Courseiva

ENCOR 350-401 (350-401) — Questions 1276–1350

1923 questions total · 26pages · All types, answers revealed

Page 17

Page 18 of 26

Page 19
1276
Multi-Selectmedium

Which two statements about SD-WAN control plane components are true? (Choose two.)

Select 2 answers
A.The vSmart controller is responsible for distributing OMP routes and policies to all edge devices in the SD-WAN fabric.
B.The vBond orchestrator is responsible for authenticating and onboarding vEdge and cEdge routers into the SD-WAN overlay.
C.The vManage controller is the primary control plane component that establishes OMP sessions with all edge routers.
D.vEdge and cEdge routers are both control plane devices that participate in OMP route exchange.
E.The OMP protocol runs between vManage and vSmart to exchange routing information and policy updates.
AnswersA, B

The vSmart controller holds the centralised control plane: it peers with every edge device over DTLS and advertises OMP routes, policies and TLOCs, so edges never need full-mesh routing adjacencies. This satisfies the stem's requirement for a true control plane component statement.

Why this answer

Option A is correct because the vSmart controller is the centralized control plane component in Cisco SD-WAN that runs OMP and distributes OMP routes, TLOCs, and policies to all vEdge and cEdge devices in the fabric. Option B is correct because the vBond orchestrator handles authentication and initial onboarding of edge devices, validating their certificates and providing the vManage and vSmart information needed to join the overlay. Option C is incorrect because vManage is the management plane (GUI, API, configuration), not the control plane, and it does not establish OMP sessions with edge routers.

Option D is incorrect because vEdge and cEdge routers are data plane/edge devices that participate in OMP as clients, not control plane devices. Option E is incorrect because OMP runs between vSmart and the edge devices (and between vSmarts), not between vManage and vSmart.

Exam trap

The trap here is confusing the management plane (vManage) with the control plane (vSmart), and assuming edge routers are control plane devices because they run OMP.

1277
MCQhard

A network engineer is configuring a Cisco IOS router to authenticate OSPF neighbors using MD5. The engineer enters the following commands under the OSPF process: area 0 authentication message-digest, and under the interface: ip ospf message-digest-key 1 md5 Cisco123. However, the neighbor relationship does not form. What is the most likely cause?

A.The area authentication command must be configured on all routers in the area, but the interface command is optional.
B.The key ID must match on both routers, but the key string can be different.
C.The key ID and key string must match on both routers, and the area authentication command must be consistent.
D.The router must be reloaded for the MD5 key to take effect.
AnswerC

For OSPF MD5 authentication to succeed, both routers must have the same key ID, the same key string, and the same authentication type configured for the area or interface. The area authentication command enables MD5 for the area, and the interface command provides the key. If any of these parameters differ, the neighbor relationship will not form.

Why this answer

OSPF MD5 authentication requires consistent configuration on both neighbors: the same key ID, the same key string, and the same authentication mode (area or interface). The area authentication command enables MD5 for the area, and the interface command provides the key. If any of these differ, OSPF authentication fails, and the routers will not become adjacent.

Exam trap

The trap here is assuming that only the key string matters, when in fact the key ID and the area authentication mode must also match.

1278
Drag & Dropmedium

Drag and drop the steps of IP SLA DNS lookup operation setup into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, define the IP SLA operation with type dns. Then specify the target DNS server and the domain name to resolve. Optionally set the DNS source interface or timeout.

Next, schedule the operation. Finally, verify the DNS resolution success and response time.

1279
MCQeasy

A network administrator is introducing infrastructure as code for Cisco IOS XE switches. The team wants to store device configurations in a version-controlled repository and apply changes only after peer review. They need a tool that can enforce the desired state and report drift without making changes during the review phase. Which tool should they use to meet these requirements?

A.SNMP polling with a custom monitoring dashboard
B.Cisco Network Services Orchestrator (NSO) with commit queues
C.Ansible with the ios_config module in check mode
D.Python script using Netmiko to push configuration commands directly
AnswerC

Ansible's check mode (--check) allows the playbook to run without applying changes, reporting what would be modified. This supports peer review and drift detection. The ios_config module can compare the running configuration against the desired lines and indicate differences. This aligns with infrastructure as code principles by enabling safe validation before actual deployment, making it the correct choice.

Why this answer

Ansible's check mode allows the playbook to simulate changes and report drift without modifying the device. This supports peer review and infrastructure as code by validating the desired state before applying. The other tools either lack built-in dry-run capabilities or are not designed for configuration review workflows.

Exam trap

The trap here is assuming that any automation tool can perform dry runs, when in fact only some tools like Ansible have explicit check mode support.

1280
MCQmedium

A network architect is designing a data center fabric that must support Layer 2 extension over a Layer 3 underlay while using a control-plane protocol that advertises MAC reachability. The design requires the use of a protocol that encapsulates Layer 2 frames in IP packets and uses an EVPN address family for MAC/IP advertisement. Which technology best meets these requirements?

A.VXLAN with BGP EVPN control plane
B.OTV with IS-IS as the control plane
C.LISP with a Map-Server/Map-Resolver
D.MPLS L2VPN with BGP for label distribution
AnswerA

VXLAN provides Layer 2 extension over a Layer 3 underlay by encapsulating Ethernet frames in UDP/IP. BGP EVPN is used as the control plane to advertise MAC and IP reachability, enabling efficient forwarding and multi-tenancy. This matches the requirement for a protocol that encapsulates Layer 2 frames in IP and uses EVPN for MAC/IP advertisement.

Why this answer

VXLAN with BGP EVPN is the correct choice because it encapsulates Layer 2 frames in UDP/IP and uses BGP EVPN as the control plane to advertise MAC and IP reachability. This provides a scalable and efficient solution for Layer 2 extension over a Layer 3 underlay, meeting the design requirements for a data center fabric.

Exam trap

The trap here is assuming that any Layer 2 extension technology uses BGP EVPN for MAC advertisement, overlooking that OTV and MPLS L2VPN use different control planes.

1281
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor a campus network. The administrator notices that a particular client device is experiencing poor performance. The administrator wants to see detailed information about the client's connectivity, including the path taken through the network and any issues encountered. Which Cisco DNA Center Assurance feature should the administrator use?

A.Application Health dashboard
B.Path Trace
C.Network Health dashboard
D.Client 360
AnswerD

Client 360 provides a comprehensive view of a specific client's experience, including onboarding, connectivity, and application performance. It shows the path taken through the network, including switches and access points, and highlights issues like onboarding failures or poor signal quality. This is the ideal tool for troubleshooting individual client performance.

Why this answer

Client 360 in Cisco DNA Center Assurance offers a detailed, client-centric view that includes onboarding, connectivity, and application experience. It displays the network path taken by the client and any issues encountered, such as authentication failures or roaming problems. This makes it the appropriate feature for troubleshooting a specific client's performance.

Exam trap

The trap here is confusing Path Trace with Client 360; Path Trace is for on-demand path simulation, while Client 360 provides ongoing client monitoring.

1282
MCQhard

A network engineer runs the following command on Router R1: R1# show ip eigrp neighbors detail EIGRP-IPv4 Neighbors for AS(100) H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 192.168.1.2 Gi0/0 13 00:12:34 12 100 0 45 Version 2.0/2.0, Retrans: 0, Retry: 0, Maxseq: 0 Prefixes: 3 Topology ids: 0 Authentication: None Topology: base (0x0) Based on this output, what can be concluded?

A.The neighbor is using EIGRP version 1.
B.The neighbor has advertised 3 prefixes to R1.
C.There is a high number of retransmissions indicating packet loss.
D.The neighbor is using MD5 authentication.
AnswerB

The 'Prefixes: 3' field in the neighbour detail output reports the number of prefixes the neighbour has advertised to this router. It reflects inbound advertisements from that EIGRP neighbour, not routes R1 itself is advertising.

Why this answer

The output shows 'Prefixes: 3' under the neighbor details, which indicates that the neighbor has advertised exactly three prefixes to R1. This is a direct interpretation of the 'show ip eigrp neighbors detail' command, where the 'Prefixes' field lists the number of routes learned from that neighbor.

Exam trap

Cisco often tests the ability to read the 'show ip eigrp neighbors detail' output carefully, where candidates may confuse the 'Prefixes' field with the number of interfaces or ignore the 'Retrans' and 'Authentication' fields, leading them to select incorrect options based on assumptions rather than the explicit data shown.

How to eliminate wrong answers

Option A is wrong because the output shows 'Version 2.0/2.0', meaning both R1 and the neighbor are running EIGRP version 2, not version 1. Option C is wrong because the 'Retrans: 0' and 'Retry: 0' fields indicate zero retransmissions and retries, which means no packet loss is occurring. Option D is wrong because the output explicitly states 'Authentication: None', so MD5 authentication is not configured.

1283
MCQmedium

A company is deploying a new data center and needs to choose between a three-tier (core, aggregation, access) and a spine-leaf architecture. The network engineer is concerned about east-west traffic patterns for server virtualization. Which architecture is most suitable and why?

A.Spine-leaf, because it provides equal-cost multipath (ECMP) for all leaf-to-leaf traffic.
B.Three-tier, because it offers more redundancy with multiple aggregation layers.
C.Spine-leaf, because it supports legacy spanning tree protocols.
D.Three-tier, because it is easier to manage with traditional VLANs.
AnswerA

Spine-leaf is correct because it structurally guarantees equal-cost multipath (ECMP) between any pair of leaf switches: every leaf is exactly one hop from every spine, so all available spine-to-spine links are equally weighted. This allows flow-level load balancing across all spine links simultaneously, maximizing bisectional bandwidth for east-west traffic. Unlike three-tier designs that rely on spanning-tree-computed forwarding paths, spine-leaf leverages Layer 3 ECMP, which also ensures consistent low latency and no idle redundancy links.

Why this answer

Spine-leaf architecture is most suitable for east-west traffic patterns because it provides a full mesh of connections between leaf switches and spine switches, enabling equal-cost multipath (ECMP) routing. This allows all leaf-to-leaf traffic to traverse multiple parallel paths with equal cost, maximizing bandwidth utilization and minimizing latency, which is critical for server virtualization traffic that often moves between hypervisors.

Exam trap

Cisco often tests the misconception that three-tier architecture is more redundant or easier to manage, but the key trap here is that candidates may overlook how east-west traffic patterns require non-blocking, low-latency paths that only a spine-leaf design with ECMP can provide.

How to eliminate wrong answers

Option B is wrong because three-tier architecture introduces a bottleneck at the aggregation layer for east-west traffic, as traffic between access switches must traverse the aggregation layer, which does not provide the same level of ECMP as spine-leaf. Option C is wrong because spine-leaf architecture does not support legacy spanning tree protocols; in fact, it relies on routing protocols like OSPF or BGP to avoid STP, and STP would block redundant links in a spine-leaf design. Option D is wrong because three-tier architecture is not easier to manage with traditional VLANs for east-west traffic; VLANs in a three-tier design often require complex STP configurations and can lead to suboptimal traffic flows, whereas spine-leaf simplifies VLAN management with VXLAN or EVPN overlays.

1284
Multi-Selectmedium

A network engineer is configuring a GRE tunnel between two Cisco IOS routers to transport multicast traffic over an IP network that does not support multicast. The engineer must ensure the tunnel is operational and multicast is forwarded correctly. Which two statements are true about GRE tunnel configuration and operation? (Choose two.)

Select 2 answers
A.The tunnel interface must be configured with the 'tunnel mode gre multipoint' command to support multicast.
B.The tunnel interface must be configured with an IP address from the same subnet as the physical interface.
C.GRE tunnels automatically encrypt all traffic, so no additional security configuration is required.
D.Multicast routing must be enabled on the tunnel interface and the underlying physical interface.
E.The tunnel source and destination must be reachable via the underlay routing table.
AnswersD, E

To forward multicast traffic over a GRE tunnel, multicast routing must be enabled on both the tunnel interface and the physical interface that carries the tunnel. The tunnel interface must be included in the multicast routing configuration (e.g., 'ip pim sparse-mode'). Otherwise, multicast packets will not be forwarded into or out of the tunnel.

Why this answer

A GRE tunnel requires that the tunnel source and destination be reachable via the underlay. Additionally, to carry multicast, multicast routing must be enabled on both the tunnel and the physical interface. These two conditions ensure the tunnel is up and multicast is forwarded.

The other options describe incorrect or unnecessary configurations.

Exam trap

The trap here is assuming GRE provides encryption or that multipoint mode is needed for multicast, when point-to-point GRE can carry multicast if multicast routing is enabled.

1285
MCQhard

A network engineer is troubleshooting an STP issue in a network that uses Rapid PVST+. The network has a root bridge (SW1) and a secondary root bridge (SW2). The engineer notices that after a link failure between SW1 and SW2, the network takes longer than expected to converge. The engineer checks the configuration and finds that SW2 has the 'spanning-tree uplinkfast' command enabled. The engineer also notices that SW2 has a lower priority than SW1. What is the most likely cause of the slow convergence?

A.UplinkFast is enabled, which is incompatible with Rapid PVST+ and causes the switch to use legacy STP convergence.
B.SW2 has a lower priority than SW1, so it takes longer to become the root bridge after failure.
C.BPDU Guard is enabled on the uplink ports, which prevents BPDU exchange.
D.Loop Guard is enabled on the uplink ports, which delays port transition.
AnswerA

Correct because UplinkFast is a proprietary Cisco feature designed for legacy 802.1D PVST+ to quickly fail over to a precomputed alternate root port when the primary uplink fails. However, UplinkFast is mutually exclusive with Rapid PVST+/RSTP, and when enabled it forces the switch to fall back to the classic Spanning Tree Protocol algorithm. That legacy mode relies on Max Age (20 seconds) and Forward Delay (15 seconds) timers, so after a root port failure the switch takes 30–50 seconds to converge instead of milliseconds, matching the behavior described.

Why this answer

UplinkFast is a legacy STP feature that is incompatible with Rapid PVST+. When enabled on a switch running Rapid PVST+, it forces the switch to revert to 802.1D STP convergence behavior on the affected ports, disabling the rapid transition mechanisms (such as proposal/agreement and sync). This causes the network to take longer to converge after a link failure, as the switch falls back to the slower listening and learning states.

Exam trap

Cisco often tests the misconception that UplinkFast is a harmless optimization that can be combined with Rapid PVST+, when in fact it forces a fallback to legacy STP behavior, causing slow convergence.

