Courseiva

ENCOR 350-401 (350-401) — Questions 1501–1575

1923 questions total · 26pages · All types, answers revealed

Page 20

Page 21 of 26

Page 22
1501
Matchingmedium

Drag and drop each STP port state on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Discards frames and listens for BPDUs

Listens for BPDUs only, no MAC learning

Learns MAC addresses but does not forward frames

Forwards frames and learns MAC addresses

Administratively shut down, no participation

Why these pairings

Blocking discards frames and listens for BPDUs; Listening listens for BPDUs only; Learning learns MAC addresses but does not forward; Forwarding sends and receives frames; Disabled is administratively down.

1502
MCQeasy

A network technician is configuring a new Cisco switch and needs to assign the management IP address to VLAN 1. Which command sequence is correct?

A.interface vlan 1; ip address 10.1.1.1 255.255.255.0; no shutdown
B.ip address 10.1.1.1 255.255.255.0; interface vlan 1; no shutdown
C.vlan 1; ip address 10.1.1.1 255.255.255.0; no shutdown
D.interface gigabitethernet0/1; ip address 10.1.1.1 255.255.255.0; no shutdown
AnswerA

To assign an IP address to the management VLAN, you enter interface configuration mode for VLAN 1 using 'interface vlan 1', then assign the IP address with 'ip address', and ensure the interface is up with 'no shutdown'. This is the standard method for configuring a management IP on a Cisco switch. VLAN 1 is the default management VLAN.

Why this answer

The correct method to assign a management IP address on a Cisco switch is to create or use the VLAN 1 interface (SVI) and assign the IP address there. The sequence 'interface vlan 1', then 'ip address', then 'no shutdown' is standard. Other options either target physical interfaces or use incorrect command modes.

Exam trap

The trap here is confusing VLAN configuration mode with VLAN interface configuration mode; IP addresses are assigned to the SVI, not the VLAN database.

1503
Matchingmedium

Drag and drop each PIM mode on the left to its matching traffic distribution method on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Uses explicit join messages to build a shared tree

Floods multicast traffic on all interfaces, then prunes unwanted branches

Builds shortest path trees from source to receivers

Uses a shared tree with no source-specific state

Operates in sparse mode by default, but allows dense mode per group

Why these pairings

PIM Sparse Mode uses explicit join to build a shared tree; Dense Mode floods initially then prunes; Source-Specific Mode uses shortest path trees from source; Bidirectional PIM uses a shared tree with no source-specific state.

1504
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor a campus network. The administrator notices that a particular client device is experiencing poor voice quality. Which Cisco DNA Center Assurance feature should be used to analyze the issue and determine the root cause?

A.Network Health Dashboard
B.Client 360
C.Path Trace
D.Application Health Dashboard
AnswerB

Client 360 provides a comprehensive view of a specific client's experience, including onboarding, connectivity, and application performance. It includes detailed metrics such as voice quality (MOS), packet loss, and latency. In this scenario, Client 360 would allow the administrator to drill down into the client's voice traffic and identify the root cause of poor voice quality.

Why this answer

Client 360 in Cisco DNA Center Assurance offers detailed insights into a specific client's network experience, including voice quality metrics like MOS, jitter, and packet loss. By using Client 360, the administrator can quickly identify whether the poor voice quality is due to network congestion, wireless interference, or other factors, enabling targeted remediation.

Exam trap

The trap here is confusing the Application Health Dashboard with Client 360; the former provides application-level health, not per-client voice quality analysis.

1505
MCQhard

A network engineer runs the following command on Switch SW7: SW7# show interfaces port-channel 1 Port-channel1 is up, line protocol is up (connected) Hardware is EtherChannel, address is aaaa.bbbb.cccc (bia aaaa.bbbb.cccc) Description: Link to Core Internet address is 192.168.1.1/30 MTU 1500 bytes, BW 2000000 Kbit/sec, DLY 10 usec, reliability 255/255, txload 1/255, rxload 1/255 Encapsulation ARPA, loopback not set Keepalive set (10 sec) Full-duplex, 1000Mb/s, link type is auto, media type is unknown input flow-control is off, output flow-control is unsupported ARP type: ARPA, ARP Timeout 04:00:00 Last input 00:00:00, output 00:00:00, output hang never Last clearing of "show interface" counters never Input queue: 0/2000/0/0 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue: 0/40 (size/max) 5 minute input rate 1000 bits/sec, 2 packets/sec 5 minute output rate 500 bits/sec, 1 packets/sec 12345 packets input, 1234567 bytes, 0 no buffer Received 0 broadcasts (0 IP multicasts) 0 runts, 0 giants, 0 throttles 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored 0 watchdog, 0 multicast, 0 pause input 0 input packets with dribble condition detected 67890 packets output, 9876543 bytes, 0 underruns 0 output errors, 0 collisions, 2 interface resets 0 unknown protocol drops 0 babbles, 0 late collision, 0 deferred 0 lost carrier, 0 no carrier, 0 pause output 0 output buffer failures, 0 output buffers swapped out Based on this output, what can be concluded?

A.The port-channel is a Layer 2 interface because it has an IP address.
B.The bandwidth of 2 Gbps suggests that two 1 Gbps links are aggregated.
C.The interface is experiencing input errors due to CRC errors.
D.The port-channel is operating at half-duplex.
AnswerB

The bandwidth of 2 Gbps (shown as 2000000 Kbit/sec) correctly suggests that two 1 Gbps links are aggregated into this EtherChannel. In an EtherChannel, the logical interface bandwidth is the sum of the bandwidths of all member links, and with two full-duplex 1 Gbps member ports, the combined bandwidth becomes 2 Gbps. This aligns with the expected output for a two-member PortChannel and confirms the aggregation is active.

Why this answer

The output shows a bandwidth of 2000000 Kbit/sec, which equals 2 Gbps. Since each individual link in the EtherChannel is operating at 1000 Mb/s (1 Gbps) and full-duplex, the total bandwidth of 2 Gbps indicates that two 1 Gbps links have been successfully aggregated into the Port-channel 1. This is a direct conclusion from the 'BW 2000000 Kbit/sec' field in the show interfaces port-channel output.

Exam trap

Cisco often tests the misconception that a port-channel with an IP address must be a Layer 2 interface, but in reality, a port-channel can be configured as a Layer 3 routed interface (no switchport) and still have an IP address, so candidates should not confuse Layer 2 vs Layer 3 based solely on the presence of an IP address.

How to eliminate wrong answers

Option A is wrong because having an IP address does not make an interface Layer 2; in fact, a Layer 3 interface (routed port) can have an IP address, while a Layer 2 port-channel would not typically have an IP address unless it is a switched virtual interface (SVI) or a routed port-channel. Option C is wrong because the output explicitly shows '0 input errors' and '0 CRC', so there are no input errors or CRC errors. Option D is wrong because the output clearly states 'Full-duplex, 1000Mb/s', so the port-channel is operating at full-duplex, not half-duplex.

1506
MCQmedium

An architect is designing an SD-Access fabric for a campus network that must support dynamic endpoint grouping based on user identity and device type. The design must minimize manual policy configuration and allow the fabric to enforce access policies at the edge. Which combination of components and protocols is required to meet these requirements?

A.Cisco ISE for policy management, LISP for control plane, VXLAN for data plane, and Cisco TrustSec for SGT-based enforcement
B.Cisco ISE for policy management, OSPF for control plane, GRE for data plane, and ACLs for enforcement
C.Cisco ISE for policy management, BGP for control plane, MPLS for data plane, and VLANs for enforcement
D.Cisco ISE for policy management, LISP for data plane, VXLAN for control plane, and 802.1X for enforcement
AnswerA

In Cisco SD-Access, ISE authenticates users and assigns Scalable Group Tags (SGTs) to define policy; LISP serves as the overlay control plane, decoupling routing from endpoint location to support host mobility and scale. VXLAN is the data plane encapsulation that transparently carries traffic and embeds the SGT in its header for group-based enforcement at fabric edge nodes. TrustSec uses those SGTs rather than IP addresses to enforce security policies consistently across the fabric, which is exactly the intended role of each protocol in the architecture.

Why this answer

SD-Access uses Cisco ISE as the policy engine to define user/device-based policies, LISP as the control plane for endpoint-to-location mapping and mobility, VXLAN as the data plane for overlay encapsulation, and Cisco TrustSec for SGT-based enforcement at the edge. This combination enables dynamic endpoint grouping without manual ACLs, as SGTs are propagated via VXLAN Group Policy Option (GPO) and enforced by the fabric edge switches.

Exam trap

Cisco often tests the specific roles of LISP (control plane) and VXLAN (data plane) in SD-Access, and the trap here is confusing their functions or assuming that traditional protocols like OSPF/BGP or ACLs/VLANs can replace the overlay control and policy enforcement mechanisms.

How to eliminate wrong answers

Option B is wrong because OSPF is a routing protocol used in the underlay, not the SD-Access control plane; GRE lacks the scalability and group-based policy support of VXLAN, and ACLs require manual configuration, contradicting the requirement to minimize manual policy. Option C is wrong because BGP is not the SD-Access control plane (LISP is), MPLS is not used as the data plane in SD-Access (VXLAN is), and VLANs enforce segmentation at Layer 2, not dynamic SGT-based policies. Option D is wrong because LISP is the control plane, not the data plane; VXLAN is the data plane, not the control plane; and 802.1X provides authentication but not the enforcement mechanism for SGT-based policies—TrustSec or SGT tagging is required for enforcement.

1507
MCQhard

A network engineer runs the following command on Router R2: R2# show vrf detail VRF CUSTOMER-B (VRF Id = 1); default RD 65000:1; default VPNID <not set> Interfaces: GigabitEthernet0/0.200 GigabitEthernet0/1.200 Address family IPV4 unicast: Export VPN route-target communities: RT:65000:100 Import VPN route-target communities: RT:65000:100 No export route-map No import route-map Address family IPV6 unicast: Export VPN route-target communities: RT:65000:100 Import VPN route-target communities: RT:65000:100 Members: 10.0.0.0/24 Based on this output, what can be concluded?

A.The VRF is configured for IPv4 only
B.The VRF uses different route-targets for import and export
C.The VRF supports both IPv4 and IPv6 VPNs with matching route-targets
D.The VRF has no interfaces assigned
AnswerC

This option is correct because the VRF configuration includes both an IPv4 unicast and an IPv6 unicast address family, each with its own VRF table. Additionally, both address families are configured with the same route-target value of 65000:100 for both import and export. This means the VRF supports both IPv4 and IPv6 VPNs, and the matching route-targets ensure that routes from both address families are respectively imported and exported to the same VPNv4/VPNv6 neighbors.

Why this answer

The output shows both 'Address family IPV4 unicast' and 'Address family IPV6 unicast' sections, each with the same export and import route-target communities (RT:65000:100). This confirms the VRF CUSTOMER-B supports both IPv4 and IPv6 VPN address families with matching route-targets, enabling MPLS L3VPN services for both address families over the same VRF.

Exam trap

Cisco often tests the misconception that a VRF supports only one address family (IPv4) by default, but the 'show vrf detail' output clearly shows separate address family sections, and candidates may overlook the IPv6 unicast section if they focus only on the route-target values.

How to eliminate wrong answers

Option A is wrong because the VRF explicitly includes an 'Address family IPV6 unicast' section, proving it is not IPv4-only. Option B is wrong because both the export and import route-target communities are identical (RT:65000:100) for both address families, not different. Option D is wrong because the output lists two interfaces (GigabitEthernet0/0.200 and GigabitEthernet0/1.200) under 'Interfaces:', so the VRF has interfaces assigned.

1508
MCQmedium

A company is virtualizing its network functions using NFV on a KVM-based hypervisor. The design must ensure that the virtual router (CSR1000v) can handle high-throughput traffic with minimal latency. Which architectural consideration is most critical for achieving this goal?

A.Pin the vCPU of the CSR1000v to dedicated physical cores and ensure the VM memory is allocated from the same NUMA node.
B.Use a Type 2 hypervisor to allow the VNF to share resources with other VMs more efficiently.
C.Enable overcommitment of CPU resources to maximize the number of VNFs per host.
D.Place the CSR1000v on a VMware ESXi host instead of KVM for better performance.
AnswerA

NFV throughput depends on CPU and memory locality. Pinning vCPUs to dedicated physical cores prevents hypervisor scheduling contention, while sourcing memory from the same NUMA node avoids cross-node QPI/UPI hops that add latency and reduce packet-processing throughput for the CSR1000v.

Why this answer

Pinning vCPUs to dedicated physical cores and allocating memory from the same NUMA node eliminates cross-NUMA memory access and CPU scheduling contention, which are critical for reducing latency and maximizing throughput in a data-plane-intensive VNF like the CSR1000v. This ensures that the VM's memory accesses are local to the NUMA node where its vCPUs run, avoiding the performance penalty of remote memory access over the QPI/UPI interconnect.

Exam trap

Cisco often tests the misconception that simply using a Type 1 hypervisor or avoiding overcommitment is sufficient, but the trap here is that candidates overlook the critical impact of NUMA locality and vCPU pinning on latency-sensitive VNFs, assuming that any virtualization optimization will suffice.

How to eliminate wrong answers

Option B is wrong because a Type 2 hypervisor (hosted on an OS) introduces additional overhead and is less performant for high-throughput NFV workloads compared to a Type 1 hypervisor like KVM, which runs directly on hardware. Option C is wrong because CPU overcommitment allows multiple vCPUs to share physical cores, which can cause resource contention and increased latency, directly undermining the goal of minimal latency for the CSR1000v. Option D is wrong because the question specifically states the design uses KVM, and while ESXi can be performant, the architectural consideration for achieving minimal latency on KVM is NUMA-aware pinning, not switching hypervisors; the correct answer addresses the universal principle of NUMA locality regardless of hypervisor.

1509
Drag & Dropmedium

Drag and drop the steps of VRF import/export route-target policy flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The order starts with configuring the export RT on the VRF, the PE advertising the VPNv4 route with that RT, the remote PE receiving the route and comparing the RT with its import RT list, if matched the route is imported into the VRF, and finally the route is installed in the VRF routing table.

