Courseiva

ENCOR 350-401 (350-401) — Questions 1201–1275

1923 questions total · 26pages · All types, answers revealed

Page 16

Page 17 of 26

Page 18
1201
MCQmedium

A network engineer is configuring a Cisco wireless LAN controller (WLC) to support a new wireless network for guests. The requirement is that guest clients must be isolated from the corporate network and only have internet access. Which feature should be configured on the WLC?

A.Radio Resource Management (RRM)
B.FlexConnect local switching
C.Quality of Service (QoS) profile
D.Guest anchor controller
AnswerD

A guest anchor controller is a dedicated WLC that handles guest traffic separately from the corporate network. Guest clients are tunneled from the foreign controller to the anchor controller, which typically resides in a DMZ. This provides isolation and ensures that guest traffic only has internet access, not corporate network access. This is the standard design for guest wireless.

Why this answer

To isolate guest wireless traffic from the corporate network and provide only internet access, a guest anchor controller is used. The guest anchor controller is typically placed in a DMZ and handles all guest traffic, while the foreign controller tunnels guest client traffic to the anchor. This design ensures that guest clients cannot reach internal corporate resources.

Exam trap

The trap here is assuming that FlexConnect local switching provides guest isolation, when it actually just changes the data path for wireless traffic.

1202
MCQhard

A network engineer is configuring a Cisco Catalyst switch to authenticate users via 802.1X. The switch must place authenticated users into a specific VLAN based on the RADIUS server's response, and unauthenticated users should have no network access. Which configuration element is required on the switch to support dynamic VLAN assignment?

A.Configure the switch to use MAC authentication bypass (MAB) and assign a static VLAN to the interface.
B.Configure the interface as a trunk port and allow all VLANs.
C.Configure the switch to use RADIUS Change of Authorization (CoA) and enable dynamic VLAN assignment on the interface.
D.Configure the RADIUS server to return the IETF attributes Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID, and ensure the switch interface is in access mode with 802.1X enabled.
AnswerD

For dynamic VLAN assignment, the RADIUS server must return the standard IETF attributes: Tunnel-Type set to VLAN, Tunnel-Medium-Type set to IEEE-802, and Tunnel-Private-Group-ID containing the VLAN ID or name. The switch interface must be configured for 802.1X and typically in access mode so that the port can be moved to the assigned VLAN upon authentication. This is the correct combination to meet the requirement.

Why this answer

Dynamic VLAN assignment in 802.1X requires the RADIUS server to return specific tunnel attributes that the switch interprets to place the authenticated user into a designated VLAN. The switch port must be configured for 802.1X and usually in access mode. The combination of the correct RADIUS attributes and the proper switch configuration enables the switch to move the port to the VLAN specified by the server after successful authentication, providing the required access control.

Exam trap

The trap here is confusing RADIUS Change of Authorization with the initial dynamic VLAN assignment mechanism, which relies on tunnel attributes in the Access-Accept message, not on CoA.

1203
MCQmedium

A network engineer is deploying a new Cisco wireless network using a 9800 Series Wireless Controller. The engineer wants to ensure that the management interface is properly configured for out-of-band management. Which interface type should be configured with an IP address for management access?

A.Virtual interface
B.Redundancy management interface
C.Service port
D.Management interface
AnswerD

The management interface on a Cisco 9800 Series Wireless Controller is used for out-of-band management, including device access via SSH, HTTPS, and SNMP. It must be configured with an IP address, subnet mask, and default gateway. This interface is separate from data interfaces and is essential for administrative access to the controller.

Why this answer

The management interface on a Cisco 9800 Series Wireless Controller is specifically designed for out-of-band management. It requires an IP address, subnet mask, and default gateway to allow administrators to access the controller via SSH, HTTPS, or SNMP. Other interfaces like the redundancy management interface, service port, and virtual interface serve different purposes and are not used for primary management access.

Exam trap

The trap here is assuming that the service port or virtual interface can be used for management access, when they serve different roles.

1204
MCQmedium

Examine the following IP SLA configuration: ip sla 1 icmp-echo 10.1.1.1 frequency 10 ip sla schedule 1 life forever start-time now What is the effect of this configuration?

A.It sends ICMP echo requests to 10.1.1.1 every 10 seconds, starting immediately and running forever.
B.It sends ICMP echo requests to 10.1.1.1 every 10 seconds, but only for 10 minutes.
C.It sends ICMP echo requests to 10.1.1.1 every 60 seconds by default.
D.It sends ICMP echo requests to 10.1.1.1 every 10 seconds, but only if an IP SLA responder is configured on the target.
AnswerA

This is the intended behavior. The 'frequency 10' command configures the interval between ICMP echo probes to 10 seconds. 'start-time now' begins the operation immediately upon activation, while 'life forever' sets no termination timestamp, so the probe runs continuously until manually stopped or the device reloads, providing long-term reachability and RTT monitoring.

Why this answer

The configuration creates an IP SLA operation (ID 1) that uses ICMP echo to monitor reachability to 10.1.1.1. The 'frequency 10' command sets the interval between probes to 10 seconds, and 'ip sla schedule 1 life forever start-time now' starts the operation immediately and runs it indefinitely. This is the standard behavior for a basic ICMP echo IP SLA operation.

Exam trap

Cisco often tests the distinction between 'frequency' (interval between probes) and 'timeout' (wait time for a reply), and the fact that ICMP echo IP SLA does not require a responder, unlike UDP jitter or TCP connect operations.

How to eliminate wrong answers

Option B is wrong because 'life forever' explicitly means the operation runs indefinitely, not for a limited time like 10 minutes; there is no default or configured lifetime that would stop it after 10 minutes. Option C is wrong because the 'frequency 10' command overrides any default interval (which is 60 seconds for ICMP echo IP SLA) to 10 seconds, so it does not use the default. Option D is wrong because ICMP echo IP SLA does not require an IP SLA responder on the target; the target simply responds to standard ICMP echo requests, and the IP SLA operation measures round-trip time based on those replies.

1205
MCQhard

A network engineer is configuring an EtherChannel between two Cisco switches. The engineer wants to use LACP and ensure that the local switch is the one that determines which ports are active in the channel. Which configuration should be applied?

A.Configure 'lacp system-priority 100' on the local switch.
B.Configure 'lacp port-priority 100' on the physical ports of the local switch.
C.Configure 'channel-group 1 mode active' on the physical ports.
D.Configure 'lacp fast-switchover' on the port-channel interface.
AnswerA

The local switch should be configured with 'lacp system-priority 100' to make it the controlling switch in the LACP negotiation. LACP uses the system priority value, combined with the switch's MAC address, to form the system ID; the lower numeric system priority is treated as higher priority, so a value of 100 (rather than the default 32768) ensures the local switch wins the election. The controlling switch makes the final decision on which physical ports are bundled into the port-channel, so this is the correct way to configure control.

Why this answer

LACP uses the system priority to determine which switch controls port selection when negotiating an EtherChannel. The switch with the lower system priority (higher preference) becomes the 'controlling' switch that decides which ports are active in the channel. By configuring 'lacp system-priority 100' on the local switch, you lower its priority value, making it the preferred decision-maker for active port selection.

Exam trap

Cisco often tests the distinction between system priority (which determines the controlling switch) and port priority (which determines active vs. standby ports within the same switch), causing candidates to confuse the two.

How to eliminate wrong answers

Option B is wrong because 'lacp port-priority' influences which ports are placed into standby mode when hardware limitations are reached, not which switch controls active port determination. Option C is wrong because 'channel-group 1 mode active' enables LACP on the ports but does not influence which switch becomes the controlling switch; both sides could be active without a priority mechanism. Option D is wrong because 'lacp fast-switchover' is a feature that speeds up failover to standby ports, not a mechanism for controlling which switch decides active ports.

1206
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip eigrp interfaces EIGRP-IPv4 Interfaces for AS(100) Interface Peers Xmit Queue Mean Pacing Time Multicast Pending Un/Reliable SRTT Un/Reliable Flow Timer Routes Gi0/0 1 0/0 12 0/10 50 0 Gi0/1 1 0/0 15 0/10 55 0 Based on this output, what can be concluded?

A.Interface Gi0/1 has higher latency than Gi0/0.
B.Both interfaces have pending routes to send.
C.The router is using EIGRP named mode.
D.There is a queue backlog on Gi0/0.
AnswerA

The EIGRP interface output reports Mean SRTT (Smoothed Round-Trip Time) of 15 ms on Gi0/1 versus 12 ms on Gi0/0. A higher SRTT indicates a longer measured round-trip delay to the EIGRP neighbor, meaning Gi0/1 experiences higher latency. This is a direct metric for delay, not merely a configured value, so the conclusion is correct.

Why this answer

The 'Mean SRTT' (Smooth Round-Trip Time) column shows the average time in milliseconds for EIGRP packets to reach a neighbor and receive an acknowledgment. Gi0/1 has an SRTT of 15 ms, while Gi0/0 has an SRTT of 12 ms, indicating higher latency on Gi0/1. This directly correlates to the path's delay, which EIGRP uses in its composite metric calculation.

Exam trap

Cisco often tests the ability to interpret the 'show ip eigrp interfaces' output, specifically the 'Mean SRTT' column, and the trap here is that candidates confuse SRTT with interface bandwidth or fail to recognize that a higher SRTT means higher latency, not necessarily a problem with queue or pending routes.

How to eliminate wrong answers

Option B is wrong because the 'Pending Routes' column shows 0 for both interfaces, meaning no routes are waiting to be sent. Option C is wrong because the command output shows 'EIGRP-IPv4 Interfaces for AS(100)', which is the classic mode format; named mode would display 'EIGRP-IPv4 (Address Family)' or similar. Option D is wrong because the 'Xmit Queue Un/Reliable' column shows 0/0 for Gi0/0, indicating no queue backlog.

1207
Multi-Selectmedium

A network architect is evaluating Cisco SD-WAN to connect branch offices to data centers and public cloud workloads. The architect wants to understand which capabilities are provided by the Cisco SD-WAN solution. (Choose two.)

Select 2 answers
A.Replacement of all branch routing with static routes only
B.Elimination of all encryption on the overlay tunnels
C.Centralized policy management through vManage with templates pushed to edge devices
D.Mandatory use of MPLS as the only WAN transport
E.Application-aware routing that selects the best path based on policy and link quality
AnswersC, E

Cisco SD-WAN centralizes configuration and policy in vManage, which pushes feature templates and centralized policies to vEdge and cEdge devices. This enables consistent, scalable provisioning of thousands of branches without manual CLI configuration. It directly supports the architect's goal of managing branch-to-data-center and cloud connectivity in a unified, policy-driven manner across the overlay.

Why this answer

Cisco SD-WAN delivers application-aware routing that continuously measures path quality and steers traffic per policy, and it centralizes configuration and policy in vManage for scalable provisioning. These two capabilities align with the architect's goal of optimizing and managing branch-to-data-center and cloud connectivity across multiple transports.

Exam trap

The trap here is assuming SD-WAN forces a single transport or static-only routing, when it is actually transport-agnostic and supports dynamic routing with application-aware path selection.

1208
MCQeasy

A network administrator is configuring a Cisco Catalyst 9000 switch to support a new wireless deployment. The wireless LAN controller is integrated into the switch, and the administrator needs to ensure that the switch can manage access points and provide centralized control. Which feature should be enabled on the switch?

A.Cisco Mobility Express
B.Cisco Embedded Wireless Controller
C.Cisco DNA Center
D.Cisco SD-Access
AnswerB

The Cisco Embedded Wireless Controller is a feature on Catalyst 9000 switches that provides integrated wireless controller functionality. It allows the switch to manage access points directly without needing an external WLC. This meets the requirement for centralized control and AP management. Enabling this feature allows the switch to act as a wireless controller, simplifying the deployment and reducing hardware footprint.

Why this answer

The Cisco Embedded Wireless Controller is a feature available on Catalyst 9000 switches that integrates wireless controller capabilities directly into the switch. This allows the switch to manage access points and provide centralized control without an external WLC. The other options are either separate products or features not integrated into the switch.

