Courseiva

ENCOR 350-401 (350-401) — Questions 1051–1125

1923 questions total · 26pages · All types, answers revealed

Page 14

Page 15 of 26

Page 16
1051
MCQmedium

A company has a campus network with two distribution switches (DSW1 and DSW2) connected via a Layer 2 trunk. Each distribution switch connects to two access switches. Spanning Tree Protocol (STP) is running with default settings. Recently, a network administrator added a new access switch (ASW3) and connected it to both distribution switches. After the connection, network performance degraded significantly, and users in VLAN 10 reported intermittent connectivity. The administrator checked the logs and saw multiple TCN notifications. What is the most likely cause of the issue?

A.The new switch is causing a Layer 2 loop due to redundant links without proper STP configuration.
B.The new switch is not configured with the same VLANs as the distribution switches.
C.The new switch has a lower bridge priority than the current root bridge.
D.The new switch has become the root bridge and is sending inferior BPDUs.
AnswerA

A Layer 2 loop occurs when redundant paths exist without Spanning Tree Protocol actively blocking one of them. The new switch, if connected with multiple links to the distribution switches and STP disabled or misconfigured, will forward broadcast frames out all ports, causing a broadcast storm. This leads to severe symptoms such as high CPU utilization on all switches, MAC address table flapping, and complete network unavailability.

Why this answer

When ASW3 is connected to both DSW1 and DSW2 via Layer 2 trunk links, it creates a physical loop in the network. With default STP settings, the new switch will participate in the spanning tree algorithm, but the sudden addition of redundant links can cause a temporary loop or instability until STP converges. The multiple TCN (Topology Change Notification) messages indicate that the spanning tree topology is flapping, leading to MAC address table flushes and intermittent connectivity for VLAN 10 users.

This is the classic symptom of a Layer 2 loop caused by redundant links without proper STP configuration or before convergence completes.

Exam trap

Cisco often tests the distinction between a Layer 2 loop causing TCN flapping and a root bridge election, where candidates mistakenly think a new root bridge is the primary problem rather than the redundant physical loop itself.

How to eliminate wrong answers

Option B is wrong because mismatched VLANs would cause traffic to be dropped or not forwarded, but would not generate TCN notifications or cause a Layer 2 loop; TCNs are triggered by changes in the spanning tree topology, not by VLAN mismatches. Option C is wrong because a lower bridge priority would make the new switch more likely to become the root bridge, but that alone does not cause a loop or performance degradation; STP would still converge and block redundant ports. Option D is wrong because if the new switch becomes the root bridge, it sends superior BPDUs (not inferior), and while this would cause a topology change, it would not inherently create a loop or cause the severe performance degradation described; the issue is the physical loop, not the root bridge election.

1052
MCQhard

A network engineer is using Cisco DNA Center Assurance to monitor a network with Cisco SD-Access fabric. The engineer notices that the fabric health score is consistently low, but individual device health scores are high. Which component of the fabric should the engineer investigate first?

A.Underlay network devices
B.Fabric control plane nodes
C.Wireless LAN controllers
D.Fabric edge nodes
AnswerB

In a Cisco SD-Access fabric, the control plane nodes (running LISP) are critical for overlay reachability. If the fabric health score is low while device health scores are high, the issue likely lies in the fabric control plane, such as LISP map-server/ map-resolver problems or inconsistent fabric domain configurations. This can cause overlay connectivity issues without affecting individual device health.

Why this answer

In Cisco SD-Access, the fabric health score reflects the health of the overlay and control plane. If individual device health scores are high but fabric health is low, the issue is likely with fabric control plane nodes (LISP map-server/map-resolver) or overlay tunnels. These components are critical for fabric operation but may not affect individual device health scores.

Investigating control plane nodes first is the logical step to identify misconfigurations or failures in the fabric overlay.

Exam trap

The trap here is focusing on underlay or edge devices because they are more tangible, but the fabric health score specifically highlights control plane and overlay issues that don't degrade individual device health.

1053
Drag & Dropmedium

Drag and drop the steps of Ansible playbook execution flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Ansible playbook execution begins with inventory parsing to identify target hosts, then loads variables from group_vars/host_vars. Next, it gathers facts from the managed nodes, applies tasks from the playbook in order, and finally runs post-task handlers if notified.

1054
MCQhard

A network engineer is deploying a wireless mesh network using outdoor access points. The mesh APs are configured to use 802.11a/n on the 5 GHz band for backhaul and 802.11b/g/n on the 2.4 GHz band for client access. The engineer notices that the mesh backhaul links are unstable and have high packet loss. What is the most likely cause of the instability?

A.The 5 GHz band is being used for both backhaul and client access, causing co-channel interference.
B.The 802.11a/n standard is obsolete and does not support mesh networking.
C.The mesh APs require a wired Ethernet connection to the root AP.
D.The 2.4 GHz band provides better range for backhaul than the 5 GHz band.
AnswerD

The 2.4 GHz band offers superior range and wall penetration compared to 5 GHz due to its longer wavelength and lower free-space path loss at equivalent transmit power. Using 5 GHz for backhaul likely results in marginal signal strength at the receiving AP, causing intermittent instability as environmental attenuation fluctuates. In contrast, 2.4 GHz would provide a more robust, stable backhaul link, even though it has fewer non-overlapping channels.

Why this answer

The instability is most likely due to the use of the 5 GHz band for backhaul. While 5 GHz offers higher throughput, it has significantly shorter range and greater attenuation than 2.4 GHz. In an outdoor mesh network, APs may be spaced far apart, and obstacles can cause packet loss on the 5 GHz link.

The 2.4 GHz band would provide better range and stability for backhaul, making option D the correct answer.

Exam trap

Candidates may assume that co-channel interference is always the culprit when mesh backhaul is unstable. However, in this scenario, the backhaul is on a dedicated radio using 5 GHz, so interference is unlikely. The real trap is overlooking the range limitations of the 5 GHz band and assuming that higher frequency always performs better for backhaul.

How to eliminate wrong answers

Option B is wrong because 802.11a/n is not obsolete; it is widely used for mesh backhaul due to its higher throughput and less congested 5 GHz spectrum, and it fully supports mesh networking when configured properly. Option C is wrong because mesh APs are designed to operate wirelessly and do not require a wired Ethernet connection to the root AP; they use wireless backhaul links to form the mesh topology. Option D is wrong because the 2.4 GHz band generally offers better range but lower throughput and is more prone to interference, making it less suitable for backhaul than the 5 GHz band, which provides higher capacity and is the typical choice for mesh backhaul links.

1055
MCQmedium

A network engineer runs the following command on a Cisco WLC: WLC# show ap config general AP-2 AP Name: AP-2 MAC Address: aabb.cc00.0200 Country Code: US - United States Regulatory Domain: 802.11bg: -A 802.11a: -A AP Submode: FlexConnect AP Mode: FlexConnect AP Join Priority: 2 Primary Controller: WLC-1 Secondary Controller: WLC-2 Tertiary Controller: WLC-3 Based on this output, what can be concluded?

A.The AP is operating in Local mode and will tunnel all traffic to the WLC.
B.The AP can locally switch client traffic and maintain connectivity even if the WLC is unreachable.
C.The AP will only work if the WLC is directly connected at Layer 2.
D.The AP is in Monitor mode and will not serve clients.
AnswerB

This is the correct choice. A FlexConnect AP can switch wireless client traffic directly on its wired interface, which removes the need to backhaul user frames to the WLC. If the CAPWAP control tunnel to the WLC is lost, the AP enters standalone mode and continues to serve the locally switched WLANs, ensuring client connectivity for remote branch sites. This resilient behavior is the primary design goal of FlexConnect, distinguishing it from Local mode.

Why this answer

The output shows 'AP Submode: FlexConnect' and 'AP Mode: FlexConnect', which indicates the AP is operating in FlexConnect mode. In FlexConnect mode, the AP can locally switch client traffic (data plane) and maintain client connectivity even if the WLC becomes unreachable, as the control plane is separated from the data plane. This is a key characteristic of FlexConnect, unlike Local mode where all traffic must be tunneled to the WLC.

Exam trap

Cisco often tests the distinction between AP modes, and the trap here is that candidates see 'AP Mode: FlexConnect' but mistakenly associate it with Local mode behavior (tunneling all traffic) or assume the AP must be directly connected at Layer 2, when in fact FlexConnect is designed for remote sites with Layer 3 connectivity.

How to eliminate wrong answers

Option A is wrong because the AP is in FlexConnect mode, not Local mode; Local mode requires all client traffic to be tunneled to the WLC via CAPWAP, but FlexConnect allows local switching. Option C is wrong because FlexConnect APs can operate across Layer 3 boundaries and do not require a direct Layer 2 connection to the WLC; they use CAPWAP control plane over any routed path. Option D is wrong because the AP is in FlexConnect mode, not Monitor mode; Monitor mode is used for wireless security scanning and does not serve clients, whereas FlexConnect APs serve clients and can locally switch traffic.

1056
MCQmedium

An engineer is deploying a wireless network in a hospital that requires strict security and client isolation. The network must support 802.1X authentication for employees and a separate guest SSID with a captive portal. The engineer configures the WLC with RADIUS servers for 802.1X and a local web server for the captive portal. However, guest users can access the internal network after authentication. What configuration change is needed?

A.Enable client isolation (peer-to-peer blocking) on the guest SSID.
B.Configure 802.1X authentication for the guest SSID as well.
C.Apply a VLAN ACL on the guest VLAN to block access to internal subnets.
D.Place the guest SSID on the same VLAN as the employee SSID.
AnswerC

Applying a VLAN ACL on the guest VLAN is the correct fix because it filters traffic at Layer 3/4 on the VLAN's SVI, allowing you to explicitly deny any traffic destined to internal subnets (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) while permitting public internet access. Unlike wireless features, this ACL is enforced regardless of the access point or client type, and it operates after the client has already obtained an IP address. It provides centralized, rule-based protection for the entire guest network segment.

Why this answer

Applying a VLAN ACL on the guest VLAN explicitly blocks traffic from the guest wireless network to the internal subnets. This ensures that after captive portal authentication, guest users cannot access internal resources. Option A is incorrect because client isolation (peer-to-peer blocking) only prevents wireless clients from communicating with each other on the same SSID; it does not block traffic from wireless clients to wired hosts on the internal network.

Option B is incorrect because 802.1X authentication is for employees, and requiring it for guests would defeat the purpose of an open guest SSID with captive portal. Option D is incorrect because placing the guest SSID on the same VLAN as the employee SSID would give guest users Layer 2 access to internal hosts, which is exactly what needs to be prevented.

Exam trap

A common misconception is that enabling client isolation on a guest SSID is sufficient to prevent guest users from accessing the internal network. In reality, client isolation only blocks wireless client-to-client communication, not traffic to wired hosts. The correct approach is to apply a VLAN ACL or use a separate VLAN with firewall rules to restrict access to internal subnets.

How to eliminate wrong answers

Option A is wrong because client isolation (peer-to-peer blocking) only prevents wireless clients on the same SSID from communicating with each other; it does not block traffic from the guest VLAN to the internal wired network. Option B is wrong because configuring 802.1X for the guest SSID would defeat the purpose of a captive portal for guests and does not address the need to isolate guest traffic from internal resources. Option D is wrong because placing the guest SSID on the same VLAN as the employee SSID would eliminate isolation entirely, allowing guests unrestricted access to internal subnets and violating security requirements.

1057
MCQeasy

A network engineer runs the following command on Switch SW3: SW3# show etherchannel load-balance EtherChannel Load-Balancing Configuration: src-dst-ip EtherChannel Load-Balancing Operational State: src-dst-ip Based on this output, what can be concluded?

A.The switch uses source MAC and destination MAC for load balancing.
B.The load-balancing method is based on source and destination IP addresses.
C.The operational state differs from the configured state, indicating a problem.
D.The switch is using round-robin to distribute traffic across ports.
AnswerB

The load-balancing method is 'src-dst-ip', meaning the switch hashes the source IP and destination IP fields to select a member link. This ensures that packets belonging to the same IP flow always traverse the same port, preserving packet ordering while distributing different flows across the bundle. This is a Layer 3 hash, commonly used for routed or L3-switched EtherChannels.