1510
MCQmedium

Consider the following configuration snippet: router bgp 65000 bgp router-id 192.168.1.1 neighbor 10.0.0.2 remote-as 65001 neighbor 10.0.0.2 timers 10 30 ! What is the effect of the 'timers 10 30' command under the BGP neighbor?

A.It sets the keepalive interval to 10 seconds and the hold time to 30 seconds for all BGP neighbors.
B.It sets the keepalive interval to 10 seconds and the hold time to 30 seconds for neighbor 10.0.0.2 only.
C.It sets the BGP keepalive interval to 30 seconds and the hold time to 10 seconds for neighbor 10.0.0.2.
D.It configures the BGP session to use a keepalive of 10 seconds and a hold time of 30 seconds, but only if the neighbor supports it.
AnswerB

This is the correct interpretation of the 'neighbor 10.0.0.2 timers 10 30' command. The syntax explicitly places the timers within the neighbor address family, meaning the keepalive interval of 10 seconds and hold time of 30 seconds are applied only to that BGP peer. This per-neighbor timer configuration overrides any global 'timers bgp' settings for this neighbor, and it does not affect other neighboring devices.

Why this answer

The 'timers 10 30' command under the BGP neighbor configuration mode sets the keepalive interval to 10 seconds and the hold time to 30 seconds specifically for that neighbor (10.0.0.2). This per-neighbor timer configuration overrides any global BGP timers set under the router bgp process, allowing granular control over individual BGP sessions.

Exam trap

Cisco often tests the distinction between global and per-neighbor BGP timer configuration, and the trap here is that candidates confuse the 'timers' command under neighbor with the global 'timers bgp' command, or misorder the keepalive and hold time values.

How to eliminate wrong answers

Option A is wrong because the command is applied under the neighbor configuration, not globally; global BGP timers are set using the 'timers bgp' command under router bgp, which affects all neighbors. Option C is wrong because it reverses the order: the first value is the keepalive interval (10 seconds), and the second is the hold time (30 seconds), not the other way around. Option D is wrong because BGP timers are unilaterally configured and advertised to the neighbor; the session will use the configured values if the neighbor accepts them, but the command does not conditionally apply only if the neighbor supports it—it is always sent in the OPEN message.

1511
MCQmedium

An enterprise network has two routers, R1 and R2, both running BGP. R1 is an eBGP speaker with ISP1, and R2 is an eBGP speaker with ISP2. Both routers are in the same AS 65000. The engineer wants to ensure that traffic from the enterprise to the Internet prefers the path through ISP1 when both links are up. R1 learns a default route from ISP1, and R2 learns a default route from ISP2. Which BGP attribute should the engineer modify on R1 to influence outbound traffic selection?

A.Set a higher local preference on R1 for the default route learned from ISP1.
B.Set a lower MED on R1 for the default route learned from ISP1.
C.Prepend AS 65000 multiple times on R2's updates to ISP2.
D.Configure a community on R1 to mark the default route as no-export.
AnswerA

Setting a higher local preference on R1 for the default advertisement from ISP1 is correct because local preference is the first major BGP attribute used to choose the outbound path (after weight) and is propagated to iBGP peers. By assigning this route a higher local preference, R1 will prefer its directly received default from ISP1 over the alternate default route learned from R2, and that preference will also be advertised to R2 via iBGP, making ISP1 the primary egress for the entire AS. Local preference is evaluated before AS_PATH, MED, and IGP cost, so it is the most direct and scalable way to control outbound traffic policy.

Why this answer

Local preference is the BGP attribute used to influence outbound traffic from an AS. It is propagated within the AS and a higher value is preferred. By setting a higher local preference on R1 for the default route learned from ISP1, R1 will prefer that route over the default route from ISP2, ensuring traffic from the enterprise to the Internet exits via ISP1.

Exam trap

Cisco often tests the distinction between attributes that influence outbound traffic (local preference, weight) versus inbound traffic (MED, AS path prepending), and the trap here is confusing MED or AS path prepending as tools for outbound path selection.

How to eliminate wrong answers

Option B is wrong because MED (Multi-Exit Discriminator) is used to influence inbound traffic into an AS, not outbound traffic; lowering MED on R1 would affect how ISP1 selects paths to reach prefixes inside AS 65000, not how R1 chooses a default route. Option C is wrong because AS path prepending is applied to outbound updates to influence inbound traffic from ISPs, making a path less preferred by lengthening the AS_PATH; it does not affect R1's outbound traffic selection. Option D is wrong because the no-export community prevents a route from being advertised to eBGP peers, which would block the default route from being sent to ISP1 or ISP2, but does not influence R1's preference for outbound traffic.

1512
Drag & Dropmedium

Drag and drop the steps of TrustSec SGT assignment and propagation via SXP into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

SGT propagation via SXP starts with ISE assigning an SGT to an endpoint, the access switch mapping IP-to-SGT, then the SXP speaker sending that mapping to an SXP listener, which updates its local SGT cache, and finally the listener uses the SGT for policy enforcement.

1513
MCQhard

A network engineer is designing a QoS policy for a WAN edge router. The requirement is to ensure that VoIP traffic receives strict priority treatment and that excess VoIP traffic is policed to prevent starvation of other traffic. Which QoS mechanism should be used?

A.Low Latency Queuing (LLQ)
B.Class-Based Weighted Fair Queuing (CBWFQ)
C.Weighted Random Early Detection (WRED)
D.Traffic Shaping
AnswerA

Low Latency Queuing (LLQ) provides strict priority queuing for delay-sensitive traffic like VoIP. It includes a policer that limits the priority queue to a configured bandwidth, preventing it from starving other queues. This matches the requirement for strict priority treatment with policing of excess VoIP traffic, making it the correct choice.

Why this answer

Low Latency Queuing (LLQ) combines strict priority queuing with a policer. The priority queue ensures VoIP packets are transmitted before other traffic, minimizing delay and jitter. The policer limits the amount of traffic that can enter the priority queue, preventing VoIP from consuming all bandwidth and starving other applications.

This dual behavior exactly matches the requirement for strict priority treatment with excess VoIP policing.

Exam trap

The trap here is assuming that CBWFQ provides strict priority, when it actually only guarantees bandwidth without prioritizing delay-sensitive traffic.

1514
MCQhard

A network engineer is analyzing traffic flows using Cisco IOS NetFlow on a router. The engineer notices that the NetFlow cache is filling up rapidly, causing older entries to be exported prematurely before they can be properly aggregated. Which NetFlow configuration parameter should the engineer adjust to control the maximum number of entries in the cache?

A.cache entries
B.cache timeout active
C.ip flow-export destination
D.cache timeout inactive
AnswerA

The 'cache entries' command under the NetFlow cache configuration specifies the maximum number of entries that the NetFlow cache can hold. When the cache reaches this limit, the router may force-export older entries to make room for new ones. By increasing this value, the engineer can allow more entries to be stored, reducing premature exports. This directly addresses the issue of the cache filling up rapidly.

Why this answer

In Cisco IOS NetFlow, the cache has a maximum number of entries defined by the 'cache entries' command. When the cache reaches this limit, the router may prematurely export older flows to free space, leading to incomplete aggregation. Increasing the cache entries allows more flows to be stored, reducing premature exports.

Other parameters like timeouts affect flow expiration but not the total capacity. The engineer should adjust 'cache entries' to match the traffic volume and available memory.

Exam trap

The trap here is confusing cache size limits with timeout settings; timeouts control when flows are exported, but 'cache entries' controls how many flows can be stored.

1515
Multi-Selecthard

Which three statements about SD-WAN overlay tunnels and transport are true? (Choose three.)

Select 3 answers
A.Control plane communication between vSmart and edge devices uses DTLS or TLS encryption.
B.Data plane tunnels between edge devices are encrypted using IPsec with IKEv2 key exchange.
C.A TLOC (Transport Location) is defined by the combination of system IP, color, and encapsulation type.
D.SD-WAN edge devices can only use MPLS or Internet as transport; LTE is not supported.
E.OMP is responsible for dynamically establishing IPsec tunnels between edge devices based on policy.
AnswersA, B, C

vSmart controllers establish control connections with edge devices over DTLS, or TLS where configured, protecting OMP route and policy exchanges. This satisfies the control plane security requirement distinguishing controller-to-edge signalling from the separate data plane tunnels.

Why this answer

Option A is correct because in Cisco SD-WAN the control plane connections between vSmart controllers and edge devices (vEdge/cEdge) are secured with DTLS or TLS, protecting OMP and other control traffic. Option B is correct because the data plane overlay tunnels between edge devices are IPsec tunnels whose keys are negotiated using IKEv2, providing encryption and authentication for payload traffic. Option C is correct because a TLOC is uniquely identified by the tuple of system IP, color, and encapsulation type (for example, system-ip, color biz-internet, encapsulation ipsec), which tells OMP how to reach the transport.

Option D is incorrect because SD-WAN supports many transport colors beyond MPLS and Internet, including LTE/5G, and LTE is explicitly supported. Option E is incorrect because OMP distributes routing and TLOC information but does not itself establish IPsec tunnels; tunnel establishment is handled by the data plane using IKE/IPsec based on TLOC and policy.

1516
MCQmedium

A network administrator is using Cisco DNA Center Assurance to monitor the health of a campus network. The administrator notices that a particular client device shows a health score of 'Poor' but the switch port statistics indicate no errors or drops. Which Cisco DNA Center Assurance feature should the administrator use to identify the root cause of the poor health score?

A.Network Health dashboard
B.Path Trace
C.Client 360
D.Application Health dashboard
AnswerC

Client 360 provides a detailed view of a specific client's connectivity, including onboarding, authentication, and application experience. It aggregates data from multiple sources to help identify why a client has a poor health score, such as RF issues, authentication failures, or DHCP problems. This is the correct tool for root cause analysis of a single client's health.

Why this answer

Cisco DNA Center Assurance's Client 360 view provides comprehensive details about a specific client, including onboarding, authentication, RF statistics, and application experience. It is designed to help troubleshoot client-specific issues and determine the root cause of poor health scores. Other dashboards offer aggregate or path-based views but lack the client-centric depth needed here.

Exam trap

The trap here is confusing network-wide monitoring dashboards with client-specific troubleshooting tools; Client 360 is the dedicated feature for deep-dive analysis of an individual client's health.

1517
MCQmedium

Consider the following configuration snippet: interface Port-channel1 switchport mode trunk switchport trunk allowed vlan 10,20,30 ! interface GigabitEthernet0/1 channel-group 1 mode active ! interface GigabitEthernet0/2 channel-group 1 mode passive What is the effect of this configuration?

A.The EtherChannel will form using LACP, and the port-channel will operate as a trunk carrying VLANs 10, 20, and 30.
B.The EtherChannel will not form because both sides must use the same LACP mode.
C.The EtherChannel will form using PAgP because the mode is not specified as lacp.
D.The EtherChannel will form but only VLAN 1 will be allowed on the trunk.
AnswerA

GigabitEthernet0/1 uses LACP active mode and GigabitEthernet0/2 uses passive mode, so the bundle negotiates successfully. The Port-channel1 interface is configured as a trunk permitting VLANs 10, 20 and 30, which is exactly what the port-channel carries.

Why this answer

The configuration uses LACP with one side in active mode (GigabitEthernet0/1) and the other in passive mode (GigabitEthernet0/2). LACP allows an active/passive combination to form an EtherChannel, unlike PAgP which requires at least one side to be in desirable mode. The trunk and allowed VLANs are configured on the port-channel interface, which applies to all member ports once the channel is established.

Exam trap

Cisco often tests the misconception that both sides of an LACP EtherChannel must use the same mode (active/active or passive/passive), but in fact active/passive works, while passive/passive does not form a channel.

How to eliminate wrong answers

Option B is wrong because LACP does not require both sides to use the same mode; active/passive is a valid combination that forms an EtherChannel. Option C is wrong because the channel-group mode commands use LACP keywords (active/passive), not PAgP keywords (desirable/auto); PAgP is not involved here. Option D is wrong because the 'switchport trunk allowed vlan' command on the port-channel interface explicitly permits VLANs 10, 20, and 30, not just VLAN 1.

1518
MCQmedium

A network engineer is configuring a new Cisco Catalyst 9300 switch stack. The company requires that the native VLAN for all 802.1Q trunk ports be changed from the default to VLAN 99. The engineer enters the global configuration command vlan dot1q tag native and then configures the trunk ports with switchport trunk native vlan 99. After applying the configuration, the engineer notices that untagged frames received on the trunk are being dropped. What is the most likely cause?

A.The vlan dot1q tag native command must be configured on all switches in the topology, not just the local switch.
B.The native VLAN must be the same on both ends of the trunk; otherwise, untagged frames are dropped.
C.The switchport trunk native vlan 99 command is only valid if the native VLAN is VLAN 1.
D.The vlan dot1q tag native command causes all native VLAN frames to be tagged, so untagged frames are dropped.
AnswerD

With vlan dot1q tag native enabled, the switch tags all frames on the native VLAN. Any untagged frames arriving on the trunk are considered invalid and dropped. This is the expected behavior when this global command is used, and it explains why untagged frames are being dropped.

Why this answer

Enabling vlan dot1q tag native globally causes the switch to tag all frames on the native VLAN for 802.1Q trunks. As a result, any untagged frames received on those trunks are dropped because they are not expected. This behavior is by design and explains the observed frame drops.

Exam trap

The trap here is assuming that vlan dot1q tag native only affects outbound tagging and not inbound frame processing.

1519
Drag & Dropmedium

Drag and drop the steps of ISE profiling-based dynamic ACL assignment into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

ISE profiling identifies the device type via DHCP/HTTP probes, matches it to a profile, then ISE downloads a dynamic ACL to the switch, which applies it to the port, and finally the switch enforces the ACL on traffic from that endpoint.

