Courseiva

ENCOR 350-401 (350-401) — Questions 1576–1650

1923 questions total · 26pages · All types, answers revealed

Page 21

Page 22 of 26

Page 23
1576
MCQmedium

A network administrator is configuring a Cisco IOS router to support IPsec VPN for remote workers. The security policy requires that the router authenticate users via digital certificates issued by a corporate PKI. The administrator has already configured the CA trustpoint and obtained a certificate. Which command must be used in the ISAKMP policy to specify that RSA signatures (digital certificates) should be used for authentication?

A.authentication rsa-sig
B.authentication rsa-encr
C.authentication eap
D.authentication pre-share
AnswerA

The 'authentication rsa-sig' command within the ISAKMP policy specifies that RSA signatures should be used for authentication. This means the router will use digital certificates obtained from a CA to authenticate peers. This matches the requirement to use digital certificates issued by a corporate PKI. The command is configured under 'crypto isakmp policy' configuration mode.

Why this answer

In an ISAKMP policy for IKEv1, the 'authentication rsa-sig' command enables RSA signature authentication, which relies on digital certificates. The other options are incorrect: pre-share uses pre-shared keys, rsa-encr uses encrypted nonces, and eap is used for EAP authentication, typically in IKEv2. The policy requires certificate-based authentication, so rsa-sig is the correct command.

Exam trap

The trap here is confusing rsa-sig with rsa-encr; rsa-sig uses digital certificates for authentication, while rsa-encr uses RSA encrypted nonces without certificates.

1577
MCQmedium

interface GigabitEthernet0/1 ip address 10.1.1.1 255.255.255.0 mpls ip mpls label protocol ldp ! router ospf 1 network 10.1.1.0 0.0.0.255 area 0 ! router ldp interface GigabitEthernet0/1 ! What is the effect of this configuration?

A.MPLS forwarding is enabled on GigabitEthernet0/1, and LDP will distribute labels for all routes in the routing table.
B.Only OSPF routes are labeled; static routes are excluded from LDP label distribution.
C.The 'mpls label protocol ldp' command is redundant because LDP is the default.
D.The configuration will fail because 'router ldp' requires an LDP router-id to be set.
AnswerA

The `mpls ip` command on GigabitEthernet0/1 enables MPLS frame-mode switching on that interface, and because `mpls label protocol ldp` is set, LDP runs on that interface. By default, LDP advertises a label for every IPv4 prefix in the routing table, regardless of whether the route was learned via OSPF, configured as static, or directly connected. Therefore, the statement that all routing-table routes receive labels is correct.

Why this answer

The `mpls ip` command under the interface enables MPLS forwarding, and the `router ldp` configuration with the interface specified activates LDP on that interface. LDP will then distribute labels for all routes in the routing table (including OSPF, static, connected, etc.) by default, as LDP does not filter based on routing protocol. The `mpls label protocol ldp` command is indeed redundant since LDP is the default label distribution protocol in Cisco IOS, but it does not break the configuration.

Exam trap

Cisco often tests the misconception that LDP only labels OSPF or IGP routes, when in fact LDP distributes labels for all routes in the routing table by default, including static and connected routes.

How to eliminate wrong answers

Option B is wrong because LDP distributes labels for all routes in the routing table, not just OSPF routes; there is no implicit filtering by routing protocol. Option C is wrong because while `mpls label protocol ldp` is redundant (LDP is the default), the configuration still works and the statement 'redundant' does not make the option correct as the question asks for the effect, not a critique of redundancy. Option D is wrong because `router ldp` does not require an explicit LDP router-id to be set; if not configured, the router will use the highest loopback IP or the highest interface IP as the LDP router-id automatically.

1578
Multi-Selecthard

Which three statements about SNMP trap and inform operations are true? (Choose three.)

Select 3 answers
A.Traps are unacknowledged notifications sent from the SNMP agent to the manager.
B.Informs are acknowledged notifications that require a response from the manager.
C.Informs use UDP port 162, the same as traps.
D.Traps are more reliable than informs because they are sent with a higher priority.
E.Informs consume less memory and processing than traps because they do not require state tracking.
AnswersA, B, C

Traps use UDP port 162 and the agent fires them without awaiting any response, so delivery is never guaranteed. This satisfies the stem's requirement for a true statement about trap behaviour: the manager sends no acknowledgement, unlike informs, which the receiver must confirm.

Why this answer

Option A is correct because SNMP traps are asynchronous, unacknowledged notifications that an agent (or managed device) sends to a manager on UDP port 162 without expecting any reply. Option B is correct because SNMP informs are also notifications, but they are acknowledged: the manager must send a Response PDU back to the sender, and the sender retransmits if no acknowledgment arrives within a timeout. Option C is correct because informs are delivered to the manager on the same well-known UDP port 162 used by traps; the difference is the acknowledgment behavior, not the transport port.

Option D is not correct because traps are actually less reliable than informs—traps are fire-and-forget with no acknowledgment, and SNMP does not assign them higher priority. Option E is not correct because informs require the sender to keep state (storing the request and waiting for a response, with retries), so they consume more memory and processing than traps, not less.

Exam trap

350-401 often tests the reliability inversion — candidates assume 'trap' sounds more reliable or that informs use a different port, when in fact informs are the reliable, acknowledged mechanism and both use UDP 162.

1579
MCQeasy

A network administrator is configuring a Cisco IOS router to support NAT overload for a small office. The inside network is 10.1.1.0/24, and the outside interface is GigabitEthernet0/1 with IP address 203.0.113.5. The administrator wants all inside hosts to share the outside interface address for internet access. Which command is required to define the NAT pool or interface used for translation?

A.ip nat inside destination list 1 interface GigabitEthernet0/1 overload
B.ip nat inside source list 1 pool MYPOOL overload
C.ip nat outside source list 1 interface GigabitEthernet0/1 overload
D.ip nat inside source list 1 interface GigabitEthernet0/1 overload
AnswerD

This command configures NAT overload, also known as Port Address Translation (PAT), using the outside interface's IP address for translation. The 'list 1' refers to an access list that defines the inside local addresses. The 'overload' keyword enables many-to-one translation by multiplexing inside addresses using port numbers. This is the correct way to configure NAT overload when using the interface address rather than a pool.

Why this answer

To configure NAT overload using the outside interface address, the correct command is 'ip nat inside source list 1 interface GigabitEthernet0/1 overload'. This command references an access list that identifies inside local addresses and translates them to the IP address of the specified interface, using port numbers to distinguish sessions. It is the standard method for enabling many inside hosts to share a single public IP address.

Exam trap

The trap here is confusing the direction of NAT (inside source versus outside source) and the use of an interface versus a pool, which can lead to incorrect translation entries.

1580
MCQmedium

A network engineer runs the following command on Router R7: R7# show ip ospf neighbor vrf CUSTOMER-E Neighbor ID Pri State Dead Time Address Interface 10.0.0.8 1 FULL/DR 00:00:35 10.0.1.2 GigabitEthernet0/0.500 10.0.0.9 1 FULL/BDR 00:00:31 10.0.2.2 GigabitEthernet0/0.600 Based on this output, what can be concluded?

A.OSPF is not configured for VRF CUSTOMER-E
B.There is only one OSPF neighbor in VRF CUSTOMER-E
C.OSPF is operating within VRF CUSTOMER-E with two neighbors
D.The DR is 10.0.0.9
AnswerC

Correct. The OSPF process is bound to VRF CUSTOMER-E, and its neighbor table shows two fully established adjacencies (state FULL/DR and FULL/BDR), confirming active link-state routing within the VRF. This is consistent with having at least two OSPF routers sharing a common segment, and the neighbor states indicate that database synchronization is complete.

Why this answer

The command `show ip ospf neighbor vrf CUSTOMER-E` explicitly queries OSPF neighbors within the VRF named CUSTOMER-E. The output shows two neighbors (10.0.0.8 and 10.0.0.9) with states FULL/DR and FULL/BDR, confirming that OSPF is actively operating inside that VRF. Therefore, option C is correct because it accurately states that OSPF is operating within VRF CUSTOMER-E with two neighbors.

Exam trap

Cisco often tests the misconception that the DR is always the neighbor with the highest IP address or the first listed, but the DR is explicitly indicated by the state field (FULL/DR), not by the Neighbor ID or IP address.

How to eliminate wrong answers

Option A is wrong because the command successfully returned neighbor details, which would not happen if OSPF were not configured for VRF CUSTOMER-E; a missing OSPF configuration under the VRF would produce an empty output or an error. Option B is wrong because the output clearly lists two neighbors (10.0.0.8 and 10.0.0.9), not one. Option D is wrong because the DR (Designated Router) is identified by the neighbor with state FULL/DR, which is 10.0.0.8, not 10.0.0.9 (the BDR).

1581
MCQhard

A network team uses Ansible to automate VLAN configuration on Cisco IOS devices. The playbook fails with the error 'Failed to connect to the host via ssh: Permission denied (publickey)'. The control node runs Ubuntu, and the network devices are configured with SSH key authentication. Which solution should the engineer implement?

A.Set ansible_ssh_private_key_file in the inventory but omit the passphrase
B.Set ansible_user to the correct username in the inventory
C.Run ssh-add on the control node to add the private key to the SSH agent
D.Enable keyboard-interactive authentication on the IOS devices
AnswerC

Running ssh-add on the control node is the correct solution because it loads the passphrase-protected private key into the running SSH agent, where its decrypted form is retained for the duration of the agent session. Once the key is in the agent, Ansible's SSH connections can use it transparently without prompting for the passphrase, since the agent responds to authentication requests. This directly addresses the root cause: the key must be pre-authenticated to the SSH agent before Ansible attempts to connect, and ssh-add is the standard way to do that in an automated, non-interactive workflow.

Why this answer

The error 'Permission denied (publickey)' indicates that the SSH key is not being presented to the IOS device. Running ssh-add on the control node loads the private key into the SSH agent, which Ansible uses by default when connecting via SSH. This resolves the authentication failure without requiring a passphrase or changing the inventory.

Exam trap

Cisco often tests the misconception that setting inventory variables like ansible_ssh_private_key_file or ansible_user alone fixes SSH key issues, when the real problem is that the key is not loaded into the SSH agent on the control node.

How to eliminate wrong answers

Option A is wrong because setting ansible_ssh_private_key_file without a passphrase does not help if the key is not loaded into the agent or if the key file is encrypted; Ansible will still fail to authenticate if the key is not accessible. Option B is wrong because setting ansible_user to the correct username addresses only the username, not the missing private key authentication; the error is about key-based authentication, not user identity. Option D is wrong because enabling keyboard-interactive authentication on IOS devices would allow password-based methods, but the issue is that the private key is not being presented; keyboard-interactive does not solve the missing key problem and may introduce security risks.

1582
MCQmedium

An enterprise is deploying Cisco SD-WAN and must ensure that data plane traffic between branch sites is encrypted and authenticated. The design must also allow the use of application-aware routing to steer traffic based on real-time performance metrics. Which component is responsible for establishing and managing the IPsec tunnels between branch routers?

A.vSmart controllers
B.vEdge/cEdge routers
C.vManage
D.vBond
AnswerB

vEdge and cEdge routers are the SD-WAN edge devices that physically anchor the branch network and handle user data forwarding. After receiving OMP routes from vSmart, they dynamically negotiate and terminate secure IPsec data plane tunnels across the underlay network, encrypting each packet and applying application-aware routing and QoS decisions. Without these edge routers, no overlay data traffic can be forwarded or encrypted, making them the only listed component responsible for IPsec tunnel establishment at the data plane.

Why this answer

The vEdge/cEdge routers are the correct answer because they are the SD-WAN edge devices that terminate IPsec tunnels for data plane traffic. In Cisco SD-WAN, the data plane is fully distributed: each vEdge or cEdge router establishes and manages its own IPsec tunnels (using DTLS/TLS for control and IPsec for data) directly with other branch routers. This allows the routers to apply application-aware routing by monitoring real-time performance metrics (e.g., loss, latency, jitter) and steering traffic across the encrypted tunnels accordingly.

Exam trap

Cisco often tests the misconception that vSmart controllers handle all tunnel management, but in SD-WAN, vSmart only distributes policies and OMP routes, while the actual IPsec tunnel establishment and data plane forwarding is a function of the vEdge/cEdge routers.

How to eliminate wrong answers

Option A is wrong because vSmart controllers are responsible for the control plane—they distribute routing policies, OMP routes, and TLOCs to vEdge/cEdge routers, but they do not establish or manage IPsec data plane tunnels. Option C is wrong because vManage is the management and orchestration plane; it provides a GUI for configuration, monitoring, and troubleshooting but does not participate in IPsec tunnel establishment. Option D is wrong because vBond is the orchestrator that handles initial authentication, NAT traversal, and vSmart/vManage discovery; it does not terminate or manage IPsec data plane tunnels.

1583
MCQmedium

A network engineer issues the following command on Router R9: R9# show ip sla configuration 7 IP SLAs Infrastructure Engine-II Entry number: 7 Owner: Tag: Type of operation to perform: icmp-echo Target address: 192.168.9.10 Source address: 192.168.9.1 Type Of Service parameter: 0x0 Request size (ARR data portion): 28 Operation timeout (milliseconds): 5000 Frequency (seconds): 30 Next Scheduled Start Time: Start Time already passed Group Scheduled : FALSE Life (seconds): 3600 Entry Ageout (seconds): never Recurring (Starting Everyday, Starting Time: 00:00:01) Status of entry (SNMP RowStatus): Active Threshold (milliseconds): 5000 Distribution Statistics: Number of statistic hours kept: 2 Number of statistic distribution buckets kept: 1 Statistic distribution interval (milliseconds): 20 Enhanced History: Based on this output, how long will this IP SLA operation run?

