Courseiva

ENCOR 350-401 (350-401) — Questions 151–225

1923 questions total · 26pages · All types, answers revealed

Page 2

Page 3 of 26

Page 4
151
MCQmedium

A network engineer is troubleshooting multicast video distribution across an enterprise campus. The multicast source is connected to a switch that is the PIM Designated Router (DR) on a multi-access segment. Receivers in a different VLAN report that they are not receiving the multicast stream, although the DR shows the correct (S,G) entry. The engineer checks the RPF neighbor for the source and notices that the unicast route to the source points to a different interface than the one where the multicast stream is received. What is the most likely cause of the issue?

A.The DR is not configured as the RP (Rendezvous Point).
B.The multicast stream is arriving on an interface that is not the RPF interface for the source.
C.The switchport connected to the source is not configured as a trunk.
D.IGMP snooping is disabled on the receiver VLAN.
AnswerB

Multicast routers enforce a Reverse Path Forwarding (RPF) check: a multicast packet is accepted only if it arrives on the interface that the unicast routing table would use to reach the source IP address. If the stream arrives on a non-RPF interface, the router discards it to prevent loops and duplicate delivery. This mismatch directly matches the described symptom of multicast traffic failing to forward, making this the correct explanation.

Why this answer

PIM uses the unicast routing table to determine the Reverse Path Forwarding (RPF) interface for a multicast source. If the multicast stream arrives on an interface that is not the RPF interface (the interface the unicast route uses to reach the source), the router will perform an RPF check and fail, dropping the multicast traffic. This is the most likely cause of the issue, as the DR has the (S,G) entry but the stream is not being forwarded due to the RPF mismatch.

Exam trap

Cisco often tests the RPF check concept by presenting a scenario where the (S,G) entry exists but traffic is not forwarded, leading candidates to incorrectly suspect IGMP snooping, RP configuration, or trunk issues, when the real problem is a unicast routing mismatch causing an RPF failure.

How to eliminate wrong answers

Option A is wrong because the DR does not need to be configured as the RP; the DR is a role on a multi-access segment for forwarding multicast traffic to the RP or directly to receivers, and the RP is a separate concept for PIM-SM. Option C is wrong because the switchport connecting the source does not need to be a trunk; the source is typically in a single VLAN, and a trunk is only needed if the source is on a different VLAN than the switch's routed interface. Option D is wrong because IGMP snooping being disabled on the receiver VLAN would prevent receivers from joining the multicast group at Layer 2, but the issue described is an RPF check failure at Layer 3, not a Layer 2 membership problem.

152
MCQmedium

Consider the following partial configuration on Router R1: ip sla 2 icmp-echo 10.2.2.2 frequency 15 ip sla schedule 2 life forever start-time now ip sla reaction-configuration 2 react timeout threshold-type immediate action-type triggerOnly Which statement about this configuration is true?

A.The IP SLA operation will send ICMP echo requests every 15 seconds and trigger an event if a timeout occurs, but the trigger will only activate once.
B.The IP SLA operation will send ICMP echo requests every 15 seconds and continuously trigger events for each timeout.
C.The IP SLA operation will send ICMP echo requests every 15 seconds and trigger an event if the round-trip time exceeds a threshold.
D.The IP SLA operation will send ICMP echo requests every 15 seconds, but the 'reaction-configuration' command is invalid because it requires a threshold value.
AnswerA

This operation is configured with a frequency of 15 seconds, meaning an ICMP echo request is sent every 15s. The reaction-configuration uses 'react timeout' with 'threshold-type immediate', so as soon as an echo reply is not received within the timeout period, the trigger fires immediately. 'action-type triggerOnly' prevents the trigger from being re-armed, so the event is raised only once even if subsequent timeouts occur.

Why this answer

The IP SLA operation sends ICMP echo requests every 15 seconds (as defined by the 'frequency 15' command) and the 'reaction-configuration' with 'threshold-type immediate' and 'action-type triggerOnly' means that as soon as a timeout occurs, a trigger event is generated, but the 'triggerOnly' keyword ensures that the trigger fires only once (not repeatedly) for the first timeout event. The operation continues to run, but no further triggers are generated for subsequent timeouts unless the reaction is rearmed.

Exam trap

Cisco often tests the distinction between 'triggerOnly' (single trigger) and 'triggerAndClear' (continuous triggering) in IP SLA reaction-configuration, and candidates commonly confuse 'timeout' reaction with 'threshold' reaction, assuming a numeric RTT threshold is always required.

How to eliminate wrong answers

Option B is wrong because 'triggerOnly' explicitly limits the trigger to a single activation; it does not continuously trigger events for each timeout. Option C is wrong because the reaction is configured to react to a 'timeout' (i.e., no response received), not to an RTT threshold; the 'threshold-type immediate' does not involve a round-trip time threshold value. Option D is wrong because the 'reaction-configuration' command is valid with 'threshold-type immediate' when reacting to a timeout; a numeric threshold is only required when using 'threshold-type x' where x is a specific millisecond value, not for 'immediate'.

153
MCQeasy

A network automation team is evaluating configuration management tools. They need a tool that uses a declarative, agentless architecture and communicates over SSH to push configuration to Cisco IOS XE devices. Which tool best fits these requirements?

A.Puppet with the Cisco IOS module
B.Ansible with the ios_config module
C.SaltStack with the napalm proxy minion
D.Chef Infra with the Cisco IOS cookbook
AnswerB

Ansible is agentless, uses SSH as its transport, and employs declarative playbooks. The ios_config module specifically manages configuration on Cisco IOS devices. It requires no software installed on the managed device, aligning perfectly with the requirement. This combination is widely used for network automation and directly satisfies the scenario's constraints.

Why this answer

Ansible is designed as an agentless automation tool that connects over SSH and uses declarative YAML playbooks. The ios_config module is purpose-built for Cisco IOS configuration management. This combination meets all stated requirements: declarative, agentless, and SSH-based.

Other tools either require agents or add architectural complexity that makes them less suitable for this scenario.

Exam trap

The trap here is conflating agentless operation with tools that can optionally run without agents but typically rely on agent-based architecture.

154
MCQhard

A network engineer is configuring IPsec site-to-site VPNs on a Cisco IOS XE router. The design requires that the router authenticate peers using certificates issued by an internal PKI rather than pre-shared keys, and that IKEv2 be used for the key exchange. Which configuration element is required to support certificate-based authentication for IKEv2 on this router?

A.A pre-shared key configured under the IKEv2 keyring with the peer's address.
B.An ISAKMP policy with authentication pre-share under the crypto isakmp configuration.
C.A crypto pki trustpoint configuration with enrollment and an RSA key pair, referenced in the IKEv2 profile.
D.A crypto map with the set peer command specifying the remote peer's hostname.
AnswerC

Certificate-based IKEv2 authentication requires a trustpoint that defines the CA, an enrolled identity certificate, and an RSA key pair on the router. The IKEv2 profile then references authentication local rsa-sig and the trustpoint so the router can present its certificate and validate the peer's certificate chain. Without a properly enrolled trustpoint, the router cannot perform RSA signature authentication, so this element is mandatory for the design.

Why this answer

IKEv2 certificate authentication requires an enrolled PKI trustpoint, an RSA key pair, and an IKEv2 profile that references RSA signature authentication with that trustpoint. Pre-shared keys and ISAKMP policies belong to the alternative authentication method or the older IKEv1 framework, and a crypto map only defines IPsec policy and peer identity. The trustpoint is the essential element enabling certificate-based peer authentication.

Exam trap

The trap here is mixing IKEv1 ISAKMP policy syntax with IKEv2 profile configuration, when IKEv2 certificate authentication depends on a trustpoint referenced in the IKEv2 profile.

155
Multi-Selecthard

Which two statements about Cisco QoS classification and marking are true? (Choose two.)

Select 2 answers
A.A class map can match traffic based on DSCP, CoS, IP precedence, or ACL.
B.Marking should be performed as close to the source as possible, typically at the access layer.
C.Marking can only be applied to Layer 2 frames using CoS bits.
D.Marking is a congestion avoidance mechanism that uses tail drop.
E.A class map is used to apply marking actions to classified traffic.
AnswersA, B

A class map defines the match criteria for traffic classification, and Cisco IOS supports matching on Layer 2 CoS, Layer 3 DSCP, IP precedence, and ACL entries within the same class map. This satisfies the stem's requirement for accurate classification and marking statements, since classification must identify traffic before marking policies apply.

Why this answer

Option A is correct because a Cisco class map (defined with the class-map command and used inside a policy map) can match traffic using criteria such as DSCP values, CoS bits, IP precedence, or ACLs (match dscp, match cos, match precedence, match access-group), which is exactly how classification is performed in MQC. Option B is correct because QoS marking is best done as close to the traffic source as possible, typically at the access layer, so that the DSCP/CoS value is preserved and honored by every downstream device without reclassification. Option C is incorrect because marking is not limited to Layer 2 CoS; devices can also set Layer 3 DSCP and IP precedence (and MPLS EXP), so CoS-only marking is false.

Option D is incorrect because tail drop is a congestion avoidance/queue management mechanism, not a marking function, and marking itself is not a congestion avoidance mechanism. Option E is incorrect because a policy map (not a class map) applies marking actions to classified traffic; the class map only identifies/matches the traffic.

Exam trap

The trap here is confusing the roles of class maps and policy maps: class maps classify, policy maps apply actions like marking. Candidates often mistakenly think class maps can apply marking actions.

156
MCQeasy

A network engineer runs the following command on Router R4: R4# show mpls interfaces Interface IP Tunnel BGP Static Operational GigabitEthernet0/0 Yes No No No Yes GigabitEthernet0/1 Yes No No No Yes GigabitEthernet0/2 No No No No No Based on this output, what can be concluded?

A.MPLS is enabled and operational on GigabitEthernet0/0 and GigabitEthernet0/1.
B.MPLS is enabled on all three interfaces, but only Gi0/0 and Gi0/1 are operational.
C.BGP and Static label switching are enabled on Gi0/0 and Gi0/1.
D.Tunnel interfaces are configured on Gi0/0 and Gi0/1.
AnswerA

The correct interpretation of the `show mpls interface` output is that both GigabitEthernet0/0 and GigabitEthernet0/1 have MPLS enabled and fully operational. The presence of 'IP: Yes' for each interface indicates that IPv4 label switching is active, while 'Operational: Yes' confirms that the MPLS data plane is ready to forward labeled packets. Therefore, MPLS is not only configured but also functioning on these two interfaces.

Why this answer

The 'show mpls interfaces' command displays MPLS status per interface. The 'Operational' column indicates whether MPLS is actively forwarding labels. GigabitEthernet0/0 and GigabitEthernet0/1 both show 'Yes' in the Operational column, confirming MPLS is enabled and operational on those interfaces.

GigabitEthernet0/2 shows 'No' in both the IP and Operational columns, meaning MPLS is not enabled or operational there.

Exam trap

Cisco often tests the distinction between the 'IP' column (configuration) and the 'Operational' column (actual forwarding state), leading candidates to mistakenly assume an interface is operational just because MPLS is configured, or to misinterpret the 'No' in the IP column as meaning MPLS is disabled entirely rather than just not enabled for IP label distribution.

How to eliminate wrong answers

Option B is wrong because the output shows GigabitEthernet0/2 has 'No' in the IP column and 'No' in the Operational column, indicating MPLS is not enabled on that interface, not just non-operational. Option C is wrong because the BGP and Static columns both show 'No' for all interfaces, meaning BGP label switching and static label switching are not enabled on Gi0/0 or Gi0/1. Option D is wrong because the Tunnel column shows 'No' for all interfaces, indicating no tunnel interfaces are configured on Gi0/0 or Gi0/1.

157
Multi-Selecthard

A network engineer is deploying a new Cisco SD-WAN fabric using Cisco vManage, vSmart, and vBond controllers. The engineer must ensure that the control plane is secure and resilient. Which two statements are true regarding the roles of these controllers? (Choose two.)

Select 2 answers
A.vSmart distributes control plane policies and routing information to WAN edge devices using OMP.
B.vBond maintains the routing table and makes path selection decisions for the overlay.
C.vBond orchestrates the control plane and is responsible for authenticating and validating all other controllers and WAN edge devices.
D.vSmart is responsible for the initial device authentication and NAT traversal.
E.vManage is responsible for authenticating WAN edge devices and distributing encryption keys.
AnswersA, C

vSmart is the control plane controller that uses the Overlay Management Protocol (OMP) to distribute routing, policy, and security information to WAN edge devices. It maintains a centralized view of the overlay and ensures consistent policy enforcement. It does not handle device authentication; that is vBond's role. vSmart is essential for dynamic path selection and policy application across the SD-WAN fabric.

Why this answer

In Cisco SD-WAN, vBond orchestrates the control plane by authenticating and validating controllers and WAN edge devices, facilitating NAT traversal. vSmart distributes control plane policies and routing information using OMP. vManage is the management plane for configuration and monitoring. These roles are distinct and critical for a secure and resilient fabric.

Exam trap

The trap here is conflating the roles of vBond and vSmart; vBond handles authentication and orchestration, while vSmart handles control plane policies and routing.

158
Drag & Dropmedium

Drag and drop the steps of SD-WAN overlay routing protocol (OMP) route advertisement sequence into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In OMP, the sequence starts with the edge device learning routes locally (connected, static, or dynamic), then redistributing them into OMP and sending to vSmart. vSmart processes and installs routes in its RIB, then advertises the best routes to other edge devices. The receiving edge device installs the route in its forwarding table and optionally redistributes into its local routing protocol.

159
MCQhard

A Cisco Catalyst 9500 switch in a data center is configured with IP Source Guard on an access port where a server is connected. The server has a static IP address of 10.10.10.50 and MAC address 00:11:22:33:44:55. The network administrator has configured a static IP source binding using the command 'ip source binding 0011.2233.4455 vlan 10 10.10.10.50 interface GigabitEthernet1/0/1'. However, the server cannot communicate through the switch. What is the most likely cause?

A.IP Source Guard only works on trunk ports, not access ports.
B.IP Source Guard requires DHCP snooping to be enabled on the VLAN even when static bindings are used.
C.The static IP source binding must be configured with the MAC address in the format xx:xx:xx:xx:xx:xx.
D.The server must use DHCP to obtain its IP address for IP Source Guard to permit traffic.
AnswerB

IP Source Guard relies on the DHCP snooping binding table to validate IP-to-MAC bindings. Even with static entries, DHCP snooping must be enabled on the VLAN to maintain the binding table and allow IP Source Guard to function. Without it, the switch cannot validate traffic and may drop packets, causing the server to lose connectivity.

