Courseiva

ENCOR 350-401 (350-401) — Questions 676–750

1923 questions total · 26pages · All types, answers revealed

Page 9

Page 10 of 26

Page 11
676
MCQeasy

A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote access. The requirement is to use IKEv2 with certificate-based authentication. The administrator has installed a valid identity certificate on the router and configured the IKEv2 profile. However, remote clients are unable to establish the VPN tunnel, and the router logs show 'IKEv2 certificate authentication failed'. What is the most likely cause?

A.The pre-shared key is not configured on the IKEv2 profile.
B.The remote clients are using IKEv1 instead of IKEv2.
C.The router's certificate has expired.
D.The IKEv2 profile is not referencing the correct trustpoint for certificate authentication.
AnswerD

In IKEv2, the profile must specify the trustpoint that contains the router's identity certificate and the CA certificate for verifying peer certificates. If the trustpoint is not referenced or is incorrect, the router cannot validate client certificates, leading to authentication failure. This is a common misconfiguration when setting up certificate-based IKEv2. The logs indicating certificate authentication failed point to a trustpoint or PKI issue.

Why this answer

For IKEv2 certificate-based authentication, the IKEv2 profile must reference a trustpoint that contains the router's identity certificate and the CA certificate to validate peer certificates. If the trustpoint is missing or incorrect, the router cannot authenticate the client's certificate, resulting in failure. Ensuring the correct trustpoint is referenced and that the CA chain is complete resolves the issue.

Exam trap

The trap here is assuming that installing a valid certificate is sufficient, while overlooking that the IKEv2 profile must explicitly point to the trustpoint for authentication to succeed.

677
MCQmedium

Consider this AAA configuration: aaa new-model aaa authentication login default local aaa authorization exec default local aaa accounting exec default start-stop group tacacs+ tacacs-server host 10.0.0.1 key SecretKey line con 0 login authentication default line vty 0 4 login authentication default What is the effect of this configuration?

A.All login attempts use local authentication; exec accounting is sent to TACACS+.
B.All login attempts use TACACS+ authentication; exec accounting is local.
C.Console login uses TACACS+; VTY login uses local; accounting is sent to TACACS+.
D.Authentication and authorization are both performed by TACACS+; accounting is local.
AnswerA

This option is correct because the command `aaa authentication login default local` applies local authentication to every login attempt, regardless of transport (console, VTY, or auxiliary). Additionally, `aaa authorization exec default local` defers authorization decisions to the local database, but that is not contradicted here. The final command, `aaa accounting exec default start-stop group tacacs+`, instructs the device to generate start and stop accounting records for each EXEC session and forward them to the TACACS+ server. Thus, authentication is local, while accounting is sent remotely to TACACS+.

Why this answer

The configuration sets AAA authentication login to use the local user database (via 'aaa authentication login default local'), so all login attempts (console and VTY) authenticate against the local device. Authorization for exec sessions is also set to local ('aaa authorization exec default local'), meaning no external authorization is used. Accounting for exec sessions is configured with 'start-stop' and points to the TACACS+ server at 10.0.0.1, so all exec session start and stop records are sent to TACACS+.

This matches option A.

Exam trap

Cisco often tests the distinction between authentication, authorization, and accounting method lists, and the trap here is that candidates assume 'default' in the accounting command implies local accounting, when in fact it refers to the method list name and the actual method is specified by 'group tacacs+'.

How to eliminate wrong answers

Option B is wrong because the 'aaa authentication login default local' command explicitly uses local authentication, not TACACS+ authentication. Option C is wrong because both console and VTY lines inherit the same 'default' authentication method list, which is local, so console does not use TACACS+ and VTY does not use local exclusively. Option D is wrong because authorization is set to local ('aaa authorization exec default local'), not TACACS+, and accounting is sent to TACACS+ (not local).

678
Multi-Selectmedium

A network architect is designing a Cisco SD-Access fabric and must ensure that the control plane and data plane are properly separated. Which two statements accurately describe the roles of fabric nodes in Cisco SD-Access? (Choose two.)

Select 2 answers
A.Fabric edge nodes encapsulate traffic in VXLAN and provide anycast gateway functionality for endpoints.
B.Fabric control plane nodes run LISP map-server and map-resolver to track endpoint locations.
C.Fabric intermediate nodes perform LISP map-cache resolution for endpoints on behalf of edge nodes.
D.Fabric border nodes are responsible for VXLAN encapsulation of traffic between edge nodes within the same fabric site.
E.Fabric edge nodes maintain the LISP map-server database for all endpoints in the fabric site.
AnswersA, B

Fabric edge nodes are responsible for VXLAN encapsulation and decapsulation at the fabric boundary. They provide the anycast gateway, which serves as the default gateway for endpoints, allowing seamless mobility. This statement correctly describes a key role of edge nodes in SD-Access, making it one of the accurate statements.

Why this answer

In Cisco SD-Access, fabric edge nodes provide VXLAN encapsulation and anycast gateway for endpoints, while control plane nodes run LISP map-server and map-resolver to track endpoint locations. Border nodes connect to external networks, and intermediate nodes provide underlay transport. Edge nodes do not maintain the LISP map-server database; that is the control plane node's function.

Exam trap

The trap here is mixing up the roles of edge, control plane, and border nodes, especially assuming edge nodes perform control plane functions like LISP map-server.

679
Multi-Selectmedium

A network engineer is implementing VXLAN on Cisco Nexus 9000 switches. The engineer needs to verify the configuration of the VXLAN data plane. Which two statements are true regarding VXLAN operation? (Choose two.)

Select 2 answers
A.VXLAN requires the underlay network to run OSPF for route distribution.
B.VXLAN encapsulates original Ethernet frames in UDP packets with destination port 4789.
C.VXLAN tunnels are established between VTEPs using a control protocol such as LISP.
D.VXLAN uses a 12-bit VLAN ID to identify the overlay network.
E.VXLAN uses a 24-bit VN-Segment ID (VNI) to identify the overlay network.
AnswersB, E

VXLAN encapsulates Layer 2 frames into UDP packets. The standard destination UDP port is 4789, as assigned by IANA. This encapsulation allows Layer 2 segments to be stretched over a Layer 3 network. The source port is dynamically chosen to provide entropy for ECMP hashing.

Why this answer

VXLAN uses a 24-bit VNI to identify overlay segments, enabling massive scalability. It encapsulates original Ethernet frames in UDP packets with destination port 4789. These two facts are fundamental to VXLAN operation and are correct.

The other statements are false: VXLAN does not require OSPF, does not use a 12-bit VLAN ID, and does not inherently use LISP for tunnel establishment.

Exam trap

The trap here is assuming VXLAN uses a 12-bit VLAN ID or requires a specific routing protocol like OSPF in the underlay, but VXLAN's scalability comes from the 24-bit VNI and underlay-agnostic design.

680
MCQhard

A network administrator is configuring a Cisco IOS router to authenticate management users against a TACACS+ server. The administrator wants to ensure that if the TACACS+ server becomes unreachable, a local username and password can still be used to log in. Which configuration accomplishes this requirement?

A.aaa authentication login default local group tacacs+
B.aaa authentication login default group tacacs+ local
C.aaa authentication login default group tacacs+ none
D.aaa authentication login default group tacacs+ enable
AnswerB

This command configures AAA authentication for login using TACACS+ first, then falls back to the local database if the TACACS+ server is unreachable. The 'local' keyword ensures that local authentication is attempted only if the TACACS+ servers do not respond, providing a failover mechanism for management access.

Why this answer

The correct method list must list 'group tacacs+' before 'local' so that TACACS+ is tried first, and local is used only if the server is unreachable. The 'local' keyword ensures that the local username database is used as a fallback. Other keywords like 'enable' or 'none' do not provide the required local username and password fallback.

Exam trap

The trap here is confusing the order of authentication methods; the first method is primary, and subsequent methods are fallbacks. Placing 'local' first would make it primary, which is not desired.

681
Matchingmedium

Drag and drop each RESTCONF method on the left to its matching NETCONF equivalent on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Retrieve data (equivalent to get or get-config)

Create a new data resource (equivalent to edit-config with create)

Replace an existing resource (equivalent to edit-config with replace)

Partially update a resource (equivalent to edit-config with merge)

Remove a resource (equivalent to edit-config with delete)

Why these pairings

RESTCONF GET retrieves data (like NETCONF get/get-config), POST creates a resource (like edit-config with operation create), PUT replaces a resource (like edit-config with operation replace), PATCH partially updates (like edit-config with operation merge), and DELETE removes a resource (like edit-config with operation delete).

682
MCQeasy

A network engineer is troubleshooting a connectivity issue and wants to verify the path that packets take from a Cisco IOS XE router to a remote destination. Which command provides a hop-by-hop listing of the path, including latency information for each hop?

A.traceroute
B.show ip interface brief
C.ping
D.show ip route
AnswerA

The traceroute command sends packets with incrementally increasing Time-to-Live (TTL) values and records the ICMP Time Exceeded messages returned by each hop. This provides a list of routers along the path and round-trip time for each hop. It is the standard tool for path discovery and latency measurement on Cisco IOS XE.

Why this answer

Traceroute is designed to discover the path to a destination by leveraging the TTL field in IP packets. Each router that decrements the TTL to zero sends an ICMP Time Exceeded message, allowing the source to build a list of hops. It also records round-trip times, making it ideal for diagnosing latency and path issues.

Exam trap

The trap here is confusing ping with traceroute; ping only tests end-to-end reachability, while traceroute reveals the intermediate hops.

683
MCQmedium

An engineer is using a Python script to retrieve interface statistics from a Cisco IOS-XE device via the REST API. The script sends a GET request to 'https://device/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1/statistics' and receives a 404 Not Found response. The interface exists and is operational. What is the most likely issue?

A.The interface name must be URL-encoded because it contains a slash.
B.The URI is incorrect; statistics are under 'interfaces-state' not 'interfaces'.
C.The device requires authentication; the script must include a valid token.
D.The REST API is not enabled on the device; the engineer must enable it first.
AnswerB

The ietf-interfaces YANG model separates configuration data under 'interfaces' from operational state under 'interfaces-state'. Statistics are operational, so requesting them beneath 'interfaces' targets a non-existent node, producing the 404 despite the interface existing and being operational.

Why this answer

In the IETF YANG models used by RESTCONF, operational state data (including interface statistics such as counters and rates) is exposed under the 'ietf-interfaces:interfaces-state' container, not under the configuration-oriented 'interfaces' container. The 'interfaces' container holds configurable attributes like enabled/disabled and description, while 'interfaces-state' holds read-only operational data. Requesting statistics from the 'interfaces' path returns 404 because that data node does not exist there.

Exam trap

350-401 often tests whether candidates confuse configuration containers with operational-state containers in YANG models, leading them to blame authentication or API enablement instead of the incorrect URI path.

How to eliminate wrong answers

Option A is wrong because while URL-encoding is a valid concern for special characters, the slash in 'GigabitEthernet1' is part of the path segment and RESTCONF handles it; the 404 is caused by the wrong data node, not encoding. Option C is wrong because an authentication failure would return 401 Unauthorized, not 404 Not Found. Option D is wrong because if RESTCONF were disabled, the connection would be refused or return a different error (e.g., 404 on the root or connection error), and the question states the interface exists and is operational, implying the API is reachable.

684
MCQmedium

A network engineer is configuring CoPP on a Cisco router to protect the control plane from excessive traffic. The router experiences high CPU utilization due to SSH and SNMP traffic. The engineer creates a class-map to match SSH (TCP/22) and SNMP (UDP/161) and applies a policy-map that polices this traffic to 1 Mbps. After applying the policy, legitimate SSH sessions from the management station start dropping intermittently. What is the most likely cause?

A.The police rate of 1 Mbps is too low for the combined SSH and SNMP traffic from the management station.
B.The CoPP policy is applied to the wrong interface, affecting transit traffic instead of control plane traffic.
C.The class-map should match on DSCP values instead of port numbers to be effective.
D.The policy-map should use the 'drop' action instead of 'police' to protect the control plane.
AnswerA

The police rate of 1 Mbps is insufficient for the aggregated SSH (TCP/22) and SNMP (UDP/161) control-plane traffic generated by the management station. Under CoPP, the policer uses a token bucket that drops packets exceeding the committed information rate, and if the peak management traffic exceeds 1 Mbps, legitimate packets will be dropped, causing timeouts or loss of management access. The correct remedy is to raise the police rate above the expected combined throughput, not to change the classification or action.

Why this answer

The most likely cause is that the police rate of 1 Mbps is too low for the combined SSH and SNMP traffic from the management station. CoPP polices all traffic matching the class-map (SSH and SNMP) as a single aggregate flow. If the management station generates bursts of SSH and SNMP traffic that together exceed 1 Mbps, the policer will drop packets, causing legitimate SSH sessions to drop intermittently.

Exam trap

Cisco often tests the misconception that a single police rate applied to a class-map containing multiple protocols is sufficient, when in reality the aggregate rate must account for the combined peak traffic of all matched protocols.

How to eliminate wrong answers

Option B is wrong because CoPP is applied to the control plane using the 'service-policy' command under 'control-plane' configuration, not to an interface; applying it to an interface would affect transit traffic, but the scenario states the policy was applied correctly to protect the control plane. Option C is wrong because matching on port numbers (TCP/22, UDP/161) is the correct and standard method for identifying SSH and SNMP traffic in a CoPP class-map; DSCP values are not typically used for these protocols and would not solve the dropping issue. Option D is wrong because the 'police' action is the correct way to rate-limit traffic in CoPP; using 'drop' would discard all matching traffic unconditionally, which would be even more disruptive than policing.

685
MCQmedium

Which statement about RSPAN is true?

A.RSPAN uses a dedicated VLAN to transport mirrored traffic from source to destination switches.
B.RSPAN can only monitor traffic within the same switch.
C.RSPAN requires the use of ERSPAN encapsulation.
D.RSPAN destination ports must be in trunk mode.
AnswerA

RSPAN (Remote Switched Port Analyzer) is designed to forward mirrored traffic from a source switch across a network to a destination switch where an analyzer is attached. To achieve this, it defines a dedicated RSPAN VLAN that serves as a transport backbone: the source SPAN session copies frames into the RSPAN VLAN, and the destination SPAN session extracts those frames to a local monitor port. This VLAN must be allowed on all trunk links between the source and destination switches and should be used exclusively for mirrored traffic to prevent interference with production data.

