Courseiva

ENCOR 350-401 (350-401) — Questions 376–450

1923 questions total · 26pages · All types, answers revealed

Page 5

Page 6 of 26

Page 7
376
MCQhard

A network administrator is configuring IPsec VPN on a Cisco IOS router. The requirement is that the tunnel must support multicast traffic for OSPF neighbor adjacency across the VPN. Which IPsec configuration element is required to meet this requirement?

A.Use a dynamic VTI with IKEv1.
B.Use transport mode instead of tunnel mode.
C.Configure GRE over IPsec.
D.Enable IKEv2 with MOBIKE.
AnswerC

GRE tunnels can carry multicast traffic, and when combined with IPsec, the GRE packets are encrypted. This allows OSPF to form neighbor adjacencies over the tunnel because OSPF uses multicast (224.0.0.5/224.0.0.6). Native IPsec cannot carry multicast, so GRE over IPsec is the standard solution for dynamic routing protocols requiring multicast over a VPN.

Why this answer

IPsec security associations are inherently unicast and cannot carry multicast or broadcast traffic. To support OSPF, which relies on multicast hellos, the design must encapsulate multicast inside a GRE tunnel and then protect that GRE tunnel with IPsec. This is commonly called GRE over IPsec or IPsec profile applied to a GRE tunnel interface.

Exam trap

The trap here is believing that IPsec itself can carry multicast, when in fact IPsec SAs are point-to-point unicast and require GRE encapsulation for multicast support.

377
MCQmedium

Given the following configuration on a Cisco IOS switch: interface GigabitEthernet0/6 switchport mode dynamic desirable What is the effect of this configuration?

A.The interface will actively try to form a trunk and will succeed if the other side is set to trunk, desirable, or auto.
B.The interface will only become a trunk if the other side is set to trunk.
C.The interface will always remain an access port.
D.The interface will not send DTP frames.
AnswerA

Dynamic desirable mode actively transmits DTP frames to initiate trunk negotiation, and it will successfully establish a trunk when the neighbor is configured as trunk (unconditional), desirable (actively negotiates), or auto (passively accepts). Only a neighbor explicitly set to access mode will refuse the DTP messages, leaving the link in access state. Therefore, the interface always attempts to trunk, and the outcome depends entirely on the peer's willingness to participate in negotiation.

Why this answer

The `switchport mode dynamic desirable` command configures the interface to actively send Dynamic Trunking Protocol (DTP) frames to negotiate trunking. If the neighboring interface is set to trunk, dynamic desirable, or dynamic auto, the negotiation will succeed and the link will become a trunk. This is because dynamic desirable actively initiates the negotiation, unlike dynamic auto which only responds.

Exam trap

Cisco often tests the distinction between dynamic desirable and dynamic auto, where the trap is that candidates forget dynamic desirable actively sends DTP frames and can form a trunk with dynamic auto, while dynamic auto only responds and will not form a trunk with another auto interface.

How to eliminate wrong answers

Option B is wrong because the interface will not only become a trunk if the other side is set to trunk; it will also succeed if the other side is set to dynamic desirable or dynamic auto, as DTP negotiation allows these combinations. Option C is wrong because the interface will not always remain an access port; it will actively negotiate to become a trunk if the neighbor supports it. Option D is wrong because the interface will send DTP frames; dynamic desirable is an active DTP mode that transmits DTP frames to initiate trunk negotiation.

378
Multi-Selectmedium

A network engineer is evaluating Cisco SD-WAN (Viptela) for a large enterprise. The engineer needs to automate the deployment of vEdge routers using zero-touch provisioning. Which two components are required to enable zero-touch provisioning for vEdge routers? (Choose two.)

Select 2 answers
A.vSmart controller
B.vManage NMS
C.vBond orchestrator
D.APIC-EM
E.Cisco DNA Center
AnswersB, C

vManage is the management plane that stores device configurations and policies. During zero-touch provisioning, the vEdge router obtains its configuration from vManage after being directed by vBond. vManage is essential for pushing the initial configuration and managing the device thereafter.

Why this answer

Zero-touch provisioning for vEdge routers requires the vBond orchestrator and vManage. vBond authenticates the vEdge and provides the addresses of the other controllers. vManage then delivers the configuration. vSmart is not required for initial provisioning, though it is needed for control plane functionality. DNA Center and APIC-EM are unrelated to SD-WAN.

Exam trap

The trap here is confusing the roles of the SD-WAN controllers and assuming that all are required for zero-touch provisioning, or mixing in components from other Cisco solutions.

379
Multi-Selecthard

A network engineer is implementing VXLAN with an EVPN control plane in a data center. The engineer must ensure that the underlay network supports the required traffic and that the overlay provides optimal forwarding. Which two statements are true regarding this implementation? (Choose two.)

Select 2 answers
A.The underlay network must be a Layer 2 network to carry VXLAN traffic.
B.EVPN requires that all VTEPs be in the same subnet.
C.The underlay network must support multicast for BUM traffic replication.
D.EVPN uses MP-BGP to distribute MAC and IP address reachability information.
E.VXLAN with EVPN supports ARP suppression to reduce broadcast traffic.
AnswersD, E

EVPN uses MP-BGP with the EVPN address family to distribute MAC and IP reachability information among VTEPs. This provides a control plane for VXLAN, enabling features like ARP suppression, optimal forwarding, and multi-homing. The BGP EVPN routes include MAC/IP advertisement routes, IMET routes for multicast, and Ethernet segment routes. This is a fundamental aspect of EVPN-based VXLAN.

Why this answer

EVPN uses MP-BGP to distribute MAC and IP reachability, enabling control-plane learning and features like ARP suppression. ARP suppression reduces broadcast traffic by allowing VTEPs to answer ARP requests locally. Multicast is not required in the underlay because EVPN uses ingress replication for BUM traffic.

The underlay must be Layer 3, and VTEPs can be in different subnets as long as they are reachable.

Exam trap

The trap here is assuming that VXLAN always requires multicast in the underlay, but EVPN eliminates that requirement by using BGP and ingress replication.

380
Matchingmedium

Drag and drop each VM storage type on the left to its matching characteristic on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Allocates storage only as data is written

Allocates all required storage at creation

Provides direct LUN access to a VM

VMware virtual disk file format

Microsoft virtual hard disk format

Why these pairings

Thin provisioning allocates space on demand. Thick provisioning allocates all space at creation. RDM (Raw Device Mapping) provides direct access to a LUN.

VMDK is the virtual disk file format. VHDX is Microsoft’s virtual hard disk format.

381
Matchingmedium

Drag and drop each DNA Center Intent API on the left to its matching use on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Retrieves network device details, serial numbers, and software versions

Provides physical and logical network topology maps

Lists network problems, severity, and suggested remediation

Tracks configuration changes, syslog messages, and SNMP traps

Manages site hierarchy and location-based network settings

Why these pairings

Intent APIs: inventory retrieves device details; topology provides network maps; issues reports network problems; events tracks changes and alerts.

382
MCQmedium

A network architect is designing a new branch office that must support wired and wireless users on the same Layer 2 segment while enforcing consistent security policy regardless of where a user connects. The design must minimize the number of VLANs and IP subnets that must be provisioned as users move between floors. Which Cisco architecture feature should be used to meet these requirements?

A.Cisco StackWise Virtual on the distribution switches
B.Cisco Software-Defined Access with traditional VLAN trunking to the WLC
C.Cisco SD-Access fabric with VXLAN overlay and policy-based segmentation
D.Cisco TrustSec with static SGACL enforcement on access ports
AnswerC

SD-Access decouples identity from location by using a VXLAN overlay, so a user keeps the same IP subnet and security group tag whether wired or wireless. This eliminates per-floor VLAN/subnet sprawl and enforces consistent group-based policy through the fabric, which directly matches the stated requirement for unified wired/wireless policy with minimal VLAN provisioning.

Why this answer

The requirement is location-independent identity with consistent policy and minimal VLAN/subnet provisioning across wired and wireless. SD-Access uses a VXLAN overlay with a LISP control plane and Cisco TrustSec group tags, allowing users to retain the same subnet and policy anywhere in the fabric. StackWise Virtual, standalone TrustSec, and VLAN trunking to a WLC all remain tied to physical VLAN boundaries and cannot deliver the same outcome.

Exam trap

The trap here is assuming that a high-availability feature such as StackWise Virtual also solves address and policy mobility across floors.

383
MCQmedium

A financial services firm wants to automate configuration backups of 200 Cisco IOS XE switches. The team prefers an imperative, script-driven approach where Python code calls a structured API and stores the retrieved configuration in a version-controlled repository. Which method best aligns with this goal?

A.Write a Python script using the requests library to issue RESTCONF GET requests against each switch and save the JSON responses to files.
B.Schedule a TFTP copy of the startup configuration from each switch to a central server using a cron job.
C.Use SNMP set operations to write the running configuration into a management server's MIB database.
D.Enable the Cisco IOS XE guest shell and run a Bash script that executes 'show running-config' on a schedule.
AnswerA

RESTCONF GET returns structured JSON or XML over HTTPS, and Python's requests library can call it directly from a script. Saving the responses into a repository gives the team version-controlled, structured backups. This matches the imperative, script-driven preference and avoids CLI parsing, making it the most aligned approach for programmatic configuration retrieval at scale.

Why this answer

RESTCONF GET requests return model-driven, structured data over HTTPS, and Python's requests library can issue them programmatically from a central control host. Saving the structured responses to a repository supports version control and diffing. Guest shell Bash scripting, SNMP, and TFTP all either rely on CLI output, cannot retrieve full configurations, or lack structured API semantics, so they miss the stated goal.

Exam trap

The trap here is equating any configuration backup method with an API-driven one, when TFTP and SNMP cannot return structured configuration data.

384
Drag & Dropmedium

Drag and drop the steps of VNF scaling up and scaling out steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Scaling up (vertical) or scaling out (horizontal) begins with the VNFM monitoring performance metrics and detecting a threshold breach. The VNFM then notifies the NFVO of the scaling requirement. The NFVO authorizes the scaling action.

The VNFM then coordinates with the VIM to allocate additional resources (scale up) or instantiate new VNF instances (scale out). Finally, the VNFM updates the VNF configuration to use the new resources or instances.

385
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip nat translations Pro Inside global Inside local Outside local Outside global --- 203.0.113.10 192.168.1.10 --- --- --- 203.0.113.11 192.168.1.11 --- --- tcp 203.0.113.10:1024 192.168.1.10:1024 198.51.100.5:80 198.51.100.5:80 Based on this output, what can be concluded?

A.The router is performing static NAT for two internal hosts.
B.The router is performing dynamic NAT for all translations.
C.The router is performing Port Address Translation (PAT) for all translations.
D.The router is translating outside global addresses to inside local addresses.
AnswerA

These translations are one-to-one and permanent, with no protocol or port fields and no outside address — a signature of manually configured static NAT. Each entry maps a private inside-local address to a public inside-global address, allowing consistent inbound and outbound connectivity for those two hosts. There is no address-pool assignment or timeout behavior, which further distinguishes it from dynamic and PAT translations.

Why this answer

The output shows two entries with '---' for protocol, indicating static NAT translations that map inside local addresses (192.168.1.10, 192.168.1.11) to inside global addresses (203.0.113.10, 203.0.113.11). The third entry is a dynamic translation for TCP traffic, but the presence of static entries confirms that static NAT is configured for at least two internal hosts. Therefore, option A is correct.

Exam trap

Cisco often tests the distinction between static and dynamic NAT by showing entries with '---' in the protocol field, which candidates may misinterpret as incomplete data or PAT, but it actually indicates a static mapping that does not use ports.

How to eliminate wrong answers

Option B is wrong because the output includes static entries (protocol '---') which are not dynamically allocated; dynamic NAT would show only entries with protocol types like TCP/UDP and would not have static mappings. Option C is wrong because PAT would show multiple inside global addresses sharing the same IP with different port numbers, but here each inside global address is unique (203.0.113.10 and 203.0.113.11) and the static entries have no port information. Option D is wrong because the translation direction is from inside local to inside global (source NAT), not translating outside global addresses to inside local addresses; the outside local and outside global columns are identical for the TCP entry, indicating no destination translation.

386
MCQmedium

A network engineer is troubleshooting intermittent packet loss on a WAN circuit connecting a branch office to headquarters. The engineer suspects the provider is not honoring the committed rate. Which tool should be used to measure one-way delay, jitter, and packet loss between the two sites and generate threshold-based alerts?

A.Cisco DNA Center Assurance with SWIM
B.IP SLA with UDP jitter operation
C.Embedded Packet Capture on the WAN interface
D.NetFlow export to a collector
AnswerB

UDP jitter operations in Cisco IP SLA send packets at a defined interval and measure round-trip latency, one-way delay, jitter, and packet loss, with configurable thresholds that trigger alerts or actions. This directly addresses the need to characterize the provider's handling of the committed rate across the WAN.

Why this answer

The correct tool is the one that actively generates synthetic traffic and reports latency, jitter, and loss with thresholds. IP SLA UDP jitter operations are purpose-built for this and integrate with tracking objects to trigger alerts or failover, which matches the engineer's need to verify the provider's adherence to the committed rate.

Exam trap

The trap here is confusing passive monitoring tools like NetFlow or packet capture with active performance measurement that can quantify one-way delay and jitter.

387
Multi-Selectmedium

A network engineer is hardening a Cisco IOS XE router against control plane attacks. The router runs OSPF, BGP, and SSH management. The engineer wants to apply Control Plane Policing (CoPP) to rate-limit nonessential traffic while ensuring routing protocols are not disrupted. Which two actions should the engineer take? (Choose two.)

