Courseiva

ENCOR 350-401 (350-401) — Questions 1651–1725

1923 questions total · 26pages · All types, answers revealed

Page 22

Page 23 of 26

Page 24
1651
MCQmedium

Examine the following configuration snippet on a Cisco IOS-XE router: interface GigabitEthernet0/1 ip vrf forwarding BLUE ip address 192.168.1.1 255.255.255.0 no shutdown What is the effect of this configuration?

A.The interface is placed into VRF BLUE, and all traffic sent or received on this interface uses the routing table of VRF BLUE.
B.The interface remains in the global routing table but is allowed to communicate with VRF BLUE via route leaking.
C.The interface is placed into VRF BLUE, but the IP address is assigned from the global routing table.
D.The configuration is invalid because VRF BLUE must be created first using 'vrf definition BLUE'.
AnswerA

Configuring 'vrf forwarding BLUE' on an interface assigns that interface to VRF BLUE, removing it from the global routing context. Any IPv4 or IPv6 address subsequently configured on the interface is installed in VRF BLUE's separate routing and forwarding tables. As a result, all traffic transiting the interface is looked up exclusively in the VRF BLUE table, providing complete path isolation from the global table.

Why this answer

The 'ip vrf forwarding BLUE' command associates the interface with VRF BLUE, which creates a separate routing table instance. All traffic entering or exiting this interface is forwarded using the VRF BLUE routing table, not the global routing table. This isolates the interface's traffic from the global routing domain.

Exam trap

Candidates may incorrectly think that the 'ip vrf forwarding BLUE' command on an interface creates the VRF automatically. In Cisco IOS-XE, the VRF must first be defined using 'vrf definition BLUE' before the interface can be associated with it. If the VRF does not exist, the command will be rejected.

How to eliminate wrong answers

Option B is wrong because the interface is not in the global routing table; 'ip vrf forwarding' moves the interface entirely into the VRF, and route leaking is an explicit additional configuration (e.g., using 'route-map' and 'import/export' commands) not implied here. Option C is wrong because the IP address is assigned within the VRF context, not from the global routing table; the VRF must already exist or be created dynamically, and the address belongs to the VRF's address space. Option D is wrong because the configuration is valid; VRF BLUE can be created implicitly by the 'ip vrf forwarding' command on the interface, or it may have been created earlier via 'vrf definition BLUE' or 'ip vrf BLUE' (legacy), but the snippet alone does not show an error.

1652
MCQeasy

A network engineer is configuring port security on a Cisco switch to prevent unauthorized devices from connecting. The requirement is to allow only the first two MAC addresses learned on the port and to automatically shut down the port if a violation occurs. Which command set should be used?

A.switchport port-security switchport port-security maximum 2 switchport port-security violation restrict
B.switchport port-security switchport port-security violation protect
C.switchport port-security switchport port-security maximum 1 switchport port-security violation shutdown
D.switchport port-security switchport port-security maximum 2 switchport port-security violation shutdown
AnswerD

This command set enables port security, sets the maximum number of MAC addresses to 2, and configures the violation action to shutdown the port. This meets the requirement of allowing only two MAC addresses and shutting down on violation. The shutdown violation mode places the port in an err-disabled state when a violation occurs.

Why this answer

Port security is configured by enabling it on the interface, setting the maximum number of allowed MAC addresses, and specifying the violation action. To allow two MAC addresses and shut down on violation, the commands switchport port-security, switchport port-security maximum 2, and switchport port-security violation shutdown are required. This ensures that only two devices can connect and any additional device causes the port to enter err-disabled state.

Exam trap

The trap here is confusing the violation modes; restrict and protect do not shut down the port, while shutdown does. Also, forgetting to set the maximum to 2 would default to 1, which is not the requirement.

1653
MCQmedium

An organization uses Chef to manage network device configurations. A cookbook that configures SNMP community strings is applied to a group of routers. After the run, one router loses SNMP access. The cookbook uses the following resource: snmp_community 'public' do action :remove end. What is the most likely cause of the issue?

A.The router's Chef client encountered a syntax error and stopped mid-execution
B.The cookbook accidentally applied a 'private' community string instead of 'public'
C.The cookbook removed the only configured SNMP community string
D.The cookbook is not idempotent and reapplied the change multiple times
AnswerC

The cookbook likely contains a resource that declares the desired set of SNMP community strings and uses Chef's convergence model to delete any string not in that set. If 'public' was the only community configured on the router, removing it leaves zero valid SNMP communities, causing management stations to lose all SNMP access. This is a classic configuration-drift accident where a declarative resource accidentally omits an existing credential.

Why this answer

The `snmp_community 'public' do action :remove end` resource explicitly removes the SNMP community string named 'public'. If 'public' was the only SNMP community string configured on the router, its removal would leave the router with no valid SNMP community, causing all SNMP access to be lost. Chef applies the resource as defined; the issue is not a syntax error or misapplication of a different string, but the direct consequence of removing the sole community.

Exam trap

The trap here is that candidates may assume the issue is a syntax error or a misapplied community string, but Cisco tests the understanding that Chef resources execute exactly as written, and removing the only SNMP community string will break SNMP access regardless of other factors.

How to eliminate wrong answers

Option A is wrong because a syntax error in the Chef client would typically cause the entire run to fail or produce an error in the Chef logs, not silently remove a community string and then stop mid-execution; the resource shown is syntactically correct. Option B is wrong because the cookbook explicitly targets the 'public' community string with the `:remove` action; there is no mention or evidence of a 'private' string being applied, and the issue is removal, not misapplication. Option D is wrong because idempotency is not the problem; the `:remove` action is inherently idempotent (removing an already-removed community does nothing), and reapplying the change multiple times would not cause the initial loss of access—the first removal alone is sufficient.

1654
MCQmedium

A network engineer configures Control Plane Policing on a Cisco IOS XE router acting as the BGP speaker for an ISP edge. The policy must protect the route processor from CPU exhaustion while still allowing BGP keepalives, SSH management, and SNMP polling from the NOC. Which CoPP design element is required to ensure BGP, SSH, and SNMP traffic is matched and rate-limited separately from transit traffic?

A.An access list applied outbound on all interfaces using 'ip access-group' to block unwanted traffic before it reaches the route processor.
B.An MQC policy attached to the WAN interface with 'service-policy input' so that all inbound traffic including BGP and SSH is policed at the interface level.
C.A route-map with 'match ip next-hop' applied to the BGP neighbor to limit the number of prefixes received from each peer.
D.A class-map that matches traffic with the 'control-plane' keyword and a policy-map applied with 'service-policy input' under the control-plane configuration mode.
AnswerD

CoPP on IOS XE requires a class-map to identify control-plane-destined traffic, typically using an ACL or 'match protocol', and a policy-map that assigns a policer. The policy-map is attached to the control-plane with 'service-policy input', which is exactly how BGP, SSH, and SNMP destined to the route processor are rate-limited without affecting transit forwarding.

Why this answer

CoPP protects the route processor by classifying traffic destined to the control plane and applying policers through an MQC policy attached under control-plane configuration mode. This allows BGP keepalives, SSH, and SNMP to be individually matched and rate-limited so that a flood of any one protocol cannot exhaust CPU resources while transit traffic is unaffected.

Exam trap

The trap here is confusing interface-level QoS policing with control-plane policing, when only a policy attached under control-plane configuration mode protects the route processor.

1655
MCQhard

A multinational organization has a BGP-based MPLS VPN network. The CE router at a branch office is connected to two PE routers (PE1 and PE2) in the service provider network. The branch uses eBGP to exchange routes with the PEs. The network administrator notices that the branch can reach some destinations but not others. The BGP table on the CE shows routes with next-hop set to the PE loopback addresses, but those loopbacks are not reachable. The CE has a default route pointing to the PEs. What is the most likely cause of the issue?

A.The next-hop addresses of the BGP routes are not reachable.
B.The default route on the CE is overriding the BGP routes.
C.The routes have an AS path that is too long.
D.The CE is not advertising its routes to the PEs.
AnswerA

In BGP, the route is only installed into the IP routing table if the next-hop IP address is reachable via an existing IGP or static route. In an MPLS VPN, the PE advertises VPN routes to the remote PE with the next-hop set to the loopback address of the advertising PE. If that loopback is not in the IGP routing table of the receiving PE or the CE, the BGP route remains in the BGP table but is not installed, causing the CE to see no usable routes.

Why this answer

The CE router learns BGP routes from the PE routers with next-hop addresses set to the PE loopback interfaces. For these routes to be installed in the routing table, the CE must have a route to the next-hop IP address. Since the CE only has a default route pointing to the PEs and the PE loopbacks are not directly connected or reachable via any specific route, the BGP routes remain hidden (not installed) because the next-hop is unreachable.

This is the most likely cause of partial reachability.

Exam trap

Cisco often tests the BGP next-hop reachability rule, where candidates mistakenly think a default route satisfies the next-hop check, but BGP requires a specific route to the next-hop address (not a default route) for the route to be installed in the routing table.

How to eliminate wrong answers

Option B is wrong because a default route does not override BGP routes; BGP routes have a lower administrative distance (20 for eBGP) and would be preferred over a default route if the next-hop were reachable. Option C is wrong because a long AS path would affect route selection only if multiple paths exist, but it does not prevent routes from being installed when the next-hop is unreachable. Option D is wrong because the issue is about receiving routes from PEs, not about the CE advertising routes; the CE is receiving BGP routes but cannot install them due to next-hop unreachability.

1656
MCQhard

A network engineer runs the following command on Router R1: R1# show policy-map interface GigabitEthernet0/0 GigabitEthernet0/0 Service-policy input: QOS_POLICY Class-map: VOICE (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp ef (46) Queueing queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 police cir 1000000 bc 31250 be 31250 conformed 0 bytes; actions: transmit exceeded 0 bytes; actions: drop violated 0 bytes; actions: drop Class-map: class-default (match-any) 100 packets, 12000 bytes 5 minute offered rate 8000 bps, drop rate 0 bps Match: any Queueing queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 100/12000 Based on this output, what can be concluded?

A.The policy is applied in the output direction.
B.Voice traffic is being policed at 1 Mbps and any excess is dropped.
C.All traffic is being policed at 8 kbps.
D.The policy is shaping traffic to 1 Mbps.
AnswerB

The VOICE class is configured with the 'police' command using a CIR of 1,000,000 bps (1 Mbps). Both the exceed-action and violate-action are 'drop', so any traffic above the committed information rate is immediately discarded rather than remarked or re-queued. This makes the statement that voice traffic is policed at 1 Mbps with excess dropped accurate.

Why this answer

The output shows a police statement for the VOICE class with a CIR of 1,000,000 bps (1 Mbps) and actions to transmit conforming traffic while dropping exceeding and violating traffic. This confirms that voice traffic is being policed at 1 Mbps and any excess is dropped. The presence of policing (not shaping) and the input direction (Service-policy input) further support this conclusion.

Exam trap

Cisco often tests the distinction between policing and shaping, where candidates mistakenly interpret a police statement as shaping or assume the policy direction is output when the output clearly shows 'input'.

How to eliminate wrong answers

Option A is wrong because the command output explicitly states 'Service-policy input: QOS_POLICY', indicating the policy is applied in the input direction, not output. Option C is wrong because the policing is applied only to the VOICE class (match ip dscp ef), not to all traffic; the class-default shows no policing and only a queue limit. Option D is wrong because the configuration uses 'police' (policing), which drops excess traffic, not 'shape' (shaping), which buffers excess traffic; shaping would show a shape statement, not a police statement.

1657
Drag & Dropmedium

Drag and drop the steps of the 802.11 client association process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The 802.11 client association process begins with the client sending a Probe Request to discover networks, followed by a Probe Response from the AP. Then the client sends an Authentication Request, the AP replies with an Authentication Response, and finally the client sends an Association Request, which the AP confirms with an Association Response.

1658
MCQmedium

A network engineer is configuring a Cisco CSR 1000v router to run multiple virtual routing and forwarding (VRF) instances. The engineer wants to ensure that traffic from VRF RED can reach the internet while traffic from VRF BLUE remains isolated. Which feature should be configured to allow VRF RED to access the global routing table?

A.MPLS L3VPN with route targets
B.GRE tunnel between VRF RED and the global table
C.VRF-lite with OSPF process per VRF
D.Route leaking using static routes with next-hop in the global table
AnswerD

Route leaking allows selective import of routes between VRFs or between a VRF and the global table. By configuring a static route in VRF RED pointing to a global next-hop, or by using BGP import/export, you can allow VRF RED to reach the internet while keeping VRF BLUE isolated.

Why this answer

Route leaking is the correct feature to allow traffic from a specific VRF to access the global routing table or another VRF. By configuring static routes or BGP import/export, the engineer can selectively leak routes for VRF RED to the global table, enabling internet access while maintaining isolation for VRF BLUE.

