefix is present in the BGP table. The engineer runs 'show ip bgp 10.0.0.0/24' and sees that the route is valid but not best. The BGP table shows that the route has a higher local preference than the current best path, but the AS_PATH is longer. What is the most likely reason the route is not being selected as best?

A.The route with higher local preference has a lower weight than the current best path.
B.The route with higher local preference has a higher MED value.
C.The route with higher local preference is not synchronized with IGP.
D.The route with higher local preference was learned from an eBGP peer, while the current best path is from an iBGP peer.
AnswerA

Cisco's BGP best-path algorithm evaluates weight first; the highest weight always wins. Since the current best path has a higher weight, it remains selected regardless of local preference, because local preference is only compared after weights are found equal. Thus a higher local preference cannot make a lower-weight route the best path.

Why this answer

BGP selects the best path based on a sequence of comparison steps. Local preference is checked before AS_PATH length, so a higher local preference should normally win. However, weight is the very first criterion in the BGP best-path selection algorithm.

If the current best path has a higher weight than the route with higher local preference, weight overrides local preference, making the higher-local-preference route not best.

Exam trap

Cisco often tests the order of BGP best-path selection steps, specifically that weight is evaluated before local preference, leading candidates to incorrectly assume that a higher local preference always wins regardless of weight.

How to eliminate wrong answers

Option B is wrong because MED is compared only after the AS_PATH length and origin code, and it is not relevant when a higher local preference is present; the issue here is that weight, which is checked first, is higher on the current best path. Option C is wrong because BGP synchronization is a Cisco-specific feature that requires an IGP route for the next-hop before installing an iBGP route, but it does not affect the best-path selection process; the route is already in the BGP table as valid, and synchronization would prevent installation, not selection as best. Option D is wrong because eBGP routes are preferred over iBGP routes only if all earlier steps (weight, local preference, locally originated) are equal; here, local preference is higher on the candidate route, but weight is the first tiebreaker and is higher on the current best path, so the eBGP vs iBGP comparison never occurs.

44
Matchingmedium

Drag and drop each HTTP method on the left to its matching REST operation on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Retrieve a resource

Create a new resource

Replace an existing resource entirely

Remove a resource

Apply partial modifications to a resource

Why these pairings

GET retrieves; POST creates; PUT replaces; DELETE removes; PATCH partially updates.

45
MCQeasy

A network engineer is using the Cisco DNA Center REST API to retrieve the health score of a specific device. The API response is as follows: { "response": [ { "deviceId": "1234567890", "hostname": "Core-Switch-1", "score": 8, "overallHealth": "good", "timestamp": 1623456789 } ], "version": "1.0" } The engineer wants to extract the 'overallHealth' value. Which Python code correctly extracts it?

A.health = response['response'][0]['overallHealth']
B.health = response['overallHealth']
C.health = response['response']['overallHealth']
D.health = response[0]['overallHealth']
AnswerA

Indexing the JSON object by key retrieves the nested value directly: `response['response']` yields the list, `[0]` selects its single dictionary element, and `['overallHealth']` returns `"good"`. This satisfies the stem's requirement to extract the health status from the parsed API response without iterating.

Why this answer

The JSON response has a top-level key 'response' whose value is a list containing one dictionary. To extract 'overallHealth', you must index into the list first: response['response'][0]['overallHealth']. This correctly navigates the nested structure.

The other options either skip the list indexing or assume a different structure.

Exam trap

350-401 often tests basic JSON parsing in Python, tricking candidates who forget that the 'response' key maps to a list and try to index it as a dictionary or skip the list index entirely.

How to eliminate wrong answers

Option B is wrong because it tries to access 'overallHealth' directly at the top level, but the key is nested inside the first element of the 'response' list. Option C is wrong because it treats 'response' as a dictionary and tries to access 'overallHealth' directly, but 'response' is a list, so you must use an integer index. Option D is wrong because it assumes the top-level object is a list and indexes it with [0], but the top level is a dictionary with a 'response' key.

46
MCQeasy

A network engineer is new to automation and wants to use a simple, agentless tool to push configuration changes to a group of Cisco IOS XE switches. The engineer prefers to write the automation tasks in YAML and does not want to install any software on the switches. Which tool should be used?

A.Puppet
B.Ansible
C.SaltStack
D.Chef
AnswerB

Ansible is an agentless automation tool that uses YAML-based playbooks to define tasks. It connects to network devices via SSH or other protocols without requiring any software installation on the managed devices. This matches the engineer's requirements: simple, agentless, and YAML-based configuration management for Cisco IOS XE switches.

Why this answer

Ansible is an agentless automation tool that uses YAML playbooks, making it ideal for simple configuration pushes to network devices without installing agents. Puppet and Chef typically require agents and use different DSLs, while SaltStack, although YAML-based, often involves a more complex architecture. Ansible's simplicity and native support for Cisco IOS XE modules align with the scenario.

Exam trap

The trap here is assuming that all configuration management tools are agentless or use YAML; in reality, Puppet and Chef require agents and use their own DSLs, while Ansible is known for being agentless and YAML-based.

47
MCQeasy

A network administrator is new to automation and wants to use a simple, agentless tool to push configuration changes to a group of Cisco IOS devices. The administrator prefers a tool that uses YAML for playbooks and does not require installing software on the managed devices. Which tool should the administrator use?

A.Puppet
B.Ansible
C.Chef
D.SaltStack
AnswerB

Ansible is an agentless automation tool that uses YAML-based playbooks to define tasks. It connects to managed devices over SSH or NETCONF, so no agent software needs to be installed on the Cisco IOS devices. This makes it ideal for simple, push-based configuration management. Ansible modules like 'ios_config' allow network engineers to automate configuration changes across multiple devices efficiently.

