Courseiva

CCNA Infrastructure Questions

75 of 179 questions · Page 1/3 · Infrastructure · Answers revealed

1
MCQmedium

A network engineer is configuring QoS on a Cisco IOS switch. The engineer needs to mark packets coming from a specific server with DSCP EF (46) and ensure that this marking is trusted throughout the network. Which command should be used to trust the DSCP markings on the interface connected to the server?

A.mls qos trust dscp
B.mls qos trust cos
C.mls qos trust ip-precedence
D.mls qos map cos-dscp 0 8 16 24 32 40 48 56
AnswerA

The 'mls qos trust dscp' command configures the interface to trust the DSCP value in incoming packets. This means the switch will use the existing DSCP marking for classification and queuing, rather than overwriting it. This is appropriate when the server is already marking its traffic with DSCP EF, as it preserves the marking and ensures proper treatment across the network.

Why this answer

To trust DSCP markings on an interface, the correct command is 'mls qos trust dscp'. This tells the switch to accept the DSCP value in incoming packets and use it for QoS processing. Since the server is already marking its traffic with DSCP EF, this command ensures that the marking is preserved and honored throughout the network, preventing the switch from re-marking the packets.

Exam trap

The trap here is confusing trust boundaries and assuming that trusting CoS is equivalent to trusting DSCP, even when the server sends untagged frames.

2
MCQhard

A network engineer is configuring a switch stack with two Catalyst 9300 switches. The engineer wants to ensure that if the active switch fails, the standby switch takes over with minimal disruption. Which statement accurately describes the stack MAC address behavior during a failover?

A.The stack MAC address is a virtual MAC address generated by the stack protocol and never changes.
B.The stack MAC address immediately changes to the new active switch's MAC address upon failover.
C.The stack MAC address is always the MAC address of the switch with the highest priority, regardless of failover.
D.The stack MAC address remains the same as the original active switch's MAC address unless the stack MAC persistence timer expires.
AnswerD

By default, the stack retains the MAC address of the original active switch for a period defined by the stack MAC persistence timer (default 4 minutes). If the failover occurs and the timer has not expired, the new active switch continues using the same stack MAC address, minimizing disruption to neighboring devices and avoiding MAC address table changes.

Why this answer

The stack MAC persistence feature keeps the original active switch's MAC address for a configurable timer (default 4 minutes). During a failover, the standby switch becomes active and continues using that MAC address if the timer has not expired. This minimizes network disruption by avoiding MAC address table updates on neighboring devices.

Exam trap

The trap here is assuming that the stack MAC address changes immediately upon failover, when in fact it is preserved by default for a persistence period.

3
MCQhard

A network engineer is implementing VXLAN with an EVPN control plane in a Cisco Nexus data center. The requirement is to provide Layer 2 extension over a Layer 3 underlay while maintaining optimal forwarding and avoiding unknown unicast flooding. Which statement describes the role of the EVPN control plane in this VXLAN fabric?

A.EVPN uses PIM-SM to build multicast trees for BUM traffic, and MAC addresses are learned only through data plane flooding.
B.EVPN uses a centralized SDN controller to distribute MAC addresses, and VTEPs must query the controller for every unknown destination.
C.EVPN relies on OSPF to flood MAC address updates to all VTEPs, ensuring that unknown unicast traffic is replicated across the fabric.
D.EVPN uses MP-BGP to distribute MAC and IP reachability information, enabling the VTEPs to learn remote MAC addresses and suppress unknown unicast flooding.
AnswerD

EVPN acts as the control plane for VXLAN, using MP-BGP to advertise MAC and IP addresses (Type 2 and Type 5 routes) to other VTEPs. This allows each VTEP to build a forwarding table for remote hosts, eliminating the need for flooding to learn MAC addresses and enabling optimal forwarding across the Layer 3 underlay.

Why this answer

EVPN with MP-BGP provides a scalable control plane for VXLAN by advertising MAC and IP reachability, which enables remote MAC learning and eliminates unknown unicast flooding. This improves efficiency and allows for optimal forwarding. The other options misattribute the control protocol or describe mechanisms that do not provide EVPN's benefits.

