Courseiva

ENCOR 350-401 (350-401) — Questions 526–600

1923 questions total · 26pages · All types, answers revealed

Page 7

Page 8 of 26

Page 9
526
Multi-Selecthard

Which three statements about Cisco DNA Center software image management are true? (Choose three.)

Select 3 answers
A.Cisco DNA Center allows administrators to define a golden image for each device family to enforce consistent software versions.
B.Cisco DNA Center can perform distributed software upgrades using a staging area on the device itself.
C.Cisco DNA Center automatically reboots devices after an image upgrade without any administrator confirmation.
D.Cisco DNA Center can compare the running image on a device against the golden image and report compliance status.
E.Cisco DNA Center uses the device's configuration file to determine the required image version.
AnswersA, B, D

Golden images let administrators designate an approved software version per device family, satisfying the requirement for consistent, enforced versions across the fleet. Compliance checks then flag or remediate devices running non-golden images, standardising the network.

Why this answer

DNA Center provides centralized image management with golden images, distributed upgrades, and compliance checks. The correct answers cover these key features. The incorrect options confuse image management with configuration backup or misstate the upgrade process (no automatic reboot without approval).

527
Multi-Selecthard

Which two statements about Cisco SD-WAN overlay routing and OMP are true? (Choose two.)

Select 2 answers
A.OMP (Overlay Management Protocol) is used to exchange routing, policy, and service information between vSmart controllers and vEdge routers.
B.OMP supports both IPv4 and IPv6 prefix advertisements within the SD-WAN overlay.
C.OMP runs directly between vEdge routers to establish a full mesh of routing adjacencies.
D.OMP routes are automatically redistributed into the local BGP process on the vEdge router.
E.OMP uses UDP port 12346 for communication between vSmart and vEdge devices.
AnswersA, B

OMP runs only between vSmart controllers and vEdge/cEdge routers, carrying route prefixes, TLOC attributes, policies and service-side information in a single protocol. That combined routing, policy and service exchange is exactly what the stem's overlay routing statement requires.

Why this answer

Option A is correct because OMP (Overlay Management Protocol) is the control-plane protocol in Cisco SD-WAN that runs between vSmart controllers and vEdge/cEdge routers, carrying routing information (OMP routes), policy, and service-related data such as TLOCs and VPN membership. Option B is correct because OMP can advertise both IPv4 and IPv6 prefixes in the overlay, allowing the SD-WAN fabric to route IPv6 traffic natively alongside IPv4. Option C is incorrect because OMP does not run directly between vEdge routers; vEdge devices form data-plane IPsec tunnels between themselves, but OMP adjacencies are established only with vSmart controllers (and vBond for orchestration).

Option D is incorrect because OMP routes are not automatically redistributed into BGP on vEdge routers; redistribution between OMP and BGP (or OSPF) must be explicitly configured via route policies. Option E is incorrect because OMP uses TCP port 12346 (not UDP) for control-plane communication between vSmart and vEdge devices.

528
MCQhard

A network engineer is designing a QoS policy for a Cisco Catalyst switch. The requirement is to ensure that a specific class of traffic receives a guaranteed minimum bandwidth during congestion while still allowing other classes to use excess bandwidth when available. Which queuing mechanism should the engineer configure?

A.First-In, First-Out (FIFO) queuing
B.Class-Based Weighted Fair Queuing (CBWFQ)
C.Weighted Random Early Detection (WRED)
D.Low Latency Queuing (LLQ)
AnswerB

CBWFQ is correct because it provides a guaranteed minimum bandwidth to each class during congestion, based on the configured bandwidth value, while allowing classes to use unused bandwidth from others. This matches the requirement for a guaranteed floor with excess sharing. It is implemented with the bandwidth command inside a policy-map class.

Why this answer

CBWFQ guarantees a minimum bandwidth to each class during congestion and allows classes to share unused bandwidth. LLQ provides strict priority, WRED only manages congestion avoidance, and FIFO offers no guarantees. Therefore CBWFQ is the mechanism that matches the stated requirement for a guaranteed floor with excess sharing.

Exam trap

The trap here is choosing LLQ because it is commonly associated with QoS, but LLQ provides strict priority rather than a guaranteed minimum bandwidth with excess sharing.

529
MCQeasy

A network administrator is configuring a switch port to support a VoIP phone and a PC connected to the phone's internal switch. The phone must be placed in VLAN 50 and the PC in VLAN 60. Which configuration on the switch port achieves this?

A.switchport mode access switchport access vlan 50 switchport trunk allowed vlan 60
B.switchport mode access switchport access vlan 50 switchport voice vlan 60
C.switchport mode access switchport access vlan 60 switchport voice vlan 50
D.switchport mode trunk switchport trunk native vlan 60 switchport trunk allowed vlan 50
AnswerC

This configuration sets the access VLAN to 60 for the PC and the voice VLAN to 50 for the phone. The phone will use VLAN 50 for voice traffic and pass untagged PC traffic to VLAN 60. This is the standard Cisco configuration for a phone with a PC attached.

Why this answer

The correct configuration uses access VLAN 60 for the PC and voice VLAN 50 for the phone. Cisco voice VLAN allows the switch to instruct the phone to use a specific VLAN for voice traffic while the PC remains on the access VLAN. This provides proper segmentation and QoS for voice.

Exam trap

The trap here is confusing the access VLAN and voice VLAN assignments, or using trunk mode instead of the dedicated voice VLAN feature.

530
MCQmedium

A network engineer is using the Cisco Meraki Dashboard API to automate the creation of VLANs across multiple networks. The engineer writes a Python script that uses the 'createNetworkVlan' endpoint. The script runs successfully for the first few networks, but then starts returning HTTP 429 errors. The engineer checks the API documentation and finds that the Meraki API has rate limits. The script currently sends requests as fast as possible. What should the engineer implement to avoid hitting the rate limit?

A.Reduce the number of networks being processed in a single script run.
B.Increase the 'per-second' rate limit by setting a higher value in the API request header.
C.Add a retry mechanism with exponential backoff when a 429 response is received.
D.Switch to using the Meraki API version 1.0 which has no rate limits.
AnswerC

A 429 Too Many Requests response signals that the client has hit a server-enforced rate limit, and the standard remedy is to wait and retry. Exponential backoff increases the delay between each retry (e.g., 1s, 2s, 4s) to avoid hammering the API, and it aligns with the server's expectation that the client will back off; optionally, you can combine it with the Retry-After header if provided. This is the widely recommended pattern for resilient API clients.

Why this answer

HTTP 429 errors indicate rate limiting, and the standard mitigation is to implement a retry mechanism with exponential backoff. This approach respects the API's rate limits by pausing and retrying after increasing delays, allowing the script to eventually succeed without overwhelming the server. The Meraki Dashboard API documentation explicitly recommends exponential backoff for handling 429 responses.

Exam trap

Cisco often tests the misconception that rate limits can be bypassed by changing request headers or using a different API version, when the correct solution is always to implement proper retry logic with backoff.

How to eliminate wrong answers

Option A is wrong because reducing the number of networks per run does not address the root cause of sending requests too quickly within a given time window; the script would still hit the rate limit if it sends bursts of requests. Option B is wrong because the 'per-second' rate limit is enforced by the server and cannot be overridden by the client via request headers; setting a higher value in the header has no effect and is not a supported feature of the Meraki API. Option D is wrong because there is no Meraki API version 1.0 that lacks rate limits; all versions of the Meraki Dashboard API enforce rate limits to protect server resources.

531
MCQhard

A network engineer is deploying a Cisco Wireless LAN Controller (WLC) in a centralized deployment mode. The engineer needs to ensure that guest traffic is isolated from internal traffic and that guests can only access the internet. Which feature should be configured on the WLC to meet these requirements?

A.Configure the guest WLAN to use the management interface.
B.Enable DHCP relay on the management interface.
C.Configure a separate WLAN with a guest SSID and map it to a dynamic interface with a dedicated VLAN.
D.Enable Peer-to-Peer Blocking on the guest WLAN.
AnswerC

Creating a separate WLAN for guests and mapping it to a dynamic interface with its own VLAN isolates guest traffic from internal networks. The dynamic interface can be configured with an ACL or firewall rules to restrict guests to internet-only access. This approach ensures that guest traffic is segregated at Layer 2 and can be controlled at Layer 3.

Why this answer

The most effective way to isolate guest traffic is to create a separate WLAN with a guest SSID and assign it to a dynamic interface with a dedicated VLAN. This segregates guest traffic at Layer 2 and allows Layer 3 restrictions via ACLs or firewall rules. Peer-to-Peer Blocking only prevents client-to-client communication, and using the management interface is insecure.

DHCP relay is unrelated to isolation.

Exam trap

The trap here is thinking that Peer-to-Peer Blocking provides complete guest isolation, when it only prevents wireless clients from talking to each other.

532
Matchingmedium

Drag and drop each NAPALM getter on the left to its matching returned data on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Device hostname, vendor, model, OS version, serial number

Interface name, description, IP address, status, speed

BGP neighbor IP, remote AS, state, uptime

LLDP neighbor device ID, port ID, platform

Power supply, fan, temperature status

Why these pairings

get_facts returns device facts like hostname and OS version, get_interfaces returns interface details, get_bgp_neighbors returns BGP neighbor information, get_lldp_neighbors returns LLDP neighbor data, and get_environment returns power and fan status.

533
Multi-Selecthard

Which three statements about EIGRP named mode configuration are true? (Choose three.)

Select 3 answers
A.Named mode uses the 'router eigrp <name>' command to enter configuration mode.
B.In named mode, the network statement is replaced by the 'af-interface' configuration under the address family.
C.Named mode supports both IPv4 and IPv6 address families within the same EIGRP process.
D.The 'address-family ipv4' command is used to enter IPv4 configuration under named mode.
E.Named mode requires the 'no shutdown' command under the address family to enable EIGRP.
AnswersA, C, D

Named mode is entered globally with router eigrp followed by an arbitrary process name, replacing the classic autonomous-system-number syntax. This single named process then hosts one or more address families, which is the structural change that defines EIGRP named mode configuration.

Why this answer

Option A is correct because EIGRP named mode is entered with the global command 'router eigrp <name>', where <name> is a virtual instance name rather than an AS number, distinguishing it from classic mode's 'router eigrp <AS-number>'. Option C is correct because a single named EIGRP process can contain multiple address families, allowing IPv4 and IPv6 to be configured together under one process using 'address-family ipv4' and 'address-family ipv6' submode commands. Option D is correct because after entering 'router eigrp <name>', you use the 'address-family ipv4' (or 'address-family ipv6') command to enter the address-family configuration submode where EIGRP parameters are set.

Option B is not correct because named mode still uses the 'network' statement under the address family to enable EIGRP on interfaces; the 'af-interface' submode is used for per-interface settings such as authentication, hello intervals, and split-horizon, not as a replacement for 'network'. Option E is not correct because EIGRP named mode does not require a 'no shutdown' command under the address family; the process and address family are enabled by configuration and the 'shutdown' command is only used to administratively disable them if desired.

Exam trap

The trap here is confusing classic-mode EIGRP syntax (network statements, no shutdown) with named-mode hierarchy, causing candidates to reject the address-family and dual-stack statements that are actually unique to named mode.

534
Multi-Selecthard

A network administrator is deploying Cisco ACI in a data center. The administrator must configure a bridge domain that allows Layer 2 connectivity between endpoints in the same tenant while also providing Layer 3 gateway services. The design requires that the bridge domain support both unicast routing and unknown unicast flooding. Which two settings must be enabled on the bridge domain to meet these requirements? (Choose two.)

Select 2 answers
A.Enable unicast routing on the bridge domain.
B.Enable DHCP relay on the bridge domain.
C.Enable IGMP snooping on the bridge domain.
D.Enable ARP flooding on the bridge domain.
E.Enable unknown unicast flooding on the bridge domain.
AnswersA, E

Enabling unicast routing on the bridge domain allows the ACI fabric to perform Layer 3 routing between subnets within the bridge domain and to external networks. This is required for the Layer 3 gateway services specified in the scenario, as the bridge domain acts as the default gateway for endpoints.

Why this answer

To provide Layer 3 gateway services, the bridge domain must have unicast routing enabled so it can route between subnets. To support unknown unicast flooding, the bridge domain must have unknown unicast flooding enabled. These two settings directly address the scenario's requirements, while other features like ARP flooding, IGMP snooping, and DHCP relay serve different purposes.

Exam trap

The trap here is assuming that ARP flooding is required for Layer 3 gateway services, when in fact unicast routing is the key setting, and confusing unknown unicast flooding with other flooding types.

535
Multi-Selectmedium

Which two statements about Ansible modules and idempotency are true? (Choose two.)