Why this answer

Ansible is the correct choice because it is agentless, uses YAML for playbooks, and connects to Cisco IOS devices over SSH without requiring any software installation on the devices. It has a rich set of network modules, such as 'ios_config', that simplify configuration management. Other tools like Puppet and Chef use different languages and often require agents, making them less suitable for this scenario.

Exam trap

The trap here is confusing Ansible with other configuration management tools that also support agentless operation but use different languages or require more setup; Ansible uniquely uses YAML playbooks and is agentless.

48
Matchingmedium

Drag and drop each BGP attribute on the left to its preferred value (highest or lowest) on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Highest

Highest

Lowest

Lowest

Lowest

Why these pairings

Higher WEIGHT and LOCAL_PREF are preferred; lower MED, AS_PATH length, and IGP metric to next-hop are preferred.

49
MCQeasy

A network engineer is implementing Cisco SD-Access and needs to understand the role of the LISP protocol. Which statement accurately describes the function of LISP in SD-Access?

A.LISP dynamically assigns IP addresses to endpoints in the fabric.
B.LISP enforces security policies between fabric segments.
C.LISP is used for data plane encapsulation between fabric nodes.
D.LISP provides the control plane for mapping endpoint identities to their locations.
AnswerD

In Cisco SD-Access, LISP (Locator/ID Separation Protocol) serves as the control plane protocol that separates endpoint identity (EID) from its location (RLOC). It maintains a mapping database that allows fabric edge nodes to query the mapping system to locate endpoints. This enables scalable, dynamic endpoint mobility and policy enforcement across the fabric.

Why this answer

LISP in SD-Access acts as the control plane, separating endpoint identity from location. It maintains a mapping database that fabric edge nodes query to resolve EID-to-RLOC mappings, enabling scalable endpoint mobility and fabric operations. The data plane uses VXLAN, while policy is enforced via TrustSec SGTs.

Exam trap

The trap here is confusing LISP with VXLAN, assuming LISP provides data plane encapsulation when it actually provides control plane mapping.

50
Drag & Dropmedium

Drag and drop the steps of RESTCONF GET with depth and field query parameters into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The process starts with constructing the URI, then appending depth and field parameters, sending the GET request, the server filtering the response, and finally the client parsing the returned data.

51
MCQeasy

What is the default EIGRP hello interval on a point-to-point serial link?

A.5 seconds
B.10 seconds
C.30 seconds
D.60 seconds
AnswerA

The default EIGRP hello interval on point-to-point serial links is 5 seconds. This design ensures fast neighbor discovery and rapid convergence since EIGRP relies on periodic hello packets (multicast to 224.0.0.10) to maintain adjacency. The corresponding hold time defaults to 15 seconds (three times the hello interval), allowing only one missed hello before the neighbor is declared down. This 5-second default also applies to Ethernet and most high-speed media, making it the standard EIGRP hello interval.

Why this answer

The default EIGRP hello interval on a point-to-point serial link is 5 seconds. EIGRP uses different hello intervals depending on the media type: for high-speed broadcast links (e.g., Ethernet) and point-to-point links, the default is 5 seconds; for multipoint non-broadcast links (e.g., Frame Relay), the default is 60 seconds.

Exam trap

Cisco often tests the distinction between EIGRP and OSPF hello intervals, so the trap here is that candidates confuse the 10-second OSPF default with EIGRP's 5-second default on point-to-point links.

How to eliminate wrong answers

Option B (10 seconds) is wrong because 10 seconds is the default hello interval for OSPF on broadcast and point-to-point links, not for EIGRP. Option C (30 seconds) is wrong because 30 seconds is not a standard EIGRP hello interval; it is the default hold time multiplier factor (3x hello) on some links, but not the hello timer itself. Option D (60 seconds) is wrong because 60 seconds is the default EIGRP hello interval only on low-speed multipoint non-broadcast links (e.g., Frame Relay multipoint), not on point-to-point serial links.

52
MCQmedium

A network engineer is deploying a new branch office that uses a single switch stack with two member switches. The stack must forward traffic between access ports in different VLANs without involving an external router. Which feature should be configured to meet this requirement?

A.Configure private VLANs on the access ports to allow communication between VLANs.
B.Configure an SVI for each VLAN on the switch stack and enable IP routing with the ip routing command.
C.Configure VTP transparent mode on all switches and create the VLANs manually.
D.Configure 802.1Q trunk links between the two stack members and enable dynamic ARP inspection.
AnswerB

This is correct because an SVI provides Layer 3 processing for a VLAN, and enabling IP routing on the stack allows inter-VLAN traffic to be routed internally. The stack acts as a single logical switch, so SVIs are active on the stack master and traffic between VLANs is routed without an external router.

Why this answer

The requirement is to route traffic between VLANs using the switch stack itself. Creating switched virtual interfaces for each VLAN and enabling IP routing allows the stack to perform inter-VLAN routing without an external router. This is a standard design for collapsed core or branch offices where a multilayer switch provides both Layer 2 and Layer 3 forwarding.

Exam trap

The trap here is assuming that creating VLANs alone enables communication between them, when in fact Layer 3 routing must be explicitly enabled with SVIs.

53
MCQmedium

An architect is designing an SD-WAN deployment for a multinational enterprise. The design must ensure that control plane traffic remains separate from data plane traffic and that the solution can scale to thousands of sites. Which architectural component is responsible for maintaining the control plane and distributing routing information?

