Courseiva

ENCOR 350-401 (350-401) — Questions 76–150

1923 questions total · 26pages · All types, answers revealed

Page 1

Page 2 of 26

Page 3
76
MCQeasy

A network engineer runs the following command on Router R4: R4# show ip sla monitor statistics 3 Round Trip Time (RTT) for Index 3 Latest RTT: 25 ms Latest Operation Start Time: 14:30:00.000 UTC Mon Mar 1 2021 Latest Operation Return Code: OK Number of successes: 100 Number of failures: 0 Over thresholds: 0 Based on this output, what can be concluded about the IP SLA operation?

A.The operation has experienced failures.
B.The operation is currently failing.
C.The operation is working correctly with no failures.
D.The round-trip time exceeds the threshold.
AnswerC

The IP SLA statistics reveal 100 successful probes with zero failures, meaning every request received a timely response and the operation has operated flawlessly over its lifetime. Additionally, the return code is 'OK', confirming the latest probe is also successful, and the over-threshold counter is 0, so no latency issues have been encountered. This all indicates the operation is functioning correctly and meeting its configured performance expectations.

Why this answer

The output shows 'Number of successes: 100' and 'Number of failures: 0', with a 'Latest Operation Return Code: OK', indicating that the IP SLA operation has been consistently successful without any failures. The latest RTT of 25 ms and the absence of threshold violations confirm the operation is working correctly.

Exam trap

Cisco often tests the distinction between 'Number of failures' (historical count) and 'Latest Operation Return Code' (current status), leading candidates to misinterpret a zero failure count as meaning the operation is currently failing when it is actually succeeding.

How to eliminate wrong answers

Option A is wrong because the output explicitly shows 'Number of failures: 0', meaning no failures have occurred, not that the operation has experienced failures. Option B is wrong because the 'Latest Operation Return Code: OK' indicates the operation is currently succeeding, not failing. Option D is wrong because the output shows 'Over thresholds: 0', meaning the round-trip time has never exceeded the configured threshold, contradicting the claim that it exceeds the threshold.

77
MCQeasy

A network engineer runs the following command on Switch SW5: SW5# show spanning-tree vlan 50 VLAN0050 Spanning tree enabled protocol ieee Root ID Priority 24626 Address aabb.cc00.0800 Cost 4 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32768 (priority 32768 sys-id-ext 50) Address aabb.cc00.0900 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- ------------------------------ Gi0/1 Root FWD 4 128.1 P2p Gi0/2 Desg FWD 4 128.2 P2p Gi0/3 Desg FWD 4 128.3 P2p Gi0/4 Altn BLK 4 128.4 P2p Based on this output, how many ports are in the Forwarding state?

A.1
B.2
C.3
D.4
AnswerC

Option 3 is correct. The `show spanning-tree` output for this VLAN/instance lists Gi0/1, Gi0/2, and Gi0/3 in the Forwarding (FWD) state, meaning these three ports are actively forwarding Ethernet frames. Gi0/4 is shown in the Blocking (BLK) state, so it is not forwarding user traffic. Therefore, exactly three ports are in the forwarding state, making answer 3 the correct choice.

Why this answer

The output shows four interfaces: Gi0/1 (Root FWD), Gi0/2 (Desg FWD), Gi0/3 (Desg FWD), and Gi0/4 (Altn BLK). Three ports (Gi0/1, Gi0/2, Gi0/3) are in the Forwarding state, while Gi0/4 is in the Blocking state. Therefore, the correct answer is 3.

Exam trap

Cisco often tests the ability to distinguish between port roles and port states; candidates may confuse the number of ports in a role (e.g., Root, Designated) with the number in the Forwarding state, or mistakenly count the Alternate port as forwarding because it has a role, ignoring its BLK state.

How to eliminate wrong answers

Option A is wrong because only 1 port in Forwarding would ignore the two Designated ports (Gi0/2 and Gi0/3) that are clearly marked FWD. Option B is wrong because 2 ports in Forwarding would miss either the Root port or one of the Designated ports, but all three are actively forwarding. Option D is wrong because 4 ports in Forwarding would include the Alternate port Gi0/4, which is in the Blocking (BLK) state, not Forwarding.

78
Drag & Dropmedium

Drag and drop the steps of VRF-aware NAT configuration steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order first defines the VRF, then configures the NAT inside and outside interfaces under the VRF, defines the NAT pool or ACL for translation, applies the NAT rule referencing the VRF, and finally verifies the translation with show ip nat translations vrf.

79
MCQmedium

Examine the following configuration snippet on a Cisco IOS switch: interface GigabitEthernet0/2 switchport mode access switchport access vlan 50 spanning-tree portfast Which statement is true about this interface?

A.The interface will immediately forward traffic without any spanning-tree delay.
B.The interface will participate in trunking and forward multiple VLANs.
C.The interface will still go through listening and learning states before forwarding.
D.The interface will only forward traffic for VLAN 1.
AnswerA

PortFast is configured on this access port, so the switch immediately moves the interface to the STP forwarding state, bypassing the 15-second listening and 15-second learning states. It still runs Spanning Tree Protocol and can send BPDUs, but it does not wait for the normal 30-second convergence delay before forwarding user traffic. This is intended for end hosts that should not cause a layer-2 loop.

Why this answer

The `spanning-tree portfast` command on an access port configured with `switchport mode access` and `switchport access vlan 50` causes the interface to bypass the normal spanning-tree listening and learning states. This allows the port to transition directly to the forwarding state, enabling immediate traffic forwarding without the usual 30-second delay (15 seconds for listening, 15 seconds for learning) associated with Rapid Spanning Tree Protocol (RSTP) or the 50-second delay with classic STP (802.1D).

Exam trap

Cisco often tests the misconception that `spanning-tree portfast` only applies to trunk ports or that it still requires the listening/learning states, when in fact it is designed specifically to bypass those states on access ports (or trunk ports with the `spanning-tree portfast trunk` variant).

How to eliminate wrong answers

Option B is wrong because the interface is configured as an access port (`switchport mode access`), which does not participate in trunking and only forwards traffic for a single VLAN (VLAN 50), not multiple VLANs. Option C is wrong because `spanning-tree portfast` specifically causes the interface to skip the listening and learning states and immediately enter the forwarding state, contradicting the claim that it will still go through those states. Option D is wrong because the `switchport access vlan 50` command assigns the interface to VLAN 50, not VLAN 1; the default VLAN for access ports is VLAN 1 only if no explicit access VLAN is configured.

80
MCQeasy

Which SNMP version introduced the use of a username and authentication/password framework, without encryption?

A.SNMPv1
B.SNMPv2c
C.SNMPv3
D.SNMPv2u
AnswerC

SNMPv3 is the correct answer because its User-based Security Model (USM) uses a username and engineID to create localized authentication keys. USM supports authentication via HMAC-MD5 or HMAC-SHA and can encrypt traffic with AES or DES, providing noAuthNoPriv, authNoPriv, and authPriv security levels. This is the first SNMP standard to support real user-based authentication and view-based access control.

Why this answer

SNMPv3 introduced a security model that provides both authentication and privacy (encryption), but the question specifically asks for the version that introduced a username and authentication/password framework without encryption. SNMPv3's User-based Security Model (USM) allows for authentication-only mode (authNoPriv), which uses a username and password (or key) for authentication but does not encrypt the payload. This distinguishes it from earlier versions that relied on community strings (SNMPv1 and SNMPv2c) or offered no standardized security framework.

Exam trap

Cisco often tests the misconception that SNMPv3 always requires encryption, when in fact it supports an authentication-only mode (authNoPriv) that matches the question's description exactly, causing candidates to overlook SNMPv3 if they think encryption is mandatory.

How to eliminate wrong answers

Option A is wrong because SNMPv1 uses only plaintext community strings for access control, with no username or authentication framework. Option B is wrong because SNMPv2c also uses community strings and adds no security enhancements over SNMPv1; it focuses on improved protocol operations (e.g., GetBulk) but lacks any authentication or encryption. Option D is wrong because SNMPv2u was an experimental party-based security model that introduced usernames and authentication, but it was never standardized as a full RFC and did not achieve widespread adoption; SNMPv3 is the definitive standard that introduced the username/password framework with optional encryption.

81
MCQmedium

Given the following Ansible playbook snippet: --- - name: Backup running config hosts: routers gather_facts: no tasks: - name: Save config ios_config: backup: yes backup_options: dir_path: /backup/ What is the purpose of the 'backup_options' parameter?

A.It specifies the directory where the backup file will be saved.
B.It specifies the filename for the backup.
C.It enables compression of the backup file.
D.It is ignored because backup: yes is already set.
AnswerA

In Ansible's Cisco IOS configuration modules (such as ios_config), the 'backup_options' parameter accepts a dictionary with a 'dir_path' key. This key determines the local filesystem directory where the configuration backup file is written when backup functionality is enabled. The filename itself is automatically generated with a timestamp, so dir_path only controls the location, not the name.

Why this answer

The 'backup_options' parameter in the ios_config module allows you to customize the backup behavior. Specifically, the 'dir_path' sub-option defines the directory path where the backup file will be saved. Without this parameter, the backup file is saved in the default location (the 'backup' subdirectory of the playbook's root directory).

Option A correctly identifies this purpose.

Exam trap

Cisco often tests the distinction between the 'backup' and 'backup_options' parameters, trapping candidates who think 'backup_options' is optional or ignored when 'backup: yes' is set, or who assume it controls the filename directly rather than the directory path.

How to eliminate wrong answers

Option B is wrong because the 'backup_options' parameter does not directly specify the filename; the filename is automatically generated by Ansible based on the hostname and timestamp. Option C is wrong because the ios_config module does not support compression of backup files; there is no 'compress' or similar sub-option in 'backup_options'. Option D is wrong because 'backup_options' is not ignored when 'backup: yes' is set; it provides additional configuration for the backup location and is fully functional.

82
MCQmedium

An enterprise is implementing MPLS L3VPN to connect multiple branch offices. The PE routers are using eBGP to exchange VPNv4 routes. The engineer notices that some VPN routes are not being advertised to the remote PE. The 'show bgp vpnv4 unicast all' on the local PE shows the routes as valid but not best. What is the most likely reason?

A.The route has a higher local preference than the best path.
B.The route is not valid due to a missing label.
C.The route is not in the BGP table.
D.The route has a higher MED value than the best path.
AnswerD

Multi-Exit Discriminator (MED) is an attribute carried across an AS and is compared only for routes from the same neighboring AS; the lowest MED is preferred. A higher MED value makes a route less desirable and would cause BGP to select the competing path with the lower MED as best. Therefore, this route being non-best is consistent with having a higher MED than the best path.

Why this answer

In BGP, the route with the highest local preference is preferred, so option A is incorrect. The route is valid, so options B and C are incorrect because a missing label would make it invalid, and being in the BGP table is confirmed. MED (Multi-Exit Discriminator) is used in the BGP path selection process; a higher MED value makes a route less preferred compared to a lower MED.

Therefore, if the route has a higher MED than the best path, it will not be selected as best, even though it is valid. This is the most likely reason for the route being valid but not best.

Exam trap

Candidates often assume that a valid route is always advertised, but BGP only advertises the best path. The trap here is confusing local preference and MED: high local preference increases preference, while high MED decreases preference.

How to eliminate wrong answers

Option B is wrong because if the route were missing a label, it would be marked as 'not valid' in the BGP table, not 'valid but not best'. Option C is wrong because the question explicitly states the route is shown in the 'show bgp vpnv4 unicast all' output, so it is in the BGP table. Option D is wrong because a higher MED value would make the route less preferred only if the paths are from the same neighboring AS; however, the route is already valid, and MED is compared after LP and AS-path length, so a higher MED would not cause the route to be valid but not best if LP is the deciding factor.

83
MCQeasy

A network engineer is configuring a Cisco IOS router to support OSPFv3 for IPv6. The router must form adjacencies on its GigabitEthernet0/0 interface, which is assigned to area 0. Which command is required to enable OSPFv3 on the interface?

A.ospf ipv6 1 area 0
B.router ospfv3 1 area 0
C.ipv6 router ospf 1 area 0
D.ipv6 ospf 1 area 0
AnswerD

The command 'ipv6 ospf 1 area 0' is used in interface configuration mode to enable OSPFv3 on that interface and assign it to area 0. The process ID '1' must match the OSPFv3 process configured globally with 'ipv6 router ospf 1'. This command allows the interface to form adjacencies and participate in OSPFv3. Without it, OSPFv3 will not run on the interface, even if the global process is configured.

Why this answer

To enable OSPFv3 on an interface, you use the interface configuration command 'ipv6 ospf <process-id> area <area-id>'. This command activates OSPFv3 on the interface and assigns it to the specified area. The process ID must match the one configured globally with 'ipv6 router ospf <process-id>'.

The other options are invalid commands or incorrect syntax.

Exam trap

The trap here is mixing up the global OSPFv3 command with the interface-level command, or reversing the keyword order.

84
MCQhard

An engineer is writing an Ansible playbook to configure OSPF on a fleet of Cisco Nexus 9000 switches. The playbook uses the nxos_ospf module. When executed, the playbook reports 'changed' for every switch, even on subsequent runs when no configuration changes are made. The engineer wants to achieve idempotent behavior. What is the most likely cause of the non-idempotent results?

A.The Ansible control node is using an outdated version of the nxos_ospf module that does not support idempotency.
B.The playbook does not specify all OSPF parameters, such as 'router-id', causing the module to detect a difference with the running configuration.
C.The switches have different NX-OS versions, causing the module to behave inconsistently.
D.The engineer forgot to use the '--check' flag to verify idempotency.
AnswerB

The playbook is likely omitting OSPF attributes that the nxos_ospf module tracks, such as 'router-id'. When a parameter is not specified, the module may treat the desired value as empty or default (e.g., the router-id derived from the loopback address), while the running configuration contains an explicit value, causing the module to detect a difference and report 'changed'. This is a classic idempotency issue: the module does not ignore unspecified parameters; it attempts to reconcile the configuration to the playbook's declared state, and every run sees the same mismatch.

