Courseiva

ENCOR 350-401 (350-401) — Questions 1726–1800

1923 questions total · 26pages · All types, answers revealed

Page 23

Page 24 of 26

Page 25
1726
MCQeasy

A company is consolidating branch servers onto a single physical host running a hypervisor. The administrator needs each virtual machine to have its own virtual NIC with an independent MAC address and to be isolated at Layer 2 from other virtual machines unless explicitly connected to the same virtual switch. Which component provides this function?

A.The hypervisor's virtual machine monitor alone
B.The physical top-of-rack switch
C.The virtual switch inside the hypervisor
D.A VLAN trunk configured on the physical NIC
AnswerC

A virtual switch connects virtual NICs within the hypervisor and forwards frames between them based on MAC addresses, giving each virtual machine its own vNIC and MAC. Virtual machines placed on different virtual switches or port groups remain isolated unless an uplink or explicit connection joins them, matching the requirement.

Why this answer

The virtual switch is the hypervisor component that gives each virtual machine a virtual NIC and forwards frames between them, enforcing isolation between port groups unless they are connected. The physical switch and trunk only carry traffic once it leaves the host, and the virtual machine monitor handles resource scheduling rather than Layer 2 forwarding.

Exam trap

The trap here is assuming the physical switch enforces isolation between virtual machines that live on the same hypervisor host.

1727
MCQmedium

Examine the following configuration: interface Port-channel1 switchport mode trunk ! interface GigabitEthernet0/1 switchport mode trunk channel-group 1 mode desirable ! interface GigabitEthernet0/2 switchport mode access channel-group 1 mode desirable What is the problem with this configuration?

A.The channel-group mode desirable is incompatible with trunk ports.
B.The port-channel interface must also be configured as access to match Gi0/2.
C.The switchport mode mismatch between Gi0/1 (trunk) and Gi0/2 (access) will prevent the EtherChannel from forming.
D.The EtherChannel will form but only Gi0/1 will be active.
AnswerC

All physical ports in a Layer 2 EtherChannel must have identical switchport characteristics, including the switchport mode. Because Gi0/1 is configured as trunk and Gi0/2 as access, the ports fail the EtherChannel consistency check, so PAgP/LACP will not place both ports into a working bundle. Correcting the mode on both members to either trunk or access is mandatory before the port-channel interface can become operational.

Why this answer

EtherChannel requires all member interfaces to have identical switchport modes (all trunk or all access). In this configuration, GigabitEthernet0/1 is configured as a trunk port while GigabitEthernet0/2 is configured as an access port. This switchport mode mismatch violates the EtherChannel consistency checks, preventing the logical bundle from forming.

Cisco switches enforce this rule to ensure consistent VLAN tagging behavior across all links in the bundle.

Exam trap

Cisco often tests the requirement that all EtherChannel member interfaces must have identical switchport modes (all trunk or all access), and candidates mistakenly think that the port-channel interface configuration overrides individual port settings or that the channel can form with mismatched modes.

How to eliminate wrong answers

Option A is wrong because the channel-group mode desirable is fully compatible with trunk ports; PAgP (Port Aggregation Protocol) operates at Layer 2 and supports both trunk and access ports. Option B is wrong because the port-channel interface does not need to be configured as access; instead, all physical member ports must have matching switchport modes, and the port-channel interface inherits its mode from the first member port added or can be manually configured to match. Option D is wrong because the EtherChannel will not form at all due to the switchport mode mismatch; Cisco switches perform consistency checks before forming the bundle, and a mode mismatch causes all ports to remain as individual interfaces rather than allowing only one to be active.

1728
MCQmedium

Examine the following HSRP configuration on a Cisco IOS-XE switch: interface Vlan10 ip address 10.0.0.2 255.255.255.0 standby 10 ip 10.0.0.1 standby 10 priority 150 standby 10 preempt What is the effect of the 'standby 10 preempt' command?

A.The router will immediately become the active router if it has a higher priority than the current active.
B.The router will become active only if the current active fails.
C.The router will send a gratuitous ARP to update the virtual MAC address.
D.The router will lower its priority to avoid becoming active.
AnswerA

Preempt lets this switch seize the active role once its priority exceeds the current active router's, rather than waiting passively. With priority 150 configured, it reclaims the virtual IP 10.0.0.1 after recovering from a failure, satisfying the requirement to restore the preferred gateway automatically.

Why this answer

The 'standby 10 preempt' command enables preemption, allowing the router to take over as the active router if it has a higher priority than the current active router. Without preempt, a router with higher priority will not become active until the current active fails. With preempt, it will immediately become active if its priority is higher.

Exam trap

350-401 often tests the difference between HSRP with and without preempt; candidates may forget that preempt is required for a higher-priority router to take over an already active lower-priority router.

How to eliminate wrong answers

Option B is wrong because that describes the behavior without preempt; with preempt, the router can become active even if the current active is still operational, provided it has higher priority. Option C is wrong because gratuitous ARP is sent by the active router when it takes over, but it is not the effect of the preempt command itself; preempt triggers the takeover, which then causes a gratuitous ARP. Option D is wrong because preempt does not lower priority; it allows a higher-priority router to take over.

1729
MCQeasy

A network engineer is troubleshooting an automated configuration change that caused a routing loop. The change was pushed via an Ansible playbook that modified OSPF cost values on multiple routers simultaneously. What is the most likely reason for the loop?

A.OSPF does not support changing costs on multiple routers at the same time
B.OSPF uses hop count as a metric, and the changes caused a count-to-infinity issue
C.The changes were applied simultaneously without allowing OSPF to converge between updates
D.The OSPF cost values were changed to non-standard values that OSPF cannot process
AnswerC

When OSPF cost changes are deployed simultaneously across multiple routers without a convergence interval, each router temporarily holds a different version of the link-state database (LSDB). This inconsistency causes the Shortest Path First (SPF) calculations on different routers to produce divergent, potentially looping paths until LSAs are fully flooded and SPF re-runs on all nodes. The correct practice is to stage changes incrementally, allowing each LSA to propagate and the SPF recalculation to complete before the next cost modification is applied.

Why this answer

Applying OSPF cost changes simultaneously on multiple routers without allowing convergence between updates can cause transient routing loops. OSPF relies on the SPF algorithm to calculate loop-free paths based on consistent link-state databases across the network. When costs are changed on multiple routers at once, some routers may have outdated LSAs, leading to inconsistent forwarding tables and temporary loops until all routers reconverge.

Exam trap

Cisco often tests the misconception that OSPF can handle simultaneous changes without issue, but the trap here is that candidates overlook the need for convergence between updates, confusing protocol capability with operational best practices.

How to eliminate wrong answers

Option A is wrong because OSPF fully supports changing costs on multiple routers simultaneously; the issue is not a protocol limitation but the lack of convergence between updates. Option B is wrong because OSPF uses cost (based on bandwidth) as its metric, not hop count; hop count is used by RIP, and count-to-infinity is a RIP-specific problem. Option D is wrong because OSPF can process any positive integer cost value (1 to 65535) as defined in RFC 2328; non-standard values are not a cause of loops.

1730
MCQmedium

Which of the following is used by EIGRP to calculate the feasible distance (FD) of a route?

A.The sum of the advertised distance (AD) of the successor and the link cost to the successor.
B.The lowest hop count among all paths to the destination.
C.The highest bandwidth among all paths to the destination.
D.The sum of all delays along the path.
AnswerA

The feasible distance (FD) is the best metric to a destination in EIGRP, computed by taking the metric reported by the next-hop router (the advertised distance, or AD) and adding the local link cost to that next hop. This sum yields the total end-to-end metric from the local router to the destination via the successor. The successor is chosen precisely because it minimizes this composite value, making the FD the definitive metric for route selection and for verifying loop-free paths in DUAL.

Why this answer

EIGRP calculates the Feasible Distance (FD) as the sum of the Advertised Distance (AD) from the successor neighbor and the link cost (metric) to that neighbor. This represents the total metric from the local router to the destination network via that path. The FD is used to determine the best route (successor) and to compare against feasible successors.

Exam trap

Cisco often tests the distinction between Feasible Distance (FD) and Advertised Distance (AD), and the trap here is that candidates confuse FD with just the link cost or one metric component (like delay or bandwidth), rather than recognizing it as the sum of the AD and the cost to the successor.

How to eliminate wrong answers

Option B is wrong because EIGRP does not use hop count for metric calculation; it uses a composite metric based on bandwidth, delay, load, and reliability (by default bandwidth and delay). Option C is wrong because while bandwidth is a component of the EIGRP metric, the FD is not simply the highest bandwidth; it is a calculated value using the composite metric formula. Option D is wrong because delay is only one component of the EIGRP metric, and the FD is not the sum of all delays along the path; it is the sum of the AD and the link cost, which itself is derived from the composite metric.

1731
MCQmedium

Examine the following CoPP configuration on a Cisco IOS-XE router: ``` class-map match-all CONTROL-PLANE match access-group name COPP-ACL ! policy-map COPP-POLICY class CONTROL-PLANE police 1000000 200000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP-POLICY ``` What is the effect of this configuration?

A.Traffic matching the ACL is rate-limited to 1 Mbps; traffic exceeding the rate is dropped.
B.All control plane traffic is rate-limited to 1 Mbps.
C.Traffic exceeding 1 Mbps is marked down but still transmitted.
D.The policy-map is applied to the data plane, not the control plane.
AnswerA

This answer is correct because the class-map references an access control list (ACL) that selects specific control-plane traffic, and the police command in the policy-map enforces a committed information rate (CIR) of 1 Mbps. When a packet matches the ACL, it is evaluated by the token bucket; conforming traffic is transmitted, while non-conforming (excess) traffic is dropped due to the configured exceed-action drop. This rate limiting is therefore applied narrowly to only the ACL-matched subset of control-plane traffic, not to all traffic or any other class.

Why this answer

The CoPP configuration uses a `police` command with a committed information rate (CIR) of 1,000,000 bits per second (1 Mbps) and a burst size of 200,000 bytes. Traffic that matches the class-map (via the named ACL) is subject to this policer; conforming traffic is transmitted, while exceeding traffic is dropped. This effectively rate-limits the matched control-plane traffic to 1 Mbps.

Exam trap

Cisco often tests the distinction between matching all control-plane traffic versus matching only traffic that hits a specific ACL, and candidates mistakenly assume the class-map applies to all control-plane traffic without reading the `match access-group` line.

How to eliminate wrong answers

Option B is wrong because the class-map uses `match-all CONTROL-PLANE` with an access-group named `COPP-ACL`, so only traffic matching that specific ACL is rate-limited, not all control-plane traffic. Option C is wrong because the `police` command specifies `conform-action transmit exceed-action drop`, meaning exceeding traffic is dropped, not marked down or transmitted. Option D is wrong because the `service-policy input COPP-POLICY` is applied under the `control-plane` configuration mode, which explicitly applies the policy to the control plane, not the data plane.

1732
MCQmedium

Given this configuration: aaa new-model aaa authentication login default group radius aaa authorization exec default group radius aaa accounting exec default start-stop group radius radius-server host 192.168.1.1 auth-port 1645 acct-port 1646 key radiuskey radius-server host 192.168.1.2 auth-port 1645 acct-port 1646 key radiuskey Which statement is true about the RADIUS server ports?

A.The RADIUS authentication port is 1645 and accounting port is 1646.
B.The RADIUS authentication port is 1812 and accounting port is 1813.
C.The RADIUS authentication port is 1646 and accounting port is 1645.
D.The RADIUS ports are not configurable; this command will be rejected.
AnswerA

This answer is correct. The command's 'auth-port 1645' and 'acct-port 1646' keywords explicitly set the RADIUS authentication and accounting UDP ports, respectively. These non-default ports are commonly associated with legacy RADIUS implementations and are fully supported by Cisco IOS. By specifying these values, the device will send RADIUS packets to UDP 1645 for authentication and UDP 1646 for accounting, overriding the IANA defaults of 1812 and 1813.

Why this answer

The configuration explicitly sets the RADIUS authentication port to 1645 and the accounting port to 1646 using the `auth-port 1645` and `acct-port 1646` keywords in the `radius-server host` commands. These are the legacy RADIUS ports (as defined in RFC 2138/2139), which Cisco devices support by default when ports are not specified, but here they are explicitly configured.

Exam trap

Cisco often tests the distinction between legacy (1645/1646) and standard (1812/1813) RADIUS ports, and the trap here is that candidates assume the default standard ports are always used, ignoring the explicit port configuration in the command.

How to eliminate wrong answers

Option B is wrong because ports 1812 (authentication) and 1813 (accounting) are the IANA-assigned standard ports per RFC 2865/2866, but the configuration explicitly overrides them with 1645 and 1646. Option C is wrong because it swaps the ports: 1646 is the accounting port, not authentication, and 1645 is the authentication port, not accounting. Option D is wrong because RADIUS ports are fully configurable on Cisco IOS using the `auth-port` and `acct-port` keywords; the command will not be rejected.

1733
MCQmedium

A network architect at a large university is designing a new campus network that must support seamless roaming for thousands of wireless clients across multiple buildings. The design requires a centralized control plane with a distributed data plane to avoid traffic tromboning. Which Cisco architecture should the architect implement?

A.Cisco Digital Network Architecture (DNA) Center with traditional campus switching
B.Cisco Application Centric Infrastructure (ACI) with spine-leaf topology
C.Cisco Software-Defined WAN (SD-WAN) with vManage and vSmart controllers
D.Cisco SD-Access with fabric-enabled switches and a fabric controller
AnswerD

Cisco SD-Access uses a fabric with a centralized control plane (LISP) and distributed data plane (VXLAN), enabling seamless mobility and preventing traffic tromboning by allowing edge nodes to forward traffic directly. This matches the requirement for centralized control and distributed data plane.

Why this answer

Cisco SD-Access fabric provides a centralized control plane using LISP and a distributed data plane using VXLAN, which enables seamless roaming and avoids traffic tromboning by allowing edge nodes to forward traffic directly. This architecture is specifically designed for campus networks requiring mobility and scalability.

Exam trap

The trap here is confusing SD-Access with SD-WAN, as both are Cisco SDN solutions but target different network domains.

1734
MCQmedium

A network engineer at a large enterprise is deploying a new branch office. The branch has two Cisco Catalyst switches, SW1 and SW2, that must participate in the same Layer 2 domain. SW1 is configured as the VTP server with domain 'CORP' and version 2. SW2 is a new switch with a higher VTP revision number and the same domain and password, but it has an empty VLAN database. The engineer connects SW2 to SW1 via a trunk link. What will happen to the VLAN database on SW1?