How to eliminate wrong answers

Option B is wrong because SW2 having a lower priority than SW1 means SW2 is less likely to become the root bridge; after a failure, the switch with the lowest priority becomes root, so a lower priority (higher numerical value) does not cause slower convergence. Option C is wrong because BPDU Guard would disable a port upon receiving a BPDU, preventing BPDU exchange entirely, which would cause a different failure mode (port errdisable) rather than slow convergence. Option D is wrong because Loop Guard prevents alternate/backup ports from transitioning to forwarding when BPDUs stop, which can cause a blocking state but does not inherently delay port transition in a way that explains longer-than-expected convergence after a link failure.

1286
Drag & Dropmedium

Drag and drop the steps of QoS policing with two-rate three-color marker (RFC 2698) into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

RFC 2698 two-rate three-color marker uses committed and peak token buckets. The correct order is: first check the committed bucket (A). If tokens are available, mark the packet green (B).

If not, check the peak bucket (C). If tokens are available, mark the packet yellow (D). If no tokens are available, mark the packet red and drop (E).

This sequence ensures proper conformance classification.

1287
MCQmedium

An enterprise is deploying a virtual router (vRouter) as part of its NFV infrastructure. The engineer needs to ensure that the vRouter can handle a sudden spike in traffic without dropping packets. The vRouter is running on a KVM hypervisor. What should the engineer configure to guarantee CPU resources for the vRouter during peak demand?

A.Enable memory ballooning on the vRouter VM.
B.Configure CPU pinning and CPU reservation for the vRouter VM.
C.Enable DPDK on the vRouter's virtual NICs.
D.Set the vRouter VM to use NUMA node pinning.
AnswerB

CPU pinning binds the vRouter's vCPUs to dedicated physical cores, and CPU reservation guarantees those cycles are not reclaimed by other VMs. Together they prevent the hypervisor scheduler from starving the vRouter during traffic spikes, avoiding packet drops.

Why this answer

CPU pinning binds the vRouter's virtual CPUs to specific physical cores, preventing other processes from using them, while CPU reservation guarantees a minimum amount of CPU capacity. Together, they ensure deterministic CPU availability during traffic spikes, preventing packet drops due to resource contention on the KVM hypervisor.

Exam trap

Cisco often tests the distinction between resource optimization (DPDK, NUMA) and resource guarantee (pinning, reservation), leading candidates to pick DPDK because it is associated with high performance, even though it does not guarantee CPU availability under contention.

How to eliminate wrong answers

Option A is wrong because memory ballooning adjusts VM memory dynamically, not CPU resources, and can actually degrade performance by reclaiming memory under pressure. Option C is wrong because DPDK accelerates packet processing by bypassing the kernel network stack, but it does not guarantee CPU resources; it requires CPU isolation (like pinning) to work effectively. Option D is wrong because NUMA node pinning optimizes memory locality and latency but does not guarantee CPU capacity; it is a topology-aware placement, not a resource reservation mechanism.

1288
Multi-Selectmedium

A network engineer is implementing 802.1X authentication on a Cisco switch. The engineer wants to ensure that the switch dynamically assigns a VLAN to the port based on the user's identity, and that the VLAN assignment is enforced by the authentication server. Which two components are required to achieve this? (Choose two.)

Select 2 answers
A.Enable MACsec on the switch port to encrypt the authentication exchange.
B.Enable DHCP snooping on the switch to validate the user's IP address.
C.Configure the authentication server to return the appropriate RADIUS attributes, such as Tunnel-Type and Tunnel-Private-Group-ID.
D.Configure the switch to use RADIUS for authentication and authorization.
E.Configure the switch port as a trunk port to allow multiple VLANs.
AnswersC, D

For dynamic VLAN assignment, the RADIUS server must send specific attributes in the Access-Accept message: Tunnel-Type (VLAN), Tunnel-Medium-Type (802), and Tunnel-Private-Group-ID (the VLAN ID). These attributes tell the switch which VLAN to assign to the port. Without these attributes, the switch cannot dynamically place the user into the correct VLAN.

Why this answer

Dynamic VLAN assignment requires the switch to authenticate users via RADIUS and receive VLAN information from the RADIUS server. The server must return the appropriate tunnel attributes (Tunnel-Type, Tunnel-Medium-Type, Tunnel-Private-Group-ID) in the Access-Accept message. These two components together allow the switch to place the user into the correct VLAN automatically.

Exam trap

The trap here is assuming that any security feature like MACsec or DHCP snooping contributes to dynamic VLAN assignment, when only RADIUS and its attributes are relevant.

1289
Multi-Selecthard

Which two statements about IP Source Guard are true? (Choose two.)

Select 2 answers
A.IP Source Guard uses the DHCP snooping binding table to validate the source IP address of packets received on a port.
B.IP Source Guard can be configured with port security to provide additional MAC address filtering.
C.IP Source Guard only works with DHCP-assigned IP addresses, not static IP addresses.
D.IP Source Guard filters traffic based on the destination MAC address.
E.IP Source Guard requires 802.1X authentication to be enabled on the port.
AnswersA, B

IP Source Guard permits traffic only when the packet's source IP matches an entry in the DHCP snooping binding table for that port, dropping spoofed addresses. This binds source IP to switch port and MAC.

Why this answer

Option A is correct because IP Source Guard (IPSG) relies on the DHCP snooping binding table (and optionally static IP source bindings) to check that the source IP address of frames arriving on an untrusted port matches an entry, dropping spoofed traffic. Option B is correct because IPSG is often deployed together with port security: port security validates source MAC addresses while IPSG validates source IP addresses, giving combined Layer 2/Layer 3 source filtering. Option C is wrong because IPSG also supports manually configured static IP source bindings via the 'ip source binding' command, so it is not limited to DHCP-assigned addresses.

Option D is wrong because IPSG inspects the source IP address (and source MAC), not the destination MAC address. Option E is wrong because IPSG does not require 802.1X; it depends on DHCP snooping or static bindings, and 802.1X is an independent access-control feature.

Exam trap

The trap is assuming IPSG only works with DHCP and cannot handle static IPs, or confusing it with DAI/port security; candidates may also think IPSG filters destination MAC, which is wrong.

1290
Drag & Dropmedium

Drag and drop the steps of micro-segmentation via SGT policy application into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Micro-segmentation starts with classifying endpoints into SGTs based on identity, then defining SGT-to-SGT policies (permit/deny). The policies are enforced at the fabric edge, where the SGT is propagated in the VXLAN header, and traffic is filtered accordingly. Finally, monitoring ensures compliance.

1291
MCQeasy

A network engineer is configuring BGP on a router that will be used for BGP route summarization. The router receives multiple more-specific prefixes from its eBGP peers. The engineer wants to advertise a summary route to the iBGP peers without advertising the more-specific routes. Which command should the engineer use to suppress the more-specific routes while still installing them in the local routing table?

A.Use the 'aggregate-address' command with the 'summary-only' keyword.
B.Use the 'network' command to advertise the summary route.
C.Use the 'summary-address' command under the BGP address family.
D.Use the 'redistribute' command to inject the summary route into BGP.
AnswerA

The aggregate-address command with the summary-only keyword creates an aggregate route in the BGP table and, crucially, suppresses advertising all more-specific component routes to BGP neighbors. This reduces route-table size and the number of BGP updates while still ensuring reachability via the aggregate. Without summary-only, the aggregate is advertised alongside the specific routes, so the explicit summary-only keyword is required to achieve full suppression.

Why this answer

The 'aggregate-address' command with the 'summary-only' keyword in BGP creates a summary route from more-specific prefixes and suppresses the advertisement of those more-specific routes to BGP peers, while still keeping them in the local routing table. This meets the requirement of advertising only the summary to iBGP peers without removing the more-specific routes from the router's own RIB.

Exam trap

Cisco often tests the distinction between suppressing routes from advertisement versus removing them from the local table, and candidates mistakenly think 'summary-only' removes the more-specific routes from the router, but it only suppresses their advertisement to BGP peers.

How to eliminate wrong answers

Option B is wrong because the 'network' command advertises a prefix only if it exists exactly in the routing table; it does not suppress more-specific routes or create an aggregate from them. Option C is wrong because 'summary-address' is not a valid BGP command; the correct command for BGP summarization is 'aggregate-address'. Option D is wrong because 'redistribute' injects routes from another protocol into BGP but does not create a summary or suppress more-specific prefixes; it would advertise all redistributed routes, including the more-specific ones.

1292
MCQmedium

A network engineer is deploying a VXLAN EVPN fabric on Cisco Nexus 9000 switches. The design requires that all VTEPs in the fabric learn the IP addresses of remote VTEPs so that BUM traffic can be replicated using ingress replication. Which control-plane component is responsible for distributing this VTEP IP address information across the fabric?

A.The EVPN Type-3 route carrying the VTEP loopback address and VNI membership
B.The PIM Anycast-RP configuration on the spine switches
C.The EVPN Type-5 route carrying IP prefix reachability for the tenant VRF
D.The EVPN Type-2 route carrying MAC and IP address bindings for host endpoints
AnswerA

EVPN Type-3 (Inclusive Multicast Ethernet Tag) routes advertise the originating VTEP's loopback IP address along with the VNI and Ethernet tag information. Receiving VTEPs build an ingress replication list from these advertisements, allowing them to replicate broadcast, unknown-unicast, and multicast traffic to every remote VTEP in the same VNI. This is exactly the control-plane mechanism the design requires.

Why this answer

Ingress replication requires each VTEP to know the loopback IP address of every other VTEP participating in the same VNI. EVPN Type-3 Inclusive Multicast Ethernet Tag routes serve precisely this purpose, advertising the originating VTEP IP, VNI, and Ethernet tag. Type-2 handles host MAC/IP bindings, Type-5 handles IP prefix advertisement, and PIM belongs to multicast replication designs.

Exam trap

The trap here is assuming that any EVPN route type distributing reachability information also distributes VTEP addresses for replication, when only the Inclusive Multicast Ethernet Tag route does that job.

1293
MCQhard

A network engineer is developing a Python script that uses the requests library to send a RESTCONF PATCH request to a Cisco IOS XE device. The script includes the header 'Content-Type: application/yang-data+json' and sends a JSON payload to update the description of an interface. The device returns HTTP 400 Bad Request. Which is the most likely cause?

A.The PATCH method is not supported by RESTCONF; PUT should be used instead.
B.The Content-Type header should be 'application/json' instead of 'application/yang-data+json'.
C.The JSON payload is not formatted according to the YANG model structure for the interface description.
D.The device does not support RESTCONF and requires NETCONF for configuration changes.
AnswerC

RESTCONF requires the payload to conform to the YANG model. If the JSON structure does not match the expected hierarchy, such as missing the 'ietf-interfaces:interface' container or incorrect nesting, the device will reject it with HTTP 400. This is the most likely cause. The engineer must ensure the payload follows the YANG model exactly.

Why this answer

An HTTP 400 Bad Request from a RESTCONF PATCH typically indicates that the request body does not conform to the YANG model structure. The payload must be correctly nested according to the model, such as including the module name and proper containers. The Content-Type is correct for RESTCONF JSON.

The PATCH method is supported. Therefore, the most likely cause is a malformed JSON payload that violates the YANG model.

Exam trap

The trap here is assuming that any JSON is acceptable, when RESTCONF requires strict adherence to the YANG model structure.

1294
MCQmedium

A network engineer is using the ncclient Python library to send NETCONF RPCs to a Cisco IOS XE device. The engineer wants to lock the running configuration datastore before making changes to prevent other NETCONF sessions from modifying it concurrently. Which NETCONF operation should be used?

A.<lock> with <target><candidate/></target>
B.<commit> with <confirmed/>
C.<edit-config> with <default-operation>replace</default-operation>
D.<lock> with <target><running/></target>
AnswerD

The <lock> operation is used to lock a datastore, preventing other sessions from modifying it. The <target> element specifies which datastore to lock, in this case <running/>. This ensures exclusive access for the session. The lock must be released with <unlock> after changes are made. This is the correct operation to prevent concurrent modifications.

Why this answer

NETCONF provides a <lock> operation to lock a datastore, preventing other sessions from modifying it. The <target> element specifies the datastore to lock. On Cisco IOS XE, only the running datastore is supported, so the correct target is <running/>.

Locking ensures that no other NETCONF session can edit the configuration until the lock is released with <unlock>. This is essential for maintaining configuration integrity during automation.

Exam trap

The trap here is assuming that Cisco IOS XE supports the candidate datastore like some other vendors; IOS XE only supports the running datastore.

1295
MCQmedium

A network engineer issues the following command on Router R8: R8# show ip ospf neighbor detail Neighbor 1.1.1.1, interface address 192.168.1.1 In the area 0 via interface GigabitEthernet0/0 Neighbor priority is 1, State is FULL, 6 state changes DR is 192.168.1.2, BDR is 192.168.1.1 Options is 0x42 (L LSR LSRR L LSR) Dead timer due in 00:00:34 Neighbor is up for 00:12:45 Index 1/1/1, retransmission queue length 0, number of retransmission 0 First 0x0(0)/0x0(0)/0x0(0) Next 0x0(0)/0x0(0)/0x0(0) Last retransmission scan length is 0, last retransmission scan time is 0 msec Based on this output, what can be concluded?

A.Router 1.1.1.1 is the Designated Router on this segment.
B.Router 1.1.1.1 is the Backup Designated Router.
C.The neighbor state is 2WAY.
D.The dead timer is 40 seconds.
AnswerB

The neighbor entry shows that 1.1.1.1 has an interface address of 192.168.1.1 and is in the FULL state. On the same line, the BDR field lists 192.168.1.1, which means this neighbor occupies the Backup Designated Router role for this multi-access segment. Because the BDR is the router that takes over if the DR fails, and the output explicitly assigns that address to this router, it is correct to conclude that 1.1.1.1 is the BDR.

Why this answer

The output shows 'BDR is 192.168.1.1', which is the interface address of neighbor 1.1.1.1. This directly indicates that router 1.1.1.1 is the Backup Designated Router on this segment. The neighbor state is FULL, confirming adjacency is fully established.

Exam trap

Cisco often tests the distinction between the neighbor's Router ID (1.1.1.1) and its interface address (192.168.1.1), causing candidates to confuse which router is the DR or BDR based on the Router ID rather than the explicit DR/BDR fields.

How to eliminate wrong answers

Option A is wrong because the DR is 192.168.1.2, not 1.1.1.1; the neighbor's interface address is 192.168.1.1, which is the BDR. Option C is wrong because the neighbor state is explicitly shown as 'FULL', not 2WAY; 2WAY is a lower state before adjacency formation. Option D is wrong because the dead timer is shown as 00:00:34, which is 34 seconds remaining, not 40 seconds; the default dead interval is 40 seconds, but the timer counts down.

