Courseiva

ENCOR 350-401 (350-401) — Questions 751–825

1923 questions total · 26pages · All types, answers revealed

Page 10

Page 11 of 26

Page 12
751
Multi-Selectmedium

A network engineer is using Cisco DNA Center Assurance to monitor and troubleshoot a network. The engineer wants to use the Assurance features to proactively detect issues and receive recommendations. Which two statements are true about Cisco DNA Center Assurance capabilities? (Choose two.)

Select 2 answers
A.It can automatically apply configuration changes to remediate issues without human intervention.
B.It integrates with Cisco Identity Services Engine (ISE) to provide client authentication details.
C.It provides real-time monitoring of network devices but does not offer historical data analysis.
D.It uses machine learning to correlate network events and identify root causes.
E.It requires the use of Cisco DNA Center appliances only; virtual deployments are not supported.
AnswersB, D

Cisco DNA Center Assurance integrates with Cisco ISE to pull client authentication and authorization information. This integration allows Assurance to show detailed client onboarding and policy compliance data. By correlating network and identity data, engineers can troubleshoot issues related to authentication and access. This is a valid and important capability.

Why this answer

Cisco DNA Center Assurance uses machine learning to correlate events and identify root causes, enabling proactive issue detection. It also integrates with Cisco ISE to provide client authentication details, enhancing troubleshooting for identity-related issues. These two capabilities are fundamental to Assurance's value proposition.

The other statements are false: Assurance does provide historical data, does not automatically remediate without human intervention, and supports virtual deployments.

Exam trap

The trap here is assuming that Assurance automatically remediates issues; it provides recommendations but requires human action for changes.

752
MCQmedium

A network engineer is deploying a new branch office and needs to assign IPv6 addresses to hosts on the LAN segment. The engineer wants hosts to automatically configure their own addresses using the MAC address and the network prefix, without relying on a DHCPv6 server. Which IPv6 address assignment method should be configured on the router interface?

A.Static IPv6 addressing
B.SLAAC
C.DHCPv6 prefix delegation
D.Stateful DHCPv6
AnswerB

SLAAC allows hosts to automatically generate their own IPv6 addresses using the network prefix from Router Advertisement messages and their interface identifier (often derived from the MAC address via EUI-64). No DHCPv6 server is needed, satisfying the requirement. The router sends RA messages with the A flag set to 1, instructing hosts to use stateless autoconfiguration. This method is ideal for simple deployments where centralized address management is not required.

Why this answer

SLAAC enables hosts to automatically generate IPv6 addresses using the prefix from Router Advertisements and their interface identifier, without needing a DHCPv6 server. This matches the requirement for self-configuration. Stateful DHCPv6 requires a server, static addressing is manual, and prefix delegation is for router-to-router prefix assignment, not host addressing.

Exam trap

The trap here is confusing SLAAC with DHCPv6, assuming that any automatic address assignment requires a server.

753
MCQmedium

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive traffic. The router has a single physical interface Gi0/0/0 that carries both management SSH traffic and transit data traffic. The administrator wants the CoPP policy to apply only to traffic destined to the router's control plane, not to transit traffic. Which CoPP configuration element must be applied to achieve this?

A.Apply the policy-map to the Gi0/0/0 interface in the input direction using the service-policy command.
B.Apply the policy-map to the control-plane global configuration using the service-policy command under control-plane.
C.Apply the policy-map to the Gi0/0/0 interface in the output direction using the service-policy command.
D.Apply the policy-map to the management VRF using the service-policy command under vrf definition.
AnswerB

CoPP is implemented by attaching a policy-map to the control-plane interface using the service-policy command under the control-plane global configuration mode. This causes the policy to inspect only packets that are punted to the route processor, thereby protecting the control plane without affecting transit traffic on physical interfaces.

Why this answer

CoPP protects the route processor by policing traffic that is punted to the control plane. The policy-map must be attached to the control-plane interface with the service-policy command under the control-plane global configuration. Applying a policy to a physical interface or in the output direction would affect transit or outbound traffic, not the control-plane path.

Exam trap

The trap here is confusing interface-level service-policy application with the specialized control-plane interface used by CoPP.

754
Drag & Dropmedium

Drag and drop the steps of DHCP snooping operation on a Cisco switch into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

DHCP snooping begins by enabling the feature globally with 'ip dhcp snooping'. Then, the feature is enabled on specific VLANs. Trusted interfaces (typically uplinks to DHCP servers) are configured with 'ip dhcp snooping trust'.

The switch then intercepts DHCP messages, building the DHCP snooping binding database from valid server responses. Finally, any DHCP server messages received on untrusted interfaces are dropped to prevent rogue server attacks.

755
MCQmedium

A network engineer is troubleshooting a routing loop in an EIGRP network. Which mechanism is designed to prevent routing loops by causing a router to reject routes that are learned from a neighbor that is not the successor?

A.Split horizon
B.Route poisoning
C.Hold-down timers
D.Feasibility condition
AnswerD

The feasibility condition is EIGRP's loop-free guarantee: a neighbor advertises a reported distance (RD) that is strictly lower than the current feasible distance (FD) to a destination. This proves the neighbor's path does not pass back through the local router, so the path can safely be used as a feasible successor. If no such neighbor exists, DUAL goes active and queries neighbors, but the feasibility condition remains the core mechanism ensuring that any selected path is genuinely loop-free.

Why this answer

The feasibility condition is a loop-prevention mechanism unique to EIGRP. It ensures that a router only accepts a route from a neighbor if that neighbor's reported distance (RD) to the destination is less than the router's own feasible distance (FD). This guarantees that the path through that neighbor is loop-free, effectively rejecting routes learned from any neighbor that is not the successor.

Exam trap

Cisco often tests the distinction between EIGRP's feasibility condition and other distance-vector loop-prevention mechanisms like split horizon or hold-down timers, expecting candidates to confuse these concepts because they all prevent loops but operate at different stages of the routing process.

How to eliminate wrong answers

Option A is wrong because split horizon prevents loops by not advertising a route back out the interface from which it was learned, but it does not evaluate whether the neighbor is the successor. Option B is wrong because route poisoning (setting the metric to infinity) is used to signal a failed route, not to reject routes from non-successor neighbors. Option C is wrong because hold-down timers are used in distance-vector protocols like RIP to suppress updates after a metric change, but EIGRP does not use hold-down timers; it relies on the Diffusing Update Algorithm (DUAL) and the feasibility condition for loop prevention.

756
MCQmedium

Examine the following configuration snippet: interface GigabitEthernet1/0/1 switchport mode access switchport access vlan 100 spanning-tree portfast spanning-tree bpduguard enable What is the effect of this configuration?

A.The port will immediately transition to forwarding state and will be error-disabled if a BPDU is received.
B.The port will remain in blocking state until a BPDU is received from the root bridge.
C.The port will only forward BPDUs and will not forward data traffic.
D.The port will participate in RSTP and will not be affected by BPDU reception.
AnswerA

With PortFast configured on an access port, the switch port bypasses the normal Spanning Tree Protocol (STP) listening and learning states and transitions directly to forwarding, allowing endpoints such as PCs or IP phones to come up immediately. When BPDU Guard is also enabled (as is typical for access ports), the arrival of any Bridge Protocol Data Unit—which would indicate another switch has been connected—triggers an immediate error-disable of the port, preventing potential Layer 2 loops. This behavior is deterministic: forwarding first, then shutdown on any unexpected BPDU.

Why this answer

The configuration enables PortFast and BPDU Guard on an access port. PortFast immediately transitions the port to forwarding state, bypassing the usual STP listening and learning phases. BPDU Guard monitors for incoming BPDUs; if any are received, it error-disables the port to prevent a potential bridging loop from an unauthorized switch connection.

Exam trap

Cisco often tests the distinction between PortFast (which speeds up convergence) and BPDU Guard (which protects against loops) — the trap here is assuming PortFast alone prevents BPDU issues, when in fact BPDU Guard is required to error-disable the port upon BPDU reception.

How to eliminate wrong answers

Option B is wrong because PortFast forces the port into forwarding state immediately, not blocking; BPDU Guard does not alter this behavior. Option C is wrong because the port forwards normal data traffic as an access port in VLAN 100, not just BPDUs. Option D is wrong because BPDU Guard explicitly reacts to BPDU reception by error-disabling the port, so the port is affected by BPDUs; RSTP is not relevant here as PortFast overrides the STP state machine.

757
MCQhard

A network engineer is designing a QoS policy for a Cisco Catalyst switch that will carry voice, video, and data traffic. The engineer wants to ensure that voice traffic receives strict priority queuing, video traffic gets guaranteed bandwidth, and data traffic uses leftover bandwidth. The switch supports Cisco Modular QoS CLI (MQC). Which queuing mechanism should be configured on the egress interface to meet these requirements?

A.First-In, First-Out (FIFO) queuing
B.Class-Based Weighted Fair Queuing (CBWFQ)
C.Low Latency Queuing (LLQ)
D.Weighted Random Early Detection (WRED)
AnswerC

LLQ provides strict priority queuing for voice traffic while allowing other classes to have guaranteed bandwidth. It is configured using the priority command within a policy map applied to the interface. This meets the requirement for voice to have strict priority, video to have guaranteed bandwidth (using bandwidth command), and data to use leftover bandwidth. Therefore, LLQ is the correct queuing mechanism for this scenario.

Why this answer

LLQ is the correct queuing mechanism because it combines strict priority queuing for voice with guaranteed bandwidth for other classes like video. It is configured using MQC with a priority command for voice and bandwidth commands for other classes. CBWFQ lacks strict priority, WRED is a congestion avoidance tool, and FIFO provides no differentiation.

Thus, LLQ meets all the stated requirements.

Exam trap

The trap here is confusing CBWFQ with LLQ, or thinking that WRED provides queuing. LLQ is specifically designed for low-latency traffic like voice.

758
MCQeasy

A retail company wants its network engineers to push consistent OSPF configurations to dozens of Cisco IOS XE routers using a declarative, agentless automation tool that connects over SSH and does not require installing software on the managed devices. Which tool best fits these requirements?

A.Ansible, using modules such as ios_config with an inventory of IOS XE devices and SSH credentials.
B.Puppet, using a master-agent architecture with the Puppet agent installed on each IOS XE router.
C.Chef, using a Chef client installed directly on each Cisco IOS XE router to converge configuration.
D.SaltStack, using Salt minions installed locally on every IOS XE device to receive configuration commands.
AnswerA

Ansible is declarative, agentless, and connects to managed nodes over SSH without installing any agent software. Its network modules, including ios_config and ios_ospf, target Cisco IOS and IOS XE devices and push configuration from playbooks. This matches the requirement for consistency across many routers, no on-device agent, and SSH-based transport exactly as described.

Why this answer

Ansible is the agentless, declarative tool that connects over SSH and uses network-specific modules to configure Cisco IOS XE devices. It needs no software installed on the routers, relying instead on SSH and Python executed on the control node. Puppet, Chef, and SaltStack in their default forms require an agent on the managed node, which IOS XE cannot host, so they fail the stated agentless requirement.

Exam trap

The trap here is assuming all configuration-management tools are agentless, when Puppet, Chef, and SaltStack default to agent-based designs.

759
MCQhard

A network team is designing QoS for a multi-tenant data center using leaf-spine architecture. Each tenant requires guaranteed bandwidth for their mission-critical applications, while best-effort traffic must not interfere. The design must use hierarchical queuing to enforce per-tenant fairness. Which queuing mechanism should the architect implement on the leaf switches?

A.Implement hierarchical QoS (HQoS) with a parent policy shaping per-tenant traffic and a child policy applying class-based weighted fair queuing (CBWFQ) for each tenant's applications.
B.Use a single level of CBWFQ on all interfaces, classifying traffic by tenant using VLANs.
C.Apply strict priority queuing for all mission-critical traffic across all tenants.
D.Configure separate physical interfaces for each tenant and apply independent QoS policies.
AnswerA

HQoS uses a two-level policy map: the parent policy shapes each tenant's aggregate traffic to its contracted bandwidth (e.g., via a shape statement applied to a class that matches the tenant), while the child policy, attached to that parent class, runs CBWFQ to schedule the tenant's application classes. This nesting decouples per-tenant rate enforcement from intra-tenant scheduling, giving both bandwidth isolation between tenants and fair treatment for different applications inside each tenant. Because shaping at the parent level acts as a per-tenant token bucket, no tenant can burst beyond its allowance, and the child policy's queue weights ensure no single application monopolizes the tenant's share.

Why this answer

Hierarchical QoS (HQoS) is the correct choice because it allows the architect to enforce per-tenant bandwidth guarantees using a parent policy (shaping) while applying class-based weighted fair queuing (CBWFQ) in a child policy to prioritize each tenant's mission-critical applications. This two-level structure ensures that best-effort traffic from one tenant cannot starve another tenant's guaranteed traffic, meeting the multi-tenant fairness requirement.

Exam trap

Cisco often tests the misconception that a single level of CBWFQ or strict priority queuing can achieve per-tenant fairness, but without hierarchical shaping, one tenant's bursty traffic can consume all available bandwidth, breaking the isolation required in multi-tenant environments.

How to eliminate wrong answers

Option B is wrong because a single level of CBWFQ on all interfaces, classifying by VLAN, cannot enforce per-tenant fairness; it would treat all traffic from different tenants equally within the same queue, allowing one tenant's best-effort traffic to interfere with another tenant's critical traffic. Option C is wrong because strict priority queuing for all mission-critical traffic across all tenants would allow a single tenant's high-priority traffic to monopolize bandwidth, starving other tenants' critical applications and violating per-tenant fairness. Option D is wrong because configuring separate physical interfaces for each tenant is not scalable in a leaf-spine architecture and does not inherently provide hierarchical queuing or per-tenant fairness; it would require excessive port consumption and does not address intra-tenant application differentiation.

760
MCQhard

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-POLICY Class-map: BGP-CLASS (match-all) 50 packets, 2500 bytes 5 minute offered rate 500 bps Match: access-group name BGP-ACL police: cir 64000 bps, bc 8000 bytes, be 8000 bytes conformed 50 packets, 2500 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: SNMP-CLASS (match-all) 200 packets, 10000 bytes 5 minute offered rate 2000 bps Match: access-group name SNMP-ACL police: cir 16000 bps, bc 2000 bytes, be 2000 bytes conformed 150 packets, 7500 bytes; actions: transmit exceeded 40 packets, 2000 bytes; actions: drop violated 10 packets, 500 bytes; actions: drop Class-map: class-default (match-any) 100 packets, 5000 bytes 5 minute offered rate 1000 bps Match: any police: cir 32000 bps, bc 4000 bytes, be 4000 bytes conformed 100 packets, 5000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Based on this output, what can be concluded?

