Courseiva

ENCOR 350-401 (350-401) — Questions 1801–1875

1923 questions total · 26pages · All types, answers revealed

Page 24

Page 25 of 26

Page 26
1801
Matchingmedium

Drag and drop each Netmiko device type on the left to its matching operating system on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Cisco IOS (classic)

Cisco NX-OS

Cisco IOS-XR

Cisco IOS-XE

Arista EOS

Why these pairings

cisco_ios is for classic IOS; cisco_nxos is for NX-OS; cisco_xr is for IOS-XR; cisco_xe is for IOS-XE.

1802
MCQmedium

Router R1 has the following OSPF configuration: interface GigabitEthernet0/0 ip address 10.1.1.1 255.255.255.0 ip ospf 1 area 0 ip ospf network point-to-point ! router ospf 1 router-id 1.1.1.1 network 10.0.0.0 0.255.255.255 area 0 What is the effect of the 'ip ospf network point-to-point' command on this interface?

A.It disables OSPF on the interface.
B.It changes the OSPF network type to point-to-point, eliminating DR/BDR election and reducing hello timer to 10 seconds.
C.It enables OSPF authentication on the interface.
D.It sets the OSPF cost to 1.
AnswerB

The `ip ospf network point-to-point` command changes the interface's OSPF network type to point-to-point, which suppresses DR/BDR election and treats the link as a direct point-to-point connection. On NBMA media this also lowers the hello interval from 30 seconds to 10 seconds and the dead interval from 120 seconds to 40 seconds, allowing faster neighbor detection and convergence while eliminating type-2 network LSA generation.

Why this answer

The 'ip ospf network point-to-point' command changes the OSPF network type on the interface from the default (broadcast for Ethernet) to point-to-point. This eliminates the need for a Designated Router (DR) and Backup Designated Router (BDR) election, as point-to-point links have only two neighbors. Additionally, the OSPF hello timer on a point-to-point network defaults to 10 seconds (versus 30 seconds for non-broadcast), and the dead timer is 40 seconds.

Exam trap

Cisco often tests the misconception that 'ip ospf network point-to-point' disables OSPF or changes timers to 30 seconds, when in fact it eliminates DR/BDR and sets hello to 10 seconds.

How to eliminate wrong answers

Option A is wrong because the command does not disable OSPF; it modifies the network type while OSPF remains active. Option C is wrong because OSPF authentication is configured separately using 'ip ospf authentication' or 'ip ospf authentication-key' commands, not by changing the network type. Option D is wrong because the OSPF cost is not set to 1 by this command; cost is derived from interface bandwidth (default 100 Mbps / bandwidth) or manually set with 'ip ospf cost'.

1803
MCQmedium

Examine the following configuration on a Cisco IOS-XE switch: interface GigabitEthernet1/0/6 switchport mode access authentication port-control auto dot1x pae authenticator dot1x timeout tx-period 3 dot1x max-req 3 dot1x timeout supp-timeout 10 What is the total time the switch will wait for a supplicant to respond before failing authentication?

A.30 seconds
B.9 seconds
C.10 seconds
D.13 seconds
AnswerB

The authenticator retransmits the EAP-Request/Identity frame with a tx-period of 3 seconds between retransmissions. With a maximum of three identity request attempts, the switch sends frames at 0s, 3s, and 6s, and then waits one final tx-period before declaring the client unresponsive. This yields a cumulative 9 seconds (3 × 3s) before the switch gives up on the unauthenticated host.

Why this answer

The switch waits for a supplicant to respond to each 802.1X EAP-Request/Identity frame. With `dot1x max-req 3`, the switch sends up to 3 retransmissions. The `dot1x timeout tx-period 3` sets the interval between retransmissions to 3 seconds.

Therefore, the total time before authentication fails is 3 retransmissions × 3 seconds = 9 seconds.

Exam trap

Cisco often tests the distinction between `tx-period` (retransmission interval) and `supp-timeout` (response wait time), leading candidates to mistakenly add or multiply the wrong timers to calculate the total authentication timeout.

How to eliminate wrong answers

Option A is wrong because 30 seconds would be the result if you incorrectly multiplied max-req (3) by supp-timeout (10), but supp-timeout is the time the switch waits for a response from the supplicant after sending a request, not the retransmission interval. Option C is wrong because 10 seconds is the supp-timeout value, which is the time the switch waits for a single EAP response before retransmitting, not the total time for all retransmissions. Option D is wrong because 13 seconds might be a sum of tx-period (3) and supp-timeout (10), but the total time is calculated as max-req × tx-period, not an addition of these timers.

1804
Drag & Dropmedium

Drag and drop the steps of network documentation and change management workflow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Change management begins with a request and impact assessment, followed by approval. After implementation, verification ensures success, and finally the documentation is updated to reflect the change.

1805
Drag & Dropmedium

Drag and drop the steps of Cisco IBNS 2.0 policy configuration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

IBNS 2.0 uses a modular policy framework. First, define the authentication template to specify the method (e.g., dot1x, MAB). Second, create the policy map that references the template and defines the behavior.

Third, apply the policy map to the interface. Fourth, enable authentication on the interface. Finally, verify the configuration using show commands.

1806
MCQhard

A network engineer is implementing VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. The fabric uses LISP for control plane and VXLAN for data plane. Which component is responsible for mapping endpoint IP addresses to fabric edge nodes?

A.Fabric edge node
B.Fabric intermediate node
C.Fabric border node
D.Control plane node
AnswerD

The control plane node in a Cisco SD-Access fabric runs the LISP Map-Server and Map-Resolver functions. It maintains the mapping database of endpoint IP addresses to fabric edge nodes (RLOCs). When an edge node needs to reach an endpoint, it sends a Map-Request to the control plane node, which responds with the Map-Reply containing the RLOC of the edge node where the endpoint is located. This enables VXLAN encapsulation and forwarding.

Why this answer

In Cisco SD-Access, the control plane node runs LISP Map-Server and Map-Resolver. It maintains the mapping of endpoint IP addresses to the RLOC of the fabric edge node where the endpoint is connected. When an edge node needs to forward traffic to an endpoint, it queries the control plane node to obtain the mapping, enabling VXLAN encapsulation.

The border and intermediate nodes do not perform this mapping function.

Exam trap

The trap here is confusing the roles of fabric nodes; the control plane node is the one that provides the mapping service, not the edge or border nodes.

1807
MCQhard

A network security team is deploying MACsec on a Cisco Catalyst 9000 switch uplink between two buildings to protect Layer 2 traffic. The team wants to ensure that the link encrypts traffic and that the peer is authenticated before secure communication begins. Which configuration approach meets these requirements?

A.Enable IPsec transport mode on the switch uplink with a crypto map and IKEv2 pre-shared key.
B.Enable port security with sticky MAC addresses and storm control on the uplink to secure the connection.
C.Enable MACsec with MKA using a pre-shared key or 802.1X-derived CAK, and set the switchport to macsec desired or must.
D.Enable 802.1AE without MKA and manually configure static secure associations on both ends.
AnswerC

MACsec on Catalyst 9000 uses the MACsec Key Agreement protocol to negotiate secure associations and authenticate peers. Configuring MKA with a connectivity association key either as a pre-shared key or derived from 802.1X, and setting the interface to macsec desired or macsec must, ensures encryption and peer authentication before traffic passes, which matches the stated requirement.

Why this answer

MACsec provides Layer 2 hop-by-hop encryption and integrity using 802.1AE, with the MACsec Key Agreement protocol handling key exchange and peer authentication. On Catalyst 9000, the supported design uses MKA with a connectivity association key from a pre-shared key or 802.1X, plus an interface mode of macsec desired or macsec must to enforce encrypted, authenticated links.

Exam trap

The trap here is confusing Layer 3 IPsec with Layer 2 MACsec and assuming a crypto map can be applied to a switch uplink for hop-by-hop encryption.

1808
MCQmedium

interface GigabitEthernet0/0 ip address 10.0.0.1 255.255.255.252 ip ospf network point-to-multipoint ip ospf hello-interval 30 ! router ospf 1 network 10.0.0.0 0.0.0.3 area 0 What is the effect of this configuration?

A.OSPF will use a 30-second hello interval and form adjacencies with all neighbors without DR/BDR election.
B.OSPF will use a 10-second hello interval and elect a DR/BDR.
C.OSPF will use a 30-second hello interval and elect a DR/BDR.
D.OSPF will use a 10-second hello interval and form adjacencies with all neighbors without DR/BDR.
AnswerA

In point-to-multipoint mode, OSPF treats each remote router as if connected by a separate point-to-point link, so a DR/BDR election is unnecessary and never occurs. The default hello interval for this network type is 30 seconds, and full adjacencies are formed with every neighbor individually. This allows the network to function correctly over non-broadcast multipoint topologies like Frame Relay or DMVPN without relying on a central hub-and-spoke election process.

Why this answer

The configuration sets the OSPF network type to point-to-multipoint, which by default uses a 30-second hello interval and does not perform DR/BDR election. The explicit 'ip ospf hello-interval 30' command confirms this interval, overriding any default. Therefore, OSPF will form adjacencies with all neighbors without electing a DR/BDR.

Exam trap

Cisco often tests the default hello intervals for different OSPF network types, and the trap here is that candidates mistakenly assume a 10-second hello interval (which is the default for broadcast and point-to-point networks) applies to point-to-multipoint, or that point-to-multipoint still requires DR/BDR election.

How to eliminate wrong answers

Option B is wrong because the hello interval is explicitly set to 30 seconds, not 10 seconds, and point-to-multipoint does not elect a DR/BDR. Option C is wrong because while the hello interval is correctly 30 seconds, point-to-multipoint networks do not elect a DR/BDR. Option D is wrong because the hello interval is 30 seconds, not 10 seconds, and although point-to-multipoint correctly avoids DR/BDR election, the hello interval mismatch makes this option incorrect.

1809
MCQeasy

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast neighbors 10.0.1.2 advertised-routes Network Next Hop Metric LocPrf Weight Path *> 172.16.0.0/16 10.0.1.1 0 100 0 i *> 172.16.1.0/24 10.0.1.1 0 100 0 i Total number of prefixes 2 Based on this output, what can be concluded?

A.R1 is receiving 2 prefixes from neighbor 10.0.1.2.
B.R1 is advertising 2 prefixes to neighbor 10.0.1.2.
C.Neighbor 10.0.1.2 is advertising these routes to R1.
D.The routes are being advertised with a next hop of 10.0.1.2.
AnswerB

This option is correct. The output is explicitly labeled as the set of routes R1 advertises to neighbor 10.0.1.2. The `advertised-routes` keyword causes the router to display the contents of the per-neighbor Adj-RIB-Out after outbound route policies have been applied, and the final line in that output reports a total of 2 prefixes. Therefore, R1 is sending exactly two prefixes toward 10.0.1.2, not receiving them.

Why this answer

The command 'show bgp ipv4 unicast neighbors 10.0.1.2 advertised-routes' specifically displays the routes that Router R1 is sending to the BGP neighbor at 10.0.1.2. The output shows two prefixes (172.16.0.0/16 and 172.16.1.0/24) with a next hop of 10.0.1.1 (R1's own interface), confirming these are routes R1 is advertising. Therefore, option B is correct.

Exam trap

Cisco often tests the distinction between 'advertised-routes' and 'received-routes' keywords, trapping candidates who confuse which device is the sender versus receiver in the BGP neighbor relationship.

How to eliminate wrong answers

Option A is wrong because the command shows advertised routes, not received routes; to see received routes, one would use 'show bgp ipv4 unicast neighbors 10.0.1.2 received-routes'. Option C is wrong because the output indicates R1 is the advertiser, not the neighbor; the neighbor 10.0.1.2 is the recipient of these routes. Option D is wrong because the next hop in the output is 10.0.1.1 (R1's own address), not 10.0.1.2, which would be the case if R1 were receiving routes from the neighbor.

1810
Drag & Dropmedium

Drag and drop the steps of EIGRP redistribution from OSPF with metric seeding into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, the EIGRP routing process must be entered. Then, the redistribute command is used with the OSPF process and a metric. Optionally, route-map filtering can be applied.

Finally, verification ensures routes appear in the EIGRP topology table.

1811
Drag & Dropmedium

Drag and drop the steps of IPv6 ACL configuration and application into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order is: create the ACL with deny/permit entries, apply it inbound on an interface, then verify with show commands. This follows standard Cisco IOS ACL configuration workflow.

1812
MCQeasy

What is the default SNMP trap port number?

A.UDP 161
B.UDP 162
C.TCP 161
D.TCP 162
AnswerB

The correct answer. SNMP traps and informs are sent from the SNMP agent to the network management station (NMS) using UDP as the transport protocol, with a destination port of 162. This is the well-known port assigned by IANA for SNMP notifications. UDP is preferred because it is lightweight and connectionless, ensuring that traps can be transmitted quickly even in unhealthy network conditions, although it also means traps may be lost; SNMPv2 introduces informs to provide acknowledgment.

Why this answer

SNMP traps are unsolicited notifications sent from an SNMP agent to a network management system (NMS) to alert about significant events. By default, these trap messages are sent over UDP port 162, as defined in RFC 1157. UDP is used because traps are connectionless and do not require acknowledgment, making them efficient for event-driven notifications.