1296
MCQmedium

A company has a large network of 500 Cisco IOS XE routers and switches spread across multiple sites. The network team wants to automate the collection of interface statistics every hour and store them in a central database for historical analysis. The team has a Linux server with Python 3 and access to all devices via SSH with key-based authentication. They have written a Python script using Netmiko to connect to each device, run 'show interfaces', and parse the output to extract key metrics (e.g., input/output errors, packets per second). The script works correctly when tested on a small subset of devices, but when run against all 500 devices, it takes too long (over 2 hours) and sometimes fails due to SSH connection timeouts. The team needs to reduce the execution time and improve reliability. Which approach should they take?

A.Reduce the collection frequency to every 4 hours
B.Implement multiprocessing or multithreading in the Python script to connect to devices concurrently
C.Replace Netmiko with SNMP polling using the pysnmp library
D.Use Ansible playbooks instead of a custom Python script
AnswerB

Implementing multiprocessing or multithreading allows the Python script to open SSH sessions to multiple routers simultaneously, dividing the 500-device workload across parallel workers. This dramatically reduces total wall-clock time, because network latency and device response delays overlap rather than accumulate. Using a ThreadPoolExecutor or multiprocessing pool with appropriate concurrency limits (e.g., 20-50 workers) can bring total runtime well under the timeout while preserving Netmiko's robust CLI interactions.

Why this answer

The primary bottleneck is sequential SSH connections to 500 devices. By using Python's multiprocessing or multithreading (e.g., concurrent.futures.ThreadPoolExecutor), the script can open multiple SSH sessions in parallel, drastically reducing total wall-clock time. Netmiko itself is not the issue; the serial execution pattern causes the 2-hour runtime and timeouts, which concurrent connections resolve by overlapping I/O wait times.

Exam trap

Cisco often tests the misconception that switching protocols (SNMP) or tools (Ansible) automatically solves performance issues, when the real root cause is lack of concurrency in the execution model.

How to eliminate wrong answers

Option A is wrong because reducing collection frequency to every 4 hours does not solve the underlying performance or reliability problem; it merely masks the symptom by collecting data less often, which may miss hourly trends and still fail when run. Option C is wrong because replacing Netmiko with SNMP polling (pysnmp) introduces a different protocol (UDP-based, community strings) that may require re-engineering the parsing logic and does not inherently improve concurrency; the bottleneck is serial execution, not the library or protocol. Option D is wrong because using Ansible playbooks instead of a custom Python script does not automatically parallelize connections unless explicitly configured with a strategy like 'free' or 'mitogen', and Ansible's default linear strategy still serializes per-batch; the team already has a working script, so switching to Ansible adds complexity without guaranteeing speedup.

1297
MCQhard

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP. After applying a CoPP policy, BGP peering drops intermittently during route churn, but SSH and SNMP remain reachable. Which action should be taken to correct the issue while preserving control plane protection?

A.Increase the policer rate for the BGP class-map in the CoPP policy.
B.Change the BGP class-map match to include only SSH and SNMP traffic.
C.Remove the CoPP policy from the control plane and reapply it after convergence.
D.Disable BGP route churn by setting the BGP scanner interval to a higher value.
AnswerA

BGP peering drops during route churn because the policer for the BGP class is too aggressive and is dropping legitimate control plane traffic. Adjusting the rate for the BGP class preserves protection for other traffic while allowing BGP keepalives and updates to pass. SSH and SNMP are unaffected because their classes have separate policers, so the fix should target the BGP class specifically.

Why this answer

CoPP policers are applied per class, so a too-low rate for the BGP class causes legitimate BGP traffic to be dropped during churn while other classes remain unaffected. Raising the BGP policer rate restores BGP stability without removing control plane protection, whereas disabling CoPP or altering class-maps would either expose the router or misclassify traffic.

Exam trap

The trap here is assuming that CoPP failures require disabling the policy, when the correct fix is to tune the specific class policer that is dropping legitimate traffic.

1298
MCQmedium

Given the following CoPP configuration: class-map match-all COPP_ICMP match access-group name ICMP_ACL ! policy-map COPP_POLICY class COPP_ICMP police 8000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY What is the effect?

A.All ICMP traffic to the control plane is rate-limited to 8000 bps.
B.ICMP traffic is permitted unconditionally.
C.The policy is applied to all interfaces, not just the control plane.
D.The class-map is missing a match-all statement.
AnswerA

The correct interpretation is that the policy-map applies a police command to the class containing ICMP traffic destined for the control plane, setting a committed information rate (CIR) of 8000 bps. The conform-action transmit allows traffic within the rate, while the exceed-action drop causes any excess ICMP packets to be discarded, so the net effect is a hard rate limit on ICMP control-plane traffic.

Why this answer

The CoPP policy matches ICMP traffic via the class-map and applies a police rate of 8000 bps to the control plane. The 'conform-action transmit exceed-action drop' ensures that traffic within the rate is forwarded, while excess traffic is dropped, effectively rate-limiting ICMP to the control plane.

Exam trap

Cisco often tests the misconception that 'match-all' is required for class-maps with a single match condition, but it is optional and the configuration is valid; the trap here is that candidates think the class-map is missing a match-all statement, but it is explicitly present.

How to eliminate wrong answers

Option B is wrong because the policy explicitly polices ICMP traffic to 8000 bps, not permitting it unconditionally; exceeding the rate results in drops. Option C is wrong because the 'service-policy input COPP_POLICY' is applied under the 'control-plane' configuration, which only affects traffic destined to the control plane, not all interfaces. Option D is wrong because the class-map already includes 'match-all' (the default behavior is match-all when not specified, but here it is explicitly stated), and the configuration is valid; the class-map correctly references an access-group named ICMP_ACL.

1299
MCQmedium

A network administrator is implementing Control Plane Policing on a Cisco IOS-XE router to protect the route processor from excessive BGP, SSH, and SNMP traffic. After applying the policy, legitimate BGP keepalives are being dropped, causing peer resets. Which action should the administrator take to resolve this while still protecting the control plane?

A.Remove the BGP class from the policy map so BGP is not policed at all
B.Apply the policy to the data plane interfaces instead of the control plane
C.Change the policy map to use priority queuing instead of policing for the BGP class
D.Raise the conform-action rate for the BGP class and verify BGP is classified before the default class
AnswerD

BGP keepalives are small but time-sensitive; if the policed rate for the BGP class is too low, drops cause peer resets. Increasing the conform rate for that class and ensuring BGP traffic matches its dedicated class before falling into the default class restores keepalive delivery while still rate-limiting other unwanted traffic. This preserves control-plane protection without harming BGP.

Why this answer

CoPP classifies control-plane traffic and applies policers per class. BGP keepalives are small and periodic; if the BGP class rate is too low or BGP is not matched before the default class, keepalives get dropped and peers reset. Increasing the conform rate for the BGP class and ensuring correct classification order restores keepalive delivery while continuing to protect the route processor from abusive traffic in other classes.

Exam trap

The trap here is assuming that removing the BGP class or switching to queuing solves the problem, when the actual fix is to tune the policer rate and verify classification order so BGP matches its dedicated class before the default class.

1300
MCQeasy

A network engineer runs the following command on Router R1: R1# show ip route 192.168.2.0 Routing entry for 192.168.2.0/24 Known via "ospf 1", distance 110, metric 20, type inter area Last update from 10.0.0.2 on GigabitEthernet0/0, 00:05:23 ago Routing Descriptor Blocks: * 10.0.0.2, via GigabitEthernet0/0, 00:05:23 ago Route metric is 20, traffic share count is 1 Based on this output, what can be concluded?

A.The route is an OSPF intra-area route
B.The route is an OSPF inter-area route
C.The route is an OSPF external route
D.The route is learned via EIGRP
AnswerB

The routing table line states 'Known via ospf 1' and includes the route tag 'type inter area', which is unambiguously how Cisco marks OSPF inter-area routes. These routes are propagated between areas via Type 3 summary LSAs, and the ABR advertises the prefix into the current area. This matches the 'inter area' classification exactly, making the route an OSPF inter-area route.

Why this answer

The output shows 'type inter area' and a metric of 20, which is the default OSPF metric for inter-area routes (type 3 LSAs). The administrative distance of 110 confirms OSPF as the routing protocol. Therefore, the route is an OSPF inter-area route, making option B correct.

Exam trap

Cisco often tests the distinction between OSPF route types by showing the 'type inter area' or 'type intra area' keyword in the show ip route output, and candidates may confuse the metric value (20) with external route metrics, forgetting that inter-area routes also use a default metric of 20 when no cost is explicitly configured.

How to eliminate wrong answers

Option A is wrong because the output explicitly states 'type inter area', not intra-area; intra-area routes would show 'type intra area' and typically have a lower metric. Option C is wrong because OSPF external routes (type 5 or 7 LSAs) would display 'type external' or 'type NSSA external' and often have a metric of 20 for E1/E2 routes, but the output clearly says 'inter area'. Option D is wrong because the administrative distance is 110 (OSPF default), not 90 or 170 (EIGRP default distances), and the output shows 'Known via ospf 1', not EIGRP.

1301
Matchingmedium

Match each First Hop Redundancy Protocol (FHRP) to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Cisco proprietary, active/standby

Open standard, active/standby

Cisco proprietary, active/active load balancing

Obsolete, uses ICMP advertisements

Another name for ICMP Router Discovery

Why these pairings

FHRPs provide default gateway redundancy. HSRP is Cisco proprietary, active/standby, preemption disabled by default. VRRP is open standard, preemption enabled.

GLBP allows load balancing among multiple routers.

1302
MCQmedium

Given the following Ansible playbook snippet: --- - name: Configure EIGRP hosts: routers gather_facts: no tasks: - name: EIGRP config ios_config: lines: - router eigrp 100 - network 192.168.1.0 parents: router eigrp 100 What is the effect of this playbook?

A.It fails because the network statement requires a wildcard mask.
B.It configures EIGRP AS 100 and advertises network 192.168.1.0/24.
C.It only enters EIGRP configuration mode without applying any network statement.
D.It works correctly because the network statement defaults to a classful mask.
AnswerA

This option is correct. In Cisco IOS, the EIGRP `network` command requires a dotted-decimal wildcard mask to define the inverse of the subnet mask; for example, `network 192.168.1.0 0.0.0.255`. If the wildcard mask is omitted, the CLI parser rejects the command as invalid, and the playbook task fails with a configuration error, so no EIGRP network is advertised.

Why this answer

The `network` statement in EIGRP requires a wildcard mask to define the exact interfaces on which EIGRP will run. Without a wildcard mask, the command `network 192.168.1.0` is incomplete and will be rejected by the Cisco IOS device, causing the playbook task to fail. The Ansible `ios_config` module sends the lines as-is to the device, so the missing wildcard mask results in a configuration error.

Exam trap

The trap here is that candidates often assume the `network` command in EIGRP defaults to a classful mask (like in older IOS versions or with RIP), but Cisco explicitly tests that EIGRP requires a wildcard mask, and omitting it causes a configuration failure.

How to eliminate wrong answers

Option B is wrong because the playbook does not actually configure EIGRP successfully; the missing wildcard mask causes the task to fail, so no network statement is applied. Option C is wrong because the playbook attempts to apply both the `router eigrp 100` and `network 192.168.1.0` lines, but the failure occurs before any configuration is committed; the `parents` directive only ensures the lines are placed under the EIGRP configuration mode, but the invalid network command still causes an error. Option D is wrong because EIGRP does not default to a classful mask; the `network` command in EIGRP explicitly requires a wildcard mask, unlike some other routing protocols (e.g., OSPF) that may accept a prefix length.

1303
MCQmedium

An engineer is designing an MPLS L3VPN service for a customer that requires overlapping IP addresses between two sites. The customer uses OSPF as the PE-CE protocol. The engineer configures VRFs on the PE routers and assigns unique route distinguishers (RDs) and route targets (RTs). However, the customer reports that routes from one site are not being installed in the other site's VRF. What is the most likely cause?

A.The route-target export on PE1 does not match the route-target import on PE2.
B.The overlapping IP addresses cause a routing loop in OSPF.
C.OSPF cannot carry overlapping prefixes in different VRFs.
D.The route distinguisher is not unique between the two sites.
AnswerA

In MPLS L3VPN, route targets (RTs) are BGP extended communities that control the redistribution of VPN routes between VRFs. The exporting PE attaches an export RT to a VPNv4 route; the importing PE only places that route into a VRF if the route's RT matches the VRF's import RT. In this scenario, PE1's export RT does not match PE2's import RT, so even though the VPNv4 route reaches PE2 via BGP, it is not installed in the VRF routing table, leaving the prefix unreachable.

Why this answer

In MPLS L3VPN, route targets (RTs) control the import and export of VPN routes between VRFs. For routes from one site to be installed in another site's VRF, the route-target export on the exporting PE must match the route-target import on the importing PE. If they do not match, the routes are not imported, even if route distinguishers (RDs) are unique and OSPF is properly configured.

Exam trap

The trap here is that candidates often confuse the role of route distinguishers (RDs) with route targets (RTs), thinking that unique RDs are sufficient for route exchange, when in fact RTs control the import/export policy between VRFs.

How to eliminate wrong answers

Option A is correct because mismatched route targets prevent route import between VRFs. Option B is wrong because overlapping IP addresses do not cause routing loops in OSPF; OSPF operates within each VRF independently, and overlapping addresses are handled by VRFs isolating routing tables. Option C is wrong because OSPF can carry overlapping prefixes in different VRFs; each VRF maintains its own OSPF process and routing table, so overlapping prefixes are not a problem.

Option D is wrong because route distinguishers (RDs) are used to make prefixes unique across the MPLS core, but they do not affect route import/export; mismatched RDs do not prevent route installation as long as RTs match.

1304
MCQmedium

A network engineer is deploying a new Cisco Catalyst 9000 switch stack and wants to protect the control plane from excessive ARP traffic that could overwhelm the CPU during a broadcast storm. The engineer needs to limit the rate of ARP packets sent to the CPU to 500 packets per second and drop the excess. Which feature should be configured on the switch?

A.Dynamic ARP Inspection (DAI) on all VLANs
B.Control Plane Policing (CoPP) with a class-map matching ARP
C.IP Source Guard on all access ports
D.Storm control configured on all access ports
AnswerB

CoPP allows the engineer to police traffic destined to the control plane, including ARP packets. By creating a class-map that matches ARP and a policy-map that sets a rate limit of 500 pps with a drop action, the switch CPU is protected from excessive ARP. This is the correct feature for rate-limiting control-plane traffic.