Select 2 answers
A.Configure a single class map that matches all IP traffic and police it to a low rate to simplify the policy.
B.Use a route map to classify traffic and attach it to the control plane with the service-policy command.
C.Create class maps that match routing protocol traffic, such as OSPF and BGP, and assign them a higher policing rate than nonessential traffic.
D.Apply the CoPP policy map under control-plane configuration mode using the service-policy command.
E.Apply the CoPP policy map inbound on all WAN interfaces to filter traffic before it reaches the route processor.
AnswersC, D

Routing protocols are essential for network stability, so they should be matched in dedicated class maps and given sufficient policing rates to avoid dropping legitimate updates. This allows CoPP to protect the CPU while preventing disruption to OSPF and BGP adjacencies, which is a key requirement in the scenario.

Why this answer

Effective CoPP requires class maps that separate essential traffic, such as OSPF and BGP, from nonessential traffic, with appropriate policing rates for each. The policy map is then applied under control-plane configuration mode. This structure protects the route processor without disrupting routing protocols or management access.

Exam trap

The trap here is applying CoPP to data interfaces or using a single blanket policer, which would either miss CPU-bound traffic or throttle essential routing and management protocols.

388
MCQeasy

What is the maximum hop count for EIGRP?

A.255
B.15
C.128
D.Unlimited
AnswerA

EIGRP uses a 1-byte field to track hop count, which gives it an absolute ceiling of 255. This limit applies regardless of metric values, so even a route with a very low composite metric becomes unreachable if it traverses more than 255 routers. The value 255 is thus the finite, hard-coded maximum, and any route advertising a hop count beyond that is considered invalid.

Why this answer

EIGRP uses a maximum hop count of 255 to prevent routing loops, which is a hard limit enforced by the protocol. This value is configurable via the 'metric maximum-hops' command under the EIGRP process, but the absolute maximum is 255. Unlike distance-vector protocols like RIP, EIGRP is an advanced distance-vector protocol that uses the Diffusing Update Algorithm (DUAL) for loop avoidance, but the hop count serves as a final safety mechanism.

Exam trap

Cisco often tests the distinction between the default hop count (100) and the maximum hop count (255), leading candidates to mistakenly select 128 or 15 due to confusion with other protocols or default values.

How to eliminate wrong answers

Option B is wrong because 15 is the maximum hop count for RIP (Routing Information Protocol), not EIGRP; this is a common confusion between distance-vector protocols. Option C is wrong because 128 is the default hop count for EIGRP, not the maximum; the default is 100, but it can be increased up to 255. Option D is wrong because EIGRP does have a finite maximum hop count of 255; it is not unlimited, as the protocol must have a loop-prevention boundary.

389
MCQmedium

A network engineer is deploying Control Plane Policing on a Cisco IOS XE router that carries eBGP, OSPF, SSH management, and SNMP traffic. The engineer wants to ensure that BGP and OSPF routing updates are never dropped while still rate-limiting SSH and SNMP. Which CoPP configuration approach best meets this requirement?

A.Apply a single class-map matching all control-plane traffic and set a single police rate that is high enough for routing protocols.
B.Create separate class-maps for BGP, OSPF, SSH, and SNMP, then apply a policy-map where routing classes use police with a high conform rate and management classes use a lower police rate.
C.Use MQC with a single class-default and configure a priority queue for BGP and OSPF packets.
D.Configure an ACL that denies SSH and SNMP to the control plane and apply it inbound on all interfaces.
AnswerB

Separate class-maps allow granular classification, and the policy-map can apply different police actions per class. Routing classes can be policed generously (or with conform-action transmit and exceed-action transmit for critical control traffic), while SSH and SNMP are rate-limited. This is the standard CoPP design pattern for differentiated control-plane protection.

Why this answer

CoPP is designed to classify control-plane traffic into distinct classes and apply independent policers. Separating routing protocols from management protocols allows the engineer to protect BGP and OSPF adjacencies while still enforcing limits on SSH and SNMP. A single class-map or class-default cannot provide this granularity, and an ACL would block rather than rate-limit management traffic.

Exam trap

The trap here is assuming that a single high-rate policer can protect all control-plane traffic without distinguishing routing protocols from management protocols.

390
Matchingmedium

Drag and drop each MPLS label operation on the left to its matching action on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Adds a new label to the top of the label stack

Removes the top label from the label stack

Replaces the top label with a new label value

Removes the label before the final hop

Adds one or more labels to an unlabeled packet

Why these pairings

Push adds a new label to the stack, pop removes the top label, and swap replaces the top label with a new one.

391
MCQmedium

A network engineer is troubleshooting a DHCP issue on a Cisco router configured as a DHCP server for a VLAN. Clients in the VLAN are able to obtain IP addresses from the DHCP server, but they are not receiving the correct DNS server address. The engineer checks the DHCP pool configuration and sees the dns-server command is configured with the correct IP address. What is the most likely cause of the problem?

A.The DHCP pool is not associated with the correct VLAN interface using the network command.
B.The DNS server is unreachable from the DHCP server.
C.The ip dhcp excluded-address command is blocking the DNS server IP.
D.The DHCP client is configured with a static DNS server address.
AnswerA

The DHCP pool is correctly identified as the root cause when the network command defines a subnet that does not match the VLAN interface's primary IP subnet. Cisco IOS selects a DHCP pool by comparing the network statement's subnet with the subnet of the interface that received the client's DHCP request (or the giaddr from a DHCP relay). If there is no matching pool, the server may assign an address from a different, incorrectly configured pool or fail to offer an address entirely, and critically, pool-specific options such as the DNS server are not delivered because they are bound to the pool that is actually selected. The symptom of clients obtaining an IP but no DNS option strongly points to this mismatch.

Why this answer

The most likely cause is that the DHCP pool is not associated with the correct VLAN interface via the `network` command. Even if the `dns-server` command is correctly configured, the router will not apply that pool to clients on a different subnet. The DHCP server uses the `network` statement to match the client's subnet (derived from the interface IP) to the correct pool; if the pool's network does not match the VLAN interface's subnet, clients will receive an address from a different pool (or no pool) that lacks the correct DNS server.

Exam trap

Cisco often tests the misconception that configuring the `dns-server` command alone is sufficient, when in fact the pool must be correctly bound to the client's subnet via the `network` command for any options to be applied.

How to eliminate wrong answers

Option B is wrong because the DNS server being unreachable from the DHCP server affects whether clients can resolve names after receiving the address, but it does not prevent the DHCP server from sending the correct DNS server IP in the DHCP offer. Option C is wrong because the `ip dhcp excluded-address` command only prevents specific IPs from being leased; it does not block the DNS server IP from being advertised as an option. Option D is wrong because a client configured with a static DNS server address would ignore the DHCP-provided DNS server, but the question states clients are not receiving the correct DNS server address, implying the DHCP server is not sending it, not that the client is overriding it.

392
MCQeasy

A network engineer is deploying streaming telemetry from a Cisco ASR 1000 router to a collector using gRPC. The engineer notices that the telemetry data is not being received by the collector. The router shows that the gRPC server is running and the collector is reachable. What is the most likely cause?

A.No telemetry subscription is configured on the router for the desired data paths.
B.The gRPC server is configured with the wrong port number.
C.The collector is not listening on the same IP address as configured on the router.
D.The telemetry data is encoded in GPB, but the collector expects JSON.
AnswerA

In model-driven telemetry, a subscription is a required configuration construct that binds the desired YANG data paths (e.g., interfaces, CPU/memory stats) to a destination collector. Even if the gRPC server is operational and the collector is reachable, no telemetry data is streamed until a subscription is created and active on the router. This is the root cause because the symptom is a complete absence of data, not malformed or dropped data.

Why this answer

The gRPC server running and the collector being reachable indicates the transport layer is functional. However, streaming telemetry requires an explicit subscription configuration on the router that defines which data paths (e.g., YANG paths) to stream and to which collector. Without a subscription, the router has no instruction to send telemetry data, even if the gRPC server is active and network connectivity exists.

Exam trap

Cisco often tests the distinction between the transport protocol (gRPC) being operational and the telemetry subscription being configured, trapping candidates who assume a running gRPC server implies telemetry data is flowing.

How to eliminate wrong answers

Option B is wrong because the gRPC server is already running, which implies the port number is correctly configured; if the port were wrong, the server would not start or the collector would not be reachable. Option C is wrong because the collector is reachable, indicating IP reachability is not the issue; the collector's listening IP is irrelevant if no subscription is pushing data. Option D is wrong because encoding mismatch (GPB vs JSON) would cause parsing errors at the collector, not a complete absence of data reception; the router would still transmit the data.

393
Drag & Dropmedium

Drag and drop the steps of SD-WAN zero-touch provisioning (ZTP) flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

ZTP starts with the device contacting the DHCP server for an IP address, then resolving the vManage hostname via DNS, establishing a DTLS connection to vManage, downloading the full configuration, and finally applying the configuration to become operational.

394
Multi-Selectmedium

A network architect is designing a VXLAN EVPN fabric on Cisco Nexus 9000 switches to replace a traditional three-tier data center design. The architect wants to use a distributed anycast gateway so that hosts can move between leaf switches without changing their default gateway. Which two statements correctly describe the anycast gateway design? (Choose two.)

Select 2 answers
A.Only the spine switches can host the anycast gateway function
B.The same gateway IP and MAC address are configured on every leaf switch that hosts the VLAN
C.Hosts must be reconfigured with a new default gateway each time they migrate
D.Each leaf switch must use a unique gateway MAC address to avoid duplicate MAC detection
E.The gateway MAC is a shared virtual MAC, typically derived from the reserved Cisco anycast gateway range
AnswersB, E

An anycast gateway uses the same virtual IP and virtual MAC on every leaf that participates in the VLAN, so a host keeps the same default gateway regardless of which leaf it attaches to. This is what enables seamless workload mobility without re-ARPing or changing host configuration when a virtual machine moves between racks.

Why this answer

A distributed anycast gateway places the same virtual gateway IP and virtual MAC on every leaf switch that hosts the VLAN. Hosts keep a consistent default gateway no matter which leaf they attach to, and ARP is answered locally on the attached leaf. This supports seamless workload mobility and avoids stretching traffic to a central gateway.

Exam trap

The trap here is assuming each leaf needs a unique gateway MAC, when the design deliberately shares one virtual MAC across all participating leaves.

395
Drag & Dropmedium

Drag and drop the steps of EIGRP authentication using MD5 key-chain into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order for configuring EIGRP MD5 authentication with a key chain is: first, create a key chain using the 'key chain' command. Next, configure a key number and key-string under the key chain. Then, enter interface configuration mode for the interface on which EIGRP is enabled.

After that, issue the command 'ip authentication mode eigrp md5' to set the authentication mode. Finally, issue the command 'ip authentication key-chain eigrp <name>' to apply the key chain to the interface.

396
MCQmedium

A Python script using Netmiko is written to send a command to a Cisco router: from netmiko import ConnectHandler device = { 'device_type': 'cisco_ios', 'ip': '192.168.1.1', 'username': 'admin', 'password': 'cisco', 'secret': 'enable' } connection = ConnectHandler(**device) connection.enable() output = connection.send_command('show ip interface brief') print(output) connection.disconnect() What is the potential issue with this script?

A.The script will fail because 'device_type' should be 'cisco_ios_telnet' for telnet connections.
B.The script will work correctly without any issues.
C.The script will fail because 'secret' is misspelled; it should be 'enable_secret'.
D.The script lacks exception handling for authentication or connection failures, which can cause the script to crash.
AnswerD

The script lacks exception handling for authentication or connection failures, which means any Netmiko exception such as AuthenticationException, NetmikoTimeoutException, or ssh_exception.NetmikoTimeoutException will propagate up and crash the script. In real-world environments, network devices may reject credentials, have SSH disabled, or become temporarily unreachable, and without try/except blocks the automation halts immediately. Properly designed scripts should catch these specific exceptions, log meaningful error messages, and optionally implement retry logic to ensure resilience.

Why this answer

The script lacks exception handling (e.g., try-except blocks) to catch authentication failures, connection timeouts, or device unreachable errors. Without this, if the device is down, credentials are wrong, or the SSH/Telnet service is unavailable, the script will crash with an unhandled exception, making it unreliable for production automation.

Exam trap

Cisco often tests the distinction between syntactically correct code and robust code, trapping candidates who assume a script that 'looks right' will always work, ignoring the need for error handling in automation scripts.

How to eliminate wrong answers

Option A is wrong because 'device_type' 'cisco_ios' defaults to SSH, not Telnet; the script does not specify a transport, so it uses SSH, and the script would work fine over SSH. Option B is wrong because while the syntax is correct, the script is fragile and will crash on any connection or authentication error, so it is not 'without any issues' in a real-world scenario. Option C is wrong because 'secret' is the correct Netmiko key for the enable password; 'enable_secret' is not a valid Netmiko dictionary key.

397
MCQhard

A network engineer issues the following command on Router R2: R2# show ip ospf interface GigabitEthernet0/0 GigabitEthernet0/0 is up, line protocol is up Internet Address 192.168.1.2/24, Area 0 Process ID 1, Router ID 2.2.2.2, Network Type BROADCAST, Cost: 10 Transmit Delay is 1 sec, State DR, Priority 1 Designated Router (ID) 2.2.2.2, Interface address 192.168.1.2 Backup Designated router (ID) 1.1.1.1, Interface address 192.168.1.1 Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5 Hello due in 00:00:03 Index 1/1/1, flood queue length 0 Next 0x0(0)/0x0(0)/0x0(0) Last flood scan length is 1, maximum is 1 Last flood scan time is 0 msec, maximum is 0 msec Neighbor Count is 2, Adjacent neighbor count is 2 Adjacent with neighbor 1.1.1.1 (Backup Designated Router) Adjacent with neighbor 3.3.3.3 Based on this output, what can be concluded?

A.R2 has a full OSPF adjacency with all neighbors on this segment.
B.R2 is the Backup Designated Router on this segment.
C.The OSPF cost to reach the network 192.168.1.0/24 is 20.
D.R2 will send hello packets every 40 seconds.
AnswerA

The 'adjacent neighbor count' of 2 is equal to the total neighbor count, which in OSPF terminology means every discovered neighbor has reached the full state after completing database exchange. On a multi-access broadcast segment, only the DR and BDR form full adjacencies with all routers, so this equality confirms that R2 has fully synchronized its LSDB with both neighbors and no neighbor is stuck in two-way or exstart state.