Exam trap

Cisco often tests the distinction between SNMP query ports (UDP 161) and trap ports (UDP 162), and candidates frequently confuse them or incorrectly assume TCP is used for SNMP traps.

How to eliminate wrong answers

Option A is wrong because UDP 161 is the default port for SNMP queries (Get, GetNext, GetBulk, Set) from the NMS to the agent, not for traps. Option C is wrong because SNMP traps never use TCP; they rely on UDP for its low-overhead, connectionless transport. Option D is wrong because TCP 162 is not a valid SNMP trap port; traps use UDP 162, and TCP is not used for SNMP trap delivery.

1813
MCQhard

A network engineer is implementing VXLAN with an Ethernet VPN (EVPN) control plane in a data center. The underlay is a Layer 3 IP network. The engineer wants to ensure that the VXLAN tunnel endpoints (VTEPs) can discover each other and that the fabric supports multihoming with all-active forwarding. Which technology should be used?

A.VXLAN with static unicast flooding and no control plane
B.VXLAN with PIM-SM multicast underlay
C.VXLAN with OSPF as the underlay routing protocol
D.VXLAN with EVPN as the control plane
AnswerD

EVPN provides a standards-based control plane for VXLAN, enabling automatic VTEP discovery, MAC address learning, and support for multihoming with all-active forwarding. EVPN uses BGP to distribute MAC and IP reachability information, and it supports Ethernet Segment (ES) multihoming, which allows a host to connect to multiple VTEPs with all links active. This matches the requirements for dynamic discovery and all-active multihoming.

Why this answer

EVPN is the correct choice because it provides a scalable control plane for VXLAN, enabling automatic VTEP discovery and MAC learning via BGP. It also supports multihoming with all-active forwarding through Ethernet Segment configurations, which allows a device to connect to multiple VTEPs simultaneously. Other options either lack a control plane or do not support the required multihoming capabilities.

Exam trap

The trap here is confusing underlay routing protocols like OSPF or multicast with the overlay control plane, or assuming that static VXLAN can provide dynamic discovery and multihoming.

1814
MCQmedium

A large enterprise is redesigning its campus network to support 5000 users across three buildings. The design must provide high availability and fast convergence in case of a link failure. The network engineer is considering using Spanning Tree Protocol (STP) in the access layer. What is the primary design concern with using STP in this scenario?

A.STP will cause slow convergence and inefficient use of redundant links.
B.STP requires all switches to be in the same VLAN to function correctly.
C.STP cannot be used with 5000 users due to MAC address table limitations.
D.STP will cause broadcast storms in a three-building design.
AnswerA

STP (802.1D) prevents loops by placing redundant switch ports in a blocking state, leaving only one active path to a given root bridge. During a topology change, the listening and learning forward-delay timers (default 15 seconds each) plus the max-age timer can cause convergence to take 30–50 seconds, far too slow for high-availability designs. Meanwhile, the blocked redundant links remain physically connected but carry no user traffic, wasting available bandwidth and forcing traffic over a single, possibly congested path. This is why modern designs often use RSTP or link aggregation, which either converge faster or utilize all links in an EtherChannel.

Why this answer

STP (802.1D) converges slowly, typically taking 30-50 seconds (listening + learning states) after a topology change. In a large campus network with 5000 users, this delay causes unacceptable downtime. Additionally, STP blocks redundant links to prevent loops, wasting bandwidth that could be used for load balancing.

Modern alternatives like Rapid PVST+ (802.1w) or MST (802.1s) offer sub-second convergence, making classic STP a poor choice for high-availability designs.

Exam trap

Cisco often tests the misconception that STP is a suitable high-availability solution, when in fact its slow convergence and blocked link inefficiency make it a poor choice for modern campus networks; candidates may overlook the need for RSTP or MST in the design.

How to eliminate wrong answers

Option B is wrong because STP does not require all switches to be in the same VLAN; it operates per VLAN (PVST/PVST+) or per instance (MST), and switches in different VLANs can still participate in STP. Option C is wrong because STP does not impose MAC address table limitations based on user count; MAC table size is a hardware limitation of the switch ASIC, not a protocol constraint, and 5000 users is well within typical switch capacities. Option D is wrong because STP is designed to prevent broadcast storms by blocking redundant paths; broadcast storms are caused by loops, which STP actively eliminates, not creates.

1815
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP relay agent for a remote subnet 10.10.10.0/24. The DHCP server is located at 172.16.1.100. The engineer issues the command 'ip helper-address 172.16.1.100' on interface GigabitEthernet0/0, which is the gateway for that subnet. However, clients on the subnet are not receiving IP addresses. What is the most likely cause?

A.The 'service dhcp' command is disabled globally on the router.
B.The DHCP server is not reachable from the router because a route to 172.16.1.100 is missing.
C.The 'ip helper-address' command must be configured on the interface facing the DHCP server, not the client-facing interface.
D.The DHCP server is configured to use a different subnet mask than the clients require.
AnswerB

For DHCP relay to work, the router must have a route to the DHCP server's IP address. If no route exists, the router cannot forward the relayed packets, and clients will not receive addresses. This is a common oversight when configuring relay agents in a new environment.

Why this answer

The 'ip helper-address' command relays DHCP broadcasts to a specified server, but the router must have a route to that server. Without a route to 172.16.1.100, the relayed packets are dropped, and clients cannot obtain addresses. Ensuring IP reachability to the DHCP server is essential for successful relay operation.

Exam trap

The trap here is assuming that configuring the helper address alone is sufficient, overlooking the need for a route to the DHCP server.

1816
MCQhard

A network engineer runs the following command on Router R4: R4# show mpls ldp neighbor vrf CUSTOMER-C Peer LDP Ident: 10.0.0.5:0; Local LDP Ident 10.0.0.4:0 TCP connection: 10.0.0.5.646 - 10.0.0.4.646 State: Oper; Msgs sent/rcvd: 500/500; Downstream Up time: 02:30:00 LDP discovery sources: GigabitEthernet0/0.300, Src IP addr: 10.0.1.2 hello sent/rcvd: 1000/1000 Addresses bound to peer LDP Ident: 10.0.1.2 10.0.2.2 Based on this output, what can be concluded?

A.LDP is not configured for VRF CUSTOMER-C
B.The LDP session is operational with peer 10.0.0.5
C.The LDP session is using TCP port 179
D.The peer is discovered via OSPF
AnswerB

The neighbor state 'Oper' confirms the LDP session is up and exchanging label mapping messages with the peer at 10.0.0.5. This is the only accurate conclusion among the choices. Operational implies the TCP connection on port 646 and the LDP initialization handshake have completed successfully.

Why this answer

The output shows 'State: Oper' and 'Up time: 02:30:00', which confirms the LDP session is fully operational. The peer LDP Ident is 10.0.0.5:0 and the local LDP Ident is 10.0.0.4:0, with a TCP connection established on port 646. This directly indicates that the LDP session with peer 10.0.0.5 is up and running.

Exam trap

Cisco often tests the distinction between LDP (TCP port 646) and BGP (TCP port 179), and candidates may confuse the 'Oper' state with a BGP session or assume LDP uses port 179 by default.

How to eliminate wrong answers

Option A is wrong because the command 'show mpls ldp neighbor vrf CUSTOMER-C' successfully returned detailed neighbor information, proving LDP is configured for that VRF. Option C is wrong because LDP uses TCP port 646, not port 179 (which is used by BGP). Option D is wrong because the output does not mention OSPF or any IGP; LDP discovery sources show a directly connected interface (GigabitEthernet0/0.300) and the peer's IP addresses, but the underlying IGP is not specified.

1817
Multi-Selectmedium

Which two statements about Type 1 and Type 2 hypervisors are true? (Choose two.)

Select 2 answers
A.A Type 1 hypervisor runs directly on the physical hardware without a host operating system.
B.A Type 2 hypervisor runs directly on the physical hardware without a host operating system.
C.VMware ESXi is an example of a Type 2 hypervisor.
D.VMware Workstation is an example of a Type 2 hypervisor.
E.Type 1 hypervisors are typically used for desktop virtualization in enterprise environments.
AnswersA, D

A Type 1 hypervisor, such as ESXi or Hyper-V, installs directly on bare metal and controls hardware itself, with no underlying host OS. This matches the stem's statement that it runs directly on physical hardware without a host operating system.

Why this answer

Option A is correct because a Type 1 (bare-metal) hypervisor, such as VMware ESXi, Microsoft Hyper-V Server, or Citrix XenServer, installs and runs directly on the physical hardware and does not require an underlying host operating system. Option D is correct because VMware Workstation is a Type 2 (hosted) hypervisor that installs as an application on top of an existing host OS like Windows or Linux. Option B is incorrect because it describes a Type 1, not a Type 2, hypervisor — Type 2 hypervisors require a host operating system.

Option C is incorrect because VMware ESXi is a Type 1 bare-metal hypervisor, not Type 2. Option E is incorrect because Type 1 hypervisors are typically deployed in data centers and server virtualization scenarios, whereas Type 2 hypervisors are more commonly used for desktop virtualization and testing.

Exam trap

The trap here is confusing the definitions of Type 1 and Type 2 hypervisors, or misidentifying common products like ESXi (Type 1) and Workstation (Type 2).

1818
Multi-Selectmedium

Which two statements about SPAN and RSPAN limitations are true? (Choose two.)

Select 2 answers
A.SPAN can cause increased CPU utilization on the switch if many packets are mirrored.
B.SPAN can monitor control plane traffic such as routing protocol updates by default.
C.RSPAN requires that the RSPAN VLAN be pruned from all trunks to avoid loops.
D.A SPAN destination port cannot be used for normal network traffic.
E.RSPAN can be used to monitor traffic on a Layer 3 routed interface.
AnswersA, D

Mirroring copies every matching frame to the destination port, so the supervisor and forwarding ASIC must process duplicate traffic. This extra per-packet work consumes switch CPU and backplane bandwidth, which is the SPAN limitation the stem asks about.

Why this answer

Option A is correct because SPAN mirrors copies of every matched frame to the destination port, and when large volumes of traffic are mirrored, the switch must replicate and forward those frames, which increases CPU and internal forwarding load. Option D is correct because a SPAN destination port is dedicated to receiving mirrored traffic; by design it does not participate in normal Layer 2 forwarding, so it cannot be used as a regular user or uplink port while configured as a destination. Option B is not correct because SPAN does not monitor control plane traffic such as routing protocol updates by default; control plane traffic is handled by the switch CPU and requires specific features like CPU port mirroring or control plane policing to observe.

Option C is not correct because RSPAN VLANs should be allowed on the trunks carrying the monitored traffic, not pruned everywhere; pruning the RSPAN VLAN from all trunks would prevent the mirrored traffic from reaching the destination. Option E is not correct because RSPAN monitors traffic at Layer 2 and is not used to monitor traffic on a Layer 3 routed interface directly.

Exam trap

350-401 often tests the misconception that SPAN can monitor control plane traffic by default or that RSPAN VLANs should be pruned, when in fact they must be allowed on trunks.

1819
MCQmedium

A network engineer is designing a QoS policy for a WAN edge router. The router must prioritize voice traffic with a strict priority queue and ensure that call signaling traffic is not starved. Which queuing mechanism should the engineer configure to meet these requirements?

A.Class-Based Weighted Fair Queuing (CBWFQ)
B.Low Latency Queuing (LLQ)
C.First-In, First-Out (FIFO) queuing
D.Weighted Random Early Detection (WRED)
AnswerB

LLQ combines a strict priority queue with CBWFQ for other traffic. Voice traffic can be placed in the priority queue to ensure minimal delay and jitter, while call signaling and other traffic are handled by CBWFQ with guaranteed bandwidth. This prevents the priority queue from starving other queues because LLQ includes a policer to limit the priority queue bandwidth.

Why this answer

LLQ is designed to provide strict priority queuing for delay-sensitive traffic like voice, while still offering bandwidth guarantees for other classes such as call signaling. The priority queue is policed to prevent starvation of other queues, ensuring that signaling traffic gets its share of bandwidth.

Exam trap

The trap here is assuming that CBWFQ alone can provide strict priority, when it actually provides weighted fair queuing without a priority queue.

1820
MCQmedium

A network engineer executes the following command on Router R8: R8# show ip sla monitor summary IP SLAs Monitor Summary Codes: * active, ^ inactive, ~ pending ID Type Destination Stats Return Code Last *1 icmp-echo 192.168.8.10 Success OK 1 ^2 udp-jitter 192.168.8.20 Success OK 2 *3 icmp-echo 192.168.8.30 Success OK 3 Based on this output, which IP SLA operations are currently active?

A.Only ID 1
B.Only ID 2
C.IDs 1 and 3
D.All three operations
AnswerC

IDs 1 and 3 are the correct selection because both entries display an asterisk (*) in the `show ip sla` output, which indicates that each operation is active, scheduled, and currently sending synthetic probe traffic. The presence of * on both entries confirms they are the only operations meeting the active-status criterion. No other entries besides IDs 1 and 3 show this marker, making this the correct answer.

Why this answer

The output shows that IP SLA operations with IDs 1 and 3 are marked with an asterisk (*), which according to the legend indicates 'active' status. Operation ID 2 is marked with a caret (^), meaning it is 'inactive'. Therefore, only IDs 1 and 3 are currently active.