Select 2 answers
A.Idempotency means that running a playbook multiple times will always result in the same final state on the managed node.
B.The 'command' module is idempotent by default because it always runs the given command.
C.The 'copy' module is idempotent because it checks the checksum of the destination file before copying.
D.All Ansible modules are inherently idempotent regardless of how they are implemented.
E.Idempotency only applies to network modules, not to Linux system modules.
AnswersA, C

Idempotency means a module checks the managed node's current state and only applies changes needed to reach the declared state, so repeated playbook runs converge on the same result without duplicating actions. This matches the statement that multiple runs produce an identical final state.

Why this answer

Option A is correct because idempotency in Ansible means that executing the same playbook repeatedly converges the managed node to the same desired final state without making unnecessary changes on subsequent runs. Option C is correct because the copy module compares the checksum (SHA-1 by default) of the source content against the destination file and only transfers the file when they differ, so repeated runs report 'ok' instead of 'changed'. Option B is wrong because the command module is not idempotent by default—it executes the given command every time unless you add guards such as creates, removes, or changed_when.

Option D is wrong because idempotency is a property of how each module is implemented, not an automatic guarantee for all modules. Option E is wrong because idempotency applies broadly across module types, including Linux system modules like yum, apt, service, and file.

Exam trap

The trap here is assuming that all Ansible modules are idempotent by default; the command and shell modules are the classic counterexamples that exam writers use to test whether candidates understand idempotency is implementation-specific.

536
MCQeasy

A network engineer is configuring an EtherChannel between a Cisco switch and a server that supports LACP. The switch ports are configured as trunk ports allowing multiple VLANs. The engineer wants to ensure the EtherChannel forms automatically without manual intervention. Which configuration should be applied on the switch?

A.Configure the port-channel with 'channel-group 1 mode active'.
B.Configure the port-channel with 'channel-group 1 mode passive'.
C.Configure the port-channel with 'channel-group 1 mode desirable'.
D.Configure the port-channel with 'channel-group 1 mode on'.
AnswerA

Configuring the port-channel with 'channel-group 1 mode active' makes the switch actively transmit LACPDUs on the member link, initiating the IEEE 802.3ad negotiation with the server. Because LACP active mode reliably establishes the EtherChannel with any peer that is either active or passive, it is the safest choice when the server's exact teaming settings are unknown. This mode also allows the switch to detect and manage the bundled link using the standard LACP state machine.

Why this answer

'mode active' enables LACP unconditionally on the switch port, causing it to actively send LACP packets to negotiate and form an EtherChannel with the server. Since the server supports LACP, this ensures automatic formation without manual intervention, and the trunk ports will carry multiple VLANs across the aggregated link.

Exam trap

Cisco often tests the distinction between LACP modes (active/passive) and PAgP modes (desirable/auto), and the trap here is that candidates confuse 'mode desirable' (PAgP) with LACP, or assume 'mode passive' is sufficient when the server might also be passive, leading to a non-forming EtherChannel.

How to eliminate wrong answers

Option B is wrong because 'mode passive' configures the switch to respond to LACP packets only if it receives them from the server, but it does not initiate negotiation; if the server is also configured in passive mode, the EtherChannel will never form. Option C is wrong because 'mode desirable' is a Cisco-proprietary PAgP mode, not LACP, and the server supports LACP, not PAgP, so the protocols are incompatible and the EtherChannel will not form. Option D is wrong because 'mode on' forces the EtherChannel to form statically without any negotiation protocol; this requires manual intervention to ensure both sides are configured identically and does not use LACP, so it does not meet the requirement of automatic formation.

537
Multi-Selectmedium

Which two statements about VRF-aware services are true? (Choose two.)

Select 2 answers
A.VRF-lite allows multiple routing instances on a single router using separate routing tables.
B.VRF-aware services such as DHCP and NAT can be configured independently per VRF.
C.VRF instances are only supported on routers running MPLS VPN.
D.Route leaking between VRFs is not supported in Cisco IOS.
E.All VRFs on a router must share the same global routing table.
AnswersA, B

VRF-lite creates multiple independent routing and forwarding tables on one device without MPLS, letting interfaces be assigned to separate instances. This satisfies the stem's requirement for multiple routing instances on a single router using distinct tables.

Why this answer

Option A is correct because VRF-lite (also called VRF without MPLS) creates multiple independent routing/forwarding instances on a single physical router, each with its own separate routing table (RIB) and forwarding table (FIB), allowing overlapping IP address spaces to be isolated without requiring MPLS. Option B is correct because VRF-aware services extend protocols and features—such as DHCP (ip dhcp pool with vrf ...), NAT (ip nat inside source ... vrf ...), and others like SNMP, syslog, and TACACS+—so each VRF can have its own independent service configuration and address space. Option C is wrong because VRF-lite explicitly supports VRFs on routers without MPLS VPN, so MPLS is not a requirement.

Option D is wrong because Cisco IOS supports route leaking between VRFs via static routes with the global keyword, MP-BGP with route targets, or import/export route-targets in MPLS VPN. Option E is wrong because each VRF maintains its own separate routing table and does not share the global routing table; the global table is only used for traffic outside any VRF.

538
MCQmedium

Examine the following configuration on a Cisco IOS-XE router: ip multicast-routing distributed ! interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip pim sparse-dense-mode ip igmp version 2 ! Which statement about this configuration is true?

A.The interface will operate in dense-mode for all multicast groups because no RP is configured.
B.The router will only support IGMPv2, and IGMPv3 queries will be ignored.
C.Multicast routing is enabled with distributed switching, and the interface will use sparse-mode if an RP is known for the group, otherwise dense-mode.
D.The configuration is invalid because 'ip multicast-routing distributed' is not a valid command.
AnswerC

The command "ip multicast-routing distributed" enables multicast routing in global configuration and, on supported distributed platforms, enables CEF-based multicast forwarding using the Multicast Forwarding Information Base (MFIB) on line cards. Combined with "ip pim sparse-dense-mode" on an interface, the router will initially send PIM joins or use dense-mode behavior depending on whether an RP is known for a given multicast group; if an RP is known (static, BSR, or Auto-RP), sparse-mode is used, otherwise the group operates in dense-mode. This is the correct interpretation of both the command and PIM mode behavior.

Why this answer

The command 'ip multicast-routing distributed' enables multicast routing with distributed switching (hardware offload) on Cisco IOS-XE. The 'ip pim sparse-dense-mode' command configures the interface to operate in sparse-mode if a valid RP is known for the multicast group; otherwise, it falls back to dense-mode. This is the standard behavior of sparse-dense mode, making option C correct.

Exam trap

Cisco often tests the misconception that 'sparse-dense-mode' always uses dense-mode when no RP is configured globally, but the correct behavior is that it checks for an RP per group, not globally.

How to eliminate wrong answers

Option A is wrong because sparse-dense-mode does not default to dense-mode for all groups; it uses sparse-mode if an RP is known and dense-mode only if no RP is known for that specific group. Option B is wrong because the 'ip igmp version 2' command sets the version the router uses to send queries, but the router will still process IGMPv3 reports from hosts (though it will ignore IGMPv3-specific features like source filtering). Option D is wrong because 'ip multicast-routing distributed' is a valid command on Cisco IOS-XE routers that support distributed hardware switching (e.g., on ASR1000 or Catalyst 9000 series).

539
Drag & Dropmedium

Drag and drop the steps of IP Source Guard binding and enforcement into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

IP Source Guard first builds the binding from DHCP snooping, then installs a per-port ACL to permit only the bound IP, applies the ACL to the access port, checks all incoming IP traffic against the ACL, and drops any traffic with a source IP not in the binding.

540
MCQmedium

A network engineer has configured a Cisco IOS IP SLA operation with an ICMP echo probe to monitor reachability of a remote branch router. The engineer wants to automatically remove a static route from the routing table when the probe fails. Which feature should be configured to achieve this?

A.Embedded Event Manager (EEM) applet that triggers on IP SLA failure and removes the route
B.Policy-Based Routing (PBR) with a route map that matches the IP SLA state
C.Floating static route with a higher administrative distance that is always present
D.IP SLA tracking object with a threshold and a static route referencing the track object
AnswerD

Configuring a tracking object (track 1 ip sla 1 reachability) and associating it with the static route (ip route 10.1.1.0 255.255.255.0 192.168.1.2 track 1) allows the router to remove the route when the IP SLA operation fails. This provides automatic failover based on reachability.

Why this answer

The correct solution is to create an IP SLA tracking object and reference it in the static route. When the IP SLA operation fails, the track object goes down, and the static route is removed from the routing table. This provides automatic failover without manual intervention.

Other options either do not remove the route or require additional scripting.

Exam trap

The trap here is assuming that IP SLA alone can modify the routing table; it requires object tracking to influence route installation.

541
Drag & Dropmedium

Drag and drop the steps of NFV MANO (VNFM/NFVO/VIM) interaction flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The interaction flow begins with the NFVO receiving a service request from OSS/BSS. The NFVO then requests resource allocation from the VIM. The VIM allocates resources and reports back.

Next, the NFVO instructs the VNFM to instantiate the VNF. Finally, the VNFM configures and starts the VNF on the allocated resources.

542
Drag & Dropmedium

Drag and drop the steps of MP-BGP VPNv4 route advertisement between PE routers into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with the PE learning the customer route via IGP or static, then redistributing it into MP-BGP as a VPNv4 route with a route distinguisher, advertising it to the other PE via MP-BGP update, the receiving PE importing the route based on matching route targets, and finally installing the route into the appropriate VRF.

543
MCQmedium

Given this OSPF configuration: router ospf 1 router-id 1.1.1.1 network 192.168.1.0 0.0.0.255 area 0 network 10.0.0.0 0.255.255.255 area 1 default-information originate always What is the effect of the 'default-information originate always' command?

A.OSPF will advertise a default route into all OSPF areas even if no default route is present in the routing table.
B.OSPF will only advertise a default route if a default route is already in the routing table.
C.OSPF will redistribute all connected routes as type 5 LSAs.
D.OSPF will generate a default route only for area 0.
AnswerA

The 'always' keyword in the 'default-information originate' command forces OSPF to generate and advertise a default route (0.0.0.0/0) throughout the entire OSPF domain, irrespective of whether a default route exists in the routing table. This guarantees connectivity to external networks via the advertising router even when it has no default route of its own, preventing blackholing in certain topologies.

Why this answer

The 'default-information originate always' command instructs OSPF to generate and advertise a default route (0.0.0.0/0) into the OSPF domain as a Type 5 External LSA, regardless of whether a default route exists in the router's own routing table. This ensures that all OSPF routers in every area receive the default route, making the advertising router a gateway of last resort.

Exam trap

Cisco often tests the distinction between 'default-information originate' (which requires a default route in the routing table) and 'default-information originate always' (which does not), leading candidates to mistakenly think the 'always' keyword is optional or that the command only affects area 0.

How to eliminate wrong answers

Option B is wrong because the 'always' keyword explicitly overrides the default behavior, which would require a default route in the routing table; without 'always', OSPF only originates the default if one is present. Option C is wrong because the command does not redistribute connected routes; it only generates a single default route, and Type 5 LSAs are used for external routes, not for all connected routes. Option D is wrong because the default route is advertised into the entire OSPF domain (all areas), not restricted to area 0; OSPF floods Type 5 LSAs throughout the autonomous system.

544
MCQhard

A network engineer is implementing VXLAN with an EVPN control plane. The underlay is a routed Layer 3 network. Which statement describes the role of the VXLAN Tunnel Endpoint (VTEP)?

A.The VTEP acts as a Layer 3 gateway for inter-subnet routing.
B.The VTEP is responsible for advertising MAC addresses to the EVPN control plane.
C.The VTEP maps VLAN IDs to VXLAN Network Identifiers (VNIs).
D.The VTEP encapsulates Layer 2 frames into VXLAN packets and forwards them over the IP underlay.
AnswerD

The VTEP is responsible for encapsulating original Layer 2 frames into VXLAN UDP packets, adding a VXLAN header, and forwarding them across the IP underlay network. It also decapsulates received VXLAN packets, making it the core component for overlay connectivity.

Why this answer

The VTEP encapsulates Layer 2 frames into VXLAN packets and forwards them over the IP underlay. It is the device that provides the overlay encapsulation and decapsulation, enabling Layer 2 connectivity across a Layer 3 network.

Exam trap

The trap here is confusing the VTEP's data plane encapsulation role with control plane functions like MAC address advertisement or additional features like inter-subnet routing.

545
Multi-Selecteasy

Which TWO features are part of Cisco TrustSec for providing role-based access control?

Select 2 answers
A.Security Group Access Control Lists (SGACLs)
B.Change of Authorization (CoA)
C.802.1X authentication
D.Security Group Tags (SGTs)
E.MACsec encryption
AnswersA, D

SGACLs enforce policies based on SGTs.