A.SW1 will not synchronize because VTP version 2 requires the same configuration revision number.
B.SW1 will overwrite SW2's VLAN database because SW1 is the VTP server.
C.SW1 will synchronize its VLAN database to SW2's database, potentially deleting VLANs.
D.SW1 will reject SW2's advertisement because SW2 is not a VTP server.
AnswerC

VTP uses the highest revision number within the same domain and password to determine which database is most current. SW2 has a higher revision number, so SW1 will accept SW2's advertisement and overwrite its own VLAN database with SW2's, which is empty. This can wipe out all VLANs on SW1 and disrupt the network.

Why this answer

VTP uses the configuration revision number to determine which switch has the most recent VLAN database. When SW2 with a higher revision number connects, SW1 accepts SW2's advertisement and replaces its own VLAN database, even though SW1 is the server. This can cause VLANs to be deleted, so it is critical to reset the revision number on new switches before connecting them to the production network.

Exam trap

The trap here is assuming that a VTP server will always overwrite clients; in reality, the highest revision number wins regardless of server or client role.

1735
MCQmedium

A network engineer is deploying a Cisco Nexus 9000 leaf switch in a VXLAN EVPN fabric. The underlay uses OSPF for loopback reachability, and the engineer must now enable the control plane that carries MAC and IP address reachability information for the overlay. Which technology must be enabled on the leaf switch to distribute this overlay reachability information?

A.LISP with a Map-Server and Map-Resolver
B.OSPFv3 with the IPv6 unicast address family
C.MP-BGP with the Layer 2 EVPN address family
D.PIM sparse mode with an Anycast-RP
AnswerC

EVPN uses MP-BGP with the L2VPN EVPN address family to advertise MAC addresses, IP-to-MAC bindings, and VTEP reachability in a VXLAN fabric. Enabling this address family in the leaf's BGP configuration lets the switch exchange Type 2 and Type 3 routes with the spine route reflectors, which is exactly the overlay control plane required here.

Why this answer

In a VXLAN EVPN fabric, the underlay (here OSPF) provides loopback-to-loopback reachability between VTEPs, while the overlay control plane is MP-BGP with the L2VPN EVPN address family. Enabling that address family allows the leaf to advertise MAC and IP address routes and VTEP membership through the spine route reflectors, replacing flood-and-learn with a scalable, standards-based control plane.

Exam trap

The trap here is assuming the routing protocol that provides underlay loopback reachability also carries overlay MAC and IP reachability information.

1736
MCQmedium

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 192.168.1.0 BGP routing table entry for 192.168.1.0/24, version 10 Paths: (2 available, best #2, table default) Advertised to update-groups: 1 Refresh Epoch 1 Local 10.0.0.2 from 10.0.1.2 (10.0.0.2) Origin IGP, metric 0, localpref 100, valid, internal rx pathid: 0, tx pathid: 0x0 Local, (received & used) 10.0.0.3 from 10.0.1.3 (10.0.0.3) Origin IGP, metric 0, localpref 200, valid, internal, best rx pathid: 0, tx pathid: 0x0 Based on this output, what can be concluded?

A.The path from 10.0.1.2 is the best path because it is received first.
B.The path from 10.0.1.3 is preferred because of a higher local preference.
C.Both paths are from external BGP peers.
D.The path from 10.0.1.2 is marked as best because it has a lower metric.
AnswerB

The correct selection is the path from 10.0.1.3 because it carries a local preference value of 200, which is higher than the 100 on the path from 10.0.1.2. Local preference is a well-known discretionary attribute that is advertised to iBGP peers and is the first major criterion compared after weight, so a higher value directly makes this route more preferred for outbound traffic. Thus, even if the other path came from a more specific or more attractive metric, the local preference overrides those later attributes.

Why this answer

The output shows two BGP paths for 192.168.1.0/24, both with Origin IGP and metric 0. The path from 10.0.1.3 has a local preference of 200, while the path from 10.0.1.2 has a local preference of 100. BGP selects the path with the highest local preference as the best path, making the path from 10.0.1.3 the best (marked as 'best' in the output).

Exam trap

Cisco often tests the BGP best path selection order, and the trap here is that candidates may confuse local preference with MED or assume that the first received route is preferred, when in fact local preference is evaluated much earlier in the decision process.

How to eliminate wrong answers

Option A is wrong because BGP does not select the best path based on which route is received first; it uses a deterministic decision process where local preference is evaluated before arrival order. Option C is wrong because both paths are marked as 'internal' (iBGP), not external (eBGP), as indicated by the 'internal' keyword in the path attributes. Option D is wrong because both paths have the same metric (0), and BGP does not use metric (MED) as a tiebreaker before local preference; the higher local preference of 200 on the path from 10.0.1.3 is the decisive factor.

1737
MCQmedium

A network administrator is configuring a Cisco IOS-XE router to support virtual routing and forwarding (VRF) for a customer. The administrator wants to ensure that traffic from the customer's VRF can reach the internet through a global routing table. Which feature should be configured to allow communication between the VRF and the global routing table?

A.VXLAN EVPN
B.VRF-aware NAT
C.MPLS Layer 3 VPN
D.Route leaking
AnswerD

Route leaking is the process of importing routes from one VRF into another, including the global routing table. By configuring route targets or using static routes with the global keyword, you can leak routes between a VRF and the global table. This allows traffic from the VRF to be routed to the internet via the global table, provided that the global table has a route to the destination.

Why this answer

Route leaking allows routes to be exchanged between VRFs, including the global routing table. By configuring route leaking, you can import routes from the global table into the VRF and export routes from the VRF to the global table. This enables communication between the VRF and the global table, allowing traffic to reach the internet.

Other features like NAT or MPLS L3VPN do not provide this local routing capability.

Exam trap

The trap here is thinking that NAT alone can connect a VRF to the global table; NAT translates addresses but does not provide the necessary routing information.

1738
MCQmedium

Consider the following configuration on a Cisco IOS-XE router: ip multicast-routing ! interface GigabitEthernet0/0 ip address 10.0.0.1 255.255.255.0 ip pim sparse-mode ip igmp static-group 239.1.1.1 ! What is the effect of the 'ip igmp static-group 239.1.1.1' command?

A.The router will send IGMP membership reports for group 239.1.1.1 out of this interface.
B.The router will include this interface in the outgoing interface list for group 239.1.1.1, even without any IGMP hosts.
C.The router will drop all multicast traffic for group 239.1.1.1 on this interface.
D.The router will create a static multicast route for 239.1.1.1 via this interface.
AnswerB

This command statically populates the IGMP group membership table for group 239.1.1.1 on this interface. As a result, the multicast routing process treats the interface as having a group member and adds it to the outgoing interface list (OIL) for that group in the multicast route entry. Even if no IGMP hosts ever send reports on this segment, multicast packets for the group are still forwarded out of the interface. This is a standard way to simulate a receiver for testing or to guarantee delivery to a network that lacks IGMP-capable hosts.

Why this answer

The 'ip igmp static-group 239.1.1.1' command configures the router to include the interface in the outgoing interface list (OIL) for the multicast group 239.1.1.1, regardless of whether any IGMP hosts are present on that subnet. This is used to forward multicast traffic for that group out of the interface as if a host had joined, without relying on dynamic IGMP membership reports.

Exam trap

Cisco often tests the distinction between 'ip igmp static-group' (which adds the interface to the OIL) and 'ip igmp join-group' (which causes the router to act as a host and send IGMP reports), leading candidates to confuse the two commands.

How to eliminate wrong answers

Option A is wrong because the router does not send IGMP membership reports; it listens for them from hosts, and the static-group command simulates a local member without generating reports. Option C is wrong because the command does not drop traffic; it ensures the interface is added to the OIL, forwarding traffic for the group. Option D is wrong because the command does not create a static multicast route (which would be done with 'ip mroute'); it only affects IGMP group membership on the interface.

1739
Multi-Selecthard

Which three statements about Multiple Spanning Tree Protocol (MSTP) are true? (Choose three.)

Select 3 answers
A.MSTP allows multiple VLANs to be grouped into a single spanning-tree instance, reducing CPU and memory usage.
B.In MSTP, the Internal Spanning Tree (IST) instance is instance 0 and is always present in every MST region.
C.MSTP requires that all switches in the same MST region have the same VLAN-to-instance mapping, revision number, and region name.
D.MSTP automatically load-balances traffic across all available uplinks without any configuration.
E.MSTP requires a separate root bridge to be elected for each VLAN in the network.
AnswersA, B, C

MSTP maps many VLANs onto a shared instance, so a single spanning-tree computation serves them all. That collapses per-VLAN STP processing into fewer instances, directly cutting CPU and memory load compared with PVST+ running one tree per VLAN.

Why this answer

MSTP (IEEE 802.1s) allows multiple VLANs to be mapped to a single spanning-tree instance (MST instance), reducing the number of STP instances needed. It uses an Internal Spanning Tree (IST) instance (instance 0) that always runs and carries BPDUs for the region. Switches in the same MST region must have identical VLAN-to-instance mappings, revision number, and region name.

MSTP interoperates with Rapid PVST+ at region boundaries by using PVST simulation mode. MSTP does not require a separate root bridge for each VLAN; instead, each MST instance has its own root bridge.

1740
MCQeasy

An engineer notices that syslog messages from a Cisco router are not timestamped correctly. The router is configured with 'service timestamps log datetime msec' and 'logging host 10.1.1.1'. The syslog server shows messages with the correct time but the local logs on the router show incorrect timestamps. What is the most likely cause?

A.The 'service timestamps log datetime msec' command is not supported on this platform.
B.The router's system clock is not synchronized via NTP or manual setting.
C.The syslog server is overwriting the timestamps.
D.The 'logging host' command must include the 'transport tcp' option.
AnswerB

Syslog messages generated on the router itself are stamped with the router's system clock before being written to local logs. If the clock is not synchronized via NTP or has not been manually set correctly, every log entry will carry the wrong date and time. This directly matches the symptom of incorrect local log timestamps, making it the correct root cause.

Why this answer

The 'service timestamps log datetime msec' command tells the router to include a timestamp in syslog messages, but the timestamp is derived from the router's system clock. If the clock is not synchronized via NTP or manually set, the local logs will show incorrect timestamps. The syslog server, however, receives the messages and applies its own timestamp upon receipt, which is why the server shows the correct time.

Therefore, the mismatch is caused by the router's unsynchronized clock.

Exam trap

Cisco often tests the distinction between the router's local timestamp (which depends on its clock) and the syslog server's receipt timestamp, leading candidates to mistakenly think the server overwrites the timestamp or that the command is unsupported.

How to eliminate wrong answers

Option A is wrong because 'service timestamps log datetime msec' is widely supported on Cisco IOS and IOS-XE platforms; it is a standard feature for adding millisecond-precision timestamps to syslog messages. Option C is wrong because the syslog server does not overwrite the timestamps embedded by the router; it typically records the time of receipt separately, and the router's timestamp is included in the message body. Option D is wrong because the 'logging host' command with TCP transport is used for reliable delivery, not for timestamp accuracy; timestamps are unaffected by the transport protocol.

1741
Matchingmedium

Drag and drop each PIM message type on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Discovers PIM neighbors and maintains adjacency

Requests to receive multicast traffic for a specific group (or S,G)

Requests to stop receiving multicast traffic for a specific group (or S,G)

Resolves which PIM router forwards multicast traffic on a multi-access network

Distributes RP information in PIM Sparse Mode

Why these pairings

PIM Hello discovers neighbors and maintains adjacency; Join is used to join a multicast tree; Prune is used to leave a tree; Assert resolves duplicate forwarding on a multi-access network; Bootstrap messages are used in PIM SM to distribute RP information.

1742
MCQhard

A network administrator is implementing VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. The fabric has two border nodes and four edge nodes. The administrator wants to ensure that traffic from a wired endpoint in VLAN 10 can reach a wireless endpoint in the same VLAN that is roaming between access points. Which component is responsible for mapping the endpoint's IP address to its location in the fabric?

A.The fabric intermediate node acts as a LISP proxy ETR to provide the mapping.
B.The fabric edge node caches the mapping and shares it directly with other edge nodes via LISP pub-sub.
C.The fabric border node performs the mapping using the LISP map-server function.
D.The fabric control plane node maintains the mapping in its LISP map-server database.
AnswerD

In Cisco SD-Access, the control plane node runs the LISP map-server and map-resolver functions. It maintains the endpoint-to-location mappings in its database. When an edge node needs to resolve an endpoint's location, it queries the control plane node, which returns the RLOC (routing locator) of the edge node where the endpoint is attached.

Why this answer

In Cisco SD-Access, the control plane node hosts the LISP map-server and map-resolver, maintaining the database of endpoint-to-RLOC mappings. Edge nodes register endpoints and query the control plane to resolve destinations. This centralized mapping enables seamless mobility and policy enforcement across the fabric.

Exam trap

The trap here is confusing the roles of border and control plane nodes, assuming the border node handles endpoint mapping when it actually handles external connectivity.

1743
MCQmedium

A network engineer runs the following command on Switch SW1: SW1# show dtp interface gi0/1 DTP information on GigabitEthernet0/1: DTP: Enabled DTP mode: Desirable DTP negotiate: TRUE DTP status: Trunk DTP trunk status: Trunking DTP timer: 30 DTP max-age: 2 DTP encapsulation: 802.1q DTP refresh rate: Both DTP requests: 10 DTP errors: 0 Based on this output, what can be concluded?

A.The interface is in access mode.
B.The interface will not form a trunk unless the neighbor is set to trunk or desirable.
C.The interface is using ISL encapsulation.
D.DTP is disabled on this interface.
AnswerB

DTP mode desirable actively sends DTP frames to form a trunk; it can form a trunk with a neighbor set to trunk, desirable, or auto.

Why this answer

The output shows DTP is enabled, mode is 'Desirable', and the interface is already trunking with 802.1q encapsulation. Option A is incorrect because the interface is trunking, not in access mode. Option B is incorrect because dynamic desirable can form a trunk with dynamic auto as well as trunk or desirable modes; the statement that it 'will not form a trunk unless the neighbor is set to trunk or desirable' is false.

Option C is incorrect because encapsulation is 802.1q, not ISL. Option D is incorrect because DTP is enabled. Since all provided options are incorrect, no correct conclusion can be selected from the given choices.