A.SNMP traffic to the control plane is experiencing drops due to exceeding its policer rate, while BGP traffic is within its rate.
B.BGP traffic is being dropped because it exceeds the CIR.
C.All traffic to the control plane is being dropped.
D.The control-plane policy is applied in the output direction.
AnswerA

The SNMP-CLASS policer shows 40 exceeded and 10 violated packets dropped against its 16000 bps CIR, while BGP-CLASS reports zero exceeded and zero violated with all 50 packets conformed and transmitted, confirming BGP stayed within its 64000 bps rate.

Why this answer

The output shows that for the SNMP-CLASS, 40 packets exceeded and 10 packets violated the policer, resulting in drops, while the BGP-CLASS had 0 exceeded and 0 violated packets, meaning all BGP traffic conformed to its CIR of 64000 bps. This confirms that SNMP traffic is being dropped due to exceeding its policer rate, while BGP traffic is within its rate.

Exam trap

The trap here is that candidates may misinterpret the 'exceeded' and 'violated' counters as indicating that all traffic in a class is being dropped, when in fact only packets that exceed the policer thresholds are dropped, while conforming traffic is still transmitted.

How to eliminate wrong answers

Option B is wrong because the BGP-CLASS shows 0 exceeded and 0 violated packets, indicating no drops; it is not exceeding its CIR. Option C is wrong because the output shows that conformed packets for all classes are being transmitted, so not all traffic is dropped. Option D is wrong because the command 'show policy-map control-plane' and the output explicitly state 'Service-policy input: CoPP-POLICY', meaning the policy is applied in the input direction, not output.

761
Multi-Selecthard

Which three statements about the Differentiated Services (DiffServ) QoS model are true? (Choose three.)

Select 3 answers
A.DiffServ uses the 6-bit DSCP field in the IP header to mark packets, allowing up to 64 different classes of service.
B.In DiffServ, core routers perform complex classification and marking based on deep packet inspection.
C.The Assured Forwarding (AF) PHB group provides four classes, each with three drop precedence levels.
D.DiffServ requires end-to-end signaling using RSVP to reserve bandwidth along the path.
E.The Expedited Forwarding (EF) PHB is designed for low-loss, low-latency traffic such as voice.
AnswersA, C, E

Correct. DSCP is 6 bits, providing 64 possible codepoints.

Why this answer

DiffServ is a class-based model that uses the DSCP field in the IP header to classify traffic. It provides per-hop behavior (PHB) and is scalable because core routers only need to inspect the DSCP field. The model does not guarantee end-to-end bandwidth reservation like IntServ does; instead, it relies on traffic conditioning at the edge.

762
MCQeasy

A network engineer is deploying Cisco SD-Access and needs to ensure that endpoint IP addresses are mapped to fabric locators so that the fabric can forward traffic between wired and wireless clients. Which control-plane node role is responsible for maintaining this mapping database?

A.Fabric border node
B.Fabric control-plane node
C.Fabric intermediate node
D.Fabric edge node
AnswerB

The control-plane node runs LISP and hosts the map-server and map-resolver functions that store endpoint identifier-to-routing locator mappings. Edge nodes register endpoints with it and query it to resolve destinations. This directly fulfills the requirement of maintaining the mapping database that enables fabric forwarding, making it the correct role.

Why this answer

In Cisco SD-Access, the control-plane node runs LISP map-server and map-resolver functions. Edge nodes register endpoint EID-to-RLOC mappings with it, and other edges query it to resolve destinations before encapsulating VXLAN traffic. Border and intermediate nodes handle external connectivity and underlay transport respectively, so they do not own the mapping database required by the scenario.

Exam trap

The trap here is confusing the data-plane edge role, which encapsulates traffic, with the control-plane role that actually stores and resolves endpoint locator mappings.

763
MCQmedium

A network engineer is deploying a new branch office that must use dynamic ARP inspection (DAI) on its access switches. The engineer wants to minimize manual configuration while ensuring that only valid IP-to-MAC bindings are permitted. Which feature should be enabled on the switches to provide the required binding information to DAI?

A.802.1X
B.IP Source Guard
C.DHCP snooping
D.Port security
AnswerC

DHCP snooping builds a binding table of IP address, MAC address, VLAN, and interface by snooping DHCP conversations. Dynamic ARP inspection uses this table to validate ARP packets on untrusted ports. Enabling DHCP snooping on the access switches provides the required bindings automatically, minimizing manual configuration while allowing DAI to block ARP spoofing.

Why this answer

Dynamic ARP inspection relies on the DHCP snooping binding table to validate ARP packets on untrusted ports. Without a source of legitimate IP-to-MAC bindings, DAI cannot distinguish spoofed ARP replies from valid ones. Enabling DHCP snooping on the access switches automatically populates that table as clients obtain leases, which satisfies the requirement to minimize manual configuration while protecting the branch office from ARP poisoning.

Exam trap

The trap here is assuming that IP Source Guard or port security can supply the binding table that DAI needs, when in fact DHCP snooping is the feature that builds and maintains those bindings.

764
MCQmedium

A network engineer is configuring a zone-based firewall (ZBF) on a Cisco router to allow traffic from the inside zone to the outside zone while blocking traffic from outside to inside. The engineer creates zones, assigns interfaces, and configures a policy-map with a class-map that matches all traffic from inside to outside. The engineer applies the policy to the zone-pair inside-to-outside. However, traffic from inside to outside is being dropped. What is the most likely reason?

A.The policy-map does not include an 'inspect' or 'pass' action for the matched traffic.
B.The zone-pair should be configured as outside-to-inside instead.
C.The class-map must also match return traffic for the firewall to allow the session.
D.The policy-map is applied to the wrong zone-pair; it should be applied to the inside zone.
AnswerA

In Zone-Based Firewall, a policy-map that matches traffic but does not specify an explicit action such as 'inspect' or 'pass' causes the router to apply the implicit default action of 'drop'. The class-map correctly identifies the inside-to-outside traffic, but the missing action means no forwarding or stateful inspection is performed, so all matched packets are silently discarded. The fix is to configure an 'inspect' action (or 'pass' for stateless forwarding) under the policy-map for that class.

Why this answer

In a zone-based firewall (ZBF), a policy-map applied to a zone-pair defines the actions to be taken on traffic flowing between the two zones. By default, traffic between zones is denied unless explicitly permitted. The class-map matches traffic from inside to outside, but without an 'inspect' or 'pass' action in the policy-map, the matched traffic is implicitly dropped.

The 'inspect' action enables stateful inspection and allows return traffic, while 'pass' permits traffic without stateful tracking; omitting either results in a deny.

Exam trap

Cisco often tests the misconception that simply matching traffic in a class-map and applying it to a zone-pair is enough to permit traffic, when in fact an explicit action (inspect or pass) is required in the policy-map.

How to eliminate wrong answers

Option B is wrong because the zone-pair direction is correct: traffic flows from inside to outside, so the zone-pair must be configured as inside-to-outside, not outside-to-inside. Option C is wrong because the class-map does not need to match return traffic; the 'inspect' action automatically creates stateful entries to allow return traffic. Option D is wrong because policy-maps are applied to zone-pairs, not directly to zones; applying a policy-map to the inside zone is not a valid ZBF configuration.

765
Multi-Selecthard

A network engineer is designing a Python script to interact with a Cisco Catalyst Center (formerly DNA Center) appliance using its Intent API. The script must retrieve a list of all network devices and then update the location of a specific device. Which two steps are required to authenticate and authorize the API requests? (Choose two.)

Select 2 answers
A.Send a POST request to /dna/system/api/v1/auth/token with Basic Authentication credentials to obtain a token.
B.Configure a separate API user with role-based access control (RBAC) permissions to allow read and write operations.
C.Enable the Intent API on the Catalyst Center appliance by running the intent-api enable command in the CLI.
D.Use the token obtained from the authentication endpoint in the X-Auth-Token header for subsequent API calls.
E.Include the username and password in every API request as query parameters.
AnswersA, D

The Catalyst Center Intent API uses token-based authentication. The engineer must first authenticate by sending a POST request to the /dna/system/api/v1/auth/token endpoint with Basic Authentication (username and password). The response contains a token that must be included in subsequent API calls as an X-Auth-Token header. This is the standard method for API access.

Why this answer

To authenticate with the Catalyst Center Intent API, the engineer must first obtain a token by sending a POST request to the authentication endpoint with Basic Authentication. Then, that token must be included in the X-Auth-Token header for all subsequent API calls. This two-step process ensures secure, token-based access to the API.

Exam trap

The trap here is assuming that credentials can be passed directly in each API call or that the API needs to be enabled manually, when actually a token must be obtained and reused.

766
MCQmedium

A network engineer is configuring a Cisco switch for 802.1X with RADIUS authentication. The switch is also configured with 'aaa authentication dot1x default group radius'. The engineer wants to use a single RADIUS server for both authentication and accounting. The RADIUS server is configured with the same shared secret for both services. The engineer configures 'radius-server host 10.1.1.1 auth-port 1812 acct-port 1813 key cisco123'. However, accounting records are not being sent to the server. The engineer verifies that the RADIUS server is reachable and that accounting is enabled on the server. What is the most likely cause?

A.The switch is missing the 'aaa accounting dot1x default start-stop group radius' command to enable accounting for 802.1X sessions.
B.The RADIUS server is using a different accounting port than 1813; the switch should use port 1646.
C.The switch must have 'aaa new-model' configured before accounting can work.
D.The RADIUS server's shared secret for accounting is different from the authentication secret.
AnswerA

In Cisco IOS, 802.1X authentication can succeed while accounting remains inactive because accounting is an independent AAA service. The `aaa accounting dot1x default start-stop group radius` command explicitly instructs the switch to generate start and stop records for authenticated sessions and forward them to the RADIUS server. Simply defining a RADIUS server or enabling authentication does not create accounting traffic, so without this global configuration command, the switch will never send interim or final accounting updates.

Why this answer

The switch is configured for RADIUS authentication but lacks the 'aaa accounting dot1x default start-stop group radius' command, which is required to enable accounting for 802.1X sessions. Without this command, the switch will not send accounting records to the RADIUS server, even if the server is reachable and accounting is enabled on it. The 'aaa authentication dot1x default group radius' command only enables authentication, not accounting.

Exam trap

Cisco often tests the distinction between authentication and accounting configuration, leading candidates to assume that enabling authentication automatically enables accounting, when in fact they require separate commands under the 'aaa' configuration mode.

How to eliminate wrong answers

Option B is wrong because port 1813 is the standard RADIUS accounting port defined in RFC 2866, and port 1646 is the legacy port used by older implementations; the switch is correctly configured with port 1813, and the server should use the same standard port. Option C is wrong because 'aaa new-model' is required to enable AAA services on Cisco IOS devices, but the presence of 'aaa authentication dot1x default group radius' indicates that 'aaa new-model' is already configured; the issue is the missing accounting command. Option D is wrong because the problem states the RADIUS server uses the same shared secret for both services, and the 'radius-server host' command applies the same key to both authentication and accounting ports; a mismatch would cause authentication to fail as well, which is not the case.

767
MCQhard

A network engineer runs the following command on Router R1: R1# show ip bgp summary BGP router identifier 10.0.0.1, local AS number 65001 BGP table version is 10, main routing table version 10 Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 192.168.1.2 4 65002 1024 1020 10 0 0 02:30:15 5 192.168.1.3 4 65003 500 498 10 0 0 00:15:20 3 10.0.0.2 4 65004 0 0 0 0 0 never Active Based on this output, what can be concluded?

A.All BGP neighbors are fully established.
B.The BGP session to 10.0.0.2 is down due to a TCP connection issue.
C.The BGP session to 192.168.1.3 has been up for 2 hours 30 minutes.
D.The router is receiving prefixes from all neighbors.
AnswerB

The BGP session to 10.0.0.2 is down due to a TCP connection issue. The Active state indicates that the local router is attempting to initiate a TCP connection to 10.0.0.2 but has not received a successful three-way handshake—either the remote peer is unreachable, a firewall is blocking TCP port 179, or the remote BGP process is not responding. Until the TCP session is established, BGP cannot exchange routes, which is why 0 prefixes are received and the session remains down.

Why this answer

The BGP session to neighbor 10.0.0.2 is in the 'Active' state with 'never' uptime and zero messages sent/received. This indicates that the router is actively trying to establish a TCP connection (port 179) but has not yet succeeded, typically due to a connectivity issue such as an unreachable IP, ACL blocking, or incorrect neighbor configuration. The 'Active' state specifically means the BGP process is waiting for the TCP connection to complete, confirming a TCP-level problem.

Exam trap

Cisco often tests the distinction between 'Active' and 'Idle' states—candidates may confuse 'Active' as meaning the session is up or partially up, but 'Active' specifically indicates a TCP connection failure, not a BGP configuration error like wrong AS number (which would cause 'Idle').

How to eliminate wrong answers

Option A is wrong because the neighbor 10.0.0.2 is in 'Active' state, not 'Established', so not all BGP neighbors are fully established. Option C is wrong because the 'Up/Down' column shows 02:30:15 for neighbor 192.168.1.2, not 192.168.1.3, which has an uptime of 00:15:20. Option D is wrong because the router is receiving prefixes only from the two established neighbors (5 and 3 prefixes), but the neighbor 10.0.0.2 has zero prefixes received (State/PfxRcd is blank), so it is not receiving prefixes from all neighbors.

768
Multi-Selectmedium

Which two statements about YANG data models and their role in model-driven telemetry are true? (Choose two.)

Select 2 answers
A.YANG is a data modeling language used to define the structure of configuration and operational state data.
B.OpenConfig YANG models are vendor-specific and only supported on Cisco devices.
C.Native YANG models are developed by the device vendor and may expose platform-specific features.
D.IETF YANG models are the only models that can be used for model-driven telemetry subscriptions.
E.YANG is a transport protocol used to stream telemetry data from network devices to collectors.
AnswersA, C

YANG defines hierarchical schemas for configuration and operational state, using containers, lists and leaves to model device data. This structure underpins model-driven telemetry, where subscribed paths stream state changes, satisfying the stem's requirement that YANG models both configuration and operational data.