1520
Multi-Selecthard

A network engineer is troubleshooting a Cisco Nexus 9000 VXLAN EVPN fabric in which a host attached to leaf-1 cannot communicate with a host in the same subnet attached to leaf-2, even though both leaf switches show the VNI as up. The engineer suspects the EVPN control plane. Which two conditions must be met for the two hosts to communicate over the VXLAN overlay? (Choose two.)

Select 2 answers
A.The two leaf switches must establish a BGP EVPN session, either directly or through a route reflector, and exchange MAC or MAC-IP routes for the VNI.
B.The spines must terminate the VXLAN tunnels and perform the inter-VTEP forwarding between the two leaf switches.
C.Each leaf's NVE source interface must be reachable in the underlay, and the remote VTEP IP must be present in the local VRF or global table.
D.The two leaf switches must use the same VLAN ID locally for the segment, because the VLAN ID is carried inside the VXLAN header.
E.The two leaf switches must have identical bridge domain configurations, including the same anycast gateway MAC address on every leaf.
AnswersA, C

VXLAN EVPN relies on MP-BGP EVPN to advertise MAC and MAC-IP reachability between VTEPs. Without an established EVPN session and the corresponding type-2 routes for the VNI, leaf-1 does not know which remote VTEP owns the destination MAC, so it cannot encapsulate the frame toward leaf-2 and traffic is dropped even though the VNI is up.

Why this answer

For hosts in the same subnet on different leaves to communicate, the fabric needs both control-plane and data-plane reachability. The EVPN session must advertise the type-2 MAC or MAC-IP routes for the VNI so each leaf learns the remote VTEP for the destination, and the underlay must be able to deliver encapsulated packets to that remote VTEP IP. Missing either element leaves the VNI up but the hosts unable to reach each other.

Exam trap

The trap here is thinking the VNI being up means the overlay is working, when EVPN route exchange and VTEP IP reachability are the actual requirements.

1521
MCQmedium

A network security team deploys Cisco TrustSec on a Catalyst 9500 fabric. The team wants to enforce a policy where a user authenticated into the 'Contractor' security group tag (SGT) is denied access to servers tagged with the 'Finance' SGT, while remaining able to reach the 'Printers' SGT. Which enforcement mechanism applies the SGACL to traffic between the tagging devices?

A.802.1X with downloadable ACLs pushed from Cisco ISE to the access switch on the user's port.
B.SGT Exchange Protocol (SXP) on the enforcement device, mapping IP addresses to SGTs at the egress point.
C.MACsec encryption with MKA on the fabric uplinks, which implicitly denies unauthorized SGT combinations.
D.SGACL enforcement applied on the egress enforcement device using the SGT carried in the Cisco Metadata (CMD) header.
AnswerD

SGACLs are evaluated on the enforcement device using the source and destination SGTs carried in the Cisco Metadata header. This allows the fabric to deny Contractor-to-Finance while permitting Contractor-to-Printers based on the policy matrix defined on Cisco ISE, satisfying the requirement precisely.

Why this answer

Cisco TrustSec enforces group-based policy by inserting the source SGT into the Cisco Metadata header and evaluating SGACLs on the egress enforcement device against the destination SGT. The policy matrix authored on ISE defines deny Contractor-to-Finance and permit Contractor-to-Printers, and the enforcement device applies it inline. SXP only propagates bindings, dACLs only filter at the port, and MACsec only secures the link.

Exam trap

The trap here is confusing SXP, which propagates SGT bindings, with SGACL enforcement, which actually denies the traffic.

1522
MCQeasy

Which of the following is a valid VLAN range that can be created on a Cisco IOS switch?

A.VLAN 100
B.VLAN 0
C.VLAN 4095
D.VLAN 1006
AnswerA

Correct. VLAN 100 is within the standard range of 1-1005.

Why this answer

VLAN 100 is a valid VLAN ID because Cisco IOS switches support VLANs in the range 1–1005 for normal-range VLANs, and VLAN 100 falls within this range. Normal-range VLANs are stored in the vlan.dat file and can be created on a standard IOS switch without requiring extended VLAN configuration.

Exam trap

Cisco often tests the misconception that any VLAN ID from 1 to 4094 is valid on any switch, but the trap here is that extended VLANs (1006–4094) require specific VTP modes or configuration, and VLANs 0, 1002–1005, and 4095 are reserved or not user-creatable.

How to eliminate wrong answers

Option B is wrong because VLAN 0 is reserved and cannot be used; VLAN IDs start at 1. Option C is wrong because VLAN 4095 is reserved for implementation use and is not available for user-created VLANs; the maximum usable VLAN ID is 4094. Option D is wrong because VLAN 1006 is in the extended VLAN range (1006–4094), which requires a switch running in transparent mode or with VTP version 3, and is not a valid normal-range VLAN that can be created by default on a standard IOS switch.

1523
MCQeasy

A company uses Chef to automate network device configuration. The network devices are Cisco IOS XE running in a brownfield environment. Which Chef component is used to manage the state of the devices?

A.Ohai
B.Chef client
C.Chef workstation
D.Chef server
AnswerB

The Chef client is the enforcement agent that runs directly on each managed device, including network infrastructure such as IOS XE, NX-OS, or IOS XR when Cisco devices are integrated with Chef. It performs the convergence loop by querying the Chef server for the node's run list, evaluating the current state using Ohai, and then executing resources to bring the device to the desired configuration. This on-device agent is precisely the component that applies the automated configuration, making it the correct answer.

Why this answer

In a Chef-managed brownfield environment with Cisco IOS XE devices, the Chef client is the agent that runs on each device (or on a proxy like a guest shell) and applies the desired state defined in cookbooks. It is responsible for converging the device's configuration to match the policy, making it the correct component for state management.

Exam trap

Cisco often tests the distinction between the Chef client (the agent that enforces state) and the Chef server (the repository), leading candidates to mistakenly select the server as the component that manages device state.

How to eliminate wrong answers

Option A is wrong because Ohai is a tool that collects system metadata (e.g., platform, interfaces) on the node and makes it available as attributes, but it does not manage state or apply configurations. Option C is wrong because the Chef workstation is where cookbooks are authored and uploaded to the Chef server; it does not run on the network devices or directly manage their state. Option D is wrong because the Chef server stores cookbooks, node data, and policies, but it does not execute configuration changes on devices; it acts as a central repository and API endpoint.

1524
Multi-Selectmedium

Which two statements about BGP path attributes are true? (Choose two.)

Select 2 answers
A.The AS_PATH attribute is well-known mandatory.
B.The LOCAL_PREF attribute is well-known discretionary.
C.The MED attribute is well-known mandatory.
D.The ORIGIN attribute is optional transitive.
E.The COMMUNITY attribute is well-known mandatory.
AnswersA, B

AS_PATH is a well-known mandatory attribute, meaning every BGP UPDATE carrying reachable NLRI must include it, and all compliant speakers must recognise it. This satisfies the stem's requirement for a true statement about path attributes, as it correctly classifies both the well-known and mandatory characteristics.

Why this answer

Option A is correct because AS_PATH is a well-known mandatory BGP path attribute: every BGP update that advertises a route must include it, and it lists the autonomous systems the prefix has traversed, which is fundamental to BGP loop prevention and best-path selection. Option B is correct because LOCAL_PREF is a well-known discretionary attribute: all BGP-speaking routers must recognize it, but it is not required in every update, and it is used locally within an AS to influence outbound path selection. Option C is wrong because MED is an optional non-transitive attribute, not well-known mandatory.

Option D is wrong because ORIGIN is a well-known mandatory attribute, not optional transitive. Option E is wrong because COMMUNITY is an optional transitive attribute, not well-known mandatory.

Exam trap

The trap is that candidates often confuse the classifications of BGP attributes. For instance, they might think MED is well-known mandatory because it's commonly used, but it's actually optional nontransitive. Similarly, ORIGIN is often mistakenly thought to be optional.

1525
MCQmedium

A network engineer is deploying a VXLAN EVPN fabric with Cisco Nexus 9000 switches. The design requires that when a leaf switch learns a MAC address from a local host, remote leaf switches should be able to install that MAC into their forwarding tables without flooding. Which EVPN route type is used to advertise MAC address reachability?

A.Type 5 IP Prefix route
B.Type 3 Inclusive Multicast Ethernet Tag route
C.Type 2 MAC/IP Advertisement route
D.Type 1 Ethernet Auto-Discovery route
AnswerC

Type 2 MAC/IP Advertisement routes carry the MAC address, IP address, and VTEP information for a host, allowing remote leaf switches to install the MAC into their forwarding tables without flooding. This route type is the core of EVPN MAC learning and enables efficient unicast forwarding across the VXLAN fabric. It directly satisfies the requirement for MAC reachability advertisement.

Why this answer

EVPN Type 2 MAC/IP Advertisement routes are specifically designed to advertise host MAC and IP addresses along with the originating VTEP. Remote leaf switches receive these routes and program the MAC into their forwarding tables, enabling known unicast traffic to be sent directly without flooding. Other EVPN route types serve different purposes such as multihoming, BUM replication, or Layer 3 prefix advertisement.

Exam trap

The trap here is confusing the EVPN route types, especially mixing up Type 2 MAC advertisement with Type 3 BUM replication.

1526
Drag & Dropmedium

Drag and drop the steps of troubleshooting a failed RSPAN session into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with verifying the RSPAN VLAN exists and is active on all switches, then checking that trunk links carry the RSPAN VLAN, then confirming the source SPAN session is correctly configured, then inspecting the destination SPAN session, and finally using debug or monitor commands to isolate the issue.

1527
MCQeasy

A network engineer is configuring a switch to support 802.1X authentication for wired clients. The requirement is to authenticate users against a centralized RADIUS server and assign dynamic VLANs based on the user's role. Which command must be configured on the switch to enable 802.1X authentication globally?

A.aaa authentication dot1x default group radius
B.dot1x system-auth-control
C.authentication port-control auto
D.dot1x pae authenticator
AnswerB

The command 'dot1x system-auth-control' enables 802.1X authentication globally on a Cisco switch. It is a prerequisite for configuring 802.1X on individual interfaces. Without this command, 802.1X authentication will not function, even if interface-level commands are configured. This command allows the switch to act as an authenticator and communicate with the RADIUS server to authenticate supplicants.

Why this answer

To enable 802.1X authentication globally on a Cisco switch, the 'dot1x system-auth-control' command must be configured. This command activates the 802.1X process and allows the switch to act as an authenticator. Other commands, such as those for RADIUS or interface-level settings, are necessary but do not globally enable 802.1X.

Exam trap

The trap here is confusing the global enablement command with interface-level or AAA commands that are also part of 802.1X configuration.

1528
MCQmedium

A network engineer is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The engineer applies a CoPP policy-map to the control plane with a class that matches BGP traffic and sets police rate 8000 conform-action transmit exceed-action drop. After applying the policy, BGP sessions intermittently flap during route convergence. Which action should the engineer take to resolve the issue while maintaining control plane protection?

A.Apply the CoPP policy to all router interfaces as an input service policy instead of to the control plane.
B.Remove the CoPP policy from the control plane interface and rely on interface ACLs instead.
C.Increase the police rate for the BGP class or change the exceed-action to transmit, after verifying the offered rate.
D.Change the CoPP policy to use priority queuing instead of policing for the BGP class.
AnswerC

The intermittent BGP flaps during convergence indicate that legitimate BGP control traffic is exceeding the 8,000 pps police rate and being dropped by the exceed-action. Increasing the police rate or changing the exceed-action to transmit for the BGP class restores session stability while still policing other control plane traffic. Verification of the offered rate is essential to size the policer correctly.

Why this answer

BGP session flapping immediately after applying a policer that drops exceeded traffic points to legitimate BGP control packets being dropped because the configured rate is too low for convergence bursts. The correct remediation is to right-size the policer for the BGP class, either by raising the rate or by permitting excess traffic, after confirming the actual offered rate from the control plane.

Exam trap

The trap here is assuming that any control plane drops must be caused by an attack rather than by an undersized policer that drops legitimate routing protocol traffic.

1529
MCQhard

An architect is designing a QoS policy for a Cisco SD-Access fabric. The policy must prioritize voice traffic from wireless clients connected to fabric-enabled access points over other traffic types. The design should use the fabric's built-in capabilities to simplify deployment. Which approach should the architect take?

A.Use Cisco TrustSec to assign an SGT to voice traffic based on ISE authentication, then apply a QoS policy on the fabric edge node that matches the SGT and provides priority queuing.
B.Configure QoS policies on the wireless LAN controller (WLC) only, marking voice traffic with DSCP EF, and rely on the fabric to preserve the marking.
C.Implement a centralized QoS policy on the fabric border node that matches the source IP addresses of voice devices.
D.Use VXLAN network identifiers (VNIs) to classify voice traffic and apply QoS on the control plane node.
AnswerA

In an SD-Access fabric, Cisco TrustSec enables ISE to assign an SGT to an authenticated IP phone, identifying it as voice even when its IP address changes. The fabric edge node, as the first hop for the voice traffic, can match that SGT and apply a policy that marks DSCP EF and places packets into the priority queue. Because SGT-based classification is independent of IP addressing, it scales cleanly and provides consistent queuing as the traffic traverses the fabric.

Why this answer

Cisco SD-Access uses TrustSec to propagate Security Group Tags (SGTs) from ISE to the fabric edge nodes. By matching the SGT assigned to voice traffic (e.g., via ISE profiling and authentication), the fabric edge node can apply a QoS policy that places that traffic into a priority queue. This leverages the fabric's built-in SGT-based policy enforcement, simplifying deployment without requiring per-device ACLs or complex marking configurations.

Exam trap

Cisco often tests the misconception that QoS marking alone (e.g., DSCP EF) is sufficient in SD-Access, when in fact the fabric requires explicit policy enforcement at the edge node, and SGT-based classification is the recommended method for scalable, identity-aware QoS.