Why this answer

The output shows that R2 is the Designated Router (DR) on this broadcast segment, with two neighbors listed: 1.1.1.1 (BDR) and 3.3.3.3. The 'Adjacent neighbor count is 2' and both neighbors are listed as 'Adjacent with neighbor', confirming that R2 has formed full OSPF adjacencies with all neighbors on this segment. In OSPF broadcast networks, only the DR and BDR form full adjacencies with all routers, while non-DR/BDR routers only form full adjacencies with the DR and BDR.

Exam trap

Cisco often tests the distinction between 'neighbor count' and 'adjacent neighbor count' — candidates may incorrectly assume that all neighbors are fully adjacent, but in broadcast networks, only the DR and BDR have full adjacencies with all routers, while other routers only have full adjacency with the DR and BDR.

How to eliminate wrong answers

Option B is wrong because R2 is the Designated Router (State DR, Priority 1), not the Backup Designated Router; the BDR is 1.1.1.1. Option C is wrong because the cost shown (Cost: 10) is the OSPF cost of the GigabitEthernet0/0 interface on R2, not the cost to reach the network 192.168.1.0/24; the cost to reach that network would be the sum of outgoing interface costs along the path. Option D is wrong because the Hello timer is configured as 10 seconds (Hello 10), not 40 seconds; the Dead timer is 40 seconds.

398
MCQmedium

Given the following Ansible playbook snippet: --- - name: Configure interface hosts: routers gather_facts: no tasks: - name: Set IP address ios_config: lines: - ip address 192.168.1.1 255.255.255.0 - no shutdown parents: interface GigabitEthernet0/1 What is the effect of this playbook?

A.It configures IP address 192.168.1.1/24 on interface GigabitEthernet0/1 and enables it.
B.It configures the IP address globally, not under the interface.
C.It only configures the IP address; no shutdown is ignored because it is not a valid command.
D.It fails because 'parents' cannot be used with 'lines' in ios_config.
AnswerA

This is the correct behavior. The 'parents: interface GigabitEthernet0/1' parameter makes the Ansible ios_config module first enter interface configuration mode; then the commands in 'lines' are applied as subcommands under that interface. The line 'ip address 192.168.1.1 255.255.255.0' assigns the IPv4 address, and 'no shutdown' changes the interface administrative state from admin-down to up, enabling the interface. The module mimics a human CLI session, so both commands are committed to the running configuration exactly as if typed manually.

Why this answer

The `ios_config` module uses the `parents` parameter to navigate into interface configuration mode before applying the `lines` commands. The `ip address 192.168.1.1 255.255.255.0` command configures the IP address with a /24 subnet mask, and `no shutdown` administratively enables the interface. This is the standard Cisco IOS behavior for interface configuration.

Exam trap

The trap here is that candidates may think `parents` is only for ACL or routing contexts, or that `lines` and `parents` are mutually exclusive, when in fact `parents` is the standard way to nest commands under a parent configuration block like an interface.

How to eliminate wrong answers

Option B is wrong because the `parents: interface GigabitEthernet0/1` parameter ensures the commands are executed in interface configuration mode, not globally; without `parents`, the commands would be applied globally, but here they are correctly scoped. Option C is wrong because `no shutdown` is a valid Cisco IOS interface command that enables the interface, and the `ios_config` module sends it exactly as written; it is not ignored. Option D is wrong because `parents` is explicitly designed to be used with `lines` in the `ios_config` module to specify the parent configuration context (e.g., interface mode) before applying the lines; this is a supported and common usage.

399
Matchingmedium

Drag and drop each STP port role on the left to its matching definition on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Best path to the root bridge

Best path for a given segment

Alternate path to the root bridge

Redundant path to the same segment

Why these pairings

Root port is the best path to the root bridge; Designated port is the best path for a segment; Alternate port provides an alternative path to the root; Backup port provides a redundant path to the same segment.

400
MCQmedium

A network engineer configures a Cisco IOS router to authenticate administrative SSH logins against a Cisco ISE server using TACACS+. After applying the configuration, a valid ISE user can log in but receives no privilege level and cannot enter privileged EXEC mode. The relevant configuration is: aaa new-model aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local tacacs server ISE address ipv4 10.10.10.50 key Cisco123 Which action most directly resolves the problem?

A.Enable AAA accounting with the aaa accounting exec default start-stop group tacacs+ command so ISE records the session.
B.Configure the ISE TACACS+ device to return the cisco-av-pair shell:priv-lvl=15 attribute for authorized users.
C.Add the aaa authorization commands 15 default group tacacs+ local command to the router.
D.Change the aaa authentication login method list to use the local database before the tacacs+ group.
AnswerB

TACACS+ authorization for EXEC sessions relies on AV pairs returned by the server. The cisco-av-pair shell:priv-lvl attribute tells the router which privilege level the user receives after authentication. Without it, the AAA client defaults to privilege level 1, so the user cannot enter privileged EXEC mode. Supplying the AV pair in the ISE authorization policy resolves the symptom directly.

Why this answer

Successful TACACS+ authentication only proves the user's identity; the privilege level comes from authorization AV pairs. Because the router shows the user authenticated but stuck at unprivileged EXEC, the ISE authorization policy must be returning no shell:priv-lvl value. Adding the cisco-av-pair shell:priv-lvl=15 attribute to the matching authorization rule gives the router the privilege level to apply after login.

Exam trap

The trap here is assuming that successful TACACS+ authentication automatically carries a privilege level, when privilege assignment actually depends on authorization AV pairs returned by the server.

401
MCQmedium

A network engineer is implementing VXLAN on a Cisco Nexus switch. The engineer wants to ensure that the VXLAN tunnel endpoint (VTEP) can forward traffic between VLANs by mapping them to VNIs. Which component is responsible for the mapping of VLANs to VNIs on the VTEP?

A.The VXLAN Network Identifier (VNI) to VLAN mapping table
B.The MAC address table
C.The ARP table
D.The underlay routing protocol
AnswerA

On a VTEP, the mapping of VLANs to VNIs is configured in the VNI-to-VLAN mapping table. When a frame enters an access port on a VLAN, the VTEP looks up the corresponding VNI and encapsulates the frame with a VXLAN header containing that VNI. This mapping is essential for bridging VLANs across the VXLAN overlay. Thus, this component is responsible for the mapping.

Why this answer

In VXLAN, each VLAN that needs to be extended across the overlay is mapped to a unique VNI. This mapping is configured on the VTEP, typically in a VLAN-to-VNI mapping table. When a frame from a VLAN enters the VTEP, the switch uses this mapping to determine the VNI and encapsulates the frame accordingly.

Therefore, the VNI-to-VLAN mapping table is the component responsible for this function.

Exam trap

The trap here is confusing the MAC address table or ARP table with the VLAN-to-VNI mapping, which is a separate configuration on the VTEP.

402
MCQmedium

A network engineer is configuring EIGRP on a router that connects to multiple remote sites via Frame Relay. The engineer wants to ensure that EIGRP does not form adjacencies over the Frame Relay interfaces to reduce overhead, but still wants to advertise the connected networks. The engineer applies the 'passive-interface' command to the Frame Relay interfaces. However, the remote sites stop receiving the routes. What is the most likely reason?

A.The 'passive-interface' command also prevents EIGRP from sending routing updates on that interface.
B.The 'passive-interface' command only affects hello packets, not updates, but the remote sites are not configured correctly.
C.The engineer should use the 'neighbor' command under the EIGRP process to specify the remote routers.
D.The remote sites are using a different EIGRP autonomous system number.
AnswerA

In EIGRP, the passive-interface command does far more than suppress hello packets; it completely disables the protocol on the specified interface for both control and data-plane updates. Specifically, the router will neither send nor receive EIGRP hello packets, which prevents the formation of any neighbor adjacency, and it will also suppress the transmission of all routing updates (unicast or multicast) out that interface. This is why remote sites stop receiving routes: even though the adjacency may have existed before, once passive-interface is applied, the router no longer advertises any learned routes over that link. The command is often used on LAN-facing interfaces to stop unnecessary multicasts, but on a WAN link it effectively isolates the remote site from the EIGRP domain.

Why this answer

The 'passive-interface' command in EIGRP prevents both hello and routing updates from being sent on the specified interface. Since EIGRP relies on hello packets to form and maintain neighbor adjacencies, applying this command to the Frame Relay interfaces stops adjacency formation. Without an adjacency, no routes are exchanged, so the remote sites stop receiving the advertised networks.

Exam trap

Cisco often tests the misconception that 'passive-interface' only affects routing updates but not hello packets, leading candidates to think adjacencies can still form and routes can be received.

How to eliminate wrong answers

Option A is correct because the 'passive-interface' command suppresses both hello and routing updates, breaking adjacency. Option B is wrong because the 'passive-interface' command does affect updates, not just hello packets; it suppresses all EIGRP traffic on the interface, including updates. Option C is wrong because the 'neighbor' command is used for EIGRP over non-broadcast multi-access (NBMA) networks like Frame Relay to define static neighbors, but it does not override the 'passive-interface' command; the interface would still be passive and no packets would be sent.

Option D is wrong because if the remote sites used a different autonomous system number, they would never form adjacencies regardless of the passive-interface command; the question states they were receiving routes before the change, so the AS numbers must match.

403
MCQmedium

A network automation engineer is using the ncclient Python library to retrieve the running configuration from a Cisco IOS XE device via NETCONF. The engineer writes a script that establishes a NETCONF session and sends a <get-config> RPC. However, the script fails with an error indicating the source datastore is not specified. What should the engineer do to correct the script?

A.Add a <filter> element to specify the configuration subtree.
B.Change the RPC to <get> instead of <get-config>.
C.Include a <target> element with <running/> in the RPC.
D.Add a <source> element with <running/> inside the <get-config> RPC.
AnswerD

The <get-config> RPC requires a <source> element to specify which datastore to retrieve configuration from. The running datastore is commonly used. Without it, the NETCONF server cannot determine which configuration to return, resulting in an error. Adding <source><running/></source> resolves the issue.

Why this answer

The <get-config> RPC in NETCONF requires a <source> element to identify the datastore (e.g., running, candidate, startup). Without it, the server cannot process the request. The correct fix is to include <source><running/></source> in the RPC.

This is a common oversight when building NETCONF scripts.

Exam trap

The trap here is assuming that <get-config> works like <get> and does not need a source, or confusing the <target> element used in edit-config with the <source> element needed for get-config.

404
MCQmedium

Consider this AAA configuration: aaa new-model aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local aaa accounting exec default stop-only group tacacs+ tacacs-server host 10.0.0.1 key SecretKey tacacs-server host 10.0.0.2 key SecretKey What is the effect of the accounting command?

A.Accounting records are sent to TACACS+ only when the exec session ends.
B.Accounting records are sent to TACACS+ at both session start and end.
C.Accounting records are sent to TACACS+ only at session start.
D.Accounting is disabled because the command uses 'stop-only' incorrectly.
AnswerA

The `aaa accounting exec default stop-only group tacacs+` command instructs the router to generate a TACACS+ stop accounting record only when the EXEC session ends. This record contains cumulative data like session duration, input/output bytes, and the reason the session closed, and it is sent to the TACACS+ server at that moment. There is no start record transmitted at session initiation, which matches the 'stop-only' behavior.

Why this answer

The `aaa accounting exec default stop-only group tacacs+` command configures TACACS+ accounting to send records only when an exec session ends. The `stop-only` keyword explicitly instructs the device to generate a single accounting record at session termination, not at session start. This is a standard TACACS+ accounting feature used to minimize network overhead while still capturing session duration and resource usage.

Exam trap

Cisco often tests the distinction between `start-stop` and `stop-only` keywords in accounting commands, and the trap here is that candidates mistakenly assume `stop-only` means accounting is disabled or that it still sends a start record, when in fact it explicitly omits the start record.

How to eliminate wrong answers

Option B is wrong because `stop-only` specifically prevents accounting records from being sent at session start; only a stop record is generated. Option C is wrong because `stop-only` sends records only at session end, not at session start. Option D is wrong because `stop-only` is a valid keyword in the `aaa accounting exec` command; it does not disable accounting but rather restricts it to stop records only.

405
Multi-Selecthard

Which TWO statements are true about RESTCONF and NETCONF in a Cisco IOS XE environment? (Choose two.)

Select 2 answers
A.RESTCONF uses HTTP methods (GET, POST, PUT, DELETE) and supports JSON and XML encoding.
B.RESTCONF supports the candidate datastore for editing configurations.
C.NETCONF uses HTTP as its transport protocol.
D.RESTCONF and NETCONF both support JSON and XML encoding.
E.NETCONF uses XML-encoded RPCs over a secure SSH session.
AnswersA, E

RESTCONF indeed uses HTTP methods and supports JSON and XML.

Why this answer

RESTCONF is designed to use standard HTTP methods (GET, POST, PUT, DELETE, PATCH) for CRUD operations on YANG-defined data, and it supports both JSON and XML encoding formats. This aligns with its goal of providing a simpler, web-friendly interface compared to NETCONF.

Exam trap

Cisco often tests the misconception that both protocols support JSON and XML equally, or that NETCONF uses HTTP, leading candidates to select option D or C incorrectly.

406
MCQhard

A network engineer is implementing Cisco TrustSec in a data center. The engineer wants to enforce security policies based on logical groupings of endpoints rather than IP addresses. Which component is used to assign a Security Group Tag (SGT) to traffic at the ingress point?

