Courseiva

ENCOR 350-401 (350-401) — Questions 226–300

1923 questions total · 26pages · All types, answers revealed

Page 3

Page 4 of 26

Page 5
226
MCQmedium

A network engineer runs the following command on Switch SW3: SW3# show etherchannel summary Flags: D - down P - in port-channel I - stand-alone s - suspended H - Hot-standby (LACP only) R - Layer3 S - Layer2 U - in use N - not in use, no aggregation f - failed to allocate aggregator M - not in use, minimum links not met u - unsuitable for bundling w - waiting to be aggregated d - default port Number of channel-groups in use: 1 Number of aggregators: 1 Group Port-channel Protocol Ports ------+-------------+-----------+--------------------------------------------- 1 Po1(SU) LACP Gi0/1(P) Gi0/2(P) Gi0/3(D) Based on this output, what can be concluded?

A.All three ports are actively participating in the EtherChannel.
B.The EtherChannel is using LACP protocol.
C.The EtherChannel is a Layer 3 port-channel.
D.Port Gi0/3 is in standby mode.
AnswerB

The Protocol column in the output explicitly reads LACP, which stands for Link Aggregation Control Protocol, the IEEE 802.3ad standard for dynamically negotiating EtherChannels. This confirms the channel is formed using LACP rather than static configuration (mode 'on') or Cisco's proprietary PAgP. Additionally, LACP is the only protocol among these that supports the standby state (flag 'H'), reinforcing that this output is from an LACP-based EtherChannel.

Why this answer

The output shows the EtherChannel is using LACP as the protocol, as indicated in the 'Protocol' column. The 'SU' flags on Po1 mean the port-channel is Layer 2 (S) and in use (U), confirming it is active. Therefore, option B is correct because LACP is explicitly listed as the protocol for this EtherChannel.

Exam trap

Cisco often tests the misinterpretation of the 'D' flag as 'down' versus 'standby', leading candidates to incorrectly assume a down port is in a standby or backup role, when in fact it is not participating at all.

How to eliminate wrong answers

Option A is wrong because port Gi0/3 has a flag of 'D' (down), meaning it is not actively participating in the EtherChannel; only Gi0/1 and Gi0/2 are up. Option C is wrong because the 'S' in 'SU' indicates Layer 2, not Layer 3 (which would be 'RU'). Option D is wrong because the 'D' flag on Gi0/3 means 'down', not 'Hot-standby' (which would be 'H' in LACP); standby mode is not supported in this context.

227
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip eigrp interfaces detail EIGRP-IPv4 Interfaces for AS(100) Interface: GigabitEthernet0/0 Mtu: 1500, Bandwidth: 1000000 Kbit, Delay: 100 microseconds Reliability: 255/255, Load: 1/255, Min MTU: 1500 Hello interval: 5 sec, Hold time: 15 sec Next hello in: 3 secs Passive interface: No Split horizon: Enabled Authentication: None Neighbor count: 1 Interface: GigabitEthernet0/1 Mtu: 1500, Bandwidth: 100000 Kbit, Delay: 1000 microseconds Reliability: 255/255, Load: 1/255, Min MTU: 1500 Hello interval: 5 sec, Hold time: 15 sec Next hello in: 1 secs Passive interface: No Split horizon: Enabled Authentication: None Neighbor count: 1 Based on this output, what can be concluded?

A.Both interfaces have the same metric weight for bandwidth and delay.
B.GigabitEthernet0/1 will have a higher EIGRP metric than GigabitEthernet0/0 for the same prefix.
C.Interface Gi0/1 is configured as a passive interface.
D.EIGRP authentication is enabled on both interfaces.
AnswerB

EIGRP computes its composite metric using the minimum bandwidth along the path and the cumulative delay; lower bandwidth and higher delay both increase the metric value. Since Gi0/1's interface statistics show a less favorable combination of bandwidth and delay compared with Gi0/0, the same prefix learned via Gi0/1 would receive a numerically higher metric. This makes Gi0/1 the less preferred path for that prefix under equal-cost conditions.

Why this answer

EIGRP uses the composite metric formula: metric = (K1 * bandwidth + (K2 * bandwidth) / (256 - load) + K3 * delay) * (K5 / (reliability + K4)). With default K values (K1=K3=1, others=0), the metric simplifies to bandwidth + delay. Gi0/0 has bandwidth 1,000,000 Kbit and delay 100 microseconds, while Gi0/1 has bandwidth 100,000 Kbit and delay 1000 microseconds.

The lower bandwidth and higher delay on Gi0/1 result in a higher metric for the same prefix.

Exam trap

Cisco often tests the misconception that the 'show ip eigrp interfaces detail' command displays the K values or metric weights, when in fact it only shows per-interface parameters like bandwidth and delay, and the K values must be verified separately with 'show ip protocols'.

How to eliminate wrong answers

Option A is wrong because the metric weights (K values) are not shown in the output; the command only displays interface-specific parameters like bandwidth and delay, not the K values themselves. Option C is wrong because the output explicitly shows 'Passive interface: No' for Gi0/1, meaning it is not configured as a passive interface. Option D is wrong because the output shows 'Authentication: None' for both interfaces, indicating no EIGRP authentication is enabled.

228
MCQhard

A healthcare provider runs a Python script that issues a RESTCONF PATCH to a Cisco IOS XE switch to modify an interface description. The device returns HTTP 400 with an error-tag of 'invalid-value'. The JSON body is syntactically valid and the URI targets the correct interface. Which action most directly resolves this error?

A.Increase the RESTCONF request timeout on the client because the switch is slow to apply configuration changes.
B.Correct the payload so the description node matches the YANG model's expected type and namespace, then resend the PATCH.
C.Change the HTTP method from PATCH to GET and re-read the interface container before writing.
D.Add a Content-Type header of application/yang-data+xml while keeping the existing JSON body unchanged.
AnswerB

An 'invalid-value' error-tag means the server rejected a data value in the payload, usually because it violates the YANG leaf's type, length, or pattern constraints, or because the leaf is placed under the wrong namespace. Aligning the JSON structure and value with the model definition resolves the rejection. The URI and HTTP method are already correct in the scenario, so the payload content is the remaining cause.

Why this answer

RESTCONF error-tags are diagnostic: 'invalid-value' points to a data value that violates the YANG model's constraints, such as a wrong type, an out-of-range number, or a leaf placed under the wrong namespace. Since the URI and method are correct and the JSON is syntactically valid, the remaining cause is the payload content. Correcting the value and its model placement makes the PATCH succeed.

Exam trap

The trap here is treating any HTTP 400 as a URL problem, when the error-tag 'invalid-value' specifically implicates the payload content.

229
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip eigrp topology EIGRP-IPv4 Topology Table for AS(100)/ID(192.168.1.1) Codes: P - Passive, A - Active, U - Update, Q - Query, R - Reply, r - reply Status, s - sia Status P 10.1.1.0/24, 1 successors, FD is 1310720 via 192.168.1.2 (1310720/1310720), GigabitEthernet0/0 P 10.2.2.0/24, 1 successors, FD is 1310720 via 192.168.1.2 (1310720/1310720), GigabitEthernet0/0 P 10.3.3.0/24, 1 successors, FD is 1310720 via 192.168.1.2 (1310720/1310720), GigabitEthernet0/0 Based on this output, what can be concluded?

A.All routes have a feasible successor.
B.The routes are in Active state, meaning the router is querying for alternate paths.
C.Each route has exactly one successor and no feasible successor.
D.The router is using EIGRP stub routing.
AnswerC

Each destination in the output has exactly one successor as shown by the single 'via' entry on the first line of each topology entry. A feasible successor would require an alternate next-hop route with RD < FD, but here the RD equals the FD for every route, making the feasibility condition false. Therefore, exactly one successor and zero feasible successors is the correct interpretation of the output.

Why this answer

The output shows each route with a code 'P' (Passive) and exactly one successor, with no feasible successor listed. In EIGRP, a feasible successor is only present if there is a backup route that satisfies the feasibility condition (reported distance < feasible distance). Since only one next-hop is shown per route and no additional entries exist, there is no feasible successor.

Option C correctly identifies this.

Exam trap

Cisco often tests the distinction between Passive and Active states in EIGRP topology table output, where candidates mistakenly think 'P' stands for 'Primary' or 'Path' instead of 'Passive', leading them to misinterpret the route state and miss the absence of feasible successors.

How to eliminate wrong answers

Option A is wrong because the output does not show any feasible successor; each route has only one successor and no backup path, so the statement 'All routes have a feasible successor' is false. Option B is wrong because the routes are in Passive state (code 'P'), not Active; Active state would indicate the router is actively querying neighbors for alternate paths, which is not the case here. Option D is wrong because the output does not indicate stub routing; EIGRP stub routing is configured with the 'eigrp stub' command and would not be evident from the topology table alone, and the routes are normal learned routes, not stub-specific behavior.

230
MCQmedium

In Cisco SD-WAN, what is the maximum number of TLOCs that can be associated with a single OMP route?

A.8
B.4
C.16
D.Unlimited
AnswerA

In Cisco SD-WAN, the OMP route's TLOC attribute is a fixed-size list that supports a maximum of 8 TLOCs. This allows up to 8 distinct paths for load balancing or failover per route. Adding more paths would require multiple OMP routes or policy-based path selection, but the protocol hard-codes the per-route limit.

Why this answer

In Cisco SD-WAN, a single OMP route can have up to 8 TLOCs (Transport Locations) associated with it. This limit is enforced by the OMP protocol to balance path diversity and control-plane scalability, ensuring that the vSmart controller does not advertise an excessive number of next-hop paths for a single prefix.

Exam trap

Cisco often tests the 8-TLOC limit to catch candidates who confuse OMP's TLOC-per-route limit with the 16-path limit common in BGP or with the default 4-path limit in some IGP protocols.

How to eliminate wrong answers

Option B (4) is wrong because the maximum is 8, not 4; this misconception may arise from the default number of TLOCs per OMP route in some older configurations, but the hard limit is 8. Option C (16) is wrong because 16 is the maximum number of OMP paths per prefix in some other routing protocols (e.g., BGP), but Cisco SD-WAN OMP specifically caps TLOCs per route at 8. Option D (Unlimited) is wrong because OMP has a fixed limit of 8 TLOCs per route to prevent control-plane overload; unlimited TLOCs would allow unbounded route churn and memory consumption on vSmart and vEdge/cEdge devices.

231
Drag & Dropmedium

Drag and drop the steps of configuring a standard ACL for traffic filtering on a Cisco IOS router into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Standard ACLs are configured by first entering global configuration mode, then defining ACL entries with permit or deny statements, where each entry specifies a source IP and wildcard mask. After defining all entries, the ACL is applied to an interface in the inbound or outbound direction. Finally, verification with 'show access-lists' confirms the ACL is active and shows hit counts.

232
MCQmedium

A network engineer is deploying virtual switching for a hypervisor host. The requirement is that virtual machines on the same host can communicate with each other using Layer 2 frame forwarding without any traffic leaving the physical NIC, and that VLAN tags be enforced per port profile. Which Cisco technology should be used to meet these requirements?

A.Cisco Nexus 1000V Virtual Ethernet Module (VEM)
B.Cisco Adaptive Security Virtual Appliance (ASAv)
C.Cisco Virtual Wide Area Application Services (vWAAS)
D.Cisco Cloud Services Router 1000V (CSR 1000V)
AnswerA

The Nexus 1000V VEM runs inside the hypervisor and performs local Layer 2 forwarding between virtual machines on the same host, so intra-host traffic never traverses the physical uplink. It also enforces port profiles and VLAN policies pushed from the Virtual Supervisor Module, which matches both stated requirements.

Why this answer

A virtual switch embedded in the hypervisor is needed so that same-host virtual machines exchange frames locally while still honoring VLAN and policy configuration. The Nexus 1000V VEM provides exactly this distributed virtual switching function, with the VSM supplying policy. The other listed products are virtual firewall, router and WAN optimization appliances, none of which perform virtual machine Layer 2 switching.

Exam trap

The trap here is assuming any virtual appliance that runs on a hypervisor can also switch traffic between virtual machines on that host.

233
MCQeasy

What is the default port used by TACACS+ for communication?

A.49
B.1812
C.1645
D.389
AnswerA

Port 49 is the IANA-assigned well-known port for TACACS+ (Terminal Access Controller Access-Control System Plus). TACACS+ uses TCP port 49 for reliable, connection-oriented transport, ensuring delivery of control messages between the network device and the AAA server. The Cisco implementation of TACACS+ defaults to TCP port 49, making this the correct answer.

Why this answer

TACACS+ uses TCP port 49 by default for communication between the Network Access Server (NAS) and the TACACS+ server. This port is defined in the TACACS+ protocol specification (RFC 1492) and is the well-known port reserved for the TACACS+ authentication, authorization, and accounting (AAA) service. Unlike RADIUS, which uses UDP, TACACS+ relies on TCP for reliable, connection-oriented transport.

Exam trap

Cisco often tests the default port for TACACS+ (49) versus RADIUS (1812/1645) to catch candidates who confuse the two protocols, especially since both are used for AAA but operate on different transport layers and ports.

How to eliminate wrong answers

Option B is wrong because port 1812 is the default port for RADIUS authentication (UDP), not TACACS+. Option C is wrong because port 1645 is an older, deprecated port historically used by RADIUS (before RFC 2865 standardized port 1812), and is not associated with TACACS+. Option D is wrong because port 389 is the default port for LDAP (Lightweight Directory Access Protocol), used for directory services, not for TACACS+ AAA communication.