Exam trap

Cisco often tests the legend interpretation in 'show ip sla monitor summary' output, where candidates may overlook the codes (*, ^, ~) and assume all listed operations are active, leading them to select 'All three operations' instead of correctly identifying only those marked with an asterisk.

How to eliminate wrong answers

Option A is wrong because it claims only ID 1 is active, but ID 3 also shows an asterisk (*) indicating active status. Option B is wrong because ID 2 is marked with a caret (^) meaning inactive, not active. Option D is wrong because ID 2 is not active; only IDs 1 and 3 are active.

1821
Multi-Selectmedium

Which two statements about the Cisco SD-Access fabric roles are true? (Choose two.)

Select 2 answers
A.The fabric edge node is responsible for connecting end devices and enforcing SGT-based policies.
B.The fabric border node is responsible for connecting the SD-Access fabric to external Layer 3 networks.
C.The control plane node is responsible for encapsulating and forwarding user traffic across the fabric.
D.The intermediate node is responsible for policy enforcement and traffic segmentation within the fabric.
E.The wireless controller in SD-Access acts as a dedicated fabric border node for wireless traffic.
AnswersA, B

Fabric edge nodes sit at the fabric boundary, connecting wired and wireless endpoints into the VXLAN overlay and applying group-based policy via SGT enforcement at the ingress point, satisfying the stem's requirement for both endpoint attachment and policy enforcement.

Why this answer

Option A is correct because the fabric edge node is the device (typically a Catalyst switch) that connects wired endpoints into the SD-Access fabric, registers them with the control plane, and enforces group-based policies using SGTs (Security Group Tags) via SGACL and CTS. Option B is correct because the fabric border node provides the handoff between the SD-Access fabric and external Layer 3 networks (such as the data center, WAN, or Internet), performing VRF-aware route leaking and SGT propagation across the fabric boundary. Option C is incorrect because the control plane node (running LISP map-server/map-resolver) handles endpoint registration and location mapping, not user traffic encapsulation; that is the role of edge and border nodes using VXLAN.

Option D is incorrect because intermediate nodes simply forward VXLAN-encapsulated traffic between fabric edge and border nodes based on the underlay routing, and they do not perform policy enforcement or segmentation. Option E is incorrect because in SD-Access the wireless controller (WLC) integrates with the fabric as a fabric-enabled WLC (or is replaced by embedded wireless on Catalyst 9800), not as a dedicated fabric border node for wireless traffic.

Exam trap

350-401 often tests the specific functions of each fabric role, and candidates may confuse intermediate nodes with edge nodes or think the WLC is a border node.

1822
MCQhard

A network engineer is configuring IPsec VPN on a Cisco IOS router. The requirement is to encrypt traffic between two sites using IKEv2. The engineer wants to ensure that the IKEv2 proposal uses AES-256 for encryption, SHA-256 for integrity, and Diffie-Hellman group 14. Which command correctly defines the IKEv2 proposal with these parameters?

A.crypto ikev2 proposal PROP encryption aes-cbc-256 integrity sha256 group 14
B.crypto ikev2 keyring KEYRING peer SITE address 1.1.1.1 pre-shared-key local secret
C.crypto isakmp policy 10 encryption aes 256 hash sha256 group 14
D.crypto ikev2 policy POLICY proposal PROP encryption aes-256 integrity sha256 group 14
AnswerA

This command sequence under crypto ikev2 proposal correctly specifies AES-CBC-256 encryption, SHA-256 integrity, and Diffie-Hellman group 14. In Cisco IOS, the IKEv2 proposal is configured with the encryption, integrity, and group keywords, and this syntax matches the required parameters for the proposal.

Why this answer

The correct command to define an IKEv2 proposal with specific encryption, integrity, and DH group is under crypto ikev2 proposal, using the encryption, integrity, and group keywords. The policy command only references a proposal, and ISAKMP policy is for IKEv1. The keyring is for authentication, not proposal parameters.

Exam trap

The trap here is mixing IKEv1 ISAKMP policy syntax with IKEv2 proposal syntax, or placing proposal parameters under the policy command.

1823
MCQmedium

A service provider is deploying NFV to offer managed SD-WAN services to enterprise customers. The architect must place virtual network functions (VNFs) such as vEdge routers and firewalls in the provider's data center. Which VNF placement model allows the provider to chain these functions efficiently and scale per customer?

A.Place all VNFs for a customer on a single hypervisor host and use internal virtual switches to chain them.
B.Use a centralized service chain with a service graph that defines the order of VNFs, and deploy VNFs on separate hosts for redundancy.
C.Deploy each VNF as a separate virtual machine on a dedicated physical server to maximize performance.
D.Use a single VNF that combines routing and firewall functions to avoid chaining complexity.
AnswerB

A centralized service chain driven by a service graph is the correct architecture because the graph explicitly models the ordered sequence of VNFs (e.g., firewall then WAN optimizer) independent of their physical placement. The SD-WAN controller can then program edge routers to steer traffic through the chain while orchestrators deploy VNFs on separate hosts to achieve high availability, failover, and per-customer customization. This separates the logical service policy from the underlying compute infrastructure, allowing the chain to be scaled horizontally and replayed across redundant hosts without reengineering the policy.

Why this answer

A centralized service chain with a service graph allows the provider to define the ordered sequence of VNFs (e.g., vEdge router then firewall) and deploy them on separate hosts for redundancy. This model aligns with NFV MANO (Management and Orchestration) principles, enabling efficient scaling per customer by instantiating VNFs as needed while maintaining the service chain across hypervisors.

Exam trap

Cisco often tests the misconception that placing all VNFs on a single host (Option A) is simpler and efficient, but the trap is that this violates NFV's high-availability and multi-tenant scaling requirements, which are core to service provider SD-WAN offerings.

How to eliminate wrong answers

Option A is wrong because placing all VNFs for a customer on a single hypervisor host creates a single point of failure and limits scalability; internal virtual switches do not provide the orchestrated service chaining required for multi-tenant NFV deployments. Option C is wrong because dedicating a physical server per VNF defeats the purpose of NFV (virtualization and resource pooling), leading to high cost and poor scalability. Option D is wrong because combining routing and firewall into a single VNF violates the modular VNF design principle and prevents independent scaling or updating of individual functions, which is essential for multi-tenant SD-WAN services.

1824
Drag & Dropmedium

Drag and drop the steps of configuring AAA on a Cisco IOS device into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

AAA configuration requires first enabling AAA globally, then defining the authentication method list, applying it to login, and optionally specifying a fallback method like local. Finally, verify with debug commands.

1825
MCQhard

A network engineer runs the following command on Switch SW3: SW3# show spanning-tree vlan 30 VLAN0030 Spanning tree enabled protocol ieee Root ID Priority 24606 Address aabb.cc00.0400 Cost 12 Port 2 (GigabitEthernet0/2) Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Bridge ID Priority 32798 (priority 32768 sys-id-ext 30) Address aabb.cc00.0500 Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec Aging Time 300 sec Interface Role Sts Cost Prio.Nbr Type ------------------- ---- --- --------- -------- ------------------------------ Gi0/1 Desg FWD 4 128.1 P2p Gi0/2 Root FWD 12 128.2 P2p Gi0/3 Desg FWD 4 128.3 P2p Based on this output, what is the root path cost from SW3 to the root bridge for VLAN 30?

A.4
B.12
C.16
D.20
AnswerB

The show spanning-tree command displays the Root ID section, which includes the bridge's own root path cost. In this output, the Cost field under Root ID is 12, indicating the total accumulated path cost from this switch to the root bridge. This metric is used for root port selection and is the correct answer. It is not a per-interface value but the sum of all outgoing port costs along the best path.

Why this answer

The root path cost is the cumulative cost from the local switch to the root bridge. In the output, the Root ID section shows a cost of 12, and the Gi0/2 interface is the root port with a cost of 12. This cost represents the total path cost from SW3 to the root bridge for VLAN 30, making option B correct.

Exam trap

Cisco often tests the distinction between the root port's cost (which is the root path cost) and the cost of other ports, leading candidates to mistakenly select the cost of a designated port (like 4) instead.

How to eliminate wrong answers

Option A is wrong because 4 is the port cost of Gi0/1 and Gi0/3, which are designated ports, not the root path cost. Option C is wrong because 16 is not a value present in the output; it might be a sum of two port costs but does not represent the root path cost. Option D is wrong because 20 is not a value present in the output; it is the Max Age timer value, not a path cost.

1826
Multi-Selecthard

Which THREE of the following are characteristics of Cisco TrustSec (CTS) security architecture?

Select 3 answers
A.It uses IPsec to encrypt traffic between network devices.
B.It uses VLANs to segment traffic based on security roles.
C.It uses Security Group Tags (SGTs) to classify traffic.
D.It provides data confidentiality using IEEE 802.1AE (MACsec) encryption.
E.It uses Security Group Access Control Lists (SGACLs) to enforce policies.
AnswersC, D, E

SGTs are used for classification.

Why this answer

C is correct because Cisco TrustSec uses Security Group Tags (SGTs) to classify traffic based on user, device, or role, rather than IP addresses. SGTs are 16-bit values (0–65535) assigned dynamically via authentication (e.g., 802.1X) or static mapping, enabling scalable policy enforcement.

Exam trap

Cisco often tests the misconception that TrustSec uses VLANs or IPsec for segmentation and encryption, when in fact it uses SGTs for classification and MACsec for Layer 2 encryption.

1827
MCQhard

A network engineer is implementing a first-hop redundancy protocol on a pair of Cisco switches. The requirement is to provide sub-second failover for IPv4 hosts and to load-balance traffic between the two switches for different VLANs. Which protocol should be used to meet these requirements?

A.ICMP Router Discovery Protocol (IRDP)
B.Hot Standby Router Protocol (HSRP) version 1
C.Virtual Router Redundancy Protocol (VRRP) version 3
D.Gateway Load Balancing Protocol (GLBP)
AnswerD

GLBP provides both sub-second failover and automatic load balancing across multiple gateways. It uses an Active Virtual Gateway (AVG) and up to four Active Virtual Forwarders (AVFs) to share traffic. Different hosts can be assigned different virtual MAC addresses, distributing the load. This meets the requirements for sub-second failover and load balancing across VLANs without manual per-VLAN group configuration.

Why this answer

GLBP is designed to provide both redundancy and load balancing. It elects an Active Virtual Gateway that assigns virtual MAC addresses to up to four Active Virtual Forwarders, allowing multiple switches to share the traffic load while providing sub-second failover. HSRP and VRRP can provide redundancy but require manual configuration for load balancing, and IRDP lacks the necessary features.

Exam trap

The trap here is assuming that HSRP or VRRP can automatically load-balance traffic across multiple switches without additional configuration, but only GLBP provides native load-balancing capabilities.

1828
MCQmedium

A network engineer needs to verify the performance of a WAN link between two Cisco routers. The engineer configures an IP SLA operation on Router A that sends ICMP echo requests to Router B every 60 seconds and stores the results. After a week, the engineer checks the results and finds that the operation has been running successfully, but no history data is available. What is the most likely reason for the lack of history data?

A.The IP SLA operation was not configured to collect history statistics.
B.The IP SLA responder was not enabled on Router B.
C.The IP SLA operation was not configured with a schedule.
D.The IP SLA operation was configured with the wrong frequency.
AnswerA

IP SLA operations do not collect history data by default. The 'history statistics' command must be configured under the IP SLA operation to enable collection of historical data. Without it, only the latest results are available. The engineer saw successful results but no history, which points to missing history configuration.

Why this answer

IP SLA operations only collect history statistics when explicitly configured with the 'history statistics' command. Without this, only the most recent results are available. The engineer saw successful results, indicating the operation ran, but no history was stored because the history collection was not enabled.

Enabling history statistics allows the router to maintain a record of past operations for analysis.

Exam trap

The trap here is assuming that IP SLA automatically stores history data once the operation runs successfully.

1829
MCQmedium

A network architect is designing a Python script that will retrieve interface statistics from a Cisco IOS XE device using the RESTCONF API. The script must authenticate with a username and password, and all communication must be encrypted. The device is configured with the 'restconf' and 'ip http secure-server' commands. Which HTTP method and authentication mechanism should the script use to retrieve the data?

A.PATCH with Basic Authentication over HTTPS
B.PUT with Token Authentication over HTTPS
C.POST with OAuth 2.0 over HTTP
D.GET with Basic Authentication over HTTPS
AnswerD

GET is the correct HTTP method for retrieving data from a RESTCONF resource. Basic Authentication over HTTPS encodes the username and password in the Authorization header, and the TLS encryption of HTTPS protects the credentials in transit. This satisfies the requirement for encrypted communication and authentication, making it the appropriate choice for this scenario.

Why this answer

RESTCONF uses HTTP methods that align with CRUD operations: GET for read, POST for create, PUT/PATCH for update, and DELETE for delete. To retrieve interface statistics, the script must use GET. Basic Authentication over HTTPS ensures that credentials are encrypted during transmission.

The combination of GET and Basic Auth over HTTPS meets both the functional and security requirements of the scenario.

Exam trap

The trap here is confusing the HTTP methods used for different CRUD operations, such as using POST or PATCH when a GET is required for retrieval.

