Courseiva

ENCOR 350-401 (350-401) — Questions 901–975

1923 questions total · 26pages · All types, answers revealed

Page 12

Page 13 of 26

Page 14
901
Drag & Dropmedium

Drag and drop the steps of NFVI resource allocation and VNF instantiation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with the NFVI administrator creating a tenant and allocating compute, storage, and network resources. Then the VNF descriptor is uploaded to the NFVO, which triggers the VNFM to request resource reservation. After resources are reserved, the VNFM instantiates the VNF using the allocated resources.

Finally, the VNF is configured and activated to provide the intended service.

902
MCQeasy

A network administrator wants to use a declarative, agentless automation tool to push VLAN configurations to a group of Cisco IOS XE switches. The tool should connect over SSH, use YAML playbooks, and require no software installation on the switches. Which tool best fits these requirements?

A.SaltStack with minions deployed on each switch and states written in YAML
B.Chef Infra Client installed on each switch with recipes written in Ruby
C.Puppet with the Cisco IOS module installed on each switch
D.Ansible with the cisco.ios collection and an inventory of the switches
AnswerD

Ansible is agentless, connecting over SSH, and uses YAML playbooks. The cisco.ios collection provides modules like ios_vlan and ios_config to manage IOS XE devices. No software needs to be installed on the switches beyond SSH and proper credentials. This matches all requirements: declarative, agentless, YAML-based, and SSH connectivity.

Why this answer

Ansible is the only option that is agentless, connects via SSH, and uses YAML playbooks. The cisco.ios collection supplies modules purpose-built for IOS XE VLAN and configuration management. Puppet, Chef, and SaltStack all generally require an agent on managed nodes, which cannot be installed on Cisco IOS XE switches, so they do not satisfy the agentless requirement.

Exam trap

The trap here is assuming any configuration management tool with a Cisco module is agentless, when Puppet, Chef, and SaltStack typically require agents that cannot run on IOS XE.

903
MCQmedium

An architect is designing an SD-Access fabric for a large enterprise campus. The design must support segmentation based on user identity and device type, and must integrate with Cisco ISE. Which fabric component and protocol should be used to enforce micro-segmentation?

A.Use VXLAN with BGP EVPN for segmentation.
B.Deploy Cisco TrustSec with SGTs and integrate with ISE.
C.Use LISP to map endpoints to virtual networks.
D.Implement VLAN-based segmentation with 802.1X.
AnswerB

Cisco TrustSec uses Security Group Tags (SGTs) assigned by ISE based on identity, endpoint posture, and other policy attributes, not on IP addressing or VLAN topology. The data plane enforces micro-segmentation through SGACLs that permit or deny traffic between source and destination SGTs, even within the same broadcast domain. ISE acts as the policy management and classification engine, dynamically updating SGT assignments and distributing access policies. Because enforcement is per security group and stateful across the overlay, this directly delivers identity-based micro-segmentation.

Why this answer

Cisco TrustSec with Security Group Tags (SGTs) is the correct choice because it provides identity- and device-type-based micro-segmentation in an SD-Access fabric. SGTs are assigned by Cisco ISE based on user/device attributes, and the fabric enforces policies by tagging packets with SGTs, allowing granular traffic filtering regardless of IP address or VLAN.

Exam trap

Cisco often tests the distinction between macro-segmentation (VXLAN/VRF) and micro-segmentation (SGT/TrustSec), and the trap here is assuming VXLAN with BGP EVPN alone provides identity-based segmentation, when it only creates separate overlay networks.

How to eliminate wrong answers

Option A is wrong because VXLAN with BGP EVPN provides network virtualization and macro-segmentation (overlay networks), not identity-based micro-segmentation; it lacks the per-user/per-device policy enforcement that SGTs offer. Option C is wrong because LISP is used for endpoint mapping and location/identity separation in SD-Access, but it does not enforce micro-segmentation policies; that role belongs to SGTs and Cisco TrustSec. Option D is wrong because VLAN-based segmentation with 802.1X only provides network-level isolation and authentication, not granular, identity-aware micro-segmentation across the fabric; it cannot dynamically enforce policies based on user identity and device type beyond initial access.

904
MCQmedium

A network administrator needs to validate that the path taken by packets from a branch router to a remote server matches the expected primary path. The administrator wants to collect per-hop latency and packet loss statistics along that path. Which tool should be used?

A.Cisco IOS Embedded Event Manager (EEM) with a Tcl script
B.IP SLA with a path-echo operation
C.IOS IP SLA with an ICMP echo operation
D.Cisco Discovery Protocol (CDP) neighbor details
AnswerB

A path-echo operation in IP SLA sends a series of packets with incrementing TTLs to discover the path and collect per-hop latency and loss statistics. This directly matches the requirement to validate the path and gather hop-by-hop performance data. It provides detailed information about each hop, including packet loss and round-trip time per hop, making it the correct tool.

Why this answer

IP SLA path-echo is designed to trace the path to a destination and collect per-hop latency and packet loss. Unlike simple ICMP echo, it provides hop-by-hop details, which are necessary to validate that traffic follows the expected primary path. The other options either lack hop-by-hop granularity or are not performance-monitoring tools.

Exam trap

The trap here is confusing IP SLA path-echo with basic ICMP echo, which only measures end-to-end reachability and does not provide per-hop statistics.

905
MCQhard

A network engineer is designing a high-availability solution for a data center using Cisco Application Centric Infrastructure (ACI). The engineer wants to ensure that the fabric can continue to operate if a spine switch fails, and that traffic is load-balanced across all available paths. Which statement accurately describes the ACI fabric architecture?

A.ACI uses a spine-leaf topology where every leaf connects to every spine, and a failed spine switch reduces capacity but does not cause an outage.
B.ACI uses a single spine switch for all traffic, and redundancy is achieved through a standby spine that takes over on failure.
C.ACI uses a traditional Spanning Tree Protocol (STP) to prevent loops, and a failed spine switch causes a full fabric outage.
D.ACI uses a ring topology for the fabric, and a failed spine switch breaks the ring, causing a partial outage.
AnswerA

In ACI, leaf switches connect to all spine switches, forming a full-mesh at the spine level. If a spine fails, the remaining spines continue to forward traffic, so the fabric remains operational. This provides high availability and load balancing across all available paths, meeting the design requirements.

Why this answer

ACI uses a spine-leaf topology where all leaf switches connect to all spine switches, providing active-active forwarding. A failed spine reduces overall capacity but does not cause an outage because other spines continue to forward traffic. This design ensures high availability and load balancing.

Exam trap

The trap here is assuming ACI relies on STP or a standby spine, when it actually uses a full-mesh active-active spine-leaf architecture.

906
MCQmedium

Consider the following partial syslog configuration on a Cisco IOS-XE switch: logging host 10.10.10.1 transport udp port 514 logging trap 6 logging source-interface Loopback0 logging on Which statement is true about this configuration?

A.Syslog messages with severity level 7 (Debugging) will be sent to 10.10.10.1.
B.Syslog messages will be sourced from the IP address of Loopback0 interface.
C.The syslog server must be configured to receive messages on TCP port 514.
D.Only syslog messages with severity level 6 (Informational) will be sent.
AnswerB

When 'logging source-interface Loopback0' is configured, the router uses the IP address assigned to Loopback0 as the source address for all outgoing syslog packets, regardless of which interface is used to route toward the syslog server. This provides a stable, predictable source IP that syslog servers can rely on for filtering and correlation. Since the command explicitly selects Loopback0, the statement is correct.

Why this answer

The `logging source-interface Loopback0` command forces all syslog messages to use the IP address of Loopback0 as the source IP in the packet, regardless of the egress interface. This ensures the syslog server sees a consistent source address, which is critical for filtering and logging reliability. The configuration is correct, so option B is true.

Exam trap

Cisco often tests the misconception that `logging trap 6` means only severity 6 messages are sent, when in fact it sends all messages with severity 0 through 6 (inclusive).

How to eliminate wrong answers

Option A is wrong because `logging trap 6` sets the severity threshold to level 6 (Informational), meaning only messages with severity 0–6 are sent; level 7 (Debugging) is excluded. Option C is wrong because the configuration explicitly specifies `transport udp port 514`, so the syslog server must listen on UDP 514, not TCP. Option D is wrong because `logging trap 6` sends all messages with severity 0 through 6 (Emergency through Informational), not only severity 6.

907
MCQmedium

A network engineer issues the following command on Router R3: R3# show ip sla statistics 2 Round Trip Time (RTT) for Index 2 Latest RTT: 12 ms Latest RTT: NoConnection/Busy/Timeout Latest Operation Start Time: 12:00:00.000 UTC Mon Mar 1 2021 Latest Operation Return Code: Timeout Number of successes: 45 Number of failures: 5 Over thresholds: 0 Based on this output, what is the most likely issue?

A.The IP SLA operation has never succeeded.
B.The target is unreachable due to a persistent failure.
C.The most recent probe timed out, indicating a possible connectivity issue.
D.The round-trip time is 12 ms, which is above the threshold.
AnswerC

The most recent IP SLA probe returned a 'Timeout' code, meaning the router did not receive an ICMP echo reply from the target within the configured timeout period (for example, the default 5000 ms). Because the historical counters show both successes and failures, this timeout is a current, isolated signal of a possible transient connectivity problem such as congestion, routing loop, or temporary unavailability. This is the only answer that correctly interprets the latest operation's return code.

Why this answer

The output shows a 'Latest Operation Return Code: Timeout' for the most recent probe, while the 'Number of successes: 45' and 'Number of failures: 5' indicate that the IP SLA operation has historically succeeded. This combination points to a transient or intermittent connectivity issue causing the latest probe to time out, not a persistent failure. Option C correctly identifies that the most recent probe timed out, suggesting a possible connectivity issue at that moment.

Exam trap

Cisco often tests the distinction between the latest probe result and the cumulative success/failure counters, trapping candidates who assume a single timeout means the target is completely unreachable or that the RTT value applies to the failed probe.

How to eliminate wrong answers

Option A is wrong because the 'Number of successes: 45' clearly shows the operation has succeeded multiple times, contradicting the claim that it has never succeeded. Option B is wrong because the 'Number of successes: 45' and only 5 failures indicate the target is generally reachable, not persistently unreachable; a persistent failure would show a high or total failure count. Option D is wrong because the 'Latest RTT: 12 ms' is the RTT from a previous successful probe, not the current one, and the output shows 'Over thresholds: 0', meaning no thresholds were exceeded.

908
MCQmedium

Consider the following configuration on a Cisco IOS-XE router: ``` ip access-list extended BLOCK_SSH deny tcp any any eq 22 permit ip any any ! line vty 0 4 access-class BLOCK_SSH in ``` Which statement is true about this configuration?

A.The ACL blocks all SSH traffic to the router, but permits other IP traffic.
B.The ACL blocks all traffic to the router because the deny statement is first.
C.The ACL only filters traffic going through the router, not destined to it.
D.The ACL permits SSH traffic because the permit statement overrides the deny.
AnswerA

The IPv4 access-class applied inbound on all VTY lines evaluates management-plane traffic destined to the router's virtual terminal ports. Since the first ACE is a TCP deny for destination port 22, every SSH handshake packet is matched and discarded before a session can be established. The later permit ip any any then allows all other IP traffic, such as ICMP, NTP, or HTTPS, to reach the router or its interfaces, so the effect is narrowly scoped to blocking SSH only.

Why this answer

The `access-class` command applied to the VTY lines filters inbound Telnet/SSH traffic destined to the router itself. The ACL `BLOCK_SSH` explicitly denies TCP traffic to port 22 (SSH) and permits all other IP traffic. Therefore, SSH connections to the router are blocked, while other IP traffic (e.g., HTTP, SNMP) is allowed.

Option A correctly describes this behavior.

Exam trap

Cisco often tests the distinction between `access-class` (filters traffic to the router) and `access-group` (filters traffic through the router), causing candidates to mistakenly think the ACL applies to transit traffic.

How to eliminate wrong answers

Option B is wrong because the ACL does not block all traffic; it only denies TCP port 22 and permits everything else, so non-SSH traffic is allowed. Option C is wrong because `access-class` applied to VTY lines filters traffic destined to the router (control plane), not transit traffic through the router (which would require an ACL applied to an interface). Option D is wrong because ACLs are processed top-down; the first matching deny statement for SSH traffic is applied, and the subsequent permit statement does not override it for SSH.

909
MCQmedium

Examine the following EIGRP configuration for route summarization: interface GigabitEthernet0/0 ip summary-address eigrp 100 192.168.0.0 255.255.252.0 What is the effect of this command?

A.EIGRP will advertise the 192.168.0.0/22 summary route out of GigabitEthernet0/0 and create a discard route.
B.EIGRP will only accept routes within the 192.168.0.0/22 range on this interface.
C.The summary route will have a metric equal to the best metric among the component routes.
D.This command will cause EIGRP to automatically summarize routes to their classful boundaries.
AnswerA

The 'ip summary-address eigrp 2a1744 192.168.0.0 255.255.252.0' command configures manual EIGRP summarization on GigabitEthernet0/0. This causes the router to advertise the 192.168.0.0/22 summary prefix out of that interface instead of the individual more-specific routes. To prevent routing loops, the router also installs a discard route (a route to Null0) for the summary prefix, ensuring that any traffic matching the summary but not a specific route is dropped locally.

Why this answer

The `ip summary-address eigrp` command creates a summary route (192.168.0.0/22) that EIGRP advertises out of the specified interface, and it automatically installs a discard (null0) route to prevent routing loops when the summary is advertised but some component routes may not be present in the routing table.

Exam trap

Cisco often tests the misconception that `ip summary-address eigrp` filters incoming routes or that it sets the summary metric to the highest metric, when in fact it creates a discard route and uses the minimum metric from component routes.

How to eliminate wrong answers

Option B is wrong because the command does not filter incoming routes; it only summarizes routes being advertised outbound. Option C is wrong because the summary route's metric is set to the minimum metric among the component routes, not the best (which could be interpreted as highest or best path). Option D is wrong because this command configures manual summarization, not automatic classful summarization; automatic summarization is controlled by the `auto-summary` command.

910
MCQhard

A DevOps team is implementing a CI/CD pipeline that automates network configuration changes. Which design principle is most important to ensure that a failed deployment does not cause prolonged outages?

