Courseiva

ENCOR 350-401 (350-401) — Questions 826–900

1923 questions total · 26pages · All types, answers revealed

Page 11

Page 12 of 26

Page 13
826
MCQmedium

An architect is planning a Cisco SD-Access fabric deployment. The design must support host mobility across multiple fabric edge nodes while ensuring consistent policy enforcement. Which fabric component is responsible for tracking endpoint locations and mapping them to the fabric?

A.Fabric control plane node
B.Fabric border node
C.Fabric edge node
D.Fabric wireless controller
AnswerA

The control plane node in SD-Access runs LISP as its mapping system, maintaining the Endpoint Database (EID-to-RLOC) for every wired or wireless endpoint in the fabric. When an edge node needs to reach a destination, it sends a Map-Request to the control plane node, which replies with the routable locator (RLOC) of the destination edge node. This node is thus the authoritative source for tracking and mapping endpoint locations, making it the correct answer.

Why this answer

In Cisco SD-Access, the fabric control plane node (based on LISP) is responsible for maintaining the endpoint database (EID-to-RLOC mappings). When a host moves between fabric edge nodes, the control plane node updates the mapping, ensuring consistent policy enforcement by providing the correct location information to all edge nodes.

Exam trap

Cisco often tests the misconception that the fabric edge node tracks endpoint locations because it directly connects to hosts, but the control plane node is the centralized mapping database in LISP-based SD-Access.

How to eliminate wrong answers

Option B is wrong because the fabric border node connects the SD-Access fabric to external networks (e.g., WAN, data center) and handles north-south traffic, but it does not track endpoint locations or maintain the EID-to-RLOC database. Option C is wrong because the fabric edge node is the access layer that connects endpoints to the fabric and enforces policies locally, but it relies on the control plane node to learn and update endpoint location mappings; it does not serve as the central mapping database. Option D is wrong because the fabric wireless controller (e.g., Cisco Catalyst 9800) manages wireless access points and client roaming within the fabric, but it does not maintain the LISP-based EID-to-RLOC mappings; that is the role of the control plane node.

827
MCQmedium

A network engineer runs the following command on switch SW2: SW2# show cts role-based sgt-map Active IPv4-SGT Mapping Table: IP Address SGT 192.168.1.10 10 192.168.1.20 20 192.168.1.30 30 Total number of entries: 3 Based on this output, what can be concluded?

A.The switch is using 802.1X to assign SGTs to endpoints.
B.The switch has a static mapping of IP addresses to SGTs.
C.The switch maintains a mapping table that associates IP addresses with SGTs for TrustSec policy enforcement.
D.The switch is using MAB to assign SGTs to endpoints.
AnswerC

The command 'show cts role-based sgt-map' displays the IP-to-SGT mapping table, which is the exact table TrustSec policy enforcement uses. Each row binds a source IP address to a Security Group Tag, and this mapping is what the switch consults when applying SGACLs to traffic. This is the most defensible conclusion because the output is literally this table.

Why this answer

The command 'show cts role-based sgt-map' displays the active IPv4-to-SGT mapping table that the switch uses for Cisco TrustSec policy enforcement. This table is dynamically populated or statically configured to associate IP addresses with Security Group Tags (SGTs), which are then used to apply role-based access control. The output confirms the switch maintains this mapping, making option C correct.

Exam trap

Cisco often tests the distinction between the mapping table itself and the method used to populate it; the trap here is assuming that seeing a populated SGT map implies a specific authentication method (like 802.1X or MAB), when in fact the table can be populated by multiple mechanisms including static configuration or SXP.

How to eliminate wrong answers

Option A is wrong because 802.1X is an authentication method that can be used to assign SGTs via RADIUS attributes (e.g., Cisco-AVPair), but the output does not show any authentication method; it only shows the resulting mapping table. Option B is wrong because the output does not indicate whether the mappings are static or dynamic; the command shows the current table regardless of how entries were learned (e.g., via SGT Exchange Protocol, 802.1X, MAB, or manual configuration). Option D is wrong because MAB (MAC Authentication Bypass) is another authentication method that can assign SGTs, but the output does not reveal the authentication mechanism used to populate the table.

828
Multi-Selectmedium

Which two statements about AAA accounting are true? (Choose two.)

Select 2 answers
A.RADIUS accounting uses UDP as the transport protocol.
B.TACACS+ accounting uses UDP as the transport protocol.
C.The wait-start accounting method delays service until the accounting start packet is acknowledged by the server.
D.AAA accounting is only supported for EXEC sessions, not for network access.
E.TACACS+ encrypts only the password portion of the accounting packet.
AnswersA, C

RADIUS accounting carries its start, stop and interim records over UDP, typically to port 1813, relying on retransmission rather than a connection-oriented session. TACACS+ instead uses TCP, so this UDP transport detail distinguishes RADIUS accounting behaviour in the stated comparison.

Why this answer

Option A is correct because RADIUS accounting operates over UDP, using destination port 1813 (or the legacy 1646), since RADIUS is a UDP-based protocol for authentication, authorization, and accounting. Option C is correct because the wait-start accounting method requires the accounting start record to be acknowledged by the AAA server before the user is granted access, unlike start-stop which sends the start record without waiting for confirmation. Option B is incorrect because TACACS+ uses TCP (port 49), not UDP, for its accounting traffic.

Option D is incorrect because AAA accounting can be applied to EXEC sessions, network access (such as PPP or VPDN), and system-level events, not EXEC sessions alone. Option E is incorrect because TACACS+ encrypts the entire packet body, not just the password portion, which is a characteristic of RADIUS.

Exam trap

350-401 often tests the transport protocol differences between RADIUS (UDP) and TACACS+ (TCP) and the encryption scope (RADIUS encrypts only password, TACACS+ encrypts entire packet), and a common mistake is to assume both use UDP or that TACACS+ only encrypts passwords.

829
MCQeasy

Which type of NAT translates multiple inside addresses to a single outside address using different port numbers?

A.Static NAT
B.Dynamic NAT
C.Port Address Translation (PAT)
D.Policy NAT
AnswerC

Port Address Translation (PAT), also known as NAT overload, is correct because it multiplexes thousands of inside hosts to a single outside IPv4 address by leveraging the transport-layer port number (TCP or UDP) to identify each unique session. The router maintains a translation table that maps (inside local address, inside local port) to (outside global address, outside global port), allowing many internal devices to share one public address simultaneously. This directly addresses the IPv4 exhaustion problem and is the standard method used in home routers and enterprise edge devices.

Why this answer

Port Address Translation (PAT) is a form of dynamic NAT that maps multiple private IP addresses to a single public IP address by differentiating traffic based on Layer 4 port numbers. This allows many internal hosts to share one outside address, conserving public IPv4 addresses. PAT is commonly used on home routers and enterprise edge devices to enable internet access for numerous devices with a single public IP.

Exam trap

Cisco often tests the distinction between Dynamic NAT and PAT by presenting a scenario where multiple inside hosts need internet access with a single public IP, and candidates mistakenly choose Dynamic NAT because they overlook the port-multiplexing requirement.

How to eliminate wrong answers

Option A is wrong because Static NAT provides a one-to-one mapping between a single inside address and a single outside address, without any port multiplexing. Option B is wrong because Dynamic NAT also uses a one-to-one mapping from a pool of public addresses, so it cannot translate multiple inside addresses to a single outside address. Option D is wrong because Policy NAT is used to match specific traffic based on ACLs or routing policies and then apply NAT translations, but it does not inherently perform port multiplexing to share a single outside address.

830
Drag & Dropmedium

Drag and drop the steps of SSL VPN (AnyConnect) session establishment into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The AnyConnect client first establishes a TLS/DTLS tunnel to the ASA headend. The ASA then authenticates the user via AAA. After authentication, the ASA pushes client configuration and assigns an IP address from a pool.

The client installs the virtual adapter with the assigned IP. Finally, the client can send encrypted traffic through the tunnel.

831
MCQmedium

A network engineer executes the following command on Router R3: R3# show ip igmp groups 239.2.2.2 IGMP Connected Group Membership Group Address Interface Uptime Expires Last Reporter 239.2.2.2 GigabitEthernet0/0 1d04h 00:02:10 192.168.1.100 Based on this output, what can be concluded?

A.The multicast group is being sourced from 192.168.1.100.
B.A host at 192.168.1.100 has joined group 239.2.2.2.
C.The router is the RP for this group.
D.The group is using IGMP version 3.
AnswerB

The correct interpretation is that a host with IP address 192.168.1.100 has joined multicast group 239.2.2.2. In the output of “show ip igmp groups” or “show ip igmp group <group>”, the “Last Reporter” field shows the IP address of the host that sent the most recent IGMP Membership Report for that group on that interface. Since the host has sent that report, the router knows to forward multicast traffic destined for 239.2.2.2 to the interface, and the host is an active receiver. This is precisely what the command output is indicating.

Why this answer

The output shows that the multicast group 239.2.2.2 has an active member on interface GigabitEthernet0/0, with the last reporter being 192.168.1.100. In IGMP, the 'Last Reporter' is the host that most recently sent an IGMP membership report for that group, confirming that a host at that IP address has joined the group. Therefore, option B is correct.

Exam trap

Cisco often tests the distinction between the multicast traffic source (the sender) and the IGMP reporter (the receiver), leading candidates to mistakenly assume the 'Last Reporter' is the source of the multicast stream.

How to eliminate wrong answers

Option A is wrong because the 'Last Reporter' field indicates the host that sent the IGMP membership report, not the source of the multicast traffic; the source is identified by the (S,G) state in PIM or IGMP snooping, not by this command. Option C is wrong because the 'show ip igmp groups' command does not provide any information about the Rendezvous Point (RP); RP information is displayed via 'show ip pim rp mapping' or 'show ip pim group-map'. Option D is wrong because the output does not include any IGMP version information; to determine the IGMP version, you would need to examine the router's IGMP configuration or use 'show ip igmp interface' to see the version in use.

832
MCQmedium

A network engineer is configuring a Cisco Wireless LAN Controller (WLC) for a high-density auditorium. The engineer wants to ensure that clients can roam seamlessly between access points while maintaining consistent security policies. Which Cisco wireless architecture feature should be enabled to allow controllers to share client context and facilitate inter-controller roaming?

A.FlexConnect
B.OfficeExtend
C.Mobility Group
D.Mobility Express
AnswerC

A Mobility Group allows multiple Cisco WLCs to share client context and coordinate roaming. When a client roams between access points on different controllers, the controllers exchange information via the mobility group, enabling seamless roaming with consistent security. This is essential for high-density environments with multiple controllers.

Why this answer

A Mobility Group is a set of Cisco WLCs configured to share client context and support seamless roaming. When a client roams between controllers, the controllers exchange information via the mobility group, ensuring that security policies and client state are maintained. This is critical in high-density environments with multiple controllers.

Mobility Express, FlexConnect, and OfficeExtend serve different purposes.

Exam trap

The trap here is confusing FlexConnect, which is for branch survivability, with Mobility Group, which enables inter-controller roaming.

833
Matchingmedium

Drag and drop each STP protection feature on the left to its matching purpose on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Immediately transitions a port to forwarding state

Err-disables a port if a BPDU is received

Prevents a port from becoming the root port

Prevents a port from transitioning to forwarding when BPDUs stop

Why these pairings

PortFast moves a port to forwarding immediately; BPDU Guard err-disables a port upon BPDU reception; Root Guard prevents a port from becoming root; Loop Guard prevents alternate/backup ports from transitioning to forwarding.

834
MCQmedium

A company is implementing QoS on its campus network. The network engineer configures a policy-map that sets the CoS value for voice traffic to 5 on a switch interface. However, when the traffic reaches the router, the CoS marking is lost. What is the most likely reason?

A.The router does not trust the CoS marking and re-marks it to 0.
B.CoS is a Layer 2 marking and is not carried across a Layer 3 hop; the router must map CoS to DSCP.
C.The switch must be configured to set DSCP instead of CoS.
D.The router must have 'mls qos trust cos' configured on the interface.
AnswerB

CoS is a Layer 2 class-of-service field carried exclusively in the 802.1Q VLAN tag, so it is only meaningful on a single Layer 2 segment. When a router receives a frame, it de-encapsulates the Layer 2 header, including the 802.1Q tag, and then forwards the packet as a Layer 3 IP packet. The CoS value is therefore lost and cannot be preserved across a routed hop; the router must explicitly map the incoming CoS value to the IP DSCP field before routing. This mapping must occur at the ingress or before the Layer 3 forwarding decision to maintain end-to-end QoS priority.

Why this answer

CoS (Class of Service) is a Layer 2 marking field in the 802.1Q VLAN tag, which is stripped when a frame passes through a Layer 3 device (router). Since the router operates at Layer 3, it does not preserve the CoS value; instead, the router must map the CoS to a DSCP (Differentiated Services Code Point) value at Layer 3 to maintain QoS across the routed hop. Option B correctly identifies this fundamental Layer 2 vs.

Layer 3 boundary issue.

Exam trap

The trap here is that candidates assume CoS is preserved across routers because they see 'trust cos' on switches, but Cisco tests the understanding that CoS is a Layer 2-only marking that disappears at a Layer 3 boundary, requiring DSCP for inter-VLAN or routed QoS.

How to eliminate wrong answers

Option A is wrong because the router does not automatically 'trust' or 're-mark' CoS to 0; CoS is simply not present in the IP packet after the Layer 2 header is removed, so no re-marking occurs. Option C is wrong because setting DSCP instead of CoS on the switch would not solve the problem—the issue is that CoS is lost at the Layer 3 boundary, and DSCP must be used on the router, but the switch can set both CoS and DSCP; the root cause is the Layer 2/3 demarcation. Option D is wrong because 'mls qos trust cos' is a Catalyst switch command (not a router command) that tells the switch to trust the CoS value on ingress; it does not apply to routers and would not preserve CoS across a Layer 3 hop.

835
Multi-Selecthard

Which three statements about MPLS Layer 3 VPNs are true? (Choose three.)

Select 3 answers
A.Customer edge (CE) routers exchange routing information with provider edge (PE) routers using static routing, RIP, OSPF, EIGRP, or BGP.
B.VRF (Virtual Routing and Forwarding) instances are used on PE routers to maintain separate routing tables for each VPN customer.
C.MP-BGP (Multiprotocol BGP) is used between PE routers to exchange VPNv4 routes, which include an RD and RT.
D.The MPLS core routers (P routers) maintain full VPN routing tables to forward traffic based on customer IP prefixes.
E.Route targets (RT) are used to uniquely identify each customer VPN across the provider network.
AnswersA, B, C

CE routers peer with PE routers at the IP layer, so any standard routing protocol works across that link: static routes, RIP, OSPF, EIGRP or BGP. The PE router then redistributes these customer routes into MP-BGP for transport across the provider backbone.