Why this answer

Control Plane Policing (CoPP) is designed to protect the CPU by rate-limiting traffic destined to the control plane. In this scenario, the engineer needs to limit ARP packets to 500 pps, which is exactly what CoPP can do by matching ARP in a class-map and applying a policer. Other features like storm control or DAI do not provide this granular control-plane protection.

Exam trap

The trap here is assuming that storm control or DAI can rate-limit ARP traffic to the CPU, when they actually operate at the data plane or for security validation.

1305
MCQhard

A network security team is deploying MACsec on a Cisco Catalyst 9300 switch connecting to a partner's Catalyst 9200 over a metro Ethernet link. The team wants to encrypt all traffic on the link and ensure that the switches mutually authenticate before any frames are forwarded. Which IEEE standard defines the key agreement and encryption used by MACsec, and which component performs the key exchange?

A.IEEE 802.1AE for encryption and IKEv2 for key agreement
B.IEEE 802.1X for encryption and IEEE 802.1AE for key agreement
C.IEEE 802.1AE for encryption and IEEE 802.1X-2010 with MKA for key agreement
D.IEEE 802.1Q for tagging and IEEE 802.1AE for key agreement
AnswerC

MACsec encryption is defined by IEEE 802.1AE, which specifies hop-by-hop encryption of Ethernet frames. Key agreement and mutual authentication are provided by MACsec Key Agreement (MKA), which is defined in IEEE 802.1X-2010. The two switches exchange MKPDUs to negotiate a secure association key, so no frames are forwarded in the clear before the session is established, satisfying the mutual authentication requirement.

Why this answer

MACsec encryption is standardized in IEEE 802.1AE, while the key agreement and mutual authentication between peers are handled by MACsec Key Agreement as defined in IEEE 802.1X-2010. Together they ensure that the Catalyst 9300 and 9200 mutually authenticate and encrypt every frame before any user traffic is forwarded across the metro Ethernet link.

Exam trap

The trap here is assuming that 802.1X itself provides MACsec encryption, when in fact 802.1X-2010 contributes the MKA key agreement and 802.1AE provides the actual frame encryption.

1306
Drag & Dropmedium

Drag and drop the steps of EIGRP named mode configuration steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Named mode starts with the router eigrp <virtual-name> command, then enters address-family configuration, configures the network, and optionally adjusts timers or other parameters. Finally, the configuration is verified.

1307
MCQmedium

A network engineer at a university is deploying Cisco HyperFlex to replace a legacy SAN-backed vSphere cluster. The design calls for fabric interconnects to be managed in Cisco UCS Manager, and the engineer wants the HyperFlex installer to fully configure the fabric interconnects and the UCS servers automatically. Which HyperFlex deployment model should the engineer choose?

A.HyperFlex standard cluster with fabric interconnects in UCS Manager-managed mode
B.HyperFlex Edge with a two-node cluster managed by the HyperFlex Connect appliance
C.Cisco UCS Mini with HyperFlex software installed manually on each node
D.HyperFlex stretched cluster across two sites using Cisco Intersight-managed fabric interconnects
AnswerA

A standard HyperFlex cluster with UCS Manager-managed fabric interconnects lets the HyperFlex installer discover and configure the fabric interconnects, server policies, and VLANs automatically. This matches the requirement for automated configuration of both fabric interconnects and UCS servers in a data-center cluster, which is exactly what the standard deployment model delivers.

Why this answer

Deploying a standard HyperFlex cluster with UCS Manager-managed fabric interconnects is the model in which the HyperFlex installer discovers and configures the fabric interconnects, server profiles, and networking automatically. Because the university wants full automation of fabric interconnect and UCS server configuration in a data-center cluster, the standard model is the only listed option that satisfies every stated requirement.

Exam trap

The trap here is assuming any HyperFlex deployment automatically configures fabric interconnects, when Edge and Intersight-managed models use different management and validation workflows.

1308
MCQmedium

Given the following configuration on a Cisco IOS-XE router: interface Tunnel100 ip address 10.0.0.1 255.255.255.252 tunnel source GigabitEthernet0/0/0 tunnel destination 192.168.1.1 tunnel mode ipsec ipv4 tunnel protection ipsec profile MYPROFILE What is the effect of this configuration?

A.It creates a GRE tunnel with IPsec encryption.
B.It creates a VTI (Virtual Tunnel Interface) that encrypts all traffic routed into the tunnel using IPsec.
C.It creates a DMVPN phase 1 tunnel with mGRE.
D.It creates a L2TPv3 tunnel for layer 2 transport.
AnswerB

This option is correct: tunnel mode ipsec ipv4 creates a static VTI (Virtual Tunnel Interface), which is a route-based IPsec VPN interface. All traffic routed into this tunnel gets encrypted and encapsulated directly into IPsec using the parameters defined in the referenced IPsec profile. Unlike GRE, a VTI has no extra GRE header, and unlike a crypto map, it allows routing protocols and policy-based routing to decide what to protect, making it a clean, scalable site-to-site VPN solution.

Why this answer

The configuration creates a Virtual Tunnel Interface (VTI) that encrypts all traffic routed into the tunnel using IPsec. The 'tunnel mode ipsec ipv4' command explicitly sets the tunnel to operate in IPsec tunnel mode (not GRE), and 'tunnel protection ipsec profile MYPROFILE' applies IPsec encryption directly to the tunnel interface. This is a standard static VTI configuration, which encrypts any IPv4 traffic that is routed into the tunnel without requiring a separate crypto map.

Exam trap

Cisco often tests the distinction between 'tunnel mode ipsec ipv4' (VTI) and 'tunnel mode gre ip' with IPsec protection, where candidates mistakenly assume any tunnel with IPsec protection must be a GRE tunnel, but the 'tunnel mode' command determines the encapsulation type.

How to eliminate wrong answers

Option A is wrong because 'tunnel mode ipsec ipv4' does not use GRE encapsulation; GRE tunnels use 'tunnel mode gre ip' and would require a separate IPsec profile for encryption, whereas this configuration uses IPsec as the tunnel encapsulation itself. Option C is wrong because DMVPN Phase 1 uses mGRE (multipoint GRE) with NHRP, not a static point-to-point tunnel; the configuration shows a single tunnel destination (192.168.1.1) and does not include 'tunnel mode gre multipoint' or NHRP commands. Option D is wrong because L2TPv3 tunnels use 'tunnel mode l2tpv3' and are designed for Layer 2 transport, not IPsec encryption of IPv4 traffic.

1309
MCQhard

A network engineer is configuring a Cisco IOS switch with 802.1X authentication. The switch is connected to a Cisco IP phone, and a PC is connected to the phone's PC port. The engineer wants to authenticate both the phone and the PC using 802.1X. Which feature should be configured to allow both devices to authenticate on the same switch port?

A.MAC Authentication Bypass (MAB)
B.Multi-Auth
C.Multi-Domain Authentication (MDA)
D.Web Authentication (WebAuth)
AnswerC

Multi-Domain Authentication (MDA) allows both a data device (PC) and a voice device (IP phone) to authenticate on the same switch port. The phone authenticates in the voice domain, and the PC authenticates in the data domain. This is the correct feature for this scenario because it separates the authentication domains and supports the typical IP phone with a PC attached.

Why this answer

Multi-Domain Authentication (MDA) is designed for scenarios where an IP phone and a PC are connected to the same switch port. It allows the phone to authenticate in the voice domain and the PC in the data domain, each with its own authentication method. This provides the necessary separation of traffic and authentication.

Exam trap

The trap here is confusing Multi-Auth with Multi-Domain Authentication; Multi-Auth allows multiple devices but does not separate voice and data domains, which is required for IP phones.

1310
MCQmedium

Given the following WLAN configuration on a Cisco 9800 WLC: wlan test-wlan 1 test-ssid client vlan VLAN10 no security wpa no security wpa2 security wpa3 no security ft What is a potential issue with this configuration?

A.The WLAN is missing a security key management (AKM) configuration.
B.The client VLAN is incorrectly configured.
C.WPA3 is not supported on this platform.
D.The SSID name is too long.
AnswerA

WPA3 authentication relies on a specific AKM, SAE (Simultaneous Authentication of Equals), which must be explicitly declared in the WLAN security profile. The CLI snippet lacks the 'security wpa3 akm sae' command, meaning the controller has no key management agreement to present to WPA3 clients. Without a defined AKM, the WPA3 encryption suite cannot negotiate session keys, so the WLAN remains non-functional for WPA3-capable devices even though other parameters like SSID and VLAN are correct.

Why this answer

The configuration enables WPA3 but omits a security key management (AKM) policy. WPA3 requires an AKM suite (e.g., SAE for personal or 802.1X for enterprise) to negotiate authentication and key derivation. Without an AKM configured, the WLAN will fail to enable or will not allow clients to associate, as the WLC cannot determine the key management protocol.

Exam trap

Cisco often tests the fact that enabling WPA3 does not automatically configure an AKM, and candidates mistakenly assume that 'security wpa3' alone is sufficient, overlooking the required key management statement.

How to eliminate wrong answers

Option B is wrong because the client VLAN configuration (VLAN10) is syntactically correct and does not cause a functional issue; the problem lies in the security parameters, not the VLAN assignment. Option C is wrong because WPA3 is supported on Cisco 9800 WLCs running appropriate software versions (e.g., IOS XE 17.x), and the platform is not inherently incompatible. Option D is wrong because the SSID 'test-ssid' is well within the 32-character maximum length for SSIDs, so length is not a factor here.

1311
MCQmedium

An enterprise is migrating from a traditional MPLS WAN to Cisco SD-WAN. The network team has deployed vEdge routers at all branch offices and a vSmart controller in the data center. The engineer configures a centralized control policy to influence path selection based on cost and latency. After the policy is activated, the engineer notices that some branches are not receiving the updated policy and are still using the default best-path selection. The vSmart is reachable from all branches, and the vEdge routers show that they are connected to the vSmart. What is the most likely reason for this issue?

A.The vEdge routers have not been rebooted after the policy change.
B.The control policy is not attached to the appropriate site list or VPN list.
C.The OMP graceful restart timer has expired, causing the vEdge to ignore the policy.
D.The BFD sessions between vEdge and vSmart are flapping.
AnswerB

Centralised control policy only takes effect on vEdge routers matched by its site list and VPN list. If those references are missing or mismatched, the vSmart distributes nothing to those branches, so they fall back to default best-path selection despite being connected.

Why this answer

In Cisco SD-WAN, centralized control policies must be explicitly attached to a site list or VPN list to define which devices or traffic the policy applies to. If the policy is not attached to the appropriate list, the vSmart controller will not push the policy to the targeted vEdge routers, causing them to continue using the default OMP best-path selection (based on administrative distance and cost). The fact that the vEdge routers are connected to the vSmart confirms the issue is with policy application, not reachability.

Exam trap

Cisco often tests the concept that a control policy must be attached to a site list or VPN list to be effective, and candidates mistakenly assume that simply configuring the policy on the vSmart is sufficient for it to apply to all devices.

How to eliminate wrong answers

Option A is wrong because vEdge routers do not require a reboot to apply control policy changes; policies are pushed dynamically via OMP from the vSmart and take effect immediately upon activation. Option C is wrong because the OMP graceful restart timer affects route convergence during a vSmart failure, not the application of a control policy; a vEdge will not ignore a policy due to this timer expiring. Option D is wrong because BFD sessions are used for data-plane path liveliness detection between vEdge routers, not for control-plane communication between vEdge and vSmart; flapping BFD sessions would not prevent policy receipt.

1312
MCQeasy

A network engineer runs the following command on Switch SW7: SW7# show spanning-tree vlan 70 VLAN0070 Spanning tree enabled protocol ieee Root ID Priority 24646 Address aabb.cc00.0c00 Cost 4 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32768 (priority 32768 sys-id-ext 70) Address aabb.cc00.0d00 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- ------------------------------ Gi0/1 Root FWD 4 128.1 P2p Gi0/2 Desg FWD 4 128.2 P2p Gi0/3 Altn BLK 4 128.3 P2p Based on this output, which port is the alternate port?

A.GigabitEthernet0/1
B.GigabitEthernet0/2
C.GigabitEthernet0/3
D.There is no alternate port.
AnswerC

GigabitEthernet0/3 is the correct alternate port because its port state is shown as Altn BLK, indicating it is blocked but has received a superior BPDU from another switch. This gives a different path to the root bridge than the root port, so it will transition to forwarding if Gi0/1 fails.

Why this answer

The alternate port is GigabitEthernet0/3 because it is in the 'Altn' role with a 'BLK' (blocking) state. In Rapid Spanning Tree Protocol (RSTP) and Per-VLAN Spanning Tree Plus (PVST+), an alternate port provides an alternative path to the root bridge and remains blocked unless the current root port fails. The output clearly shows Gi0/3 as 'Altn BLK', making it the alternate port.

Exam trap

Cisco often tests the distinction between alternate and backup ports; the trap here is that candidates may confuse 'Altn' (alternate, which provides a backup to the root port) with 'Backup' (which provides a backup to the designated port on the same segment), or assume that only root and designated ports exist in a stable topology.

How to eliminate wrong answers

Option A is wrong because GigabitEthernet0/1 is the root port (Role: Root, State: FWD), which is the best path to the root bridge, not an alternate port. Option B is wrong because GigabitEthernet0/2 is a designated port (Role: Desg, State: FWD), which forwards traffic on the segment and is not an alternate port. Option D is wrong because an alternate port is explicitly listed in the output (Gi0/3 with role 'Altn'), so the statement 'There is no alternate port' is false.

1313
Multi-Selecthard

Which three statements about classification and marking in a QoS architecture are true? (Choose three.)

Select 3 answers
A.Classification can be based on the source IP address, destination port, or protocol type using an access control list.
B.Marking at Layer 3 uses the DSCP field, which provides 64 possible values, while IP Precedence provides only 8.
C.The MPLS EXP field is used to mark packets only at the ingress of an MPLS network and is never changed within the core.
D.Marking should be performed as close to the source as possible to ensure consistent treatment across the network.
E.NBAR (Network Based Application Recognition) can classify traffic by inspecting the payload up to Layer 7.
AnswersA, B, E

Classification examines packet header fields, and an ACL matches source IP address, destination port, or protocol type, so traffic can be sorted into classes before marking. This satisfies the stem's requirement for a header-based classification mechanism.

