Courseiva

ENCOR 350-401 (350-401) — Questions 1426–1500

1923 questions total · 26pages · All types, answers revealed

Page 19

Page 20 of 26

Page 21
1426
MCQmedium

A network architect is deploying a Cisco SD-WAN fabric with a single data center and 40 branch sites. The design requires that all branch sites use a single IPsec tunnel to reach the data center VPN concentrator, and that traffic between branches must transit the data center rather than form direct site-to-site tunnels. Which Cisco SD-WAN topology should the architect select?

A.Hub-and-spoke
B.Point-to-point
C.Full mesh
D.Partial mesh
AnswerA

With a hub-and-spoke topology, each branch (spoke) establishes tunnels only to the data center (hub), and inter-branch traffic is hairpinned through the hub. This matches the requirement that all branches use a single IPsec tunnel to the VPN concentrator and that branch-to-branch traffic transits the data center.

Why this answer

The requirement that every branch hold one tunnel to the data center and that branch-to-branch traffic be hairpinned through the hub is the defining characteristic of a hub-and-spoke SD-WAN topology. Full and partial mesh topologies deliberately create direct spoke-to-spoke tunnels, which would bypass the VPN concentrator and contradict the stated design.

Exam trap

The trap here is assuming that more direct tunnels always improve performance, when the design explicitly requires all inter-branch traffic to transit the data center.

1427
Drag & Dropmedium

Drag and drop the steps of ERSPAN (Encapsulated RSPAN) session configuration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

ERSPAN configuration requires first defining the source and destination, then enabling the session. The order ensures the session references exist before activation.

1428
MCQmedium

A network engineer is troubleshooting a security issue and needs to capture all traffic between two servers connected to different switches. The switches are connected via a trunk link. The monitoring station is connected to a third switch. The engineer decides to use RSPAN. Which of the following is a mandatory requirement for RSPAN to function correctly?

A.The RSPAN VLAN must be configured as the native VLAN on all trunk ports.
B.The RSPAN VLAN must be pruned from all trunk ports to prevent loops.
C.The RSPAN VLAN must be configured with the 'remote-span' command on all switches.
D.The RSPAN VLAN must be the same as the management VLAN for the switches.
AnswerC

The 'remote-span' command, issued in config-vlan mode, is the definitive way to designate a VLAN as an RSPAN VLAN on each switch that participates in the RSPAN domain. This command tells the switch not to use the VLAN for normal user traffic or routing, and it enables the switch to treat that VLAN as a transport for mirrored packets. Without this configuration on all switches in the path, the switches could erroneously flood or drop the RSPAN traffic, or attempt to use the VLAN for normal switching; the command guarantees consistent RSPAN behavior across intermediate and endpoint switches.

Why this answer

RSPAN (Remote SPAN) requires the RSPAN VLAN to be configured with the 'remote-span' command on all switches that participate in the RSPAN session. This command marks the VLAN as a dedicated RSPAN VLAN, preventing it from being used for normal data traffic and ensuring that the mirrored frames are flooded correctly across the trunk links to the destination switch. Without this command, the VLAN behaves as a regular data VLAN, which can cause forwarding loops or incorrect delivery of mirrored traffic.

Exam trap

Cisco often tests the misconception that the RSPAN VLAN must be pruned or set as native, when in fact the critical requirement is the 'remote-span' command on all switches to isolate the VLAN for mirroring purposes.

How to eliminate wrong answers

Option A is wrong because the RSPAN VLAN must not be configured as the native VLAN on trunk ports; doing so would cause the RSPAN frames to be sent untagged, which can interfere with normal traffic and break the RSPAN session. Option B is wrong because the RSPAN VLAN must not be pruned from trunk ports; pruning would prevent the mirrored traffic from traversing the trunk links, defeating the purpose of RSPAN. Option D is wrong because the RSPAN VLAN has no requirement to match the management VLAN; it is a dedicated VLAN used solely for transporting mirrored traffic and is independent of management VLANs.

1429
MCQhard

A network engineer is configuring a Cisco router to use TACACS+ for authentication and authorization of EXEC sessions. The engineer configures 'aaa new-model', 'aaa authentication login default group tacacs+ local', and 'aaa authorization exec default group tacacs+ local'. When a user tries to log in via SSH, the router prompts for username and password, but after entering correct credentials, the user is immediately disconnected. The TACACS+ server logs show that the authentication was successful. What is the most likely cause?

A.The TACACS+ server is not configured to authorize the user for EXEC access, so it sends a 'deny' response, causing the router to disconnect the user.
B.The 'aaa authorization exec' command should be 'aaa authorization commands 15' to allow the user to execute commands after login.
C.The router's SSH configuration is missing the 'ip ssh authentication-retries' command.
D.The 'local' fallback in the authorization command is overriding the TACACS+ response.
AnswerA

TACACS+ authorization for EXEC access is a distinct AAA phase that occurs after authentication. When the router is configured with `aaa authorization exec tacacs+`, it sends an authorization request for the EXEC service to the TACACS+ server. If the server returns a deny for service=exec, the router terminates the session immediately, even if the user's credentials were valid. This is a classic cause of 'auth succeeded, then disconnected' behavior.

Why this answer

The TACACS+ authentication succeeded, but the user was disconnected immediately after login. This indicates that the authorization step failed. With 'aaa authorization exec default group tacacs+ local', the router sends an authorization request to the TACACS+ server for EXEC shell access.

If the server responds with a 'deny' (or does not include the necessary service=shell attribute), the router denies the session and disconnects the user, even though authentication passed.

Exam trap

Cisco often tests the distinction between authentication (verifying identity) and authorization (granting access/permissions), leading candidates to overlook that a successful authentication does not guarantee a successful authorization, especially when the TACACS+ server is not configured to authorize EXEC sessions.

How to eliminate wrong answers

Option B is wrong because 'aaa authorization commands 15' is used to authorize individual privileged EXEC commands, not to grant initial EXEC shell access; the user must first be authorized for an EXEC session before any commands can be run. Option C is wrong because 'ip ssh authentication-retries' controls how many times a user can retry SSH authentication before being disconnected, but the user already authenticated successfully, so this setting is irrelevant to the post-authentication disconnect. Option D is wrong because the 'local' fallback in the authorization command only applies if the TACACS+ server does not respond (timeout or unreachable); it does not override a specific 'deny' response from the server.

1430
MCQmedium

A network architect is designing a campus network for a large university with 10,000+ users. The design must provide high availability, minimize failure domains, and allow for easy scaling of the access layer. The core layer should be resilient and support fast convergence. Which hierarchical design model best meets these requirements?

A.Three-tier hierarchical design with access, distribution, and core layers, using redundant links and VRRP for gateway redundancy
B.Collapsed core design with core and distribution combined into one layer
C.Flat Layer 2 design with all switches in a single VLAN
D.Leaf-spine design with all switches acting as leafs and spines
AnswerA

A three-tier model with redundant links and VRRP confines failures to individual access or distribution segments, shrinking failure domains while the core provides resilient fast-converging paths. This directly satisfies the university's high-availability, scalability and minimal-failure-domain constraints for 10,000+ users.

Why this answer

The three-tier hierarchical design (access, distribution, core) is the correct choice because it provides clear separation of failure domains, allows easy scaling by adding access switches, and supports high availability through redundant links and VRRP (or HSRP/GLBP) for first-hop gateway redundancy. The core layer can be designed with fast-converging protocols like ECMP and BFD to meet the resilience and convergence requirements for a large campus with 10,000+ users.

Exam trap

Cisco often tests the misconception that a collapsed core design is always more efficient for small-to-medium networks, but for a large campus with 10,000+ users, the three-tier model is required to minimize failure domains and allow independent scaling of the access layer.

How to eliminate wrong answers

Option B is wrong because a collapsed core design combines the core and distribution layers, which reduces the number of devices but creates a larger failure domain and limits scalability at the access layer, making it unsuitable for a large university campus. Option C is wrong because a flat Layer 2 design with all switches in a single VLAN creates a massive broadcast domain, leading to poor convergence, security risks, and no fault isolation, which violates the requirement to minimize failure domains. Option D is wrong because leaf-spine design is optimized for data center east-west traffic patterns and does not align with the north-south traffic flow typical of a campus network; it also does not provide the same level of gateway redundancy and access-layer scaling as a three-tier design.

1431
Matchingmedium

Drag and drop each EIGRP metric component on the left to its matching K variable on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

K1

K2

K3

K4

Why these pairings

In the EIGRP metric formula, the K values correspond to specific metric components: K1 is bandwidth, K2 is load, K3 is delay, K4 is reliability. MTU is not a K variable; the EIGRP metric does not include MTU.

Exam trap

MTU is not a K variable; K5 is not used in the standard EIGRP metric.

1432
Drag & Dropmedium

Drag and drop the steps of TrustSec SGT classification and enforcement into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order for TrustSec SGT classification and enforcement begins with the switch classifying the endpoint and assigning an SGT (A). The ingress switch then tags the packet with that SGT (B). The packet is forwarded with the SGT in the header (C).

On the egress switch, the SGT is looked up in the SGACL (D), and finally the switch permits or denies the traffic based on the SGACL (E).

1433
MCQeasy

A network engineer is configuring an IPsec site-to-site VPN between two Cisco IOS-XE routers. The design requires that the data payload be encrypted and that the two peers authenticate each other using pre-shared keys without any certificate infrastructure. Which combination of IKEv2 parameters must be configured on both peers to establish the tunnel?

A.An IKEv2 profile alone with inline pre-shared-key configuration
B.An IKEv2 proposal, a transform set, and a dynamic crypto map
C.An IKEv2 proposal, an IKEv2 policy, an IKEv2 keyring, and an IKEv2 profile
D.An ISAKMP policy, a crypto keyring with RSA signatures, and a crypto map
AnswerC

In IKEv2 on Cisco IOS-XE, a proposal defines the encryption, integrity, and PRF algorithms, a policy binds proposals to a match criterion, a keyring holds the pre-shared keys, and a profile ties the keyring to the peer and local identities and references the policy. All four components are needed to negotiate the IKEv2 SA using PSK authentication, making this the correct set.

Why this answer

IKEv2 on Cisco IOS-XE separates concerns: proposals define algorithms, policies select proposals based on match criteria, keyrings store pre-shared keys, and profiles bind identities, keyrings, and policies together. All four are required to negotiate the IKEv2 security association using PSK authentication with no PKI. The data-plane IPsec configuration (transform set and profile or map) is separate and layered on top of this control-plane configuration.

Exam trap

The trap here is confusing IKEv1 constructs such as ISAKMP policies and crypto maps with the IKEv2 building blocks, or assuming a profile alone can hold the pre-shared key without a keyring.

1434
MCQmedium

A network engineer runs the following command on Router R8: R8# show ip nhrp 10.0.0.1/32 via 10.0.0.1 Tunnel0 created 00:10:00, expire 01:50:00 Type: dynamic, Flags: unique registered NBMA address: 192.168.1.1 10.0.0.2/32 via 10.0.0.2 Tunnel0 created 00:05:00, expire 01:55:00 Type: dynamic, Flags: unique registered NBMA address: 192.168.1.2 Based on this output, what can be concluded?

A.The router has static NHRP mappings configured.
B.The router is a DMVPN hub with two registered spokes.
C.The NHRP entries are about to expire because the expire time is less than 2 hours.
D.The router is a spoke because it has only two entries.
AnswerB

This router is operating as a DMVPN hub because it has multiple dynamic NHRP entries, each flagged as 'unique' and 'registered'. In DMVPN, spokes initiate NHRP registration to the hub, which then stores their physical (NBMA) addresses in its NHRP cache. Two distinct entries with these flags indicate that two separate spokes have successfully registered, which is the expected behavior for a hub in a hub-and-spoke topology.

Why this answer

The output shows two NHRP entries with 'Type: dynamic' and 'Flags: unique registered', which indicates that these are spokes that have dynamically registered their NBMA addresses with this router. The presence of multiple registered entries and the absence of static NHRP mappings confirm this router is acting as a DMVPN hub, as hubs maintain a registry of all connected spokes.

Exam trap

Cisco often tests the distinction between hub and spoke roles by the number and type of NHRP entries—candidates mistakenly think a router with multiple entries is a spoke, but in reality, a hub has many dynamic entries (spokes registered to it), while a spoke typically has one static or dynamic entry for the hub.

How to eliminate wrong answers

Option A is wrong because the entries show 'Type: dynamic', not 'static', meaning they were learned via NHRP registration, not configured manually. Option C is wrong because the expire times (01:50:00 and 01:55:00) are well above zero and indicate the entries are valid for nearly two more hours, not about to expire. Option D is wrong because a spoke typically has only one NHRP entry (the hub), whereas having two registered entries is characteristic of a hub that receives registrations from multiple spokes.

1435
Matchingmedium

Drag and drop each SGT value range on the left to its matching policy type on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Reserved for system use (e.g., unknown SGT)

User-defined scalable groups

Default SGTs assigned by Cisco DNA Center

Static SGTs configured manually

Dynamic SGTs assigned by ISE

Why these pairings

SGTs 0-1 are reserved, 2-9999 are user-defined, 10000-19999 are default, 20000-29999 are static, and 30000-65535 are dynamic.

1436
Drag & Dropmedium

Drag and drop the steps of EIGRP variance-based unequal-cost load balancing into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

To enable unequal-cost load balancing, first ensure feasible successors exist, then set the variance multiplier, optionally adjust the metric offset, and finally verify the load sharing across multiple paths.