Why this answer

The command output shows both the configured and operational load-balancing method as 'src-dst-ip', which means the switch uses a hash of both the source and destination IP addresses to select the EtherChannel link. This is the correct interpretation because 'src-dst-ip' explicitly indicates IP-based load balancing, not MAC-based or round-robin.

Exam trap

Cisco often tests the distinction between MAC-based and IP-based load balancing, and candidates may confuse 'src-dst-ip' with 'src-dst-mac' or incorrectly assume that the operational state must always match the configured state (which is true here, but the trap is that some candidates think a mismatch is normal).

How to eliminate wrong answers

Option A is wrong because 'src-dst-ip' refers to source and destination IP addresses, not MAC addresses; MAC-based load balancing would show 'src-dst-mac'. Option C is wrong because the configured and operational states both show 'src-dst-ip', meaning they match, so there is no problem. Option D is wrong because EtherChannel does not use round-robin; it uses a hash algorithm (e.g., XOR of source and destination IP) to deterministically select a link, not a per-packet round-robin.

1058
MCQmedium

An engineer configures gRPC dial-out telemetry on a Cisco IOS-XE device: ``` telemetry ietf subscription 100 receiver ip address 10.1.1.100 port 50051 protocol grpc-tcp source-address 10.1.1.1 encoding encode-kvgpb filter xpath /interfaces/interface/state/counters update-policy periodic 10000 ``` What is the purpose of the 'source-address' command?

A.It specifies the IP address of the telemetry receiver.
B.It specifies the source IP address for the telemetry stream.
C.It enables the device to receive telemetry data from the receiver.
D.It specifies the IP address of the network management station.
AnswerB

The source-address command sets the local IP the IOS-XE device uses as the origin of its gRPC dial-out connection, so the collector at 10.1.1.100 sees telemetry arriving from 10.1.1.1 rather than an arbitrary egress interface address.

Why this answer

The 'source-address' command specifies the IP address that the device uses as the source IP when sending telemetry data to the receiver. This ensures that the receiver can identify the device and that the traffic is sourced from a specific interface.

1059
MCQhard

A network engineer is configuring a Cisco ASA firewall with a site-to-site VPN to a remote peer. The engineer wants to ensure that only specific subnets are encrypted and that traffic from other subnets is not sent through the tunnel. Which configuration element defines the traffic that will be protected by the VPN?

A.The IKEv2 proposal and policy settings.
B.The crypto ACL (access list) referenced in the crypto map.
C.The tunnel-group configuration for the remote peer.
D.The group-policy applied to the VPN connection.
AnswerB

The crypto ACL defines the interesting traffic that will be encrypted and sent through the VPN tunnel. It specifies source and destination subnets that are permitted, and only matching traffic is protected. On Cisco ASA, this ACL is referenced in the crypto map entry. It is the correct element to control which subnets are encrypted, as required by the scenario.

Why this answer

In a site-to-site VPN on Cisco ASA, the crypto ACL (also called the interesting traffic ACL) defines which source and destination subnets are encrypted and sent through the tunnel. Only traffic matching this ACL is protected; other traffic is sent in clear text or dropped based on interface ACLs. The tunnel-group, group-policy, and IKEv2 proposals handle peer authentication and encryption parameters, but not traffic selection.

Exam trap

The trap here is assuming that the tunnel-group or IKEv2 proposals define the traffic to be encrypted, when in fact the crypto ACL is the sole determinant of interesting traffic.

1060
MCQhard

A network engineer is automating the configuration of VLANs on a Cisco Nexus 9000 switch using Python and the NX-API. The engineer sends a Python dictionary with the CLI commands to the API and receives a successful response. However, when checking the switch, the VLANs are not created. The engineer verifies that the credentials and IP address are correct, and the API is enabled. The engineer also notices that the API response contains a 'code' field of '200' and a 'result' field that shows the command output. What is the most likely cause of the issue?

A.The API response code of 200 indicates an error, and the engineer should check for a different status code.
B.The VLAN commands are incorrect; the engineer should use 'vlan 10' instead of 'vlan 10-20'.
C.The engineer used the 'show' message type in the API request instead of 'cli_conf'.
D.The switch requires a 'commit' command after configuration changes via NX-API.
AnswerC

In NX-API, the `type` field in the request payload determines how the switch processes the command. Sending `show` (or `cli_show`) tells the API to execute a read-only show command and return its output, so configuration commands are never executed and the switch configuration remains unchanged. To apply configuration changes, the engineer must set the message type to `cli_conf`, which places the switch in global configuration mode and executes the supplied commands. This mismatch between the API message type and the intended operation is the root cause of the problem.

Why this answer

The NX-API requires the 'message' type to be set to 'cli_conf' for configuration commands. Using 'show' (the default) only executes show commands and returns output, but does not apply any configuration changes to the switch. Even though the API returns a 200 status code and command output, the configuration is not actually committed.

Exam trap

Cisco often tests the distinction between 'cli_show' and 'cli_conf' message types in NX-API, trapping candidates who assume a 200 response and command output guarantee that configuration changes were applied.

How to eliminate wrong answers

Option A is wrong because an HTTP 200 status code indicates a successful API call, not an error; the issue is not with the response code but with the request type. Option B is wrong because the 'vlan 10-20' syntax is valid in Cisco NX-OS for creating a range of VLANs, so the command itself is not incorrect. Option D is wrong because Cisco Nexus 9000 switches running NX-OS do not require an explicit 'commit' command for NX-API configuration changes; the configuration is applied immediately when using the correct 'cli_conf' message type.

1061
Matchingmedium

Drag and drop each YANG module on the left to its matching standard body on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

OpenConfig

IETF

Cisco-IOS-XE

OpenConfig

IETF

Why these pairings

OpenConfig: vendor-neutral YANG models. IETF: RFC-based YANG models. Cisco-IOS-XE: Cisco proprietary YANG models for IOS-XE.

1062
MCQmedium

A network engineer is deploying Cisco DNA Center Assurance to monitor a campus network. The engineer wants to leverage machine learning to baseline normal behavior and detect anomalies without manually defining thresholds. Which capability should be enabled?

A.Network Time Travel
B.Path Trace
C.AI Network Analytics
D.Sensor-driven tests
AnswerC

AI Network Analytics in Cisco DNA Center uses machine learning to establish a dynamic baseline of normal network behavior and detect anomalies without manual thresholds. It continuously learns from telemetry and surfaces deviations, directly matching the engineer's goal of automated anomaly detection.

Why this answer

AI Network Analytics is the Cisco DNA Center Assurance feature that applies machine learning to create baselines and detect anomalies without manual thresholds. It continuously analyzes telemetry to identify deviations, which aligns with the engineer's goal of automated, threshold-free monitoring.

Exam trap

The trap here is confusing historical or diagnostic tools like Time Travel or Path Trace with the machine-learning baselining engine that actually performs anomaly detection.

1063
MCQhard

An engineer is writing a Python script to parse the output of 'show ip interface brief' from multiple Cisco routers. The engineer uses the netmiko library to collect the output and then uses regular expressions to extract the interface name, IP address, and status. The script works correctly for most routers, but on one router, the output format is slightly different (e.g., extra spaces or different column headers). The engineer wants to make the parsing more robust. What is the best approach?

A.Write a custom parser that handles each router's output format individually.
B.Use the 'split()' method to tokenize each line and then extract the relevant fields by position.
C.Use the 'textfsm' library with a pre-defined template for 'show ip interface brief'.
D.Use the 're' module with a more complex regular expression that accounts for optional whitespace.
AnswerC

The TextFSM library with a pre-defined template is correct because it applies a state-machine-driven set of regex rules to map the human-readable 'show ip interface brief' output into structured values like interface, IP address, status, and protocol. Templates are reusable across different IOS versions and even between vendors because they tolerate extra spaces and optional lines, and they produce clean lists of dictionaries for Jinja2 or Netmiko workflows. This is the standard approach used by ntc-templates and Ansible for reliable CLI parsing.

Why this answer

TextFSM is specifically designed to parse semi-structured CLI output from network devices. By using a pre-defined template for 'show ip interface brief', the engineer can handle variations in whitespace, column headers, and formatting without writing custom code for each router. This approach is more maintainable and robust than manual parsing methods.

Exam trap

Cisco often tests the misconception that regular expressions alone are sufficient for parsing CLI output, but the trap here is that TextFSM is the industry-standard tool for robustly handling semi-structured network device output, not just regex or positional splitting.

How to eliminate wrong answers

Option A is wrong because writing a custom parser for each router's output format is not scalable and defeats the purpose of automation; it introduces high maintenance overhead and does not leverage existing parsing libraries. Option B is wrong because using the 'split()' method to tokenize lines by position assumes a fixed column layout, which fails when extra spaces or different column headers shift field positions. Option D is wrong because using a more complex regular expression with optional whitespace can become brittle and hard to maintain as output variations increase; it does not handle structural changes like different column headers or missing fields gracefully.

1064
MCQmedium

Analyze this NAT configuration: ``` ip nat pool GLOBAL 203.0.113.10 203.0.113.20 netmask 255.255.255.0 ip nat inside source list 1 pool GLOBAL overload access-list 1 permit 192.168.1.0 0.0.0.255 ``` Which statement is correct?

A.Traffic from 192.168.1.0/24 is translated to addresses in the range 203.0.113.10-20, using PAT.
B.Each host in 192.168.1.0/24 gets a unique IP from the pool without port translation.
C.The pool must include the outside interface IP address.
D.Access-list 1 is used to filter inbound traffic.
AnswerA

This is correct. The ACL identifies inside source addresses 192.168.1.0/24, and the ip nat pool command creates a public address range 203.0.113.10–20. The overload keyword activates Port Address Translation, permitting many inside hosts to share those 11 addresses simultaneously by rewriting source ports, rather than requiring a one-to-one mapping.

Why this answer

The configuration uses a NAT pool with the 'overload' keyword, which enables Port Address Translation (PAT). Access-list 1 matches the inside local network 192.168.1.0/24, and the 'ip nat inside source list 1 pool GLOBAL overload' command translates multiple inside hosts to the pool addresses (203.0.113.10–20) using unique port numbers, allowing many hosts to share a single public IP.

Exam trap

Cisco often tests the distinction between dynamic NAT (one-to-one mapping without overload) and PAT (many-to-one with overload); the trap here is that candidates may overlook the 'overload' keyword and assume each host gets a unique IP from the pool.

How to eliminate wrong answers

Option B is wrong because the 'overload' keyword explicitly enables PAT, so each host does not get a unique IP; instead, multiple hosts share pool addresses via port translation. Option C is wrong because the NAT pool does not need to include the outside interface IP address; the pool defines a separate range of global addresses, and the outside interface can have a different IP. Option D is wrong because access-list 1 is used to identify inside source traffic for translation, not to filter inbound traffic; inbound filtering would require a different access-list applied to an interface.

1065
MCQmedium

A network engineer runs the following command on Router R3: R3# show mls qos interface GigabitEthernet0/1 GigabitEthernet0/1 trust state: trust DSCP trust mode: trust dscp COS override: dis default COS: 0 DSCP Mutation Map: default dscp mutation map trust device: none qos mode: port-based R3# show mls qos QoS is enabled globally QoS global counters: total packets not matching QoS criteria = 0 Total packets with known CoS = 0 Total packets dropped by policing = 0 Based on this output, what can be concluded?

A.The interface is configured to trust CoS values.
B.The interface will overwrite incoming DSCP values with default CoS.
C.The interface trusts the DSCP markings of incoming packets.
D.QoS is disabled globally.
AnswerC

The command output states 'trust state: trust DSCP' and 'trust mode: trust dscp', confirming that the interface is configured to honor the DSCP markings carried in the IP header of incoming packets. In this mode, the switch classifies each packet according to its DSCP value and maps that value to the appropriate QoS queue or policy, without altering the original DSCP field.

Why this answer

The output shows 'trust state: trust DSCP' and 'trust mode: trust dscp', which explicitly indicates that the interface trusts the DSCP markings of incoming packets. Additionally, 'qos mode: port-based' confirms that QoS is enabled on the interface, and the global QoS status shows 'QoS is enabled globally'. Therefore, the interface will preserve and use the incoming DSCP values for QoS classification.

