Courseiva

ENCOR 350-401 (350-401) — Questions 1126–1200

1923 questions total · 26pages · All types, answers revealed

Page 15

Page 16 of 26

Page 17
1126
MCQmedium

An engineer is troubleshooting intermittent connectivity issues between two data center switches. The link is a 10GE LACP port-channel. Which misconfiguration could cause packet loss?

A.MTU size is set to 1500 on one switch and 9000 on the other.
B.Auto-negotiation is disabled on both ends.
C.Spanning-tree BPDU guard is enabled on the port-channel.
D.One switch is configured with active LACP and the other with passive LACP.
AnswerA

Mismatched MTU sizes break the link's ability to carry full-size frames consistently. A 9000-byte jumbo frame sent toward the 1500-byte interface is dropped or fragmented, causing intermittent packet loss on the LACP port-channel, especially for large transfers.

Why this answer

An MTU mismatch between two switches in a port-channel can cause packet fragmentation or drops. With LACP, both sides must have matching MTU settings to ensure proper frame forwarding. If one switch has an MTU of 1500 and the other 9000 (jumbo frames), packets exceeding 1500 bytes will be dropped by the switch with the smaller MTU, causing intermittent packet loss.

In contrast, an active/passive LACP configuration is valid and commonly used; it does not cause packet loss if both sides are properly configured. Passive-passive would prevent the port-channel from forming, but that is not the case here.

Exam trap

The trap is that many candidates assume active/passive LACP is a misconfiguration, but it is actually valid. Instead, MTU mismatches are a common source of packet loss in port-channels. Always verify MTU settings when troubleshooting intermittent connectivity.

How to eliminate wrong answers

Option A is wrong because MTU mismatch does not cause packet loss on a port-channel; it causes fragmentation issues or dropped oversized frames, but the link itself remains operational and LACP will still form. Option B is wrong because auto-negotiation is not required on 10GE fiber links (e.g., 10GBASE-SR/LR) where speed and duplex are fixed; disabling it on both ends is standard practice and does not cause packet loss. Option C is wrong because BPDU guard is a spanning-tree feature that err-disables a port upon receiving a BPDU, but it does not cause intermittent packet loss; it either shuts the port down or leaves it operational, not a flapping or loss condition.

1127
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate management users via TACACS+. The requirement is to allow fallback to the local database if all TACACS+ servers are unreachable. Which AAA configuration achieves this?

A.aaa authentication login default group tacacs+ none
B.aaa authentication login default local group tacacs+
C.aaa authentication login default group tacacs+ enable
D.aaa authentication login default group tacacs+ local
AnswerD

This command configures the default login authentication method list to try TACACS+ first, then fall back to the local username database if the TACACS+ servers do not respond. The 'local' keyword ensures that local authentication is used as a backup, providing administrative access even when the AAA server is unreachable.

Why this answer

The correct configuration uses the default method list with TACACS+ first and local fallback. The 'group tacacs+' keyword specifies TACACS+ servers, and 'local' ensures the router's local username database is used if all TACACS+ servers are unreachable. This provides centralized authentication with a resilient backup.

Exam trap

The trap here is confusing the order of authentication methods or using 'none' or 'enable' instead of 'local' for fallback, which either compromises security or fails to use the local database.

1128
MCQhard

A network engineer needs to monitor traffic from a specific VLAN (VLAN 100) on a Cisco Catalyst 9300 switch and send the mirrored traffic to a monitoring station on a different switch across a routed network. The engineer decides to use ERSPAN. Which configuration is required on the source switch?

A.Configure 'monitor session 1 type erspan-source' and then 'source vlan 100' and 'destination ip 192.168.1.100'.
B.Configure 'monitor session 1 source vlan 100' and 'monitor session 1 destination interface Gi1/0/24'.
C.Configure 'monitor session 1 source vlan 100' and 'monitor session 1 destination remote vlan 999'.
D.Configure 'monitor session 1 source vlan 100' and 'monitor session 1 destination interface Gi1/0/24' and then 'monitor session 1 encapsulation replicate'.
AnswerA

This is the only configuration that actually creates an ERSPAN source session. The 'type erspan-source' keyword puts the session into ERSPAN mode, and the 'source vlan 100' selects the VLAN to mirror while 'destination ip 192.168.1.100' defines the remote IPv4 address of the collector or destination switch. ERSPAN encapsulates the mirrored packets in GRE with an IP outer header, enabling the traffic to traverse a routed Layer 3 network that local SPAN and RSPAN cannot cross.

Why this answer

ERSPAN (Encapsulated Remote SPAN) is used to send mirrored traffic across a routed network by encapsulating the mirrored packets in GRE (Generic Routing Encapsulation) and sending them to a destination IP address. Option A correctly configures an ERSPAN source session with 'monitor session 1 type erspan-source', specifies the source VLAN 100, and sets the destination IP address of the monitoring station (192.168.1.100), which allows the traffic to traverse Layer 3 boundaries.

Exam trap

Cisco often tests the distinction between local SPAN, RSPAN, and ERSPAN, and the trap here is that candidates confuse RSPAN (which uses a remote VLAN and Layer 2 transport) with ERSPAN (which uses GRE and Layer 3 transport), leading them to select option C.

How to eliminate wrong answers

Option B is wrong because it configures a local SPAN session (destination interface), which cannot send traffic across a routed network; it only mirrors to a local port on the same switch. Option C is wrong because 'destination remote vlan 999' is used for RSPAN (Remote SPAN), which requires a dedicated VLAN and Layer 2 adjacency between switches, not a routed network. Option D is wrong because it also configures a local SPAN session with 'destination interface' and 'encapsulation replicate' (which preserves the original encapsulation on the mirrored port), but this still cannot traverse Layer 3 boundaries; ERSPAN requires the 'type erspan-source' and a destination IP address.

1129
Matchingmedium

Drag and drop each MPLS role on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Forwards MPLS packets by performing label lookup and swapping

Pushes labels on ingress and pops labels on egress

Core router that swaps labels without pushing or popping

Edge router that connects customer sites and runs MPLS VPNs

Customer edge router that connects to the PE

Why these pairings

LSR forwards packets based on labels, LER pushes/pops labels at the edge, P is a core LSR that only swaps labels, PE provides VPN services at the edge, and CE is the customer device connecting to the MPLS network.

1130
MCQmedium

ip vrf RED rd 200:1 route-target export 200:1 route-target import 200:1 ! interface GigabitEthernet0/1 ip vrf forwarding RED ip address 10.1.1.1 255.255.255.0 ! router bgp 65000 neighbor 192.168.1.1 remote-as 65000 neighbor 192.168.1.1 update-source Loopback0 address-family vpnv4 neighbor 192.168.1.1 activate neighbor 192.168.1.1 send-community extended ! Which statement about this configuration is true?

A.The configuration is correct for MPLS L3VPN, but the VRF RED must also be configured under BGP with 'address-family ipv4 vrf RED'.
B.The 'send-community extended' command is unnecessary because it is enabled by default.
C.The interface GigabitEthernet0/1 requires 'mpls ip' to forward MPLS packets.
D.The VRF RED will automatically import routes from the VPNv4 address-family without additional configuration.
AnswerA

The statement is correct: for an MPLS L3VPN, the VRF RED configuration itself is valid, but the VRF must also be activated in BGP under the 'address-family ipv4 vrf RED' stanza. This enables BGP to import and export routes between the VRF and the VPNv4 address family, converting IPv4 VRF routes into VPNv4 routes with the appropriate route target extended communities. Without this BGP address-family configuration, the VRF will have no BGP peering for VPN routes, so even if other pieces are in place, end-to-end L3VPN connectivity will not work.

Why this answer

In an MPLS L3VPN configuration, after creating the VRF and applying it to an interface, you must also configure the VRF under BGP using the 'address-family ipv4 vrf RED' command to exchange IPv4 routes within that VRF. Without this, the VRF will not participate in BGP route exchange, and the VPNv4 address-family alone cannot import or export VRF routes. The given configuration is incomplete, as it lacks the VRF-specific address-family under BGP.

Exam trap

Cisco often tests the misconception that applying a VRF to an interface and configuring route-target import/export is sufficient for BGP route exchange, but the missing 'address-family ipv4 vrf' under BGP is the critical step that candidates overlook.

How to eliminate wrong answers

Option B is wrong because the 'send-community extended' command is not enabled by default for VPNv4 neighbors; it must be explicitly configured to allow the exchange of extended communities, which are essential for MPLS L3VPN route target filtering. Option C is wrong because the 'mpls ip' command is required on interfaces that participate in MPLS forwarding (e.g., core-facing interfaces), but not on the customer-facing interface GigabitEthernet0/1, which only needs VRF forwarding and an IP address. Option D is wrong because VRF RED will not automatically import routes from the VPNv4 address-family; you must explicitly configure the VRF under BGP with 'address-family ipv4 vrf RED' and then use the 'import' and 'export' route-target commands (already done in VRF definition) to control route exchange.

1131
MCQmedium

A network engineer is writing a Python script to retrieve the list of interfaces from a Cisco IOS XE device using RESTCONF. The script sends a GET request to https://10.1.1.1/restconf/data/ietf-interfaces:interfaces and receives a 401 Unauthorized response. The device is reachable, and RESTCONF is enabled. The engineer verifies that the username and password are correct. Which action should the engineer take to resolve the issue?

A.Configure the HTTP client to use basic authentication with the correct credentials.
B.Enable the RESTCONF API using the 'restconf' command under global configuration.
C.Change the request method from GET to POST.
D.Add the header 'Accept: application/yang-data+json' to the request.
AnswerA

A 401 Unauthorized response means the request lacks valid authentication credentials. RESTCONF uses HTTP authentication, typically basic auth. The engineer must include an Authorization header with the base64-encoded username:password. Even if the credentials are correct, they must be sent in the request. The script likely omitted the auth parameter, causing the server to reject the request. Adding basic authentication resolves the issue.

Why this answer

A 401 Unauthorized response indicates that the request lacks valid authentication credentials. RESTCONF relies on HTTP authentication, so the client must include an Authorization header, typically using basic authentication. Even if the username and password are correct, they must be transmitted with the request.

The other options address different issues: content negotiation, API enablement, or HTTP method, none of which cause a 401. Therefore, configuring basic authentication is the correct fix.

Exam trap

The trap here is assuming that a 401 error means incorrect credentials, when it often means credentials were never sent.

1132
MCQeasy

What is the default OSPF hello interval on a broadcast multi-access network (e.g., Ethernet)?

A.10 seconds
B.30 seconds
C.5 seconds
D.40 seconds
AnswerA

OSPF sends hello packets every 10 seconds on broadcast multi-access segments such as Ethernet, satisfying the default timer requirement. This interval lets routers detect neighbours quickly while avoiding excessive overhead. It differs from NBMA and point-to-multipoint networks, which default to 30 seconds.

Why this answer

On a broadcast multi-access network like Ethernet, OSPF defaults to a hello interval of 10 seconds. This is defined in RFC 2328 and is used to quickly detect neighbor failures while keeping control traffic overhead manageable. The corresponding dead interval is 40 seconds (4 times the hello interval).

Exam trap

Cisco often tests the distinction between hello and dead intervals, and candidates confuse the 40-second dead interval with the hello interval, or incorrectly recall the NBMA hello interval of 30 seconds.

How to eliminate wrong answers

Option B is wrong because 30 seconds is the default hello interval for OSPF on non-broadcast multi-access (NBMA) networks, not broadcast multi-access. Option C is wrong because 5 seconds is not a standard OSPF hello interval; it is sometimes used in tuned configurations but is not the default. Option D is wrong because 40 seconds is the default dead interval on broadcast networks, not the hello interval.

1133
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP server for a subnet. The router must provide IP addresses, default gateway, and DNS server information to clients. Which configuration is required?

A.ip dhcp pool POOL1, network 192.168.1.0 255.255.255.0, default-router 192.168.1.1, dns-server 8.8.8.8
B.ip dhcp pool POOL1, network 192.168.1.0 255.255.255.0, default-router 192.168.1.1, dns-server 8.8.8.8, lease 0 8
C.ip dhcp excluded-address 192.168.1.1 192.168.1.10, then ip dhcp pool POOL1 with network 192.168.1.0 255.255.255.0 and default-router 192.168.1.1
D.ip dhcp pool POOL1, host 192.168.1.100 255.255.255.0, hardware-address 0000.1111.2222
AnswerA

This configuration creates a DHCP pool named POOL1, defines the network and subnet mask, and provides the default gateway and DNS server. The ip dhcp pool command enters DHCP pool configuration mode, where network, default-router, and dns-server are valid commands. This fully satisfies the requirement to provide IP addresses, gateway, and DNS information to clients. It is the correct and standard way to configure a Cisco IOS DHCP server.

Why this answer

A Cisco IOS DHCP server requires a pool with network, default-router, and dns-server commands to provide IP addresses, gateway, and DNS information. The excluded-address command is optional but often used. The lease command is optional and not required for basic operation.

Manual bindings are for specific hosts and do not serve a subnet. Therefore, the configuration that includes network, default-router, and dns-server is the correct choice.

Exam trap

The trap here is focusing on excluded addresses or lease times as required, when the essential DHCP options for client configuration are network, default-router, and dns-server.

1134
MCQmedium

An enterprise is migrating a legacy application from a physical server to a virtual machine on a KVM-based hypervisor. The application requires direct access to a PCIe network interface card for performance reasons. The engineer needs to provide the VM with dedicated hardware access while maintaining isolation from other VMs. Which technology should the engineer use?

A.Use PCI passthrough to assign the NIC directly to the VM.
B.Enable SR-IOV and assign a virtual function to the VM.
C.Configure a paravirtualized network driver (virtio).
D.Attach the VM to a Linux bridge using macvtap.
AnswerA

PCI passthrough uses an IOMMU such as Intel VT-d to remap the physical NIC's PCIe function directly into the guest's address space, so the VM's device driver owns the entire NIC exclusively. The hypervisor leaves the data plane, eliminating virtual switching and emulation overhead to reach native line-rate throughput. However, this dedicates the NIC to a single VM, so it cannot be shared and live migration is typically unsupported because the device is pinned.