A.Ingress enforcement device
B.Security Group ACL (SGACL)
C.Egress enforcement device
D.Cisco Identity Services Engine (ISE)
AnswerA

The ingress enforcement device, such as a switch or wireless controller, assigns the SGT to traffic as it enters the network. It can do this statically via port configuration or dynamically based on authentication and authorization from Cisco ISE. The SGT is then carried in the packet, allowing egress devices to enforce SGACLs based on the tag without needing to reclassify the traffic.

Why this answer

In Cisco TrustSec, the ingress enforcement device assigns the Security Group Tag (SGT) to packets as they enter the network. This can be done statically by configuring a port or dynamically via 802.1X authentication and authorization with Cisco ISE. The SGT is then carried in the packet, enabling egress enforcement devices to apply SGACLs based on the tag without re-examining IP addresses.

Exam trap

The trap here is confusing the role of Cisco ISE, which defines and provides SGT information, with the ingress device that actually applies the tag to the traffic.

407
MCQhard

A company is implementing QoS in a campus network. Voice traffic must be prioritized over data traffic, and all traffic should be marked at Layer 2 and Layer 3. Which combination of marking values should be used on access ports to achieve this?

A.CoS 5, DSCP AF41
B.CoS 5, DSCP CS3
C.CoS 5, DSCP EF
D.CoS 4, DSCP EF
AnswerC

CoS 5 combined with DSCP EF (Expedited Forwarding, DSCP 46) is the industry-standard marking for voice bearer traffic in a campus network. This dual marking ensures that voice frames are placed in the strict-priority queue at both Layer 2 and Layer 3, providing the low latency, low jitter, and minimal packet loss that real-time audio requires. The EF PHB (Per-Hop Behavior) is designed to guarantee a configured bandwidth and queue service, while CoS 5 aligns with the Cisco-recommended voice VLAN and switch port trust settings, making this the only correct answer.

Why this answer

Voice traffic requires strict priority queuing, which is achieved by marking with CoS 5 at Layer 2 and DSCP EF (46) at Layer 3. CoS 5 maps to the priority queue in Cisco switches, and DSCP EF is the standard per-hop behavior for Expedited Forwarding (RFC 3246), ensuring low latency and jitter for voice. Access ports must trust these markings to prioritize voice over data traffic.

Exam trap

The trap here is that candidates confuse CoS 5 with DSCP EF for voice but may pick CoS 4 (used for video) or DSCP AF41 (used for premium data), failing to recognize that voice requires both strict priority marking (CoS 5) and the Expedited Forwarding PHB (DSCP EF) to guarantee low-latency treatment.

How to eliminate wrong answers

Option A is wrong because DSCP AF41 (Assured Forwarding 4, low drop) is designed for premium data traffic, not real-time voice; it does not provide strict priority queuing and can be subject to congestion management. Option B is wrong because DSCP CS3 (Class Selector 3) is typically used for broadcast video or signaling, not voice; it lacks the strict priority treatment required for real-time audio. Option D is wrong because CoS 4 is used for video conferencing (e.g., CoS 4, DSCP AF41) or streaming video, not voice; voice requires CoS 5 to map to the priority queue, and using CoS 4 would place voice in a lower-priority queue.

408
MCQeasy

A network engineer is writing a Python script using the ncclient library to retrieve the running configuration from a Cisco IOS XE device via NETCONF. The script uses the <get-config> RPC with the source datastore set to 'running'. After running the script, the engineer receives a large XML response but needs to extract only the interface configuration. Which NETCONF capability allows the engineer to filter the response to include only specific configuration data?

A.The 'rollback-on-error' capability, which reverts changes if an error occurs and returns only the changed data.
B.The 'candidate' datastore, which contains only the differences from the running configuration.
C.The 'with-defaults' capability, which allows the server to return only non-default configuration.
D.The <filter> element within the <get-config> RPC, specifying a subtree filter or XPath filter.
AnswerD

NETCONF supports filtering of <get-config> and <get> responses using the <filter> element. The filter can be a subtree filter (matching XML structure) or an XPath filter (using XPath expressions). By specifying a filter, the engineer can limit the response to only the desired configuration, such as interfaces. This is a standard NETCONF capability and is essential for efficient data retrieval.

Why this answer

NETCONF provides a <filter> element within <get-config> and <get> RPCs to restrict the response to specific data. The filter can be a subtree filter or an XPath filter. This allows the engineer to retrieve only the interface configuration, reducing the payload and processing time.

The other capabilities mentioned do not serve this purpose.

Exam trap

The trap here is confusing capabilities that affect data representation (like with-defaults) with those that filter data (like filter).

409
MCQmedium

An engineer is configuring a new switch stack using Cisco StackWise technology. The stack must be resilient to the failure of the active switch, and the engineer wants to ensure that the standby switch takes over with minimal disruption. The engineer has four switches in the stack. Which statement describes the role of the standby switch in a StackWise stack?

A.The standby switch is responsible for managing the stack and is the primary switch for forwarding traffic.
B.The standby switch is elected based on the highest priority value, and it only becomes active if the current active switch fails.
C.The standby switch actively forwards traffic and maintains a synchronized copy of the active switch's configuration and state.
D.The standby switch takes over as the active switch if the active switch fails, and it is kept synchronized with the active switch's configuration and state.
AnswerD

In a StackWise stack, the standby switch is a hot-standby that continuously synchronizes its configuration and state with the active switch. If the active switch fails, the standby switch quickly becomes the new active switch, minimizing disruption. This is the correct description of the standby switch's role, ensuring high availability and rapid failover.

Why this answer

The standby switch in a StackWise stack is a hot-standby that maintains a synchronized copy of the active switch's configuration and state. Upon failure of the active switch, the standby switch assumes the active role, providing redundancy and minimal downtime. This mechanism is critical for stack resilience, allowing the stack to continue operating seamlessly.

Exam trap

The trap here is assuming that the standby switch forwards traffic or participates in management, when in fact it remains in a passive hot-standby state until a failover occurs.

410
MCQeasy

What is the default trust state of a Cisco IOS switch port when no 'mls qos trust' command is configured?

A.The port trusts the CoS value of incoming packets.
B.The port trusts the DSCP value of incoming packets.
C.The port is untrusted and marks all incoming packets with CoS 0.
D.The port trusts both CoS and DSCP values.
AnswerC

When QoS is globally enabled, all switchports default to an untrusted state, meaning they do not preserve any priority information carried in incoming frames. Every packet received on such a port is marked with CoS 0 (and correspondingly DSCP 0) before entering the switch fabric, so saying the port is untrusted and marks all packets with CoS 0 accurately describes the default behavior.

Why this answer

By default, Cisco IOS switch ports are untrusted for QoS. Without the 'mls qos trust' command, the port does not trust any Layer 2 CoS or Layer 3 DSCP markings. Instead, it applies a default CoS value of 0 to all incoming packets, effectively re-marking them to the lowest priority.

This ensures that traffic from untrusted sources (e.g., end hosts) does not retain potentially high-priority markings.

Exam trap

Cisco often tests the misconception that a switch port will trust existing markings by default, but the correct default behavior is to treat all ports as untrusted and apply CoS 0.

How to eliminate wrong answers

Option A is wrong because the port does not trust the CoS value by default; it overwrites it with CoS 0. Option B is wrong because the port does not trust the DSCP value by default; DSCP is ignored and the port uses the default CoS 0. Option D is wrong because the port trusts neither CoS nor DSCP by default; both are overwritten with CoS 0 unless an explicit 'mls qos trust' command is configured.

411
MCQeasy

A network administrator is deploying a new Cisco Catalyst switch in a campus network. The administrator wants to enable a feature that automatically assigns a voice VLAN to Cisco IP phones connected to the switch, based on CDP or LLDP information. Which feature should be configured?

A.VLAN Trunking Protocol
B.Voice VLAN
C.Private VLAN
D.Dynamic ARP Inspection
AnswerB

Voice VLAN is a Cisco feature that automatically assigns a VLAN to IP phones based on CDP or LLDP discovery. The switch detects the phone and places its voice traffic in the configured voice VLAN, while data traffic from a connected PC remains in the access VLAN. This simplifies deployment and ensures QoS for voice.

Why this answer

The Voice VLAN feature allows a switch to automatically assign a VLAN to Cisco IP phones using CDP or LLDP. When a phone is detected, the switch instructs the phone to tag voice traffic with the voice VLAN ID. This separates voice and data traffic, enabling QoS and security policies.

The other options are unrelated to automatic voice VLAN assignment.

Exam trap

The trap here is confusing VLAN management protocols like VTP with endpoint-specific VLAN assignment features like Voice VLAN.

412
MCQmedium

A network engineer is deploying a Cisco Nexus 9000 leaf-spine fabric with VXLAN EVPN. The design requires that all leaf switches act as VTEPs and that each leaf learn remote MAC addresses only from the fabric control plane rather than from data-plane flooding. Which configuration on the leaf switches accomplishes this requirement?

A.Configure `arp suppression` on all leaf switches so that ARP requests are answered locally without control-plane involvement.
B.Configure the NVE interface with `source-interface loopback0` and enable `host-reachability protocol bgp`.
C.Configure `flooding enable` globally on each leaf so unknown unicast frames are replicated to all VTEPs in the fabric.
D.Configure `ingress-replication protocol static` on the NVE interface with a list of all remote VTEP addresses.
AnswerB

Enabling BGP as the host-reachability protocol on the NVE interface causes the leaf to advertise and learn MAC/IP and IMET routes through EVPN, so remote MAC addresses are resolved from the control plane instead of flood-and-learn. The loopback source provides a stable VTEP address reachable across the underlay, which is required for the EVPN peering and for tunnel endpoints to be consistent.

Why this answer

The requirement is control-plane MAC learning across the VXLAN fabric. Binding the NVE interface to a loopback and enabling BGP as the host-reachability protocol makes the leaf a VTEP that exchanges EVPN MAC/IP and IMET routes with its peers. Remote MAC addresses are then resolved from BGP EVPN advertisements, eliminating flood-and-learn.

Flooding, static ingress replication, and ARP suppression alone cannot satisfy that control-plane requirement.

Exam trap

The trap here is assuming that enabling ARP suppression or flooding achieves control-plane MAC learning, when only the host-reachability protocol tied to BGP EVPN does that.

413
MCQmedium

Given the following configuration: ip access-list extended FILTER permit tcp any host 10.1.1.1 eq 22 permit icmp any any echo-reply ! interface GigabitEthernet0/4 ip access-group FILTER in What traffic is permitted?

A.Only SSH traffic to 10.1.1.1 is permitted.
B.SSH to 10.1.1.1 and ICMP Echo Reply are permitted.
C.All ICMP traffic is permitted.
D.Only traffic from host 10.1.1.1 is permitted.
AnswerB

The ACL permits exactly two types of traffic: SSH to destination host 10.1.1.1, matching the ubiquitous TCP/22 ACE, and ICMP echo-reply (type 0), which is the response packet generated when the device answers a ping. The first ACE uses 'host 10.1.1.1' as the destination, and the second ACE explicitly matches that ICMP type. Together, those two permit statements validate this answer as the only fully accurate description of the ACL's effect.

Why this answer

The access list FILTER permits TCP traffic to destination host 10.1.1.1 on port 22 (SSH) and ICMP packets of type Echo Reply. Since the list is applied inbound on GigabitEthernet0/4, only these two types of traffic are allowed into the interface. Option B correctly identifies both permitted traffic types.

Exam trap

Cisco often tests the distinction between 'permit icmp any any echo-reply' (only replies) versus 'permit icmp any any' (all ICMP), leading candidates to overgeneralize the ICMP permit.

How to eliminate wrong answers

Option A is wrong because it omits the ICMP Echo Reply permit, which is explicitly allowed by the second ACE. Option C is wrong because the ICMP permit is limited to echo-reply only, not all ICMP types (e.g., echo, unreachable, time-exceeded are denied). Option D is wrong because the ACL permits traffic to host 10.1.1.1, not from it, and also permits ICMP echo-reply from any source.

414
MCQmedium

A network engineer is using Ansible to manage a group of Cisco IOS XE devices. The engineer wants to ensure that the playbook can securely connect to the devices without prompting for passwords and without storing passwords in plaintext in the playbook. Which method should be used to provide the credentials?

A.Use the ansible_ssh_pass variable in the inventory file and encrypt the inventory with Ansible Vault.
B.Use the --ask-pass command-line option when running the playbook.
C.Store the passwords in an encrypted file using Ansible Vault and reference them in the playbook.
D.Set the ANSIBLE_PASSWORD environment variable on the control node before running the playbook.
AnswerC

Ansible Vault allows encrypting sensitive data such as passwords. The encrypted file can be decrypted at runtime with a vault password, which can be provided via a file or prompt. This keeps passwords out of plaintext in the playbook and enables secure, non-interactive automation. This is the recommended method for securing credentials in Ansible.

Why this answer

Ansible Vault provides a secure way to encrypt sensitive data like passwords. By storing credentials in an encrypted file and referencing them in the playbook, the engineer can run playbooks without interactive prompts and without exposing passwords in plaintext. This is the standard best practice for securing credentials in Ansible automation, including for Cisco IOS XE devices.

Exam trap

The trap here is thinking that environment variables or interactive prompts are secure enough, when they either expose passwords or require manual intervention.

415
MCQeasy

A network administrator needs to secure management access to a Cisco IOS XE switch. The requirement is to ensure that only SSH version 2 is used for remote CLI access, and that Telnet is disabled. Which configuration achieves this?

A.Configure 'transport input telnet ssh' on the VTY lines and set 'ip ssh version 2' globally.
B.Configure 'transport output ssh' on the VTY lines and set 'ip ssh version 1' globally.
C.Configure 'transport input ssh' on the VTY lines and set 'ip ssh version 2' globally.
D.Configure 'line vty 0 4' with 'login local' and 'password cisco', then set 'ip ssh version 2' globally.
AnswerC

The 'transport input ssh' command on the VTY lines restricts remote CLI access to SSH only, effectively disabling Telnet. Setting 'ip ssh version 2' globally forces the device to use only SSH version 2. Together, these commands meet the requirement to allow only SSHv2 and block Telnet, which is the standard hardening practice for management access.