1437
MCQmedium

A network engineer uses the Requests library to send a RESTCONF PATCH request to modify the hostname of a Cisco IOS-XE device: ```python import requests from requests.auth import HTTPBasicAuth url = 'https://192.168.1.1/restconf/data/Cisco-IOS-XE-native:native/hostname' headers = {'Content-Type': 'application/yang-data+json'} auth = HTTPBasicAuth('admin', 'cisco123') payload = { 'Cisco-IOS-XE-native:hostname': 'NewRouter' } response = requests.patch(url, json=payload, headers=headers, auth=auth, verify=False) print(response.status_code) ``` What is the expected HTTP status code if the request is successful?

A.200 OK
B.201 Created
C.204 No Content
D.202 Accepted
AnswerC

204 No Content is the standard success response for a RESTCONF PATCH operation per RFC 8040. It tells the client that the server applied the patch successfully and that the response body is intentionally empty, avoiding unnecessary payload transfer. This makes 204 the correct answer for a successful RESTCONF PATCH.

Why this answer

A successful RESTCONF PATCH request returns HTTP status code 204 No Content because the operation modifies an existing resource without returning a response body. The PATCH method in RESTCONF is used for partial updates to a target resource, and per RFC 8040, a 204 response indicates that the server has successfully applied the modifications and the response has no payload.

Exam trap

Cisco often tests the distinction between HTTP methods and their corresponding success codes, and the trap here is that candidates confuse PATCH with PUT (which returns 200 or 204) or POST (which returns 201), leading them to incorrectly select 200 OK or 201 Created.

How to eliminate wrong answers

Option A is wrong because 200 OK would imply a response body is returned, but RESTCONF PATCH does not return content on success. Option B is wrong because 201 Created is used for POST requests that create a new resource, not for PATCH modifications. Option D is wrong because 202 Accepted is used for asynchronous operations that have not yet completed, whereas RESTCONF PATCH is synchronous and returns 204 on immediate success.

1438
MCQhard

A financial services company has deployed Cisco UCS servers with VMware vSphere 7.0 to host critical trading applications. The network uses Cisco Nexus 9000 switches in a VXLAN EVPN fabric with BGP as the underlay. The environment includes 50 ESXi hosts, each connected via two 40G interfaces to two different leaf switches in a VPC. The VMs are spread across multiple hosts and communicate over VXLAN. Recently, the operations team migrated a set of VMs from an old VLAN-based network to a new VXLAN segment (VNI 50000). After the migration, users report intermittent connectivity issues and packet loss. The engineering team captures traffic and notices that some VMs send ARP requests that are not being replied to, even though the target VM is active. Further analysis shows that the ARP requests are being flooded to all VTEPs, but the replies are not reaching the source. The team checks the underlay and finds no issues with BGP or routing. The NVE interfaces are up, and the VNI is configured. Which of the following is the most likely cause of the issue?

A.The ingress replication list is missing some VTEPs.
B.The symmetric routing configuration is missing on the leaf switches.
C.The VPC configuration between the leaf switches and ESXi hosts is incorrect.
D.The MAC address of the target VM is not being advertised in EVPN type-2 routes because the VM's MAC is learned on a different leaf switch than expected.
AnswerD

In EVPN, each leaf switch advertises locally learned MAC addresses via MP-BGP Type-2 routes. If the target VM's MAC is learned on a leaf different from the one the source leaf expects, or if that leaf has not advertised the route, the source leaf has no EVPN entry for that MAC. It floods the ARP request as BUM, but the reply is sent as unicast, and without a Type-2 route the source cannot properly deliver or cache the reply, leading to unidirectional communication failure.

Why this answer

The issue is that the target VM's MAC address is not being advertised via EVPN Type-2 routes from the leaf switch where it resides. When the source VM sends an ARP request, the ingress VTEP floods it to all VTEPs in the VNI's ingress replication list, but the reply from the target VM must be unicast back. If the target's MAC is not in the EVPN control plane (e.g., because it was learned on a different leaf than expected due to asymmetric MAC learning or stale entries), the reply cannot be forwarded correctly, causing intermittent connectivity.

Exam trap

Cisco often tests the distinction between data-plane flooding (which works) and control-plane advertisement (which fails), leading candidates to incorrectly blame replication lists or VPC issues instead of identifying the missing EVPN Type-2 route.

How to eliminate wrong answers

Option A is wrong because if the ingress replication list were missing some VTEPs, the ARP requests would not reach those VTEPs at all, but the problem states the ARP requests are flooded to all VTEPs, so the list is complete. Option B is wrong because symmetric routing is a design choice for inter-VNI routing (e.g., between different VNIs), not for intra-VNI ARP handling within the same VNI; the issue is about MAC/IP advertisement, not routing asymmetry. Option C is wrong because the VPC configuration between leaf switches and ESXi hosts affects link-level redundancy and loop prevention, but the underlay is healthy and NVE interfaces are up, so VPC misconfiguration would cause connectivity issues unrelated to ARP reply forwarding.

1439
Matchingmedium

Drag and drop each NAT terminology on the left to its matching definition on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

The IP address of the host as seen from inside the network

The translated IP address of the host as seen from outside the network

The IP address of the remote host as seen from inside the network

The IP address of the remote host as seen from outside the network

A range of public IP addresses used for dynamic translation

Why these pairings

Inside local is the private IP of the host; inside global is the public IP after translation; outside local is the private IP of the remote host; outside global is the public IP of the remote host.

1440
MCQhard

A network engineer runs the following command on Router R9: R9# show queueing interface GigabitEthernet0/1 Interface GigabitEthernet0/1 queueing strategy: class-based weighted fair Queueing on output: Class-based Weighted Fair Queueing Queueing on input: FIFO R9# show policy-map interface GigabitEthernet0/1 GigabitEthernet0/1 Service-policy output: QOS_POLICY Class-map: VOICE (match-any) 100 packets, 10000 bytes 5 minute offered rate 10000 bps, drop rate 0 bps Match: ip dscp ef (46) Queueing strict priority queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 100/10000 police cir 1000000 bc 15625 be 15625 conformed 100 packets, 10000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: DATA (match-any) 200 packets, 20000 bytes 5 minute offered rate 20000 bps, drop rate 0 bps Match: ip dscp af31 (26) Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 200/20000 bandwidth remaining percent 50 Class-map: class-default (match-any) 300 packets, 30000 bytes 5 minute offered rate 30000 bps, drop rate 0 bps Match: any Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 300/30000 bandwidth remaining percent 50 Based on this output, what can be concluded?

A.The interface uses WFQ for output queuing.
B.Voice traffic is being dropped because it exceeds the police rate.
C.Data traffic is guaranteed 50% of the remaining bandwidth after priority queuing.
D.The policy-map is applied to input traffic.
AnswerC

The DATA class is configured with 'bandwidth remaining percent 50', meaning it is guaranteed 50% of the bandwidth left after the strict priority queue (LLQ) for VOICE has been served. This is relative to remaining bandwidth, not a fixed absolute percentage of the interface rate, so data can use more than half when voice is silent but is protected to at least half when voice is active. It is a correct statement about the policy's bandwidth allocation.

Why this answer

The 'bandwidth remaining percent 50' command under the DATA class-map allocates 50% of the interface bandwidth that remains after the strict-priority VOICE queue has been serviced. This is the standard behavior for class-based weighted fair queuing (CBWFQ) when a priority queue is present: the priority queue is served first, and then the remaining bandwidth is distributed among the non-priority classes according to their configured percentages.

Exam trap

Cisco often tests the distinction between 'bandwidth percent' (which allocates a percentage of the total interface bandwidth) and 'bandwidth remaining percent' (which allocates a percentage of the bandwidth left after priority queuing), and candidates frequently confuse these two commands.

How to eliminate wrong answers

Option A is wrong because the output shows 'queueing strategy: class-based weighted fair', not legacy WFQ; CBWFQ is a distinct mechanism that allows user-defined classes and bandwidth guarantees, whereas WFQ is a flow-based algorithm without class maps. Option B is wrong because the police statistics show 'conformed 100 packets, 10000 bytes' and 'exceeded 0 packets, 0 bytes', indicating that no voice traffic has exceeded the police rate of 1 Mbps and thus no drops have occurred. Option D is wrong because the 'show policy-map interface' output explicitly states 'Service-policy output: QOS_POLICY', confirming the policy is applied to output traffic, not input.

1441
MCQmedium

Consider the following OSPF configuration on router R2: interface GigabitEthernet0/0 ip address 192.168.1.2 255.255.255.0 ip ospf 1 area 0 ip ospf hello-interval 5 ! router ospf 1 router-id 2.2.2.2 network 192.168.1.0 0.0.0.255 area 0 Which statement is true about this configuration?

A.The OSPF dead interval is automatically set to 20 seconds.
B.The OSPF dead interval remains at the default of 40 seconds.
C.This configuration will cause OSPF to use MD5 authentication.
D.The OSPF network type changes to point-to-point.
AnswerA

When you configure 'ip ospf hello-interval 5' on an interface, Cisco IOS automatically recalculates the OSPF dead interval to four times the hello interval, producing a dead interval of 20 seconds (4 × 5 = 20). This automatic adjustment preserves the default 4-to-1 ratio, ensuring that neighbor hold-down timing remains consistent with the hello interval. To achieve a different dead interval, you would need to explicitly configure 'ip ospf dead-interval'.

Why this answer

The OSPF dead interval is automatically set to four times the hello interval when the hello interval is manually configured. By default, OSPF uses a hello interval of 10 seconds and a dead interval of 40 seconds on broadcast networks. However, when you explicitly set the hello interval to 5 seconds using the 'ip ospf hello-interval 5' command, the router automatically adjusts the dead interval to 20 seconds (4 × 5 seconds) to maintain the standard ratio, unless the dead interval is also manually configured.

Exam trap

Cisco often tests the automatic relationship between the OSPF hello and dead intervals, and the trap here is that candidates assume the dead interval remains at the default value (40 seconds) even after changing the hello interval, rather than understanding it scales proportionally to 4× the new hello interval.

How to eliminate wrong answers

Option B is wrong because the OSPF dead interval does not remain at the default of 40 seconds; it is automatically recalculated to 20 seconds when the hello interval is changed to 5 seconds. Option C is wrong because the configuration shown does not include any authentication commands such as 'ip ospf authentication message-digest' or 'ip ospf message-digest-key', so MD5 authentication is not enabled. Option D is wrong because the network type remains as the default broadcast (multi-access) for GigabitEthernet interfaces; changing the network type to point-to-point requires the explicit command 'ip ospf network point-to-point'.

1442
MCQeasy

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which IPsec configuration component defines this traffic?

A.Transform set
B.Crypto map
C.Access control list (ACL)
D.IKE policy
AnswerC

The ACL in an IPsec configuration defines the interesting traffic that will be encrypted. In this scenario, an ACL permitting IP from 10.1.1.0/24 to 10.2.2.0/24 would ensure only that traffic is encrypted. The crypto map references this ACL to match traffic. Other traffic not matching the ACL is sent unencrypted.

Why this answer

In Cisco IPsec configuration, the ACL (often called the crypto ACL) specifies the traffic that should be protected. The crypto map then references this ACL. Traffic that matches the ACL is encrypted; traffic that does not match is sent in clear text.

Therefore, the ACL is the component that defines the interesting traffic.

Exam trap

The trap here is confusing the role of the crypto map (which binds components) with the ACL (which actually defines the traffic).

1443
MCQhard

A network engineer is configuring a Cisco Nexus 9000 switch in a VXLAN EVPN fabric. The engineer wants to ensure that the switch can advertise MAC addresses learned from local hosts to other VTEPs. Which EVPN route type is used to advertise MAC address reachability information?

A.Type 2 - MAC/IP Advertisement route
B.Type 3 - Inclusive Multicast Ethernet Tag route
C.Type 1 - Ethernet Auto-Discovery route
D.Type 5 - IP Prefix route
AnswerA

Type 2 EVPN routes are used to advertise MAC addresses and optionally IP addresses. When a VTEP learns a MAC address from a local host, it generates a Type 2 route and advertises it to other VTEPs via BGP EVPN. This allows remote VTEPs to learn the MAC-to-VTEP mapping and forward traffic correctly. Type 2 routes are essential for Layer 2 and Layer 3 VXLAN EVPN operation.

Why this answer

In EVPN, MAC address reachability is advertised using Type 2 routes, also known as MAC/IP Advertisement routes. When a VTEP learns a local MAC address, it creates a Type 2 route containing the MAC address, the VNI, and the next-hop VTEP IP. This route is distributed via BGP EVPN to other VTEPs, enabling them to build the MAC-to-VTEP mapping for forwarding.

Exam trap

The trap here is mixing up EVPN route types; Type 2 is for MAC/IP advertisement, while Type 3 is for multicast and Type 5 is for IP prefixes.

1444
Multi-Selectmedium

A company is deploying an MPLS VPN to connect multiple branch sites to a central data center. The network engineer must ensure that customer traffic is isolated from other customers and that routing information is kept separate. Which two statements are correct about MPLS Layer 3 VPNs? (Choose two.)

Select 2 answers
A.Route targets are used to identify the VRF on the PE router that a packet belongs to.
B.Customer edge routers must run MP-BGP with the provider edge routers to exchange VPN routes.
C.VRF instances on PE routers provide logical separation of customer routing tables.
D.The MPLS label stack consists of only a single label for all VPN traffic.
E.MP-BGP is used to distribute customer routes across the MPLS backbone.
AnswersC, E

VRF (Virtual Routing and Forwarding) instances create separate routing and forwarding tables on PE routers. Each customer is assigned its own VRF, so routes from one customer are not leaked into another's table. This logical separation is fundamental to MPLS Layer 3 VPNs and ensures traffic isolation. The VRF also allows overlapping IP address spaces between customers, which is a key benefit of MPLS VPNs.

