Courseiva

ENCOR 350-401 (350-401) — Questions 301–375

1923 questions total · 26pages · All types, answers revealed

Page 4

Page 5 of 26

Page 6
301
MCQeasy

A company uses VRF-lite to separate management traffic (VRF MGMT) from user traffic (VRF USER) on a Cisco Catalyst 3850 stack. The management network is 10.0.0.0/24, and the user network is 192.168.1.0/24. The engineer wants to allow SSH access from the user network to the management network for device administration. The switch has an SVI for each VRF. What is the simplest way to achieve this while maintaining VRF isolation?

A.Configure a static route in VRF USER pointing to the VRF MGMT's SVI IP address, and enable route leaking between the VRFs.
B.Place both SVIs in the same VRF and use access-lists to restrict traffic.
C.Use a firewall between the VRFs to filter traffic.
D.Configure the switch to use the global routing table for SSH traffic only.
AnswerA

This is correct because VRF route leaking explicitly permits the USER VRF to learn a route to the management SVI in the MGMT VRF without merging the two routing tables. By configuring a static route in VRF USER with the MGMT SVI IP as the next hop, and then enabling route leaking (for example, via import/export route targets or an appropriate leak statement), the switch installs only the necessary prefix into USER's RIB. This allows SSH from USER hosts to reach the MGMT VRF while all other traffic remains isolated, preserving the path-isolation requirement with minimal configuration overhead.

Why this answer

VRF-lite inherently isolates routing tables, so to allow SSH from VRF USER to VRF MGMT while maintaining isolation, you must leak routes between the VRFs. A static route in VRF USER pointing to the VRF MGMT SVI IP address, combined with route leaking (e.g., using `route-map` and `import/export` commands), enables the necessary reachability without merging the VRFs. This is the simplest method as it avoids additional hardware or complex configurations.

Exam trap

Cisco often tests the misconception that VRFs are completely isolated and cannot communicate without breaking isolation, but route leaking is the correct method to allow selective inter-VRF traffic while maintaining VRF separation.

How to eliminate wrong answers

Option B is wrong because placing both SVIs in the same VRF breaks VRF isolation entirely, defeating the purpose of separating management and user traffic. Option C is wrong because introducing a firewall is unnecessary and adds complexity; VRF-lite with route leaking can achieve the goal natively on the switch without external devices. Option D is wrong because configuring the switch to use the global routing table for SSH traffic only is not a standard or supported feature in VRF-lite; SSH traffic still follows the VRF routing table unless explicit route leaking is configured.

302
Drag & Dropmedium

Drag and drop the steps to configure port security on a Cisco switch in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Port security limits unauthorized MAC addresses; violation mode defines action on violation.

303
MCQhard

An engineer is configuring a new Cisco 9800 WLC in a branch office. The WLC will manage 50 APs and must provide guest access with a captive portal. The engineer configures a guest SSID with open authentication and a redirect ACL for the captive portal. However, after the configuration, clients can associate to the guest SSID but cannot reach the captive portal page. What is the most likely cause?

A.The guest SSID is configured with open authentication, which does not support captive portal.
B.The redirect ACL is missing entries for DNS and HTTP traffic to the captive portal server.
C.The WLC does not have a dedicated guest interface configured.
D.The captive portal requires a RADIUS server to be configured on the WLC.
AnswerB

The redirect ACL, also called the pre-auth ACL, is the core mechanism that makes a Cisco WLC captive portal work. Before a client is web-authenticated, this ACL defines which traffic is permitted through, and everything else is redirected to the virtual interface (or portal server). If entries for DNS (UDP/53) and HTTP (TCP/80) toward the captive portal server or the virtual gateway are missing, the client cannot resolve the portal domain or its initial HTTP request is blackholed instead of being redirected. Without those explicit permits, the WLC drops or fails to redirect the client's traffic, so the captive portal never appears in the browser.

Why this answer

The redirect ACL is used to permit traffic that should bypass the captive portal (e.g., DNS and HTTP traffic to the captive portal server) while redirecting all other HTTP traffic. If the ACL is missing entries for DNS and HTTP to the portal server, the client's DNS lookup for the portal server or the initial HTTP request to it will be redirected instead of allowed, causing the captive portal page to fail to load. This is a common misconfiguration on Cisco 9800 WLCs, where the redirect ACL must explicitly permit the necessary traffic to the portal server.

Exam trap

Cisco often tests the misconception that captive portal requires a RADIUS server or a dedicated interface, but the real trap is that the redirect ACL must explicitly permit traffic to the portal server and DNS, or the portal page will never load.

How to eliminate wrong answers

Option A is wrong because open authentication does support captive portal; the captive portal intercepts HTTP traffic after association, regardless of the authentication method. Option C is wrong because a dedicated guest interface is not strictly required for captive portal; the WLC can use a service port or a VLAN interface for guest traffic, and the issue described is about ACL misconfiguration, not interface absence. Option D is wrong because captive portal on a Cisco 9800 WLC can operate with local authentication or without a RADIUS server; RADIUS is only needed if using external authentication for the portal.

304
MCQmedium

A network architect is designing a Cisco SD-Access fabric for a campus network. The architect wants to ensure that endpoints in the same virtual network can communicate with each other even when they are attached to different fabric edge nodes. Which control plane component is responsible for resolving endpoint location information across the fabric?

A.Fabric control plane node
B.Cisco DNA Center
C.Fabric border node
D.Cisco Identity Services Engine (ISE)
AnswerA

The fabric control plane node runs the LISP map-server and map-resolver functions. It maintains the mapping of endpoint IP addresses to fabric edge nodes, enabling communication between endpoints attached to different edge nodes. When an edge node needs to reach an endpoint not locally attached, it queries the control plane node for the location, which returns the RLOC of the correct edge node.

Why this answer

The fabric control plane node in Cisco SD-Access implements LISP map-server and map-resolver functions. It maintains a database of endpoint IP addresses and their corresponding fabric edge node RLOCs. When an endpoint on one edge node needs to communicate with an endpoint on another edge node, the source edge node queries the control plane node to learn the destination's location, enabling VXLAN encapsulation and delivery.

Exam trap

The trap here is assuming that Cisco DNA Center or ISE performs endpoint location resolution, when in fact the fabric control plane node handles that function.

305
MCQhard

A network engineer is designing a high-availability campus network using Cisco StackWise Virtual technology on two Cisco Catalyst 9000 switches. The engineer wants to ensure that the control plane remains operational if one switch fails, and that the data plane can continue forwarding traffic with minimal disruption. Which statement accurately describes the operation of StackWise Virtual in this scenario?

A.One switch is active for control plane and management, while the other is standby; both switches forward data traffic using a unified data plane.
B.StackWise Virtual requires a dedicated Layer 3 link for control plane synchronization, and data traffic is forwarded only by the active switch.
C.The two switches load-balance control plane functions, with each switch managing a subset of VLANs and routing protocols independently.
D.Both switches run independent control planes and synchronize routing tables via a dedicated link, with each switch forwarding traffic independently.
AnswerA

StackWise Virtual combines two switches into a single logical entity. One switch is elected active and handles control plane and management functions, while the other is standby and ready to take over. Both switches actively forward data traffic, providing increased bandwidth and redundancy. This active/standby control plane with active/active data plane is the defining characteristic of StackWise Virtual.

Why this answer

Cisco StackWise Virtual merges two physical switches into one logical switch. The active switch runs the control plane and management, while the standby switch is ready to take over. Both switches forward data traffic, providing active/active forwarding.

This design ensures high availability: if the active switch fails, the standby becomes active, and data forwarding continues on the remaining switch with minimal disruption.

Exam trap

The trap here is assuming that StackWise Virtual uses active/active control planes or that only the active switch forwards traffic, when in fact it is active/standby for control and active/active for data.

306
MCQhard

A network engineer runs the following command on Router R6: R6# show ip bgp vpnv4 all summary BGP router identifier 10.0.0.6, local AS number 65000 BGP table version is 10, main routing table version 10 10 network entries using 1440 bytes of memory 10 path entries using 800 bytes of memory 4/3 BGP path/bestpath attribute entries using 576 bytes of memory 2 BGP AS-PATH entries using 48 bytes of memory 0 BGP route-map cache entries using 0 bytes of memory 0 BGP filter-list cache entries using 0 bytes of memory Bitfield cache entries: current 1 (at peak 2) using 32 bytes of memory BGP using 2896 total bytes of memory BGP activity 20/10 prefixes, 20/10 paths, scan interval 60 secs Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 10.0.0.7 4 65001 1000 1000 10 0 0 00:20:00 5 10.0.0.8 4 65002 500 500 10 0 0 00:10:00 3 Based on this output, what can be concluded?

A.Both BGP sessions are in the Idle state.
B.The router is receiving VPNv4 prefixes from both neighbors.
C.The BGP table has no entries because the table version is 10.
D.The neighbor 10.0.0.8 is not configured for VPNv4.
AnswerB

The State/PfxRcd values of 5 and 3 for the two neighbors indicate that the local router has received a total of eight VPNv4 unicast prefixes from them. Because the command is issued under the VPNv4 address family, these prefixes are VPNv4 routes, which carry an 8-byte route distinguisher and are used in MPLS L3VPN to propagate customer prefixes across the provider backbone. The nonzero counts prove active, established sessions and successful VPNv4 route exchange with both peers, so the correct interpretation is that the router is receiving VPNv4 prefixes from both neighbors.

Why this answer

The output shows that neighbor 10.0.0.7 (AS 65001) has 5 prefixes received (State/PfxRcd = 5) and neighbor 10.0.0.8 (AS 65002) has 3 prefixes received (State/PfxRcd = 3). Since the command 'show ip bgp vpnv4 all summary' specifically displays VPNv4 address family information, these received prefixes are VPNv4 routes. Therefore, Router R6 is successfully receiving VPNv4 prefixes from both BGP neighbors.

Exam trap

Cisco often tests the misinterpretation of the 'State/PfxRcd' column, where candidates mistakenly think a numeric value indicates a state like 'Idle' or 'Active', rather than recognizing it as the count of received prefixes confirming an Established session.

How to eliminate wrong answers

Option A is wrong because both neighbors show an Up/Down time (00:20:00 and 00:10:00) and a numeric State/PfxRcd value, indicating the sessions are in the Established state, not Idle. Option C is wrong because the BGP table version being 10 indicates the table has been updated and is stable; the output explicitly shows '10 network entries' and '10 path entries', proving the BGP table has entries. Option D is wrong because neighbor 10.0.0.8 shows 3 prefixes received (State/PfxRcd = 3) under the VPNv4 summary, confirming it is configured for VPNv4 and is actively exchanging VPNv4 routes.

307
MCQhard

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-POLICY Class-map: ICMP-CLASS (match-all) 10 packets, 1000 bytes 5 minute offered rate 0 bps Match: access-group name ICMP-ACL police: cir 8000 bps, bc 1500 bytes, be 1500 bytes conformed 10 packets, 1000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: SSH-CLASS (match-all) 5 packets, 500 bytes 5 minute offered rate 0 bps Match: access-group name SSH-ACL police: cir 16000 bps, bc 3000 bytes, be 3000 bytes conformed 5 packets, 500 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: class-default (match-any) 20 packets, 2000 bytes 5 minute offered rate 0 bps Match: any police: cir 64000 bps, bc 8000 bytes, be 8000 bytes conformed 20 packets, 2000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Based on this output, what can be concluded?

A.ICMP traffic to the control plane is rate-limited to 8 kbps, and all packets so far have been within the conform rate.
B.SSH traffic to the control plane is being dropped because it exceeds the CIR.
C.The control-plane policy is applied in the output direction.
D.All traffic to the control plane is rate-limited to 64 kbps.
AnswerA

The output for the ICMP class shows a police CIR of 8000 bps, and the conformed counter equals the total packet count while the exceeded/dropped counter is zero. This means every ICMP packet destined to the control plane was measured as within the committed information rate and was marked conform, so the packets were transmitted normally rather than rate-limited further. The correct statement identifies both the configured rate and the observed behavior: rate-limited to 8 kbps, but with no actual drops because traffic never exceeded the conform burst. This is supported by the 'police' configuration and the accumulated conformed/exceeded statistics in the control-plane policy output.

Why this answer

The output shows that for the ICMP-CLASS, the police command sets a CIR of 8000 bps (8 kbps). The counters show 10 packets conformed and 0 packets exceeded or violated, meaning all ICMP traffic to the control plane has been within the conform rate and transmitted. This directly confirms that ICMP traffic is rate-limited to 8 kbps and has not yet exceeded that limit.

Exam trap

Cisco often tests the misconception that the class-default police rate applies to all traffic, but in CoPP, each class-map has its own independent police rate, and only traffic not matching explicit classes falls into class-default.

How to eliminate wrong answers

Option B is wrong because the output shows 0 exceeded and 0 violated packets for SSH-CLASS, indicating no SSH traffic has been dropped due to exceeding the CIR; all 5 packets were conformed and transmitted. Option C is wrong because the command 'show policy-map control-plane' and the output line 'Service-policy input: CoPP-POLICY' explicitly show the policy is applied in the input direction, not output. Option D is wrong because the 64 kbps police rate applies only to the class-default catch-all class, not to all traffic; ICMP and SSH have their own separate police rates (8 kbps and 16 kbps respectively), so not all traffic is rate-limited to 64 kbps.

308
Multi-Selecthard

Which three statements about policing and shaping are true? (Choose three.)

Select 3 answers
A.Policing can be applied in both the inbound and outbound directions on an interface.
B.Shaping buffers excess packets and may introduce additional delay.
C.Policing uses a token bucket algorithm to measure traffic rates.
D.Shaping can be applied inbound to limit traffic entering an interface.
E.Policing always drops packets that exceed the configured rate and never re-marks them.
AnswersA, B, C

Correct because policing is supported on both input and output directions in Cisco IOS.