A.Forever
B.30 seconds
C.3600 seconds
D.5000 milliseconds
AnswerC

The IP SLA operation's 'life' parameter is explicitly configured to 3600 seconds, which equals one hour. This value determines how long the probe will run from its start time before it automatically stops. The life is independent of the frequency (30 seconds) and timeout (5000 milliseconds), and it represents the total active duration, not the interval or per-probe timeout.

Why this answer

The 'Life (seconds): 3600' field explicitly defines the duration for which the IP SLA operation remains active. This value overrides any other timing parameters, meaning the operation will run for 3600 seconds (1 hour) from its start time, regardless of the frequency or threshold settings.

Exam trap

Cisco often tests the distinction between 'Life', 'Frequency', and 'Timeout' in IP SLA configurations, and the trap here is that candidates confuse the 'Frequency' (30 seconds) or 'Timeout' (5000 ms) with the total operation duration, overlooking the explicit 'Life' field.

How to eliminate wrong answers

Option A is wrong because 'Forever' would require the Life field to be set to 'never' or the operation to be recurring without a life limit, but here Life is explicitly 3600 seconds. Option B is wrong because 30 seconds is the frequency (interval between probes), not the total runtime of the operation. Option D is wrong because 5000 milliseconds is the operation timeout (how long to wait for a reply) and also the threshold value, not the overall lifetime.

1584
MCQhard

A network engineer is developing a Python script to configure OSPF on a Cisco IOS XE device using the NETCONF protocol. The script establishes an SSH session and sends a <edit-config> RPC with the target datastore set to 'running'. The configuration is applied successfully, but after a device reload, the OSPF configuration is missing. The engineer verifies that the <edit-config> operation included the 'default-operation' parameter set to 'merge'. What is the most likely reason for the configuration loss?

A.The <edit-config> operation was applied to the 'candidate' datastore instead of the 'running' datastore, and the candidate was not committed.
B.The 'default-operation' parameter should have been set to 'replace' instead of 'merge' to ensure the configuration is saved to NVRAM.
C.The NETCONF session was not closed properly, causing the device to roll back the configuration upon session termination.
D.The NETCONF <edit-config> operation modifies the running configuration but does not automatically save it to the startup configuration; a separate <copy-config> or <commit> to startup is required.
AnswerD

NETCONF <edit-config> on Cisco IOS XE modifies the running configuration. To persist changes across a reload, the running configuration must be copied to the startup configuration. This can be done with a <copy-config> RPC targeting the 'startup' datastore or by using the 'copy running-config startup-config' command. Without this step, the configuration is lost on reload, which matches the scenario.

Why this answer

NETCONF <edit-config> operations on Cisco IOS XE modify the running configuration. To persist changes across a reload, the running configuration must be explicitly saved to the startup configuration using a <copy-config> RPC or equivalent. The scenario describes a classic case where the configuration is applied but not saved, leading to loss after reload.

The other options incorrectly attribute the loss to datastore targeting, merge behavior, or session handling.

Exam trap

The trap here is assuming that NETCONF automatically saves changes to startup, when it only modifies the running configuration.

1585
Drag & Dropmedium

Drag and drop the steps of IP addressing scheme design and subnetting steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

IP addressing design starts with gathering requirements, then choosing a private address space. Subnetting is applied to create subnets, which are assigned to specific network segments, and finally summarized to reduce routing table size.

1586
Drag & Dropmedium

Drag and drop the steps of Multiple SPAN source ports with filter VLAN into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The configuration must first specify the session, then define sources and filter VLAN, and finally activate the session.

1587
MCQmedium

A network engineer runs the following command on switch SW1: SW1# show authentication sessions interface GigabitEthernet1/0/1 Interface: GigabitEthernet1/0/1 MAC Address: 0011.2233.4455 IP Address: 192.168.1.100 Status: Authz Success Domain: DATA Oper host mode: multi-auth Oper control dir: both Session timeout: N/A Common Session ID: 0A1B2C3D4E5F6G7H8I9J Acct Session ID: 0x0000000A Handle: 0x00000001 Current Method List: mab Method: MAB State: Authz Success Based on this output, what can be concluded?

A.The client authenticated using 802.1X with a username and password.
B.The client was authenticated based on its MAC address via MAB.
C.The port is in multi-domain mode, allowing one data and one voice device.
D.The session is for voice traffic because the domain is DATA.
AnswerB

The session shows 'Method: MAB' and 'State: Authz Success', confirming that the port's MAC address was validated by the RADIUS server using MAC Authentication Bypass. This occurs when the switch does not receive an 802.1X EAP response from the client and falls back to its MAC address as the identity. The successful authorization indicates the client is accepted based on that MAC address.

Why this answer

The output shows the current method list as 'mab' and the method as 'MAB' with a state of 'Authz Success'. This indicates that the client was authenticated using MAC Authentication Bypass (MAB), which uses the MAC address as the credentials, not 802.1X. The 'Status: Authz Success' confirms successful authorization, and the 'Domain: DATA' indicates it is a data device, not voice.

Exam trap

Cisco often tests the distinction between 'multi-auth' and 'multi-domain' host modes, where candidates mistakenly assume 'multi-auth' allows only one data and one voice device, but it actually allows multiple devices of any type.

How to eliminate wrong answers

Option A is wrong because the current method list is 'mab', not 'dot1x', and the state shows MAB success, meaning 802.1X was not used; if 802.1X had been used, the method would show 'dot1x'. Option C is wrong because the output shows 'Oper host mode: multi-auth', not 'multi-domain'; multi-auth allows multiple devices per port, while multi-domain allows one data and one voice device. Option D is wrong because the domain is 'DATA', which indicates the session is for data traffic, not voice; voice traffic would show 'VOICE' in the domain field.

1588
MCQmedium

A network engineer is configuring a new Cisco IOS switch that will be deployed in a data center. The switch must forward traffic for VLAN 10 while ensuring that the native VLAN for all trunk ports is not susceptible to VLAN hopping attacks. The engineer decides to change the native VLAN from the default to an unused VLAN 999. Which command sequence correctly configures the native VLAN on a trunk port?

A.vlan 999 name NATIVE interface GigabitEthernet0/1 switchport mode trunk switchport trunk allowed vlan 999
B.interface GigabitEthernet0/1 switchport trunk encapsulation dot1q switchport trunk native vlan 999 switchport mode trunk
C.interface GigabitEthernet0/1 switchport mode trunk switchport trunk native vlan 999
D.interface GigabitEthernet0/1 switchport mode access switchport access vlan 999
AnswerC

This sequence enters interface configuration mode, sets the port to trunk mode, and assigns VLAN 999 as the native VLAN. This is the correct Cisco IOS syntax to change the native VLAN on a trunk port, mitigating VLAN hopping by using an unused VLAN.

Why this answer

The correct configuration requires entering interface configuration mode, setting the port to trunk mode, and then specifying the native VLAN with 'switchport trunk native vlan 999'. This ensures that untagged traffic is associated with an unused VLAN, reducing VLAN hopping risk. The other options either misconfigure the port mode or do not properly set the native VLAN.

Exam trap

The trap here is confusing the native VLAN with an allowed VLAN or an access VLAN, and forgetting to set the port to trunk mode first.

1589
Multi-Selecteasy

Which TWO statements are true about Cisco DNA Center automation? (Choose two.)

Select 2 answers
A.DNA Center primarily uses SNMP to manage devices.
B.DNA Center only supports greenfield deployments.
C.DNA Center uses a declarative model for network configuration.
D.DNA Center provides a single dashboard for network management.
E.DNA Center uses an imperative model for network configuration.
AnswersC, D

DNA Center's intent-based declarative model lets engineers define the desired end state, and the controller computes and applies device configuration to reach it. This contrasts with imperative per-device CLI configuration, and is a defining characteristic of DNA Center automation.

Why this answer

Option C is correct because Cisco DNA Center is built around intent-based networking, where administrators define the desired end state (intent) declaratively and DNA Center translates that intent into device-level configurations, rather than requiring per-device imperative command sequences. Option D is correct because DNA Center offers a centralized, single-pane-of-glass dashboard that unifies assurance, monitoring, automation, and policy management across the fabric, giving one management view for the network. Options A, B, and E are not correct: DNA Center does not primarily rely on SNMP for management (it uses APIs such as REST, NETCONF, and SSH/CLI for automation and telemetry), it supports both greenfield and brownfield deployments rather than only greenfield, and it does not use an imperative model as its core configuration approach.

Exam trap

Cisco often tests the distinction between declarative and imperative models, and the trap here is that candidates mistakenly associate DNA Center's automation with imperative scripting (like Python or Ansible playbooks) rather than recognizing its intent-based, declarative nature.

1590
MCQmedium

Examine the following configuration: policy-map QUEUE class GOLD bandwidth percent 25 queue-limit 64 packets class SILVER bandwidth percent 25 queue-limit 128 packets class class-default fair-queue interface GigabitEthernet0/2 service-policy output QUEUE Which statement about this configuration is true?

A.The GOLD class has a smaller queue limit than SILVER, which may cause more packet drops for GOLD traffic under congestion.
B.The SILVER class will always receive more bandwidth than GOLD because of its larger queue limit.
C.The configuration is invalid because 'queue-limit' cannot be used with 'bandwidth percent' in the same class.
D.The 'fair-queue' command in class-default will override the bandwidth allocation for GOLD and SILVER.
AnswerA

GOLD's queue-limit of 64 packets is half SILVER's 128, so during congestion GOLD fills its buffer sooner and tail-drops excess packets earlier, despite both classes receiving equal 25 percent bandwidth guarantees. Bandwidth percent governs scheduling weight, not buffer depth, so the smaller limit directly increases GOLD's drop probability.

Why this answer

The GOLD class has a queue-limit of 64 packets, while the SILVER class has a queue-limit of 128 packets. Under congestion, the smaller queue for GOLD will fill up faster, leading to more tail drops for GOLD traffic, even though both classes are allocated the same bandwidth percentage. This demonstrates that queue-limit directly affects drop probability, not bandwidth allocation.

Exam trap

Cisco often tests the misconception that a larger queue-limit implies more bandwidth, when in fact queue-limit only affects buffer depth and drop behavior, not bandwidth allocation.

How to eliminate wrong answers

Option B is wrong because queue-limit does not affect bandwidth allocation; bandwidth is controlled by the 'bandwidth percent' command, which is set to 25% for both GOLD and SILVER, so they receive equal bandwidth under congestion. Option C is wrong because 'queue-limit' can be used with 'bandwidth percent' in the same class; they are independent QoS parameters that control different aspects (bandwidth guarantee vs. queue depth). Option D is wrong because 'fair-queue' in class-default only applies to the default class and does not override the explicit bandwidth allocation for GOLD and SILVER classes, which are configured with strict bandwidth percentages.

1591
MCQhard

A network engineer is troubleshooting a VXLAN EVPN fabric on Cisco Nexus 9000 switches. Hosts in VLAN 100 on different leaf switches cannot communicate, even though the EVPN control plane shows the MAC addresses. The engineer suspects a problem with the VXLAN data plane. Which command should be used to verify the VXLAN tunnel endpoints (VTEPs) and their status?

A.show vxlan interface
B.show bgp l2vpn evpn
C.show nve peers
D.show ip arp vrf all
AnswerC

This command displays the status of VXLAN tunnel endpoints (VTEPs) and their peering relationships. It shows the IP addresses of remote VTEPs, the VNI, and the state of the tunnel. If the tunnel is down, this command will indicate that, helping the engineer identify why hosts cannot communicate despite EVPN MAC entries.

Why this answer

The 'show nve peers' command is used to verify the status of VXLAN tunnel endpoints and their peering relationships. It provides details such as the remote VTEP IP, VNI, and tunnel state. If the tunnel is down, this command helps identify the issue, which is critical when EVPN control plane information is present but data plane connectivity is failing.

Exam trap

The trap here is assuming that control plane verification (such as BGP EVPN routes) is sufficient to confirm data plane connectivity, when in fact VXLAN tunnel status must be checked separately.

1592
MCQeasy

A network administrator must secure management access to a Cisco Catalyst 9300 switch so that only encrypted sessions are accepted and any Telnet attempt is refused. The administrator wants to enforce this with the fewest configuration lines on the VTY lines. Which configuration accomplishes this?

A.line vty 0 15 followed by transport output ssh
B.line vty 0 15 followed by login local and transport input telnet ssh
C.line vty 0 15 followed by transport input all then access-class 10 in with an ACL denying TCP port 23
D.line vty 0 15 followed by transport input ssh
AnswerD

The transport input ssh command on the VTY lines permits only SSH and implicitly rejects Telnet, so no additional access-class or ACL is required. This satisfies the requirement with a single line inside line configuration mode, assuming the device already has a hostname, domain name, and RSA key pair generated for SSH to function.

Why this answer

Restricting inbound VTY access to SSH is done by entering line configuration mode and issuing transport input ssh, which permits only SSH and denies Telnet by default. Because Telnet is implicitly excluded, no ACL is needed, making this the most concise and reliable way to enforce encrypted-only management access on the switch.

Exam trap

The trap here is confusing transport input with transport output, which control opposite directions of the management session.

1593
MCQhard

An engineer is deploying VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. Hosts in the same subnet are attached to different edge nodes. Which mechanism ensures that a host's default gateway MAC address is identical on every edge node while still allowing local forwarding?