234
Matchingmedium

Drag and drop each EAP method on the left to its matching authentication type on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Mutual certificate-based authentication

Server-side certificate with MSCHAPv2 inner method

Protected Access Credential (PAC) for secure tunneling

Simple username and password hash (no mutual authentication)

Generic Token Card for one-time password or certificate

Why these pairings

EAP-TLS uses certificates, PEAP uses server certificate with inner MSCHAPv2, EAP-FAST uses a PAC, and EAP-MD5 uses simple password hash.

235
Drag & Dropmedium

Drag and drop the steps to configure a site-to-site IPsec VPN on a Cisco router in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

IPsec VPN setup requires IKE phase 1, then phase 2 (transform set and crypto map).

236
MCQmedium

A network engineer is building a Python script that must retrieve the operational state of all interfaces from a Cisco IOS XE device using RESTCONF. The engineer sends a GET request to https://10.1.1.1/restconf/data/ietf-interfaces:interfaces-state and receives an HTTP 401 Unauthorized response. The device is reachable, RESTCONF is enabled, and the correct credentials are being used in the request. What is the most likely cause of the 401 response?

A.The device's RESTCONF service is configured to use NETCONF over SSH instead of HTTPS, so the request must be sent to port 830.
B.The RESTCONF API requires the Accept header to be set to application/yang-data+json.
C.The HTTP Basic Authentication credentials are not being sent because the Authorization header is missing or malformed.
D.The URL path should be /restconf/data/ietf-interfaces:interfaces instead of interfaces-state.
AnswerC

A 401 Unauthorized response indicates the server did not receive valid authentication credentials. RESTCONF over HTTPS typically uses HTTP Basic Authentication, which requires a properly formatted Authorization header containing base64-encoded username and password. If the script omits this header or encodes it incorrectly, the device rejects the request with 401 even though the credentials themselves are valid.

Why this answer

An HTTP 401 Unauthorized response is returned when authentication credentials are missing or invalid. With RESTCONF on Cisco IOS XE, authentication is performed using HTTP Basic Authentication, so the request must include a correctly formed Authorization header. Since the credentials are known to be correct, the failure must stem from the header not being transmitted or being malformed, which is a common scripting oversight.

Exam trap

The trap here is assuming a 401 error is caused by wrong credentials rather than by the Authorization header being absent or incorrectly formatted in the HTTP request.

237
MCQeasy

A network administrator is configuring a new Cisco Catalyst switch and needs to assign a management IP address to VLAN 1. Which command is used to enter the interface configuration mode for VLAN 1?

A.interface fastethernet 0/1
B.interface vlan 1
C.interface range vlan 1
D.vlan 1
AnswerB

The command 'interface vlan 1' is used to create or enter the configuration mode for the switched virtual interface (SVI) associated with VLAN 1. This allows the administrator to assign an IP address to the VLAN interface, enabling management access to the switch. This is the correct command to configure a management IP on VLAN 1.

Why this answer

To assign a management IP address to VLAN 1 on a Cisco switch, you must configure the switched virtual interface (SVI) for VLAN 1. The command 'interface vlan 1' enters interface configuration mode for that SVI, where you can then use the 'ip address' command to assign an IP address and enable the interface with 'no shutdown'.

Exam trap

The trap here is confusing the command to create a VLAN (vlan 1) with the command to configure its Layer 3 interface (interface vlan 1). Creating a VLAN does not automatically create an SVI.

238
MCQhard

A network engineer is deploying Cisco DNA Center in a brownfield network. The engineer wants to use DNA Center to automate the configuration of QoS policies across all access switches. After discovering the devices and adding them to Inventory, the engineer creates a QoS policy and assigns it to a site. However, when attempting to provision, DNA Center reports that the devices are in 'Compliance Error' state. What is the most likely reason?

A.The devices have existing QoS configurations that conflict with the new policy.
B.The devices are not running a supported IOS-XE version for QoS automation.
C.The DNA Center appliance does not have enough storage to process the QoS policy.
D.The QoS policy was created with an invalid DSCP value.
AnswerA

DNA Center compares the intended QoS configuration against the running configuration on each device. Pre-existing QoS class maps, policy maps or service policies that differ from the template cause provisioning to fail with Compliance Error, so the conflicting configuration must be reconciled first.

Why this answer

In Cisco DNA Center, when a device is provisioned with a configuration template or policy (like a QoS policy assigned at a site), the device enters 'Compliance Error' if its running configuration does not match the intended configuration. In a brownfield network, pre-existing QoS configurations on the access switches commonly conflict with the newly pushed policy, causing the mismatch. DNA Center flags this rather than silently overwriting, which is why the engineer sees the error.

Exam trap

The trap is assuming 'Compliance Error' means a version or hardware problem, when in DNA Center it almost always means the running config diverges from the intended policy — often due to pre-existing brownfield configuration.

How to eliminate wrong answers

Option B is wrong because an unsupported IOS-XE version would typically surface as a software-image or device-support issue, not a QoS-specific compliance error after the policy was already created and assigned. Option C is wrong because appliance storage has no bearing on per-device configuration compliance state. Option D is wrong because an invalid DSCP value would be rejected at policy creation time, not manifest as a device compliance error during provisioning.

239
Drag & Dropmedium

Drag and drop the steps of DSCP re-marking at enterprise WAN edge into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

At the enterprise WAN edge, traffic is first classified based on existing markings or other criteria. Then a policy-map is created to set the new DSCP value. The policy is applied outbound on the WAN interface.

The router re-marks packets as they exit. Finally, the new DSCP value is verified using show commands.

240
MCQhard

A network engineer is troubleshooting a Cisco Nexus 9000 switch configured with VXLAN EVPN. The engineer notices that the switch is not learning remote MAC addresses from the EVPN control plane. The underlay is OSPF, and BGP EVPN peering is established with the spine switches. Which command should the engineer use to verify that the switch is receiving EVPN Type-2 routes?

A.show ip route vrf all
B.show l2route evpn mac all
C.show nve peers
D.show bgp l2vpn evpn
AnswerD

The command 'show bgp l2vpn evpn' displays the BGP EVPN table, including Type-2 routes (MAC/IP advertisement routes). If the switch is not receiving Type-2 routes, this command will show an empty table or missing entries for the expected MAC addresses. It is the primary command to verify EVPN route reception and is essential for troubleshooting control-plane learning.

Why this answer

To verify that the switch is receiving EVPN Type-2 routes, the engineer should use 'show bgp l2vpn evpn'. This command displays the BGP EVPN table, where Type-2 routes appear as '[2]:[MAC/IP]' entries. If these routes are missing, the switch will not learn remote MAC addresses via EVPN.

Checking the BGP EVPN table is the first step in troubleshooting control-plane learning issues.

Exam trap

The trap here is confusing data-plane verification commands like 'show nve peers' with control-plane verification commands like 'show bgp l2vpn evpn', or looking at the L2 route table instead of the BGP table.

241
MCQeasy

An engineer is configuring multicast on a Cisco router. The router receives multicast traffic from a source on interface GigabitEthernet0/0 and needs to forward it to receivers on interface GigabitEthernet0/1. The engineer enables PIM sparse mode on both interfaces and configures a static RP. However, the router does not create a multicast routing entry for the (S,G) pair. What is the most likely missing configuration?

A.The global command 'ip multicast-routing' is not configured.
B.The interface GigabitEthernet0/0 is not configured with an IP address.
C.The RP address is not reachable from the router.
D.The router is not configured as a candidate RP.
AnswerA

The global command 'ip multicast-routing' is a prerequisite for any multicast forwarding on a Cisco router. Without this command, the router does not build the multicast routing table (mroute) nor run Protocol Independent Multicast (PIM), so even if packets arrive on GigabitEthernet0/0, they are treated as ordinary unicast traffic and no (S,G) or (*,G) entry is created. This is the root cause because all other configuration—interface IP addresses, PIM, and RP knowledge—is irrelevant until multicast routing is enabled.

Why this answer

The most likely missing configuration is the global command 'ip multicast-routing'. Without this command, the router cannot enable multicast forwarding or build multicast routing tables, regardless of PIM configuration on interfaces or static RP definition. PIM sparse mode and RP configuration are dependent on multicast routing being globally enabled first.

Exam trap

Cisco often tests the prerequisite of 'ip multicast-routing' as a hidden requirement, leading candidates to focus on PIM modes or RP configuration while overlooking the fundamental global enablement command.

How to eliminate wrong answers

Option B is wrong because an interface without an IP address cannot participate in routing, but the scenario states the router receives multicast traffic on GigabitEthernet0/0, implying it has an IP address; the issue is the lack of multicast routing enablement, not interface addressing. Option C is wrong because while RP reachability is necessary for PIM sparse mode operations, the router would still create a multicast routing entry for the (S,G) pair if multicast routing were enabled; unreachable RP would cause registration issues but not prevent the initial entry creation. Option D is wrong because a static RP does not require the router to be a candidate RP; candidate RP is used for dynamic RP discovery (e.g., Auto-RP or BSR), but static RP configuration on the router is sufficient for PIM sparse mode when multicast routing is enabled.

242
Matchingmedium

Drag and drop each 802.11 standard on the left to its matching frequency band and maximum speed on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

2.4 GHz, 11 Mbps

5 GHz, 54 Mbps

2.4 GHz, 54 Mbps

2.4/5 GHz, 600 Mbps

5 GHz, 6.9 Gbps

Why these pairings

802.11b operates at 2.4 GHz with 11 Mbps; 802.11a at 5 GHz with 54 Mbps; 802.11g at 2.4 GHz with 54 Mbps; 802.11n can use both 2.4 and 5 GHz with 600 Mbps; 802.11ac operates only at 5 GHz with up to 6.9 Gbps.

243
Multi-Selectmedium

Which two statements about REST API HTTP methods are true? (Choose two.)

Select 2 answers
A.GET is a safe method that must not change server state.
B.POST is idempotent, meaning multiple identical requests have the same effect.
C.DELETE is non-idempotent and each request may have a different outcome.
D.PUT is idempotent and replaces the entire resource at the target URI.
E.PATCH is always idempotent because it uses a patch document.
AnswersA, D

GET is defined as safe under HTTP semantics, meaning it must not alter server state; it is intended solely for retrieval. This satisfies the stem's requirement for a true statement about REST methods, since safety distinguishes GET from state-changing methods such as POST, PUT, PATCH and DELETE.

Why this answer

Option A is correct because GET is defined by the HTTP specification as a safe method, meaning it is intended only for retrieval and must not alter server state. Option D is correct because PUT is idempotent—repeating the same request yields the same result—and it replaces the entire resource representation at the target URI. Option B is wrong because POST is not idempotent; multiple identical POSTs can create multiple resources or trigger repeated side effects.

Option C is wrong because DELETE is idempotent, since deleting an already-deleted resource leaves the server in the same state. Option E is wrong because PATCH is not guaranteed to be idempotent; its effect depends on the patch document and the resource's current state.

Exam trap

350-401 often tests the safe-versus-idempotent distinction, tricking candidates into assuming POST is idempotent or that DELETE is not — the key is that idempotency concerns server state, not response codes.

244
MCQmedium

A network engineer is designing a QoS policy for a WAN edge router. Voice traffic must be serviced with strict priority and guaranteed low latency, while a policer must limit voice to 30 percent of the interface bandwidth to prevent starvation of other queues. Which queuing mechanism should the engineer configure?

A.First-In, First-Out (FIFO) queuing on the WAN interface
B.Class-Based Weighted Fair Queuing (CBWFQ) with a bandwidth guarantee
C.Weighted Random Early Detection (WRED) on the voice class
D.Low Latency Queuing (LLQ) with a priority policer
AnswerD

Low Latency Queuing combines a strict priority queue for voice with a policer that caps the priority traffic at a configured rate, such as 30 percent of interface bandwidth. This ensures voice is serviced first with minimal delay while preventing the priority class from starving other queues if voice traffic exceeds the limit, exactly matching the design requirement.

Why this answer

Low Latency Queuing is the correct choice because it creates a strict priority queue for voice while applying a policer that caps the priority class at a configured rate, such as 30 percent of interface bandwidth. This gives voice minimal delay and jitter while preventing it from consuming all bandwidth. CBWFQ lacks strict priority, WRED is a drop mechanism, and FIFO offers no prioritization or policing.

Exam trap

The trap here is assuming that any bandwidth-guaranteeing queuing method provides strict priority, when only LLQ combines a strict priority queue with a policer to protect other traffic classes from starvation.

245
Matchingmedium

Drag and drop each BGP message type on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Establishes BGP peering parameters

Advertises or withdraws prefixes

Reports error conditions

Maintains session liveness

Requests re-advertisement of routes

Why these pairings

OPEN establishes peering; UPDATE advertises/withdraws routes; NOTIFICATION signals errors; KEEPALIVE maintains session; ROUTE-REFRESH requests re-advertisement.

246
MCQhard

A network engineer runs the following command on Switch SW7: SW7# show monitor session 7 Session 7 --------- Type : Local Session Source Ports : Both : Gi1/0/1 Destination Ports : Gi1/0/20 Encapsulation : Native Ingress : Enabled Based on this output, what can be concluded?

A.The destination port Gi1/0/20 can forward incoming traffic in addition to sending mirrored traffic.
B.This is an RSPAN session with a remote VLAN.
C.Only egress traffic from Gi1/0/1 is mirrored.
D.The destination port is configured to block all incoming traffic.
AnswerA

Ingress is enabled on the destination port, so Gi1/0/20 still forwards its own incoming traffic while also transmitting the mirrored copy of Gi1/0/1. Without ingress, the port would drop all normal received frames and act purely as a monitor output. This satisfies the stem's question about the port's forwarding behaviour.