How to eliminate wrong answers

Option B is wrong because relying solely on the WLC to mark voice traffic with DSCP EF does not guarantee that the fabric will preserve the marking end-to-end; the fabric edge node must still apply a local QoS policy to honor the DSCP value, and the WLC-only approach ignores the fabric's ability to use SGTs for simplified, scalable policy. Option C is wrong because matching source IP addresses on the fabric border node is not scalable for voice traffic from many wireless clients, and the border node is not the optimal location for per-flow QoS classification in SD-Access; classification should occur at the fabric edge where traffic enters the fabric. Option D is wrong because VXLAN network identifiers (VNIs) are used for Layer 2 and Layer 3 segmentation, not for QoS classification; applying QoS on the control plane node is incorrect as the control plane handles overlay routing and database functions, not data-plane packet forwarding or queuing.

1530
MCQhard

An engineer is configuring a Cisco Nexus 9000 switch as a VXLAN Tunnel Endpoint in a spine-leaf fabric. The requirement is that the switch must perform VXLAN encapsulation and decapsulation in hardware without relying on the supervisor CPU, and it must support distributed anycast gateway for the tenant subnets. Which feature set must be enabled to meet these requirements?

A.Traditional Layer 2 switching with STP
B.Cisco NX-OS with the VXLAN feature and distributed anycast gateway enabled
C.Cisco ACI with a fabric-wide VXLAN pool
D.Cisco Nexus Dashboard with fabric controller mode
AnswerB

On Nexus 9000 switches, enabling the VXLAN feature allows the hardware ASIC to perform VXLAN encapsulation and decapsulation at line rate, avoiding supervisor CPU involvement. Configuring a distributed anycast gateway with the same virtual IP and MAC on every leaf provides optimal first-hop routing for tenant subnets. Together these features satisfy both the hardware-based VXLAN data plane and the anycast gateway design requirement.

Why this answer

Nexus 9000 switches support VXLAN encapsulation and decapsulation in hardware once the VXLAN feature is enabled, keeping forwarding off the supervisor CPU. A distributed anycast gateway configured with a shared virtual IP and MAC across leaf switches provides efficient first-hop routing for tenant subnets, meeting both requirements for this VXLAN Tunnel Endpoint design.

Exam trap

The trap here is confusing a centralized management or SDN platform with the on-switch feature set that actually delivers hardware VXLAN forwarding and distributed anycast gateway.

1531
Multi-Selectmedium

Which three statements about syslog message severity levels are correct? (Choose three.)

Select 3 answers
A.Severity level 0 (emergencies) indicates the system is unusable.
B.Severity level 3 (errors) includes error conditions that still allow the system to function.
C.Severity level 5 (notifications) is used for normal but significant conditions, such as interface up/down.
D.Severity level 6 (informational) is used for debugging messages that are only useful during troubleshooting.
E.The default logging console severity level on Cisco IOS is 3 (errors).
AnswersA, B, C

Severity level 0 maps to emergencies, the highest priority, signalling that the system itself is unusable and requires immediate attention. This satisfies the stem's requirement for a correct syslog severity statement, since level 0 sits at the top of the eight-level scale, above alerts and critical conditions.

Why this answer

Option A is correct because syslog severity level 0 is defined as "emergencies," meaning the system is unusable and immediate attention is required. Option B is correct because severity level 3 is "errors," which covers error conditions that still allow the system to continue functioning, unlike level 0-2. Option C is correct because severity level 5 is "notifications," used for normal but significant conditions such as interface up/down events.

Option D is incorrect because debugging messages are severity level 7, while level 6 is "informational" for normal operational messages. Option E is incorrect because the default logging console severity level on Cisco IOS is level 2 (critical), not level 3 (errors).

Exam trap

The trap here is confusing severity 6 (informational) with severity 7 (debugging), and assuming the Cisco IOS default logging console level is 3 when it is actually 2 (critical).

1532
Drag & Dropmedium

Drag and drop the steps of EIGRP route summarization configuration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

EIGRP route summarization first requires enabling EIGRP, configuring the network statement, then entering interface configuration mode, applying the summary-address command, and finally verifying the summary route in the routing table.

1533
MCQmedium

Which statement correctly describes the difference between RADIUS and TACACS+?

A.RADIUS encrypts the entire packet; TACACS+ encrypts only the password.
B.RADIUS encrypts only the password; TACACS+ encrypts the entire packet body.
C.Both protocols encrypt the entire packet.
D.Neither protocol encrypts any part of the packet.
AnswerB

RADIUS hides only the password field within the Access-Request, leaving attributes such as username and service type readable. TACACS+ encrypts the whole packet body, including all authorisation and accounting attributes, using a shared secret over TCP port 49.

Why this answer

RADIUS encrypts only the password attribute in the Access-Request packet using a shared secret and MD5 hash, leaving the rest of the packet (e.g., username, service type) in cleartext. TACACS+ encrypts the entire body of the packet (all fields except the standard header) using a shared secret and MD5-based encryption, providing confidentiality for all AAA information. This makes option B correct because it accurately describes the encryption scope difference between the two protocols.

Exam trap

Cisco often tests the misconception that RADIUS encrypts more than it actually does; the trap here is assuming RADIUS encrypts the entire packet like TACACS+, when in fact RADIUS only encrypts the password attribute, while TACACS+ encrypts the entire packet body.

How to eliminate wrong answers

Option A is wrong because it reverses the encryption behavior: RADIUS encrypts only the password, not the entire packet, while TACACS+ encrypts the entire packet body, not just the password. Option C is wrong because RADIUS does not encrypt the entire packet; only the password is encrypted, and other fields like username and NAS-IP-Address are sent in cleartext. Option D is wrong because both protocols do encrypt at least some part of the packet: RADIUS encrypts the password, and TACACS+ encrypts the entire packet body.

1534
MCQeasy

A network engineer is configuring a Cisco router for AAA using a RADIUS server. The engineer wants to ensure that if the RADIUS server is unreachable, the router falls back to local authentication for console access. The engineer configures 'aaa authentication login default group radius local' and 'aaa authentication login CONSOLE local'. The console line is configured with 'login authentication CONSOLE'. However, when the RADIUS server is down, the engineer cannot log in via the console. What is the problem?

A.The router has no local usernames configured, so the 'local' method has no users to authenticate against.
B.The 'aaa authentication login CONSOLE local' command should be 'aaa authentication login CONSOLE group radius local' to include RADIUS as a fallback.
C.The console line should use the default authentication list instead of a named list.
D.The 'aaa new-model' command is missing, so AAA is not enabled.
AnswerA

The 'local' method in an AAA login method list instructs the router to check credentials against the locally defined username database (created with the 'username' command). If the router has no usernames configured, there are zero valid usernames/passwords to authenticate against, so the login attempt fails immediately. This is true regardless of the method list name or whether aaa new-model is enabled. Thus the correct root cause is the empty local user database.

Why this answer

The 'aaa authentication login CONSOLE local' command tells the router to use only local authentication for the CONSOLE list. When the RADIUS server is down, the console login fails because no local usernames have been configured, so there are no credentials to authenticate against. The fallback to local authentication in the default list is irrelevant because the console line explicitly uses the CONSOLE list, which does not include RADIUS.

Exam trap

Cisco often tests the nuance that a named authentication list completely replaces the default list for that line, so candidates mistakenly think the default list's fallback logic still applies when the named list's method fails.

How to eliminate wrong answers

Option B is wrong because the CONSOLE list is intentionally configured to use only local authentication; adding 'group radius local' would make it fall back to RADIUS first, which is not the desired behavior for console access when RADIUS is unreachable. Option C is wrong because using a named list is correct and allows separate authentication policies for console vs. other lines; the default list would apply RADIUS with local fallback, which is not the requirement. Option D is wrong because if 'aaa new-model' were missing, the AAA commands would be rejected by the CLI, and the engineer would not have been able to configure the authentication lists at all.

1535
MCQhard

A network engineer is implementing a Python script to interact with a Cisco IOS XE device using RESTCONF. The script must authenticate using basic authentication over HTTPS and retrieve the configured hostname. Which Python code snippet correctly performs this task using the requests library?

A.import requests url = 'https://192.168.1.1/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1' headers = {'Accept': 'application/yang-data+json'} response = requests.get(url, headers=headers, auth=('admin', 'password'), verify=False) hostname = response.json()['name']
B.import requests url = 'https://192.168.1.1/restconf/data/Cisco-IOS-XE-native:native/hostname' headers = {'Accept': 'application/yang-data+json'} response = requests.get(url, headers=headers, verify=False) hostname = response.json()['Cisco-IOS-XE-native:hostname']
C.import requests url = 'https://192.168.1.1/restconf/data/Cisco-IOS-XE-native:native/hostname' headers = {'Content-Type': 'application/yang-data+json'} response = requests.get(url, headers=headers, auth=('admin', 'password'), verify=False) hostname = response.json()['hostname']
D.import requests url = 'https://192.168.1.1/restconf/data/Cisco-IOS-XE-native:native/hostname' headers = {'Accept': 'application/yang-data+json'} response = requests.get(url, headers=headers, auth=('admin', 'password'), verify=False) hostname = response.json()['Cisco-IOS-XE-native:hostname']
AnswerD

This snippet uses the correct RESTCONF URL for the hostname, sets the Accept header to 'application/yang-data+json', provides basic authentication credentials, and disables SSL verification. The JSON response for this leaf is a dictionary with the key 'Cisco-IOS-XE-native:hostname'. This correctly retrieves the hostname.

Why this answer

The correct RESTCONF request must use the proper URL for the hostname leaf, set the Accept header to 'application/yang-data+json', provide basic authentication, and parse the response using the fully qualified key 'Cisco-IOS-XE-native:hostname'. The other options use the wrong URL, wrong header, wrong JSON key, or omit authentication.

Exam trap

The trap here is using Content-Type instead of Accept for a GET request, or forgetting the namespace prefix in the JSON key, both of which cause failures.

1536
MCQmedium

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs and runs SSH for management. The administrator wants to ensure that a sudden flood of BGP updates from a misbehaving peer does not starve the SSH management plane, while still allowing legitimate BGP traffic. Which CoPP configuration approach best meets this requirement?

A.Apply an ACL that denies TCP port 179 from the ISP peer addresses directly to the BGP router process using the neighbor command.
B.Define a class-map matching BGP (TCP port 179) and SSH (TCP port 22) in a single class, then apply a single policer with a low rate to that combined class.
C.Define separate class-maps for BGP and SSH, assign each to its own policy-map class with independent policers, then apply the policy-map globally with the service-policy command under control-plane.
D.Configure a QoS policy-map with a priority queue for SSH and apply it outbound on the ISP-facing interfaces.
AnswerC

Separating BGP and SSH into distinct classes with independent policers allows the administrator to rate-limit BGP traffic tightly while guaranteeing SSH a separate, protected bandwidth allocation. Applying the policy-map globally under the control-plane configuration mode enforces policing on all control-plane traffic destined to the route processor, satisfying the requirement to prevent BGP floods from starving management access.

Why this answer

Effective CoPP design uses granular classification so that different control-plane protocols are policed independently. BGP and SSH have very different traffic profiles, so placing them in separate classes with separate policers lets the administrator tightly limit BGP while reserving bandwidth for SSH. The policy-map must then be attached under the control-plane configuration to affect traffic punted to the route processor.

Exam trap

The trap here is assuming that combining related control-plane protocols into one class simplifies CoPP without sacrificing protection for management traffic.

1537
MCQeasy

What is the default IGMP version on a Cisco IOS interface when IP multicast routing is enabled?

A.IGMPv1
B.IGMPv2
C.IGMPv3
D.IGMPv2 is default only if PIM is enabled; otherwise, no IGMP.
AnswerB

IGMPv2 is the correct default on Cisco IOS interfaces when multicast routing is enabled. It introduced the Leave Group message and a querier election mechanism, which makes group membership teardown much faster than IGMPv1, and these features are considered the baseline for IPv4 multicast on IOS. An interface with multicast routing (via a global 'ip multicast-routing' command) running IGMPv2 requires no additional version-specific configuration, so 'ip igmp version' is not present in the running config by default.

Why this answer

When IP multicast routing is enabled on a Cisco IOS interface, the default IGMP version is IGMPv2. This is because IGMPv2 provides the necessary functionality for host membership querying and reporting, including the leave group message, which IGMPv1 lacks. The default is independent of PIM configuration, as IGMP operates at Layer 2/3 for group management, while PIM handles multicast routing between routers.

Exam trap

Cisco often tests the misconception that IGMP version depends on PIM configuration or that IGMPv3 is the default due to its advanced features, but the default is always IGMPv2 on a multicast-enabled interface.

How to eliminate wrong answers

Option A is wrong because IGMPv1 is not the default; it lacks the leave group message and is obsolete for modern multicast deployments. Option C is wrong because IGMPv3 is not the default; it is an advanced version that supports source-specific multicast (SSM) and must be explicitly configured with the 'ip igmp version 3' command. Option D is wrong because IGMPv2 is the default regardless of whether PIM is enabled; IGMP operates on the interface as soon as IP multicast routing is enabled, even without PIM, to manage group memberships.

1538
MCQeasy

A network engineer is troubleshooting a connectivity issue in a switched network. The network uses Rapid PVST+ with multiple VLANs. The engineer notices that a host connected to an access port on SW1 cannot communicate with the default gateway, which is on a distribution switch. The access port is configured with PortFast and BPDU Guard. The engineer checks the switch logs and sees that the port went into errdisable state. What is the most likely cause of the errdisable state?

A.Another switch was connected to the access port, causing BPDU Guard to disable the port.
B.A broadcast storm occurred due to a loop in the network.
C.The host connected to the port caused a duplex mismatch.
D.The cable connecting the host is faulty, causing link flaps.
AnswerA

When an access port is configured with PortFast, it assumes only an end host is attached, and BPDU Guard is often enabled to protect the STP domain. If another switch connects and sends a BPDU, BPDU Guard immediately places the port in errdisable state, which matches the log's reference to BPDU Guard. This is the only option that explains why the port was disabled and why the log specifically cites BPDU Guard.

Why this answer

The access port is configured with PortFast and BPDU Guard. PortFast immediately transitions the port to forwarding, but BPDU Guard monitors for incoming BPDUs. When another switch is connected to this access port, it sends BPDUs, triggering BPDU Guard to error-disable the port to prevent a potential bridging loop.

