Courseiva

CCNA Architecture Questions

75 of 142 questions · Page 1/2 · Architecture · Answers revealed

1
MCQhard

A network architect is designing a Cisco SD-Access fabric. The customer requires that the fabric support both IPv4 and IPv6 traffic natively without the use of any translation mechanisms. Which statement describes the correct configuration approach?

A.The fabric underlay must be configured with IPv6 only, and the overlay can be dual-stack.
B.IPv6 is not supported in SD-Access; only IPv4 is supported in the overlay.
C.IPv6 traffic must be translated to IPv4 at the fabric edge using NAT64.
D.The fabric overlay can be configured as dual-stack, supporting both IPv4 and IPv6, while the underlay remains IPv4.
AnswerD

Cisco SD-Access supports a dual-stack overlay, meaning that both IPv4 and IPv6 packets can be encapsulated in VXLAN and transported over an IPv4 underlay. This allows native IPv6 communication without translation. The underlay can remain IPv4, as the fabric data plane uses VXLAN with an IPv4 transport. This is the recommended approach for supporting both protocols natively.

Why this answer

Cisco SD-Access supports a dual-stack overlay, allowing both IPv4 and IPv6 to be carried natively over an IPv4 underlay. The VXLAN data plane encapsulates Layer 2 frames, which can carry either IPv4 or IPv6 packets. The underlay can remain IPv4, as it only needs to route the VXLAN tunnel endpoints.

This design meets the requirement for native IPv6 without translation. No translation mechanisms like NAT64 are needed.

Exam trap

The trap here is assuming that native IPv6 support requires an IPv6-only underlay or translation, when in fact the overlay can be dual-stack over an IPv4 underlay.

2
Multi-Selecthard

Which TWO statements are correct about Cisco SD-Access architecture? (Choose two.)

Select 2 answers
A.VXLAN encapsulation is used for data plane traffic within the fabric.
B.Control plane nodes host the LISP mapping database.
C.Wireless access points must be directly connected to the fabric edge switches.
D.Fabric edge nodes are responsible for connecting the fabric to external networks.
E.The fabric uses VLANs to isolate tenant traffic.
AnswersA, B

VXLAN is the encapsulation used to carry Layer 2 frames over Layer 3 fabric.

Why this answer

VXLAN is the encapsulation protocol used in the Cisco SD-Access fabric to carry data plane traffic between fabric edge nodes. VXLAN provides a Layer 2 overlay over a Layer 3 underlay, enabling scalable segmentation and mobility without VLAN limitations.

Exam trap

Cisco often tests the misconception that VLANs are used for fabric segmentation, but the correct answer is VXLAN VNIs; similarly, candidates may confuse the roles of fabric edge and border nodes, thinking edges handle external connectivity.

3
MCQeasy

A network engineer is configuring a new Cisco Catalyst switch for a small branch office. The engineer needs to ensure that the switch can be managed remotely via SSH and that only encrypted management traffic is allowed. The management VLAN is VLAN 10, and the switch's management IP address will be 10.10.10.2/24. Which command must be entered to assign the management IP address to the switch?

A.ip default-gateway 10.10.10.2
B.management ip address 10.10.10.2 255.255.255.0
C.interface gigabitethernet0/1 -> ip address 10.10.10.2 255.255.255.0
D.interface vlan 10 -> ip address 10.10.10.2 255.255.255.0
AnswerD

To assign an IP address for management on a Cisco switch, you create an SVI for the management VLAN and assign the IP address under that interface. This is the correct method because it allows the switch to be reachable on VLAN 10. The command sequence is entered in global configuration mode: interface vlan 10, then ip address 10.10.10.2 255.255.255.0. This enables SSH management when combined with proper default gateway and SSH configuration.

Why this answer

On Cisco switches, management IP addresses are assigned to a switched virtual interface (SVI) representing the management VLAN. The correct command sequence is to enter interface configuration mode for the management VLAN and assign the IP address and subnet mask. This allows the switch to be managed via SSH on that VLAN.

The other options either assign an IP to a physical interface (not typical for switches), set a default gateway without an IP, or use an invalid command.

Exam trap

The trap here is confusing the method for assigning management IPs on switches (SVI) with routers (physical interface), or thinking a default gateway command assigns an IP.

4
MCQeasy

A network engineer is implementing Cisco SD-Access and needs to understand the role of the LISP protocol. Which statement accurately describes the function of LISP in SD-Access?

A.LISP dynamically assigns IP addresses to endpoints in the fabric.
B.LISP enforces security policies between fabric segments.
C.LISP is used for data plane encapsulation between fabric nodes.
D.LISP provides the control plane for mapping endpoint identities to their locations.
AnswerD

In Cisco SD-Access, LISP (Locator/ID Separation Protocol) serves as the control plane protocol that separates endpoint identity (EID) from its location (RLOC). It maintains a mapping database that allows fabric edge nodes to query the mapping system to locate endpoints. This enables scalable, dynamic endpoint mobility and policy enforcement across the fabric.

Why this answer

LISP in SD-Access acts as the control plane, separating endpoint identity from location. It maintains a mapping database that fabric edge nodes query to resolve EID-to-RLOC mappings, enabling scalable endpoint mobility and fabric operations. The data plane uses VXLAN, while policy is enforced via TrustSec SGTs.

Exam trap

The trap here is confusing LISP with VXLAN, assuming LISP provides data plane encapsulation when it actually provides control plane mapping.

5
MCQhard

A network administrator is deploying a Cisco SD-WAN solution. The administrator wants to ensure that control plane information is securely distributed between vSmart controllers and vEdge routers. Which protocol does Cisco SD-WAN use for this purpose?

A.BGP
B.IPsec
C.DTLS
D.OMP
AnswerD

Overlay Management Protocol (OMP) is the control plane protocol used in Cisco SD-WAN. It runs between vSmart controllers and vEdge routers to distribute routing, policy, and service information securely. OMP uses TLS for encryption and authentication, ensuring secure communication. It is the correct protocol for this requirement.

Why this answer

Cisco SD-WAN uses Overlay Management Protocol (OMP) for control plane communication between vSmart controllers and vEdge routers. OMP distributes routing, policy, and service information, and it runs over secure TLS/DTLS sessions. While BGP, IPsec, and DTLS play roles in SD-WAN, OMP is the specific control plane protocol that enables the overlay network's dynamic routing and policy enforcement.

Exam trap

The trap here is confusing the transport security protocol (DTLS) with the actual control plane routing protocol (OMP), or assuming that BGP is used for overlay control when it is only used for external route exchange.

6
MCQhard

A network designer is evaluating a virtual switch deployment in a Cisco ACI fabric. The requirement is to extend a bridge domain across multiple leaf switches while allowing the fabric to perform distributed IP routing at the leaf for endpoints in that bridge domain. Which ACI construct should the designer use?

A.A VRF with policy-based redirect to a service graph
B.A tenant with a single EPG mapped to a static path
C.A private network with an external bridged domain
D.A bridge domain with hardware proxy and unicast routing enabled
AnswerD

This is correct because enabling unicast routing on a bridge domain, combined with the hardware proxy function, allows the leaf switches to perform distributed gateway routing for endpoints in that bridge domain. The anycast gateway is programmed on every leaf, so traffic is routed at the ingress leaf without tromboning to a central spine, meeting the distributed routing requirement.

Why this answer

In Cisco ACI, distributed first-hop routing is achieved by enabling unicast routing on the bridge domain and using the hardware proxy anycast gateway. This programs the same gateway IP and MAC on every leaf, so endpoints are routed at their ingress leaf. The other constructs address isolation, service insertion, or static endpoint attachment, none of which delivers distributed routing.

Exam trap

The trap here is confusing bridge domain routing attributes with VRF isolation or service-graph features, which do not provide distributed anycast gateway routing at the leaf.

7
MCQhard

A network engineer is designing a QoS policy for a WAN edge router. The router must prioritize voice traffic with strict priority while ensuring that other traffic classes are not starved. The engineer decides to use Low Latency Queueing (LLQ). Which additional mechanism should be configured to prevent starvation of other queues when voice traffic exceeds its allocated bandwidth?

A.Weighted Random Early Detection (WRED) on the voice queue
B.Traffic shaping on the voice class to smooth bursts
C.Policing on the voice class to limit its bandwidth
D.Class-Based Weighted Fair Queueing (CBWFQ) on the voice class
AnswerC

In LLQ, the priority queue is serviced first and can starve other queues if not policed. Configuring policing on the voice class limits the amount of traffic that can enter the priority queue, ensuring that other queues get bandwidth. This is the standard method to prevent starvation in LLQ deployments.

Why this answer

LLQ provides a strict priority queue for voice, but without a policer, the priority queue can consume all available bandwidth and starve other queues. Configuring policing on the voice class limits the priority traffic to a defined rate, ensuring that other classes receive their configured bandwidth. This is the recommended practice for LLQ.

Exam trap

The trap here is thinking that CBWFQ or shaping can prevent starvation, when the correct mechanism is a policer on the priority queue.

8
Multi-Selecthard

A network engineer is implementing Cisco TrustSec in a campus network. Which two components are required to enable Security Group Tagging (SGT) and enforcement? (Choose two.)

Select 2 answers
A.Spanning Tree Protocol (STP) root guard
B.Dynamic Host Configuration Protocol (DHCP) snooping
C.Cisco Identity Services Engine (ISE)
D.Access Control List (ACL) for each user
E.Security Group Tag Exchange Protocol (SXP)
AnswersC, E

Cisco ISE is the policy server that assigns SGTs to users and devices during authentication. It also defines security group access control policies (SGACLs) that determine which tags can communicate. Without ISE, there is no centralized source for tag assignment and policy, so it is a fundamental component of a TrustSec deployment.

Why this answer

To implement Cisco TrustSec with SGT tagging and enforcement, Cisco ISE is required to assign SGTs and define policies, and SXP is needed to propagate SGT mappings to non-TrustSec-capable devices. Together, they enable scalable group-based access control across the network.

Exam trap

The trap here is thinking that traditional security features like DHCP snooping or per-user ACLs are part of TrustSec, when TrustSec uses SGTs and SGACLs managed by ISE.

9
MCQmedium

A network architect is designing a three-tier campus network with a pair of Cisco Catalyst 9500 switches at the core. The design requires that the core layer avoid maintaining a large MAC address table and instead forward traffic based on Layer 3 reachability. Which technology should be implemented on the core switches to meet this requirement?

A.VLAN Trunking Protocol pruning
B.Layer 3 switching with routed ports
C.Routed access layer
D.Cisco StackWise Virtual
AnswerB

Configuring the core switches with routed ports (no switchport) enables pure Layer 3 forwarding, eliminating MAC address table entries for those interfaces and relying on routing protocols or static routes. This directly satisfies the requirement to avoid a large MAC address table and forward based on Layer 3 reachability, which is typical in a three-tier campus core.

Why this answer

In a three-tier campus design, the core layer should be optimized for high-speed Layer 3 forwarding. Using routed ports on the core switches eliminates Layer 2 switching and MAC address table scaling concerns, allowing the core to forward solely based on Layer 3 reachability. This aligns with Cisco's recommended design for large campus networks.

Exam trap

The trap here is assuming that any high-availability technology like StackWise Virtual automatically converts the core to Layer 3 forwarding, when in fact it only provides logical device consolidation.

10
Multi-Selecthard

A network architect is evaluating Cisco SD-Access fabric deployment options for a large campus. The design team wants to understand the roles that fabric nodes play in forwarding traffic and in connecting the fabric to external networks. Which two statements accurately describe Cisco SD-Access fabric node roles? (Choose two.)

Select 2 answers
A.Fabric intermediate nodes maintain the LISP map database and answer EID-to-RLOC queries from edge nodes.
B.Fabric border nodes are responsible for registering wired endpoint EIDs and building VXLAN tunnels to access switches.
C.Fabric edge nodes run the LISP map-server and map-resolver functions for the entire fabric.
D.Fabric border nodes connect the SD-Access fabric to external networks and perform route redistribution between the fabric and external routing domains.
E.Fabric edge nodes encapsulate traffic from wired endpoints into VXLAN and register endpoint EIDs with the control-plane node.
AnswersD, E

Fabric border nodes provide the handoff between the fabric and external networks such as data center, WAN, or legacy campus. They run routing adjacencies and redistribute or leak routes between the fabric's VXLAN domain and outside domains, which is exactly what the scenario describes.

