Courseiva

ENCOR 350-401 (350-401) — Questions 976–1050

1923 questions total · 26pages · All types, answers revealed

Page 13

Page 14 of 26

Page 15
976
MCQmedium

A company uses Cisco NFVIS to host a virtual ASA (vASA) and a virtual router (vRouter). The engineer notices that the vASA cannot communicate with the vRouter even though both are on the same NFVIS host. The vASA is connected to a bridge network, and the vRouter is connected to a different bridge. What should the engineer do to enable communication between the two VNFs?

A.Connect a physical cable between two ports on the NFVIS host.
B.Create a new bridge that connects both VNFs, or use a virtual switch to route between the bridges.
C.Configure VLAN tagging on both VNFs with the same VLAN ID.
D.Add a static route on each VNF pointing to the other VNF's IP address.
AnswerB

Correct. In NFVIS, you can create a Linux bridge that acts as a virtual Layer 2 switch. Attaching both VNFs' vNICs to the same bridge places them in the same broadcast domain, allowing direct communication via MAC learning and forwarding. Alternatively, if the VNFs reside on different bridges (separate Layer 2 domains), you can use a virtual router—either a VNF configured for routing or NFVIS's own virtual switch—to route packets between those bridges. This is the standard method for inter-VNF connectivity on a single NFVIS host.

Why this answer

In NFVIS, VNFs attached to different bridge networks are isolated at Layer 2. To enable communication between them, you must either create a new bridge that connects both VNFs or use a virtual switch (e.g., a Linux bridge with routing enabled) to forward traffic between the two bridges. This allows the VNFs to share a common Layer 2 domain or have a routed path through the hypervisor.

Exam trap

Cisco often tests the misconception that VLAN tagging alone can connect VNFs across different bridges, but VLANs only segment traffic within a single bridge and do not create connectivity between separate bridges.

How to eliminate wrong answers

Option A is wrong because physically cabling ports on the NFVIS host would create a loop or require external hardware, and NFVIS does not support direct physical loopback connections for internal VNF-to-VNF traffic. Option C is wrong because VLAN tagging alone does not bridge separate bridge networks; both VNFs would need to be on the same bridge with matching VLANs for Layer 2 connectivity. Option D is wrong because static routes only work if there is already a Layer 3 path between the VNFs; with different bridges, there is no connectivity at Layer 2 or Layer 3 without an intermediate router or bridge.

977
MCQmedium

An Ansible playbook uses the cisco.ios.ios_l3_interfaces module to configure an IPv4 address on GigabitEthernet0/1: ```yaml --- - name: Configure IPv4 address hosts: cisco-routers gather_facts: no tasks: - name: Set IP address cisco.ios.ios_l3_interfaces: config: - name: GigabitEthernet0/1 ipv4: - address: 10.1.1.1/24 state: merged ``` What is the effect of the 'state: merged' parameter?

A.It replaces the entire L3 configuration on the interface with only the provided address.
B.It adds the IP address to the interface, merging with any existing configuration.
C.It deletes the IP address if it exists.
D.It only checks the configuration without making changes.
AnswerB

'merged' adds the configuration to the existing one without removing other settings.

Why this answer

The 'merged' state adds the provided configuration to the existing configuration without removing any other settings. If the interface already has an IP address, it will be replaced only if the address is different; otherwise, it remains unchanged.

978
MCQeasy

What is the default OSPF reference bandwidth used for cost calculation in Cisco IOS?

A.100 Mbps
B.1000 Mbps
C.10 Mbps
D.1 Mbps
AnswerA

100 Mbps is the OSPF default reference bandwidth defined in RFC 2328, and it is used in the formula cost = reference-bandwidth / interface-bandwidth. With this default, a 100 Mbps interface has a cost of 1, and any interface faster than 100 Mbps also receives a cost of 1 because OSPF costs are integer values; this is why network administrators often raise the reference bandwidth in modern high-speed networks.

Why this answer

In Cisco IOS, the default OSPF reference bandwidth is 100 Mbps. OSPF calculates the cost of an interface as the reference bandwidth divided by the interface bandwidth. With the default reference of 100 Mbps, a FastEthernet (100 Mbps) interface gets a cost of 1, which is the minimum cost.

This default was established when FastEthernet was considered high-speed, but it can be changed using the 'auto-cost reference-bandwidth' command to accommodate faster links like GigabitEthernet.

Exam trap

Cisco often tests the default OSPF reference bandwidth as 100 Mbps, and the trap here is that candidates confuse it with the actual interface bandwidth (e.g., 10 Mbps for Ethernet) or assume it matches the fastest common link speed (e.g., 1000 Mbps for GigabitEthernet).

How to eliminate wrong answers

Option B (1000 Mbps) is wrong because 1000 Mbps is not the default; it is a common value set manually to avoid cost rounding issues on GigabitEthernet and faster interfaces. Option C (10 Mbps) is wrong because 10 Mbps is the bandwidth of an Ethernet interface, not the reference bandwidth; using 10 Mbps would make all faster links have fractional costs. Option D (1 Mbps) is wrong because 1 Mbps is the bandwidth of a legacy serial link and would result in extremely high costs for modern interfaces; the default reference bandwidth is 100 Mbps.

979
MCQmedium

Consider the following TrustSec configuration on a Cisco switch: cts role-based enforcement interface GigabitEthernet1/0/3 cts manual sap pmk 0123456789ABCDEF mode-list both What is the purpose of this configuration?

A.It enables 802.1X authentication with a pre-shared key.
B.It configures the interface to use SGT (Security Group Tag) propagation via SXP.
C.It enables CTS inline tagging with a pre-shared key for SGT exchange between peers.
D.It enables dynamic VLAN assignment based on user authentication.
AnswerC

This correctly describes the `cts manual` command with a `sap pmk` policy: manual TrustSec mode uses a pre-shared key to bring up a Security Association Protocol session. After SAP is established, the interface performs inline SGT tagging, inserting the SGT into the CMD (Cisco Meta-Data) header of each frame so the peer can enforce security-group-based policies. The pre-shared key authenticates the peer for this SGT exchange, not for user authentication.

Why this answer

The `cts manual` command with `sap pmk` and `mode-list both` configures Cisco TrustSec (CTS) inline tagging on the interface. This enables the exchange of Security Group Tags (SGTs) between directly connected peers using a pre-shared key (PSK) for authentication and encryption of the SGT metadata, without requiring 802.1X or SXP. The `mode-list both` specifies that both Layer 2 (802.1AE MACsec) and Layer 3 (SGT encapsulation) protection are used.

Exam trap

The trap here is that candidates confuse `cts manual` with SXP or 802.1X, because all three involve security group tags or authentication, but `cts manual sap` is specifically for inline tagging with a pre-shared key on a directly connected link, not for SXP propagation or 802.1X-based dynamic VLAN assignment.

How to eliminate wrong answers

Option A is wrong because this configuration does not involve 802.1X authentication; it uses a pre-shared key (PMK) for CTS inline tagging, not for 802.1X EAP or MAB. Option B is wrong because SXP (SGT Exchange Protocol) is used for propagating SGTs across non-TrustSec-capable links or routers, not for inline tagging on a directly connected interface; the `cts manual` command with `sap` is for inline tagging, not SXP. Option D is wrong because dynamic VLAN assignment is a feature of 802.1X or MAB, not of CTS inline tagging; CTS focuses on SGT-based security group access control, not VLAN changes.

980
Drag & Dropmedium

Drag and drop the steps of EIGRP stub configuration for hub-and-spoke into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In hub-and-spoke EIGRP, the spoke router is configured as a stub to limit query propagation. First, enter router configuration mode, then enable EIGRP on the spoke, configure it as a stub, optionally restrict advertised routes, and finally verify the stub status.

981
MCQeasy

A network team must design QoS for a campus network that carries voice, video, and data traffic. The design must use the DiffServ model and ensure that voice traffic is prioritized over all other traffic classes. Which DSCP marking and queuing strategy should be used for voice?

A.Mark voice with AF41 and place in a weighted fair queue.
B.Mark voice with EF and place in a strict priority queue.
C.Mark voice with CS3 and place in a low-latency queue.
D.Mark voice with BE and rely on WRED for drop precedence.
AnswerB

DiffServ uses DSCP to classify traffic. EF (46) provides low latency, low jitter and assured bandwidth for voice, and a strict priority queue services it ahead of all other classes, guaranteeing voice is prioritised over video and data.

Why this answer

Voice traffic requires strict priority to ensure minimal jitter and latency. DSCP EF (Expedited Forwarding, per RFC 3246) is the standard marking for real-time traffic like voice, and placing it in a strict priority queue (LLQ) guarantees that voice packets are serviced before any other queue, which is essential for meeting QoS requirements in a DiffServ model.

Exam trap

The trap here is that candidates often confuse AF41 (used for video) with voice marking, or assume that any low-latency queue (LLQ) works regardless of DSCP value, but Cisco specifically tests that voice must use EF and strict priority queue, not just any low-latency queue.

How to eliminate wrong answers

Option A is wrong because AF41 (Assured Forwarding class 4, low drop probability) is designed for traffic that can tolerate some delay and jitter, such as video conferencing, not for voice which needs strict priority; weighted fair queue does not provide the absolute priority required for voice. Option C is wrong because CS3 (Class Selector 3) is a legacy marking that does not guarantee low latency or strict priority; while a low-latency queue (LLQ) is correct, the DSCP marking must be EF for voice, not CS3. Option D is wrong because BE (Best Effort, DSCP 0) is the default marking for non-priority traffic, and WRED (Weighted Random Early Detection) is a congestion avoidance mechanism that drops packets before queue overflow, which is unsuitable for voice as it introduces jitter and packet loss.

982
MCQmedium

A network engineer at a logistics company is building a Python script that must retrieve the running configuration of a Cisco IOS XE router without parsing CLI screen-scraping output. The engineer wants a programmatic, model-driven interface that returns structured data over HTTPS. Which approach best satisfies this requirement?

A.Use SNMPv3 with the get-bulk operation to walk the ifTable and reconstruct the running configuration from MIB objects.
B.Use NETCONF over an SSH subsystem on TCP port 830 and parse the XML reply for the running configuration datastore.
C.Use the Cisco IOS XE CLI over a Telnet session and capture the output of 'show running-config' with a regular expression parser.
D.Use RESTCONF over HTTPS on TCP port 443 with the Accept header set to application/yang-data+json to read the configuration datastore.
AnswerD

RESTCONF is the IETF model-driven interface that maps YANG models onto HTTP methods and runs over HTTPS on TCP port 443. Setting the Accept header to application/yang-data+json tells the device to return JSON-encoded structured data rather than XML. This directly satisfies the requirement for a programmatic, model-driven interface over HTTPS without CLI screen-scraping.

Why this answer

RESTCONF is the IETF-defined protocol that exposes YANG-modeled data through HTTP methods and runs over HTTPS on port 443. By setting the Accept header to application/yang-data+json, the client receives JSON-encoded structured data instead of XML, avoiding CLI parsing entirely. NETCONF uses SSH on port 830, SNMP does not expose the configuration datastore, and Telnet screen-scraping is neither secure nor model-driven.

Exam trap

The trap here is assuming any model-driven protocol uses HTTPS, when NETCONF is actually carried as an SSH subsystem on port 830.

983
Multi-Selecthard

Which three statements about Cisco DNA Center wireless assurance are true? (Choose three.)

Select 3 answers
A.DNA Center collects telemetry from wireless controllers and access points to provide health scores for clients and APs.
B.DNA Center can be used to troubleshoot client connectivity issues by replaying historical client association events.
C.DNA Center uses synthetic test clients (sensors) to simulate client traffic and measure wireless performance.
D.DNA Center replaces the WLC for real-time client association and roaming decisions.
E.DNA Center requires a dedicated wireless LAN controller to be deployed solely for assurance data collection.
AnswersA, B, C

DNA Center's assurance engine ingests streaming telemetry from wireless controllers and access points, then computes per-client and per-AP health scores from that data. This satisfies the stem's requirement for wireless assurance: continuous monitoring and scoring rather than configuration alone, giving visibility into client experience and radio performance across the fabric.

Why this answer

Option A is correct because DNA Center's wireless assurance gathers streaming telemetry and statistics from wireless controllers and access points, then aggregates them into health scores for clients, APs, and the wireless network. Option B is correct because DNA Center retains historical client data, allowing administrators to replay past association, authentication, and roaming events to troubleshoot connectivity problems. Option C is correct because DNA Center supports synthetic test clients (sensors) that emulate real client traffic to proactively measure wireless performance such as onboarding, throughput, and latency.

Option D is not correct because client association and roaming decisions remain with the wireless LAN controller (or AP in local mode), not DNA Center, which is a management and assurance platform. Option E is not correct because DNA Center does not require a dedicated WLC solely for assurance; it collects telemetry from the existing wireless infrastructure already managed by DNA Center.

Exam trap

The trap here is confusing DNA Center's assurance role with actual control plane functions, leading candidates to believe it replaces the WLC for real-time decisions or requires dedicated hardware, when it is primarily an analytics and assurance overlay.

984
MCQmedium

A network operations center (NOC) is deploying streaming telemetry from Cisco IOS-XE devices to a Kafka-based analytics platform. The engineer needs to ensure that the telemetry data is encoded in a compact, efficient format for high-volume streaming. Which encoding format should the engineer configure?

A.Google Protocol Buffers (GPB) encoding.
B.JSON encoding.
C.XML encoding.
D.CSV encoding.
AnswerA

GPB (Google Protocol Buffers) is a binary, schema-based serialization format that produces compact payloads, drastically reducing bandwidth and CPU overhead compared to text encodings. Its generated codecs and native support in gRPC make it the standard choice for high-volume, model-driven streaming telemetry on Cisco platforms. Because the schema is defined in .proto files and tied to YANG models, decoding is fast and unambiguous, even under sustained telemetry rates.

Why this answer

Google Protocol Buffers (GPB) is the correct encoding because it provides a compact, binary serialization format that minimizes bandwidth and CPU overhead, making it ideal for high-volume streaming telemetry. Cisco IOS-XE devices support GPB encoding natively for model-driven telemetry, allowing efficient data transmission to analytics platforms like Kafka.

Exam trap

Cisco often tests the misconception that JSON is the default or most efficient encoding for telemetry, but the trap here is that GPB is specifically designed for compact, high-volume streaming and is the recommended format for production-scale deployments.

How to eliminate wrong answers

Option B is wrong because JSON encoding is text-based and verbose, leading to larger payload sizes and higher CPU usage for parsing, which is inefficient for high-volume streaming. Option C is wrong because XML encoding is even more verbose than JSON, with significant overhead from tags and attributes, making it unsuitable for compact, high-throughput telemetry. Option D is wrong because CSV encoding lacks structure for nested or hierarchical telemetry data and is not a standard encoding for model-driven telemetry streams.

