Courseiva

ENCOR 350-401 (350-401) — Questions 1351–1425

1923 questions total · 26pages · All types, answers revealed

Page 18

Page 19 of 26

Page 20
1351
Multi-Selecthard

A network automation team is using the NETCONF protocol to manage a fleet of Cisco IOS XE devices. They need to ensure that configuration changes are applied atomically and that they can roll back to a previous configuration if an error occurs. Which two NETCONF capabilities must be supported and used to achieve these requirements? (Choose two.)

Select 2 answers
A.:validate
B.:startup
C.:rollback-on-error
D.:writable-running
E.:candidate
AnswersC, E

The :rollback-on-error capability ensures that if any operation within a <commit> fails, the server automatically rolls back the entire transaction to the previous state. This provides automatic error recovery and guarantees atomicity. Without it, a partial commit could leave the device in an inconsistent state. This capability is crucial for the team's requirement to roll back on error.

Why this answer

To achieve atomic configuration changes and rollback, the :candidate and :rollback-on-error capabilities are required. The :candidate capability enables editing a candidate datastore and committing changes atomically. The :rollback-on-error capability ensures that if any part of the commit fails, the entire transaction is rolled back.

Together, they provide the transactional integrity and error recovery the team needs.

Exam trap

The trap here is assuming that :validate or :writable-running alone can provide atomicity and rollback, when they only offer validation or direct editing without transactional guarantees.

1352
MCQmedium

Consider the following configuration snippet on a Cisco IOS-XE router: interface GigabitEthernet0/1 ip address 10.1.1.1 255.255.255.0 ip pim sparse-mode ip igmp version 3 ! router ospf 1 network 10.1.1.0 0.0.0.255 area 0 ! What is the effect of this configuration?

A.The interface will participate in PIM sparse-mode and IGMPv3, but PIM sparse-mode requires an RP to be configured or learned.
B.The interface will operate in PIM dense-mode because no RP is configured.
C.IGMPv3 is incompatible with PIM sparse-mode and will be ignored.
D.The router will automatically use dense-mode because OSPF is enabled.
AnswerA

PIM sparse-mode is explicitly enabled on the interface with the ip pim sparse-mode command, which also activates IGMPv3 as the host membership protocol. In sparse mode, routers must send explicit join messages toward a rendezvous point (RP) to build multicast distribution trees. Without a configured or dynamically learned RP (e.g., via Auto-RP or BSR), the router cannot construct these shared trees, and multicast forwarding will fail. Therefore, the interface does participate in both PIM sparse-mode and IGMPv3, but the missing RP is a critical operational requirement.

Why this answer

The configuration explicitly enables PIM sparse-mode on the interface, which requires a rendezvous point (RP) to be known—either statically configured or dynamically learned via Auto-RP or BSR. The `ip igmp version 3` command enables IGMPv3, which is fully compatible with PIM sparse-mode and allows for source-specific multicast (SSM) support. OSPF is only used for unicast routing and does not affect PIM mode selection.

Exam trap

Cisco often tests the misconception that PIM sparse-mode automatically reverts to dense-mode when no RP is configured, but in reality, sparse-mode requires an explicit RP and will not forward traffic without one.

How to eliminate wrong answers

Option B is wrong because PIM sparse-mode does not fall back to dense-mode when no RP is configured; instead, the interface will simply not forward multicast traffic until an RP is learned. Option C is wrong because IGMPv3 is fully compatible with PIM sparse-mode and is actually required for SSM; it is not ignored. Option D is wrong because OSPF has no influence on PIM mode—PIM mode is determined solely by the `ip pim sparse-mode` or `ip pim dense-mode` command on the interface.

1353
MCQmedium

Refer to the exhibit. A network engineer has configured VRFs on a router. A packet arrives on Gi0/1/0 with destination IP 10.1.1.2. Which VRF is used for routing this packet?

A.Global routing table
B.Mgmt-intf
C.CUSTOMER-B
D.CUSTOMER-A
AnswerD

The packet enters via Gi0/1/0, and the exhibit shows this interface is configured in VRF CUSTOMER-A. When a packet arrives on an interface, the router immediately associates it with that interface's VRF and performs the destination IP lookup in the corresponding VRF-specific routing table. Because Gi0/1/0 belongs to CUSTOMER-A, the forwarding decision uses the routes, next hops, and constructs (e.g., VRF-specific ARP or CEF) belonging to CUSTOMER-A. This is why CUSTOMER-A is the correct answer.

Why this answer

The packet arrives on interface Gi0/1/0, which is configured under VRF CUSTOMER-A (as shown in the exhibit with 'ip vrf forwarding CUSTOMER-A'). When a VRF is applied to an ingress interface, the router uses that VRF's routing table (not the global table) to perform the destination IP lookup. Therefore, the packet with destination 10.1.1.2 is routed using the CUSTOMER-A VRF.

Exam trap

Cisco often tests the concept that the VRF used for routing is determined by the ingress interface's VRF assignment, not by the destination IP address or any other packet attribute, leading candidates to mistakenly assume the global table is used when no VRF is explicitly mentioned in the routing lookup.

How to eliminate wrong answers

Option A is wrong because the global routing table is used only when the ingress interface is not associated with any VRF, or when the VRF is explicitly bypassed (e.g., via 'ip route vrf' commands); here Gi0/1/0 is VRF-aware. Option B is wrong because 'Mgmt-intf' is a special VRF used exclusively for management traffic (e.g., SSH, SNMP) on the management interface, not for data-plane forwarding on Gi0/1/0. Option C is wrong because CUSTOMER-B is a different VRF; the interface Gi0/1/0 is bound to CUSTOMER-A, not CUSTOMER-B, so the router will not use CUSTOMER-B's routing table for this packet.

1354
MCQeasy

A network engineer is analyzing traffic patterns using Cisco IOS IP Service Level Agreements (IP SLA). The engineer wants to measure the round-trip time (RTT) for HTTP traffic to a web server at 10.1.1.1. Which IP SLA operation type should be configured?

A.icmp-echo
B.http
C.tcp-connect
D.udp-jitter
AnswerB

The HTTP operation type in IP SLA sends HTTP requests to a specified URL and measures the response time. It can be configured to use GET or RAW operations and can measure the time to establish a TCP connection, send the request, and receive the response. This directly measures HTTP traffic RTT, which is what the engineer wants. It is the correct choice for measuring HTTP performance.

Why this answer

The HTTP IP SLA operation is designed to measure the response time of HTTP requests. It sends a request to a web server and measures the time to receive the response. This provides the RTT for HTTP traffic.

Other operation types like ICMP echo, TCP connect, or UDP jitter do not measure application-layer HTTP performance. Therefore, the HTTP operation is the correct choice.

Exam trap

The trap here is confusing TCP connect with HTTP; TCP connect only measures the handshake, not the full HTTP request/response cycle.

1355
Matchingmedium

Drag and drop each EIGRP timer on the left to its matching default value on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

5 seconds

15 seconds

3 minutes

60 seconds

180 seconds

Why these pairings

Hello timer default is 5 seconds on LAN; Hold timer default is 15 seconds; Active timer default is 3 minutes.

1356
MCQeasy

A network engineer is configuring EtherChannel between two Cisco switches using LACP. The engineer wants to ensure that if fewer than two links are operational, the EtherChannel does not come up. Which command should be configured?

A.Configure 'port-channel min-links 2' under the port-channel interface.
B.Configure 'lacp min-bundle 2' under the port-channel interface.
C.Configure 'channel-group 1 mode active' on the physical ports.
D.Configure 'port-channel max-links 2' under the port-channel interface.
AnswerA

Configuring 'port-channel min-links 2' on the port-channel interface instructs the switch to bring the bundle into operation only when at least two member links are physically up and have completed negotiation. If the number of active links falls below this threshold, the port-channel is administratively shut down to prevent application traffic from relying on a single link with degraded bandwidth. This command is supported for both LACP and PAgP and is the correct method to enforce a minimum link count.

Why this answer

The 'port-channel min-links' command configures the minimum number of active member links required for the EtherChannel to become operational. When set to 2, the port-channel will not come up unless at least two links are active, meeting the engineer's requirement. This feature is supported by both LACP and PAgP, but is specifically configured under the port-channel interface.

Exam trap

Cisco often tests the distinction between 'min-links' and 'max-links' commands, and the trap here is that candidates may confuse 'min-links' with 'max-links' or incorrectly assume that setting the channel-group mode (active/passive) alone enforces a minimum link requirement.

How to eliminate wrong answers

Option B is wrong because 'lacp min-bundle 2' is not a valid Cisco IOS command; the correct command is 'lacp min-links' (though this is a less common alternative, the standard and correct command is 'port-channel min-links'). Option C is wrong because 'channel-group 1 mode active' enables LACP active mode on the physical ports, which is necessary for LACP negotiation but does not enforce a minimum number of operational links before the EtherChannel comes up. Option D is wrong because 'port-channel max-links 2' sets the maximum number of active links allowed in the bundle, not the minimum; it would limit the EtherChannel to two links but would not prevent it from coming up with fewer than two.

1357
Multi-Selectmedium

Which two statements about MPLS VPN (Layer 3 VPN) are true? (Choose two.)

Select 2 answers
A.PE routers maintain separate VRF tables for each VPN customer.
B.P routers must maintain a full routing table for each VPN customer.
C.MP-BGP is used to exchange VPNv4 routes between PE routers.
D.CE routers run MPLS and participate in label distribution with the PE.
E.The VPN label is used by P routers to forward traffic across the MPLS core.
AnswersA, C

Each PE router holds a separate VRF table per VPN customer, isolating that customer's routes and forwarding decisions. This satisfies the stem's Layer 3 VPN requirement by preventing overlapping customer address space from colliding, keeping each VPN's traffic logically separate across the shared provider backbone.

Why this answer

Option A is correct because in an MPLS Layer 3 VPN, each PE router instantiates a separate VRF (Virtual Routing and Forwarding) table per customer VPN, which keeps customer routes isolated and allows overlapping address spaces. Option C is correct because PE routers use MP-BGP (Multiprotocol BGP, specifically the VPNv4 address family) to exchange customer routes with the appropriate route targets and VPN labels. Option B is wrong because P routers only need to forward labeled packets based on the outer IGP/LDP label and do not hold per-VPN customer routing tables.

Option D is wrong because CE routers are typically plain IP routers that do not run MPLS or exchange labels with the PE. Option E is wrong because the inner VPN label is used by the egress PE (not the P routers) to identify the customer VRF; P routers forward based on the outer transport label.

Exam trap

350-401 often tests whether candidates confuse the roles of P, PE, and CE routers, and candidates frequently think P routers need per-VPN tables or that CE routers run MPLS, which is incorrect.

1358
MCQmedium

An Ansible playbook uses the cisco.dnac.site module to create a new building site. The playbook is: - name: Create building site cisco.dnac.site: host: "{{ dnac_host }}" username: "{{ dnac_username }}" password: "{{ dnac_password }}" validate_certs: no state: present site: name: Building-B type: building parentName: Area-1 address: "123 Main St" latitude: 37.7749 longitude: -122.4194 register: result What is the purpose of the 'parentName' parameter?

A.It specifies the name of the building's parent in the hierarchy, such as an area or global site.
B.It defines the DNS domain name for the building.
C.It sets the name of the network profile associated with the building.
D.It is used to specify the building's primary IP address.
AnswerA

The parentName parameter places the new building within the existing site hierarchy by naming its immediate parent, here Area-1. Cisco DNA Center requires this to attach Building-B beneath the correct area rather than at the global root.

Why this answer

The 'parentName' parameter specifies the name of the building's parent in the Cisco DNA Center site hierarchy, such as an area or the global site. In the cisco.dnac.site module, this parameter establishes the hierarchical relationship, ensuring the new building is created under the correct parent site (e.g., Area-1) rather than at the root level.

Exam trap

350-401 often tests whether candidates understand the DNA Center site hierarchy and the role of 'parentName' in establishing parent-child relationships; the trap is confusing it with DNS or network profile parameters.

How to eliminate wrong answers

Option B is wrong because 'parentName' does not define a DNS domain name; DNS settings are configured separately in network profiles or global settings. Option C is wrong because 'parentName' does not set a network profile name; network profiles are associated with sites via separate modules or settings. Option D is wrong because 'parentName' is not used for IP addressing; IP addresses are assigned to network devices and interfaces, not to site hierarchy objects.

1359
MCQmedium

An Ansible playbook uses the uri module to make a REST API call to Cisco DNA Center: --- - hosts: localhost gather_facts: no tasks: - name: Get devices uri: url: "https://dna-center/api/v1/network-device" method: GET headers: X-Auth-Token: "{{ token }}" return_content: yes register: result - debug: var: result.json What is missing from this playbook?

A.The playbook is missing a task to authenticate and obtain the X-Auth-Token before making the API call.
B.The playbook will work if the token is defined in the inventory file.
C.The playbook should use the 'cisco.dnac' collection instead of the uri module.
D.The playbook is missing the 'validate_certs: no' parameter to ignore SSL errors.
AnswerA

The DNA Center REST API is protected by token-based authentication. A playbook must first send a POST request to /dna/system/api/v1/auth/token using Basic Auth with valid credentials; the JSON response contains a Token field that must be passed in the X-Auth-Token header for all subsequent API calls. Without this initial task, the GET request in the playbook will be rejected with HTTP 401 Unauthorized, regardless of other settings.

Why this answer

The playbook attempts to call the Cisco DNA Center API using the `uri` module with a placeholder `{{ token }}` for the X-Auth-Token header, but it never performs the initial authentication step to obtain that token. Cisco DNA Center requires a POST request to `/api/system/v1/auth/token` with valid credentials (username/password) to receive a token, which must then be used in subsequent API calls. Without this authentication task, the playbook will fail because the token variable is undefined or invalid.

Exam trap

Cisco often tests the distinction between using a generic module like `uri` versus a dedicated collection, but the trap here is that candidates overlook the fundamental authentication prerequisite and focus on superficial issues like SSL certificates or inventory variables.