Why this answer

Restricting VTY access to SSH with 'transport input ssh' and forcing SSH version 2 with 'ip ssh version 2' ensures that only secure SSHv2 sessions are accepted. This combination disables Telnet and prevents fallback to the weaker SSH version 1, satisfying the management access hardening requirement.

Exam trap

The trap here is assuming that setting 'ip ssh version 2' alone disables Telnet, when the VTY transport input must also be restricted to SSH.

416
MCQmedium

A network administrator is troubleshooting a network issue using Cisco DNA Center Assurance. The administrator wants to identify which network devices are experiencing the highest number of errors, such as CRC errors and interface flaps. Which Assurance dashboard should the administrator use?

A.Client Health
B.Network Health
C.Application Health
D.Path Trace
AnswerB

The Network Health dashboard in Cisco DNA Center Assurance provides an overview of device and link health, including error counters such as CRC errors and interface flaps. It highlights devices with the most issues, allowing administrators to quickly identify problematic areas. This is the appropriate dashboard for finding devices with high error rates.

Why this answer

The Network Health dashboard in Cisco DNA Center Assurance aggregates health metrics for network devices and links, including error counters like CRC errors and interface flaps. It ranks devices by health and highlights those with the most issues, enabling administrators to quickly pinpoint and address problems. This makes it the right choice for identifying devices with high error rates.

Exam trap

The trap here is assuming that Client Health or Application Health would show device-level error statistics, when they focus on clients and applications respectively.

417
MCQhard

A network engineer is configuring a DMVPN Phase 3 deployment with EIGRP as the routing protocol. The hub router has multiple spoke routers behind a single physical interface. The engineer notices that spoke-to-spoke traffic is being forwarded through the hub instead of directly. The spoke routers have the correct NHRP and mGRE configuration. What is the most likely cause of this issue?

A.The hub router is configured with 'no ip next-hop-self eigrp' under the tunnel interface.
B.The hub router is configured with 'ip next-hop-self eigrp' under the tunnel interface.
C.The spoke routers have 'ip nhrp shortcut' configured but the hub does not have 'ip nhrp redirect'.
D.The spoke routers are using static NHRP mappings to the hub only, without dynamic NHRP registration.
AnswerB

In a DMVPN phase 3 deployment with EIGRP, the hub's 'ip next-hop-self eigrp' overrides the next hop in advertised routes to the hub's own tunnel address. As a result, spokes receive routing updates that point to the hub for all remote networks, so they never discover the actual tunnel IP of the destination spoke. Without that real next hop, NHRP's shortcut triggering mechanism never fires, and traffic must hair-pin through the hub instead of building a direct spoke-to-spoke tunnel.

Why this answer

In DMVPN Phase 3, spoke-to-spoke direct communication relies on the hub sending an NHRP Redirect to inform the source spoke of a better path. However, if the hub has 'ip next-hop-self eigrp' configured under the tunnel interface, EIGRP updates sent from the hub will set the next-hop to the hub's own tunnel IP address. This causes the spoke routers to install routes with the hub as the next-hop, preventing them from triggering an NHRP resolution for a direct spoke-to-spoke tunnel.

The correct behavior for Phase 3 is to use 'no ip next-hop-self eigrp' so that the original spoke's next-hop is preserved, allowing spokes to resolve the destination via NHRP.

Exam trap

Cisco often tests the distinction between Phase 2 and Phase 3 DMVPN behavior, where candidates mistakenly think 'ip next-hop-self' is always required for EIGRP over DMVPN, but in Phase 3 it must be disabled to allow NHRP shortcut resolution.

How to eliminate wrong answers

Option A is wrong because 'no ip next-hop-self eigrp' is actually the correct configuration for DMVPN Phase 3; it preserves the original next-hop in EIGRP updates, enabling spoke-to-spoke direct traffic. Option C is wrong because 'ip nhrp shortcut' on spokes and 'ip nhrp redirect' on the hub are required for Phase 3 operation; if both are missing, traffic would not be redirected, but the question states the spokes have correct NHRP configuration, implying 'ip nhrp shortcut' is present, and the hub's missing redirect would cause a different symptom (no NHRP Redirect messages). Option D is wrong because static NHRP mappings to the hub only are typical in Phase 2 and Phase 3; dynamic registration is used for the hub to learn spoke addresses, but static mappings do not prevent spoke-to-spoke traffic if the routing protocol correctly preserves next-hop information.

418
MCQmedium

A network engineer is troubleshooting a Cisco Catalyst 9300 switch that is experiencing intermittent packet drops. The engineer suspects a hardware forwarding issue and needs to verify the status of the switch's forwarding ASIC and its associated resources. Which command should the engineer use to display the current ASIC and forwarding resource utilization?

A.show mac address-table
B.show platform resources
C.show platform hardware fed switch active fwd-asic resource
D.show interfaces counters errors
AnswerC

This command displays detailed forwarding ASIC resource utilization, including TCAM, packet buffer, and other hardware forwarding resources, on the active switch of a Catalyst 9000 series switch. It is the correct choice for verifying ASIC status and resource usage when troubleshooting hardware forwarding issues, as it provides granular per-ASIC data that can identify resource exhaustion or errors.

Why this answer

The correct command is 'show platform hardware fed switch active fwd-asic resource', which provides detailed information about the forwarding ASIC resources on the active switch. This includes TCAM and packet buffer utilization, which are essential for identifying hardware forwarding issues. The other commands focus on general system resources, interface errors, or MAC address tables, none of which directly address ASIC resource utilization.

Exam trap

The trap here is confusing general platform resource commands with those that specifically target forwarding ASIC resources, which are distinct on Catalyst 9000 series switches.

419
MCQeasy

A network engineer is using Cisco SD-WAN vManage APIs to automate the deployment of a new branch site. The engineer needs to retrieve a list of all devices in the overlay network. Which REST API endpoint should the engineer use?

A.GET /dataservice/network/connections
B.GET /dataservice/template/device
C.GET /dataservice/system/device
D.GET /dataservice/device
AnswerD

The /dataservice/device endpoint in vManage REST API returns a list of all devices managed by vManage, including their system IP, hostname, and status. This is the correct endpoint for retrieving device inventory. It supports filtering and pagination. The engineer can use this to identify devices for further automation tasks.

Why this answer

The vManage REST API provides the /dataservice/device endpoint to retrieve a list of all devices in the SD-WAN overlay. This endpoint returns details such as device IP, hostname, model, and status. It is the standard way to obtain device inventory for automation scripts.

Other endpoints serve different purposes, such as templates or connections.

Exam trap

The trap here is confusing the device inventory endpoint with the device template endpoint, which manages configuration templates rather than listing devices.

420
MCQeasy

What is the default STP hello timer value in seconds?

A.1 second
B.2 seconds
C.5 seconds
D.10 seconds
AnswerB

2 seconds is the correct default hello timer as defined by IEEE 802.1D for classic Spanning Tree Protocol. The root bridge sends a configuration BPDU every 2 seconds, and non-root bridges forward these BPDUs outward to maintain a stable, loop-free topology. This 2-second default is also used in Rapid Spanning Tree Protocol (RSTP) and Multiple Spanning Tree Protocol (MSTP).

Why this answer

The default STP hello timer is 2 seconds, as defined by IEEE 802.1D. This timer controls how often a root bridge sends configuration BPDUs to maintain the spanning-tree topology. The hello timer value is used in conjunction with the forward delay and max age timers to ensure loop-free convergence.

Exam trap

Cisco often tests the distinction between the hello timer (2 seconds), forward delay (15 seconds), and max age (20 seconds), and candidates frequently confuse the hello timer with the forward delay or max age values.

How to eliminate wrong answers

Option A is wrong because 1 second is not the default STP hello timer; it is the default for Rapid PVST+ hello interval in some Cisco implementations, but the standard STP hello is 2 seconds. Option C is wrong because 5 seconds is the default forward delay timer, not the hello timer. Option D is wrong because 10 seconds is the default max age timer, which determines how long a switch waits before re-evaluating BPDU information, not the hello interval.

421
MCQmedium

A network engineer runs the following command on Router R1: R1# show aaa sessions Total sessions since last reload: 5 Session Id: 1 Unique Id: 1 User Name: admin IP Address: 10.1.1.100 Idle Time: 0 Timeout: 0 Type: Login Method: RADIUS Session Id: 2 Unique Id: 2 User Name: jdoe IP Address: 10.1.1.101 Idle Time: 120 Timeout: 0 Type: Login Method: LOCAL Based on this output, what can be concluded?

A.All users are authenticated via RADIUS.
B.User jdoe authenticated using local authentication.
C.The RADIUS server is unreachable for all users.
D.Both sessions are using TACACS+ for authorization.
AnswerB

Session 2 in the AAA output lists the username 'jdoe' and explicitly reports 'Method: LOCAL', meaning the device authenticated this user using its locally configured user accounts. This is a fundamental fallback or per-user method in AAA, where the network device itself stores credentials instead of querying an external server. Therefore, the correct conclusion is that jdoe was authenticated locally, even if RADIUS was available for other sessions.

Why this answer

The output shows two sessions: user 'admin' authenticated via RADIUS (Method: RADIUS) and user 'jdoe' authenticated via LOCAL (Method: LOCAL). Option B correctly states that user jdoe authenticated using local authentication, as indicated by the 'Method: LOCAL' field in the session details.

Exam trap

Cisco often tests the ability to read the 'Method' field in the 'show aaa sessions' output, where candidates may mistakenly assume that all sessions use the same authentication method or that a single method applies to all users, ignoring the per-session detail.

How to eliminate wrong answers

Option A is wrong because not all users are authenticated via RADIUS; user jdoe's session shows Method: LOCAL, indicating local authentication was used. Option C is wrong because the RADIUS server is not necessarily unreachable for all users; user admin successfully authenticated via RADIUS, which proves the server was reachable at least for that session. Option D is wrong because the output only shows authentication methods (RADIUS and LOCAL) and does not provide any information about TACACS+ for authorization; the command 'show aaa sessions' does not display authorization protocol details.

422
MCQmedium

A network engineer is configuring port security on a Cisco switch. The requirement is to allow only the first MAC address that appears on the port to be learned and to automatically disable the port if a violation occurs. The engineer configures 'switchport port-security mac-address sticky' but does not specify a maximum number of secure MAC addresses. After connecting a single host, the port works. However, when the host is replaced with a different device, the port is error-disabled. What is the most likely reason?

A.The default maximum number of secure MAC addresses is 1, so the second MAC address triggers a violation.
B.The sticky keyword requires the engineer to first manually configure a maximum number of MAC addresses.
C.The violation mode is set to 'restrict' by default, which causes the port to error-disable after one violation.
D.The port security aging type is set to 'absolute' by default, causing the sticky address to expire immediately.
AnswerA

Port security defaults to a maximum of one secure MAC address per port, so the sticky command alone does not raise that limit. When the replacement device presents a second MAC, the default maximum is exceeded and the violation mode error-disables the port.

Why this answer

The default maximum number of secure MAC addresses on a switchport is 1. When the engineer configured 'switchport port-security mac-address sticky' without specifying a maximum, the port learned the first host's MAC address as a sticky entry. When a different device was connected, its MAC address exceeded the default limit of 1, triggering a security violation.

Since the default violation mode is 'shutdown', the port was error-disabled.

Exam trap

Cisco often tests the default values for port security features, specifically that the default maximum number of secure MAC addresses is 1 and the default violation mode is 'shutdown', leading candidates to overlook the need to configure 'switchport port-security maximum' when using sticky learning for multiple hosts.

How to eliminate wrong answers

Option B is wrong because the 'sticky' keyword does not require manual configuration of a maximum number of MAC addresses; the default maximum is 1, and sticky addresses are counted against that limit. Option C is wrong because the default violation mode is 'shutdown', not 'restrict'; 'restrict' would cause the port to drop offending traffic and increment a counter but not error-disable the port. Option D is wrong because port security aging type is not set to 'absolute' by default (it is disabled by default), and even if aging were configured, it would not cause the sticky address to expire immediately upon connecting a new device.

423
MCQhard

A network engineer is implementing Cisco TrustSec (CTS) with Security Group Tags (SGTs) using SXP (SGT Exchange Protocol). The engineer configures the switch as an SXP speaker and the Cisco ISE as an SXP listener. The engineer verifies that SXP peers are established. However, when the engineer checks 'show cts role-based sgt map', the SGT mappings for users are not present. What is the most likely cause?

A.The SXP version mismatch between the switch and ISE.
B.The switch is not configured to assign SGTs to users via 802.1X or static mapping.
C.The ISE is configured as an SXP speaker instead of a listener.
D.The SXP connection is using the wrong TCP port.
AnswerB

SXP is a transport mechanism that only propagates IP-to-SGT bindings that already exist locally on the speaker device. If the access switch has not been configured with a downloadable SGT from 802.1X (e.g., via Cisco ISE policy and RADIUS dACL attributes) or with static 'ip sgt' mappings, then its SXP table is empty and there is nothing to publish to ISE. The absence of local SGT assignments is the direct cause of no SGTs being sent.

Why this answer

The SXP protocol only propagates SGT-to-IP mappings that already exist on the speaker device. If the switch is not configured to assign SGTs to users via 802.1X or static mapping, no SGT mappings will be generated to send to ISE. The 'show cts role-based sgt map' command displays the local SGT mapping table, which remains empty because the switch has no mechanism to associate users with SGTs.

Exam trap

Cisco often tests the misconception that SXP itself creates or assigns SGTs, when in reality SXP only propagates existing mappings; the trap here is assuming a working SXP peer relationship guarantees populated SGT mappings.

