Courseiva

ENCOR 350-401 (350-401) — Questions 1876–1923

1923 questions total · 26pages · All types, answers revealed

Page 25

Page 26 of 26

1876
MCQeasy

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) for a new office building. The company requires that guest users be isolated from internal users and that guest traffic be tunneled directly to the DMZ. Which feature should the administrator configure on the WLC?

A.Auto-anchor with dynamic VLAN assignment
B.FlexConnect with local switching
C.Mobility group with default settings
D.Guest anchor controller
AnswerD

A guest anchor controller allows guest traffic to be tunneled from the foreign controller to a designated anchor controller in the DMZ. This isolates guest traffic from internal networks and fulfills the requirement to tunnel guest traffic directly to the DMZ.

Why this answer

A guest anchor controller tunnels guest traffic from the foreign controller to an anchor controller in the DMZ, isolating guest traffic from internal networks. This is the standard Cisco WLC design for guest access, ensuring that guest traffic does not traverse internal networks and is directly routed to the DMZ.

Exam trap

The trap here is assuming that FlexConnect local switching or mobility groups alone can isolate guest traffic to the DMZ, but they do not provide the required tunneling.

1877
MCQmedium

A network administrator is designing a campus network that must support a single management IP address for a pair of Catalyst 9000 switches acting as a collapsed core. The design requires that both switches actively forward traffic, that the control plane operate as one logical device, and that a single configuration file be maintained. Which technology meets these requirements?

A.Cisco StackWise Virtual
B.Cisco IOS-XE with HSRP and GLBP
C.Cisco StackWise with a StackWise cable
D.Virtual Port Channel with HSRP
AnswerA

StackWise Virtual combines two Catalyst 9000 switches into one logical entity with a single management IP and one configuration file. Both switches actively forward traffic in an active-active fashion using a virtual switch link, which exactly matches the requirement for one logical control plane and dual active forwarding in a collapsed core design.

Why this answer

StackWise Virtual merges two Catalyst 9000 switches into a single logical switch using a virtual switch link. It provides one management IP, one configuration file, and active-active forwarding, which is precisely what the collapsed core design requires. Classic StackWise is intended for different topologies, while vPC with HSRP and HSRP/GLBP keep separate control planes and configurations, so they do not meet the single logical device requirement.

Exam trap

The trap here is equating first-hop redundancy protocols such as HSRP with a true single-control-plane switch virtualization technology.

1878
Drag & Dropmedium

Drag and drop the steps of SNMP trap generation and forwarding into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The SNMP agent monitors the device for a defined event, then builds a trap message including the OID and value, encapsulates it in a UDP packet, looks up the trap destination in the SNMP configuration, and finally forwards the packet to the NMS.

1879
MCQmedium

A network engineer runs the following command on Router R1: R1# show bgp summary BGP router identifier 10.0.0.1, local AS number 65001 BGP table version is 14, main routing table version 14 4 network entries using 1152 bytes of memory 4 path entries using 320 bytes of memory 2/1 BGP path/bestpath attribute entries using 560 bytes of memory 0 BGP route reflector client to client reflections 2 BGP community entries using 80 bytes of memory Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 10.0.1.2 4 65002 2345 2346 14 0 0 00:12:34 3 10.0.1.3 4 65003 1234 1235 14 0 0 00:08:21 2 10.0.1.4 4 65004 567 568 14 0 0 00:05:45 0 Based on this output, what can be concluded?

A.Neighbor 10.0.1.4 is in the 'Active' state because it received 0 prefixes.
B.Neighbor 10.0.1.4 has sent 0 prefixes to R1.
C.Neighbor 10.0.1.4 is not advertising any prefixes to R1.
D.The BGP session with 10.0.1.4 is down.
AnswerC

The value 0 in the State/PfxRcd column means the BGP session with 10.0.1.4 is fully established (otherwise a state word would appear), but R1 has not received any network-layer reachability information from that neighbor. This situation occurs when 10.0.1.4 has no routes to advertise, or an outbound route-map, prefix-list, or filter is suppressing its advertisements. Since the session is up, the lack of prefixes is a routing-policy outcome, not a session failure. Thus, the neighbor is simply not advertising any prefixes to R1.

Why this answer

The 'State/PfxRcd' column shows the number of prefixes received from each neighbor. Neighbor 10.0.1.4 has a value of 0, meaning it has not advertised any prefixes to R1. The session is established (Up/Down shows 00:05:45), so the neighbor is reachable and the BGP session is up, but it is not sending any prefixes.

Exam trap

The trap here is that candidates may misinterpret the '0' in the 'State/PfxRcd' column as a session failure or that R1 is not sending prefixes, when it actually indicates the neighbor is not advertising any prefixes to R1.

How to eliminate wrong answers

Option A is wrong because the neighbor is in the 'Established' state (indicated by the Up/Down timer), not 'Active'; the 'Active' state would show a different status in the State/PfxRcd column. Option B is wrong because the 'MsgSent' column (568) indicates messages sent to the neighbor, but the 'State/PfxRcd' column shows prefixes received from the neighbor, not sent by R1. Option D is wrong because the Up/Down timer of 00:05:45 confirms the BGP session is up and established, not down.

1880
MCQeasy

A network engineer is designing an OSPF network with multiple areas. The engineer wants to ensure that routers in area 2 can reach networks in area 0, but they should not learn any external routes from other ASs. Which OSPF area type should be configured for area 2?

A.Stub area
B.Not-so-stubby area (NSSA)
C.Totally stubby area
D.Standard area
AnswerA

A stub area is the correct choice because it filters out Type 5 (external) LSAs, preventing the router from learning external routes. Instead, the ABR automatically injects a default route (0.0.0.0/0) into the stub area, which routers use to forward traffic to destinations outside the OSPF domain. This satisfies the requirement of not learning external routes while still allowing full outbound connectivity.

Why this answer

A stub area blocks Type 5 LSAs (external routes from other ASs) while allowing Type 3 summary LSAs from area 0. This ensures routers in area 2 can reach networks in area 0 via inter-area routes but do not learn external routes, meeting the requirement exactly.

Exam trap

Cisco often tests the distinction between stub and totally stubby areas: candidates confuse 'blocking external routes' with 'blocking all routes except the default,' forgetting that a stub area still allows inter-area summary LSAs (Type 3) from area 0.

How to eliminate wrong answers

Option B (NSSA) is wrong because it allows Type 7 LSAs to carry external routes into the area, which would still introduce external routes from other ASs, violating the requirement. Option C (totally stubby area) is wrong because it blocks both Type 5 and Type 3 LSAs, preventing routers in area 2 from learning inter-area routes to networks in area 0. Option D (standard area) is wrong because it permits all LSA types, including Type 5 external LSAs, so routers would learn external routes from other ASs.

1881
MCQmedium

A network architect is designing a Cisco SD-Access fabric for a hospital campus. The hospital requires that guest wireless users be allowed access only to the internet, while clinical staff devices must reach internal EHR servers. The fabric uses Cisco DNA Center and Cisco Identity Services Engine for policy. Which fabric component enforces the group-based policy between these user groups?

A.The Cisco DNA Center Intent API translating business intent into device configuration
B.The fabric control plane node running LISP map-server functions
C.The fabric intermediate node forwarding VXLAN-encapsulated traffic between edge nodes
D.The fabric edge node applying Cisco TrustSec group-based access control lists
AnswerD

Fabric edge nodes encapsulate traffic in VXLAN and enforce group-based policy using Cisco TrustSec security group tags and scalable group ACLs derived from ISE policy. When a guest wireless user tries to reach an EHR server, the ingress edge node drops the packet based on the source and destination security group tags. This directly delivers the required isolation between guest and clinical traffic in the SD-Access fabric.

Why this answer

Group-based policy in a Cisco SD-Access fabric is enforced at the fabric edge node using Cisco TrustSec security group tags and scalable group ACLs, with group membership and policy defined in Cisco Identity Services Engine. This lets the hospital block guest-to-EHR flows while permitting clinical staff access, without redesigning VLANs or subnets for each user category.

Exam trap

The trap here is assuming the controller or the underlay enforces user policy, when enforcement actually occurs on the fabric edge node through group-based ACLs.

1882
MCQmedium

A network engineer checks AAA accounting on a router: R1# show aaa accounting Accounting method list 'default': Type: exec Start-stop: group radius Accounting records: Total started: 10 Total stopped: 8 Total failed: 2 Last record: user 'admin', start time 00:01:00 UTC Mar 1 2023 Based on this output, what can be concluded?