A.vBond orchestrator
B.vManage NMS
C.vSmart controller
D.vEdge router
AnswerC

vSmart controller is the central control plane component that runs the Overlay Management Protocol (OMP) to advertise routes and policies to all vEdge and cEdge devices. It learns reachability information from edge routers, applies centralized policies, and then computes and distributes the necessary forwarding state to maintain an optimized overlay. This makes vSmart the authoritative source for route and policy information, hence the correct answer.

Why this answer

The vSmart controller is the centralized control plane component in Cisco SD-WAN that distributes routing information (OMP routes) and policies to all vEdge/cEdge routers. It maintains the control plane by separating route advertisement and policy enforcement from the data plane, which is handled by the vEdge routers. This separation allows the solution to scale to thousands of sites because vSmart controllers can be clustered and do not process actual data traffic.

Exam trap

Cisco often tests the misconception that the vBond orchestrator handles control plane functions because of its role in initial authentication and orchestration, but vBond does not distribute routing information—that is exclusively the vSmart controller's role.

How to eliminate wrong answers

Option A is wrong because the vBond orchestrator is responsible for initial authentication, NAT traversal, and orchestrating connections between vSmart, vManage, and vEdge devices, not for maintaining the control plane or distributing routing information. Option B is wrong because vManage NMS is the network management system that provides centralized configuration, monitoring, and analytics, but it does not participate in the control plane or distribute routing updates. Option D is wrong because the vEdge router is a data plane device that forwards traffic based on routes learned from the vSmart controller; it does not originate or distribute routing information to other sites.

54
MCQhard

A network engineer runs the following command on Router R9: R9# show policy-map interface GigabitEthernet0/0.900 GigabitEthernet0/0.900 Service-policy input: QOS_POLICY_VRF_G Class-map: CLASS_VOICE (match-all) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp ef (46) police: cir 1000000 bps, bc 31250 bytes, be 31250 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: CLASS_DATA (match-all) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp af31 (26) police: cir 2000000 bps, bc 62500 bytes, be 62500 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: class-default (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any Based on this output, what can be concluded?

A.No QoS policy is applied to this interface
B.The policy only polices voice traffic
C.A QoS policy is applied inbound on GigabitEthernet0/0.900, policing voice and data traffic
D.The policy is applied outbound
AnswerC

The configuration shows 'service-policy input' on GigabitEthernet0/0.900, which places the QoS policy in the inbound direction for that subinterface. The policy-map contains class-maps for voice (DSCP EF) and data (DSCP AF31), each with a 'police' command that applies token-bucket rate limiting. Therefore, the correct interpretation is that inbound traffic on this subinterface is classified and policed for both voice and data types.

Why this answer

The output shows the 'Service-policy input: QOS_POLICY_VRF_G' line, confirming that a QoS policy is applied inbound on GigabitEthernet0/0.900. The policy contains two user-defined class maps: CLASS_VOICE (matching DSCP EF) with a police rate of 1 Mbps and CLASS_DATA (matching DSCP AF31) with a police rate of 2 Mbps, both with conform/transmit and exceed/violate drop actions. This demonstrates that both voice and data traffic are being policed, making option C correct.

Exam trap

Cisco often tests the ability to read the 'Service-policy input' or 'output' direction in the command output, as candidates may overlook the direction keyword and incorrectly assume the policy is applied outbound or not applied at all.

How to eliminate wrong answers

Option A is wrong because the 'Service-policy input: QOS_POLICY_VRF_G' line explicitly shows a QoS policy is applied inbound on the subinterface. Option B is wrong because the policy includes both CLASS_VOICE and CLASS_DATA class maps, each with policing actions, so it polices both voice and data traffic, not just voice. Option D is wrong because the command output specifies 'Service-policy input', indicating the policy is applied inbound, not outbound.

55
MCQmedium

An engineer is configuring a FlexVPN hub-and-spoke network. The hub router has a loopback0 with IP 10.0.0.1/32. The spokes are configured to use IKEv2 with certificates. The engineer notices that the spokes can establish the IKEv2 tunnel and can ping the hub's tunnel IP, but cannot reach the loopback0 address. The hub has a static route for the spoke subnets. What is the most likely issue?

A.The IKEv2 proposal does not match between hub and spoke.
B.The certificate authority is not trusted by the hub.
C.The tunnel interface is not in an up/up state.
D.The loopback0 is not advertised in the routing protocol.
AnswerD

The correct cause is that the hub's loopback0 network is not being advertised to the spokes by the dynamic routing protocol (such as EIGRP or OSPF) running over the DMVPN tunnel. Even though the tunnel is up and the tunnel IP is reachable, the spokes have no routing entry for the loopback0 prefix, so packets destined to that loopback are dropped or sent toward some default route. The fix is to include loopback0 in the routing protocol's network statements and ensure it is advertised through the tunnel, not just the tunnel interface itself.

Why this answer

The spokes can establish the IKEv2 tunnel and ping the hub's tunnel IP, confirming that the tunnel interface is up and the IKEv2 session is functional. However, the loopback0 address (10.0.0.1/32) is not reachable from the spokes because it is not advertised into the routing protocol (e.g., OSPF, EIGRP, or BGP) used over the FlexVPN tunnel. Without a route to the loopback0 prefix, the spokes' traffic to 10.0.0.1 is dropped by the hub's routing table, even though the tunnel is operational.

Exam trap

Cisco often tests the distinction between tunnel reachability (IKEv2 and tunnel interface up) and routing reachability (prefixes advertised over the tunnel), leading candidates to incorrectly focus on IKEv2 or certificate issues when the tunnel is already established.