Why this answer

Option A is correct because YANG (RFC 6020/7950) is a data modeling language that defines the hierarchical structure, syntax, and semantics of configuration data and operational state data on network devices, which is the foundation for model-driven telemetry. Option C is correct because native YANG models are authored by the device vendor (e.g., Cisco IOS XE native models) and can expose platform-specific features and proprietary data nodes not covered by standard models. Option B is incorrect because OpenConfig YANG models are vendor-neutral, community-developed models intended to work across multiple vendors, not vendor-specific or Cisco-only.

Option D is incorrect because model-driven telemetry subscriptions can use native, OpenConfig, and IETF YANG models, not IETF models exclusively. Option E is incorrect because YANG is a modeling language, not a transport protocol; telemetry streaming is carried by protocols such as gRPC, NETCONF, or RESTCONF.

Exam trap

The trap here is confusing YANG with a transport protocol or thinking OpenConfig models are vendor-specific; candidates might also think only IETF models are used for telemetry.

769
MCQmedium

An engineer uses the following Ansible playbook to configure an interface on a Cisco IOS-XE device using the cisco.ios.ios_interfaces module: ```yaml --- - name: Configure interface hosts: cisco-routers gather_facts: no tasks: - name: Set interface description cisco.ios.ios_interfaces: config: - name: GigabitEthernet0/1 description: "Uplink to Core" enabled: true state: replaced ``` What is the result of running this playbook?

A.The interface will have the description set and all other parameters remain unchanged.
B.The playbook will fail because 'enabled' is not a valid parameter for ios_interfaces.
C.The interface will be configured with only the description and enabled state, removing any other existing configuration.
D.The playbook will fail because 'state: replaced' requires a 'before' and 'after' state.
AnswerC

With `state: replaced`, the cisco.ios.ios_interfaces module treats the supplied config as the complete desired state for GigabitEthernet0/1, so any existing settings not listed — such as IP addressing, MTU or speed — are removed. Only the description and enabled state remain, satisfying the stem's requirement to strip other configuration.

Why this answer

The cisco.ios.ios_interfaces module with state: replaced enforces the exact declared configuration on the interface, meaning any parameters not specified in the task are reset to their defaults. Since only 'description' and 'enabled' are declared, all other existing interface settings (such as IP addressing, MTU, speed, duplex, or other L2/L3 attributes) are removed or reverted. This is the defining behavior of 'replaced' versus 'merged' in declarative Ansible network modules.

Exam trap

350-401 often tests the distinction between Ansible state values (merged vs. replaced vs. overridden), and candidates commonly assume 'replaced' behaves like 'merged' and only adds configuration.

How to eliminate wrong answers

Option A is wrong because it describes the behavior of state: merged (which only overlays declared attributes and leaves everything else intact), not state: replaced. Option B is wrong because 'enabled' is a valid boolean parameter of cisco.ios.ios_interfaces that controls the administrative up/down state of the interface. Option D is wrong because 'replaced' does not require before/after state blocks — that concept belongs to other declarative tools or to state: overridden semantics, not to this module's parameter schema.

770
MCQhard

A network engineer is configuring a Cisco IOS XE router to support NETCONF over SSH. The requirement is to allow a remote management station to retrieve and modify the router's configuration using NETCONF. Which command must be used to enable the NETCONF subsystem on the router?

A.netconf-yang
B.restconf
C.ip http server
D.ssh server netconf
AnswerA

The command 'netconf-yang' enables the NETCONF subsystem on a Cisco IOS XE router. It starts the NETCONF server and allows the router to be managed via NETCONF over SSH. This command is essential for enabling programmatic access to the router's configuration and operational data using YANG models. Without this command, the router will not accept NETCONF sessions, even if SSH is configured.

Why this answer

To enable NETCONF over SSH on a Cisco IOS XE router, the 'netconf-yang' command must be configured. This command starts the NETCONF server and allows the router to be managed using NETCONF. It is a prerequisite for establishing NETCONF sessions and is essential for automated configuration and monitoring.

Exam trap

The trap here is confusing NETCONF with RESTCONF or assuming that enabling the HTTP server is sufficient for NETCONF access.

771
Multi-Selectmedium

A network engineer is deploying 802.1X on Catalyst access switches with Cisco ISE as the RADIUS server. Some endpoints, such as printers and badge readers, do not support 802.1X supplicants. The design must allow these devices onto a restricted VLAN while still requiring authentication for laptops. Which TWO mechanisms should the engineer configure to achieve this? (Choose two.)

Select 2 answers
A.Configure MAB (MAC Authentication Bypass) on the switch ports to authenticate non-supplicant devices using their MAC address against ISE.
B.Apply an ACL that permits only MAC addresses in the OUI range of the printer vendor.
C.Configure the switch to use TACACS+ for endpoint authentication instead of RADIUS.
D.Disable 802.1X on the ports used by non-supplicant devices and assign them to a static VLAN.
E.Enable authentication order dot1x mab on the switch ports so the switch tries 802.1X first and falls back to MAB.
AnswersA, E

MAB allows devices without an 802.1X supplicant to be authenticated by their MAC address, which ISE validates against its identity store or profiling database. This lets printers and badge readers obtain limited access through the same port configuration that serves supplicant-capable laptops. MAB is the standard fallback for non-supplicant endpoints in Cisco 802.1X deployments.

Why this answer

The design needs one port configuration that serves both endpoint types. MAB authenticates non-supplicant devices by MAC address through ISE, and the authentication order of dot1x followed by mab ensures supplicant-capable laptops use 802.1X while printers and badge readers fall back to MAB. Together these provide differentiated, authenticated access without per-port manual reconfiguration.

Exam trap

The trap here is disabling 802.1X on ports used by non-supplicant devices, which removes authentication instead of adding a fallback method.

772
MCQmedium

A network engineer is deploying Cisco DNA Center Assurance to monitor a campus fabric. The engineer needs to verify that the fabric underlay and overlay health scores are being calculated correctly. Which data source does Cisco DNA Center Assurance primarily use to compute the fabric health score?

A.Syslog messages forwarded to the DNA Center syslog collector
B.SNMP polling of fabric edge nodes every 5 minutes
C.NetFlow records exported from fabric edge switches
D.Streaming telemetry from fabric nodes via the network data platform
AnswerD

Cisco DNA Center Assurance uses streaming telemetry from fabric nodes, collected by the Network Data Platform (NDP), to compute health scores. This provides near-real-time data on underlay and overlay performance, including latency, packet loss, and fabric control plane status. The NDP aggregates and analyzes this data to generate the health score.

Why this answer

Cisco DNA Center Assurance computes fabric health scores using streaming telemetry collected by the Network Data Platform. This telemetry includes underlay and overlay performance metrics, control plane status, and client health. The NDP processes this data to generate real-time health scores, enabling proactive monitoring and troubleshooting.

Other data sources like SNMP, syslog, or NetFlow supplement assurance but are not the primary basis for fabric health scoring.

Exam trap

The trap here is assuming that SNMP polling or NetFlow is the primary data source for DNA Center Assurance health scores, when in fact streaming telemetry via the Network Data Platform is the foundation.

773
MCQmedium

A network engineer is deploying a new wireless LAN controller (WLC) in a campus network. The WLC must manage 200 access points across three buildings. The engineer configures the WLC with a management IP address and enables CAPWAP. However, the access points fail to join the WLC. The APs are in the same VLAN as the WLC and can ping the WLC's management IP. What is the most likely cause of the APs not joining?

A.The WLC does not have a CAPWAP source interface configured.
B.The APs are not configured with DHCP option 43 to point to the WLC.
C.The APs are running an incompatible IOS version that does not support CAPWAP.
D.The APs must be assigned a static IP address to join the WLC.
AnswerB

This is correct. APs typically use DHCP to obtain an IP address and look for DHCP option 43 to discover the WLC. Without option 43, they cannot find the WLC even if they have IP connectivity.

Why this answer

The APs are in the same VLAN and can ping the WLC, but they still fail to join. Since the APs use DHCP by default, they rely on DHCP option 43 to obtain the WLC's IP address for CAPWAP discovery. Without this option, the APs do not know which WLC to join, even though they have IP connectivity.

Option A is incorrect because the management interface is the default CAPWAP source; a separate source interface is not required for APs in the same VLAN.

Exam trap

The trap is that candidates may assume that because APs can ping the WLC, they should be able to join automatically. In reality, APs need to discover the WLC, which commonly relies on DHCP option 43. Without it, APs cannot initiate the CAPWAP join process even with layer 3 connectivity.

How to eliminate wrong answers

Option B is wrong because DHCP option 43 is used to provide the WLC IP address to APs when they are in a different subnet or need to discover the WLC via DHCP; in this scenario, the APs are in the same VLAN as the WLC and can already ping it, so they would use CAPWAP Layer 3 discovery (broadcast or DNS) without needing DHCP option 43. Option C is wrong because the question states the APs are running CAPWAP (the engineer enables CAPWAP on the WLC), and incompatible IOS versions would typically cause a different error, such as a version mismatch message, not a failure to join when the APs can reach the WLC. Option D is wrong because APs can join a WLC using DHCP-assigned IP addresses; static IP assignment is not a requirement for CAPWAP join, and the APs already have IP connectivity via DHCP.

774
MCQeasy

A network administrator needs to securely manage a Cisco Catalyst switch remotely. The requirement is to encrypt all management traffic, including username and password, between the administrator's workstation and the switch. Which management protocol should be enabled on the switch to meet this requirement?

A.Telnet
B.HTTP
C.SNMPv2c
D.SSH version 2
AnswerD

SSH version 2 encrypts the entire management session, including authentication credentials and command output, using strong cryptography. Enabling SSHv2 on the switch and disabling Telnet ensures that remote CLI administration is confidential and integrity-protected. This directly satisfies the requirement that all management traffic between the administrator's workstation and the switch be encrypted, making SSHv2 the correct management protocol.

Why this answer

SSH version 2 encrypts the full management session, protecting credentials and commands in transit, which is exactly what the policy requires. Telnet and HTTP send data in cleartext, and SNMPv2c is neither encrypted nor intended for interactive CLI management. Enabling SSHv2 and disabling insecure protocols satisfies the encrypted remote administration requirement.

Exam trap

The trap here is overlooking that SNMPv2c management traffic is cleartext, so only SSHv2 among the choices provides encrypted interactive administration.

775
MCQhard

A security team is deploying Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. They notice that after applying a CoPP policy, OSPF adjacency with a directly connected neighbor flaps intermittently. Which action should the engineer take to resolve the issue while maintaining control plane protection?

A.Add a class-map matching OSPF traffic and associate it with a policer that has a higher committed information rate.
B.Configure OSPF authentication on the interface to reduce the volume of OSPF packets processed.
C.Remove the CoPP policy from the control plane and rely on ACLs on the management interface.
D.Change the CoPP policy to use a police rate of 8000 pps for all traffic classes.
AnswerA

OSPF hello and LSA traffic to the route processor must be permitted at a sufficient rate to maintain adjacency. Creating a class-map for OSPF and assigning a policer with an adequate CIR ensures control plane protection remains in place while allowing legitimate routing protocol traffic, which resolves the flapping caused by the default policer dropping OSPF packets.

Why this answer

CoPP uses class-maps and policy-maps to rate-limit traffic destined to the control plane. If the default policer for routing protocols is too low, OSPF hellos can be dropped, causing adjacency flaps. Creating a dedicated class for OSPF and assigning a policer with a higher committed information rate allows legitimate routing traffic while still protecting the route processor.

Exam trap

The trap here is assuming that removing CoPP or applying a blanket high rate is acceptable, rather than tuning the specific class that is being dropped.

776
MCQeasy

An enterprise is deploying Cisco SD-WAN with vManage, vSmart, vBond, and vEdge routers. The architect must design the control plane to securely onboard new vEdge routers and establish DTLS/TLS tunnels. Which component is responsible for the initial authentication and coordination of control plane connections?

A.vManage
B.vSmart
C.vBond
D.vEdge
AnswerC

vBond is the SD-WAN's trust anchor and the first server a vEdge router contacts. It verifies the router's certificate against a preconfigured list, performs NAT traversal, and supplies the router with the list of active vSmart and vManage controllers. Without this orchestration, a vEdge router has no secure path to join the overlay network.

Why this answer

In Cisco SD-WAN, vBond is the orchestrator responsible for the initial authentication and coordination of control plane connections. When a new vEdge router attempts to join the fabric, it first contacts vBond, which authenticates the device using its serial number and certificate, then provides the IP addresses of the vSmart controllers and vManage. This establishes the DTLS/TLS tunnels for the control plane.

Exam trap

Cisco often tests the misconception that vManage handles all initial authentication because it is the central management interface, but vBond is specifically designed for orchestrating the initial control plane connections.

How to eliminate wrong answers

Option A is wrong because vManage is the management and monitoring plane, handling configuration, policy, and analytics, but it does not perform initial authentication or coordinate control plane connections. Option B is wrong because vSmart is the control plane controller that distributes routing and policy information via OMP, but it relies on vBond for initial device onboarding and authentication. Option D is wrong because vEdge is the data plane router that initiates connections to vBond, vSmart, and vManage, but it is not responsible for authenticating or coordinating other components.

777
Drag & Dropmedium

Drag and drop the steps of NBAR2 application recognition and classification steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, enable NBAR2 on the interface using ip nbar protocol-discovery. Then create a class-map to match the application using match protocol. Next, create a policy-map to mark or apply QoS actions.

Apply the policy-map to the interface. Finally, verify NBAR2 statistics using show ip nbar protocol-discovery.

778
MCQmedium

An engineer is configuring multicast on a Cisco switch running IOS. The switch is acting as the IGMP querier for a VLAN. The engineer notices that multicast traffic is being flooded to all ports in the VLAN, even though only a few receivers have joined the group. The engineer checks the IGMP snooping configuration and sees that IGMP snooping is enabled globally and on the VLAN. What is the most likely cause of the flooding?

A.The IGMP querier is not elected on the VLAN.
B.The multicast source is connected to a trunk port.
C.The switch has PIM enabled on the VLAN interface.
D.The receivers are using IGMPv3.
AnswerA

IGMP snooping builds and refreshes its forwarding table only when IGMP queries are present on the VLAN to solicit membership reports from receivers. If no IGMP querier is elected on the VLAN (for example, no multicast router is enabled to send general queries and the switch's querier feature is disabled), the switch never receives periodic reports and cannot maintain the multicast group, so it floods multicast frames to every port. This is the direct cause of the flooding problem.