Why this answer

Policing drops or re-marks traffic exceeding a rate and does not buffer, while shaping buffers and smooths traffic to a lower rate. Both use token bucket algorithms. Shaping introduces delay but reduces drops, whereas policing can cause TCP retransmissions due to drops.

Policing can be applied inbound or outbound, shaping typically outbound.

309
MCQhard

A network engineer is configuring a Cisco IOS XE router to support NETCONF over SSH for automated configuration. The management application requires that the router expose a standards-based data model and that configuration changes be applied as complete, atomic transactions. Which action must the engineer take?

A.Configure SNMPv3 with authPriv and use SET operations to push the configuration
B.Enable the NETCONF-YANG feature with the netconf-yang command and use the candidate datastore with the commit operation
C.Enable the guest shell and run Python scripts that call the CLI parser for configuration
D.Enable the RESTCONF API with the ip http secure-server command and use the YANG models exposed there
AnswerB

The netconf-yang command enables NETCONF over SSH on port 830 and activates the Cisco IOS XE YANG data models. Using the candidate datastore allows a client to stage edits and then apply them with a commit, which provides atomic transaction semantics: either all changes apply or none do. This directly satisfies the standards-based model and atomic commit requirements described.

Why this answer

NETCONF over SSH is enabled on Cisco IOS XE with the netconf-yang command, which starts the NETCONF server on TCP 830 and loads the YANG models. The candidate datastore plus commit gives transactional behavior: changes are staged, validated, and applied atomically, with rollback possible on failure. This is the standards-based, model-driven approach the automation application requires.

Exam trap

The trap here is confusing model-driven programmability transports, assuming that enabling RESTCONF or the guest shell provides the same atomic NETCONF transaction behavior over SSH.

310
Multi-Selectmedium

Which three statements about REST API authentication and security are true? (Choose three.)

Select 3 answers
A.Token-based authentication typically uses the HTTP Authorization header to pass the token.
B.HTTPS is recommended for REST APIs to ensure data encryption in transit.
C.API keys provide the same level of security as OAuth 2.0 tokens.
D.Basic authentication over HTTP is secure because the credentials are base64-encoded.
E.OAuth 2.0 is an authorization framework that can be used for REST API access.
AnswersA, B, E

Token-based authentication conveys credentials as a bearer token inside the HTTP Authorization request header, letting the API validate the caller without server-side session state. This satisfies the stem's requirement for a true REST API security statement.

Why this answer

Option A is correct because token-based authentication (e.g., Bearer tokens) conventionally transmits the token in the HTTP Authorization header, such as 'Authorization: Bearer <token>', allowing the server to validate the caller's identity on each request. Option B is correct because HTTPS (HTTP over TLS) encrypts data in transit, protecting credentials, tokens, and payloads from eavesdropping and man-in-the-middle attacks, and is a baseline recommendation for any REST API. Option E is correct because OAuth 2.0 is an authorization framework that issues access tokens with defined scopes, enabling delegated, limited access to REST API resources without sharing user credentials.

Option C is incorrect because API keys are simple static identifiers with no built-in scoping, expiration, or delegation, so they do not provide the same security level as OAuth 2.0 tokens. Option D is incorrect because base64 encoding is not encryption; Basic authentication over HTTP exposes credentials in easily decodable form and is only safe when layered over HTTPS.

Exam trap

The trap is thinking API keys are as secure as OAuth tokens, or that base64 encoding provides security, which it does not.

311
Multi-Selectmedium

Which two statements about queuing and congestion management are true? (Choose two.)

Select 2 answers
A.CBWFQ allows you to define multiple classes and assign each a guaranteed minimum bandwidth.
B.LLQ combines a strict priority queue with CBWFQ classes to support real-time traffic.
C.Weighted Fair Queuing (WFQ) is the default queuing mechanism on all Cisco router interfaces.
D.Tail drop is the only drop policy available for CBWFQ queues.
E.FIFO queuing provides per-class bandwidth guarantees.
AnswersA, B

Correct because CBWFQ allocates bandwidth to each class based on the 'bandwidth' command.

Why this answer

CBWFQ provides guaranteed bandwidth to classes, while LLQ adds a strict priority queue for delay-sensitive traffic. WFQ is the default on low-speed interfaces. FIFO is used on high-speed interfaces by default.

Tail drop is the default drop policy for FIFO and CBWFQ queues.

312
MCQmedium

A network engineer is implementing VXLAN on a Cisco Nexus 9000 series switch running NX-OS. The underlay network uses OSPF and the loopback0 interface of each VTEP is advertised. The engineer wants to verify that the VXLAN tunnel endpoints can communicate. Which command should be used to check the VXLAN tunnel status?

A.show interface tunnel
B.show vxlan interface
C.show nve peers
D.show ip ospf neighbor
AnswerC

The 'show nve peers' command displays the state of VXLAN tunnel endpoints (VTEPs) and their peer relationships. It shows the IP address of each peer, the VNI, and the state (Up/Down). This directly verifies if VTEPs can communicate over the underlay, which is essential for VXLAN operation.

Why this answer

The 'show nve peers' command is the correct way to verify VXLAN tunnel endpoint communication. It provides details about peer VTEPs, including their IP addresses and state. This command is essential for troubleshooting VXLAN overlay connectivity, as it directly shows whether tunnels are established and operational.

Exam trap

The trap here is assuming that OSPF neighbor adjacency guarantees VXLAN tunnel establishment, but underlay routing and overlay tunnels are separate and must be verified independently.

313
MCQeasy

A company is deploying a virtualized network function (VNF) for a Cisco CSR1000v router on a VMware vSphere hypervisor. The architect must choose the hypervisor type to ensure the best performance for the VNF. Which hypervisor type is VMware vSphere classified as, and why is it suitable for VNF deployment?

A.Type 2 hypervisor; it runs on top of an operating system, providing flexibility for VNF management.
B.Type 1 hypervisor; it runs directly on the hardware, offering near-native performance for VNFs.
C.Type 1 hypervisor; it requires a host OS for management, adding overhead.
D.Type 2 hypervisor; it is embedded in the hardware firmware.
AnswerB

The correct answer is a Type 1 hypervisor because it runs directly on the physical hardware, giving VNFs direct access to CPU, memory, and NIC queues. This architecture minimizes latency and enables high-performance features like SR-IOV and DPDK, which are critical for SD-WAN edge devices handling real-time traffic. Cisco SD-WAN virtual appliances (vEdge, vSmart) are validated on ESXi and KVM, both Type 1 hypervisors, to guarantee near-native packet forwarding.

Why this answer

VMware vSphere is a Type 1 (bare-metal) hypervisor because it installs directly onto the physical server hardware without requiring a host operating system. This architecture eliminates OS overhead, allowing the Cisco CSR1000v VNF to achieve near-native performance for packet processing and routing functions, which is critical for meeting throughput and latency requirements in SD-WAN deployments.

Exam trap

Cisco often tests the distinction between Type 1 and Type 2 hypervisors by pairing the correct classification with a misleading justification (e.g., 'requires a host OS' for Type 1), so candidates must remember that Type 1 hypervisors run directly on hardware and do not rely on a general-purpose OS for core operations.

How to eliminate wrong answers

Option A is wrong because VMware vSphere is not a Type 2 hypervisor; Type 2 hypervisors (e.g., VMware Workstation) run on top of a host OS, which adds latency and resource contention unsuitable for production VNFs. Option C is wrong because Type 1 hypervisors like vSphere do not require a host OS for management—they include a built-in management partition (e.g., VMkernel) that handles resource scheduling and I/O directly, minimizing overhead. Option D is wrong because Type 2 hypervisors are not embedded in hardware firmware; that describes a hypervisor integrated into the system firmware (e.g., some embedded hypervisors), and vSphere is a software-installed Type 1 hypervisor, not firmware-based.

314
MCQeasy

A network engineer needs to provide secure remote-access VPN connectivity for employees using Cisco AnyConnect. The requirement is to use digital certificates issued by the corporate PKI for both server and client authentication. Which component must be configured on the Cisco ASA to validate client certificates presented during the VPN session?

A.A trustpoint containing the CA certificate that signed the client certificates.
B.A local user account with the privilege level 15 assigned.
C.An IKEv2 pre-shared key configured under the tunnel group.
D.An LDAP attribute map for group policy assignment.
AnswerA

To validate client certificates, the ASA must trust the issuing CA. A trustpoint holds the CA certificate and enables the ASA to verify the certificate chain presented by AnyConnect clients. Without this trustpoint, the ASA cannot confirm the client certificate is genuine, so it is the required configuration for certificate-based client authentication.

Why this answer

Certificate-based client authentication requires the ASA to trust the CA that issued the client certificates. Configuring a trustpoint with the CA certificate allows the ASA to validate the chain presented by AnyConnect. Pre-shared keys, local user accounts, and LDAP attribute maps do not perform certificate validation and therefore cannot fulfill the PKI-based authentication requirement.

Exam trap

The trap here is assuming any authentication configuration, such as a local user or LDAP map, will validate certificates, when only a trustpoint containing the issuing CA certificate enables certificate chain validation.

315
MCQhard

A security team wants to deploy MACsec on a Cisco Catalyst switch uplink between two buildings to protect Layer 2 traffic. The switches are Cisco Catalyst 9300 series running IOS XE, and the link must encrypt all frames between them. Which statement accurately describes a requirement for this deployment?

A.MACsec can only be enabled on routed ports, so the uplink must be converted from a switchport to a no switchport interface.
B.MACsec requires that both switches support the MACsec feature and that a connectivity association key be configured or negotiated before encrypted traffic can flow.
C.MACsec encrypts only control plane traffic, so data frames between the switches would remain in clear text.
D.MACsec requires that 802.1X authentication be completed on the link before any encryption keys can be generated.
AnswerB

MACsec uses a secure connectivity association defined by a connectivity association key (CAK) and connectivity association key name (CKN), either pre-shared or negotiated via MKA. Both endpoints must support MACsec and agree on keys before encrypted frames can be exchanged. This matches the requirement to protect all Layer 2 traffic on the uplink between the two Catalyst switches.

Why this answer

MACsec secures Layer 2 links by encrypting frames using keys derived from a connectivity association. Both endpoints must support MACsec and share matching key material, either pre-shared or via MKA. This allows the uplink between the Catalyst switches to carry encrypted traffic, meeting the requirement to protect all frames on that link.

Exam trap

The trap here is believing MACsec requires 802.1X or routed ports, when in fact it needs matching key material and MACsec-capable endpoints on the Layer 2 link.

316
MCQeasy

A network engineer is implementing QoS on a WAN link to prioritize voice traffic. Which queuing mechanism provides the lowest latency for real-time traffic?

A.Low Latency Queuing (LLQ)
B.Weighted Random Early Detection (WRED)
C.Class-Based Weighted Fair Queuing (CBWFQ)
D.First-In, First-Out (FIFO)
AnswerA

Low Latency Queuing (LLQ) is correct because it integrates a strict priority queue (PQ) with CBWFQ. The LLQ scheduler always empties the priority class before servicing any other CBWFQ class, which guarantees that real-time packets like voice are dequeued first and experience minimal, jitter-free delay. To prevent the PQ from starving other classes, LLQ applies a policer to priority-class traffic, dropping or shaping excess packets while still meeting the latency objective for admitted real-time flows.

Why this answer

LLQ is correct because it combines strict priority queuing with CBWFQ, ensuring that voice traffic (marked with EF or CS5) is dequeued before any other traffic class. This strict priority mechanism guarantees the lowest possible latency for real-time traffic, as packets in the priority queue are always transmitted first, regardless of congestion on the WAN link.

Exam trap

The trap here is that candidates often confuse CBWFQ with LLQ, assuming that CBWFQ's bandwidth allocation provides low latency, but CBWFQ lacks a strict priority queue and cannot guarantee the sub-10ms jitter required for real-time voice traffic.

How to eliminate wrong answers

Option B is wrong because WRED is a congestion avoidance mechanism that drops packets probabilistically before the queue is full, but it does not provide any latency guarantee or priority treatment for real-time traffic. Option C is wrong because CBWFQ provides bandwidth guarantees for different traffic classes but does not include a strict priority queue; all classes share the link based on weights, which can introduce jitter and delay for voice. Option D is wrong because FIFO is a simple first-come-first-served queuing mechanism with no differentiation or priority, leading to unpredictable latency and packet loss for real-time traffic during congestion.

317
MCQhard

A network engineer issues the following command on Router R6: R6# show ip nat translations Pro Inside global Inside local Outside local Outside global --- 192.168.1.100 10.0.0.10 --- --- --- 192.168.1.101 10.0.0.11 --- --- udp 192.168.1.100:1234 10.0.0.10:1234 203.0.113.5:53 203.0.113.5:53 tcp 192.168.1.101:80 10.0.0.11:80 198.51.100.2:443 198.51.100.2:443 Based on this output, what is true about the NAT translations?

A.All translations are static NAT entries.
B.The translation for 10.0.0.10 to 192.168.1.100 is a dynamic NAT without PAT.
C.The router is performing only PAT (overload).
D.The outside global address is the same for all translations.
AnswerB

The translation for 10.0.0.10 to 192.168.1.100 appears in the show ip nat translations output without any protocol or port information, meaning the mapping is a pure IP-to-IP rewrite. That is the signature of a dynamic NAT translation taken from a pool without the overload keyword, not a PAT entry. It is dynamic because the router instantiated it on the first packet from 10.0.0.10 and will remove it after the idle timeout expires, unlike a static entry that is always present.

Why this answer

The output shows two static-like entries (the first two lines with no protocol or port) and two dynamic entries with PAT (the UDP and TCP lines). The first translation for 10.0.0.10 to 192.168.1.100 has no protocol or port information, indicating it is a dynamic NAT entry without PAT (port address translation), because PAT would show specific ports. Option B correctly identifies this translation as dynamic NAT without PAT.