How to eliminate wrong answers

Option B is wrong because defining the token in the inventory file does not solve the missing authentication step; the token must be dynamically obtained from DNA Center via a POST request, not statically defined. Option C is wrong because the `cisco.dnac` collection is not required; the `uri` module is perfectly capable of making REST API calls, and the question focuses on the missing authentication logic, not the module choice. Option D is wrong because while `validate_certs: no` might be needed in lab environments with self-signed certificates, it is not the primary issue; the playbook will fail due to the missing token regardless of SSL validation settings.

1360
Matchingmedium

Drag and drop each IP SLA reaction action on the left to its corresponding behavior on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Send a log message

Send an SNMP notification

Start another IP SLA operation

Disable reaction

Trigger on probe timeout

Why these pairings

Syslog sends a log message; SNMP trap sends an SNMP notification; trigger starts another IP SLA operation; none disables reaction; timeout triggers on probe timeout.

1361
MCQmedium

A network engineer is using a Python script with the ncclient library to retrieve interface statistics from a Cisco IOS XE router. The script connects successfully, but when it sends a <get> RPC, the router returns an error stating that the requested data model is not supported. The engineer verifies that the YANG model is present on the device. What is the most likely cause of this error?

A.The script is using the wrong NETCONF port; it should use port 830 instead of 22.
B.The NETCONF session is using the default namespace urn:ietf:params:xml:ns:netconf:base:1.0 instead of the correct YANG namespace.
C.The ncclient library version is incompatible with the router's NETCONF implementation.
D.The YANG model is present but not enabled in the NETCONF capability set on the device.
AnswerD

For a YANG model to be accessible via NETCONF, it must be advertised in the device's NETCONF capabilities. Even if the model file exists, if it is not enabled or supported by the NETCONF server, requests will fail. The engineer should check the <hello> message for the model's namespace and revision. This is the most likely cause of the error.

Why this answer

The error indicates that the NETCONF server does not support the requested YANG model, even though the model file exists. In NETCONF, capabilities are advertised in the initial <hello> exchange. If a model is not listed there, it is not enabled for NETCONF access.

The engineer must verify the device's NETCONF capabilities and ensure the model is supported and enabled.

Exam trap

The trap here is assuming that the presence of a YANG file on the device automatically makes it available via NETCONF, when in fact it must be advertised as a capability.

1362
MCQhard

A network engineer runs the following command on Router R5: R5# show mpls ldp discovery Local LDP Identifier: 10.5.5.5:0 Discovery Sources: Interfaces: GigabitEthernet0/0: xmit/recv LDP Id: 10.5.5.4:0, no hello (expired) GigabitEthernet0/1: xmit/recv LDP Id: 10.5.5.6:0 Based on this output, what is the state of the LDP session with neighbor 10.5.5.4?

A.The LDP session with 10.5.5.4 is operational because the interface is in xmit/recv mode.
B.The LDP session with 10.5.5.4 is not established because no hello messages have been received from that neighbor.
C.The LDP session with 10.5.5.4 is down because the interface is not operational.
D.The LDP session with 10.5.5.4 is using targeted discovery.
AnswerB

A basic LDP session requires a hello adjacency, which is built only after receiving a valid hello from the peer. The output shows 'no hello (expired)', meaning the LDP hello holdtimer elapsed without any hello from 10.5.5.4. Therefore, the TCP connection and LDP session with that neighbor are not established, even though the local interface is in xmit/recv mode.

Why this answer

The output shows 'no hello (expired)' for the LDP neighbor 10.5.5.4, indicating that hello messages from that neighbor have not been received within the hello hold time. LDP sessions are established only after both routers exchange hello messages; without receiving hellos, the session cannot be formed. The 'xmit/recv' state on the interface means the router is transmitting and capable of receiving hellos, but the expired hello from the neighbor confirms the session is down.

Exam trap

Cisco often tests the distinction between LDP discovery (hello exchange) and LDP session establishment (TCP connection), so candidates mistakenly assume 'xmit/recv' means the session is up, when it only indicates the interface is participating in hello discovery.

How to eliminate wrong answers

Option A is wrong because 'xmit/recv' indicates the interface is enabled for LDP discovery (sending and listening for hellos), but it does not imply the LDP session is operational; the session requires successful hello exchange and TCP connection setup, which is absent here due to the expired hello. Option C is wrong because the interface is operational (shown as 'xmit/recv'), and the issue is not interface failure but the neighbor's hello messages timing out. Option D is wrong because the discovery source is listed under 'Interfaces' (link-local discovery), not 'Targeted Hellos', so this is basic LDP discovery on a directly connected link, not targeted discovery.

1363
MCQmedium

A network engineer is troubleshooting a Cisco Nexus 9000 leaf switch in a VXLAN EVPN fabric. Hosts in VLAN 200 on one leaf cannot reach hosts in VLAN 200 on a remote leaf, although the Type 2 routes are present in the EVPN table. The engineer confirms that the local VTEP address is correct. Which action should the engineer take to verify that the VNI is properly mapped to the VLAN and that traffic is placed into the correct overlay?

A.Run show ip route vrf all to confirm that the tenant prefixes are installed in the routing table
B.Run show bgp l2vpn evpn to confirm that the Type 2 routes are received from the remote leaf
C.Run show interface nve1 to confirm that the NVE interface is administratively up and has the correct source address
D.Run show vxlan vni to confirm the VNI-to-VLAN mapping and check the VXLAN interface state
AnswerD

The show vxlan vni command displays the mapping between VLANs and VNIs and indicates whether the VXLAN interface is up. If the VLAN-to-VNI mapping is missing or the VXLAN interface is down, hosts cannot be placed into the correct overlay, which matches the symptom of remote reachability failing despite EVPN routes being present.

Why this answer

The show vxlan vni command reveals the VLAN-to-VNI bindings and the state of the VXLAN interface, which is exactly what must be validated when hosts in the same VLAN cannot communicate across leaves despite EVPN routes being present. Routing table, EVPN table, and NVE interface checks address different layers and do not confirm the overlay mapping for VLAN 200.

Exam trap

The trap here is assuming that receiving EVPN routes proves the local overlay mapping is correct, when a missing VLAN-to-VNI binding still breaks forwarding.

1364
Drag & Dropmedium

Drag and drop the steps of the DiffServ traffic classification and marking pipeline into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In the DiffServ QoS pipeline, traffic must first be classified using class maps, then marked with a policy map, and finally applied to an interface using a service policy. The order ensures that packets are identified, marked, and then enforced on the egress interface.

1365
MCQmedium

Given the following configuration: interface Port-channel1 no switchport ip address 192.168.1.1 255.255.255.0 ! interface GigabitEthernet0/1 no switchport channel-group 1 mode on ! interface GigabitEthernet0/2 no switchport channel-group 1 mode on Which statement is true about this EtherChannel?

A.The EtherChannel will form only if the neighbor also uses LACP active mode.
B.The EtherChannel will form and operate as a Layer 3 routed interface.
C.The EtherChannel will not form because the interfaces are in no switchport mode.
D.The EtherChannel will form but will use PAgP negotiation.
AnswerB

This is correct. Applying 'no switchport' to the physical interfaces makes them routed Layer 3 ports, and 'channel-group X mode on' bundles them unconditionally into a port-channel. Because the member interfaces are all routed, the resulting port-channel also operates as a Layer 3 interface, allowing IP addresses to be assigned directly to the port-channel for routing.

Why this answer

The configuration uses `channel-group 1 mode on`, which forces the EtherChannel to form without any negotiation protocol (LACP or PAgP). Since both interfaces are configured with `no switchport` and an IP address is assigned to the Port-channel interface, the EtherChannel operates as a Layer 3 routed interface. Option B is correct because the channel will form and function as a routed port.

Exam trap

Cisco often tests the distinction between static (`mode on`) and dynamic (LACP/PAgP) EtherChannels, and the trap here is that candidates assume `mode on` requires a negotiation protocol or that `no switchport` prevents channel formation, when in fact it enables Layer 3 operation.

How to eliminate wrong answers

Option A is wrong because `mode on` does not use LACP; it forces the channel without negotiation, so the neighbor does not need to use LACP active mode. Option C is wrong because `no switchport` mode is required for a Layer 3 EtherChannel; the interfaces being in no switchport mode does not prevent the channel from forming. Option D is wrong because `mode on` does not use PAgP; it creates a static EtherChannel without any negotiation protocol.

1366
Multi-Selecthard

Which three statements about telemetry data collection methods are true? (Choose three.)

Select 3 answers
A.SNMP is a push-based telemetry method where agents send traps to the NMS.
B.Syslog messages can be used as a form of telemetry to report events and state changes.
C.Model-driven telemetry supports both periodic and event-driven subscriptions.
D.gNMI is a protocol used to retrieve and manipulate configuration state, and it also supports telemetry subscriptions.
E.Telemetry data can only be encoded in XML format.
AnswersB, C, D

Syslog sends event-driven data from devices to a collector, fitting the telemetry definition.

Why this answer

Option B is correct because syslog is a standard event-notification mechanism in which devices send severity-tagged messages about events and state changes to a collector, making it a valid (if unstructured) telemetry source. Option C is correct because model-driven telemetry (MDT) on platforms like IOS XE/NX-OS supports subscription types including periodic (sample-interval based) and event-driven (on-change) subscriptions, often configured via NETCONF/RESTCONF or gNMI. Option D is correct because gNMI (gRPC Network Management Interface) provides Get, Set, and Subscribe RPCs, so it both retrieves/manipulates configuration and state and carries streaming telemetry subscriptions.

Option A is not correct as stated: SNMP traps are indeed agent-initiated (push), but the option's framing is misleading because SNMP polling is pull-based and traps are only one part of SNMP, so it is not a true blanket statement about SNMP being push-based telemetry. Option E is not correct because telemetry data can be encoded in multiple formats, including JSON (e.g., JSON-IETF), Protobuf/GPB, and XML, so XML is not the only encoding.

Exam trap

350-401 often tests the misconception that SNMP is push-based (it is primarily pull-based) and that telemetry data is limited to XML encoding (it supports JSON and GPB as well).

1367
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip access-lists Extended IP access list 120 10 permit tcp 10.0.0.0 0.255.255.255 any eq 22 (5 matches) 20 permit tcp 172.16.0.0 0.0.255.255 any eq 22 (3 matches) 30 deny tcp any any eq 22 (2 matches) 40 permit ip any any (10 matches) Based on this output, what can be concluded?

A.SSH access from 192.168.1.0/24 would be denied.
B.SSH access from 10.0.0.0/8 is denied.
C.All SSH traffic is permitted.
D.The ACL has an implicit deny at the end.
AnswerA

Entry 30 of the ACL is an explicit deny statement for SSH traffic from any source IP address that has not already been permitted by entries 10 or 20. Because the source prefix 192.168.1.0/24 is outside the ranges specified in those earlier permit statements, it matches the wildcard condition of entry 30 and is denied. This occurs before the final permit-any statement (entry 40), which only applies to non-SSH traffic. Thus, SSH access from 192.168.1.0/24 is indeed denied.

Why this answer

The ACL 120 explicitly denies TCP traffic to port 22 (SSH) from any source not matching the earlier permit statements. The source 192.168.1.0/24 is not covered by the permit entries (10.0.0.0/8 or 172.16.0.0/16), so it hits line 30 (deny tcp any any eq 22) and is denied. The 5 matches on line 10 and 3 on line 20 confirm that only traffic from those specific subnets is permitted for SSH.

Exam trap

Cisco often tests the misconception that an implicit deny at the end of an ACL is the only reason traffic is blocked, ignoring that explicit deny entries can also block traffic and that the order of entries matters.

How to eliminate wrong answers

Option B is wrong because the ACL permits SSH traffic from 10.0.0.0/8 (line 10), as shown by the 5 matches. Option C is wrong because SSH traffic is not all permitted; line 30 explicitly denies SSH from any source not matching lines 10 or 20, and the 2 matches on line 30 confirm that some SSH traffic is blocked. Option D is wrong because while an implicit deny does exist at the end of every ACL, the explicit deny on line 30 is the reason SSH from 192.168.1.0/24 is blocked; the implicit deny would only apply to traffic not matching any explicit permit or deny, but here the explicit deny catches it first.

1368
Drag & Dropmedium

Drag and drop the steps of multicast RP discovery using Auto-RP into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Auto-RP uses a mapping agent that listens for RP announcements, then advertises the RP mapping via a well-known group; all routers learn the RP and use it for group-to-RP mapping.

1369
Drag & Dropmedium

Drag and drop the steps of VNF life cycle management into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order follows the ETSI NFV lifecycle: first onboard the VNF package, then instantiate the VNF, configure the VNF, scale the VNF as needed, and finally terminate the VNF when no longer required.

1370
MCQhard

A network engineer is configuring BGP on a Cisco router that is part of an enterprise network with multiple BGP peers. The router receives routes from two different ISPs. The engineer wants to ensure that only specific prefixes from ISP-A are installed in the routing table, while all other routes from ISP-A are ignored. Additionally, the engineer wants to accept all routes from ISP-B. Which BGP feature should be used on the router for the peering with ISP-A?

A.Apply a distribute list under the BGP neighbor configuration for ISP-A.
B.Configure a network statement under BGP for the desired prefixes.
C.Use the default-information originate command under BGP.
D.Apply a route map to the neighbor using the route-map command in the inbound direction.
AnswerA

Applying a distribute list under the BGP neighbor configuration for ISP-A creates an inbound path-filtering mechanism that evaluates each incoming BGP update against a referenced prefix list or access list. The distribute list examines only the NLRI's prefix and prefix length, permitting exactly the specified prefixes and silently ignoring all others before any other BGP policy is applied. This is the simplest and most targeted method for the stated requirement, as it does not involve attribute modification or complex conditional logic.

Why this answer

A distribute list applied under the BGP neighbor configuration for ISP-A allows the engineer to filter specific prefixes using an access list or prefix list, ensuring only the desired prefixes are installed in the routing table while all others from ISP-A are ignored. This is the correct tool for inbound route filtering on a per-neighbor basis, as it directly controls which routes are accepted into the BGP table and subsequently the routing table.