Why this answer

Security Group Access Control Lists (SGACLs) are a core component of Cisco TrustSec, enforcing role-based access control by applying policies based on Security Group Tags (SGTs). SGACLs replace traditional IP-based ACLs, allowing dynamic, identity-aware traffic filtering that scales across the network.

Exam trap

Cisco often tests the distinction between the authentication mechanism (802.1X) and the authorization/enforcement components (SGTs and SGACLs), leading candidates to mistakenly select 802.1X as a TrustSec RBAC feature.

546
MCQmedium

A network engineer needs to programmatically retrieve the operational status of all GigabitEthernet interfaces on a Cisco IOS XE device. The engineer wants to use a REST-based protocol that returns data in JSON and uses HTTP methods. The device is configured with 'restconf' and 'ip http secure-server'. Which protocol should the engineer use?

A.SSH with CLI commands
B.RESTCONF over HTTPS
C.SNMPv3 with JSON output
D.NETCONF over SSH
AnswerB

RESTCONF is a REST-based protocol that uses HTTP methods (GET, POST, PUT, PATCH, DELETE) and supports JSON encoding. It is enabled on IOS XE with the 'restconf' command and uses the HTTPS server. This matches the requirement to retrieve interface status programmatically with JSON and HTTP.

Why this answer

RESTCONF is the correct choice because it is a REST-based protocol that uses HTTP methods and supports JSON encoding. It is enabled on Cisco IOS XE with the 'restconf' command and leverages the HTTPS server. The other options either use different transports (NETCONF over SSH), different data formats (SNMP), or are not REST-based (SSH CLI).

Exam trap

The trap here is assuming that NETCONF is the only model-driven programmatic interface for Cisco IOS XE, overlooking that RESTCONF provides a RESTful alternative with JSON support.

547
MCQmedium

Given the following configuration: interface GigabitEthernet0/0 ip address 10.0.0.1 255.255.255.0 ip access-group 101 in ! access-list 101 permit tcp 192.168.1.0 0.0.0.255 any eq 80 access-list 101 deny ip any any What is the effect of this configuration?

A.Incoming traffic from 192.168.1.0/24 to any destination on port 80 is permitted; all other incoming traffic is denied.
B.Outgoing traffic from the router to 192.168.1.0/24 on port 80 is permitted; all other outgoing traffic is denied.
C.Incoming traffic from any source to 192.168.1.0/24 on port 80 is permitted; all other incoming traffic is denied.
D.The access-list will permit all TCP traffic from 192.168.1.0/24, regardless of destination port.
AnswerA

This is correct because the access-list entry 'permit tcp 192.168.1.0 0.0.0.255 any eq 80' matches packets that enter the chosen interface (inbound direction) with a source IP in 192.168.1.0/24, any destination IP, and a destination TCP port of 80 (HTTP). Once this permit statement is evaluated and no other permit entries exist, the implicit deny all at the end of the ACL causes all other inbound traffic to be dropped. Therefore only HTTP from the specified subnet is allowed; everything else is denied.

Why this answer

The configuration applies access-list 101 inbound on GigabitEthernet0/0. The first ACE permits TCP traffic from source network 192.168.1.0/24 to any destination on port 80 (HTTP). The second ACE denies all other IP traffic.

Since the access list is applied in the inbound direction, it filters traffic entering the router through that interface. Therefore, only incoming traffic matching the permit statement is allowed; everything else is denied.

Exam trap

Cisco often tests the distinction between inbound and outbound ACL application, and the trap here is confusing the direction of the access-group or misreading the source/destination in the ACL entries.

How to eliminate wrong answers

Option B is wrong because the access list is applied inbound (ip access-group 101 in), not outbound; it filters traffic entering the interface, not leaving the router. Option C is wrong because it reverses the source and destination: the permit statement specifies source 192.168.1.0/24, not destination; traffic from any source to 192.168.1.0/24 on port 80 would be denied unless it also originated from that subnet. Option D is wrong because the permit statement explicitly restricts to TCP destination port 80 (eq 80); it does not permit all TCP traffic from 192.168.1.0/24 regardless of port.

548
MCQmedium

A service provider is deploying NFV to host virtual network functions (VNFs) such as firewalls, routers, and WAN optimizers on a single server. The design must support service chaining, where traffic flows through multiple VNFs in a specific order, and must allow dynamic insertion of new VNFs without re-cabling. Which technology should be used to implement the service chain?

A.VLAN trunking between VNFs on the same hypervisor
B.VXLAN overlay with policy-based forwarding to direct traffic through VNFs
C.Static routing between VNFs using dedicated interfaces
D.MPLS L3VPN between VNFs
AnswerB

VXLAN overlay with policy-based forwarding is the correct approach because it uses VXLAN Network Identifiers (VNIs) to create scalable, isolated tunnels that can span the hypervisor without physical topology constraints. Traffic can be steered through a desired sequence of VNFs by applying policies based on packet attributes or VNI, allowing seamless insertion, removal, or reordering of VNFs without reconfiguring the underlying network.

Why this answer

VXLAN overlay with policy-based forwarding (PBF) is the correct choice because it enables service chaining by encapsulating traffic and steering it through a sequence of VNFs based on policies, without requiring physical re-cabling. This allows dynamic insertion of new VNFs by simply updating the forwarding policies in the overlay, which is essential for NFV environments where VNFs are hosted on the same server and must be chained flexibly.

Exam trap

The trap here is that candidates often confuse VLAN trunking (Option A) as sufficient for service chaining, but VLANs only provide segmentation, not the policy-based traffic steering required to enforce a specific ordered sequence of VNFs.

How to eliminate wrong answers

Option A is wrong because VLAN trunking between VNFs on the same hypervisor is limited to Layer 2 segmentation and cannot dynamically steer traffic through a specific ordered sequence of VNFs without manual reconfiguration or complex bridging. Option C is wrong because static routing between VNFs using dedicated interfaces requires physical or virtual interface changes and manual route updates, which does not support dynamic insertion of new VNFs without re-cabling or reconfiguration. Option D is wrong because MPLS L3VPN between VNFs is designed for site-to-site connectivity across a WAN, not for intra-server service chaining, and it lacks the policy-based traffic steering needed to enforce a specific VNF order on a single host.

549
Multi-Selectmedium

Which two statements about Cisco DNA Center integration with Cisco SD-Access are true? (Choose two.)

Select 2 answers
A.Cisco DNA Center is used to design and provision the SD-Access fabric, including defining virtual networks and host pools.
B.Cisco DNA Center automatically configures OSPF as the control plane protocol for SD-Access.
C.Cisco DNA Center can enforce group-based policies using Scalable Group Tags (SGTs) in the SD-Access fabric.
D.Cisco DNA Center requires a separate WAN controller to manage SD-Access border nodes.
E.Cisco DNA Center configures SD-Access edge nodes as the core routers of the network.
AnswersA, C

Cisco DNA Center provides the design and provisioning workflow for SD-Access, satisfying the stem's requirement. Through its fabric designer, administrators define virtual networks, host pools, and underlay settings, then DNA Center automates device configuration and fabric deployment across the campus, removing manual CLI provisioning.

Why this answer

Option A is correct because Cisco DNA Center provides the SD-Access design and provisioning workflow, where the administrator defines the fabric sites, virtual networks (VNs), and host pools that map to IP address pools used for endpoint assignment. Option C is correct because Cisco DNA Center integrates with Cisco Identity Services Engine (ISE) to enforce group-based policies by assigning and propagating Scalable Group Tags (SGTs) through the SD-Access fabric, enabling micro-segmentation via Cisco TrustSec. Option B is incorrect because SD-Access uses LISP as the control plane protocol for the fabric overlay, not OSPF; OSPF or IS-IS may be used as the underlay routing protocol, but DNA Center does not automatically configure OSPF as the SD-Access control plane.

Option D is incorrect because SD-Access border nodes are managed directly by Cisco DNA Center as part of the fabric, and no separate WAN controller is required for that purpose. Option E is incorrect because SD-Access edge nodes are access-layer devices that connect endpoints to the fabric, not core routers; the core layer is handled by underlay devices and the fabric's border/control plane nodes.

Exam trap

The trap is confusing the SD-Access fabric control plane protocol (LISP) with the underlay routing protocol (OSPF/IS-IS) — candidates often select OSPF thinking it is the fabric control plane, when LISP is the correct answer.

550
Drag & Dropmedium

Drag and drop the steps of SD-Access fabric node onboarding into DNA Center into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order begins with physical connectivity and discovery, followed by adding the device to inventory, assigning it to a site, configuring the network profile and fabric role, and finally provisioning the node. This sequence ensures the device is discovered, recognized, and properly configured within the SD-Access fabric.

551
Drag & Dropmedium

Drag and drop the steps of SD-WAN edge device (vEdge/cEdge) bring-up sequence into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order follows the Cisco SD-WAN device bootstrapping process: first the device obtains an IP address via DHCP, then it discovers the vManage using DNS or a redirect server, establishes a DTLS/TLS control connection to vManage, downloads its configuration, and finally establishes OMP sessions with vSmart controllers.

552
MCQeasy

A network administrator is configuring a Cisco switch to support a new wireless LAN controller (WLC) that requires the switch port to carry traffic for multiple VLANs. The WLC will be connected to a trunk port. Which command must be used to configure the switch port as a trunk?

A.switchport nonegotiate
B.switchport mode trunk
C.switchport trunk encapsulation dot1q
D.switchport mode access
AnswerB

The command 'switchport mode trunk' configures the interface to operate as a trunk, allowing it to carry traffic for multiple VLANs. This is necessary for connecting a WLC that needs to support multiple VLANs. It is the standard command to set a port to trunk mode on Cisco switches, enabling 802.1Q encapsulation.

Why this answer

To configure a switch port as a trunk, the command 'switchport mode trunk' must be used. This enables the port to carry traffic for multiple VLANs using 802.1Q encapsulation. While other commands like 'switchport trunk encapsulation dot1q' may be required on some platforms, the essential command to set the mode is 'switchport mode trunk'.

This is a fundamental configuration for connecting devices that need multiple VLANs, such as a WLC.

Exam trap

The trap here is confusing the command that sets the encapsulation with the command that actually enables trunking mode, or thinking that disabling DTP is sufficient.

553
MCQmedium

Examine the following AAA configuration snippet: aaa new-model aaa authentication login default local aaa authentication login CONSOLE local aaa authorization exec default local aaa accounting exec default start-stop group tacacs+ line con 0 login authentication CONSOLE line vty 0 4 login authentication default What is the effect of this configuration?

A.Console login uses local authentication; VTY login uses local authentication; exec accounting is sent to TACACS+.
B.Console login uses TACACS+ authentication; VTY login uses local authentication; exec accounting is disabled.
C.Both console and VTY login use TACACS+ authentication; exec accounting is sent to TACACS+.
D.Console login uses local authentication; VTY login uses TACACS+ authentication; accounting is not configured.
AnswerA

The exhibit's AAA configuration binds a named method list, CONSOLE, to the console line, and that list contains only the keyword 'local', so console logins check the local user database. VTY lines are not bound to any custom list, so they inherit the default method list, which also specifies local authentication. For accounting, the command `exec accounting start-stop tacacs+` is globally configured, meaning each EXEC session's start and stop are recorded and sent to the TACACS+ server. Therefore, authentication remains local for both access types, but accounting traffic is forwarded to TACACS+.

Why this answer

The configuration defines two AAA authentication login lists: 'default' and 'CONSOLE'. Both lists use the 'local' method, meaning they authenticate against the local user database. The 'aaa authorization exec default local' command enables local authorization for exec sessions, and 'aaa accounting exec default start-stop group tacacs+' sends accounting records for exec sessions to the TACACS+ server.

The 'line con 0' applies the 'CONSOLE' list, and 'line vty 0 4' applies the 'default' list, so both use local authentication. Therefore, option A is correct.

Exam trap

Cisco often tests the distinction between named and default AAA method lists, and the trap here is assuming that 'aaa authentication login default local' applies to all lines uniformly, when in fact a named list applied to a specific line (like 'CONSOLE' on console) overrides the default for that line.

How to eliminate wrong answers

Option B is wrong because the console login is configured to use local authentication (via 'aaa authentication login CONSOLE local'), not TACACS+. Option C is wrong because neither console nor VTY login uses TACACS+ authentication; both use local authentication as specified by the 'local' keyword in their respective login lists. Option D is wrong because VTY login uses the 'default' authentication list, which is also set to 'local', not TACACS+, and exec accounting is explicitly configured with 'aaa accounting exec default start-stop group tacacs+', so accounting is not disabled.