Why this answer

The nxos_ospf module requires all mandatory OSPF parameters to be explicitly defined in the playbook to achieve idempotency. If parameters such as 'router-id' are omitted, the module compares the current running configuration (which may have a default or previously configured router-id) against the playbook's parameters. Since the playbook does not specify the router-id, the module interprets this as a missing parameter and attempts to reconfigure OSPF, resulting in a 'changed' status on every run.

Specifying all OSPF parameters ensures the module can accurately detect that the desired state matches the current state.

Exam trap

Cisco often tests the misconception that omitting optional parameters in Ansible modules will be ignored, when in fact the module treats missing parameters as a mismatch, causing non-idempotent behavior.

How to eliminate wrong answers

Option A is wrong because the nxos_ospf module has supported idempotency for many releases; an outdated version would typically cause errors or missing features, not a persistent 'changed' status on every run. Option C is wrong because different NX-OS versions may affect module behavior, but the core issue is parameter specification, not version inconsistency; the module is designed to work across versions with proper parameters. Option D is wrong because the '--check' flag is used to simulate changes and verify idempotency, not to cause or fix idempotency issues; forgetting it does not cause non-idempotent results.

85
Multi-Selecthard

A network engineer is implementing Cisco TrustSec in a campus network. Which two components are required to enable Security Group Tagging (SGT) and enforcement? (Choose two.)

Select 2 answers
A.Spanning Tree Protocol (STP) root guard
B.Dynamic Host Configuration Protocol (DHCP) snooping
C.Cisco Identity Services Engine (ISE)
D.Access Control List (ACL) for each user
E.Security Group Tag Exchange Protocol (SXP)
AnswersC, E

Cisco ISE is the policy server that assigns SGTs to users and devices during authentication. It also defines security group access control policies (SGACLs) that determine which tags can communicate. Without ISE, there is no centralized source for tag assignment and policy, so it is a fundamental component of a TrustSec deployment.

Why this answer

To implement Cisco TrustSec with SGT tagging and enforcement, Cisco ISE is required to assign SGTs and define policies, and SXP is needed to propagate SGT mappings to non-TrustSec-capable devices. Together, they enable scalable group-based access control across the network.

Exam trap

The trap here is thinking that traditional security features like DHCP snooping or per-user ACLs are part of TrustSec, when TrustSec uses SGTs and SGACLs managed by ISE.

86
Drag & Dropmedium

Drag and drop the steps of AAA method list fallback from RADIUS to local into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

When a method list specifies RADIUS then local, the device first attempts RADIUS authentication. If the RADIUS server is unreachable (timeout), the device falls back to the next method in the list, which is local authentication using the local user database.

87
MCQmedium

A network architect is designing a three-tier campus network with a pair of Cisco Catalyst 9500 switches at the core. The design requires that the core layer avoid maintaining a large MAC address table and instead forward traffic based on Layer 3 reachability. Which technology should be implemented on the core switches to meet this requirement?

A.VLAN Trunking Protocol pruning
B.Layer 3 switching with routed ports
C.Routed access layer
D.Cisco StackWise Virtual
AnswerB

Configuring the core switches with routed ports (no switchport) enables pure Layer 3 forwarding, eliminating MAC address table entries for those interfaces and relying on routing protocols or static routes. This directly satisfies the requirement to avoid a large MAC address table and forward based on Layer 3 reachability, which is typical in a three-tier campus core.

Why this answer

In a three-tier campus design, the core layer should be optimized for high-speed Layer 3 forwarding. Using routed ports on the core switches eliminates Layer 2 switching and MAC address table scaling concerns, allowing the core to forward solely based on Layer 3 reachability. This aligns with Cisco's recommended design for large campus networks.

Exam trap

The trap here is assuming that any high-availability technology like StackWise Virtual automatically converts the core to Layer 3 forwarding, when in fact it only provides logical device consolidation.

88
MCQhard

A network engineer is troubleshooting an OSPF issue where a router is not learning a route to a network that is advertised via a type 5 LSA from an ASBR. The engineer checks the OSPF database and sees the type 5 LSA, but the route is not in the routing table. The forwarding address in the LSA is 0.0.0.0. What is the most likely cause?

A.The ASBR is not reachable via an OSPF internal route.
B.The type 5 LSA has a metric of 16777215.
C.The OSPF process ID on the ASBR is different from the other routers.
D.The type 5 LSA is being filtered by an outbound route filter.
AnswerA

OSPF computes external routes from type 5 LSAs only if the originating ASBR is reachable through an intra-area or inter-area route. The SPF algorithm builds a shortest-path tree to the ASBR first; if the ASBR's router LSA is missing or the resulting next hop has no valid OSPF route, the external prefix is left in the LSDB but never installed in the RIB. This is a fundamental adjacency-dependent rule for external route installation.

Why this answer

When a Type 5 LSA has a forwarding address of 0.0.0.0, OSPF routers will use the ASBR as the next hop for the external route. For the route to be installed in the routing table, the ASBR must be reachable via an OSPF intra-area or inter-area route. If the ASBR is not reachable (e.g., no valid OSPF route to the ASBR's router ID), the Type 5 LSA is considered unreachable and is not installed, even though it exists in the OSPF database.

Exam trap

Cisco often tests the misconception that a Type 5 LSA present in the database automatically guarantees the route is installed, but the trap here is that the forwarding address of 0.0.0.0 requires the ASBR to be reachable via an OSPF internal route, which is a common oversight.

How to eliminate wrong answers

Option B is wrong because a metric of 16777215 (the maximum OSPF metric) would cause the route to be considered unreachable, but the question states the LSA is present in the database and the forwarding address is 0.0.0.0, not that the metric is invalid. Option C is wrong because OSPF process IDs are locally significant and do not affect the exchange of LSAs or route installation between routers; different process IDs on different routers do not prevent route learning. Option D is wrong because an outbound route filter would prevent the LSA from being sent or received, but the engineer confirms the Type 5 LSA is present in the database, meaning it was not filtered.

89
MCQhard

A network engineer is configuring MPLS TE (Traffic Engineering) in an MPLS core to optimize bandwidth utilization. After enabling MPLS TE on all core routers and configuring tunnels, the engineer notices that traffic is not being rerouted when a link fails. The 'show mpls traffic-eng tunnels' shows the tunnels are up but not using the backup path. What is the most likely missing configuration?

A.MPLS TE FRR (Fast Reroute) is not configured on the tunnels.
B.LDP is not enabled on the core interfaces.
C.RSVP is not configured on the core routers.
D.OSPF is not configured with MPLS TE extensions.
AnswerA

MPLS TE Fast Reroute is the mechanism that provisions pre-established bypass tunnels to protect specific links or nodes along the primary TE path. Without FRR, a link failure forces the headend LSR to detect the outage, recompute a new path using CSPF, and re-signal the tunnel, resulting in a multi-second outage. Enabling FRR with the 'fast-reroute' or 'link protection' keyword under the tunnel interface is what actually installs precomputed backup paths for immediate local protection.

Why this answer

MPLS TE Fast Reroute (FRR) is the mechanism that provides local protection and rapid traffic rerouting upon link or node failure. Without FRR configured on the tunnels, the head-end router must detect the failure, recompute the path, and signal a new LSP, which is a slow process. The fact that tunnels are up but not using a backup path indicates that FRR backup tunnels (e.g., link or node protection) have not been configured, so traffic continues to flow through the failed link until the head-end reacts.

Exam trap

Cisco often tests the distinction between MPLS TE tunnel establishment and MPLS TE protection mechanisms; candidates mistakenly assume that simply enabling MPLS TE and configuring tunnels automatically provides fast reroute, but FRR is a separate configuration step requiring explicit backup tunnel definitions.

How to eliminate wrong answers

Option B is wrong because LDP is not required for MPLS TE; MPLS TE uses RSVP-TE for label distribution and path signaling, not LDP. Option C is wrong because RSVP must be enabled on core routers for MPLS TE to function; if RSVP were missing, tunnels would not be established at all, but the scenario states tunnels are up. Option D is wrong because while OSPF with TE extensions (opaque LSAs) is needed for traffic engineering database (TED) and path computation, the absence of this configuration would prevent tunnels from being set up or optimized, but the tunnels are already up; the issue is specifically about failure rerouting, which requires FRR.

90
Multi-Selecthard

Which three statements about extended ACLs on Cisco IOS are true? (Choose three.)

Select 3 answers
A.Extended ACLs can filter based on source and destination IP addresses.
B.Extended ACLs can filter based on TCP or UDP port numbers.
C.Extended ACLs are processed in order until a matching permit or deny statement is found.
D.Extended ACLs can filter based on source MAC addresses.
E.Extended ACLs only filter traffic based on the source IP address.
AnswersA, B, C

Extended ACLs match on Layer 3 and Layer 4 fields, including both source and destination addresses, unlike standard ACLs which filter on source only. This satisfies the stem's requirement by confirming the broader matching capability that distinguishes extended from standard ACLs on Cisco IOS.

Why this answer

Option A is correct because extended ACLs match on both source and destination IP addresses, unlike standard ACLs that match only the source. Option B is correct because extended ACLs can specify Layer 4 protocol (TCP/UDP) and port numbers using operators like eq, gt, lt, and range. Option C is correct because ACLs are evaluated top-down, and the first matching statement is applied; once a match occurs, no further entries are checked.

Option D is not correct because MAC address filtering requires MAC ACLs (e.g., mac access-list), not extended IP ACLs. Option E is not correct because filtering solely on source IP is the behavior of standard ACLs, not extended ACLs.

Exam trap

350-401 often tests the misconception that extended ACLs can filter on MAC addresses or only source IP, but they operate at Layer 3 and 4, not Layer 2.

91
Drag & Dropmedium

Drag and drop the steps of the 802.1X EAP-TLS authentication exchange into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In the 802.1X EAP-TLS authentication exchange, the process begins with the supplicant sending an EAPoL-Start message to initiate authentication. The authenticator then sends an EAP-Request/Identity. The supplicant replies with EAP-Response/Identity, which the authenticator forwards to the RADIUS server.

Finally, the RADIUS server sends an EAP-Request for the client certificate to begin the TLS handshake.

92
Multi-Selecthard

Which three statements about Cisco TrustSec security group access control lists (SGACLs) are true? (Choose three.)

Select 3 answers
A.SGACLs define policies based on source and destination security group tags.
B.SGACLs are typically downloaded from the Cisco ISE policy server to network devices.
C.SGACLs are applied directly to switch ports using the ip access-group command.
D.SGACLs can be used to permit or deny traffic between different security groups.
E.SGACLs can rewrite the security group tag in the packet header.
AnswersA, B, D

TrustSec SGACLs are enforced against security group tags rather than IP addresses, so each rule matches a source SGT and destination SGT pair. This satisfies the stem's requirement for a true statement about SGACL policy definition.

Why this answer

Option A is correct because Cisco TrustSec SGACLs are policy constructs that match on source and destination Security Group Tags (SGTs) rather than IP addresses, enabling group-based rather than topology-based enforcement. Option B is correct because in a TrustSec deployment, SGACL policies are defined and managed on Cisco ISE (the policy server) and downloaded to the enforcing network devices (such as switches and routers) via the SXP or native TrustSec enforcement mechanisms. Option D is correct because the fundamental purpose of an SGACL is to permit or deny traffic flowing between different security groups, with each SGACL specifying the actions (permit, deny, or logging) for traffic from a source SGT to a destination SGT.

Option C is not correct because SGACLs are not applied with the ip access-group command; that command applies traditional IP ACLs to interfaces, whereas SGACLs are enforced through TrustSec policy and referenced by the device's role-based enforcement configuration. Option E is not correct because SGACLs do not rewrite the SGT in the packet header; the SGT is inserted or propagated by the TrustSec classification and tagging functions (for example, on the ingress device or via SXP), while SGACLs only enforce permit/deny decisions based on the existing tags.

Exam trap

The trap is confusing SGACLs with traditional ACLs, leading candidates to select options about applying them to ports or rewriting tags, which are not functions of SGACLs.

93
MCQmedium

Examine the following configuration: flow exporter EXPORTER-1 destination 10.0.0.1 source Loopback0 transport udp 2055 option interface-table option application-table ! What is the purpose of the 'option interface-table' and 'option application-table' commands?

A.They cause the exporter to send interface and application metadata to the collector periodically.
B.They filter the flow data to include only traffic from the specified interfaces and applications.
C.They enable the exporter to collect interface and application statistics locally.
D.They are required only when using IPFIX, not NetFlow v9.
AnswerA

In NetFlow v9 and IPFIX, option data records are carried in dedicated option template flow sets that the exporter transmits on a periodic interval. These records supply metadata such as interface names, interface descriptions, and application IDs, which the collector uses to enrich the flow records it has already received. Because option data is refresh-based, the exporter re-sends it so the collector always has current context.

Why this answer

The 'option interface-table' and 'option application-table' commands configure the NetFlow exporter to periodically send metadata (interface names/descriptions and application-to-port mappings) to the collector. This metadata is essential for the collector to interpret flow records correctly, especially when interfaces are renamed or applications are dynamically mapped. The exporter sends these options templates at a default interval (e.g., every 600 seconds) via UDP 2055, independent of regular flow records.

Exam trap

Cisco often tests the distinction between 'exporting metadata' versus 'filtering or collecting locally' — the trap here is assuming these commands affect which flows are sent rather than enriching the data the collector receives.

How to eliminate wrong answers

Option B is wrong because these commands do not filter flow data; they only cause metadata to be exported. Filtering is done via flow record match statements or access-lists, not exporter options. Option C is wrong because the exporter does not store or analyze statistics locally; it simply forwards the metadata to the collector.

Option D is wrong because both NetFlow v9 and IPFIX support option templates; the commands are not exclusive to IPFIX.