Exam trap

Cisco often tests the distinction between 'trust DSCP' and 'trust CoS'—the trap here is that candidates may confuse the 'trust state: trust DSCP' output with trusting CoS, especially when the 'default COS' field is present, leading them to incorrectly select Option A or B.

How to eliminate wrong answers

Option A is wrong because the interface trusts DSCP, not CoS; 'trust state: trust DSCP' and 'COS override: dis' confirm that CoS values are not trusted. Option B is wrong because the interface does not overwrite incoming DSCP values; 'trust mode: trust dscp' means DSCP values are preserved, and 'default COS: 0' only applies when no trust is set. Option D is wrong because the output explicitly states 'QoS is enabled globally' and the interface shows 'qos mode: port-based', indicating QoS is active.

1066
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor the health of a wireless network. The administrator notices that a particular client device is experiencing frequent disconnects. Which Assurance feature should be used to view a chronological list of events related to that specific client, including association, authentication, and roaming events?

A.Sensor Test
B.Network Health Dashboard
C.Client 360
D.Application Health
AnswerC

Client 360 provides a comprehensive view of a specific client, including its connectivity history, onboarding events, and performance metrics. It shows a timeline of association, authentication, and roaming events, making it ideal for troubleshooting intermittent disconnects. The administrator can see exactly when the client disconnected and what happened during the process, enabling root cause analysis.

Why this answer

Client 360 in Cisco DNA Center Assurance offers a detailed, per-client view that includes a timeline of events such as association, authentication, and roaming. This feature allows the administrator to pinpoint when and why a client disconnected. Other Assurance features like the Network Health Dashboard or Application Health provide aggregate or application-level views, not the granular client event history required.

Therefore, Client 360 is the correct choice for troubleshooting a specific client's disconnects.

Exam trap

The trap here is confusing the Network Health Dashboard with Client 360; the dashboard shows overall health, but only Client 360 provides the detailed event timeline for a single client.

1067
MCQhard

A network architect is designing a Cisco ACI fabric for a multi-tenant data center. Tenants must be isolated at Layer 3, but some tenants require shared services such as a firewall and load balancer. Which Cisco ACI construct should the architect use to allow selective communication between tenants while maintaining isolation?

A.A VRF leak between the tenant VRFs using route targets
B.A bridge domain shared between tenants with a common subnet
C.A shared L3Out with a common EPG for all tenants
D.A contract between the tenant EPG and a shared services EPG in the common tenant
AnswerD

In Cisco ACI, the common tenant can host shared services EPGs, and contracts can be exported and consumed across tenants. This allows a tenant EPG to communicate with the shared firewall or load balancer while keeping other inter-tenant traffic isolated. The contract defines exactly which protocols and ports are permitted, satisfying both sharing and isolation.

Why this answer

Cisco ACI enables selective inter-tenant communication by placing shared services in the common tenant and using contracts that are exported and consumed by tenant EPGs. This preserves Layer 3 isolation between tenants while permitting only the traffic defined by the contract. The shared services EPG can be a firewall or load balancer, and the contract enforces the allowed protocols and ports.

Exam trap

The trap here is thinking that shared services require merging VRFs or bridge domains, when ACI actually provides cross-tenant contracts with the common tenant to maintain isolation.

1068
Matchingeasy

Drag and drop each leased line technology on the left to its matching speed on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

1.544 Mbps

2.048 Mbps

44.736 Mbps

155.52 Mbps

622.08 Mbps

Why these pairings

T1 = 1.544 Mbps, E1 = 2.048 Mbps, DS3 = 44.736 Mbps, OC-3 = 155.52 Mbps, OC-12 = 622.08 Mbps.

1069
MCQhard

A security team wants to protect a campus network from MAC flooding attacks that could overflow the CAM table on access switches. The requirement is to limit the number of source MAC addresses learned per switch port and to automatically err-disable a port when the limit is exceeded, while still allowing a VoIP phone and a PC on the same port. Which configuration approach meets these requirements?

A.Configure port security with the maximum parameter, sticky learning, and violation shutdown on each access port.
B.Configure storm control for unicast traffic at a low threshold on each access port.
C.Configure port security with the maximum parameter, sticky learning, and violation restrict on each access port.
D.Enable BPDU Guard and Root Guard on all access ports to block MAC flooding attempts.
AnswerA

Port security with a maximum MAC count enforces the learning limit, sticky learning dynamically records MACs into the running configuration, and the shutdown violation mode err-disables the port when the limit is exceeded. This directly satisfies the requirement to cap learned MAC addresses and automatically disable offending ports.

Why this answer

Port security limits the source MAC addresses that can be learned on a switch port. Setting a maximum value caps how many MACs are accepted, sticky learning stores dynamically learned addresses in the configuration, and the shutdown violation mode err-disables the port upon violation. Together these features neutralize MAC flooding while permitting a phone and PC by allowing at least two MACs.

Exam trap

The trap here is selecting the restrict violation mode, which logs and drops but never err-disables the port, failing the explicit requirement for automatic shutdown.

1070
MCQmedium

A network engineer is implementing a Zone-Based Firewall (ZBFW) on a Cisco IOS XE router. The router has three interfaces: inside (GigabitEthernet0/0), outside (GigabitEthernet0/1), and DMZ (GigabitEthernet0/2). The security policy requires that traffic from the inside zone to the outside zone be inspected, traffic from the outside zone to the DMZ be allowed only for HTTP and HTTPS, and all other traffic between zones be denied by default. Which configuration step is essential to achieve this policy?

A.Configure a single zone pair from inside to outside with an inspect policy and rely on implicit permit for other traffic.
B.Create a class map that matches HTTP and HTTPS traffic and apply it as a policy to the outside interface.
C.Apply an ACL to the outside interface to permit HTTP and HTTPS to the DMZ and deny all other traffic.
D.Assign interfaces to zones and create zone pairs with inspect policies for inside-to-outside and outside-to-DMZ.
AnswerD

This is the fundamental ZBFW configuration. Interfaces must be assigned to zones, and zone pairs define the direction of traffic flow. For traffic to be allowed, a zone pair must exist with a policy that inspects or passes traffic. The default action for inter-zone traffic is drop, so explicit policies are needed. This step is essential to meet the requirements of inspecting inside-to-outside and allowing only HTTP/HTTPS from outside to DMZ.

Why this answer

Zone-Based Firewall requires interfaces to be assigned to zones, and traffic between zones is controlled by zone pairs. Each zone pair has a policy that defines actions like inspect, pass, or drop. By default, inter-zone traffic is dropped, so explicit policies are needed for allowed traffic.

The correct configuration involves creating zones, assigning interfaces, and defining zone pairs with appropriate inspect policies for inside-to-outside and outside-to-DMZ, ensuring the default deny posture.

Exam trap

The trap here is thinking that an ACL or a single zone pair can satisfy all requirements, but ZBFW requires explicit zone pairs for each direction and default deny between zones.

1071
MCQmedium

Consider the following configuration snippet: policy-map QOS_POLICY class VOICE priority percent 30 class VIDEO bandwidth percent 20 queue-limit 50 packets class class-default fair-queue queue-limit 100 packets What is the effect of this configuration?

A.The VOICE class traffic is always sent before other classes, but if it exceeds 30% of the interface bandwidth, excess traffic is dropped.
B.The VOICE class traffic is always sent before other classes, and excess traffic beyond 30% is queued in the default class.
C.The VIDEO class traffic is treated with strict priority after the VOICE class.
D.The class-default uses Weighted Fair Queuing with a maximum queue size of 100 packets, and all classes share the remaining bandwidth equally.
AnswerA

The VOICE class is assigned strict priority through the `priority` command, so its packets are dequeued before any other class whenever the priority queue is non-empty. The `percent 30` keyword configures an aggregate policer that allows traffic up to 30% of the interface bandwidth and drops any excess immediately (conform-action transmit, exceed-action drop). This is a hard ceiling—excess voice traffic is not re-queued or forwarded, it is discarded on the spot.

Why this answer

The 'priority percent 30' command under the VOICE class enables strict priority queuing, meaning VOICE traffic is always transmitted before any other class. However, the priority queue is policed at 30% of the interface bandwidth; any traffic exceeding this rate is dropped, not queued. This is a fundamental behavior of the priority command in Cisco IOS — excess priority traffic is dropped to prevent starvation of other queues.

Exam trap

Cisco often tests the misconception that excess priority traffic is re-queued into the default class or another queue, when in fact it is always dropped to enforce the bandwidth limit and protect other traffic classes.

How to eliminate wrong answers

Option B is wrong because excess priority traffic beyond the configured percentage is dropped, not re-queued into the default class; the priority command does not allow excess traffic to fall back to another queue. Option C is wrong because the VIDEO class uses bandwidth percent 20, which is a non-priority queue (class-based weighted fair queuing), not strict priority; only the VOICE class has strict priority. Option D is wrong because the class-default uses fair-queue, but the remaining bandwidth is not shared equally among all classes — the VIDEO class has a guaranteed 20%, and the remaining bandwidth after VOICE and VIDEO is shared among the default class flows via fair-queuing, not equally across all classes.

1072
Drag & Dropmedium

Drag and drop the steps of NAT64 IPv6-to-IPv4 translation flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

NAT64 translates IPv6 packets to IPv4. The IPv6 host sends a packet to a synthetic IPv6 address, the router extracts the embedded IPv4 destination, creates a NAT64 binding, translates headers, and forwards the IPv4 packet.

1073
MCQhard

A large enterprise uses a centralized automation platform based on Ansible Tower to manage its network infrastructure. The network consists of 500 Cisco IOS XE routers and switches distributed across multiple sites. The automation team has created a playbook that configures BGP peerings on all devices. The playbook uses the ios_bgp module. Recently, during a maintenance window, the playbook was run against a subset of devices that were supposed to be upgraded to a new IOS XE version. However, after the run, several devices lost their BGP configurations entirely. The team discovers that the new IOS XE version introduced a new BGP configuration model that is not fully compatible with the ios_bgp module's expected CLI commands. The playbook failed silently on those devices, and the existing BGP configuration was removed. The team needs to prevent this from happening in future maintenance windows. Which action should be taken?

A.Add a pre-task that validates the device's OS version and conditionally applies the appropriate module or command set
B.Implement idempotency checks in the playbook using the 'check_mode' option
C.Set 'gather_facts: no' in the playbook to speed up execution and avoid version detection issues
D.Replace the ios_bgp module with the ios_config module and use raw CLI commands for BGP configuration
AnswerA

Running a pre-task that inspects ansible_net_version and then uses conditional logic to select either the native ios_bgp module or an alternative module (e.g., ios_config) ensures that the playbook aligns with the device's supported API and syntax. This avoids silent failures caused by module versions that do not recognize the running IOS release, and it is the recommended pattern for maintaining idempotent, OS-aware automation across a heterogeneous fleet.

Why this answer

It directly addresses the root cause: the new IOS XE version uses an incompatible BGP configuration model. By adding a pre-task that validates the OS version, the playbook can conditionally apply the correct module (e.g., ios_bgp for older versions or a different module/CLI for the new model), preventing silent failures and configuration loss. This ensures the automation adapts to version-specific changes, maintaining idempotency and safety.

Exam trap

Cisco often tests the misconception that idempotency (check_mode) or simply using raw CLI commands (ios_config) solves version incompatibility, when the real solution is version-aware conditional logic to handle model changes.

How to eliminate wrong answers

Option B is wrong because 'check_mode' only simulates changes without applying them; it does not prevent the ios_bgp module from removing existing BGP configs due to incompatibility, nor does it handle version-specific behavior. Option C is wrong because setting 'gather_facts: no' would skip version detection entirely, making the playbook blind to the OS version and increasing the risk of applying incompatible commands. Option D is wrong because replacing ios_bgp with ios_config and raw CLI commands bypasses Ansible's structured module logic, losing idempotency and validation, and still requires version-aware logic to avoid the same incompatibility issue.

1074
MCQmedium

A network engineer is troubleshooting a wireless connectivity issue in a campus network managed by Cisco DNA Center. The Assurance module shows that several access points have high client association failures. The engineer checks the wireless controller configuration and finds that the APs are registered and functional. What is the most likely cause of the association failures?