A.Use a single source of truth for all configurations
B.Ensure the automation framework supports rollback to a known good state
C.Implement idempotent configuration scripts
D.Run the deployment in a lab environment first
AnswerB

Rollback to a known good state is the critical safety net in a CI/CD pipeline because it directly addresses the recovery-time objective after a failed deployment. The automation framework should preserve the last-known-good configuration (e.g., a snapshot, a config replace file, or a rollback token) and be able to reapply it automatically or on-demand when health checks fail. This minimizes mean time to recovery and is the only option that actively restores service rather than merely preventing or mitigating the impact of a failure.

Why this answer

In a CI/CD pipeline for network automation, the ability to roll back to a known good state is the most critical design principle for minimizing downtime. If a deployment fails (e.g., a misapplied ACL or BGP configuration), the automation framework must be able to revert the network device to its previous stable configuration—often by reapplying a saved startup config or using a tool like Ansible's `network_backup` role or Cisco NSO's rollback mechanism. Without this, a failed deployment could leave the network in a broken state until manual intervention, causing prolonged outages.

Exam trap

Cisco often tests the distinction between 'preventing errors' (idempotency, single source of truth) and 'recovering from errors' (rollback), and the trap here is that candidates confuse idempotency with rollback, thinking that re-running a script will fix a failure, when in fact idempotency only ensures consistency, not recovery from a broken state.

How to eliminate wrong answers

Option A is wrong because a single source of truth (e.g., a Git repository for configurations) is important for consistency and auditability, but it does not directly address recovery from a failed deployment; it prevents drift but not the need for rollback. Option C is wrong because idempotent scripts ensure that repeated runs produce the same result, which helps avoid unintended changes, but they do not provide a mechanism to revert to a previous state if a deployment introduces a fault. Option D is wrong because running a deployment in a lab environment first is a best practice for testing, but it does not guarantee that a production deployment won't fail; the question specifically asks about ensuring that a failed deployment does not cause prolonged outages, which requires a rollback capability in production.

911
Matchingmedium

Drag and drop each NETCONF operation on the left to its action on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Retrieve running configuration and state data

Retrieve configuration from a specific datastore

Modify the target configuration datastore

Confirm a candidate configuration as the new running config

Prevent other NETCONF sessions from altering a datastore

Why these pairings

Correct pairings: get retrieves running config and state data; get-config retrieves a specific datastore; edit-config modifies configuration; commit confirms a candidate configuration; lock prevents other sessions from modifying a datastore.

912
MCQhard

A network security team is deploying Cisco TrustSec in a data center environment. They want to assign Security Group Tags (SGTs) to traffic based on user identity and device type without relying on IP addresses or VLANs. The team plans to use inline tagging on Cisco Nexus switches that support hardware-based SGACL enforcement. Which statement correctly describes how inline tagging propagates SGT information?

A.The SGT is inserted into the Layer 2 frame using Cisco Metadata (CMD) fields, allowing downstream devices to enforce SGACLs without reclassification.
B.The SGT is encoded in the DSCP field of the IP header, enabling enforcement at any Layer 3 device along the path.
C.The SGT is stored in the ARP cache of each device, and devices query a central server to resolve SGTs for enforcement decisions.
D.The SGT is propagated through a proprietary GRE tunnel between all TrustSec-capable devices, encapsulating the original frame.
AnswerA

Inline tagging uses Cisco Metadata to carry the SGT value within the Ethernet frame itself. Downstream devices that support CMD can read the tag and enforce SGACLs directly, eliminating the need to reclassify traffic based on IP or user identity at each hop, which preserves the original classification throughout the path.

Why this answer

Inline tagging in Cisco TrustSec inserts the SGT directly into the Ethernet frame using Cisco Metadata fields. This allows downstream devices to enforce SGACLs based on the original classification without needing to reclassify traffic, preserving security group integrity across the network path.

Exam trap

The trap here is assuming SGTs are carried in IP headers like DSCP, when in reality they are embedded in Layer 2 frames using Cisco Metadata.

913
Multi-Selecthard

Which three statements about Dynamic Trunking Protocol (DTP) are true? (Choose three.)

Select 3 answers
A.DTP is a Cisco proprietary protocol.
B.DTP frames are sent on the native VLAN.
C.The 'switchport mode dynamic desirable' setting causes the interface to actively attempt to form a trunk.
D.DTP operates at Layer 3 of the OSI model.
E.DTP is used to negotiate trunking on routed ports.
AnswersA, B, C

DTP is Cisco proprietary, so it only negotiates trunking between Cisco switches; non-Cisco devices ignore its frames. This satisfies the stem's requirement for a true statement, since standard 802.1Q lacks any negotiation mechanism, and DTP's proprietary nature is a defining characteristic tested on the 350-401 exam.

Why this answer

Option A is correct because DTP (Dynamic Trunking Protocol) is a Cisco proprietary protocol used to negotiate trunk encapsulation and trunking mode between directly connected Cisco switches. Option B is correct because DTP frames are sent untagged on the native VLAN (VLAN 1 by default), which is why both ends must agree on the native VLAN for DTP to function properly. Option C is correct because 'switchport mode dynamic desirable' makes the interface actively initiate DTP negotiation and form a trunk if the neighbor responds with trunk, desirable, or auto mode.

Option D is incorrect because DTP operates at Layer 2 (data link layer), not Layer 3. Option E is incorrect because DTP negotiates trunking on switch ports, not routed ports; routed ports are configured with 'no switchport' and do not run DTP.

Exam trap

The trap here is confusing DTP with protocols that operate at Layer 3 or assuming it works on routed ports; candidates might think DTP negotiates trunking on any port type, but it is strictly for switch ports (Layer 2).

914
MCQhard

A network engineer issues the following command on Router R9: R9# show ip pim bsr-router PIMv2 Bootstrap Router (BSR) information This system is the Bootstrap Router (BSR) BSR address: 10.0.0.11 Uptime: 1w2d, BSR priority: 0, Hash mask length: 30 Next bootstrap message in 00:00:45 Based on this output, what can be concluded?

A.This router is the elected BSR.
B.This router is a candidate BSR but not elected.
C.The BSR priority is 192.
D.The hash mask length is 32.
AnswerA

The command output's explicit statement 'This system is the Bootstrap Router' verifies that this router has won the BSR election and currently serves as the elected BSR for the PIM domain. As the elected BSR, it is responsible for originating Bootstrap messages that advertise the RP set to all other PIM routers. A candidate BSR alone would not generate this output phrase; the router must have the active BSR role.

Why this answer

The output explicitly states 'This system is the Bootstrap Router (BSR)', which means the router on which the command was issued is the elected BSR for the PIM domain. The BSR address of 10.0.0.11 confirms this is the router's own IP address, and the uptime of 1 week 2 days indicates it has been functioning as the BSR for an extended period, further solidifying its elected status.

Exam trap

Cisco often tests the distinction between a candidate BSR and the elected BSR, where candidates may misinterpret the phrase 'This system is the Bootstrap Router (BSR)' as merely indicating participation in the election process rather than confirming election.

How to eliminate wrong answers

Option B is wrong because the output clearly states 'This system is the Bootstrap Router (BSR)', indicating it is the elected BSR, not just a candidate. Option C is wrong because the output shows 'BSR priority: 0', not 192; a priority of 0 is the default and does not indicate a higher priority value. Option D is wrong because the output shows 'Hash mask length: 30', not 32; the hash mask length is used for RP selection and is explicitly displayed as 30 in the command output.

915
MCQhard

A global enterprise is transitioning from a traditional three-tier campus architecture to a software-defined access (SD-Access) fabric. Which architectural consideration is most critical for the underlay network?

A.Configure a routed access layer with a link-state routing protocol (IS-IS or OSPF).
B.Implement PIM-SM for multicast routing in the underlay.
C.Preserve existing VLANs across the fabric to minimize changes.
D.Deploy VRF-lite on all edge nodes to isolate tenants.
AnswerA

A routed access layer with IS-IS or OSPF is the required foundation for an SD-Access underlay. Link-state protocols offer rapid convergence, loop-free topology, and hierarchical scalability, which are essential when building a large leaf-and-spine fabric. The underlay is a pure L3 network, and all devices carry only unique loopback/p2p addresses, allowing the overlay (LISP/VXLAN) to run independently of L2 constraints. Without this routed design, the fabric cannot propagate reachability efficiently and may revert to spanning-tree, which is explicitly contrary to SD-Access best practices.

Why this answer

In an SD-Access fabric, the underlay network must provide IP connectivity between all fabric devices (edge, control plane, border nodes) using a routed access layer with a link-state routing protocol like IS-IS or OSPF. This ensures fast convergence, loop-free topology, and support for the overlay's VXLAN tunnels. A routed access layer eliminates spanning-tree dependencies and aligns with the fabric's requirement for a simple, scalable IP-based transport.

Exam trap

Cisco often tests the misconception that the underlay must support multicast (PIM) or preserve legacy VLANs, when in fact the underlay only needs unicast routing and the overlay handles all segmentation and multicast replication via head-end replication or native multicast.

How to eliminate wrong answers

Option B is wrong because PIM-SM is used for multicast routing in the overlay (for traffic such as ARP or multicast applications), not in the underlay; the underlay only needs unicast routing to establish VXLAN tunnels. Option C is wrong because preserving existing VLANs across the fabric contradicts the SD-Access design principle of decoupling the overlay from the underlay; VLANs are mapped to virtual network identifiers (VNIs) in the overlay, and the underlay should be a clean, routed IP network. Option D is wrong because VRF-lite is a Layer 3 segmentation technique used in traditional networks, not in the SD-Access underlay; tenant isolation is achieved via the overlay's VXLAN and LISP/VN segmentation, not by configuring VRFs on underlay interfaces.

916
Multi-Selectmedium

A network administrator is implementing NetFlow on a Cisco IOS XE router to monitor traffic. Which two statements about NetFlow are true? (Choose two.)

Select 2 answers
A.NetFlow can export flow data to a collector using UDP.
B.NetFlow requires SNMP to be enabled on the router.
C.NetFlow can be configured to export only ingress or egress traffic on an interface.
D.NetFlow collects packet payload data for deep packet inspection.
E.NetFlow export uses TCP port 2055 by default.
AnswersA, C

NetFlow version 5, 9, and IPFIX can use UDP as the transport protocol for exporting flow records to a collector. UDP is commonly used because it is lightweight and the loss of some flow records is acceptable for monitoring purposes. However, some versions like NetFlow v9 can also use SCTP, but UDP is a valid option. This statement is true.

Why this answer

The two true statements are that NetFlow can export flow data using UDP and that it can be configured to export only ingress or egress traffic on an interface. NetFlow does not require SNMP, does not collect payload data, and does not use TCP port 2055 by default.

Exam trap

The trap here is assuming NetFlow uses TCP for reliable export or that it captures payloads, which it does not.

917
MCQhard

A network engineer runs the following command on Switch SW1: SW1# show interfaces gi0/1 trunk Port Mode Encapsulation Status Native vlan Gi0/1 on 802.1q trunking 1 Port Vlans allowed on trunk Gi0/1 10,20 Port Vlans allowed and active in management domain Gi0/1 10,20 Port Vlans in spanning tree forwarding state and not pruned Gi0/1 10,20 Based on this output, what can be concluded?

A.VLAN 1 is allowed on this trunk.
B.The trunk is using DTP dynamic desirable mode.
C.Only VLANs 10 and 20 are allowed on this trunk.
D.The native VLAN is 10.
AnswerC

The output explicitly contains 'Vlans allowed on trunk: 10,20'. On Cisco Catalyst switches, this line is the definitive list of VLANs permitted to traverse the trunk link; all other VLANs, including VLAN 1, are pruned or dropped at ingress. Thus only VLANs 10 and 20 are eligible for trunking, making this statement correct.

Why this answer

The output shows that the 'Vlans allowed on trunk' list contains only VLANs 10 and 20. This means the trunk has been explicitly configured to permit only those VLANs, and all other VLANs (including VLAN 1) are pruned or blocked from traversing the trunk. Therefore, only VLANs 10 and 20 are allowed, making option C correct.

Exam trap

Cisco often tests the distinction between the native VLAN and the allowed VLAN list; candidates mistakenly assume that the native VLAN is always permitted on the trunk, but the allowed list explicitly controls which VLANs can pass traffic, and the native VLAN must be included in that list to be forwarded.

How to eliminate wrong answers

Option A is wrong because the 'Vlans allowed on trunk' line explicitly lists only VLANs 10 and 20; VLAN 1 is not included, so it is not allowed on this trunk. Option B is wrong because the 'Mode' field shows 'on', which indicates that trunking is statically configured (no DTP negotiation), not using DTP dynamic desirable mode. Option D is wrong because the 'Native vlan' field shows '1', not 10; the native VLAN is the VLAN used for untagged traffic on the trunk, and here it is VLAN 1.

918
Matchingmedium

Drag and drop each hypervisor product on the left to its matching vendor on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

VMware

Red Hat

Microsoft

Citrix

Oracle

Why these pairings

VMware vSphere is from VMware, KVM is from Red Hat (open source, but Red Hat is the primary commercial backer), Microsoft Hyper-V is from Microsoft, Xen is from Citrix (originally from the Xen Project), and Oracle VM is from Oracle.

919
MCQmedium

A network engineer is configuring VXLAN on a Cisco Nexus 9000 switch. The engineer wants to ensure that the VXLAN tunnel interface uses the loopback 0 interface as the source for all VXLAN traffic. Which command should be entered under the NVE interface configuration?

A.tunnel source loopback0
B.source-interface loopback0
C.vxlan source-interface loopback0
D.interface loopback0
AnswerB

This command correctly specifies the loopback 0 interface as the source for VXLAN tunnel traffic. It ensures that the VTEP IP address is derived from a stable, always-up interface, which is a best practice for VXLAN deployments. The loopback interface provides redundancy and avoids disruption if a physical interface goes down.

Why this answer

The correct command to set the source interface for VXLAN tunnels under the NVE interface is 'source-interface loopback0'. This ensures that the VTEP IP address is derived from a stable loopback interface, which is a best practice for VXLAN deployments. The other options are either invalid or apply to different technologies.