Therefore, enabling the Embedded Wireless Controller is the correct choice.

Exam trap

The trap here is confusing Cisco DNA Center or SD-Access with the embedded wireless controller feature on Catalyst 9000 switches.

1209
Multi-Selectmedium

A network engineer is analyzing the output of the show processes cpu sorted command on a Cisco Catalyst 9300 switch and notices that the CPU utilization is consistently high. Which two methods can help identify the cause of high CPU utilization? (Choose two.)

Select 2 answers
A.Use the show interfaces counters errors command to check for interface errors.
B.Use the show processes cpu history command to view CPU utilization over time.
C.Use the show tech-support command to collect all diagnostic information.
D.Use the show processes cpu sorted command to identify the top CPU-consuming processes.
E.Use the show platform resources command to view hardware resource utilization.
AnswersB, D

The show processes cpu history command displays a graphical representation of CPU utilization over the past 60 seconds, 60 minutes, and 72 hours. This helps correlate high CPU with specific events or times, such as a spike during a network storm or a scheduled task. It provides historical context that can identify patterns and narrow down the cause of sustained high CPU.

Why this answer

The show processes cpu history command provides historical CPU utilization graphs, helping correlate spikes with events. The show processes cpu sorted command lists processes by CPU usage, directly identifying the top consumers. Together, they allow an engineer to pinpoint which process is causing high CPU and when it occurs.

The other commands provide additional context but are not the primary methods for identifying the cause of high CPU.

Exam trap

The trap here is thinking show tech-support directly identifies the cause; it collects data but does not analyze it for you.

1210
Multi-Selecthard

A network engineer is deploying a Cisco SD-WAN solution using vManage, vSmart, and vBond controllers. The engineer must ensure that the control plane and data plane are secure and that routers can authenticate to the controllers. Which two statements are true regarding the Cisco SD-WAN controller components? (Choose two.)

Select 2 answers
A.vSmart stores the full configuration and acts as the CA for certificate management.
B.vManage is responsible for forwarding data plane traffic between branches.
C.vBond establishes IPsec tunnels for data plane traffic between vEdge routers.
D.vSmart distributes control plane policies and routes to vEdge routers using OMP.
E.vBond orchestrates the initial authentication and allows vEdge routers to locate vSmart and vManage controllers.
AnswersD, E

vSmart is the controller that implements control plane policies and distributes routing information via the Overlay Management Protocol (OMP). It maintains the centralized control plane and pushes policies to vEdge devices. This is essential for SD-WAN fabric operation.

Why this answer

In Cisco SD-WAN, vBond orchestrates initial authentication and helps routers find other controllers. vSmart distributes control plane policies and routes using OMP. These two components are essential for establishing the secure overlay and enabling centralized control. The management plane (vManage) and data plane (vEdge routers) have different roles.

Exam trap

The trap here is confusing the management plane, control plane, and data plane responsibilities among vManage, vSmart, and vBond.

1211
MCQmedium

A network administrator is deploying Cisco Application Centric Infrastructure (ACI) and needs to allow two endpoint groups (EPGs) in different bridge domains to communicate while applying a contract that permits only TCP port 443. Which ACI construct provides the policy enforcement point where the contract is applied?

A.The VXLAN tunnel interface on the spine
B.The bridge domain subnet SVI on the border leaf
C.The policy enforcement point on the leaf where the EPGs reside
D.The APIC controller cluster policy compiler
AnswerC

In ACI, the leaf switch acts as the policy enforcement point, translating contracts into hardware ACL and forwarding rules applied to the EPG interfaces. When a contract permitting TCP 443 is attached between EPGs, the leaf enforces that filter for traffic between them, which is exactly the construct required.

Why this answer

ACI applies contracts at the leaf switch, which acts as the policy enforcement point for the attached EPGs. The APIC distributes the compiled policy, but the leaf hardware renders and enforces the permit for TCP port 443 between the two EPGs in their respective bridge domains.

Exam trap

The trap here is assuming the central APIC controller enforces contracts in the data path rather than only distributing policy.

1212
Multi-Selecthard

Which three statements about IPv4 ACLs on Cisco IOS are true? (Choose three.)

Select 3 answers
A.Standard ACLs can filter traffic based on source IP address only.
B.Extended ACLs can filter based on source and destination IP addresses, protocol, and port numbers.
C.An implicit deny any statement is automatically added at the end of every ACL.
D.ACL entries are processed from bottom to top, with the last match determining the action.
E.An ACL applied to an inbound interface filters traffic leaving that interface.
AnswersA, B, C

Standard ACLs match only on the source IPv4 address, so they cannot distinguish destination, protocol or port. This limited matching capability is the defining constraint that separates standard ACLs from extended ACLs on Cisco IOS.

Why this answer

Option A is correct because standard IPv4 ACLs (numbered 1–99 and 1300–1999, or named with the standard keyword) match only on the source IP address, so they can permit or deny traffic solely by source. Option B is correct because extended IPv4 ACLs (numbered 100–199 and 2000–2699, or named with the extended keyword) can match source and destination IP addresses, the IP protocol (ip, tcp, udp, icmp, etc.), and Layer 4 port numbers using operators such as eq, gt, lt, and range. Option C is correct because every Cisco IOS ACL ends with an implicit deny any (deny ip any any for extended, deny any for standard), which drops any packet that does not match an earlier permit statement.

Option D is incorrect because ACL entries are processed top-down, and the first match determines the action, not the last match. Option E is incorrect because an inbound ACL filters traffic entering the interface, while an outbound ACL filters traffic leaving the interface.

Exam trap

350-401 often tests ACL processing order and direction — candidates assume 'last match wins' or confuse inbound/outbound filtering, but IOS ACLs are first-match, top-down, and inbound filters traffic entering the interface.

1213
MCQeasy

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) to secure wireless client traffic. The requirement is to encrypt all wireless traffic between the client and the access point using a pre-shared key, without requiring a separate authentication server. Which security policy should the administrator configure on the WLC?

A.WPA2 Enterprise with 802.1X
B.WPA2 Personal with AES
C.Open authentication with Web Policy
D.WPA3 Enterprise with 192-bit mode
AnswerB

WPA2 Personal uses a pre-shared key (PSK) for authentication and AES for encryption. It does not require an external authentication server, meeting the requirement. This is suitable for small to medium networks where a shared key is acceptable and simplifies deployment.

Why this answer

WPA2 Personal with AES uses a pre-shared key for authentication and AES for encryption, providing strong security without the need for an external RADIUS server. This aligns with the requirement to encrypt traffic using a PSK and no separate authentication server. Enterprise modes require a server, and open authentication lacks encryption.

Exam trap

The trap here is assuming that Enterprise modes can be used without a server, or that open authentication provides encryption.

1214
Matchingmedium

Drag and drop each VM network mode on the left to its matching behavior description on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

VM appears as a separate device on the physical network

VM uses host IP for outbound connectivity

VM communicates only with host and other VMs on same virtual switch

VM communicates only with other VMs on same virtual switch, not with host

VM connects to a user-defined virtual switch

Why these pairings

Bridged mode connects the VM to the physical network as if it were a separate host. NAT mode allows the VM to share the host’s IP address for outbound access. Host-only mode creates an isolated network between the host and VMs.

Internal mode isolates VMs from the host. Custom mode allows the user to select a specific virtual switch.

1215
Multi-Selectmedium

A network engineer is designing a VXLAN EVPN fabric using Cisco Nexus 9000 switches. The engineer must choose a multicast mode for BUM (Broadcast, Unknown unicast, Multicast) traffic replication. Which two statements are true regarding the use of multicast in a VXLAN EVPN fabric? (Choose two.)

Select 2 answers
A.Ingress replication is required when using multicast mode.
B.Multicast mode eliminates the need for BGP EVPN for control plane learning.
C.Each VNI is typically mapped to a unique multicast group address.
D.Multicast requires the underlay network to support PIM SM and an RP.
E.Multicast mode requires a separate multicast group for each VTEP.
AnswersC, D

In a multicast-based VXLAN fabric, each VNI is mapped to a multicast group address. VTEPs that have the VNI configured join that group via IGMP. When a VTEP needs to send BUM traffic for that VNI, it sends the VXLAN-encapsulated packet to the multicast group, and all VTEPs in the group receive it. This mapping is configured on each VTEP.

Why this answer

In a VXLAN EVPN fabric using multicast for BUM traffic, the underlay must support multicast routing, typically PIM SM with an RP. Each VNI is mapped to a unique multicast group address, and VTEPs join the group for their VNIs. This allows BUM traffic to be replicated to all VTEPs in the VNI.

BGP EVPN is still used for control plane learning.

Exam trap

The trap here is assuming multicast replaces BGP EVPN or that ingress replication is used alongside multicast, when in fact they are alternative methods for BUM traffic handling.

1216
Matchingmedium

Drag and drop each wireless AP mode on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Serves clients with CAPWAP control and data to WLC

Switches client data locally at the AP

Listens for rogue access points on all channels

Captures packets and forwards to a remote analyzer

Detects rogue devices by monitoring wired traffic

Why these pairings

Local mode serves clients with CAPWAP control and data; FlexConnect mode switches client data locally; Monitor mode listens for rogue APs; Sniffer mode captures packets for analysis; Rogue Detector mode detects rogue devices via wired network.

1217
MCQmedium

A network engineer runs the following command on Switch SW1: SW1# show interfaces gi0/1 trunk Port Mode Encapsulation Status Native vlan Gi0/1 desirable n-802.1q trunking 1 Port Vlans allowed on trunk Gi0/1 1-1005 Port Vlans allowed and active in management domain Gi0/1 1,10,20 Port Vlans in spanning tree forwarding state and not pruned Gi0/1 1,10,20 Based on this output, what can be concluded?

A.The interface is configured as an access port.
B.The trunk is using ISL encapsulation.
C.VLANs 2-9 are allowed but not active.
D.The native VLAN is 10.
AnswerC

This is correct because the trunk's allowed VLAN list permits VLANs 1-1005, but the VLAN database only has VLANs 1, 10, and 20 in an active/up state (for instance, 'Status: active'). VLANs 2-9 are therefore permitted on the trunk but are not active, so they will not carry traffic until they are created and brought up, or until ports are assigned to them. Being allowed on a trunk does not make a VLAN operationally active; the VLAN must exist and have an active administrative state.

Why this answer

The output shows that VLANs 1-1005 are allowed on the trunk, but only VLANs 1, 10, and 20 are active in the management domain. This means VLANs 2-9 and 11-19, 21-1005 are allowed but not active (i.e., not created or not present on the switch). Option C correctly identifies that VLANs 2-9 are among those allowed but not active.

Exam trap

The trap here is that candidates often confuse 'allowed on trunk' with 'active in management domain', leading them to assume all allowed VLANs are actually forwarding traffic, when in fact only those listed in the second line are active.

How to eliminate wrong answers

Option A is wrong because the interface is in 'desirable' mode and shows 'trunking' status, which indicates it is a trunk port, not an access port. Option B is wrong because the encapsulation is 'n-802.1q' (likely a typo for '802.1q'), which is IEEE 802.1Q, not ISL (Cisco's proprietary encapsulation). Option D is wrong because the output explicitly shows 'Native vlan 1', not 10.

1218
MCQhard

A network engineer is troubleshooting a performance issue with a virtual firewall (vFW) running on a Cisco NFVIS host. The vFW is experiencing high packet loss during peak traffic. The engineer checks the NFVIS monitoring dashboard and sees that the vFW's CPU usage is low, but the host's memory usage is high. What is the most likely cause of the packet loss?

A.The vFW is CPU-bound, but the monitoring is inaccurate.
B.The host's CPU is oversubscribed, causing vCPU starvation.
C.The host is under memory pressure, causing the hypervisor to swap or balloon memory from the vFW.
D.The vFW's packet buffer is exhausted, but the monitoring does not show it.
AnswerC

This is correct because high host memory usage triggers the hypervisor's memory-reclaim mechanisms, such as ballooning or swapping out guest pages, to free memory for other workloads. When the vFW's memory is inflated or its pages are swapped, the guest OS may have to fault pages back in, adding significant latency to its data-plane processing. This increased latency can cause the vFW to drop packets because it cannot process traffic fast enough, even though the vFW's own memory usage appears normal from inside the guest.