Exam trap

The trap here is thinking that simply configuring a routing protocol within each VRF will allow internet access, when in fact inter-VRF or VRF-to-global communication requires route leaking.

1659
MCQeasy

A network engineer is configuring a Cisco IOS switch and needs to assign a specific port to VLAN 20 as an access port. The port is currently in VLAN 1 and is administratively up. Which sequence of interface configuration commands correctly places the port into VLAN 20 as an access port?

A.switchport mode access followed by switchport access vlan 20
B.vlan 20 followed by switchport mode access
C.switchport mode dynamic auto followed by switchport access vlan 20
D.switchport access vlan 20 followed by switchport mode trunk
AnswerA

Entering interface configuration mode and issuing switchport mode access sets the port to access mode, and switchport access vlan 20 assigns it to VLAN 20. This is the standard Cisco IOS method to configure a static access port. The VLAN must exist in the VLAN database, but the command sequence itself is correct for placing the port into VLAN 20.

Why this answer

To place an interface into a specific VLAN as an access port on a Cisco IOS switch, the engineer enters interface configuration mode, sets the port to access mode with switchport mode access, and assigns the VLAN with switchport access vlan 20. This ensures the port carries untagged traffic for VLAN 20 only.

Exam trap

The trap here is confusing the global vlan command that creates a VLAN with the interface-level switchport access vlan command that assigns a port to an existing VLAN.

1660
MCQmedium

A network administrator is deploying a new branch office that requires a dynamic routing protocol supporting unequal-cost load balancing and fast convergence. The topology includes Cisco routers only. Which routing protocol should be implemented?

A.BGP
B.OSPF
C.EIGRP
D.RIPv2
AnswerC

EIGRP supports unequal-cost load balancing through the variance command, allowing traffic to be distributed across multiple paths with different metrics. It also converges quickly using the feasible successor mechanism, making it suitable for this branch office scenario. OSPF and BGP do not natively support unequal-cost load balancing, and RIP has slow convergence.

Why this answer

EIGRP is the only protocol among the choices that inherently supports unequal-cost load balancing via the variance feature and provides fast convergence through its feasible successor mechanism. OSPF and BGP support only equal-cost multipath, and RIPv2 lacks both features, making EIGRP the correct choice for this scenario.

Exam trap

The trap here is assuming that OSPF or BGP can perform unequal-cost load balancing because they support equal-cost multipath.

1661
MCQmedium

A network administrator is deploying a new branch office with a Cisco Catalyst 9200 switch. The security policy requires that any endpoint connecting to access ports must be authenticated before being granted network access, and unauthenticated devices must be placed into a restricted VLAN. The administrator wants to minimize configuration on the switch and rely on the authentication server to assign the VLAN dynamically. Which 802.1X feature should be configured on the switch to meet these requirements?

A.Configure 802.1X with VLAN assignment via RADIUS attributes.
B.Configure port security with sticky MAC addresses and a violation action of restrict.
C.Configure Web Authentication (WebAuth) with a guest VLAN.
D.Configure MAC Authentication Bypass (MAB) with a fallback VLAN.
AnswerA

This is the correct approach. 802.1X authentication allows the switch to authenticate endpoints using credentials (e.g., username/password or certificate) against a RADIUS server like Cisco ISE. The server can return attributes such as Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID to dynamically assign the endpoint to a specific VLAN. This meets the requirement of authenticating endpoints and placing unauthenticated devices into a restricted VLAN (e.g., a guest VLAN) if configured.

Why this answer

The requirement is to authenticate endpoints and dynamically assign VLANs based on authentication server response. 802.1X with RADIUS attributes allows the switch to act as an authenticator, passing credentials to a RADIUS server, which can then return VLAN assignment attributes. This ensures only authenticated devices gain access, and unauthenticated devices can be placed in a restricted VLAN. Other options either do not authenticate or do not provide dynamic VLAN assignment based on user identity.

Exam trap

The trap here is confusing port security or MAB with 802.1X, which actually provides authentication and dynamic VLAN assignment through RADIUS attributes.

1662
MCQmedium

Consider the following configuration: ip access-list extended BLOCK_TELNET deny tcp any any eq 23 permit ip any any ! interface GigabitEthernet0/2 ip access-group BLOCK_TELNET out Which statement is true?

A.Telnet traffic entering GigabitEthernet0/2 is blocked.
B.Telnet traffic leaving GigabitEthernet0/2 is blocked.
C.All outbound traffic is blocked.
D.The ACL is incorrectly applied; only named ACLs can be applied outbound.
AnswerB

Because the ACL is applied outbound and contains a deny statement for TCP port 23, any Telnet packet that is about to leave GigabitEthernet0/2 is dropped. The order matters: the deny telnet line is evaluated first, so the permitted implicit/explicit permit at the end does not rescue Telnet. This precisely blocks Telnet egress while permitting all other outbound traffic.

Why this answer

The ACL BLOCK_TELNET is applied to interface GigabitEthernet0/2 in the outbound direction using the 'ip access-group BLOCK_TELNET out' command. The ACL denies TCP traffic destined for port 23 (Telnet) and permits all other IP traffic. Since it is applied outbound, it filters traffic leaving the interface, meaning Telnet sessions initiated from the device or passing through the interface outbound will be blocked.

Option B correctly states that Telnet traffic leaving GigabitEthernet0/2 is blocked.

Exam trap

Cisco often tests the distinction between inbound and outbound ACL application; the trap here is that candidates may assume the ACL blocks Telnet traffic in both directions or misread the 'out' keyword as applying to traffic entering the interface, leading them to select Option A.

How to eliminate wrong answers

Option A is wrong because the ACL is applied outbound, not inbound; inbound filtering would require the 'in' keyword, and the ACL would then block Telnet traffic entering the interface. Option C is wrong because the ACL permits all other IP traffic after denying Telnet (port 23), so only Telnet traffic is blocked, not all outbound traffic. Option D is wrong because both numbered and named ACLs can be applied in either direction (inbound or outbound) on an interface; the 'ip access-group' command supports both named and numbered ACLs for inbound and outbound filtering.

1663
MCQmedium

A data center team is deploying a VXLAN EVPN fabric on Cisco Nexus 9000 switches and wants to eliminate the need for multicast underlay replication for broadcast, unknown unicast, and multicast traffic. Which mechanism should the team implement to achieve ingress replication of BUM traffic?

A.Configure PIM sparse mode on all underlay interfaces
B.Enable IGMP snooping on all leaf access ports
C.Enable head-end replication using EVPN Type 3 routes
D.Configure MSDP peering between all leaf switches
AnswerC

EVPN Type 3 Inclusive Multicast Ethernet Tag routes advertise VTEP and VNI membership, letting each ingress VTEP build a replication list of remote VTEPs. The ingress leaf then replicates BUM frames individually to every remote VTEP, which is head-end or ingress replication. This removes the requirement for multicast in the underlay entirely.

Why this answer

With EVPN, Type 3 Inclusive Multicast Ethernet Tag routes advertise each VTEP's interest in a VNI, allowing ingress leaf switches to construct a list of remote VTEPs per VNI. BUM frames are then replicated by the ingress VTEP directly to each remote VTEP, which is head-end replication and removes the need for a multicast-capable underlay.

Exam trap

The trap here is confusing multicast replication in the underlay with EVPN-based ingress replication, which is signaled by Type 3 routes.

1664
Matchingmedium

Drag and drop each WAN topology type on the left to its matching characteristic on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Simple dedicated link between two sites

Central site connects to multiple remote sites

Every site directly connected to every other site

Some sites directly connected, others through intermediate

Service provider network providing any-to-any Layer 3 connectivity

Why these pairings

Point-to-point is simple and dedicated; hub-and-spoke centralizes traffic; full mesh provides high redundancy; partial mesh balances cost and redundancy; MPLS VPN offers any-to-any connectivity.

1665
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor the health of a campus network. The administrator wants to receive alerts when the number of clients on a specific wireless controller exceeds a threshold. Which feature in Cisco DNA Center Assurance should be used to configure this?

A.Sensor-driven Tests
B.Assurance Issues and Events
C.Custom Assurance Thresholds
D.Network Health Dashboard
AnswerC

Cisco DNA Center Assurance allows administrators to define custom thresholds for various metrics, including client count on wireless controllers. By setting a threshold, an alert is triggered when the metric exceeds the defined value. This is the correct feature to use for the described requirement.

Why this answer

Cisco DNA Center Assurance provides the ability to set custom thresholds for health metrics. To alert when client count exceeds a limit, the administrator configures a custom threshold for the wireless controller's client count. This generates an alert when the condition is met.

The other features are for monitoring and testing but not for threshold configuration.

Exam trap

The trap here is confusing monitoring dashboards with configuration interfaces for custom alerts, assuming that any health view allows threshold setting.

1666
MCQmedium

A network architect is designing a new branch office that requires a switch to be managed centrally without a dedicated physical controller appliance on-site. The switch must support fabric capabilities and be onboarded using Plug and Play. Which Cisco Catalyst switch platform should be selected?

A.Cisco Catalyst 9200
B.Cisco Nexus 9000
C.Cisco Catalyst 2960-X
D.Cisco ASR 1000
AnswerA

The Catalyst 9200 supports SD-Access fabric edge and can be onboarded via Cisco DNA Center Plug and Play without a local controller. It is designed for branch deployments requiring fabric capabilities, making it the correct choice for this scenario.

Why this answer

The Catalyst 9200 is a fixed access switch that supports SD-Access fabric edge and can be discovered and onboarded by Cisco DNA Center using Plug and Play, eliminating the need for a local controller. The other platforms either lack fabric support or are designed for different roles.

Exam trap

The trap here is assuming any Catalyst switch supports SD-Access fabric, but older models like the 2960-X do not.

1667
MCQmedium

Examine the following configuration for a Cisco IOS-XE device: interface GigabitEthernet0/0 ip address 10.0.0.1 255.255.255.252 ipv6 address 2001:db8::1/64 ipv6 ospf 1 area 0 ! interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ipv6 address 2001:db8:1::1/64 ipv6 ospf 1 area 0 ! ipv6 router ospf 1 router-id 2.2.2.2 Which statement is true about OSPFv3 operation?

A.OSPFv3 will form adjacencies over both interfaces using the configured IPv6 addresses.
B.OSPFv3 will form adjacencies over both interfaces using link-local addresses.
C.OSPFv3 will only run on GigabitEthernet0/0 because the router-id is not configured for GigabitEthernet0/1.
D.OSPFv3 requires an explicit network command under the OSPFv3 process to enable on interfaces.
AnswerB

OSPFv3 runs per-link over IPv6 and forms adjacencies using link-local addresses (fe80::/10), which are automatically generated on each interface. The configured global addresses are irrelevant to neighbour discovery, so adjacencies establish on both GigabitEthernet0/0 and GigabitEthernet0/1.

Why this answer

OSPFv3 forms adjacencies using IPv6 link-local addresses (fe80::/10), not the global unicast addresses configured on the interfaces. The `ipv6 ospf 1 area 0` command enables OSPFv3 on the interface, and the router automatically uses the link-local address as the source for hello packets. The global IPv6 addresses (2001:db8::1/64 and 2001:db8:1::1/64) are used for reachability but not for neighbor establishment.

Exam trap

The trap here is assuming OSPFv3 uses global IPv6 addresses for adjacencies like OSPFv2 uses IPv4 addresses; candidates often forget that OSPFv3 relies on link-local addresses for neighbor formation.

How to eliminate wrong answers

Option A is wrong because OSPFv3 does not use global IPv6 addresses for adjacency formation; it uses link-local addresses. Option C is wrong because the router-id is configured globally under the OSPFv3 process (router-id 2.2.2.2), and OSPFv3 does not require per-interface router-ids; adjacencies can form on both interfaces. Option D is wrong because OSPFv3 does not use the network command; instead, it is enabled per-interface using the `ipv6 ospf <process-id> area <area-id>` interface command.

1668
MCQmedium

A company is migrating its legacy firewall services to a virtualized environment using Cisco NFV. The network engineer deploys a virtual firewall (vFW) on an NFVIS-enabled UCS platform. After the deployment, traffic through the vFW is intermittent and performance monitoring shows high CPU usage on the host. Which action should the engineer take to improve performance?

A.Enable SR-IOV on the physical NICs and assign VFs to the vFW.
B.Increase the number of vCPUs allocated to the vFW VM.
C.Configure QoS policies on the vFW to prioritize traffic.
D.Disable hyperthreading on the host CPU.
AnswerA

SR-IOV enables a virtual function (VF) to be assigned directly to the vFW, bypassing the hypervisor's virtual switch and its associated CPU overhead. This allows the VM to perform I/O operations with near-native performance because the NIC hardware handles data plane processing, reducing latency and CPU usage. That is why it specifically addresses the bottleneck described in the scenario.