Exam trap

The trap here is confusing the command syntax for VXLAN with that of traditional GRE tunnels, leading to the use of 'tunnel source' instead of the correct 'source-interface'.

920
Drag & Dropmedium

Drag and drop the steps of YANG data model traversal for interface stats into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The process starts with identifying the YANG module, then navigating the tree to the interface container, retrieving statistics, and optionally filtering or using NETCONF/RESTCONF.

921
MCQhard

An engineer is configuring a Cisco Nexus 9000 switch running VXLAN EVPN. Tenant traffic must be encapsulated with a VXLAN header that includes a 24-bit VNI, and the underlay must provide loopback-based VTEP addressing with ECMP. The engineer notices that the switch is not forming VXLAN tunnels to remote leaf switches. Which configuration issue is the most likely cause?

A.The switch is using a 12-bit VLAN ID instead of the required 24-bit VNI in the VXLAN header
B.The NVE interface is missing the source-interface loopback and the VNI-to-VLAN mapping is incomplete
C.The underlay is running OSPF instead of BGP, which prevents VXLAN tunnel establishment
D.The switch is configured with VXLAN VNI 16777216, which exceeds the 24-bit range
AnswerB

The NVE interface requires a source-interface, typically a loopback, to establish the VTEP address used in VXLAN tunnels. If the source interface is missing or the VNI-to-VLAN mapping under the NVE interface is incomplete, the switch cannot build tunnels or map traffic into VNIs. This directly explains why VXLAN tunnels to remote leaf switches are not forming in the scenario.

Why this answer

VXLAN tunnel formation on a Nexus 9000 requires the NVE interface to have a source-interface, usually a loopback, and correct VNI-to-VLAN mappings. Without a valid VTEP source address or with incomplete VNI mappings, the switch cannot establish tunnels to remote leaf VTEPs, which matches the observed failure.

Exam trap

The trap here is blaming the underlay routing protocol or VNI bit width, when the actual prerequisite for tunnel formation is a valid NVE source interface and complete VNI-to-VLAN mappings.

922
MCQmedium

router bgp 65000 bgp router-id 10.0.0.1 neighbor 10.0.0.2 remote-as 65001 neighbor 10.0.0.2 route-map FILTER in ! route-map FILTER deny 10 match ip address prefix-list BLOCKED route-map FILTER permit 20 ! ip prefix-list BLOCKED seq 5 permit 10.0.0.0/8 ! What is the effect of this configuration?

A.All routes from neighbor 10.0.0.2 are accepted except those matching 10.0.0.0/8.
B.Only routes matching 10.0.0.0/8 are accepted from the neighbor.
C.The configuration is invalid because route-map must have a permit statement first.
D.The prefix-list is misconfigured because it should use 'deny' instead of 'permit'.
AnswerA

The route-map is evaluated in ascending sequence order, and each BGP route is checked against the clauses. The first clause is a deny statement that matches the prefix-list for 10.0.0.0/8, so any route within that aggregate is rejected. The subsequent permit clause with no match conditions acts as a catch-all, allowing every other route. Thus, only routes that fall under 10.0.0.0/8 are filtered, while all other prefixes from the neighbor are accepted.

Why this answer

The route-map FILTER is applied inbound from neighbor 10.0.0.2. Sequence 10 denies routes that match the prefix-list BLOCKED, which permits 10.0.0.0/8. Sequence 20 is a permit statement with no match, which implicitly permits all other routes.

Therefore, only routes matching 10.0.0.0/8 are denied, and all other routes are accepted.

Exam trap

Cisco often tests the interaction between route-map sequence numbers and the implicit deny at the end of a route-map, leading candidates to forget that a permit statement with no match (like sequence 20) is needed to allow all other routes through.

How to eliminate wrong answers

Option B is wrong because the configuration denies routes matching 10.0.0.0/8, not accepts them. Option C is wrong because route-maps can start with a deny statement; there is no requirement for the first statement to be permit. Option D is wrong because the prefix-list uses 'permit' to define which prefixes are matched by the route-map's deny clause; using 'deny' in the prefix-list would not match the intended prefixes.

923
Multi-Selecthard

Which three statements about SD-WAN segmentation and multi-tenancy are true? (Choose three.)

Select 3 answers
A.Each VPN in SD-WAN corresponds to a separate VRF on the edge device, providing Layer 3 isolation.
B.OMP advertises VPN membership information so that edge devices know which VPNs are reachable via each TLOC.
C.Extranet VPN configuration allows selected routes to be shared between different VPNs on the same edge device.
D.VPN 0 is used for service-side connectivity, such as connecting to a corporate LAN or data center.
E.Multi-tenancy in SD-WAN requires separate physical edge devices for each tenant to ensure isolation.
AnswersA, B, C

Each SD-WAN VPN maps to a distinct VRF on the edge device, so routes and forwarding tables remain separate between segments. This satisfies the multi-tenancy requirement for Layer 3 isolation, preventing traffic leaking between tenants or departments.

Why this answer

Option A is correct because in Cisco SD-WAN each VPN is mapped to a distinct VRF on the edge device, which provides Layer 3 routing isolation between segments. Option B is correct because OMP carries VPN membership in its routing updates, so edge devices learn which VPNs are reachable through each TLOC. Option C is correct because extranet VPN configuration enables controlled route sharing between different VPNs on the same edge device, allowing selective inter-VPN connectivity.

Option D is incorrect because VPN 0 is the transport VPN used for WAN/control connections, not service-side LAN or data center connectivity. Option E is incorrect because SD-WAN multi-tenancy can be achieved logically through VPN segmentation on shared edge devices, without requiring separate physical devices per tenant.

924
MCQhard

A network engineer is configuring a Cisco IOS router to establish a site-to-site VPN with a remote peer using IKEv2. The engineer wants to ensure that the router uses a pre-shared key for authentication and that the IKEv2 proposal uses AES-256 for encryption and SHA-256 for integrity. Which configuration sequence correctly sets up the IKEv2 proposal and keyring?

A.crypto ikev2 proposal PROPOSAL1; encryption aes-cbc-256; integrity sha256; group 14; crypto ikev2 keyring KEYRING1; peer PEER1; address 203.0.113.1; pre-shared-key local Cisco123; pre-shared-key remote Cisco123
B.crypto ikev2 proposal PROPOSAL1; encryption aes-cbc-256; integrity sha256; group 14; crypto ikev2 keyring KEYRING1; peer PEER1; address 203.0.113.1; pre-shared-key local Cisco123
C.crypto ikev2 policy POLICY1; encryption aes-cbc-256; integrity sha256; group 14; crypto ikev2 keyring KEYRING1; peer PEER1; address 203.0.113.1; pre-shared-key local Cisco123; pre-shared-key remote Cisco123
D.crypto ikev2 proposal PROPOSAL1; encryption aes-256; integrity sha-256; group 14; crypto ikev2 keyring KEYRING1; peer PEER1; address 203.0.113.1; pre-shared-key Cisco123
AnswerA

This sequence correctly defines an IKEv2 proposal with AES-256 encryption, SHA-256 integrity, and DH group 14. It then creates a keyring with a peer address and matching local and remote pre-shared keys. This is the proper syntax for IKEv2 configuration on Cisco IOS, ensuring the proposal and keyring are correctly associated for the VPN.

Why this answer

The correct configuration includes the proper IKEv2 proposal with encryption aes-cbc-256 and integrity sha256, and a keyring with both local and remote pre-shared keys. This ensures the router can authenticate with the remote peer using the correct cryptographic parameters.

Exam trap

The trap here is using incorrect keywords like aes-256 instead of aes-cbc-256, or omitting the remote pre-shared key, which are common syntax errors in IKEv2 configuration.

925
MCQmedium

An architect is designing a QoS policy for a campus LAN that must support real-time voice and video traffic alongside mission-critical data. The design must use the DiffServ model with consistent per-hop behavior across all switches. Which approach should the architect choose to ensure that voice traffic receives priority queuing while video traffic is guaranteed bandwidth without starving other classes?

A.Use the MQC framework to classify traffic based on DSCP markings, apply a priority queue for EF traffic, and allocate a minimum bandwidth guarantee for AF41 traffic.
B.Implement a single FIFO queue on all interfaces and rely on the default CoS-to-queue mapping to prioritize voice.
C.Configure strict priority queuing for all traffic marked with DSCP values greater than 0.
D.Use the IntServ model with RSVP to reserve bandwidth for each voice and video flow.
AnswerA

The MQC framework is the standard Cisco DiffServ implementation: a class-map matches traffic by DSCP (EF for voice, AF41 for video), and a policy-map assigns an explicit priority queue to EF while reserving a minimum bandwidth portion for AF41. Priority for EF ensures low-latency treatment for voice, while the bandwidth guarantee protects video from starvation during congestion, aligning with the EF and AF PHBs defined in RFC 3246 and RFC 2597. This provides the required differentiated treatment in a scalable, class-based manner.

Why this answer

It uses the Modular QoS CLI (MQC) framework to classify traffic by DSCP markings, which aligns with the DiffServ model's per-hop behavior consistency. By applying a strict priority queue for EF (Expedited Forwarding, DSCP 46) traffic, voice gets low-latency treatment, while a minimum bandwidth guarantee for AF41 (Assured Forwarding, DSCP 34) ensures video traffic receives a guaranteed share without starving other classes, as AF uses weighted fair queuing with bandwidth allocation.

Exam trap

Cisco often tests the misconception that strict priority queuing can be applied broadly to multiple traffic classes without starvation risks, but the trap here is that only EF (voice) should use priority queuing, while AF (video) requires a bandwidth guarantee to avoid starving other classes.

How to eliminate wrong answers

Option B is wrong because a single FIFO queue cannot provide differentiated treatment; it treats all traffic equally, causing voice and video to suffer jitter and delay, and default CoS-to-queue mappings are not sufficient for consistent per-hop behavior across switches. Option C is wrong because strict priority queuing for all traffic with DSCP > 0 would place multiple classes (e.g., AF, CS) into the priority queue, leading to starvation of lower-priority traffic and potential queue overflow for voice. Option D is wrong because the IntServ model with RSVP is not designed for campus LANs with DiffServ; it requires per-flow state and signaling, which does not scale and violates the requirement for consistent per-hop behavior across all switches.

926
Multi-Selecthard

A network administrator is analyzing the output of 'show ip sla statistics' on a Cisco router. Which two statements correctly describe the information provided by this command? (Choose two.)

Select 2 answers
A.It displays the number of successes and failures for the IP SLA operation.
B.It lists the IP addresses of all intermediate hops along the path.
C.It displays the configured threshold and timeout values for the operation.
D.It provides a detailed packet-by-packet capture of the probe traffic.
E.It shows the round-trip time (RTT) for the most recent operation.
AnswersA, E

The 'show ip sla statistics' command provides a summary of the operation's results, including the number of successes and failures. This helps administrators quickly assess the reliability of the monitored path or service. It is a key piece of information for validating SLA compliance.

Why this answer

The 'show ip sla statistics' command provides operational results such as success/failure counts and the latest RTT. It does not show packet captures, hop-by-hop details, or configuration parameters. Thus, the statements about successes/failures and RTT are correct.

Exam trap

The trap here is assuming that 'show ip sla statistics' displays configuration details or hop-by-hop information, when it only shows aggregated performance results.

927
MCQeasy

What is the default hold time multiplier for EIGRP?

A.3
B.4
C.5
D.10
AnswerA

The default EIGRP hello interval is 5 seconds on most media, and the default hold time is 15 seconds, meaning the hold time is exactly three times the hello interval. This 3:1 ratio is the Cisco default and is what 'eigrp d5bb85' refers to in the command output. A router uses this multiplier to determine when a neighbor is unreachable after missing consecutive hello packets.

Why this answer

The default hold time multiplier for EIGRP is 3. This multiplier is applied to the hello interval to calculate the hold time (hold time = hello interval × multiplier). By default, EIGRP uses a hello interval of 5 seconds on most interfaces (or 60 seconds on low-speed NBMA interfaces), so the default hold time is 15 seconds (5 × 3) or 180 seconds (60 × 3).

Exam trap

Cisco often tests the default hold time multiplier (3) versus the default hold time (15 seconds), causing candidates to confuse the multiplier with the actual hold time value or to mistakenly recall the default hello interval (5 seconds) as the multiplier.

How to eliminate wrong answers

Option B (4) is wrong because the default EIGRP hold time multiplier is not 4; a multiplier of 4 would result in a hold time of 20 seconds (5 × 4), which is not the Cisco default. Option C (5) is wrong because a multiplier of 5 would yield a hold time of 25 seconds (5 × 5), which is not the standard default value. Option D (10) is wrong because a multiplier of 10 would produce a hold time of 50 seconds (5 × 10), far exceeding the default 15 seconds; this value is not used as the default multiplier in EIGRP.

928
MCQmedium

A network engineer is configuring MPLS L3VPN on a Cisco IOS-XE router. The VRF CUSTOMER_C has route-target import 300:1 and export 300:1. The PE receives VPNv4 routes from the route reflector, but the CE router connected to the PE cannot ping any remote site IP addresses. The PE can ping the remote site IP addresses from the VRF. What is the most likely cause?

A.The CE router does not have a default route pointing to the PE's VRF interface.
B.The VRF is missing the route-target export command.
C.The PE router is not running a routing protocol with the CE router.
D.The MPLS LDP is not enabled on the PE-CE link.
AnswerA

In an MPLS L3VPN, the CE router must have a route—either a default route or a specific prefix—that points toward the PE's VRF-facing interface as the next hop. Without such a route, the CE cannot forward packets to the PE for remote VPN destinations, so pings from the CE fail. The PE can still ping remote sites because its VRF routing table contains the remote VPNv4 routes, which proves the problem is the CE's missing next hop rather than the PE's VRF configuration.

Why this answer

The PE can ping remote site IP addresses from within the VRF, confirming that the VRF has the correct route-target import/export configuration and that VPNv4 routes are being received and installed in the VRF routing table. However, the CE router cannot ping remote sites, which indicates that the CE does not have a route pointing to the PE’s VRF interface as its next hop. Without a default route or a specific route pointing to the PE’s VRF-facing interface, the CE has no path to forward traffic to remote VPN destinations, even though the PE can reach them.