A.All accounting records were successfully sent.
B.Accounting is configured for EXEC sessions using RADIUS.
C.Accounting is performed using TACACS+.
D.No users have logged in since accounting was enabled.
AnswerB

The running configuration includes the command 'aaa accounting exec start-stop group radius', which directs the router to generate a start accounting record when a user initiates an EXEC session (such as SSH or console) and a stop record when that session ends. The 'exec' keyword specifically applies to user shell sessions, not to network services like dot1x or VPN, and 'group radius' identifies the RADIUS server group as the destination. This matches the output and is the correct interpretation.

Why this answer

The output shows an accounting method list named 'default' for type 'exec' using 'group radius' with start-stop accounting. This confirms that accounting is configured for EXEC sessions (user logins) and that RADIUS is the protocol used to send accounting records. The 'Total started: 10' and 'Total stopped: 8' indicate some records were not successfully stopped, but the configuration itself is correctly identified.

Exam trap

Cisco often tests the distinction between authentication and accounting configuration, and the trap here is that candidates may see 'Total failed: 2' and incorrectly assume the configuration is broken, rather than recognizing that the output still clearly shows the accounting method list is correctly set to RADIUS for EXEC sessions.

How to eliminate wrong answers

Option A is wrong because 'Total failed: 2' indicates that 2 accounting records were not successfully sent, contradicting the claim that all records were successfully sent. Option C is wrong because the output explicitly shows 'group radius', not TACACS+, as the accounting method. Option D is wrong because 'Total started: 10' and the last record showing user 'admin' with a start time prove that users have logged in since accounting was enabled.

1883
Drag & Dropmedium

Drag and drop the steps of 802.1X port authentication with MAB fallback into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The switch first attempts 802.1X by sending an EAP-Request/Identity. If no response is received, it initiates MAB by sending a RADIUS Access-Request with the MAC address. The RADIUS server checks the MAC against its database and responds with Access-Accept or Access-Reject.

The switch then opens or blocks the port accordingly.

1884
MCQmedium

router bgp 65000 bgp router-id 10.0.0.1 neighbor 10.0.0.2 remote-as 65001 neighbor 10.0.0.2 ebgp-multihop 2 neighbor 10.0.0.2 update-source Loopback0 ! What is the purpose of the ebgp-multihop 2 command?

A.It allows the eBGP session to be established with a neighbor that is not directly connected, with a maximum of 2 hops.
B.It sets the maximum number of prefixes that can be received from the neighbor to 2.
C.It limits the number of paths BGP can install for load balancing to 2.
D.It enables BGP multipath for eBGP with a hop count of 2.
AnswerA

Correct. In standard eBGP, the IP TTL of BGP packets is set to 1 by default, meaning the neighbor must be directly connected at the link layer. The `ebgp-multihop 2` command increases the TTL to 2, letting the BGP update traverse one intermediate router and enabling the session to an eBGP peer that is not directly connected. This is commonly used when peering between loopback interfaces for resilience or when the peer is reachable through a multihop path.

Why this answer

The ebgp-multihop 2 command allows an eBGP session to be established between peers that are not directly connected at Layer 3. By setting the TTL to 2, it permits the BGP packets to traverse one intermediate router (hop) to reach the neighbor, which is necessary when using loopback interfaces for eBGP peering.

Exam trap

Cisco often tests the distinction between ebgp-multihop (which adjusts TTL for non-directly connected peering) and BGP multipath (which enables load balancing), causing candidates to confuse the two features.

How to eliminate wrong answers

Option B is wrong because the command to set the maximum number of prefixes received from a neighbor is 'neighbor maximum-prefix', not ebgp-multihop. Option C is wrong because BGP multipath for load balancing is configured with 'maximum-paths' (or 'maximum-paths ibgp'/'maximum-paths ebgp'), not with ebgp-multihop. Option D is wrong because ebgp-multihop does not enable BGP multipath; it only adjusts the TTL to allow non-directly connected eBGP peering, while multipath is a separate feature for load balancing across multiple equal-cost paths.

1885
MCQeasy

A network engineer is configuring a Cisco Catalyst switch to participate in a StackWise Virtual domain. The engineer needs to ensure that the two switches form a single logical entity and that the control plane is synchronized. Which statement correctly describes a requirement for StackWise Virtual operation?

A.The switches must be configured with different hostnames and separate management IP addresses to avoid conflicts.
B.The switches must use a dedicated StackWise cable and can be from different Catalyst switch families.
C.The switches must be connected via a standard 1 Gigabit Ethernet uplink and can run different software versions.
D.The switches must be connected by a StackWise Virtual Link using supported ports, and they must run the same software version.
AnswerD

StackWise Virtual requires a dedicated StackWise Virtual Link (SVL) between the two switches using supported high-bandwidth ports, and both switches must run identical software versions to form a single logical entity. This ensures control plane synchronization and consistent forwarding behavior, which is essential for the domain to operate correctly.

Why this answer

StackWise Virtual combines two physical switches into one logical switch. It requires a dedicated high-bandwidth StackWise Virtual Link using supported ports and identical software versions on both switches. This allows a single control plane, unified management, and simplified topology without Spanning Tree loops between the pair.

Exam trap

The trap here is assuming StackWise Virtual uses the same dedicated stacking cable as traditional StackWise, when it actually uses supported Ethernet ports for the virtual link.

1886
MCQeasy

A network engineer is configuring OSPF on a router that has multiple interfaces in the same area. The engineer wants to ensure that the router does not become the designated router (DR) on any of these interfaces. What should the engineer do?

A.Set the OSPF priority to 0 on all interfaces.
B.Configure the OSPF network type as point-to-point on all interfaces.
C.Use the 'ip ospf dr-priority' command to set a high priority on other routers.
D.Configure the router as an ABR.
AnswerA

In OSPF, DR/BDR election on broadcast multi-access networks is determined by the interface priority (range 0-255). Setting the 'ip ospf priority 0' command on every local interface makes the router ineligible to ever be elected as DR or BDR, because OSPF only considers routers with a non-zero priority as candidates. This is the standard, granular way to prevent a specific router from taking that control-plane role without altering the network type or affecting other routers' eligibility.

Why this answer

Setting the OSPF priority to 0 on all interfaces prevents the router from participating in the DR/BDR election process. A router with priority 0 will never become the DR or BDR on any segment, regardless of its Router ID or other factors. This is the only method that guarantees the router will not be elected as DR on any interface.

Exam trap

The trap here is that candidates often confuse DR/BDR election prevention with network type changes, thinking that point-to-point is the only way to avoid DR election, but the priority 0 method is the direct and correct answer for preventing a specific router from becoming DR without altering the network type.

How to eliminate wrong answers

Option B is wrong because configuring the OSPF network type as point-to-point eliminates the need for a DR/BDR election entirely, but it does not prevent the router from becoming the DR on interfaces that are not point-to-point; it changes the election behavior on those specific interfaces, but the question asks for a solution that works on all interfaces without altering the network type. Option C is wrong because setting a high priority on other routers does not guarantee that this router will not become the DR; if those other routers are not present or have lower Router IDs, this router could still be elected. Option D is wrong because configuring the router as an ABR (Area Border Router) has no effect on DR/BDR election; ABR status is about routing between areas, not about interface election roles.

1887
Multi-Selectmedium

A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator needs to ensure that the VPN traffic is encrypted and authenticated. Which two protocols are used in IPsec to provide encryption and authentication? (Choose two.)

Select 2 answers
A.L2TP
B.SSL
C.AH
D.GRE
E.ESP
AnswersC, E

Authentication Header (AH) is an IPsec protocol that provides authentication and integrity but does not provide encryption. It ensures that the data is from a legitimate source and has not been altered. In the scenario, AH can be used for authentication, but it does not encrypt the traffic.

Why this answer

ESP and AH are the two core IPsec protocols. ESP provides encryption and optional authentication, while AH provides authentication and integrity but no encryption. Together or separately, they can secure VPN traffic.

The other options are tunneling or security protocols not part of IPsec's native encryption and authentication mechanisms.

Exam trap

The trap here is confusing tunneling protocols like GRE or L2TP with IPsec protocols, or thinking that SSL is part of IPsec when it is a separate security protocol.

1888
Matchingmedium

Drag and drop each OSPF LSA type on the left to its matching description on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Describes the router's own directly connected links and neighbors

Generated by the Designated Router to describe all routers attached to a multi-access segment

Advertises networks from one area into another area (inter-area routes)

Advertises the location of an Autonomous System Boundary Router (ASBR)

Advertises routes redistributed from another routing domain (external routes)

Why these pairings

LSA Type 1 (Router LSA) describes a router's own links; Type 2 (Network LSA) is generated by the DR; Type 3 (Summary LSA) advertises inter-area routes; Type 4 (ASBR Summary LSA) advertises the location of an ASBR; Type 5 (AS External LSA) advertises external routes.