Exam trap

Cisco often tests the distinction between filtering incoming routes (distribute list or route map) versus originating routes (network statement) or generating defaults (default-information originate), leading candidates to confuse route map with distribute list when both can filter, but the question explicitly asks for the feature that 'should be used' and distribute list is the precise answer for prefix-only filtering without attribute manipulation.

How to eliminate wrong answers

Option B is wrong because a network statement under BGP is used to originate a prefix into BGP, not to filter incoming routes from a neighbor. Option C is wrong because the default-information originate command is used to generate a default route into BGP, not to filter specific prefixes from a peer. Option D is wrong because while a route map can be used for inbound filtering, the question specifies a distribute list as the correct feature; a route map is more complex and typically used for attribute manipulation, but a distribute list is the simpler, direct filtering mechanism for prefix-based control.

1371
MCQhard

A network engineer writes an Ansible playbook to gather facts from a Cisco IOS device using the ios_facts module: ```yaml --- - name: Gather IOS Facts hosts: ios_devices gather_facts: no tasks: - name: Collect facts cisco.ios.ios_facts: gather_subset: - hardware register: device_facts - name: Show serial number debug: msg: "Serial number is {{ device_facts['ansible_facts']['ansible_net_serialnum'] }}" ``` What is a potential issue with this playbook?

A.The 'gather_subset' parameter is misspelled; it should be 'gather_subset' (correct spelling).
B.The playbook is missing 'connection: network_cli' and 'become: yes' to enable network device access.
C.The registered variable 'device_facts' should be accessed as 'device_facts.ansible_facts.ansible_net_serialnum' using dot notation.
D.The 'hardware' subset is invalid; it should be 'all' to get serial number.
AnswerB

Network modules require the playbook to set 'connection: network_cli' and 'become: yes' so Ansible can interact with the device's CLI over SSH with privilege escalation. Without 'network_cli', the default 'smart' connection attempts to use the general SSH connection, which does not handle device prompts, terminal length, or enable mode correctly. 'become: yes' is needed to enter privileged exec mode on most Cisco IOS/CSR devices, especially for commands like 'show serial number' or 'show version' that require enable privileges.

Why this answer

Ansible network modules like cisco.ios.ios_facts require the connection type to be set to 'network_cli' (or 'ansible.netcommon.network_cli') and privilege escalation with 'become: yes' to interact with network devices. Without these, the playbook will fail to connect to the Cisco IOS device, as the default 'smart' connection is designed for Linux hosts, not network gear.

Exam trap

Cisco often tests the requirement for 'connection: network_cli' and 'become: yes' in Ansible playbooks for network devices, as candidates frequently assume the default connection works for all hosts.

How to eliminate wrong answers

Option A is wrong because 'gather_subset' is correctly spelled; the parameter name is 'gather_subset' in the cisco.ios.ios_facts module, not 'gather_subset' (the option text is a trick with identical spelling). Option C is wrong because both dot notation and bracket notation are valid in Jinja2; 'device_facts.ansible_facts.ansible_net_serialnum' would work equally well, so this is not a potential issue. Option D is wrong because the 'hardware' subset is valid and includes the serial number; 'all' is not required, and using 'all' would gather excessive facts unnecessarily.

1372
MCQmedium

A network engineer issues the following command on Router R6: R6# show ip sla statistics 5 Round Trip Time (RTT) for Index 5 Latest RTT: 150 ms Latest Operation Start Time: 16:00:00.000 UTC Mon Mar 1 2021 Latest Operation Return Code: OK Number of successes: 10 Number of failures: 0 Over thresholds: 8 Based on this output, what does the 'Over thresholds: 8' indicate?

A.8 probes failed to reach the target.
B.8 probes had RTT exceeding the configured threshold.
C.8 probes were sent in total.
D.The threshold is set to 150 ms.
AnswerB

The 'Over thresholds' counter in IP SLA statistics tracks how many successful probes had an RTT greater than the configured threshold. This counter is 8, meaning eight probes completed, but their round-trip time exceeded the threshold. These probes are not failures—they got a response—but they violate the SLA latency objective. Thus this option correctly interprets the number 8.

Why this answer

The 'Over thresholds: 8' field indicates that out of the 10 successful probes, 8 of them had a round-trip time (RTT) that exceeded the configured threshold value. This is a key performance metric in IP SLA that helps identify when network latency is degrading beyond acceptable limits, even though the probes themselves completed successfully (return code OK).

Exam trap

Cisco often tests the distinction between 'failures' (probes that did not receive a response) and 'over thresholds' (probes that succeeded but were slow), so candidates mistakenly assume 'over thresholds' means failed probes or total probes sent.

How to eliminate wrong answers

Option A is wrong because 'Over thresholds' counts probes that succeeded but exceeded the RTT threshold, not failed probes; failures are tracked separately in the 'Number of failures' field, which is 0. Option C is wrong because the total number of probes sent is the sum of successes (10) and failures (0), which equals 10, not 8. Option D is wrong because the output does not show the configured threshold value; it only shows the latest RTT (150 ms), and the threshold could be set to a lower value (e.g., 100 ms) to cause 8 over-threshold events.

1373
Matchingmedium

Drag and drop each telemetry protocol on the left to its matching transport on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

HTTP/2

gRPC

SSH

HTTPS

Not a standard telemetry transport

Why these pairings

gRPC uses HTTP/2, gNMI uses gRPC, NETCONF uses SSH, RESTCONF uses HTTPS, and HTTP is not a standard telemetry transport.

1374
Multi-Selectmedium

Which two statements about EIGRP feasible successors are true? (Choose two.)

Select 2 answers
A.A feasible successor must have a reported distance less than the feasible distance.
B.A feasible successor is immediately used when the successor fails, without any query process.
C.The feasible distance is the metric of the feasible successor route.
D.EIGRP will always have at least one feasible successor for every route.
E.The feasible successor is stored in the routing table as a backup route.
AnswersA, B

The feasibility condition requires a neighbour's reported distance to be strictly lower than the local feasible distance. Meeting this guarantees the path is loop-free, which is exactly what qualifies that neighbour as a feasible successor and satisfies the stem's stated criterion.

Why this answer

Option A is correct because the feasibility condition requires that a neighbor's reported distance (RD, the neighbor's own metric to the destination) be strictly less than the local feasible distance (FD, the current best metric), which guarantees the path is loop-free. Option B is correct because a feasible successor is a pre-validated loop-free backup already held in the EIGRP topology table, so when the successor fails EIGRP can promote it instantly to the routing table without sending queries or entering Active state. Option C is wrong because the feasible distance is the metric of the current successor (the best route), not of the feasible successor.

Option D is wrong because EIGRP does not guarantee a feasible successor exists for every route; if none satisfies the feasibility condition, the route goes Active and queries are sent. Option E is wrong because feasible successors are kept in the EIGRP topology table, not installed in the routing table, which holds only the best (successor) routes.

Exam trap

The trap is confusing the topology table with the routing table (feasible successors are not in the routing table) and misunderstanding the feasibility condition direction — candidates often think RD must be greater than FD or that a feasible successor is always available.

1375
MCQhard

An enterprise campus uses Cisco Catalyst 9000 switches in a StackWise Virtual configuration at the distribution layer. The network team wants dual-homed access switches to use all uplinks simultaneously while avoiding spanning-tree blocking, and they want the distribution pair to appear as a single logical device to routing peers. Which statement describes how StackWise Virtual supports this design?

A.The pair presents one control plane and a single management IP, and Multichassis EtherChannel allows access switches to use all uplinks without STP blocking.
B.The two chassis elect an active and standby supervisor, and only the active chassis forwards traffic at any time.
C.The pair requires VSS with a virtual switch domain and PAgP to form the virtual switch link between the two chassis.
D.The pair operates as two independent Layer 3 gateways that share a virtual IP using HSRP on each VLAN interface.
AnswerA

StackWise Virtual merges two Catalyst 9000 chassis into one logical switch with a unified control plane, one management address, and one configuration. Multichassis EtherChannel, an MEC, lets a downstream access switch bundle uplinks to both chassis into one port-channel, so all links forward and spanning tree sees a single logical neighbor. This satisfies both the bandwidth and the single-logical-device requirements in the distribution pair.

Why this answer

StackWise Virtual combines two Catalyst 9000 chassis into one logical switch with a shared control plane, one management IP, and one configuration. Multichassis EtherChannel lets downstream switches bundle uplinks to both chassis into a single port-channel, so all links actively forward while spanning tree sees one logical device, and routing peers see a single next hop.

Exam trap

The trap here is assuming that only the active chassis forwards traffic in StackWise Virtual, when both chassis actively forward data-plane traffic.

1376
MCQmedium

A network engineer is implementing IPsec VPN on a Cisco IOS XE router. The design requires that traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet be encrypted, while all other traffic should be sent unencrypted. The engineer creates a crypto ACL. Which action must be taken to ensure the crypto ACL correctly identifies the traffic to protect?

A.Configure the crypto ACL with 'permit ip any any' to ensure all traffic is encrypted, then use a route-map to exclude the non-interesting traffic.
B.Configure the crypto ACL with 'permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255' and ensure there is an implicit deny or an explicit deny for other traffic.
C.Configure the crypto ACL with 'deny ip any any' followed by 'permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255'.
D.Configure the crypto ACL with 'permit ip 10.1.1.0 0.0.0.255 any' to cover all destinations from the source subnet, then rely on the VPN peer to filter.
AnswerB

The crypto ACL defines interesting traffic by permitting the specific source and destination subnets. Only traffic matching a permit statement is encrypted. An implicit deny at the end means other traffic is not matched and therefore not encrypted, which aligns with the requirement to send other traffic unencrypted. This is the correct way to define the VPN traffic selector.

Why this answer

The crypto ACL must permit only the specific source and destination subnets that require encryption. Because ACLs have an implicit deny, traffic not matching the permit is not considered interesting and is sent unencrypted. This precisely implements the requirement to encrypt only traffic between 10.1.1.0/24 and 10.2.2.0/24.

Exam trap

The trap here is misunderstanding the implicit deny in a crypto ACL: placing an explicit deny before the permit would block the desired traffic from being encrypted.

1377
MCQmedium

Consider the following BGP configuration: router bgp 65000 bgp router-id 1.1.1.1 neighbor 10.1.1.2 remote-as 65001 neighbor 10.1.1.2 route-map SET_MED out ! route-map SET_MED permit 10 set metric 50 What is the effect of this configuration?

A.Routes advertised to 10.1.1.2 will have the MED set to 50, influencing inbound path selection in AS 65001.
B.Routes advertised to 10.1.1.2 will have the MED set to 50, influencing outbound path selection from AS 65000.
C.Routes received from 10.1.1.2 will have the MED set to 50.
D.The MED value will be set to 50 for all routes in the BGP table.
AnswerA

This route-map, applied outbound to neighbor 10.1.1.2, sets the Multi-Exit Discriminator (MED) to 50 for all prefixes sent to that peer. Because MED is an inbound path-selection metric, AS 65001 will prefer the lowest MED among paths to AS 65000, so this value of 50 makes this path less attractive than a lower-MED path, steering traffic away from this link when an alternative exists.

Why this answer

The route-map SET_MED is applied to outbound updates to neighbor 10.1.1.2, setting the MED (Multi-Exit Discriminator) attribute to 50. MED is a metric that influences inbound path selection in the neighboring AS (AS 65001), telling its routers which path to prefer when multiple entry points exist into AS 65000. Therefore, option A correctly describes the effect.

Exam trap

Cisco often tests the distinction between inbound and outbound route-map application, and the trap here is confusing that MED influences inbound path selection in the receiving AS, not outbound path selection from the advertising AS.

How to eliminate wrong answers

Option B is wrong because MED influences inbound path selection into the AS that advertises the routes, not outbound path selection from the advertising AS. Option C is wrong because the route-map is applied 'out' (outbound), not 'in' (inbound), so it affects routes sent to the neighbor, not received from it. Option D is wrong because the route-map only applies to routes advertised to neighbor 10.1.1.2, not to all routes in the BGP table.

1378
MCQmedium

In Cisco TrustSec, which component is responsible for assigning a Security Group Tag (SGT) to a user or device based on authentication?

A.The RADIUS server (ISE) assigns the SGT during authentication.
B.The switch dynamically assigns the SGT based on the MAC address.
C.The endpoint device sends its SGT in the EAPOL-Start message.
D.The SGT is derived from the VLAN ID assigned to the port.
AnswerA

During 802.1X authentication, the endpoint credentials are sent to ISE (the policy server). Upon validation, ISE returns a RADIUS Access-Accept message that carries the Security Group Tag (SGT) as a Cisco AV-pair (e.g., cisco-av-pair=...). The switch then programs this SGT for the session and uses it to enforce TrustSec policies, such as SGACLs. This ensures the classification is centralized, consistent, and dynamic based on the user or device identity.

Why this answer

In Cisco TrustSec, the Security Group Tag (SGT) is assigned by the RADIUS server—specifically Cisco ISE—during the 802.1X authentication process. When a user or device authenticates, ISE evaluates the authentication result and policy, then returns the SGT as a RADIUS attribute (e.g., Cisco-AVPair or MS-MPPE-Send-Key) in the Access-Accept message. The switch then uses this SGT to enforce security group-based access control (SGACL) for traffic from that endpoint.

Exam trap

Cisco often tests the misconception that the SGT is derived from the VLAN or assigned by the switch dynamically, when in fact it is a policy-based attribute returned by the RADIUS server (ISE) during authentication.

How to eliminate wrong answers

Option B is wrong because the switch does not dynamically assign an SGT based on MAC address; MAC address-based assignment is a static method that requires manual configuration (e.g., 'cts role-based sgt' on the switch) and is not dynamically assigned during authentication. Option C is wrong because the endpoint device never sends an SGT in the EAPOL-Start message; EAPOL-Start is used to initiate 802.1X authentication and contains no SGT information—the SGT is assigned by the RADIUS server after successful authentication. Option D is wrong because the SGT is not derived from the VLAN ID; VLAN ID and SGT are separate constructs—VLANs segment Layer 2 traffic, while SGTs are used for scalable security group policy enforcement independent of VLAN assignment.