Why this answer

In Cisco SD-Access, fabric edge nodes encapsulate endpoint traffic in VXLAN and register EIDs with the control-plane node, while fabric border nodes connect the fabric to external networks and redistribute routes. Those two roles match the accurate statements, whereas intermediate and control-plane responsibilities are assigned incorrectly elsewhere.

Exam trap

The trap here is mixing up the control-plane node's LISP map-server duties with the forwarding duties of intermediate and edge nodes.

11
MCQhard

A network administrator is implementing Cisco TrustSec in a data center. The security team wants to enforce segmentation based on user roles rather than IP addresses. The administrator has configured security group tags (SGTs) on the access layer switches and now needs to propagate this information across the network. Which protocol should be used to carry SGT information between Cisco TrustSec-capable devices?

A.RADIUS
B.TACACS+
C.SXP
D.802.1X
AnswerC

SXP (SGT Exchange Protocol) is used to propagate SGT information between Cisco TrustSec-capable devices, especially when some devices do not support hardware-based SGT tagging. It allows IP-to-SGT mappings to be shared across network boundaries, enabling consistent policy enforcement. In this scenario, SXP is the correct protocol to carry SGT information between devices that need to enforce role-based segmentation.

Why this answer

SXP (SGT Exchange Protocol) is designed to propagate SGT-to-IP mappings between Cisco TrustSec domains, particularly when devices cannot natively tag packets with SGTs. It enables policy enforcement across network boundaries by sharing the mapping of IP addresses to security groups. This allows consistent role-based segmentation even in mixed environments.

Exam trap

The trap here is assuming that RADIUS, which can deliver SGTs during authentication, also propagates SGTs between network devices for enforcement, when that is the role of SXP.

12
MCQhard

A network engineer is deploying a new branch office that connects to the headquarters via a Cisco SD-WAN solution. The branch has two WAN transports: an MPLS circuit and a broadband internet link. The engineer wants to ensure that business-critical traffic uses the MPLS circuit while guest traffic uses the broadband link, and that failover occurs automatically if the MPLS circuit degrades. Which Cisco SD-WAN feature should be configured to meet these requirements?

A.Policy-based routing (PBR) using route maps that match on source subnet.
B.Static routes with administrative distance manipulation on the branch router.
C.Application-aware routing policy with SLA classes and path preference.
D.Per-VPN QoS trust boundaries on the branch edge interfaces.
AnswerC

Application-aware routing policies in Cisco SD-WAN use SLA classes to monitor path characteristics such as latency, jitter, and loss. By associating business-critical traffic with an SLA class that prefers MPLS and configuring a fallback to broadband, the engineer ensures preferred path selection and automatic failover when the MPLS circuit degrades.

Why this answer

Cisco SD-WAN application-aware routing uses SLA classes to continuously monitor path performance and select the best path per application. By mapping business-critical traffic to an SLA class that prefers MPLS and falls back to broadband, and guest traffic to a policy that prefers broadband, the engineer achieves both path separation and automatic failover on degradation.

Exam trap

The trap here is confusing QoS or PBR with application-aware routing, which is the SD-WAN feature that actually monitors SLA and performs dynamic path selection.

13
Multi-Selectmedium

A network architect is designing a Cisco SD-WAN fabric using vManage, vSmart, and vBond controllers. Which two statements accurately describe the control plane and onboarding behavior in this architecture? (Choose two.)

Select 2 answers
A.The vBond controller must be deployed behind a NAT device and cannot have a public IP address.
B.WAN Edge devices must run OSPF in the overlay to exchange routes with each other.
C.The vBond controller authenticates and orchestrates initial connectivity between WAN Edge devices and the controllers.
D.The vManage controller forwards user data traffic between WAN Edge devices in the data plane.
E.The vSmart controller distributes control-plane policies and routes overlay topology information to WAN Edge devices via OMP.
AnswersC, E

This is correct because vBond is the first point of contact for WAN Edge devices; it validates their identity and provides the information needed to reach vManage and vSmart. It acts as the orchestrator for control connections, enabling secure onboarding without pre-configuring every peer address on each edge device.

Why this answer

In Cisco SD-WAN, vBond handles authentication and orchestration of initial control connections, while vSmart is the control plane that uses OMP to distribute routing and policy information. vManage is management plane only, OSPF is not the overlay routing protocol, and vBond generally needs public reachability for discovery.

Exam trap

The trap here is mixing management-plane and control-plane roles, such as assuming vManage forwards data or that OSPF runs in the overlay instead of OMP.

14
MCQmedium

A network administrator is configuring a Cisco wireless controller for a branch office. The design requires that guest clients be isolated from corporate clients while still using the same physical access points. Which Cisco wireless architecture feature should be used to separate the traffic?

A.Enable Peer-to-Peer Blocking on the guest WLAN.
B.Configure separate WLANs mapped to different VLANs and apply an interface group.
C.Configure the access points in local mode and use FlexConnect local switching for all WLANs.
D.Use a separate WLAN with a guest VLAN and enforce ACLs or a firewall between the guest and corporate subnets.
AnswerD

Creating a dedicated guest WLAN mapped to a separate VLAN, combined with ACLs or firewall rules between the guest and corporate subnets, provides clear Layer 2 and Layer 3 separation. This approach isolates guest traffic while allowing shared physical access points. It directly satisfies the requirement to separate guest and corporate clients, making it the correct design choice.

Why this answer

Guest isolation in a Cisco wireless deployment is achieved by placing guest clients on a dedicated WLAN and VLAN, then enforcing separation at Layer 3 with ACLs or a firewall. Peer-to-Peer Blocking only stops client-to-client traffic within a WLAN, interface groups are for dynamic interface mapping, and FlexConnect local switching addresses traffic forwarding rather than segmentation.

Exam trap

The trap here is treating Peer-to-Peer Blocking or interface groups as security segmentation tools, when they do not isolate traffic between different WLANs or VLANs.

15
MCQmedium

A network architect is designing a new branch office that must run Cisco SD-WAN with a single WAN transport and requires all control-plane and data-plane traffic to be encrypted by default using DTLS/TLS tunnels managed by the controller. Which SD-WAN component is responsible for establishing the secure control connections and distributing route and policy information to the branch edge devices?

A.vAnalytics engine
B.vManage NMS
C.vSmart controller
D.vBond orchestrator
AnswerC

The vSmart controller is the SD-WAN control-plane component that builds DTLS/TLS control connections with each vEdge/cEdge and distributes OMP routes, TLOCs, and centralized policy. In this branch scenario, the edge device registers to vSmart, which pushes the routing and policy information needed for the single-transport overlay, making it the component that owns control-plane distribution.

Why this answer

In Cisco SD-WAN, the control plane is handled by the vSmart controller, which peers with each edge device over DTLS/TLS and uses OMP to advertise TLOCs, routes, and centralized policy. The branch edge in this design needs those control connections, so the vSmart controller is the component that satisfies the requirement.

Exam trap

The trap here is assuming that vManage, because it is the centralized GUI, also acts as the control plane that distributes routes and policy to edge devices.

16
MCQmedium

A company is implementing QoS in a network where voice traffic must have strict priority over all other traffic. Which queuing mechanism should be used on the outbound interface of a router to ensure voice packets are always sent first?

A.Random Early Detection (RED)
B.Low Latency Queuing (LLQ)
C.First In First Out (FIFO)
D.Class-Based Weighted Fair Queuing (CBWFQ)
AnswerB

LLQ (Low Latency Queuing) combines a strict-priority queue with CBWFQ: the priority queue is serviced first on every scheduling cycle, before any CBWFQ class queues, so voice is dequeued with minimal and deterministic delay. The priority queue can be policed to a configured rate to prevent a flood of priority traffic from starving the non-priority classes, but within the committed rate voice effectively experiences 'express lane' treatment. This strict-priority scheduling is exactly what makes LLQ the standard QoS queueing strategy for real-time voice traffic in an enterprise.

Why this answer

Low Latency Queuing (LLQ) is the correct choice because it combines Class-Based Weighted Fair Queuing (CBWFQ) with a strict priority queue, ensuring that voice traffic (marked with EF or CS5) is always dequeued before any other traffic class. This guarantees low latency and jitter for real-time traffic, which is essential for voice quality.

Exam trap

Cisco often tests the distinction between CBWFQ and LLQ, trapping candidates who think CBWFQ alone provides priority queuing, when in fact LLQ is required to add the strict priority queue for real-time traffic.

How to eliminate wrong answers

Option A is wrong because Random Early Detection (RED) is a congestion avoidance mechanism that drops packets probabilistically before a queue fills, not a queuing mechanism that prioritizes traffic. Option C is wrong because First In First Out (FIFO) treats all packets equally with no priority, causing voice packets to be delayed behind data bursts. Option D is wrong because Class-Based Weighted Fair Queuing (CBWFQ) provides bandwidth guarantees per class but does not include a strict priority queue, so voice traffic can still experience delay during congestion.

17
MCQeasy

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) and needs to ensure that the management interface is reachable from the wired network. Which interface on the WLC is used for out-of-band management and is typically assigned an IP address on the management VLAN?

A.Management interface
B.Virtual interface
C.Dynamic interface
D.AP-manager interface
AnswerA

The management interface on a Cisco WLC is used for out-of-band management, including GUI, CLI, and RADIUS communication. It is typically assigned an IP address on the management VLAN and is essential for controller reachability. It is the primary interface for administrative access.

Why this answer

The management interface on a Cisco WLC is used for out-of-band management, providing administrative access via GUI, CLI, and RADIUS. It is assigned an IP address on the management VLAN and is critical for controller reachability. Dynamic, AP-manager, and virtual interfaces serve different purposes.

Exam trap

The trap here is assuming the AP-manager interface handles management because it manages access points, but it is specifically for AP communication, not administrative access.

18
MCQhard

A network architect is evaluating Cisco SD-WAN for a company with 50 branch sites and two data centers. The design must provide application-aware routing, direct internet access at branches, and centralized policy management. Which Cisco SD-WAN component is responsible for distributing policies and reachability information to the branch devices?

A.vBond
B.vManage
C.vEdge or cEdge router
D.vSmart
AnswerD

vSmart is the control plane component that distributes policies and reachability information to all SD-WAN devices. It uses OMP to share routing and policy data, enabling application-aware routing and centralized policy enforcement. The branch devices receive their forwarding policies and route information from vSmart, making it the correct answer.

Why this answer

The vSmart controller is the control plane component of Cisco SD-WAN, responsible for distributing policies and reachability information using OMP. It enables centralized policy management and application-aware routing by sharing routing and policy data with all SD-WAN devices in the overlay.

Exam trap

The trap here is confusing the management plane function of vManage with the control plane function of vSmart, leading to the selection of vManage for policy distribution.

19
MCQmedium

A mid-size enterprise is deploying a new branch office with 50 users. The branch will have its own router, switch, and wireless AP. The WAN link is a 50 Mbps MPLS circuit. The company uses VoIP and requires Quality of Service. The network administrator has configured the router with a QoS policy that marks VoIP traffic with DSCP EF and all other traffic with DSCP 0. The policy also shapes traffic to 50 Mbps. After deployment, users report that voice quality is poor during peak hours. The administrator checks the router and sees that the output queue on the WAN interface is often full and drops are occurring. Which action should the administrator take to improve voice quality?

A.Increase the shaping rate to 60 Mbps to allow for burst.
B.Configure a priority queue for DSCP EF traffic within the shaper.
C.Replace shaping with policing to drop non-voice traffic.
D.Change the marking to use CoS instead of DSCP for better QoS.
AnswerB

A priority queue, implemented via LLQ (Low Latency Queuing) within the CBWFQ shaper, ensures that DSCP EF voice packets are dequeued ahead of all other classes before the shaped output is released. This guarantees that voice traffic experiences low latency and jitter, and critically, that voice packets are not tail-dropped when the shaper's buffer is temporarily congested due to bursts. The priority queue's strict scheduling protects real-time traffic from the queue-full condition that causes drops in other classes.

Why this answer

The shaper is limiting traffic to 50 Mbps, but during peak hours, the aggregate traffic exceeds this rate, causing the output queue to fill and drop packets indiscriminately. By configuring a priority queue for DSCP EF (VoIP) traffic within the shaper, the router will service VoIP packets before other traffic, ensuring low latency and jitter even when the link is congested. This is the standard Cisco approach for voice quality on shaped links, as priority queuing bypasses the normal FIFO or CBWFQ behavior for marked traffic.