Exam trap

Cisco often tests the misconception that if the PE can reach remote sites from the VRF, the CE must also be able to reach them, but the trap is that the CE’s routing table is independent and requires explicit route injection or a default route pointing to the PE.

How to eliminate wrong answers

Option B is wrong because the VRF already has route-target export 300:1 configured, and the PE can ping remote sites from the VRF, proving that VPNv4 routes are being exported and imported correctly. Option C is wrong because the PE can ping remote sites from the VRF, which implies that a routing protocol (or static route) is running between the PE and CE to exchange routes; otherwise the PE would not have a route to the CE’s subnet. Option D is wrong because MPLS LDP is not required on the PE-CE link; LDP is used for label distribution in the MPLS core, not on the customer-facing link, which typically uses IP routing or static routes.

929
MCQhard

An enterprise network uses TACACS+ for device administration and RADIUS for network access (VPN and wireless). The TACACS+ server is configured to authorize commands. A network engineer notices that after a recent upgrade of the TACACS+ server software, some commands that were previously authorized are now being denied. The engineer checks the router configuration and sees 'aaa authorization commands 15 default group tacacs+'. The TACACS+ server logs show that the authorization requests are being sent and responded to. What is the most likely cause?

A.The router's 'aaa authorization commands 15 default group tacacs+' command is missing the 'local' keyword, so if TACACS+ denies, there is no fallback.
B.The TACACS+ server upgrade changed the default authorization behavior from permissive to restrictive, requiring explicit 'permit' statements for each command, and the existing rules may not cover all commands.
C.The router's privilege level 15 is not correctly assigned to the user.
D.The TACACS+ server is not reachable due to a firewall change, causing the router to deny all commands.
AnswerB

The TACACS+ server's command authorization policy is the decisive factor here. When the server was upgraded, the default authorization behavior for commands likely changed from permissive to restrictive, meaning that without explicit 'permit' statements for each command, the server will respond with a denial. The existing rules on the TACACS+ server may not cover all commands that the user is trying to execute, so even though the router correctly forwards authorization requests, the server's deny response blocks the commands. The fix is to update the TACACS+ server's rule set to explicitly permit the required commands at privilege level 15.

Why this answer

TACACS+ uses an authorization model where the server explicitly permits or denies each command. After an upgrade, the default behavior may have changed from a permissive mode (allowing commands not explicitly denied) to a restrictive mode (denying commands not explicitly permitted). Since the router is configured to use TACACS+ for command authorization (aaa authorization commands 15 default group tacacs+), and the server logs show requests and responses, the issue is that the server is now denying commands that were previously allowed due to missing explicit permit statements.

Exam trap

Cisco often tests the distinction between authentication and authorization, and the trap here is that candidates assume a reachability or configuration syntax issue (like missing 'local' or privilege level) rather than understanding that TACACS+ authorization is server-driven and its default behavior can change after an upgrade.

How to eliminate wrong answers

Option A is wrong because the 'local' keyword is not required for fallback; TACACS+ command authorization does not inherently need a local fallback, and the router is correctly sending requests to the TACACS+ server, which is responding. Option C is wrong because privilege level 15 is correctly assigned via the 'aaa authorization commands 15' command, and the user's privilege level is typically set during authentication, not causing selective command denials after a server upgrade. Option D is wrong because the TACACS+ server logs show that authorization requests are being sent and responded to, indicating the server is reachable and not blocked by a firewall.

930
MCQmedium

What is the purpose of the Dynamic Trunking Protocol (DTP) on Cisco switches?

A.To automatically negotiate trunking between two Cisco switches.
B.To dynamically assign VLANs to access ports.
C.To provide security by encrypting trunk traffic.
D.To prevent loops in the network.
AnswerA

Dynamic Trunking Protocol (DTP) is a Cisco proprietary Layer 2 protocol operating on point-to-point Ethernet links to automatically negotiate a common trunking mode (access, trunk, desirable, auto) and establish an 802.1Q trunk when both switches are DTP-capable. It sends DTP frames on the native VLAN to determine whether the neighboring port is willing to become a trunk, thereby eliminating the need for manual trunk configuration. However, DTP only negotiates the trunking state; it does not define which VLANs are allowed on the trunk.

Why this answer

DTP (Dynamic Trunking Protocol) is a Cisco proprietary protocol used to automatically negotiate the operational mode (access or trunk) of a switch port between two Cisco switches. When both ends are configured with DTP modes like dynamic desirable or dynamic auto, the link can become a trunk without manual configuration, simplifying deployment in environments where trunking is needed.

Exam trap

The trap here is that candidates confuse DTP with VTP (VLAN Trunking Protocol), which manages VLAN database propagation, or assume DTP provides security features like encryption, when in fact it only negotiates trunking and can be a security risk.

How to eliminate wrong answers

Option B is wrong because DTP negotiates trunking, not VLAN assignment; VLANs are assigned to access ports via the 'switchport access vlan' command or VTP, not DTP. Option C is wrong because DTP provides no encryption or security; trunk traffic encryption is handled by protocols like MACsec (802.1AE) or IPsec, not DTP. Option D is wrong because loop prevention is the function of Spanning Tree Protocol (STP), not DTP; DTP can actually create loops if misconfigured with STP disabled.

931
MCQmedium

An engineer is using the Cisco DNA Center REST API to retrieve a list of network devices and their health scores. The engineer writes a Python script using the requests library. The script successfully retrieves data for the first 100 devices, but when trying to get the next 100, the API returns an empty list. The engineer checks the API documentation and finds that the endpoint supports pagination with the 'offset' and 'limit' parameters. The current script does not handle pagination. What should the engineer do to retrieve all devices?

A.Increase the 'limit' parameter to 1000 in a single API call.
B.Use the 'next' URL from the response headers to automatically fetch the next page.
C.Write a loop that increments the 'offset' parameter by the 'limit' value until all pages are retrieved.
D.Switch to using the Cisco DNA Center Python SDK which handles pagination automatically.
AnswerC

Implementing a loop that increments the offset by the current limit is the canonical way to handle offset/limit pagination. The loop should begin with offset=0 and continue fetching pages, incrementing offset by the limit each iteration, until the returned page contains fewer items than the requested limit (or zero), signaling the last page. This approach is efficient, deterministic, and works whether the total record count is known or not, making it the correct fix for the script.

Why this answer

The Cisco DNA Center REST API uses offset-based pagination, where the 'offset' parameter specifies the starting index and 'limit' defines the number of records per page. To retrieve all devices, the engineer must write a loop that increments the offset by the limit value (e.g., 100) in each iteration until the API returns an empty list, indicating all pages have been fetched. This approach ensures complete data retrieval without exceeding any API-imposed maximum limit.

Exam trap

Cisco often tests the distinction between offset-based pagination (using 'offset' and 'limit') and cursor-based pagination (using a 'next' URL), leading candidates to incorrectly assume that the API provides a 'next' link in headers, which is not the case for DNA Center REST APIs.

How to eliminate wrong answers

Option A is wrong because increasing the 'limit' parameter to 1000 may exceed the API's maximum allowed limit (often 500 or 1000), causing the request to be rejected or truncated, and it does not guarantee retrieval of all devices if the total count exceeds that limit. Option B is wrong because the Cisco DNA Center REST API does not provide a 'next' URL in response headers for pagination; it relies on explicit 'offset' and 'limit' parameters, not cursor-based or link-based pagination. Option D is wrong because while the Cisco DNA Center Python SDK can simplify pagination, the question specifically asks what the engineer should do to retrieve all devices, and the correct answer is to implement pagination logic in the script; switching to the SDK is an alternative but not the direct solution to the problem described.

932
MCQeasy

A network administrator is configuring a new Cisco IOS router and needs to enable OSPFv2 on an interface with the correct area and network type. The interface is a broadcast multi-access network. Which command should be used to enable OSPF on the interface and set the area to 0?

A.router ospf 1: area 0 interface GigabitEthernet0/0
B.interface GigabitEthernet0/0: ip ospf 1 area 0
C.interface GigabitEthernet0/0: ip ospf area 0
D.router ospf 1: network 10.0.0.0 0.0.0.255 area 0
AnswerB

This command enables OSPF process 1 on the interface and assigns it to area 0. It is the interface-level method for enabling OSPF, which is precise and avoids the need for network statements. This is the recommended practice in modern Cisco IOS because it directly associates the interface with the OSPF process and area, reducing configuration errors.

Why this answer

The interface-level command 'ip ospf 1 area 0' enables OSPF process 1 on the interface and assigns it to area 0. This method is preferred over network statements because it is explicit and avoids unintended OSPF activation on other interfaces. The other options are either invalid syntax or less precise methods.

Exam trap

The trap here is assuming that OSPF must be enabled via the 'network' command under router configuration, overlooking the interface-level command.

933
Matchingmedium

Drag and drop each BGP attribute on the left to the value that is preferred (highest or lowest) during path selection on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Highest

Highest

Lowest

Lowest

Lowest

Why these pairings

Higher weight is preferred; higher LOCAL_PREF is preferred; shorter AS_PATH length is preferred; lower MULTI_EXIT_DISC is preferred; lower IGP metric to next-hop is preferred.

934
MCQmedium

Consider the following configuration for a FlexVPN spoke router: interface Tunnel0 ip address 10.0.0.2 255.255.255.0 tunnel source GigabitEthernet0/0/0 tunnel mode gre ip tunnel protection ipsec profile FLEXPROF ip nhrp network-id 100 ip nhrp nhs 10.0.0.1 ip nhrp map 10.0.0.1 192.168.1.1 What is the purpose of the 'ip nhrp map 10.0.0.1 192.168.1.1' command?

A.It maps the spoke's tunnel IP to its own physical interface IP for local routing.
B.It provides a static mapping from the hub's tunnel IP (10.0.0.1) to the hub's physical IP (192.168.1.1) so the spoke can reach the hub.
C.It enables multicast mapping for dynamic spoke discovery.
D.It configures the spoke to register with the hub using the specified physical address.
AnswerB

This static NHRP mapping on the spoke tells the spoke that the hub's tunnel interface 10.0.0.1 is reachable through the hub's physical NBMA address 192.168.1.1. Since the spoke needs to send initial NHRP registration and traffic to the hub before it learns dynamic mappings, this static map is essential. It is configured on the spoke, not the hub.

Why this answer

The 'ip nhrp map 10.0.0.1 192.168.1.1' command statically maps the hub's tunnel IP address (10.0.0.1) to its physical (NBMA) IP address (192.168.1.1). This is required on the spoke because NHRP is used to resolve the hub's tunnel IP to its underlying transport address so the spoke can build the GRE/IPsec tunnel. Without this static mapping, the spoke would not know where to send packets destined for the hub's tunnel interface.

Exam trap

Cisco often tests the distinction between NHRP static mapping (for the hub's address) and NHRP registration (where the spoke sends its own mapping to the hub), leading candidates to confuse the purpose of 'ip nhrp map' with registration or multicast functions.

How to eliminate wrong answers

Option A is wrong because the command does not map the spoke's tunnel IP to its own physical interface; that mapping is implicit or handled by the spoke's local routing and NHRP registration. Option C is wrong because NHRP multicast mapping (used for dynamic spoke discovery) is configured with 'ip nhrp map multicast', not with a unicast mapping command. Option D is wrong because the spoke registers with the hub using its own physical address, which is learned dynamically or configured via 'ip nhrp nhs' and 'ip nhrp registration no-unique'; this command provides a static mapping for the hub, not a registration directive.

935
Matchingmedium

Drag and drop each MPLS VPN role on the left to its matching description on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Customer edge router that connects to the provider network

Provider edge router that attaches labels and runs MP-BGP with other PEs

Provider core router that switches MPLS labels and does not hold customer routes

Router that connects two different MPLS VPN domains or autonomous systems

Route Reflector that reduces MP-BGP peering by reflecting VPN routes

Why these pairings

CE routers connect customer sites to the provider; PE routers label customer routes and exchange VPNv4 prefixes via MP-BGP; P routers perform label switching without storing customer routes; ASBR routers connect different MPLS domains; RRs propagate VPN routes within an AS.

936
MCQeasy

A network administrator is configuring a new Cisco IOS router and needs to enable OSPFv3 for IPv6 on an interface. The interface is already configured with an IPv6 address. Which command must be entered in interface configuration mode to enable OSPFv3 on that interface?

A.ipv6 ospf 1 area 0
B.ospfv3 1 ipv6 area 0
C.ipv6 router ospf 1
D.ip ospf 1 area 0
AnswerA

This command enables OSPFv3 on the interface and associates it with OSPF process 1 and area 0. It is the correct way to enable OSPFv3 for IPv6 on an interface in Cisco IOS. The process ID must match the one configured in the global 'ipv6 router ospf' command. This command is essential for OSPFv3 operation on a per-interface basis.

Why this answer

To enable OSPFv3 for IPv6 on an interface in Cisco IOS, the correct interface configuration command is 'ipv6 ospf <process-id> area <area-id>'. This command activates OSPFv3 on the interface and links it to the specified OSPFv3 process and area. The process ID must match the one defined in the global 'ipv6 router ospf' command.

Without this command, the interface will not participate in OSPFv3 routing.

Exam trap

The trap here is confusing OSPFv2 for IPv4 with OSPFv3 for IPv6, leading to the use of 'ip ospf' instead of 'ipv6 ospf'.

937
MCQmedium

Examine the following configuration snippet on a Cisco IOS-XE router: interface GigabitEthernet0/1 service-policy output QOS_POLICY policy-map QOS_POLICY class VOICE priority percent 10 class VIDEO bandwidth percent 30 class class-default fair-queue What is the effect of this configuration?

A.VOICE traffic is guaranteed 10% of the interface bandwidth with strict priority queuing, VIDEO traffic is guaranteed 30%, and all other traffic shares the remaining bandwidth using fair-queuing.
B.VOICE traffic is limited to 10% of bandwidth, VIDEO to 30%, and all other traffic is dropped if the interface is congested.
C.VOICE traffic is given priority over VIDEO, but VIDEO can use up to 30% of bandwidth only if VOICE is not using its allocation.
D.The policy-map is invalid because 'priority' and 'bandwidth' cannot be used together in the same policy-map.
AnswerA

This is correct. The 'priority' command places VOICE in a strict-priority (LLQ) queue and, during congestion, guarantees it the configured 10% of interface bandwidth so it cannot be starved by other traffic. The 'bandwidth' command reserves 30% of bandwidth for VIDEO, ensuring its minimum service under load. The default class with 'fair-queue' applies flow-based WFQ to all other traffic, which fairly shares the remaining bandwidth without dropping any class outright.