1889
MCQhard

A network automation team is using NETCONF to configure a Cisco IOS XE device. They send an <edit-config> RPC with the default-operation set to 'merge'. The target configuration already has an interface GigabitEthernet0/1 with an IP address of 10.1.1.1/24. The RPC payload includes a new IP address of 10.1.1.2/24 for the same interface. What will be the result on the device?

A.The interface will have both IP addresses configured as secondary addresses.
B.The device will ignore the new IP address and keep the existing one.
C.The existing IP address will be replaced with the new IP address.
D.The RPC will fail with a 'data-exists' error because the IP address is already configured.
AnswerC

In NETCONF, the 'merge' operation combines the configuration data in the RPC with the existing configuration. For a leaf node like the IP address, which is a single instance, the new value overwrites the existing value. The interface will end up with only the new IP address 10.1.1.2/24. This is because the merge operation updates the leaf with the provided value, effectively replacing the old one.

Why this answer

The NETCONF 'merge' operation (default-operation='merge') combines the RPC's configuration with the device's existing configuration. For a leaf node such as an IP address, which can only have one value, the merge results in the new value overwriting the old one. Therefore, the interface's IP address is replaced with 10.1.1.2/24.

This behavior is consistent with the NETCONF RFC 6241, where merge updates existing data and creates new data as needed.

Exam trap

The trap here is thinking that merge operation adds to existing configuration without overwriting, but for single-instance leaf nodes, it replaces the value.

1890
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate management users via TACACS+. The router must use the TACACS+ server at 10.1.1.100 with the shared secret 'Cisco123'. The administrator wants to ensure that if the TACACS+ server is unreachable, authentication falls back to the local database. Which configuration is required?

A.aaa authentication login default group tacacs+ none
B.aaa authentication login default group tacacs+ enable
C.aaa authentication login default local group tacacs+
D.aaa authentication login default group tacacs+ local
AnswerD

This command configures AAA authentication for login using the default method list. It specifies that the TACACS+ group should be tried first, and if the server is unreachable, the local database is used as a fallback. This meets the requirement for fallback authentication. The 'group tacacs+' keyword refers to the TACACS+ servers defined with the 'tacacs server' command.

Why this answer

The correct command is 'aaa authentication login default group tacacs+ local'. It configures the default method list to attempt TACACS+ authentication first, and if the TACACS+ server is unreachable, it falls back to the local username and password database. This provides redundancy while maintaining individual user accountability.

Exam trap

The trap here is the order of methods in the AAA authentication command; placing 'local' before 'group tacacs+' changes the fallback behavior and may inadvertently allow local credentials to be used even when the TACACS+ server is available.

1891
MCQmedium

A network administrator is deploying a Cisco Catalyst 9300 switch stack at the access layer. The security policy requires that when an unauthorized device connects to an access port, the port must immediately stop forwarding traffic, generate a syslog message, and increment the violation counter, while allowing the administrator to manually re-enable the port after investigation. Which port security violation mode should be configured?

A.err-disable recovery
B.protect
C.restrict
D.shutdown
AnswerD

Shutdown mode places the port into an err-disabled state immediately upon a violation, stops all forwarding, generates a syslog message, and increments the violation counter. Recovery requires manual intervention (or err-disable recovery configuration), matching the scenario's requirement that the administrator re-enable the port after investigation. This is the classic default violation mode on Cisco Catalyst switches and satisfies every stated condition.

Why this answer

Port security shutdown mode is the only violation action that immediately err-disables the interface, halts forwarding, logs a syslog message, increments the violation counter, and requires manual recovery. Protect and restrict leave the port up, and err-disable recovery is a global timer feature rather than a violation mode. The stated need for manual re-enablement after investigation confirms shutdown is correct.

Exam trap

The trap here is assuming that restrict mode shuts down the port because it logs violations, when in fact only shutdown mode err-disables the interface.

1892
Drag & Dropmedium

Drag and drop the steps of QoS pre-classify for encrypted VPN traffic into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, the crypto map is configured with QoS pre-classify (A) to enable the feature. Next, the service-policy is applied to the tunnel interface (B) to enforce QoS. When a packet arrives, the original packet enters the router before encryption (C).

Classification and policing are performed based on the original marking (E). Afterwards, the original DSCP is copied to the encrypted packet header (D) to preserve QoS markings. This sequence ensures correct QoS treatment for VPN traffic.

1893
Matchingmedium

Drag and drop each Control plane protection feature on the left to its matching threat on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

CPU overload from excessive control plane traffic

IP spoofing attacks

Rogue DHCP server

ARP cache poisoning

IP spoofing on access ports

Why these pairings

CoPP protects against CPU overload; uRPF against IP spoofing; DHCP snooping against rogue DHCP server; DAI against ARP cache poisoning; IP Source Guard against IP spoofing on access ports.

1894
MCQhard

Refer to the exhibit. R1 has two equal-cost OSPF E2 routes to 10.1.1.0/24 via two different next hops. However, when tracing to 10.1.1.1, all traffic uses the path through 10.0.1.2. What is the most likely reason?

A.One route has a higher administrative distance.
B.A default route is overriding the specific route.
C.The route via 10.0.2.2 is an E1 route.
D.OSPF E2 routes do not factor interface cost; but the router uses the interface cost as a tie-breaker for equal-cost routes.
AnswerD

OSPF E2 routes advertise the external metric from the ASBR and intentionally discard the internal cost accumulated along the path, so two E2 routes with the same metric appear equal. However, Cisco IOS and many other implementations avoid a random choice by applying a tie-breaking rule: when the E2 metric and AD are identical, the router compares the OSPF interface cost (or the cost to the ASBR) and prefers the path with the lower cost. In the exhibit, the two E2 routes have equal external metrics, but the route via the interface with lower cost is installed, while the other is held as a candidate. Thus, the apparent equal-cost routes are not truly equal for forwarding because interface cost breaks the tie.

Why this answer

OSPF E2 routes do not include the internal cost to the ASBR; the cost shown in the routing table is the external metric only. When two E2 routes have the same external metric, Cisco IOS uses the interface cost as a tie-breaker to select the best next hop. In this scenario, the interface to 10.0.1.2 has a lower cost than the interface to 10.0.2.2, so all traffic is forwarded via 10.0.1.2.

Exam trap

Cisco often tests the subtle tie-breaking behavior for OSPF E2 routes, where candidates mistakenly assume that equal-cost E2 routes will always be load-balanced, ignoring the interface cost tie-breaker that Cisco IOS applies.

How to eliminate wrong answers

Option A is wrong because administrative distance is a per-protocol preference and both routes are OSPF E2 routes, so they share the same AD (110 by default). Option B is wrong because a default route would only be used if no specific route to 10.1.1.0/24 existed; the router has two specific routes and will use them, not a default. Option C is wrong because if the route via 10.0.2.2 were an E1 route, it would include the internal cost to the ASBR, making its total metric higher than the E2 route, and it would not be considered equal-cost; the question states both are equal-cost E2 routes.

1895
MCQhard

A network engineer is using the Cisco Catalyst Center (formerly DNA Center) Intent API to retrieve a list of all network devices. The engineer sends a GET request to /dna/intent/api/v1/network-device but receives a 401 Unauthorized error. The engineer has already obtained a valid authentication token from /dna/system/api/v1/auth/token. What is the most likely reason for the 401 error?

A.The token has expired and must be refreshed every 60 minutes.
B.The token must be URL-encoded before being placed in the header.
C.The token must be included in the request header as 'X-Auth-Token: <token>'.
D.The API endpoint requires the token to be sent as a Bearer token in the Authorization header.
AnswerC

The Cisco Catalyst Center Intent API requires the authentication token to be passed in the HTTP header 'X-Auth-Token'. If the token is included in the body or as a query parameter, the API will reject the request with 401 Unauthorized. The engineer must set the header correctly. This is a common mistake when first using the API.

Why this answer

The Cisco Catalyst Center Intent API uses a custom authentication header named 'X-Auth-Token' to pass the token obtained from the authentication endpoint. Failure to include this header, or using a different scheme like Bearer, results in a 401 Unauthorized error. The engineer must set 'X-Auth-Token' with the token value in all subsequent API calls.

Exam trap

The trap here is assuming that Catalyst Center uses standard OAuth Bearer tokens, when it actually requires a proprietary X-Auth-Token header.