A.A shared virtual MAC address is configured on the anycast SVI of every edge node in the fabric.
B.Each edge node uses a unique gateway MAC derived from its loopback0 address.
C.Edge nodes learn the gateway MAC from the fabric border node through VXLAN Group Policy Option headers.
D.The fabric control plane assigns a single gateway MAC that is flooded to edge nodes via LISP map-register messages.
AnswerA

The distributed anycast gateway uses the same virtual MAC on the anycast SVI of all edge nodes, so hosts see one consistent gateway identity regardless of attachment point. Each edge node can forward locally for hosts in its own subnet while the shared MAC preserves a stable default gateway, enabling seamless mobility and optimal forwarding without tromboning traffic to a central gateway.

Why this answer

In a Cisco SD-Access fabric, distributed anycast gateway requires the same virtual MAC address configured on the anycast SVI of every edge node. This shared identity lets hosts keep a consistent default gateway while each edge node forwards locally, avoiding hairpinning through a central gateway and supporting host mobility across the fabric.

Exam trap

The trap here is confusing the fabric control plane's LISP endpoint mappings with gateway MAC distribution, when the anycast gateway MAC is simply a locally configured virtual MAC shared across edge nodes.

1594
Multi-Selecthard

A network architect is evaluating Cisco StackWise Virtual technology for a pair of Cisco Catalyst 9000 switches that will act as a single logical entity at the distribution layer. Which two statements accurately describe Cisco StackWise Virtual? (Choose two.)

Select 2 answers
A.Each switch in the StackWise Virtual pair maintains an independent control plane and separate management IP address.
B.It requires that both switches run different IOS XE versions to provide software redundancy.
C.The StackWise Virtual Link can be formed using any two 1 Gigabit Ethernet ports on the switches.
D.It supports Multichassis EtherChannel (MEC) so that access switches can dual-home to both stack members.
E.It combines two physical switches into one logical switch using a StackWise Virtual Link between them.
AnswersD, E

StackWise Virtual supports Multichassis EtherChannel, allowing a downstream access switch to form a port-channel with one link to each stack member. Because the two switches operate as one logical device, the port-channel is seen as a single EtherChannel, providing loop-free redundancy and active-active forwarding without relying on spanning tree to block a link.

Why this answer

Cisco StackWise Virtual combines two Catalyst 9000 switches into one logical switch via a StackWise Virtual Link, presenting a single control plane and management IP. It enables Multichassis EtherChannel so downstream devices can dual-home with active-active forwarding. The SVL requires high-speed ports, both switches must run the same IOS XE version, and the pair shares one control plane rather than maintaining independent ones.

Exam trap

The trap here is assuming that StackWise Virtual is simply two independent switches with a redundant link, when it actually merges them into one logical switch with a single control plane and requires matching software and high-speed SVL ports.

1595
MCQeasy

A network engineer is configuring a new Cisco IOS switch and needs to ensure that the management VLAN is properly secured. The engineer wants to restrict management access to only the IT department subnet 10.10.10.0/24. Which configuration should be applied to the VTY lines?

A.access-class 10 in
B.ip access-class 10 in
C.access-list 10 permit 10.10.10.0 0.0.0.255
D.ip access-group 10 in
AnswerA

The access-class command is used on VTY lines to filter incoming Telnet or SSH connections based on a standard or extended ACL. Applying 'access-class 10 in' with an ACL that permits 10.10.10.0/24 and denies all others restricts management access to the IT subnet. This is the correct configuration to meet the requirement.

Why this answer

To restrict management access to a specific subnet on Cisco IOS devices, you configure an ACL that permits that subnet and denies others, then apply it to the VTY lines using the access-class command. The access-class command filters incoming connections to the VTY lines. The correct syntax is 'access-class 10 in'.

This ensures that only hosts from the IT department subnet can establish management sessions, meeting the security requirement.

Exam trap

The trap here is confusing the interface command 'ip access-group' with the VTY line command 'access-class', which is used to filter management traffic.

1596
MCQhard

A network engineer runs the following command on Switch SW2: SW2# show spanning-tree vlan 10 VLAN0010 Spanning tree enabled protocol ieee Root ID Priority 32778 Address aabb.cc00.0100 Cost 19 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32778 (priority 32768 sys-id-ext 10) Address aabb.cc00.0200 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- -------------------------------- Gi0/1 Root FWD 19 128.1 P2p Gi0/2 Altn BLK 19 128.2 P2p Gi0/3 Desg FWD 19 128.3 P2p Based on this output, what can be concluded?

A.SW2 is the root bridge for VLAN 10.
B.The root bridge for VLAN 10 has MAC address aabb.cc00.0100.
C.Port Gi0/2 is in forwarding state.
D.The STP priority for VLAN 10 is 32768.
AnswerB

The Root ID field in the spanning-tree output announces the root bridge's identifier, and it lists aabb.cc00.0100 as the root MAC for VLAN 10. STP elects the root based on the lowest bridge ID, and this MAC belongs to whichever switch has won that election for this VLAN. Therefore the root bridge for VLAN 10 is the switch with that MAC address, not the local switch.

Why this answer

The output shows that the Root ID has MAC address aabb.cc00.0100, while the Bridge ID (SW2 itself) has MAC address aabb.cc00.0200. Since SW2 is not the root bridge (its Bridge ID differs from the Root ID), the root bridge for VLAN 10 must be the switch with MAC address aabb.cc00.0100. The Root ID field always identifies the root bridge in the spanning tree.

Exam trap

Cisco often tests the distinction between the Root ID and Bridge ID fields in 'show spanning-tree' output, causing candidates to mistakenly think the local switch is the root when they see its own priority, without checking the MAC address or root port status.

How to eliminate wrong answers

Option A is wrong because SW2's Bridge ID (aabb.cc00.0200) does not match the Root ID (aabb.cc00.0100), and SW2 has a root port (Gi0/1) with a cost of 19, indicating it is not the root bridge. Option C is wrong because the output shows Gi0/2 is in the 'Altn BLK' (Alternate Blocking) role and state, not forwarding. Option D is wrong because the STP priority for VLAN 10 is 32778 (as shown in the Bridge ID line), which is the base priority 32768 plus the VLAN ID 10 (sys-id-ext), not 32768 alone.

1597
MCQmedium

A network engineer is configuring a Cisco Nexus 9000 switch as a VXLAN Tunnel Endpoint (VTEP) in a spine-leaf fabric. The engineer needs to verify that the NVE interface is operational and that the VNI-to-VLAN mapping is correct. Which command should the engineer use to display the VXLAN tunnel endpoints and their associated VNIs?

A.show nve vni
B.show nve interface nve1
C.show nve peers
D.show vxlan vni
AnswerA

The 'show nve vni' command displays the VNIs configured on the NVE interface along with their associated VLANs, the VNI state, and the multicast group or peer information. This directly verifies the VNI-to-VLAN mapping and confirms that the NVE interface is operational. It is the most comprehensive command for checking both the VTEP status and the VNI mapping, making it the correct choice for this scenario.

Why this answer

The engineer needs to verify both the NVE interface operational status and the VNI-to-VLAN mapping. The 'show nve vni' command provides a comprehensive view of the VNIs, their associated VLANs, and the state of each VNI, which directly addresses the requirement. Other commands show partial information, such as peers or interface details, but do not combine the mapping and operational status in one output.

Exam trap

The trap here is assuming that 'show nve peers' or 'show nve interface' alone can verify the VNI-to-VLAN mapping, when in fact only 'show nve vni' displays that mapping along with VNI state.

1598
Multi-Selectmedium

A network automation team is evaluating YANG as the data modeling language underpinning its Cisco IOS XE automation. Which two statements accurately describe YANG in this context? (Choose two.)

Select 2 answers
A.YANG replaces the need for underlying transport protocols by embedding its own session and encryption layer for device communication.
B.YANG modules can include constraints such as type, range, and pattern on leaves, and devices enforce these during configuration validation.
C.YANG data can only be serialized as XML, so JSON payloads are invalid for any NETCONF or RESTCONF operation.
D.YANG models are proprietary to Cisco and cannot be extended or reused across different vendors' network operating systems.
E.YANG defines a hierarchical, tree-structured schema for configuration and state data that protocols such as NETCONF and RESTCONF can transport.
AnswersB, E

YANG leaves carry built-in types and restriction statements like range, length, pattern, and mandatory. When a NETCONF or RESTCONF write arrives, the device validates the value against these constraints, producing errors such as 'invalid-value' if violated. This enforcement is central to why model-driven interfaces are more reliable than CLI screen-scraping, and it directly reflects how YANG behaves on IOS XE.

Why this answer

YANG is a hierarchical data modeling language that defines configuration and state schemas transported by NETCONF and RESTCONF. Its leaves carry constraints such as type, range, and pattern that devices validate on write, which is why model-driven automation is more robust than CLI scraping. YANG is an open standard, is not a transport itself, and its data can be encoded in XML or JSON depending on the protocol and media type.

Exam trap

The trap here is confusing YANG, a modeling language, with the transport protocols that actually carry its data.

1599
Matchingmedium

Drag and drop each hypervisor type on the left to its matching characteristic on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Runs directly on physical hardware without a host OS

Runs on top of an existing operating system

Example of a Type 1 hypervisor

Example of a Type 2 hypervisor

Linux-based Type 1 hypervisor that is part of the kernel

Why these pairings

Type 1 hypervisors run directly on hardware and are common in data centers; Type 2 run on a host OS and are used for desktop virtualization.

1600
Multi-Selectmedium

Which two statements about SNMPv3 security models are true? (Choose two.)

Select 2 answers
A.The authNoPriv security model provides authentication but no encryption.
B.The noAuthNoPriv security model uses both a username and a password for authentication.
C.The authPriv security model provides both authentication and encryption.
D.SNMPv3 requires the use of a separate engine ID for each SNMP manager and agent.
E.The authPriv model supports only AES-256 for encryption.
AnswersA, C

authNoPriv pairs HMAC authentication (MD5 or SHA) with no payload encryption, so messages are verified as genuine but remain readable in transit. This satisfies the stem's requirement for a true SNMPv3 security-level statement, distinguishing it from authPriv, which adds DES or AES confidentiality.

Why this answer

Option A is correct because the authNoPriv security level in SNMPv3 authenticates messages using HMAC with MD5 or SHA (verifying integrity and origin) but does not encrypt the payload, so data travels in cleartext. Option C is correct because authPriv combines authentication with encryption, using a privacy protocol such as DES, 3DES, or AES to protect the PDU contents. Option B is wrong because noAuthNoPriv performs no authentication at all, relying only on a username (security name) with no password or HMAC verification.

Option D is wrong because SNMPv3 does not require a separate engine ID per manager and agent; each SNMP engine has one unique engine ID, and managers can communicate with multiple agents using their respective IDs. Option E is wrong because authPriv supports multiple encryption algorithms (DES, 3DES, AES-128/192/256 depending on implementation), not only AES-256.

Exam trap

350-401 often tests the security-level naming — candidates misread 'noAuthNoPriv' as requiring a password, or assume authPriv mandates AES-256, when the model actually supports multiple cipher suites and noAuthNoPriv uses no credentials at all.

1601
MCQmedium

A network architect is designing QoS for a converged network carrying voice, video, and data. The design must use the DiffServ model and ensure that voice traffic is marked with the highest priority and that video traffic is marked with a lower priority but still above data. Which DSCP markings should be assigned to voice and video traffic, respectively, to comply with the standard Per-Hop Behavior (PHB) definitions?

A.Voice: DSCP 46 (EF); Video: DSCP 34 (AF41)
B.Voice: DSCP 56 (CS7); Video: DSCP 48 (CS6)
C.Voice: DSCP 40 (AF41); Video: DSCP 46 (EF)
D.Voice: DSCP 26 (AF31); Video: DSCP 18 (AF21)
AnswerA

Voice is marked DSCP 46 (EF), which places it in the strict-priority queue in every Cisco router/switch, ensuring minimal delay, jitter, and loss—essential for real-time voice. Video uses DSCP 34 (AF41), an assured-forwarding class with low drop precedence, giving it priority over ordinary data but not over voice, while still allowing it to be dropped gracefully under severe congestion. This pairing follows the standard Cisco Enterprise QoS model and ensures voice quality is never compromised by video bursts.

Why this answer

The DiffServ model defines specific Per-Hop Behaviors (PHBs) for different traffic types. Voice traffic requires low latency, jitter, and loss, which is best served by the Expedited Forwarding (EF) PHB, assigned DSCP 46. Video traffic, while still delay-sensitive, can tolerate some loss and is typically marked with Assured Forwarding (AF41, DSCP 34), which provides a lower priority queue than EF but higher than best-effort data.

Exam trap

Cisco often tests the specific DSCP values for EF (46) and AF41 (34) and the fact that voice must use EF (not AF or CS) to ensure strict priority queuing, while video uses the highest AF class (AF41) to differentiate it from data without breaking the EF queue.

How to eliminate wrong answers

Option B is wrong because DSCP 56 (CS7) and DSCP 48 (CS6) are Class Selector codepoints used for network control traffic (e.g., routing protocols), not for voice or video; they would starve other traffic and violate the standard PHB definitions. Option C is wrong because it reverses the priority: DSCP 40 (AF41) is for video, not voice, and DSCP 46 (EF) is for voice, not video; this would incorrectly prioritize video over voice. Option D is wrong because DSCP 26 (AF31) and DSCP 18 (AF21) are Assured Forwarding classes with lower drop precedence, typically used for mission-critical data or streaming video, not for real-time voice; they do not provide the strict priority queuing required for voice traffic.