Why this answer

The 'priority percent 10' command under class VOICE enables strict priority queuing, guaranteeing that VOICE traffic is served first up to 10% of the interface bandwidth. The 'bandwidth percent 30' under class VIDEO provides a minimum bandwidth guarantee of 30% during congestion. The 'fair-queue' under class-default ensures that all other traffic shares the remaining bandwidth fairly using flow-based queuing, which is the default behavior when no explicit bandwidth is configured.

Exam trap

Cisco often tests the misconception that 'priority' and 'bandwidth' cannot coexist in the same policy-map, but they are allowed as long as they are in different classes; the trap is that candidates think the policy-map is invalid, when in fact it is a standard LLQ configuration.

How to eliminate wrong answers

Option B is wrong because it incorrectly states that all other traffic is dropped during congestion; in reality, class-default uses fair-queuing to share remaining bandwidth, not drop. Option C is wrong because it suggests VIDEO can use up to 30% only if VOICE is not using its allocation; the 'bandwidth percent' command guarantees a minimum bandwidth regardless of VOICE usage, not a conditional maximum. Option D is wrong because 'priority' and 'bandwidth' can be used together in the same policy-map; they are applied to different classes, which is perfectly valid and common in Cisco QoS designs.

938
Drag & Dropmedium

Drag and drop the steps of configuring Dynamic NAT on a Cisco IOS router into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Dynamic NAT configuration starts by defining the pool of global IP addresses using 'ip nat pool'. Next, an access list is created to identify the inside local addresses that will be translated. The NAT source list is then configured to associate the ACL with the pool.

After that, the inside and outside interfaces are designated with 'ip nat inside' and 'ip nat outside'. Finally, translation is verified with 'show ip nat translations'.

939
MCQmedium

A network architect is designing a new branch office that requires a controller-based wireless solution. The branch has a single Cisco Catalyst 9800-CL appliance and needs to support 802.1X authentication with dynamic VLAN assignment for employee SSIDs. Which deployment mode should the architect use for the access points to meet these requirements with minimal configuration on the APs?

A.FlexConnect mode with central switching enabled for the employee SSIDs
B.Sniffer mode with the APs capturing 802.11 frames for analysis
C.Local mode with the APs managed by the Catalyst 9800-CL controller
D.Monitor mode with the APs dedicated to spectrum analysis and rogue detection
AnswerC

In local mode, the AP establishes a CAPWAP tunnel to the Catalyst 9800-CL and the controller handles all client authentication, including 802.1X and dynamic VLAN assignment. This centralizes configuration and keeps the APs simple, matching the requirement for minimal AP configuration. Local mode is the standard controller-based deployment for branch offices with centralized management.

Why this answer

Local mode is the correct choice because it keeps the APs lightweight and relies on the Catalyst 9800-CL controller for all client authentication and VLAN assignment. This centralizes the complex configuration on the controller, reducing AP-side setup. The other modes either add unnecessary complexity for survivability or do not serve client traffic at all.

Exam trap

The trap here is assuming that FlexConnect is always required for branch offices, when local mode is sufficient if WAN survivability is not a requirement.

940
MCQmedium

A network engineer is configuring a Cisco IOS router to support a site-to-site VPN using IPsec. The engineer wants to ensure that traffic from the local subnet 10.1.1.0/24 to the remote subnet 10.2.2.0/24 is encrypted. Which configuration is required to define the interesting traffic?

A.crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 deny ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
B.crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip any any
C.crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
D.crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip 10.2.2.0 0.0.0.255 10.1.1.0 0.0.0.255
AnswerC

This configuration defines an access list (101) that matches traffic from 10.1.1.0/24 to 10.2.2.0/24, and references it in the crypto map with the 'match address' command. This access list identifies the interesting traffic that will be encrypted by IPsec. The crypto map also sets the peer and transform set, completing the IPsec configuration.

Why this answer

The correct configuration uses an access list that permits IP traffic from the local subnet to the remote subnet and references it in the crypto map with 'match address'. This defines the interesting traffic that triggers the IPsec tunnel. The other options either deny the traffic, permit all traffic, or reverse the source and destination, which do not precisely meet the requirement.

Exam trap

The trap here is using a deny statement or 'any any' in the access list, which either excludes the desired traffic or includes too much, leading to incorrect encryption behavior.

941
Drag & Dropmedium

Drag and drop the steps of LLQ configuration for voice traffic into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, classify voice traffic using a class-map matching DSCP EF. Then create a policy-map and assign the class to priority (LLQ). Optionally configure a bandwidth guarantee for other classes.

Apply the service-policy on the WAN interface. Finally, verify the LLQ operation using show policy-map interface.

942
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip eigrp neighbors EIGRP-IPv4 Neighbors for AS(100) H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 192.168.1.2 Gi0/0 13 00:12:34 12 100 0 45 1 10.1.1.2 Gi0/1 12 00:10:20 15 120 0 32 Based on this output, what can be concluded?

A.Both neighbors are using MD5 authentication.
B.Neighbor 192.168.1.2 has a higher metric than 10.1.1.2.
C.Both neighbors are fully established and exchanging routing information.
D.Router R1 is using EIGRP named mode.
AnswerC

A Q Cnt (queue count) of 0 means there are no EIGRP packets queued for transmission to the neighbor, indicating that all updates, queries, and replies have been processed and acknowledged, which is characteristic of a fully established adjacency. The presence of a valid, non-zero uptime value for both neighbors confirms that they have successfully completed the initial neighbor discovery and exchange process and are actively exchanging routing information. Thus, the output directly supports the conclusion that both neighbors are fully established and exchanging EIGRP routing information.

Why this answer

The 'show ip eigrp neighbors' output displays two neighbors in a stable state, indicated by the 'Q Cnt' (Queue Count) of 0 for both, meaning no packets are waiting to be sent. The 'Seq Num' (Sequence Number) values (45 and 32) show that R1 has received and processed EIGRP updates from each neighbor, confirming the adjacency is fully established and routing information is being exchanged. This output does not provide any metric or authentication details, so only the conclusion that both neighbors are fully operational is valid.

Exam trap

Cisco often tests the misconception that the 'show ip eigrp neighbors' output reveals authentication status or metric values, but the table only shows transport-layer reliability statistics and adjacency state, not security or routing metric details.

How to eliminate wrong answers

Option A is wrong because the 'show ip eigrp neighbors' output does not include any authentication type or key information; MD5 or SHA authentication status is verified with 'show ip eigrp interfaces detail' or 'show key chain', not from the neighbor table. Option B is wrong because the neighbor table does not display route metrics; metrics are shown per route in the topology table ('show ip eigrp topology') or routing table, and the SRTT/RTO values here are timers for reliable transport, not metrics. Option D is wrong because the output shows 'EIGRP-IPv4 Neighbors for AS(100)', which is the classic EIGRP configuration format; named mode EIGRP would display 'EIGRP-IPv4 VR-FOO Neighbors' or similar with a VRF or named instance, not just the AS number.

943
Matchingmedium

Drag and drop each NETCONF operation on the left to its matching action on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Retrieve operational state and configuration data

Retrieve only configuration data from a datastore

Create, update, or delete configuration data

Confirm and apply candidate configuration changes

Prevent other NETCONF sessions from modifying a datastore

Why these pairings

get retrieves operational state and configuration, get-config retrieves only configuration, edit-config modifies configuration, commit applies candidate changes, and lock prevents other sessions from modifying the datastore.

944
MCQmedium

An enterprise is migrating its data center to a leaf-spine architecture. The design must provide high availability and support for east-west traffic patterns. Which design choice best meets these requirements?

A.Deploy a collapsed core with a single pair of core switches.
B.Use a three-tier hierarchical design with access, distribution, and core layers.
C.Implement a leaf-spine topology with multiple spine switches and ECMP.
D.Use a ring topology connecting all switches in a loop.
AnswerC

Leaf-spine is a two-stage topology where each leaf switch connects to every spine switch, forming a full mesh that provides predictable, uniformly low latency between any two servers. Equal-cost multipath (ECMP) enables traffic to be hash-distributed across all available spine uplinks, maximizing aggregate bandwidth while avoiding link oversubscription. Adding spine or leaf switches scales bandwidth and port density linearly, and the multiple active paths deliver fast failover and high availability, making this design ideal for heavy east-west virtualization traffic.

Why this answer

A leaf-spine topology with multiple spine switches and Equal-Cost Multi-Path (ECMP) routing provides high availability by eliminating single points of failure and supports east-west traffic patterns by ensuring that any leaf switch can reach any other leaf switch with a consistent number of hops (typically one hop via a spine). ECMP allows load balancing across all available spine links, maximizing bandwidth and redundancy for data center east-west flows.

Exam trap

Cisco often tests the misconception that a three-tier design is always more reliable or that a collapsed core is sufficient for modern data centers, but the trap here is that candidates overlook the specific requirement for east-west traffic patterns, which demands a flat, non-blocking fabric like leaf-spine with ECMP rather than traditional hierarchical or ring topologies.

How to eliminate wrong answers

Option A is wrong because a collapsed core with a single pair of core switches still creates a bottleneck for east-west traffic, as all inter-subnet traffic must traverse the core pair, and it does not provide the same level of scalability or deterministic latency as a full leaf-spine design. Option B is wrong because a three-tier hierarchical design (access, distribution, core) introduces additional latency and oversubscription for east-west traffic, as traffic between access switches must traverse both distribution and core layers, which is suboptimal for modern data center east-west patterns. Option D is wrong because a ring topology creates a single loop that can cause broadcast storms and relies on Spanning Tree Protocol (STP) to block redundant paths, leading to inefficient use of links and potential convergence delays, which violates high availability and east-west traffic requirements.

945
MCQmedium

A network administrator is implementing a VXLAN EVPN fabric in a data center. The requirement is to provide Layer 2 connectivity between two leaf switches for a VLAN that must be stretched across the fabric. Which EVPN route type is used to advertise MAC address reachability information?

A.Type 1 - Ethernet Auto-Discovery route
B.Type 3 - Inclusive Multicast Ethernet Tag route
C.Type 4 - Ethernet Segment route
D.Type 2 - MAC/IP Advertisement route
AnswerD

Type 2 EVPN routes are used to advertise MAC address and optionally IP address reachability. In a VXLAN EVPN fabric, leaf switches advertise their locally learned MAC addresses using Type 2 routes. This allows other leaf switches to learn remote MAC addresses and forward traffic accordingly. Type 2 routes are essential for Layer 2 connectivity and are the correct choice for advertising MAC address reachability.

Why this answer

In a VXLAN EVPN fabric, MAC address reachability is advertised using Type 2 EVPN routes, also known as MAC/IP Advertisement routes. These routes allow leaf switches to learn remote MAC addresses and provide Layer 2 connectivity across the fabric. Type 2 routes are fundamental for the operation of EVPN-based VXLAN networks.

Exam trap

The trap here is confusing the different EVPN route types, especially Type 2 with Type 3, which is used for BUM traffic distribution.

946
MCQhard

A network engineer is troubleshooting a Cisco IOS-XE router that hosts several virtual routing and forwarding instances. A route to 10.20.30.0/24 exists in both the global routing table and in VRF CUSTOMER_A. A packet arrives on an interface assigned to VRF CUSTOMER_A with destination 10.20.30.10. How does the router determine which routing table to consult?

A.It always consults the global routing table first and falls back to the VRF table only if no match is found.
B.It uses the destination address to choose the VRF whose route has the longest prefix match.
C.It uses the VRF forwarding table associated with the ingress interface's VRF.
D.It compares administrative distance between the global and VRF entries and selects the lower value.
AnswerC

VRF selection is driven by the ingress interface. Because the receiving interface is bound to VRF CUSTOMER_A, the router performs the lookup in the CUSTOMER_A forwarding table, where the 10.20.30.0/24 route may point to a different next hop than the global entry, keeping tenant traffic isolated.

Why this answer

The VRF used for a forwarding lookup is determined by the VRF membership of the ingress interface, not by the destination address. Once the interface's VRF is identified, the router performs a longest prefix match inside that VRF's forwarding table, which keeps overlapping tenant and global addressing independent and isolated.

Exam trap

The trap here is believing the router compares or falls back between the global table and a VRF table when both contain the same prefix.

947
Multi-Selecthard

Which two statements about multicast RP (Rendezvous Point) are true? (Choose two.)

Select 2 answers
A.The RP is used only in PIM sparse mode and is the root of the shared distribution tree.
B.A single RP can serve multiple multicast groups, and multiple RPs can be configured for different group ranges.
C.The RP must be the first-hop router for all multicast sources in the network.
D.The RP must be directly connected to all multicast receivers.
E.In PIM dense mode, the RP is used to limit multicast flooding.
AnswersA, B

PIM sparse mode builds a shared tree rooted at the RP, so all sources and receivers initially meet there; dense mode floods instead and uses no RP. This directly satisfies the question's requirement that the RP anchors the shared distribution tree.

Why this answer

Option A is correct because the Rendezvous Point is a PIM-SM (sparse mode) concept: sources register with the RP and receivers join the shared tree (*, G) rooted at the RP, which forwards traffic until an SPT switchover occurs. Option B is correct because a single RP can service many groups, and Cisco IOS supports multiple RPs mapped to different group ranges via Anycast RP or MSDP, or by configuring separate RPs for different multicast group address ranges. Option C is incorrect because the RP does not need to be the first-hop router for sources; sources simply unicast-register their traffic to the RP through their DR.

Option D is incorrect because receivers join the shared tree via their local DR and IGMP, not through direct connection to the RP. Option E is incorrect because PIM dense mode uses flood-and-prune with no RP; the RP is specific to sparse mode.

Exam trap

This is a straight forward question that asks for two true statements; options C, D, and E are incorrect. Candidates should carefully read the number of correct options required.

948
Multi-Selecthard

A network automation team is designing a solution to manage configuration changes across a fleet of Cisco IOS XE devices. They want to use model-driven programmability with YANG data models. Which two protocols can be used to programmatically retrieve and modify configuration using YANG models on these devices? (Choose two.)