Exam trap

The trap here is confusing the underlay multicast mechanism (PIM-SM) with the overlay control plane (EVPN), or assuming a centralized controller is required for EVPN.

4
MCQhard

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using SHA-256 HMAC cryptographic authentication on an interface. Which command sequence correctly enables this authentication?

A.ip ospf authentication key-chain <name> and configure a key chain with key 1 using cryptographic-algorithm hmac-sha-256
B.ip ospf authentication followed by ip ospf authentication-key <password>
C.ip ospf authentication null
D.ip ospf authentication message-digest followed by ip ospf message-digest-key 1 md5 <key>
AnswerA

This sequence correctly enables OSPFv2 SHA-256 HMAC authentication. The interface command ip ospf authentication key-chain references a key chain, which must be defined globally with a key that specifies the cryptographic algorithm hmac-sha-256 and a password. This provides stronger security than MD5. The key chain allows for key rollover and multiple keys with different lifetimes, which is essential for operational flexibility.

Why this answer

OSPFv2 supports SHA-256 HMAC authentication through key chains. The interface command ip ospf authentication key-chain <name> references a key chain configured with key 1 and cryptographic-algorithm hmac-sha-256. This provides cryptographic authentication with stronger hashing than MD5.

Simple authentication and MD5 do not meet the SHA-256 requirement, and null disables authentication.

Exam trap

The trap here is assuming that MD5 message-digest authentication is equivalent to SHA-256 HMAC, when MD5 uses a different and weaker algorithm.

5
MCQmedium

A network engineer is deploying a new branch office that uses a single switch stack with two member switches. The stack must forward traffic between access ports in different VLANs without involving an external router. Which feature should be configured to meet this requirement?

A.Configure private VLANs on the access ports to allow communication between VLANs.
B.Configure an SVI for each VLAN on the switch stack and enable IP routing with the ip routing command.
C.Configure VTP transparent mode on all switches and create the VLANs manually.
D.Configure 802.1Q trunk links between the two stack members and enable dynamic ARP inspection.
AnswerB

This is correct because an SVI provides Layer 3 processing for a VLAN, and enabling IP routing on the stack allows inter-VLAN traffic to be routed internally. The stack acts as a single logical switch, so SVIs are active on the stack master and traffic between VLANs is routed without an external router.

Why this answer

The requirement is to route traffic between VLANs using the switch stack itself. Creating switched virtual interfaces for each VLAN and enabling IP routing allows the stack to perform inter-VLAN routing without an external router. This is a standard design for collapsed core or branch offices where a multilayer switch provides both Layer 2 and Layer 3 forwarding.

Exam trap

The trap here is assuming that creating VLANs alone enables communication between them, when in fact Layer 3 routing must be explicitly enabled with SVIs.

6
MCQhard

A network engineer is deploying a Cisco SD-Access fabric and needs to ensure that endpoints can communicate with devices outside the fabric. The engineer configures a fabric border node. Which functionality does the border node provide in this architecture?

A.It provides connectivity between the fabric and external networks, such as data centers or the internet.
B.It authenticates endpoints and assigns them to fabric VNs based on policy.
C.It acts as the mapping database system that stores endpoint location information.
D.It encapsulates fabric traffic into VXLAN and forwards it to the control plane node.
AnswerA

The fabric border node is responsible for bridging the SD-Access fabric to external networks. It translates fabric VXLAN encapsulation to traditional networking protocols and vice versa, allowing endpoints inside the fabric to reach destinations outside. It also advertises fabric prefixes to external networks. This is the primary role of a border node in Cisco SD-Access.

Why this answer

In Cisco SD-Access, the fabric border node serves as the gateway between the fabric and external networks. It performs VXLAN-to-traditional network translation, allowing fabric endpoints to communicate with external destinations. It also advertises external routes into the fabric and fabric prefixes to external networks.

The border node does not handle endpoint authentication, mapping database services, or control plane functions; those are handled by edge nodes and control plane nodes respectively.

Exam trap

The trap here is confusing the border node with the control plane node or edge node; the border node's primary role is external connectivity, not endpoint registration or authentication.

7
MCQhard

A network engineer is implementing VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. Hosts in the same subnet are attached to different edge nodes. The engineer must ensure that a host retains its default gateway IP and MAC address when it moves between edge nodes. Which technology should be configured on the edge nodes?