This matches the log entry showing the port went into errdisable state. Note that BPDU Guard is specifically designed to protect against unauthorized switches, and Root Guard is a separate mechanism used on uplinks.

Exam trap

Cisco often tests the distinction between BPDU Guard (which reacts to BPDUs) and other errdisable causes like loop guard, UDLD, or link-flap; the trap here is assuming that any errdisable on an access port must be due to a physical issue (duplex, cable) rather than a deliberate STP protection mechanism.

How to eliminate wrong answers

Option B is wrong because a broadcast storm due to a loop would typically cause high CPU utilization and potential port flapping, but it would not directly trigger BPDU Guard to error-disable a port; BPDU Guard specifically reacts to BPDU reception, not broadcast storms. Option C is wrong because a duplex mismatch causes CRC errors, late collisions, and performance degradation, but it does not cause BPDU Guard to disable the port; duplex mismatch is detected by interface counters, not by BPDU Guard. Option D is wrong because a faulty cable causing link flaps would result in the port repeatedly going up/down, which could trigger errdisable due to link-flap protection (if configured), but not BPDU Guard; the logs specifically mention errdisable from BPDU Guard, not from link flaps.

1539
Drag & Dropmedium

Drag and drop the steps of RSPAN session configuration and traffic flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with creating a dedicated VLAN for RSPAN traffic, then configuring the source switch to monitor traffic and forward it to that VLAN, followed by configuring the intermediate switches to transport the RSPAN VLAN, then configuring the destination switch to receive and analyze the traffic, and finally verifying end-to-end packet flow.

1540
MCQmedium

A network engineer is configuring a Cisco Catalyst switch to support a new wireless access point that will carry management traffic on VLAN 10 and client traffic on VLAN 20. The AP connects to a single switchport and requires both VLANs to be trunked with 802.1Q tagging, with VLAN 10 as the native VLAN. Which configuration on the switchport will meet these requirements?

A.switchport mode trunk switchport trunk native vlan 10 switchport trunk allowed vlan 10,20
B.switchport mode dynamic auto switchport trunk native vlan 10 switchport trunk allowed vlan 10,20
C.switchport mode access switchport access vlan 10 switchport trunk allowed vlan 20
D.switchport mode trunk switchport trunk encapsulation dot1q switchport trunk native vlan 20 switchport trunk allowed vlan 10,20
AnswerA

This correctly configures the port as an 802.1Q trunk, sets VLAN 10 as the native VLAN (untagged), and allows both VLAN 10 and VLAN 20 on the trunk. The AP can send management traffic untagged on VLAN 10 and tag client traffic for VLAN 20, exactly matching the requirements for the wireless deployment.

Why this answer

The switchport must be configured as a trunk to carry multiple VLANs. Setting the native VLAN to 10 ensures untagged management traffic uses VLAN 10, and allowing VLANs 10 and 20 permits both management and client traffic. The other options either do not enable trunking, set the wrong native VLAN, or use a dynamic mode that may not form a trunk with an access point.

Exam trap

The trap here is assuming that an access point always uses an access port for management, but in this scenario, multiple VLANs require a trunk with a specific native VLAN.

1541
MCQmedium

spanning-tree mode rapid-pvst What is the effect of this global configuration command?

A.The switch will use Rapid PVST+ for all VLANs, providing faster convergence than classic STP.
B.The switch will use MSTP for all VLANs.
C.The switch will use classic STP for all VLANs.
D.The switch will disable STP on all ports.
AnswerA

Rapid PVST+ runs a separate 802.1w instance per VLAN, so each VLAN's topology converges independently using rapid handshake proposals and agreements rather than timers. This satisfies the stem's requirement of faster convergence than classic 802.1D STP while retaining per-VLAN load balancing.

Why this answer

The command 'spanning-tree mode rapid-pvst' enables Rapid PVST+ (Per-VLAN Spanning Tree Plus) on the switch, which runs a separate instance of RSTP (802.1w) for each VLAN. This provides faster convergence than classic STP (802.1D) by using mechanisms such as sync/agreement handshakes, edge ports, and link types, while still maintaining per-VLAN topology independence.

Exam trap

Cisco often tests the distinction between 'rapid-pvst' (RSTP per VLAN) and 'mst' (MSTP, which maps multiple VLANs to fewer instances), and candidates may confuse 'rapid-pvst' with simply enabling RSTP globally without understanding it applies per VLAN.

How to eliminate wrong answers

Option B is wrong because MSTP (Multiple Spanning Tree Protocol, 802.1s) is enabled with the command 'spanning-tree mode mst', not 'rapid-pvst'. Option C is wrong because classic STP (802.1D) is the default mode on many switches or is set with 'spanning-tree mode pvst', not with 'rapid-pvst'. Option D is wrong because the command does not disable STP; STP is disabled globally with 'no spanning-tree vlan <vlan>' or 'spanning-tree mode none' (if supported), not by setting the mode to rapid-pvst.

1542
MCQhard

A network engineer is using Cisco DNA Center's Assurance to troubleshoot a performance issue reported by users on a specific floor. The engineer wants to analyze the path that traffic takes from a client to a server in the data center, including details of each hop such as device, interface, and any ACLs applied. Which Cisco DNA Center Assurance feature provides this information?

A.Application Health
B.Path Trace
C.Client 360
D.Network Health
AnswerB

Path Trace is a Cisco DNA Center Assurance feature that allows you to trace the path of a flow between two endpoints, such as a client and a server. It provides hop-by-hop details, including device names, ingress/egress interfaces, and any ACLs or QoS policies applied. This is exactly what the engineer needs to analyze the traffic path and identify where issues may occur.

Why this answer

Cisco DNA Center Assurance's Path Trace feature provides a visual and detailed hop-by-hop view of the path that traffic takes between two endpoints. It includes information about each device, interface, and any policies applied, making it ideal for troubleshooting performance issues along the path. Other features like Network Health, Client 360, and Application Health do not offer this level of path detail.

Exam trap

The trap here is assuming that Client 360 or Application Health can provide path details; however, only Path Trace is designed to show the complete hop-by-hop path and associated policies.

1543
MCQeasy

A network engineer is new to network automation and wants to use a declarative, agentless tool that uses YAML playbooks to push configuration to Cisco IOS devices over SSH. Which tool should the engineer choose?

A.Puppet
B.SaltStack
C.Ansible
D.Chef
AnswerC

Ansible is a declarative, agentless automation tool that uses YAML playbooks and connects to devices over SSH. It does not require an agent on the managed device, making it ideal for network automation. The scenario describes exactly these characteristics.

Why this answer

Ansible is known for being agentless, using YAML playbooks, and connecting over SSH. These features align perfectly with the engineer's requirements. Puppet and Chef typically require agents and use different configuration languages, while SaltStack, though YAML-based, uses a different architecture and terminology.

Exam trap

The trap here is assuming that any declarative automation tool uses YAML playbooks and is agentless, when in fact Ansible is uniquely characterized by these traits in common network automation contexts.

1544
MCQhard

A network engineer runs the following command on Router R3: R3# show ip nat statistics Total active translations: 5 (0 static, 5 dynamic; 5 extended) Outside interfaces: GigabitEthernet0/0 Inside interfaces: GigabitEthernet0/1 Hits: 1234 Misses: 5 CEF Translated packets: 1200, CEF Punted packets: 34 Expired translations: 10 Dynamic mappings: -- Inside Source [Id] ip nat pool POOL1 203.0.113.1 203.0.113.10 netmask 255.255.255.240 refcount 5 Based on this output, what can be concluded?

A.The NAT pool has exhausted all available addresses.
B.The NAT translations are all static.
C.The router is performing Port Address Translation (PAT).
D.The inside interface is GigabitEthernet0/0.
AnswerC

The router is indeed performing Port Address Translation (PAT), also known as NAT overload. The key clue is that the translation entries are labeled "extended" — this means they include Layer 4 port numbers (TCP/UDP) in addition to IP addresses, allowing many inside hosts to share a single outside public IP. PAT is the standard mechanism for conserving IPv4 addresses in enterprise and home networks, and it is confirmed by the presence of extended dynamic translations in the output.

Why this answer

The output shows 5 dynamic translations with an 'extended' type, which indicates that the router is using Port Address Translation (PAT) because extended translations include both IP address and port number. Additionally, the NAT pool POOL1 has a range of 203.0.113.1 to 203.0.113.10 (10 addresses), but there are 5 active translations, which would be impossible with basic NAT unless PAT is used to multiplex multiple inside hosts to the same outside IP via unique port numbers.

Exam trap

Cisco often tests the distinction between 'dynamic' and 'extended' translations in 'show ip nat statistics' output, where candidates mistakenly assume 'dynamic' means basic NAT, but 'extended' is the key indicator of PAT (overload) being used.

How to eliminate wrong answers

Option A is wrong because the NAT pool has 10 available addresses (203.0.113.1 through 203.0.113.10), and only 5 translations are active, so addresses are not exhausted. Option B is wrong because the output explicitly states '0 static, 5 dynamic' translations, so the translations are all dynamic, not static. Option D is wrong because the output shows 'Inside interfaces: GigabitEthernet0/1', not GigabitEthernet0/0, which is listed as the outside interface.

1545
MCQmedium

A network architect is designing a Cisco SD-Access fabric for a large campus. The architect needs to ensure that the fabric can scale to support thousands of endpoints and that the control plane uses a dedicated protocol for endpoint registration and location. Which component of the SD-Access architecture provides this control plane function?

A.Cisco Identity Services Engine
B.Cisco DNA Center
C.VXLAN tunnel endpoints
D.LISP map server and map resolver
AnswerD

In Cisco SD-Access, the control plane is based on LISP (Locator/ID Separation Protocol). The map server and map resolver (often co-located on control plane nodes) maintain the mapping of endpoint identifiers (EIDs) to routing locators (RLOCs). This enables scalable endpoint registration and location without flooding, which is essential for large fabrics supporting thousands of endpoints.

Why this answer

The SD-Access fabric uses LISP as its control plane protocol. The map server and map resolver maintain the endpoint ID-to-routing locator mappings, allowing fabric edge nodes to register endpoints and query for their locations. This design eliminates the need for flooding and supports large-scale deployments.

DNA Center, VXLAN VTEPs, and ISE serve different roles: management, data forwarding, and policy/identity, respectively.

Exam trap

The trap here is confusing the management platform (DNA Center) with the control plane protocol (LISP), or assuming that VXLAN handles endpoint registration.

1546
Matchingmedium

Drag and drop each flow record field on the left to its matching category (key or non-key) on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Key field

Key field

Key field

Non-key field

Non-key field

Why these pairings

Key fields define a unique flow (e.g., source IP, destination IP, protocol). Non-key fields provide additional data (e.g., byte count, packet count, timestamps).

1547
MCQhard

A network engineer is troubleshooting a Cisco SD-WAN deployment where a branch router (vEdge) is not forming a control connection with the vSmart controller. The engineer verifies that the vEdge has IP reachability to the vSmart controller's public IP address on port 12346. Which additional step is required for the control connection to be established?

A.The vEdge must have OSPF configured to advertise its loopback interface to the vSmart controller.
B.The vEdge must have a valid certificate installed and be authenticated by the vBond orchestrator.
C.The vEdge must be configured with a static route to the vSmart controller's private IP address.
D.The vEdge must be configured with the vSmart controller's IP address as its default gateway.
AnswerB

In Cisco SD-WAN, the vEdge router must authenticate with the vBond orchestrator to obtain the list of vSmart controllers and establish control connections. This requires a valid certificate installed during onboarding. Without proper authentication, the vEdge cannot join the overlay network, even if IP reachability exists.

Why this answer

For a vEdge to establish a control connection with a vSmart controller, it must first authenticate with the vBond orchestrator using its certificate. This process provides the vEdge with the necessary information, including the vSmart's IP address and credentials to establish the DTLS control connection. IP reachability alone is insufficient.

Exam trap

The trap here is assuming that IP reachability to the vSmart controller is enough for the control connection, overlooking the mandatory authentication and certificate exchange with the vBond orchestrator.

1548
MCQhard

A network engineer is troubleshooting an issue where Cisco DNA Center is not sending configuration changes to a group of switches. The engineer checks the Provisioning dashboard and sees that the devices are in 'Pending' state. The engineer has already created the intent (network profile) and assigned it to the site. What is the most likely cause?

A.The engineer has not executed the Provision workflow to deploy the configuration.
B.The devices are not reachable from DNA Center.
C.The DNA Center appliance is out of disk space.
D.The network profile contains an invalid configuration.
AnswerA

Devices remain in 'Pending' until the Provision workflow is explicitly run; creating and assigning the network profile only defines intent. Cisco DNA Center does not push configuration automatically on assignment, so the engineer must select the devices and execute Provision to deploy the configuration and clear the pending state.

Why this answer

In Cisco DNA Center, after creating an intent (network profile) and assigning it to a site, the configuration is not automatically deployed to devices. The engineer must explicitly run the Provision workflow to push the configuration to the devices. The 'Pending' state indicates that the devices are awaiting provisioning.

Exam trap

350-401 often tests the misconception that assigning a network profile automatically deploys configurations; candidates must remember that provisioning is a separate, explicit action.

How to eliminate wrong answers

Option B is wrong because if devices were unreachable, they would likely show as 'Unreachable' or 'Unmanaged' rather than 'Pending'. Option C is wrong because disk space issues would typically cause broader system failures, not just a 'Pending' state for specific devices. Option D is wrong because an invalid configuration would usually result in a validation error during provisioning, not a 'Pending' state; the devices are simply waiting for the provision action.

1549
MCQmedium

interface GigabitEthernet0/1 spanning-tree portfast spanning-tree bpduguard enable end What is the effect of this configuration?