94
Multi-Selecthard

A network architect is evaluating Cisco SD-Access fabric deployment options for a large campus. The design team wants to understand the roles that fabric nodes play in forwarding traffic and in connecting the fabric to external networks. Which two statements accurately describe Cisco SD-Access fabric node roles? (Choose two.)

Select 2 answers
A.Fabric intermediate nodes maintain the LISP map database and answer EID-to-RLOC queries from edge nodes.
B.Fabric border nodes are responsible for registering wired endpoint EIDs and building VXLAN tunnels to access switches.
C.Fabric edge nodes run the LISP map-server and map-resolver functions for the entire fabric.
D.Fabric border nodes connect the SD-Access fabric to external networks and perform route redistribution between the fabric and external routing domains.
E.Fabric edge nodes encapsulate traffic from wired endpoints into VXLAN and register endpoint EIDs with the control-plane node.
AnswersD, E

Fabric border nodes provide the handoff between the fabric and external networks such as data center, WAN, or legacy campus. They run routing adjacencies and redistribute or leak routes between the fabric's VXLAN domain and outside domains, which is exactly what the scenario describes.

Why this answer

In Cisco SD-Access, fabric edge nodes encapsulate endpoint traffic in VXLAN and register EIDs with the control-plane node, while fabric border nodes connect the fabric to external networks and redistribute routes. Those two roles match the accurate statements, whereas intermediate and control-plane responsibilities are assigned incorrectly elsewhere.

Exam trap

The trap here is mixing up the control-plane node's LISP map-server duties with the forwarding duties of intermediate and edge nodes.

95
Drag & Dropmedium

Drag and drop the steps of SNMP community-based access control setup into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order is: first enable SNMP agent globally (E), then define the community string (A), then configure an access-list for the manager (B), then create an SNMP view (C), and finally apply the view to the community (D). Enabling the agent globally must occur first to activate SNMP on the device, followed by defining community strings and associating them with ACLs and views for access control.

96
MCQeasy

A network administrator is configuring a Cisco Catalyst switch to assign a voice VLAN to IP phones and a data VLAN to connected PCs on the same port. The phones are Cisco and use CDP to communicate VLAN information. Which configuration should be applied to the switch port?

A.Configure the port as an access port in the data VLAN and enable the voice VLAN with the 'switchport voice vlan' command.
B.Configure the port as a dynamic auto port and set the voice VLAN to be negotiated via DTP.
C.Configure the port as a private VLAN host port and map the voice VLAN as a secondary VLAN.
D.Configure the port as a trunk with native VLAN for data and allow the voice VLAN.
AnswerA

This configuration allows the switch port to carry data traffic for the PC in the access VLAN (untagged) and voice traffic for the phone in the voice VLAN (tagged with 802.1Q). The 'switchport voice vlan' command instructs the switch to use CDP to tell the phone which VLAN to use for voice. This is the standard and recommended method for connecting Cisco IP phones and PCs on the same port.

Why this answer

The correct configuration is to set the port as an access port in the data VLAN and then specify the voice VLAN using the 'switchport voice vlan' command. This allows the switch to use CDP to inform the IP phone of the voice VLAN, so the phone tags its voice traffic with the appropriate VLAN ID while the PC's data traffic remains untagged in the access VLAN. This is the Cisco best practice for connecting IP phones and PCs to the same switch port.

Exam trap

The trap here is thinking that a trunk port is required to carry both voice and data VLANs; in reality, an access port with a voice VLAN handles both, with the phone tagging voice traffic.

97
MCQhard

A network engineer is implementing Cisco TrustSec in a campus network. The requirement is to classify traffic based on the identity of the user and the device, and to enforce policy across the network without relying on IP addresses. Which component assigns the Security Group Tag (SGT) to the packet at ingress?

A.The egress switch removes the SGT and applies the Security Group ACL based on the source IP address.
B.The ingress access layer switch or router inserts the SGT into the packet using inline tagging or SXP.
C.The Cisco DNA Center appliance assigns the SGT during fabric VXLAN encapsulation.
D.The Cisco Identity Services Engine (ISE) assigns the SGT directly into the packet header.
AnswerB

The ingress network device is responsible for classifying traffic and imposing the SGT. It receives the SGT value from ISE during authentication, then inserts the tag into the packet using inline tagging (Cisco Metadata or 802.1AE) or propagates the mapping via SXP to devices that do not support inline tagging. This is the enforcement point for tag imposition.

Why this answer

In Cisco TrustSec, the ingress network device classifies traffic and imposes the SGT after receiving the classification from ISE. Tag propagation uses inline tagging or SXP, and egress devices enforce Security Group ACLs based on source and destination SGTs. The policy decision comes from ISE, but tag imposition happens at the ingress enforcement point.

Exam trap

The trap here is assuming that ISE, as the policy server, writes the SGT into packets, when ISE only provides the classification and the ingress network device performs tag imposition.

98
MCQmedium

A network engineer is troubleshooting connectivity issues in a multi-tenant environment where each tenant's traffic is isolated using VRF-Lite. The engineer notices that tenants in the same VRF cannot communicate with each other across different access switches. Which design change should be implemented to enable inter-switch VRF communication?

A.Use the same VLAN for all tenants and rely on VLAN ACLs.
B.Create trunk links with 802.1Q subinterfaces on each switch and assign each subinterface to the appropriate VRF.
C.Configure static routes on each switch pointing to the next-hop IP in the global routing table.
D.Enable OSPF with a single area on all switches and redistribute between VRFs.
AnswerB

Creating an 802.1Q trunk with subinterfaces lets each switch or router terminate multiple VLANs on a single physical link, and each subinterface can be explicitly bound to a tenant's VRF. This gives each tenant an isolated routing table; the switch will route packets received on a subinterface using only the routes in that subinterface's assigned VRF. The trunk carries tagged frames for all tenants, but the VRF association ensures that traffic from tenant A's VLAN never enters tenant B's routing path, even though they share the same physical ports and trunk. This is a standard VRF-lite design for inter-switch VRF connectivity.

Why this answer

VRF-Lite requires 802.1Q trunking to extend Layer 3 VRF boundaries across switches. By creating subinterfaces on trunk links and assigning each subinterface to the appropriate VRF, traffic from the same VRF on different switches can be routed through the VRF-specific routing table, enabling inter-switch communication while maintaining isolation.

Exam trap

Cisco often tests the misconception that VRF-Lite can use the global routing table for inter-switch communication, but the trap here is that VRF-Lite requires explicit Layer 3 subinterfaces on trunk links to extend VRF boundaries, not just VLANs or static routes in the global table.

How to eliminate wrong answers

Option A is wrong because using the same VLAN for all tenants with VLAN ACLs does not provide Layer 3 VRF isolation; it only filters at Layer 2/3 within the global routing table, breaking the multi-tenant separation required. Option C is wrong because static routes in the global routing table would bypass VRF isolation, mixing tenant traffic and defeating the purpose of VRF-Lite. Option D is wrong because OSPF with redistribution between VRFs is complex and not supported in VRF-Lite without additional protocols like MP-BGP; VRF-Lite relies on static or connected routes within each VRF, not dynamic routing redistribution.

99
Multi-Selectmedium

A network engineer is configuring a Cisco IOS XE router to support a site-to-site VXLAN tunnel over an existing IP underlay. The engineer must configure the NVE interface and ensure that the underlay provides the necessary transport. Which two statements are true about this configuration? (Choose two.)

Select 2 answers
A.The NVE interface must be assigned an IP address from the same subnet as the remote VTEP.
B.VXLAN requires that the underlay provide Layer 2 adjacency between all VTEPs.
C.The underlay must run MPLS LDP to carry VXLAN traffic between VTEPs.
D.VXLAN uses UDP port 4789 as the destination port for encapsulated traffic by default.
E.The NVE interface is configured with a source interface that provides the tunnel source IP address.
AnswersD, E

VXLAN encapsulates Layer 2 frames in UDP, and the IANA-assigned default destination port is 4789. Cisco platforms use this port by default when sending VXLAN-encapsulated traffic. If a firewall or ACL is in the path, it must permit UDP 4789 so that the tunnel traffic is not dropped. Changing the port is possible but uncommon and must match on all VTEPs.

Why this answer

VXLAN on Cisco IOS XE uses an NVE interface that references a source interface for the tunnel source IP, and it encapsulates frames in UDP with default destination port 4789. The underlay only needs IP reachability between VTEPs; MPLS LDP, shared subnets, and Layer 2 adjacency are not required. These two statements correctly describe the configuration and transport behavior.

Exam trap

The trap here is assuming VXLAN needs MPLS or Layer 2 adjacency in the underlay, when it actually runs over a plain IP underlay using UDP 4789 and a sourced NVE interface.

100
Multi-Selecthard

Which three statements about CoPP configuration and operation are true? (Choose three.)

Select 3 answers
A.CoPP uses a class map to classify traffic destined for the control plane.
B.CoPP uses the 'police' command within a policy map to rate-limit traffic.
C.The 'control-plane' command is used to enter control plane configuration mode.
D.CoPP is applied using the 'ip access-group' command on the control plane interface.
E.CoPP can only filter IPv4 traffic.
AnswersA, B, C

CoPP class maps identify control-plane traffic by matching ACLs or protocols, separating it into classes. The policy map then applies actions per class, satisfying the requirement to classify traffic destined for the control plane before rate-limiting it.

Why this answer

Option A is correct because CoPP (Control Plane Policing) relies on a class map to identify and classify traffic that is destined to the control plane, typically using ACLs or match statements to select protocols such as routing updates, management traffic, or ICMP. Option B is correct because the rate-limiting action in CoPP is implemented by configuring the 'police' command inside a policy map, which enforces a committed information rate (CIR) and burst parameters on the classified control-plane traffic. Option C is correct because the 'control-plane' global configuration command enters control plane configuration mode, where the service policy is attached to the control plane using the 'service-policy' command.

Option D is not correct because CoPP is not applied with 'ip access-group' on a control plane interface; instead, the policy map is attached under control plane configuration mode with 'service-policy'. Option E is not correct because CoPP can match and police more than IPv4 traffic, including IPv6, ARP, and other non-IP control-plane protocols, depending on the platform and class-map configuration.

Exam trap

350-401 often tests the specific commands and application points for CoPP, and candidates may confuse it with interface ACLs or assume it only supports IPv4.

101
Drag & Dropmedium

Drag and drop the steps of service function chaining (SFC) path setup into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

SFC path setup begins with classifying traffic to determine which service chain to apply. Next, the classifier encapsulates packets with an NSH header. Then the SFC path is computed by the controller using the service function path identifier.

After path computation, the controller installs forwarding entries in each service function forwarder. Finally, traffic traverses the chain as SFFs forward packets between VNFs.

102
MCQeasy

A network engineer is configuring an EtherChannel between two Cisco switches. The engineer wants to use PAgP and ensure that the channel forms only if the neighboring switch is also configured for PAgP. Which mode should be configured on the local switch?

A.Configure 'channel-group 1 mode desirable' on the physical ports.
B.Configure 'channel-group 1 mode auto' on the physical ports.
C.Configure 'channel-group 1 mode active' on the physical ports.
D.Configure 'channel-group 1 mode on' on the physical ports.
AnswerA

PAgP desirable mode actively transmits PAgP packets on the physical ports, initiating the negotiation to form an EtherChannel with the neighboring switch. This is the required behavior when the peer is configured with a PAgP mode such as desirable or auto, because desirable ensures that at least one side is driving the negotiation. It also validates that the ports on both ends meet consistency requirements before the channel is established.

Why this answer

PAgP (Port Aggregation Protocol) is a Cisco proprietary protocol that negotiates EtherChannel links. The 'desirable' mode actively sends PAgP packets to initiate negotiation and will form a channel only with a neighbor also running PAgP (either in 'desirable' or 'auto' mode). This meets the requirement of ensuring the channel forms only if the neighbor is configured for PAgP.

Exam trap

Cisco often tests the distinction between PAgP and LACP modes, and the trap here is that candidates confuse 'active' (LACP) with 'desirable' (PAgP), or assume 'auto' is sufficient when the requirement is to actively ensure the neighbor is also running PAgP.

How to eliminate wrong answers

Option B is wrong because 'auto' mode passively waits for PAgP packets from the neighbor and will form a channel only if the neighbor is in 'desirable' mode, but it does not actively initiate negotiation; however, the question requires ensuring the channel forms only if the neighbor is also configured for PAgP, and 'auto' still allows formation with a PAgP neighbor, so it is not the best answer for active initiation. Option C is wrong because 'active' mode is used with LACP (IEEE 802.3ad), not PAgP; PAgP uses 'desirable' and 'auto' modes. Option D is wrong because 'on' mode forces the EtherChannel without any protocol negotiation, meaning it will form even if the neighbor is not running PAgP, which violates the requirement that the channel forms only if the neighbor is configured for PAgP.

103
MCQhard

A network administrator is implementing Cisco TrustSec in a data center. The security team wants to enforce segmentation based on user roles rather than IP addresses. The administrator has configured security group tags (SGTs) on the access layer switches and now needs to propagate this information across the network. Which protocol should be used to carry SGT information between Cisco TrustSec-capable devices?

A.RADIUS
B.TACACS+
C.SXP
D.802.1X
AnswerC

SXP (SGT Exchange Protocol) is used to propagate SGT information between Cisco TrustSec-capable devices, especially when some devices do not support hardware-based SGT tagging. It allows IP-to-SGT mappings to be shared across network boundaries, enabling consistent policy enforcement. In this scenario, SXP is the correct protocol to carry SGT information between devices that need to enforce role-based segmentation.

Why this answer

SXP (SGT Exchange Protocol) is designed to propagate SGT-to-IP mappings between Cisco TrustSec domains, particularly when devices cannot natively tag packets with SGTs. It enables policy enforcement across network boundaries by sharing the mapping of IP addresses to security groups. This allows consistent role-based segmentation even in mixed environments.