A.VRRP with preemption enabled on all edge nodes
B.Anycast gateway with the same IP and MAC address on all edge nodes for that subnet
C.HSRP group with a unique virtual IP per edge node
D.Proxy ARP on the edge nodes
AnswerB

In a VXLAN fabric, a distributed anycast gateway uses the same virtual IP and virtual MAC for the default gateway on every edge node that hosts the subnet. A roaming host sees no change in gateway identity, so ARP entries remain valid. This provides seamless mobility and optimal forwarding without tromboning traffic to a central gateway.

Why this answer

A distributed anycast gateway assigns the same virtual IP and virtual MAC to the default gateway on every edge node hosting a subnet. Hosts can move between edge nodes without changing their gateway ARP entry, which preserves connectivity and avoids suboptimal paths. This is a fundamental requirement for seamless host mobility in VXLAN EVPN fabrics.

Exam trap

The trap here is assuming first-hop redundancy protocols like HSRP or VRRP can provide a distributed gateway, when they only offer one active gateway per subnet.

8
MCQeasy

A network engineer is configuring a Cisco IOS router to support OSPFv3 for IPv6. The router must form adjacencies on its GigabitEthernet0/0 interface, which is assigned to area 0. Which command is required to enable OSPFv3 on the interface?

A.ospf ipv6 1 area 0
B.router ospfv3 1 area 0
C.ipv6 router ospf 1 area 0
D.ipv6 ospf 1 area 0
AnswerD

The command 'ipv6 ospf 1 area 0' is used in interface configuration mode to enable OSPFv3 on that interface and assign it to area 0. The process ID '1' must match the OSPFv3 process configured globally with 'ipv6 router ospf 1'. This command allows the interface to form adjacencies and participate in OSPFv3. Without it, OSPFv3 will not run on the interface, even if the global process is configured.

Why this answer

To enable OSPFv3 on an interface, you use the interface configuration command 'ipv6 ospf <process-id> area <area-id>'. This command activates OSPFv3 on the interface and assigns it to the specified area. The process ID must match the one configured globally with 'ipv6 router ospf <process-id>'.

The other options are invalid commands or incorrect syntax.

Exam trap

The trap here is mixing up the global OSPFv3 command with the interface-level command, or reversing the keyword order.

9
MCQeasy

A network administrator is configuring a Cisco Catalyst switch to assign a voice VLAN to IP phones and a data VLAN to connected PCs on the same port. The phones are Cisco and use CDP to communicate VLAN information. Which configuration should be applied to the switch port?

A.Configure the port as an access port in the data VLAN and enable the voice VLAN with the 'switchport voice vlan' command.
B.Configure the port as a dynamic auto port and set the voice VLAN to be negotiated via DTP.
C.Configure the port as a private VLAN host port and map the voice VLAN as a secondary VLAN.
D.Configure the port as a trunk with native VLAN for data and allow the voice VLAN.
AnswerA

This configuration allows the switch port to carry data traffic for the PC in the access VLAN (untagged) and voice traffic for the phone in the voice VLAN (tagged with 802.1Q). The 'switchport voice vlan' command instructs the switch to use CDP to tell the phone which VLAN to use for voice. This is the standard and recommended method for connecting Cisco IP phones and PCs on the same port.

Why this answer

The correct configuration is to set the port as an access port in the data VLAN and then specify the voice VLAN using the 'switchport voice vlan' command. This allows the switch to use CDP to inform the IP phone of the voice VLAN, so the phone tags its voice traffic with the appropriate VLAN ID while the PC's data traffic remains untagged in the access VLAN. This is the Cisco best practice for connecting IP phones and PCs to the same switch port.

Exam trap

The trap here is thinking that a trunk port is required to carry both voice and data VLANs; in reality, an access port with a voice VLAN handles both, with the phone tagging voice traffic.

10
MCQhard

A network engineer is implementing Cisco TrustSec in a campus network. The requirement is to classify traffic based on the identity of the user and the device, and to enforce policy across the network without relying on IP addresses. Which component assigns the Security Group Tag (SGT) to the packet at ingress?