Why this answer

PCI passthrough (Option A) is correct because it assigns the entire physical PCIe NIC directly to the VM, giving it exclusive, dedicated hardware access with full performance and no hypervisor overhead. This meets the requirement for direct access while maintaining isolation, as other VMs cannot use the same device.

Exam trap

Cisco often tests the distinction between PCI passthrough (dedicated, exclusive access) and SR-IOV (shared, but with virtual functions), and the trap here is that candidates may choose SR-IOV thinking it provides 'dedicated' access, when in fact it still involves the PF and is designed for sharing the physical NIC among multiple VMs.

How to eliminate wrong answers

Option B is wrong because SR-IOV assigns a virtual function (VF) to the VM, which provides near-direct access but still involves the physical function (PF) and the hypervisor's IOMMU for mediation, not fully dedicated hardware access like passthrough. Option C is wrong because paravirtualized drivers (virtio) emulate a network device in software, adding hypervisor overhead and not providing direct PCIe hardware access. Option D is wrong because macvtap connects the VM to a Linux bridge via a tap interface, which uses software switching and does not grant direct hardware access to the NIC.

1135
Drag & Dropmedium

Drag and drop the steps of creating and applying an Ansible role for network device configuration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, define the role structure with defaults, vars, tasks, and handlers. Then, write the tasks in main.yml to configure interfaces. Next, set default variables in defaults/main.yml.

After that, create a playbook that references the role. Finally, execute the playbook against the target inventory.

1136
MCQmedium

A network architect is designing a new branch office that requires a controller-based wireless solution with centralized management, but the branch has limited bandwidth and must continue forwarding client traffic locally even if the WAN link to the headquarters controller fails. The branch has a single Cisco Catalyst 9800-L controller and several Cisco Catalyst 9100 access points. Which deployment mode should the architect choose for the access points?

A.Local mode with CAPWAP control and data tunnels to the controller
B.Sniffer mode with packet capture to a remote server
C.FlexConnect mode with local switching enabled on the access points
D.Monitor mode with dedicated air monitoring on all access points
AnswerC

FlexConnect mode allows the access point to switch client traffic locally at the branch while still being managed by the controller. If the WAN link fails, the AP enters standalone mode and continues to serve clients with local switching, meeting the requirement for local forwarding and reduced WAN bandwidth usage. This is the correct choice for branch survivability.

Why this answer

FlexConnect with local switching allows the access point to forward client traffic locally at the branch, reducing WAN bandwidth consumption and providing survivability if the controller becomes unreachable. The controller still manages the AP for configuration and control plane functions, but data traffic does not need to traverse the WAN. This matches the branch requirements for centralized management and local forwarding.

Exam trap

The trap here is assuming that any controller-based deployment tunnels all client traffic to the controller, overlooking FlexConnect local switching for branch survivability.

1137
MCQhard

A network engineer is configuring an IP SLA operation to monitor the reachability of a critical server at 10.1.1.1. The engineer wants to generate a syslog message and trigger a track object if the response time exceeds 100 ms. Which IP SLA operation type should be used?

A.HTTP
B.ICMP Echo
C.UDP Jitter
D.TCP Connect
AnswerB

ICMP Echo is the correct choice because it measures round-trip time and reachability to a destination. The engineer can set a threshold of 100 ms and configure a reaction to trigger when the threshold is exceeded, which can then be tracked. This operation type is specifically designed for this purpose.

Why this answer

ICMP Echo is the most suitable IP SLA operation for monitoring basic reachability and round-trip time to a server. It allows configuration of a threshold and reactions, which can trigger syslog messages and track objects when the threshold is exceeded, directly meeting the engineer's requirements.

Exam trap

The trap here is selecting a more complex operation like UDP Jitter or TCP Connect when the requirement is simply to monitor reachability and response time with a threshold.

1138
MCQeasy

A network engineer uses Cisco DNA Center API to retrieve the health of a device. The API call returns: ```json { "response": [ { "deviceId": "1234567890", "healthScore": 85, "overallHealth": "good", "memory": { "used": 4096, "total": 8192, "usage": 50 }, "cpu": { "usage": 25 } } ] } ``` What does the healthScore of 85 indicate?

A.The device is healthy with a score of 85 out of 100.
B.The device is critical and needs immediate attention.
C.The device has 85% memory usage.
D.The device has 85% CPU usage.
AnswerA

The healthScore field is a normalised 0-100 metric, so 85 denotes good overall device health, corroborated by overallHealth set to good, 50 percent memory usage and 25 percent CPU usage. It is not a percentage of failed checks.

Why this answer

In Cisco DNA Center's device health API, healthScore is a normalized 0–100 value where higher is better; 85 corresponds to 'good' overall health. The overallHealth field ('good') confirms the interpretation. Memory usage (50%) and CPU usage (25%) are separate metrics and are not the healthScore.

Exam trap

350-401 often tests whether candidates can parse JSON API responses correctly; the trap is confusing a nested metric (memory.usage or cpu.usage) with the top-level healthScore.

How to eliminate wrong answers

Option B is wrong because a critical device would show a low healthScore (typically below 60) and overallHealth would be 'poor' or 'critical', not 'good'. Option C is wrong because memory usage is reported separately as memory.usage = 50, not 85. Option D is wrong because CPU usage is reported separately as cpu.usage = 25, not 85.

1139
Multi-Selectmedium

Which two statements about Rapid PVST+ are true? (Choose two.)

Select 2 answers
A.Rapid PVST+ uses a proposal/agreement handshake to achieve rapid convergence.
B.Rapid PVST+ runs a separate instance of STP for each VLAN.
C.Rapid PVST+ requires the UplinkFast feature to be enabled for fast uplink convergence.
D.In Rapid PVST+, the root bridge is elected based on the lowest MAC address only.
E.Rapid PVST+ supports only two port roles: designated and root.
AnswersA, B

Rapid PVST+ replaces the timer-based listening and learning states with a proposal/agreement handshake between switches, synchronising port roles quickly. This mechanism drives rapid convergence per VLAN, satisfying the requirement for fast topology reconvergence after a link change.

Why this answer

Rapid PVST+ is an enhancement of the original 802.1D STP that provides faster convergence by using a proposal/agreement handshake. It runs a separate instance of RSTP for each VLAN, enabling per-VLAN load balancing. The UplinkFast feature is not needed because RSTP already handles uplink convergence quickly.

The root bridge is elected based on bridge priority, not MAC address alone. Port roles include alternate and backup, not just designated and root.

1140
MCQhard

A network engineer is troubleshooting a Cisco ACI environment where a tenant's application is experiencing intermittent connectivity issues. The engineer suspects that the issue is related to the ACI fabric's forwarding behavior. Which tool can be used to verify the end-to-end path and policy enforcement for a specific flow within the ACI fabric?

A.Cisco APIC Tenant Traceroute
B.Cisco APIC Contract Viewer
C.Cisco ACI Virtual Edge (AVE) CLI
D.Cisco Nexus Dashboard Insights
AnswerA

The Cisco APIC Tenant Traceroute tool allows engineers to trace the path of a specific flow through the ACI fabric, from source to destination. It simulates the flow and shows each step, including policy enforcement points, leaf and spine switches, and any drop or redirect actions. This is ideal for troubleshooting intermittent connectivity issues because it provides visibility into the actual forwarding path and policy application. It helps identify where packets may be dropped or misrouted within the fabric.

Why this answer

The Cisco APIC Tenant Traceroute tool is designed to trace the end-to-end path of a specific flow within the ACI fabric. It simulates the flow and shows each hop, including policy enforcement and any drops. This makes it the best choice for troubleshooting intermittent connectivity issues.

The Contract Viewer only shows policy configuration, the AVE CLI is limited to virtual edge troubleshooting, and Nexus Dashboard Insights is more for analytics than on-demand path tracing.

Exam trap

The trap here is assuming that a monitoring tool like Nexus Dashboard Insights can provide the same real-time path tracing as the dedicated Tenant Traceroute tool.

1141
Matchingmedium

Drag and drop each LDP message type on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Discovers LDP neighbors on a link

Establishes and negotiates LDP session parameters

Maintains an established LDP session

Advertises label bindings for FECs

Reports errors or advisory information

Why these pairings

Discovery uses Hello messages, Session uses Initialization/Keepalive, Advertisement uses Label Mapping, and Notification signals errors.

1142
Matchingmedium

Drag and drop each NFV component on the left to its matching role on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Software instance of a network function running on NFVI

Compute, storage, and networking resources that host VNFs

Framework for lifecycle management and orchestration of NFV resources

Abstraction layer that decouples VNF software from underlying hardware

Manages fault, configuration, accounting, performance, and security for a VNF

Why these pairings

VNFs are software implementations of network functions; NFVI provides the infrastructure; MANO orchestrates and manages the lifecycle.

1143
Drag & Dropmedium

Drag and drop the steps of DMVPN Phase 3 NHRP registration and spoke-to-spoke tunnel establishment into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In DMVPN Phase 3, the spoke first registers its NHRP mapping with the hub, then the hub propagates the mapping. When a spoke needs to reach another spoke, it sends an NHRP resolution request to the hub, the hub replies with the mapping, and then the spoke initiates a direct IPsec tunnel to the target spoke.

1144
MCQeasy

A network engineer runs the following command on Router R1: R1# show ip access-lists 101 Extended IP access list 101 10 permit tcp 192.168.1.0 0.0.0.255 any eq 80 (100 matches) 20 deny tcp any any eq 23 (50 matches) 30 permit ip any any (200 matches) Based on this output, what can be concluded?

A.Telnet traffic from 192.168.1.0/24 is permitted.
B.Telnet traffic from any source is denied.
C.HTTP traffic from any source is permitted.
D.All traffic is permitted because of the last entry.
AnswerB

This is correct because the ACL contains an explicit deny statement for TCP port 23 (Telnet) with source any and destination any. When a packet matches this entry, the router immediately drops it and does not evaluate any subsequent ACEs. Even though a later entry permits all IP traffic, the sequential and first-match nature of Cisco ACLs ensures the Telnet deny takes precedence. Thus, Telnet from any source, including 192.168.1.0/24, is denied.

Why this answer

The ACL explicitly denies TCP traffic to port 23 (Telnet) from any source, as shown by the 'deny tcp any any eq 23' statement with 50 matches. This rule is processed before the final permit any any, so Telnet traffic is denied regardless of the source IP.

Exam trap

Cisco often tests the sequential evaluation of ACLs, where candidates mistakenly think a later 'permit any any' overrides earlier denies, but the trap is that once a packet matches a deny rule, processing stops and the packet is dropped.

How to eliminate wrong answers

Option A is wrong because Telnet traffic from 192.168.1.0/24 is not explicitly permitted; the first line only permits HTTP (port 80) from that subnet, and the Telnet deny statement applies to all sources, including 192.168.1.0/24. Option C is wrong because HTTP traffic is permitted only from source 192.168.1.0/24, not from any source; the 'any' in the permit statement refers to the destination, not the source. Option D is wrong because while the last entry permits all traffic, it does not override the earlier deny for Telnet; ACLs are processed top-down, and once a match is found (like the Telnet deny), subsequent entries are not evaluated for that traffic.

1145
Multi-Selecthard

A network engineer is designing a Python script that uses the YANG models supported by a Cisco IOS XE device to configure interface descriptions via RESTCONF. The engineer wants to ensure the script uses the correct data model and avoids errors. Which TWO actions should the engineer take? (Choose two.)

Select 2 answers
A.Verify the YANG module revision date to ensure compatibility with the IOS XE version running on the device.
B.Use the 'Content-Type: application/yang-data+xml' header for all RESTCONF requests to ensure compatibility with YANG models.
C.Use the Cisco IOS XE native YANG model 'Cisco-IOS-XE-native' for interface configuration, as it is always available and supports all features.
D.Retrieve the list of supported YANG modules using the RESTCONF API endpoint /restconf/data/ietf-yang-library:modules-state.
E.Assume that all YANG modules are available on all IOS XE devices, so no verification is needed.
AnswersA, D

YANG modules are versioned with revision dates. A module revision may change between IOS XE releases, and using an outdated or mismatched revision can cause errors. By checking the revision date from the yang-library, the engineer can ensure the script uses the correct model version for the device's software, preventing schema mismatches.

Why this answer

To configure interfaces via RESTCONF using YANG models, the engineer must first discover which YANG modules are supported by the device. The ietf-yang-library provides this information, including module names, revisions, and features. Checking the revision date ensures the script uses the correct version for the device's software.

These two actions prevent schema errors and ensure successful configuration.

Exam trap

The trap here is assuming that all YANG modules are universally available or that the native model is always the correct choice, without verifying support and revision compatibility.

1146
MCQhard

A network engineer is implementing VXLAN with a Layer 2 gateway on a Cisco Nexus 9000 series switch. The design uses a distributed anycast gateway to provide optimal forwarding for hosts in the same subnet across different leaf switches. The engineer needs to ensure that all leaf switches use the same virtual MAC address for the gateway. Which feature must be configured to achieve this?

A.HSRP
B.VRRP
C.Anycast gateway
D.GLBP
AnswerC

The anycast gateway feature allows multiple leaf switches to share the same virtual IP and MAC address for a subnet's default gateway. This enables hosts to use a consistent gateway regardless of their location, and ensures optimal forwarding without traffic tromboning. Configuring the same virtual MAC on all leaf switches achieves the requirement.

Why this answer

The anycast gateway feature in Cisco VXLAN allows all leaf switches to share the same virtual IP and MAC address for a subnet's default gateway. This provides active-active gateway functionality, ensuring that hosts always use the optimal path and avoiding traffic tromboning. Configuring the same virtual MAC on all leaf switches is part of the anycast gateway configuration.

Exam trap

The trap here is assuming that traditional first-hop redundancy protocols like HSRP, VRRP, or GLBP can provide a distributed anycast gateway, when they actually elect a single active gateway.

1147
MCQmedium

A network engineer runs the following command on Router R9: R9# show ip pim neighbor PIM Neighbor Table Neighbor Address Interface Uptime Expires Mode 192.168.1.10 GigabitEthernet0/0 1w2d 00:01:30 Dense 192.168.1.11 GigabitEthernet0/0 2w0d 00:01:25 Sparse 192.168.1.12 GigabitEthernet0/1 3d04h 00:01:28 Sparse Based on this output, what can be concluded?