Why this answer

RSPAN (Remote SPAN) uses a dedicated RSPAN VLAN to carry mirrored traffic from the source switch to one or more destination switches across a network. This allows monitoring of traffic on remote switches, unlike local SPAN which is confined to a single switch. The RSPAN VLAN must be configured on all intermediate switches and trunked appropriately to ensure the mirrored traffic reaches the destination.

Exam trap

Cisco often tests the distinction between RSPAN and ERSPAN, where candidates mistakenly think RSPAN uses encapsulation (like ERSPAN) or that destination ports must be trunks, when in fact RSPAN relies on a dedicated VLAN and access ports at the destination.

How to eliminate wrong answers

Option B is wrong because RSPAN is specifically designed to monitor traffic across multiple switches, not just within the same switch (that is local SPAN). Option C is wrong because RSPAN uses a dedicated VLAN for transport, not ERSPAN encapsulation; ERSPAN (Encapsulated Remote SPAN) uses GRE encapsulation to transport mirrored traffic over Layer 3 networks, which is a different technology. Option D is wrong because RSPAN destination ports are typically configured as access ports in the RSPAN VLAN, not trunk ports; trunk mode is used on intermediate switch ports that carry the RSPAN VLAN, not on the destination monitoring port itself.

686
MCQmedium

A network engineer is configuring a new Cisco IOS router and wants to ensure that OSPFv2 adjacencies form only on the interface that connects to the trusted internal network. The router has three interfaces: GigabitEthernet0/0 (internal), GigabitEthernet0/1 (DMZ), and GigabitEthernet0/2 (Internet). The engineer enables OSPF process 1 and wants to advertise the internal network 10.1.1.0/24 while preventing OSPF from sending or receiving hello packets on the other interfaces. Which configuration accomplishes this goal?

A.router ospf 1 network 10.1.1.0 0.0.0.255 area 0 passive-interface default no passive-interface GigabitEthernet0/0
B.router ospf 1 network 10.1.1.0 0.0.0.255 area 0 passive-interface GigabitEthernet0/1 passive-interface GigabitEthernet0/2
C.router ospf 1 network 10.1.1.0 0.0.0.255 area 0 ip ospf passive-interface GigabitEthernet0/1 ip ospf passive-interface GigabitEthernet0/2
D.router ospf 1 network 10.1.1.0 0.0.0.255 area 0 passive-interface GigabitEthernet0/0
AnswerA

This configuration enables OSPF on the router, advertises the internal subnet, and sets all interfaces to passive by default. The 'no passive-interface GigabitEthernet0/0' command re-enables OSPF hello processing only on the internal interface, allowing adjacencies to form there while suppressing them on the DMZ and Internet interfaces. This matches the requirement exactly.

Why this answer

The requirement is to allow OSPF adjacencies only on the internal interface while suppressing them on all others. Setting 'passive-interface default' disables OSPF hello processing on every interface, and then 'no passive-interface GigabitEthernet0/0' re-enables it only on the internal interface. This ensures that OSPF runs exclusively where intended and prevents unintended adjacencies on the DMZ and Internet links.

Exam trap

The trap here is assuming that the network command alone controls which interfaces run OSPF, when in fact OSPF can run on any interface whose IP matches the network statement, and passive-interface is needed to suppress hellos on specific interfaces.

687
Matchingmedium

Drag and drop each CoS value on the left to its matching traffic type on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Voice payload

Video conferencing

Call signaling

Critical data

Best-effort data

Why these pairings

CoS values are used in 802.1Q frames: CoS 5 for voice, CoS 4 for video, CoS 3 for call signaling, CoS 2 for critical data, CoS 0 for best-effort data.

688
MCQhard

A network engineer runs the following command on switch SW6: SW6# show cts role-based counters Role-based counters: Source Group Dest Group Packets Sent Bytes Sent Packets Denied Bytes Denied 10 20 1500 120000 0 0 10 30 0 0 500 40000 Based on this output, what can be concluded?

A.Traffic from SGT 10 to SGT 20 is being denied.
B.Traffic from SGT 10 to SGT 30 is being permitted.
C.Traffic from SGT 10 to SGT 20 is being permitted, and traffic from SGT 10 to SGT 30 is being denied.
D.No traffic has been sent between any SGTs.
AnswerC

The counters confirm both flow outcomes: for SGT 10 to SGT 20, the deny counter is zero while the permit counter has incremented, so that traffic is being permitted; for SGT 10 to SGT 30, the deny counter has incremented 500 times, proving that traffic is being denied. This is the only interpretation that is consistent with both observed counter values and explains the full policy behavior.

Why this answer

The output shows that for the source group (SGT) 10 to destination group (SGT) 20, packets sent and bytes sent are non-zero (1500 and 120000 respectively), while packets denied and bytes denied are zero. This indicates traffic is being permitted. For SGT 10 to SGT 30, packets sent and bytes sent are zero, but packets denied and bytes denied are non-zero (500 and 40000), indicating traffic is being denied.

Therefore, option C is correct.

Exam trap

The trap here is that candidates often misinterpret the 'Packets Sent' and 'Packets Denied' columns, assuming that non-zero values in one column imply the opposite action for the other, when in fact both columns are independent counters that must be read together to determine the actual policy outcome.

How to eliminate wrong answers

Option A is wrong because the counters show packets sent (1500) and bytes sent (120000) for SGT 10 to SGT 20, with zero denied packets, meaning traffic is permitted, not denied. Option B is wrong because the counters show zero packets sent and bytes sent for SGT 10 to SGT 30, but 500 packets denied and 40000 bytes denied, meaning traffic is denied, not permitted. Option D is wrong because the counters clearly show traffic has been sent between SGT 10 and SGT 20 (1500 packets), so traffic has been sent between some SGTs.

689
MCQhard

A company uses Cisco TrustSec in its campus network. Security policy requires that a user authenticated by 802.1X be assigned a Security Group Tag (SGT) based on the user's Active Directory group, and that the SGT be carried to downstream switches for enforcement. The access switch is configured for 802.1X with Cisco ISE. Which combination of features must be enabled to meet the requirement?

A.SGT assignment via ISE and enabling MACsec on all inter-switch links
B.SGT assignment via ISE and enabling 802.1X on all downstream switch ports
C.SGT assignment via ISE and configuring dynamic ARP inspection on all switches
D.SGT assignment via ISE authorization policy and inline tagging or SXP propagation on the switch uplinks
AnswerD

ISE can return an SGT in the authorization result based on Active Directory group membership, and the access switch applies it to the session. To carry the tag to downstream devices, either inline tagging on the link or SXP propagation must be configured, enabling enforcement of group-based policy across the network.

Why this answer

Cisco TrustSec assigns SGTs through ISE authorization rules that can reference Active Directory group membership. For the tag to reach downstream switches, the network must propagate it using inline tagging on capable links or SXP where inline tagging is not supported. This enables consistent group-based enforcement across the campus.

Exam trap

The trap here is assuming that enabling 802.1X on additional ports or adding Layer 2 security features like DAI or MACsec will propagate the SGT, when propagation actually requires inline tagging or SXP.

690
MCQhard

A network designer is planning a Cisco SD-WAN solution. The customer requires that control plane and data plane traffic be separated, and that the control plane uses a protocol that provides secure, scalable, and resilient overlay topology. Which component of Cisco SD-WAN architecture should the designer use for the control plane?

A.vBond
B.vManage
C.vEdge
D.vSmart
AnswerD

vSmart controllers form the control plane of Cisco SD-WAN. They run the Overlay Management Protocol (OMP) to distribute routing, policy, and key information to vEdge routers, establishing a secure and scalable overlay. They maintain the control plane relationships and enforce centralized policies, separating control from data plane.

Why this answer

vSmart controllers provide the control plane in Cisco SD-WAN, using OMP to distribute routing and policy information to vEdge routers. They establish secure control connections and maintain the overlay topology, separate from the data plane. vManage handles management, vBond handles orchestration, and vEdge routers forward data.

Exam trap

The trap here is assuming vBond is the control plane because it handles initial authentication, but vBond is only the orchestrator, while vSmart provides the actual control plane.

691
MCQmedium

A network engineer is configuring a Cisco IOS router to export NetFlow data to a collector. The engineer wants to ensure that only ingress traffic on GigabitEthernet0/0 is monitored and that the NetFlow cache is optimized for high traffic volumes. Which configuration step is required to enable NetFlow on the interface?

A.ip route-cache flow
B.ip flow-export version 9
C.ip flow ingress
D.ip flow-export destination
AnswerC

The 'ip flow ingress' command enables NetFlow accounting for ingress traffic on the interface. It is the correct command to start capturing flow data for incoming packets. This is a fundamental step in configuring NetFlow on a Cisco IOS router, and it must be applied to the interface that will be monitored.

Why this answer

To enable NetFlow on a specific interface for ingress traffic, the 'ip flow ingress' command must be configured in interface configuration mode. This command activates NetFlow accounting for packets entering the interface, allowing the router to collect flow statistics. The global export commands only define where and how to send the data, but the interface command is what starts the capture.

Exam trap

The trap here is thinking that global NetFlow export commands automatically enable flow capture on interfaces, but interface-level configuration is mandatory.

692
MCQhard

An engineer configures VXLAN EVPN on a Nexus 9000 switch. The configuration is shown. The switch does not advertise any EVPN routes for VNI 10100. Which configuration change is required to fix this issue?

A.Configure "evpn" and "vni 10100 l2" under the BGP address-family l2vpn evpn.
B.Remove the mcast-group from the NVE member, because EVPN uses BGP for control plane.
C.Change the source-interface to a physical interface.
D.Add an IP address to the VLAN 100 interface in the default VRF.
AnswerA

The VNI must be explicitly activated under BGP EVPN. Without the 'vni 10100 l2' configuration inside address-family l2vpn evpn, BGP has no awareness of this L2 VNI and will not originate or import the type-2 (MAC/IP) and type-3 (inclusive multicast) routes needed for remote VTEPs to learn MAC addresses. Adding that command, along with 'evpn' as the address family, is what makes the control plane advertise the VNI. This is the missing configuration causing the issue.

Why this answer

For VXLAN EVPN on a Nexus 9000, the BGP address-family l2vpn evpn must explicitly contain the 'evpn' keyword and the 'vni 10100 l2' command to advertise Layer 2 VNI routes. Without this configuration, BGP does not know to inject the VNI's MAC/VTEP information into the EVPN route table, so no EVPN routes are advertised for VNI 10100.

Exam trap

Cisco often tests the distinction between the NVE interface configuration (which enables VXLAN encapsulation) and the BGP EVPN address-family configuration (which enables route advertisement), leading candidates to mistakenly focus on NVE or interface settings instead of the missing BGP VNI injection.

How to eliminate wrong answers

Option B is wrong because removing the mcast-group from the NVE member would break BUM traffic replication in multicast mode, but the issue is about EVPN route advertisement, not data-plane flooding; EVPN uses BGP for control plane, but the mcast-group is still needed for multicast-based BUM traffic. Option C is wrong because changing the source-interface to a physical interface is not required; a loopback interface is the recommended source for NVE to ensure stability and is not the cause of missing EVPN routes. Option D is wrong because adding an IP address to VLAN 100 interface in the default VRF is unrelated to EVPN route advertisement; VLAN 100 is the Layer 2 VLAN associated with VNI 10100, but its SVI IP is only needed for Layer 3 VNI or gateway functionality, not for advertising EVPN routes.

693
MCQhard

A network security engineer is deploying MACsec on a Cisco Catalyst 9000 switch. The switch is connected to a Cisco IP phone that does not support MACsec, and a PC is connected to the phone. The engineer wants to encrypt traffic between the switch and the phone, but the phone does not support MACsec. What should the engineer do to secure the link?

A.Replace the phone with a MACsec-capable model or use a different encryption method such as IPsec for the traffic.
B.Use a MACsec-capable switch port and enable `macsec` with `fallback` to allow unencrypted traffic if the phone does not support it.
C.Configure the switch port to use MACsec for the PC traffic and leave the phone traffic unencrypted.
D.Enable MACsec on the switch port with `macsec` and configure the phone to use 802.1X with MAB.
AnswerA

Since the phone does not support MACsec, link-layer encryption cannot be established. The engineer must either upgrade to a MACsec-capable phone or use a higher-layer encryption method like IPsec, which can encrypt traffic end-to-end regardless of link-layer capabilities. This is the only viable way to secure the traffic.

Why this answer

MACsec is a link-layer encryption protocol that requires both endpoints to support it. If the IP phone does not support MACsec, the switch cannot encrypt traffic to the phone at Layer 2. The engineer must either replace the phone with a MACsec-capable model or use a higher-layer encryption method such as IPsec to secure the traffic.

Exam trap

The trap here is assuming that MACsec can be selectively applied or that it can fall back to clear text, when in reality it requires both endpoints to support it.

694
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor the health of wireless clients. The administrator notices that some clients are experiencing poor performance, but the Assurance dashboard shows them as 'Good'. Which action should the administrator take to troubleshoot the issue?

A.Verify that the wireless controller is registered with Cisco DNA Center.
B.Check the overall network health dashboard for any global alerts.
C.Restart the Cisco DNA Center Assurance service.
D.Review the client's detailed health metrics, including RSSI, SNR, and retry rates.
AnswerD

Cisco DNA Center Assurance provides detailed client health metrics beyond the overall health score. By drilling down into a specific client's details, you can view RSSI, SNR, retry rates, and other RF parameters that may indicate poor performance despite an overall 'Good' status. This granular data helps identify the root cause of the issue.

Why this answer

Cisco DNA Center Assurance client health scores are composite metrics that may not reflect all RF issues. When clients report poor performance but show 'Good' health, the administrator should examine detailed client metrics such as RSSI, SNR, and retry rates to uncover hidden problems. The other options are either too broad or unnecessary.

Exam trap

The trap here is assuming that the overall client health score in Assurance is sufficient to diagnose all performance issues, when in fact detailed metrics are needed.