A.The egress switch removes the SGT and applies the Security Group ACL based on the source IP address.
B.The ingress access layer switch or router inserts the SGT into the packet using inline tagging or SXP.
C.The Cisco DNA Center appliance assigns the SGT during fabric VXLAN encapsulation.
D.The Cisco Identity Services Engine (ISE) assigns the SGT directly into the packet header.
AnswerB

The ingress network device is responsible for classifying traffic and imposing the SGT. It receives the SGT value from ISE during authentication, then inserts the tag into the packet using inline tagging (Cisco Metadata or 802.1AE) or propagates the mapping via SXP to devices that do not support inline tagging. This is the enforcement point for tag imposition.

Why this answer

In Cisco TrustSec, the ingress network device classifies traffic and imposes the SGT after receiving the classification from ISE. Tag propagation uses inline tagging or SXP, and egress devices enforce Security Group ACLs based on source and destination SGTs. The policy decision comes from ISE, but tag imposition happens at the ingress enforcement point.

Exam trap

The trap here is assuming that ISE, as the policy server, writes the SGT into packets, when ISE only provides the classification and the ingress network device performs tag imposition.

11
Multi-Selectmedium

A network engineer is configuring a Cisco IOS XE router to support a site-to-site VXLAN tunnel over an existing IP underlay. The engineer must configure the NVE interface and ensure that the underlay provides the necessary transport. Which two statements are true about this configuration? (Choose two.)

Select 2 answers
A.The NVE interface must be assigned an IP address from the same subnet as the remote VTEP.
B.VXLAN requires that the underlay provide Layer 2 adjacency between all VTEPs.
C.The underlay must run MPLS LDP to carry VXLAN traffic between VTEPs.
D.VXLAN uses UDP port 4789 as the destination port for encapsulated traffic by default.
E.The NVE interface is configured with a source interface that provides the tunnel source IP address.
AnswersD, E

VXLAN encapsulates Layer 2 frames in UDP, and the IANA-assigned default destination port is 4789. Cisco platforms use this port by default when sending VXLAN-encapsulated traffic. If a firewall or ACL is in the path, it must permit UDP 4789 so that the tunnel traffic is not dropped. Changing the port is possible but uncommon and must match on all VTEPs.

Why this answer

VXLAN on Cisco IOS XE uses an NVE interface that references a source interface for the tunnel source IP, and it encapsulates frames in UDP with default destination port 4789. The underlay only needs IP reachability between VTEPs; MPLS LDP, shared subnets, and Layer 2 adjacency are not required. These two statements correctly describe the configuration and transport behavior.

Exam trap

The trap here is assuming VXLAN needs MPLS or Layer 2 adjacency in the underlay, when it actually runs over a plain IP underlay using UDP 4789 and a sourced NVE interface.

12
MCQeasy

An engineer needs to configure a switchport to carry traffic for multiple VLANs to a router using a single physical link. Which configuration should be applied on the switchport?

A.Configure the port as a dynamic desirable port.
B.Configure the port as a trunk port.
C.Configure the port as a routed port.
D.Configure the port as an access port.
AnswerB

A trunk port tags frames with 802.1Q VLAN identifiers, allowing multiple VLANs to traverse one physical link to the router. Access ports carry only a single untagged VLAN, so they cannot satisfy the multi-VLAN requirement.

Why this answer

A trunk port is specifically designed to carry traffic for multiple VLANs over a single physical link using IEEE 802.1Q encapsulation. This allows the switch to tag frames with VLAN IDs, enabling the router (often configured as a router-on-a-stick) to route between VLANs.

Exam trap

The trap here is that candidates often confuse Dynamic Desirable (a DTP negotiation mode) with a trunk port configuration, thinking negotiation automatically results in trunking, but the question asks for the configuration that directly enables multi-VLAN traffic, not a negotiation protocol.

How to eliminate wrong answers

Option A is wrong because Dynamic Desirable is a Dynamic Trunking Protocol (DTP) mode that negotiates trunking with the remote device, but it does not directly configure the port to carry multiple VLANs; it is a negotiation state, not the final configuration. Option C is wrong because a routed port is a Layer 3 interface that operates like a router port, stripping all Layer 2 switching and VLAN tagging, so it cannot carry multiple VLANs on a single link. Option D is wrong because an access port belongs to only one VLAN and strips any VLAN tags from frames, making it unsuitable for carrying multiple VLANs.