A.All PIM neighbors are operating in Sparse mode.
B.Router R9 has three PIM neighbors, one in Dense mode and two in Sparse mode.
C.The PIM neighbor 192.168.1.12 is on the same interface as the others.
D.All PIM neighbors are in the 'Expires' state.
AnswerB

This is the correct interpretation of the show ip pim neighbor output. The table lists exactly three PIM neighbors, and the Mode column identifies the first neighbor (192.168.1.11) as Dense while the other two neighbors (192.168.1.12 and 192.168.1.13) are Sparse. Therefore, Router R9 has three PIM neighbors total, with one in Dense mode and two in Sparse mode, accurately reflecting the per-interface PIM mode configuration.

Why this answer

The output shows three PIM neighbors: 192.168.1.10 with mode 'Dense', and 192.168.1.11 and 192.168.1.12 with mode 'Sparse'. This indicates that Router R9 has one neighbor operating in PIM Dense mode and two in PIM Sparse mode, which is consistent with the 'Mode' column in the 'show ip pim neighbor' output.

Exam trap

Cisco often tests the ability to read the 'Mode' column accurately and avoid assuming all neighbors share the same mode or interface, as candidates may overlook the 'Dense' entry or misinterpret the 'Expires' timer as a state rather than a countdown.

How to eliminate wrong answers

Option A is wrong because not all neighbors are in Sparse mode; 192.168.1.10 is explicitly listed as 'Dense'. Option C is wrong because 192.168.1.12 is on GigabitEthernet0/1, while the other two neighbors are on GigabitEthernet0/0, indicating different interfaces. Option D is wrong because the 'Expires' column shows time remaining (e.g., 00:01:30) before the neighbor entry times out, not a state; all neighbors are in an active state, not an 'Expires' state.

1148
Matchingmedium

Drag and drop each wireless roaming method on the left to its matching 802.11 standard on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

802.11r

802.11k

802.11k

802.11v

802.11v

Why these pairings

802.11r enables fast BSS transition (FT) with reduced reauthentication time; 802.11k provides neighbor report and channel information; 802.11v offers network-assisted power saving and BSS transition management.

1149
MCQmedium

A network engineer is deploying a Cisco SD-WAN solution for a global enterprise with multiple regional hubs. The engineer wants to ensure that traffic from branch offices to the internet is always forwarded directly from the branch, even if the branch has a primary MPLS link and a backup broadband link. The engineer configures the vSmart policy to direct internet-bound traffic to use the local exit at the branch. However, after deployment, the engineer notices that some internet traffic is still being sent to the regional hub before reaching the internet. What is the most likely cause of this behavior?

A.The engineer configured the data policy under VPN 0 instead of the service VPN (e.g., VPN 10).
B.The branch router does not have a default route in its routing table for the service VPN.
C.The engineer used a localized data policy instead of a centralized data policy.
D.The OMP route redistribution is not enabled on the branch router.
AnswerA

In Cisco SD-WAN, data policy is applied per VPN and direction. Placing the policy under VPN 0 (the transport VPN) means it only inspects traffic entering or leaving the transport interface, not the service-side traffic from the LAN. Internet-bound traffic from the service VPN (e.g., VPN 10) must be matched by a data policy configured under that specific service VPN. Because the policy was placed in VPN 0, it never matched the LAN traffic, so the local exit was not enforced and the traffic continued toward the hub.

Why this answer

In Cisco SD-WAN, data policies that control traffic forwarding (such as forcing local internet exit) must be applied to the service VPN (e.g., VPN 10) where the branch’s LAN and internet-bound traffic resides. Configuring the policy under VPN 0 (the transport VPN) only affects overlay tunnel traffic and control-plane packets, not user traffic. Since the engineer applied the policy to VPN 0, the policy did not match internet-bound traffic in the service VPN, causing it to follow the default route toward the regional hub.

Exam trap

Cisco often tests the distinction between VPN 0 and service VPNs in SD-WAN policy application, trapping candidates who assume any data policy applied globally will affect all traffic, when in fact the VPN context determines which traffic the policy matches.

How to eliminate wrong answers

Option B is wrong because the branch router does have a default route in the service VPN (likely pointing to the hub via OMP), which is why traffic is being sent to the hub; the issue is that the data policy intended to override that route was misapplied. Option C is wrong because a localized data policy is applied per device and can still influence local forwarding; the core problem is the VPN context, not the policy type. Option D is wrong because OMP route redistribution is not required for internet-bound traffic to be forwarded locally; the branch can have a local default route via DHCP or static, and the data policy is what should redirect traffic to that local exit.

1150
Drag & Dropmedium

Drag and drop the steps of IPsec IKEv2 tunnel establishment into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

IKEv2 establishment starts with IKE_SA_INIT to negotiate cryptographic parameters and exchange Diffie-Hellman keys. Next, IKE_AUTH authenticates the peers and establishes the first CHILD_SA. Then, additional CHILD_SAs can be created via CREATE_CHILD_SA.

Finally, the IPsec SA is used to encrypt data traffic.

1151
MCQmedium

An engineer is managing a Cisco NFVIS host running multiple virtual network functions (VNFs). The engineer needs to upgrade the NFVIS software to a new version that includes critical security patches. The upgrade process must minimize downtime. Which upgrade method should the engineer use?

A.Use the 'patch install' command to apply the upgrade without rebooting.
B.Use the 'software install add' command to stage the image, then 'activate' and 'commit' with a single reboot.
C.Perform a clean installation of the new NFVIS version and redeploy all VNFs.
D.Migrate all VNFs to another NFVIS host, then upgrade the original host.
AnswerB

This is the correct upgrade workflow: 'software install add' stages the image onto the device, 'activate' makes it the next boot image, and 'commit' finalizes the change. The entire process triggers a single reboot, which is the intended way to apply NFVIS upgrades while minimizing downtime. This is the only supported method for in-place NFVIS upgrades.

Why this answer

The 'software install add' command stages the new NFVIS image, followed by 'activate' and 'commit' with a single reboot, which minimizes downtime by performing the upgrade in a single reboot cycle. This method is the recommended approach for upgrading NFVIS while preserving existing VNF configurations and minimizing service disruption.

Exam trap

Cisco often tests the misconception that NFVIS upgrades can be applied without a reboot, but the correct method always requires a single reboot to activate the new software version.

How to eliminate wrong answers

Option A is wrong because NFVIS does not support a 'patch install' command that applies upgrades without a reboot; security patches typically require a system reboot to load the new kernel and services. Option C is wrong because a clean installation and redeployment of all VNFs would cause maximum downtime and is not the intended upgrade method for minimizing disruption. Option D is wrong because migrating all VNFs to another NFVIS host is a valid disaster recovery or maintenance technique but is not the standard upgrade method for a single host and introduces additional complexity and potential downtime.

1152
MCQmedium

A network engineer runs the following command on Router R9: R9# show ip ospf interface brief Interface PID Area IP Address/Mask Cost State Nbrs F/C Gi0/0 1 0 192.168.1.9/24 10 DR 2/2 Gi0/1 1 1 10.0.0.9/24 20 BDR 1/1 Lo0 1 0 9.9.9.9/32 1 LOOP 0/0 Based on this output, what can be concluded?

A.R9 is the Designated Router on the segment connected to Gi0/1.
B.R9 has two fully adjacent neighbors on Gi0/0.
C.The loopback interface Lo0 is advertised as a /24 network.
D.R9 is an Area Border Router.
AnswerB

The 'Nbrs F/C' column for Gi0/0, which stands for Fully adjacent neighbors / Count of all neighbors, displays 2/2. This means that R9 has exactly two neighbors on that interface, and both have reached the 'Full' state, indicating fully adjacent neighbors with synchronized link-state databases. Therefore, the statement that R9 has two fully adjacent neighbors on Gi0/0 is a factual conclusion directly supported by the output.

Why this answer

The output shows that on interface Gi0/0, R9 has a state of DR (Designated Router) and 2 fully adjacent neighbors (Nbrs F/C = 2/2). The '2/2' indicates 2 neighbors in a full state out of 2 total neighbors, meaning both neighbors have completed the OSPF adjacency process. Therefore, R9 has two fully adjacent neighbors on Gi0/0, making option B correct.

Exam trap

Cisco often tests the misinterpretation of the 'Nbrs F/C' field, where candidates confuse the total neighbor count with the number of fully adjacent neighbors, or assume that being in the DR state on one interface implies DR status on all interfaces.

How to eliminate wrong answers

Option A is wrong because on Gi0/1, R9 is in the BDR (Backup Designated Router) state, not DR; the DR on that segment would be another router. Option C is wrong because the loopback interface Lo0 is configured with a /32 mask (as shown by 9.9.9.9/32), and OSPF advertises it as a host route (/32) by default, not as a /24 network. Option D is wrong because R9 has interfaces in Area 0 and Area 1, but the output does not show any interface in a different area that would indicate it is an ABR; an ABR must have at least one interface in Area 0 and one in another non-backbone area, which is true here, but the output does not confirm that R9 is actually performing ABR functions (e.g., it could be a simple multi-area router without LSA type 3 generation), and the question asks what can be concluded from the output—being in two areas does not automatically mean it is an ABR without further evidence of route redistribution between areas.

1153
MCQeasy

A network engineer executes the following command on Router R5: R5# show ip sla monitor configuration 4 IP SLAs Monitor Configuration Entry number: 4 Owner: Tag: Type of operation to perform: udp-jitter Target address: 192.168.5.10 Target port: 16384 Source address: 192.168.5.1 Source port: 0 Type Of Service parameter: 0x0 Request size (ARR data portion): 32 Operation timeout (milliseconds): 5000 Frequency (seconds): 60 Next Scheduled Start Time: Start Time already passed Group Scheduled : FALSE Life (seconds): Forever Entry Ageout (seconds): never Recurring (Starting Everyday, Starting Time: 00:00:01) Status of entry (SNMP RowStatus): Active Threshold (milliseconds): 5000 Distribution Statistics: Number of statistic hours kept: 2 Number of statistic distribution buckets kept: 1 Statistic distribution interval (milliseconds): 20 Enhanced History: Based on this output, what type of IP SLA operation is configured?

A.ICMP echo
B.UDP jitter
C.TCP connect
D.HTTP get
AnswerB

Correct. The output explicitly states the operation type is 'udp-jitter'. This IP SLA operation sends a series of UDP packets with sequence numbers and timestamps to a destination port, then compares send and receive times to calculate one-way delay, jitter, and packet loss. It is commonly used to emulate voice or video traffic and assess network quality for real-time applications.

Why this answer

The command output explicitly shows 'Type of operation to perform: udp-jitter', which confirms that the IP SLA operation is configured as UDP jitter. This operation measures round-trip delay, one-way delay, jitter, and packet loss by sending UDP packets to the target address and port (192.168.5.10:16384). The presence of jitter-specific fields like 'Threshold (milliseconds)' and 'Statistic distribution interval (milliseconds)' further validates this type.

Exam trap

Cisco often tests the ability to distinguish IP SLA types by key fields in the output, and the trap here is that candidates may overlook the explicit 'Type of operation to perform: udp-jitter' line and instead focus on the target port number (16384) or source address, mistakenly assuming it is a TCP connect or HTTP get operation.

How to eliminate wrong answers

Option A is wrong because ICMP echo (ping) would show 'Type of operation to perform: icmp-echo' and would not include jitter-specific parameters like target port, distribution statistics, or threshold values for jitter measurement. Option C is wrong because TCP connect would show 'Type of operation to perform: tcp-connect' and focuses on TCP connection establishment time, not on jitter or packet loss statistics. Option D is wrong because HTTP get would show 'Type of operation to perform: http-get' and measures HTTP transaction response time, lacking UDP jitter attributes such as source port, request size, and distribution statistics.

1154
MCQhard

A network administrator is configuring a Cisco IOS XE router to act as a VPN headend with IKEv2. The security policy requires that the router authenticate to peers using a certificate from a corporate PKI, and that peers authenticate using EAP-MSCHAPv2. Which IKEv2 authentication configuration on the headend meets these requirements?

A.Configure 'authentication local rsa-sig' and 'authentication remote eap query-identity' under the IKEv2 profile.
B.Configure 'authentication local pre-share' and 'authentication remote pre-share' under the IKEv2 profile.
C.Configure 'authentication local eap query-identity' and 'authentication remote rsa-sig' under the IKEv2 profile.
D.Configure 'authentication local rsa-sig' and 'authentication remote rsa-sig' under the IKEv2 profile.
AnswerA

The 'authentication local rsa-sig' command specifies that the local router uses RSA signatures, which are derived from a certificate, for its own authentication. The 'authentication remote eap query-identity' command instructs the router to request the peer's identity and use EAP for remote authentication, which supports EAP-MSCHAPv2. This combination matches the policy requirements for certificate-based local auth and EAP-based remote auth.

Why this answer

IKEv2 profiles separate local and remote authentication methods. To use a certificate for the headend, 'authentication local rsa-sig' is required. To authenticate peers with EAP-MSCHAPv2, 'authentication remote eap query-identity' is used, which triggers EAP negotiation and allows the peer to respond with EAP-MSCHAPv2 credentials.

Exam trap

The trap here is mixing up local and remote authentication keywords, or assuming that RSA signatures on both sides would satisfy an EAP requirement for peers.

1155
MCQmedium

Given the following configuration on a Cisco switch: monitor session 1 source interface GigabitEthernet1/0/1 - 3 both monitor session 1 destination interface GigabitEthernet1/0/4 What is the effect of this configuration?

A.Traffic from GigabitEthernet1/0/1, 1/0/2, and 1/0/3 is copied to GigabitEthernet1/0/4.
B.Only traffic from GigabitEthernet1/0/1 is copied to GigabitEthernet1/0/4.
C.Traffic from GigabitEthernet1/0/4 is copied to GigabitEthernet1/0/1, 1/0/2, and 1/0/3.
D.The configuration is invalid because a SPAN session can only have one source interface.
AnswerA

The range keyword in the SPAN session configuration designates GigabitEthernet1/0/1, 1/0/2, and 1/0/3 as multiple source interfaces, all feeding copied traffic to a single destination port, GigabitEthernet1/0/4. Local SPAN explicitly allows multiple source interfaces in one session, and the monitoring port receives a replica of each source's traffic without altering the original forwarding path, making this the correct behavior.