Exam trap

Cisco often tests the distinction between dynamic NAT without PAT and PAT by showing entries with and without port numbers, leading candidates to mistakenly assume all entries are PAT or all are static when the output contains a mix.

How to eliminate wrong answers

Option A is wrong because the presence of protocol/port entries (UDP and TCP) and the absence of '---' in all fields indicates dynamic translations with PAT, not static NAT; static NAT entries would show a fixed one-to-one mapping without port variation. Option C is wrong because the first two entries have no protocol or port, meaning PAT is not applied to those translations; the router is performing both dynamic NAT (without PAT) and PAT (with overload) simultaneously. Option D is wrong because the outside global addresses differ: 203.0.113.5 for the UDP entry and 198.51.100.2 for the TCP entry, and the first two entries have no outside global address listed.

318
MCQeasy

A network engineer is writing a Python script to interact with a Cisco IOS XE device using RESTCONF. The engineer wants to retrieve the current configuration of a specific interface. Which HTTP method and URI should be used?

A.PUT https://<device>/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1
B.POST https://<device>/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1
C.GET https://<device>/restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1
D.GET https://<device>/restconf/data/ietf-interfaces:interfaces/interface/GigabitEthernet1
AnswerC

RESTCONF uses the GET method to retrieve data. The URI path /restconf/data/ietf-interfaces:interfaces/interface=GigabitEthernet1 correctly targets a specific interface using the YANG model ietf-interfaces. This is the standard way to read configuration data via RESTCONF. The other methods and URIs are either incorrect HTTP verbs or malformed paths.

Why this answer

To retrieve configuration data via RESTCONF, the GET method must be used with a URI that correctly identifies the resource. The URI must follow the RESTCONF syntax for list keys, which uses key=value. The correct option uses GET and the proper URI format to access the specific interface.

The other options use incorrect HTTP methods or malformed URIs, which would not retrieve the desired data.

Exam trap

The trap here is mixing up HTTP methods or using the wrong syntax for list keys; RESTCONF requires key=value, not key/value.

319
MCQmedium

Given the following configuration: interface GigabitEthernet0/0 ip address 10.1.1.1 255.255.255.0 ip pim sparse-mode ip igmp version 3 What is the purpose of the 'ip igmp version 3' command?

A.It enables IGMP version 3, which allows hosts to join multicast groups from specific sources, supporting SSM.
B.It enables IGMP version 3, which increases the number of multicast groups supported to 1024.
C.It enables IGMP version 3, which is required for PIM dense-mode operation.
D.It enables IGMP version 3, which disables IGMP snooping on the interface.
AnswerA

IGMPv3 introduces source-specific membership (INCLUDE/EXCLUDE) messages, allowing hosts to explicitly request traffic from a particular source (S,G). This is the foundation of SSM, where the recipient signals a join for a specific source and group, and the router can then forward multicast traffic exclusively from that source. Without IGMPv3, SSM cannot function because legacy IGMPv1/v2 reports are group-only and lack source selection.

Why this answer

The 'ip igmp version 3' command enables IGMPv3 on the interface, which supports Source-Specific Multicast (SSM) by allowing hosts to specify both the multicast group and the source address in their membership reports. This is essential for SSM operation with PIM sparse-mode, as IGMPv3 provides the source filtering capability that IGMPv2 lacks.

Exam trap

Cisco often tests the misconception that IGMPv3 is simply a 'newer version' with generic improvements, when in fact its key differentiator is source-specific filtering for SSM support.

How to eliminate wrong answers

Option B is wrong because IGMP version 3 does not define a limit of 1024 multicast groups; the number of supported groups depends on hardware resources and platform, not the IGMP version. Option C is wrong because IGMPv3 is not required for PIM dense-mode; PIM dense-mode can operate with IGMPv1 or IGMPv2, and IGMPv3 is specifically associated with PIM sparse-mode and SSM. Option D is wrong because 'ip igmp version 3' does not disable IGMP snooping; IGMP snooping is a Layer 2 feature controlled by separate commands (e.g., 'ip igmp snooping') and is independent of the IGMP version configured on the interface.

320
MCQmedium

Router R3 has the following OSPF configuration: router ospf 1 router-id 3.3.3.3 network 10.0.0.0 0.255.255.255 area 0 default-information originate always metric 20 metric-type 2 What is the effect of the 'default-information originate always' command?

A.It redistributes all connected routes into OSPF.
B.It injects a default route into OSPF only if a default route is present in the routing table.
C.It injects a default route into OSPF unconditionally, with metric 20 and type E2.
D.It sets the OSPF router ID to 3.3.3.3 and enables default route filtering.
AnswerC

This is correct because the command uses the 'always' keyword to unconditionally originate a default route into the OSPF domain, and the explicit 'metric 20' and 'metric-type 2' keywords dictate the cost and external type of that route. The resulting LSA is an external type 2 (E2) route with a metric of 20, which will be advertised to all OSPF neighbors. No default route needs to exist in the local routing table for this advertisement to occur.

Why this answer

The 'default-information originate always' command injects a default route (0.0.0.0/0) into the OSPF link-state database unconditionally, regardless of whether the router itself has a default route in its routing table. The 'always' keyword overrides the default behavior, which requires a pre-existing default route. The metric 20 and metric-type 2 (E2) are explicitly set in the command, making the injected route an external type 2 route with a seed metric of 20.

Exam trap

Cisco often tests the distinction between the default behavior (inject only if a default route exists) and the 'always' keyword (unconditional injection), leading candidates to mistakenly think 'always' is required for any default route injection or that it modifies the metric behavior.

How to eliminate wrong answers

Option A is wrong because 'default-information originate' injects a default route, not all connected routes; redistributing connected routes requires the 'redistribute connected' command under OSPF. Option B is wrong because the 'always' keyword makes the injection unconditional; without 'always', the command would require a default route in the routing table, but with 'always' it does not. Option D is wrong because the 'router-id 3.3.3.3' is a separate configuration line that sets the OSPF router ID, and the 'default-information originate' command does not enable any filtering; it injects a default route.

321
Multi-Selecthard

Which three statements about the Multiple Spanning Tree Protocol (MSTP) are true? (Choose three.)

Select 3 answers
A.MSTP allows multiple VLANs to be mapped to a single spanning-tree instance.
B.MSTP uses an Internal Spanning Tree (IST) to interconnect MST regions.
C.MSTP is backward compatible with 802.1D and RSTP.
D.MSTP requires a separate spanning-tree instance for every VLAN.
E.MSTP uses a different BPDU format than RSTP.
AnswersA, B, C

MSTP maps many VLANs onto a single spanning-tree instance, so a handful of instances can serve hundreds of VLANs. This is the protocol's core efficiency gain over per-VLAN spanning tree, reducing bridge processing and control-plane load.

Why this answer

Option A is correct because MSTP (IEEE 802.1s) lets you group many VLANs into a single Multiple Spanning Tree Instance (MSTI), so one topology serves all VLANs mapped to it, greatly reducing the number of spanning-tree instances compared with PVST+. Option B is correct because MSTP builds an Internal Spanning Tree (IST) as instance 0, which carries the Common and Internal Spanning Tree (CIST) information and connects MST regions to each other and to other STP domains. Option C is correct because MSTP is designed to interoperate with 802.1D (classic STP) and 802.1w (RSTP) devices, treating them as part of the CIST so legacy switches can participate in the topology.

Option D is wrong because requiring one instance per VLAN describes PVST+/RPVST+, whereas MSTP's whole purpose is to map multiple VLANs to a single instance. Option E is wrong because MSTP uses the same RSTP-style BPDU format (with MSTP-specific extensions in the MSTI configuration messages), not a fundamentally different BPDU format.

Exam trap

350-401 often tests the misconception that MSTP requires one instance per VLAN (that's PVST+) or that it uses a unique BPDU format, when it actually reuses RSTP BPDUs with MSTP extensions.

322
MCQmedium

A network engineer is configuring a new Cisco Catalyst switch that will participate in a VTP domain. The switch must not be able to create, modify, or delete VLANs, but it must synchronize its VLAN database with the current VTP server. Which VTP mode should be configured on this switch?

A.VTP transparent mode
B.VTP off mode
C.VTP server mode
D.VTP client mode
AnswerD

VTP client mode allows the switch to receive and synchronize VLAN information from VTP servers but prevents it from creating, modifying, or deleting VLANs. This exactly matches the requirement: the switch cannot make VLAN changes but will stay synchronized with the VTP server.

Why this answer

VTP client mode is designed for switches that should receive VLAN configuration from VTP servers but not modify it. The switch will synchronize its VLAN database with advertisements from the server, ensuring consistency, while its configuration interface prevents local VLAN creation or deletion. This satisfies both constraints: no VLAN changes and synchronization with the server.

Exam trap

The trap here is confusing VTP transparent mode with client mode, thinking that transparent mode prevents VLAN changes while still synchronizing.

323
MCQhard

A network engineer is implementing VXLAN with a Cisco Nexus 9000 series switch acting as a VTEP. The engineer wants to ensure that the VXLAN traffic is encapsulated and forwarded correctly over the underlay network. Which statement describes the VXLAN encapsulation and forwarding process?

A.VXLAN encapsulates Layer 2 frames in UDP packets with a destination port of 4789, and the VTEP uses the overlay routing table to forward the encapsulated packet to the remote VTEP.
B.VXLAN encapsulates Layer 3 packets in UDP packets with a destination port of 4789, and the VTEP performs a lookup in the underlay routing table to forward the encapsulated packet to the remote VTEP.
C.VXLAN encapsulates Layer 2 frames in GRE tunnels, and the VTEP uses the underlay routing table to forward the encapsulated packet to the remote VTEP.
D.VXLAN encapsulates Layer 2 frames in UDP packets with a destination port of 4789, and the VTEP performs a lookup in the underlay routing table to forward the encapsulated packet to the remote VTEP.
AnswerD

VXLAN uses MAC-in-UDP encapsulation, with the outer UDP destination port typically set to 4789 (IANA-assigned). The VTEP encapsulates the original Layer 2 frame, adds an outer IP header with the source and destination VTEP addresses, and forwards the packet based on the underlay routing table. This allows Layer 2 segments to be stretched over a Layer 3 underlay.

Why this answer

VXLAN encapsulates original Layer 2 frames into UDP packets, with the outer UDP destination port typically 4789. The VTEP adds an outer IP header and forwards the packet based on the underlay network's routing table. This allows the overlay Layer 2 network to span across a Layer 3 underlay.

The encapsulation process preserves the original frame, and the underlay routing ensures the packet reaches the remote VTEP.

Exam trap

The trap here is confusing the overlay and underlay forwarding tables, or assuming VXLAN uses GRE encapsulation instead of UDP.

324
Matchinghard

Drag and drop each SD-WAN policy type on the left to its matching application point on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Applied on vSmart to influence OMP route and TLOC propagation

Applied on WAN edge routers to modify forwarding behavior (e.g., NAT, QoS)

Applied on WAN edge routers to steer traffic based on application and SLA

Applied on WAN edge routers to export NetFlow v9/IPFIX flow records

Applied on vSmart to control which VPNs are advertised to specific sites

Why these pairings

Control policies affect routing decisions; data policies affect forwarding; app-route policies affect per-tunnel path selection; cflowd policies enable traffic flow monitoring.

325
Matchingmedium

Drag and drop each syslog severity level on the left to its matching numeric value on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

0

1

2

3

4

Why these pairings

Syslog severity levels range from 0 (Emergency) to 7 (Debug).

326
MCQhard

A network engineer runs the following command on Router R5: R5# show ip route vrf CUSTOMER-A Routing Table: CUSTOMER-A Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2 i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route Gateway of last resort is 10.1.1.1 to network 0.0.0.0 10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks C 10.1.1.0/24 is directly connected, GigabitEthernet0/0 B 10.2.2.0/24 [20/0] via 10.1.1.1, 00:10:20 Based on this output, what can be concluded?

A.The VRF has no routes and is not functional.
B.The route 10.2.2.0/24 is learned via OSPF.
C.The VRF has a default route pointing to 10.1.1.1.
D.The BGP route is sourced from an internal BGP peer.
AnswerC

The VRF routing table shows a 'Gateway of last resort is 10.1.1.1' line, which indicates a default route of 0.0.0.0/0 is installed with next hop 10.1.1.1. This S* route means any destination not matching a more specific prefix will be sent to 10.1.1.1. Thus, the correct statement is that the VRF has a default route pointing to 10.1.1.1.

Why this answer

The output shows a VRF routing table with a gateway of last resort set to 10.1.1.1 for network 0.0.0.0, which is a default route. This indicates that the VRF has a default route pointing to 10.1.1.1, making option C correct. The presence of a connected route and a BGP-learned route further confirms the VRF is functional.

Exam trap

Cisco often tests the distinction between eBGP and iBGP by using administrative distance values; the trap here is that candidates may assume any BGP route is from an internal peer without checking the AD value, which for eBGP is 20 and for iBGP is 200.

How to eliminate wrong answers

Option A is wrong because the VRF has both a connected route (10.1.1.0/24) and a BGP-learned route (10.2.2.0/24), so it is functional. Option B is wrong because the route 10.2.2.0/24 is marked with 'B' in the routing table, which indicates it is learned via BGP, not OSPF. Option D is wrong because the BGP route shows an administrative distance of 20 and a metric of 0, which are typical for eBGP (external BGP) routes, not iBGP (internal BGP) routes; iBGP routes typically have an administrative distance of 200.

327
Multi-Selecthard

Which three statements about Cisco DNA Center Assurance are true? (Choose three.)