13
MCQmedium

A network engineer configured a router with the command `ip route 0.0.0.0 0.0.0.0 192.168.1.1` and also has a specific static route for 10.1.1.0/24 pointing to 192.168.1.1. A packet arrives destined for 10.1.1.5. Which route will the router use to forward the packet?

A.The specific static route for 10.1.1.0/24 because it has a longer prefix length.
B.The default route because it is less specific and matches all destinations.
C.The router will load-balance the packet across both routes.
D.The packet will be dropped because of conflicting static routes.
AnswerA

The router uses the longest prefix match rule. The specific route 10.1.1.0/24 has a prefix length of 24, while the default route has a prefix length of 0. The more specific route wins, so the packet is forwarded using the static route for 10.1.1.0/24 via 192.168.1.1.

Why this answer

The correct answer is the specific static route for 10.1.1.0/24. Cisco IOS uses longest prefix match to select the best route. A default route (0.0.0.0/0) is the least specific and is only used when no other route matches.

Since a more specific route exists for the destination, that route is chosen.

Exam trap

The trap here is assuming that a default route takes precedence because it is configured first or because it is a default route, but longest prefix match always wins regardless of configuration order.

14
MCQmedium

A network administrator is configuring a Cisco IOS router to act as a DHCP server for a subnet. The administrator wants to ensure that the router assigns IP addresses to clients and also provides them with the IP address of a TFTP server for configuration files. Which DHCP option should the administrator configure to provide the TFTP server address?

A.Option 67
B.Option 66
C.Option 43
D.Option 150
AnswerB

DHCP option 66 is used to specify the TFTP server name or IP address. In Cisco IOS, this is configured with the 'option 66 ip <ip-address>' command within the DHCP pool. This option is commonly used for IP phones and other devices that need to download configuration files from a TFTP server. Therefore, it is the correct choice to provide the TFTP server address.

Why this answer

DHCP option 66 is the standard option for specifying the TFTP server name or IP address. Configuring this option in the DHCP pool allows clients to learn the TFTP server address, which they can use to download configuration files. This is the correct choice for providing the TFTP server address to DHCP clients.

Exam trap

The trap here is confusing option 66 with option 67 or option 150, which serve different purposes such as specifying the bootfile name or providing a list of TFTP servers for IP phones.

15
MCQeasy

A network administrator is configuring a Cisco switch port that connects to an IP phone and a PC. The phone must tag voice traffic with VLAN 200, and the PC must send untagged traffic on VLAN 100. Which configuration is required on the switch port?

A.switchport mode access; switchport access vlan 100; switchport voice vlan 200
B.switchport mode access; switchport access vlan 200; switchport voice vlan 100
C.switchport mode trunk; switchport trunk encapsulation dot1q; switchport trunk allowed vlan 100,200
D.switchport mode trunk; switchport trunk native vlan 100; switchport trunk allowed vlan 200
AnswerA

This configuration sets the port as an access port for data VLAN 100 and enables voice VLAN 200 for tagged voice traffic from the IP phone. The phone will tag voice frames with VLAN 200, while the PC sends untagged frames that are placed in VLAN 100. This is the standard Cisco IP phone configuration.

Why this answer

The correct configuration uses an access port with a data VLAN and a voice VLAN. The voice VLAN feature allows the switch to instruct the IP phone to tag voice traffic with the specified VLAN, while the PC's untagged traffic is placed in the access VLAN. This provides separation of voice and data traffic and is the typical deployment for Cisco IP phones.

Exam trap

The trap here is selecting a trunk configuration when the voice VLAN feature on an access port is the intended solution for a phone and PC on the same switch port.

16
MCQhard

A network engineer is configuring OSPF on a multiaccess segment. The design requires that the DR/BDR election be deterministic, with Router A always becoming the DR and Router B always becoming the BDR. Both routers are Cisco IOS devices. Which configuration on Router A ensures it wins the DR election?