Why this answer

The configuration uses a local SPAN session to mirror traffic from a range of source interfaces (GigabitEthernet1/0/1 through 1/0/3) to a single destination interface (GigabitEthernet1/0/4). The keyword 'both' indicates that both ingress and egress traffic from the source interfaces are copied. This allows network administrators to monitor all traffic on those ports without disrupting the production flow.

Exam trap

Cisco often tests the hyphen range syntax in SPAN source interfaces, where candidates mistakenly think only the first interface is selected or that the syntax is invalid, rather than recognizing it as a valid range operator.

How to eliminate wrong answers

Option B is wrong because the hyphen in 'GigabitEthernet1/0/1 - 3' specifies a range of interfaces (1, 2, and 3), not just the first interface; Cisco IOS interprets the dash as a range operator. Option C is wrong because it reverses the direction of the SPAN session—the destination interface receives copied traffic, it does not send traffic to the sources. Option D is wrong because a SPAN session can have multiple source interfaces, either specified individually or as a range, as long as they are all on the same switch for a local SPAN.

1156
MCQeasy

A network administrator is configuring a Cisco Catalyst switch to prevent unauthorized devices from connecting to an access port. The administrator wants to ensure that only one MAC address is allowed on the port, and if a violation occurs, the port should be shut down and an SNMP trap sent. Which port security violation mode should be configured?

A.protect
B.restrict
C.errdisable
D.shutdown
AnswerD

Shutdown mode places the port into an error-disabled state when a violation occurs, effectively shutting it down. It also sends an SNMP trap and syslog message. This matches the requirement to shut down the port and send an SNMP trap. The port can be recovered manually or via errdisable recovery. This is the correct violation mode for the described policy.

Why this answer

The shutdown violation mode meets both requirements: it shuts down the port (error-disabled) and sends an SNMP trap. Protect mode only drops traffic, restrict mode drops and sends traps but does not shut down the port. Errdisable is a state, not a mode.

Thus, shutdown is the correct configuration for this security policy.

Exam trap

The trap here is confusing the errdisable state with a configurable violation mode, or assuming restrict mode also shuts down the port.

1157
MCQhard

A network engineer is designing a model-driven telemetry solution for a large enterprise network with thousands of devices. The engineer wants to minimize the load on the network devices and the collector by sending data only when significant changes occur. The engineer decides to use on-change subscriptions. However, after deployment, the engineer notices that some subscriptions are sending updates too frequently, causing high CPU usage on the devices. What is the most likely reason for this excessive update frequency?

A.The engineer configured a sample-interval in addition to on-change, causing both periodic and on-change updates
B.The YANG paths include high-frequency changing leafs like interface counters or CPU load
C.The collector is overwhelmed and sending back-pressure signals causing retransmissions
D.The engineer used JSON encoding instead of GPB, causing larger payloads and more CPU usage
AnswerB

On-change subscriptions trigger updates whenever a subscribed leaf changes. Selecting YANG paths containing rapidly fluctuating leafs such as interface counters or CPU load causes near-continuous notifications, driving excessive device CPU usage — precisely the symptom described in the stem.

Why this answer

On-change subscriptions in model-driven telemetry (MDT) trigger an update whenever a subscribed YANG leaf changes value. If the subscription path includes volatile leafs such as interface counters, CPU load, or queue statistics that change on every packet or polling cycle, the device will emit updates almost continuously, driving up CPU and collector load. The fix is to subscribe to stable configuration or state leafs, or use periodic subscriptions with a sample-interval for high-churn data.

Exam trap

The trap here is assuming that on-change subscriptions are always low-overhead; candidates forget that the update rate depends entirely on how volatile the subscribed YANG leafs are, not on the subscription mode itself.

How to eliminate wrong answers

Option A is wrong because configuring a sample-interval alongside on-change is not a standard MDT behavior that would cause both periodic and on-change updates to fire simultaneously — the subscription mode is either on-change or periodic, not both. Option C is wrong because collectors do not send back-pressure signals that cause devices to retransmit telemetry; MDT is a push model from device to collector, and retransmission is not a mechanism in this flow. Option D is wrong because JSON versus GPB encoding affects payload size and serialization efficiency, not the frequency of updates — the update rate is determined by the subscription trigger, not the encoding format.

1158
MCQmedium

A network engineer is troubleshooting a connectivity problem between two hosts on the same VLAN. The engineer suspects a duplex mismatch on the switch port. Which command should be used to verify the duplex settings on a Cisco Catalyst switch interface?

A.show controllers ethernet-controller
B.show interfaces gigabitEthernet 0/1
C.show interfaces counters errors
D.show interfaces status
AnswerB

The show interfaces gigabitEthernet 0/1 command provides detailed information about the interface, including duplex, speed, and error counters. This allows the engineer to confirm the operational duplex mode and detect a mismatch. It is the most direct way to verify duplex settings on a specific interface.

Why this answer

To verify duplex settings on a Cisco Catalyst switch interface, the show interfaces command with the specific interface is the most appropriate because it displays the operational duplex, speed, and error counters. This allows the engineer to quickly identify a duplex mismatch, which often results in late collisions and performance degradation.

Exam trap

The trap here is assuming that summary commands like show interfaces status provide enough detail to diagnose duplex mismatches, when they actually lack the granular error counters needed.

1159
MCQeasy

What is the default OSPF hello interval on an Ethernet link?

A.10 seconds
B.30 seconds
C.40 seconds
D.5 seconds
AnswerA

On Ethernet broadcast multi-access networks, OSPF's default hello interval is 10 seconds. This value is defined in RFC 2328 for broadcast and point-to-point interfaces, and the associated dead interval is 40 seconds (4 times the hello). The 10-second hello keeps neighbor adjacency establishment quick while maintaining a reasonable control-plane overhead.

Why this answer

The default OSPF hello interval on an Ethernet link is 10 seconds, as specified in RFC 2328. Ethernet is a broadcast multi-access network type, and OSPF uses a 10-second hello interval on such networks to maintain neighbor adjacencies and detect failures within the dead interval (default 40 seconds, or 4 times the hello interval).

Exam trap

Cisco often tests the confusion between the OSPF hello interval and dead interval, where candidates mistakenly select 40 seconds (the dead interval) instead of 10 seconds (the hello interval) on Ethernet links.

How to eliminate wrong answers

Option B (30 seconds) is wrong because 30 seconds is the default hello interval for OSPF on non-broadcast multi-access (NBMA) networks, such as Frame Relay, not on Ethernet. Option C (40 seconds) is wrong because 40 seconds is the default OSPF dead interval on Ethernet, not the hello interval; candidates often confuse the two. Option D (5 seconds) is wrong because 5 seconds is the default hello interval for OSPF on point-to-point and point-to-multipoint networks, not on Ethernet broadcast multi-access links.

1160
MCQeasy

A network administrator is configuring a Cisco Catalyst switch to allow management access only from the subnet 10.10.10.0/24. The administrator wants to apply an ACL to the VTY lines. Which command correctly applies the ACL named MGMT to the VTY lines?

A.ip access-group MGMT in
B.access-class MGMT in
C.ip access-class MGMT in
D.access-list MGMT in
AnswerB

The access-class command is used under line configuration mode to restrict incoming VTY connections based on an ACL. The in keyword specifies that the ACL filters traffic entering the VTY lines. This is the correct way to apply an ACL to management access, ensuring only hosts from permitted subnets can establish SSH or Telnet sessions.

Why this answer

To restrict management access to a Cisco device, an ACL is defined globally and then applied to the VTY lines using the access-class command in line configuration mode. The in keyword filters incoming connections. This ensures that only hosts matching the ACL's permit statements can establish remote management sessions, effectively limiting access to the specified subnet.

Exam trap

The trap here is confusing interface ACL application with VTY ACL application; many candidates mistakenly use ip access-group on VTY lines, but the correct command is access-class.

1161
Matchingmedium

Drag and drop each 802.1X component on the left to its matching role on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Client device requesting network access

Network device that enforces port-based access control

RADIUS server that validates credentials and returns authorization attributes

Protocol used between supplicant and authenticator to carry EAP frames

Protocol used between authenticator and authentication server for AAA

Why these pairings

The supplicant requests access, the authenticator (switch/AP) enforces port control, and the authentication server (RADIUS) validates credentials.

1162
Drag & Dropmedium

Drag and drop the steps of TACACS+ command authorization flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

TACACS+ command authorization starts with the user entering a command, which is sent to the TACACS+ server. The server checks the command against the user's authorization profile and responds with permit or deny. The device executes or blocks the command accordingly, and finally logs the result.

1163
MCQmedium

A network engineer is configuring a Cisco Catalyst switch port that connects to an IP phone and a PC. The phone must tag its voice traffic with VLAN 200, and the PC must send untagged traffic that the switch places into VLAN 10. Which interface configuration accomplishes this?

A.switchport mode access switchport access vlan 10 switchport voice vlan 200
B.switchport mode trunk switchport trunk native vlan 10 switchport trunk allowed vlan 200
C.switchport mode access switchport access vlan 200 switchport voice vlan 10
D.switchport mode trunk switchport trunk encapsulation dot1q switchport trunk native vlan 200
AnswerA

This is the correct configuration. Setting the port to access mode with access VLAN 10 handles the untagged PC traffic, while the switchport voice vlan 200 command tells the switch to recognize 802.1Q-tagged frames for VLAN 200 as voice traffic from the attached IP phone. This is the standard Cisco IP telephony deployment model for a single physical port supporting both a phone and a PC.

Why this answer

The access-plus-voice configuration is the standard way to support an IP phone and a PC on one switch port. The access VLAN carries untagged PC traffic, and the voice VLAN carries 802.1Q-tagged phone traffic. This allows the phone to tag its own traffic while the PC sends untagged frames, and the switch classifies them into the correct VLANs without needing a trunk on the port.

Exam trap

The trap here is assuming that a trunk is required to support a voice VLAN on an access port, when the switchport voice vlan command already handles the tagging.

1164
Matchingmedium

Drag and drop each cisco.ios module on the left to its matching purpose on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Push configuration commands to Cisco IOS devices

Execute show and exec commands on Cisco IOS devices

Collect device facts such as version, interfaces, and serial numbers

Manage VLAN configuration (create, delete, modify)

Configure Layer 3 interface properties like IP address

Why these pairings

ios_config pushes configuration commands, ios_command runs show commands, ios_facts gathers device facts, ios_vlans manages VLANs, and ios_l3_interfaces configures Layer 3 interfaces.

1165
MCQmedium

Examine the following configuration snippet applied to a Cisco IOS-XE device: interface GigabitEthernet0/1 ip address 10.1.1.1 255.255.255.0 ip nat inside ! interface GigabitEthernet0/2 ip address 192.168.1.1 255.255.255.0 ip nat outside ! access-list 100 permit ip 10.1.1.0 0.0.0.255 any ip nat inside source list 100 interface GigabitEthernet0/2 overload What is the effect of this configuration?

A.It translates all IP traffic from 10.1.1.0/24 to the IP address 192.168.1.1 using port address translation.
B.It performs static NAT for the host 10.1.1.1 to 192.168.1.1.
C.It translates all traffic from 192.168.1.0/24 to the IP address 10.1.1.1.
D.It allows all IP traffic from any source to any destination without translation.
AnswerA

Port address translation is enabled by the **overload** keyword, which lets many inside hosts share the single outside address 192.168.1.1 by multiplexing sessions across unique source port numbers. Access-list 100 matches the 10.1.1.0/24 source range, satisfying the requirement to translate all inside traffic to that interface address.

Why this answer

The configuration uses 'ip nat inside source list 100 interface GigabitEthernet0/2 overload', which is dynamic NAT with PAT (overload). ACL 100 matches all traffic sourced from 10.1.1.0/24, and the 'overload' keyword enables port address translation so many inside hosts share the single outside interface IP 192.168.1.1. Therefore all IP traffic from 10.1.1.0/24 is translated to 192.168.1.1 using PAT.

Exam trap

The trap here is confusing dynamic NAT with overload (PAT) against static NAT, and reversing the inside/outside direction — candidates who see 'ip nat inside source' and assume a one-to-one mapping pick static NAT, while those who misread the interface roles pick the reversed translation.

How to eliminate wrong answers

Option B is wrong because static NAT requires the 'ip nat inside source static <inside-local> <inside-global>' command, which is absent here; the config uses a dynamic source list with overload. Option C is wrong because the direction is reversed — the 'ip nat inside' interface is 10.1.1.1/24 and 'ip nat outside' is 192.168.1.1/24, so translation goes from 10.1.1.0/24 to 192.168.1.1, not the other way. Option D is wrong because ACL 100 is referenced by the NAT source list, not applied to an interface as a traffic filter, and NAT is actively configured, so traffic is not passed untranslated.

1166
MCQmedium

A network engineer runs the following command on Router R1: R1# show crypto isakmp sa dst src state conn-id slot 10.1.1.2 10.1.1.1 MM_NO_STATE 1 0 Based on this output, what can be concluded?

A.The IPsec VPN tunnel is fully established and passing traffic.
B.IKE Phase 1 is in progress but not yet complete.
C.The ISAKMP SA has been deleted due to a timeout.
D.The remote peer has rejected the IKE proposal.
AnswerB

In IKEv1 main mode, MM_NO_STATE is the initial state entered when the IKE SA negotiation is starting but no proposal has been accepted. This state reflects an active attempt: the router is either sending or waiting for main mode packets, and the SA has not yet progressed to later states such as MM_SA_SETUP, MM_KEY_EXCH, or ultimately QM_IDLE. Thus, the tunnel is being built but is not finished, and the negotiation could be ongoing or stalled, but it is definitively not complete.

Why this answer

The output shows an ISAKMP Security Association (SA) in MM_NO_STATE, which indicates that IKE Phase 1 (Main Mode) negotiations have been initiated but have not yet completed. The state MM_NO_STATE means no Main Mode state has been established, so the IKE SA is not fully formed, and IPsec Phase 2 cannot proceed. Therefore, the VPN tunnel is not established, and Option B correctly identifies that IKE Phase 1 is in progress but incomplete.