Why this answer

The output shows a local SPAN session with the destination port Gi1/0/20 configured with 'Ingress : Enabled'. This means the destination port can forward incoming traffic (traffic received on Gi1/0/20) in addition to sending mirrored traffic from the source port Gi1/0/1. By default, a SPAN destination port drops all incoming traffic, but enabling ingress allows it to process and forward incoming frames.

Exam trap

Cisco often tests the misconception that a SPAN destination port always drops all incoming traffic, but the 'Ingress : Enabled' setting explicitly overrides that default behavior, making it a common trap for candidates who overlook the ingress field in the output.

How to eliminate wrong answers

Option B is wrong because the session type is explicitly 'Local Session', not RSPAN; RSPAN uses a remote VLAN to transport mirrored traffic to a different switch, which is not indicated here. Option C is wrong because the source port is configured with 'Both', meaning both ingress and egress traffic from Gi1/0/1 are mirrored, not only egress. Option D is wrong because 'Ingress : Enabled' indicates the destination port is configured to accept incoming traffic, not block it; blocking incoming traffic is the default behavior when ingress is disabled.

247
Multi-Selecteasy

Which two statements about IP SLA probe scheduling and operation states are true? (Choose two.)

Select 2 answers
A.The 'schedule' command with 'start-time now' causes the IP SLA operation to begin immediately.
B.An IP SLA operation in the 'active' state indicates that the probe is currently being sent and responses are being collected.
C.The 'life' parameter in the IP SLA configuration sets the frequency at which probes are sent.
D.An IP SLA operation remains in the 'pending' state until the 'start-time' is reached, even if the configuration is complete.
E.The 'schedule' command with 'life forever' causes the operation to stop after a single probe.
AnswersA, B

Correct because 'start-time now' starts the operation as soon as the command is entered.

Why this answer

Option A is correct because the 'schedule' command with 'start-time now' instructs the IP SLA operation to begin executing immediately upon configuration, rather than waiting for a future start time. Option B is correct because the 'active' state of an IP SLA operation means the probe is currently running—packets are being sent and responses are being collected according to the configured frequency and timeout. Option C is incorrect because the 'life' parameter defines how long the operation remains scheduled (its total lifetime), not the probe frequency; frequency is set by the 'frequency' command.

Option D is incorrect because an operation does not stay in 'pending' merely until start-time if the configuration is complete—it transitions to 'active' when the schedule starts, and 'pending' typically indicates the operation is not yet scheduled or is waiting for scheduling resources. Option E is incorrect because 'life forever' means the operation continues indefinitely until manually stopped, not that it stops after a single probe.

Exam trap

The trap is conflating the 'life' parameter with the 'frequency' parameter — candidates assume 'life' controls probe frequency, when it actually controls the total duration the operation remains active.

248
Drag & Dropmedium

Drag and drop the steps of stateless DHCPv6 address assignment steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Stateless DHCPv6 uses SLAAC for addressing and DHCPv6 for additional parameters. The host sends an RS, receives an RA with the O flag, then sends an Information-Request and receives a Reply with options like DNS.

249
MCQmedium

Consider the following configuration: router eigrp 100 network 10.0.0.0 0.255.255.255 passive-interface default no passive-interface GigabitEthernet0/0 Which statement is true about this EIGRP configuration?

A.EIGRP will send and receive updates only on GigabitEthernet0/0.
B.EIGRP will send updates on all interfaces except GigabitEthernet0/0.
C.EIGRP will not send any updates because the network statement is incorrect.
D.EIGRP will form adjacencies on all interfaces that have an IP address in the 10.0.0.0/8 range.
AnswerA

Because the router is configured with passive-interface default, every interface is placed in passive mode by default, meaning EIGRP will not send or process updates on them. The 'no passive-interface GigabitEthernet0/0' command explicitly removes that passive designation only for GigabitEthernet0/0, allowing EIGRP to both send and receive updates on that single interface. As a result, EIGRP adjacency and update exchange occur exclusively on Gi0/0, exactly as the correct answer states, while all other interfaces remain passive and do not participate in EIGRP.

Why this answer

The `passive-interface default` command sets all interfaces to passive by default, preventing EIGRP from sending or receiving hello packets (and thus updates) on them. The `no passive-interface GigabitEthernet0/0` command then overrides this default for that specific interface, allowing EIGRP to send and receive updates only on GigabitEthernet0/0. The network statement 10.0.0.0 0.255.255.255 enables EIGRP on any interface matching the 10.0.0.0/8 range, but the passive-interface logic restricts actual adjacency formation.

Exam trap

Cisco often tests the interaction between `passive-interface default` and `no passive-interface` to see if candidates understand that the default passive setting overrides all interfaces except those explicitly enabled, rather than the reverse.

How to eliminate wrong answers

Option B is wrong because the configuration uses `passive-interface default` followed by `no passive-interface GigabitEthernet0/0`, which makes only GigabitEthernet0/0 active for EIGRP updates, not all interfaces except GigabitEthernet0/0. Option C is wrong because the network statement `10.0.0.0 0.255.255.255` is a valid wildcard mask that matches the 10.0.0.0/8 prefix, and EIGRP will enable on any interface with an IP in that range; the passive-interface logic does not invalidate the network statement. Option D is wrong because although the network statement enables EIGRP on all interfaces in the 10.0.0.0/8 range, the `passive-interface default` command suppresses hello packets and adjacency formation on all interfaces except GigabitEthernet0/0, so adjacencies will not form on other interfaces.

250
MCQhard

A network engineer runs the following command on Router R7: R7# show ip sla monitor statistics 6 Round Trip Time (RTT) for Index 6 Latest RTT: NoConnection/Busy/Timeout Latest Operation Start Time: 18:00:00.000 UTC Mon Mar 1 2021 Latest Operation Return Code: Timeout Number of successes: 0 Number of failures: 15 Over thresholds: 0 Based on this output, what is the status of the IP SLA operation?

A.The operation is functioning normally with occasional timeouts.
B.The target is reachable but with high latency.
C.The target is unreachable, as all probes have timed out.
D.The operation has been configured but not started.
AnswerC

The IP SLA statistics show 15 probes sent and 15 failures, all with a return code of 'Timeout'. A 100% loss rate with timeout return codes is conclusive evidence that the target is not responding to the probe traffic, meaning it is unreachable from the source device. This could be due to the target being down, a routing issue, or an ACL dropping the probes, but the operational conclusion is that the target is not reachable.

Why this answer

The output shows 15 failures with a 'Timeout' return code and no successes, indicating that every probe sent has timed out. In IP SLA, a 'NoConnection/Busy/Timeout' RTT and a 'Timeout' return code mean the target is not responding to the probe, confirming unreachability. Option C correctly states the target is unreachable because all probes have failed.

Exam trap

Cisco often tests the distinction between 'timeout' (no response) and 'high latency' (slow but successful responses), so candidates may incorrectly assume timeouts indicate latency rather than unreachability.

How to eliminate wrong answers

Option A is wrong because the operation is not functioning normally; zero successes and 15 failures indicate persistent timeouts, not occasional ones. Option B is wrong because high latency would still show some successful RTT values, but here the RTT is 'NoConnection/Busy/Timeout' with no successes, meaning the target is not reachable at all. Option D is wrong because the operation has clearly started—it has a start time and 15 failures—so it is not merely configured but not started.

251
Multi-Selectmedium

Which three statements about OSPF route summarization are true? (Choose three.)

Select 3 answers
A.Inter-area route summarization is configured on ABRs using the "area range" command.
B.External route summarization is configured on ASBRs using the "summary-address" command.
C.Route summarization reduces the size of the LSDB and improves network convergence.
D.Route summarization can be configured on any OSPF router to reduce Type 1 LSAs.
E.Summarization in OSPF can be applied to Type 1 and Type 2 LSAs to reduce flooding.
AnswersA, B, C

Inter-area summarisation is configured on area border routers with the **area** *range* command, which consolidates Type 3 summary LSAs for networks within a specified area. This satisfies the stem's requirement for a true OSPF summarisation statement, since ABRs generate inter-area prefixes and can suppress individual component routes.

Why this answer

Option A is correct because inter-area summarization is performed on Area Border Routers (ABRs) with the "area <area-id> range <ip> <mask>" command, which aggregates Type 3 summary LSAs advertised into other areas. Option B is correct because external route summarization is configured on Autonomous System Boundary Routers (ASBRs) using the "summary-address <ip> <mask>" command, which aggregates Type 5 (or Type 7) external LSAs. Option C is correct because summarization shrinks the link-state database and routing tables by replacing many specific prefixes with one aggregate, which reduces SPF computation overhead and speeds convergence.

Option D is wrong because Type 1 router LSAs describe a router's own links and cannot be summarized, and summarization is not performed on arbitrary routers. Option E is wrong because OSPF summarization applies to Type 3 and Type 5/7 LSAs, not to Type 1 and Type 2 LSAs, which must remain intact within an area for topology accuracy.

Exam trap

The trap is assuming OSPF can summarize any LSA type; candidates forget that Type 1 and Type 2 LSAs are intra-area and cannot be summarized, and that summarization is only performed on ABRs and ASBRs.

252
MCQmedium

A network engineer runs the following command on Router R3: R3# show bgp vpnv4 unicast all summary BGP router identifier 10.0.0.3, local AS number 65000 BGP table version is 10, main routing table version 10 10 network entries using 1440 bytes of memory 10 path entries using 1360 bytes of memory 6/5 BGP path/bestpath attribute entries using 840 bytes of memory 4 BGP AS-PATH entries using 112 bytes of memory 0 BGP route-map cache entries using 0 bytes of memory 0 BGP filter-list cache entries using 0 bytes of memory BGP using 3752 total bytes of memory BGP activity 20/10 prefixes, 20/10 paths, scan interval 60 secs Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 192.168.1.1 4 65000 1000 1000 10 0 0 01:23:45 5 192.168.2.2 4 65000 800 800 10 0 0 00:45:12 3 Based on this output, what can be concluded?

A.Both neighbors are eBGP peers
B.Both neighbors are iBGP peers exchanging VPNv4 prefixes
C.The neighbor 192.168.1.1 is not receiving any prefixes
D.The BGP table has 20 prefixes
AnswerB

The output is from the IPv4 VPNv4 BGP table, and both neighbors are configured with the same AS number (65000) as the local router, which classifies them as iBGP peers. The PfxRcd column shows that each neighbor has sent 5 prefixes, meaning they are actively exchanging VPNv4 prefixes with this router. This is the correct interpretation of the 'show bgp vpnv4 unicast all' output.

Why this answer

The command `show bgp vpnv4 unicast all summary` displays BGP VPNv4 unicast summary information for all VRFs. Both neighbors (192.168.1.1 and 192.168.2.2) are in the same AS 65000, and the output shows they are exchanging VPNv4 prefixes (State/PfxRcd shows 5 and 3 prefixes received). This confirms they are iBGP peers within the same AS, specifically for VPNv4 address family, which is used in MPLS Layer 3 VPN environments to carry customer VPN routes.

Exam trap

Cisco often tests the distinction between eBGP and iBGP by using the same AS number in the output, and candidates may overlook that the `vpnv4 unicast all` address family is specifically for MPLS VPN iBGP peering, not for standard IPv4 unicast.

How to eliminate wrong answers

Option A is wrong because both neighbors have the same AS number (65000) as the local router, which indicates iBGP peering, not eBGP (which requires different AS numbers). Option C is wrong because the State/PfxRcd column shows 5 prefixes received from 192.168.1.1, meaning it is actively receiving prefixes. Option D is wrong because the output clearly states '10 network entries' and '20/10 prefixes' (activity counters), not 20 prefixes in the current BGP table.

253
MCQeasy

Which of the following is a valid AP mode on Cisco 9800 WLCs that allows the AP to function as a standalone access point without controller management?

A.Local mode
B.FlexConnect mode
C.Monitor mode
D.Sniffer mode
AnswerB

FlexConnect (formerly Hybrid REAP) lets an AP locally switch client traffic at the edge and can continue to service clients even if the CAPWAP link to the WLC drops, using local authentication and forwarding policies. This 'split-tunnel' or local-switching capability is precisely what enables a remote site to keep working independently when WAN/controller connectivity is unavailable. That's why it's correct.

Why this answer

FlexConnect mode (option B) is the correct answer because it allows a Cisco AP to switch client traffic locally at the AP and continue forwarding traffic even if the connection to the Cisco 9800 WLC is lost, effectively functioning as a standalone access point without controller management. In this mode, the AP can operate in a 'connected' or 'standalone' state, with the latter providing full local switching and authentication when the CAPWAP tunnel to the controller is down.

Exam trap

Cisco often tests the misconception that FlexConnect is only a 'remote office' mode and not a true standalone mode, leading candidates to incorrectly choose Local mode because they assume all APs require constant controller contact.

How to eliminate wrong answers

Option A is wrong because Local mode requires the AP to maintain a CAPWAP tunnel to the WLC at all times; if the controller is unreachable, the AP stops serving clients. Option C is wrong because Monitor mode is a dedicated RF-sensing mode used for rogue detection and wireless intrusion prevention, not for serving client traffic. Option D is wrong because Sniffer mode is used to capture and forward 802.11 frames to a remote packet analyzer, and it does not provide any client connectivity or standalone functionality.

254
MCQhard

A network engineer is deploying a new Cisco Catalyst 9000 switch stack. The engineer wants to ensure that the stack uses the most efficient use of stack ports and provides the highest possible bandwidth between stack members. Which stacking technology and topology should be used?