1830
Matchingmedium

Drag and drop each MPLS label field on the left to its matching bit size on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

20 bits

3 bits

1 bit

8 bits

32 bits

Why these pairings

The MPLS label has 4 fields: Label (20 bits), TC (3 bits), S (1 bit), and TTL (8 bits).

1831
MCQmedium

A network engineer runs the following command on Router R7: R7# show mpls ldp capabilities LDP Capabilities: Dynamic Capability: advertised Typed Wildcard FEC: advertised MTU Signaling: advertised P2MP: not advertised MPLS OAM: advertised LDP Graceful Restart: advertised Helper mode: enabled Restart mode: enabled Reconnect time: 120 sec Recovery time: 180 sec Based on this output, which capability is NOT supported by this router?

A.LDP Graceful Restart
B.MTU Signaling
C.P2MP (Point-to-Multipoint)
D.Dynamic Capability
AnswerC

The output lists P2MP as "not advertised", meaning the router does not signal Point-to-Multipoint LDP capability to its peers. Every other capability shown, including Typed Wildcard FEC and LDP Graceful Restart, is advertised, isolating P2MP as the unsupported one.

Why this answer

The output shows 'P2MP: not advertised', which explicitly indicates that Point-to-Multipoint (P2MP) capability is not supported on this router. All other listed capabilities, including LDP Graceful Restart, MTU Signaling, and Dynamic Capability, are shown as 'advertised' and therefore supported.

Exam trap

Cisco often tests the ability to read the 'show mpls ldp capabilities' output literally, where the trap is that candidates assume all capabilities are supported by default or confuse 'not advertised' with a misconfiguration rather than a lack of feature support.

How to eliminate wrong answers

Option A is wrong because the output clearly shows 'LDP Graceful Restart: advertised' with both helper and restart modes enabled, so it is supported. Option B is wrong because 'MTU Signaling: advertised' appears in the output, confirming support. Option D is wrong because 'Dynamic Capability: advertised' is listed, indicating the router supports dynamic capability advertisement.

1832
MCQmedium

A network engineer is using Cisco DNA Center Assurance to troubleshoot a user's poor voice quality. The engineer wants to view detailed hop-by-hop performance metrics for the path between the user's endpoint and the voice gateway over the last 24 hours. Which Assurance feature should the engineer use?

A.Application Experience
B.Path Trace
C.Client 360
D.Network Health Dashboard
AnswerB

Path Trace in Cisco DNA Center Assurance provides hop-by-hop performance metrics, including latency, jitter, and packet loss, for a specified path and time window. It uses data from network devices and can visualize the exact path taken. This directly answers the requirement to see detailed hop-by-hop metrics between two endpoints over the last 24 hours.

Why this answer

Cisco DNA Center Assurance Path Trace is designed to provide detailed hop-by-hop performance metrics for a specific path between two endpoints. It collects and displays latency, jitter, and packet loss per hop, which is essential for diagnosing voice quality issues. The other features offer summary or client-centric views but not the granular path data required.

Exam trap

The trap here is confusing high-level health dashboards with the granular path analysis that Path Trace provides.

1833
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate management users against a RADIUS server. The engineer wants to ensure that if the RADIUS server is unreachable, the router falls back to local authentication using the local username database. Which configuration should be applied?

A.aaa authentication login default group radius local
B.aaa authentication login default group radius enable
C.aaa authentication login default group radius none
D.aaa authentication login default local group radius
AnswerA

This command configures AAA authentication for login to first use the RADIUS server group and then fall back to the local database if the RADIUS server is unreachable. The 'local' keyword ensures that local authentication is attempted as a backup, providing resilience.

Why this answer

The correct configuration uses 'group radius' followed by 'local' to ensure that RADIUS is tried first and local authentication is used only as a fallback when the RADIUS server is unreachable. This provides both centralized authentication and resilience.

Exam trap

The trap here is reversing the order of methods or using 'enable' or 'none' as fallback, which do not provide local database fallback.

1834
Drag & Dropmedium

Drag and drop the steps of configuring a site-to-site IPsec VPN on Cisco IOS into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order for configuring a site-to-site IPsec VPN is: first define the IKE policy (Phase 1 parameters), then define the IPsec transform set (Phase 2 parameters), then create the crypto ACL to match interesting traffic, then configure the crypto map to bind all parameters, and finally apply the crypto map to the outgoing interface.

1835
Matchingmedium

Drag and drop each Python library on the left to its matching network use case on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Simplifies SSH connections to network devices

Provides a unified API for configuration and state retrieval

Enables parallel task execution across inventory

Supports asynchronous network device communication

Offers raw SSH protocol implementation

Why these pairings

Netmiko simplifies SSH to network devices; NAPALM provides multi-vendor abstraction; Nornir is task-based and parallel; Scrapli is async-focused; Paramiko is low-level SSH.

1836
MCQmedium

A network engineer is using the YANG Suite tool to explore YANG models supported by a Cisco IOS XE device. The engineer wants to retrieve the list of available YANG modules from the device using NETCONF. Which NETCONF operation should be used to obtain this information?

A.<get-schema>
B.<get> with a filter for ietf-yang-library:modules-state
C.<get-config> with a filter for ietf-netconf-monitoring:netconf-state
D.<edit-config> to add a new module
AnswerB

The ietf-yang-library YANG module defines a data model for listing YANG modules supported by a device. By using the <get> operation with a subtree filter targeting 'ietf-yang-library:modules-state', the engineer can retrieve the list of all available YANG modules. This is the standard method for discovering YANG models via NETCONF.

Why this answer

To retrieve the list of YANG modules supported by a Cisco IOS XE device, the engineer should use the <get> operation with a filter for 'ietf-yang-library:modules-state'. This data is operational and provided by the ietf-yang-library module. The <get-schema> operation retrieves a specific schema, while <get-config> and <edit-config> are for configuration data.

Thus, the correct operation is <get> with the appropriate filter.

Exam trap

The trap here is confusing the retrieval of a specific YANG schema with listing all available modules, or using <get-config> for operational data.

1837
MCQmedium

Given the following partial configuration on a Cisco IOS-XE router: ip pim rp-address 10.0.0.1 10 access-list 10 permit 224.0.0.0 0.255.255.255 ! interface GigabitEthernet0/0 ip pim sparse-mode ! What is the effect of this configuration?

A.The router will use 10.0.0.1 as the RP for all multicast groups from 224.0.0.0 to 224.255.255.255, and the interface will operate in sparse-mode.
B.The router will ignore the static RP because the ACL includes the reserved link-local range (224.0.0.0/24).
C.The interface must also be configured with 'ip pim dense-mode' for the RP to work.
D.The RP address 10.0.0.1 must be configured on a loopback interface on the same router.
AnswerA

The command 'ip pim rp-address 10.0.0.1 10' associates ACL 10 with the static rendezvous point (RP) address for the entire 224.0.0.0/8 group range, since ACL 10 matches all addresses from 224.0.0.0 to 224.255.255.255. When an interface is configured with 'ip pim sparse-mode', it joins the PIM sparse-mode domain, where multicast forwarding relies on an RP for group registration and shared-tree construction. Because the ACL explicitly includes the full 224.0.0.0/8 range, the router will indeed use 10.0.0.1 as the RP for all groups in that range, and the interface operating in sparse-mode will actively use this RP to build the rendezvous point tree (RPT).

Why this answer

The configuration statically assigns 10.0.0.1 as the RP for multicast groups matching access-list 10, which permits the range 224.0.0.0 through 224.255.255.255 (a /8 prefix). The interface GigabitEthernet0/0 is set to PIM sparse-mode, which is required for sparse-mode operation. This combination allows the router to use the static RP for groups in that range, and the interface will participate in sparse-mode multicast forwarding.

Exam trap

Cisco often tests the misconception that the ACL in the 'ip pim rp-address' command must exclude the reserved link-local range (224.0.0.0/24), but in fact the command accepts any ACL, and the router will apply the RP to all matching groups, including the link-local range, even though those groups are not typically forwarded.

How to eliminate wrong answers

Option B is wrong because the ACL includes the entire 224.0.0.0/8 range, which does contain the reserved link-local multicast range (224.0.0.0/24), but Cisco IOS does not automatically ignore the static RP for that range; the configuration is valid and the router will apply the RP to all groups in the ACL, including the link-local range, though link-local groups are typically not routed. Option C is wrong because PIM sparse-mode does not require dense-mode; the interface is correctly configured for sparse-mode, and the RP is used for sparse-mode groups. Option D is wrong because the RP address 10.0.0.1 does not need to be on the same router; it can be any reachable IP address, and the static RP configuration simply points to that address.

1838
MCQmedium

A network architect is designing a controller-based wireless deployment for a large campus. The customer wants centralized management, policy enforcement, and the ability to deploy a single wireless LAN controller that can handle up to 6,000 access points. Which Cisco platform should the architect recommend?

A.Cisco Mobility Express
B.Cisco 5520 Wireless Controller
C.Cisco Catalyst 9800-80 Wireless Controller
D.Cisco Catalyst 9800-L Wireless Controller
AnswerC

The Catalyst 9800-80 is a high-end appliance in the Catalyst 9800 series, supporting up to 6,000 access points and 64,000 clients. It provides centralized management, policy enforcement, and runs IOS-XE, making it ideal for large campus deployments. It meets the exact scalability requirement of the scenario.

Why this answer

The Catalyst 9800-80 is purpose-built for large-scale wireless deployments, supporting up to 6,000 access points and 64,000 clients. It offers centralized management, policy enforcement, and runs on IOS-XE, aligning with modern intent-based networking. The other options either lack the required scale or are designed for smaller environments.

Exam trap

The trap here is assuming that any Catalyst 9800 model can scale to 6,000 access points, when only the 9800-80 supports that capacity.

1839
MCQhard

An engineer is configuring a VXLAN EVPN fabric on Cisco Nexus 9000 switches. VLAN 100 on leaf-1 must be mapped to VNI 10100, and the same Layer 2 segment must extend to leaf-2. The engineer creates VLAN 100 and enters the NVE interface configuration. Which configuration on leaf-1 correctly maps VLAN 100 to VNI 10100 so that the Layer 2 segment can be extended over the VXLAN overlay?

A.interface nve1 / no shutdown / source-interface loopback0 / member vni 10100 / ingress-replication protocol bgp
B.vlan 100 / vn-segment 10100 / interface nve1 / no shutdown / source-interface loopback0 / member vni 10100 / ingress-replication protocol static
C.interface nve1 / no shutdown / source-interface loopback0 / member vni 10100 / vlan 100
D.vlan 100 / vn-segment 10100 / interface nve1 / no shutdown / source-interface loopback0 / member vni 10100
AnswerD

On Nexus 9000, the VLAN-to-VNI binding is created with the vn-segment command under the VLAN configuration, which maps VLAN 100 to VNI 10100. The NVE interface then references that VNI with member vni 10100 and uses loopback0 as the VTEP source. Together these commands correctly encapsulate VLAN 100 traffic and extend the Layer 2 segment to leaf-2.

Why this answer

Extending a VLAN over VXLAN on Nexus 9000 requires two coordinated pieces: the VLAN must be mapped to a VNI using vn-segment under the VLAN, and the NVE interface must include that VNI as a member with a valid source interface. The vn-segment command is what actually binds the Layer 2 segment to the VNI, while the NVE membership enables encapsulation. Omitting either piece leaves VLAN 100 local to leaf-1 and unable to reach leaf-2.

Exam trap

The trap here is believing that adding the VNI under the NVE interface is enough, when the VLAN itself must also be mapped to that VNI with the vn-segment command.

1840
Multi-Selectmedium

Which two statements about SNMPv3 security features are true? (Choose two.)

Select 2 answers
A.The authNoPriv security level provides authentication using MD5 or SHA, but no encryption.
B.The noAuthNoPriv security level provides both authentication and encryption.
C.The authPriv security level provides authentication using MD5 or SHA, and encryption using DES or AES.
D.SNMPv3 users are identified solely by the community string, similar to SNMPv2c.
E.The SNMP engine ID is optional and only used for debugging purposes.
AnswersA, C

authNoPriv sits between noAuthNoPriv and authPriv on the SNMPv3 security ladder: packets carry a message authentication code computed with HMAC-MD5 or HMAC-SHA, verifying origin and integrity, yet the payload remains cleartext because no privacy protocol is negotiated.

Why this answer

Option A is correct because the authNoPriv security level in SNMPv3 performs message authentication and integrity checking using either HMAC-MD5-96 or HMAC-SHA-96, but it deliberately does not provide data encryption (privacy). Option C is correct because authPriv combines authentication via MD5 or SHA with encryption, using DES or AES (with AES-128 being common) to protect the payload. Option B is wrong because noAuthNoPriv provides neither authentication nor encryption, relying only on a username match.

Option D is wrong because SNMPv3 replaces community strings with the User-based Security Model (USM), where users are identified by a userName combined with an authoritative SNMP engine ID. Option E is wrong because the SNMP engine ID is mandatory and uniquely identifies the SNMP engine for each device; it is used for key localization and discovery, not merely debugging.

Exam trap

350-401 often tests the misconception that SNMPv3 still uses community strings or that noAuthNoPriv offers any security, when in fact SNMPv3 replaces communities with USM users and engine IDs.

1841
Multi-Selectmedium

Which two statements about policing and shaping in a QoS architecture are true? (Choose two.)

