Courseiva

ENCOR 350-401 (350-401) — Questions 451–525

1923 questions total · 26pages · All types, answers revealed

Page 6

Page 7 of 26

Page 8
451
Multi-Selecthard

A network administrator is configuring MACsec on a Cisco Catalyst switch to secure Layer 2 traffic between two switches. Which two statements about MACsec are true? (Choose two.)

Select 2 answers
A.MACsec requires IPsec to establish the secure channel.
B.MACsec encrypts the entire Ethernet frame including the source and destination MAC addresses.
C.MACsec provides end-to-end encryption between any two hosts in a campus network.
D.MACsec provides encryption and integrity for Ethernet frames at Layer 2.
E.MACsec can be deployed with Cisco TrustSec to provide encryption on switch-to-switch links.
AnswersD, E

MACsec (802.1AE) provides hop-by-hop encryption and integrity check for Ethernet frames. It encrypts the payload and adds an integrity check value (ICV) to detect tampering. This is correct: it operates at Layer 2 and secures the data link between two directly connected devices.

Why this answer

MACsec (802.1AE) provides Layer 2 encryption and integrity for Ethernet frames, and it is commonly deployed with Cisco TrustSec for switch-to-switch links. It uses MKA for key agreement, not IPsec. It does not encrypt MAC addresses, and it is hop-by-hop rather than end-to-end.

Exam trap

The trap here is assuming MACsec provides end-to-end encryption or that it relies on IPsec, when it is actually a hop-by-hop Layer 2 technology using MKA.

452
MCQmedium

A company is deploying an SD-Access fabric with multiple sites connected via a WAN. The design must allow inter-site traffic to be forwarded without requiring a full mesh of VXLAN tunnels between all edge nodes. Which fabric role should be used to interconnect the sites?

A.Fabric border node
B.Fabric control plane node
C.Fabric edge node
D.Fabric WAN controller
AnswerA

In SD-Access, border nodes connect the fabric to external Layer 3 networks (e.g., WAN, data center, Internet) by translating VXLAN encapsulated traffic to traditional routing. They advertise fabric IP prefixes externally and support inter-site VXLAN data plane, handling north-south and east-west inter-site traffic. They also enforce policy and host the LISP control plane for external reachability.

Why this answer

A Fabric Border Node is the correct role because it acts as the gateway between the SD-Access fabric and external networks, including WAN connections. It performs Network-to-Network Interconnection (NNI) by translating VXLAN-encapsulated traffic into the appropriate WAN transport (e.g., IPsec, MPLS) and handles inter-site routing without requiring a full mesh of VXLAN tunnels between all Edge Nodes. This design leverages the Border Node to aggregate traffic and forward it over the WAN, reducing tunnel overhead and simplifying the fabric architecture.

Exam trap

Cisco often tests the misconception that a Fabric Edge Node can directly forward traffic between sites, but the trap here is that Edge Nodes only handle intra-site VXLAN tunnels and rely on Border Nodes for any traffic leaving the fabric site.

How to eliminate wrong answers

Option B is wrong because a Fabric Control Plane Node (using LISP/Map-Server) manages endpoint-to-location mappings and registration within a single fabric site; it does not forward data traffic or interconnect sites over a WAN. Option C is wrong because a Fabric Edge Node is responsible for attaching endpoints (wired/wireless) and encapsulating traffic into VXLAN tunnels within the same fabric site; it cannot directly forward traffic between different sites without a Border Node. Option D is wrong because there is no official 'Fabric WAN Controller' role in Cisco SD-Access; WAN integration is handled by the Fabric Border Node, which can be paired with external WAN controllers (e.g., vManage) but is not a separate fabric role.

453
MCQmedium

A network engineer is configuring MPLS L3VPN on a Cisco IOS-XE PE router. The engineer creates a VRF named CUSTOMER_A with route-target import and export 100:1. After configuring the VRF on the interface connected to the CE router, the CE router can ping the PE's VRF interface IP, but cannot reach any remote VPNv4 routes. The BGP session between PE and route reflector is up. What is the most likely cause?

A.The route-target import/export values are mismatched with the route reflector's configuration.
B.The VRF is not activated under BGP using the address-family ipv4 vrf CUSTOMER_A command.
C.The CE router is not configured with a default route pointing to the PE.
D.The PE router needs the mpls ip command on the interface facing the CE router.
AnswerB

Without the address-family ipv4 vrf CUSTOMER_A command under BGP, the PE does not establish an internal BGP session for that VRF nor inject connected/static routes into VPNv4. This means no VPNv4 routes are generated for CUSTOMER_A, and no remote VPNv4 routes are imported into the VRF, so only the directly connected CE subnet is reachable. Activating the VRF in BGP is the mandatory prerequisite for inter-site route exchange in MPLS Layer 3 VPN.

Why this answer

The CE router can ping the PE's VRF interface IP, confirming Layer 2 and VRF interface configuration are correct. However, the CE cannot reach remote VPNv4 routes, which indicates that the PE is not advertising or installing those routes into the VRF. The most likely cause is that the VRF CUSTOMER_A has not been activated under BGP using the 'address-family ipv4 vrf CUSTOMER_A' command, which is required to exchange IPv4 routes between the PE and CE within the VRF context and to redistribute them into MP-BGP for VPNv4 propagation.

Exam trap

Cisco often tests the misconception that a working BGP session to the route reflector and correct route-target values alone are sufficient for VPNv4 route exchange, when in fact the VRF must be explicitly activated under BGP to enable route advertisement and import.

How to eliminate wrong answers

Option A is wrong because the route-target import/export values (100:1) are configured on the PE, and the route reflector does not need matching route-targets; it only reflects VPNv4 routes based on the RTs attached to the routes, and the PE's import RT must match the export RT of the remote PE, not the route reflector. Option C is wrong because the CE router not having a default route pointing to the PE would affect reachability to remote networks from the CE, but the symptom is that the CE cannot reach remote VPNv4 routes at all, which is a routing advertisement issue on the PE, not a missing default route on the CE. Option D is wrong because the 'mpls ip' command is required on the PE's core-facing interfaces to enable MPLS forwarding, not on the interface facing the CE, which is a Layer 3 VRF interface that does not require MPLS encapsulation.

454
MCQmedium

Review the ACL configuration: ip access-list extended TEST permit tcp 192.168.1.0 0.0.0.255 any eq 80 permit tcp 192.168.1.0 0.0.0.255 any eq 443 deny ip any any ! interface GigabitEthernet0/3 ip access-group TEST in What is missing or incorrect?

A.The ACL should use a wildcard mask of 255.255.255.0 instead of 0.0.0.255.
B.The deny ip any any is redundant because ACLs have an implicit deny at the end.
C.The ACL must be applied outbound to filter incoming traffic.
D.The ACL should use the keyword 'established' to allow return traffic.
AnswerB

Cisco IOS ACLs automatically append an implicit 'deny ip any any' at the end of every access list, so any traffic not explicitly permitted is discarded without further configuration. The explicit 'deny ip any any' is therefore redundant—it does not change the outcome but can still be included for clarity, to generate logging via the 'log' keyword, or to make the default behavior visible to someone reading the config. Removing it would not alter the security posture.

Why this answer

The `deny ip any any` line is redundant. Cisco ACLs have an implicit deny all at the end of every ACL, so adding an explicit deny is unnecessary and does not change the behavior. The configuration is otherwise valid for filtering inbound traffic on GigabitEthernet0/3.

Exam trap

Cisco often tests the concept of the implicit deny to see if candidates recognize that an explicit deny at the end of an ACL is redundant and does not alter functionality.

How to eliminate wrong answers

Option A is wrong because the wildcard mask 0.0.0.255 is correct for matching the 192.168.1.0/24 network; a wildcard mask of 255.255.255.0 would match only the single host 192.168.1.0, not the entire subnet. Option C is wrong because the ACL is applied inbound, which is correct for filtering traffic entering the interface; applying it outbound would filter traffic leaving the interface, not the incoming traffic the question implies. Option D is wrong because the `established` keyword is used for TCP stateful filtering (matching ACK or RST bits) and is not needed here since the permit statements already allow inbound TCP traffic to ports 80 and 443 from the specified source network.

455
MCQmedium

interface GigabitEthernet0/0 ip address 10.0.0.1 255.255.255.0 ip nat outside ! interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ip nat inside ! access-list 1 permit 192.168.1.0 0.0.0.255 ! ip nat inside source list 1 interface GigabitEthernet0/0 overload What is the effect of this configuration?

A.All traffic from 192.168.1.0/24 will be translated to the IP address of GigabitEthernet0/0 using PAT.
B.Only one host from 192.168.1.0/24 can access the internet at a time.
C.Traffic from the outside interface will be translated to 192.168.1.0/24.
D.The configuration will fail because the access list must be applied to an interface.
AnswerA

This statement is correct. The 'overload' keyword makes the router perform Port Address Translation (PAT), where all hosts from the 192.168.1.0/24 network that are matched by the access list have their source IP addresses translated to the IP address configured on GigabitEthernet0/0. Unique source port numbers are assigned to each concurrent connection, allowing many internal hosts to share the single public interface IP.

Why this answer

This configuration uses dynamic NAT with Port Address Translation (PAT), also known as NAT overload. The `ip nat inside source list 1 interface GigabitEthernet0/0 overload` command translates all source IP addresses matching access-list 1 (the 192.168.1.0/24 subnet) to the single IP address of the outside interface (10.0.0.1), using unique source port numbers to differentiate multiple simultaneous sessions. This allows all hosts in the inside network to share the single public IP address for internet access.

Exam trap

Cisco often tests the distinction between dynamic NAT (one-to-one, limited by pool size) and PAT (many-to-one, using port multiplexing), and candidates mistakenly think that 'overload' still limits translation to one host at a time or that the access list must be applied to an interface for NAT to work.

How to eliminate wrong answers

Option B is wrong because PAT (overload) allows multiple hosts from the 192.168.1.0/24 network to access the internet simultaneously by multiplexing sessions via different source port numbers, not one at a time. Option C is wrong because the configuration translates inside source addresses to the outside interface IP, not the reverse; traffic from the outside interface is not translated to the inside network unless a separate `ip nat outside source` command is configured. Option D is wrong because the access list does not need to be applied to an interface; it is referenced directly by the `ip nat inside source list` command to define which traffic to translate, which is a valid and common NAT configuration.

456
MCQmedium

A network engineer issues the following command on Router R5: R5# show ip pim interface Interface PIM Nbrs Hello DR DR Count Intvl Prior GigabitEthernet0/0 on 2 30 1 10.1.1.1 GigabitEthernet0/1 on 1 30 1 10.2.2.2 Loopback0 on 0 30 1 10.3.3.3 Based on this output, what can be concluded?

A.The DR on GigabitEthernet0/0 is 10.1.1.1.
B.The DR on GigabitEthernet0/1 is the local router.
C.PIM is disabled on Loopback0.
D.The hello interval on GigabitEthernet0/0 is 60 seconds.
AnswerA

The output definitively shows that for GigabitEthernet0/0, the DR column lists 10.1.1.1. In PIM Sparse Mode, the DR is the router with the highest IP address on the subnet unless priority overrides, and the address shown is the elected DR for that interface. Therefore, the statement matches the command output and is correct.

Why this answer

The output shows that on GigabitEthernet0/0, the DR (Designated Router) IP address is 10.1.1.1, which is listed in the 'DR' column. This indicates that 10.1.1.1 is the elected DR for that interface, making option A correct. The DR is elected based on the highest IP address when DR priorities are equal (both are 1 here), and 10.1.1.1 is the neighbor with the highest IP on that segment.

Exam trap

Cisco often tests the misconception that the local router is always the DR when it has a higher IP, but the output clearly shows the DR IP in the 'DR' column, which may belong to a neighbor, not the local router.

How to eliminate wrong answers

Option B is wrong because the DR on GigabitEthernet0/1 is 10.2.2.2, which is not the local router's IP (the local router's IP is not shown in the output, but the DR column lists 10.2.2.2, meaning the local router is not the DR). Option C is wrong because the 'on' status in the PIM column for Loopback0 indicates PIM is enabled, not disabled; 'on' means PIM is active on that interface. Option D is wrong because the Hello Interval column shows 30 for GigabitEthernet0/0, not 60 seconds; the default PIM hello interval is 30 seconds.

457
MCQmedium

A network architect is evaluating Cisco StackWise Virtual for a pair of distribution switches. The design requires that the two switches appear as a single logical entity for Layer 2 and Layer 3 forwarding, and that they support Multichassis EtherChannel (MEC) to access switches. Which statement accurately describes a characteristic of Cisco StackWise Virtual?

A.It requires a dedicated stack cable between the switches for control plane communication.
B.It is limited to two switches and cannot be expanded to more than two.
C.It requires that both switches run different IOS versions to ensure compatibility.
D.It supports active/active forwarding, allowing both switches to forward traffic simultaneously.
AnswerD

Cisco StackWise Virtual enables active/active forwarding, meaning both switches in the virtual domain can forward traffic concurrently. This provides load balancing and increased bandwidth utilization. Multichassis EtherChannel (MEC) leverages this capability, allowing access switches to form a port-channel with both distribution switches for redundancy and increased throughput.