Why this answer

When the NFVIS host experiences high memory pressure, the hypervisor may reclaim memory from virtual machines (VMs) using mechanisms such as ballooning or swapping. This reduces the memory available to the vFW, causing it to drop packets because its packet buffers or operating system memory are forcibly reclaimed. The vFW's CPU remains low because the bottleneck is memory, not processing power.

Exam trap

Cisco often tests the distinction between CPU and memory bottlenecks in virtualized environments, where candidates mistakenly assume high packet loss must be CPU-related, ignoring that memory pressure from the hypervisor can cause the vFW to lose packets even when its CPU is idle.

How to eliminate wrong answers

Option A is wrong because the monitoring dashboard shows low CPU usage, and NFVIS monitoring is generally accurate for CPU metrics; the issue is not CPU-bound. Option B is wrong because the problem statement indicates low vFW CPU usage and high host memory usage, not high host CPU usage or vCPU starvation; CPU oversubscription would manifest as high CPU ready times, not memory pressure. Option D is wrong because packet buffer exhaustion would typically be caused by insufficient memory allocation to the vFW or memory pressure from the host, but the monitoring would show buffer drops or memory usage; the question states the host's memory is high, pointing to host-level memory pressure as the root cause.

1219
MCQhard

A Cisco Catalyst 9500 switch is configured for 802.1X with MAC Authentication Bypass (MAB) fallback on a port connected to an IP phone that has a PC daisy-chained behind it. The phone authenticates successfully using 802.1X, but the PC behind the phone fails authentication and is placed in the guest VLAN. The requirement is that the PC be authenticated individually and placed in the data VLAN, while the phone remains in the voice VLAN. Which feature should be configured on the switch port to meet this requirement?

A.Web Authentication (WebAuth) fallback
B.Multi-authentication
C.Multi-host authentication
D.Multi-domain authentication
AnswerB

Multi-authentication (also called multi-auth) allows multiple devices on a single port to be authenticated independently, each receiving its own authorization result. With a phone and a daisy-chained PC, the phone can authenticate via 802.1X into the voice VLAN and the PC can authenticate via MAB or 802.1X into the data VLAN. This is the Cisco feature designed for this exact topology.

Why this answer

The daisy-chained PC must be authenticated separately from the phone so it can be placed in the data VLAN while the phone uses the voice VLAN. Cisco multi-authentication (multi-auth) supports multiple independent authentications on one port, including a mix of 802.1X and MAB. Multi-domain supports only one device per domain and multi-host applies the first result to all hosts, so neither meets the requirement.

Exam trap

The trap here is confusing multi-domain, multi-host, and multi-auth; multi-domain supports only one device per domain, while multi-auth is required for multiple independently authenticated devices on the same port.

1220
MCQmedium

What is the maximum number of WLANs that can be configured on a single AP in a Cisco 9800 WLC deployment?

A.8
B.16
C.32
D.64
AnswerB

On Cisco Catalyst 9100 series APs and similar modern platforms, each radio (2.4GHz, 5GHz, and 6GHz on Wi-Fi 6E) supports up to 16 WLANs simultaneously. This is a per-radio limit, so an AP with two radios can support 32 distinct SSIDs when split across bands, though each WLAN typically maps to a single SSID. The IOS XE wireless controller allows configuration of 16 WLANs per radio interface.

Why this answer

In a Cisco 9800 WLC deployment, each AP supports up to 16 WLANs (SSIDs). This is a hard limit enforced by the controller, regardless of the AP model. The 9800 WLC maps WLANs to APs via policy profiles, and the AP can serve a maximum of 16 unique SSIDs simultaneously.

Exam trap

Cisco often tests the distinction between global WLAN capacity (up to 4096 on the 9800) and per-AP WLAN capacity (16), causing candidates to confuse the two and select 64 (the global maximum) or 32 (a common but incorrect guess).

How to eliminate wrong answers

Option A is wrong because 8 WLANs was the limit on older Cisco controllers (e.g., 5508 or 2504) running AireOS, not on the 9800 WLC with IOS-XE. Option C is wrong because 32 WLANs exceeds the AP's hardware and software capability; the 9800 WLC supports up to 4096 WLANs globally, but each AP is limited to 16. Option D is wrong because 64 WLANs is the maximum number of WLANs that can be configured globally on the 9800 WLC, not per AP.

1221
Matchingmedium

Drag and drop each EIGRP packet type on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Discovers and maintains neighbor relationships

Sends routing information to neighbors

Requests information about a lost route

Responds to a query with routing information

Acknowledges receipt of a reliable packet

Why these pairings

Hello packets discover and maintain neighbors; Update packets carry routing information; Query packets ask for alternate paths; Reply packets respond to queries; ACK packets acknowledge reliable delivery.

1222
MCQhard

A network engineer executes the following command on Router R5: R5# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 10.0.0.6 1 FULL/DR 00:00:35 192.168.1.6 GigabitEthernet0/0 10.0.0.7 1 FULL/BDR 00:00:32 192.168.1.7 GigabitEthernet0/0 10.0.0.8 1 2WAY/DROTHER 00:00:38 192.168.1.8 GigabitEthernet0/0 Based on this output, what can be concluded about the OSPF network?

A.The OSPF network type is point-to-point.
B.Router R5 is the DR on this segment.
C.The OSPF network type is broadcast.
D.All neighbors are in the FULL state.
AnswerC

The neighbor states FULL/DR, FULL/BDR, and 2WAY/DROTHER are only possible on OSPF network types that perform DR/BDR election, such as broadcast or NBMA. On a broadcast multiaccess network like Ethernet, OSPF elects a DR and BDR to reduce adjacencies, and DROTHER routers remain in 2WAY with each other. The router's output clearly shows a neighbor as the DR and another in the DROTHER state, confirming the network type is broadcast.

Why this answer

The output shows neighbors in states FULL/DR, FULL/BDR, and 2WAY/DROTHER, which are characteristic of a broadcast multiaccess network where a Designated Router (DR) and Backup Designated Router (BDR) are elected. The presence of a 2WAY/DROTHER state indicates that non-DR/BDR routers maintain a two-way adjacency without exchanging full LSDBs, which only occurs on broadcast or non-broadcast multiaccess (NBMA) networks. Since the network type is not point-to-point (which would show only FULL states) and the DR/BDR roles are present, the OSPF network type must be broadcast.

Exam trap

Cisco often tests the misconception that all OSPF neighbors must be in FULL state for proper operation, but on broadcast networks, DROTHER routers remain in 2WAY state with each other to reduce LSA flooding overhead.

How to eliminate wrong answers

Option A is wrong because a point-to-point network would show only FULL state neighbors with no DR/BDR election, and the output clearly shows DR/BDR roles. Option B is wrong because Router R5's own state is not shown in the output; the 'State' column reflects the neighbor's state relative to R5, and since R5 sees a DR and BDR but is not listed as DR itself, R5 is likely a DROTHER. Option D is wrong because the neighbor 10.0.0.8 is in the 2WAY/DROTHER state, not FULL, so not all neighbors are in FULL state.

1223
Multi-Selecthard

Which three statements about MPLS traffic engineering (MPLS-TE) are true? (Choose three.)

Select 3 answers
A.MPLS-TE uses RSVP-TE to signal LSPs and reserve resources.
B.OSPF or IS-IS can be extended to carry TE link attributes.
C.MPLS-TE allows traffic to follow paths that differ from the IGP shortest path.
D.MPLS-TE relies on LDP to distribute labels for TE tunnels.
E.MPLS-TE uses BGP to compute the best path for TE LSPs.
AnswersA, B, C

RSVP-TE is the signalling protocol that establishes label-switched paths and reserves bandwidth along an explicit route, satisfying the stem's requirement for a true MPLS-TE statement. It carries the explicit route object and reservation parameters, distinguishing MPLS-TE from plain label distribution.

Why this answer

Option A is correct because MPLS-TE uses RSVP-TE as its signaling protocol to establish label-switched paths (LSPs) and reserve bandwidth resources along the explicit path. Option B is correct because OSPF and IS-IS are extended with TE extensions (OSPF-TE and IS-IS-TE) to flood TE link attributes such as available bandwidth, administrative groups, and link metrics in the TE database. Option C is correct because MPLS-TE's core purpose is to route traffic over explicitly defined paths that can deviate from the IGP shortest path, enabling constraint-based routing and load balancing.

Option D is incorrect because LDP distributes labels for hop-by-hop IGP-based LSPs and does not perform the resource reservation or explicit path signaling required for TE tunnels. Option E is incorrect because BGP is a path-vector routing protocol used for inter-domain routing and does not compute paths for TE LSPs; path computation is done by the headend router using the TE database (CSPF).

Exam trap

The trap here is conflating LDP (used for IGP-based label distribution) with RSVP-TE (used for TE tunnel signaling) — candidates who remember 'MPLS uses LDP' often wrongly pick option D.

1224
MCQhard

A network engineer is implementing a Cisco TrustSec solution. The engineer needs to classify traffic based on user identity and apply security policies accordingly. Which component is responsible for tagging packets with a Security Group Tag (SGT) at the ingress point?

A.Policy Enforcement Point (PEP)
B.Policy Decision Point (PDP)
C.Network Device Admission Control (NDAC)
D.Ingress Policy Enforcement Point (Ingress PEP)
AnswerD

The Ingress Policy Enforcement Point (Ingress PEP) is the device where traffic enters the TrustSec domain. It is responsible for classifying the traffic and tagging the packet with the appropriate Security Group Tag (SGT). This tagging allows subsequent devices to enforce policies based on the SGT without reclassifying the traffic. The Ingress PEP is typically a switch or router that supports TrustSec.

Why this answer

In Cisco TrustSec, the Ingress Policy Enforcement Point (Ingress PEP) is the device that first receives traffic into the TrustSec domain. It classifies the traffic, determines the source Security Group Tag (SGT), and inserts the SGT into the packet. This tag is then used by other enforcement points to apply security policies.

The PDP (ISE) provides the policy, but the Ingress PEP performs the tagging.

Exam trap

The trap here is confusing the roles of the PDP and PEP, or assuming that the PDP tags packets, when in fact the tagging is done at the ingress point.

1225
Drag & Dropmedium

Drag and drop the steps of JSON vs XML encoding selection for RESTCONF into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The process begins by examining the Accept header in the client request to determine the desired response format (JSON or XML). After the server processes the request and sends a response, the client verifies the Content-Type header to confirm the format used. The client then selects JSON if lightweight parsing is preferred, and selects XML if schema validation is needed (both selections occur in sequence as part of the decision-making process).

Finally, the client encodes the payload in the selected format for subsequent requests or for parsing the response.

1226
Multi-Selecteasy

Which TWO statements correctly describe characteristics of virtual device contexts (VDCs) in Cisco Nexus switches?

Select 2 answers
A.VDCs allow overlapping VLAN IDs across different VDCs only if using different VNIs.
B.VDCs provide Layer 3 routing isolation by default across all VDCs.
C.Each VDC can have its own admin account and separate management interface.
D.VDCs are supported on all Cisco IOS-XE switches.
E.VDCs enable partitioning of a single physical switch into multiple logical switches.
AnswersC, E

Correct: VDCs provide administrative and management isolation.

Why this answer

Each VDC in a Cisco Nexus switch can be configured with its own administrative credentials and a dedicated management interface (e.g., mgmt0). This allows separate administrative domains and management access per VDC, which is a key feature for multi-tenant environments.

Exam trap

Cisco often tests the misconception that VDCs automatically provide Layer 3 routing isolation, but in reality, routing isolation requires explicit VRF configuration per VDC.

1227
Multi-Selecthard

A network engineer is using Cisco DNA Center Assurance to troubleshoot a wireless client that frequently disconnects. The engineer wants to identify the root cause by examining relevant assurance data. Which two types of information are available in the Client 360 view to help diagnose the issue? (Choose two.)