A.RF interference or poor signal-to-noise ratio on the affected APs.
B.The APs are not running the recommended firmware version.
C.The wireless controller has reached its maximum number of APs.
D.The DNA Center Assurance module is not properly configured to monitor wireless events.
AnswerA

With APs registered and functional, association failures point to the radio layer. RF interference or a poor signal-to-noise ratio prevents clients from completing association, which Cisco DNA Center Assurance surfaces as high client association failure counts on the affected APs.

Why this answer

High client association failures with functional, registered APs most commonly indicate RF-layer problems such as interference, poor SNR, or coverage gaps. Association failures occur when clients cannot complete the 802.11 association handshake, which is heavily dependent on RF signal quality. DNA Center Assurance would flag these as RF health issues rather than configuration or controller problems.

Exam trap

The trap is that candidates focus on configuration or software causes (firmware, controller limits, monitoring config) when the scenario explicitly states APs are registered and functional — pointing to the physical/RF layer as the remaining variable.

How to eliminate wrong answers

Option B is wrong because firmware version mismatches typically cause AP registration or feature failures, not client association failures — and the question states the APs are registered and functional. Option C is wrong because if the controller had reached its maximum AP capacity, the APs would not be registered at all, contradicting the scenario. Option D is wrong because if Assurance were not properly configured, it would not be showing the association failure data in the first place — the fact that it displays the failures means monitoring is working.

1075
MCQeasy

A network administrator is troubleshooting a Cisco Catalyst switch and suspects a Layer 2 loop. The administrator wants to verify the Spanning Tree Protocol (STP) topology and identify the root bridge. Which command should be used?

A.show mac address-table
B.show spanning-tree
C.show interfaces trunk
D.show cdp neighbors
AnswerB

The 'show spanning-tree' command displays the STP topology, including the root bridge, root port, designated ports, and port states. It is the primary command to verify STP operation and detect loops. On a Cisco Catalyst switch, this command provides detailed information for each VLAN, helping the administrator identify the root bridge and any blocked ports.

Why this answer

To verify STP topology and identify the root bridge, the 'show spanning-tree' command is the correct choice. It provides detailed output for each VLAN, including the root bridge ID, root path cost, and port roles. This allows the administrator to confirm the expected topology and detect any loops or misconfigurations.

Exam trap

The trap here is confusing MAC address table output with STP topology information; seeing the same MAC on multiple ports suggests a loop but does not confirm STP status.

1076
Drag & Dropmedium

Drag and drop the steps of NUMA-aware VM placement process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The order starts with enabling NUMA in the BIOS, then configuring the hypervisor, creating the VM with NUMA settings, and finally verifying placement and performance.

1077
MCQmedium

A network engineer is implementing a VXLAN overlay over an existing Layer 3 campus network. The requirement is to carry Layer 2 frames across the Layer 3 underlay. Which protocol is used to encapsulate the original Layer 2 frame for transport across the IP network?

A.802.1Q tagging on the underlay
B.MPLS label stack with a Layer 2 VPN
C.VXLAN with a UDP header
D.GRE with a protocol type of 0x6558
AnswerC

VXLAN encapsulates the original Layer 2 frame inside a MAC-in-UDP header. The 8-byte VXLAN header, UDP header, and outer IP header allow the frame to be routed across a Layer 3 underlay. This directly satisfies the scenario requirement to carry Layer 2 frames over an IP network.

Why this answer

VXLAN encapsulates the original Layer 2 frame in a MAC-in-UDP format. The outer IP and UDP headers allow the encapsulated frame to be routed across a Layer 3 underlay, which is exactly what the scenario requires. Other encapsulation methods either need a different underlay or do not provide the VXLAN VNI and VTEP behavior.

Exam trap

The trap here is assuming that any tunneling protocol can carry Layer 2 over Layer 3, when VXLAN specifically uses UDP encapsulation and a VNI, not GRE or MPLS.

1078
MCQeasy

A network administrator is using Cisco DNA Center to monitor a campus network. The administrator wants to receive an alert when a switch's CPU utilization exceeds 80% for more than 5 minutes. Which feature should be configured?

A.Issue definitions with custom severity
B.Assurance health score thresholds
C.Syslog forwarding to an external server
D.Assurance custom threshold rules
AnswerD

Assurance custom threshold rules in Cisco DNA Center allow you to define alerts based on specific metric thresholds, such as CPU utilization exceeding 80% for a sustained period. This directly matches the administrator's need to be notified when the condition persists for more than 5 minutes.

Why this answer

Custom threshold rules in Cisco DNA Center Assurance are designed to trigger alerts when a monitored metric crosses a defined threshold for a specified duration. Configuring a rule for CPU utilization above 80% for 5 minutes directly fulfills the administrator's requirement, unlike health score or issue-based features.

Exam trap

The trap here is assuming health scores or issue definitions can enforce a specific metric threshold, when only custom threshold rules provide that granular control.

1079
MCQmedium

A network engineer is using Cisco DNA Center to manage a network with multiple sites. The engineer wants to ensure that all devices at a remote site have the same NTP server configuration. The engineer creates a network profile with the NTP settings and assigns it to the site. After provisioning, the engineer checks one of the switches and finds that the NTP configuration is missing. What should the engineer check first?

A.Verify that the device is assigned to the correct site in DNA Center.
B.Check if the NTP server is reachable from the device.
C.Ensure that the device is running a supported IOS version.
D.Recreate the network profile with the correct NTP settings.
AnswerA

Network profiles bind settings such as NTP to a site, and DNA Center only pushes them to devices associated with that site. If the switch sits under a different site hierarchy, provisioning silently omits the NTP configuration, so verifying site assignment is the logical first check.

Why this answer

In Cisco DNA Center, network profiles with settings like NTP are applied to devices based on site assignment. If a device is not assigned to the correct site, the profile settings will not be provisioned to it. The first thing to verify is that the device is assigned to the intended site, because site assignment is the mechanism that binds network profiles to devices.

Exam trap

The trap is jumping to recreate the profile or check device-level issues when the most common root cause in DNA Center provisioning failures is a site assignment mismatch — the profile exists but isn't bound to the device.

How to eliminate wrong answers

Option B is wrong because NTP server reachability would affect time synchronization, not whether the NTP configuration is present on the device — the question states the configuration is missing entirely, indicating a provisioning issue, not a connectivity issue. Option C is wrong because an unsupported IOS version would typically cause provisioning failures or compatibility warnings, but the question implies other devices at the site were provisioned successfully, making site assignment the more likely culprit. Option D is wrong because recreating the network profile is premature — the profile was already created with the correct settings, and the issue is more likely that it wasn't applied to the device due to site assignment mismatch.

1080
Matchingmedium

Drag and drop each REST HTTP status code on the left to its matching meaning on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Request succeeded and response body contains data

New resource was created successfully

Request is malformed or invalid

Authentication credentials are missing or invalid

Requested resource does not exist

Why these pairings

200 OK indicates success, 201 Created indicates resource creation, 400 Bad Request indicates client error, 401 Unauthorized indicates authentication failure, 404 Not Found indicates missing resource, and 500 Internal Server Error indicates server failure.

1081
MCQmedium

A company is deploying a WAN with MPLS VPN and wants to ensure that customer traffic is isolated from other customers. Which technology is used to maintain separation in the MPLS core?

A.VLAN tagging
B.MPLS labels
C.IPsec tunnels
D.Virtual Routing and Forwarding (VRF)
AnswerD

Virtual Routing and Forwarding (VRF) creates separate, independent IP routing tables and associated forwarding tables on the Provider Edge (PE) router. Each VRF instance contains its own set of routes, interfaces, and routing protocol processes, ensuring that customer A's routing information is completely invisible to customer B. This table separation is how an MPLS L3VPN achieves routing isolation, even though both customers share the same physical backbone. When combined with route distinguishers (RDs) and route targets (RTs), VRF controls the import and export of routes into the VPN, thereby maintaining strict logical isolation across a shared MPLS core.

Why this answer

VRF (Virtual Routing and Forwarding) is the technology used in MPLS VPN to maintain customer traffic separation within the MPLS core. Each customer is assigned a unique VRF on the Provider Edge (PE) router, which maintains a separate routing table and forwarding instance, ensuring that traffic from one customer never crosses into another customer's routing domain. This separation is enforced at Layer 3, independent of the MPLS label switching that occurs in the core.

Exam trap

Cisco often tests the misconception that MPLS labels alone provide customer separation, but labels are only a forwarding mechanism; the actual isolation comes from VRF instances on the PE routers.

How to eliminate wrong answers

Option A is wrong because VLAN tagging (802.1Q) operates at Layer 2 and is used for segmenting traffic within a LAN or between switches, not for isolating customer traffic across an MPLS WAN core. Option B is wrong because MPLS labels are used for forwarding packets through the core based on label-switched paths (LSPs), but they do not inherently provide customer separation; labels are assigned per FEC and can be shared across customers without VRF. Option C is wrong because IPsec tunnels provide encryption and authentication for secure communication over untrusted networks, but they do not provide routing isolation or separate forwarding tables; they are a security mechanism, not a Layer 3 isolation technology.

1082
MCQmedium

A network architect is designing a campus fabric using Cisco SD-Access to centralize policy enforcement and simplify segmentation. The design must support endpoint groups for IoT devices and employees, with traffic policy applied consistently across wired and wireless. Which control plane component is responsible for maintaining the mapping between endpoint identifiers and their location in the fabric?

A.VXLAN tunnel endpoints
B.Cisco Identity Services Engine
C.LISP map-server and map-resolver
D.Cisco DNA Center fabric controller
AnswerC

LISP is the control plane protocol in SD-Access. The map-server registers endpoint EID-to-RLOC mappings from fabric edge nodes, and the map-resolver answers map requests from ingress tunnel routers. This enables scalable endpoint mobility and policy enforcement based on endpoint groups, exactly as required for IoT and employee segmentation across wired and wireless.

Why this answer

In Cisco SD-Access, the LISP control plane maintains the endpoint identifier to routing locator mappings. The map-server registers these mappings from fabric edge nodes, while the map-resolver responds to queries from ingress tunnel routers. This separation of control and data plane allows scalable endpoint mobility and consistent policy enforcement across wired and wireless fabric devices.

Exam trap

The trap here is confusing the SD-Access data plane encapsulation (VXLAN) with the control plane protocol (LISP) that actually holds the endpoint-to-location mappings.

1083
MCQmedium

An enterprise network uses OSPF as its IGP. The network engineer notices that a particular route learned via OSPF is not being installed in the routing table, even though the neighbor adjacency is up and the route appears in the OSPF database. The route is an external route redistributed from EIGRP. What is the most likely cause?

A.The OSPF process ID is different on the routers.
B.The external route has a higher administrative distance than the internal route.
C.The forwarding address in the type 5 LSA is not reachable via an OSPF internal route.
D.The OSPF metric for the external route is too high.
AnswerC

For redistributed external routes, OSPF installs the type 5 LSA only if the forwarding address is reachable through an OSPF internal route. If that address resolves via another protocol or not at all, the route stays in the database but never enters the routing table.

Why this answer

OSPF requires the forwarding address (FA) in a Type 5 LSA to be reachable via an OSPF internal route (intra-area or inter-area) for the external route to be installed in the routing table. If the FA is not reachable, the router will ignore the LSA and not install the route, even though the LSA exists in the OSPF database and the neighbor adjacency is up.

Exam trap

Cisco often tests the forwarding address reachability requirement for Type 5 LSAs, and the trap here is that candidates assume any route in the OSPF database will automatically be installed, ignoring the recursive lookup condition for external routes with a non-zero forwarding address.

How to eliminate wrong answers

Option A is wrong because the OSPF process ID is locally significant and does not affect route installation between routers; different process IDs can still form adjacencies and exchange routes. Option B is wrong because OSPF external routes (type 5) have a default administrative distance of 110, while internal OSPF routes also have 110; the issue is not about AD comparison between internal and external OSPF routes, but about reachability of the forwarding address. Option D is wrong because a high OSPF metric does not prevent route installation; it only influences route selection among multiple paths; the route will still be installed if the metric is valid and the forwarding address is reachable.