Why this answer

SR-IOV (Single Root I/O Virtualization) allows a physical NIC to present multiple virtual functions (VFs) directly to a VM, bypassing the hypervisor's virtual switch and reducing CPU overhead for packet processing. In an NFVIS environment, high host CPU usage with intermittent traffic indicates that the vFW is consuming excessive CPU cycles due to software-based I/O. Assigning VFs to the vFW offloads packet handling to the NIC hardware, lowering host CPU utilization and stabilizing traffic.

Exam trap

The trap here is that candidates often assume adding more vCPUs (Option B) will solve performance issues, but Cisco tests the understanding that I/O bottlenecks in NFV are typically resolved by hardware offload techniques like SR-IOV, not by increasing compute resources.

How to eliminate wrong answers

Option B is wrong because increasing vCPUs can actually worsen CPU contention and overhead in a virtualized environment, especially if the bottleneck is I/O processing rather than compute capacity. Option C is wrong because QoS policies manage traffic prioritization but do not reduce the underlying CPU overhead caused by inefficient I/O virtualization; they may even add additional processing load. Option D is wrong because disabling hyperthreading reduces logical CPU cores, which can decrease overall throughput and increase latency, contrary to the goal of improving performance.

1669
MCQhard

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive traffic. The router has management SSH access, BGP peering, and SNMP monitoring. After applying a CoPP policy, the engineer notices that BGP sessions flap intermittently, but SSH and SNMP remain stable. Which action should the engineer take to resolve the BGP flapping while maintaining control plane protection?

A.Remove the CoPP policy from the control plane interface.
B.Reclassify BGP traffic into the SNMP class to share its rate limit.
C.Increase the rate limit for the BGP class in the CoPP policy.
D.Enable QoS pre-classify on the BGP neighbor interface.
AnswerC

BGP flapping indicates that BGP control plane traffic is being dropped due to an overly restrictive policer. Increasing the rate limit for the BGP class allows legitimate BGP keepalives and updates to pass while still protecting the route processor from excessive BGP traffic. This is the targeted fix because SSH and SNMP are stable, confirming that only the BGP class needs adjustment.

Why this answer

When CoPP policers are too strict, protocols like BGP may experience drops leading to session flaps. Since SSH and SNMP are stable, the issue is isolated to the BGP class. Increasing the rate limit for that class allows BGP to operate within acceptable thresholds while still protecting the route processor.

This maintains overall control plane security without sacrificing routing stability.

Exam trap

The trap here is assuming that any CoPP issue requires disabling the policy entirely, rather than tuning the specific class that is causing drops.

1670
MCQmedium

A network architect is designing a Cisco SD-Access fabric for a hospital campus. The fabric must support wired and wireless clients, and the architect wants to ensure that all fabric edge nodes use a consistent mapping of endpoint IP addresses to fabric locations. Which control plane component is responsible for maintaining the endpoint-to-edge-node mapping database?

A.Fabric intermediate node
B.Fabric border node
C.Cisco DNA Center
D.Fabric control plane node
AnswerD

The fabric control plane node runs LISP and maintains the endpoint-to-edge-node mapping database, known as the map-server and map-resolver. When a fabric edge node needs to locate an endpoint, it queries the control plane node, which returns the RLOC of the edge node where the endpoint is attached. This ensures consistent mapping across all fabric edge nodes.

Why this answer

In Cisco SD-Access, the control plane node is the LISP map-server and map-resolver that stores endpoint identifiers (EIDs) and their routing locators (RLOCs). Fabric edge nodes register endpoints with the control plane node and query it for location resolution. This design centralizes endpoint reachability information, ensuring that every edge node has a consistent view of where endpoints are attached.

Exam trap

The trap here is assuming that DNA Center, as the management platform, also provides the real-time endpoint location database, when that role belongs to the fabric control plane node running LISP.

1671
MCQmedium

An engineer is using a Python script to configure a new VLAN on a Cisco Nexus 9000 switch using the NX-API REST API. The script sends a POST request to 'https://switch/api/mo/org.json' with a JSON payload containing the VLAN configuration. The switch responds with a 403 Forbidden error. What is the most likely cause?

A.The payload format is incorrect; the engineer must use XML instead of JSON.
B.The user account does not have the required RBAC privileges to configure VLANs.
C.The switch does not support NX-API; the engineer must use NETCONF instead.
D.The URI is incorrect; the correct URI should be 'https://switch/api/node/mo/org.json'.
AnswerB

A 403 Forbidden response indicates the request was authenticated but the account lacks permission for the operation. NX-API REST enforces role-based access control, so configuring VLANs requires a role granting that privilege; insufficient RBAC rights produce exactly this rejection.

Why this answer

A 403 Forbidden error indicates that the server understood the request but refuses to authorize it. In NX-API, this often occurs when the user does not have sufficient privileges to perform the operation. The engineer should check that the user account used for authentication has the necessary RBAC roles to configure VLANs.

1672
Multi-Selectmedium

A data center team is designing a VXLAN EVPN fabric on Cisco Nexus 9000 switches to replace an aging three-tier topology. They want to understand which functions are performed by the VXLAN tunnel endpoints and the EVPN control plane. Which two statements accurately describe VXLAN EVPN behavior? (Choose two.)

Select 2 answers
A.The VXLAN Network Identifier is a 12-bit field, limiting each fabric to 4094 segments.
B.VXLAN requires that the underlay fabric run only Layer 2 trunks between every leaf and spine.
C.VTEPs must be configured with the same IP address on every leaf switch to form a single tunnel endpoint.
D.VTEPs encapsulate original Layer 2 frames inside UDP packets destined to the remote VTEP IP address.
E.EVPN uses MP-BGP to distribute MAC and IP reachability information among VTEPs.
AnswersD, E

VXLAN data plane encapsulation wraps the original Ethernet frame in a VXLAN header, then UDP, IP and a new outer Ethernet header. The outer destination IP is the remote VTEP's loopback address, which is reachable over the routed underlay. This is precisely how frames cross the Layer 3 fabric between leaf switches in the scenario.

Why this answer

VXLAN encapsulates original frames in UDP and delivers them to a remote VTEP's IP address, while EVPN supplies a BGP-based control plane that distributes MAC and IP reachability so flooding is minimized. The underlay is routed, the VNI field is 24 bits wide, and each VTEP requires its own unique address, so the other statements misstate fundamental VXLAN EVPN design facts.

Exam trap

The trap here is mixing up the 12-bit VLAN ID with the 24-bit VXLAN Network Identifier when reasoning about segment scale.

1673
MCQmedium

Given the following configuration: interface GigabitEthernet0/1 service-policy output QOS_POLICY Which statement is true about applying a service-policy in the output direction?

A.The policy-map is applied to traffic exiting the interface, allowing queuing and scheduling decisions.
B.The policy-map is applied to traffic entering the interface, performing classification and marking.
C.The policy-map can only be applied if the interface is in a shutdown state.
D.The policy-map must contain a class-default with a shape command to be valid.
AnswerA

Applying a policy-map with the output keyword attaches it to the egress path of the interface. This allows the router to perform congestion management tasks such as class-based weighted fair queueing (CBWFQ), low-latency queueing (LLQ), and traffic shaping on packets as they leave the interface. The queuing and scheduling decisions determine how traffic is transmitted, including bandwidth allocation and priority for real-time flows.

Why this answer

When a service-policy is applied in the output direction, the policy-map inspects and acts on packets as they leave the interface. This allows the policy to perform queuing and scheduling decisions (e.g., CBWFQ, LLQ, shaping) on outbound traffic, which is the correct behavior for managing bandwidth and latency on egress.

Exam trap

Cisco often tests the distinction between input and output service-policies, where candidates mistakenly assume that output policies are used for marking or classification, when in fact those actions are typically performed on ingress.

How to eliminate wrong answers

Option B is wrong because applying a service-policy in the output direction does not affect traffic entering the interface; input direction (service-policy input) is used for classification and marking on ingress. Option C is wrong because a service-policy can be applied to an interface regardless of its operational state; it does not require the interface to be in a shutdown state. Option D is wrong because a policy-map applied in the output direction does not require a class-default with a shape command; shaping is optional, and the policy can contain other actions like bandwidth, priority, or queue-limit without a shape statement.

1674
Multi-Selecthard

Which two statements about configuring SPAN on Cisco IOS-XE switches are true? (Choose two.)

Select 2 answers
A.A SPAN source can be a physical port or an EtherChannel interface.
B.A SPAN destination port can also be configured as a SPAN source port.
C.Only one source port can be configured per SPAN session.
D.The SPAN destination port must belong to the same VLAN as the source port.
E.A SPAN destination port cannot be a routed port.
AnswersA, E

Correct because SPAN supports both physical ports and port-channel interfaces as sources.

Why this answer

The correct answers are A and E. A is true because SPAN source interfaces can be individual physical ports or EtherChannel interfaces (port channels). E is true because a SPAN destination port is a switch port put into SPAN monitoring mode and cannot be a Layer 3 routed port.

B is false: a port configured as a SPAN destination cannot simultaneously serve as a SPAN source. C is false: a SPAN session can have multiple source ports. D is false: the destination port is placed into a special SPAN mode and does not need to belong to the same VLAN as the source.

1675
Multi-Selectmedium

A network engineer is deploying Cisco ACI in a data center. The engineer needs to configure a bridge domain that provides Layer 2 connectivity between endpoints in the same tenant. Which two statements about Cisco ACI bridge domains are true? (Choose two.)

Select 2 answers
A.A bridge domain requires a VLAN pool to be defined in the fabric access policies.
B.A bridge domain can contain multiple subnets.
C.A bridge domain can only contain a single subnet.
D.A bridge domain provides Layer 3 routing between subnets by default.
E.A bridge domain must be associated with a VRF to provide Layer 3 routing.
AnswersB, E

A Cisco ACI bridge domain can have multiple subnets configured under it. Each subnet is associated with a gateway IP address on the ACI fabric. This allows a single bridge domain to support multiple IP subnets, providing flexibility in addressing and segmentation within the same Layer 2 domain.

Why this answer

In Cisco ACI, a bridge domain is a Layer 2 construct that can contain multiple subnets and must be associated with a VRF to enable Layer 3 routing. The VRF provides the routing context, and multiple subnets allow flexible IP addressing within the same bridge domain. VLAN pools are used for VLAN allocation but are not a direct requirement for the bridge domain itself.

Exam trap

The trap here is assuming that a bridge domain inherently provides Layer 3 routing or is limited to a single subnet, when in fact it requires VRF association for routing and supports multiple subnets.

1676
MCQmedium

A network engineer must protect the Cisco IOS control plane from an excessive volume of ARP traffic generated by a compromised host in VLAN 20. The engineer wants to limit ARP packets that are punted to the CPU, while allowing normal data forwarding to continue unaffected. Which feature should be configured to accomplish this goal?

A.Control Plane Policing (CoPP)
B.Storm control configured for broadcast traffic on the host-facing port
C.IP Source Guard on the host-facing port
D.Dynamic ARP Inspection (DAI) on VLAN 20
AnswerA

CoPP applies a QoS policy to the control plane and can rate-limit specific punted traffic classes, such as ARP, using a class-map matching ARP and a policy-map with a policer. This directly limits how many ARP packets reach the CPU while leaving transit data-plane forwarding untouched. It is the intended tool for protecting the route processor from excessive exception traffic.

Why this answer

Protecting the CPU from excessive punted ARP traffic requires a mechanism that polices traffic destined to the control plane. Control Plane Policing provides exactly this by allowing class-based rate limiting of specific protocols such as ARP. DAI, storm control, and IP Source Guard operate at the access or data plane and address spoofing or broadcast volume, not CPU-bound exception traffic.

Exam trap

The trap here is assuming that any ARP-related security feature, such as DAI, will protect the CPU from ARP floods, when only control plane policing rate-limits traffic punted to the route processor.

1677
MCQmedium

A network administrator is deploying a Cisco Catalyst 9300 switch stack at the access layer. The security policy requires that when an endpoint device is connected to a port and later replaced by a different device, the port must automatically learn the new MAC address without administrative intervention, but a violation must generate a syslog message and increment a counter. The administrator configures the interface with the command 'switchport port-security violation restrict'. Which additional command is required to meet the requirement that the new device is learned automatically?

A.switchport port-security aging time 2
B.switchport port-security mac-address sticky
C.switchport port-security maximum 1
D.switchport port-security mac-address 0011.2233.4455
AnswerB

Sticky learning dynamically learns the MAC address of the first device and adds it to the running configuration. When the device is replaced, the old sticky entry can age out or be removed, and the new device is learned. With violation restrict, a syslog and counter increment occur on violation. This meets the requirement without manual intervention, unlike static configuration.

Why this answer

Sticky learning allows the switch to dynamically learn MAC addresses and add them to the running configuration, so when a device is replaced, the new MAC can be learned without manual reconfiguration. Combining sticky with violation restrict ensures a syslog and counter increment on violation. Maximum, static MAC, and aging do not provide the required automatic learning behavior.