Exam trap

Cisco often tests the misconception that any ISAKMP SA entry indicates a working tunnel, but the state field is critical—MM_NO_STATE means the negotiation is incomplete, not that the tunnel is up.

How to eliminate wrong answers

Option A is wrong because MM_NO_STATE indicates the IKE SA is not established, so the IPsec VPN tunnel cannot be fully established or passing traffic. Option C is wrong because a deleted SA would show a state like MM_DELETE or no entry at all, not MM_NO_STATE. Option D is wrong because a rejected IKE proposal would typically result in a state like MM_NO_STATE or an error message in the debug output, but the presence of an SA entry with conn-id 1 suggests the negotiation is still ongoing, not that it has been rejected.

1167
MCQmedium

Consider the following configuration on a Cisco IOS-XE router: vrf definition RED rd 100:1 route-target export 100:1 route-target import 100:1 ! interface GigabitEthernet0/2 vrf forwarding RED ip address 10.10.10.1 255.255.255.0 Which statement is true about this configuration?

A.The VRF RED is correctly configured for MPLS L3VPN, and the interface is placed in VRF RED.
B.The 'rd' command is optional for VRF operation and can be omitted.
C.The 'route-target export' and 'route-target import' must match the RD value exactly.
D.This configuration will cause the interface to use the global routing table for forwarding.
AnswerA

This configuration is valid for MPLS L3VPN because the VRF RD (route distinguisher) uniquely identifies VRF RED in the MPLS domain, and the export/import route targets define how routes are distributed to other VRFs. Associating the interface with VRF RED via 'ip vrf forwarding RED' ensures that all traffic on that interface is forwarded using VRF RED's routing and CEF tables, not the global table. This is exactly how a customer edge interface is bound to a VPN routing instance in a service provider MPLS VPN deployment.

Why this answer

The configuration defines a VRF named RED with an RD of 100:1 and matching route-target import/export values, which is the standard setup for an MPLS L3VPN. The 'vrf forwarding RED' command under the interface assigns that interface to the VRF, isolating its routing table from the global table. This allows the router to participate in a Layer 3 VPN by importing and exporting routes with the specified route-target.

Exam trap

Cisco often tests the misconception that the route-target must match the RD exactly, but in reality they serve different purposes and can be configured independently.

How to eliminate wrong answers

Option B is wrong because the 'rd' (route distinguisher) command is mandatory for VRF operation in MPLS L3VPN contexts; without it, the VRF cannot distinguish overlapping IP prefixes across different VPNs. Option C is wrong because the route-target import/export values do not have to match the RD value; they are independent identifiers used for VPN route distribution and can differ from the RD. Option D is wrong because the 'vrf forwarding RED' command under the interface causes the interface to use the VRF-specific routing table, not the global routing table.

1168
Multi-Selectmedium

A network engineer is designing a Python script that uses the YANG models supported by a Cisco IOS XE device to retrieve interface statistics via NETCONF. The engineer wants to ensure the script can parse the response and extract the operational data. Which two steps are necessary when using the ncclient library to retrieve and process the data? (Choose two.)

Select 2 answers
A.Enable the :candidate capability on the device to retrieve statistics
B.Parse the XML response using a library like xml.etree.ElementTree or lxml
C.Convert the XML response to JSON using the ncclient library
D.Use the <get> RPC with a filter specifying the interface statistics subtree
E.Use the <edit-config> RPC to read the interface statistics
AnswersB, D

NETCONF returns data in XML format. To extract specific values, the script must parse the XML. Libraries such as xml.etree.ElementTree or lxml allow navigation of the XML tree. This step is necessary to process the response and retrieve the statistics values for further use.

Why this answer

To retrieve interface statistics via NETCONF, the script must send a <get> RPC with a filter to target the specific data. The response is XML, so parsing it with an XML library is required to extract values. Other options like <edit-config> or :candidate are for configuration management, not data retrieval.

Exam trap

The trap here is thinking that ncclient automatically converts XML to JSON or that <edit-config> can be used for reading data, but NETCONF uses XML and <get> for retrieval.

1169
MCQmedium

A network engineer is comparing first-hop redundancy options for a campus access layer. The requirement is to provide gateway redundancy for IPv6 hosts while also allowing load sharing between two routers, and the solution must use an open standard rather than a Cisco-proprietary protocol. Which FHRP should the engineer select?

A.Proxy Address Resolution Protocol (Proxy ARP)
B.Gateway Load Balancing Protocol (GLBP)
C.Hot Standby Router Protocol (HSRP) version 2
D.Virtual Router Redundancy Protocol (VRRP) version 3
AnswerD

VRRPv3 is an open standard defined by the IETF and supports both IPv4 and IPv6. It allows multiple routers to share a virtual IP and can be configured for load sharing across groups. Since the scenario requires IPv6 gateway redundancy with an open standard, VRRPv3 satisfies all stated conditions.

Why this answer

VRRPv3 is an IETF open standard that supports IPv6 and allows multiple routers to participate in gateway redundancy, with load sharing achievable through multiple virtual router groups. It is the only listed option that is both open standard and suited to IPv6 first-hop redundancy with load sharing.

Exam trap

The trap here is assuming that any FHRP supporting IPv6 also satisfies the open-standard requirement, when HSRP and GLBP remain Cisco-proprietary.

1170
Multi-Selectmedium

A network engineer is configuring a GRE tunnel between two Cisco IOS routers to transport multicast traffic and routing protocols across an IP network. Which two statements about GRE tunnel configuration and operation are true? (Choose two.)

Select 2 answers
A.GRE tunnel interfaces must be assigned an IP address from the same subnet as the physical interfaces.
B.GRE tunnels support multicast and broadcast traffic by default.
C.GRE tunnels can only carry unicast IP traffic.
D.The tunnel source and tunnel destination must be reachable via the underlay network.
E.GRE tunnels automatically encrypt all traffic passing through them.
AnswersB, D

GRE is designed to encapsulate a wide variety of protocols, including multicast and broadcast. When you configure a GRE tunnel, it acts like a virtual point-to-point link that can carry multicast traffic, which is essential for routing protocols like OSPF and EIGRP that use multicast hellos. This is a key advantage over IPsec tunnels, which typically only support unicast unless specifically configured with GRE.

Why this answer

GRE tunnels support multicast and broadcast traffic, making them suitable for carrying routing protocol hellos and other multicast applications. Additionally, the tunnel source and destination must be reachable via the underlay network for the tunnel to come up. GRE does not provide encryption, and tunnel interfaces are typically assigned IP addresses from a separate subnet, not the same as physical interfaces.

Exam trap

The trap here is assuming that GRE provides encryption or that it only supports unicast traffic, when in fact it supports multicast and broadcast but lacks encryption.

1171
Drag & Dropmedium

Drag and drop the steps of VNF service chain instantiation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Service chain instantiation begins with defining the chain, then selecting VNFs, allocating resources, connecting VNFs via virtual links, and finally testing the chain to verify functionality.

1172
Drag & Dropmedium

Drag and drop the steps of STP path cost manipulation for load balancing into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

To load balance with STP, first identify redundant links. Then change the path cost on one switch's port to make it less preferred. This alters the root port selection.

The switch recalculates the spanning tree, and traffic is redirected to the lower-cost path. Finally, verify the new root port and forwarding state.

1173
MCQhard

A network engineer is configuring MACsec on a point-to-point link between two Cisco Catalyst switches to provide Layer 2 encryption. The engineer wants to use a pre-shared key for authentication and ensure that the key is rotated periodically. Which MACsec component must be configured to specify the pre-shared key and the key rotation timer?

A.An IKEv2 profile with a preshared key and a rekey timer applied to the interface.
B.A RADIUS server configuration with a shared secret and a session timeout applied to the interface.
C.A MACsec key chain with a key string and a lifetime configured under the interface.
D.A crypto map with a preshared key and a lifetime applied to the switch port.
AnswerC

MACsec on Cisco switches uses a key chain to store the connectivity association key (CAK) and its lifetime. The key chain is referenced under the interface with the mka key-chain command, and the lifetime controls key rotation. This satisfies the requirement for a preshared key and periodic rotation.

Why this answer

MACsec on Cisco switches uses a key chain to store the connectivity association key and its lifetime, which controls key rotation. The key chain is referenced under the interface with the mka key-chain command. This configuration provides the preshared key and periodic rotation required by the scenario, unlike IPsec mechanisms such as IKEv2 or crypto maps.

Exam trap

The trap here is confusing MACsec key management with IPsec mechanisms like IKEv2 or crypto maps, when MACsec specifically uses MKA and a key chain for preshared keys and rotation.

1174
MCQhard

A network engineer is deploying a new Cisco Catalyst switch and needs to implement a loop prevention mechanism that allows rapid convergence and supports multiple VLANs. The engineer decides to use Rapid PVST+. Which statement accurately describes a characteristic of Rapid PVST+ operation?

A.It requires all switches in the network to be configured with the same bridge priority to ensure consistent root election.
B.It uses a single spanning-tree instance for all VLANs, which simplifies configuration but reduces flexibility.
C.It provides separate spanning-tree instances for each VLAN and uses Rapid Spanning Tree Protocol (RSTP) enhancements for faster convergence.
D.It is compatible only with switches running IEEE 802.1D STP and cannot interoperate with RSTP devices.
AnswerC

Rapid PVST+ is Cisco's implementation of RSTP that runs a separate instance per VLAN. It incorporates RSTP mechanisms such as edge ports, link-type point-to-point, and proposal/agreement to achieve rapid convergence. This allows per-VLAN topology optimization and fast failover, making it suitable for modern switched networks with multiple VLANs.

Why this answer

Rapid PVST+ is a Cisco enhancement that runs a separate RSTP instance per VLAN. It uses RSTP's rapid convergence features like edge ports and proposal/agreement, while maintaining per-VLAN topology. This allows for fast failover and load balancing across VLANs.

The other options mischaracterize its operation, such as claiming a single instance or lack of interoperability.

Exam trap

The trap here is confusing Rapid PVST+ with MSTP or single-instance STP, or assuming it lacks per-VLAN capabilities or RSTP interoperability.

1175
MCQmedium

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) for a new office. The office has a mix of corporate laptops and guest devices. The administrator wants to ensure that guest devices can only access the Internet and are isolated from the corporate network. Which WLC feature should be configured to achieve this?

A.FlexConnect local switching
B.Guest WLAN with a dedicated interface and ACL
C.Dynamic VLAN assignment
D.Access Control Lists (ACLs) on the WLC
AnswerB

Creating a separate guest WLAN mapped to a dedicated interface (e.g., a DMZ VLAN) and applying an ACL that permits only Internet-bound traffic is the standard method for guest isolation. This ensures guest devices cannot reach corporate subnets. The WLC supports this through interface mapping and ACLs applied to the WLAN.

Why this answer

To isolate guest traffic, the administrator should create a separate guest WLAN and map it to a dedicated interface, such as a DMZ VLAN. Then, an ACL can be applied to that WLAN to restrict traffic to only Internet-bound destinations. This prevents guests from accessing corporate resources.

Other options like dynamic VLAN or FlexConnect do not inherently provide the required isolation.

Exam trap

The trap here is thinking that dynamic VLAN assignment alone provides guest isolation, when actually a separate WLAN with a dedicated interface and ACL is needed.

1176
MCQmedium

A network engineer is building a Python script to configure a Cisco IOS XE device via RESTCONF. The script sends a POST request to the URI https://10.1.1.1/restconf/data/ietf-interfaces:interfaces with the JSON payload shown. The device returns HTTP 415 Unsupported Media Type. Which change to the script will resolve the error?

A.Add the header 'Accept: application/yang-data+json' to the request.
B.Include authentication credentials in the request body.
C.Change the HTTP method from POST to PUT.
D.Add the header 'Content-Type: application/yang-data+json' to the request.
AnswerD

RESTCONF requires the Content-Type header to be application/yang-data+json when sending a JSON payload. Without it, the device cannot determine the payload format and returns 415. Adding this header tells the server the body is YANG data encoded in JSON, allowing it to parse and apply the configuration.

Why this answer

RESTCONF uses HTTP and requires standard headers to indicate payload format. When sending JSON, the Content-Type header must be set to application/yang-data+json. The server uses this to select the correct parser.

Without it, the device returns 415 Unsupported Media Type, indicating it cannot process the body.

Exam trap

The trap here is confusing the Accept header (which specifies the desired response format) with the Content-Type header (which specifies the format of the request body).

1177
MCQmedium

An engineer retrieves telemetry data from a Cisco IOS-XE device using RESTCONF and receives the following response: ```json { "ietf-interfaces:interfaces": { "interface": [ { "name": "GigabitEthernet1", "type": "iana-if-type:ethernetCsmacd", "enabled": true, "ipv4": { "address": [ { "ip": "192.168.1.1", "netmask": "255.255.255.0" } ] } } ] } } ``` What is the correct way to access the IP address of the interface using Python?

A.data['ietf-interfaces:interfaces']['interface'][0]['ipv4']['address'][0]['ip']
B.data['interface'][0]['ipv4']['address']['ip']
C.data['interfaces']['interface']['ipv4']['address']['ip']
D.data['ietf-interfaces:interfaces']['interface']['ipv4']['address'][0]['ip']
AnswerA

RESTCONF returns the JSON exactly as structured by the YANG module, so the top-level key retains its module prefix. Indexing the interface list, then the ipv4 address list, reaches the ip leaf, matching the nested hierarchy shown in the response.

Why this answer

The JSON response nests the interface data under the top-level key 'ietf-interfaces:interfaces', then under 'interface' (a list), then indexes the first element, then accesses 'ipv4', then 'address' (a list), then indexes the first element, then accesses 'ip'. The correct path must include the module-prefixed top-level key, the list indexing on 'interface', and the list indexing on 'address'.

Exam trap

The trap is forgetting that YANG list nodes become Python lists requiring [0] indexing and that the top-level key includes the module prefix, causing candidates to omit either the prefix or the list index.

How to eliminate wrong answers

Option B is wrong because it omits the top-level 'ietf-interfaces:interfaces' key and treats 'interface' as a top-level key, and it also fails to index the 'address' list. Option C is wrong because it uses 'interfaces' without the 'ietf-interfaces:' module prefix and does not index the 'interface' list or the 'address' list. Option D is wrong because it fails to index the 'interface' list with [0], treating it as a dictionary instead of a list.