985
MCQmedium

A network engineer runs the following command on a Cisco WLC: WLC# show client summary Client MAC Address AP Name WLAN State Protocol RSSI SNR 00:11:22:33:44:55 AP-1 1 Run 802.11ac -65 25 00:11:22:33:44:66 AP-2 2 Run 802.11n -70 20 00:11:22:33:44:77 AP-1 1 Run 802.11ac -60 30 00:11:22:33:44:88 AP-3 3 Probe 802.11ax -75 15 Based on this output, what can be concluded?

A.All clients are fully associated and passing traffic.
B.The client with MAC 00:11:22:33:44:88 is attempting to associate but is not yet connected.
C.The client with MAC 00:11:22:33:44:55 has the best signal strength.
D.All clients are using 802.11ac or higher.
AnswerB

The client with MAC 00:11:22:33:44:88 is in Probe state, which means it has transmitted probe requests and is listening for probe responses from potential APs. It has not yet performed 802.11 authentication or association, so it is effectively attempting to connect but is not an associated client and cannot exchange data traffic. This precisely matches the correct statement: it is trying to associate but is not yet connected.

Why this answer

The client with MAC 00:11:22:33:44:88 is in the 'Probe' state, which indicates it has sent a probe request and is attempting to associate with the WLC, but it has not yet completed the association process or transitioned to the 'Run' state. Only clients in the 'Run' state are fully associated and passing traffic, making option B correct.

Exam trap

Cisco often tests the misinterpretation of RSSI values, where candidates mistakenly think a more negative RSSI (e.g., -65 dBm) is stronger than a less negative one (e.g., -60 dBm), or they overlook the client state column and assume all listed clients are actively passing traffic.

How to eliminate wrong answers

Option A is wrong because the client with MAC 00:11:22:33:44:88 is in the 'Probe' state, not 'Run', so not all clients are fully associated and passing traffic. Option C is wrong because the client with MAC 00:11:22:33:44:77 has an RSSI of -60 dBm, which is higher (less negative) than the -65 dBm of 00:11:22:33:44:55, making it the client with the best signal strength. Option D is wrong because the client with MAC 00:11:22:33:44:66 is using 802.11n, which is not 802.11ac or higher (802.11ac and 802.11ax are higher, but 802.11n is an older standard).

986
MCQeasy

A network engineer is configuring a Cisco Catalyst switch to mitigate VLAN hopping attacks. The switch has multiple access ports assigned to VLAN 10 and trunk ports connecting to other switches. The engineer wants to ensure that an attacker cannot send double-tagged frames to hop into another VLAN. Which action should the engineer take on all access ports?

A.Configure the access ports with the switchport mode access command and enable BPDU Guard.
B.Configure the access ports with the switchport mode trunk command and set the native VLAN to an unused VLAN.
C.Configure the access ports with the switchport mode access command and disable Dynamic Trunking Protocol (DTP) on them.
D.Configure the access ports with the switchport mode access command and assign them to the native VLAN.
AnswerC

Setting access ports to access mode and disabling DTP prevents the port from negotiating a trunk, which is a primary vector for VLAN hopping attacks. Attackers can exploit DTP to form a trunk and gain access to all VLANs. By explicitly configuring the port as access and disabling DTP with 'switchport nonegotiate', the port will not trunk. This is a recommended best practice.

Why this answer

To mitigate VLAN hopping, access ports should be explicitly configured as access ports and DTP should be disabled to prevent trunk negotiation. Attackers can use DTP to negotiate a trunk and then send tagged frames to access other VLANs. Disabling DTP with 'switchport nonegotiate' on access ports prevents this.

The other options either do not address the attack or are misconfigurations.

Exam trap

The trap here is thinking that BPDU Guard or native VLAN changes on access ports prevent VLAN hopping, when the primary mitigation is disabling DTP and forcing access mode.

987
Matchingmedium

Drag and drop each STP timer on the left to its matching default value on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

2 seconds

15 seconds

20 seconds

Why these pairings

Hello timer defaults to 2 seconds; Forward delay defaults to 15 seconds; Max age defaults to 20 seconds.

988
Multi-Selecthard

Which three statements about Cisco SD-Access policy enforcement are true? (Choose three.)

Select 3 answers
A.Policy enforcement in SD-Access is based on Scalable Group Tags (SGTs) assigned to endpoints.
B.Cisco ISE is used to define and manage SGT-to-policy mappings in the SD-Access fabric.
C.The fabric border node enforces all intra-fabric policies between different virtual networks.
D.The SGT information is carried in the VXLAN header using the Group Policy Option (GPO).
E.The underlay network devices must be aware of SGTs to forward traffic correctly.
AnswersA, B, D

SD-Access enforces group-based policy using SGTs applied to endpoints, rather than traditional IP-based ACLs. This satisfies the stem by naming the actual tagging mechanism that the fabric's policy plane relies on for segmentation and contract enforcement between scalable groups.

Why this answer

Option A is correct because SD-Access group-based policy enforcement relies on Scalable Group Tags (SGTs) that are assigned to endpoints (statically or dynamically via Cisco ISE), and these tags are the basis for permitting or denying traffic between groups rather than relying solely on IP addresses. Option B is correct because Cisco Identity Services Engine (ISE) is the policy controller in SD-Access: it defines SGTs, maintains the SGT-to-policy mappings (group-based access control contracts), and distributes that policy information to the fabric control plane nodes. Option D is correct because in the SD-Access VXLAN data plane the SGT is carried in the VXLAN-GPO (Group Policy Option) header field, allowing the egress fabric edge node to enforce policy based on the source group tag without the underlay needing to inspect the packet.

Option C is not correct because intra-fabric policy enforcement between endpoints in different virtual networks is performed by the fabric edge nodes (with the SGT carried in VXLAN-GPO), not by the border node, which primarily handles external connectivity and VRF-aware handoff. Option E is not correct because the underlay network only provides IP reachability between fabric nodes; it does not need to be aware of SGTs, since SGT-based policy is enforced at the fabric edge in the overlay.

Exam trap

350-401 often tests the misconception that the underlay must be SGT-aware or that the border node enforces all intra-fabric policy, when in fact SGTs are carried in the VXLAN overlay and enforcement occurs at the fabric edge.

989
MCQmedium

A network engineer is configuring a Cisco IOS router to support VRF-lite for a customer. The engineer creates a VRF named CUST_A and assigns an interface to it using the command ip vrf forwarding CUST_A. After assigning the interface, the engineer notices that the interface IP address is removed. Which action must the engineer take to restore connectivity?

A.Reapply the IP address to the interface after assigning it to the VRF.
B.Configure a global IP address and then assign the interface to the VRF.
C.Enable OSPF within the VRF to automatically restore the IP address.
D.Remove the VRF from the interface and then reassign it to reset the IP address.
AnswerA

When an interface is assigned to a VRF using the ip vrf forwarding command, any existing IP address is removed because the interface's IP address is now part of the VRF's routing table. The engineer must re-enter the IP address configuration after the VRF assignment. This is a common operational step when configuring VRF-lite.

Why this answer

Assigning an interface to a VRF with ip vrf forwarding removes any existing IP address because the interface's addressing is now scoped to the VRF. The engineer must reapply the IP address after the VRF assignment. This is a standard step in VRF-lite configuration.

The other options either suggest incorrect order or misunderstand the behavior of VRF assignment.

Exam trap

The trap here is assuming that the IP address remains configured when an interface is assigned to a VRF, when in fact it is removed and must be reconfigured.

990
MCQmedium

Examine the following configuration snippet: ip pim send-rp-announce Loopback0 scope 10 group-list 10 ip pim send-rp-discovery scope 10 access-list 10 permit 239.0.0.0 0.255.255.255 ! interface Loopback0 ip address 192.168.0.1 255.255.255.255 ip pim sparse-mode ! What is the purpose of this configuration?

A.The router will act as both a candidate RP for groups 239.0.0.0/8 and a mapping agent for Auto-RP within a scope of 10 hops.
B.The router will only act as a mapping agent and will not advertise itself as an RP.
C.The router will use the IP address of GigabitEthernet0/0 as the RP address.
D.The router will only accept RP announcements from other routers within 10 hops.
AnswerA

The configuration combines both Auto-RP roles: the router is a candidate RP because it announces itself for the 239.0.0.0/8 group range, and it is also the RP-mapping agent because it sends RP-discovery messages. The 'scope 10' parameter limits the TTL of these Auto-RP messages to 10 hops, controlling how far the announcements and discovery messages propagate.

Why this answer

The configuration enables Auto-RP, where the `ip pim send-rp-announce` command designates the router as a candidate RP for the multicast group range 239.0.0.0/8 (permitted by access-list 10), using Loopback0's IP address (192.168.0.1) as the RP address. The `ip pim send-rp-discovery` command makes the router act as the mapping agent, distributing RP-to-group mappings via Auto-RP discovery messages within a scope of 10 hops. Together, these commands fulfill both roles: candidate RP and mapping agent.

Exam trap

Cisco often tests the distinction between the roles of candidate RP and mapping agent in Auto-RP, and the trap here is that candidates assume a router configured with `send-rp-announce` is only a candidate RP and cannot also be the mapping agent, but both roles can coexist on the same router.

How to eliminate wrong answers

Option B is wrong because the `ip pim send-rp-announce` command explicitly configures the router to advertise itself as a candidate RP, so it does not act solely as a mapping agent. Option C is wrong because the `ip pim send-rp-announce Loopback0` command specifies Loopback0 as the source interface for the RP address, not GigabitEthernet0/0; the RP address is taken from the interface's IP address (192.168.0.1). Option D is wrong because the `scope 10` on the `ip pim send-rp-discovery` command limits the propagation of discovery messages to 10 hops, not the acceptance of RP announcements; the router as a mapping agent receives announcements from any candidate RP within the PIM domain, and the scope only restricts how far its own discovery messages travel.

991
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor a campus network. The administrator notices that a specific client device is experiencing poor performance. Which feature in DNA Center Assurance provides a detailed timeline of events, including onboarding, authentication, and application usage for a specific client?

A.Path Trace
B.Client 360
C.Application Health dashboard
D.Network Health dashboard
AnswerB

Client 360 is a feature in Cisco DNA Center Assurance that provides a comprehensive view of a specific client device. It includes a detailed timeline of events such as onboarding, authentication, DHCP, DNS, and application usage. This allows administrators to troubleshoot client-specific issues by correlating events over time. It is the correct tool for this scenario because it gives a holistic view of the client's network experience.

Why this answer

Client 360 in Cisco DNA Center Assurance provides a holistic view of a specific client, including a detailed timeline of onboarding, authentication, DHCP, DNS, and application usage. This is essential for troubleshooting client-specific performance issues because it correlates all relevant events in one place. The other options provide broader infrastructure or application views but lack the per-client event timeline needed here.

Exam trap

The trap here is confusing Client 360 with Path Trace; Path Trace shows the network path but not the client's event timeline.

992
MCQmedium

Examine the following Python script that uses the netmiko library to send configuration commands to a Cisco IOS-XE device: ```python from netmiko import ConnectHandler device = { 'device_type': 'cisco_ios', 'ip': '192.168.1.1', 'username': 'admin', 'password': 'cisco', } connection = ConnectHandler(**device) config_commands = [ 'interface GigabitEthernet1/0/1', 'description Link to Core', 'ip address 10.1.1.1 255.255.255.0', 'no shutdown' ] output = connection.send_config_set(config_commands) print(output) connection.disconnect() ``` What is the purpose of this script?

A.It retrieves the running configuration of the device.
B.It configures interface GigabitEthernet1/0/1 with a description, IP address, and enables it.
C.It saves the configuration to the startup configuration.
D.It tests connectivity to the device using ping.
AnswerB

The script passes a list of interface-level commands to `send_config_set()`, which enters global configuration mode and applies each line in sequence. This sets the description, assigns 10.1.1.1/24, and issues `no shutdown`, satisfying the stem's requirement to configure and enable GigabitEthernet1/0/1 on the IOS-XE device.

Why this answer

The script uses Netmiko's `send_config_set()` method to push a list of configuration commands to the device. The commands configure interface GigabitEthernet1/0/1 with a description, assign an IP address, and issue `no shutdown` to enable the interface. This matches option B exactly.

Exam trap

Cisco often tests the distinction between `send_command()` (for show commands) and `send_config_set()` (for configuration commands), leading candidates to mistakenly think the script retrieves the running config when it actually applies changes.

How to eliminate wrong answers

Option A is wrong because `send_config_set()` sends configuration commands, not retrieval commands like `show running-config`. Option C is wrong because the script does not include a `save` or `write memory` command; it only applies the configuration changes to the running config. Option D is wrong because the script uses Netmiko to send CLI commands, not to perform ICMP ping tests; there is no ping function or connectivity test involved.

993
MCQmedium

A network engineer is deploying Cisco TrustSec in a campus network. The security team requires that the Security Group Tag (SGT) be carried inside the Ethernet frame so that switches in the path can enforce group-based policy without inline tagging. Which Cisco-proprietary protocol should be enabled on the uplinks between the access and distribution switches to achieve this?

A.Layer 2 Tunneling Protocol (L2TP)
B.Cisco TrustSec CMD (Cisco Meta Data)
C.802.1AE MACsec
D.Cisco TrustSec SXP
AnswerB

Cisco Meta Data (CMD) is the TrustSec inline tagging mechanism that inserts the SGT into a reserved field of the Ethernet frame. Enabling CMD on the inter-switch uplinks allows each hop to read the tag and apply Security Group ACLs without re-classifying based on IP address, which is exactly the inline tagging behaviour the scenario requires.

Why this answer

Inline SGT tagging between TrustSec-capable switches is accomplished with Cisco Meta Data, which places the Security Group Tag into the Ethernet frame so each hop can enforce Security Group ACLs. MACsec provides encryption rather than tag transport, SXP propagates IP-to-SGT mappings across non-TrustSec hops, and L2TP is unrelated to TrustSec tagging.

Exam trap

The trap here is assuming that any Layer 2 security feature on the uplink, such as MACsec, will also carry the SGT for TrustSec policy enforcement.

994
MCQhard

A network engineer is configuring PIM sparse mode in a network that uses a Bootstrap Router (BSR) for RP discovery. The engineer has configured a candidate BSR and candidate RPs. However, some routers in the network are not learning the RP set. The engineer checks the BSR and sees that it is receiving candidate RP advertisements, but the BSR messages are not being forwarded to all routers. What is the most likely cause?

A.PIM is not enabled on all interfaces between the BSR and the other routers.
B.The candidate BSR priority is set too low.
C.The candidate RPs are not in the same OSPF area as the BSR.
D.The BSR is not configured as a candidate RP.
AnswerA

BSR messages are PIM protocol packets forwarded hop by hop, so every transit interface between the BSR and downstream routers must have PIM enabled. Without PIM on those links, the bootstrap messages are dropped and routers never receive the RP set, even though the BSR itself receives candidate RP advertisements.