How to eliminate wrong answers

Option A is wrong because SXP version mismatch would prevent the SXP peer relationship from establishing, but the engineer verified that SXP peers are established. Option C is wrong because if ISE were configured as an SXP speaker instead of a listener, the switch would be the listener and the SXP connection would still be established, but the direction of propagation would be reversed; however, the issue is that no mappings exist on the switch to propagate. Option D is wrong because SXP uses TCP port 64999 by default; using the wrong port would prevent the SXP peer from establishing, which contradicts the verification that peers are established.

424
MCQhard

A network engineer is configuring OSPF on a Cisco router. The router is connected to a broadcast network with multiple OSPF neighbors. The engineer wants to ensure that this router does not become the Designated Router (DR) or Backup Designated Router (BDR) on this network. Which configuration achieves this goal?

A.Set the OSPF priority to 0 on the interface.
B.Set the OSPF network type to point-to-point.
C.Configure the interface as passive.
D.Configure the router as a stub router.
AnswerA

Setting the OSPF priority to 0 on an interface prevents that router from being elected as DR or BDR. The priority value is used in the DR election process; routers with priority 0 are ineligible. This is the correct method to ensure the router does not become DR or BDR while still participating in OSPF on that network.

Why this answer

The OSPF priority is an 8-bit field in the Hello packet used in DR/BDR election. A router with priority 0 is never elected as DR or BDR. Setting the interface priority to 0 achieves the goal while allowing the router to remain a DROTHER and fully participate in OSPF.

Other methods like changing network type or making the interface passive have side effects that are not desired.

Exam trap

The trap here is confusing DR election manipulation with other OSPF features like stub routing or passive interfaces, which have different purposes.

425
MCQmedium

A network administrator is deploying a Cisco Wireless LAN Controller (WLC) running AireOS in a branch office. The security policy requires that guest wireless clients be isolated from internal corporate clients and that guest traffic be tunneled back to a DMZ interface on the WLC. Which WLAN configuration element should the administrator use to meet these requirements?

A.Configure the guest WLAN with AP group VLAN tagging and enable FlexConnect local switching.
B.Configure the guest WLAN to use the management interface with a separate SSID.
C.Configure the guest WLAN to use the virtual interface and enable Web Auth.
D.Configure a dynamic interface mapped to the guest VLAN and assign it to the guest WLAN.
AnswerD

A dynamic interface on the AireOS WLC is a user-defined VLAN interface that maps a WLAN to a specific VLAN and is commonly placed on a DMZ segment for guest traffic. Assigning the guest WLAN to a dynamic interface isolates guest clients from corporate clients on the management interface and allows traffic to be tunneled to a firewall in the DMZ.

Why this answer

Guest wireless traffic on an AireOS WLC is isolated and tunneled by mapping the guest WLAN to a dynamic interface whose VLAN resides in a DMZ. The dynamic interface defines the VLAN and IP subnet for that WLAN, and the WLC forwards guest client traffic through that interface rather than the management interface. This design keeps guest clients off corporate VLANs and allows a firewall to enforce policy in the DMZ.

Exam trap

The trap here is assuming that creating a separate SSID or enabling Web Auth automatically isolates guest traffic, when the actual isolation comes from mapping the WLAN to a dedicated dynamic interface on a DMZ VLAN.

426
MCQeasy

A network engineer is configuring a new Cisco IOS router and needs to ensure that the router can be managed remotely via SSH. The engineer has already generated RSA keys and configured a username and password. Which additional command is required to enable SSH access on the VTY lines?

A.ip ssh version 2
B.login local
C.transport input ssh
D.crypto key generate rsa
AnswerC

The command 'transport input ssh' under the VTY line configuration restricts incoming connections to SSH only, which is required to enable SSH access. Without it, the router may still allow Telnet or other protocols. This command ensures that only secure shell connections are accepted, aligning with the requirement to manage the router via SSH.

Why this answer

To enable SSH access on a Cisco IOS router, after generating RSA keys and configuring local authentication, the VTY lines must be configured with 'transport input ssh'. This command restricts incoming connections to SSH, ensuring secure remote management. The other commands are either prerequisites already completed or additional security settings that do not directly enable SSH on the VTY lines.

Exam trap

The trap here is thinking that generating RSA keys or setting SSH version 2 automatically enables SSH on the VTY lines, when in fact the 'transport input ssh' command is specifically required to allow SSH connections.

427
MCQmedium

A network engineer is configuring a Cisco CSR 1000v router to support a virtual routing and forwarding (VRF) instance for a customer. The engineer wants to enable OSPFv2 within the VRF and ensure that OSPF routes are installed in the VRF's routing table. Which command is required to start the OSPF process for the VRF?

A.router ospf 1 vrf CUSTOMER
B.ip router ospf 1 vrf CUSTOMER
C.router ospf 1 address-family ipv4 vrf CUSTOMER
D.router ospf 1 vrf CUSTOMER
AnswerA

The command 'router ospf 1 vrf CUSTOMER' starts an OSPF process with process ID 1 and associates it with the VRF named CUSTOMER. This is the correct syntax to enable OSPF within a specific VRF on Cisco IOS-XE. Once configured, OSPF will run in the context of that VRF, and routes will be installed in the VRF's routing table.

Why this answer

The correct command to enable OSPFv2 in a VRF on Cisco IOS-XE is 'router ospf <process-id> vrf <vrf-name>'. This associates the OSPF process with the specified VRF, allowing it to run in that VRF's routing context. The other options either use incorrect syntax or are appropriate for different platforms or protocols.

Exam trap

The trap here is mixing up IOS-XE and NX-OS syntax, or incorrectly placing the VRF parameter on a separate line instead of on the router ospf command itself.

428
MCQmedium

A network engineer runs the following command on Router R7: R7# show vrf brief Name Default RD Protocols Interfaces Mgmt-intf <not set> ipv4,ipv6 GigabitEthernet0/0 CUSTOMER-A 65001:100 ipv4 GigabitEthernet0/1.10 CUSTOMER-B 65001:200 ipv4 GigabitEthernet0/1.20 Based on this output, what can be concluded?

A.VRF CUSTOMER-A is using IPv6.
B.VRF Mgmt-intf has a route distinguisher set.
C.VRF CUSTOMER-B is associated with subinterface GigabitEthernet0/1.20.
D.All VRFs are using the same route distinguisher.
AnswerC

VRF CUSTOMER-B is correctly associated with subinterface GigabitEthernet0/1.20, as shown in the Interface column of the output. This association is made by applying the command "ip vrf forwarding CUSTOMER-B" on that subinterface, which binds the subinterface's traffic to the CUSTOMER-B VRF routing table. Therefore, this is the correct option.

Why this answer

The 'show vrf brief' output explicitly lists GigabitEthernet0/1.20 under the Interfaces column for VRF CUSTOMER-B, confirming that this subinterface is associated with that VRF. VRFs use subinterfaces to segment traffic for different customers or tenants on the same physical link, and the output directly shows this mapping.

Exam trap

Cisco often tests the ability to read the 'show vrf brief' output accurately, and the trap here is that candidates may assume all VRFs have an RD set or that the Protocols column implies IPv6 support without checking the specific entry.

How to eliminate wrong answers

Option A is wrong because the Protocols column for VRF CUSTOMER-A shows only 'ipv4', not 'ipv6', so it is not using IPv6. Option B is wrong because the Default RD column for VRF Mgmt-intf shows '<not set>', meaning no route distinguisher is configured for that VRF. Option D is wrong because each VRF has a different route distinguisher: Mgmt-intf has none, CUSTOMER-A uses 65001:100, and CUSTOMER-B uses 65001:200.

429
MCQmedium

Given the following Ansible playbook snippet: --- - name: Configure VLAN hosts: switches gather_facts: no tasks: - name: Create VLAN 100 ios_vlan: vlan_id: 100 name: Engineering state: present Which statement is true about this playbook?

A.It creates VLAN 100 with name Engineering if it does not exist.
B.It only checks if VLAN 100 exists and reports its status.
C.It deletes VLAN 100 if it exists.
D.It fails because 'name' is not a valid parameter for ios_vlan.
AnswerA

The ios_vlan module with state: present performs an idempotent operation: if VLAN 100 does not exist in the device's VLAN database, it creates it and assigns the name 'Engineering'. If the VLAN already exists but has a different name, the module updates the name to match the declared state. Because the operation is declarative, Ansible compares the current configuration to the desired configuration and applies only necessary changes.

Why this answer

The `ios_vlan` module with `state: present` ensures the VLAN exists with the specified parameters. Since `gather_facts: no` is set, the playbook does not gather device facts but still performs the configuration task. The correct answer is A because the module will create VLAN 100 with the name 'Engineering' if it does not already exist on the switch.

Exam trap

Cisco often tests the distinction between `state: present` (create/update) and `state: absent` (delete), and the trap here is assuming `state: present` only checks or reports status rather than actively configuring the device.

How to eliminate wrong answers

Option B is wrong because `state: present` does not perform a check-only operation; it actively configures the VLAN. Option C is wrong because `state: present` creates or updates the VLAN, not deletes it (deletion requires `state: absent`). Option D is wrong because `name` is a valid parameter for the `ios_vlan` module, used to set the VLAN's descriptive name.

430
MCQeasy

A network engineer runs the following command on Router R1: R1# show bgp ipv4 unicast summary | include 10.0.1.5 10.0.1.5 4 65005 3456 3457 15 0 0 00:15:22 5 Based on this output, what can be concluded?

A.The BGP session with 10.0.1.5 has been down for 15 minutes and 22 seconds.
B.The BGP session with 10.0.1.5 is up and has received 5 prefixes.
C.The BGP session with 10.0.1.5 is in the 'Active' state.
D.The BGP session with 10.0.1.5 has sent 5 prefixes.
AnswerB

The '5' in the State/PfxRcd column is the number of Network Layer Reachability Information (NLRI) prefixes that this router received from 10.0.1.5 over the established BGP session. Crucially, when the session is in the Established state, the column shows a numeric prefix count rather than a state keyword such as Active, Idle, or Connect. Thus, the neighbor is up and has successfully exchanged routes.

Why this answer

The 'show bgp ipv4 unicast summary' output displays BGP neighbor status. The column 'Up/Down' shows '00:15:22', indicating the session has been established for 15 minutes and 22 seconds, not down. The last column shows '5', which under the 'PfxRcd' (Prefixes Received) column indicates the number of prefixes received from the neighbor.

Therefore, the session is up and has received 5 prefixes.

Exam trap

Cisco often tests the misinterpretation of the 'Up/Down' column, where candidates mistakenly read it as downtime instead of uptime, and the confusion between prefixes received (PfxRcd) and prefixes sent (PfxSent), which is not shown in this output.

How to eliminate wrong answers

Option A is wrong because the 'Up/Down' column value '00:15:22' represents the duration the session has been up, not down; a down session would show a different state or 'never'. Option C is wrong because the output shows a valid neighbor IP, AS number, and uptime, indicating the session is in the Established state, not Active; the Active state would not show prefixes received. Option D is wrong because the '5' in the output corresponds to prefixes received (PfxRcd), not sent; sent prefixes are not displayed in this summary output.

431
MCQmedium

A network engineer is deploying a new branch office with a single Cisco Catalyst switch that will connect to the corporate network via a routed uplink. The switch must be able to forward traffic for VLANs 10, 20, and 30 over that single uplink to a router. The router interface is configured with subinterfaces and dot1Q encapsulation. Which switchport configuration should be applied to the uplink port?

A.switchport mode access switchport access vlan 10
B.switchport mode dynamic desirable switchport trunk allowed vlan 10,20,30
C.switchport mode trunk switchport trunk encapsulation dot1q switchport trunk allowed vlan 10,20,30
D.switchport mode trunk switchport trunk native vlan 10 switchport trunk allowed vlan 20,30
AnswerC

A trunk port with 802.1Q encapsulation carries multiple VLANs over one physical link, tagging frames with the appropriate VLAN ID. Restricting allowed VLANs to 10, 20, and 30 matches the router's subinterfaces and prevents unnecessary broadcast flooding. This is the standard router-on-a-stick configuration and satisfies the multi-VLAN uplink requirement.

Why this answer

The uplink must be a trunk to carry multiple VLANs to the router's subinterfaces. Configuring the port as a static trunk with 802.1Q encapsulation and limiting allowed VLANs to the ones in use ensures tagged frames reach the correct router subinterfaces. Dynamic trunking or access mode would not reliably support multiple VLANs over a single physical link.

Exam trap

The trap here is assuming that a trunk port must be configured with dynamic desirable to form a trunk with a router, when routers do not typically participate in DTP and require a static trunk configuration.

432
MCQeasy

A network administrator is using Cisco DNA Center to monitor the health of network devices. The administrator wants to see a summary of the overall network health and any issues that need attention. Which Cisco DNA Center feature provides this information?

A.Assurance
B.Policy
C.Provision
D.Design
AnswerA

The Assurance feature in Cisco DNA Center provides comprehensive monitoring, health dashboards, and issue detection. It uses telemetry and analytics to show network health, client health, and application health, and it highlights problems that need attention. This is the correct feature for the administrator's requirement.

Why this answer

Cisco DNA Center Assurance is designed to give network administrators a holistic view of network health. It collects data from devices and uses machine learning to detect anomalies and provide insights. The health dashboard summarizes the status of network devices, clients, and applications, and lists issues with recommended actions.

The other features are related to configuration and policy, not monitoring.

Exam trap

The trap here is mixing up the automation and assurance functions of Cisco DNA Center; Design, Policy, and Provision are for configuration, while Assurance is for monitoring.

433
MCQhard

A network engineer is configuring CoPP on a Cisco router to protect the control plane from excessive traffic. The engineer creates a class-map that matches traffic with a specific ACL that permits TCP port 22 (SSH) from a management subnet (192.168.1.0/24) and denies all other traffic. The CoPP policy applies a police rate of 1 Mbps to this class. After applying the policy, the engineer notices that SSH sessions from the management subnet are being dropped intermittently. The engineer checks the CoPP statistics and sees that the traffic rate is 500 kbps. What is the most likely cause?

