Courseiva

ENCOR 350-401 (350-401) — Questions 601–675

1923 questions total · 26pages · All types, answers revealed

Page 8

Page 9 of 26

Page 10
601
MCQeasy

A REST API call is made to Cisco DNA Center to get the list of network devices: GET /dna/intent/api/v1/network-device Headers: X-Auth-Token: <token> The response is: { "response": [ { "id": "123456", "managementIpAddress": "10.10.10.1", "platformId": "C9300-24P", "role": "ACCESS" } ], "version": "1.0" } What does this response indicate?

A.The response contains a single device with management IP 10.10.10.1 and role ACCESS.
B.The response indicates an error because the 'version' field is missing a value.
C.The response contains multiple devices, but only one is shown due to pagination.
D.The response requires authentication because the token is missing.
AnswerA

The JSON response is an array with exactly one object, and that object contains a management IP address of 10.10.10.1 and a role set to ACCESS. This indicates the Ansible task queried the device inventory and successfully retrieved a single device record. Because the array length is one, there is no ambiguity about multiple devices.

Why this answer

The response is a valid JSON object from Cisco DNA Center's REST API. The 'response' array contains one device object with fields 'id', 'managementIpAddress', 'platformId', and 'role'. The 'version' field is informational and correctly present.

Therefore, option A correctly interprets the response as containing a single device with management IP 10.10.10.1 and role ACCESS.

Exam trap

Cisco often tests the misconception that a missing or incomplete 'version' field indicates an error, but in reality, the 'version' field is always present and valid in successful DNA Center API responses.

How to eliminate wrong answers

Option B is wrong because the 'version' field is present with a value of '1.0', so it is not missing; the response is valid. Option C is wrong because the response shows a single object in the 'response' array, not multiple devices; pagination would be indicated by additional fields like 'totalCount' or 'pageSize', which are absent. Option D is wrong because the request includes the 'X-Auth-Token' header with a token value, so authentication is already provided; the response does not indicate any authentication error.

602
Drag & Dropmedium

Drag and drop the steps of Netconf/Yang-based device monitoring subscription into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First establish NETCONF session, then subscribe to YANG data, then receive periodic updates, and finally unsubscribe.

603
MCQhard

A company is deploying a new wireless network in a large warehouse. The network engineer must choose between using a centralized WLC architecture (with CAPWAP tunnels) or a converged access (SD-Access) wireless architecture. The warehouse has high-density client areas and requires low latency for real-time applications like voice and video. Which architecture should the engineer choose and why?

A.Centralized WLC architecture, because it provides better RF management and security.
B.Converged access (SD-Access) wireless, because it allows local switching of traffic at the access layer, reducing latency.
C.Centralized WLC architecture, because it requires fewer access points to cover the warehouse.
D.Converged access (SD-Access) wireless, because it requires fewer WLCs to manage the network.
AnswerB

Converged access (SD-Access) wireless is correct because fabric-enabled access points can switch data traffic locally at the access layer rather than tunneling it to a central WLC. The WLC still handles control-plane functions like radio resource management, but user data moves directly toward the fabric edge, which minimizes network delay and jitter for real-time applications. This local switching is exactly what makes SD-Access wireless preferable for a warehouse with latency-sensitive traffic.

Why this answer

Converged access (SD-Access) wireless enables local switching of traffic at the access layer, which eliminates the need to hairpin traffic through a centralized WLC. This reduces latency significantly, which is critical for real-time applications like voice and video in high-density warehouse environments. Centralized CAPWAP tunnels would add unnecessary delay by forcing all traffic back to the WLC.

Exam trap

Cisco often tests the misconception that centralized WLC is always better for RF management and security, but the trap here is ignoring the latency requirements of real-time applications, which favor local switching in SD-Access wireless.

How to eliminate wrong answers

Option A is wrong because while centralized WLC architecture does provide centralized RF management and security, it introduces higher latency due to CAPWAP encapsulation and hairpinning of all traffic to the WLC, which is detrimental to real-time voice and video. Option C is wrong because the number of access points required is determined by coverage and capacity needs, not the architecture choice; centralized WLC does not inherently require fewer APs. Option D is wrong because converged access (SD-Access) wireless does not necessarily reduce the number of WLCs; it may even require additional fabric controllers, and the primary benefit is local switching, not WLC count reduction.

604
MCQmedium

Consider the following configuration on a Cisco IOS-XE switch: interface GigabitEthernet1/0/1 switchport mode access authentication port-control auto dot1x pae authenticator dot1x timeout tx-period 5 spanning-tree portfast What is the effect of this configuration?

A.The port will immediately transition to forwarding state and then wait for authentication.
B.The switch will act as an 802.1X authenticator and the port will be unauthorized until a successful authentication.
C.The port will be placed in a VLAN assigned by the RADIUS server after authentication.
D.The switch will act as a supplicant and respond to EAP requests from an upstream authenticator.
AnswerB

The 'dot1x pae authenticator' command configures the switch port to operate as the 802.1X authenticator, meaning it initiates and manages EAP exchanges with the connected client (supplicant). The 'authentication port-control auto' setting explicitly places the port in the unauthorized state initially, allowing only EAPOL traffic to flow. Only after the client successfully authenticates against the configured authentication method (e.g., RADIUS) does the controlled port transition to the authorized state and forward normal data traffic.

Why this answer

The configuration enables 802.1X authentication on the port with `authentication port-control auto`, making the port start in the unauthorized state. The `dot1x pae authenticator` command configures the switch as the authenticator (not a supplicant). The `spanning-tree portfast` command allows the port to transition to forwarding quickly after authentication succeeds, but until then, the port remains unauthorized and blocks traffic.

Option B correctly states that the switch acts as an authenticator and the port is unauthorized until successful authentication.

Exam trap

Cisco often tests the distinction between authenticator and supplicant roles, and the trap here is that candidates confuse `dot1x pae authenticator` with a supplicant configuration or assume that `spanning-tree portfast` overrides the unauthorized state, leading them to pick Option A or D.

How to eliminate wrong answers

Option A is wrong because the port does not immediately transition to forwarding; it remains in the unauthorized state until 802.1X authentication completes, and `spanning-tree portfast` only speeds up the transition after authentication succeeds. Option C is wrong because the configuration does not include any RADIUS-assigned VLAN commands (such as `authentication fallback` or `vlan assignment`), and the port is configured as a static access port without dynamic VLAN assignment. Option D is wrong because the `dot1x pae authenticator` command explicitly sets the switch to act as an authenticator, not a supplicant; a supplicant role would require `dot1x pae supplicant` or similar.

605
Multi-Selectmedium

A network security team is hardening a Cisco IOS XE router that terminates IPsec tunnels to remote branch offices. The team wants to use zone-based firewall (ZBFW) to inspect traffic between the inside, outside, and VPN zones. Which two statements correctly describe zone-based firewall behavior on this platform? (Choose two.)

Select 2 answers
A.Applying an inspect action to a zone pair automatically creates a reverse zone pair for return traffic.
B.Traffic between two interfaces assigned to the same zone is implicitly permitted and not inspected by the zone policy.
C.Interfaces not assigned to any zone are treated as members of the self zone and inspected.
D.Traffic between two zones with no configured zone pair is implicitly denied by default.
E.A zone pair must be configured bidirectionally; a single zone pair covers traffic in both directions automatically.
AnswersB, D

ZBFW treats all interfaces in the same zone as a single trust domain, so intra-zone traffic is not inspected and is permitted by default. This design simplifies policy by letting administrators define inspection only for inter-zone flows. In this scenario, if two branch-facing interfaces were both in the VPN zone, traffic between them would bypass inspection, which is a key behavior to understand when designing zone membership.

Why this answer

ZBFW permits intra-zone traffic without inspection and denies inter-zone traffic by default unless a zone pair with a policy exists. Zone pairs are unidirectional, inspection handles return traffic for established sessions, and unassigned interfaces use classic ACL behavior rather than joining the self zone. These behaviors drive how the branch router's inside, outside, and VPN zones must be paired and inspected.

Exam trap

The trap here is assuming a single zone pair inspects traffic in both directions, when zone pairs are unidirectional and return traffic is handled by the stateful inspect action.

606
MCQmedium

interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip ospf network broadcast ip ospf priority 0 ! router ospf 1 network 192.168.1.0 0.0.0.255 area 0 What is the effect of setting the OSPF priority to 0 on this interface?

A.The router will never become the DR or BDR on this segment.
B.The router will have a higher chance of becoming the DR.
C.The router will only form adjacencies with other routers that have priority 0.
D.The router will use a longer hello interval.
AnswerA

In OSPF broadcast multiaccess networks, the DR/BDR election is governed by the interface priority field, which ranges from 0 to 255. Setting a priority of 0 explicitly marks the router as ineligible to participate in the election, so it can never be selected as the DR or BDR, regardless of its Router ID or any other factor. The router remains fully operational as a DROther and still establishes adjacencies with the DR and BDR.

Why this answer

Setting the OSPF priority to 0 on an interface prevents the router from participating in the Designated Router (DR) and Backup Designated Router (BDR) election process. This means the router will never become the DR or BDR on that broadcast segment, as per RFC 2328. It will instead remain a DROTHER and only form full adjacencies with the DR and BDR, not with other DROTHER routers.

Exam trap

Cisco often tests the misconception that priority 0 means 'lowest priority' or 'least likely to become DR,' when in fact it means 'ineligible to become DR or BDR' — a binary disqualification, not a comparative value.

How to eliminate wrong answers

Option B is wrong because a priority of 0 eliminates the chance of becoming DR, not increases it; higher priority values (1-255) increase the chance. Option C is wrong because OSPF routers with priority 0 still form adjacencies with the DR and BDR, not only with other priority 0 routers; DROTHER routers do not form full adjacencies with each other. Option D is wrong because the hello interval is configured independently via the 'ip ospf hello-interval' command and is not affected by the priority setting.

607
MCQeasy

A network engineer is planning to use Cisco DNA Center to automate the deployment of a new branch office. The engineer has already discovered the devices and added them to Inventory. The engineer wants to use a template to configure the devices consistently. Which tool in DNA Center should the engineer use to create and apply the template?

A.Use the 'Template Editor' to create a CLI template and apply it during provisioning.
B.Use the 'Policy Editor' to create a policy-based configuration.
C.Use the 'Command Runner' to execute commands on multiple devices.
D.Use the 'Network Profiles' to define the configuration.
AnswerA

Template Editor is DNA Center's dedicated tool for authoring CLI templates with variables, then binding them to devices during provisioning. Since discovery and Inventory are complete, this satisfies the consistency requirement by applying the same configuration template across the new branch devices.

Why this answer

The Template Editor in Cisco DNA Center is specifically designed for creating reusable CLI templates that can be applied to devices during provisioning. It allows engineers to define variables and conditional logic, ensuring consistent configuration across multiple devices. This tool is part of the Design > Templates workflow and integrates directly with the provisioning process, making it the correct choice for automating branch office deployments.

Exam trap

The trap here is confusing the Template Editor with other DNA Center tools like Policy Editor or Command Runner, which serve different purposes; candidates might assume any tool that pushes configuration can create templates, but only the Template Editor is designed for reusable CLI templates.

How to eliminate wrong answers

Option B is wrong because the Policy Editor is used for creating policy-based configurations for SD-Access fabrics, such as group-based policies and access control, not for CLI template creation. Option C is wrong because Command Runner is a tool for executing ad-hoc show or diagnostic commands on multiple devices simultaneously, not for creating and applying configuration templates. Option D is wrong because Network Profiles are used to define site-specific settings like device credentials, SNMP, and syslog, but they do not create or apply configuration templates.

608
MCQmedium

Examine the following configuration: interface Port-channel1 switchport mode trunk ! interface GigabitEthernet0/1 switchport mode trunk channel-group 1 mode active spanning-tree portfast ! interface GigabitEthernet0/2 switchport mode trunk channel-group 1 mode active spanning-tree portfast What is the effect of the 'spanning-tree portfast' command on the member interfaces of this EtherChannel?

A.The PortFast will be applied to the EtherChannel, causing it to immediately transition to forwarding.
B.The PortFast on the member interfaces will be ignored because they are part of an EtherChannel.
C.The PortFast will cause the EtherChannel to form faster.
D.The configuration will cause a spanning-tree loop because PortFast is used on trunk ports.
AnswerB

When interfaces are grouped into an EtherChannel, the software creates a single logical port-channel interface that represents the entire bundle. STP treats this logical port-channel as the spanning-tree port, and per-interface STP parameters on the physical member links are effectively overridden and ignored. The member interfaces are not independent STP ports; they are just physical paths within the aggregated link. Therefore, PortFast configured on the members has no effect on the STP state of the EtherChannel, making this statement correct.

Why this answer

When interfaces are configured as members of an EtherChannel, any spanning-tree configuration applied directly to the member interfaces (such as 'spanning-tree portfast') is ignored. Spanning-tree operates on the logical port-channel interface, not the individual physical members. Therefore, the PortFast command on GigabitEthernet0/1 and GigabitEthernet0/2 has no effect; instead, PortFast must be configured on the Port-channel interface itself to apply to the bundle.

Exam trap

Cisco often tests the misconception that STP features configured on physical interfaces are inherited by the EtherChannel, when in fact they are ignored and must be applied to the logical port-channel interface.