Select 2 answers
A.Wireless controller CPU utilization
B.RF statistics for the client
C.Application response time
D.Client onboarding history
E.Switch interface error counters
AnswersB, D

RF statistics for the client, such as RSSI, SNR, and channel utilization, are available in Client 360. These metrics help determine if the disconnections are due to poor signal quality, interference, or coverage gaps. By analyzing RF trends over time, the engineer can correlate disconnects with RF conditions.

Why this answer

Client 360 in Cisco DNA Center Assurance provides a comprehensive view of a specific client's connectivity, including onboarding history and RF statistics. Onboarding history reveals the steps and failures during connection attempts, while RF statistics show signal quality and interference. Together, they enable the engineer to diagnose why the client disconnects, such as authentication failures or poor coverage.

Exam trap

The trap here is assuming that Client 360 includes device-level metrics like controller CPU or switch interface counters, when it actually provides client-centric data such as onboarding events and RF statistics.

1228
MCQeasy

A network engineer is deploying QoS on a Cisco Catalyst 4500 switch to support four queues per port. The engineer wants to assign voice traffic to queue 1 (priority), video to queue 2, critical data to queue 3, and best-effort to queue 4. The switch is configured with the default CoS-to-queue mapping. However, video traffic is being placed in queue 1 along with voice. What should the engineer do to separate them?

A.Modify the CoS-to-queue mapping using the 'mls qos srr-queue output cos-map' command
B.Change the video traffic marking to DSCP AF41 and rely on DSCP-to-queue mapping
C.Apply a service policy that uses a priority queue for voice only
D.Increase the number of queues to eight
AnswerA

This command is correct because on Catalyst switches the default queue assignment for output traffic is based on the CoS value in the 802.1Q header. By modifying the CoS-to-queue map, you can explicitly assign voice (typically CoS 5) to a strict-priority queue and video (e.g., CoS 4) to a separate standard queue, thereby preventing inter-class contention. The command takes precedence over any default mapping and gives the engineer deterministic control over which hardware queue each marked packet uses.

Why this answer

The default CoS-to-queue mapping on Cisco Catalyst 4500 switches maps CoS 5 (voice) to queue 1 (priority queue) and CoS 4 (video) also to queue 1. To separate video into queue 2, the engineer must modify the CoS-to-queue mapping using the 'mls qos srr-queue output cos-map' command, which reassigns CoS values to specific output queues. This directly overrides the default behavior and places video traffic in the correct queue.

Exam trap

Cisco often tests the misconception that DSCP marking or service policies alone can override the default CoS-to-queue mapping, when in fact the mapping must be explicitly reconfigured on platforms like the Catalyst 4500.

How to eliminate wrong answers

Option B is wrong because relying on DSCP-to-queue mapping does not change the CoS-to-queue mapping; the switch uses CoS marking (derived from DSCP) by default, and video marked as AF41 (DSCP 34) maps to CoS 4, which still falls into queue 1. Option C is wrong because applying a service policy with a priority queue for voice only does not alter the underlying CoS-to-queue mapping; video traffic marked with CoS 4 would still be placed in queue 1 unless the mapping is changed. Option D is wrong because increasing the number of queues to eight does not change the default CoS-to-queue mapping; video traffic would still map to queue 1 unless the mapping is explicitly reconfigured.

1229
MCQmedium

A network architect is designing a Fabric-enabled campus with Cisco SD-Access and must choose the optimal underlay routing protocol. The fabric will use VXLAN data-plane encapsulation, and the architect wants minimal configuration on the intermediate underlay devices while supporting fast convergence and equal-cost multipath. Which underlay routing approach should be recommended?

A.Enable RIPng on all underlay devices to provide simple hop-count-based routing.
B.Use Cisco SD-Access fabric with an IS-IS underlay automatically enabled by the fabric provisioning workflow.
C.Deploy eBGP between all underlay switches using unique autonomous system numbers per device.
D.Configure OSPFv2 in a single area on all underlay devices, including the fabric edge and border nodes.
AnswerB

In Cisco SD-Access, the recommended underlay for a Fabric-enabled campus is IS-IS, which is automatically configured by the fabric provisioning workflow through Cisco DNA Center. IS-IS supports fast convergence and ECMP, and the automated deployment minimizes manual configuration on intermediate underlay switches, matching the stated requirement for minimal configuration.

Why this answer

Cisco SD-Access uses an IS-IS underlay that is automatically provisioned by Cisco DNA Center, reducing manual configuration on intermediate devices while supporting fast convergence and ECMP. OSPFv2 and eBGP require explicit per-device configuration and are not the automated fabric underlay. RIPng is unsuitable due to hop limits and slow convergence.

Exam trap

The trap here is assuming any dynamic routing protocol works equally well as an SD-Access underlay, when the automated fabric workflow specifically deploys IS-IS for minimal configuration.

1230
Matchingmedium

Drag and drop each VPN type on the left to its matching tunnel technology on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

mGRE with NHRP

IKEv2-based VPN

GDOI group key management

TLS/DTLS for remote access

IKEv1 or IKEv2 with ESP

Why these pairings

DMVPN uses mGRE and NHRP; FlexVPN uses IKEv2; GET VPN uses GDOI; AnyConnect uses TLS/DTLS; Site-to-Site IPsec VPN uses IKEv1 or IKEv2 with ESP.

1231
Multi-Selectmedium

Which two statements about Control Plane Policing (CoPP) are true? (Choose two.)

Select 2 answers
A.CoPP uses ACLs to match traffic destined for the control plane.
B.CoPP is applied as a service policy on the control plane interface.
C.CoPP can only be used to rate-limit traffic, not to drop it.
D.CoPP is applied to all physical interfaces to protect the data plane.
E.CoPP can only filter IPv4 traffic.
AnswersA, B

CoPP classifies control-plane-bound traffic using ACLs, which match packets destined to the router itself, such as routing protocols and management traffic. These ACL matches feed the class maps that define which traffic the policy subsequently rate-limits.

Why this answer

Option A is correct because CoPP relies on class maps built from ACLs (or NBAR, QoS groups, etc.) to classify and match traffic that is destined to the control plane, such as routing protocol, management, and ICMP packets processed by the route processor. Option B is correct because CoPP is implemented by attaching a service policy to the control plane interface using the global configuration command 'service-policy input <policy-name>' under 'control-plane' (or 'control-plane host/subinterface'), which is the standard deployment point. Option C is false because CoPP can both rate-limit and drop or police excess traffic via the policer actions (transmit, drop, set precedence), not merely rate-limit.

Option D is false because CoPP protects the control plane, not the data plane, and it is applied to the control plane interface rather than all physical interfaces. Option E is false because CoPP can match IPv4, IPv6, MPLS, and non-IP traffic through appropriate ACLs and class maps, so it is not limited to IPv4.

Exam trap

350-401 often tests where CoPP is applied — candidates assume it goes on physical interfaces like a normal service policy, but CoPP is attached to the control plane interface to protect the route processor.

1232
MCQeasy

What is the default OSPF hello interval on an Ethernet link in Cisco IOS?

A.10 seconds
B.30 seconds
C.40 seconds
D.5 seconds
AnswerA

On OSPF broadcast multi-access networks such as Ethernet, the default hello interval is 10 seconds, and the associated dead interval is 40 seconds (four times the hello). This is the standard value defined in RFC 2328 for broadcast and point-to-point network types, ensuring timely neighbor discovery and liveness detection without excessive control-plane overhead. Because both routers must agree on the hello interval to form an adjacency, the Ethernet default of 10 seconds is the correct answer.

Why this answer

In Cisco IOS, the default OSPF hello interval for broadcast multi-access networks such as Ethernet is 10 seconds. This value is defined in RFC 2328 and is used to maintain neighbor adjacencies; if a hello is not received within the dead interval (default 40 seconds, or 4 times the hello interval), the neighbor is declared down.

Exam trap

Cisco often tests the default OSPF hello interval on Ethernet (10 seconds) versus the dead interval (40 seconds) or the hello interval on other network types (e.g., NBMA at 30 seconds), so candidates must memorize the exact per-network-type defaults.

How to eliminate wrong answers

Option B (30 seconds) is wrong because 30 seconds is the default hello interval for OSPF on non-broadcast multi-access (NBMA) networks like Frame Relay, not Ethernet. Option C (40 seconds) is wrong because 40 seconds is the default OSPF dead interval on Ethernet, not the hello interval. Option D (5 seconds) is wrong because 5 seconds is the default hello interval for OSPF on point-to-point links in some implementations, but not the default for Ethernet broadcast networks in Cisco IOS.

1233
Multi-Selecthard

A network engineer is deploying Cisco DNA Center Assurance and wants to ensure that the system can accurately monitor and troubleshoot network issues. Which two statements about Cisco DNA Center Assurance are true? (Choose two.)

Select 2 answers
A.Assurance requires SNMP polling for all device monitoring.
B.Assurance uses streaming telemetry to collect data from network devices.
C.Assurance provides a graphical view of the network topology and device health.
D.Assurance requires manual configuration of each device to enable monitoring.
E.Assurance can only monitor wired devices, not wireless.
AnswersB, C

Cisco DNA Center Assurance leverages streaming telemetry to gather near real-time data from network devices. This allows for continuous monitoring and rapid detection of issues. Streaming telemetry is more efficient than polling and provides granular data for analysis. This is a key feature of Assurance.

Why this answer

Cisco DNA Center Assurance uses streaming telemetry for real-time data collection and provides a graphical topology view of network health. These features enable proactive monitoring and rapid troubleshooting. The other statements are false: Assurance does not require SNMP polling for all devices, it supports both wired and wireless, and it does not require manual per-device configuration for monitoring.

Exam trap

The trap here is assuming that Assurance relies solely on SNMP polling or requires manual configuration, when it actually uses streaming telemetry and automated onboarding.

1234
Drag & Dropmedium

Drag and drop the steps of REST API call using Requests library to DNA Center into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with importing the Requests library, sending a POST request to the authentication endpoint with credentials, extracting the token from the JSON response, using the token in headers for a GET request to a resource endpoint, and finally parsing the JSON response.

1235
MCQmedium

A network engineer is deploying a new WLAN and needs to ensure that client traffic is encrypted using AES with a pre-shared key. Which security configuration should be applied to the wireless SSID?

A.WPA2-PSK with AES
B.WPA3-PSK with AES
C.WPA2-PSK with TKIP
D.WEP with AES
AnswerA

WPA2-PSK with AES-CCMP is the appropriate choice because it offers robust wireless encryption (AES in counter mode with CBC-MAC) and uses a pre-shared key for straightforward authentication. This configuration is widely supported, passes PCI DSS requirements for strong encryption, and fulfills the stated requirement of using AES-based security. It balances compatibility with strong protection.

Why this answer

WPA2-PSK with AES is the correct choice because the requirement specifies AES encryption with a pre-shared key. WPA2-PSK (Wi-Fi Protected Access 2 – Pre-Shared Key) mandates AES-CCMP (Counter Mode Cipher Block Chaining Message Authentication Code Protocol) as the encryption protocol, providing strong, standards-compliant security for client traffic. This configuration directly satisfies the need for both AES encryption and PSK authentication.

Exam trap

Candidates may mistakenly think that WPA3-PSK is a valid term because WPA3 uses AES and a pre-shared key (password). However, the industry-standard name is WPA3-Personal (which uses SAE for key exchange), not WPA3-PSK. The option 'WPA3-PSK with AES' is incorrect due to non-standard terminology, while WPA2-PSK with AES fully meets the need for AES encryption and PSK authentication.

How to eliminate wrong answers

Option B is wrong because WPA3-PSK uses AES encryption but introduces Simultaneous Authentication of Equals (SAE) instead of a traditional pre-shared key handshake; while it supports PSK, the question explicitly asks for a configuration that ensures AES with a pre-shared key, and WPA3-PSK is not the only or most direct answer given the options. Option C is wrong because WPA2-PSK with TKIP uses the RC4-based Temporal Key Integrity Protocol, not AES, which violates the requirement for AES encryption. Option D is wrong because WEP (Wired Equivalent Privacy) does not support AES; it uses RC4 encryption and is deprecated due to severe security vulnerabilities, making it incompatible with the AES requirement.