1379
MCQhard

A network engineer configured a Cisco IOS-XE router with VRF CUSTOMER_A and assigned Gi0/0/1 to it. The interface is up and has an IP address, but traffic sourced from the VRF cannot reach a remote prefix that is present in the global routing table. The engineer confirms the global route exists and the next hop is reachable. What is the most likely cause?

A.The interface must be configured with the ip vrf forwarding command a second time
B.The global routing table entry is a recursive route that cannot be resolved
C.CEF is disabled on the router, forcing all traffic to be process-switched
D.The VRF has no route to the destination and requires route leaking or a default route
AnswerD

A VRF maintains its own separate routing and forwarding table, so prefixes in the global table are not automatically visible inside CUSTOMER_A. Because the destination prefix exists only in the global table, the VRF has no matching route and drops the traffic. The engineer must either leak the global prefix into the VRF or provide a default route within the VRF.

Why this answer

VRFs create fully isolated routing and forwarding tables on the same physical router. A prefix installed in the global table is not automatically available inside a VRF, and vice versa. To allow the VRF to reach that destination, the engineer must either redistribute or leak the route between the global table and the VRF, or install a default route inside the VRF.

Exam trap

The trap here is assuming that a route visible in the global routing table is automatically usable by traffic sourced inside a VRF.

1380
MCQmedium

A network engineer is using the Cisco SD-WAN vManage API to automate the creation of a new VPN template. The engineer sends a POST request to /dataservice/template/feature with a JSON body and receives an HTTP 400 Bad Request error. The JSON payload is syntactically valid. What is the most likely cause of this error?

A.The API endpoint URL is incorrect and should include the '/template/feature' path without '/dataservice'.
B.The request must use HTTP instead of HTTPS because vManage does not support TLS for API calls.
C.The JSON payload contains a field value that violates the template schema, such as an invalid IP address format.
D.The request is missing the 'X-XSRF-TOKEN' header required for CSRF protection.
AnswerC

An HTTP 400 Bad Request in vManage often indicates that the request body fails validation against the expected schema. Even if JSON syntax is correct, semantic errors like invalid IP addresses, missing required fields, or incorrect data types cause the API to reject the payload. Correcting the field values to match the template schema resolves the issue.

Why this answer

An HTTP 400 Bad Request from the vManage API indicates that the server cannot process the request due to client error, often because the JSON payload fails schema validation. Even with valid JSON syntax, incorrect field values or missing required attributes cause rejection. The engineer should validate the payload against the template schema and correct any semantic errors.

Exam trap

The trap here is assuming that a 400 error always means malformed JSON syntax, when it can also result from valid JSON that violates the API's schema requirements.

1381
MCQmedium

A network engineer runs the following command on a Cisco WLC: WLC# show ap inventory all AP Inventory Information ----------------------- AP Name: AP-1 Base MAC: aabb.cc00.0100 Model: AIR-CAP3702I-A-K9 Software: 8.5.151.0 AP Name: AP-2 Base MAC: aabb.cc00.0200 Model: AIR-AP2802I-B-K9 Software: 8.5.151.0 AP Name: AP-3 Base MAC: aabb.cc00.0300 Model: AIR-AP3802I-A-K9 Software: 8.5.151.0 Based on this output, what can be concluded?

A.All APs are running the same software version and are compatible with the WLC.
B.AP-1 is a lightweight AP and AP-2 and AP-3 are autonomous APs.
C.AP-3 has a hardware failure because its model is different.
D.The WLC is running a software version that only supports AP-2 and AP-3.
AnswerA

In a WLC-centric deployment, all access points must run a software release that is supported by and interoperable with the controller's firmware. Here, every AP displays the identical version 8.5.151.0, which indicates a uniform, compatible codebase. This consistency, combined with the WLC successfully listing them without join errors, confirms that all APs are running the same software and are fully compatible with the WLC.

Why this answer

The output shows all three APs (AIR-CAP3702I-A-K9, AIR-AP2802I-B-K9, AIR-AP3802I-A-K9) are running software version 8.5.151.0, which is a valid Cisco IOS-XE release for the WLC. All listed models are lightweight (CAPWAP-based) APs that are compatible with a Cisco WLC running the same major code train. The WLC can manage mixed-model APs as long as they are supported in its software release, and version 8.5.151.0 supports these 3700, 2800, and 3800 series APs.

Exam trap

Cisco often tests the misconception that AP model numbers with 'CAP' versus 'AP' indicate autonomous vs. lightweight mode, but in reality, both prefixes can denote lightweight APs; the key differentiator is the software image and the presence of a WLC in the network.

How to eliminate wrong answers

Option B is wrong because all three APs are lightweight (CAPWAP) APs, as indicated by the 'AIR-CAP' and 'AIR-AP' prefixes (the 'C' in CAP stands for Controller-based, and 'AP' without 'C' still denotes a lightweight AP in this context; autonomous APs would have a different model number like AIR-AP3800I-A-K9 without the 'C' but still require a different software image). Option C is wrong because having a different model (AIR-AP3802I-A-K9) does not indicate hardware failure; the WLC inventory command shows operational APs, and model diversity is normal in a mixed deployment. Option D is wrong because the WLC software version 8.5.151.0 supports all three AP models listed; there is no indication that only AP-2 and AP-3 are supported.

1382
Multi-Selectmedium

A network engineer is analyzing the output of 'show ip sla statistics' on a Cisco IOS router. The engineer notices that the SLA operation is returning 'Timeout' for several probes. Which two statements are true about the potential causes of this issue? (Choose two.)

Select 2 answers
A.The timeout value may be set too low for the network latency.
B.The target device may be unreachable due to a routing issue.
C.The source interface may not have a valid IP address configured.
D.The SLA operation may be using an unsupported protocol type.
E.The SLA operation may be configured with an incorrect frequency.
AnswersA, B

If the timeout value is set lower than the actual round-trip time, the probe will time out even if the response eventually arrives. This is common in high-latency networks. Adjusting the timeout to accommodate network conditions can resolve the timeouts.

Why this answer

Timeouts in IP SLA statistics indicate that the probe packets are not receiving a response within the configured timeout period. This can be caused by the target being unreachable due to routing or ACL issues, or by the timeout value being too low relative to network latency. Both conditions prevent the successful completion of the probe, leading to timeouts.

Exam trap

The trap here is confusing timeout with other failures like 'unreachable' or 'error', and assuming that configuration errors like frequency or unsupported protocol cause timeouts, when they typically cause different symptoms.

1383
MCQmedium

A network engineer issues the following command on Router R3: R3# show ip bgp summary BGP router identifier 10.0.0.3, local AS number 65003 BGP table version is 12345, main routing table version 12345 Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 192.168.1.1 4 65001 12345 12345 12345 0 0 1w2d 150 192.168.1.2 4 65002 12345 12345 12345 0 0 2w0d 200 Based on this output, what can be concluded?

A.Both BGP neighbors are in the 'Idle' state.
B.Router R3 has received a total of 350 prefixes from its BGP neighbors.
C.The BGP session with 192.168.1.1 is down.
D.Router R3 is in AS 65001.
AnswerB

The State/PfxRcd column of show ip bgp summary lists how many BGP prefixes have been accepted from each specific neighbor. Router R3's output shows 150 prefixes from one neighbor and 200 from the other, and adding these two independent count values yields 350 total received prefixes. This total represents all successful UPDATE messages that R3 has processed from its two peers, not a mere administrative distance or route metric.

Why this answer

The 'State/PfxRcd' column shows the number of prefixes received from each neighbor. Router R3 has received 150 prefixes from 192.168.1.1 and 200 prefixes from 192.168.1.2, totaling 350 prefixes. This confirms that both BGP sessions are established and exchanging routes.

Exam trap

Cisco often tests the misinterpretation of the 'State/PfxRcd' column, where candidates mistakenly think a numeric value indicates a state like 'Idle' or 'Active', rather than understanding it represents the number of received prefixes.

How to eliminate wrong answers

Option A is wrong because both neighbors show an Up/Down time (1w2d and 2w0d) and a prefix count, indicating they are in the 'Established' state, not 'Idle'. Option C is wrong because the Up/Down time of 1w2d and a prefix count of 150 for 192.168.1.1 clearly show the session is up and exchanging routes. Option D is wrong because the output shows 'local AS number 65003', meaning Router R3 is in AS 65003, not AS 65001.

1384
MCQeasy

A network engineer is using the Cisco SD-WAN vManage REST API to retrieve a list of all devices in the overlay network. The engineer writes a Python script that sends a GET request to https://vmanage-ip/dataservice/device but receives a 401 Unauthorized error. What is the most likely reason for this error?

A.The script is missing the X-XSRF-TOKEN header.
B.The script has not obtained a valid session token via the /j_security_check endpoint.
C.The script is using the wrong HTTP method; it should use POST instead of GET.
D.The script is using HTTP instead of HTTPS.
AnswerB

The vManage REST API requires authentication using a session token. The client must first POST credentials to /j_security_check to obtain a JSESSIONID cookie, which is then included in subsequent requests. Without this token, the server returns 401 Unauthorized. The script must authenticate before accessing /dataservice/device. This is the most likely cause of the error.

Why this answer

The Cisco SD-WAN vManage REST API requires authentication via a session token. The client must POST credentials to /j_security_check to obtain a JSESSIONID cookie, which is then used in subsequent requests. Without this token, any request to protected endpoints like /dataservice/device returns 401 Unauthorized.

The engineer must implement the authentication step before retrieving device data.

Exam trap

The trap here is assuming that basic authentication or a simple API key is sufficient, when vManage requires a session-based token obtained from /j_security_check.

1385
Drag & Dropmedium

Drag and drop the steps of DNA Center assurance issue detection and root cause analysis into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Assurance starts with collecting telemetry, detecting an anomaly, raising an issue, correlating data for root cause, and then recommending a remediation action.

1386
MCQmedium

A network team is using Ansible to manage a fleet of Cisco IOS XE switches. The team wants to ensure that the Ansible playbook can connect to the switches without prompting for passwords and without storing passwords in plaintext. The team has generated an SSH key pair and copied the public key to the switches. Which Ansible connection method and authentication mechanism should the team use?

A.Use the local connection with SSH key-based authentication.
B.Use the network_cli connection with SSH key-based authentication.
C.Use the ssh connection with password authentication stored in an Ansible vault.
D.Use the netconf connection with SSH key-based authentication.
AnswerB

The network_cli connection plugin is designed for network devices and supports SSH key-based authentication. By copying the public key to the switches, Ansible can authenticate using the private key without passwords. This meets the requirement of no password prompts and no plaintext passwords. The network_cli plugin handles the SSH session and CLI interaction.

Why this answer

For Cisco IOS XE switches, Ansible uses the network_cli connection plugin to establish SSH sessions and send CLI commands. SSH key-based authentication allows passwordless login by using the private key on the control node, with the public key installed on the switches. This avoids plaintext passwords and interactive prompts.

Other connection plugins like ssh or local are not suitable for network device CLI management.

Exam trap

The trap here is choosing the generic ssh connection plugin for network devices, which is incorrect because network devices require the network_cli plugin for proper CLI interaction.

1387
MCQmedium

A network engineer is implementing a CI/CD pipeline for network configuration changes. The pipeline uses Git for version control and Jenkins for orchestration. The engineer wants to ensure that configuration changes are validated before deployment to production devices. Which approach best integrates validation into the pipeline?

A.Run a syntax check using a YANG model validator against the proposed configuration before merging.
B.Use SNMP traps to detect configuration errors after deployment.
C.Manually review the configuration changes in a change advisory board meeting.
D.Apply the configuration directly to production devices and monitor for errors.
AnswerA

Using a YANG model validator ensures the configuration adheres to the device's data model, catching syntax and semantic errors early. This validation can be automated in the CI pipeline, preventing invalid configurations from being deployed. It aligns with infrastructure-as-code best practices.

Why this answer

Integrating YANG model validation into the CI pipeline allows automated checks against device data models, ensuring configurations are syntactically and semantically correct before deployment. This proactive approach reduces errors and aligns with CI/CD best practices for network automation.

Exam trap

The trap here is thinking that post-deployment monitoring or manual review is sufficient, when CI/CD emphasizes automated pre-deployment validation to catch issues early.

1388
MCQhard

An Ansible playbook uses the cisco.nxos.nxos_config module to configure a Nexus switch: --- - hosts: nxos_switches gather_facts: no connection: network_cli tasks: - name: Configure VLAN cisco.nxos.nxos_config: lines: - vlan 100 - name Test_VLAN parents: vlan 100 What will be the result of this playbook?

A.The playbook will successfully create VLAN 100 and set its name to Test_VLAN.
B.The playbook will fail because the 'parents' parameter cannot be the same as the lines.
C.The playbook will fail because 'cisco.nxos.nxos_config' does not support VLAN configuration.
D.The playbook will work but only if the Nexus switch runs NX-OS 7.0 or later.
AnswerB

The module's parents parameter is designed to provide the configuration context under which the lines should be applied. When you set parents to 'vlan 100' and simultaneously include 'vlan 100' in the lines list, the module builds a configuration hierarchy where 'vlan 100' appears as a subcommand of itself. NX-OS rejects this invalid nested structure because a command cannot serve as its own parent. Therefore, the module raises an error and the intended VLAN configuration is never applied.

Why this answer

The `parents` parameter in the `cisco.nxos.nxos_config` module specifies the parent configuration context (e.g., `vlan 100`) under which the `lines` should be applied. When `lines` includes the same command as `parents` (e.g., `vlan 100`), it creates a conflict because the module attempts to enter the parent context and then apply the line again, which is invalid in NX-OS CLI syntax. This results in a playbook failure.

Exam trap

The trap here is that candidates assume the `parents` parameter is optional or that overlapping commands are harmless, but Cisco tests the precise understanding that `parents` defines the configuration context and must not duplicate commands in `lines`.

How to eliminate wrong answers

Option A is wrong because the playbook will not successfully create VLAN 100 and set its name; it will fail due to the invalid `parents` and `lines` overlap. Option C is wrong because the `cisco.nxos.nxos_config` module does support VLAN configuration via CLI lines, as it can send any valid NX-OS configuration commands. Option D is wrong because the playbook's failure is not related to the NX-OS version; the issue is with the Ansible module's parameter usage, which is independent of the switch OS version.