Exam trap

Cisco often tests the misconception that increasing bandwidth or policing alone solves voice quality issues, but the trap here is that shaping without a priority queue causes all traffic to be treated equally, so VoIP suffers from jitter and delay even if the total rate is within the shaped limit.

How to eliminate wrong answers

Option A is wrong because increasing the shaping rate to 60 Mbps does not solve the underlying congestion; it only shifts the bottleneck and may cause the provider to drop traffic if the CIR is strictly 50 Mbps, leading to continued packet loss for VoIP. Option C is wrong because policing would drop excess traffic indiscriminately, including VoIP packets, unless a separate policer is applied per class, and it does not provide the strict priority queuing needed for voice. Option D is wrong because changing the marking to CoS (Layer 2) does not improve QoS on a WAN interface that typically uses DSCP (Layer 3) for queuing decisions; the router's output queue is based on Layer 3 markings, and CoS is lost when traversing the MPLS network unless explicitly mapped.

20
MCQmedium

A network administrator is configuring a Cisco Catalyst 9300 switch stack using StackWise-480 technology. The administrator wants to ensure that if the active switch fails, the standby switch takes over with minimal disruption. Which statement describes the behavior of the stack during a failover?

A.The stack splits into multiple independent switches, each with its own configuration.
B.The master switch is elected based on the highest MAC address, and all other switches reload.
C.The standby switch becomes active, and the stack retains its configuration and forwarding state.
D.All switches in the stack reload and then elect a new active switch.
AnswerC

In a StackWise-480 deployment, the standby switch is ready to take over if the active switch fails. The stack retains its configuration and forwarding state, and the standby becomes active with minimal disruption. This is the designed behavior for high availability, ensuring that network services continue without a full stack reload.

Why this answer

StackWise-480 provides high availability by maintaining a standby switch that is ready to take over if the active switch fails. The stack retains its configuration and forwarding state, allowing for minimal disruption. The standby switch becomes active, and the member switches continue to operate without a full reload.

Exam trap

The trap here is assuming that a failover causes a stack-wide reload or split, when in fact the standby simply assumes the active role.

21
MCQeasy

A network engineer is deploying a new branch office that requires a WAN connection with built-in encryption and dynamic multipoint VPN capabilities. The engineer wants to use a Cisco technology that supports spoke-to-spoke communication without requiring traffic to traverse the hub. Which technology should be implemented?

A.DMVPN
B.IPsec VPN
C.GRE tunnel
D.MPLS L3VPN
AnswerA

DMVPN (Dynamic Multipoint VPN) allows spoke-to-spoke tunnels to be established on demand, enabling direct communication between branch sites without routing traffic through the hub. It uses mGRE (multipoint GRE) and NHRP (Next Hop Resolution Protocol) to dynamically discover and build tunnels. This matches the requirement for dynamic multipoint VPN with encryption, typically provided by IPsec.

Why this answer

DMVPN is designed to provide dynamic multipoint VPN connectivity, allowing spokes to establish direct tunnels with each other as needed. It combines mGRE, NHRP, and IPsec to deliver scalable, encrypted, and dynamic branch connectivity. This eliminates the need to route spoke-to-spoke traffic through the hub, improving latency and reducing hub bandwidth consumption.

Exam trap

The trap here is confusing IPsec VPN with DMVPN, assuming that any encrypted VPN automatically supports dynamic spoke-to-spoke tunnels, when DMVPN specifically adds the multipoint dynamic capability.

22
MCQmedium

A network engineer is implementing Cisco TrustSec in a campus network. The security team wants to enforce access policies based on user identity and device type without relying on IP addresses. Which component is responsible for assigning Security Group Tags (SGTs) to traffic at the ingress point?

A.Cisco Identity Services Engine (ISE)
B.Cisco Firepower Threat Defense (FTD)
C.Cisco DNA Center
D.Cisco Catalyst switch with TrustSec support
AnswerD

The ingress Cisco Catalyst switch (or wireless controller) is responsible for assigning SGTs to packets based on the classification policy received from ISE. It inserts the SGT into the Cisco Metadata (CMD) field of the packet or uses inline tagging. This enables enforcement throughout the network without relying on IP addresses. Thus, the switch is the component that assigns SGTs at the ingress point.

Why this answer

In Cisco TrustSec, the ingress network device (such as a Catalyst switch or wireless controller) is responsible for classifying and tagging packets with SGTs. This classification is based on policies downloaded from ISE. The switch inserts the SGT into the packet, allowing subsequent devices to enforce access policies without examining IP addresses.

ISE defines the policies but does not perform the tagging.

Exam trap

The trap here is assuming that ISE, as the policy engine, also performs the tagging, when in fact the tagging is done by the ingress network device.

23
MCQhard

A network engineer is deploying Cisco SD-Access and needs to ensure that endpoints in the same virtual network (VN) can communicate across fabric sites while endpoints in different VNs remain isolated. Which control plane component is responsible for propagating endpoint reachability information between fabric sites?

A.Cisco DNA Center fabric site border node
B.Cisco DNA Center fabric intermediate node
C.Cisco DNA Center fabric control plane node
D.Cisco Identity Services Engine policy node
AnswerC

The fabric control plane node runs LISP and maintains the mapping of endpoint EIDs to RLOCs. When a fabric site is connected via a transit network, control plane nodes in each site exchange LISP map-register and map-notify messages so that endpoints in the same VN are reachable across sites while different VNs stay isolated by their respective VRFs and LISP instance IDs.

Why this answer

In Cisco SD-Access, the control plane node runs LISP and is responsible for registering endpoint EID-to-RLOC mappings and sharing them with control plane nodes in other fabric sites over the transit network. This allows endpoints in the same virtual network to be reached across sites while VN isolation is preserved through separate LISP instance IDs and VRFs. Border and intermediate nodes forward data plane traffic but do not propagate reachability.

Exam trap

The trap here is confusing the border node's data plane role in VXLAN encapsulation with the control plane node's LISP responsibility for propagating endpoint reachability between fabric sites.

24
MCQhard

A network engineer is deploying a Cisco SD-WAN solution with two data center sites and 40 branch sites. The design must ensure that traffic from a branch to a critical application in Data Center A always prefers the MPLS transport while using the internet transport only when MPLS latency exceeds a defined threshold. Which Cisco SD-WAN component and feature combination accomplishes this?

A.vSmart controller with application-aware routing policy using SLA classes and preferred transport
B.vManage with CLI templates that set static routes for the application subnet
C.vSmart controller with OSPF cost manipulation on the MPLS transport
D.vBond orchestrator with BFD echo and OMP route redistribution
AnswerA

Application-aware routing policy is created on the vSmart controller and distributed to vEdge or cEdge devices. It defines SLA classes with latency, jitter, and loss thresholds, and can specify a preferred transport such as MPLS. When the SLA is violated, the policy allows failover to the internet transport, exactly matching the requirement to prefer MPLS and fall back on high latency.

Why this answer

Cisco SD-WAN implements application-aware routing policy on the vSmart controller. The policy defines SLA classes with latency, jitter, and loss thresholds and maps applications to preferred transports. When a preferred transport such as MPLS meets the SLA, traffic stays there; when the SLA is violated, the policy permits failover to the internet transport.

The vBond orchestrator, CLI templates, and OSPF cost tuning do not provide this conditional, application-specific behavior.

Exam trap

The trap here is confusing the vBond orchestrator's control-plane role with the vSmart controller's policy and path-selection role.

25
MCQmedium

A network engineer is designing a QoS policy for a WAN edge router. Voice traffic must be serviced with strict priority and guaranteed low latency, while a policer must limit voice to 30 percent of the interface bandwidth to prevent starvation of other queues. Which queuing mechanism should the engineer configure?

A.First-In, First-Out (FIFO) queuing on the WAN interface
B.Class-Based Weighted Fair Queuing (CBWFQ) with a bandwidth guarantee
C.Weighted Random Early Detection (WRED) on the voice class
D.Low Latency Queuing (LLQ) with a priority policer
AnswerD

Low Latency Queuing combines a strict priority queue for voice with a policer that caps the priority traffic at a configured rate, such as 30 percent of interface bandwidth. This ensures voice is serviced first with minimal delay while preventing the priority class from starving other queues if voice traffic exceeds the limit, exactly matching the design requirement.

Why this answer

Low Latency Queuing is the correct choice because it creates a strict priority queue for voice while applying a policer that caps the priority class at a configured rate, such as 30 percent of interface bandwidth. This gives voice minimal delay and jitter while preventing it from consuming all bandwidth. CBWFQ lacks strict priority, WRED is a drop mechanism, and FIFO offers no prioritization or policing.

Exam trap

The trap here is assuming that any bandwidth-guaranteeing queuing method provides strict priority, when only LLQ combines a strict priority queue with a policer to protect other traffic classes from starvation.

26
MCQeasy

A network engineer is configuring a new Cisco Wireless LAN Controller (WLC) and needs to ensure that the WLC can be managed remotely from a different subnet. The WLC is connected to a switch port that is configured as a trunk. Which interface on the WLC must be configured with an IP address to allow remote management?

A.Virtual interface
B.Dynamic interface
C.Service port
D.Management interface
AnswerD

The management interface on a Cisco WLC is used for in-band management. It must be configured with an IP address, subnet mask, and default gateway to allow remote management from a different subnet. This interface is also used for communication with access points, DHCP, and other services. It is typically mapped to a VLAN on the trunk port.

Why this answer

The management interface on a Cisco WLC is the correct interface for remote management. It is configured with an IP address and default gateway, allowing access from different subnets. It is also used for AP communication and other services.

The service port is for out-of-band management, the virtual interface is for internal functions, and dynamic interfaces are for user traffic.

Exam trap

The trap here is confusing the service port with the management interface, as both can be used for management, but only the management interface supports in-band remote management from a different subnet.

27
MCQmedium

A network architect is designing a Cisco SD-Access fabric for a campus network. The architect wants to ensure that endpoints in the same virtual network can communicate with each other even when they are attached to different fabric edge nodes. Which control plane component is responsible for resolving endpoint location information across the fabric?

A.Fabric control plane node
B.Cisco DNA Center
C.Fabric border node
D.Cisco Identity Services Engine (ISE)
AnswerA

The fabric control plane node runs the LISP map-server and map-resolver functions. It maintains the mapping of endpoint IP addresses to fabric edge nodes, enabling communication between endpoints attached to different edge nodes. When an edge node needs to reach an endpoint not locally attached, it queries the control plane node for the location, which returns the RLOC of the correct edge node.

Why this answer

The fabric control plane node in Cisco SD-Access implements LISP map-server and map-resolver functions. It maintains a database of endpoint IP addresses and their corresponding fabric edge node RLOCs. When an endpoint on one edge node needs to communicate with an endpoint on another edge node, the source edge node queries the control plane node to learn the destination's location, enabling VXLAN encapsulation and delivery.

Exam trap

The trap here is assuming that Cisco DNA Center or ISE performs endpoint location resolution, when in fact the fabric control plane node handles that function.

28
MCQhard

A network engineer is designing a high-availability campus network using Cisco StackWise Virtual technology on two Cisco Catalyst 9000 switches. The engineer wants to ensure that the control plane remains operational if one switch fails, and that the data plane can continue forwarding traffic with minimal disruption. Which statement accurately describes the operation of StackWise Virtual in this scenario?

A.One switch is active for control plane and management, while the other is standby; both switches forward data traffic using a unified data plane.
B.StackWise Virtual requires a dedicated Layer 3 link for control plane synchronization, and data traffic is forwarded only by the active switch.
C.The two switches load-balance control plane functions, with each switch managing a subset of VLANs and routing protocols independently.
D.Both switches run independent control planes and synchronize routing tables via a dedicated link, with each switch forwarding traffic independently.
AnswerA

StackWise Virtual combines two switches into a single logical entity. One switch is elected active and handles control plane and management functions, while the other is standby and ready to take over. Both switches actively forward data traffic, providing increased bandwidth and redundancy. This active/standby control plane with active/active data plane is the defining characteristic of StackWise Virtual.

Why this answer

Cisco StackWise Virtual merges two physical switches into one logical switch. The active switch runs the control plane and management, while the standby switch is ready to take over. Both switches forward data traffic, providing active/active forwarding.

This design ensures high availability: if the active switch fails, the standby becomes active, and data forwarding continues on the remaining switch with minimal disruption.

Exam trap

The trap here is assuming that StackWise Virtual uses active/active control planes or that only the active switch forwards traffic, when in fact it is active/standby for control and active/active for data.