Why this answer

Option A is correct because the CE-PE routing relationship is a standard routing adjacency in which the CE router can run static routing, RIP, OSPF, EIGRP, or BGP with the PE router; the PE router then redistributes those routes into the appropriate VRF. Option B is correct because VRF instances on PE routers create separate routing and forwarding tables per VPN customer, which keeps overlapping customer address space isolated. Option C is correct because PE routers use MP-BGP to exchange VPNv4 prefixes, and each VPNv4 route carries a route distinguisher (RD) to make the prefix unique plus route targets (RTs) to control import/export into VRFs.

Option D is not correct because P routers in the MPLS core only switch labeled packets and do not maintain customer VPN routing tables; VPN awareness resides at the PE routers. Option E is not correct because route targets are extended BGP community attributes used to control VPN route import and export between VRFs, not to uniquely identify a customer VPN; that uniqueness function is performed by the route distinguisher (RD).

Exam trap

350-401 often tests the RD vs. RT distinction — candidates confuse the RD (uniqueness) with the RT (import/export policy) and incorrectly assume P routers hold VPN routing tables.

836
MCQhard

A network administrator is configuring a Cisco Catalyst 9000 switch to authenticate users via 802.1X. The authentication server is a Cisco Identity Services Engine (ISE). The administrator wants to ensure that if the ISE server becomes unreachable, the switch will allow devices to connect with limited access. Which feature should be configured?

A.MAC Authentication Bypass
B.Critical VLAN
C.Inaccessible Authentication Bypass
D.Guest VLAN
AnswerC

Inaccessible Authentication Bypass (IAB) allows a port to grant access when the authentication server is unreachable. It can be configured to assign the port to a critical VLAN or apply a specific policy. This matches the requirement to allow devices to connect with limited access when ISE is down.

Why this answer

Inaccessible Authentication Bypass is designed to handle the situation where the RADIUS server is unreachable. It allows the switch to apply a preconfigured access policy, often assigning the port to a critical VLAN, ensuring that devices can still connect with limited access. This meets the requirement of maintaining connectivity during server outages.

Exam trap

The trap here is confusing Guest VLAN with Critical VLAN or Inaccessible Authentication Bypass; Guest VLAN is for non-802.1X devices, while IAB is for server unreachability.

837
MCQeasy

A security team wants to protect a web application hosted behind a Cisco IOS router from cross-site scripting and SQL injection attacks without modifying the application itself. Which Cisco IOS feature is designed for this purpose?

A.Zone-Based Policy Firewall
B.IPsec VPN with AES encryption
C.Cisco IOS IPS with signature-based inspection
D.Control Plane Policing
AnswerC

Cisco IOS Intrusion Prevention System inspects packet payloads against signatures and can detect and drop application-layer attacks such as cross-site scripting and SQL injection. Because it examines the content of HTTP requests, it can block malicious patterns without any change to the hosted application, matching the requirement to protect the web app transparently.

Why this answer

Detecting and blocking application-layer attacks like cross-site scripting and SQL injection requires payload inspection, which is what Cisco IOS IPS provides through its signature set. Firewalls, CoPP, and IPsec operate at other layers and cannot identify malicious HTTP content, so signature-based IPS is the appropriate feature when the application itself cannot be modified.

Exam trap

The trap here is confusing stateful firewall policy, which permits or denies flows, with intrusion prevention, which inspects payload content for attack signatures.

838
MCQmedium

A network administrator is configuring a Cisco wireless controller to support a high-density auditorium. The design requires that client devices be evenly distributed across available access points and that roaming be optimized for voice traffic. Which feature should be enabled to achieve these goals?

A.Cisco Aironet Extensions
B.Cisco Client Load Balancing
C.Cisco Band Select
D.Cisco CleanAir
AnswerB

Cisco Client Load Balancing distributes client devices across access points by delaying association responses when an AP is heavily loaded. This helps achieve even distribution in high-density environments. Combined with other features like 802.11k/v, it can optimize roaming, but load balancing itself is the primary feature for even client distribution, making it correct here.

Why this answer

Cisco Client Load Balancing is designed to distribute clients evenly across access points by managing association requests. In a high-density auditorium, this prevents any single AP from becoming overloaded, improving overall performance. For voice roaming, additional features like 802.11k/v/r are recommended, but the primary feature for even distribution is load balancing, which directly addresses the stated requirement.

Exam trap

The trap here is confusing load balancing with band steering or spectrum analysis, which do not address even client distribution across APs.

839
MCQmedium

spanning-tree vlan 10 priority 4096 What is the effect of this global configuration command?

A.The switch will have a bridge priority of 4096 for VLAN 10, increasing its chance to become root bridge.
B.The switch will have a bridge priority of 4096 for all VLANs.
C.The switch will become the root bridge for VLAN 10 immediately.
D.The switch will have a bridge priority of 4096 for VLAN 10 and all other VLANs will use 32768.
AnswerA

The command 'spanning tree vlan 10 priority 4096' sets the bridge priority for the VLAN 10 spanning tree instance to 4096, lowering it from the default 32768. Because STP elects the root bridge using the lowest bridge ID (priority + MAC address), this significantly increases the switch's chances of winning the election for that VLAN. However, it does not guarantee the switch becomes root—any switch with a lower priority value or an equal priority but lower MAC address will still be preferred.

Why this answer

The command `spanning-tree vlan 10 priority 4096` sets the bridge priority for VLAN 10 to 4096. A lower bridge priority value increases the likelihood that this switch will be elected as the root bridge for that VLAN, because the spanning-tree algorithm selects the switch with the lowest bridge priority as the root. However, it does not guarantee immediate root status, as other switches with an even lower priority could still win the election.

Exam trap

Cisco often tests the distinction between setting a priority that influences root election versus guaranteeing root status, leading candidates to mistakenly think the switch becomes root immediately.

How to eliminate wrong answers

Option B is wrong because the command specifies VLAN 10, so the priority change applies only to that VLAN, not to all VLANs. Option C is wrong because setting the priority to 4096 does not force the switch to become root immediately; it only increases its chance, and the root election still depends on comparing priorities with other switches. Option D is wrong because the command does not affect other VLANs; they retain their default priority of 32768, but the statement incorrectly implies that the switch explicitly sets other VLANs to 32768, which is not configured by this command.

840
Multi-Selecthard

Which three statements about VRF-lite are true? (Choose three.)

Select 3 answers
A.VRF-lite allows multiple routing instances on a single router using static or dynamic routing protocols.
B.VRF-lite does not require MPLS to operate.
C.VRF-lite provides path isolation by maintaining separate forwarding tables.
D.VRF-lite supports MPLS VPN inter-AS option B.
E.VRF-lite requires BGP as the routing protocol between VRFs.
AnswersA, B, C

VRF-lite instantiates multiple independent routing and forwarding tables on one device, each running static routes or dynamic protocols such as OSPF or EIGRP. This satisfies the stem's requirement that the statement accurately describes VRF-lite's support for multiple routing instances per router.

Why this answer

VRF-lite is a technology that creates multiple independent routing and forwarding instances on a single physical router, and each VRF can run its own static routes or dynamic routing protocols such as OSPF, EIGRP, or BGP, which is exactly what option A states. Option B is correct because VRF-lite is essentially VRF without MPLS; it relies on separate routing/forwarding tables and interface assignment rather than label switching, so no MPLS infrastructure is needed. Option C is correct because the core mechanism of VRF-lite is path isolation through per-VRF routing tables (and associated FIBs), keeping traffic from different VRFs separate even though they share the same physical device.

Option D is incorrect because MPLS VPN inter-AS option B is a feature of full MPLS L3VPN deployments involving ASBRs exchanging labeled VPNv4 routes, which is beyond VRF-lite's scope. Option E is incorrect because VRF-lite does not mandate BGP; any supported routing protocol or static routing can be used within each VRF.

841
MCQhard

A network engineer runs the following command on Router R1: R1# show mpls ldp neighbor Peer LDP Ident: 10.0.0.2:0, Local LDP Ident: 10.0.0.1:0 TCP connection: 10.0.0.2.646 - 10.0.0.1.179 State: Oper; Msgs sent/rcvd: 100/95; Downstream Up time: 00:10:00 LDP discovery sources: GigabitEthernet0/0, Src IP: 10.0.0.2 Addresses bound to peer LDP Ident: 10.0.0.2 192.168.2.2 Peer LDP Ident: 10.0.0.3:0, Local LDP Ident: 10.0.0.1:0 TCP connection: 10.0.0.3.646 - 10.0.0.1.179 State: Oper; Msgs sent/rcvd: 200/190; Downstream Up time: 00:20:00 LDP discovery sources: GigabitEthernet0/1, Src IP: 10.0.0.3 Addresses bound to peer LDP Ident: 10.0.0.3 192.168.3.3 Based on this output, what can be concluded?

A.The router has two LDP peers that are both operational
B.The router is using LDP in downstream-on-demand mode
C.The LDP session with 10.0.0.2 is down
D.The router has only one LDP neighbor
AnswerA

The output displays two LDP peers with IP addresses 10.0.0.2 and 10.0.0.3. Each peer entry shows 'State: Oper', meaning the LDP sessions are operational and exchanging label bindings. Therefore, the router has two active LDP neighbors, making this statement correct.

Why this answer

The output shows two LDP peers (10.0.0.2 and 10.0.0.3) with the State: Oper for both, indicating both Label Distribution Protocol sessions are fully operational. The 'Downstream' label mode confirms unsolicited downstream label advertisement, which is the default behavior. Therefore, option A is correct.

Exam trap

Cisco often tests the distinction between 'Downstream' and 'Downstream-on-Demand' label advertisement modes, and candidates may mistakenly assume 'Downstream' implies on-demand behavior or overlook the explicit 'State: Oper' field indicating session health.

How to eliminate wrong answers

Option B is wrong because the output explicitly shows 'Downstream' label mode, not 'Downstream-on-Demand' (which would appear as 'Downstream on Demand' or 'DoD'). Option C is wrong because the peer 10.0.0.2 has State: Oper and an uptime of 00:10:00, meaning the session is up, not down. Option D is wrong because the output clearly lists two separate peers (10.0.0.2 and 10.0.0.3), not just one.

842
Multi-Selecthard

Which three statements about the classification and marking tools in Cisco IOS are true? (Choose three.)

Select 3 answers
A.The trust boundary can be configured using the 'mls qos trust' command on a switch port to trust the CoS or DSCP value received from an attached device.
B.NBAR (Network-Based Application Recognition) can classify traffic based on application signatures, including HTTP URLs and SSL certificate fields.
C.Layer 2 CoS marking uses a 3-bit field in the 802.1Q tag, providing 8 possible values, while DSCP uses 6 bits for 64 values.
D.The 'set dscp' command in a policy map can be used to mark packets with a DSCP value, but only on egress interfaces.
E.MPLS EXP bits are a 3-bit field used for QoS in MPLS networks and are always directly mapped from the IP DSCP value without any configuration.
AnswersA, B, C

The mls qos trust command on a switch port establishes the trust boundary, instructing the switch to accept and preserve the CoS or DSCP markings already applied by the attached device instead of reclassifying the traffic.

Why this answer

Option A is correct because the 'mls qos trust' interface command (e.g., 'mls qos trust cos' or 'mls qos trust dscp') establishes the trust boundary on a switch port, instructing the switch to accept and honor the CoS or DSCP values already present in frames received from an attached device rather than re-marking them. Option B is correct because NBAR is a Cisco IOS classification engine that inspects packet payloads and matches application signatures, including HTTP URL strings and SSL/TLS certificate fields, allowing granular application-aware classification beyond simple Layer 3/Layer 4 criteria. Option C is correct because the 802.1Q tag carries a 3-bit Priority Code Point (CoS) field yielding 8 values (0-7), while the IP header's DSCP field is 6 bits yielding 64 values (0-63), which is the fundamental difference in granularity between Layer 2 and Layer 3 marking.

Option D is incorrect because 'set dscp' in a policy map can be applied on ingress or egress, not exclusively egress. Option E is incorrect because MPLS EXP bits are not automatically mapped from IP DSCP; mapping between DSCP and EXP requires explicit configuration (e.g., via table-map or policy), so the 'always directly mapped' claim is false.

Exam trap

The trap here is assuming that 'set dscp' only works on egress or that MPLS EXP is automatically derived from DSCP without configuration; candidates often overlook that marking can occur on ingress and that MPLS QoS requires explicit mapping.

843
MCQmedium

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and NTP. The requirement is to protect the route processor from excessive BGP keepalive traffic while still allowing all legitimate BGP peering. Which CoPP module should the administrator use to classify and police this traffic before the policy is applied to the control plane?

A.A class map that matches BGP traffic using an ACL or NBAR, referenced by a policy map, which is then applied with the service-policy command under control-plane configuration mode.
B.A route map applied inbound on the BGP neighbor session that sets a lower precedence for keepalive packets.
C.A class map referenced by a policy map that is applied outbound on the WAN interface toward the BGP peer.
D.An access list applied directly to the physical interface facing the BGP peer using the ip access-group command.
AnswerA

CoPP on IOS XE uses a modular QoS CLI structure: class maps identify control-plane traffic, a policy map defines policing actions, and the policy is attached to the control plane with service-policy under control-plane mode. Matching BGP via ACL or NBAR lets the administrator police keepalives while permitting other BGP flows, which satisfies the stated requirement.

Why this answer

Control Plane Policing requires a modular QoS configuration: class maps to identify traffic, a policy map to define policer actions, and the service-policy command applied under control-plane configuration mode. This structure allows BGP keepalives to be matched and policed while other traffic is handled separately, directly protecting the route processor as the scenario requires.

Exam trap

The trap here is assuming a route map or interface ACL can police traffic destined to the route processor, when CoPP specifically requires a policy map attached to the control plane.

844
MCQeasy

A network team must design a QoS policy for a WAN link that carries voice, video, and data. The policy must ensure that voice traffic is never dropped, even during congestion. Which queuing mechanism should be used for the voice class?

A.Class-based weighted fair queuing (CBWFQ).
B.Low-latency queuing (LLQ).
C.Weighted random early detection (WRED).
D.First-in, first-out (FIFO) queuing.
AnswerB

LLQ combines class-based weighted fair queueing with a strict priority queue, allowing voice traffic to be placed in a dedicated priority queue that is served before all other queues. This guarantees that voice packets are always served first, providing low latency and eliminating drops for voice traffic even during congestion. To prevent the priority queue from starving other classes, LLQ typically applies a policer to limit the amount of traffic that can use the priority queue.