Select 2 answers
A.Policing can be configured on both ingress and egress interfaces, while shaping is only supported on egress interfaces.
B.Shaping uses a token bucket algorithm to meter traffic and drops packets that exceed the configured rate.
C.Policing introduces variable delay because it buffers excess traffic before forwarding.
D.Both policing and shaping can re-mark packets that conform to the configured rate.
E.The 'shape average' command configures shaping to use the average rate over time, while 'shape peak' allows bursts above the average.
AnswersA, E

Policing is a token-bucket-based mechanism that can be applied on both ingress and egress interfaces because it only evaluates conformance and immediately drops or re-marks excess packets without buffering. Shaping, however, must buffer nonconforming traffic in a queue and schedule it for later transmission, which requires an output interface; hence Cisco IOS only supports shaping on egress. This is why ingress rate limiting is almost always done with policing, while shaping is reserved for smoothing traffic leaving an interface.

Why this answer

Policing drops or re-marks traffic exceeding a rate, while shaping buffers excess traffic to smooth bursts. Policing is applied inbound or outbound, shaping is typically outbound. Policing does not introduce delay, shaping does.

Both can use token bucket algorithms.

1842
MCQmedium

An architect is designing an SD-Access fabric for a large campus network. The design must support wireless clients that roam across different access switches without requiring a centralized wireless LAN controller. Which fabric component and protocol combination should the architect use to enable this mobility?

A.Fabric edge switches with VXLAN and LISP; APs in local mode with a centralized WLC.
B.Fabric edge switches with VXLAN and LISP; APs in fabric mode (SD-Access enabled).
C.Fabric border nodes with VXLAN and LISP; APs in flexconnect mode with a local switch.
D.Fabric control plane nodes with VXLAN and LISP; APs in monitor mode.
AnswerB

In SD-Access wireless, the CAPWAP control plane terminates on the fabric WLC, but the AP's data plane terminates locally on the fabric edge switch, which uses VXLAN to carry the wireless client traffic across the fabric. The wireless client is registered as a LISP EID with the fabric control plane, enabling seamless roaming between APs without changing the client's IP address. Only this fabric-mode AP design preserves the distributed anycast gateway and micro-segmentation for wireless endpoints.

Why this answer

SD-Access fabric uses fabric edge switches with VXLAN (data plane) and LISP (control plane) to create a distributed overlay that supports seamless wireless client roaming. APs in fabric mode (SD-Access enabled) integrate directly with the fabric, allowing the fabric edge to handle mobility without a centralized WLC, as the client's context is maintained across the VXLAN overlay.

Exam trap

Cisco often tests the misconception that SD-Access requires a centralized WLC for wireless roaming, but the trap here is that fabric mode APs offload mobility to the fabric edge switches using VXLAN/LISP, eliminating the need for a WLC controller.

How to eliminate wrong answers

Option A is wrong because APs in local mode with a centralized WLC require the WLC to anchor traffic and manage roaming, contradicting the design requirement of no centralized WLC. Option C is wrong because fabric border nodes are used for external connectivity (e.g., to WAN or Internet), not for wireless client mobility; FlexConnect mode with a local switch does not use VXLAN/LISP fabric integration and still relies on a WLC for control. Option D is wrong because fabric control plane nodes (e.g., LISP map-server/map-resolver) handle endpoint ID-to-location mapping, not wireless client mobility; APs in monitor mode are for passive scanning and do not forward client traffic.

1843
MCQmedium

Review the following OSPF configuration: router ospf 1 network 192.168.1.0 0.0.0.255 area 0 network 10.0.0.0 0.255.255.255 area 1 default-information originate always metric 20 metric-type 1 ! What is the effect of the 'default-information originate always metric 20 metric-type 1' command?

A.It injects a default route into OSPF only if a default route exists in the routing table, with metric 20 and type E1.
B.It injects a default route into OSPF unconditionally, with metric 20 and type E1.
C.It injects a default route into OSPF with metric 20 and type E2, but only if a default route exists.
D.It injects a default route into OSPF with metric 20 and type E1, but only for area 0.
AnswerB

This is the correct behavior for the OSPF 'default-information originate always' command. The 'always' keyword forces the router to originate and advertise a default route unconditionally, regardless of whether a default route is present in its routing table. The metric 20 and metric-type 1 specify that the route is advertised as an external type 1 (E1) route, which includes the cumulative internal cost to the ASBR. This matches the command syntax 'default-information originate always metric 20 metric-type 1'.

Why this answer

The 'default-information originate always' command injects a default route into the OSPF link-state database unconditionally, even if no default route exists in the routing table. The 'metric 20' sets the OSPF cost to 20, and 'metric-type 1' makes it an E1 (Type 1) external route, meaning the metric includes the internal cost to the ASBR plus the external cost.

Exam trap

Cisco often tests the distinction between 'default-information originate' (conditional) and 'default-information originate always' (unconditional), and the difference between metric-type 1 (E1) and metric-type 2 (E2), to see if candidates understand the exact behavior of each keyword.

How to eliminate wrong answers

Option A is wrong because the 'always' keyword causes the default route to be injected unconditionally, not only if a default route exists in the routing table. Option C is wrong because the command specifies 'metric-type 1', which results in an E1 route, not an E2 route; additionally, the 'always' keyword removes the condition of a pre-existing default route. Option D is wrong because the 'default-information originate' command applies to the entire OSPF process, not just area 0; the network statements define which interfaces participate in which areas, but the default route is advertised into all areas unless filtered.

1844
MCQeasy

What is the default value of the BGP 'weight' attribute for routes learned from a neighbor?

A.0
B.100
C.32768
D.1
AnswerA

Correct. For any route that is learned via a BGP session (eBGP or iBGP), the default Cisco weight is 0. Weight is the first attribute evaluated in the BGP best-path selection algorithm, and a higher weight is preferred; since no explicit weight configuration has been applied, the default of 0 is the correct value.

Why this answer

The BGP 'weight' attribute is a Cisco-proprietary attribute that is locally significant only to the router on which it is configured. By default, routes learned from a BGP neighbor have a weight of 0, while routes originated locally on the router (e.g., via network or aggregate-address commands) have a weight of 32768. Weight is the highest priority BGP attribute in the path selection process, so a route with a higher weight is preferred over one with a lower weight.

Exam trap

Cisco often tests the distinction between the default weight for locally originated routes (32768) versus routes learned from a neighbor (0), causing candidates to mistakenly choose 32768 when asked about learned routes.

How to eliminate wrong answers

Option B (100) is wrong because 100 is the default administrative distance for IBGP routes, not the default BGP weight. Option C (32768) is wrong because 32768 is the default weight for locally originated routes (e.g., routes injected via the network command), not for routes learned from a neighbor. Option D (1) is wrong because there is no BGP attribute or default value of 1 for weight; weight values range from 0 to 65535, and 0 is the default for learned routes.

1845
Multi-Selectmedium

Which two statements about SD-WAN architecture are true? (Choose two.)

Select 2 answers
A.The vSmart controller is responsible for distributing routing and policy information to the WAN edge routers.
B.vEdge routers establish IPsec tunnels directly with each other for data plane traffic.
C.The vBond orchestrator is responsible for forwarding data traffic between branch sites.
D.vEdge routers establish OMP sessions with each other to exchange control plane information.
E.Control plane communication between vSmart and vEdge is secured using IPsec.
AnswersA, B

The vSmart controller runs the control plane, computing and distributing OMP routing and policy information to WAN edge routers, which then make forwarding decisions. This satisfies the statement describing vSmart's role in propagating routes and policies.

Why this answer

Option A is correct because in Cisco SD-WAN the vSmart controller is the centralized control plane component that distributes OMP routing information and policy (centralized and application-aware routing policies) to the WAN edge devices. Option B is correct because vEdge routers build the data plane themselves: they establish IPsec (and where applicable GRE) tunnels directly between edge devices, with the vSmart/vBond only facilitating control and orchestration, not carrying the payload traffic. Option C is wrong because the vBond orchestrator only performs initial authentication and NAT traversal/orchestration, helping edges find each other and the vSmart controllers; it does not forward data traffic.

Option D is wrong because OMP sessions are formed between each vEdge and the vSmart controller (over DTLS/TLS), not between vEdge routers themselves. Option E is wrong because control plane communication between vSmart and vEdge uses DTLS/TLS (with OMP running over it), not IPsec, which is used for the data plane tunnels.

Exam trap

350-401 often tests the role separation between vBond, vSmart, and vManage, so candidates confuse the orchestrator (vBond) with the controller (vSmart) and incorrectly assume vBond forwards data or that vEdges peer with each other via OMP.

1846
MCQeasy

What is the default syslog severity level for console logging on a Cisco IOS device?

A.debugging (level 7)
B.informational (level 6)
C.warnings (level 4)
D.errors (level 3)
AnswerA

The default console logging severity in Cisco IOS is debugging (level 7), which is the least severe level and permits every syslog message from emergency (0) through debug (7) to be displayed. Because no explicit logging console command is configured by default, all syslog messages appear on the console, including informational and debugging messages.

Why this answer

By default, Cisco IOS devices log messages with severity levels 0 through 7 (emergencies through debugging) to the console. This is because the console logging default is set to 'debugging' (level 7), meaning all syslog messages, regardless of severity, are displayed on the console. This behavior is controlled by the 'logging console debugging' command, which is the default configuration.

Exam trap

Cisco often tests the default syslog severity for console logging versus other logging destinations (like buffer or monitor), where the default may differ (e.g., buffer logging defaults to debugging as well, but monitor logging defaults to informational), causing candidates to confuse the defaults.

How to eliminate wrong answers

Option B is wrong because informational (level 6) is not the default; it would filter out debugging messages (level 7), but the default console logging includes all levels down to debugging. Option C is wrong because warnings (level 4) would only show messages from level 0 to 4, excluding many lower-severity messages like notifications and informational, which are included by default. Option D is wrong because errors (level 3) would restrict console output to only emergencies, alerts, critical, and errors, missing the default inclusion of warnings, notifications, and informational messages.

1847
Multi-Selecthard

Which three statements about RPF check in IP multicast are true? (Choose three.)

Select 3 answers
A.The RPF check ensures that multicast packets are forwarded only if they arrive on the interface that the router would use to send unicast traffic back to the source.
B.If the RPF check fails, the multicast packet is dropped by the router.
C.The RPF check is performed only on the first packet of a multicast stream to determine the forwarding path.
D.The RPF check relies solely on the multicast routing table (MRIB) to determine the incoming interface.
E.A multicast packet can fail the RPF check even if the unicast route to the source exists, if the packet arrives on a different interface than the one used for unicast return traffic.
AnswersA, B, E

The router consults its unicast routing table for the source address and derives the outgoing interface toward it. Multicast packets are accepted only when received on that same interface, which builds the shortest-path distribution tree and prevents forwarding loops in the topology.

Why this answer

Option A is correct because the RPF check verifies that a multicast packet arrives on the interface the router would use to reach the source via the unicast routing table (or the MRIB derived from it), which is the fundamental definition of the RPF check in IP multicast. Option B is correct because when the incoming interface does not match the RPF interface, the router considers the packet to have arrived via a suboptimal or looped path and silently drops it. Option E is correct because the RPF check compares the actual arrival interface against the RPF interface; even if a valid unicast route to the source exists, a packet arriving on any other interface fails the check and is discarded.

Option C is not correct because the RPF check is performed on every multicast packet, not just the first packet of a stream, to continuously guard against loops and suboptimal paths. Option D is not correct because the RPF check can use the unicast routing table (or the MRIB, which is populated from unicast routing information) and, in some implementations, static mroutes, so it does not rely solely on the multicast routing table.

Exam trap

350-401 often tests the misconception that RPF is only checked on the first packet or that it uses the multicast routing table exclusively; candidates must remember RPF is per-packet and based on the unicast route to the source.

1848
MCQhard

A security architect is designing segmentation for a data center using Cisco TrustSec. The requirement is that classification of traffic into Security Group Tags (SGTs) occur at the access layer based on the identity of the user or device, and that enforcement occur at the data center core where the SGT-to-SGACL matrix is applied. Which statement describes the correct deployment approach?

A.SGTs are assigned by Cisco ISE to the core switch, and enforcement is performed by the access switch using downloadable ACLs.
B.SGTs are assigned by the access switch using 802.1X or SXP, propagated in the SGT Exchange Protocol or inline tagging, and enforced by SGACLs on the core device.
C.SGTs are assigned at the core based on destination subnet, and enforcement occurs at the access layer using PACLs.
D.SGTs are carried in IPsec ESP headers across the data center, and enforcement is performed by the Cisco ASA using the SGT matrix.
AnswerB

TrustSec separates classification from enforcement. Access-layer devices assign SGTs based on identity (802.1X, MAB) or receive them via SXP from upstream, then propagate the tag in the packet header using inline tagging (CMD) or via SXP to devices that cannot tag. Enforcement devices at the core apply SGACLs from the SGT matrix. This matches the described architecture.

Why this answer

TrustSec's strength is the separation of classification from enforcement. Identity-based classification happens as close to the source as possible at the access layer, using 802.1X, MAB, or SXP to assign SGTs. Tags then travel across the fabric via inline tagging or SXP propagation.

Enforcement devices, typically in the distribution or core, apply SGACLs derived from the SGT matrix, allowing consistent policy regardless of IP addressing or topology changes.