A.Cisco StackWise with a star topology
B.Cisco StackPower with a ring topology
C.Cisco StackWise with a full mesh topology
D.Cisco StackWise with a ring topology
AnswerD

Cisco StackWise uses a ring topology to connect stack members. This provides redundancy because if one stack cable fails, the ring can still forward traffic in the opposite direction. StackWise-480 and StackWise-1T are common on Catalyst 9000 switches, offering high bandwidth (480 Gbps or 1 Tbps) and efficient use of stack ports. A ring topology is the standard and most efficient for StackWise.

Why this answer

Cisco StackWise uses a ring topology to connect stack members, providing high bandwidth and redundancy. If a cable fails, the ring can still function. StackWise-480 and StackWise-1T are used on Catalyst 9000 switches, offering up to 480 Gbps or 1 Tbps of stacking bandwidth.

StackPower is for power sharing, not data stacking.

Exam trap

The trap here is confusing StackPower with StackWise; StackPower is for power redundancy, while StackWise is for data stacking.

255
MCQhard

A campus switch connects to an IP phone that has a PC daisy-chained behind it. The engineer wants the phone to reside in VLAN 100 and the PC in VLAN 200, with the phone tagging its own voice traffic. Which interface configuration accomplishes this?

A.switchport mode access, switchport access vlan 100, switchport voice vlan 200
B.switchport mode access, switchport access vlan 200, switchport trunk encapsulation dot1q
C.switchport mode trunk, switchport trunk native vlan 200, switchport trunk allowed vlan 100,200
D.switchport mode access, switchport access vlan 200, switchport voice vlan 100
AnswerD

An access port with a voice VLAN configured uses Cisco's multi-VLAN access behavior: untagged frames from the attached PC are placed in the access VLAN, while 802.1Q-tagged frames from the phone are placed in the voice VLAN. Setting the access VLAN to 200 and the voice VLAN to 100 satisfies the requirement that the PC sit in VLAN 200 and the phone in VLAN 100.

Why this answer

Cisco's voice VLAN feature allows a single access port to serve two devices in different VLANs. The PC, which sends untagged frames, is placed in the access VLAN, while the IP phone, which tags its traffic with 802.1Q, is placed in the voice VLAN. Setting the access VLAN to 200 for the PC and the voice VLAN to 100 for the phone matches the requirement exactly.

Exam trap

The trap here is believing that a trunk must be configured to support an IP phone, when an access port with a voice VLAN already handles tagged phone traffic and untagged PC traffic.

256
Drag & Dropmedium

Drag and drop the steps of Cisco TrustSec inline tagging across fabric into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

TrustSec inline tagging starts with the ingress switch classifying traffic and adding an SGT to the frame, then forwarding it across the fabric, the egress switch reading the SGT, matching it to an SGACL, and finally enforcing the permit/deny decision.

257
MCQmedium

Given this NAT configuration: ``` interface GigabitEthernet0/0 ip address 10.0.0.1 255.255.255.0 ip nat inside ! interface GigabitEthernet0/1 ip address 198.51.100.1 255.255.255.0 ip nat outside ! ip nat inside source static 10.0.0.5 198.51.100.5 ``` What is the purpose of this configuration?

A.It translates all traffic from 10.0.0.0/24 to 198.51.100.0/24 using PAT.
B.It creates a one-to-one mapping between 10.0.0.5 and 198.51.100.5, allowing inbound and outbound traffic.
C.It translates only outbound traffic from 10.0.0.5 to 198.51.100.5.
D.The configuration is incomplete; it needs an access-list.
AnswerB

Static NAT establishes a persistent one-to-one binding between the inside local address 10.0.0.5 and the inside global address 198.51.100.5. Because this entry is permanent, both outbound traffic from the inside host and inbound traffic to the global address are translated, allowing external hosts to initiate sessions to the internal server. This is the defining characteristic of static NAT: the mapping is fixed regardless of direction.

Why this answer

The configuration uses the 'ip nat inside source static' command to create a permanent one-to-one mapping between the inside local address 10.0.0.5 and the inside global address 198.51.100.5. This static NAT allows both outbound traffic (source translation) and inbound traffic (destination translation) to and from the mapped host, enabling bidirectional communication without the need for an access list.

Exam trap

Cisco often tests the misconception that all NAT configurations require an access list, but static NAT is a notable exception—it uses a direct mapping and does not need an ACL to define the inside host.

How to eliminate wrong answers

Option A is wrong because the configuration uses static NAT, not PAT (Port Address Translation), and it only translates traffic for a single host (10.0.0.5), not the entire 10.0.0.0/24 subnet. Option C is wrong because static NAT translates both outbound and inbound traffic; it is not limited to outbound traffic only. Option D is wrong because the configuration is complete; static NAT does not require an access list (unlike dynamic NAT or PAT, which often use an ACL to define which inside addresses are eligible for translation).

258
Multi-Selecthard

Which two statements about EtherChannel configuration and verification are true? (Choose two.)

Select 2 answers
A.On IOS-XE, the 'channel-group 1 mode active' command creates the port-channel interface automatically if it does not exist.
B.The 'show etherchannel load-balance' command displays the current load-balancing method and the hash algorithm used.
C.In a Layer 3 EtherChannel, you must assign an IP address to the port-channel interface and also to each member interface.
D.The 'channel-group 1 mode desirable' command is valid on both IOS-XE and NX-OS platforms.
E.If physical ports in an EtherChannel have different speed or duplex settings, the EtherChannel will still form but with reduced bandwidth.
AnswersA, B

Correct because when the first physical port is added with a mode that enables LACP, the port-channel interface is dynamically created.

Why this answer

EtherChannel interfaces can be configured as Layer 2 (switchport) or Layer 3 (no switchport). The 'channel-group' command assigns a physical port to a port-channel. The 'show etherchannel summary' command displays the state and bundle information.

On NX-OS, the 'channel-group' command uses the 'force' option to override mismatched parameters.

259
MCQmedium

Refer to the exhibit. Which OSPF route type is the default route?

A.External type 2 (E2)
B.Inter-area (IA)
C.NSSA external type 2 (N2)
D.External type 1 (E1)
AnswerA

When OSPF redistributes a default route, the default metric-type is 2 (E2), which means the route's metric remains fixed at the ASBR-advertised value (20) and does not include the internal cost of reaching that ASBR. This is why a default route injected via redistribute or default-information originate is normally seen as an E2 route unless metric-type 1 is explicitly selected.

Why this answer

The exhibit shows a default route (0.0.0.0/0) being redistributed into OSPF from another routing protocol or static route. By default, OSPF redistributes routes as External Type 2 (E2), meaning the metric does not include the internal cost to the ASBR. The route is not an NSSA type because the area is not configured as a not-so-stubby area, and it is not an inter-area route because it originates outside the OSPF domain.

Exam trap

Cisco often tests the default OSPF metric type for redistributed routes (E2) and the fact that a default route can be an external route, not just an inter-area or NSSA type, leading candidates to confuse it with N2 or IA when the area type is not explicitly stated.

How to eliminate wrong answers

Option B is wrong because Inter-area (IA) routes are prefixes learned from another OSPF area, not redistributed external routes; a default route redistributed into OSPF is external, not inter-area. Option C is wrong because NSSA external type 2 (N2) routes only appear in not-so-stubby areas (NSSA) and are translated to type 5 LSAs by the ABR; the exhibit does not indicate an NSSA configuration. Option D is wrong because External type 1 (E1) routes include the internal cost to the ASBR in their metric, but OSPF defaults to E2 for redistributed routes unless explicitly configured with the 'metric-type 1' keyword.

260
MCQmedium

A RESTCONF request is sent to a Cisco IOS-XE device to retrieve interface statistics: GET /restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1 Accept: application/yang-data+json Response: { "ietf-interfaces:interface": [ { "name": "GigabitEthernet1", "type": "iana-if-type:ethernetCsmacd", "enabled": true, "ietf-ip:ipv4": { "address": [ { "ip": "192.168.1.1", "netmask": "255.255.255.0" } ] } } ] } What does the response indicate about the interface?

A.The interface GigabitEthernet1 is enabled and has an IPv4 address of 192.168.1.1/24.
B.The interface is disabled because the 'enabled' field is missing.
C.The response indicates an error because the interface type is incorrect.
D.The response shows that the interface has no IP address configured.
AnswerA

The correct interpretation of the returned data is that GigabitEthernet1 is administratively and operationally ready: the 'enabled' field is explicitly present and set to true, and the 'ipv4' section contains both an 'address' of 192.168.1.1 and a 'netmask' of 255.255.255.0. A netmask of 255.255.255.0 corresponds to a /24 prefix length. Additionally, the 'type' field 'ethernetCsmacd' confirms this is a standard Ethernet interface, so the interface is up and has a valid IPv4 address.

Why this answer

The response includes an 'enabled' field set to 'true' and an IPv4 address of '192.168.1.1' with a netmask of '255.255.255.0', which corresponds to a /24 prefix. The RESTCONF GET request successfully retrieves the interface configuration from the ietf-interfaces YANG data model, confirming the interface is administratively up and has an IPv4 address configured.

Exam trap

Cisco often tests the distinction between configuration data and operational state data in RESTCONF/NETCONF responses; the trap here is that candidates may assume the 'enabled' field is missing or misinterpret the netmask as a prefix length, leading them to incorrectly select options B or D.

How to eliminate wrong answers

Option B is wrong because the 'enabled' field is present and set to 'true', not missing; the response clearly shows 'enabled': true. Option C is wrong because the interface type 'iana-if-type:ethernetCsmacd' is the correct standard type for a GigabitEthernet interface per the IANA ifType definitions, so there is no error. Option D is wrong because the response explicitly includes an IPv4 address (192.168.1.1) with a netmask, indicating an IP address is configured.

261
Multi-Selectmedium

A network administrator is configuring a Cisco IOS zone-based firewall (ZBFW) on a router that connects a LAN zone to an Internet zone. The administrator wants to allow outbound HTTP and HTTPS from the LAN to the Internet while blocking all other outbound traffic, and to allow return traffic for established sessions. Which two configuration elements are required to accomplish this? (Choose two.)

Select 2 answers
A.A NAT configuration that translates LAN addresses to the Internet-facing interface address.
B.A parameter map that defines inspection parameters for HTTP and HTTPS.
C.A class map that matches HTTP and HTTPS traffic and a policy map that applies an inspect action.
D.Zone pairs that define the LAN-to-Internet direction and apply the policy map with the service-policy command.
E.An extended ACL applied inbound on the LAN interface to permit HTTP and HTTPS.
AnswersC, D

Zone-based firewall uses class maps to identify traffic and policy maps to apply actions such as inspect. To allow HTTP and HTTPS from LAN to Internet, a class map matching those protocols is required, and the policy map must apply the inspect action so that return traffic is permitted for established sessions.

Why this answer

Zone-based firewall on Cisco IOS requires class maps to identify traffic and policy maps to apply actions like inspect. The policy map must be applied to a zone pair that defines the direction of traffic, in this case LAN to Internet. The inspect action allows return traffic for established sessions, and any traffic not explicitly permitted is implicitly denied by the zone pair policy.

Exam trap

The trap here is assuming that an interface ACL or NAT is part of the zone-based firewall configuration, when ZBFW specifically uses class maps, policy maps, and zone pairs with service-policy.

262
Drag & Dropmedium

Drag and drop the steps of SD-Access fabric border handoff configuration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with defining the external network, then creating the SVI for the handoff, configuring the routing protocol, applying the border handoff policy, and finally verifying the connectivity. This sequence ensures the border node can properly connect the fabric to external networks.

263
MCQmedium

A network engineer is migrating a physical server running a critical database to a virtual machine on a VMware vSphere cluster. The database requires high I/O performance and low latency. The engineer decides to use VMFS datastores with multiple extents to improve performance. After migration, the database performance is worse than on the physical server. What is the most likely reason?

A.VMFS datastores with multiple extents can cause I/O to span multiple LUNs, increasing latency.
B.The VMFS datastore does not support files larger than 2 TB.
C.The virtual disk is configured as thin provisioned, causing write amplification.
D.The virtual disk is configured as thick eager zeroed, causing slow initial writes.
AnswerA

This is correct because a VMFS datastore can be created by concatenating multiple extents, each residing on a different LUN. When a virtual machine's file (VMDK) is stored on such a datastore, I/O operations can be striped or scattered across those physical LUNs. Because separate LUNs often reside on different spindles, RAID groups, or storage tiers, the hypervisor may need to wait for round-trips over multiple paths or controllers, adding per-I/O overhead and increasing latency beyond what a single-extent datastore would incur.

Why this answer

VMFS datastores with multiple extents distribute data across multiple LUNs, which can cause I/O operations to span physical storage devices. This introduces additional latency due to the need for coordination across LUNs, negating the performance benefit expected from a single, contiguous LUN. For a database requiring high I/O and low latency, this spanning effect degrades performance compared to a physical server with direct-attached storage.

Exam trap

Cisco often tests the misconception that multiple extents improve performance by aggregating bandwidth, when in fact they increase latency due to I/O spanning and SCSI locking overhead.

How to eliminate wrong answers

Option B is wrong because VMFS datastores support files larger than 2 TB; VMFS-5 and later allow virtual disks up to 62 TB, so file size is not the issue. Option C is wrong because thin provisioning can cause write amplification due to on-demand allocation, but the question specifies the engineer used multiple extents, and thin provisioning is not mentioned as the chosen configuration; the primary performance issue here is the extent spanning. Option D is wrong because thick eager zeroed pre-allocates and zeros blocks during creation, which can slow initial writes but does not explain ongoing poor performance after migration; the problem is persistent latency from multi-extent I/O.