Why this answer

Cisco StackWise Virtual allows two physical switches to operate as a single logical switch, supporting active/active forwarding. This means both switches can forward traffic simultaneously, and Multichassis EtherChannel (MEC) can be used to connect access switches to both distribution switches for redundancy and load sharing. This design provides high availability and efficient bandwidth utilization.

Exam trap

The trap here is assuming that StackWise Virtual uses a dedicated stacking cable like traditional StackWise, when it actually uses standard Ethernet ports for the virtual link.

458
Drag & Dropmedium

Drag and drop the steps of BGP policy application (route-map, prefix-list, AS-path ACL) into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, you create the prefix-list or AS-path ACL to match routes. Then you define the route-map with match and set clauses. Next, you apply the route-map to a neighbor under the BGP address-family.

After that, you clear the BGP session to apply the policy. Finally, you verify the policy effect with show ip bgp.

459
MCQeasy

What is the purpose of the 'police' command in a QoS policy-map?

A.To shape traffic to a specific rate by buffering excess packets.
B.To limit the rate of traffic and take action (drop or remark) on packets that exceed the rate.
C.To prioritize traffic by assigning it to a strict priority queue.
D.To classify traffic based on IP precedence or DSCP values.
AnswerB

Policing uses a token bucket (or single/two-rate policer) to measure traffic arrival against a configured committed information rate (CIR) and burst size. Packets that conform are forwarded unchanged, while excess packets are either dropped or have their precedence/DSCP marked down (e.g., set to a lower drop probability). This fits the classic definition of policing, which is a rate-limiting action that takes immediate action on nonconforming packets without buffering.

Why this answer

The 'police' command in a Cisco QoS policy-map implements traffic policing, which enforces a rate limit by measuring traffic flow and taking immediate action—typically dropping or remarking packets—when the traffic exceeds the configured rate. Unlike shaping, policing does not buffer excess traffic; it acts on packets in real time, making it ideal for marking down or discarding non-compliant traffic at the ingress or egress of an interface.

Exam trap

Cisco often tests the distinction between policing and shaping—the trap here is that candidates confuse 'police' with 'shape' because both limit traffic rates, but policing drops/remarks without buffering, while shaping queues and delays excess traffic.

How to eliminate wrong answers

Option A is wrong because shaping (not policing) buffers excess packets to smooth traffic to a specific rate; the 'police' command drops or remarks, not buffers. Option C is wrong because strict priority queuing is configured with the 'priority' command within a class, not with 'police'; policing controls rate, not queue scheduling. Option D is wrong because traffic classification based on IP precedence or DSCP is done with the 'class-map' and 'match' commands, not with the 'police' action; policing is applied after classification.

460
MCQeasy

A network administrator is examining the output of the show interfaces command on a switch and notices a high number of CRC errors on a Gigabit Ethernet port. What is the most likely cause of these errors?

A.Duplex mismatch
B.VLAN mismatch
C.Speed mismatch
D.Cable interference or damage
AnswerD

CRC errors indicate that frames are being corrupted during transmission, which is commonly caused by cable interference, damage, or poor quality cabling. The CRC checksum fails when bits are altered, so the issue is likely at the physical layer. This is the most probable cause.

Why this answer

CRC errors are a physical layer symptom indicating frame corruption. The most common cause is cable interference, damage, or faulty connectors. While duplex mismatch can cause errors, it typically manifests as late collisions and FCS errors, not CRC errors.

Therefore, cable issues are the most likely cause.

Exam trap

The trap here is attributing CRC errors to duplex mismatch, when in fact CRC errors are more directly indicative of physical layer problems such as bad cabling.

461
Multi-Selecthard

A network security team is implementing Cisco TrustSec in a campus network. They need to deploy Security Group Tags (SGTs) and enforce policies using Security Group ACLs (SGACLs). Which two statements are true regarding SGT propagation and enforcement in this environment? (Choose two.)

Select 2 answers
A.SGT Exchange Protocol (SXP) is used to propagate SGTs to devices that do not support hardware-based tagging.
B.SXP requires the use of IPsec for secure communication between peers.
C.SGTs can be propagated inline within the Ethernet frame using Cisco Metadata (CMD) on supported hardware.
D.SGACLs are enforced only on the ingress interface where the SGT is assigned.
E.SGTs are always carried in the IP header using the DSCP field.
AnswersA, C

SXP is a control-plane protocol that maps IP addresses to SGTs and is used to propagate SGT information to devices that cannot perform inline tagging, such as older switches or routers. It allows these devices to enforce SGACLs based on the SGT mapping. This is a key component of TrustSec for mixed environments.

Why this answer

SGTs can be propagated inline using Cisco Metadata on supported hardware, and SXP is used for devices that cannot do inline tagging. These two methods allow flexible deployment in mixed environments. SGACLs can be enforced at various points, not just ingress, and SGTs are not carried in DSCP.

SXP does not mandate IPsec.

Exam trap

The trap here is assuming SGTs are carried in the IP header or that enforcement is limited to ingress, while the actual mechanisms are inline tagging and SXP with enforcement at multiple points.

462
Matchingmedium

Drag and drop each DHCP option on the left to its matching purpose on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Provides vendor-specific information such as TFTP server address

Identifies the vendor class of the DHCP client

Carries relay agent information for DHCP snooping

Specifies the TFTP server name

Specifies the TFTP server IP address for Cisco phones

Why these pairings

Option 43 provides vendor-specific info; Option 60 identifies vendor class; Option 82 is relay agent information.

463
MCQeasy

An engineer configures IP SLA 50 to monitor the response time of a TCP connection to a server at 10.1.1.1 on port 80. The operation is used to trigger a backup path. The engineer notices that the IP SLA operation shows 'State: Active' and 'Latest RTT: 100 ms', but the server is actually down and not responding to TCP SYN packets. What is the most likely reason?

A.A stateful firewall or load balancer is responding to the TCP SYN on behalf of the server, causing the probe to succeed.
B.The IP SLA TCP connect probe does not actually verify that the server responds; it only checks if the port is open.
C.The IP SLA operation must be configured with a 'timeout' value lower than 100 ms to detect the failure.
D.The server is actually responding to the probe but not to other traffic because the probe uses a different source IP.
AnswerA

A stateful firewall or load balancer that performs TCP proxy or stateful inspection can intercept the inbound SYN and reply with a SYN-ACK on behalf of the backend server. The IP SLA TCP connect operation only confirms that it received a SYN-ACK, so the handshake appears successful even if the actual server is down or unreachable. Because the intermediary completes the three-way handshake, the probe incorrectly reports an RTT of 100 ms while real application traffic still fails.

Why this answer

A stateful firewall or load balancer can intercept the TCP SYN packet sent by the IP SLA probe and respond with a SYN-ACK on behalf of the actual server, even if the server is down. This causes the IP SLA TCP connect operation to complete the three-way handshake and report a successful state with a valid RTT, misleading the engineer into thinking the server is reachable.

Exam trap

Cisco often tests the misconception that IP SLA TCP connect only checks if the port is open (like a port scan), when in reality it performs a full TCP handshake, and the trap here is that candidates overlook how middleboxes can spoof successful handshakes, leading them to incorrectly choose option B.

How to eliminate wrong answers

Option B is wrong because the IP SLA TCP connect probe does verify that the server responds by completing a full TCP three-way handshake; it does not merely check if the port is open via a stateless scan. Option C is wrong because the timeout value does not affect whether the probe succeeds or fails when a false positive response is received; the probe completes within the RTT of 100 ms, so lowering the timeout below 100 ms would cause a timeout only if the probe actually waited longer, but here the response arrives quickly. Option D is wrong because the probe uses the source IP of the router's egress interface by default, and the server being down would not respond regardless of source IP; the issue is that a middlebox is responding, not that the server treats different source IPs differently.

464
MCQmedium

A network architect is designing a Cisco SD-WAN fabric for a company with 50 branch sites. The company requires that each branch have two WAN transports (MPLS and Internet) with per-application traffic steering, and that the fabric use a controller-based architecture for centralized policy. Which Cisco SD-WAN component is responsible for distributing fabric-wide policy and managing control plane connectivity?

A.vManage NMS
B.vSmart controller
C.vEdge router
D.vBond orchestrator
AnswerB

The vSmart controller is the centralized policy and control plane component of Cisco SD-WAN. It distributes OMP routes and policies to vEdge routers, enabling per-application traffic steering across MPLS and Internet transports. It does not forward data traffic; it only manages control plane and policy. This matches the requirement for centralized policy in a controller-based architecture.

Why this answer

In Cisco SD-WAN, the vSmart controller is the brain of the control plane. It distributes OMP routes and policies to all vEdge routers, enabling centralized policy and per-application traffic steering. The vBond orchestrator handles initial authentication, vManage provides management, and vEdge routers forward data.

Only vSmart distributes fabric-wide policy and manages control plane connectivity.

Exam trap

The trap here is confusing the management plane role of vManage with the control plane policy distribution role of vSmart.

465
Multi-Selecthard

Which three statements about virtual machine (VM) resource allocation and overcommitment are true? (Choose three.)

Select 3 answers
A.Memory overcommitment allows the sum of all virtual machine memory allocations to exceed the physical RAM of the host.
B.CPU overcommitment is achieved by scheduling virtual CPUs onto physical cores, often with a ratio greater than 1:1.
C.Overcommitment always guarantees better performance for all virtual machines.
D.Storage overcommitment is supported by thin provisioning, where virtual disks consume only the space actually used.
E.A hypervisor cannot overcommit CPU resources because each vCPU must be pinned to a dedicated physical core.
AnswersA, B, D

Memory overcommitment lets the hypervisor assign more RAM to VMs than the host physically holds, relying on reclaim techniques such as ballooning, swapping and transparent page sharing to satisfy actual demand. This directly satisfies the stem's requirement that total VM memory allocations may exceed physical host RAM.

Why this answer

Option A is correct because memory overcommitment is precisely the technique that lets the total configured guest RAM exceed the host's physical RAM, with the hypervisor reclaiming pages via mechanisms like ballooning, swapping, or transparent page sharing. Option B is correct because CPU overcommitment works by having the hypervisor scheduler time-slice multiple vCPUs onto fewer physical cores, commonly at ratios above 1:1, so vCPUs are not permanently bound to cores. Option D is correct because thin provisioning implements storage overcommitment by allocating blocks on demand, so a virtual disk only consumes physical capacity equal to the data actually written rather than its full nominal size.

Option C is incorrect because overcommitment is a trade-off that can degrade performance under contention and never guarantees better performance for all VMs. Option E is incorrect because a hypervisor can and routinely does overcommit CPU resources; pinning each vCPU to a dedicated physical core is optional and not a requirement.

Exam trap

The trap here is the absolutist wording in options C and E — 'always guarantees' and 'cannot overcommit' — which candidates may accept if they conflate overcommitment with guaranteed performance or assume vCPU-to-core pinning is mandatory.

466
MCQmedium

interface GigabitEthernet0/2 spanning-tree link-type point-to-point end What is the effect of this configuration?

A.The port will use RSTP fast transition mechanisms assuming a point-to-point link.
B.The port will become a designated port immediately.
C.The port will disable STP on that link.
D.The port will use shared medium behavior.
AnswerA

Setting the link type to point-to-point marks the switchport as a direct, full-duplex connection between exactly two switches, which lets Rapid Spanning Tree (RSTP/Rapid PVST+) invoke its proposal/agreement mechanism. Once the root port sends a proposal and receives agreement from the downstream designated port, the port can enter the forwarding state immediately instead of waiting through the default 15-second listening and 15-second learning timers. This fast transition is the key benefit of RSTP over classic 802.1D STP and is only used when the link is treated as point-to-point.

Why this answer

The `spanning-tree link-type point-to-point` command manually overrides the port's link type to point-to-point, forcing the port to use Rapid Spanning Tree Protocol (RSTP) fast transition mechanisms (proposal/agreement handshake) instead of the slower 802.1D listening/learning states. This is correct because RSTP relies on the link type to determine whether it can safely perform a fast transition to the forwarding state; a point-to-point link allows immediate transition without waiting for timers.

Exam trap

The trap here is that candidates often confuse the `spanning-tree link-type point-to-point` command with disabling STP or forcing a designated port, when in reality it only influences the RSTP fast transition behavior based on the perceived link type.

How to eliminate wrong answers

Option B is wrong because the command does not directly force a port to become a designated port; the RSTP proposal/agreement process determines the port role (root, designated, alternate, backup) based on bridge ID and path cost, not the link-type setting. Option C is wrong because the command does not disable STP; STP remains active and the port still participates in spanning tree calculations, just with faster convergence. Option D is wrong because the command explicitly sets the link type to point-to-point, which is the opposite of shared medium behavior; shared medium behavior would be used with a hub or half-duplex link, and this command forces point-to-point even if the physical medium is shared.

467
MCQhard

A network architect is designing a Cisco SD-Access fabric. The requirement is to provide segmentation for different user groups (employees, guests, contractors) while allowing them to share the same physical infrastructure. Which Cisco SD-Access component is responsible for enforcing group-based policies between endpoints?

A.Identity Services Engine (ISE)
B.Fabric Edge Node
C.Control Plane Node (CP Node)
D.Fabric Border Node
AnswerB

Fabric edge nodes are responsible for enforcing group-based policies using Scalable Group ACLs (SGACLs). They encapsulate traffic with VXLAN and include the source group tag (SGT) and destination group tag (DGT) in the VXLAN header. Based on these tags, the edge node applies the appropriate SGACL. This enforces segmentation between user groups even when they share the same physical network.