Why this answer

BSR messages are PIM protocol messages that must traverse every router between the BSR and the receivers. If PIM is not enabled on all transit interfaces, those routers will not forward BSR messages, so downstream routers never learn the RP set. Enabling PIM on all relevant interfaces restores BSR flooding and RP discovery.

Exam trap

350-401 often tests whether candidates blame BSR priority or OSPF area mismatches when the real issue is that PIM must be enabled on every transit interface for BSR messages to flood correctly.

How to eliminate wrong answers

Option B is wrong because BSR priority only affects which candidate becomes the BSR; a low priority would mean another router is elected, but it would not prevent BSR messages from being forwarded if PIM is enabled everywhere. Option C is wrong because BSR and RP discovery are PIM-level functions that do not require the candidate RPs to be in the same OSPF area as the BSR, as long as unicast reachability exists. Option D is wrong because the BSR does not need to be a candidate RP; these are independent roles, and the question states candidate RPs are already configured.

995
Drag & Dropmedium

Drag and drop the steps of deploying a virtual router as a VNF into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Deploying a virtual router VNF starts with uploading the image, then creating the VM, attaching virtual interfaces, configuring routing protocols, and finally verifying connectivity.

996
Drag & Dropmedium

Drag and drop the steps of AAA accounting for command logging setup into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

AAA accounting for commands requires first enabling AAA globally, then defining an accounting method list for commands. The method list is applied to a line (e.g., vty or console). The device then sends command logs to the accounting server, which records them.

997
Multi-Selectmedium

A network engineer is designing a Python script to automate configuration changes on a fleet of Cisco IOS XE devices using the NETCONF protocol. The script must ensure that changes are atomic and that the device validates the configuration before committing. Which two NETCONF capabilities must the script check for during the capability exchange to guarantee these requirements? (Choose two.)

Select 2 answers
A.urn:ietf:params:netconf:capability:candidate:1.0
B.urn:ietf:params:netconf:capability:startup:1.0
C.urn:ietf:params:netconf:capability:rollback-on-error:1.0
D.urn:ietf:params:netconf:capability:validate:1.0
E.urn:ietf:params:netconf:capability:writable-running:1.0
AnswersA, D

The candidate capability allows the script to edit the candidate datastore, validate changes, and commit them atomically. Without it, direct edits to the running datastore may not support rollback or validation, violating the atomicity requirement. Checking for this capability ensures the device supports the candidate configuration workflow.

Why this answer

To ensure atomic changes and pre-commit validation, the script must use the candidate datastore and the validate capability. The candidate capability allows editing a separate configuration, validating it, and committing atomically. The validate capability provides the <validate> RPC to check the candidate before commit.

Together, they satisfy both requirements; other capabilities do not provide both atomicity and validation.

Exam trap

The trap here is assuming that rollback-on-error alone guarantees atomicity and validation, but it only handles errors after commit and does not validate beforehand.

998
MCQmedium

A network engineer has configured a Cisco IOS IP SLA operation using ICMP echo to monitor reachability to a remote branch router. The engineer wants to correlate the results with syslog messages and SNMP traps to detect when the branch becomes unreachable. Which IP SLA configuration step is required to generate these notifications?

A.Configure the ip sla monitor operation with the tag command to enable logging.
B.Enable IP SLA responder on the remote branch router and configure the operation to use the responder.
C.Configure an IP SLA reaction with a threshold and an action such as logging or SNMP trap.
D.Configure the ip sla schedule command with the life forever option to ensure continuous monitoring.
AnswerC

This is correct because IP SLA reactions define what happens when a monitored threshold is breached. By specifying a reaction condition (e.g., timeout) and an action (e.g., logging, SNMP trap), the device generates syslog messages and SNMP traps when the SLA operation fails or exceeds the threshold. This directly enables correlation with monitoring systems.

Why this answer

To generate syslog messages and SNMP traps based on IP SLA results, you must configure a reaction that specifies a threshold and an action. The reaction monitors the operation's return code or metrics and triggers the defined action when the condition is met. Without a reaction, the operation collects data silently, and no notifications are sent.

Exam trap

The trap here is assuming that scheduling an IP SLA operation or using a responder automatically generates alerts, when in fact reactions are required to produce notifications.

999
MCQeasy

An enterprise is deploying Cisco SD-WAN with multiple vSmart controllers for redundancy. The engineer configures the vEdge routers to connect to two vSmart controllers. After deployment, the engineer notices that the vEdge routers are only connected to one vSmart, and the second vSmart is not being used. The vEdge routers show that the second vSmart is reachable. What is the most likely reason for this behavior?

A.The vEdge routers are designed to use only one vSmart at a time; the second is for redundancy.
B.The vEdge routers can only connect to one vSmart at a time.
C.The vEdge routers need to be rebooted to establish a connection to the second vSmart.
D.The second vSmart has a different site ID than the first.
AnswerA

The vEdge router is designed to establish an OMP session with a single active vSmart controller at any given time, while concurrently maintaining DTLS/TLS tunnels to additional vSmart controllers for redundancy. The active vSmart processes all route exchanges and policy decisions; the backup vSmart remains in a standby state, ready to assume control automatically if the active vSmart fails. This active/standby model ensures control-plane continuity without requiring manual intervention or reboots.

Why this answer

In Cisco SD-WAN, vEdge routers are designed to establish a control connection to only one active vSmart controller at a time, even when multiple vSmart controllers are configured for redundancy. The second vSmart serves as a standby; the vEdge will fail over to it only if the primary vSmart becomes unreachable. Since the vEdge shows the second vSmart is reachable but not actively used, this confirms the expected behavior of active/standby redundancy rather than load balancing.

Exam trap

Cisco often tests the misconception that multiple vSmart controllers are used for load balancing or concurrent connections, when in fact they are strictly for active/standby redundancy, and a vEdge will only ever hold one active control connection at a time.

How to eliminate wrong answers

Option B is wrong because vEdge routers can indeed be configured with multiple vSmart controllers, but they do not maintain simultaneous active connections to all of them; the design is active/standby, not concurrent. Option C is wrong because rebooting the vEdge would not force it to connect to the second vSmart; the vEdge will only switch to the standby vSmart if the primary fails, regardless of reboot. Option D is wrong because site ID is used for OMP route propagation and policy, not for determining which vSmart a vEdge connects to; vSmart selection is based on DTLS/TLS control connections and priority, not site ID.

1000
Multi-Selecthard

Which three statements about VRF route targets are true? (Choose three.)

Select 3 answers
A.Route targets are used to control which routes are imported into a VRF.
B.Route targets are used to control which routes are exported from a VRF.
C.A VRF can have multiple import and export route targets configured.
D.Route targets and route distinguishers are the same BGP attribute.
E.Route targets are only used in MPLS VPN and not in VRF-lite.
AnswersA, B, C

Import route targets are attached to VRFs; when MP-BGP receives a VPNv4 route, the route target extended community is matched against the VRF's import list, determining whether that route enters the VRF's routing table. This satisfies the constraint of controlling route import.

Why this answer

Option A is correct because route targets (RTs) are extended BGP community attributes attached to VPNv4/VPNv6 routes that determine which routes a VRF imports into its routing table, based on matching the VRF's import RT list. Option B is correct because the export RT attached to a VRF's routes identifies which remote VRFs are allowed to import those routes, thereby controlling which routes leave the VRF into the MP-BGP VPN table. Option C is correct because IOS/IOS-XE and similar platforms allow multiple import and export RTs per VRF (e.g., 'route-target import 65000:1' and 'route-target export 65000:2' can be repeated), enabling complex many-to-many VPN topologies.

Option D is incorrect because the route distinguisher (RD) is an 8-byte field prepended to the IPv4 prefix to make it unique in the VPNv4 address family, while the route target is an extended community used for import/export policy — they are distinct BGP attributes with different functions. Option E is incorrect because route targets are also used in VRF-lite deployments (typically with MP-BGP between PE routers) to control route import/export between VRFs, not exclusively in MPLS VPNs.

Exam trap

The trap is conflating route targets with route distinguishers — candidates assume they are the same BGP attribute because both are used in MPLS VPNs, but RD makes prefixes unique while RT controls import/export policy.

1001
MCQmedium

A network engineer is troubleshooting OSPF adjacency issues between two routers connected via a Gigabit Ethernet link. The engineer notices that the routers are stuck in the EXSTART state. Both routers have the same MTU of 1500 bytes. What is the most likely cause of this issue?

A.The OSPF network type is point-to-point on one router and broadcast on the other.
B.The OSPF hello and dead intervals are mismatched.
C.One router has a lower IP MTU configured on the interface, causing the DBD packet to be dropped.
D.The OSPF router IDs are the same.
AnswerC

In the EXSTART state, OSPF routers exchange Database Description (DBD) packets to negotiate the master/slave relationship and begin advertising their link-state databases. DBD packets are often the largest OSPF packets sent, and if one router has a lower interface IP MTU, the DBD packet may exceed that MTU and be silently dropped by the receiving router's IP stack. Because the DBD packet never arrives, the routers cannot complete the master/slave negotiation and remain stuck in EXSTART indefinitely. This is a textbook symptom of an MTU mismatch on the OSPF interface.

Why this answer

When OSPF routers are stuck in the EXSTART state, it typically indicates a problem with the Database Description (DBD) packet exchange. Even though both routers have the same configured MTU of 1500 bytes, one router may have a lower IP MTU on its interface (e.g., due to a different interface MTU or encapsulation overhead), causing the DBD packet to be fragmented or dropped. Since OSPF DBD packets are not fragmented, a mismatch in the actual IP MTU prevents the adjacency from progressing beyond EXSTART.

Exam trap

Cisco often tests the nuance that the configured MTU (e.g., 1500 bytes) may not equal the actual IP MTU due to overhead from encapsulation or interface settings, leading to DBD packet drops and a stuck EXSTART state.

How to eliminate wrong answers

Option A is wrong because mismatched OSPF network types (e.g., point-to-point vs. broadcast) would cause the routers to get stuck in the INIT or 2-WAY state, not EXSTART; the DBD exchange process is not even reached. Option B is wrong because mismatched hello and dead intervals prevent the routers from forming a neighbor relationship at all, leaving them stuck in the DOWN or INIT state, not EXSTART. Option D is wrong because duplicate OSPF router IDs would cause a conflict that prevents adjacency formation, typically resulting in a state of DOWN or INIT, not EXSTART.

1002
MCQmedium

A network engineer runs the following command on Router R6: R6# show ip dhcp conflict IP address Detection method Detection time VRF 10.0.0.10 Ping Mar 01 2025 10:00 AM default 10.0.0.15 Gratuitous ARP Mar 01 2025 10:05 AM default Based on this output, what can be concluded?

A.The DHCP server has successfully assigned these addresses to clients.
B.The addresses 10.0.0.10 and 10.0.0.15 are unavailable for DHCP assignment.
C.The DHCP server uses only ping to detect conflicts.
D.The conflicts were caused by the DHCP server itself.
AnswerB

When an address is logged as a conflict, the DHCP server removes it from the normal allocation pool and will not offer it in future DISCOVER messages until the conflict is explicitly cleared. Both 10.0.0.10 and 10.0.0.15 remain in this conflicted state, making them permanently unavailable for DHCP assignment unless an administrator runs 'clear ip dhcp conflict' or removes the entries. This exclusion prevents the server from duplicating addresses already in use elsewhere.

Why this answer

The output shows two IP addresses that have been detected as conflicting with other devices on the network. When a DHCP server detects a conflict (via ping or gratuitous ARP), it marks those addresses as unavailable and will not assign them to new clients. Therefore, 10.0.0.10 and 10.0.0.15 are excluded from the DHCP pool until the conflicts are cleared by an administrator.

Exam trap

Cisco often tests the misconception that a DHCP conflict log shows successfully assigned addresses, when in fact it shows addresses that the server detected as already in use and therefore excluded from assignment.

How to eliminate wrong answers

Option A is wrong because the DHCP conflict log indicates that these addresses were involved in a conflict, meaning they were not successfully assigned to clients; instead, the server detected another device already using the address. Option C is wrong because the output shows two different detection methods: Ping and Gratuitous ARP, proving the DHCP server uses both methods to detect conflicts, not only ping. Option D is wrong because the conflicts were detected by the DHCP server via external probes (ping and gratuitous ARP), but the conflicts themselves are typically caused by another device on the network using the same IP address, not by the DHCP server itself.

1003
MCQeasy

A network administrator is deploying a Cisco Wireless LAN Controller (WLC) and access points in a branch office. The administrator wants to ensure that all management traffic between the WLC and APs is encrypted and that APs can discover the WLC across a Layer 3 network. Which protocol should be used for AP-to-WLC communication?

A.SNMPv3 with AES encryption for AP management and discovery.
B.LWAPP with IPsec encryption between AP and WLC.
C.Mobility Express with HTTPS management and no CAPWAP tunnel.
D.CAPWAP with DTLS encryption enabled on the management interface.
AnswerD

CAPWAP (Control and Provisioning of Wireless Access Points) is the standard protocol for AP-to-WLC communication. It uses DTLS to encrypt control and data traffic, and it supports Layer 3 discovery via broadcast, DHCP option 43, or DNS. Enabling DTLS ensures management traffic is encrypted, and CAPWAP operates across Layer 3 networks, satisfying both requirements.

Why this answer

CAPWAP is the current protocol for AP-to-WLC communication, and it supports DTLS encryption for control and data traffic. It also enables Layer 3 discovery through options like DHCP option 43 or DNS. LWAPP is deprecated, Mobility Express is for controller-less setups, and SNMPv3 is for management polling, not AP tunneling.

Therefore, CAPWAP with DTLS is the correct choice.

Exam trap

The trap here is selecting LWAPP because it sounds similar, but it is an older protocol that lacks native DTLS encryption and is not used in modern deployments.

1004
MCQhard

An engineer configures model-driven telemetry on a Cisco IOS-XE device with the following gRPC dial-out configuration: ``` telemetry ietf subscription 101 encoding encode-kvgpb filter xpath /interfaces/interface/state/counters source-address 10.1.1.1 stream yang-push update-policy periodic 500 receiver ip address 10.2.2.2 50001 protocol grpc-tcp ``` What is the purpose of the 'encoding encode-kvgpb' command?

A.It sets the encoding to JSON format for human readability.
B.It specifies that the data should be encoded using the Key-Value Google Protocol Buffers format.
C.It enables compression of the telemetry data.
D.It sets the encoding to XML format.
AnswerB

Key-Value GPB encoding serialises each telemetry field as a key-value pair within a compact protobuf message, which the gRPC-TCP receiver at 10.2.2.2:50001 decodes natively. This satisfies the dial-out subscription's requirement for efficient, structured streaming of the periodic 500-centisecond interface counter data over gRPC.