264
Drag & Dropmedium

Drag and drop the steps of Cisco ISE profiling and policy assignment flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The flow starts with endpoint authentication via 802.1X/MAB, then ISE collects profiling data (e.g., DHCP, HTTP). ISE matches the endpoint to a profiling policy, assigns an identity group, and finally applies the appropriate authorization policy (e.g., SGT, VLAN).

265
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate management users via TACACS+. The TACACS+ server is reachable at 10.1.1.100. The administrator wants to ensure that if the TACACS+ server becomes unreachable, the router will fall back to local authentication using the local username 'admin' with password 'Cisco123'. Which configuration should be applied?

A.aaa new-model aaa authentication login default group tacacs+ local tacacs server TAC1 address ipv4 10.1.1.100 key SecretKey username admin privilege 15 secret Cisco123
B.aaa new-model aaa authentication login default group tacacs+ local tacacs-server host 10.1.1.100 key SecretKey username admin privilege 15 secret Cisco123
C.aaa new-model aaa authentication login default group tacacs+ tacacs server TAC1 address ipv4 10.1.1.100 key SecretKey username admin privilege 15 secret Cisco123
D.aaa new-model aaa authentication login default group tacacs+ local tacacs server TAC1 address ipv4 10.1.1.100 key SecretKey username admin privilege 15 password Cisco123
AnswerA

This configuration enables AAA, sets the default login authentication method list to use TACACS+ first and then local as fallback, defines the TACACS+ server, and creates a local username. This ensures that if the TACACS+ server is unreachable, the router will use the local database for authentication.

Why this answer

The correct configuration enables AAA, specifies TACACS+ with local fallback in the authentication method list, defines the TACACS+ server using the modern 'tacacs server' command, and creates a local username with a secret. This ensures authentication works even if the TACACS+ server is down.

Exam trap

The trap here is forgetting to include the 'local' keyword as a fallback method, which would cause authentication to fail if the TACACS+ server is unreachable.

266
MCQmedium

Consider the following DMVPN configuration on a hub router: interface Tunnel0 ip address 10.0.0.1 255.255.255.0 no ip redirects ip nhrp map multicast dynamic ip nhrp network-id 100 tunnel source GigabitEthernet0/0/0 tunnel mode gre multipoint What is the effect of the command 'ip nhrp map multicast dynamic'?

A.It statically maps the hub's own NBMA address to the multicast group.
B.It enables the hub to dynamically add spoke NBMA addresses to the multicast NHRP map for forwarding multicast traffic to all spokes.
C.It configures the hub to send NHRP registration requests to the multicast address 224.0.0.1.
D.It disables multicast forwarding over the tunnel interface.
AnswerB

This is the correct function. When a spoke sends an NHRP Registration Request, the hub records the spoke's NBMA (tunnel source) address and dynamically adds it to the multicast NHRP map for the tunnel interface. The hub then uses this map to replicate broadcast and multicast traffic (e.g., routing protocol hellos) to every registered spoke by sending a separate IPsec-encapsulated copy to each spoke's NBMA address, enabling pseudo-broadcast over the point-to-multipoint DMVPN network.

Why this answer

The command 'ip nhrp map multicast dynamic' on a DMVPN hub router instructs the router to dynamically add the NBMA addresses of spoke routers to the multicast NHRP mapping table as they register. This allows the hub to replicate multicast traffic (e.g., routing protocol hellos) to all spokes by using the dynamically learned NBMA addresses, enabling efficient dynamic spoke-to-spoke communication via the hub.

Exam trap

Cisco often tests the distinction between static and dynamic NHRP multicast mapping, where candidates mistakenly think 'dynamic' refers to the hub dynamically registering with a multicast group (like IGMP) rather than dynamically learning spoke NBMA addresses for multicast replication.

How to eliminate wrong answers

Option A is wrong because the command does not statically map the hub's own NBMA address; static mapping is done with 'ip nhrp map' without the 'dynamic' keyword. Option C is wrong because NHRP registration requests are sent by spokes to the hub, not by the hub to a multicast address; the hub uses this command to accept and map those registrations for multicast forwarding. Option D is wrong because the command enables multicast forwarding over the tunnel interface, not disables it; disabling multicast would require 'no ip nhrp map multicast' or similar.

267
Drag & Dropmedium

Drag and drop the steps of a NETCONF get-config operation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The NETCONF get-config operation begins with establishing a secure SSH session, then the client sends a hello message to exchange capabilities. After the server responds with its hello, the client sends the get-config request. The server retrieves the configuration and sends the reply.

268
MCQmedium

A network engineer is troubleshooting an STP issue in a switched network. The network has two distribution switches connected via a trunk, and each distribution switch connects to the same access switch. The engineer notices that the root bridge is not the intended distribution switch. Upon checking, the engineer sees that the access switch has a higher priority than the distribution switches. The engineer needs to ensure that the intended distribution switch becomes the root bridge without causing a temporary loop. What should the engineer do?

A.Configure the 'spanning-tree vlan vlan-id root primary' command on the intended distribution switch.
B.Set the priority of the access switch to 0 using the 'spanning-tree vlan vlan-id priority 0' command.
C.Increase the priority of the distribution switch to 61440 using the 'spanning-tree vlan vlan-id priority 61440' command.
D.Disable STP on the distribution switch and manually configure it as the root bridge.
AnswerA

The `spanning-tree vlan vlan-id root primary` command is a Cisco macro that forces the switch to become the root bridge by automatically setting its bridge priority to 24576, or to 4096 less than the current lowest priority if another switch already has a priority below 24576. This adjusts the priority dynamically without manual calculation, ensuring the intended distribution switch wins the root election. The command also configures the switch to be the primary root for that VLAN, which is exactly the desired outcome.

Why this answer

The 'spanning-tree vlan vlan-id root primary' command dynamically sets the switch's bridge priority to 24576 (or 4096 if the current root has a priority lower than 24576) and ensures the switch becomes the root bridge without manual priority miscalculation. This command also adjusts the priority of neighboring switches if needed, preventing temporary loops by avoiding the need to disable or reset STP. It is the safest and most efficient method to force a specific switch to become the root bridge in a live network.

Exam trap

Cisco often tests the misconception that increasing a switch's priority (making it numerically higher) helps it become root, when in fact the root bridge is elected based on the lowest bridge priority value.

How to eliminate wrong answers

Option B is wrong because setting the access switch's priority to 0 would make it the root bridge, which is the opposite of the intended goal (the distribution switch should be root). Option C is wrong because increasing the distribution switch's priority to 61440 (a high value) would make it less likely to become the root bridge, not more; the root bridge is elected with the lowest priority value. Option D is wrong because disabling STP on the distribution switch would break loop prevention entirely, potentially causing a Layer 2 loop and network outage, and manually configuring it as root without STP is not a valid or safe method.

269
Multi-Selectmedium

Which two statements about policing and shaping are true? (Choose two.)

Select 2 answers
A.Policing can be configured on both ingress and egress interfaces, whereas shaping is typically applied only on egress interfaces.
B.Shaping drops packets that exceed the configured rate, while policing buffers them to meet the rate.
C.Both policing and shaping use a token bucket algorithm to measure traffic rates.
D.Shaping is more suitable than policing for traffic that must be dropped immediately, such as scavenger-class traffic.
E.Policing always introduces additional latency due to queuing, while shaping does not.
AnswersA, C

Correct. Policing is bidirectional; shaping is unidirectional (outbound) because it requires buffering.

Why this answer

Policing drops or re-marks packets that exceed a configured rate, while shaping buffers excess packets and delays them to smooth traffic. Policing can be applied inbound or outbound, but shaping is typically outbound only. Shaping uses a buffer, which can introduce jitter.

270
MCQeasy

A network administrator is deploying a virtual switch on a Cisco UCS B-Series blade server. The administrator wants the virtual switch to be managed by Cisco UCS Manager and to support Cisco VM-FEX so that virtual machine traffic is visible to the upstream fabric interconnects. Which virtual switch technology meets these requirements?

A.Cisco Nexus 1000V Virtual Supervisor Module
B.Cisco Virtual Machine Fabric Extender in UCS Manager
C.VMware vSphere Standard Switch
D.Open vSwitch with Cisco ACI integration
AnswerB

VM-FEX in Cisco UCS Manager presents virtual interfaces from the fabric interconnect down to the hypervisor, so virtual machine traffic is treated like traffic from a physical adapter. It is managed directly in UCS Manager and provides the upstream visibility the administrator wants, satisfying both requirements in the scenario.

Why this answer

VM-FEX integrated with Cisco UCS Manager is the virtual switching technology that lets the fabric interconnect manage virtual interfaces and expose virtual machine traffic to upstream ports. It is administered from UCS Manager, which the administrator requires. Nexus 1000V, vSphere Standard Switch, and Open vSwitch do not provide UCS Manager-managed VM-FEX capability in this scenario.

Exam trap

The trap here is assuming any Cisco virtual switch integrates with UCS Manager, when VM-FEX is the specific feature that provides that management and visibility.

271
MCQeasy

A network engineer is troubleshooting an EIGRP issue where two routers, R1 and R2, are directly connected. Neither router shows an EIGRP adjacency with the other. The engineer checks the interface configurations and finds that R1 has 'ip authentication mode eigrp 1 md5' and 'ip authentication key-chain eigrp 1 MYKEY' configured, while R2 has no authentication configured. What is the most likely cause?

A.R1 has authentication configured, but R2 does not, so R1 will reject R2's hello packets, and no adjacency forms.
B.R2 will automatically learn the authentication key from R1 and form an adjacency.
C.R1 will form an adjacency with R2 because authentication is optional.
D.The adjacency will form but only for routes that are not authenticated.
AnswerA

EIGRP supports MD5 or HMAC-SHA-256 authentication, which must be configured with a matching key on both neighbors. When R1 has authentication enabled, it inspects the EIGRP authentication TLV in every incoming hello packet; R2's hellos lack this TLV because R2 has no authentication configured, so R1 silently discards them. Because R1 never accepts R2's hellos, the two-way neighbor discovery process fails, and no adjacency is ever established.

Why this answer

R1 has authentication configured, so it includes MD5 authentication data in its hello packets and expects authenticated hellos from neighbors. R2 does not have authentication configured, so it sends unauthenticated hellos. R1 drops R2's unauthenticated hellos, and R2 does not process R1's authenticated hellos (or the mismatch prevents a bidirectional relationship), resulting in no EIGRP adjacency being formed on either router.

Exam trap

Cisco often tests the misconception that authentication is optional or that a router can learn keys dynamically; the trap here is assuming that an adjacency can form unidirectionally when authentication is mismatched, when in fact EIGRP requires matching authentication parameters for bidirectional neighbor discovery.

How to eliminate wrong answers

Option B is wrong because EIGRP does not support automatic key learning; authentication keys must be manually configured on both routers. Option C is wrong because when authentication is enabled on one side, it is not optional—the receiving router will drop unauthenticated or mismatched hello packets, preventing adjacency formation. Option D is wrong because EIGRP authentication applies to all EIGRP packets (including hellos and updates); there is no mechanism to form an adjacency for only a subset of routes.

272
Drag & Dropmedium

Drag and drop the steps of LDP session establishment between LSRs into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

LDP session establishment starts with discovering neighbors via Hello messages over UDP, then opening a TCP connection. The LSRs exchange initialization parameters over TCP, followed by Keepalive messages to confirm the session. Finally, label mappings are exchanged for FECs.

273
Multi-Selectmedium

Which two statements about the Cisco Enterprise Campus Architecture are true? (Choose two.)

Select 2 answers
A.The distribution layer provides policy-based connectivity and controls traffic flow between access and core layers.
B.The access layer is responsible for routing between VLANs and providing high-speed switching for the campus backbone.
C.The core layer should be designed for high-speed transport and minimal latency, avoiding CPU-intensive features like ACLs.
D.A two-tier hierarchical design (collapsed core) is recommended for large campus networks with thousands of users.
E.The core layer should enforce security policies and perform packet inspection to protect the campus network.
AnswersA, C

The distribution layer aggregates access switches and enforces policy, performing inter-VLAN routing, filtering and QoS between access and core. This satisfies the requirement for policy-based connectivity and traffic-flow control, keeping the core free for high-speed transport.

Why this answer

Option A is correct because in the Cisco Enterprise Campus Architecture the distribution layer is the aggregation point that provides policy-based connectivity, inter-VLAN routing, route summarization, and controls traffic flow between the access and core layers. Option C is correct because the core layer is designed as a high-speed transport backbone with minimal latency, so CPU-intensive features such as ACLs, packet inspection, and policy enforcement should be avoided there. Option B is wrong because routing between VLANs and high-speed backbone switching are functions of the distribution and core layers, not the access layer, which primarily provides user/device connectivity and Layer 2 switching with PoE and port security.

Option D is wrong because a two-tier collapsed-core design is recommended for smaller campus networks, whereas large campuses with thousands of users typically use a three-tier hierarchical design. Option E is wrong because security policy enforcement and packet inspection belong at the distribution (and access) layers, not the core, which must remain fast and simple.

Exam trap

350-401 often tests the misconception that the core layer should enforce security or that the access layer performs inter-VLAN routing, confusing the roles of each tier in the hierarchical model.

274
MCQmedium

Examine the following configuration snippet: interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ip ospf hello-interval 20 ip ospf dead-interval 80 What is the effect of this configuration?