A.The port will immediately transition to forwarding state and will be error-disabled if a BPDU is received.
B.The port will go through normal STP states and will be error-disabled if a BPDU is received.
C.The port will immediately transition to forwarding and ignore any BPDUs received.
D.The port will remain in blocking state until a BPDU is received.
AnswerA

Enabling PortFast on a switchport causes it to bypass the STP listening and learning states and transition directly to forwarding, which is appropriate for host-facing access ports. If BPDU Guard is also enabled on that port, any received BPDU—which should never arrive from an end host—is treated as a misconfiguration, and the port is immediately placed into the error-disabled state. This protects the access domain from accidental loops or rogue switch connections, and the port stays in error-disable until manual intervention or an errdisable recovery timer is configured.

Why this answer

The `spanning-tree portfast` command causes the port to immediately transition to the forwarding state, bypassing the listening and learning states. The `spanning-tree bpduguard enable` command places the port in an error-disabled state if any BPDU is received, as BPDU reception on a PortFast-enabled port indicates an unauthorized switch connection, which could cause a bridging loop.

Exam trap

Cisco often tests the misconception that BPDUguard ignores BPDUs or that PortFast still goes through STP states, but the key trap is that BPDUguard error-disables the port upon BPDU reception, not just ignores or blocks it.

How to eliminate wrong answers

Option B is wrong because PortFast causes immediate transition to forwarding, not normal STP states. Option C is wrong because BPDUguard does not ignore BPDUs; it error-disables the port upon BPDU reception. Option D is wrong because PortFast immediately transitions to forwarding, not remaining in blocking state, and BPDUguard does not require a BPDU to unblock.

1550
Multi-Selectmedium

Which two statements about using Python for configuration management and templating in network automation are true? (Choose two.)

Select 2 answers
A.Jinja2 templates allow the use of variables and control structures like loops and conditionals to generate network device configurations.
B.A Python script can load a Jinja2 template, render it with device-specific data, and push the resulting configuration to a network device.
C.Jinja2 can be used to execute CLI commands on network devices directly from within the template.
D.Jinja2 is a Python library used for parsing YAML files.
E.Python cannot be used to generate configuration files because it lacks templating capabilities.
AnswersA, B

Jinja2 is a text templating engine, so variables, for loops, and if conditionals let one template generate many device-specific configurations. This satisfies the scenario's templating requirement, unlike plain string concatenation, which cannot express conditional or repeated configuration blocks.

Why this answer

Option A is correct because Jinja2 is a templating engine that supports variables, loops ({% for %}), and conditionals ({% if %}), which are used to dynamically generate network device configurations. Option B is correct because a typical Python automation workflow loads a Jinja2 template, renders it with device-specific data (e.g., from YAML/JSON), and then pushes the rendered configuration to the device via libraries like Netmiko or NAPALM. Option C is incorrect because Jinja2 only renders text; it cannot execute CLI commands on devices—that requires a separate connection library.

Option D is incorrect because Jinja2 is a templating engine, not a YAML parser; YAML parsing is handled by libraries like PyYAML. Option E is incorrect because Python, combined with Jinja2, is widely used to generate configuration files.

Exam trap

350-401 often tests the misconception that Jinja2 can execute device commands or parse YAML, when it is strictly a text templating engine that must be paired with separate libraries for I/O and parsing.

1551
MCQmedium

Given the following configuration on a Cisco IOS-XE device: router ospf 1 network 10.0.0.0 0.255.255.255 area 0 ! interface GigabitEthernet0/0 ip address 10.1.1.1 255.255.255.0 ip ospf cost 10 ! interface GigabitEthernet0/1 ip address 10.2.2.1 255.255.255.0 ! Which statement is true about OSPF operation?

A.Both interfaces will have an OSPF cost of 10.
B.GigabitEthernet0/0 will have an OSPF cost of 10, and GigabitEthernet0/1 will have a default cost based on its bandwidth.
C.Both interfaces will have the same OSPF cost because they are in the same area.
D.OSPF will not run on either interface because the network command uses a wildcard mask of 0.255.255.255.
AnswerB

The interface-level ip ospf cost 10 overrides the reference-bandwidth calculation on GigabitEthernet0/0, fixing its cost at 10. GigabitEthernet0/1 has no explicit cost, so IOS-XE derives the default from its bandwidth. Both interfaces fall within network 10.0.0.0 0.255.255.255 area 0.

Why this answer

The ip ospf cost 10 command is applied only to GigabitEthernet0/0, explicitly setting its OSPF cost to 10. GigabitEthernet0/1 does not have a cost configured, so OSPF will use the default cost calculated from the interface's bandwidth (reference bandwidth divided by interface bandwidth). Therefore, GigabitEthernet0/0 has cost 10, and GigabitEthernet0/1 has the default cost.

Exam trap

The trap here is assuming that a cost configured on one interface applies to all interfaces in the same area, or misunderstanding the wildcard mask in the network command.

How to eliminate wrong answers

Option A is wrong because the cost is configured only on GigabitEthernet0/0; GigabitEthernet0/1 does not inherit that cost. Option C is wrong because OSPF cost is per-interface and not determined by the area; interfaces in the same area can have different costs. Option D is wrong because the network command with wildcard 0.255.255.255 matches any interface with an IP address in the 10.0.0.0/8 range, which includes both 10.1.1.1 and 10.2.2.1, so OSPF will run on both interfaces.

1552
MCQmedium

A network engineer runs the following command on a Cisco WLC: WLC# show ap rf-profile summary RF-Profile Name: default-rf-profile Description: Default RF Profile Band: 2.4 GHz Channel Width: 20 MHz Data Rates: 1,2,5.5,11,6,9,12,18,24,36,48,54 Mbps Power Level: 1 (max) RF-Profile Name: low-power Description: Low Power Profile Band: 2.4 GHz Channel Width: 20 MHz Data Rates: 1,2,5.5,11,6,9,12,18,24,36,48,54 Mbps Power Level: 5 Based on this output, what can be concluded?

A.The low-power profile reduces the transmit power of the AP.
B.The default profile uses 40 MHz channels.
C.The low-power profile disables all data rates below 12 Mbps.
D.The low-power profile is for 5 GHz band.
AnswerA

The low-power profile in Cisco APs selects a lower transmit power level (for example, level 5 as opposed to level 1), which directly reduces the RF power emitted by the AP. This shrinks the cell coverage area, allowing for denser AP deployment with less co-channel overlap and interference. It is purely a transmit-power adjustment; it does not change channel width, data rates, or band.

Why this answer

The 'Power Level: 5' in the low-power profile indicates a lower transmit power setting compared to 'Power Level: 1 (max)' in the default profile. On Cisco WLCs, power levels are numbered inversely to actual transmit power, with higher numbers representing lower power output. Therefore, the low-power profile reduces the AP's transmit power.

Exam trap

Cisco often tests the inverse relationship between power level numbers and actual transmit power, where candidates mistakenly think a higher power level means higher power output.

How to eliminate wrong answers

Option B is wrong because the default profile explicitly shows 'Channel Width: 20 MHz', not 40 MHz. Option C is wrong because the low-power profile lists the same data rates (including 1, 2, 5.5, 11 Mbps) as the default profile, so no rates below 12 Mbps are disabled. Option D is wrong because the low-power profile clearly specifies 'Band: 2.4 GHz', not the 5 GHz band.

1553
MCQmedium

An enterprise is migrating its data center to a leaf-spine architecture to support high east-west traffic between servers. The design must provide non-blocking forwarding and allow for easy scaling by adding more spines. Which characteristic is essential for the spine switches in this design?

A.Spine switches must run Spanning Tree Protocol (STP) to prevent loops
B.Spine switches must support high port density and high forwarding capacity, and act as Layer 3 routers
C.Spine switches must be connected to each other to provide redundancy
D.Spine switches must perform NAT to translate between VLANs
AnswerB

The spine layer is the fabric's core, aggregating all leaf switches, so it must have high port density to terminate connections from every leaf, and high forwarding capacity (throughput and packet-per-second) to handle the aggregate east-west traffic without oversubscription. As a Layer 3 router, each spine forwards IP packets between subnets using the routing table, not MAC addresses, and leverages Equal-Cost Multipath (ECMP) to spread flows across all available leaf links. This makes the spine the critical scale and performance bottleneck in the design.

Why this answer

In a leaf-spine architecture designed for non-blocking forwarding and high east-west traffic, spine switches must act as Layer 3 routers with high port density and forwarding capacity. This allows them to perform Equal-Cost Multi-Path (ECMP) routing, which distributes traffic across all available uplinks without blocking, ensuring that any leaf can reach any other leaf with predictable latency and full bandwidth utilization.

Exam trap

Cisco often tests the misconception that STP is needed in all redundant switch designs, but in a Layer 3 leaf-spine architecture, STP is not used because routing protocols inherently prevent loops and allow all links to be active.

How to eliminate wrong answers

Option A is wrong because Spanning Tree Protocol (STP) is a Layer 2 loop-prevention mechanism that actively blocks redundant links, which would defeat the purpose of a non-blocking leaf-spine design where all links must be active and forwarding. Option C is wrong because spine switches are never directly connected to each other in a valid leaf-spine topology; doing so would create a Layer 3 routing loop or a Layer 2 loop, and redundancy is achieved by having multiple spine switches, not by interconnecting them. Option D is wrong because NAT is used for translating between private and public IP addresses, not for inter-VLAN routing; in a leaf-spine design, inter-VLAN routing is performed by the spine switches using Layer 3 forwarding (e.g., OSPF or BGP), not NAT.

1554
MCQeasy

An engineer is configuring a new VLAN 100 on a switch. Which command must be used to create the VLAN?

A.vlan 100
B.switchport access vlan 100
C.vlan database
D.interface vlan 100
AnswerA

The global configuration command 'vlan 100' creates VLAN 100 and enters VLAN configuration mode, allowing optional parameters such as a name or MTU to be applied. This is the standard and correct method to create a VLAN on modern Cisco IOS switches, as it directly adds the VLAN to the switch's VLAN database and running configuration. Without this command, other VLAN-related commands have no VLAN to act upon.

Why this answer

The correct command to create a new VLAN on a Cisco IOS switch is 'vlan 100' entered in global configuration mode. This command creates VLAN 100 and enters VLAN configuration mode, allowing you to assign a name or other parameters. The other options either apply an existing VLAN to an interface, use a deprecated method, or create a switched virtual interface (SVI) for Layer 3 routing, none of which actually create the VLAN itself.

Exam trap

Cisco often tests the distinction between creating a VLAN and applying it to an interface, so candidates mistakenly choose 'switchport access vlan 100' thinking it both creates and assigns the VLAN, when in fact it only assigns an existing VLAN.

How to eliminate wrong answers

Option B is wrong because 'switchport access vlan 100' assigns an interface to VLAN 100, but it does not create the VLAN; if VLAN 100 does not exist, the command may fail or the interface will be in an inactive state. Option C is wrong because 'vlan database' is a legacy, deprecated command from older Catalyst OS (CatOS) and is not used in modern IOS-based switches; it does not create VLANs in the running configuration. Option D is wrong because 'interface vlan 100' creates a Layer 3 switched virtual interface (SVI) for routing, but it does not create the VLAN itself; the VLAN must already exist or be created separately before the SVI can be used.

1555
MCQmedium

A network administrator issues the following command on a Cisco switch: Switch# show aaa servers RADIUS: id 1, priority 1, host 192.168.1.10, auth-port 1812, acct-port 1813 State: current UP, duration 3600s, previous duration 0s Dead: total 0, retransmit 0 RADIUS: id 2, priority 2, host 192.168.1.20, auth-port 1812, acct-port 1813 State: current UP, duration 100s, previous duration 300s Dead: total 3, retransmit 2 Based on this output, what can be concluded?

A.Both RADIUS servers are currently unreachable.
B.Server 192.168.1.20 has a history of failures.
C.Server 192.168.1.10 is the backup server.
D.TACACS+ is also configured on these servers.
AnswerB

The output shows a 'dead total' of 3 for 192.168.1.20, meaning the server has been marked dead three times. Additionally, the retransmit count of 2 indicates that on at least one occasion, two retransmissions were necessary before a response, suggesting intermittent performance or failure. While the server is currently UP, this historical data confirms past unreachability or timeouts.

Why this answer

The output shows that server 192.168.1.20 has a 'Dead: total 3' and 'retransmit 2', indicating it has been marked dead three times and two retransmissions occurred, confirming a history of failures. In contrast, server 192.168.1.10 shows 'Dead: total 0, retransmit 0', meaning it has no failure history. The 'current UP' state for both servers only reflects their present status, not their reliability history.

Exam trap

Cisco often tests the distinction between a server's current operational state (UP/DOWN) and its historical reliability (Dead/retransmit counters), leading candidates to mistakenly assume that a 'current UP' state implies no past failures.

How to eliminate wrong answers

Option A is wrong because both servers show 'State: current UP', meaning they are currently reachable, not unreachable. Option C is wrong because server 192.168.1.10 has priority 1, which is the primary server, not the backup; the backup would have a higher priority number (e.g., priority 2). Option D is wrong because the output only displays RADIUS server information from the 'show aaa servers' command; TACACS+ servers would appear in a separate section or require a different command, and there is no evidence of TACACS+ configuration here.

1556
Drag & Dropmedium

Drag and drop the steps of WLC high availability SSO failover steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In HA SSO, the active WLC fails, the standby detects the failure via RP link, takes over the active role, reinitializes interfaces, and then clients reassociate to the new active WLC.

1557
Multi-Selectmedium

Which two statements about virtual machine migration (vMotion/VMware) or live migration (Hyper-V) are true? (Choose two.)

Select 2 answers
A.During live migration, the virtual machine must be powered off to transfer memory contents.
B.Live migration copies the memory state of the VM from the source host to the destination host while the VM continues to run.
C.Live migration requires that both source and destination hosts use the same shared storage for the VM's virtual disks.
D.Both source and destination hosts must have compatible CPU feature sets to ensure the VM does not encounter instruction errors after migration.
E.After a live migration, the virtual machine's IP address changes to match the new network segment.
AnswersB, D

Live migration achieves near-zero downtime by iteratively copying memory pages to the destination while the VM keeps running, then briefly pausing to transfer the final dirty pages and CPU state. This satisfies the stem's requirement that the VM continues to run throughout the migration.