Exam trap

The trap here is reversing classification and enforcement points, or assuming SGACL enforcement happens on the access switch using dACLs rather than on TrustSec-capable devices in the core using the SGT matrix.

1849
Drag & Dropmedium

Drag and drop the steps of OpenAPI schema validation for DNA Center REST call into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Validation begins with retrieving the OpenAPI spec, then parsing the endpoint, validating the request against the schema, checking the response, and finally handling any validation errors.

1850
Drag & Dropmedium

Drag and drop the steps of 4G/LTE WAN failover with IP SLA tracking into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, configure the primary WAN interface and the LTE backup interface. Then, create an IP SLA probe to monitor the primary link. Track the SLA with a tracking object.

Set a static route with a higher metric for the LTE interface, tied to the track. When the primary fails, the track goes down, and the LTE route becomes active.

1851
MCQmedium

Examine the following EIGRP configuration snippet: interface GigabitEthernet0/0 ip bandwidth-percent eigrp 100 50 What is the effect of this command?

A.EIGRP will use up to 50% of the interface bandwidth for its control traffic.
B.EIGRP will only advertise routes that have a metric within 50% of the best path.
C.EIGRP will use 50% of the interface bandwidth for data traffic.
D.EIGRP will reduce its hello interval by 50%.
AnswerA

EIGRP's `ip bandwidth-percent eigrp` command directly controls the maximum percentage of an interface's configured bandwidth that EIGRP control packets (hello, update, query, reply, and ACK) may consume. Setting it to 50 means EIGRP caps its own control-plane traffic at half the interface's bandwidth, preventing EIGRP from starving data traffic. This is a rate-limiting mechanism for routing protocol overhead, not for route selection or forwarding.

Why this answer

The `ip bandwidth-percent eigrp 100 50` command configures EIGRP to use up to 50% of the interface's configured bandwidth for its control traffic (hello, update, query, and reply packets). This limits the amount of bandwidth EIGRP can consume to prevent it from starving other traffic. The percentage is applied to the interface's `bandwidth` setting, not the actual physical link speed.

Exam trap

Cisco often tests the misconception that `ip bandwidth-percent eigrp` controls data traffic or route selection, when in fact it only limits EIGRP's own control plane bandwidth usage.

How to eliminate wrong answers

Option B is wrong because EIGRP does not have a mechanism to advertise only routes within a percentage of the best path; variance and offset-lists are used for unequal-cost load balancing, not route filtering based on metric percentage. Option C is wrong because this command specifically limits EIGRP control traffic, not data traffic; data traffic is unaffected by this command. Option D is wrong because the `ip bandwidth-percent eigrp` command does not influence the hello interval; hello intervals are configured separately with `ip hello-interval eigrp`.

1852
Multi-Selectmedium

Which two statements about NFV architecture and components are true? (Choose two.)

Select 2 answers
A.The NFV Infrastructure (NFVI) includes compute, storage, and networking resources that host VNFs.
B.Virtual Network Functions (VNFs) are software implementations of network functions that run on virtualized infrastructure.
C.Each VNF must be deployed on its own dedicated physical server to ensure performance isolation.
D.The Virtualized Infrastructure Manager (VIM) is responsible for managing the lifecycle of VNFs.
E.The NFV Orchestrator is primarily responsible for allocating virtual resources to VNFs.
AnswersA, B

The NFVI comprises the hardware and virtualisation layers — compute, storage and networking — that together provide the environment hosting VNFs. This matches the stem's requirement for a true statement about NFV components and their defined roles.

Why this answer

Option A is correct because the NFV Infrastructure (NFVI) is defined by ETSI as the totality of hardware and software resources—compute (e.g., x86 servers), storage, and networking—on which VNFs are deployed and executed. Option B is correct because a Virtual Network Function (VNF) is precisely the software implementation of a network function (such as a firewall, router, or MME) that runs on virtualized infrastructure rather than on proprietary hardware. Option C is wrong because VNFs are designed to run on virtual machines or containers on shared, virtualized infrastructure, not on dedicated physical servers.

Option D is wrong because VNF lifecycle management (instantiation, scaling, termination) is handled by the VNF Manager (VNFM), while the VIM manages the NFVI resources. Option E is wrong because allocating virtual resources to VNFs is the VIM's responsibility; the NFV Orchestrator focuses on end-to-end service orchestration and network service lifecycle management.

Exam trap

The trap is confusing the roles of VIM, VNFM, and NFVO — candidates often assume the VIM manages VNF lifecycle when it actually manages only the underlying NFVI resources.

1853
MCQhard

A network engineer is using Cisco DNA Center Assurance to troubleshoot a client connectivity issue. The engineer notices that the client's health score is low due to onboarding failures. Which component of Cisco DNA Center Assurance should be examined first to identify the root cause?

A.Network Health
B.Application Health
C.Path Trace
D.Client 360
AnswerD

Client 360 provides a comprehensive view of a specific client's connectivity, including onboarding, authentication, and performance details. It shows the client's journey through the network, including association, authentication, DHCP, and DNS. For onboarding failures, Client 360 will display the exact step where the failure occurred, such as authentication failure or DHCP timeout, making it the primary tool for root cause analysis.

Why this answer

Client 360 is the correct component because it provides detailed information about a specific client's onboarding process, including authentication, DHCP, and DNS steps. It allows the engineer to pinpoint the exact failure point. Network Health, Application Health, and Path Trace offer broader or different perspectives that do not focus on individual client onboarding.

Exam trap

The trap here is confusing network-wide health monitoring with client-specific troubleshooting, leading to choosing Network Health instead of Client 360.

1854
MCQmedium

A network engineer is implementing a REST API script to retrieve interface statistics from a Cisco IOS XE device. The engineer wants to use the most efficient method that supports HTTP/2 and streaming telemetry. Which API should be used?

A.NETCONF over SSH
B.SNMPv3
C.RESTCONF
D.gRPC
AnswerD

gRPC is a high-performance RPC framework that uses HTTP/2 for transport, supports streaming, and is used for model-driven telemetry on Cisco IOS XE. It allows efficient, real-time streaming of telemetry data and supports bidirectional streaming. This makes it the best choice for retrieving interface statistics with streaming telemetry and HTTP/2 benefits.

Why this answer

gRPC is the only option that natively uses HTTP/2 and supports streaming telemetry. It is designed for efficient, high-performance telemetry collection from Cisco IOS XE devices. NETCONF and RESTCONF are not optimized for streaming, and SNMPv3 is a polling protocol.

Therefore, gRPC is the correct choice.

Exam trap

The trap here is assuming that RESTCONF or NETCONF can handle streaming telemetry, but they are not designed for high-frequency streaming; gRPC is the protocol for that.

1855
MCQeasy

What is the default OSPF hello interval on an Ethernet link in a Cisco router?

A.10 seconds
B.30 seconds
C.5 seconds
D.40 seconds
AnswerA

The default OSPF HelloInterval on an Ethernet broadcast multi-access link is 10 seconds. Every 10 seconds a router sends an OSPF Hello packet out each OSPF-enabled interface to discover neighboring routers and maintain the neighbor relationship. This value is defined in RFC 2328 and is also the default for point-to-point links, but 10 seconds is the correct default specifically for the Ethernet network type in this question.

Why this answer

The default OSPF hello interval on an Ethernet link (which is a broadcast multi-access network type) is 10 seconds. This is defined in RFC 2328 and is the default on Cisco routers for broadcast and point-to-point network types. The hello interval determines how often a router sends hello packets to discover and maintain neighbor relationships.

Exam trap

Cisco often tests the default OSPF hello interval on Ethernet (broadcast) networks, and the trap here is that candidates confuse it with the dead interval (40 seconds) or with the hello interval used on other network types like NBMA (30 seconds).

How to eliminate wrong answers

Option B (30 seconds) is wrong because 30 seconds is the default hello interval for OSPF on NBMA (Non-Broadcast Multi-Access) networks, such as Frame Relay, not on Ethernet. Option C (5 seconds) is wrong because 5 seconds is not a standard OSPF hello interval; it might be confused with the default dead interval multiplier (4x hello) or with EIGRP's default hello interval on some media. Option D (40 seconds) is wrong because 40 seconds is the default OSPF dead interval on broadcast networks (4 x 10 seconds), not the hello interval.

1856
Drag & Drophard

Drag and drop the steps of gNMI Subscribe RPC using Python gRPC library into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with importing the gNMI protobuf modules and gRPC, creating a secure channel with credentials, instantiating the gNMI stub, building a SubscribeRequest with paths and mode, and finally calling the Subscribe RPC and iterating over responses.

1857
MCQmedium

A network engineer is configuring a Cisco IOS router to authenticate OSPF neighbors using MD5 cryptographic authentication on an interface. The engineer enters the following commands: interface GigabitEthernet0/0, ip ospf authentication message-digest, ip ospf message-digest-key 1 md5 Cisco123. However, the OSPF adjacency with the neighbor router is not forming. Which additional configuration is required on the neighbor router to establish the adjacency?

A.Configure the neighbor with the command area 0 authentication message-digest.
B.Configure the neighbor with the command ip ospf authentication-key Cisco123.
C.Configure the same key ID and password on the neighbor's interface with ip ospf message-digest-key 1 md5 Cisco123.
D.Configure the neighbor with the command ip ospf authentication null.
AnswerC

For OSPF MD5 authentication to succeed, both routers must have the same key ID and password configured on their interfaces. The neighbor must have the identical message-digest-key command with the same key number and MD5 password. Without this matching configuration, authentication will fail, and the adjacency will not form.

Why this answer

OSPF MD5 authentication requires both neighbors to have the same key ID and password configured on their interfaces. The engineer configured MD5 on one router, so the neighbor must have the identical 'ip ospf message-digest-key' command. Without matching keys, authentication fails and the adjacency does not form.

Exam trap

The trap here is assuming that enabling MD5 authentication on one side is sufficient, or confusing plain text authentication with MD5 authentication.

1858
Multi-Selecthard

A network security team is deploying MACsec on Cisco Catalyst switches to protect Layer 2 traffic between two distribution switches. They want to ensure that the link is encrypted and that only authorized devices can participate in the secured session. Which two statements about MACsec operation on Cisco platforms are correct? (Choose two.)

Select 2 answers
A.MACsec can be configured in switch-to-host mode where the host runs an 802.1X supplicant that supports MACsec key agreement, allowing encryption to the endpoint.
B.MACsec uses the MKA protocol to negotiate and exchange keys between peers, and it can be configured with a pre-shared key or with 802.1X-based key derivation.
C.MACsec is only supported on routed ports and cannot be enabled on switch access ports or EtherChannel member links.
D.MACsec encryption keys are exchanged in clear text during the MKA handshake, so the link is only protected against physical taps after the session is established.
E.MACsec operates at Layer 3 and encrypts IP packets between routers, requiring IPsec configuration on the participating interfaces.
AnswersA, B

Cisco supports MACsec in switch-to-host deployments, where the endpoint runs a supplicant capable of MKA, such as the Cisco AnyConnect Network Access Manager or a compatible NIC driver. This extends encryption to the access edge rather than only between switches. It requires 802.1X authentication and a supplicant that supports MACsec, but it is a valid and commonly deployed mode.

Why this answer

MACsec secures Ethernet frames using MKA to negotiate keys, supporting both pre-shared CAK and 802.1X-based key derivation. It can be deployed switch-to-switch or switch-to-host when the endpoint has a MACsec-capable supplicant. These two facts address the requirement for encryption and authorized participation on the Layer 2 link.

Exam trap

The trap here is assuming MACsec is a Layer 3 IPsec-like technology or that it sends keys in clear text, when it is actually a Layer 2 frame encryption method with secure MKA key exchange.

1859
MCQeasy

A network administrator is configuring a Cisco IOS router to authenticate management users against a centralized TACACS+ server. The administrator wants to ensure that if the TACACS+ server is unreachable, a locally configured user can still log in. Which command should be used to define the authentication method list for login?

A.aaa authorization exec default group tacacs+ local
B.aaa authentication login default group radius local
C.aaa authentication login default group tacacs+ none
D.aaa authentication login default group tacacs+ local
AnswerD

This method list tells the router to try TACACS+ first, then fall back to the local user database if the server does not respond. The local keyword ensures that a locally configured username and password can be used during an outage. This meets the requirement for centralized authentication with a local fallback.

Why this answer

The aaa authentication login default command defines the method list for login authentication. Listing group tacacs+ before local ensures the router attempts TACACS+ first and falls back to the local database only if the server is unreachable. This provides both centralized control and a reliable local backup for management access.

Exam trap

The trap here is using the none keyword as a fallback, which bypasses authentication entirely instead of using local credentials.

1860
Multi-Selectmedium

A network engineer is implementing VXLAN in a data center to support a large number of tenants. The engineer must ensure that the VXLAN overlay supports Layer 2 connectivity over a Layer 3 underlay. Which two statements are true about VXLAN? (Choose two.)