1896
MCQhard

A network engineer runs the following debug on a router: R1# debug aaa authentication *Mar 1 00:01:23.456: AAA/BIND(00000001): Bind iplist *Mar 1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Pick method list 'default' *Mar 1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Method=RADIUS *Mar 1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): RADIUS server 10.1.1.10:1812, timeout 5, retransmit 2 *Mar 1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Sent username 'admin', password **** *Mar 1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Received PASS response *Mar 1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Pass Based on this output, what can be concluded?

A.Authentication failed due to incorrect password.
B.The router used TACACS+ for authentication.
C.The RADIUS server 10.1.1.10 authenticated the user successfully.
D.The user 'admin' was authenticated using local database.
AnswerC

The debug output shows the RADIUS server 10.1.1.10 responding to the authentication request with a PASS response, which is the RADIUS Access-Accept message. This confirms that the server successfully authenticated the user, and the router accepts the session. The output also identifies the username as 'admin' and marks the authentication as successful with 'Pass,' so the correct answer is that the RADIUS server authenticated the user successfully.

Why this answer

The debug output shows a successful AAA authentication process: the router binds to an IP list, selects the default method list, attempts RADIUS authentication against server 10.1.1.10:1812, sends the username 'admin' with a masked password, and receives a 'PASS response' followed by 'Pass'. This confirms that the RADIUS server authenticated the user successfully, making option C correct.

Exam trap

Cisco often tests the distinction between RADIUS and TACACS+ by including port numbers or method names in debug output, and the trap here is that candidates may assume 'PASS response' could mean local authentication or fail to notice the RADIUS-specific port 1812.

How to eliminate wrong answers

Option A is wrong because the debug output explicitly shows 'Received PASS response' and 'Pass', indicating successful authentication, not a failure due to incorrect password. Option B is wrong because the debug shows 'Method=RADIUS' and the server uses port 1812 (RADIUS default), not TCP port 49 used by TACACS+. Option D is wrong because the method list selected is 'default' and the method used is RADIUS, not local authentication; there is no indication of a local database lookup.

1897
Multi-Selectmedium

Which two statements about IP SLA with object tracking are true? (Choose two.)

Select 2 answers
A.A tracking object can monitor the state of an IP SLA operation and change state when the operation fails.
B.The 'track' command is used to create a tracking object that references an IP SLA operation by its operation number.
C.Object tracking can only be used with static routes, not with dynamic routing protocols like EIGRP or OSPF.
D.The tracking object automatically modifies the routing table when the IP SLA operation fails.
E.An IP SLA operation can be configured after the tracking object that references it.
AnswersA, B

The tracker polls the referenced IP SLA operation's return code and transitions between up and down accordingly, so downstream features react to probe failure. This satisfies the stem's requirement that a tracking object monitor operation state and change state on failure.

Why this answer

Option A is correct because a track object tied to an IP SLA operation (via 'track 1 ip sla 1 reachability' or 'state') polls that operation's return code and transitions the object between Up and Down when the probe fails or recovers, which is the core purpose of IP SLA object tracking. Option B is correct because the 'track' command creates the tracking object and references the IP SLA operation by its operation number (for example, 'track 1 ip sla 1'), linking the tracker to that specific probe. Option C is wrong because tracked objects can be referenced by static routes, policy-based routing, HSRP/VRRP, and dynamic routing protocols such as EIGRP or OSPF to influence their behavior.

Option D is wrong because the tracking object only changes its own Up/Down state and notifies clients; it does not itself edit the routing table, since the referencing route or protocol must be configured to react to the tracker. Option E is wrong because the IP SLA operation must already exist before the tracking object can reference it by number, so the operation cannot be configured afterward.

Exam trap

350-401 often tests the dependency order: the IP SLA operation must be configured before the tracking object, and candidates may mistakenly think the tracking object can be created first.

1898
MCQhard

A network administrator runs the following debug on a router: R1# debug aaa authorization *Mar 1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Processing author request for user 'jdoe' *Mar 1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Method=TACACS+ *Mar 1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): TACACS+ server 10.1.1.10:49, timeout 5 *Mar 1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Sent author request *Mar 1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Received PASS response *Mar 1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Pass Based on this output, what can be concluded?

A.The user jdoe failed authorization.
B.Authorization was performed using RADIUS.
C.The TACACS+ server authorized the user successfully.
D.The user was authenticated but not authorized.
AnswerC

The TACACS+ server responded with a PASS result for the authorization request, which signifies that the user jdoe was authorized successfully. In TACACS+, the server sends a set of AV-pairs along with the PASS result, defining the user's permitted commands or services. This output confirms that the server granted the user the requested authorization.

Why this answer

The debug output shows a 'Received PASS response' from the TACACS+ server at 10.1.1.10:49, followed by 'Pass'. This indicates that the TACACS+ authorization request for user 'jdoe' was successful. TACACS+ encrypts the entire packet and separates authentication, authorization, and accounting (AAA), allowing granular authorization control.

Exam trap

Cisco often tests the distinction between authentication and authorization; the trap here is that candidates see 'authorization' and assume a PASS response means authentication succeeded, but the debug is specifically for authorization, and a PASS response only confirms authorization was granted, not that authentication occurred (though in practice, authorization typically follows authentication).

How to eliminate wrong answers

Option A is wrong because the debug clearly shows a 'PASS response' and 'Pass', not a failure. Option B is wrong because the debug explicitly states 'Method=TACACS+' and references TACACS+ server 10.1.1.10:49; RADIUS uses UDP ports 1812/1813 and does not separate authorization from authentication in the same way. Option D is wrong because the debug is specifically for 'debug aaa authorization', and the 'Received PASS response' confirms authorization succeeded; authentication is a separate process not shown here, but the authorization pass implies the user was already authenticated.

1899
MCQhard

A network automation team is using the ncclient Python library to configure a Cisco IOS XE router via NETCONF. The engineer wants to ensure the configuration changes are applied atomically and that the device automatically rolls back if any part of the change fails. Which NETCONF capability must the engineer verify is advertised by the device before relying on this behavior?

A.urn:ietf:params:netconf:capability:candidate:1.0
B.urn:ietf:params:netconf:capability:writable-running:1.0
C.urn:ietf:params:netconf:capability:validate:1.0
D.urn:ietf:params:netconf:capability:confirmed-commit:1.0
AnswerD

The confirmed-commit capability enables a commit operation that must be confirmed within a specified timeout; if confirmation does not occur, the device automatically reverts to the previous configuration. This provides the automatic rollback behavior the engineer needs. Without this capability, a failed or unconfirmed commit would leave the device in the new configuration state, so verifying its advertisement is essential for atomic, safe changes.

Why this answer

To achieve atomic configuration with automatic rollback, the NETCONF confirmed-commit capability is required. It allows a commit to be provisional until explicitly confirmed; if confirmation is not received within the timeout, the device reverts to the prior configuration. Verifying that the device advertises this capability ensures the automation can rely on rollback semantics rather than leaving the device in an inconsistent state after a failure.

Exam trap

The trap here is confusing the candidate datastore capability with confirmed-commit, assuming that using a candidate automatically provides rollback when in fact only confirmed-commit does.

1900
MCQhard

A network engineer is designing a data center network using Cisco ACI. The design must support multiple tenants with isolated policies. The engineer needs to ensure that traffic between endpoints in different tenants is blocked by default. Which ACI construct provides this isolation?

A.Tenant
B.VRF
C.Bridge Domain
D.Contract
AnswerA

In Cisco ACI, a tenant is the top-level logical container that provides administrative, fault, and policy isolation. Endpoints, EPGs, VRFs, bridge domains, and contracts all reside within a tenant, and traffic between different tenants is blocked by default unless an explicit contract establishes a communication path. This is why tenant, not any sub-tenant construct, is the correct answer for the entity that isolates traffic between separate organizations or departments.

Why this answer

In Cisco ACI, a Tenant is the top-level logical container that provides administrative and policy isolation. By default, endpoints in different tenants cannot communicate because each tenant has its own separate policy domain, and no contracts exist between them. This makes the Tenant the correct construct for ensuring traffic between different tenants is blocked by default.

Exam trap

Cisco often tests the misconception that VRFs or Bridge Domains provide cross-tenant isolation, but the trap here is that VRFs and BDs are scoped within a single tenant and do not inherently block traffic between different tenants—only the Tenant construct enforces default isolation.

How to eliminate wrong answers

Option B is wrong because a VRF (Virtual Routing and Forwarding) provides Layer 3 network segmentation within a tenant, but it does not enforce policy isolation between tenants; multiple VRFs can exist within the same tenant and inter-VRF traffic can be allowed via contracts. Option C is wrong because a Bridge Domain (BD) is a Layer 2 forwarding construct within a tenant that defines a subnet and associated VRF, but it does not provide cross-tenant isolation; BDs are scoped to a single tenant. Option D is wrong because a Contract defines the rules for allowed communication between endpoint groups (EPGs) within or across tenants, but it is not the default isolation mechanism; contracts are used to explicitly permit traffic, whereas isolation between tenants is inherent to the Tenant construct itself.