Why this answer

When IGMP snooping is enabled but no IGMP querier exists on the VLAN, the switch cannot learn which ports have interested receivers because no general queries are sent. Without querier-generated queries, the snooping database remains empty, causing the switch to flood multicast traffic to all ports in the VLAN as if snooping were disabled.

Exam trap

Cisco often tests the misconception that enabling IGMP snooping alone is sufficient to prevent flooding, without realizing that an IGMP querier must be present on the VLAN to populate the snooping table.

How to eliminate wrong answers

Option B is wrong because connecting a multicast source to a trunk port does not inherently cause flooding; IGMP snooping still operates on the VLAN and can learn receiver ports from IGMP reports. Option C is wrong because PIM (Protocol Independent Multicast) is a Layer 3 routing protocol and does not affect Layer 2 IGMP snooping behavior on a switch; enabling PIM on the VLAN interface does not disable or interfere with IGMP snooping. Option D is wrong because IGMPv3 receivers still send IGMP reports in response to queries, and IGMP snooping supports IGMPv3; the version does not cause flooding.

779
MCQmedium

A network architect is selecting a switching platform for a data center access layer that must support lossless Ethernet for FCoE. The platform must provide per-priority flow control so that storage traffic can be paused without affecting LAN traffic. Which technology should the architect specify?

A.EtherChannel with LACP
B.Jumbo frame support
C.Priority Flow Control (PFC)
D.Link Layer Discovery Protocol (LLDP)
AnswerC

PFC is the correct choice because it operates on IEEE 802.1Q CoS priorities and allows a receiver to send a PAUSE frame for a specific priority, pausing only the storage class of traffic while LAN traffic on other priorities continues unimpeded. This satisfies the requirement for lossless FCoE without head-of-line blocking across the entire link.

Why this answer

Lossless Ethernet for FCoE requires a mechanism that can pause a specific traffic class without stopping all traffic on the link. Priority Flow Control does exactly that by acting on CoS values, allowing storage frames to be paused while ordinary LAN traffic continues. LLDP, EtherChannel, and jumbo frames each address different concerns and none provides per-priority pause.

Exam trap

The trap here is assuming that enabling jumbo frames or EtherChannel is sufficient for lossless FCoE, when only a per-priority pause mechanism prevents drops for the storage class.

780
MCQmedium

A network engineer at a branch office needs to configure a Cisco IOS router to obtain its WAN interface IPv4 address dynamically from the ISP using DHCP while also ensuring the ISP can reach a web server hosted on the internal LAN at 10.10.10.50. Which single command on the router's WAN interface accomplishes the address acquisition requirement?

A.ip dhcp pool WAN_POOL
B.ip helper-address 203.0.113.1
C.ip address dhcp
D.ip address negotiated
AnswerC

This command configures the interface as a DHCP client, allowing it to dynamically request an IPv4 address, subnet mask, default gateway, and DNS servers from the ISP's DHCP server. It satisfies the requirement to obtain the WAN address dynamically without manual configuration, and is the standard Cisco IOS method for client-side DHCP on an interface.

Why this answer

The requirement is for the router to dynamically obtain an IPv4 address from the ISP. The ip address dhcp interface command enables DHCP client functionality, which is the correct method for Ethernet WAN interfaces. Other options either configure the router as a DHCP server, forward DHCP requests, or use PPP-based negotiation, none of which meet the scenario's need for standard DHCP client behavior on an Ethernet WAN link.

Exam trap

The trap here is confusing DHCP client and DHCP server roles, or assuming that ip address negotiated works for Ethernet DHCP.

781
MCQhard

A network automation team uses a Python script with the ncclient library to configure a Cisco IOS XE device via NETCONF. The script establishes a session and sends an <edit-config> RPC with a candidate datastore. After sending the RPC, the script immediately sends a <commit> RPC, but the device returns an error indicating that the candidate datastore is not supported. Which statement explains the cause of this error?

A.The device requires the use of NETCONF over SSH instead of TLS for candidate datastore operations.
B.The script must first send a <lock> RPC on the candidate datastore before editing.
C.The script must send a <validate> RPC before the <commit> to ensure the candidate configuration is valid.
D.The device does not support the candidate datastore, so the script must use the running datastore directly.
AnswerD

The error explicitly states that the candidate datastore is not supported. Many Cisco IOS XE devices support only the running datastore for NETCONF edits, not the candidate datastore. The candidate datastore allows staging changes before committing, but if it is unsupported, the <edit-config> must target the running datastore. The script should be modified to use the running datastore instead of candidate, and the <commit> operation is unnecessary because changes take effect immediately.

Why this answer

The error indicates that the candidate datastore is not supported by the device. Cisco IOS XE devices often support only the running datastore for NETCONF edits. The candidate datastore allows a two-phase commit, but if it is not available, the script must target the running datastore.

The <commit> operation is only for the candidate datastore. Therefore, the script should be changed to edit the running datastore directly, which applies changes immediately.

Exam trap

The trap here is assuming all NETCONF devices support the candidate datastore, when many Cisco IOS XE devices only support the running datastore.

782
MCQeasy

A network engineer is deploying a virtualized branch solution using Cisco Enterprise Network Function Virtualization Infrastructure Software (NFVIS). The goal is to run multiple virtual network functions such as a virtual router and a virtual firewall on a single Cisco UCS E-Series or C-Series server at the branch. Which statement accurately describes how NFVIS supports this deployment?

A.NFVIS provides a hypervisor and lifecycle management for hosting multiple VNFs on the branch server
B.NFVIS replaces the need for any hypervisor by running VNFs directly on bare metal without virtualization
C.NFVIS only supports a single VNF per physical server and cannot host multiple virtual machines
D.NFVIS is a cloud-only orchestration tool that cannot run on branch appliances
AnswerA

Cisco NFVIS is a Linux KVM-based virtualization platform that provides the hypervisor, VM lifecycle management, and orchestration APIs needed to host multiple virtual network functions on a single branch server. It allows the engineer to deploy, monitor, and manage VNFs such as virtual routers and firewalls from a centralized interface, directly supporting the multi-VNF branch design in the scenario.

Why this answer

Cisco NFVIS is a KVM-based virtualization platform that supplies the hypervisor, VM lifecycle management, and orchestration needed to run multiple virtual network functions on a single branch server. This enables consolidating a virtual router, virtual firewall, and other services at the branch, which matches the engineer's deployment goal.

Exam trap

The trap here is assuming NFVIS is only an orchestration overlay or that it removes the hypervisor, when it actually embeds a KVM hypervisor to host multiple VNFs.

783
Multi-Selecthard

A network engineer is using NetFlow to monitor traffic on a Cisco router. The engineer wants to export NetFlow data to a collector for analysis. Which two commands are required to configure NetFlow export on the router? (Choose two.)

Select 2 answers
A.ip flow-export destination 192.168.1.100 2055
B.ip flow-export version 9
C.ip flow ingress
D.ip flow-cache timeout active 1
E.ip flow-top-talkers
AnswersA, B

The ip flow-export destination command specifies the IP address and port of the NetFlow collector. This is required to send NetFlow data to an external collector. Without this command, the router would not know where to export the flow records, so it is essential for NetFlow export configuration.

Why this answer

To export NetFlow data, the router must be configured with the destination collector address and port, and the export version. The ip flow-export destination command specifies where to send the data, and the ip flow-export version command specifies the format. These two commands are essential for the export process.

Enabling NetFlow on interfaces is also needed, but that is not part of the export configuration commands.

Exam trap

The trap here is thinking that enabling NetFlow on an interface is part of the export configuration; interface commands are separate from export commands.

784
MCQhard

A network engineer is troubleshooting a VMware vSphere cluster where a VM with a large memory footprint (256 GB) is experiencing poor performance. The host has two NUMA nodes, each with 128 GB of memory. The VM is configured with 256 GB of memory and 4 vCPUs. Performance monitoring shows high memory latency and CPU ready time. What is the most likely cause?

A.The VM's memory size forces it to span multiple NUMA nodes, increasing memory access latency.
B.The VM has too few vCPUs for the memory size.
C.The host is using memory ballooning to reclaim memory from other VMs.
D.The host's memory is overcommitted.
AnswerA

On a NUMA (Non-Uniform Memory Access) system, each node contains local memory with low latency, while accessing memory from a remote node traverses the QPI/UPI interconnect, adding significant latency. If a VM's memory allocation exceeds the capacity of a single NUMA node, the hypervisor must back the guest's physical memory with pages from multiple nodes, forcing some accesses to be remote. This VM-to-NUMA-node mismatch directly increases memory access latency and is the correct explanation, because the symptom is memory latency, not CPU or host pressure.

Why this answer

The VM is configured with 256 GB of memory, but each NUMA node on the host has only 128 GB. Since a single NUMA node cannot satisfy the VM's memory allocation, the hypervisor must split the VM across both NUMA nodes. This forces memory accesses to cross the NUMA interconnect (e.g., QPI or UPI), which introduces significantly higher latency compared to local memory access, directly causing the observed high memory latency and increased CPU ready time.

Exam trap

Cisco often tests the misconception that memory performance issues are always due to overcommitment or ballooning, but the trap here is that the VM's memory size exactly matches the total host memory, leading candidates to overlook the NUMA boundary constraint.

How to eliminate wrong answers

Option B is wrong because the number of vCPUs (4) is not directly related to memory latency; CPU ready time is affected by vCPU-to-pCPU scheduling contention, not by memory size. Option C is wrong because memory ballooning reclaims memory from VMs to avoid overcommitment, but it does not cause high memory latency or CPU ready time; it would instead cause guest OS swapping or performance degradation due to memory pressure. Option D is wrong because memory overcommitment would lead to ballooning or swapping, not specifically to NUMA-spanning latency; the host has exactly 256 GB total memory, so the VM's allocation is not overcommitted.

785
MCQmedium

A company runs a Cisco IOS router as the WAN edge. The security team wants to detect and log traffic that matches a set of known malicious signatures without blocking legitimate traffic, while still dropping clearly malformed packets. Which technology should be deployed on the router?

A.Zone-Based Policy Firewall with inspect actions
B.IPsec VPN with AES-256 encryption between peers
C.Cisco IOS Intrusion Prevention System with signature categories set to alert
D.Control Plane Policing with a rate limit on management traffic
AnswerC

Cisco IOS IPS uses signatures to inspect traffic for known attack patterns and can be configured per signature or category to produce alerts rather than drops. This supports detection and logging of malicious traffic without blocking legitimate sessions, while malformed packets can still be dropped by specific signatures or by the IPS engine itself.

Why this answer

Cisco IOS IPS inspects packets against a signature database and can be tuned to alert on matching traffic instead of dropping it, which meets the detection-and-logging requirement while preserving legitimate flows. Malformed packets can be handled by specific drop signatures, giving the security team both visibility and selective enforcement on the WAN edge router.

Exam trap

The trap here is assuming any stateful or encrypted feature provides signature-based detection, when only IPS matches known attack patterns.

786
MCQhard

A network engineer configures SNMPv3 on a Cisco router for secure monitoring. The configuration includes 'snmp-server group ADMIN v3 priv', 'snmp-server user admin ADMIN v3 auth sha cisco123 priv aes 128 cisco456', and 'snmp-server host 10.1.1.2 version 3 priv admin'. The NMS is configured with the same credentials. However, the NMS cannot poll the router. The engineer verifies that the router's SNMP agent is enabled. What is the most likely cause?

A.The SNMPv3 user is not associated with the group correctly.
B.The NMS must be configured with the router's SNMP engine ID.
C.The 'priv' keyword in the host command should be 'auth' instead.
D.The AES encryption key must be exactly 16 characters.
AnswerB

The NMS must be provisioned with the router's local SNMP engine ID because SNMPv3 user-based authentication (USM) derives each user's authentication and privacy keys by hashing the passphrase together with the authoritative engine ID. Without the correct engine ID, the NMS calculates a different localized key than the router, so the HMAC validation fails and the router silently discards the request after sending it with 'noAuth' or the NMS sees an authentication failure. Even if the username, passwords, and AES settings are identical, a mismatched engine ID always breaks SNMPv3 authentication, making this the necessary corrective action.

Why this answer

The most likely cause is that the NMS must be configured with the router's SNMP engine ID. In SNMPv3, the engine ID is used to derive authentication and encryption keys. Even if the username and passwords match, if the NMS does not know the router's engine ID, it will compute different keys and fail to authenticate or decrypt responses, preventing polling.

Exam trap

Cisco often tests the subtle requirement that SNMPv3 key derivation depends on the engine ID, leading candidates to overlook this and incorrectly focus on user-group association, security level keywords, or key length restrictions.

How to eliminate wrong answers

Option A is wrong because the configuration 'snmp-server user admin ADMIN v3 auth sha cisco123 priv aes 128 cisco456' correctly associates the user 'admin' with the group 'ADMIN' via the group name in the user command. Option C is wrong because the 'priv' keyword in the host command specifies that the NMS must use both authentication and privacy (encryption) to communicate, which matches the user's configured security level; changing it to 'auth' would require only authentication, not encryption, and would not fix the issue. Option D is wrong because the AES encryption key in the 'snmp-server user' command is a passphrase, not a fixed-length key; Cisco IOS accepts passphrases of varying lengths and derives the actual 128-bit key from them.

787
MCQmedium

A network administrator runs the following command on a switch: Switch# show aaa method-list Method List Name: default Type: authentication Group: radius Group: local Method List Name: console Type: authentication Group: local Method List Name: default Type: authorization Group: tacacs+ Group: local Based on this output, what can be concluded?

A.Authorization for all users uses RADIUS.
B.Console authentication uses RADIUS as fallback.
C.RADIUS is the primary authentication method for default login.
D.TACACS+ is used for authentication.
AnswerC

Within the default authentication method list, group radius appears as the first method, so when a new session triggers authentication, the device forwards the credentials to the RADIUS server before considering local or any other fallback. This makes RADIUS the primary source of truth for verifying usernames and passwords for default login, which typically applies to remote VTY users. Only if RADIUS cannot be reached or the server responds with an error would the later methods be attempted.

Why this answer

The output shows that the default method list for authentication uses RADIUS as the first method and local as the fallback. Since 'default' applies to all lines and services that do not have a named list, RADIUS is the primary authentication method for default login. Option C correctly identifies this primary role of RADIUS.