Select 2 answers
A.VXLAN encapsulates Layer 2 frames in UDP packets for transport over a Layer 3 network.
B.VXLAN uses a 24-bit VNI to identify up to 16 million segments.
C.VXLAN uses a 12-bit VLAN ID to identify segments.
D.VXLAN requires a multicast underlay for all broadcast, unknown unicast, and multicast traffic.
E.VXLAN tunnel endpoints (VTEPs) must be configured with the same IP address on all devices.
AnswersA, B

VXLAN encapsulates original Layer 2 frames within UDP packets, typically using UDP port 4789. This encapsulation allows Layer 2 connectivity to be extended over a routed Layer 3 underlay, which is essential for data center interconnect and overlay networks. The use of UDP provides a standard transport that can traverse IP networks.

Why this answer

VXLAN uses a 24-bit VNI, allowing up to 16 million segments, and encapsulates Layer 2 frames in UDP packets for transport over a Layer 3 underlay. These two characteristics enable scalable multi-tenancy and Layer 2 extension across routed networks. The other statements are false: multicast is not mandatory, VTEPs require unique IPs, and VXLAN does not use 12-bit VLAN IDs.

Exam trap

The trap here is confusing VXLAN's VNI size with VLAN IDs or assuming multicast is mandatory for VXLAN, when it is only one of several replication methods.

1861
MCQhard

A network engineer is configuring EIGRP on a router that connects to a service provider network. The engineer wants to advertise a default route to internal routers. The engineer configures 'ip default-network 0.0.0.0' and redistributes a static default route into EIGRP. However, internal routers are not receiving the default route. The engineer checks the EIGRP topology table and sees the default route with a metric of 1. What is the most likely reason?

A.The engineer used 'ip default-network' which is not supported in EIGRP; instead, 'default-information originate' should be used.
B.The static default route is not configured correctly; the engineer should use 'ip route 0.0.0.0 0.0.0.0 <next-hop>'.
C.The internal routers have a route to the default network with a better metric from another source.
D.The engineer needs to configure 'eigrp stub' on the router to allow default route advertisement.
AnswerB

Correct. The static default route must be correctly configured with a next-hop IP address. If the static route is missing or uses an interface instead of a next-hop, it may not be valid, and the redistribution will not propagate the route to internal routers, despite appearing in the topology table with a metric.

Why this answer

The engineer's configuration includes both 'ip default-network 0.0.0.0' (which is an IGRP command, not EIGRP) and redistribution of a static default route. The appearance of the default route in the EIGRP topology table with metric 1 indicates that redistribution occurred, but the route is not being advertised to internal routers. The most likely reason is that the static default route itself is not correctly configured.

For EIGRP redistribution to succeed, the static route must point to a valid next-hop IP address using the syntax 'ip route 0.0.0.0 0.0.0.0 <next-hop>'. If the engineer used an interface instead of a next-hop, or the next-hop is unreachable, the static route may be invalid or not installed in the routing table, preventing its advertisement to EIGRP neighbors.

Exam trap

Cisco often tests the misconception that 'ip default-network' works with EIGRP, when in fact it is an IGRP-specific command, and candidates may confuse it with the correct 'default-information originate' command used in EIGRP and OSPF.

How to eliminate wrong answers

Option B is wrong because the static route syntax 'ip route 0.0.0.0 0.0.0.0 <next-hop>' is correct and commonly used; the issue is not with the static route configuration but with the EIGRP advertisement method. Option C is wrong because the topology table shows the default route with a metric of 1, and if internal routers had a better metric from another source, the route would still be present in the topology table but not selected as best; the problem is that the route is not being advertised at all. Option D is wrong because configuring 'eigrp stub' restricts the router from advertising routes learned from other EIGRP neighbors, but it does not prevent the advertisement of a locally originated default route via 'default-information originate'; the stub feature is used to limit route propagation, not to enable default route advertisement.

1862
MCQmedium

A network engineer is configuring a VXLAN EVPN fabric on Cisco Nexus switches. The fabric must support Layer 2 extension across multiple leaf switches while maintaining optimal forwarding for Layer 3 traffic. Which control plane component is responsible for advertising MAC and IP address bindings to all leaf switches?

A.PIM sparse mode
B.Cisco Fabric Services (CFS)
C.MP-BGP EVPN address family
D.OSPFv3 with address families
AnswerC

MP-BGP EVPN is the control plane that distributes MAC and IP bindings via EVPN routes such as Type 2 and Type 5. It enables all leaf switches to learn remote MAC/IP addresses and provides optimal forwarding without relying on flood-and-learn. This matches the requirement for a scalable, efficient VXLAN EVPN fabric.

Why this answer

MP-BGP EVPN is the standard control plane for VXLAN EVPN fabrics. It advertises MAC and IP bindings using EVPN route types, enabling leaf switches to learn remote endpoints and forward traffic optimally without flooding. The other protocols listed are either underlay routing, multicast, or fabric management tools and do not provide the required EVPN address family.

Exam trap

The trap here is assuming that any routing protocol or multicast mechanism can distribute MAC and IP bindings, when only MP-BGP EVPN provides that capability in a VXLAN EVPN fabric.

1863
MCQhard

A network engineer uses the Requests library to query a Cisco IOS-XE device via RESTCONF for interface statistics: ```python import requests from requests.auth import HTTPBasicAuth url = 'https://192.168.1.1/restconf/data/Cisco-IOS-XE-interfaces-oper:interfaces/interface=GigabitEthernet1/0/1/statistics' headers = {'Accept': 'application/yang-data+json'} auth = HTTPBasicAuth('admin', 'cisco123') response = requests.get(url, headers=headers, auth=auth, verify=False) print(response.json()) ``` What is the most likely issue with this code?

A.The URL is missing the '/data' segment; it should be '/restconf/data/...'
B.The interface name 'GigabitEthernet1/0/1' in the URL must be URL-encoded as 'GigabitEthernet1%2F0%2F1'.
C.The Accept header should be 'application/json' instead of 'application/yang-data+json'.
D.The HTTP method should be POST instead of GET.
AnswerB

In a RESTCONF URI, each slash delimits a path segment, so an interface name like 'GigabitEthernet1/0/1' must be percent-encoded as 'GigabitEthernet1%2F0%2F1' to remain a single key segment. Without encoding, the server interprets the input as multiple nested path elements (e.g., an 'interface' container with intermediate nodes), causing the request to 404 or target the wrong data. Thus the fix is to URL-encode the interface name before constructing the request.

Why this answer

The code contains an unencoded slash in the interface name 'GigabitEthernet1/0/1', which is a special character in RESTCONF URIs. It must be URL-encoded as 'GigabitEthernet1%2F0%2F1' to be correctly interpreted as a list key value. Therefore, option B correctly identifies the issue.

Option A is false because the URL already includes '/restconf/data/'. Option C is incorrect because 'application/yang-data+json' is the proper Accept header for RESTCONF YANG data. Option D is false because GET is the correct HTTP method for data retrieval.

Exam trap

Candidates may overlook the requirement to URL-encode special characters like '/' in RESTCONF URIs and assume the code is correct, leading them to select superficially plausible but incorrect options such as A or C.

How to eliminate wrong answers

Option A is wrong because the URL already includes '/data' after '/restconf', so the path is correct. Option C is wrong because 'application/yang-data+json' is the correct media type for RESTCONF YANG data in JSON format, as defined in RFC 8040; 'application/json' is generic and may not be accepted by the RESTCONF server. Option D is wrong because retrieving interface statistics is a read operation that requires the HTTP GET method, not POST.

1864
Multi-Selectmedium

Which two statements about YANG data models in model-driven telemetry are true? (Choose two.)

Select 2 answers
A.YANG models are used to define the data structures streamed in telemetry subscriptions.
B.OpenConfig YANG models are vendor-neutral and supported across multiple network operating systems.
C.Native YANG models are standardized by the IETF and used universally.
D.NETCONF is a YANG data model used for telemetry configuration.
E.RESTCONF provides a YANG-based data model for streaming telemetry.
AnswersA, B

YANG provides the schema that describes the hierarchical data nodes a device exposes, so telemetry subscriptions reference those paths to select which counters and state values are streamed, satisfying the requirement for structured, model-driven data encoding.

Why this answer

Option A is correct because YANG (RFC 7950) defines the schema and data structures—containers, lists, leaves, and paths—that model-driven telemetry subscriptions reference when selecting which operational data to stream. Option B is correct because OpenConfig YANG models are developed collaboratively and vendor-neutral, so they can be supported across multiple network operating systems such as Cisco IOS XE, Junos, and others, enabling consistent telemetry paths. Option C is wrong because native YANG models are vendor-specific (e.g., Cisco or Juniper native models), not IETF-standardized; the IETF standardizes models like ietf-interfaces, not all native models.

Option D is wrong because NETCONF (RFC 6241) is a protocol, not a YANG data model, and it is used for configuration/state retrieval rather than being a telemetry model. Option E is wrong because RESTCONF (RFC 8040) is an HTTP-based protocol for accessing YANG-modeled data, not a YANG data model itself, and streaming telemetry is typically delivered via gRPC, gNMI, or UDP-based push rather than RESTCONF.

Exam trap

350-401 often tests the confusion between protocols and data models — candidates may think NETCONF or RESTCONF are YANG models, but they are transport protocols that use YANG.

1865
MCQhard

A network engineer is implementing QoS on a Cisco IOS router. The engineer wants to ensure that VoIP traffic is prioritized and that excess VoIP traffic is dropped when the interface is congested. Which QoS mechanism should be used?

A.Weighted Random Early Detection (WRED) on the VoIP class.
B.Class-Based Weighted Fair Queuing (CBWFQ) with a bandwidth guarantee.
C.Traffic shaping on the VoIP class.
D.Low Latency Queuing (LLQ) with a policer.
AnswerD

LLQ provides a strict priority queue for VoIP traffic, ensuring low latency and jitter. When combined with a policer, it can limit the amount of traffic that enters the priority queue, dropping excess VoIP packets during congestion. This meets the requirement to prioritize and drop excess VoIP traffic.

Why this answer

For VoIP, LLQ provides a strict priority queue to minimize latency and jitter. To prevent excess VoIP traffic from starving other queues, a policer is applied to the priority queue, dropping packets that exceed the configured rate. This combination ensures VoIP is prioritized and excess traffic is dropped during congestion.

Exam trap

The trap here is thinking that CBWFQ or shaping can handle VoIP prioritization, but only LLQ with a policer provides both strict priority and drop of excess traffic.

1866
MCQhard

A network automation engineer is developing a Python script using the ncclient library to configure a Cisco IOS XE device via NETCONF. The engineer wants to lock the running datastore, apply a candidate configuration, validate it, and then commit it. Which sequence of ncclient operations correctly performs this workflow?

A.manager.lock('candidate') manager.edit_config(target='candidate', config=config_payload) manager.validate('candidate') manager.commit() manager.unlock('candidate')
B.manager.lock('running') manager.edit_config(target='candidate', config=config_payload) manager.validate('candidate') manager.commit() manager.unlock('running')
C.manager.lock('candidate') manager.edit_config(target='running', config=config_payload) manager.validate('candidate') manager.commit() manager.unlock('candidate')
D.manager.lock('running') manager.edit_config(target='running', config=config_payload) manager.validate('running') manager.commit() manager.unlock('running')
AnswerA

This sequence correctly locks the candidate datastore, edits it with the desired configuration, validates the candidate, commits the changes to running, and then unlocks the candidate. This follows the NETCONF confirmed-commit workflow and is the standard approach when using the candidate datastore with ncclient. It ensures atomicity and prevents conflicts.

Why this answer

The correct NETCONF workflow with a candidate datastore involves locking the candidate, editing it, validating it, committing to running, and unlocking. This ensures configuration changes are atomic and can be validated before application. The ncclient library maps these to lock, edit_config, validate, commit, and unlock methods.

Using the candidate datastore is essential for this sequence.

Exam trap

The trap here is mixing datastores—locking running while editing candidate, or editing running directly—which breaks the candidate-based transactional model.

1867
MCQmedium

A service provider uses a Cisco ASR 1000 router to provide MPLS L3VPN services to multiple customers. Each customer has their own VRF. Recently, a new customer was added with VRF CUSTOMER_C. After configuration, the customer reports that they can reach some remote sites but not others. The network engineer checks the VRF configuration and finds that the route targets for CUSTOMER_C are correctly configured. The engineer also verifies that BGP sessions to the PE routers are up. The missing routes are from a site that uses a different PE router. Which action should the engineer take to resolve the issue?

A.Increase the MTU on the link between the PE routers.
B.Reconfigure LDP on the PE routers to establish a targeted session.
C.Check the MPLS label stack on the local PE to ensure labels are being swapped correctly.
D.Verify that the route target import/export values on the remote PE match those on the local PE for VRF CUSTOMER_C.
AnswerD

In MPLS Layer 3 VPNs, each VRF is configured with import and export route targets; a received VPNv4 route is installed into a VRF only if its route-target list matches one of the VRF's import targets. If the export RT on the advertising PE does not match the import RT configured in the remote PE for VRF CUSTOMER_C, the route is accepted into the BGP VPNv4 table but silently filtered out of the VRF. Verifying and correcting the RT values to be consistent on both PEs is the requisite fix, as this is the control-plane mechanism responsible for the observed missing route.

Why this answer

The issue is that the remote PE router does not have the correct route target import/export configuration for VRF CUSTOMER_C. In MPLS L3VPN, VRFs on different PEs must have matching route target values to import and export VPNv4 routes into the correct VRF. Even if the local PE is correctly configured, the remote PE must also import the routes from the local PE using the same route target.