Select 3 answers
A.Cisco DNA Center Assurance uses streaming telemetry from devices to monitor network health in real time.
B.Cisco DNA Center Assurance can automatically remediate issues by changing device configurations.
C.Cisco DNA Center Assurance provides a client health score based on RF metrics, application performance, and connectivity.
D.Cisco DNA Center Assurance relies solely on SNMP polling for data collection.
E.Cisco DNA Center Assurance can proactively detect anomalies and send alerts before users are impacted.
AnswersA, C, E

Cisco DNA Center Assurance relies on model-driven streaming telemetry, where devices push operational data continuously rather than waiting for polling intervals. This satisfies the real-time network health monitoring requirement, delivering near-instant visibility into device and client state without the latency inherent in SNMP-based collection cycles.

Why this answer

Option A is correct because Cisco DNA Center Assurance collects streaming telemetry (model-driven telemetry, e.g., gRPC/telemetry subscriptions) from network devices to provide near real-time visibility into network health rather than relying only on periodic polling. Option C is correct because Assurance computes a client health score that aggregates RF metrics (RSSI, SNR, retries), onboarding/connectivity status, and application performance (via Application Experience) into a single 0-10 score. Option E is correct because Assurance uses machine learning and baseline analytics to proactively detect anomalies and raise issues/alerts before end users are impacted.

Option B is not correct because Assurance itself is a monitoring and analytics function; automated configuration changes are performed by separate DNA Center features such as SWIM, Plug and Play, or intent-based automation, not by Assurance remediation. Option D is not correct because Assurance does not rely solely on SNMP polling; it primarily uses streaming telemetry (with SNMP/syslog as supplementary sources), so 'solely' makes the statement false.

Exam trap

The trap here is confusing Assurance (monitoring/analytics) with DNA Center's automation capabilities — candidates often assume Assurance auto-remediates, but remediation is a separate workflow feature.

328
Matchingmedium

Drag and drop each queuing mechanism on the left to its matching feature on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

No classification, single queue, packets served in order of arrival

Automatically classifies flows and provides fair queuing per flow

Allows creation of custom traffic classes with guaranteed bandwidth

Adds a strict priority queue within CBWFQ for delay-sensitive traffic

Multiple queues with strict priority servicing, lower queues starve if higher queues are non-empty

Why these pairings

FIFO is the simplest queuing with no classification; WFQ provides fair bandwidth distribution; CBWFQ allows user-defined classes; LLQ adds a strict priority queue; PQ always services the highest-priority queue first.

329
Multi-Selectmedium

Which TWO of the following are valid methods to mitigate VLAN hopping attacks?

Select 2 answers
A.Configure switchport mode dynamic auto on all ports.
B.Disable Dynamic Trunking Protocol (DTP) on all access ports.
C.Set the native VLAN to VLAN 1 on all trunk ports.
D.Set the native VLAN to an unused VLAN ID on all trunk ports.
E.Use 802.1Q trunking instead of ISL.
AnswersB, D

Prevents trunk negotiation.

Why this answer

Disabling Dynamic Trunking Protocol (DTP) on all access ports prevents a switch port from automatically negotiating a trunk, which is the primary vector for VLAN hopping attacks. An attacker can spoof DTP messages to force a port into trunking mode, gaining access to multiple VLANs; disabling DTP eliminates this risk.

Exam trap

Cisco often tests the misconception that simply using 802.1Q trunking (Option E) or setting the native VLAN to VLAN 1 (Option C) provides security, when in fact the key mitigations are disabling DTP on access ports and using an unused native VLAN on trunk ports.

330
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP server for a subnet that also contains a DHCP relay agent. The router must ensure that DHCP clients receive the correct default gateway address of 10.1.1.1, which is the router's own interface on that subnet. Which command is required to accomplish this?

A.ip dhcp excluded-address 10.1.1.1
B.ip dhcp pool POOL1 followed by default-router 10.1.1.1
C.ip default-gateway 10.1.1.1 in global configuration mode
D.ip helper-address 10.1.1.1 under the router's interface
AnswerB

The default-router command inside the DHCP pool configuration specifies the default gateway address that clients receive. Since the router's interface on the subnet is 10.1.1.1, this command ensures clients are configured with that address as their gateway, which is essential for proper routing.

Why this answer

To provide DHCP clients with a default gateway, the network engineer must configure the default-router command within the DHCP pool. This command specifies the IP address of the gateway that clients will use to reach other networks. The other options are either for different purposes or do not configure the DHCP server to supply gateway information.

Exam trap

The trap here is confusing the ip helper-address command, which is used for DHCP relay, with the default-router command, which sets the gateway for DHCP clients.

331
Matchinghard

Drag and drop each BGP path selection criterion on the left to its order of preference (1 = highest priority) on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

1

2

3

4

5

Why these pairings

Weight (highest) is checked first, then LOCAL_PREF (highest), then locally originated routes, then AS_PATH (shortest), then ORIGIN (IGP < EGP < incomplete).

332
Multi-Selecthard

A network engineer is hardening a Cisco IOS XE router that terminates IPsec site-to-site tunnels with remote branches. The security policy requires that the router only accept IKEv2 negotiations using cryptographically strong parameters and that it validate peer identity via certificates issued by the corporate PKI. Which two configuration elements must the engineer apply to meet these requirements? (Choose two.)

Select 2 answers
A.Configure 'crypto ikev2 limit max-in-negotiation-sa 10' on the router to throttle aggressive IKEv2 negotiations.
B.Configure an IKEv2 proposal that includes aes-cbc-256 for encryption, sha512 for integrity, and group 19 for the DH key exchange.
C.Configure 'crypto ikev2 dpd 10 3 periodic' to detect dead peers and tear down stale SAs quickly.
D.Configure an IKEv2 keyring with pre-shared keys per peer and bind the keyring to the IKEv2 profile.
E.Configure an IKEv2 profile with 'authentication local rsa-sig' and 'authentication remote rsa-sig', and reference a PKI trustpoint that validates the corporate CA chain.
AnswersB, E

An IKEv2 proposal with aes-cbc-256, sha512, and DH group 19 (256-bit ECP) enforces cryptographically strong negotiation parameters. Only peers offering these algorithms can complete IKEv2 SA establishment, satisfying the strong-parameters half of the policy without weakening backward compatibility beyond the stated requirement.

Why this answer

Meeting the policy requires two things: an IKEv2 proposal that enforces strong encryption, integrity, and DH groups, and an IKEv2 profile that authenticates both local and remote peers with RSA signatures validated against the corporate PKI trustpoint. PSK keyrings, DPD timers, and SA throttling controls address other concerns and do not satisfy the cryptographic-strength or certificate-validation requirements.

Exam trap

The trap here is treating any IKEv2 hardening knob, such as DPD or SA limits, as equivalent to enforcing strong algorithms and certificate-based authentication.

333
MCQmedium

A network engineer runs the following command on Router R4: R4# show interfaces tunnel 0 Tunnel0 is up, line protocol is up Hardware is Tunnel Internet address is 10.0.0.4/30 MTU 17916 bytes, BW 100 Kbit/sec, DLY 50000 usec, reliability 255/255, txload 1/255, rxload 1/255 Encapsulation TUNNEL, loopback not set Keepalive not set Tunnel source 192.168.1.4, destination 192.168.2.4 Tunnel protocol/transport GRE/IP Key disabled, sequencing disabled Checksumming of packets disabled Last input never, output never, output hang never Last clearing of "show interface" counters never Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue: 0/0 (size/max) 5 minute input rate 0 bits/sec, 0 packets/sec 5 minute output rate 0 bits/sec, 0 packets/sec 0 packets input, 0 bytes, 0 no buffer Received 0 broadcasts (0 IP multicasts) 0 runts, 0 giants, 0 throttles 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort 0 packets output, 0 bytes, 0 underruns 0 output errors, 0 collisions, 0 interface resets 0 unknown protocol drops 0 output buffer failures, 0 output buffers swapped out Based on this output, what is true about this tunnel?

A.The tunnel is using IPsec encryption.
B.The tunnel is a GRE tunnel that is up and operational.
C.The tunnel is using MPLS over GRE.
D.The tunnel is down because there are no packets.
AnswerB

The tunnel interface is up/up, meaning the interface administrative state is up and the line protocol is up. The protocol is GRE/IP, which confirms a Generic Routing Encapsulation tunnel configured over an IP transport network. An operational GRE tunnel only requires the tunnel source/destination to be reachable and the tunnel mode to be set to GRE; the tunnel being up/up independently verifies that it is operational, regardless of traffic flow.

Why this answer

The output shows 'Tunnel protocol/transport GRE/IP', confirming this is a GRE tunnel. The interface status is 'up, line protocol is up', and the counters show zero errors, indicating the tunnel is fully operational. The lack of packet traffic does not indicate a failure; GRE tunnels can be up without active data flow.

Exam trap

Cisco often tests the misconception that a tunnel with zero packets or zero traffic is down, but the 'line protocol is up' status confirms it is operational regardless of traffic counters.

How to eliminate wrong answers

Option A is wrong because the output shows 'Key disabled, sequencing disabled, Checksumming of packets disabled' and no mention of IPsec (e.g., crypto map, transform set, or IPsec SA), so encryption is not in use. Option C is wrong because there is no indication of MPLS labels or MPLS over GRE (which would require additional configuration like 'tunnel mode mpls' or 'mpls ip' on the tunnel); the output explicitly states 'GRE/IP'. Option D is wrong because the tunnel is up (line protocol is up) and zero packets do not indicate a down state; tunnels can be operational without traffic.

334
MCQmedium

A network administrator is deploying Cisco TrustSec in a campus network. The security team wants to enforce role-based access control between endpoints without relying on IP addresses or VLANs, and they need to ensure that access policies are consistently applied even when endpoints move between switches. The administrator has already configured Cisco ISE for authentication and authorization. Which technology should be used to propagate the security group tag (SGT) information to network devices that do not support SGT tagging natively?

A.MACsec (802.1AE)
B.IPsec VPN tunnels
C.SXP (SGT Exchange Protocol)
D.802.1X with EAP-TLS
AnswerC

SXP is a Cisco TrustSec protocol that propagates SGT-to-IP mappings to network devices that cannot natively tag packets with SGTs. It allows enforcement of security group ACLs (SGACLs) on devices that lack hardware SGT support by exchanging IP-to-SGT bindings with peer devices. This enables consistent policy enforcement across mixed hardware, which matches the scenario's requirement for propagation to non-SGT-capable devices.

Why this answer

SXP is designed to share SGT-to-IP bindings with devices that cannot natively tag packets with SGTs, enabling consistent role-based access control across mixed hardware. The other options either provide encryption, authentication, or tunneling but do not propagate SGT information. In a Cisco TrustSec deployment where some switches lack hardware SGT support, SXP bridges the gap so that SGACLs can still be enforced based on the endpoint's security group.

Exam trap

The trap here is confusing SGT propagation with SGT enforcement or authentication, assuming that any security feature can carry SGT information when only SXP is designed for that purpose.

335
MCQeasy

Which QoS mechanism is used to prevent congestion by dropping packets before a queue becomes full?

A.Weighted Random Early Detection (WRED)
B.Priority Queuing (PQ)
C.Class-Based Weighted Fair Queuing (CBWFQ)
D.Tail Drop
AnswerA

WRED monitors average queue depth and probabilistically drops packets once the minimum threshold is crossed, signalling TCP senders to slow down before the queue fills completely. This proactive congestion avoidance differs from tail drop, which discards only when the queue is already full.

Why this answer

Weighted Random Early Detection (WRED) is a congestion avoidance mechanism that proactively drops packets before a queue becomes full. By monitoring the average queue depth and dropping packets with a probability that increases as the queue depth grows, WRED signals TCP senders to reduce their transmission rate, thereby preventing tail drop and global synchronization. This differs from congestion management mechanisms like PQ or CBWFQ, which only act on packets after the queue is full.

Exam trap

Cisco often tests the distinction between congestion management (queuing/scheduling) and congestion avoidance (drop policy), so the trap here is that candidates confuse mechanisms like CBWFQ or PQ (which manage queues after they form) with WRED (which prevents queues from filling up in the first place).

How to eliminate wrong answers

Option B is wrong because Priority Queuing (PQ) is a congestion management mechanism that services queues in strict priority order, not a congestion avoidance mechanism; it does not drop packets before the queue is full. Option C is wrong because Class-Based Weighted Fair Queuing (CBWFQ) is a scheduling mechanism that allocates bandwidth to classes and queues packets, but it does not proactively drop packets to prevent congestion. Option D is wrong because Tail Drop is a passive congestion management mechanism that drops packets only when the queue is completely full, which can cause global TCP synchronization and does not prevent congestion by dropping packets early.

336
Matchingmedium

Drag and drop each protocol on the left to its matching characteristic on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Uses UDP transport; Encrypts only the password in the packet; Combines authentication and authorization into one process

Uses TCP transport; Encrypts the entire packet payload

Why these pairings

RADIUS uses UDP, encrypts only the password, and combines authentication and authorization. TACACS+ uses TCP, encrypts the entire packet, and separates authentication, authorization, and accounting.

337
MCQhard

A network architect is designing a Cisco SD-Access fabric that spans two buildings. The fabric must support Layer 2 extension for a legacy application that requires broadcast traffic to reach hosts in both buildings. The architect plans to use a single fabric with two fabric edge nodes connected to a common control plane node. Which component of the SD-Access architecture is responsible for mapping endpoint identifiers to fabric edge nodes?

A.Fabric intermediate node
B.Control plane node
C.Fabric border node
D.Fabric wireless controller
AnswerB

The control plane node runs the LISP map-server and map-resolver functions, maintaining the database that maps endpoint identifiers (EIDs) to routing locators (RLOCs), which are the fabric edge nodes. When a fabric edge needs to reach an endpoint, it queries the control plane node to learn which edge node is authoritative for that endpoint, enabling proper forwarding.