Exam trap

The trap here is assuming that setting a maximum or aging time enables automatic learning of a replacement device, when only sticky learning dynamically adds the new MAC to the configuration.

1678
MCQhard

A company is deploying a virtualized firewall on a VMware ESXi host. The firewall VM requires high network throughput and low latency. The engineer decides to use SR-IOV to assign a virtual function (VF) from a physical NIC to the VM. After configuration, the VM can communicate, but the host's management network becomes unreachable. What is the most likely cause?

A.The physical NIC's PF is also used for the host management network, and SR-IOV configuration disrupted it.
B.The VM's VF is using the same MAC address as the host management interface.
C.The ESXi host requires a dedicated physical NIC for management when using SR-IOV.
D.The VM's VF is consuming all available bandwidth on the NIC.
AnswerA

The host's management network is typically bound to a VMkernel adapter placed on a virtual switch whose uplink is the physical NIC's Physical Function (PF). When SR-IOV is enabled on that same NIC, the system often needs to reset or reconfigure the PF driver, which can temporarily remove the uplink from the vSwitch or change its queue and ring settings. That disruption makes the VMkernel adapter lose link and renders the ESXi host unreachable via the management IP. This is not a VM forwarding issue but a loss of the PF's own network capability.

Why this answer

When SR-IOV is enabled on a physical NIC, the Physical Function (PF) is shared between the host management network and the Virtual Functions (VFs). If the PF is used for the host management network, enabling SR-IOV can disrupt the PF's driver or configuration, causing the management network to become unreachable. This is a common misconfiguration where the same NIC is used for both management and SR-IOV VFs.

Exam trap

Cisco often tests the misconception that SR-IOV requires a dedicated management NIC, but the real issue is that the same PF cannot serve both management and SR-IOV VFs without disruption.

How to eliminate wrong answers

Option B is wrong because SR-IOV VFs are assigned unique MAC addresses by the hypervisor, and a MAC address conflict would cause connectivity issues for the VM, not the host management network. Option C is wrong because ESXi does not require a dedicated physical NIC for management when using SR-IOV; it only requires that the PF used for management is not also used for SR-IOV VFs. Option D is wrong because bandwidth consumption by the VM's VF would degrade performance but would not make the host management network unreachable; the management network would still be accessible, albeit potentially slower.

1679
Matchingmedium

Drag and drop each Cisco security feature on the left to its matching OSI layer on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Layer 2

Layer 3

Layer 3/4

Layer 4-7

Layer 2

Why these pairings

Port security operates at Layer 2; ACL at Layer 3; zone-based firewall at Layer 3/4; IPS at Layer 4-7; MACsec at Layer 2.

1680
MCQhard

A network engineer is implementing QoS on a Cisco router that connects to a service provider. The provider uses MPLS and expects the MPLS EXP bits to be set for voice traffic. The engineer configures a policy-map that sets the MPLS EXP to 5. However, the provider reports that the EXP bits are not being set. What is the most likely reason?

A.The policy-map is applied to the incoming interface, but MPLS EXP marking must be done on the outgoing interface.
B.The router does not support setting MPLS EXP bits.
C.The MPLS EXP bits are set automatically based on the IP precedence.
D.The policy-map must use 'set mpls experimental imposition 5' instead of 'set mpls experimental 5'.
AnswerA

The correct issue is that the policy-map is applied to the incoming interface, but MPLS EXP marking must be performed on the outgoing interface. When a packet enters the MPLS domain, the label is not yet imposed on the inbound interface; the label push occurs during forwarding, and the MPLS encapsulation is added on the outgoing interface toward the next hop. Therefore, applying 'set mpls experimental 5' inbound cannot affect the EXP bits of a label that has not yet been created—marking must be configured on the outbound interface where the label exists.

Why this answer

The most likely reason is that the policy-map is applied to the incoming interface, but MPLS EXP marking must be applied on the outgoing interface. MPLS EXP bits are set at the imposition (ingress) of the MPLS label stack, which occurs when the packet is forwarded out of an interface that has MPLS enabled. If the policy-map is applied inbound, it marks the IP packet before MPLS encapsulation, and the EXP bits are not set on the MPLS label.

The correct approach is to apply the policy-map outbound on the interface facing the service provider, so that the 'set mpls experimental' command marks the EXP bits on the imposed label.

Exam trap

Cisco often tests the concept that MPLS EXP marking must be applied on the outgoing interface (where MPLS encapsulation occurs), not on the incoming interface, leading candidates to incorrectly assume that inbound marking is sufficient.

How to eliminate wrong answers

Option B is wrong because modern Cisco routers that support MPLS (e.g., ISR, ASR series) fully support setting MPLS EXP bits via policy-maps; this is a standard QoS feature. Option C is wrong because MPLS EXP bits are not automatically set based on IP precedence; they must be explicitly configured using a policy-map or can be copied from IP precedence if the 'mpls ip' command with 'mpls experimental' is configured, but this is not automatic and requires specific configuration. Option D is wrong because 'set mpls experimental 5' is the correct command for marking the EXP bits on the imposed label; 'set mpls experimental imposition 5' is not a valid Cisco IOS command.

1681
MCQmedium

An engineer is deploying a Cisco SD-WAN solution using Cisco vManage. The company requires that the WAN edge devices authenticate to the controllers using certificates signed by an enterprise PKI rather than the default Cisco-signed certificates. Which component must be configured to issue and manage these certificates?

A.Cisco vBond orchestrator
B.Cisco vManage
C.Cisco vSmart controller
D.An external certificate authority (CA) server
AnswerD

In Cisco SD-WAN, when using enterprise PKI, an external CA server (such as Microsoft Certificate Services or a third-party CA) signs the device certificates. The WAN edge devices generate a CSR, which is sent to the CA; the CA returns a signed certificate that the device uses to authenticate to the controllers. This satisfies the requirement for certificates signed by an enterprise PKI.

Why this answer

Cisco SD-WAN supports two certificate options: the default Cisco-signed certificates or enterprise PKI. For enterprise PKI, an external CA must sign the device certificates. The vManage, vSmart, and vBond components do not issue certificates; they only validate them during control plane establishment.

Therefore, an external CA server is required to meet the enterprise PKI requirement.

Exam trap

The trap here is assuming that vManage, as the management component, also acts as the certificate authority for enterprise PKI.

1682
MCQhard

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that traffic from a specific subnet is encrypted and sent to a remote peer, while all other traffic is sent unencrypted. The engineer has configured an extended ACL for the crypto map. Which additional configuration is required to ensure that the crypto map is applied to the correct interface and that the VPN tunnel is established?

A.Configure a static route to the remote peer's public IP address pointing to the next-hop router.
B.Enable NAT on the interface to translate the private subnet to a public address before encryption.
C.Configure an ISAKMP policy with a matching pre-shared key on both peers.
D.Apply the crypto map to the outbound interface using the crypto map command under interface configuration.
AnswerD

The crypto map must be applied to the interface that sends traffic to the remote peer, typically the WAN interface, using the crypto map <name> command. This enables the router to evaluate outbound packets against the ACL, match interesting traffic, and initiate the IPsec tunnel. Without applying the crypto map to an interface, the VPN configuration remains inactive.

Why this answer

The crypto map defines the IPsec policy and must be applied to the outbound interface facing the remote peer. This application is what causes the router to inspect outbound packets, match the ACL, and initiate the IPsec tunnel. Other elements like ISAKMP policies and static routes are supporting configurations but do not activate the crypto map.

Exam trap

The trap here is focusing on IKE or NAT details while overlooking that the crypto map must be applied to an interface to become operational.

1683
MCQeasy

A network engineer runs the following command on Switch SW8: SW8# show spanning-tree vlan 80 VLAN0080 Spanning tree enabled protocol ieee Root ID Priority 24656 Address aabb.cc00.0e00 Cost 12 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32768 (priority 32768 sys-id-ext 80) Address aabb.cc00.0f00 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- ------------------------------ Gi0/1 Root FWD 12 128.1 P2p Gi0/2 Desg FWD 4 128.2 P2p Gi0/3 Desg FWD 4 128.3 P2p Gi0/4 Altn BLK 4 128.4 P2p Based on this output, what is the cost of the root port?

A.4
B.8
C.12
D.16
AnswerC

The root port Gi0/1 is assigned a port cost of 12 in the spanning-tree output, representing the cumulative cost to reach the root bridge from this switch. This value is calculated by summing the cost of the root port's link plus any upstream costs, and it determines the best path to the root. Since the output shows 'cost 12' for the root port, 12 is the correct answer.

Why this answer

The root port cost is the cost to reach the root bridge, which is explicitly shown in the 'Root ID' section as 'Cost 12'. This cost is associated with the root port (Gi0/1), which has a role of 'Root' and a status of 'FWD'. Therefore, the correct answer is 12.

Exam trap

Cisco often tests the distinction between the root port cost (shown in the 'Root ID' section) and the local port cost (shown in the 'Cost' column for each interface), leading candidates to mistakenly pick the local cost of the root port (which is 12 in this case, but the trap is that they might pick the cost of a designated port like 4).

How to eliminate wrong answers

Option A is wrong because 4 is the cost of the designated ports (Gi0/2 and Gi0/3) and the alternate port (Gi0/4), not the root port. Option B is wrong because 8 is not present in the output; it might be a distractor from adding the root cost (12) and a local port cost (4). Option D is wrong because 16 is not derived from any value in the output; it could be a misreading of the root bridge's priority (24656) or a miscalculation.

1684
Matchingmedium

Match each QoS feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Identifying traffic based on specific fields

Setting the DSCP or CoS value in a packet

Dropping packets that exceed a configured rate

Buffering packets to maintain a configured rate

Managing packet order during congestion

Why these pairings

Correct matches: Classification (A), Marking (B), Policing (C), Queuing (F). Common confusions: Shaping vs. Congestion Avoidance (WRED), where Shaping buffers and WRED drops early.

1685
MCQmedium

Examine the following configuration snippet: interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ip ospf network point-to-point ip ospf hello-interval 10 ip ospf dead-interval 40 ! router ospf 1 network 192.168.1.0 0.0.0.255 area 0 What is the effect of this configuration?

A.OSPF adjacency will form with a neighbor using hello/dead intervals of 10/40 seconds.
B.OSPF adjacency will not form because the hello interval is too low for point-to-point.
C.The network command under router ospf will be ignored because the interface has an explicit network type.
D.OSPF will use the default broadcast network type because the point-to-point keyword is misspelled.
AnswerA

This is correct because the interface has been explicitly configured as point-to-point, which uses a default hello interval of 10 seconds and a dead interval of 40 seconds on Cisco IOS. These timers match the neighbor's timers, so the two routers will form a full adjacency. Additionally, the point-to-point network type suppresses DR/BDR election, making adjacency establishment straightforward and deterministic.

Why this answer

The configuration sets the OSPF network type to point-to-point on the interface, which allows OSPF to form an adjacency with a neighbor using the configured hello interval of 10 seconds and dead interval of 40 seconds. These intervals are valid for point-to-point networks, and the network command under router ospf correctly enables OSPF on the interface. Therefore, an adjacency will form as long as the neighbor's intervals match.

Exam trap

Cisco often tests the misconception that the network command is ignored when an explicit ip ospf network type is configured, but in reality both work together—the network command enables OSPF on the interface, and the ip ospf network command only changes the OSPF network type.

How to eliminate wrong answers

Option B is wrong because a hello interval of 10 seconds is not too low for point-to-point; the default hello interval for point-to-point is 10 seconds, and it can be set lower (e.g., 1 second) without preventing adjacency formation as long as the neighbor matches. Option C is wrong because the network command under router ospf is not ignored; it is still used to determine which interfaces participate in OSPF, and the explicit network type on the interface only overrides the default network type, not the network command. Option D is wrong because the keyword 'point-to-point' is correctly spelled in the configuration snippet, and OSPF will use the point-to-point network type, not the default broadcast type.

1686
Multi-Selectmedium

Which two statements about Ansible automation in a Cisco environment are true? (Choose two.)

Select 2 answers
A.Ansible uses a push-based model to configure network devices.
B.Ansible requires an agent to be installed on managed Cisco devices.
C.Ansible Tower provides a web-based GUI and role-based access control.
D.The default Ansible inventory file is written in YAML format.
E.Ansible playbooks are written in Python.
AnswersA, C

Ansible operates push-based: the control node connects to managed devices and pushes modules over SSH or network APIs, rather than agents pulling configuration. This suits Cisco environments where no persistent agent runs on the device.

Why this answer

Option A is correct because Ansible operates on a push-based (agentless) model: the control node connects to managed Cisco devices over SSH (or NETCONF/RESTCONF via connection plugins) and pushes modules/playbooks to them, so no persistent agent is needed. Option C is correct because Ansible Tower (now Red Hat Ansible Automation Platform's controller) provides a web-based GUI, REST API, and role-based access control (RBAC) for managing inventories, credentials, and job templates. Option B is wrong because Ansible is agentless and does not require installing software on managed Cisco devices.