695
MCQeasy

A network engineer is designing a QoS policy for a Cisco router that connects to an MPLS VPN. The service provider expects all traffic to be marked with IP Precedence values. The engineer wants to ensure that voice traffic (DSCP EF) is mapped to IP Precedence 5. What configuration is required on the router to perform this mapping?

A.Configure a policy-map that sets the IP precedence to 5 using 'set ip precedence 5'.
B.Configure a policy-map that sets the DSCP to EF, and the router will automatically set IP precedence to 5.
C.Use the 'qos map dscp-ip-precedence' command to create a mapping table.
D.The router will automatically map DSCP EF to IP precedence 5 without any configuration.
AnswerA

The MQC policy-map action `set ip precedence 5` explicitly writes the 3-bit IP precedence value in the Type of Service byte. Precedence 5 is the standard value associated with the EF PHB (DSCP 46), so this command satisfies the marking requirement directly. In Cisco IOS/IOS-XE, this is the correct method when the requirement is specifically to mark IP precedence, and attaching the policy map to the interface (or globally) makes the classification and marking take effect.

Why this answer

The 'set ip precedence 5' command in a policy-map explicitly marks the IP Precedence field to 5, which corresponds to the same value as DSCP EF (46) in the IP header. This ensures that voice traffic is marked with IP Precedence 5 as required by the service provider, regardless of any existing DSCP markings.

Exam trap

Cisco often tests the misconception that DSCP and IP Precedence are automatically synchronized or that a single command like 'set dscp ef' will implicitly set the IP Precedence field, when in fact they are independent markings that require separate configuration.

How to eliminate wrong answers

Option B is wrong because setting DSCP to EF does not automatically set IP Precedence to 5; the router treats DSCP and IP Precedence as separate fields, and explicit configuration is needed to map between them. Option C is wrong because the 'qos map dscp-ip-precedence' command does not exist; the correct command for creating a mapping table is 'qos map dscp-ip-precedence' is not a valid Cisco IOS command, and such mappings are typically done via policy-map actions. Option D is wrong because the router does not automatically map DSCP EF to IP Precedence 5; without explicit configuration, the IP Precedence field remains unchanged or is set based on default behavior, which may not meet the service provider's requirement.

696
Drag & Dropmedium

Drag and drop the steps of VRF selection using policy-based routing into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with creating an extended ACL to match the traffic (A), then defining a route-map using the match ip and set vrf commands (B), applying the route-map to the incoming interface (C), after which the router evaluates the policy for each packet (D), and finally matching packets are forwarded into the specified VRF (E). Configuration steps must precede operational steps.

697
MCQeasy

Which of the following is a valid transport protocol for model-driven telemetry receivers on Cisco IOS-XE?

A.HTTP
B.gRPC
C.FTP
D.SNMP
AnswerB

gRPC is a valid transport for model-driven telemetry on Cisco IOS-XE, carrying dial-out subscriptions over HTTP/2 with protobuf-encoded data. It satisfies the stem's receiver requirement, unlike NETCONF or RESTCONF, which are configuration and retrieval protocols rather than telemetry transports.

Why this answer

gRPC is a supported transport protocol for telemetry receivers, along with gNMI and others.

698
MCQmedium

A network engineer is troubleshooting a Layer 2 loop that occurred in a network using Rapid PVST+. The network has three switches: SW1 (root), SW2, and SW3. The engineer examines the topology and finds that SW2 and SW3 are connected via a link that is not supposed to be there. The engineer suspects that an unauthorized switch was connected to the network, causing the loop. The engineer wants to prevent such loops in the future by configuring a feature that will disable any port that receives a BPDU from an unauthorized switch. Which feature should the engineer configure on the access ports?

A.Enable BPDU Guard on all access ports.
B.Enable Loop Guard on all access ports.
C.Enable Root Guard on all access ports.
D.Enable UDLD on all access ports.
AnswerA

BPDU Guard is the correct choice because it actively shuts down the port by placing it into an errdisable state whenever any BPDU is received on an access port. Since access ports should never receive BPDUs from an end host, a received BPDU indicates an unauthorized switch attempting to participate in spanning tree, and BPDU Guard immediately blocks that port to preserve the intended STP topology and prevent potential loops.

Why this answer

BPDU Guard is the correct feature because it immediately error-disables a port when a BPDU is received, preventing loops from unauthorized switches. Since the engineer wants to protect access ports from receiving BPDUs (which should never occur on a properly configured access port), BPDU Guard directly addresses the scenario of an unauthorized switch being connected and sending BPDUs.

Exam trap

Cisco often tests the distinction between BPDU Guard and Root Guard, where candidates mistakenly choose Root Guard because they think it protects against unauthorized switches, but Root Guard only prevents a port from becoming root, not from receiving BPDUs and causing loops.

How to eliminate wrong answers

Option B is wrong because Loop Guard prevents alternate or root ports from becoming designated in the absence of BPDUs, but it does not disable a port upon receiving an unexpected BPDU; it only prevents loops caused by unidirectional link failures. Option C is wrong because Root Guard prevents a port from becoming a root port by placing it into a root-inconsistent state if a superior BPDU is received, but it does not disable the port; it still allows BPDU reception and does not block all BPDUs from unauthorized switches. Option D is wrong because UDLD detects and disables ports experiencing unidirectional links, but it does not react to BPDU reception; it uses its own keepalive mechanism and is unrelated to preventing loops from unauthorized switches sending BPDUs.

699
MCQmedium

A network administrator is using Cisco DNA Center Assurance to monitor a campus network. The administrator wants to receive alerts when the onboarding time for wireless clients exceeds a defined threshold. Which Cisco DNA Center Assurance feature should be configured to accomplish this?

A.Assurance Issues
B.Assurance Health Rules
C.Network Health Dashboard
D.Issues and Alerts
AnswerB

Assurance Health Rules (also known as Health Rules) in Cisco DNA Center allow administrators to define custom thresholds and conditions for various health metrics, including onboarding time. By configuring a health rule, the administrator can specify a threshold and have Cisco DNA Center generate an alert when that threshold is exceeded. This is the correct feature for proactive, threshold-based alerting.

Why this answer

Cisco DNA Center Assurance Health Rules enable the creation of custom thresholds for a wide range of metrics, including client onboarding time. When the defined threshold is breached, an alert is triggered. Other dashboards and issue lists are either passive or based on predefined logic and do not support user-defined thresholds for this purpose.

Exam trap

The trap here is confusing the monitoring dashboards and predefined issue detection with the configurable Health Rules that actually allow custom thresholds and alert generation.

700
MCQmedium

An engineer is troubleshooting a problem where a host in VLAN 20 cannot communicate with a host in VLAN 30, even though both are connected to the same access switch. The access switch is configured with VLANs 20 and 30, and the uplink to the distribution switch is a trunk that allows both VLANs. The distribution switch has SVIs for both VLANs and IP routing is enabled. The engineer verifies that the trunk is up and both VLANs are allowed. What is the most likely cause of the communication failure?

A.The hosts are not configured with the correct default gateway pointing to the SVI on the distribution switch.
B.The trunk is not allowing VLAN 20 or VLAN 30.
C.Spanning Tree Protocol is blocking the SVI interfaces.
D.The native VLAN mismatch on the trunk is causing the issue.
AnswerA

The hosts cannot reach the SVI because their default gateway is either absent or set to an incorrect IP address. For inter-VLAN communication, each host must send Layer 3 packets to its VLAN's SVI IP, which then routes them to other VLANs. If the gateway points to the wrong address (e.g., another host or a nonexistent IP), frames are sent to the wrong destination and never reach the distribution switch's routing engine.

Why this answer

Hosts in different VLANs must communicate through a Layer 3 device. The correct default gateway for each host should be the IP address of the SVI on the distribution switch for its respective VLAN. If the hosts are configured with an incorrect or no default gateway, traffic cannot be routed between VLAN 20 and VLAN 30, even though the trunk and SVIs are properly configured.

Exam trap

Cisco often tests the misconception that a properly configured trunk and SVIs alone guarantee inter-VLAN communication, when in fact the hosts must have the correct default gateway configured to reach the SVI.

How to eliminate wrong answers

Option B is wrong because the engineer already verified that the trunk is up and both VLANs are allowed, so a trunk misconfiguration is not the cause. Option C is wrong because Spanning Tree Protocol (STP) operates on Layer 2 interfaces and does not block SVI interfaces; SVIs are virtual Layer 3 interfaces and are not subject to STP blocking. Option D is wrong because a native VLAN mismatch on a trunk would cause issues for untagged traffic (typically management or CDP), but it would not prevent routed communication between hosts in different VLANs if the trunk is up and both VLANs are allowed.

701
MCQmedium

A network engineer is configuring a Cisco Nexus 9000 switch as a VTEP in a VXLAN EVPN fabric. The engineer wants to ensure that the switch uses the loopback0 interface as the source for VXLAN tunnels and that it can dynamically learn remote VTEPs via BGP EVPN. Which command set is required under the NVE interface?

A.interface nve1; source-interface loopback0; vni 10000; ip address 10.0.0.1/32
B.interface nve1; source-interface loopback0; no shutdown
C.interface nve1; source-interface loopback0; peer-ip 10.0.0.2
D.interface nve1; source-interface loopback0; host-reachability protocol bgp
AnswerD

Under the NVE interface, source-interface loopback0 sets the VTEP IP address, and host-reachability protocol bgp enables BGP EVPN for remote VTEP and MAC learning. This combination is essential for a functioning VTEP in an EVPN fabric. Without the source-interface, the NVE would not know which IP to use for tunnels, and without host-reachability, it would rely on data-plane learning.

Why this answer

For a Cisco Nexus 9000 VTEP in an EVPN fabric, the NVE interface must be configured with source-interface loopback0 to set the tunnel source IP and host-reachability protocol bgp to enable dynamic learning of remote VTEPs and MAC addresses via BGP EVPN. Other commands like no shutdown are necessary but insufficient, and static peer-ip or IP address under NVE is incorrect.

Exam trap

The trap here is forgetting the host-reachability protocol bgp command, which is often overlooked when focusing only on the source-interface configuration.

702
Multi-Selectmedium

Which two statements about NFV MANO (Management and Orchestration) are true? (Choose two.)

Select 2 answers
A.The VNF Manager (VNFM) is responsible for the lifecycle management of VNF instances, including instantiation and scaling.
B.The NFV Orchestrator (NFVO) coordinates the allocation of resources across multiple VNFs and the NFVI.
C.The Virtualized Infrastructure Manager (VIM) manages the lifecycle of VNFs and their connectivity.
D.The VIM is responsible for service chaining and policy enforcement within the NFV environment.
E.The VNFM is responsible for managing the physical hardware resources in the NFVI.
AnswersA, B

The VNFM handles lifecycle operations for virtual network functions, covering instantiation, scaling, updating and termination, as ETSI MANO defines. This satisfies the stem's requirement for a true MANO statement, since lifecycle management of VNF instances falls squarely within the VNFM's orchestration role rather than the NFVO or VIM.

Why this answer

Option A is correct because the VNF Manager (VNFM) in the ETSI NFV MANO architecture owns the lifecycle of VNF instances, performing operations such as instantiation, configuration, scaling, healing, and termination of VNFs. Option B is correct because the NFV Orchestrator (NFVO) performs resource orchestration and network service orchestration, coordinating resource allocation across multiple VNFs and the NFVI, and managing Network Service (NS) lifecycle. Option C is incorrect because VNF lifecycle management belongs to the VNFM, while the Virtualized Infrastructure Manager (VIM) manages the NFVI compute, storage, and network resources (e.g., via OpenStack) and their virtualization, not VNF lifecycles.

Option D is incorrect because service chaining and policy enforcement are handled by the NFVO/VNFM and the NFVI forwarding functions (e.g., via SFC/OpenFlow), not by the VIM, which controls the virtualized infrastructure resources. Option E is incorrect because the VNFM manages VNF software instances, not physical hardware; physical and virtualized infrastructure resources in the NFVI are managed by the VIM.

Exam trap

The trap is conflating VIM responsibilities with VNFM/NFVO duties — candidates assume the VIM does 'everything infrastructure-related,' but ETSI strictly separates VNF lifecycle (VNFM) from NFVI resource management (VIM).

703
MCQhard

A network engineer runs the following command on Router R8: R8# show ip pim neighbor vrf CUSTOMER-F Neighbor Interface Uptime/Expires Ver DR 10.0.3.2 GigabitEthernet0/0.700 02:00:00/00:01:30 v2 1/ DR 10.0.4.2 GigabitEthernet0/0.800 01:30:00/00:01:45 v2 0/ NDR (BDR) Based on this output, what can be concluded?

A.PIM is not configured for VRF CUSTOMER-F
B.The DR is 10.0.4.2
C.PIM is enabled in VRF CUSTOMER-F with a DR and BDR
D.Both neighbors are using PIM version 1
AnswerC

The output explicitly shows two PIM neighbors within VRF CUSTOMER-F, and the role column designates 10.0.3.2 as DR and 10.0.4.2 as BDR, confirming that PIM is enabled and operating normally on this VRF. The DR/BDR election is functional, which verifies the multicast routing control plane is active. This matches the expected behavior for a properly configured VRF with PIM.

Why this answer

The output shows two PIM neighbors (10.0.3.2 and 10.0.4.2) with their respective interfaces, uptimes, and DR/BDR roles. The presence of a DR (Designated Router) and BDR (Backup Designated Router) indicates that PIM is enabled and operating in VRF CUSTOMER-F, with the DR being 10.0.3.2 (as shown by '1/ DR') and the BDR being 10.0.4.2 (as shown by '0/ NDR (BDR)'). Therefore, option C is correct.

Exam trap

Cisco often tests the misinterpretation of the DR/BDR column, where candidates mistakenly assume the neighbor with 'BDR' is the DR, or that PIM is not running when neighbors are present.

How to eliminate wrong answers

Option A is wrong because the output clearly shows PIM neighbors with DR/BDR roles, confirming that PIM is configured and active in VRF CUSTOMER-F. Option B is wrong because the DR is 10.0.3.2 (indicated by '1/ DR'), not 10.0.4.2, which is the BDR (Backup Designated Router). Option D is wrong because both neighbors are using PIM version 2 (as shown by 'v2' in the Ver column), not version 1.