Why this answer

The control plane node hosts the LISP map-server and map-resolver, which together maintain the EID-to-RLOC mappings that tell fabric edge nodes where each endpoint is located. This mapping is essential for directing traffic to the correct edge node within the SD-Access fabric.

Exam trap

The trap here is assuming that the border node handles all inter-node communication, when in fact the control plane node is the authoritative source for endpoint location mappings.

338
MCQmedium

A network engineer must protect the OSPF adjacency between two Cisco routers from spoofed hello packets injected by a rogue device on the same broadcast segment. The engineer wants to use a cryptographic authentication method that is natively supported by OSPFv2 and does not rely on plain-text key exchange. Which configuration should be applied to the interfaces?

A.ip ospf authentication-key <key>
B.ip ospf authentication key-chain <name>
C.ip ospf authentication message-digest and ip ospf message-digest-key 1 md5 <key>
D.ip ospf authentication null
AnswerC

OSPFv2 message-digest authentication uses MD5 to hash the key and packet contents, so the key is never sent in cleartext. Configuring ip ospf authentication message-digest enables cryptographic authentication on the interface, and ip ospf message-digest-key 1 md5 supplies the key material. Neighbors must share the same key ID and key string for the adjacency to form, which satisfies the requirement to protect against spoofed hellos.

Why this answer

OSPFv2 supports two authentication types: simple password and message-digest (MD5). Only message-digest provides cryptographic protection, because it hashes the packet with a shared key rather than transmitting the key. Enabling ip ospf authentication message-digest on the interface plus defining ip ospf message-digest-key with an MD5 key ensures hellos are authenticated and spoofed packets from a rogue host are rejected before the adjacency can be affected.

Exam trap

The trap here is assuming that any OSPF authentication command provides cryptographic protection, when simple password authentication transmits the key in cleartext and offers no real defense.

339
MCQmedium

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs and is managed over SSH. The administrator needs to protect the route processor from excessive BGP and SSH traffic without breaking the existing sessions. Which action should be taken when applying the CoPP policy?

A.Apply the policy-map to the control-plane interface using the service-policy input command.
B.Apply the policy-map to the management VRF interface using service-policy input.
C.Apply the policy-map globally with the service-policy command in global configuration mode.
D.Apply the policy-map to each ISP-facing physical interface with service-policy output.
AnswerA

CoPP policies are applied to the control plane by attaching the policy-map to the control-plane interface with service-policy input. This filters traffic destined to the route processor while allowing transit traffic to pass untouched, which preserves the BGP and SSH sessions.

Why this answer

CoPP is designed to classify and police traffic destined to the route processor. The policy-map must be attached to the control-plane interface with service-policy input so that only CPU-bound traffic is policed while transit traffic remains unaffected, preserving BGP peering and SSH management access.

Exam trap

The trap here is assuming CoPP is applied to physical interfaces like a normal QoS policy, when it must be attached to the control-plane interface.

340
Multi-Selectmedium

Which three statements about DHCP snooping are true? (Choose three.)

Select 3 answers
A.DHCP snooping is configured on Layer 2 switches to filter DHCP messages on untrusted ports.
B.The DHCP snooping binding table includes the client MAC address, IP address, lease time, VLAN, and port number.
C.Ports connected to DHCP servers should be configured as trusted ports.
D.The DHCP snooping binding database is stored in NVRAM by default.
E.DHCP snooping validates DHCPv6 messages by default when enabled globally.
AnswersA, B, C

DHCP snooping operates at Layer 2, intercepting DHCP messages arriving on untrusted ports and dropping server-sourced offers, ACKs and NAKs that would otherwise reach clients. Configuring it on access switches satisfies the stem's requirement to filter rogue DHCP traffic before it crosses the broadcast domain, which a Layer 3 device could not do at frame level.

Why this answer

Option A is correct because DHCP snooping is a Layer 2 switch security feature that inspects DHCP messages and filters them on untrusted ports, blocking unauthorized DHCP server replies such as rogue offers. Option B is correct because the DHCP snooping binding table records the client MAC address, leased IP address, lease time, VLAN, and ingress port, which is exactly the information used for subsequent IP-to-MAC enforcement. Option C is correct because ports facing legitimate DHCP servers (or uplinks toward them) must be configured as trusted so their DHCP OFFER/ACK messages are not dropped, while host-facing ports remain untrusted.

Option D is not correct because the binding database is held in memory and is not stored in NVRAM by default; persistence requires explicit configuration such as a database agent or file. Option E is not correct because DHCP snooping is an IPv4 DHCP feature, and DHCPv6 snooping/guard must be enabled separately rather than being validated by default when DHCP snooping is enabled globally.

Exam trap

The trap is assuming the binding database is persistent by default (it is not) and assuming DHCP snooping covers DHCPv6 automatically (it does not; DHCPv6 snooping is a separate feature).

341
MCQmedium

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and SNMP. The administrator needs to verify which traffic classes are being matched and how many packets are being dropped by the policy. Which command should be used to display the CoPP policy statistics and class-map information?

A.show policy-map interface
B.show class-map
C.show policy-map control-plane
D.show control-plane host open-ports
AnswerC

This command displays the Control Plane policy-map configuration and the per-class packet statistics, including matched and dropped packets. It directly shows which traffic classes are being matched and how many packets are being dropped, which is exactly what the administrator needs to verify CoPP operation.

Why this answer

The show policy-map control-plane command is specifically designed to display the CoPP policy configuration and per-class statistics, including matched and dropped packets. It allows the administrator to verify which traffic classes are being matched and how many packets are being dropped by the policy. The other commands either show only class-map definitions or interface-level policy statistics, which are not relevant to the control plane.

Exam trap

The trap here is confusing interface-level policy statistics with control plane policy statistics, or assuming that show class-map displays counters when it only shows match criteria.

342
MCQhard

A network engineer is troubleshooting a Cisco SD-WAN deployment where some branches experience intermittent packet loss. The engineer suspects that the issue is related to the control plane connections between vEdge routers and the vSmart controller. Which command should be used on a vEdge router to verify the status of the control connections?

A.show bfd sessions
B.show interface
C.show control connections
D.show omp sessions
AnswerC

The 'show control connections' command displays the state of control plane connections between the vEdge router and vSmart controllers, including uptime, local and remote IPs, and status. This directly helps verify if the control plane is stable, which is crucial for diagnosing intermittent packet loss due to control plane issues.

Why this answer

The 'show control connections' command on a vEdge router provides detailed information about the control plane connections to vSmart controllers, including state, uptime, and any errors. Since the engineer suspects control plane instability causing intermittent packet loss, this command is the most direct way to verify the status and health of those connections.

Exam trap

The trap here is assuming that OMP session status alone is sufficient to diagnose control plane issues, when the underlying control connection state must also be verified.

343
Matchingmedium

Match each network automation tool to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Agentless automation using YAML playbooks

Agent-based configuration management using Puppet DSL

Agent-based using Ruby recipes

Agent-based with remote execution

Standard for network configuration and state data

Why these pairings

Correct matches: Ansible is agentless and uses SSH/YAML; Puppet uses client-server with DSL; Chef uses server and Ruby DSL; SaltStack uses master-minion and can be agentless. Common confusions involve mixing agentless and agent-based models.

344
Multi-Selectmedium

Which three statements about RADIUS server configuration and operation are true? (Choose three.)

Select 3 answers
A.The default UDP port for RADIUS authentication is 1812.
B.The shared secret configured on the Cisco device must match the shared secret on the RADIUS server.
C.The 'radius-server host' command can include an optional 'key' parameter to specify the shared secret.
D.RADIUS uses TCP to ensure reliable delivery of authentication packets.
E.If no port is specified, RADIUS uses port 1645 for authentication by default.
AnswersA, B, C

RADIUS authentication traditionally used UDP 1645, but RFC 2865 reassigned it to UDP 1812, with accounting on 1813. Cisco devices default to 1812 for authentication, making this the standard port for access-request and access-challenge exchanges.

Why this answer

Option A is correct because RADIUS authentication uses UDP port 1812 by default (with 1813 for accounting), as defined in RFC 2865/2866. Option B is correct because the shared secret is a pre-shared key used to encrypt and authenticate RADIUS messages, so the value configured on the Cisco device (via the 'radius-server key' or per-host 'key') must exactly match the value on the RADIUS server or authentication will fail. Option C is correct because the 'radius-server host' command supports an optional 'key' parameter, allowing a per-server shared secret to be specified, e.g., 'radius-server host 10.1.1.1 key MySecret'.

Option D is incorrect because RADIUS uses UDP, not TCP, for transport. Option E is incorrect because the legacy port 1645 is not the default; the standard default authentication port is 1812 (1645 was used by some early implementations but is not the default).

Exam trap

The trap here is confusing RADIUS with TACACS+ (which uses TCP) and mixing up the legacy ports 1645/1646 with the standard 1812/1813, leading candidates to select incorrect options about transport protocol and default ports.

345
Multi-Selecthard

A network engineer is configuring VXLAN on a Cisco Nexus switch. The engineer needs to ensure that the VXLAN tunnel endpoint (VTEP) can forward traffic between hosts in the same VXLAN segment across the Layer 3 underlay. Which two statements are true about VXLAN operation? (Choose two.)

Select 2 answers
A.VXLAN tunnel endpoints must be directly connected at Layer 2.
B.VXLAN requires a multicast underlay for all deployments.
C.VXLAN encapsulates original Ethernet frames in UDP.
D.VXLAN uses a 12-bit identifier to maintain compatibility with VLANs.
E.VXLAN uses a 24-bit VNI to identify Layer 2 segments.
AnswersC, E

VXLAN encapsulates original Layer 2 Ethernet frames within UDP packets, typically using UDP port 4789. This allows Layer 2 segments to be extended over a Layer 3 underlay network. The encapsulation includes a VXLAN header with the VNI, and the outer IP header enables routing across the underlay. This is the core mechanism of VXLAN.

Why this answer

VXLAN uses a 24-bit VNI to identify Layer 2 segments, supporting up to 16 million segments, and encapsulates original Ethernet frames in UDP (port 4789) to extend Layer 2 over a Layer 3 underlay. Multicast is not mandatory, and VTEPs do not require Layer 2 adjacency. The 12-bit identifier is for VLANs, not VXLAN.

Exam trap

The trap here is assuming VXLAN requires multicast or Layer 2 adjacency, when it is designed to operate over Layer 3 with unicast or multicast replication.

346
Multi-Selecteasy

Which three statements about HTTP response status codes in REST APIs are true? (Choose three.)

Select 3 answers
A.200 OK is used to indicate a successful GET request.
B.201 Created is returned when a resource is successfully created via POST.
C.404 Not Found indicates a server-side error.
D.400 Bad Request is a client error indicating malformed request syntax.
E.500 Internal Server Error is a client error.
AnswersA, B, D

A successful GET returns the requested representation with 200 OK, confirming the resource was retrieved. This is the standard success code for read operations, distinguishing it from 201, which signals resource creation rather than retrieval.

Why this answer

Option A is correct because 200 OK is the standard success status code returned when a GET request successfully retrieves a representation of the requested resource. Option B is correct because 201 Created is returned after a POST request successfully creates a new resource, typically accompanied by a Location header pointing to the new resource's URI. Option D is correct because 400 Bad Request is a 4xx client error status indicating the server cannot process the request due to malformed syntax, invalid framing, or deceptive request routing.

Option C is incorrect because 404 Not Found is a 4xx client error meaning the origin server did not find a current representation for the target resource, not a server-side error. Option E is incorrect because 500 Internal Server Error is a 5xx server error indicating the server encountered an unexpected condition that prevented it from fulfilling the request, not a client error.

Exam trap

350-401 often tests whether candidates correctly map status codes to their class (4xx = client, 5xx = server), tempting them to label 404 as a server error or 500 as a client error.

347
MCQhard

A network engineer runs the following command on Router R7: R7# show ip ospf virtual-links Virtual Link OSPF_VL0 to router 2.2.2.2 is up Run as demand circuit DoNotAge LSA allowed. Transit area 1, via interface GigabitEthernet0/1, Cost of using 10 Transmit Delay is 1 sec, State POINT_TO_POINT, Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5 Hello due in 00:00:07 Adjacency State FULL Based on this output, what can be concluded?

A.The virtual link is used to connect area 0 to a non-backbone area.
B.Router 2.2.2.2 is the other endpoint of the virtual link.
C.The virtual link is down.
D.The virtual link uses area 0 as the transit area.
AnswerB

The virtual link is identified by the router ID of its remote endpoint, and in the displayed output 'ospf 2a54f7' (likely from 'show ip ospf virtual-links'), the destination is 'router 2.2.2.2'. This means 2.2.2.2 is the neighboring ABR that, together with the local router, forms the virtual adjacency across the transit area. Therefore, stating that 2.2.2.2 is the other endpoint is accurate.

Why this answer

The output shows that the virtual link OSPF_VL0 to router 2.2.2.2 is up and the adjacency state is FULL. This confirms that router 2.2.2.2 is the remote endpoint of the virtual link, as the command displays the router ID of the neighbor at the other end of the virtual link.

Exam trap

Cisco often tests the misconception that the router ID shown in the virtual link output is the local router's ID, when in fact it is the remote endpoint's router ID, as confirmed by the 'to router' syntax in the command output.

How to eliminate wrong answers

Option A is wrong because the virtual link is used to connect a non-backbone area to area 0, not to connect area 0 to a non-backbone area; the virtual link extends area 0 into a transit area. Option C is wrong because the output explicitly states 'Virtual Link ... is up' and 'Adjacency State FULL', indicating the link is operational. Option D is wrong because the transit area is area 1, not area 0; the output shows 'Transit area 1'.

348
Multi-Selectmedium

Which two statements about the QoS trust boundary on a Cisco switch are true? (Choose two.)