How to eliminate wrong answers

Option A is wrong because the IKEv2 proposal mismatch would prevent the IKEv2 tunnel from establishing at all, yet the spokes can establish the tunnel and ping the hub's tunnel IP. Option B is wrong because if the certificate authority were not trusted by the hub, the IKEv2 authentication would fail during the certificate exchange, preventing tunnel establishment. Option C is wrong because the tunnel interface must be in an up/up state for the spokes to successfully ping the hub's tunnel IP, which is confirmed in the scenario.

56
MCQmedium

Given the following SPAN configuration on a Cisco IOS-XE switch: monitor session 4 source interface GigabitEthernet1/0/6 tx monitor session 4 destination interface GigabitEthernet1/0/7 What does this configuration do?

A.Only traffic transmitted from GigabitEthernet1/0/6 is copied to GigabitEthernet1/0/7.
B.Both ingress and egress traffic on GigabitEthernet1/0/6 is copied to GigabitEthernet1/0/7.
C.Traffic on GigabitEthernet1/0/7 is mirrored to GigabitEthernet1/0/6.
D.The configuration is invalid because the destination interface must be in the same VLAN as the source.
AnswerA

The 'tx' keyword in the monitor session command restricts copying to egress traffic only, meaning frames that the source interface GigabitEthernet1/0/6 transmits out of itself. The switch captures those frames and forwards a copy out of the destination interface GigabitEthernet1/0/7, which is configured as a SPAN destination. No ingress frames received on the source are considered, so the description is accurate.

Why this answer

The configuration uses the 'tx' keyword to specify that only traffic transmitted (egress) from GigabitEthernet1/0/6 should be copied to the destination interface GigabitEthernet1/0/7. Without the 'tx' keyword, the default behavior would be to monitor both ingress and egress traffic, but the explicit 'tx' limits the SPAN session to egress traffic only.

Exam trap

Cisco often tests the subtle difference between the default SPAN behavior (both ingress and egress) and the explicit 'tx' or 'rx' keywords, leading candidates to assume both directions are always monitored.

How to eliminate wrong answers

Option B is wrong because it assumes both ingress and egress traffic are copied, but the 'tx' keyword explicitly restricts monitoring to transmitted traffic only. Option C is wrong because it reverses the source and destination roles; the configuration copies traffic from GigabitEthernet1/0/6 to GigabitEthernet1/0/7, not the other way around. Option D is wrong because there is no requirement for the source and destination interfaces to be in the same VLAN; SPAN can copy traffic across VLANs, and the destination interface is typically placed in a separate monitoring VLAN or left in its default VLAN.

57
MCQmedium

A network engineer is writing a Python script using the ncclient library to retrieve the running configuration from a Cisco IOS XE device. The script connects using NETCONF over SSH on port 830. The engineer wants to filter the response to only include interface configuration data. Which NETCONF operation should be used to retrieve the configuration with a filter?

A.<get> with a <filter> element.
B.<copy-config> with a <source> of <running>.
C.<edit-config> with a <target> of <running>.
D.<get-config> with a <source> of <running> and a <filter> element.
AnswerD

<get-config> is the NETCONF operation used to retrieve configuration data. It requires a <source> element specifying the configuration datastore (e.g., <running>) and can include a <filter> to limit the data returned. This is the correct way to retrieve a subset of the running configuration, such as interface configuration.

Why this answer

The <get-config> operation is specifically designed to retrieve configuration data from a datastore. It supports a <filter> element to select specific portions of the configuration, such as interfaces. This allows the engineer to retrieve only the desired data, reducing payload size and processing time.

Exam trap

The trap here is confusing <get> with <get-config>; <get> retrieves both configuration and state data, while <get-config> retrieves only configuration.

58
MCQmedium

Consider the following configuration snippet: ``` interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ip nat inside ! interface GigabitEthernet0/2 ip address 203.0.113.1 255.255.255.0 ip nat outside ! ip nat inside source list 1 interface GigabitEthernet0/2 overload access-list 1 permit 192.168.1.0 0.0.0.255 ``` What is the effect of this configuration?

A.It translates all traffic from 192.168.1.0/24 to the IP address 203.0.113.1, using port address translation.
B.It performs static NAT for each host in 192.168.1.0/24 to a unique IP in the 203.0.113.0/24 network.
C.It translates only traffic from 192.168.1.1 to the outside interface IP.
D.The configuration is invalid because 'ip nat inside' and 'ip nat outside' are on the wrong interfaces.
AnswerA

The presence of the 'overload' keyword in the NAT configuration, combined with an access list that matches the entire 192.168.1.0/24 subnet, causes the router to perform Port Address Translation. Every inside host sharing the single public IPv4 address 203.0.113.1 is differentiated by a unique TCP/UDP port number, while the configuration does not reserve any pool of public addresses. This is the expected behavior for many-to-one internet access.

Why this answer

This configuration implements dynamic NAT with Port Address Translation (PAT), also known as NAT overload. The access list matches the 192.168.1.0/24 source network, and the 'ip nat inside source list 1 interface GigabitEthernet0/2 overload' command translates all matching inside local addresses to the single outside interface IP (203.0.113.1) using unique port numbers to differentiate sessions. This allows multiple internal hosts to share the public IP simultaneously.

Exam trap

Cisco often tests the distinction between dynamic NAT (with or without overload) and static NAT, and the trap here is that candidates may think 'overload' implies static mapping or that the access list only applies to the first host, when in fact it applies to the entire subnet and enables PAT.