554
Drag & Dropmedium

Drag and drop the steps of using a REST API to retrieve interface statistics from a Cisco device into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The process starts with authenticating to the device's REST API, then constructing the GET request for the interface statistics endpoint. The device processes the request, retrieves the data, and sends a JSON response. The client then parses the JSON to extract the statistics.

555
Multi-Selecteasy

Which two statements about network design for high availability are true? (Choose two.)

Select 2 answers
A.HSRP allows two or more routers to share a virtual IP address, providing default gateway redundancy.
B.HSRP automatically load-balances traffic across all routers in the group.
C.StackWise Virtual allows two physical switches to operate as a single logical switch for redundancy.
D.A single uplink from an access switch to the distribution layer is sufficient for high availability.
E.Redundant links between switches do not require Spanning Tree Protocol to prevent loops.
AnswersA, C

HSRP satisfies the default gateway redundancy constraint by having routers share a virtual IP and MAC address, so hosts keep one gateway address. The active router forwards traffic; if it fails, the standby assumes the virtual address, preserving gateway availability without host reconfiguration.

Why this answer

Option A is correct because HSRP (Hot Standby Router Protocol) lets two or more routers form a group that shares a single virtual IP address and virtual MAC address, so hosts use that virtual IP as their default gateway and failover to a standby router occurs transparently if the active router fails. Option C is correct because StackWise Virtual (Cisco StackWise Virtual / VSS-style technology) combines two physical switches into one logical switch with a single control plane and management interface, so if one chassis fails the other continues forwarding, providing device-level redundancy. Option B is wrong because HSRP is active/standby by design and does not load-balance traffic across all group members (that requires GLBP or MHSRP).

Option D is wrong because a single uplink is a single point of failure; high availability requires redundant uplinks or an EtherChannel. Option E is wrong because redundant links between switches create Layer 2 loops, so STP (or a loop-prevention mechanism like RSTP/MSTP) is required to block redundant paths.

Exam trap

The trap here is assuming HSRP load-balances by default; candidates who confuse HSRP with GLBP pick option B, but HSRP is active/standby only.

556
Multi-Selectmedium

Which two statements about Cisco SD-WAN control plane components are true? (Choose two.)

Select 2 answers
A.vSmart controllers are responsible for distributing OMP routes and policies to vEdge routers.
B.vBond orchestrators authenticate and onboard vEdge routers into the SD-WAN fabric.
C.vEdge routers function as the control plane devices that maintain the routing table for the entire SD-WAN domain.
D.vManage is the control plane component that distributes BGP routes to all WAN Edge routers.
E.TLOCs are used by vSmart controllers to redistribute routes between different OMP instances.
AnswersA, B

vSmart controllers run the OMP overlay, receiving routes from vEdge routers and redistributing them alongside centralised policies. This satisfies the stem's requirement for a true control plane statement: vSmart handles route and policy distribution, while vManage provides management and vBond handles orchestration and authentication.

Why this answer

Option A is correct because vSmart controllers run the OMP (Overlay Management Protocol) control plane and are the devices that advertise OMP routes, TLOCs, and centralized policies to the vEdge/WAN Edge routers, forming the overlay routing and policy brain of the fabric. Option B is correct because vBond orchestrators handle authentication, authorization, and initial onboarding of vEdge routers, acting as the first point of contact that validates devices and helps them discover vSmart and vManage controllers. Option C is incorrect because vEdge routers are data plane/edge devices that receive OMP routes from vSmart; they do not maintain the routing table for the entire SD-WAN domain.

Option D is incorrect because vManage is the management plane (GUI/API for configuration, monitoring, and provisioning), not a control plane component distributing BGP routes. Option E is incorrect because TLOCs (Transport Locators) are attributes carried in OMP updates that identify a WAN Edge's transport endpoints; they are not used by vSmart to redistribute routes between OMP instances.

Exam trap

350-401 often tests plane confusion: candidates mix up vManage (management), vSmart (control), vBond (orchestration/authentication), and vEdge (data), and pick options that assign routing or policy distribution to the wrong component.

557
MCQmedium

Examine this configuration: interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ipv6 address 2001:db8::1/64 ipv6 ospf 1 area 0 What is the effect of the 'ipv6 ospf 1 area 0' command?

A.It enables OSPFv3 process 1 on this interface and assigns it to area 0.
B.It enables OSPFv2 process 1 on this interface and assigns it to area 0.
C.It enables OSPFv3 on this interface but the process ID must match the router ospf process ID; if not, it will be ignored.
D.It enables OSPFv3 on this interface but area 0 is invalid for IPv6; OSPFv3 uses area 0.0.0.0.
AnswerA

The command 'ipv6 ospf 1 area 0' is the correct IOS interface subcommand to enable OSPFv3, the IPv6-capable version of OSPF, on that link. It starts OSPFv3 process 1 for that interface and places the interface in backbone area 0, which is the mandatory area that interconnects all other areas. The process ID is locally significant, and the area ID is a 32-bit value, with '0' being shorthand for 0.0.0.0.

Why this answer

The 'ipv6 ospf 1 area 0' command enables OSPFv3 (the IPv6 version of OSPF) on the specified interface, assigns it to OSPFv3 process 1, and places the interface in area 0 (the backbone area). This is the correct syntax for activating OSPFv3 on an interface under a specific process and area, independent of any global OSPFv3 process configuration.

Exam trap

Cisco often tests the distinction between OSPFv2 and OSPFv3 interface commands, and the trap here is that candidates confuse 'ip ospf' (OSPFv2) with 'ipv6 ospf' (OSPFv3) or assume the process ID must match a pre-existing global process, when in fact the interface command can auto-create the process.

How to eliminate wrong answers

Option B is wrong because 'ipv6 ospf' is specific to OSPFv3, not OSPFv2; OSPFv2 uses the 'ip ospf' command for IPv4. Option C is wrong because the process ID in the interface command does not need to match a global 'router ospf' process ID; OSPFv3 can be configured directly on the interface, and if no global process exists, one is automatically created. Option D is wrong because area 0 is perfectly valid for OSPFv3; OSPFv3 uses the same area numbering (including decimal 0 for the backbone) as OSPFv2, not area 0.0.0.0 as a required format.

558
Multi-Selectmedium

A network administrator is deploying 802.1X on Cisco Catalyst access switches with Cisco ISE as the RADIUS server. The design requires that devices failing authentication be placed into a restricted VLAN, and that IP phones be authenticated before the attached PC. Which two features must be configured to meet these requirements? (Choose two.)

Select 2 answers
A.Configure an authentication failure VLAN using the authentication event fail action authorize vlan command.
B.Enable 802.1X multi-domain authentication on the port so the phone and PC authenticate independently.
C.Enable port security with sticky MAC addresses on the access port.
D.Configure a guest VLAN on the switch port for hosts that do not support 802.1X.
E.Configure MAC Authentication Bypass (MAB) as the primary authentication method instead of 802.1X.
AnswersA, B

The authentication event fail action authorize vlan command on the switch port directs hosts that fail 802.1X authentication into a specified restricted VLAN. This exactly matches the requirement to isolate failed devices. It is the correct IOS configuration to define failure handling behavior for the port and is essential for the design described.

Why this answer

Placing failed authentications into a restricted VLAN is accomplished with the authentication event fail action authorize vlan command, which defines failure handling. Supporting an IP phone and a PC on one port with independent authentication requires multi-domain authentication, which creates separate voice and data sessions. Together these two features meet both design requirements.

Exam trap

The trap here is confusing a guest VLAN, which serves non-supplicant devices, with a restricted failure VLAN, which isolates devices that actively fail authentication.

559
MCQeasy

In Cisco SD-WAN, what is the default OMP hello interval (in seconds) between a vEdge router and a vSmart controller?

A.10 seconds
B.30 seconds
C.60 seconds
D.5 seconds
AnswerA

The default OMP hello interval is 10 seconds. OMP peers (vSmart and vEdge/cEdge) exchange hello keepalives every 10 seconds over the DTLS/TLS control-plane tunnel to verify that the peer is alive and to maintain the session. This timer is the Cisco SD-WAN default and is not changed by any standard configuration, making 10 seconds the correct answer.

Why this answer

The default OMP hello interval between a vEdge router and a vSmart controller in Cisco SD-WAN is 10 seconds. OMP (Overlay Management Protocol) uses these periodic hello messages to maintain adjacency and detect failures, with a default dead interval of 60 seconds (6 times the hello interval).

Exam trap

Cisco often tests the distinction between the OMP hello interval (10 seconds) and the OMP dead interval (60 seconds), and candidates frequently confuse the two or mistakenly apply BGP or OSPF default timers to OMP.

How to eliminate wrong answers

Option B (30 seconds) is wrong because it is the default OMP hello interval for vBond controllers, not for vEdge-to-vSmart communication. Option C (60 seconds) is wrong because that is the default OMP dead interval, not the hello interval. Option D (5 seconds) is wrong because it is the default hello interval for BGP or OSPF in some contexts, but not for OMP in Cisco SD-WAN.

560
MCQhard

A network engineer uses Netmiko to connect to multiple Cisco IOS XE devices and execute commands. The script runs correctly for most devices but fails for one device with the error: 'ValueError: SSH session not active'. The device is reachable and SSH credentials are correct. What is the most likely cause?

A.The connection timeout is set too low
B.The device has reached the maximum number of SSH sessions
C.The device's SSH server is not fully initialized
D.The device requires an enable password but none was provided
AnswerC

This error from Netmiko/Paramiko means the SSHTransport object is not in an active state when invoke_shell() is called. On Cisco devices, this commonly occurs when the device is still booting and the SSH server has not fully initialized—for example, RSA keys are still being generated—so the server accepts TCP but aborts the SSH protocol handshake, leaving the client transport inactive.

Why this answer

The error 'ValueError: SSH session not active' indicates that Netmiko attempted to establish an SSH connection but the session was not fully active. The most likely cause is that the device's SSH server is not fully initialized, which can happen if the device is still booting or the SSH process has not completed startup. This is distinct from reachability or credential issues, as the device responds to pings but the SSH daemon is not ready to accept connections.

Exam trap

The trap here is that candidates often confuse network reachability or credential validity with SSH session state, assuming that if the device is pingable and credentials are correct, the SSH session must work, but Cisco tests the understanding that SSH session initialization is a separate process that can fail even when the device is reachable.

How to eliminate wrong answers

Option A is wrong because a low connection timeout would typically result in a 'Connection timed out' or 'Timeout' error, not a 'ValueError: SSH session not active' which indicates the session was initiated but not active. Option B is wrong because reaching the maximum number of SSH sessions would produce an error like 'Too many connections' or 'Connection refused', not a ValueError about session inactivity. Option D is wrong because a missing enable password would cause an authentication failure or privilege escalation error after the SSH session is established, not a failure to activate the SSH session itself.

561
MCQmedium

A network engineer is deploying a new virtualized application on a VMware vSphere cluster. The application requires dedicated CPU cores to meet licensing requirements, and the engineer must ensure that no other virtual machine can use those cores. The cluster uses VMware ESXi 7.0. Which configuration should the engineer apply to the virtual machine?

A.Configure CPU affinity to pin the VM to specific physical cores.
B.Set a CPU reservation equal to the number of vCPUs.
C.Enable NUMA node affinity for the VM.
D.Configure a CPU limit equal to the number of vCPUs.
AnswerA

CPU affinity (often called core pinning) is the only mechanism that directly maps a VM's vCPUs to specific physical cores (pCPUs) in the hypervisor's CPU scheduler. By creating a 1:1 binding between each vCPU and a designated physical core, the hypervisor will not schedule any other vCPU or host process on those pinned cores, giving the VM exclusive, dedicated access. This is precisely what the network engineer needs for a latency-sensitive virtual network function, because it eliminates core-sharing contention and provides deterministic and consistent performance.

Why this answer

CPU affinity (option A) is the correct configuration because it explicitly binds a virtual machine's vCPUs to specific physical cores, ensuring that no other VM can use those cores. This meets the licensing requirement for dedicated CPU cores by preventing co-scheduling or sharing of those physical cores with other workloads, which CPU reservation alone does not guarantee.

Exam trap

The trap here is that candidates confuse CPU reservation with dedicated core assignment, assuming that reserving CPU resources guarantees exclusive access to physical cores, when in fact reservation only guarantees resource availability, not exclusivity.

How to eliminate wrong answers

Option B is wrong because a CPU reservation guarantees that the specified amount of CPU resources (in MHz) will be available to the VM, but it does not prevent other VMs from using the same physical cores; the hypervisor can still schedule other VMs on those cores when the VM is idle. Option C is wrong because NUMA node affinity optimizes memory locality for performance by binding a VM to a specific NUMA node, but it does not provide exclusive access to individual CPU cores; other VMs can still run on cores within that NUMA node. Option D is wrong because a CPU limit caps the maximum CPU usage of the VM, but it does not reserve or dedicate cores; it only restricts the VM from consuming more than the specified amount, and other VMs can still use the same physical cores.