A.Set the OSPF priority to 0 on Router A's interface.
B.Configure a higher Router ID on Router B.
C.Set the OSPF priority to 255 on Router A's interface.
D.Set the OSPF network type to point-to-point on Router A's interface.
AnswerC

OSPF DR/BDR election is based first on interface priority, then on Router ID. The highest priority wins. Priority 255 is the maximum value and ensures Router A has the highest priority on the segment, making it the DR provided no other router has the same priority with a higher Router ID. This is the standard way to force a router to become DR.

Why this answer

To ensure a router becomes DR, its OSPF interface priority must be higher than all other routers on the segment. Priority 255 is the maximum and guarantees victory unless another router also has 255 and a higher Router ID. Setting priority to 0 makes a router ineligible, a higher Router ID on another router would favor that router, and point-to-point network type removes DR/BDR election altogether.

Exam trap

The trap here is thinking that Router ID is the primary factor in DR election, when priority takes precedence.

17
Multi-Selecthard

A network engineer is deploying a new Cisco SD-WAN fabric using Cisco vManage, vSmart, and vBond controllers. The engineer must ensure that the control plane is secure and resilient. Which two statements are true regarding the roles of these controllers? (Choose two.)

Select 2 answers
A.vSmart distributes control plane policies and routing information to WAN edge devices using OMP.
B.vBond maintains the routing table and makes path selection decisions for the overlay.
C.vBond orchestrates the control plane and is responsible for authenticating and validating all other controllers and WAN edge devices.
D.vSmart is responsible for the initial device authentication and NAT traversal.
E.vManage is responsible for authenticating WAN edge devices and distributing encryption keys.
AnswersA, C

vSmart is the control plane controller that uses the Overlay Management Protocol (OMP) to distribute routing, policy, and security information to WAN edge devices. It maintains a centralized view of the overlay and ensures consistent policy enforcement. It does not handle device authentication; that is vBond's role. vSmart is essential for dynamic path selection and policy application across the SD-WAN fabric.

Why this answer

In Cisco SD-WAN, vBond orchestrates the control plane by authenticating and validating controllers and WAN edge devices, facilitating NAT traversal. vSmart distributes control plane policies and routing information using OMP. vManage is the management plane for configuration and monitoring. These roles are distinct and critical for a secure and resilient fabric.

Exam trap

The trap here is conflating the roles of vBond and vSmart; vBond handles authentication and orchestration, while vSmart handles control plane policies and routing.

18
Multi-Selecthard

A network engineer is implementing VXLAN with Cisco SD-Access. The engineer needs to ensure that the fabric supports Layer 2 and Layer 3 traffic between endpoints in different subnets. Which two components are required in the VXLAN data plane to achieve this? (Choose two.)

Select 2 answers
A.VXLAN Network Identifier (VNI)
B.Locator/ID Separation Protocol (LISP)
C.Cisco TrustSec Security Group Tag (SGT)
D.VXLAN Tunnel Endpoint (VTEP)
E.Intermediate System to Intermediate System (IS-IS)
AnswersA, D

The VNI is a 24-bit identifier that segments the VXLAN overlay. Each VNI represents a Layer 2 or Layer 3 segment. It is used to identify the tenant or subnet. Without VNIs, there is no separation of traffic. In SD-Access, VNIs are mapped to VRFs and subnets. They are required to differentiate traffic in the overlay. Therefore, VNI is a required component.

Why this answer

In VXLAN, the data plane relies on VTEPs to encapsulate and decapsulate traffic, and VNIs to identify the overlay segments. These two components are essential for forwarding Layer 2 and Layer 3 traffic across the underlay. LISP is a control plane protocol, IS-IS is an underlay routing protocol, and SGT is for policy enforcement.

Therefore, VTEP and VNI are the correct choices for the data plane.

Exam trap

The trap here is confusing control plane protocols like LISP with data plane components, or assuming that security tags like SGT are required for basic connectivity.

19
MCQmedium

An engineer configures a VXLAN tunnel between two Nexus switches acting as VTEPs. The underlay is a routed Layer 3 network using OSPF, and the loopback interfaces of the VTEPs are reachable. However, hosts in the same VXLAN VNI on different VTEPs cannot communicate. Which action should the engineer take to resolve the issue?