Select 2 answers
A.RESTCONF over HTTPS
B.NETCONF over SSH
C.SSH with CLI commands
D.CLI over Telnet
E.SNMPv3 with YANG models
AnswersA, B

RESTCONF is a RESTful protocol that also uses YANG models. It maps YANG data to HTTP methods (GET, POST, PUT, PATCH, DELETE) and uses JSON or XML. Cisco IOS XE supports RESTCONF over HTTPS. It is ideal for web-based automation and integrates well with modern tooling. It is a valid protocol for model-driven configuration.

Why this answer

NETCONF and RESTCONF are the two primary protocols for model-driven programmability using YANG models on Cisco IOS XE. NETCONF uses SSH and XML, while RESTCONF uses HTTPS and JSON/XML. Both allow structured configuration and state retrieval.

SNMP, Telnet, and CLI-based SSH do not natively support YANG and are not considered model-driven.

Exam trap

The trap here is assuming that any remote management protocol can use YANG models, when only NETCONF and RESTCONF are designed for model-driven programmability.

949
MCQhard

A network engineer is implementing MACsec on a Cisco switch-to-switch link to provide encryption. Both switches support MACsec and are configured with the same pre-shared key (PSK). The engineer configures 'mka' and 'macsec' on the interfaces. After configuration, the link does not come up, and the engineer sees 'MKA not operational' in the show macsec status. What is the most likely cause?

A.The pre-shared key (PSK) configured on both switches does not match.
B.MACsec requires a RADIUS server for key distribution, which is not configured.
C.The interfaces are configured with different VLANs, causing MACsec to fail.
D.The interfaces must be configured as trunk ports for MACsec to work.
AnswerA

MKA (MACsec Key Agreement) requires both peers to derive the same Connectivity Association Key (CAK) from the configured pre-shared key. If the PSKs differ, each switch computes a different CAK, so MKA authentication fails and no secure channel is established. This is the most direct cause of MACsec failing on a point-to-point link when both ends are configured with PSKs.

Why this answer

The 'MKA not operational' error indicates that the MACsec Key Agreement (MKA) protocol cannot establish a secure session. Since both switches are configured with a pre-shared key (PSK), the most likely cause is that the PSK values do not match, preventing MKA from completing the mutual authentication and key derivation process. MKA relies on the Connectivity Association Key (CAK) derived from the PSK; mismatched PSKs result in different CAKs, causing the MKA exchange to fail.

Exam trap

Cisco often tests the misconception that MACsec always requires a RADIUS server or 802.1X, but the question explicitly states a PSK is configured, so the trap is to overlook that the PSK mismatch is the direct cause of MKA failure.

How to eliminate wrong answers

Option B is wrong because MACsec can operate with a pre-shared key (PSK) without a RADIUS server; a RADIUS server is only required for 802.1X-based key distribution, not for PSK-based MKA. Option C is wrong because VLAN configuration does not affect MACsec operation; MACsec operates at Layer 2 and is independent of VLAN assignments. Option D is wrong because MACsec does not require trunk ports; it works on both access and trunk ports as long as the interface supports MACsec and MKA is enabled.

950
Multi-Selecthard

Which three statements about dynamic ARP inspection (DAI) are true? (Choose three.)

Select 3 answers
A.DAI validates ARP packets by checking the sender MAC and IP addresses against the DHCP snooping binding table.
B.DAI can be configured on a per-VLAN basis using the 'ip arp inspection vlan' command.
C.DAI includes rate limiting to prevent ARP flooding attacks.
D.DAI inspects both IPv4 ARP and IPv6 Neighbor Discovery packets.
E.DAI validates the destination IP address in ARP requests to prevent man-in-the-middle attacks.
AnswersA, B, C

DAI intercepts ARP packets on untrusted ports and compares each packet's sender MAC and sender IP against the DHCP snooping binding database, dropping any mismatch. This satisfies the stem's requirement for a true statement, since the binding table is the sole trust anchor DAI consults before forwarding ARP traffic.

Why this answer

Option A is correct because DAI works by intercepting ARP packets on untrusted ports and comparing the sender MAC and sender IP against entries in the DHCP snooping binding table (or a configured ARP ACL), dropping packets that do not match. Option B is correct because DAI is enabled per VLAN with the global configuration command 'ip arp inspection vlan <vlan-list>', allowing selective deployment on the VLANs that need protection. Option C is correct because DAI supports ARP packet rate limiting via the 'ip arp inspection limit rate <pps>' interface command, which protects the switch CPU from ARP flooding and denial-of-service attacks.

Option D is not correct because DAI inspects only IPv4 ARP packets; IPv6 Neighbor Discovery is handled by IPv6 First-Hop Security features such as IPv6 snooping, not DAI. Option E is not correct because DAI validates the sender MAC and sender IP (and optionally the destination MAC against the binding table), not the destination IP in ARP requests, so it does not operate in the way described.

Exam trap

The trap is thinking DAI inspects destination IPs or covers IPv6 — candidates confuse DAI with other inspection features and forget it only validates sender information in IPv4 ARP.

951
MCQmedium

A network engineer is configuring a VRF on a Cisco IOS-XE router to isolate a customer's traffic. The engineer creates VRF CUST_A, assigns the customer-facing interface to it, and runs the show ip route vrf CUST_A command, which returns no routes. The interface is up and the customer router is reachable. What is the most likely cause?

A.The ip vrf forwarding command must be applied to the VRF definition rather than to the interface.
B.The VRF was created but no route distinguisher or route target was configured, which is required for any VRF to install routes.
C.The global routing table must be cleared with the clear ip route * command before VRF routes will appear.
D.The interface was placed in the VRF, but no IP address or routing protocol was configured on that interface within the VRF.
AnswerD

An interface assigned to a VRF contributes its connected route to that VRF's table only if it has an IP address. If the interface has no address, or if no static route or routing protocol is configured inside the VRF address family, the VRF routing table will be empty. This matches the symptom of show ip route vrf CUST_A returning no routes.

Why this answer

A VRF routing table is populated by connected routes from interfaces that both belong to the VRF and have IP addresses, plus any static routes or dynamic routing configured inside the VRF address family. If the interface was moved into the VRF but never addressed, or if no routing protocol or static route was configured within the VRF, the table stays empty. Verifying the interface address and the VRF's routing configuration explains the symptom.

Exam trap

The trap here is assuming a VRF needs a route distinguisher and route target to hold local routes, when those are only needed for MPLS L3VPN signaling.

952
MCQmedium

Examine the following VRF configuration: vrf definition BLUE rd 1:1 route-target export 1:1 route-target import 2:2 ! interface GigabitEthernet0/5 vrf forwarding BLUE ip address 10.0.0.1 255.255.255.0 What is the effect of having different export and import route targets?

A.The VRF exports routes tagged with RT 1:1 and imports routes tagged with RT 2:2, enabling selective route exchange.
B.The configuration is invalid because export and import RTs must be identical.
C.The VRF will only import routes from other VRFs that also have RT 1:1.
D.This configuration disables route advertisement for VRF BLUE.
AnswerA

This is correct because in a VRF, the route-target export (RT 1:1) is attached as a BGP extended community to all routes the VRF advertises, while the route-target import (RT 2:2) filters incoming routes based on whether they carry RT 2:2. Since the export and import RTs are independent, this asymmetric configuration allows the VRF to selectively exchange routes with other VRFs or VRF instances in a hub-and-spoke or inter-VRF routing design, without needing the RTs to match.

Why this answer

The VRF BLUE configuration uses different route targets for export (1:1) and import (2:2). This enables selective route exchange: routes learned in VRF BLUE are exported with RT 1:1, and only routes tagged with RT 2:2 are imported into VRF BLUE. This is a common design for hub-and-spoke or inter-VRF route leaking scenarios where import and export RTs are intentionally asymmetric.

Exam trap

Cisco often tests the misconception that export and import route targets must match, but in reality they can differ to control route propagation in complex MPLS VPN designs.

How to eliminate wrong answers

Option B is wrong because Cisco IOS allows different export and import route targets; they do not need to be identical. Option C is wrong because the VRF imports routes tagged with RT 2:2, not RT 1:1; routes from other VRFs with RT 1:1 would be exported, not imported. Option D is wrong because the configuration does not disable route advertisement; routes are still exported with RT 1:1 and imported with RT 2:2, enabling normal VRF operation.

953
MCQmedium

A network engineer is configuring a Cisco Nexus 9000 switch as a VXLAN Tunnel Endpoint (VTEP). The switch has two loopback interfaces: Loopback0 (10.0.0.1/32) and Loopback1 (10.0.0.2/32). The engineer wants VXLAN traffic to use the loopback interface that is also used for BGP EVPN peering. Which command should be used to specify the source interface for the VXLAN tunnels?

A.interface nve1 source-interface loopback1
B.interface loopback1 vxlan source-interface
C.interface nve1 source-interface loopback0
D.feature nv overlay source-interface loopback1
AnswerA

The 'source-interface loopback1' command under the NVE interface configuration sets Loopback1 as the source for all VXLAN encapsulated traffic. Since Loopback1 is also used for BGP EVPN peering, this ensures consistent reachability and avoids asymmetric routing. This is the correct way to bind the VTEP source to a specific loopback, which is a common best practice in VXLAN EVPN deployments.

Why this answer

The correct configuration is to specify the source interface under the NVE interface using 'source-interface loopback1'. This binds the VTEP to the same loopback used for BGP EVPN peering, ensuring that the tunnel source address is reachable and consistent with the control plane. Using a different loopback could cause routing inconsistencies and is not recommended when the same loopback is already used for EVPN peering.

Exam trap

The trap here is confusing the global 'feature nv overlay' command with the interface-level source-interface configuration, or assuming the source interface should be configured on the loopback rather than under the NVE interface.

954
Drag & Dropmedium

Drag and drop the steps of NETCONF edit-config with candidate datastore flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The candidate datastore flow begins with locking the candidate, then editing it, validating the changes, committing them to running, and finally unlocking the candidate.

955
MCQmedium

Examine this Python script that uses the napalm library to manage a Cisco IOS-XE device: ```python from napalm import get_network_driver driver = get_network_driver('ios') device = driver('192.168.1.1', 'admin', 'cisco') device.open() print(device.get_facts()) device.close() ``` What is the output of this script?

A.It displays the running configuration of the device.
B.It prints a dictionary containing device facts like hostname, model, uptime, etc.
C.It applies a configuration change to the device.
D.It tests connectivity to the device using ICMP.
AnswerB

This option is correct because get_facts() is a NAPALM method that returns a dictionary containing key-value pairs of device information, including hostname, model, uptime, serial number, os_version, and vendor. The script likely calls this method and then prints the resulting dictionary to the console. This dictionary provides a normalized, vendor-agnostic view of the device's basic identity and operational state, which is useful for inventory and auditing purposes.

Why this answer

The script uses the napalm library with the 'ios' driver to connect to a Cisco IOS-XE device. The `get_facts()` method returns a dictionary containing device facts such as hostname, vendor, model, serial number, uptime, and OS version. Therefore, the output is a dictionary of these facts, not a configuration or connectivity test.

Exam trap

Cisco often tests the distinction between `get_facts()` and `get_config()` to see if candidates confuse retrieving device metadata with retrieving the actual configuration.

How to eliminate wrong answers

Option A is wrong because `get_facts()` does not retrieve the running configuration; to get the running configuration, you would use `get_config()` or `cli('show running-config')`. Option C is wrong because the script does not call any method to apply configuration changes, such as `load_merge_candidate()` or `commit_config()`. Option D is wrong because the script does not perform an ICMP test; connectivity is established via SSH (or Telnet) when `device.open()` is called, but the output is from `get_facts()`, not a ping.

956
MCQmedium

Examine the following Python script snippet that uses netmiko to configure a Cisco IOS-XE device: ```python from netmiko import ConnectHandler device = { 'device_type': 'cisco_ios', 'ip': '192.168.1.1', 'username': 'admin', 'password': 'cisco', } connection = ConnectHandler(**device) output = connection.send_command('show ip interface brief') print(output) connection.disconnect() ``` What is the primary purpose of this script?

A.It configures an IP address on an interface.
B.It retrieves and prints the output of 'show ip interface brief'.
C.It saves the running configuration to startup configuration.
D.It backs up the configuration to a TFTP server.
AnswerB

The script calls send_command with 'show ip interface brief' and prints the returned string, so its purpose is purely read-only retrieval of interface status. No configuration commands are sent, distinguishing it from a configuration or backup script.

Why this answer

The script uses netmiko's `send_command()` method, which sends a show command to the device and returns the output. It does not include any configuration commands or file transfer operations. Therefore, its primary purpose is to retrieve and print the output of 'show ip interface brief'.

Exam trap

Cisco often tests the distinction between `send_command()` (for show commands) and `send_config_set()` (for configuration commands), leading candidates to mistakenly think any script that connects to a device is performing configuration changes.

How to eliminate wrong answers

Option A is wrong because the script uses `send_command()` to issue a show command, not a configuration command like `ip address`; no `send_config_set()` or `config_mode()` is used. Option C is wrong because saving the running configuration to startup configuration requires a command like `write memory` or `copy running-config startup-config`, which is not present. Option D is wrong because backing up to a TFTP server would require a command like `copy running-config tftp:` or a file transfer method, and the script only uses `send_command()` for a show command.

957
Multi-Selecthard

Which three statements about model-driven telemetry are true? (Choose three.)

Select 3 answers
A.Model-driven telemetry uses YANG data models to define the data to be streamed.
B.Telemetry data can be pushed from the network device to a collector using gRPC or gNMI.
C.Model-driven telemetry supports both periodic and on-change subscriptions.
D.Model-driven telemetry requires SSH for secure data transport.
E.Model-driven telemetry increases the polling overhead compared to SNMP.
AnswersA, B, C

Model-driven telemetry relies on YANG data models to define precisely which data nodes are streamed, giving structured, schema-driven output. This satisfies the requirement that the data to be streamed is specified by models rather than arbitrary OIDs.