Exam trap

The trap here is assuming that RADIUS, which can deliver SGTs during authentication, also propagates SGTs between network devices for enforcement, when that is the role of SXP.

104
MCQeasy

An engineer needs to configure a switchport to carry traffic for multiple VLANs to a router using a single physical link. Which configuration should be applied on the switchport?

A.Configure the port as a dynamic desirable port.
B.Configure the port as a trunk port.
C.Configure the port as a routed port.
D.Configure the port as an access port.
AnswerB

A trunk port tags frames with 802.1Q VLAN identifiers, allowing multiple VLANs to traverse one physical link to the router. Access ports carry only a single untagged VLAN, so they cannot satisfy the multi-VLAN requirement.

Why this answer

A trunk port is specifically designed to carry traffic for multiple VLANs over a single physical link using IEEE 802.1Q encapsulation. This allows the switch to tag frames with VLAN IDs, enabling the router (often configured as a router-on-a-stick) to route between VLANs.

Exam trap

The trap here is that candidates often confuse Dynamic Desirable (a DTP negotiation mode) with a trunk port configuration, thinking negotiation automatically results in trunking, but the question asks for the configuration that directly enables multi-VLAN traffic, not a negotiation protocol.

How to eliminate wrong answers

Option A is wrong because Dynamic Desirable is a Dynamic Trunking Protocol (DTP) mode that negotiates trunking with the remote device, but it does not directly configure the port to carry multiple VLANs; it is a negotiation state, not the final configuration. Option C is wrong because a routed port is a Layer 3 interface that operates like a router port, stripping all Layer 2 switching and VLAN tagging, so it cannot carry multiple VLANs on a single link. Option D is wrong because an access port belongs to only one VLAN and strips any VLAN tags from frames, making it unsuitable for carrying multiple VLANs.

105
MCQeasy

A network engineer is configuring a PPPoE client on a Cisco router for a DSL connection. The engineer configures the dialer interface with the correct PPPoE profile and authentication credentials. The PPPoE session establishes, but the router cannot ping the ISP's gateway IP address. The engineer checks the routing table and sees that a default route is present via the dialer interface. What is the most likely cause?

A.The dialer interface does not have an IP address negotiated via IPCP.
B.The physical interface is configured with 'no ip address'.
C.The default route is pointing to the wrong next-hop IP.
D.The ISP's gateway is not responding to ICMP.
AnswerA

The presence of an IP address on the dialer interface is fundamental to PPPoE operation. During PPPoE, the ISP assigns an IPv4 address through IPCP (IP Control Protocol) as part of the PPP negotiation. If the dialer interface lacks an IP address, the router cannot build a usable routing table entry for the default route, and all traffic destined for the Internet is dropped because there is no valid source address. Without this IPCP-assigned address, even though the PPPoE session is established at Layer 2, the router has no IP reachability to the ISP gateway.

Why this answer

In a PPPoE setup, the dialer interface typically obtains its IP address dynamically from the ISP via IPCP (IP Control Protocol) during PPP negotiation. If IPCP fails or is not configured to negotiate an address, the dialer interface remains unnumbered or without a usable IP address. Even though the PPPoE session is established and a default route exists, the router cannot route traffic because it lacks a valid source IP address on the dialer interface to send packets to the ISP's gateway.

Exam trap

Cisco often tests the distinction between a successful PPPoE session (Layer 2) and a fully functional IP layer (Layer 3), trapping candidates who assume a session establishment and a default route guarantee connectivity.

How to eliminate wrong answers

Option B is wrong because the physical interface (e.g., Ethernet) is often configured with 'no ip address' in a PPPoE configuration, as the dialer interface handles the IP layer; this is normal and does not prevent pinging the gateway. Option C is wrong because the default route is present via the dialer interface, not a specific next-hop IP; PPPoE uses a point-to-point link, so the route is implicitly via the interface, and a wrong next-hop IP is not applicable here. Option D is wrong because while the ISP's gateway might not respond to ICMP, the question states the router cannot ping the gateway, which is a symptom of a missing IP address on the dialer interface; ICMP filtering is a possible secondary issue but not the most likely cause given the session is up and a default route exists.

106
Drag & Dropmedium

Drag and drop the steps of MPLS Traffic Engineering (TE) tunnel setup (RSVP) into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

MPLS TE tunnel setup begins with IGP extension configuration to propagate link attributes, followed by explicit path definition. RSVP-TE then signals the tunnel using PATH messages, which are processed by intermediate routers to reserve bandwidth. Finally, RESV messages confirm the reservation and establish the tunnel.

107
MCQmedium

A network administrator is configuring 802.1X on a Cisco Catalyst switch. The switch is connected to a Cisco IP phone with a PC attached to the phone's data port. The requirement is to authenticate both the phone and the PC separately, with the phone in the voice VLAN and the PC in the data VLAN. Which 802.1X feature should be enabled?

A.Multi-Authentication (Multi-Auth)
B.MAC Authentication Bypass (MAB)
C.Multi-Domain Authentication (MDA)
D.Web Authentication (WebAuth)
AnswerC

MDA allows both a voice device (phone) and a data device (PC) to authenticate independently on the same switch port. Each device is authenticated in its respective VLAN (voice and data), and the switch applies separate policies. This meets the requirement of authenticating both devices separately.

Why this answer

Multi-Domain Authentication (MDA) is designed for scenarios where a voice device and a data device share a switch port. It allows both to authenticate independently and assigns them to their respective VLANs, meeting the requirement for separate authentication and VLAN segmentation.

Exam trap

The trap here is confusing Multi-Auth with MDA; Multi-Auth allows multiple devices but places them in the same VLAN, while MDA separates voice and data domains.

108
MCQmedium

Consider the following BGP configuration: router bgp 65000 bgp router-id 10.0.0.1 neighbor 10.0.0.2 remote-as 65001 neighbor 10.0.0.2 route-map SET-MED out ! route-map SET-MED permit 10 set metric 50 ! What is the effect of this route-map on outbound updates to neighbor 10.0.0.2?

A.It sets the MED to 50 for all routes advertised to 10.0.0.2, but only if they match a prefix-list.
B.It sets the MED to 50 for all routes advertised to 10.0.0.2.
C.It sets the local preference to 50 for routes received from 10.0.0.2.
D.It filters all routes to 10.0.0.2 because there is no match statement.
AnswerB

The route-map is applied in the outbound direction to neighbor 10.0.0.2. The single permit sequence without a match clause matches all routes, and the set metric 50 command sets the MED to 50. Therefore, every route advertised to that neighbor will carry the MED value of 50. No filtering occurs; the route-map simply modifies the MED attribute for all outbound updates.

Why this answer

The route-map SET-MED is applied to outbound updates to neighbor 10.0.0.2 with a permit sequence 10 and a set metric 50 command, but no match statement. In BGP, a route-map with a permit clause and no match condition matches all routes by default. Therefore, the MED (Multi-Exit Discriminator) attribute is set to 50 for every route advertised to that neighbor.

Exam trap

Cisco often tests the misconception that a route-map without a match statement will deny or filter all routes, but in reality, a permit clause with no match matches everything and applies the set actions.

How to eliminate wrong answers

Option A is wrong because the route-map does not reference any prefix-list, so it applies to all routes, not only those matching a prefix-list. Option C is wrong because the set metric command modifies the MED, not local preference; local preference is set with set local-preference and is an inbound attribute. Option D is wrong because a permit route-map without a match statement does not filter routes; it matches all routes and applies the set actions.

109
MCQeasy

A network administrator is using Cisco DNA Center Assurance to monitor the health of a campus network. The administrator wants to receive alerts when a switch's health score drops below a threshold. Which Assurance feature should be configured to generate these alerts?

A.Assurance Issues and Notifications
B.Sensor-driven tests
C.Network Health Dashboard
D.Path Trace
AnswerA

Cisco DNA Center Assurance allows administrators to define issues and configure notifications based on health score thresholds. By setting up assurance issues, the system can trigger alerts via email, syslog, or webhook when a switch's health score falls below a specified value. This is the correct feature for proactive alerting.

Why this answer

To generate alerts when a switch's health score drops below a threshold, the administrator must configure Assurance Issues and Notifications in Cisco DNA Center. This feature allows defining specific health score conditions and setting up notification channels such as email or webhooks. The Network Health Dashboard is for visualization, Path Trace for troubleshooting, and Sensor-driven tests for proactive monitoring, none of which provide threshold-based alerting directly.

Exam trap

The trap here is assuming that the Network Health Dashboard or Sensor-driven tests automatically send alerts, when in fact alerting requires explicit configuration of Assurance Issues and Notifications.

110
MCQmedium

A network engineer configured a router with the command `ip route 0.0.0.0 0.0.0.0 192.168.1.1` and also has a specific static route for 10.1.1.0/24 pointing to 192.168.1.1. A packet arrives destined for 10.1.1.5. Which route will the router use to forward the packet?

A.The specific static route for 10.1.1.0/24 because it has a longer prefix length.
B.The default route because it is less specific and matches all destinations.
C.The router will load-balance the packet across both routes.
D.The packet will be dropped because of conflicting static routes.
AnswerA

The router uses the longest prefix match rule. The specific route 10.1.1.0/24 has a prefix length of 24, while the default route has a prefix length of 0. The more specific route wins, so the packet is forwarded using the static route for 10.1.1.0/24 via 192.168.1.1.

Why this answer

The correct answer is the specific static route for 10.1.1.0/24. Cisco IOS uses longest prefix match to select the best route. A default route (0.0.0.0/0) is the least specific and is only used when no other route matches.

Since a more specific route exists for the destination, that route is chosen.

Exam trap

The trap here is assuming that a default route takes precedence because it is configured first or because it is a default route, but longest prefix match always wins regardless of configuration order.

111
MCQmedium

A network architect is designing a Cisco SD-Access fabric for a university campus that requires segmentation between student, faculty, and guest traffic. The design must use Cisco TrustSec for scalable security group tags (SGTs) and integrate with Cisco ISE for policy enforcement. Which fabric component should the architect use to enforce SGT-based policies at the access layer?

A.Fabric border node
B.Fabric control plane node
C.Fabric edge node
D.Wireless LAN controller
AnswerC

The fabric edge switch is the correct enforcement point for SGT policies in an SD-Access fabric. When a wired or wireless endpoint authenticates via ISE, the edge switch receives the SGT through RADIUS (or CoA) and associates it with the endpoint's MAC/IP address. Every packet from that endpoint is then classified with the SGT, and the edge switch applies the corresponding SGACL in hardware to permit or deny traffic based on source and destination SGTs. This occurs at the access layer, exactly where the endpoint connects, making the fabric edge the critical device for enforcing SGT-based policies.

Why this answer

The fabric edge node is the correct component because it is the access-layer switch in Cisco SD-Access that performs SGT-based enforcement. It receives SGT-to-SGT policy from Cisco ISE via the control plane node and applies the corresponding security ACLs (SGACLs) at the port level, ensuring segmentation between student, faculty, and guest traffic at the point of entry.

Exam trap

Cisco often tests the misconception that the fabric border node or control plane node enforces policies, when in fact the fabric edge node is the only device that applies SGT-based access control at the access layer.

How to eliminate wrong answers

Option A is wrong because the fabric border node connects the SD-Access fabric to external networks (e.g., WAN, data center) and handles SGT propagation between fabrics or to non-fabric devices, but it does not enforce SGT policies at the access layer. Option B is wrong because the fabric control plane node manages LISP overlay mappings and distributes SGT-to-IP bindings, but it does not perform inline policy enforcement on user traffic. Option D is wrong because the Wireless LAN Controller (WLC) manages CAPWAP tunnels and wireless client mobility, but in SD-Access, SGT-based enforcement at the access layer is handled by the fabric edge node (wired or wireless via the fabric-enabled WLC acting as a wireless edge), not the standalone WLC.

112
Drag & Dropmedium

Drag and drop the steps of OSPF SPF calculation steps (Dijkstra) into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The Dijkstra algorithm first initializes the candidate list with the root node, then iteratively moves the lowest-cost candidate to the tree, updating neighbor costs, and finally builds the routing table from the shortest-path tree.

113
MCQmedium

A network engineer runs the following command on Router R2: R2# debug ip dhcp server events *Mar 1 00:05:23.123: DHCPD: DHCPDISCOVER received from client 0063.6973.636f.2d30.3030.302e.3030.3030.2e30.3030.312d.4574.30 on interface GigabitEthernet0/1 *Mar 1 00:05:23.124: DHCPD: Sending DHCPOFFER to client 0063.6973.636f.2d30.3030.302e.3030.3030.2e30.3030.312d.4574.30 (10.0.0.2) *Mar 1 00:05:23.125: DHCPD: DHCPREQUEST received from client 0063.6973.636f.2d30.3030.302e.3030.3030.2e30.3030.312d.4574.30 *Mar 1 00:05:23.126: DHCPD: Sending DHCPACK to client 0063.6973.636f.2d30.3030.302e.3030.3030.2e30.3030.312d.4574.30 (10.0.0.2) Based on this debug output, what can be concluded?

A.The DHCP server failed to allocate an IP address to the client.
B.The client is using DHCPv6 because of the long client ID.
C.The DHCP server successfully assigned IP address 10.0.0.2 to the client.
D.The DHCP server is configured with a pool that excludes 10.0.0.2.
AnswerC

The DHCPACK message carries the allocated IPv4 address in the 'yiaddr' field; here that value is 10.0.0.2. After receiving a DHCPREQUEST, the server verifies the binding and responds with DHCPACK to conclude the lease creation process. This proves the server successfully assigned that specific address to the client, and the client is now permitted to configure 10.0.0.2 on its interface.

Why this answer

The debug output shows the complete DHCPv4 four-message exchange: DHCPDISCOVER, DHCPOFFER, DHCPREQUEST, and DHCPACK. The final DHCPACK from the server to the client with IP address 10.0.0.2 confirms that the server successfully assigned that address to the client. The absence of any DHCPNAK or error message indicates a successful allocation.