A.The OSPF hello interval is changed to 20 seconds, and the dead interval is changed to 80 seconds, maintaining the default 4:1 ratio.
B.The OSPF hello interval is changed to 20 seconds, but the dead interval remains at the default of 40 seconds.
C.The OSPF hello interval is changed to 20 seconds, and the dead interval is automatically set to 60 seconds.
D.This configuration will cause OSPF adjacency failure because the dead interval must be exactly 4 times the hello interval.
AnswerA

The OSPF configuration in the scenario explicitly sets the hello interval to 20 seconds and the dead interval to 80 seconds, which preserves OSPF's default dead-to-hello ratio of 4:1 (80/20 = 4). Because both neighbors are configured with these same values, the OSPF dead interval timer remains consistent, and adjacency formation occurs normally. This matches the requirement that neighbors must agree on timer values, not that a strict 4:1 ratio is mandated.

Why this answer

The configuration explicitly sets the OSPF hello interval to 20 seconds and the dead interval to 80 seconds, which maintains the default 4:1 ratio (dead = hello × 4). OSPF allows manual configuration of these timers, and as long as both sides of the adjacency match, the ratio can be any value; the 4:1 default is not enforced by the protocol.

Exam trap

Cisco often tests the misconception that the dead interval must always be exactly 4 times the hello interval, but the actual requirement is that the timers must match between neighbors, not that a specific ratio must be maintained.

How to eliminate wrong answers

Option B is wrong because the 'ip ospf dead-interval 80' command explicitly overrides the default dead interval (40 seconds for a 10-second hello), so it does not remain at 40. Option C is wrong because OSPF does not automatically set the dead interval to 60 seconds when the hello interval is changed; the dead interval must be explicitly configured or it stays at the default (which would be 80 seconds if the hello were 20, but here it is explicitly set to 80). Option D is wrong because OSPF does not require the dead interval to be exactly 4 times the hello interval; the only requirement is that the timers match on both OSPF neighbors for adjacency to form, and any ratio is acceptable as long as it is consistent.

275
Multi-Selectmedium

Which two statements about NAT configuration on Cisco IOS-XE are true? (Choose two.)

Select 2 answers
A.NAT overload (PAT) allows multiple internal hosts to share a single public IP address by using unique source port numbers.
B.The ip nat inside source list 1 pool POOL overload command enables dynamic NAT without port translation.
C.A static NAT entry is created using the ip nat inside source static 192.168.1.10 203.0.113.10 command.
D.The ip nat outside command is applied to the internal interface to mark it as the source of NAT translations.
E.Dynamic NAT without overload translates multiple inside addresses to a single outside address using port numbers.
AnswersA, C

NAT overload, or PAT, multiplexes many inside local addresses onto one inside global address by translating source port numbers, keeping each flow distinct. This satisfies the requirement to share a single public IP across multiple internal hosts simultaneously.

Why this answer

Option A is correct because NAT overload, also called PAT, lets many inside hosts share one public IP by multiplexing translations with unique source port numbers, which is exactly how the ip nat inside source list ... overload form operates. Option C is correct because the syntax ip nat inside source static 192.168.1.10 203.0.113.10 creates a one-to-one static NAT mapping between the inside local address 192.168.1.10 and the inside global address 203.0.113.10. Option B is wrong because the overload keyword specifically enables port address translation, so it is not dynamic NAT without port translation.

Option D is wrong because ip nat outside is applied to the outside interface, not the internal interface, to mark it as the NAT outside domain. Option E is wrong because dynamic NAT without overload performs one-to-one address translation and does not use port numbers to share a single outside address.

Exam trap

350-401 often tests the distinction between dynamic NAT (one-to-one from a pool) and PAT/overload (many-to-one with port translation), plus the correct interface marking (ip nat inside vs ip nat outside), causing candidates to swap the two or misread the overload keyword.

276
MCQmedium

An enterprise is designing a QoS architecture for its WAN edge routers connecting to multiple service providers. The design must support traffic shaping to avoid packet drops due to provider policers, while also prioritizing real-time traffic. Which approach should the architect use to shape traffic to the contracted CIR while still allowing bursts?

A.Apply a shape average policy on the egress interface of the WAN edge router, setting the CIR and burst parameters to match the provider contract.
B.Use a policer on the ingress interface to drop traffic exceeding the CIR.
C.Configure a shaper on the provider's device instead of the customer router.
D.Set the interface bandwidth to the CIR and rely on FIFO queuing.
AnswerA

Shape average on the egress interface uses a token bucket to constrain the long-term average traffic rate to the CIR while permitting short bursts up to the configured Bc (and optionally Be). Unlike a policer, the shaper queues excess packets so they are transmitted later, which smooths traffic sent toward the provider and prevents the provider's ingress policer from seeing micro-bursts that trigger tail drops. Matching the CIR and burst parameters to the provider contract ensures the shaped output stays within the contracted traffic profile, making this the only option that actively enforces the committed rate while preserving burst absorption.

Why this answer

'shape average' on the egress interface allows the router to buffer excess traffic and transmit it at the contracted CIR, while the burst parameters (Bc and Be) enable short-term bursts above CIR to accommodate real-time traffic spikes without drops. This prevents the provider's policer from discarding packets, as the shaper ensures the outbound traffic rate stays within the agreed contract limits.

Exam trap

Cisco often tests the distinction between shaping and policing—the trap here is that candidates may choose policing (Option B) because it seems simpler, but they overlook that shaping buffers bursts to avoid drops, which is essential when the provider enforces a policer downstream.

How to eliminate wrong answers

Option B is wrong because policing on the ingress interface drops or marks traffic exceeding the CIR, which does not prevent packet loss from the provider's egress policer and fails to buffer bursts; it also does not shape traffic to match the contract. Option C is wrong because the provider's device is typically not under the customer's administrative control, and shaping on the provider side would not allow the customer to prioritize their own real-time traffic or manage bursts locally. Option D is wrong because setting interface bandwidth to CIR does not perform shaping—it only influences routing metrics and QoS calculations, and FIFO queuing provides no prioritization for real-time traffic, leading to jitter and potential drops.

277
MCQmedium

A network engineer is configuring a VXLAN overlay. The underlay is an IP-routed network, and the engineer needs to ensure that the VXLAN tunnel endpoints can discover each other's VTEP IP addresses dynamically. Which technology should be used?

A.PIM sparse mode
B.MP-BGP EVPN
C.OSPFv3
D.LISP
AnswerB

MP-BGP EVPN is the control plane that distributes MAC and IP reachability information, including VTEP IP addresses, between VXLAN tunnel endpoints. It allows dynamic discovery of remote VTEPs and their associated MAC addresses, eliminating the need for flood-and-learn. This is the standard Cisco SD-Access and data center VXLAN control plane.

Why this answer

MP-BGP EVPN acts as the VXLAN control plane, allowing VTEPs to exchange reachability information for MAC and IP addresses. This enables dynamic discovery of remote VTEPs and their endpoints, avoiding the inefficiencies of flood-and-learn. PIM, OSPFv3, and LISP do not provide the required EVPN address family for VXLAN tunnel endpoint discovery.

Exam trap

The trap here is confusing underlay routing protocols like OSPFv3 or multicast PIM with the overlay control plane needed for VTEP and MAC discovery.

278
MCQmedium

A network engineer is deploying Control Plane Policing on a Cisco IOS XE router that runs BGP, SSH management, and SNMP monitoring. The engineer must ensure that BGP keepalives are never dropped even during a control-plane flood, while SSH and SNMP traffic should be rate-limited. Which CoPP configuration element accomplishes this requirement?

A.Create a class-map matching BGP traffic with a 'police' action and assign it to the control-plane policy-map.
B.Create a class-map matching BGP traffic and apply a 'police' action with a conform-action of 'transmit' and an exceed-action of 'transmit'.
C.Create a class-map matching BGP traffic and apply a 'police' action with a very high committed information rate (CIR).
D.Create a class-map matching BGP traffic and reference it in the control-plane policy-map without applying any police action.
AnswerD

Classes in a control-plane policy-map that have no police action applied are not rate-limited, so matching BGP traffic and simply referencing it in the policy-map exempts BGP from CoPP policing. The engineer can then apply 'police' actions to SSH and SNMP classes. This satisfies the requirement that BGP keepalives are never dropped while still rate-limiting other control-plane traffic.

Why this answer

CoPP works by classifying control-plane traffic and applying actions, most commonly 'police'. Any class that has no police action is effectively passed without rate limiting, which is exactly what is needed for BGP keepalives that must never be dropped. SSH and SNMP classes can then receive 'police' actions with appropriate conform/exceed handling.

This design isolates critical routing protocol traffic from the effects of a control-plane flood.

Exam trap

The trap here is assuming that every class in a CoPP policy-map must have a police action, when in fact a class without a police action passes traffic unconditionally.

279
MCQmedium

A network engineer is automating the deployment of VLANs across multiple switches using Ansible. The playbook runs successfully on most switches, but one switch fails with an error indicating that the VLAN configuration command is not recognized. What is the most likely cause?

A.Ansible lacks the appropriate module for VLAN configuration
B.The inventory file has a syntax error for that specific host
C.The switch runs a different IOS version with different VLAN CLI syntax
D.SSH connectivity to the switch is blocked by an ACL
AnswerC

VLAN configuration syntax is not identical across all Cisco IOS versions: older IOS releases traditionally used 'vlan database' mode, while modern IOS-XE and many IOS 15.x train support interface configuration mode with 'vlan <vlan-id>'. If the playbook uses commands like 'vlan <id>' inside interface config or relies on VTP-related syntax that the specific IOS version does not recognize, the switch will return a '% Invalid input' error at the CLI. This failure would occur only on switches running that divergent IOS version, while other switches with compatible syntax execute successfully.

Why this answer

The most likely cause is that the switch runs a different IOS version with different VLAN CLI syntax. Ansible executes commands via SSH, and if the switch expects a different command format (e.g., 'vlan 10' vs. 'vlan database' on older CatOS), the playbook will fail with a command-not-recognized error. This is a common issue when automating across heterogeneous network devices.

Exam trap

The trap here is that candidates may assume a module or connectivity issue, but Cisco tests the understanding that different IOS versions or platforms (e.g., IOS vs. CatOS) have distinct VLAN CLI syntax, which Ansible modules must handle via conditional logic or version-specific variables.

How to eliminate wrong answers

Option A is wrong because Ansible has dedicated modules like 'ios_vlan' for VLAN configuration on Cisco IOS devices, so lacking a module is not the issue. Option B is wrong because an inventory file syntax error would typically cause a connection failure or host-not-found error, not a command-not-recognized error during execution. Option D is wrong because if SSH connectivity were blocked by an ACL, the playbook would fail at the connection stage with a timeout or authentication error, not after successfully sending a command.

280
Multi-Selectmedium

Which two statements about Cisco DNA Center software image management (SWIM) are true? (Choose two.)

Select 2 answers
A.Cisco DNA Center allows administrators to define a golden image for each device family and automatically enforce compliance.
B.Cisco DNA Center can upgrade device images remotely without requiring physical access to the devices.
C.Cisco DNA Center SWIM requires all devices to have a TFTP server configured locally to receive new images.
D.Cisco DNA Center SWIM does not provide any compliance reporting or audit trails for image versions.
E.Cisco DNA Center SWIM only supports Cisco Catalyst 9000 series switches and cannot manage older platforms.
AnswersA, B

SWIM maintains a golden image per device family and continuously compares running images against it, flagging or remediating non-compliant devices. This satisfies the stem by showing DNA Center's automated compliance enforcement, not merely image storage or manual upload.

Why this answer

Option A is correct because Cisco DNA Center SWIM lets administrators designate a golden (approved) image per device family and then run compliance checks that flag and remediate devices whose running image deviates from that golden image. Option B is correct because SWIM performs remote image distribution and activation over the management network, so devices can be upgraded without an engineer physically visiting them. Option C is wrong because SWIM uses DNA Center's own image repository and file transfer mechanisms (for example, HTTPS/SCP-style transfer to devices), not a locally configured TFTP server on each device.

Option D is wrong because SWIM does include image compliance status, version tracking, and audit/history reporting. Option E is wrong because SWIM supports a broad range of Cisco platforms (including many Catalyst switching and routing families), not only Catalyst 9000 series devices.

Exam trap

350-401 often tests the difference between traditional manual image management (TFTP, console access) and DNA Center's automated SWIM, causing candidates to assume legacy requirements like local TFTP servers.

281
MCQhard

A network engineer runs the following command on Router R4: R4# show ip pim rp mapping PIM Group-to-RP Mappings This system is an RP (Auto-RP) This system is an RP (BSR) Group(s) 224.0.0.0/4 RP 10.0.0.2 (?), v2v1 Info source: 10.0.0.2 (?), elected via Auto-RP, expires in 00:01:30 RP 10.0.0.3 (?), v2v1 Info source: 10.0.0.3 (?), elected via BSR, expires in 00:02:00 Based on this output, what can be concluded?

A.Only Auto-RP is being used for RP mapping.
B.Only BSR is being used for RP mapping.
C.Both Auto-RP and BSR are configured, causing multiple RP mappings.
D.The router is not an RP.
AnswerC

The output shows two distinct RP addresses for the same group range, one elected via Auto-RP and one elected via BSR. This occurs when both Auto-RP and BSR are configured, and the router accepts RP information from both protocols. The result is multiple RP mappings for the same multicast group, which can cause inconsistent RPF behavior and forwarding loops if the RPs differ.

Why this answer

The output shows two separate RP mappings for the same group range 224.0.0.0/4: one from Auto-RP (RP 10.0.0.2) and one from BSR (RP 10.0.0.3). The router also explicitly states 'This system is an RP (Auto-RP)' and 'This system is an RP (BSR)', confirming that both protocols are actively configured and providing RP information, leading to multiple RP mappings.