How to eliminate wrong answers

Option A is wrong because PortFast is not applied to the EtherChannel from the member interfaces; it is ignored, so the EtherChannel does not immediately transition to forwarding. Option C is wrong because PortFast on member interfaces does not cause the EtherChannel to form faster; EtherChannel formation depends on LACP or PAgP negotiation, not PortFast. Option D is wrong because using PortFast on trunk ports does not inherently cause a spanning-tree loop; loops are prevented by spanning-tree itself, and PortFast simply bypasses the listening/learning states on access or trunk ports (with caution), but here it is ignored entirely.

609
Multi-Selectmedium

Which THREE of the following are valid considerations when planning a wireless network for high-density environments?

Select 3 answers
A.Use a channel reuse plan that minimizes co-channel interference.
B.Prefer the 5 GHz band over 2.4 GHz for client connectivity.
C.Lower AP transmit power to reduce cell size and increase capacity.
D.Increase AP transmit power to maximize coverage.
E.Enable 2.4 GHz band only to maximize range.
AnswersA, B, C

In a high-density wireless design, co-channel interference is the primary limiting factor because all APs on the same channel share the medium. A channel reuse plan ensures that APs operating on the same non-overlapping channel are separated by enough physical distance, often using different channels for adjacent cells. This spatial reuse maximizes aggregate throughput by allowing more simultaneous transmissions.

Why this answer

A channel reuse plan that minimizes co-channel interference is essential in high-density environments to ensure that adjacent access points (APs) do not use the same or overlapping channels, which would degrade throughput. By carefully planning channel assignments (e.g., using non-overlapping channels in the 5 GHz band), you maximize spatial reuse and overall network capacity.

Exam trap

Cisco often tests the misconception that increasing AP transmit power always improves coverage and performance, when in fact, in high-density environments, lowering power and reducing cell size is the correct strategy to increase capacity and minimize interference.

610
MCQeasy

A network engineer is new to automation and wants to use a simple, agentless tool to push configuration changes to a group of Cisco IOS XE switches. The engineer prefers to write playbooks in YAML and use SSH for connectivity. Which tool should the engineer choose?

A.Ansible
B.Puppet
C.SaltStack
D.Chef
AnswerA

Ansible is an agentless automation tool that uses SSH to connect to managed devices. It uses YAML-based playbooks, which match the engineer's preference. For Cisco IOS XE, Ansible provides modules like ios_config and ios_command that run over SSH. This makes Ansible the ideal choice for simple, agentless configuration management with YAML playbooks.

Why this answer

Ansible is an agentless automation tool that uses SSH for connectivity and YAML for playbooks. It provides dedicated modules for Cisco IOS XE, such as ios_config and ios_command, enabling straightforward configuration pushes. The engineer's requirements for agentless operation, YAML playbooks, and SSH align perfectly with Ansible's design, making it the correct choice among the options.

Exam trap

The trap here is assuming that any configuration management tool can use YAML and SSH, when only Ansible natively combines both for agentless network automation.

611
MCQeasy

A network administrator is configuring a Cisco Catalyst switch and needs to assign a port to VLAN 20 as an access port. Which command sequence is correct?

A.interface GigabitEthernet0/1, then switchport mode access, then switchport access vlan 20
B.interface GigabitEthernet0/1, then switchport mode trunk, then switchport trunk vlan 20
C.interface GigabitEthernet0/1, then switchport access vlan 20, then switchport mode access
D.vlan 20, then interface GigabitEthernet0/1, then switchport access vlan 20
AnswerA

This sequence enters interface configuration mode, sets the port to access mode, and assigns it to VLAN 20. The switchport mode access command ensures the port operates as an access port, and switchport access vlan 20 places it in the correct VLAN. This is the standard method to configure an access port on a Cisco Catalyst switch.

Why this answer

To assign a switch port to a specific VLAN as an access port, you must enter interface configuration mode, set the port to access mode with switchport mode access, and then assign the VLAN with switchport access vlan 20. This ensures the port operates correctly as an access port in the desired VLAN.

Exam trap

The trap here is forgetting to set the port to access mode first, which can cause the port to remain in dynamic mode and potentially negotiate a trunk.

612
MCQhard

A network engineer is implementing VXLAN with BGP EVPN on Cisco Nexus switches. The underlay network is OSPF, and the overlay uses MP-BGP EVPN. The engineer wants to ensure that the VXLAN tunnel endpoints (VTEPs) can discover each other and exchange MAC and IP address information. Which statement correctly describes the role of the BGP EVPN address family in this scenario?

A.It provides a routing underlay for the VXLAN tunnels by advertising VTEP loopback addresses.
B.It synchronizes the MAC address tables of all VTEPs by flooding unknown unicast traffic.
C.It encapsulates the original Ethernet frames into VXLAN packets and forwards them across the underlay.
D.It distributes MAC and IP address reachability information for hosts and enables VTEP peer discovery.
AnswerD

The BGP EVPN address family carries MAC and IP address reachability information in the form of EVPN routes, such as Type 2 and Type 5 routes. This allows VTEPs to learn about remote hosts and VTEPs, facilitating the creation of VXLAN tunnels and enabling efficient forwarding without flooding.

Why this answer

The BGP EVPN address family is used to distribute MAC and IP address reachability information across VTEPs. This enables control plane learning, reducing flooding and allowing VTEPs to discover remote hosts and VTEPs. The other options incorrectly attribute underlay routing, data plane encapsulation, or flooding-based learning to BGP EVPN.

Exam trap

The trap here is assuming that BGP EVPN handles encapsulation or underlay routing, when it is actually an overlay control plane protocol for distributing host reachability.

613
MCQhard

A network automation team uses a Python script with the ncclient library to configure a Cisco IOS XE router via NETCONF. The script sends an <edit-config> RPC with a candidate datastore, but the router returns an error indicating the candidate datastore is not supported. The team wants to make configuration changes without affecting the running configuration until they are verified. Which NETCONF capability should the team ensure is enabled on the router to allow this workflow?

A.:writable-running
B.:rollback-on-error
C.:confirmed-commit
D.:candidate
AnswerD

The :candidate capability indicates support for a candidate configuration datastore, which allows changes to be staged and validated before being committed to the running configuration. Without this capability, the router cannot accept edits to a candidate datastore, resulting in the error. Enabling :candidate enables the desired workflow of testing configurations before applying them.

Why this answer

To use a candidate datastore for staging configuration changes, the NETCONF server must support the :candidate capability. This allows the client to edit the candidate configuration, validate it, and then commit it to the running configuration. Other capabilities like :confirmed-commit and :rollback-on-error enhance commit behavior but require :candidate as a prerequisite.

Thus, enabling :candidate is necessary.

Exam trap

The trap here is assuming that :writable-running allows staging changes without impact, but it directly modifies the running configuration, which is not the desired workflow.

614
Multi-Selectmedium

A network security team is evaluating Cisco TrustSec (CTS) for deployment in a campus network. The team wants to understand which components are essential for enforcing security group tags (SGTs) and providing role-based access control. Which two of the following are required to implement CTS with SGT enforcement? (Choose two.)

Select 2 answers
A.Cisco AnyConnect Network Access Manager for endpoint posture
B.Dynamic Host Configuration Protocol (DHCP) snooping
C.Cisco Identity Services Engine (ISE) for policy and SGT assignment
D.Spanning Tree Protocol (STP) for loop prevention
E.Inline tagging or SGT Exchange Protocol (SXP) for tag propagation
AnswersC, E

Cisco ISE is the policy engine that assigns SGTs to users and devices during authentication. It also defines security group ACLs (SGACLs) that determine what traffic is permitted between groups. Without ISE, dynamic SGT assignment and centralized policy management are not possible, making it a fundamental component of CTS.

Why this answer

Implementing Cisco TrustSec requires a policy engine to assign SGTs and a method to propagate those tags. Cisco ISE provides the centralized policy and SGT assignment, while inline tagging or SXP ensures that SGTs are carried across network devices. Together, they enable enforcement of SGACLs.

STP, DHCP snooping, and AnyConnect NAM are not essential for SGT-based access control, though they may be used in a broader security architecture.

Exam trap

The trap here is confusing general security features like DHCP snooping or AnyConnect with the core components required for CTS SGT enforcement.

615
MCQeasy

A network administrator is configuring a Cisco Catalyst switch to support a new VLAN 200 for a guest network. The administrator wants to ensure that VLAN 200 is created and active on the switch. Which command should be used?

A.interface vlan 200
B.vlan database
C.vlan 200
D.switchport access vlan 200
AnswerC

The 'vlan 200' command in global configuration mode creates VLAN 200 and enters VLAN configuration mode. This is the correct way to create a VLAN on a Cisco Catalyst switch. After entering this command, the VLAN is active by default unless it is shutdown. This command is essential for adding a new VLAN to the switch's VLAN database.

Why this answer

To create a VLAN on a Cisco Catalyst switch, the 'vlan 200' command is used in global configuration mode. This command creates the VLAN and enters VLAN configuration mode, where additional parameters like name can be set. The VLAN is active by default.

Other commands like 'switchport access vlan' assign ports to the VLAN but do not create it, and 'interface vlan' creates an SVI, not the VLAN itself.

Exam trap

The trap here is confusing VLAN creation with port assignment or SVI creation, assuming that assigning a port to a VLAN automatically creates it.

616
MCQmedium

A network engineer runs the following command on Router R8: R8# show policy-map interface GigabitEthernet0/1 GigabitEthernet0/1 Service-policy output: QOS_POLICY Class-map: VOICE (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp ef (46) Queueing strict priority queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 police cir 1000000 bc 15625 be 15625 conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: DATA (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp af31 (26) Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 bandwidth remaining percent 50 Class-map: class-default (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 bandwidth remaining percent 50 Based on this output, what can be concluded?

A.Voice traffic is being prioritized but not policed.
B.The interface is not passing any traffic.
C.Data traffic is being dropped due to policing.
D.The policy-map is applied to input traffic.
AnswerB

This is correct because the output of `show policy-map interface` displays all class counters as zero, including classifications, bytes, and drops. A zero packet count across every class indicates that no packets have been classified or forwarded on this interface since the policy was attached. Therefore, the interface is not passing any traffic at all.

Why this answer

The output shows all counters at zero for every class, including the class-default, and the '5 minute offered rate' is 0 bps for all classes. This indicates that no packets have been processed by this policy-map on GigabitEthernet0/1, meaning the interface is not passing any traffic. The presence of policing and queuing configurations does not imply traffic is being dropped; the counters confirm zero activity.

Exam trap

Cisco often tests the ability to interpret zero counters in QoS output, trapping candidates who assume that configured policies (like policing or queuing) are actively dropping or shaping traffic without verifying the actual packet counts.

How to eliminate wrong answers

Option A is wrong because the output explicitly shows a police command under the VOICE class with a CIR of 1000000 bps, meaning voice traffic is both prioritized (strict priority queue) and policed. Option B is correct as explained. Option C is wrong because the DATA class shows zero packets, zero drops, and a drop rate of 0 bps, indicating no traffic has been processed, let alone dropped due to policing.

Option D is wrong because the output states 'Service-policy output: QOS_POLICY', which means the policy-map is applied in the output direction, not input.

617
MCQmedium

A network engineer runs the following command on Switch SW5: SW5# show running-config | section interface port-channel interface Port-channel1 switchport mode trunk switchport trunk allowed vlan 1-100,200-300 ! interface Port-channel2 switchport mode access switchport access vlan 10 ! SW5# show interfaces trunk Port Mode Encapsulation Status Native vlan Po1 on 802.1q trunking 1 Port Vlans allowed on trunk Po1 1-100,200-300 Port Vlans allowed and active in management domain Po1 1-100,200-300 Port Vlans in spanning tree forwarding state and not pruned Po1 1-100,200-300 Based on this output, what can be concluded?

A.Port-channel2 is also trunking but not displayed due to a software bug.
B.Port-channel1 is trunking and allowed VLANs include VLANs 101-199.
C.Port-channel1 is operational as a trunk with the configured allowed VLANs.
D.The native VLAN on Po1 is VLAN 10.
AnswerC

The output confirms Port-channel1 is in trunking mode, is operationally up, and its allowed VLAN list matches the configured VLANs of 1-100 and 200-300. The 'show interfaces trunk' command verifies that the port-channel is carrying traffic for the exact set of VLANs that were configured, with no unexpected additions or removals. This matches the correct operational state expected for a properly configured EtherChannel trunk.

Why this answer

The 'show interfaces trunk' output confirms that Port-channel1 is trunking with an operational status of 'trunking', and the 'Vlans allowed on trunk' line matches the configured allowed VLANs (1-100,200-300). This indicates the trunk is up and functioning with the intended VLAN list, making option C correct.

Exam trap

Cisco often tests the distinction between trunk and access port behavior, and the trap here is assuming that a port-channel with an access configuration will still appear in trunk output or that the native VLAN can be inferred from the access VLAN configuration.

How to eliminate wrong answers

Option A is wrong because Port-channel2 is configured as an access port (switchport mode access), so it will not appear in the 'show interfaces trunk' output, which only displays trunk ports; there is no software bug. Option B is wrong because the allowed VLANs explicitly exclude VLANs 101-199, as shown in the configuration and trunk output (only 1-100 and 200-300 are allowed). Option D is wrong because the native VLAN on Po1 is VLAN 1, as indicated by the 'Native vlan' column in the trunk output, not VLAN 10.

618
MCQhard

A network administrator is configuring a Cisco IOS XE device to send syslog messages to a remote server. The administrator wants to ensure that only messages with severity level 4 and higher (i.e., more severe) are sent. Which command should be used?