1602
MCQmedium

A network engineer runs the following command on a Cisco WLC: WLC# show ap stats ap-name AP-1 AP Statistics for AP-1 ---------------------- Channel Utilization: 45% Interference: 10% Noise Floor: -95 dBm Total Packets Received: 15000 Total Packets Sent: 12000 Total Errors: 200 Based on this output, what can be concluded?

A.The channel is heavily congested with utilization above 80%.
B.The noise floor is high, indicating potential interference.
C.The AP is experiencing a significant number of errors relative to packets received.
D.The channel utilization is moderate and the noise floor is low.
AnswerD

A channel utilization of 45% is moderate—the medium is busy but not oversaturated, leaving room for additional client traffic and retransmissions. A noise floor of -95 dBm is very low, meaning background RF interference is minimal. These two attributes together indicate a relatively clean and stable RF channel, which is why this is the correct assessment of the AP's environment.

Why this answer

The channel utilization of 45% is considered moderate (typically below 50% is acceptable), and the noise floor of -95 dBm is very low (excellent), indicating a clean RF environment. The interference value of 10% is also low, and the error count of 200 out of 15,000 received packets (1.33%) is not significant. This output shows a healthy AP with no major issues.

Exam trap

Cisco often tests the misconception that any non-zero error count or moderate utilization is automatically problematic, when in fact the absolute values and percentages must be evaluated against established thresholds (e.g., noise floor below -90 dBm is good, utilization under 50% is moderate).

How to eliminate wrong answers

Option A is wrong because 45% channel utilization is far below the 80% threshold that would indicate heavy congestion; Cisco recommends planning for utilization under 50% for good performance. Option B is wrong because a noise floor of -95 dBm is actually very low (excellent), not high; typical noise floor values above -80 dBm are considered high and problematic. Option C is wrong because 200 errors out of 15,000 received packets is only about 1.33%, which is not a significant error rate; significant errors would typically be above 5-10% or indicate physical layer issues.

1603
MCQmedium

A network engineer is deploying a new branch office with a Cisco Catalyst 9300 switch. The switch must participate in the corporate OSPF domain but must not become a designated router (DR) or backup designated router (BDR) on any broadcast segment. Which configuration should the engineer apply to the switch's OSPF interface?

A.ip ospf priority 0
B.ip ospf network point-to-point
C.ip ospf database-filter all out
D.ip ospf cost 65535
AnswerA

Setting the OSPF interface priority to 0 makes the router ineligible to become DR or BDR on that broadcast segment. The priority value is carried in Hello packets and used in the DR election; a priority of 0 explicitly excludes the interface from the election, ensuring the switch remains a DROTHER and only forms adjacencies with the DR and BDR.

Why this answer

The OSPF interface priority determines which routers are eligible to become DR or BDR on a broadcast or non-broadcast multi-access segment. A priority of 0 makes the router ineligible for these roles, so it will remain a DROTHER regardless of its router ID. This is the correct way to ensure the switch never becomes DR or BDR while still participating in OSPF.

Exam trap

The trap here is assuming that any OSPF interface setting that alters adjacency behavior, such as changing the network type, will also prevent DR/BDR election without side effects.

1604
Drag & Dropmedium

Drag and drop the steps of Layer 3 EtherChannel (routed port-channel) setup into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order for Layer 3 EtherChannel (routed port-channel) setup is: first, create the port-channel interface using 'interface port-channel'. Next, configure the member ports as Layer 3 interfaces with 'no switchport' and assign them to the port-channel using 'channel-group'. Then, assign an IP address to the port-channel interface.

After that, enable the port-channel interface with 'no shutdown'. Finally, verify routing using 'show ip route' and ping.

1605
Multi-Selecthard

A network engineer is implementing Cisco SD-Access and needs to configure the fabric to support both wired and wireless clients. Which two components are required to enable wireless integration in a Cisco SD-Access fabric? (Choose two.)

Select 2 answers
A.Fabric Border Node
B.Fabric Wireless Controller (WLC)
C.Fabric-enabled Access Point
D.Fabric Edge Node
E.Fabric Control Plane Node
AnswersB, C

The Fabric Wireless Controller (WLC) is essential for integrating wireless access points into the SD-Access fabric. It manages the wireless infrastructure and communicates with the fabric control plane to register wireless clients and their locations. The Fabric WLC uses VXLAN to tunnel client traffic to the fabric edge nodes. Without it, wireless clients cannot be part of the fabric's unified policy and segmentation. Thus, it is a required component for wireless integration.

Why this answer

To integrate wireless clients into a Cisco SD-Access fabric, you need a Fabric Wireless Controller (WLC) to manage the wireless infrastructure and a fabric-enabled Access Point to connect wireless clients to the fabric. The Fabric WLC communicates with the fabric control plane to register client locations, and the APs encapsulate traffic in VXLAN. Other components like Fabric Edge, Border, and Control Plane nodes are part of the fabric but are not specific to enabling wireless integration.

Exam trap

The trap here is assuming that any fabric node (like Edge or Border) is sufficient for wireless integration, when in fact specific wireless components (Fabric WLC and fabric-enabled APs) are required.

1606
MCQeasy

A network engineer is designing a campus network and needs to ensure high availability for the core layer. Which design best practice should be implemented?

A.Use a single distribution switch to simplify management.
B.Deploy two core switches configured with VSS or StackWise.
C.Configure the core layer for Layer 2 switching only.
D.Use spanning-tree PortFast on all core switch ports.
AnswerB

VSS or StackWise combines two physical core switches into one logical device, providing stateful failover and sub-second convergence between the chassis. This approach enables active-active traffic forwarding and allows downstream switches to use Cross-Stack EtherChannel (MEC), so both links carry traffic rather than one being blocked by spanning tree. Because the pair appears as a single switch, routing protocols and STP see one node, which simplifies configuration and improves redundancy compared to a standalone pair running HSRP.

Why this answer

Deploying two core switches with VSS (Virtual Switching System) or StackWise provides both redundancy and active-active load balancing at the core layer. VSS virtualizes two physical switches into a single logical switch, eliminating the need for Spanning Tree Protocol (STP) on inter-switch links and enabling sub-second failover. This design ensures high availability by removing single points of failure and maximizing throughput between distribution and core layers.

Exam trap

Cisco often tests the misconception that the core layer should remain Layer 2 for simplicity, but in modern campus designs, the core must route at Layer 3 to avoid STP convergence delays and support ECMP load balancing.

How to eliminate wrong answers

Option A is wrong because using a single distribution switch creates a single point of failure, violating high-availability requirements for the core layer. Option C is wrong because the core layer should route traffic at Layer 3 to enable fast convergence and load balancing; restricting it to Layer 2 switching forces STP dependency and suboptimal path utilization. Option D is wrong because PortFast is an access-layer feature designed to bypass STP listening/learning on end-host ports; applying it to core switch ports (which connect to other switches) would risk bridging loops and network instability.

1607
MCQhard

A network engineer checks the AAA server status: R1# show aaa servers RADIUS: id 1, priority 1, host 10.1.1.10, auth-port 1812, acct-port 1813 State: current DEAD, duration 0s, previous duration 500s Dead: total 1, retransmit 3 RADIUS: id 2, priority 2, host 10.1.1.20, auth-port 1812, acct-port 1813 State: current UP, duration 200s, previous duration 0s Dead: total 0, retransmit 0 Based on this output, what can be concluded?

A.Both RADIUS servers are operational.
B.The backup server is currently handling authentication.
C.The primary server has never failed before.
D.TACACS+ is also configured on these servers.
AnswerB

The primary RADIUS server is marked DEAD, so the IOS RADIUS failover mechanism automatically routes authentication requests to the next configured server, which is the backup. The output shows the backup server with an UP state and active request counts, confirming it is the one currently handling authentication. This is the expected and correct condition during a primary-server outage.

Why this answer

The output shows that the primary RADIUS server (10.1.1.10) is in a DEAD state, while the backup server (10.1.1.20) is UP and has been handling authentication for 200 seconds. This confirms that the backup server is currently processing AAA requests, making option B correct.

Exam trap

Cisco often tests the misinterpretation of 'Dead: total 1' as meaning the server is currently dead for the first time, when in fact it indicates the cumulative number of times the server has transitioned to a dead state, not the current status.

How to eliminate wrong answers

Option A is wrong because the primary server (10.1.1.10) is DEAD, so not both servers are operational. Option C is wrong because the 'Dead: total 1' counter indicates the primary server has failed at least once before, contradicting 'never failed'. Option D is wrong because the output only shows RADIUS server details; there is no evidence of TACACS+ configuration on these servers, and the command 'show aaa servers' does not display TACACS+ status unless TACACS+ servers are explicitly configured.

1608
MCQhard

A network engineer is using a Python script with the 'requests' library to interact with a Cisco IOS XE device via RESTCONF. The script sends a GET request to the URI 'https://192.168.1.1/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1' but receives a 401 Unauthorized error. The engineer has verified that the RESTCONF service is enabled and the URI is correct. What is the most likely cause of the error?

A.The RESTCONF request must include an Accept header specifying 'application/yang-data+json'.
B.The RESTCONF URI is incorrect because it should use 'config' instead of 'data'.
C.The device requires authentication, and the script did not provide valid credentials.
D.The device's HTTP server is not enabled, so it is rejecting the connection.
AnswerC

A 401 Unauthorized response indicates that the request lacks valid authentication credentials. RESTCONF on Cisco IOS XE requires authentication, typically via HTTP Basic Authentication or token-based methods. If the Python script did not include the 'auth' parameter with a valid username and password, or if the credentials are incorrect, the device will return 401. The engineer must configure the script to send proper authentication headers.

Why this answer

The 401 Unauthorized status code specifically means that the request lacks valid authentication credentials. RESTCONF on Cisco IOS XE requires authentication, and the Python script must include a valid username and password, typically using HTTP Basic Auth. Without it, the device rejects the request.

The other options would produce different error codes, such as 406 for missing Accept header or 404 for incorrect URI.

Exam trap

The trap here is assuming that a missing Accept header or incorrect URI causes a 401 error; in reality, 401 is solely about authentication, while other issues yield different status codes.

1609
MCQmedium

A network engineer runs the following command on Switch SW1: SW1# show spanning-tree vlan 10 VLAN0010 Spanning tree enabled protocol ieee Root ID Priority 32778 Address 0011.2233.4455 Cost 19 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32778 (priority 32768 sys-id-ext 10) Address 0011.2233.4466 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- -------------------------------- Gi0/1 Root FWD 19 128.1 P2p Gi0/2 Altn BLK 19 128.2 P2p Based on this output, what can be concluded?

A.The local switch is the root bridge for VLAN 10
B.The local switch is not the root bridge for VLAN 10
C.Interface Gi0/2 is in a forwarding state
D.The spanning-tree mode is Rapid PVST+
AnswerB

This is the correct inference from the spanning-tree output. The Root ID field shows a MAC address of 0011.2233.4455, whereas the local switch's Bridge ID uses 0011.2233.4466, so they are different. In STP, a switch knows it is not the root when its own bridge ID does not match the Root ID. Therefore, the local switch must be a non-root switch, and it will have a root port selected toward the root bridge.

Why this answer

The output shows that the local switch (Bridge ID 0011.2233.4466) has a Root ID of 0011.2233.4455, which is different from its own Bridge ID. Additionally, the Root Cost is 19, and the Root Port is Gi0/1. This confirms that the local switch is not the root bridge for VLAN 10; it is a non-root switch with a root port in the forwarding state.

Exam trap

Cisco often tests the distinction between the Root ID and Bridge ID in 'show spanning-tree' output, where candidates mistakenly assume the local switch is the root if they see a priority value without checking the MAC address.

How to eliminate wrong answers

Option A is wrong because the local switch's Bridge ID (0011.2233.4466) does not match the Root ID (0011.2233.4455), so it is not the root bridge. Option C is wrong because the Role column shows Gi0/2 as 'Altn' (Alternate) and the Status as 'BLK' (Blocking), not forwarding. Option D is wrong because the output shows 'Spanning tree enabled protocol ieee', which indicates IEEE 802.1D (classic STP), not Rapid PVST+ (which would show 'protocol ieee' with 'Rapid' or 'PVST' in the mode line).

1610
MCQmedium

A network architect is designing QoS for a Cisco SD-WAN deployment that uses a mix of MPLS and broadband Internet transports. The design must ensure that interactive video traffic is not delayed by large file transfers, even when the Internet link experiences congestion. Which SD-WAN policy type should the architect use to enforce this behavior?

A.Configure a localized QoS policy on the WAN edge routers that matches video traffic and applies a priority queue.
B.Use a centralized data policy to steer video traffic to the MPLS link only.
C.Implement a centralized application-aware routing policy to prefer the MPLS link for video.
D.Configure a VPN membership policy to isolate video traffic in a separate VPN.
AnswerA

Localized QoS policies are attached directly to the WAN edge router's egress interface, where congestion actually occurs. Within the policy-map, you create a class dedicated to video (matched via DSCP EF or NBAR) and assign it strict priority using the 'priority' command, which yields low-latency queuing (LLQ). This ensures video packets are dequeued before bulk traffic at every hop, directly minimizing jitter and end-to-end delay on each link. Unlike path-selection or isolation approaches, this provides a per-interface bandwidth guarantee that survives regardless of which transport is used.