Why this answer

In Cisco SD-Access, segmentation is achieved through the use of Scalable Group Tags (SGTs) and SGACLs. The fabric edge nodes are the enforcement points where SGACLs are applied. When an endpoint sends traffic, the edge node adds the source SGT to the VXLAN header.

The destination edge node uses the source and destination SGTs to apply the correct SGACL. This allows different user groups to be segmented even when using the same physical infrastructure. ISE assigns SGTs, but enforcement is at the edge.

Exam trap

The trap here is assuming that ISE enforces the policies because it assigns SGTs, when in fact the fabric edge nodes are the enforcement points.

468
Matchinghard

Drag and drop each BGP path selection criterion on the left to its correct order of preference (1 = highest priority) on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

1

2

3

4

5

Why these pairings

Weight (highest) is checked first, then LOCAL_PREF (highest), then locally originated routes, then AS_PATH length (shortest), then ORIGIN (IGP > EGP > incomplete).

469
Multi-Selectmedium

Which three statements about Cisco QoS policing and shaping are true? (Choose three.)

Select 3 answers
A.Policing can re-mark traffic that exceeds the configured rate to a lower priority.
B.Shaping buffers excess traffic and transmits it later to avoid drops.
C.Both policing and shaping use a token bucket algorithm to measure traffic rates.
D.Policing buffers traffic that exceeds the rate to reduce packet loss.
E.Shaping is typically applied on the ingress interface to control incoming traffic.
AnswersA, B, C

Policing meters traffic against the token bucket and, instead of dropping, can mark conforming or exceeding packets with a new DSCP or IP precedence value, lowering their priority downstream. This satisfies the requirement to re-mark excess traffic.

Why this answer

Policing drops or re-marks traffic exceeding a rate, while shaping buffers excess traffic. Policing is typically applied inbound, shaping outbound. Option A is correct because policing can mark down traffic (e.g., set DSCP to 0) when the rate is exceeded.

Option B is correct because shaping buffers traffic to smooth bursts, reducing drops. Option C is correct because both use a token bucket model to measure conformance. Option D is incorrect because policing does not buffer; it drops or re-marks.

Option E is incorrect because shaping is applied on egress, not ingress.

470
Matchingmedium

Drag and drop each data encoding format on the left to its matching use case on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Lightweight data interchange for REST APIs

Structured data format used in NETCONF messages

Human-readable format for configuration files

Binary serialization for high-performance systems

Why these pairings

JSON is lightweight and widely used in REST APIs, XML is verbose and used in NETCONF, YAML is human-readable for configuration files, and Protobuf is efficient for high-performance systems.

471
MCQmedium

Examine the following interface configuration on a Cisco IOS-XE switch: ``` interface GigabitEthernet0/1 switchport mode access switchport port-security switchport port-security maximum 2 switchport port-security violation restrict switchport port-security mac-address sticky ``` What is the effect of this configuration?

A.The port will dynamically learn MAC addresses, allow up to 2 addresses, and if a third MAC is seen, it will drop the traffic but keep the port up.
B.The port will learn up to 2 MAC addresses and then shut down if a third is seen.
C.The port will allow only 2 MAC addresses and will generate a syslog message but continue forwarding traffic from the third MAC.
D.The port will learn MAC addresses dynamically and convert them to secure MAC addresses, but the maximum is 1 by default.
AnswerA

With port security in violation mode restrict, the switch dynamically learns secure MAC addresses up to the configured maximum of two. When a third distinct source MAC appears, frames from that unknown MAC are dropped by the port, but the port remains administratively up and operational for the two learned addresses. Restrict does not disable the interface; it silently discards violating traffic and increments the security violation counter, which is exactly what this scenario describes.

Why this answer

The configuration sets port-security with a maximum of 2 MAC addresses, violation mode 'restrict', and sticky MAC learning. When a third MAC address is seen, the 'restrict' action drops traffic from that MAC but keeps the port up, generates a syslog message, and increments the violation counter. Option A correctly describes this behavior.

Exam trap

Cisco often tests the distinction between violation modes ('shutdown', 'restrict', 'protect'), and the trap here is confusing 'restrict' with 'shutdown' or assuming 'restrict' silently drops all traffic, when in fact it only drops traffic from the violating MAC and logs the event.

How to eliminate wrong answers

Option B is wrong because it describes the 'shutdown' violation mode, which would disable the port upon a violation, not the 'restrict' mode configured here. Option C is wrong because 'restrict' does not continue forwarding traffic from the violating MAC; it drops that traffic while allowing other valid MACs to communicate. Option D is wrong because the 'switchport port-security maximum 2' command explicitly sets the maximum to 2, overriding the default of 1, and sticky learning converts dynamically learned addresses to secure MACs.

472
Matchingmedium

Drag and drop each VNF category on the left to its matching example on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Cisco CSR 1000v

Cisco Firepower NGFWv

F5 BIG-IP Virtual Edition

Cisco vWAAS

Cisco Firepower NGIPSv

Why these pairings

VNFs replace physical appliances; common examples include virtual routers, firewalls, and load balancers.

473
MCQhard

A network engineer runs the following command on Router R5: R5# show ip nat translations Pro Inside global Inside local Outside local Outside global udp 192.0.2.20:1234 10.0.0.20:1234 203.0.113.1:53 203.0.113.1:53 tcp 192.0.2.20:5678 10.0.0.20:5678 198.51.100.1:80 198.51.100.1:80 Based on this output, what can be concluded?

A.The router is configured with static NAT for two internal hosts.
B.The router is performing Port Address Translation (PAT) for multiple sessions from the same internal host.
C.The router is performing destination NAT.
D.The inside local address 10.0.0.20 is using two different global addresses.
AnswerB

The translation table shows two entries both sourced from inside local 10.0.0.20, and both are assigned the same inside global address 192.0.2.20. The differentiator between the sessions is the source port, which is the defining behavior of Port Address Translation (PAT) / NAT overload. PAT lets one internal host sustain multiple concurrent TCP or UDP flows through a single public IP by rewriting each packet's source port along with the IP address, which matches the entries given in the question.

Why this answer

The output shows two different translations (UDP and TCP) for the same inside local address 10.0.0.20, both using the same inside global address 192.0.2.20 but with different port numbers (1234 and 5678). This is characteristic of Port Address Translation (PAT), also known as NAT overload, where a single public IP address is shared among multiple sessions from the same internal host by multiplexing on the transport layer port. Option B correctly identifies this behavior.

Exam trap

Cisco often tests the distinction between static NAT and PAT by showing multiple translations from the same inside local address with different ports, leading candidates to mistakenly think static NAT is involved when the key clue is the port multiplexing.

How to eliminate wrong answers

Option A is wrong because static NAT would map a single inside local address to a single inside global address in a one-to-one fashion, not show multiple sessions with different ports; the output shows two sessions from the same inside local host, not two different hosts. Option C is wrong because destination NAT (also called outside NAT or reverse NAT) would change the destination IP address in packets, but the output shows the same outside local and outside global addresses (203.0.113.1:53 and 198.51.100.1:80), indicating no destination translation is occurring. Option D is wrong because the inside local address 10.0.0.20 is using only one inside global address (192.0.2.20) for both sessions, not two different global addresses.

474
MCQmedium

Examine the following configuration snippet: interface GigabitEthernet0/1 ip access-group FILTER_IN in ! ip access-list extended FILTER_IN deny icmp any any echo permit ip any any What is the effect of this configuration?

A.It blocks all ICMP traffic inbound on GigabitEthernet0/1.
B.It blocks inbound ICMP Echo requests on GigabitEthernet0/1.
C.It blocks all inbound traffic on GigabitEthernet0/1.
D.It blocks outbound ICMP Echo requests on GigabitEthernet0/1.
AnswerB

This configuration filters ingress traffic on GigabitEthernet0/1 by matching ICMP packets with type 8, which is the Echo request used by ping. Because the access-group is applied in the inbound direction, any ICMP Echo request arriving on the interface is denied and dropped, while every other packet—including other ICMP types and all IP protocols—matches the final permit ip any any and is permitted. The result is precisely that inbound ICMP Echo requests (pings) are blocked, but nothing else is affected.

Why this answer

The access list FILTER_IN explicitly denies ICMP packets with the 'echo' type (ping requests) while permitting all other IP traffic. Applied inbound on GigabitEthernet0/1, this blocks only inbound ICMP Echo requests, not all ICMP traffic (e.g., Echo replies, TTL-exceeded messages are permitted). The 'permit ip any any' at the end ensures all other traffic is allowed.

Exam trap

Cisco often tests the distinction between 'all ICMP' and 'specific ICMP types' — the trap here is assuming 'deny icmp any any echo' blocks all ICMP traffic, when it only blocks Echo requests, leaving other ICMP types permitted.

How to eliminate wrong answers

Option A is wrong because the ACL only denies ICMP 'echo' (type 8), not all ICMP types; other ICMP messages like Echo reply (type 0) or unreachable (type 3) are permitted. Option C is wrong because the ACL permits all IP traffic except the specific ICMP echo deny; it does not block all inbound traffic. Option D is wrong because the ACL is applied inbound on the interface, so it filters traffic entering the interface, not outbound traffic; outbound filtering would require the 'out' keyword.

475
Drag & Dropmedium

Drag and drop the steps of SR-IOV configuration for VM network bypass into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The configuration begins with enabling SR-IOV in the BIOS, then creating virtual functions, assigning them to the VM, and finally installing drivers inside the VM.

476
Multi-Selecthard

A network engineer is deploying a new Cisco SD-Access fabric. The design includes underlay and overlay networks. Which two statements accurately describe the underlay network in a Cisco SD-Access fabric? (Choose two.)

Select 2 answers
A.The underlay encapsulates user traffic in VXLAN to provide overlay connectivity.
B.The underlay provides a loop-free topology using a routing protocol and does not rely on Spanning Tree Protocol.
C.The underlay is responsible for mapping endpoint IP addresses to fabric locators (RLOCs).
D.The underlay uses a static routing protocol to simplify configuration and reduce overhead.
E.The underlay uses a routing protocol such as IS-IS or OSPF to provide reachability between fabric nodes.
AnswersB, E

The underlay is typically a Layer 3 routed network that uses a routing protocol to ensure loop-free paths. It does not rely on Spanning Tree Protocol, which is a Layer 2 loop prevention mechanism. This is a correct characteristic of the SD-Access underlay.

Why this answer

In Cisco SD-Access, the underlay provides IP reachability between fabric nodes using a routing protocol such as IS-IS or OSPF, and it is a loop-free Layer 3 network that does not rely on Spanning Tree Protocol. VXLAN encapsulation and LISP mapping are overlay functions. Static routing is not the typical underlay approach.

Exam trap

The trap here is confusing underlay and overlay responsibilities; VXLAN encapsulation and LISP mapping are overlay functions, not underlay.

477
Multi-Selecthard

A network administrator is using Cisco DNA Center Assurance to troubleshoot a user's poor voice quality. The administrator wants to identify whether the issue is related to the network or the application. Which two Assurance features should be used to gather relevant data? (Choose two.)

Select 2 answers
A.Application Health
B.Network Health Dashboard
C.Client 360
D.Path Trace
E.Sensor Test
AnswersA, C

Application Health provides detailed metrics on application performance, including network latency, jitter, and packet loss for specific applications like voice. It can help determine if the voice quality issue is due to the application itself or the network path. By analyzing application-specific data, the administrator can isolate whether the problem is within the application or the underlying network.

Why this answer

To troubleshoot poor voice quality, the administrator should use Application Health to get application-specific performance metrics such as jitter and packet loss, and Client 360 to examine the specific client's connectivity and RF conditions. Together, these features provide a comprehensive view of both the application and the client's network experience. Other features like the Network Health Dashboard or Sensor Test offer broader or synthetic data, which may not pinpoint the issue for a specific user.

Thus, Application Health and Client 360 are the correct choices.

Exam trap

The trap here is assuming that the Network Health Dashboard provides application-level details, but it only shows device health, not voice quality metrics.

478
MCQhard

A network automation team is using the Cisco DNA Center Intent API to create a new site hierarchy and assign devices. The API call to create the site returns HTTP 202 Accepted, but a subsequent call to assign a device to that site fails with an error that the site does not exist. The team is polling the task endpoint but has not yet received a success status. What is the most likely explanation?

A.The 202 response means the request is processed asynchronously, and the site is not available until the associated task completes successfully
B.The site creation API requires a PUT instead of a POST, so the site was never created
C.The device assignment must be performed before site creation, so the order of operations is reversed
D.The API token expired between the two calls, causing the second call to fail with a site-not-found error
AnswerA

Cisco DNA Center returns HTTP 202 Accepted for asynchronous operations, including site creation. The response includes a task ID, and the site is not fully created until that task reaches a success state. The device assignment fails because the site does not yet exist. The team must poll the task endpoint until completion before proceeding.

Why this answer

Cisco DNA Center Intent API operations such as site creation are asynchronous and return HTTP 202 Accepted with a task ID. The site is not available for subsequent operations until the task completes successfully. The team must poll the task endpoint until it reports success before attempting to assign devices to the new site, which resolves the site-not-found error.