Select 2 answers
A.By default, a Cisco switch port in access mode trusts the CoS value received from the attached device.
B.On a trunk port, the switch can be configured to trust the CoS value by default.
C.The trust boundary can be extended to the endpoint by configuring the interface with the 'mls qos trust' command.
D.When a Cisco IP Phone is connected, the switch automatically trusts the CoS values from the phone but not from the PC behind the phone.
E.The 'trust device cisco-phone' command enables the switch to trust all CoS values from both the phone and the attached PC.
AnswersB, C

Trunk ports carry 802.1Q frames between infrastructure devices, so the switch defaults to trusting the CoS field in the frame header. This design assumes that the upstream switch, router, or voice gateway has already classified and marked the traffic, and preserving that Layer 2 marking prevents frame-by-frame reclassification. If you want to trust DSCP instead of CoS on a trunk, you must explicitly override the default with 'mls qos trust dscp'.

Why this answer

The trust boundary defines which device in the network is trusted to mark QoS values. By default, Cisco switches trust the CoS value on trunk ports but do not trust the DSCP value on access ports. The trust boundary can be extended to the endpoint by configuring the switch port as trusted, and the Cisco IP Phone can override the marking from the attached PC.

349
MCQeasy

A company is deploying a wireless network in an office with high client density. Which Cisco architecture is best suited to handle client roaming without requiring a central controller for every roaming event?

A.Mesh networking
B.Autonomous APs
C.Centralized switching with a WLC
D.FlexConnect
AnswerD

FlexConnect is correct because it separates the control plane (which remains with the WLC) from the data plane (which is switched locally at the AP). This allows client traffic to be forwarded directly to the wired network at each access point, avoiding unnecessary latency and controller bottlenecks, which is ideal for high-bandwidth, high-density indoor environments. Furthermore, FlexConnect supports IEEE 802.11r fast roaming and can perform client-based or AP-based neighbor discovery when connected to a WLC, ensuring seamless and fast handoffs as users move across the office. Its design balances centralized management with localized forwarding, offering both the operational consistency of a controller and the performance of distributed switching.

Why this answer

FlexConnect (option D) is the correct architecture because it allows client data traffic to be switched locally at the remote site, while the control plane remains centralized. This design eliminates the need for a central controller to process every roaming event, as clients can roam between FlexConnect APs using local switching and 802.11r (Fast Roaming) without requiring a WLC in the data path.

Exam trap

Cisco often tests the misconception that centralized switching (WLC) is always required for seamless roaming, but FlexConnect decouples the data plane from the control plane to allow local roaming without a central controller in the data path.

How to eliminate wrong answers

Option A is wrong because mesh networking is designed for extending coverage in areas without wired backhaul, not for handling high-density client roaming with local switching; it still relies on a central controller for roaming decisions. Option B is wrong because autonomous APs operate independently without any central coordination, making seamless roaming inefficient and requiring manual configuration for each AP, which is unsuitable for high-density environments. Option C is wrong because centralized switching with a WLC forces all client traffic through the controller, creating a bottleneck and requiring the WLC to process every roaming event, which increases latency and reduces scalability in high-density deployments.

350
Drag & Dropmedium

Drag and drop the steps of MPLS LDP label distribution and FIB population into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, IP routing must be operational so that the IGP converges. Then LDP is enabled on interfaces and forms neighbor relationships. LDP then assigns local labels to FECs and advertises them to neighbors.

The remote label is received and installed in the LIB. Finally, the LFIB is populated with the best label bindings for forwarding.

351
MCQmedium

An architect is designing a virtualized service chain for a campus network using NFV. The chain must include a firewall, WAN optimizer, and IPS. The architect needs to minimize latency by placing VNFs on the same hypervisor host. Which design consideration is most important?

A.Ensure all VNFs are pinned to the same NUMA node on the hypervisor host.
B.Use a Type 2 hypervisor to reduce overhead.
C.Place each VNF on a separate physical host to avoid resource contention.
D.Enable DPDK on the virtual switch to accelerate packet processing.
AnswerA

In multi-socket servers, memory accessed from a remote NUMA node incurs significantly higher latency and consumes inter-socket bandwidth, which can severely degrade throughput for VNF service chains. Pinning all VNFs to the same NUMA node ensures memory allocations are local to the CPU cores executing packet processing, maximizing cache locality and minimizing cross-node traffic. This configuration directly reduces the latency and overhead associated with data plane forwarding between VNFs within a chain.

Why this answer

Pinning all VNFs to the same NUMA node on the hypervisor host minimizes inter-NUMA memory access latency, which is critical for achieving low-latency packet processing in an NFV service chain. When VNFs are placed on different NUMA nodes, memory accesses must traverse the QPI/UPI interconnect, adding significant latency. By co-locating the firewall, WAN optimizer, and IPS on the same NUMA node, the architect ensures that all packet processing stays within the same memory domain, reducing latency to the minimum possible on that host.

Exam trap

Cisco often tests the misconception that DPDK or a Type 2 hypervisor is the primary solution for low-latency NFV, when in fact NUMA awareness is the foundational requirement that must be addressed first.

How to eliminate wrong answers

Option B is wrong because Type 2 hypervisors (hosted on an OS) introduce additional overhead from the host OS scheduler and drivers, which increases latency compared to Type 1 (bare-metal) hypervisors; the question requires minimizing latency, so a Type 2 hypervisor is counterproductive. Option C is wrong because placing each VNF on a separate physical host forces packets to traverse the network between hosts, adding switching and link latency that is far higher than any intra-host contention; this directly contradicts the goal of minimizing latency. Option D is wrong because enabling DPDK on the virtual switch accelerates packet processing by bypassing the kernel, but it does not address the fundamental latency penalty of cross-NUMA memory access; DPDK is a performance optimization, not a substitute for proper NUMA placement.

352
MCQeasy

A network administrator is configuring a Cisco Catalyst switch to assign a voice VLAN to IP phones. The phones will tag voice traffic with VLAN 200, and data traffic from attached PCs should be untagged in VLAN 10. Which interface configuration correctly implements this?

A.Switchport mode trunk, switchport trunk native vlan 10, switchport trunk allowed vlan 200
B.Switchport mode trunk, switchport trunk encapsulation dot1q, switchport trunk native vlan 200
C.Switchport mode access, switchport access vlan 200, switchport voice vlan 10
D.Switchport mode access, switchport access vlan 10, switchport voice vlan 200
AnswerD

This configuration sets the port as an access port for data VLAN 10 and enables voice VLAN 200 for tagged voice traffic. The switchport voice vlan command instructs the switch to use 802.1Q tagging for voice frames while data frames remain untagged. This is the standard Cisco configuration for connecting an IP phone with a PC attached, meeting the requirements.

Why this answer

The correct configuration uses an access port for data VLAN 10 and the switchport voice vlan command for voice VLAN 200. This enables the switch to send CDP/LLDP-MED instructions to the phone to tag voice traffic in VLAN 200 while data remains untagged in VLAN 10. It is the standard Cisco IP telephony deployment.

Exam trap

The trap here is confusing voice VLAN configuration with trunk configuration; voice VLAN is enabled on an access port, not by making the port a trunk.

353
Multi-Selecthard

Which three statements about NAT64 and NPTv6 are true? (Choose three.)

Select 3 answers
A.NAT64 translates IPv6 packets to IPv4 packets and vice versa, allowing IPv6-only clients to access IPv4 servers.
B.NPTv6 (Network Prefix Translation) translates the IPv6 prefix of a packet while preserving the host portion of the address.
C.NAT64 requires a DNS64 server to synthesize AAAA records from A records for IPv6 clients.
D.NPTv6 provides port address translation similar to PAT in IPv4 NAT.
E.Both NAT64 and NPTv6 require stateful inspection of all traffic flows.
AnswersA, B, C

NAT64 performs stateful protocol translation between the IPv6 and IPv4 headers, rewriting addresses and ports so an IPv6-only host can reach an IPv4-only server. This satisfies the stem's requirement that translation works in both directions, unlike NPTv6, which only rewrites prefixes and cannot cross protocol versions.

Why this answer

Option A is correct because NAT64 is a stateful translation mechanism defined in RFC 6146 that converts IPv6 packet headers into IPv4 headers (and back), enabling IPv6-only hosts to reach IPv4-only servers using a NAT64 prefix such as 64:ff9b::/96. Option B is correct because NPTv6 (RFC 6296) is a stateless prefix translator that rewrites only the IPv6 network prefix while leaving the interface identifier (host portion) intact, preserving end-to-end checksum neutrality. Option C is correct because NAT64 alone cannot resolve IPv4-only destinations for an IPv6-only client; a DNS64 resolver is needed to synthesize AAAA records from A records so the client obtains a routable IPv6 address that the NAT64 gateway can translate.

Option D is incorrect because NPTv6 is stateless and does not perform port address translation; PAT is a feature of stateful NAT44/NAT64, not NPTv6. Option E is incorrect because NPTv6 is explicitly stateless and does not inspect or track flows, whereas only NAT64 maintains stateful bindings.

Exam trap

350-401 often tests the misconception that NPTv6 performs port translation or is stateful, confusing it with NAT64 or PAT.

354
MCQmedium

A network administrator is troubleshooting a BGP routing issue where routes from an eBGP neighbor are not being installed in the routing table. The 'show ip bgp' output shows the routes are received but not valid. What is the most likely cause?

A.The AS-path contains the local AS number.
B.The next-hop IP address is not reachable.
C.BGP synchronization is enabled.
D.The maximum-prefix limit has been exceeded.
AnswerB

Correct. For a BGP route to be considered valid and installed in the routing table, the next-hop IP address must be reachable via an IGP or static route. If the next hop is not reachable, the route will appear in the 'show ip bgp' output but be marked as not valid.

Why this answer

For a BGP route to be considered valid and installed in the routing table, the next-hop IP address must be reachable via an IGP or a static route. If the next hop is not reachable, the route will appear in the 'show ip bgp' output but will be marked as not valid (often with a 'r' for received but not valid). This is the most common cause when routes are received from an eBGP neighbor but not installed.

Exam trap

Cisco often tests the distinction between routes being received in the BGP table versus being installed in the routing table, and the trap here is that candidates confuse synchronization (a deprecated feature) with the next-hop reachability requirement, which is the immediate cause of the 'not valid' status.

How to eliminate wrong answers

Option A is wrong because if the AS-path contains the local AS number, BGP would reject the route due to loop prevention (the route would be marked as invalid or not received at all), but the question states routes are received. Option C is wrong because BGP synchronization is disabled by default in modern IOS versions and, even if enabled, it would affect the route's validity only if the prefix is not present in the IGP, but the next-hop reachability check is more fundamental. Option D is wrong because exceeding the maximum-prefix limit would cause the BGP session to be torn down or the neighbor to be shut down, not simply mark routes as not valid while keeping them in the BGP table.

355
MCQhard

An engineer is configuring a FlexVPN hub-and-spoke topology using IKEv2. The hub router is configured with a dynamic crypto map and a local pool for assigning IP addresses to spokes. The spokes are configured with a static crypto map and a tunnel interface with an IP address from the pool. The tunnel comes up, but the spoke cannot ping the hub's tunnel interface. The hub can ping the spoke's tunnel interface. What is the most likely cause?

A.The spoke is configured with a static IP address on the tunnel interface that is not in the hub's IP pool.
B.The hub is missing the 'tunnel protection ipsec' command on the tunnel interface.
C.The spoke's crypto map is not using the correct pre-shared key.
D.The hub's IKEv2 profile is not configured with 'authentication remote rsa-sig'.
AnswerA

Correct. In FlexVPN, the hub assigns IP addresses from a pool. If the spoke statically configures an IP address, the hub may not have a route back to that address, causing asymmetric routing or unreachability.

Why this answer

In a FlexVPN hub-and-spoke topology with IKEv2, the hub assigns IP addresses to spokes from a local pool. If the spoke's tunnel interface is configured with a static IP address that is not within the hub's pool, the hub will not recognize the spoke's tunnel IP as a valid address from its pool. This causes asymmetric routing: the hub can reach the spoke because it has a route to the static IP, but the spoke cannot reach the hub because the hub has no route back to the spoke's tunnel IP (or the hub's reverse route injection fails).

The correct behavior is for the spoke to obtain its tunnel IP dynamically via IKEv2 configuration exchange or to use an IP from the hub's pool.

Exam trap

Cisco often tests the misconception that a static IP on the spoke's tunnel interface is acceptable as long as the tunnel is up, but the key point is that the hub's route injection depends on the IP being within the configured pool.

How to eliminate wrong answers

Option B is wrong because the 'tunnel protection ipsec' command is required on both hub and spoke tunnel interfaces to apply IPsec protection; without it, the tunnel would not come up at all, but the question states the tunnel is up. Option C is wrong because if the pre-shared key were incorrect, IKEv2 authentication would fail and the tunnel would not establish; the tunnel is up, so the keys match. Option D is wrong because 'authentication remote rsa-sig' is used for RSA signature-based authentication, but the question does not specify that RSA is required; IKEv2 can use pre-shared keys, and the tunnel is up, indicating authentication succeeded.

356
Multi-Selectmedium

Which three statements about trunking and VLAN pruning are true? (Choose three.)

Select 3 answers
A.VTP pruning dynamically removes VLANs from a trunk if the VLAN is not present on the remote switch.
B.Manual pruning can be achieved using the 'switchport trunk allowed vlan' command.
C.VTP pruning requires VTP to be enabled on the switches in the management domain.
D.VTP pruning is only supported in VTP version 3.
E.The 'switchport trunk native vlan' command is used to prune VLANs from a trunk.
AnswersA, B, C

VTP pruning suppresses flooding for a VLAN on a trunk only when the downstream switch reports no active ports in that VLAN, based on VTP advertisements. This matches the stem's constraint about dynamic removal tied to remote switch membership.