Why this answer

IP Source Guard uses the DHCP snooping binding table to validate source IP and MAC addresses on a port. Static bindings can be added manually, but DHCP snooping must still be enabled on the VLAN to activate the binding table and allow IP Source Guard to filter traffic. Without DHCP snooping, the static binding is not effective, and the switch may drop legitimate traffic.

Exam trap

The trap here is assuming that static IP source bindings eliminate the need for DHCP snooping, when in fact DHCP snooping must be enabled on the VLAN for IP Source Guard to function.

160
MCQmedium

A network engineer is configuring dynamic ARP inspection (DAI) on a Cisco switch to prevent ARP spoofing. The switch has DHCP snooping enabled and the DHCP server is trusted. The engineer enables DAI on VLAN 10 and configures 'ip arp inspection trust' on the port connected to the DHCP server. After enabling DAI, some legitimate ARP replies from hosts are being dropped. The engineer checks the DAI statistics and sees 'ARP ACL drops' incrementing. What is the most likely reason?

A.The hosts have static IP addresses, so their MAC-IP bindings are not in the DHCP snooping database.
B.The port connected to the DHCP server should be untrusted for DAI to work correctly.
C.The DHCP server is in a different VLAN, and DAI cannot validate cross-VLAN ARP.
D.DAI is checking the destination MAC address, which does not match the expected value.
AnswerA

DAI validates ARP packets by looking up the source MAC and IP in the DHCP snooping binding table, which is populated only by DHCP-assigned addresses. Because these hosts use static IPs, no binding entry exists for them. Consequently, DAI will consider their ARP packets invalid and drop them unless an ARP ACL explicitly permits their IP-to-MAC mapping.

Why this answer

When DAI is enabled on a VLAN, it validates ARP packets against the DHCP snooping binding database. If a host has a static IP address, its MAC-IP binding is not automatically present in the DHCP snooping database. Without a valid binding, DAI treats the ARP reply as invalid and drops it, incrementing the 'ARP ACL drops' counter.

The correct solution is to either configure static DHCP snooping bindings or use ARP ACLs to permit the static hosts.

Exam trap

Cisco often tests the misconception that DAI only works with DHCP-assigned addresses, but the real trap is that candidates forget static IP hosts require manual binding entries or ARP ACLs to avoid being dropped.

How to eliminate wrong answers

Option B is wrong because the port connected to the DHCP server must be configured as trusted for DAI; trusted ports are allowed to send any ARP packet without validation, which is necessary for the DHCP server to function correctly. Option C is wrong because DAI operates within a single VLAN and does not validate cross-VLAN ARP; the DHCP server can be in a different VLAN as long as DHCP snooping is configured to relay bindings across VLANs. Option D is wrong because DAI validates the source MAC and IP addresses in the ARP body against the DHCP snooping database, not the destination MAC address; destination MAC validation is not a standard DAI check.

161
Matchingmedium

Drag and drop each WPA security version on the left to its matching authentication method on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Pre-Shared Key (PSK)

802.1X/EAP

Pre-Shared Key (PSK)

802.1X/EAP

Simultaneous Authentication of Equals (SAE)

Why these pairings

WPA Personal uses Pre-Shared Key (PSK); WPA Enterprise uses 802.1X/EAP; WPA2 Personal uses PSK; WPA2 Enterprise uses 802.1X/EAP; WPA3 Personal uses Simultaneous Authentication of Equals (SAE).

162
Multi-Selecteasy

Which three statements about Cisco SD-WAN architecture components and their roles are true? (Choose three.)

Select 3 answers
A.vManage provides a centralized dashboard for configuration, monitoring, and troubleshooting of the entire SD-WAN fabric.
B.vSmart controllers are responsible for distributing routing information and policies to all WAN Edge routers in the overlay.
C.vBond orchestrators authenticate WAN Edge routers and assist in NAT traversal for establishing tunnels.
D.vSmart controllers are responsible for NAT traversal and public IP discovery for WAN Edge routers behind NAT.
E.vManage distributes OMP routes to vEdge routers to populate the overlay routing table.
AnswersA, B, C

vManage is the management plane component, offering a single dashboard for configuration templates, monitoring, and troubleshooting across the whole SD-WAN fabric. This satisfies the requirement for centralised operational visibility and control over all overlay devices.

Why this answer

Option A is correct because vManage is the centralized management plane component of Cisco SD-WAN, providing a single dashboard/GUI for configuration, monitoring, and troubleshooting of the entire fabric. Option B is correct because vSmart controllers are the control plane: they run OMP and distribute routing information, policies, and TLOCs to all WAN Edge routers in the overlay. Option C is correct because vBond orchestrators are the orchestration plane: they authenticate WAN Edge devices joining the fabric and perform NAT traversal/public IP discovery so tunnels can be established.

Option D is wrong because NAT traversal and public IP discovery are vBond functions, not vSmart functions. Option E is wrong because OMP route distribution to vEdge routers is done by vSmart controllers, not by vManage, which is the management plane.

Exam trap

The trap here is confusing vBond and vSmart roles — candidates often assume the 'smart' controller handles NAT traversal because it sounds more capable, but NAT traversal is strictly vBond's job.

163
MCQmedium

A network engineer is using the Python 'requests' library to interact with a Cisco DNA Center controller. The engineer wants to retrieve a list of all network devices. Which HTTP method and URL should be used?

A.POST https://<dnac-ip>/dna/intent/api/v1/network-device
B.GET https://<dnac-ip>/api/v1/network-device
C.PUT https://<dnac-ip>/dna/intent/api/v1/network-device
D.GET https://<dnac-ip>/dna/intent/api/v1/network-device
AnswerD

Cisco DNA Center's Intent API uses the base path '/dna/intent/api/v1/'. The endpoint '/network-device' returns a list of all network devices. A GET request is used to retrieve data. This is the correct method and URL for fetching device inventory. Authentication is required via a token, but the method and path are correct.

Why this answer

Cisco DNA Center's Intent API provides RESTful endpoints for managing network devices. To retrieve a list of devices, a GET request to '/dna/intent/api/v1/network-device' is used. This returns JSON data with device details.

Other HTTP methods like POST, PUT, or DELETE are for creating, updating, or deleting resources. The correct base path is essential; omitting '/dna/intent' leads to failure.

Exam trap

The trap here is using an incorrect base path or HTTP method, such as omitting '/dna/intent' or using POST to retrieve data.

164
MCQmedium

A network architect is designing a new branch office that must run Cisco SD-WAN with a single WAN transport and requires all control-plane and data-plane traffic to be encrypted by default using DTLS/TLS tunnels managed by the controller. Which SD-WAN component is responsible for establishing the secure control connections and distributing route and policy information to the branch edge devices?

A.vAnalytics engine
B.vManage NMS
C.vSmart controller
D.vBond orchestrator
AnswerC

The vSmart controller is the SD-WAN control-plane component that builds DTLS/TLS control connections with each vEdge/cEdge and distributes OMP routes, TLOCs, and centralized policy. In this branch scenario, the edge device registers to vSmart, which pushes the routing and policy information needed for the single-transport overlay, making it the component that owns control-plane distribution.

Why this answer

In Cisco SD-WAN, the control plane is handled by the vSmart controller, which peers with each edge device over DTLS/TLS and uses OMP to advertise TLOCs, routes, and centralized policy. The branch edge in this design needs those control connections, so the vSmart controller is the component that satisfies the requirement.

Exam trap

The trap here is assuming that vManage, because it is the centralized GUI, also acts as the control plane that distributes routes and policy to edge devices.

165
Drag & Dropmedium

Drag and drop the steps of MPLS Layer 3 VPN VRF configuration on a PE router into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, you enable MPLS globally on the PE router. Then, you create the VRF and assign an RD. Next, you configure the route-target import and export policies.

After that, you apply the VRF to the customer-facing interface. Finally, you redistribute routes between the VRF and the MPLS backbone using BGP.

166
MCQeasy

What is the purpose of the 'ip sla schedule' command in IP SLA configuration?

A.It defines the type of IP SLA operation.
B.It sets the frequency of the IP SLA operation.
C.It starts the IP SLA operation and sets its lifetime and start time.
D.It configures threshold monitoring for the IP SLA operation.
AnswerC

The ip sla schedule command activates a defined IP SLA operation and specifies when it begins and how long it remains active. Without scheduling, the operation stays pending and generates no probes, so no latency, jitter, or reachability statistics are collected.

Why this answer

The 'ip sla schedule' command is used to start an IP SLA operation and configure its lifetime and start time. Without this command, the IP SLA operation is configured but remains inactive. This command controls when the operation begins and how long it runs, which is essential for scheduled monitoring.

Exam trap

Cisco often tests the distinction between configuration commands (like defining the operation type or frequency) and the activation command ('ip sla schedule'), leading candidates to confuse the purpose of each command in the IP SLA workflow.

How to eliminate wrong answers

Option A is wrong because the type of IP SLA operation is defined by the 'ip sla' command followed by the operation type (e.g., 'icmp-echo', 'udp-jitter'), not by the 'ip sla schedule' command. Option B is wrong because the frequency of the IP SLA operation is set using the 'frequency' command within the IP SLA configuration mode, not by 'ip sla schedule'. Option D is wrong because threshold monitoring is configured using the 'threshold' and 'timeout' commands within the IP SLA configuration, or via the 'ip sla reaction-configuration' command, not by 'ip sla schedule'.

167
Multi-Selectmedium

Which three statements about VRF path isolation in a service provider network are true? (Choose three.)

Select 3 answers
A.VRFs allow multiple customers to share the same physical infrastructure while keeping their traffic isolated.
B.In MPLS VPN, VRFs are combined with route targets to control route distribution between PE routers.
C.VRF-aware features such as NAT, QoS, and ACLs can be applied per VRF to enforce path isolation policies.
D.VRF can be used to replace VLANs for Layer 2 isolation.
E.In VRF-lite, path isolation is achieved using MPLS labels.
AnswersA, B, C

VRFs provide logical separation at Layer 3 by maintaining independent routing and forwarding tables per customer on shared hardware. This satisfies the stem's path isolation requirement, letting overlapping address space coexist without leakage between tenants across the same physical service provider infrastructure.

Why this answer

Option A is correct because a VRF (Virtual Routing and Forwarding) instance creates a separate routing table on the same physical router, so multiple customers can share the provider's physical infrastructure while their traffic and routing information remain logically isolated. Option B is correct because in MPLS L3VPN, each VRF is associated with route targets (extended BGP communities) that control which routes are exported from and imported into the VRF, thereby governing route distribution between PE routers. Option C is correct because VRF-aware features such as NAT, QoS, and ACLs can be configured within a specific VRF context, allowing per-VRF policy enforcement that maintains path isolation between customers.

Option D is not correct because VRFs operate at Layer 3 by separating routing tables, whereas VLANs provide Layer 2 broadcast-domain isolation; VRF does not replace VLANs for Layer 2 segmentation. Option E is not correct because VRF-lite achieves isolation using separate routing/forwarding tables and interfaces (typically without MPLS), not by using MPLS labels.

Exam trap

The trap is confusing VRF with VLANs for Layer 2 isolation, or thinking VRF-lite uses MPLS labels. Candidates might also overlook that VRF-aware features can be applied per VRF.

168
Multi-Selecthard

A network engineer is deploying MACsec on a Cisco Catalyst switch to secure point-to-point links between the access and distribution layers. The design must ensure data confidentiality and integrity on the wire, and must use a key agreement mechanism that supports dynamic key exchange. Which TWO of the following are required to meet these requirements? (Choose two.)

Select 2 answers
A.Configure MACsec (802.1AE) on the point-to-point interfaces to provide data confidentiality and integrity.
B.Configure a private VLAN between the access and distribution switches to isolate traffic.
C.Configure MKA (MACsec Key Agreement) on the participating interfaces to negotiate and rotate keys.
D.Configure 802.1X with EAP-TLS on the inter-switch links to establish the encryption keys.
E.Configure IPsec transport mode between the switches to encrypt all Layer 2 traffic.
AnswersA, C

MACsec, defined in IEEE 802.1AE, provides hop-by-hop encryption and integrity checking at Layer 2 using GCM-AES. Enabling MACsec on the interfaces is what actually secures the wire between access and distribution. MKA alone negotiates keys but does not encrypt frames, so MACsec must be configured to satisfy the confidentiality and integrity requirement.

Why this answer

MACsec (802.1AE) supplies Layer 2 encryption and integrity, while MKA provides the dynamic key agreement, peer discovery, and key rotation. Both must be configured on the point-to-point links to meet the confidentiality, integrity, and dynamic key exchange requirements. IPsec, 802.1X, and private VLANs do not deliver Layer 2 link encryption with MKA.

Exam trap

The trap here is treating 802.1X as the key agreement for MACsec, when MKA is the protocol that negotiates and rotates MACsec keys.

169
MCQhard

A network administrator is deploying a new QoS policy to prioritize voice traffic across a WAN link. The policy must ensure that voice packets are not dropped even during congestion, and that bandwidth is guaranteed for voice. Which queuing mechanism should be used for the voice class?

A.Weighted Random Early Detection (WRED)
B.Low Latency Queuing (LLQ)
C.Class-Based Weighted Fair Queuing (CBWFQ)
D.First-In, First-Out (FIFO) queuing
AnswerB

LLQ combines a strict-priority queue with a guaranteed bandwidth allocation, so voice packets are serviced first and never dropped during congestion while their reserved bandwidth is protected. CBWFQ alone offers no strict priority, so latency-sensitive voice could still be delayed.

Why this answer

LLQ is the correct choice because it combines strict priority queuing with CBWFQ, ensuring that voice traffic is placed into a strict priority queue that is serviced before any other queues. This guarantees low latency and prevents voice packet drops during congestion by allowing the priority queue to be policed to a configured bandwidth limit, while still providing bandwidth guarantees for the voice class.

Exam trap

Cisco often tests the distinction between CBWFQ and LLQ, where candidates mistakenly choose CBWFQ because it offers bandwidth guarantees, but fail to recognize that only LLQ provides the strict priority queuing required for real-time voice traffic to avoid drops and delay.