1389
MCQmedium

Given this configuration: interface GigabitEthernet0/0 ip address 172.16.1.1 255.255.255.0 ip pim sparse-mode ! interface GigabitEthernet0/1 ip address 172.16.2.1 255.255.255.0 ip pim sparse-mode ! ip pim rp-address 172.16.1.1 What is the effect of this configuration?

A.The router uses 172.16.1.1 as the RP for all multicast groups, and PIM sparse-mode is enabled on both interfaces.
B.The router will automatically elect an RP using BSR because no RP is configured.
C.PIM dense-mode is used because sparse-mode is not fully configured.
D.The configuration is invalid because the RP address must be a loopback interface.
AnswerA

This configuration is correct because the command 'ip pim rp-address 172.16.1.1' statically designates 172.16.1.1 as the rendezvous point for all multicast groups, and the accompanying 'ip pim sparse-mode' statements on both interfaces ensure PIM operates in sparse mode, which is required for RP-based multicast forwarding. Static RP assignment takes precedence over dynamic mechanisms like Auto-RP or BSR, and it applies globally to all groups unless a group-list qualifier is specified. With sparse-mode enabled, receivers explicitly join via the RP, and senders register with the RP, establishing the shared tree before potentially switching to the shortest path tree.

Why this answer

The configuration statically assigns 172.16.1.1 as the RP for all multicast groups using the 'ip pim rp-address' command, and both interfaces are explicitly configured with 'ip pim sparse-mode'. This ensures that PIM sparse-mode is operational on the interfaces and that the router uses the specified RP for group-to-RP mapping, making option A correct.

Exam trap

Cisco often tests the misconception that the RP must be a loopback interface for stability, but the command accepts any reachable IP address, including a physical interface, as long as it is configured with 'ip pim sparse-mode' or 'ip pim sparse-dense-mode'.

How to eliminate wrong answers

Option B is wrong because an RP is explicitly configured with 'ip pim rp-address 172.16.1.1', so the router will not use BSR for automatic RP election. Option C is wrong because PIM sparse-mode is fully configured on both interfaces and an RP is defined; PIM dense-mode is not used. Option D is wrong because the RP address does not need to be a loopback interface; it can be any IP address reachable by the router, including a physical interface address like 172.16.1.1.

1390
MCQmedium

A network administrator is deploying a Cisco Catalyst switch with DHCP snooping. The switch is configured with DHCP snooping globally and on VLAN 10. A DHCP server is connected to GigabitEthernet1/0/5, and client devices are connected to GigabitEthernet1/0/6 through 1/0/20. The administrator notices that DHCP offers from the server are being dropped. What is the most likely cause?

A.The DHCP snooping database agent is not configured.
B.The client ports are configured as trusted.
C.DHCP snooping is not enabled on the VLAN of the client ports.
D.The DHCP server port is not configured as trusted.
AnswerD

DHCP snooping drops DHCP server messages (OFFER, ACK) received on untrusted ports. By default, all ports are untrusted. The port connected to the DHCP server must be explicitly configured with 'ip dhcp snooping trust' to allow server responses. Since the server is on GigabitEthernet1/0/5 and is not trusted, its offers are dropped, matching the symptom.

Why this answer

DHCP snooping treats all ports as untrusted by default and drops DHCP server messages received on untrusted ports. To allow legitimate DHCP server responses, the port connected to the DHCP server must be configured with 'ip dhcp snooping trust'. In this scenario, the server port GigabitEthernet1/0/5 is untrusted, so offers are dropped.

Trusting the server port resolves the issue while maintaining protection against rogue DHCP servers on client ports.

Exam trap

The trap here is assuming that enabling DHCP snooping globally and on the VLAN is sufficient, when in fact the server-facing port must also be explicitly trusted.

1391
Multi-Selectmedium

A network engineer is comparing the characteristics of agent-based and agentless automation tools for managing Cisco IOS XE devices. Which two statements accurately describe agentless automation? (Choose two.)

Select 2 answers
A.Agentless tools often rely on APIs or CLI scraping to push configuration changes.
B.Agentless tools provide real-time telemetry streaming from devices without additional configuration.
C.Agentless tools are unable to manage devices from multiple vendors.
D.Agentless tools require a persistent agent to be installed on each managed device.
E.Agentless tools typically use SSH or HTTPS to communicate with network devices.
AnswersA, E

Agentless tools interact with devices using existing interfaces like RESTCONF, NETCONF, or SSH CLI. They may parse CLI output or use structured APIs to apply changes. This approach avoids installing software on devices. This statement is correct and highlights how agentless tools operate.

Why this answer

Agentless automation tools, such as Ansible, do not require software on the managed devices. They communicate over standard protocols like SSH or HTTPS and use APIs or CLI to push changes. This makes them easy to deploy and suitable for multi-vendor environments.

The other statements incorrectly attribute agent-based characteristics or overstate capabilities. The correct answers are the ones that accurately reflect how agentless tools operate.

Exam trap

The trap here is conflating agentless with agent-based tools, or assuming agentless tools provide advanced features like telemetry streaming without extra configuration.

1392
MCQmedium

A network engineer needs to configure a switch port to authenticate end hosts against a RADIUS server. The requirement is that if the RADIUS server becomes unreachable, the port should place the host on a guest VLAN instead of shutting down. Which command must be added to the interface configuration?

A.authentication host-mode multi-auth
B.authentication event server dead action authorize vlan 10
C.authentication event fail action authorize vlan 10
D.authentication open
AnswerB

This command instructs the switch to place the port into the specified guest VLAN when the RADIUS server fails to respond to authentication requests, satisfying the requirement to avoid shutting the port down. It is part of Cisco IOS 802.1X authentication event configuration and directly addresses the server-dead condition by authorizing a fallback VLAN rather than a critical VLAN.

Why this answer

When a RADIUS server becomes unreachable, the switch can be configured to authorize the port into a specific VLAN rather than shutting it down. The 'authentication event server dead action authorize vlan' command implements this by defining the VLAN to assign. The other options either handle different authentication events or alter port behaviour in ways that do not match the requirement.

Exam trap

The trap here is confusing authentication failure actions with server-dead actions, where a server-dead event requires a distinct command to handle unreachable RADIUS servers.

1393
MCQmedium

Examine the following configuration snippet: interface GigabitEthernet0/1 ip flow monitor FLOW-MONITOR input ip flow monitor FLOW-MONITOR output ! flow monitor FLOW-MONITOR exporter EXPORTER-1 record netflow ipv4 original-input ! flow exporter EXPORTER-1 destination 192.168.1.100 transport udp 2055 ! What is the effect of this configuration?

A.NetFlow v9 records are sent to the collector at 192.168.1.100 on UDP port 2055.
B.NetFlow v5 records are sent to the collector at 192.168.1.100 on UDP port 2055.
C.IPFIX records are sent to the collector at 192.168.1.100 on UDP port 2055.
D.The configuration is missing the 'ip flow-export source' command to specify the source interface.
AnswerA

The flow monitor in this configuration references the record type 'netflow ipv4 original-input' and is linked to a flow exporter that sends packets to 192.168.1.100 via UDP port 2055. Because the exporter does not explicitly set a version, Cisco IOS/IOS-XE defaults to NetFlow v9, which is the template-based format required for the flexible fields in this record. Therefore, the exported traffic is indeed NetFlow v9 records to that collector/port.

Why this answer

The configuration uses the 'netflow ipv4 original-input' record, which is a predefined record for NetFlow v9 (the default when no explicit version is specified). The exporter sends data to 192.168.1.100 on UDP port 2055, which is the standard port for NetFlow collectors. This results in NetFlow v9 records being exported to the collector.

Exam trap

Cisco often tests the misconception that 'netflow ipv4 original-input' implies NetFlow v5 or that IPFIX is automatically used, when in fact the default version is v9 unless explicitly changed to v10 (IPFIX).

How to eliminate wrong answers

Option B is wrong because 'netflow ipv4 original-input' record is associated with NetFlow v9, not v5; v5 uses a fixed format and is not specified by this record type. Option C is wrong because IPFIX (RFC 7011) requires the 'record netflow ipv4 original-input' to be explicitly configured with 'ip flow-export version 10' or a dedicated IPFIX record template, which is absent here. Option D is wrong because the 'ip flow-export source' command is not mandatory for NetFlow export to function; if omitted, the router uses the egress interface's IP address as the source, though it is a best practice to configure it for consistency.

1394
MCQmedium

Examine the following SD-WAN policy configuration on a Cisco vSmart controller: policy control-policy CONTROL_POLICY sequence 10 match route prefix-list PL_10 action accept set community 100:10 ! prefix-list PL_10 sequence 10 match ip-address 10.0.0.0/24 ! What is the effect of this control policy?

A.The policy matches routes with prefix 10.0.0.0/24 and sets the community value 100:10 on those routes before advertising them via OMP.
B.The policy matches routes with prefix 10.0.0.0/24 and sets the community 100:10 on the local router's routing table.
C.The policy denies all routes except 10.0.0.0/24 and sets community 100:10.
D.The policy is invalid because prefix-list names cannot contain underscores.
AnswerA

In Cisco SD-WAN, a control policy configured on a vSmart controller matches OMP routes based on attributes such as prefix and applies actions before the routes are advertised via OMP. This policy uses a prefix-list to match 10.0.0.0/24 and sets the OMP community value 100:10 on those matched routes, which then propagate through the overlay to remote edges. The local RIB and routing table are not modified; only the OMP route attributes are updated for advertisement.

Why this answer

This control policy matches OMP routes that have the prefix 10.0.0.0/24 (as defined by the prefix-list PL_10) and, upon a match, sets the community value 100:10 on those routes. The action 'accept' means the route is permitted and the 'set community' modifies the route's attributes before it is advertised via OMP to other vSmart or vEdge devices. This is a standard SD-WAN control policy operation for manipulating route attributes within the overlay.

Exam trap

Cisco often tests the distinction between OMP route manipulation and local RIB changes, leading candidates to incorrectly assume that 'set community' modifies the local routing table instead of the OMP advertisement.

How to eliminate wrong answers

Option B is wrong because the 'set community' action in a control policy on the vSmart applies to the OMP route advertisement, not to the local router's routing table (RIB); the local RIB is unaffected by control policies. Option C is wrong because the policy does not contain a 'deny' action or a default action to deny all other routes; it only defines a match and accept for 10.0.0.0/24, meaning routes not matching the prefix-list are implicitly denied (since there is no default action), but the policy does not explicitly deny all routes and does not set community on non-matching routes. Option D is wrong because prefix-list names can contain underscores; the configuration is syntactically valid in Cisco SD-WAN.

1395
Drag & Dropmedium

Drag and drop the steps of DHCP failover configuration between primary and standby into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

DHCP failover requires both servers to be configured with the same scope and failover parameters. First, configure the primary server with the failover peer name and IP address of the standby. Then, configure the standby server with the same peer name and the primary's IP.

Enable the failover on the primary, which starts the negotiation. The standby then enters partner-down state until it synchronizes. Finally, both servers become active and share lease information.

1396
MCQhard

A network automation team is using Cisco NSO (Network Services Orchestrator) to manage a multi-vendor network. They have created a service model in YANG and deployed it. A network engineer notices that when a device configuration is changed manually outside of NSO, NSO does not automatically correct it. Which NSO feature should be configured to ensure that NSO re-applies the intended configuration when a device drifts from the service model?

A.Set up a periodic 'sync-from' operation to pull the device configuration into NSO.
B.Configure NSO to use the 'commit dry-run' option when deploying services.
C.Configure the device to use NETCONF Call Home to notify NSO of changes.
D.Enable the 'reconcile' action on the device or service in NSO.
AnswerD

NSO provides a reconcile action that compares the actual device configuration with the intended configuration from the service model and re-applies any missing or altered settings. This action can be triggered manually or scheduled. By enabling reconcile, the engineer ensures that drift is corrected according to the service model. This is the correct feature for enforcing configuration compliance in NSO.

Why this answer

To correct configuration drift in Cisco NSO, the reconcile action is used. It compares the device's actual configuration with the intended configuration defined by the service model and re-applies any discrepancies. This ensures that the device remains compliant with the service intent.

Other options either do not address drift correction or would worsen the situation by syncing the wrong state. Reconcile is the standard mechanism for enforcing compliance in NSO.

Exam trap

The trap here is confusing sync-from with reconcile; sync-from pulls device config into NSO, while reconcile pushes the intended config to the device.

1397
Drag & Dropmedium

Drag and drop the steps of the QoS shaping and policing configuration sequence into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Shaping and policing require first defining traffic classes, then configuring the shaping/policing actions in a policy map, applying the policy to an interface, and finally adjusting parameters based on monitoring. This order ensures proper traffic control.

1398
Multi-Selectmedium

Which two statements about VRF configuration in Cisco IOS-XE are true? (Choose two.)

Select 2 answers
A.A VRF instance maintains its own routing table, CEF table, and forwarding table.
B.VRF can be used with OSPF by configuring the OSPF process under the VRF context.
C.VRF requires MPLS to be enabled on the router.
D.A VRF is automatically associated with all VLANs on a switch.
E.VRF is a Layer 2 isolation mechanism.
AnswersA, B

Each VRF instance is a separate Layer 3 routing domain, so it holds its own RIB, Cisco Express Forwarding adjacency table and forwarding information base. This isolation satisfies the stem's requirement that VRFs keep traffic and routes distinct on shared hardware.

Why this answer

Option A is correct because a VRF (Virtual Routing and Forwarding) instance creates a fully separate Layer 3 routing domain, maintaining its own RIB (routing table), its own CEF/FIB (forwarding table), and its own set of interfaces, which is exactly what provides traffic isolation between VRFs on the same physical router. Option B is correct because IOS-XE supports running routing protocols per VRF; OSPF is enabled inside a VRF by entering router ospf <process> vrf <vrf-name> (or by configuring the process under the VRF context), giving that VRF its own OSPF instance, LSDB, and adjacencies. Option C is not required: MPLS is a common transport for VRF traffic across a provider core (as in MPLS L3VPN), but a VRF works locally on a single router without MPLS enabled.