Why this answer

The command 'encoding encode-kvgpb' explicitly sets the telemetry data encoding to Key-Value Google Protocol Buffers (kvGPB). This is a compact, efficient binary format that maps YANG leaf paths to key-value pairs, optimized for high-frequency streaming telemetry over gRPC. It is not JSON, XML, or a compression mechanism; it is a specific serialization format defined for model-driven telemetry on Cisco IOS-XE.

Exam trap

The trap here is confusing encoding formats with compression or assuming that 'kvgpb' stands for something else; candidates might pick JSON or XML due to familiarity, but the exam tests precise knowledge of telemetry encoding keywords.

How to eliminate wrong answers

Option A is wrong because JSON encoding would be specified with 'encoding encode-json' or similar, not 'encode-kvgpb'; kvGPB is binary and not human-readable. Option C is wrong because 'encode-kvgpb' does not enable compression; compression would be a separate setting or inherent to gRPC, but this command solely defines the data encoding format. Option D is wrong because XML encoding would be indicated by 'encoding encode-xml' or similar; kvGPB is a binary protocol buffers variant, not XML.

1005
MCQeasy

A company is deploying Cisco DNA Center and wants to use streaming telemetry from its network devices to provide real-time visibility. The network consists of Cisco Catalyst 9000 switches running IOS-XE. The engineer needs to configure the devices to stream telemetry data to DNA Center. Which protocol should the engineer use for the telemetry transport?

A.gRPC (Google Remote Procedure Call).
B.NetFlow v9.
C.SNMPv3.
D.Syslog.
AnswerA

gRPC (Google Remote Procedure Call) is the correct answer because Cisco DNA Center leverages model-driven telemetry, and gRPC is the standard transport for that telemetry. It uses protocol buffers to encode structured YANG data and supports high-frequency, push-based subscriptions over HTTP/2. This allows DNA Center to stream interface counters, CPU/memory utilization, and other operational state from devices in near real-time, eliminating the need for repeated polling.

Why this answer

Cisco DNA Center uses gRPC (Google Remote Procedure Call) as the transport protocol for model-driven telemetry from IOS-XE devices like the Catalyst 9000 series. gRPC leverages HTTP/2 and Protocol Buffers to efficiently stream structured YANG-modeled data, providing the real-time visibility required by DNA Center. This is the standard method for streaming telemetry in modern Cisco SD-Access and intent-based networking architectures.

Exam trap

Cisco often tests the distinction between legacy monitoring protocols (NetFlow, SNMP, Syslog) and modern model-driven telemetry, so the trap here is that candidates may confuse NetFlow v9 (a flow export protocol) with streaming telemetry, or assume SNMPv3 is sufficient for real-time visibility, when in fact gRPC is the required transport for DNA Center's telemetry pipeline.

How to eliminate wrong answers

Option B (NetFlow v9) is wrong because NetFlow is a flow-based accounting and monitoring protocol, not a streaming telemetry transport; it exports flow records (e.g., IP, ports) rather than structured YANG-modeled operational data, and DNA Center does not use NetFlow for real-time device telemetry. Option C (SNMPv3) is wrong because SNMP is a poll-based protocol that uses a request-response model (GET/SET/TRAP), which is inefficient for high-frequency, real-time streaming; it lacks the push-based, subscription-driven architecture of gRPC telemetry. Option D (Syslog) is wrong because Syslog is a text-based logging protocol for event messages (e.g., errors, warnings), not a structured telemetry transport; it cannot stream granular, high-frequency operational state data like interface counters or CPU utilization in a machine-readable format.

1006
MCQmedium

Which IP SLA operation type requires an IP SLA responder to be configured on the target device?

A.ICMP echo
B.UDP jitter
C.TCP connect
D.HTTP get
AnswerB

UDP jitter is designed to assess network performance by sending multiple UDP packets and computing latency, jitter, and packet loss. It requires an IP SLA responder on the far end because the responder must embed precise transmit and receive timestamps into each packet and return them to the source. Without the responder, the destination would not process the IP SLA control messages or generate the timestamped reply packets, making accurate jitter measurements impossible.

Why this answer

UDP jitter (option B) is the correct answer because it is the only IP SLA operation type among the options that requires a dedicated IP SLA responder on the target device. The responder is necessary to generate accurate timestamps for one-way delay, jitter, and packet loss measurements, as the UDP jitter operation sends a configurable number of UDP packets and expects the responder to return precise timing information. Without the responder, the target device would not process the packets in a way that yields meaningful jitter statistics.

Exam trap

Cisco often tests the misconception that ICMP echo (option A) requires a responder because it is a common monitoring tool, but in reality, ICMP echo works with any standard IP host and does not need the IP SLA responder feature.

How to eliminate wrong answers

Option A is wrong because ICMP echo uses standard ICMP echo requests and replies, which any IP-enabled device can respond to without an IP SLA responder; the source router handles all timing locally. Option C is wrong because TCP connect only tests the ability to establish a TCP three-way handshake to a specified port, and the target device's normal TCP stack handles the connection without needing an IP SLA responder. Option D is wrong because HTTP get sends an HTTP request to a web server and measures the response time; the web server processes the request natively, and no IP SLA responder is required.

1007
MCQhard

A network engineer is configuring a Zone-Based Firewall on a Cisco IOS XE router. The design requires that traffic from the inside zone to the outside zone be inspected, that return traffic be permitted, and that traffic from the outside zone to the inside zone be dropped unless it matches an existing session. Which configuration element is required to achieve this behavior?

A.A class map that matches on the outside interface and an ACL that permits established sessions
B.A zone pair with a service policy that applies inspect to inside-to-outside traffic
C.A policy map with the pass action applied to the outside-to-inside zone pair
D.A zone pair with a service policy that applies drop to the outside-to-inside zone pair
AnswerB

Zone-Based Firewall uses zone pairs to define directional policy between zones. Applying a service policy with the inspect action on the inside-to-outside zone pair creates stateful inspection, so return traffic from the outside zone is automatically permitted. Without this inspect action, the router treats the zones as separate and return traffic would be dropped by the default inter-zone deny.

Why this answer

Zone-Based Firewall policies are applied to zone pairs and are directional. Inspecting traffic from the inside zone to the outside zone creates session state, which allows return traffic from outside to inside automatically. Without the inspect action on that zone pair, the default inter-zone deny would block return traffic, so the inspect policy is the essential element.

Exam trap

The trap here is thinking that a drop policy on the outside-to-inside zone pair is needed, when in ZBF the inspect action on the reverse direction handles return traffic automatically.

1008
MCQmedium

A network engineer is configuring a GRE tunnel between two sites to transport IPv6 traffic over an IPv4-only underlay. The engineer wants to ensure that the tunnel interface supports IPv6 and that traffic is encrypted. Which technology should be combined with GRE to provide encryption?

A.IPsec in tunnel mode
B.MACsec
C.TLS
D.IPsec in transport mode
AnswerA

IPsec in tunnel mode encrypts the entire original IP packet, including the GRE header and payload, and encapsulates it within a new IPsec packet. This provides confidentiality and integrity for the GRE tunnel, making it suitable for transporting IPv6 over an IPv4 underlay securely. It is the standard method for protecting GRE tunnels.

Why this answer

To encrypt a GRE tunnel, IPsec in tunnel mode is used. It encrypts the entire original packet, including the GRE header, and encapsulates it in a new IPsec packet. This provides confidentiality and integrity for the tunneled traffic.

Transport mode does not encapsulate the original packet, MACsec is Layer 2 only, and TLS is application-layer, so they are not suitable for this scenario.

Exam trap

The trap here is confusing IPsec transport mode with tunnel mode; transport mode does not encrypt the GRE header, so it is not appropriate for protecting GRE tunnels.

1009
MCQmedium

A network engineer is deploying a new branch office switch and needs to configure a switched virtual interface (SVI) to act as the default gateway for VLAN 10. The VLAN has been created and ports have been assigned. Which additional step is required for the SVI to become operational and pass traffic?

A.Configure a physical port as a trunk and allow VLAN 10 on it.
B.Enable IP routing globally with the ip routing command.
C.Assign the SVI to a port-channel for redundancy.
D.Assign an IP address to the SVI with the interface vlan 10 command, then issue no shutdown.
AnswerD

An SVI is created with the interface vlan 10 command. To make it operational, you must assign an IP address and enable it with no shutdown. The SVI will remain down until at least one access port in VLAN 10 is up and the VLAN exists in the VLAN database. Once these conditions are met, the SVI can route traffic for the subnet.

Why this answer

An SVI requires an IP address and must be enabled with no shutdown. The VLAN must exist and have at least one active access port for the SVI to come up. Global IP routing is needed for inter-VLAN routing but does not affect the SVI's operational state.

Trunking or port-channels are unrelated to bringing up an SVI for a single VLAN.

Exam trap

The trap here is assuming that creating the VLAN and assigning ports is sufficient to bring up the SVI, but the SVI also needs an IP address and no shutdown, and at least one active port.

1010
Matchingmedium

Drag and drop each MP-BGP address family on the left to its matching use case on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Carries MPLS Layer 3 VPN routes with route distinguisher and route target

Carries standard IPv4 unicast routes (non-VPN)

Carries standard IPv6 unicast routes

Carries MPLS Layer 3 VPN routes for IPv6 customer prefixes

Carries Layer 2 VPN information such as VPLS or EVPN

Why these pairings

The VPNv4 unicast address family carries MPLS VPN routes with RD and RT; IPv4 unicast carries standard IPv4 routes; IPv6 unicast carries IPv6 routes; VPNv6 unicast carries IPv6 MPLS VPN routes; L2VPN address family carries Layer 2 VPN information like VPLS.

1011
MCQhard

A network engineer is deploying a Cisco Wireless LAN Controller (WLC) in a large campus with 500 access points. The engineer must ensure that the WLC can handle the expected client load and that APs can join the controller securely. Which protocol does the AP use to discover and join the WLC, and what is the default secure management protocol for the WLC GUI?

A.LWAPP for AP join; HTTP for WLC GUI
B.DTLS for AP join; HTTPS for WLC GUI
C.CAPWAP for AP join; HTTP for WLC GUI
D.CAPWAP for AP join; HTTPS for WLC GUI
AnswerD

Access points use CAPWAP (Control and Provisioning of Wireless Access Points) to discover and join a WLC, encapsulating control and data traffic. The WLC GUI is accessed via HTTPS by default, providing secure management. This combination meets the requirement for secure AP join and management in a large campus deployment.

Why this answer

Access points use CAPWAP to discover and join a WLC, establishing both control and data tunnels. The control channel is secured with DTLS, while the data channel may also be encrypted. The WLC GUI is accessed via HTTPS by default, ensuring secure management.

This pairing is standard for Cisco wireless deployments and satisfies the need for secure AP join and management.

Exam trap

The trap here is confusing the secure transport protocol (DTLS) with the discovery and join protocol (CAPWAP), or assuming HTTP is the default for WLC management.

1012
MCQmedium

Examine the following configuration: policy-map SHAPE_POLICY class class-default shape average 10000000 service-policy INNER_POLICY What is the purpose of the nested service-policy (service-policy INNER_POLICY) under the shape command?

A.It applies the INNER_POLICY to traffic after shaping, allowing per-class queuing within the shaped rate.
B.It applies the INNER_POLICY to traffic before shaping, which is not supported.
C.It is used to shape traffic twice, first at 10 Mbps and then again based on INNER_POLICY.
D.This configuration is invalid because service-policy cannot be nested under shape.
AnswerA

In hierarchical QoS (HQoS), the outer policy performs shaping at the parent level, and after the shaper has metered the traffic to the configured rate, the inner policy is applied to the shaped output. This allows the child policy to classify and queue traffic into multiple classes, all within the aggregate shaped bandwidth. The result is that each class gets its own queue and scheduling behavior, but the total output never exceeds the parent's shaped rate, so per-class queuing occurs inside the shaper's token bucket.

Why this answer

The nested service-policy under the shape command applies the INNER_POLICY to traffic after it has been shaped to 10 Mbps. This allows per-class queuing and scheduling within the shaped rate, enabling finer QoS control such as bandwidth allocation or priority queuing for specific traffic classes while ensuring the overall output does not exceed the shaped rate.

Exam trap

Cisco often tests the concept that a nested service-policy under shape applies after shaping, not before, and that it is a valid method for hierarchical QoS, leading candidates to incorrectly assume it is unsupported or that it shapes traffic twice.

How to eliminate wrong answers

Option B is wrong because the nested service-policy under shape is applied after shaping, not before; applying a policy before shaping would require a different configuration (e.g., a parent policy with a service-policy before the shape command). Option C is wrong because the configuration does not shape traffic twice; the shape command defines the shaping rate, and the nested policy manages queuing within that rate, not additional shaping. Option D is wrong because nesting a service-policy under shape is a valid and supported Cisco IOS QoS feature, commonly used for hierarchical QoS (HQoS).

1013
Matchingmedium

Drag and drop each IP SLA threshold type on the left to its trigger condition on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Trigger when metric exceeds threshold

Trigger on first violation

Trigger after N consecutive violations

Trigger after N violations within M probes

Do not trigger

Why these pairings

Over-threshold triggers when a metric exceeds the configured value; immediate triggers on the first violation; consecutive triggers after a specified number of consecutive violations.

1014
Drag & Dropmedium

Drag and drop the steps of SNMP bulk walk operation process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The manager initiates a GetBulkRequest, the agent responds with multiple variables, and the process repeats until all OIDs are retrieved.

1015
Multi-Selectmedium

Which three statements about SD-WAN (Cisco Catalyst SD-WAN) are true? (Choose three.)

Select 3 answers
A.The vSmart controller is responsible for distributing control plane information such as OMP routes and policies to the WAN edge routers.
B.The vBond controller is primarily used for device authentication and orchestration of initial connections.
C.The vManage controller forwards all data traffic between branch sites.
D.WAN edge routers can connect to the SD-WAN fabric using multiple transport interfaces (e.g., MPLS, Internet, LTE).
E.OMP (Overlay Management Protocol) runs between vEdge routers and the vManage controller.
AnswersA, B, D

The vSmart controller distributes OMP routes, policies and TLOC information across the overlay, satisfying the need for centralised control plane intelligence. It computes and pushes routing and policy decisions to WAN edge routers, which forward data plane traffic directly without transiting the controller.

Why this answer

Option A is correct because in Cisco Catalyst SD-WAN the vSmart controller owns the control plane: it receives OMP routes and policies from WAN edge devices, runs the route/policy decision process, and redistributes the resulting OMP routes and policies to the other WAN edge routers. Option B is correct because the vBond controller (orchestrator) performs initial device authentication and authorization, and it tells each WAN edge router how to reach the vManage and vSmart controllers so the overlay tunnels can be established. Option D is correct because a WAN edge router supports multiple WAN transport interfaces (MPLS, Internet, LTE/5G, etc.) and can build secure IPsec/GRE overlay tunnels over each, enabling application-aware path selection and transport failover.