1236
Multi-Selectmedium

A network engineer is implementing Cisco TrustSec in a campus network. The engineer needs to configure the enforcement of security group tags (SGTs) on Cisco Catalyst switches. Which two statements are true regarding SGT enforcement and propagation? (Choose two.)

Select 2 answers
A.SGTs are only supported on Cisco ASA firewalls and not on Cisco Catalyst switches.
B.SGTs are assigned to endpoints by Cisco ISE during authentication and can be used for role-based access control.
C.SGT enforcement is performed by security group ACLs (SGACLs) on Cisco ISE, which pushes them to switches.
D.SGTs are encrypted in the packet to prevent tampering, and only Cisco ISE can decrypt them.
E.SGTs can be propagated through a network using inline tagging or SXP.
AnswersB, E

Cisco ISE assigns an SGT to an endpoint as part of the authorization policy after successful authentication. This SGT represents the endpoint's role or group. The switch then uses this SGT in conjunction with SGACLs to enforce role-based access control. This is a fundamental part of Cisco TrustSec.

Why this answer

SGTs can be propagated via inline tagging or SXP, allowing enforcement across devices that may not support inline tagging. Cisco ISE assigns SGTs to endpoints during authentication, enabling role-based access control. Enforcement is performed on network devices using SGACLs, not on ISE itself.

Exam trap

The trap here is thinking that SGACL enforcement happens on Cisco ISE, when in fact ISE only defines and distributes the policies; enforcement is on the network device.

1237
MCQhard

A network engineer issues the following command on Router R6: R6# debug ip ospf hello OSPF: Send hello to 224.0.0.5 via GigabitEthernet0/0 (192.168.1.6) OSPF: Rcv hello from 1.1.1.1, GigabitEthernet0/0, area 0.0.0.0 Neighbor state is 2WAY, options 0x2 OSPF: End of hello processing Based on this output, what can be concluded?

A.R6 has formed a full adjacency with neighbor 1.1.1.1.
B.The hello packet was sent to the DR/BDR multicast address 224.0.0.6.
C.R6 and 1.1.1.1 are neighbors, but a full adjacency may not yet be formed.
D.The OSPF network type is point-to-point.
AnswerC

The 2WAY state confirms that R6 and 1.1.1.1 have exchanged Hello packets that include each other's Router ID, making them OSPF neighbors. However, 2WAY is only a preliminary step; a full adjacency (FULL) requires an exchange of Database Description packets, Link-State Requests, and Link-State Updates to synchronize their OSPF link-state databases. Moreover, on broadcast multi-access networks, a router forms FULL adjacencies only with the DR/BDR, so two non-DR routers can remain in 2WAY without ever reaching FULL. Thus, being neighbors does not guarantee a full adjacency exists.

Why this answer

The debug output shows the neighbor state is 2WAY, which indicates that R6 has received a hello from 1.1.1.1 and bidirectional communication is established, but a full adjacency has not yet been formed. In OSPF, the 2WAY state is a prerequisite for advancing to the ExStart state and eventually to FULL, but on multiaccess networks, the router must also wait for the Designated Router (DR) and Backup Designated Router (BDR) election process to complete before proceeding. Therefore, option C correctly states that R6 and 1.1.1.1 are neighbors, but a full adjacency may not yet be formed.

Exam trap

Cisco often tests the distinction between the 2WAY and FULL states, and the trap here is that candidates mistakenly assume that receiving a hello packet means a full adjacency has been formed, ignoring the multi-step OSPF neighbor state machine and the role of DR/BDR elections on broadcast networks.

How to eliminate wrong answers

Option A is wrong because the neighbor state is 2WAY, not FULL; a full adjacency is only achieved after the database description (DBD), LSR, LSU, and LSAck exchanges in the ExStart, Exchange, Loading, and FULL states. Option B is wrong because the hello packet was sent to 224.0.0.5, which is the AllSPFRouters multicast address used for OSPF hello packets on broadcast and point-to-point networks, not the DR/BDR multicast address 224.0.0.6. Option D is wrong because the use of multicast address 224.0.0.5 and the presence of a 2WAY state (which implies a DR/BDR election process) strongly suggest a broadcast network type, not point-to-point; on a point-to-point link, neighbors typically transition directly to FULL without a 2WAY state.

1238
Multi-Selectmedium

A network administrator is implementing Dynamic ARP Inspection (DAI) on a Cisco Catalyst switch. The network uses DHCP for most endpoints, but a few servers have static IP addresses. Which two actions are required to ensure DAI allows legitimate traffic while blocking ARP spoofing? (Choose two.)

Select 2 answers
A.Configure static ARP ACLs for hosts with statically assigned IP addresses.
B.Enable port security with sticky MAC addresses on all access ports.
C.Configure DAI to trust all access ports.
D.Disable IP Source Guard on all access ports.
E.Enable DHCP snooping on the VLANs where DAI is enabled.
AnswersA, E

Hosts with static IP addresses do not appear in the DHCP snooping binding table, so DAI would drop their ARP packets. Creating a static ARP ACL and applying it to the DAI configuration with the arp access-list command allows those specific IP-to-MAC mappings to be validated. This ensures legitimate static hosts are not blocked while spoofing remains prevented.

Why this answer

DAI validates ARP packets against the DHCP snooping binding table, so DHCP snooping must be enabled on the same VLANs. Static hosts are not in that table, so an ARP ACL must be configured to permit their specific IP-to-MAC bindings. Together, these actions allow legitimate DHCP and static traffic while blocking spoofed ARP packets.

Exam trap

The trap here is forgetting that DAI depends on DHCP snooping bindings, so static hosts require an ARP ACL or they will be dropped.

1239
MCQmedium

A network engineer is configuring a Cisco Nexus 9000 switch as a VTEP in a VXLAN EVPN fabric. The engineer needs to specify the loopback0 interface as the source for VXLAN tunnels. Which command must be entered under the NVE interface configuration?

A.vxlan source-interface loopback0
B.interface loopback0
C.source-interface loopback0
D.source loopback0
AnswerC

This command correctly sets the loopback0 interface as the source for VXLAN tunnels on the NVE interface. In Cisco NX-OS, under interface nve1, the 'source-interface loopback0' command designates the loopback interface whose IP address will be used as the source IP in the outer IP header of VXLAN encapsulated packets. This is essential for VTEP reachability and tunnel establishment.

Why this answer

The correct command to set the source interface for VXLAN tunnels on a Cisco Nexus 9000 NVE interface is 'source-interface loopback0'. This command ensures that the loopback0 IP address is used as the source IP for VXLAN encapsulated traffic, which is critical for VTEP reachability and proper tunnel establishment. Without it, the NVE interface cannot function correctly.

Exam trap

The trap here is confusing the NVE source interface command with similar commands used in other contexts, such as 'source-interface' under NTP or 'interface loopback0' to enter interface configuration.

1240
MCQeasy

A network administrator is deploying a new branch office that requires a redundant default gateway for hosts on VLAN 10. The administrator wants to use a Cisco-proprietary protocol that provides sub-second failover and supports load sharing between two routers. Which First Hop Redundancy Protocol should be used?

A.Hot Standby Router Protocol (HSRP)
B.Virtual Router Redundancy Protocol (VRRP)
C.Gateway Load Balancing Protocol (GLBP)
D.Intermediate System to Intermediate System (IS-IS)
AnswerC

GLBP is a Cisco-proprietary First Hop Redundancy Protocol that provides both redundancy and load sharing. It uses an Active Virtual Gateway (AVG) and up to four Active Virtual Forwarders (AVFs). The AVG assigns virtual MAC addresses to each AVF, and hosts are distributed across the AVFs for load balancing. Failover is sub-second, and if an AVF fails, another AVF takes over its virtual MAC address.

Why this answer

Gateway Load Balancing Protocol (GLBP) is the correct choice because it is Cisco-proprietary and provides both redundancy and load sharing. Unlike HSRP, which has a single active router, GLBP uses an Active Virtual Gateway to distribute traffic across multiple Active Virtual Forwarders, each with its own virtual MAC address. This allows hosts to share the load while maintaining sub-second failover.

Exam trap

The trap here is assuming that HSRP provides load sharing by default, when in fact it requires multiple groups and is not inherently load-balancing.

1241
Matchingmedium

Drag and drop each BGP attribute on the left to its matching type on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Well-known mandatory

Well-known mandatory

Well-known discretionary

Optional non-transitive

Optional transitive

Why these pairings

AS_PATH and NEXT_HOP are well-known mandatory; LOCAL_PREF is well-known discretionary; MED is optional non-transitive; COMMUNITY is optional transitive.

1242
MCQeasy

What is the default lease time for a DHCP pool in Cisco IOS?

A.1 day
B.12 hours
C.2 days
D.Infinite
AnswerA

The Cisco IOS DHCP server assigns a default lease duration of 86,400 seconds, which is exactly 24 hours or one day. This lease time is used for any pool where the lease command is not explicitly configured. Because the question asks for the default lease, 1 day is the correct answer.

Why this answer

The default DHCP lease time in Cisco IOS is 1 day (86400 seconds). This is defined in the DHCP pool configuration and is applied automatically when no lease duration is explicitly specified. The lease time determines how long a client can use an assigned IP address before it must renew the lease.

Exam trap

Cisco often tests the default lease time as a memorization point, and the trap here is that candidates may confuse the Cisco IOS default with the default lease time of other DHCP servers (e.g., Windows Server defaults to 8 days) or assume a shorter time like 12 hours is more common.

How to eliminate wrong answers

Option B (12 hours) is wrong because the default lease time is 1 day, not 12 hours; 12 hours would require explicit configuration with the 'lease 0 12' command. Option C (2 days) is wrong because 2 days is not the default; it would need to be set manually with 'lease 2'. Option D (Infinite) is wrong because Cisco IOS does not use an infinite lease by default; an infinite lease would require the 'lease infinite' command, which is rarely used in production due to address exhaustion risks.

1243
Matchingmedium

Drag and drop each DMVPN phase on the left to its matching NHRP operation type on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Hub-and-spoke with NHRP registration

Spoke-to-spoke dynamic tunnel via NHRP resolution request/reply

NHRP with prefix-based spoke-to-spoke shortcut

Why these pairings

DMVPN has only three phases. Phase 1 uses NHRP for hub registration only; Phase 2 uses NHRP for spoke-to-spoke dynamic tunnel creation via resolution request/reply; Phase 3 uses NHRP with prefix-based spoke-to-spoke shortcut.

1244
MCQmedium

A network engineer is configuring port security on a Cisco switch to prevent unauthorized devices from connecting. The requirement is to allow only the first two MAC addresses learned on an interface, and to disable the interface if a violation occurs. Which configuration achieves this?

A.switchport port-security maximum 2 switchport port-security violation err-disable
B.switchport port-security maximum 2 switchport port-security violation shutdown
C.switchport port-security maximum 2 switchport port-security violation protect
D.switchport port-security maximum 2 switchport port-security violation restrict
AnswerB

This is the correct configuration. It sets the maximum number of secure MAC addresses to 2 and also specifies the violation action as 'shutdown'. When a third MAC address attempts to use the port, the switch places the interface in an err-disabled state, which completely disables the port and blocks all traffic, satisfying the requirement to disable the interface upon a violation.

Why this answer

The 'shutdown' violation mode places the interface into an err-disabled state when a port security violation occurs, which matches the requirement to disable the interface. The 'maximum 2' command limits the number of allowed MAC addresses to two, and the first two learned MAC addresses are dynamically secured. This combination ensures that any additional MAC address triggers a violation and disables the port.

Exam trap

Cisco often tests the distinction between 'shutdown' (disables the interface) and 'restrict' (drops traffic but keeps the interface up), leading candidates to confuse the two when the requirement explicitly calls for disabling the interface.

How to eliminate wrong answers

Option A is wrong because 'err-disable' is not a valid violation mode; the correct keyword is 'shutdown' to disable the interface. Option C is wrong because 'protect' drops packets from unknown MAC addresses but does not disable the interface or generate a syslog message, failing the requirement to disable the interface. Option D is wrong because 'restrict' drops packets from unknown MAC addresses and generates a syslog message but does not disable the interface, also failing the requirement.