How to eliminate wrong answers

Option A is wrong because WRED is a congestion avoidance mechanism that drops packets proactively based on queue depth, not a queuing mechanism that guarantees bandwidth or provides strict priority; it would drop voice packets during congestion, violating the requirement. Option C is wrong because CBWFQ provides bandwidth guarantees and fair queuing for classes but does not include a strict priority queue, so voice traffic would experience delay and jitter during congestion, leading to potential drops. Option D is wrong because FIFO queuing offers no differentiation or priority, causing voice packets to be treated the same as all other traffic, resulting in drops and delay during congestion.

170
Multi-Selecthard

Which three statements about EIGRP packet types are true? (Choose three.)

Select 3 answers
A.Hello packets are sent unreliably and do not require an acknowledgment.
B.Update packets are always sent as multicast to all EIGRP neighbors.
C.Query packets are sent reliably and require a Reply from each neighbor.
D.ACK packets are unicast and are used to acknowledge reliable EIGRP packets.
E.Reply packets are sent unreliably to conserve bandwidth.
AnswersA, C, D

EIGRP Hello packets use the unreliable RTP path, so they carry no sequence number and are never acknowledged. This satisfies the stem's requirement for a true statement about packet types: neighbours detect each other and maintain adjacency through periodic, unacknowledged multicasts rather than reliable delivery.

Why this answer

Option A is correct because EIGRP Hello packets are sent to the multicast address 224.0.0.10 using an unreliable delivery method and are not acknowledged, serving only for neighbor discovery and keepalive. Option C is correct because Query packets are sent reliably, meaning they require an acknowledgment, and each neighbor must respond with a Reply packet to indicate it has processed the query. Option D is correct because ACK packets are unicast to the sender of a reliable EIGRP packet and contain no data, existing solely to acknowledge receipt of reliable packets such as Updates, Queries, and Replies.

Option B is incorrect because Update packets are not always multicast; they can be sent as unicast when replying to a specific neighbor or during initial neighbor formation. Option E is incorrect because Reply packets are sent reliably and require acknowledgment, not unreliably, to ensure the querying router receives the response.

Exam trap

The trap here is confusing which EIGRP packet types are reliable versus unreliable, and whether they are sent as multicast or unicast. Candidates often mistakenly think all Update packets are multicast or that Reply packets are unreliable.

171
MCQmedium

Examine the following partial configuration on a Cisco IOS-XE device: interface GigabitEthernet0/1 ip address 10.1.1.1 255.255.255.0 ip ospf hello-interval 5 ip ospf dead-interval 20 ! What is the effect of this configuration?

A.The router will send OSPF hello packets every 5 seconds and declare a neighbor dead after 20 seconds of no hello.
B.The router will send OSPF hello packets every 10 seconds and declare a neighbor dead after 40 seconds, overriding the configuration.
C.The configuration is invalid because the dead interval must be exactly four times the hello interval.
D.The router will not form OSPF adjacencies because the hello and dead intervals are not default.
AnswerA

This is correct because OSPF hello and dead intervals are configurable per interface, and once configured with 5 and 20 seconds, the router will use those exact values for sending hello packets and for declaring a neighbor unreachable. The dead interval of 20 seconds is four times the hello interval, maintaining the recommended ratio for OSPF stability and fast convergence. This configuration is valid and commonly used to tune OSPF convergence times on point-to-point links.

Why this answer

The `ip ospf hello-interval 5` command sets the OSPF hello interval to 5 seconds, and the `ip ospf dead-interval 20` command sets the dead interval to 20 seconds. These per-interface commands override the default hello interval of 10 seconds and dead interval of 40 seconds for broadcast networks, allowing the router to send hello packets every 5 seconds and declare a neighbor dead after 20 seconds of no hello reception.

Exam trap

Cisco often tests the misconception that the dead interval must always be exactly four times the hello interval, but in reality, while the default ratio is 4:1, you can configure any values as long as they match on neighboring routers.

How to eliminate wrong answers

Option B is wrong because it incorrectly states that the router will send hello packets every 10 seconds and use a dead interval of 40 seconds, which would only occur if the default intervals were used; the explicit configuration overrides these defaults. Option C is wrong because while the dead interval is typically four times the hello interval by default, Cisco IOS-XE allows manual configuration of any hello and dead intervals, and the configuration is valid as long as both intervals are set consistently on neighboring routers. Option D is wrong because the router can still form OSPF adjacencies with non-default hello and dead intervals, provided that the neighboring routers are configured with matching hello and dead intervals; mismatched intervals prevent adjacency formation, not the fact that they are non-default.

172
Multi-Selecthard

A network engineer is implementing VXLAN with Cisco SD-Access. The engineer needs to ensure that the fabric supports Layer 2 and Layer 3 traffic between endpoints in different subnets. Which two components are required in the VXLAN data plane to achieve this? (Choose two.)

Select 2 answers
A.VXLAN Network Identifier (VNI)
B.Locator/ID Separation Protocol (LISP)
C.Cisco TrustSec Security Group Tag (SGT)
D.VXLAN Tunnel Endpoint (VTEP)
E.Intermediate System to Intermediate System (IS-IS)
AnswersA, D

The VNI is a 24-bit identifier that segments the VXLAN overlay. Each VNI represents a Layer 2 or Layer 3 segment. It is used to identify the tenant or subnet. Without VNIs, there is no separation of traffic. In SD-Access, VNIs are mapped to VRFs and subnets. They are required to differentiate traffic in the overlay. Therefore, VNI is a required component.

Why this answer

In VXLAN, the data plane relies on VTEPs to encapsulate and decapsulate traffic, and VNIs to identify the overlay segments. These two components are essential for forwarding Layer 2 and Layer 3 traffic across the underlay. LISP is a control plane protocol, IS-IS is an underlay routing protocol, and SGT is for policy enforcement.

Therefore, VTEP and VNI are the correct choices for the data plane.

Exam trap

The trap here is confusing control plane protocols like LISP with data plane components, or assuming that security tags like SGT are required for basic connectivity.

173
MCQmedium

Consider this SNMP configuration on a Cisco IOS-XE switch: snmp-server community public RO snmp-server community private RW snmp-server ifindex persist What is the purpose of the 'snmp-server ifindex persist' command?

A.It prevents SNMP interface indices from changing after a router reload or interface configuration change.
B.It enables SNMP traps for interface status changes.
C.It forces SNMP to use persistent storage for community strings.
D.It allows SNMP to index interfaces by their names instead of numbers.
AnswerA

This command enables the persistence of ifIndex values across router reloads and interface reconfigurations. Without it, Cisco IOS assigns interface indices dynamically based on the order in which hardware and subinterfaces are discovered at boot time, so a reload or adding/removing interfaces can shift the indices. By writing the current ifIndex mapping to persistent storage, the command ensures the NMS continues to associate interface statistics with the correct interface.

Why this answer

The 'snmp-server ifindex persist' command ensures that SNMP interface indices (ifIndex values) remain consistent across router reloads or configuration changes. This is critical for network management systems (NMS) that rely on stable ifIndex values to correlate interface statistics over time, as without persistence, ifIndex values may be reassigned dynamically upon reboot or interface configuration modifications.

Exam trap

The trap here is that candidates confuse 'persist' with enabling traps or saving community strings, when in fact it specifically stabilizes interface index numbering across reboots.

How to eliminate wrong answers

Option B is wrong because enabling SNMP traps for interface status changes is configured with the 'snmp-server enable traps' command, not 'snmp-server ifindex persist'. Option C is wrong because persistent storage for community strings is not related to ifIndex persistence; community strings are stored in the running configuration and can be saved to NVRAM via 'copy running-config startup-config'. Option D is wrong because SNMP always indexes interfaces by numeric ifIndex values as defined in RFC 2863, not by interface names; the command does not change the indexing method to names.

174
Matchingmedium

Drag and drop each STP variant on the left to its matching standard on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

IEEE 802.1D

IEEE 802.1w

IEEE 802.1s

Cisco proprietary

Cisco proprietary (based on 802.1w)

Why these pairings

STP is IEEE 802.1D; RSTP is IEEE 802.1w; MSTP is IEEE 802.1s; PVST+ is Cisco proprietary.

175
Multi-Selecthard

Which three statements about OSPF LSA types are true? (Choose three.)

Select 3 answers
A.Type 1 LSAs are generated by every OSPF router to describe its own interfaces and neighbors.
B.Type 2 LSAs are generated by the Designated Router on multiaccess networks.
C.Type 5 LSAs are generated by ASBRs to advertise routes from other routing domains.
D.Type 3 LSAs are generated by ASBRs to summarize routes between areas.
E.Type 4 LSAs are generated by the ASBR to advertise its presence to other areas.
AnswersA, B, C

Every OSPF router originates a Type 1 Router LSA describing its own interfaces, neighbours and link costs, flooded within its area only. This satisfies the requirement that each router advertises its local topology, forming the basis of the area's shortest-path tree.

Why this answer

Option A is correct because Type 1 Router LSAs are originated by every OSPF router (in each area it belongs to) to describe its own links, interfaces, and neighbor relationships within that area. Option B is correct because Type 2 Network LSAs are generated only by the Designated Router (DR) on multiaccess segments such as Ethernet, representing the subnet and the routers attached to it. Option C is correct because Type 5 AS External LSAs are originated by ASBRs to advertise routes redistributed from outside the OSPF autonomous system (other routing domains) throughout the OSPF domain.

Option D is wrong because Type 3 Summary LSAs are generated by ABRs, not ASBRs, to advertise inter-area routes. Option E is wrong because Type 4 Summary ASBR LSAs are generated by ABRs to advertise the location of an ASBR to other areas, not by the ASBR itself.

Exam trap

350-401 often tests the ABR vs. ASBR responsibility split for Type 3, 4, and 5 LSAs — the trap is assuming the ASBR generates Type 4 (it does not; the ABR does) or that Type 3 comes from the ASBR (it comes from the ABR).

176
MCQmedium

A company is implementing QoS in a network where voice traffic must have strict priority over all other traffic. Which queuing mechanism should be used on the outbound interface of a router to ensure voice packets are always sent first?

A.Random Early Detection (RED)
B.Low Latency Queuing (LLQ)
C.First In First Out (FIFO)
D.Class-Based Weighted Fair Queuing (CBWFQ)
AnswerB

LLQ (Low Latency Queuing) combines a strict-priority queue with CBWFQ: the priority queue is serviced first on every scheduling cycle, before any CBWFQ class queues, so voice is dequeued with minimal and deterministic delay. The priority queue can be policed to a configured rate to prevent a flood of priority traffic from starving the non-priority classes, but within the committed rate voice effectively experiences 'express lane' treatment. This strict-priority scheduling is exactly what makes LLQ the standard QoS queueing strategy for real-time voice traffic in an enterprise.

Why this answer

Low Latency Queuing (LLQ) is the correct choice because it combines Class-Based Weighted Fair Queuing (CBWFQ) with a strict priority queue, ensuring that voice traffic (marked with EF or CS5) is always dequeued before any other traffic class. This guarantees low latency and jitter for real-time traffic, which is essential for voice quality.

Exam trap

Cisco often tests the distinction between CBWFQ and LLQ, trapping candidates who think CBWFQ alone provides priority queuing, when in fact LLQ is required to add the strict priority queue for real-time traffic.

How to eliminate wrong answers

Option A is wrong because Random Early Detection (RED) is a congestion avoidance mechanism that drops packets probabilistically before a queue fills, not a queuing mechanism that prioritizes traffic. Option C is wrong because First In First Out (FIFO) treats all packets equally with no priority, causing voice packets to be delayed behind data bursts. Option D is wrong because Class-Based Weighted Fair Queuing (CBWFQ) provides bandwidth guarantees per class but does not include a strict priority queue, so voice traffic can still experience delay during congestion.

177
MCQeasy

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) and needs to ensure that the management interface is reachable from the wired network. Which interface on the WLC is used for out-of-band management and is typically assigned an IP address on the management VLAN?

A.Management interface
B.Virtual interface
C.Dynamic interface
D.AP-manager interface
AnswerA

The management interface on a Cisco WLC is used for out-of-band management, including GUI, CLI, and RADIUS communication. It is typically assigned an IP address on the management VLAN and is essential for controller reachability. It is the primary interface for administrative access.

Why this answer

The management interface on a Cisco WLC is used for out-of-band management, providing administrative access via GUI, CLI, and RADIUS. It is assigned an IP address on the management VLAN and is critical for controller reachability. Dynamic, AP-manager, and virtual interfaces serve different purposes.

Exam trap

The trap here is assuming the AP-manager interface handles management because it manages access points, but it is specifically for AP communication, not administrative access.

178
MCQmedium

An engineer is deploying a new branch office that must run multiple isolated routing domains on a single Cisco IOS-XE router. Each department requires its own routing table and overlapping IP addressing. The engineer plans to use VRF-Lite. Which configuration step is required to ensure that routes from one VRF do not leak into another?

A.Assign the VRF to the appropriate interfaces and configure a separate routing protocol instance within each VRF.
B.Enable MPLS LDP on all interfaces and redistribute the global routing table into each VRF.
C.Configure a single OSPF process and use different area IDs for each department.
D.Associate each VRF with a unique route distinguisher (RD) and route target (RT) in the BGP configuration.
AnswerA

VRF-Lite isolates routing by binding interfaces to a VRF and running an independent routing process per VRF. Without a routing instance inside the VRF, the router has no routes for that VRF, and without interface binding, traffic uses the global table. This combination provides the required isolation on a single device.

Why this answer

VRF-Lite achieves isolation by binding interfaces to a VRF and running a separate routing protocol instance inside each VRF. This creates independent routing and forwarding tables, allowing overlapping IP addresses and preventing route leakage. RDs, RTs, and MPLS are not needed on a single device; they are relevant only when extending VRFs across a provider core.

Exam trap

The trap here is assuming that VRF-Lite requires MPLS, RDs, or RTs for local isolation, when in fact interface binding and per-VRF routing processes are sufficient.

179
MCQmedium

A network engineer runs the following command on Router R8: R8# show ip mroute count IP Multicast Statistics Group: 239.4.4.4, Source: 10.0.0.9 Packets: 1500, Bytes: 1200000, Average rate: 8000 pps, 5 sec rate: 0 pps Group: 239.5.5.5, Source: 10.0.0.10 Packets: 0, Bytes: 0, Average rate: 0 pps, 5 sec rate: 0 pps Based on this output, what can be concluded?