Exam trap

A common misconception is that dynamic desirable only forms a trunk with trunk or other desirable interfaces, but it can also form a trunk with dynamic auto. Additionally, the output indicates the link is already trunking, so statements about future trunk formation are not directly concluded.

How to eliminate wrong answers

Option A is wrong because the interface is in trunking state (DTP status: Trunking), not access mode. Option C is wrong because the output explicitly shows 'DTP encapsulation: 802.1q', not ISL. Option D is wrong because the output shows 'DTP: Enabled', so DTP is clearly enabled on this interface.

1744
Drag & Dropmedium

Drag and drop the steps of RADIUS CoA (Change of Authorization) message flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

RADIUS CoA allows a server to dynamically change a session's authorization. The server sends a CoA-Request to the network access server (NAS). The NAS acknowledges with CoA-ACK and applies the new policy.

If the session is affected, the NAS may send a disconnect or re-authenticate.

1745
MCQhard

A network administrator is configuring a VXLAN EVPN fabric. The administrator wants to optimize the forwarding of broadcast, unknown unicast, and multicast (BUM) traffic by using a multicast group per VLAN. Which VXLAN feature should be configured on the VTEPs to achieve this?

A.Multicast underlay with PIM Sparse Mode
B.Ingress replication
C.EVPN Integrated Routing and Bridging (IRB)
D.Anycast VTEP
AnswerA

In VXLAN, BUM traffic can be replicated using multicast in the underlay. By mapping each VLAN to a unique multicast group address, VTEPs can efficiently forward BUM traffic only to interested VTEPs. Configuring PIM Sparse Mode in the underlay enables this multicast replication. This approach optimizes BUM traffic by avoiding unicast head-end replication and leverages the underlay multicast capabilities.

Why this answer

Using a multicast underlay with PIM Sparse Mode allows each VLAN to be mapped to a unique multicast group, so BUM traffic is replicated only to VTEPs that have joined that group. This optimizes bandwidth and reduces unnecessary flooding. Ingress replication and anycast VTEP do not provide per-VLAN multicast group mapping.

EVPN IRB is for routing, not BUM optimization.

Exam trap

The trap here is assuming that any VXLAN feature like ingress replication or anycast VTEP can optimize BUM traffic, but only multicast underlay with PIM Sparse Mode supports per-VLAN multicast groups.

1746
Drag & Dropmedium

Drag and drop the steps of MPLS traffic engineering (MPLS-TE) tunnel setup into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, IGP must be configured with TE extensions (e.g., OSPF TE) to flood link attributes. Then MPLS-TE is enabled on interfaces. The headend router computes a path using CSPF based on constraints.

The tunnel interface is configured with the destination and constraints. Finally, RSVP-TE signals the LSP and reserves bandwidth along the path.

1747
MCQhard

A network engineer issues the following command on Router R7: R7# show ip pim tunnel Tunnel1: Type: PIM Encap Source: 10.0.0.7, Destination: 10.0.0.8 Status: up Based on this output, what can be concluded?

A.This tunnel is used for PIM register encapsulation to the RP.
B.This tunnel is used for MDT data group forwarding.
C.This tunnel is used for BSR messages.
D.This tunnel is used for Auto-RP announcements.
AnswerA

In Protocol Independent Multicast Sparse Mode (PIM-SM), when a source sends multicast traffic to a group with unknown or no downstream receivers, the first-hop router (FHR) encapsulates each original multicast packet into a unicast PIM Register message and sends it to the rendezvous point (RP). This tunnel interface, often named Tunnel0, serves as the virtual point-to-point link for that encapsulation, carrying the multicast payload inside unicast PIM packets. The RP decapsulates these messages, learns the source's existence, and then can join the shortest path tree toward the source.

Why this answer

The 'show ip pim tunnel' output displays a PIM Encap tunnel, which is automatically created by Cisco IOS to encapsulate multicast packets from a source that is outside the Rendezvous Point (RP) tree. The tunnel sends these encapsulated packets to the RP (10.0.0.8) using unicast PIM register messages, making option A correct.

Exam trap

Cisco often tests the distinction between PIM register encapsulation (used for source-to-RP communication) and other tunnel types like MDT or Auto-RP, leading candidates to confuse the purpose of the PIM Encap tunnel.

How to eliminate wrong answers

Option B is wrong because MDT (Multicast Distribution Tree) data group forwarding is used in MVPN (Multicast VPN) environments, not in standard PIM register tunnels shown here. Option C is wrong because BSR (Bootstrap Router) messages are flooded hop-by-hop using PIM, not through a PIM Encap tunnel. Option D is wrong because Auto-RP announcements are sent via multicast groups (224.0.1.39 and 224.0.1.40) and rely on PIM sparse-dense mode, not on a PIM Encap tunnel.

1748
MCQeasy

A network engineer runs the following command on Switch SW4: SW4# show spanning-tree vlan 40 VLAN0040 Spanning tree enabled protocol ieee Root ID Priority 24616 Address aabb.cc00.0600 Cost 8 Port 1 (GigabitEthernet0/1) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32768 (priority 32768 sys-id-ext 40) Address aabb.cc00.0700 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- ------------------------------ Gi0/1 Root FWD 8 128.1 P2p Gi0/2 Desg FWD 4 128.2 P2p Gi0/3 Desg FWD 4 128.3 P2p Based on this output, which port is the root port?

A.GigabitEthernet0/1
B.GigabitEthernet0/2
C.GigabitEthernet0/3
D.There is no root port because SW4 is the root bridge.
AnswerA

GigabitEthernet0/1 is the root port on SW4. In STP, a non-root bridge selects the single port that receives the best (lowest-cost) BPDU from the root bridge, and that port is assigned the Root role. Because the output shows Gi0/1 with role 'Root', it is the path toward the root bridge, even though SW4 itself is not the root bridge.

Why this answer

The root port is the port on a non-root bridge that provides the lowest-cost path to the root bridge. In the output, SW4 is not the root bridge because its Bridge ID (priority 32768 + VLAN 40) is higher than the Root ID priority 24616, and the Root Cost is 8 via Gi0/1. The 'Role' column shows Gi0/1 as 'Root' and its 'Sts' is 'FWD', confirming it is the root port.

Exam trap

Cisco often tests the distinction between the root port (on a non-root bridge) and the designated port (on a root bridge or segment), and candidates may mistakenly think a switch with a lower-cost port is the root bridge or that all forwarding ports are root ports.

How to eliminate wrong answers

Option B is wrong because Gi0/2 has a role of 'Desg' (designated), not 'Root', and its cost of 4 is lower than the root cost of 8, but that cost is for its own segment, not the path to the root. Option C is wrong because Gi0/3 also has a role of 'Desg' and is a designated port, not a root port. Option D is wrong because SW4 is not the root bridge; the Root ID priority 24616 differs from SW4's Bridge ID priority 32768 (with sys-id-ext 40), and the root cost of 8 indicates SW4 is downstream from the root bridge.

1749
MCQeasy

A network administrator is configuring a Cisco IOS router to protect the control plane from excessive CPU utilization caused by malicious traffic. The administrator wants to rate-limit specific types of traffic destined to the route processor while allowing all other traffic to pass without restriction. Which feature should be configured?

A.Policy-Based Routing
B.Management Plane Protection
C.Control Plane Policing
D.Control Plane Protection
AnswerC

Control Plane Policing (CoPP) uses a modular QoS CLI policy applied to the control plane interface to rate-limit or drop traffic destined to the route processor. It allows granular classification of traffic types such as routing protocols, management access, and ICMP, while permitting unmatched traffic to pass, which matches the requirement exactly.

Why this answer

Control Plane Policing applies a QoS policy to the control plane interface, allowing administrators to classify and rate-limit specific traffic types destined to the route processor while permitting other traffic. This directly addresses CPU protection from malicious floods without affecting transit traffic.

Exam trap

The trap here is confusing Control Plane Policing with Control Plane Protection, when CPPr is a granular extension and CoPP is the standard feature for rate-limiting control plane traffic.

1750
MCQhard

A network engineer is implementing Cisco SD-Access for a campus network. The fabric uses LISP for control plane and VXLAN for data plane. The engineer needs to ensure that endpoints in the same VLAN but on different fabric edge nodes can communicate. Which Cisco SD-Access component is responsible for mapping endpoint EIDs to RLOCs?

A.Fabric border node
B.Fabric edge node
C.Intermediate node
D.Control plane node
AnswerD

The control plane node in SD-Access runs LISP map-server and map-resolver functions. It maintains the mapping database of endpoint EIDs to RLOCs (fabric edge node locators). When an edge node needs to reach an endpoint, it queries the control plane node, which resolves the EID to the correct RLOC. This enables communication across fabric edge nodes.

Why this answer

In Cisco SD-Access, the control plane node provides LISP map-server and map-resolver services. It stores the EID-to-RLOC mappings for all endpoints registered by fabric edge nodes. When an edge node needs to send traffic to an endpoint on another edge node, it queries the control plane node to resolve the destination RLOC, enabling VXLAN encapsulation and forwarding.

This centralizes mapping and supports mobility.

Exam trap

The trap here is assuming that fabric edge nodes resolve EIDs locally; in reality, they query the control plane node for mappings.

1751
Multi-Selecteasy

Which three statements about SSL VPNs are true? (Choose three.)

Select 3 answers
A.SSL VPNs use the TLS protocol to encrypt traffic between client and server.
B.SSL VPNs require a pre-shared key for authentication.
C.Clientless SSL VPN access allows users to access web applications using only a browser.
D.SSL VPNs can only operate over TCP port 443.
E.SSL VPNs support port forwarding for non-web applications.
AnswersA, C, E

SSL VPNs operate over TLS, the successor to SSL, encrypting the session between client and server at the transport layer. This satisfies the stem's requirement for a true statement about SSL VPNs, since TLS provides the cryptographic tunnel without requiring IPsec or dedicated client software in clientless deployments.

Why this answer

Option A is correct because SSL VPNs fundamentally rely on the TLS (Transport Layer Security) protocol to provide encryption, integrity, and authentication for the tunnel between the client and the VPN gateway. Option C is correct because clientless SSL VPN mode requires only a standard web browser and typically provides access to web-based applications through a portal, without installing a dedicated client. Option E is correct because SSL VPN clients can support port forwarding, which redirects traffic from specific local TCP ports to resources behind the VPN gateway, enabling access to non-web applications.

Option B is not correct because SSL VPNs commonly authenticate users with certificates, usernames/passwords, or multi-factor methods; a pre-shared key is characteristic of IPsec VPNs, not a general SSL VPN requirement. Option D is not correct because although SSL VPNs commonly use TCP port 443, they are not limited to it and can be configured on other ports or use DTLS/UDP for performance.

Exam trap

The trap here is conflating SSL VPN authentication with IPsec's pre-shared key model, and assuming SSL VPNs are locked to TCP 443 when they actually support multiple ports and DTLS.

1752
MCQmedium

An engineer is troubleshooting a problem where a trunk link between two Cisco switches is not passing traffic for VLAN 10, but other VLANs are working. The trunk is configured with switchport mode trunk on both sides. The engineer checks the allowed VLAN list and sees VLAN 10 is included. The native VLAN is set to 1 on both sides. What is the most likely cause?

A.VLAN 10 is not created in the VLAN database on one of the switches.
B.VTP pruning has removed VLAN 10 from the trunk.
C.The native VLAN is mismatched.
D.Spanning Tree Protocol is blocking VLAN 10 on the trunk.
AnswerA

VLAN 10 must exist in the local VLAN database on both switches before traffic can cross an 802.1Q trunk. If one switch lacks VLAN 10, that switch will not forward tagged frames for that VLAN, even though the trunk interface is administratively up and the VLAN is in the allowed list. The switch will not create the VLAN dynamically unless VTP is in server mode and advertises it, so the missing database entry is the root cause.

Why this answer

The most likely cause is that VLAN 10 is not created in the VLAN database on one of the switches. Even if VLAN 10 is included in the allowed VLAN list on the trunk, a switch will not forward traffic for a VLAN that does not exist in its local VLAN database. The trunk interface will be operationally down for that specific VLAN, preventing traffic from passing.

Exam trap

Cisco often tests the distinction between a VLAN being allowed on a trunk and a VLAN being created in the VLAN database, leading candidates to focus on trunk configuration rather than verifying the VLAN's existence on both switches.

How to eliminate wrong answers

Option B is wrong because VTP pruning removes VLANs from the trunk only when no switch in the VTP domain has any active ports in that VLAN; if VLAN 10 is configured on the trunk and other VLANs work, VTP pruning is unlikely to be the issue. Option C is wrong because the native VLAN is set to 1 on both sides, so there is no mismatch; a native VLAN mismatch would cause issues for untagged traffic, not specifically for VLAN 10. Option D is wrong because Spanning Tree Protocol (STP) blocks per-VLAN on a per-interface basis only if there is a loop or port role change; STP would not block only VLAN 10 while allowing other VLANs unless VLAN 10 has a specific topology issue, but the question states other VLANs are working, making this less likely than a missing VLAN database entry.

1753
MCQhard

A network engineer is implementing VXLAN with a Cisco Nexus 9000 series switch acting as a VTEP. The underlay network is OSPF, and the overlay uses BGP EVPN. The engineer notices that VM traffic between two hosts on different VTEPs is not being encapsulated. Which action should be taken to ensure VXLAN traffic is properly encapsulated and forwarded?

A.Ensure that the underlay OSPF cost is equal on all links to allow ECMP for VXLAN traffic.
B.Configure a VRF for the overlay and redistribute the VRF routes into OSPF.
C.Enable VXLAN feature and configure the NVE interface with a source interface and a VNI mapping to the VLAN.
D.Configure a VXLAN tunnel interface with the source interface as the loopback0 and the destination as the remote VTEP's loopback0.
AnswerC

To enable VXLAN encapsulation, the `feature nv overlay` and `feature vn-segment-vlan-based` must be enabled, and an NVE interface must be configured with a source interface (usually a loopback) and a VNI mapped to the VLAN. The NVE interface is the VTEP, and without it, VXLAN encapsulation does not occur.

Why this answer

VXLAN encapsulation requires the NVE interface to be configured with a source interface and VNI-to-VLAN mapping. Enabling the VXLAN features and configuring the NVE interface are essential steps. Without these, the switch will not encapsulate traffic, even if the underlay and overlay routing are correct.