1084
MCQhard

A security architect is designing a network where endpoint identity and group membership must follow users and devices across both wired and wireless networks, and policy enforcement must be consistent regardless of VLAN or IP subnet. Which Cisco solution provides this identity-based, group-based access control?

A.Cisco AnyConnect with posture assessment only
B.Cisco Umbrella with DNS-layer security and SIG
C.Cisco TrustSec with Security Group Tags and Cisco ISE
D.Cisco Stealthwatch with NetFlow analytics
AnswerC

Cisco TrustSec assigns Security Group Tags to users and devices based on identity and group membership determined by Cisco ISE, and enforcement uses those tags rather than IP addresses or VLANs. This allows consistent policy across wired and wireless domains. Because tags travel with the traffic, access control remains intact even when subnets or VLANs change.

Why this answer

Cisco TrustSec uses Security Group Tags derived from identity and group information, typically populated by Cisco ISE, to enforce policy independent of IP addresses and VLANs. Because the tags travel with the traffic, consistent access control is maintained across wired and wireless networks, which matches the architect's requirements.

Exam trap

The trap here is confusing visibility and analytics products with enforcement technologies that actually tag and control traffic by identity.

1085
Matchingmedium

Drag and drop each WAN encapsulation on the left to its matching use case on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Cisco proprietary point-to-point serial encapsulation

Supports authentication and multilink on serial links

Encapsulation for DSL broadband connections

Legacy packet-switched WAN technology

Bundles multiple PPP links for increased bandwidth

Why these pairings

HDLC is Cisco proprietary and used for point-to-point serial links. PPP supports authentication and multilink. PPPoE is used for DSL broadband connections.

Frame Relay is a legacy packet-switched WAN technology. MLPPP bundles multiple PPP links.

1086
MCQmedium

A network engineer is writing a Python script to retrieve the operational state of all GigabitEthernet interfaces from a Cisco IOS XE device using RESTCONF. The device is configured with HTTPS and the engineer has valid credentials. The script uses the 'requests' library to send a GET request to the RESTCONF API. Which HTTP header must be included in the request to specify that the client expects JSON-formatted data in the response?

A.Accept: application/json
B.Content-Type: application/json
C.Content-Type: application/yang-data+json
D.Accept: application/yang-data+json
AnswerD

This header tells the RESTCONF server that the client expects the response body in JSON format according to the YANG data model. Cisco IOS XE RESTCONF uses the media type 'application/yang-data+json' for JSON-encoded YANG data. Without it, the server may return XML or an error. This is the correct header to include.

Why this answer

To retrieve JSON-formatted data from a RESTCONF API on Cisco IOS XE, the client must include the Accept header with the value 'application/yang-data+json'. This media type is defined by RFC 8040 for RESTCONF and ensures the server returns the response in JSON according to the YANG model. The Content-Type header is only for request bodies, and 'application/json' is not the correct media type for RESTCONF.

Exam trap

The trap here is confusing the Accept header, which specifies the desired response format, with the Content-Type header, which describes the request body format.

1087
MCQmedium

A network engineer is configuring a Cisco Catalyst switch port that connects to an IP phone. The phone must place voice traffic in VLAN 200 and data traffic from a daisy-chained PC in VLAN 100. The switch port is currently configured as a static access port in VLAN 100. Which configuration must the engineer apply to meet these requirements?

A.Configure the interface as a dynamic auto trunk and set the voice VLAN to 200 with the switchport voice vlan command.
B.Configure the interface as a trunk, set the native VLAN to 200, and allow VLANs 100 and 200 on the trunk.
C.Configure the interface with the switchport voice vlan 200 command while leaving the access VLAN as 100.
D.Configure the interface as a trunk, set the native VLAN to 100, and allow only VLAN 200 on the trunk.
AnswerC

The switchport voice vlan command enables the voice VLAN feature on an access port. Data frames from the PC remain untagged in the access VLAN (100), while voice frames from the phone are tagged with VLAN 200. The phone can also receive the voice VLAN assignment through LLDP-MED or CDP, making this the correct and simplest solution for a phone-plus-PC topology.

Why this answer

The voice VLAN feature on a Cisco access port allows a phone to send tagged voice frames while data frames from a daisy-chained PC remain untagged in the access VLAN. Configuring the port with switchport voice vlan 200 and leaving it as an access port in VLAN 100 provides the required separation without manual trunk configuration.

Exam trap

The trap here is assuming that a trunk must be configured to separate voice and data traffic, when the voice VLAN feature on an access port already handles this automatically.

1088
Drag & Dropmedium

Drag and drop the steps of NAPALM get_facts() retrieval from IOS-XE device into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with importing the NAPALM library and driver, then creating a driver object with device credentials, calling the open() method to establish the connection, invoking get_facts() to retrieve device facts, and finally closing the connection.

1089
Multi-Selectmedium

A network administrator is deploying a Cisco SD-Access fabric and needs to ensure that the underlay network is properly configured. Which two statements about the underlay network in SD-Access are true? (Choose two.)

Select 2 answers
A.The underlay can be configured as a Layer 2 network with VLANs to simplify deployment.
B.The underlay network carries endpoint subnet information and is used for endpoint-to-endpoint communication.
C.The underlay must support MTU sizes large enough to accommodate VXLAN encapsulation overhead.
D.The underlay uses a routing protocol such as IS-IS or OSPF to provide IP connectivity between fabric nodes.
E.The underlay uses VXLAN to encapsulate traffic between fabric nodes.
AnswersC, D

VXLAN adds 50 bytes of overhead (outer IP, UDP, VXLAN header). The underlay must support an MTU of at least 1550 bytes (typically 1600 or higher) to avoid fragmentation of VXLAN-encapsulated packets. If the underlay MTU is too small, large packets may be dropped or fragmented, causing performance issues. Therefore, configuring jumbo frames on the underlay is a best practice for SD-Access.

Why this answer

The underlay in SD-Access provides IP connectivity between fabric nodes using a routing protocol like IS-IS or OSPF, and it must support a larger MTU to accommodate VXLAN encapsulation overhead. The underlay does not carry endpoint subnet information; that is the role of the overlay. It is a Layer 3 network, not Layer 2, and it does not use VXLAN for encapsulation.

Exam trap

The trap here is conflating the underlay with the overlay, assuming the underlay carries endpoint prefixes or uses VXLAN, when it only provides IP transport.

1090
MCQeasy

Refer to the exhibit. An engineer notices that interface resets have occurred. What is the most likely cause of the interface resets?

A.Cable or hardware issue causing link flapping
B.CRC errors due to noise
C.Collisions on the link
D.Interface is administratively down
AnswerA

Interface resets occur when the interface goes down and comes back up, typically due to physical layer problems like faulty cables, damaged connectors, or hardware issues causing link flapping. This distinguishes resets from other errors.

Why this answer

Interface resets typically indicate that the interface has gone down and come back up, which is most commonly caused by a physical layer issue such as a faulty cable, damaged connector, or hardware problem that leads to link flapping. When the link flaps, the interface counters increment the 'resets' field, reflecting the number of times the interface has been reset due to a loss of carrier or a link state change. This is distinct from errors like CRC or collisions, which do not directly cause the interface to reset.

Exam trap

The trap here is that candidates often confuse interface resets with CRC errors or collisions, but Cisco specifically tests that resets are caused by physical layer issues (link flapping) rather than data-link layer errors.

How to eliminate wrong answers

Option B is wrong because CRC errors are caused by noise or signal integrity issues and are counted separately in the 'input errors' field; they do not directly cause the interface to reset. Option C is wrong because collisions are normal on half-duplex links and are tracked in collision counters, but they do not trigger interface resets. Option D is wrong because an administratively down interface is manually disabled via the 'shutdown' command and would show 'administratively down' in the show interface output, not resets.

1091
Multi-Selectmedium

Which two statements about AAA authorization and accounting are true? (Choose two.)

Select 2 answers
A.Authorization determines what commands a user is allowed to execute after authentication.
B.Authorization ensures that all traffic between the client and server is encrypted.
C.Accounting is used to authenticate users based on their previous login history.
D.Accounting provides a record of user activities for auditing or billing purposes.
E.Authorization can only be based on the source IP address of the user.
AnswersA, D

Authorization defines the privileges granted to an authenticated identity, so it directly governs which commands a user may execute on the device. This satisfies the stem's requirement by separating authorisation from authentication, which only verifies identity, and from accounting, which logs activity.

Why this answer

Option A is correct because AAA authorization, which occurs after authentication succeeds, defines the privileges and specific commands a user is permitted to execute on the device, typically enforced via per-user or per-group attributes returned by the AAA server (e.g., TACACS+ or RADIUS attributes). Option D is correct because AAA accounting logs user activity—such as start/stop times, commands issued, and bytes transferred—into accounting records that support auditing, billing, and security monitoring. Option B is not correct because encryption of traffic between client and server is a function of the AAA protocol/transport (e.g., TACACS+ encrypts the entire payload, RADIUS encrypts only the password), not of authorization.

Option C is not correct because accounting does not authenticate users; authentication verifies identity, while accounting records activity. Option E is not correct because authorization can be based on many factors, including user identity, group membership, time-of-day, and per-command attributes, not solely the source IP address.

Exam trap

The trap here is conflating the three A's — candidates often assume authorization includes encryption or that accounting performs authentication, when each function is strictly separate.

1092
MCQhard

A network engineer is configuring a new switch stack using Cisco StackWise technology. The engineer wants to ensure that if the stack master fails, another switch takes over with minimal disruption. Which statement accurately describes the failover behavior in a StackWise stack?

A.All switches in the stack must be rebooted to elect a new master, causing a network outage.
B.The stack master election is based on the highest MAC address, and failover requires a reboot of all stack members.
C.The standby switch becomes the new master without reloading, and other members continue forwarding traffic.
D.The failed master must be physically replaced before the stack can resume normal operations.
AnswerC

In a StackWise stack, the standby switch automatically takes over as master if the active master fails. The failover is designed to be hitless or near-hitless, with other stack members continuing to forward traffic without reloading. This provides high availability and minimal disruption, which is a key benefit of StackWise technology.

Why this answer

Cisco StackWise provides high availability by allowing a standby switch to take over as master if the active master fails. This failover is designed to be hitless or near-hitless, with other stack members continuing to forward traffic. No reboot of all switches is required, and the failed master does not need immediate replacement.

This ensures minimal disruption to network operations.

Exam trap

The trap here is assuming that StackWise failover requires a full stack reboot or that the failed master must be replaced immediately, when in fact the standby takes over seamlessly.

1093
MCQmedium

A network engineer is writing a Python script using the requests library to interact with a Cisco IOS XE device's RESTCONF API. The script needs to authenticate using basic authentication and retrieve interface details. The engineer writes the following code snippet: import requests url = 'https://192.168.1.1/restconf/data/ietf-interfaces:interfaces' headers = {'Accept': 'application/yang-data+json'} response = requests.get(url, headers=headers, auth=('admin', 'password'), verify=False) However, the script returns a 401 Unauthorized error. What is the most likely cause?

A.The credentials are incorrect or the user does not have sufficient privileges.
B.The verify=False parameter disables SSL verification, which causes the server to reject the request.
C.The Accept header is set incorrectly; it should be application/yang-data+xml.
D.The URL is missing the .json extension, which is required for RESTCONF.
AnswerA

A 401 Unauthorized error indicates authentication failure. The most likely cause is that the username or password is wrong, or the user account lacks the necessary permissions to access the RESTCONF API. The engineer should verify the credentials and ensure the user has appropriate privilege level (e.g., privilege 15).

Why this answer

A 401 Unauthorized response from RESTCONF means the authentication credentials are missing or invalid. The script uses basic authentication with a username and password; if those are incorrect or the user lacks permissions, the server rejects the request. The engineer should confirm the credentials and user privilege level.

Exam trap

The trap here is focusing on headers or URL formatting when a 401 error specifically indicates an authentication problem, not a content or syntax issue.

1094
Drag & Dropmedium

Drag and drop the steps of RPF check verification for multicast forwarding into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The RPF check ensures that incoming multicast packets arrive on the correct interface toward the source. First, the router examines the source IP address. Then it consults the unicast routing table to find the best route.