A.Multicast traffic is flowing for group 239.4.4.4.
B.Multicast traffic is flowing for group 239.5.5.5.
C.Both groups are receiving traffic.
D.The source for group 239.4.4.4 is 10.0.0.10.
AnswerA

In the multicast routing table, the entry for group 239.4.4.4 shows non-zero packet and byte counters, which indicate that the router has actively forwarded or received multicast packets for this group. These counters increment as traffic traverses the (S,G) or (*,G) path, confirming live multicast flow. In contrast, the other group's entry remains at zero, so this is the only active group.

Why this answer

The output shows 1500 packets and 1,200,000 bytes received for group 239.4.4.4 from source 10.0.0.9, with an average rate of 8000 pps, indicating active multicast traffic. In contrast, group 239.5.5.5 shows zero packets and bytes, confirming no traffic is flowing for that group. The 'show ip mroute count' command displays per-group and per-source packet and byte counters, directly reflecting multicast forwarding activity.

Exam trap

Cisco often tests the distinction between multicast route state (presence of an (S,G) entry) and actual traffic flow, so candidates may mistakenly assume that any entry in 'show ip mroute' implies active traffic, when in fact only non-zero packet/byte counters confirm forwarding.

How to eliminate wrong answers

Option B is wrong because the output shows 0 packets and 0 bytes for group 239.5.5.5, meaning no multicast traffic is flowing for that group. Option C is wrong because only group 239.4.4.4 has non-zero counters, so both groups are not receiving traffic. Option D is wrong because the source for group 239.4.4.4 is listed as 10.0.0.9, not 10.0.0.10.

180
MCQhard

A network architect is evaluating Cisco SD-WAN for a company with 50 branch sites and two data centers. The design must provide application-aware routing, direct internet access at branches, and centralized policy management. Which Cisco SD-WAN component is responsible for distributing policies and reachability information to the branch devices?

A.vBond
B.vManage
C.vEdge or cEdge router
D.vSmart
AnswerD

vSmart is the control plane component that distributes policies and reachability information to all SD-WAN devices. It uses OMP to share routing and policy data, enabling application-aware routing and centralized policy enforcement. The branch devices receive their forwarding policies and route information from vSmart, making it the correct answer.

Why this answer

The vSmart controller is the control plane component of Cisco SD-WAN, responsible for distributing policies and reachability information using OMP. It enables centralized policy management and application-aware routing by sharing routing and policy data with all SD-WAN devices in the overlay.

Exam trap

The trap here is confusing the management plane function of vManage with the control plane function of vSmart, leading to the selection of vManage for policy distribution.

181
Drag & Dropmedium

Drag and drop the steps of Jinja2 template rendering for device config generation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The process begins by importing the Jinja2 Environment and FileSystemLoader, creating an environment with a loader pointing to the template directory, loading the template file, defining a dictionary with variables, and finally calling render() to produce the configuration string.

182
Drag & Dropmedium

Drag and drop the steps of VRF-aware NAT configuration for path isolation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, you create the VRF and assign an RD. Then, you configure the NAT inside and outside interfaces under the VRF. Next, you define the NAT pool and access list for translation.

After that, you apply the NAT rules with 'ip nat inside source' referencing the VRF. Finally, you verify NAT translations using 'show ip nat translations vrf'.

183
Multi-Selecthard

Which two statements about SNMP trap and inform operations are true? (Choose two.)

Select 2 answers
A.An SNMP inform request is acknowledged by the manager with a response PDU.
B.SNMP traps are more reliable than informs because they use UDP port 162.
C.Both SNMPv1 and SNMPv2c support the inform operation.
D.Informs consume more network bandwidth and memory resources than traps.
E.Traps are sent from the manager to the agent to request configuration changes.
AnswersA, D

An inform is a confirmed-class notification: the receiving manager must reply with a Response PDU, letting the agent retransmit if none arrives. This satisfies the stem's acknowledgement requirement, unlike an unacknowledged trap, which is fire-and-forget with no confirmation returned to the sender.

Why this answer

Option A is correct because an SNMP inform request is a confirmed notification: the receiving manager must reply with a Response PDU (using the same request-id) so the sender knows the notification was received. Option D is correct because informs require the sender to retain the notification in memory until the acknowledgment arrives and to retransmit if no response is received, adding bandwidth and memory overhead compared with unacknowledged traps. Options B, C, and E are not correct: traps are less reliable than informs since they are unacknowledged, SNMPv1 does not support the inform operation (it was introduced with SNMPv2), and traps are sent from an agent to a manager, not from a manager to an agent to request configuration changes.

Exam trap

350-401 often tests the reliability trade-off between traps and informs — candidates assume traps are 'better' because they're simpler, missing that informs provide acknowledgment at the cost of bandwidth and memory.

184
Multi-Selecthard

A network automation engineer is using NETCONF to configure a Cisco IOS XE device. The engineer wants to ensure that the configuration changes are applied atomically and that the device can roll back to a previous configuration if an error occurs. Which two NETCONF capabilities should the engineer verify are supported by the device? (Choose two.)

Select 2 answers
A.:writable-running
B.:validate
C.:startup
D.:rollback-on-error
E.:candidate
AnswersD, E

:rollback-on-error is a NETCONF capability that ensures if any part of a configuration transaction fails, the entire transaction is rolled back to the previous state. This directly supports the requirement for atomicity and automatic rollback. It works in conjunction with the candidate datastore. Therefore, verifying this capability is necessary to guarantee that errors do not leave the device in a partially configured state.

Why this answer

To achieve atomic configuration changes and rollback on error with NETCONF, the device must support the :candidate and :rollback-on-error capabilities. The :candidate capability provides a staging area for changes, allowing them to be applied as a single transaction. The :rollback-on-error capability ensures that if any part of the transaction fails, the entire change set is discarded, reverting to the previous configuration.

Together, they enable reliable and safe configuration management.

Exam trap

The trap here is confusing validation or writable-running with atomicity and rollback, which are specifically provided by :candidate and :rollback-on-error.

185
MCQhard

A network engineer is designing a multicast network for IPTV. Which protocol is used by routers to discover which multicast groups are of interest to directly connected hosts?

A.Rendezvous Point (RP)
B.Internet Group Management Protocol (IGMP)
C.Protocol Independent Multicast (PIM)
D.Multicast Source Discovery Protocol (MSDP)
AnswerB

IGMP is the end-system to router protocol that lets hosts on a directly connected subnet announce their interest in a specific multicast group, which is exactly what an IPTV receiver must do to request a channel. Routers send general queries and process membership reports to maintain an active group list on each interface. IGMPv3 further supports source-specific joins (S,G), enabling explicit control over which IPTV streams are received. Without IGMP, the first-hop router would have no way to know that a host wants multicast traffic.

Why this answer

IGMP is the protocol used between hosts and their directly connected routers to signal membership in multicast groups. When a host wants to receive traffic for a specific IPTV multicast stream, it sends an IGMP membership report, and the router uses this information to build its multicast forwarding state for that subnet. Without IGMP, the router would have no way of knowing which groups are of interest to local hosts.

Exam trap

Cisco often tests the distinction between host-to-router signaling (IGMP) and router-to-router multicast routing (PIM), so candidates mistakenly choose PIM when the question explicitly asks about discovering groups of interest to directly connected hosts.

How to eliminate wrong answers

Option A is wrong because a Rendezvous Point (RP) is a router in a PIM-SM domain that acts as a meeting point for multicast sources and receivers, not a protocol for discovering host group interest. Option C is wrong because PIM is a multicast routing protocol used between routers to build distribution trees, not a protocol for hosts to report group membership to their first-hop router. Option D is wrong because MSDP is used to exchange active source information between different PIM-SM domains (e.g., between RPs), not for host-to-router group discovery.

186
MCQeasy

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive SSH traffic. The engineer wants to classify SSH traffic destined to the router itself and apply a policer to it. Which mechanism is used by CoPP to classify traffic before the policer is applied?

A.Class maps that match on the control-plane interface and access control lists
B.Policy maps that match on the ingress data-plane interface
C.Route maps that match on the management VRF and next-hop address
D.ACLs applied directly to the VTY lines with the access-class command
AnswerA

CoPP uses a modular QoS CLI structure in which class maps match traffic destined to the control plane. Matching combines the control-plane keyword with ACLs, protocol keywords, or NBAR to identify specific flows such as SSH. The matched traffic is then referenced by a policy map that applies a policer, which is attached to the control plane with the service-policy command.

Why this answer

CoPP is built on the modular QoS CLI, where class maps identify control-plane traffic using the control-plane keyword combined with ACLs or protocol matches. A policy map then applies a policer to those classes, and the policy is attached to the control plane with service-policy. This layered approach lets administrators rate-limit SSH and other punted traffic without affecting transit forwarding.

Exam trap

The trap here is confusing VTY access-class filtering with CoPP policing; access-class restricts who can connect, while CoPP actually rate-limits traffic destined to the route processor.

187
Multi-Selecthard

Which three statements about Ansible roles and directory structure are true? (Choose three.)

Select 3 answers
A.A role must contain at least a 'tasks' directory with a main.yml file to be functional.
B.Variables defined in the 'defaults' directory of a role have the highest precedence.
C.The 'meta' directory in a role can define dependencies on other roles using the 'dependencies' key.
D.Handlers in a role are defined in the 'handlers' directory and are triggered by the 'notify' directive in tasks.
E.Roles cannot be shared or reused across different Ansible projects.
AnswersA, C, D

Ansible loads a role's logic from tasks/main.yml, so a role lacking that directory and file has no tasks to execute and cannot function. This satisfies the statement's requirement, though other directories such as handlers, vars and templates remain optional.

Why this answer

Option A is correct because a role's core behavior lives in its tasks/main.yml file; without a tasks directory containing main.yml, the role has no tasks to execute and is effectively non-functional. Option C is correct because the meta directory's main.yml uses the dependencies key to declare other roles that must run before this role, enabling role composition. Option D is correct because handlers are stored in handlers/main.yml and are only run when a task using the notify directive reports a changed state.

Option B is incorrect because variables in defaults/main.yml have the lowest precedence, not the highest, so they are easily overridden. Option E is incorrect because roles are designed for reuse and can be shared across projects via Ansible Galaxy, Git, or collections.

Exam trap

The 350-401 exam often tests the misconception that defaults have high precedence, when in fact they are the lowest, and that roles are not reusable, which contradicts their purpose.

188
MCQmedium

A mid-size enterprise is deploying a new branch office with 50 users. The branch will have its own router, switch, and wireless AP. The WAN link is a 50 Mbps MPLS circuit. The company uses VoIP and requires Quality of Service. The network administrator has configured the router with a QoS policy that marks VoIP traffic with DSCP EF and all other traffic with DSCP 0. The policy also shapes traffic to 50 Mbps. After deployment, users report that voice quality is poor during peak hours. The administrator checks the router and sees that the output queue on the WAN interface is often full and drops are occurring. Which action should the administrator take to improve voice quality?

A.Increase the shaping rate to 60 Mbps to allow for burst.
B.Configure a priority queue for DSCP EF traffic within the shaper.
C.Replace shaping with policing to drop non-voice traffic.
D.Change the marking to use CoS instead of DSCP for better QoS.
AnswerB

A priority queue, implemented via LLQ (Low Latency Queuing) within the CBWFQ shaper, ensures that DSCP EF voice packets are dequeued ahead of all other classes before the shaped output is released. This guarantees that voice traffic experiences low latency and jitter, and critically, that voice packets are not tail-dropped when the shaper's buffer is temporarily congested due to bursts. The priority queue's strict scheduling protects real-time traffic from the queue-full condition that causes drops in other classes.

Why this answer

The shaper is limiting traffic to 50 Mbps, but during peak hours, the aggregate traffic exceeds this rate, causing the output queue to fill and drop packets indiscriminately. By configuring a priority queue for DSCP EF (VoIP) traffic within the shaper, the router will service VoIP packets before other traffic, ensuring low latency and jitter even when the link is congested. This is the standard Cisco approach for voice quality on shaped links, as priority queuing bypasses the normal FIFO or CBWFQ behavior for marked traffic.

Exam trap

Cisco often tests the misconception that increasing bandwidth or policing alone solves voice quality issues, but the trap here is that shaping without a priority queue causes all traffic to be treated equally, so VoIP suffers from jitter and delay even if the total rate is within the shaped limit.

How to eliminate wrong answers

Option A is wrong because increasing the shaping rate to 60 Mbps does not solve the underlying congestion; it only shifts the bottleneck and may cause the provider to drop traffic if the CIR is strictly 50 Mbps, leading to continued packet loss for VoIP. Option C is wrong because policing would drop excess traffic indiscriminately, including VoIP packets, unless a separate policer is applied per class, and it does not provide the strict priority queuing needed for voice. Option D is wrong because changing the marking to CoS (Layer 2) does not improve QoS on a WAN interface that typically uses DSCP (Layer 3) for queuing decisions; the router's output queue is based on Layer 3 markings, and CoS is lost when traversing the MPLS network unless explicitly mapped.

189
MCQmedium

A network engineer is deploying a Cisco SD-Access fabric. The design requires that endpoints in the same virtual network can communicate with each other even when they attach to different fabric edge nodes, while endpoints in different virtual networks remain isolated. Which control-plane component is responsible for registering endpoint IP-to-location mappings and answering fabric edge node queries?

A.Fabric control-plane node
B.Fabric intermediate node
C.Cisco DNA Center appliance
D.Fabric edge node
AnswerA

The fabric control-plane node runs LISP as the control plane for SD-Access, maintaining the endpoint ID-to-RLOC mapping database. Edge nodes register locally learned endpoints with it and query it to resolve remote endpoint locations before building VXLAN tunnels. This centralized mapping service enables same-virtual-network communication across edge nodes while keeping different virtual networks isolated through separate LISP instance IDs.

Why this answer

In Cisco SD-Access, the fabric control-plane node provides the LISP-based mapping database that stores endpoint ID-to-RLOC associations. Edge nodes register local endpoints and query this node to learn where remote endpoints reside, which enables communication between endpoints in the same virtual network across different edge nodes while preserving isolation between virtual networks.

Exam trap

The trap here is assuming Cisco DNA Center performs the runtime endpoint mapping lookups, when it actually handles design, policy, and automation while the fabric control-plane node owns the LISP mapping database.