Why this answer

Option A is correct because classification commonly uses ACLs to match fields such as source IP address, destination port, and protocol type, which are exactly the Layer 3/Layer 4 criteria listed. Option B is correct because Layer 3 marking uses the 6-bit DSCP field in the IP header, giving 2^6 = 64 values, whereas the older IP Precedence field is only 3 bits, giving 2^3 = 8 values. Option E is correct because NBAR performs deep packet inspection and can recognize applications by examining payload content up to Layer 7, beyond simple header-based classification.

Option C is not correct because the MPLS EXP field can be modified within the MPLS core, for example at label swap or PHP operations, and is not restricted to ingress-only marking. Option D is not correct as a universal QoS statement because marking is often recommended near the source or at the trust boundary, but it is not an absolute rule and can be performed at aggregation or edge devices depending on policy and trust models.

Exam trap

The trap here is assuming MPLS EXP is immutable in the core or that marking must always happen at the source — candidates confuse design best practices with protocol capabilities.

1314
MCQmedium

A network administrator is configuring a Cisco wireless LAN controller (WLC) to support a new employee SSID. The SSID must use WPA2-Enterprise with 802.1X authentication against an external RADIUS server. The administrator has already configured the RADIUS server on the WLC. Which additional step is required to complete the configuration?

A.Create a new WLAN and set the Layer 2 Security to WPA2 with 802.1X, and set the Layer 3 Security to None.
B.Create a new WLAN and set the Layer 2 Security to WPA2 with PSK, and set the Layer 3 Security to Web Policy.
C.Create a new WLAN and set the Layer 2 Security to None, and set the Layer 3 Security to Web Policy with RADIUS authentication.
D.Create a new WLAN and set the Layer 2 Security to WPA2 with 802.1X, and set the Layer 3 Security to Web Policy.
AnswerA

For WPA2-Enterprise with 802.1X, the WLAN's Layer 2 Security must be set to WPA2 with 802.1X. Layer 3 Security should be set to None because 802.1X handles authentication at Layer 2. This configuration enables the WLC to use the RADIUS server for authentication.

Why this answer

For WPA2-Enterprise with 802.1X, the WLAN must use Layer 2 Security set to WPA2 with 802.1X, which leverages the configured RADIUS server for authentication. Layer 3 Security should remain None to avoid additional web authentication. This setup ensures that clients authenticate via 802.1X and receive AES encryption.

Exam trap

The trap here is adding Layer 3 Web Policy in addition to 802.1X, which would cause double authentication and is not required for WPA2-Enterprise.

1315
Drag & Dropmedium

Drag and drop the steps of SD-Access underlay provisioning via LAN Automation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

LAN Automation begins with the seed device discovering new switches via CDP, then the new switches are automatically configured with the underlay template, including PnP and DHCP. After configuration, the switches join the fabric underlay, and finally, the automation process verifies connectivity and updates the inventory.

1316
Drag & Dropmedium

Drag and drop the steps of KVM VM provisioning via virsh CLI into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

KVM provisioning via virsh begins with defining the VM XML configuration. Then, the VM is started using virsh start. Next, the VM's console is accessed to complete OS installation.

After that, the VM is shut down gracefully. Finally, the VM is restarted for production use.

1317
MCQeasy

What is the default CoS-to-queue mapping on a Cisco switch that supports QoS?

A.CoS 0-1 to queue 1, CoS 2-3 to queue 2, CoS 4-5 to queue 3, CoS 6-7 to queue 4
B.CoS 0-2 to queue 1, CoS 3-5 to queue 2, CoS 6-7 to queue 3
C.CoS 0 to queue 1, CoS 1 to queue 2, CoS 2 to queue 3, CoS 3 to queue 4
D.All CoS values are mapped to a single queue by default.
AnswerA

This is the default CoS-to-queue assignment on many Cisco Catalyst switches, where the eight CoS priorities are paired: CoS 0-1 map to queue 1, CoS 2-3 to queue 2, CoS 4-5 to queue 3, and CoS 6-7 to queue 4. This pairing reflects the hardware's four egress queues and allows differentiated treatment for traffic classes while preserving the eight CoS fields. In this default configuration, queue scheduling (typically SRR) uses these pairs to allocate bandwidth without requiring custom QoS policy.

Why this answer

On Cisco switches that support QoS, the default Class of Service (CoS) to queue mapping distributes CoS values across four egress queues. CoS 0 and 1 are mapped to queue 1 (best effort), CoS 2 and 3 to queue 2, CoS 4 and 5 to queue 3, and CoS 6 and 7 to queue 4 (highest priority). This mapping is defined by the default trust state and is used to prioritize traffic based on the 802.1p priority bits in the VLAN tag.

Exam trap

Cisco often tests the default CoS-to-queue mapping as a memorization point, and the trap here is that candidates confuse the default mapping with a custom or logical grouping, such as assuming CoS 5 is always in the highest queue or that each CoS gets its own queue.

How to eliminate wrong answers

Option B is wrong because it maps CoS 0-2 to queue 1, CoS 3-5 to queue 2, and CoS 6-7 to queue 3, which is a three-queue mapping that does not match the standard four-queue default on Cisco switches. Option C is wrong because it assigns each CoS value (0, 1, 2, 3) to a separate queue, which is not the default; the default groups CoS values into pairs per queue. Option D is wrong because Cisco switches do not map all CoS values to a single queue by default; they use multiple queues to provide differentiated QoS based on CoS markings.

1318
MCQmedium

Consider the following configuration: policy-map QUEUE_POLICY class VOICE priority level 1 police cir 1000000 class VIDEO priority level 2 police cir 2000000 class class-default fair-queue What is the effect of using priority level 1 and priority level 2?

A.VOICE traffic (level 1) is always sent before VIDEO traffic (level 2), and both are policed.
B.VOICE and VIDEO traffic are treated equally and share the priority bandwidth.
C.VIDEO traffic (level 2) is sent before VOICE traffic (level 1) because it has a higher police rate.
D.This configuration is invalid because only one priority level is allowed.
AnswerA

In Cisco's hierarchical QoS, 'priority level 1' and 'priority level 2' create separate strict-priority queues. The scheduler empties level 1 before level 2, so voice is always sent before video, even if video's policed rate were higher. Both levels are independently policed to their configured rates; excess traffic is dropped or optionally re-marked. This is valid on platforms such as the ASR 1000 that support multiple priority levels.

Why this answer

The 'priority level' command under a class in a policy-map allows multiple priority queues with different levels. Level 1 is the highest priority, so VOICE traffic (level 1) is always scheduled before VIDEO traffic (level 2). Both classes are also subject to policing, which enforces a maximum rate (CIR) and drops or remarks excess traffic.

This ensures low-latency treatment for VOICE while still providing priority queuing for VIDEO, but with a lower scheduling preference.

Exam trap

The trap here is that candidates often assume only one priority queue is allowed per policy-map, but Cisco tests the 'priority level' feature which permits multiple priority queues with hierarchical strict scheduling.

How to eliminate wrong answers

Option B is wrong because VOICE and VIDEO are not treated equally; priority level 1 (VOICE) is strictly scheduled before priority level 2 (VIDEO), creating a hierarchical priority structure. Option C is wrong because a higher police rate does not affect scheduling priority; priority level determines scheduling order, not the policing rate. Option D is wrong because the configuration is valid; Cisco IOS supports multiple priority levels (up to 16 in some platforms) using the 'priority level' command, allowing differentiated priority queuing.

1319
MCQeasy

A network engineer is deploying a new branch office that connects to the headquarters over an MPLS Layer 3 VPN provided by a service provider. The branch has a single CE router running eBGP with the provider PE router. The engineer wants to advertise the branch LAN prefix into the MPLS VPN while keeping the branch routing table simple. Which approach is appropriate?

A.Configure the CE router to redistribute the LAN prefix into eBGP toward the PE router.
B.Configure the CE router to run OSPF with the PE router and redistribute the LAN prefix into OSPF.
C.Configure a static route on the PE router pointing to the branch LAN prefix.
D.Configure the CE router to send the LAN prefix using MPLS label distribution to the PE router.
AnswerA

In an MPLS Layer 3 VPN, the CE router exchanges routes with the provider PE router using eBGP. Redistributing the branch LAN prefix into BGP advertises it to the PE, which places it into the correct VRF and propagates it across the provider backbone to other sites in the same VPN. This keeps the branch routing table simple because the CE only needs a default or summarized route toward the PE.

Why this answer

In an MPLS Layer 3 VPN, the customer edge router exchanges routes with the provider edge router using a PE-CE routing protocol such as eBGP. Redistributing the branch LAN prefix into eBGP advertises it to the PE, which imports it into the correct VRF and propagates it to other VPN sites, keeping the branch routing table simple with a default route toward the provider.

Exam trap

The trap here is thinking the customer must configure the provider PE router or use MPLS label distribution, when the customer only controls the CE side.

1320
MCQmedium

A network engineer is troubleshooting a routing loop between two OSPF areas. To verify the path that packets are taking, the engineer decides to use the Cisco IOS Embedded Event Manager (EEM) to generate a syslog message when the OSPF neighbor state changes. Which EEM applet configuration is required to trigger on the OSPF neighbor state change?

A.event tag ospf-neighbor timer watchdog time 60
B.event tag ospf-neighbor cli pattern "show ip ospf neighbor"
C.event tag ospf-neighbor syslog pattern "%OSPF-5-ADJCHG"
D.event tag ospf-neighbor snmp oid 1.3.6.1.2.1.14.10.1.6
AnswerC

This applet uses a syslog event detector that matches the OSPF adjacency change syslog message. When the router logs a %OSPF-5-ADJCHG message, the EEM applet triggers. This is a common method to monitor OSPF neighbor state changes without polling. The pattern must match the exact syslog text, and the tag is used to associate actions.

Why this answer

The correct configuration uses a syslog event detector to match the OSPF adjacency change message. When OSPF neighbor state changes, the router generates a %OSPF-5-ADJCHG syslog message. An EEM applet with a syslog event detector and the appropriate pattern will trigger actions based on that message.

This provides immediate, event-driven monitoring without polling. The other options either use inappropriate event detectors or incorrect syntax for this purpose.

Exam trap

The trap here is confusing the CLI event detector with the syslog event detector; the CLI detector triggers on command input, not on syslog messages.

1321
Multi-Selecthard

A network architect is evaluating VXLAN as the data plane encapsulation for a new data center fabric. Which two statements accurately describe how VXLAN operates? (Choose two.)

Select 2 answers
A.VXLAN replaces the original Ethernet header with a new one and discards the original source MAC.
B.VXLAN tunnel endpoints must use the same IP address to form a tunnel.
C.VXLAN encapsulates original Layer 2 frames inside UDP datagrams sent to destination port 4789.
D.VXLAN uses a 24-bit VXLAN Network Identifier, allowing over 16 million logical segments.
E.VXLAN requires the underlay to be a single Layer 2 domain with no routing between VTEPs.
AnswersC, D

VXLAN uses MAC-in-UDP encapsulation with the standard destination UDP port 4789. The original Ethernet frame is carried inside the UDP payload, allowing Layer 2 segments to be stretched across a Layer 3 underlay. This is a defining operational characteristic of VXLAN and is accurate for this fabric design.

Why this answer

VXLAN encapsulates original Layer 2 frames in UDP datagrams destined for port 4789 and identifies each logical segment with a 24-bit VNI supporting about 16 million segments. These two properties let the fabric scale far beyond VLAN limits while running over a routed Layer 3 underlay between distinct VTEP addresses.

Exam trap

The trap here is assuming VXLAN still depends on a flat Layer 2 underlay or a 12-bit segment identifier like traditional VLANs.

1322
Drag & Dropmedium

Drag and drop the steps of named ACL modification using sequence numbers into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Sequence numbers allow editing named ACLs without re-entering all entries. The correct order is: view current entries, insert a new entry at a specific sequence, then verify the updated ACL.

1323
Drag & Dropmedium

Drag and drop the steps of IP SLA scheduling with frequency and lifetime into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, the IP SLA operation is created. Then the frequency (how often to run) is configured. The lifetime (how long to run) is set.

The operation is scheduled to start. Finally, the schedule is verified.

1324
MCQmedium

A network engineer runs the following command on Router R6: R6# show ip pim rp 239.3.3.3 RP 10.0.0.4 Info source: 10.0.0.4, via bootstrap, priority 192, holdtime 150, expires in 00:02:30 Based on this output, what can be concluded?

A.The RP was learned via Auto-RP.
B.The RP was learned via BSR.
C.The RP was statically configured.
D.The RP is 10.0.0.5.
AnswerB

The RP's source is shown as 'via bootstrap', which is the standard output when a router receives RP information from the BSR protocol defined in RFC 5059. BSR uses a designated bootstrap router to flood RP-set information throughout the PIM domain, allowing all routers to dynamically learn the active RP. The command 'show ip pim rp mapping' or similar would display this exact phrase for BSR-learned RPs, confirming that BSR is the correct mechanism.

Why this answer

The output shows 'via bootstrap', which indicates the RP was learned through the Bootstrap Router (BSR) mechanism. BSR is a dynamic RP discovery protocol that uses a bootstrap router to distribute RP information throughout the PIM domain, making option B correct.

Exam trap

Cisco often tests the distinction between 'via bootstrap' (BSR) and 'via Auto-RP' in show command output, leading candidates to confuse the two dynamic RP discovery methods.

How to eliminate wrong answers

Option A is wrong because Auto-RP uses multicast announcements (224.0.1.39 and 224.0.1.40) and would show 'via Auto-RP' in the output, not 'via bootstrap'. Option C is wrong because a statically configured RP would not show an info source or holdtime; it would simply display the RP address without a dynamic source. Option D is wrong because the output explicitly states 'RP 10.0.0.4', not 10.0.0.5.

1325
MCQmedium

A network engineer is configuring a Cisco Catalyst switch to authenticate users via 802.1X. The RADIUS server is reachable at 10.10.10.5 using the key 'Cisco123'. The switch must dynamically assign VLANs based on the RADIUS attributes returned. Which configuration is required on the switch to enable dynamic VLAN assignment?

A.aaa new-model aaa authentication dot1x default group radius aaa accounting network default start-stop group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control
B.aaa new-model aaa authentication dot1x default group radius aaa authorization network default group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control
C.aaa new-model aaa authentication dot1x default group radius aaa authorization network default group radius radius-server host 10.10.10.5 key Cisco123 no dot1x system-auth-control
D.aaa new-model aaa authentication dot1x default group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control
AnswerB

This configuration includes 'aaa authorization network default group radius', which is necessary for the switch to authorize the user and apply VLAN assignment from the RADIUS server. The authentication command verifies credentials, while authorization processes the returned attributes such as tunnel-type, tunnel-medium, and tunnel-private-group-id to assign the VLAN. The RADIUS server and dot1x system-auth-control are also correctly configured.