Exam trap

Cisco often tests the distinction between authentication and authorization method lists; the trap here is assuming that the default authorization list's use of TACACS+ implies it is also used for authentication, when in fact the authentication default list uses RADIUS.

How to eliminate wrong answers

Option A is wrong because the default authorization list uses TACACS+ as the primary method, not RADIUS; RADIUS is not even listed in the authorization default list. Option B is wrong because the console authentication list uses only local authentication, with no RADIUS fallback. Option D is wrong because TACACS+ is used for authorization, not authentication; the authentication default list uses RADIUS and local, not TACACS+.

788
MCQmedium

Given the following snippet from a Cisco 9800 WLC: ap ethernet-port default-ethernet-port description "Default Ethernet Port" mode trunk allowed vlan 10,20,30 native vlan 10 What is the effect of this configuration on the AP?

A.The AP's Ethernet port will tag all traffic with VLAN 10.
B.The AP will use VLAN 10 for management traffic and VLANs 20 and 30 for client traffic.
C.The AP will only allow VLAN 10 traffic.
D.The AP's Ethernet port is configured as an access port.
AnswerB

This is correct because the switchport trunk native vlan 10 command makes VLAN 10 the untagged, management VLAN for the AP, while the switchport trunk allowed vlan 20,30 command permits tagged client traffic on those VLANs. The AP's management IP resides in VLAN 10, and SSIDs are mapped to VLAN 20 and 30 for client data, maintaining separation between management and user traffic.

Why this answer

The configuration sets the AP's Ethernet port as a trunk port with VLAN 10 as the native VLAN and allowed VLANs 10, 20, and 30. In Cisco wireless architectures, the AP uses the native VLAN (VLAN 10) for management traffic (e.g., CAPWAP control) and the other allowed VLANs (20 and 30) for client data traffic, which is tunneled via CAPWAP to the WLC. This matches option B.

Exam trap

Cisco often tests the misconception that the native VLAN is always tagged or that the AP's trunk port behaves like a switch trunk, when in fact the native VLAN carries untagged management traffic and the allowed VLANs carry tagged client traffic.

How to eliminate wrong answers

Option A is wrong because VLAN 10 is the native VLAN, so traffic on VLAN 10 is sent untagged, not tagged; only traffic on VLANs 20 and 30 would be tagged. Option C is wrong because the 'allowed vlan 10,20,30' command permits multiple VLANs, not just VLAN 10. Option D is wrong because the 'mode trunk' command explicitly configures the port as a trunk port, not an access port.

789
MCQmedium

A network engineer is troubleshooting why a newly added Cisco Catalyst 9300 switch is not appearing in Cisco DNA Center's topology view, even though it is reachable via SSH from the management network. The switch has been configured with the correct SNMP community string. Which protocol must be enabled on the switch for Cisco DNA Center to discover and monitor it?

A.NETCONF
B.Syslog
C.IP SLA
D.SNMP
AnswerD

Cisco DNA Center uses SNMP to discover and monitor network devices. Even if SSH is reachable and the community string is correct, SNMP must be enabled on the switch for DNA Center to poll device information such as interfaces, CPU, and topology data. Without SNMP, the device will not appear in the topology view or be monitored.

Why this answer

Cisco DNA Center relies on SNMP to discover and monitor network devices. Although SSH may be used for CLI-based configuration, SNMP is the protocol that provides the management data for topology and health monitoring. Without SNMP enabled and correctly configured, the switch will not be discovered, regardless of SSH reachability or correct community strings.

Exam trap

The trap here is assuming that SSH access alone is sufficient for Cisco DNA Center to discover and monitor a device, when SNMP is the required protocol for discovery and assurance.

790
MCQmedium

A network engineer runs the following command on Switch SW2: SW2# show interfaces port-channel 1 etherchannel Port-channel1 : Age of the Port-channel = 0d:00h:10m:32s Logical slot/port = 16/1 Number of ports = 2 HotStandby port = null Port state = Port-channel Ag-Inuse Protocol = LACP Ports in the Port-channel: Index Load Port EC state No of bits ------+------+------+----------------+---------- 0 00 Gi0/0 Active 4 1 00 Gi0/1 Active 4 Time since last port bundled: 0d:00h:05m:23s Gi0/1 Based on this output, what can be concluded?

A.The EtherChannel is not operational because the load is zero.
B.Both member ports are in Active state, meaning they are participating in LACP negotiation.
C.The port-channel is in 'Ag-Inuse' state, which means it is not yet forwarding traffic.
D.Load balancing is set to source-destination IP, causing the zero load values.
AnswerB

Both member ports being in the 'Active' state means they are in LACP active mode and are actively exchanging LACP data units (LACPDUs) to negotiate and maintain the aggregation. This is a key indicator that the physical links have successfully formed an operational bundle, alongside the port-channel showing 'Ag-Inuse'. Thus, this is the correct observation about the EtherChannel's operational status.

Why this answer

The output shows both Gi0/0 and Gi0/1 in the 'Active' state under the LACP protocol. In LACP, the Active state means the ports are actively participating in LACP negotiation and have successfully formed the EtherChannel. The 'Port-channel Ag-Inuse' state confirms the port-channel is active and in use, forwarding traffic.

Exam trap

Cisco often tests the misconception that a load value of '00' means the EtherChannel is down or not forwarding traffic, when in reality it only indicates no traffic has been load-balanced to that specific port at the time of the command output.

How to eliminate wrong answers

Option A is wrong because a load value of '00' in the 'show interfaces port-channel' output does not indicate the EtherChannel is non-operational; it simply means the load-balancing algorithm has not yet distributed any traffic across the member ports, which is normal for a newly formed or idle channel. Option C is wrong because the 'Ag-Inuse' state (Aggregate-Inuse) indicates the port-channel is active and forwarding traffic, not that it is not yet forwarding. Option D is wrong because the load values of '00' are not caused by the load-balancing method; they reflect that no traffic has been hashed to those specific ports, and the output does not display the configured load-balancing algorithm.

791
Drag & Dropmedium

Drag and drop the steps of IKEv2 IPsec tunnel establishment into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

IKEv2 uses a two-phase process: Phase 1 (IKE_SA_INIT) establishes a secure channel, then Phase 2 (IKE_AUTH and CREATE_CHILD_SA) authenticates peers and creates IPsec SAs. The order is: 1. IKE_SA_INIT exchange, 2.

IKE_AUTH exchange, 3. CREATE_CHILD_SA exchange, 4. IPsec SA installation, 5.

Data encryption/decryption.

792
MCQhard

A network engineer is troubleshooting why a Cisco Catalyst 9300 switch is not exporting flow data to a NetFlow collector. The engineer verified that the flow record and exporter are correctly configured and that the collector is reachable. Which additional configuration is required on the switch to enable Flexible NetFlow?

A.Apply the flow monitor to an interface in the ingress direction.
B.Add the collector IP address to the flow record using the collect counter bytes command.
C.Enable NetFlow version 9 globally with the ip flow-export version 9 command.
D.Configure a flow sampler to reduce CPU overhead.
AnswerA

Flexible NetFlow requires a flow monitor to be applied to an interface to activate flow accounting. Without applying the monitor, no flows are tracked or exported, even if the record and exporter are correctly defined. The ingress direction is typical for capturing incoming traffic, and this step is mandatory for the feature to function.

Why this answer

Flexible NetFlow requires three main components: a flow record, a flow exporter, and a flow monitor. The monitor ties the record and exporter together and must be applied to an interface to activate flow accounting. Without applying the monitor, no flows are processed or exported, regardless of other configurations.

The other options are either incorrect commands or optional features.

Exam trap

The trap here is assuming that defining the flow record and exporter is sufficient, overlooking the mandatory step of applying the flow monitor to an interface.

793
MCQhard

An engineer is deploying a virtual network function (VNF) on a Cisco NFVIS host. The VNF requires four virtual NICs, each connected to a different network segment. The engineer creates four bridges on NFVIS and attaches each vNIC to a separate bridge. After deployment, the VNF can only communicate on the first bridge. What is the most likely cause?

A.The bridges are all mapped to the same physical interface without subinterfaces, causing a conflict.
B.The VNF's operating system does not support multiple NICs.
C.The vNICs have duplicate MAC addresses.
D.The bridges were created in the wrong order.
AnswerA

In NFVIS, every bridge must be mapped to a unique physical interface (or a VLAN subinterface), because the Linux bridge binds to the underlying netdev. When multiple bridges are all mapped to the same untagged physical NIC, only the first bridge can claim that NIC's datapath; the others receive no traffic because there is no 802.1Q tag to demultiplex frames among them. This is the classic root cause where one VNF appears up and the other VNFs have no connectivity.

Why this answer

In Cisco NFVIS, bridges are Layer 2 forwarding constructs that must be mapped to a physical interface (or subinterface) to provide external connectivity. When multiple bridges are all mapped to the same physical interface without using subinterfaces (e.g., GigabitEthernet0/0), they share the same VLAN and MAC domain, causing traffic from the second, third, and fourth bridges to be dropped or misdirected. The VNF can only communicate on the first bridge because that bridge's vNIC is the only one that successfully establishes a valid forwarding path through the physical interface.

Exam trap

Cisco often tests the misconception that bridges in NFVIS are isolated by default, when in fact they require explicit mapping to unique physical interfaces or subinterfaces to avoid Layer 2 conflicts.

How to eliminate wrong answers

Option B is wrong because modern VNF operating systems (e.g., Linux, Cisco IOS XE) fully support multiple NICs; the issue is not OS-level but NFVIS bridge configuration. Option C is wrong because NFVIS automatically assigns unique MAC addresses to each vNIC from a pool, and duplicate MACs would cause a different symptom (e.g., ARP flapping) rather than total loss of communication on all but one bridge. Option D is wrong because the order in which bridges are created has no effect on their functionality; NFVIS treats all bridges equally regardless of creation sequence.

794
Multi-Selecthard

Which three statements about configuring AAA on Cisco IOS devices are true? (Choose three.)

Select 3 answers
A.The aaa new-model command enables AAA services on the device.
B.The aaa new-model command disables local authentication and forces the use of an external server.
C.The radius-server host command is used to specify the IP address and shared secret for a RADIUS server.
D.The tacacs-server host command is used to specify the IP address and shared secret for a RADIUS server.
E.The aaa authentication login command defines a method list for login authentication.
AnswersA, C, E

The aaa new-model command activates the AAA subsystem, after which authentication, authorisation and accounting methods can be defined and applied to lines and interfaces. Without it, the device ignores those method lists, so this command is the prerequisite for any AAA configuration.

Why this answer

Option A is correct because the aaa new-model command is the global configuration command that enables the AAA access-control model on a Cisco IOS device, activating authentication, authorization, and accounting functionality. Option C is correct because the radius-server host command specifies a RADIUS server's IP address (or hostname) and can include the shared secret via the key parameter, identifying the server for AAA communication. Option E is correct because the aaa authentication login command creates a named or default method list that defines the sequence of authentication methods (such as local, RADIUS, or TACACS+) applied to login sessions.

Option B is incorrect because aaa new-model does not disable local authentication; local authentication remains available as a method within a method list, and external servers are only used if configured in that list. Option D is incorrect because the tacacs-server host command configures a TACACS+ server, not a RADIUS server, and the shared secret is typically set with the tacacs-server key command.

Exam trap

The trap here is mixing up the commands for RADIUS and TACACS+ servers, or thinking aaa new-model disables local authentication; candidates might also forget that method lists are required for specific authentication methods.

795
Drag & Dropmedium

Drag and drop the steps of configuring a Cisco IOS Zone-Based Firewall (ZBFW) into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

ZBFW configuration begins by defining zones to group interfaces. Next, create a class-map to classify traffic of interest. Then, create a policy-map to specify actions (inspect, drop, pass) for each class.

After that, assign the policy-map to a zone-pair between source and destination zones. Finally, assign interfaces to their respective zones to activate the firewall.

796
MCQeasy

A network administrator is new to automation and wants to use a simple, agentless tool to push configuration changes to Cisco IOS XE devices. The administrator prefers using YAML for playbook definitions and wants to avoid installing software on the managed devices. Which tool best fits these requirements?

A.Ansible
B.Chef
C.SaltStack
D.Puppet
AnswerA

Ansible is an agentless automation tool that uses YAML for playbooks. It connects to devices over SSH or NETCONF and does not require installing agents on managed nodes. It has modules like ios_config for Cisco IOS XE. This matches the administrator's requirements for simplicity and no agent installation.

Why this answer

Ansible is an agentless automation tool that uses YAML for playbooks, making it easy to learn and use. It connects to network devices via SSH or NETCONF and does not require installing software on the devices. This aligns perfectly with the administrator's need for a simple, agentless solution.

Exam trap

The trap here is assuming that all configuration management tools are agentless and use YAML; only Ansible is agentless by default and uses YAML for playbooks.

797
MCQhard

A network engineer needs to monitor traffic between two VLANs on a Cisco Catalyst 9300 switch. The engineer wants to capture all packets that traverse the switch between VLAN 10 and VLAN 20. The monitoring station is connected to port Gi1/0/24. Which configuration should the engineer use to capture this inter-VLAN traffic?

A.Configure 'monitor session 1 source interface Gi1/0/1 both' and 'monitor session 1 destination interface Gi1/0/24'.
B.Configure 'monitor session 1 source vlan 10 - 20 both' and 'monitor session 1 destination interface Gi1/0/24'.
C.Configure an RSPAN VLAN and use 'monitor session 1 source vlan 10 - 20' and 'monitor session 1 destination remote vlan 100'.
D.Configure an ERSPAN session with source IP and destination IP.
AnswerB

This is the correct approach because VLAN-based SPAN with 'source vlan 10 - 20 both' copies every frame that enters or leaves any port in those VLANs, including the routed traffic that is forwarded by the SVI between VLANs. The keyword 'both' ensures that both ingress (received by the VLAN) and egress (transmitted from the VLAN) traffic are mirrored, which is exactly what is needed to observe the complete inter-VLAN communication. The destination interface Gi1/0/24 is a local analyzer port on the same switch, so no remote encapsulation is required.

Why this answer

Inter-VLAN traffic on a switch is routed by the switch virtual interface (SVI) and appears on the VLANs themselves. By using 'monitor session 1 source vlan 10 - 20 both', the SPAN session captures all packets entering or leaving VLANs 10 and 20, which includes the routed traffic between them. The destination interface Gi1/0/24 receives this mirrored traffic, allowing the monitoring station to see all inter-VLAN packets.