It identifies the outgoing interface for that route. It compares that interface with the arrival interface of the multicast packet. If they match, the packet is forwarded; otherwise, it is dropped.

1095
MCQmedium

A company has deployed a Cisco ASA firewall in transparent mode. The internal network uses VLAN 10 and the external network uses VLAN 20. The ASA is configured with two bridge groups: BVI 10 for inside and BVI 20 for outside. The security policy must allow HTTPS traffic from inside to outside. Which access-list entry is correct?

A.access-list INSIDE extended permit tcp 192.168.1.0 255.255.255.0 any eq 443 access-group INSIDE in interface inside
B.access-list GLOBAL extended permit ip 192.168.1.0 255.255.255.0 any
C.access-list GLOBAL extended permit tcp any any eq 443
D.access-list GLOBAL extended permit tcp 192.168.1.0 255.255.255.0 any eq 443
AnswerD

This is the correct configuration for transparent mode. The global access-list is the only ACL applied to a transparent ASA, and it evaluates all traffic crossing the Layer 2 bridge. The rule precisely matches the requirement: source is the inside subnet 192.168.1.0/24, destination is any, and service is TCP 443 (HTTPS), thus permitting only outbound HTTPS from the inside network while implicitly denying everything else. This adheres to least-privilege access control and is applied globally so that traffic from any interface, including the inside, is filtered consistently.

Why this answer

In transparent mode, the ASA acts as a Layer 2 bridge, so traffic must be permitted by a global access list applied to the bridge group virtual interface (BVI). Option D correctly uses the GLOBAL access list to permit TCP traffic from the inside subnet (192.168.1.0/24) to any destination on port 443 (HTTPS), which satisfies the security policy.

Exam trap

Cisco often tests the misconception that transparent mode uses interface-based ACLs like routed mode, when in fact transparent mode requires global ACLs applied to the BVI, and the 'GLOBAL' keyword is mandatory for Layer 2 traffic filtering.

How to eliminate wrong answers

Option A is wrong because in transparent mode, access lists are applied globally to the BVI, not per interface; the 'access-group INSIDE in interface inside' command is invalid in transparent mode. Option B is wrong because it permits all IP traffic (including non-HTTPS) and uses the 'ip' protocol instead of 'tcp', which violates the requirement to allow only HTTPS. Option C is wrong because it permits any source (including untrusted external hosts) to initiate HTTPS traffic, which does not restrict traffic from inside to outside as required.

1096
MCQhard

A network engineer is configuring control plane policing (CoPP) on a Cisco IOS XE router that peers BGP with two service providers and is managed over SSH from a jump host. After applying a new policy-map, the engineer notices that BGP sessions remain up but SSH logins intermittently time out during traffic spikes. Which action should the engineer take to resolve the SSH timeouts while preserving the CoPP protection model?

A.Add a class-map matching TCP port 22 traffic and attach it to the policy-map with an appropriate rate and conform/exceed actions.
B.Remove the service-policy from the control plane and rely on QoS on the data plane instead.
C.Increase the BGP class rate and move the SSH class into the BGP class-map.
D.Configure an ACL that permits only the jump host's IP and apply it as the match for the class-default class.
AnswerA

SSH traffic must be explicitly classified so CoPP can rate-limit it separately instead of letting it fall into a default or catch-all class that may be policed aggressively. Adding a TCP port 22 class with a suitable rate and transmit action preserves protection while guaranteeing management access. This is the standard CoPP design practice for management protocols.

Why this answer

CoPP works by classifying punted control-plane traffic into classes and applying per-class policers. If SSH is not explicitly matched, it is handled by class-default, which is often policed conservatively. Creating a dedicated class matching TCP port 22 with an adequate rate and a conform action of transmit ensures interactive management traffic survives bursts while BGP and other protocols stay protected.

Exam trap

The trap here is treating CoPP as an all-or-nothing filter and removing it, rather than recognizing that unclassified management traffic is the real cause of the timeouts.

1097
Multi-Selectmedium

Which two statements about Python data structures used in network automation are true? (Choose two.)

Select 2 answers
A.Tuples are commonly used to store device credentials because they can be modified easily.
B.Dictionaries are used to store key-value pairs such as device IP, username, and password.
C.Sets are ordered and allow indexing to retrieve specific elements.
D.Lists are ordered and can be used to store multiple device names for iteration.
E.Strings are mutable and ideal for storing multiple device configurations.
AnswersB, D

Dictionaries map unique keys to values, so a device's IP, username and password can be stored as named fields and retrieved by key. This satisfies the stem's requirement for storing key-value pairs in automation data structures.

Why this answer

Option B is correct because dictionaries store data as key-value pairs, making them ideal for mapping attributes like device IP, username, and password to a device, and they are widely used in network automation for structured device inventories. Option D is correct because lists are ordered, mutable sequences that preserve element order and support indexing and iteration, so they work well for holding multiple device names to loop over. Option A is wrong because tuples are immutable, so they cannot be modified easily and are not suited for credentials that need updating.

Option C is wrong because sets are unordered and do not support indexing, so they cannot retrieve elements by position. Option E is wrong because strings are immutable, not mutable, and a single string is a poor structure for storing multiple device configurations.

Exam trap

The trap is mixing up mutability and ordering properties: candidates often forget tuples are immutable, sets are unordered, and strings are immutable.

1098
Multi-Selecthard

Which three statements about Cisco TrustSec (CTS) are true? (Choose three.)

Select 3 answers
A.Cisco TrustSec uses Security Group Tags (SGTs) to classify traffic based on user or device identity.
B.SGTs are typically assigned to IP addresses using a centralized SGT mapping database.
C.802.1X can be used as the authentication mechanism to dynamically assign an SGT to a supplicant.
D.Cisco TrustSec eliminates the need for all traditional ACLs in the network.
E.SGTs can be carried in the Ethernet frame header using Cisco's inline tagging method.
AnswersA, C, E

Security Group Tags are the classification mechanism at the heart of TrustSec, tagging packets based on user or device identity rather than IP addresses. This identity-based classification is what enables scalable, topology-independent segmentation across the network.

Why this answer

Option A is correct because Cisco TrustSec classifies traffic by applying Security Group Tags (SGTs) that represent the identity/role of the user or device, enabling group-based policy rather than IP-based rules. Option C is correct because 802.1X authentication can drive dynamic SGT assignment: after the supplicant authenticates, the ISE/AAA server returns an authorization result (e.g., cisco-av-pair with an SGT value) that the switch applies to the port/session. Option E is correct because TrustSec supports inline tagging, where the 16-bit SGT is inserted into the Ethernet frame (using the Cisco Meta Data / CMD header with EtherType 0x8909) so the tag travels with the packet hop-by-hop.

Option B is not correct as stated because SGTs are not 'typically assigned to IP addresses' via a centralized mapping database; SGT-to-IP mappings are used for devices that cannot tag natively (e.g., via SXP or IP-to-SGT mapping), but the primary assignment is identity/session-based, not IP-based. Option D is not correct because TrustSec augments, but does not eliminate, traditional ACLs; SGACL enforcement still relies on underlying ACL-like constructs and existing ACLs may remain for other purposes.

Exam trap

350-401 often tests CTS details, and candidates incorrectly believe SGTs are mapped to IPs centrally or that CTS removes all ACLs, missing that SGTs are identity-based and SGACLs replace only some ACL functions.

1099
MCQmedium

A network engineer is deploying a VXLAN EVPN fabric on Cisco Nexus 9000 switches. The underlay is a Layer 3 routed fabric using OSPF. The engineer needs to ensure that multicast replication is not used for BUM (Broadcast, Unknown Unicast, Multicast) traffic. Which VXLAN EVPN configuration is required on the leaf switches?

A.Configure the NVE interface with a multicast group address using the `member vni <vni> mcast-group <group-address>` command.
B.Configure PIM sparse mode on all underlay interfaces and enable multicast routing on the leaf switches.
C.Configure the NVE interface with `ingress-replication protocol bgp` and ensure EVPN is enabled for the VNI.
D.Configure the NVE interface with `source-interface loopback0` and rely on OSPF to flood BUM traffic to all VTEPs.
AnswerC

Ingress replication with BGP EVPN allows the leaf to replicate BUM traffic to all remote VTEPs in the EVPN control plane without using multicast in the underlay. This is the correct approach when multicast replication is not desired. The command `ingress-replication protocol bgp` enables this behavior.

Why this answer

To avoid multicast replication in a VXLAN EVPN fabric, ingress replication must be used. The leaf switches must be configured with `ingress-replication protocol bgp` under the NVE interface, and EVPN must be enabled for the VNI. This allows the leaf to use the EVPN control plane to discover remote VTEPs and replicate BUM traffic to them via unicast.

Multicast replication requires PIM in the underlay, which is not desired here.

Exam trap

The trap here is assuming that VXLAN always requires multicast in the underlay for BUM traffic replication, when in fact ingress replication via BGP EVPN is a common alternative.

1100
Drag & Dropmedium

Drag and drop the steps of VLAN mapping on trunk interfaces into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First enter the trunk interface, configure encapsulation, then apply the VLAN mapping policy (translate or map), and finally verify the mapping.

1101
Drag & Dropmedium

Drag and drop the steps of Cisco NSO service provisioning workflow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The Cisco NSO workflow starts with the operator defining a service in YANG model. Then NSO maps the service to device configurations using a service template. Next, NSO pushes the configuration to network devices via NETCONF.

After that, NSO updates the service database with the operational state. Finally, NSO verifies the service by checking device state and alarms.

1102
Multi-Selecthard

A network automation team is evaluating YANG models to manage Cisco IOS XE devices. They need to ensure that the models they choose can be used with both NETCONF and RESTCONF. Which two statements about YANG models are true in this context? (Choose two.)

Select 2 answers
A.YANG models can be augmented to add vendor-specific data.
B.YANG models can only define configuration data, not operational state data.
C.YANG models are written in XML and must be converted to JSON for RESTCONF.
D.YANG models are specific to NETCONF and cannot be used with RESTCONF.
E.YANG models define the data structure and semantics for configuration and state data.
AnswersA, E

YANG supports augmentation, allowing vendors to extend standard models with proprietary data. Cisco IOS XE uses augmentations to add features not covered by IETF or OpenConfig models. This is essential for managing Cisco-specific functionality. The statement is true and highlights the flexibility of YANG for vendor customization.

Why this answer

YANG is a data modeling language that defines both configuration and state data, and it is used by both NETCONF and RESTCONF. It supports augmentations for vendor-specific extensions. These characteristics make YANG suitable for multi-protocol automation.

The other statements are incorrect because they misrepresent YANG's protocol independence, encoding, or scope.

Exam trap

The trap here is assuming that YANG is tied to a single protocol or that it cannot model operational data, when in fact it is protocol-agnostic and covers both config and state.

1103
MCQeasy

A network engineer uses the Cisco DNA Center API to trigger a provisioning workflow for a new device. The API call returns the following JSON response: { "response": { "taskId": "task-12345", "url": "/api/v1/task/task-12345" }, "version": "1.0" } The engineer then polls the task status using the URL. Which HTTP method should be used to retrieve the task status?

A.GET
B.POST
C.PUT
D.DELETE
AnswerA

Retrieving task status is a read-only operation against the returned URL, so GET is the correct HTTP method. POST, PUT, or DELETE would attempt to modify or create resources, which is inappropriate for simply polling the task's current state.

Why this answer

To retrieve the status of a task, a GET request should be sent to the provided URL. The task ID is used to query the task API endpoint.

1104
Multi-Selectmedium

Which two statements about 802.1X port states and access control are true? (Choose two.)

Select 2 answers
A.Before authentication, the switch port is in the unauthorized state and only allows EAPOL frames.
B.After successful 802.1X authentication, the port transitions to the authorized state and all traffic is permitted.
C.In multi-auth mode, the port becomes authorized for all devices once the first device authenticates successfully.
D.The port remains in the unauthorized state until the client sends data traffic.
E.802.1X can be configured on a Layer 3 interface to authenticate users before routing.
AnswersA, B

Before authentication, the port stays in the uncontrolled (unauthorized) state, permitting only EAPOL traffic between supplicant and authenticator. This satisfies the stem's access-control constraint: no ordinary data frames pass until the authentication server authorises the supplicant, after which the port transitions to the controlled, authorised state.