How to eliminate wrong answers

Option B is wrong because static NAT would require individual 'ip nat inside source static' commands for each host, and the configuration uses a dynamic access list with overload, not a one-to-one mapping to unique IPs. Option C is wrong because the access list permits the entire 192.168.1.0/24 subnet, not just host 192.168.1.1, so all hosts in that subnet are translated. Option D is wrong because the interfaces are correctly configured: GigabitEthernet0/1 is the inside network (private) and GigabitEthernet0/2 is the outside network (public), which is the standard placement for NAT.

59
Multi-Selecthard

Which three statements about the benefits and challenges of NFV are true? (Choose three.)

Select 3 answers
A.NFV reduces capital expenditure by allowing network functions to run on standard, off-the-shelf hardware.
B.NFV enables faster time-to-market for new services by decoupling software from hardware.
C.One challenge of NFV is the potential performance overhead introduced by the virtualization layer.
D.NFV reduces the overall security attack surface by consolidating multiple functions into a single physical device.
E.NFV eliminates the need for physical cabling in the data center.
AnswersA, B, C

Running network functions as software on commodity x86 servers removes reliance on costly proprietary appliances, directly lowering capital expenditure. This cost-reduction mechanism is exactly the NFV benefit the stem asks you to identify as true.

Why this answer

Option A is correct because NFV replaces purpose-built, proprietary appliances with Virtual Network Functions (VNFs) running on commercial off-the-shelf (COTS) x86 servers, which lowers capital expenditure on specialized hardware. Option B is correct because decoupling network functions from proprietary hardware lets operators deploy and scale new services as software images, dramatically shortening service creation and time-to-market cycles. Option C is correct because the hypervisor/virtualization layer and virtual switching (e.g., vSwitch, SR-IOV, DPDK overhead) add processing latency and throughput penalties compared with bare-metal network functions, which is a recognized NFV performance challenge.

Option D is not correct because consolidating many functions onto shared hardware and hypervisors actually enlarges the attack surface and creates new hypervisor and multi-tenancy risks rather than reducing it. Option E is not correct because NFV virtualizes network functions, not physical links; physical cabling and the underlying transport network are still required to interconnect servers, switches, and storage.

Exam trap

The trap here is assuming NFV automatically improves security or eliminates physical infrastructure, when in fact it can increase attack surface and still requires physical cabling; candidates often confuse NFV with SDN or overlook the performance overhead of virtualization.

60
MCQhard

A network engineer is deploying a Cisco SD-Access fabric and needs to ensure that endpoints can communicate with devices outside the fabric. The engineer configures a fabric border node. Which functionality does the border node provide in this architecture?

A.It provides connectivity between the fabric and external networks, such as data centers or the internet.
B.It authenticates endpoints and assigns them to fabric VNs based on policy.
C.It acts as the mapping database system that stores endpoint location information.
D.It encapsulates fabric traffic into VXLAN and forwards it to the control plane node.
AnswerA

The fabric border node is responsible for bridging the SD-Access fabric to external networks. It translates fabric VXLAN encapsulation to traditional networking protocols and vice versa, allowing endpoints inside the fabric to reach destinations outside. It also advertises fabric prefixes to external networks. This is the primary role of a border node in Cisco SD-Access.

Why this answer

In Cisco SD-Access, the fabric border node serves as the gateway between the fabric and external networks. It performs VXLAN-to-traditional network translation, allowing fabric endpoints to communicate with external destinations. It also advertises external routes into the fabric and fabric prefixes to external networks.

The border node does not handle endpoint authentication, mapping database services, or control plane functions; those are handled by edge nodes and control plane nodes respectively.

Exam trap

The trap here is confusing the border node with the control plane node or edge node; the border node's primary role is external connectivity, not endpoint registration or authentication.

61
Matchingmedium

Drag and drop each OSPF packet type on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Discovers neighbors and maintains adjacency state

Contains a list of LSA headers for database synchronization

Requests specific LSAs from a neighbor

Sends one or more complete LSAs to a neighbor

Confirms receipt of LSU packets

Why these pairings

Hello packets discover and maintain neighbor relationships; DBD packets contain a summary of the LSDB; LSR packets request specific LSAs; LSU packets send full LSAs in response to LSRs; LSAck packets acknowledge receipt of LSUs.

62
MCQhard

A network administrator is deploying a Cisco SD-WAN solution. The administrator wants to ensure that control plane information is securely distributed between vSmart controllers and vEdge routers. Which protocol does Cisco SD-WAN use for this purpose?

A.BGP
B.IPsec
C.DTLS
D.OMP
AnswerD

Overlay Management Protocol (OMP) is the control plane protocol used in Cisco SD-WAN. It runs between vSmart controllers and vEdge routers to distribute routing, policy, and service information securely. OMP uses TLS for encryption and authentication, ensuring secure communication. It is the correct protocol for this requirement.

Why this answer

Cisco SD-WAN uses Overlay Management Protocol (OMP) for control plane communication between vSmart controllers and vEdge routers. OMP distributes routing, policy, and service information, and it runs over secure TLS/DTLS sessions. While BGP, IPsec, and DTLS play roles in SD-WAN, OMP is the specific control plane protocol that enables the overlay network's dynamic routing and policy enforcement.

Exam trap

The trap here is confusing the transport security protocol (DTLS) with the actual control plane routing protocol (OMP), or assuming that BGP is used for overlay control when it is only used for external route exchange.

63
MCQhard

A network engineer is configuring IPsec VPN on a Cisco IOS XE router. The requirement is to protect traffic between two sites using ESP with AES-256 encryption and SHA-256 authentication, and to ensure that the tunnel is rekeyed every 3600 seconds. Which configuration element directly controls the rekey interval?