Option D is wrong because the default Ansible inventory file is INI-formatted (hosts), though YAML inventories are supported. Option E is wrong because playbooks are written in YAML, not Python (Python is used for modules and plugins).

Exam trap

350-401 often tests Ansible's agentless push model and the YAML vs INI distinction — candidates mistakenly believe Ansible requires agents or that playbooks are Python, or confuse inventory format with playbook format.

1687
MCQhard

A network architect is designing a QoS policy for a campus network. The architect needs to ensure that voice traffic is prioritized over all other traffic types, even during congestion. Which queuing mechanism should be used on the egress interface to provide strict priority to voice traffic?

A.Low Latency Queuing (LLQ)
B.Class-Based Weighted Fair Queuing (CBWFQ)
C.Weighted Random Early Detection (WRED)
D.First-In, First-Out (FIFO) queuing
AnswerA

LLQ provides strict priority queuing for delay-sensitive traffic such as voice. It combines priority queuing with CBWFQ. The priority queue is serviced first, and voice traffic is placed in this queue, ensuring it is transmitted before other traffic even during congestion. LLQ also includes a policer to limit the priority queue bandwidth, preventing starvation of other queues.

Why this answer

Low Latency Queuing (LLQ) provides strict priority queuing, which ensures that voice traffic is serviced before all other traffic. LLQ is an extension of CBWFQ that includes a priority queue for delay-sensitive traffic. The priority queue is policed to prevent bandwidth starvation of other queues.

CBWFQ, WRED, and FIFO do not offer strict priority and are not suitable for voice traffic prioritization.

Exam trap

The trap here is confusing CBWFQ with LLQ; CBWFQ alone does not provide strict priority, but LLQ adds a priority queue to CBWFQ for voice traffic.

1688
MCQmedium

A network engineer is configuring a Cisco Wireless LAN Controller (WLC) to authenticate corporate users using 802.1X with a RADIUS server. The requirement is to ensure that only users with valid credentials can access the wireless network, and that the RADIUS server is reachable. Which WLC configuration step is required to enable 802.1X authentication?

A.Enable MAC filtering on the WLC and add the MAC addresses of authorized users.
B.Configure the WLAN with WPA2 Enterprise security and specify the RADIUS server IP address and shared secret.
C.Configure the WLAN with WPA2 Personal security and specify a pre-shared key.
D.Configure the WLAN with Open security and enable web authentication using the RADIUS server.
AnswerB

To enable 802.1X authentication on a WLC, the WLAN must be configured with WPA2 Enterprise security, which uses 802.1X/EAP. The RADIUS server details, including IP address and shared secret, must be specified so the WLC can communicate with the authentication server. This configuration ensures that clients authenticate via the RADIUS server before gaining network access.

Why this answer

802.1X authentication on a Cisco WLC requires the WLAN to be configured with WPA2 Enterprise security. This setting enables the use of EAP, which relays authentication to a RADIUS server. The RADIUS server IP address and shared secret must be configured so the WLC can communicate with the server.

This ensures that only users with valid credentials, as verified by the RADIUS server, can access the wireless network.

Exam trap

The trap here is confusing WPA2 Personal (PSK) with WPA2 Enterprise (802.1X); only Enterprise mode uses a RADIUS server for per-user authentication.

1689
MCQeasy

A network administrator is enabling a virtual routing and forwarding instance on a Cisco IOS-XE router to separate customer traffic. The administrator issues the ip vrf forwarding CUSTOMER_A command on Gi0/0/1, and the interface immediately loses its IP address. What is the reason for this behavior?

A.The router reloaded and lost the running configuration
B.The interface entered a shutdown state due to the VRF assignment
C.Assigning an interface to a VRF removes any previously configured IP address
D.The VRF was not yet created in global configuration mode
AnswerC

When an interface is moved into a VRF, Cisco IOS-XE removes its existing IP address because the address belonged to the global routing table. The administrator must re-enter the IP address after the VRF assignment so the interface has an address within the VRF's own address space. This is expected behavior, not a fault.

Why this answer

On Cisco IOS-XE, entering the ip vrf forwarding command on an interface moves that interface into the named VRF and removes any IP address previously configured in the global table. The address must be reapplied afterward so the interface participates in the VRF's routing and forwarding tables. This is normal, expected behavior.

Exam trap

The trap here is treating the disappearance of the IP address as a fault or a sign of a missing VRF, rather than as expected behavior when moving an interface between routing tables.

1690
Drag & Dropmedium

Drag and drop the steps of SD-Access fabric border node configuration steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Configuration starts with enabling LISP on the border node, then configuring the EID-to-RLOC mapping and border services. Next, the border is connected to external networks (e.g., WAN), followed by applying VRF and SGT policies, and finally verifying the border operation.

1691
MCQeasy

What is the default update interval for a Cisco IOS-XE telemetry subscription when using update-policy periodic without specifying a value?

A.1000 milliseconds
B.10000 milliseconds
C.5000 milliseconds
D.The command requires a value; there is no default.
AnswerB

Omitting the value in an update-policy periodic subscription applies the platform default of 10000 milliseconds, satisfying the stem's unspecified-interval constraint. IOS-XE telemetry therefore pushes updates every ten seconds without explicit configuration, matching the documented default rather than a user-defined cadence.

Why this answer

The default periodic interval is 10000 milliseconds (10 seconds) if not explicitly configured.

1692
MCQhard

A network security team is implementing Cisco TrustSec in a campus network. The team wants to enforce access based on a tag carried in the packet rather than by IP address, and wants the tag to be propagated across the network without per-hop reclassification. Which Cisco TrustSec component assigns and inserts the Security Group Tag (SGT) at the ingress point?

A.The egress device reclassifying the packet and applying the SGT before forwarding.
B.The Cisco Identity Services Engine (ISE) inserting the SGT into every packet.
C.The Security Group Tag Exchange Protocol (SXP) on the egress device.
D.The ingress device performing classification and tagging of the packet.
AnswerD

In Cisco TrustSec, the ingress device classifies traffic and inserts the Security Group Tag into the packet, either inline in the Layer 2 frame or via a tag in the Ethernet header. This tagging at ingress allows downstream devices to enforce policy based on the SGT without reclassifying by IP. It is the correct component for assigning and inserting the SGT.

Why this answer

Cisco TrustSec relies on the ingress device to classify traffic and insert the Security Group Tag, which is then carried inline so downstream devices can enforce policy without reclassification. ISE defines the tags and policies but does not insert them, SXP propagates mappings to non-inline devices, and egress devices enforce rather than assign tags.

Exam trap

The trap here is assuming that ISE, which defines the security groups, also inserts the SGT into packets, when tagging actually occurs on the ingress network device.

1693
MCQmedium

Consider the following SD-WAN configuration snippet on a Cisco IOS-XE router: interface GigabitEthernet0/0/1 ip address 10.1.1.1 255.255.255.0 tunnel-interface encapsulation ipsec color biz-internet no allow-service bgp allow-service dhcp allow-service dns allow-service icmp ! What is the effect of this configuration?

A.The interface is configured as an SD-WAN tunnel interface with color biz-internet, allowing DHCP, DNS, and ICMP traffic but blocking BGP.
B.The interface is configured as a standard WAN interface with IPsec encryption, allowing all services including BGP.
C.The configuration enables the interface as a loopback tunnel for OMP traffic only, blocking all other services.
D.The interface is configured for SD-WAN with color biz-internet, but the 'no allow-service bgp' command is invalid on a tunnel interface.
AnswerA

This is correct because the `tunnel-interface` command provisions the physical GigabitEthernet interface as an SD-WAN transport tunnel, and the `color biz-internet` attribute designates the WAN transport class. The `allow-service` statement explicitly permits DHCP, DNS, and ICMP while the `no allow-service bgp` line denies BGP, so the interface only carries the listed services and not BGP.

Why this answer

The configuration applies to a GigabitEthernet interface that is placed into SD-WAN tunnel mode using the 'tunnel-interface' command. The 'color biz-internet' assigns the transport color, and the 'allow-service' and 'no allow-service' commands explicitly control which control-plane services are permitted over the tunnel. DHCP, DNS, and ICMP are allowed, while BGP is explicitly denied, making option A correct.

Exam trap

Cisco often tests the misconception that 'no allow-service bgp' is invalid or that the tunnel-interface configuration only applies to loopback interfaces, when in fact it is a valid command applied to physical interfaces to filter control-plane traffic per transport color.

How to eliminate wrong answers

Option B is wrong because the interface is not a standard WAN interface; it is an SD-WAN tunnel interface, and the 'no allow-service bgp' command blocks BGP rather than allowing all services. Option C is wrong because the interface is not a loopback tunnel for OMP traffic only; it is a physical interface acting as an SD-WAN transport tunnel that can carry multiple services, not just OMP. Option D is wrong because the 'no allow-service bgp' command is perfectly valid on an SD-WAN tunnel interface; it is used to explicitly deny BGP control-plane traffic over that specific transport tunnel.

1694
Drag & Drophard

Drag and drop the steps of SNMPv3 secure agent configuration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order for SNMPv3 secure agent configuration is: First, define the SNMPv3 group with security model (B). Then, enable the SNMP agent with snmp-server command (A). Next, create the SNMPv3 user with authentication and privacy keys (C).

Then, assign the user to the group (D). Finally, configure SNMPv3 view and ACL for access restriction (E). This order ensures that the group and user are defined before enabling the agent, and access control is applied last.

Exam trap

A common mistake is to enable the SNMP agent first, but the group and security model must be configured before enabling the agent to ensure the agent starts with the correct security configuration.

1695
Multi-Selecthard

Which three statements about using Python for device inventory and data serialization in network automation are true? (Choose three.)

Select 3 answers
A.A Python script can read a YAML file containing device hostnames and IP addresses, then use that data to connect to each device and gather inventory information.
B.The json module in Python can be used to serialize a dictionary containing device inventory data into a JSON string for storage or transmission.
C.CSV files can be parsed using Python's csv module to import device inventory data, such as hostname, IP, and credentials, into a script.
D.YAML files in Python cannot contain comments, so all inventory data must be described without explanatory text.
E.JSON is always more human-readable than YAML for complex inventory structures.
AnswersA, B, C

YAML parsing via PyYAML yields hostnames and IPs as native Python structures, which the script iterates over to open per-device sessions and collect inventory. This satisfies the stem's requirement that serialised data drives automated, multi-device gathering rather than manual entry.

Why this answer

Option A is correct because Python can load a YAML inventory file with libraries such as PyYAML (yaml.safe_load), iterate over the parsed hostnames and IP addresses, and use those values to drive connections to each device for inventory collection. Option B is correct because Python's built-in json module provides json.dumps() to serialize a dictionary of inventory data into a JSON string suitable for storage or transmission, and json.loads() to deserialize it. Option C is correct because the standard csv module (e.g., csv.DictReader) can parse CSV inventory files containing fields like hostname, IP, and credentials and feed them into an automation script.

Option D is incorrect because YAML explicitly supports comments using the # character, so inventory files can include explanatory text. Option E is incorrect because JSON is not always more human-readable than YAML; YAML's indentation-based, comment-friendly syntax is often considered more readable for complex nested structures.

Exam trap

The trap here is assuming that JSON is always more human-readable than YAML, or that YAML cannot contain comments, due to unfamiliarity with YAML's features; candidates may incorrectly eliminate the correct options based on these misconceptions.

1696
MCQmedium

A network engineer is configuring a new Cisco Catalyst switch that will participate in a VTP domain. The engineer wants to ensure the switch can create, modify, and delete VLANs for the domain while also receiving updates. The switch must not overwrite the existing VLAN database on other switches in the domain. Which VTP mode should be configured?

A.VTP client mode
B.VTP server mode
C.VTP transparent mode
D.VTP off mode
AnswerB

VTP server mode allows the switch to create, modify, and delete VLANs for the entire VTP domain. The switch can also receive and process VTP advertisements from other servers, but it will not overwrite the existing VLAN database unless its configuration revision number is higher. By default, a new switch has a revision number of 0, so it will not overwrite existing databases. This meets all requirements.

Why this answer

VTP server mode enables a switch to create, modify, and delete VLANs for the entire VTP domain. It also receives VTP advertisements from other servers and clients. A new switch with a default revision number of 0 will not overwrite the existing VLAN database unless its revision number is higher.

Therefore, server mode satisfies the need to manage VLANs domain-wide while safely receiving updates.

Exam trap

The trap here is assuming that a VTP server will automatically overwrite other switches' VLAN databases, when in fact it only does so if its configuration revision number is higher than the existing one.