1245
Multi-Selectmedium

Which two statements about using Python for network automation with Cisco devices are true? (Choose two.)

Select 2 answers
A.Netmiko is a Python library that simplifies SSH connections to network devices by handling authentication and session establishment.
B.NAPALM can be used to retrieve operational state data from network devices using a vendor-agnostic API.
C.Python scripts for network automation are compiled into native machine code for faster execution.
D.The netmiko library can only be used with Cisco IOS devices.
E.Paramiko is a higher-level library than Netmiko and provides additional automation features.
AnswersA, B

Netmiko wraps Paramiko to abstract per-vendor SSH prompts, handling login credentials, enable mode and prompt detection so scripts need not manage raw channels. This satisfies the stem's requirement for simplified SSH session establishment and authentication against Cisco devices.

Why this answer

Option A is correct because Netmiko is a Python library built on top of Paramiko that abstracts SSH connection details—handling authentication, session establishment, and device prompts—so scripts can interact with Cisco devices without manually managing low-level SSH. Option B is correct because NAPALM provides a vendor-agnostic API with methods such as get_facts(), get_interfaces(), and get_config() that retrieve operational state and configuration data across multiple vendors, including Cisco IOS, IOS-XR, NX-OS, and Junos. Option C is incorrect because Python is an interpreted language; scripts are executed by the Python interpreter and are not compiled into native machine code.

Option D is incorrect because Netmiko supports many platforms beyond Cisco IOS, including Cisco IOS-XE, IOS-XR, NX-OS, ASA, Juniper, Arista, and others via its platform-specific drivers. Option E is incorrect because Paramiko is a lower-level SSH library, while Netmiko is the higher-level abstraction that adds network-device-specific automation features on top of Paramiko.

Exam trap

The trap here is confusing the layering of Paramiko, Netmiko, and NAPALM, and assuming Netmiko is Cisco-IOS-only when it is actually multi-vendor.

1246
Multi-Selecthard

A network security team is hardening a Cisco IOS-XE router that terminates a site-to-site VPN to the internet. They want to ensure that the router itself cannot be managed from untrusted networks and that its management protocols are protected. Which two configuration actions achieve these goals? (Choose two.)

Select 2 answers
A.Enable the exec-timeout 0 0 command on all VTY lines to prevent session lockouts during maintenance
B.Apply an access list to the VTY lines that permits only trusted management subnets and add the transport input ssh command
C.Configure a local username with privilege level 15 and no password to ensure emergency access is always available
D.Enable the ip http server command to allow web-based management as a backup access method
E.Configure an ACL on the WAN interface that denies SNMP and NETCONF from untrusted sources while permitting VPN traffic
AnswersB, E

Restricting VTY access with an ACL to trusted management subnets and disabling Telnet via transport input ssh prevents unauthenticated or cleartext management from untrusted networks. This directly addresses the goal of protecting the router's management plane from the internet and is a standard hardening step on Cisco IOS-XE edge devices.

Why this answer

Hardening the management plane requires restricting who can reach the management interfaces and how. Limiting VTY access with an ACL to trusted subnets and forcing SSH eliminates cleartext and unauthorized remote logins, while an interface ACL that blocks SNMP and NETCONF from untrusted sources prevents those services from being exploited from the internet. Together these actions protect the router's management plane without disrupting the site-to-site VPN traffic.

Exam trap

The trap here is treating convenience measures such as disabling exec-timeout, enabling plain HTTP, or creating passwordless privileged accounts as acceptable hardening, when they actually increase exposure on an internet-facing router.

1247
MCQmedium

A network engineer runs the following command on Router R5: R5# show queueing interface GigabitEthernet0/1 Interface GigabitEthernet0/1 queueing strategy: weighted fair Queueing on output: Weighted Fair Queueing Current fair queue configuration: Number of queues: 256 Dynamic queues: 256 Reserved queues: 0 Current WFQ global configuration: Total dynamic queues: 256 Total reserved queues: 0 Class based weighted fair queueing: enabled Queueing on input: FIFO Based on this output, what can be concluded?

A.The interface uses FIFO queuing for output.
B.The interface uses Weighted Fair Queueing for output with 256 queues.
C.The interface uses Class-Based Weighted Fair Queueing (CBWFQ).
D.The interface uses Priority Queuing.
AnswerB

This is correct because the output contains two decisive statements: 'Queueing on output: Weighted Fair Queueing' and 'Number of queues: 256'. The first confirms the active output scheduling is WFQ, while the second specifies the number of dynamic queues used for flow classification. WFQ separates packets into conversations based on flow characteristics (source/destination address, ports, protocol, ToS) and schedules them fairly so that interactive flows are not starved by high-bandwidth bulk transfers. The default WFQ uses 256 queues (or a power of two), which matches the output.

Why this answer

The output explicitly states 'Queueing on output: Weighted Fair Queueing' and shows 'Number of queues: 256', confirming that the interface uses WFQ with 256 queues for output. WFQ is a flow-based queuing mechanism that dynamically assigns packets to queues based on flow characteristics, and the output confirms this configuration.

Exam trap

Cisco often tests the distinction between 'Weighted Fair Queueing' (flow-based WFQ) and 'Class-Based Weighted Fair Queueing' (CBWFQ), where the presence of 'class based weighted fair queueing: enabled' in the output does not mean CBWFQ is the active queuing strategy—it only indicates the feature is available, while the actual strategy is determined by the 'queueing strategy' line.

How to eliminate wrong answers

Option A is wrong because the output shows 'Queueing on output: Weighted Fair Queueing', not FIFO; FIFO is only used on input. Option C is wrong because while the output mentions 'Class based weighted fair queueing: enabled', this indicates CBWFQ is available but not necessarily active; the actual queueing strategy shown is 'weighted fair' (flow-based WFQ), not CBWFQ which requires explicit class maps and policy maps. Option D is wrong because Priority Queuing is not mentioned anywhere in the output; the interface uses WFQ, which is a different queuing mechanism.

1248
MCQmedium

A network engineer is designing a new branch office that must support wired and wireless users with unified policy enforcement and automation. The company wants to minimize manual configuration and ensure consistent security policies across all access ports. Which Cisco architecture should the engineer recommend?

A.Cisco SD-WAN
B.Cisco SD-Access
C.Cisco ACI
D.Cisco TrustSec
AnswerB

SD-Access uses a fabric with VXLAN encapsulation and Cisco Identity Services Engine (ISE) for policy, enabling consistent security and automation across wired and wireless. It provides a single policy plane and reduces manual configuration through fabric provisioning, matching the requirement for unified policy and minimal manual effort.

Why this answer

Cisco SD-Access is a campus fabric architecture that integrates wired and wireless access with centralized policy using Cisco ISE and VXLAN. It automates fabric provisioning and enforces consistent security policies across all access ports, directly addressing the need for unified policy and minimal manual configuration in a branch office.

Exam trap

The trap here is confusing campus fabric automation with WAN or data center architectures that also provide policy but not for unified campus access.

1249
Multi-Selecteasy

Which two statements about OSPF neighbor states are true? (Choose two.)

Select 2 answers
A.The 2-Way state indicates that both routers have seen their own router ID in the neighbor's hello packet.
B.The Full state indicates that the routers have synchronized their LSDBs and are fully adjacent.
C.In the ExStart state, routers exchange Database Description packets containing LSA headers.
D.In the Exchange state, routers send Link State Requests and receive Link State Updates.
E.The Down state is the final state when a neighbor is unreachable.
AnswersA, B

2-Way is declared once each router sees its own Router ID listed in the neighbour's Hello packet, proving two-way reachability. This bidirectional confirmation is the defining mechanism of the state, so the statement accurately describes when it is reached.

Why this answer

Option A is correct because the 2-Way state is reached when a router receives a Hello packet from a neighbor that contains its own Router ID in the neighbor list field, confirming bidirectional communication. Option B is correct because Full state means the two routers have successfully completed database synchronization, so their link-state databases (LSDBs) are identical and they are fully adjacent. Option C is incorrect because Database Description (DBD) packets with LSA headers are exchanged in the Exchange state, not the ExStart state; ExStart only negotiates the master/slave relationship and initial DBD sequence numbers.

Option D is incorrect because Link State Requests and Link State Updates are exchanged in the Loading state, not the Exchange state. Option E is incorrect because Down is the initial state, not the final state, when no Hello packets have been received from the neighbor.

Exam trap

The trap here is confusing the ExStart/Exchange/Loading states — candidates often mix up which packets (DBD, LSR, LSU) are exchanged in which state, and mistakenly think Down is a terminal state rather than the initial one.

1250
MCQmedium

A network engineer runs the following command on Router R4: R4# show ip dhcp binding Bindings from all pools not associated with VRF: IP address Client-ID/ Lease expiration Type Hardware address/ User name 10.0.0.10 0063.6973.636f.2d30. Mar 01 2025 12:00 PM Automatic 3030.302e.3030.3030. 2e30.3030.312d.4574. 30 10.0.0.11 0063.6973.636f.2d30. Mar 01 2025 12:05 PM Automatic 3030.302e.3030.3030. 2e30.3030.312d.4574. 31 Based on this output, what can be concluded?

A.Both clients have static DHCP reservations.
B.The DHCP server has two active leases.
C.The DHCP server is out of addresses.
D.The clients are using DHCPv6.
AnswerB

The DHCP binding table displays two entries, each with an IP address, client identifier, and a lease expiration time in the future. Active leases are defined as bindings that are currently assigned and not expired; both entries meet this criterion. This indicates the server has successfully leased addresses to two clients.

Why this answer

The output shows two IP addresses (10.0.0.10 and 10.0.0.11) with lease expiration times and a type of 'Automatic', which indicates that these are dynamically assigned leases from the DHCP pool. The presence of two active leases confirms that the DHCP server has successfully allocated two addresses to clients, making option B correct.

Exam trap

Cisco often tests the distinction between 'Automatic' (dynamic) and 'Manual' (reservation) in the 'show ip dhcp binding' output, leading candidates to confuse active leases with static reservations.

How to eliminate wrong answers

Option A is wrong because the 'Type' column shows 'Automatic', not 'Manual' or 'Static', which would indicate a static DHCP reservation configured with the 'ip dhcp pool' command and a 'hardware-address' statement. Option C is wrong because the output shows two active leases, and there is no indication of exhaustion (e.g., no 'out of addresses' error or zero available addresses in the pool). Option D is wrong because the IP addresses shown (10.0.0.10 and 10.0.0.11) are IPv4 addresses, and the command 'show ip dhcp binding' is specific to DHCPv4; DHCPv6 bindings are displayed with 'show ipv6 dhcp binding'.

1251
Drag & Dropmedium

Drag and drop the steps of YANG push periodic vs on-change subscription into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with defining the subscription parameters, then configuring the push method (periodic or on-change), followed by establishing the telemetry session, sending updates, and finally the collector processing the data.

1252
Multi-Selectmedium

A network engineer is deploying a VXLAN EVPN fabric on Cisco Nexus 9000 switches. The engineer must configure the NVE interface and ensure proper VXLAN data plane operation. Which two statements about VXLAN EVPN configuration on Nexus 9000 are true? (Choose two.)

Select 2 answers
A.The EVPN control plane requires BGP to be configured with the EVPN address family on the spine and leaf switches.
B.VXLAN uses a 24-bit VNI field, allowing for up to 16 million unique VNIs.
C.The NVE interface must be configured with a source interface that is reachable via the underlay routing protocol.
D.Each VNI must be mapped to a unique VLAN on every leaf switch in the fabric.
E.The NVE interface must be configured with a multicast group for broadcast, unknown unicast, and multicast (BUM) traffic.
AnswersA, C

In a VXLAN EVPN fabric, BGP is used as the EVPN control plane. The spine and leaf switches must be configured with the EVPN address family (address-family l2vpn evpn) to exchange EVPN routes. This allows the fabric to learn MAC addresses and IP addresses dynamically, reducing the need for flooding. Without BGP EVPN, the fabric would rely on data plane learning, which is less efficient. Thus, this statement is true for Nexus 9000 VXLAN EVPN configuration.