704
MCQhard

A network engineer is analyzing network traffic using Cisco IOS Embedded Packet Capture (EPC) on a Cisco ISR router. The engineer wants to capture only TCP packets with a source port of 80 and a destination IP address of 10.1.1.1. Which EPC configuration is required to achieve this?

A.Define a class map that matches tcp source eq 80 and destination host 10.1.1.1, then apply it to the capture point.
B.Define an access list that permits tcp any eq 80 host 10.1.1.1, then reference it in the capture point with 'access-list'.
C.Define a flow record with match ipv4 source port 80 and destination address 10.1.1.1, then apply it to the capture point.
D.Define a capture buffer with 'filter' option specifying tcp port 80 and host 10.1.1.1.
AnswerB

EPC uses an access list to filter captured traffic. The access list 'permit tcp any eq 80 host 10.1.1.1' matches TCP packets with source port 80 and destination IP 10.1.1.1. This access list is then applied to the capture point using the 'access-list' keyword. This is the correct method to filter specific traffic in EPC, as it leverages standard ACL syntax to define match criteria.

Why this answer

EPC uses an access list to filter packets. The access list 'permit tcp any eq 80 host 10.1.1.1' matches the required traffic, and it is applied to the capture point with the 'access-list' keyword. Other options involve features like class maps or flow records that are not used by EPC for filtering.

The capture buffer only defines storage, not filtering.

Exam trap

The trap here is confusing EPC filtering with QoS or NetFlow mechanisms, such as class maps or flow records, which are not applicable to EPC.

705
MCQhard

An engineer is implementing a VXLAN overlay network using Cisco Nexus switches. The engineer needs to ensure that the VXLAN tunnel endpoint (VTEP) can dynamically learn the mapping of remote VTEP IP addresses to MAC addresses. Which protocol should be used to achieve this dynamic learning?

A.OSPF
B.IS-IS
C.MP-BGP EVPN
D.PIM sparse mode
AnswerC

MP-BGP EVPN is a control plane protocol that allows VTEPs to exchange MAC address and IP address reachability information. It provides a scalable way to dynamically learn remote VTEP mappings, eliminating the need for flood-and-learn. In a VXLAN EVPN setup, MP-BGP EVPN is used to distribute MAC/IP bindings, enabling efficient and scalable overlay networks. This is the correct protocol for dynamic learning.

Why this answer

MP-BGP EVPN is the control plane protocol used in VXLAN overlays to dynamically exchange MAC address and IP address reachability information between VTEPs. It replaces flood-and-learn with a scalable, efficient control plane, enabling optimal forwarding and reducing flooding. This is the correct protocol for dynamic VTEP mapping learning.

Exam trap

The trap here is confusing underlay routing protocols like OSPF or IS-IS with overlay control plane protocols, which are responsible for MAC address learning in VXLAN EVPN.

706
Drag & Dropmedium

Drag and drop the steps of Unicast Reverse Path Forwarding (uRPF) check process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

uRPF first receives a packet on an interface, then looks up the source IP in the routing table, verifies that the incoming interface matches the best reverse path, and if it matches, forwards the packet; otherwise, it drops the packet.

707
Multi-Selectmedium

Which TWO statements are true about IP SLA? (Choose two.)

Select 2 answers
A.IP SLA is only supported on ASR routers.
B.IP SLA can be used with tracking objects to trigger route changes.
C.IP SLA can measure jitter between two devices.
D.IP SLA uses actual user traffic for measurements.
E.IP SLA can only measure round-trip time, not one-way delay.
AnswersB, C

IP SLA operations can be tied to Cisco tracking objects using the 'track' command, where the tracked object state changes based on probe reachability or response-time thresholds. When the probe fails consecutive times, the tracking object transitions to 'down', which can trigger a floating static route, policy-based routing, or other route manipulation to redirect traffic. This creates a dynamic failover or convergence mechanism driven by synthetic traffic rather than solely by physical link state.

Why this answer

IP SLA can be combined with tracking objects and the 'track' command to influence routing decisions. When an IP SLA probe fails or falls below a threshold, the tracked object changes state, which can trigger a route change (e.g., via a static route with a higher administrative distance or a PBR policy). This allows the network to react to network performance or reachability issues automatically.

Exam trap

Cisco often tests the misconception that IP SLA uses real user traffic (Option D) or that it is limited to RTT (Option E), when in fact it generates synthetic probes and can measure one-way delay with proper time synchronization.

708
Matchingmedium

Drag and drop each RADIUS attribute name on the left to its matching attribute number on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

1

4

6

8

22

Why these pairings

RADIUS attribute numbers are standardized: User-Name=1, NAS-IP-Address=4, Service-Type=6, Framed-IP-Address=8, and Framed-Route=22.

709
Drag & Dropmedium

Drag and drop the steps of deploying a CoPP policy on a Cisco IOS-XE router into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Deploying CoPP requires first defining ACLs to classify traffic, then creating class maps, then a policy map, then applying it to the control plane, and finally verifying the policy.

710
MCQeasy

A network engineer is using Cisco DNA Center to monitor network health. The Assurance dashboard shows that a particular access switch has a high CPU utilization issue. The engineer wants to investigate the root cause using DNA Center's built-in tools. Which feature should the engineer use to analyze the switch's CPU utilization over time?

A.Use the 'Trends' feature in Assurance to view CPU utilization over time.
B.Use the 'Command Runner' to execute 'show process cpu' on the switch.
C.Use the 'Path Trace' tool to analyze traffic paths.
D.Use the 'Software Image Management' to check for software bugs.
AnswerA

The Trends feature in Assurance plots historical telemetry, letting the engineer chart the access switch's CPU utilisation over time and correlate the spike with its root cause, which the real-time health dashboard alone cannot show.

Why this answer

Cisco DNA Center Assurance includes a 'Trends' feature that provides historical time-series visualization of device health metrics, including CPU utilization, memory, and interface statistics. This is the purpose-built tool for analyzing how a metric has changed over time, which is exactly what the engineer needs to investigate the high-CPU condition. It correlates the metric with other Assurance data (client, application, network) to help identify root cause.

Exam trap

The trap is confusing Assurance's analytical/trending tools with on-demand CLI tools like Command Runner — the exam expects you to know that historical metric analysis lives in Trends, not in ad-hoc command execution.

How to eliminate wrong answers

Option B is wrong because Command Runner executes CLI commands on demand and returns a point-in-time snapshot — it does not provide historical trending or time-series analysis. Option C is wrong because Path Trace is a live traffic-path analysis tool for tracing packet flow between endpoints, not for examining device resource metrics. Option D is wrong because Software Image Management handles image repository, upgrade scheduling, and compliance — it does not analyze CPU utilization.

711
MCQhard

A network engineer is analyzing traffic flows on a Cisco Nexus switch and needs to collect NetFlow data. The engineer wants to export flow records to an external collector at 192.168.100.50 on port 2055. Which configuration step is required to enable NetFlow export?

A.Use the 'netflow export destination 192.168.100.50 2055' command in global configuration mode and enable NetFlow on the management interface.
B.Configure a flow exporter with the destination 192.168.100.50 and transport UDP 2055, then apply a flow monitor to the interface.
C.Enable NetFlow on the interface with the 'ip flow ingress' command and specify the collector with 'ip flow-export destination 192.168.100.50 2055'.
D.Configure a NetFlow collector group with the destination 192.168.100.50 and port 2055, then enable NetFlow on the VLAN interface.
AnswerB

On Cisco Nexus switches, NetFlow is configured using flow exporters, flow records, and flow monitors. The flow exporter defines the collector's IP address and UDP port. The flow monitor references the exporter and record, and is applied to an interface. This enables the export of flow data to the specified collector.

Why this answer

On Cisco Nexus switches, NetFlow export requires defining a flow exporter that specifies the collector's IP address and UDP port. A flow record defines the match and collect fields, and a flow monitor ties them together. The flow monitor is then applied to the interface.

This modular approach is different from traditional IOS routers.

Exam trap

The trap here is applying IOS NetFlow commands like 'ip flow ingress' to a Nexus switch, which uses NX-OS and a different configuration model.

712
Multi-Selectmedium

Which two statements about PIM sparse mode are true? (Choose two.)

Select 2 answers
A.PIM sparse mode uses an explicit join model to receive multicast traffic.
B.PIM sparse mode routers always use the shortest path tree (SPT) immediately after the first packet is received.
C.PIM sparse mode builds a shared tree rooted at the rendezvous point (RP).
D.PIM sparse mode uses a flood-and-prune mechanism to distribute multicast traffic.
E.PIM sparse mode requires the use of a bootstrap router (BSR) to operate.
AnswersA, C

Receivers must explicitly send PIM joins toward the rendezvous point to be added to the distribution tree; traffic is only delivered where requested. This explicit join model is the defining mechanism of sparse mode, contrasting with dense mode's flood-and-prune approach.

Why this answer

Option A is correct because PIM-SM is fundamentally an explicit-join protocol: receivers send IGMP joins, the last-hop router sends a PIM (*,G) Join toward the RP, and traffic only flows where joins have been explicitly requested, unlike dense mode's implicit-join/push model. Option C is correct because PIM-SM first builds a shared distribution tree rooted at the rendezvous point (RP), known as the RPT or (*,G) tree, which all sources and receivers initially use before any switch to a source-specific SPT. Option B is wrong because after the first packet arrives via the shared tree, the last-hop router may switch to the shortest path tree only if the SPT threshold is met (default is typically 0, but it is not automatic or immediate in all cases, and the shared tree is used first).

Option D is wrong because flood-and-prune is the mechanism used by PIM dense mode, not sparse mode. Option E is wrong because BSR is only one of several ways to distribute RP information (static RP, Auto-RP, and BSR are all valid); PIM-SM can operate with a statically configured RP and does not require BSR.

Exam trap

350-401 often tests the difference between PIM sparse and dense modes, so candidates must remember that sparse mode uses explicit joins and a shared tree, while dense mode uses flood-and-prune.

713
Multi-Selecthard

A network architect is evaluating Cisco SD-Access for a large campus. The architect must ensure the fabric supports policy enforcement based on user identity and group membership, and that the fabric can scale to thousands of endpoints without flooding the underlay. Which two statements are correct about how SD-Access achieves these goals? (Choose two.)

Select 2 answers
A.The fabric uses a single shared bridge domain across all edge nodes to avoid VLAN proliferation.
B.The underlay uses VXLAN flooding to propagate endpoint reachability to all fabric edge nodes.
C.The LISP control plane in SD-Access registers endpoint EID-to-RLOC mappings so fabric edge nodes can resolve destinations without flooding the underlay.
D.Cisco TrustSec security group tags are carried in the VXLAN Group Policy Option header so fabric edge nodes can enforce group-based ACLs.
E.Fabric edge nodes use OSPF to advertise endpoint host routes into the underlay for reachability.
AnswersC, D

In SD-Access, the LISP map server and map resolver track endpoint identifier to routing locator mappings. Fabric edge nodes register local endpoints and query the map server for remote ones, which provides a control-plane lookup instead of data-plane flooding. This is how the fabric scales to thousands of endpoints while avoiding broadcast or unknown unicast flooding across the underlay.

Why this answer

SD-Access scales by moving endpoint reachability into the LISP control plane, where EID-to-RLOC mappings are registered and resolved, avoiding underlay flooding. Policy is enforced with Cisco TrustSec group tags carried in the VXLAN Group Policy Option header, enabling group-based ACLs at fabric edge nodes. The underlay is a routed IS-IS fabric that does not carry endpoint host routes or rely on VXLAN flooding, and the overlay does not require a single stretched bridge domain.

Exam trap

The trap here is assuming the SD-Access underlay floods endpoint information or carries host routes, when endpoint reachability is actually resolved by LISP in the overlay.

714
MCQmedium

Given the following SNMPv3 configuration on a Cisco IOS-XE router: snmp-server group ADMIN v3 priv write ADMINVIEW snmp-server user admin ADMIN v3 auth sha cisco123 priv aes 128 cisco456 snmp-server view ADMINVIEW iso included What is missing or incorrect in this configuration?

A.The SNMPv3 user 'admin' must also specify an engine ID for the router.
B.The view 'ADMINVIEW' includes the entire ISO tree, which might be too permissive for a restricted write view.
C.The privacy password 'cisco456' must be at least 8 characters long.
D.The group 'ADMIN' must be configured with a read view to allow SNMP get operations.
AnswerB

The view command 'iso included' in Cisco IOS SNMP configuration includes the entire ISO OID subtree (1.3.6.1), which covers all MIB objects accessible via SNMP. For a write view intended to be restricted, this is overly permissive because it grants write access to virtually any managed object, including critical system parameters. This defeats the purpose of VACM (View-Based Access Control Model) restriction, making it a security flaw. Hence, the configuration should use a more specific subtree, such as 'system' or 'interfaces', to limit the write scope.

Why this answer

The view 'ADMINVIEW' is configured with 'iso included', which includes the entire ISO OID tree. This grants write access to all MIB objects, which is overly permissive for a restricted write view. In SNMPv3, a write view should be limited to specific OIDs or subtrees to enforce least privilege, and including the entire ISO tree violates that principle.

Option D is incorrect because a read view is not required if the group is only intended for write operations. The configuration as shown only specifies a write view, which is sufficient for SNMP set operations. Adding a read view is optional and not a mandatory missing piece.

Exam trap

Cisco often tests the misconception that a write view must be paired with a read view, or that engine IDs are always required for user creation, but the real trap here is overlooking that including the entire ISO tree makes the write view too permissive for a restricted administrative group.

How to eliminate wrong answers

Option A is wrong because the SNMPv3 user 'admin' does not need to specify an engine ID; the router automatically uses its local engine ID when the user is created without one, and this is valid for local SNMP operations. Option C is wrong because the privacy password 'cisco456' is 9 characters long, which meets the minimum length requirement of 8 characters for SNMPv3 passwords. Option D is wrong because the group 'ADMIN' is configured with a write view only, which is valid; a read view is not mandatory for SNMPv3 groups, and the configuration allows write operations without requiring read access.

715
MCQeasy

A network administrator at a small company wants to prevent users from plugging unauthorized switches into wall jacks and creating loops or bypassing security controls. The administrator decides to implement BPDU Guard on all access ports on a Cisco Catalyst switch. Which statement accurately describes the behavior of BPDU Guard when configured on an access port?