Why this answer

Low-latency queuing (LLQ) is the correct choice because it combines strict priority queuing with CBWFQ, allowing voice traffic to be placed in a strict priority queue that is serviced first before any other queues. This ensures that voice packets are never dropped due to congestion, as long as the configured policer rate is not exceeded, meeting the requirement that voice traffic is never dropped.

Exam trap

Cisco often tests the misconception that CBWFQ alone can provide low latency for voice, but the trap is that CBWFQ lacks a strict priority queue, so only LLQ guarantees zero drops for real-time traffic during congestion.

How to eliminate wrong answers

Option A is wrong because CBWFQ provides guaranteed bandwidth for each class but does not include a strict priority queue, so voice traffic could still experience delay or drop during congestion if the queue is full. Option C is wrong because WRED is a congestion avoidance mechanism that proactively drops packets before a queue is full, which would cause voice drops and is unsuitable for real-time traffic that requires zero drops. Option D is wrong because FIFO queuing treats all traffic equally with no priority, so during congestion voice packets would be dropped along with other traffic, violating the requirement.

845
MCQmedium

Review the following DHCP relay configuration: ``` interface Vlan10 ip address 192.168.10.1 255.255.255.0 ip helper-address 172.16.1.100 ``` What is the effect of the 'ip helper-address' command?

A.It forwards DHCP requests from VLAN 10 to the DHCP server at 172.16.1.100.
B.It configures the router as a DHCP server for VLAN 10.
C.It translates the source IP of DHCP requests to 192.168.10.1.
D.It blocks DHCP traffic from VLAN 10.
AnswerA

The ip helper-address command on the VLAN 10 SVI enables DHCP relay: the router intercepts the client's Layer 3 broadcast DHCPDISCOVER on interface gi0/0.10, rewrites it as a unicast packet, and forwards it to the configured server at 172.16.1.100. It also populates the giaddr (gateway IP address) field with its own interface IP (192.168.10.1), which tells the server exactly which subnet the client lies on so the correct scope is selected. The server's DHCPOFFER is then routed back to the relay agent, which broadcasts it to the client on VLAN 10.

Why this answer

The 'ip helper-address' command configures the router to act as a DHCP relay agent. It intercepts DHCP broadcast requests from clients on VLAN 10 (subnet 192.168.10.0/24) and unicasts them to the specified DHCP server at 172.16.1.100, allowing the server to assign an IP address from a different subnet. This is defined in RFC 1542 and is essential for centralized DHCP services across multiple VLANs.

Exam trap

Cisco often tests the misconception that 'ip helper-address' translates the source IP address of the DHCP request, when in fact it modifies the giaddr field to enable the server to reply correctly.

How to eliminate wrong answers

Option B is wrong because 'ip helper-address' does not enable the router to act as a DHCP server; it only relays DHCP messages to an external server. Option C is wrong because the command does not translate the source IP; the relay agent changes the gateway IP address (giaddr field) in the DHCP packet to 192.168.10.1, not the source IP. Option D is wrong because the command forwards DHCP traffic, not blocks it; blocking would require an access control list (ACL).

846
MCQmedium

A network engineer is using the Cisco DNA Center Intent API to create a new site hierarchy. The engineer sends a POST request to /dna/intent/api/v1/site with a JSON payload defining the site. The API returns a 202 Accepted response with a task ID. What should the engineer do next to confirm the site was created successfully?

A.Check the DNA Center audit logs to see if the site creation was logged.
B.Resend the POST request with the same payload to ensure the site is created.
C.Use the task ID to poll the GET /dna/intent/api/v1/task/{taskId} endpoint until the task status is 'SUCCESS'.
D.Immediately send a GET request to /dna/intent/api/v1/site to verify the site exists.
AnswerC

The 202 Accepted response includes a task ID for asynchronous operations. The engineer should poll the task endpoint using that ID to check the status. Once the task status is 'SUCCESS', the site creation is complete. This is the standard pattern for DNA Center Intent API operations that are long-running.

Why this answer

When the DNA Center Intent API returns 202 Accepted, it means the request is being processed asynchronously. The response includes a task ID. The engineer must poll the task endpoint with that ID until the status indicates success.

This ensures the site creation is complete before proceeding with dependent tasks.

Exam trap

The trap here is assuming the operation is synchronous and immediately checking for the site, when the 202 response signals asynchronous processing requiring task polling.

847
MCQeasy

A network administrator is configuring a Cisco IOS switch to authenticate users via 802.1X. The administrator wants to ensure that if the RADIUS server is unreachable, users are placed into a guest VLAN with limited access. Which feature should be configured to achieve this?

A.Configure authentication host-mode multi-auth under the interface.
B.Configure authentication open under the interface.
C.Configure authentication event server dead action authorize vlan 100 under the interface.
D.Configure authentication event fail action authorize vlan 100 under the interface.
AnswerC

The authentication event server dead action authorize vlan 100 command instructs the switch to place the port into VLAN 100 if the RADIUS server is considered dead (unreachable). This provides a fallback for users when the authentication server cannot be contacted, allowing limited access as defined by the guest VLAN. This is the correct feature for the scenario.

Why this answer

To place users into a guest VLAN when the RADIUS server is unreachable, the authentication event server dead action authorize vlan command must be configured on the interface. This command triggers the fallback VLAN when the server is marked dead. The other options address different authentication events or host modes and do not provide the required server-dead fallback.

Exam trap

The trap here is confusing authentication failure (wrong credentials) with server unreachability; the commands for each are different, and only the server dead action provides the guest VLAN when the RADIUS server is down.

848
MCQmedium

Given the following configuration snippet on a Cisco IOS-XE switch: interface GigabitEthernet1/0/1 switchport mode access switchport access vlan 10 spanning-tree portfast monitor session 1 source interface GigabitEthernet1/0/1 both monitor session 1 destination interface GigabitEthernet1/0/2 What is the effect of this configuration?

A.All traffic entering and leaving GigabitEthernet1/0/1 is copied to GigabitEthernet1/0/2.
B.Only traffic entering GigabitEthernet1/0/1 is copied to GigabitEthernet1/0/2.
C.Traffic on GigabitEthernet1/0/2 is replicated to GigabitEthernet1/0/1.
D.The configuration is invalid because the destination port must be in trunk mode.
AnswerA

The monitor session statement names GigabitEthernet1/0/1 as source with the 'both' keyword, so ingress and egress frames on that port are replicated to the destination port GigabitEthernet1/0/2. SPAN copies traffic; it does not alter forwarding on the access port.

Why this answer

The configuration uses a local SPAN session to copy traffic from a source interface (GigabitEthernet1/0/1) to a destination interface (GigabitEthernet1/0/2). The keyword 'both' specifies that both ingress and egress traffic on the source port are mirrored, so all traffic entering and leaving GigabitEthernet1/0/1 is sent to the destination port for monitoring.

Exam trap

The trap here is that candidates often confuse 'both' with 'rx' or 'tx' and assume only one direction is mirrored, or they mistakenly think the destination port must be in trunk mode to carry VLAN tags, but in local SPAN the destination port can be an access port and the mirrored frames are sent untagged by default.

How to eliminate wrong answers

Option B is wrong because it claims only ingress traffic is copied, but the 'both' keyword explicitly includes egress traffic as well. Option C is wrong because it reverses the direction of the SPAN session, stating traffic from the destination is replicated to the source, which is not how SPAN works; the source is always the monitored port. Option D is wrong because the destination port in a local SPAN session does not need to be in trunk mode; it can be an access port, and the configuration is valid as long as the destination port is not used for normal data forwarding.

849
Drag & Drophard

Drag and drop the steps of OSPF route redistribution into a different autonomous system into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Redistribution requires first configuring the routing process that will receive the routes, then defining the source protocol and metric, optionally setting route tags for loop prevention, applying a route map for filtering, and finally verifying the redistributed routes appear in the OSPF database.

850
MCQhard

A network engineer is implementing Cisco SD-Access and needs to ensure that the fabric provides policy-based segmentation and mobility for endpoints. Which component is responsible for maintaining the endpoint location and identity information?

A.Cisco Identity Services Engine (ISE)
B.LISP Map-Server
C.Cisco DNA Center
D.VXLAN Tunnel Endpoint (VTEP)
AnswerB

The LISP Map-Server maintains the mapping of endpoint identities (EIDs) to routing locators (RLOCs), effectively tracking endpoint location and identity. It registers EID-to-RLOC mappings from fabric edge nodes and responds to map requests. This enables policy-based segmentation and mobility by allowing endpoints to be reached regardless of their location. Thus, it is the correct component.

Why this answer

The LISP Map-Server is responsible for maintaining endpoint location and identity information in Cisco SD-Access. It registers EID-to-RLOC mappings from fabric edge nodes and provides them to other nodes upon request. This enables seamless mobility and policy-based segmentation, as endpoints can be reached regardless of their physical location.

Other components like DNA Center and ISE play different roles in management and policy.

Exam trap

The trap here is confusing the management plane (DNA Center) or policy plane (ISE) with the control plane (LISP Map-Server) that actually tracks endpoint location and identity.

851
MCQmedium

An engineer is configuring a Cisco IOS XE switch to secure the management plane. The requirement is to allow SSH only from the management subnet 10.10.10.0/24 and block all other management protocols such as Telnet and HTTP. Which configuration approach best meets this requirement?

A.Configure an ACL on the management VLAN SVI to deny Telnet and HTTP, and rely on the default transport input all on the VTY lines.
B.Enable AAA with a local database and configure privilege levels so that only users from 10.10.10.0/24 can log in.
C.Apply an ACL to the VTY lines with transport input ssh and configure the ACL to permit 10.10.10.0/24 only.
D.Configure ip http secure-server, disable ip http server, and apply an ACL to the VTY lines that permits any source using SSH.
AnswerC

Combining transport input ssh on the VTY lines with an access-class ACL that permits only 10.10.10.0/24 restricts remote management to SSH from the management subnet. Telnet and other line-based protocols are refused because transport input is limited to ssh, and non-permitted source addresses are dropped by the ACL before they reach the VTY lines, satisfying both requirements.

Why this answer

The VTY lines control remote management access. Setting transport input ssh disables Telnet and other line protocols, while an access-class ACL applied to the VTY lines filters source addresses before login. Permitting only 10.10.10.0/24 satisfies the subnet restriction.

Together these settings secure the management plane by limiting both the protocol and the source of administrative connections.

Exam trap

The trap here is assuming that disabling HTTP and Telnet on the web server alone secures management access, when VTY line transport and access-class controls are what actually restrict SSH sources.

852
MCQmedium

Examine this configuration: policy-map QOS_POLICY class VOICE priority percent 10 class VIDEO bandwidth percent 30 class class-default fair-queue ! interface GigabitEthernet0/0 service-policy output QOS_POLICY What is the effect of this policy-map?

A.Voice traffic gets strict priority up to 10% of interface bandwidth, video gets at least 30%, and all other traffic is fair-queued.
B.Voice and video both get priority queuing, with voice at 10% and video at 30%.
C.The policy-map is invalid because you cannot use both priority and bandwidth in the same policy-map.
D.The policy-map will only shape traffic, not prioritize it.
AnswerA

In the policy-map, the voice class is configured with the priority command, which creates a strict priority queue capped at 10% of the interface bandwidth, ensuring Voice over IP packets are serviced first and minimizing delay and jitter. The video class uses the bandwidth command, which reserves a minimum of 30% of link capacity for video traffic using class-based weighted fair queuing (CBWFQ), though this does not guarantee immediate scheduling over other classes. All other traffic falls into the default class, where the fair-queue command applies, permitting equal distribution of the remaining bandwidth among remaining flows. Thus, the statement accurately describes the configured queuing behavior.

Why this answer

The policy-map uses the 'priority percent 10' command under class VOICE, which provides strict priority queuing for voice traffic, guaranteeing it is serviced first up to 10% of the interface bandwidth. The 'bandwidth percent 30' command under class VIDEO allocates a minimum bandwidth guarantee of 30% for video traffic, while the 'fair-queue' command under class-default ensures all other traffic shares the remaining bandwidth fairly using Cisco's Class-Based Weighted Fair Queuing (CBWFQ). This configuration is valid and commonly used in enterprise QoS designs to prioritize real-time traffic while still providing bandwidth guarantees for other critical traffic.

Exam trap

Cisco often tests the misconception that 'priority' and 'bandwidth' cannot coexist in the same policy-map, or that 'bandwidth' implies priority queuing, when in fact they serve different roles (strict priority vs. guaranteed minimum bandwidth) and are commonly used together in enterprise QoS designs.

How to eliminate wrong answers

Option B is wrong because it incorrectly states that both voice and video get priority queuing; in this configuration, only the VOICE class uses the 'priority' command, while the VIDEO class uses 'bandwidth', which provides a minimum bandwidth guarantee, not strict priority. Option C is wrong because it claims the policy-map is invalid; Cisco IOS allows the use of both 'priority' and 'bandwidth' commands in the same policy-map, as long as the priority class is configured first and the total bandwidth allocations do not exceed 100%. Option D is wrong because the policy-map does not include any 'shape' command; it applies queuing and scheduling policies (priority, bandwidth, and fair-queue) on output, not traffic shaping.

853
Multi-Selectmedium

Which TWO statements about Cisco DNA Center's Assurance capabilities are correct?

Select 2 answers
A.It uses streaming telemetry to collect data for real-time analytics.
B.It supports only wired networks and not wireless.
C.It is a fully cloud-based solution with no on-premises components.
D.It only displays network device health scores and does not provide path tracing.
E.It can proactively detect potential issues based on historical trends.
AnswersA, E

Streaming telemetry pushes continuous, model-driven data from network devices to Cisco DNA Center, enabling near real-time analytics rather than polling-based SNMP collection. This satisfies the stem's Assurance requirement for live health monitoring, rapid fault detection and granular visibility into device and client performance across the fabric.

Why this answer

Option A is correct because Cisco DNA Center Assurance relies on streaming telemetry (model-driven telemetry pushed from devices) rather than legacy SNMP polling, enabling near real-time analytics and faster issue detection. Option E is correct because Assurance applies machine learning and baseline analytics to historical data, allowing it to proactively identify trends and predict potential problems before they impact users. Option B is incorrect because Assurance covers both wired and wireless networks, including wireless client onboarding and RF health monitoring.

Option C is incorrect because DNA Center is typically deployed as an on-premises appliance (with cloud-managed options like DNA Center in the cloud, but not exclusively cloud-based). Option D is incorrect because Assurance provides far more than health scores, including path trace, client 360 views, and network topology analysis.

Exam trap

The trap here is that candidates often assume DNA Center is purely cloud-based or only supports wired networks, but Cisco deliberately tests the hybrid deployment model and the unified wired/wireless assurance scope.