Why this answer

The NVE interface requires a reachable source interface for VXLAN tunnels to form, and the EVPN control plane relies on BGP with the EVPN address family to exchange MAC and IP reachability information. These two statements are true for VXLAN EVPN configuration on Nexus 9000. The other options are either general VXLAN facts not specific to EVPN configuration, incorrect requirements, or applicable only to flood-and-learn VXLAN.

Exam trap

The trap here is assuming that multicast is always required for BUM traffic in VXLAN, when in EVPN deployments ingress replication can be used instead, making multicast optional.

1253
MCQeasy

A network engineer is configuring a Cisco IOS switch to use 802.1X authentication for endpoints connected to interface GigabitEthernet1/0/1. The engineer wants to ensure that if the RADIUS server is unreachable, the port will be placed in a restricted VLAN. Which command should be used?

A.authentication host-mode multi-auth
B.authentication event fail action authorize vlan 10
C.authentication event no-response action authorize vlan 10
D.authentication event server dead action authorize vlan 10
AnswerD

This command specifies that if the RADIUS server becomes unreachable, the port will be authorized into VLAN 10, providing restricted access. It is used within 802.1X configuration to define fallback behavior when the authentication server is dead, ensuring that endpoints can still gain limited network access according to policy.

Why this answer

The command 'authentication event server dead action authorize vlan 10' is specifically designed to handle the case where the RADIUS server is unreachable, placing the port into VLAN 10 as a fallback. This ensures that endpoints can still access limited network resources according to policy when the authentication server is down.

Exam trap

The trap here is confusing the server dead event with fail or no-response events, which handle different failure conditions.

1254
Drag & Dropmedium

Drag and drop the steps of using a Python REST API call to retrieve device configuration via Cisco DNA Center into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The process begins with authenticating to the DNA Center API to obtain a token. Then, the device UUID is retrieved using a GET request to the device list endpoint. Next, a GET request is sent to fetch the running configuration for that device.

The JSON response is parsed to extract the configuration text. Finally, the configuration is saved to a local file.

1255
MCQmedium

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs. After applying a policer to the control plane, the BGP sessions tear down repeatedly while OSPF adjacencies stay stable. The administrator confirms CPU utilization is low. Which action should be taken to resolve the issue?

A.Apply the CoPP policy to the data plane interfaces using the service-policy input command.
B.Increase the CIR of the policer class matching BGP traffic and permit the BGP class in the control-plane service policy.
C.Disable CEF switching on the router so BGP packets are process-switched and bypass the policer.
D.Enable NetFlow on the WAN interfaces and export records to a collector for BGP traffic analysis.
AnswerB

BGP session teardown with low CPU indicates the policer is dropping BGP keepalives before they reach the control plane. Raising the committed information rate for the BGP class and explicitly permitting that class in the control-plane policy allows the protocol traffic to pass at the required rate, restoring adjacency stability without disabling CoPP for other traffic.

Why this answer

CoPP policies inspect and police traffic punted to the route processor. When a policer for a critical routing protocol is too restrictive, protocol hellos and keepalives are dropped, causing peering failures even though CPU load is low. Adjusting the policer rate and ensuring the protocol class is permitted restores the required control-plane traffic while retaining protection against abuse.

Exam trap

The trap here is assuming that low CPU utilization proves CoPP is working correctly, when in fact a too-strict policer silently discards essential routing protocol keepalives.

1256
Drag & Dropmedium

Drag and drop the steps of 802.11r Fast BSS Transition (FT) roaming steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

802.11r FT roaming uses a key hierarchy to reduce latency. The client first discovers the target AP via scanning. The client sends an FT Authentication request containing a Mobility Domain Identifier (MDIE) and R0KH-ID.

The target AP responds with an FT Authentication response with key data. The client then sends an FT Association request, and the AP completes the process with an FT Association response.

1257
Multi-Selectmedium

A network engineer is deploying IP SLA to monitor network performance. The engineer needs to configure an IP SLA operation that measures jitter and packet loss between two Cisco routers. Which two statements are true about configuring IP SLA for this purpose? (Choose two.)

Select 2 answers
A.The ip sla responder command must be configured on the destination router.
B.The operation type udp-jitter is used to measure jitter and packet loss.
C.The ip sla schedule command is optional and only needed for historical data collection.
D.The operation can be configured using the icmp-echo operation type to measure jitter.
E.The ip sla responder command must be configured on the source router.
AnswersA, B

For UDP jitter operations, the destination router must have the ip sla responder command enabled to provide accurate measurements. The responder allows the destination to timestamp incoming packets and return them, enabling the source to calculate jitter and packet loss. Without it, the operation may still function in some cases, but the responder is required for precise jitter and loss statistics, making this statement correct.

Why this answer

To measure jitter and packet loss with IP SLA, the engineer should use the udp-jitter operation type and configure the ip sla responder on the destination router. The responder ensures accurate timestamping and response, while scheduling is mandatory to start the operation. The icmp-echo operation does not measure jitter, and the responder belongs on the destination, not the source.

Exam trap

The trap here is assuming that any IP SLA operation can measure jitter or that the responder is configured on the source router, when in fact udp-jitter and a destination responder are required.

1258
MCQhard

A network engineer is configuring a Cisco IOS router to support OSPFv3 for IPv6. The router is connected to two OSPFv3 areas: area 0 and area 1. The engineer wants to summarize the IPv6 routes from area 1 into area 0 using the prefix 2001:DB8:1::/48. Which command should be used on the area border router (ABR)?

A.area 1 range 2001:DB8:1::/48
B.summary-address 2001:DB8:1::/48
C.ipv6 ospf summary-prefix 2001:DB8:1::/48
D.area 0 range 2001:DB8:1::/48
AnswerA

This command configures inter-area route summarization for OSPFv3 on the ABR. The 'area 1 range' command tells the ABR to advertise a single summary route for the specified prefix into other areas. It must be configured under IPv6 router OSPF configuration mode. This is the correct way to summarize OSPFv3 routes between areas.

Why this answer

In OSPFv3, inter-area route summarization is configured on an ABR using the 'area <area-id> range <prefix>' command. The area ID specifies the source area whose routes are to be summarized. Here, routes from area 1 are summarized into area 0 using the prefix 2001:DB8:1::/48.

The other commands either do not exist, are for external summarization, or specify the wrong area.

Exam trap

The trap here is confusing inter-area summarization with external summarization, or using the wrong area ID in the command.

1259
MCQmedium

A network engineer is configuring OSPF in a multi-area design. The engineer wants to reduce the amount of LSA flooding and the size of the LSDB in area 0. Which OSPF feature should be implemented on the ABR to achieve this goal?

A.Configure area 0 as a stub area.
B.Configure the ABR with an area filter-list to filter type 3 LSAs.
C.Configure OSPF database overflow protection.
D.Configure the ABR as an ASBR.
AnswerB

The area filter-list command on an ABR filters type 3 summary LSAs entering or leaving an area, directly and proactively reducing the number of LSAs in area 0's link-state database. Only type 3 LSAs that describe inter-area prefixes are affected, so selected routes are omitted from the ABR's summary advertisements without disrupting the backbone's transit role or intra-area operations. This is the only option that reduces LSDB size while maintaining correct OSPF design.

Why this answer

Configuring an area filter-list on the ABR allows the engineer to filter Type 3 summary LSAs entering or leaving area 0. This directly reduces LSA flooding and shrinks the LSDB in area 0 by preventing specific inter-area prefixes from being advertised into the backbone, without altering the area type or requiring additional redistribution.

Exam trap

The trap here is that candidates often assume area 0 can be made a stub area to reduce LSAs, but Cisco tests the fact that area 0 is a transit area and cannot be a stub, making the filter-list the correct tool for this specific goal.

How to eliminate wrong answers

Option A is wrong because area 0 cannot be configured as a stub area; OSPF requires area 0 to be a transit area and stub areas cannot have virtual links or ASBRs, making this configuration invalid. Option C is wrong because OSPF database overflow protection limits the total number of LSAs in the LSDB to prevent memory exhaustion, but it does not selectively reduce LSA flooding or the LSDB size in area 0 as requested. Option D is wrong because configuring the ABR as an ASBR would introduce external LSAs (Type 5) into the OSPF domain, increasing the LSDB size and flooding, which is the opposite of the goal.

1260
Drag & Dropmedium

Drag and drop the steps of using Ansible to push a new VLAN configuration to a Cisco IOS switch into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, define the VLAN ID and name in a variable file. Then, write a playbook task using ios_vlan module. Next, specify the connection parameters (ansible_network_os, ansible_user, etc.) in the inventory.

After that, run the playbook to apply the configuration. Finally, verify the VLAN on the switch using show vlan.

1261
Multi-Selecthard

Which three statements about QoS trust boundaries and marking are true? (Choose three.)

Select 3 answers
A.By default, Cisco Catalyst switches trust the CoS value received from connected devices.
B.The 'mls qos trust cos' command configures the switch to trust the CoS marking on incoming packets.
C.The trust boundary can be extended to an IP phone using CDP, allowing the phone to mark traffic.
D.Marking at Layer 2 uses DSCP values in the IP header.
E.A switch can re-mark packets by using a policy map with the 'set' command applied to an interface.
AnswersB, C, E

Correct because this command sets the trust state to CoS on a switch port.

Why this answer

The trust boundary defines where the device trusts or re-marks QoS markings. Typically, the boundary is at the access layer switch. The 'mls qos trust' command sets trust.

By default, Cisco switches do not trust CoS or DSCP; they must be configured. Trust can be extended to IP phones via CDP. Marking can be done at Layer 2 (CoS) or Layer 3 (DSCP).

1262
MCQhard

A network automation engineer is using the ncclient Python library to retrieve configuration from a Cisco IOS XE device via NETCONF. The engineer sends a <get-config> RPC with a filter for the interface configuration. The device returns a large XML response, but the engineer only needs the interface description and IP address. Which NETCONF capability should the engineer use to filter the response to only the required data?

A.urn:ietf:params:netconf:capability:subtree:1.0
B.urn:ietf:params:netconf:capability:xpath:1.0
C.urn:ietf:params:netconf:capability:writable-running:1.0
D.urn:ietf:params:netconf:capability:rollback-on-error:1.0
AnswerA

The subtree filtering capability allows the client to specify a filter that selects only the desired subtrees of the configuration data. By using a subtree filter, the engineer can request only the interface description and IP address, reducing the response size and processing. This is the standard way to filter NETCONF responses.

Why this answer

NETCONF supports filtering of configuration data through capabilities. The subtree filtering capability allows a client to specify a filter that matches only the desired portions of the configuration tree. By using a subtree filter, the engineer can retrieve only the interface description and IP address, minimizing the response size and improving efficiency.

Other capabilities like writable-running or rollback-on-error do not provide filtering.

Exam trap

The trap here is confusing filtering capabilities with other NETCONF capabilities that deal with write operations or error handling, such as writable-running or rollback-on-error.

1263
Matchingmedium

Drag and drop each infrastructure hardening technique on the left to its matching configuration command on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

interface range GigabitEthernet0/1-24 ; shutdown

banner login ^C Authorized access only ^C

ip ssh version 2

no cdp run

service password-encryption

Why these pairings

Disable unused ports with 'interface range ... shutdown'; set login banner with 'banner login'; enable SSH with 'ip ssh version 2'; disable CDP with 'no cdp run'; set password encryption with 'service password-encryption'.

1264
Drag & Dropmedium

Drag and drop the steps of OpenConfig interface counters subscription and decode into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The process begins by subscribing to the OpenConfig path, receiving the encoded data, decoding it using the YANG model, extracting counters, and then analyzing the results.

1265
MCQmedium

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS-XE router that also runs OSPF, BGP, and SSH management. The engineer needs to protect the control plane while ensuring that routing protocol traffic and management sessions are not disrupted. Which CoPP design approach best meets these requirements?