Why this answer

Option A is correct because VTP pruning dynamically removes a VLAN from a trunk link when the neighboring switch has no access ports in that VLAN, preventing unnecessary flooded traffic. Option B is correct because manual pruning is accomplished by explicitly limiting the VLANs allowed on a trunk with the 'switchport trunk allowed vlan' interface command. Option C is correct because VTP pruning is a VTP feature and therefore requires VTP to be enabled and the switches to share the same VTP management domain.

Option D is incorrect because VTP pruning is supported in VTP versions 1 and 2 as well as version 3, not only version 3. Option E is incorrect because 'switchport trunk native vlan' sets the native VLAN for untagged traffic on a trunk; it does not prune VLANs.

Exam trap

The trap here is conflating VTP pruning with VTP version support and with unrelated trunk commands—candidates often assume pruning is a VTPv3-only feature or mistake the native VLAN command for a pruning mechanism.

357
Drag & Dropmedium

Drag and drop the steps of DMVPN Phase 1 spoke-to-hub tunnel setup into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In DMVPN Phase 1, the spoke first establishes an mGRE tunnel to the hub using a multipoint interface. The hub then registers the spoke's NHRP mapping. After registration, the spoke can dynamically learn routes from the hub via the tunnel.

Finally, the spoke sends traffic through the hub, which routes it to the destination.

358
Drag & Drophard

Drag and drop the steps of cisco.ios.ios_config module idempotent apply flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The ios_config module first connects to the device, retrieves the running config, compares it with the desired config, applies only the necessary changes, and then saves the config if specified, ensuring idempotency.

359
Multi-Selectmedium

A network engineer is implementing IPsec VPN on a Cisco IOS XE router to connect a branch office to headquarters. The engineer must ensure that the IKEv2 negotiation uses strong authentication and that the data plane is protected with integrity and encryption. Which two configuration elements are required to achieve this? (Choose two.)

Select 2 answers
A.Configure an IKEv2 keyring or PKI trustpoint to authenticate the peers.
B.Configure 'crypto isakmp policy' with pre-shared key authentication for IKEv1.
C.Configure an IPsec transform set specifying ESP encryption and authentication algorithms.
D.Configure 'crypto ipsec profile' with 'set security-association lifetime seconds 3600' only.
E.Configure a crypto ACL with 'permit ip any any' to match all traffic.
AnswersA, C

IKEv2 requires peer authentication before establishing the IPsec SA. A keyring with pre-shared keys or a PKI trustpoint with certificates provides that authentication. Without it, IKEv2 negotiation fails. This element is mandatory for strong authentication and directly supports the requirement. It is separate from the IPsec transform set, which protects the data plane, so both are needed in the overall configuration.

Why this answer

IKEv2 requires peer authentication, provided by a keyring with pre-shared keys or a PKI trustpoint. The data plane is protected by an IPsec transform set that specifies ESP encryption and authentication algorithms. Both elements must be configured and referenced correctly in the IPsec profile or crypto map.

The other options either apply to IKEv1 or do not provide the required security functions.

Exam trap

The trap here is confusing IKEv1 and IKEv2 configuration syntax, and assuming a crypto ACL or lifetime setting alone can provide authentication and encryption.

360
MCQmedium

A network automation engineer is developing a Python script that will retrieve interface statistics from a Cisco IOS XE device using NETCONF. The engineer needs to discover which YANG models are supported by the device before constructing the RPC. Which NETCONF capability exchange message should the script send first to obtain this information?

A.Send a RESTCONF GET request to the /restconf/data/ietf-yang-library:modules-state endpoint.
B.Establish an SSH session and read the <hello> message sent by the device immediately after the NETCONF subsystem is started.
C.Issue a NETCONF <get-config> RPC with a filter specifying the urn:ietf:params:xml:ns:yang:ietf-interfaces namespace.
D.Send an <rpc> message with a <get> operation targeting the ietf-netconf-monitoring model.
AnswerB

When a NETCONF session is established over SSH, both the client and server exchange <hello> messages. The server's <hello> contains a <capabilities> element listing all supported YANG models and protocol features. This is the standard mechanism for capability discovery, and the client must parse this message to learn which models are available.

Why this answer

The NETCONF protocol requires a capability exchange during session establishment. The server sends a <hello> message containing a <capabilities> element that lists all supported YANG models and protocol features. The client must parse this message to discover available models before sending any RPCs.

This is fundamental to NETCONF operation and is defined in RFC 6241.

Exam trap

The trap here is assuming that capability discovery requires an explicit RPC or RESTCONF query, when it is actually part of the initial NETCONF session handshake.

361
MCQmedium

Router R5 has the following OSPF configuration: router ospf 1 router-id 5.5.5.5 network 10.0.0.0 0.255.255.255 area 0 area 0 authentication message-digest ! interface GigabitEthernet0/0 ip address 10.1.1.5 255.255.255.0 ip ospf message-digest-key 1 md5 cisco123 What is missing from this OSPF authentication configuration?

A.The configuration is complete and correct.
B.The interface needs the 'ip ospf authentication message-digest' command.
C.The 'area 0 authentication' command should be 'area 0 authentication md5'.
D.The 'network' command should include the area authentication keyword.
AnswerB

Area 0 already enables MD5 authentication, but the interface itself lacks the enabling command, so no digest is sent. Adding 'ip ospf authentication message-digest' on GigabitEthernet0/0 activates authentication, allowing the configured key 1 to be used.

Why this answer

OSPF authentication configuration requires two components: an area-level authentication type (configured via `area 0 authentication message-digest`) and an interface-level authentication mode (configured via `ip ospf authentication message-digest`). The interface command tells the OSPF process to actually use the key defined with `ip ospf message-digest-key`. Without it, the interface defaults to no authentication, even though the area is configured for authentication.

Exam trap

The trap here is that candidates assume configuring the area authentication and the key is sufficient, overlooking the mandatory interface-level `ip ospf authentication message-digest` command that activates authentication on the specific interface.

How to eliminate wrong answers

Option A is wrong because the configuration is incomplete; the interface lacks the `ip ospf authentication message-digest` command, so OSPF packets on GigabitEthernet0/0 will not be authenticated. Option C is wrong because `area 0 authentication md5` is not a valid Cisco IOS command; the correct syntax is `area 0 authentication message-digest`. Option D is wrong because the `network` command does not support an area authentication keyword; area authentication is configured separately under the OSPF process or on the interface.

362
MCQhard

A network engineer is troubleshooting a Cisco Nexus 9000 switch configured for VXLAN EVPN. The engineer notices that the switch is not learning remote MAC addresses from other VTEPs. The underlay routing is working, and MP-BGP EVPN peering is established. Which configuration issue could prevent the switch from learning remote MAC addresses?

A.The BGP router ID is not unique.
B.The VNI is not mapped to the correct VLAN in the EVPN configuration.
C.The underlay OSPF cost is too high.
D.The switch is configured with a static VXLAN tunnel instead of a dynamic one.
AnswerB

For VXLAN EVPN to learn remote MAC addresses, the VNI must be mapped to the correct VLAN. If the mapping is missing or incorrect, the switch cannot associate incoming EVPN routes with the local VLAN, preventing MAC learning. This is a common misconfiguration that breaks overlay connectivity.

Why this answer

In VXLAN EVPN, the VNI must be mapped to the correct VLAN for the switch to associate EVPN routes with local VLANs and learn remote MAC addresses. If the mapping is missing or incorrect, the switch cannot install remote MACs into the MAC address table, even if EVPN peering is up and the underlay is functional.

Exam trap

The trap here is focusing on underlay or BGP peering issues when the problem is actually a local mapping mismatch between the VNI and VLAN, which is a common EVPN configuration oversight.

363
MCQeasy

Which BGP attribute is preferred with the lowest value?

A.MED
B.Local Preference
C.Weight
D.Origin
AnswerA

MED (Multi-Exit Discriminator) is an optional, non-transitive BGP attribute used to influence inbound traffic from a neighboring autonomous system. When comparing multiple paths that share the same neighboring AS, Cisco IOS prefers the path with the lowest MED value, making lower better. MED is the correct answer because it is the only attribute among the listed options where a numerically lower value is explicitly preferred in BGP path selection, and it is typically set to reflect internal IGP metrics or link costs.

Why this answer

MED (Multi-Exit Discriminator) is a BGP attribute that is preferred with the lowest value. It is used to influence inbound traffic to an AS when multiple entry points exist, and a lower MED value is more preferred over a higher one.

Exam trap

Cisco often tests the confusion between attributes that use 'lowest is best' (like MED and IGP metric) versus 'highest is best' (like Local Preference and Weight), so candidates mistakenly apply the 'highest is best' rule to MED.

How to eliminate wrong answers

Option B (Local Preference) is wrong because Local Preference is preferred with the highest value, not the lowest, and is used to influence outbound traffic from an AS. Option C (Weight) is wrong because Weight is a Cisco-proprietary attribute that is preferred with the highest value, and it is local to the router. Option D (Origin) is wrong because Origin is preferred in the order IGP < EGP < incomplete, not based on a numeric value.

364
MCQmedium

A network engineer is troubleshooting an EIGRP issue in a large enterprise network. Two routers, R1 and R2, are connected via a T1 link. R1 is learning a route to 10.0.0.0/8 from R2 with a metric of 28160, but the same route is also learned from another neighbor with a metric of 26880. The engineer notices that the route from R2 is not being installed in the routing table. What is the most likely cause?

A.The route from R2 is a feasible successor, so it is not installed in the routing table.
B.EIGRP is using unequal-cost load balancing, so the higher metric route is not used.
C.The route with metric 28160 is not installed because EIGRP selects the route with the lowest metric.
D.The route from R2 is a summary route, so it is not installed in the routing table.
AnswerC

EIGRP computes a composite metric from bandwidth, delay, load, and reliability, then selects the path with the lowest metric as the successor to install in the routing table. Any other paths, even if they are feasible successors or simply higher-metric routes, remain in the topology table. Since 26880 is lower than 28160, the route from R2 is not installed, directly illustrating EIGRP's best-path selection mechanism.

Why this answer

C is correct because EIGRP installs only the route with the best (lowest) metric into the routing table. The route from R2 has a metric of 28160, while the other neighbor advertises the same route with a metric of 26880. Since 26880 is lower, R1 selects that route as the successor and does not install the higher-metric route from R2.

Exam trap

Cisco often tests the misconception that all learned EIGRP routes are installed in the routing table, but in reality only the successor (lowest metric) is installed unless unequal-cost load balancing is explicitly configured.

How to eliminate wrong answers

Option A is wrong because a feasible successor is a backup route that is kept in the topology table but not installed in the routing table unless the successor fails; however, the question states that the route from R2 is not installed, but it is not necessarily a feasible successor—it could simply be a non-successor route that does not meet the feasibility condition. Option B is wrong because unequal-cost load balancing (variance) is optional and, even if enabled, would only load-balance across routes that meet the variance multiplier; the route with metric 28160 would still not be installed if it is not selected as a successor or feasible successor under the variance condition. Option D is wrong because there is no indication that the route from R2 is a summary route; summary routes are typically installed with a lower administrative distance or as a local route, and the metric difference alone does not imply summarization.

365
Multi-Selecteasy

Which THREE benefits does network automation provide over manual configuration?

Select 3 answers
A.Increased security by eliminating the need for SSH access
B.Lower initial investment compared to manual processes
C.Reduced risk of configuration errors
D.Consistent configuration across all devices
E.Faster deployment of configuration changes
AnswersC, D, E

Automation eliminates manual mistakes.

Why this answer

Network automation eliminates human error during repetitive configuration tasks. By using tools like Ansible, Python scripts, or NETCONF/YANG models, configurations are applied consistently without typos or missed commands, which are common in manual CLI entry. This directly reduces the risk of syntax errors, missing parameters, or inconsistent settings that can lead to network outages.

Exam trap

Cisco often tests the misconception that automation eliminates all manual access methods like SSH, but in reality, automation relies on SSH or similar transports for device communication, and the trap is assuming automation reduces security risks by removing SSH entirely.

366
Matchingmedium

Drag and drop each BGP attribute on the left to its matching attribute type on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Well-known mandatory

Well-known discretionary

Optional transitive

Optional non-transitive

Well-known mandatory

Why these pairings

AS_PATH is well-known mandatory; LOCAL_PREF is well-known discretionary; COMMUNITY is optional transitive; MULTI_EXIT_DISC is optional non-transitive; ORIGIN is well-known mandatory.

367
Drag & Dropmedium

Drag and drop the steps of Flexible NetFlow flow record and exporter setup into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order begins with defining the flow record, then the flow exporter, then the flow monitor, then applying it to an interface, and finally verifying with show commands.

368
MCQmedium

A company is using a dual-homed MPLS L3VPN connection with two different ISPs. The CE router is running eBGP with both PE routers. The engineer wants to ensure that inbound traffic from the Internet to the company's web servers uses both links, but outbound traffic from the company should prefer ISP A. The company advertises the same /24 prefix to both ISPs. What BGP configuration should the engineer apply on the CE router?

A.Set a lower MED for routes advertised to ISP A and a higher MED for routes advertised to ISP B.
B.Use AS path prepending on routes advertised to ISP B and set a higher local preference for routes learned from ISP A.
C.Advertise a more specific prefix (e.g., /25) to ISP A and a less specific prefix (/24) to ISP B.
D.Configure the CE router to use BGP multipath with both ISPs.
AnswerB

AS path prepending artificially extends the AS_PATH attribute, so ISP B sees a longer AS path and deprioritizes that route for inbound traffic, while the /24 remains advertised normally. Setting a higher local preference for routes learned from ISP A only influences routers inside your autonomous system, causing outbound traffic to prefer ISP A regardless of other attributes. This separation of inbound and outbound control is exactly the standard BGP traffic engineering approach.