Exam trap

The trap here is confusing underlay routing issues with overlay encapsulation; the lack of encapsulation is due to missing NVE configuration, not OSPF or BGP.

1754
MCQmedium

Given the following configuration snippet on a Cisco 9800 WLC: wireless profile policy test-policy no security ft aaa-override no mac-filtering no wlan-switch central-switching What is the effect of this configuration?

A.Client traffic is locally switched at the AP.
B.Client traffic is centrally switched through the WLC.
C.Fast roaming (802.11r) is enabled for this policy.
D.MAC filtering is enabled for client authentication.
AnswerB

When the 'central-switching' command is present, the AP encapsulates all client 802.11 frames in CAPWAP and sends them to the WLC for forwarding at the network layer. This central switching model places the WLC in the data path for all client traffic, which is exactly the behavior described in this correct option. Therefore, client traffic flows through the WLC rather than being bridged at the access point.

Why this answer

The `central-switching` command in the wireless profile policy forces all client traffic to be tunneled back to the WLC for processing, rather than being bridged locally at the AP. This is the definition of central switching, making option B correct. The `no wlan-switch` command further confirms that local switching is disabled.

Exam trap

Cisco often tests the confusion between `central-switching` and `local-switching`, where candidates mistakenly think `central-switching` means traffic is switched at the AP, or they overlook that `no wlan-switch` explicitly disables local switching.

How to eliminate wrong answers

Option A is wrong because `central-switching` explicitly directs traffic to the WLC, not the AP; local switching would require `wlan-switch` or `local-switching` commands. Option C is wrong because `no security ft` disables Fast Transition (802.11r), not enables it; FT is controlled by the `security ft` command. Option D is wrong because `no mac-filtering` explicitly disables MAC filtering, not enables it.

1755
Matchingmedium

Drag and drop each QoS model on the left to its matching characteristic on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Uses RSVP to signal per-flow reservations; Requires per-flow state in every router

Classifies traffic using DSCP markings; Scales well for large enterprise networks

No guarantees for delivery or delay

Why these pairings

IntServ uses RSVP for per-flow signaling, DiffServ uses DSCP marking for per-hop behavior, Best Effort provides no guarantees, IntServ requires state in routers, and DiffServ scales well for large networks.

1756
MCQhard

A network engineer is using Ansible to push ACL changes to a group of Cisco IOS routers. The playbook uses the ios_acl_interfaces module to bind ACLs to interfaces. After running the playbook, the engineer notices that some routers have the ACL applied inbound instead of outbound as intended. The playbook specifies 'direction: outbound'. What is the most likely cause of this issue?

A.The routers have a different IOS version that interprets 'outbound' as 'in'.
B.The playbook uses 'direction: outbound' but the module expects 'direction: out'.
C.The engineer forgot to include the 'state: present' parameter, so the module did not apply the ACL.
D.The ACL itself is defined with the wrong direction in the playbook.
AnswerB

This is the root cause: `ios_acl_interfaces` requires `direction` to be literally `in` or `out`, and `outbound` is not a valid enum value. If the module does not immediately raise an argument-spec error, it may silently fall back to the default direction, which is `in`, thereby applying the ACL to inbound traffic. The observed behavior matches exactly: the ACL is active but filtering the wrong direction. Correcting the value to `out` would produce the intended outbound traffic filtering.

Why this answer

The ios_acl_interfaces module in Ansible expects the direction parameter to be specified as 'in' or 'out', not 'outbound'. When 'direction: outbound' is used, the module either ignores the value or defaults to 'in', causing the ACL to be applied inbound instead of outbound. This is a common parameter naming mismatch between the Ansible module and the engineer's expectation.

Exam trap

The trap here is that candidates assume Ansible modules accept human-readable keywords like 'outbound' or 'inbound', but Cisco modules strictly require the exact CLI syntax ('in' or 'out'), and any deviation results in silent misconfiguration.

How to eliminate wrong answers

Option A is wrong because IOS does not interpret 'outbound' as 'in'; the direction keywords in Cisco IOS are 'in' and 'out', and 'outbound' is not a valid keyword. Option C is wrong because the 'state: present' parameter is not required for the ios_acl_interfaces module to apply an ACL; the module applies the ACL based on the configuration provided, and omitting 'state' does not change the direction. Option D is wrong because the ACL definition itself does not include a direction; direction is specified separately in the interface binding, not within the ACL entries.

1757
Drag & Dropmedium

Drag and drop the steps of DNA Center template deployment to a device into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Template deployment starts with creating the template, then associating it with a site, committing the changes, deploying to the target device, and verifying the deployment.

1758
MCQeasy

A network engineer configures SNMPv2c on a Cisco switch to send traps to an NMS. The engineer uses 'snmp-server community public RO' and 'snmp-server host 10.1.1.1 version 2c public'. The NMS receives traps, but the engineer notices that the traps contain the IP address of the management interface (VLAN 1) instead of the loopback interface (Loopback0) that is used for management. The engineer wants the traps to use the loopback IP as the source. What should the engineer do?

A.Configure 'snmp-server source-interface traps Loopback0'.
B.Configure 'snmp-server trap-source Loopback0'.
C.Configure 'ip snmp source-interface Loopback0'.
D.Change the management interface IP to match the loopback.
AnswerB

This is the correct global configuration command for setting the source IP of SNMP traps. It instructs the router or switch to use the IP address of Loopback0 as the source address in the IP header of every trap (and inform) packet. Because a loopback interface is always reachable and never goes down, unlike a physical interface, this ensures the NMS sees a stable, predictable source IP, which is especially useful for filtering and device identification.

Why this answer

The correct command to set the source IP address for SNMP traps on a Cisco device is 'snmp-server trap-source Loopback0'. This command forces all SNMP trap messages to use the IP address of the specified interface as the source, regardless of which interface they exit. Option B is correct because it directly configures the trap source to the loopback interface, ensuring the NMS sees the loopback IP instead of the VLAN 1 management IP.

Exam trap

Cisco often tests the exact command syntax for SNMP source interface configuration, and candidates frequently confuse 'snmp-server trap-source' with the incorrect 'snmp-server source-interface traps' or 'ip snmp source-interface'.

How to eliminate wrong answers

Option A is wrong because 'snmp-server source-interface traps Loopback0' is not a valid Cisco IOS command; the correct syntax uses 'trap-source' not 'source-interface'. Option C is wrong because 'ip snmp source-interface Loopback0' is not a valid command; SNMP source interface configuration is done under the 'snmp-server' global configuration mode. Option D is wrong because changing the management interface IP to match the loopback is unnecessary and would cause IP address duplication; the proper solution is to configure the trap source interface.

1759
MCQhard

A network engineer runs the following command on Switch SW8: SW8# show etherchannel 2 detail | include "Port state|Port: Gi|Partner" Port: Gi0/0 Port state = Up, In-Bundle Port: Gi0/1 Port state = Up, In-Bundle Port: Gi0/2 Port state = Down, Not-In-Bundle Partner information: Gi0/0: Partner state = bndl Gi0/1: Partner state = bndl Gi0/2: Partner state = down Based on this output, what can be concluded?

A.All three ports are bundled and forwarding traffic.
B.Gi0/2 is not bundled because the partner is in 'down' state, indicating a physical layer issue.
C.The EtherChannel is using PAgP because the partner state shows 'bndl'.
D.Gi0/2 is in standby mode waiting to become active.
AnswerB

EtherChannel formation requires that both the local and partner ports be in an 'up' state; in the output, Gi0/2 shows both local and partner states as 'down', which is the classic symptom of a physical-layer failure—e.g., a bad cable, unplugged fiber, or administratively down interface. Since the partner cannot receive or transmit LACP/PAgP PDUs, the negotiation fails and the port is not added to the bundle. Thus, the root cause is a Layer 1 problem, not a configuration mismatch.

Why this answer

The output shows that Gi0/2 is in 'Down, Not-In-Bundle' state and its partner state is 'down', which indicates a physical layer issue such as a bad cable, disabled port, or misconfiguration on the remote side. Since the port is down, it cannot participate in the EtherChannel bundle, confirming that only Gi0/0 and Gi0/1 are active and forwarding traffic.

Exam trap

The trap here is that candidates assume 'Down' means the port is in a standby or backup role, but in EtherChannel, 'Down' always indicates a physical or link-level failure, not a standby state.

How to eliminate wrong answers

Option A is wrong because Gi0/2 is down and not bundled, so not all three ports are forwarding traffic. Option C is wrong because the 'bndl' partner state is used by both PAgP and LACP; the output does not show PAgP-specific fields like 'learn' or 'method', so the protocol cannot be determined from this output alone. Option D is wrong because Gi0/2 is in 'Down' state, not in standby; standby mode (hot-standby) would show 'Up, Not-In-Bundle' with a partner state of 'standby' or 'hot-sby', not 'down'.

1760
Matchingmedium

Drag and drop each 802.11 standard on the left to its matching frequency band and maximum data rate on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

2.4 GHz, up to 11 Mbps

5 GHz, up to 54 Mbps

2.4 GHz, up to 54 Mbps

2.4/5 GHz, up to 600 Mbps

5 GHz, up to 6.9 Gbps

Why these pairings

802.11b operates at 2.4 GHz with 11 Mbps; 802.11a operates at 5 GHz with 54 Mbps; 802.11g operates at 2.4 GHz with 54 Mbps; 802.11n operates at both 2.4 and 5 GHz with 600 Mbps; 802.11ac operates at 5 GHz with up to 6.9 Gbps.

1761
Multi-Selecthard

Which TWO statements about NETCONF and YANG are true?

Select 2 answers
A.NETCONF sessions are stateless
B.YANG defines both the data model and the RPC operations for network devices
C.NETCONF uses TLS as the mandatory transport protocol
D.YANG is a data modeling language used to define the structure of configuration and state data
E.NETCONF uses XML as the data encoding format
AnswersD, E

YANG is a data modeling language used to define the hierarchical structure of configuration and state data in a device. It describes nodes, types, and constraints, allowing controllers and applications to understand the data that NETCONF retrieves and modifies. This is the core purpose of YANG, separate from transport or encoding details, and it is correct because YANG models the data, not the protocol messages.

Why this answer

YANG (RFC 7950) is a data modeling language specifically designed to define the structure of configuration and state data, as well as notifications and RPCs, for network devices. It provides a hierarchical, schema-based representation of data that can be serialized into XML or JSON, making it the standard for modeling NETCONF and RESTCONF datastores.

Exam trap

The trap here is confusing YANG's role in defining data models with NETCONF's role in defining transport and RPC operations, leading candidates to incorrectly select Option B, while also mistaking NETCONF's mandatory SSH transport for TLS.

1762
MCQeasy

An engineer is automating the configuration of SNMPv3 on a large number of Cisco IOS-XE devices using Ansible. The playbook uses the ios_snmp_server module. The engineer wants to ensure that the SNMP configuration is applied only if the device is running a specific IOS version that supports SNMPv3. Which Ansible feature should the engineer use to conditionally execute the task?

A.Use the 'tags' feature to selectively run the SNMP task only on certain devices.
B.Use the 'register' directive to capture the output and then use 'failed_when' to skip the task.
C.Use the 'when' clause with a condition on the 'ansible_net_version' fact.
D.Use the 'block' and 'rescue' structure to handle version mismatches.
AnswerC

The when clause is the standard Ansible mechanism for per-host conditional execution; it evaluates a Jinja2 expression against facts such as ansible_net_version, and if the expression is false, the task is skipped entirely for that host. For network devices, facts must first be gathered via a module like ios_facts, which populates ansible_net_version with the IOS image version. Using 'when: ansible_net_version is version('16.9', '>=')' is the correct, declarative way to run the SNMP task only on devices matching the version criteria.

Why this answer

The 'when' clause in Ansible allows conditional execution of a task based on a fact or variable. The 'ansible_net_version' fact, gathered by the ios_facts module, contains the exact IOS version string. By using 'when: ansible_net_version is version('X.Y.Z', '>=')', the engineer can ensure the SNMPv3 configuration task runs only on devices running a supported IOS version, avoiding errors on unsupported platforms.

Exam trap

Cisco often tests the distinction between static task selection (tags) and dynamic conditional execution (when), leading candidates to mistakenly choose 'tags' for runtime version checks.

How to eliminate wrong answers

Option A is wrong because 'tags' are used to selectively run or skip tasks during playbook execution, but they do not evaluate runtime conditions like IOS version; tags are static labels, not conditional logic. Option B is wrong because 'register' captures task output and 'failed_when' marks a task as failed based on conditions, but neither skips the task execution itself; the task would still attempt to run and potentially fail. Option D is wrong because 'block' and 'rescue' handle errors after a task fails, not prevent the task from running; they are for exception handling, not pre-execution conditional checks.

1763
MCQmedium

Given the following configuration on a Cisco IOS switch: interface GigabitEthernet0/4 switchport mode trunk switchport trunk allowed vlan except 100-200 What is the effect of this configuration?

A.The trunk will forward traffic for all VLANs except VLANs 100 through 200.
B.The trunk will only forward traffic for VLANs 100 through 200.
C.The trunk will forward traffic for all VLANs.
D.The trunk will not forward any traffic because the allowed list is empty.
AnswerA

The command `switchport trunk allowed vlan except 100-200` starts from the default allowed list, which includes all VLANs (1-4094), and subtracts VLANs 100 through 200 from that set. As a result, the trunk forwards traffic for every VLAN outside this range, including the native VLAN and any user-configured VLANs beyond the excluded block. This is the standard behavior of the `except` keyword: it creates a deny list rather than an allow list.

Why this answer

The 'switchport trunk allowed vlan except 100-200' command explicitly removes VLANs 100 through 200 from the allowed VLAN list on the trunk. All other VLANs (1-99 and 201-4094) remain permitted. This is the standard behavior of the 'except' keyword in Cisco IOS trunk configuration.

Exam trap

Cisco often tests the 'except' keyword to trap candidates who confuse it with 'add' or 'remove', leading them to think the trunk only forwards the specified range or that the allowed list becomes empty.

How to eliminate wrong answers

Option B is wrong because the 'except' keyword excludes the specified VLAN range, not includes it; the trunk will forward traffic for all VLANs except 100-200, not only those VLANs. Option C is wrong because the configuration explicitly removes VLANs 100-200, so the trunk does not forward traffic for all VLANs. Option D is wrong because the allowed list is not empty; it contains all VLANs except 100-200, so traffic for other VLANs is still forwarded.