854
MCQmedium

Examine the following IPsec configuration snippet: crypto ikev2 proposal IKEV2_PROP encryption aes-cbc-256 integrity sha256 group 14 ! crypto ikev2 policy IKEV2_POL proposal IKEV2_PROP ! crypto ipsec transform-set TSET esp-aes 256 esp-sha256-hmac mode tunnel ! crypto ipsec profile IPSEC_PROF set transform-set TSET set ikev2-profile IKEV2_POL Which statement about this configuration is true?

A.The transform set uses ESP with AES-256 encryption and SHA-256 HMAC for authentication.
B.The IKEv2 proposal uses AES-256, SHA-256, and DH group 14, but the IPsec profile will not apply because the ikev2-profile command is missing the 'set' keyword.
C.The transform set is configured in transport mode, which is incorrect for site-to-site VPN.
D.The IPsec profile is incomplete because it does not include a PFS (Perfect Forward Secrecy) setting.
AnswerA

The transform set is correctly defined. The commands `esp-aes 256` and `esp-sha256-hmac` under `crypto ipsec transform-set` specify the Encapsulating Security Payload (ESP) with AES-256 for confidentiality and the SHA-256 HMAC variant for integrity and authentication. This is a valid and secure combination for a site-to-site IPsec VPN. The statement matches the configuration, making it the correct answer.

Why this answer

The transform set explicitly uses 'esp-aes 256' for encryption and 'esp-sha256-hmac' for authentication, which matches the description of ESP with AES-256 encryption and SHA-256 HMAC. The IKEv2 proposal and profile are correctly configured, and the 'mode tunnel' command ensures the transform set operates in tunnel mode, which is appropriate for site-to-site VPNs.

Exam trap

Cisco often tests the distinction between the IKEv2 proposal (control plane) and the IPsec transform set (data plane), and the trap here is that candidates might confuse the 'set ikev2-profile' command syntax or assume PFS is mandatory, when in fact the configuration is valid as shown.

How to eliminate wrong answers

Option B is wrong because the 'set ikev2-profile' command is correctly used within the crypto ipsec profile; the syntax is 'set ikev2-profile [name]', and the snippet shows 'set ikev2-profile IKEV2_POL', which is valid. Option C is wrong because the transform set is configured with 'mode tunnel', not transport mode, making it suitable for site-to-site VPNs. Option D is wrong because PFS is not a mandatory component of an IPsec profile; it is an optional setting that can be added via 'set pfs' under the transform set or IKEv2 proposal, but its absence does not make the profile incomplete.

855
MCQmedium

A network engineer runs the following command on Router R4: R4# show policy-map interface GigabitEthernet0/1 GigabitEthernet0/1 Service-policy input: SHAPE_POLICY Class-map: class-default (match-any) 1000 packets, 100000 bytes 5 minute offered rate 100000 bps, drop rate 0 bps Match: any Queueing shape (average) cir 500000, bc 5000, be 5000 target shape rate 500000 Based on this output, what can be concluded?

A.Traffic is being shaped to an average rate of 500 kbps.
B.Traffic is being policed to 500 kbps.
C.The policy is applied to output traffic.
D.The offered rate exceeds the shaping rate, causing drops.
AnswerA

The `shape` command with a CIR of 500000 bits per second configures a token-bucket shaper that limits the long-term average transmit rate to 500 kbps. Unlike policing, shaping smooths traffic by buffering excess packets in a queue, then sending them at the configured rate, so the output is a regulated, even flow rather than bursty with drops. This is exactly what the policy-map does for the matched traffic.

Why this answer

The output shows a shape (average) cir 500000 with a target shape rate of 500000, which is 500,000 bps (500 kbps). Shaping buffers excess traffic to enforce an average rate, unlike policing which drops or marks. The 'drop rate 0 bps' confirms no drops are occurring, so traffic is being shaped to 500 kbps.

Exam trap

Cisco often tests the distinction between shaping and policing, where candidates confuse the 'shape' keyword with 'police' or misinterpret the 'input' direction as output, especially when the interface is GigabitEthernet0/1 and the policy is named SHAPE_POLICY.

How to eliminate wrong answers

Option B is wrong because the command is 'shape (average)', not 'police', and shaping buffers traffic rather than dropping or marking it like policing does. Option C is wrong because the output explicitly states 'Service-policy input: SHAPE_POLICY', indicating the policy is applied to input traffic, not output. Option D is wrong because the offered rate is 100,000 bps, which is below the shaping rate of 500,000 bps, and the drop rate is 0 bps, so no drops are occurring.

856
MCQhard

A network engineer configures model-driven telemetry on a Cisco IOS-XE device using gRPC dial-out. The subscription configuration snippet is: ``` telemetry ietf subscription 100 encoding encode-kvgpb filter xpath /interfaces/interface/statistics stream yang-push update-policy periodic 500 receiver ip address 10.1.1.1 50001 protocol grpc-tcp ``` What is the primary issue with this configuration?

A.The 'encoding' should be 'encode-json' or 'encode-gpb' instead of 'encode-kvgpb' for gRPC.
B.The 'stream' should be 'yang-notif' instead of 'yang-push'.
C.The 'update-policy periodic' value must be between 100 and 1000 milliseconds.
D.The 'receiver' command should specify 'protocol grpc' instead of 'grpc-tcp'.
AnswerA

The encoding in a gRPC telemetry receiver must be either 'encode-json' or 'encode-gpb' because gRPC natively carries JSON or Google Protocol Buffers payloads. 'encode-kvgpb' (Key Value GPB) is a legacy binary encoding used with Cisco's old telemetry transport over TCP, not with gRPC. If you specify 'encode-kvgpb' under a gRPC receiver, the session fails to establish or sends malformed data. Therefore, the correct fix is to switch the encoding to 'encode-json' or 'encode-gpb'.

Why this answer

GRPC dial-out on Cisco IOS-XE requires the encoding to be 'encode-gpb' (GPB) or 'encode-json' (JSON), not 'encode-kvgpb'. The 'encode-kvgpb' encoding is used for gRPC dial-in (subscriptions initiated by the collector), not dial-out. Using the wrong encoding will cause the telemetry data to be malformed or rejected by the receiver.

Exam trap

Cisco often tests the distinction between dial-in and dial-out telemetry configurations, specifically that 'encode-kvgpb' is only valid for dial-in, while dial-out requires 'encode-gpb' or 'encode-json', leading candidates to mistakenly assume any GPB encoding works for both.

How to eliminate wrong answers

Option B is wrong because 'yang-push' is the correct stream for model-driven telemetry subscriptions that push YANG-defined data; 'yang-notif' is not a valid stream type in this context. Option C is wrong because the 'update-policy periodic' value of 500 milliseconds is valid; there is no mandatory range of 100–1000 milliseconds, and values outside that range are permitted. Option D is wrong because 'protocol grpc-tcp' is the correct syntax for specifying gRPC over TCP in dial-out subscriptions; 'protocol grpc' alone is ambiguous and not a valid command.

857
Multi-Selecthard

Which three statements about hypervisor security and isolation are true? (Choose three.)

Select 3 answers
A.A VM escape attack occurs when an attacker breaks out of a virtual machine to access the hypervisor or other VMs.
B.Virtual machines are inherently isolated from each other and do not require any additional security measures.
C.The hypervisor must enforce memory and device isolation to prevent one VM from accessing another VM's data.
D.Regularly patching the hypervisor and reducing its attack surface are important security practices.
E.Virtual machines have direct access to physical hardware resources such as CPU and memory.
AnswersA, C, D

A VM escape exploits a hypervisor or virtualisation flaw so code running inside a guest breaks containment, reaching the hypervisor or neighbouring VMs. This is precisely the definition the stem requires: breaking out of a virtual machine to access the hypervisor or other VMs.

Why this answer

Option A is correct because a VM escape is precisely the class of attack in which code running inside a guest breaks the virtualization boundary to reach the hypervisor or other guests, which is why hypervisor hardening matters. Option C is correct because the hypervisor (or VMM) is responsible for partitioning and enforcing isolation of memory, CPU, and I/O devices, typically via hardware-assisted virtualization features such as Intel VT-x/EPT or AMD-V/RVI, so one VM cannot read or write another VM's data. Option D is correct because the hypervisor is a high-value attack surface, so applying vendor patches and minimizing exposed services and virtual devices (reducing attack surface) are standard hardening practices.

Option B is wrong because VMs are only isolated if the hypervisor and its configuration are secure; they are not inherently safe and still need patching, monitoring, and access controls. Option E is wrong because guest VMs access virtualized hardware presented by the hypervisor, not the physical CPU and memory directly, which is what enables the isolation the hypervisor enforces.

Exam trap

The trap here is the misconception that VMs are automatically secure due to isolation, leading candidates to overlook the need for hypervisor patching and hardening, or to assume VMs have direct hardware access when the hypervisor mediates all interactions.

858
Drag & Dropmedium

Drag and drop the steps of YANG module import and augmentation resolution into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order follows YANG module processing: first the module is imported, then its base schema is parsed, next augmentations are resolved, then conflicts are detected, and finally the complete schema tree is built.

859
MCQmedium

A network engineer runs the following command on Router R2: R2# show crypto ipsec sa peer 10.2.2.2 interface: Tunnel0 Crypto map tag: CMAP, local addr 10.1.1.2 protected vrf: (none) local ident (addr/mask/prot/port): (10.1.1.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port): (10.2.2.0/255.255.255.0/0/0) current_peer 10.2.2.2 port 500 PERMIT, flags={origin_is_acl,} #pkts encaps: 1500, #pkts encrypt: 1500, #pkts digest: 1500 #pkts decaps: 1200, #pkts decrypt: 1200, #pkts verify: 1200 #pkts compressed: 0, #pkts decompress: 0 #pkts not compressed: 0, #pkts compr. failed: 0 #pkts not decompressed: 0, #pkts decompress failed: 0 #send errors 0, #recv errors 0 Based on this output, what can be concluded?

A.The IPsec tunnel is functioning correctly with no issues.
B.There is a routing problem causing packets to be dropped in one direction.
C.The tunnel is using compression, as shown by the compress counters.
D.The remote peer is not responding to IKE requests.
AnswerB

A routing problem is indicated by the higher encaps count compared to decaps count. This means packets are being encrypted and sent into the tunnel, but fewer packets are arriving and being decrypted from the remote peer. Typically, this is caused by missing return routes, asymmetric routing, or firewall rules that drop encrypted traffic in one direction, leading to packet loss.

Why this answer

The output shows 1500 packets encapsulated and encrypted (outbound) but only 1200 packets decapsulated and decrypted (inbound). This asymmetry indicates that 300 packets were sent but not returned, which points to a routing issue causing packets to be dropped in one direction. A properly functioning IPsec tunnel should have roughly symmetric packet counts in both directions if traffic is bidirectional.

Exam trap

Cisco often tests the ability to interpret IPsec SA counters, where candidates mistakenly assume that any non-zero counters mean the tunnel is fully functional, ignoring the critical asymmetry between outbound and inbound packet counts.

How to eliminate wrong answers

Option A is wrong because the packet counts are asymmetric (1500 out vs 1200 in), which indicates a problem rather than a fully functional tunnel. Option C is wrong because the compress counters are all zero, showing that compression is not being used. Option D is wrong because the tunnel has established an IPsec SA (as shown by the encaps/decaps counters), meaning IKE phase 1 and phase 2 completed successfully and the remote peer is responding.

860
MCQeasy

A network engineer is configuring a Cisco Nexus 9000 switch as a VXLAN Tunnel Endpoint. The engineer needs to define the source interface used for the VXLAN tunnels and map VLANs to a VNI. Which command sequence accomplishes this?

A.interface nve1, then source-interface loopback1, then member vni 10000 associated-vrf tenant1
B.interface nve1, then source-interface loopback1, then member vni 10000, then vlan 100 under the VNI
C.feature nv overlay, interface nve1, source-interface loopback1, member vni 10000, then under interface Vlan100 configure vn-segment 10000
D.interface vxlan1, then source-interface loopback1, then vni 10000 vlan 100 mapping
AnswerC

This sequence enables the NV overlay feature, creates the NVE interface, sets the loopback as the tunnel source, adds the VNI as a member, and maps VLAN 100 to VNI 10000 using vn-segment under the SVI. This is the correct Nexus 9000 method for defining a VTEP and binding a VLAN to a VNI for Layer 2 VXLAN bridging. All required elements are present and correctly placed.

Why this answer

On Nexus 9000 NX-OS, VXLAN configuration requires enabling the NV overlay feature, creating interface nve1, specifying the loopback as the tunnel source, adding the VNI as a member, and mapping the VLAN to the VNI with vn-segment under the VLAN interface. The other options misplace commands or use syntax from other platforms.

Exam trap

The trap here is mixing up the placement of the VLAN-to-VNI mapping, which belongs under the VLAN interface as vn-segment, not under the NVE interface or the VNI member configuration.

861
MCQmedium

A Python script uses NAPALM to retrieve the ARP table from a Cisco IOS-XE device: from napalm import get_network_driver driver = get_network_driver('ios') device = driver('192.168.1.1', 'admin', 'cisco') device.open() arp_table = device.get_arp_table() print(arp_table) device.close() What is the issue with this script?

A.The script will fail because the driver name 'ios' is incorrect; it should be 'iosxe' for IOS-XE devices.
B.The script will work correctly because 'ios' is the correct driver for all Cisco IOS devices.
C.The script will fail because the 'get_arp_table()' method requires an argument.
D.The script will work but only if the device is running IOS-XE 16.12 or later.
AnswerA

The NAPALM driver name must match the device's actual operating system family. For IOS-XE devices, the correct driver is 'iosxe' because that driver uses the appropriate command syntax and parser for IOS-XE's 'show ip arp' output, while the 'ios' driver is reserved for classic Cisco IOS (e.g., Catalyst 2960 running IOS 15.x). Passing 'ios' to an IOS-XE device will make NAPALM issue classic IOS commands that IOS-XE may reject or parse incorrectly, causing the script to fail with an error such as 'unable to execute command' or an invalid output error.

Why this answer

The NAPALM driver for Cisco IOS-XE devices is 'iosxe', not 'ios'. The 'ios' driver is designed for classic Cisco IOS, which uses a different data model and CLI structure. Using 'ios' on an IOS-XE device will cause NAPALM to fail when attempting to retrieve data like the ARP table due to incompatible command outputs or missing XML/JSON structures.

Exam trap

Cisco often tests the misconception that 'ios' is a catch-all driver for all Cisco IOS-based devices, when in fact IOS-XE requires a separate driver due to its modern API support.

How to eliminate wrong answers

Option B is wrong because the 'ios' driver is not universally compatible with all Cisco IOS devices; it specifically targets classic IOS, while IOS-XE requires the 'iosxe' driver to handle its NETCONF/RESTCONF-based data models. Option C is wrong because the 'get_arp_table()' method in NAPALM does not require any arguments; it retrieves the full ARP table by default. Option D is wrong because the script will fail regardless of the IOS-XE version; the driver name mismatch is a fundamental configuration error that prevents connection, not a version-dependent feature.