29
MCQhard

A network architect is designing a Cisco SD-Access fabric that spans two buildings. The fabric must support Layer 2 extension for a legacy application that requires broadcast traffic to reach hosts in both buildings. The architect plans to use a single fabric with two fabric edge nodes connected to a common control plane node. Which component of the SD-Access architecture is responsible for mapping endpoint identifiers to fabric edge nodes?

A.Fabric intermediate node
B.Control plane node
C.Fabric border node
D.Fabric wireless controller
AnswerB

The control plane node runs the LISP map-server and map-resolver functions, maintaining the database that maps endpoint identifiers (EIDs) to routing locators (RLOCs), which are the fabric edge nodes. When a fabric edge needs to reach an endpoint, it queries the control plane node to learn which edge node is authoritative for that endpoint, enabling proper forwarding.

Why this answer

The control plane node hosts the LISP map-server and map-resolver, which together maintain the EID-to-RLOC mappings that tell fabric edge nodes where each endpoint is located. This mapping is essential for directing traffic to the correct edge node within the SD-Access fabric.

Exam trap

The trap here is assuming that the border node handles all inter-node communication, when in fact the control plane node is the authoritative source for endpoint location mappings.

30
MCQeasy

A company is deploying a wireless network in an office with high client density. Which Cisco architecture is best suited to handle client roaming without requiring a central controller for every roaming event?

A.Mesh networking
B.Autonomous APs
C.Centralized switching with a WLC
D.FlexConnect
AnswerD

FlexConnect is correct because it separates the control plane (which remains with the WLC) from the data plane (which is switched locally at the AP). This allows client traffic to be forwarded directly to the wired network at each access point, avoiding unnecessary latency and controller bottlenecks, which is ideal for high-bandwidth, high-density indoor environments. Furthermore, FlexConnect supports IEEE 802.11r fast roaming and can perform client-based or AP-based neighbor discovery when connected to a WLC, ensuring seamless and fast handoffs as users move across the office. Its design balances centralized management with localized forwarding, offering both the operational consistency of a controller and the performance of distributed switching.

Why this answer

FlexConnect (option D) is the correct architecture because it allows client data traffic to be switched locally at the remote site, while the control plane remains centralized. This design eliminates the need for a central controller to process every roaming event, as clients can roam between FlexConnect APs using local switching and 802.11r (Fast Roaming) without requiring a WLC in the data path.

Exam trap

Cisco often tests the misconception that centralized switching (WLC) is always required for seamless roaming, but FlexConnect decouples the data plane from the control plane to allow local roaming without a central controller in the data path.

How to eliminate wrong answers

Option A is wrong because mesh networking is designed for extending coverage in areas without wired backhaul, not for handling high-density client roaming with local switching; it still relies on a central controller for roaming decisions. Option B is wrong because autonomous APs operate independently without any central coordination, making seamless roaming inefficient and requiring manual configuration for each AP, which is unsuitable for high-density environments. Option C is wrong because centralized switching with a WLC forces all client traffic through the controller, creating a bottleneck and requiring the WLC to process every roaming event, which increases latency and reduces scalability in high-density deployments.

31
MCQmedium

A network architect is designing a new branch office that must support wired and wireless users on the same Layer 2 segment while enforcing consistent security policy regardless of where a user connects. The design must minimize the number of VLANs and IP subnets that must be provisioned as users move between floors. Which Cisco architecture feature should be used to meet these requirements?

A.Cisco StackWise Virtual on the distribution switches
B.Cisco Software-Defined Access with traditional VLAN trunking to the WLC
C.Cisco SD-Access fabric with VXLAN overlay and policy-based segmentation
D.Cisco TrustSec with static SGACL enforcement on access ports
AnswerC

SD-Access decouples identity from location by using a VXLAN overlay, so a user keeps the same IP subnet and security group tag whether wired or wireless. This eliminates per-floor VLAN/subnet sprawl and enforces consistent group-based policy through the fabric, which directly matches the stated requirement for unified wired/wireless policy with minimal VLAN provisioning.

Why this answer

The requirement is location-independent identity with consistent policy and minimal VLAN/subnet provisioning across wired and wireless. SD-Access uses a VXLAN overlay with a LISP control plane and Cisco TrustSec group tags, allowing users to retain the same subnet and policy anywhere in the fabric. StackWise Virtual, standalone TrustSec, and VLAN trunking to a WLC all remain tied to physical VLAN boundaries and cannot deliver the same outcome.

Exam trap

The trap here is assuming that a high-availability feature such as StackWise Virtual also solves address and policy mobility across floors.

32
MCQhard

A network engineer is implementing Cisco TrustSec in a data center. The engineer wants to enforce security policies based on logical groupings of endpoints rather than IP addresses. Which component is used to assign a Security Group Tag (SGT) to traffic at the ingress point?

A.Ingress enforcement device
B.Security Group ACL (SGACL)
C.Egress enforcement device
D.Cisco Identity Services Engine (ISE)
AnswerA

The ingress enforcement device, such as a switch or wireless controller, assigns the SGT to traffic as it enters the network. It can do this statically via port configuration or dynamically based on authentication and authorization from Cisco ISE. The SGT is then carried in the packet, allowing egress devices to enforce SGACLs based on the tag without needing to reclassify the traffic.

Why this answer

In Cisco TrustSec, the ingress enforcement device assigns the Security Group Tag (SGT) to packets as they enter the network. This can be done statically by configuring a port or dynamically via 802.1X authentication and authorization with Cisco ISE. The SGT is then carried in the packet, enabling egress enforcement devices to apply SGACLs based on the tag without re-examining IP addresses.

Exam trap

The trap here is confusing the role of Cisco ISE, which defines and provides SGT information, with the ingress device that actually applies the tag to the traffic.

33
MCQeasy

A network administrator is deploying a new Cisco Catalyst switch in a campus network. The administrator wants to enable a feature that automatically assigns a voice VLAN to Cisco IP phones connected to the switch, based on CDP or LLDP information. Which feature should be configured?

A.VLAN Trunking Protocol
B.Voice VLAN
C.Private VLAN
D.Dynamic ARP Inspection
AnswerB

Voice VLAN is a Cisco feature that automatically assigns a VLAN to IP phones based on CDP or LLDP discovery. The switch detects the phone and places its voice traffic in the configured voice VLAN, while data traffic from a connected PC remains in the access VLAN. This simplifies deployment and ensures QoS for voice.

Why this answer

The Voice VLAN feature allows a switch to automatically assign a VLAN to Cisco IP phones using CDP or LLDP. When a phone is detected, the switch instructs the phone to tag voice traffic with the voice VLAN ID. This separates voice and data traffic, enabling QoS and security policies.

The other options are unrelated to automatic voice VLAN assignment.

Exam trap

The trap here is confusing VLAN management protocols like VTP with endpoint-specific VLAN assignment features like Voice VLAN.

34
MCQeasy

A network engineer is configuring a new Cisco IOS router and needs to ensure that the router can be managed remotely via SSH. The engineer has already generated RSA keys and configured a username and password. Which additional command is required to enable SSH access on the VTY lines?

A.ip ssh version 2
B.login local
C.transport input ssh
D.crypto key generate rsa
AnswerC

The command 'transport input ssh' under the VTY line configuration restricts incoming connections to SSH only, which is required to enable SSH access. Without it, the router may still allow Telnet or other protocols. This command ensures that only secure shell connections are accepted, aligning with the requirement to manage the router via SSH.

Why this answer

To enable SSH access on a Cisco IOS router, after generating RSA keys and configuring local authentication, the VTY lines must be configured with 'transport input ssh'. This command restricts incoming connections to SSH, ensuring secure remote management. The other commands are either prerequisites already completed or additional security settings that do not directly enable SSH on the VTY lines.

Exam trap

The trap here is thinking that generating RSA keys or setting SSH version 2 automatically enables SSH on the VTY lines, when in fact the 'transport input ssh' command is specifically required to allow SSH connections.

35
MCQeasy

A small business has a single router connected to the internet and a switch for the LAN. They want to implement VLANs to separate guest and corporate traffic. The router has only one physical interface to the switch. The network engineer proposes using subinterfaces with 802.1Q trunking on the router interface. Which configuration step is required on the switch port connected to the router?

A.Configure the port as a routed port.
B.Configure the port as an access port in VLAN 1.
C.Configure the port as a trunk port.
D.Configure the port as a dynamic desirable port.
AnswerC

A trunk port carries frames from multiple VLANs and tags each frame with its 802.1Q VLAN ID, except for the native VLAN which remains untagged. Router subinterfaces configured with encapsulation dot1Q can accept these tagged frames, allowing the router to route between VLANs over one physical link. This is the required configuration for router-on-a-stick inter-VLAN routing when a single router interface must handle traffic for many VLANs.

Why this answer

The router uses subinterfaces with 802.1Q trunking to carry multiple VLANs over a single physical link. For this to work, the switch port connected to the router must be configured as a trunk port, which tags frames with VLAN IDs as they traverse the link. This allows the router to route between VLANs using its subinterfaces, each associated with a specific VLAN.

Exam trap

Cisco often tests the misconception that a switch port connecting to a router can remain as an access port or use DTP, but the key is that the router's subinterface requires 802.1Q-tagged frames, which only a statically configured trunk port can provide.

How to eliminate wrong answers

Option A is wrong because a routed port is a Layer 3 interface on a switch, used for routing between networks, not for carrying multiple VLANs over a single link; it would not support 802.1Q trunking. Option B is wrong because an access port belongs to a single VLAN and strips VLAN tags, which would prevent the router from receiving tagged frames for multiple VLANs, breaking the subinterface design. Option D is wrong because dynamic desirable is a DTP (Dynamic Trunking Protocol) mode used to negotiate trunking between Cisco switches, but it is not required or recommended for a router-to-switch connection; the router interface does not participate in DTP, so the switch port must be statically set as a trunk.

36
MCQhard

A network architect is designing a campus network that must support seamless mobility for wireless clients across Layer 3 boundaries. The design requires that clients retain their IP address when roaming between different subnets. Which Cisco technology should be implemented to achieve this?

A.Cisco Application Centric Infrastructure (ACI) with endpoint groups
B.Cisco Overlay Transport Virtualization (OTV) between campus buildings
C.Cisco FabricPath with Layer 3 forwarding
D.Cisco Locator/ID Separation Protocol (LISP) with mobility
AnswerD

LISP separates endpoint identity from location, allowing a client to keep its IP address while its location changes. In a campus design, LISP can be used to provide seamless mobility across Layer 3 boundaries by updating the mapping of the endpoint identifier to its new routing locator.

Why this answer

LISP separates endpoint identity from location, enabling a wireless client to retain its IP address as it roams across Layer 3 boundaries. The client's endpoint identifier remains constant, while the mapping to its new routing locator is updated in the LISP mapping system. This makes LISP the appropriate technology for seamless mobility in a campus design.

Exam trap

The trap here is confusing data center overlay technologies like OTV or ACI with campus mobility solutions, when LISP is specifically designed for identity-location separation and mobility.

37
MCQmedium

A network architect is evaluating Cisco StackWise Virtual for a pair of distribution switches. The design requires that the two switches appear as a single logical entity for Layer 2 and Layer 3 forwarding, and that they support Multichassis EtherChannel (MEC) to access switches. Which statement accurately describes a characteristic of Cisco StackWise Virtual?

A.It requires a dedicated stack cable between the switches for control plane communication.
B.It is limited to two switches and cannot be expanded to more than two.
C.It requires that both switches run different IOS versions to ensure compatibility.
D.It supports active/active forwarding, allowing both switches to forward traffic simultaneously.
AnswerD

Cisco StackWise Virtual enables active/active forwarding, meaning both switches in the virtual domain can forward traffic concurrently. This provides load balancing and increased bandwidth utilization. Multichassis EtherChannel (MEC) leverages this capability, allowing access switches to form a port-channel with both distribution switches for redundancy and increased throughput.

Why this answer

Cisco StackWise Virtual allows two physical switches to operate as a single logical switch, supporting active/active forwarding. This means both switches can forward traffic simultaneously, and Multichassis EtherChannel (MEC) can be used to connect access switches to both distribution switches for redundancy and load sharing. This design provides high availability and efficient bandwidth utilization.

Exam trap

The trap here is assuming that StackWise Virtual uses a dedicated stacking cable like traditional StackWise, when it actually uses standard Ethernet ports for the virtual link.