A.crypto ipsec transform-set <name> esp-aes 256 esp-sha256-hmac
B.crypto map <name> 10 ipsec-isakmp
C.crypto ipsec security-association lifetime seconds 3600
D.crypto isakmp key <key> address <peer>
AnswerC

The 'crypto ipsec security-association lifetime seconds 3600' command sets the IPsec SA lifetime to 3600 seconds, after which the SA is rekeyed. This is the correct command to control the rekey interval for the IPsec (data) tunnel. The IKE SA lifetime is controlled separately with 'crypto isakmp policy' or 'crypto ikev2 policy' settings, but the IPsec SA lifetime is what governs data tunnel rekeying.

Why this answer

The IPsec SA lifetime, configured with 'crypto ipsec security-association lifetime seconds 3600', determines when the data tunnel is rekeyed. This is distinct from the IKE SA lifetime, which governs the control plane. The transform-set defines the algorithms (AES-256, SHA-256), the crypto map ties the policy together, and the pre-shared key authenticates the peers, but only the security-association lifetime command controls the rekey interval.

Exam trap

The trap here is confusing the IKE SA lifetime with the IPsec SA lifetime, and assuming that the transform-set or crypto map controls rekeying.

64
MCQmedium

A network engineer is configuring a Cisco Catalyst 9000 switch to support a VXLAN EVPN fabric. The engineer wants to enable the switch to act as a VTEP and perform VXLAN encapsulation and decapsulation. Which command must be configured to create the VXLAN tunnel interface?

A.interface vlan 1
B.interface tunnel 1
C.interface nve 1
D.interface vxlan 1
AnswerC

The 'interface nve 1' command creates a Network Virtualization Edge (NVE) interface, which is the logical interface used for VXLAN tunneling. Under this interface, you configure the source-interface and member VNIs. This is the standard way to enable VTEP functionality on Cisco platforms.

Why this answer

To enable VXLAN on a Cisco switch, you must create an NVE interface using the 'interface nve 1' command. This interface is responsible for VXLAN encapsulation and decapsulation. Other interface types like tunnel, vxlan, or vlan do not provide VXLAN functionality.

Exam trap

The trap here is assuming that VXLAN uses a generic tunnel interface, but Cisco implements VXLAN via the NVE interface.

65
MCQhard

A network engineer is implementing VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. Hosts in the same subnet are attached to different edge nodes. The engineer must ensure that a host retains its default gateway IP and MAC address when it moves between edge nodes. Which technology should be configured on the edge nodes?

A.VRRP with preemption enabled on all edge nodes
B.Anycast gateway with the same IP and MAC address on all edge nodes for that subnet
C.HSRP group with a unique virtual IP per edge node
D.Proxy ARP on the edge nodes
AnswerB

In a VXLAN fabric, a distributed anycast gateway uses the same virtual IP and virtual MAC for the default gateway on every edge node that hosts the subnet. A roaming host sees no change in gateway identity, so ARP entries remain valid. This provides seamless mobility and optimal forwarding without tromboning traffic to a central gateway.

Why this answer

A distributed anycast gateway assigns the same virtual IP and virtual MAC to the default gateway on every edge node hosting a subnet. Hosts can move between edge nodes without changing their gateway ARP entry, which preserves connectivity and avoids suboptimal paths. This is a fundamental requirement for seamless host mobility in VXLAN EVPN fabrics.

Exam trap

The trap here is assuming first-hop redundancy protocols like HSRP or VRRP can provide a distributed gateway, when they only offer one active gateway per subnet.

66
MCQhard

A network designer is evaluating a virtual switch deployment in a Cisco ACI fabric. The requirement is to extend a bridge domain across multiple leaf switches while allowing the fabric to perform distributed IP routing at the leaf for endpoints in that bridge domain. Which ACI construct should the designer use?

A.A VRF with policy-based redirect to a service graph
B.A tenant with a single EPG mapped to a static path
C.A private network with an external bridged domain
D.A bridge domain with hardware proxy and unicast routing enabled
AnswerD

This is correct because enabling unicast routing on a bridge domain, combined with the hardware proxy function, allows the leaf switches to perform distributed gateway routing for endpoints in that bridge domain. The anycast gateway is programmed on every leaf, so traffic is routed at the ingress leaf without tromboning to a central spine, meeting the distributed routing requirement.

Why this answer

In Cisco ACI, distributed first-hop routing is achieved by enabling unicast routing on the bridge domain and using the hardware proxy anycast gateway. This programs the same gateway IP and MAC on every leaf, so endpoints are routed at their ingress leaf. The other constructs address isolation, service insertion, or static endpoint attachment, none of which delivers distributed routing.

Exam trap

The trap here is confusing bridge domain routing attributes with VRF isolation or service-graph features, which do not provide distributed anycast gateway routing at the leaf.

67
Matchingmedium

Drag and drop each IP SLA schedule parameter on the left to its function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Defines when the operation begins

Sets the interval between probes

Sets the total duration of the operation

Removes the operation after inactivity

Sets the value that triggers a reaction

Why these pairings

Start-time defines when the operation begins; frequency sets the interval between probes; life sets the total duration of the operation.

68
Drag & Dropmedium

Drag and drop the steps of the 802.1X/EAP authentication process for a wireless client into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order is: 1. Client sends EAPoL-Start to the AP (A). 2. AP sends EAP-Request Identity (B). 3.

Client sends EAP-Response Identity (C). 4. RADIUS sends EAP-Request credentials (D). 5. Client sends EAP-Response credentials (E).

This sequence is standard for 802.1X/EAP wireless authentication.