Why this answer

Option A is correct because in 802.1X the controlled port starts in the unauthorized state, and only EAPOL (Ethernet type 0x888E) frames are permitted so the supplicant can negotiate with the authenticator; all other traffic is dropped. Option B is correct because once the supplicant successfully authenticates via EAP over EAPOL and the RADIUS server returns Access-Accept, the authenticator moves the controlled port to the authorized state and normal data traffic is allowed. Option C is wrong because multi-auth mode authorizes each device individually, so the port is not opened for all devices after just the first successful authentication.

Option D is wrong because authentication is triggered by EAPOL-Start (or EAPOL frames), not by ordinary data traffic, and the port stays unauthorized until authentication succeeds. Option E is wrong because 802.1X is a Layer 2 port-based access control mechanism applied to switch ports, not to Layer 3 routed interfaces.

1105
MCQeasy

A network administrator is configuring a new Cisco Catalyst switch and needs to ensure that the management VLAN interface is reachable from a remote subnet. The switch currently has no default gateway configured. Which command should be used to allow the switch to communicate with devices on other subnets?

A.ip route 0.0.0.0 0.0.0.0 192.168.1.1
B.ip default-gateway 192.168.1.1
C.ip gateway 192.168.1.1
D.default-router 192.168.1.1
AnswerB

The 'ip default-gateway' command is used on Layer 2 switches to specify a default gateway for management traffic. When the switch is not performing routing, it needs a default gateway to reach remote subnets. This command sets the gateway of last resort for the management interface. Without it, the switch can only communicate with devices on the same subnet, so this is the correct solution for the scenario.

Why this answer

On a Layer 2 switch, the management interface (such as VLAN 1 or a management VLAN SVI) requires a default gateway to communicate with remote subnets. The 'ip default-gateway' command provides this functionality. Unlike a router, a Layer 2 switch does not run a routing protocol or maintain a routing table for management traffic, so a default route is not applicable.

The correct command is 'ip default-gateway'.

Exam trap

The trap here is confusing the switch's management default gateway command with a router's default route command.

1106
Drag & Dropmedium

Drag and drop the steps of Embedded Packet Capture (EPC) on IOS-XE steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

EPC requires defining a capture buffer, then a capture point, associating them, starting the capture, and finally exporting or viewing.

1107
Drag & Dropmedium

Drag and drop the steps of Cisco Flex (FlexConnect) AP mode operation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

A FlexConnect AP first discovers and joins the WLC, then downloads its configuration and policy. When a client associates, the AP locally switches traffic if configured. The AP sends client data to the WLC for authentication and then applies the downloaded policy locally.

1108
MCQhard

A service provider is using Cisco ASR 9000 routers and needs to collect NetFlow data from multiple customers' traffic. The engineer wants to ensure that flow records from different customers are not mixed and can be identified separately. The router supports Flexible NetFlow. What is the best approach?

A.Define a custom flow record that includes the 'match ipv4 vlan' or 'match ipv4 vrf' field to identify each customer's traffic, and apply a single flow monitor on the shared interface.
B.Configure a separate flow monitor for each customer interface and export to different collectors.
C.Use NetFlow v9 export with the 'match ipv4 source address' field only, and rely on the collector to separate by source IP.
D.Enable SNMP interface polling to track per-customer traffic statistics.
AnswerA

A custom flow record built with Flexible NetFlow can reference the VRF name or VLAN tag alongside the standard 5-tuple, so flows from different customers sharing the same physical interface are tagged at the source router. Because the flow monitor is attached to the shared interface, it captures all traffic in a single pass, and the collector uses the VRF/VLAN key to separate per-customer statistics. This eliminates reliance on IP uniqueness and scales to many VPNs or VLANs without needing a separate monitor per tenant.

Why this answer

Flexible NetFlow allows you to define a custom flow record that includes key fields such as 'match ipv4 vrf' (VRF-aware NetFlow) to uniquely identify each customer's traffic. By applying a single flow monitor on a shared interface (e.g., a trunk or core link), the router can tag flows with the VRF or VLAN identifier, ensuring per-customer separation without needing multiple monitors or collectors. This approach is efficient and leverages the router's ability to export differentiated flow records to a single collector, which can then filter based on the VRF or VLAN field.

Exam trap

Cisco often tests the misconception that you must use separate flow monitors or collectors for each customer, when in fact Flexible NetFlow's VRF or VLAN match fields allow a single monitor to separate flows, reducing configuration and resource usage.

How to eliminate wrong answers

Option B is wrong because configuring a separate flow monitor for each customer interface and exporting to different collectors adds unnecessary complexity and resource overhead; it does not leverage Flexible NetFlow's ability to tag flows within a single monitor, and it may not scale well with many customers. Option C is wrong because using only 'match ipv4 source address' is insufficient for separating customers, as source IPs can overlap across different VRFs or VLANs, and the collector would have no reliable way to distinguish which customer a flow belongs to without additional context like VRF or VLAN. Option D is wrong because SNMP interface polling provides aggregate traffic statistics (e.g., bytes/packets per interface) and cannot identify individual flows or separate traffic from multiple customers sharing the same interface; it is a completely different technology from NetFlow.

1109
Drag & Dropmedium

Drag and drop the steps of implementing QoS trust boundaries on a Cisco switch into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, identify the trust boundary (e.g., access port). Then configure the trusted interface to trust CoS or DSCP. Next, set the default CoS for untrusted frames.

Finally, verify the configuration and adjust as needed.

1110
Drag & Dropmedium

Drag and drop the steps of SVI configuration for inter-VLAN routing into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

SVI configuration requires first creating the VLAN, then the SVI interface, assigning an IP address, enabling the interface, and finally verifying routing. This order ensures the VLAN exists before the SVI is created and routing is enabled.

1111
Drag & Dropmedium

Drag and drop the steps of the QoS trust boundary configuration process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The trust boundary process starts by enabling trust on the interface, then optionally setting a default CoS/DSCP for untrusted traffic, and finally applying a service policy to enforce policing or marking. Verification ensures the trust boundary is correctly applied.

1112
MCQmedium

A network administrator checks the AAA configuration on a router: R1# show running-config | include aaa aaa new-model aaa authentication login default group radius local aaa authentication login console local aaa authorization exec default group tacacs+ local aaa accounting exec default start-stop group radius Based on this output, what can be concluded?

A.Console login uses RADIUS authentication.
B.EXEC authorization uses TACACS+ as the primary method.
C.Accounting is performed using TACACS+.
D.Local authentication is never used.
AnswerB

The command 'aaa authorization exec default group tacacs+ local' creates a default EXEC authorization list applied to all EXEC sessions. When a user attempts to start a privileged EXEC shell, the device first sends an authorization request to the TACACS+ server group; only if that server is unavailable or returns no response does it fall back to the local database. Because TACACS+ appears first in the list, it is the primary method for EXEC authorization, making this statement correct.

Why this answer

The command 'aaa authorization exec default group tacacs+ local' specifies that TACACS+ is the primary method for EXEC authorization, with local as a fallback. This means the router first attempts to authorize EXEC access via TACACS+; if the TACACS+ server does not respond, it falls back to local authentication.

Exam trap

Cisco often tests the distinction between authentication, authorization, and accounting methods, and the trap here is that candidates confuse the method used for one function (e.g., authentication) with another (e.g., authorization or accounting), or assume that 'default' applies uniformly across all AAA functions.

How to eliminate wrong answers

Option A is wrong because the command 'aaa authentication login console local' explicitly sets local authentication for console login, not RADIUS. Option C is wrong because the command 'aaa accounting exec default start-stop group radius' specifies RADIUS for accounting, not TACACS+. Option D is wrong because local authentication is used as a fallback for the default login method (after RADIUS) and as the sole method for console login, so it is indeed used.

1113
Drag & Dropmedium

Drag and drop the steps of troubleshooting an IP SLA operation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Start by checking reachability to the target IP (D) to ensure the destination is reachable. Then review system logs (E) for any errors related to IP SLA. Next, check the IP SLA configuration (A) for correctness.

After that, examine IP SLA statistics (C) for failures or timeouts. Finally, verify the operation is scheduled and active (B) to confirm it is running as expected.

1114
Multi-Selecthard

A network engineer is configuring a Cisco IOS router for QoS and wants to ensure that voice traffic is prioritized and that excess traffic is dropped rather than buffered when congestion occurs. The engineer decides to use Low Latency Queueing (LLQ). Which two statements accurately describe the behavior of LLQ? (Choose two.)

Select 2 answers
A.LLQ provides a strict priority queue that is serviced before other queues, ensuring low latency for voice traffic.
B.LLQ can be configured only on interfaces that support hardware queuing, such as serial interfaces.
C.LLQ buffers all excess traffic in the priority queue until bandwidth becomes available, ensuring no packets are dropped.
D.LLQ uses a policer to limit the amount of traffic that can enter the priority queue, dropping excess packets.
E.LLQ allows multiple priority queues to be configured, each with its own bandwidth guarantee.
AnswersA, D

LLQ includes a strict priority queue that is always serviced first when packets are present, which minimizes delay and jitter for voice. This is a key characteristic of LLQ, making it suitable for real-time traffic. The priority queue is typically configured with a bandwidth guarantee and a policer to limit its maximum rate, preventing starvation of other queues.

Why this answer

LLQ provides a single strict priority queue that is serviced before other queues, ensuring low latency for voice. It uses a policer to cap the priority queue's bandwidth, dropping excess packets to prevent starvation of other queues. These two characteristics are fundamental to LLQ's operation and make it suitable for real-time traffic while maintaining fairness.

Exam trap

The trap here is assuming that LLQ allows multiple priority queues or that it buffers excess priority traffic, when in fact it supports only one priority queue and drops excess packets via a policer.

1115
MCQhard

An enterprise is using OSPF in a multi-area design. Area 1 is a regular area, and Area 2 is a totally stubby area. Which LSA types are present in Area 2?

A.Type 1, Type 2, Type 3 (including default)
B.Type 1, Type 2, Type 3, Type 5
C.Type 1, Type 2, Type 4, Type 5
D.Type 1, Type 2, Type 3 (including default), Type 4
AnswerA

In a totally stubby area, the ABR suppresses Type 4 (ASBR-summary) and Type 5 (AS-external) LSAs, and also replaces all Type 3 inter-area summaries with a single default route. This leaves only Type 1 (router) and Type 2 (network) LSAs for intra-area topology, plus the injected Type 3 default LSA for any traffic leaving the area. Therefore, the allowed LSA set is exactly Type 1, Type 2, and the default Type 3.

Why this answer

In a totally stubby area, the ABR blocks Type 4 and Type 5 LSAs and replaces all Type 3 inter-area routes with a single default route (Type 3 LSA with link-state ID 0.0.0.0). Therefore, only Type 1 (router), Type 2 (network), and the default Type 3 LSAs are present. This matches option A.

Exam trap

Cisco often tests the distinction between a standard stub area (which allows Type 3 summaries but blocks Type 4 and Type 5) and a totally stubby area (which additionally blocks all Type 3 summaries except the default), causing candidates to confuse the LSA types allowed in each.

How to eliminate wrong answers

Option B is wrong because Type 5 (AS-external) LSAs are blocked in a totally stubby area; they are only present in a standard stub area if not using the 'no-summary' keyword. Option C is wrong because Type 4 (ASBR-summary) LSAs are also blocked in a totally stubby area, and Type 5 LSAs are blocked as well. Option D is wrong because Type 4 LSAs are not present in a totally stubby area; the ABR does not advertise the ASBR location into the area.

1116
MCQhard

A network engineer runs the following command on Switch SW9: SW9# show monitor session 9 Session 9 --------- Type : Remote Destination Session Source RSPAN VLAN : 300 Destination Ports : Gi1/0/40 Encapsulation : Native Ingress : Disabled Based on this output, what can be concluded?

A.This switch receives mirrored traffic from RSPAN VLAN 300 and sends it to Gi1/0/40.
B.This is a local SPAN session with source VLAN 300.
C.The RSPAN VLAN 300 is used to send traffic to a remote switch.
D.Ingress traffic on Gi1/0/40 is forwarded to the RSPAN VLAN.
AnswerA

The session type is Remote Destination Session, so this switch is the destination device: it receives mirrored traffic carried in source RSPAN VLAN 300 and forwards it out of destination port Gi1/0/40. Ingress is disabled, so traffic entering Gi1/0/40 is not mirrored.