38
MCQmedium

A network architect is designing a Cisco SD-WAN fabric for a company with 50 branch sites. The company requires that each branch have two WAN transports (MPLS and Internet) with per-application traffic steering, and that the fabric use a controller-based architecture for centralized policy. Which Cisco SD-WAN component is responsible for distributing fabric-wide policy and managing control plane connectivity?

A.vManage NMS
B.vSmart controller
C.vEdge router
D.vBond orchestrator
AnswerB

The vSmart controller is the centralized policy and control plane component of Cisco SD-WAN. It distributes OMP routes and policies to vEdge routers, enabling per-application traffic steering across MPLS and Internet transports. It does not forward data traffic; it only manages control plane and policy. This matches the requirement for centralized policy in a controller-based architecture.

Why this answer

In Cisco SD-WAN, the vSmart controller is the brain of the control plane. It distributes OMP routes and policies to all vEdge routers, enabling centralized policy and per-application traffic steering. The vBond orchestrator handles initial authentication, vManage provides management, and vEdge routers forward data.

Only vSmart distributes fabric-wide policy and manages control plane connectivity.

Exam trap

The trap here is confusing the management plane role of vManage with the control plane policy distribution role of vSmart.

39
MCQhard

A network engineer is configuring a Cisco Catalyst 9000 switch for a new access layer. The engineer needs to enable a feature that allows the switch to authenticate endpoints using 802.1X and then assign them to a specific VLAN based on the result. Which Cisco feature should be configured to dynamically assign VLANs?

A.Private VLAN (PVLAN) edge
B.Dynamic ARP Inspection (DAI)
C.802.1X with VLAN assignment via RADIUS
D.VLAN Membership Policy Server (VMPS)
AnswerC

When 802.1X is configured with a RADIUS server, such as Cisco ISE, the server can return attributes that instruct the switch to place the authenticated endpoint into a specific VLAN. This is done using the IETF RADIUS attribute Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID. The switch then dynamically assigns the port to that VLAN. This feature is supported on Catalyst 9000 switches and is the standard method for dynamic VLAN assignment.

Why this answer

The correct feature is 802.1X with VLAN assignment via RADIUS. When an endpoint authenticates via 802.1X, the switch acts as an authenticator and relays credentials to a RADIUS server like Cisco ISE. Upon successful authentication, the RADIUS server can return tunnel attributes that specify the VLAN.

The switch then dynamically assigns the port to that VLAN, allowing for role-based access control and simplified VLAN management.

Exam trap

The trap here is selecting VMPS, which is an older dynamic VLAN assignment method based on MAC addresses, not 802.1X authentication, and is not supported on modern Catalyst switches.

40
MCQmedium

A network architect is designing a fabric that must support Layer 2 and Layer 3 connectivity for endpoints across multiple sites without stretching VLANs between them. The design requires a control plane that separates the endpoint identifier from the routing locator, allowing traffic to be tunneled over a routed underlay. Which Cisco architecture component provides this separation in an SD-Access fabric?

A.MP-BGP EVPN with MPLS L3VPN VRFs
B.Cisco TrustSec with SGT Exchange Protocol
C.OTV with IS-IS adjacency over the WAN
D.LISP control plane with VXLAN data plane
AnswerD

LISP separates endpoint identity (EID) from routing locator (RLOC), which is exactly the identifier/locator split the scenario demands. VXLAN provides the tunneling data plane over the routed underlay, and the fabric border and edge nodes register EIDs to the map server. Together they deliver Layer 2 and Layer 3 overlay connectivity without stretching VLANs across sites.

Why this answer

The Cisco SD-Access fabric uses LISP as its control plane to separate endpoint identity from routing location, and VXLAN as the data plane to tunnel overlay traffic across a routed underlay. This combination lets endpoints remain in their Layer 2 or Layer 3 virtual networks without extending VLANs between sites, which is precisely what the architect requires.

Exam trap

The trap here is assuming that any overlay technology that tunnels Layer 2 traffic, such as OTV or EVPN, satisfies the SD-Access fabric requirement, when the specific identifier/locator separation is provided by LISP.

41
MCQeasy

A network administrator is configuring a Cisco IOS router to participate in a First Hop Redundancy Protocol group. The requirement is that the group must use a virtual MAC address of 0000.0c07.acXX and support only IPv4. Which protocol should the administrator configure?

A.Hot Standby Router Protocol (HSRP) version 1
B.HSRP version 2
C.Virtual Router Redundancy Protocol (VRRP) version 2
D.Gateway Load Balancing Protocol (GLBP)
AnswerA

HSRP version 1 uses the virtual MAC address 0000.0c07.acXX, where XX is the group number in hexadecimal, and it supports only IPv4. Configuring HSRPv1 with the standby command and a group number satisfies both requirements, making it the correct choice for this scenario.

Why this answer

HSRP version 1 is the only protocol listed that uses the virtual MAC address 0000.0c07.acXX and supports IPv4 only. VRRPv2 uses a different MAC prefix, GLBP uses 0007.b400.XXYY, and HSRPv2 uses 0000.0c9f.fXXX. The administrator should configure HSRPv1 to meet the exact virtual MAC and IPv4-only requirements.

Exam trap

The trap here is assuming that any FHRP will work because they all provide gateway redundancy, when the specific virtual MAC address format and IPv4-only limitation uniquely identify HSRP version 1.

42
MCQhard

A network engineer is designing a QoS policy for a Cisco Catalyst switch. The requirement is to ensure that a specific class of traffic receives a guaranteed minimum bandwidth during congestion while still allowing other classes to use excess bandwidth when available. Which queuing mechanism should the engineer configure?

A.First-In, First-Out (FIFO) queuing
B.Class-Based Weighted Fair Queuing (CBWFQ)
C.Weighted Random Early Detection (WRED)
D.Low Latency Queuing (LLQ)
AnswerB

CBWFQ is correct because it provides a guaranteed minimum bandwidth to each class during congestion, based on the configured bandwidth value, while allowing classes to use unused bandwidth from others. This matches the requirement for a guaranteed floor with excess sharing. It is implemented with the bandwidth command inside a policy-map class.

Why this answer

CBWFQ guarantees a minimum bandwidth to each class during congestion and allows classes to share unused bandwidth. LLQ provides strict priority, WRED only manages congestion avoidance, and FIFO offers no guarantees. Therefore CBWFQ is the mechanism that matches the stated requirement for a guaranteed floor with excess sharing.

Exam trap

The trap here is choosing LLQ because it is commonly associated with QoS, but LLQ provides strict priority rather than a guaranteed minimum bandwidth with excess sharing.

43
MCQhard

A network engineer is deploying a Cisco Wireless LAN Controller (WLC) in a centralized deployment mode. The engineer needs to ensure that guest traffic is isolated from internal traffic and that guests can only access the internet. Which feature should be configured on the WLC to meet these requirements?

A.Configure the guest WLAN to use the management interface.
B.Enable DHCP relay on the management interface.
C.Configure a separate WLAN with a guest SSID and map it to a dynamic interface with a dedicated VLAN.
D.Enable Peer-to-Peer Blocking on the guest WLAN.
AnswerC

Creating a separate WLAN for guests and mapping it to a dynamic interface with its own VLAN isolates guest traffic from internal networks. The dynamic interface can be configured with an ACL or firewall rules to restrict guests to internet-only access. This approach ensures that guest traffic is segregated at Layer 2 and can be controlled at Layer 3.

Why this answer

The most effective way to isolate guest traffic is to create a separate WLAN with a guest SSID and assign it to a dynamic interface with a dedicated VLAN. This segregates guest traffic at Layer 2 and allows Layer 3 restrictions via ACLs or firewall rules. Peer-to-Peer Blocking only prevents client-to-client communication, and using the management interface is insecure.

DHCP relay is unrelated to isolation.

Exam trap

The trap here is thinking that Peer-to-Peer Blocking provides complete guest isolation, when it only prevents wireless clients from talking to each other.

44
MCQhard

A large enterprise has a campus network with a collapsed core design. The core switch connects to two distribution switches, each serving several access switches. The network uses OSPF as the IGP. Recently, after a link failure between the core and distribution switch A, the network experienced a 30-second outage before converging. The engineer wants to improve convergence time to under 5 seconds. The budget is limited, so hardware upgrades are not an option. The engineer is considering the following actions: A. Enable OSPF Fast Hello on all interfaces. B. Reduce OSPF dead timer to 1 second and hello timer to 333 milliseconds. C. Implement OSPF LSA throttling with a minimum interval of 0 ms. D. Use OSPF incremental SPF (iSPF). Which action will provide the most significant improvement in convergence time for this scenario?

A.Enable OSPF Fast Hello on all interfaces.
B.Reduce OSPF dead timer to 1 second and hello timer to 333 milliseconds.
C.Implement OSPF LSA throttling with a minimum interval of 0 ms.
D.Use OSPF incremental SPF (iSPF).
AnswerB

The OSPF dead timer is the primary factor in convergence delay because it dictates how long a router waits for a missing hello before marking the neighbor unavailable. Setting the dead timer to 1 second ensures that a link failure is detected within roughly one second, and a hello interval of 333 milliseconds satisfies the standard three-hello requirement while maintaining a stable neighbor state. This direct reduction of the detection timer cuts the outage from tens of seconds to about one second, whereas other mechanisms only optimize post-detection processing.

Why this answer

Reducing the OSPF dead timer to 1 second and hello timer to 333 milliseconds directly addresses the 30-second outage caused by the link failure. The default dead timer (40 seconds on broadcast networks) is the primary contributor to convergence delay, as OSPF must wait for the dead interval to expire before declaring a neighbor down. By lowering these timers, failure detection drops from 40 seconds to approximately 1 second, which is the most impactful single change for convergence under budget constraints.

Exam trap

Cisco often tests the misconception that Fast Hello (Option A) is the best way to speed convergence, but the trap is that Fast Hello alone does not reduce the dead timer below 1 second unless explicitly configured with a multiplier, and the dead timer is the dominant factor in failure detection time.

How to eliminate wrong answers

Option A is wrong because OSPF Fast Hello (using the 'ip ospf dead-interval minimal hello-multiplier' command) sends hellos at sub-second intervals but still relies on the dead timer for failure detection; it does not inherently reduce the dead timer below 1 second, so it may not achieve the sub-5-second convergence goal without also adjusting the dead interval. Option C is wrong because OSPF LSA throttling (with 'timers throttle lsa all') controls the rate at which LSAs are generated and retransmitted, not failure detection; it helps with network stability during flapping but does not reduce the time to detect a link failure. Option D is wrong because incremental SPF (iSPF) optimizes SPF computation by only recalculating affected routes, but it does not address the primary bottleneck of neighbor failure detection; the 30-second outage is dominated by the dead timer, not SPF calculation time.

45
MCQeasy

A network administrator is configuring a Cisco Catalyst 9000 switch to participate in a StackWise Virtual configuration. The administrator wants to ensure that the switch is ready to be added to an existing StackWise Virtual domain. Which command must be issued on the new switch before it can join the domain?

A.switch convert mode virtual
B.switch virtual domain 1
C.stackwise-virtual domain 1
D.stackwise-virtual enable
AnswerA

The command 'switch convert mode virtual' converts a standalone switch to StackWise Virtual mode. This is required before the switch can join an existing StackWise Virtual domain. It changes the switch's operation to support the virtual domain and prepares it for the stacking connection. Without this conversion, the switch remains in standalone mode and cannot participate in the virtual domain.

Why this answer

To join a StackWise Virtual domain, a standalone switch must first be converted using 'switch convert mode virtual'. This command changes the switch's mode of operation and allows it to form a virtual domain with another switch. After conversion, the domain ID and other parameters can be configured.

Exam trap

The trap here is confusing StackWise Virtual commands with traditional StackWise commands, such as 'switch virtual domain'.

46
Multi-Selecteasy

Which TWO are benefits of using a spine-leaf architecture in a data center? (Choose two.)

Select 2 answers
A.Predictable latency between any two devices
B.Increased number of single points of failure
C.Increased broadcast domain size
D.Reduced need for VLANs
E.Higher bandwidth utilization through multiple equal-cost paths
AnswersA, E

Traffic always traverses one spine hop, resulting in consistent latency.

Why this answer

A is correct because spine-leaf architecture ensures that every leaf switch is connected to every spine switch, creating a full-mesh topology. This design guarantees that traffic between any two leaf switches traverses at most one spine hop, resulting in predictable, consistent latency regardless of which devices are communicating.