1764
MCQmedium

What is the purpose of the 'ip nat inside source list' command in Cisco IOS?

A.It defines the inside interface for NAT.
B.It identifies the traffic to be translated and the translation method.
C.It filters inbound traffic before NAT is applied.
D.It configures the router as a DHCP server.
AnswerB

The access-list referenced by 'ip nat inside source list' identifies the traffic that will be translated, while the accompanying pool or interface keyword defines the translation method, such as dynamic NAT, PAT, or static mapping. The ACL matches source IP addresses and the subsequent parameters determine how those addresses are translated. Therefore, this command properly ties the match criteria to the translation action.

Why this answer

The 'ip nat inside source list' command is used to define which traffic (identified by an access list) should be translated and to specify the translation method, such as dynamic NAT, PAT, or static NAT. It links the ACL that matches the source IP addresses to a NAT pool or interface, enabling the router to perform the translation for outbound traffic.

Exam trap

The trap here is that candidates confuse 'ip nat inside source list' with 'ip nat inside' (which defines the inside interface), leading them to select option A, but the 'source list' specifically ties an ACL to a translation method, not the interface role.

How to eliminate wrong answers

Option A is wrong because the 'ip nat inside' command (not 'ip nat inside source list') is used to define the inside interface for NAT. Option C is wrong because the command does not filter inbound traffic; it specifies source traffic to be translated, and NAT filtering is handled by separate ACLs or zone-based policies. Option D is wrong because the command is unrelated to DHCP; DHCP server configuration uses the 'ip dhcp pool' and 'network' commands.

1765
Drag & Dropmedium

Drag and drop the steps of Docker container networking with bridge mode into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Bridge networking starts with creating a Docker bridge network. Then, a container is run attached to that bridge. Next, the container gets an IP from the bridge subnet.

After that, port mapping is configured for external access. Finally, the container communicates with others via the bridge.

1766
Drag & Dropmedium

Drag and drop the steps of FlexVPN IKEv2 spoke registration to hub into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

FlexVPN uses IKEv2 for authentication and tunnel setup. The spoke initiates IKEv2 SA negotiation with the hub. After authentication, the hub assigns an IP address to the spoke via configuration payload.

The spoke then registers its identity with the hub using IKEv2 notify messages. Finally, the spoke installs the tunnel route and can communicate.

1767
Multi-Selecthard

Which three statements about Ansible playbooks and roles are true? (Choose three.)

Select 3 answers
A.Roles in Ansible use a standardized directory structure that includes 'tasks', 'handlers', 'vars', 'defaults', and 'meta'.
B.The 'import_role' module includes a role dynamically during play execution.
C.Handlers are special tasks that run only when notified by other tasks, and they run only once even if notified multiple times.
D.Variables defined in the 'defaults' directory of a role have the highest precedence.
E.The 'meta' directory in a role is used to define role dependencies.
AnswersA, C, E

Ansible roles enforce a fixed directory layout — tasks, handlers, vars, defaults, meta, templates and files — so content is discovered automatically by convention rather than declared in the playbook, enabling reuse and clean separation of variables from defaults.

Why this answer

Option A is correct because Ansible roles follow a standardized directory layout containing subdirectories such as tasks, handlers, vars, defaults, meta, files, and templates, which allows roles to be reused and shared consistently. Option C is correct because handlers are tasks triggered only via the notify directive, and Ansible runs each notified handler only once at the end of a play, even if multiple tasks notify it. Option E is correct because the meta directory holds main.yml, where role dependencies are declared under the dependencies key, and it can also define galaxy metadata.

Option B is incorrect because import_role is a static import processed at playbook parsing time, whereas include_role is the module that includes a role dynamically during execution. Option D is incorrect because variables in a role's defaults directory have the lowest precedence among role variables, not the highest; vars files and inventory or play-level variables override them.

Exam trap

The trap here is confusing 'import_role' (static, parse-time) with 'include_role' (dynamic, runtime), and reversing the precedence of 'defaults' versus 'vars' in a role — candidates often assume defaults are authoritative when they are actually the weakest.

1768
MCQeasy

A network team is designing an SD-Access fabric for a large enterprise. The design must support automated provisioning and policy management. Which management platform is essential for deploying and managing the fabric?

A.Cisco DNA Center
B.Cisco ISE
C.Cisco Prime Infrastructure
D.Cisco vManage
AnswerA

Cisco DNA Center is the centralized management, automation, and assurance platform that SD-Access is built around. It provides the intent-based fabric provisioning workflows that automatically configure fabric domains, control-plane nodes, border nodes, and edge nodes, while also orchestrating policy definitions and translating business intent into network configuration. Without DNA Center, the fabric underlay and overlay cannot be deployed as a cohesive SD-Access architecture, making it the correct management platform for the fabric.

Why this answer

Cisco DNA Center is the essential management platform for deploying and managing an SD-Access fabric because it provides a centralized, intent-based interface for automating the entire fabric lifecycle, including design, provisioning, policy creation, and assurance. It integrates with Cisco ISE for policy enforcement and with network devices via APIs (e.g., NETCONF/YANG) to push configurations such as VXLAN, LISP, and CTS SGTs. Without DNA Center, the automated provisioning and policy management required for SD-Access cannot be achieved at scale.

Exam trap

Cisco often tests the distinction between management platforms (DNA Center for SD-Access) and policy/identity engines (ISE) or other overlay technologies (vManage for SD-WAN), so the trap here is confusing the role of ISE as a policy enforcer with the role of DNA Center as the fabric orchestrator.

How to eliminate wrong answers

Option B (Cisco ISE) is wrong because ISE handles identity services, authentication, authorization, and policy enforcement (e.g., 802.1X, SGT classification), but it is not the management platform for deploying or provisioning the SD-Access fabric itself; it works in conjunction with DNA Center. Option C (Cisco Prime Infrastructure) is wrong because Prime Infrastructure is a legacy network management tool that lacks support for SD-Access fabric automation, VXLAN/EVPN provisioning, and intent-based policy workflows; it cannot deploy or manage the fabric. Option D (Cisco vManage) is wrong because vManage is the management platform for Cisco SD-WAN (Viptela-based), not for SD-Access; SD-Access uses DNA Center for centralized control, while vManage manages overlay tunnels and WAN edge routers in a separate technology domain.

1769
MCQmedium

A company is deploying a multi-tenant data center using VMware vSphere. The architect must ensure that each tenant’s virtual machines (VMs) are isolated at Layer 2 while sharing the same physical NICs. Which design approach best meets this requirement?

A.Configure a single standard virtual switch and assign each VM to a separate port group with unique VLAN IDs.
B.Deploy a separate physical NIC for each tenant and bridge them to the VMs.
C.Use a distributed virtual switch with VLAN trunking and assign all VMs to the same port group.
D.Enable promiscuous mode on the virtual switch to allow all VMs to see each other’s traffic.
AnswerA

Configuring a single standard virtual switch with separate port groups for each VM and assigning unique VLAN IDs isolates traffic at Layer 2 by ensuring that frames from one VM are tagged with its designated VLAN and cannot be forwarded to a VM in a different VLAN segment, as the virtual switch enforces VLAN boundaries at the virtual port level. This approach allows all tenants to share the same physical NIC(s) while keeping broadcast, multicast, and unicast traffic constrained to the assigned VLAN, meeting the isolation requirement without additional hardware.

Why this answer

Configuring a standard virtual switch with separate port groups and unique VLAN IDs provides Layer 2 isolation between tenants by leveraging 802.1Q VLAN tagging. Each VM’s traffic is tagged with its assigned VLAN ID, ensuring that VMs in different port groups cannot communicate directly at Layer 2, even though they share the same physical NICs.

Exam trap

The trap here is that candidates often confuse VLAN trunking (which carries multiple VLANs on a single link) with port group assignment, mistakenly thinking that placing all VMs in the same port group with trunking provides isolation, when in fact it collapses all tenants into a single broadcast domain.

How to eliminate wrong answers

Option B is wrong because deploying a separate physical NIC for each tenant defeats the requirement to share the same physical NICs, and bridging them to VMs does not provide efficient Layer 2 isolation in a multi-tenant design. Option C is wrong because using a distributed virtual switch with VLAN trunking and assigning all VMs to the same port group would place all tenants in the same broadcast domain, breaking Layer 2 isolation. Option D is wrong because enabling promiscuous mode on the virtual switch allows all VMs to see each other’s traffic, which completely violates the isolation requirement.

1770
MCQmedium

A network engineer runs the following command on Switch SW1: SW1# show etherchannel summary Flags: D - down P - bundled in port-channel I - stand-alone s - suspended H - Hot-standby (LACP only) R - Layer3 S - Layer2 U - in use N - not in use, no aggregation f - failed to allocate aggregator M - not in use, minimum links not met u - unsuitable for bundling w - waiting to be aggregated d - default port Number of channel-groups in use: 1 Number of aggregators: 1 Group Port-channel Protocol Ports ------+-------------+-----------+-------------------------------------------- 1 Po1(SU) LACP Gi0/0(P) Gi0/1(P) Gi0/2(s) Gi0/3(D) Based on this output, what can be concluded?

A.Port-channel 1 is operating as a Layer 3 interface.
B.Interface Gi0/2 is suspended due to a configuration mismatch.
C.Interface Gi0/3 is in standby mode waiting to join the bundle.
D.All four interfaces are actively forwarding traffic in the EtherChannel.
AnswerB

The lowercase 's' flag on Gi0/2 means the port is suspended from the EtherChannel bundle, not forwarding traffic. A port is suspended when its configuration parameters—such as speed, duplex, trunk allowed VLANs, or native VLAN—do not match the other members of the port-channel. To protect the network from loops or misforwarding, the switch holds the port in a suspended state until its settings are reconciled with the bundle. This matches the correct answer.

Why this answer

The output shows Gi0/2 with an '(s)' flag, which means 'suspended'. In LACP EtherChannel, a port is suspended when there is a configuration mismatch (e.g., different speed, duplex, VLAN settings, or trunk allowed VLANs) that prevents it from being bundled. The '(D)' flag on Gi0/3 indicates the port is down, not suspended.

Exam trap

Cisco often tests the distinction between 'suspended' (configuration mismatch) and 'down' (physical/administrative issue), leading candidates to misinterpret the '(s)' flag as a standby or waiting state.

How to eliminate wrong answers

Option A is wrong because the '(SU)' flag on Port-channel 1 indicates Layer 2 (S) and in use (U), not Layer 3 (R). Option C is wrong because Gi0/3 shows '(D)' for down, not '(H)' for Hot-standby (LACP only). Option D is wrong because Gi0/2 is suspended and Gi0/3 is down, so only two interfaces (Gi0/0 and Gi0/1) are actively forwarding traffic.

1771
Matchingmedium

Drag and drop each MQC command on the left to its configuration level on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Defines traffic classification criteria

Associates class-maps with QoS actions

Applies a policy-map to an interface

References a class-map for actions

Specifies classification criteria

Why these pairings

class-map defines traffic classes. policy-map associates class-maps with QoS actions. service-policy applies the policy-map to an interface. class (within policy-map) references a class-map. match (within class-map) specifies classification criteria.

1772
MCQhard

A service provider is migrating from a traditional IP core to an MPLS core. The engineer has configured LDP on all core routers and verified that LDP sessions are established. However, some prefixes learned via OSPF are not being assigned labels. The 'show mpls ldp bindings' command shows missing bindings for certain routes. What is the most likely cause?

A.The routes are not present in the global routing table on the router.
B.The OSPF process is not redistributed into LDP.
C.LDP is configured to only assign labels to BGP routes.
D.The 'mpls ldp autoconfig' command is missing on OSPF.
AnswerA

The correct reason is that LDP binds labels only to prefixes that are actively installed in the global routing table (RIB). In this scenario, even though OSPF may be advertising the routes through neighboring routers, those specific destinations are absent from the router's RIB, so there is no forwarding equivalence class (FEC) for LDP to assign a label binding to. Since LDP is a pure RIB consumer, any route missing from the global table—due to filtering, administrative distance issues, or passive interfaces—will never receive a label.

Why this answer

LDP assigns labels to every prefix present in the global routing table by default. If a prefix is not in the routing table (e.g., because it is a directly connected subnet that is not advertised via OSPF or is filtered by a route-map), LDP will not generate a label binding for it. The 'show mpls ldp bindings' command only displays bindings for routes that exist in the routing table, so missing bindings indicate the routes are absent from the global RIB.

Exam trap

The trap here is that candidates assume LDP requires a special configuration to work with OSPF, but in reality LDP automatically labels all routes in the global routing table, so missing bindings point to the routes not being present in the RIB rather than a protocol interaction issue.

How to eliminate wrong answers

Option B is wrong because LDP does not require redistribution from OSPF; it works directly with the IP routing table and automatically assigns labels to all IGP-learned prefixes. Option C is wrong because LDP is not selective by default — it assigns labels to all routes in the global routing table, not just BGP routes. Option D is wrong because 'mpls ldp autoconfig' is a Cisco command used to enable LDP on OSPF interfaces, not to control which prefixes receive labels; missing it would prevent LDP sessions from forming on those interfaces, but the question states LDP sessions are already established.

1773
MCQhard

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 10.10.10.0 BGP routing table entry for 10.10.10.0/24, version 20 Paths: (2 available, best #1, table default) Advertised to update-groups: 1 Refresh Epoch 1 65050 65100 10.0.1.2 from 10.0.1.2 (10.0.0.2) Origin IGP, metric 0, localpref 100, weight 0, valid, external, best rx pathid: 0, tx pathid: 0x0 65050 65100 65200 10.0.1.3 from 10.0.1.3 (10.0.0.3) Origin IGP, metric 0, localpref 100, weight 0, valid, external rx pathid: 0, tx pathid: 0x0 Based on this output, what can be concluded?

A.Path #2 is the best path because it has a longer AS_PATH, indicating more specific routing.
B.Path #1 is the best path because it has a shorter AS_PATH length.
C.Both paths are equally preferred, and BGP uses tie-breaking rules like router ID.
D.Path #1 is the best path because it is received from a higher IP address.
AnswerB

Path #1 wins on AS_PATH length, the fourth BGP best-path attribute after weight, local preference and locally originated routes. Its AS_PATH contains two autonomous systems (65050, 65100) versus three for path #2 (65050, 65100, 65200), so the shorter sequence is selected as best, satisfying the tie-break at that step.