Exam trap

The trap here is treating a 202 Accepted response as immediate success, when it only means the request was queued for asynchronous processing.

479
MCQeasy

A network administrator is configuring a Cisco IOS router to act as a DHCP server for the 10.10.10.0/24 subnet. The router interface GigabitEthernet0/0 is configured with IP address 10.10.10.1/24. Which command is required to specify the DNS server address that will be provided to DHCP clients?

A.domain-name-server 8.8.8.8
B.dns-server 8.8.8.8
C.ip name-server 8.8.8.8
D.ip dhcp dns 8.8.8.8
AnswerB

Within the DHCP pool configuration mode, the 'dns-server' command specifies the DNS server IP address that DHCP clients will receive. This is the correct command to provide DNS information to clients. It is configured under 'ip dhcp pool' and can list multiple DNS servers. This ensures clients can resolve domain names. The command is essential for proper network operation when DHCP is used for address assignment.

Why this answer

The correct command to specify DNS servers for DHCP clients is 'dns-server' within the DHCP pool configuration mode. This command directly populates the DNS option in DHCP offers. The other options are either global router DNS settings or invalid commands.

Proper configuration ensures that clients receive the necessary DNS information to resolve hostnames, which is critical for network functionality.

Exam trap

The trap here is confusing the router's own DNS configuration ('ip name-server') with the DHCP pool option ('dns-server') that is sent to clients.

480
MCQhard

A network engineer is configuring a Cisco Catalyst 9000 switch for a new access layer. The engineer needs to enable a feature that allows the switch to authenticate endpoints using 802.1X and then assign them to a specific VLAN based on the result. Which Cisco feature should be configured to dynamically assign VLANs?

A.Private VLAN (PVLAN) edge
B.Dynamic ARP Inspection (DAI)
C.802.1X with VLAN assignment via RADIUS
D.VLAN Membership Policy Server (VMPS)
AnswerC

When 802.1X is configured with a RADIUS server, such as Cisco ISE, the server can return attributes that instruct the switch to place the authenticated endpoint into a specific VLAN. This is done using the IETF RADIUS attribute Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID. The switch then dynamically assigns the port to that VLAN. This feature is supported on Catalyst 9000 switches and is the standard method for dynamic VLAN assignment.

Why this answer

The correct feature is 802.1X with VLAN assignment via RADIUS. When an endpoint authenticates via 802.1X, the switch acts as an authenticator and relays credentials to a RADIUS server like Cisco ISE. Upon successful authentication, the RADIUS server can return tunnel attributes that specify the VLAN.

The switch then dynamically assigns the port to that VLAN, allowing for role-based access control and simplified VLAN management.

Exam trap

The trap here is selecting VMPS, which is an older dynamic VLAN assignment method based on MAC addresses, not 802.1X authentication, and is not supported on modern Catalyst switches.

481
MCQmedium

A network architect is designing a fabric that must support Layer 2 and Layer 3 connectivity for endpoints across multiple sites without stretching VLANs between them. The design requires a control plane that separates the endpoint identifier from the routing locator, allowing traffic to be tunneled over a routed underlay. Which Cisco architecture component provides this separation in an SD-Access fabric?

A.MP-BGP EVPN with MPLS L3VPN VRFs
B.Cisco TrustSec with SGT Exchange Protocol
C.OTV with IS-IS adjacency over the WAN
D.LISP control plane with VXLAN data plane
AnswerD

LISP separates endpoint identity (EID) from routing locator (RLOC), which is exactly the identifier/locator split the scenario demands. VXLAN provides the tunneling data plane over the routed underlay, and the fabric border and edge nodes register EIDs to the map server. Together they deliver Layer 2 and Layer 3 overlay connectivity without stretching VLANs across sites.

Why this answer

The Cisco SD-Access fabric uses LISP as its control plane to separate endpoint identity from routing location, and VXLAN as the data plane to tunnel overlay traffic across a routed underlay. This combination lets endpoints remain in their Layer 2 or Layer 3 virtual networks without extending VLANs between sites, which is precisely what the architect requires.

Exam trap

The trap here is assuming that any overlay technology that tunnels Layer 2 traffic, such as OTV or EVPN, satisfies the SD-Access fabric requirement, when the specific identifier/locator separation is provided by LISP.

482
MCQmedium

Consider the following Python script that uses the requests library to delete a VLAN via RESTCONF on a Cisco IOS-XE device: ```python import requests from requests.auth import HTTPBasicAuth url = 'https://192.168.1.1/restconf/data/Cisco-IOS-XE-native:native/vlan=10' headers = { 'Accept': 'application/yang-data+json', 'Content-Type': 'application/yang-data+json' } auth = HTTPBasicAuth('admin', 'cisco') response = requests.delete(url, headers=headers, auth=auth, verify=False) print(response.status_code) ``` What is the expected outcome if the VLAN 10 exists?

A.It will retrieve the configuration of VLAN 10.
B.It will create VLAN 10 if it does not exist.
C.It will delete VLAN 10 from the device configuration.
D.It will return an error because the payload is missing.
AnswerC

RESTCONF DELETE against the exact data node URL removes the targeted VLAN instance; with VLAN 10 present, IOS-XE returns 204 No Content and the VLAN is removed from the running configuration. The URL path identifies the list entry, so the operation succeeds.

Why this answer

The `requests.delete()` method sends an HTTP DELETE request to the RESTCONF API endpoint for VLAN 10. When the VLAN exists, the device processes the DELETE operation and removes the VLAN configuration from the running config, returning a 204 No Content status code upon success.

Exam trap

The trap here is that candidates may confuse HTTP methods, thinking DELETE requires a payload like PUT/POST, or mistakenly believe DELETE can retrieve or create resources, when in fact each HTTP method has a distinct CRUD mapping in RESTCONF.

How to eliminate wrong answers

Option A is wrong because an HTTP DELETE request does not retrieve data; retrieving data requires an HTTP GET request. Option B is wrong because creating a resource uses an HTTP POST or PUT request, not DELETE. Option D is wrong because RESTCONF DELETE operations do not require a payload; the resource is identified by the URL path alone, and a missing payload does not cause an error for DELETE.

483
Drag & Dropmedium

Drag and drop the steps of configuring model-driven telemetry with gRPC on a Cisco IOS-XE device into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, enable telemetry and define the destination. Then, create a subscription with a sensor path. Next, set the update policy.

Finally, verify the telemetry data is being sent.

484
Drag & Dropmedium

Drag and drop the steps of IKEv2 fragmentation and DPD keepalive process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

During IKEv2, if the IKE packet exceeds the MTU, the sender fragments it into smaller pieces. The receiver reassembles the fragments into the original packet. After the IKE SA is established, the peers send Dead Peer Detection (DPD) keepalives to verify connectivity.

If no response is received, the peer retransmits the DPD. After multiple failures, the peer declares the SA dead and deletes it.

485
MCQmedium

A network engineer is designing a WAN connection for a branch office that requires high availability and bandwidth aggregation. The branch has two internet connections from different ISPs. The engineer wants to use both links actively for load balancing and failover. Which design approach should be used?

A.Deploy SD-WAN to actively use both links with policy-based load balancing.
B.Configure static routes with different metrics for each link and use HSRP for failover.
C.Use BGP with both ISPs and rely on BGP best path selection for load balancing.
D.Implement a VPN tunnel between the branch and headquarters using only one link.
AnswerA

SD-WAN is purpose-built for active/active WAN utilization: it establishes secure overlay tunnels across both transport links and uses centralized or distributed policy-based routing to steer traffic per application, class, or SLA. This allows both links to carry production traffic simultaneously, with dynamic path selection for load balancing and fast reroute if one link degrades or fails. The policy engine also factors in real-time loss, latency, and jitter, making it the only option that truly satisfies the requirement to actively use both links.

Why this answer

SD-WAN is the correct design because it natively supports active/active utilization of multiple WAN links with policy-based load balancing, allowing traffic to be distributed across both ISP connections based on application policies, SLA metrics, or other criteria. It also provides seamless failover by dynamically rerouting traffic if one link fails, meeting the requirements for high availability and bandwidth aggregation without relying on a single active link.

Exam trap

Cisco often tests the misconception that BGP multipath or static routes with HSRP can achieve active/active load balancing, but these methods either require complex tuning or are inherently active/passive, failing to meet the policy-based and application-aware requirements that SD-WAN uniquely addresses.

How to eliminate wrong answers

Option B is wrong because static routes with different metrics and HSRP are designed for active/passive failover, not active/active load balancing; HSRP operates at Layer 2 for gateway redundancy and does not distribute traffic across multiple WAN links. Option C is wrong because BGP best path selection selects only a single best path per prefix by default, and while BGP can be tuned for load balancing with features like multipath, it does not inherently provide policy-based load balancing or application-aware traffic steering like SD-WAN. Option D is wrong because implementing a VPN tunnel using only one link defeats the purpose of using both links for load balancing and failover, leaving the branch dependent on a single connection.

486
Drag & Dropmedium

Drag and drop the steps of Cisco IOS-XE mdt subscription via CLI configuration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The CLI configuration begins by entering global config, defining the receiver, setting the subscription parameters, applying the subscription, and verifying it.

487
Multi-Selectmedium

Which two statements about RESTCONF are true? (Choose two.)

Select 2 answers
A.RESTCONF uses SSH for transport security.
B.RESTCONF uses HTTP methods such as GET, PUT, POST, DELETE, and PATCH.
C.RESTCONF is designed to replace NETCONF entirely.
D.RESTCONF supports both JSON and XML encoding for data representation.
E.RESTCONF uses remote procedure calls (RPCs) for all operations.
AnswersB, D

RESTCONF maps CRUD operations onto standard HTTP verbs, so GET retrieves, PUT replaces, POST creates, DELETE removes and PATCH merges configuration data. This satisfies the stem's requirement for a true statement, since RESTCONF is defined by the IETF as a RESTful, HTTP-based protocol operating on YANG-modelled data.

Why this answer

Option B is correct because RESTCONF is a RESTful protocol that maps CRUD operations onto standard HTTP methods — GET to retrieve data, POST to create, PUT to replace, PATCH to modify, and DELETE to remove resources — as defined in RFC 8040. Option D is correct because RESTCONF supports both JSON (the default, media type application/yang-data+json) and XML (application/yang-data+xml) encoding for representing YANG-modeled data. Option A is incorrect because RESTCONF runs over HTTPS (HTTP over TLS, typically port 443), not SSH; SSH is the transport used by NETCONF.

Option C is incorrect because RESTCONF is not intended to replace NETCONF entirely — it is a complementary, lightweight HTTP-based alternative, and NETCONF remains widely used for full configuration and RPC capabilities. Option E is incorrect because RESTCONF uses HTTP methods for operations rather than RPCs; RPC-style operations are characteristic of NETCONF, and RESTCONF only supports a limited RPC mechanism via POST to specific operation resources.

Exam trap

350-401 often tests the confusion between RESTCONF and NETCONF transport and encoding: candidates may incorrectly assume RESTCONF uses SSH like NETCONF, or that RESTCONF replaces NETCONF, when in fact they are complementary and use different transports and operation models.

488
MCQhard

A security architect is designing a Cisco TrustSec deployment for a campus network. The architect needs to ensure that security group tags (SGTs) are propagated across a Layer 2 trunk between two Catalyst switches that do not support SGACL enforcement. Which technology should be used to carry SGT information inline within the Ethernet frame?

A.MACsec
B.SXP
C.802.1Q tunneling (QinQ)
D.Cisco Meta Data (CMD)
AnswerD

Cisco Meta Data (CMD) is the inline tagging method that embeds the SGT directly into the Ethernet frame using a special EtherType. It allows SGT propagation across Layer 2 trunks without requiring SGACL enforcement on every switch. This is the correct technology for carrying SGT information inline in the frame, enabling TrustSec propagation across the campus.

Why this answer

Cisco Meta Data (CMD) is the inline tagging mechanism in Cisco TrustSec that inserts the SGT into the Ethernet frame. It enables SGT propagation across switches that may not enforce SGACLs, allowing downstream devices to apply policies. This satisfies the requirement for inline SGT carriage over a Layer 2 trunk.

Exam trap

The trap here is confusing SXP with inline tagging; SXP exchanges SGT bindings out-of-band, while CMD embeds the tag directly in the frame.

489
MCQmedium

Examine this configuration: aaa new-model aaa authentication login default local aaa authorization exec default local aaa accounting exec default start-stop group tacacs+ line vty 0 4 login authentication default privilege level 15 What is missing to ensure that VTY users are authenticated via TACACS+?

A.The 'aaa authentication login default' command should include 'group tacacs+' before 'local'.
B.The 'aaa authorization exec default' command should include 'group tacacs+'.
C.The 'aaa accounting exec default' command should include 'group tacacs+'.
D.The 'privilege level 15' command under VTY lines is missing.
AnswerA

The default authentication method list must name 'group tacacs+' as the first method because Cisco AAA evaluates method list entries in order and stops at the first success or failure. With only 'local' configured, the router never sends the username and password to the TACACS+ server, so TACACS+ users cannot authenticate. Adding 'group tacacs+' before 'local' still preserves local as a fallback if the TACACS+ server is unreachable, which is exactly the correct fix for this scenario.