Why this answer

A localized QoS policy on the WAN edge router can classify interactive video traffic and place it into a priority queue, ensuring low-latency treatment even when the Internet link is congested. This policy operates locally on the router, directly controlling queuing and scheduling behavior on the specific interface, which is essential for protecting real-time traffic from bulk file transfers.

Exam trap

Cisco often tests the distinction between traffic-steering policies (centralized data or app-aware routing) and local queuing mechanisms (QoS policies), leading candidates to mistakenly choose a path-selection solution when the question explicitly asks about preventing delay on a congested link.

How to eliminate wrong answers

Option B is wrong because a centralized data policy steers traffic based on routing decisions but does not provide per-hop queuing or congestion management; it cannot guarantee that video traffic is not delayed by file transfers on the same link. Option C is wrong because an application-aware routing policy selects the best path (e.g., MPLS) but does not enforce local queuing behavior; if the Internet link is the only available path or is chosen, video traffic can still be delayed without a priority queue. Option D is wrong because a VPN membership policy isolates traffic into separate logical networks but does not affect queuing or scheduling on the physical interface; congestion on the Internet link would still affect all traffic in that VPN.

1611
MCQmedium

Consider the following EIGRP configuration: router eigrp 100 metric weights 0 1 0 1 0 0 What does this configuration accomplish?

A.It sets the EIGRP metric to use bandwidth and delay only, which is the default behavior.
B.It disables the use of bandwidth in the metric calculation.
C.It enables the use of load and reliability in the metric calculation.
D.It changes the metric to use only delay.
AnswerA

The EIGRP metric weights command modifies the K values used in the composite metric calculation. By default, K1 and K3 are set to 1 while K2, K4, and K5 are set to 0, which means only bandwidth and delay are considered. This command explicitly configures those default values, so it does not alter the metric behavior from the standard EIGRP operation.

Why this answer

The `metric weights` command in EIGRP allows you to modify the K values used in the composite metric calculation. The default K values are K1=1, K2=0, K3=1, K4=0, K5=0, which means only bandwidth (K1) and delay (K3) are used. The configuration `metric weights 0 1 0 1 0 0` explicitly sets K1=1, K2=0, K3=1, K4=0, K5=0, which matches the default behavior.

Therefore, option A is correct.

Exam trap

Cisco often tests the misconception that the `metric weights` command changes the metric calculation from the default, when in fact the given values exactly match the default K values (1,0,1,0,0).

How to eliminate wrong answers

Option B is wrong because the configuration sets K1=1, which enables the use of bandwidth in the metric calculation, not disables it. Option C is wrong because the configuration sets K2=0 and K4=0, which disables load and reliability, respectively; enabling them would require K2=1 and K4=1. Option D is wrong because the configuration sets K1=1, so bandwidth is still included; to use only delay, you would need K1=0 and K3=1.

1612
MCQhard

A company is deploying Cisco CSR1000v virtual routers in a KVM environment. The architect needs to ensure high availability by allowing VMs to move between physical hosts without service interruption. Which feature must be supported by the hypervisor and storage?

A.Live migration with shared storage (e.g., NFS or iSCSI).
B.Cold migration with local storage only.
C.Storage vMotion without shared storage.
D.Using a distributed virtual switch without shared storage.
AnswerA

This is correct because the VM's virtual disk resides on a storage device accessible by both source and destination hosts. During migration, only the memory state and CPU execution context are copied over the network, while the disk stays on the shared storage, so there is no need to transfer large disk files. This results in near-zero downtime and preserves the running state for seamless migration between ESXi hosts. The shared storage and compatible vMotion network are essential for this to work.

Why this answer

Live migration (also known as VM migration) allows a running virtual machine to move between physical hosts with zero downtime. For this to work in a KVM environment with Cisco CSR1000v routers, the hypervisor must support live migration, and the storage must be shared (e.g., NFS or iSCSI) so that the VM's disk image remains accessible from both source and destination hosts. Without shared storage, the VM's disk state cannot be preserved during migration, causing service interruption.

Exam trap

Cisco often tests the distinction between live migration (requires shared storage) and vMotion/Storage vMotion (VMware-specific terms), leading candidates to confuse cross-hypervisor features or assume distributed virtual switches solve storage issues.

How to eliminate wrong answers

Option B is wrong because cold migration requires the VM to be powered off, which causes service interruption, contradicting the requirement for high availability without service interruption. Option C is wrong because Storage vMotion is a VMware-specific feature that allows migration without shared storage, but the question specifies a KVM environment, and even in VMware, it requires shared storage for live migration; without shared storage, the VM's disk must be copied, causing downtime. Option D is wrong because a distributed virtual switch (DVS) is a networking abstraction that does not address storage requirements; without shared storage, the VM's disk is inaccessible on the destination host, preventing live migration.

1613
Drag & Dropmedium

Drag and drop the steps of telemetry path validation using YANG DevKit into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Validation starts by loading the YANG model, parsing the path, checking it against the schema, testing it on a device, and then confirming the output.

1614
Drag & Dropmedium

Drag and drop the steps of a RESTCONF PUT transaction on IOS-XE into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order ensures the RESTCONF PUT request is properly authenticated, targeted, and validated before the device applies the configuration. First, the client must authenticate with the device. Then it constructs the PUT request with the target URI.

The device validates the request, applies the configuration, and finally sends a success response.

1615
MCQmedium

A network engineer is designing a QoS policy for a Cisco Catalyst switch. The policy must ensure that voice traffic receives strict priority scheduling, while video and critical data traffic are guaranteed a minimum bandwidth. The engineer decides to use Modular QoS CLI (MQC) to create a policy map. Which queuing mechanism should be configured within the policy map to provide strict priority for voice traffic?

A.shape average
B.priority
C.police
D.bandwidth remaining percent
AnswerB

The priority command in an MQC policy map enables strict priority queuing, which means that traffic in this class is serviced before any other queues as long as the queue is not empty. It also allows configuration of a policer to limit the priority traffic. This is the correct mechanism to ensure voice traffic receives strict priority scheduling, as required.

Why this answer

In MQC, the priority command within a policy map enables strict priority queuing, ensuring that voice traffic is scheduled before other classes. The bandwidth remaining percent command allocates minimum bandwidth but not strict priority; shape average shapes traffic; and police enforces rate limits. Only priority provides the strict priority behavior required for voice.

Exam trap

The trap here is confusing the priority command with bandwidth guarantees; the priority command provides strict priority, while bandwidth remaining percent only guarantees a minimum share after priority traffic is served.

1616
Drag & Dropmedium

Drag and drop the steps of DMVPN Phase 2 NHRP resolution process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In DMVPN Phase 2, the spoke sends an NHRP Resolution Request to the hub to learn the destination spoke's NBMA address. The hub forwards the request to the destination spoke, which replies with an NHRP Resolution Reply. The hub relays this reply back to the originating spoke.

Finally, the originating spoke installs the NHRP shortcut entry and can initiate a direct tunnel to the destination spoke.

1617
MCQhard

A company is deploying a new Cisco wireless LAN controller (WLC) and wants to use RADIUS for authenticating wireless users. The WLC is configured with the RADIUS server IP, shared secret, and authentication port 1812. However, users are unable to authenticate. The network engineer checks the RADIUS server logs and sees that the server is receiving authentication requests from the WLC but is responding with an 'Access-Reject' message. The WLC logs show 'RADIUS server not responding' for the same server. What is the most likely cause?

A.The RADIUS server is configured to use a different source IP address for RADIUS responses than the IP address configured on the WLC, causing the WLC to drop the responses.
B.The WLC is configured with the wrong authentication port; RADIUS uses port 1645, not 1812.
C.The WLC's RADIUS server configuration has the wrong shared secret, causing the server to reject requests.
D.The WLC is not configured with a valid management interface IP address to reach the RADIUS server.
AnswerA

Correct because the WLC typically expects RADIUS responses to come from the same IP address as the configured server; if the server uses a different source IP (e.g., a loopback or secondary IP), the WLC may not recognize the response and logs 'server not responding'.

Why this answer

The RADIUS server is receiving authentication requests and sending 'Access-Reject' responses, but the WLC logs show 'RADIUS server not responding'. This indicates the WLC is not receiving the responses. The most likely cause is a source IP mismatch: the RADIUS server sends responses from a different IP address than the one configured on the WLC.

The WLC drops these responses because they do not match the expected source IP, making it appear as if the server is not responding.

Exam trap

Cisco often tests the subtle difference between a server rejecting requests (wrong secret) versus the client not receiving responses (source IP mismatch), tempting candidates to choose the shared secret option when the logs clearly show the server is processing requests.

How to eliminate wrong answers

Option B is wrong because RADIUS officially uses UDP port 1812 for authentication per RFC 2865; port 1645 is legacy and not the standard. Option C is wrong because if the shared secret were incorrect, the RADIUS server would silently drop the request or send an 'Access-Reject' only after failing to decrypt the packet, but the server logs show it is receiving and processing requests, which requires a matching secret. Option D is wrong because the WLC is successfully sending authentication requests to the RADIUS server (as confirmed by server logs), proving the management interface IP is valid and reachable.

1618
MCQmedium

An engineer is deploying a Linux virtual machine on a KVM hypervisor. The VM needs to be connected to a virtual network that provides isolation from other VMs on the same host but allows communication with the host and external networks. The engineer creates a Linux bridge and attaches the VM's tap interface to it. However, the VM cannot reach the external network. The host has a physical NIC (eth0) connected to the corporate network. What is the missing configuration step?

A.Add the physical NIC (eth0) as a port to the Linux bridge.
B.Configure a default gateway on the VM's network interface.
C.Assign an IP address to the Linux bridge interface.
D.Enable IP forwarding and configure NAT on the host.
AnswerA

The bridge must include a physical uplink port (eth0) to serve as a switching fabric between VMs and the external network. Without eth0 as a port, the bridge is an isolated Layer 2 domain where frames can only reach other VMs or the host itself; nothing is forwarded beyond. Adding eth0 to the bridge (e.g., with 'ip link set eth0 master br0') makes the bridge act like a virtual switch with a trunk/access port to the physical LAN, allowing VM traffic to reach the gateway and other hosts directly.

Why this answer

A Linux bridge acts like a virtual switch. To allow the VM to reach the external network, the physical NIC (eth0) must be added as a port to the bridge. This bridges the VM's tap interface with the host's physical network, enabling Layer 2 connectivity to the corporate network and upstream routing.

Exam trap

The trap here is that candidates confuse bridging with NAT or routing, assuming that IP forwarding or NAT is required for external access, when in fact a bridged setup simply needs the physical NIC as a bridge port to extend Layer 2 connectivity.

How to eliminate wrong answers

Option B is wrong because a default gateway on the VM is necessary for routing beyond the local subnet, but it is not the missing step—the VM cannot even reach the host or external network without the bridge being connected to the physical NIC. Option C is wrong because assigning an IP to the bridge interface is required for the host to communicate on the bridged network, but the VM's inability to reach the external network is due to the lack of physical connectivity, not the bridge's IP. Option D is wrong because enabling IP forwarding and NAT is only needed if the host is acting as a router for the VM (e.g., in a routed or NAT-based setup), but the scenario describes a bridged network where the VM should be on the same Layer 2 segment as the host's physical network, not NAT'd.

1619
MCQeasy

Which component of Cisco ACI is responsible for policy enforcement and forwarding decisions?

A.Cisco Nexus Dashboard
B.Leaf switch
C.Spine switch
D.APIC
AnswerB

Leaf switches in Cisco ACI are responsible for policy enforcement and forwarding decisions. They connect to endpoints (servers, storage, etc.) and apply the policies defined by the APIC. The leaf switches maintain the forwarding tables and enforce contracts between endpoint groups.

Why this answer

Leaf switches in Cisco ACI are responsible for policy enforcement and forwarding decisions. They connect to endpoints and apply the policies programmed by the APIC. The APIC manages the policies, but the leaf switches enforce them and forward traffic based on those policies.

Exam trap

The trap here is assuming that the APIC, as the controller, also enforces policies, but in ACI, the data plane enforcement is done by the leaf switches.

1620
MCQhard

A network administrator is analyzing NetFlow data on a Cisco IOS router to identify top talkers. The administrator notices that a large amount of traffic is being exported but the NetFlow cache is filling up quickly. Which action should the administrator take to reduce the cache size while maintaining visibility into the most significant flows?

A.Enable NetFlow aggregation with a suitable aggregation scheme, such as protocol-port or source-prefix.
B.Decrease the NetFlow cache timeout values for active and inactive flows.
C.Increase the NetFlow cache timeout values for active and inactive flows.
D.Configure NetFlow to export only ingress traffic on all interfaces.
AnswerA

NetFlow aggregation combines individual flows into aggregated flows based on criteria like protocol and port or source prefix. This reduces the number of entries in the cache, lowering memory usage and export volume, while still providing visibility into major traffic patterns. It is an effective way to manage cache size without losing sight of significant flows.

Why this answer

NetFlow aggregation reduces the number of flow entries by combining individual flows into aggregated records based on criteria like protocol and port or source prefix. This directly decreases cache size and export load while preserving visibility into major traffic patterns. Adjusting timeouts can have side effects such as increased export volume or incomplete data, whereas aggregation is designed to optimize cache usage without sacrificing essential visibility.

Exam trap

The trap here is assuming that decreasing timeouts will solve cache size issues; while it can reduce entries, it often leads to more frequent exports and lost granularity, whereas aggregation is the intended method to reduce cache size while maintaining meaningful visibility.

1621
Drag & Dropmedium

Drag and drop the steps of ISE RADIUS policy evaluation order into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Cisco ISE evaluates RADIUS policies in a specific order: first authentication policies, then authorization policies (based on conditions), and finally the default rule if no match is found. This ensures proper access control.