A.It filters BPDUs from being forwarded out of the port while allowing the port to remain active.
B.It converts the access port into a trunk port when BPDUs are detected to allow proper spanning tree convergence.
C.It places the port into err-disabled state if a BPDU is received on the port.
D.It sends a syslog message and drops only the offending BPDU while keeping the port operational.
AnswerC

BPDU Guard is designed to protect access ports from receiving BPDUs. When a BPDU is detected on a port with BPDU Guard enabled, the switch immediately places that port into err-disabled state, preventing the unauthorized device from participating in spanning tree and potentially causing loops or topology changes.

Why this answer

BPDU Guard protects access ports by err-disabling them when any BPDU is received. This prevents unauthorized switches from being connected and potentially disrupting the spanning tree topology. It is commonly deployed alongside PortFast on access ports to ensure that end-user devices cannot participate in STP.

Exam trap

The trap here is confusing BPDU Guard with BPDU Filter, where BPDU Filter suppresses BPDUs while BPDU Guard disables the port upon receiving one.

716
MCQeasy

A network engineer is configuring a new switch that will be used as an access layer switch. The switch connects to two distribution switches via trunk links. The engineer wants to ensure that the access switch does not become the root bridge for any VLAN. The engineer also wants to provide redundancy so that if one uplink fails, the other uplink takes over quickly. The engineer is using Rapid PVST+. What configuration should the engineer apply on the access switch?

A.Configure 'spanning-tree vlan vlan-list priority 61440' on the access switch.
B.Configure 'spanning-tree vlan vlan-list priority 0' on the access switch.
C.Enable UplinkFast on the access switch to provide fast failover.
D.Enable PortFast on the trunk ports to speed up convergence.
AnswerA

Setting the switch's spanning-tree priority to 61440 (the highest numerical value) ensures its bridge ID will never be preferred over a legitimate root, because the root election down-selects the lowest bridge priority. Since Rapid PVST+ (802.1w) is already active, link failures are recovered through explicit proposal/agreement handshakes, eliminating the need for any extra convergence mechanism. This is the recommended way to pin the root on a distribution switch while making access switches incapable of becoming root even after a topology change.

Why this answer

Setting the spanning-tree priority to 61440 (which is 0xF000 in hex) makes the switch a very unlikely root bridge candidate. In Rapid PVST+, the bridge priority is a 4-bit value (0-15) multiplied by 4096, so 61440 corresponds to priority 15 — the highest possible value. This ensures the access switch will never become the root bridge for any VLAN, while Rapid PVST+ provides fast failover (sub-second convergence) via its alternate/backup port mechanism without needing UplinkFast.

Exam trap

Cisco often tests the misconception that UplinkFast is needed with Rapid PVST+ for fast failover, but Rapid PVST+ already includes its own fast convergence (based on the 802.1w standard), making UplinkFast obsolete.

How to eliminate wrong answers

Option B is wrong because setting priority 0 makes the switch the most likely root bridge candidate, which directly contradicts the requirement to never become root. Option C is wrong because UplinkFast is a legacy Cisco proprietary feature for 802.1D STP; Rapid PVST+ already provides fast failover (typically 1-2 seconds) via its own convergence mechanism, making UplinkFast unnecessary and redundant. Option D is wrong because PortFast is designed for access ports connected to end hosts to bypass listening/learning states; applying it to trunk ports would disable STP on those links, risking loops and violating the requirement for redundancy with STP protection.

717
MCQeasy

A network engineer is configuring a Cisco Catalyst 9000 switch to support a virtual routing and forwarding (VRF) instance for a guest network. The engineer wants to ensure that traffic from the guest VRF cannot leak into the corporate VRF. Which configuration step is required to maintain isolation between VRFs?

A.Assign the guest VRF to a separate VLAN and configure inter-VLAN routing.
B.Configure a route target export and import policy to control route leaking.
C.Place the guest network interfaces into the guest VRF and do not configure any route leaking.
D.Enable VRF-aware routing and ensure no static routes point between VRFs.
AnswerC

VRF instances are isolated by default. By assigning interfaces to the guest VRF, traffic within that VRF is separate from the corporate VRF. As long as no route leaking (such as static routes or BGP route targets) is configured, the VRFs remain isolated. This is the correct and sufficient step to maintain isolation.

Why this answer

VRFs provide logical separation of routing tables. When you assign interfaces to a VRF, those interfaces use that VRF's routing table. By default, there is no communication between VRFs unless you explicitly configure route leaking, such as static routes with next-hop VRF or BGP route targets.

Therefore, placing the guest interfaces in the guest VRF and not configuring any route leaking ensures isolation. Other options either do not enforce isolation or are unnecessary.

Exam trap

The trap here is overcomplicating VRF isolation by thinking that route targets or inter-VLAN routing are needed, when simply placing interfaces in the VRF without route leaking is sufficient.

718
MCQhard

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against DoS attacks. The router has a management plane that includes SSH and SNMP, and a control plane that includes routing protocols like OSPF and BGP. The engineer wants to rate-limit traffic destined to the route processor while ensuring that management traffic is not dropped during high CPU load. Which CoPP configuration approach is most appropriate?

A.Configure separate classes for management traffic (SSH, SNMP) and control plane traffic (OSPF, BGP), and assign higher rate limits to management traffic.
B.Use a single class that matches all IP traffic and set a high rate limit to avoid dropping any packets.
C.Apply a single CoPP policy that classifies all traffic to the route processor and sets a low rate limit for all classes.
D.Configure CoPP only for routing protocols and rely on QoS for management traffic.
AnswerA

This is the best practice. By creating separate classes, the engineer can apply different rate limits. Management traffic should have a higher rate limit to ensure administrators can always access the device, while control plane protocols can have lower limits to protect the route processor. This granularity ensures that critical management access is not starved during an attack, and routing protocols are still protected but not at the expense of management access.

Why this answer

CoPP allows granular control over traffic destined to the route processor. By separating management and control plane traffic into different classes, the engineer can assign higher rate limits to management traffic to ensure administrative access is maintained, while still protecting the route processor from excessive control plane traffic. This approach balances security and availability, preventing both DoS attacks and administrator lockout.

Exam trap

The trap here is assuming that a single CoPP policy with a uniform rate limit is sufficient, overlooking the need to prioritize management traffic to prevent lockout during an attack.

719
MCQmedium

Given the following SD-WAN configuration on a Cisco IOS-XE router: router ospf 1 redistribute bgp 65000 subnets network 192.168.1.0 0.0.0.255 area 0 ! interface GigabitEthernet0/0/0 ip address 192.168.1.1 255.255.255.0 ip ospf network point-to-point ! Which statement is true?

A.The OSPF network type is point-to-point, so the hello interval defaults to 10 seconds on this interface.
B.The OSPF network type is point-to-point, so the dead interval defaults to 120 seconds.
C.The redistribution of BGP into OSPF will cause OSPF to advertise all BGP routes, including those learned via SD-WAN overlay.
D.The configuration is incomplete because OSPF requires a router-id to be manually configured.
AnswerA

On a point-to-point OSPF network type, Cisco's default hello interval is 10 seconds, identical to the default on broadcast networks. This is because both network types use the same timer defaults on Cisco IOS, and the dead interval is then calculated as 4 × 10 = 40 seconds. Since the option specifically addresses the hello interval, it is correct.

Why this answer

On a Cisco IOS-XE router, when the OSPF network type is set to point-to-point, the default hello interval is 10 seconds (not 30 seconds as on broadcast networks). The dead interval defaults to 40 seconds (four times the hello interval), not 120 seconds. This configuration is valid and does not require a manually configured router-id, as OSPF can dynamically select one.

The redistribution of BGP into OSPF only injects routes that are in the BGP table; it does not automatically include all SD-WAN overlay routes unless they are present in BGP.

Exam trap

Cisco often tests the default OSPF timer values for different network types, specifically tricking candidates into thinking point-to-point uses 30-second hello or 120-second dead intervals, which are actually defaults for NBMA networks.

How to eliminate wrong answers

Option B is wrong because the OSPF dead interval for a point-to-point network defaults to 40 seconds (4 × hello interval of 10 seconds), not 120 seconds. Option C is wrong because the 'redistribute bgp 65000 subnets' command only redistributes BGP routes that are in the BGP routing table; it does not automatically advertise all SD-WAN overlay routes unless they are learned via BGP and meet redistribution criteria (e.g., subnets keyword includes classless prefixes). Option D is wrong because OSPF does not require a manually configured router-id; if none is configured, OSPF automatically selects the highest IP address on a loopback interface or the highest IP address on any active physical interface.

720
Matchingmedium

Drag and drop each SD-Access fabric role on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Connects the SD-Access fabric to external Layer 2 or Layer 3 networks

Attaches wired endpoints to the fabric and enforces access policies

Hosts the LISP map-server and map-resolver functions

Manages wireless endpoints and integrates with the fabric edge

Provides wireless connectivity and tunnels client traffic to the fabric edge

Why these pairings

The fabric border node connects the fabric to external networks, the fabric edge node connects endpoints to the fabric, and the fabric control node manages LISP mapping and VXLAN tunnels.

721
MCQmedium

A network architect is designing a WAN with Cisco SD-WAN. The requirement is to ensure that traffic from a branch office to a critical SaaS application is prioritized and uses the best path based on real-time performance metrics. Which Cisco SD-WAN feature should be used to meet this requirement?

A.Cisco Umbrella
B.Quality of Service (QoS)
C.Direct Internet Access (DIA)
D.Application-Aware Routing
AnswerD

Application-Aware Routing (AAR) in Cisco SD-WAN uses real-time performance metrics such as latency, jitter, and packet loss to select the best path for specific applications. It can direct traffic based on SLA policies, ensuring critical SaaS applications get prioritized treatment. This feature meets the requirement by dynamically choosing the optimal path and enforcing QoS. Therefore, it is the correct answer.

Why this answer

Application-Aware Routing is the correct feature because it uses real-time performance metrics to select the best path for applications, ensuring critical SaaS traffic is prioritized and uses the optimal path. It integrates with QoS to enforce prioritization, meeting the requirement. Other features like DIA and QoS address different aspects but do not provide dynamic path selection based on performance.

Exam trap

The trap here is confusing QoS, which prioritizes traffic within a path, with Application-Aware Routing, which selects the path based on performance metrics.

722
MCQmedium

interface GigabitEthernet0/3 spanning-tree guard root end What is the effect of this configuration?

A.The port will error-disable if it receives a BPDU that would cause the switch to become a non-root bridge.
B.The port will block all BPDUs received from other switches.
C.The port will become the root port for the VLAN.
D.The port will ignore BPDUs from switches with lower bridge ID.
AnswerA

Root Guard is a protection mechanism enabled on designated ports of a switch that should remain the root bridge. If such a port receives a BPDU from another switch that advertises a lower bridge ID or better root path cost, that BPDU is 'superior' and would normally cause the local switch to surrender root status. Rather than accept it, Root Guard places the port into a root-inconsistent (blocking) state — often referred to as error-disabling the port — so the intended root remains authoritative. The port does not pass traffic until the invalid BPDUs stop and the STP topology stabilizes.

Why this answer

The `spanning-tree guard root` command enables Root Guard on the interface. Root Guard prevents the port from becoming a root port by error-disabling the port if it receives a superior BPDU (one that would cause the switch to become a non-root bridge). This protects the spanning-tree root bridge placement from being usurped by an unauthorized switch.

Exam trap

Cisco often tests the distinction between Root Guard and BPDU Guard: candidates confuse Root Guard (which error-disables upon receiving a superior BPDU) with BPDU Guard (which error-disables upon receiving any BPDU on a PortFast port), or mistakenly think Root Guard blocks or ignores BPDUs entirely.

How to eliminate wrong answers

Option B is wrong because Root Guard does not block all BPDUs; it only monitors for superior BPDUs and error-disables the port if one is received, while normal BPDU processing continues otherwise. Option C is wrong because Root Guard prevents the port from becoming a root port; it does not force the port to become the root port. Option D is wrong because Root Guard does not ignore BPDUs from switches with lower bridge ID; instead, it reacts to superior BPDUs (which typically come from switches with a lower bridge ID) by error-disabling the port.

723
Multi-Selecthard

Which three statements about virtual networking and hypervisor switches are true? (Choose three.)

Select 3 answers
A.A standard virtual switch (vSwitch) operates at Layer 2 and can forward frames between virtual machines on the same host.
B.A distributed virtual switch (DVS) provides consistent network configuration across multiple ESXi hosts in a cluster.
C.Virtual switches support VLAN tagging using IEEE 802.1Q trunking between the hypervisor and physical switches.
D.Spanning Tree Protocol (STP) must always be enabled on virtual switches to prevent loops in the virtual network.
E.A virtual switch can only be configured with a single port group for all virtual machines.
AnswersA, B, C

A standard vSwitch is a software Layer 2 bridge inside one hypervisor, forwarding Ethernet frames between VMs on that same host using MAC learning. It satisfies the scenario's on-host switching constraint, since traffic between local VMs never leaves the physical host.

Why this answer

Option A is correct because a standard vSwitch is a Layer 2 software construct that learns MAC addresses and forwards Ethernet frames between VMs connected to it on the same ESXi host. Option B is correct because a distributed virtual switch (DVS/vDS) is managed centrally at the vCenter level and pushes a consistent port group, VLAN, and teaming configuration to all member ESXi hosts in a cluster. Option C is correct because virtual switches support IEEE 802.1Q VLAN tagging, allowing VLAN IDs to be assigned to port groups or passed through as trunked tagged frames between the hypervisor and the physical switch.

Option D is not required: virtual switches do not create the Layer 2 loops that STP solves, and ESXi vSwitches do not run STP by default (the physical network handles loop prevention). Option E is false because a single vSwitch can host many port groups, each with its own VLAN, teaming, and security policies.

724
MCQmedium

router bgp 65000 bgp router-id 10.0.0.1 neighbor 10.0.0.2 remote-as 65001 neighbor 10.0.0.2 route-map SET_COMMUNITY in ! route-map SET_COMMUNITY permit 10 set community 100:200 ! What is the effect of this configuration?