A.logging monitor 4
B.logging console 4
C.logging trap 4
D.logging buffered 4
AnswerC

The 'logging trap 4' command sets the syslog severity level for messages sent to the syslog server to level 4 (warnings). This means only messages with severity 4 and higher (0-4) will be sent, which matches the requirement. It is the correct command to limit syslog messages to the specified severity.

Why this answer

The 'logging trap' command specifically controls the severity level of messages sent to remote syslog servers. Setting it to 4 ensures that only messages with severity 4 and higher (more severe) are sent. The other commands control console, buffer, and monitor logging, which are local destinations and do not affect remote syslog.

Exam trap

The trap here is confusing the different logging destinations and using 'logging console' or 'logging buffered' instead of 'logging trap' for remote syslog.

619
MCQmedium

A network engineer is configuring a pair of Catalyst switches to run VRRP on VLAN 10 (10.10.10.0/24). The virtual IP must be 10.10.10.1 with a priority of 110 on the primary switch and 100 on the standby. The primary switch is currently active. Which configuration on the primary switch correctly sets the VRRP priority and virtual IP?

A.interface vlan 10 ip address 10.10.10.2 255.255.255.0 vrrp 10 ip 10.10.10.1 vrrp 10 priority 110
B.interface vlan 10 ip address 10.10.10.2 255.255.255.0 vrrp 10 ip 10.10.10.1 255.255.255.0 vrrp 10 priority 110
C.interface vlan 10 ip address 10.10.10.2 255.255.255.0 vrrp 10 ip 10.10.10.1 vrrp 10 priority 100
D.interface vlan 10 ip address 10.10.10.2 255.255.255.0 vrrp 10 virtual-ip 10.10.10.1 vrrp 10 priority 110
AnswerA

This configuration enters VLAN 10 SVI, assigns the physical IP 10.10.10.2, then enables VRRP group 10 with virtual IP 10.10.10.1 and priority 110. In VRRP, the highest priority becomes the master; 110 exceeds the default 100, making this switch the master. The syntax matches Cisco IOS VRRP commands exactly.

Why this answer

VRRP on Cisco IOS uses the `vrrp <group> ip <address>` command to define the virtual IP, and `vrrp <group> priority <value>` to set priority. The highest priority becomes the master. The correct configuration assigns the physical IP, defines the virtual IP 10.10.10.1, and sets priority 110, ensuring this switch becomes the master.

Other options contain invalid syntax or set the wrong priority.

Exam trap

The trap here is confusing VRRP command syntax with HSRP, such as using `virtual-ip` or including a subnet mask, which are not valid for VRRP.

620
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 10.0.0.2 1 FULL/DR 00:00:32 192.168.1.2 GigabitEthernet0/0 10.0.0.3 1 2WAY/DROTHER 00:00:35 192.168.1.3 GigabitEthernet0/0 Based on this output, what can be concluded?

A.R1 is the Backup Designated Router (BDR) on this segment.
B.R1 has a full OSPF adjacency with the neighbor 10.0.0.3.
C.R1 is a DROTHER on this segment.
D.The OSPF network type is point-to-point.
AnswerC

R1's interface shows 2WAY/DROTHER with neighbour 10.0.0.3, and FULL/DR with 10.0.0.2, meaning R1 formed full adjacency only with the DR. On a broadcast segment, DROTHERs stay in 2WAY with each other, so R1 itself is a DROTHER, not the DR or BDR.

Why this answer

The output shows R1 has a neighbor with state 2WAY/DROTHER (10.0.0.3), which indicates that R1 is also a DROTHER on this broadcast multiaccess segment. The FULL/DR neighbor (10.0.0.2) is the Designated Router, and since R1 is not the BDR (no FULL/BDR state), it must be a DROTHER.

Exam trap

Cisco often tests the misconception that 2WAY state means a full adjacency, but in OSPF, 2WAY is a normal neighbor state on broadcast networks between DROTHERs, not a full adjacency (which requires FULL state).

How to eliminate wrong answers

Option A is wrong because R1 is not the BDR; the BDR would appear with state FULL/BDR, but the only FULL neighbor is the DR (10.0.0.2). Option B is wrong because the neighbor 10.0.0.3 is in the 2WAY state, not FULL, meaning they have an established neighbor relationship but not a full adjacency (they exchange Hellos but not LSAs directly). Option D is wrong because the presence of DR/BDR states (FULL/DR, 2WAY/DROTHER) indicates a broadcast multiaccess network type, not point-to-point.

621
MCQeasy

A network automation engineer is using the Python 'ncclient' library to manage a Cisco IOS XE device via NETCONF. The engineer wants to retrieve the running configuration. Which NETCONF operation should be used to accomplish this?

A.<get-config> with a source of <running/>
B.<get> with a filter for <config>
C.<edit-config> with a target of <running/>
D.<copy-config> from <running/> to <startup/>
AnswerA

The <get-config> operation is designed to retrieve configuration data from a specified datastore, such as <running/>. It returns the configuration in XML format. This is the correct NETCONF operation for reading configuration, as it does not include state data. The engineer can then parse the XML to extract the running configuration.

Why this answer

NETCONF provides specific operations for different tasks. To retrieve configuration data, the <get-config> operation is used with a source datastore, such as <running/>. This returns the configuration without state data.

Other operations like <get> retrieve both config and state, while <edit-config> and <copy-config> are for writing or copying. The correct choice is <get-config>.

Exam trap

The trap here is confusing <get> with <get-config>; <get> retrieves both configuration and state data, but <get-config> is specifically for configuration.

622
MCQhard

A network engineer is deploying a virtual WAN edge device using Cisco SD-WAN on an NFVIS platform. After powering on the VM, the device fails to boot and the NFVIS console shows 'ERROR: No bootable device found'. The engineer verified that the ISO image is correctly uploaded. What is the most likely cause?

A.The VM's virtual disk size is too small for the WAN edge image.
B.The VM's CPU type is set to 'host-passthrough' instead of 'qemu64'.
C.The boot order in the VM configuration does not have the CD-ROM (ISO) as the first device.
D.The ISO image is corrupted and NFVIS cannot read it.
AnswerC

The ISO installation image is mounted as a virtual CD-ROM; if the VM's boot order does not list the CD-ROM first, the firmware will pivot to the empty virtual hard disk. Since that disk has no boot loader and no installed NFVIS image, the firmware reports 'no bootable device'. Changing the boot order to prioritize the CD-ROM (or virtual media) lets the installer start and deploy the WAN edge image to the disk.

Why this answer

The error 'No bootable device found' indicates that the VM attempted to boot from a device that does not contain a bootable operating system. In NFVIS, when deploying a virtual WAN edge device from an ISO, the VM's boot order must be configured to prioritize the CD-ROM (ISO) device. If the boot order defaults to the virtual hard disk (which is empty before installation), the VM will fail to find a bootable medium and produce this exact error.

Exam trap

Cisco often tests the distinction between image upload errors (corruption, size) and boot process errors (boot order), leading candidates to incorrectly suspect the ISO or disk configuration when the real issue is a missing boot device priority.

How to eliminate wrong answers

Option A is wrong because the virtual disk size does not prevent the VM from booting from the ISO; the disk is only used after the OS is installed. Option B is wrong because the CPU type 'host-passthrough' is actually recommended for Cisco SD-WAN VMs on NFVIS to expose the full CPU feature set; 'qemu64' would be a less compatible choice. Option D is wrong because if the ISO were corrupted, NFVIS would typically report a checksum or mount error, not a 'No bootable device found' message, which specifically points to boot order misconfiguration.

623
MCQhard

A network engineer issues the following command on a router: R1# show tacacs TACACS+ Server: 10.1.1.10/49 Socket opens: 5 Socket closes: 3 Socket aborts: 0 Total packets sent: 10 Total packets received: 9 Retransmissions: 1 Timeouts: 1 Current idle time: 30 seconds Based on this output, what can be concluded?

A.The TACACS+ server is unreachable.
B.There have been no authentication attempts.
C.The TACACS+ server experienced a single timeout.
D.All packets were successfully acknowledged.
AnswerC

The timeout counter shows exactly 1, meaning one request was transmitted but no response was received within the configured timeout period. Since 10 packets were sent and only 9 were received, the single mismatch between sent and received is precisely accounted for by this timeout. This is a normal transient condition, such as a dropped packet or a slow server response, not a systemic failure.

Why this answer

The output shows 'Timeouts: 1', which indicates that exactly one TACACS+ request did not receive a response within the expected time. This confirms that the TACACS+ server experienced a single timeout, making option C correct. The server is reachable (socket opens/closes show successful connections), and authentication attempts have occurred (total packets sent/received).

Exam trap

Cisco often tests the distinction between 'timeouts' and 'server unreachable' — candidates may incorrectly assume a timeout means the server is unreachable, but the output clearly shows successful socket opens, proving the server is reachable and the timeout was a single failed request.

How to eliminate wrong answers

Option A is wrong because the output shows socket opens (5) and socket closes (3), indicating successful TCP connections to the server, so it is reachable. Option B is wrong because total packets sent (10) and received (9) prove authentication attempts have occurred. Option D is wrong because the retransmission count (1) and timeout count (1) indicate that not all packets were successfully acknowledged; one packet timed out.

624
MCQmedium

An organization uses Ansible to manage network device configurations. They have a playbook that uses the ios_command module to execute 'show ip route' on multiple routers and then uses the 'debug' module to print the output. Recently, the playbook started failing with 'Timeout (12s) waiting for privilege escalation prompt'. The routers are reachable and SSH credentials are correct. What is the most likely cause?

A.The routers are configured with a different enable secret that does not match the one in the Ansible vault.
B.The 'ansible_connection' is set to 'network_cli' but the 'ansible_become_method' is not set to 'enable'.
C.The SSH key exchange is taking longer than the default 12-second timeout.
D.The ios_command module requires a different privilege level to execute 'show ip route'.
AnswerB

With ansible_connection: network_cli, Ansible must be told to escalate privileges by setting ansible_become: yes and ansible_become_method: enable. If the become method is omitted, the automation engine has no way to issue the enable command, so IOS remains at the user EXEC prompt and Ansible times out waiting for a privileged prompt that never arrives. The ios_command tasks then fail with a 'timeout waiting for privilege escalation prompt' error instead of returning command output.

Why this answer

The error 'Timeout (12s) waiting for privilege escalation prompt' indicates that Ansible successfully connected to the routers via SSH but failed to escalate privileges to enable mode. For network devices like Cisco IOS routers, when using the 'network_cli' connection type, the 'ansible_become_method' must be explicitly set to 'enable' to send the 'enable' command and handle the privilege escalation prompt. Without this setting, Ansible does not attempt to enter enable mode, causing the timeout when the module requires higher privileges to execute commands like 'show ip route'.

Exam trap

Cisco often tests the distinction between connection authentication (SSH credentials) and privilege escalation (enable mode), leading candidates to incorrectly focus on credential mismatches or SSH issues when the real problem is the missing 'ansible_become_method: enable' parameter.

How to eliminate wrong answers

Option A is wrong because the error message specifically mentions 'privilege escalation prompt', not authentication failure; a mismatched enable secret would cause an 'invalid password' or 'authentication failure' error, not a timeout waiting for the prompt. Option C is wrong because the 12-second timeout is the default for privilege escalation, not for SSH key exchange; SSH key exchange timeout is controlled by 'ansible_ssh_timeout' and would produce a different error like 'Connection timed out' or 'Authentication failed'. Option D is wrong because the 'ios_command' module can execute 'show ip route' at privilege level 1 (user exec mode) or higher; the issue is not about the required privilege level but about the failure to escalate to enable mode at all.

625
Drag & Dropmedium

Drag and drop the steps of Metro Ethernet E-Line service provisioning into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

E-Line provisioning starts with defining the service attributes and customer endpoints. The provider then configures the UNI on each customer edge device. Next, the EVC is created across the provider network to connect the two UNIs.

Finally, the service is tested and activated for the customer.

626
MCQmedium

A network engineer runs the following command on Router R6: R6# show mpls ldp neighbor 10.6.6.7 detail Peer LDP Ident: 10.6.6.7:0; Local LDP Ident 10.6.6.6:0 TCP connection: 10.6.6.7.646 - 10.6.6.6.179 State: Oper; Msgs sent/rcvd: 200/195; Downstream Up time: 1d04h LDP discovery sources: Targeted Hello 10.6.6.6 -> 10.6.6.7, active, passive Addresses bound to peer LDP Ident: 10.6.6.7 192.168.6.7 Hold time: 15 seconds; keepalive interval: 5 seconds Peer hold time: 15 seconds; keepalive interval: 5 seconds Based on this output, what type of LDP session is this?

A.This is a link-local LDP session because the discovery source is an interface.
B.This is a targeted LDP session established between two non-directly connected routers.
C.This is a multicast LDP session because the hold time is 15 seconds.
D.This is a BGP session because the TCP connection shows port 179.
AnswerB

This is a targeted LDP session because the discovery source is a 'Targeted Hello,' which is used to establish LDP peering between routers that are not directly connected. Targeted hellos are unicast to a configured neighbor's IP address, enabling the LDP peers to form a TCP session and exchange labels even across multiple hops. The output confirms this by showing the discovery source as targeted, and the session state is operational, indicating an established targeted LDP session.