69
MCQmedium

Examine this configuration for a site-to-site VPN on a Cisco router: crypto isakmp policy 10 encryption aes 256 hash sha256 authentication pre-share group 14 lifetime 86400 ! crypto ipsec transform-set TSET esp-aes 256 esp-sha256-hmac mode tunnel ! crypto map CMAP 10 ipsec-isakmp set peer 192.168.1.1 set transform-set TSET match address 101 ! interface GigabitEthernet0/0/0 ip address 10.0.0.1 255.255.255.0 crypto map CMAP ! access-list 101 permit ip 192.168.10.0 0.0.0.255 192.168.20.0 0.0.0.255 Which statement about this configuration is true?

A.The crypto map uses IKEv2 for key exchange because the transform set uses SHA-256.
B.The access-list 101 defines the traffic that will be encrypted; traffic from 192.168.10.0/24 to 192.168.20.0/24 will be protected.
C.The ISAKMP policy lifetime of 86400 seconds is too long and will cause the tunnel to fail.
D.The crypto map should be applied to the tunnel interface, not the physical interface.
AnswerB

Access-list 101 is referenced by the crypto map's 'match address 101' statement, which defines the interesting traffic that will be protected by IPsec. The ACL explicitly permits traffic from source network 192.168.10.0/24 to destination network 192.168.20.0/24, so only that traffic triggers the establishment of the IPsec security association. This is correct because without a matching ACL entry, no traffic would be encrypted and the VPN would not carry any payload.

Why this answer

Access-list 101 is used by the crypto map to match traffic that should be encrypted via IPsec. The ACL permits traffic from source network 192.168.10.0/24 to destination network 192.168.20.0/24, so that traffic will be protected by the IPsec tunnel. This is the standard method for defining interesting traffic in a site-to-site VPN.

Exam trap

Cisco often tests the misconception that the crypto map should be applied to a tunnel interface, but in reality it must be applied to the physical egress interface for site-to-site VPNs.

How to eliminate wrong answers

Option A is wrong because the use of SHA-256 in the transform set does not indicate IKEv2; IKEv2 is configured with the 'crypto ikev2' commands, not with ISAKMP policy commands, and the configuration shown uses 'crypto isakmp policy' which is IKEv1. Option C is wrong because an ISAKMP lifetime of 86400 seconds (24 hours) is a common and valid default value; it will not cause the tunnel to fail. Option D is wrong because the crypto map must be applied to the physical interface (or subinterface) that connects to the remote peer, not to a tunnel interface; applying it to a tunnel interface would be incorrect for a site-to-site VPN.

70
MCQmedium

A network engineer configures VRF-lite on a router with the following snippet: vrf definition GREEN rd 200:1 ! interface GigabitEthernet0/3 vrf forwarding GREEN ip address 172.16.1.1 255.255.255.0 ! router ospf 10 vrf GREEN network 172.16.1.0 0.0.0.255 area 0 What is missing from this configuration to enable proper OSPF routing within VRF GREEN?

A.The configuration is complete and OSPF will operate correctly within VRF GREEN.
B.The 'network' command should specify the interface instead of the subnet.
C.The 'vrf definition GREEN' must include a 'route-target' command.
D.The OSPF process must be configured under the global VRF context, not using 'vrf GREEN'.
AnswerA

The configuration is complete because the 'router ospf <pid> vrf GREEN' command correctly creates an OSPF process bound to VRF GREEN, and the 'network' statement uses a wildcard mask to advertise the appropriate subnet into OSPF. The router-id is automatically selected from the highest loopback or active interface address in the VRF, so no explicit router-id is required. Thus, OSPF will operate correctly within the VRF.

Why this answer

The configuration is complete for VRF-lite OSPF routing. In VRF-lite, the 'vrf definition GREEN' with an RD, the interface assignment via 'vrf forwarding GREEN', and the OSPF process with 'vrf GREEN' and the network statement are all that is required. OSPF will operate correctly within VRF GREEN using the specified network in area 0.

Exam trap

Cisco often tests the misconception that VRF-lite requires 'route-target' commands, which are actually only necessary for MPLS VPNs, not for simple VRF-lite configurations.

How to eliminate wrong answers

Option B is wrong because the 'network' command in OSPF can specify a subnet with a wildcard mask, which is the standard method; it does not need to specify the interface directly. Option C is wrong because 'route-target' commands are required for MPLS VPN (VRF-lite does not use MPLS), not for VRF-lite where only the RD is needed for route distinguishment. Option D is wrong because the OSPF process can be configured under the global VRF context using the 'vrf GREEN' keyword after the process ID, which is the correct syntax for associating an OSPF process with a VRF.

71
MCQhard

A network engineer is designing a QoS policy for a WAN edge router. The router must prioritize voice traffic with strict priority while ensuring that other traffic classes are not starved. The engineer decides to use Low Latency Queueing (LLQ). Which additional mechanism should be configured to prevent starvation of other queues when voice traffic exceeds its allocated bandwidth?

A.Weighted Random Early Detection (WRED) on the voice queue
B.Traffic shaping on the voice class to smooth bursts
C.Policing on the voice class to limit its bandwidth
D.Class-Based Weighted Fair Queueing (CBWFQ) on the voice class
AnswerC

In LLQ, the priority queue is serviced first and can starve other queues if not policed. Configuring policing on the voice class limits the amount of traffic that can enter the priority queue, ensuring that other queues get bandwidth. This is the standard method to prevent starvation in LLQ deployments.

Why this answer

LLQ provides a strict priority queue for voice, but without a policer, the priority queue can consume all available bandwidth and starve other queues. Configuring policing on the voice class limits the priority traffic to a defined rate, ensuring that other classes receive their configured bandwidth. This is the recommended practice for LLQ.