A.The CoPP policy has a conform-action of drop, which drops all traffic matching the class.
B.The police rate is too low, and the traffic is being dropped due to exceeding the rate.
C.The ACL is denying SSH traffic from the management subnet.
D.The CoPP policy is applied to the wrong interface, so it is not affecting SSH traffic.
AnswerB

The police rate alone can cause drops even when the average bit rate is below the configured police rate because CoPP uses a token bucket that only allows short bursts up to the burst size. Once the bucket is empty, every packet that exceeds the sustained rate or even a momentary burst is marked as exceeding and is dropped by the exceed-action. Intermittent drops are the classic symptom of a policer with a low rate or small burst parameters, not a config error.

Why this answer

The most likely cause is that traffic is exceeding the police rate in bursts, even though the average rate is 500 kbps and the configured police rate is 1 Mbps. Policing uses a token bucket, and TCP SSH traffic from the management subnet can burst above the configured rate. When bursts exceed the police rate, the exceed-action (by default, drop) drops the excess packets, causing intermittent SSH drops.

If the conform-action were set to drop, all conforming traffic would be dropped consistently, not intermittently. The default conform-action is transmit, and there is no indication it was changed.

Exam trap

A common pitfall is assuming that an average traffic rate below the police rate means there should be no drops. CoPP policing is based on bursts as well as average rate; intermittent drops often occur when bursts exceed the configured rate, even if the average rate is below the police rate.

How to eliminate wrong answers

Option B is wrong because the traffic rate is 500 kbps, which is below the police rate of 1 Mbps, so exceeding the rate is not the cause of drops. Option C is wrong because the ACL permits TCP port 22 from the management subnet, so it is not denying SSH traffic. Option D is wrong because CoPP policies are applied globally to the control plane via the 'control-plane' command, not to a specific interface, and the policy is affecting SSH traffic (drops are occurring).

434
MCQhard

A network engineer is deploying 802.1X on a Cisco switch with Cisco ISE as the RADIUS server. The engineer wants to allow devices that do not support 802.1X supplicant to connect to a guest VLAN. Which feature should be configured on the switch port to accomplish this?

A.Enable MAB (MAC Authentication Bypass) on the port.
B.Configure the port as a trunk port with native VLAN set to the guest VLAN.
C.Set the port to force-authorized mode.
D.Configure the port as a multi-auth port with an authentication open mode.
AnswerA

MAB allows devices that do not support 802.1X to authenticate using their MAC address. When MAB is enabled, the switch sends the device's MAC address to the RADIUS server (ISE) as username and password. If the MAC address is known, the device can be authorized and assigned to a VLAN, such as a guest VLAN. This is the standard method to support non-supplicant devices.

Why this answer

MAC Authentication Bypass (MAB) enables non-802.1X devices to authenticate using their MAC address. The switch sends the MAC to ISE, which can authorize the device and assign it to a guest VLAN via RADIUS attributes. This allows devices like printers or legacy IP phones to gain network access without supplicant software, while still enforcing policy.

Exam trap

The trap here is thinking that multi-auth or open mode automatically handles non-supplicant devices; MAB is specifically designed for MAC-based authentication of such devices.

435
Multi-Selecthard

A security team is hardening a Cisco IOS router that terminates IPsec site-to-site tunnels to several branch offices. The team wants to protect the control plane by rate-limiting and filtering traffic destined to the router's own CPU. Which two mechanisms are designed specifically for control plane protection on Cisco IOS? (Choose two.)

Select 2 answers
A.Control Plane Policing (CoPP)
B.MACsec on the WAN interface
C.Zone-Based Policy Firewall (ZBFW)
D.Control Plane Protection (CPPr)
E.IPsec DMVPN with IKEv2
AnswersA, D

CoPP uses a modular QoS CLI policy attached to the control-plane interface to rate-limit and classify traffic destined to the route processor. It allows the engineer to define class maps for protocols such as IKE, SSH, and SNMP, then apply policing actions so that a flood of tunnel negotiation packets cannot exhaust CPU resources. This directly addresses the hardening goal for the IPsec headend by protecting the control plane from abusive traffic.

Why this answer

Control plane protection on Cisco IOS is provided by CoPP, which uses MQC policies on the control-plane interface, and CPPr, which adds subinterface granularity for host, transit, and CEF-exception traffic. Both are purpose-built to classify and rate-limit traffic destined to the route processor. Data plane mechanisms such as MACsec and ZBFW, and tunneling architectures such as DMVPN, do not protect the CPU from control plane floods.

Exam trap

The trap here is confusing data plane security features like MACsec and ZBFW with control plane protection mechanisms, even though only CoPP and CPPr police traffic destined to the route processor.

436
MCQmedium

A network engineer runs the following command on Router R4: R4# show mpls ldp neighbor Peer LDP Ident: 10.0.0.2:0; Local LDP Ident 10.0.0.1:0 TCP connection: 10.0.0.2.646 - 10.0.0.1.54567 State: Oper; Msgs sent/rcvd: 100/95; Downstream Up time: 00:15:30 LDP discovery sources: GigabitEthernet0/0, Src IP addr: 10.0.0.2 Addresses bound to peer LDP Ident: 10.0.0.2 192.168.1.1 Based on this output, what can be concluded?

A.The LDP session is down due to a TCP connection issue.
B.The LDP session is established over the GigabitEthernet0/0 interface.
C.The peer is not sending any LDP messages.
D.The local router has only one label binding for the peer.
AnswerB

In the output of 'show mpls ldp neighbor', the 'Discovery Source' (or 'Discovery sources') field lists the interface through which LDP hello messages were received from the peer. Since the output shows GigabitEthernet0/0 as the discovery source, the neighbor adjacency was formed over that interface, and the LDP session (which uses a TCP connection for label exchange) is consequently established over that interface. This confirms that LDP is operating correctly on GigabitEthernet0/0, which is why this answer is correct.

Why this answer

The output shows 'State: Oper' (Operational), which indicates the LDP session is fully established and operational. The 'LDP discovery sources' line lists GigabitEthernet0/0 as the interface through which the peer (10.0.0.2) was discovered, confirming that the LDP session is established over that interface. This is the correct interpretation of the show command.

Exam trap

Cisco often tests the distinction between LDP neighbor discovery (via UDP hellos) and LDP session establishment (via TCP), and candidates may confuse the 'Addresses bound' field with label bindings, leading them to incorrectly select option D.

How to eliminate wrong answers

Option A is wrong because the state is 'Oper' (Operational), not down, and the TCP connection is listed with source and destination ports, indicating it is active. Option C is wrong because 'Msgs sent/rcvd: 100/95' shows that messages are being both sent and received, so the peer is actively sending LDP messages. Option D is wrong because the output only shows the 'Addresses bound to peer LDP Ident' (two addresses), not label bindings; label bindings are displayed with a different command like 'show mpls ldp bindings'.

437
MCQeasy

A network administrator is configuring a new Cisco IOS switch. The administrator needs to assign switch port GigabitEthernet0/1 to VLAN 20 and ensure that the port is in access mode. Which command sequence is correct?

A.interface GigabitEthernet0/1; switchport mode access; switchport access vlan 20
B.interface GigabitEthernet0/1; switchport mode trunk; switchport trunk allowed vlan 20
C.interface GigabitEthernet0/1; switchport mode dynamic auto; switchport access vlan 20
D.interface GigabitEthernet0/1; switchport access vlan 20; switchport mode access
AnswerA

This sequence enters interface configuration mode, sets the port to access mode, and assigns it to VLAN 20. The 'switchport mode access' command forces the port to operate as an access port, and 'switchport access vlan 20' associates it with VLAN 20. This is the standard method to configure an access port on a Cisco switch.

Why this answer

To assign a switch port to a VLAN and set it as an access port, the correct commands are 'switchport mode access' followed by 'switchport access vlan 20'. This ensures the port operates in access mode and carries traffic for VLAN 20. The other options either configure trunking or dynamic negotiation, which do not meet the access mode requirement.

Exam trap

The trap here is thinking that assigning a VLAN automatically sets the port to access mode, or confusing access and trunk configuration commands.

438
MCQhard

A network engineer is configuring CoPP on a Cisco ASR 1000 router to protect the control plane from excessive traffic. The engineer wants to allow BGP traffic from a specific peer (10.0.0.1) while rate-limiting all other BGP traffic. The engineer creates an ACL that permits TCP port 179 from host 10.0.0.1 and denies all other BGP traffic. The CoPP class-map matches this ACL. However, after applying the policy, BGP sessions from other peers are still being established. What is the most likely reason?

A.The ACL denies all other BGP traffic, so CoPP does not match it, and it falls through to the default class, which permits it.
B.The ACL is applied in the wrong order; the deny statement should be before the permit statement.
C.BGP uses UDP port 179, not TCP, so the ACL does not match BGP traffic.
D.CoPP does not affect BGP sessions because they are established before the policy is applied.
AnswerA

CoPP class-maps only act on traffic the ACL permits; denied traffic matches no class and falls to the default class, which typically permits it. So other BGP peers are not rate-limited, explaining why their sessions still establish.

Why this answer

The ACL is designed to match BGP traffic from host 10.0.0.1 (permit) and deny all other BGP traffic. However, CoPP class-maps match traffic based on permit statements in the ACL; a deny statement in the ACL causes the traffic to not be matched by that class. As a result, BGP traffic from other peers is not classified into the rate-limiting class and falls through to the default class, which typically permits all traffic.

This explains why BGP sessions from other peers are still being established.

Exam trap

Cisco often tests the misconception that a deny statement in an ACL used with CoPP will drop traffic, when in reality it only prevents the traffic from being matched by that class, allowing it to fall through to the default class which typically permits everything.

How to eliminate wrong answers

Option B is wrong because the order of permit and deny statements in an ACL is critical, but here the permit for host 10.0.0.1 is correctly placed before the deny all; the issue is not about order but about how CoPP treats deny entries. Option C is wrong because BGP uses TCP port 179, not UDP; this is a fundamental protocol fact. Option D is wrong because CoPP affects all traffic arriving at the control plane after the policy is applied, regardless of when sessions were established; existing sessions are still subject to rate-limiting.

439
MCQmedium

Given the following configuration: policy-map MARKING_POLICY class CRITICAL_DATA set dscp af31 class BULK_DATA set dscp af11 class class-default set dscp default What is the effect of the set dscp default command in the class-default?

A.It sets the DSCP value to 0, which is the default best-effort marking.
B.It sets the DSCP value to the original value of the packet, effectively not changing it.
C.It sets the DSCP value to 46, which is the default for voice.
D.It is invalid because class-default cannot have a set action.
AnswerA

The `set dscp 0` command explicitly overwrites the Differentiated Services Code Point bits with binary 000000. DSCP 0, also known as CS0 or default PHB, is the standard best-effort marking applied to normal IP traffic. Because this is an explicit action in a policy-map, it always results in DSCP 0 regardless of any original marking.

Why this answer

The 'set dscp default' command explicitly sets the DSCP field to a value of 0, which corresponds to the default best-effort per-hop behavior (PHB) as defined in RFC 2474. This ensures that any traffic not matching the user-defined classes (CRITICAL_DATA or BULK_DATA) is marked with the lowest priority, which is the standard behavior for class-default in a marking policy.

Exam trap

Cisco often tests the misconception that 'default' means 'leave the original value unchanged' or that it refers to a specific high-priority default like voice, rather than the actual DSCP value of 0 for best-effort traffic.

How to eliminate wrong answers

Option B is wrong because 'set dscp default' does not preserve the original packet value; it overwrites the DSCP field with a fixed value of 0. Option C is wrong because DSCP 46 (EF) is the default for voice traffic, not the 'default' keyword, which maps to DSCP 0. Option D is wrong because class-default can indeed have a set action; it is a valid and common practice to mark all unmatched traffic with a specific DSCP value.

440
Multi-Selectmedium

Which TWO STP features are used to improve convergence time after a topology change?

Select 2 answers
A.UplinkFast
B.BackboneFast
C.Root Guard
D.BPDU Guard
E.PortFast
AnswersA, B

This is a Cisco proprietary STP enhancement that accelerates convergence after a direct link failure on a switch port that was in a blocking state. When a root port fails, UplinkFast immediately transitions a designated alternate port to forwarding state without waiting for the normal MAX Age + Forward Delay timers (typically 30-50 seconds). It works by caching a multicast frame from the root to verify the alternate path, but the primary effect is fast failover to a redundant uplink, often within 1-5 seconds. This directly improves convergence time.

Why this answer

UplinkFast is correct because it enables a switch to immediately use an alternate root port when its current root port fails, bypassing the usual 30-second listening and learning delay. This is achieved by artificially lowering the bridge priority of the switch to trigger a topology change notification, allowing the backup port to transition directly to forwarding. BackboneFast is correct because it reduces convergence time by detecting indirect link failures in the backbone and allowing a switch to expire its Max Age timer (default 20 seconds) immediately, rather than waiting for the full timer to expire, thus speeding up the transition to a new root port.

Exam trap

Cisco often tests the distinction between features that improve convergence (UplinkFast, BackboneFast) versus features that provide security or edge-port behavior (Root Guard, BPDU Guard, PortFast), leading candidates to mistakenly select PortFast because it also speeds up initial port transition, but it does not react to topology changes.

441
MCQmedium

A data center architect is designing a virtualized environment to host critical applications. The design must maximize performance by allowing virtual machines (VMs) to directly access physical CPU cores and memory without hypervisor overhead for latency-sensitive workloads. Which hypervisor configuration should be used?

A.Enable hyper-threading and overcommit CPU resources
B.Use a Type 2 hypervisor (e.g., VMware Workstation) for better isolation
C.Configure NUMA pinning and CPU pinning for each VM to dedicated cores and memory nodes
D.Enable memory ballooning to reclaim unused memory from VMs
AnswerC

NUMA pinning assigns each VM to a specific NUMA node so that all memory allocations stay within that node's local memory, eliminating costly remote memory access over the interconnect. CPU pinning locks a VM's vCPUs to specific physical cores, preventing the hypervisor from migrating them across sockets or cores and removing run-queue and scheduling delays. Combined, these techniques provide deterministic access to dedicated cores and local memory, preserving cache locality and reducing latency to near-bare-metal levels, which is essential for latency-sensitive enterprise applications.