Why this answer

MPLS Layer 3 VPNs rely on VRF instances on PE routers to separate customer routing tables and MP-BGP to distribute VPNv4 routes across the provider backbone. Route targets control route import/export, but they do not identify the VRF for packet forwarding. The label stack typically has two labels.

CE routers do not run MP-BGP; they run standard routing protocols with the PE. Thus, the correct statements are about VRF separation and MP-BGP route distribution.

Exam trap

The trap here is confusing route targets with the mechanism that identifies the VRF for packet forwarding; route targets control route distribution, not packet classification.

1445
Drag & Dropmedium

Drag and drop the steps of FlexVPN spoke-to-spoke dynamic tunnel creation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In FlexVPN, a spoke sends an IKEv2 authentication request to the hub. The hub authenticates the spoke and sends back the IKEv2 configuration payload with the remote spoke's address. The originating spoke then initiates a direct IKEv2 session to the remote spoke.

Both spokes complete IKEv2 authentication and IPsec SA setup. Finally, traffic flows directly between the spokes without going through the hub.

1446
Multi-Selectmedium

A network architect is designing a data center fabric that uses VXLAN with an EVPN control plane on Cisco Nexus 9000 switches. The architect must justify why EVPN is preferred over a flood-and-learn VXLAN data plane. Which two statements correctly describe advantages of using an EVPN control plane in this design? (Choose two.)

Select 2 answers
A.It distributes MAC address reachability through BGP so VTEPs do not need to flood frames to learn remote host locations
B.It converts VXLAN tunnels into MPLS LSPs to improve forwarding performance between leaf switches
C.It eliminates the need for any underlay routing protocol because BGP carries all traffic between leaf switches
D.It removes the requirement for a loopback interface on each VTEP by using physical interface addresses
E.It supports multihoming of servers to two leaf switches with all-active forwarding using Ethernet Segment identifiers
AnswersA, E

With EVPN, MAC and IP bindings are advertised as BGP route types, so each VTEP learns remote host locations from the control plane rather than from data-plane flooding. This reduces unknown-unicast flooding and speeds convergence. In a flood-and-learn design, every VTEP must flood to discover remote MACs, which wastes bandwidth and creates scaling problems in large fabrics.

Why this answer

An EVPN control plane advertises MAC and IP reachability via BGP, avoiding data-plane flooding for host learning, and it supports standards-based all-active multihoming through Ethernet Segment identifiers and DF election. It does not remove the underlay routing requirement, convert VXLAN to MPLS, or eliminate the VTEP loopback, so those statements are incorrect for this design.

Exam trap

The trap here is conflating the overlay control plane with the underlay transport, leading to the false belief that EVPN removes the need for underlay routing or VTEP loopbacks.

1447
MCQhard

A network engineer is troubleshooting a Cisco Wireless LAN Controller (WLC) deployment where clients cannot associate to an SSID. The SSID is configured with WPA2-Enterprise and uses a RADIUS server for authentication. The engineer verifies that the RADIUS server is reachable and the shared secret is correct. Which additional configuration on the WLC is required for clients to successfully authenticate?

A.Configure the WLC management interface with a static IP address.
B.Set the WLAN to use PSK instead of Enterprise.
C.Configure the WLC as a RADIUS client on the RADIUS server.
D.Enable 802.1X on the WLAN and specify the RADIUS server.
AnswerD

For WPA2-Enterprise, the WLAN must be configured to use 802.1X authentication and point to the correct RADIUS server. If 802.1X is not enabled or the RADIUS server is not specified on the WLAN, clients cannot authenticate. This is a common oversight when configuring enterprise SSIDs on a WLC.

Why this answer

For WPA2-Enterprise authentication, the WLAN on the WLC must be configured to use 802.1X and reference the RADIUS server. Even if the RADIUS server is reachable and the shared secret is correct, the WLAN will not trigger authentication unless 802.1X is enabled and the server is specified in the WLAN's security settings.

Exam trap

The trap here is focusing on RADIUS server-side configuration when the missing piece is often the 802.1X setting on the WLAN itself.

1448
Multi-Selectmedium

Which two statements about Ansible inventory files are true? (Choose two.)

Select 2 answers
A.Ansible can use a dynamic inventory script that queries an external source such as AWS EC2.
B.The default location for the Ansible inventory file is /etc/ansible/hosts.
C.Ansible inventory files can only be written in INI format.
D.Group variables in an inventory must be defined in separate files under the group_vars directory.
E.The inventory file can only contain hostnames, not IP addresses.
AnswersA, B

Dynamic inventory scripts let Ansible query external sources such as AWS EC2 at runtime, so hosts are discovered rather than hard-coded in a static file. This satisfies the requirement to manage cloud instances whose addresses change frequently, keeping the inventory current without manual edits.

Why this answer

Option A is correct because Ansible supports dynamic inventory, where an executable inventory script (or inventory plugin) queries an external source such as AWS EC2 and returns host data in JSON, allowing hosts to be discovered at runtime. Option B is correct because, when no inventory is specified with -i or configured in ansible.cfg, Ansible falls back to the default inventory file located at /etc/ansible/hosts. Option C is false because inventories can be written in INI, YAML, or as dynamic JSON-producing scripts, not INI only.

Option D is false because group variables can be defined directly inside the inventory file (e.g., [group:vars] in INI) as well as in group_vars files. Option E is false because inventory hosts may be specified as hostnames, IP addresses, or FQDNs.

Exam trap

350-401 often tests inventory basics — candidates wrongly believe only INI format is supported or that group variables must live in separate files, missing YAML support and inline variable definitions.

1449
MCQeasy

A network engineer is planning a new branch office network. The branch will have a single Cisco IOS router that connects to the internet via a GigabitEthernet interface. The engineer wants to configure NAT to allow internal hosts to access the internet. Which NAT type should be configured to allow multiple internal hosts to share the single public IP address?

A.Static NAT
B.Dynamic NAT
C.NAT64
D.Port Address Translation (PAT)
AnswerD

PAT, also known as NAT overload, allows multiple internal hosts to share a single public IP address by translating both IP addresses and port numbers. Each internal host's connections are tracked using unique source port numbers, enabling thousands of simultaneous connections through one public IP. This is the correct choice for the scenario.

Why this answer

Port Address Translation (PAT), or NAT overload, is designed to allow many internal hosts to share a single public IP address. It uses unique source port numbers to distinguish between sessions, making it the most efficient use of a single public IP. This is the standard method for branch offices with a single internet connection.

Exam trap

The trap here is confusing dynamic NAT with PAT; dynamic NAT still requires a pool of public addresses and does not allow overloading a single address.

1450
MCQmedium

A network engineer is configuring BGP on a Cisco router that connects to two ISPs. The router has a default route pointing to each ISP. The engineer wants to load balance outbound traffic across both ISPs. The router receives a default route from both ISPs. Which BGP configuration approach will allow the router to install both default routes in the routing table and load balance traffic?

A.Configure the maximum-paths command under the BGP address family and use the bgp bestpath as-path multipath-relax command.
B.Configure the network command to advertise the default route from both ISPs.
C.Set the local preference to the same value on both default routes.
D.Use the redistribute command to redistribute the default routes into BGP.
AnswerA

The BGP best-path algorithm normally installs only one route per prefix into the routing table. Configuring maximum-paths under the BGP address family sets the maximum number of eligible paths that can be installed, while the bgp bestpath as-path multipath-relax command instructs BGP to disregard AS_PATH length differences when selecting these multipath candidates. Together, they enable load balancing across multiple default routes from different ISPs even when the AS_PATH lengths are not identical.

Why this answer

The `maximum-paths` command under the BGP address family enables the router to install multiple paths for the same prefix (in this case, the default route 0.0.0.0/0) into the routing table. The `bgp bestpath as-path multipath-relax` command is necessary because the two default routes from different ISPs will have different AS_PATH lengths; this command relaxes the requirement for equal AS_PATH length, allowing the router to consider them as multipath candidates. Together, they allow both default routes to be installed and used for load balancing outbound traffic.

Exam trap

Cisco often tests the nuance that simply having equal BGP path attributes (like local preference) does not enable multipath installation; candidates must remember that `maximum-paths` and `multipath-relax` are explicitly required to install and load balance multiple BGP routes, even for default routes.

How to eliminate wrong answers

Option B is wrong because the `network` command is used to inject a prefix into BGP from the IP routing table, not to install received routes; the router already receives the default routes from the ISPs, so advertising them again is irrelevant to load balancing. Option C is wrong because setting the same local preference on both default routes only ensures they have equal preference in the BGP best-path selection process, but without `maximum-paths` and `multipath-relax`, the router will still select only one best path and install a single default route. Option D is wrong because `redistribute` is used to import routes from another routing protocol into BGP, not to control how received BGP routes are installed; redistributing the default routes would create a new BGP route, but it does not enable multipath installation of the received routes.

1451
MCQhard

An engineer is configuring RSPAN to monitor traffic from multiple switches in a data center. The monitoring station is connected to a central switch. The engineer has configured an RSPAN VLAN (VLAN 999) on all switches and set up the source sessions on the remote switches. However, the monitoring station receives no traffic. On the central switch, the engineer verifies that the RSPAN VLAN is active and that the destination session is configured. What is a likely missing configuration?

A.The trunk ports between the switches do not have the RSPAN VLAN (999) in their allowed VLAN list.
B.The destination session on the central switch is configured with 'monitor session 2 destination remote vlan 999' instead of 'monitor session 2 destination interface Gi1/0/1'.
C.The source sessions on the remote switches are configured with 'monitor session 1 source vlan 100' but the destination is not set to 'remote vlan 999'.
D.The RSPAN VLAN is not created as a remote SPAN VLAN; it must be configured with 'remote-span' command.
AnswerA

The trunk ports between the switches do not have the RSPAN VLAN (999) in their allowed VLAN list. This is the root cause because RSPAN relies on a dedicated VLAN to carry mirrored traffic across the Layer 2 fabric. Even if the VLAN is active on each switch, an ISL or 802.1Q trunk will prune or drop any VLAN not explicitly permitted in its allowed list. Since the default allowed list typically includes only VLANs 1-1005, a higher VLAN such as 999 may be silently omitted. Without VLAN 999 allowed on every trunk in the path, the mirrored frames never reach the destination switch, so the analyzer sees no traffic.

Why this answer

RSPAN traffic is carried over an RSPAN VLAN that must be allowed on all trunk links between the source switches and the central switch. If the RSPAN VLAN (999) is not included in the allowed VLAN list on the trunk ports, the mirrored frames will be dropped, and the monitoring station will receive no traffic. This is the most likely missing configuration because the engineer verified the VLAN is active and the destination session is set, but did not check the trunk pruning.

Exam trap

Cisco often tests the subtle requirement that the RSPAN VLAN must be explicitly permitted on trunk ports, as candidates may assume that a VLAN created and active on both ends is automatically carried across a trunk.

How to eliminate wrong answers

Option B is wrong because 'monitor session 2 destination remote vlan 999' is the correct command to define the RSPAN VLAN as the destination for the central switch; the destination interface (Gi1/0/1) is configured separately as the egress port for the monitoring station, so this syntax is not an error. Option C is wrong because the source sessions on remote switches must use 'monitor session 1 source ...' and then 'monitor session 1 destination remote vlan 999' to send traffic into the RSPAN VLAN; the description in the option omits the destination command, which would indeed cause failure, but the question states the engineer configured the source sessions, implying the destination remote vlan was set, so this is not the likely missing piece. Option D is wrong because the 'remote-span' command is required on the RSPAN VLAN to prevent normal data traffic from using it, but the question states the RSPAN VLAN is active and the destination session is configured, so this command is likely already applied; the missing step is the trunk allowed list.

1452
MCQhard

A network automation team is using the Cisco SD-WAN vManage REST API to monitor the status of WAN Edge devices. The team writes a Python script that authenticates using basic authentication and then sends a GET request to /dataservice/device. The script receives a 401 Unauthorized error even though the credentials are correct. The team verifies that the user account has the 'admin' role. What is the most likely cause of the authentication failure?

A.The vManage API requires the use of a session token obtained via /j_security_check instead of basic authentication.
B.The vManage API requires TLS client certificate authentication for all API calls.
C.The script must include the header 'Content-Type: application/json' in the GET request to authenticate.
D.The user account must be assigned the 'api' role in addition to the 'admin' role to access the REST API.
AnswerA

The Cisco SD-WAN vManage REST API does not support basic authentication for most endpoints. Instead, clients must authenticate by sending a POST request to /j_security_check with username and password, which returns a JSESSIONID cookie. Subsequent requests must include this cookie. Using basic authentication results in a 401 error even with valid credentials.

Why this answer

The Cisco SD-WAN vManage REST API uses session-based authentication. Clients must first POST to /j_security_check with credentials to obtain a JSESSIONID cookie, which is then included in subsequent requests. Basic authentication is not supported, leading to a 401 error even with valid credentials.

Exam trap

The trap here is assuming that the vManage API supports basic authentication like many REST APIs, when it actually requires a session cookie obtained via a specific login endpoint.