Why this answer

B is correct because BGP selects the best path based on the shortest AS_PATH length when all other attributes (weight, local preference, origin) are equal. In the output, Path #1 has an AS_PATH of '65050 65100' (2 AS numbers) while Path #2 has '65050 65100 65200' (3 AS numbers), making Path #1 the best path. The 'best #1' annotation confirms this selection.

Exam trap

Cisco often tests the AS_PATH length comparison by presenting two paths with different AS_PATH lengths but identical other attributes, expecting candidates to know that shorter AS_PATH is preferred, not longer.

How to eliminate wrong answers

Option A is wrong because a longer AS_PATH does not indicate more specific routing; BGP prefers shorter AS_PATH lengths, not longer ones. Option C is wrong because the paths are not equally preferred; Path #1 is explicitly marked as best due to shorter AS_PATH, so tie-breaking rules like router ID are not invoked. Option D is wrong because BGP does not use the IP address of the next-hop or neighbor as a tie-breaker for best path selection; the decision is based on AS_PATH length in this case.

1774
Multi-Selecthard

Which three statements about gRPC and gNMI in the context of model-driven telemetry are true? (Choose three.)

Select 3 answers
A.gRPC uses HTTP/2 as its transport protocol and Protocol Buffers as its interface definition language.
B.gNMI (gRPC Network Management Interface) is a gRPC-based protocol that can be used for both telemetry and configuration operations.
C.gNMI telemetry subscriptions can only use YANG paths from OpenConfig models.
D.gNMI relies on NETCONF for session establishment and data encoding.
E.gNMI supports both periodic and on-change telemetry subscriptions.
AnswersA, B, E

gRPC's transport is HTTP/2, enabling multiplexed streams over one connection, while Protocol Buffers define the service contract and serialise payloads compactly. This satisfies the stem's requirement for accurate model-driven telemetry statements, since gNMI itself is built as a gRPC service using these same mechanisms.

Why this answer

Option A is correct because gRPC is built on HTTP/2 for transport (providing multiplexed streams, flow control, and header compression) and uses Protocol Buffers as its IDL for defining services and messages. Option B is correct because gNMI is a gRPC-based protocol defined by OpenConfig that supports both telemetry subscriptions (Subscribe RPC) and configuration operations (Get, Set, Capabilities RPCs). Option E is correct because gNMI defines subscription modes including SAMPLE (periodic) and ON_CHANGE, allowing devices to stream updates either at fixed intervals or when values change.

Option C is incorrect because gNMI subscriptions can use any YANG-modeled paths, including native vendor models, not only OpenConfig models. Option D is incorrect because gNMI operates directly over gRPC/HTTP/2 and does not rely on NETCONF for session establishment or encoding; it uses Protocol Buffers for encoding.

Exam trap

350-401 often tests whether candidates conflate gNMI with NETCONF because both use YANG — the trap is assuming gNMI inherits NETCONF's transport or model restrictions, when in fact gNMI is pure gRPC/HTTP2/protobuf and supports both OpenConfig and native YANG paths.

1775
MCQmedium

A network engineer is deploying a Cisco SD-WAN solution using vManage, vSmart, and vBond controllers. The engineer needs to ensure that the data plane is secure and that tunnels are established between WAN edge devices. Which component is responsible for orchestrating the control plane and distributing policies to WAN edge devices?

A.vManage
B.vBond orchestrator
C.WAN edge device
D.vSmart controller
AnswerD

The vSmart controller is the centralized control plane component in Cisco SD-WAN. It distributes routing and policy information to WAN edge devices using the Overlay Management Protocol (OMP). This enables secure tunnel establishment and consistent policy enforcement across the fabric, making it the correct answer for orchestrating the control plane.

Why this answer

In Cisco SD-WAN, the vSmart controller is the control plane component. It uses the Overlay Management Protocol (OMP) to distribute routing information and policies to WAN edge devices. The vBond orchestrator handles authentication and discovery, while vManage provides management.

The vSmart controller is specifically responsible for orchestrating the control plane and policy distribution.

Exam trap

The trap here is confusing the management plane role of vManage with the control plane role of vSmart, since both are central to SD-WAN operations but perform different functions.

1776
Multi-Selectmedium

Which three statements about telemetry protocols and data collection are true? (Choose three.)

Select 3 answers
A.gNMI is a gRPC-based network management protocol that supports telemetry streaming.
B.In dial-out telemetry, the network device initiates the connection to the collector.
C.Telemetry can provide higher granularity and lower latency compared to SNMP polling.
D.SNMP is the only protocol supported for telemetry data collection on Cisco IOS XE devices.
E.gNMI requires the device to be configured with a CLI-based telemetry profile.
AnswersA, B, C

gNMI runs over gRPC and provides streaming telemetry, satisfying the stem's requirement for a protocol supporting continuous data collection. Unlike SNMP polling or syslog push, gNMI's subscribe operations deliver model-driven updates on change, which is precisely the telemetry streaming capability the question asks you to identify.

Why this answer

gNMI is a gRPC-based protocol for streaming telemetry and managing network devices. Dial-out telemetry pushes data from the device to a collector. Telemetry can provide more granular data than SNMP.

SNMP is still widely used for legacy monitoring. gNMI does not require CLI configuration for telemetry.

1777
MCQmedium

A network engineer is implementing a first-hop redundancy protocol on a pair of Cisco switches. The design requires that the virtual IP address be the same as one of the physical interface addresses, and that the standby group use a virtual MAC address of 0000.0c07.acXX. Which protocol meets these requirements?

A.VRRP
B.SLB
C.GLBP
D.HSRP
AnswerD

HSRP uses a virtual MAC address of 0000.0c07.acXX, where XX is the group number in hexadecimal. It also allows the virtual IP address to be the same as one of the physical interface addresses on the active router. This matches the requirements exactly, making HSRP the correct choice.

Why this answer

HSRP is a Cisco-proprietary first-hop redundancy protocol that uses the virtual MAC address 0000.0c07.acXX and permits the virtual IP to be the same as a physical interface IP. VRRP and GLBP use different MAC address formats. Therefore, HSRP uniquely satisfies both conditions in the scenario.

Exam trap

The trap here is mixing up the virtual MAC address formats of HSRP, VRRP, and GLBP; only HSRP uses the 0000.0c07.acXX prefix.

1778
Drag & Dropmedium

Drag and drop the steps of Ansible inventory grouping and variable inheritance into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Ansible inventory grouping and variable inheritance follows a hierarchy: first, group variables are defined in group_vars files; then, host variables are defined in host_vars files; next, the inventory parser resolves group parent-child relationships; after that, variables are merged with child groups overriding parent groups; finally, host-specific variables take highest precedence.

1779
MCQhard

An engineer is troubleshooting a network where OSPF neighbors are stuck in the EXSTART state. What is the most likely cause?

A.Dead timer mismatch
B.Authentication misconfiguration
C.Mismatched OSPF area IDs
D.MTU mismatch between the routers
AnswerD

During the EXSTART/EXCHANGE phase, OSPF routers exchange database description (DBD) packets that can be as large as the interface MTU; if one router's MTU is lower, the larger DBD packet will be dropped or fragmented, and the neighbor will never leave EXSTART because it keeps waiting for a valid DBD sequence. The interface MTU mismatch is a classic cause of OSPF adjacencies stuck in EXSTART, as the router with the smaller MTU silently discards the oversized multicast packets. This can be diagnosed by checking the 'show ip ospf neighbor' state and by ensuring both ends have the same MTU or by enabling 'ip ospf mtu-ignore' as a workaround.

Why this answer

The EXSTART state in OSPF indicates that routers have formed a bidirectional communication (2-Way state) and are now attempting to exchange Database Description (DBD) packets to negotiate the master/slave relationship and the initial sequence number. An MTU mismatch between the routers is the most common cause of neighbors being stuck in EXSTART because the router with the smaller MTU will drop DBD packets that exceed its interface MTU, preventing the exchange from progressing to the Loading state.

Exam trap

Cisco often tests the EXSTART state as a symptom of MTU mismatch, but candidates frequently confuse it with authentication or area ID mismatches, which actually prevent adjacency formation at earlier stages like INIT or 2-Way.

How to eliminate wrong answers

Option A is wrong because a dead timer mismatch typically causes neighbors to be stuck in the INIT or 2-Way state, not EXSTART, as the routers will fail to receive Hello packets within the dead interval. Option B is wrong because authentication misconfiguration usually prevents OSPF neighbors from forming adjacency at all, often resulting in the INIT state or no neighbor relationship, not EXSTART. Option C is wrong because mismatched OSPF area IDs prevent the formation of any adjacency beyond the 2-Way state, as routers will not exchange Hello packets with mismatched area IDs, and they will not reach EXSTART.

1780
MCQhard

A network architect is designing a Cisco SD-Access fabric for a large enterprise. The fabric will use VXLAN encapsulation and a Layer 3 underlay. The architect must ensure that the fabric supports the separation of policy from topology and allows endpoints to be assigned to virtual networks. Which Cisco SD-Access component is responsible for maintaining the mapping between endpoint IP addresses and their fabric locators, and for providing the control plane that enables fabric edge nodes to resolve endpoint locations?

A.Fabric border node
B.Fabric intermediate node
C.Fabric edge node
D.Control plane node
AnswerD

The control plane node in Cisco SD-Access maintains the mapping database of endpoint IP addresses to fabric locators (such as VTEP addresses) and provides the control plane that fabric edge nodes use to resolve endpoint locations. It uses LISP to register and query endpoint information, enabling separation of policy from topology. This directly matches the requirement described.

Why this answer

In Cisco SD-Access, the control plane node hosts the LISP map-server and map-resolver functions, maintaining the endpoint-to-locator mapping database. Fabric edge nodes query this node to resolve endpoint locations. This design separates policy from topology and supports virtual network assignment.

The other components either connect endpoints, handle external traffic, or forward underlay packets, but none maintain the mapping database.

Exam trap

The trap here is confusing the control plane node with the fabric border node, because both are central fabric components, but only the control plane node maintains the endpoint mapping database and provides LISP-based resolution.

1781
MCQmedium

A network team is designing QoS for a Cisco SD-WAN fabric connecting multiple branch offices to a central data center. The design must ensure that VoIP traffic from branch sites receives priority treatment across the WAN overlay, regardless of the underlying transport (MPLS, Internet, LTE). Which architectural component should the team configure to enforce consistent QoS policies across all WAN edges?

A.Configure a centralized QoS policy on vManage that matches VoIP DSCP markings and applies priority queuing on all WAN edge routers.
B.Define a localized QoS policy on each branch router using MQC, matching the same DSCP values.
C.Use the vSmart controller to apply QoS policy only on the MPLS transport, leaving Internet and LTE unmanaged.
D.Implement QoS using RSVP across the overlay tunnels.
AnswerA

Centralized QoS policies in Cisco SD-WAN are defined in vManage and propagated by vSmart to every WAN edge router, ensuring identical classification and scheduling behavior across all transports. Matching VoIP DSCP EF markings and assigning them to a priority queue in the policy reduces latency and jitter for real-time traffic, which is the architecturally correct approach for fabric-wide uniformity.

Why this answer

VManage serves as the centralized SD-WAN management plane, allowing administrators to define a single QoS policy that matches VoIP DSCP markings (e.g., EF for expedited forwarding) and applies priority queuing across all WAN edge routers. This ensures consistent treatment of VoIP traffic over any transport (MPLS, Internet, LTE) by pushing the policy to all vEdge/cEdge devices via the vSmart controller, leveraging the SD-WAN overlay's ability to enforce QoS independently of the underlying physical transport.

Exam trap

Cisco often tests the misconception that QoS policies must be configured locally on each router (Option B) or that RSVP is required for guaranteed service in SD-WAN, but the key is that SD-WAN centralizes QoS management via vManage and vSmart to ensure consistency across all transports.

How to eliminate wrong answers

Option B is wrong because defining a localized QoS policy on each branch router using MQC (Modular QoS CLI) is operationally inefficient and error-prone in a large SD-WAN deployment; it lacks centralized management and consistency, and does not leverage the SD-WAN fabric's ability to enforce policies across all transports uniformly. Option C is wrong because using the vSmart controller to apply QoS policy only on MPLS transport violates the design requirement of treating VoIP traffic consistently across all transports (MPLS, Internet, LTE); this approach would leave Internet and LTE links unmanaged, causing potential degradation of VoIP over those transports. Option D is wrong because RSVP (Resource Reservation Protocol) is a per-flow signaling protocol designed for IntServ (Integrated Services) QoS, which does not scale well in an SD-WAN overlay environment and is not used for enforcing consistent QoS policies across WAN edges; SD-WAN relies on DiffServ (Differentiated Services) markings and centralized policy, not RSVP.

1782
MCQmedium

A network engineer runs the following command on Switch SW1: SW1# show vlan brief VLAN Name Status Ports ---- -------------------------------- --------- ------------------------------- 1 default active Gi0/1, Gi0/2, Gi0/3 10 Sales active Gi0/4, Gi0/5 20 Engineering active Gi0/6, Gi0/7 1002 fddi-default act/unsup 1003 token-ring-default act/unsup 1004 fddinet-default act/unsup 1005 trnet-default act/unsup Based on this output, what can be concluded?

A.All ports shown are in trunk mode.
B.VLANs 1002-1005 are active and supported.
C.Interfaces Gi0/1, Gi0/2, and Gi0/3 are in VLAN 1.
D.VLAN 20 has no ports assigned.
AnswerC

In the 'show vlan brief' output, the Ports column for VLAN 1 lists Gi0/1, Gi0/2, and Gi0/3, which is exactly what identifies those interfaces as access ports in VLAN 1. Access ports are statically assigned to a VLAN and their membership appears in this list. Because trunk links are not displayed the same way as individual access members in this output, the listed interfaces are definitively VLAN 1 access ports.

Why this answer

The 'show vlan brief' output explicitly lists Gi0/1, Gi0/2, and Gi0/3 under VLAN 1 (default), confirming these interfaces are access ports assigned to VLAN 1. VLAN 1 is the default VLAN on Cisco switches, and all ports not explicitly configured otherwise belong to it.

Exam trap

Cisco often tests the distinction between access and trunk port representation in 'show vlan brief' versus 'show interfaces trunk', leading candidates to incorrectly assume all listed ports are trunk ports or that VLANs 1002-1005 are fully functional.