1622
MCQhard

A network architect is designing a QoS policy for a Cisco Catalyst switch that must prioritize voice traffic over all other traffic, while ensuring that bulk data transfers do not starve other applications. The design requires strict priority for voice and a guaranteed minimum bandwidth for business-critical applications. Which two mechanisms should be used together to meet these requirements?

A.Priority Queuing (PQ) and Custom Queuing (CQ)
B.Low Latency Queuing (LLQ) and Class-Based Weighted Fair Queuing (CBWFQ)
C.Class-Based Marking and Policing
D.Weighted Random Early Detection (WRED) and First-In First-Out (FIFO) queuing
AnswerB

LLQ provides a strict priority queue for voice, ensuring low latency and jitter. CBWFQ provides guaranteed bandwidth for other classes, such as business-critical applications, preventing starvation. Together, they meet the requirements by prioritizing voice while allocating minimum bandwidth to other traffic classes.

Why this answer

LLQ and CBWFQ are used together to provide strict priority for voice traffic while guaranteeing bandwidth for other classes. LLQ places voice in a priority queue with a policed rate to prevent starvation, and CBWFQ allocates minimum bandwidth to business-critical applications, ensuring they are not starved by bulk data.

Exam trap

The trap here is confusing congestion avoidance mechanisms like WRED with queuing mechanisms, or assuming that legacy queuing methods provide the same integrated functionality as LLQ and CBWFQ.

1623
Multi-Selecteasy

Which three statements about NFV use cases and deployment models are true? (Choose three.)

Select 3 answers
A.Virtual CPE (vCPE) is a common NFV use case that replaces physical routers and firewalls at customer sites with software-based functions.
B.Virtual Evolved Packet Core (vEPC) virtualizes mobile core network functions such as MME, SGW, and PGW.
C.NFV can be deployed on-premises, in a private cloud, or in a public cloud infrastructure.
D.NFV requires dedicated hardware appliances for each virtualized network function.
E.NFV deployments are limited to static, non-scalable configurations.
AnswersA, B, C

vCPE virtualises branch routing, firewall and WAN functions as software VNFs on commodity hardware, removing dedicated appliances at customer premises. This directly satisfies the stem's requirement for an NFV use case replacing physical routers and firewalls at customer sites.

Why this answer

Option A is correct because Virtual CPE (vCPE) is a widely recognized NFV use case in which customer-premises functions such as routing, firewalling, and NAT are delivered as software VNFs on commodity hardware or virtualized platforms instead of dedicated physical appliances. Option B is correct because the Virtual Evolved Packet Core (vEPC) virtualizes 4G/LTE core elements including the MME (Mobility Management Entity), SGW (Serving Gateway), and PGW (Packet Data Network Gateway) as VNFs running on NFV infrastructure. Option C is correct because NFV can be deployed across multiple environments, including on-premises data centers, private clouds, and public cloud infrastructures, since the NFV architectural framework separates VNFs from the underlying virtualization and hardware layers.

Option D is incorrect because NFV explicitly aims to decouple network functions from proprietary dedicated hardware appliances, running them instead on general-purpose servers and standard virtualization platforms. Option E is incorrect because NFV supports dynamic, elastic, and scalable configurations through MANO (Management and Orchestration) and VNF lifecycle management, rather than being limited to static deployments.

Exam trap

The trap is the pair of absolute statements (D and E) that contradict NFV's core value proposition — any option claiming NFV 'requires dedicated hardware' or is 'limited to static configurations' is automatically false because NFV exists precisely to avoid those limitations.

1624
MCQmedium

A network automation engineer is using the Cisco DNA Center Intent API to retrieve a list of all network devices. The engineer sends a GET request to the URL https://dnac.example.com/api/v1/network-device but receives a 401 Unauthorized error. The engineer has already obtained a valid authentication token. What is the most likely cause of the error?

A.The request must use HTTP instead of HTTPS.
B.The API endpoint /api/v1/network-device requires a POST request.
C.The token must be passed as a query parameter named 'token'.
D.The token was not included in the request header as an X-Auth-Token.
AnswerD

The Cisco DNA Center Intent API requires the authentication token to be included in the HTTP header with the key 'X-Auth-Token'. Without this header, the API returns 401 Unauthorized even if the token is valid. The engineer must add the header 'X-Auth-Token: <token>' to the GET request to authenticate successfully.

Why this answer

The Cisco DNA Center Intent API uses token-based authentication. After obtaining a token via the authentication API, the token must be included in every subsequent request as an HTTP header named 'X-Auth-Token'. Omitting this header causes a 401 Unauthorized response.

The engineer should add the header with the valid token to successfully retrieve the device list. Other methods like query parameters or different HTTP methods are not used for authentication.

Exam trap

The trap here is assuming the token can be passed as a query parameter or that HTTP is acceptable, when DNA Center strictly requires the token in the X-Auth-Token header over HTTPS.

1625
MCQhard

An engineer is configuring BGP on a router that will act as a route reflector to reduce iBGP peering requirements. The router has several iBGP peers. The engineer wants to ensure that the route reflector does not modify the next-hop attribute of routes it reflects to its clients. Which configuration command should the engineer use?

A.Configure 'neighbor next-hop-unchanged' under the BGP address family for the route reflector clients.
B.Configure 'no bgp next-hop-self' under the BGP address family for the route reflector clients.
C.Configure 'bgp route-reflector' under the BGP address family.
D.Configure 'neighbor next-hop-self' on the route reflector for its clients.
AnswerA

Configuring 'neighbor next-hop-unchanged' under the BGP address family for route-reflector clients explicitly tells the router to leave the next-hop attribute untouched when reflecting routes. This is the correct method because it preserves the original next-hop as advertised by the eBGP peer or other source, preventing the route reflector from replacing it with its own address. The command is applied per-neighbor within the address family, and it overrides the default behavior where the router might otherwise modify the next-hop to itself. By doing so, clients learn the true next-hop and can forward traffic optimally without an unnecessary hop through the reflector.

Why this answer

The 'neighbor next-hop-unchanged' command under the BGP address family instructs the route reflector to preserve the original next-hop attribute when reflecting routes to its clients. By default, a route reflector may modify the next-hop to its own address, but this command overrides that behavior, ensuring the next-hop remains as received from the non-client iBGP peer. This is essential in designs where clients must see the original next-hop for optimal path selection or to avoid unnecessary routing hops.

Exam trap

Cisco often tests the distinction between 'neighbor next-hop-unchanged' and 'neighbor next-hop-self', where candidates mistakenly think that disabling 'next-hop-self' (option B) is sufficient to preserve the next-hop, but the correct command is the explicit 'next-hop-unchanged' to override any default or configured modifications.

How to eliminate wrong answers

Option B is wrong because 'no bgp next-hop-self' removes the default next-hop-self behavior for eBGP-learned routes, but it does not specifically control the next-hop attribute for routes reflected by a route reflector; it is a global or address-family command that affects all iBGP peers, not just clients. Option C is wrong because 'bgp route-reflector' is not a valid Cisco IOS command; the correct command to enable route reflection is 'neighbor route-reflector-client' under the BGP address family. Option D is wrong because 'neighbor next-hop-self' on the route reflector for its clients would force the next-hop to be changed to the route reflector's own IP address, which is the opposite of what the engineer wants (to leave the next-hop unchanged).

1626
MCQhard

A network engineer runs the following command on Switch SW9: SW9# show etherchannel 4 port-channel Port-channels in the group: --------------------------- Port-channel: Po4 (Primary Aggregator) Age of the Port-channel = 0d:00h:20m:10s Logical slot/port = 16/4 Number of ports = 3 HotStandby port = null Port state = Port-channel Ag-Inuse Protocol = LACP Ports in the Port-channel: Index Load Port EC state No of bits ------+------+------+----------------+---------- 0 00 Gi0/0 Active 4 1 00 Gi0/1 Active 4 2 00 Gi0/2 Standby 4 Time since last port bundled: 0d:00h:15m:00s Gi0/1 Based on this output, what can be concluded?

A.All three ports are actively forwarding traffic in the EtherChannel.
B.Gi0/2 is in standby mode because it is not receiving LACP packets from the neighbor.
C.The EtherChannel has a maximum bundle size of 2, so Gi0/2 is a hot-standby port.
D.The port-channel is not in use because the load is zero.
AnswerC

This is the correct interpretation: Cisco switches allow you to limit the active bundle size using either "port-channel max-bundle" or "lacp max-bundle," and when that limit is reached, surplus operational links become hot-standby ports. Gi0/2 is a fully functioning LACP participant but is intentionally not included in the active set of two ports. It continuously exchanges LACP messages and stays synchronized, so it can seamlessly assume forwarding duties without renegotiation should either of the two active ports go down.

Why this answer

The output shows three ports in the port-channel, but only two are in the 'Active' state (Gi0/0 and Gi0/1), while Gi0/2 is in 'Standby' state. This indicates that the EtherChannel has a maximum bundle size of 2, likely configured with the 'lacp max-bundle 2' command, which limits the number of active ports to two, making Gi0/2 a hot-standby port that will become active only if one of the active ports fails.

Exam trap

The trap here is that candidates often misinterpret the 'Standby' state as a failure or misconfiguration (like not receiving LACP packets), rather than recognizing it as a deliberate feature of LACP's max-bundle configuration.

How to eliminate wrong answers

Option A is wrong because Gi0/2 is in 'Standby' state, not 'Active', so it is not forwarding traffic; only two ports are actively forwarding. Option B is wrong because standby mode in LACP is not due to a failure to receive LACP packets—if Gi0/2 were not receiving LACP packets, it would be in a 'Down' or 'Suspended' state, not 'Standby'; standby is a deliberate configuration for redundancy. Option D is wrong because the load value of '00' in the output is a placeholder for load balancing information and does not indicate that the port-channel is not in use; the port-channel is 'Ag-Inuse' (Aggregator In Use), meaning it is actively forwarding traffic on the active ports.

1627
Multi-Selecthard

Which three statements about error handling and debugging in Python network automation scripts are true? (Choose three.)

Select 3 answers
A.Using 'pass' in an except block is a best practice to ignore errors in production scripts.
B.The try-except block allows a script to handle connection timeouts without crashing.
C.Using the logging module helps record errors and debug information to a file.
D.Print statements can be used to debug variable values during script development.
E.The continue statement is used to handle exceptions in Python.
AnswersB, C, D

Wrapping connection attempts in try-except lets the script catch socket timeouts and similar exceptions, then log or retry rather than terminating abruptly. This directly satisfies the stem's requirement that a script handle connection timeouts without crashing.

Why this answer

Option B is correct because wrapping network calls (e.g., socket.connect or requests.get) in a try-except block lets the script catch exceptions like socket.timeout or TimeoutError and handle them gracefully instead of terminating. Option C is correct because Python's logging module provides configurable handlers such as FileHandler and RotatingFileHandler to persist error and debug messages to a file, which is essential for auditing automation runs. Option D is correct because print() statements are a common, simple debugging technique during development to inspect variable values and trace execution flow before formal logging is added.

Option A is not correct because using 'pass' in an except block silently swallows exceptions, hiding failures and making production troubleshooting difficult; best practice is to log or re-raise. Option E is not correct because 'continue' is a loop control statement that skips to the next iteration, not an exception-handling mechanism; exceptions are handled with try-except-finally.

1628
MCQmedium

A network architect is designing a Cisco SD-WAN fabric for a company with 30 branch sites and two data centers. The architect wants to ensure that control plane information is exchanged securely and that data plane traffic can be forwarded even if the control plane is temporarily unavailable. Which component should be deployed to meet these requirements?

A.Cisco vEdge routers
B.Cisco vSmart
C.Cisco vBond
D.Cisco vManage
AnswerA

Cisco vEdge routers (or cEdge routers) are the data plane components at branch and data center sites. They establish secure control connections to vSmart and vBond, and they forward data plane traffic based on policies and routes received. They can continue forwarding traffic using cached control information if the control plane is temporarily unavailable, satisfying the scenario.

Why this answer

The data plane in Cisco SD-WAN is handled by vEdge/cEdge routers, which forward traffic and maintain secure connections to the control plane. They can continue forwarding based on last-known routing and policy information if the control plane is disrupted. The management plane (vManage), orchestration plane (vBond), and control plane (vSmart) do not forward production data traffic, so they cannot meet the requirement for continued data plane forwarding.

Exam trap

The trap here is assuming that the control plane component (vSmart) also forwards data traffic, when in fact SD-WAN separates control, data, management, and orchestration planes.

1629
Drag & Dropmedium

Drag and drop the steps of the RADIUS authentication process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

RADIUS uses UDP and encrypts only the password in the Access-Request. The server checks credentials and responds with Access-Accept or Access-Reject. Accounting-Start is sent after authentication succeeds.

1630
MCQmedium

A network engineer wants to automate configuration backups for a fleet of Cisco IOS XE devices using Ansible. The engineer uses the ios_config module with the backup: yes option and sets the backup directory via the ANSIBLE_BACKUP_DIR environment variable. After running the playbook, the engineer finds that no backup files are created on the control node. What is the most likely cause?

A.The ios_config module does not support the backup option; the ios_command module must be used instead.
B.The ios_config module requires the backup option to be set to a file path, not a boolean value.
C.The ANSIBLE_BACKUP_DIR environment variable is not recognized by Ansible; the backup directory must be specified using the backup_options parameter in the task.
D.The Ansible control node must have the paramiko library installed for backups to work; otherwise, backups are silently skipped.
AnswerC

Ansible does not use an environment variable named ANSIBLE_BACKUP_DIR to set the backup directory. Instead, the ios_config module provides the backup_options parameter, which includes a dir_path sub-option to specify where backups are stored. Without this, backups may be saved to a default location or not at all, depending on the Ansible version.