Why this answer

The 'aaa authentication login default local' command specifies that the default login authentication method is local, meaning VTY users are authenticated against the local user database. To authenticate via TACACS+, the command must include 'group tacacs+' before 'local' so that TACACS+ is tried first, with local as a fallback. Without this, TACACS+ is never consulted for authentication, even though authorization and accounting are configured for TACACS+.

Exam trap

Cisco often tests the distinction between authentication, authorization, and accounting, and the trap here is that candidates see 'group tacacs+' in the accounting or authorization commands and assume authentication is also covered, when in fact each AAA component must be explicitly configured with the desired method list.

How to eliminate wrong answers

Option B is wrong because 'aaa authorization exec default local' controls what commands or EXEC access a user is allowed after authentication, not the authentication method itself; even if TACACS+ is added here, it does not fix the missing TACACS+ in the authentication login command. Option C is wrong because 'aaa accounting exec default start-stop group tacacs+' already includes TACACS+ for accounting, but accounting only logs actions after authentication; it does not authenticate the user. Option D is wrong because 'privilege level 15' under VTY lines sets the privilege level for authenticated users, but it does not affect the authentication method; the user must first be authenticated via the configured method, which is currently local only.

490
MCQmedium

A network engineer is troubleshooting a performance issue between two hosts connected to a Cisco Catalyst 3850 switch. The engineer wants to capture all traffic sent and received by Host A (Gi1/0/1) and send it to a monitoring station connected to Gi1/0/24. The engineer configures 'monitor session 1 source interface Gi1/0/1 both' and 'monitor session 1 destination interface Gi1/0/24'. However, the monitoring station receives only traffic sent by Host A, not traffic received. What is the most likely cause?

A.The source interface is configured as an access port, and the SPAN session cannot capture both directions on an access port.
B.The destination port is in the same VLAN as the source interface, causing the switch to drop the copied frames due to loop prevention.
C.The 'monitor session 1 destination interface Gi1/0/24' command does not support egress SPAN; only ingress SPAN is allowed.
D.The engineer must also configure 'monitor session 1 filter ip' to capture both directions.
AnswerB

When the SPAN destination port resides in the same VLAN as the source interface, the switch forwards the replicated frames into the same broadcast domain, which can cause a bridging loop. To prevent this, loop prevention mechanisms—typically STP and hardware protections—drop those copied frames, resulting in no traffic arriving at the analyzer. The destination port must be placed in a different VLAN or made a dedicated SPAN destination to avoid this loop-avoidance drop.

Why this answer

The most likely cause is that the destination port (Gi1/0/24) is in the same VLAN as the source interface (Gi1/0/1). When a SPAN destination port resides in the same VLAN as the source, the switch may drop the copied egress frames to prevent a switching loop, because the destination port would otherwise re-inject the traffic back into the same VLAN. This behavior is specific to local SPAN on Catalyst switches, where the destination port must be in a different VLAN or configured as a trunk with only the monitoring VLAN allowed.

Exam trap

Cisco often tests the misconception that SPAN captures all traffic regardless of VLAN membership, but the trap here is that the destination port's VLAN membership can cause the switch to drop egress copies due to loop prevention, even though the configuration appears correct.

How to eliminate wrong answers

Option A is wrong because an access port can be a SPAN source and capture both ingress and egress traffic; the issue is not related to the port mode. Option C is wrong because the 'monitor session destination interface' command supports both ingress and egress SPAN; the problem is not a limitation of egress SPAN. Option D is wrong because no IP filter is required to capture both directions; the 'both' keyword on the source already enables bidirectional capture, and a filter would only restrict traffic, not enable missing direction.

491
MCQeasy

A network administrator must secure management access to a Cisco IOS XE router so that only SSH version 2 is accepted and Telnet is disabled on all VTY lines. Which configuration accomplishes this requirement?

A.Configure line vty 0 4 with the exec-timeout command and set the SSH version to 2.
B.Configure transport input ssh on the VTY lines and set the SSH version to 2 globally.
C.Configure transport input telnet ssh on the VTY lines and set the SSH version to 2.
D.Configure transport output ssh on the VTY lines and set the SSH version to 2.
AnswerB

The transport input ssh command on the VTY lines restricts inbound management sessions to SSH, effectively disabling Telnet. Setting the SSH version to 2 with ip ssh version 2 ensures only the stronger protocol version is negotiated. Together these commands satisfy the requirement to allow only SSHv2 and block Telnet.

Why this answer

Restricting management to SSH requires the transport input ssh command applied to the VTY lines, which removes Telnet as an accepted transport. Enforcing SSH version 2 with ip ssh version 2 ensures the stronger protocol is used. Together they block Telnet and guarantee only SSHv2 sessions are accepted on the router.

Exam trap

The trap here is confusing transport input with transport output; only transport input controls which protocols may connect inbound to the VTY lines.

492
Multi-Selecthard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The router runs OSPF, BGP, SSH management, and NTP. The engineer wants to ensure that OSPF hello packets are always prioritized and that SSH traffic from the management subnet is rate-limited. Which two statements about the CoPP configuration are true? (Choose two.)

Select 2 answers
A.CoPP is applied to individual data plane interfaces using the 'service-policy input' command on each physical interface.
B.CoPP uses a modular QoS CLI policy map applied globally with the 'service-policy' command under control-plane configuration mode.
C.The default CoPP policy that ships with Cisco IOS XE already rate-limits SSH and OSPF traffic without any custom configuration.
D.CoPP policies can differentiate OSPF and SSH traffic by using ACLs referenced in class maps to match specific protocols and source addresses.
E.CoPP can only police traffic; it cannot mark or prioritize specific control plane protocols such as OSPF.
AnswersB, D

CoPP is implemented using MQC constructs where a class map matches control plane traffic and a policy map defines policing actions. The policy map is then applied under the control-plane configuration mode using the service-policy command, which directs the policy to the route processor's traffic rather than to data plane interfaces.

Why this answer

CoPP uses MQC class maps and policy maps applied under control-plane configuration mode. Class maps reference ACLs to distinguish protocols like OSPF and SSH, allowing differentiated policing and prioritization actions. Applying the policy to physical interfaces or assuming default policies meet custom requirements are common misconceptions.

Exam trap

The trap here is confusing CoPP with interface-level QoS by assuming the service-policy is applied to data plane interfaces rather than the control plane.

493
MCQhard

A network engineer is configuring QoS on a Cisco IOS router. The engineer needs to ensure that packets marked with DSCP AF31 are placed into a queue that guarantees at least 30% of the interface bandwidth during congestion, while allowing other traffic to use any remaining bandwidth. Which configuration should be used?

A.policy-map QOS class AF31 shape average percent 30
B.policy-map QOS class AF31 bandwidth remaining percent 30
C.policy-map QOS class AF31 bandwidth percent 30
D.policy-map QOS class AF31 priority percent 30
AnswerC

The 'bandwidth percent 30' command guarantees that the class AF31 receives at least 30% of the interface bandwidth during congestion. This is a CBWFQ configuration that provides a minimum bandwidth guarantee, ensuring that AF31 traffic is prioritized while allowing other classes to use the remaining bandwidth. It directly satisfies the requirement.

Why this answer

The 'bandwidth percent 30' command in a policy map class guarantees that the class receives at least 30% of the interface bandwidth during congestion. This is part of CBWFQ and provides a minimum bandwidth guarantee, meeting the requirement while allowing other traffic to utilize remaining bandwidth.

Exam trap

The trap here is confusing bandwidth guarantee commands like 'bandwidth percent' with priority or shaping commands that limit or prioritize traffic differently.

494
MCQmedium

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router. The router has management SSH access, SNMP monitoring, and BGP peering. After applying the CoPP policy shown in the exhibit, the engineer notices that SNMP polling from the management station fails, while SSH and BGP remain operational. Which action should be taken to restore SNMP polling while maintaining control plane protection?

A.Increase the policer rate for the default class to allow all unmatched traffic, including SNMP.
B.Remove the CoPP policy from the control plane and reapply it after verifying SNMP connectivity.
C.Configure an ACL to permit SNMP traffic and apply it to the management interface instead of the control plane.
D.Add a class-map that matches SNMP traffic (UDP port 161) and include it in the CoPP policy with an appropriate policer rate.
AnswerD

The CoPP policy likely does not have a class-map for SNMP, so SNMP packets fall into the default class and may be dropped by the default policer. Adding a specific class-map for SNMP (UDP 161) with a suitable policer ensures SNMP traffic is permitted at the required rate while still protecting the control plane from excessive SNMP traffic.

Why this answer

CoPP policies must explicitly classify and police all desired control plane traffic. If SNMP is not classified, it falls into the default class, which typically has a low rate and may drop legitimate SNMP. Adding a dedicated class-map for SNMP with an appropriate policer restores connectivity while preserving protection.

Exam trap

The trap here is assuming that increasing the default policer rate or removing CoPP is acceptable, rather than adding the missing classification for SNMP.

495
Matchingmedium

Drag and drop each SD-WAN controller on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Centralized management, monitoring, and GUI dashboard

Control plane policy distribution and OMP route propagation

First point of contact for device authentication and NAT discovery

WAN edge router running Viptela OS

WAN edge router running IOS-XE with SD-WAN features

Why these pairings

vManage provides centralized management and monitoring; vSmart distributes control plane policies and OMP routes; vBond authenticates and orchestrates initial device onboarding and NAT traversal.

496
MCQhard

A network engineer is configuring NAT overload (PAT) on a Cisco router to allow multiple internal hosts to share a single public IP address. The engineer uses the command ip nat inside source list 1 interface GigabitEthernet0/0 overload. After testing, internal hosts can access the internet, but some applications fail intermittently. The engineer suspects a NAT issue. What is the most likely cause?

A.The access list 1 is too permissive and includes the public IP address of the router.
B.The NAT translation table is filling up due to a large number of concurrent sessions, causing new translations to be denied.
C.The router is not configured with ip nat inside on the internal interface.
D.The overload keyword is misspelled or not supported on this IOS version.
AnswerB

With Port Address Translation (PAT), a single public IP can support at most about 65,000 simultaneous translations because each session must use a unique source port (1–65535, minus reserved). When the router's NAT table reaches this limit, it drops new connection attempts, denying translations for additional inside hosts. As existing sessions age out or are cleared, the table frees ports, allowing new connections to succeed, which matches the intermittent failure pattern described. High concurrent sessions—common with web browsing, streaming, or file transfers—can easily fill the table.

Why this answer

NAT overload (PAT) uses a single public IP address and tracks sessions via port numbers. With many internal hosts, the router can exhaust its available port numbers (typically 65,535 per public IP), causing new translations to be denied. This leads to intermittent application failures as some sessions cannot be translated.

Exam trap

Cisco often tests the misconception that NAT overload failures are due to missing interface configurations or ACL issues, when in fact the real problem is port exhaustion from too many concurrent sessions.

How to eliminate wrong answers

Option A is wrong because the access list 1 is used to match internal source addresses, not to filter the public IP; including the public IP would not cause intermittent failures as the router does not translate traffic sourced from its own interface. Option C is wrong because if ip nat inside were missing on the internal interface, no internal hosts would be able to access the internet at all, not just intermittently. Option D is wrong because the overload keyword is correctly spelled and supported on all modern IOS versions that support NAT; a misspelling would cause a syntax error, not intermittent failures.

497
MCQhard

A network security engineer is configuring 802.1X on a Cisco Catalyst switch with Cisco ISE as the RADIUS server. The switch is configured with 'dot1x system-auth-control' and the interface is set to 'authentication port-control auto'. The engineer wants to allow a printer that does not support 802.1X to connect to the network by using MAC Authentication Bypass (MAB). Which additional configuration is required on the switch interface to enable MAB?

A.Configure 'authentication host-mode multi-auth' under the interface configuration mode.
B.Configure 'mab' under the interface configuration mode.
C.Configure 'dot1x pae authenticator' under the interface configuration mode.
D.Configure 'authentication order dot1x mab' under the interface configuration mode.
AnswerB

MAB is enabled on an interface with the 'mab' command in interface configuration mode. This allows the switch to use the device's MAC address as the username and password for RADIUS authentication when 802.1X times out. It is the standard method to support non-802.1X devices like printers. The other commands do not enable MAB.

Why this answer

MAC Authentication Bypass (MAB) is enabled on a switch interface with the 'mab' command. This allows the switch to use the connecting device's MAC address as credentials for RADIUS authentication when 802.1X is not supported. The other commands either control host mode, set the authenticator role, or define authentication order, but none enable MAB.

Exam trap

The trap here is confusing commands that define authentication order or host mode with the command that actually enables MAB functionality.

498
MCQmedium

A network engineer is configuring VXLAN on a Cisco Nexus 9000 series switch. The underlay network is a routed Layer 3 network using OSPF. The engineer needs to ensure that the VXLAN tunnel endpoint (VTEP) IP addresses are reachable across the underlay. Which statement describes the correct configuration for the VTEP source interface?

A.The VTEP source interface must be a VLAN interface (SVI) on the switch, and the VLAN must be allowed on all trunk links.
B.The VTEP source interface must be a loopback interface with an IP address advertised into the underlay routing protocol.
C.The VTEP source interface must be a subinterface configured with 802.1Q encapsulation.
D.The VTEP source interface must be a physical interface that is directly connected to the underlay network.
AnswerB

Using a loopback interface as the VTEP source ensures high availability because it remains up as long as any path to the underlay exists. Advertising the loopback IP into OSPF makes it reachable by remote VTEPs, enabling VXLAN tunnels to form. This is the recommended design for VXLAN in Cisco Nexus environments.