How to eliminate wrong answers

Option A is wrong because the output shows ports assigned to specific VLANs, which is characteristic of access ports, not trunk ports; trunk ports carry multiple VLANs and would not be listed under a single VLAN in 'show vlan brief'. Option B is wrong because VLANs 1002-1005 are shown with status 'act/unsup', meaning they are administratively active but unsupported on modern hardware (e.g., no FDDI or Token Ring interfaces), so they are not fully active and supported. Option D is wrong because VLAN 20 (Engineering) has ports Gi0/6 and Gi0/7 assigned, as clearly listed in the output.

1783
MCQhard

A network engineer is implementing Cisco SD-Access and needs to ensure that endpoints in a virtual network can communicate with a shared service that resides in a different virtual network. The shared service must be reachable from multiple virtual networks without duplicating the service. Which SD-Access component should be configured to provide this inter-VN communication?

A.Control plane node
B.Fusion router
C.Fabric edge node
D.Fabric border node
AnswerB

The fusion router is used in SD-Access to provide inter-VN routing and to connect to shared services that reside outside the fabric or in a different VN. It allows multiple virtual networks to reach a common service without duplicating it. It is typically connected to the border node and runs VRF-aware routing to leak routes between VNs.

Why this answer

The fusion router is specifically designed to enable inter-VN communication and shared services in Cisco SD-Access. It connects to the fabric border node and uses VRF leaking to allow endpoints in different virtual networks to reach common services. Fabric edge nodes, border nodes, and control plane nodes have different roles and do not provide this function.

The fusion router ensures that shared services are not duplicated across VNs.

Exam trap

The trap here is confusing the border node's role of external connectivity with the fusion router's role of inter-VN routing and shared services.

1784
MCQhard

A network engineer writes an Ansible playbook to configure a VLAN on a Cisco Nexus switch: ```yaml --- - name: Configure VLAN hosts: nxos_switches gather_facts: no tasks: - name: Create VLAN 100 cisco.nxos.nxos_vlan: vlan_id: 100 name: test_vlan state: present ``` What is a potential issue with this playbook?

A.The module name is incorrect; it should be 'nxos_vlan_config' instead of 'nxos_vlan'.
B.The playbook is missing the 'connection: network_cli' and 'become: yes' directives to enable privileged mode.
C.The VLAN ID must be a string, not an integer.
D.The 'state: present' is invalid; it should be 'state: create'.
AnswerB

Ansible network modules for NX-OS require the connection variable to be set to 'network_cli' so that the module can establish a persistent SSH session to the network device. In addition, 'become: yes' with 'become_method: enable' is needed to enter privileged exec mode, otherwise the module cannot execute configuration commands. Omitting these directives means the playbook will fail or the module will be unable to apply the VLAN configuration.

Why this answer

Ansible modules for Cisco NX-OS require `connection: network_cli` (or `ansible_connection: network_cli`) to use the CLI transport, and `become: yes` to elevate privileges to enable mode (similar to `enable` on a switch). Without these, the playbook will fail to authenticate or execute privileged commands, as the `nxos_vlan` module needs to send configuration commands that require enable access.

Exam trap

The trap here is that candidates often assume Ansible modules for network devices work like Linux modules without needing explicit connection and privilege escalation directives, leading them to overlook the mandatory `connection: network_cli` and `become: yes` settings.

How to eliminate wrong answers

Option A is wrong because `nxos_vlan` is a valid Ansible module for managing VLANs on NX-OS; `nxos_vlan_config` is a different module (part of the `nxos_config` family) but not required here. Option C is wrong because the `vlan_id` parameter in the `nxos_vlan` module accepts an integer (e.g., `100`) as shown in the official documentation; it does not need to be a string. Option D is wrong because `state: present` is the correct and valid value to ensure the VLAN exists; `state: create` is not a valid option for this module.

1785
MCQmedium

Examine the following EIGRP configuration on a Cisco IOS-XE device: router eigrp 100 network 10.0.0.0 0.255.255.255 passive-interface default no passive-interface GigabitEthernet0/0 ! interface GigabitEthernet0/0 ip address 10.1.1.1 255.255.255.0 ! interface GigabitEthernet0/1 ip address 10.2.2.1 255.255.255.0 Which statement is true?

A.EIGRP will form adjacencies on both GigabitEthernet0/0 and GigabitEthernet0/1.
B.EIGRP will form an adjacency only on GigabitEthernet0/0.
C.EIGRP will not form any adjacencies because the network command does not match the interface subnets.
D.EIGRP will form adjacencies on all interfaces except those with 'passive-interface' configured.
AnswerB

Correct. GigabitEthernet0/0 is not passive, so it will send and receive hellos. GigabitEthernet0/1 is passive by default.

Why this answer

The passive-interface default command sets all interfaces to passive, and the no passive-interface GigabitEthernet0/0 command re-enables EIGRP adjacency formation only on GigabitEthernet0/0. GigabitEthernet0/1 remains passive, so it will not form an adjacency. The network command with the wildcard mask 0.255.255.255 matches both 10.1.1.0/24 and 10.2.2.0/24, so both interfaces are included in EIGRP, but only the non-passive one forms adjacencies.

Exam trap

350-401 often tests the interaction between passive-interface default and no passive-interface, where candidates incorrectly assume all interfaces matching the network command will form adjacencies.

How to eliminate wrong answers

Option A is wrong because GigabitEthernet0/1 is still passive due to passive-interface default and was not explicitly re-enabled. Option C is wrong because the network command 10.0.0.0 0.255.255.255 does match both interface subnets, so EIGRP does run on them. Option D is wrong because it incorrectly states that adjacencies form on all interfaces except passive ones; in this configuration, only GigabitEthernet0/0 is non-passive, so only it forms an adjacency.

1786
MCQhard

A network engineer is designing a network that uses Cisco SD-Access with a fabric that includes a border node and control plane node. The engineer must ensure that traffic from external networks can reach endpoints within the fabric. Which function does the border node provide in this architecture?

A.It provides connectivity between the fabric and external networks, such as WAN or data center.
B.It maintains the mapping of endpoint IP addresses to fabric edge nodes.
C.It enforces security policies between endpoints within the same virtual network.
D.It acts as the default gateway for all endpoints in the fabric.
AnswerA

The border node in Cisco SD-Access provides connectivity between the fabric and external networks. It handles traffic entering and leaving the fabric, performing functions such as VXLAN-to-VLAN translation and routing to external networks. This allows external users to reach fabric endpoints.

Why this answer

The border node in Cisco SD-Access provides connectivity between the fabric and external networks, handling traffic entering and leaving the fabric. It performs VXLAN-to-VLAN translation and routing, enabling external users to reach fabric endpoints. This is distinct from the control plane node's mapping function and the edge node's policy enforcement.

Exam trap

The trap here is confusing the border node's external connectivity role with the control plane node's mapping role or the edge node's gateway role.

1787
MCQeasy

A network engineer is learning about data models used in network automation. The engineer needs to choose a data modeling language that is human-readable, supports hierarchical data structures, and is used by NETCONF and RESTCONF to define the structure of configuration and state data. Which data modeling language should the engineer choose?

A.JSON
B.YANG
C.XML
D.SNMP MIB
AnswerB

YANG is a data modeling language used to model configuration and state data manipulated by NETCONF, RESTCONF, and other protocols. It is human-readable, hierarchical, and defines the structure, syntax, and semantics of data. YANG models are used by Cisco IOS XE and other vendors to expose their APIs. The engineer should choose YANG because it is specifically designed for this purpose and is the standard for model-driven programmability.

Why this answer

YANG is the data modeling language standardized by IETF for NETCONF and RESTCONF. It provides a hierarchical, human-readable way to model configuration and state data. JSON and XML are serialization formats used to encode data, but they do not define the data model.

SNMP MIBs are for SNMP and not used by NETCONF/RESTCONF. Therefore, YANG is the correct choice for modeling data in modern network automation.

Exam trap

The trap here is confusing data serialization formats like JSON or XML with data modeling languages like YANG.

1788
Drag & Dropmedium

Drag and drop the steps of LISP EID-to-RLOC mapping resolution process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The process begins when the ingress tunnel router (ITR) receives a packet for a destination EID. The ITR sends a Map-Request to the Map-Server, which looks up the mapping and replies with a Map-Reply containing the RLOC. The ITR then caches the mapping and encapsulates the packet to the egress tunnel router (ETR).

1789
MCQeasy

What is the default STP port cost for a 10 Gigabit Ethernet interface?

A.1
B.2
C.4
D.19
AnswerB

A cost of 2 is the correct path-cost value for a 10 Gbps link in the IEEE 802.1t short-method table. This value is part of the revised non-linear cost scale, where lower costs represent higher bandwidths, and 10 Gbps specifically corresponds to 2. Using this value ensures accurate Spanning Tree calculation for 10 Gbps interfaces, making it the right choice for the question.

Why this answer

The default STP port cost for a 10 Gigabit Ethernet interface is 2, as defined by the IEEE 802.1D-2004 standard (which uses a 32-bit path cost formula: 20,000,000 / link speed in Mbps). For 10 Gbps (10,000 Mbps), the calculation is 20,000,000 / 10,000 = 2,000, but the standard caps the cost at a maximum of 200,000 and a minimum of 1, with 10 Gbps assigned a cost of 2. This value is used by Rapid PVST+ and MST in Cisco IOS.

Exam trap

Cisco often tests the difference between the old 16-bit cost values (e.g., 19 for 100 Mbps, 4 for 1 Gbps) and the new 32-bit cost values (e.g., 2 for 10 Gbps), so candidates mistakenly apply the older cost table to 10 Gigabit Ethernet and choose 4 or 19.

How to eliminate wrong answers

Option A is wrong because a cost of 1 is reserved for link speeds of 20 Gbps or higher (e.g., 40 Gbps or 100 Gbps) under the IEEE 802.1D-2004 cost formula, not for 10 Gigabit Ethernet. Option C is wrong because a cost of 4 corresponds to a 2.5 Gbps link (20,000,000 / 2,500 = 8,000, but the standard assigns 4 to 2.5 Gbps), not 10 Gbps. Option D is wrong because a cost of 19 is the default for a 100 Mbps Fast Ethernet interface under the original IEEE 802.1D-1998 16-bit cost formula (1000 / 100 = 10, but Cisco uses 19 for 100 Mbps), not for 10 Gigabit Ethernet.

1790
Multi-Selecteasy

Which TWO statements about virtual switching in a hypervisor environment are correct?

Select 2 answers
A.A virtual switch can be connected to a physical network through uplink ports.
B.A virtual switch does not support VLAN tagging.
C.A virtual switch performs routing between different subnets.
D.A virtual switch forwards frames between virtual machines based on MAC addresses.
E.A virtual switch is a physical device installed in the hypervisor host.
AnswersA, D

Uplink ports bind a virtual switch to physical NICs, bridging guest VM traffic onto the wired network. This satisfies the stem's requirement for correct virtual switching statements, since without uplinks, VMs on the vSwitch could only communicate internally, isolated from the physical infrastructure.

Why this answer

Option A is correct because a virtual switch (vSwitch) uses uplink ports, also called physical NICs or pNICs, to bridge virtual machine traffic onto the physical network, allowing VMs to communicate beyond the host. Option D is correct because a virtual switch operates at Layer 2, learning MAC addresses and forwarding Ethernet frames between virtual machines (and to uplinks) based on destination MAC addresses, just like a physical switch. Option B is wrong because virtual switches do support VLAN tagging, typically via VLAN IDs on port groups or virtual switch ports (e.g., 802.1Q tagging).

Option C is wrong because a virtual switch is a Layer 2 device and does not perform IP routing between subnets; routing requires a router or Layer 3 device. Option E is wrong because a virtual switch is a software construct running inside the hypervisor, not a physical device installed in the host.

Exam trap

Cisco often tests the misconception that virtual switches are physical devices or that they perform Layer 3 functions, when in fact they are software-based Layer 2 forwarding engines that support VLANs and uplink connectivity.

1791
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip route vrf CUSTOMER-A VRF CUSTOMER-A: Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2 i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route Gateway of last resort is 10.0.1.1 to network 0.0.0.0 10.0.0.0/8 is variably subnetted, 3 subnets, 2 masks C 10.0.0.0/30 is directly connected, GigabitEthernet0/0.100 L 10.0.0.1/32 is directly connected, GigabitEthernet0/0.100 B 10.0.2.0/24 [200/0] via 192.168.1.2, 00:12:34 Based on this output, what can be concluded?

A.VRF CUSTOMER-A has a BGP-learned route to 10.0.2.0/24
B.VRF CUSTOMER-A is not using BGP for routing
C.The default route is learned via BGP
D.GigabitEthernet0/0.100 is not associated with VRF CUSTOMER-A
AnswerA

The correct answer is confirmed by the routing table entry for VRF CUSTOMER-A. The prefix 10.0.2.0/24 is prefixed with 'B', which designates a route learned via the Border Gateway Protocol. The next-hop of 192.168.1.2 is the BGP peer address or an eBGP neighbor, proving that BGP is actively exchanging routes within this VRF. Additionally, the route is present in the VRF's isolated routing table, meaning the BGP session is associated with the VRF via the address-family configuration.

Why this answer

The output shows a BGP-learned route to 10.0.2.0/24 with the code 'B' and the administrative distance [200/0], indicating it is an external BGP route. The route is installed in the VRF CUSTOMER-A routing table, confirming that VRF CUSTOMER-A is using BGP and has learned this prefix via BGP from the next-hop 192.168.1.2.

Exam trap

Cisco often tests the distinction between the 'Gateway of last resort' and BGP-learned default routes; candidates may incorrectly assume the default route is BGP-learned because BGP is present in the table, but the output explicitly shows the gateway is 10.0.1.1, not a BGP next-hop.

How to eliminate wrong answers

Option B is wrong because the presence of a BGP-learned route (code 'B') in the VRF table proves that VRF CUSTOMER-A is using BGP for routing. Option C is wrong because the default route (Gateway of last resort) is set to 10.0.1.1, which is not a BGP-learned route; it is likely a static or connected default, and no BGP default route is shown in the table. Option D is wrong because the directly connected subnet 10.0.0.0/30 and local host route 10.0.0.1/32 are both on GigabitEthernet0/0.100, which is listed under VRF CUSTOMER-A, proving the interface is associated with the VRF.

1792
MCQeasy

Which IPsec protocol provides both encryption and authentication within a single ESP header?