190
MCQhard

A network engineer runs the following command on Router R1: R1# show ip eigrp topology all-links EIGRP-IPv4 Topology Table for AS(100)/ID(192.168.1.1) Codes: P - Passive, A - Active, U - Update, Q - Query, R - Reply, r - reply Status, s - sia Status P 10.1.1.0/24, 1 successors, FD is 1310720, serno 5 via 192.168.1.2 (1310720/1310720), GigabitEthernet0/0 via 10.2.2.2 (1587200/1310720), GigabitEthernet0/1 P 10.2.2.0/24, 1 successors, FD is 1310720, serno 6 via 192.168.1.2 (1310720/1310720), GigabitEthernet0/0 via 10.2.2.2 (1587200/1310720), GigabitEthernet0/1 Based on this output, what can be concluded?

A.Both routes have a feasible successor via 10.2.2.2.
B.The route 10.1.1.0/24 has two successors.
C.The alternate path via 10.2.2.2 will be used immediately if the successor fails.
D.The router has two paths to 10.1.1.0/24, but only one is in the routing table.
AnswerD

Only the successor is installed in the routing table; the other path is not used unless the successor fails and queries are sent.

Why this answer

The output shows that for 10.1.1.0/24, the feasible distance (FD) is 1310720 and there is only one successor (the route via 192.168.1.2). The alternate path via 10.2.2.2 has a reported distance (RD) of 1310720, which equals the FD, so it does not satisfy the feasibility condition (RD < FD) and therefore is not a feasible successor. Only the successor route is installed in the routing table.

Exam trap

Cisco often tests the distinction between a successor and a feasible successor, and the trap here is that candidates assume any alternate path with a lower metric than the FD is a feasible successor, but the feasibility condition requires the reported distance to be strictly less than the feasible distance, not less than or equal.

How to eliminate wrong answers

Option A is wrong because the alternate path via 10.2.2.2 has a reported distance equal to the feasible distance, which violates the feasibility condition (RD must be strictly less than FD) and thus is not a feasible successor. Option B is wrong because the output explicitly states '1 successors' for 10.1.1.0/24, meaning there is only one successor, not two. Option C is wrong because the alternate path is not a feasible successor; if the successor fails, EIGRP must send queries and go active for that route before it can use the alternate path, so it will not be used immediately.

191
MCQmedium

An engineer configures a VXLAN tunnel between two Nexus switches acting as VTEPs. The underlay is a routed Layer 3 network using OSPF, and the loopback interfaces of the VTEPs are reachable. However, hosts in the same VXLAN VNI on different VTEPs cannot communicate. Which action should the engineer take to resolve the issue?

A.Configure static VXLAN tunnels between the VTEPs using the destination-udp-port command.
B.Enable OSPF on the loopback interfaces and advertise them into the underlay.
C.Enable PIM sparse mode on the underlay and configure a rendezvous point for multicast replication.
D.Configure the NVE interface with the correct source-interface and ensure the VNI is mapped to the VLAN.
AnswerD

The NVE interface must be configured with a source-interface (typically a loopback) and the VNI must be associated with the correct VLAN. Without this mapping, VXLAN encapsulation or decapsulation fails, preventing communication between hosts on different VTEPs. This is a common misconfiguration that directly causes the described symptom, making this the correct action to resolve the issue.

Why this answer

The NVE interface on a Cisco Nexus VTEP must have a source-interface configured, usually a loopback, and each VNI must be mapped to a VLAN. Without these, VXLAN encapsulation and decapsulation fail, so hosts in the same VNI on different VTEPs cannot communicate. The underlay is already operational, so the fix is to correct the NVE and VNI configuration.

Exam trap

The trap here is assuming the underlay routing is at fault when the loopbacks are already reachable, leading to unnecessary OSPF or PIM changes instead of checking the NVE interface and VNI mapping.

192
MCQmedium

A network administrator is configuring a Cisco Catalyst 9300 switch stack using StackWise-480 technology. The administrator wants to ensure that if the active switch fails, the standby switch takes over with minimal disruption. Which statement describes the behavior of the stack during a failover?

A.The stack splits into multiple independent switches, each with its own configuration.
B.The master switch is elected based on the highest MAC address, and all other switches reload.
C.The standby switch becomes active, and the stack retains its configuration and forwarding state.
D.All switches in the stack reload and then elect a new active switch.
AnswerC

In a StackWise-480 deployment, the standby switch is ready to take over if the active switch fails. The stack retains its configuration and forwarding state, and the standby becomes active with minimal disruption. This is the designed behavior for high availability, ensuring that network services continue without a full stack reload.

Why this answer

StackWise-480 provides high availability by maintaining a standby switch that is ready to take over if the active switch fails. The stack retains its configuration and forwarding state, allowing for minimal disruption. The standby switch becomes active, and the member switches continue to operate without a full reload.

Exam trap

The trap here is assuming that a failover causes a stack-wide reload or split, when in fact the standby simply assumes the active role.

193
MCQmedium

A network administrator is configuring IPsec VPN on a Cisco IOS router. The administrator wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which configuration element is required to define this traffic?

A.A crypto ACL that permits IP traffic from 10.1.1.0/24 to 10.2.2.0/24.
B.An ACL applied to the outside interface with 'ip access-group' to permit the traffic and enable encryption.
C.A prefix list that permits the source and destination subnets, applied to the crypto map.
D.A route map that matches the source and destination subnets and sets the next-hop to the VPN peer.
AnswerA

A crypto ACL (also called an encryption ACL) defines the interesting traffic that should be protected by IPsec. It is referenced in the crypto map. Permitting traffic from 10.1.1.0/24 to 10.2.2.0/24 ensures that only this traffic is encrypted. Other traffic falls through the implicit deny and is sent unencrypted, as desired. This is the standard method to specify VPN traffic.

Why this answer

IPsec uses a crypto ACL to define which traffic is protected. This ACL is referenced in a crypto map, which is applied to the interface. Traffic matching the ACL is encrypted; other traffic is not.

The crypto ACL must permit the specific source and destination subnets. Other options do not correctly identify interesting traffic for IPsec.

Exam trap

The trap here is confusing interface ACLs with crypto ACLs; only the crypto ACL referenced in the crypto map defines interesting traffic for encryption.

194
MCQeasy

A network technician is troubleshooting a switch that is experiencing high CPU utilization. The technician runs the command 'show processes cpu sorted' and notices that the process 'ARP Input' is consuming a large percentage of CPU. Which action should the technician take to mitigate this issue?

A.Implement ARP rate limiting or ARP policing on the affected interfaces.
B.Enable Dynamic ARP Inspection (DAI) on all VLANs.
C.Configure a static ARP entry for the affected hosts.
D.Increase the ARP cache timeout to reduce ARP requests.
AnswerA

ARP rate limiting or policing limits the number of ARP packets processed by the switch's CPU, preventing excessive ARP traffic from overwhelming the control plane. This directly reduces the load on the ARP Input process. It is an effective mitigation for high CPU caused by ARP storms or ARP-based attacks. Configuring this on interfaces facing untrusted hosts can protect the switch.

Why this answer

High CPU utilization from the ARP Input process is typically caused by a large number of ARP packets being sent to the switch's CPU. Implementing ARP rate limiting or policing on interfaces can control the rate at which ARP packets are processed, preventing the CPU from being overwhelmed. Other options like static ARP entries or increasing cache timeout do not address the volume of ARP traffic.

Enabling DAI can worsen the CPU load. Therefore, ARP rate limiting is the most effective mitigation.

Exam trap

The trap here is thinking that security features like Dynamic ARP Inspection reduce CPU load, but they actually add processing overhead.

195
MCQhard

A network engineer is configuring NAT on a Cisco router to allow internal hosts to access the internet. The engineer uses the command ip nat inside source static tcp 192.168.1.10 80 203.0.113.1 80. After testing, external users can access the internal web server using the public IP. However, internal hosts cannot access the web server using the public IP. What is the most likely cause?

A.The router does not have NAT hairpinning enabled, so internal traffic to the public IP is not translated.
B.The static NAT entry is missing the extendable keyword.
C.The internal hosts have a route to the public IP via the router's outside interface.
D.The access list used for NAT is blocking internal traffic.
AnswerA

Without NAT hairpinning, the router treats a packet from an inside host to the inside server's public IP as inside-to-inside traffic. By default, Cisco IOS applies NAT only to packets crossing a NAT boundary between inside and outside interfaces, so the destination translation is never consulted. Consequently, the public IP is not translated to the private server address and the packet fails. To enable this, you must explicitly configure hairpinning, for example with 'ip nat enable route-map' on the involved interfaces.

Why this answer

The issue is that NAT hairpinning (also known as NAT reflection or NAT loopback) is not enabled by default on Cisco IOS. When an internal host sends traffic to the public IP address (203.0.113.1), the router sees the destination as its own outside interface IP and forwards the packet out that interface without performing the static NAT translation. The packet never reaches the internal web server (192.168.1.10).

To fix this, the engineer must enable hairpinning using the 'ip nat enable' command on the inside interface or configure a route-map to force the router to translate traffic sourced from the inside network destined to the public IP.

Exam trap

Cisco often tests the misconception that static NAT entries automatically handle internal-to-public traffic, when in fact hairpinning must be explicitly configured to allow traffic from the inside network to be translated and reflected back to another inside host.

How to eliminate wrong answers

Option B is wrong because the 'extendable' keyword is used to allow multiple NAT translations to use the same global address with different ports, which is not relevant to the hairpinning issue. Option C is wrong because if internal hosts had a route to the public IP via the router's outside interface, traffic would be forwarded out that interface and never reach the internal server; this would actually worsen the problem, not solve it. Option D is wrong because the question states the static NAT entry is configured without an access list; static NAT does not require an ACL, and an ACL would not block internal-to-public traffic unless explicitly applied to filter such traffic.

196
MCQhard

A network engineer is troubleshooting a NAT issue where an internal host cannot establish an SSH session to a remote server on the internet. The engineer checks the NAT translations on the border router and sees that the translation for the host's source IP is present. However, the SSH session times out. The engineer also notices that the remote server's IP is not in the NAT translation table. What is the most likely cause?

A.The router is performing NAT only for the source IP, but the return traffic is taking a different path that does not go through the NAT router.
B.The SSH server is blocking connections from the public IP address.
C.The NAT overload is causing port conflicts for SSH.
D.The access list used for NAT is denying the SSH traffic.
AnswerA

Correct because if the return traffic does not pass through the same NAT router, the router will not create an inbound translation entry, and the packet will not be translated back to the private IP.

Why this answer

The presence of a source NAT translation for the internal host indicates that the router is correctly translating the outbound SSH traffic. However, the absence of the remote server's IP in the NAT translation table suggests that the return traffic from the server is not reaching the NAT router. This typically occurs when the return path takes a different route through the network, bypassing the router that performed the NAT, so the router never sees the reply packets and cannot create the necessary reverse translation entry.

As a result, the SSH session times out because the host receives no response.

Exam trap

Cisco often tests the misconception that a successful source NAT translation guarantees bidirectional traffic flow, but the trap here is that candidates overlook the requirement for symmetric routing in stateful NAT operations.

How to eliminate wrong answers

Option B is wrong because the SSH server blocking connections from the public IP would typically result in a connection refused or reset, not a timeout, and the NAT translation table would still show the server's IP for the return traffic if it arrived at the router. Option C is wrong because NAT overload (PAT) uses unique port numbers to differentiate sessions; port conflicts are rare and would cause immediate failures or resets, not a timeout with a missing server IP in the table. Option D is wrong because if the ACL were denying SSH traffic, the router would not create the source NAT translation at all, yet the translation for the host's source IP is present, indicating the ACL permitted the outbound traffic.

197
MCQeasy

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) to use 802.1X authentication for wireless clients. The administrator wants to ensure that the WLC communicates with the RADIUS server securely. Which protocol should be used to encrypt the RADIUS communication between the WLC and the RADIUS server?

A.RADIUS with IPsec
B.RADIUS over TLS (RadSec)
C.RADIUS with MS-CHAPv2
D.RADIUS with EAP-TLS
AnswerB

RadSec (RADIUS over TLS) encrypts RADIUS packets using TLS, providing secure communication between the WLC and the RADIUS server. This protects credentials and attributes from eavesdropping. It is the recommended method for securing RADIUS traffic in modern deployments.

Why this answer

RadSec (RADIUS over TLS) is the correct protocol to encrypt RADIUS communication between a WLC and a RADIUS server. It uses TLS to secure the entire RADIUS packet, ensuring confidentiality and integrity. Other options either refer to authentication methods or do not provide native encryption for RADIUS.

Exam trap

The trap here is confusing authentication protocols like EAP-TLS or MS-CHAPv2 with transport encryption mechanisms, leading to the selection of an option that secures client authentication but not the RADIUS transport.

198
MCQhard

A network engineer runs the following command on switch SW4: SW4# show cts environment-data CTS Environment Data: Device ID: SW4.cisco.com Device Name: SW4 CTS Capabilities: SGT, SXP, CTSD, CTSA SGT: 100 SXP Node: Enabled SXP Connection: 10.1.1.1:64999 Based on this output, what can be concluded?

A.The switch is using 802.1X for authentication.
B.The switch has an SXP connection to a peer at 10.1.1.1.
C.The switch's SGT is 10.
D.The switch is not capable of SGT assignment.
AnswerB

The output explicitly states 'SXP Node enabled' and lists an SXP connection to 10.1.1.1:64999, which is the well-known TCP port for SXP. This indicates the switch actively exchanges SGT-to-IP bindings with that peer, using SXP to propagate Cisco TrustSec security group tags to devices that don't support inline tagging.

Why this answer

The output shows 'SXP Connection: 10.1.1.1:64999', which directly indicates that the switch has an active SXP (Security Exchange Protocol) connection to a peer at IP address 10.1.1.1. SXP is used to propagate Security Group Tags (SGTs) between Cisco TrustSec devices, and the presence of this line confirms the connection is established.

Exam trap

Cisco often tests the ability to read the exact values in the command output, so candidates may misread 'SGT: 100' as '10' or confuse the SXP connection line with an authentication method like 802.1X.

How to eliminate wrong answers

Option A is wrong because the output does not show any 802.1X configuration or authentication status; it only displays CTS environment data, which is unrelated to 802.1X. Option C is wrong because the output clearly shows 'SGT: 100', not 10. Option D is wrong because the output explicitly lists 'SGT' under 'CTS Capabilities', indicating the switch is fully capable of SGT assignment and propagation.