Option C is wrong because vManage is the management/analytics plane and does not forward data-plane traffic between branches; user traffic traverses the IPsec/GRE overlay tunnels directly between WAN edge routers. Option E is wrong because OMP is a control-plane protocol that runs between WAN edge routers and the vSmart controller (over DTLS/TLS), not between WAN edge routers and vManage.

Exam trap

350-401 often tests the roles of SD-WAN controllers; candidates may incorrectly assign data forwarding to vManage or think OMP runs between vEdge and vManage, confusing the management plane with the control plane.

1016
MCQhard

An engineer is implementing a QoS policy on a Cisco IOS XE router. The requirement is to prioritize voice traffic (marked DSCP EF) and ensure that it receives strict priority scheduling with a guaranteed bandwidth of 30% of the interface capacity. Which queuing mechanism should be configured on the interface?

A.First-In, First-Out (FIFO) queuing with a rate limit for voice traffic.
B.Low Latency Queuing (LLQ) with a priority statement for the voice class.
C.Weighted Random Early Detection (WRED) with a precedence-based drop policy for voice.
D.Class-Based Weighted Fair Queuing (CBWFQ) with a bandwidth guarantee for the voice class.
AnswerB

LLQ is an extension of CBWFQ that adds a strict priority queue for delay-sensitive traffic such as voice. Configuring a priority statement for the voice class ensures that packets marked DSCP EF are dequeued first, up to the specified bandwidth (30%). This provides strict priority scheduling and guarantees bandwidth, meeting both requirements for voice traffic.

Why this answer

Low Latency Queuing (LLQ) combines the bandwidth guarantees of CBWFQ with a strict priority queue. By configuring a priority statement for the voice class, packets marked DSCP EF are placed in a low-latency queue that is serviced before other queues, ensuring minimal delay and jitter. The priority bandwidth allocation of 30% guarantees that voice traffic receives the necessary bandwidth even during congestion.

Exam trap

The trap here is assuming that CBWFQ alone can provide strict priority for voice; in reality, only LLQ (CBWFQ with a priority queue) offers strict priority scheduling.

1017
MCQhard

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router. The router runs OSPF, BGP, SSH management, and SNMP polling. After applying a CoPP policy, the administrator notices that OSPF adjacencies flap intermittently while BGP and SSH remain stable. Which action should the administrator take to resolve the flapping while maintaining control plane protection?

A.Remove the CoPP policy entirely and rely on interface ACLs for control plane protection.
B.Increase the committed information rate (CIR) for the OSPF class in the CoPP policy.
C.Apply the CoPP policy only to the BGP and SSH classes, leaving OSPF unpoliced.
D.Configure OSPF authentication to reduce the number of OSPF packets processed by the route processor.
AnswerB

OSPF hellos and LSAs are being dropped because the policer for the OSPF class is too restrictive. Increasing the CIR for that class allows more OSPF control traffic to reach the route processor, stabilizing adjacencies. This maintains protection for other protocols while addressing the specific queue that is over-policing legitimate OSPF packets during normal adjacency formation and maintenance.

Why this answer

OSPF adjacency flapping after applying CoPP indicates that the policer for the OSPF control plane class is dropping legitimate hello or LSA packets. Increasing the CIR for that class allows the required OSPF traffic to be punted to the route processor. This preserves control plane protection for other protocols while resolving the flapping, which is a common tuning step in CoPP deployments.

Exam trap

The trap here is thinking that CoPP either works or does not, when in reality each class needs to be tuned to match the protocol's legitimate traffic profile.

1018
Matchingmedium

Drag and drop each EIGRP router role on the left to its matching definition on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Next-hop router for the best route to a destination

Backup next-hop router meeting the feasibility condition

Directly connected EIGRP router exchanging Hello packets

Lowest metric to a destination from the local router

Metric advertised by a neighbor for a specific route

Why these pairings

In EIGRP, successors are the next-hop routers for the best path to a destination. Feasible successors serve as backup next-hop routers that meet the feasibility condition. Neighbors are directly connected EIGRP routers that exchange Hello packets.

Feasible Distance is the lowest metric from the local router to a destination. Reported Distance is the metric that a neighbor advertises for a specific route.

1019
MCQmedium

Examine the following configuration: interface GigabitEthernet0/0 ip address 172.16.1.1 255.255.255.0 ipv6 address 2001:db8:1::1/64 ipv6 ospf 100 area 0 ! What is missing from this configuration to enable OSPFv3 on this interface?

A.The configuration is complete; no additional commands are needed.
B.The command 'ipv6 router ospf 100' must be added globally to create the OSPFv3 process.
C.The interface needs the 'ipv6 ospf network point-to-point' command to work.
D.The 'ipv6 unicast-routing' command must be enabled globally.
AnswerB

The global command 'ipv6 router ospf 100' creates the OSPFv3 routing process with process ID 100 and enters router configuration mode. Only after this process exists can interface-level commands like 'ipv6 ospf 100 area 0' become operational. This is the missing required step, making the configuration functional and allowing the router to exchange LSAs with its neighbors.

Why this answer

OSPFv3 requires an active OSPFv3 process on the router before it can be enabled on any interface. The 'ipv6 router ospf 100' global command creates the OSPFv3 process with process ID 100, which is necessary for the interface-level 'ipv6 ospf 100 area 0' command to function. Without this global process, the interface configuration is incomplete and OSPFv3 will not operate.

Exam trap

Cisco often tests the requirement that an OSPFv3 process must be created globally with 'ipv6 router ospf <process-id>' before interface-level OSPFv3 commands will work, leading candidates to mistakenly think the interface configuration alone is sufficient.

How to eliminate wrong answers

Option A is wrong because the configuration is not complete; the OSPFv3 process must be created globally with 'ipv6 router ospf 100' for the interface command to take effect. Option C is wrong because 'ipv6 ospf network point-to-point' is an optional command used to override the default network type (e.g., broadcast) and is not required for basic OSPFv3 operation on this interface. Option D is wrong because 'ipv6 unicast-routing' enables IPv6 routing globally but is not specifically required for OSPFv3; OSPFv3 can run without it as long as IPv6 is configured, though it is commonly enabled for practical routing.

1020
MCQmedium

A network engineer is implementing QoS on a Cisco IOS router. The requirement is to classify traffic based on the DSCP value in the IP header and then mark it with a new DSCP value. Which QoS mechanism should be used to accomplish this?

A.Class-based weighted fair queueing (CBWFQ)
B.Policy-based routing (PBR)
C.Low latency queueing (LLQ)
D.Modular QoS CLI (MQC)
AnswerD

MQC is the framework for configuring QoS on Cisco IOS. It uses class-maps to classify traffic (e.g., matching DSCP) and policy-maps to define actions such as marking with a new DSCP value. The service-policy command applies the policy to an interface. This is the standard and correct method to classify and mark traffic based on DSCP.

Why this answer

The Modular QoS CLI (MQC) is the correct framework for classifying traffic based on DSCP and marking it with a new DSCP value. It involves creating a class-map to match the desired DSCP, a policy-map to set the new DSCP, and applying the service-policy to an interface. This provides a flexible and standardized way to implement QoS policies.

Exam trap

The trap here is confusing QoS mechanisms that use MQC (like CBWFQ and LLQ) with MQC itself. CBWFQ and LLQ are queuing actions within a policy-map, but the classification and marking is done by the MQC framework.

1021
MCQhard

A network engineer is deploying Cisco TrustSec (CTS) with Security Group Access Control Lists (SGACLs) on a campus network. The engineer configures the switch with 'cts role-based enforcement' and assigns SGTs to users via 802.1X. The engineer tests connectivity between a user in SGT 10 and a server in SGT 20. The SGACL permits traffic from SGT 10 to SGT 20, but the user cannot reach the server. The engineer checks 'show cts role-based sgt map' and sees that the user's SGT is 0. What is the most likely cause?

A.The RADIUS server is not configured to send the SGT in the Access-Accept message.
B.The SGACL is applied to the wrong interface.
C.The switch is not configured with 'cts role-based enforcement'.
D.The user's SGT is 0, which is a valid SGT that denies all traffic.
AnswerA

The SGT is not derived from the switch's local configuration or the interface; it is assigned dynamically by the RADIUS server during 802.1X authentication via a vendor-specific attribute (e.g., cisco-avpair with cts:security-tag). If the RADIUS server does not return this attribute in the Access-Accept message, the switch has no SGT to map to the user's role, leaving the user unclassified. Consequently, even though 'cts role-based enforcement' is enabled, the switch cannot apply any SGACL because it has no valid SGT for the session. The correct fix is to configure the RADIUS server to include the appropriate SGT for the authenticated user.

Why this answer

The user's SGT is shown as 0 in the 'show cts role-based sgt map' output, which is the default SGT assigned when no SGT is received from the RADIUS server. Since the SGACL permits traffic from SGT 10 to SGT 20, but the user has SGT 0, the SGACL does not match, and traffic is implicitly denied. The most likely cause is that the RADIUS server is not configured to send the SGT in the Access-Accept message, so the switch cannot dynamically assign the correct SGT.

Exam trap

Cisco often tests the misconception that SGT 0 is a special deny-all SGT, but in reality, SGT 0 is the default untagged SGT and simply means no SGT was assigned, causing traffic to be implicitly denied by SGACL default-deny logic.

How to eliminate wrong answers

Option B is wrong because the SGACL is applied globally via 'cts role-based enforcement' and is not tied to a specific interface; the issue is the SGT assignment, not the interface application. Option C is wrong because the engineer configured 'cts role-based enforcement' and the switch is enforcing SGACLs, but the SGT is 0 due to missing RADIUS attributes, not because the command is missing. Option D is wrong because SGT 0 is not a valid SGT that denies all traffic; it is the default untagged SGT, and traffic with SGT 0 is subject to the default deny behavior of SGACLs when no matching entry exists, but it does not inherently deny all traffic—it simply does not match the permit rule.

1022
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip nat translations Pro Inside global Inside local Outside local Outside global --- 192.0.2.10 10.0.0.10 --- --- --- 192.0.2.11 10.0.0.11 --- --- Based on this output, what can be concluded?

A.Dynamic NAT is configured with a pool of addresses.
B.Static NAT is configured for two internal hosts.
C.PAT is translating multiple internal addresses to a single global address.
D.NAT is not operational because no outside local addresses are shown.
AnswerB

Static NAT creates persistent one-to-one mappings that appear in 'show ip nat translations' as entries with an inside global address and a corresponding inside local address, but no protocol, port, or outside address fields. The output shows exactly two such pairs, meaning two internal hosts have been statically translated to two unique global addresses. Because the mappings exist in the configuration regardless of traffic, they display even when no connection is active.

Why this answer

The output shows two inside global addresses (192.0.2.10 and 192.0.2.11) mapped one-to-one to inside local addresses (10.0.0.10 and 10.0.0.11), with no outside local or outside global entries. This is characteristic of static NAT, where each internal host is permanently assigned a specific global address, typically configured with 'ip nat inside source static' commands.

Exam trap

Cisco often tests the distinction between static NAT and dynamic NAT by showing a translation table without outside addresses or ports, leading candidates to incorrectly assume NAT is broken or that PAT is in use.

How to eliminate wrong answers

Option A is wrong because dynamic NAT uses a pool of addresses and creates translations on demand, but the output shows no 'outside local' or 'outside global' entries and the mappings are static (no dynamic allocation). Option C is wrong because PAT (Port Address Translation) would show protocol and port numbers in the 'Pro' column, and multiple inside locals would map to a single inside global with different ports; here, each inside local has a unique inside global with no ports. Option D is wrong because NAT is operational; the absence of outside local addresses is normal for static NAT translations that only involve inside-to-outside mapping, and the translations are active as shown.

1023
MCQmedium

A network engineer runs the following command on Switch SW6: SW6# show monitor session 6 Session 6 --------- Type : Remote Destination Session Source RSPAN VLAN : 200 Destination Ports : Gi1/0/12 Encapsulation : Native Ingress : Disabled Based on this output, what can be concluded?

A.This switch receives mirrored traffic from RSPAN VLAN 200 and sends it to Gi1/0/12.
B.This is a local SPAN session with source VLAN 200.
C.The RSPAN VLAN 200 is used to send traffic to a remote switch.
D.Ingress traffic on Gi1/0/12 is forwarded to the RSPAN VLAN.
AnswerA

The 'Remote Destination Session' type with a source RSPAN VLAN confirms this switch acts as the destination, receiving mirrored frames from VLAN 200 and forwarding them out Gi1/0/12. Ingress is disabled, so only received traffic is sent to that port.

Why this answer

The output shows a Remote Destination Session, meaning this switch (SW6) is the destination switch in an RSPAN configuration. It receives mirrored traffic from RSPAN VLAN 200 and forwards it out of the destination port Gi1/0/12. The 'Source RSPAN VLAN: 200' indicates the VLAN carrying the mirrored traffic from the source switch, and 'Destination Ports: Gi1/0/12' confirms the local egress interface for the mirrored packets.

Exam trap

Cisco often tests the distinction between RSPAN source and destination roles; the trap here is confusing 'Source RSPAN VLAN' as the source of the mirrored traffic (it is the transport VLAN) versus the source switch, leading candidates to incorrectly think the switch is sending traffic to a remote switch.

How to eliminate wrong answers

Option B is wrong because the session type is 'Remote Destination Session', not a local SPAN session, and the source is an RSPAN VLAN (200), not a source VLAN for local SPAN. Option C is wrong because the RSPAN VLAN 200 is used to receive mirrored traffic from a remote source switch, not to send traffic to a remote switch; the destination switch is the local switch. Option D is wrong because 'Ingress: Disabled' means that ingress traffic on Gi1/0/12 is not forwarded to the RSPAN VLAN; the port is used only for egress of mirrored traffic.

1024
Matchingmedium

Drag and drop each CPU feature on the left to its matching virtualization purpose on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Intel hardware virtualization support

Reduces memory virtualization overhead

Enables direct VM access to physical NIC

Provides direct I/O device assignment

AMD hardware virtualization support

Why these pairings

VT-x enables hardware-assisted virtualization for Intel CPUs. EPT (Extended Page Tables) reduces memory overhead by handling guest page tables in hardware. SR-IOV allows a physical NIC to appear as multiple virtual functions.

VT-d provides direct I/O access for VMs. AMD-V is AMD’s equivalent of VT-x.

1025
MCQeasy

A network engineer is new to automation and wants to use a Python script to configure a Cisco IOS XE device. The engineer prefers a protocol that uses HTTP methods and JSON for data encoding, as it is easier to read and debug. Which protocol should the engineer choose?

A.NETCONF
B.SNMP
C.RESTCONF
D.SSH with CLI commands
AnswerC

RESTCONF is designed to use HTTP methods (GET, POST, PUT, PATCH, DELETE) and supports both XML and JSON encoding. It is built on the same YANG models as NETCONF but provides a RESTful interface that is easier to work with, especially for those familiar with JSON and HTTP. This matches the engineer's preferences.