Why this answer

Option A is correct because model-driven telemetry is built on YANG data models, which define the structure and semantics of the data that the device streams to the collector. Option B is correct because telemetry data is pushed from the network device to a collector using protocols such as gRPC (often with gNMI as the transport/encoding interface), rather than being polled. Option C is correct because model-driven telemetry supports subscription types including periodic (sample/dial-in or dial-out intervals) and on-change (event-driven) subscriptions.

Option D is incorrect because model-driven telemetry does not require SSH for data transport; it typically uses gRPC/gNMI over TLS, and SSH is not the streaming transport. Option E is incorrect because model-driven telemetry is push-based and generally reduces polling overhead compared to SNMP polling, not increases it.

Exam trap

350-401 often tests the misconception that MDT is a pull-based model like SNMP — candidates must remember MDT is fundamentally push-based, and that SSH is not the transport protocol.

958
MCQeasy

A network administrator is configuring a Cisco IOS-XE router to support Virtual Routing and Forwarding (VRF). The administrator wants to ensure that traffic from different VRFs can be routed between each other using a shared service VRF. Which VRF feature allows routes to be leaked between VRFs?

A.VRF forwarding table
B.IP routing protocol redistribution
C.Route distinguisher
D.Route target export and import
AnswerD

In VRF-lite or MPLS L3VPN, route targets control the import and export of routes between VRFs. By configuring matching route targets on two VRFs, routes from one VRF can be imported into another. This is the standard method for route leaking between VRFs. It allows controlled communication between VRFs without merging them entirely.

Why this answer

Route targets are used to control the import and export of routes between VRFs. By configuring matching route targets on two VRFs, routes can be leaked from one VRF to another. This is the standard method for inter-VRF communication in MPLS L3VPN and VRF-lite environments.

Route distinguishers make prefixes unique but do not control leaking.

Exam trap

The trap here is confusing the role of the route distinguisher with that of the route target; the RD makes prefixes unique, while the RT controls import/export.

959
MCQeasy

A network administrator is configuring a new Cisco IOS switch and wants to ensure that the management VLAN is isolated from user traffic. The administrator needs to assign an IP address to VLAN 1 for management access. Which command should be used to enter the interface configuration mode for VLAN 1?

A.interface vlan 1
B.ip address 192.168.1.1 255.255.255.0
C.interface fastethernet 0/1
D.vlan 1
AnswerA

The command 'interface vlan 1' enters the configuration mode for the switched virtual interface (SVI) associated with VLAN 1. This allows the administrator to assign an IP address to the management VLAN. This is the correct method to configure Layer 3 connectivity on a switch for management purposes. It is a fundamental step in setting up in-band management on Cisco switches.

Why this answer

To assign an IP address to a VLAN for management, you must enter the SVI configuration using 'interface vlan 1'. This creates a logical Layer 3 interface for that VLAN. The other options either configure physical interfaces, create the VLAN without Layer 3, or are incomplete without entering the interface mode first.

Exam trap

The trap here is confusing VLAN creation with SVI configuration, thinking that creating a VLAN automatically allows IP assignment.

960
Multi-Selectmedium

Which two statements about 802.1X authentication with MAC Authentication Bypass (MAB) are true? (Choose two.)

Select 2 answers
A.MAB is used as a fallback authentication method for devices that do not support 802.1X.
B.MAB requires the supplicant to present a digital certificate for authentication.
C.In MAB, the switch sends the MAC address of the endpoint as the username and password to the RADIUS server.
D.MAB encrypts the MAC address using TLS before sending it to the RADIUS server.
E.MAB uses EAPoL to transport the MAC address between the switch and the endpoint.
AnswersA, C

MAB provides fallback authentication when a device lacks an 802.1X supplicant, satisfying the stem's requirement for non-802.1X-capable endpoints. The switch learns the source MAC address and forwards it to the RADIUS server as both username and password. This permits printers, cameras and similar devices to gain network access without supplicant software.

Why this answer

Option A is correct because MAB is specifically designed as a fallback for endpoints that lack an 802.1X supplicant, such as printers, cameras, and legacy devices, allowing the switch to authenticate them by MAC address when EAPoL identity exchange fails or is absent. Option C is correct because in MAB the switch (authenticator) uses the endpoint's source MAC address as both the username and password in a RADIUS Access-Request, typically formatted as the MAC in a consistent case and delimiter scheme (e.g., aabbccddeeff or aa:bb:cc:dd:ee:ff). Option B is wrong because MAB does not use digital certificates; certificate-based authentication belongs to EAP-TLS, which requires a supplicant.

Option D is wrong because MAB sends the MAC address in cleartext within RADIUS attributes (e.g., User-Name and User-Password/CHAP), not TLS-encrypted, and RADIUS itself is not inherently TLS-protected. Option E is wrong because EAPoL is used between the supplicant and the switch for 802.1X, whereas MAB is triggered precisely when no EAPoL supplicant responds, and the MAC address is carried to the RADIUS server over RADIUS, not EAPoL.

961
Multi-Selectmedium

Which two statements about AAA authentication methods are true? (Choose two.)

Select 2 answers
A.The local method for authentication uses the enable password for privilege level 15 access.
B.The enable method for authentication uses the enable password or secret.
C.The none method for authentication provides fallback to the local database if the server is unreachable.
D.The login local method authenticates users against the local username database.
E.The line password method for authentication uses the enable secret password.
AnswersB, D

The enable authentication method verifies the user against the locally configured enable password or enable secret before granting privileged EXEC mode. It is a distinct method from login authentication, which validates via line, local, or AAA credentials.

Why this answer

Option B is correct because the AAA 'enable' authentication method prompts for the enable password (configured with 'enable password') or the enable secret (configured with 'enable secret'), which is exactly what this method is designed to verify. Option D is correct because the 'login local' method authenticates users against the local username/password database created with the 'username' command, rather than against a remote AAA server. Option A is wrong because the 'local' method uses the local username database, not the enable password, for authentication.

Option C is wrong because the 'none' method performs no authentication at all and does not fall back to the local database. Option E is wrong because the line password method uses the line password configured with the 'password' command under 'line con/vty', not the enable secret.

Exam trap

350-401 often tests the specific password each method uses; candidates may confuse the 'local' method with the enable password or the 'line' method with the enable secret.

962
Multi-Selectmedium

A network engineer is building a Python script to interact with a Cisco IOS XE device using RESTCONF. The script must authenticate, retrieve interface configuration, and handle the response. Which two actions are required to successfully complete this task? (Choose two.)

Select 2 answers
A.Configure the device with an SNMP community string so RESTCONF can authenticate the API session.
B.Use the 'ncclient' library to establish a NETCONF session on port 830 and then issue RESTCONF calls through that session.
C.Enable the RESTCONF agent on the device by entering the 'restconf' global configuration command and ensuring the HTTPS server is active.
D.Install the 'yangsuite' package on the IOS XE device to validate the RESTCONF payloads before sending them.
E.Send an HTTP GET request to the appropriate RESTCONF URI, such as /restconf/data/ietf-interfaces:interfaces, with the Accept header set to application/yang-data+json.
AnswersC, E

RESTCONF is not enabled by default on IOS XE. The 'restconf' global command starts the RESTCONF agent, and it depends on the HTTPS server being active via 'ip http secure-server'. Without these, the device will not accept RESTCONF requests, resulting in connection failures or 401 errors. This step is mandatory before any RESTCONF API call can succeed.

Why this answer

Successful RESTCONF interaction requires enabling the RESTCONF agent and HTTPS server on the device, then issuing proper HTTP requests to the correct RESTCONF data URIs with appropriate media type headers. NETCONF libraries, SNMP settings, and client-side YANG tools do not enable or perform RESTCONF operations, so only enabling RESTCONF and using correct HTTP GET requests are required.

Exam trap

The trap here is conflating NETCONF and RESTCONF tooling, assuming that a NETCONF library or SNMP configuration contributes to RESTCONF access when RESTCONF is purely HTTP-based.

963
MCQeasy

A network administrator is comparing configuration management tools and wants to use one that is agentless, uses YAML for playbooks, and communicates with Cisco IOS XE devices over SSH. Which tool best meets these requirements?

A.Puppet
B.Chef
C.SaltStack
D.Ansible
AnswerD

Ansible is agentless, connecting to devices over SSH, and uses YAML-formatted playbooks to define automation tasks. It includes modules such as ios_config and ios_command that specifically target Cisco IOS XE devices. This matches all stated requirements: no agent, YAML syntax, and SSH communication, making it the correct choice for this scenario.

Why this answer

Ansible is designed as an agentless automation tool that communicates over SSH and uses YAML playbooks. It provides network-specific modules for Cisco IOS XE, allowing configuration and command execution without installing software on the managed devices. This combination of agentless architecture, YAML syntax, and SSH transport exactly matches the administrator's requirements, distinguishing it from agent-based tools like Puppet, Chef, and SaltStack.

Exam trap

The trap here is assuming that any tool using YAML or supporting SSH is equivalent, when in fact Ansible is uniquely agentless with YAML playbooks as its core design.

964
MCQmedium

A network architect is designing a Cisco SD-WAN fabric for a retail chain with 200 branch sites. The design must provide a single control-plane protocol that distributes routing and policy information between the SD-WAN controllers and the WAN Edge devices, while keeping data-plane traffic direct between branches. Which technology should the architect select for the control plane?

A.Intermediate System-to-Intermediate System (IS-IS)
B.Locator/ID Separation Protocol (LISP)
C.Cisco Overlay Management Protocol (OMP)
D.Border Gateway Protocol (BGP) with route reflectors
AnswerC

OMP is the SD-WAN control-plane protocol that runs between WAN Edge devices and the vSmart controller over DTLS/TLS. It advertises TLOCs, service-side routes, and centralized policy, enabling the controller to orchestrate fabric reachability without hairpinning data traffic. This matches the requirement of a single control plane with direct branch-to-branch data forwarding, so it is the correct choice.

Why this answer

Cisco SD-WAN uses OMP as the single control-plane protocol between the vSmart controller and WAN Edge devices. OMP carries TLOC, route, and policy information, allowing the controller to make forwarding decisions while data traffic flows directly between branches. BGP and IS-IS are underlay or service-side protocols, and LISP belongs to SD-Access, so they do not meet the stated design requirement.

Exam trap

The trap here is assuming that any routing protocol carrying prefixes between WAN Edge devices can serve as the SD-WAN fabric control plane, when only OMP provides TLOC and centralized policy distribution.

965
MCQmedium

Consider this configuration for TrustSec on a Cisco switch: cts role-based enforcement interface GigabitEthernet1/0/5 cts manual sap pmk AABBCCDDEEFF00112233445566778899 mode-list both propagate sgt What is the purpose of the 'propagate sgt' command under the interface?

A.It allows the switch to receive SGT information from the connected device.
B.It enables the switch to insert SGT tags into packets forwarded out of this interface.
C.It enables the switch to enforce role-based access control on this interface.
D.It configures the interface to use SXP for SGT propagation.
AnswerB

The 'propagate sgt' interface command instructs the switch to take the SGT it has associated with a received frame (either from its own classification or from an upstream TrustSec device) and insert that tag into the 802.1Q or MACsec header of packets forwarded out of this interface. This is an egress tagging action only — the switch is not learning SGTs from the neighbor on this port, nor is it applying any policy decision. It enables downstream devices that are TrustSec-capable to receive the SGT and use it for their own enforcement, effectively extending the TrustSec domain across that link.

Why this answer

The 'propagate sgt' command under a TrustSec manual interface instructs the switch to insert the Security Group Tag (SGT) into packets that are forwarded out of this interface. This is essential for downstream devices to receive the SGT and enforce role-based access control (RBAC) based on the source's security group. Option B correctly identifies this behavior.

Exam trap

Cisco often tests the distinction between 'propagate sgt' (which inserts SGT into packets) and SXP (which propagates SGT mappings via TCP), causing candidates to confuse the two or think 'propagate sgt' is about receiving SGT information.

How to eliminate wrong answers

Option A is wrong because 'propagate sgt' does not involve receiving SGT information; receiving SGT from a connected device is typically done via SXP (SGT Exchange Protocol) or by decoding inline tags. Option C is wrong because enforcement of role-based access control is enabled by the 'cts role-based enforcement' command globally, not by 'propagate sgt' on an interface. Option D is wrong because SXP is a separate protocol used for SGT propagation over Layer 3 links, and 'propagate sgt' is specifically for inserting SGT into packets on a Layer 2 interface, not for using SXP.

966
MCQmedium

A network engineer is deploying a new branch office router that must obtain its WAN interface IP address dynamically from the ISP while also advertising its LAN prefix into OSPF. The engineer configures the WAN interface with the ip address dhcp command. Which additional configuration is required on the router to ensure the LAN prefix is advertised into OSPF with the correct network statement when the WAN IP changes?

A.Enable OSPF on the WAN interface and rely on connected route redistribution.
B.Use the network command with a wildcard mask that matches the LAN subnet under router ospf.
C.Configure a static route to the ISP and redistribute it into OSPF.
D.Configure OSPF to use the interface's DHCP-assigned IP address as the router ID.
AnswerB

The network command under router ospf with a wildcard mask matching the LAN subnet will advertise the LAN prefix into OSPF regardless of the WAN IP address. This is the standard method to enable OSPF on an interface and advertise its connected network. It does not depend on the WAN IP, so it remains stable when the DHCP lease changes.

Why this answer

The network command under router ospf with a wildcard mask matching the LAN subnet is the correct way to advertise the LAN prefix into OSPF. It is independent of the WAN interface's DHCP-assigned IP address, so the advertisement remains stable even if the WAN IP changes. Other options either advertise the wrong prefix or introduce unnecessary complexity.

Exam trap

The trap here is assuming that because the WAN interface uses DHCP, the OSPF configuration must also be dynamic, but the LAN advertisement is separate and should use a static network statement.

967
MCQmedium

A network engineer writes a Python script using Paramiko to execute a command on a Cisco IOS device: ```python import paramiko ssh = paramiko.SSHClient() ssh.set_missing_host_key_policy(paramiko.AutoAddPolicy()) ssh.connect('192.168.1.1', username='admin', password='cisco123') stdin, stdout, stderr = ssh.exec_command('show version') output = stdout.read().decode() print(output) ssh.close() ``` What is a potential issue with this approach?