199
MCQeasy

A network engineer is deploying a new branch office that requires a WAN connection with built-in encryption and dynamic multipoint VPN capabilities. The engineer wants to use a Cisco technology that supports spoke-to-spoke communication without requiring traffic to traverse the hub. Which technology should be implemented?

A.DMVPN
B.IPsec VPN
C.GRE tunnel
D.MPLS L3VPN
AnswerA

DMVPN (Dynamic Multipoint VPN) allows spoke-to-spoke tunnels to be established on demand, enabling direct communication between branch sites without routing traffic through the hub. It uses mGRE (multipoint GRE) and NHRP (Next Hop Resolution Protocol) to dynamically discover and build tunnels. This matches the requirement for dynamic multipoint VPN with encryption, typically provided by IPsec.

Why this answer

DMVPN is designed to provide dynamic multipoint VPN connectivity, allowing spokes to establish direct tunnels with each other as needed. It combines mGRE, NHRP, and IPsec to deliver scalable, encrypted, and dynamic branch connectivity. This eliminates the need to route spoke-to-spoke traffic through the hub, improving latency and reducing hub bandwidth consumption.

Exam trap

The trap here is confusing IPsec VPN with DMVPN, assuming that any encrypted VPN automatically supports dynamic spoke-to-spoke tunnels, when DMVPN specifically adds the multipoint dynamic capability.

200
Multi-Selecthard

Which three statements about Cisco SD-Access design are true? (Choose three.)

Select 3 answers
A.VXLAN is used as the data plane encapsulation in SD-Access to create overlay tunnels.
B.The fabric border node is the access layer switch that connects end devices to the network.
C.LISP provides the control plane for SD-Access by managing endpoint identifiers and routing locators.
D.The border node provides connectivity between the SD-Access fabric and traditional networks or the WAN.
E.SD-Access requires a three-tier hierarchical design with core, distribution, and access layers.
AnswersA, C, D

VXLAN provides the Layer 2 overlay that carries endpoint traffic across the SD-Access underlay, encapsulating original frames in UDP. This satisfies the design requirement for a data plane encapsulation, separating the virtual overlay from the physical routed fabric.

Why this answer

Cisco SD-Access is a policy-based, intent-driven network architecture that uses VXLAN for overlay tunneling and LISP for control plane. It separates the network into fabric and non-fabric domains. The fabric uses a border node to connect to external networks.

Option A is correct because VXLAN provides the data plane encapsulation. Option C is correct because LISP is the control plane that maps endpoints to their locations. Option D is correct because the border node connects the fabric to outside networks (e.g., WAN, Internet).

Option B is incorrect because the fabric edge is the access layer switch that connects endpoints, not the border. Option E is incorrect because SD-Access typically uses a two-tier spine-leaf design, not a three-tier core-distribution-access.

201
MCQmedium

A campus network architect is redesigning the LAN to support high availability and east-west traffic growth. The current design uses a traditional three-tier hierarchy with a collapsed core. The architect must choose a new design that provides predictable latency, simple scalability, and efficient use of uplinks. Which design should the architect select?

A.Collapsed core design with redundant core switches and distribution layers.
B.Leaf-spine design with all leaf switches connected to all spine switches.
C.Mesh design where every switch connects to every other switch.
D.Traditional three-tier design with access, distribution, and core layers.
AnswerB

A leaf-spine design connects every leaf switch to every spine switch, creating a full-mesh fabric at the spine layer while keeping each leaf's uplinks identical. Every server-to-server flow takes at most two hops, and with ECMP (Equal-Cost Multipathing), traffic is spread across all spines, avoiding oversubscription and providing predictable, low latency. Scaling is horizontal — adding another spine increases bandwidth and path options without rewiring existing leaves.

Why this answer

The leaf-spine design (option B) provides predictable latency because every leaf switch is exactly one hop away from any other leaf switch via the spine, regardless of traffic path. This design also scales simply by adding more leaf or spine switches without reconfiguring existing connections, and it uses uplinks efficiently through equal-cost multipath (ECMP) load balancing, making it ideal for east-west traffic growth in a modern data center or campus LAN.

Exam trap

Cisco often tests the misconception that a collapsed core design is sufficient for high availability and east-west traffic, but the trap here is that candidates overlook the predictable latency and linear scalability benefits of leaf-spine, which are explicitly required by the question's criteria.

How to eliminate wrong answers

Option A is wrong because a collapsed core design with redundant core switches and distribution layers still introduces variable hop counts and potential bottlenecks for east-west traffic, as traffic between distribution switches must traverse the core, increasing latency and reducing predictability. Option C is wrong because a full mesh design does not scale efficiently; the number of connections grows quadratically (n*(n-1)/2), leading to excessive cabling and port usage, and it lacks the structured, predictable latency of leaf-spine. Option D is wrong because the traditional three-tier design (access, distribution, core) introduces multiple hops and oversubscription at the distribution layer, which increases latency and complicates scaling for east-west traffic patterns.

202
MCQhard

A network engineer is configuring a Cisco SD-WAN fabric with vManage, vSmart, and vBond controllers. The engineer wants to ensure that all branch routers automatically discover the vSmart and vManage controllers without manually configuring the vSmart or vManage addresses on each branch. The engineer has configured the vBond with a public IP address and enabled NAT traversal. However, branch routers are failing to establish control connections. The engineer verifies that the branch routers have the correct organization name but have not been configured with the vBond IP address. What is the most likely missing configuration?

A.The vManage IP address is not configured on the branch routers.
B.The vSmart IP address is not configured on the branch routers.
C.The vBond IP address is not configured on the branch routers.
D.The DTLS port 12346 is not open on the branch routers' firewall.
AnswerC

The vBond orchestrator is the mandatory initial entry point in the SD-WAN discovery process: each branch router must have a configured vBond IP or resolvable vBond hostname to initiate the DTLS control-plane session. vBond authenticates the vEdge, verifies its identity, and then returns the IP addresses of vManage and vSmart for further configuration. Without this bootstrap value, the router cannot begin the fabric handshake, which precisely explains the symptoms in the scenario.

Why this answer

In Cisco SD-WAN, branch routers use a two-phase discovery process: they first connect to the vBond controller to authenticate and receive the list of vSmart and vManage controllers. Since the engineer has already configured the vBond with a public IP and enabled NAT traversal, and the branch routers have the correct organization name, the missing piece is that the vBond IP address must be explicitly configured on each branch router (via the 'system vbond' CLI command or the equivalent in the device template). Without this, the branch routers have no initial target to contact for the bootstrap discovery process, so they cannot automatically learn the vSmart and vManage addresses.

Exam trap

Cisco often tests the misconception that branch routers need the vSmart or vManage IP configured directly, when in fact the vBond is the single mandatory bootstrap address for automatic discovery.

How to eliminate wrong answers

Option A is wrong because the vManage IP address is not required on branch routers for initial control connection establishment; vManage is used for management and monitoring, and its address is learned from vBond during the discovery phase. Option B is wrong because the vSmart IP address is also not statically configured on branch routers; it is dynamically provided by vBond after the branch router successfully authenticates with vBond. Option D is wrong because DTLS port 12346 is the default port used by vBond for control connections, and the engineer has already enabled NAT traversal and verified reachability; if the port were blocked, the branch routers would not be able to reach vBond at all, but the scenario states vBond is reachable, so the firewall is not the issue.

203
MCQmedium

A network engineer is implementing Cisco TrustSec in a campus network. The security team wants to enforce access policies based on user identity and device type without relying on IP addresses. Which component is responsible for assigning Security Group Tags (SGTs) to traffic at the ingress point?

A.Cisco Identity Services Engine (ISE)
B.Cisco Firepower Threat Defense (FTD)
C.Cisco DNA Center
D.Cisco Catalyst switch with TrustSec support
AnswerD

The ingress Cisco Catalyst switch (or wireless controller) is responsible for assigning SGTs to packets based on the classification policy received from ISE. It inserts the SGT into the Cisco Metadata (CMD) field of the packet or uses inline tagging. This enables enforcement throughout the network without relying on IP addresses. Thus, the switch is the component that assigns SGTs at the ingress point.

Why this answer

In Cisco TrustSec, the ingress network device (such as a Catalyst switch or wireless controller) is responsible for classifying and tagging packets with SGTs. This classification is based on policies downloaded from ISE. The switch inserts the SGT into the packet, allowing subsequent devices to enforce access policies without examining IP addresses.

ISE defines the policies but does not perform the tagging.

Exam trap

The trap here is assuming that ISE, as the policy engine, also performs the tagging, when in fact the tagging is done by the ingress network device.

204
MCQhard

A network engineer is deploying Cisco SD-Access and needs to ensure that endpoints in the same virtual network (VN) can communicate across fabric sites while endpoints in different VNs remain isolated. Which control plane component is responsible for propagating endpoint reachability information between fabric sites?

A.Cisco DNA Center fabric site border node
B.Cisco DNA Center fabric intermediate node
C.Cisco DNA Center fabric control plane node
D.Cisco Identity Services Engine policy node
AnswerC

The fabric control plane node runs LISP and maintains the mapping of endpoint EIDs to RLOCs. When a fabric site is connected via a transit network, control plane nodes in each site exchange LISP map-register and map-notify messages so that endpoints in the same VN are reachable across sites while different VNs stay isolated by their respective VRFs and LISP instance IDs.

Why this answer

In Cisco SD-Access, the control plane node runs LISP and is responsible for registering endpoint EID-to-RLOC mappings and sharing them with control plane nodes in other fabric sites over the transit network. This allows endpoints in the same virtual network to be reached across sites while VN isolation is preserved through separate LISP instance IDs and VRFs. Border and intermediate nodes forward data plane traffic but do not propagate reachability.

Exam trap

The trap here is confusing the border node's data plane role in VXLAN encapsulation with the control plane node's LISP responsibility for propagating endpoint reachability between fabric sites.

205
MCQhard

A network engineer is configuring a Cisco IOS router for NAT overload (PAT) to allow internal hosts on the 10.1.1.0/24 network to access the internet using the router's outside interface IP address. The engineer wants to ensure that all internal hosts can initiate connections and that return traffic is correctly translated. Which configuration is required?

A.ip nat inside source list 1 interface GigabitEthernet0/0 overload, with an access list permitting 10.1.1.0/24, and interfaces marked as inside and outside.
B.ip nat inside source static 10.1.1.1 203.0.113.1, with interfaces marked as inside and outside.
C.ip nat inside source list 1 pool MYPOOL overload, with a pool of public addresses, and interfaces marked as inside and outside.
D.ip nat outside source list 1 interface GigabitEthernet0/0 overload, with an access list permitting 10.1.1.0/24, and interfaces marked as inside and outside.
AnswerA

This configuration enables NAT overload (PAT) by translating all internal addresses matching the access list to the outside interface's IP address. The overload keyword allows multiple hosts to share the same public IP. Marking interfaces as inside and outside is essential for NAT to function correctly. This meets the requirements.

Why this answer

The correct configuration uses ip nat inside source list with the interface keyword and overload to translate internal addresses to the outside interface IP. This enables PAT, allowing multiple internal hosts to share the single public IP. The access list must permit the internal subnet, and interfaces must be correctly marked as inside and outside for NAT to operate.

Exam trap

The trap here is confusing NAT overload using an interface with NAT using a pool, or misusing the outside source command, which is for different translation scenarios.

206
MCQmedium

Examine the following configuration snippet: interface GigabitEthernet1/0/2 switchport mode access authentication port-control auto mab dot1x pae authenticator dot1x timeout tx-period 10 Which statement about this configuration is true?

A.MAB will be attempted first, and if it fails, 802.1X will be used.
B.802.1X will be attempted first; if the client does not respond, MAB will be used as a fallback.
C.The port will be placed in a guest VLAN if both 802.1X and MAB fail.
D.The switch will act as a supplicant for MAB and an authenticator for 802.1X.
AnswerB

This is correct. The switch, acting as the authenticator, first sends EAPOL-Request/Identity frames and waits for the client's EAPOL response. If the client is not 802.1X-capable or has no supplicant enabled, it will not respond; after the EAPOL timeout expires, the switch falls back to MAB. MAB then performs a RADIUS authentication using the MAC address as both username and password, allowing legacy devices such as printers or IP phones to authenticate without a supplicant.

Why this answer

The configuration sets the switchport as an 802.1X authenticator (dot1x pae authenticator) with MAB enabled. By default, 802.1X is attempted first; if the client does not respond to EAPOL requests (e.g., due to lack of 802.1X supplicant), the switch falls back to MAB, which uses the source MAC address for authentication. The dot1x timeout tx-period 10 sets the interval for retransmitting EAPOL-Start frames, reinforcing the initial 802.1X attempt before fallback.

Exam trap

Cisco often tests the order of authentication methods (802.1X first, then MAB) and the misconception that MAB is attempted before 802.1X, which is incorrect because 802.1X is always the primary method unless explicitly overridden with 'authentication order' or 'authentication priority' commands.

How to eliminate wrong answers

Option A is wrong because MAB is not attempted first; 802.1X is always attempted first, and MAB is used only as a fallback when no EAPOL response is received. Option C is wrong because the configuration does not include a guest VLAN (e.g., 'authentication guest-vlan' command), and the port behavior upon failure is not defined in this snippet. Option D is wrong because the switch acts as an authenticator for both MAB and 802.1X, not as a supplicant; MAB is a server-based authentication method where the switch sends the MAC address to the RADIUS server, but the switch remains the authenticator.

207
MCQeasy

An enterprise is deploying QoS across a network that includes both Cisco and non-Cisco devices. The engineer wants to use a marking scheme that is end-to-end and not stripped at Layer 3 boundaries. Which marking field should the engineer use?

A.CoS
B.IP Precedence
C.DSCP
D.MPLS EXP
AnswerC

DSCP (Differentiated Services Code Point) is the 6-bit field in the ToS byte of the IP header, making it a true Layer 3 marking that remains intact as packets traverse routers. It is standardized by the IETF and supports up to 64 codepoints, enabling scalable QoS policies like EF (Expedited Forwarding) and AF (Assured Forwarding). Because it is carried in the IP header itself, DSCP is preserved across heterogeneous network devices and is the preferred marking for end-to-end QoS in enterprise and service provider networks.