Why this answer

The output shows a targeted hello (10.6.6.6 -> 10.6.6.7) as the LDP discovery source, and the TCP connection uses port 646 (LDP) on one side and port 179 (BGP) on the other. This indicates the session is established between two routers that are not directly connected (non-adjacent), which is the definition of a targeted LDP session. The presence of 'active, passive' in the discovery source confirms that one router initiated the targeted hello and the other responded.

Exam trap

Cisco often tests the distinction between link-local (directly connected) and targeted (non-directly connected) LDP sessions, and the trap here is that candidates see port 179 and assume it is BGP, when in fact it is a targeted LDP session using a non-standard TCP port.

How to eliminate wrong answers

Option A is wrong because the discovery source is a targeted hello, not an interface; link-local LDP sessions use interface-based hellos (multicast to 224.0.0.2) between directly connected neighbors. Option C is wrong because LDP does not use multicast sessions; the hold time of 15 seconds is a standard LDP timer, not an indicator of session type. Option D is wrong because the TCP connection shows port 646 (LDP) on the remote side and port 179 (BGP) on the local side, but this is a common misconfiguration or observation in targeted LDP where the local router uses a BGP port number; the session is still LDP, not BGP.

627
MCQeasy

What is the default quiet-period timer value in Cisco IOS 802.1X configuration?

A.30 seconds
B.60 seconds
C.120 seconds
D.10 seconds
AnswerB

The default quiet-period in Cisco 802.1X is 60 seconds. This timer is triggered after an authentication failure, placing the switch port in a quiet state during which EAPOL requests from the supplicant are ignored. The 60-second default balances security against usability, preventing rapid brute-force attempts while still giving users a reasonable chance to retry.

Why this answer

The default quiet-period timer in Cisco IOS 802.1X configuration is 60 seconds. This timer defines the period the switch waits after a failed authentication attempt before re-initiating authentication with the same supplicant. It prevents repeated authentication attempts from overwhelming the switch and the RADIUS server.

Exam trap

Cisco often tests the quiet-period timer by confusing it with the tx-period (10 seconds) or the re-authentication timer (30 seconds), so candidates must memorize the exact default values for each distinct 802.1X timer.

How to eliminate wrong answers

Option A (30 seconds) is wrong because it is the default value for the re-authentication timer, not the quiet-period timer. Option C (120 seconds) is wrong because it is not a default timer value in 802.1X; it might be confused with the server timeout or a manually configured value. Option D (10 seconds) is wrong because it is the default value for the tx-period timer, which controls how often EAP-Request/Identity frames are retransmitted to a supplicant that has not responded.

628
MCQmedium

A network architect is designing a new branch office that requires a lightweight, scalable solution for device onboarding and policy enforcement. The branch has minimal on-site IT staff and must integrate with the existing Cisco DNA Center deployment at headquarters. Which Cisco SD-Access fabric role is responsible for providing the layer 3 gateway and policy enforcement for wired and wireless endpoints in this branch?

A.Fabric border node
B.Fabric control plane node
C.Fabric intermediate node
D.Fabric edge node
AnswerD

The fabric edge node provides the layer 3 gateway and policy enforcement for endpoints in the SD-Access fabric. It encapsulates traffic using VXLAN and registers endpoints with the control plane node. In a branch with minimal IT staff, the edge node enables automated onboarding and consistent policy from Cisco DNA Center, exactly as required.

Why this answer

The fabric edge node is the device that connects endpoints to the SD-Access fabric and serves as their default gateway. It enforces group-based policies and encapsulates traffic in VXLAN toward other fabric nodes. In a branch with limited IT staff, it enables zero-touch onboarding and centralized policy from Cisco DNA Center, satisfying both scalability and integration needs.

Exam trap

The trap here is assuming that any fabric node can enforce policy and act as a gateway, when in fact only the edge node performs those functions for endpoints.

629
Matchingmedium

Drag and drop each streaming telemetry mode on the left to its matching trigger on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Data is sent at a fixed interval

Data is sent only when a value changes

The device decides when to send data

On-change with additional suppression rules

Combination of periodic and on-change triggers

Why these pairings

Periodic sends at intervals, on-change sends on value change, target-defined leaves timing to the device, on-change-with-policy adds conditions, and periodic-and-on-change combines both.

630
MCQmedium

An engineer is configuring QoS on a Cisco ASR 1000 router to support three traffic classes: voice (EF), video (AF41), and data (default). The link is a 50 Mbps Ethernet circuit. The engineer wants to guarantee 10 Mbps for voice, 20 Mbps for video, and the remaining for data. The current policy uses bandwidth percent statements. During congestion, voice traffic is not receiving its guaranteed bandwidth. What is the most likely cause?

A.The interface bandwidth command is not set to 50000 kbps
B.The voice class should use priority instead of bandwidth
C.The video class should use bandwidth remaining percent
D.The policy map is applied in the input direction
AnswerA

The root cause is that CBWFQ's percent-based bandwidth commands (bandwidth percent, priority percent) are calculated against the interface `bandwidth` setting, not the physical line rate. If an Ethernet interface retains its default bandwidth of 1000000 kbps (1 Gbps) while the actual WAN circuit is 50 Mbps, a voice class configured with `bandwidth percent 10` would reserve 100000 kbps instead of 5000 kbps. Without `bandwidth 50000` under the interface, the percentages do not map to the real link speed, so the voice class appears under-allocated even though the configuration is logically correct.

Why this answer

The bandwidth percent command allocates a percentage of the interface bandwidth, which by default is derived from the physical interface speed. On a Cisco ASR 1000, if the interface bandwidth is not manually set to 50000 kbps, the router may use a different default value (e.g., 1000000 kbps for Ethernet), causing the bandwidth percent to allocate a much larger absolute amount than intended. This leads to incorrect bandwidth guarantees, such as voice not receiving its required 10 Mbps during congestion.

Exam trap

Cisco often tests the misconception that bandwidth percent always uses the physical link speed, when in fact it uses the interface bandwidth value, which must be explicitly set if the link speed differs from the default.

How to eliminate wrong answers

Option B is wrong because using priority instead of bandwidth would give voice strict priority queuing, which could starve other classes but does not address the root cause of incorrect bandwidth allocation due to the interface bandwidth mismatch. Option C is wrong because bandwidth remaining percent is used for distributing leftover bandwidth after priority queues, but the issue here is that the base bandwidth percentage is miscalculated, not that video needs a different allocation method. Option D is wrong because applying the policy map in the input direction would affect inbound traffic, but the problem is about outbound bandwidth guarantees during congestion; QoS typically shapes or polices inbound traffic differently, and the scenario implies outbound congestion.

631
Matchingmedium

Drag and drop each VRF component on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Uniquely identifies a VRF to allow overlapping IPv4 prefixes

Determines which routes are imported into or exported from a VRF

Stores all routes learned within a specific VRF

Holds routes for the default or global routing table

Used by hardware to make forwarding decisions based on the RIB

Why these pairings

Route Distinguisher (RD) makes IPv4 prefixes unique across VRFs; Route Target (RT) controls import/export of routes; the VRF RIB stores routes learned within that VRF; the global RIB holds routes for the global routing table; the FIB is used for forwarding decisions.

632
MCQmedium

A network administrator is deploying Cisco TrustSec in a campus network. The security team wants to enforce access policy based on a device's role rather than its IP address, so that the enforced policy remains consistent even when endpoints move between VLANs or subnets. Which Cisco TrustSec component is responsible for assigning and carrying this role-based identity through the network?

A.IPsec tunnel established between the access switch and the Cisco DNA Center appliance.
B.Security Group Tag (SGT) applied at ingress and propagated via inline tagging or SXP.
C.MACsec encryption applied on the uplink between access and distribution switches.
D.Cisco Identity Services Engine (ISE) profiling the endpoint after DHCP and HTTP probes.
AnswerB

The SGT is a 16-bit value inserted into the frame or packet at the ingress device, which then enforces policy at egress based on the tag instead of IP. Propagation via inline tagging or the SGT Exchange Protocol (SXP) keeps role identity intact across VLAN and subnet boundaries, which is exactly what the security team requires.

Why this answer

Role-based enforcement in TrustSec depends on Security Group Tags that travel with the traffic. The ingress device classifies the packet and inserts the SGT; downstream devices enforce the Security Group ACL based on that tag. Because the tag, not the IP address, drives policy, endpoints keep the same access rights after moving between VLANs and subnets, satisfying the stated requirement.

Exam trap

The trap here is assuming that endpoint profiling or encryption alone delivers role-based enforcement, when only the Security Group Tag actually carries role identity in the data plane.

633
MCQmedium

Consider the following configuration on a Cisco IOS-XE switch: interface GigabitEthernet0/3 switchport trunk encapsulation dot1q switchport mode trunk switchport trunk native vlan 1 What is the effect of this configuration?

A.The interface will operate as an 802.1Q trunk, and untagged frames will be associated with VLAN 1.
B.The interface will operate as an ISL trunk.
C.The interface will drop all untagged frames.
D.The interface will only forward traffic for VLAN 1.
AnswerA

With 'switchport mode trunk' and 'switchport trunk encapsulation dot1q', the interface inserts a 4-byte 802.1Q tag for frames on all VLANs except the native VLAN. Because the default native VLAN is VLAN 1, any untagged frame received on the trunk is classified as belonging to VLAN 1 and forwarded accordingly. This is the standard behavior for a dot1q trunk unless the native VLAN is explicitly changed with 'switchport trunk native vlan'.

Why this answer

The configuration sets the interface to 802.1Q trunking mode and explicitly defines VLAN 1 as the native VLAN. On an 802.1Q trunk, the native VLAN is the VLAN to which untagged frames are assigned when received on the trunk port. Since VLAN 1 is the default native VLAN and is explicitly configured here, untagged frames will be associated with VLAN 1, allowing them to traverse the trunk without an 802.1Q tag.

Exam trap

Cisco often tests the misconception that a trunk port drops untagged frames or that the native VLAN is only for management traffic, when in fact untagged frames are always associated with the native VLAN on an 802.1Q trunk.

How to eliminate wrong answers

Option B is wrong because the command 'switchport trunk encapsulation dot1q' explicitly sets the trunking protocol to 802.1Q, not ISL; ISL is a Cisco-proprietary encapsulation that is not supported on modern IOS-XE switches and would require 'switchport trunk encapsulation isl'. Option C is wrong because an 802.1Q trunk does not drop untagged frames; instead, it assigns them to the native VLAN (VLAN 1 by default or as configured). Option D is wrong because the interface is configured as a trunk, which forwards traffic for multiple VLANs (all allowed VLANs by default), not only VLAN 1; the native VLAN setting only affects how untagged frames are handled, not the scope of VLANs forwarded.

634
Drag & Dropmedium

Drag and drop the steps of CoPP policy evaluation order into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

CoPP evaluates packets against class maps in sequential order. The first match determines the action. The default class is processed last if no match occurs.

635
MCQmedium

A network engineer is deploying Cisco SD-Access and wants to ensure that traffic from employee endpoints is tunneled to a fabric border node for external connectivity. Which component is responsible for encapsulating endpoint traffic into VXLAN and forwarding it to the border?

A.Fabric edge node
B.Fabric border node
C.Fabric intermediate node
D.Fabric control plane node
AnswerA

Fabric edge nodes are responsible for encapsulating endpoint traffic into VXLAN and forwarding it to the border. They act as VTEPs, mapping endpoint IP addresses to fabric locators and tunneling traffic across the underlay. This design provides policy enforcement and segmentation, ensuring that employee traffic destined for external networks is properly encapsulated and sent to the border for routing.

Why this answer

Fabric edge nodes are the VTEPs that encapsulate endpoint traffic into VXLAN and forward it toward the border for external connectivity. They handle the mapping and tunneling of endpoint traffic, ensuring that employee endpoints can reach external networks through the fabric border. Control plane nodes manage mapping, border nodes decapsulate, and intermediate nodes only forward encapsulated packets.

Exam trap

The trap here is assuming that the border node encapsulates traffic, when in fact it decapsulates traffic leaving the fabric and edge nodes perform encapsulation.

636
MCQeasy

A network engineer is configuring a Cisco IOS-XE router to support virtual routing and forwarding (VRF) for a multi-tenant environment. The engineer wants to ensure that traffic from each tenant is isolated and that overlapping IP addresses can be used. Which command is used to create a VRF instance and enter VRF configuration mode?

A.vrf forwarding TENANT_A
B.vrf definition TENANT_A
C.ip vrf forwarding TENANT_A
D.ip vrf TENANT_A
AnswerB

The global configuration command 'vrf definition TENANT_A' creates a VRF instance named TENANT_A and enters VRF configuration mode. This command is used on Cisco IOS-XE routers to define a VRF, which provides separate routing and forwarding tables for each tenant. Within VRF configuration mode, the engineer can configure route distinguishers (RD) and route targets (RT) to control route import and export. This command is essential for enabling VRF-lite or MPLS Layer 3 VPNs, allowing overlapping IP addresses across tenants.

Why this answer

The correct command to create a VRF instance on a Cisco IOS-XE router is 'vrf definition TENANT_A'. This command creates the VRF and enters VRF configuration mode, where route distinguishers and route targets can be configured. The 'ip vrf' command is legacy and not recommended on IOS-XE.

The 'vrf forwarding' and 'ip vrf forwarding' commands are used on interfaces to assign them to an existing VRF, not to create one.

Exam trap

The trap here is confusing the legacy 'ip vrf' command with the modern 'vrf definition' command, as both create VRFs but only the latter is recommended on IOS-XE.