562
MCQhard

A network engineer runs the following command on Switch SW1: SW1# show vlan id 10 VLAN ID: 10 VLAN Name: Sales VLAN Type: Ethernet VLAN State: active MTU: 1500 Remote SPAN VLAN: No Primary VLAN ID: 10 Private VLAN Type: Primary Associated Secondary VLAN IDs: 100, 200 Based on this output, what can be concluded?

A.VLAN 10 is a community VLAN.
B.VLAN 10 is an isolated VLAN.
C.VLAN 10 is a primary private VLAN.
D.VLAN 10 is a normal data VLAN with no private VLAN features.
AnswerC

This is correct because the command output unambiguously lists 'Private VLAN Type: Primary' under VLAN 10's configuration, along with its associated secondary VLANs. A primary private VLAN is the root VLAN that carries upstream/downstream traffic and interconnects promiscuous ports with the secondary VLANs mapped to it. The presence of associated secondary VLAN fields confirms VLAN 10 is the primary in this private VLAN domain, making this the accurate description.

Why this answer

The output shows VLAN 10 configured as a Primary VLAN with associated secondary VLANs 100 and 200, which is the defining characteristic of a primary private VLAN. This is confirmed by the fields 'Private VLAN Type: Primary' and 'Associated Secondary VLAN IDs: 100, 200'. Therefore, VLAN 10 is a primary private VLAN, not a normal data VLAN.

Exam trap

Cisco often tests the distinction between the 'show vlan' output for a primary VLAN versus a secondary VLAN, and the trap here is that candidates mistakenly think the presence of 'Associated Secondary VLAN IDs' means the VLAN itself is a secondary VLAN, when in fact only the primary VLAN lists its associated secondary VLANs.

How to eliminate wrong answers

Option A is wrong because a community VLAN is a type of secondary private VLAN that allows communication within the same community and with the primary VLAN, but the output explicitly identifies VLAN 10 as a Primary VLAN, not a community VLAN. Option B is wrong because an isolated VLAN is another type of secondary private VLAN that only allows communication with the primary VLAN, and the output shows VLAN 10 as the Primary VLAN, not an isolated VLAN. Option D is wrong because the presence of 'Private VLAN Type: Primary' and associated secondary VLANs indicates that VLAN 10 is participating in private VLAN features, making it a private VLAN rather than a normal data VLAN.

563
MCQhard

A network engineer is configuring a Cisco Nexus 9000 switch in VXLAN EVPN mode. The engineer wants the leaf switch to advertise the local MAC addresses and IP addresses of hosts in a VLAN to remote leaf switches so that Layer 2 and Layer 3 forwarding can occur without flooding. Which EVPN route type must the engineer ensure is advertised for this purpose?

A.Type 2 MAC/IP Advertisement route
B.Type 3 Inclusive Multicast Ethernet Tag route
C.Type 1 Ethernet Auto-Discovery route
D.Type 5 IP Prefix route
AnswerA

Type 2 MAC/IP Advertisement routes carry the host MAC address and optionally the host IP address, along with the originating VTEP, for a given VNI. Advertising Type 2 routes lets remote leaf switches install MAC and ARP/ND entries and forward unicast traffic directly, avoiding flooding for known hosts.

Why this answer

EVPN Type 2 MAC/IP Advertisement routes are the route type that carries host MAC addresses and, optionally, host IP addresses with the originating VTEP. Advertising them lets remote leaf switches program MAC and ARP/ND entries for known hosts, enabling unicast forwarding without flooding. Type 1, Type 3, and Type 5 routes serve different purposes and do not carry host reachability.

Exam trap

The trap here is confusing the multicast tunnel endpoint advertisement with the host reachability advertisement, since both are exchanged automatically in a VXLAN EVPN fabric.

564
Multi-Selectmedium

Which two statements about NetFlow are true? (Choose two.)

Select 2 answers
A.NetFlow records are unidirectional by default.
B.Sampled NetFlow reduces CPU impact by analyzing only a subset of packets.
C.Flexible NetFlow can export user-defined flow keys using NetFlow v5 format.
D.NetFlow can be used as a replacement for SNMP polling for interface utilization.
E.NetFlow v9 supports only IPv4 traffic.
AnswersA, B

A NetFlow flow is defined by a one-way tuple of source and destination addresses, ports, and protocol, so each record describes traffic in a single direction. Return traffic generates a separate record, which is why bidirectional analysis requires correlating two flows.

Why this answer

Option A is correct because a standard NetFlow flow record is defined by a unidirectional 5-tuple (source IP, destination IP, source port, destination port, and protocol), so each direction of a conversation is tracked as a separate flow entry. Option B is correct because Sampled NetFlow applies a sampling rate (for example, 1 out of every 100 packets) so the router or switch only inspects a subset of traffic, which lowers CPU and memory overhead compared with full NetFlow accounting. Option C is not correct because user-defined flow keys and flexible field selection require Flexible NetFlow export formats such as NetFlow v9 or IPFIX, not the fixed NetFlow v5 record layout.

Option D is not correct because NetFlow provides flow-level traffic detail and is complementary to SNMP interface counters, not a drop-in replacement for SNMP polling of interface utilization. Option E is not correct because NetFlow v9 is template-based and can carry IPv4, IPv6, MPLS, and other protocol fields, not only IPv4 traffic.

Exam trap

350-401 often tests the misconception that NetFlow replaces SNMP for interface utilization, but NetFlow is flow-level and sampled, while SNMP provides exact interface counters.

565
Matchingmedium

Drag and drop each ACL type on the left to its matching capability on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Filters based on source IP address only

Filters based on source/destination IP, protocol, and port numbers

Allows identification by alphanumeric name instead of number

Applies a time range to restrict access during specific periods

Authenticates a user and then opens a temporary hole in the firewall

Why these pairings

Standard ACLs filter only source IP; Extended ACLs filter source/dest IP, protocol, and ports; Named ACLs allow identification by name; Time-based ACLs use time ranges; Dynamic ACLs authenticate per-user.

566
MCQhard

An engineer is designing a Layer 2 network with redundancy. The network uses MST (Multiple Spanning Tree) to reduce the number of STP instances. The engineer has configured two regions: Region 1 and Region 2. The engineer notices that switches in Region 1 are not forming a single MST region, and instead, they are treating each other as if they are in different regions. The engineer checks the configuration and finds that the region name and revision number are the same on all switches in Region 1, but the VLAN-to-instance mapping is different on one switch. What is the most likely cause of the issue?

A.The VLAN-to-instance mapping is not consistent across all switches in Region 1.
B.The root bridge for each MST instance is not configured correctly.
C.BPDU Guard is enabled on the inter-switch links, preventing BPDU exchange.
D.PortFast is enabled on the inter-switch links, causing the switches to ignore BPDUs.
AnswerA

The IEEE 802.1s MST region is identified by a computed configuration digest, which is derived from the VLAN-to-instance mapping, the region name, and the revision number. If one switch in Region 1 uses a different mapping (for example, VLAN 10 assigned to instance 2 instead of instance 1), its digest differs even if the name and revision match. Switches with different digests cannot distinguish internal MST BPDUs from external ones, so they treat each other as separate regions, causing an incorrect top-level tree and per-instance topology. This is exactly the failure symptom described in the scenario.

Why this answer

In MST, all switches within a region must agree on three parameters: the region name, the revision number, and the VLAN-to-instance mapping. Even if the region name and revision number match, a single mismatch in the VLAN-to-instance mapping causes the switches to treat each other as if they belong to different regions, preventing them from forming a single MST region.

Exam trap

Cisco often tests the fact that all three components of the MST configuration (name, revision, and VLAN-to-instance mapping) must match exactly for switches to be in the same region, and candidates mistakenly think only the name and revision matter.

How to eliminate wrong answers

Option B is wrong because the root bridge configuration for each MST instance affects the spanning-tree topology within the region but does not determine whether switches belong to the same region; region membership is based solely on the MST configuration identifier (name, revision, mapping). Option C is wrong because BPDU Guard is a port security feature that shuts down a port upon receiving a BPDU, but it does not prevent BPDU exchange before the port is err-disabled; moreover, the issue described is about region formation, not BPDU filtering. Option D is wrong because PortFast immediately transitions a port to the forwarding state but does not cause switches to ignore BPDUs; BPDUs are still processed, and PortFast does not affect MST region formation.

567
MCQeasy

A network engineer uses the following Python script with Netmiko to send a command to a Cisco IOS-XE device: ```python from netmiko import ConnectHandler device = { 'device_type': 'cisco_ios', 'ip': '10.1.1.1', 'username': 'admin', 'password': 'password', 'secret': 'enable_secret' } connection = ConnectHandler(**device) output = connection.send_command('show ip interface brief') print(output) connection.disconnect() ``` What is the purpose of the 'secret' parameter in the device dictionary?

A.It is used for SSH key-based authentication.
B.It is used to enter enable mode after connecting to the device.
C.It is used to encrypt the session.
D.It is used to set the SNMP community string.
AnswerB

Netmiko's 'secret' supplies the enable password, which the library sends after login to escalate from user EXEC to privileged EXEC mode. Without it, commands such as 'show ip interface brief' that require elevated privileges would be rejected by the IOS-XE device.

Why this answer

In Netmiko, the 'secret' parameter in the device dictionary is the enable password used to enter privileged EXEC (enable) mode after the initial SSH connection is established. When Netmiko connects, it authenticates with the username/password, and if 'secret' is provided, it can send the enable command to elevate privileges. This is required for commands that need privileged access, such as 'show running-config' on some platforms.

Exam trap

350-401 often tests the distinction between authentication parameters (username/password), privilege escalation (secret/enable), and transport security (SSH keys), causing candidates to confuse 'secret' with SSH key authentication or session encryption.

How to eliminate wrong answers

Option A is wrong because SSH key-based authentication in Netmiko uses the 'use_keys' and 'key_file' parameters, not 'secret'. Option C is wrong because 'secret' does not encrypt the session — SSH already encrypts the session transport; 'secret' is purely for enable-mode authentication. Option D is wrong because SNMP community strings are unrelated to Netmiko's device dictionary and are configured via SNMP parameters, not 'secret'.

568
MCQhard

A large enterprise has a campus network with a collapsed core design. The core switch connects to two distribution switches, each serving several access switches. The network uses OSPF as the IGP. Recently, after a link failure between the core and distribution switch A, the network experienced a 30-second outage before converging. The engineer wants to improve convergence time to under 5 seconds. The budget is limited, so hardware upgrades are not an option. The engineer is considering the following actions: A. Enable OSPF Fast Hello on all interfaces. B. Reduce OSPF dead timer to 1 second and hello timer to 333 milliseconds. C. Implement OSPF LSA throttling with a minimum interval of 0 ms. D. Use OSPF incremental SPF (iSPF). Which action will provide the most significant improvement in convergence time for this scenario?

A.Enable OSPF Fast Hello on all interfaces.
B.Reduce OSPF dead timer to 1 second and hello timer to 333 milliseconds.
C.Implement OSPF LSA throttling with a minimum interval of 0 ms.
D.Use OSPF incremental SPF (iSPF).
AnswerB

The OSPF dead timer is the primary factor in convergence delay because it dictates how long a router waits for a missing hello before marking the neighbor unavailable. Setting the dead timer to 1 second ensures that a link failure is detected within roughly one second, and a hello interval of 333 milliseconds satisfies the standard three-hello requirement while maintaining a stable neighbor state. This direct reduction of the detection timer cuts the outage from tens of seconds to about one second, whereas other mechanisms only optimize post-detection processing.

Why this answer

Reducing the OSPF dead timer to 1 second and hello timer to 333 milliseconds directly addresses the 30-second outage caused by the link failure. The default dead timer (40 seconds on broadcast networks) is the primary contributor to convergence delay, as OSPF must wait for the dead interval to expire before declaring a neighbor down. By lowering these timers, failure detection drops from 40 seconds to approximately 1 second, which is the most impactful single change for convergence under budget constraints.

Exam trap

Cisco often tests the misconception that Fast Hello (Option A) is the best way to speed convergence, but the trap is that Fast Hello alone does not reduce the dead timer below 1 second unless explicitly configured with a multiplier, and the dead timer is the dominant factor in failure detection time.