A.The script will work fine because exec_command() sends the command over SSH.
B.The script will fail because the username and password are passed as plaintext; Paramiko requires key-based authentication.
C.The script will fail because Cisco IOS does not support SSH command execution; it requires an interactive shell session.
D.The script will fail because the output should be read using stdout.readlines() instead of stdout.read().
AnswerC

The failure occurs because Cisco IOS does not support the SSH exec channel that Paramiko's exec_command() uses; it expects a full interactive terminal session. When exec_command() sends a single command, IOS has no mechanism to run it directly and may close the channel or ignore it. The correct approach is invoke_shell(), which allocates a VTY session and lets the automation interact with the CLI prompts.

Why this answer

Cisco IOS devices typically require an interactive shell session for command execution over SSH. The Paramiko `exec_command()` method sends a single command and expects a response, but IOS does not natively support this non-interactive mode; it expects a VTY interactive session. As a result, the script may hang, return no output, or fail to execute the command properly.

Exam trap

The trap here is that candidates assume SSH automation works identically across all devices, but Cisco IOS requires an interactive shell session rather than the single-command exec channel that Paramiko's `exec_command()` uses.

How to eliminate wrong answers

Option A is wrong because the script will not work fine; Cisco IOS does not support direct command execution via SSH without an interactive shell, so `exec_command()` will not produce the expected output. Option B is wrong because Paramiko supports password-based authentication, and passing credentials as plaintext is not inherently a failure point; the issue is not with authentication method but with IOS's SSH behavior. Option D is wrong because `stdout.read()` is a valid way to read the output; `stdout.readlines()` would also work but is not required, and the failure is not due to the read method.

968
MCQeasy

A network engineer is configuring a Cisco Wireless LAN Controller (WLC) for a new wireless network. The engineer wants to ensure that client traffic is tunneled back to the WLC and that the WLC is the single point of management for the access points. Which mode should the access points be configured in?

A.Sniffer mode
B.FlexConnect mode
C.Monitor mode
D.Local mode
AnswerD

In local mode, access points establish a Control and Provisioning of Wireless Access Points (CAPWAP) tunnel to the WLC for both management and client data traffic. This allows the WLC to be the single point of management and ensures client traffic is tunneled back to the WLC. Local mode is the default and most common deployment mode for centralized wireless networks.

Why this answer

Local mode is the standard mode for access points in a centralized wireless deployment. It creates a CAPWAP tunnel to the WLC, carrying both management and client data traffic. This ensures that the WLC is the single point of management and that all client traffic is tunneled back to the WLC, meeting the engineer's requirements.

Other modes either do not serve clients or switch traffic locally.

Exam trap

The trap here is confusing FlexConnect mode, which can also be managed by the WLC but does not tunnel client traffic by default, with Local mode.

969
MCQmedium

A network engineer is configuring NTP authentication on a Cisco IOS-XE router. The goal is to ensure the router only synchronizes with a trusted NTP server and that the server's keys are validated. Which sequence of configuration steps correctly enforces authenticated NTP peering?

A.Define the key with `ntp authentication-key 1 md5 <key>` and add `ntp server <ip> key 1`, omitting `ntp authenticate` because the server command implies authentication.
B.Enable `ntp authenticate` and mark the key trusted with `ntp trusted-key 1`, but do not configure the key value itself, relying on the server to supply it.
C.Configure `ntp master 1` on the router and add `ntp server <ip>`, because a stratum 1 master enforces authentication automatically.
D.Enable `ntp authenticate`, define the key with `ntp authentication-key 1 md5 <key>`, mark it trusted with `ntp trusted-key 1`, then add `ntp server <ip> key 1`.
AnswerD

This sequence turns on authentication globally, creates the MD5 key, marks that key as trusted so the router accepts it, and associates the key with the server. Each step is required: without `ntp authenticate` the router ignores authentication, without a trusted key it rejects valid packets, and without the key number on the server command it will not use the key for that peer. Together they enforce authenticated peering.

Why this answer

Enforcing authenticated NTP requires four coordinated elements: the global `ntp authenticate` command, a defined authentication key with its MD5 value, a `ntp trusted-key` statement for that key number, and the key reference on the `ntp server` command. Missing any one element breaks the chain, either by leaving authentication disabled, by rejecting valid packets, or by failing to associate the key with the specific peer.

Exam trap

The trap here is thinking that referencing a key on the `ntp server` command is sufficient, when the global `ntp authenticate` command and a trusted-key statement are also mandatory.

970
MCQhard

A network engineer configured VRF TENANT_A and moved the subinterfaces into the VRF. After the change, the CEF table shows the prefixes but the next-hop addresses are unreachable. What is the most likely cause?

A.LISP is not configured to map the virtual network.
B.The next-hop IP addresses are in the global routing table, not in the VRF.
C.OSPF is not redistributing the routes into the VRF.
D.The physical interface is not configured as a trunk.
AnswerB

VRF segregation creates an independent routing and CEF table, so next hops must reside within the same VRF. If the next-hop addresses belong to the global table, they are unresolvable inside VRF TENANT_A, leaving prefixes present but next hops unreachable.

Why this answer

When subinterfaces are moved into a VRF, the CEF table for that VRF will contain the learned prefixes, but the next-hop addresses must also be reachable within the same VRF. If the next-hop IP addresses reside in the global routing table instead of the VRF, the VRF will have no route to those next hops, causing them to be marked as unreachable. This is a common misconfiguration where the next-hop adjacency is not established within the VRF context.

Exam trap

Cisco often tests the concept that VRF creates a completely isolated routing table, and the trap here is that candidates assume CEF showing the prefix means the route is fully functional, overlooking that the next-hop must also be in the same VRF.

How to eliminate wrong answers

Option A is wrong because LISP (Locator/ID Separation Protocol) is not required for basic VRF operation; it is used for overlay network virtualization and mobility, not for resolving next-hop reachability within a VRF. Option C is wrong because OSPF redistribution is not the root cause; the issue is that the next-hop addresses are not present in the VRF's routing table, not that routes are missing from OSPF. Option D is wrong because trunk configuration on the physical interface is irrelevant to VRF next-hop reachability; subinterfaces can be placed into a VRF regardless of whether the parent interface is a trunk or access port.

971
MCQhard

An engineer is configuring a new access switch that connects to two distribution switches via trunk links. The distribution switches are configured with Rapid PVST+ and are both running as root bridges for different VLANs. The engineer wants to ensure that the access switch does not become the root bridge for any VLAN, even if the distribution switches fail. The engineer also wants to prevent any unauthorized switch from becoming root. What configuration should the engineer apply on the access switch?

A.Configure 'spanning-tree vlan 1-4094 priority 61440' and enable Root Guard on the uplink ports.
B.Configure 'spanning-tree vlan 1-4094 priority 0' and enable BPDU Guard on the uplink ports.
C.Configure 'spanning-tree vlan 1-4094 priority 4096' and enable Loop Guard on the uplink ports.
D.Configure 'spanning-tree vlan 1-4094 priority 61440' and enable BPDU Guard on the uplink ports.
AnswerA

Setting the bridge priority to 61440, the maximum valid value, makes this switch the least preferred candidate in the root bridge election, so it can never assume the root role. Enabling Root Guard on the uplink ports monitors incoming BPDUs and places any port receiving a superior BPDU into a root-inconsistent state, blocking that path and preserving the current root. Together, these actions ensure the switch stays as a non-root and remains resilient against an unauthorized switch attempting to claim root.

Why this answer

Setting the spanning-tree priority to 61440 (the highest possible value) ensures the access switch will never become the root bridge, even if the current root bridges fail. Enabling Root Guard on the uplink ports prevents any unauthorized switch from becoming root by placing the port into a root-inconsistent state if a superior BPDU is received, thus protecting the root bridge election.

Exam trap

Cisco often tests the distinction between Root Guard and BPDU Guard, where candidates mistakenly apply BPDU Guard (which shuts down ports receiving any BPDU) instead of Root Guard (which specifically protects the root bridge election) on trunk links.

How to eliminate wrong answers

Option B is wrong because setting the priority to 0 makes the access switch the most likely candidate to become root, which directly contradicts the requirement to prevent it from becoming root. Option C is wrong because priority 4096 is a low value that could allow the access switch to become root if the distribution switches fail, and Loop Guard prevents alternate/root port loops but does not protect against unauthorized root bridges. Option D is wrong because while the priority 61440 is correct, BPDU Guard is used to shut down ports that receive BPDUs (typically on access ports), not to prevent unauthorized root bridges on trunk links; Root Guard is the appropriate feature for this purpose.

972
MCQmedium

A network engineer is configuring a remote access VPN using Cisco AnyConnect on an ASA. The engineer wants to use certificate-based authentication. The ASA is configured with a CA server. After configuration, users can connect, but they are prompted for a username and password instead of using certificates. The engineer checks the ASA configuration and sees that the tunnel group has authentication method set to AAA. What should the engineer do to fix this?

A.Re-enroll the CA certificate on the ASA.
B.Change the connection profile to use the correct group.
C.Configure the group policy to require certificates.
D.Change the tunnel group authentication method to certificate.
AnswerD

Changing the tunnel group authentication method to certificate is the correct action because the tunnel group is where the ASA determines whether to accept usernames/passwords, client certificates, or both. Once the AnyConnect client presents a certificate, the ASA must be configured with the authentication method of 'certificate' (or 'both') in the matching tunnel group to validate that certificate and map it to a user identity. Without this setting, the ASA falls back to its default AAA login prompt, ignoring the client's certificate and causing the exact behavior seen where users can establish a network connection but cannot authenticate.

Why this answer

The tunnel group authentication method determines how users are authenticated for the VPN connection. When set to AAA, the ASA prompts for a username and password, bypassing certificate-based authentication. Changing it to 'certificate' tells the ASA to use the client certificate for authentication, which matches the requirement for certificate-based authentication with AnyConnect.

Exam trap

Cisco often tests the distinction between tunnel group authentication (which controls the credential prompt) and group policy authorization (which applies after authentication), leading candidates to mistakenly configure the group policy instead of the tunnel group.

How to eliminate wrong answers

Option A is wrong because re-enrolling the CA certificate does not change the authentication method; the ASA already trusts the CA, but the tunnel group still requires AAA credentials. Option B is wrong because the connection profile (tunnel group) is already in use; the issue is the authentication method within that profile, not which group is selected. Option C is wrong because group policies control authorization attributes (like split-tunneling or ACLs), not the authentication method; authentication is configured at the tunnel group level, not the group policy.

973
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive CPU utilization due to malicious traffic. The engineer wants to ensure that BGP, SSH, and SNMP traffic are rate-limited appropriately. After applying the CoPP policy, the engineer notices that BGP sessions are flapping. Which action should the engineer take to resolve the issue while maintaining protection?

A.Remove the CoPP policy from the control plane and apply it only to the data plane.
B.Configure a separate class-map for BGP and assign it to a higher priority queue in the policy-map.
C.Enable BGP graceful restart to prevent session flapping during CoPP drops.
D.Increase the rate limit for the class-map that matches BGP traffic.
AnswerD

BGP sessions flapping indicate that the CoPP policy is dropping legitimate BGP keepalives or updates due to an overly restrictive rate limit. Increasing the rate limit for the BGP class-map allows sufficient BGP control traffic to reach the route processor while still protecting against excessive traffic. This balances protection with operational stability.

Why this answer

BGP session flapping after applying CoPP typically occurs because the policer is dropping legitimate BGP control packets. The correct fix is to increase the rate limit for the BGP traffic class so that keepalives and updates are not dropped, while still protecting the control plane from excessive traffic. Other options either do not address the rate limit or suggest inappropriate mechanisms.

Exam trap

The trap here is thinking that CoPP uses queuing or that BGP graceful restart can prevent flapping caused by policer drops, when the real issue is an insufficient rate limit.

974
Drag & Dropmedium

Drag and drop the steps of SD-WAN policy creation and push via vManage into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Policy creation begins with defining the policy in vManage, then attaching it to a group of devices, after which vManage pushes the policy to vSmart, vSmart translates it into OMP updates, and finally the edge devices receive and enforce the policy.

975
MCQhard

A telemetry subscription is configured on a Cisco IOS-XE device using gRPC dial-out: telemetry ietf subscription 101 encoding encode-kvgpb filter xpath /interfaces/interface/statistics stream yang-push update-policy periodic 500 receiver ip address 10.10.10.10 50001 protocol grpc-tcp What does this configuration do?

A.It sends interface statistics every 500 milliseconds to the receiver using gRPC.
B.It sends interface statistics every 500 seconds to the receiver at 10.10.10.10 port 50001 using gRPC.
C.It sends configuration changes for interfaces to the receiver using gRPC.
D.It sends interface statistics only when there is a change, using a push model.
AnswerB

This is the correct answer. The summarized configuration shows a telemetry subscription that uses gRPC as the transport, with a destination-group pointing to the receiver at IPv4 10.10.10.10 port 50001. The sensor-group filters interface statistics, and the update-policy periodic 500 means those statistics are pushed every 500 seconds, independent of whether the values changed. This correctly describes a periodic push of interface counters to the specified collector over gRPC.

Why this answer

The configuration uses an `update-policy periodic 500` statement, which specifies a 500-second interval for sending updates, not 500 milliseconds. The receiver is configured with IP address 10.10.10.10 on port 50001 using the `grpc-tcp` protocol, and the filter XPath `/interfaces/interface/statistics` selects interface statistics. This is a gRPC dial-out telemetry subscription that periodically pushes data to the collector.

Exam trap

Cisco often tests the unit of time in `update-policy periodic` — candidates mistakenly assume milliseconds due to common networking timers (e.g., OSPF hello intervals), but Cisco IOS-XE telemetry always uses seconds for periodic updates.

How to eliminate wrong answers

Option A is wrong because it incorrectly interprets the `periodic 500` as 500 milliseconds, but in Cisco IOS-XE telemetry, the value is in seconds, not milliseconds. Option C is wrong because the configuration uses a `filter xpath /interfaces/interface/statistics` which selects operational statistics, not configuration changes; it also uses `stream yang-push` which pushes state data, not configuration. Option D is wrong because the `update-policy periodic 500` explicitly sets a fixed interval of 500 seconds, not an on-change trigger; an on-change policy would use `update-policy on-change` instead.

Page 12

Page 13 of 26

Page 14