Why this answer

The output shows a Remote Destination Session, meaning this switch (SW9) is the destination switch in an RSPAN configuration. It receives mirrored traffic from RSPAN VLAN 300 and forwards it out of the destination port Gi1/0/40. The 'Source RSPAN VLAN: 300' indicates the VLAN carrying the mirrored traffic from the remote source switch, and 'Destination Ports: Gi1/0/40' confirms the local egress port.

Exam trap

Cisco often tests the distinction between source and destination RSPAN roles; the trap here is that candidates confuse 'Source RSPAN VLAN' as the source of traffic being mirrored, when in a destination session it actually refers to the VLAN that receives mirrored traffic from a remote source.

How to eliminate wrong answers

Option B is wrong because the session type is 'Remote Destination Session', not a local SPAN session; a local SPAN would have a source interface or VLAN directly on the same switch, not an RSPAN VLAN. Option C is wrong because this switch is the destination of the RSPAN traffic, not the source; the RSPAN VLAN is used to receive traffic from a remote switch, not to send it. Option D is wrong because ingress on Gi1/0/40 is disabled (as shown in the output), meaning no traffic entering that port is forwarded to the RSPAN VLAN; ingress is only relevant for local SPAN or when configured for encapsulation replication.

1117
MCQhard

A network engineer is designing a new data center network using Cisco ACI. The engineer needs to ensure that traffic between two endpoints in different EPGs is allowed only if a contract permits it. Which ACI construct is used to define the rules that permit or deny traffic between EPGs?

A.Tenant
B.Contract
C.Application Profile
D.Bridge Domain
AnswerB

In Cisco ACI, a contract defines the rules that permit or deny traffic between EPGs. It consists of subjects and filters that specify the protocols and ports allowed. Contracts are applied to EPGs as providers or consumers. When an EPG provides a contract and another consumes it, traffic is allowed according to the contract's filters. This is the fundamental mechanism for enforcing policy in ACI, making it the correct answer.

Why this answer

In Cisco ACI, contracts are the constructs that define the rules for permitting or denying traffic between EPGs. A contract contains subjects and filters that specify the allowed protocols and ports. EPGs can be providers or consumers of contracts, and traffic is only allowed if a contract is in place.

This policy-based approach ensures that communication between endpoints is explicitly permitted, aligning with a zero-trust security model.

Exam trap

The trap here is confusing the logical grouping constructs like tenants, application profiles, and bridge domains with the policy enforcement construct, which is the contract.

1118
MCQmedium

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The administrator wants to protect the route processor from excessive control-plane traffic while still allowing legitimate routing protocol and management traffic. The administrator creates a class map that matches BGP, OSPF, and SSH traffic and applies a police action with a committed information rate. Which additional configuration element is required to complete the CoPP implementation?

A.Configure a route map that matches the control-plane protocols and reference it in the policy map.
B.Apply the policy map to all physical interfaces using the service-policy input command under interface configuration mode.
C.Apply the policy map to the control plane using the service-policy input command under control-plane configuration mode.
D.Enable NetFlow on the router to export control-plane traffic statistics to a collector.
AnswerC

CoPP requires a policy map to be attached to the control plane with service-policy input under control-plane configuration mode. Without this attachment, the class maps and policy map exist but are not enforced on control-plane traffic, leaving the route processor unprotected.

Why this answer

CoPP is implemented by defining class maps to identify control-plane traffic, a policy map to apply actions such as police, and then attaching the policy map to the control plane with service-policy input under control-plane configuration mode. Without that attachment, the policy is never applied to control-plane traffic, so the route processor remains vulnerable to excessive protocol or management packets.

Exam trap

The trap here is assuming that applying a policy map to physical interfaces protects the control plane, when CoPP specifically requires attachment under control-plane configuration mode.

1119
MCQmedium

A network team is deploying a virtualized WAN optimization appliance. The appliance must be able to process traffic at line rate on a 10 Gbps link. The hypervisor host has multiple physical NICs. Which design choice will best ensure the VM can achieve the required throughput?

A.Assign the VM a virtual function (VF) using SR-IOV on the physical NIC.
B.Use a standard virtual switch with a single vCPU for the VM.
C.Enable jumbo frames on the virtual switch only.
D.Configure the VM with multiple vNICs and use NIC teaming.
AnswerA

SR-IOV is the correct choice because it partitions a physical NIC into multiple virtual functions (VFs), each directly assigned to a VM without hypervisor involvement. The VM's vNIC maps to a VF that owns dedicated DMA queues, interrupt vectors, and packet-processing hardware, so data bypasses the software vSwitch and its CPU-intensive copying. This yields near-native throughput, low latency, and minimal host CPU overhead, making it far superior to any software-based virtualization approach.

Why this answer

SR-IOV (Single Root I/O Virtualization) allows a physical NIC to present multiple virtual functions (VFs) directly to a VM, bypassing the hypervisor's virtual switch. This reduces CPU overhead and latency, enabling the VM to achieve near line-rate throughput on a 10 Gbps link by allowing direct hardware access for data plane traffic.

Exam trap

Cisco often tests the misconception that adding more vNICs or teaming can solve throughput issues, but the real bottleneck is the hypervisor's software switching overhead, which SR-IOV eliminates by providing direct hardware pass-through.

How to eliminate wrong answers

Option B is wrong because a standard virtual switch with a single vCPU introduces significant CPU overhead and context-switching latency, which cannot sustain 10 Gbps line-rate processing. Option C is wrong because enabling jumbo frames on the virtual switch only does not reduce the hypervisor's I/O bottleneck; jumbo frames must also be supported end-to-end on the physical NIC and VM to improve throughput, but they alone cannot guarantee line rate. Option D is wrong because multiple vNICs with NIC teaming in the VM adds complexity and still relies on the hypervisor's virtual switch for packet forwarding, which introduces software overhead that prevents achieving line-rate performance on a 10 Gbps link.

1120
Drag & Dropmedium

Drag and drop the steps of EtherChannel troubleshooting and verification steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Troubleshooting EtherChannel should begin with checking the physical port status using 'show interfaces' to identify any link-level issues such as errors or down ports. Next, verify the EtherChannel bundle with 'show etherchannel summary' to confirm that the bundle is formed and which ports are members. Then, inspect protocol details with 'show etherchannel detail' to look for mismatches in configuration like PAgP/LACP modes or VLAN allowed lists.

After that, check load-balancing with 'show etherchannel load-balance' to ensure traffic is distributed as expected. Finally, test end-to-end connectivity with ping and traceroute to confirm data flow across the bundle.

Exam trap

A common pitfall is starting with 'show etherchannel detail' before verifying basic physical status and bundle formation. Always check physical ports first, as misconfigured or down ports will prevent the bundle from forming.

1121
Drag & Dropmedium

Drag and drop the steps of MPLS L3VPN packet forwarding steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The order begins with the ingress PE receiving an IP packet from the CE, looking up the VRF to find the next hop and label, pushing the MPLS label stack, forwarding the labeled packet across the MPLS core, and finally the egress PE popping the label and forwarding the IP packet to the destination CE.

1122
Multi-Selectmedium

A network administrator is using Cisco DNA Center Assurance to monitor the health of a wireless network. The administrator wants to identify the root cause of poor wireless client experience. Which two actions can be taken within Cisco DNA Center Assurance to troubleshoot this issue? (Choose two.)

Select 2 answers
A.Use the Path Trace tool to visualize the path between a client and a destination.
B.Use the Application Health dashboard to monitor application performance.
C.Use the Network Health dashboard to view overall network device health.
D.Use the Client Health dashboard to view detailed metrics for a specific wireless client.
E.Use the Intelligent Capture feature to analyze wireless packet captures.
AnswersD, E

The Client Health dashboard in Cisco DNA Center Assurance provides detailed metrics such as onboarding time, connectivity, and throughput for individual clients. This allows the administrator to pinpoint issues affecting a specific wireless client, making it a key tool for troubleshooting poor client experience.

Why this answer

To troubleshoot poor wireless client experience, the administrator should use the Client Health dashboard for detailed per-client metrics and Intelligent Capture for deep packet-level analysis. These tools together provide the necessary visibility into wireless-specific issues such as RF conditions and client onboarding problems.

Exam trap

The trap here is confusing general network monitoring dashboards with client-specific troubleshooting tools, overlooking that only Client Health and Intelligent Capture offer the granular wireless client data needed.

1123
Multi-Selectmedium

A network architect is designing a Cisco SD-Access fabric. The security team requires that endpoint traffic be segmented into separate virtual networks and that group-based policy be enforced without using traditional VLANs or ACLs between fabric edge nodes. Which two Cisco SD-Access fabric components or features support these requirements? (Choose two.)

Select 2 answers
A.Cisco TrustSec Security Group Tags (SGTs) enforced by the fabric
B.Virtual Extensible LAN (VXLAN) data plane encapsulation with fabric VNIs
C.Private VLANs configured on every fabric edge switch port
D.Dynamic ARP Inspection on all fabric underlay links
E.Extended ACLs applied inbound on every fabric edge uplink
AnswersA, B

SGTs carry group-based policy information in the VXLAN header, allowing the fabric to enforce scalable group-based access control across edge nodes without hop-by-hop ACLs. This satisfies the requirement for group-based policy enforcement that is independent of VLAN or IP subnet boundaries in the SD-Access fabric.

Why this answer

SD-Access uses VXLAN encapsulation with a fabric VNI per virtual network to provide data-plane segmentation, and it carries Security Group Tags so that group-based policy can be enforced consistently across fabric edge nodes. Together these deliver segmentation and policy without depending on VLANs or hop-by-hop ACLs between edge switches.

Exam trap

The trap here is assuming that legacy Layer 2 isolation tools such as private VLANs or extended ACLs can deliver fabric-wide segmentation and group policy in SD-Access.

1124
MCQmedium

Examine this DHCP configuration: ``` service dhcp ip dhcp pool POOL2 network 10.20.20.0 255.255.255.0 default-router 10.20.20.1 lease infinite ``` What is the effect of the 'lease infinite' command?

A.Clients will receive an infinite lease and never need to renew.
B.The lease time is set to the default value of 1 day.
C.Clients will be unable to obtain an IP address because infinite is invalid.
D.The router will ignore the lease command and use the default.
AnswerA

The `ip dhcp pool` command `lease infinite` explicitly configures the DHCP server to assign an address with no expiration time. Because the lease never expires, the client never needs to send a DHCPREQUEST to renew it, and the address remains valid indefinitely. This is a valid configuration that forces the client to keep the same IP for as long as the pool exists, though it can exhaust the address pool if clients move or go offline without releasing.

Why this answer

The 'lease infinite' command in a Cisco DHCP pool configuration sets the lease duration to never expire, meaning clients will not need to renew their IP addresses. This is a valid Cisco IOS command that overrides the default lease time of 1 day, and DHCP clients will treat the lease as having an infinite lifetime, so they will not attempt renewal.

Exam trap

The trap here is that candidates may think 'infinite' is an invalid or unsupported keyword, confusing it with the common misconception that Cisco DHCP only accepts numeric lease values, when in fact 'infinite' is a legitimate Cisco IOS parameter.

How to eliminate wrong answers

Option B is wrong because 'lease infinite' does not set the lease to the default value of 1 day; it explicitly sets an infinite lease, which is different from the default. Option C is wrong because 'infinite' is a valid keyword in Cisco IOS for the 'lease' command, and clients will successfully obtain IP addresses with an infinite lease. Option D is wrong because the router does not ignore the command; it applies the infinite lease as configured, overriding the default behavior.

1125
Drag & Dropmedium

Drag and drop the steps of SD-WAN traffic engineering app-aware routing steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order for SD-WAN traffic engineering app-aware routing steps is: first, traffic is classified by application (A); then path performance is measured via probes (B); then metrics are compared to SLA thresholds (C); then the best path meeting the SLA is selected (D); and finally traffic is forwarded over the chosen path (E).

Page 14

Page 15 of 26

Page 16