1178
MCQmedium

A network engineer runs the following command on Router R3: R3# show mpls ldp bindings lib entry: 10.1.1.1/32, rev 2 local binding: label: 16 remote binding: lsr: 10.1.1.2:0, label: 17 lib entry: 10.2.2.0/24, rev 4 local binding: label: 18 remote binding: lsr: 10.1.1.2:0, label: 19 lib entry: 10.3.3.0/24, rev 6 local binding: label: 20 remote binding: lsr: 10.1.1.2:0, label: 21 Based on this output, what is true?

A.For prefix 10.1.1.1/32, the local label is 16 and the remote label from LSR 10.1.1.2 is 17.
B.The router has learned label bindings from two different LDP peers.
C.The label for prefix 10.2.2.0/24 is 18 locally and 19 remotely, indicating that the remote LSR will use label 18.
D.The LIB entry for 10.3.3.0/24 has a revision number of 6, meaning it was the sixth entry added.
AnswerA

The output directly shows, for prefix 10.1.1.1/32, a local binding of label 16 and a remote binding advertised by LSR 10.1.1.2:0 with label 17. This satisfies the stem's requirement to interpret the LDP bindings table, confirming both label values and the advertising peer exactly as displayed.

Why this answer

The output of 'show mpls ldp bindings' directly shows that for prefix 10.1.1.1/32, the local label assigned by R3 is 16, and the remote label learned from LSR 10.1.1.2 (its LDP peer) is 17. This is a straightforward reading of the command output, confirming the local and remote label bindings for that FEC.

Exam trap

Cisco often tests the ability to correctly interpret 'show mpls ldp bindings' output, specifically the trap is that candidates confuse the remote label as the label the local router will use to forward traffic, when in fact the remote label is what the peer uses to reach the FEC.

How to eliminate wrong answers

Option B is wrong because the output shows only one remote LSR (10.1.1.2:0) for all three prefixes, indicating a single LDP peer, not two different peers. Option C is wrong because the remote label 19 is the label that the remote LSR (10.1.1.2) will use to reach 10.2.2.0/24, not the label that R3 will use; R3 will use its local label 18 to forward traffic to that prefix. Option D is wrong because the revision number (rev 6) is a local counter for changes to the LIB entry, not an indication of the order in which entries were added; it increments with each update to that specific FEC, not the sequence of all entries.

1179
MCQeasy

A network administrator is configuring a Cisco IOS router to provide DHCP services to a remote subnet. The router's interface on that subnet is configured with the address 10.1.1.1/24. Which command is required to exclude the router's own address from the DHCP pool?

A.ip dhcp pool 10.1.1.1
B.ip dhcp relay information option
C.ip dhcp excluded-address 10.1.1.1
D.ip dhcp excluded-address 10.1.1.0 10.1.1.255
AnswerC

The 'ip dhcp excluded-address' command prevents the router from assigning specific addresses, such as its own interface address, to DHCP clients. It is configured in global configuration mode and can specify a single address or a range. This ensures the router's IP is not leased to other devices.

Why this answer

The 'ip dhcp excluded-address' command is used to prevent specific IP addresses from being assigned by the DHCP server. In this scenario, excluding the router's interface address 10.1.1.1 ensures it remains available for the router itself and is not leased to a client.

Exam trap

The trap here is confusing the command to exclude addresses with the command to create a pool; excluding the entire subnet would break DHCP service.

1180
MCQeasy

An enterprise network uses OSPF in the core and EIGRP in the campus distribution layer. The engineer needs to redistribute routes between the two protocols. Which design consideration is most important to prevent routing loops?

A.Set appropriate administrative distance values for redistributed routes.
B.Use route maps to filter all redistributed routes.
C.Enable OSPF on all EIGRP interfaces.
D.Use a single routing protocol throughout the network.
AnswerA

Setting administrative distance (AD) for redistributed routes is essential because AD determines the trustworthiness of routing sources. When routes are redistributed between OSPF and EIGRP, their default AD values may cause a redistributed route (e.g., an EIGRP external route with AD 170) to be preferred over the original protocol's internal route, leading to routing loops or suboptimal paths. By explicitly setting AD values, you ensure that routes from the original protocol are always preferred, maintaining loop-free and predictable routing behavior.

Why this answer

Setting appropriate administrative distance values for redistributed routes is crucial to prevent routing loops when redistributing between OSPF and EIGRP. By default, EIGRP has an administrative distance of 170 for external routes and 90 for internal routes, while OSPF uses 110. If redistributed routes are not assigned a higher administrative distance, a router might prefer a redistributed route over a directly learned route, creating a feedback loop where routes are re-injected into the original protocol.

Adjusting the administrative distance ensures that redistributed routes are less preferred than native routes, breaking the loop.

Exam trap

Cisco often tests the misconception that route filtering (option B) is the primary loop-prevention mechanism, but the real trap is that administrative distance must be adjusted to prevent the redistribution feedback loop, especially when multiple routers perform mutual redistribution.

How to eliminate wrong answers

Option B is wrong because using route maps to filter all redistributed routes is overly restrictive and can prevent necessary route propagation, but it does not directly address the root cause of routing loops, which is the preference for redistributed routes over native ones. Option C is wrong because enabling OSPF on all EIGRP interfaces would merge the two routing domains, defeating the purpose of redistribution and potentially causing instability, but it does not prevent loops in a multi-protocol environment. Option D is wrong because using a single routing protocol throughout the network is a valid design choice but is not a consideration for preventing loops during redistribution; the question specifically asks about redistributing between two protocols, so this option avoids the problem rather than solving it.

1181
MCQmedium

A network engineer runs the following command on Switch SW4: SW4# show monitor session 4 Session 4 --------- Type : Local Session Source VLANs : RX Only : 10,20 Destination Ports : Gi1/0/25 Encapsulation : Native Ingress : Disabled Based on this output, what can be concluded?

A.Only incoming traffic on VLANs 10 and 20 is mirrored to Gi1/0/25.
B.Both incoming and outgoing traffic on VLANs 10 and 20 are mirrored.
C.This is an RSPAN session using VLANs 10 and 20 as remote VLANs.
D.The destination port Gi1/0/25 is configured to receive mirrored traffic.
AnswerA

The SPAN session is configured with source VLANs 10 and 20 and an explicit direction of 'receive only' (Rx). As frames ingress on any port that is an active member of those VLANs, the switch copies them to the destination port Gi1/0/25, while leaving the normal forwarding path untouched. No outgoing or transmitted frames from those VLANs are captured because the monitor direction is limited to ingress traffic.

Why this answer

The output shows a local SPAN session with source VLANs 10 and 20 configured for RX Only, meaning only incoming traffic on those VLANs is mirrored to the destination port Gi1/0/25. The 'Ingress: Disabled' confirms that the destination port does not inject any traffic back into the switch, and 'Encapsulation: Native' indicates the mirrored frames are sent without an additional VLAN tag. Therefore, option A is correct because the session explicitly mirrors only received (incoming) traffic from VLANs 10 and 20.

Exam trap

Cisco often tests the distinction between 'RX Only', 'TX Only', and 'both' in SPAN sessions, and candidates mistakenly assume that a source VLAN automatically mirrors all traffic in both directions unless explicitly stated otherwise.

How to eliminate wrong answers

Option B is wrong because the session specifies 'RX Only' for the source VLANs, which means only incoming traffic is mirrored, not both incoming and outgoing traffic. Option C is wrong because this is a local SPAN session (Type: Local Session), not an RSPAN session; RSPAN would use a dedicated RSPAN VLAN as the source, not VLANs 10 and 20 directly, and the session type would be 'Remote Session'. Option D is wrong because the destination port Gi1/0/25 is configured to receive mirrored traffic, but the question asks what can be concluded from the output; the statement in D is factually correct but does not describe the conclusion about what traffic is mirrored—it merely restates a configuration detail, and the key conclusion is about the source VLANs and direction.

1182
MCQmedium

A network engineer runs the following command on Router R1: R1# show bgp summary BGP router identifier 192.168.1.1, local AS number 65001 BGP table version is 10, main routing table version 10 Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 192.168.1.2 4 65002 1024 1020 10 0 0 00:12:34 15 192.168.1.3 4 65003 2048 2040 10 0 0 00:24:56 20 Based on this output, what can be concluded?

A.Both BGP sessions are in the established state
B.The BGP session with 192.168.1.2 is idle
C.Router R1 is using iBGP with both neighbors
D.The BGP table version is 10, meaning 10 prefixes are in the table
AnswerA

The output shows State/PfxRcd counts of 15 and 20 for the two neighbors. In BGP's state machine, only the established state populates the PfxRcd column with a numeric prefix count; any other state (Idle, Connect, Active, OpenSent, OpenConfirm) would display the state name or a placeholder. Consequently, both neighbors are fully peering and exchanging reachability information.

Why this answer

The 'State/PfxRcd' column shows the number of prefixes received from each neighbor, and the 'Up/Down' column shows the session uptime, both of which indicate that the BGP sessions are fully established. An idle session would show 'Idle' in the State/PfxRcd column, not a prefix count. Therefore, both sessions are in the established state.

Exam trap

Cisco often tests the distinction between the BGP table version (a change counter) and the prefix count in the State/PfxRcd column, leading candidates to mistakenly interpret the version number as the number of prefixes.

How to eliminate wrong answers

Option B is wrong because the output shows '15' and '20' in the State/PfxRcd column, indicating the sessions are established and exchanging prefixes; an idle session would display 'Idle' or 'Active' in that column. Option C is wrong because the neighbor AS numbers (65002 and 65003) differ from the local AS 65001, which means these are eBGP sessions, not iBGP (iBGP requires the same AS number). Option D is wrong because the BGP table version (10) is a version counter that increments with each change to the BGP table, not a count of prefixes; the actual number of prefixes is shown in the State/PfxRcd column (15 and 20).

1183
Multi-Selectmedium

Which two statements about PIM sparse mode (PIM-SM) are true? (Choose two.)

Select 2 answers
A.PIM-SM uses a pull model where receivers explicitly join the multicast group.
B.In PIM-SM, the rendezvous point (RP) is the root of the shared tree.
C.PIM-SM automatically switches to the shortest path tree (SPT) immediately after the first multicast packet is received.
D.PIM-SM requires all routers in the domain to be configured with the same RP address.
E.PIM-SM supports only one RP per multicast group.
AnswersA, B

PIM-SM builds distribution trees only when receivers signal interest, so it operates as a pull model: the last-hop router sends explicit PIM joins toward the rendezvous point. This satisfies the stem's requirement that receivers explicitly join the group, unlike dense-mode flood-and-prune push behaviour.

Why this answer

Option A is correct because PIM-SM operates on a pull model: receivers must explicitly signal their interest by sending IGMP joins, which trigger PIM (*,G) Join messages toward the RP, rather than relying on flood-and-prune push behavior. Option B is correct because in PIM-SM the rendezvous point (RP) is the root of the shared distribution tree (the RPT, denoted (*,G)), through which all sources initially send their traffic and receivers join. Option C is incorrect because the switch from the shared tree to the shortest path tree (SPT) is not immediate upon the first packet; it occurs when the last-hop router receives traffic and meets the SPT-switchover threshold, or is triggered administratively.

Option D is incorrect because PIM-SM does not require every router to be statically configured with the same RP address; RP information can be learned dynamically via bootstrap router (BSR) or Auto-RP mechanisms. Option E is incorrect because PIM-SM can support multiple RPs per multicast group (for load sharing and redundancy) using anycast RP or MSDP, and a single RP can serve multiple groups.

Exam trap

The trap is assuming that PIM-SM immediately switches to SPT or that only one RP is allowed, but the exam tests the pull model and the RP's role as the shared tree root, while the SPT switchover is conditional and multiple RPs are supported.

1184
MCQeasy

A network engineer is using the Cisco DNA Center API to initiate a network discovery. The API endpoint '/dna/intent/api/v1/discovery' is called with a POST request containing the following JSON payload: ```json { "discoveryType": "Range", "ipAddressList": "10.10.20.1-10.10.20.254", "protocolOrder": "SSH", "timeout": 5, "retryCount": 3 } ``` The API returns a 202 Accepted status code. What does this indicate?

A.The discovery was completed successfully and devices are added.
B.The request is invalid and the payload needs correction.
C.The discovery has been accepted and is being processed asynchronously.
D.The server is busy and the request is queued.
AnswerC

HTTP 202 Accepted means the request was validated and queued, not completed. Cisco DNA Center processes discovery asynchronously, returning a task identifier the client polls for status. A 200 would indicate synchronous completion; 202 confirms the discovery is running in the background.

Why this answer

A 202 Accepted status code indicates that the request has been accepted for processing, but the processing is not complete. In the context of Cisco DNA Center discovery, it means the discovery job has been initiated and will run asynchronously.

Exam trap

The trap is assuming that a 2xx status code always means immediate success, leading candidates to pick 'completed successfully' instead of recognizing asynchronous processing.

How to eliminate wrong answers

Option A is wrong because 202 does not mean the discovery is completed; that would be 200 OK or 201 Created. Option B is wrong because a 400 Bad Request would indicate an invalid payload. Option D is wrong because 202 is not about server busyness; 503 Service Unavailable would indicate that.

1185
Multi-Selectmedium

Which two statements about using Python for network automation are true? (Choose two.)

Select 2 answers
A.The netmiko library is commonly used to automate SSH connections to Cisco devices.
B.The paramiko library provides a high-level API for network automation tasks.
C.The requests library can be used to send HTTP requests to REST APIs on network devices.
D.The telnetlib library is recommended for secure network automation.
E.The scapy library is used to send configuration commands to network devices.
AnswersA, C

Netmiko builds on Paramiko to handle SSH transport, device prompts, and enable-mode escalation, so a Python script can drive Cisco CLI sessions programmatically. This satisfies the automation requirement by removing manual telnet or SSH interaction, unlike SNMP-based polling libraries.