862
MCQmedium

Given the following SNMP configuration on a Cisco IOS-XE router: snmp-server community public RO snmp-server community private RW snmp-server location Building-A snmp-server contact admin@example.com snmp-server enable traps snmp linkdown linkup snmp-server host 192.168.1.100 version 2c public What is the effect of this configuration?

A.The router will send SNMP traps to 192.168.1.100 using community string 'public' for linkdown and linkup events.
B.The router will send SNMP traps to 192.168.1.100 using community string 'private' for all SNMP traps.
C.The router will only accept SNMP read requests using community 'public' and write requests using community 'private'.
D.The router will send SNMPv3 traps to 192.168.1.100 using authentication.
AnswerA

The command `snmp-server enable traps snmp linkdown linkup` explicitly enables only the linkDown and linkUp notifications, and `snmp-server host 192.168.1.100 public` designates 192.168.1.100 as the trap receiver using the community string 'public'. Because version 2c is the default for this command, the traps are sent as SNMPv2c with 'public' as the community string. This is the intended behavior described in the question, so this option is correct.

Why this answer

The `snmp-server host` command specifies the destination for SNMP notifications, and the community string 'public' is explicitly included in the command, overriding the default behavior of using the first configured RW community. The `snmp-server enable traps snmp linkdown linkup` command enables only linkdown and linkup traps. Therefore, the router sends only those two trap types to 192.168.1.100 using the 'public' community string.

Exam trap

Cisco often tests the fact that the community string in the `snmp-server host` command explicitly overrides the default trap community, and that only the traps listed in the `enable traps` command are sent, not all possible traps.

How to eliminate wrong answers

Option B is wrong because the `snmp-server host` command explicitly uses 'public', not 'private', and the configuration only enables linkdown and linkup traps, not 'all' SNMP traps. Option C is wrong because it describes the effect of the `snmp-server community` commands (read-only for 'public', read-write for 'private'), but the question asks specifically about the effect of the entire configuration, including the trap-related commands; the trap behavior is the focus. Option D is wrong because the command specifies `version 2c`, which uses SNMPv2c community-based security, not SNMPv3 authentication.

863
MCQmedium

An architect is planning a virtualized infrastructure for a branch office that will host a Cisco ISRv router and a local DHCP server. The architect wants to minimize management overhead and ensure the VMs can be easily backed up. Which hypervisor deployment model is most appropriate?

A.Deploy a Type 1 hypervisor on the branch server and manage VMs via a centralized vCenter or similar tool.
B.Use a Type 2 hypervisor on a desktop PC at the branch.
C.Run the ISRv and DHCP server as containers on the same host.
D.Install the ISRv directly on physical hardware without virtualization.
AnswerA

A Type 1 hypervisor runs directly on the branch server's hardware without a host OS, delivering near-native performance for production VM workloads. Centralized management via vCenter or a similar tool provides enterprise-grade features such as live migration, centralized logging, role-based access control, and snapshot-based backup—essential for managing a branch ISRv and DHCP server. This approach maintains the isolation and resource control needed for a virtual router while giving administrators a single pane of glass for the entire branch environment.

Why this answer

A Type 1 hypervisor (bare-metal) runs directly on the server hardware, providing near-native performance for the Cisco ISRv router and DHCP server. Centralized management via vCenter or similar tools reduces administrative overhead and enables efficient VM backup and recovery, meeting the architect's requirements for minimal management overhead and easy backup.

Exam trap

Cisco often tests the distinction between Type 1 and Type 2 hypervisors in the context of network functions like ISRv, where the trap is that candidates may choose a Type 2 hypervisor for simplicity, overlooking the performance and management overhead penalties for production branch office deployments.

How to eliminate wrong answers

Option B is wrong because a Type 2 hypervisor runs on top of an existing operating system (e.g., VMware Workstation on Windows), which adds overhead, reduces performance for network functions like ISRv, and complicates backup and centralized management. Option C is wrong because containers share the host OS kernel and do not provide the full virtualization isolation required for a Cisco ISRv router, which expects a dedicated virtual machine environment; containers also complicate backup compared to VM snapshots. Option D is wrong because installing ISRv directly on physical hardware eliminates virtualization benefits, making backup more difficult (physical server backup vs.

VM snapshots) and increasing management overhead for the branch office.

864
MCQmedium

A network engineer configures SNMPv2c on a Cisco router to monitor CPU and memory utilization. The NMS is reachable and configured with the same community string 'public'. However, the NMS receives no traps from the router. The engineer verifies that the router's SNMP configuration includes 'snmp-server enable traps' and 'snmp-server host 192.168.1.100 version 2c public'. What is the most likely cause of the missing traps?

A.The router's SNMP agent is disabled.
B.The community string 'public' is not defined on the router.
C.The router lacks specific trap configuration for CPU and memory utilization.
D.The NMS is using SNMPv3, which is incompatible with SNMPv2c traps.
AnswerC

This is correct because 'snmp-server enable traps' alone only enables the trap subsystem globally; it does not automatically enable every notification type. On Cisco IOS, high CPU and memory utilization traps require explicit configuration with commands such as 'snmp-server enable traps cpu threshold' and 'snmp-server enable traps memory', often combined with 'snmp-server cpu threshold' to set the actual trigger level. Without these specific commands, the router will not emit the desired performance traps.

Why this answer

SNMPv2c requires explicit trap configuration for specific MIB objects. The 'snmp-server enable traps' command enables generic trap notifications (like linkUp/linkDown), but CPU and memory utilization traps are defined in the CISCO-PROCESS-MIB and CISCO-MEMORY-POOL-MIB, which require additional 'snmp-server enable traps cpu' and 'snmp-server enable traps memory' commands. Without these specific configurations, the router will not send CPU or memory utilization traps even if the NMS is reachable.

Exam trap

Cisco often tests the misconception that 'snmp-server enable traps' alone enables all trap types, when in fact it only enables generic traps, and specific MIB-based traps (like CPU and memory) require additional subcommands.

How to eliminate wrong answers

Option A is wrong because the SNMP agent is implicitly enabled when SNMP is configured (e.g., via 'snmp-server community' or 'snmp-server host'), and the engineer has already applied SNMP commands, so the agent is active. Option B is wrong because the 'snmp-server host' command includes the community string 'public', which implicitly defines that community string on the router; no separate 'snmp-server community public' is required for trap generation. Option D is wrong because the NMS is configured with the same community string 'public' and the router is sending traps using SNMPv2c; SNMPv3 and SNMPv2c are not inherently incompatible for trap reception if the NMS supports both versions, and the question states the NMS is configured with the same community string, implying it is using SNMPv2c.

865
MCQhard

A network architect is designing a Cisco SD-Access fabric. The requirement is to provide secure segmentation for different departments without deploying separate physical networks or traditional VRFs on every switch. Which Cisco SD-Access component provides this segmentation by using a group-based policy model?

A.Access Control List (ACL)
B.Scalable Group Tag (SGT)
C.VLAN pool
D.Virtual Routing and Forwarding (VRF)
AnswerB

SGTs are used in Cisco SD-Access to provide micro-segmentation. Each endpoint is assigned an SGT, and group-based policies (SGACLs) enforce traffic between groups. This allows segmentation without traditional VRFs on every switch, meeting the requirement for secure departmental separation.

Why this answer

Cisco SD-Access uses Scalable Group Tags (SGTs) to implement group-based segmentation. Endpoints are assigned SGTs, and Security Group ACLs (SGACLs) enforce policy between groups. This approach provides micro-segmentation without the need for traditional VRFs on every switch, simplifying operations and improving security.

Exam trap

The trap here is assuming that VRFs are the only way to segment traffic, overlooking the identity-based, group-policy model that SD-Access provides through SGTs.

866
MCQhard

A network architect is designing a QoS policy for a Cisco Catalyst switch. The architect needs to ensure that voice traffic is marked with the appropriate DSCP value for expedited forwarding. Which DSCP value should be used for voice traffic?

A.CS7 (56)
B.CS6 (48)
C.AF31 (26)
D.EF (46)
AnswerD

EF (Expedited Forwarding) with DSCP value 46 is the standard marking for voice traffic. It provides low latency, low jitter, and low loss, which are critical for voice quality. Voice traffic should be marked with EF to ensure it receives priority treatment in the network. This is a widely accepted best practice.

Why this answer

Voice traffic should be marked with DSCP EF (46) to ensure expedited forwarding, which provides low latency, jitter, and loss. Other DSCP values like AF31 are used for call signaling, while CS6 and CS7 are reserved for network control. Proper marking ensures that voice packets receive priority treatment in QoS-enabled networks.

Exam trap

The trap here is confusing voice payload marking with call signaling marking, or using control traffic DSCP values for voice.

867
MCQmedium

Examine this IP SLA configuration on Router R1: ip sla 4 icmp-echo 10.4.4.4 frequency 10 ip sla schedule 4 life forever start-time now ip sla reaction-configuration 4 react timeout threshold-type immediate action-type triggerOnly Which of the following is missing from this configuration to make it useful for tracking?

A.A 'track' object that references the IP SLA operation is missing.
B.The 'frequency' command is missing; it should be set to 60 seconds.
C.The 'ip sla responder' must be configured on the target router.
D.The 'life' parameter should be set to a specific number of repetitions.
AnswerA

An IP SLA operation on its own only generates probe results; it has no effect on routing, redundancy, or other services until those results are consumed by a tracking object. The missing piece is a command like 'track 1 ip sla 7389dc reachability' (or 'track 1 ip sla 7389dc' on some software versions) that polls the operation's return code and exposes it as an up/down state. Without a track object, nothing references the IP SLA, so the router never acts on the probe failure—hence the correct answer.

Why this answer

The IP SLA operation is configured to monitor reachability to 10.4.4.4 and trigger an action on timeout, but without a 'track' object that references this IP SLA operation, the router has no mechanism to use the SLA state to influence routing decisions (e.g., via route policy or static route tracking). The 'track' object is essential to bridge the IP SLA monitoring to a routing or policy action, making the configuration useful for failover or conditional routing.

Exam trap

Cisco often tests the misconception that configuring IP SLA alone is sufficient for tracking, when in fact the 'track' object is the mandatory link that makes the SLA state actionable for routing or policy decisions.

How to eliminate wrong answers

Option B is wrong because the 'frequency 10' command is already present and set to 10 seconds, which is a valid and often appropriate interval; there is no requirement to set it to 60 seconds. Option C is wrong because 'ip sla responder' is only needed for UDP jitter or other one-way SLA operations that require a response from the target; for ICMP echo, the target router responds natively to ICMP packets without any special responder configuration. Option D is wrong because the 'life forever' parameter is perfectly valid for continuous monitoring; setting a specific number of repetitions would cause the SLA to stop after that count, which is typically undesirable for tracking purposes.

868
MCQmedium

A network engineer is troubleshooting intermittent connectivity issues between two switches connected via a trunk link. The engineer notices that the port counters show a high number of CRC errors and runts on one side. Which action should the engineer take first?

A.Check the cable and connectors for damage or loose connections.
B.Increase the MTU size on the interface.
C.Configure the interface with a different duplex setting.
D.Disable Dynamic Trunking Protocol (DTP) on the interface.
AnswerA

CRC errors and runts are statistical counters that typically indicate frame corruption at the data-link layer, almost always rooted in physical-layer problems. Faulty patch cables, damaged RJ-45 connectors, improper termination, or electromagnetic interference near the cable can cause bit-level corruption that the NIC detects as cyclic redundancy check failures. Runts—frames shorter than 64 bytes—frequently accompany this condition when transceivers detect a signal loss or electrical anomaly mid-frame. Therefore, inspecting the physical path from the switchport through the patch panel to the end device is the first and most effective troubleshooting step.

Why this answer

CRC errors and runts on a trunk link typically indicate a Layer 1 physical-layer issue, such as faulty cabling, damaged connectors, or poor termination. The first and most logical step is to inspect and test the physical cable and connectors, as this is the most common root cause and the easiest to verify before making configuration changes.

Exam trap

Cisco often tests the principle that Layer 1 issues must be resolved first before considering Layer 2 or Layer 3 changes, and the trap here is that candidates jump to configuration changes (like duplex or DTP) instead of verifying the physical medium.

How to eliminate wrong answers

Option B is wrong because increasing the MTU size would not resolve CRC errors or runts; it could actually exacerbate the problem by allowing larger frames that are more susceptible to corruption on a faulty physical link. Option C is wrong because duplex mismatch usually causes alignment errors, late collisions, or FCS errors, not specifically CRC errors and runts; moreover, modern switches with auto-negotiation rarely have duplex issues unless manually misconfigured. Option D is wrong because disabling DTP addresses trunk negotiation and VLAN tagging issues, not physical-layer errors like CRC and runts.

869
MCQmedium

router bgp 65000 bgp router-id 10.0.0.1 neighbor 10.0.0.2 remote-as 65001 neighbor 10.0.0.2 route-map SET_MED out ! route-map SET_MED permit 10 set metric 50 ! What is the effect of this configuration on routes advertised to 10.0.0.2?

A.All routes sent to 10.0.0.2 will have the MED value set to 50.
B.Routes received from 10.0.0.2 will have their MED set to 50.
C.The local preference of routes sent to 10.0.0.2 is set to 50.
D.The configuration is invalid because MED cannot be set on outbound updates.
AnswerA

With the route-map applied to the neighbor in the outbound direction, every BGP route that is being advertised toward 10.0.0.2 is processed through the 'set metric 50' command. This sets the MULTI_EXIT_DISC (MED) attribute to 50 on those advertised routes, thereby signaling the external peer that this path is more preferred for incoming traffic. Since the direction is explicitly 'out', the policy applies only to updates leaving the router toward 10.0.0.2.

Why this answer

The route-map SET_MED is applied to outbound updates to neighbor 10.0.0.2, and the 'set metric 50' command sets the Multi-Exit Discriminator (MED) attribute to 50 for all routes advertised to that neighbor. The MED is a metric used to influence inbound traffic from the AS of the neighbor, and it is propagated to the neighbor's BGP table.

Exam trap

Cisco often tests the distinction between outbound and inbound route-map application, and the trap here is confusing the 'set metric' command (which sets MED) with 'set local-preference' or assuming that MED cannot be set on outbound updates.

How to eliminate wrong answers

Option B is wrong because the route-map is applied to outbound updates ('out'), not inbound updates, so it does not affect routes received from 10.0.0.2. Option C is wrong because the 'set metric' command sets the MED, not the local preference; local preference is set using 'set local-preference' and is used for outbound traffic within the local AS. Option D is wrong because the configuration is valid; MED can be set on outbound updates using a route-map with the 'set metric' command, and this is a common practice for influencing path selection in neighboring ASes.