Exam trap

Cisco often tests the misconception that a router cannot be an RP for both Auto-RP and BSR simultaneously, but the output confirms it can, and the trap is that candidates assume only one protocol is active when both are clearly listed.

How to eliminate wrong answers

Option A is wrong because the output clearly shows a BSR-elected RP (10.0.0.3) in addition to the Auto-RP mapping, so Auto-RP is not the only protocol in use. Option B is wrong because the output also shows an Auto-RP-elected RP (10.0.0.2), so BSR is not the only protocol in use. Option D is wrong because the router explicitly states 'This system is an RP (Auto-RP)' and 'This system is an RP (BSR)', indicating it is acting as an RP for both protocols.

282
MCQmedium

Examine the following configuration: policy-map MARKING class VOICE set dscp ef class VIDEO set dscp af41 class class-default set dscp default interface GigabitEthernet0/0 service-policy input MARKING Which statement is true?

A.Incoming packets matching the VOICE class will have their DSCP set to EF (46), VIDEO to AF41 (34), and all others to default (0).
B.The policy-map will only mark packets if the interface is congested.
C.The configuration is invalid because 'set dscp' cannot be used in a 'service-policy input' direction.
D.The policy-map will remark the DSCP of outgoing packets on GigabitEthernet0/0.
AnswerA

In a Modular QoS CLI policy-map, the 'set dscp' action unconditionally rewrites the DSCP field of every packet that matches the class. Because the policy-map is attached with 'service-policy input', this marking occurs as packets enter the interface: voice traffic is set to EF (46), video to AF41 (34), and class-default traffic to 0. This makes the statement correct.

Why this answer

The configuration applies the MARKING policy-map as a service-policy input on GigabitEthernet0/0. This means all incoming packets are classified and have their DSCP values set according to the policy: VOICE class packets get DSCP EF (46), VIDEO class packets get DSCP AF41 (34), and all other packets (class-default) get DSCP default (0). The 'set dscp' action is valid in the input direction and does not require congestion to take effect.

Exam trap

The trap here is that candidates often confuse marking with congestion management, assuming that QoS actions like 'set dscp' only take effect during congestion, when in fact marking is a non-congestion-dependent action that applies to every matching packet.

How to eliminate wrong answers

Option B is wrong because the 'set dscp' action in a policy-map is a marking action that occurs on every matching packet regardless of congestion; it is not a queuing or dropping action that depends on congestion. Option C is wrong because 'set dscp' is perfectly valid in the input direction; marking can be applied to incoming packets before they are processed by the router. Option D is wrong because the service-policy is applied in the input direction, meaning it processes incoming packets, not outgoing packets; for outgoing marking, the policy would need to be applied as 'service-policy output'.

283
MCQeasy

Which BGP attribute is preferred when it has the lowest value?

A.MED (Multi-Exit Discriminator)
B.Local Preference
C.Weight
D.AS Path
AnswerA

The MED attribute is used to indicate the preferred path into an AS; lower MED is better.

Why this answer

The Multi-Exit Discriminator (MED) is a BGP path attribute used to influence inbound traffic to an AS from multiple entry points. A lower MED value is preferred over a higher one, making it the correct answer among the options where the lowest value is preferred.

Exam trap

Cisco often tests the distinction between attributes where higher is preferred (Local Preference, Weight) versus lower is preferred (MED, AS Path length), and the trap here is that candidates might confuse MED with Local Preference or Weight, both of which use higher values as better.

How to eliminate wrong answers

Option B (Local Preference) is wrong because Local Preference is used to influence outbound traffic from an AS, and a higher value is preferred, not lower. Option C (Weight) is wrong because Weight is a Cisco-proprietary attribute that is preferred when it has a higher value, not lower. Option D (AS Path) is wrong because a shorter AS Path length is preferred, meaning a lower count is better, but the question asks for an attribute where the lowest value is preferred, and AS Path is not typically described as a 'value' in the same sense as MED; moreover, AS Path length is a count, not a metric like MED, and the question's phrasing aligns more directly with MED's explicit numeric comparison.

284
MCQeasy

Refer to the exhibit. A network administrator notices that some DHCP packets are being dropped due to 'MAC Address Mismatch'. What is the most likely cause of this drop?

A.The DHCP server is sending packets with an incorrect server identifier option.
B.The DHCP client is using a different MAC address in the DHCP packet than the source MAC in the Ethernet frame.
C.The DHCP client is sending a request with an incorrect transaction ID.
D.The DHCP offer packet is arriving on an untrusted port.
AnswerB

This is the correct cause. DHCP snooping compares the source MAC address in the Ethernet frame header with the 'chaddr' field inside the DHCP packet itself. When the DHCP client inserts a different MAC address in the chaddr field than the actual source MAC of the frame, the switch flags this as a potential spoofing attempt and drops the packet, incrementing the 'MAC address mismatch' counter. This check prevents a client from impersonating another device's MAC address in DHCP requests.

Why this answer

The DHCP snooping feature on a switch compares the source MAC address in the Ethernet frame with the chaddr (client hardware address) field inside the DHCP packet. When a DHCP client sends a packet with a different MAC in the frame than in the chaddr field, the switch considers it a 'MAC Address Mismatch' and drops the packet. This security mechanism prevents a rogue client from spoofing another device's MAC address to obtain a lease.

Exam trap

Cisco often tests the distinction between Layer 2 MAC checks (frame vs. chaddr) and Layer 3 or application-layer checks (server identifier, transaction ID), leading candidates to confuse DHCP snooping drops with client-side validation failures.

How to eliminate wrong answers

Option A is wrong because the DHCP server identifier option (option 54) is used by clients to identify which server to respond to, and an incorrect server identifier would cause a client to ignore the offer, not a switch to drop the packet due to MAC mismatch. Option B is correct as described. Option C is wrong because an incorrect transaction ID (XID) would cause the DHCP client to ignore the server's reply, but the switch does not check the XID for MAC mismatch drops; the XID mismatch is a client-side validation issue.

Option D is wrong because an untrusted port is a DHCP snooping concept where the switch drops DHCP server messages (OFFER, ACK, etc.) received on that port, not client messages, and the 'MAC Address Mismatch' check applies to client messages on untrusted ports as well, but the specific cause described is the mismatch between frame MAC and chaddr.

285
Matchingmedium

Drag and drop each OSPF area type on the left to its matching characteristic on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Must connect all other areas; area 0

Blocks Type 5 LSAs; allows Type 3 summary LSAs

Blocks Type 5 and Type 3 LSAs; uses default route only

Allows Type 7 LSAs for external routes; blocks Type 5 LSAs

Blocks Type 5 and Type 3; allows Type 7 for external routes

Why these pairings

Backbone area (0) connects all other areas; Stub area blocks Type 5 LSAs but allows Type 3; Totally stubby area blocks both Type 5 and Type 3 (default route only); NSSA allows Type 7 LSAs for external routes but blocks Type 5; NSSA totally stubby blocks Type 5 and Type 3 but allows Type 7.

286
MCQeasy

A network administrator needs to secure management access to a Cisco IOS XE switch. The requirement is that only SSH version 2 with a 2048-bit RSA key be accepted, that Telnet be disabled, and that only the 'netadmin' user with privilege level 15 be allowed to log in via VTY lines 0 through 4. Which configuration accomplishes this?

A.crypto key generate rsa modulus 2048; ip ssh version 2; line vty 0 4; transport input ssh; login local; username netadmin privilege 15 secret <password>
B.crypto key generate rsa modulus 2048; ip ssh version 1; line vty 0 4; transport input ssh; login local; username netadmin privilege 15 secret <password>
C.crypto key generate rsa modulus 2048; ip ssh version 2; line vty 0 4; transport input ssh; login local; username netadmin privilege 1 secret <password>
D.crypto key generate rsa modulus 1024; ip ssh version 2; line vty 0 4; transport input telnet ssh; login local; username netadmin privilege 15 secret <password>
AnswerA

This sequence generates a 2048-bit RSA key, restricts SSH to version 2, disables Telnet by allowing only SSH transport on the VTY lines, and enforces local authentication with a privilege 15 user. All three requirements—SSHv2, no Telnet, and netadmin-only access—are satisfied by this configuration.

Why this answer

The correct configuration generates a 2048-bit RSA key, forces SSH version 2, restricts VTY transport to SSH only (disabling Telnet), and uses local authentication with the netadmin user at privilege 15. Alternatives fail because they use a weak key size, allow Telnet, force SSHv1, or assign the wrong privilege level, each violating at least one stated requirement.

Exam trap

The trap here is overlooking one of the three simultaneous conditions—key size, SSH version, or privilege level—and selecting a configuration that only partially satisfies the policy.

287
Drag & Dropmedium

Drag and drop the steps of the CAPWAP discovery and join process between a lightweight AP and a WLC into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The CAPWAP process starts with the AP obtaining an IP address (via DHCP), then discovering the WLC (via DHCP option 43 or DNS). The AP sends a Discovery Request, the WLC replies with a Discovery Response, and finally the AP sends a Join Request to establish the control tunnel.

288
MCQhard

A network engineer is using Ansible to manage a fleet of Cisco IOS XE devices. The engineer wants to ensure that the playbook is idempotent and only makes changes when necessary. The playbook uses the ios_config module with a set of lines to configure an interface. After running the playbook, the engineer notices that the task always reports 'changed' even when the configuration is already present. What is the most likely reason for this behavior?

A.One of the configuration lines contains a value that the device automatically modifies, such as a timestamp or a sequence number, causing a mismatch.
B.The Ansible control node is using an outdated version of the ios_config module that has a known bug with idempotency.
C.The playbook is using the 'lines' parameter without the 'parents' parameter, causing the module to miscompare the configuration.
D.The ios_config module does not support idempotency; it always applies the configuration and reports changed.
AnswerA

If a configuration line includes a value that the device changes automatically (e.g., 'description Configured on 2025-01-01' or an ACL sequence number), the module will see a difference each time and reapply the line. This results in a 'changed' status even when the intent is already met. The engineer should avoid such dynamic values or use templates that account for them.

Why this answer

The ios_config module achieves idempotency by comparing the desired lines with the running configuration. If a line contains a value that the device automatically alters, such as a timestamp or a sequence number, the comparison will always show a difference, causing the task to report 'changed' and reapply the line. The engineer should remove or template such dynamic values to restore idempotency.

Exam trap

The trap here is blaming the module for lacking idempotency when the real issue is a configuration line that the device dynamically modifies.

289
Matchingmedium

Drag and drop each data encoding format on the left to its typical use case on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Human-readable, commonly used in REST APIs

Verbose, supports schemas and namespaces

Human-friendly, often used for configuration files

Compact binary format for efficient serialization

Why these pairings

Correct pairings: JSON is human-readable and widely used in REST APIs; XML is verbose with schema support; YAML is human-friendly for configuration files; Protobuf is a compact binary format for high-performance RPC.

290
MCQhard

A network automation team is using YANG models with NETCONF to configure a Cisco IOS XE device. They want to change the description of a loopback interface. The engineer writes an <edit-config> RPC with the 'operation' attribute set to 'merge' on the <description> leaf. The RPC is accepted, but the description is not changed. The engineer verifies that the YANG path is correct and that the interface exists. What is the most likely reason the description was not updated?

A.The <edit-config> RPC was sent to the 'candidate' datastore, but a <commit> operation was not performed.
B.The description leaf is read-only in the YANG model and cannot be modified via NETCONF.
C.The 'merge' operation requires the parent container to be specified with a namespace, which was omitted.
D.The 'operation' attribute must be set to 'replace' instead of 'merge' to change a leaf value.
AnswerA

If the device is configured to use the candidate datastore, changes made via <edit-config> are not active until a <commit> RPC is issued. The RPC would be accepted without error, but the running configuration remains unchanged. This is a common oversight when using NETCONF with candidate datastores. Issuing a <commit> applies the changes.

Why this answer

When using NETCONF with a candidate datastore, <edit-config> modifies the candidate configuration but does not affect the running configuration until a <commit> RPC is executed. The RPC being accepted without error indicates the edit was valid but not applied. The engineer must send a <commit> to activate the change.

Other options like namespace or operation type would typically produce errors, not silent acceptance.

Exam trap

The trap here is assuming that a successful <edit-config> RPC immediately changes the running configuration, forgetting that candidate datastores require an explicit commit.

291
MCQhard

A network engineer is configuring QoS on a Cisco switch to ensure that video traffic (DSCP AF41) is not dropped during congestion. The engineer creates a policy-map that sets the queue-limit for the AF41 class. However, the switch is still dropping video packets. What is the most likely cause?

A.The queue-limit is set too low, causing tail drops.
B.The switch uses a single queue for all traffic unless multiple queues are configured.
C.The video traffic is not being marked with DSCP AF41.
D.The policy-map must be applied to the output direction.
AnswerB

Modern switching platforms often use a single FIFO or default priority queue for all traffic until multiple egress queues are explicitly configured through QoS profile or class-map-to-queue mappings. If the engineer only attached a policy-map that sets DSCP/CoS but did not map the class to one of the available hardware queues, the video traffic remains in the default queue and receives no dedicated bandwidth or drop protection. Therefore, the root cause is the absence of a multi-queue schedule, not the marking or policy-map direction.

Why this answer

By default, Cisco switches use a single queue for all traffic. Creating a policy-map that sets a queue-limit for the AF41 class does not automatically create a separate queue for that class; the switch must have multiple egress queues configured (e.g., via the 'priority-queue out' command or by mapping DSCP values to specific queues). Without multiple queues, all traffic shares the same queue, and setting a queue-limit on a class within a single-queue system does not prevent drops during congestion.