Why this answer

Option A is correct because netmiko is a multi-vendor Python library built on top of Paramiko that simplifies establishing SSH (and Telnet) sessions to network devices such as Cisco IOS, IOS-XE, and NX-OS, handling prompts, paging, and enable mode automatically. Option C is correct because the requests library is the standard Python HTTP client used to send GET, POST, PUT, PATCH, and DELETE requests to REST APIs (for example, Cisco DNA Center, Meraki, or NX-API), typically with JSON payloads and authentication headers. Option B is incorrect because Paramiko is a low-level SSHv2 implementation, not a high-level network-automation API; netmiko provides that higher-level abstraction.

Option D is incorrect because telnetlib sends credentials and data in cleartext, so it is not recommended for secure automation—SSH-based tools like netmiko or Paramiko should be used instead. Option E is incorrect because Scapy is a packet crafting, sending, and sniffing library, not a tool for pushing configuration commands to network devices.

Exam trap

350-401 often tests library purpose confusion, especially paramiko vs. netmiko (low-level vs. high-level) and scapy vs. netmiko (packet crafting vs. device configuration), causing candidates to pick plausible-sounding but incorrect pairings.

1186
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip route 10.1.1.0 Routing entry for 10.1.1.0/24 Known via "bgp 65001", distance 200, metric 0 Tag 65002, type external Last update from 192.168.1.2 00:00:15 ago Routing Descriptor Blocks: * 192.168.1.2, from 192.168.1.2, 00:00:15 ago Route metric is 0, traffic share count is 1 AS Hops 1 Route tag 65002 MPLS label: 18 Based on this output, what can be concluded?

A.The route is learned via OSPF and tagged with an MPLS label.
B.The route is learned via BGP and has an MPLS label assigned, indicating MPLS forwarding.
C.The route is a directly connected interface with an MPLS label.
D.The route is a static route with an MPLS label.
AnswerB

The command output shows 'Known via bgp 65001' and 'MPLS label: 18', which together confirm that the route was received from a BGP peer in AS 65001 and that an MPLS label has been assigned to the prefix. In BGP labeled unicast or MPLS VPN operation, the label is propagated with the route so that ingress PEs can impose the correct label and forward traffic along the LSP. This is the only option that correctly correlates both the routing protocol source and the MPLS forwarding indicator.

Why this answer

The output shows the route is known via BGP (AS 65001) with a distance of 200, which is the administrative distance for external BGP routes. The presence of an MPLS label (18) in the routing table indicates that MPLS forwarding is enabled for this prefix, typically via Label Distribution Protocol (LDP) or BGP label distribution. This confirms that the route is learned via BGP and has an MPLS label assigned, making option B correct.

Exam trap

Cisco often tests the misconception that MPLS labels only appear in the CEF table or MPLS forwarding table, but they can also be displayed in the routing table when MPLS forwarding is active, leading candidates to incorrectly dismiss option B.

How to eliminate wrong answers

Option A is wrong because the route is explicitly identified as 'Known via bgp 65001', not OSPF, and OSPF does not use MPLS labels in the routing table. Option C is wrong because the route is not directly connected; it is learned from a neighbor (192.168.1.2) and has an AS hop count of 1, indicating it is a BGP external route. Option D is wrong because the route is not static; it is dynamically learned via BGP, as shown by the BGP AS number and the 'type external' field.

1187
MCQhard

A network engineer runs the following command on switch SW8: SW8# show cts role-based sgt-map 192.168.1.10 IP Address: 192.168.1.10 SGT: 10 Source: SXP Based on this output, what can be concluded?

A.The SGT mapping was configured manually.
B.The SGT mapping was learned via SXP from a peer.
C.The IP address 192.168.1.10 is not mapped to any SGT.
D.The SGT mapping is from local authentication.
AnswerB

The IP address 192.168.1.10 is associated with SGT 10, and the source column shows SXP. This means the binding was learned dynamically via the Security Exchange Protocol from a peer device that is speaking SXP, rather than being configured locally or derived from authentication events. SXP propagates IP-to-SGT mappings that were originally assigned at an authentication point, allowing downstream devices to perform SGT enforcement without direct authentication. Therefore, this is the correct interpretation of the output.

Why this answer

The output shows 'Source: SXP', which indicates that the Security Group Tag (SGT) mapping for IP address 192.168.1.10 was learned via the SXP (SGT Exchange Protocol) from a peer. SXP is used to propagate SGT-to-IP bindings from an authentication point (e.g., an ISE or a switch) to other network devices without requiring inline enforcement. Therefore, the mapping was not manually configured, not locally authenticated, and is indeed mapped to SGT 10.

Exam trap

Cisco often tests the distinction between the 'Source' field in 'show cts role-based sgt-map' output, where candidates may confuse 'SXP' with manual configuration or local authentication, leading them to incorrectly select options A or D.

How to eliminate wrong answers

Option A is wrong because the source is 'SXP', not 'Manual' or 'CLI', so the mapping was learned dynamically from a peer, not manually configured. Option C is wrong because the output explicitly shows an SGT value of 10, meaning the IP address is mapped to that SGT. Option D is wrong because the source is 'SXP', not 'Local' or 'Auth'; local authentication would show a source like 'Auth' or 'Local' and typically involves 802.1X or MAB, not SXP.

1188
MCQhard

A network administrator is deploying a new Cisco Catalyst switch in a data center. The switch must support a protocol that allows multiple physical links to be bundled into a single logical link, providing increased bandwidth and redundancy. The administrator wants to ensure that the protocol can dynamically negotiate the bundle formation with the connected device. Which protocol should be configured?

A.UniDirectional Link Detection (UDLD)
B.Link Aggregation Control Protocol (LACP)
C.Spanning Tree Protocol (STP)
D.Port Aggregation Protocol (PAgP)
AnswerB

LACP is an IEEE 802.3ad standard protocol that dynamically negotiates EtherChannel formation between devices from different vendors. It provides increased bandwidth and redundancy by bundling multiple physical links into a single logical link. This meets the requirement for dynamic negotiation and interoperability.

Why this answer

LACP is the IEEE standard for dynamic link aggregation, allowing switches from different vendors to negotiate an EtherChannel. It bundles multiple physical links into one logical link for increased bandwidth and redundancy. PAgP is Cisco-proprietary, while UDLD and STP serve entirely different purposes.

Exam trap

The trap here is confusing link aggregation protocols with loop prevention or link monitoring protocols, or assuming PAgP is universally supported.

1189
Multi-Selectmedium

Which two statements about IPsec IKEv2 are true? (Choose two.)

Select 2 answers
A.IKEv2 uses UDP port 500 for initial negotiation and can switch to UDP port 4500 for NAT traversal.
B.IKEv2 requires a separate authentication phase for each security association established.
C.IKEv2 supports EAP authentication for remote access VPNs.
D.IKEv2 uses only pre-shared keys for authentication and does not support digital certificates.
E.IKEv2 is backward compatible with IKEv1 and can interoperate with older peers.
AnswersA, C

IKEv2 begins negotiation over UDP 500, then detects NAT along the path and switches to UDP 4500, which encapsulates ESP-in-UDP to survive address translation. This satisfies the stem's NAT traversal requirement, since port 4500 allows the encrypted payload to pass through NAT devices that would otherwise drop native ESP packets.

Why this answer

Option A is correct because IKEv2 performs its initial IKE_SA_INIT exchange over UDP port 500, and when NAT is detected it switches to UDP port 4500 (NAT-T) to encapsulate ESP/IKE traffic and traverse NAT devices. Option C is correct because IKEv2 natively supports EAP methods (e.g., EAP-MSCHAPv2, EAP-TLS) as an authentication mechanism, which is commonly used for remote-access VPN clients. Option B is wrong because IKEv2 establishes the IKE SA once and then creates multiple child SAs (IPsec SAs) under that single IKE SA without requiring a separate authentication phase for each.

Option D is wrong because IKEv2 supports multiple authentication methods including pre-shared keys, digital certificates (RSA/ECDSA), and EAP. Option E is wrong because IKEv2 is not backward compatible with IKEv1; the two versions do not interoperate and require separate implementations or negotiation fallback mechanisms.

Exam trap

The trap here is assuming IKEv2 is backward compatible with IKEv1 or that it only supports PSK — candidates who confuse IKEv1 limitations with IKEv2 features pick the wrong options.

1190
MCQmedium

Consider the following BGP configuration on a Cisco IOS-XE router: router bgp 65001 neighbor 10.0.0.2 remote-as 65002 neighbor 10.0.0.2 route-map SET_COMMUNITY out ! route-map SET_COMMUNITY permit 10 set community 65001:100 What is the effect of this configuration?

A.The router will set the community to 65001:100 on all routes received from neighbor 10.0.0.2.
B.The router will set the community to 65001:100 on all routes advertised to neighbor 10.0.0.2.
C.The router will filter routes with community 65001:100 from being advertised.
D.The router will remove the community from routes advertised to the neighbor.
AnswerB

The outbound route-map applies the set community action to every prefix advertised to 10.0.0.2, so the neighbour receives routes tagged 65001:100. Because no send-community keyword is shown, the attribute is set locally but only transmitted if community propagation is enabled.

Why this answer

The route-map SET_COMMUNITY is applied with the 'out' keyword on the neighbor statement, meaning it is evaluated on routes being advertised to neighbor 10.0.0.2. The 'set community 65001:100' action therefore stamps the community value 65001:100 on all outbound routes sent to that neighbor.

Exam trap

350-401 often tests the direction of route-map application — candidates confuse 'in' (affects received routes) with 'out' (affects advertised routes) and pick the wrong effect.

How to eliminate wrong answers

Option A is wrong because an 'out' route-map affects outbound advertisements, not inbound received routes — to modify received routes you would use 'in'. Option C is wrong because the route-map uses 'set community', not a 'match community' with a deny action; nothing filters routes based on community. Option D is wrong because 'set community 65001:100' adds/sets the community value; it does not remove communities (that would require 'set community none' or 'set comm-list delete').

1191
Multi-Selectmedium

Which two statements about MPLS Layer 3 VPNs are true? (Choose two.)

Select 2 answers
A.PE routers use MP-BGP to exchange VPNv4 routes that include the route distinguisher and the VPN label.
B.P routers in the MPLS core must maintain a full routing table for each customer VRF.
C.CE routers must run MPLS and participate in the label distribution with the PE router.
D.Each VRF on a PE router maintains a separate routing table and forwarding table per customer.
E.The MPLS label stack in a Layer 3 VPN always contains exactly one label.
AnswersA, D

MP-BGP carries VPNv4 routes between PE routers, with each route tagged by a route distinguisher for uniqueness and a VPN label for forwarding. This exchange populates VRFs across the provider core, satisfying the stem's requirement for a true MPLS Layer 3 VPN statement.

Why this answer

Option A is correct because in an MPLS Layer 3 VPN, PE routers use MP-BGP (multiprotocol BGP, specifically the VPNv4 address family) to exchange customer routes, and each VPNv4 NLRI carries the 8-byte route distinguisher that makes the prefix unique plus the VPN label (an inner MPLS label) used by the egress PE to identify the customer VRF. Option D is correct because each VRF on a PE router is a separate routing and forwarding instance with its own RIB and FIB, which is what keeps overlapping customer address space isolated and allows per-VRF label assignment. Option B is wrong because P routers in the core only need to forward labeled packets based on the outer transport label; they do not hold per-customer VRF tables (that is the whole point of the MPLS L3VPN architecture).

Option C is wrong because CE routers are typically ordinary IP routers that do not run MPLS or participate in label distribution; they simply peer with the PE via a routing protocol or static routes. Option E is wrong because the MPLS label stack in an L3VPN normally contains at least two labels: an outer IGP/LDP transport label used to reach the egress PE and an inner VPN label used to identify the customer VRF, and it can contain more labels in some scenarios.

Exam trap

The trap here is confusing the roles of P and PE routers — candidates often assume every router in the MPLS domain must know customer routes, when in fact P routers only swap the outer transport label and remain VRF-unaware.

1192
MCQhard

A cloud provider uses Cisco ACI to automate provisioning of tenant networks. A new tenant requires a Layer 2 bridge domain that extends to an external Layer 2 network via a VPC. The engineer creates a bridge domain with the settings: Type: Regular, L2 Unknown Unicast: Flood, L3 Unknown Multicast Flood: Flood, and Multi-Destination Flooding: Flood. The VPC is configured as a virtual port channel. The tenant reports that broadcast traffic is not reaching the external network. What is the most likely cause?

A.The VPC configuration does not support L2 extension.
B.The bridge domain is configured as proxy mode for L2 unknown unicast.
C.The L2Out is not configured to flood BUM traffic.
D.The bridge domain type should be set to 'L2 Only'.
AnswerC

An L2Out connects the ACI fabric to an external Layer 2 network, but by default BUM (broadcast, unknown unicast, multicast) traffic is not automatically flooded through every L2Out. The 'flood on' setting under the L2Out must be explicitly enabled so that BUM frames received in the BD are also sent to the external network; without it, BUM traffic is dropped or handled only locally. Since this L2Out lacks that flood configuration, the L2 extension does not actually extend L2 flooding, which explains the connectivity problem.

Why this answer

The bridge domain is configured to flood BUM (Broadcast, Unknown Unicast, and Multicast) traffic internally, but the L2Out (Layer 2 external connection) must also be explicitly configured to flood BUM traffic to the external network. Without this configuration on the L2Out, the ACI fabric will not forward broadcast or multicast frames across the VPC to the external Layer 2 network, even though the bridge domain itself permits flooding.

Exam trap

Cisco often tests the distinction between bridge domain flood settings and L2Out flood settings, trapping candidates who assume that enabling flooding in the bridge domain automatically allows BUM traffic to reach external networks.

How to eliminate wrong answers

Option A is wrong because a VPC (Virtual Port Channel) in ACI is specifically designed to support Layer 2 extension by providing a loop-free, redundant connection to external switches, and it does not inherently block L2 traffic. Option B is wrong because the bridge domain is explicitly configured with 'L2 Unknown Unicast: Flood', not proxy mode; proxy mode would be 'L2 Unknown Unicast: Proxy', which is not the case here. Option D is wrong because the bridge domain type 'Regular' is appropriate for a Layer 2 bridge domain that extends to an external network; setting it to 'L2 Only' would disable Layer 3 forwarding but would not affect the flooding of BUM traffic to the external network via the L2Out.