Why this answer

The ios_config module's backup feature saves the device configuration to the Ansible control node. The directory for these backups is not controlled by an environment variable like ANSIBLE_BACKUP_DIR; instead, it is set using the backup_options parameter, specifically the dir_path sub-option. Without specifying this, backups may go to a default location or fail to be created, leading to the observed issue.

Exam trap

The trap here is assuming that Ansible uses environment variables to configure module-specific options like backup directories, when in fact such options are defined within the playbook task itself.

1631
MCQmedium

A network engineer runs the following command on Switch SW6: SW6# show spanning-tree vlan 60 VLAN0060 Spanning tree enabled protocol ieee Root ID Priority 24636 Address aabb.cc00.0a00 Cost 8 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32768 (priority 32768 sys-id-ext 60) Address aabb.cc00.0b00 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- ------------------------------ Gi0/1 Root FWD 8 128.1 P2p Gi0/2 Desg FWD 4 128.2 P2p Gi0/3 Altn BLK 4 128.3 P2p Gi0/4 Desg FWD 4 128.4 P2p Based on this output, what is the bridge priority of the root bridge for VLAN 60?

A.24576
B.24636
C.32768
D.32828
AnswerB

The Root ID priority in the output is 24636, which is the complete 16-bit priority value formed by the base priority (24576, or 0x6000) plus the VLAN system ID extension (60, or 0x003C). This value is lower than 32768, indicating that the root bridge has a higher priority (a lower numeric value) than the default, which is why it won the root election. Thus, 24636 is the correct answer.

Why this answer

The root bridge's priority is shown in the 'Root ID' section as 'Priority 24636'. This value includes the system ID extension (VLAN 60), so the actual bridge priority is 24636 - 60 = 24576. However, the question asks for the bridge priority as displayed in the output, which is 24636.

Option B is correct because the output explicitly lists the root bridge priority as 24636.

Exam trap

Cisco often tests whether candidates understand that the 'Priority' field in the 'Root ID' section includes the system ID extension (VLAN ID), so the displayed value is not the base priority but the combined value, leading many to incorrectly subtract the VLAN ID when the question simply asks for the value as shown.

How to eliminate wrong answers

Option A is wrong because 24576 is the base priority (24636 minus the VLAN 60 sys-id-ext), but the question asks for the bridge priority as shown in the output, which includes the system ID extension. Option C is wrong because 32768 is the bridge priority of the local switch (SW6), not the root bridge. Option D is wrong because 32828 is not a valid priority value in this context; it might be a distractor combining the local bridge priority (32768) with the VLAN ID (60) incorrectly.

1632
MCQmedium

A network engineer is deploying a VXLAN EVPN fabric. The underlay is a routed Layer 3 network using OSPF. Hosts in the same subnet are attached to leaf switches that are not directly connected. The engineer must ensure that the fabric provides optimal forwarding for East-West traffic without tromboning through a centralized gateway. Which VXLAN component should be configured to accomplish this?

A.Anycast distributed gateway with the same MAC and IP on all leaf switches
B.OSPF area 0 with stub areas on all leaf switches to reduce LSAs
C.Static VXLAN tunnel endpoints mapped to each leaf switch's loopback address
D.VXLAN Network Identifier (VNI) mapping to a single centralized gateway
AnswerA

An anycast distributed gateway configures the same gateway IP and MAC on every leaf switch, so each leaf can route traffic locally for its directly attached hosts. This avoids sending traffic to a centralized gateway and prevents suboptimal tromboning. It is the standard VXLAN EVPN design for optimal East-West forwarding.

Why this answer

An anycast distributed gateway places the same gateway IP and MAC on every leaf switch, allowing each leaf to route traffic for its local hosts. This eliminates the need to send traffic to a centralized gateway, providing optimal East-West forwarding. It is a key feature of VXLAN EVPN fabrics for efficient inter-subnet routing.

Exam trap

The trap here is assuming that any gateway configuration will automatically optimize East-West traffic, when in fact only a distributed anycast gateway avoids tromboning.

1633
MCQhard

A network engineer is using the RESTCONF API on a Cisco IOS XE device to configure an interface. The engineer sends a PATCH request to the URL https://device/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1 with the following JSON payload: {"ietf-interfaces:interface": {"description": "Uplink to Core"}}. The request returns a 400 Bad Request error. What is the most likely reason for this error?

A.The URL should use the data store 'running' instead of 'data'.
B.The Content-Type header is missing or incorrect; it should be application/yang-data+json.
C.The PATCH method is not supported by RESTCONF; PUT should be used instead.
D.The interface name must be URL-encoded, so GigabitEthernet1 should be GigabitEthernet%31.
AnswerB

RESTCONF requires the Content-Type header to be set to 'application/yang-data+json' when sending JSON payloads. If the header is missing or set to 'application/json', the server may reject the request with a 400 Bad Request. The engineer must include the correct media type to ensure the server parses the payload correctly.

Why this answer

RESTCONF requires the Content-Type header to be 'application/yang-data+json' for JSON payloads. Without this header, the server cannot interpret the payload and returns a 400 Bad Request. The PATCH method is supported, the URL path is correct, and the interface name does not need encoding.

Ensuring the correct media type resolves the error.

Exam trap

The trap here is focusing on the HTTP method or URL structure while overlooking the mandatory Content-Type header required by RESTCONF for JSON payloads.

1634
Drag & Dropmedium

Drag and drop the steps of PIM-SM join and source registration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In PIM-SM, a receiver's DR sends a (*,G) Join toward the RP. The RP then sends a (S,G) Join toward the source. The source's DR registers the source with the RP via a unicast Register message.

The RP de-encapsulates the Register and sends a Register-Stop back to the source's DR to stop the registration process.

1635
MCQhard

A network engineer is using the YANG Suite tool to explore YANG models on a Cisco IOS XE device. The engineer wants to retrieve the operational state of all interfaces using NETCONF. The engineer sends a <get> RPC with a filter that selects the 'interfaces-state' container from the ietf-interfaces YANG module. The device returns an empty response. The engineer confirms that interfaces are up and running. What is the most likely reason for the empty response?

A.The 'interfaces-state' container is deprecated in favor of the 'interfaces' container with 'config false' nodes.
B.The ietf-interfaces YANG module is not supported by the device.
C.The NETCONF session is using the 'candidate' datastore, which does not contain operational data.
D.The filter is using the wrong namespace for the ietf-interfaces module.
AnswerA

In newer revisions of the ietf-interfaces YANG module (RFC 8343), the 'interfaces-state' container was removed and replaced by the 'interfaces' container containing both configuration and state data, with state nodes marked as 'config false'. If the device implements the newer model, a filter targeting 'interfaces-state' will return no data. The engineer should query the 'interfaces' container instead.

Why this answer

The ietf-interfaces YANG module has evolved. In RFC 8343, the 'interfaces-state' container was deprecated and its contents merged into the 'interfaces' container. State data is now represented as 'config false' nodes within the same tree.

If a device implements the newer revision, a filter for 'interfaces-state' will not match any data, resulting in an empty response. The engineer should adjust the filter to target the 'interfaces' container and look for state nodes.

Exam trap

The trap here is assuming that the 'interfaces-state' container still exists in all implementations, when it has been deprecated in newer YANG models.

1636
MCQeasy

A network automation team wants to programmatically configure a Cisco Catalyst 9300 switch using RESTCONF. The switch is running Cisco IOS XE 17.x. Which HTTP method should be used to create a new VLAN by sending a JSON payload to the RESTCONF URI /restconf/data/Cisco-IOS-XE-vlan:vlan?

A.GET
B.PUT
C.PATCH
D.POST
AnswerD

RESTCONF uses POST to create a new resource in a data tree. Sending a JSON body to the VLAN list URI creates the specified VLAN. The device responds with 201 Created and a Location header. This is the correct method when the target resource does not yet exist and you are adding a new list entry.

Why this answer

RESTCONF maps CRUD operations to HTTP methods: POST creates a new resource within a collection. To add a new VLAN to the VLAN list, the correct method is POST to the list URI. PUT would require the full resource URI and replaces content, PATCH modifies existing resources, and GET only reads.

Thus POST is the correct choice for creating a new VLAN.

Exam trap

The trap here is confusing POST with PUT; POST creates a subordinate resource in a collection, while PUT creates or replaces a resource at a specific URI.

1637
Drag & Dropmedium

Drag and drop the steps of DNA Center assurance issue detection and root cause into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with collecting telemetry from devices, then analyzing the data to detect anomalies, then generating an issue, then identifying the root cause via guided remediation, and finally presenting the resolution steps. This aligns with Cisco's assurance workflow.

1638
MCQmedium

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP polling. A class-map named CLASS-MGMT matches SNMP and SSH traffic, and a policy-map named COPP-POLICY applies a police rate of 8000 bps with a conform-action transmit and exceed-action drop for that class. After the policy is attached to the control plane, SNMP polling intermittently fails while BGP remains stable. Which action should the engineer take to resolve the SNMP failures while still protecting the route processor?

A.Move the policy-map from the control plane to the data plane interface facing the SNMP server.
B.Add a new class-map that matches BGP and apply a lower police rate to it, then reattach the policy.
C.Increase the police rate in the CLASS-MGMT class to a value that accommodates the normal SNMP and SSH burst rate.
D.Change the exceed-action from drop to transmit so that SNMP packets are never discarded.
AnswerC

SNMP polling and SSH generate bursty traffic to the route processor. An 8000 bps police rate is far below the normal management traffic rate, so conforming packets are transmitted but excess packets are dropped, causing intermittent SNMP failures. Raising the rate for that class to match observed management traffic preserves CoPP protection while allowing legitimate management polling to reach the control plane.

Why this answer

SNMP polling is bursty and can briefly exceed a very low police rate. When the exceed-action drops packets, polling becomes intermittent. The correct fix is to raise the police rate for the management class to a value that reflects real SNMP and SSH traffic while keeping CoPP in place to protect the route processor from abuse.

Disabling enforcement or moving the policy to the data plane is not appropriate.

Exam trap

The trap here is assuming that any CoPP drop means the policy should be removed or the exceed-action changed to transmit, rather than tuning the rate to match legitimate control-plane traffic.

1639
Drag & Dropmedium

Drag and drop the steps of BFD session establishment for path liveliness into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

BFD session establishment starts with the edge device detecting a new transport tunnel, then sending a BFD hello packet, the remote device responds with a BFD echo, the two devices negotiate parameters, and finally the session becomes Up and is used for liveliness monitoring.

1640
MCQeasy

What is the purpose of the 'aaa authorization exec default local' command?

A.It authenticates users for exec access using the local database.
B.It authorizes exec sessions using the local database, determining if a user can start a shell and their privilege level.
C.It enables accounting for exec commands to the local database.
D.It sets the privilege level for all users to 15.
AnswerB

The 'aaa authorization exec default local' command configures authorization for exec (shell) sessions using the local user database. When a user is authenticated, this level of authorization checks the locally configured 'username' entry, including its 'privilege' attribute, to determine whether the user may start an exec shell and at what privilege level (1-15) they will operate.

Why this answer

The 'aaa authorization exec default local' command is used to authorize EXEC sessions (user shell access) by checking the local database on the device. It determines whether a user is permitted to start a shell and what privilege level they should receive, based on the local user account configuration. This is distinct from authentication, which verifies identity, and accounting, which logs actions.

Exam trap

Cisco often tests the distinction between authentication, authorization, and accounting; the trap here is confusing 'authorization' with 'authentication', leading candidates to pick Option A because they think the command is about verifying who the user is, rather than what they are allowed to do.

How to eliminate wrong answers

Option A is wrong because it describes authentication (verifying user identity), not authorization (determining allowed actions and privilege level); the command uses 'authorization', not 'authentication'. Option C is wrong because it refers to accounting (logging commands), which is configured with 'aaa accounting exec' commands, not authorization. Option D is wrong because the command does not set a privilege level of 15 for all users; it authorizes based on the local database, where privilege levels are defined per user account (e.g., via 'username privilege 15').

1641
MCQhard

A network engineer runs the following command on Router R2: R2# show class-map Class Map match-any VOICE (id 1) Match ip dscp ef (46) Class Map match-any DATA (id 2) Match ip dscp af31 (26) Class Map match-any class-default (id 0) Match any R2# show policy-map Policy Map QOS_POLICY Class VOICE priority level 1 police cir 1000000 bc 15625 be 15625 Class DATA bandwidth remaining percent 50 Class class-default bandwidth remaining percent 50 R2# show policy-map interface GigabitEthernet0/1 GigabitEthernet0/1 Service-policy output: QOS_POLICY Class-map: VOICE (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp ef (46) Queueing strict priority queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 police cir 1000000 bc 15625 be 15625 conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: DATA (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp af31 (26) Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 bandwidth remaining percent 50 (0 kbps) Class-map: class-default (match-any) 100 packets, 10000 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 100/10000 bandwidth remaining percent 50 (0 kbps) Based on this output, what can be concluded?