Why this answer

Option B is correct because live migration (Hyper-V) and vMotion (VMware) are designed to transfer the running VM's memory state, including the active memory pages and CPU register state, from the source host to the destination host while the VM remains powered on and continues servicing requests, with only a brief pause during the final switchover. Option D is correct because the destination host's processor must expose a compatible CPU feature set (e.g., matching instruction set extensions such as SSE4.2, AVX, or NX/DEP) so that the migrated VM does not execute instructions unsupported by the new physical CPU; VMware uses Enhanced vMotion Compatibility (EVC) baselines and Hyper-V uses processor compatibility mode to mask differences. Option A is wrong because live migration explicitly avoids powering off the VM; that describes a cold migration instead.

Option C is wrong because shared storage is not strictly required — vMotion can use shared storage, but Hyper-V live migration and VMware vMotion also support migrating the VM's virtual disks (storage migration) or using SMB 3.0/CSV paths without identical shared storage. Option E is wrong because live migration preserves the VM's network identity, including its IP address, since the virtual NIC and its configuration move with the VM; the IP does not change unless the guest OS or network configuration is altered.

1558
MCQhard

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer wants to ensure that only routers with the correct key can form adjacencies, and that the key is not sent in clear text. Which command sequence correctly enables MD5 authentication on an interface?

A.ip ospf authentication-key <key> and ip ospf authentication
B.ip ospf authentication message-digest and ip ospf message-digest-key 1 md5 <key>
C.area 0 authentication message-digest and ip ospf message-digest-key 1 md5 <key>
D.ip ospf authentication null and ip ospf message-digest-key 1 md5 <key>
AnswerB

The interface-level command ip ospf authentication message-digest enables MD5 authentication for OSPF on that interface. The ip ospf message-digest-key command defines the key ID and MD5 key. Together, they satisfy the requirement to authenticate neighbors using MD5 without sending the key in clear text.

Why this answer

To enable MD5 authentication on a specific OSPF interface, you use the interface command ip ospf authentication message-digest and then define the key with ip ospf message-digest-key. This ensures that OSPF packets are authenticated with MD5 and the key is not transmitted in clear text, meeting the scenario's security requirement.

Exam trap

The trap here is confusing plaintext authentication with MD5, or using area-wide authentication when interface-level is required, which can leave other interfaces unprotected or misconfigured.

1559
MCQhard

An enterprise network is experiencing high CPU utilization on the distribution layer switches. The design uses VLANs with SVIs for inter-VLAN routing, and HSRP for first-hop redundancy. The engineer notices that the standby switch is also experiencing high CPU. What is the most likely cause?

A.The standby switch is processing HSRP hellos for all VLANs, causing CPU spikes.
B.The standby switch is forwarding all broadcast traffic due to a misconfigured STP root.
C.The standby switch is performing routing for all VLANs because the active switch failed.
D.The standby switch is processing VTP updates from the distribution layer.
AnswerA

Each VLAN configured for HSRP creates a separate HSRP group, and the standby switch must process multicast hello packets (normally sent every 3 seconds) for every one of those groups. With hundreds of VLANs, the cumulative volume of hello packets—each requiring CPU interrupt handling, state-machine updates, and authentication checks—can saturate the control plane and manifest as CPU spikes. This makes HSRP hello processing the most plausible cause of standby CPU utilization in a large L3-access design.

Why this answer

In an HSRP setup, both the active and standby routers process incoming Hello messages for every VLAN on which HSRP is configured. Even though the standby switch does not forward inter-VLAN traffic, it must still receive and process periodic HSRP hellos (default every 3 seconds) to maintain its role and detect active failures. With a large number of VLANs, the cumulative CPU overhead from processing these hellos can cause high utilization on both switches.

Exam trap

Cisco often tests the misconception that the standby switch is idle or only processes traffic during failover, when in reality it must continuously process HSRP hellos for every configured group, which can become a significant CPU burden in large VLAN deployments.

How to eliminate wrong answers

Option B is wrong because broadcast traffic is forwarded based on the VLAN's STP topology, not the HSRP role; a misconfigured STP root could cause suboptimal forwarding but would not specifically cause high CPU on the standby switch. Option C is wrong because if the active switch had failed, the standby would transition to active and begin routing, but the question states both switches are experiencing high CPU simultaneously, not that a failover occurred. Option D is wrong because VTP updates are processed by all switches in the same VTP domain regardless of HSRP state, and VTP processing is typically minimal unless large topology changes occur; it would not selectively cause high CPU on the standby.

1560
Multi-Selecteasy

Which two statements about VRF-lite configuration are true? (Choose two.)

Select 2 answers
A.In VRF-lite, each VRF maintains its own independent routing table.
B.Interfaces are assigned to a VRF using the 'ip vrf forwarding' command under interface configuration.
C.VRF-lite requires MPLS enabled on all interfaces.
D.VRF-lite can only use static routes for inter-VRF communication.
E.A router can have at most two VRFs configured.
AnswersA, B

VRF-lite achieves path isolation by giving each VRF a separate RIB and FIB, so overlapping prefixes between tenants never conflict. This satisfies the requirement for independent per-VRF forwarding decisions on a single physical device, without MPLS labels.

Why this answer

Option A is correct because VRF-lite creates separate virtual routing and forwarding instances, each with its own independent routing and forwarding table (RIB/FIB), which is the core purpose of VRF-lite—traffic isolation without MPLS. Option B is correct because on Cisco IOS/IOS-XE, an interface is bound to a VRF by entering interface configuration mode and issuing the 'ip vrf forwarding <vrf-name>' command, which associates the interface's Layer 3 traffic with that VRF's routing table. Option C is incorrect because VRF-lite specifically does not require MPLS; it is the MPLS-free variant of VRF used for path isolation on a single device or with plain 802.1Q trunks.

Option D is incorrect because inter-VRF communication can be achieved with various methods, including route leaking via static routes, dynamic routing protocols, or external devices—not static routes exclusively. Option E is incorrect because a router can support many VRFs (hundreds or thousands depending on platform resources), not a maximum of two.

Exam trap

The trap here is confusing VRF-lite with MPLS L3VPN — candidates often assume MPLS is required, but VRF-lite is explicitly the MPLS-free variant, and it supports many VRFs, not just two.

1561
Matchingmedium

Drag and drop each YANG statement on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Groups related nodes into a subtree

Defines a single scalar value node

Defines a sequence of entries with keys

Defines an array of scalar values

Defines a derived type from an existing base type

Why these pairings

In YANG, container groups related nodes, leaf holds a single scalar value, list defines a sequence of entries, leaf-list is an array of scalar values, and typedef defines a derived type.

1562
Multi-Selecthard

A network engineer is deploying MACsec on a Catalyst switch uplink between two buildings to protect Layer 2 traffic. Which two statements about MACsec operation on Cisco Catalyst switches are true? (Choose two.)

Select 2 answers
A.MACsec encrypts traffic end to end from the originating host to the final destination host across all intermediate routers.
B.MACsec requires an MKA session and a connectivity association key to establish secure associations between peers.
C.MACsec replaces 802.1X and removes the need for any authentication server in the network.
D.MACsec provides hop-by-hop encryption and integrity for Ethernet frames using the 802.1AE standard.
E.MACsec can be deployed only on routed ports and is incompatible with switch access ports.
AnswersB, D

The MACsec Key Agreement protocol negotiates session keys between peers using a connectivity association key, which can be provided statically or derived through 802.1X. Without a successful MKA session, the link will not pass protected traffic. This key management layer distinguishes MACsec from simple link encryption and ensures both ends agree on cipher suites and key material.

Why this answer

MACsec secures individual Ethernet links using 802.1AE encryption and integrity, and it relies on MKA with a connectivity association key to negotiate secure associations between peers. Because it operates hop by hop, each device along the path must participate, and it does not replace 802.1X or provide end-to-end encryption across a routed network.

Exam trap

The trap here is treating MACsec as end-to-end encryption when it actually protects each Layer 2 hop independently.

1563
MCQhard

A network engineer is configuring a GETVPN solution for a large enterprise with many remote sites. The engineer wants to ensure that all traffic between sites is encrypted using a common group key. The key server (KS) is a Cisco ASR 1000. After configuration, the group members (GMs) can register with the KS, but traffic between GMs is not encrypted. The engineer checks the KS configuration and sees that the crypto gdoi group has been defined with a transform set and a security association. What is the most likely missing configuration?

A.The KS is missing an access list to define the traffic to encrypt.
B.The group name on the GMs does not match the KS.
C.The KS is not configured with an IPsec profile.
D.The GMs are in different IP subnets than the KS.
AnswerA

In GETVPN, the key server (KS) defines which traffic is encrypted by creating a group policy that includes an extended access-list as the traffic selector. If this ACL is missing, the KS has no 'interesting traffic' to bind to the GDOI security association, so even though GMs may register successfully, they receive no encryption policy. As a result, no traffic is encrypted between GMs.

Why this answer

In GETVPN, the Key Server (KS) distributes the common group key, but the actual encryption of traffic between Group Members (GMs) is controlled by an access list (ACL) that defines which traffic should be encrypted. Without this ACL on the KS, the GMs receive the key but have no policy specifying which packets to encrypt, so traffic between GMs remains unencrypted. The correct configuration requires an ACL under the crypto gdoi group to identify the protected traffic (e.g., permit ip 10.0.0.0 0.255.255.255 10.0.0.0 0.255.255.255).

Exam trap

Cisco often tests the misconception that a transform set and SA alone are sufficient for encryption, but in GETVPN the traffic selector (ACL) is mandatory and must be defined on the KS to be pushed to GMs.

How to eliminate wrong answers

Option B is wrong because if the group name on the GMs did not match the KS, the GMs would fail to register with the KS entirely, but the scenario states that GMs can register successfully. Option C is wrong because GETVPN does not use an IPsec profile on the KS; IPsec profiles are used in FlexVPN or DMVPN, not in GDOI-based GETVPN. Option D is wrong because GETVPN is designed to work across different subnets; the GMs can be in different IP subnets than the KS and still encrypt traffic between them, as long as the KS is reachable for registration and rekey.

1564
MCQhard

A network engineer is designing a Cisco SD-Access fabric for a campus network. The fabric must support both wired and wireless clients, and the engineer wants to ensure that traffic from wired endpoints is encapsulated and forwarded through the fabric without requiring the endpoints to change their IP addresses. Which component of the SD-Access architecture is responsible for encapsulating traffic from wired endpoints and forwarding it to the fabric edge?

A.Control plane node
B.Fabric edge node
C.Fabric intermediate node
D.Fabric border node
AnswerB

The fabric edge node is responsible for encapsulating traffic from wired endpoints using VXLAN and forwarding it to the fabric. It acts as the first-hop router for endpoints and registers them with the control plane node. This component is essential for wired client integration in SD-Access, as it provides the anycast gateway and encapsulation functions.

Why this answer

In Cisco SD-Access, the fabric edge node is the device that connects wired endpoints to the fabric. It encapsulates traffic from wired endpoints into VXLAN and forwards it to the destination fabric edge node based on the control plane mapping. This allows endpoints to keep their IP addresses and be part of a virtual network without re-addressing.

Exam trap

The trap here is confusing the role of the fabric edge node with that of the border node, assuming that any fabric device can encapsulate endpoint traffic.

1565
MCQhard

A network engineer runs the following command on Switch SW3: SW3# show monitor session 3 Session 3 --------- Type : Remote Destination Session Source RSPAN VLAN : 100 Destination Ports : Gi1/0/15 Encapsulation : Native Ingress : Disabled Based on this output, what can be concluded?

A.This switch receives mirrored traffic from the RSPAN VLAN and sends it to Gi1/0/15.
B.This is a local SPAN session with source VLAN 100.
C.The RSPAN VLAN 100 is used to send traffic to a remote switch.
D.Ingress traffic on Gi1/0/15 is forwarded to the RSPAN VLAN.
AnswerA

A Remote Destination Session is configured on the switch that terminates the RSPAN session. This switch has source RSPAN VLAN 100, meaning it receives mirrored frames from that VLAN and copies them out Gi1/0/15, which is the analyzer port. The destination port is an egress-only monitor port, so the statement accurately describes the data flow.

Why this answer

The output shows a Remote Destination Session, meaning this switch (SW3) is the destination switch in an RSPAN configuration. It receives mirrored traffic from RSPAN VLAN 100 and forwards it out of the destination port Gi1/0/15, typically to a monitoring device. The 'Ingress: Disabled' confirms that traffic entering Gi1/0/15 is not being injected back into the switch.

Exam trap

Cisco often tests the distinction between source and destination RSPAN sessions, and the trap here is confusing the role of the RSPAN VLAN—candidates may think it is used to send traffic away from the switch rather than receive mirrored traffic for local monitoring.

How to eliminate wrong answers

Option B is wrong because the session type is 'Remote Destination Session', not 'Local SPAN', and the source is an RSPAN VLAN, not a source VLAN for local SPAN. Option C is wrong because RSPAN VLAN 100 is used to carry mirrored traffic from source switches to this destination switch, not to send traffic to a remote switch from this switch. Option D is wrong because ingress on Gi1/0/15 is disabled, meaning traffic entering that port is not forwarded to the RSPAN VLAN; the RSPAN VLAN is the source of mirrored traffic, not a destination for ingress traffic.

1566
Matchingmedium

Drag and drop each SNMP operation on the left to its matching direction on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Manager requests a specific variable from agent

Manager requests the next variable in a MIB tree

Manager requests a large block of data efficiently

Manager modifies a variable on the agent

Agent sends unsolicited notification to manager

Why these pairings

GET, GETNEXT, GETBULK, and SET are initiated by the manager; TRAP and INFORM are initiated by the agent.

1567
Multi-Selecthard

Which three statements about MPLS forwarding are true? (Choose three.)