1453
MCQmedium

A network engineer is deploying Cisco ACI in a data center. The requirement is to allow an external Layer 3 router to dynamically learn the endpoints that reside in a specific bridge domain (BD) and to advertise the BD's subnet to the external network. The external router is connected to a border leaf switch. Which Cisco ACI construct must be configured to meet this requirement?

A.A VRF with a contract that permits all traffic between the external router and the BD.
B.A bridge domain with unicast routing enabled and a contract to the external EPG.
C.An L3Out with an external EPG and OSPF or BGP peering to the external router.
D.An EPG with a static path binding to the external router's interface.
AnswerC

An L3Out defines the Layer 3 connection to an external router. It includes an external EPG that represents the external network, and routing protocols like OSPF or BGP can be configured to exchange routes. The border leaf advertises the BD subnet and learns external routes, enabling dynamic endpoint reachability. This is the correct construct for external Layer 3 connectivity.

Why this answer

The L3Out construct in Cisco ACI is designed for external Layer 3 connectivity. It includes an external EPG and supports routing protocols such as OSPF, BGP, or EIGRP. By configuring an L3Out on the border leaf, the fabric can peer with the external router, advertise the bridge domain subnet, and learn external routes.

Contracts are for policy, not route exchange, and static path bindings are for Layer 2 connectivity.

Exam trap

The trap here is confusing contracts or static path bindings with the routing protocol peering that only an L3Out provides for external Layer 3 connectivity.

1454
Multi-Selectmedium

Which two statements about NFV performance considerations are true? (Choose two.)

Select 2 answers
A.SR-IOV allows a virtual function (VF) to be directly assigned to a VM, providing near-native network performance.
B.NUMA awareness is the primary technique to improve NFV packet processing performance.
C.DPDK provides a set of libraries and drivers for fast packet processing in user space, bypassing the kernel network stack.
D.Using a virtual switch with multiple bonded uplinks eliminates the need for any performance optimization.
E.NFV performance is inherently lower than physical appliances and cannot be improved.
AnswersA, C

SR-IOV bypasses the hypervisor's virtual switch by assigning a hardware virtual function directly to the guest, eliminating software-based packet processing overhead. This satisfies the stem's performance constraint, delivering near-native throughput and reduced CPU load compared with virtio or full emulation, which matters for NFV workloads requiring line-rate forwarding.

Why this answer

Option A is correct because SR-IOV (Single Root I/O Virtualization) lets a physical NIC expose virtual functions (VFs) that can be directly assigned to a VM via PCI passthrough, so traffic bypasses the hypervisor's virtual switch and gives near-native throughput and low latency. Option C is correct because DPDK (Data Plane Development Kit) supplies user-space libraries, PMD drivers, and hugepage-based memory management that let applications poll NICs directly, bypassing the kernel network stack to achieve high packet-processing rates. Option B is not correct as stated because NUMA awareness is an important optimization for memory locality, but it is not the primary technique for NFV packet processing; SR-IOV, DPDK, and CPU pinning play more central roles.

Option D is wrong because bonding multiple uplinks improves redundancy and aggregate bandwidth but does not remove the need for tuning such as DPDK, SR-IOV, or CPU pinning. Option E is wrong because NFV performance can be substantially improved with the right hardware and software optimizations, often approaching or matching physical appliance performance.

Exam trap

The trap here is that NUMA awareness sounds like a fundamental performance technique, so candidates pick it over the more specific SR-IOV/DPDK pair; the exam expects you to distinguish primary data-plane accelerators from supporting tuning knobs.

1455
MCQmedium

A network engineer is implementing VRF-Lite on a Cisco IOS router to separate traffic from two different departments. The router has two interfaces, GigabitEthernet0/0 and GigabitEthernet0/1, each assigned to a different VRF. The engineer wants to verify that the VRFs are properly configured and that routes are being populated. Which command displays the routing table for a specific VRF?

A.show ip vrf
B.show vrf interface
C.show ip route
D.show ip route vrf DEPARTMENT1
AnswerD

This command displays the IP routing table for the VRF named DEPARTMENT1. It is the correct way to verify routes within a specific VRF. Without specifying the VRF, the global routing table is shown, which does not include VRF routes. This command is essential for troubleshooting VRF-Lite configurations.

Why this answer

To view the routing table for a specific VRF, the show ip route vrf command must be used. The global show ip route only displays the global table. Commands like show vrf interface and show ip vrf provide VRF configuration information but not the routes themselves.

Verifying VRF routes is critical in VRF-Lite deployments to ensure proper traffic separation.

Exam trap

The trap here is using show ip route without the vrf keyword, which only shows the global routing table and misses VRF-specific routes.

1456
Multi-Selecthard

Which three statements about Ansible modules for Cisco IOS-XE are true? (Choose three.)

Select 3 answers
A.The ios_config module supports idempotent configuration changes by comparing the desired state with the running configuration.
B.The ios_command module can be used to execute show commands and capture output for parsing.
C.The ios_facts module gathers only interface statistics from the device.
D.The ios_vlan module is used to create and delete VLANs on Cisco IOS devices.
E.The ios_lldp module can only enable LLDP globally, not on specific interfaces.
AnswersA, B, D

The ios_config module compares the supplied configuration lines against the device's running configuration and pushes only the missing lines, so repeated runs produce no further change. This satisfies the idempotency requirement rather than blindly reapplying commands each execution.

Why this answer

Option A is correct because ios_config is the declarative configuration module for IOS-XE: it renders the candidate lines, compares them against the device's running configuration (via the network_cli connection and the device's show running-config output), and only pushes the diff, which makes repeated runs idempotent. Option B is correct because ios_command is the read-only module designed to run arbitrary operational (show) commands on IOS-XE and return structured results in the stdout/stdout_lines keys, which can then be parsed by filters or subsequent tasks. Option D is correct because ios_vlan manages VLAN resources on Cisco IOS/IOS-XE devices, allowing VLANs to be created, modified (name, state), and removed declaratively.

Option C is not correct because ios_facts collects a broad set of facts—including hardware, software version, hostname, interfaces, and IP addressing—not just interface statistics. Option E is not correct because ios_lldp supports interface-level parameters (such as enabling/disabling LLDP per interface via the interfaces option), not only the global enable/disable state.

Exam trap

The trap is that candidates may assume ios_facts only gathers interface statistics (it gathers much more) or that ios_lldp is limited to global configuration (it supports interface-level), leading them to incorrectly exclude the true statements.

1457
MCQmedium

A network engineer is troubleshooting a DHCP issue where a client is not receiving an IP address from a Cisco router configured as a DHCP server. The engineer checks the DHCP pool configuration and sees that the network command is configured with the correct subnet. The engineer also verifies that the ip dhcp excluded-address command is not blocking any addresses. However, the client's DHCP discover message is not reaching the router. What is the most likely cause?

A.The router's interface is configured with the no ip forward-protocol udp bootps command.
B.The router's interface is not in the same VLAN as the client, and no ip helper-address is configured.
C.The DHCP pool is configured with the wrong default-router option.
D.The router's DHCP server is disabled globally with the no service dhcp command.
AnswerB

This is correct because DHCP clients use Layer 2 broadcast (destination FF:FF:FF:FF:FF:FF) to send DHCPDISCOVER messages, and broadcasts never cross a Layer 3 boundary by default. If the router's interface is in a different VLAN from the client, the broadcast stays confined to the client's broadcast domain. To reach a DHCP server in another subnet, you must configure an `ip helper-address` on the client's VLAN interface, which converts the broadcast into a unicast (or directed broadcast) to the DHCP server. Without that relay, the router will never receive the DISCOVER because it is not on the same VLAN.

Why this answer

If the client and the router's DHCP server interface are on different VLANs (i.e., different subnets), the DHCP discover broadcast will not cross the Layer 3 boundary unless the router interface has an ip helper-address configured. The ip helper-address command enables the router to convert the broadcast DHCP discover into a unicast and forward it to the DHCP server. Without it, the client's broadcast never reaches the server, even if the DHCP pool is correctly defined.

Exam trap

Cisco often tests the distinction between a router acting as a DHCP server versus a DHCP relay agent, and the trap here is that candidates assume a correctly configured DHCP pool is sufficient, overlooking the requirement for ip helper-address when the client and server are on different subnets.

How to eliminate wrong answers

Option A is wrong because the no ip forward-protocol udp bootps command would prevent the router from forwarding DHCP broadcasts to a remote server, but the question states the router itself is the DHCP server, so this command is irrelevant. Option C is wrong because a wrong default-router option would cause the client to receive an IP but potentially have incorrect gateway information; it would not prevent the DHCP discover message from reaching the router. Option D is wrong because if the DHCP server were disabled globally with no service dhcp, the router would not respond to any DHCP requests, but the engineer already verified the DHCP pool configuration, implying the service is enabled; moreover, the issue is that the discover message is not reaching the router, not that the router is failing to respond.

1458
MCQmedium

Consider the following DHCP snooping configuration on a Cisco IOS-XE switch: ``` ip dhcp snooping ip dhcp snooping vlan 10 interface GigabitEthernet0/1 ip dhcp snooping trust ! interface GigabitEthernet0/2 ip dhcp snooping limit rate 10 ``` Which statement is true?

A.Gi0/1 is trusted for DHCP snooping, and Gi0/2 will drop DHCP packets exceeding 10 per second.
B.Gi0/2 is trusted and will forward all DHCP packets without rate limiting.
C.The switch will only snoop DHCP on VLAN 10, but rate limiting applies to all VLANs.
D.Gi0/1 will rate-limit DHCP packets to 10 per second.
AnswerA

Correct. In DHCP snooping, a trusted port is explicitly configured to receive DHCP server traffic, so Gi0/1 bypasses all DHCP snooping validation and forwards DHCP packets normally. Gi0/2 is not configured as trusted, making it an untrusted port; the 'ip dhcp snooping limit rate 10' command applies rate limiting to that interface, so any DHCP packets exceeding 10 per second on Gi0/2 will be dropped.

Why this answer

The 'ip dhcp snooping trust' command on Gi0/1 explicitly marks that interface as trusted, allowing all DHCP messages through without inspection. On Gi0/2, the 'ip dhcp snooping limit rate 10' command applies a rate limit of 10 packets per second to DHCP traffic; any DHCP packets exceeding this rate are dropped, which is a standard DHCP snooping rate-limiting behavior.

Exam trap

Cisco often tests the misconception that 'ip dhcp snooping limit rate' implies trust or that rate limiting applies globally, when in fact it is an interface-level feature that only applies to untrusted interfaces.

How to eliminate wrong answers

Option B is wrong because Gi0/2 is not configured as a trusted interface; the 'ip dhcp snooping limit rate 10' command does not imply trust, and untrusted interfaces are subject to DHCP snooping validation and rate limiting. Option C is wrong because DHCP snooping is enabled only on VLAN 10, and rate limiting is applied per interface, not per VLAN; the rate limit on Gi0/2 affects only that interface's DHCP traffic, regardless of VLAN. Option D is wrong because Gi0/1 is configured as a trusted interface, and rate limiting is not applied to trusted interfaces by default; the 'ip dhcp snooping limit rate' command is not present on Gi0/1, so no rate limiting occurs there.

1459
MCQmedium

A network team is designing an SD-WAN overlay for a multinational enterprise with 500+ branch sites. The design must ensure that control plane traffic (e.g., OMP updates) is encrypted and authenticated between all vSmart controllers and vEdge routers, while allowing data plane traffic to use IPsec tunnels between branch sites directly. Which architectural element is responsible for orchestrating the initial authentication and certificate enrollment of all SD-WAN devices?

A.vManage
B.vSmart
C.vBond
D.vEdge
AnswerC

vBond is the orchestrator and the first point of contact for any device attempting to join the SD-WAN overlay. It authenticates devices by verifying their serial numbers and certificates against the configured credentials, and then provides the authenticated device with the IP addresses of vManage and vSmart. This mutual authentication ensures that only trusted devices can participate, and without vBond, no device can complete the initial handshake to join the fabric.

Why this answer

C is correct because the vBond orchestrator is the sole component responsible for initial authentication and certificate enrollment in Cisco SD-WAN. It acts as a trusted certificate authority (CA) proxy, validating the serial numbers and certificates of all vSmart controllers and vEdge routers before they join the overlay network. Without vBond, devices cannot establish trust or receive the authorized list of vSmart and vManage IP addresses.

Exam trap

Cisco often tests the misconception that vManage handles all management functions including authentication, but the trap here is that vBond is the dedicated orchestrator for initial trust and certificate enrollment, while vManage only manages the devices after they have been authenticated.

How to eliminate wrong answers

Option A is wrong because vManage is the management and monitoring plane, handling configuration templates, policies, and analytics, but it does not perform initial authentication or certificate enrollment. Option B is wrong because vSmart is the control plane controller that distributes OMP routes and policies, but it relies on vBond for initial trust and does not handle certificate issuance. Option D is wrong because vEdge is a data plane router that terminates IPsec tunnels and forwards traffic; it is a client in the authentication process, not the orchestrator of it.

1460
MCQmedium

A company is deploying a virtualized router (CSR1000v) on VMware vSphere. The VNF must support high throughput and low latency. Which vSphere configuration option should the architect select to optimize network performance?