Why this answer

RESTCONF is the protocol that uses HTTP methods and supports JSON encoding, making it ideal for engineers who prefer a RESTful API. It leverages YANG models to structure data, providing a modern and readable way to automate Cisco IOS XE devices. The other protocols either use different encodings or are not based on HTTP.

Exam trap

The trap here is confusing RESTCONF with NETCONF, as both use YANG models; however, only RESTCONF is inherently HTTP- and JSON-friendly.

1026
MCQmedium

A large enterprise is migrating from traditional SNMP-based monitoring to streaming telemetry for better scalability and real-time visibility. The network team has Cisco Nexus 9000 switches running NX-OS. They want to stream interface counters and BGP neighbor state changes to a collector. Which telemetry technology should they implement?

A.Configure model-driven telemetry (MDT) using gRPC or gNMI to subscribe to the desired YANG data models for interface counters and BGP state.
B.Enable NetFlow v9 on the switches and configure the collector to receive flow records that include interface statistics.
C.Use SNMP traps to send interface and BGP state changes to the collector.
D.Deploy IP SLA responders on the switches to measure performance and send results via syslog.
AnswerA

Model-driven telemetry (MDT) with gRPC or gNMI creates a persistent subscription to YANG-defined data models, allowing the NX-OS device to push interface counters and BGP state at a configured cadence or immediately on change. This push model scales to thousands of counters without collector polling overhead and supports structured encoding (protobuf/JSON), making it ideal for real-time visibility. Unlike flow or event mechanisms, MDT is purpose-built for streaming operational state from network devices.

Why this answer

Model-driven telemetry (MDT) using gRPC or gNMI is the correct choice because it provides a push-based, scalable, and real-time streaming mechanism for subscribing to specific YANG data paths, such as interface counters and BGP neighbor state, directly from Cisco Nexus 9000 switches running NX-OS. This approach eliminates the polling overhead of SNMP and supports high-frequency data collection, making it ideal for large-scale enterprise monitoring.

Exam trap

Cisco often tests the distinction between streaming telemetry (push-based, model-driven) and legacy monitoring methods like SNMP or NetFlow, where candidates mistakenly choose NetFlow because it sounds similar to 'streaming' or SNMP traps because they think 'state changes' imply event-driven traps, but the key is that MDT provides structured, scalable, and real-time data for operational state, not just flow records or performance metrics.

How to eliminate wrong answers

Option B is wrong because NetFlow v9 is designed for traffic flow analysis (e.g., IP flows, protocols, ports) and does not natively stream interface counters or BGP neighbor state changes; it focuses on network traffic metadata, not device operational state. Option C is wrong because SNMP traps are event-driven but lack the scalability and granularity of streaming telemetry; they are pull-based for counters and can miss state changes due to unreliable UDP transport, and they do not support the high-frequency, model-driven subscriptions required for real-time visibility. Option D is wrong because IP SLA responders measure network performance metrics like latency and jitter, not interface counters or BGP neighbor state; they send results via syslog, which is a log-based, non-structured method unsuitable for streaming telemetry.

1027
Matchingmedium

Drag and drop each PnP workflow step on the left to its matching action on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Assigns a discovered device to a specific site and profile

Applies initial bootstrap configuration via CLI template

Installs the required software image on the device

Deploys full configuration including interfaces, VLANs, and routing

Replaces a failed device with a new one using the same configuration

Why these pairings

PnP steps: Claim assigns a device to a site; Day0 Template applies initial configuration; Image Upgrade updates the device software; Provision deploys the full configuration.

1028
Multi-Selecthard

Which three statements about the Cisco Enterprise WAN design principles are true? (Choose three.)

Select 3 answers
A.SD-WAN architecture separates the control plane and data plane, allowing centralized policy management.
B.Dual-homing a branch office to two different service provider routers increases WAN availability.
C.DMVPN requires a full mesh of static IPsec tunnels between all spoke routers.
D.MPLS Layer 3 VPNs use Virtual Routing and Forwarding (VRF) instances to provide customer isolation.
E.DMVPN requires a full mesh of IPsec tunnels between all spoke routers.
AnswersA, B, D

Correct because SD-WAN uses a controller-based approach where the control plane is centralized, simplifying policy deployment.

Why this answer

Option A is correct because SD-WAN (e.g., Cisco Catalyst SD-WAN/Viptela) physically and logically separates the control plane (vSmart controllers using OMP) from the data plane (vEdge/cEdge routers forwarding traffic), which enables centralized policy configuration and distribution. Option B is correct because dual-homing a branch to two distinct service provider edge routers provides path and device redundancy, so a single provider router or link failure does not isolate the branch, thereby increasing WAN availability. Option D is correct because MPLS Layer 3 VPNs use per-customer VRF instances on provider edge routers to keep overlapping customer address spaces and routing tables logically isolated while MPLS labels (e.g., VPNv4 route targets) carry the traffic across the provider core.

Option C is not correct because DMVPN is specifically designed to avoid a full mesh of static tunnels; it uses mGRE with NHRP to build dynamic spoke-to-spoke tunnels on demand. Option E is also not correct because DMVPN does not require a full mesh of IPsec tunnels between spokes—spokes register with the hub via NHRP and only form direct IPsec tunnels dynamically when needed.

Exam trap

The trap is confusing DMVPN with traditional full-mesh IPsec VPNs; candidates may think DMVPN requires a full mesh, but it actually eliminates that requirement.

1029
MCQhard

A network administrator must protect the control plane of a Cisco IOS XE router that peers BGP with an ISP. The requirement is to rate-limit specifically ARP and IPv4 TTL-expired packets destined to the route processor while allowing all other transit traffic to be forwarded normally. Which CoPP implementation step is required to achieve this?

A.Enable Control Plane Protection with a port-filter policy that drops ARP and TTL-expired packets before they reach the route processor.
B.Apply an ACL directly to the BGP peer interface inbound to deny ARP and TTL-expired packets, then rely on uRPF to drop remaining control-plane traffic.
C.Configure an MQC service policy with service-policy type control-plane on the BGP-facing interface to rate-limit ARP and TTL-expired packets.
D.Create an ACL matching ARP and TTL-expired traffic, reference it in a class-map of type control-plane, define a policy-map with police actions, and attach it with service-policy type control-plane in global configuration.
AnswerD

CoPP on IOS XE requires classifying control-plane-bound traffic with a class-map of type control-plane, then applying policing in a policy-map that is attached globally with service-policy type control-plane. An ACL matching ARP and TTL-expired packets provides the specific match, and transit traffic is unaffected because CoPP only inspects packets punted to the route processor.

Why this answer

CoPP uses MQC with a class-map of type control-plane to identify traffic punted to the route processor, a policy-map to police that class, and a global service-policy type control-plane attachment. Matching ARP and TTL-expired packets with an ACL inside the class-map isolates exactly the traffic to be rate-limited, while transit traffic continues to be forwarded in hardware and is never inspected by CoPP.

Exam trap

The trap here is attaching the control-plane service policy to an interface instead of globally, which would police forwarded traffic rather than packets punted to the route processor.

1030
MCQmedium

A network engineer is using Cisco DNA Center to automate the deployment of a new VLAN across multiple access switches. The engineer creates a new network profile with the VLAN definition and assigns it to a site. However, after provisioning, the VLAN is not created on any of the switches. The engineer verifies that the devices are in the Inventory and are reachable. What is the most likely cause?

A.The engineer did not run the Provision workflow to push the configuration to the devices.
B.The VLAN ID conflicts with an existing VLAN on the switches.
C.The switches do not support the VLAN ID range.
D.The DNA Center appliance is not licensed for the Automation module.
AnswerA

Assigning a network profile to a site only stages the intended configuration; the Provision workflow must then be run to push those settings to the devices. Without provisioning, DNA Center leaves the switches untouched, so the VLAN never appears despite correct inventory and reachability.

Why this answer

In Cisco DNA Center, creating a network profile and assigning it to a site only defines the intent — it does not push configuration to devices. The engineer must run the Provision workflow (Design > Network Settings, then Provision > Devices) to actually generate and deploy the CLI configuration, including the new VLAN, to the target switches. Until provisioning is executed, the devices remain unchanged even though they are in Inventory and reachable.

Exam trap

The trap is assuming DNA Center is fully declarative and auto-pushes any profile change — candidates forget that the explicit Provision workflow must be run to translate intent into device configuration.

How to eliminate wrong answers

Option B is wrong because a VLAN ID conflict would typically cause a provisioning error or warning during the Provision workflow, not silent non-creation — and the scenario states the VLAN was never created at all, which points to provisioning not being run. Option C is wrong because virtually all modern Cisco access switches support the standard VLAN range (1–4094), so a range limitation is not a plausible cause for a routine VLAN deployment. Option D is wrong because licensing issues would block access to the Automation/Provision features entirely or produce an explicit license error, not a silent failure to create a VLAN after a profile was successfully built.

1031
Drag & Dropmedium

Drag and drop the steps of vSphere VM snapshot creation and revert steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with taking the snapshot and ends with reverting to it. First, the snapshot is taken while the VM is running. Then, changes are made to the VM.

Next, the snapshot is reverted to restore the previous state. After that, the snapshot is deleted to free storage. Finally, the VM continues running without the snapshot.

1032
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip interface GigabitEthernet0/1 | include access list Inbound access list is not set Outbound access list is 140 R1# show access-lists 140 Extended IP access list 140 10 permit tcp 192.168.1.0 0.0.0.255 any eq 443 (25 matches) 20 deny tcp any any eq 443 (10 matches) 30 permit ip any any (50 matches) Based on this output, what can be concluded?

A.HTTPS traffic from sources outside 192.168.1.0/24 is denied when exiting the interface.
B.All HTTPS traffic is permitted outbound.
C.The ACL is applied inbound on the interface.
D.The ACL permits all traffic from 192.168.1.0/24.
AnswerA

Because ACL 140 is applied to outbound traffic on this interface, it evaluates packets as they are leaving the interface. Entry 10 permits HTTPS only from the 192.168.1.0/24 source network, while entry 20 explicitly denies HTTPS from any source that does not match that permit. Therefore, HTTPS sessions initiated from addresses outside that subnet will be denied when they attempt to exit the interface.

Why this answer

The ACL 140 is applied outbound on GigabitEthernet0/1. It permits TCP port 443 (HTTPS) traffic only from source 192.168.1.0/24, then denies all other HTTPS traffic, and finally permits all other IP traffic. Since the deny statement (line 20) blocks HTTPS from any source not matching the permit (line 10), traffic from outside 192.168.1.0/24 is denied when exiting the interface, making option A correct.

Exam trap

Cisco often tests the distinction between inbound and outbound ACL application, and the trap here is that candidates see 'permit ip any any' and mistakenly think all traffic is allowed, ignoring the order-specific deny of HTTPS from other sources.

How to eliminate wrong answers

Option B is wrong because the ACL does not permit all HTTPS traffic outbound; it specifically permits HTTPS only from 192.168.1.0/24 and denies all other HTTPS traffic. Option C is wrong because the 'show ip interface' output clearly shows 'Outbound access list is 140' and 'Inbound access list is not set', indicating the ACL is applied outbound, not inbound. Option D is wrong because the ACL permits only TCP port 443 (HTTPS) from 192.168.1.0/24, not all traffic; line 30 permits all IP traffic, but that applies to any source after the deny of HTTPS, not a blanket permit for the 192.168.1.0/24 subnet.

1033
MCQmedium

A network engineer is deploying a new branch office with a single Cisco Catalyst switch. The branch requires that all access ports automatically authenticate devices using 802.1X with RADIUS, but also allow unauthenticated devices to be placed into a guest VLAN. Which feature must be configured on the switch to meet this requirement?

A.Configure 802.1X authentication with a guest VLAN on the access ports.
B.Configure Web Authentication (WebAuth) with a guest VLAN on the access ports.
C.Configure MAC authentication bypass (MAB) with a guest VLAN on the access ports.
D.Configure port security with a guest VLAN on the access ports.
AnswerA

Configuring 802.1X with a guest VLAN allows authenticated devices to be placed into a VLAN after successful RADIUS authentication, while unauthenticated devices are assigned to a separate guest VLAN. This meets the branch requirement exactly. The guest VLAN feature is specifically designed for this scenario and is supported on Cisco Catalyst switches.

Why this answer

The requirement is to authenticate devices using 802.1X with RADIUS and also provide a guest VLAN for unauthenticated devices. The 802.1X with guest VLAN feature on Cisco switches accomplishes this by assigning authenticated users to a VLAN and unauthenticated users to a guest VLAN. This is a standard implementation for branch offices needing both secure and guest access.

Exam trap

The trap here is confusing 802.1X with MAC authentication bypass or web authentication, which serve different purposes and do not provide the exact combination of 802.1X and guest VLAN.

1034
MCQhard

A network automation team is using Ansible to push configuration changes to a fleet of Cisco IOS XE devices. The playbook uses the 'ios_config' module with the 'backup: yes' option. During a recent run, the playbook failed on one device due to a syntax error in the configuration lines. The team wants to ensure that if a failure occurs, the device automatically reverts to its previous configuration without manual intervention. Which Ansible feature should be used to achieve this?

A.Use the 'ios_config' module with the 'rollback' parameter set to 'yes'.
B.Implement a 'block' and 'rescue' section in the playbook to run a rollback task if the configuration fails.
C.Set the 'ansible_command_timeout' to a higher value to prevent premature failure.
D.Enable 'config' mode with the 'save_when' parameter set to 'modified'.
AnswerB

Ansible's block/rescue structure allows error handling. The configuration task can be placed in a block, and if it fails, the rescue section can execute a rollback task, such as using 'cli_command' to run 'configure replace' with a previously saved configuration file. This provides automatic rollback without manual intervention, directly addressing the requirement.

Why this answer

To automatically revert to the previous configuration upon failure, the playbook must include error handling. Ansible's block/rescue construct allows tasks to be grouped, and if any task in the block fails, the rescue section runs. Within rescue, a task can invoke 'configure replace' using a saved configuration file, restoring the device to its prior state.

This approach ensures atomic rollback without manual intervention.

Exam trap

The trap here is assuming that the ios_config module has built-in rollback capabilities or that saving the configuration provides automatic recovery.

1035
MCQeasy

A network engineer is using a Python script with the requests library to retrieve interface information from a Cisco IOS XE device via RESTCONF. The script sends a GET request to https://192.168.1.1/restconf/data/ietf-interfaces:interfaces but receives a 401 Unauthorized error. The engineer has verified that the device has RESTCONF enabled and the URL is correct. Which action should the engineer take to resolve the error?