870
MCQmedium

router bgp 65000 bgp router-id 10.0.0.1 neighbor 10.0.0.2 remote-as 65001 neighbor 10.0.0.2 route-map SET_ORIGIN in ! route-map SET_ORIGIN permit 10 set origin incomplete ! What is the effect of this configuration?

A.Routes received from 10.0.0.2 will have their origin set to incomplete, making them less preferred compared to IGP origin.
B.Routes sent to 10.0.0.2 will have their origin set to incomplete.
C.The router will not advertise any routes with origin incomplete to other peers.
D.The configuration is invalid because origin cannot be changed with a route-map.
AnswerA

A route-map applied in the inbound direction to neighbor 10.0.0.2 will process received BGP updates and modify their origin attribute to incomplete (value 2). Since origin is a well-known mandatory attribute considered during best-path selection, incomplete is less preferred than IGP (0) or EGP (1). This makes the route less attractive within BGP path selection.

Why this answer

The route-map SET_ORIGIN is applied as an inbound filter to neighbor 10.0.0.2. When a route is received, the 'set origin incomplete' command changes the origin attribute to incomplete (value 2). In BGP path selection, origin incomplete is the least preferred origin type, making these routes less preferred than routes with IGP (value 0) or EGP (value 1) origin.

Exam trap

Cisco often tests the directionality of route-maps (in vs out) and the fact that origin can be modified with a route-map, leading candidates to mistakenly think the route-map applies to outbound updates or that origin is immutable.

How to eliminate wrong answers

Option B is wrong because the route-map is applied 'in' (inbound), not 'out' (outbound), so it affects received routes, not sent routes. Option C is wrong because the configuration does not filter or suppress routes; it only modifies the origin attribute of received routes, and routes with origin incomplete can still be advertised to other peers. Option D is wrong because the origin attribute can be changed using a route-map with the 'set origin' command; this is a valid BGP configuration.

871
Drag & Dropmedium

Drag and drop the steps of Streaming telemetry sensor path subscription flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First a sensor path is defined, then a subscription is created with destination, the device pushes data periodically, the collector receives and processes, and the subscription can be updated or deleted.

872
MCQmedium

Examine the following telemetry configuration on a Cisco IOS-XE device: telemetry ietf subscription 200 encoding encode-kvgpb filter xpath /interfaces/interface[name='GigabitEthernet0/0/0']/state stream yang-push update-policy on-change receiver ip address 192.168.1.100 50001 protocol grpc Which statement is true about this configuration?

A.Data is pushed only when a change occurs in the state of GigabitEthernet0/0/0.
B.Data is pushed every 200 seconds to the collector.
C.The subscription uses JSON encoding.
D.The filter selects all interfaces, not just GigabitEthernet0/0/0.
AnswerA

The update-policy on-change setting makes the subscription push telemetry only when the subscribed YANG state data changes, rather than at fixed intervals. The xpath filter scopes this to GigabitEthernet0/0/0's state, so no periodic stream occurs while values remain static.

Why this answer

This subscription uses on-change update policy, so data is pushed only when a change occurs in the specified subtree.

873
MCQmedium

Examine this SNMP configuration snippet from a Cisco IOS-XE router: snmp-server community MyComm RO 10 access-list 10 permit 192.168.1.0 0.0.0.255 What is the effect of this configuration?

A.SNMP read requests from any host in the 192.168.1.0/24 network using community 'MyComm' will be accepted.
B.SNMP read and write requests from 192.168.1.0/24 using community 'MyComm' will be accepted.
C.Only SNMP requests from the 192.168.1.0/24 network are allowed, regardless of community string.
D.The access-list 10 is incomplete; it needs a deny statement to block other traffic.
AnswerA

The access-list 10 is used as a source IP filter that permits exactly the 192.168.1.0/24 subnet, and this ACL is explicitly associated with the community string 'MyComm' through an SNMP server command (e.g., snmp-server community MyComm RO 10). Because the RO (read-only) keyword is present, only read operations such as GET, GETNEXT, and GETBULK are allowed; write operations like SET are silently rejected even for hosts in the permitted network. Therefore, any device in 192.168.1.0/24 that supplies the correct community string can successfully perform SNMP reads, while all other sources are implicitly denied by the ACL's implicit deny rule.

Why this answer

The `snmp-server community MyComm RO 10` command creates an SNMPv2c community string named 'MyComm' with read-only (RO) access, and the trailing '10' references access-list 10. Access-list 10 permits only the 192.168.1.0/24 subnet. The combined effect is that SNMP GET (read) requests from any host in that subnet using the community string 'MyComm' are accepted, while all other SNMP requests are implicitly denied.

Exam trap

Cisco often tests the distinction between 'RO' and 'RW' in SNMP community strings, and the trap here is that candidates assume 'RO' still allows write operations or that the ACL alone controls access without the community string.

How to eliminate wrong answers

Option B is wrong because the 'RO' keyword explicitly restricts access to read-only; write (SET) requests are not permitted. Option C is wrong because the community string 'MyComm' is still required; the access list does not bypass community string validation. Option D is wrong because the access list is complete—Cisco IOS uses an implicit 'deny any' at the end of an access list, so no explicit deny statement is needed to block other traffic.

874
Multi-Selectmedium

Which three statements about path isolation using VRF are true? (Choose three.)

Select 3 answers
A.VRFs allow overlapping IP addresses between different virtual networks on the same router.
B.VRF-lite can provide path isolation without the use of MPLS.
C.VRF-based path isolation ensures encryption of all data between VRFs.
D.A VRF can be used to separate customer traffic in a service provider network.
E.VRF-lite requires a full mesh of trunk links between all routers in the network.
AnswersA, B, D

Each VRF maintains its own separate routing and forwarding table, so identical IP prefixes can exist in different VRFs on the same router without conflict. This satisfies the stem's requirement for overlapping IP addresses between virtual networks.

Why this answer

Option A is correct because a VRF maintains a separate routing and forwarding table (RIB/FIB) per virtual network, so the same IP prefix, such as 10.0.0.0/24, can exist in multiple VRFs on the same router without conflict. Option B is correct because VRF-lite implements path isolation using only VRFs and per-VRF interface/static or routing-protocol instances, without requiring MPLS labels or an MPLS-enabled core. Option D is correct because service providers commonly use VRFs (for example, in MPLS L3VPN or VRF-lite designs) to keep each customer's traffic in a distinct routing and forwarding instance, preventing route leakage between customers.

Option C is not correct because VRFs provide logical separation of routing and forwarding, not cryptographic protection; encryption would require IPsec or another security mechanism. Option E is not correct because VRF-lite does not mandate a full mesh of trunk links; it relies on per-VRF subinterfaces or links and appropriate routing, and full-mesh topologies are not a VRF-lite requirement.

Exam trap

The trap here is confusing VRF with encryption or assuming VRF-lite requires a full mesh; candidates often mistakenly think VRFs provide security through encryption, but they only provide logical separation.

875
MCQeasy

A network engineer is configuring a Cisco Catalyst switch to send flow data to a NetFlow collector for traffic analysis. The engineer wants to ensure that only ingress traffic on a specific interface is exported. Which command is required to enable NetFlow on that interface?

A.ip flow egress
B.ip route-cache flow
C.ip flow-export destination
D.ip flow ingress
AnswerD

The 'ip flow ingress' command enables NetFlow for ingress traffic on the interface. It tells the switch to capture flow data for packets entering that interface and export it to the configured collector. This is the correct command to meet the requirement of exporting only ingress traffic from a specific interface.

Why this answer

To enable NetFlow for ingress traffic on a specific interface, the 'ip flow ingress' command must be applied in interface configuration mode. This command activates flow capture for packets entering the interface. The other options either enable egress flow, use an outdated method, or configure the export destination rather than enabling flow capture.

Exam trap

The trap here is mixing up the interface-level command to enable NetFlow with the global command to define the collector destination.

876
Multi-Selecthard

Which three statements about YANG data models are true? (Choose three.)

Select 3 answers
A.YANG is used to define data models for NETCONF and RESTCONF.
B.YANG models are written in XML syntax.
C.YANG supports hierarchical data structures using containers and lists.
D.YANG modules are compiled into MIB files for SNMP.
E.YANG includes built-in data types such as string, int32, and enumeration.
AnswersA, C, E

YANG provides the schema language describing configuration and state data, and both NETCONF and RESTCONF use those models to structure their payloads. This shared modelling role is why the same YANG module can be consumed by either protocol.

Why this answer

Option A is correct because YANG (RFC 7950) is the standard data modeling language used to define the configuration and state data manipulated by NETCONF (RFC 6241) and RESTCONF (RFC 8040) protocols. Option C is correct because YANG organizes data hierarchically using constructs such as containers (for grouping nodes) and lists (for repeated entries keyed by leaf values), enabling tree-structured schemas. Option E is correct because YANG defines built-in types including string, int32, uint32, boolean, enumeration, and others, which can be used directly or restricted via derived types.

Option B is not correct because YANG modules are written in a dedicated YANG syntax, not XML; XML is only one of the encodings (alongside JSON) used to represent YANG-modeled data on the wire. Option D is not correct because YANG modules are not compiled into SNMP MIBs; SNMP uses SMIv2 MIBs, and YANG-to-MIB translation is a separate, non-standard mapping, not a compilation step.

Exam trap

350-401 often tests whether candidates confuse YANG (the modeling language) with XML (an encoding) and with SNMP MIBs (a completely separate management framework).

877
Drag & Dropmedium

Drag and drop the steps of BGP route aggregation and suppress-map process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order for BGP route aggregation with suppress-map is: first, define a prefix-list to match the more-specific routes you want to suppress. Second, create a route-map with a suppress clause that references the prefix-list. Third, configure the aggregate-address in BGP under the address-family.

Fourth, apply the suppress-map to the aggregate-address command (typically as part of the aggregate-address command itself). Finally, verify the summary route and the suppressed routes.

878
MCQeasy

A network engineer is using the Python requests library to interact with a Cisco IOS XE device's RESTCONF API. The engineer wants to retrieve the configured hostname. Which HTTP method and URI should be used?

A.PUT https://<device-ip>/restconf/data/Cisco-IOS-XE-native:native/hostname
B.POST https://<device-ip>/restconf/data/Cisco-IOS-XE-native:native/hostname
C.GET https://<device-ip>/restconf/data/Cisco-IOS-XE-native:native/hostname
D.GET https://<device-ip>/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1
AnswerC

This is the correct RESTCONF URI to retrieve the hostname from the Cisco IOS XE native YANG model. The GET method is used to read data. The URI path follows the YANG model structure, starting with the module name and then the data node. This will return the hostname if configured.

Why this answer

To retrieve the hostname via RESTCONF, the engineer must use the GET method with the correct URI that points to the hostname leaf in the Cisco IOS XE native YANG model. The URI structure includes the module name (Cisco-IOS-XE-native), the container (native), and the leaf (hostname). This is a straightforward read operation.

Exam trap

The trap here is confusing the HTTP methods for reading versus writing, and mixing up YANG models for different data.

879
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP relay agent for a subnet that has no local DHCP server. The DHCP server is at 10.10.10.5, and the router interface facing the clients is GigabitEthernet0/1 with IP address 10.20.20.1. Which command must be applied to the interface so that client DHCP broadcasts are forwarded to the server?

A.ip helper-address 10.10.10.5
B.ip dhcp relay 10.10.10.5
C.ip forward-protocol udp 67
D.ip dhcp pool CLIENT relay 10.10.10.5
AnswerA

The ip helper-address command is configured on the client-facing interface and instructs the router to forward UDP broadcasts, including DHCP DISCOVER and REQUEST, to the specified server as unicast packets. It also inserts the giaddr field with the interface IP so the server can select the correct pool. This directly satisfies the scenario.

Why this answer

DHCP relay is enabled by placing ip helper-address on the interface receiving client broadcasts. The router then converts those broadcasts into unicast packets toward the specified server and populates the giaddr field so the server can identify the correct subnet. The other commands either do not exist, do not specify a server, or configure the router as a server rather than a relay, so they do not meet the requirement.

Exam trap

The trap here is confusing DHCP server pool configuration with DHCP relay configuration, which are separate features applied in different configuration modes.

880
MCQeasy

A network engineer is monitoring traffic from a server connected to a Cisco Catalyst 3850 switch. The engineer configures a SPAN session with source interface Gi1/0/1 and destination interface Gi1/0/24. The monitoring station receives traffic, but the engineer notices that the destination port is not forwarding any normal traffic. What is the most likely reason?

A.The destination port is automatically configured as a SPAN destination port, which disables normal switching on that port.
B.The destination port must be configured as a trunk port to forward SPAN traffic.
C.The destination port must be configured as an access port to forward SPAN traffic.
D.The destination port is in an err-disabled state due to a loop.
AnswerA

In a SPAN configuration, the switch automatically reconfigures the designated destination port as a SPAN destination port. This places the port into a specialized monitoring mode where it no longer participates in the normal Layer 2 forwarding process, meaning it will not forward unicast or broadcast frames destined for end stations. Consequently, any device connected to that port will lose normal network connectivity and only receive the copied traffic from the SPAN session. This automatic behavior is a core characteristic of Cisco switches and is the direct cause of the observed symptom.

Why this answer

When a port is configured as a SPAN destination port, the switch automatically disables normal switching (Layer 2 forwarding) on that interface. This is because the destination port is dedicated to receiving mirrored copies of traffic from the source port and forwarding them to an external monitoring device. As a result, the destination port will not forward any normal traffic, which explains the engineer's observation.

Exam trap

Cisco often tests the misconception that a SPAN destination port can still forward normal traffic or that it requires a specific switchport mode (trunk or access), when in fact the switch automatically disables all normal switching on that port.

How to eliminate wrong answers

Option B is wrong because a SPAN destination port does not need to be a trunk port; it can be any switchport mode, and the switch automatically disables normal switching on it regardless of trunk or access configuration. Option C is wrong because a SPAN destination port does not need to be an access port; the port's mode is irrelevant as normal switching is disabled. Option D is wrong because the destination port is not in an err-disabled state; it is operational but its normal forwarding function is intentionally disabled by the SPAN configuration.

881
MCQmedium

A network engineer uses NAPALM to retrieve the ARP table from a Cisco IOS-XE device: ```python from napalm import get_network_driver driver = get_network_driver('ios') device = driver('192.168.1.1', 'admin', 'cisco123') device.open() arp_table = device.get_arp_table() print(arp_table) device.close() ``` What is the expected data type of arp_table?