Exam trap

Cisco often tests the misconception that spine-leaf eliminates VLANs or reduces broadcast domains, but the architecture actually uses Layer 3 routing to contain broadcast domains while still requiring VLANs for Layer 2 segmentation at the leaf level.

47
Drag & Dropmedium

Drag and drop the steps to configure a static route on a Cisco IOS router into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Static routes require global config mode and must specify the destination network, subnet mask, and next-hop address or exit interface.

48
MCQmedium

A network engineer is designing a high-availability campus network using Cisco StackWise Virtual. The engineer wants to ensure that if the virtual link fails, the switches do not both become active and cause a split-brain scenario. Which mechanism should be implemented to detect and prevent a dual-active situation?

A.Enable PAgP on the virtual link to detect dual-active condition.
B.Enable BFD on the virtual link to rapidly detect failures.
C.Configure VRRP on the switches to monitor the virtual link.
D.Configure a separate physical link as a dual-active detection link and enable dual-active detection.
AnswerD

In StackWise Virtual, a dual-active detection link is a separate physical connection between the two switches that is used to detect a virtual link failure. When the virtual link fails, the switches use this link to determine which switch should remain active. Configuring this link and enabling dual-active detection prevents both switches from becoming active and causing a split-brain.

Why this answer

StackWise Virtual uses a dual-active detection link to prevent a split-brain scenario. This is a separate physical link between the two switches that is used to detect a virtual link failure. When the virtual link fails, the switches communicate over the dual-active detection link to determine which switch should remain active.

Configuring this link and enabling dual-active detection is the correct approach.

Exam trap

The trap here is confusing dual-active detection with other protocols like PAgP, VRRP, or BFD, which serve different purposes and do not prevent a split-brain in StackWise Virtual.

49
MCQmedium

A network administrator is deploying a new Cisco Catalyst switch and wants to enable a feature that provides per-port MAC address limiting to prevent MAC flooding attacks. The administrator also wants to ensure that when the limit is exceeded, the port is err-disabled. Which command set accomplishes this?

A.switchport port-security maximum 5, switchport port-security violation shutdown
B.switchport port-security, switchport port-security maximum 5, switchport port-security violation restrict
C.switchport port-security, switchport port-security maximum 5, switchport port-security violation shutdown
D.switchport port-security, switchport port-security maximum 5, switchport port-security violation protect
AnswerC

Enabling port security with switchport port-security, setting the maximum number of MAC addresses, and configuring the violation action to shutdown causes the port to err-disable when the limit is exceeded. This directly meets the requirement to limit MAC addresses per port and shut down on violation. The commands are applied in interface configuration mode.

Why this answer

To limit MAC addresses per port and err-disable the port on violation, the administrator must enable port security, set the maximum, and configure the shutdown violation mode. The shutdown mode places the port into an err-disabled state when the limit is exceeded, which is exactly what the scenario requires.

Exam trap

The trap here is selecting restrict or protect violation modes, which do not err-disable the port, instead of shutdown, which does.

50
Multi-Selectmedium

Which THREE of the following are valid considerations when planning a wireless network for high-density environments?

Select 3 answers
A.Use a channel reuse plan that minimizes co-channel interference.
B.Prefer the 5 GHz band over 2.4 GHz for client connectivity.
C.Lower AP transmit power to reduce cell size and increase capacity.
D.Increase AP transmit power to maximize coverage.
E.Enable 2.4 GHz band only to maximize range.
AnswersA, B, C

In a high-density wireless design, co-channel interference is the primary limiting factor because all APs on the same channel share the medium. A channel reuse plan ensures that APs operating on the same non-overlapping channel are separated by enough physical distance, often using different channels for adjacent cells. This spatial reuse maximizes aggregate throughput by allowing more simultaneous transmissions.

Why this answer

A channel reuse plan that minimizes co-channel interference is essential in high-density environments to ensure that adjacent access points (APs) do not use the same or overlapping channels, which would degrade throughput. By carefully planning channel assignments (e.g., using non-overlapping channels in the 5 GHz band), you maximize spatial reuse and overall network capacity.

Exam trap

Cisco often tests the misconception that increasing AP transmit power always improves coverage and performance, when in fact, in high-density environments, lowering power and reducing cell size is the correct strategy to increase capacity and minimize interference.

51
MCQeasy

A network administrator is configuring a Cisco Catalyst switch and needs to assign a port to VLAN 20 as an access port. Which command sequence is correct?

A.interface GigabitEthernet0/1, then switchport mode access, then switchport access vlan 20
B.interface GigabitEthernet0/1, then switchport mode trunk, then switchport trunk vlan 20
C.interface GigabitEthernet0/1, then switchport access vlan 20, then switchport mode access
D.vlan 20, then interface GigabitEthernet0/1, then switchport access vlan 20
AnswerA

This sequence enters interface configuration mode, sets the port to access mode, and assigns it to VLAN 20. The switchport mode access command ensures the port operates as an access port, and switchport access vlan 20 places it in the correct VLAN. This is the standard method to configure an access port on a Cisco Catalyst switch.

Why this answer

To assign a switch port to a specific VLAN as an access port, you must enter interface configuration mode, set the port to access mode with switchport mode access, and then assign the VLAN with switchport access vlan 20. This ensures the port operates correctly as an access port in the desired VLAN.

Exam trap

The trap here is forgetting to set the port to access mode first, which can cause the port to remain in dynamic mode and potentially negotiate a trunk.

52
MCQeasy

A network administrator is configuring a Cisco Catalyst switch to support a new VLAN 200 for a guest network. The administrator wants to ensure that VLAN 200 is created and active on the switch. Which command should be used?

A.interface vlan 200
B.vlan database
C.vlan 200
D.switchport access vlan 200
AnswerC

The 'vlan 200' command in global configuration mode creates VLAN 200 and enters VLAN configuration mode. This is the correct way to create a VLAN on a Cisco Catalyst switch. After entering this command, the VLAN is active by default unless it is shutdown. This command is essential for adding a new VLAN to the switch's VLAN database.

Why this answer

To create a VLAN on a Cisco Catalyst switch, the 'vlan 200' command is used in global configuration mode. This command creates the VLAN and enters VLAN configuration mode, where additional parameters like name can be set. The VLAN is active by default.

Other commands like 'switchport access vlan' assign ports to the VLAN but do not create it, and 'interface vlan' creates an SVI, not the VLAN itself.

Exam trap

The trap here is confusing VLAN creation with port assignment or SVI creation, assuming that assigning a port to a VLAN automatically creates it.

53
MCQmedium

A network architect is designing a new branch office that requires a lightweight, scalable solution for device onboarding and policy enforcement. The branch has minimal on-site IT staff and must integrate with the existing Cisco DNA Center deployment at headquarters. Which Cisco SD-Access fabric role is responsible for providing the layer 3 gateway and policy enforcement for wired and wireless endpoints in this branch?

A.Fabric border node
B.Fabric control plane node
C.Fabric intermediate node
D.Fabric edge node
AnswerD

The fabric edge node provides the layer 3 gateway and policy enforcement for endpoints in the SD-Access fabric. It encapsulates traffic using VXLAN and registers endpoints with the control plane node. In a branch with minimal IT staff, the edge node enables automated onboarding and consistent policy from Cisco DNA Center, exactly as required.

Why this answer

The fabric edge node is the device that connects endpoints to the SD-Access fabric and serves as their default gateway. It enforces group-based policies and encapsulates traffic in VXLAN toward other fabric nodes. In a branch with limited IT staff, it enables zero-touch onboarding and centralized policy from Cisco DNA Center, satisfying both scalability and integration needs.

Exam trap

The trap here is assuming that any fabric node can enforce policy and act as a gateway, when in fact only the edge node performs those functions for endpoints.

54
MCQeasy

A network administrator is deploying a new Cisco SD-WAN solution. The administrator needs to ensure that the control plane is separated from the data plane and that the solution can dynamically select the best path for application traffic based on policies. Which component of Cisco SD-WAN is responsible for centralized control plane functions and distributing routing information to the WAN Edge devices?

A.WAN Edge
B.vManage
C.vBond
D.vSmart
AnswerD

vSmart is the centralized control plane component of Cisco SD-WAN. It distributes routing information, policies, and keys to the WAN Edge devices. It uses Overlay Management Protocol (OMP) to exchange routes and policies, enabling dynamic path selection based on application policies. This matches the requirement for centralized control plane functions.

Why this answer

vSmart is the centralized control plane in Cisco SD-WAN, using OMP to distribute routing and policies to WAN Edge devices. It enables dynamic path selection and separates control from data plane. vManage is management, vBond is orchestration, and WAN Edge is data plane.

Exam trap

The trap here is confusing the management plane (vManage) with the control plane (vSmart), or assuming vBond handles routing.

55
MCQhard

A network architect is designing a data center network using Cisco ACI. The architect must ensure that traffic between endpoints in different EPGs is allowed only when a contract exists. Which Cisco ACI component is responsible for enforcing these contracts?

A.Policy Enforcement Point (PEP)
B.Application Policy Infrastructure Controller (APIC)
C.Spine switch
D.Endpoint Group (EPG)
AnswerA

In Cisco ACI, the Policy Enforcement Point (PEP) is responsible for enforcing contracts between EPGs. The PEP is typically implemented in the leaf switches, where it applies filters and actions defined in the contract. This ensures that traffic is permitted or denied based on the contract, meeting the security requirement.

Why this answer

In Cisco ACI, contracts define allowed communication between EPGs. The Policy Enforcement Point (PEP), implemented on leaf switches, enforces these contracts by applying the specified filters and actions. The APIC defines the policy, but enforcement occurs at the leaf.

Spines and EPGs do not enforce contracts, making the PEP the correct component.

Exam trap

The trap here is assuming the APIC enforces contracts because it manages policy, but actual enforcement is distributed to the leaf switches as PEPs.

56
MCQhard

A network engineer is designing a large-scale campus network using Cisco SD-Access. The fabric must support thousands of endpoints and provide optimal forwarding paths. Which control plane component is responsible for maintaining the mapping of endpoint IP addresses to fabric edge nodes?

A.Fabric intermediate node
B.Cisco DNA Center
C.Fabric control plane node
D.Fabric edge node
AnswerC

The fabric control plane node, which runs LISP map-server and map-resolver functions, maintains the database of endpoint IP addresses and their associated fabric edge nodes. It provides the mapping service that allows fabric edge nodes to locate endpoints and establish optimal forwarding paths, making it essential for large-scale SD-Access deployments.

Why this answer

In Cisco SD-Access, the fabric control plane node uses LISP to maintain a mapping database of endpoint IP addresses to their current fabric edge nodes. This enables fabric edge nodes to query the control plane and forward traffic directly to the correct edge node, ensuring optimal paths and scalability for thousands of endpoints.

Exam trap

The trap here is attributing the endpoint mapping function to the management platform or edge nodes, when in fact it is the dedicated control plane node that holds the mapping database.

57
MCQeasy

A network administrator is planning a new Cisco Catalyst switch stack and wants to verify that the stacking cables provide redundancy so that the loss of a single stacking link does not split the stack. The switches support StackWise-480. Which cabling practice should the administrator follow to achieve a resilient stack ring?

A.Connect only the first and last switches in the stack and leave the middle switches unconnected.
B.Connect the switches in a full mesh using a separate cable between every pair of switches.
C.Connect each switch to the next and the last switch back to the first to form a ring.
D.Connect the switches in a single daisy chain using one cable between each pair of switches.
AnswerC

StackWise-480 uses a ring topology in which each switch connects to the next and the final switch connects back to the first. This loop allows traffic to flow in either direction, so a single cable or switch failure does not split the stack. That matches the requirement for a resilient stack ring.

Why this answer

A StackWise-480 stack should be cabled as a ring, with each switch connected to the next and the last switch connected back to the first. This loop gives the stack two paths for stacking traffic, so a single link failure does not split the stack, which is exactly what the administrator needs.

Exam trap

The trap here is thinking that any cabling that connects all switches is sufficient, when StackWise-480 specifically needs a closed ring to survive a single link failure.

58
Multi-Selectmedium

A network architect is designing a Cisco SD-Access fabric and must ensure that the control plane and data plane are properly separated. Which two statements accurately describe the roles of fabric nodes in Cisco SD-Access? (Choose two.)