1697
Matchingeasy

Drag and drop each HTTP status code on the left to its meaning on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Request succeeded

Resource created

Malformed request syntax

Authentication required or failed

Requested resource not found

Why these pairings

Correct pairings: 200 OK for success; 201 Created for resource creation; 400 Bad Request for client error; 401 Unauthorized for missing/invalid credentials; 404 Not Found for missing resource; 500 Internal Server Error for server-side failure.

1698
Matchingmedium

Drag and drop each IP SLA operation type on the left to its measured metric on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Round-trip time and packet loss

Delay, jitter, and packet loss

Connection establishment time

Page load time and success

DNS resolution time

Why these pairings

ICMP echo measures round-trip time and packet loss; UDP jitter measures delay, jitter, and packet loss; TCP connect measures connection establishment time; HTTP measures page load time and success; DNS measures DNS resolution time.

1699
MCQmedium

A network engineer runs the following command on Switch SW1: SW1# show interfaces gi0/1 switchport Name: Gi0/1 Switchport: Enabled Administrative Mode: trunk Operational Mode: trunk Administrative Trunking Encapsulation: dot1q Operational Trunking Encapsulation: dot1q Negotiation of Trunking: On Access Mode VLAN: 1 (default) Trunking Native Mode VLAN: 1 (default) Administrative Native VLAN tagging: enabled Voice VLAN: none Administrative private-vlan host-association: none Administrative private-vlan mapping: none Administrative private-vlan trunk native VLAN: none Administrative private-vlan trunk Native VLAN tagging: enabled Administrative private-vlan trunk encapsulation: dot1q Administrative private-vlan trunk normal VLANs: none Administrative private-vlan trunk private VLANs: none Operational private-vlan: none Trunking VLANs Enabled: ALL Pruning VLANs Enabled: 2-1001 Capture Mode Disabled Capture VLANs Allowed: ALL Based on this output, what can be concluded?

A.The interface is configured as an access port.
B.DTP is enabled on this interface.
C.The native VLAN is tagged with 802.1Q.
D.All VLANs except 2-1001 are pruned.
AnswerB

The command output includes the line 'Negotiation of Trunking: On', which confirms that Dynamic Trunking Protocol (DTP) is enabled and actively attempting to negotiate trunking with the connected neighbor. DTP is a Cisco proprietary protocol that allows the interface to dynamically decide between access and trunk mode. This is the correct and directly supported conclusion from the provided switchport trunk information.

Why this answer

The output shows 'Negotiation of Trunking: On', which indicates that Dynamic Trunking Protocol (DTP) is enabled on the interface. DTP is a Cisco proprietary protocol used to negotiate trunking between switches. Since the interface is in trunk mode and DTP is on, option B is correct.

Exam trap

Cisco often tests the distinction between 'Pruning VLANs Enabled' and 'Trunking VLANs Enabled', where candidates mistakenly think that VLANs listed under pruning are actively removed from the trunk, when in fact they are only eligible for pruning if VTP pruning is enabled.

How to eliminate wrong answers

Option A is wrong because the 'Administrative Mode: trunk' and 'Operational Mode: trunk' clearly indicate the port is configured as a trunk, not an access port. Option C is wrong because 'Administrative Native VLAN tagging: enabled' means the switch will tag frames on the native VLAN with an 802.1Q header, but the native VLAN itself (VLAN 1) is not tagged by default; tagging is an additional configuration that forces tagging of native VLAN frames, not that the native VLAN is inherently tagged. Option D is wrong because 'Trunking VLANs Enabled: ALL' shows all VLANs are allowed on the trunk, while 'Pruning VLANs Enabled: 2-1001' indicates VLANs 2-1001 are eligible for pruning by VTP, not that they are currently pruned.

1700
MCQmedium

A network engineer runs the following command on Switch SW1: SW1# show spanning-tree vlan 10 VLAN0010 Spanning tree enabled protocol ieee Root ID Priority 32778 Address 0011.2233.4455 Cost 19 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32778 (priority 32768 sys-id-ext 10) Address 0011.2233.4466 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- -------------------------------- Gi0/1 Root FWD 19 128.1 P2p Gi0/2 Altn BLK 19 128.2 P2p Gi0/3 Desg FWD 19 128.3 P2p Based on this output, what can be concluded?

A.SW1 is the root bridge for VLAN 10.
B.Gi0/2 is in blocking state due to loop prevention.
C.Gi0/3 is a root port.
D.The root bridge has a higher priority than SW1.
AnswerB

Gi0/2 is correctly placed in blocking state because Spanning Tree Protocol designates it as an alternate port, which functions as a redundant path to the root bridge that is less optimal than the root port. This blocking state is intentional loop prevention; if Gi0/2 were allowed to forward, it would create a Layer 2 forwarding loop in the switched topology. The alternate port role is typical in networks with redundant links and does not indicate a failure or misconfiguration.

Why this answer

The output shows Gi0/2 is in the Alternate (Altn) role with a Blocking (BLK) state. In Rapid PVST+ (IEEE 802.1w), an alternate port provides a backup path to the root bridge and is placed in a blocking state to prevent Layer 2 loops. Since SW1 is not the root bridge (its Bridge ID priority 32778 is equal to the Root ID priority, but its MAC address 0011.2233.4466 is higher than the root's 0011.2233.4455), Gi0/2 is blocking as a loop-prevention mechanism.

Exam trap

Cisco often tests the distinction between port roles (Root, Designated, Alternate, Backup) and port states (FWD, BLK), where candidates mistakenly assume that any port in a blocking state is a Backup port or that a Designated port must be on the root bridge, when in fact Alternate ports block to prevent loops on non-root bridges.

How to eliminate wrong answers

Option A is wrong because SW1 is not the root bridge for VLAN 10; the Root ID shows a MAC address of 0011.2233.4455, while SW1's Bridge ID MAC is 0011.2233.4466, and the root cost is 19 via Gi0/1, indicating SW1 is a non-root switch. Option C is wrong because Gi0/3 is in the Desg (Designated) role with FWD state, not a root port; the root port is Gi0/1, which has the Root role and FWD state. Option D is wrong because the root bridge has the same priority (32778) as SW1, not a higher priority; the root is elected based on the lowest bridge ID, and here the root's MAC address is lower, making it the root despite equal priority.

1701
Drag & Dropmedium

Drag and drop the steps of OSPFv3 IPv6 neighbor adjacency formation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

OSPFv3 neighbor formation follows the same state machine as OSPFv2: Down, Init, 2-Way, ExStart, Exchange, Loading, Full. The steps reflect the key actions at each state.

1702
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against control plane overload. The router has management traffic (SSH, SNMP) and routing protocol traffic (OSPF, BGP). After applying the CoPP policy, the engineer notices that OSPF adjacencies are flapping. Which action should the engineer take to resolve this issue while maintaining control plane protection?

A.Increase the rate limit for the OSPF class in the CoPP policy.
B.Configure OSPF to use a different DSCP value so it matches a higher-priority class in the CoPP policy.
C.Remove the CoPP policy from the control plane and reapply it after OSPF stabilizes.
D.Apply the CoPP policy only to the management plane interface instead of the control plane.
AnswerA

OSPF adjacency flapping indicates that OSPF hello packets are being dropped due to the policer rate being too low. Increasing the rate limit for the OSPF class allows legitimate OSPF control traffic to pass while still protecting the control plane from excessive traffic. This is the correct action because it directly addresses the dropped OSPF packets without removing protection entirely.

Why this answer

OSPF adjacency flapping after CoPP deployment indicates that OSPF hello packets are being dropped by the policer. The CoPP policy likely has a rate limit for OSPF that is too low for the network's requirements. Increasing the rate limit for the OSPF class allows OSPF traffic to pass while still enforcing a policer to protect against excess traffic.

This maintains control plane protection and resolves the flapping.

Exam trap

The trap here is assuming that any CoPP issue requires removing the policy, when in fact tuning the rate limits for specific classes is the correct approach to balance protection and protocol operation.

1703
MCQhard

A network engineer is implementing model-driven telemetry on a Cisco Nexus 9000 switch to monitor VLAN and STP changes. The engineer wants to use the native telemetry protocol with UDP as the transport. After configuring the telemetry subscription with the 'destination-group' and 'sensor-group', the engineer notices that the collector is not receiving any data. The collector is reachable and the UDP port is open. What is the most likely missing configuration?

A.The engineer forgot to configure a 'source-interface' under the destination-group
B.The engineer did not create a 'policy' that binds the sensor-group and destination-group
C.The YANG models for VLAN and STP are not supported in the native telemetry protocol
D.The engineer used GPB encoding instead of JSON, and the collector only accepts JSON
AnswerB

The subscription remains incomplete without a policy that binds the sensor-group to the destination-group. Cisco's telemetry configuration requires this association before data streams; without it, the switch has sensors and destinations defined but no instruction to send one to the other, so nothing reaches the collector despite reachability.

Why this answer

On Nexus 9000 model-driven telemetry, a subscription requires three components: a destination-group (collector address/port), a sensor-group (YANG paths), and a subscription policy that binds them together. Without the policy, the sensor-group and destination-group are defined but never associated, so no data is exported.

Exam trap

The trap is stopping configuration after defining destination-group and sensor-group — candidates forget that the subscription policy is the mandatory binding step that actually activates telemetry.

How to eliminate wrong answers

Option A is wrong because source-interface is optional under destination-group; its absence would not prevent telemetry from being sent if routing is correct. Option C is wrong because VLAN and STP YANG models are supported by the native telemetry protocol on NX-OS. Option D is wrong because GPB vs JSON encoding is a collector-side compatibility issue; if the collector only accepted JSON, the engineer would see malformed data, not zero data — and the scenario says nothing about encoding mismatch.

1704
MCQmedium

A network engineer is writing a Python script to retrieve interface statistics from a Cisco IOS XE device using RESTCONF. The script sends a GET request to https://10.1.1.1/restconf/data/ietf-interfaces:interfaces but receives an HTTP 406 Not Acceptable response. The engineer verifies that the device has RESTCONF enabled and the credentials are correct. Which action should the engineer take to resolve this issue?

A.Enable NETCONF on the device and use it instead of RESTCONF.
B.Change the HTTP method from GET to POST.
C.Add a Content-Type header of application/yang-data+json to the request.
D.Add an Accept header of application/yang-data+json to the request.
AnswerD

RESTCONF requires the client to specify the desired media type via the Accept header. Without it, the server may return 406 Not Acceptable. Setting Accept: application/yang-data+json tells the server to return data in JSON format, which is the standard for RESTCONF. This directly resolves the 406 error by indicating the client's supported response format.

Why this answer

The 406 Not Acceptable status code indicates that the server cannot produce a response matching the client's Accept header. In RESTCONF, the client must specify the desired media type, such as application/yang-data+json. Without it, the server may reject the request.

Adding the Accept header tells the server to return JSON-encoded YANG data, which is the expected format.

Exam trap

The trap here is confusing the Accept header with the Content-Type header, assuming that any media type header will fix the 406 error.

1705
Multi-Selecteasy

Which two statements about the 'ip access-group' command are true? (Choose two.)

Select 2 answers
A.The 'ip access-group' command applies an ACL to an interface in a specified direction.
B.The 'ip access-group' command can be applied to both physical interfaces and SVIs.
C.The 'ip access-group' command creates a new ACL if the named ACL does not exist.
D.The 'ip access-group' command can only filter traffic in the inbound direction.
E.The 'ip access-group' command is used to apply a CoPP policy to the control plane.
AnswersA, B

The ip access-group command binds a numbered or named ACL to a specific interface and specifies whether filtering applies inbound or outbound. This satisfies the stem's requirement for an accurate statement about the command's behaviour.

Why this answer

Option A is correct because the 'ip access-group' command binds an existing ACL to an interface and requires a direction keyword (in or out), thereby filtering traffic in that specified direction. Option B is correct because 'ip access-group' can be configured on physical interfaces (e.g., GigabitEthernet0/1) as well as on switched virtual interfaces (SVIs) such as interface Vlan10, since both are Layer 3 interfaces that support ACL application. Option C is incorrect because 'ip access-group' only applies an already-defined ACL; it does not create one, and referencing a nonexistent ACL results in an error or an empty ACL depending on platform.

Option D is incorrect because the command supports both the inbound and outbound directions via the 'in' and 'out' keywords. Option E is incorrect because CoPP policies are applied to the control plane using the 'service-policy' command under 'control-plane' configuration, not with 'ip access-group'.

1706
MCQeasy

A network engineer is writing a Python script to query interface statistics from a Cisco IOS XE device using NETCONF. The script must establish a secure session that supports configuration and state data retrieval. Which transport protocol and port should the engineer use for the NETCONF session?

A.SSH over TCP port 22
B.HTTPS over TCP port 443
C.TLS over TCP port 6513
D.HTTP over TCP port 80
AnswerA

NETCONF uses SSH as its transport protocol, and the standard port for SSH is TCP 22. This provides a secure, encrypted channel for NETCONF messages. The engineer should connect to port 22 to establish the NETCONF session, which supports both configuration and state data retrieval via RPCs.