Exam trap

Cisco often tests the ability to interpret debug output by showing a successful DHCPACK and having candidates incorrectly assume a failure because they misread the hexadecimal client ID as DHCPv6 or because they confuse the DHCPOFFER with a final assignment.

How to eliminate wrong answers

Option A is wrong because the debug output shows a DHCPACK being sent, which is the server's final acknowledgment of a successful IP address assignment; a failure would result in a DHCPNAK. Option B is wrong because the long client ID is a DHCPv4 client identifier (option 61) encoded in hexadecimal, not a DHCPv6 identifier; DHCPv6 uses DUIDs and different message types (SOLICIT, ADVERTISE, REQUEST, REPLY). Option D is wrong because the server assigned 10.0.0.2 to the client, which would not happen if that address were in an excluded pool; an excluded address would cause the server to either not offer it or send a DHCPNAK.

114
MCQeasy

A network engineer is using the Cisco SD-WAN vManage REST API to retrieve a list of all devices. The engineer sends a GET request to /dataservice/device but receives a 403 Forbidden error. The engineer has already authenticated successfully and obtained a valid session cookie. What is the most likely reason for this error?

A.The session cookie has expired and needs to be renewed.
B.The request must include an X-XSRF-TOKEN header to prevent CSRF attacks.
C.The user account does not have the necessary permissions to access the device inventory.
D.The API endpoint /dataservice/device requires a POST request instead of GET.
AnswerC

A 403 Forbidden error indicates that the server understood the request but refuses to authorize it. Even with a valid session, the user's role must include permission to access the /dataservice/device endpoint. The engineer should check the user's role and group permissions in vManage to ensure they have read access to device inventory.

Why this answer

A 403 Forbidden error indicates that the authenticated user does not have the required permissions to access the requested resource. In vManage, user roles and group permissions control access to API endpoints. The engineer must ensure the account has read access to device inventory.

Exam trap

The trap here is confusing 403 Forbidden with 401 Unauthorized; the former means authenticated but not authorized, so re-authenticating will not help.

115
MCQmedium

A network engineer runs the following command on Router R1: R1# show aaa sessions Total sessions since last reset: 10 Session Id: 5 Unique Id: 5 User Name: admin IP Address: 192.168.1.100 Idle Time: 0:00:05 Timeout: 0:10:00 Type: SSH Method: local Session Id: 6 Unique Id: 6 User Name: neteng IP Address: 10.0.0.2 Idle Time: 0:02:30 Timeout: 0:10:00 Type: SSH Method: tacacs+ Based on this output, what can be concluded?

A.Both sessions are authenticated using TACACS+.
B.Session 5 is authenticated locally.
C.Session 6 will be disconnected due to idle timeout.
D.Both sessions are using RADIUS for authentication.
AnswerB

The Method field for session 5 reads 'local', which confirms the user was authenticated using the device's local user database, typically configured with 'username' global commands or in the local AAA configuration. Local authentication is commonly used as a fallback method or for console access, and it does not involve any external AAA server. The device compared the supplied credentials directly against its stored username and password hashes, and on success, established the session.

Why this answer

The output shows that Session 5 has 'Method: local', which means the user 'admin' was authenticated using the local database on the router, not an external AAA server. Session 6 uses 'Method: tacacs+', confirming TACACS+ authentication for that session. Therefore, only Session 5 is authenticated locally, making option B correct.

Exam trap

Cisco often tests the distinction between authentication methods shown in the 'Method' field of 'show aaa sessions', where candidates may incorrectly assume all sessions use the same method or misinterpret idle timeout as an immediate disconnection trigger.

How to eliminate wrong answers

Option A is wrong because Session 5 uses 'local' authentication, not TACACS+. Option C is wrong because the 'Idle Time' of 0:02:30 is less than the 'Timeout' of 0:10:00, so Session 6 is not yet disconnected due to idle timeout; the timeout value is the maximum idle time before disconnection, not a guarantee of immediate disconnection. Option D is wrong because neither session uses RADIUS; Session 5 uses 'local' and Session 6 uses 'tacacs+'.

116
Multi-Selecthard

Which three statements about IP SLA probe types and their characteristics are true? (Choose three.)

Select 3 answers
A.The UDP jitter operation measures one-way delay, jitter, and packet loss in both directions.
B.The ICMP echo operation measures round-trip time and can also provide jitter calculations.
C.The TCP connect operation measures the time to establish a TCP three-way handshake.
D.The HTTP operation measures the time to resolve the DNS name of the target web server.
E.The ICMP echo operation requires the IP SLA responder to be enabled on the target device.
AnswersA, B, C

UDP jitter probes send timestamped packets at scheduled intervals, letting the responder compute per-direction delay, jitter and loss, satisfying the stem's requirement for bidirectional measurement. Unlike ICMP echo, which reports only round-trip statistics, this operation distinguishes each direction's performance.

Why this answer

Option A is correct because the UDP jitter operation sends a stream of UDP packets and, with an IP SLA responder on the far end, reports one-way delay (both directions), positive and negative jitter (inter-packet delay variation), and packet loss in each direction. Option B is correct because the ICMP echo operation measures round-trip time by sending ICMP Echo Requests, and the resulting per-probe RTT samples can be used to derive jitter statistics. Option C is correct because the TCP connect operation times how long it takes to complete the TCP three-way handshake (SYN, SYN-ACK, ACK) with a target host and port, which is useful for verifying application reachability.

Option D is not correct because DNS resolution timing is provided by the DNS operation, not the HTTP operation, which measures transaction time such as connect, request, and response. Option E is not correct because ICMP echo works without an IP SLA responder on the target; the responder is required for operations like UDP jitter that need timestamping and packet generation support.

Exam trap

350-401 often tests the specific metrics and responder requirements of IP SLA probe types; candidates may incorrectly assume ICMP echo requires a responder or that HTTP measures DNS resolution.

117
Matchingmedium

Drag and drop each DSCP value on the left to its matching Per-Hop Behavior (PHB) on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

EF

AF11

AF21

AF31

AF41

Why these pairings

DSCP 46 maps to EF (Expedited Forwarding), DSCP 10 maps to AF11 (Assured Forwarding class 1 low drop), DSCP 18 maps to AF21 (Assured Forwarding class 2 low drop), DSCP 26 maps to AF31 (Assured Forwarding class 3 low drop), DSCP 34 maps to AF41 (Assured Forwarding class 4 low drop).

118
MCQhard

A network engineer is deploying a new branch office that connects to the headquarters via a Cisco SD-WAN solution. The branch has two WAN transports: an MPLS circuit and a broadband internet link. The engineer wants to ensure that business-critical traffic uses the MPLS circuit while guest traffic uses the broadband link, and that failover occurs automatically if the MPLS circuit degrades. Which Cisco SD-WAN feature should be configured to meet these requirements?

A.Policy-based routing (PBR) using route maps that match on source subnet.
B.Static routes with administrative distance manipulation on the branch router.
C.Application-aware routing policy with SLA classes and path preference.
D.Per-VPN QoS trust boundaries on the branch edge interfaces.
AnswerC

Application-aware routing policies in Cisco SD-WAN use SLA classes to monitor path characteristics such as latency, jitter, and loss. By associating business-critical traffic with an SLA class that prefers MPLS and configuring a fallback to broadband, the engineer ensures preferred path selection and automatic failover when the MPLS circuit degrades.

Why this answer

Cisco SD-WAN application-aware routing uses SLA classes to continuously monitor path performance and select the best path per application. By mapping business-critical traffic to an SLA class that prefers MPLS and falls back to broadband, and guest traffic to a policy that prefers broadband, the engineer achieves both path separation and automatic failover on degradation.

Exam trap

The trap here is confusing QoS or PBR with application-aware routing, which is the SD-WAN feature that actually monitors SLA and performs dynamic path selection.

119
Drag & Dropmedium

Drag and drop the steps of configuring Control Plane Policing (CoPP) on a Cisco IOS router into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

CoPP protects the control plane by filtering traffic. First, define an access-list to match the traffic of interest (e.g., SSH, BGP). Second, create a class-map to reference the access-list.

Third, create a policy-map that assigns a police action (rate-limit) to the class. Fourth, apply the policy-map to the control plane in the inbound direction. Finally, verify the policy with show commands to ensure correct operation.

120
MCQmedium

Which of the following is true about the STP max age timer?

A.It is the time a port spends in the listening state.
B.It is the interval between BPDU transmissions.
C.It is the maximum time a switch stores BPDU information before discarding it.
D.It is the time a port waits before transitioning from blocking to listening.
AnswerC

Max age is the STP timer that dictates how long a switch will store BPDU information before considering it stale. By default, this is 20 seconds; if no new BPDU arrives from a neighbor within that window, the switch discards the outdated information and may trigger a topology recalculation. This ensures that no switch acts on obsolete root or path information, which could result in loops or suboptimal forwarding paths.

Why this answer

The STP max age timer defines the maximum time a switch will store a received BPDU before discarding it. If a switch does not receive a new BPDU from the root bridge within this interval (default 20 seconds), it assumes the root bridge has failed and initiates a topology change, recalculating the spanning tree.

Exam trap

Cisco often tests the max age timer by confusing it with the forward delay timer or the hello timer, so candidates mistakenly associate it with port state transition durations rather than its actual role in aging out BPDU information.

How to eliminate wrong answers

Option A is wrong because the time a port spends in the listening state is controlled by the forward delay timer (default 15 seconds), not the max age timer. Option B is wrong because the interval between BPDU transmissions is the hello timer (default 2 seconds), which determines how often the root bridge sends configuration BPDUs. Option D is wrong because the time a port waits before transitioning from blocking to listening is zero (the transition is immediate once the port is elected as a designated or root port); the max age timer influences the transition from blocking to listening only indirectly by causing a topology change when it expires.

121
MCQmedium

A network engineer is writing a Python script to automate the backup of running configurations from a list of 50 Cisco IOS-XE devices. The script uses the netmiko library and a for loop to connect to each device, execute 'show run', and write the output to a file. After running the script, the engineer notices that the script fails on the 15th device with a timeout error, and the remaining devices are not processed. The engineer wants to ensure that if one device fails, the script continues with the next device. What is the best way to modify the script?

A.Increase the global timeout value in the netmiko connection handler.
B.Use the concurrent.futures module to run each connection in a separate thread.
C.Wrap the connection and backup logic inside a try-except block within the for loop.
D.Replace the for loop with a while loop that retries the connection three times before moving on.
AnswerC

Wrapping the connection and backup logic inside a try-except block within the for loop directly addresses the failure point: each device's operations are executed in its own protected scope. When a device raises an exception (e.g., NetMikoTimeoutException or NetMikoAuthenticationException), the except clause catches it, allowing the script to log the error and continue with the next iteration. This pattern, often called 'fail-continue', ensures that a single unreachable or misconfigured device does not abort the backup process for all remaining devices, which is the core requirement of a resilient network automation script.

Why this answer

Wrapping the connection and backup logic inside a try-except block within the for loop catches exceptions (such as netmiko's NetMikoTimeoutException) for each device individually. This allows the loop to continue processing the remaining devices after a failure, rather than aborting the entire script. The try-except pattern is the standard Python approach for handling runtime errors without breaking iterative processes.

Exam trap

Cisco often tests the distinction between handling exceptions (try-except) versus changing configuration (timeout) or parallelism (threading), and the trap here is that candidates may think increasing timeouts or using threads alone will solve the failure propagation issue without understanding that exception handling is required to continue execution after an error.

How to eliminate wrong answers

Option A is wrong because increasing the global timeout does not prevent the script from stopping on failure; it only delays the timeout error and does not handle the exception, so the script will still abort on the 15th device. Option B is wrong because concurrent.futures introduces parallelism, which can improve performance but does not inherently handle exceptions per device; if one thread fails, the main thread may still raise an unhandled exception unless each thread also uses try-except. Option D is wrong because a while loop with retries only retries the same failed device three times; if all retries fail, the script still stops unless an exception handler is added, and it does not guarantee continuation to the next device.

122
Multi-Selectmedium

Which two statements about Network Function Virtualization (NFV) architecture are true? (Choose two.)

Select 2 answers
A.NFV decouples network functions from proprietary hardware appliances.
B.NFV requires specialized ASICs to achieve line-rate performance.
C.Virtual Network Functions (VNFs) run on top of the NFV Infrastructure (NFVI).
D.The VNF Manager is solely responsible for resource orchestration across multiple VIMs.
E.NFV mandates the use of virtual machines and cannot use container-based deployments.
AnswersA, C

NFV's core architectural principle separates network functions such as firewalls and routers from dedicated, vendor-specific appliances, letting them run as software on general-purpose servers. This decoupling directly satisfies the stem's requirement for a true statement about NFV architecture.

Why this answer

Option A is correct because the core premise of NFV is decoupling network functions (such as firewalls, routers, and load balancers) from dedicated proprietary hardware appliances, allowing them to run as software on standard commercial off-the-shelf (COTS) servers. Option C is correct because in the ETSI NFV reference architecture, Virtual Network Functions (VNFs) execute on top of the NFV Infrastructure (NFVI), which provides the compute, storage, and network resources (often via a hypervisor) that the VNFs consume. Option B is incorrect because NFV explicitly aims to avoid dependence on specialized hardware such as ASICs, relying instead on general-purpose hardware, though acceleration technologies may optionally be used.

Option D is incorrect because resource orchestration across multiple VIMs is the responsibility of the NFV Orchestrator (NFVO), while the VNF Manager handles the lifecycle management of VNF instances. Option E is incorrect because NFV does not mandate virtual machines; container-based and other cloud-native deployments are valid forms of VNF implementation.