Select 2 answers
A.Fabric edge nodes encapsulate traffic in VXLAN and provide anycast gateway functionality for endpoints.
B.Fabric control plane nodes run LISP map-server and map-resolver to track endpoint locations.
C.Fabric intermediate nodes perform LISP map-cache resolution for endpoints on behalf of edge nodes.
D.Fabric border nodes are responsible for VXLAN encapsulation of traffic between edge nodes within the same fabric site.
E.Fabric edge nodes maintain the LISP map-server database for all endpoints in the fabric site.
AnswersA, B

Fabric edge nodes are responsible for VXLAN encapsulation and decapsulation at the fabric boundary. They provide the anycast gateway, which serves as the default gateway for endpoints, allowing seamless mobility. This statement correctly describes a key role of edge nodes in SD-Access, making it one of the accurate statements.

Why this answer

In Cisco SD-Access, fabric edge nodes provide VXLAN encapsulation and anycast gateway for endpoints, while control plane nodes run LISP map-server and map-resolver to track endpoint locations. Border nodes connect to external networks, and intermediate nodes provide underlay transport. Edge nodes do not maintain the LISP map-server database; that is the control plane node's function.

Exam trap

The trap here is mixing up the roles of edge, control plane, and border nodes, especially assuming edge nodes perform control plane functions like LISP map-server.

59
MCQhard

A network designer is planning a Cisco SD-WAN solution. The customer requires that control plane and data plane traffic be separated, and that the control plane uses a protocol that provides secure, scalable, and resilient overlay topology. Which component of Cisco SD-WAN architecture should the designer use for the control plane?

A.vBond
B.vManage
C.vEdge
D.vSmart
AnswerD

vSmart controllers form the control plane of Cisco SD-WAN. They run the Overlay Management Protocol (OMP) to distribute routing, policy, and key information to vEdge routers, establishing a secure and scalable overlay. They maintain the control plane relationships and enforce centralized policies, separating control from data plane.

Why this answer

vSmart controllers provide the control plane in Cisco SD-WAN, using OMP to distribute routing and policy information to vEdge routers. They establish secure control connections and maintain the overlay topology, separate from the data plane. vManage handles management, vBond handles orchestration, and vEdge routers forward data.

Exam trap

The trap here is assuming vBond is the control plane because it handles initial authentication, but vBond is only the orchestrator, while vSmart provides the actual control plane.

60
Multi-Selecthard

A network architect is evaluating Cisco SD-Access for a large campus. The architect must ensure the fabric supports policy enforcement based on user identity and group membership, and that the fabric can scale to thousands of endpoints without flooding the underlay. Which two statements are correct about how SD-Access achieves these goals? (Choose two.)

Select 2 answers
A.The fabric uses a single shared bridge domain across all edge nodes to avoid VLAN proliferation.
B.The underlay uses VXLAN flooding to propagate endpoint reachability to all fabric edge nodes.
C.The LISP control plane in SD-Access registers endpoint EID-to-RLOC mappings so fabric edge nodes can resolve destinations without flooding the underlay.
D.Cisco TrustSec security group tags are carried in the VXLAN Group Policy Option header so fabric edge nodes can enforce group-based ACLs.
E.Fabric edge nodes use OSPF to advertise endpoint host routes into the underlay for reachability.
AnswersC, D

In SD-Access, the LISP map server and map resolver track endpoint identifier to routing locator mappings. Fabric edge nodes register local endpoints and query the map server for remote ones, which provides a control-plane lookup instead of data-plane flooding. This is how the fabric scales to thousands of endpoints while avoiding broadcast or unknown unicast flooding across the underlay.

Why this answer

SD-Access scales by moving endpoint reachability into the LISP control plane, where EID-to-RLOC mappings are registered and resolved, avoiding underlay flooding. Policy is enforced with Cisco TrustSec group tags carried in the VXLAN Group Policy Option header, enabling group-based ACLs at fabric edge nodes. The underlay is a routed IS-IS fabric that does not carry endpoint host routes or rely on VXLAN flooding, and the overlay does not require a single stretched bridge domain.

Exam trap

The trap here is assuming the SD-Access underlay floods endpoint information or carries host routes, when endpoint reachability is actually resolved by LISP in the overlay.

61
MCQmedium

A network architect is designing a WAN with Cisco SD-WAN. The requirement is to ensure that traffic from a branch office to a critical SaaS application is prioritized and uses the best path based on real-time performance metrics. Which Cisco SD-WAN feature should be used to meet this requirement?

A.Cisco Umbrella
B.Quality of Service (QoS)
C.Direct Internet Access (DIA)
D.Application-Aware Routing
AnswerD

Application-Aware Routing (AAR) in Cisco SD-WAN uses real-time performance metrics such as latency, jitter, and packet loss to select the best path for specific applications. It can direct traffic based on SLA policies, ensuring critical SaaS applications get prioritized treatment. This feature meets the requirement by dynamically choosing the optimal path and enforcing QoS. Therefore, it is the correct answer.

Why this answer

Application-Aware Routing is the correct feature because it uses real-time performance metrics to select the best path for applications, ensuring critical SaaS traffic is prioritized and uses the optimal path. It integrates with QoS to enforce prioritization, meeting the requirement. Other features like DIA and QoS address different aspects but do not provide dynamic path selection based on performance.

Exam trap

The trap here is confusing QoS, which prioritizes traffic within a path, with Application-Aware Routing, which selects the path based on performance metrics.

62
MCQhard

A network architect is designing a Cisco SD-WAN solution with multiple data centers and a mix of MPLS and Internet transports. The company requires that business-critical traffic (e.g., ERP) always use the MPLS transport, while guest traffic uses the Internet. Which Cisco SD-WAN feature should be used to enforce this policy?

A.Centralized data policy
B.Direct Internet Access (DIA)
C.Application-aware routing
D.VPN segmentation
AnswerA

Centralized data policy in Cisco SD-WAN allows you to define traffic steering based on application, source/destination, and transport. You can create a policy that matches ERP traffic and directs it exclusively to the MPLS transport, while matching guest traffic and directing it to the Internet. This enforces the required path selection.

Why this answer

Centralized data policy in Cisco SD-WAN is used to define traffic steering rules. By creating a policy that matches ERP traffic and sets the preferred transport to MPLS, and another that matches guest traffic and sets the transport to Internet, the architect can enforce the requirement. Other features like AAR or VPN segmentation do not provide this static transport enforcement.

Exam trap

The trap here is confusing application-aware routing, which dynamically chooses paths based on SLA, with centralized data policy, which can enforce a static transport preference for specific applications.

63
MCQmedium

A network engineer is troubleshooting a routing loop in an EIGRP network. Which mechanism is designed to prevent routing loops by causing a router to reject routes that are learned from a neighbor that is not the successor?

A.Split horizon
B.Route poisoning
C.Hold-down timers
D.Feasibility condition
AnswerD

The feasibility condition is EIGRP's loop-free guarantee: a neighbor advertises a reported distance (RD) that is strictly lower than the current feasible distance (FD) to a destination. This proves the neighbor's path does not pass back through the local router, so the path can safely be used as a feasible successor. If no such neighbor exists, DUAL goes active and queries neighbors, but the feasibility condition remains the core mechanism ensuring that any selected path is genuinely loop-free.

Why this answer

The feasibility condition is a loop-prevention mechanism unique to EIGRP. It ensures that a router only accepts a route from a neighbor if that neighbor's reported distance (RD) to the destination is less than the router's own feasible distance (FD). This guarantees that the path through that neighbor is loop-free, effectively rejecting routes learned from any neighbor that is not the successor.

Exam trap

Cisco often tests the distinction between EIGRP's feasibility condition and other distance-vector loop-prevention mechanisms like split horizon or hold-down timers, expecting candidates to confuse these concepts because they all prevent loops but operate at different stages of the routing process.

How to eliminate wrong answers

Option A is wrong because split horizon prevents loops by not advertising a route back out the interface from which it was learned, but it does not evaluate whether the neighbor is the successor. Option B is wrong because route poisoning (setting the metric to infinity) is used to signal a failed route, not to reject routes from non-successor neighbors. Option C is wrong because hold-down timers are used in distance-vector protocols like RIP to suppress updates after a metric change, but EIGRP does not use hold-down timers; it relies on the Diffusing Update Algorithm (DUAL) and the feasibility condition for loop prevention.

64
MCQhard

A network engineer is designing a QoS policy for a Cisco Catalyst switch that will carry voice, video, and data traffic. The engineer wants to ensure that voice traffic receives strict priority queuing, video traffic gets guaranteed bandwidth, and data traffic uses leftover bandwidth. The switch supports Cisco Modular QoS CLI (MQC). Which queuing mechanism should be configured on the egress interface to meet these requirements?

A.First-In, First-Out (FIFO) queuing
B.Class-Based Weighted Fair Queuing (CBWFQ)
C.Low Latency Queuing (LLQ)
D.Weighted Random Early Detection (WRED)
AnswerC

LLQ provides strict priority queuing for voice traffic while allowing other classes to have guaranteed bandwidth. It is configured using the priority command within a policy map applied to the interface. This meets the requirement for voice to have strict priority, video to have guaranteed bandwidth (using bandwidth command), and data to use leftover bandwidth. Therefore, LLQ is the correct queuing mechanism for this scenario.

Why this answer

LLQ is the correct queuing mechanism because it combines strict priority queuing for voice with guaranteed bandwidth for other classes like video. It is configured using MQC with a priority command for voice and bandwidth commands for other classes. CBWFQ lacks strict priority, WRED is a congestion avoidance tool, and FIFO provides no differentiation.

Thus, LLQ meets all the stated requirements.

Exam trap

The trap here is confusing CBWFQ with LLQ, or thinking that WRED provides queuing. LLQ is specifically designed for low-latency traffic like voice.

65
MCQeasy

A network engineer is deploying Cisco SD-Access and needs to ensure that endpoint IP addresses are mapped to fabric locators so that the fabric can forward traffic between wired and wireless clients. Which control-plane node role is responsible for maintaining this mapping database?

A.Fabric border node
B.Fabric control-plane node
C.Fabric intermediate node
D.Fabric edge node
AnswerB

The control-plane node runs LISP and hosts the map-server and map-resolver functions that store endpoint identifier-to-routing locator mappings. Edge nodes register endpoints with it and query it to resolve destinations. This directly fulfills the requirement of maintaining the mapping database that enables fabric forwarding, making it the correct role.

Why this answer

In Cisco SD-Access, the control-plane node runs LISP map-server and map-resolver functions. Edge nodes register endpoint EID-to-RLOC mappings with it, and other edges query it to resolve destinations before encapsulating VXLAN traffic. Border and intermediate nodes handle external connectivity and underlay transport respectively, so they do not own the mapping database required by the scenario.

Exam trap

The trap here is confusing the data-plane edge role, which encapsulates traffic, with the control-plane role that actually stores and resolves endpoint locator mappings.

66
MCQmedium

A network architect is selecting a switching platform for a data center access layer that must support lossless Ethernet for FCoE. The platform must provide per-priority flow control so that storage traffic can be paused without affecting LAN traffic. Which technology should the architect specify?

A.EtherChannel with LACP
B.Jumbo frame support
C.Priority Flow Control (PFC)
D.Link Layer Discovery Protocol (LLDP)
AnswerC

PFC is the correct choice because it operates on IEEE 802.1Q CoS priorities and allows a receiver to send a PAUSE frame for a specific priority, pausing only the storage class of traffic while LAN traffic on other priorities continues unimpeded. This satisfies the requirement for lossless FCoE without head-of-line blocking across the entire link.

Why this answer

Lossless Ethernet for FCoE requires a mechanism that can pause a specific traffic class without stopping all traffic on the link. Priority Flow Control does exactly that by acting on CoS values, allowing storage frames to be paused while ordinary LAN traffic continues. LLDP, EtherChannel, and jumbo frames each address different concerns and none provides per-priority pause.

Exam trap

The trap here is assuming that enabling jumbo frames or EtherChannel is sufficient for lossless FCoE, when only a per-priority pause mechanism prevents drops for the storage class.

67
MCQhard

A network architect is designing a campus network that must support thousands of endpoints with a fabric overlay. The design requires that the underlay provide fast convergence and equal-cost multipathing without running a separate routing protocol in the overlay. Which underlay routing protocol should be selected to meet these requirements?