Exam trap

The trap here is thinking that CBWFQ or shaping can prevent starvation, when the correct mechanism is a policer on the priority queue.

72
Multi-Selecthard

Which three statements about using Python for interacting with Cisco IOS-XE devices via NETCONF and RESTCONF are true? (Choose three.)

Select 3 answers
A.The ncclient Python library can be used to establish a NETCONF session with a Cisco IOS-XE device and retrieve YANG-modeled data.
B.RESTCONF uses HTTP methods such as GET, POST, PUT, and DELETE to access YANG-defined data on a network device.
C.YANG models define the structure and constraints of data that can be accessed via NETCONF or RESTCONF.
D.RESTCONF only supports data encoding in YAML format.
E.NETCONF is always faster than RESTCONF for retrieving large amounts of data because it uses a binary encoding.
AnswersA, B, C

The ncclient library implements the NETCONF protocol over SSH, opening a session on port 830 and exchanging XML-encoded RPCs. It retrieves configuration and state data modelled by YANG, satisfying the stem's requirement for programmatic IOS-XE interaction via NETCONF rather than RESTCONF's HTTP-based interface.

Why this answer

Option A is correct because ncclient is a Python library specifically designed to implement the NETCONF protocol, allowing a script to open an SSH-based NETCONF session (typically on port 830) with a Cisco IOS-XE device, send <get> or <get-config> RPCs, and retrieve YANG-modeled configuration and state data. Option B is correct because RESTCONF is a RESTful protocol that maps YANG data to HTTP resources and uses standard HTTP methods — GET to read, POST to create, PUT/PATCH to modify, and DELETE to remove — against URIs such as /restconf/data/ietf-interfaces:interfaces. Option C is correct because YANG is the data modeling language that defines the hierarchical structure, data types, and constraints of the data exposed by both NETCONF and RESTCONF, so any Python interaction with these protocols ultimately manipulates YANG-modeled content.

Option D is incorrect because RESTCONF supports XML and JSON encodings (selected via the Content-Type/Accept headers), not YAML. Option E is incorrect because NETCONF uses XML encoding, not binary, and performance depends on factors such as payload size, transport, and implementation rather than a guaranteed speed advantage over RESTCONF.

Exam trap

The trap is the claim that NETCONF uses binary encoding or is inherently faster — NETCONF is XML-based, and speed depends on implementation, not encoding format.

73
Drag & Dropmedium

Drag and drop the steps of OSPF virtual link configuration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

A virtual link connects a non-backbone area to Area 0 through a transit area. First, identify the ABR with the transit area, then configure the virtual link on both ABRs using the router ID of the neighbor, ensure the transit area has full OSPF adjacency, and finally verify the virtual link is operational.

74
MCQhard

A network administrator is troubleshooting a Cisco SD-WAN deployment where a branch site is experiencing intermittent connectivity to a SaaS application. The administrator suspects that the issue is related to the application-aware routing policy not correctly identifying the application. Which component of Cisco SD-WAN is responsible for identifying applications in the data plane?

A.vBond orchestrator
B.vSmart controller
C.vManage NMS
D.vEdge router
AnswerD

The vEdge router is responsible for data plane forwarding and application identification. It uses deep packet inspection (DPI) or Cisco NBAR to classify traffic into applications, which is essential for application-aware routing policies. This classification allows the router to make informed path selection decisions based on application performance requirements.

Why this answer

Application identification in Cisco SD-WAN is performed by the vEdge router, which uses deep packet inspection (DPI) or Cisco NBAR to recognize applications. This classification is critical for application-aware routing, as it enables the router to apply policies that steer traffic based on application performance. The vEdge router then forwards traffic accordingly, ensuring that SaaS applications receive appropriate treatment.

Exam trap

The trap here is assuming that centralized controllers like vSmart or vManage perform application identification, but this function is distributed to the data plane on vEdge routers.

75
MCQmedium

Examine the following configuration on a Cisco 9800 WLC: ap profile default-ap-profile description "Default AP Profile" country US management-user admin Which statement is true about this configuration?

A.This profile configures the SSID for the AP.
B.The country code is set to the United States, affecting allowed channels and transmit power.
C.This profile enables 802.11r fast roaming.
D.The management user 'admin' is used for client authentication.
AnswerB

The statement is correct because the AP profile sets the country code to the United States, forcing the access point to comply with the FCC regulatory domain. That country code dictates which 2.4 GHz channels are valid (typically 1–11 rather than 12–14), which 5 GHz channels are available, including DFS restrictions, and the maximum allowable transmit power (EIRP) per channel. Setting the wrong country code can cause illegal transmissions or harmful interference, so the country code is a mandatory, compliance-relevant field within the AP profile.

Why this answer

The 'country US' command in the AP profile sets the regulatory domain to the United States, which determines the allowed channels, maximum transmit power levels, and DFS requirements for the AP. This is a fundamental wireless configuration that ensures compliance with local regulations.

Exam trap

Cisco often tests the distinction between AP profiles (which handle hardware and regulatory settings) and WLAN profiles (which handle SSID and security parameters), leading candidates to mistakenly associate SSID or roaming configuration with the AP profile.

How to eliminate wrong answers

Option A is wrong because an AP profile does not configure SSIDs; SSIDs are configured in WLAN profiles and mapped to APs via policy tags or AP join profiles. Option C is wrong because 802.11r fast roaming is enabled on the WLAN (SSID) level under the 'security ft' or 'fast-roaming' settings, not in the AP profile. Option D is wrong because the 'management-user admin' command defines the username for AP management access (e.g., SSH or console), not for client authentication, which is handled by 802.1X, PSK, or other methods on the WLAN.

Page 1 of 26

Page 2