Exam trap

Cisco often tests the misconception that creating a class-map and policy-map with a queue-limit automatically creates a separate queue for that traffic, when in fact the switch must have multiple queues explicitly configured to isolate traffic classes.

How to eliminate wrong answers

Option A is wrong because setting the queue-limit too low could cause tail drops, but the question states the engineer created a queue-limit for the AF41 class, and the core issue is that the switch is not using separate queues for different traffic classes. Option C is wrong because the problem is not about marking; the engineer is configuring QoS for video traffic marked as DSCP AF41, and the drops occur even if the marking is correct, due to the lack of multiple queues. Option D is wrong because the policy-map must be applied in the output direction for egress queuing, but the engineer likely applied it correctly; the real issue is that the switch does not have multiple queues configured to isolate the AF41 traffic.

292
MCQhard

A network engineer runs the following command on Router R8: R8# show ip dhcp server statistics Memory usage: 12345 Address pools: 2 Database agents: 0 Automatic bindings: 10 Manual bindings: 2 Expired bindings: 1 Malformed messages: 0 Message Received BOOTREQUEST 0 DHCPDISCOVER 100 DHCPREQUEST 95 DHCPDECLINE 1 DHCPRELEASE 2 DHCPINFORM 0 Based on this output, what can be concluded?

A.The DHCP server has received more DHCPDISCOVER messages than DHCPREQUEST messages, indicating some clients did not proceed to request.
B.The DHCP server has 12 active leases.
C.The DHCP server rejected 5 DHCPDISCOVER messages.
D.The DHCP server has 2 manual bindings that are static reservations.
AnswerA

In DORA, a client first sends DHCPDISCOVER to locate servers; after receiving DHCPOFFER, it sends DHCPREQUEST to accept the offered lease. Because the server logged 100 DISCOVERs but only 95 REQUESTs, five clients either received no suitable offer or abandoned the process before accepting. Thus, the count mismatch directly indicates some clients failed to proceed past the offer phase.

Why this answer

The DHCP server received 100 DHCPDISCOVER messages but only 95 DHCPREQUEST messages. This indicates that 5 clients sent DHCPDISCOVER messages but did not proceed to send a DHCPREQUEST, which could be due to network issues, client configuration, or the client not selecting an offered IP address. The DHCP process requires a client to send a DHCPREQUEST after receiving a DHCPOFFER, so the discrepancy shows incomplete DORA (Discover, Offer, Request, Acknowledge) cycles.

Exam trap

Cisco often tests the ability to interpret DHCP server statistics by presenting numbers that seem to imply a direct relationship (like DISCOVER vs. REQUEST) and expects candidates to understand the DORA flow rather than jumping to conclusions about rejections or malformed messages.

How to eliminate wrong answers

Option B is wrong because the total active leases are the sum of automatic bindings (10) and manual bindings (2), which equals 12, but the output shows 'Expired bindings: 1', meaning one lease has expired and is no longer active; thus, active leases are 11, not 12. Option C is wrong because the output shows 'Malformed messages: 0', indicating no messages were rejected due to malformation; the difference between DHCPDISCOVER (100) and DHCPREQUEST (95) does not imply rejection but rather clients that did not proceed in the DORA process. Option D is wrong because manual bindings (2) are indeed static reservations, but this is a true statement based on the output; however, the question asks 'what can be concluded?' and Option D is not a conclusion derived from the statistics—it is a factual restatement of the output, and the correct conclusion is the one about the discrepancy between DISCOVER and REQUEST messages.

293
Multi-Selecthard

Which three statements about MPLS VPN (Layer 3 VPN) are true? (Choose three.)

Select 3 answers
A.PE routers maintain separate VRF instances for each customer.
B.Route distinguishers (RDs) are used to make overlapping customer prefixes unique.
C.Route targets (RTs) control the import and export of routes between VRFs.
D.P routers must maintain customer VPN routing information.
E.MPLS VPNs use a single label to forward packets across the service provider core.
AnswersA, B, C

Each customer's routes are held in a separate VRF routing table on the PE router, isolating overlapping address space per VPN. This per-VRF separation is the core mechanism that keeps customer traffic distinct across the shared MPLS backbone.

Why this answer

Option A is correct because in an MPLS Layer 3 VPN, each PE router maintains separate VRF (Virtual Routing and Forwarding) instances per customer, which keeps customer routing tables isolated on the shared PE device. Option B is correct because a route distinguisher (RD) is prepended to a customer IPv4 prefix to create a unique VPNv4 address, allowing overlapping customer prefixes (such as duplicate 10.0.0.0/8 networks) to coexist in the provider's BGP table. Option C is correct because route targets (RTs) are extended BGP community attributes that control which VRFs import and export specific routes, thereby defining the VPN topology (hub-and-spoke, full mesh, etc.).

Option D is not correct because P (provider) routers only forward labeled packets through the core and do not hold customer VPN routing information; that responsibility belongs to PE routers. Option E is not correct because MPLS VPN forwarding typically uses a two-label stack: an outer label (LDP or RSVP-TE) to reach the egress PE and an inner label (VPN label) to identify the customer VRF or next hop.

Exam trap

350-401 often tests the misconception that P routers participate in customer routing or that MPLS uses a single label — candidates forget the two-label stack and the fact that only PE routers maintain VRFs.

294
Drag & Drophard

Drag and drop the steps of configuring NETCONF YANG-based telemetry with on-change subscription into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, enable NETCONF on the device. Then, define a sensor group that includes the YANG paths to monitor for changes. Next, create a subscription that specifies the sensor group, a receiver, and the on-change update policy.

After that, apply the subscription to activate it. Finally, the device sends updates only when the monitored data changes.

295
MCQeasy

A network engineer is configuring a new Cisco Wireless LAN Controller (WLC) and needs to ensure that the WLC can be managed remotely from a different subnet. The WLC is connected to a switch port that is configured as a trunk. Which interface on the WLC must be configured with an IP address to allow remote management?

A.Virtual interface
B.Dynamic interface
C.Service port
D.Management interface
AnswerD

The management interface on a Cisco WLC is used for in-band management. It must be configured with an IP address, subnet mask, and default gateway to allow remote management from a different subnet. This interface is also used for communication with access points, DHCP, and other services. It is typically mapped to a VLAN on the trunk port.

Why this answer

The management interface on a Cisco WLC is the correct interface for remote management. It is configured with an IP address and default gateway, allowing access from different subnets. It is also used for AP communication and other services.

The service port is for out-of-band management, the virtual interface is for internal functions, and dynamic interfaces are for user traffic.

Exam trap

The trap here is confusing the service port with the management interface, as both can be used for management, but only the management interface supports in-band remote management from a different subnet.

296
MCQmedium

A network engineer is deploying a Cisco SD-Access fabric using Cisco DNA Center. The design requires that wired users authenticate via 802.1X and be assigned to a specific overlay segment based on their department. Which Cisco SD-Access fabric component is responsible for authenticating the endpoint and assigning the endpoint to the correct overlay?

A.Cisco DNA Center
B.Fabric border node
C.Fabric edge node
D.Fabric control plane node
AnswerC

The fabric edge node is the first-hop device that connects wired endpoints to the fabric. It runs the host tracking database and acts as the authenticator for 802.1X, mapping the endpoint to the appropriate virtual network based on the Cisco DNA Center policy. When a user connects, the edge node performs authentication and assigns the endpoint to the correct overlay segment.

Why this answer

In Cisco SD-Access, the fabric edge node is the device where endpoints connect and are authenticated. It uses 802.1X, MAC authentication bypass, or web authentication to verify identity and then assigns the endpoint to a virtual network based on the policy defined in Cisco DNA Center. The control plane node handles LISP mappings, and the border node handles external connectivity, so they do not perform the authentication and assignment role.

Exam trap

The trap here is assuming that Cisco DNA Center performs the authentication, when it only defines policy and the edge node enforces it.

297
MCQeasy

A network engineer is configuring a Cisco IOS switch and needs to ensure that a port connected to a server is placed into the forwarding state immediately when the link comes up, without going through the listening and learning states. The engineer also wants to protect against accidental loops if a switch is connected to that port. Which feature should be configured on the port?

A.UplinkFast
B.BackboneFast
C.PortFast with BPDU Guard
D.Root Guard
AnswerC

PortFast allows a port to transition immediately to the forwarding state when the link comes up, bypassing listening and learning. BPDU Guard disables the port if it receives a BPDU, protecting against accidental loops if a switch is connected. Together, they meet the requirements for fast server connectivity and loop protection.

Why this answer

PortFast transitions a port immediately to forwarding, which is ideal for server connections. BPDU Guard disables the port if a BPDU is received, preventing loops if a switch is mistakenly connected. The combination provides both fast connectivity and loop protection, making it the correct choice for this scenario.

Exam trap

The trap here is confusing PortFast with other spanning-tree enhancements like UplinkFast or BackboneFast, which serve different purposes and do not provide immediate forwarding on access ports.

298
MCQhard

A network engineer is implementing VXLAN with a Cisco Nexus 9000 series switch acting as a VTEP. The engineer needs to ensure that the VXLAN overlay can carry traffic for multiple tenants while maintaining isolation. Which component is responsible for identifying the VXLAN segment and providing tenant isolation?

A.Destination IP address in the outer IP header
B.VXLAN Network Identifier (VNI)
C.UDP source port number
D.VLAN ID in the outer Ethernet header
AnswerB

The VNI is a 24-bit identifier that uniquely identifies a VXLAN segment. It provides isolation for tenants by separating traffic into distinct logical networks. Each VNI maps to a specific Layer 2 or Layer 3 domain, ensuring that traffic from different tenants remains isolated even when using the same underlay.

Why this answer

The VXLAN Network Identifier (VNI) is a 24-bit field in the VXLAN header that uniquely identifies each VXLAN segment. It allows up to 16 million segments, enabling massive multi-tenancy. Tenant isolation is achieved because each VNI represents a separate logical network, and traffic from different VNIs is not mixed.

The VNI is the key component for identifying the segment and ensuring isolation.

Exam trap

The trap here is assuming that the outer VLAN ID or IP addresses provide tenant isolation, when in fact the VNI is the sole identifier for the VXLAN segment.

299
MCQmedium

A network automation team is using Cisco DNA Center's Intent API to retrieve a list of all network devices. The team writes a Python script that sends a GET request to the /dna/intent/api/v1/network-device endpoint. The script includes a valid authentication token in the headers, but the response returns a 403 Forbidden error. The token was obtained successfully using the /dna/system/api/v1/auth/token endpoint. What is the most likely reason for the 403 error?

A.The API endpoint requires a different HTTP method, such as POST.
B.The API request is missing the required 'X-Auth-Token' header.
C.The authentication token has expired and must be refreshed.
D.The user account associated with the token does not have the necessary RBAC permissions to access the network device API.
AnswerD

Cisco DNA Center enforces role-based access control (RBAC). Even with a valid token, if the user account lacks the required permissions for the Intent API, the request will be denied with 403 Forbidden. The team must ensure the user has a role that includes access to the network device inventory, such as SUPER-ADMIN-ROLE or a custom role with appropriate privileges.

Why this answer

In Cisco DNA Center, authentication tokens are obtained via the /dna/system/api/v1/auth/token endpoint. However, possessing a valid token does not guarantee access to all APIs. Each API endpoint requires specific RBAC permissions.

A 403 Forbidden error indicates that the authenticated user does not have the required role or permission to access the network-device API. The team should verify the user's role and adjust RBAC settings accordingly.

Exam trap

The trap here is assuming that a valid authentication token automatically grants access to all API endpoints, overlooking the role-based access control (RBAC) requirements.

300
MCQmedium

A network engineer runs the following command on switch SW9: SW9# show cts role-based policy Role-based policy: Source Group Dest Group Action 10 20 PERMIT 10 30 DENY 20 30 PERMIT Based on this output, what can be concluded?

A.Traffic from SGT 10 to SGT 20 is denied.
B.Traffic from SGT 20 to SGT 30 is permitted.
C.Traffic from SGT 30 to SGT 10 is denied.
D.The policy is configured on an ISE server.
AnswerB

The displayed Security Group ACL (SGACL) contains a rule with source SGT 20 and destination SGT 30, and the action for that rule is PERMIT. This explicitly allows traffic from security group 20 to security group 30, making the statement correct. No other rule in the output overrides or denies this match, so the traffic is indeed permitted.

Why this answer

The command 'show cts role-based policy' displays Cisco TrustSec (CTS) role-based policies that define access control between source and destination Security Group Tags (SGTs). The output shows that traffic from SGT 20 to SGT 30 is explicitly permitted (PERMIT action), making option B correct. These policies are unidirectional, meaning the action applies only from the specified source group to the specified destination group.

Exam trap

Cisco often tests the unidirectional nature of CTS role-based policies, where candidates mistakenly assume policies are bidirectional or that a permit in one direction implies a permit in the reverse direction.

How to eliminate wrong answers

Option A is wrong because the output shows a PERMIT action for source group 10 to destination group 20, not a deny. Option C is wrong because the policy is unidirectional; the output only lists policies for source groups 10 and 20, not for source group 30, so no conclusion can be drawn about traffic from SGT 30 to SGT 10. Option D is wrong because the policy is displayed on the switch itself via the CLI, indicating it is locally configured or downloaded from ISE but not necessarily configured on an ISE server; the command output does not specify the policy source.

Page 3

Page 4 of 26

Page 5