A.Intermediate System-to-Intermediate System (IS-IS)
B.Enhanced Interior Gateway Routing Protocol (EIGRP)
C.Border Gateway Protocol (BGP)
D.Open Shortest Path First (OSPF) with multiple areas
AnswerA

IS-IS is the recommended underlay routing protocol for Cisco SD-Access fabrics. It provides fast convergence, supports ECMP, and scales well in large campus deployments. It operates independently of the LISP/VXLAN overlay, allowing the underlay to focus on IP reachability. This directly meets the requirements for fast convergence and multipathing without overlay routing, making it the correct selection.

Why this answer

Cisco SD-Access recommends IS-IS as the underlay routing protocol because it provides fast convergence, scalable ECMP, and clean separation from the LISP/VXLAN overlay. OSPF, EIGRP, and BGP can provide routing but are not the standard underlay choice for large fabric deployments and may add complexity or converge more slowly in this context.

Exam trap

The trap here is assuming any protocol with ECMP support is equally suitable as a fabric underlay, when IS-IS is specifically recommended for SD-Access due to its convergence and integration characteristics.

68
MCQmedium

A network administrator is deploying QoS in a converged network. Which approach correctly implements trust boundaries and marking?

A.Set trust boundary at the access layer switch and re-mark packets based on source.
B.Configure marking only at the core layer to simplify policy.
C.Trust only the distribution layer switches to mark traffic.
D.Trust the DSCP values set by IP phones and workstations.
AnswerA

The access layer is the optimal trust boundary because it is the first device in the path that can inspect source identities (e.g., IP phone vs. workstation) with port-level granularity. Re-marking DSCP here ensures that packets enter the network with a consistent QoS class, allowing all downstream switches to rely on these markings for queuing and policing. This prevents untrusted end devices from dictating their own priority, which is essential for converged networks carrying voice, video, and data.

Why this answer

In a converged network, trust boundaries should be established at the access layer to ensure that marking decisions are made as close to the source as possible. By setting the trust boundary at the access layer switch and re-marking packets based on source (e.g., trusting only IP phones while re-marking workstation traffic), the network can enforce policy before traffic enters the core, preventing unauthorized or misconfigured endpoints from influencing QoS markings. This aligns with Cisco's best practice of trusting only known devices and re-marking all other traffic to a default or lower priority.

Exam trap

Cisco often tests the misconception that trust boundaries should be placed at the distribution or core layer for simplicity, but the trap is that marking must happen at the access layer to prevent untrusted endpoints from injecting high-priority traffic into the network.

How to eliminate wrong answers

Option B is wrong because configuring marking only at the core layer violates the principle of trust boundaries; marking should occur at the access layer to prevent congestion and ensure policy is applied early, and relying solely on core marking can lead to oversubscription and loss of differentiation. Option C is wrong because trusting only the distribution layer to mark traffic introduces unnecessary latency and complexity, and it fails to protect the network from untrusted endpoints at the access edge, which is the correct location for trust boundaries. Option D is wrong because while IP phones can be trusted to set correct DSCP values (e.g., EF for voice), workstations should never be trusted to mark their own traffic, as they may be compromised or misconfigured; the trust boundary must differentiate between trusted and untrusted sources.

69
MCQmedium

A network engineer is configuring a Cisco Wireless LAN Controller (WLC) for a high-density auditorium. The engineer wants to ensure that clients can roam seamlessly between access points while maintaining consistent security policies. Which Cisco wireless architecture feature should be enabled to allow controllers to share client context and facilitate inter-controller roaming?

A.FlexConnect
B.OfficeExtend
C.Mobility Group
D.Mobility Express
AnswerC

A Mobility Group allows multiple Cisco WLCs to share client context and coordinate roaming. When a client roams between access points on different controllers, the controllers exchange information via the mobility group, enabling seamless roaming with consistent security. This is essential for high-density environments with multiple controllers.

Why this answer

A Mobility Group is a set of Cisco WLCs configured to share client context and support seamless roaming. When a client roams between controllers, the controllers exchange information via the mobility group, ensuring that security policies and client state are maintained. This is critical in high-density environments with multiple controllers.

Mobility Express, FlexConnect, and OfficeExtend serve different purposes.

Exam trap

The trap here is confusing FlexConnect, which is for branch survivability, with Mobility Group, which enables inter-controller roaming.

70
MCQmedium

A network administrator is configuring a Cisco wireless controller to support a high-density auditorium. The design requires that client devices be evenly distributed across available access points and that roaming be optimized for voice traffic. Which feature should be enabled to achieve these goals?

A.Cisco Aironet Extensions
B.Cisco Client Load Balancing
C.Cisco Band Select
D.Cisco CleanAir
AnswerB

Cisco Client Load Balancing distributes client devices across access points by delaying association responses when an AP is heavily loaded. This helps achieve even distribution in high-density environments. Combined with other features like 802.11k/v, it can optimize roaming, but load balancing itself is the primary feature for even client distribution, making it correct here.

Why this answer

Cisco Client Load Balancing is designed to distribute clients evenly across access points by managing association requests. In a high-density auditorium, this prevents any single AP from becoming overloaded, improving overall performance. For voice roaming, additional features like 802.11k/v/r are recommended, but the primary feature for even distribution is load balancing, which directly addresses the stated requirement.

Exam trap

The trap here is confusing load balancing with band steering or spectrum analysis, which do not address even client distribution across APs.

71
MCQhard

A network engineer is implementing Cisco SD-Access and needs to ensure that the fabric provides policy-based segmentation and mobility for endpoints. Which component is responsible for maintaining the endpoint location and identity information?

A.Cisco Identity Services Engine (ISE)
B.LISP Map-Server
C.Cisco DNA Center
D.VXLAN Tunnel Endpoint (VTEP)
AnswerB

The LISP Map-Server maintains the mapping of endpoint identities (EIDs) to routing locators (RLOCs), effectively tracking endpoint location and identity. It registers EID-to-RLOC mappings from fabric edge nodes and responds to map requests. This enables policy-based segmentation and mobility by allowing endpoints to be reached regardless of their location. Thus, it is the correct component.

Why this answer

The LISP Map-Server is responsible for maintaining endpoint location and identity information in Cisco SD-Access. It registers EID-to-RLOC mappings from fabric edge nodes and provides them to other nodes upon request. This enables seamless mobility and policy-based segmentation, as endpoints can be reached regardless of their physical location.

Other components like DNA Center and ISE play different roles in management and policy.

Exam trap

The trap here is confusing the management plane (DNA Center) or policy plane (ISE) with the control plane (LISP Map-Server) that actually tracks endpoint location and identity.

72
MCQhard

A network architect is designing a QoS policy for a Cisco Catalyst switch. The architect needs to ensure that voice traffic is marked with the appropriate DSCP value for expedited forwarding. Which DSCP value should be used for voice traffic?

A.CS7 (56)
B.CS6 (48)
C.AF31 (26)
D.EF (46)
AnswerD

EF (Expedited Forwarding) with DSCP value 46 is the standard marking for voice traffic. It provides low latency, low jitter, and low loss, which are critical for voice quality. Voice traffic should be marked with EF to ensure it receives priority treatment in the network. This is a widely accepted best practice.

Why this answer

Voice traffic should be marked with DSCP EF (46) to ensure expedited forwarding, which provides low latency, jitter, and loss. Other DSCP values like AF31 are used for call signaling, while CS6 and CS7 are reserved for network control. Proper marking ensures that voice packets receive priority treatment in QoS-enabled networks.

Exam trap

The trap here is confusing voice payload marking with call signaling marking, or using control traffic DSCP values for voice.

73
Multi-Selecthard

A network engineer is deploying Cisco SD-WAN in a hybrid cloud environment. The company requires secure segmentation between guest, employee, and IoT traffic across all branches. The engineer must ensure that traffic from each segment is isolated and that policies can be applied per segment. Which two components are used to achieve this segmentation? (Choose two.)

Select 2 answers
A.VPN segments in vManage
B.Application-aware routing policies
C.VRF instances on WAN Edge devices
D.IPsec tunnels between branches
E.VLANs on the WAN Edge routers
AnswersA, C

VPN segments in vManage allow the creation of separate virtual private networks (VPNs) within the SD-WAN overlay. Each segment has its own routing table and can be assigned to different VRFs on the WAN Edge devices. This provides isolation between guest, employee, and IoT traffic. Policies can be applied per VPN segment, enabling granular control. This is a core mechanism for segmentation in Cisco SD-WAN.

Why this answer

In Cisco SD-WAN, segmentation is achieved by creating VPN segments in vManage and mapping them to VRF instances on the WAN Edge devices. The VPN segments define the logical separation, and the VRFs enforce it by maintaining separate routing and forwarding tables. Together, they provide end-to-end isolation and allow policies to be applied per segment.

Other options like VLANs or IPsec tunnels do not provide fabric-wide segmentation, and application-aware routing policies are for path selection, not isolation.

Exam trap

The trap here is confusing segmentation mechanisms with transport security or local VLANs, which do not provide end-to-end isolation across the SD-WAN fabric.

74
MCQhard

A network engineer is designing a high-availability solution for a data center using Cisco Application Centric Infrastructure (ACI). The engineer wants to ensure that the fabric can continue to operate if a spine switch fails, and that traffic is load-balanced across all available paths. Which statement accurately describes the ACI fabric architecture?

A.ACI uses a spine-leaf topology where every leaf connects to every spine, and a failed spine switch reduces capacity but does not cause an outage.
B.ACI uses a single spine switch for all traffic, and redundancy is achieved through a standby spine that takes over on failure.
C.ACI uses a traditional Spanning Tree Protocol (STP) to prevent loops, and a failed spine switch causes a full fabric outage.
D.ACI uses a ring topology for the fabric, and a failed spine switch breaks the ring, causing a partial outage.
AnswerA

In ACI, leaf switches connect to all spine switches, forming a full-mesh at the spine level. If a spine fails, the remaining spines continue to forward traffic, so the fabric remains operational. This provides high availability and load balancing across all available paths, meeting the design requirements.

Why this answer

ACI uses a spine-leaf topology where all leaf switches connect to all spine switches, providing active-active forwarding. A failed spine reduces overall capacity but does not cause an outage because other spines continue to forward traffic. This design ensures high availability and load balancing.

Exam trap

The trap here is assuming ACI relies on STP or a standby spine, when it actually uses a full-mesh active-active spine-leaf architecture.

75
MCQhard

A global enterprise is transitioning from a traditional three-tier campus architecture to a software-defined access (SD-Access) fabric. Which architectural consideration is most critical for the underlay network?

A.Configure a routed access layer with a link-state routing protocol (IS-IS or OSPF).
B.Implement PIM-SM for multicast routing in the underlay.
C.Preserve existing VLANs across the fabric to minimize changes.
D.Deploy VRF-lite on all edge nodes to isolate tenants.
AnswerA

A routed access layer with IS-IS or OSPF is the required foundation for an SD-Access underlay. Link-state protocols offer rapid convergence, loop-free topology, and hierarchical scalability, which are essential when building a large leaf-and-spine fabric. The underlay is a pure L3 network, and all devices carry only unique loopback/p2p addresses, allowing the overlay (LISP/VXLAN) to run independently of L2 constraints. Without this routed design, the fabric cannot propagate reachability efficiently and may revert to spanning-tree, which is explicitly contrary to SD-Access best practices.

Why this answer

In an SD-Access fabric, the underlay network must provide IP connectivity between all fabric devices (edge, control plane, border nodes) using a routed access layer with a link-state routing protocol like IS-IS or OSPF. This ensures fast convergence, loop-free topology, and support for the overlay's VXLAN tunnels. A routed access layer eliminates spanning-tree dependencies and aligns with the fabric's requirement for a simple, scalable IP-based transport.

Exam trap

Cisco often tests the misconception that the underlay must support multicast (PIM) or preserve legacy VLANs, when in fact the underlay only needs unicast routing and the overlay handles all segmentation and multicast replication via head-end replication or native multicast.

How to eliminate wrong answers

Option B is wrong because PIM-SM is used for multicast routing in the overlay (for traffic such as ARP or multicast applications), not in the underlay; the underlay only needs unicast routing to establish VXLAN tunnels. Option C is wrong because preserving existing VLANs across the fabric contradicts the SD-Access design principle of decoupling the overlay from the underlay; VLANs are mapped to virtual network identifiers (VNIs) in the overlay, and the underlay should be a clean, routed IP network. Option D is wrong because VRF-lite is a Layer 3 segmentation technique used in traditional networks, not in the SD-Access underlay; tenant isolation is achieved via the overlay's VXLAN and LISP/VN segmentation, not by configuring VRFs on underlay interfaces.

Page 1 of 2 · 142 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Architecture questions.