123
Matchingmedium

Drag and drop each ACL action on the left to its matching result on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Packet is allowed to pass through the ACL

Packet is discarded and not forwarded

Adds a descriptive comment to the ACL entry

Generates a syslog message when a packet matches the entry

Assigns a numeric identifier to the ACL line for insertion/deletion

Why these pairings

Permit allows the packet; Deny discards the packet; Remark adds a comment; Log generates a log message for matched packets; Sequence-number assigns a line number for editing.

124
MCQmedium

Which BGP attribute is used as the first tie-breaker when multiple paths are available and the weight is equal?

A.Local preference
B.AS path length
C.Origin code
D.MED
AnswerA

Local preference is the second attribute in Cisco's BGP best-path selection process, immediately after the locally significant weight. Because it is a well-known discretionary attribute, it is advertised among iBGP peers within an AS, allowing a network operator to influence outbound traffic across all routers. A higher local preference means the path is more preferred, so it overrides even a longer AS path.

Why this answer

When multiple BGP paths are available for the same prefix, the first tie-breaker after comparing weight (where higher weight is preferred) is Local Preference (Local Pref). Since weight is a Cisco-proprietary attribute that is only locally significant, the next step in the BGP best-path selection algorithm is to compare the Local Preference value, with the highest value being preferred. This makes Local Preference the correct first tie-breaker when weight is equal.

Exam trap

Cisco often tests the order of BGP path selection steps, and the trap here is that candidates confuse the Cisco-proprietary 'weight' attribute (which is checked first) with the standard 'Local Preference' attribute (which is checked second), leading them to incorrectly select AS path length or MED as the next tie-breaker.

How to eliminate wrong answers

Option B is wrong because AS path length is the third tie-breaker in the BGP best-path selection process, used only after comparing weight and Local Preference. Option C is wrong because Origin code (IGP, EGP, incomplete) is the fourth tie-breaker, evaluated after AS path length. Option D is wrong because MED (Multi-Exit Discriminator) is the fifth tie-breaker, used only after comparing Origin code, and it is compared only when paths come from the same neighboring AS.

125
Matchingeasy

Drag and drop each Ansible task return value on the left to its matching meaning on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

The task made a change to the target system

The task completed successfully without making changes

The task encountered an error and did not complete

The task was not executed due to a condition (e.g., when clause)

The target host could not be reached via the connection method

Why these pairings

changed indicates a modification was made, ok means no change but success, failed means error, skipped means condition not met, and unreachable means host could not be contacted.

126
MCQmedium

What is the purpose of the 'encapsulation replicate' keyword in a SPAN destination configuration?

A.It preserves the original VLAN tag of mirrored frames.
B.It duplicates the mirrored traffic to multiple destination ports.
C.It enables RSPAN functionality.
D.It allows the destination port to send traffic as well.
AnswerA

The 'encapsulation replicate' keyword tells the SPAN destination port to preserve the original 802.1Q VLAN tag on every mirrored frame sent to the monitoring device. Without this keyword, the switch strips the VLAN tag and delivers untagged frames, which can obscure which VLAN a packet originally traversed. Using this feature ensures the monitor can see VLAN membership, which is critical for troubleshooting per-VLAN issues.

Why this answer

The 'encapsulation replicate' keyword in a SPAN destination configuration ensures that the mirrored frames retain their original 802.1Q VLAN tag when they are sent out the SPAN destination port. Without this keyword, the switch strips the VLAN tag from the mirrored frames, which can cause issues if the monitoring device relies on VLAN information for analysis. This keyword is specifically used to preserve the original VLAN ID for accurate traffic inspection.

Exam trap

The trap here is that candidates often confuse 'encapsulation replicate' with duplicating traffic to multiple ports (Option B) or enabling RSPAN (Option C), when in fact it is a simple VLAN tag preservation mechanism that is easily overlooked in favor of more complex concepts.

How to eliminate wrong answers

Option B is wrong because 'encapsulation replicate' does not duplicate traffic to multiple destination ports; that function is achieved by configuring multiple SPAN sessions or using a local SPAN with multiple destination ports in a single session, but the keyword itself only controls VLAN tag preservation. Option C is wrong because RSPAN functionality is enabled by configuring a remote VLAN (RSPAN VLAN) and using the 'remote-span' command on the VLAN, not by the 'encapsulation replicate' keyword, which is a local SPAN feature. Option D is wrong because the SPAN destination port is dedicated to receiving mirrored traffic and cannot send its own traffic; the 'encapsulation replicate' keyword does not alter this behavior, and any attempt to send traffic from the destination port would cause a loop or configuration error.

127
MCQeasy

A network administrator is new to automation and wants to start using Ansible to manage a group of Cisco IOS XE switches. The administrator has installed Ansible on a Linux control node and created an inventory file listing the switches. The administrator now needs to create a playbook that will gather facts from the switches and display them. Which Ansible module should the administrator use in the playbook to collect operational facts from the Cisco IOS XE devices?

A.ios_facts
B.ios_config
C.ios_command
D.setup
AnswerA

The ios_facts module is specifically designed to collect facts from Cisco IOS devices, including IOS XE. It gathers information such as hostname, version, interfaces, and hardware details. Using this module, the administrator can retrieve operational data and display it using the debug or other output mechanisms. It is the correct choice for fact gathering on Cisco IOS XE platforms.

Why this answer

Ansible provides platform-specific modules for network devices. For Cisco IOS XE, the ios_facts module is designed to collect a wide range of operational facts, such as version, interfaces, and hardware. It returns structured data that can be used in playbooks.

This module is the standard way to gather facts from IOS XE devices without manual parsing.

Exam trap

The trap here is assuming that the generic setup module works for network devices, but it only works for Linux/Unix hosts; network devices require vendor-specific fact modules.

128
MCQmedium

Consider the following Python script using the requests library to interact with a Cisco IOS-XE device via RESTCONF: ```python import requests from requests.auth import HTTPBasicAuth url = 'https://192.168.1.1/restconf/data/Cisco-IOS-XE-native:native/interface/GigabitEthernet=1/0/1' headers = { 'Accept': 'application/yang-data+json', 'Content-Type': 'application/yang-data+json' } auth = HTTPBasicAuth('admin', 'cisco') response = requests.get(url, headers=headers, auth=auth, verify=False) print(response.json()) ``` What is the script attempting to do?

A.It updates the IP address of GigabitEthernet1/0/1.
B.It retrieves the configuration of GigabitEthernet1/0/1 in JSON format.
C.It deletes the interface configuration.
D.It creates a new interface.
AnswerB

A GET request with an Accept header of application/yang-data+json asks the server to return the YANG configuration data for GigabitEthernet1/0/1 serialized as JSON, per RFC 7951. The server resolves the URI to a specific data node in the running datastore and sends a 200 OK response whose body represents that interface's configuration. This is a read-only operation; the configuration itself remains unchanged. Thus, the correct outcome is a JSON-formatted retrieval of the interface configuration.

Why this answer

The script uses an HTTP GET request to the RESTCONF API endpoint for GigabitEthernet1/0/1. The GET method is specifically used to retrieve data, and the 'Accept: application/yang-data+json' header tells the server to return the configuration in JSON format. This matches option B exactly.

Exam trap

Cisco often tests the distinction between HTTP methods in RESTCONF/NETCONF, and the trap here is that candidates may confuse a GET request with a configuration change because they see a URL path that looks like it modifies an interface.

How to eliminate wrong answers

Option A is wrong because a GET request is read-only and cannot update or modify any configuration; updates require PUT or PATCH methods. Option C is wrong because deleting an interface requires a DELETE HTTP method, not GET. Option D is wrong because creating a new interface requires a POST or PUT method, not GET.

129
Multi-Selecthard

Which three statements about Python functions and modules for network automation are true? (Choose three.)

Select 3 answers
A.Using functions helps avoid code duplication and improves script maintainability.
B.The os module is used to parse JSON data from network device responses.
C.The json module is used to convert JSON strings to Python dictionaries.
D.The csv module is used to parse JSON data from network devices.
E.The re module is useful for extracting specific patterns from device show command output.
AnswersA, C, E

Functions encapsulate reusable logic, so repeated configuration or parsing tasks are defined once and called many times, directly satisfying the maintainability constraint in the stem. This reduces duplication across scripts, lowering the risk of inconsistent edits when changes are required.

Why this answer

Option A is correct because defining reusable functions encapsulates logic so the same code can be called from multiple places, eliminating copy-paste duplication and making scripts easier to read, test, and maintain. Option C is correct because the json module provides json.loads() to deserialize a JSON-formatted string into Python dictionaries/lists, which is exactly how automation scripts convert device API responses into usable Python objects. Option E is correct because the re module supplies regular-expression matching (re.search, re.findall, re.match) that is ideal for pulling structured values such as interface names, IP addresses, or uptime out of unstructured 'show' command output.

Option B is not correct because the os module handles operating-system interactions like paths and environment variables, not JSON parsing. Option D is not correct because the csv module reads and writes comma-separated value files, not JSON data returned by network devices.

Exam trap

The trap here is confusing standard-library module names — candidates often assume 'os' or 'csv' handle JSON because they sound generic, when only 'json' does.

130
MCQmedium

A network administrator is configuring a Cisco IOS router to act as a DHCP server for a subnet. The administrator wants to ensure that the router assigns IP addresses to clients and also provides them with the IP address of a TFTP server for configuration files. Which DHCP option should the administrator configure to provide the TFTP server address?

A.Option 67
B.Option 66
C.Option 43
D.Option 150
AnswerB

DHCP option 66 is used to specify the TFTP server name or IP address. In Cisco IOS, this is configured with the 'option 66 ip <ip-address>' command within the DHCP pool. This option is commonly used for IP phones and other devices that need to download configuration files from a TFTP server. Therefore, it is the correct choice to provide the TFTP server address.

Why this answer

DHCP option 66 is the standard option for specifying the TFTP server name or IP address. Configuring this option in the DHCP pool allows clients to learn the TFTP server address, which they can use to download configuration files. This is the correct choice for providing the TFTP server address to DHCP clients.

Exam trap

The trap here is confusing option 66 with option 67 or option 150, which serve different purposes such as specifying the bootfile name or providing a list of TFTP servers for IP phones.

131
MCQhard

A security architect is evaluating MACsec on a Cisco Catalyst switch uplink between two buildings. The requirement is to encrypt all Layer 2 traffic on the link with minimal configuration and use a standards-based key agreement. Which statement correctly describes how MACsec should be deployed on this link?

A.MACsec must be configured with a pre-shared CAK/CKN pair on both switches, and MKA uses this pair to derive session keys.
B.MACsec can be enabled only on routed ports and is incompatible with switch-to-switch trunk links carrying multiple VLANs.
C.MACsec encrypts only the payload of IP packets, leaving the Ethernet header visible for switching.
D.MACsec requires 802.1X EAP-TLS authentication of both switches before any frame encryption can occur.
AnswerA

MACsec uses the MACsec Key Agreement (MKA) protocol, which relies on a Connectivity Association Key (CAK) and its name (CKN). When configured with a static pre-shared CAK/CKN, MKA derives the Secure Association Key (SAK) used to encrypt traffic. This is the standard, low-configuration deployment for a point-to-point uplink and meets the requirement for standards-based key agreement.

Why this answer

MACsec secures point-to-point Ethernet links using MKA to negotiate encryption keys. A static CAK and CKN configured on both ends lets MKA derive the SAK that encrypts each frame, requiring no external authentication server. This is the standard, minimal-configuration approach for a switch uplink, and MACsec encrypts the full Ethernet frame, not just IP payloads.

Exam trap

The trap here is believing MACsec always requires 802.1X, when a static pre-shared CAK/CKN with MKA is a valid and common deployment for switch-to-switch links.

132
MCQeasy

A network administrator is configuring a Cisco switch port that connects to an IP phone and a PC. The phone must tag voice traffic with VLAN 200, and the PC must send untagged traffic on VLAN 100. Which configuration is required on the switch port?

A.switchport mode access; switchport access vlan 100; switchport voice vlan 200
B.switchport mode access; switchport access vlan 200; switchport voice vlan 100
C.switchport mode trunk; switchport trunk encapsulation dot1q; switchport trunk allowed vlan 100,200
D.switchport mode trunk; switchport trunk native vlan 100; switchport trunk allowed vlan 200
AnswerA

This configuration sets the port as an access port for data VLAN 100 and enables voice VLAN 200 for tagged voice traffic from the IP phone. The phone will tag voice frames with VLAN 200, while the PC sends untagged frames that are placed in VLAN 100. This is the standard Cisco IP phone configuration.

Why this answer

The correct configuration uses an access port with a data VLAN and a voice VLAN. The voice VLAN feature allows the switch to instruct the IP phone to tag voice traffic with the specified VLAN, while the PC's untagged traffic is placed in the access VLAN. This provides separation of voice and data traffic and is the typical deployment for Cisco IP phones.

Exam trap

The trap here is selecting a trunk configuration when the voice VLAN feature on an access port is the intended solution for a phone and PC on the same switch port.

133
MCQmedium

A network engineer is using Python with the ncclient library to configure a Cisco IOS XE device via NETCONF. The script connects successfully but receives an RPC error when trying to apply a candidate configuration. The engineer inspects the device capabilities and sees 'urn:ietf:params:netconf:capability:candidate:1.0' is NOT listed. What is the most likely reason for the failure?

A.The device does not support the NETCONF candidate datastore, so candidate configuration operations cannot be used.
B.The device requires a YANG model to be loaded before candidate configuration can be used.
C.The NETCONF session must use SSH version 2, but the device is using SSH version 1.
D.The ncclient library version is incompatible with the IOS XE NETCONF implementation.
AnswerA

The absence of the 'candidate' capability in the NETCONF capabilities list means the device does not support the candidate datastore. NETCONF operations like edit-config with candidate target or commit will fail. The engineer must use the running datastore directly or enable candidate support if available.

Why this answer

The NETCONF capabilities exchange advertises supported features. The candidate datastore capability indicates whether the device supports a candidate configuration that can be edited and committed. Without it, operations targeting the candidate datastore will fail.