Option D is wrong because VRFs are not automatically bound to VLANs; interface-to-VRF association is an explicit configuration (e.g., ip vrf forwarding <name> under the SVI), and VLANs are a Layer 2 construct independent of VRF membership. Option E is wrong because VRF is a Layer 3 isolation mechanism; Layer 2 isolation is provided by VLANs (or VRF-lite's Layer 3 separation over separate subinterfaces), not by VRF itself.

Exam trap

The trap is confusing VRF with VLANs or assuming MPLS is required. Candidates might think VRF is Layer 2 or that it automatically applies to all VLANs.

1399
MCQeasy

A network engineer is configuring a Cisco IOS-XE router to support virtual routing and forwarding (VRF). The engineer wants to ensure that the VRF can be used for MPLS VPN and that the router can maintain separate routing tables. Which command is used to create a VRF named CUSTOMER?

A.vrf definition CUSTOMER
B.ip vrf CUSTOMER
C.interface vrf CUSTOMER
D.vrf CUSTOMER
AnswerA

The 'vrf definition CUSTOMER' command in global configuration mode creates a VRF instance named CUSTOMER. This command is used in Cisco IOS-XE to define a VRF and enter VRF configuration mode, where you can specify address families, route targets, and other parameters. It is the correct way to create a VRF for MPLS VPN or other segmentation purposes.

Why this answer

The correct command to create a VRF named CUSTOMER on a Cisco IOS-XE router is 'vrf definition CUSTOMER'. This command creates the VRF and enters VRF configuration mode, allowing the engineer to configure address families and other parameters. The 'ip vrf' command is an older alternative but lacks support for IPv6 and is not recommended for new deployments.

Exam trap

The trap here is assuming that 'ip vrf' is still the preferred command for creating VRFs on modern IOS-XE routers, when in fact 'vrf definition' is the current standard that supports both IPv4 and IPv6 address families.

1400
Multi-Selectmedium

Which two statements about IGMP snooping are true? (Choose two.)

Select 2 answers
A.IGMP snooping reduces unnecessary multicast flooding on a Layer 2 switch.
B.IGMP snooping uses the IGMP querier election process to select the switch with the highest IP address as the querier.
C.IGMP snooping can be configured to replace IGMP on the router interface.
D.IGMP snooping listens to IGMP membership reports and leave messages to build a forwarding table.
E.IGMP snooping modifies the IP header of multicast packets to include group membership information.
AnswersA, D

IGMP snooping lets a Layer 2 switch inspect IGMP join and leave messages, building a per-VLAN multicast forwarding table. Frames are then forwarded only to ports with interested receivers, satisfying the stem's requirement to reduce unnecessary multicast flooding.

Why this answer

Option A is correct because IGMP snooping allows a Layer 2 switch to examine IGMP messages and forward multicast traffic only to ports that have interested receivers, rather than flooding it to all ports in the VLAN. Option D is correct because the switch snoops IGMP membership reports and leave messages to dynamically build and maintain a Layer 2 multicast forwarding table mapping groups to ports. Option B is incorrect because querier election is an IGMP function performed by multicast routers (or a snooping switch acting as querier), not a mechanism that defines IGMP snooping itself.

Option C is incorrect because IGMP snooping operates transparently on the switch and does not replace IGMP on router interfaces. Option E is incorrect because IGMP snooping does not modify IP headers; it only inspects IGMP control messages to build forwarding state.

Exam trap

The trap here is confusing IGMP snooping (Layer 2 optimization that listens to IGMP) with IGMP itself (Layer 3 group management) — candidates often pick the querier-election option because they conflate the two protocols.

1401
MCQmedium

Consider this configuration: interface Port-channel1 switchport mode trunk switchport trunk native vlan 999 ! interface GigabitEthernet0/1 switchport mode trunk switchport trunk native vlan 999 channel-group 1 mode active ! interface GigabitEthernet0/2 switchport mode trunk switchport trunk native vlan 999 channel-group 1 mode active What is the effect of the 'switchport trunk native vlan 999' command on the EtherChannel?

A.The EtherChannel will drop all untagged frames because the native VLAN is not in the allowed list.
B.The EtherChannel will use VLAN 999 as the native VLAN, and any untagged frames will be associated with VLAN 999.
C.The EtherChannel will not form because the native VLAN must be the same across all interfaces, which it is.
D.The EtherChannel will form but the native VLAN will be ignored on the port-channel.
AnswerB

Correct: When the native VLAN is configured as 999 on the EtherChannel, the port-channel treats all untagged frames as belonging to VLAN 999. This is standard 802.1Q trunk behavior: untagged frames are placed into the native VLAN, and in this case the native VLAN is explicitly set to 999 rather than the default VLAN 1. Both ends of the EtherChannel must agree on the native VLAN value to avoid misconfiguration, and here that consistency is maintained.

Why this answer

The 'switchport trunk native vlan 999' command on each physical interface and on the port-channel interface ensures that the EtherChannel uses VLAN 999 as the native VLAN. Untagged frames received on any member link are associated with VLAN 999, and frames tagged with VLAN 999 are sent untagged. Since the configuration is consistent across all interfaces, the EtherChannel forms correctly and operates with VLAN 999 as the native VLAN.

Exam trap

Cisco often tests the misconception that the native VLAN must be VLAN 1 or that changing it will break the EtherChannel, but the key requirement is consistency across all interfaces, not a specific VLAN number.

How to eliminate wrong answers

Option A is wrong because the native VLAN is explicitly set to 999, which is in the allowed VLAN list by default (all VLANs 1-4094 are allowed unless restricted), so untagged frames are not dropped but associated with VLAN 999. Option C is wrong because the native VLAN is the same (999) on all interfaces and the port-channel, so the EtherChannel forms without issue; the statement incorrectly implies a mismatch. Option D is wrong because the native VLAN is not ignored on the port-channel; it is inherited from the physical interfaces and applied to the logical port-channel interface, functioning as configured.

1402
MCQmedium

A network engineer is designing a QoS policy for a campus network. The requirement is that voice traffic must be guaranteed strict priority treatment over all other traffic types, even during congestion. Which queuing mechanism should be configured on the egress interfaces to meet this requirement?

A.Class-Based Weighted Fair Queuing (CBWFQ)
B.Low Latency Queuing (LLQ)
C.First-In, First-Out (FIFO) queuing
D.Weighted Random Early Detection (WRED)
AnswerB

LLQ combines strict priority queuing with CBWFQ. It designates one or more classes as priority queues, which are serviced before any other queues. This ensures that voice traffic receives strict priority treatment and minimal delay and jitter, even during congestion. LLQ also includes a policer to limit the priority queue bandwidth, preventing starvation of other traffic. It directly satisfies the requirement for strict priority for voice.

Why this answer

LLQ is the Cisco IOS queuing mechanism that provides strict priority to designated classes, such as voice, while using CBWFQ for other classes. The priority queue is serviced first, ensuring minimal delay and jitter for voice even under congestion. A policer limits the priority queue to prevent it from starving other queues.

CBWFQ, WRED, and FIFO do not provide strict priority scheduling, so LLQ is the correct choice.

Exam trap

The trap here is confusing CBWFQ with LLQ; CBWFQ provides weighted bandwidth guarantees but not strict priority, which is essential for voice traffic.

1403
MCQhard

A network engineer is using Ansible to manage a fleet of Cisco IOS XE devices. The playbook uses the 'ios_config' module to push a set of configuration lines. After running the playbook, the engineer notices that the configuration changes are not being saved to the startup configuration, and the devices revert to the previous configuration after a reboot. Which parameter should be added to the 'ios_config' task to ensure the running configuration is saved to the startup configuration?

A.diff_against: startup
B.replace: config
C.backup: yes
D.save_when: always
AnswerD

The 'save_when' parameter in the ios_config module controls when the running configuration is saved to the startup configuration. Setting it to 'always' ensures that after any configuration change, the running config is saved. This directly addresses the issue of changes not persisting after reboot. It is the correct parameter to use.

Why this answer

The 'save_when' parameter with the value 'always' forces the ios_config module to save the running configuration to the startup configuration after every change. This ensures that configuration persists across reboots. Other parameters like 'backup', 'diff_against', and 'replace' serve different purposes and do not save the configuration.

Thus, 'save_when: always' is the correct solution.

Exam trap

The trap here is assuming that any configuration change automatically saves to startup, or confusing backup and diff parameters with saving the configuration.

1404
MCQeasy

A network engineer is automating the collection of syslog messages from a Cisco ASA firewall using a Python script that connects via SSH and runs 'show log'. The script uses the paramiko library. The script works for a few minutes, but then the SSH connection drops with an error 'Server connection dropped'. The engineer suspects that the ASA is closing the connection due to inactivity. What is the best way to keep the connection alive?

A.Increase the buffer size in the paramiko SSH client.
B.Run a dummy command like 'show clock' every 30 seconds to keep the session active.
C.Set the 'keepalive' parameter in the paramiko Transport object to send keepalive packets every 30 seconds.
D.Use the netmiko library instead, which automatically handles keepalives.
AnswerC

Setting the 'keepalive' parameter in the Paramiko Transport object is the correct approach because it tells the SSH transport layer to send keepalive packets on its own at the specified interval, without interfering with any running shell commands. Paramiko's `set_keepalive()` method works by transmitting a simple SSH protocol message (e.g., an SSH2_MSG_IGNORE or global request) whenever no data has been sent for that interval. These lightweight packets reset the idle timers on firewalls and the remote SSH server, keeping the session open cleanly and automatically.

Why this answer

The paramiko library provides a built-in keepalive mechanism via the `Transport` object's `set_keepalive()` method. This sends TCP keepalive packets at the specified interval (e.g., 30 seconds) to prevent the ASA firewall from closing the SSH session due to inactivity. Unlike application-layer workarounds, this operates at the transport layer and does not consume CPU cycles on the ASA for command execution.

Exam trap

Cisco often tests the distinction between application-layer workarounds (like running dummy commands) and proper transport-layer keepalive mechanisms, and the trap here is that candidates mistakenly think running a periodic command is the simplest or most reliable solution, when in fact it is inefficient and can disrupt the automation workflow.

How to eliminate wrong answers

Option A is wrong because increasing the buffer size only affects the amount of data that can be buffered before reading; it does not prevent the ASA from timing out the idle SSH session. Option B is wrong because running a dummy command like 'show clock' every 30 seconds is an application-layer workaround that adds unnecessary load on the ASA and may interfere with the syslog collection output; it is not a proper keepalive mechanism. Option D is wrong because while netmiko does have built-in keepalive support, the question specifically asks about the best way to keep the connection alive using the paramiko library, and netmiko is a higher-level library that abstracts paramiko; the correct paramiko-native approach is to use the Transport object's keepalive parameter.

1405
MCQmedium

A network engineer is deploying a Cisco SD-Access fabric using Cisco DNA Center. The design requires that endpoints in the same virtual network (VN) be able to communicate even when they are attached to different fabric edge nodes. Which data plane technology does SD-Access use to carry the endpoint traffic across the fabric underlay?

A.MPLS L3VPN with a route target per virtual network
B.GRE with a tunnel key per virtual network
C.OTV with an overlay VLAN per virtual network
D.VXLAN with a fabric VNI mapped to each virtual network
AnswerD

SD-Access uses VXLAN encapsulation in the fabric data plane. Each virtual network is mapped to a unique VNI, and the fabric edge nodes and border nodes act as VTEPs. The endpoint traffic is carried inside VXLAN tunnels across the underlay, which allows Layer 2 and Layer 3 communication between endpoints attached to different edge nodes while maintaining segmentation.

Why this answer

Cisco SD-Access uses VXLAN as the data plane encapsulation. Each virtual network is mapped to a unique VNI, and the fabric edge and border nodes encapsulate endpoint traffic in VXLAN. This allows endpoints in the same VN to communicate across different edge nodes while preserving segmentation.

The control plane uses LISP to map endpoint identities to fabric locations.

Exam trap

The trap here is confusing the SD-Access data plane with other tunneling technologies like GRE or MPLS, which are not used inside the SD-Access fabric.

1406
MCQhard

A service provider wants to deploy a virtualized firewall as a VNF in a service chain. The VNF must be inserted transparently into the traffic path without requiring changes to the existing IP addressing. Which service chaining method should the architect choose?

A.Use static routing to point traffic to the VNF.
B.Implement policy-based routing (PBR) to redirect traffic to the VNF.
C.Deploy the VNF in inline mode with proxy ARP.
D.Use VRF-lite to separate traffic and route through the VNF.
AnswerB

PBR matches traffic based on source, destination, or protocol and overrides the routing table by setting a next-hop to the VNF, all without changing endpoint IP configuration. This enables selective, policy-based service chaining while keeping the original source and destination addresses intact, so the VNF can process traffic and forward it back to the intended path.

Why this answer

Policy-based routing (PBR) allows the architect to redirect traffic to the VNF based on match criteria such as source/destination IP or protocol, without altering the existing IP addressing scheme. This enables transparent insertion of the VNF into the service chain, as PBR overrides the routing table for selected traffic and forwards it to the virtualized firewall, while the original IP headers remain unchanged.

Exam trap

Cisco often tests the misconception that inline mode with proxy ARP is the simplest transparent insertion method, but candidates overlook that proxy ARP modifies Layer 2 behavior and can break transparency, whereas PBR operates at Layer 3 without altering IP addressing.

How to eliminate wrong answers

Option A is wrong because static routing requires modifying the routing table to point traffic to the VNF, which changes the next-hop behavior and may disrupt existing IP addressing or routing policies. Option C is wrong because deploying the VNF in inline mode with proxy ARP would require the VNF to respond to ARP requests on behalf of other devices, altering the Layer 2 topology and potentially causing IP address conflicts or transparency issues. Option D is wrong because VRF-lite separates traffic into different routing tables, but it does not inherently redirect traffic through the VNF without additional routing changes, and it adds complexity without achieving transparent insertion.

1407
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor the health of a wireless network. The administrator notices that a particular client device shows a poor health score. Which Cisco DNA Center Assurance feature should the administrator use to determine the root cause of the poor health score?