Why this answer

NETCONF is transported over SSH, which by default listens on TCP port 22. This provides a secure, encrypted connection suitable for configuration and state data retrieval. Other protocols like TLS or HTTP are either not supported on Cisco IOS XE for NETCONF or are used for different APIs such as RESTCONF.

The engineer must use SSH on port 22 to establish a NETCONF session.

Exam trap

The trap here is confusing NETCONF with RESTCONF, which uses HTTPS on port 443, or assuming NETCONF over TLS is the default on Cisco IOS XE.

1707
MCQmedium

A company is deploying a new campus network with a hierarchical design (core, distribution, access). The QoS design must ensure that voice traffic is prioritized end-to-end, and that marking is trusted only on access ports connected to IP phones. Which architectural approach should the architect take for classification and marking?

A.Configure the access switches to trust DSCP on ports connected to IP phones, and apply queuing policies on distribution and core switches that match the trusted markings.
B.Remark all traffic to a single DSCP value at the access layer and apply priority queuing at the core.
C.Apply QoS policies only at the core layer, ignoring markings from the access layer.
D.Use the distribution layer to reclassify traffic based on source MAC addresses of IP phones.
AnswerA

Trusting DSCP on IP phone ports is the correct trust boundary because Cisco IP phones set Expedited Forwarding (EF, DSCP 46) for voice RTP; access switches should preserve this marking via 'mls qos trust dscp' rather than re-marking. With those markings intact, distribution and core switches can apply consistent queuing policies—strict priority for EF voice, class-based queuing for call signaling (CS3/AF31) and data—so voice quality is maintained end to end and the trust boundary stays at the access layer.

Why this answer

It aligns with the Cisco QoS trust boundary model for campus networks. IP phones are trusted endpoints that mark voice traffic with the correct DSCP values (e.g., EF for voice, AF41 for video). By configuring the access switch port to trust DSCP from the IP phone, the marking is preserved end-to-end.

Distribution and core switches then apply queuing policies (e.g., LLQ) based on these trusted markings, ensuring voice traffic receives priority treatment across the entire network.

Exam trap

Cisco often tests the concept that the trust boundary must be set at the access layer, not at the distribution or core, and that trusting DSCP from IP phones is the correct method, while remarking all traffic to a single value or ignoring markings entirely are common misconceptions that break end-to-end QoS.

How to eliminate wrong answers

Option B is wrong because remarking all traffic to a single DSCP value at the access layer eliminates any differentiation between voice, video, and data, defeating the purpose of QoS and causing all traffic to be treated equally, which would starve voice of priority. Option C is wrong because applying QoS policies only at the core layer ignores the need to establish a trust boundary at the access layer; without trusting or marking at the edge, the core has no reliable markings to act upon, and the access layer may re-mark or drop priority packets. Option D is wrong because reclassifying traffic based on source MAC addresses at the distribution layer is inefficient and unscalable; classification should occur as close to the source as possible (at the access layer), and MAC-based classification does not leverage the standard DSCP markings that IP phones already set.

1708
Matchingmedium

Drag and drop each OSPF router role on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Generates Type 2 Network LSA and maintains full adjacencies with all routers on the segment

Becomes DR if the current DR fails; also maintains full adjacencies

Forms adjacencies only with DR and BDR; does not form full adjacencies with other DROTHERs

Redistributes routes from other routing protocols into OSPF

Connects two or more OSPF areas and advertises inter-area routes

Why these pairings

DR (Designated Router) generates Network LSAs and manages adjacencies on multi-access networks; BDR (Backup DR) takes over if the DR fails; DROTHER routers form full adjacencies only with DR and BDR; ASBR redistributes routes from other protocols; ABR connects multiple areas.

1709
MCQmedium

A network engineer is writing a Python script to retrieve the operational state of a GigabitEthernet interface from a Cisco IOS XE device using RESTCONF. The script sends a GET request to https://10.1.1.1/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1 but receives a 406 Not Acceptable response. The device supports RESTCONF and the interface exists. Which HTTP header should the engineer add to the request to resolve this error?

A.Accept: application/xml
B.Accept: application/yang-data+json
C.Authorization: Basic YWRtaW46YWRtaW4=
D.Content-Type: application/yang-data+json
AnswerB

RESTCONF requires the client to specify the desired media type for the response. The 406 Not Acceptable error occurs when the Accept header is missing or does not match a media type the server can produce. Adding Accept: application/yang-data+json tells the server to return the data in JSON format, which IOS XE supports, resolving the error.

Why this answer

The 406 Not Acceptable status code indicates that the server cannot produce a response matching the Accept header. In RESTCONF, the client must specify the desired media type, such as application/yang-data+json, to retrieve data in JSON. Without it, the server may reject the request.

Adding the correct Accept header resolves the negotiation issue.

Exam trap

The trap here is confusing the Accept header, which specifies the desired response format, with the Content-Type header, which specifies the format of the request body, leading to an incorrect fix.

1710
Drag & Dropmedium

Drag and drop the steps of PIM DM (Dense Mode) flood and prune steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

PIM DM initially floods multicast traffic to all PIM-enabled interfaces; downstream routers that have no interested receivers send Prune messages upstream to stop unwanted traffic.

1711
MCQhard

A network engineer is deploying a Cisco SD-Access fabric for a campus network. The fabric consists of border nodes, control plane nodes, edge nodes, and an intermediate node. The engineer needs to ensure that endpoints in the fabric can communicate with external networks such as the data center and the internet. Which component of the SD-Access architecture is responsible for providing connectivity between the fabric and external networks?

A.Control plane node
B.Edge node
C.Border node
D.Intermediate node
AnswerC

Border nodes in Cisco SD-Access provide connectivity between the fabric and external networks, such as the data center, internet, or legacy networks. They perform the role of LISP proxy tunnel routers (PxTRs) and can also run BGP or other routing protocols to exchange routes with external devices. In this scenario, the border node is the correct component because it is specifically designed to handle external traffic entering and leaving the fabric.

Why this answer

In Cisco SD-Access, border nodes are responsible for connecting the fabric to external networks. They act as the gateway between the fabric and outside networks, performing functions such as LISP proxy and route redistribution. Control plane nodes handle endpoint registration, edge nodes connect endpoints, and intermediate nodes connect multiple fabric sites.

Thus, the border node is the correct component for providing external connectivity.

Exam trap

The trap here is confusing the roles of border nodes and intermediate nodes, or assuming that control plane nodes handle external routing.

1712
Multi-Selectmedium

Which two statements about EIGRP stub routing are true? (Choose two.)

Select 2 answers
A.A stub router advertises only connected and summary routes by default.
B.A stub router can still be used as a transit router for other EIGRP neighbors.
C.The 'eigrp stub' command is configured on the hub router in a hub-and-spoke topology.
D.EIGRP stub routing reduces query scoping and improves convergence.
E.A stub router can be configured with the 'receive-only' keyword to advertise all its routes.
AnswersA, D

EIGRP stub routing suppresses transit traffic by default, advertising only connected and summary routes to its neighbours. This satisfies the stem's requirement for a true statement: the stub router limits its advertised prefixes, preventing it from becoming a transit path while still sharing its directly attached and summarised networks.

Why this answer

Option A is correct because when the 'eigrp stub' command is configured without additional keywords, the router defaults to advertising only connected and summary routes to its EIGRP neighbors, which limits the routing information it propagates. Option D is correct because stub routing confines EIGRP queries to the stub router's local domain, preventing them from being forwarded to the stub, which reduces query scope and speeds up network convergence. Option B is incorrect because a stub router is explicitly not used as a transit router; it does not advertise routes learned from other EIGRP neighbors, so traffic cannot pass through it to reach other networks.

Option C is incorrect because the 'eigrp stub' command is configured on the spoke (stub) routers in a hub-and-spoke topology, not on the hub router. Option E is incorrect because the 'receive-only' keyword configures the stub router to advertise no routes at all, not to advertise all its routes.

Exam trap

350-401 often tests the direction of stub configuration (spoke, not hub) and the default advertisement behavior (connected + summary), while confusing candidates with the 'receive-only' keyword that actually suppresses all advertisements.

1713
MCQmedium

A network engineer is configuring a Cisco IOS XE router to support Network Address Translation (NAT) for a small office. The router has an inside interface GigabitEthernet0/0/0 and an outside interface GigabitEthernet0/0/1. The engineer wants to translate all inside hosts to the outside interface IP address using PAT. Which configuration snippet correctly implements this?

A.ip nat inside source static 192.168.1.10 203.0.113.1; interfaces marked inside/outside; no access-list needed
B.ip nat inside source list 1 interface GigabitEthernet0/0/1 overload; interface GigabitEthernet0/0/0: ip nat inside; interface GigabitEthernet0/0/1: ip nat outside; access-list 1 permit 192.168.1.0 0.0.0.255
C.ip nat inside source list 1 pool MYPOOL overload; ip nat pool MYPOOL 203.0.113.1 203.0.113.1 netmask 255.255.255.0; interfaces marked inside/outside; access-list 1 permit 192.168.1.0 0.0.0.255
D.ip nat outside source list 1 interface GigabitEthernet0/0/0 overload; interfaces marked inside/outside; access-list 1 permit any
AnswerB

This configuration uses PAT overload by referencing the outside interface in the ip nat inside source command, which translates all inside hosts to the outside interface IP. The access list defines the inside subnet, and the interfaces are marked correctly as inside and outside. This is the standard method for PAT to a single outside address, matching the requirement.

Why this answer

The correct PAT configuration for translating all inside hosts to the outside interface IP uses the ip nat inside source list command with the interface keyword and overload. The access list defines the inside subnet, and interfaces are marked inside and outside. Static NAT, NAT pools, and outside source NAT do not meet the specific requirement of translating all inside hosts to the outside interface IP.

Exam trap

The trap here is confusing static NAT or pool-based NAT with PAT to an interface, when the scenario explicitly requires translating all inside hosts to the outside interface IP.

1714
MCQmedium

Examine this DHCP configuration: ``` ip dhcp pool POOL1 network 10.10.10.0 255.255.255.0 default-router 10.10.10.1 dns-server 8.8.8.8 lease 0 12 ! ip dhcp excluded-address 10.10.10.1 10.10.10.10 ``` Which statement is true?

A.DHCP clients will receive a lease for 12 hours.
B.The router will assign IP addresses from 10.10.10.1 to 10.10.10.254.
C.The default lease is used because the lease command is incomplete.
D.The DNS server is set to 8.8.8.8, but clients will ignore it.
AnswerA

The DHCP pool configuration includes the command lease 0 12, which explicitly sets the lease duration to 0 days, 12 hours, and 0 minutes. Cisco IOS accepts this as a valid lease time, and clients will receive a lease expiration 12 hours after the address is assigned. Without a lease command, the default is 1 day, but here the explicit 12-hour value overrides that default.

Why this answer

The `lease 0 12` command explicitly sets the DHCP lease duration to 12 hours (0 days, 12 hours). The router will assign addresses from 10.10.10.11 to 10.10.10.254, as the excluded-address range (10.10.10.1–10.10.10.10) removes the first ten addresses from the pool, and the network statement defines the 10.10.10.0/24 subnet.

Exam trap

Cisco often tests the interaction between the `network` command and the `ip dhcp excluded-address` command, leading candidates to incorrectly assume the entire subnet is available for DHCP assignment without considering the exclusion range.

How to eliminate wrong answers

Option B is wrong because the `ip dhcp excluded-address 10.10.10.1 10.10.10.10` command prevents the router from assigning addresses 10.10.10.1 through 10.10.10.10, so the assignable range is 10.10.10.11 to 10.10.10.254, not 10.10.10.1 to 10.10.10.254. Option C is wrong because the `lease 0 12` command is complete and valid; it specifies 0 days and 12 hours, so the default lease (1 day) is not used. Option D is wrong because the `dns-server 8.8.8.8` command configures the DHCP server to offer that DNS server address to clients, and clients will accept and use it unless they are configured to ignore DHCP options (which is not the default behavior).

1715
MCQeasy

A network engineer is new to automation and wants to start by writing a simple Python script to interact with a Cisco IOS XE device using RESTCONF. Which Python library is specifically designed to simplify sending HTTP requests to RESTCONF APIs?

A.Netmiko
B.Ncclient
C.Paramiko
D.Requests
AnswerD

The Requests library is a popular Python HTTP library that simplifies sending HTTP requests. It is commonly used with RESTCONF to interact with Cisco devices because it handles HTTP methods like GET, POST, PUT, PATCH, and DELETE, and supports authentication and JSON/XML payloads. It is an excellent choice for beginners.

Why this answer

The Requests library is designed for making HTTP requests in Python, which is exactly what RESTCONF uses. It abstracts the complexities of HTTP and allows easy interaction with RESTCONF APIs, including authentication and data formatting. Other libraries like Netmiko and Ncclient are for SSH and NETCONF, respectively, and are not suited for RESTCONF.