1901
MCQmedium

A network administrator is deploying a Cisco IOS-XE router as the WAN edge. The security policy requires that the router itself be protected against brute-force SSH attacks originating from the untrusted internet, without affecting transit traffic forwarded through the router. The administrator wants to use a feature that automatically blocks the offending source IP after repeated failed login attempts. Which Cisco IOS-XE feature should be configured?

A.Zone-Based Firewall with a policy dropping TCP port 22 inbound
B.IP Source Guard on the WAN interface
C.Control Plane Policing (CoPP) with a class-map matching TCP port 22
D.Login Enhancements (login block-for) with an ACL triggered after failed attempts
AnswerD

The login block-for feature, often called Login Enhancements, monitors failed login attempts against the router's local authentication and, when the threshold is exceeded within the configured window, places a temporary ACL that blocks all further login attempts from offending sources for the quiet period. It protects the router's control plane without affecting transit traffic, matching the stated requirement exactly.

Why this answer

The login block-for command, part of Cisco IOS Login Enhancements, watches failed authentication attempts against the device itself. When the configured failure threshold is crossed inside the observation window, the router installs a temporary access list that denies further login attempts from offending hosts for the quiet period. Because it only affects traffic destined to the router's management plane, transit forwarding is unaffected, which is precisely what the scenario demands.

Exam trap

The trap here is assuming that CoPP or an ACL can provide dynamic, attempt-triggered blocking of brute-force sources, when only Login Enhancements tracks failed logins and applies the temporary deny automatically.

1902
MCQhard

An engineer is deploying Cisco SD-Access and wants to separate the roles of the underlay and the fabric overlay. The design must provide a Layer 3 routed underlay using IS-IS, and the fabric edge nodes must register endpoint information with a fabric control-plane node. Which node type in Cisco SD-Access is responsible for mapping endpoint identity to location and answering EID-to-RLOC queries from fabric edge nodes?

A.Fabric border node
B.Fabric wireless controller
C.Fabric control-plane node
D.Fabric intermediate node
AnswerC

The fabric control-plane node runs LISP map-server and map-resolver functions. Fabric edge nodes register endpoint EIDs with it, and it answers EID-to-RLOC map requests so that edge nodes can build VXLAN tunnels to the correct destination. In this design it is the component that owns identity-to-location mapping, satisfying the requirement stated in the scenario.

Why this answer

In Cisco SD-Access, the fabric control-plane node hosts the LISP map-server and map-resolver. Fabric edge nodes register endpoint identifiers with it, and it answers EID-to-RLOC queries, enabling VXLAN tunnel establishment between edge nodes. That responsibility matches the requirement to map endpoint identity to location.

Exam trap

The trap here is confusing the border node, which connects the fabric to outside networks, with the control-plane node, which owns LISP mapping and endpoint registration.

1903
MCQmedium

A network administrator is using Cisco DNA Center Assurance to monitor the health of a wireless network. The administrator notices that a particular access point is reporting a high number of client association failures. Which Cisco DNA Center Assurance feature should be used to correlate these failures with client device types and identify the root cause?

A.Network Health dashboard
B.Client 360
C.Path Trace
D.Application Health dashboard
AnswerB

Client 360 provides a comprehensive view of a specific client's experience, including connection history, onboarding issues, and performance metrics. It correlates data such as association failures with client device type, operating system, and location, enabling the administrator to identify patterns and root causes of wireless connectivity problems.

Why this answer

Client 360 in Cisco DNA Center Assurance is designed to provide detailed insights into individual client devices, including their onboarding process, association failures, and performance. By using Client 360, the administrator can filter and analyze association failures by client type, helping to pinpoint whether specific devices are experiencing issues due to compatibility or configuration problems.

Exam trap

The trap here is confusing Client 360 with the Network Health dashboard, but only Client 360 offers per-client granularity and correlation with device types.

1904
MCQhard

A network architect is designing a Cisco SD-Access fabric. The requirement is to provide Layer 3 isolation between different departments while allowing them to share the same physical network. Which Cisco SD-Access component is responsible for providing this isolation?

A.Locator/ID Separation Protocol (LISP)
B.Scalable Group Tag (SGT)
C.Virtual Network (VN)
D.VXLAN Network Identifier (VNI)
AnswerC

In Cisco SD-Access, a Virtual Network (VN) is a logical partition that provides Layer 3 isolation. Each VN is associated with a VRF, and endpoints in different VNs cannot communicate at Layer 3 unless there is a fusion router or external policy. This meets the requirement for department isolation while sharing the physical underlay.

Why this answer

In Cisco SD-Access, Layer 3 isolation between departments is achieved by assigning them to different Virtual Networks (VNs). Each VN is essentially a separate VRF, and the fabric uses VXLAN with distinct VNIs to carry traffic for each VN. This allows the same physical infrastructure to support multiple isolated logical networks.

Exam trap

The trap here is confusing the data plane identifier (VNI) with the logical isolation construct (VN). While a VNI is used to separate traffic in the encapsulation, the actual Layer 3 isolation is provided by the VN's associated VRF.

1905
MCQhard

A company is deploying an SD-Access fabric with a centralized policy model. The design must ensure that all traffic between virtual networks (VNs) is inspected by a firewall. Which fabric role should be used to enforce this inter-VN policy?

A.Fabric border node
B.Fabric edge node
C.Fabric control plane node
D.Fabric WAN router
AnswerA

The fabric border node is the correct answer because it serves as the gateway between the SD-Access fabric and external networks (such as a data center or WAN). Critically, border nodes can apply policy-based routing (PBR) to inter-VN traffic, allowing it to be steered to an external firewall for inspection before being allowed to continue — a capability that makes the border node the natural point for inter-VN policy enforcement. In Cisco SD-Access, border nodes also perform LISP proxy-ETR (PETR) and proxy-ITR functionality, enabling them to handle traffic destined outside the fabric and to apply security policy at the network edge without needing a dedicated internal firewall. Thus, the border node is specifically designed to enforce inter-VN security policy, not just forward traffic.

Why this answer

In a centralized policy model for SD-Access, the fabric border node is the correct role to enforce inter-VN traffic policies because it is the only node that can route traffic between different virtual networks (VNs) while applying firewall inspection. The border node connects the fabric to external networks and, when configured with a firewall, can enforce policies such as IP-based ACLs or zone-based firewalls for traffic crossing VNs. This design ensures that all inter-VN traffic is funneled through the border node for inspection, aligning with the centralized policy model where policy enforcement occurs at the network edge.

Exam trap

Cisco often tests the misconception that fabric edge nodes enforce all policies, but the trap here is that inter-VN traffic requires a routing point (the border node) to apply firewall inspection, while edge nodes only enforce intra-VN policies like SGT-based access control.

How to eliminate wrong answers

Option B (Fabric edge node) is wrong because fabric edge nodes are responsible for attaching endpoints to the fabric and enforcing host-level policies (e.g., SGT-based policies) within a single VN, not for routing or inspecting traffic between VNs. Option C (Fabric control plane node) is wrong because the control plane node handles LISP mapping and registration (e.g., EID-to-RLOC mappings) and does not participate in data-plane forwarding or policy enforcement. Option D (Fabric WAN router) is wrong because a WAN router connects the fabric to external WAN networks (e.g., MPLS or Internet) and is not specifically designed for inter-VN policy enforcement within the fabric; inter-VN traffic is typically routed through the border node, not the WAN router.

1906
Multi-Selecteasy

Which THREE of the following are benefits of implementing a spine-leaf architecture in a data center?

Select 3 answers
A.Provides predictable latency for east-west traffic.
B.Eliminates the need for spanning-tree protocol.
C.Reduces the amount of cabling required.
D.Simplifies scalability by adding leaf switches without redesign.
E.Eliminates the need for firewall appliances.
AnswersA, B, D

Correct. Spine-leaf provides predictable latency for east-west traffic because every leaf-to-leaf path crosses exactly one spine switch, giving a consistent hop count of two (leaf-to-spine-to-leaf) regardless of which leaf pair communicates. This uniform topology yields low, bounded, and predictable latency, unlike hierarchical designs where traffic may traverse multiple aggregation and core layers with variable distances. It is a key reason spine-leaf suits latency-sensitive data center applications.