A.Use the default e1000 NIC driver.
B.Enable SR-IOV on the physical NIC and assign virtual functions to the VM.
C.Use VMXNET3 paravirtualized NIC.
D.Configure the VM with multiple vCPUs and large memory.
AnswerB

SR-IOV (Single Root I/O Virtualization) partitions a physical NIC into multiple Virtual Functions (VFs), each with dedicated hardware queues, interrupts, and DMA resources. When a VF is directly assigned to a VM using PCI passthrough, the guest driver communicates with the NIC hardware without hypervisor mediation in the data path, yielding near-native throughput and latencies. This is the correct choice for NFV because it bypasses the virtual switch and most of the hypervisor's I/O stack, though it requires SR-IOV-capable hardware and sacrifices some features like live migration.

Why this answer

SR-IOV (Single Root I/O Virtualization) allows a physical NIC to present multiple virtual functions (VFs) directly to a VM, bypassing the hypervisor's virtual switch. This reduces latency and CPU overhead, making it ideal for high-throughput, low-latency VNFs like the CSR1000v. Option B is correct because SR-IOV provides near-native performance by allowing the VM to directly access the NIC hardware.

Exam trap

Cisco often tests the misconception that VMXNET3 is the best performance option for all VNFs, but the trap here is that SR-IOV is required when the question explicitly demands 'high throughput and low latency' because it eliminates hypervisor overhead.

How to eliminate wrong answers

Option A is wrong because the default e1000 NIC driver is a fully emulated, legacy driver that introduces significant CPU overhead and poor performance, unsuitable for high-throughput VNFs. Option C is wrong because while VMXNET3 is a paravirtualized NIC that offers better performance than e1000, it still passes through the hypervisor's virtual switch, adding latency compared to SR-IOV's direct hardware access. Option D is wrong because simply adding more vCPUs and memory does not optimize network performance; it can even cause contention or scheduling overhead without addressing the I/O path bottleneck.

1461
Drag & Dropmedium

Drag and drop the steps of ACL reflexive access list (dynamic inspection) flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Reflexive ACLs work by evaluating outbound traffic to create dynamic entries that allow return traffic. The order is: define extended ACL, apply outbound, define reflexive ACL, apply inbound, then the reflexive entry is created dynamically.

1462
MCQeasy

What is the default native VLAN on a Cisco switch trunk port?

A.VLAN 1
B.VLAN 0
C.VLAN 1002
D.VLAN 4095
AnswerA

VLAN 1 is the default native VLAN on all Cisco switches. When a port is configured as an access port or when a trunk is created without an explicit native VLAN assignment, VLAN 1 carries all untagged traffic for backward compatibility with legacy bridging. It is also part of the default VLAN list that cannot be deleted from a standard switch, making it the correct answer to any question asking for the default 802.1Q native VLAN.

Why this answer

The default native VLAN on a Cisco switch trunk port is VLAN 1. The native VLAN is the VLAN that carries untagged traffic over a trunk link, and by default, all switch ports (including trunk ports) belong to VLAN 1. This is defined in the IEEE 802.1Q standard, which specifies that frames on the native VLAN are not tagged with a VLAN ID.

Exam trap

Cisco often tests the misconception that the native VLAN is always VLAN 1 by default, but the trap is that candidates may confuse it with the management VLAN (also often VLAN 1) or assume that changing the native VLAN is required for trunking to work.

How to eliminate wrong answers

Option B is wrong because VLAN 0 is not a valid VLAN number; VLAN IDs range from 1 to 4094, with 0 and 4095 reserved for internal use (e.g., 802.1p priority tagging). Option C is wrong because VLAN 1002 is one of the default VLANs (1002-1005) reserved for legacy Token Ring and FDDI networks, not the native VLAN. Option D is wrong because VLAN 4095 is reserved for implementation-specific use (e.g., 'all VLANs' in some Cisco configurations) and is not a valid native VLAN.

1463
Matchingmedium

Drag and drop each authentication mode on the left to its matching behavior on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Allows traffic before authentication completes

Blocks all traffic until authentication succeeds

Permits traffic but logs authentication failures

Allows traffic when RADIUS server is unreachable

Supports one voice and one data device per port

Why these pairings

Open mode allows traffic before authentication, closed mode blocks until success, monitor mode logs but does not enforce.

1464
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive control-plane traffic. The engineer wants to rate-limit ARP and DHCP snooping-related traffic destined to the control plane while allowing routing protocol traffic without restriction. Which CoPP component must the engineer configure to classify and match this traffic before applying the policy?

A.A policy map that references the control-plane host and matches all IP traffic by default.
B.An access list applied directly to the control-plane interface with the ip access-group command.
C.A class map that matches traffic using ACLs and/or match protocol commands.
D.A route map applied to the control-plane interface with the service-policy command.
AnswerC

CoPP uses a modular QoS CLI structure: class maps define the traffic to be matched, policy maps define the actions, and the service-policy is applied to the control-plane interface. To rate-limit ARP and DHCP snooping traffic, the engineer must first create class maps that identify those protocols using ACLs or match protocol statements, then reference them in a policy map.

Why this answer

CoPP relies on the modular QoS CLI, where class maps classify control-plane traffic, policy maps apply policing actions, and the service-policy is attached to the control-plane interface. To rate-limit ARP and DHCP snooping traffic while leaving routing protocols unrestricted, the engineer must create class maps that match those specific protocols and reference them in a policy map, which is then applied to the control plane.

Exam trap

The trap here is confusing CoPP with ACL-based control-plane filtering, when CoPP specifically requires class maps and a policy map applied via service-policy on the control-plane interface.

1465
MCQhard

A network engineer is implementing a first-hop redundancy protocol on a pair of Cisco switches. The design requires that the standby router take over if the active router fails, and that the virtual MAC address be 0000.0c07.ac0a. Which protocol and group number are being used?

A.HSRP group 10
B.HSRP group 170
C.VRRP group 10
D.GLBP group 10
AnswerA

HSRP uses a virtual MAC address in the format 0000.0c07.acXX, where XX is the group number in hexadecimal. The address 0000.0c07.ac0a corresponds to group 10 (0a in hex equals 10 in decimal). HSRP provides redundancy with an active and standby router.

Why this answer

The virtual MAC address 0000.0c07.ac0a indicates HSRP with group 10 because the last two hex digits (0a) represent the group number in hexadecimal. HSRP uses this MAC format, while VRRP and GLBP use different formats.

Exam trap

The trap here is misinterpreting the hexadecimal group number or confusing the MAC address formats of different first-hop redundancy protocols.

1466
MCQhard

A network engineer runs the following command on Router R3: R3# show dmvpn Legend: Attrb -> S: Static, D: Dynamic, I: Incomplete N: NATed, L: Local, X: No Socket # Ent -> Number of NHRP entries with same NBMA peer NHS Status: E => Expecting Replies, R => Responding, W => Waiting UpDn Time -> Up or Down Time for a Tunnel ========================================================================== Interface: Tunnel0, IPv4 NHRP Details Type:Hub, NHRP Peers:2, # Ent Peer NBMA Addr Peer Tunnel Add State UpDn Tm Attrb ----- --------------- --------------- ----- -------- ----- 1 192.168.1.1 10.0.0.1 UP 00:12:34 D 1 192.168.1.2 10.0.0.2 UP 00:10:20 D Based on this output, what can be concluded?

A.This router is a spoke in the DMVPN network.
B.There are two active spoke routers connected to this hub.
C.The tunnel interface is down because no peers are listed.
D.The router is using static NHRP mappings for all peers.
AnswerB

The NHRP peer table lists two distinct entries, each with a state of `UP` and a flag showing `D` for dynamically registered peers. These entries represent two spoke routers that have successfully completed NHRP registration with this hub, and they remain reachable through the mGRE tunnel. The presence of two `UP` dynamic peers directly confirms that exactly two active spoke routers are connected to this hub.

Why this answer

The output shows the router is a Hub (Type:Hub) with two NHRP peers (NHRP Peers:2), both in the UP state with dynamic (D) attribute entries. This confirms that two spoke routers have successfully registered with this hub via NHRP, making option B correct.

Exam trap

Cisco often tests the distinction between Hub and Spoke roles in DMVPN output; candidates mistakenly assume any router with multiple peers must be a spoke, but the 'Type:Hub' field and dynamic attribute entries clearly identify the hub role.

How to eliminate wrong answers

Option A is wrong because the output explicitly states 'Type:Hub', not Spoke, and the hub is the central router in a DMVPN topology. Option C is wrong because the tunnel interface is clearly up (both peers show UP state and UpDn Tm values), and peers are listed (two entries). Option D is wrong because the Attrb column shows 'D' (Dynamic) for both peers, indicating NHRP dynamically resolved the mappings, not static configuration.

1467
MCQmedium

Consider the following partial configuration for QoS on a Cisco IOS-XE router: class-map match-all VOICE match ip dscp ef ! policy-map QOS_POLICY class VOICE priority 1000 class class-default fair-queue ! interface GigabitEthernet0/0 service-policy output QOS_POLICY What is the effect of the 'priority 1000' command under class VOICE?

A.Voice traffic is placed in a strict priority queue with a bandwidth limit of 1000 kbps.
B.Voice traffic is given a minimum bandwidth guarantee of 1000 kbps but no priority.
C.Voice traffic is dropped if it exceeds 1000 kbps.
D.Voice traffic is shaped to 1000 kbps.
AnswerA

The `priority` command creates a low-latency queue serviced before other classes, and its 1000 value sets the guaranteed bandwidth in kbps. This satisfies the stem's requirement to identify the effect of `priority 1000`: voice traffic receives strict priority scheduling capped at 1000 kbps, while `fair-queue` handles remaining class-default traffic.

Why this answer

The 'priority 1000' command under a class in a policy-map enables Low Latency Queuing (LLQ) for that class, placing its traffic in a strict priority queue. The value 1000 specifies the bandwidth limit in kbps that the priority queue is policed to; traffic exceeding this rate is dropped when congestion occurs. This ensures voice traffic gets low latency while preventing it from starving other classes.

Exam trap

The trap is confusing priority with bandwidth; candidates may think priority 1000 guarantees 1000 kbps without dropping, but it actually polices and drops excess traffic during congestion.

How to eliminate wrong answers

Option B is wrong because 'priority' provides strict priority service, not just a minimum bandwidth guarantee; the 'bandwidth' command would give a minimum guarantee without priority. Option C is wrong because although excess traffic above 1000 kbps is dropped during congestion, the primary effect is strict priority queuing with a policed rate, not simply dropping all traffic above the limit. Option D is wrong because shaping buffers excess traffic to smooth it, whereas priority policing drops excess traffic immediately.

1468
Drag & Dropmedium

Drag and drop the steps of EIGRP DUAL route computation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

EIGRP DUAL first identifies feasible successors via reported distance, then selects the best path as successor. If the successor fails, it checks feasible successors; if none exist, it goes active and queries neighbors. After replies, it computes a new successor.

1469
Drag & Dropmedium

Drag and drop the steps of DSCP-to-CoS mapping at LAN boundary into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

At the LAN boundary (switch port), DSCP is mapped to CoS for 802.1Q trunking. The order ensures proper trust, mapping, and queuing for consistent QoS across the campus network.

1470
Drag & Dropmedium

Drag and drop the steps of DMVPN Phase 3 spoke-to-spoke shortcut creation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In DMVPN Phase 3, when a spoke needs to reach another spoke, it first sends traffic to the hub. The hub forwards the packet with an NHRP redirect. The source spoke then sends an NHRP resolution request to the hub to get the destination spoke's NBMA address.

The hub replies with the mapping, and the source spoke dynamically builds a direct mGRE tunnel to the destination spoke.

1471
MCQmedium

router bgp 65000 bgp router-id 10.0.0.1 neighbor 10.0.0.2 remote-as 65000 ! Which statement about this configuration is true?

A.This is an iBGP session because the remote AS matches the local AS.
B.This is an eBGP session because the neighbor IP is in a different subnet.
C.The router will automatically set next-hop-self for routes sent to this neighbor.
D.The configuration is invalid because iBGP requires a loopback interface.
AnswerA

The session is classified as iBGP because the neighbor's configured remote-as matches the local autonomous system number (ASN). In BGP, the sole criterion for declaring a session internal is that both peers belong to the same AS; the neighbor can be any reachable IP address, even across subnets. Since the remote-as is equal to the local AS, the BGP state machine treats it as an internal session, which affects attributes like next-hop handling and loop prevention. This is the fundamental rule that distinguishes iBGP from eBGP.

Why this answer

This configuration establishes an iBGP session because the local AS number (65000) matches the remote AS number (65000). In BGP, when both routers share the same AS, the session is classified as internal BGP (iBGP), regardless of the IP addressing scheme used.

Exam trap

Cisco often tests the distinction between iBGP and eBGP based solely on AS numbers, leading candidates to mistakenly think subnet differences or interface types determine the session type.

How to eliminate wrong answers

Option B is wrong because eBGP is defined by different AS numbers, not by subnet differences; iBGP can operate between neighbors in different subnets. Option C is wrong because next-hop-self is not automatically set for iBGP neighbors; it must be explicitly configured with the 'neighbor x.x.x.x next-hop-self' command. Option D is wrong because iBGP does not require a loopback interface; while loopbacks are commonly used for stability, the configuration is valid with any interface IP.

1472
MCQmedium

Review the following configuration: vrf definition CUSTOMER_A rd 65000:100 route-target export 65000:100 route-target import 65000:100 ! interface GigabitEthernet0/4 vrf forwarding CUSTOMER_A ip address 192.168.100.1 255.255.255.0 ! router bgp 65000 address-family ipv4 vrf CUSTOMER_A redistribute connected What is the purpose of the 'redistribute connected' command under the VRF address-family?