637
MCQeasy

A network administrator is deploying a new Cisco SD-WAN solution. The administrator needs to ensure that the control plane is separated from the data plane and that the solution can dynamically select the best path for application traffic based on policies. Which component of Cisco SD-WAN is responsible for centralized control plane functions and distributing routing information to the WAN Edge devices?

A.WAN Edge
B.vManage
C.vBond
D.vSmart
AnswerD

vSmart is the centralized control plane component of Cisco SD-WAN. It distributes routing information, policies, and keys to the WAN Edge devices. It uses Overlay Management Protocol (OMP) to exchange routes and policies, enabling dynamic path selection based on application policies. This matches the requirement for centralized control plane functions.

Why this answer

vSmart is the centralized control plane in Cisco SD-WAN, using OMP to distribute routing and policies to WAN Edge devices. It enables dynamic path selection and separates control from data plane. vManage is management, vBond is orchestration, and WAN Edge is data plane.

Exam trap

The trap here is confusing the management plane (vManage) with the control plane (vSmart), or assuming vBond handles routing.

638
MCQeasy

A network team is planning to migrate from a Type 2 hypervisor to a Type 1 hypervisor for their production VMs. They need to understand the architectural impact. Which statement correctly describes a key difference between Type 1 and Type 2 hypervisors?

A.Type 1 hypervisors run directly on the physical hardware, while Type 2 hypervisors run on top of a host operating system.
B.Type 1 hypervisors require a host OS for device drivers, while Type 2 hypervisors include their own drivers.
C.Type 2 hypervisors are always more secure than Type 1 because of the additional OS layer.
D.Type 1 hypervisors cannot support hardware passthrough, but Type 2 can.
AnswerA

Type 1 hypervisors, also known as bare-metal hypervisors, run directly on the host hardware without an underlying operating system; the hypervisor itself acts as the resource manager and scheduler. Type 2 hypervisors, by contrast, are applications installed on top of a general-purpose host OS, which mediates all hardware access. This fundamental split drives most other differences in performance, security, and management.

Why this answer

Type 1 hypervisors (bare-metal) run directly on the physical hardware without an underlying operating system, providing direct access to hardware resources and better performance. Type 2 hypervisors (hosted) run as an application on top of a host operating system, which introduces additional overhead and resource contention. This architectural difference is fundamental to understanding virtualization performance and isolation in production environments.

Exam trap

Cisco often tests the misconception that Type 2 hypervisors are more secure due to an additional OS layer, but the trap here is that the extra layer actually increases the attack surface and reduces security isolation compared to a Type 1 hypervisor.

How to eliminate wrong answers

Option B is wrong because Type 1 hypervisors include their own built-in device drivers and do not require a host OS for device drivers; Type 2 hypervisors rely on the host OS for driver support. Option C is wrong because Type 2 hypervisors are generally less secure than Type 1 due to the larger attack surface introduced by the host OS layer, not more secure. Option D is wrong because Type 1 hypervisors fully support hardware passthrough (e.g., PCIe passthrough via Intel VT-d or AMD IOMMU), while Type 2 hypervisors often have limited or more complex passthrough support due to the host OS abstraction.

639
MCQhard

A network security team deploys Cisco ISE for 802.1X wired authentication. The switches are configured with MAB as a fallback. A printer that does not support 802.1X is connected, but ISE rejects it even though the printer's MAC address is in the correct identity group. The switch port shows the authentication method as MAB and the status as unauthorized. Which configuration issue is the most likely cause?

A.The MAC address format in the ISE endpoint identity group does not match the format sent by the switch in the MAB request.
B.The switch port is configured with authentication host-mode multi-domain instead of multi-auth.
C.The RADIUS shared secret on the switch does not match the one configured for the switch in Cisco ISE.
D.The switch is configured with dot1x pae authenticator on the port instead of pae supplicant.
AnswerA

ISE matches MAB requests against endpoint MAC addresses in its database using a specific format. If the endpoint was added with a different delimiter or case than what the switch sends in the Calling-Station-Id, ISE will not match the identity group and will reject the request, causing the unauthorized state.

Why this answer

MAB authentication depends on ISE matching the MAC address sent in the RADIUS request to an endpoint record. If the stored MAC format differs from the format in the Calling-Station-Id attribute, the endpoint is not matched to its identity group and authorization fails. Ensuring consistent MAC formatting resolves the rejection.

Exam trap

The trap here is focusing on switch-side 802.1X host modes or RADIUS secrets while overlooking that MAB success hinges on exact MAC address formatting in the ISE endpoint database.

640
MCQmedium

A network administrator is configuring a site-to-site IPsec VPN between two Cisco IOS routers. The design requires that only traffic from specific subnets be encrypted and that the routers use a preshared key for authentication. Which combination of configuration elements must the administrator define to match the interesting traffic and establish the tunnel?

A.An ISAKMP policy, a preshared key, and a crypto map applied to the WAN interface without an ACL for interesting traffic.
B.A route map defining interesting traffic, a crypto map, and a transform set applied to the LAN interface.
C.An ACL defining interesting traffic, an ISAKMP policy, a preshared key, and a crypto map applied to the WAN interface.
D.An ACL defining interesting traffic, a transform set, and a crypto map applied to the LAN interface without an ISAKMP policy.
AnswerC

A classic site-to-site IPsec VPN on Cisco IOS requires an extended ACL to identify interesting traffic, an ISAKMP (IKE) policy to define Phase 1 parameters, a preshared key for peer authentication, and a crypto map that references the ACL and transform set and is applied to the WAN interface. Together these elements establish and encrypt the tunnel.

Why this answer

A Cisco IOS site-to-site IPsec VPN requires an extended ACL to identify interesting traffic, an ISAKMP policy to define Phase 1 parameters, a preshared key for peer authentication, and a crypto map that ties the ACL and transform set together and is applied to the WAN interface. All of these elements work together to negotiate and encrypt traffic between the peers.

Exam trap

The trap here is assuming that a route map or an interface other than the WAN can define or carry the IPsec policy, when interesting traffic must be defined by an ACL and the crypto map must be applied to the WAN interface.

641
MCQmedium

A network engineer is troubleshooting an EtherChannel between two Cisco switches. The show etherchannel 1 port-channel command shows the port-channel is up, but traffic is not load-balanced evenly. The engineer notices that all traffic is using only one link. The physical ports are all configured identically. What is the most likely cause?

A.The load-balancing method is set to src-mac, and the traffic is from multiple MAC addresses.
B.The load-balancing method is set to src-dst-ip, and all traffic is between the same two IP addresses.
C.The physical ports have different speeds.
D.The port-channel is configured with 'lacp fast-switchover'.
AnswerB

The src-dst-ip method hashes both the source and destination IP addresses together to select an egress link. When every packet between two IP endpoints is going between the same pair, the hash output is identical for each packet, so the deterministic hash always maps to the same member port. This is exactly the condition that forces all traffic onto a single link, even if multiple flows exist between those IPs.

Why this answer

When the load-balancing method is set to src-dst-ip, the hash is computed from the source and destination IP addresses. If all traffic flows between the same two IP addresses, the hash result will always be identical, causing all frames to be forwarded over the same physical link. This explains why the port-channel is up but only one link carries all traffic.

Exam trap

Cisco often tests the misconception that any load-balancing method will automatically distribute traffic evenly, but the trap here is that the hash algorithm's output depends on the diversity of the hashed fields—if those fields are identical for all traffic, only one link is used regardless of the method.

How to eliminate wrong answers

Option A is wrong because src-mac load balancing would hash based on source MAC addresses; if traffic comes from multiple MAC addresses, the hash would likely distribute across multiple links, not concentrate on one. Option C is wrong because the question states the physical ports are configured identically, so differing speeds cannot be the cause; moreover, EtherChannel requires all ports to have the same speed and duplex. Option D is wrong because 'lacp fast-switchover' is not a valid Cisco command or feature; LACP uses fast or slow rate for PDU transmission, but this does not affect load-balancing behavior.

642
MCQhard

A network administrator is troubleshooting a connectivity issue between two switches connected via a trunk link. The trunk is configured with 802.1Q encapsulation. The administrator suspects that the native VLAN is mismatched. Which command displays the native VLAN configuration on a Cisco Catalyst switch?

A.show interfaces trunk
B.show running-config interface GigabitEthernet0/1
C.show vlan brief
D.show spanning-tree interface GigabitEthernet0/1
AnswerA

The show interfaces trunk command displays the trunk interfaces, their mode, encapsulation, and the native VLAN. It explicitly lists the native VLAN in the output, allowing the administrator to quickly verify if it matches on both ends. This is the most direct command to check the native VLAN configuration on a trunk port.

Why this answer

The show interfaces trunk command is specifically designed to display trunk interface details, including the native VLAN. It provides a concise summary that makes it easy to compare native VLAN settings between switches. While the running configuration also contains the native VLAN setting, show interfaces trunk is the most direct and efficient command for this purpose, especially when checking multiple trunks.

Exam trap

The trap here is thinking show vlan brief shows native VLAN information; it only shows VLAN-to-port assignments for access ports.

643
MCQeasy

A network team is evaluating automation tools to manage a large Cisco IOS XE environment. They need a tool that uses a declarative, agentless approach and can be run from a central server without installing software on managed devices. Which tool best fits this requirement?

A.Puppet
B.SaltStack
C.Chef
D.Ansible
AnswerD

Ansible is an agentless automation tool that uses SSH or NETCONF to connect to devices, requiring no agent installation on managed nodes. It uses declarative playbooks written in YAML. This aligns perfectly with the requirement for an agentless, declarative tool run from a central server. Ansible is widely used for Cisco network automation.

Why this answer

Ansible is agentless, using SSH or NETCONF to connect to devices, and uses declarative YAML playbooks. It runs from a central control node without installing agents on managed devices. Puppet, Chef, and SaltStack typically require agents, making them less suitable for this specific requirement.

Exam trap

The trap here is confusing agentless operation with tools that can optionally run agentless; Ansible is inherently agentless, while others are primarily agent-based.

644
MCQhard

A network architect is designing a data center network using Cisco ACI. The architect must ensure that traffic between endpoints in different EPGs is allowed only when a contract exists. Which Cisco ACI component is responsible for enforcing these contracts?

A.Policy Enforcement Point (PEP)
B.Application Policy Infrastructure Controller (APIC)
C.Spine switch
D.Endpoint Group (EPG)
AnswerA

In Cisco ACI, the Policy Enforcement Point (PEP) is responsible for enforcing contracts between EPGs. The PEP is typically implemented in the leaf switches, where it applies filters and actions defined in the contract. This ensures that traffic is permitted or denied based on the contract, meeting the security requirement.

Why this answer

In Cisco ACI, contracts define allowed communication between EPGs. The Policy Enforcement Point (PEP), implemented on leaf switches, enforces these contracts by applying the specified filters and actions. The APIC defines the policy, but enforcement occurs at the leaf.

Spines and EPGs do not enforce contracts, making the PEP the correct component.

Exam trap

The trap here is assuming the APIC enforces contracts because it manages policy, but actual enforcement is distributed to the leaf switches as PEPs.

645
MCQeasy

A network administrator is configuring a Cisco Catalyst switch and needs to assign a port to VLAN 20 as an access port. The port is currently in VLAN 1. Which command sequence correctly configures the interface?

A.interface GigabitEthernet0/1, then switchport access vlan 20, then switchport mode access
B.interface GigabitEthernet0/1, then switchport trunk allowed vlan 20, then switchport mode trunk
C.interface GigabitEthernet0/1, then switchport mode dynamic auto, then switchport access vlan 20
D.interface GigabitEthernet0/1, then switchport mode access, then switchport access vlan 20
AnswerD

This sequence enters interface configuration mode, sets the port to access mode, and assigns VLAN 20. It is the correct and standard method to configure an access port on a Cisco Catalyst switch. The port will carry untagged traffic for VLAN 20, and any existing VLAN 1 assignment is overridden.

Why this answer

To configure a switch port as an access port in VLAN 20, you enter interface configuration mode, set the mode to access with switchport mode access, and then assign the VLAN with switchport access vlan 20. This ensures the port operates as a static access port and carries untagged traffic for VLAN 20.

Exam trap

The trap here is confusing access and trunk configuration, or using the wrong order of commands that might leave the port in a dynamic state.

646
MCQhard

A network engineer runs the following command on Switch SW1: SW1# show interfaces trunk Port Mode Encapsulation Status Native vlan Gi0/1 on 802.1q trunking 1 Gi0/2 on 802.1q trunking 1 Port Vlans allowed on trunk Gi0/1 1-1005 Gi0/2 1-1005 Port Vlans allowed and active in management domain Gi0/1 1,10,20 Gi0/2 1,10,20 Port Vlans in spanning tree forwarding state and not pruned Gi0/1 1,10,20 Gi0/2 1,10,20 Based on this output, what can be concluded?

A.VLANs 2-9 are allowed but not active on the trunk.
B.The trunk is using ISL encapsulation.
C.VLAN 1 is pruned from the trunk.
D.Only VLANs 10 and 20 are forwarding traffic.
AnswerA

The allowed list spans 1-1005, but the active management domain shows only 1, 10 and 20, proving VLANs 2-9 exist in the allowed range yet carry no active ports. Spanning-tree forwarding state confirms the same set, so those VLANs are permitted but dormant.