Why this answer

For dynamic VLAN assignment with 802.1X, the switch must authenticate the user and authorize the session to receive VLAN attributes from the RADIUS server. The 'aaa authorization network default group radius' command enables the switch to process these attributes. Without it, the switch will not apply the VLAN, even if authentication succeeds.

The RADIUS server and global 802.1X configuration are also required.

Exam trap

The trap here is assuming that authentication alone is sufficient for dynamic VLAN assignment, but authorization is required to process and apply the RADIUS attributes.

1326
MCQmedium

A network engineer is designing a wireless network for a large auditorium that must support high-density client access. The engineer plans to use Cisco Catalyst 9800 Series Wireless Controllers and Wi-Fi 6 access points. Which feature should be enabled to improve airtime efficiency and reduce overhead for many concurrent clients?

A.802.11r
B.MU-MIMO
C.Band steering
D.OFDMA
AnswerD

OFDMA (Orthogonal Frequency-Division Multiple Access) is a key feature of Wi-Fi 6 that allows multiple clients to be served simultaneously within the same channel by allocating subsets of subcarriers. This improves airtime efficiency and reduces overhead in high-density environments by enabling parallel transmissions to multiple clients. In an auditorium with many concurrent clients, OFDMA significantly enhances capacity and performance.

Why this answer

OFDMA is a Wi-Fi 6 feature that partitions a channel into smaller resource units, allowing simultaneous transmission to multiple clients. This reduces contention and overhead, making it ideal for high-density environments like auditoriums. By enabling OFDMA, the network can serve many clients more efficiently, improving overall throughput and user experience.

Exam trap

The trap here is confusing MU-MIMO with OFDMA, assuming that MU-MIMO alone solves high-density efficiency, when OFDMA specifically addresses subcarrier-level multiplexing for many concurrent clients.

1327
MCQmedium

A Python script uses the requests library to interact with Cisco DNA Center's REST API: import requests url = "https://dna-center/api/v1/network-device" headers = { "X-Auth-Token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9..." } response = requests.get(url, headers=headers, verify=False) print(response.json()) What is a security concern with this script?

A.The script uses a hardcoded token, which is a security risk.
B.The script disables SSL certificate verification, making it vulnerable to man-in-the-middle attacks.
C.The script does not handle HTTP errors, which could expose sensitive information.
D.The script uses an incorrect URL; the path should be /dna/intent/api/v1/network-device.
AnswerB

Disabling SSL certificate verification with verify=False means the client accepts any certificate presented, including a forged one from a man-in-the-middle. This allows an attacker to intercept, decrypt, and modify traffic between the script and the DNA Center API, exposing credentials and data. In production, certificates should be validated against a trusted CA or internal enterprise CA. This is the most direct and exploitable security flaw in the script as written.

Why this answer

Setting `verify=False` in the `requests.get()` call disables SSL/TLS certificate validation. This means the client will not verify the identity of the Cisco DNA Center server, making the connection vulnerable to man-in-the-middle (MITM) attacks where an attacker could intercept or modify the API traffic. In production environments, certificate validation should always be enabled to ensure the authenticity of the server.

Exam trap

Cisco often tests the distinction between authentication token management (hardcoding) and transport security (SSL verification), leading candidates to incorrectly focus on the hardcoded token as the primary risk when the disabled certificate validation is the more critical security flaw in this specific context.

How to eliminate wrong answers

Option A is wrong because while hardcoded tokens are generally a security concern, the token shown is a valid JSON Web Token (JWT) that is typically short-lived and obtained via an authentication endpoint; the primary security flaw in this script is the disabled certificate verification, not the token storage. Option C is wrong because the script does not handle HTTP errors, but this is a reliability concern, not a security vulnerability; it does not directly expose sensitive information unless error responses contain such data, which is not indicated here. Option D is wrong because the URL used (`/api/v1/network-device`) is correct for the Cisco DNA Center API; the path `/dna/intent/api/v1/network-device` is used for the Intent API, but the script is using the base API, which is valid.

1328
Multi-Selecthard

Which three statements about NFV and its relationship with SDN are true? (Choose three.)

Select 3 answers
A.NFV can leverage SDN to dynamically create and manage network paths between VNFs.
B.SDN can provide the network abstraction that allows NFV to decouple network functions from underlying hardware.
C.NFV and SDN are independent technologies that can be deployed separately or together.
D.SDN is a prerequisite for implementing NFV in any network environment.
E.NFV requires SDN to perform service function chaining.
AnswersA, B, C

SDN controllers compute and program forwarding paths, letting NFV orchestration steer traffic dynamically between VNFs without manual configuration. This satisfies the stem's requirement that NFV can leverage SDN to create and manage network paths between virtual network functions.

Why this answer

Option A is correct because NFV commonly uses SDN controllers (e.g., OpenDaylight, ONOS) to program flow rules and dynamically establish paths between VNFs, enabling flexible traffic steering. Option B is correct because SDN's control/data plane separation and centralized abstraction let NFV decouple network functions from proprietary hardware, so VNFs can run on commodity servers with programmable connectivity. Option C is correct because NFV and SDN are complementary but architecturally independent: NFV virtualizes network functions, SDN centralizes control, and each can be deployed alone or together.

Option D is wrong because NFV can be implemented without SDN, for example using traditional routing and manual configuration. Option E is wrong because service function chaining can be achieved through other mechanisms such as overlay tunnels, policy-based routing, or dedicated appliances, not strictly SDN.

Exam trap

The trap here is the common misconception that NFV and SDN are interdependent or that one requires the other, leading candidates to incorrectly select options D or E.

1329
MCQmedium

A network engineer is troubleshooting a wireless network where clients in a conference room experience intermittent connectivity. The engineer notices that the access point in that room is showing a high number of CRC errors on its uplink interface. The AP is connected to a Cisco 9300 switch via a copper cable. What is the most likely cause of the CRC errors?

A.The AP is overloaded with too many clients.
B.The Ethernet cable is faulty or of poor quality.
C.The switch port is configured with a duplex mismatch.
D.The AP is not receiving enough power from Power over Ethernet (PoE).
AnswerB

CRC errors on a copper Ethernet link indicate that the receiving interface detected frames whose cyclic redundancy check did not match the computed value, which is almost always caused by electrical signal corruption. A faulty or low-quality cable (e.g., damaged pairs, improper termination, or crosstalk) introduces bit errors that corrupt the frame at the physical layer. This directly explains why the AP's wired uplink shows CRC errors while the rest of the switch port statistics appear normal.

Why this answer

CRC errors on an Ethernet interface indicate that frames are being received with invalid checksums, typically due to physical-layer issues such as signal degradation, crosstalk, or faulty cabling. Since the AP is connected via a copper cable to a Cisco 9300 switch, a faulty or poor-quality Ethernet cable is the most direct cause of these errors, as it can introduce bit errors that corrupt the frame's FCS.

Exam trap

Cisco often tests the distinction between CRC errors (physical layer) and duplex-mismatch errors (runts/giants/FCS), leading candidates to incorrectly choose duplex mismatch when the symptom is specifically CRC errors.

How to eliminate wrong answers

Option A is wrong because CRC errors are a Layer 1/physical-layer issue; an overloaded AP would cause client association or throughput problems, not CRC errors on the uplink. Option C is wrong because while duplex mismatch can cause frame errors, it typically manifests as runts, giants, or FCS errors on both sides, and modern switches with Auto-MDIX and IEEE 802.3u auto-negotiation rarely allow a mismatch unless manually misconfigured; CRC errors specifically point to cable or signal integrity issues. Option D is wrong because insufficient PoE power would cause the AP to fail to boot or to reboot intermittently, not to generate CRC errors on a functioning uplink.

1330
MCQhard

An enterprise is implementing Cisco TrustSec (CTS) to enforce role-based access control. The network engineer configures the switch with 'cts role-based enforcement' and 'cts manual' on an interface connecting to a trusted Cisco switch. The engineer also configures Security Group Tags (SGTs) on the RADIUS server. However, traffic between two hosts in different SGTs is not being filtered as expected. The engineer checks 'show cts role-based counters' and sees no drops. What is the most likely reason for the lack of enforcement?

A.The switch is not configured for 802.1X on the interface.
B.The 'cts manual' command is incorrect; 'cts dot1x' should be used instead.
C.The SGTs are not being propagated to the switch; the switch lacks SGT mappings for the hosts.
D.The 'show cts role-based counters' command shows no drops, indicating the ACLs are not configured.
AnswerC

This is correct because role-based enforcement in Cisco TrustSec depends entirely on the switch having a valid SGT mapping for the traffic source. If the SGT is not propagated via CTS/SXP/RADIUS or manually configured as an IP-SGT mapping, the switch cannot determine which SGT to assign to the hosts' traffic. Without that mapping, packets remain untagged or are assigned a default SGT, and the role-based ACL (RBACL) is never applied, so the expected drop does not happen. The root cause is the missing SGT propagation or mapping on the switch, not the interface mode.

Why this answer

Cisco TrustSec enforcement relies on the switch having the correct SGT-to-IP mapping for each host. Even if SGTs are assigned on the RADIUS server and CTS role-based enforcement is enabled, the switch must learn the SGT for each source IP address. Without these mappings, the switch cannot classify traffic into SGTs and therefore cannot apply role-based ACLs, resulting in no drops in the counters.

Exam trap

Cisco often tests the distinction between SGT assignment (via RADIUS) and SGT propagation (via SXP or manual mapping), leading candidates to assume that configuring SGTs on the RADIUS server alone is sufficient for enforcement.

How to eliminate wrong answers

Option A is wrong because 802.1X is not required for CTS manual mode; CTS manual uses pre-shared keys and static SGT assignments on the interface, not 802.1X authentication. Option B is wrong because 'cts manual' is the correct command for a trusted link to another Cisco switch; 'cts dot1x' is used for endpoint authentication, not switch-to-switch links. Option D is wrong because 'show cts role-based counters' showing no drops indicates that no packets are being matched by the role-based ACLs, which is consistent with missing SGT mappings, not with missing ACLs (the ACLs are likely configured but not triggered due to lack of classification).

1331
Multi-Selectmedium

A network engineer is deploying Cisco TrustSec in a campus network. The engineer needs to implement Security Group Tag (SGT) propagation and enforcement. Which two methods can be used to propagate SGTs? (Choose two.)

Select 2 answers
A.802.1X supplicant tagging
B.RADIUS Change of Authorization (CoA) tagging
C.SGT Exchange Protocol (SXP)
D.IPsec tunnel tagging
E.Inline tagging using Cisco Metadata (CMD)
AnswersC, E

SXP is a control-plane protocol that propagates IP-to-SGT mappings to devices that cannot perform inline tagging, such as older switches or firewalls. It allows SGTs to be shared across network boundaries, enabling enforcement on devices that lack hardware support for inline tagging. This is a standard method for SGT propagation in TrustSec.

Why this answer

SGTs can be propagated using inline tagging with Cisco Metadata (CMD), which embeds tags in the frame, or using SXP, which shares IP-to-SGT mappings with devices that cannot perform inline tagging. These two methods are standard in Cisco TrustSec deployments, enabling enforcement across diverse network devices.

Exam trap

The trap here is confusing authentication protocols like 802.1X or RADIUS CoA with SGT propagation methods, which are specifically inline tagging and SXP.

1332
MCQhard

A network engineer configures SNMPv3 on a Cisco router with the following: 'snmp-server group GRP v3 priv', 'snmp-server user usr GRP v3 auth sha pass1 priv aes 128 pass2'. The NMS is configured with the same credentials. However, the NMS cannot perform SNMP walks. The engineer notices that the router's SNMP agent is responding to queries from other devices. What is the most likely cause?

A.The user's authentication key is too short.
B.The group 'GRP' is not associated with a view that allows read access to the MIB tree.
C.The NMS is using SNMPv2c community strings instead of SNMPv3.
D.The router's SNMP engine ID has changed since the user was created.
AnswerB

Without a view clause, the group has no MIB access rights, so the agent silently drops or rejects the NMS's authenticated requests despite valid SHA/AES credentials. Other devices succeed because their groups map to views permitting read access, satisfying the walk requirement.

Why this answer

The 'snmp-server group GRP v3 priv' command creates an SNMPv3 group with privacy (encryption) but does not associate it with any view. By default, SNMPv3 groups have no read, write, or notify access unless a view is explicitly configured. Without a view that permits read access to the MIB tree, the NMS cannot perform SNMP walks, even though the router responds to other queries (e.g., from different groups or versions).

Exam trap

Cisco often tests the misconception that configuring SNMPv3 with authentication and privacy alone is sufficient for access, when in fact a view must be explicitly assigned to the group to allow read operations.

How to eliminate wrong answers

Option A is wrong because the authentication key length is not the issue; SHA keys can be any length, and Cisco truncates or hashes them to the required size. Option C is wrong because the NMS is configured with the same SNMPv3 credentials, and the router is responding to other devices, indicating SNMPv3 is functional; the problem is access control, not version mismatch. Option D is wrong because an engine ID change would cause authentication failures (the user's credentials would be invalidated), but the router is still responding to queries, so the engine ID is consistent.

1333
Multi-Selectmedium

Which three statements about FlexVPN are true? (Choose three.)

Select 3 answers
A.FlexVPN uses IKEv2 as its underlying key exchange protocol.
B.FlexVPN supports both site-to-site and remote access VPN topologies.
C.FlexVPN requires a dedicated AAA server for all authentication functions.
D.FlexVPN can use digital certificates or pre-shared keys for authentication.
E.FlexVPN uses NHRP to dynamically discover spoke routers and establish direct tunnels.
AnswersA, B, D

FlexVPN relies exclusively on IKEv2 for tunnel negotiation, unlike legacy DMVPN deployments that commonly use IKEv1. This satisfies the stem's requirement for a true FlexVPN statement, since IKEv2 provides the mandatory key exchange underpinning its unified configuration model, native redundancy, and per-peer policy flexibility.

Why this answer

Option A is correct because FlexVPN is built on IKEv2, which handles the key exchange and security association negotiation for both IPsec and FlexVPN tunnels. Option B is correct because FlexVPN is a unified framework that supports site-to-site, hub-and-spoke, and remote-access VPN topologies using the same IKEv2/IPsec infrastructure. Option D is correct because FlexVPN supports multiple authentication methods, including digital certificates (RSA/ECDSA) and pre-shared keys, as well as EAP-based methods.