A.It advertises the directly connected network of GigabitEthernet0/4 into BGP for VRF CUSTOMER_A.
B.It redistributes all BGP routes into the VRF's routing table.
C.It enables BGP to exchange routes with other VRFs on the same router.
D.It is used to leak routes between VRF CUSTOMER_A and the global routing table.
AnswerA

This is correct because the command, typically the BGP network statement or redistribution directive under the address-family ipv4 vrf CUSTOMER_A, injects the subnet assigned to GigabitEthernet0/4 into the BGP table for that VRF. The connected route is advertised to BGP peers in the VRF as reachable, enabling the VRF's customers to reach that directly attached network. This does not affect any other VRF or the global routing table.

Why this answer

The 'redistribute connected' command under the BGP address-family for VRF CUSTOMER_A injects the directly connected network on GigabitEthernet0/4 (192.168.100.0/24) into the BGP table for that VRF. This allows BGP to advertise that subnet to BGP peers within the VRF, enabling reachability to the VRF's local interface network.

Exam trap

Cisco often tests the misconception that 'redistribute connected' in a VRF context applies to all connected interfaces globally, when in fact it only applies to interfaces assigned to that specific VRF.

How to eliminate wrong answers

Option B is wrong because 'redistribute connected' injects directly connected routes into BGP, not the other way around; BGP routes are not redistributed into the VRF routing table by this command. Option C is wrong because BGP does not exchange routes between VRFs on the same router unless explicit route leaking (e.g., using import/export RTs or VRF-lite) is configured, and this command does not enable inter-VRF exchange. Option D is wrong because leaking routes between a VRF and the global routing table requires additional configuration (e.g., route-target import/export between VRF and global, or using 'network' commands with a route-map), not simply redistributing connected routes under the VRF address-family.

1473
MCQmedium

A network engineer runs the following command on switch SW5: SW5# show cts sxp connections SXP Connections: Peer IP Source IP Conn Status Duration 10.1.1.1 10.1.1.2 Up 2d3h 10.1.1.3 10.1.1.2 Down 0d0h Based on this output, what can be concluded?

A.Both SXP connections are operational.
B.The SXP connection to 10.1.1.1 has been up for 2 days and 3 hours.
C.The switch is using 802.1X for authentication.
D.The SXP connection to 10.1.1.3 is up.
AnswerB

The SXP connection to 10.1.1.1 is correctly identified as being up for 2 days and 3 hours because the output shows the status 'Up' with a duration of '2d3h' for that peer. This specifically indicates the SXP TCP session has been established and stable for that period without interruption. The presence of a duration counter confirms the connection is actively maintained, making this the only true statement among the options.

Why this answer

The command 'show cts sxp connections' displays the status of SXP (Security Group Tag Exchange Protocol) connections. The output shows that the connection to peer 10.1.1.1 has a status of 'Up' and a duration of '2d3h', meaning it has been established for 2 days and 3 hours. Option B correctly identifies this fact.

Exam trap

Cisco often tests the ability to read the output of 'show cts sxp connections' accurately, where the trap is that candidates may assume all connections are up or misinterpret the 'Down' status as 'Up' due to not carefully checking the 'Conn Status' column.

How to eliminate wrong answers

Option A is wrong because the connection to 10.1.1.3 has a status of 'Down', so not both SXP connections are operational. Option C is wrong because the output is from 'show cts sxp connections', which is specific to SXP and Cisco TrustSec, not 802.1X authentication; 802.1X is a separate IEEE standard for port-based network access control. Option D is wrong because the connection to 10.1.1.3 shows 'Down' in the Conn Status column, indicating it is not up.

1474
Drag & Dropmedium

Drag and drop the steps of Wireless client IP address assignment via DHCP bridging into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In DHCP bridging, the client first associates and authenticates. The AP then bridges the DHCP Discover from the client to the wired network. The DHCP server replies with Offer, the client sends Request, and the server sends Ack, completing the process.

1475
MCQmedium

A network architect is designing an SD-Access fabric for a large enterprise campus. The design must support segmentation at Layer 2 and Layer 3 across the fabric, using a centralized control plane and policy enforcement. Which two protocols are essential for the SD-Access overlay to meet these requirements?

A.LISP and VXLAN
B.MP-BGP and MPLS
C.OSPF and GRE
D.IS-IS and NVGRE
AnswerA

In Cisco SD-Access, LISP serves as the overlay control plane by storing endpoint identifiers and mapping them to routing locators, enabling host mobility, segmentation, and scalable forwarding decisions. VXLAN is the overlay data plane, wrapping Ethernet frames in UDP/IP with a VNI that isolates tenants and virtual networks. Together they decouple the logical fabric from the physical underlay, allowing arbitrary Layer 2 and Layer 3 topologies over a routed IP fabric.

Why this answer

LISP (Locator/ID Separation Protocol) provides the centralized control plane for endpoint identity-to-location mapping and policy-based forwarding, while VXLAN (Virtual Extensible LAN) supplies the data-plane encapsulation needed for Layer 2 and Layer 3 segmentation across the underlay. Together, they enable scalable overlay segmentation with a centralized policy enforcement point in SD-Access.

Exam trap

Cisco often tests the misconception that MPLS or EVPN is the required overlay for SD-Access, but the exam specifically expects LISP and VXLAN as the essential protocols for the fabric overlay.

How to eliminate wrong answers

Option B is wrong because MP-BGP and MPLS are used in MPLS VPN architectures (e.g., L3VPN/EVPN) but are not the essential overlay protocols for Cisco SD-Access; SD-Access uses LISP for control plane and VXLAN for data plane, not MPLS. Option C is wrong because OSPF and GRE provide only basic routing and tunneling without the centralized control plane or segmentation capabilities required; GRE lacks the multi-tenant VNI-based segmentation that VXLAN offers. Option D is wrong because IS-IS is an underlay routing protocol and NVGRE is a Microsoft-proprietary overlay that does not integrate with Cisco’s SD-Access fabric; SD-Access specifically requires LISP and VXLAN.

1476
MCQhard

A network engineer is configuring a Cisco Catalyst switch to support 802.1X authentication for wired users. The company requires that if the RADIUS server becomes unreachable, devices on a critical VLAN should be allowed access to the network without authentication. Which feature should be configured on the switch to meet this requirement?

A.Inaccessible Authentication Bypass
B.Guest VLAN
C.Critical VLAN
D.MAC Authentication Bypass
AnswerA

Inaccessible Authentication Bypass (IAB) is a Cisco feature that allows a port to be authorized and placed into a configurable critical VLAN when the RADIUS server is unreachable. This ensures that critical devices can still access the network without authentication during a server outage, meeting the requirement exactly.

Why this answer

Inaccessible Authentication Bypass (IAB) is designed to handle the exact situation where the RADIUS server becomes unreachable. When enabled, the switch places the port into a critical VLAN, allowing devices to gain network access without authentication. This feature is essential for maintaining connectivity for critical devices during an authentication server outage.

Exam trap

The trap here is confusing Inaccessible Authentication Bypass with Critical VLAN; while related, IAB is the feature that enables the bypass behavior when the server is down, whereas Critical VLAN is the VLAN assignment used by IAB.

1477
MCQeasy

A network administrator is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The security policy requires that the VPN use IKEv2 with certificate-based authentication. Which command must be configured on both routers to specify the trustpoint that will be used for IKEv2 authentication?

A.crypto ikev2 proposal <name> and then encryption aes-cbc-256 under the proposal.
B.crypto ikev2 profile <name> and then pki trustpoint <trustpoint-name> under the profile.
C.crypto ikev2 profile <name> and then match certificate <map-name> under the profile.
D.crypto ikev2 keyring <name> and then pre-shared-key <key> under the keyring.
AnswerB

Within an IKEv2 profile, the 'pki trustpoint' command specifies which PKI trustpoint the router will use for certificate-based authentication. This is the correct way to bind a trustpoint to an IKEv2 profile. Both routers must have this configured to present and validate certificates during IKEv2 negotiation, satisfying the certificate-based authentication requirement.

Why this answer

IKEv2 certificate-based authentication requires a PKI trustpoint to be associated with the IKEv2 profile. The 'pki trustpoint' command under the IKEv2 profile binds the trustpoint, enabling the router to use certificates for authentication. This must be configured on both peers.

Other commands like 'match certificate' are used for certificate map matching, and keyrings are for PSK authentication, neither of which satisfies the certificate requirement.

Exam trap

The trap here is confusing the command that binds a trustpoint to an IKEv2 profile with the command that matches certificate fields or configures PSK authentication, leading to an incomplete or incorrect configuration.

1478
MCQmedium

Examine the following partial Cisco IOS-XE configuration: interface GigabitEthernet0/1 switchport mode access switchport access vlan 10 ip access-group ACL_IN in spanning-tree portfast What is the effect of this configuration?

A.The port will immediately transition to forwarding state, reducing STP convergence time for end hosts.
B.The port will become a trunk port and participate in VLAN trunking.
C.The port will use Rapid PVST+ and immediately forward after a link failure.
D.The port will block all inbound traffic due to the ACL.
AnswerA

spanning-tree portfast moves the access port straight to forwarding, bypassing listening and learning states, so end hosts gain connectivity without waiting for STP convergence. The port remains access in VLAN 10 with ACL_IN applied inbound.

Why this answer

The configuration enables PortFast on an access port, allowing it to transition directly to forwarding state, bypassing the listening and learning phases. This is commonly used for end-host ports to avoid delays caused by spanning-tree convergence.

1479
Drag & Dropmedium

Drag and drop the steps of adding a new VLAN to a trunk link into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, create the VLAN globally on the switch. Then, verify the VLAN exists. Next, ensure the trunk allows that VLAN.

After that, check the trunk's allowed VLAN list. Finally, test connectivity for hosts in the new VLAN.

1480
MCQmedium

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP monitoring. After applying a new CoPP policy, BGP sessions flap intermittently while SSH and SNMP continue to work. The engineer wants to confirm which traffic class is being dropped. Which action should the engineer take?

A.Run show ip bgp summary to check the BGP neighbor state and reset the sessions.
B.Capture traffic on the control plane interface using an Embedded Packet Capture with a BGP filter.
C.Enable debug ip ssh and debug snmp packets to compare with BGP debugs.
D.Review CoPP class-map and policy-map statistics with show policy-map control-plane to identify the class with drops.
AnswerD

The show policy-map control-plane command displays per-class packet and byte counters, including dropped packets, for the control plane policy. Since BGP is flapping while SSH and SNMP work, inspecting these counters reveals which class is exceeding its rate and dropping traffic, directly identifying the misconfigured class.

Why this answer

CoPP applies a policy-map to the control plane and maintains per-class statistics. Because SSH and SNMP still function while BGP flaps, the BGP class is likely exceeding its configured rate. Viewing the control-plane policy-map counters shows which class has drops, pinpointing the class that needs a higher rate or burst value.

Exam trap

The trap here is troubleshooting the BGP neighbor state instead of inspecting the CoPP policy-map counters that actually reveal which traffic class is being policed and dropped.

1481
MCQmedium

A network engineer is configuring 802.1X on a Cisco Catalyst 9300 switch for a wired network. The engineer wants to allow devices that do not support 802.1X (e.g., printers) to still access the network using MAB (MAC Authentication Bypass). The engineer configures the interface with 'authentication port-control auto', 'dot1x pae authenticator', and 'mab'. However, after connecting a printer, the switch logs show 'MAB failed' repeatedly. The printer's MAC address is in the RADIUS server database. What is the most likely cause?

A.The RADIUS server is not configured to accept MAC addresses in the format sent by the switch (e.g., with dots or colons).
B.The switch is not configured with 'dot1x timeout tx-period' to initiate MAB.
C.The interface is configured as 'switchport mode trunk', which does not support MAB.
D.The printer is not responding to EAP-Request/Identity packets.
AnswerA

During MAC Authentication Bypass, the switch uses the source MAC address as both username and password for the RADIUS request. Cisco IOS typically formats this as dotted hex (e.g., xxxx.xxxx.xxxx) or sometimes hyphenated (e.g., xx-xx-xx-xx-xx-xx). If the RADIUS server's user database or identity store is configured to accept colon-separated or concatenated format only, the authentication fails because the credentials do not match any expected entry. This is a classic configuration mismatch, not a protocol or timer issue.

Why this answer

The most likely cause is that the RADIUS server expects the MAC address in a specific format (e.g., with colons or hyphens), but the switch sends it in a different format (e.g., with dots or no separators). MAB works by the switch sending the printer's MAC address as the username and password in a RADIUS Access-Request. If the format does not match the server's database, authentication fails, even though the MAC is present.

This is a common configuration mismatch between Cisco switches and RADIUS servers.

Exam trap

Cisco often tests the misconception that MAB requires EAP or that the client must respond to EAP packets, but MAB is a non-EAP method that bypasses the 802.1X supplicant entirely.

How to eliminate wrong answers

Option B is wrong because 'dot1x timeout tx-period' controls the interval between EAP-Request/Identity retransmissions, which is irrelevant to MAB; MAB does not use EAP. Option C is wrong because MAB is supported on trunk interfaces; the switchport mode does not inherently block MAB, though 802.1X may behave differently on trunks. Option D is wrong because MAB does not require the printer to respond to EAP packets; the switch initiates MAB after detecting the link and sends the MAC to the RADIUS server without any EAP exchange with the client.

1482
MCQmedium

An engineer is troubleshooting an EIGRP convergence issue in a network with redundant links. The engineer notices that when a primary link fails, the backup link takes over immediately, but the routing table shows the route with a higher metric. The engineer wants to ensure that the backup link is used only when the primary fails, and that traffic is not load-balanced. The engineer has configured 'variance 2' on all routers. What is the most likely effect of this configuration?