How to eliminate wrong answers

Option A is wrong because OSPF Fast Hello (using the 'ip ospf dead-interval minimal hello-multiplier' command) sends hellos at sub-second intervals but still relies on the dead timer for failure detection; it does not inherently reduce the dead timer below 1 second, so it may not achieve the sub-5-second convergence goal without also adjusting the dead interval. Option C is wrong because OSPF LSA throttling (with 'timers throttle lsa all') controls the rate at which LSAs are generated and retransmitted, not failure detection; it helps with network stability during flapping but does not reduce the time to detect a link failure. Option D is wrong because incremental SPF (iSPF) optimizes SPF computation by only recalculating affected routes, but it does not address the primary bottleneck of neighbor failure detection; the 30-second outage is dominated by the dead timer, not SPF calculation time.

569
MCQmedium

A network engineer is deploying a new branch office that uses Cisco SD-Access. The fabric must support both wired and wireless clients, with a single control plane that provides host tracking, location, and policy enforcement. Which fabric component is responsible for these functions?

A.Cisco Identity Services Engine (ISE)
B.Fabric control plane node
C.Fabric edge node
D.Cisco DNA Center
AnswerB

In Cisco SD-Access, the fabric control plane node runs the LISP map-server and map-resolver functions, maintaining the endpoint identifier (EID) to routing locator (RLOC) mappings for all fabric endpoints. This provides host tracking, location, and a unified control plane for both wired and wireless clients. The control plane node is essential for scalable fabric operations and policy enforcement through group-based policies.

Why this answer

The fabric control plane node in Cisco SD-Access runs LISP map-server and map-resolver, providing a centralized database for endpoint-to-RLOC mappings. This enables host tracking, location services, and a single control plane for both wired and wireless clients. DNA Center and ISE are supporting components for management and policy, but they do not provide the runtime control-plane functions described in the scenario.

Exam trap

The trap here is assuming that DNA Center or ISE provides the fabric control plane, when in fact they are management and policy components that rely on the control plane node for endpoint tracking.

570
MCQeasy

A network administrator is configuring a Cisco Catalyst 9000 switch to participate in a StackWise Virtual configuration. The administrator wants to ensure that the switch is ready to be added to an existing StackWise Virtual domain. Which command must be issued on the new switch before it can join the domain?

A.switch convert mode virtual
B.switch virtual domain 1
C.stackwise-virtual domain 1
D.stackwise-virtual enable
AnswerA

The command 'switch convert mode virtual' converts a standalone switch to StackWise Virtual mode. This is required before the switch can join an existing StackWise Virtual domain. It changes the switch's operation to support the virtual domain and prepares it for the stacking connection. Without this conversion, the switch remains in standalone mode and cannot participate in the virtual domain.

Why this answer

To join a StackWise Virtual domain, a standalone switch must first be converted using 'switch convert mode virtual'. This command changes the switch's mode of operation and allows it to form a virtual domain with another switch. After conversion, the domain ID and other parameters can be configured.

Exam trap

The trap here is confusing StackWise Virtual commands with traditional StackWise commands, such as 'switch virtual domain'.

571
Multi-Selecthard

Which three statements about queuing and congestion avoidance in a QoS architecture are true? (Choose three.)

Select 3 answers
A.Class-Based Weighted Fair Queuing (CBWFQ) assigns a weight to each class and guarantees a minimum bandwidth during congestion.
B.Low Latency Queuing (LLQ) provides a strict priority queue that is serviced before any other queues, which can cause starvation of other queues if not policed.
C.Weighted Random Early Detection (WRED) can be used only with TCP traffic and drops packets randomly based on the average queue depth.
D.Tail drop is a congestion avoidance mechanism that drops packets from the front of the queue when it is full.
E.WRED can be configured per class within a policy map using the 'random-detect' command under the class.
AnswersA, B, E

CBWFQ is a class-based scheduling mechanism that builds on per-flow WFQ by classifying packets into user-defined classes, each configured with a minimum bandwidth (as an absolute rate, percentage, or relative weight). When congestion occurs, the scheduler services classes in proportion to their configured weights or bandwidth guarantees, ensuring each class receives its minimum share while still allowing idle classes' bandwidth to be redistributed. This guarantee only applies during congestion; under light load, classes can exceed their configured bandwidth.

Why this answer

Queuing manages packets when output is congested, using algorithms like CBWFQ and LLQ. Congestion avoidance techniques like WRED proactively drop packets to prevent tail drops. LLQ provides strict priority queuing for delay-sensitive traffic.

WRED can be configured per class in a policy map.

572
MCQhard

A network engineer is deploying MACsec on a Cisco Catalyst 9300 switch to secure a point-to-point link between two access switches. The engineer configures the switchport with the macsec command and a pre-shared key. After applying the configuration, the link comes up but MACsec is not encrypting traffic. Which action should the engineer take to resolve the issue?

A.Apply the macsec command under the VLAN interface instead of the physical interface.
B.Change the switchport mode to trunk to allow MACsec frames to pass.
C.Enable MACsec globally using the macsec command in global configuration mode.
D.Configure the key server protocol (MKA) with a matching connectivity association key (CAK) on both switches and ensure the key server priority is set.
AnswerD

MACsec requires MKA to negotiate session keys between peers. If the CAK or key server priority does not match on both ends, MKA will not establish a secure association, and MACsec will not encrypt traffic even though the link is up. Configuring a matching CAK and designating a key server on both switches allows MKA to complete negotiation, after which MACsec encryption begins.

Why this answer

MACsec relies on MKA to establish a secure channel between two directly connected devices. For MKA to succeed, both peers must share the same connectivity association key and agree on the key server. If these parameters are missing or mismatched, the link remains up but MACsec encryption does not activate.

Verifying and matching the MKA configuration on both switches is the correct troubleshooting step.

Exam trap

The trap here is assuming that enabling MACsec on the interface is sufficient, without ensuring MKA parameters match on both ends of the link.

573
MCQmedium

Given the following Ansible playbook snippet: --- - name: Configure OSPF hosts: routers gather_facts: no tasks: - name: OSPF config ios_config: lines: - router ospf 1 - network 10.0.0.0 0.255.255.255 area 0 parents: router ospf 1 What is wrong with this playbook?

A.The 'parents' parameter should not be used with 'router ospf 1' in lines; it causes a configuration error.
B.The network statement uses a wildcard mask instead of subnet mask, which is incorrect.
C.The OSPF process ID must be 1, but it can be any number.
D.There is no error; the playbook works correctly.
AnswerA

In Ansible's ios_config module, the `parents` parameter specifies the configuration mode to enter before applying `lines`. When `parents` is set to 'router ospf 1', the module already issues that command to navigate into OSPF configuration mode. Adding `router ospf 1` again inside the `lines` list results in a nested command that the Cisco IOS parser does not accept in this context, producing a configuration error. The correct usage is to place only OSPF subcommands, such as network statements, in `lines` and let `parents` handle the mode entry.

Why this answer

The `parents` parameter in the `ios_config` module specifies the parent configuration mode under which the `lines` should be applied. When `lines` already includes `router ospf 1`, using `parents: router ospf 1` causes Ansible to attempt entering the OSPF router configuration mode twice, leading to a configuration error. The correct approach is to either omit the `parents` parameter or include only the network statement in `lines` with the appropriate parent.

Exam trap

Cisco often tests the misconception that the `parents` parameter is optional or redundant when the mode entry command is already in `lines`, but in reality, it causes a duplicate command error because the module enters the parent mode first.

How to eliminate wrong answers

Option B is wrong because Cisco IOS uses wildcard masks in OSPF network statements (e.g., `network 10.0.0.0 0.255.255.255 area 0`), which is correct syntax; a subnet mask would be invalid. Option C is wrong because the OSPF process ID can be any number, but the playbook does not enforce a specific value; the issue is not about the process ID being 1. Option D is wrong because the playbook contains a logical error in the use of the `parents` parameter, as explained in the correct answer.

574
MCQmedium

Given the following configuration: aaa new-model aaa authentication login default group radius local aaa authorization exec default group radius local aaa accounting exec default start-stop group radius radius-server host 192.168.1.100 key Cisco123 radius-server host 192.168.1.101 key Cisco123 Which statement is true about this configuration?

A.If the first RADIUS server (192.168.1.100) is unreachable, the second server (192.168.1.101) is tried before falling back to local.
B.The RADIUS servers are used for authentication only, not for authorization or accounting.
C.Local authentication is always attempted first, then RADIUS.
D.The RADIUS key is optional; if omitted, the router uses an empty key.
AnswerA

When a user attempts authentication, the router consults the method list and sends the request to the first configured RADIUS server, 192.168.1.100. Only if that server times out or is unreachable does the router move to the next server in the list, 192.168.1.101, rather than immediately using local authentication. If all RADIUS servers are unavailable or return errors, the router then falls back to the local database as the final method, so the described behavior is correct.

Why this answer

The configuration uses the 'default' method list for login authentication, exec authorization, and exec accounting. The order 'group radius local' means the router first attempts authentication, authorization, and accounting via the RADIUS servers in the order they are configured. If the first RADIUS server (192.168.1.100) is unreachable, the second server (192.168.1.101) is tried before falling back to local authentication.

This is because the 'group radius' keyword directs the router to try all configured RADIUS servers in sequence before resorting to the 'local' fallback method.

Exam trap

Cisco often tests the misconception that 'group radius local' means local authentication is tried first, or that RADIUS servers are only used for authentication, when in fact the order of methods in the list determines the sequence, and the same method list can apply to authentication, authorization, and accounting.

How to eliminate wrong answers

Option B is wrong because the configuration includes 'aaa authorization exec default group radius local' and 'aaa accounting exec default start-stop group radius', which explicitly use RADIUS for both authorization and accounting, not just authentication. Option C is wrong because the order 'group radius local' specifies that RADIUS is attempted first, and local authentication is only used as a fallback if all RADIUS servers are unreachable. Option D is wrong because the 'key' is mandatory when using RADIUS; if omitted, the router will not be able to authenticate with the RADIUS server, and the command 'radius-server host' requires a key to be specified for secure communication.

575
Multi-Selecteasy

Which TWO are benefits of using a spine-leaf architecture in a data center? (Choose two.)

Select 2 answers
A.Predictable latency between any two devices
B.Increased number of single points of failure
C.Increased broadcast domain size
D.Reduced need for VLANs
E.Higher bandwidth utilization through multiple equal-cost paths
AnswersA, E

Traffic always traverses one spine hop, resulting in consistent latency.

Why this answer

A is correct because spine-leaf architecture ensures that every leaf switch is connected to every spine switch, creating a full-mesh topology. This design guarantees that traffic between any two leaf switches traverses at most one spine hop, resulting in predictable, consistent latency regardless of which devices are communicating.

Exam trap

Cisco often tests the misconception that spine-leaf eliminates VLANs or reduces broadcast domains, but the architecture actually uses Layer 3 routing to contain broadcast domains while still requiring VLANs for Layer 2 segmentation at the leaf level.

576
Drag & Dropmedium

Drag and drop the steps of WPA3 client authentication process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

WPA3 uses SAE (Simultaneous Authentication of Equals) handshake. First, the AP announces WPA3 capability in beacons. The client then initiates the SAE commit exchange, followed by the SAE confirm exchange.

After SAE completes, the 4-Way Handshake occurs, and finally group key is installed.

577
Drag & Dropmedium

Drag and drop the steps to configure a static route on a Cisco IOS router into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Static routes require global config mode and must specify the destination network, subnet mask, and next-hop address or exit interface.

578
Multi-Selecthard

Which THREE are common causes of high CPU utilization on a Cisco Catalyst switch? (Choose three.)

Select 3 answers
A.Broadcast storms
B.Excessive hardware switching of packets
C.Low memory conditions
D.Frequent STP topology changes
E.ACL logging with 'log' keyword
AnswersA, D, E

A broadcast storm floods every port with endlessly circulating frames, forcing the switch CPU to process enormous volumes of broadcast traffic and replicate frames across the broadcast domain. This software-path processing load, rather than normal hardware switching, is what drives control-plane CPU utilisation upward.

Why this answer

Broadcast storms (A) are a classic cause of high CPU utilization on a Catalyst switch because flooded broadcast frames are punted to the CPU for processing and replication to all ports in the VLAN, overwhelming the control plane. Frequent STP topology changes (D) drive high CPU because each TCN forces the switch to recompute the spanning-tree topology, flush MAC address entries, and process BPDUs, consuming significant control-plane cycles. ACL logging with the 'log' keyword (E) is correct because every matching packet is punted to the CPU to generate a syslog message, and a high volume of matches can saturate the CPU.

Excessive hardware switching of packets (B) is not a cause of high CPU since hardware (ASIC) switching is designed to forward packets at wire speed without involving the CPU. Low memory conditions (C) affect memory, not CPU utilization, and are not a common cause of high CPU on a Catalyst switch.

Exam trap

Cisco often tests the distinction between control plane (CPU-processed) and data plane (ASIC-switched) traffic; the trap here is assuming hardware switching tasks consume CPU cycles, when in fact they are offloaded to dedicated hardware.