Why this answer

For VXLAN, the VTEP source interface should be a loopback interface with an IP address advertised into the underlay routing protocol. This ensures that the VTEP IP remains reachable even if a physical link fails, providing redundancy. The underlay network must route the loopback IP so that remote VTEPs can establish VXLAN tunnels.

Exam trap

The trap here is assuming that any interface with an IP address can serve as the VTEP source, but the best practice is to use a loopback for stability and redundancy.

499
Matchingmedium

Drag and drop each EtherChannel port state on the left to its matching description on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Port is actively forwarding traffic in the EtherChannel

Port is active but not part of any EtherChannel

Port is administratively down or error-disabled in the channel

Why these pairings

In EtherChannel, ports can be in one of three states: bundled, stand-alone, or suspended. A bundled port actively forwards traffic in the channel. A stand-alone port is active but not part of any EtherChannel.

A suspended port is administratively down or error-disabled. The remaining options are distractors that do not match any of these states.

500
Multi-Selectmedium

A network engineer is comparing YANG models used in Cisco IOS XE automation. The engineer needs to distinguish between standard IETF YANG models and Cisco-specific YANG models. Which two statements accurately describe these YANG model types? (Choose two.)

Select 2 answers
A.IETF YANG models can only be used with NETCONF, while Cisco-specific models can only be used with RESTCONF.
B.Cisco-specific YANG models are always required to configure any feature on Cisco IOS XE devices.
C.Cisco-specific YANG models are defined in RFCs and are open standards maintained by the IETF.
D.Cisco-specific YANG models often use a namespace that includes 'cisco' and are tailored to expose Cisco IOS XE features.
E.IETF YANG models are vendor-neutral and defined in RFCs, allowing consistent configuration across multi-vendor environments.
AnswersD, E

Cisco-specific YANG models typically have a namespace URI containing 'cisco.com' and are designed to expose Cisco IOS XE-specific features and operational data. They complement standard models by providing access to proprietary functionality. For example, Cisco-IOS-XE-native is a common model for native configuration. This statement accurately describes their naming and purpose.

Why this answer

IETF YANG models are vendor-neutral standards from the IETF, enabling multi-vendor consistency. Cisco-specific models have namespaces indicating Cisco and expose IOS XE features. Both can be used over NETCONF or RESTCONF.

The other statements are false: Cisco models are not always required, not limited to RESTCONF, and not IETF standards.

Exam trap

The trap here is assuming Cisco-specific models are always needed or that model type dictates the protocol, when in fact standard models can be used and both protocols support any YANG model.

501
MCQhard

A network administrator is using Cisco DNA Center Assurance to monitor a campus network. The administrator notices that a particular client device is experiencing intermittent connectivity drops. The administrator wants to view the historical trend of the client's connectivity and identify the root cause. Which Cisco DNA Center Assurance feature should the administrator use?

A.Client 360
B.Application Health dashboard
C.Path Trace
D.Network Health dashboard
AnswerA

Client 360 in Cisco DNA Center Assurance provides a comprehensive view of a specific client's connectivity, including historical trends, onboarding information, and detailed event timeline. It allows the administrator to drill down into the client's connectivity issues, view past sessions, and identify root causes such as authentication failures or RF problems. This is the correct tool for troubleshooting a single client's intermittent drops.

Why this answer

Client 360 is the Cisco DNA Center Assurance feature designed to provide detailed, historical, and real-time information about a specific client device. It includes connectivity trends, event timelines, and root cause analysis for client issues. The Network Health dashboard, Application Health dashboard, and Path Trace serve different purposes: overall network health, application performance, and flow path analysis, respectively.

Therefore, Client 360 is the correct choice for troubleshooting intermittent connectivity of a single client.

Exam trap

The trap here is confusing Client 360 with Path Trace; Path Trace is for flow analysis, while Client 360 is for client-centric historical troubleshooting.

502
MCQhard

An engineer is troubleshooting a connectivity issue between two switches, SW1 and SW2, connected via a trunk. The trunk is configured with switchport mode trunk on both sides. The engineer notices that some VLANs are not passing traffic, even though they are in the allowed list. The output of 'show interfaces trunk' on SW1 shows that VLANs 10, 20, and 30 are in the allowed list and are active. However, hosts in VLAN 30 cannot reach the distribution switch. What is the most likely cause?

A.VLAN 30 is not created in the VLAN database on SW2.
B.The native VLAN is mismatched between SW1 and SW2.
C.VTP pruning is removing VLAN 30 from the trunk.
D.The trunk is not forming due to DTP negotiation.
AnswerA

VLAN 30 is not created in the VLAN database on SW2. A trunk link will forward frames for a VLAN only if that VLAN exists in the local VLAN database of the switch; otherwise the switch drops the frames as ingress/egress filtering prevents unknown VLANs from crossing the trunk. Even though SW1 has VLAN 30 configured and the allowed list on SW2 may include VLAN 30 by default, SW2 cannot pass frames for a VLAN it does not know. Creating VLAN 30 on SW2 (or using VTP to propagate it) is required for end-to-end connectivity.

Why this answer

VLAN 30 must exist in the VLAN database on both switches for traffic to be forwarded across the trunk. Even if VLAN 30 is in the allowed list and active on SW1, if it has not been created on SW2, SW2 will discard frames tagged with VLAN 30 because it has no VLAN 30 interface or forwarding table entry. This is a common misconfiguration where the VLAN is allowed on the trunk but not present on the remote switch.

Exam trap

Cisco often tests the misconception that being in the allowed list on the trunk is sufficient for traffic to pass, when in fact the VLAN must be created in the VLAN database on both ends of the trunk.

How to eliminate wrong answers

Option B is wrong because a native VLAN mismatch would cause issues with untagged frames, not with tagged VLAN 30 traffic, and the trunk is already up. Option C is wrong because VTP pruning would remove VLAN 30 from the allowed list on the trunk, but the output shows VLAN 30 is still in the allowed list and active on SW1. Option D is wrong because the trunk is already formed (switchport mode trunk on both sides disables DTP negotiation), so the trunk is up and the issue is with VLAN 30 specifically.

503
Matchingmedium

Drag and drop each Netmiko device type on the left to its matching OS on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Cisco IOS

Cisco NX-OS

Cisco IOS-XR

Cisco IOS-XE

Cisco ASA

Why these pairings

cisco_ios maps to IOS, cisco_nxos to NX-OS, cisco_xr to IOS-XR, and cisco_xe to IOS-XE. The fifth pair cisco_asa maps to ASA.

504
MCQmedium

An architect is designing an SD-WAN policy to ensure that real-time video traffic from headquarters to branch offices is always sent over the most reliable transport, while all other traffic uses the least-cost path. Which type of policy should be used to achieve this?

A.Localized data policy applied on the vEdge router.
B.Centralized data policy configured on vSmart.
C.Centralized control policy for route manipulation.
D.Localized app-route policy on the branch vEdge.
AnswerB

Centralized data policy on vSmart is the only mechanism that combines application identification (via DPI or NBAR) with real-time SLA metrics (loss, latency, jitter) to dynamically steer traffic over the best overlay tunnel. The policy is defined centrally on vSmart and then distributed to vEdge routers as part of the OMP route and policy updates, allowing network-wide, consistent forwarding decisions. This makes it the correct solution for application-aware path selection based on live link conditions.

Why this answer

A centralized data policy configured on vSmart is correct because it allows the SD-WAN controller to enforce application-aware routing decisions across the fabric. By matching real-time video traffic and steering it over the transport with the highest loss/reachability metrics (most reliable), while using a separate rule to direct all other traffic over the least-cost path, the policy is applied globally from the vSmart controller without requiring per-router configuration.

Exam trap

Cisco often tests the distinction between control policies (which manipulate routing information) and data policies (which manipulate packet forwarding), and the trap here is that candidates confuse centralized control policy with centralized data policy, thinking route manipulation can achieve application-based path selection when it cannot.

How to eliminate wrong answers

Option A is wrong because a localized data policy on the vEdge router can only influence local forwarding decisions and cannot enforce a consistent, fabric-wide policy that distinguishes real-time video from other traffic based on centralized application recognition. Option C is wrong because a centralized control policy manipulates route prefixes and OMP routes (e.g., TLOC preferences) to influence path selection at the control plane, not to apply per-packet application-based forwarding rules like steering video over the most reliable transport. Option D is wrong because a localized app-route policy on the branch vEdge is used for local per-tunnel load balancing or failover based on SLA metrics, but it cannot implement a global policy that differentiates real-time video from other traffic across all sites; it is also not designed to enforce a least-cost path for all other traffic.

505
Multi-Selecthard

A network engineer is implementing VXLAN with Cisco SD-Access. The engineer must ensure that the underlay network provides the necessary transport for VXLAN traffic. Which two statements about VXLAN and its underlay are true? (Choose two.)

Select 2 answers
A.VXLAN uses a 24-bit VNID, allowing over 16 million unique segments.
B.VXLAN tunnels are established between VTEPs, which can be physical or virtual switches.
C.VXLAN requires the underlay to be a Layer 2 network with STP.
D.VXLAN uses a 12-bit VNID, similar to VLAN IDs.
E.VXLAN requires a multicast-enabled underlay for BUM traffic replication.
AnswersA, B

VXLAN encapsulates Layer 2 frames in UDP and uses a 24-bit VXLAN Network Identifier (VNID), which provides up to 16,777,216 unique segments. This scalability is a key advantage over VLANs, which are limited to 4094. The large VNID space supports multi-tenant data centers and large-scale segmentation in SD-Access.

Why this answer

VXLAN uses a 24-bit VNID for large-scale segmentation and relies on VTEPs to encapsulate traffic. The underlay is typically Layer 3, not Layer 2, and BUM traffic can be handled via multicast or unicast control-plane replication. The two correct statements are the 24-bit VNID and the role of VTEPs.

Exam trap

The trap here is assuming VXLAN requires multicast or a Layer 2 underlay, when in fact modern implementations use unicast replication over a Layer 3 underlay.

506
Matchingmedium

Drag and drop each STP variant on the left to its matching IEEE standard on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

IEEE 802.1D

IEEE 802.1w

IEEE 802.1s

Cisco proprietary per-VLAN spanning tree

Why these pairings

STP is 802.1D; RSTP is 802.1w; MSTP is 802.1s; PVST+ is a Cisco proprietary extension of 802.1D.

507
Multi-Selecthard

Which two statements about BGP route selection are true? (Choose two.)

Select 2 answers
A.A route with a higher LOCAL_PREF is preferred over a route with a lower LOCAL_PREF.
B.A route learned via eBGP is preferred over a route learned via iBGP, all else being equal.
C.A route with a longer AS_PATH is preferred over a route with a shorter AS_PATH.
D.The MED attribute is always compared regardless of the AS of the neighbor.
E.The IGP metric to the next hop is the first criterion in BGP path selection.
AnswersA, B

LOCAL_PREF is evaluated early in the BGP best-path algorithm, before AS_PATH and origin. A higher value signals local preference, so the route with the greater LOCAL_PREF wins, directly satisfying the statement about preference ordering between competing paths.

Why this answer

Option A is correct because LOCAL_PREF is evaluated early in the BGP best-path algorithm (after weight and before AS_PATH), and a higher LOCAL_PREF value is always preferred over a lower one. Option B is correct because, all other attributes being equal, eBGP-learned routes are preferred over iBGP-learned routes, since eBGP routes are considered more trustworthy and are evaluated before the IGP metric tiebreaker. Option C is incorrect because BGP prefers the shorter AS_PATH, not the longer one, to minimize the number of autonomous systems traversed.

Option D is incorrect because MED is only compared between routes from the same neighboring AS by default (unless bgp always-compare-med is configured). Option E is incorrect because the IGP metric to the next hop is one of the last tiebreakers in the BGP path selection process, not the first criterion.

508
MCQmedium

An engineer must secure the management plane of a Cisco IOS XE router so that only SSH version 2 is accepted for remote administration, while Telnet and SSHv1 are rejected. Which set of commands accomplishes this?

A.ip ssh server algorithm encryption aes128-ctr aes256-ctr line vty 0 4 transport input all
B.line vty 0 4 transport input telnet ssh ip ssh version 2
C.line vty 0 4 transport input ssh ip ssh version 2
D.line vty 0 4 transport input ssh no ip ssh version 1
AnswerC

The transport input ssh command restricts VTY lines to SSH only, blocking Telnet, while ip ssh version 2 forces the router to negotiate only SSHv2 sessions. Together they satisfy both requirements. This is the canonical method on Cisco IOS XE for enforcing SSHv2-only management access.

Why this answer

Restricting VTY lines with 'transport input ssh' eliminates Telnet access, and 'ip ssh version 2' forces the SSH server to negotiate only version 2. Used together under the correct configuration modes, they enforce SSHv2-only remote management. Other combinations either leave Telnet enabled, use invalid syntax, or fail to restrict the transport protocol.

Exam trap

The trap here is believing that disabling SSHv1 requires a 'no' form command, when the correct approach is to explicitly set 'ip ssh version 2'.