A.The variance 2 command causes EIGRP to install only the best metric route, so the backup link is not used.
B.The variance 2 command causes EIGRP to install both the primary and backup routes, resulting in unequal-cost load balancing.
C.The variance 2 command has no effect on route installation; it only affects the feasible successor selection.
D.The variance 2 command is used for equal-cost load balancing only.
AnswerB

With variance 2, the primary route's feasible distance is doubled, so any feasible successor whose composite metric falls within twice that value is installed alongside the primary. This installs both routes and enables unequal-cost load balancing, meaning packets are distributed across the two links in proportion to the inverse of their metrics. For an engineer who wants the primary link to carry 100% of traffic unless it fails, this variance setting is counterproductive because the backup link will be actively used, which is exactly the unintended behavior described.

Why this answer

The 'variance 2' command in EIGRP allows the router to install multiple routes to the same destination network in the routing table, even if their metrics are not equal, as long as the metric of the alternate route is within the variance multiplier (2x) of the best metric (the feasible distance). Since the backup link has a higher metric but is within the variance, EIGRP installs both routes, causing unequal-cost load balancing. This explains why the backup link is actively used for traffic, contrary to the engineer's desire to use it only as a failover.

Exam trap

Cisco often tests the misconception that 'variance' only affects feasible successor selection or that it is used for equal-cost load balancing, when in fact it directly controls the installation of multiple unequal-cost paths into the routing table.

How to eliminate wrong answers

Option A is wrong because the 'variance 2' command does not restrict EIGRP to only the best metric route; it explicitly allows additional routes with higher metrics to be installed. Option C is wrong because the variance command directly affects route installation by allowing multiple routes into the routing table, not just feasible successor selection (which is controlled by the feasibility condition and the 'metric' command). Option D is wrong because the variance command is specifically designed for unequal-cost load balancing, not equal-cost load balancing (which is the default behavior without variance).

1483
MCQmedium

A network engineer is designing a new data center leaf-spine fabric using Cisco Nexus 9000 switches. The design requires that the fabric automatically discover the IP addresses of remote VTEPs participating in a VXLAN EVPN deployment. Which control-plane protocol should be enabled on the leaf switches to provide this dynamic VTEP discovery?

A.OSPFv3 in the underlay network
B.Protocol Independent Multicast (PIM) sparse mode
C.Cisco Fabric Services (CFS) over the management network
D.Multiprotocol BGP with EVPN address family
AnswerD

MP-BGP with the EVPN address family is the control plane for VXLAN EVPN. It advertises Type-2 and Type-3 routes that carry VTEP IP addresses, enabling automatic discovery of remote VTEPs. Without it, VTEPs must be statically configured, losing the dynamic fabric benefits of EVPN.

Why this answer

VXLAN EVPN uses MP-BGP with the EVPN address family as the overlay control plane. It advertises Type-2 (MAC/IP) and Type-3 (IMET) routes, allowing leaf switches to learn remote VTEP IP addresses automatically. This eliminates the need for static VTEP configuration and supports efficient multi-tenancy and mobility.

Exam trap

The trap here is confusing the underlay routing protocol (such as OSPF or IS-IS) with the overlay control plane that actually carries VTEP reachability and MAC/IP bindings.

1484
Multi-Selecthard

A network engineer is deploying a Cisco SD-WAN solution using vManage, vSmart, and vBond controllers. Which two statements accurately describe the roles of these controllers in the SD-WAN overlay? (Choose two.)

Select 2 answers
A.vBond controllers are responsible for distributing routing information and policies to vEdge routers.
B.vSmart controllers are responsible for the data plane forwarding and encryption of traffic between vEdge routers.
C.vBond orchestrates the initial authentication and brings up the control plane connections between vEdge routers and vSmart controllers.
D.vSmart controllers establish permanent data plane tunnels with each vEdge router for traffic forwarding.
E.vManage provides a centralized management plane for configuration, monitoring, and troubleshooting of the SD-WAN fabric.
AnswersC, E

vBond acts as the orchestrator in Cisco SD-WAN. It is the first point of contact for vEdge routers. It authenticates the routers and provides them with the IP addresses of the vSmart controllers and vManage. vBond also facilitates the establishment of control plane connections (DTLS) between vEdge routers and vSmart controllers. It does not participate in the data plane or routing decisions. Its primary role is onboarding and orchestration.

Why this answer

In Cisco SD-WAN, vBond orchestrates initial authentication and control plane connectivity, while vManage provides centralized management. vSmart handles control plane routing and policy distribution, and vEdge routers handle data plane forwarding. The correct statements are about vBond's orchestration role and vManage's management role.

Exam trap

The trap here is confusing the control plane and data plane responsibilities of vSmart and vBond, or assuming that vSmart handles data forwarding.

1485
Matchingmedium

Drag and drop each SPAN type on the left to its correct scope description on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Mirrors traffic on the same switch where the source and destination ports reside.

Mirrors traffic to a destination on a different switch using a dedicated VLAN.

Mirrors traffic to a destination reachable via Layer 3 using GRE encapsulation.

Receives the mirrored traffic and should be configured as a monitor session port.

The port whose traffic is being copied for monitoring.

Why these pairings

Local SPAN mirrors traffic on the same switch; RSPAN extends mirroring across switches using a dedicated VLAN; ERSPAN encapsulates mirrored packets in GRE for routing over Layer 3 networks.

1486
Drag & Dropmedium

Drag and drop the steps of IP SLA with threshold and reaction configuration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, define the IP SLA operation with a type and target. Then set the threshold values for the monitored metric. Next, configure the reaction to trigger on threshold violation.

After that, schedule the operation to start. Finally, verify the configuration to ensure it works.

1487
MCQmedium

A network engineer is developing a Python script to retrieve interface statistics from a Cisco IOS XE device using RESTCONF. The script sends a GET request to the URI https://10.1.1.1/restconf/data/ietf-interfaces:interfaces. The device returns a 401 Unauthorized error. The engineer verifies that the RESTCONF API is enabled and the URI is correct. Which action should the engineer take to resolve this issue?

A.Configure the HTTP client to use Basic authentication with valid user credentials.
B.Enable the NETCONF protocol on the device using the netconf-yang command.
C.Change the request method from GET to POST to retrieve interface statistics.
D.Add the header 'Content-Type: application/yang-data+json' to the request.
AnswerA

RESTCONF requires authentication, and a 401 Unauthorized indicates missing or invalid credentials. Cisco IOS XE supports Basic authentication over HTTPS, so the engineer must include a valid username and password in the request headers. This directly addresses the authentication failure without altering device configuration.

Why this answer

A 401 Unauthorized response from a RESTCONF API indicates that the request lacks valid authentication credentials. Cisco IOS XE RESTCONF uses HTTP Basic authentication, so the client must include an Authorization header with a base64-encoded username and password. Without this, the device rejects the request regardless of the URI or method.

Therefore, configuring Basic authentication is the correct solution.

Exam trap

The trap here is assuming that enabling NETCONF or adjusting headers will fix an authentication error, when the real issue is missing credentials.

1488
MCQhard

A network engineer runs the following command on Router R1: R1# show ip eigrp traffic EIGRP-IPv4 Traffic Statistics for AS(100) Hellos sent/received: 1000/950 Updates sent/received: 45/40 Queries sent/received: 2/3 Replies sent/received: 3/2 Acks sent/received: 50/48 Input queue high water mark: 1 Input queue depth: 0 Total packets sent: 1100 Total packets received: 1043 Based on this output, what can be concluded?

A.The router has experienced many route flaps.
B.The network is stable with few topology changes.
C.The router is using EIGRP stub to suppress queries.
D.There is a high packet loss on the network.
AnswerB

EIGRP sends Queries when a feasible successor is lost and it must ask neighbors for alternate paths; Replies are the responses. Low values for both show that the topology has not changed often. Stable network conditions are also reflected by low update counts and no excessive retransmissions, meaning the EIGRP adjacency has remained healthy with few convergence events.

Why this answer

The output shows a very low number of EIGRP Queries (2 sent, 3 received) and Replies (3 sent, 2 received), which indicates that the network has experienced very few topology changes. A stable EIGRP network with minimal route flaps will have a high ratio of Hellos to Updates/Queries, as seen here (1000 Hellos vs. 45 Updates). Therefore, the network is stable with few topology changes, making option B correct.

Exam trap

Cisco often tests the misconception that a high number of Hellos indicates instability or that a small difference between sent and received packets automatically means packet loss, when in fact EIGRP Hellos are sent unreliably (multicast) and may be lost without retransmission, so a small discrepancy is normal.

How to eliminate wrong answers

Option A is wrong because route flaps would generate a high number of Updates and Queries, but the output shows only 45 Updates sent and 2 Queries sent, which is very low. Option C is wrong because the output does not show any evidence of EIGRP stub configuration; stub routers suppress queries entirely, but here queries are still being sent and received (2 sent, 3 received), indicating stub is not in use. Option D is wrong because packet loss would be reflected in a mismatch between sent and received packets (e.g., Hellos sent 1000 vs. received 950 is a 5% difference, which is normal for EIGRP due to timing and multicast delivery, not indicative of high loss; total sent 1100 vs. received 1043 is a 5.2% difference, which is typical in a healthy network).

1489
MCQmedium

An engineer is troubleshooting multicast performance issues. The network uses PIM sparse mode with a static RP. The engineer notices that the multicast traffic from a source to a group is taking a suboptimal path, causing high latency. The engineer checks the multicast routing table on the last-hop router and sees that the (S,G) entry has an incoming interface that is not the shortest path to the source. What is the most likely reason for this suboptimal path?

A.The last-hop router has not yet switched to the SPT.
B.The RP is not configured as the DR on its segment.
C.The multicast source is using a different group address.
D.The last-hop router has a higher metric to the source than to the RP.
AnswerA

In Protocol Independent Multicast sparse-mode, the last-hop router initially joins the shared tree toward the RP. After receiving the first data packet from the source via the RP, it should immediately send an (S,G) join toward the source to switch to the shortest path tree. If that switchover hasn't occurred—commonly because the spt-threshold is set to infinity—traffic continues to be forwarded along the shared tree, explaining why the packet path still goes through the RP.

Why this answer

In PIM sparse mode, the last-hop router initially receives multicast traffic via the shared tree (RP) and then switches to the shortest path tree (SPT) toward the source once the traffic rate exceeds a threshold (default 0 kbps in Cisco IOS). If the (S,G) entry shows an incoming interface that is not the shortest path to the source, it indicates the router has not yet performed the SPT switchover, so it is still using the RP-based path, which may be suboptimal.

Exam trap

Cisco often tests the misconception that a suboptimal path is caused by RP placement or metric issues, when in fact the core concept is the SPT switchover mechanism in PIM sparse mode.

How to eliminate wrong answers

Option B is wrong because the DR (Designated Router) role is relevant on multi-access networks for forwarding multicast traffic to the RP, but it does not affect the last-hop router's path selection toward the source; the suboptimal path is due to SPT switchover timing, not DR configuration. Option C is wrong because if the source used a different group address, the (S,G) entry would not exist for the group in question, and the engineer would see no multicast routing entry or a different group; the issue is path selection, not group mismatch. Option D is wrong because a higher metric to the source than to the RP is the normal condition that triggers the SPT switchover—if the metric to the source is lower, the router would already be on the SPT; the suboptimal path occurs because the router has not yet switched, not because of metric comparison.

1490
MCQeasy

A network administrator needs to configure a Cisco IOS switch to authenticate users against a RADIUS server before granting access to a switchport. The requirement is that if the RADIUS server becomes unreachable, the port should fall back to the configured access VLAN and not shut down. Which set of commands accomplishes this?

A.aaa new-model aaa authentication dot1x default group radius dot1x system-auth-control interface GigabitEthernet1/0/1 authentication port-control auto authentication host-mode multi-auth authentication event server dead action authorize vlan 10
B.aaa new-model aaa authentication dot1x default group radius dot1x system-auth-control interface GigabitEthernet1/0/1 authentication port-control auto
C.aaa new-model aaa authentication dot1x default group radius dot1x system-auth-control interface GigabitEthernet1/0/1 authentication port-control auto authentication open authentication event fail action authorize vlan 20
D.aaa new-model aaa authentication login default group radius local dot1x system-auth-control interface GigabitEthernet1/0/1 authentication port-control force-authorized
AnswerA

This configuration enables 802.1X with RADIUS authentication, sets the port to auto mode, allows multiple authenticated hosts, and uses the authentication event server dead action authorize vlan 10 command. When the RADIUS server is unreachable, the port is placed in the specified access VLAN (10) rather than shutting down or remaining unauthorized, exactly matching the fallback requirement.

Why this answer

To authenticate users against RADIUS and fall back to a specific access VLAN when the server is unreachable, the switch needs 802.1X enabled globally, RADIUS as the authentication method, port-control auto on the interface, and the authentication event server dead action authorize vlan command. That command keeps the port usable in the designated VLAN during server outages.

Exam trap

The trap here is assuming that enabling 802.1X with port-control auto alone provides fallback behavior, when a server-dead action must be explicitly configured to authorize the port into an access VLAN.

1491
MCQhard

A network designer is planning a QoS policy for a campus network that carries voice, video, and critical business applications. The design must ensure that voice traffic receives priority treatment with minimal latency and jitter, while preventing starvation of other traffic. Which queuing mechanism should be used on the egress interfaces to meet these requirements?