A.A list of dictionaries, each with keys such as 'interface', 'ip', 'mac', and 'age'.
B.A dictionary with keys 'arp_table' and a list of tuples.
C.A string containing the raw CLI output of 'show arp'.
D.A list of strings, each representing an ARP entry.
AnswerA

NAPALM's get_arp_table() method returns a list of dictionaries, not raw text or a custom wrapper. Each dictionary represents a single ARP entry and includes structured keys such as 'interface', 'ip', 'mac', and 'age', making the data directly usable in Python logic such as filtering or comparison. This is the expected data model for NAPALM across multiple network platforms, because it normalizes vendor-specific CLI output into a consistent, machine-readable format.

Why this answer

NAPALM's `get_arp_table()` method returns a list of dictionaries, where each dictionary represents a single ARP entry with keys such as 'interface', 'ip', 'mac', and 'age'. This is the standardized data structure across all NAPALM-supported platforms, including Cisco IOS-XE, ensuring consistent programmatic access to ARP table data.

Exam trap

Cisco often tests the misconception that NAPALM returns raw CLI output (Option C) or a nested dictionary (Option B), when in fact it returns a list of dictionaries for table-like data such as ARP tables.

How to eliminate wrong answers

Option B is wrong because NAPALM's `get_arp_table()` does not return a dictionary with an 'arp_table' key; it returns a flat list of dictionaries directly. Option C is wrong because NAPALM abstracts away raw CLI output; it returns structured data (list of dicts), not a string of 'show arp' output. Option D is wrong because each ARP entry is a dictionary with multiple fields (interface, IP, MAC, age), not a simple string; a list of strings would lose the structured key-value pairs.

882
MCQmedium

A network engineer is configuring a new Cisco Catalyst 9300 switch stack. The design requires that if the active switch fails, the standby switch takes over the active role, and the member switch that was formerly standby becomes the new standby. The engineer needs to verify and influence the election order. Which mechanism determines the active and standby switch election in a switch stack?

A.The switch that is powered on first becomes active, and the switch that is powered on last becomes standby.
B.The switch with the lowest MAC address is always active, and the switch with the highest MAC address is always standby.
C.The switch with the highest serial number becomes active, and the switch with the second-highest serial number becomes standby.
D.The switch with the highest priority value becomes active, and the switch with the second-highest priority becomes standby.
AnswerD

In a Cisco switch stack, the active and standby switches are elected based on the stack priority value. If priorities are equal, the switch with the lowest MAC address wins. This priority can be configured with the 'switch X priority Y' command, allowing deterministic control over which member becomes active and which becomes standby.

Why this answer

Stack priority is the primary factor in electing the active and standby switches. A higher priority wins; if priorities are equal, the lower MAC address wins. This allows administrators to design deterministic failover by setting priorities appropriately.

The other options incorrectly cite MAC address, serial number, or power-on order as the primary election criteria.

Exam trap

The trap here is assuming that the first switch powered on or the one with the lowest MAC address always becomes active, overlooking the configurable stack priority that can override these factors.

883
MCQmedium

Consider the following EIGRP configuration on a Cisco IOS router: router eigrp 100 network 10.0.0.0 passive-interface default no passive-interface GigabitEthernet0/1 What is the effect of this configuration?

A.All interfaces except GigabitEthernet0/1 are passive and will not form EIGRP adjacencies.
B.EIGRP hellos are sent on all interfaces, but GigabitEthernet0/1 is prevented from forming adjacencies.
C.Only the network 10.0.0.0 is advertised, and all interfaces are passive.
D.EIGRP will only form adjacencies on interfaces with an IP address in the 10.0.0.0/8 range.
AnswerA

The command 'passive-interface default' under EIGRP configuration flips the default behavior so that every interface is passive unless explicitly excluded. A passive interface does not send or process EIGRP hello packets, so it cannot form an adjacency with any neighbor. By then issuing 'no passive-interface GigabitEthernet0/1' (or the equivalent), only that interface remains active and capable of establishing EIGRP neighbors, while all other interfaces stay passive.

Why this answer

The 'passive-interface default' command sets all interfaces to passive by default, preventing them from sending EIGRP hellos and forming adjacencies. The 'no passive-interface GigabitEthernet0/1' command then overrides this default for that specific interface, allowing it to send hellos and form adjacencies. Therefore, only GigabitEthernet0/1 is active for EIGRP neighbor discovery, while all other interfaces remain passive.

Exam trap

Cisco often tests the interaction between 'passive-interface default' and 'no passive-interface' to see if candidates understand that the default command makes all interfaces passive, and the 'no' form selectively activates only the specified interface, rather than the reverse.

How to eliminate wrong answers

Option B is wrong because it reverses the logic: 'passive-interface default' prevents hellos on all interfaces by default, not sends them, and 'no passive-interface' enables hellos on the specified interface, not prevents them. Option C is wrong because the 'network 10.0.0.0' command enables EIGRP on any interface whose IP address falls within the 10.0.0.0/8 range, but the passive-interface configuration still controls whether hellos are sent and adjacencies formed; the configuration does not make all interfaces passive—only the default passive setting does, which is overridden for GigabitEthernet0/1. Option D is wrong because the 'network 10.0.0.0' command does not restrict adjacency formation to only 10.0.0.0/8 interfaces; it enables EIGRP on those interfaces, but the passive-interface default command would still prevent adjacencies on all interfaces except GigabitEthernet0/1, regardless of their IP address range.

884
Multi-Selectmedium

A network engineer is deploying VXLAN EVPN on a Cisco Nexus 9000 switch. Which two statements about the configuration of the NVE interface are true? (Choose two.)

Select 2 answers
A.The NVE interface is a physical interface that connects to the underlay network.
B.The NVE interface requires an IP address to be configured directly on it.
C.The NVE interface can be configured with multiple source interfaces for redundancy.
D.The NVE interface must be configured with a source interface that is reachable via the underlay network.
E.Each VNI must be associated with the NVE interface using the member vni command.
AnswersD, E

The source interface for the NVE interface must be reachable via the underlay network so that VXLAN tunnels can be established. Typically, a loopback interface is used, and its IP address must be advertised into the underlay routing protocol. Without reachability, VXLAN traffic cannot be encapsulated and forwarded to remote VTEPs.

Why this answer

The two true statements are that the NVE interface must have a source interface reachable via the underlay network, and each VNI must be associated with the NVE interface using the member vni command. These are essential for VXLAN operation. The source interface provides the VTEP IP, and the VNI association enables VXLAN encapsulation for specific VNIs.

Exam trap

The trap here is assuming that the NVE interface is a physical interface or that it requires an IP address directly, when in fact it is a logical interface that relies on a separate source interface.

885
Multi-Selecthard

A network engineer is deploying Cisco SD-WAN in a hybrid cloud environment. The company requires secure segmentation between guest, employee, and IoT traffic across all branches. The engineer must ensure that traffic from each segment is isolated and that policies can be applied per segment. Which two components are used to achieve this segmentation? (Choose two.)

Select 2 answers
A.VPN segments in vManage
B.Application-aware routing policies
C.VRF instances on WAN Edge devices
D.IPsec tunnels between branches
E.VLANs on the WAN Edge routers
AnswersA, C

VPN segments in vManage allow the creation of separate virtual private networks (VPNs) within the SD-WAN overlay. Each segment has its own routing table and can be assigned to different VRFs on the WAN Edge devices. This provides isolation between guest, employee, and IoT traffic. Policies can be applied per VPN segment, enabling granular control. This is a core mechanism for segmentation in Cisco SD-WAN.

Why this answer

In Cisco SD-WAN, segmentation is achieved by creating VPN segments in vManage and mapping them to VRF instances on the WAN Edge devices. The VPN segments define the logical separation, and the VRFs enforce it by maintaining separate routing and forwarding tables. Together, they provide end-to-end isolation and allow policies to be applied per segment.

Other options like VLANs or IPsec tunnels do not provide fabric-wide segmentation, and application-aware routing policies are for path selection, not isolation.

Exam trap

The trap here is confusing segmentation mechanisms with transport security or local VLANs, which do not provide end-to-end isolation across the SD-WAN fabric.

886
Matchingmedium

Drag and drop each syslog severity level on the left to its matching severity number on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

0

1

2

3

4

Why these pairings

Emergency=0, Alert=1, Critical=2, Error=3, Warning=4, Notice=5, Informational=6, Debug=7.

887
MCQeasy

A network administrator is configuring a Cisco IOS switch and needs to verify the current VLAN configuration, including VLAN IDs, names, and status. Which command should be used?

A.show vlan brief
B.show interfaces switchport
C.show vlan id 1
D.show vlan summary
AnswerA

The show vlan brief command displays a concise summary of all VLANs, including VLAN ID, name, status, and the ports assigned to each VLAN. This provides exactly the information needed to verify the current VLAN configuration on the switch.

Why this answer

The show vlan brief command is the standard way to display all VLANs on a switch, including their IDs, names, status, and associated ports. It gives a comprehensive overview that allows an administrator to quickly verify the VLAN configuration. Other commands either filter to a single VLAN or provide only summary counts.

Exam trap

The trap here is selecting a command that shows VLAN information but not the complete list, such as show vlan id or show vlan summary.

888
MCQmedium

Consider the following configuration on a Cisco 9800 WLC: ap join-profile default-join-profile description "Default Join Profile" controller 1 primary 10.1.1.1 controller 2 secondary 10.1.1.2 What is the purpose of this configuration?

A.It configures the AP's management IP address.
B.It specifies the WLCs that the AP should attempt to join in order of priority.
C.It enables CAPWAP DTLS encryption.
D.It defines the AP's radio parameters.
AnswerB

This command specifies the WLCs that the AP should attempt to join in order of priority. It uses the primary and secondary keywords to set the order of preferred controllers, ensuring that the AP attempts to join its intended WLC first before falling back to other options. This is crucial for load balancing and for ensuring that the AP is managed by the correct controller in a multi-WLC environment.

Why this answer

This configuration defines the primary and secondary controller IP addresses within an AP join profile on a Cisco 9800 WLC. The AP uses these addresses to prioritize which WLC to join via CAPWAP discovery, attempting the primary controller first and falling back to the secondary if the primary is unreachable. Option B correctly identifies this as specifying the WLCs in order of priority.

Exam trap

Cisco often tests the distinction between AP join profiles (which control controller priority) and AP-specific or RF profiles (which control radio parameters), leading candidates to confuse the purpose of the join profile with radio configuration.

How to eliminate wrong answers

Option A is wrong because the AP's management IP address is typically obtained via DHCP or statically configured on the AP itself, not through a WLC join profile. Option C is wrong because CAPWAP DTLS encryption is enabled via separate configuration (e.g., 'ap dtls' or 'crypto pki' commands), not by listing controller IPs. Option D is wrong because radio parameters (e.g., channel, power, band) are configured in AP-specific or RF profiles, not in the join profile which controls controller discovery and association.

889
MCQmedium

A network administrator is configuring a Cisco IOS router to terminate a site-to-site IPsec VPN with a remote peer that uses dynamic public IP addressing. The administrator wants the router to accept IKE negotiations from any peer that presents a valid pre-shared key and matches a specific protected subnet. Which configuration element is required to support this?

A.A dynamic crypto map entry referenced by a static crypto map, with the remote peer address set to 0.0.0.0.
B.A static crypto map with set peer 0.0.0.0 and a wildcard pre-shared key on the local router.
C.An IKEv2 profile with match identity remote address 0.0.0.0 and a certificate map for peer authentication.
D.A GRE tunnel with IPsec transport mode protecting the tunnel endpoints and dynamic routing over the tunnel.
AnswerA

When the remote peer has an unknown or changing IP address, the headend uses a dynamic crypto map entry with no set peer address so it can accept IKE proposals from any source. A static crypto map references the dynamic map with the set crypto map dynamic command, allowing the router to learn the peer address from the incoming negotiation and apply the correct transform set and ACL.

Why this answer

To accept IPsec negotiations from a peer whose IP address is not known in advance, the headend uses a dynamic crypto map entry that has no configured peer address. A static crypto map references it, so incoming IKE negotiations can be matched, the peer address learned, and the appropriate transform set and ACL applied to build the tunnel.

Exam trap

The trap here is thinking that a wildcard pre-shared key alone allows any peer, when the crypto map must also be dynamic to learn the unknown peer address.

890
MCQmedium

Examine the following RSPAN configuration on a Cisco switch: vlan 200 name RSPAN_VLAN remote-span monitor session 3 source interface GigabitEthernet1/0/5 both monitor session 3 destination remote vlan 200 interface GigabitEthernet1/0/10 switchport mode trunk switchport trunk allowed vlan 200 What is missing for RSPAN to function correctly across multiple switches?

A.The RSPAN VLAN 200 must be created on all switches that will forward the mirrored traffic.
B.The destination remote vlan 200 command should include 'encapsulation replicate'.
C.The source interface must be in trunk mode to monitor VLANs.
D.The monitor session number must match on all switches.
AnswerA

RSPAN mirrors traffic onto a dedicated VLAN, and in order for those mirrored frames to be bridged from the source switch to the destination switch, every switch along the path must have VLAN 200 created and permitted on its trunks. This VLAN is special: it is configured with the 'remote-span' command so that it is not treated as a regular user data VLAN, and if it is missing or pruned on any intermediate switch, the analyzed traffic will simply be dropped, and the network analyzer will never see the mirrored frames.

Why this answer

For RSPAN to operate across multiple switches, the RSPAN VLAN (VLAN 200) must be created and configured with the 'remote-span' command on every switch that will forward the mirrored traffic. Without this, intermediate switches will not treat VLAN 200 as a special RSPAN VLAN, causing the mirrored frames to be dropped or mishandled. The configuration shown only creates the RSPAN VLAN on the local switch, but other switches in the path also need the VLAN and the 'remote-span' command to propagate the mirrored traffic correctly.

Exam trap

Cisco often tests the misconception that the monitor session number must be consistent across switches, but the trap here is that the RSPAN VLAN must be created on all intermediate switches with the 'remote-span' command, not just the source and destination switches.

How to eliminate wrong answers

Option B is wrong because 'encapsulation replicate' is used in local SPAN to copy the original encapsulation (e.g., dot1q) from the source interface to the destination port, but it is not required or valid for RSPAN destinations, which use a remote VLAN. Option C is wrong because the source interface in an RSPAN session does not need to be in trunk mode; it can be an access port or trunk port, and the 'both' keyword already captures ingress and egress traffic regardless of the port mode. Option D is wrong because the monitor session number is locally significant to each switch and does not need to match across switches; RSPAN uses the VLAN number to identify the mirrored traffic, not the session number.

891
Multi-Selecthard

A network security engineer is deploying Cisco TrustSec in a campus network. The engineer wants to implement Security Group Tagging (SGT) and enforce policies based on SGTs. Which two mechanisms can be used to propagate SGTs between network devices? (Choose two.)