509
Multi-Selectmedium

A company has a requirement to provide redundancy for the default gateway on a subnet. Two switches are configured with HSRP. Which requirement must be met for the interfaces on the switches to form the HSRP group?

Select 1 answer
A.The interfaces must be on the same physical switch.
B.The interfaces must be Layer 2 switchports.
C.The interfaces must have the same IP address.
D.The interfaces must be in the same VLAN.
AnswersD

HSRP requires all participants to be in the same Layer 2 broadcast domain because hello messages are multicast onto the local VLAN. The multicast destination is 224.0.0.2 (HSRPv1) or 224.0.0.102 (HSRPv2) with a TTL of 1; if the interfaces reside in different VLANs, the broadcast domains are isolated, so the hellos never reach the peer and no HSRP adjacency forms. The virtual IP must also belong to the same IP subnet as the real interface IPs, and that subnet maps to exactly one VLAN; different VLANs imply different subnets and break the redundant gateway function.

Why this answer

HSRP is a First Hop Redundancy Protocol that provides a virtual gateway for hosts. To form an HSRP group, the participating interfaces must be Layer 3 interfaces (either SVIs on switches or routed ports on multilayer switches) that are configured with IP addresses and belong to the same VLAN. Option B is incorrect because HSRP does not run on Layer 2 switchports; those ports do not have IP addresses and cannot send HSRP messages.

Option D is correct because being in the same VLAN ensures the switches share the same broadcast domain, allowing HSRP multicast hello messages to reach each other.

Exam trap

A common misconception is that HSRP interfaces must be Layer 2 switchports. In reality, HSRP requires Layer 3 interfaces (SVIs or routed ports) that are in the same VLAN to exchange multicast hellos and maintain the virtual IP and MAC address.

510
MCQhard

An enterprise uses VRF-lite on a Cisco Catalyst 9300 to isolate a guest network (VRF GUEST) from the corporate network (VRF CORP). The guest network uses DHCP from a server in the corporate network. The engineer configures a DHCP relay on the guest SVI pointing to the corporate DHCP server. The DHCP server is in VRF CORP. The guest clients are not receiving IP addresses. What is the issue?

A.The DHCP relay agent is not configured to use the VRF GUEST; the ip helper-address command must be applied under the VRF interface, but the DHCP server is in a different VRF, requiring inter-VRF routing or the use of the ip dhcp relay information option.
B.The DHCP server is in a different VRF, and the switch does not have a route from the GUEST VRF to the CORP VRF for the DHCP server.
C.The DHCP server is not configured with a scope for the guest subnet.
D.The guest VRF is missing the ip dhcp relay command globally.
AnswerB

When the DHCP relay agent receives a broadcast on an interface in the GUEST VRF, it generates a unicast DHCP request to the server address specified by ip helper-address, but it consults the GUEST VRF routing table to determine the egress interface and next hop. Because the DHCP server resides in the CORP VRF, the GUEST VRF routing table does not have a route to that server IP, so the relay packet is silently dropped. A route leak or a static route from the GUEST VRF to the CORP VRF (and back) is required to allow the unicast relay traffic to span the VRFs.

Why this answer

The DHCP server resides in VRF CORP, but the DHCP relay agent on the guest SVI forwards the discover packet within VRF GUEST. Without a route from VRF GUEST to the DHCP server's subnet in VRF CORP, the relayed packet cannot reach the server. Inter-VRF routing (e.g., a route leak or VRF-aware service) is required for the relay to forward the packet across VRFs.

Exam trap

Cisco often tests the misconception that configuring ip helper-address alone is sufficient for DHCP relay across VRFs, ignoring the need for inter-VRF reachability or route leaking.

How to eliminate wrong answers

Option A is wrong because the ip helper-address command is correctly applied under the guest SVI (which is in VRF GUEST), and the issue is not about the relay information option (option 82) but about the lack of a route between VRFs. Option C is wrong because the DHCP server may have a scope for the guest subnet, but the packet never reaches the server due to the routing issue, so the scope configuration is irrelevant. Option D is wrong because there is no global ip dhcp relay command in Cisco IOS; DHCP relay is enabled per interface with ip helper-address, and the VRF is inherited from the SVI.

511
MCQmedium

A network engineer configures IP SLA 60 to monitor the jitter of a VoIP call path between two sites. The operation uses UDP jitter with a target of 192.168.3.3 on port 16384. The engineer notices that the IP SLA operation shows 'State: Active' and 'Latest RTT: 10 ms', but the jitter values are all zero. The remote router has an IP SLA responder configured. What is the most likely cause?

A.The IP SLA operation is configured with a 'num-packets' value of 1, so only one packet is sent per probe, and jitter cannot be calculated.
B.The remote router's IP SLA responder is not configured to calculate jitter, only to echo packets.
C.The IP SLA operation is using a 'frequency' that is too high, causing the probes to be sent too quickly and jitter to be zero.
D.The network path has no variable delay, so jitter is naturally zero.
AnswerA

This is the correct diagnosis. For the IP SLA UDP jitter operation (type 'udp-jitter'), the source router sends a burst of packets per probe—by default 10—and measures the inter-arrival time differences among the returned packets to compute jitter. If the engineer set the 'num-packets' parameter to 1, only a single packet is sent per probe, so there are no two consecutive packets from which to calculate delay variation. The result is that jitter is reported as zero, not because the network has no variation, but because the probe lacks the required packet pair.

Why this answer

UDP jitter requires multiple packets per probe to measure inter-packet delay variation. If 'num-packets' is set to 1, only a single packet is sent, so there are no successive packet pairs from which jitter can be calculated. The 'Latest RTT: 10 ms' indicates the single packet was echoed, but with only one packet, jitter values remain zero.

Exam trap

Cisco often tests the misconception that jitter is derived from RTT or that a single packet can provide jitter statistics, when in fact jitter requires multiple packets per probe to compute delay variation.

How to eliminate wrong answers

Option B is wrong because the IP SLA responder is correctly configured (as stated) and does not need special jitter calculation—it simply echoes packets; the jitter calculation is performed by the initiator based on multiple packets. Option C is wrong because a high frequency (short interval between probes) does not cause jitter to be zero; it might increase jitter or cause packet loss, but it does not eliminate the ability to calculate jitter. Option D is wrong because while a zero-variable-delay path would yield zero jitter, the scenario explicitly states jitter values are all zero, which is highly unlikely in a real VoIP path; the more plausible explanation is a configuration issue with packet count.

512
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP server for a subnet. The engineer wants to exclude a range of addresses from being assigned dynamically. Which command should be used?

A.ip dhcp pool
B.ip dhcp snooping
C.ip dhcp excluded-address
D.ip dhcp relay information
AnswerC

The 'ip dhcp excluded-address' command is used to specify a range of IP addresses that the DHCP server should not assign to clients. This is typically used for addresses that are statically assigned to servers, printers, or other network devices. It ensures that the DHCP server does not hand out these addresses, preventing conflicts.

Why this answer

The 'ip dhcp excluded-address' command is specifically designed to prevent the DHCP server from assigning certain IP addresses. The other commands serve different purposes: creating a pool, enabling snooping, or configuring relay information. Thus, 'ip dhcp excluded-address' is the correct choice.

Exam trap

The trap here is confusing the DHCP pool configuration with address exclusion, when exclusion is configured globally, not within the pool.

513
Multi-Selecthard

Which three statements about NFV MANO (Management and Orchestration) are true? (Choose three.)

Select 3 answers
A.The NFV Orchestrator (NFVO) is responsible for network service orchestration and resource orchestration across multiple VIMs.
B.The VNF Manager (VNFM) handles lifecycle management of VNF instances, including instantiation, scaling, and termination.
C.The Virtualized Infrastructure Manager (VIM) controls and manages the NFVI compute, storage, and network resources.
D.OSS/BSS systems are part of the NFV MANO framework and directly manage VNF instances.
E.The NFVO directly manages the hypervisor layer to allocate virtual resources to VNFs.
AnswersA, B, C

The NFVO performs both network service orchestration and resource orchestration, coordinating across multiple VIMs. This cross-domain scope distinguishes it from the VNFM, which manages individual VNF instances rather than end-to-end services spanning several virtualised infrastructures.

Why this answer

Option A is correct because the NFV Orchestrator (NFVO) performs network service orchestration (composing VNFs into network services via NSDs/VNF Forwarding Graphs) and resource orchestration, coordinating resource requests across one or more VIMs in the NFVI. Option B is correct because the VNF Manager (VNFM) is responsible for the lifecycle management of VNF instances, including instantiation, scaling, updating, healing, and termination, as defined in ETSI NFV MANO. Option C is correct because the Virtualized Infrastructure Manager (VIM) controls and manages the NFVI compute, storage, and network resources, typically exposing them through APIs such as OpenStack Nova, Cinder, and Neutron.

Option D is not correct because OSS/BSS are external systems that interact with NFV MANO (mainly through the NFVO's Os-Ma-nfvo reference point) but are not themselves part of the MANO framework and do not directly manage VNF instances. Option E is not correct because the NFVO does not directly manage the hypervisor layer; resource allocation in the NFVI is performed by the VIM, with the NFVO issuing resource-orchestration requests rather than hypervisor-level commands.

Exam trap

350-401 often tests the boundaries between MANO components, and candidates may incorrectly assign hypervisor management to NFVO instead of VIM, or include OSS/BSS as part of MANO.

514
Multi-Selectmedium

A network security team is deploying MACsec on a Cisco Catalyst 9000 switch series to secure Layer 2 traffic between two switches. Which two statements about MACsec operation are true? (Choose two.)

Select 2 answers
A.MACsec encrypts the entire Ethernet frame including the source and destination MAC addresses.
B.MACsec uses MKA (MACsec Key Agreement) to negotiate session keys between peers.
C.MACsec provides hop-by-hop encryption using the GCM-AES-128 cipher suite.
D.MACsec requires the use of IKEv2 to establish the secure channel between switches.
E.MACsec can only be deployed on routed interfaces, not on switchports.
AnswersB, C

MKA is a protocol defined in IEEE 802.1X-2010 that handles key agreement for MACsec. It elects a key server, distributes secure association keys (SAKs), and manages key rotation. On Cisco switches, MKA must be enabled with a pre-shared key or 802.1X-derived CAK. This statement correctly describes how MACsec establishes and maintains cryptographic keys between peers.

Why this answer

MACsec is an IEEE 802.1AE standard that provides hop-by-hop encryption and integrity on Ethernet links. It uses GCM-AES-128 for encryption and MKA for key agreement. It does not encrypt MAC addresses, and it does not use IKEv2.

It is deployed on switchports, not routed interfaces. Therefore, the two true statements are that it provides hop-by-hop encryption with GCM-AES-128 and that it uses MKA to negotiate session keys.

Exam trap

The trap here is confusing MACsec with IPsec by assuming it uses IKEv2 or encrypts the entire frame including MAC addresses, when it actually uses MKA and leaves MAC addresses in clear text.

515
Multi-Selectmedium

Which two statements about telemetry subscription types in model-driven telemetry are true? (Choose two.)

Select 2 answers
A.In a dial-in subscription, the network device initiates the connection to the telemetry collector.
B.In a dial-out subscription, the network device pushes telemetry data to a configured collector.
C.On-change subscriptions stream data at a regular, user-defined cadence.
D.Periodic subscriptions stream data at a fixed interval, which is defined by the sample-interval parameter.
E.Dial-out subscriptions are less scalable than dial-in subscriptions because each device must manage its own connections.
AnswersB, D

Dial-out subscriptions invert the usual model: the router or switch initiates the session and pushes telemetry to a preconfigured collector, rather than awaiting a receiver's request. This matches the stem's requirement for a true statement about subscription types.

Why this answer

Option B is correct because in a dial-out (also called push) subscription the network device itself initiates the session and pushes telemetry data to a preconfigured collector address, rather than waiting for the collector to connect. Option D is correct because periodic subscriptions send updates at a fixed, user-defined interval controlled by the sample-interval parameter, delivering data continuously regardless of whether values changed. Option A is incorrect because in a dial-in subscription it is the collector (receiver) that initiates the connection to the device, not the device.

Option C is incorrect because on-change subscriptions stream data only when a monitored value changes, not at a regular cadence. Option E is incorrect because dial-out is generally considered more scalable for large deployments, since the collector passively receives streams and does not have to poll or maintain a session per device.

Exam trap

350-401 often tests the direction of connection initiation in dial-in vs. dial-out, where candidates might confuse which side initiates the connection.

516
MCQeasy

A network engineer is new to automation and wants to use a Python library that provides a simple, high-level interface for interacting with network devices, including Cisco IOS XE, without dealing with low-level SSH or NETCONF details. The engineer needs to quickly script configuration changes and command execution. Which Python library is best suited for this requirement?

A.Requests
B.Ncclient
C.Netmiko
D.Paramiko
AnswerC

Netmiko is a Python library built on top of Paramiko that simplifies SSH connections to network devices. It handles device-specific prompts, paging, and other nuances, allowing engineers to send configuration commands and retrieve output easily. It supports Cisco IOS XE and many other vendors. For a beginner needing a high-level interface without dealing with low-level details, Netmiko is ideal. It abstracts the complexities of SSH and device interaction.