Option C is incorrect because FlexVPN does not require a dedicated AAA server; local authentication or certificates can be used, and AAA is optional. Option E is incorrect because NHRP is used by DMVPN, not FlexVPN; FlexVPN uses IKEv2 routing and IPsec to establish tunnels without NHRP.

Exam trap

350-401 often tests the DMVPN-versus-FlexVPN distinction, baiting candidates into selecting NHRP as a FlexVPN feature because NHRP is so strongly associated with dynamic spoke discovery in DMVPN — remember NHRP is IKEv1/DMVPN, not FlexVPN.

1334
MCQeasy

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 192.168.1.0/24 BGP routing table entry for 192.168.1.0/24, version 15 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 65050, (received & used) 10.0.1.2 from 10.0.1.2 (10.0.0.2) Origin IGP, metric 0, localpref 100, weight 0, valid, external, best rx pathid: 0, tx pathid: 0x0 Based on this output, what can be concluded?

A.The route was learned from an internal BGP peer.
B.The route is from AS 65050 and is the best path.
C.The route has a local preference of 0.
D.The route is not valid because it is external.
AnswerB

The AS_PATH attribute in the output lists '65050', indicating that the route's origin is AS 65050 and that this prefix was advertised across the AS boundary from that autonomous system. Additionally, the route is flagged as 'best', meaning it has survived all tie-breaking steps in the BGP best-path selection algorithm and will be installed in the routing table. This combination of the correct origin AS and the 'best' flag makes this the only accurate statement.

Why this answer

The output shows the BGP table entry for 192.168.1.0/24 with path 65050, and the line 'valid, external, best' confirms that this route is from AS 65050 and is selected as the best path. The 'best' keyword in the status flags directly indicates that this path is the best among all available paths for this prefix.

Exam trap

Cisco often tests the distinction between 'valid' and 'best' — candidates may incorrectly assume that an external route is automatically invalid or that 'external' implies a problem, but the output clearly shows the route is both valid and best.

How to eliminate wrong answers

Option A is wrong because the route is learned from an external BGP peer (indicated by 'external' in the status flags and the neighbor IP 10.0.1.2, which is not in the same AS as the router's BGP configuration). Option C is wrong because the output explicitly shows 'localpref 100', not 0; local preference defaults to 100 for routes from external peers unless modified. Option D is wrong because the route is explicitly marked as 'valid' in the output, and being external does not make it invalid; external routes are valid if they pass BGP path validation.

1335
Matchingmedium

Drag and drop each Layer 2 attack on the left to its matching mitigation feature on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Port security

DHCP snooping

Dynamic ARP Inspection

BPDU guard

Disable Dynamic Trunking Protocol

Why these pairings

MAC flooding is mitigated by port security; DHCP starvation by DHCP snooping; ARP spoofing by DAI; STP manipulation by BPDU guard; VLAN hopping by disabling DTP.

1336
MCQmedium

A network engineer runs the following command on Router R1: R1# show policy-map interface GigabitEthernet0/1 GigabitEthernet0/1 Service-policy output: QOS_POLICY Class-map: VOICE (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp ef (46) Queueing queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 police cir 1000000 bc 15625 be 15625 conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: class-default (match-any) 100 packets, 10000 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any Queueing queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 100/10000 Based on this output, what can be concluded?

A.Voice traffic is being marked with DSCP EF and is being policed at 1 Mbps.
B.Voice traffic is not being classified because no packets match the VOICE class.
C.All traffic is being dropped due to the police action.
D.The policy-map is applied in the input direction.
AnswerB

This is the correct interpretation of the output. The VOICE class, which likely uses a class-map matching DSCP EF, shows 0 packets in the 'show policy-map interface' output, meaning no traffic has been classified into that class. This could be because voice traffic is absent, is not marked with DSCP EF at the source, or the match statement is misconfigured. As a result, the QoS actions (like police) inside the VOICE class have never been triggered.

Why this answer

The output shows 0 packets matched for the VOICE class, meaning no traffic has been classified as voice despite the policy being configured. The police action is configured but never triggered because no packets match the class. Therefore, the correct conclusion is that voice traffic is not being classified.

Exam trap

Cisco often tests the ability to read 'show policy-map interface' output carefully, where the trap is that candidates assume a configured policy is actively shaping or policing traffic without verifying the packet match counters.

How to eliminate wrong answers

Option A is wrong because while the policy does police voice traffic at 1 Mbps (cir 1000000), the output shows 0 packets matched, so voice traffic is not actually being marked or policed. Option C is wrong because the class-default shows 100 packets output with 0 drops, indicating traffic is being forwarded, not dropped. Option D is wrong because the command 'show policy-map interface' output explicitly states 'Service-policy output', meaning the policy is applied in the output direction, not input.

1337
Drag & Dropmedium

Drag and drop the steps of DNA Center network discovery and device sync into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Discovery starts with defining the discovery scope, running the discovery, adding discovered devices to inventory, syncing device details, and finally assigning devices to a site.

1338
MCQeasy

A company is deploying a virtual WAN optimizer (vWAAS) on a Cisco NFVIS host. The engineer needs to ensure that the vWAAS can intercept traffic between two VNFs running on the same host. The traffic currently flows directly between the VNFs without passing through the vWAAS. What should the engineer configure to redirect the traffic?

A.Create a service chain in NFVIS that places the vWAAS between the two VNFs.
B.Configure a static route on each VNF pointing to the vWAAS.
C.Enable WCCP on the vWAAS and configure the VNFs to use WCCP.
D.Use policy-based routing on the VNFs to forward traffic to the vWAAS.
AnswerA

In NFVIS, service chaining defines an ordered data path that steers traffic through a sequence of VNFs at the virtual switch level, so placing the vWAAS between the two VNFs ensures it inspects and optimizes traffic without requiring any routing changes inside the VNFs themselves. This is the native, supported method because NFVIS uses service chain rules to redirect traffic between the VNF's virtual interfaces, making the vWAAS operate as an inline service node. Configuring routes or policies on the VNFs would not provide the same guaranteed, ordered traffic steering and would be operationally cumbersome.

Why this answer

NFVIS supports service chaining, which allows an administrator to define a sequence of VNFs that traffic must traverse. By creating a service chain that places the vWAAS between the two VNFs, NFVIS will automatically redirect the traffic through the vWAAS using internal bridging or vSwitch forwarding rules, without requiring any configuration changes on the VNFs themselves.

Exam trap

The trap here is that candidates often assume traffic redirection between VNFs must be done at Layer 3 (routing) using static routes or PBR, but Cisco tests the understanding that NFVIS service chaining operates at Layer 2 within the hypervisor, providing transparent interception without modifying the VNFs.

How to eliminate wrong answers

Option B is wrong because static routes on the VNFs would only affect traffic destined for specific subnets, not intercept all traffic between them; moreover, the VNFs would need to know the vWAAS as a next hop, which does not solve the problem of redirecting traffic that currently flows directly. Option C is wrong because WCCP (Web Cache Communication Protocol) is designed for redirecting traffic to a cache engine or WAN optimizer in a network, but it requires WCCP support on the routers or switches, not on VNFs running on the same NFVIS host, and the VNFs themselves typically do not run WCCP. Option D is wrong because policy-based routing (PBR) on the VNFs would require modifying the routing configuration of each VNF, which is complex, not scalable, and defeats the purpose of using NFVIS service chaining to handle traffic redirection transparently at the hypervisor level.

1339
MCQeasy

A network engineer executes the following command on Router R2: R2# show ip sla configuration 1 IP SLAs Infrastructure Engine-II Entry number: 1 Owner: admin Tag: Type of operation to perform: icmp-echo Target address: 192.168.2.10 Source address: 192.168.2.1 Type Of Service parameter: 0x0 Request size (ARR data portion): 28 Operation timeout (milliseconds): 5000 Frequency (seconds): 60 Next Scheduled Start Time: Start Time already passed Group Scheduled : FALSE Life (seconds): Forever Entry Ageout (seconds): never Recurring (Starting Everyday, Starting Time: 00:00:01) Status of entry (SNMP RowStatus): Active Threshold (milliseconds): 5000 Distribution Statistics: Number of statistic hours kept: 2 Number of statistic distribution buckets kept: 1 Statistic distribution interval (milliseconds): 20 Enhanced History: Based on this output, what is the frequency of the IP SLA operation?

A.30 seconds
B.60 seconds
C.120 seconds
D.5000 milliseconds
AnswerB

The output line "Frequency (seconds): 60" directly states the interval at which the icmp-echo probe to 192.168.2.10 repeats, satisfying the stem's request for the operation's frequency. Frequency governs how often each cycle restarts, distinct from the 5000 ms timeout and threshold values shown.

Why this answer

The command output shows 'Frequency (seconds): 60', which directly indicates that the IP SLA operation repeats every 60 seconds. This is the correct answer because the frequency parameter defines the time interval between successive probe executions.

Exam trap

Cisco often tests the distinction between 'frequency' and 'timeout' values, as candidates may confuse the 5000-millisecond timeout with the 60-second frequency.

How to eliminate wrong answers

Option A is wrong because the output explicitly states 'Frequency (seconds): 60', not 30 seconds; a frequency of 30 seconds would require a different configuration. Option C is wrong because 120 seconds is not shown in the output; the frequency is clearly 60 seconds, not double that value. Option D is wrong because 5000 milliseconds is the operation timeout (5 seconds), not the frequency; the frequency is measured in seconds and is set to 60.

1340
MCQeasy

Which LACP mode must be configured on at least one side of an EtherChannel for the channel to establish?

A.Active
B.Passive
C.Desirable
D.On
AnswerA

Active is the correct choice because LACP Active mode proactively initiates the EtherChannel negotiation by sending LACP packets to the peer. It successfully forms a channel with a peer configured in either Active or Passive mode, making it the preferred mode for dynamic link aggregation in standards-based (IEEE 802.3ad) environments.

Why this answer

LACP (Link Aggregation Control Protocol) uses two modes: Active and Passive. For an EtherChannel to form, at least one side must be configured as Active, which actively sends LACP packets to negotiate the link. If both sides are Passive, neither will initiate negotiation, and the channel will not establish.

Exam trap

Cisco often tests the distinction between LACP and PAgP modes, and the trap here is that candidates confuse 'Desirable' (a PAgP mode) with an LACP mode, or assume 'Passive' can initiate the negotiation.

How to eliminate wrong answers

Option B (Passive) is wrong because a Passive interface waits to receive LACP packets from a peer; if both sides are Passive, no negotiation occurs and the channel fails to form. Option C (Desirable) is wrong because Desirable is a PAgP mode, not an LACP mode; PAgP is Cisco-proprietary and not part of the LACP standard (IEEE 802.3ad). Option D (On) is wrong because On is a static mode that forces the channel without any negotiation protocol; it does not use LACP at all and requires manual configuration on both sides.

1341
MCQhard

A network engineer is designing a campus network that must support rapid convergence and load balancing across multiple links. The design uses Cisco StackWise Virtual technology on a pair of Catalyst 9000 switches. The engineer wants to ensure that the control plane remains active on both switches and that traffic can be forwarded by both switches simultaneously. Which statement accurately describes the StackWise Virtual operation?

A.Both switches share a single control plane and a single management IP address, and both forward traffic.
B.Only one switch performs routing, while the other switch only performs Layer 2 switching.
C.One switch is active, and the other is standby; only the active switch forwards traffic.
D.The switches operate independently with separate control planes, and a First Hop Redundancy Protocol (FHRP) is required for gateway redundancy.
AnswerA

StackWise Virtual combines two physical switches into a single logical switch with one control plane and one management IP. Both switches actively forward traffic, and the control plane is distributed, allowing both to process control protocols. This provides active-active forwarding and simplified management, meeting the design goals.

Why this answer

StackWise Virtual creates a single logical switch from two physical switches, with one control plane and one management IP. Both switches actively forward traffic, providing active-active operation and eliminating the need for FHRP. This design supports rapid convergence and load balancing across links.

Exam trap

The trap here is assuming StackWise Virtual operates like a traditional active-standby high-availability pair, when in fact both switches are active and forward traffic.

1342
MCQhard

A network engineer is configuring a Cisco router to use TACACS+ for command authorization. The engineer configures 'aaa authorization commands 15 default group tacacs+ local'. When a user with privilege level 15 tries to execute the 'reload' command, the router sends an authorization request to the TACACS+ server. The server responds with an 'Access-Accept' but the command is still denied. The engineer checks the router's configuration and sees that 'aaa accounting commands 15 default start-stop group tacacs+' is also configured. What could be the issue?

A.The TACACS+ server's 'Access-Accept' response does not include the necessary authorization attributes to permit the 'reload' command, so the router denies it.
B.The 'aaa accounting commands 15' command is causing the router to send accounting records before authorization, which delays the response and causes a timeout.
C.The router's 'aaa authorization commands 15' should use 'group tacacs+' without 'local' to ensure only TACACS+ is used.
D.The user's privilege level on the router is not actually 15, despite the configuration.
AnswerA

In TACACS+, authentication and authorization are separate phases. An Access-Accept only confirms the user's identity; command authorization requires the server to explicitly send an authorization response with attributes such as 'permit' or the specific command (e.g., 'cmd=reload') to allow execution. Without any permitting AV pair, the router's authorization policy defaults to deny, so the 'reload' command is blocked despite a successful authentication.

Why this answer

The TACACS+ 'Access-Accept' response must include the specific command (e.g., 'reload') in an authorization attribute (like 'cmd=reload') for the router to permit it. Without these attributes, the router treats the response as a denial, even though the authentication succeeded. The 'local' fallback in the authorization command only applies if the TACACS+ server is unreachable, not when it responds without the required attributes.

Exam trap

Cisco often tests the misconception that an 'Access-Accept' response universally permits all actions, when in fact TACACS+ authorization requires explicit attributes for each command or service.

How to eliminate wrong answers

Option B is wrong because 'aaa accounting commands 15' sends accounting records after command execution (start-stop), not before authorization; it does not cause timeouts that would deny the command. Option C is wrong because including 'local' as a fallback is valid and not the cause of the denial; the issue is the server's response lacking authorization attributes, not the fallback method. Option D is wrong because the user's privilege level is irrelevant; the authorization is based on the command and the server's response, not the user's configured privilege level on the router.