579
Drag & Dropmedium

Drag and drop the steps of MST region configuration and operation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

MST configuration begins with entering MST mode and defining the region name, revision number, and VLAN-to-instance mapping. After configuration, the switch computes an MD5 digest of the MST configuration to identify region membership. Switches in the same region then run IST (Internal Spanning Tree) and CIST (Common and Internal Spanning Tree) to elect a root bridge for the region.

Finally, per-instance spanning trees are calculated within the region.

580
MCQmedium

A network administrator is deploying 802.1X on Cisco Catalyst switches with Cisco ISE as the RADIUS server. The administrator wants to allow devices that do not support 802.1X, such as printers, to connect to the network. Which feature should be configured on the switch ports to support these devices while maintaining security?

A.Configure the switch ports as 802.1X supplicants so they can authenticate on behalf of connected devices.
B.Enable MAC Authentication Bypass (MAB) on the switch ports so that the MAC address of non-802.1X devices is sent to ISE for authentication.
C.Implement 802.1X with EAP-TLS and install certificates on the printers.
D.Disable 802.1X on the ports and rely on port security to restrict access based on MAC addresses.
AnswerB

MAB allows non-802.1X-capable devices like printers to be authenticated by their MAC address. The switch learns the MAC address and sends it to ISE as the username and password. ISE can then apply an authorization policy, such as placing the device in a specific VLAN or applying an ACL. This maintains centralized control while supporting legacy devices.

Why this answer

MAC Authentication Bypass allows devices that lack 802.1X supplicant software to be authenticated by their MAC address against Cisco ISE. The switch sends the MAC address as both username and password, and ISE applies the appropriate authorization policy. This enables printers and similar devices to connect while still enforcing centralized access control.

Exam trap

The trap here is confusing the roles of supplicant, authenticator, and authentication server, and assuming the switch can authenticate on behalf of endpoints without MAB.

581
Drag & Dropmedium

Drag and drop the steps of Control Plane Policing (CoPP) rate-limit evaluation into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

CoPP first classifies traffic using an access list, then matches it to a class map, then applies a policy map with a police action (rate-limit), activates the policy on the control plane, and finally the hardware performs policing.

582
Drag & Dropmedium

Drag and drop the steps of sFlow agent sampling and forwarding steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

sFlow begins with the agent sampling packets at a configured rate, then extracts header and counter information, encapsulates the sample into an sFlow datagram, sends the datagram to the collector via UDP, and finally the collector analyzes the samples for monitoring.

583
MCQmedium

Router R6 has the following OSPF configuration: router ospf 1 router-id 6.6.6.6 network 192.168.0.0 0.0.255.255 area 0 passive-interface default no passive-interface GigabitEthernet0/0 ! interface GigabitEthernet0/0 ip address 192.168.1.6 255.255.255.0 ip ospf 1 area 0 What is the effect of the 'passive-interface default' command?

A.All OSPF interfaces become passive, including GigabitEthernet0/0.
B.Only GigabitEthernet0/0 is active; all other OSPF interfaces are passive.
C.OSPF adjacencies are formed on all interfaces.
D.The 'passive-interface default' command is ignored because the 'network' command is used.
AnswerB

The passive-interface default directive makes every OSPF-enabled interface passive unless a specific interface is later excluded. The no passive-interface GigabitEthernet0/0 command removes that default for Gi0/0, permitting OSPF hello packets and adjacency formation on that link. All other OSPF interfaces remain passive and silent, so only GigabitEthernet0/0 is active in OSPF terms. This precisely matches the configuration, making it the correct answer.

Why this answer

The 'passive-interface default' command sets all OSPF interfaces to passive by default, meaning they will not send or receive OSPF hello packets and thus cannot form adjacencies. The subsequent 'no passive-interface GigabitEthernet0/0' overrides this for that specific interface, making it the only active OSPF interface. This matches option B.

Exam trap

Cisco often tests the interaction between 'passive-interface default' and 'no passive-interface' to see if candidates understand that the default command applies to all interfaces and must be explicitly overridden per interface, rather than assuming the 'network' command alone controls adjacency formation.

How to eliminate wrong answers

Option A is wrong because the 'no passive-interface GigabitEthernet0/0' command explicitly overrides the default passive setting for that interface, so not all interfaces become passive. Option C is wrong because OSPF adjacencies are only formed on interfaces that are not passive; with 'passive-interface default', only GigabitEthernet0/0 is active, so adjacencies form only on that interface. Option D is wrong because the 'passive-interface default' command is not ignored; it works in conjunction with the 'network' command, which defines which interfaces participate in OSPF, but the passive setting controls whether hellos are sent and adjacencies are formed on those interfaces.

584
Multi-Selectmedium

Which two statements about Cisco DNA Center automation workflows are true? (Choose two.)

Select 2 answers
A.Cisco DNA Center supports Plug and Play (PnP) for zero-touch device onboarding.
B.Cisco DNA Center uses template-based provisioning to apply consistent configurations across devices.
C.Cisco DNA Center only supports GUI-based configuration; CLI access is not available.
D.Cisco DNA Center automates configuration of all network devices, including third-party switches.
E.Cisco DNA Center uses SNMP to push configuration changes to devices.
AnswersA, B

Cisco DNA Center's Plug and Play workflow automatically discovers unconfigured devices, assigns them to sites, and pushes day-zero configurations, removing manual CLI setup. This zero-touch onboarding capability satisfies the statement about PnP support in automation workflows.

Why this answer

Option A is correct because Cisco DNA Center's Plug and Play (PnP) workflow lets new devices automatically discover the controller, authenticate via certificates or pre-shared keys, and receive their day-0/day-1 configuration without manual intervention, enabling true zero-touch onboarding. Option B is correct because DNA Center uses template-based provisioning (for example, CLI templates and regular/compound templates in the Template Editor) to render and push consistent, standardized configurations across many devices, reducing drift and manual errors. Option C is wrong because DNA Center also offers CLI access and APIs (Intent API, REST) alongside the GUI, so it is not GUI-only.

Option D is wrong because DNA Center's automation is primarily for Cisco devices (IOS-XE, NX-OS, AireOS, etc.) and does not fully automate all third-party switches. Option E is wrong because configuration changes are pushed via NETCONF/YANG, SSH/CLI, or the PnP protocol, not SNMP, which is used mainly for monitoring and telemetry rather than configuration.

585
Multi-Selectmedium

Which three statements about NAT traversal and translation are true? (Choose three.)

Select 3 answers
A.IPsec NAT traversal uses UDP encapsulation on port 4500 to allow ESP traffic to pass through a NAT device.
B.The ip nat outside source command translates the source IP address of packets arriving on the outside interface.
C.NAT can translate both source and destination IP addresses in the same packet for different translation rules.
D.NAT automatically translates IP addresses embedded in application-layer payloads such as FTP or SIP.
E.The ip nat inside destination command translates the destination MAC address of packets entering the inside interface.
AnswersA, B, C

NAT-T encapsulates ESP packets inside UDP datagrams on port 4500, allowing them to traverse NAT devices that cannot process ESP or handle PAT for protocol 50. This satisfies the stem's requirement by enabling IPsec traffic through NAT where raw ESP would be dropped.

Why this answer

Option A is correct because IPsec NAT-T encapsulates ESP packets inside UDP datagrams sent to port 4500, which lets the NAT device track the flow and allows the encapsulated ESP traffic to traverse the NAT. Option B is correct because the ip nat outside source command performs translation on the source address of packets that arrive on the outside interface, typically used for outside-to-inside translation scenarios. Option C is correct because NAT can apply separate translation rules that modify both the source and destination IP addresses within the same packet, as with twice NAT or policy NAT configurations.

Option D is not correct because standard NAT does not automatically translate IP addresses embedded in application-layer payloads; ALGs or application inspection are required for protocols like FTP or SIP. Option E is not correct because the ip nat inside destination command translates the destination IP address of packets entering the inside interface, not the destination MAC address.

Exam trap

The trap is assuming NAT automatically rewrites application-layer embedded IPs (it does not — that is ALG/fixup territory) and confusing 'ip nat inside destination' (destination IP translation) with MAC translation.

586
MCQeasy

A network engineer is configuring a Cisco IOS router to support NAT for a small office. The inside network uses the 192.168.1.0/24 subnet, and the outside interface is GigabitEthernet0/0 with IP address 203.0.113.5. The engineer wants to translate all inside addresses to the outside interface address. Which command is required to define the NAT source list?

A.ip nat pool POOL 203.0.113.5 203.0.113.5 netmask 255.255.255.0
B.ip nat inside source list 1 interface GigabitEthernet0/0 overload
C.access-list 1 permit 192.168.1.0 0.0.0.255
D.ip nat inside source static 192.168.1.1 203.0.113.5
AnswerC

This access list defines the inside local addresses that will be translated. The wildcard mask 0.0.0.255 matches the entire 192.168.1.0/24 subnet. The access list is then referenced in the ip nat inside source list command to specify which traffic should be translated.

Why this answer

To define the NAT source list, an access list must be created that matches the inside local addresses. The command access-list 1 permit 192.168.1.0 0.0.0.255 accomplishes this by permitting the entire 192.168.1.0/24 subnet. This list is then referenced in the ip nat inside source list command to enable translation.

Exam trap

The trap here is confusing the access list that defines the source addresses with the NAT translation command that references it, leading to selecting the latter as the answer.

587
MCQmedium

Consider the following configuration: router bgp 65000 bgp router-id 192.168.0.1 neighbor 10.0.0.2 remote-as 65001 neighbor 10.0.0.2 ebgp-multihop 2 neighbor 10.0.0.2 update-source Loopback0 ! interface Loopback0 ip address 192.168.0.1 255.255.255.255 What is missing for this BGP session to establish?

A.A route to reach 10.0.0.2 is missing; the neighbor must be reachable via the routing table.
B.The ebgp-multihop value should be 1 for a directly connected neighbor.
C.The remote-as must be the same as the local AS for EBGP.
D.The router-id must be the same as the update-source interface IP.
AnswerA

BGP establishes sessions over TCP port 179, so the router must have a valid route to 10.0.0.2 in its IPv4 unicast routing table before attempting the connection. Without that route, packets destined for the neighbor are dropped, the TCP three-way handshake never completes, and the BGP session remains Idle. This would happen even if the neighbor has reachability to this router, because BGP requires bidirectional IP reachability.

Why this answer

For an eBGP session to establish, the neighbor IP address (10.0.0.2) must be reachable via the routing table. The configuration uses `ebgp-multihop 2` and an update-source of Loopback0, but there is no route (static or dynamic) to reach 10.0.0.2, so the TCP connection cannot be initiated. Without reachability, BGP will remain in the Idle state.

Exam trap

Cisco often tests the misconception that ebgp-multihop alone ensures connectivity, but the trap here is that candidates forget BGP requires IP reachability in the routing table for the neighbor address, not just a configured multihop value.

How to eliminate wrong answers

Option B is wrong because ebgp-multihop 2 is correctly used when the neighbor is not directly connected (e.g., using loopback interfaces); setting it to 1 would assume a directly connected interface, which is not the case here. Option C is wrong because for eBGP, the remote-as must be different from the local AS (65000 vs 65001), so stating it must be the same is incorrect. Option D is wrong because the router-id does not need to match the update-source interface IP; the router-id is used for BGP identifier purposes and can be any unique IP, while the update-source specifies which interface's IP to use for the TCP connection.

588
Drag & Dropmedium

Drag and drop the steps of Netmiko multi-threaded device polling workflow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The workflow begins by importing required modules (threading and Netmiko), defining a function for device connection and command execution, creating a list of devices, then using threading.Thread to spawn threads for each device, and finally joining threads to wait for completion.

589
Drag & Dropmedium

Drag and drop the steps of Ansible Tower (AWX) job template execution steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

In Ansible Tower/AWX, a job template execution starts with creating the template, launching it, which triggers inventory and credential resolution, then the playbook runs, and finally the job output is displayed for review.

590
MCQmedium

A network engineer is designing a high-availability campus network using Cisco StackWise Virtual. The engineer wants to ensure that if the virtual link fails, the switches do not both become active and cause a split-brain scenario. Which mechanism should be implemented to detect and prevent a dual-active situation?

A.Enable PAgP on the virtual link to detect dual-active condition.
B.Enable BFD on the virtual link to rapidly detect failures.
C.Configure VRRP on the switches to monitor the virtual link.
D.Configure a separate physical link as a dual-active detection link and enable dual-active detection.
AnswerD

In StackWise Virtual, a dual-active detection link is a separate physical connection between the two switches that is used to detect a virtual link failure. When the virtual link fails, the switches use this link to determine which switch should remain active. Configuring this link and enabling dual-active detection prevents both switches from becoming active and causing a split-brain.