Why this answer

Spine-leaf architecture provides predictable latency for east-west traffic because every leaf switch connects to every spine switch, ensuring consistent hop count. It simplifies scalability: adding a new leaf switch requires connecting it to all spine switches without redesign. Additionally, spine-leaf eliminates the need for Spanning Tree Protocol (STP) because it uses Layer 3 routing between leaf and spine switches, removing Layer 2 loops.

Therefore, options A, B, and D are correct. Option C is incorrect because spine-leaf increases cabling due to full mesh connectivity. Option E is incorrect because firewall appliances are still required for security.

Exam trap

Cisco often tests the misconception that spine-leaf reduces cabling or eliminates all protocols like STP and firewalls, when in fact it increases cabling and only removes Layer 2 loops while still requiring routing protocols and security appliances.

1907
Drag & Dropmedium

Drag and drop the steps of SD-Access fabric endpoint registration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order begins with the endpoint sending an ARP or DHCP request, the edge node detecting the new endpoint, registering it with the control plane (LISP), the control plane updating the map server, and finally the edge node installing the necessary forwarding entries. This sequence ensures the endpoint is properly discovered and integrated into the fabric.

1908
MCQhard

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast 10.0.0.0/8 BGP routing table entry for 10.0.0.0/8, version 25 Paths: (2 available, best #2, table default) Advertised to update-groups: 1 Refresh Epoch 1 65050 65100 10.0.1.2 from 10.0.1.2 (10.0.0.2) Origin IGP, metric 0, localpref 100, weight 0, valid, external rx pathid: 0, tx pathid: 0x0 65050 10.0.1.3 from 10.0.1.3 (10.0.0.3) Origin IGP, metric 0, localpref 100, weight 0, valid, external, best rx pathid: 0, tx pathid: 0x0 Based on this output, what can be concluded?

A.Path #1 is the best path because it has a longer AS_PATH, indicating more specific routing.
B.Path #2 is the best path because it has a shorter AS_PATH.
C.Both paths are equally preferred, and BGP uses tie-breaking rules like router ID.
D.Path #2 is the best path because it is received from a higher IP address.
AnswerB

BGP's best-path algorithm evaluates attributes in a fixed order: after comparing Weight, Local Preference, and locally-originated paths, it selects the route with the shortest AS_PATH. Here Path #2 carries only AS 65050 in its AS_SEQUENCE, giving it a path length of 1, while Path #1 lists 65050 65100, a length of 2. Because AS_PATH comparison occurs before any tie-breaking steps, Path #2 wins as the best path solely based on this shorter AS path.

Why this answer

BGP selects the best path based on a set of well-defined tie-breaking rules. After comparing weight, local preference, and origin, the next step is AS_PATH length. Path #2 has an AS_PATH of '65050' (one AS), while Path #1 has '65050 65100' (two ASes).

Since a shorter AS_PATH is preferred, Path #2 is chosen as the best path, making option B correct.

Exam trap

Cisco often tests the BGP best-path selection order, and the trap here is that candidates may assume that a longer AS_PATH indicates a more specific or preferred route, or that the path with the higher neighbor IP address is chosen, when in fact BGP strictly prefers the shortest AS_PATH at this stage of the decision process.

How to eliminate wrong answers

Option A is wrong because a longer AS_PATH is actually less preferred in BGP best-path selection, not more specific; AS_PATH length is a metric for path preference, not route specificity. Option C is wrong because the paths are not equally preferred; the output explicitly shows that Path #2 is the best due to a shorter AS_PATH, and BGP tie-breaking rules are applied sequentially, not arbitrarily. Option D is wrong because BGP does not compare neighbor IP addresses as a tie-breaker at this stage; the shorter AS_PATH is the decisive factor here, and router ID or IP address comparisons only come into play much later in the BGP decision process.

1909
MCQeasy

A network administrator is configuring a new VLAN 100 on a switch and wants to ensure that the VLAN is created and active. Which command is required to create a VLAN in the VLAN database?

A.interface vlan 100
B.name VLAN100
C.vlan 100
D.switchport access vlan 100
AnswerC

vlan 100 is the global configuration command that creates a new VLAN with ID 100 and immediately enters VLAN configuration mode. This is the required first step when establishing a new VLAN, as it adds the VLAN to the switch's local VLAN database. From this mode, you can set optional parameters such as the VLAN name, MTU, or other interface-specific settings. Issuing this command makes the VLAN available for subsequent operations like assigning access ports or creating an SVI.

Why this answer

The 'vlan 100' command is executed in global configuration mode to create a VLAN in the VLAN database on a Cisco IOS switch. This command creates the VLAN and places the switch into VLAN configuration mode, where optional parameters like name can be set. The VLAN is active immediately upon creation, provided the switch is in VTP server or transparent mode.

Exam trap

Cisco often tests the distinction between creating a VLAN with 'vlan <id>' versus creating an SVI with 'interface vlan <id>', leading candidates to confuse Layer 2 VLAN creation with Layer 3 interface configuration.

How to eliminate wrong answers

Option A is wrong because 'interface vlan 100' creates a Layer 3 switched virtual interface (SVI) for routing, not the VLAN itself. Option B is wrong because 'name VLAN100' is a subcommand used within VLAN configuration mode to assign a name to an existing VLAN, not to create the VLAN. Option D is wrong because 'switchport access vlan 100' assigns an access port to VLAN 100, but the VLAN must already exist or be dynamically created via VTP; it does not create the VLAN in the database.

1910
MCQeasy

A network engineer runs the following command on a Cisco WLC: WLC# show wlan summary WLAN ID SSID Status Security Interface 1 Guest Enabled Open guest-vlan 2 Corporate Enabled WPA2 corp-vlan 3 IoT Disabled WPA2 iot-vlan 4 Management Enabled WPA2 mgmt-vlan Based on this output, what can be concluded?

A.All WLANs are currently active and serving clients.
B.WLAN 3 is not operational because it is disabled.
C.The Guest WLAN uses WPA2 security.
D.The Management WLAN is on the guest-vlan interface.
AnswerB

The Status column shows WLAN 3 as Disabled, meaning the WLAN is administratively shut down and will not broadcast or accept client associations. Its SSID, security and interface settings remain configured but inactive until the WLAN is enabled.

Why this answer

The 'show wlan summary' output clearly shows that WLAN 3 (IoT) has a Status of 'Disabled', meaning it is not operational and cannot serve clients. Only enabled WLANs can transmit beacons and accept client associations. Therefore, option B is correct because a disabled WLAN is effectively non-functional.

Exam trap

Cisco often tests the ability to read the 'Status' column accurately, as candidates may mistakenly assume all listed WLANs are active or confuse the 'Security' column with the 'Status' column.

How to eliminate wrong answers

Option A is wrong because WLAN 3 is disabled, so not all WLANs are active and serving clients. Option C is wrong because the Guest WLAN (ID 1) shows 'Open' security, not WPA2. Option D is wrong because the Management WLAN (ID 4) is on the 'mgmt-vlan' interface, not 'guest-vlan'.

1911
MCQhard

A network engineer runs the following command on Router R1: R1# show ip access-lists Extended IP access list 150 10 permit tcp 10.0.0.0 0.255.255.255 any eq 23 (2 matches) 20 deny tcp any any eq 23 (8 matches) 30 permit tcp 172.16.0.0 0.0.255.255 any eq 22 (4 matches) 40 deny tcp any any eq 22 (1 match) 50 permit ip any any (15 matches) Based on this output, what can be concluded?

A.Telnet from 192.168.1.0/24 would be denied, and SSH from 10.0.0.0/8 would be denied.
B.Telnet from 10.0.0.0/8 is denied.
C.SSH from 172.16.0.0/16 is denied.
D.All traffic is permitted.
AnswerA

Telnet from 192.168.1.0/24 matches entry 20 (deny), and SSH from 10.0.0.0/8 does not match entry 30 (which permits only from 172.16.0.0/16), so it matches entry 40 (deny).

Why this answer

The ACL 150 processes entries sequentially. Telnet (TCP port 23) from 192.168.1.0/24 is not explicitly permitted by the first permit statement (which only allows source 10.0.0.0/8) and is denied by the subsequent deny statement (line 20). SSH (TCP port 22) from 10.0.0.0/8 is permitted by line 10 only for Telnet, not SSH; line 30 permits SSH only from 172.16.0.0/16, so SSH from 10.0.0.0/8 hits line 40 (deny) and is denied.

The implicit deny at the end would also block unmatched traffic, but here explicit denies apply.

Exam trap

Cisco often tests the misconception that a permit statement for one protocol (e.g., Telnet) also permits another protocol (e.g., SSH) from the same source, when in fact each ACE applies only to the specified protocol and port.