Paramiko is for SSH and not HTTP.

Exam trap

The trap here is confusing RESTCONF with NETCONF or CLI automation, leading to the selection of libraries like Ncclient or Netmiko, which are not HTTP-based.

1716
MCQmedium

A network engineer is troubleshooting an issue where a Cisco router is not responding to SNMP polls from a network management station (NMS) at 192.168.1.50. The router has a CoPP policy that includes a class-map matching SNMP traffic (UDP port 161). The engineer checks the CoPP statistics and sees that SNMP packets from the NMS are being dropped. The engineer wants to allow SNMP from the NMS while still protecting the control plane. Which configuration change should the engineer make?

A.Modify the CoPP ACL to include a permit statement for UDP port 161 from host 192.168.1.50 before the deny statement.
B.Increase the police rate for the CoPP class that matches SNMP traffic.
C.Remove the CoPP policy from the control plane and rely on interface ACLs.
D.Change the SNMP port on the router to a non-standard port to avoid the CoPP policy.
AnswerA

The CoPP policy evaluates control-plane traffic using an ordered ACL; if the class-map references an ACL with a deny hit for the NMS's source, SNMP from 192.168.1.50 is not classified into the intended class and may fall through to a default drop action. Inserting a permit statement for UDP port 161 from that host before the existing deny entry ensures the class-map matches correctly, allowing the traffic to be policed under the appropriate CoPP class. This is the only option that directly fixes the selective source-based drop while preserving the security policy.

Why this answer

The CoPP policy is dropping SNMP packets from the NMS because the class-map matching SNMP traffic (UDP port 161) is applied without an exception for the specific management station. By modifying the ACL to include a permit statement for UDP port 161 from host 192.168.1.50 before the deny statement, the router will match and allow those packets before they hit the drop action, preserving control plane protection while permitting the NMS polls.

Exam trap

Cisco often tests the concept that CoPP ACLs are processed in order, and candidates may incorrectly assume that increasing the police rate or removing the policy entirely is the solution, rather than understanding that a specific permit entry for the trusted host must be placed before the deny statement.

How to eliminate wrong answers

Option B is wrong because increasing the police rate for the CoPP class would allow more SNMP traffic in general, but it would not selectively permit the NMS while still dropping other SNMP traffic; it would also reduce protection against SNMP-based DoS attacks. Option C is wrong because removing the CoPP policy entirely and relying on interface ACLs would leave the control plane unprotected against other types of control plane attacks, as interface ACLs do not provide the same granular rate-limiting and classification for control plane traffic. Option D is wrong because changing the SNMP port on the router to a non-standard port would require reconfiguring both the router and the NMS, and it would not bypass the CoPP policy unless the class-map is also updated; the CoPP policy matches UDP port 161, so a different port would not be matched and thus not dropped, but this is an impractical workaround that does not address the root cause.

1717
MCQmedium

A network engineer is deploying Cisco SD-Access and needs to provide fabric edge nodes with a mapping database for endpoint locations. The fabric uses LISP for control plane and VXLAN for data plane encapsulation. Which component is responsible for maintaining the endpoint-to-edge-node mapping and responding to map requests?

A.Fabric Edge Node
B.Fabric Border Node
C.Fabric Intermediate Node
D.Control Plane Node
AnswerD

The Control Plane Node (CPN) runs the LISP map server and map resolver. It maintains the endpoint ID-to-RLOC mapping database and responds to map-requests from fabric edge nodes. When an edge node needs to locate an endpoint, it queries the CPN, which returns the RLOC of the edge node where the endpoint is attached.

Why this answer

In Cisco SD-Access, the Control Plane Node runs the LISP map server and map resolver, maintaining the endpoint-to-RLOC mapping database. Fabric edge nodes query this node to resolve endpoint locations. The Control Plane Node is the central authority for the LISP control plane, enabling scalable endpoint mobility and policy enforcement.

Exam trap

The trap here is assuming that fabric edge nodes maintain the endpoint mapping database, but they only register endpoints and query the Control Plane Node for resolution.

1718
Drag & Dropmedium

Drag and drop the steps of Cisco DNA Center device onboarding via PnP into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The PnP onboarding process begins with the device obtaining an IP address via DHCP and receiving the PnP server address from DHCP options. The device then discovers the Cisco DNA Center PnP server and authenticates using a certificate or credentials. After authentication, the device downloads its Day 0 configuration and image from DNA Center.

Finally, the device applies the configuration and joins the fabric or network.

1719
Multi-Selecteasy

Which two statements about NetFlow flow records and export are correct? (Choose two.)

Select 2 answers
A.NetFlow v9 uses a template-based export format.
B.IPFIX is the IETF standard version of NetFlow, based on NetFlow v9.
C.NetFlow v5 supports variable-length fields and custom flow keys.
D.NetFlow export uses TCP by default to ensure reliable delivery.
E.NetFlow v5 can export IPv6 flow information.
AnswersA, B

NetFlow v9 replaces the fixed-format records of v5 with reusable templates, letting a collector interpret varied field layouts without prior knowledge of each exporter's configuration. This satisfies the scenario's requirement for flexible, extensible flow export, since templates are periodically resent so collectors can decode records dynamically.

Why this answer

Option A is correct because NetFlow v9 introduced a template-based export format, where the exporter periodically sends template records that define the layout and field types of subsequent data records, allowing flexible and extensible flow record definitions. Option B is correct because IPFIX (Internet Protocol Flow Information Export) is the IETF standard (RFC 7011) derived from and based on NetFlow v9, adopting its template-based architecture while standardizing field specifications. Option C is incorrect because NetFlow v5 uses a fixed, predefined record format with fixed-length fields and a fixed flow key, not variable-length fields or custom keys.

Option D is incorrect because NetFlow export traditionally uses UDP (typically port 2055) for efficiency, not TCP by default, though TCP is an option in some implementations like IPFIX. Option E is incorrect because NetFlow v5 only supports IPv4 flow information; IPv6 support was introduced with NetFlow v9 and IPFIX.

Exam trap

The trap is assuming that NetFlow v5 supports modern features like IPv6 or variable-length fields, or that export uses TCP for reliability, when in fact UDP is standard.

1720
Drag & Dropmedium

Drag and drop the steps of disaster recovery failover process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Failover begins with detecting the primary failure, then activating the backup path. Traffic is redirected to the secondary site, and after the primary is restored, operations are switched back in a controlled manner.

1721
MCQhard

A network engineer is deploying Cisco SD-Access and needs to integrate a new fabric site with an existing traditional network. The requirement is to allow endpoints in the fabric to communicate with external networks while preserving their fabric-assigned IP addresses and providing policy enforcement. Which component is responsible for this integration?

A.Fabric control plane node
B.Fabric edge node
C.Fabric border node
D.Fabric intermediate node
AnswerC

The fabric border node connects the SD-Access fabric to external networks (traditional L3 networks, data centers, or other fabric sites). It performs route redistribution between the fabric's LISP/VXLAN domains and external routing protocols, and can enforce policy via SGT propagation. It preserves endpoint IP addresses by advertising fabric prefixes externally and importing external routes into the fabric.

Why this answer

The fabric border node is the component that connects the SD-Access fabric to external networks. It handles route redistribution between the fabric and external routing domains, preserves endpoint IP addresses, and can enforce policy using SGTs. Edge, control plane, and intermediate nodes have different roles and do not provide external integration.

Exam trap

The trap here is confusing the roles of fabric nodes, particularly assuming the control plane node handles external routing or that edge nodes perform border functions.

1722
MCQmedium

A network engineer is troubleshooting a Cisco Nexus 9000 leaf switch that is part of a VXLAN EVPN fabric. The engineer notices that the leaf is not learning remote MAC addresses, although the underlay is operational and BGP EVPN sessions are established. Which action should the engineer take to verify that the leaf is receiving EVPN Type 2 routes?

A.Check the output of 'show vxlan interface' on the leaf.
B.Check the output of 'show ip route' on the leaf.
C.Check the output of 'show nve peers' on the leaf.
D.Check the output of 'show bgp l2vpn evpn' on the leaf.
AnswerD

The command 'show bgp l2vpn evpn' displays the EVPN routes received from BGP peers, including Type 2 (MAC/IP advertisement) routes. If the leaf is not learning remote MACs, this command will show whether Type 2 routes are present. If they are missing, the issue may be with the BGP EVPN configuration or route reflectors. This is the correct verification step.

Why this answer

To verify that the leaf is receiving EVPN Type 2 routes, you must examine the BGP EVPN table. The command 'show bgp l2vpn evpn' displays all EVPN routes, including Type 2 MAC/IP advertisement routes. If these routes are missing, the leaf will not learn remote MAC addresses.

Other commands like 'show nve peers' show VTEP peers but not MAC routes, and 'show vxlan interface' shows tunnel configuration, not routes.

Exam trap

The trap here is assuming that seeing NVE peers or underlay routes is sufficient to confirm MAC learning, when actually you need to inspect the BGP EVPN table for Type 2 routes.

1723
MCQhard

A network engineer is using a Python script with the ncclient library to retrieve configuration from a Cisco IOS XE device via NETCONF. The script uses the <get-config> RPC with a source of <running/> and a filter of <native xmlns="http://cisco.com/ns/yang/Cisco-IOS-XE-native"/>. The script successfully retrieves the configuration but the output is in XML format. The engineer wants to convert this XML into a Python dictionary for easier manipulation. Which Python library is specifically designed to parse XML into a dictionary structure?

A.ElementTree
B.lxml
C.BeautifulSoup
D.xmltodict
AnswerD

xmltodict is a Python library that converts XML into a dictionary, making it easy to work with XML data in Python. It preserves attributes and nested structures, and is commonly used with NETCONF responses. It directly addresses the need to transform XML into a dictionary for manipulation.

Why this answer

xmltodict is specifically designed to convert XML into a Python dictionary, making it the ideal choice for transforming NETCONF XML responses into a manipulable dictionary format.

Exam trap

The trap here is confusing general XML parsing libraries with a library that specifically outputs a dictionary.

1724
Drag & Dropmedium

Drag and drop the steps of configuring a Layer 2 EtherChannel using PAgP into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, create the port-channel interface globally. Then set the channel-group mode to desirable on the first interface. Next, set the same mode on the second interface.

After that, verify the bundle forms using show commands. Finally, assign the port-channel to a VLAN to enable data forwarding. This sequence ensures PAgP negotiation completes before the bundle is used.

1725
MCQmedium

A network engineer is configuring 802.1X on a Cisco switch for a guest network. The engineer wants to allow guests to access the internet after authentication but restrict access to internal resources. The engineer configures the switch with 'authentication port-control auto' and a downloadable ACL (dACL) from the RADIUS server. After a guest authenticates, the engineer tests connectivity and finds that the guest can access internal servers. What is the most likely cause?

A.The switchport is configured as 'switchport mode trunk', which does not support dACLs.
B.The guest is not being authenticated; the switch is using MAB instead.
C.The switch is not configured with 'ip access-group' to apply the dACL.
D.The RADIUS server is not sending the dACL attributes in the Access-Accept message.
AnswerD

This is correct because the switch only applies a dACL when the RADIUS Access-Accept message contains the appropriate downloadable ACL attributes, such as Cisco-AVPair (e.g., 'ip:inacl#<acl-name>') or Filter-ID. If those attributes are absent, the switch receives no policy and therefore permits the guest's traffic without any IPv4 ACL filtering. The RADIUS server must be configured to return the dACL for the particular user or policy; otherwise, no access restrictions are enforced by the switch.

Why this answer

The most likely cause is that the RADIUS server is not sending the dACL attributes in the Access-Accept message. For a downloadable ACL to be applied, the RADIUS server must include specific attributes (e.g., Cisco-AVPair with 'ip:inacl#<seq>=permit/deny...' or using IETF attributes like Filter-ID referencing a dACL name) in the Access-Accept. Without these attributes, the switch cannot apply the dACL, and the guest retains default access, which may include internal resources if no other ACL is in place.

Exam trap

The trap here is that candidates often assume the switch needs an explicit 'ip access-group' command to apply the dACL, but Cisco tests the understanding that dACLs are dynamically applied by the switch based on RADIUS attributes, not static interface configuration.

How to eliminate wrong answers

Option A is wrong because 'switchport mode trunk' does support dACLs on the native VLAN or when the port is in multi-domain mode; the issue is not about trunk mode blocking dACLs. Option B is wrong because if the guest is not authenticated and MAB is used instead, the switch would typically apply a default or MAB-specific ACL, but the scenario states the guest authenticates, and the problem is that the dACL is not applied, not that authentication failed. Option C is wrong because dACLs are applied dynamically by the switch upon receiving the RADIUS attributes; there is no need to manually configure an 'ip access-group' on the interface—the switch installs the dACL automatically as a per-user ACL.

Page 22

Page 23 of 26

Page 24