Why this answer

The output shows that VLANs 1-1005 are allowed on the trunk, but only VLANs 1, 10, and 20 are listed as active in the management domain. This means VLANs 2-9 are configured on the trunk but are not active (i.e., not created or not present on the switch), so they do not forward traffic. Option A correctly identifies this condition.

Exam trap

Cisco often tests the difference between 'allowed on trunk' and 'active in management domain' to trick candidates into thinking all allowed VLANs are forwarding, when in fact only active VLANs forward traffic.

How to eliminate wrong answers

Option B is wrong because the encapsulation is explicitly shown as '802.1q', not ISL, which is a Cisco proprietary protocol that is now largely deprecated. Option C is wrong because VLAN 1 is listed in the 'Vlans in spanning tree forwarding state and not pruned' section, indicating it is forwarding and not pruned; pruning would remove it from that list. Option D is wrong because VLAN 1 is also in the forwarding state and not pruned, so traffic for VLAN 1 is also being forwarded, not just VLANs 10 and 20.

647
MCQmedium

A network engineer is deploying Control Plane Policing on a Cisco IOS-XE router that runs OSPF, BGP, and SSH management. The engineer wants to rate-limit routing protocol traffic while ensuring that SSH management traffic is never dropped, even during a routing protocol flood. The router uses a single physical interface for all control plane traffic. Which CoPP design approach best meets these requirements?

A.Create separate class-maps for OSPF, BGP, and SSH, then apply individual policers to each class in the policy-map, with SSH assigned a higher rate or set to conform-action transmit.
B.Use a single class-map for OSPF and BGP, and rely on SSH being exempt because it is TCP-based and not subject to CoPP.
C.Configure CoPP only on the management interface and leave the data interfaces unprotected.
D.Apply a single class-map matching all control plane traffic and set a single policer with a high rate limit.
AnswerA

Creating separate class-maps allows the engineer to apply distinct policers to each traffic type. By giving SSH a higher rate limit or configuring it to always transmit, management access is protected. OSPF and BGP can be rate-limited independently to prevent control plane overload. This granular approach is the recommended CoPP design for protecting critical management traffic.

Why this answer

Separate class-maps for OSPF, BGP, and SSH allow individual policing actions. Assigning SSH a higher rate or conform-action transmit ensures management access is preserved during routing protocol floods. This granular CoPP design protects both routing stability and administrative access, which is the core goal of control plane policing.

Exam trap

The trap here is assuming that SSH management traffic is automatically exempt from CoPP because it is TCP-based, when in fact all control plane traffic is subject to the policy-map.

648
MCQmedium

Given the following configuration on a Cisco IOS router: policy-map SHAPE class class-default shape average 1000000 interface Serial0/0/0 service-policy output SHAPE What is the effect of this configuration?

A.The router will limit the transmit rate on Serial0/0/0 to an average of 1 Mbps by queuing excess packets.
B.The router will drop any traffic exceeding 1 Mbps on Serial0/0/0.
C.The router will mark all traffic with a rate limit of 1 Mbps but not enforce it.
D.The configuration is invalid because 'shape average' requires a class-map with a match statement.
AnswerA

This is the definition of traffic shaping. The 'shape average 1000000' command configures a token bucket that allows bursts up to the committed burst size, but the average transmit rate is capped at 1 Mbps. When traffic exceeds this rate, excess packets are buffered in the shaping queue rather than dropped (unless the queue overflows and tail drop occurs). This smoothing of traffic avoids packet loss and is appropriate for interfaces that can tolerate delay but need to conform to a subscribed rate.

Why this answer

The configuration applies a shaping policy to the Serial0/0/0 interface, which limits the transmit rate to an average of 1 Mbps. Shaping works by queuing excess packets that exceed the configured rate, smoothing the traffic burst and preventing packet loss due to interface congestion. This is why Option A is correct.

Exam trap

Cisco often tests the distinction between shaping (queuing) and policing (dropping/remarking), so candidates mistakenly choose the dropping option (B) when they see a rate limit, not realizing shaping buffers excess traffic.

How to eliminate wrong answers

Option B is wrong because shaping does not drop traffic; it queues excess packets to enforce the rate, whereas policing would drop or remark traffic. Option C is wrong because shaping actively enforces the rate by buffering, not just marking traffic without enforcement. Option D is wrong because 'shape average' in the class-default class does not require a match statement; class-default matches all unclassified traffic by default.

649
MCQeasy

A network engineer is configuring uRPF (unicast Reverse Path Forwarding) on a Cisco router to prevent spoofed IP traffic. The engineer enables uRPF in strict mode on the ingress interface connected to the internal network. After enabling uRPF, legitimate traffic from internal hosts is being dropped. The engineer checks the routing table and sees that the routes for the internal subnets are present. What is the most likely cause?

A.The return route for the source IP points to a different interface than the one where the packet arrived.
B.uRPF is checking the destination IP address, which is not reachable.
C.The router does not have a default route, so uRPF drops all traffic.
D.uRPF cannot be used with static routes; it requires a dynamic routing protocol.
AnswerA

Strict Unicast Reverse Path Forwarding validates the source address of a packet by performing a reverse lookup in the FIB. If the best route to the source IP is not via the same interface that received the packet, the router drops it. This prevents spoofed traffic where an attacker sends packets with a source address that would legitimately arrive on a different interface, ensuring asymmetric routing paths or forged addresses are rejected.

Why this answer

In strict uRPF mode, the router checks that the source IP address of an incoming packet is reachable via the same interface on which the packet arrived. Even if the route for the source subnet exists in the routing table, if the best return route points to a different interface (e.g., a backup link or a different path), the packet will be dropped. This is the most common cause of legitimate traffic being dropped after enabling strict uRPF.

Exam trap

Cisco often tests the misconception that uRPF only checks for the existence of a route in the routing table, but the trap here is that strict mode additionally requires the incoming interface to match the outgoing interface for the source IP's return path.

How to eliminate wrong answers

Option B is wrong because uRPF checks the source IP address, not the destination IP address; destination reachability is irrelevant to uRPF. Option C is wrong because uRPF does not require a default route; it only requires a matching route for the source IP via the ingress interface, and the presence of internal subnet routes already satisfies this. Option D is wrong because uRPF works with any type of route, including static routes; it does not require a dynamic routing protocol.

650
Matchingmedium

Drag and drop each SNMP component on the left to its matching role on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Network management station that polls agents

Software module running on managed device

Virtual database defining managed objects

Numeric identifier for a specific managed object

Password-like string used for authentication in v1/v2c

Why these pairings

The manager collects data, the agent runs on the device, MIB defines the data structure, and OID identifies specific variables.

651
Drag & Dropmedium

Drag and drop the steps of connecting to a network device via Netmiko into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order starts with importing the Netmiko library, then creating a device dictionary with connection parameters, establishing the SSH connection using ConnectHandler, sending a command (e.g., 'show ip interface brief'), and finally closing the connection with disconnect(). This sequence follows standard Netmiko workflow for device access.

652
MCQmedium

A network engineer runs the following command on Router R1: R1# show access-lists 130 Extended IP access list 130 10 permit icmp host 10.1.1.1 any echo (8 matches) 20 permit icmp host 10.1.1.1 any echo-reply (5 matches) 30 deny icmp any any (3 matches) 40 permit ip any any (12 matches) Based on this output, what can be concluded?

A.ICMP packets from sources other than 10.1.1.1 are denied.
B.All ICMP traffic is permitted.
C.The ACL permits all traffic from 10.1.1.1.
D.The ACL is applied inbound on an interface.
AnswerA

This is correct because the ACL's logic is explicit: entries 10 and 20 only match ICMP echo requests and echo replies sourced from 10.1.1.1. A final explicit deny entry (entry 30) then catches every other ICMP packet, regardless of its type or destination, and drops it. Thus, any ICMP packet with a source address different from 10.1.1.1 is denied, which makes the statement accurate.

Why this answer

The ACL explicitly denies all ICMP traffic (line 30) except for echo and echo-reply from host 10.1.1.1 (lines 10 and 20). The 'deny icmp any any' statement matches ICMP packets from any source other than 10.1.1.1, and the 'permit ip any any' at line 40 only permits non-ICMP traffic. Therefore, ICMP packets from sources other than 10.1.1.1 are denied.

Exam trap

Cisco often tests the misconception that a 'permit ip any any' at the end of an ACL permits all traffic, including ICMP, but candidates must remember that earlier explicit deny statements for a specific protocol take precedence and are not overridden by a later permit of all IP.

How to eliminate wrong answers

Option B is wrong because the ACL does not permit all ICMP traffic; line 30 explicitly denies ICMP from any source, and only echo and echo-reply from 10.1.1.1 are permitted. Option C is wrong because the ACL does not permit all traffic from 10.1.1.1; it only permits ICMP echo and echo-reply from that host, while other IP traffic from 10.1.1.1 would be subject to the 'permit ip any any' at line 40, but that is not specific to 10.1.1.1. Option D is wrong because the output of 'show access-lists 130' does not indicate the direction or interface where the ACL is applied; the command only displays the ACL contents and match counters, not its application.

653
Multi-Selecthard

Which three statements about BGP route reflectors are true? (Choose three.)

Select 3 answers
A.Route reflectors allow iBGP speakers to advertise routes learned from other iBGP speakers without requiring a full mesh.
B.A route reflector client must be fully meshed with all other clients in the same cluster.
C.The route reflector can be a client of another route reflector.
D.The cluster ID is used to prevent routing loops in a route reflector environment.
E.The route reflector modifies the AS_PATH attribute to prevent loops.
AnswersA, C, D

Route reflection removes the iBGP full-mesh requirement: the reflector re-advertises routes learned from one client to other clients and non-clients. This directly satisfies the scalability constraint of avoiding a full mesh between all iBGP speakers.

Why this answer

Option A is correct because a route reflector relaxes the iBGP full-mesh requirement by reflecting routes learned from one iBGP peer to other iBGP peers (its clients and non-clients), so speakers no longer need direct sessions with every other iBGP speaker. Option C is correct because route reflectors can be arranged in a hierarchy: a route reflector can itself be a client of a higher-level route reflector, allowing large ASes to scale beyond a single cluster. Option D is correct because the CLUSTER_ID attribute (a 4-byte value, often derived from the router ID) identifies the cluster and lets a route reflector detect and drop routes that have already been reflected, preventing loops within the cluster.

Option B is not correct because route reflector clients do not need to be fully meshed with each other; they only peer with the route reflector, which is the whole point of the design. Option E is not correct because loop prevention in route reflection is handled by ORIGINATOR_ID and CLUSTER_ID (and CLUSTER_LIST), not by modifying AS_PATH, which is used for inter-AS loop prevention in eBGP.

Exam trap

350-401 often tests the misconception that route reflectors modify AS_PATH for loop prevention; the correct mechanisms are ORIGINATOR_ID and CLUSTER_LIST.

654
MCQeasy

An organization wants to implement 802.1X authentication on its wired network using Cisco ISE as the authentication server. The switches are configured with the necessary RADIUS settings. Which additional configuration is required on the switch interfaces to enable 802.1X?

A.dot1x pae authenticator
B.authentication port-control auto
C.authentication port-control force-authorized
D.authentication port-control force-unauthorized
AnswerB

This command sets the port's authentication mode to auto, meaning the port will be unauthorized until the client successfully authenticates via 802.1X. It triggers the authentication process and is the required command to enable 802.1X on an interface. This is the correct answer because it directly controls the port's state based on authentication.

Why this answer

'authentication port-control auto' is the required interface command to enable 802.1X authentication on a switch port. This command sets the port to initiate the authentication process, placing it in the unauthorized state until the client successfully authenticates via the RADIUS server (Cisco ISE). Without this command, the port will not enforce 802.1X.

Exam trap

Cisco often tests the distinction between the 'dot1x pae authenticator' command and the 'authentication port-control auto' command, leading candidates to mistakenly think the PAE command alone enables 802.1X, when in fact both are required for full functionality.

How to eliminate wrong answers

Option A is wrong because 'dot1x pae authenticator' is a subcommand that enables the Port Access Entity (PAE) role as authenticator, but it is not sufficient alone; the port must also be configured with 'authentication port-control auto' to actually enforce 802.1X. Option C is wrong because 'authentication port-control force-authorized' places the port in an always-authorized state, effectively disabling 802.1X authentication and allowing all traffic without verification. Option D is wrong because 'authentication port-control force-unauthorized' places the port in a permanently unauthorized state, blocking all traffic regardless of authentication attempts, which is not the goal for enabling 802.1X.

655
MCQmedium

Consider the following configuration: flow monitor FM-1 exporter EXPORTER-1 record netflow ipv4 original-input cache entries 16000 ! Which statement about this configuration is correct?

A.The flow cache can hold up to 16,000 flow entries simultaneously.
B.The flow cache will export flows every 16,000 seconds.
C.The flow cache will store only 16,000 bytes of flow data.
D.The flow cache will automatically increase to 32,000 entries if needed.
AnswerA

The command 'cache entries' (Cisco IOS command 'ip flow-cache entries' or 'flow-cache entries' under the flow exporter) defines the maximum number of flow records that can be held concurrently in the flow cache. The value 16,000 is the default or configured limit for the number of flow entries, each of which is a structure containing fields such as source/destination IP, source/destination port, protocol, and byte/packet counters. When this limit is reached, new flows trigger eviction of existing entries (usually the oldest or least active) to make room, but the configured size itself does not change automatically.