A.Configure a CoPP policy that only rate-limits ICMP and Telnet, leaving all other control plane traffic unclassified and unpolished.
B.Apply a single CoPP policy that classifies all control plane traffic into one class and rate-limits it to a conservative value.
C.Apply the CoPP policy to all data plane interfaces in the inbound direction, which will indirectly protect the control plane.
D.Create multiple granular classes (for example, routing protocols, management, and exception traffic) and apply class-specific policers, while ensuring control plane traffic is not dropped by the default class.
AnswerD

Granular classification lets the engineer allocate adequate bandwidth to OSPF, BGP, and SSH while policing less critical or malicious traffic more aggressively. The default class should be configured to not drop, or to drop only after all classified traffic is serviced, so that unclassified but legitimate control plane packets are not silently discarded and routing or management sessions remain stable.

Why this answer

CoPP protects the route processor by classifying and policing traffic destined to the control plane. Granular classes allow routing protocols and management traffic to receive enough bandwidth, while the default class should be configured not to drop so that legitimate unclassified traffic survives. This design balances protection with operational stability for OSPF, BGP, and SSH.

Exam trap

The trap here is assuming a single conservative CoPP policer is sufficient, when it actually throttles legitimate routing and management traffic along with attacks.

1266
Drag & Dropmedium

Drag and drop the steps of SPAN session on EtherChannel member ports into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

SPAN on EtherChannel requires configuring the session, specifying source ports (member or port-channel), setting destination, and enabling.

1267
MCQeasy

A network engineer is configuring a Cisco CSR 1000v router in a virtualized environment. The engineer needs to ensure that the router can forward traffic between multiple virtual routing and forwarding (VRF) instances while maintaining isolation. Which technology should the engineer use to allow communication between specific VRFs?

A.VRF leaking
B.Policy-based routing
C.VLAN trunking
D.GRE tunneling
AnswerA

VRF leaking allows routes to be selectively imported and exported between VRF instances, enabling controlled communication while maintaining isolation for other traffic. This is the standard method to allow specific inter-VRF communication on Cisco IOS-XE routers without merging the routing tables entirely.

Why this answer

VRF leaking is the correct technology because it allows specific routes to be imported from one VRF into another, enabling controlled communication while preserving isolation. This is typically done using route targets and route maps. Other options like GRE tunneling or policy-based routing can be used in specific cases but are not the standard method for inter-VRF communication on a single router.

Exam trap

The trap here is thinking that any tunneling or routing policy can enable inter-VRF communication, when VRF leaking is the specific and standard feature designed for this purpose.

1268
Drag & Dropmedium

Drag and drop the steps of IP SLA HTTP operation for application monitoring into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, the HTTP operation is defined with the target URL. Then optional parameters like HTTP method or version are set. The operation is configured to monitor HTTP response.

Next, the operation is scheduled. Finally, verification is done to confirm the operation is active.

1269
Matchingmedium

Match each Cisco switch security feature to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Limits MAC addresses on a port

Filters untrusted DHCP messages

Validates ARP packets

Prevents IP spoofing

Limits broadcast/multicast traffic

Why these pairings

Port Security limits MAC addresses per port to prevent MAC flooding. DHCP Snooping filters DHCP messages to block rogue servers. Dynamic ARP Inspection validates ARP packets using DHCP snooping entries to prevent spoofing.

IP Source Guard filters IP traffic based on the binding table to prevent IP spoofing. Common confusions include swapping these functions, e.g., assigning ARP spoofing prevention to Port Security or MAC flooding prevention to DHCP Snooping.

1270
MCQeasy

A network administrator is hardening a Cisco IOS switch that connects to user workstations. The security policy requires that when an unauthorized MAC address appears on an access port, the port must drop only the offending frames, generate a syslog message, and increment a counter, without shutting down the port or requiring administrative intervention. Which port security violation mode meets these requirements?

A.restrict
B.shutdown
C.protect
D.drop-and-log
AnswerA

Restrict mode drops the offending frames, sends a syslog message, and increments the violation counter, while keeping the port up. This matches every requirement: no shutdown, no admin intervention, and full auditing. It is the standard choice when visibility into violations is needed without disrupting the port.

Why this answer

Port security offers three violation modes. Restrict drops unauthorized frames while sending SNMP traps, syslog messages, and incrementing the violation counter, and it leaves the port operational. Because the policy forbids err-disable and requires logging plus counters, restrict is the only mode that satisfies all conditions simultaneously.

Exam trap

The trap here is confusing protect with restrict, forgetting that only restrict generates syslog messages and increments the violation counter.

1271
MCQeasy

A network engineer is configuring a Cisco SD-WAN solution for a multinational corporation. The engineer wants to use a centralized data policy to steer all traffic from the Finance department (VPN 10) to a specific WAN link (MPLS) for security reasons. The engineer creates a policy that matches traffic from VPN 10 and sets the preferred color to 'mpls'. After applying the policy, the engineer tests and finds that traffic from VPN 10 is still using the Internet link. The vEdge routers show that the policy is received and active. What is the most likely reason?

A.The vEdge routers have not rebooted after the policy was applied.
B.The policy is not attached to the correct site list or VPN list.
C.The data policy was applied on the vEdge instead of the vSmart.
D.The preferred color is not configured correctly in the policy.
AnswerB

A centralized data policy must be explicitly attached to a site list and a VPN list to define where it is enforced. If the policy is attached to the wrong site list (or wrong VPN list), vSmart may still distribute it, but the vEdge routers in the intended sites will never apply it to the relevant traffic. This is exactly the kind of configuration error that lets a policy appear present yet have no effect.

Why this answer

The most likely reason is that the centralized data policy was not attached to the correct site list or VPN list. In Cisco SD-WAN, a centralized data policy must be explicitly associated with the sites (via site list) and VPNs (via VPN list) where it should be applied. Even if the policy is received and active on the vEdge routers, without proper attachment to the VPN 10 site list, the policy will not enforce the preferred color 'mpls' for Finance traffic, leaving it to use the default Internet link.

Exam trap

Cisco often tests the distinction between policy definition and policy attachment, where candidates assume that simply creating and applying a policy globally is sufficient, but the policy must be explicitly linked to the correct site list and VPN list to take effect.

How to eliminate wrong answers

Option A is wrong because vEdge routers do not require a reboot for centralized data policies to take effect; policies are applied dynamically via the vSmart controller. Option C is wrong because centralized data policies are designed to be applied on the vSmart controller, not directly on the vEdge; applying on the vEdge would be a local policy, which is a different mechanism. Option D is wrong because the preferred color 'mpls' is a valid configuration in a centralized data policy; the issue is not with the color value but with the policy attachment scope.

1272
MCQhard

A network engineer is implementing Cisco TrustSec in a campus network. The security team wants to assign a security group tag to traffic based on the identity of the user authenticated via 802.1X, and then enforce policy based on that tag in the data center. Which Cisco TrustSec component is responsible for classifying the traffic with the appropriate security group tag at the access layer?

A.Identity Services Engine (ISE) as the policy server combined with the access switch enforcing the authorization result
B.Security Group ACLs (SGACLs) on the destination device
C.Security Group Tag Exchange Protocol (SXP)
D.MACsec encryption on the uplink between access and distribution switches
AnswerA

In Cisco TrustSec, ISE authenticates the user via 802.1X and returns an authorization result that includes the SGT. The access switch enforces that result by tagging the user's traffic with the assigned SGT. This classification at the access layer is what allows downstream devices to enforce group-based policies. ISE provides the identity-to-SGT mapping, and the switch applies it.

Why this answer

Cisco TrustSec classification begins with authentication. ISE authenticates the user and returns an authorization profile containing the SGT, and the access switch applies that tag to the user's traffic. This inline tagging at the access layer allows enforcement devices to apply group-based policies.

SXP propagates mappings, SGACLs enforce policy, and MACsec protects links, but none of them assign the tag based on identity.

Exam trap

The trap here is confusing the propagation of SGT mappings via SXP or the enforcement via SGACLs with the actual classification step, which happens on the access device using the ISE authorization result.

1273
MCQhard

An engineer is using the Cisco pyATS framework to test the configuration of a new QoS policy on a router. The engineer writes a testbed file and a test script that logs into the router, applies the configuration, and then verifies the output of 'show policy-map interface'. The test script fails because the verification step cannot find the expected output. The engineer confirms that the configuration was applied successfully. What is the most likely cause of the failure?

A.The pyATS library requires Python 3.8 or later, and the engineer is using an older version.
B.The testbed file has incorrect credentials for the router.
C.The test script does not include a sleep or wait mechanism after applying the configuration.
D.The test script uses the 'genie' library instead of 'pyats' for parsing.
AnswerC

When a QoS policy is applied on a Cisco IOS-XE device, the operational output—such as 'show policy-map interface'—does not update instantly; the device takes a short period to propagate the configuration into its internal data structures and hardware abstraction layer. The test script pushes the configuration and immediately parses the output without any sleep, wait, or polling loop, so the verification runs before the policy is fully reflected. Adding a delay (for example, 'time.sleep(5)' or a Genie 'learn' with a 'sleep' argument) or implementing a retry loop would give the device time to converge and allow the test to pass.

Why this answer

After applying a QoS policy with the `service-policy` command, the router may take a short time to update the operational state shown in `show policy-map interface`. Without an explicit sleep or wait mechanism in the pyATS test script, the verification step executes before the router has processed and reflected the new policy, causing a mismatch even though the configuration was applied successfully.

Exam trap

Cisco often tests the misconception that CLI configuration changes are reflected immediately in show commands, when in reality there is often a brief propagation delay that automation scripts must account for with a wait mechanism.

How to eliminate wrong answers

Option A is wrong because pyATS supports Python 3.6 and later, and the question does not indicate any Python version incompatibility; the failure is not related to Python version requirements. Option B is wrong because the engineer confirmed the configuration was applied successfully, which means the testbed file credentials were correct and the login step succeeded. Option D is wrong because the 'genie' library is actually the parsing library that works with pyATS, not a separate framework; using 'genie' for parsing is standard and would not cause the verification to fail to find expected output.

1274
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip pim neighbor PIM Neighbor Table Neighbor Address Interface Uptime Expires Mode 10.1.1.2 GigabitEthernet0/0 2w0d 00:01:25 DR 10.1.1.3 GigabitEthernet0/0 2w0d 00:01:20 B Based on this output, what can be concluded?

A.PIM sparse mode is operating on this interface.
B.PIM Bidir mode is configured on this interface.
C.PIM dense mode is in use on this interface.
D.PIM SSM is enabled on this interface.
AnswerB

The Mode field displays 'B', which is the Cisco IOS indicator for Bidir-PIM. Bidir mode requires a DR election on multi-access networks to forward multicast traffic toward the RP, and here the DR flag is present, confirming that the interface is participating in that election. Since the B flag is specifically reserved for Bidir operation and is not used by any other PIM mode, this is the correct match.

Why this answer

The output shows PIM neighbor modes of 'DR' and 'B'. In PIM Bidir mode, the Designated Router (DR) is elected to forward traffic upstream, and the 'B' flag indicates a Bidir-capable neighbor. This mode is explicitly identified by the 'B' flag in the PIM neighbor table, which is not present in sparse or dense mode.

Therefore, the interface is operating in PIM Bidir mode.

Exam trap

Cisco often tests the meaning of the 'B' flag in the 'show ip pim neighbor' output, and candidates mistakenly associate it with 'Bootstrap Router' or 'Backup' instead of 'Bidir'.

How to eliminate wrong answers

Option A is wrong because PIM sparse mode does not display a 'B' flag in the neighbor table; sparse mode neighbors show only 'DR' or no flag. Option C is wrong because PIM dense mode uses flood-and-prune behavior and does not have a 'B' flag; its neighbor table would not show 'B' mode. Option D is wrong because PIM SSM (Source-Specific Multicast) relies on IGMPv3 and does not use PIM neighbor flags like 'B'; SSM does not involve a Bidir flag.

1275
Drag & Dropmedium

Drag and drop the steps of CoPP class-map match criteria and rate-limit application into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

CoPP configuration requires defining class-maps first, then policy-map with police statements, then applying to control-plane. The order ensures proper traffic classification and rate-limiting.

Page 16

Page 17 of 26

Page 18