1193
MCQmedium

A network architect is designing a new branch office that must support wired and wireless users with a single unified policy and automated onboarding for guests. The design requires centralized management, fabric-based segmentation, and the ability to enforce group-based policies without manual VLAN provisioning at the branch. Which Cisco architecture should be used?

A.Cisco ACI
B.Cisco SD-Access
C.Cisco SD-WAN
D.Cisco Catalyst Center with traditional VLANs
AnswerB

Cisco SD-Access is a campus fabric architecture that uses LISP for control plane, VXLAN for data plane, and Cisco TrustSec for group-based policy. It provides centralized management via Cisco DNA Center, automated fabric provisioning, and consistent policy for wired and wireless users, including guest onboarding, which matches the requirements exactly.

Why this answer

Cisco SD-Access is the campus fabric solution that integrates wired and wireless into a single policy domain using LISP, VXLAN, and TrustSec. It centralizes management through Cisco DNA Center and enables automated onboarding and group-based segmentation without manual VLAN configuration, making it the correct architecture for the branch requirements.

Exam trap

The trap here is assuming that Catalyst Center automation alone delivers fabric segmentation, when SD-Access specifically provides the fabric overlay and group-based policy.

1194
MCQmedium

A network administrator is implementing IP Source Guard (IPSG) on a Cisco Catalyst 3850 switch to prevent IP spoofing. The administrator enables DHCP snooping and IPSG on VLAN 10. A user connects a laptop with a statically assigned IP address 10.10.10.50/24 and gateway 10.10.10.1. The laptop cannot reach any network resources. What is the most likely reason?

A.DHCP snooping must be disabled for IP Source Guard to function with static addresses.
B.IP Source Guard requires that the IP address be learned via DHCP snooping or be statically configured in an IP source binding.
C.IP Source Guard only works with IPv6 addresses, so IPv4 static addresses are not supported.
D.The laptop must be configured with a DHCP address even if a static IP is desired, because IPSG blocks all non-DHCP traffic.
AnswerB

IP Source Guard uses the DHCP snooping database to validate source IP and MAC addresses. For static IP addresses, an IP source binding must be manually configured using the ip source binding command. Without this binding, the switch drops all traffic from the laptop because it cannot verify the source, causing complete loss of connectivity.

Why this answer

IP Source Guard relies on the DHCP snooping binding table to validate source IP and MAC addresses. When a device uses a static IP address, no dynamic binding exists, so the switch drops its traffic. To allow the static address, an IP source binding must be manually configured with the ip source binding command, which populates the binding table.

Exam trap

The trap here is assuming that IP Source Guard automatically permits statically assigned IP addresses, when it actually requires either a DHCP-learned binding or a manual static binding.

1195
MCQeasy

A network engineer is troubleshooting a wireless network where clients in a specific area report slow speeds and frequent disconnections. The engineer uses a spectrum analyzer and finds high utilization on channel 11 in the 2.4 GHz band. The engineer also notices that several neighboring access points are using channel 11. What is the most likely cause of the issue?

A.Co-channel interference from neighboring access points using the same channel.
B.Adjacent channel interference from access points using channels 10 and 12.
C.Non-WiFi interference from devices like microwaves or cordless phones.
D.The access point is overloaded with too many clients.
AnswerA

Multiple BSSIDs operating on the same 2.4 GHz channel create co-channel contention: when two APs' coverage areas overlap on channel 11, all associated stations must contend for the same RF medium via CSMA/CA. The resulting deferred transmissions, hidden-node collisions, and excessive backoff produce high channel utilization, frame retries, and ultimately client disconnects. This directly matches the spectrum analyzer showing sustained energy on channel 11 and the presence of neighboring APs configured to that same channel.

Why this answer

The spectrum analyzer shows high utilization on channel 11, and neighboring APs are also using channel 11. This is a classic case of co-channel interference (CCI), where multiple APs on the same channel cause contention, hidden node problems, and increased collisions, leading to degraded throughput and frequent disconnections for clients in that area.

Exam trap

Cisco often tests the distinction between co-channel interference and adjacent channel interference, where candidates mistakenly choose adjacent channel interference when the question explicitly states neighboring APs are on the same channel.

How to eliminate wrong answers

Option B is wrong because adjacent channel interference (ACI) occurs when overlapping channels (e.g., 10 and 12) cause partial overlap with channel 11, but the question states neighboring APs are using channel 11 itself, not adjacent channels. Option C is wrong because non-WiFi interference (e.g., microwaves, cordless phones) typically causes wideband noise or specific frequency spikes, but the spectrum analyzer specifically shows high utilization on channel 11, which is a WiFi channel, not a non-WiFi source. Option D is wrong because while an overloaded AP can cause slow speeds, the spectrum analyzer evidence points to channel utilization from other APs on the same channel, not client count; client overload would manifest as high airtime utilization but not necessarily from neighboring APs.

1196
Matchingmedium

Drag and drop each IP SLA tracking object on the left to its application on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Used with a floating static route

Used to adjust HSRP priority

Used with policy-based routing

Why these pairings

IP SLA tracking uses only two standard object types: 'track ip sla <id> state' and 'track ip sla <id> reachability'. 'track ip sla <id> delay' and 'track ip sla <id> threshold' are not valid tracking objects. P1, P2, and P3 correctly map to their applications: reachability for floating static routes, state for adjusting HSRP priority, and reachability for policy-based routing. P4 and P5 are incorrect because the specified tracking objects do not exist.

Exam trap

Some candidates might mistakenly think that delay or threshold are valid IP SLA tracking objects, but only state and reachability are standard.

1197
MCQhard

A network engineer is troubleshooting voice quality issues on a WAN link. The engineer notices that voice packets are being dropped during congestion. The QoS policy uses LLQ for voice traffic, but the priority queue is not providing the expected bandwidth. What is the most likely cause?

A.The priority queue is not configured with a bandwidth statement.
B.The priority queue has a built-in policer that drops traffic exceeding the configured bandwidth.
C.The class-map is not matching voice traffic correctly.
D.The router is using FIFO queuing instead of LLQ.
AnswerB

This is correct. In Low Latency Queuing (LLQ), the `priority` command with a bandwidth value creates both a strict priority queue and an implicit policer. This policer strictly limits the traffic served from the priority queue to the configured bandwidth; any voice traffic exceeding that rate is immediately dropped, rather than being queued. This mechanism prevents the priority queue from starving other queues, but it requires that the bandwidth be sized to handle voice bursts. Therefore, the drops are the expected behavior of the policer when the configured rate is too low for the incoming voice traffic.

Why this answer

The priority queue in LLQ uses a built-in policer that drops traffic exceeding the configured bandwidth. When congestion occurs, the policer enforces the bandwidth limit by dropping excess packets, which explains why voice packets are being dropped despite the priority queue being active. This is a fundamental behavior of LLQ to prevent the priority queue from starving other queues.

Exam trap

Cisco often tests the misconception that the priority queue provides unlimited bandwidth during congestion, when in fact LLQ uses a policer to enforce the configured bandwidth limit, causing drops for excess traffic.

How to eliminate wrong answers

Option A is wrong because the priority queue in LLQ does not require a bandwidth statement; it uses the 'priority' command which implicitly sets the bandwidth and enables the policer. Option C is wrong because if the class-map were not matching voice traffic correctly, the voice packets would not be placed into the priority queue at all, leading to different symptoms such as no prioritization rather than drops during congestion. Option D is wrong because if the router were using FIFO queuing, there would be no priority queue mechanism, and voice packets would experience general congestion drops without any bandwidth guarantee, not the specific behavior of the priority policer.

1198
MCQmedium

Consider the following configuration on a Cisco router: class-map match-any CRITICAL_DATA match ip dscp af21 af22 af23 policy-map QOS class CRITICAL_DATA bandwidth remaining percent 50 class class-default fair-queue interface GigabitEthernet0/0 service-policy output QOS Which statement about this configuration is true?

A.Traffic matching DSCP AF21, AF22, or AF23 is guaranteed 50% of the interface bandwidth, and all other traffic is subject to fair-queuing.
B.Only traffic with DSCP AF21 is matched; AF22 and AF23 are ignored because 'match-any' requires all conditions to be true.
C.The configuration is invalid because 'bandwidth remaining percent' cannot be used with 'fair-queue' in the same policy-map.
D.The policy-map will only be applied to incoming traffic on GigabitEthernet0/0.
AnswerA

Because the class map uses match-any, traffic marked with DSCP AF21, AF22, or AF23 is all placed into this class. The 'bandwidth remaining percent 50' command reserves half of the interface's available non-priority bandwidth for that class, and since no priority queue is configured, this effectively gives those AF flows a 50% share of the link when congestion occurs. Traffic that does not match any listed DSCP value falls into the implicit class-default, which is explicitly configured with fair-queue, so all other flows share the remaining 50% fairly.

Why this answer

The 'bandwidth remaining percent 50' command under class CRITICAL_DATA guarantees that traffic matching DSCP AF21, AF22, or AF23 will receive 50% of any remaining bandwidth after any explicit bandwidth reservations are satisfied. The 'class-default' uses fair-queuing, which distributes the remaining bandwidth equally among flows in that class. Since no explicit bandwidth is reserved elsewhere, the CRITICAL_DATA class effectively gets 50% of the interface bandwidth, and all other traffic is subject to fair-queuing.

Exam trap

Cisco often tests the distinction between 'match-any' and 'match-all' in class-maps, where candidates mistakenly think 'match-any' requires all conditions to be true, when in fact it matches if any one condition is true.

How to eliminate wrong answers

Option B is wrong because 'match-any' means the class matches if any one of the listed DSCP values (AF21, AF22, or AF23) is present, not all; the statement incorrectly claims that only AF21 is matched. Option C is wrong because 'bandwidth remaining percent' and 'fair-queue' can coexist in the same policy-map; 'bandwidth remaining percent' allocates a percentage of leftover bandwidth to a class, while 'fair-queue' in class-default provides per-flow queuing without conflict. Option D is wrong because the 'service-policy output QOS' command applies the policy to outgoing traffic on GigabitEthernet0/0, not incoming traffic.

1199
Multi-Selectmedium

Which two statements about the Cisco FlexConnect architecture are true? (Choose two.)

Select 2 answers
A.FlexConnect APs can locally switch client data traffic when the CAPWAP tunnel to the WLC is down.
B.FlexConnect APs must always tunnel all client traffic back to the WLC for central switching.
C.FlexConnect APs can be assigned to a FlexConnect group to share the same VLAN and ACL configuration.
D.FlexConnect APs require a direct Layer 2 connection to the WLC at all times.
E.FlexConnect APs cannot support native VLAN tagging on the uplink interface.
AnswersA, C

FlexConnect enables local switching, so the AP bridges client traffic directly onto the access VLAN rather than tunnelling it to the WLC. When the CAPWAP control tunnel drops, clients on that locally switched WLAN retain connectivity and continue forwarding data.

Why this answer

Option A is correct because FlexConnect's defining feature is local switching: the AP bridges client traffic directly onto the local wired VLAN at the branch, and this continues to function in standalone mode when the CAPWAP control tunnel to the WLC is lost. Option C is correct because FlexConnect groups let you apply a common set of VLAN-to-WLAN mappings, ACLs, and other settings to multiple APs, simplifying branch configuration and enabling features like VLAN-based central switching. Option B is wrong because FlexConnect explicitly supports local switching rather than requiring all client traffic to be tunneled to the WLC.

Option D is wrong because FlexConnect APs are designed for branch deployments where the WLC is remote over a Layer 3 network, not directly Layer 2 attached. Option E is wrong because FlexConnect APs do support native VLAN tagging on their uplink switch port.

Exam trap

350-401 often tests the misconception that FlexConnect APs must always tunnel traffic to the WLC; candidates forget that local switching and standalone mode are core FlexConnect capabilities.

1200
MCQmedium

A network engineer is configuring a site-to-site IPsec VPN between two Cisco routers. The engineer wants to ensure that the VPN tunnel uses the strongest possible encryption and authentication algorithms. The engineer configures the following: crypto isakmp policy 10, authentication pre-share, encryption aes-256, group 14, lifetime 86400. On the remote router, the engineer configures: crypto isakmp policy 10, authentication pre-share, encryption aes-256, group 14, lifetime 86400. The tunnel fails to establish. What is the most likely cause?

A.The lifetimes are set too high; they should be 3600 seconds.
B.The hash algorithm is not specified and defaults may differ between routers.
C.The Diffie-Hellman group 14 is not supported on these routers.
D.Pre-shared keys cannot be used with AES-256 encryption.
AnswerB

In IKEv1, when a transform set does not explicitly name the HMAC hash algorithm, the router substitutes a built-in default that varies across Cisco IOS versions and platforms—often SHA-1 in older releases but SHA-256 in newer builds. If the two routers default to different hashes, the hash algorithm field in the proposal differs, so the responder cannot find an acceptable transform and IKE SA negotiation fails, even though all explicitly configured parameters match. This is a classic invisible-difference problem because the config appears consistent, but the effective proposal is not.

Why this answer

The most likely cause is that the hash algorithm is not specified in the ISAKMP policy. By default, Cisco IOS uses SHA-1 (or MD5 on older versions) for the hash algorithm, but if one router defaults to SHA-1 and the other defaults to MD5, the IKE Phase 1 proposals will not match, causing the tunnel to fail. The configuration must explicitly include the `hash` command to ensure both peers agree on the same hash algorithm.

Exam trap

Cisco often tests the fact that the hash algorithm is a mandatory parameter in an ISAKMP policy, and candidates mistakenly assume that omitting it will default to a consistent value across routers, leading to a mismatch.

How to eliminate wrong answers

Option A is wrong because the lifetime of 86400 seconds (24 hours) is a standard default and is not the cause of the failure; mismatched lifetimes would cause renegotiation issues but not a complete failure to establish. Option C is wrong because Diffie-Hellman group 14 (2048-bit) is widely supported on modern Cisco routers running IOS 15.x and later, and is not the issue here. Option D is wrong because pre-shared keys are fully compatible with AES-256 encryption; the two are independent parameters in IKE Phase 1.

Page 15

Page 16 of 26

Page 17