A.Routes received from 10.0.0.2 are tagged with community 100:200, but the community is not sent to other BGP peers unless send-community is configured.
B.Routes received from 10.0.0.2 are tagged with community 100:200 and automatically sent to all neighbors.
C.The route-map is applied to outbound updates to 10.0.0.2, setting community on routes sent to that neighbor.
D.The configuration is invalid because the community must be a string, not a numeric value.
AnswerA

This is correct because the route-map 'bgp' is applied inbound from neighbor 10.0.0.2, and it sets the community 100:200 on all received routes. However, BGP does not include community attributes in updates to other peers unless the neighbor is explicitly configured with the send-community parameter. Without send-community, the routes are advertised but the community attribute is stripped, so it never propagates beyond the local router.

Why this answer

The route-map SET_COMMUNITY is applied to inbound updates from neighbor 10.0.0.2, so routes received from that neighbor are tagged with community 100:200. However, BGP does not propagate communities to other peers unless the neighbor is explicitly configured with the send-community command. Without send-community, the community attribute is stripped from outbound updates, so the community is not sent to other BGP peers.

Exam trap

Cisco often tests the distinction between inbound and outbound route-map application, and the fact that communities are not automatically sent to peers without explicit send-community configuration, leading candidates to assume the community is propagated by default.

How to eliminate wrong answers

Option B is wrong because BGP does not automatically send communities to all neighbors; the send-community command is required under the neighbor configuration for the community attribute to be included in outbound updates. Option C is wrong because the route-map is applied with the 'in' keyword, meaning it affects inbound routes from 10.0.0.2, not outbound updates to that neighbor. Option D is wrong because the community value 100:200 is a valid numeric format (AS:value) and is perfectly acceptable in BGP configuration.

725
MCQhard

A network administrator is troubleshooting high CPU utilization on a Catalyst 9300 switch. The output of 'show processes cpu sorted' shows the 'IP Input' process consuming 45% CPU. Which tool should be used to identify the specific packets causing the issue?

A.Use extended ping from the switch to generate traffic.
B.Configure a SPAN session to capture all traffic to the CPU.
C.Check CDP neighbors to see if any devices are flooding.
D.Enable IP traffic export (NetFlow) on the switch.
AnswerD

NetFlow (IP traffic export) samples and exports flow records containing source/destination IP addresses, Layer 4 ports, protocol numbers, and packet/byte counts to a NetFlow collector. By analyzing these exported records, the administrator can pinpoint exactly which flows are contributing to the saturated 'IP Input' process, such as specific hosts generating large volumes of routed traffic. This local, low-overhead mechanism is specifically designed for flow-level visibility and is the correct tool for this troubleshooting scenario.

Why this answer

The 'IP Input' process handles incoming IP packets that require CPU processing, such as routing protocol updates, management traffic, or packets destined to the switch itself. Enabling IP traffic export (NetFlow) on the switch allows the administrator to analyze traffic flows and identify the specific source/destination IP addresses, ports, and protocols consuming CPU cycles, without overwhelming the CPU further. NetFlow provides granular visibility into the types of packets being processed, making it the correct tool for this scenario.

Exam trap

The trap here is that candidates often confuse SPAN (traffic mirroring) with a diagnostic tool, but SPAN does not provide built-in traffic analysis and can worsen CPU load, whereas NetFlow is designed for flow-level analysis without adding significant overhead.

How to eliminate wrong answers

Option A is wrong because extended ping generates ICMP echo requests from the switch, which would add to the CPU load rather than help diagnose the existing high utilization, and it does not capture or analyze the packets already causing the issue. Option B is wrong because configuring a SPAN session to capture all traffic to the CPU would mirror the traffic to a monitoring port, but it does not provide a built-in analysis mechanism on the switch; it requires an external analyzer and could further increase CPU load due to the mirroring process. Option C is wrong because CDP neighbors only provide information about directly connected Cisco devices and their capabilities; checking CDP cannot identify the specific packets causing high CPU utilization, as CDP is a Layer 2 discovery protocol unrelated to IP packet processing.

726
Multi-Selectmedium

Which two statements about MPLS label operations are true? (Choose two.)

Select 2 answers
A.The ingress LSR imposes a label onto the packet.
B.The egress LSR removes the label before forwarding the IP packet.
C.The egress LSR pushes a new label onto the packet.
D.Each LSR in the LSP performs label imposition.
E.Transit LSRs perform label imposition.
AnswersA, B

The ingress LSR classifies the incoming IP packet, assigns the appropriate forwarding equivalence class, and pushes the corresponding label onto the packet before forwarding it into the MPLS domain. This imposition step satisfies the stem's ingress label-operation statement.

Why this answer

Option A is correct because the ingress LSR (label edge router) is the entry point of the MPLS domain and performs label imposition (push), adding an MPLS shim header to the incoming IP packet before forwarding it into the LSP. Option B is correct because the egress LSR (also an LER) performs label disposition (pop), removing the MPLS label so the packet leaves the domain as a normal IP packet toward its destination. Option C is wrong because pushing a new label is an ingress/transit function, not something the egress LSR does when exiting the MPLS domain.

Option D is wrong because label imposition occurs only at the ingress edge, not at every LSR along the LSP. Option E is wrong because transit LSRs perform label swapping (swap), not imposition, forwarding packets based on the incoming label.

Exam trap

The trap is mixing up which LSR performs which label operation — candidates often think transit or egress LSRs impose labels, but only the ingress LSR pushes the initial label, while transit swaps and egress pops.

727
Drag & Dropmedium

Drag and drop the steps of MSTP region and instance configuration steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

MSTP configuration begins with entering MST configuration mode, assigning a region name and revision number, mapping VLANs to instances, and then activating the configuration. Finally, the MST instance priority is set to influence root bridge selection.

728
Drag & Dropmedium

Drag and drop the steps of DNA Center SWIM (Software Image Management) upgrade flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

SWIM upgrade begins with importing the image, then distributing it to the device, performing a pre-check, activating the image, and finally committing the upgrade.

729
MCQmedium

Examine the following configuration: flow record REC-1 match ipv4 source address match ipv4 destination address match ipv4 protocol collect interface input collect interface output collect counter bytes collect counter packets ! flow monitor MON-1 record REC-1 exporter EXPORTER-1 ! interface GigabitEthernet0/1 ip flow monitor MON-1 input ! What is the purpose of this configuration?

A.It collects NetFlow data for incoming traffic, including source/destination IP, protocol, and byte/packet counts.
B.It collects NetFlow data for both incoming and outgoing traffic on the interface.
C.It configures Flexible NetFlow with a user-defined record that includes TCP flags.
D.It sends flow data to the exporter using IPFIX format.
AnswerA

The Flexible NetFlow configuration defines a custom record using match statements for source IP, destination IP, and protocol, along with collect statements for byte and packet counts. The monitor is attached to the interface with the 'input' keyword, which restricts capture to ingress traffic only. This is the standard way to monitor incoming flows without affecting outbound traffic, and the collected fields directly match the description.

Why this answer

The configuration defines a Flexible NetFlow record (REC-1) that matches IPv4 source/destination addresses and protocol, and collects interface input/output along with byte and packet counters. The flow monitor MON-1 applies this record to incoming traffic only (ip flow monitor MON-1 input), so it collects NetFlow data exclusively for inbound packets on GigabitEthernet0/1.

Exam trap

Cisco often tests the directional keyword ('input' vs. 'output') to see if candidates assume both directions are captured by default, when in fact only the specified direction is monitored.

How to eliminate wrong answers

Option B is wrong because the 'input' keyword on the interface restricts collection to incoming traffic only; outgoing traffic is not monitored. Option C is wrong because the record does not include TCP flags (match tcp flags) or any other Layer 4 header fields beyond protocol. Option D is wrong because the configuration does not specify IPFIX format; by default, Flexible NetFlow uses NetFlow version 9 unless the exporter is explicitly configured with 'export-protocol ipfix'.

730
MCQeasy

An engineer is troubleshooting a site-to-site VPN between a Cisco ASA and a Cisco IOS router. The VPN is configured using IKEv1 with pre-shared keys. The tunnel establishes and traffic flows, but after a few hours, the tunnel drops and re-establishes. The engineer checks the logs and sees that the Phase 1 SA is being rekeyed. What is the most likely reason for the tunnel dropping?

A.The Dead Peer Detection (DPD) interval is too short.
B.The IKE Phase 1 lifetime is set too low.
C.The IPsec transform set is misconfigured.
D.The Phase 2 lifetime is longer than Phase 1.
AnswerB

An IKE Phase 1 lifetime that is set too low forces frequent ISAKMP SA renegotiations. If the new Phase 1 exchange cannot complete before the current Phase 1 SA expires, the existing IPsec SAs are invalidated and traffic is dropped while new tunnels are built. Even when rekeys do complete, the short lifetime increases the overlap and timing mismatch with the Phase 2 IPsec lifetime, making drops more likely during transitions. This is the correct cause because it directly matches the symptom of recurring connectivity interruptions.

Why this answer

The most likely reason for the tunnel dropping and re-establishing after a few hours is that the IKE Phase 1 lifetime is set too low. When the Phase 1 SA expires, it must be rekeyed, which can cause a brief interruption in the VPN tunnel. The logs confirm a Phase 1 SA rekey, directly pointing to a short lifetime as the root cause.

Exam trap

Cisco often tests the misconception that a short DPD interval causes rekeys, but the key clue is the log entry specifically mentioning 'Phase 1 SA being rekeyed,' which directly points to the IKE lifetime, not DPD.

How to eliminate wrong answers

Option A is wrong because a short Dead Peer Detection (DPD) interval would cause the tunnel to drop due to missed keepalives, not because of a scheduled rekey of the Phase 1 SA. Option C is wrong because a misconfigured IPsec transform set would prevent Phase 2 negotiation entirely or cause traffic to fail, not cause periodic rekeys after the tunnel is established. Option D is wrong because if Phase 2 lifetime is longer than Phase 1, the Phase 2 SA would remain active until it expires; the tunnel drop is specifically tied to the Phase 1 rekey, not a mismatch in lifetimes.

731
MCQhard

A network architect is designing a Cisco SD-WAN solution with multiple data centers and a mix of MPLS and Internet transports. The company requires that business-critical traffic (e.g., ERP) always use the MPLS transport, while guest traffic uses the Internet. Which Cisco SD-WAN feature should be used to enforce this policy?

A.Centralized data policy
B.Direct Internet Access (DIA)
C.Application-aware routing
D.VPN segmentation
AnswerA

Centralized data policy in Cisco SD-WAN allows you to define traffic steering based on application, source/destination, and transport. You can create a policy that matches ERP traffic and directs it exclusively to the MPLS transport, while matching guest traffic and directing it to the Internet. This enforces the required path selection.

Why this answer

Centralized data policy in Cisco SD-WAN is used to define traffic steering rules. By creating a policy that matches ERP traffic and sets the preferred transport to MPLS, and another that matches guest traffic and sets the transport to Internet, the architect can enforce the requirement. Other features like AAR or VPN segmentation do not provide this static transport enforcement.

Exam trap

The trap here is confusing application-aware routing, which dynamically chooses paths based on SLA, with centralized data policy, which can enforce a static transport preference for specific applications.

732
MCQmedium

Examine the following BGP configuration on a Cisco IOS-XE router: ``` router bgp 65000 bgp default local-preference 150 neighbor 10.1.1.1 remote-as 65001 neighbor 10.1.1.1 password cisco123 neighbor 10.1.1.1 route-map SET-MED out ! route-map SET-MED permit 10 set metric 50 ``` What is the effect of the route-map on outbound updates to 10.1.1.1?

A.The MED value of routes advertised to 10.1.1.1 is set to 50.
B.The local preference of routes received from 10.1.1.1 is set to 150.
C.The route-map filters routes; only those with metric 50 are advertised.
D.The password is applied to the BGP session, but the route-map is ignored due to the password.
AnswerA

This route-map is applied to BGP routes before they are sent to the peer, and it explicitly uses a set command that assigns the Multi-Exit Discriminator (MED) value of 50 to all advertised routes. MED is a non-transitive BGP attribute that influences the peer's inbound path selection, with a lower value preferred over a higher one. Therefore, the statement is correct: the MED of routes advertised to 10.1.1.1 is set to 50.

Why this answer

The route-map SET-MED is applied to outbound updates to neighbor 10.1.1.1 using the 'route-map SET-MED out' command. The route-map permits all routes (no match statement) and sets the MED (Multi-Exit Discriminator) attribute to 50. This means that when the local router advertises routes to this eBGP neighbor, the MED value in those updates will be 50, influencing the neighbor's inbound path selection.

Exam trap

Cisco often tests the distinction between 'route-map out' (affects outbound updates) and 'route-map in' (affects inbound updates), and the trap here is assuming the route-map filters routes when it actually sets an attribute without any match conditions.

How to eliminate wrong answers

Option B is wrong because the 'bgp default local-preference 150' command sets the default local preference for routes received from all eBGP peers, not just 10.1.1.1, and the route-map does not affect local preference. Option C is wrong because the route-map has no match clause, so it permits all routes; it does not filter based on metric 50—it sets the metric to 50 on all advertised routes. Option D is wrong because the password and route-map are independent configurations; the route-map is not ignored due to the password—both are applied correctly.

733
MCQmedium

A network administrator is deploying Cisco Identity Services Engine (ISE) for wired 802.1X authentication on a Cisco Catalyst 9200 switch. The RADIUS server is reachable at 10.10.10.50 with shared secret 'C1sco123'. The administrator wants the switch to authenticate users before granting access to the data VLAN, and to place unauthenticated devices into a restricted VLAN. Which command sequence correctly enables 802.1X on a switch port?

A.aaa new-model; radius server ISE; address ipv4 10.10.10.50 auth-port 1812 acct-port 1813; key C1sco123; interface GigabitEthernet1/0/1; authentication port-control force-authorized; dot1x pae authenticator
B.aaa new-model; tacacs server ISE; address ipv4 10.10.10.50; key C1sco123; interface GigabitEthernet1/0/1; authentication port-control auto; dot1x pae supplicant
C.aaa new-model; radius server ISE; address ipv4 10.10.10.50 auth-port 1645 acct-port 1646; key C1sco123; interface GigabitEthernet1/0/1; authentication port-control auto; dot1x pae authenticator
D.aaa new-model; radius server ISE; address ipv4 10.10.10.50 auth-port 1812 acct-port 1813; key C1sco123; interface GigabitEthernet1/0/1; authentication port-control auto; dot1x pae authenticator
AnswerD

This sequence enables AAA with 'aaa new-model', configures the ISE RADIUS server with the correct ports and key, then on the interface enables 802.1X port-based authentication with 'authentication port-control auto' and designates the switch port as an authenticator with 'dot1x pae authenticator'. This is the correct method to authenticate before granting access and to use an auth-fail VLAN if configured.