Without this, the remote PE will not install the VPNv4 prefixes into its VRF, causing the customer to be unable to reach sites connected to that remote PE.

Exam trap

Cisco often tests the misconception that route target configuration is only needed on one PE, or that BGP session status alone guarantees route exchange, when in fact both import and export RTs must match across all PEs participating in the same VRF.

How to eliminate wrong answers

Option A is wrong because increasing the MTU on the link between PE routers would not affect route reachability; MTU issues typically cause packet fragmentation or drops, not missing routes in a VRF. Option B is wrong because LDP targeted sessions are used for MPLS label distribution between non-adjacent routers, but in this scenario the PE routers are already exchanging BGP VPNv4 routes and LDP is not the mechanism for VRF route import/export. Option C is wrong because checking the MPLS label stack on the local PE would verify label switching, but the problem is that the remote PE does not have the routes in its VRF, not that labels are being swapped incorrectly; label swapping issues would cause forwarding failures, not missing routes in the routing table.

1868
Multi-Selecthard

Which three statements about 802.1X port-based authentication are true? (Choose three.)

Select 3 answers
A.The supplicant communicates with the authenticator using EAP over LAN (EAPoL) frames.
B.The authenticator is typically a network switch or wireless access point.
C.The supplicant is the device that provides authentication services, such as a RADIUS server.
D.The authentication server is usually a RADIUS server that validates credentials.
E.802.1X is only supported on wireless networks and cannot be used on wired switches.
AnswersA, B, D

EAPoL carries Extensible Authentication Protocol exchanges directly between the supplicant and the authenticator across the point-to-point LAN segment, satisfying 802.1X's requirement that authentication traffic terminate at the switch port before reaching the authentication server. The authenticator then relays these exchanges to RADIUS, keeping the supplicant's credentials off the wire in cleartext.

Why this answer

Option A is correct because in 802.1X the supplicant (client) exchanges EAP authentication messages with the authenticator encapsulated in EAP over LAN (EAPoL) frames, as defined by IEEE 802.1X. Option B is correct because the authenticator is the network access device that controls the port—typically a LAN switch or a wireless access point—and relays EAP messages between the supplicant and the authentication server. Option D is correct because the authentication server is normally a RADIUS server that validates the supplicant's credentials and returns an Access-Accept or Access-Reject to the authenticator.

Option C is incorrect because it misidentifies the supplicant; the supplicant is the client device requesting access, while the RADIUS server acts as the authentication server. Option E is incorrect because 802.1X is defined for both wired and wireless LANs and is commonly deployed on wired switches as well as WLAN infrastructure.

Exam trap

350-401 often tests the role reversal between supplicant and authentication server, and the misconception that 802.1X is wireless-only, so candidates must firmly associate supplicant=client, authenticator=switch/WAP, authentication server=RADIUS.

1869
Multi-Selectmedium

Which two statements about OSPF network types are true? (Choose two.)

Select 2 answers
A.On a broadcast multiaccess network, OSPF elects a DR and BDR to reduce LSA flooding.
B.The OSPF point-to-point network type requires a DR/BDR election.
C.On a non-broadcast multiaccess (NBMA) network, OSPF can use the neighbor command to manually discover neighbors.
D.The OSPF point-to-multipoint network type always elects a DR.
E.The default OSPF network type for a loopback interface is point-to-point.
AnswersA, C

Broadcast multiaccess segments elect a DR and BDR, which form adjacencies with all routers and originate network LSAs on the segment's behalf. This reduces full-mesh adjacency count and consequent LSA flooding across the shared medium.

Why this answer

Option A is correct because on a broadcast multiaccess network OSPF does elect a DR and BDR, which reduces the number of adjacencies and LSA flooding by having all other routers form full adjacencies only with the DR/BDR. Option C is correct because on an NBMA network OSPF does not automatically discover neighbors via multicast, so the neighbor command is used to manually specify neighbor IP addresses and enable unicast Hello packets. Option B is incorrect because the point-to-point network type does not require a DR/BDR election; it forms a direct adjacency.

Option D is incorrect because point-to-multipoint treats the network as a collection of point-to-point links and does not elect a DR/BDR. Option E is incorrect because the default OSPF network type for a loopback interface is loopback, which is advertised as a stub host route, not point-to-point.

Exam trap

350-401 often tests whether candidates remember that point-to-point and point-to-multipoint network types skip DR/BDR election, while broadcast and NBMA do not — and that loopback defaults to the loopback network type, not point-to-point.

1870
Drag & Dropmedium

Drag and drop the steps of Cisco DHCP snooping binding table population into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

DHCP snooping builds the binding table by first enabling snooping globally, then on specific VLANs, and designating trusted ports. The switch intercepts DHCP messages, extracts client info from ACK packets, and populates the binding table with the lease information.

1871
MCQmedium

A network engineer is deploying a new branch office with a single Cisco Catalyst 9300 switch. The branch has three VLANs: VLAN 10 (users), VLAN 20 (voice), and VLAN 30 (management). The engineer needs to route traffic between these VLANs directly on the switch without using an external router. Which feature should be configured on the switch to enable inter-VLAN routing?

A.Configure 802.1Q trunking to an external router and enable Router-on-a-Stick.
B.Configure a routed port on the switch and connect it to each VLAN's subnet.
C.Enable private VLANs to isolate traffic between VLANs.
D.Configure Switch Virtual Interfaces (SVIs) for each VLAN and enable IP routing.
AnswerD

SVIs are logical Layer 3 interfaces associated with VLANs. Creating an SVI for each VLAN and enabling IP routing allows the multilayer switch to route traffic between VLANs internally. This is the standard method for inter-VLAN routing on a Catalyst switch, eliminating the need for an external router and providing high-performance routing.

Why this answer

Inter-VLAN routing on a multilayer switch is achieved by creating a Switch Virtual Interface (SVI) for each VLAN and enabling IP routing. SVIs act as default gateways for hosts in each VLAN, and the switch routes packets between them. This method is efficient, scalable, and does not require an external router, making it ideal for the branch office scenario.

Exam trap

The trap here is assuming that a routed port can belong to multiple VLANs or that Router-on-a-Stick is required for inter-VLAN routing on a multilayer switch.

1872
MCQhard

A network security engineer is configuring Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The engineer wants to rate-limit SSH traffic to 100 kbps with a burst of 8000 bytes, and ensure that any traffic exceeding the rate is dropped. The engineer applies the following policy: policy-map COPP-POLICY class SSH-CLASS police 100000 8000 exceed-action drop After applying the service-policy to the control plane, the engineer notices that SSH sessions intermittently disconnect during large file transfers over SCP. What is the most likely cause?

A.Control Plane Policing does not support the exceed-action drop keyword; the correct action is transmit.
B.The service-policy must be applied to the control plane with the input keyword, otherwise SSH traffic is not policed.
C.The police rate is configured in kilobits per second, but the burst size is in kilobytes, causing a mismatch that drops all SSH packets.
D.The police rate is configured in bits per second, but the burst size is too small for SCP transfers, causing packets to be dropped.
AnswerD

The police command specifies the rate in bits per second (100000 bps = 100 kbps) and the burst in bytes (8000 bytes). During large SCP transfers, the burst of SSH packets can exceed 8000 bytes, causing the policer to drop packets and disconnect sessions. Increasing the burst size would allow more data before policing, resolving the intermittent drops.

Why this answer

The police command uses bits per second for the rate and bytes for the burst. A 100 kbps rate with an 8000-byte burst is too restrictive for SCP file transfers, which generate bursts of SSH packets larger than 8000 bytes. The policer drops excess packets, causing SSH sessions to disconnect intermittently.

Increasing the burst size or rate would resolve the problem.

Exam trap

The trap here is confusing the units of the police command, assuming the burst is in bits or kilobytes, when it is actually in bytes, leading to an undersized burst for the traffic profile.

1873
MCQeasy

A network engineer is configuring a Cisco Nexus 9000 switch as a VXLAN tunnel endpoint. The engineer needs to define the source IP address used for the VXLAN tunnels and ensure the switch can replicate broadcast, unknown unicast, and multicast traffic. Which configuration element must be created to source the tunnels?

A.A subinterface on the uplink port configured with encapsulation dot1q and used as the NVE source.
B.A tunnel interface configured with tunnel mode gre and the underlay destination as the source.
C.A loopback interface with an IP address that is used as the NVE source in the interface nve1 configuration.
D.A VLAN interface with the same IP address as the underlay physical interface to act as the tunnel source.
AnswerC

The NVE interface on a Nexus 9000 requires a source-interface, typically a loopback, whose IP address becomes the tunnel endpoint. This address must be reachable across the underlay so remote VTEPs can establish VXLAN tunnels. Configuring the loopback and referencing it with the source-interface command under interface nve1 is the standard method to define the tunnel source.

Why this answer

On a Cisco Nexus 9000, the NVE interface is used to define VXLAN tunnel endpoints, and it must reference a source interface, typically a loopback with a stable IP address. That loopback address becomes the VTEP address that remote switches use to build tunnels. The other options describe unrelated interface types or encapsulations that do not fulfill the VXLAN tunnel source requirement.

Exam trap

The trap here is assuming any routed interface can serve as the NVE source, when a stable loopback is the standard and expected choice.

1874
MCQmedium

A network engineer runs the following command on Router R7: R7# show crypto ikev2 sa detail IKEv2 SAs: Session-id:1, Status:UP-ACTIVE, IKE count:1, Child count:1 Tunnel-id Local Remote Status Role 1 10.1.1.1/4500 10.2.2.2/4500 READY INITIATOR Encr: AES-CBC 256, Hash: SHA256, DH Grp:14, Auth sign: PSK, Auth verify: PSK Life/Active Time: 86400/3600 sec Child SA: Local selector 10.1.1.0/0 - 10.1.1.255/65535 Remote selector 10.2.2.0/0 - 10.2.2.255/65535 ESP spi in/out: 0x12345678/0x87654321 Based on this output, what can be concluded?

A.The IKEv2 SA is in a failed state because it is READY.
B.The tunnel is using pre-shared keys for authentication.
C.The tunnel is using RSA signatures for authentication.
D.The IKEv2 SA has expired because the life time is 86400 seconds.
AnswerB

The output directly shows 'Auth sign: PSK' and 'Auth verify: PSK', which are the IKEv2 authentication fields that specify the integrity/authentication algorithm used during the IKE_AUTH exchange. When both fields display 'PSK', the tunnel is unambiguously using pre-shared keys for authentication, meaning both peers derive the same symmetric key from a shared secret. This is a common, low-overhead authentication method in IPsec VPNs, and the Cisco CLI explicitly reports it in the 'show crypto ikev2 sa' or 'show crypto ikev2 profile' output.

Why this answer

The output shows 'Auth sign: PSK' and 'Auth verify: PSK', which explicitly indicates that pre-shared keys (PSK) are used for IKEv2 authentication. The status 'READY' and 'UP-ACTIVE' confirm the SA is operational, not failed. Therefore, option B is correct.

Exam trap

Cisco often tests the interpretation of 'show crypto ikev2 sa detail' output, and the trap here is that candidates may misinterpret 'READY' as a failure state or confuse 'Auth sign: PSK' with RSA signatures, especially when the output also shows encryption and hash algorithms.

How to eliminate wrong answers

Option A is wrong because 'READY' is a normal operational state for an IKEv2 SA, not a failed state; the status 'UP-ACTIVE' confirms the SA is active. Option C is wrong because the output shows 'Auth sign: PSK' and 'Auth verify: PSK', not RSA signatures; RSA signatures would appear as 'Auth sign: RSA' or similar. Option D is wrong because the lifetime of 86400 seconds (24 hours) is the configured maximum lifetime, and the 'Active Time: 3600 sec' indicates the SA has been active for 3600 seconds, not that it has expired.

1875
MCQmedium

A network architect is designing a controller-based wireless deployment for a large campus. The requirement is to provide seamless roaming for voice clients across Layer 3 boundaries while keeping the client IP address unchanged. Which Cisco SD-Access fabric feature should be used to meet this requirement?

A.Configure the fabric to use VXLAN with Layer 2 flooding and enable ARP proxy on the edge nodes.
B.Deploy a dedicated WLC in each building and configure inter-controller roaming with mobility groups.
C.Configure the fabric edge nodes to run HSRP on the anycast gateway and enable preemption for fast failover.
D.Enable IP mobility on the fabric edge nodes and configure the fabric control plane to track client locations.
AnswerD

Cisco SD-Access fabric supports IP mobility, which allows a client to roam across Layer 3 boundaries while keeping its IP address. The fabric control plane node (using LISP) tracks endpoint locations, and the edge nodes encapsulate traffic in VXLAN. When a client roams, the new edge node registers the client's new location, and the fabric forwards traffic to the correct edge, ensuring seamless roaming without IP address change.

Why this answer

In Cisco SD-Access, IP mobility is the feature that enables seamless roaming across Layer 3 boundaries while preserving the client IP address. The fabric control plane node tracks endpoint locations, and edge nodes use VXLAN encapsulation to forward traffic to the correct edge. This is essential for voice clients that require uninterrupted connectivity during roaming.

Exam trap

The trap here is assuming that traditional WLC mobility groups or Layer 2 flooding are sufficient for seamless Layer 3 roaming in an SD-Access fabric.

Page 24

Page 25 of 26

Page 26