Why this answer

DSCP (Differentiated Services Code Point) is the correct choice because it is defined in RFC 2474 as a Layer 3 marking field in the IP header. Unlike CoS (Layer 2) or MPLS EXP (which is stripped at MPLS boundaries), DSCP markings are preserved across Layer 3 boundaries (routers) and can be used end-to-end across both Cisco and non-Cisco devices, as long as the intermediate devices trust the DSCP value.

Exam trap

Cisco often tests the distinction between Layer 2 (CoS) and Layer 3 (DSCP) marking, and the trap here is that candidates confuse 'end-to-end' with 'within a single domain,' leading them to choose CoS or MPLS EXP, which are not preserved across Layer 3 boundaries.

How to eliminate wrong answers

Option A is wrong because CoS (Class of Service) is a Layer 2 marking field in the 802.1Q/p header, which is stripped when a frame passes through a Layer 3 boundary (router) and is not preserved across IP networks. Option B is wrong because IP Precedence is a 3-bit field in the IP header that provides only 8 classes, but it is often re-marked or ignored in modern networks; DSCP (6 bits) is the preferred Layer 3 marking for end-to-end QoS and is backward-compatible with IP Precedence. Option D is wrong because MPLS EXP (Experimental bits) is a Layer 2.5 marking field used within an MPLS domain; it is stripped when the MPLS label is removed at the egress LER, so it is not end-to-end across Layer 3 boundaries.

208
MCQmedium

A network administrator is deploying a new Cisco Catalyst switch and wants to restrict management access to the switch. The requirement is that only hosts on the 10.10.10.0/24 subnet can access the switch via SSH, and all other SSH attempts must be denied. Which configuration achieves this?

A.access-list 10 permit 10.10.10.0 0.0.0.255; interface vlan 1; ip access-group 10 in
B.access-list 10 permit 10.10.10.0 0.0.0.255; line vty 0 4; access-class 10 in
C.access-list 10 deny 10.10.10.0 0.0.0.255; line vty 0 4; access-class 10 in
D.access-list 110 permit tcp 10.10.10.0 0.0.0.255 any eq 22; line vty 0 4; access-class 110 in
AnswerB

This configuration creates a standard ACL that permits the 10.10.10.0/24 subnet and applies it inbound to the VTY lines with access-class. This restricts SSH and Telnet access to only that subnet, meeting the requirement. The implicit deny at the end of the ACL blocks all other sources.

Why this answer

Using a standard ACL that permits the 10.10.10.0/24 subnet and applying it inbound on the VTY lines with access-class restricts SSH and Telnet access to only that subnet. The implicit deny at the end blocks all other sources, satisfying the requirement without affecting other traffic.

Exam trap

The trap here is applying an ACL to an interface instead of the VTY lines, or using an extended ACL when a standard ACL is sufficient, which can lead to unintended filtering or lack of restriction.

209
MCQeasy

A network administrator is configuring a site-to-site VPN between two Cisco routers using IPsec. The administrator wants to ensure that the data transmitted between the sites is encrypted and authenticated. Which IPsec protocol should be used to provide both confidentiality and integrity for the data payload?

A.Generic Routing Encapsulation (GRE)
B.Internet Key Exchange (IKE)
C.Authentication Header (AH)
D.Encapsulating Security Payload (ESP)
AnswerD

ESP provides confidentiality through encryption and can also provide authentication and integrity for the payload. It is the standard choice for VPNs requiring encryption. ESP can operate in transport or tunnel mode; in tunnel mode, it encrypts the entire original IP packet. This meets the requirement for both confidentiality and integrity of the data payload.

Why this answer

ESP is the IPsec protocol that provides both confidentiality (encryption) and integrity/authentication for the data payload. AH only provides integrity and authentication, while IKE is for key exchange and GRE is a tunneling protocol without built-in security. Therefore, ESP is the correct choice for encrypting and authenticating VPN traffic.

Exam trap

The trap here is selecting AH because it sounds like it provides authentication, but it lacks encryption; ESP is needed for confidentiality.

210
MCQmedium

A network engineer is configuring QoS on a Cisco router to prioritize business-critical applications. The engineer creates a class-map that matches traffic based on the destination IP address and port. However, the class-map does not match the expected traffic. What is the most likely reason?

A.The class-map uses 'match-all' but the engineer intended to use 'match-any'.
B.The access-list used for matching is not applied to the correct interface.
C.The router does not support matching on both IP and port in the same class-map.
D.The class-map must be applied to the interface before it can match traffic.
AnswerA

Because the class-map is configured with 'match-all', every match statement must evaluate true for a packet to be classified into that class. QoS class-maps default to 'match-all' unless 'match-any' is explicitly specified; if the engineer configured multiple match conditions such as 'match access-group' and 'match protocol' and only one of those conditions is satisfied, the packet will not be placed in this user-defined class. As a result, the intended QoS policy (such as marking, policing, or queuing) will not apply to that traffic, and the packet falls through to the default class. Changing the class-map to 'match-any' allows the traffic to match when any one of the conditions is true.

Why this answer

When a class-map uses 'match-all', all match conditions must be true for a packet to be classified. If the engineer intended to match traffic based on either the destination IP address OR the port, using 'match-any' would allow the class-map to match if any single condition is met. The mismatch occurs because the class-map is too restrictive, requiring both conditions to be satisfied simultaneously.

Exam trap

Cisco often tests the subtle difference between 'match-all' (default) and 'match-any' in class-maps, trapping candidates who assume that multiple match conditions automatically use OR logic.

How to eliminate wrong answers

Option B is wrong because the access-list used for matching is referenced inside the class-map, not applied directly to the interface; the class-map itself is applied to the interface via a policy-map, so the access-list does not need separate interface application. Option C is wrong because Cisco routers fully support matching on both IP and port in the same class-map using nested match statements or an extended access-list; there is no inherent limitation. Option D is wrong because a class-map does not need to be applied to an interface to match traffic; it is the policy-map that references the class-map and is applied to the interface, and the class-map itself can be tested independently.

211
Multi-Selectmedium

A network engineer is configuring a Cisco IOS router to support PIM Sparse Mode (PIM-SM) for multicast traffic. The engineer needs to ensure that the router can dynamically discover Rendezvous Points (RPs). Which two mechanisms can be used to achieve this? (Choose two.)

Select 2 answers
A.MSDP
B.Anycast RP
C.Bootstrap Router (BSR)
D.Auto-RP
E.Static RP configuration
AnswersC, D

BSR is a standards-based mechanism for dynamic RP discovery. It uses candidate RPs and a Bootstrap Router to distribute RP information to all routers in the PIM domain. Routers receive BSR messages and automatically learn the RP mappings. This is a valid method for dynamic RP discovery, making BSR correct.

Why this answer

Auto-RP and Bootstrap Router (BSR) are the two primary mechanisms for dynamic RP discovery in PIM-SM. Auto-RP is Cisco proprietary and uses a mapping agent, while BSR is an open standard. Both allow routers to automatically learn which RP to use for multicast groups, eliminating the need for manual configuration on every router.

These methods enhance scalability and simplify multicast network management.

Exam trap

The trap here is confusing RP redundancy mechanisms like Anycast RP and MSDP with dynamic RP discovery, which are distinct functions.

212
MCQmedium

A network engineer runs the following command on Router R3: R3# show interfaces GigabitEthernet0/0 GigabitEthernet0/0 is up, line protocol is up Hardware is ISR4331-2x1GE, address is aabb.cc00.0300 (bia aabb.cc00.0300) Internet address is 10.0.0.3/24 MTU 1500 bytes, BW 1000000 Kbit/sec, DLY 10 usec, reliability 255/255, txload 1/255, rxload 1/255 Encapsulation ARPA, loopback not set Keepalive set (10 sec) Full-duplex, 1000Mb/s, media type is RJ45 output flow-control is unsupported, input flow-control is unsupported ARP type: ARPA, ARP Timeout 04:00:00 Last input 00:00:00, output 00:00:00, output hang never Last clearing of "show interface" counters never Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue: 0/40 (size/max) 5 minute input rate 1000 bits/sec, 2 packets/sec 5 minute output rate 2000 bits/sec, 3 packets/sec 12345 packets input, 1234567 bytes, 0 no buffer Received 123 broadcasts (0 IP multicasts) 0 runts, 0 giants, 0 throttles 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored 0 watchdog, 0 multicast, 0 pause input 12345 packets output, 2345678 bytes, 0 underruns 0 output errors, 0 collisions, 1 interface resets 0 unknown protocol drops 0 babbles, 0 late collision, 0 deferred 0 lost carrier, 0 no carrier, 0 pause output 0 output buffer failures, 0 output buffers swapped out Based on this output, what can be concluded?

A.The interface has experienced a hardware failure.
B.The interface has had one reset since the last counter clear.
C.The interface is experiencing high input errors.
D.The interface is operating at half-duplex.
AnswerB

This is correct because the output explicitly displays '1 interface resets' under the interface counters. In Cisco IOS, the 'interface resets' counter increments each time the interface is reset, typically due to a line protocol drop, a manual admin down/up toggle, or a media renegotiation. The value of '1' indicates exactly one reset event has occurred since the last time the 'clear counters' command was issued on this interface. This is a direct, factual reading of the counter, and interpreting it as 'one reset since the last counter clear' is the most accurate and literal interpretation of the given output.

Why this answer

The output shows '1 interface resets' under the output statistics. Interface resets occur when the interface is reset by software or hardware, often due to a configuration change, a cable issue, or a temporary link flap. Since the last clearing of counters, this single reset indicates a past event, not a current hardware failure.

Exam trap

Cisco often tests the distinction between 'interface resets' and 'input errors' — candidates may mistakenly assume any non-zero counter indicates a problem, but a single reset is normal and does not imply hardware failure or high errors.

How to eliminate wrong answers

Option A is wrong because there are no input errors, CRC errors, or other signs of hardware failure; the interface is up/up with no errors. Option C is wrong because the output explicitly shows '0 input errors' and '0 CRC', indicating no high input errors. Option D is wrong because the interface is operating at 'Full-duplex, 1000Mb/s', not half-duplex.

213
MCQmedium

interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip ospf network non-broadcast ip ospf priority 1 ! router ospf 1 network 192.168.1.0 0.0.0.255 area 0 neighbor 192.168.1.2 What is the effect of this configuration?

A.OSPF will form an adjacency with 192.168.1.2 and elect a DR/BDR based on priority.
B.OSPF will form an adjacency with 192.168.1.2 without DR/BDR election.
C.OSPF will automatically discover neighbors via multicast and form adjacencies.
D.OSPF will use a 30-second hello interval and suppress DR/BDR election.
AnswerA

On a non-broadcast (NBMA) OSPF network type, the link is treated as a multi-access segment, so after the neighbor 192.168.1.2 is manually configured, OSPF forms a full adjacency and performs a DR/BDR election. The router with the highest interface priority (then highest router ID) becomes DR, and election occurs only among routers with priority greater than 0. This is correct because non-broadcast network type requires unicast neighbor configuration and still has multi-access semantics.

Why this answer

The configuration sets the OSPF network type to non-broadcast on the interface, which requires manual neighbor statements (neighbor 192.168.1.2) to form adjacencies. In non-broadcast mode, OSPF uses unicast instead of multicast, but it still performs DR/BDR election because the network type is considered multi-access (like Frame Relay). The ip ospf priority 1 command influences the election, so the correct answer is that OSPF will form an adjacency with 192.168.1.2 and elect a DR/BDR based on priority.

Exam trap

Cisco often tests the misconception that 'non-broadcast' means 'no DR/BDR election,' but the trap here is that non-broadcast is still a multi-access network type and requires DR/BDR election, unlike point-to-point or point-to-multipoint network types.

How to eliminate wrong answers

Option B is wrong because non-broadcast OSPF networks are multi-access and do require DR/BDR election; only point-to-point or point-to-multipoint network types suppress the election. Option C is wrong because non-broadcast networks do not use multicast (224.0.0.5/224.0.0.6) for neighbor discovery; they rely on manually configured neighbor statements. Option D is wrong because the hello interval for non-broadcast networks is 30 seconds by default, but DR/BDR election is not suppressed; it is still performed, and the 30-second hello is not the primary effect described in the question.

214
MCQmedium

A network administrator is analyzing syslog messages from a Cisco Catalyst switch and notices the message %SW_MATM-4-MACFLAP_NOTIF: Host 0000.1111.2222 in vlan 10 is flapping between port Gi1/0/1 and port Gi1/0/2. What is the most likely cause of this message?

A.A loop exists in VLAN 10 due to a misconfigured spanning tree.
B.A device with MAC address 0000.1111.2222 is connected to both Gi1/0/1 and Gi1/0/2, possibly via a loop or a dual-homed connection.
C.The switch has a software bug causing incorrect MAC address learning.
D.The MAC address 0000.1111.2222 is configured as a static MAC address on two different ports.
AnswerB

This is the most likely cause. The switch is learning the same MAC address on two different ports, which indicates the device is either connected to both ports (e.g., via a loop or a misconfigured NIC teaming) or there is a loop in the network. The switch detects the flapping and generates the syslog message to alert the administrator.

Why this answer

The %SW_MATM-4-MACFLAP_NOTIF message indicates that the switch has detected the same MAC address being learned on two different ports within a short period. This is most commonly caused by a loop or a device connected to multiple ports, leading to inconsistent MAC address table entries. The administrator should investigate the physical connections and spanning tree topology.

Exam trap

The trap here is immediately blaming spanning tree without considering that a dual-homed device or duplicate MAC can also cause the same symptom.

215
Multi-Selecthard

A network security engineer is deploying Cisco TrustSec in a campus network. The engineer wants to implement Security Group Tags (SGTs) and enforce policies using a Cisco Catalyst switch as an enforcement point. Which two statements are true regarding SGT propagation and enforcement in this scenario? (Choose two.)

Select 2 answers
A.SGTs are always carried in the IP header as a DSCP value to ensure end-to-end propagation.
B.SGTs can be propagated through a Layer 2 trunk using Cisco Metadata (CMD) or inline tagging.
C.Enforcement devices must be configured with the 'cts manual' command on trunk interfaces to enable SGT propagation.
D.The Security Group Access Control List (SGACL) is downloaded from Cisco ISE to the enforcement device to define permitted traffic between SGTs.
E.SGT enforcement requires that all switches in the path support Cisco TrustSec and have SGT propagation enabled.
AnswersB, D

Cisco TrustSec supports SGT propagation through Layer 2 trunks using either Cisco Metadata (CMD) or inline tagging (also known as SGT Exchange Protocol or SXP for Layer 3). Inline tagging embeds the SGT in the Ethernet frame, allowing switches to enforce policies based on the tag without needing to look up the source identity.