A.Class-Based Weighted Fair Queuing (CBWFQ)
B.Weighted Random Early Detection (WRED)
C.First-In, First-Out (FIFO) queuing
D.Low Latency Queuing (LLQ)
AnswerD

LLQ provides a strict priority queue for voice traffic while also supporting other queues with guaranteed bandwidth. This ensures voice gets minimal latency and jitter, and the policer on the priority queue prevents starvation of other traffic. It is the recommended mechanism for meeting strict voice requirements in a campus QoS design.

Why this answer

Low Latency Queuing (LLQ) combines a strict priority queue with class-based weighted fair queuing for other traffic. The priority queue is typically used for voice, ensuring minimal delay and jitter, while a policer limits its bandwidth to prevent starvation of other classes. This makes LLQ the correct choice for meeting strict voice QoS requirements.

Exam trap

The trap here is selecting CBWFQ because it provides bandwidth guarantees, but it lacks the strict priority scheduling that voice traffic requires to minimize latency and jitter.

1492
MCQmedium

In BGP best path selection, which of the following is compared first?

A.Highest weight
B.Highest local preference
C.Shortest AS-path
D.Lowest MED
AnswerA

Weight is a Cisco-proprietary attribute evaluated before all other BGP path attributes, so the route with the highest weight wins immediately. This satisfies the stem's requirement for the first comparison in the best path algorithm, preceding local preference, AS path length and origin.

Why this answer

BGP best path selection begins by comparing the weight attribute, which is Cisco-proprietary and local to the router. The path with the highest weight is preferred first, making option A correct. Weight is evaluated before any other BGP attribute, including local preference, AS-path length, and MED.

Exam trap

Cisco often tests the exact order of BGP path selection attributes, and the trap here is that candidates mistakenly think local preference or AS-path length is the first comparison, because those are more commonly discussed in multi-AS designs, but weight always comes first in Cisco's implementation.

How to eliminate wrong answers

Option B is wrong because highest local preference is compared after weight, not first. Option C is wrong because shortest AS-path is the third attribute compared, after weight and local preference. Option D is wrong because lowest MED is compared after AS-path length (and other attributes like origin type) in the BGP decision process.

1493
MCQhard

A network engineer is deploying Cisco ACI in a data center. The engineer needs to configure a bridge domain that allows traffic to be routed between two EPGs that are in different subnets. Which ACI object must be configured to enable inter-subnet routing within the bridge domain?

A.Bridge domain with unicast routing enabled and subnets configured
B.Subnet under the bridge domain with a scope of 'Advertised Externally'
C.VRF
D.Contract
AnswerA

To enable inter-subnet routing within a bridge domain, you must configure the bridge domain with unicast routing enabled and define the subnets on the bridge domain. This allows the ACI fabric to route between EPGs in different subnets that are part of the same bridge domain.

Why this answer

Inter-subnet routing in Cisco ACI is enabled by configuring a bridge domain with unicast routing turned on and defining the necessary subnets. This allows the fabric to act as the default gateway for endpoints in those subnets and route traffic between them, even if they are in different EPGs.

Exam trap

The trap here is assuming that a contract or VRF alone enables inter-subnet routing, when the bridge domain must have unicast routing enabled and subnets defined.

1494
MCQeasy

A network administrator is configuring a new Cisco Catalyst switch and needs to ensure that the management VLAN interface is reachable from a remote subnet. The switch is at its default configuration. Which command must be applied to the management VLAN interface to allow remote management from a different subnet?

A.ip name-server 10.1.1.1
B.ip route 0.0.0.0 0.0.0.0 10.1.1.1
C.ip routing
D.ip default-gateway 10.1.1.1
AnswerD

The 'ip default-gateway' command is used on a Layer 2 switch to specify a default gateway for management traffic when the switch is not running a routing protocol. This allows the management VLAN interface to communicate with remote subnets, enabling remote management from a different subnet.

Why this answer

On a Layer 2 switch, the management VLAN interface requires a default gateway to communicate with devices on other subnets. The 'ip default-gateway' command specifies that gateway, allowing the switch to be managed remotely from a different subnet without enabling full IP routing.

Exam trap

The trap here is confusing the default gateway command for Layer 2 switches with the default route command used on Layer 3 devices, which leads to incorrect configuration on a switch.

1495
Multi-Selecthard

A network engineer is configuring a new Cisco IOS router for OSPFv2 in a multi-area OSPF domain. The router will be an Area Border Router (ABR) connecting Area 0 and Area 10. The engineer must ensure that the router correctly summarizes routes from Area 10 into Area 0 and that it does not become a designated router (DR) on any broadcast network. Which two configuration steps are required to meet these requirements? (Choose two.)

Select 2 answers
A.Set the OSPF interface priority to 0 on all interfaces that participate in OSPF.
B.Configure the router with the 'area 10 stub' command under the OSPF routing process.
C.Configure the router with the 'auto-cost reference-bandwidth 100000' command under the OSPF routing process.
D.Configure the router with the 'area 10 range 10.10.0.0 255.255.0.0' command under the OSPF routing process.
E.Configure the router with the 'passive-interface default' command under the OSPF routing process.
AnswersA, D

Setting the OSPF interface priority to 0 prevents the router from being elected as a designated router (DR) or backup designated router (BDR) on broadcast networks. This meets the requirement that the router does not become a DR. The priority is configured per interface with the 'ip ospf priority 0' command under the interface configuration.

Why this answer

To summarize routes from Area 10 into Area 0, the ABR must use the 'area 10 range' command. To prevent the router from becoming a DR, the OSPF interface priority must be set to 0 on all participating interfaces. These two steps directly satisfy the requirements.

The other options either configure stub areas, alter cost calculations, or suppress OSPF on interfaces, none of which meet the stated goals.

Exam trap

The trap here is assuming that configuring an area as stub or changing the reference bandwidth will influence summarization or DR election, when these are unrelated OSPF features.

1496
MCQmedium

Given the configuration: interface Port-channel1 switchport mode trunk switchport trunk allowed vlan 10-20 ! interface GigabitEthernet0/1 switchport mode trunk channel-group 1 mode passive ! interface GigabitEthernet0/2 switchport mode trunk channel-group 1 mode passive What is missing for this EtherChannel to form with a neighbor that uses LACP active?

A.The member interfaces must also have the 'switchport trunk allowed vlan 10-20' command.
B.The port-channel interface must be configured with 'channel-group 1' to associate the member ports.
C.Nothing is missing; the configuration is valid and the EtherChannel will form with the neighbor.
D.The member interfaces must use LACP active mode to form the channel.
AnswerC

This option is correct. The member interfaces already have the necessary physical and logical configuration (trunk mode, same VLAN allowed list inherited from the port-channel, and LACP mode), and the port-channel interface is created automatically when the member interfaces are configured with channel-group. The neighbor is presumably configured compatibly, so the EtherChannel will successfully form. Nothing is missing from the configuration.

Why this answer

The configuration is valid because LACP uses a negotiation system where one side must be in active mode and the other in passive mode to form an EtherChannel. Here, the neighbor is configured with LACP active, and the local member interfaces are configured with 'channel-group 1 mode passive', which is the correct counterpart. The 'switchport trunk allowed vlan' command is only needed on the port-channel interface, not on the member interfaces, as the port-channel interface inherits and propagates the VLAN list to the member ports.

Exam trap

Cisco often tests the misconception that both sides must use the same LACP mode (active/active or passive/passive), when in fact LACP requires one side to be active and the other can be passive to successfully form an EtherChannel.

How to eliminate wrong answers

Option A is wrong because the 'switchport trunk allowed vlan' command is configured on the port-channel interface, and the member interfaces automatically inherit this configuration; applying it to the member interfaces is unnecessary and can cause inconsistency. Option B is wrong because the 'channel-group 1' command is already applied to the member interfaces (GigabitEthernet0/1 and 0/2), which dynamically creates the port-channel interface; no additional 'channel-group' command is required on the port-channel interface itself. Option D is wrong because LACP passive mode is the correct counterpart to a neighbor using LACP active; both sides do not need to be active, as LACP will negotiate and form the channel with one side active and the other passive.

1497
MCQmedium

A network architect is designing a Cisco SD-WAN fabric for a company with 50 branch sites. The company wants to ensure that business-critical traffic (such as VoIP and ERP) is prioritized over best-effort traffic (such as guest internet) across the overlay. The architect plans to use the vManage controller to define an application-aware routing policy. Which component of the Cisco SD-WAN solution is responsible for enforcing the application-aware routing policy on the data plane?

A.vManage
B.vEdge router
C.vBond orchestrator
D.vSmart controller
AnswerB

The vEdge router (or cEdge in Cisco SD-WAN) is the data plane device that actually enforces application-aware routing policies. It inspects traffic, classifies applications, and applies the forwarding decisions defined in the policy. Since the question asks where the policy is enforced, the vEdge router is the correct component because it sits in the forwarding path and executes the policy.

Why this answer

In Cisco SD-WAN, application-aware routing policies are defined centrally on vManage, but they are enforced by the data plane devices—vEdge routers (or cEdge routers). These devices inspect traffic, identify applications, and apply the policy actions such as preferred path or SLA-based forwarding. The vSmart controller distributes policy information, but it does not process user traffic.

Therefore, the vEdge router is the correct answer.

Exam trap

The trap here is assuming that the management or control plane component (vManage or vSmart) enforces the policy, when in fact enforcement happens at the data plane edge device.

1498
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip sla summary IPSLAs Latest Operation Summary Codes: * active, ^ inactive, ~ pending ID Type Destination Stats Return Code Last 1 icmp-echo 192.168.1.10 Success OK 1 2 icmp-echo 192.168.1.20 Success OK 2 3 udp-jitter 192.168.1.30 Success OK 3 *4 icmp-echo 192.168.1.40 Success OK 10 Based on this output, what can be concluded?

A.All IP SLA operations are active.
B.IP SLA operation 4 is currently active.
C.IP SLA operation 3 has failed.
D.IP SLA operation 1 has the highest round-trip time.
AnswerB

Operation ID 4 is the only entry in the output that carries an asterisk (*), and in Cisco IOS IP SLA, that symbol denotes an operation that is currently executing active probes. All other entries show no such marker, so they are not in an active state at this moment. This is a direct and unambiguous indication that operation 4 is the sole active IP SLA operation.

Why this answer

The asterisk (*) in the first column of the 'show ip sla summary' output indicates that IP SLA operation 4 is currently active. The other operations (IDs 1, 2, and 3) have no asterisk, meaning they are inactive. The 'Return Code' column shows 'OK' for all operations, confirming they completed successfully, but only operation 4 is actively running.

Exam trap

Cisco often tests the misinterpretation of the 'Last' column as round-trip time (RTT) rather than the time since the last operation, leading candidates to incorrectly compare values as RTT.

How to eliminate wrong answers

Option A is wrong because only operation 4 has an asterisk (*) next to its ID, indicating it is active; operations 1, 2, and 3 are inactive (no asterisk). Option C is wrong because operation 3 has a 'Return Code' of 'OK', meaning it succeeded, not failed. Option D is wrong because the 'Last' column shows the time in seconds since the last operation completed, not the round-trip time (RTT); operation 1 has a 'Last' value of 1 second, which is the lowest, not the highest.

1499
Drag & Dropmedium

Drag and drop the steps of Syslog severity filtering and rate-limiting configuration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, enable logging on the device (A). Second, set the logging severity level (B). Third, configure rate-limit messages (C).

Fourth, specify the logging buffer size (D). Finally, display logging statistics to verify (E).

1500
Multi-Selectmedium

Which two statements about the Cisco QoS trust boundary are true? (Choose two.)

Select 2 answers
A.The trust boundary can be set at the access layer switch port connected to an IP phone.
B.The 'mls qos trust cos' command configures the interface to trust the Layer 2 CoS value.
C.By default, all Cisco switch interfaces trust the incoming CoS or DSCP marking.
D.The trust boundary is always located at the distribution layer switch.
E.When a PC is connected to a switch port, the switch automatically trusts the DSCP value from the PC.
AnswersA, B

Extending the trust boundary to the access switch port facing an IP phone is valid because the phone marks CoS or DSCP for attached devices, letting the switch trust those markings rather than reclassify. This satisfies the stem's requirement for a true trust boundary location, since classification occurs at the network edge.

Why this answer

Option A is correct because the trust boundary is typically established at the access layer switch port where an IP phone connects, since the phone can mark voice traffic with CoS/DSCP and the switch can be configured to trust those markings from the phone while untrusting traffic from an attached PC. Option B is correct because the interface-level command 'mls qos trust cos' explicitly configures the port to trust the incoming Layer 2 CoS field, allowing the switch to honor the CoS value for QoS classification and queuing. Option C is incorrect because Cisco switch interfaces do not trust incoming CoS or DSCP by default; they typically trust nothing (or default to a best-effort/CoS 0 behavior) until trust is explicitly configured.

Option D is incorrect because the trust boundary is not always at the distribution layer; it is commonly placed at the access layer, though it can be extended to other points depending on design. Option E is incorrect because a switch does not automatically trust DSCP markings from an attached PC; trust must be explicitly configured, and PC traffic is generally untrusted by default.

Exam trap

The trap here is the assumption that Cisco switches trust QoS markings out of the box — many candidates pick option C because they confuse 'QoS is enabled' with 'QoS trust is configured', when in fact trust is disabled by default on all access ports.

Page 19

Page 20 of 26

Page 21