A.Configure static VXLAN tunnels between the VTEPs using the destination-udp-port command.
B.Enable OSPF on the loopback interfaces and advertise them into the underlay.
C.Enable PIM sparse mode on the underlay and configure a rendezvous point for multicast replication.
D.Configure the NVE interface with the correct source-interface and ensure the VNI is mapped to the VLAN.
AnswerD

The NVE interface must be configured with a source-interface (typically a loopback) and the VNI must be associated with the correct VLAN. Without this mapping, VXLAN encapsulation or decapsulation fails, preventing communication between hosts on different VTEPs. This is a common misconfiguration that directly causes the described symptom, making this the correct action to resolve the issue.

Why this answer

The NVE interface on a Cisco Nexus VTEP must have a source-interface configured, usually a loopback, and each VNI must be mapped to a VLAN. Without these, VXLAN encapsulation and decapsulation fail, so hosts in the same VNI on different VTEPs cannot communicate. The underlay is already operational, so the fix is to correct the NVE and VNI configuration.

Exam trap

The trap here is assuming the underlay routing is at fault when the loopbacks are already reachable, leading to unnecessary OSPF or PIM changes instead of checking the NVE interface and VNI mapping.

20
MCQhard

A network engineer is configuring a Cisco IOS router for NAT overload (PAT) to allow internal hosts on the 10.1.1.0/24 network to access the internet using the router's outside interface IP address. The engineer wants to ensure that all internal hosts can initiate connections and that return traffic is correctly translated. Which configuration is required?

A.ip nat inside source list 1 interface GigabitEthernet0/0 overload, with an access list permitting 10.1.1.0/24, and interfaces marked as inside and outside.
B.ip nat inside source static 10.1.1.1 203.0.113.1, with interfaces marked as inside and outside.
C.ip nat inside source list 1 pool MYPOOL overload, with a pool of public addresses, and interfaces marked as inside and outside.
D.ip nat outside source list 1 interface GigabitEthernet0/0 overload, with an access list permitting 10.1.1.0/24, and interfaces marked as inside and outside.
AnswerA

This configuration enables NAT overload (PAT) by translating all internal addresses matching the access list to the outside interface's IP address. The overload keyword allows multiple hosts to share the same public IP. Marking interfaces as inside and outside is essential for NAT to function correctly. This meets the requirements.

Why this answer

The correct configuration uses ip nat inside source list with the interface keyword and overload to translate internal addresses to the outside interface IP. This enables PAT, allowing multiple internal hosts to share the single public IP. The access list must permit the internal subnet, and interfaces must be correctly marked as inside and outside for NAT to operate.

Exam trap

The trap here is confusing NAT overload using an interface with NAT using a pool, or misusing the outside source command, which is for different translation scenarios.

21
MCQmedium

A network administrator is deploying a new Cisco Catalyst switch and wants to restrict management access to the switch. The requirement is that only hosts on the 10.10.10.0/24 subnet can access the switch via SSH, and all other SSH attempts must be denied. Which configuration achieves this?

A.access-list 10 permit 10.10.10.0 0.0.0.255; interface vlan 1; ip access-group 10 in
B.access-list 10 permit 10.10.10.0 0.0.0.255; line vty 0 4; access-class 10 in
C.access-list 10 deny 10.10.10.0 0.0.0.255; line vty 0 4; access-class 10 in
D.access-list 110 permit tcp 10.10.10.0 0.0.0.255 any eq 22; line vty 0 4; access-class 110 in
AnswerB

This configuration creates a standard ACL that permits the 10.10.10.0/24 subnet and applies it inbound to the VTY lines with access-class. This restricts SSH and Telnet access to only that subnet, meeting the requirement. The implicit deny at the end of the ACL blocks all other sources.

Why this answer

Using a standard ACL that permits the 10.10.10.0/24 subnet and applying it inbound on the VTY lines with access-class restricts SSH and Telnet access to only that subnet. The implicit deny at the end blocks all other sources, satisfying the requirement without affecting other traffic.

Exam trap

The trap here is applying an ACL to an interface instead of the VTY lines, or using an extended ACL when a standard ACL is sufficient, which can lead to unintended filtering or lack of restriction.