A.Path Trace
B.Network Health dashboard
C.Application Health dashboard
D.Client 360
AnswerD

Client 360 provides a detailed view of a specific client's connectivity, including onboarding, authentication, association, and performance metrics. It shows the client's health score, issues, and the ability to drill down into specific events and path trace. This is the correct tool to determine why a client has a poor health score, as it aggregates data from multiple sources and provides root cause analysis.

Why this answer

Client 360 in Cisco DNA Center Assurance provides a comprehensive view of a specific client's network experience, including onboarding, authentication, and performance. It aggregates data and presents a health score with detailed metrics and events. To determine the root cause of a poor health score, the administrator should use Client 360, which offers drill-down capabilities and suggested actions.

Other dashboards provide broader or different scopes of information.

Exam trap

The trap here is assuming that the Network Health dashboard provides client-level root cause analysis, when it actually focuses on device and network health.

1408
MCQmedium

A network administrator is configuring 802.1X authentication on a Cisco switch port. The port is connected to a VoIP phone that then connects to a PC. The administrator wants to authenticate both the phone and the PC separately, with the phone using MAB and the PC using 802.1X. Which feature should be configured on the switch port to support this?

A.Web Authentication (WebAuth)
B.Multi-Domain Authentication (MDA)
C.Multi-Host
D.Multi-Auth
AnswerB

MDA allows both a data device and a voice device to authenticate independently on the same switch port. It places the phone in the voice VLAN and the PC in the data VLAN, each with its own authentication session. This matches the requirement to authenticate the phone via MAB and the PC via 802.1X. MDA is designed for this exact scenario.

Why this answer

MDA is specifically designed to allow a voice device and a data device to authenticate separately on the same switch port. The phone can use MAB while the PC uses 802.1X, and they are placed in different VLANs. Multi-Auth and Multi-Host do not provide this voice/data separation, and WebAuth is a different authentication method.

Thus, MDA is the correct feature.

Exam trap

The trap here is confusing Multi-Auth with MDA; Multi-Auth allows multiple devices but does not separate voice and data domains as required for a VoIP phone and PC.

1409
Matchingmedium

Drag and drop each DNA Center ISE integration component on the left to its matching role on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Shares context and session data between DNA Center and ISE

Enforces security group tags (SGTs) for micro-segmentation

Provides authentication, authorization, and accounting for network access

Manages guest user portal, sponsor workflows, and captive portal

Identifies endpoint device type and attributes for policy enforcement

Why these pairings

ISE integration: pxGrid shares context; TrustSec enforces SGTs; RADIUS provides AAA; Guest services manage guest access; Profiling identifies endpoint types.

1410
Drag & Dropmedium

Drag and drop the steps of OMP route advertisement between vSmart and vEdge into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

OMP route advertisement begins with the vEdge learning a local route, then advertising it via OMP to vSmart, vSmart processes the route and may apply policies, then vSmart advertises the route to other vEdges, and finally the receiving vEdge installs the route into its forwarding table.

1411
MCQhard

A network engineer runs the following command on Router R1: R1# show ip pim neighbor PIM Neighbor Table Neighbor Address Interface Uptime Expires Mode 10.0.0.2 GigabitEthernet0/0 00:10:00 00:01:30 Dense 10.0.0.3 GigabitEthernet0/1 00:20:00 00:01:20 Sparse Based on this output, what can be concluded?

A.All PIM neighbors are operating in sparse mode
B.The router is configured with mixed PIM modes on different interfaces
C.The router is using PIM version 2 exclusively
D.The neighbor 10.0.0.3 is not a valid PIM neighbor
AnswerB

The router is correctly identified as having mixed PIM modes on different interfaces because the neighbor table shows one neighbor in Dense mode and another in Sparse mode. This indicates that the router's interfaces are configured with different PIM modes, as PIM mode is a per-interface setting. Such a configuration is valid but can lead to suboptimal multicast behavior if not carefully planned, as dense mode floods traffic while sparse mode requires explicit joins.

Why this answer

The output shows that interface GigabitEthernet0/0 has a PIM neighbor in Dense mode, while GigabitEthernet0/1 has a neighbor in Sparse mode. This indicates that Router R1 is configured with different PIM modes on different interfaces, which is known as mixed PIM mode. Therefore, option B is correct.

Exam trap

Cisco often tests the ability to read the 'Mode' column in the 'show ip pim neighbor' output, where candidates mistakenly assume all neighbors share the same mode or that the mode column indicates the router's global PIM mode rather than per-interface configuration.

How to eliminate wrong answers

Option A is wrong because the neighbor on GigabitEthernet0/0 is operating in Dense mode, not Sparse mode, so not all neighbors are in sparse mode. Option C is wrong because the output does not display PIM version information; PIM version 2 is the default for most modern IOS versions, but the command output does not confirm exclusive use of version 2, and PIM version 1 could still be in use. Option D is wrong because the neighbor 10.0.0.3 is listed with a valid uptime and expires timer, indicating it is a valid PIM neighbor; the Mode column shows 'Sparse', which is a legitimate PIM mode.

1412
MCQhard

A network administrator is troubleshooting an issue where OSPF routes are not being learned from a neighbor. The administrator checks the OSPF configuration and sees that both routers are in the same area. The neighbor state is stuck in EXSTART. What is the most likely cause?

A.The router ID is the same on both routers.
B.The area ID is different.
C.The hello timer is set to 30 seconds on one router.
D.The interface MTU does not match.
AnswerD

An MTU mismatch is the classic cause of an OSPF neighbor being stuck in EXSTART; during the Database Description exchange, each router advertises its outgoing interface MTU in the DBD packet header. If one router's interface has a lower MTU, it discards DBD packets that declare a larger MTU, so the neighboring router never receives a valid acknowledgment and remains in EXSTART. Because OSPF does not initialize the DBD exchange until both MTUs are verified equal, the adjacency stalls at the point where the Master/Slave election occurs, exactly matching the reported symptom.

Why this answer

When OSPF neighbors are stuck in the EXSTART state, it typically indicates a problem with the Database Description (DBD) packet exchange process. The most common cause is an MTU mismatch between the interfaces, because OSPF will not proceed to the Exchange state if the DBD packet is larger than the interface MTU and gets silently dropped. This prevents the routers from agreeing on the master/slave relationship and exchanging link-state information.

Exam trap

The trap here is that candidates often confuse the EXSTART state with issues like hello/dead timer mismatches or area mismatches, which actually prevent the adjacency from reaching the 2-WAY state, not the EXSTART state.

How to eliminate wrong answers

Option A is wrong because duplicate router IDs would cause a neighbor state of DOWN or a conflict that prevents adjacency formation entirely, not a state stuck in EXSTART. Option B is wrong because if the area ID were different, the routers would not even reach the 2-WAY state, let alone EXSTART; they would remain in INIT or DOWN. Option C is wrong because mismatched hello timers would prevent the routers from reaching the 2-WAY state (they would stay in INIT), not cause them to get stuck in EXSTART.

1413
MCQeasy

A network administrator is troubleshooting a performance issue in a large enterprise campus network. The network consists of Cisco Catalyst 9300 switches acting as access switches and Cisco Catalyst 9500 switches as distribution. Users on VLAN 10 report intermittent slow file transfers to a server on VLAN 20. The administrator has verified that there are no errors on the links, CPU utilization is normal, and STP topology is stable. The administrator suspects a possible QoS issue. Upon checking the QoS configuration on the access switch, the administrator finds that the default QoS configuration is in place, which trusts the CoS value at the port level. The connected devices are IP phones and PCs; the IP phones mark voice traffic with CoS 5. The server on VLAN 20 is connected to a distribution switch. Which action should the administrator take to most likely resolve the issue?

A.Apply a policy map that polices voice traffic to 128 kbps to free bandwidth for data.
B.Disable QoS entirely on all switches to eliminate any potential QoS-related drops.
C.Configure auto QoS for VoIP on the access ports to ensure proper classification and queuing.
D.Configure trust DSCP on the access ports to prioritize all traffic based on DSCP values.
AnswerC

Auto QoS for VoIP on access ports dynamically configures the necessary trust boundaries, classification, and egress queuing to properly handle voice traffic. It typically sets the ingress port to trust CoS for the connected IP phone, marks voice traffic appropriately, and places it in the priority queue to minimize latency and drop risk. This is the correct remediation because it matches the network behavior to the requirements of voice—ensuring priority without manual, error-prone configuration.

Why this answer

Auto QoS for VoIP automatically configures the necessary class maps, policy maps, and trust settings to properly classify and queue voice traffic (CoS 5) while ensuring data traffic is not starved. The default QoS configuration trusts CoS at the port level, but without proper queuing and scheduling, voice and data may compete for buffers, causing intermittent slow file transfers. Auto QoS sets up strict priority queuing for voice and allocates bandwidth for data, resolving the performance issue without manual misconfiguration.

Exam trap

Cisco often tests the misconception that simply trusting CoS or DSCP values is sufficient to prioritize traffic, when in fact trust alone does not configure the egress queuing and scheduling policies needed to prevent congestion and ensure bandwidth allocation.

How to eliminate wrong answers

Option A is wrong because policing voice traffic to 128 kbps would drop voice packets that exceed this rate, degrading voice quality, and does not address the root cause of data traffic being starved due to improper queuing. Option B is wrong because disabling QoS entirely removes all prioritization, which can cause both voice and data to be treated equally, potentially worsening the performance issue for file transfers during congestion. Option D is wrong because configuring trust DSCP on access ports would trust DSCP markings from PCs and IP phones, but the default QoS configuration already trusts CoS; changing to DSCP trust may not align with the existing CoS markings from IP phones and could lead to misclassification, while still lacking proper queuing policies.

1414
MCQmedium

Consider the following SPAN configuration on a Cisco IOS-XE switch: monitor session 2 source interface GigabitEthernet1/0/3 rx monitor session 2 destination interface GigabitEthernet1/0/4 What is the effect of this configuration?

A.Only traffic received on GigabitEthernet1/0/3 is copied to GigabitEthernet1/0/4.
B.Both ingress and egress traffic on GigabitEthernet1/0/3 is copied to GigabitEthernet1/0/4.
C.Traffic on GigabitEthernet1/0/4 is mirrored to GigabitEthernet1/0/3.
D.The configuration is invalid because the destination interface must be in trunk mode.
AnswerA

The `rx` keyword restricts the source to ingress traffic only, so frames received on GigabitEthernet1/0/3 are copied to the destination port GigabitEthernet1/0/4. Egress traffic transmitted out of the source interface is not mirrored, satisfying the stem's receive-only monitoring constraint.

Why this answer

The configuration explicitly specifies the `rx` keyword for the source interface, which limits SPAN to copying only received (ingress) traffic on GigabitEthernet1/0/3 to the destination interface GigabitEthernet1/0/4. Without the `rx` or `tx` keyword, the default behavior would copy both directions, but here the explicit `rx` overrides that default.

Exam trap

The trap here is that candidates often assume SPAN always copies both ingress and egress traffic by default, but the explicit `rx` keyword changes the behavior to only ingress, and Cisco tests whether you notice that keyword in the configuration.

How to eliminate wrong answers

Option B is wrong because the `rx` keyword restricts the SPAN session to only ingress traffic; both ingress and egress traffic would only be copied if no direction keyword or the `both` keyword were used. Option C is wrong because SPAN is unidirectional from source to destination; the destination interface receives a copy of traffic, it does not mirror traffic back to the source. Option D is wrong because the destination interface does not need to be in trunk mode; it can be an access port, and the configuration is valid as long as the destination interface is not already used in another SPAN session or as a source.

1415
MCQhard

A network engineer is deploying Cisco SD-Access and needs to ensure that endpoint traffic is encapsulated and forwarded between fabric edge nodes. The design uses an overlay that carries Layer 2 and Layer 3 traffic over a Layer 3 underlay. Which protocol does Cisco SD-Access use for the data plane encapsulation in this fabric?

A.LISP with a locator/ID separation header
B.VXLAN with a Group Policy Option (GPO) header
C.OTV with an adjacency server
D.GRE with a fabric header
AnswerB

Cisco SD-Access uses VXLAN as the data plane encapsulation, and it adds a Group Policy Option header to carry security group tag information. This allows the fabric to enforce group-based policies without requiring traditional ACLs on every device, which is a core part of the SD-Access architecture.

Why this answer

Cisco SD-Access fabric data plane uses VXLAN encapsulation, enhanced with a Group Policy Option header. This header carries the source group tag, enabling scalable group-based policy enforcement. The control plane uses LISP for endpoint location mapping, but the actual packet encapsulation for endpoint traffic is VXLAN, making it the correct choice for the data plane.

Exam trap

The trap here is confusing the control plane protocol (LISP) with the data plane encapsulation (VXLAN), since both are central to SD-Access but serve different roles.

1416
MCQmedium

An enterprise is redesigning its WAN QoS architecture to support real-time voice, video, and critical data applications over a limited bandwidth link. The architect must ensure that voice traffic receives strict priority queuing and that video traffic is guaranteed a minimum bandwidth, while allowing best-effort traffic to use remaining capacity. Which queuing strategy should be deployed on the WAN edge routers?

A.FIFO (First In, First Out) with tail drop
B.CBWFQ (Class-Based Weighted Fair Queuing) without a priority queue
C.LLQ (Low Latency Queuing) with a strict priority queue for voice and CBWFQ for video and data
D.WRED (Weighted Random Early Detection) with DSCP-based drop probabilities
AnswerC

LLQ combines a strict priority queue with CBWFQ, ensuring that voice packets are always transmitted first, which minimizes both latency and jitter for real-time traffic. The priority queue is typically policed to a configured bandwidth limit to prevent a flood of voice traffic from starving video or data. Meanwhile, video and data are placed into CBWFQ classes that receive guaranteed bandwidth under the weighted fair scheduler, allowing the design to satisfy both strict voice latency and bandwidth guarantees for other critical applications.

Why this answer

LLQ combines a strict priority queue for delay-sensitive voice traffic with CBWFQ for other classes, guaranteeing minimum bandwidth for video while allowing best-effort traffic to share remaining capacity. This satisfies the requirement for strict priority queuing for voice and bandwidth guarantees for video, which CBWFQ alone cannot provide because it lacks a priority queue.