Why this answer

CPU pinning and NUMA pinning allow virtual machines to directly access dedicated physical CPU cores and memory nodes, eliminating hypervisor scheduling overhead and ensuring low-latency access to local memory. This configuration is essential for latency-sensitive workloads in a virtualized data center, as it provides near-bare-metal performance by avoiding resource contention and cross-NUMA memory access penalties.

Exam trap

Cisco often tests the misconception that hyper-threading or memory ballooning can improve performance for latency-sensitive workloads, when in fact these features are designed for resource efficiency and can introduce unpredictability or overhead.

How to eliminate wrong answers

Option A is wrong because enabling hyper-threading and overcommitting CPU resources increases contention for physical cores and introduces hypervisor scheduling overhead, which degrades performance for latency-sensitive workloads. Option B is wrong because a Type 2 hypervisor (e.g., VMware Workstation) runs on top of a host operating system, adding extra layers of abstraction and overhead that reduce performance and are unsuitable for data center critical applications. Option D is wrong because memory ballooning is a technique for reclaiming unused memory from VMs to allow overcommitment, but it does not provide direct memory access and can cause performance degradation due to balloon driver overhead and potential swapping.

442
MCQeasy

A small business has a single router connected to the internet and a switch for the LAN. They want to implement VLANs to separate guest and corporate traffic. The router has only one physical interface to the switch. The network engineer proposes using subinterfaces with 802.1Q trunking on the router interface. Which configuration step is required on the switch port connected to the router?

A.Configure the port as a routed port.
B.Configure the port as an access port in VLAN 1.
C.Configure the port as a trunk port.
D.Configure the port as a dynamic desirable port.
AnswerC

A trunk port carries frames from multiple VLANs and tags each frame with its 802.1Q VLAN ID, except for the native VLAN which remains untagged. Router subinterfaces configured with encapsulation dot1Q can accept these tagged frames, allowing the router to route between VLANs over one physical link. This is the required configuration for router-on-a-stick inter-VLAN routing when a single router interface must handle traffic for many VLANs.

Why this answer

The router uses subinterfaces with 802.1Q trunking to carry multiple VLANs over a single physical link. For this to work, the switch port connected to the router must be configured as a trunk port, which tags frames with VLAN IDs as they traverse the link. This allows the router to route between VLANs using its subinterfaces, each associated with a specific VLAN.

Exam trap

Cisco often tests the misconception that a switch port connecting to a router can remain as an access port or use DTP, but the key is that the router's subinterface requires 802.1Q-tagged frames, which only a statically configured trunk port can provide.

How to eliminate wrong answers

Option A is wrong because a routed port is a Layer 3 interface on a switch, used for routing between networks, not for carrying multiple VLANs over a single link; it would not support 802.1Q trunking. Option B is wrong because an access port belongs to a single VLAN and strips VLAN tags, which would prevent the router from receiving tagged frames for multiple VLANs, breaking the subinterface design. Option D is wrong because dynamic desirable is a DTP (Dynamic Trunking Protocol) mode used to negotiate trunking between Cisco switches, but it is not required or recommended for a router-to-switch connection; the router interface does not participate in DTP, so the switch port must be statically set as a trunk.

443
MCQmedium

A network engineer is using Cisco DNA Center Assurance to monitor the health of a wireless network. The engineer notices that a particular access point is reporting a high number of client disconnects. Which feature in DNA Center Assurance would best help identify the root cause of these disconnects?

A.Network Health Dashboard
B.Client 360
C.Device 360
D.Application Health
AnswerB

Client 360 provides detailed information about a specific client's connectivity experience, including disconnect reasons, onboarding issues, and RF statistics. By selecting the affected clients, the engineer can see the exact cause of disconnects, such as authentication failures or roaming problems, making it the best tool for root cause analysis.

Why this answer

Client 360 in Cisco DNA Center Assurance offers detailed client-level analytics, including disconnect reasons and historical data, which is essential for troubleshooting client disconnects. The Network Health Dashboard and Device 360 provide broader views, while Application Health is unrelated to client connectivity issues. Thus, Client 360 is the correct tool for root cause analysis.

Exam trap

The trap here is assuming that Device 360 provides per-client disconnect details, when it actually focuses on the device's overall health.

444
Drag & Dropmedium

Drag and drop the steps of EtherChannel troubleshooting and verification into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Troubleshooting begins with checking physical layer, then verifying protocol negotiation, inspecting bundle state, checking load balancing, and finally reviewing logs.

445
MCQmedium

A network administrator is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The requirement is that the VPN must support dynamic routing protocol updates across the tunnel and allow multicast traffic between the sites. Which IPsec configuration mode should be used?

A.IPsec tunnel mode with a crypto map applied to the physical interface
B.GRE over IPsec using a tunnel interface protected by IPsec
C.IPsec transport mode with an access list matching only protocol 47
D.DMVPN phase 1 with only mGRE and no IPsec protection
AnswerB

A GRE tunnel interface can carry unicast, multicast, and broadcast traffic, which allows dynamic routing protocols such as OSPF or EIGRP to form adjacencies and exchange updates. Wrapping the GRE tunnel in IPsec protects the traffic. This combination meets both the routing and multicast requirements that plain IPsec tunnel mode cannot satisfy.

Why this answer

GRE over IPsec creates a virtual tunnel interface that supports multicast and broadcast, enabling dynamic routing protocols to run across the VPN. IPsec then protects the GRE-encapsulated packets. This design satisfies both the routing update and multicast requirements that standard IPsec tunnel mode with a crypto map cannot deliver.

Exam trap

The trap here is assuming plain IPsec tunnel mode carries multicast and routing protocols, which it does not without GRE or another encapsulation.

446
MCQhard

A network security engineer is configuring an IPsec site-to-site VPN between two Cisco IOS routers. The engineer wants to ensure that the VPN tunnel uses perfect forward secrecy (PFS) and that the encryption is AES-256. Which combination of commands achieves this?

A.crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp without set pfs
B.crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group5
C.crypto ipsec transform-set TS esp-aes 256 esp-sha256-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group14
D.crypto ipsec transform-set TS esp-3des esp-md5-hmac, then crypto map CM 10 ipsec-isakmp with set pfs group2
AnswerC

The transform-set with esp-aes 256 and esp-sha256-hmac specifies AES-256 encryption and SHA-256 HMAC for integrity. The set pfs group14 command in the crypto map enables perfect forward secrecy using Diffie-Hellman group 14 (2048-bit). This combination meets both requirements: AES-256 encryption and PFS. The transform-set and crypto map together define the IPsec policy for the tunnel.

Why this answer

To achieve AES-256 encryption and perfect forward secrecy, the transform-set must specify esp-aes 256 and esp-sha256-hmac, and the crypto map must include set pfs with a strong Diffie-Hellman group such as group14. This ensures that each new IPsec SA uses a unique key derived from a fresh Diffie-Hellman exchange, providing forward secrecy. The combination of these commands meets the security requirements.

Exam trap

The trap here is either forgetting to enable PFS or selecting a weak Diffie-Hellman group, which would not satisfy the requirement for perfect forward secrecy with strong encryption.

447
Matchingmedium

Drag and drop each RADIUS attribute on the left to its correct attribute number on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Attribute 1

Attribute 4

Attribute 6

Attribute 8

Attribute 5

Why these pairings

RADIUS attribute numbers are standardized: User-Name is 1, NAS-IP-Address is 4, Service-Type is 6, Framed-IP-Address is 8, and NAS-Port is 5.

448
MCQmedium

A network engineer runs the following command on Router R3: R3# show ip route ospf Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2 i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP a - application route + - replicated route, % - next hop override Gateway of last resort is not set 10.0.0.0/8 is variably subnetted, 5 subnets, 3 masks O IA 10.1.1.0/24 [110/20] via 192.168.1.1, 00:12:34, GigabitEthernet0/0 O 10.2.2.0/24 [110/10] via 192.168.1.2, 00:15:22, GigabitEthernet0/0 O E2 10.3.3.0/24 [110/20] via 192.168.1.3, 00:08:11, GigabitEthernet0/0 Based on this output, what can be concluded?

A.The route to 10.3.3.0/24 is an external route redistributed into OSPF.
B.The route to 10.1.1.0/24 is in the same OSPF area as R3.
C.The metric for 10.3.3.0/24 includes the internal cost to the ASBR.
D.R3 is an ASBR.
AnswerA

The route to 10.3.3.0/24 is an external route redistributed into OSPF. In the routing table, the code 'O E2' explicitly marks this as an OSPF external route of type 2. Type 2 (E2) routes are routes that originated outside the OSPF domain and were redistributed into OSPF, typically from another routing protocol such as EIGRP or BGP. The external cost is carried as configured on the ASBR, and in this case the metric of 20 is the default external cost for redistributed routes, confirming the redistributed origin.

Why this answer

The route to 10.3.3.0/24 is marked as 'O E2' in the output, which stands for OSPF external type 2. This indicates that the route was redistributed into OSPF from another routing protocol or a different OSPF process, making it an external route. The 'E2' designation confirms it is an external route with a fixed metric that does not include the internal cost to the ASBR.

Exam trap

Cisco often tests the difference between OSPF external type 1 (E1) and type 2 (E2) routes, specifically that E2 routes do not include the internal cost to the ASBR, which is a common misconception that leads candidates to incorrectly select option C.

How to eliminate wrong answers

Option B is wrong because the route to 10.1.1.0/24 is marked as 'O IA' (OSPF inter-area), which means it originates from a different OSPF area than R3, not the same area. Option C is wrong because for an OSPF external type 2 (E2) route, the metric shown (20) is the external metric only and does not include the internal cost to the ASBR; that behavior is specific to external type 1 (E1) routes. Option D is wrong because R3 is simply receiving these OSPF routes; there is no indication in the output that R3 is redistributing routes into OSPF, which would be required for it to be an ASBR.

449
MCQeasy

A network engineer is configuring NAT on a Cisco router to allow internal hosts to access the internet. The engineer uses the command ip nat inside source list 100 interface GigabitEthernet0/0 overload, where access list 100 permits only the 10.0.0.0/8 network. After testing, hosts in the 10.0.0.0/8 network can access the internet, but hosts in the 172.16.0.0/16 network cannot. The engineer verifies that the 172.16.0.0/16 hosts have connectivity to the router. What is the most likely cause?

A.The access list 100 does not permit the 172.16.0.0/16 network.
B.The router's interface GigabitEthernet0/0 is not configured with ip nat outside.
C.The 172.16.0.0/16 hosts have a default gateway pointing to a different router.
D.The NAT pool is exhausted for the 172.16.0.0/16 network.
AnswerA

In Cisco NAT, the access list referenced by ip nat inside source list is evaluated against the source addresses of traffic entering the inside interface. Because ACL 100 does not contain an explicit permit statement for 172.16.0.0/16, the implicit deny any at the end prevents those packets from being translated. The router therefore forwards them with their private source IP unchanged, so return traffic from the Internet cannot be routed back to that subnet. A working ping to the gateway does not imply NAT is working; it only confirms Layer 3 reachability.

Why this answer

The command `ip nat inside source list 100 interface GigabitEthernet0/0 overload` uses access list 100 to define which source IP addresses are eligible for NAT. Since ACL 100 permits only the 10.0.0.0/8 network, any traffic from 172.16.0.0/16 is not matched by the ACL and therefore is not translated. Even though the 172.16.0.0/16 hosts have connectivity to the router, their packets are forwarded without NAT and likely dropped by the ISP or the next-hop router because they contain private IP addresses.

Exam trap

Cisco often tests the misconception that the `ip nat inside source list` command automatically translates all inside traffic, when in fact the access list explicitly controls which source addresses are translated.

How to eliminate wrong answers

Option B is wrong because the router's interface GigabitEthernet0/0 is the outside interface, and the command `ip nat inside source list ... interface GigabitEthernet0/0 overload` implicitly designates that interface as the NAT outside interface; the `ip nat outside` command on that interface is not required for NAT overload to function. Option C is wrong because the engineer verified that the 172.16.0.0/16 hosts have connectivity to the router, which means their default gateway is correctly pointing to the router; if it pointed elsewhere, they would not have connectivity to the router. Option D is wrong because NAT pool exhaustion applies only when using a pool of public addresses with `ip nat pool`, but this configuration uses interface overload (PAT), which translates multiple private addresses to a single public IP address and does not have a pool that can be exhausted.

450
MCQhard

A network architect is designing a campus network that must support seamless mobility for wireless clients across Layer 3 boundaries. The design requires that clients retain their IP address when roaming between different subnets. Which Cisco technology should be implemented to achieve this?

A.Cisco Application Centric Infrastructure (ACI) with endpoint groups
B.Cisco Overlay Transport Virtualization (OTV) between campus buildings
C.Cisco FabricPath with Layer 3 forwarding
D.Cisco Locator/ID Separation Protocol (LISP) with mobility
AnswerD

LISP separates endpoint identity from location, allowing a client to keep its IP address while its location changes. In a campus design, LISP can be used to provide seamless mobility across Layer 3 boundaries by updating the mapping of the endpoint identifier to its new routing locator.

Why this answer

LISP separates endpoint identity from location, enabling a wireless client to retain its IP address as it roams across Layer 3 boundaries. The client's endpoint identifier remains constant, while the mapping to its new routing locator is updated in the LISP mapping system. This makes LISP the appropriate technology for seamless mobility in a campus design.

Exam trap

The trap here is confusing data center overlay technologies like OTV or ACI with campus mobility solutions, when LISP is specifically designed for identity-location separation and mobility.

Page 5

Page 6 of 26

Page 7