Why this answer

StackWise Virtual uses a dual-active detection link to prevent a split-brain scenario. This is a separate physical link between the two switches that is used to detect a virtual link failure. When the virtual link fails, the switches communicate over the dual-active detection link to determine which switch should remain active.

Configuring this link and enabling dual-active detection is the correct approach.

Exam trap

The trap here is confusing dual-active detection with other protocols like PAgP, VRRP, or BFD, which serve different purposes and do not prevent a split-brain in StackWise Virtual.

591
Drag & Dropmedium

Drag and drop the steps of syslog message generation and storage into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

A process or kernel generates a syslog message with a facility and severity, the syslogd daemon compares the severity to the configured logging level, then writes the message to the local buffer, optionally forwards it to a remote syslog server, and finally the message is stored or displayed.

592
Drag & Dropmedium

Drag and drop the steps of MPLS L2VPN (AToM) pseudowire setup into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

AToM pseudowire setup starts with configuring the attachment circuit on both PE routers. Then a pseudowire class is defined, specifying encapsulation and control word. The VC label is signaled via LDP, and the pseudowire is bound to the attachment circuit.

Finally, the pseudowire becomes operational and forwards L2 frames.

593
MCQmedium

A network engineer is designing an EIGRP network with multiple routers. The network has a core layer where all routers are fully meshed. The engineer wants to ensure that if a link fails, EIGRP converges quickly without relying on route redistribution or static routes. The engineer configures EIGRP with default timers. However, during a failure simulation, convergence takes over 15 seconds. What is the most likely reason?

A.EIGRP is using passive interfaces on the core routers, preventing rapid updates.
B.The failed link was the only feasible successor for the affected routes, causing EIGRP to go into active state and query neighbors.
C.EIGRP hold timers are set to 180 seconds by default, causing slow detection.
D.The engineer configured 'eigrp stub' on the core routers, which prevents query propagation.
AnswerB

EIGRP uses DUAL to maintain a feasible successor for each route. When the only feasible successor for a set of routes fails, EIGRP marks those routes active and sends QUERY packets to all neighbors, which may propagate transitively across the network. The router must wait for every REPLY before computing new routes, and in a large network, this query/reply cycle can easily exceed 15 seconds, causing the observed slow convergence. This active-state process is a classic cause of slow EIGRP convergence.

Why this answer

When the only feasible successor (FS) for a route fails, EIGRP cannot perform a local recomputation and must transition the route to the active state. It then sends query packets to all neighbors to find an alternative path, which introduces significant delay due to the need to wait for replies from every neighbor in a fully meshed core. With default timers, this query/reply process can easily exceed 15 seconds, especially if any neighbor is slow to respond.

Exam trap

Cisco often tests the misconception that EIGRP convergence is always fast due to its DUAL algorithm, but the trap here is that without a feasible successor, the active query process can cause significant delays, especially in a fully meshed network.

How to eliminate wrong answers

Option A is wrong because passive interfaces suppress the sending of EIGRP hellos and updates, which would prevent neighbor formation entirely, not just slow convergence; the scenario implies neighbors are established. Option C is wrong because the default EIGRP hold timer is 15 seconds (not 180 seconds), and even if it were longer, the failure detection delay alone would not account for a 15-second convergence time when the primary issue is query propagation. Option D is wrong because configuring 'eigrp stub' on core routers would actually speed convergence by preventing query propagation, not slow it; stubs do not propagate queries, so they reduce the active-state delay.

594
MCQmedium

A network administrator is deploying a new Cisco Catalyst switch and wants to enable a feature that provides per-port MAC address limiting to prevent MAC flooding attacks. The administrator also wants to ensure that when the limit is exceeded, the port is err-disabled. Which command set accomplishes this?

A.switchport port-security maximum 5, switchport port-security violation shutdown
B.switchport port-security, switchport port-security maximum 5, switchport port-security violation restrict
C.switchport port-security, switchport port-security maximum 5, switchport port-security violation shutdown
D.switchport port-security, switchport port-security maximum 5, switchport port-security violation protect
AnswerC

Enabling port security with switchport port-security, setting the maximum number of MAC addresses, and configuring the violation action to shutdown causes the port to err-disable when the limit is exceeded. This directly meets the requirement to limit MAC addresses per port and shut down on violation. The commands are applied in interface configuration mode.

Why this answer

To limit MAC addresses per port and err-disable the port on violation, the administrator must enable port security, set the maximum, and configure the shutdown violation mode. The shutdown mode places the port into an err-disabled state when the limit is exceeded, which is exactly what the scenario requires.

Exam trap

The trap here is selecting restrict or protect violation modes, which do not err-disable the port, instead of shutdown, which does.

595
MCQhard

A network engineer is configuring QoS on a Cisco IOS XE router. The router must mark all ingress traffic from a specific subnet with DSCP AF31 and ensure that this marking is trusted throughout the network. Which configuration step is required to achieve this?

A.Apply a policy map that sets DSCP AF31 as an output service policy on the router's uplink interface.
B.Create a class map matching the subnet, then a policy map that sets DSCP AF31, and apply it as a service policy on the ingress interface.
C.Configure 'mls qos trust dscp' on the ingress interface and rely on the subnet's existing markings.
D.Use a route map to set DSCP AF31 for all routes matching the subnet and redistribute into OSPF.
AnswerB

To mark traffic from a subnet, you must classify it with a class map, define the marking action in a policy map using 'set dscp af31', and attach the policy to the ingress interface with 'service-policy input'. This ensures packets are marked at ingress, and subsequent devices can trust the DSCP if configured to do so.

Why this answer

To mark traffic from a specific subnet with DSCP AF31, you need a class map to identify the traffic, a policy map to set the DSCP, and the policy applied as an ingress service policy. This ensures packets are marked before any queuing or forwarding decisions, allowing downstream devices to trust and act on the marking.

Exam trap

The trap here is confusing QoS marking with trusting markings; trusting DSCP only preserves existing values and does not mark unmarked traffic.

596
MCQeasy

A network administrator is configuring a Cisco IOS router to use VRRP. The router should be the master for the virtual IP 192.168.1.1 on interface GigabitEthernet0/0. The administrator wants to ensure that if this router fails, another router takes over with minimal delay. Which command should be used to set the priority to 150?

A.vrrp 1 priority 150 preempt
B.vrrp 1 preempt priority 150
C.standby 1 priority 150
D.vrrp 1 priority 150
AnswerD

The command vrrp 1 priority 150 sets the VRRP priority to 150 for group 1 on the interface. A higher priority makes the router more likely to become the master. The default priority is 100, and the range is 1–254. Priority 150 is higher than default, so this router will become master if it is the highest priority in the group. This command is entered in interface configuration mode.

Why this answer

The command vrrp 1 priority 150 correctly sets the VRRP priority to 150 for group 1. A higher priority increases the chance of becoming the master. The default priority is 100, and the range is 1–254.

Preemption is enabled by default, so no additional command is needed. This ensures the router becomes master and takes over quickly if needed.

Exam trap

The trap here is mixing up VRRP and HSRP commands; the standby command is for HSRP, while VRRP uses the vrrp command.

597
MCQmedium

An engineer is configuring a Cisco Catalyst switch with VXLAN to extend Layer 2 connectivity between two data centers. The switch will act as a VXLAN Tunnel Endpoint (VTEP) and must encapsulate traffic from VLAN 10 into VXLAN VNI 10010. Which command is required to map the VLAN to the VNI?

A.vxlan vlan 10 vni 10010
B.interface vlan 10: vxlan vni 10010
C.vlan configuration 10: vn-segment 10010
D.vxlan vni 10010 vlan 10
AnswerC

This is the correct command to map a VLAN to a VXLAN VNI on a Cisco Catalyst switch. Under 'vlan configuration 10', the 'vn-segment 10010' command associates VLAN 10 with VNI 10010. This enables the VTEP to encapsulate frames from VLAN 10 into VXLAN packets with VNI 10010, allowing Layer 2 extension across the IP network.

Why this answer

To map a VLAN to a VXLAN VNI on a Cisco Catalyst switch, the engineer must enter VLAN configuration mode for the specific VLAN and use the 'vn-segment' command. This creates the association that allows the VTEP to encapsulate traffic from that VLAN into VXLAN packets with the specified VNI. Other command forms are invalid or apply to different platforms.

Exam trap

The trap here is confusing the SVI configuration with VXLAN VLAN-to-VNI mapping, or using syntax from other vendors or platforms.

598
MCQmedium

A network engineer is configuring OSPF on a multiaccess network. The engineer wants to ensure that only two specific routers become DR and BDR, and that other routers do not participate in the election. Which OSPF interface setting should be configured on the routers that should not become DR or BDR?

A.ip ospf database-filter all out
B.ip ospf network point-to-point
C.ip ospf priority 1
D.ip ospf priority 0
AnswerD

Setting the OSPF priority to 0 on an interface makes that router ineligible to become DR or BDR. This is the correct way to prevent a router from participating in the DR/BDR election. The router will still form adjacencies and exchange routing information, but it will remain a DROTHER. This setting is commonly used on routers that should not be DR/BDR, such as those with lower processing power or at the edge of the network.

Why this answer

Setting OSPF priority to 0 on an interface makes the router ineligible to become DR or BDR. This is the standard method to exclude routers from the election while still allowing them to participate in OSPF as DROTHERs. Other options either do not affect eligibility or change the network type entirely.

Exam trap

The trap here is thinking that any priority value other than 0 can exclude a router, when only 0 makes it ineligible.

599
MCQhard

A network engineer is implementing QoS on a Cisco IOS router. The engineer wants to ensure that VoIP traffic is marked with DSCP EF and that the router prioritizes this traffic during congestion. Which mechanism should be used to provide priority queuing for VoIP?

A.Class-Based Weighted Fair Queuing (CBWFQ)
B.Weighted Random Early Detection (WRED)
C.Traffic Shaping
D.Low Latency Queuing (LLQ)
AnswerD

LLQ combines CBWFQ with a strict priority queue. It allows VoIP traffic to be placed in a priority queue that is serviced before other queues, ensuring minimal delay and jitter. LLQ is the recommended mechanism for prioritizing real-time traffic like VoIP during congestion.

Why this answer

LLQ is the QoS mechanism that provides strict priority queuing, ensuring that VoIP traffic marked with DSCP EF is serviced before other traffic during congestion. This minimizes latency and jitter, which are critical for voice quality. LLQ is configured using the 'priority' command within a policy map.

Exam trap

The trap here is assuming that CBWFQ alone can provide priority, when it only guarantees bandwidth without strict priority.

600
MCQmedium

A network engineer runs the following command on Switch SW1: SW1# show etherchannel summary Flags: D - down P - bundled in port-channel I - stand-alone s - suspended H - Hot-standby (LACP only) R - Layer3 S - Layer2 U - in use N - not in use, no aggregation f - failed to allocate aggregator M - not in use, minimum links not met u - unsuitable for bundling w - waiting to be aggregated d - default port Number of channel-groups in use: 1 Number of aggregators: 1 Group Port-channel Protocol Ports ------+-------------+-----------+-------------------------------------------- 1 Po1(SU) LACP Gi0/1(P) Gi0/2(P) Gi0/3(D) Based on this output, what can be concluded?

A.The EtherChannel is using PAgP.
B.Port Gi0/3 is bundled in the channel.
C.The port-channel is a Layer 3 interface.
D.The EtherChannel has two active member links.
AnswerD

The EtherChannel has two active member links. The 'P' flag appears on both Gi0/1 and Gi0/2, indicating that exactly two physical interfaces are bundled into the port-channel and are actively forwarding traffic. Since no other ports display the 'P' flag, the EtherChannel is active with two member links. Other ports, such as Gi0/3, show 'D' and are not part of the operational bundle, confirming the two-link count.

Why this answer

The output shows that Gi0/1 and Gi0/2 have a flag of 'P' (bundled in port-channel), while Gi0/3 has a flag of 'D' (down). Therefore, only two ports are actively bundled, making option D correct. The 'SU' flags on Po1 indicate the port-channel is Layer 2 (S) and in use (U), not Layer 3.

Exam trap

Cisco often tests the interpretation of the 'show etherchannel summary' flags, where candidates mistakenly assume a port listed in the output is active, ignoring the specific flag character (e.g., 'D' vs 'P').

How to eliminate wrong answers

Option A is wrong because the protocol column explicitly shows 'LACP', not PAgP. Option B is wrong because Gi0/3 has a flag of 'D' (down), not 'P' (bundled), meaning it is not part of the active bundle. Option C is wrong because the 'S' in 'Po1(SU)' indicates Layer 2, not Layer 3 (which would be 'R').

Page 7

Page 8 of 26

Page 9