Exam trap

Cisco often tests the distinction between CBWFQ and LLQ, trapping candidates who think CBWFQ alone can provide strict priority queuing, when in fact only LLQ adds the 'priority' keyword to create a low-latency queue.

How to eliminate wrong answers

Option A is wrong because FIFO with tail drop provides no differentiation between traffic types, causing voice and video to suffer delay and drops alongside best-effort data. Option B is wrong because CBWFQ without a priority queue cannot offer strict priority queuing for voice, which is essential for low-latency real-time traffic. Option D is wrong because WRED is a congestion avoidance mechanism that manages drop probabilities based on DSCP, not a queuing strategy, and it cannot guarantee minimum bandwidth or strict priority for voice.

1417
MCQmedium

In a Cisco QoS policy, what is the difference between 'bandwidth' and 'bandwidth remaining' commands?

A.There is no difference; both commands allocate bandwidth based on the total interface bandwidth.
B.'bandwidth' allocates from the total bandwidth, while 'bandwidth remaining' allocates from the bandwidth left after priority queues.
C.'bandwidth' is used for output policies, while 'bandwidth remaining' is used for input policies.
D.'bandwidth' guarantees a minimum rate, while 'bandwidth remaining' sets a maximum rate.
AnswerB

This is the correct answer. The 'bandwidth' command, in a CBWFQ policy map, explicitly allocates a guaranteed rate from the total interface bandwidth, and that rate is reserved under congestion. In contrast, 'bandwidth remaining' specifies a percentage or proportion of the bandwidth that is left after the priority queue (for low-latency traffic) and after all explicit 'bandwidth' allocations have been satisfied. Therefore, 'bandwidth remaining' is a fair-sharing mechanism for the leftover, non-priority bandwidth rather than a reservation from the full link capacity.

Why this answer

The 'bandwidth' command allocates a guaranteed minimum bandwidth from the total interface bandwidth during congestion, while 'bandwidth remaining' allocates bandwidth only from the leftover bandwidth after the priority queue (LLQ) has taken its share. This distinction is critical in Cisco QoS policies where priority queues can consume a large portion of the link, and remaining bandwidth must be distributed among other classes using a ratio or percentage.

Exam trap

Cisco often tests the misconception that 'bandwidth remaining' is an alternative way to allocate from total bandwidth, when in fact it specifically operates on the post-priority queue leftover bandwidth, making it essential for proper LLQ design.

How to eliminate wrong answers

Option A is wrong because the two commands operate on different bandwidth pools: 'bandwidth' allocates from the total interface bandwidth, whereas 'bandwidth remaining' allocates only from the bandwidth left after priority queues have been serviced. Option C is wrong because both commands are used in output policies; 'bandwidth remaining' is not specific to input policies, and input policies typically use policing rather than shaping. Option D is wrong because 'bandwidth' guarantees a minimum rate during congestion, but 'bandwidth remaining' also guarantees a minimum rate from the remaining pool, not a maximum rate; the 'police' command sets a maximum rate.

1418
MCQhard

A network engineer is configuring IPv6 First Hop Security on a Cisco switch to mitigate rogue RA attacks. The engineer enables RA guard on the switch and applies a policy that allows only the default gateway to send RAs. After configuration, hosts are unable to obtain IPv6 addresses via SLAAC. The engineer checks the switch and sees that RA guard is dropping all RAs. What is the most likely cause?

A.The RA guard policy does not include the IPv6 address or MAC address of the legitimate default gateway.
B.The switch has DHCPv6 snooping enabled, which conflicts with RA guard.
C.SLAAC requires the host to send a router solicitation first, which is being blocked by RA guard.
D.RA guard is configured in 'block' mode, which drops all RAs regardless of the policy.
AnswerA

RA guard is a policy-based IPv6 first-hop security feature that forwards Router Advertisements only from devices explicitly authorized by the policy. If the legitimate default gateway's IPv6 address or MAC address is not listed in that policy, the switch treats those RAs as rogue and silently drops them. Consequently, hosts never receive the gateway's prefix information or default route, breaking SLAAC and causing the reported connectivity loss. The fix is to add the actual gateway to the RA guard policy as a trusted device.

Why this answer

RA Guard drops Router Advertisements (RAs) based on a policy that defines which devices are authorized to send them. If the policy does not include the IPv6 address or MAC address of the legitimate default gateway, the switch will treat all RAs as unauthorized and drop them, preventing hosts from performing SLAAC. This is the most likely cause because the engineer enabled RA guard with a policy but failed to specify the trusted gateway's identity.

Exam trap

Cisco often tests the misconception that RA Guard has a 'block' mode or that it blocks RS messages, when in reality the issue is almost always a missing or incorrect trusted device entry in the RA guard policy.

How to eliminate wrong answers

Option B is wrong because DHCPv6 snooping and RA guard are independent features; DHCPv6 snooping does not inherently conflict with RA guard, and enabling both would not cause RA guard to drop all RAs unless the policy is misconfigured. Option C is wrong because RA guard does not block Router Solicitations (RSs); it only filters RAs, and SLAAC requires the host to send an RS first, which is not blocked. Option D is wrong because RA guard does not have a 'block' mode that drops all RAs regardless of policy; the policy must explicitly define trusted devices, and if no device is trusted, all RAs are dropped by default, but this is a policy misconfiguration, not a separate mode.

1419
Drag & Dropmedium

Drag and drop the steps of IP SLA tracking with static route failover into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, the IP SLA operation is defined to monitor reachability. Then a track object is created that references the IP SLA operation. The track object is configured with a threshold for up/down state.

A static route is configured with the track object for failover. Finally, the static route is verified to use the track.

1420
MCQhard

A network engineer is designing a Cisco SD-WAN fabric with two data centers and 200 branch sites. The requirement is that branch sites use direct internet access for SaaS applications while business-critical traffic to the data centers traverses a secure IPsec tunnel. Which Cisco SD-WAN feature should the engineer use to define and enforce these traffic steering policies?

A.Application-aware routing with centralized data policy
B.TLOC extension between WAN edge routers at each branch
C.BFD-based path selection with static routes
D.Control plane and data plane separation with OMP
AnswerA

Cisco SD-WAN centralized data policy lets the engineer define traffic steering rules based on application, source, destination, and other match criteria, and then apply actions such as directing traffic over a specific VPN or out the local internet connection. Application-aware routing continuously measures path characteristics to select the best path. Together they satisfy the requirement to send SaaS traffic directly to the internet while forcing critical traffic through IPsec tunnels to the data centers.

Why this answer

Cisco SD-WAN centralized data policy is the mechanism for defining traffic steering rules based on application and other match criteria. Combined with application-aware routing, which measures path performance, the engineer can direct SaaS traffic out the local internet connection and force business-critical traffic through IPsec tunnels to the data centers. This combination directly addresses the stated requirement.

Exam trap

The trap here is assuming that OMP or BFD alone can steer traffic by application, when application-based forwarding requires centralized data policy plus application-aware routing.

1421
MCQhard

A network engineer issues the following command on Router R8: R8# show policy-map interface gigabitethernet 0/1 GigabitEthernet0/1 Service-policy output: SHAPE-1M Class-map: class-default (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any queue limit 64 packets (queue depth 0) (congestion occurrences) shape (average) cir 1000000, bc 10000, be 10000 target shape rate 1000000 Based on this output, what is true about the traffic shaping policy?

A.The policy is policing traffic to 1 Mbps.
B.The policy is shaping traffic to an average rate of 1 Mbps.
C.The policy is dropping all traffic because the queue is full.
D.The policy is applied in the input direction.
AnswerB

The configuration 'shape (average) cir 1000000' indicates a committed information rate (CIR) of 1,000,000 bits per second, which equals 1 Mbps. Shaping averages the traffic rate over time by buffering bursts and draining them through a token bucket, so the long-term average matches the CIR. This is the correct interpretation of the policy's behavior.

Why this answer

The output shows 'shape (average) cir 1000000', which configures traffic shaping to an average rate of 1 Mbps. Shaping buffers excess traffic and smooths it out over time, unlike policing which drops or marks packets. The 'target shape rate 1000000' confirms the shaped rate is 1 Mbps.

Exam trap

Cisco often tests the distinction between shaping and policing; the trap here is that candidates see 'cir 1000000' and assume policing, but shaping uses the same CIR terminology and the 'shape' keyword is the giveaway.

How to eliminate wrong answers

Option A is wrong because the command 'shape (average)' implements shaping, not policing; policing would use the 'police' command and would show actions like 'conform-action' or 'exceed-action'. Option C is wrong because the queue depth is 0, indicating no packets are currently queued, and the queue limit is 64 packets, so the queue is not full. Option D is wrong because the output explicitly states 'Service-policy output: SHAPE-1M', meaning the policy is applied in the output (egress) direction, not input.

1422
Multi-Selecthard

A network engineer is deploying VXLAN with an EVPN control plane in a data center. The underlay is a routed Layer 3 network using OSPF. The engineer must ensure that the VXLAN data plane and EVPN control plane operate correctly. Which two statements about this deployment are true? (Choose two.)

Select 2 answers
A.EVPN uses BGP as its control plane to distribute MAC and IP address reachability information among VTEPs.
B.The VXLAN Tunnel Endpoint (VTEP) must have a unique IP address in the underlay, and this address is used as the source for VXLAN encapsulated traffic.
C.EVPN requires the underlay to be a Layer 2 network so that BGP peering can be established without routing.
D.The VTEP must be configured with the same IP address on all leaf switches to allow anycast tunneling.
E.VXLAN requires the underlay network to run a multicast routing protocol such as PIM to replicate broadcast, unknown unicast, and multicast traffic.
AnswersA, B

EVPN is a BGP address family (L2VPN EVPN) that carries MAC and IP reachability information. VTEPs peer with each other or with route reflectors using MP-BGP and advertise EVPN routes. This replaces flood-and-learn for MAC learning and provides control-plane learning, making the statement correct for an EVPN deployment.

Why this answer

In a VXLAN-EVPN deployment, each VTEP needs a unique underlay IP address used as the source for encapsulated traffic, and EVPN relies on MP-BGP to distribute MAC and IP reachability. Multicast is optional and typically replaced by ingress replication, anycast VTEP is a design choice, and the underlay must be Layer 3 for scalability. These two statements accurately describe the core requirements.

Exam trap

The trap here is assuming VXLAN always requires multicast in the underlay, which is only true for flood-and-learn without a control plane.

1423
MCQeasy

A network administrator is configuring a Cisco IOS switch to support a new voice VLAN. The administrator wants to ensure that voice traffic is tagged with CoS 5 and data traffic is untagged. Which command should be applied to the interface connected to an IP phone?

A.switchport voice vlan 10
B.switchport trunk encapsulation dot1q
C.mls qos trust cos
D.switchport mode access
AnswerA

This command enables the voice VLAN on the interface, allowing the switch to send Cisco Discovery Protocol (CDP) or Link Layer Discovery Protocol (LLDP) information to the IP phone. The phone can then tag voice traffic with the appropriate VLAN and CoS. It also allows data traffic from the PC to be untagged. This is the correct configuration for a voice VLAN.

Why this answer

The switchport voice vlan command enables the voice VLAN on an access port, allowing the switch to advertise the voice VLAN to the IP phone via CDP or LLDP. The phone then tags voice frames with the voice VLAN and CoS, while data from the attached PC remains untagged. Other commands like trunk encapsulation or access mode do not provide voice VLAN functionality.

QoS trust may be needed but is not the primary configuration.

Exam trap

The trap here is confusing voice VLAN configuration with trunk configuration or QoS trust, which are related but do not by themselves enable voice VLAN separation.

1424
MCQeasy

A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote users. The requirement is to use a protocol that supports both IKEv2 and native IPv6 transport, and that can provide per-user policy enforcement. Which technology should the administrator implement?

A.Dynamic Multipoint VPN (DMVPN) with mGRE and NHRP.
B.FlexVPN with IKEv2 and per-user attributes.
C.GET VPN with Group Domain of Interpretation (GDOI).
D.SSL VPN with Cisco AnyConnect.
AnswerB

FlexVPN is a Cisco IOS framework that uses IKEv2 and supports IPv6 transport. It allows per-user policy enforcement through authorization attributes such as IP address, DNS, and split tunnel ACLs. It is well suited for remote access VPN headends and can scale to many users while maintaining granular policy control.

Why this answer

FlexVPN is the correct choice because it is built on IKEv2 and supports IPv6 transport. It also provides per-user policy enforcement through authorization attributes, making it ideal for a remote access VPN headend. Other options either do not support IKEv2, are designed for site-to-site topologies, or lack per-user policy enforcement.

Exam trap

The trap here is equating remote access VPN with SSL VPN only, overlooking that FlexVPN also supports remote access with IKEv2 and per-user policies.

1425
MCQmedium

A network architect is designing a new branch office that must support a single physical link carrying traffic for multiple tenants while keeping each tenant's routing and forwarding isolated. The design requires that the branch device maintain separate routing tables and forwarding instances per tenant, all on the same physical interface using 802.1Q encapsulation. Which architecture component should be implemented on the branch router to meet these requirements?

A.Multiprotocol Label Switching (MPLS) L3VPN on the branch router
B.Policy-Based Routing (PBR) with route maps
C.Generic Routing Encapsulation (GRE) tunnels per tenant
D.Virtual Routing and Forwarding (VRF) with 802.1Q subinterfaces
AnswerD

VRF provides separate routing and forwarding tables on a single device, and combining it with 802.1Q subinterfaces allows traffic from multiple tenants to be tagged and mapped to distinct VRFs on the same physical link. This satisfies the isolation and shared-link requirements exactly as described.

Why this answer

VRF is the Cisco IOS XE feature that creates separate routing and forwarding tables on one device. When paired with 802.1Q subinterfaces, each tenant's VLAN tag maps to a specific VRF, allowing a single physical link to carry isolated tenant traffic. This directly fulfills the requirement for per-tenant routing isolation on a shared branch link.

Exam trap

The trap here is assuming that any encapsulation or tunneling technology automatically provides separate routing tables, when only VRF creates distinct RIBs and FIBs on the device.

Page 18

Page 19 of 26

Page 20