Why this answer

The 'cache entries 16000' command under the flow monitor specifies the maximum number of flow entries that the NetFlow cache can hold simultaneously. This is a hard limit on the size of the flow cache, not a timer or byte limit. Therefore, the flow cache can store up to 16,000 concurrent flow records before it must either export or age out older entries to make room.

Exam trap

Cisco often tests the distinction between 'cache entries' (a count of flow records) and other cache parameters like timers or byte limits, leading candidates to confuse the number of entries with a time interval or memory size.

How to eliminate wrong answers

Option B is wrong because 'cache entries' defines the number of flow entries, not a time interval; export timers are configured separately (e.g., 'cache timeout active' or 'cache timeout inactive'). Option C is wrong because 'cache entries' specifies the count of flow records, not a byte size; the cache memory usage depends on the record format and platform, not this parameter. Option D is wrong because the cache entry limit is a fixed maximum; it will not automatically increase to 32,000 entries — if the cache is full, the router must age out or export existing flows before new ones can be created.

656
MCQmedium

A network administrator is deploying a new Cisco Catalyst 9200 switch at a branch office. The security policy requires that when a device connected to a port is shut down or moved, the switch must immediately send a SNMP trap and place the port into an error-disabled state while also incrementing a violation counter. The administrator configures port security with the violation mode that meets these requirements. Which command must be applied to the interface to achieve this?

A.switchport port-security violation disable
B.switchport port-security violation restrict
C.switchport port-security violation protect
D.switchport port-security violation shutdown
AnswerD

Shutdown mode causes the port to go into an error-disabled state immediately upon a violation, sends an SNMP trap, and increments the violation counter. This exactly matches the stated security policy. The port must be manually re-enabled with a shutdown/no shutdown sequence after the violation is resolved.

Why this answer

The security policy requires the switch to send an SNMP trap and place the port into an error-disabled state when a violation occurs. The shutdown violation mode does exactly that: it error-disables the port, generates a syslog/SNMP notification, and increments the violation counter. The restrict mode only increments counters and sends notifications without disabling the port, while protect mode silently drops frames.

Disable is not a valid keyword.

Exam trap

The trap here is assuming that restrict mode also error-disables the port, when in fact it only drops frames and logs the violation without shutting down the interface.

657
Drag & Dropmedium

Drag and drop the steps of the gRPC dial-out telemetry subscription flow into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The correct order is: first, configure the telemetry receiver (destination) on the network device. Next, define a sensor group to specify which YANG data paths to collect. Then, create a subscription associating the sensor group with the receiver.

After that, enable the subscription to start streaming data. Finally, the device streams telemetry data to the receiver.

658
Multi-Selecthard

Which three statements about OSPF LSA types are correct? (Choose three.)

Select 3 answers
A.Type 1 LSAs (Router LSAs) are generated by every OSPF router and describe the router's interfaces and neighbors within an area.
B.Type 2 LSAs (Network LSAs) are generated by the DR on broadcast and NBMA networks to list all routers attached to the segment.
C.Type 3 LSAs (Summary LSAs) are generated by ASBRs to advertise external routes into the OSPF domain.
D.Type 4 LSAs (ASBR Summary LSAs) are generated by ABRs to advertise the location of an ASBR to routers in other areas.
E.Type 5 LSAs (AS External LSAs) are flooded only within the area where they originate.
AnswersA, B, D

Every OSPF router originates a Type 1 Router LSA describing its own links, interface states and costs, flooded only within its area. This satisfies the requirement that each router advertises its local topology, forming the basis of the area's shortest-path tree.

Why this answer

Option A is correct because Type 1 Router LSAs are originated by every OSPF-enabled router, are scoped to a single area, and describe that router's links (interfaces, IP addresses, metrics) and its neighbors on those links. Option B is correct because Type 2 Network LSAs are generated only by the Designated Router on multi-access segments such as broadcast and NBMA networks, and they list the DR, the BDR, and all attached routers to represent the transit network. Option D is correct because Type 4 ASBR Summary LSAs are produced by Area Border Routers to tell routers in other areas how to reach an Autonomous System Boundary Router located in a different area.

Option C is wrong because Type 3 Summary LSAs are generated by ABRs to advertise inter-area routes, not by ASBRs to advertise external routes. Option E is wrong because Type 5 AS External LSAs are flooded throughout the entire OSPF autonomous system (except stub/NSSA areas), not confined to the originating area.

Exam trap

350-401 often tests the confusion between ABRs and ASBRs — candidates wrongly attribute Type 3 Summary LSAs to ASBRs, when ABRs generate Type 3 and ASBRs generate Type 5, and they forget Type 5 LSAs flood domain-wide rather than staying area-local.

659
MCQhard

A network engineer is designing a large-scale campus network using Cisco SD-Access. The fabric must support thousands of endpoints and provide optimal forwarding paths. Which control plane component is responsible for maintaining the mapping of endpoint IP addresses to fabric edge nodes?

A.Fabric intermediate node
B.Cisco DNA Center
C.Fabric control plane node
D.Fabric edge node
AnswerC

The fabric control plane node, which runs LISP map-server and map-resolver functions, maintains the database of endpoint IP addresses and their associated fabric edge nodes. It provides the mapping service that allows fabric edge nodes to locate endpoints and establish optimal forwarding paths, making it essential for large-scale SD-Access deployments.

Why this answer

In Cisco SD-Access, the fabric control plane node uses LISP to maintain a mapping database of endpoint IP addresses to their current fabric edge nodes. This enables fabric edge nodes to query the control plane and forward traffic directly to the correct edge node, ensuring optimal paths and scalability for thousands of endpoints.

Exam trap

The trap here is attributing the endpoint mapping function to the management platform or edge nodes, when in fact it is the dedicated control plane node that holds the mapping database.

660
MCQmedium

A network engineer deploys Cisco HyperFlex with ESXi hosts and a vSwitch. The requirement is that storage traffic for the HyperFlex distributed data platform be isolated from management and VM traffic, and that jumbo frames be used end to end. Which configuration on the ESXi host satisfies this requirement?

A.Create a VMkernel adapter on the VM traffic vSwitch with an MTU of 1500 and tag it with the storage VLAN.
B.Add the storage VMkernel adapter to the existing management vSwitch and set the MTU to 9000 on that vSwitch.
C.Create a dedicated vSwitch with an MTU of 9000, attach the storage VMkernel adapter to it, and place the physical uplinks connected to the storage VLAN on that vSwitch.
D.Configure a distributed vSwitch with an MTU of 9000 and attach all VMkernel adapters, including storage, to a single uplink team.
AnswerC

Isolating storage on its own vSwitch with a 9000 MTU and dedicated uplinks on the storage VLAN separates the traffic from management and VM flows while enabling jumbo frames end to end. The storage VMkernel adapter carries the HyperFlex data traffic, and the dedicated uplinks ensure the storage VLAN is not shared with other traffic types. This matches HyperFlex networking requirements.

Why this answer

HyperFlex storage traffic should run on a dedicated vSwitch with jumbo frames enabled and its own physical uplinks on the storage VLAN. This isolates the distributed data platform traffic from management and VM flows and allows the 9000 MTU to be applied end to end. Sharing a vSwitch, using a 1500 MTU, or merging storage into a common uplink team all fail the isolation and jumbo frame requirements.

Exam trap

The trap here is assuming that simply raising the MTU to 9000 satisfies the design, when dedicated storage vSwitch and uplink isolation are equally required.

661
MCQmedium

A network engineer is troubleshooting a problem where Cisco DNA Center is not receiving syslog messages from a critical core switch. The switch is configured to send syslog to the DNA Center's IP address. The engineer checks the DNA Center syslog collector and finds that it is enabled. What should the engineer check next?

A.Verify that the syslog port (UDP 514) is not blocked by a firewall or ACL.
B.Check if the syslog messages are in the correct format.
C.Ensure that the switch is in the Inventory and managed by DNA Center.
D.Restart the syslog collector service on DNA Center.
AnswerA

With the collector enabled and the switch configured, the remaining variable is transport. Syslog uses UDP 514, so an intervening firewall or ACL silently dropping that traffic would explain why DNA Center receives nothing despite correct endpoint configuration.

Why this answer

Syslog uses UDP port 514 by default, and if a firewall or ACL between the switch and Cisco DNA Center is blocking that port, the collector will never receive messages even though both endpoints are correctly configured. Since the collector is enabled and the switch is configured to send, the next logical troubleshooting step is verifying network path reachability for UDP 514. This is the most common cause of silent syslog failures in production.

Exam trap

350-401 often tests the assumption that if a service is 'enabled' and the source is 'configured,' it must be working — candidates overlook Layer 3/4 filtering (UDP 514 blocked) as the silent killer of syslog, SNMP traps, and NetFlow exports.

How to eliminate wrong answers

Option B is wrong because syslog message format is standardized (RFC 3164/5424) and Cisco devices emit compatible messages by default; a format mismatch would not prevent receipt entirely and is not the first thing to check when nothing arrives. Option C is wrong because DNA Center can receive syslog from devices that are not yet in Inventory — syslog collection is independent of device onboarding, so this would not explain the failure. Option D is wrong because the question already states the syslog collector is enabled; restarting a running service is a random action, not a diagnostic step, and would not address a blocked port.

662
MCQmedium

Examine the following configuration on a Cisco 9800 WLC: wireless profile policy test-policy no security wpa no security wpa2 security wpa3 security wpa3 akm sae security ft over-the-ds What is the effect of the 'security ft over-the-ds' command?

A.It enables 802.11r fast roaming using over-the-air messaging.
B.It enables 802.11r fast roaming using the distribution system for key exchange.
C.It disables fast roaming for this policy.
D.It configures the AP to use a different radio band.
AnswerB

In 802.11r fast roaming, the over-the-DS mode enables key exchange between the client and target AP via the distribution system (usually the wired network), rather than directly over the air. This reduces roaming latency because the target AP's key is provided before the client reassociates. The command in question specifically turns on this behavior, making this the correct answer.

Why this answer

The 'security ft over-the-ds' command enables 802.11r Fast Transition (FT) using the Distribution System (DS) for key exchange. In this mode, the client and target AP communicate via the current AP over the wired network (DS) rather than over the air, reducing over-the-air overhead and improving roaming efficiency. This is in contrast to 'over-the-air' mode, where the client directly exchanges FT authentication messages with the target AP wirelessly.

Exam trap

Cisco often tests the distinction between 'over-the-air' and 'over-the-ds' keywords, trapping candidates who assume 'over-the-ds' refers to wireless DS (like mesh backhaul) rather than the wired distribution system.

How to eliminate wrong answers

Option A is wrong because 'over-the-ds' specifically configures 802.11r fast roaming to use the distribution system (wired network) for key exchange, not over-the-air messaging. Option C is wrong because the command does not disable fast roaming; it enables it using a specific transport method (DS). Option D is wrong because the command has no effect on radio band selection; it only controls the method of FT key exchange.

663
Matchingeasy

Drag and drop each protocol number on the left to its matching protocol on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

ICMP

TCP

UDP

OSPF

IGMP

Why these pairings

Protocol 1 is ICMP, 6 is TCP, 17 is UDP, 89 is OSPF, 2 is IGMP.

664
MCQeasy

A network administrator is configuring a Cisco CSR 1000v router in a virtualized environment. The administrator needs to ensure that the virtual router can forward traffic between virtual machines on different VLANs. Which feature must be enabled on the CSR 1000v to support this?

A.VRF Lite
B.IPsec VPN
C.IP routing
D.NAT
AnswerC

Enabling IP routing on the Cisco CSR 1000v allows it to route traffic between different VLANs. By default, routing may be disabled. Once enabled with the 'ip routing' command, the router can forward packets between subnets, including those on different VLANs, provided interfaces are configured correctly.

Why this answer

To forward traffic between different VLANs, a Cisco CSR 1000v must have IP routing enabled. This allows the router to route packets between subnets configured on different interfaces or subinterfaces. Without IP routing, the router will not forward traffic between VLANs, regardless of other features.

Exam trap

The trap here is confusing features that provide security or isolation, such as VRF Lite or IPsec, with the fundamental requirement of enabling IP routing for basic inter-VLAN communication.

665
MCQhard

A network automation engineer is using Cisco DNA Center's Intent API to retrieve a list of all network devices. The engineer writes a Python script that sends a GET request to the /dna/intent/api/v1/network-device endpoint. The script receives an HTTP 403 Forbidden response. The engineer has verified that the username and password are correct and that the user has the SUPER-ADMIN-ROLE. What is the most likely cause of the issue?

A.The API endpoint requires a valid X-Auth-Token header, which the script did not include.
B.The script must use HTTPS instead of HTTP to access the API.
C.The user account is locked due to multiple failed login attempts.
D.The API endpoint URL is incorrect and should be /dna/intent/api/v1/network-device/count.
AnswerA

Cisco DNA Center's Intent API uses token-based authentication. After authenticating via /dna/system/api/v1/auth/token, the script must include the returned token in the X-Auth-Token header for subsequent requests. Without this header, the server returns 403 Forbidden even if credentials are correct. The script likely omitted this step, causing the authorization failure.

Why this answer

Cisco DNA Center's Intent API requires token-based authentication. The script must first obtain a token from the authentication endpoint and then include it in the X-Auth-Token header for all subsequent API calls. Without this header, the server returns 403 Forbidden, indicating the request lacks proper authorization.

Correct credentials alone are insufficient; the token is mandatory.