Exam trap

Cisco often tests the misconception that inter-VLAN traffic must be captured by monitoring a physical port (like the SVI or a trunk), when in fact VLAN-based SPAN captures all traffic on the VLAN, including routed traffic, without needing to specify a particular interface.

How to eliminate wrong answers

Option A is wrong because it only mirrors traffic on a single physical interface (Gi1/0/1), which does not capture inter-VLAN traffic unless that specific port is the only path between VLANs, which is not the case on a switch. Option C is wrong because RSPAN is used to send mirrored traffic to a remote switch over a dedicated VLAN, but the question asks to capture traffic on the same switch with a monitoring station connected directly to it, making RSPAN unnecessary and overly complex. Option D is wrong because ERSPAN encapsulates mirrored traffic in GRE packets and sends it to a remote IP destination, which is not required here since the monitoring station is locally connected to the switch.

798
MCQmedium

Given the following configuration on a Cisco IOS-XE switch: interface GigabitEthernet0/1 switchport mode trunk switchport trunk native vlan 999 switchport trunk allowed vlan 10,20,30 What is the effect of this configuration?

A.The interface will forward traffic for VLANs 10, 20, and 30, and all untagged frames will be placed into VLAN 999.
B.The interface will forward traffic for all VLANs except 10, 20, and 30, and the native VLAN is 1.
C.The interface will operate as an access port in VLAN 999.
D.The interface will forward traffic for VLANs 10, 20, and 30, and all frames will be tagged including the native VLAN.
AnswerA

This is correct because the command 'switchport trunk allowed vlan 10,20,30' explicitly restricts the trunk to carry only those three VLANs. Additionally, 'switchport trunk native vlan 999' changes the default native VLAN from 1 to 999, so any untagged frames received on this trunk are assigned to VLAN 999 and forwarded accordingly. Tagged frames for VLANs 10, 20, and 30 are forwarded normally, while untagged frames are handled as part of VLAN 999, which is the expected behavior for a configured native VLAN.

Why this answer

The configuration sets the interface as a trunk port, explicitly allows only VLANs 10, 20, and 30 to traverse it, and designates VLAN 999 as the native VLAN. On a trunk, the native VLAN is used for untagged frames (e.g., DTP, CDP, or any traffic sent without an 802.1Q header), so all untagged frames received or sent on this interface will be associated with VLAN 999.

Exam trap

Cisco often tests the distinction between the native VLAN being untagged by default and the 'switchport trunk native vlan tag' command that forces tagging, leading candidates to incorrectly assume that all VLANs on a trunk are always tagged.

How to eliminate wrong answers

Option B is wrong because the 'switchport trunk allowed vlan 10,20,30' command explicitly permits only those VLANs, not all VLANs except them; the interface will not forward traffic for any other VLANs. Option C is wrong because the 'switchport mode trunk' command forces the interface to operate as a trunk port, not an access port; the native VLAN setting does not change the port mode. Option D is wrong because the native VLAN on an 802.1Q trunk is by default untagged; the configuration does not include 'switchport trunk native vlan tag' (which would force tagging of the native VLAN), so frames in VLAN 999 remain untagged.

799
Drag & Dropmedium

Drag and drop the steps of IGMP v3 SSM membership report process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In IGMPv3 SSM, the host first sends a membership report with (S,G) inclusion, the querier processes it, updates its state, and then triggers PIM (S,G) join toward the source.

800
Multi-Selecteasy

Which three statements about Syslog severity levels are true? (Choose three.)

Select 3 answers
A.Severity level 0 (Emergency) indicates that the system is unusable.
B.Severity level 5 (Notice) is a normal but significant condition.
C.Severity level 6 (Informational) is used for informational messages that require immediate action.
D.Severity level 7 (Debugging) is the lowest severity level.
E.Severity level 4 (Warning) is more severe than level 3 (Error).
AnswersA, B, D

Severity 0 maps to Emergency, defined in RFC 5424 as the system being unusable — the highest-urgency condition, where the device can no longer perform its function. This satisfies the stem's requirement for a true statement about Syslog severity levels, since level 0 is the most severe classification.

Why this answer

Option A is correct because Syslog severity level 0 is Emergency, meaning the system is unusable and requires immediate attention. Option B is correct because severity level 5 is Notice, defined as a normal but significant condition that is not an error. Option D is correct because severity level 7 is Debugging, the lowest severity level in the Syslog scale, used for debug-level messages.

Option C is incorrect because severity level 6 is Informational, which covers normal operational messages that do not require immediate action. Option E is incorrect because severity level 4 (Warning) is less severe than level 3 (Error), since lower numeric values indicate higher severity in Syslog.

Exam trap

350-401 often tests the counterintuitive numeric ordering of syslog severities — candidates assume higher numbers mean higher severity (like most scales) and misjudge comparisons such as Warning (4) vs. Error (3).

801
MCQmedium

A network engineer is using Cisco DNA Center's Intent API to create a new site hierarchy for a branch office. The engineer sends a POST request to the /dna/intent/api/v1/site endpoint with a JSON payload containing the site name and parent site. The API returns HTTP 202 Accepted. The engineer immediately sends a GET request to retrieve the newly created site but receives a 404 Not Found. What is the most likely explanation?

A.The site creation is an asynchronous operation, and the GET request was sent before the task completed.
B.The POST request must use the PUT method to create a new site.
C.The GET request must include the same JSON payload as the POST to retrieve the site.
D.The site name must be unique across all sites, and a duplicate name caused the creation to fail silently.
AnswerA

Cisco DNA Center often processes site creation asynchronously. A 202 Accepted response indicates the request was accepted but not yet completed. The API typically returns a task ID in the response body. The engineer must poll the task status until it succeeds before the site is available. Sending a GET immediately can result in 404 because the site does not exist yet.

Why this answer

Cisco DNA Center's Intent API uses asynchronous operations for many tasks, including site creation. A 202 Accepted response means the request is being processed. The response usually contains a task ID.

The engineer should poll the task endpoint until the task completes successfully, then retrieve the site. A GET immediately after the POST can return 404 because the site is not yet available.

Exam trap

The trap here is treating a 202 Accepted response as immediate completion, leading to a premature GET that returns 404.

802
MCQmedium

A network engineer has configured an IP SLA operation on a Cisco router to monitor the reachability of a remote server. The engineer wants to ensure that the operation sends ICMP echo requests every 30 seconds and that the router tracks the operation's state to influence a static route. Which command is required to associate the IP SLA operation with the static route?

A.ip route 10.1.1.0 255.255.255.0 192.168.1.1 track 1
B.ip route 10.1.1.0 255.255.255.0 192.168.1.1 sla 1
C.ip route 10.1.1.0 255.255.255.0 192.168.1.1 ip sla 1
D.ip route 10.1.1.0 255.255.255.0 192.168.1.1 monitor 1
AnswerA

This command creates a static route to 10.1.1.0/24 via next-hop 192.168.1.1 and associates it with tracked object 1. The track object is linked to the IP SLA operation, so if the operation fails, the route is removed from the routing table. This is the correct way to tie IP SLA state to a static route.

Why this answer

To associate an IP SLA operation with a static route, the engineer must use the 'track' keyword in the static route configuration. The tracked object is created separately and linked to the IP SLA operation. This allows the static route to be withdrawn if the IP SLA operation fails, providing reliable path failover based on reachability.

Exam trap

The trap here is assuming that IP SLA can be directly referenced in a static route statement without using a tracked object; the correct method is to use the 'track' keyword.

803
Drag & Dropmedium

Drag and drop the steps of parsing 'show interfaces' output using TextFSM into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order of steps for parsing 'show interfaces' output using TextFSM is: first, capture CLI output from the device (A); second, load the TextFSM template file (B); third, initialize the TextFSM parser with the template (C); fourth, parse the output using the ParseText method (D); finally, access the structured data as a list of dictionaries (E). This sequence follows the logical workflow of a script: obtain raw data, set up the template, apply the parser, and retrieve structured results.

804
MCQhard

An engineer is configuring 802.1X on a Cisco Catalyst switch port where a PC is connected. The requirement is that if the authentication server becomes unreachable, the port should still allow the PC to send traffic in a restricted VLAN rather than being shut down. Which configuration meets this requirement?

A.authentication open
B.authentication host-mode multi-auth
C.authentication event server dead action authorize vlan 999
D.authentication event fail action authorize vlan 999
AnswerC

The authentication event server dead action authorize vlan command places the port into the specified restricted VLAN when the RADIUS server becomes unreachable. This allows the connected endpoint to send limited traffic instead of the port being placed in an unauthorized state, directly satisfying the requirement of continued but restricted access during a server outage.

Why this answer

When RADIUS becomes unreachable, the switch needs an explicit policy for the resulting dead-server condition. The authentication event server dead action authorize vlan command places the port into a designated restricted VLAN, allowing limited connectivity while the outage persists. Other commands address failed credentials, host count, or pre-authentication access, none of which provide the required restricted-VLAN fallback.

Exam trap

The trap here is mixing up the fail action, which reacts to rejected credentials, with the server dead action, which reacts to an unreachable authentication server.

805
MCQmedium

Examine the following BGP configuration: router bgp 65001 bgp log-neighbor-changes neighbor 10.1.1.1 remote-as 65002 neighbor 10.1.1.1 route-map SET_MED out ! route-map SET_MED permit 10 set metric 50 What is the purpose of this configuration?

A.It sets the MED value to 50 for all routes sent to the neighbor 10.1.1.1.
B.It sets the local preference to 50 for routes received from the neighbor.
C.It filters routes with a metric of 50 from being advertised to the neighbor.
D.It sets the weight to 50 for routes learned from the neighbor.
AnswerA

The route-map is applied in the outbound direction for neighbor 10.1.1.1, and the set metric command sets the BGP MED (Multi-Exit Discriminator) value to 50 for every permitted route. Because the route-map contains a permit statement without a restrictive match clause, all routes advertised to this neighbor carry MED 50. This influences the neighbor's inbound path selection, preferring lower MED values, so routes with MED 50 may be less preferred than routes with lower MED from other peers.

Why this answer

The configuration applies a route-map named SET_MED to outbound updates toward neighbor 10.1.1.1. The route-map permits all routes (no match statement) and sets the Multi-Exit Discriminator (MED) to 50. MED is a BGP path attribute that influences inbound traffic from the neighbor AS, making this path less preferred if the neighbor has a lower MED from another entry point.

Thus, all routes sent to 10.1.1.1 will carry a MED of 50.

Exam trap

Cisco often tests the distinction between BGP path attributes (MED vs. local preference vs. weight) and the direction in which they are applied (inbound vs. outbound), causing candidates to confuse 'set metric' with 'set local-preference' or 'set weight'.

How to eliminate wrong answers

Option B is wrong because local preference is set using the 'set local-preference' command in a route-map, and it applies to inbound updates, not outbound; the configuration here uses 'set metric' (MED) on outbound updates. Option C is wrong because the route-map is configured with 'permit' and no match condition, so it does not filter routes; it modifies the MED attribute of all advertised routes, not filtering based on metric. Option D is wrong because weight is a Cisco-proprietary attribute set with 'set weight' in a route-map, and it applies to inbound updates; this configuration sets MED on outbound updates, not weight.

806
MCQhard

A network administrator is deploying Cisco ACI in a data center. The administrator needs to ensure that a new tenant's application profile can communicate with an external Layer 2 network that is connected to a border leaf switch. Which ACI construct must be configured to extend the tenant's bridge domain to the external network?

A.A Layer 3 Outside (L3Out)
B.A VXLAN tunnel to the external switch
C.A Layer 2 Outside (L2Out)
D.A bridge domain with a flood scope of 'external'
AnswerC

In Cisco ACI, an L2Out is used to extend a bridge domain to an external Layer 2 network. It is configured on a border leaf and includes an external bridged domain and an external bridged network. This allows Layer 2 connectivity between the ACI fabric and external devices, which is exactly what is needed to extend the tenant's bridge domain.

Why this answer

To extend a Cisco ACI bridge domain to an external Layer 2 network, an L2Out must be configured. This construct defines the external bridged domain and network, and is applied to a border leaf interface. It allows Layer 2 traffic to pass between the ACI fabric and external devices, preserving VLAN tags or mapping them as needed.

Exam trap

The trap here is confusing L2Out with L3Out; L3Out is for routed connectivity, while L2Out is specifically for Layer 2 extension.

807
MCQmedium

A network engineer is writing a Python script to retrieve the configured hostname from a Cisco IOS XE device using RESTCONF. The device has RESTCONF enabled, and the engineer sends a GET request to https://10.1.1.1/restconf/data/Cisco-IOS-XE-native:native/hostname with the header 'Accept: application/yang-data+json'. However, the request fails with HTTP 401 Unauthorized. The engineer verifies that the device is reachable and RESTCONF is enabled. What is the most likely reason for the failure?

A.The RESTCONF URI is incorrect; it should be /restconf/data/ietf-interfaces:interfaces to retrieve hostname information.
B.The RESTCONF API requires the use of HTTPS with a valid certificate, and the device's certificate is self-signed.
C.The engineer did not include valid authentication credentials in the request, such as a username and password or a token.
D.The request is missing the 'Content-Type' header, which is required for all RESTCONF requests.
AnswerC

HTTP 401 Unauthorized specifically indicates that the request lacks valid authentication credentials. RESTCONF on Cisco IOS XE requires authentication, typically via HTTP Basic Authentication or token-based methods. Without proper credentials, the device rejects the request. The engineer must include an Authorization header with valid credentials to succeed.

Why this answer

The 401 Unauthorized status code is a clear indication that authentication failed. RESTCONF on Cisco IOS XE requires the client to provide credentials, usually via HTTP Basic Authentication. Without a valid Authorization header, the device denies access.

The other options describe issues that would produce different error codes or are irrelevant to authentication.

Exam trap

The trap here is assuming that a self-signed certificate or missing Content-Type header causes a 401 error, when in fact 401 is strictly about missing or invalid authentication credentials.

808
MCQhard

A network security team is hardening a Cisco IOS-XE router that terminates IPsec VPN tunnels. They want to protect the control plane from CPU-intensive IKE and management traffic without dropping legitimate tunnel establishment packets. They decide to apply a Control Plane Policing (CoPP) policy. Which statement best describes how CoPP interacts with the forwarding plane and the control plane on this router?