A.Enable the RESTCONF-YANG feature on the device using the restconf-yang command in global configuration mode.
B.Change the request method from GET to POST to retrieve the interface information.
C.Configure the device to allow unauthenticated access by adding the 'restconf no-auth' command.
D.Include a valid username and password in the request using HTTP Basic Authentication.
AnswerD

A 401 Unauthorized error indicates that the request lacks valid authentication credentials. RESTCONF on Cisco IOS XE requires authentication, typically via HTTP Basic Authentication. The engineer must include the username and password in the request headers. This is the standard method to authenticate RESTCONF requests. Without credentials, the device rejects the request, resulting in a 401 error.

Why this answer

A 401 Unauthorized error means the request lacks valid authentication credentials. RESTCONF on Cisco IOS XE requires HTTP Basic Authentication. The engineer must include a valid username and password in the request headers.

This is the correct and secure way to authenticate RESTCONF requests.

Exam trap

The trap here is thinking that enabling RESTCONF is sufficient for access, when in fact authentication credentials must also be supplied with each request.

1036
MCQmedium

A network engineer issues the following command on Router R2: R2# show ip mroute 239.1.1.1 IP Multicast Routing Table Flags: D - Dense, S - Sparse, B - Bidir Group, s - SSM Group, C - Connected, L - Local, P - Pruned, R - RP-bit set, F - Register flag, T - SPT-bit set, J - Join SPT, M - MSDP created entry, E - Extranet, X - Proxy Join Timer Running, A - Candidate for MSDP Advertisement, U - URD, I - Received Source Specific Host Report, Z - Multicast Tunnel, z - MDT-data group session, Y - Joined MDT-data group, y - Sending to MDT-data group Outgoing interface flags: H - Hardware switched, A - Assert winner Timers: Uptime/Expires Interface state: Interface, Next-Hop or VCD, State/Mode (*, 239.1.1.1), 00:03:45/00:02:15, RP 10.0.0.1, flags: S Incoming interface: GigabitEthernet0/0, RPF nbr 10.0.0.1 Outgoing interface list: GigabitEthernet0/1, Forward/Sparse, 00:03:45/00:02:15 Based on this output, what can be concluded?

A.The group is using PIM dense mode.
B.The RP for this group is 10.0.0.1.
C.The multicast traffic is being hardware switched.
D.The group is a Bidir group.
AnswerB

The multicast routing table output for group ff2fef explicitly contains a (*,G) entry with the text 'RP 10.0.0.1', which is the Rendezvous Point address used by PIM-SM to build the shared tree. In PIM-SM, the RP is the root of the (*,G) tree; receivers join towards the RP and sources register with it. The presence of this RP statement in the output is authoritative and confirms that 10.0.0.1 is indeed the RP for this group, so the statement is correct.

Why this answer

The output shows a (*, G) entry for 239.1.1.1 with the flags field containing 'S', which indicates Sparse Mode. The line 'RP 10.0.0.1' explicitly identifies the Rendezvous Point for this group. Therefore, option B is correct because the RP is indeed 10.0.0.1.

Exam trap

Cisco often tests the ability to read the flags field in 'show ip mroute' output, where candidates mistakenly interpret the 'S' flag as 'SSM' instead of 'Sparse', or overlook that the 'RP' field explicitly identifies the Rendezvous Point.

How to eliminate wrong answers

Option A is wrong because the flags field shows 'S' (Sparse), not 'D' (Dense), so the group is using PIM sparse mode, not dense mode. Option C is wrong because the outgoing interface flags do not include 'H' (Hardware switched); the output shows 'Forward/Sparse' without any hardware switching indication. Option D is wrong because the flags field does not contain 'B' (Bidir Group); it contains 'S' for Sparse mode, and the presence of an RP confirms this is a sparse-mode group, not a bidirectional group.

1037
MCQhard

A network engineer runs the following command on Router R2: R2# show mpls forwarding-table Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 16 Pop Label 10.1.1.1/32 0 Gi0/0 192.168.1.1 17 18 10.2.2.0/24 1500 Gi0/1 192.168.2.3 18 Untagged 10.3.3.0/24 0 Gi0/2 192.168.3.4 Based on this output, what is the correct interpretation?

A.For prefix 10.1.1.1/32, the router will pop the MPLS label before forwarding because the outgoing label is 'Pop Label'.
B.For prefix 10.2.2.0/24, the router will impose label 18 onto the packet.
C.For prefix 10.3.3.0/24, the router will forward the packet with an MPLS label of 18.
D.The router has received 1500 bytes for prefix 10.2.2.0/24, and the outgoing interface is Gi0/1.
AnswerA

For the /32 prefix, the outgoing label is 'Pop Label', which signals Penultimate Hop Popping (PHP). The router, acting as the penultimate LSR, removes the MPLS label before forwarding the IP packet to the egress router, avoiding the need for the egress to perform a label lookup. This operation reduces processing overhead and is a common optimization in MPLS networks.

Why this answer

The 'Pop Label' entry in the 'Outgoing Label' column indicates that for the prefix 10.1.1.1/32, Router R2 is the penultimate hop (PHP) in the MPLS network. According to MPLS PHP behavior, the router will remove (pop) the top label from the MPLS packet before forwarding the IP packet to the next hop (192.168.1.1), which is the egress LSR.

Exam trap

Cisco often tests the distinction between 'Pop Label' (PHP), 'Untagged' (egress or no label), and a numeric outgoing label (swap), and candidates commonly misinterpret 'Untagged' as meaning the label is removed or that a label is still present.

How to eliminate wrong answers

Option B is wrong because the 'Outgoing Label' of 18 means the router will swap the incoming label with label 18, not impose a new label; label imposition occurs at the ingress LSR. Option C is wrong because the 'Untagged' entry indicates that for prefix 10.3.3.0/24, the router forwards the packet as a standard IP packet without any MPLS label, not with label 18. Option D is wrong because the 'Bytes Label Switched' column shows 1500 bytes have been switched for that prefix, not that the router has received 1500 bytes; it is a cumulative counter of forwarded traffic.

1038
MCQmedium

A network engineer is configuring model-driven telemetry on a Cisco IOS-XE router to stream interface statistics to a collector using gRPC. The engineer wants to ensure that the telemetry data is sent only when there is a change in the interface counters, rather than at a fixed interval. Which configuration parameter should the engineer use to achieve this behavior?

A.Use a periodic subscription with a sample-interval of 0
B.Configure an on-change subscription
C.Set the suppress-repetition flag in a periodic subscription
D.Use a dynamic subscription with a sample-interval of 1 second
AnswerB

An on-change subscription publishes telemetry only when the monitored interface counters actually change, satisfying the requirement to avoid fixed-interval updates. A periodic subscription would instead stream at a configured interval regardless of whether values changed.

Why this answer

'on-change' subscription because it triggers updates only when the monitored data changes, unlike periodic subscriptions that send data at fixed intervals. The other options are incorrect because 'periodic' sends data at a fixed interval, 'suppress-repetition' reduces duplicate updates in periodic subscriptions but does not enable on-change behavior, and 'sample-interval' is used for periodic subscriptions.

1039
MCQmedium

A network engineer is configuring a Cisco switch for 802.1X port-based authentication. The switch is configured with a RADIUS server for authentication. The engineer wants to allow devices that fail 802.1X authentication to still access a limited guest VLAN. The engineer configures 'authentication port-control auto' and 'authentication host-mode multi-host' on the interface. However, when a non-802.1X-capable device is connected, the port remains in the unauthorized state and does not fall into the guest VLAN. What is missing?

A.The interface needs the 'authentication guest-vlan <vlan-id>' command to specify the VLAN for non-802.1X devices.
B.The switch must have 'aaa authentication dot1x default group radius' configured globally.
C.The 'authentication host-mode multi-host' command should be replaced with 'authentication host-mode multi-domain' to support guest VLAN.
D.The port must be configured as a trunk port to allow the guest VLAN.
AnswerA

The interface-level command 'authentication guest-vlan <vlan-id>' is required to define a fallback VLAN for devices that do not respond to 802.1X or whose authentication times out. Without this command, a non-802.1X capable device will be denied access or left in an unauthorized state, because the switch has no VLAN to assign it. The guest VLAN is a per-interface configuration, separate from global AAA commands, and it must reference an existing VLAN on the switch.

Why this answer

The 'authentication guest-vlan <vlan-id>' command is missing. This command explicitly defines the VLAN to which the port will assign devices that fail 802.1X authentication or are non-802.1X-capable. Without it, the switch has no configured fallback VLAN, so the port remains in the unauthorized state even with 'authentication port-control auto' and 'authentication host-mode multi-host' configured.

Exam trap

Cisco often tests the distinction between the authentication method (RADIUS configuration) and the fallback mechanism (guest VLAN), leading candidates to assume that missing AAA commands are the root cause when the actual missing piece is the explicit guest VLAN assignment.

How to eliminate wrong answers

Option B is wrong because 'aaa authentication dot1x default group radius' is a global command that enables RADIUS-based authentication for 802.1X, but it is not the missing piece; the issue is the lack of a guest VLAN assignment, not the authentication method. Option C is wrong because 'authentication host-mode multi-host' is actually required to allow multiple hosts (including the non-802.1X device) on the same port after authentication; replacing it with 'multi-domain' would restrict the port to one host per domain and would not fix the guest VLAN fallback. Option D is wrong because the port does not need to be a trunk; guest VLANs are supported on access ports, and the switch internally maps the unauthorized state to the guest VLAN without requiring trunking.

1040
MCQmedium

A company is migrating its branch WAN to a Cisco SD-WAN solution. The design team wants to use a single overlay that supports both point-to-point and multipoint traffic, and they want to avoid running separate tunnels for unicast and multicast. Which Cisco SD-WAN technology should they enable on the overlay?

A.Cisco SD-WAN multicast with replication using a rendezvous point
B.Cisco SD-WAN Direct Internet Access with NAT
C.Cisco SD-WAN Application-Aware Routing with BFD probes
D.Cisco SD-WAN TLOC extension between two transports
AnswerA

Cisco SD-WAN supports multicast over the overlay by replicating traffic through the fabric with a rendezvous point, allowing one overlay to carry both unicast and multicast. This meets the goal of a single overlay without separate tunnels for each traffic type.

Why this answer

Multicast support in Cisco SD-WAN uses overlay replication coordinated by a rendezvous point, letting the same fabric carry unicast and multicast without parallel tunnel types. Application-Aware Routing, TLOC extension, and Direct Internet Access serve different purposes and do not deliver multipoint transport across the overlay.

Exam trap

The trap here is confusing overlay path-selection or offload features with the mechanism that actually replicates multicast traffic across the SD-WAN fabric.

1041
MCQmedium

A network engineer runs the following command on Switch SW1: SW1# show vlan brief VLAN Name Status Ports ---- -------------------------------- --------- ------------------------------- 1 default active Gi0/1, Gi0/2, Gi0/3 10 Sales active Gi0/4, Gi0/5 20 Engineering active Gi0/6 1002 fddi-default act/unsup 1003 token-ring-default act/unsup 1004 fddinet-default act/unsup 1005 trnet-default act/unsup Based on this output, what can be concluded?

A.VLAN 20 is not operational because it has only one port assigned.
B.The switch supports FDDI and Token Ring VLANs.
C.Port Gi0/6 is an access port in VLAN 20.
D.VLAN 10 has more broadcast traffic than VLAN 20.
AnswerC

In the 'show vlan' output, a port listed under a specific VLAN without any trunking indicator is an access port. Gi0/6 appears in the VLAN 20 section, and there is no mention of 802.1Q encapsulation or trunk mode, so it belongs to only VLAN 20. An access port carries traffic for exactly one untagged VLAN, and this membership confirms that Gi0/6 is an access port in VLAN 20.

Why this answer

The 'show vlan brief' output lists VLANs and their assigned ports. Port Gi0/6 is listed under VLAN 20, and since it is the only port in that VLAN, it must be an access port (or a trunk port that only allows VLAN 20, but the context of a single port in a VLAN typically indicates an access port). Access ports belong to a single VLAN and do not carry tags, so Gi0/6 is an access port in VLAN 20.

Exam trap

Cisco often tests the misconception that a VLAN must have multiple ports to be operational, or that the presence of VLANs 1002-1005 implies actual support for FDDI/Token Ring, when in fact they are unsupported defaults.

How to eliminate wrong answers

Option A is wrong because a VLAN can be operational with only one port assigned; there is no requirement for multiple ports. Option B is wrong because the FDDI and Token Ring VLANs (1002-1005) are default VLANs that exist in the switch's database for backward compatibility but are not actually supported on modern Ethernet switches; they show 'act/unsup' meaning they are not operational. Option D is wrong because the output provides no information about broadcast traffic levels; broadcast traffic depends on hosts and applications, not just the number of ports in a VLAN.

1042
MCQmedium

A network engineer runs the following command on Switch SW1: SW1# show monitor session 1 Session 1 --------- Type : Local Session Source Ports : Both : Gi1/0/1 Both : Gi1/0/2 Destination Ports : Gi1/0/10 Encapsulation : Native Ingress : Disabled Based on this output, what can be concluded?

A.Traffic from Gi1/0/1 and Gi1/0/2 is copied to Gi1/0/10 for monitoring.
B.This is an RSPAN session that sends traffic to a remote VLAN.
C.Ingress traffic on Gi1/0/10 is forwarded to the source ports.
D.The destination port is configured to capture only egress traffic.
AnswerA

This is a Local SPAN session. The source ports Gi1/0/1 and Gi1/0/2 each capture both ingress and egress traffic, and the switch copies those frames to the destination port Gi1/0/10, which resides on the same switch. The monitoring device connected to Gi1/0/10 receives a real-time copy of all traffic seen on the source ports, without any impact to the original traffic flow.

Why this answer

The output shows a local SPAN session where source ports Gi1/0/1 and Gi1/0/2 are configured to capture both ingress and egress traffic, and the destination port is Gi1/0/10. This means all traffic entering or leaving the source ports is copied to Gi1/0/10 for monitoring. The 'Both' keyword under source ports confirms bidirectional traffic capture, and the destination port is not involved in any forwarding back to the sources.

Exam trap

Cisco often tests the distinction between 'Both' (capturing ingress and egress) and the 'Ingress' field under the destination port (which controls whether incoming traffic on the destination port is forwarded), leading candidates to confuse capture direction with destination port behavior.

How to eliminate wrong answers

Option B is wrong because the session type is explicitly 'Local Session', not RSPAN; RSPAN would show a destination as a remote VLAN (e.g., 'Remote VLAN') and use a different session type. Option C is wrong because the destination port (Gi1/0/10) is used only for receiving copied traffic; it does not forward ingress traffic to the source ports—SPAN is unidirectional from source to destination. Option D is wrong because the source ports are configured with 'Both', meaning both ingress and egress traffic are captured, not only egress; the 'Ingress' field under destination port refers to whether incoming traffic on the destination port is forwarded (disabled here), not the capture direction.

1043
MCQmedium

interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip ospf network point-to-point ip ospf hello-interval 10 ! router ospf 1 network 192.168.1.0 0.0.0.255 area 0 What is the effect of this configuration?