Why this answer

AS path prepending makes the route to ISP B appear less attractive for inbound traffic, while setting a higher local preference on routes learned from ISP A makes ISP A the preferred path for outbound traffic. This combination achieves the asymmetric routing goal: inbound traffic uses both links (since prepending only influences ISP B's decision, not ISP A's), and outbound traffic prefers ISP A due to the higher local preference.

Exam trap

Cisco often tests the distinction between inbound and outbound traffic engineering: candidates confuse attributes that influence inbound traffic (like MED and AS path prepending) with those that influence outbound traffic (like local preference and weight), leading them to pick Option A or C incorrectly.

How to eliminate wrong answers

Option A is wrong because MED is a metric sent to a specific neighbor and is only compared when paths come from the same AS; since the two ISPs are different ASes, MED would not be compared, and even if it were, lower MED makes a route more preferred, which would attract more inbound traffic to ISP A, not balance it. Option C is wrong because advertising a more specific prefix (/25) to ISP A would cause ISP A to prefer that route over the /24, attracting all inbound traffic to ISP A, not balancing it; also, this violates the requirement to advertise the same /24 prefix to both ISPs. Option D is wrong because BGP multipath allows the CE router to load-balance outbound traffic across both ISPs, but the requirement is to prefer ISP A for outbound traffic, not to load-balance equally.

369
MCQmedium

interface GigabitEthernet0/1 ip address 10.1.1.1 255.255.255.0 mpls ip mpls label protocol tdp ! router ospf 1 network 10.1.1.0 0.0.0.255 area 0 ! router ldp interface GigabitEthernet0/1 ! Which statement about this configuration is true?

A.The interface will use TDP for label distribution, ignoring the LDP configuration under router ldp.
B.The router will use LDP because the global configuration overrides the interface command.
C.Both TDP and LDP will be used simultaneously on the interface.
D.The configuration will fail because TDP is not supported on this platform.
AnswerA

The interface-level command 'mpls label protocol tdp' takes precedence over any global or routing-protocol-level LDP configuration. On Cisco IOS, interface-specific configuration is applied after global settings and thus overrides them, so the interface uses TDP exclusively for label distribution. Even though 'router ldp' enables LDP globally, the interface's explicit TDP directive forces TDP on that interface. This is the standard precedence behavior for MPLS label protocol selection.

Why this answer

The interface-level command `mpls label protocol tdp` explicitly sets TDP (Tag Distribution Protocol) for that interface. When both an interface-specific `mpls label protocol` command and a global `router ldp` configuration exist, the interface-level command takes precedence. Therefore, GigabitEthernet0/1 will use TDP for label distribution, and the LDP configuration under `router ldp` is effectively ignored for that interface.

Exam trap

The trap here is that candidates often assume the global `router ldp` configuration overrides an interface-level `mpls label protocol tdp` command, but Cisco explicitly tests that the interface-level command takes precedence.

How to eliminate wrong answers

Option B is wrong because the interface-level command overrides the global LDP configuration, not the other way around. Option C is wrong because TDP and LDP are mutually exclusive on a single interface; a router cannot run both simultaneously on the same interface. Option D is wrong because TDP is supported on Cisco IOS platforms that support MPLS, and the configuration will not fail due to TDP being unsupported.

370
MCQhard

An enterprise is migrating from a traditional three-tier campus design to a software-defined access (SD-Access) fabric. The engineer needs to ensure that the existing wireless infrastructure integrates seamlessly. Which component of SD-Access is responsible for integrating wireless and wired policies?

A.Fabric Edge node
B.Fabric Control node
C.Fabric Border node
D.Wireless LAN Controller (WLC)
AnswerA

The Fabric Edge node is the ingress point for every endpoint—wired or wireless—into the SD-Access fabric. It terminates VXLAN tunnels from access switches and wireless APs, hosts the anycast gateway for the subnet, and enforces policy via Cisco TrustSec (SGT-based segmentation) and ACLs. All user traffic enters here, making it the correct component for integrating policies and providing connectivity.

Why this answer

The Fabric Edge node is the correct answer because it is the SD-Access component that serves as the attachment point for both wired and wireless endpoints. In an SD-Access fabric, the Fabric Edge node terminates the VXLAN tunnels from the wireless LAN controller (WLC) and applies consistent policy (e.g., SGT-based ACLs) to traffic from both wired and wireless users, ensuring seamless integration of the existing wireless infrastructure.

Exam trap

Cisco often tests the misconception that the WLC is responsible for policy integration, but in SD-Access, the WLC is merely a wireless controller that tunnels client traffic to the Fabric Edge node, which is the actual policy enforcement point.

How to eliminate wrong answers

Option B (Fabric Control node) is wrong because it handles LISP control-plane functions such as endpoint registration and mapping, not the integration of wireless policies. Option C (Fabric Border node) is wrong because it connects the fabric to external networks (e.g., WAN, data center) and performs NAT or route advertisement, but does not directly integrate wireless policies. Option D (Wireless LAN Controller) is wrong because while the WLC manages APs and wireless sessions, it is not the component responsible for integrating wireless and wired policies within the fabric; that role belongs to the Fabric Edge node, which applies consistent policy enforcement across both domains.

371
MCQhard

A network engineer runs the following command on a Cisco WLC: WLC# show ap stats ap-name AP-3 AP Statistics for AP-3 ---------------------- Channel Utilization: 75% Interference: 30% Noise Floor: -80 dBm Total Packets Received: 5000 Total Packets Sent: 4500 Total Errors: 1500 Based on this output, what can be concluded?

A.The AP is operating in a clean environment with low interference.
B.The high error rate suggests possible co-channel interference or signal issues.
C.The channel utilization is low, indicating spare capacity.
D.The noise floor is excellent at -80 dBm.
AnswerB

A 30% error rate is abnormally high for a healthy wireless link, indicating that frames are frequently corrupted or lost. This pattern is typically associated with co-channel interference from neighboring APs or signal issues such as excessive path loss, multipath, or hidden nodes. The high error rate is a key diagnostic sign, making this the most accurate conclusion.

Why this answer

The output shows a total error count of 1500 out of 5000 received packets, which is a 30% error rate. This high error rate, combined with 75% channel utilization and 30% interference, strongly indicates co-channel interference or signal degradation issues. In wireless networks, excessive errors often stem from overlapping channels, poor signal-to-noise ratio, or adjacent-cell interference, making option B the correct conclusion.

Exam trap

Cisco often tests the misconception that a high noise floor (e.g., -80 dBm) is good, when in fact lower (more negative) values indicate less background noise and a cleaner RF environment.

How to eliminate wrong answers

Option A is wrong because 30% interference and a 75% channel utilization indicate a congested and noisy environment, not a clean one. Option C is wrong because 75% channel utilization is considered high, not low, and suggests the channel is near saturation with little spare capacity. Option D is wrong because a noise floor of -80 dBm is actually poor (high) for enterprise Wi-Fi; an excellent noise floor would be around -95 dBm or lower, as higher values indicate more background noise.

372
MCQeasy

Refer to the exhibit. An administrator needs to ensure that traffic to 192.168.1.0/24 is forwarded via a different path than traffic to 192.168.2.0/24, even though both routes are learned via OSPF with the same metric. Which action should the administrator take?

A.Configure policy-based routing to match 192.168.1.0/24 and set the next hop to 10.0.0.1.
B.Add a static route for 192.168.1.0/24 with a lower administrative distance than OSPF.
C.Use the 'distance ospf' command to change the OSPF administrative distance for all routes.
D.Adjust the OSPF cost on the interface to 10.0.0.2.
AnswerB

A static route to 192.168.1.0/24 with administrative distance 1 creates a more trustworthy entry than OSPF's default AD of 110, so the router prefers the static route for that exact prefix. This is the precise, surgical fix: it overrides OSPF only for this subnet while leaving all other OSPF-learned routes untouched, and it does not depend on the metrics of the two equal-cost OSPF paths.

Why this answer

Adding a static route for 192.168.1.0/24 with a lower administrative distance (e.g., 1) than OSPF (default 110) forces the router to prefer the static route over the OSPF-learned route, even though the OSPF metric is the same. This allows traffic to 192.168.1.0/24 to use a different next-hop (e.g., 10.0.0.1) while traffic to 192.168.2.0/24 continues using the OSPF-learned path via 10.0.0.2, achieving the desired path differentiation without altering OSPF metrics or using complex PBR.

Exam trap

Cisco often tests the misconception that policy-based routing (PBR) is the only way to force traffic to a different next-hop, when in fact a simple static route with a lower administrative distance can achieve the same result more efficiently and is a common technique for path selection without altering routing protocol metrics.

How to eliminate wrong answers

Option A is wrong because policy-based routing (PBR) matches traffic based on source/destination and sets the next hop, but it does not change the routing table; it overrides the forwarding decision for matched packets, which is unnecessary complexity when a simple static route can achieve the same result with less overhead. Option C is wrong because using the 'distance ospf' command changes the administrative distance for all OSPF routes globally, affecting both 192.168.1.0/24 and 192.168.2.0/24 equally, so it cannot differentiate the path for only one prefix. Option D is wrong because adjusting the OSPF cost on the interface to 10.0.0.2 would change the metric for all routes learned via that interface, potentially altering the path for both prefixes and not specifically isolating 192.168.1.0/24 to a different next-hop.

373
MCQhard

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-POLICY Class-map: MGMT-CLASS (match-all) 100 packets, 5000 bytes 5 minute offered rate 1000 bps Match: access-group name MGMT-ACL police: cir 32000 bps, bc 4000 bytes, be 4000 bytes conformed 80 packets, 4000 bytes; actions: transmit exceeded 15 packets, 750 bytes; actions: drop violated 5 packets, 250 bytes; actions: drop Class-map: class-default (match-any) 200 packets, 10000 bytes 5 minute offered rate 2000 bps Match: any police: cir 64000 bps, bc 8000 bytes, be 8000 bytes conformed 200 packets, 10000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Based on this output, what can be concluded?

A.Management traffic to the control plane is being policed, and some packets are being dropped because they exceed the configured rate.
B.All management traffic is being transmitted without drops.
C.The policer is configured in the output direction.
D.The class-default is dropping packets.
AnswerA

Management traffic matching MGMT-ACL is policed at 32 kbps, and the exceeded and violated counters confirm drops: 15 exceeded packets plus 5 violated packets were discarded rather than transmitted. This satisfies the stem's constraint that control-plane policing actively rate-limits management traffic, proving CoPP enforcement is operational on R1.

Why this answer

The output shows that the CoPP-POLICY policy map is applied to the control plane in the input direction. For the MGMT-CLASS class, the policer has a CIR of 32000 bps, and the counters show 15 packets exceeded and 5 packets violated, both with a drop action. This confirms that some management traffic is being dropped because it exceeds the configured rate, making option A correct.

Exam trap

Cisco often tests the distinction between 'input' and 'output' direction for CoPP, and the trap here is that candidates assume the policy is applied in the output direction or overlook the drop counters in the MGMT-CLASS, leading them to incorrectly select option B or C.

How to eliminate wrong answers

Option B is wrong because the output clearly shows 15 exceeded and 5 violated packets being dropped for the MGMT-CLASS, so not all management traffic is transmitted without drops. Option C is wrong because the command 'show policy-map control-plane' without specifying 'output' defaults to the input direction, and the output explicitly states 'Service-policy input: CoPP-POLICY', confirming it is applied in the input direction. Option D is wrong because the class-default counters show 0 exceeded and 0 violated packets, meaning no packets are being dropped in that class.

374
MCQeasy

A network engineer is troubleshooting a Connectivity issue between two data center switches. The engineer suspects a physical layer problem and wants to verify the cable and interface status. Which command should be used to check the status of all interfaces, including the link state and speed?

A.show running-config interface
B.show ip interface brief
C.show mac address-table
D.show interfaces status
AnswerD

The 'show interfaces status' command provides a summary of all interfaces, including their status (connected/notconnect), VLAN, duplex, speed, and type. This is ideal for quickly verifying physical layer connectivity and interface configuration on Cisco switches, as it displays the operational state and speed of each port.

Why this answer

The 'show interfaces status' command is the correct choice because it provides a concise summary of all switch ports, including operational status, speed, duplex, and VLAN assignment. This allows the engineer to quickly identify any ports that are down or operating at incorrect speeds, which are common symptoms of physical layer problems.

Exam trap

The trap here is assuming that 'show ip interface brief' provides the same information as 'show interfaces status', but the former is limited to Layer 3 and lacks speed/duplex details.

375
MCQmedium

A network administrator is using the Cisco DNA Center Assurance application to troubleshoot a user's slow wireless experience. The administrator notices that the client's onboarding time is high and wants to see a detailed timeline of the client's onboarding process, including association, authentication, and DHCP phases. Which Cisco DNA Center Assurance feature provides this information?

A.Path Trace
B.Application Health Dashboard
C.Network Health Dashboard
D.Client 360 view
AnswerD

The Client 360 view in Cisco DNA Center Assurance provides a comprehensive, detailed timeline of a specific client's onboarding and connectivity events. It includes granular data on association, authentication, DHCP, and other phases, allowing the administrator to pinpoint delays. This is exactly the tool needed to analyze the onboarding process step by step.

Why this answer

The Client 360 view is designed to provide a holistic, detailed view of a single client's experience, including a timeline of onboarding phases. It allows administrators to drill down into specific events like association, authentication, and DHCP, which is essential for troubleshooting slow onboarding. Other dashboards and tools offer aggregate or path-based data, not per-client onboarding details.

Exam trap

The trap here is confusing aggregate health dashboards or path tracing tools with the per-client detailed timeline available in Client 360.

Page 4

Page 5 of 26

Page 6