Select 2 answers
A.RADIUS Change of Authorization (CoA) with SGT attributes
B.Inline tagging using Cisco Metadata (CMD) in the Ethernet frame
C.Native tagging (inline tagging) within the Ethernet frame
D.SGT Exchange Protocol (SXP)
E.IPsec Encapsulating Security Payload (ESP) with SGT extension
AnswersC, D

Native tagging, also known as inline tagging, inserts the SGT into the Ethernet frame using the Cisco TrustSec header. This allows switches and routers that support TrustSec hardware to read the SGT directly from the frame and enforce policies without needing an external mapping protocol. It is the preferred method for high-performance SGT propagation in the campus.

Why this answer

SGTs can be propagated between network devices using two primary mechanisms: native tagging (inline tagging) where the SGT is embedded in the Ethernet frame, and SXP where the SGT bindings are exchanged via a control-plane protocol. These methods allow enforcement points to apply Security Group ACLs based on the source SGT.

Exam trap

The trap here is confusing RADIUS CoA with SGT propagation, when CoA is only for session authorization changes.

892
MCQeasy

A network engineer is using the Cisco DNA Center REST API to retrieve the list of network devices. The engineer sends a GET request to '/dna/intent/api/v1/network-device' and receives a 400 Bad Request response. The API documentation indicates that the request requires a query parameter 'siteId'. What should the engineer do to resolve the issue?

A.Include the 'siteId' query parameter in the request URL.
B.Change the HTTP method to POST because GET is not supported for this endpoint.
C.Add an 'Authorization' header with a valid token because the API requires authentication.
D.Use a different API endpoint, such as '/dna/intent/api/v1/site', to retrieve device information.
AnswerA

The 400 error arises because the endpoint mandates the siteId query parameter, so appending it to the URL satisfies that validation requirement. Without it, Cisco DNA Center rejects the request before processing. Adding ?siteId=<value> returns the device list correctly.

Why this answer

A 400 Bad Request indicates the server could not process the request due to a client-side error, and the API documentation explicitly states that the 'siteId' query parameter is required. Adding it to the URL (e.g., /dna/intent/api/v1/network-device?siteId=<id>) supplies the missing input and resolves the error. The HTTP method and endpoint are already correct per the documentation.

Exam trap

350-401 often tests HTTP status code semantics — candidates frequently misattribute 400 errors to authentication (401) or method issues (405) instead of recognizing a missing or malformed request parameter.

How to eliminate wrong answers

Option B is wrong because the endpoint is documented as a GET; changing to POST would not fix a missing required parameter and would likely return 405 Method Not Allowed. Option C is wrong because a missing Authorization header would produce 401 Unauthorized, not 400 Bad Request — the engineer would have received a different status code if authentication were the issue. Option D is wrong because /dna/intent/api/v1/site returns site information, not the device list, so it does not satisfy the original goal of retrieving network devices.

893
MCQmedium

Consider the following configuration: class-map match-any VOICE match ip dscp ef class-map match-any VIDEO match ip dscp af41 match ip dscp af42 What is the effect of the match-any keyword in these class-maps?

A.A packet must match all specified DSCP values to be classified into the class.
B.A packet matching either DSCP EF or AF41 will be classified into both classes.
C.A packet matching any one of the specified DSCP values is classified into that class.
D.The match-any keyword is invalid for DSCP matching; only match-all is supported.
AnswerC

The match-any keyword in a class-map means the match conditions are combined with a logical OR. Consequently, a packet is classified into that class if it matches any one of the specified DSCP values—for example, either DSCP EF or AF41. This is the standard behavior for DSCP-based classification in the Modular QoS CLI (MQC).

Why this answer

The `match-any` keyword in a Cisco class-map means that a packet needs to match only one of the listed match criteria to be classified into that class. In the VIDEO class-map, a packet matching either DSCP AF41 or AF42 will be classified as VIDEO. This is the default behavior for class-maps when no keyword is specified, but explicitly using `match-any` reinforces that logical OR operation is applied.

Exam trap

Cisco often tests the confusion between `match-any` (logical OR) and `match-all` (logical AND), expecting candidates to mistakenly think that `match-any` requires all conditions or that it causes a packet to be placed into multiple classes simultaneously.

How to eliminate wrong answers

Option A is wrong because `match-any` uses logical OR, not AND; a packet does not need to match all specified DSCP values. Option B is wrong because a packet matching DSCP EF would be classified only into the VOICE class, not both classes, as class-maps are evaluated independently and a single packet can match multiple class-maps but the keyword does not cause cross-classification. Option D is wrong because `match-any` is perfectly valid for DSCP matching; Cisco IOS supports both `match-any` and `match-all` keywords in class-map definitions.

894
MCQeasy

A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote access using SSL VPN. The requirement is to allow users to connect via a web browser and access internal web applications without installing a client. Which feature should the administrator configure?

A.Configure 'ip http server' and 'ip http secure-server' to allow web access to internal applications.
B.Configure 'webvpn' with 'enable' and set up a context with a gateway and a port-forward or URL list.
C.Configure 'crypto ssl server' and 'crypto ssl client' policies for the SSL VPN.
D.Configure 'crypto isakmp policy' and 'crypto ipsec transform-set' for remote access.
AnswerB

Cisco SSL VPN (WebVPN) allows clientless access through a browser. Enabling 'webvpn' and configuring a context with a gateway provides the entry point, while URL lists or port-forwarding define accessible resources. This meets the requirement for browser-based access without a client. It is the standard configuration for clientless SSL VPN on Cisco IOS.

Why this answer

Clientless SSL VPN on Cisco IOS is configured using the 'webvpn' feature. Enabling 'webvpn' and creating a context with a gateway, along with URL lists or port-forwarding, allows users to access internal web applications through a browser without a client. Other options either require a client or do not provide VPN functionality.

Exam trap

The trap here is confusing the router's HTTP management server with the WebVPN feature, or assuming IPsec can provide clientless access.

895
Multi-Selecthard

A network automation team is evaluating RESTCONF as a replacement for CLI scraping on Cisco IOS XE devices. They need to understand the operational characteristics of RESTCONF to design their tooling. Which two statements accurately describe RESTCONF behavior on Cisco IOS XE? (Choose two.)

Select 2 answers
A.RESTCONF uses HTTP methods such as GET, POST, PUT, PATCH, and DELETE to manipulate YANG-modeled data.
B.RESTCONF requires a candidate datastore to be enabled before any configuration changes can be made.
C.RESTCONF uses SSH as its transport protocol and does not support HTTPS.
D.RESTCONF messages are encoded in XML or JSON, with JSON support available on Cisco IOS XE.
E.RESTCONF automatically translates YANG models into SNMP MIBs for monitoring.
AnswersA, D

RESTCONF is a RESTful protocol that maps CRUD operations to HTTP methods. GET retrieves data, POST creates, PUT replaces, PATCH modifies, and DELETE removes. This aligns with the RESTCONF RFC and is how IOS XE exposes YANG-modeled configuration and state. The team can rely on these standard methods for automation, making this statement accurate and essential for designing tooling.

Why this answer

RESTCONF is a RESTful protocol that uses HTTP methods to manipulate YANG-modeled data and supports both XML and JSON encodings. On Cisco IOS XE, JSON is supported, which is advantageous for modern automation. The other statements are false: candidate datastore is not mandatory, SSH is not the transport, and there is no automatic YANG-to-MIB translation.

Exam trap

The trap here is confusing RESTCONF's transport and encoding with those of NETCONF, leading to incorrect assumptions about SSH usage or mandatory candidate datastores.

896
Multi-Selectmedium

A network engineer is implementing MACsec on a Cisco Catalyst switch to secure Layer 2 traffic between two campus distribution switches. Which two statements accurately describe MACsec operation on Cisco platforms? (Choose two.)

Select 2 answers
A.MACsec can secure traffic end-to-end between two hosts separated by multiple Layer 3 hops.
B.MACsec uses the MACsec Key Agreement (MKA) protocol to negotiate and distribute session keys between peers.
C.MACsec requires the use of IKEv2 to establish the security association between switches.
D.MACsec encrypts the entire IP packet including the original source and destination IP addresses.
E.MACsec provides hop-by-hop encryption and integrity checking on Ethernet frames between directly connected devices.
AnswersB, E

MKA is the control protocol that establishes the secure association between MACsec peers, electing a key server and distributing the secure association key used for encryption. It runs over EAPOL frames and is fundamental to how MACsec maintains and refreshes cryptographic material on a link.

Why this answer

MACsec is a Layer 2 hop-by-hop security standard that encrypts Ethernet frames and validates integrity between directly connected devices. The MKA protocol handles key negotiation and distribution, electing a key server and refreshing keys. It does not provide end-to-end protection across Layer 3 hops and does not rely on IKEv2, which belongs to the IPsec suite.

Exam trap

The trap here is conflating MACsec with IPsec by assuming MACsec provides end-to-end protection or uses IKEv2 for key negotiation.

897
Drag & Dropmedium

Drag and drop the steps of Cisco DNA Center assurance data collection workflow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Assurance begins with network devices streaming telemetry data (e.g., NetFlow, SNMP, syslog) to DNA Center. DNA Center processes and correlates the data to build a baseline of normal behavior. It then applies machine learning models to detect anomalies.

Alerts and insights are generated for potential issues. Finally, the dashboard displays health scores and recommended actions for the administrator.

898
MCQmedium

A network engineer is troubleshooting an EIGRP adjacency issue between two routers. The engineer verifies that both routers have the same K-values and autonomous system number. However, the adjacency does not form. Which configuration issue is most likely the cause?

A.Authentication is configured on one router but not on the other.
B.The network statement uses an incorrect subnet mask.
C.One router has a loopback interface that is not advertised.
D.The hello and hold timers do not match.
AnswerA

EIGRP authenticates each hello packet and every routing update using a configured key, typically MD5 or SHA-2. If one router has authentication enabled (e.g., 'ip authentication mode eigrp' and 'ip authentication key-chain eigrp') while the peer does not, the receiving router fails the authentication check and silently discards the hello, so no adjacency can ever form. Even a key mismatch or different key-chain name on both sides produces the same failure, making this a classic common cause of missing EIGRP neighbor relationships.

Why this answer

In EIGRP, authentication (MD5 or SHA) must be configured identically on both peers. If one router has authentication enabled and the other does not, the routers will reject each other's hello packets, preventing adjacency formation even if K-values and AS numbers match. This is a common misconfiguration that breaks neighbor relationships silently.

Exam trap

Cisco often tests the misconception that EIGRP requires matching hello and hold timers (like OSPF), but EIGRP is more tolerant; the real adjacency blocker is authentication mismatch, which is frequently overlooked when K-values and AS numbers are correct.

How to eliminate wrong answers

Option B is wrong because the network statement in EIGRP uses a wildcard mask, not a subnet mask; an incorrect subnet mask in the network statement would affect which interfaces participate in EIGRP but would not prevent adjacency if both routers have matching interfaces and AS numbers. Option C is wrong because a loopback interface that is not advertised does not affect EIGRP adjacency; adjacency forms on directly connected interfaces, and a non-advertised loopback has no impact on hello packet exchange. Option D is wrong because EIGRP does not require hello and hold timers to match; EIGRP uses a graceful restart mechanism where mismatched timers still allow adjacency (though hold time must be greater than hello interval to avoid flapping).

899
MCQmedium

A network automation engineer is writing a Python script to retrieve interface statistics from a Cisco IOS XE device using NETCONF. The script uses the 'ncclient' library and connects to the device on port 830. However, the connection fails with a 'Could not open socket' error. The engineer confirms that the device is reachable via ping and SSH on port 22. What is the most likely reason for the failure?

A.NETCONF is not enabled on the device.
B.The 'ncclient' library requires Python 2, but the script is using Python 3.
C.The firewall is blocking outbound connections on port 830.
D.The device's SSH server is configured to use a non-standard port.
AnswerA

NETCONF uses TCP port 830, which is separate from the standard SSH port 22. If NETCONF is not enabled on the Cisco IOS XE device via the 'netconf-yang' command, the device will not listen on port 830, and the connection attempt will fail with a socket error. The engineer's ability to SSH on port 22 does not guarantee NETCONF is active. Enabling 'netconf-yang' is required to start the NETCONF SSH server.

Why this answer

The 'Could not open socket' error when connecting to port 830 typically means the NETCONF service is not enabled on the device. NETCONF uses a separate SSH server on port 830, which is activated by the 'netconf-yang' command. The engineer's successful SSH on port 22 only confirms the standard SSH server is running, not NETCONF.

Therefore, enabling NETCONF is the required fix.

Exam trap

The trap here is assuming that if SSH on port 22 works, NETCONF should also work; however, NETCONF requires a separate service on port 830 that must be explicitly enabled.

900
MCQmedium

A company is deploying a virtualized network function (VNF) on a KVM-based host. The VNF requires dedicated CPU cores and must avoid performance interference from other VMs. Which hypervisor configuration best meets these requirements?

A.Enable CPU overcommitment and use a single NUMA node.
B.Configure CPU pinning and use dedicated NUMA nodes.
C.Use VMware vSphere with DRS set to Aggressive.
D.Deploy the VNF as a container instead of a VM.
AnswerB

CPU pinning binds each vCPU to a dedicated physical core, eliminating run-queue contention and preventing unwanted context switches, which guarantees consistent processing capacity. Dedicated NUMA nodes ensure that the memory nearest to those pinned cores is exclusively used, avoiding the increased latency and reduced bandwidth of cross-NUMA memory access. Together, these measures provide deterministic, line-rate performance essential for production NFV deployments.

Why this answer

CPU pinning binds the VNF's vCPUs to specific physical cores, ensuring dedicated CPU resources and preventing interference from other VMs. Using dedicated NUMA nodes further optimizes memory locality, reducing latency and avoiding cross-NUMA memory access, which is critical for performance-sensitive VNFs.

Exam trap

Cisco often tests the distinction between hypervisor-agnostic concepts (like CPU pinning) and vendor-specific features (like VMware DRS), and the trap here is that candidates may choose VMware options even when the question explicitly specifies a KVM-based host.

How to eliminate wrong answers

Option A is wrong because CPU overcommitment allows multiple VMs to share physical cores, which can cause performance interference and is the opposite of dedicated resource requirements. Option C is wrong because VMware vSphere with DRS set to Aggressive is a VMware-specific solution, not a KVM-based hypervisor configuration, and DRS focuses on load balancing rather than dedicated CPU pinning. Option D is wrong because deploying the VNF as a container does not provide dedicated CPU cores in the same way as CPU pinning; containers share the host OS kernel and can still experience resource contention without explicit CPU affinity settings.

Page 11

Page 12 of 26

Page 13