Why this answer

SGTs can be propagated through Layer 2 trunks using Cisco Metadata (CMD) or inline tagging, and SGACLs are downloaded from Cisco ISE to enforcement devices to define permitted traffic between SGTs. These two statements are true. Not all switches need to support TrustSec for enforcement, SGTs are not carried in the IP header as DSCP, and 'cts manual' is not the primary command for trunk propagation.

Exam trap

The trap here is assuming that SGTs are carried in the IP header or that all switches must support TrustSec, when in fact they can be propagated via inline tagging or SXP and enforcement can be centralized.

216
MCQhard

An enterprise network uses 802.1X for wired access. The authentication server is a Cisco ISE. Recently, some Windows 10 clients fail to authenticate, while others succeed. The engineer checks the switch configuration and finds 'authentication port-control auto' and 'dot1x pae authenticator' are configured. The failing clients show 'EAP failure' in the logs. The engineer suspects a mismatch in EAP method. Which EAP method is most likely causing the issue if the ISE is configured to require EAP-TLS but the Windows clients are configured for PEAP-MSCHAPv2?

A.EAP-TLS requires a client certificate, which the Windows clients do not have.
B.EAP-FAST requires a PAC file that the Windows clients do not have.
C.LEAP uses a shared secret that is not configured on the clients.
D.EAP-MD5 does not support mutual authentication, causing the failure.
AnswerA

EAP-TLS is a certificate-based mutual authentication method: the server presents a certificate and the client must also present a valid client certificate. Since the Windows clients have not been issued client certificates, the client cannot complete the TLS handshake, so authentication fails despite the server being configured for EAP-TLS. This is the root cause described in the scenario.

Why this answer

EAP-TLS requires a client-side certificate for authentication. If the ISE is configured to require EAP-TLS but the Windows 10 clients are configured for PEAP-MSCHAPv2, the clients will not present a certificate, causing the ISE to send an EAP failure. This mismatch in EAP method explains why only clients without the proper certificate configuration fail.

Exam trap

Cisco often tests the concept that EAP-TLS is the only EAP method that requires a client certificate by default, and candidates may confuse it with PEAP or EAP-FAST, which do not require client certificates for the inner authentication.

How to eliminate wrong answers

Option B is wrong because EAP-FAST uses a PAC (Protected Access Credential) file, but the scenario describes a mismatch between EAP-TLS and PEAP-MSCHAPv2, not EAP-FAST; the clients are not configured for EAP-FAST, so a missing PAC is irrelevant. Option C is wrong because LEAP is a Cisco-proprietary, legacy EAP method that uses a shared secret (usually a password), but the issue is a method mismatch between EAP-TLS and PEAP-MSCHAPv2, not a missing LEAP shared secret. Option D is wrong because EAP-MD5 does not support mutual authentication (only server-side authentication), but the failure is due to the client not having a certificate for EAP-TLS, not because of mutual authentication requirements; EAP-MD5 is not involved in this scenario.

217
MCQmedium

A network administrator is troubleshooting a network performance issue and suspects a duplex mismatch on a switch port. Which command should be used to verify the duplex settings on a Cisco switch interface?

A.show interfaces GigabitEthernet0/1
B.show running-config interface GigabitEthernet0/1
C.show interfaces status
D.show controllers GigabitEthernet0/1
AnswerA

The show interfaces GigabitEthernet0/1 command displays detailed information about the specified interface, including the configured and operational duplex mode. This is the correct command to verify duplex settings, as it shows both the hardware and configured duplex, and can indicate mismatches.

Why this answer

The show interfaces command provides comprehensive details about an interface, including duplex mode, speed, and error statistics. It shows both the configured duplex and the operational duplex, which is essential for detecting a mismatch. When a duplex mismatch occurs, the interface may show late collisions and other errors.

The other commands either lack detail or do not show operational duplex.

Exam trap

The trap here is relying on the running configuration, which only shows configured duplex and not the actual operational duplex, potentially missing a mismatch.

218
MCQhard

A network engineer is deploying a Cisco SD-WAN solution with two data center sites and 40 branch sites. The design must ensure that traffic from a branch to a critical application in Data Center A always prefers the MPLS transport while using the internet transport only when MPLS latency exceeds a defined threshold. Which Cisco SD-WAN component and feature combination accomplishes this?

A.vSmart controller with application-aware routing policy using SLA classes and preferred transport
B.vManage with CLI templates that set static routes for the application subnet
C.vSmart controller with OSPF cost manipulation on the MPLS transport
D.vBond orchestrator with BFD echo and OMP route redistribution
AnswerA

Application-aware routing policy is created on the vSmart controller and distributed to vEdge or cEdge devices. It defines SLA classes with latency, jitter, and loss thresholds, and can specify a preferred transport such as MPLS. When the SLA is violated, the policy allows failover to the internet transport, exactly matching the requirement to prefer MPLS and fall back on high latency.

Why this answer

Cisco SD-WAN implements application-aware routing policy on the vSmart controller. The policy defines SLA classes with latency, jitter, and loss thresholds and maps applications to preferred transports. When a preferred transport such as MPLS meets the SLA, traffic stays there; when the SLA is violated, the policy permits failover to the internet transport.

The vBond orchestrator, CLI templates, and OSPF cost tuning do not provide this conditional, application-specific behavior.

Exam trap

The trap here is confusing the vBond orchestrator's control-plane role with the vSmart controller's policy and path-selection role.

219
MCQmedium

A network engineer is deploying a Cisco SD-Access fabric. The design requires that endpoints be authenticated and assigned to a VLAN and VRF based on their identity before any traffic is forwarded. Which Cisco SD-Access component is responsible for this function?

A.Cisco Identity Services Engine
B.Fabric border node
C.Fabric control plane node
D.Fabric edge node
AnswerA

Cisco ISE authenticates endpoints using 802.1X, MAC authentication bypass, or web authentication, and returns the VLAN and VRF (or SGT) assignment to the fabric edge node. This is the identity services function that enforces policy before forwarding.

Why this answer

Cisco ISE is the identity services component that authenticates endpoints and returns the VLAN and VRF assignment to the fabric edge node. The edge node then places the endpoint into the correct virtual network and applies group-based policy. Neither the control plane nor border nodes perform authentication or endpoint classification.

Exam trap

The trap here is assuming the fabric edge node or control plane node performs endpoint authentication and VLAN/VRF assignment, when that is actually the role of Cisco ISE.

220
Multi-Selectmedium

Which two statements about VLAN trunking using IEEE 802.1Q are true? (Choose two.)

Select 2 answers
A.The 802.1Q tag includes a 12-bit VLAN ID field.
B.The native VLAN is not tagged on an 802.1Q trunk.
C.The native VLAN must always be VLAN 1.
D.The 802.1Q tag uses a TPID value of 0x88A8.
E.802.1Q supports a maximum of 4096 VLANs.
AnswersA, B

The 802.1Q tag inserts a 12-bit VLAN Identifier field, allowing 4094 usable VLANs per trunk. This directly satisfies the question's requirement by confirming the tag's defined structure, distinguishing it from ISL's 15-bit field and enabling standard-based multi-vendor trunking.

Why this answer

Option A is correct because the IEEE 802.1Q tag contains a 12-bit VLAN Identifier (VID) field, which allows VLAN IDs from 0 to 4095 (with 0 and 4095 reserved), giving 4094 usable VLANs. Option B is correct because on an 802.1Q trunk, frames belonging to the native VLAN are transmitted untagged, while all other VLAN frames carry the 4-byte tag. Option C is incorrect because the native VLAN is configurable and does not have to be VLAN 1, though VLAN 1 is the default.

Option D is incorrect because 802.1Q uses a TPID value of 0x8100, whereas 0x88A8 is associated with 802.1ad (QinQ/Provider Bridging). Option E is incorrect because 802.1Q's 12-bit VID field supports 4096 possible values (4094 usable), not a maximum of 4096 usable VLANs as commonly misstated.

Exam trap

The trap is confusing 802.1Q with 802.1ad (0x88A8 vs 0x8100) and miscounting the VLAN range as 4096 instead of 4094 usable VLANs.

221
MCQeasy

A network administrator is configuring a zone-based firewall on a Cisco IOS XE router. The requirement is to allow HTTP traffic from the INSIDE zone to the OUTSIDE zone while blocking all other traffic initiated from INSIDE. Which action must be taken to define the traffic that is permitted?

A.Configure a route-map that matches HTTP and apply it to the zone pair.
B.Create a class-map that matches HTTP, then reference it in a policy-map and apply the policy-map to the zone pair.
C.Apply an ACL directly to the INSIDE zone interface with the ip access-group command.
D.Enable NAT with an overload statement matching HTTP on the OUTSIDE interface.
AnswerB

Zone-based firewall uses class-maps to identify traffic and policy-maps to define actions. The policy-map is applied to a zone pair (INSIDE to OUTSIDE) with the service-policy command, so only HTTP is permitted while other traffic is dropped by default.

Why this answer

Zone-based firewall policy is built with class-maps for traffic identification and policy-maps for action. The policy-map is attached to a zone pair, and traffic not explicitly permitted is dropped by default, which matches the requirement to allow only HTTP from INSIDE to OUTSIDE.

Exam trap

The trap here is assuming interface ACLs or route-maps control inter-zone traffic, when zone-based firewall requires class-maps and policy-maps on a zone pair.

222
Multi-Selecteasy

Which THREE of the following are components of a Cisco ACI fabric? (Choose three.)

Select 3 answers
A.Firewall
B.Spine switch
C.Router
D.APIC controller
E.Leaf switch
AnswersB, D, E

Spine switches form the fabric backbone.

Why this answer

The spine switch is a core component of a Cisco ACI fabric, forming the spine-leaf topology. Spine switches provide high-speed, non-blocking connectivity between leaf switches and handle all east-west traffic, relying on IS-IS as the routing protocol for fabric discovery and forwarding.

Exam trap

Cisco often tests the distinction between native fabric components (spine, leaf, APIC) and external devices (firewall, router) that can be integrated but are not part of the fabric itself, leading candidates to mistakenly include them as fabric components.

223
Multi-Selecthard

A network engineer is configuring a Cisco IOS router to support NAT overload (PAT) for a small office. The inside network is 192.168.1.0/24, and the outside interface is GigabitEthernet0/1 with IP address 203.0.113.5. The engineer wants to translate all inside addresses to the outside interface address. Which two commands are required to complete this configuration? (Choose two.)

Select 2 answers
A.access-list 1 permit 192.168.1.0 0.0.0.255
B.ip nat outside source list 1 interface GigabitEthernet0/1 overload
C.ip nat inside source list 1 interface GigabitEthernet0/1 overload
D.ip nat inside source static 192.168.1.10 203.0.113.5
E.ip nat inside source list 1 pool MYPOOL overload
AnswersA, C

This access list defines the inside local addresses that are eligible for NAT translation. It permits the entire 192.168.1.0/24 subnet. The NAT command references this list to identify which traffic should be translated. Without this access list, the NAT configuration would not know which addresses to translate. Therefore, it is a required command.

Why this answer

To configure NAT overload (PAT) using the outside interface address, two commands are needed: an access list to define the inside local addresses, and the 'ip nat inside source list' command with the 'overload' keyword referencing that list and the outside interface. The access list permits the 192.168.1.0/24 subnet, and the NAT command translates all permitted addresses to the outside interface's IP. The other options either use a pool, configure the wrong direction, or create a static translation, none of which meet the requirement.

Exam trap

The trap here is confusing the direction of NAT (inside source vs. outside source) or forgetting the 'overload' keyword, which is essential for PAT.

224
MCQmedium

Examine the following SD-WAN configuration on a Cisco vEdge router: vpn 0 interface ge0/0 ip address 10.0.0.1/24 tunnel-interface encapsulation ipsec color public-internet allow-service all ! interface ge0/1 ip address 10.0.0.2/24 tunnel-interface encapsulation ipsec color 3g allow-service all ! Which statement is correct?

A.Both interfaces are in VPN 0, which is the transport VPN, and they will establish tunnels with the vSmart controller.
B.The interfaces are in VPN 0, which is the service VPN, and they will be used for customer traffic.
C.The configuration is invalid because tunnel interfaces cannot have IP addresses in the same VPN.
D.The 'allow-service all' command is not supported on vEdge routers.
AnswerA

In Cisco SD-WAN, VPN 0 is the dedicated transport VPN that carries underlay connectivity and control plane traffic. The two interfaces are placed in this VPN so they can connect to the WAN edge and establish secure tunnels (DTLS/TLS) with the vSmart controller; they are not used for end-user or customer traffic. This placement also allows vBond to orchestrate the overlay, and the interfaces are often physical ports or subinterfaces that provide underlay transport.

Why this answer

VPN 0 is the transport VPN in Cisco SD-WAN, used exclusively for underlay network connectivity and control plane traffic. The two interfaces ge0/0 and ge0/1 are configured as tunnel interfaces with IPsec encapsulation and different colors (public-internet and 3g), which allows them to establish secure DTLS/TLS tunnels to the vSmart controller for orchestration and policy distribution. This is correct because transport VPN interfaces are designed to carry overlay control traffic, not customer data.

Exam trap

Cisco often tests the misconception that VPN 0 is a service VPN or that multiple tunnel interfaces in the same VPN are invalid, but the key is remembering that VPN 0 is strictly the transport underlay and supports multiple colored interfaces for control-plane connectivity.

How to eliminate wrong answers

Option B is wrong because VPN 0 is the transport VPN, not the service VPN; service VPNs are VPN 1-512 and are used for customer traffic. Option C is wrong because the configuration is valid; multiple tunnel interfaces can exist in the same transport VPN with different IP addresses and colors to provide path diversity and redundancy. Option D is wrong because 'allow-service all' is fully supported on vEdge routers to permit all control-plane services (e.g., OMP, BFD, SSH) over the tunnel interface.

225
Drag & Dropmedium

Drag and drop the steps to configure OSPF on a Cisco router in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

OSPF configuration starts with enabling the OSPF process, then defining networks and areas.

Page 2

Page 3 of 26

Page 4