The engineer should verify capabilities before attempting candidate-based workflows and use the running datastore instead.

Exam trap

The trap here is assuming that a successful NETCONF connection implies full feature support, when in fact capabilities must be checked to confirm datastore and operation support.

134
Multi-Selectmedium

A network architect is designing a Cisco SD-WAN fabric using vManage, vSmart, and vBond controllers. Which two statements accurately describe the control plane and onboarding behavior in this architecture? (Choose two.)

Select 2 answers
A.The vBond controller must be deployed behind a NAT device and cannot have a public IP address.
B.WAN Edge devices must run OSPF in the overlay to exchange routes with each other.
C.The vBond controller authenticates and orchestrates initial connectivity between WAN Edge devices and the controllers.
D.The vManage controller forwards user data traffic between WAN Edge devices in the data plane.
E.The vSmart controller distributes control-plane policies and routes overlay topology information to WAN Edge devices via OMP.
AnswersC, E

This is correct because vBond is the first point of contact for WAN Edge devices; it validates their identity and provides the information needed to reach vManage and vSmart. It acts as the orchestrator for control connections, enabling secure onboarding without pre-configuring every peer address on each edge device.

Why this answer

In Cisco SD-WAN, vBond handles authentication and orchestration of initial control connections, while vSmart is the control plane that uses OMP to distribute routing and policy information. vManage is management plane only, OSPF is not the overlay routing protocol, and vBond generally needs public reachability for discovery.

Exam trap

The trap here is mixing management-plane and control-plane roles, such as assuming vManage forwards data or that OSPF runs in the overlay instead of OMP.

135
MCQhard

A network engineer is configuring OSPF on a multiaccess segment. The design requires that the DR/BDR election be deterministic, with Router A always becoming the DR and Router B always becoming the BDR. Both routers are Cisco IOS devices. Which configuration on Router A ensures it wins the DR election?

A.Set the OSPF priority to 0 on Router A's interface.
B.Configure a higher Router ID on Router B.
C.Set the OSPF priority to 255 on Router A's interface.
D.Set the OSPF network type to point-to-point on Router A's interface.
AnswerC

OSPF DR/BDR election is based first on interface priority, then on Router ID. The highest priority wins. Priority 255 is the maximum value and ensures Router A has the highest priority on the segment, making it the DR provided no other router has the same priority with a higher Router ID. This is the standard way to force a router to become DR.

Why this answer

To ensure a router becomes DR, its OSPF interface priority must be higher than all other routers on the segment. Priority 255 is the maximum and guarantees victory unless another router also has 255 and a higher Router ID. Setting priority to 0 makes a router ineligible, a higher Router ID on another router would favor that router, and point-to-point network type removes DR/BDR election altogether.

Exam trap

The trap here is thinking that Router ID is the primary factor in DR election, when priority takes precedence.

136
Matchingmedium

Drag and drop each WAN transport type on the left to its matching SD-WAN characteristic on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Provides guaranteed SLA, low jitter, and private connectivity

Cost-effective transport with variable latency and potential packet loss

Cellular transport enabling mobility and rapid deployment with moderate bandwidth

High-bandwidth, low-latency cellular transport with network slicing capabilities

High-latency transport used for remote or maritime connectivity

Why these pairings

MPLS offers predictable performance; broadband Internet provides low-cost but variable quality; LTE offers mobility; 5G adds low latency and high bandwidth.

137
MCQmedium

A network administrator is configuring a Cisco wireless controller for a branch office. The design requires that guest clients be isolated from corporate clients while still using the same physical access points. Which Cisco wireless architecture feature should be used to separate the traffic?

A.Enable Peer-to-Peer Blocking on the guest WLAN.
B.Configure separate WLANs mapped to different VLANs and apply an interface group.
C.Configure the access points in local mode and use FlexConnect local switching for all WLANs.
D.Use a separate WLAN with a guest VLAN and enforce ACLs or a firewall between the guest and corporate subnets.
AnswerD

Creating a dedicated guest WLAN mapped to a separate VLAN, combined with ACLs or firewall rules between the guest and corporate subnets, provides clear Layer 2 and Layer 3 separation. This approach isolates guest traffic while allowing shared physical access points. It directly satisfies the requirement to separate guest and corporate clients, making it the correct design choice.

Why this answer

Guest isolation in a Cisco wireless deployment is achieved by placing guest clients on a dedicated WLAN and VLAN, then enforcing separation at Layer 3 with ACLs or a firewall. Peer-to-Peer Blocking only stops client-to-client traffic within a WLAN, interface groups are for dynamic interface mapping, and FlexConnect local switching addresses traffic forwarding rather than segmentation.

Exam trap

The trap here is treating Peer-to-Peer Blocking or interface groups as security segmentation tools, when they do not isolate traffic between different WLANs or VLANs.

138
Multi-Selectmedium

Which three statements about BGP peering are true? (Choose three.)

Select 3 answers
A.eBGP peers are typically directly connected, but can be multi-hop with the ebgp-multihop command.
B.iBGP peers can be non-directly connected and often use loopback interfaces for reachability.
C.The default TTL for eBGP packets is 255.
D.In iBGP, all routers within the same AS must be fully meshed unless route reflectors or confederations are used.
E.The BGP router ID is used only for OSPF, not for BGP.
AnswersA, B, D

eBGP peers conventionally establish sessions across directly connected interfaces, since TTL defaults to one. The ebgp-multihop command raises that TTL, permitting sessions between non-adjacent routers separated by intermediate hops. This satisfies the stem's requirement that eBGP peering is typically direct but can be extended across multiple hops when needed.

Why this answer

Option A is correct because eBGP peering normally requires directly connected neighbors, but the Cisco IOS command neighbor x.x.x.x ebgp-multihop <ttl> allows an eBGP session to be established across multiple hops. Option B is correct because iBGP peers do not have to be directly connected; they commonly peer using loopback interfaces, relying on an IGP or static routes for reachability. Option D is correct because iBGP has a split-horizon-like rule preventing routes learned from one iBGP peer from being advertised to another, so full mesh peering is required unless route reflectors or confederations are used.

Option C is not correct because the default TTL for eBGP packets is 1, not 255; 255 is the maximum TTL value. Option E is not correct because the BGP router ID is a 32-bit value used by BGP to identify the router, not an OSPF-only concept.

Exam trap

The trap here is confusing the default TTL for eBGP (which is 1) with the maximum TTL (255), and mistakenly thinking the BGP router ID is used by OSPF.

139
MCQeasy

A network administrator is using Cisco SD-WAN to manage a large enterprise network. They want to automate the deployment of a new branch site using a template. Which component of Cisco SD-WAN is responsible for pushing the configuration to the WAN edge devices?

A.vSmart
B.vManage
C.vAnalytics
D.vBond
AnswerB

vManage is the centralized management plane in Cisco SD-WAN. It hosts the templates and orchestrates configuration pushes to WAN edge devices via the vBond and vSmart controllers. When a template is attached to a device, vManage generates the configuration and sends it to the device. This makes vManage the correct component for automating branch deployment.

Why this answer

In Cisco SD-WAN, vManage is the management plane component that centralizes configuration and policy. It stores templates and orchestrates their deployment to WAN edge devices. The other components have different roles: vBond handles orchestration and NAT traversal, vSmart manages control plane policies, and vAnalytics provides reporting.

Only vManage is responsible for pushing configurations.

Exam trap

The trap here is confusing the roles of the SD-WAN controllers, particularly assuming that vSmart or vBond might handle configuration pushes because they are involved in device onboarding.

140
MCQhard

A network engineer is troubleshooting a performance issue on a Cisco Catalyst 9300 switch. The engineer suspects that a specific application is using excessive bandwidth. The switch supports Flexible NetFlow. The engineer wants to monitor only the traffic from that application without affecting the switch's CPU. What is the most efficient way to configure this?

A.Define a flow record that matches the specific application using NBAR or an ACL, and apply a flow monitor with a sampler rate to reduce CPU impact.
B.Enable NetFlow on all interfaces and export all flows to the collector, then filter at the collector.
C.Use SNMP to poll interface counters and calculate the bandwidth used by the application.
D.Configure port mirroring (SPAN) to send all traffic to an external probe for analysis.
AnswerA

This is correct because Flexible NetFlow permits a flow record that matches only the target application via NBAR (e.g., using an application match in a flow record) or an ACL in a flow monitor. Adding a sampler rate—for instance, sampling 1 out of every N packets—reduces the number of packets that must be inspected and cached, lowering CPU utilization and export bandwidth while still providing statistically accurate application-level visibility. This confines resource consumption to the specific traffic of interest rather than processing every flow on the switch.

Why this answer

Flexible NetFlow allows you to define a flow record that matches specific application traffic using NBAR or an ACL, and applying a flow monitor with a sampler rate reduces the number of packets processed, minimizing CPU impact. This approach targets only the desired traffic without the overhead of monitoring all flows, making it the most efficient method for the engineer's goal.

Exam trap

Cisco often tests the misconception that NetFlow must be enabled globally or that all flows must be exported, when in fact Flexible NetFlow allows targeted monitoring with samplers to minimize CPU impact.

How to eliminate wrong answers

Option B is wrong because enabling NetFlow on all interfaces and exporting all flows to the collector would generate unnecessary CPU and bandwidth overhead, as it processes and exports all traffic, not just the specific application. Option C is wrong because SNMP polling of interface counters provides aggregate bandwidth statistics per interface, not per-application granularity, so it cannot isolate the bandwidth used by a specific application. Option D is wrong because port mirroring (SPAN) sends all traffic to an external probe, which consumes switch CPU resources for replication and does not filter traffic at the source, making it less efficient than using Flexible NetFlow with a sampler.

141
MCQhard

An organization is migrating from a traditional three-tier architecture to a leaf-spine fabric using VXLAN EVPN. The design requires that virtual machines can move between racks without IP address changes. Which technology must be enabled at the leaf switches to support this mobility?

A.Overlay Transport Virtualization (OTV).
B.VXLAN with EVPN control plane.
C.VRF-Lite with route redistribution.
D.MPLS L3VPN with BGP.
AnswerB

VXLAN with EVPN is the correct solution because it combines a Layer 2 data-plane overlay (VXLAN over UDP) with a modern BGP-based control plane (EVPN) that advertises MAC and IP reachability per VNI. This enables stretched Layer 2 forwarding across an IP underlay, allowing VMs to retain their IP and MAC addresses while migrating between switches, with EVPN providing MAC learning, ARP suppression, and multi-homing capabilities. It is purpose-built for constructing flexible, scalable network fabrics for internal mobility and is the standard approach for legacy-to-fabric migration scenarios.

Why this answer

VXLAN with EVPN control plane (B) is correct because it provides a Layer 2 overlay network that extends VLANs across the leaf-spine fabric, enabling virtual machine mobility without IP address changes. EVPN uses BGP to distribute MAC and IP address information, allowing the leaf switches to learn and forward traffic to VMs regardless of their physical location, which is essential for seamless VM migration between racks.

Exam trap

Cisco often tests the distinction between Layer 2 extension technologies (VXLAN EVPN) and Layer 3 VPNs (MPLS L3VPN), leading candidates to mistakenly choose MPLS L3VPN because it also uses BGP, but it cannot support Layer 2 mobility without IP changes.

How to eliminate wrong answers

Option A is wrong because Overlay Transport Virtualization (OTV) is a Cisco proprietary technology designed for interconnecting data centers over Layer 3 networks, not for intra-fabric VM mobility within a single leaf-spine architecture. Option C is wrong because VRF-Lite with route redistribution provides Layer 3 segmentation and routing but does not support Layer 2 extension or MAC mobility required for VM migration without IP changes. Option D is wrong because MPLS L3VPN with BGP is a Layer 3 VPN technology that operates at Layer 3 and cannot extend Layer 2 domains, making it unsuitable for preserving IP addresses during VM moves.

142
MCQeasy

A company uses Cisco Catalyst Center (formerly DNA Center) for intent-based networking. After upgrading the Catalyst Center appliance, the engineer notices that some devices are unreachable via the network, but the Catalyst Center GUI shows them as 'Managed'. What is the most likely cause?

A.SNMP community strings are misconfigured
B.Devices were reassigned to different roles
C.Certificate trust between devices and Catalyst Center expired
D.The IP address of the Catalyst Center appliance changed after the upgrade
AnswerD

If the Catalyst Center appliance's IP address is changed after an upgrade, the management network's routing and ARP entries are disrupted. Devices that are configured to send telemetry or accept management commands to/from the old IP address will no longer be reachable, because their ARP caches, DHCP reservations, or static routes still reference the previous address. Additionally, any access control lists on the devices that permit management traffic from the appliance's old IP will silently drop the new source address. This directly explains why all devices become unreachable after the upgrade, even though the appliance itself is up.

Why this answer

When the Catalyst Center appliance is upgraded, its IP address may change if the upgrade process resets network configuration or if the appliance is redeployed with a new IP. Devices are managed via IP-based communication (e.g., SSH, SNMP, NETCONF), and if the Catalyst Center IP changes, devices will still show as 'Managed' in the GUI because the database retains the device state, but the devices themselves cannot be reached because they are trying to communicate with the old IP address. This mismatch causes unreachability despite the managed status.

Exam trap

Cisco often tests the distinction between GUI state (which can be stale) and actual network reachability, leading candidates to focus on protocol misconfigurations (like SNMP or certificates) rather than the underlying IP connectivity change.

How to eliminate wrong answers

Option A is wrong because SNMP community string misconfigurations would cause polling failures and likely show devices as 'Unmanaged' or with errors, not as 'Managed' while being unreachable. Option B is wrong because reassigning devices to different roles is a configuration change that would not inherently cause unreachability; it would affect policy application, not basic connectivity. Option C is wrong because certificate trust expiration would affect secure communication (e.g., for NETCONF or RESTCONF), but Catalyst Center uses IP-based management and would typically show a certificate error or authentication failure, not a simple unreachability while still showing 'Managed'.