1343
MCQmedium

A network engineer is building a Python script to retrieve the operational status of all GigabitEthernet interfaces from a Cisco IOS XE device. The script uses the requests library and sends a GET request to the RESTCONF URL https://10.1.1.1/restconf/data/ietf-interfaces:interfaces-state. The device returns HTTP 401 Unauthorized. The engineer has verified that the RESTCONF service is enabled and the URL is correct. Which action should be taken to resolve the issue?

A.Change the HTTP method from GET to POST to retrieve operational data.
B.Include HTTP Basic Authentication credentials in the request using the auth parameter of the requests library.
C.Add an Accept header with the value application/yang-data+json to the request.
D.Enable the NETCONF protocol on the device and use it instead of RESTCONF.
AnswerB

RESTCONF on Cisco IOS XE requires authentication for all requests. HTTP 401 Unauthorized explicitly means the request lacks valid credentials. Providing a username and password via HTTP Basic Authentication (e.g., requests.get(url, auth=('admin', 'password'))) supplies the necessary authentication, allowing the request to succeed if the credentials are correct and the user has sufficient privileges.

Why this answer

The HTTP 401 Unauthorized response indicates that the RESTCONF request lacked valid authentication. Cisco IOS XE devices require authentication for RESTCONF operations, typically using HTTP Basic Authentication. Adding the appropriate credentials via the requests library's auth parameter will allow the request to proceed.

Other changes, such as modifying headers or HTTP methods, do not address the authentication requirement.

Exam trap

The trap here is assuming that a 401 error is caused by an incorrect URL or missing header, rather than recognizing it as a clear indication of missing or invalid authentication credentials.

1344
MCQhard

A network engineer is using Cisco DNA Center's Intent API to automate the configuration of a new branch site. The engineer needs to create a new site hierarchy, assign devices to the site, and apply a template that configures VLANs and QoS. The engineer writes a Python script that calls the DNA Center APIs in sequence. After running the script, the site is created, and devices are assigned, but the template application fails with an error indicating that the device is not provisioned. What is the most likely missing step in the automation workflow?

A.The engineer must provision the devices to the site using the DNA Center provisioning API before applying templates.
B.The engineer must create a network profile that includes the template before assigning devices to the site.
C.The engineer must synchronize the devices with DNA Center by triggering a discovery job after site assignment.
D.The engineer must first add the devices to a fabric domain before applying templates.
AnswerA

In Cisco DNA Center, before a template can be applied to a device, the device must be provisioned to a site. Provisioning involves assigning the device to a site and configuring management IP, credentials, and other parameters. The Intent API has a provisioning endpoint that must be called after device assignment. Without provisioning, template application fails with an error indicating the device is not provisioned. This is the missing step.

Why this answer

Cisco DNA Center requires devices to be provisioned to a site before templates can be applied. Provisioning configures the device with the necessary management settings and associates it with the site. The Intent API provides a provisioning endpoint that must be called after assigning devices to the site.

Without this step, template application fails. The other options are either for different workflows (fabric, discovery) or not prerequisites.

Exam trap

The trap here is assuming that assigning a device to a site is sufficient for template application, when provisioning is a separate required step.

1345
MCQmedium

A network engineer is deploying a new branch office that uses Cisco SD-WAN with a single transport underlay. The design requires that the branch router participate in the SD-WAN fabric and establish control connections to the controllers. Which component must the engineer configure on the branch device to allow it to register with the SD-WAN controllers and receive policy from vManage?

A.A unique system IP address and organization name configured on the device
B.An IPsec pre-shared key matching the vBond controller
C.A VRF named TRANSPORT with an OSPF process advertising the system IP
D.A BGP autonomous system number peering with the vSmart controller
AnswerA

The system IP and organization name are the two identifiers the SD-WAN controllers use to authenticate and track a device. Without a matching organization name and a unique system IP, the device cannot establish control connections to vBond, vSmart, and vManage, so it will not receive centralized policy or join the overlay.

Why this answer

For a Cisco SD-WAN device to join the overlay, it must be configured with a unique system IP address and the same organization name as the controllers. These values are used during the initial vBond handshake and subsequent control connections to vSmart and vManage. Without them, the device cannot authenticate, receive centralized policy, or participate in the fabric.

Exam trap

The trap here is assuming that an underlay routing protocol such as BGP or OSPF with the controllers is required for registration, when in fact the SD-WAN control plane uses TLS/DTLS tunnels authenticated by organization name and system IP.

1346
MCQmedium

Examine the CoPP configuration: class-map match-any COPP_SSH match access-group name SSH_ACL ! policy-map COPP_POLICY class COPP_SSH police 10000 conform-action transmit exceed-action drop class class-default police 5000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY Which statement is true?

A.SSH traffic is limited to 10 kbps; all other control plane traffic is limited to 5 kbps.
B.All control plane traffic is limited to 10 kbps.
C.The class-default police rate is ignored because it is not explicitly matched.
D.The policy-map should be applied to an interface, not the control plane.
AnswerA

SSH class (COPP_SSH) is explicitly matched with a police rate of 10000 bps, so SSH control-plane packets conform to that 10 kbps limit. The class-default is configured with a police rate of 5000 bps, applying to all other control-plane traffic not matched by a specific class. Since CoPP uses a hierarchy where class-default catches unmatched traffic, the effective result is SSH at 10 kbps and everything else at 5 kbps.

Why this answer

The CoPP policy explicitly matches SSH traffic via the COPP_SSH class and applies a police rate of 10,000 bps (10 kbps) to it. All other control plane traffic falls into class-default, which is policed at 5,000 bps (5 kbps). The 'conform-action transmit exceed-action drop' ensures that traffic exceeding these rates is dropped, so SSH is limited to 10 kbps and all other control plane traffic to 5 kbps.

Exam trap

Cisco often tests the misconception that class-default is optional or ignored when not explicitly configured, but in reality it is always present and must be considered in CoPP policies to avoid unintended drops of essential control plane traffic.

How to eliminate wrong answers

Option B is wrong because it incorrectly states that all control plane traffic is limited to 10 kbps, ignoring the separate police rate of 5 kbps applied to class-default. Option C is wrong because class-default is explicitly matched in the policy-map and its police rate is not ignored; it is a default class that catches all unmatched traffic. Option D is wrong because CoPP policies are specifically designed to be applied to the control plane using the 'control-plane' command, not to an interface; applying it to an interface would not protect the control plane from CPU-bound traffic.

1347
MCQmedium

A network engineer writes the following Ansible playbook to configure an interface on a Cisco IOS-XE device: --- - hosts: routers gather_facts: no tasks: - name: Configure interface cisco.ios.ios_config: lines: - ip address 192.168.1.1 255.255.255.0 parents: interface GigabitEthernet0/1 What is the issue with this playbook?

A.The playbook will fail because the 'cisco.ios.ios_config' module requires the 'connection: network_cli' parameter in the play or inventory.
B.The playbook will work correctly because the module automatically detects the device type.
C.The playbook will fail because 'cisco.ios.ios_config' is not a valid module name.
D.The playbook will work but only if the device is running IOS-XE 16.9 or later.
AnswerA

ios_config is a network module in the cisco.ios collection, and Ansible must establish a persistent network_cli connection before it can send configuration commands. Without `ansible_connection: network_cli` in inventory or `connection: network_cli` at the play level, Ansible uses the default 'smart' connection, which cannot initialize the IOS CLI terminal plugin. The playbook therefore fails with a connection error rather than reaching the module logic.

Why this answer

The 'cisco.ios.ios_config' module requires the connection type to be set to 'network_cli' (or 'ansible.netcommon.network_cli') in the play or inventory, because it uses a persistent SSH connection to send CLI commands to the device. Without this setting, Ansible defaults to the 'smart' connection plugin, which does not support the network-specific module's requirements, causing the playbook to fail.

Exam trap

Cisco often tests the requirement for 'connection: network_cli' with network modules, and the trap here is that candidates assume the module will work with the default connection plugin or that the module name is invalid, when in fact the module is correct but the connection method is missing.

How to eliminate wrong answers

Option B is wrong because the module does not automatically detect the device type; it requires explicit connection settings and the correct collection (cisco.ios) to be installed. Option C is wrong because 'cisco.ios.ios_config' is a valid fully qualified collection name (FQCN) for the module in the cisco.ios collection, which is the standard way to reference it. Option D is wrong because the playbook's issue is not related to the IOS-XE version; it will fail regardless of the version due to the missing connection parameter.

1348
MCQmedium

Consider this VLAN configuration on a Cisco switch: vlan 10 name Sales vlan 20 name Engineering interface GigabitEthernet0/1 switchport mode trunk switchport trunk allowed vlan 10,20 What is missing if the switch needs to carry VLAN 30 traffic on this trunk?

A.VLAN 30 must be created and added to the allowed VLAN list on the trunk.
B.The trunk must be configured as an access port for VLAN 30.
C.The native VLAN must be changed to VLAN 30.
D.The switchport mode must be changed to dynamic desirable.
AnswerA

On an 802.1Q trunk, each VLAN must first exist in the switch's local VLAN database and then be explicitly included in the allowed VLAN list on the trunk interface. Without both steps, the switch filters frames for VLAN 30, even if the VLAN is defined elsewhere in the SD-Access fabric. The edge node must have a consistent local VLAN-to-SGT mapping, and traffic will be dropped in hardware if the VLAN is not present and permitted.

Why this answer

A trunk port only forwards traffic for VLANs that exist in the switch's VLAN database and are explicitly permitted in the allowed VLAN list. VLAN 30 is neither created (no 'vlan 30' command) nor added to the trunk's allowed list (missing 'switchport trunk allowed vlan add 30'), so the switch will drop any frames tagged with VLAN 30. Creating the VLAN and updating the allowed list ensures the trunk can forward VLAN 30 traffic.

Exam trap

Cisco often tests the misconception that simply creating a VLAN on the switch is enough for trunk traffic, but the allowed VLAN list must also be explicitly updated, or the trunk will drop frames for that VLAN.

How to eliminate wrong answers

Option B is wrong because an access port cannot carry multiple VLANs; it belongs to a single VLAN and strips the 802.1Q tag, which would break trunking for VLANs 10 and 20. Option C is wrong because changing the native VLAN to 30 does not allow VLAN 30 traffic on the trunk; the native VLAN is used for untagged frames on a trunk and does not add a new VLAN to the allowed list. Option D is wrong because dynamic desirable mode uses DTP to negotiate trunking but does not create VLANs or modify the allowed VLAN list; the issue is missing VLAN creation and allowed list configuration, not trunk mode negotiation.

1349
MCQmedium

Consider the following configuration snippet from a Cisco IOS-XE router: router eigrp 100 network 10.0.0.0 network 192.168.1.0 passive-interface default no passive-interface GigabitEthernet0/0 What is the effect of the passive-interface commands?

A.EIGRP hellos are suppressed on all interfaces except GigabitEthernet0/0.
B.EIGRP hellos are sent on all interfaces, but updates are blocked.
C.EIGRP adjacency is formed on all interfaces except GigabitEthernet0/0.
D.EIGRP is disabled on all interfaces.
AnswerA

Passive-interface default suppresses EIGRP hello packets on every interface, preventing neighbour adjacencies from forming there. The subsequent no passive-interface GigabitEthernet0/0 re-enables hellos on that specific interface, so adjacencies form only through Gi0/0. This satisfies the stem's requirement that EIGRP updates flow solely via the designated uplink.

Why this answer

The command 'passive-interface default' sets all interfaces to passive mode, meaning EIGRP hello packets are suppressed on all interfaces. The subsequent 'no passive-interface GigabitEthernet0/0' re-enables EIGRP hellos on that specific interface. Therefore, EIGRP hellos are sent only on GigabitEthernet0/0 and suppressed on all other interfaces.

This is a common configuration to prevent EIGRP from forming adjacencies on unwanted interfaces.

Exam trap

350-401 often tests the behavior of passive interfaces in different routing protocols, and candidates may confuse EIGRP's suppression of hellos with other protocols' behavior.

How to eliminate wrong answers

Option B is wrong because passive interfaces suppress hellos entirely, not just updates. Option C is wrong because passive interfaces do not form adjacencies; the 'no passive-interface' command enables hellos and thus adjacency formation on GigabitEthernet0/0, but the question asks about the effect of the passive-interface commands, which is to suppress hellos on all except GigabitEthernet0/0. Option D is wrong because EIGRP is not disabled; it is still running on the interfaces, but hellos are suppressed on passive ones.

1350
MCQeasy

A network engineer runs the following command on Router R1: R1# show vrf brief Name Default RD Protocols Interfaces CUSTOMER_A 65000:100 ipv4 Gi0/0.100 CUSTOMER_B 65000:200 ipv4 Gi0/0.200 MANAGEMENT 65000:999 ipv4 Gi0/1 Based on this output, what can be concluded?

A.All VRFs are using the same route distinguisher.
B.The MANAGEMENT VRF is used for customer traffic.
C.CUSTOMER_A and CUSTOMER_B are on the same physical interface but different subinterfaces.
D.The router is running MPLS L3VPN.
AnswerC

The correct interpretation is that CUSTOMER_A and CUSTOMER_B each use a subinterface on the same physical GigabitEthernet0/0 port: CUSTOMER_A is configured on Gi0/0.100 and CUSTOMER_B on Gi0/0.200. This is a classic VRF-lite design, where 802.1Q VLAN tags on trunk subinterfaces allow one physical link to carry traffic for multiple VRFs, with each subinterface mapped to a separate VRF. Segmenting customer traffic onto different subinterfaces of the same physical interface preserves isolation while reducing hardware port consumption.

Why this answer

The output shows that both CUSTOMER_A and CUSTOMER_B are associated with subinterfaces Gi0/0.100 and Gi0/0.200, which are subinterfaces of the same physical interface Gi0/0. This is a common design for MPLS L3VPN or VRF-lite deployments where multiple VRFs share a single physical link using 802.1Q VLAN tagging.

Exam trap

Cisco often tests the distinction between VRF-lite and MPLS L3VPN; the trap here is that candidates assume any VRF configuration implies MPLS is running, but the show vrf brief output alone does not confirm MPLS—it only shows VRF definitions and interface bindings.

How to eliminate wrong answers

Option A is wrong because each VRF has a different route distinguisher (65000:100, 65000:200, 65000:999), not the same. Option B is wrong because the MANAGEMENT VRF is typically used for out-of-band management traffic (e.g., SSH, SNMP), not for customer traffic; customer traffic is carried in CUSTOMER_A and CUSTOMER_B. Option D is wrong because the output does not show any MPLS-specific information (e.g., LDP, VRF forwarding with MPLS labels); the router could be using VRF-lite without MPLS.

Page 17

Page 18 of 26

Page 19