A.Voice traffic is being prioritized with strict priority queuing and policed at 1 Mbps.
B.Data traffic is being guaranteed 50% of the remaining bandwidth.
C.All traffic is being handled by class-default, which gets 100% of the bandwidth.
D.The police command on VOICE is causing drops for voice traffic.
AnswerC

This option is correct because the policy-map output shows that only class-default has matched traffic, with 100 packets. On Cisco IOS, class-default is the implicit final class that catches all packets not matched by user-defined class-maps; when it is the only class with non-zero traffic, it is allowed to use 100% of the interface bandwidth. Since VOICE and DATA classes are empty, no other queuing or policing actions are invoked, and class-default receives the full link capacity.

Why this answer

The output shows that only class-default has processed any packets (100 packets, 10000 bytes), while the VOICE and DATA classes have zero packets. This indicates that no traffic matching DSCP EF or AF31 has been offered, so all traffic falls into class-default, which is allocated 50% of the remaining bandwidth. However, since the VOICE class is empty, the priority queue is unused, and class-default effectively receives all available bandwidth.

Exam trap

Cisco often tests the misconception that simply configuring a QoS policy means it is actively shaping or prioritizing traffic, but the key is to check the actual packet counters to see which classes are receiving traffic.

How to eliminate wrong answers

Option A is wrong because although the VOICE class is configured with strict priority queuing and a police rate of 1 Mbps, the output shows zero packets matched for VOICE, so no voice traffic is being prioritized or policed. Option B is wrong because the DATA class is configured with bandwidth remaining percent 50, but again zero packets have been matched for DATA, so no data traffic is being guaranteed that bandwidth. Option D is wrong because the police command on VOICE is not causing drops for voice traffic; the output shows zero packets in the VOICE class, so no policing actions have been triggered.

1642
MCQmedium

Given the following policy-map: policy-map QOS_POLICY class VOICE priority percent 30 class VIDEO bandwidth percent 20 queue-limit 100 packets class class-default fair-queue What is the effect of the 'priority percent 30' command in the VOICE class?

A.Voice traffic is placed in a strict priority queue with a guaranteed bandwidth of 30% of the interface bandwidth.
B.Voice traffic is limited to 30% of the interface bandwidth and will be dropped if exceeded.
C.Voice traffic is given a weight of 30 in the weighted fair queueing algorithm.
D.Voice traffic is re-marked with IP precedence 30.
AnswerA

The priority command in a Cisco MQC policy map creates a strict priority queue (PQ) for the voice class, which is drained by the scheduler before any other queue. The percentage specifies the bandwidth reserved for that queue during congestion, ensuring low latency and jitter for real-time traffic. This guarantee is measured against the interface bandwidth, so voice always has a dedicated share of link capacity even under heavy load.

Why this answer

The 'priority percent 30' command in the VOICE class configures a strict priority queue (LLQ) that guarantees voice traffic up to 30% of the interface bandwidth. During congestion, voice packets are always transmitted before other traffic, but they are policed to ensure they do not exceed the allocated 30%, preventing starvation of other queues.

Exam trap

Cisco often tests the misconception that 'priority percent' simply limits bandwidth like a policer, but the key trap is that it also provides strict priority queuing, which guarantees low latency for voice traffic, not just a bandwidth cap.

How to eliminate wrong answers

Option B is wrong because the priority percent command does not simply drop traffic that exceeds 30%; it polices the traffic, but during congestion, excess packets are dropped, while under no congestion, voice can burst above the percentage. Option C is wrong because the priority command creates a strict priority queue, not a weighted fair queue; weighted fair queueing uses weights for bandwidth allocation, not for priority queuing. Option D is wrong because the priority percent command does not re-mark packets; it only affects queuing and policing behavior, while marking is done by a separate 'set' command in a policy-map.

1643
Drag & Dropmedium

Drag and drop the steps of iBGP route reflection configuration steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Route reflection requires first enabling BGP, then configuring the cluster ID, designating the route reflector client, and finally verifying the reflection behavior.

1644
MCQmedium

A security architect is designing a campus network where all access-layer switch ports must authenticate endpoints before granting any Layer 2 connectivity. The design requires the switch to communicate with Cisco ISE using EAP over RADIUS, and the endpoint must be validated before any VLAN assignment occurs. Which 802.1X component role must the access-layer switch perform in this design?

A.Authentication server
B.RADIUS proxy
C.Authenticator
D.Supplicant
AnswerC

The switch acts as the authenticator, controlling access to the port based on the outcome of EAP exchanges with the endpoint and RADIUS decisions from Cisco ISE. It relays EAP frames between the supplicant and authentication server, enforces port authorization state, and applies VLAN or ACL results. This matches the requirement that endpoints be authenticated before any Layer 2 connectivity is granted.

Why this answer

In 802.1X, the three roles are supplicant, authenticator, and authentication server. The access-layer switch controls the physical port and relays EAP messages between the endpoint and Cisco ISE, so it functions as the authenticator. It also enforces the authorization result, such as a dynamic VLAN or downloadable ACL, which satisfies the requirement that the endpoint be validated before Layer 2 access is granted.

Exam trap

The trap here is confusing the switch that enforces port access with the server that validates credentials, which leads candidates to select the authentication server role.

1645
MCQmedium

A network engineer is configuring a Cisco Wireless LAN Controller (WLC) to support a new WLAN that requires 802.1X authentication with EAP-TLS. The engineer must ensure that the WLC forwards authentication requests to an external RADIUS server. Which configuration is required on the WLC?

A.Enable PSK on the WLAN and configure a pre-shared key.
B.Define a RADIUS server on the WLC and set the WLAN security to 802.1X with the RADIUS server selected.
C.Set the WLAN security to 802.1X and enable the local EAP server on the WLC.
D.Configure the WLAN with Web Policy authentication and a local net user.
AnswerB

For 802.1X with EAP-TLS, the WLC must act as a RADIUS client and forward EAP messages to an external RADIUS server. Configuring the server on the WLC and selecting it in the WLAN's security settings enables this. The WLC does not terminate EAP-TLS; it passes the authentication to the RADIUS server.

Why this answer

To support 802.1X with EAP-TLS, the WLC must be configured with an external RADIUS server and the WLAN must use 802.1X security referencing that server. The WLC then relays EAP messages between the client and the RADIUS server, which performs certificate-based authentication. This is the standard deployment for enterprise wireless with EAP-TLS.

Exam trap

The trap here is assuming the WLC can locally terminate EAP-TLS, when it typically proxies EAP to an external RADIUS server for certificate validation.

1646
MCQmedium

A network engineer is configuring a Cisco Nexus 9000 switch with VXLAN EVPN. The engineer wants to ensure that the switch can forward traffic between VLANs that are mapped to the same VXLAN Network Identifier (VNI) but are on different leaf switches. Which component is responsible for mapping the VLAN to the VNI on the ingress leaf switch?

A.Ingress replication
B.VLAN-to-VNI mapping
C.VXLAN Tunnel Endpoint (VTEP)
D.EVPN route type 2
AnswerB

The VLAN-to-VNI mapping is configured on the ingress leaf switch to associate a VLAN with a VNI. When a frame arrives on an access port in a VLAN, the switch uses this mapping to encapsulate the frame in VXLAN with the corresponding VNI. This allows Layer 2 connectivity to be extended across the VXLAN fabric. The mapping is typically configured under the VLAN configuration or via a VLAN-VNI mapping command. Without this mapping, the switch would not know which VNI to use for encapsulation.

Why this answer

The VLAN-to-VNI mapping is the component that associates a VLAN with a VNI on the ingress leaf switch. When a frame enters the access port, the switch uses this mapping to encapsulate it in VXLAN with the correct VNI. EVPN route type 2 is for MAC/IP advertisement, the VTEP encapsulates and decapsulates VXLAN traffic, and ingress replication is used for BUM traffic handling.

Only the VLAN-to-VNI mapping directly performs the required function.

Exam trap

The trap here is confusing the VTEP with the VLAN-to-VNI mapping, as the VTEP uses the mapping but is not the mapping itself.

1647
Drag & Dropmedium

Drag and drop the steps of the hierarchical campus network design process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order begins with implementing the core layer to establish high-speed backbone switching. Next, connect WAN edge routers for remote site access, followed by verifying end-to-end connectivity and redundancy to ensure the infrastructure works before adding edge services. Then, design the access layer with VLANs and port security, and finally configure the distribution layer for inter-VLAN routing.

This sequence ensures the foundational transport is in place before adding user-facing and aggregation services.

1648
MCQhard

A network engineer is troubleshooting QoS on a Cisco Nexus 9000 switch. The switch is configured with a policy map that uses a class-default with a bandwidth remaining percent of 100. However, during congestion, traffic in a priority queue (class-map for EF) is experiencing drops even though the priority queue is not fully utilized. What is the most likely cause?

A.The priority queue is implicitly policed to a default rate on Nexus switches
B.The class-default bandwidth remaining percent should be set to 0
C.The priority queue is not configured with a queue-limit
D.The switch is using strict priority queuing without any shaping
AnswerA

On Cisco Nexus switches, the strict priority queue is not left uncapped; NX-OS implicitly applies a default policer to the priority queue (often the interface line rate or a platform-specific default) even when you do not configure a 'police' command. This policer uses a token bucket that drops traffic exceeding the allowed rate, so bursts of high-priority traffic can be dropped. The drops are therefore caused by policing, not by queuing or scheduling, which is why this is the correct diagnosis.

Why this answer

On Cisco Nexus 9000 switches, a priority queue (class-map for EF) is implicitly policed to a default rate of 1 Gbps (or the interface speed, whichever is lower) when no explicit policer is configured. This implicit policing can cause drops in the priority queue even if the queue itself is not fully utilized, because the policer rate limits the traffic before it enters the queue. The class-default bandwidth remaining percent of 100 is unrelated to this issue, as it only affects non-priority queues during congestion.

Exam trap

Cisco often tests the misconception that priority queue drops are always due to queue exhaustion or misconfigured bandwidth percentages, when in reality the implicit policer on Nexus platforms is the hidden cause.

How to eliminate wrong answers

Option B is wrong because setting class-default bandwidth remaining percent to 0 would starve all non-priority traffic, but it does not address the implicit policing of the priority queue. Option C is wrong because a queue-limit is not required for priority queues on Nexus switches; the default queue-limit is sufficient, and drops are caused by policing, not queue depth. Option D is wrong because strict priority queuing without shaping is the expected behavior for a priority queue, and it does not cause drops unless the policer rate is exceeded.

1649
Multi-Selecthard

A security architect is designing a Zero Trust access solution for a campus using Cisco Identity Services Engine. The requirement is to enforce dynamic, identity-based segmentation without relying solely on static VLANs, and to support both wired and wireless endpoints. Which two capabilities should be leveraged? (Choose two.)

Select 2 answers
A.Change of Authorization (CoA) from ISE to dynamically reapply authorization policies on session changes
B.Cisco Platform Exchange Grid (pxGrid) to share context between ISE and third-party security tools
C.Security Group Tags (SGTs) applied via ISE and enforced by Cisco TrustSec-capable switches
D.MAC Authentication Bypass (MAB) as the primary authentication method for all endpoints
E.Static VLAN assignment per access switch port to isolate user groups
AnswersA, C

CoA lets ISE push new authorization results, such as a new SGT or VLAN, to the network access device when posture or identity changes. This enables dynamic enforcement without reconnecting the endpoint. Combined with SGTs, CoA ensures segmentation stays current as conditions change, which is essential for a Zero Trust model across wired and wireless.

Why this answer

Security Group Tags assigned by ISE and enforced by TrustSec-capable switches provide identity-based segmentation independent of VLANs, while Change of Authorization allows ISE to dynamically update authorization results as identity or posture changes. Together they deliver dynamic, identity-driven access across wired and wireless, which static VLANs, MAB, or pxGrid alone cannot achieve.

Exam trap

The trap here is selecting pxGrid or MAB as if they enforced segmentation, when in fact SGTs plus CoA are the mechanisms that dynamically tag and reauthorize endpoint traffic.

1650
MCQmedium

An architect is designing an SD-Access fabric for a campus with multiple buildings. The design must support wireless clients seamlessly roaming across fabric edge nodes. Which technology is used in the fabric to provide mobility for wireless endpoints?

A.LISP
B.VXLAN
C.OTV
D.MPLS
AnswerA

LISP separates endpoint identity (EID) from location (RLOC), so a roaming wireless client keeps its IP address while the fabric edge registers the new RLOC with the control plane. This satisfies the seamless roaming constraint across edge nodes without re-addressing clients.

Why this answer

LISP (Locator/ID Separation Protocol) is the correct technology because it decouples the endpoint identifier (EID) from its routing locator (RLOC), enabling seamless roaming across fabric edge nodes. In SD-Access, LISP maintains a mapping database that tracks wireless endpoint locations, allowing traffic to be forwarded to the correct fabric edge without re-anchoring or tunneling changes as clients move between access points.

Exam trap

Cisco often tests the misconception that VXLAN alone handles mobility, but the trap here is that VXLAN is only the data-plane encapsulation; LISP is the control-plane protocol that actually enables endpoint tracking and seamless roaming in SD-Access.

How to eliminate wrong answers

Option B (VXLAN) is wrong because VXLAN is used for network virtualization and overlay encapsulation in SD-Access, but it does not provide endpoint mobility or location tracking; LISP handles the control plane for mobility. Option C (OTV) is wrong because OTV is a Layer 2 extension technology for connecting data centers over Layer 3 networks, not designed for endpoint mobility within a campus fabric. Option D (MPLS) is wrong because MPLS is a label-switching transport technology used for traffic engineering and VPNs, lacking the endpoint identity-to-location mapping required for wireless roaming in SD-Access.

Page 21

Page 22 of 26

Page 23