143
MCQmedium

Examine the following OSPF configuration on a Cisco IOS-XE router: router ospf 1 router-id 1.1.1.1 network 10.0.0.0 0.255.255.255 area 0 network 192.168.1.0 0.0.0.255 area 1 default-information originate always metric 10 metric-type 1 What is the effect of the 'default-information originate always' command?

A.A default route is advertised into OSPF only if the router has a default route in its routing table.
B.A default route is unconditionally advertised into OSPF with metric 10 and type E1.
C.The router will redistribute static default routes into OSPF.
D.The router will generate a default route only for area 1.
AnswerB

The always keyword removes the dependency on a local default route, so the router advertises 0.0.0.0/0 into OSPF regardless of its own routing table. The metric 10 and metric-type 1 arguments set the advertised cost and mark it as an E1 external route.

Why this answer

The 'default-information originate always' command unconditionally injects a default route (0.0.0.0/0) into OSPF, regardless of whether the router itself has a default route. The metric 10 and metric-type 1 set the cost and external type to E1, meaning the cost is the sum of external and internal costs.

Exam trap

350-401 often tests the 'always' keyword's effect, causing candidates to think it requires a default route in the routing table or that it redistributes static routes.

How to eliminate wrong answers

Option A is wrong because without the 'always' keyword, the router only advertises a default route if it has one in its routing table. Option C is wrong because the command does not redistribute static default routes; it originates a default route into OSPF. Option D is wrong because the command originates the default route into all areas the router is connected to, not just area 1.

144
MCQmedium

An organization is implementing 802.1X for wireless users using Cisco ISE as the RADIUS server. The network engineer configures the wireless LAN controller (WLC) with 802.1X authentication. Users report that they can connect to the SSID but cannot access any network resources. The engineer checks the WLC and sees that users are authenticated and assigned to VLAN 100. The engineer also checks the switchport connecting the WLC and sees it is a trunk. What is the most likely issue?

A.The RADIUS server is not sending the correct VLAN ID in the Access-Accept.
B.The switch trunk port does not have VLAN 100 allowed.
C.The WLC is not configured for 802.1X on the uplink to the switch.
D.The users' devices are not configured for MAB.
AnswerB

This is the correct root cause. The WLC is configured to tag wireless client traffic on VLAN 100 and sends it over the uplink to the switch. The switch trunk port carrying this uplink must have VLAN 100 explicitly allowed in its allowed VLAN list; otherwise, the switch drops the tagged frames, preventing client traffic from reaching the rest of the network. Since the clients get IP addresses from a DHCP server reachable through the trunk (or at least associate successfully), the failure is at the trunk's egress filtering, not at the authentication phase.

Why this answer

The users are authenticated and assigned to VLAN 100 by the RADIUS server, but the switch trunk port connecting the WLC does not have VLAN 100 in its allowed list. This means traffic from the WLC for VLAN 100 is dropped at the switch, preventing network access even though authentication succeeded. The trunk must explicitly permit VLAN 100 for the dynamic VLAN assignment to work.

Exam trap

Cisco often tests the misconception that authentication success alone guarantees network access, when in fact the trunk's allowed VLAN list or the VLAN's existence on the switch can block traffic even after a successful RADIUS Access-Accept.

How to eliminate wrong answers

Option A is wrong because the RADIUS server is correctly sending VLAN 100 in the Access-Accept, as evidenced by the WLC showing users assigned to that VLAN. Option C is wrong because 802.1X on the WLC uplink to the switch is not required; the WLC uses a static trunk or access port, and 802.1X is only applied to the wireless client association, not the wired uplink. Option D is wrong because MAB (MAC Authentication Bypass) is a fallback method for devices that do not support 802.1X supplicants, and the users are already successfully authenticating via 802.1X, so MAB is irrelevant.

145
MCQeasy

Which component in Cisco SD-WAN is responsible for orchestrating the overlay network, including authentication and NAT traversal?

A.vBond orchestrator
B.vSmart controller
C.vManage NMS
D.vEdge router
AnswerA

vBond orchestrator is the correct answer because it provides the initial orchestration, authentication, and NAT traversal that allow vEdge and vSmart routers to discover and securely connect to vManage. It acts as the security trust anchor in Cisco SD-WAN, distributing certificates and ensuring all devices are authenticated before they join the overlay fabric. Without vBond, no device can bootstrap into the SD-WAN network.

Why this answer

The vBond orchestrator is responsible for the initial authentication of all SD-WAN components (vSmart, vManage, vEdge/cEdge) into the overlay network. It also performs NAT traversal by discovering and distributing the public IP addresses and port numbers of vEdge routers behind NAT, enabling secure DTLS/TLS connections between them. Without vBond, new devices cannot securely join the fabric or establish control-plane connectivity.

Exam trap

Cisco often tests the misconception that vSmart handles all control-plane functions including authentication, but the trap here is that vSmart only manages OMP routes and policies, while vBond is the dedicated orchestrator for initial trust and NAT traversal.

How to eliminate wrong answers

Option B (vSmart controller) is wrong because the vSmart controller is responsible for distributing control-plane policies (e.g., routing, data policies) and managing the OMP (Overlay Management Protocol) sessions, not for initial authentication or NAT traversal. Option C (vManage NMS) is wrong because vManage is the network management system that provides a GUI for configuration, monitoring, and analytics, but it does not handle device authentication or NAT discovery. Option D (vEdge router) is wrong because vEdge routers are the data-plane devices that forward traffic and terminate tunnels; they do not orchestrate the overlay or authenticate other components.

146
Matchingmedium

Drag and drop each DTP mode on the left to its matching trunking behavior on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Actively sends DTP frames; forms trunk if neighbor is trunk, desirable, or auto

Passively waits for DTP frames; forms trunk only if neighbor is trunk or desirable

Forces the interface to be a trunk regardless of DTP negotiation

Forces the interface to be an access port; never forms a trunk

Disables DTP; requires manual trunk configuration

Why these pairings

Dynamic desirable actively sends DTP frames and forms a trunk if the neighbor is trunk, dynamic desirable, or dynamic auto. Dynamic auto forms a trunk only if the neighbor is trunk or dynamic desirable. Trunk always forms a trunk.

Access never forms a trunk. None disables DTP.

147
Multi-Selecthard

Which three statements about BGP route selection are true? (Choose three.)

Select 3 answers
A.A route with a lower MED is preferred over a route with a higher MED when all other factors are equal.
B.A route with a higher LOCAL_PREF is preferred over a route with a lower LOCAL_PREF.
C.A route with a shorter AS_PATH is preferred over a route with a longer AS_PATH.
D.A route with a lower weight is preferred over a route with a higher weight.
E.A route with ORIGIN code EGP is preferred over a route with ORIGIN code IGP.
AnswersA, B, C

MED, the optional non-transitive metric, is compared between routes from the same neighbouring AS; the lower value wins when earlier attributes such as weight, LOCAL_PREF and AS_PATH length tie. This matches the stem's condition that all other factors are equal.

Why this answer

Option A is correct because in the BGP best-path algorithm, when all preceding attributes are equal, the route with the lower Multi-Exit Discriminator (MED) value is preferred over one with a higher MED. Option B is correct because a higher LOCAL_PREF (local preference) is always preferred over a lower LOCAL_PREF, and this attribute is evaluated early in the BGP decision process, before AS_PATH. Option C is correct because a shorter AS_PATH is preferred over a longer AS_PATH when comparing routes, as this attribute is checked after LOCAL_PREF and before ORIGIN.

Option D is incorrect because Cisco weight prefers a higher weight, not a lower one. Option E is incorrect because the ORIGIN code preference order is IGP (i) over EGP (e) over INCOMPLETE (?), so EGP is not preferred over IGP.

Exam trap

The trap here is that candidates often confuse weight and LOCAL_PREF preference direction, or forget that ORIGIN preference is IGP > EGP > INCOMPLETE, leading them to select D or E incorrectly.

148
MCQmedium

Examine this OSPF configuration on router R4: interface GigabitEthernet0/0 ip address 172.16.1.4 255.255.255.0 ip ospf 1 area 0 ip ospf cost 50 ! router ospf 1 router-id 4.4.4.4 network 172.16.0.0 0.0.255.255 area 0 What is the OSPF cost of the GigabitEthernet0/0 interface?

A.50
B.1 (default for GigabitEthernet)
C.100 (derived from reference bandwidth 100 Mbps / 1 Gbps)
D.10 (derived from reference bandwidth 1000 Mbps / 100 Mbps)
AnswerA

The OSPF cost on this interface is explicitly configured to 50 using the 'ip ospf cost' command. This manual assignment takes absolute precedence over any automatically derived cost, so the router uses exactly 50 when computing the SPF metric for routes learned via this interface. Because the configured value is 50, it is the correct answer.

Why this answer

The OSPF cost of an interface is determined by the `ip ospf cost` command, which explicitly overrides the default cost calculation based on reference bandwidth. Since R4's GigabitEthernet0/0 interface has `ip ospf cost 50` configured under it, the cost is set to 50 regardless of the interface bandwidth or reference bandwidth settings.

Exam trap

Cisco often tests the precedence of the `ip ospf cost` command over the default cost calculation, trapping candidates who assume the default cost for GigabitEthernet (1) or who incorrectly calculate the cost using the reference bandwidth formula without considering the explicit configuration.

How to eliminate wrong answers

Option B is wrong because the default OSPF cost for a GigabitEthernet interface is not 1; the default cost is calculated as reference bandwidth (default 100 Mbps) divided by interface bandwidth (1000 Mbps), which equals 1 only if the reference bandwidth is set to 1000 Mbps. Option C is wrong because the cost derived from the default reference bandwidth (100 Mbps) divided by 1 Gbps would be 0.1, which is not a valid OSPF cost (costs are integers, and Cisco rounds up to 1). Option D is wrong because the calculation of 1000 Mbps / 100 Mbps equals 10, but this would only apply if the reference bandwidth were changed to 1000 Mbps and the interface bandwidth were 100 Mbps, which does not match the GigabitEthernet interface's actual bandwidth of 1 Gbps.

149
MCQmedium

A network engineer applies the above CoPP policy on a router. The router has BGP peers, SSH management, and SNMP monitoring. After applying this policy, which traffic will be affected?

A.BGP sessions may flap due to dropped keepalives.
B.Data plane traffic will be dropped.
C.Only SSH sessions will be rate-limited.
D.SNMP and SSH will be unaffected because they are explicitly permitted.
AnswerA

BGP keepalives are sent periodically (typically every 60 seconds) and matched by the CoPP BGP class because they are control-plane TCP traffic to/from port 179. If the policer's committed rate is exceeded—even briefly—the excess keepalives are dropped. After a few missed keepalives, the BGP hold timer (default 180 seconds) expires, causing the peer session to flap. The same policer can also drop BGP route updates, which may cause instability beyond just keepalives.

Why this answer

The CoPP policy applies to control plane traffic, not data plane traffic. BGP keepalives are control plane packets; if the policy drops or rate-limits them, BGP sessions may time out and flap. The correct answer is A because BGP keepalives are essential for maintaining neighbor adjacency, and dropping them directly causes session instability.

Exam trap

Cisco often tests the misconception that CoPP affects data plane traffic or that only management protocols like SSH are impacted, when in fact control plane policing targets all control plane packets, including routing protocol keepalives.

How to eliminate wrong answers

Option B is wrong because CoPP operates on the control plane, not the data plane; data plane traffic is forwarded in hardware and unaffected by control plane policing. Option C is wrong because the policy affects all control plane traffic matching the class maps, not just SSH; BGP and SNMP are also subject to rate-limiting or dropping. Option D is wrong because SNMP and SSH are not 'unaffected' — they are explicitly permitted only if they match a permit ACE in the class map; if the class map drops or rate-limits them, they will be affected.

150
MCQmedium

Consider the following configuration: class-map match-all HTTP match protocol http policy-map QOS class HTTP police 2000000 1500 3000 conform-action transmit exceed-action drop interface GigabitEthernet0/1 service-policy input QOS What is the effect of this configuration?

A.HTTP traffic is policed to an average rate of 2 Mbps; packets that exceed the rate are dropped, while conforming packets are transmitted.
B.HTTP traffic is shaped to an average rate of 2 Mbps; excess packets are buffered.
C.The police command will mark HTTP packets with a DSCP value of 0 if they exceed the rate.
D.The configuration is invalid because 'police' cannot be used in a 'service-policy input' direction.
AnswerA

Policing enforces a 2 Mbps average rate using a token bucket; every arriving HTTP packet is evaluated against that bucket. Packets that find enough tokens are transmitted unchanged because of the conform-action transmit clause, while packets that exceed the bucket depth trigger the exceed-action drop and are discarded immediately. Policing does not buffer, so excess traffic is dropped rather than delayed.

Why this answer

The 'police' command in the policy-map enforces a traffic policer on HTTP traffic matched by the class-map. The parameters '2000000' (2 Mbps) define the committed information rate (CIR), '1500' is the normal burst (Bc), and '3000' is the excess burst (Be). Conforming packets are transmitted, while packets exceeding the rate are dropped, which is the standard behavior of a policer in the input direction.

Exam trap

Cisco often tests the distinction between policing and shaping, and the trap here is that candidates confuse 'police' with 'shape' or assume that 'police' cannot be applied in the input direction, when in fact policing is commonly used on input interfaces.

How to eliminate wrong answers

Option B is wrong because 'police' implements policing, not shaping; policing drops excess traffic, while shaping buffers it. Option C is wrong because the 'police' command does not mark packets with DSCP 0 by default; marking requires an additional 'set' action or a 'conform-action' or 'exceed-action' that explicitly sets a DSCP value. Option D is wrong because 'police' is fully valid in the 'service-policy input' direction; policing is commonly applied on input to rate-limit incoming traffic.

Page 1

Page 2 of 26

Page 3