How to eliminate wrong answers

Option B is wrong because Telnet from 10.0.0.0/8 is explicitly permitted by line 10 (permit tcp 10.0.0.0 0.255.255.255 any eq 23), as shown by the 2 matches. Option C is wrong because SSH from 172.16.0.0/16 is explicitly permitted by line 30 (permit tcp 172.16.0.0 0.0.255.255 any eq 22), as shown by the 4 matches. Option D is wrong because not all traffic is permitted; line 50 (permit ip any any) only matches traffic that hasn't been denied earlier, but Telnet from non-10.0.0.0/8 sources and SSH from non-172.16.0.0/16 sources are explicitly denied by lines 20 and 40, respectively, and the implicit deny at the end would block any other unmatched traffic.

1912
MCQeasy

In OSPF, which LSA type is used to describe routes to networks within the same area and is generated by the router that owns the network?

A.Type 1 (Router LSA)
B.Type 2 (Network LSA)
C.Type 3 (Summary LSA)
D.Type 5 (External LSA)
AnswerA

Type 1 Router LSAs are originated by every OSPF router to advertise its own active interfaces and connected neighbors, including link type, link ID, interface IP, and metric. These LSAs are always confined to the area in which they are generated and form the base graph that Dijkstra's SPF algorithm processes. Because every router must describe itself before any other LSA can be interpreted, Type 1 is the most basic and essential LSA type.

Why this answer

Type 1 (Router LSA) is correct because each OSPF router generates a Type 1 LSA to describe its directly connected links and networks within the same area. This LSA is flooded only within the originating area and is the fundamental building block for intra-area route calculation using the SPF algorithm.

Exam trap

Cisco often tests the distinction between the router that originates the LSA (Type 1) versus the DR that generates the LSA for the network segment (Type 2), causing candidates to confuse the 'owner' of the network with the DR's role.

How to eliminate wrong answers

Option B (Type 2 Network LSA) is wrong because it is generated by the Designated Router (DR) on a broadcast or NBMA network to describe the routers attached to that segment, not by the router that owns the network. Option C (Type 3 Summary LSA) is wrong because it is generated by an Area Border Router (ABR) to advertise routes from one area to another, not for intra-area networks. Option D (Type 5 External LSA) is wrong because it is generated by an Autonomous System Boundary Router (ASBR) to advertise routes redistributed from outside the OSPF domain, not for networks within the same area.

1913
MCQmedium

Review the following IP SLA configuration on Router R1: ip sla 3 icmp-echo 10.3.3.3 frequency 30 ip sla schedule 3 life forever start-time now ip sla reaction-configuration 3 react rtt threshold-type xof 5 threshold-value 100 action-type triggerAndReset What is the purpose of the 'threshold-type xof 5' parameter?

A.It triggers an event if 5 out of the last 10 RTT measurements exceed 100 ms.
B.It triggers an event if 5 consecutive RTT measurements exceed 100 ms.
C.It triggers an event if the RTT exceeds 100 ms for 5 seconds.
D.It triggers an event if the RTT exceeds 100 ms and then repeats 5 times.
AnswerB

The 'xof' keyword in IP SLA reaction configuration defines the number of consecutive threshold violations needed to trigger an event. Here, 'xof 5' means five RTT probe samples in a row must each exceed 100 ms; if any single probe falls back below the threshold, the consecutive counter resets to zero. Only after those five uninterrupted high measurements does the event fire.

Why this answer

The 'threshold-type xof 5' parameter in IP SLA triggers an action when 5 consecutive RTT measurements exceed the specified threshold of 100 ms. This is a 'consecutive violations' threshold, meaning the event fires only after a sustained pattern of failures, not based on a sliding window or time duration. The 'xof' keyword specifically indicates the number of consecutive probe results that must exceed the threshold before the reaction is triggered.

Exam trap

Cisco often tests the distinction between 'xof' (consecutive violations) and 'average' or 'mean' threshold types, leading candidates to mistakenly think 'xof 5' means 5 out of the last 10 probes.

How to eliminate wrong answers

Option A is wrong because 'xof' does not use a sliding window of 10 measurements; that behavior would be configured with 'threshold-type average' or a different parameter. Option C is wrong because IP SLA thresholds are based on probe counts, not time duration; there is no 'for 5 seconds' mechanism in this context. Option D is wrong because 'xof 5' does not mean the threshold is exceeded and then repeats 5 times; it means 5 consecutive violations must occur before the action is taken.

1914
Matchingeasy

Drag and drop each broadband type on the left to its matching technology on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Uses telephone line with ADSL or VDSL

Uses coaxial cable with DOCSIS

Uses optical fiber with GPON

Uses cellular radio with OFDMA

Uses geostationary satellite with high latency

Why these pairings

DSL uses telephone lines with frequencies above voice. Cable uses coaxial cable with DOCSIS. Fiber uses optical fiber with GPON or active Ethernet. 4G LTE uses cellular radio.

Satellite uses geostationary or LEO satellites.

1915
MCQmedium

A network engineer is configuring a Cisco router to provide internet access to a small office using a single public IP address assigned by the ISP. The engineer wants to allow internal hosts to initiate connections to the internet, but also needs to make a web server on the internal network reachable from the internet. The engineer configures a standard access list for NAT and an ip nat inside source list command. However, external users cannot reach the internal web server. What is the most likely cause?

A.The access list used for NAT does not permit the web server's IP address.
B.The engineer forgot to add the ip nat inside source static command for the web server.
C.The ip nat inside and ip nat outside commands are applied on the wrong interfaces.
D.The global configuration mode is missing the ip nat pool command.
AnswerB

For inbound traffic to reach an internal web server, the router must translate the public destination IP back to the server's private IP. This requires an explicit ip nat inside source static command (or the TCP/UDP port-specific variant) that defines the one-to-one binding between the public address and the private address. Without this command, the router has no entry in its NAT table for the destination address and will drop the packets, so external clients cannot connect.

Why this answer

The scenario describes a need for both dynamic PAT (for internal hosts to reach the internet) and static NAT (to make the internal web server reachable from the internet). The 'ip nat inside source list' command alone performs dynamic NAT/PAT, translating multiple inside addresses to the single public IP. To allow inbound connections to the web server, a static one-to-one mapping is required using the 'ip nat inside source static tcp' command, which creates a permanent translation entry.

Without this static command, the router has no way to know which inside host should receive incoming traffic destined for the public IP on port 80.

Exam trap

Cisco often tests the distinction between dynamic NAT (using 'ip nat inside source list') and static NAT (using 'ip nat inside source static'), leading candidates to incorrectly assume that a single NAT configuration can handle both outbound and inbound traffic without additional commands.

How to eliminate wrong answers

Option A is wrong because the access list used for NAT should permit the internal hosts that need to initiate outbound connections; the web server's IP does not need to be in that list for inbound static NAT, as static NAT bypasses the access list entirely. Option C is wrong because if the 'ip nat inside' and 'ip nat outside' commands were applied on the wrong interfaces, outbound connectivity for internal hosts would also fail, not just inbound access to the web server. Option D is wrong because the 'ip nat pool' command is used for dynamic NAT with a pool of public addresses, not for PAT with a single public IP or for static NAT; the scenario uses a single public IP, so no pool is required.

1916
MCQmedium

Given the following EIGRP configuration on a router: router eigrp 200 network 192.168.1.0 0.0.0.255 network 10.0.0.0 Which statement about this configuration is true?

A.EIGRP will be enabled on any interface with an IP address in the 10.0.0.0/8 range, and only on interfaces with an IP address in the 192.168.1.0/24 range.
B.Both network statements are classful and will enable EIGRP on all interfaces with IP addresses in the 192.168.0.0/16 and 10.0.0.0/8 ranges.
C.EIGRP will only be enabled on interfaces with an IP address in the 192.168.1.0/24 range.
D.This configuration will cause an error because wildcard masks are not allowed in EIGRP network statements.
AnswerA

In classic EIGRP configuration, the network command with a wildcard mask (e.g., `network 192.168.1.0 0.0.0.255`) matches only the specific subnet 192.168.1.0/24, while a plain classful `network 10.0.0.0` matches all interfaces with any address in the 10.0.0.0/8 range. Therefore EIGRP is enabled precisely on those interfaces, and the router will begin forming adjacencies only on interfaces that match either statement.

Why this answer

The first network statement uses a wildcard mask (0.0.0.255) to enable EIGRP only on interfaces in the 192.168.1.0/24 subnet, while the second network statement (10.0.0.0) is classful and enables EIGRP on all interfaces in the 10.0.0.0/8 range. EIGRP network statements can include a wildcard mask to specify a subnet; without one, the router assumes the classful boundary.