Why this answer

802.1X on a Cisco switch requires enabling AAA, defining the RADIUS server with the correct ports and key, and configuring the interface as an authenticator with 'authentication port-control auto'. The switch acts as the authenticator, ISE as the authentication server, and the endpoint as the supplicant. Using 'force-authorized' bypasses authentication, TACACS+ is not used for 802.1X, and legacy ports 1645/1646 are incorrect.

Exam trap

The trap here is confusing the authenticator role with the supplicant role, or selecting force-authorized instead of auto, which would bypass authentication.

734
MCQhard

A network security architect is designing a Zero Trust architecture for a campus network using Cisco Identity Services Engine (ISE) and Cisco TrustSec. The requirement is to enforce segmentation based on user identity and device posture, and to apply policy dynamically as users move between wired and wireless access points. Which Cisco TrustSec component is responsible for tagging packets with a Security Group Tag (SGT) at the access layer?

A.The Policy Administration Node (PAN) in Cisco ISE.
B.The access layer switch or wireless controller that supports Cisco TrustSec.
C.The Policy Enforcement Node (PEN) in Cisco ISE.
D.The Cisco DNA Center appliance.
AnswerB

In Cisco TrustSec, the access layer device, such as a Catalyst switch or wireless controller, is responsible for classifying and tagging packets with an SGT after the endpoint is authenticated. This tagging enables enforcement throughout the network based on the Security Group Tag, allowing dynamic segmentation as users move between wired and wireless access points.

Why this answer

In Cisco TrustSec, the access layer device performs classification and tagging by inserting the SGT into the packet after authentication and authorization. ISE nodes define and evaluate policy, but they do not tag packets. This design allows dynamic segmentation to follow users as they move between wired and wireless access points.

Exam trap

The trap here is confusing the policy decision point with the enforcement point, when SGT tagging actually occurs on the access device.

735
MCQmedium

A network engineer is writing a Python script to retrieve the operational status of all GigabitEthernet interfaces from a Cisco IOS XE device using NETCONF. The script establishes an SSH session to the device on port 830 and sends a <get> RPC with a subtree filter. The device responds with an <rpc-error> indicating 'unknown-element' for the filter. Which action should the engineer take to resolve this issue?

A.Verify that the YANG model for the interface operational data is supported and use the correct namespace in the filter.
B.Convert the subtree filter to an XPath filter and resend the <get> RPC.
C.Change the NETCONF transport from SSH to TLS by enabling the netconf-tls feature on the device.
D.Increase the NETCONF session timeout on the device using the netconf max-sessions command.
AnswerA

The 'unknown-element' error occurs when the filter references a data node that is not defined in any YANG model supported by the device or when the namespace is incorrect. The engineer must confirm that the device supports the ietf-interfaces or Cisco-specific interface YANG model and that the filter uses the exact namespace and node names from that model.

Why this answer

The 'unknown-element' error in NETCONF indicates that the filter references a data node that the device does not recognize. This typically happens when the YANG model is not supported or the namespace is incorrect. The engineer must verify that the device supports the relevant YANG model and that the filter uses the correct namespace and node names.

Exam trap

The trap here is assuming that changing the NETCONF transport or session parameters will fix a filter validation error, when the issue is actually a mismatch between the filter and the supported YANG models.

736
MCQmedium

A medium-sized enterprise is migrating to a Cisco DNA Center-managed network. The security policy requires that all administrative access to network devices be authenticated via TACACS+ and that authorization for commands be enforced per user role. The network team has configured ISE as the AAA server and integrated it with DNA Center. After configuration, engineers report that they can log in to devices via SSH but are not prompted for a password when entering 'enable' mode; instead, they are granted full privileges immediately. Additionally, while in configuration mode, some engineers can issue 'debug' commands that they should not have access to. The configuration on the devices includes 'aaa new-model', 'aaa authentication login default group tacacs+ local', 'aaa authorization exec default group tacacs+ local', and 'aaa authorization commands 15 default group tacacs+ local'. What is the most likely cause of the privilege escalation and missing authorization?

A.The TACACS+ server is not reachable, so the device is using local authentication, but the local database has all users at privilege level 15.
B.The 'aaa authentication enable default' command is missing, so the device is not requiring authentication to enter enable mode, and command authorization is not being enforced because the user is already at privilege 15.
C.Command authorization is only configured for privilege level 15, but users are logging in at level 1; they need 'aaa authorization commands 1 default' as well.
D.The 'privilege level' command is set to 15 on the VTY lines, bypassing AAA authorization.
AnswerB

The absence of 'aaa authentication enable default' leaves the default behavior of no authentication for enable mode, allowing any user to switch to privileged EXEC without a password. Once in enable mode, the user is at privilege level 15, and if command authorization is configured for level 15, the device may not trigger an authorization check because the user already holds full privilege, or the check may occur but without prior authentication it is ineffective. This configuration flaw directly explains why no credentials are prompted and why authorization seems bypassed.

Why this answer

The missing 'aaa authentication enable default group tacacs+ local' command means the device does not require TACACS+ authentication to enter enable mode. Since the user is already at privilege level 15 after login (due to the 'aaa authorization exec' command or local user configuration), they are not prompted for a password and are granted full privileges immediately. Additionally, command authorization is only configured for privilege level 15 ('aaa authorization commands 15'), so once the user is at level 15, no further authorization checks are performed for commands like 'debug', bypassing the intended per-role enforcement.

Exam trap

Cisco often tests the distinction between authentication (who you are) and authorization (what you can do), and the trap here is that candidates assume 'aaa authorization commands 15' alone enforces command restrictions, but they overlook that without 'aaa authentication enable', users may already be at privilege 15, making command authorization ineffective.

How to eliminate wrong answers

Option A is wrong because if the TACACS+ server were unreachable, the 'aaa authentication login default group tacacs+ local' command would fall back to local authentication, but the issue is about enable mode and command authorization, not login; also, local users would not automatically be at privilege 15 unless explicitly configured. Option C is wrong because command authorization for privilege level 1 is irrelevant; the problem is that users are already at privilege 15, so commands at level 15 are authorized without further checks, and adding 'aaa authorization commands 1' would not fix the enable mode or the privilege escalation. Option D is wrong because the 'privilege level' command on VTY lines would set the initial privilege level for all users, but the configuration shown does not include this command, and the described behavior (no password prompt for enable, debug commands allowed) is consistent with missing enable authentication and command authorization at the current privilege level, not with a VTY line setting.

737
MCQmedium

A network security administrator is configuring a Cisco IOS Zone-Based Firewall on a branch router. The inside zone and outside zone are defined, and the administrator wants to allow inside hosts to initiate sessions to outside servers while preventing outside hosts from initiating sessions to inside hosts. Which configuration accomplishes this?

A.A zone pair from inside to outside with a policy that inspects the relevant traffic, and no zone pair from outside to inside.
B.A zone pair from outside to inside with an inspect action and no zone pair from inside to outside.
C.A single zone pair from inside to outside with a drop action, and a class-map matching return traffic.
D.A zone pair from outside to inside with a policy that inspects traffic, plus a zone pair from inside to outside with a pass action.
AnswerA

Zone-Based Firewall uses zone pairs to define directional policy. Creating a zone pair from inside to outside with an inspect action permits inside-initiated sessions and automatically allows return traffic. Because there is no zone pair from outside to inside, traffic initiated from the outside zone to the inside zone is denied by default, which matches the requirement exactly.

Why this answer

Zone-Based Firewall policy is directional and defined by zone pairs. An inside-to-outside zone pair with an inspect action permits inside-initiated sessions and statefully allows return traffic, while the absence of an outside-to-inside zone pair causes traffic initiated from the outside to be dropped by the default inter-zone policy, achieving the required asymmetry.

Exam trap

The trap here is assuming that configuring an inspect action on one zone pair automatically permits sessions in both directions rather than only the direction defined by the zone pair.

738
MCQeasy

A network engineer is using Cisco SD-WAN vManage APIs to automate the creation of a new VPN template. The engineer needs to authenticate to the vManage REST API using a Python script. Which authentication method is natively supported by the vManage API for programmatic access?

A.Session-based authentication using a cookie obtained from /j_security_check
B.API key authentication using a static key generated in the vManage GUI
C.Certificate-based authentication using X.509 client certificates
D.OAuth 2.0 with JWT tokens issued by vManage
AnswerA

The vManage REST API uses session-based authentication where the client posts credentials to /j_security_check and receives a JSESSIONID cookie. This cookie must be included in subsequent API requests. This is the standard method for programmatic access to vManage, allowing scripts to authenticate and perform operations.

Why this answer

The vManage REST API uses session-based authentication. A client sends a POST request to /j_security_check with username and password, receives a JSESSIONID cookie, and includes it in subsequent requests. This method is standard for automating vManage operations.

Other methods like OAuth or API keys are not natively supported for the vManage API.

Exam trap

The trap here is assuming that vManage supports OAuth or API keys like some other Cisco platforms, but it actually uses session cookies for API authentication.

739
MCQmedium

Consider the following IPv6 access-list on a Cisco IOS-XE router: ``` ipv6 access-list PERMIT_ICMP permit icmp any any echo-request permit icmp any any echo-reply deny ipv6 any any ! interface GigabitEthernet0/0 ipv6 traffic-filter PERMIT_ICMP in ``` What is the effect of this configuration?

A.Only IPv6 ping (echo-request and echo-reply) is allowed inbound on Gi0/0; all other IPv6 traffic is dropped.
B.All ICMPv6 traffic is permitted inbound on Gi0/0.
C.The ACL is applied outbound, so it filters traffic leaving Gi0/0.
D.The ACL permits all IPv6 traffic because the deny statement is at the end.
AnswerA

The ACL on Gi0/0 contains two permit statements matching ICMPv6 echo-request (type 128) and echo-reply (type 129), followed by an explicit deny statement for all other IPv6 traffic. Because the ACL is applied inbound with the 'in' keyword, only packets entering the interface that match these two permit statements are forwarded; any other IPv6 packet is dropped. This is a common security practice to allow ping while blocking other ICMPv6 control messages.

Why this answer

The ACL explicitly permits only ICMPv6 echo-request and echo-reply messages, which are the packets used by IPv6 ping. The final 'deny ipv6 any any' statement drops all other IPv6 traffic. Since the ACL is applied inbound on GigabitEthernet0/0 via the 'ipv6 traffic-filter' command, only IPv6 ping is allowed in; all other IPv6 packets are denied.

Exam trap

Cisco often tests the distinction between ICMPv6 and ICMPv4, and the trap here is that candidates assume 'icmp' in an IPv6 ACL permits all ICMPv6 types, when in fact only the explicitly listed types (echo-request, echo-reply) are allowed.

How to eliminate wrong answers

Option B is wrong because the ACL permits only echo-request and echo-reply, not all ICMPv6 types (e.g., Neighbor Solicitation, Router Advertisement are denied). Option C is wrong because the 'in' keyword in 'ipv6 traffic-filter PERMIT_ICMP in' explicitly applies the ACL to inbound traffic, not outbound. Option D is wrong because the implicit deny at the end of an ACL is replaced by the explicit 'deny ipv6 any any' statement, which still blocks all non-permitted traffic; the permit statements do not override the deny.

740
Drag & Dropmedium

Drag and drop the steps of OSPF summarization at ABR configuration steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, identify the subnets to summarize into a single prefix. Then, configure the area range command on the ABR under the OSPF process, specifying the area and the summary prefix. Optionally, set the 'not-advertise' keyword to suppress the summary.

Verify the summary route in the OSPF database using 'show ip ospf summary-address'. Finally, check that the summary route appears in the routing table of other routers.

741
MCQhard

A network engineer runs the following command on Switch SW4: SW4# show etherchannel 1 detail Channel-group number: 1 Group state = L2 Ports in the group: ------------------- Port: Gi0/0 -------- Port state = Up, In-Bundle Channel group = 1 Mode = Active/PagNego Gcchange = - Port-channel = Po1 GC = 0x00010001 Pseudo port-channel = Po1 Port index = 0 Load = 0x00 Flags: S - Device is sending Slow LACPDUs F - Device is sending Fast LACPDUs A - Device is in active mode. P - Device is in passive mode. Local information: LACP port Admin Oper Port Port Port Flags State Priority Key Key Number State Gi0/0 SA bndl 32768 0x1 0x1 0x101 0x3D Partner information: LACP port Admin Oper Port Port Port Flags State Priority Key Key Number State Gi0/0 SA bndl 32768 0x1 0x1 0x102 0x3D Age of the port = 0d:00h:15m:20s Based on this output, what can be concluded?

A.The port is in passive mode and waiting for the partner to initiate.
B.The port is sending fast LACPDUs because the flag is 'F'.
C.The port is bundled and the LACP state is synchronized.
D.The port is not in use because the load is 0x00.
AnswerC

The port's 'bndl' state in the EtherChannel summary indicates it is successfully bundled into the channel, and the LACP state value 0x3D signifies that the port is synchronized with its peer. This full operational state means the port is actively forwarding traffic as part of the EtherChannel.

Why this answer

The output shows both the local and partner ports in 'bndl' state with LACP state 0x3D, which indicates the port is bundled and synchronized. The 'SA' flags confirm active mode and slow LACPDUs, and the 'bndl' state means the EtherChannel is fully operational with LACP in sync.

Exam trap

Cisco often tests the misconception that 'Load = 0x00' means the port is idle, but in reality it is a default value for the first port index in the EtherChannel and does not reflect traffic utilization.