Exam trap

The trap here is assuming that correct username and password are sufficient for API access, overlooking the need for a token in the X-Auth-Token header.

666
MCQeasy

A network engineer is configuring a new Cisco Catalyst switch to connect to an existing network. The uplink to the distribution switch is configured as a trunk. The engineer wants to ensure that the trunk uses 802.1Q encapsulation and that the native VLAN is set to VLAN 100. The distribution switch is a Cisco Catalyst 3850. Which configuration should the engineer apply on the uplink interface?

A.switchport mode trunk; switchport trunk native vlan 100
B.switchport trunk encapsulation dot1q; switchport mode trunk; switchport trunk native vlan 100
C.switchport mode dynamic desirable; switchport trunk native vlan 100
D.switchport mode trunk; switchport trunk allowed vlan 100
AnswerA

This is the correct configuration. The command 'switchport mode trunk' forces the interface into permanent 802.1Q trunking mode, independent of DTP negotiation. Adding 'switchport trunk native vlan 100' correctly changes the native VLAN assignment from the default VLAN 1 to VLAN 100, so untagged traffic on this trunk is interpreted as belonging to VLAN 100. This combination reliably establishes a trunk with the desired native VLAN.

Why this answer

On modern Cisco Catalyst switches that run LAN Base or IP Base software, the default trunk encapsulation is 802.1Q, so the 'switchport trunk encapsulation dot1q' command is not required. The 'switchport mode trunk' forces the interface into trunking mode, and 'switchport trunk native vlan 100' sets the native VLAN to 100, which matches the requirement.

Exam trap

Cisco often tests the fact that on modern switches (like the 3850), the 'switchport trunk encapsulation dot1q' command is not available because 802.1Q is the only supported encapsulation, leading candidates to incorrectly include it.

How to eliminate wrong answers

Option B is wrong because on a Catalyst 3850 (which runs IOS XE), the 'switchport trunk encapsulation dot1q' command is not supported; the switch only supports 802.1Q encapsulation and does not accept this command, making it invalid. Option C is wrong because 'switchport mode dynamic desirable' uses DTP to negotiate trunking, which does not guarantee the interface will become a trunk and does not set the native VLAN to 100. Option D is wrong because 'switchport trunk allowed vlan 100' restricts the trunk to only VLAN 100, rather than setting the native VLAN to 100, which is a different function.

667
Drag & Dropmedium

Drag and drop the steps of IPFIX template negotiation and export into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The exporter first sends a template set to the collector, the collector acknowledges, then the exporter sends data records using that template, and templates may be withdrawn or resent periodically.

668
Drag & Dropmedium

Drag and drop the steps of Hierarchical QoS (H-QoS) parent/child policy steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

H-QoS uses a child policy for per-class actions and a parent policy to shape aggregate traffic. The order ensures child policy is defined first, then parent references it, and finally applied to the interface.

669
MCQeasy

An engineer is using Ansible to automate the configuration of NTP on a group of Cisco IOS-XE switches. The playbook uses the ios_ntp module. The engineer wants to ensure that the NTP configuration is applied only to switches that are in the 'core' group, not the 'access' group. The inventory file defines these groups. Which Ansible feature should the engineer use to restrict the playbook to the 'core' group?

A.Use the 'when' clause to check if the switch is in the 'core' group using the 'group_names' variable.
B.Set the 'hosts' field in the play to 'core' instead of 'all'.
C.Use the 'limit' option when running the ansible-playbook command to specify the 'core' group.
D.Define a variable in the 'core' group and use 'vars_prompt' to ask the engineer which group to run on.
AnswerB

Setting hosts: core in the play header is the most direct, idempotent way to restrict execution to only those switches that belong to the 'core' inventory group. The hosts field accepts an inventory pattern or group name, and Ansible evaluates the pattern before the play starts, so no hosts outside the group are even considered for connection. This is the standard Ansible playbook design feature for targeting a subset of managed nodes.

Why this answer

Setting the 'hosts' field in the play to 'core' directly targets only the switches in the 'core' group from the inventory. This is the standard Ansible method for restricting a playbook to a specific inventory group, ensuring that the ios_ntp module configures NTP only on those devices.

Exam trap

Cisco often tests the distinction between inventory-based targeting (using the 'hosts' field) versus runtime conditionals (using 'when') or command-line overrides (using 'limit'), leading candidates to overcomplicate the solution when the simplest, most direct method is correct.

How to eliminate wrong answers

Option A is wrong because the 'when' clause with 'group_names' would check a condition at runtime, but it is inefficient and unnecessary when the 'hosts' directive can directly target the group; also, 'group_names' is a list variable that requires proper syntax and may cause unexpected behavior if not used correctly. Option C is wrong because the 'limit' option is a command-line override that can be used to further restrict execution, but it is not the primary or recommended way to restrict a playbook to a group within the play definition itself; relying on 'limit' makes the playbook less portable and more error-prone. Option D is wrong because 'vars_prompt' is used to prompt for variables during execution, not to restrict which group of hosts a play runs on; it does not control the target hosts and would not prevent the play from running on all hosts if 'hosts: all' is set.

670
MCQmedium

A data center architect is designing a virtualized environment for a latency-sensitive application. The application requires dedicated CPU cores and memory to avoid performance degradation. Which hypervisor feature should be configured to meet this requirement?

A.Enable CPU pinning and memory reservation for the VM.
B.Use a shared storage solution to reduce I/O latency.
C.Configure the VM with a large vNUMA node to spread memory access.
D.Enable memory overcommitment to maximize utilization.
AnswerA

CPU pinning binds the VM's vCPUs to specific physical cores, preventing other VMs from scheduling on those pCPUs and eliminating runqueue contention. Memory reservation guarantees that the hypervisor always allocates the VM's required memory from physical RAM, so the VM never suffers from ballooning or swapping. Together these provide deterministic CPU and memory access, directly mitigating the jitter and latency caused by noisy neighbors.

Why this answer

CPU pinning binds a VM's virtual CPUs to specific physical cores, ensuring dedicated processing resources and preventing CPU contention from other VMs. Memory reservation guarantees that the specified amount of physical memory is always available to the VM, eliminating the risk of memory swapping or ballooning that would introduce latency. Together, these features provide the deterministic performance required for latency-sensitive applications in a virtualized environment.

Exam trap

Cisco often tests the distinction between resource allocation features that guarantee performance (CPU pinning and memory reservation) versus features that optimize utilization or storage I/O, leading candidates to mistakenly select shared storage or memory overcommitment when the question explicitly demands dedicated resources.

How to eliminate wrong answers

Option B is wrong because shared storage solutions (e.g., NFS, iSCSI, Fibre Channel) address I/O latency for storage access, not CPU or memory contention; the question specifically requires dedicated CPU cores and memory, not storage performance. Option C is wrong because configuring a VM with a large vNUMA node spreads memory access across multiple NUMA nodes, which can increase remote memory access latency and degrade performance for latency-sensitive applications; the goal is to keep memory access local, not spread it. Option D is wrong because memory overcommitment allows the hypervisor to allocate more virtual memory to VMs than physical memory exists, relying on swapping or ballooning to reclaim memory, which introduces unpredictable latency and violates the requirement for dedicated memory.

671
MCQhard

A network administrator is configuring a Cisco IOS router to authenticate OSPF neighbors using MD5. The router must use key 1 with the password 'Cisco123' on interface GigabitEthernet0/0. Which configuration is correct?

A.interface GigabitEthernet0/0 ip ospf authentication-key Cisco123 ip ospf authentication
B.router ospf 1 area 0 authentication message-digest ip ospf message-digest-key 1 md5 Cisco123
C.interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 Cisco123
D.router ospf 1 authentication message-digest message-digest-key 1 md5 Cisco123
AnswerC

This configuration enables OSPF MD5 authentication on the interface and defines the key with ID 1 and password 'Cisco123'. The 'ip ospf authentication message-digest' command activates MD5 authentication for OSPF on that interface, and the 'ip ospf message-digest-key' command specifies the key. This is the correct method to configure MD5 authentication on a per-interface basis in Cisco IOS.

Why this answer

To enable OSPF MD5 authentication on a specific interface, you must enter interface configuration mode, enable MD5 authentication with 'ip ospf authentication message-digest', and define the key with 'ip ospf message-digest-key 1 md5 Cisco123'. This ensures that OSPF packets on that interface are authenticated using MD5, meeting the security requirement.

Exam trap

The trap here is confusing area-wide authentication with interface-level key configuration, leading to placing the key under the OSPF process instead of the interface.

672
MCQmedium

Given the configuration: flow monitor FM-1 exporter EXPORTER-1 record netflow ipv4 original-input cache timeout active 60 cache timeout inactive 15 ! What is the effect of the 'cache timeout active 60' command?

A.Flows that are active for more than 60 seconds are exported immediately and then removed from the cache.
B.Flows that are inactive for 60 seconds are exported and removed from the cache.
C.The cache will hold a maximum of 60 active flows at any time.
D.Flow records are sent to the exporter every 60 seconds.
AnswerA

This statement is correct, but the nuance is that when the active timeout (configured with 'ip flow-cache timeout active 60') expires, the flow is exported immediately to the collector, yet if the flow is still in progress, NetFlow creates a new cache entry to track the continuation of the same session. This prevents long-lived flows (e.g., large file transfers) from being invisible until they end, providing periodic accounting updates. The original cache entry is indeed removed after export, but the flow's data is not lost; it is continued in the new entry with a fresh start time.

Why this answer

The 'cache timeout active 60' command configures the NetFlow cache to export and remove any flow that has been active for 60 seconds, even if it is still ongoing. This ensures that long-lived flows are reported periodically rather than waiting until the flow ends, which could delay visibility into sustained traffic patterns.

Exam trap

Cisco often tests the distinction between 'active' and 'inactive' timeouts, and the trap here is confusing the active timeout (which exports long-lived flows while they are still active) with the inactive timeout (which exports flows that have stopped sending data).

How to eliminate wrong answers

Option B is wrong because it describes the behavior of the 'cache timeout inactive' command, which exports flows that have been idle for the specified time, not the active timeout. Option C is wrong because the command does not limit the number of flows in the cache; it sets a time-based export trigger, and cache size is controlled by the 'cache entries' command. Option D is wrong because the command does not define a periodic export interval for all records; it only triggers export for individual flows that have been continuously active for 60 seconds, and the 'cache timeout active' timer resets after each export for that flow.

673
MCQmedium

An organization uses Cisco DNA Center to automate network provisioning. A network engineer deploys a new access switch but finds that the switch does not receive the intended configuration template. The switch appears in DNA Center inventory with status 'Managed'. What is the most likely cause?

A.The switch has not been discovered by DNA Center
B.The switch is not in Plug and Play mode
C.The switch does not have a valid DNA license
D.The switch is not assigned to a site
AnswerD

In DNA Center, CLI templates are created and then associated with a site, and devices that are not assigned to a site cannot be targeted by the provisioning workflow that applies those templates. Template configuration via the 'Provision' workflow only operates on devices that belong to a selected site in the network hierarchy. Thus the correct fix is to assign the switch to a site, after which the templates and compliance checks become applicable.

Why this answer

In Cisco DNA Center, configuration templates are applied based on site assignment. A switch that appears as 'Managed' in inventory has been discovered and is under DNA Center's control, but if it is not assigned to a specific site, DNA Center cannot determine which template to push. Site assignment is a prerequisite for template-based provisioning; without it, the intended configuration will not be deployed.

Exam trap

Cisco often tests the distinction between 'Managed' and 'Provisioned' states, trapping candidates who assume that a device being managed automatically means it has received its configuration.

How to eliminate wrong answers

Option A is wrong because the switch appears in inventory with status 'Managed', which means it has already been discovered by DNA Center. Option B is wrong because Plug and Play (PnP) is a separate provisioning method; DNA Center can apply templates to switches that are not in PnP mode as long as they are managed and site-assigned. Option C is wrong because a valid DNA license is required for advanced features but not for basic template application; the switch being 'Managed' indicates it has the necessary licensing to be under DNA Center control.

674
MCQeasy

A network administrator is planning a new Cisco Catalyst switch stack and wants to verify that the stacking cables provide redundancy so that the loss of a single stacking link does not split the stack. The switches support StackWise-480. Which cabling practice should the administrator follow to achieve a resilient stack ring?

A.Connect only the first and last switches in the stack and leave the middle switches unconnected.
B.Connect the switches in a full mesh using a separate cable between every pair of switches.
C.Connect each switch to the next and the last switch back to the first to form a ring.
D.Connect the switches in a single daisy chain using one cable between each pair of switches.
AnswerC

StackWise-480 uses a ring topology in which each switch connects to the next and the final switch connects back to the first. This loop allows traffic to flow in either direction, so a single cable or switch failure does not split the stack. That matches the requirement for a resilient stack ring.

Why this answer

A StackWise-480 stack should be cabled as a ring, with each switch connected to the next and the last switch connected back to the first. This loop gives the stack two paths for stacking traffic, so a single link failure does not split the stack, which is exactly what the administrator needs.

Exam trap

The trap here is thinking that any cabling that connects all switches is sufficient, when StackWise-480 specifically needs a closed ring to survive a single link failure.

675
Drag & Dropmedium

Drag and drop the steps for the DHCP DORA process in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

DHCP uses Discover, Offer, Request, Acknowledge (DORA) for dynamic address assignment.

Page 8

Page 9 of 26

Page 10