Exam trap

Cisco often tests the distinction between classful and classless network statements in EIGRP, where candidates mistakenly assume that a network statement without a wildcard mask applies only to the exact subnet rather than the entire classful range.

How to eliminate wrong answers

Option B is wrong because the first network statement uses a wildcard mask (0.0.0.255), which restricts EIGRP to the 192.168.1.0/24 subnet, not the classful 192.168.0.0/16 range. Option C is wrong because the second network statement (10.0.0.0) is classful and enables EIGRP on all interfaces in the 10.0.0.0/8 range, not just the 192.168.1.0/24 subnet. Option D is wrong because EIGRP explicitly supports wildcard masks in network statements (e.g., network 192.168.1.0 0.0.0.255) to allow subnet-level granularity.

1917
MCQmedium

A network engineer configures IP SLA 20 to monitor the response time of a DNS server at 10.1.1.1 using DNS query for 'example.com'. The operation is used to influence routing decisions. The engineer notices that the IP SLA operation shows 'State: Active' and 'Latest RTT: 50 ms', but the DNS server is actually down and not responding to any queries. What is the most likely reason?

A.The IP SLA DNS probe is using a cached DNS response from the router's DNS resolver, so it does not actually query the server.
B.The IP SLA DNS probe must be configured with a 'timeout' value lower than 50 ms to detect the failure.
C.The DNS server is responding to the probe but not to other queries because the probe uses a different port.
D.The IP SLA operation is configured with a 'frequency' that is too low, causing the probe to be sent before the server times out.
AnswerA

The IP SLA DNS probe is designed to send a DNS query to a specified server and measure the response time. If the router's DNS resolver has caching enabled and has previously resolved the queried name, it may answer from its local cache without ever transmitting the query to the configured DNS server. This results in a successful probe with a low RTT (e.g., 50 ms) even when the actual DNS server is unreachable, because the reply comes from the router itself. To avoid this, the DNS name used in the probe must be unique or DNS caching must be disabled to force an end-to-end query.

Why this answer

IP SLA DNS probes rely on the router's local DNS resolver. If the resolver has a cached response for 'example.com', the probe will return the cached RTT without actually querying the DNS server. This explains why the operation shows 'Active' and a 50 ms RTT even though the DNS server is down.

Exam trap

Cisco often tests the misconception that IP SLA DNS probes always generate live queries to the server, when in fact the router's DNS resolver may serve cached responses, leading to false-positive results.

How to eliminate wrong answers

Option B is wrong because reducing the timeout below 50 ms would not cause the probe to detect a failure; the probe is not timing out—it is returning a cached response. Option C is wrong because IP SLA DNS probes use the standard DNS port 53 by default, and the server being down would affect all queries regardless of port. Option D is wrong because a low frequency would cause probes to be sent more often, not less; the issue is not about timing but about the router using a cached response instead of performing a live query.

1918
Multi-Selectmedium

Which THREE attributes are typically included in a YANG module for interface configuration? (Choose three.)

Select 3 answers
A.switchport mode
B.description
C.mtu
D.ip address
E.mac address
AnswersB, C, D

A YANG interface module carries a description leaf holding free-text administrative annotation for the interface. It is a standard configurable attribute alongside administrative state and addressing, making it one of the three expected interface attributes.

Why this answer

In a YANG module for interface configuration, the 'description' leaf (option B) is a standard attribute used to set a human-readable interface description via the CLI equivalent 'description <text>'. The 'mtu' leaf (option C) is also standard, representing the interface Maximum Transmission Unit, commonly configured with 'mtu <value>' and modeled in YANG as an unsigned integer. The 'ip address' node (option D) is included to assign an IPv4 address and subnet mask to an interface, typically modeled as a container or list with 'address' and 'prefix-length' leaves.

Option A, 'switchport mode', is a Layer 2 switching attribute found in vendor-specific or Cisco YANG models (e.g., Cisco IOS XE native model) but is not a generic interface configuration attribute in standard IETF YANG models like ietf-interfaces. Option E, 'mac address', is usually a read-only operational state or a hardware-assigned value, not a typical configurable attribute in a YANG interface configuration module.

Exam trap

Cisco often tests the distinction between configurable YANG leaves (like 'description', 'mtu', 'ip address') and operational state leaves (like 'mac address') or platform-specific extensions (like 'switchport mode') to see if candidates understand the standard IETF interface model versus proprietary additions.

1919
Drag & Dropmedium

Drag and drop the steps of Private VLAN (PVLAN) configuration steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First create the primary VLAN, then the secondary VLANs (community or isolated), then associate them. Finally configure host and promiscuous ports.

1920
MCQhard

A network architect is comparing Cisco StackWise Virtual and traditional StackWise for a new data center access layer. The requirement is that the two switches operate as one logical device while remaining physically separate, with each switch having its own control plane processes that are synchronized, and that the pair support Multichassis EtherChannel to downstream servers. Which statement correctly describes Cisco StackWise Virtual in this scenario?

A.StackWise Virtual requires a dedicated stacking cable and forms a single control plane with one master and one standby member
B.StackWise Virtual uses VSS with a Virtual Switch Link and requires one chassis to be active while the other is in hot standby
C.StackWise Virtual only supports single-chassis EtherChannel because each switch forwards independently
D.StackWise Virtual combines two switches into one logical entity using a StackWise Virtual Link, and each chassis maintains its own control plane that is synchronized with its peer
AnswerD

StackWise Virtual pairs two physical switches into a single logical device over a StackWise Virtual Link. Unlike classic StackWise with a master and members, both chassis run independent control planes that stay synchronized, and Multichassis EtherChannel to downstream devices is supported.

Why this answer

StackWise Virtual merges two chassis into one logical device through a StackWise Virtual Link while preserving independent, synchronized control planes on each switch. It supports Multichassis EtherChannel to downstream devices, which is exactly what the architect needs for the data center access layer.

Exam trap

The trap here is conflating StackWise Virtual with classic StackWise or VSS, which use different link types and control-plane models.

1921
Multi-Selectmedium

A network engineer is analyzing Cisco DNA Center Assurance data to troubleshoot a wireless client's poor performance. The engineer observes that the client's health score is low due to high retry rates and low SNR. Which TWO Assurance metrics should the engineer examine to further diagnose the issue? (Choose two.)

Select 2 answers
A.AP channel utilization and interference
B.Switch CPU utilization
C.DHCP pool utilization
D.WAN latency and jitter
E.Client RSSI and SNR trends
AnswersA, E

AP channel utilization and interference metrics show how congested the wireless channel is and whether external interference is present. High channel utilization or interference can cause high retry rates and low SNR. DNA Center Assurance provides these metrics per AP and band, enabling the engineer to identify if the issue is due to co-channel interference or a noisy environment.

Why this answer

To diagnose high retry rates and low SNR, the engineer should examine RF-related metrics. Client RSSI and SNR trends reveal signal quality and potential coverage gaps. AP channel utilization and interference show if the channel is congested or noisy.

Together, these metrics help identify whether the issue is due to distance, interference, or channel overlap. Other metrics like switch CPU, WAN latency, or DHCP utilization do not directly address wireless RF performance.

Exam trap

The trap here is selecting wired or WAN metrics like switch CPU or WAN latency, which are unrelated to wireless RF symptoms such as high retry rates and low SNR.

1922
Drag & Dropmedium

Drag and drop the steps of STP portfast and BPDU guard configuration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

PortFast is enabled globally or per interface to bypass listening/learning. BPDU guard is then configured to disable the port if a BPDU is received. The configuration is applied to the interface, and the port transitions to forwarding immediately.

Finally, errdisable recovery can be set.

1923
MCQhard

A network administrator is analyzing traffic flows using Cisco DNA Center Assurance. The administrator wants to see which applications are consuming the most bandwidth on a specific interface of a Catalyst 9500 switch. Which feature should be enabled on the switch to provide this level of granularity?

A.Syslog
B.IP SLA
C.SNMP
D.NetFlow
AnswerD

NetFlow provides detailed information about IP traffic flows, including source and destination IP addresses, ports, protocol, and byte counts. When enabled on an interface and exported to Cisco DNA Center, it allows the administrator to identify which applications are consuming the most bandwidth. This is the correct feature for application visibility and bandwidth analysis.

Why this answer

NetFlow is the appropriate feature to enable on the switch to gain application-level visibility into bandwidth consumption. It exports flow records that include application identification through NBAR2, allowing Cisco DNA Center to present detailed bandwidth usage per application. Without NetFlow, the administrator would only see aggregate interface statistics.

Exam trap

The trap here is confusing SNMP interface counters with application-level flow analysis; SNMP shows total bytes but not which applications are responsible.

Page 25

Page 26 of 26