Select 3 answers
A.MPLS forwarding uses the Label Forwarding Information Base (LFIB) to make forwarding decisions.
B.The LFIB is populated by label distribution protocols such as LDP.
C.The LIB stores all labels learned from LDP neighbors, but the LFIB is used for actual forwarding.
D.MPLS forwarding uses the Forwarding Information Base (FIB) for label lookups.
E.MPLS forwarding uses the Routing Information Base (RIB) to determine the next hop.
AnswersA, B, C

MPLS forwarding is label-swapping driven: the LFIB maps an incoming label and interface to an outgoing label and next hop, and the router consults it for every labelled packet. This makes the LFIB the authoritative data plane structure for forwarding decisions.

Why this answer

Option A is correct because MPLS forwarding decisions are made by matching the incoming label against the Label Forwarding Information Base (LFIB), which maps an incoming label to an outgoing label and next-hop interface. Option B is correct because the LFIB is populated by label distribution protocols such as LDP, which binds labels to routes and advertises them to neighbors. Option C is correct because the Label Information Base (LIB) holds all label bindings learned from LDP neighbors, while the LFIB contains only the best/selected entries actually used for forwarding labeled packets.

Option D is incorrect because the FIB is used for IP forwarding lookups, not for MPLS label lookups. Option E is incorrect because the RIB is used by routing protocols to select best routes and populate the FIB/LFIB, but it is not consulted directly for MPLS forwarding decisions.

Exam trap

The trap is mixing up the LIB and LFIB: candidates often think the LIB is used for forwarding, but the LIB is the control-plane database of all learned labels, while the LFIB is the forwarding table with only the best entries.

1568
MCQmedium

Examine the following configuration on a Cisco IOS-XE switch: interface GigabitEthernet0/5 switchport mode trunk switchport trunk native vlan 999 switchport trunk allowed vlan 10,20,30 switchport nonegotiate What is the effect of the 'switchport nonegotiate' command?

A.The interface will not send DTP frames, but will still respond to incoming DTP frames.
B.The interface will not send or process DTP frames, and remains a trunk.
C.The interface will revert to an access port.
D.The interface will negotiate trunking using ISL instead of DTP.
AnswerB

This is correct. 'switchport nonegotiate' completely disables DTP after 'switchport mode trunk' is configured, so no DTP frames are sent or processed. The interface remains a statically configured trunk, because nonegotiate only suppresses trunk negotiation and does not alter the forced trunk mode.

Why this answer

The 'switchport nonegotiate' command disables Dynamic Trunking Protocol (DTP) on the interface. When configured on a trunk port, the interface will neither send nor process any DTP frames, ensuring the port remains in trunk mode regardless of the neighbor's DTP configuration. This is commonly used when connecting to non-Cisco devices that do not support DTP, or to prevent unwanted trunk negotiation.

Exam trap

Cisco often tests the misconception that 'switchport nonegotiate' only stops sending DTP frames but still allows the interface to respond to them, when in fact it disables all DTP processing, both sending and receiving.

How to eliminate wrong answers

Option A is wrong because 'switchport nonegotiate' prevents the interface from both sending and processing DTP frames; it does not allow the interface to respond to incoming DTP frames. Option C is wrong because the interface does not revert to an access port; it remains a trunk as explicitly configured with 'switchport mode trunk'. Option D is wrong because DTP is used to negotiate either ISL or 802.1Q trunking, but 'switchport nonegotiate' disables DTP entirely, not switches to ISL negotiation.

1569
MCQhard

A network engineer is deploying a new Cisco Catalyst switch and must ensure that the management VLAN 50 is the only VLAN allowed on the trunk link to the distribution switch, while also ensuring that the native VLAN matches on both ends. The distribution switch is already configured with switchport trunk native vlan 999 and switchport trunk allowed vlan 50. Which configuration on the new switch will satisfy these requirements?

A.interface GigabitEthernet0/1 switchport mode dynamic desirable switchport trunk native vlan 999 switchport trunk allowed vlan 50
B.interface GigabitEthernet0/1 switchport mode trunk switchport trunk native vlan 999 switchport trunk allowed vlan 50
C.interface GigabitEthernet0/1 switchport mode trunk switchport trunk native vlan 50 switchport trunk allowed vlan 50
D.interface GigabitEthernet0/1 switchport mode trunk switchport trunk allowed vlan 50 switchport trunk native vlan 1
AnswerB

This configuration sets the port as a trunk, matches the native VLAN to 999, and restricts allowed VLANs to 50. It aligns with the distribution switch configuration, ensuring native VLAN consistency and limiting traffic to the management VLAN. This meets both requirements exactly.

Why this answer

To match the distribution switch, the new switch must be configured as a static trunk with native VLAN 999 and allowed VLAN 50. This ensures native VLAN consistency and restricts the trunk to only the management VLAN, preventing unnecessary traffic and security risks.

Exam trap

The trap here is overlooking the native VLAN mismatch that occurs if the native VLAN is not explicitly set to 999, or assuming that dynamic trunking will always form a trunk with a statically configured peer.

1570
Multi-Selecthard

Which three statements about OSPF area types are correct? (Choose three.)

Select 3 answers
A.A stub area blocks Type 5 AS External LSAs but allows Type 3 Summary LSAs and a default route.
B.A totally stubby area blocks both Type 5 and Type 3 LSAs, injecting only a default route into the area.
C.A not-so-stubby-area (NSSA) allows Type 5 LSAs to be imported from external networks.
D.A standard area can contain Type 1, 2, 3, 4, and 5 LSAs.
E.A totally NSSA blocks Type 3 LSAs but allows Type 5 LSAs from external sources.
AnswersA, B, D

Stub areas block Type 5 AS External LSAs at the ABR, preventing external flooding, while Type 3 Summary LSAs still enter and the ABR injects a default route. This matches the stated stub behaviour exactly.

Why this answer

Option A is correct because a stub area, configured with the area stub command, blocks Type 5 AS External LSAs at the ABR while still permitting Type 3 Summary LSAs, and the ABR injects a default route (Type 3 LSA 0.0.0.0) so internal routers can reach external destinations. Option B is correct because a totally stubby area (area stub no-summary) blocks both Type 5 AS External LSAs and Type 3 Summary LSAs, leaving only a single default route injected by the ABR plus intra-area Type 1 and 2 LSAs. Option D is correct because a standard OSPF area carries Type 1 Router LSAs, Type 2 Network LSAs, Type 3 Summary LSAs, Type 4 ASBR Summary LSAs, and Type 5 AS External LSAs.

Option C is incorrect because an NSSA does not import Type 5 LSAs; it uses Type 7 LSAs for external routes originated inside the area, which the ABR translates to Type 5 when flooding into the backbone. Option E is incorrect because a totally NSSA blocks Type 3 Summary LSAs (except the default route) and does not allow Type 5 LSAs; external routes inside it are carried as Type 7 LSAs.

Exam trap

The trap here is confusing the LSA types blocked by stub, totally stubby, NSSA, and totally NSSA areas—especially the role of Type 7 LSAs in NSSAs and the fact that totally stubby areas block Type 3 LSAs while stub areas do not.

1571
MCQmedium

A network engineer is configuring 802.1X on a Cisco switch for a voice VLAN deployment. The switchport is connected to an IP phone, which then connects to a PC. The engineer configures the interface with 'authentication port-control auto', 'dot1x pae authenticator', and 'switchport voice vlan 10'. The PC authenticates successfully, but the IP phone does not get an IP address from the voice VLAN. The engineer verifies that the phone is configured for 802.1X and the RADIUS server is correct. What is the most likely cause?

A.The IP phone does not support 802.1X and is not configured for MAB.
B.The switchport is missing 'switchport mode access' command.
C.The RADIUS server is not sending the voice VLAN ID in the Access-Accept.
D.The PC is using the voice VLAN instead of the data VLAN.
AnswerA

In a port running 802.1X, the switch treats the phone as an endpoint that must authenticate before the voice VLAN is applied. Because the phone cannot run the 802.1X supplicant and MAB is not enabled, the switch never receives a successful authentication to classify the device as voice, so the port remains in the unauthorized state and the locally configured `switchport voice vlan` is not assigned. The phone therefore stays on the data VLAN or gets no usable VLAN.

Why this answer

The IP phone fails to obtain an IP address from the voice VLAN because it is configured for 802.1X but does not support it, and the switchport is not configured for MAC Authentication Bypass (MAB). Without MAB, the switch will not place the phone into the voice VLAN until it successfully authenticates. Since the phone cannot complete 802.1X, it remains in the data VLAN or an unauthorized state, preventing it from receiving a voice VLAN IP address.

Exam trap

Cisco often tests the misconception that configuring 'authentication port-control auto' and 'dot1x pae authenticator' alone is sufficient for all devices, when in fact non-802.1X-capable devices like IP phones require MAB as a fallback mechanism to be placed into the voice VLAN.

How to eliminate wrong answers

Option B is wrong because 'switchport mode access' is not required for voice VLAN deployments; the voice VLAN feature works with 'switchport mode access' implicitly set by default, and the missing command would not prevent the phone from getting a voice VLAN IP address. Option C is wrong because the RADIUS server does not need to send the voice VLAN ID in the Access-Accept; the voice VLAN is configured locally on the switchport with 'switchport voice vlan 10', and the RADIUS server only needs to authenticate the phone's credentials. Option D is wrong because the PC authenticates successfully and uses the data VLAN; the issue is that the phone itself is not authenticating, not that the PC is using the wrong VLAN.

1572
Multi-Selectmedium

A network engineer is designing a Python script to interact with a Cisco IOS XE device using RESTCONF. The engineer needs to perform a partial modification of the interface description without affecting other configured parameters. Which two HTTP methods and payload considerations are appropriate for this task? (Choose two.)

Select 2 answers
A.Use the PATCH method with a JSON payload containing only the fields to be changed.
B.Use the POST method to create a new data node for the description under the interface.
C.Use the DELETE method to remove the existing description and then POST a new one.
D.Use the PATCH method with an XML payload and set the Content-Type header to application/yang-data+xml.
E.Use the PUT method with a JSON payload containing only the fields to be changed.
AnswersA, D

RESTCONF supports the PATCH method to apply partial modifications to a resource. When using PATCH with a JSON payload, only the specified fields are altered, leaving other existing configuration intact. This is ideal for changing a single interface description without overwriting the entire interface configuration. The payload must be structured according to the YANG model, targeting the specific leaf to be modified.

Why this answer

Partial modification of a RESTCONF resource is achieved with the PATCH method, which updates only the specified fields. Both JSON and XML payloads are supported, provided the Content-Type header matches the encoding. Using PUT would replace the entire resource, and POST or DELETE are not appropriate for modifying an existing leaf.

Therefore, the two correct approaches are PATCH with JSON and PATCH with XML.

Exam trap

The trap here is assuming that PUT can be used for partial updates like PATCH, when PUT actually replaces the entire resource and can inadvertently erase other configuration.

1573
MCQhard

A network engineer is configuring a Cisco Catalyst switch to support a new wireless access point that will use 802.1X authentication with EAP-TLS. The switch port must be configured to allow multiple hosts, but only one host should be authenticated. Which command should be used to enable this behavior?

A.authentication host-mode multi-host
B.authentication host-mode multi-auth
C.authentication host-mode single-host
D.authentication host-mode multi-domain
AnswerA

Multi-host mode allows multiple hosts to connect to a single port, but only the first host is authenticated. Once that host is authenticated, all other hosts are granted access without individual authentication. This matches the scenario where multiple hosts are allowed but only one host should be authenticated, making it the correct command.

Why this answer

The requirement is to allow multiple hosts on a switch port while authenticating only one host. This is exactly the behavior of multi-host mode, where the first host authenticates and subsequent hosts are allowed without authentication. Multi-auth would authenticate each host individually, multi-domain is for voice and data domains, and single-host denies additional hosts.

Thus, multi-host mode is the correct choice.

Exam trap

The trap here is assuming that allowing multiple hosts always requires multi-auth mode, when multi-host mode is specifically designed for a single authentication for multiple devices.

1574
MCQmedium

A network engineer is deploying Cisco DNA Center in a large campus network with 5000+ devices. After initial setup, the engineer notices that the Assurance module is not receiving telemetry data from many access switches. The switches are running IOS-XE 16.12 and are reachable via SNMP. What is the most likely cause of this issue?

A.The switches are not configured with NETCONF/YANG or telemetry streaming.
B.The DNA Center appliance is not licensed for the Assurance module.
C.The switches are not running the correct IOS-XE version for DNA Center compatibility.
D.The SNMP community string is incorrect on the switches.
AnswerA

Assurance relies on streaming telemetry pushed from devices, not SNMP polling. IOS-XE switches need NETCONF/YANG or model-driven telemetry configured; without it, DNA Center receives no health data even though the devices remain reachable and manageable.

Why this answer

Cisco DNA Center Assurance relies on telemetry data collected via NETCONF/YANG or gRPC, not just SNMP. If the switches are not configured for telemetry, Assurance will not receive the necessary data. SNMP is used for inventory and basic monitoring, but not for the rich telemetry required by Assurance.

1575
Multi-Selectmedium

A network engineer is designing an automation solution that uses Python with the ncclient library to manage Cisco IOS XE devices via NETCONF. The engineer needs to ensure that the solution can retrieve interface configurations, modify them, and verify the changes. Which two NETCONF operations should the engineer use to accomplish these tasks? (Choose two.)

Select 2 answers
A.<delete-config>
B.<get>
C.<edit-config>
D.<copy-config>
E.<get-config>
AnswersC, E

The <edit-config> operation is used to modify the configuration in a target datastore. It supports operations like merge, replace, create, and delete. The engineer would use this to apply changes to interface configurations. It is the core operation for making configuration changes via NETCONF and is required to fulfill the modification requirement.

Why this answer

To retrieve interface configurations, the engineer should use <get-config>, which fetches configuration data from a datastore. To modify those configurations, <edit-config> is the correct operation, allowing targeted changes. Together, these operations enable reading the current state, applying changes, and then verifying by re-reading the configuration.

Exam trap

The trap here is confusing <get> with <get-config>; <get> retrieves both state and config, while <get-config> is specifically for configuration data, which is what the engineer needs for precise editing.

Page 20

Page 21 of 26

Page 22