How to eliminate wrong answers

Option A is wrong because the local port shows flag 'A' (active mode), not passive, and the state is 'bndl' (bundled), not waiting. Option B is wrong because the flag shown is 'S' (slow LACPDUs), not 'F'; the output explicitly lists 'S - Device is sending Slow LACPDUs'. Option D is wrong because load value 0x00 is a default or placeholder in the show command and does not indicate the port is unused; the port is clearly bundled and forwarding traffic.

742
MCQmedium

Consider the following configuration: flow exporter EXPORTER-1 destination 10.0.0.1 source Loopback0 transport udp 9996 template data timeout 60 ! Which statement about this configuration is true?

A.Template data records are sent every 60 seconds to the collector.
B.The exporter uses UDP port 9996 to send flow data and templates.
C.The source interface Loopback0 is used only for flow data, not for templates.
D.The exporter will send template data only when a new flow is detected.
AnswerA

In NetFlow v9/IPFIX, template records define the data record format and must be present on the collector before any data can be decoded. The 'template data timeout' command sets the refresh interval, so a template FlowSet is re-sent to the collector every 60 seconds regardless of whether new data flows have been observed. This periodic refresh keeps the collector's template cache synchronized and avoids relying on the timing of new flows.

Why this answer

The `template data timeout 60` command under the flow exporter configuration specifies the interval in seconds at which the exporter sends NetFlow version 9 or IPFIX template data records to the collector. This ensures the collector has the current field definitions to decode incoming flow records. Option A correctly states that template data records are sent every 60 seconds to the collector.

Exam trap

Cisco often tests the misconception that the `template data timeout` command controls how often flow data is exported, rather than the template refresh interval, or that templates are sent only on demand rather than periodically.

How to eliminate wrong answers

Option B is wrong because the `transport udp 9996` command configures the destination UDP port for both flow data and template records; templates are not sent on a separate port. Option C is wrong because the `source Loopback0` command defines the source IP address for all packets sent by the exporter, including both flow data and template records. Option D is wrong because template data is sent at the configured timeout interval (60 seconds) and also when a new flow is detected, but the primary behavior is periodic transmission; the statement implies templates are sent only on new flow detection, which is incorrect.

743
Matchingmedium

Drag and drop each TACACS+ packet type on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Initiates an authentication session and contains the username

Sends a challenge (e.g., password prompt) or authentication result

Carries the user's response to a challenge

Indicates successful authentication and may include authorization attributes

Indicates authentication failure

Why these pairings

START begins authentication and contains username; REPLY sends challenge or result; CONTINUE sends response to challenge; ACCEPT indicates successful authentication; REJECT indicates authentication failure.

744
MCQhard

A network administrator is using Cisco DNA Center Assurance to troubleshoot a client connectivity issue. The client is associated to a wireless controller but cannot reach the default gateway. The administrator notices that the client's onboarding status shows 'DHCP failed'. Which Assurance feature should the administrator use to trace the client's path and identify where DHCP packets are being dropped?

A.Path Trace
B.Application Experience
C.Sensor-driven tests
D.Network Time Travel
AnswerA

Path Trace in Cisco DNA Center Assurance visually traces the path of a client's traffic through the network, showing each hop and any drops. It can simulate DHCP requests and responses, highlighting where packets are discarded. This directly addresses the need to identify where DHCP packets are being dropped for the client, making it the correct tool.

Why this answer

Path Trace in Cisco DNA Center Assurance is designed to trace the exact path of a client's traffic, including DHCP, through the network. It shows each device and interface the traffic traverses and identifies where packets are dropped. This makes it the ideal tool for troubleshooting a client's DHCP failure by pinpointing the drop location.

Other features like Time Travel or Application Experience provide different types of analysis but not hop-by-hop path tracing.

Exam trap

The trap here is confusing Path Trace with Network Time Travel or Sensor-driven tests, which provide historical or simulated data rather than real-time hop-by-hop path analysis for a specific client.

745
MCQmedium

Given the following Ansible playbook snippet: --- - name: Configure SNMP hosts: routers gather_facts: no tasks: - name: SNMP community ios_config: lines: - snmp-server community public RO What is the result of this playbook?

A.It configures an SNMP community string 'public' with read-only access.
B.It fails because 'RO' is not a valid keyword; it should be 'read-only'.
C.It configures the community string only for SNMPv3.
D.It removes any existing SNMP community strings.
AnswerA

The ios_config module pushes the listed configuration lines verbatim to the device, so 'snmp-server community public RO' creates community string 'public' with read-only access. Because gather_facts is disabled, no fact collection interferes; the task simply applies the SNMP community as specified.

Why this answer

The ios_config module pushes the line 'snmp-server community public RO' into the device's running configuration. On Cisco IOS, 'RO' is the valid abbreviation for read-only when defining an SNMP community string, so the playbook successfully creates a read-only community named 'public'. The playbook does not gather facts and does not specify a 'save_when' parameter, so it modifies the running config only.

Exam trap

350-401 often tests whether candidates know that 'RO' is a valid IOS abbreviation and that ios_config is idempotent and does not save to startup-config by default.

How to eliminate wrong answers

Option B is wrong because 'RO' is a valid IOS keyword abbreviation for read-only; the full form 'snmp-server community public RO' is standard and accepted. Option C is wrong because SNMPv3 does not use community strings at all — it uses users, authentication, and privacy (USM); the command shown is SNMPv1/v2c syntax. Option D is wrong because ios_config with 'lines' adds or updates the specified lines; it does not remove existing community strings unless you use 'no snmp-server community ...' or the 'replace'/'before'/'after' options.

746
MCQmedium

A network engineer is deploying a Cisco Catalyst 9300 switch stack that will host several isolated tenant environments. Each tenant must have its own separate routing table and its own independent instance of a dynamic routing protocol on the same physical switch, while sharing the same physical uplinks to the core. Which technology should the engineer implement to meet these requirements?

A.Virtual Routing and Forwarding (VRF)
B.Virtual Switching System (VSS)
C.Private VLAN (PVLAN) configuration
D.VLAN access map on the uplink
AnswerA

VRF creates multiple independent Layer 3 routing and forwarding tables on a single physical device, so each tenant gets its own RIB/FIB and can run a separate routing protocol instance. This directly satisfies the requirement of isolated routing tables plus independent protocol instances sharing the same physical uplinks and hardware.

Why this answer

VRF is the Cisco IOS/IOS-XE feature that partitions a single physical router or switch into multiple logically separate Layer 3 routing domains. Each VRF maintains its own routing and forwarding table and can run its own routing protocol process, which is exactly what is needed when several tenants must share hardware and uplinks while remaining logically isolated.

Exam trap

The trap here is confusing Layer 2 isolation features such as private VLANs with true Layer 3 routing table separation.

747
Multi-Selecthard

Which three statements about RADIUS and TACACS+ are true? (Choose three.)

Select 3 answers
A.RADIUS combines authentication and authorization in a single packet.
B.TACACS+ uses TCP port 49 by default.
C.RADIUS encrypts the entire packet payload for all attributes.
D.TACACS+ provides separate authentication, authorization, and accounting processes.
E.RADIUS supports per-command authorization for shell sessions.
AnswersA, B, D

RADIUS merges authentication and authorization into one Access-Accept packet, returning attributes such as service type and IP assignment together. TACACS+ separates these functions, issuing distinct authentication and authorization exchanges. This combined-packet behaviour is the specific RADIUS trait being verified.

Why this answer

Option A is correct because RADIUS, defined in RFC 2865/2866, performs authentication and authorization together in a single Access-Request/Access-Accept exchange, so the two functions are not separated into distinct transactions. Option B is correct because TACACS+ operates over TCP and listens on port 49 by default, providing reliable transport unlike RADIUS's use of UDP. Option D is correct because TACACS+ is designed with fully separated AAA functions, allowing authentication, authorization, and accounting to be handled as independent processes and even directed to different servers.

Option C is incorrect because RADIUS only encrypts the password (User-Password attribute) using a shared secret and MD5, leaving the rest of the packet payload, such as other attributes, in cleartext. Option E is incorrect because per-command authorization for shell/CLI sessions is a hallmark of TACACS+, whereas RADIUS lacks native support for granular per-command authorization.

Exam trap

The trap here is assuming RADIUS encrypts all data or supports command authorization like TACACS+; candidates often mix up the capabilities of the two protocols.

748
MCQhard

An enterprise has two BGP routers, R1 and R2, both in AS 65000. R1 peers with ISP1 (AS 100) and R2 peers with ISP2 (AS 200). The enterprise advertises a prefix 192.168.0.0/24 to both ISPs. The engineer wants to ensure that traffic from the Internet to this prefix enters the network primarily via R1, and only uses R2 if the link to ISP1 fails. Which BGP attribute should be manipulated on the updates sent to the ISPs?

A.Prepend AS 65000 multiple times on R2's updates to ISP2.
B.Set a higher MED on R1's updates to ISP1.
C.Set a higher local preference on R1 for routes learned from ISP1.
D.Use the no-export community on R1's updates to ISP1.
AnswerA

AS_PATH prepending artificially lengthens the AS path by adding multiple copies of the enterprise's ASN (65000) to the prefix advertised to ISP2. Because ISP2's BGP best-path algorithm compares AS_PATH length among equal-preference routes, the path through R2 appears longer than the same prefix advertised via ISP1's shorter AS path. This induces ISP2 to select the ISP1 route for inbound traffic, thereby directing traffic to R1 as intended. It is a standard, lightweight technique that only changes how ISPs view the return path, without affecting outbound routing.

Why this answer

To influence inbound traffic from the Internet, you must manipulate attributes sent to the ISPs. AS path prepending makes a route appear less preferred by artificially lengthening the AS path. By prepending AS 65000 multiple times on R2's updates to ISP2, ISP2 will see a longer AS path for the prefix and prefer the shorter path via ISP1, causing traffic to enter primarily via R1 unless the ISP1 link fails.

Exam trap

Cisco often tests the distinction between attributes that influence inbound vs. outbound traffic; the trap here is confusing local preference (outbound) with AS path prepending (inbound), leading candidates to incorrectly choose local preference manipulation.

How to eliminate wrong answers

Option B is wrong because MED is a metric exchanged between ASes to influence inbound traffic from a neighboring AS, but it is only compared when paths come from the same neighboring AS; here ISP1 and ISP2 are different ASes, so MED would not be compared. Option C is wrong because local preference is an attribute used within an AS to influence outbound traffic, not sent to external peers; setting it on R1 for routes learned from ISP1 affects R1's choice of exit path, not how ISPs send traffic inbound. Option D is wrong because the no-export community prevents a route from being advertised to any eBGP peers beyond the immediate neighbor; using it on R1's updates to ISP1 would block the prefix from being propagated further, which is unrelated to influencing inbound path preference.

749
MCQhard

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect against DoS attacks. The router has a management plane that must remain accessible via SSH and SNMP, and a control plane that must process BGP and OSPF routing updates. The administrator applies a CoPP policy that rate-limits all traffic destined to the control plane to 1000 pps, except for traffic from trusted management subnets. After applying the policy, BGP sessions flap intermittently. What is the most likely cause?

A.The CoPP policy is rate-limiting BGP keepalives and updates, causing session timeouts.
B.The CoPP policy is applied to the data plane instead of the control plane, causing routing updates to be dropped.
C.The CoPP policy is incorrectly classifying SSH traffic as BGP, leading to rate limiting of SSH.
D.The CoPP policy is dropping SNMP traps, causing BGP to lose its peer state.
AnswerA

CoPP policies that apply a blanket rate limit to all control plane traffic can inadvertently throttle essential routing protocol messages like BGP keepalives and updates. If the rate limit is too low or not exempting BGP, sessions may flap due to missed keepalives or delayed updates. The policy must be fine-tuned to allow sufficient bandwidth for routing protocols.

Why this answer

CoPP policies must be carefully designed to avoid throttling critical control plane protocols. A blanket rate limit of 1000 pps may be insufficient for BGP, especially if there are many peers or frequent updates. BGP keepalives are sent every 60 seconds by default, but updates and other messages can burst.

If the policer drops these, sessions can flap. The correct approach is to create granular class-maps that match BGP and other routing protocols, and assign appropriate rates or exempt them from policing.

Exam trap

The trap here is assuming that a single rate limit for all control plane traffic is safe, without considering the specific needs of routing protocols like BGP.

750
MCQeasy

An architect is designing a virtualized environment for network functions that require direct access to physical NICs for performance. The hypervisor must support PCI passthrough. Which hypervisor type is best suited for this requirement?

A.Type 1 hypervisor (e.g., VMware ESXi or KVM).
B.Type 2 hypervisor (e.g., VirtualBox or VMware Workstation).
C.Container runtime (e.g., Docker).
D.Bare-metal server without virtualization.
AnswerA

A Type 1 hypervisor runs directly on the server's hardware with no underlying OS, giving it exclusive control of the CPU, memory, and I/O devices. Through VT-d/IOMMU, it can map a physical PCIe function to a single VM, enabling device passthrough that delivers near-native throughput for NICs and GPUs. Examples like VMware ESXi and KVM (via Linux's kernel modules) are purpose-built for this role, which is why they are the correct answer.

Why this answer

A Type 1 hypervisor (bare-metal) runs directly on the hardware and has direct access to physical resources, including PCIe devices. It supports PCI passthrough (e.g., Intel VT-d or AMD IOMMU), which allows a virtual machine to directly access a physical NIC without hypervisor intervention, maximizing performance for network functions. VMware ESXi and KVM are common Type 1 hypervisors that implement this capability.

Exam trap

Cisco often tests the distinction between Type 1 and Type 2 hypervisors, and the trap here is that candidates may assume any hypervisor can support PCI passthrough, overlooking the architectural overhead of Type 2 hypervisors that prevents direct hardware access.

How to eliminate wrong answers

Option B is wrong because a Type 2 hypervisor (e.g., VirtualBox or VMware Workstation) runs on top of a host OS, adding an extra layer that introduces latency and typically does not support direct PCI passthrough to physical NICs for production-grade performance. Option C is wrong because container runtimes (e.g., Docker) share the host kernel and do not provide direct access to physical PCI devices; they rely on the host's network stack, which cannot achieve the same performance as PCI passthrough for network functions. Option D is wrong because a bare-metal server without virtualization cannot host multiple virtualized network functions simultaneously, which defeats the purpose of a virtualized environment; the question explicitly requires virtualization.

Page 9

Page 10 of 26

Page 11