Why this answer

Netmiko is designed to simplify SSH-based interactions with network devices. It provides a high-level, consistent interface across multiple vendors, handling device-specific behaviors like prompt detection and output paging. For a network engineer new to automation who needs to quickly script configuration changes and command execution on Cisco IOS XE, Netmiko is the most appropriate choice.

It reduces the complexity of low-level SSH libraries.

Exam trap

The trap here is selecting Paramiko because it is a common SSH library, but it lacks the high-level abstractions that Netmiko provides for network devices.

517
MCQmedium

Given this configuration on a Cisco IOS-XE router: crypto ikev2 keyring KEYRING peer SPOKE1 address 192.168.2.1 pre-shared-key cisco123 ! crypto ikev2 profile IKEV2_PROF match identity remote address 192.168.2.1 255.255.255.255 authentication remote pre-share authentication local pre-share keyring KEYRING ! What is missing from this configuration for a successful IKEv2 tunnel to the peer at 192.168.2.1?

A.The configuration is complete; no additional commands are needed.
B.The profile is missing the 'set transform-set' command to specify the IPsec transform set.
C.The IKEv2 proposal and policy are not defined and must be referenced by the profile or the IPsec profile.
D.The keyring must use a different name to match the profile.
AnswerC

IKEv2 requires a proposal (encryption, integrity, DH group) and a policy to associate the proposal with the profile. Without these, the IKEv2 negotiation will fail.

Why this answer

The configuration is missing an IKEv2 proposal and an IKEv2 policy, which define the encryption, integrity, and DH group parameters for the IKEv2 SA. The profile must reference these via the 'proposal' command under the IKEv2 proposal or the 'match proposal' command under the IKEv2 policy; without them, the router has no agreed-upon parameters to negotiate with the peer, so the tunnel cannot be established.

Exam trap

Cisco often tests the distinction between IKEv1 and IKEv2 configuration requirements, and the trap here is that candidates assume an IKEv2 profile alone is sufficient, forgetting that IKEv2 still requires explicit proposal and policy definitions.

How to eliminate wrong answers

Option A is wrong because the configuration lacks the mandatory IKEv2 proposal and policy definitions, which are required for IKEv2 SA negotiation. Option B is wrong because the 'set transform-set' command belongs to an IPsec profile (crypto ipsec profile), not an IKEv2 profile; the IKEv2 profile handles authentication and key exchange, not IPsec transforms. Option D is wrong because the keyring name must match the one referenced in the profile (KEYRING), and it does; there is no requirement for a different name.

518
MCQmedium

A network engineer is troubleshooting a Cisco Nexus 9000 switch configured with VXLAN EVPN. The engineer notices that the switch is not advertising EVPN routes for a specific VNI. The NVE interface is up, and the VNI is configured. Which action should the engineer take to verify that the VNI is properly associated with the EVPN control plane?

A.Check the output of 'show bgp l2vpn evpn' to see if the VNI is advertised in the EVPN address family.
B.Check the output of 'show vlan id 10' to see if VLAN 10 is active and mapped to the VNI.
C.Check the output of 'show interface nve1' to verify that the NVE interface is operational.
D.Check the output of 'show nve vni' to see if the VNI is up and associated with the NVE interface.
AnswerA

The 'show bgp l2vpn evpn' command displays the EVPN routes in the BGP table, including Type-2 and Type-3 routes for MAC and IMET. By checking this output, the engineer can verify whether the VNI is being advertised. If the VNI is not present, it indicates a configuration issue with the EVPN control plane, such as missing VNI configuration under the EVPN address family or BGP neighbor issues.

Why this answer

To verify that a VNI is properly associated with the EVPN control plane, the engineer should check the BGP EVPN table using 'show bgp l2vpn evpn'. This command displays EVPN routes, including those for the VNI. If the VNI is not advertised, it indicates a configuration issue in the EVPN address family or BGP.

Other commands like 'show nve vni' or 'show interface nve1' do not directly show EVPN route advertisement.

Exam trap

The trap here is focusing on NVE interface or VNI status commands, which show data plane information, rather than checking the BGP EVPN table, which is the control plane for EVPN route advertisement.

519
MCQhard

A network engineer is configuring model-driven telemetry on a Cisco IOS-XE device that is part of a DNA Center managed fabric. The telemetry subscription configuration is: telemetry ietf subscription 101 encoding encode-kvgpb filter xpath /process-cpu-ios-xe-oper:cpu-usage/cpu-utilization stream yang-push update-policy periodic 500 receiver ip address 10.10.10.10 port 5555 protocol grpc-tcp What is the purpose of the 'encoding encode-kvgpb' line?

A.It sets the encoding to JSON format for the telemetry data.
B.It specifies that the data should be encoded using Google Protocol Buffers (protobuf) with key-value pairs.
C.It enables encryption of the telemetry data.
D.It defines the compression algorithm for the telemetry stream.
AnswerB

The `encode-kvgpb` setting selects key-value Google Protocol Buffers encoding, compacting the YANG-modelled CPU telemetry into a schema-driven binary format. This satisfies the subscription's requirement to stream efficiently to the gRPC receiver at 10.10.10.10:5555, since protobuf serialisation is far smaller than JSON or XML payloads over the same periodic 500-centisecond interval.

Why this answer

The 'encoding encode-kvgpb' line specifies that telemetry data should be encoded using Google Protocol Buffers (protobuf) in a key-value format. KV-GPB (Key-Value Google Protocol Buffers) is a compact, efficient encoding used for streaming telemetry data to a receiver, and it is the standard encoding for gRPC-based telemetry subscriptions on IOS-XE.

Exam trap

The trap is assuming 'encode-kvgpb' relates to encryption or compression because of the unfamiliar acronym — candidates must recognise that 'kvgpb' stands for Key-Value Google Protocol Buffers, a serialisation format, not a security or compression feature.

How to eliminate wrong answers

Option A is wrong because JSON encoding would be specified with 'encoding encode-json', not 'encode-kvgpb'. Option C is wrong because encryption is handled by the transport protocol (e.g., gRPC over TLS), not by the encoding directive — 'encode-kvgpb' only defines the data serialisation format. Option D is wrong because compression is not controlled by the encoding line; the encoding defines the serialisation format, not any compression algorithm.

520
MCQeasy

A network administrator is configuring a Cisco IOS router to participate in a First Hop Redundancy Protocol group. The requirement is that the group must use a virtual MAC address of 0000.0c07.acXX and support only IPv4. Which protocol should the administrator configure?

A.Hot Standby Router Protocol (HSRP) version 1
B.HSRP version 2
C.Virtual Router Redundancy Protocol (VRRP) version 2
D.Gateway Load Balancing Protocol (GLBP)
AnswerA

HSRP version 1 uses the virtual MAC address 0000.0c07.acXX, where XX is the group number in hexadecimal, and it supports only IPv4. Configuring HSRPv1 with the standby command and a group number satisfies both requirements, making it the correct choice for this scenario.

Why this answer

HSRP version 1 is the only protocol listed that uses the virtual MAC address 0000.0c07.acXX and supports IPv4 only. VRRPv2 uses a different MAC prefix, GLBP uses 0007.b400.XXYY, and HSRPv2 uses 0000.0c9f.fXXX. The administrator should configure HSRPv1 to meet the exact virtual MAC and IPv4-only requirements.

Exam trap

The trap here is assuming that any FHRP will work because they all provide gateway redundancy, when the specific virtual MAC address format and IPv4-only limitation uniquely identify HSRP version 1.

521
MCQhard

A network engineer is troubleshooting a Cisco SD-WAN deployment where a branch site is experiencing intermittent connectivity to the data center. The engineer suspects that the issue is related to the Bidirectional Forwarding Detection (BFD) configuration on the WAN Edge routers. Which Cisco SD-WAN component is responsible for establishing BFD sessions between WAN Edge routers?

A.WAN Edge routers
B.vSmart
C.vBond
D.vManage
AnswerA

WAN Edge routers are responsible for establishing BFD sessions with each other. BFD is used to detect link failures and measure quality metrics such as latency, jitter, and packet loss. These sessions are established over the data plane, typically over IPsec tunnels or direct links. The WAN Edge routers send BFD packets periodically and use the results to make routing decisions. Therefore, they are the component that establishes and maintains BFD sessions.

Why this answer

In Cisco SD-WAN, BFD sessions are established between WAN Edge routers to monitor the health of the data plane tunnels. These sessions are used to detect failures and measure performance metrics. The WAN Edge routers are responsible for sending and receiving BFD packets.

The other components (vManage, vBond, vSmart) are part of the management, orchestration, and control planes and do not establish BFD sessions. Thus, the WAN Edge routers are the correct answer.

Exam trap

The trap here is assuming that the control plane component vSmart establishes BFD sessions because it manages routing; actually, BFD is a data plane function handled by WAN Edge routers.

522
MCQmedium

A network engineer runs the following command on switch SW7: SW7# show authentication registrations Authentication Method Registrations: Method Priority Type dot1x 10 Interface mab 20 Interface webauth 30 Interface Based on this output, what can be concluded?

A.The switch will try MAB before 802.1X.
B.The switch will try 802.1X first, then MAB, then web authentication.
C.Web authentication is the primary method.
D.Only 802.1X is registered.
AnswerB

This is correct. On Cisco Catalyst switches, the default authentication method order is determined by the priority values: dot1x (10), mab (20), and webauth (30). The switch first attempts 802.1X to authenticate the supplicant; if that fails or times out, it falls back to MAC authentication bypass (MAB). If MAB also fails or is not applicable, the switch then falls back to web authentication as the final method. This ordering ensures the most secure method is attempted first, with less secure methods as fallbacks.

Why this answer

The command output shows authentication methods registered with their priorities. The 'Priority' column indicates the order in which the switch attempts each method: lower numbers are tried first. Since dot1x has priority 10, mab has 20, and webauth has 30, the switch will attempt 802.1X first, then MAB, then web authentication.

This is the default fallback behavior for interface-based authentication on Cisco switches.

Exam trap

Cisco often tests the misconception that the 'Priority' column indicates the method's importance or preference, when in fact a lower numeric value means it is attempted first, making the order of fallback the key takeaway.

How to eliminate wrong answers

Option A is wrong because MAB has a higher priority number (20) than 802.1X (10), meaning 802.1X is attempted first, not MAB. Option C is wrong because web authentication has the highest priority number (30), making it the last resort method, not the primary. Option D is wrong because the output clearly shows three methods registered (dot1x, mab, webauth), not only 802.1X.

523
MCQmedium

A network engineer is configuring a Switched Port Analyzer (SPAN) session on a Cisco Catalyst switch to capture traffic from a specific VLAN. Which configuration command is required to monitor all traffic on VLAN 10 and send it to a destination port?

A.monitor session 1 source interface vlan 10
B.monitor session 1 destination vlan 10
C.monitor session 1 source vlan 10
D.monitor session 1 filter vlan 10
AnswerC

This command configures the SPAN session to use VLAN 10 as the source, capturing all traffic within that VLAN. It is the correct first step to monitor VLAN traffic. The destination is then configured separately with the monitor session destination command.

Why this answer

To monitor all traffic on VLAN 10, the correct command is 'monitor session 1 source vlan 10'. This sets the source VLAN for the SPAN session. The destination port is then configured separately.

Other options either use incorrect syntax or confuse source and destination roles.

Exam trap

The trap here is confusing the source and destination configuration, or using incorrect syntax like 'interface vlan' when 'vlan' alone is required for VLAN-based SPAN.

524
Drag & Dropmedium

Drag and drop the steps of DNA Center site hierarchy creation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with defining the top-level site (e.g., continent or country), then adds the area, then the building, then the floor, and finally assigns the floor plan. This hierarchical structure is required for proper network segmentation and assurance in Cisco DNA Center.

525
MCQhard

A network engineer is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router. The router runs BGP, OSPF, SSH management, and SNMP. After applying a CoPP policy that rate-limits all control-plane traffic to 1000 pps, BGP sessions flap and OSPF adjacencies reset during peak traffic. Which action should the engineer take to resolve the problem while maintaining control-plane protection?

A.Create separate class-maps for BGP, OSPF, SSH, and SNMP, and apply protocol-specific rate limits within the policy-map.
B.Enable Control Plane Protection (CPPr) with the aggregate option to automatically prioritize routing protocols.
C.Increase the global CoPP rate limit to 5000 pps to accommodate all control-plane protocols.
D.Remove the CoPP policy from the control plane and rely on QoS policies on data interfaces instead.
AnswerA

CoPP works by classifying traffic into distinct classes and applying individual policers. Creating separate class-maps for each protocol allows the engineer to set appropriate rates for BGP and OSPF while still policing SSH and SNMP. This targeted approach protects the control plane without starving routing protocols, resolving the flapping while maintaining security.

Why this answer

CoPP uses a modular QoS CLI (MQC) structure with class-maps to identify traffic types and a policy-map to apply policers per class. A single policer for all control-plane traffic causes legitimate routing protocol updates to compete with management and monitoring traffic, leading to drops and session resets. The correct solution is to define separate class-maps for BGP, OSPF, SSH, and SNMP, then assign differentiated rate limits in the policy-map.

This preserves control-plane protection while ensuring routing protocols receive adequate bandwidth.

Exam trap

The trap here is treating CoPP as a single-rate mechanism and either removing it or inflating the global limit instead of using granular per-protocol classification, which is the intended design.

Page 6

Page 7 of 26

Page 8