A.OSPF will use a 10-second hello interval and suppress DR/BDR election.
B.OSPF will use a 30-second hello interval and elect a DR/BDR.
C.OSPF will use a 10-second hello interval but still elect a DR/BDR.
D.OSPF will use a 30-second hello interval and suppress DR/BDR election.
AnswerA

This is the correct behavior. The `point-to-point` OSPF network type is designed for links that connect exactly two routers, such as serial interfaces using PPP or HDLC. By definition, it eliminates DR/BDR election because there is no need to reduce adjacency flooding on a two-router segment, and it uses the default 10-second hello interval (with a 40-second dead interval). Configuring `ip ospf network point-to-point` is redundant when the interface already defaults to this type, but it is often used to explicitly override an interface's default OSPF network type on platforms like Ethernet or Frame Relay.

Why this answer

The `ip ospf network point-to-point` command changes the OSPF network type on the interface to point-to-point, which suppresses the DR/BDR election process because point-to-point links have only two neighbors. The `ip ospf hello-interval 10` command overrides the default hello interval for point-to-point networks (which is 10 seconds by default anyway, but explicitly setting it ensures consistency). Thus, OSPF uses a 10-second hello interval and does not elect a DR/BDR.

Exam trap

Cisco often tests the misconception that changing the hello interval alone affects DR/BDR election, or that the point-to-point network type still uses a 30-second hello interval like NBMA, when in fact point-to-point suppresses DR/BDR and uses a 10-second hello interval by default.

How to eliminate wrong answers

Option B is wrong because it incorrectly states a 30-second hello interval; the configured hello interval is 10 seconds, and the default for point-to-point is also 10 seconds, not 30. Option C is wrong because it claims DR/BDR election still occurs, but the point-to-point network type explicitly suppresses DR/BDR election. Option D is wrong because it combines both errors: a 30-second hello interval (incorrect) and suppression of DR/BDR election (correct in concept but paired with the wrong interval).

1044
MCQmedium

An engineer is troubleshooting an MPLS VPN where CE1 (10.1.1.0/24) cannot reach CE2 (10.2.2.0/24). The PE routers are running OSPF with the CE routers. On PE1, the 'show ip route vrf CUSTOMER' output shows 10.2.2.0/24 as an OSPF route, but the prefix is not present in the global BGP table. What is the most likely cause?

A.Redistribution from OSPF into BGP under the VRF is not configured on PE1.
B.The OSPF adjacency between PE1 and CE1 is down.
C.The VRF forwarding table on PE1 is full.
D.MPLS LDP is not enabled on the PE1-CE1 link.
AnswerA

Within an MPLS L3VPN, simply running OSPF in the VRF does not make a CE route available to the MP-BGP VPNv4 control plane. The PE must explicitly execute a redistribution command, such as 'redistribute ospf 1 vrf CUSTOMER' under 'router bgp AS ... address-family ipv4 vrf CUSTOMER'. Missing this command means the OSPF-installed route stays confined to the VRF RIB; it is never given a route distinguisher, tagged with an export route target, or sent to remote PEs. Consequently, even a healthy OSPF adjacency and populated VRF still result in no VPNv4 prefix.

Why this answer

In an MPLS VPN, the PE router must redistribute OSPF routes learned from the CE into MP-BGP under the VRF to propagate them across the MPLS backbone. Without this redistribution, the prefix 10.2.2.0/24 appears in the VRF routing table as an OSPF route but is never injected into the BGP table, so it cannot be advertised to the remote PE. This explains why CE1 cannot reach CE2 despite the route being present locally on PE1.

Exam trap

Cisco often tests the distinction between a route being present in the VRF routing table versus being present in the BGP table, trapping candidates who assume that OSPF-learned routes are automatically propagated across the MPLS VPN backbone without explicit redistribution into MP-BGP.

How to eliminate wrong answers

Option B is wrong because if the OSPF adjacency between PE1 and CE1 were down, the 10.2.2.0/24 route would not appear in the VRF routing table at all, but the question states it is present. Option C is wrong because a full VRF forwarding table would cause route installation failures or drops, not the specific symptom of a route missing from the global BGP table while present in the VRF. Option D is wrong because MPLS LDP on the PE1-CE1 link is irrelevant for MPLS VPN; LDP is used for label distribution in the core, not on the CE-facing link, and the issue is about BGP route propagation, not label switching.

1045
MCQmedium

A network architect is designing the QoS architecture for a Cisco SD-WAN deployment that carries voice, video, and data traffic across MPLS and Internet transports. The design must use a consistent DiffServ marking strategy across all transports and ensure that voice traffic is prioritized over video. Which QoS policy type and marking approach should the architect use?

A.Use localized QoS policies on each WAN edge router with CoS markings based on the transport type.
B.Use a centralized QoS policy that marks traffic with DSCP and applies per-queue shaping on the WAN edge.
C.Use MPLS EXP markings for MPLS transport and IP Precedence for Internet transport.
D.Use NBAR2 to automatically classify traffic and apply markings based on application signatures.
AnswerB

A centralized QoS policy, defined in vManage and pushed to all WAN edge routers, is the correct SD-WAN approach because it applies identical DSCP marking rules regardless of the underlying transport. DSCP operates at the IP layer, so it can be preserved across IPsec tunnels by instructing the tunnel to copy the outer TOS field, allowing service providers and remote routers to honor priority markings. The per-queue shaping component uses scheduling constructs such as strict priority for voice and a separate bandwidth pool for video, ensuring that real-time traffic receives predictable latency and jitter even when a transport link is congested. This transport-independent, centrally managed model is the foundation of Cisco SD-WAN QoS.

Why this answer

Cisco SD-WAN uses centralized QoS policies applied via vSmart to ensure consistent DiffServ marking (DSCP) across all transports (MPLS and Internet). Per-queue shaping on the WAN edge router allows voice traffic to be prioritized over video by assigning voice to a higher-priority queue (e.g., queue 4 with DSCP EF) and video to a lower queue (e.g., queue 3 with DSCP AF41), ensuring voice is always serviced first.

Exam trap

Cisco often tests the misconception that localized QoS policies are sufficient for multi-transport consistency, but the trap here is that only centralized QoS policies in SD-WAN can enforce uniform DiffServ markings across all transports, while options like NBAR2 or per-transport markings (EXP vs. IP Precedence) fail to meet the requirement for a consistent strategy.

How to eliminate wrong answers

Option A is wrong because localized QoS policies on each WAN edge router would not guarantee a consistent marking strategy across all transports, as each router could apply different CoS markings based on local configuration, violating the design requirement for consistency. Option C is wrong because using MPLS EXP markings for MPLS transport and IP Precedence for Internet transport creates an inconsistent marking strategy across transports, and IP Precedence is a legacy field that does not provide the granularity of DSCP, which is required for proper DiffServ behavior. Option D is wrong because NBAR2 is a classification tool that can identify applications, but it does not define the QoS policy type or marking strategy; it would need to be combined with a centralized policy to ensure consistent marking, and the question specifically asks for the policy type and marking approach, not just classification.

1046
MCQhard

A company has a network with multiple VLANs connected via a Layer 3 switch acting as the gateway for all VLANs. The network uses Rapid PVST+ for spanning tree. Recently, the network team added a new access switch to VLAN 100. After the switch was connected, users in VLAN 100 experienced intermittent connectivity, and the Layer 3 switch logs show 'SPANTREE-2-ROOTGUARD_BLOCK' messages for the port connected to the new switch. The new switch is intended to provide additional access ports for VLAN 100. The network team ensured that the new switch's configuration is correct for VLAN 100 access. What is the most likely cause of the issue, and what action should be taken to resolve it?

A.Change the port configuration on the new switch to access mode for VLAN 100.
B.Disable Root Guard on the Layer 3 switch port connected to the new switch.
C.Configure the new switch with a higher bridge priority (e.g., 28672) to prevent it from becoming the root bridge.
D.Remove the new switch from the network because it is causing a BPDU attack.
AnswerC

Configuring the new switch with a higher bridge priority (e.g., 28672) ensures that its BPDUs are inferior to those of the current root bridge, so Root Guard on the Layer 3 switch port will no longer block the port. Since bridge priority is the first criterion in root bridge election, setting a value like 28672 (higher than the current root's priority) makes the new switch a non-root candidate. This resolves the root guard blocking while keeping the new switch operational and preserving the intended spanning-tree topology.

Why this answer

The issue is that the new switch, intended as an access switch, has a lower bridge priority (or default priority of 32768) than the existing root bridge for VLAN 100. When connected, it becomes the new root bridge, causing topology changes and intermittent connectivity. Root Guard on the Layer 3 switch port detects this superior BPDU and blocks the port to protect the root bridge position.

Configuring the new switch with a higher bridge priority (e.g., 28672) ensures it cannot become the root bridge, resolving the Root Guard blocks.

Exam trap

Cisco often tests the misconception that Root Guard is the problem and should be disabled, when in fact the root cause is the new switch's bridge priority being too low, and the correct fix is to adjust the priority on the new switch.

How to eliminate wrong answers

Option A is wrong because the port is already configured as an access port for VLAN 100 (the team verified correct configuration), and changing it again would not address the root bridge election issue. Option B is wrong because disabling Root Guard would allow the new switch to become the root bridge, causing the same intermittent connectivity and potential instability; Root Guard is a protective feature, not the cause. Option D is wrong because the new switch is not causing a BPDU attack; it is simply sending superior BPDUs due to its default bridge priority, which is a normal behavior that Root Guard is designed to protect against.

1047
MCQhard

An enterprise is deploying a virtualized network function (VNF) for a next-generation firewall on a KVM-based hypervisor. The architect must ensure that the VNF can handle high throughput without CPU bottlenecks. Which hypervisor configuration technique should the architect use to dedicate physical CPU cores to the VNF?

A.Enable CPU overcommitment to allow the VNF to use any available CPU cycles.
B.Configure NUMA pinning and CPU pinning to dedicate physical cores to the VNF's virtual CPUs.
C.Use VMware vSphere instead of KVM for better VNF performance.
D.Increase the number of virtual CPUs assigned to the VNF to improve throughput.
AnswerB

Configuring NUMA pinning and CPU pinning dedicates physical CPU cores and ensures their memory is allocated on the same NUMA node, giving the VNF exclusive, non-overlapping access to compute resources. In KVM, NUMA pinning binds each virtual CPU to a specific host core and the VM’s memory to a local NUMA node, avoiding expensive remote memory accesses and eliminating hypervisor scheduler contention. This deterministic resource allocation is essential for high-throughput SD-WAN VNFs, which need stable forward rates and low jitter under load. It is the recommended NFV performance practice over any other tuning option.

Why this answer

CPU pinning (also called CPU affinity) binds specific virtual CPUs (vCPUs) of the VNF to dedicated physical CPU cores, eliminating context-switching overhead and ensuring deterministic performance. NUMA pinning further aligns vCPUs and memory with the same Non-Uniform Memory Access node, reducing latency. This configuration is critical for VNFs like next-generation firewalls that require high throughput and low jitter.

Exam trap

Cisco often tests the misconception that simply increasing vCPU count (Option D) or enabling overcommitment (Option A) can solve performance issues, when in reality, dedicated core assignment via pinning is required for deterministic VNF throughput.

How to eliminate wrong answers

Option A is wrong because CPU overcommitment allows multiple VMs to share physical cores, which can lead to CPU contention and performance bottlenecks, exactly the opposite of what is needed for high-throughput VNFs. Option C is wrong because the question explicitly asks about a KVM-based hypervisor, and recommending VMware vSphere does not solve the configuration requirement; it also implies a platform change rather than a configuration technique. Option D is wrong because simply increasing the number of vCPUs without pinning them to dedicated cores can cause excessive scheduling overhead and cache thrashing, degrading throughput rather than improving it.

1048
MCQmedium

What is the default multicast group range for Source-Specific Multicast (SSM) as defined by IANA and supported by Cisco IOS?

A.224.0.0.0/4
B.232.0.0.0/8
C.239.0.0.0/8
D.233.0.0.0/8
AnswerB

232.0.0.0/8 is the default and IANA-assigned range for Source-Specific Multicast (SSM), as defined in RFC 4607. In SSM, receivers explicitly subscribe to a specific source and group using the (S,G) notation, and this dedicated /8 prefix ensures that globally unique SSM groups are used consistently across the Internet. This range is the correct answer because it is exclusively reserved for SSM operations, unlike other multicast blocks that serve different purposes. Cisco devices and other routers recognize 232/8 as the default SSM range when SSM is enabled.

Why this answer

The IANA has reserved the 232.0.0.0/8 address range for Source-Specific Multicast (SSM), and Cisco IOS supports this default allocation. SSM uses (S,G) state, where receivers subscribe to a specific source's traffic for a group in this range, eliminating the need for a shared tree and RP. This is defined in RFC 4607.

Exam trap

Cisco often tests the distinction between the SSM range (232.0.0.0/8) and the administratively scoped range (239.0.0.0/8), as candidates frequently confuse the two due to both being 'special' multicast ranges.

How to eliminate wrong answers

Option A is wrong because 224.0.0.0/4 is the entire IPv4 multicast address space, not the SSM-specific range. Option C is wrong because 239.0.0.0/8 is the Administratively Scoped (private) multicast range, used for local or limited-scope multicast, not SSM. Option D is wrong because 233.0.0.0/8 is the GLOP addressing range (RFC 3180), used for statically assigned multicast addresses based on AS numbers, not SSM.

1049
Drag & Dropmedium

Drag and drop the steps of GET VPN key server registration and rekey into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In GET VPN, a group member (GM) first registers with the key server (KS) using ISAKMP. The KS authenticates the GM and then pushes the current policy and encryption keys (TEK and KEK) to the GM. The KS periodically sends a rekey message to all GMs to update the keys before they expire.

1050
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor a campus network. The administrator notices that the health score for a particular building has dropped significantly. Which feature of Cisco DNA Center Assurance should the administrator use to identify the root cause of the issue by analyzing network events and device performance metrics over time?

A.AI Network Analytics
B.Assurance Issues
C.Network Health Dashboard
D.Path Trace
AnswerA

AI Network Analytics in Cisco DNA Center uses machine learning to analyze historical network data, including device performance metrics and events, to identify anomalies and root causes. It can correlate data over time, detect trends, and provide insights into why a health score dropped, making it the appropriate tool for this scenario.

Why this answer

AI Network Analytics leverages machine learning to process large volumes of historical data, including device performance metrics and network events, to identify the root cause of health score degradation. Unlike dashboards or path trace tools that provide current state or connectivity views, AI Network Analytics correlates past and present data to uncover underlying issues, making it the correct choice for deep root cause analysis.

Exam trap

The trap here is confusing the high-level health dashboard with deep analytics; the dashboard shows symptoms, while AI Network Analytics provides the machine learning-driven root cause analysis needed to understand why a health score dropped.

Page 13

Page 14 of 26

Page 15