A.CoPP can only classify traffic using NBAR2 deep packet inspection, so it cannot match IKE or SSH and requires a separate Zone-Based Firewall policy to protect the control plane.
B.CoPP uses MQC to classify traffic destined to the route processor and applies a policer in the control-plane host path, so it can rate-limit IKE and SSH without affecting transit traffic that is forwarded in hardware.
C.CoPP requires enabling 'ip cef distributed' and a PFC on the supervisor to offload policed control traffic to hardware, otherwise it cannot rate-limit IKE packets.
D.CoPP classifies and polices all packets entering any interface, including transit traffic, so it must be applied with 'service-policy input' on every physical interface to be effective.
AnswerB

CoPP leverages Modular QoS CLI to classify packets punted to the route processor, including IKE, SSH, and SNMP, and polices them in a dedicated control-plane host path. Because the policy is applied with 'service-policy input' under 'control-plane', it only affects traffic destined to the device itself, leaving hardware-forwarded transit traffic untouched. This matches the requirement to protect the CPU while preserving legitimate tunnel establishment.

Why this answer

CoPP applies MQC classification and policing to packets destined for the route processor via the control-plane host path, protecting the CPU from floods of IKE, SSH, or SNMP without touching hardware-forwarded transit traffic. It is configured once under 'control-plane', not per interface, and does not require distributed CEF or NBAR2 to match common control-plane protocols.

Exam trap

The trap here is assuming CoPP is an interface-level QoS policy that filters transit traffic instead of a control-plane host-path policer targeting only packets destined to the route processor.

809
Multi-Selecthard

Which two statements about DMVPN phase 2 are true? (Choose two.)

Select 2 answers
A.In DMVPN phase 2, spoke routers can establish direct tunnels to each other without traffic passing through the hub.
B.DMVPN phase 2 requires mGRE on the hub only; spokes use point-to-point GRE tunnels.
C.NHRP redirect messages are used in phase 2 to inform spokes of better paths to remote destinations.
D.DMVPN phase 2 supports only IPsec protection and cannot operate without encryption.
E.In DMVPN phase 2, spoke routers must be configured with static crypto maps for IPsec.
AnswersA, C

Phase 2 permits spoke-to-spoke tunnels built directly, bypassing the hub for data forwarding. Spokes learn each other's tunnel endpoints via NHRP resolution through the hub, then establish direct GRE tunnels, satisfying the requirement that inter-spoke traffic avoids hub transit.

Why this answer

Option A is correct because DMVPN phase 2 enables spoke-to-spoke direct tunnels: spokes learn each other's NBMA addresses via NHRP and can build dynamic mGRE tunnels so data traffic bypasses the hub. Option C is correct because in phase 2 the hub uses NHRP redirect messages to tell a spoke that a better path to the destination exists, prompting the spoke to send an NHRP resolution request and build a direct tunnel. Option B is wrong because phase 2 requires mGRE on both the hub and the spokes, not point-to-point GRE on spokes.

Option D is wrong because DMVPN phase 2 can run with or without IPsec; encryption is optional. Option E is wrong because spokes use dynamic crypto maps or IPsec profiles, not static crypto maps, to support spoke-to-spoke IPsec tunnels.

Exam trap

The trap is confusing DMVPN phases: phase 1 only hub-to-spoke, phase 2 adds spoke-to-spoke with NHRP redirect, phase 3 adds NHRP shortcut and scalability improvements. Candidates must remember that phase 2 uses mGRE on spokes and NHRP redirect.

810
MCQeasy

What is the default OSPF hello interval on an Ethernet broadcast network?

A.10 seconds
B.30 seconds
C.5 seconds
D.20 seconds
AnswerA

On Ethernet (broadcast) and point-to-point links, OSPF's default hello interval is 10 seconds, as defined in RFC 2328. This 10-second hello is also paired with a default dead interval of 40 seconds (four times the hello), allowing a neighbor to be declared down after missed hellos. This setting balances fast neighbor detection with acceptable control-plane overhead on high-bandwidth LAN segments.

Why this answer

On Ethernet broadcast networks, OSPF defaults to a hello interval of 10 seconds, as specified in RFC 2328. This interval is used to maintain neighbor relationships and detect failures quickly on high-speed multi-access links.

Exam trap

Cisco often tests the OSPF hello interval default by mixing up broadcast and NBMA values, leading candidates to mistakenly choose 30 seconds for Ethernet networks.

How to eliminate wrong answers

Option B is wrong because 30 seconds is the default hello interval for OSPF on non-broadcast multi-access (NBMA) networks, such as Frame Relay, not on Ethernet broadcast networks. Option C is wrong because 5 seconds is not a standard OSPF hello interval; it is sometimes used in proprietary or tuned configurations but not the default. Option D is wrong because 20 seconds is not a default OSPF hello interval; it might be confused with the default dead interval multiplier (4 times the hello interval) which would be 40 seconds for a 10-second hello, not 20.

811
MCQhard

A network architect is designing a campus network that must support thousands of endpoints with a fabric overlay. The design requires that the underlay provide fast convergence and equal-cost multipathing without running a separate routing protocol in the overlay. Which underlay routing protocol should be selected to meet these requirements?

A.Intermediate System-to-Intermediate System (IS-IS)
B.Enhanced Interior Gateway Routing Protocol (EIGRP)
C.Border Gateway Protocol (BGP)
D.Open Shortest Path First (OSPF) with multiple areas
AnswerA

IS-IS is the recommended underlay routing protocol for Cisco SD-Access fabrics. It provides fast convergence, supports ECMP, and scales well in large campus deployments. It operates independently of the LISP/VXLAN overlay, allowing the underlay to focus on IP reachability. This directly meets the requirements for fast convergence and multipathing without overlay routing, making it the correct selection.

Why this answer

Cisco SD-Access recommends IS-IS as the underlay routing protocol because it provides fast convergence, scalable ECMP, and clean separation from the LISP/VXLAN overlay. OSPF, EIGRP, and BGP can provide routing but are not the standard underlay choice for large fabric deployments and may add complexity or converge more slowly in this context.

Exam trap

The trap here is assuming any protocol with ECMP support is equally suitable as a fabric underlay, when IS-IS is specifically recommended for SD-Access due to its convergence and integration characteristics.

812
Drag & Drophard

Drag and drop the steps of OSPF redistribution from EIGRP with metric conversion into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Redistribution requires enabling redistribution, setting a seed metric (or using default-metric), optionally matching routes, and then verifying. The order ensures routes are properly injected.

813
Multi-Selectmedium

Which three statements about RRM (Radio Resource Management) in a Cisco wireless LAN are true? (Choose three.)

Select 3 answers
A.RRM automatically selects the best channel for each AP based on interference measurements.
B.RRM requires a dedicated hardware controller to perform RF calculations.
C.RRM can adjust the transmit power of APs to optimize coverage and reduce co-channel interference.
D.RRM uses a leader AP to collect and distribute RF measurements to other APs in the same RF group.
E.RRM automatically enables client load balancing across APs in the same coverage area.
AnswersA, C, D

RRM's dynamic channel assignment continuously scans RF conditions and assigns each AP the channel with least interference, avoiding manual planning. This satisfies the automatic channel-selection claim, distinguishing it from static channel plans configured per access point.

Why this answer

Option A is correct because RRM's Dynamic Channel Assignment (DCA) continuously monitors each AP's RF environment—using metrics like noise, interference, and neighboring AP beacons—and automatically assigns the least-interfered channel to each radio. Option C is correct because RRM's Transmit Power Control (TPC) algorithm adjusts each AP's radio transmit power to balance coverage and capacity, shrinking cells to reduce co-channel interference while maintaining adequate signal for clients. Option D is correct because RRM organizes APs into RF groups, and within each group a single AP is elected as the RF group leader; that leader aggregates the neighbor and interference data (via NMSP/CCX measurements) and computes channel and power plans that are distributed to all members.

Option B is not correct because RRM is a software feature of the WLC (and, in newer architectures, of Catalyst 9800 controllers or embedded wireless in Catalyst 9000 switches)—no dedicated hardware appliance is required. Option E is not correct because client load balancing is a separate feature (Aggressive Load Balancing / band steering) and is not part of RRM's DCA/TPC/RF-group functions.

Exam trap

The trap is conflating RRM with client load balancing or assuming RRM needs dedicated hardware — candidates pick 'load balancing' because it sounds RF-related, but RRM is strictly about channel, power, and measurement coordination.

814
MCQhard

A network engineer runs the following command on Router R6: R6# show policy-map interface GigabitEthernet0/1 GigabitEthernet0/1 Service-policy output: QOS_POLICY Class-map: VOICE (match-any) 500 packets, 50000 bytes 5 minute offered rate 50000 bps, drop rate 0 bps Match: ip dscp ef (46) Queueing strict priority queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 500/50000 police cir 1000000 bc 15625 be 15625 conformed 500 packets, 50000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: DATA (match-any) 1000 packets, 100000 bytes 5 minute offered rate 100000 bps, drop rate 0 bps Match: ip dscp af31 (26) Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 1000/100000 bandwidth remaining percent 50 Class-map: class-default (match-any) 2000 packets, 200000 bytes 5 minute offered rate 200000 bps, drop rate 0 bps Match: any Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 2000/200000 bandwidth remaining percent 50 Based on this output, what can be concluded?

A.Voice traffic is being dropped because it exceeds the police rate.
B.Data traffic is being guaranteed 50% of the remaining bandwidth.
C.All traffic is being shaped to a CIR of 1 Mbps.
D.The policy-map is applied to input traffic.
AnswerB

The `bandwidth remaining percent 50` command on the DATA class ensures that data packets receive 50% of the bandwidth that is left over after the strict-priority voice queue has been serviced. This is a proportional share of residual capacity, not an absolute fixed bandwidth guarantee. In a CBWFQ policy, this allows the data class to compete with other default classes using the remaining bandwidth percentage toward the total unallocated bandwidth.

Why this answer

The 'bandwidth remaining percent 50' command under the DATA class guarantees that class 50% of any bandwidth left unused by the strict-priority VOICE class. The policy-map is applied in the output direction, and the VOICE class uses a police (not shape) with a CIR of 1 Mbps, so only excess voice packets are dropped, not all traffic shaped. The class-default also gets 50% of the remaining bandwidth, confirming that the DATA class is indeed guaranteed 50% of the leftover bandwidth.

Exam trap

Cisco often tests the distinction between 'police' (which drops or marks excess traffic) and 'shape' (which buffers to a rate), and candidates mistakenly assume 'police cir' implies shaping or that any CIR command shapes all traffic.

How to eliminate wrong answers

Option A is wrong because the police output shows 0 exceeded and 0 violated packets, meaning no voice traffic has been dropped due to exceeding the police rate. Option C is wrong because the policy uses a 'police' command (which meters and drops or marks) on the VOICE class, not a 'shape' command; shaping would buffer and delay traffic to a CIR, which is not configured here. Option D is wrong because the command 'show policy-map interface GigabitEthernet0/1' output explicitly states 'Service-policy output: QOS_POLICY', indicating the policy is applied to output traffic, not input.

815
MCQeasy

A network administrator is configuring a Cisco IOS XE router to protect against spoofed source addresses on an internal interface facing user subnets. The requirement is to drop packets whose source address does not match the routing table entry for the incoming interface. Which feature should be enabled?

A.Access Control List with the log keyword applied to the interface
B.IP Source Guard on the interface
C.Unicast Reverse Path Forwarding (uRPF) in strict mode on the interface
D.Dynamic ARP Inspection on the interface
AnswerC

Strict uRPF checks that the source address of an incoming packet is reachable via the same interface the packet arrived on, using the routing table. If the source is not reachable through that interface, the packet is dropped, which directly blocks spoofed source addresses from user subnets. This matches the requirement to validate source addresses against the routing table for the incoming interface.

Why this answer

Unicast RPF in strict mode checks the routing table for the source address of each incoming packet and verifies that the source is reachable via the same interface the packet arrived on. If not, the packet is dropped, which prevents source address spoofing. This is the standard IOS XE feature for validating source addresses on an interface against the routing table.

Exam trap

The trap here is confusing Layer 2 anti-spoofing features like IP Source Guard and Dynamic ARP Inspection with Layer 3 uRPF, which uses the routing table to validate sources on routed interfaces.

816
MCQmedium

A network engineer runs the following command on Router R1: R1# show mpls ldp neighbor Peer LDP Ident: 10.0.0.2:0; Local LDP Ident 10.0.0.1:0 TCP connection: 10.0.0.2.646 - 10.0.0.1.49231 State: Oper; Msgs sent/rcvd: 100/95; Downstream Up time: 01:23:45 LDP discovery sources: GigabitEthernet0/0, Src IP addr: 192.168.1.2 Addresses bound to peer LDP Ident: 10.0.0.2 192.168.1.2 Based on this output, what can be concluded?

A.The LDP session is not yet established.
B.The LDP session is using TCP port 646.
C.The LDP neighbor is using a different router ID than 10.0.0.2.
D.The LDP session has been up for 1 hour 23 minutes.
AnswerB

LDP uses TCP port 646 as its well-known transport port for reliable exchange of label binding messages. The output's TCP connection line explicitly lists port 646 for the remote endpoint, confirming that the session is running over the standard LDP TCP port. Had it been a non-default port, the configuration would have required an explicit 'port' statement under the MPLS LDP router configuration.

Why this answer

The output shows 'TCP connection: 10.0.0.2.646 - 10.0.0.1.49231', which indicates that the LDP session is using TCP port 646 on the peer side. This is the well-known port for Label Distribution Protocol (LDP), as defined in RFC 5036. The session state is 'Oper' (Operational), confirming the session is established and functioning correctly.

Exam trap

Cisco often tests the interpretation of the 'Up time' field, where candidates might overlook that the format includes seconds (HH:MM:SS) and incorrectly assume it only shows hours and minutes, leading them to select a partially correct but inaccurate option like D.

How to eliminate wrong answers

Option A is wrong because the session state is 'Oper' (Operational), meaning the LDP session is fully established, not pending. Option C is wrong because the 'Peer LDP Ident: 10.0.0.2:0' explicitly shows the neighbor's router ID is 10.0.0.2, and the addresses bound to the peer include 10.0.0.2, confirming it is the router ID. Option D is wrong because the 'Up time: 01:23:45' indicates the session has been up for 1 hour, 23 minutes, and 45 seconds, not just 1 hour 23 minutes; the seconds value is part of the uptime display.

817
Multi-Selectmedium

Which two statements about SPAN and RSPAN are true? (Choose two.)