A.AH (Authentication Header)
B.ESP (Encapsulating Security Payload)
C.IKE (Internet Key Exchange)
D.GRE (Generic Routing Encapsulation)
AnswerB

ESP (Encapsulating Security Payload) is the correct choice because it is designed to provide confidentiality via encryption, and it can also offer optional integrity and authentication for the protected payload. In tunnel mode, ESP encapsulates the entire original IP packet and encrypts its contents, making it unreadable to eavesdroppers. This makes ESP the standard IPsec protocol for secure VPN data transmission, as it directly satisfies the need for encryption.

Why this answer

ESP (Encapsulating Security Payload) provides both encryption for data confidentiality and authentication (via an optional Integrity Check Value) within a single ESP header. Unlike AH, ESP can encrypt the payload while also offering integrity and origin authentication, making it the correct choice for combined services in a single header.

Exam trap

Cisco often tests the misconception that AH provides encryption or that ESP cannot provide authentication, when in fact ESP includes an optional authentication field (ICV) and is the standard for combined encryption and authentication in IPsec.

How to eliminate wrong answers

Option A is wrong because AH (Authentication Header) provides only authentication and integrity, not encryption, and it authenticates parts of the outer IP header, which ESP does not. Option C is wrong because IKE (Internet Key Exchange) is a protocol used to negotiate and establish IPsec security associations (SAs), not to provide encryption or authentication within a packet header. Option D is wrong because GRE (Generic Routing Encapsulation) is a tunneling protocol that encapsulates packets but does not provide any native encryption or authentication; it is often used with IPsec for secure transport.

1793
MCQmedium

A network engineer is configuring Cisco ACI to extend a Layer 2 bridge domain to an external Layer 2 network. The engineer must ensure that the ACI fabric can forward traffic between the bridge domain and the external network without routing. Which ACI construct should be configured to achieve this?

A.Layer 3 Outside (L3Out)
B.Tenant
C.VRF
D.Layer 2 Outside (L2Out)
AnswerD

A Layer 2 Outside (L2Out) is specifically designed to extend a Layer 2 bridge domain to an external Layer 2 network. It allows the ACI fabric to connect to external switches and forward Layer 2 traffic without routing. This is achieved by mapping the bridge domain to an external VLAN on the L2Out. Thus, L2Out is the correct construct for extending a Layer 2 bridge domain to an external Layer 2 network.

Why this answer

To extend a Layer 2 bridge domain to an external Layer 2 network in Cisco ACI, the correct construct is a Layer 2 Outside (L2Out). L2Out maps the bridge domain to an external VLAN and allows Layer 2 traffic to traverse between the fabric and the external switch without routing. Other constructs like L3Out, Tenant, or VRF do not provide this Layer 2 extension capability.

Therefore, L2Out is the correct choice.

Exam trap

The trap here is confusing L2Out with L3Out; L2Out is for Layer 2 extension, while L3Out is for Layer 3 routing to external networks.

1794
MCQmedium

Given the following SD-WAN CLI output on a Cisco IOS-XE router: show sdwan omp routes 10.1.1.0/24, received, admin-distance: 250 via 10.0.0.1, interface GigabitEthernet0/0/1, color biz-internet, loss: 0, latency: 10 via 10.0.0.2, interface GigabitEthernet0/0/2, color 3g, loss: 1, latency: 50 Which statement is true?

A.The route via 10.0.0.1 (biz-internet) is preferred because it has lower loss and latency.
B.The route via 10.0.0.2 (3g) is preferred because it has a higher latency, which indicates a more stable path.
C.Both routes are equally preferred because OMP uses ECMP by default.
D.The admin-distance of 250 indicates that these routes are learned via BGP.
AnswerA

The SD-WAN OMP path-selection algorithm compares data-plane metrics such as loss, latency, and jitter for each transport tunnel, and a lower value is always preferred for loss and latency. Because the biz-internet path via 10.0.0.1 reports lower loss and lower latency than the 3G path via 10.0.0.2, it is selected as the active route. This metric-based choice is performed regardless of the underlying routing protocol used to transport the overlay.

Why this answer

OMP (Overlay Management Protocol) in Cisco SD-WAN selects the best path based on the lowest path cost, which is calculated using metrics such as loss, latency, and jitter. In this output, the route via 10.0.0.1 (biz-internet) has loss 0 and latency 10, which is lower than the route via 10.0.0.2 (3g) with loss 1 and latency 50, making it the preferred path. The admin-distance of 250 is specific to OMP routes and does not affect this comparison.

Exam trap

Cisco often tests the misconception that OMP uses ECMP by default for all routes, but in reality, OMP only load-balances across paths with identical metrics, and the admin-distance of 250 is frequently confused with BGP's admin-distance.

How to eliminate wrong answers

Option B is wrong because higher latency does not indicate a more stable path; OMP prefers lower latency and loss for optimal performance. Option C is wrong because OMP does not use ECMP by default for routes with different metrics; ECMP only applies when multiple paths have equal cost (same loss, latency, jitter). Option D is wrong because the admin-distance of 250 is the default for OMP routes, not BGP; BGP has a default admin-distance of 20 for eBGP and 200 for iBGP.

1795
Drag & Dropmedium

Drag and drop the steps of a VM live migration process in vSphere into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order for vMotion live migration begins with initiating the migration from the source host (A). Then, initial memory pages are copied to the destination (B). While the VM continues running, dirty memory pages are tracked and iteratively copied (C).

Next, the VM is quiesced and the final state is copied (D). Finally, the VM is resumed on the destination host (E).

Exam trap

A common mistake is to think that the VM must be quiesced before copying final state, but quiescing happens after iterative copying to ensure consistency. Also, resuming the VM on the destination is the last step, not the first.

1796
MCQhard

An engineer configures IP SLA 30 to monitor the one-way delay to a remote site using UDP jitter. The operation is used to adjust routing metrics via route maps. The engineer notices that the IP SLA operation shows 'State: Active' but the one-way delay values are inconsistent, sometimes showing negative values. What is the most likely cause?

A.The IP SLA operation is not configured with a 'request-data-size' that matches the remote router's MTU, causing fragmentation and delay variations.
B.The source and destination routers do not have synchronized clocks via NTP, causing one-way delay calculations to be inaccurate.
C.The IP SLA operation is using a 'frequency' that is too high, causing the probes to overlap and corrupt the statistics.
D.The remote router's IP SLA responder is not configured, so the source is using a different method to estimate delay.
AnswerB

The one-way delay measurement in an IP SLA UDP jitter operation is computed by subtracting the source router's send timestamp from the destination router's receive timestamp. If the two routers' clocks are not synchronized via NTP (or an equivalent time source), the calculated difference will be offset by the clock skew, which can easily produce a negative value. Without NTP, the timestamps are meaningless for absolute one-way delay, even though round-trip time would still be valid.

Why this answer

IP SLA UDP jitter measures one-way delay by timestamping packets at both the source and destination. If the clocks on the two routers are not synchronized via NTP, the timestamps will be offset, leading to inaccurate (and sometimes negative) one-way delay values. Negative delay occurs when the destination timestamp appears earlier than the source timestamp due to clock skew.

Exam trap

Cisco often tests the concept that one-way delay measurements require synchronized clocks, while round-trip time (RTT) does not, leading candidates to overlook the NTP requirement when they see negative delay values.

How to eliminate wrong answers

Option A is wrong because the 'request-data-size' mismatch with MTU would cause fragmentation or packet loss, not negative one-way delay values; negative delay is a clock synchronization issue, not a size/fragmentation issue. Option C is wrong because a high 'frequency' might cause probe overlap or resource exhaustion, but it would not produce negative delay values; negative delay is specifically a timestamp/clock problem. Option D is wrong because if the remote router's IP SLA responder were not configured, the source would not be able to perform UDP jitter at all (the operation would fail or show 'Inactive'), not produce inconsistent negative delays.

1797
Multi-Selectmedium

Which two statements about 802.1X port-based authentication on a Cisco switch are true? (Choose two.)

Select 2 answers
A.The switch acts as the authenticator in the 802.1X framework.
B.The RADIUS server acts as the authenticator in the 802.1X framework.
C.802.1X can only be configured on router interfaces, not on switch ports.
D.EAP over LAN (EAPoL) is used between the supplicant and the authenticator.
E.802.1X authentication is only applicable to wireless networks.
AnswersA, D

In 802.1X the switch port enforces authentication, relaying EAP frames between supplicant and RADIUS server, so it is the authenticator. This satisfies the framework role the stem asks about, distinct from the supplicant (client) and authentication server.

Why this answer

Option A is correct because in the 802.1X framework the switch port functions as the authenticator, controlling access to the LAN by relaying credentials between the supplicant and the authentication server. Option D is correct because EAPoL (EAP over LAN, EtherType 0x888E) is the Layer 2 protocol used between the supplicant (client) and the authenticator (switch) to carry EAP authentication messages. Option B is wrong because the RADIUS server acts as the authentication server, not the authenticator; it validates credentials and returns Accept/Reject to the switch.

Option C is wrong because 802.1X is a port-based access control method configured on switch ports (and can also run on some router interfaces), not limited to routers. Option E is wrong because 802.1X is widely deployed on wired Ethernet switch ports as well as wireless networks.

Exam trap

350-401 often tests the three 802.1X roles — candidates confuse the authenticator (switch) with the authentication server (RADIUS), picking the RADIUS server as the authenticator because it performs the actual credential check.

1798
MCQmedium

Consider the following partial configuration on Router R1: ip sla 5 icmp-echo 10.5.5.5 frequency 10 ip sla schedule 5 life forever start-time now ip sla reaction-configuration 5 react rtt threshold-type immediate threshold-value 200 action-type triggerAndReset What is the effect of the 'action-type triggerAndReset' parameter?

A.It triggers an event once and then stops monitoring.
B.It triggers an event each time the RTT exceeds 200 ms and resets the counter after each trigger.
C.It triggers an event only if the RTT exceeds 200 ms for 5 consecutive probes.
D.It triggers an event and then immediately stops the IP SLA operation.
AnswerB

Under the 'immediate' threshold type, the IP SLA reaction fires as soon as a single RTT probe exceeds 200 ms. The 'triggerAndReset' action then resets the reaction counter to zero, enabling the condition to be re-triggered by the very next qualifying probe. This creates a repeating event stream for every individual crossing above 200 ms, rather than a one-time or sustained-detection alert. The IP SLA operation itself remains active and keeps generating probes, so each new violation is independently reported without administrative intervention.

Why this answer

The 'action-type triggerAndReset' parameter in the IP SLA reaction configuration causes the router to generate an event (e.g., a syslog message or SNMP trap) each time the measured round-trip time (RTT) exceeds the specified threshold of 200 ms. After each trigger, the monitoring state is reset, allowing the router to continue monitoring and trigger again on subsequent threshold violations. This is why option B is correct.

Exam trap

Cisco often tests the distinction between 'triggerAndReset' (which allows repeated triggers) and 'triggerOnly' (which triggers once and then stops monitoring), so the trap here is confusing 'triggerAndReset' with a one-time action or a consecutive-count threshold.

How to eliminate wrong answers

Option A is wrong because 'triggerAndReset' does not stop monitoring after the first event; it continues to monitor and can trigger multiple times. Option C is wrong because the configuration uses 'threshold-type immediate', which triggers on every single RTT violation, not after a consecutive count of 5. Option D is wrong because the IP SLA operation is scheduled with 'life forever' and is not stopped by the trigger; only an event is generated while the probe continues.

1799
MCQhard

A network engineer is configuring a Cisco IOS router to establish a site-to-site VPN using IPsec. The engineer wants to ensure that the VPN tunnel only carries traffic for the subnet 10.1.1.0/24 to 10.2.2.0/24. Which configuration element is required to define the interesting traffic?

A.ISAKMP policy
B.crypto map
C.IPsec transform set
D.crypto ACL (extended access list)
AnswerD

The crypto ACL, typically an extended access list, defines the interesting traffic that should be encrypted and sent through the VPN tunnel. It specifies the source and destination subnets, such as permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255. This ACL is referenced by the crypto map.

Why this answer

The crypto ACL, an extended access list, defines the interesting traffic that should be protected by IPsec. It specifies the source and destination addresses and ports. The crypto map then references this ACL to apply the IPsec policies.

Without the crypto ACL, the router would not know which packets to encrypt and send through the tunnel.

Exam trap

The trap here is confusing the roles of the various IPsec components; the crypto ACL defines interesting traffic, while the crypto map applies the policies.

1800
MCQmedium

An architect is designing an SD-Access fabric for a campus network that requires segmentation of guest, employee, and IoT traffic. The design must use Cisco TrustSec for policy enforcement. Which component is responsible for assigning the Security Group Tag (SGT) to endpoints upon authentication?

A.Cisco ISE
B.Fabric edge node
C.Fabric control plane node
D.Cisco DNA Center
AnswerA

Cisco ISE is the SDA identity and policy layer; during 802.1X, MAB, or web authentication it authenticates each endpoint and dynamically classifies it by assigning a Security Group Tag (SGT). The SGT is sourced from ISE and distributed to the fabric via RADIUS and pxGrid, so downstream devices use that tag rather than IP ACLs for consistent policy enforcement. Without ISE, no endpoint can be reliably associated with an SGT in a scalable SD-Access deployment.

Why this answer

Cisco ISE is the policy decision point in a TrustSec-enabled SD-Access fabric. When an endpoint authenticates via 802.1X, MAB, or web authentication, ISE evaluates the authentication result and the applicable authorization policy, then dynamically assigns a Security Group Tag (SGT) to the endpoint. This SGT is passed to the network access device (e.g., fabric edge node) via RADIUS attributes in the Access-Accept message, enabling consistent policy enforcement throughout the fabric.

Exam trap

Cisco often tests the distinction between the policy decision point (ISE) and the policy enforcement point (fabric edge node), so the trap here is that candidates mistakenly think the fabric edge node assigns the SGT because it applies the tag to packets, but the assignment occurs during authentication by ISE.

How to eliminate wrong answers

Option B is wrong because the fabric edge node is the enforcement point that applies the SGT to traffic based on the tag received from ISE, but it does not assign the SGT itself. Option C is wrong because the fabric control plane node (e.g., LISP map-server) manages endpoint-to-location mappings and handles EID-to-RLOC resolution, not SGT assignment. Option D is wrong because Cisco DNA Center is the management and orchestration platform for the SD-Access fabric; it provisions policies and configurations but does not dynamically assign SGTs during authentication.

Page 23

Page 24 of 26

Page 25