Select 2 answers
A.SPAN mirrors traffic only on the local switch.
B.RSPAN uses a dedicated VLAN to transport mirrored traffic across multiple switches.
C.SPAN can be used to mirror traffic between switches without additional configuration.
D.RSPAN supports both ingress and egress mirroring on the source switch.
E.RSPAN requires a separate management VLAN to function.
AnswersA, B

Correct because SPAN is local to the switch where the source ports reside.

Why this answer

SPAN mirrors traffic locally on the same switch. RSPAN uses a dedicated VLAN to carry mirrored traffic across switches. SPAN can monitor both ingress and egress traffic.

RSPAN supports only ingress mirroring on source ports, not egress. SPAN cannot be used across switches without RSPAN or ERSPAN. RSPAN does not require a separate management VLAN.

818
MCQmedium

Consider this configuration: interface GigabitEthernet0/2 switchport mode trunk switchport trunk native vlan 10 switchport trunk allowed vlan 10,20,30 ! interface Vlan10 ip address 192.168.10.1 255.255.255.0 Which statement is true about this configuration?

A.The native VLAN 10 cannot be used as a routed interface because it is the native VLAN.
B.The trunk will only allow VLANs 10, 20, and 30, and VLAN 10 is the native VLAN.
C.The SVI for VLAN 10 will not come up because the native VLAN must be untagged.
D.The configuration is invalid because the native VLAN must be the same as the management VLAN.
AnswerB

The command 'switchport trunk allowed vlan 10,20,30' explicitly limits the VLANs permitted on the trunk to 10, 20, and 30, effectively pruning all other VLANs from that trunk link. Additionally, 'switchport trunk native vlan 10' assigns VLAN 10 as the native VLAN, meaning frames in VLAN 10 are sent untagged across the trunk. This is a valid configuration that restricts traffic to those VLANs while making VLAN 10 the untagged native VLAN.

Why this answer

The configuration explicitly permits VLANs 10, 20, and 30 on the trunk using the 'switchport trunk allowed vlan' command, and VLAN 10 is set as the native VLAN with the 'switchport trunk native vlan 10' command. The native VLAN carries untagged traffic on the trunk, but it is still a valid VLAN that can be included in the allowed list and can have an SVI for routing. The SVI for VLAN 10 will come up as long as the VLAN exists and there is at least one active switchport in that VLAN, which is satisfied by the trunk port.

Exam trap

Cisco often tests the misconception that the native VLAN cannot be used for routing or that it must be excluded from the allowed VLAN list, but in reality, the native VLAN is simply the VLAN that carries untagged frames and can be included in the allowed list and have an SVI.

How to eliminate wrong answers

Option A is wrong because the native VLAN can absolutely be used as a routed interface; the SVI for VLAN 10 will function normally, and there is no restriction that prevents a native VLAN from having an IP address. Option C is wrong because the native VLAN being untagged on the trunk does not prevent the SVI from coming up; the SVI is a Layer 3 interface that is independent of whether the VLAN traffic is tagged or untagged on the physical port. Option D is wrong because there is no requirement that the native VLAN must match the management VLAN; the management VLAN is typically used for out-of-band management traffic and can be any VLAN, while the native VLAN is a trunk-specific concept for untagged frames.

819
MCQeasy

An engineer is deploying a virtual router (vRouter) on a Cisco NFVIS host. The vRouter needs to advertise routes to a physical router connected to the host's management port. The engineer configures the vRouter with an IP address on the same subnet as the management port. However, the physical router does not receive any routing updates. What should the engineer do to enable route exchange?

A.Configure a static route on the vRouter pointing to the physical router.
B.Enable OSPF on the vRouter's management interface.
C.Change the management port to a trunk port to carry routing updates.
D.Connect the vRouter to a data plane interface (e.g., a bridge connected to a physical data port) instead of the management port.
AnswerD

The vRouter must attach to a data plane interface—such as a Linux bridge or OVS bridge bound to a physical NIC—so that its OSPF packets traverse the same forwarding network as the physical router. This places the vRouter in-band, allowing multicast hello packets and database descriptors to reach the OSPF neighbor. Only then will router LSA exchange and adjacency state transitions occur properly over the intended routed network.

Why this answer

In Cisco NFVIS, the management port is isolated from the data plane and is intended only for out-of-band management traffic. Routing protocols like OSPF or BGP cannot exchange routes over the management interface because it lacks the necessary data-plane forwarding capabilities. To advertise routes to a physical router, the vRouter must be connected to a data plane interface, such as a bridge mapped to a physical data port, which supports routing protocol adjacency and packet forwarding.

Exam trap

Cisco often tests the misconception that the management port can be used for data-plane functions like routing protocol exchange, when in fact NFVIS strictly isolates management traffic to a separate bridge that does not support Layer 3 routing adjacencies.

How to eliminate wrong answers

Option A is wrong because configuring a static route on the vRouter pointing to the physical router would only install a route in the vRouter's routing table; it does not cause the vRouter to advertise routes to the physical router, so no route exchange occurs. Option B is wrong because enabling OSPF on the vRouter's management interface is ineffective; the management port in NFVIS is a control-plane-only interface that does not support routing protocol adjacency or data-plane forwarding, so OSPF neighbors will not form. Option C is wrong because changing the management port to a trunk port does not enable routing protocol exchange; the management port is still isolated from the data plane and cannot carry routing updates regardless of trunking configuration.

820
MCQmedium

A network administrator is deploying QoS in a converged network. Which approach correctly implements trust boundaries and marking?

A.Set trust boundary at the access layer switch and re-mark packets based on source.
B.Configure marking only at the core layer to simplify policy.
C.Trust only the distribution layer switches to mark traffic.
D.Trust the DSCP values set by IP phones and workstations.
AnswerA

The access layer is the optimal trust boundary because it is the first device in the path that can inspect source identities (e.g., IP phone vs. workstation) with port-level granularity. Re-marking DSCP here ensures that packets enter the network with a consistent QoS class, allowing all downstream switches to rely on these markings for queuing and policing. This prevents untrusted end devices from dictating their own priority, which is essential for converged networks carrying voice, video, and data.

Why this answer

In a converged network, trust boundaries should be established at the access layer to ensure that marking decisions are made as close to the source as possible. By setting the trust boundary at the access layer switch and re-marking packets based on source (e.g., trusting only IP phones while re-marking workstation traffic), the network can enforce policy before traffic enters the core, preventing unauthorized or misconfigured endpoints from influencing QoS markings. This aligns with Cisco's best practice of trusting only known devices and re-marking all other traffic to a default or lower priority.

Exam trap

Cisco often tests the misconception that trust boundaries should be placed at the distribution or core layer for simplicity, but the trap is that marking must happen at the access layer to prevent untrusted endpoints from injecting high-priority traffic into the network.

How to eliminate wrong answers

Option B is wrong because configuring marking only at the core layer violates the principle of trust boundaries; marking should occur at the access layer to prevent congestion and ensure policy is applied early, and relying solely on core marking can lead to oversubscription and loss of differentiation. Option C is wrong because trusting only the distribution layer to mark traffic introduces unnecessary latency and complexity, and it fails to protect the network from untrusted endpoints at the access edge, which is the correct location for trust boundaries. Option D is wrong because while IP phones can be trusted to set correct DSCP values (e.g., EF for voice), workstations should never be trusted to mark their own traffic, as they may be compromised or misconfigured; the trust boundary must differentiate between trusted and untrusted sources.

821
MCQmedium

A network automation team needs to securely retrieve the running configuration from 200 Cisco IOS XE routers daily using a Python script. The script must authenticate with individual user credentials, use a structured data format, and avoid screen-scraping. Which approach best meets these requirements?

A.Use SNMPv3 GET requests with the OID for the running configuration MIB object to retrieve the full configuration.
B.Use the requests library to send HTTP GET requests to the device's web UI login page, then scrape the configuration page HTML.
C.Use the ncclient Python library to send NETCONF <get-config> RPCs over SSH, requesting the <running> datastore with a YANG-modeled filter.
D.Use the paramiko library to open an SSH session and execute the 'show running-config' command, then parse the raw text output.
AnswerC

NETCONF over SSH provides secure, authenticated access with structured XML payloads defined by YANG models. The <get-config> RPC retrieves the running configuration in a machine-readable format, eliminating screen-scraping. ncclient is a standard Python library for NETCONF, and individual credentials are supported. This directly satisfies all stated requirements.

Why this answer

NETCONF over SSH with ncclient delivers secure, credential-based access and returns configuration data as structured XML governed by YANG models. This eliminates the fragility of parsing CLI text and avoids screen-scraping. The other approaches either return unstructured output, cannot retrieve full configurations reliably, or rely on UI scraping, so they do not meet the stated automation requirements.

Exam trap

The trap here is assuming that any SSH-based method (such as Paramiko running show commands) counts as structured automation, when only model-driven APIs like NETCONF return schema-validated data.

822
MCQmedium

A network automation engineer is using the Cisco DNA Center Intent API to retrieve a list of all network devices. The engineer needs to authenticate to the API. Which authentication method should be used to obtain a token for subsequent API calls?

A.OAuth 2.0 client credentials grant flow.
B.POST to the /dna/system/api/v1/auth/token endpoint with Basic authentication.
C.API key passed in the X-Auth-Token header.
D.Basic authentication with username and password in the Authorization header.
AnswerB

Cisco DNA Center's Intent API requires a POST request to the /dna/system/api/v1/auth/token endpoint, using Basic authentication with the username and password. The response contains a token that must be included in subsequent requests in the X-Auth-Token header. This is the standard authentication flow for the Intent API.

Why this answer

The Cisco DNA Center Intent API uses token-based authentication. The client must POST to the /dna/system/api/v1/auth/token endpoint with Basic authentication credentials. The response includes a token that is then used in the X-Auth-Token header for subsequent API calls.

This is the documented and required method for API access.

Exam trap

The trap here is assuming that standard authentication methods like Basic auth or OAuth are used directly, when DNA Center requires a specific token retrieval step.

823
MCQhard

A security engineer is configuring CoPP (Control Plane Policing) on a Cisco router to protect the control plane from DoS attacks. The policy must rate-limit SSH traffic to 1 Mbps with a burst of 2000 bytes, and drop all other traffic destined to the control plane that exceeds a default rate. Which class-map and policy-map configuration is correct?

A.class-map match-all SSH match protocol ssh policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop
B.class-map match-all SSH match access-group name SSH_ACL policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop
C.class-map match-all SSH match protocol ssh policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop
D.class-map match-all SSH match protocol ssh policy-map COPP class SSH police 2000 1000000 conform-action transmit exceed-action drop
AnswerC

This is the correct CoPP configuration: `class-map match-all SSH` with `match protocol ssh` classifies SSH control-plane traffic, and the policy map `COPP` applies a police rate of 1,000,000 bps with a burst of 2000 bytes, dropping exceeding traffic. The `class-default` then polices all other control-plane traffic at 8000 bps, ensuring that no unclassified protocol can flood the CPU. The syntax and parameters are correctly ordered (rate in bps, burst in bytes), providing comprehensive control-plane protection.

Why this answer

It uses the 'match protocol ssh' class-map to identify SSH traffic, applies a police rate of 1,000,000 bps (1 Mbps) with a burst of 2000 bytes, and includes a class-default with a police rate of 8000 bps to drop all other control-plane traffic exceeding a default rate. This matches the requirement to rate-limit SSH and drop other traffic that exceeds a default rate, which is a common CoPP best practice to protect the control plane.

Exam trap

Cisco often tests the requirement for a class-default policy in CoPP to drop all other traffic, and the trap here is that candidates may forget that without it, unmatched traffic is permitted by default, or they may confuse the order of police parameters (rate vs. burst).

How to eliminate wrong answers

Option A is wrong because it lacks a class-default policy; without it, any traffic not matching the SSH class is implicitly permitted, failing to drop other traffic exceeding a default rate. Option B is wrong because it uses 'match access-group name SSH_ACL' instead of 'match protocol ssh', which is less efficient and not the direct method for matching SSH protocol traffic; also, the class-default police rate of 8000 is correct, but the match method is incorrect for the requirement. Option D is wrong because it swaps the police parameters: the first value (2000) is the burst size and the second (1000000) is the rate, but the correct syntax is 'police rate burst', so this would apply a rate of 2000 bps and a burst of 1,000,000 bytes, which does not meet the 1 Mbps rate requirement.

824
Multi-Selecthard

Which two statements about multicast RPF check are true? (Choose two.)

Select 2 answers
A.The RPF check uses the unicast routing table (or a dedicated multicast routing table) to determine the best path back to the multicast source.
B.If the RPF check fails, the multicast packet is dropped to prevent routing loops.
C.The RPF check is performed only on the first packet of a multicast stream; subsequent packets are forwarded without verification.
D.The RPF check can be overridden by configuring a static multicast route (mroute) that points to a different incoming interface.
E.The RPF check is only relevant for PIM-SM and not for PIM-DM.
AnswersA, B

Correct because the RPF check compares the source IP address of the multicast packet against the routing table (RIB or MRIB) to find the outgoing interface toward the source; the packet is accepted only if it arrives on that interface.

Why this answer

RPF check is a fundamental loop prevention mechanism in multicast. It verifies that the incoming interface of a multicast packet is the same interface the router would use to reach the source. If the check fails, the packet is dropped.

RPF can be influenced by static mroutes and is performed on all multicast packets, not just data.

825
MCQeasy

A network engineer is using the Cisco Meraki REST API to update the SSID settings for a wireless network. The engineer sends a PUT request to 'https://api.meraki.com/api/v1/networks/{networkId}/wireless/ssids/{ssidNumber}' with a JSON payload containing the new settings. The API returns a 429 Too Many Requests error. What should the engineer do to resolve this issue?

A.Implement exponential backoff and retry the request after a delay.
B.Change the HTTP method to POST because PUT is not supported for this endpoint.
C.Add an 'X-Cisco-Meraki-API-Key' header with a higher rate limit key.
D.Use a different API endpoint, such as 'https://api.meraki.com/api/v1/organizations/{orgId}/ssids'.
AnswerA

A 429 response signals rate limiting, not a malformed payload. Retrying immediately would compound the throttling, so exponential backoff with jitter spaces retries progressively until the Meraki API's rate window resets and the PUT succeeds.

Why this answer

A 429 error indicates rate limiting; the API has received too many requests from the client within a given time frame. The engineer should implement exponential backoff and retry logic, or reduce the request rate.

Page 10

Page 11 of 26

Page 12