22
Multi-Selectmedium

A network engineer is configuring a Cisco IOS router to support PIM Sparse Mode (PIM-SM) for multicast traffic. The engineer needs to ensure that the router can dynamically discover Rendezvous Points (RPs). Which two mechanisms can be used to achieve this? (Choose two.)

Select 2 answers
A.MSDP
B.Anycast RP
C.Bootstrap Router (BSR)
D.Auto-RP
E.Static RP configuration
AnswersC, D

BSR is a standards-based mechanism for dynamic RP discovery. It uses candidate RPs and a Bootstrap Router to distribute RP information to all routers in the PIM domain. Routers receive BSR messages and automatically learn the RP mappings. This is a valid method for dynamic RP discovery, making BSR correct.

Why this answer

Auto-RP and Bootstrap Router (BSR) are the two primary mechanisms for dynamic RP discovery in PIM-SM. Auto-RP is Cisco proprietary and uses a mapping agent, while BSR is an open standard. Both allow routers to automatically learn which RP to use for multicast groups, eliminating the need for manual configuration on every router.

These methods enhance scalability and simplify multicast network management.

Exam trap

The trap here is confusing RP redundancy mechanisms like Anycast RP and MSDP with dynamic RP discovery, which are distinct functions.

23
Multi-Selecthard

A network engineer is configuring a Cisco IOS router to support NAT overload (PAT) for a small office. The inside network is 192.168.1.0/24, and the outside interface is GigabitEthernet0/1 with IP address 203.0.113.5. The engineer wants to translate all inside addresses to the outside interface address. Which two commands are required to complete this configuration? (Choose two.)

Select 2 answers
A.access-list 1 permit 192.168.1.0 0.0.0.255
B.ip nat outside source list 1 interface GigabitEthernet0/1 overload
C.ip nat inside source list 1 interface GigabitEthernet0/1 overload
D.ip nat inside source static 192.168.1.10 203.0.113.5
E.ip nat inside source list 1 pool MYPOOL overload
AnswersA, C

This access list defines the inside local addresses that are eligible for NAT translation. It permits the entire 192.168.1.0/24 subnet. The NAT command references this list to identify which traffic should be translated. Without this access list, the NAT configuration would not know which addresses to translate. Therefore, it is a required command.

Why this answer

To configure NAT overload (PAT) using the outside interface address, two commands are needed: an access list to define the inside local addresses, and the 'ip nat inside source list' command with the 'overload' keyword referencing that list and the outside interface. The access list permits the 192.168.1.0/24 subnet, and the NAT command translates all permitted addresses to the outside interface's IP. The other options either use a pool, configure the wrong direction, or create a static translation, none of which meet the requirement.

Exam trap

The trap here is confusing the direction of NAT (inside source vs. outside source) or forgetting the 'overload' keyword, which is essential for PAT.

24
MCQeasy

A network administrator is configuring a new Cisco Catalyst switch and needs to assign a management IP address to VLAN 1. Which command is used to enter the interface configuration mode for VLAN 1?

A.interface fastethernet 0/1
B.interface vlan 1
C.interface range vlan 1
D.vlan 1
AnswerB

The command 'interface vlan 1' is used to create or enter the configuration mode for the switched virtual interface (SVI) associated with VLAN 1. This allows the administrator to assign an IP address to the VLAN interface, enabling management access to the switch. This is the correct command to configure a management IP on VLAN 1.

Why this answer

To assign a management IP address to VLAN 1 on a Cisco switch, you must configure the switched virtual interface (SVI) for VLAN 1. The command 'interface vlan 1' enters interface configuration mode for that SVI, where you can then use the 'ip address' command to assign an IP address and enable the interface with 'no shutdown'.

Exam trap

The trap here is confusing the command to create a VLAN (vlan 1) with the command to configure its Layer 3 interface (interface vlan 1). Creating a VLAN does not automatically create an SVI.

25
MCQhard

A network engineer is deploying a new Cisco Catalyst 9000 switch stack. The engineer wants to ensure that the stack uses the most efficient use of stack ports and provides the highest possible bandwidth between stack members. Which stacking technology and topology should be used?

A.Cisco StackWise with a star topology
B.Cisco StackPower with a ring topology
C.Cisco StackWise with a full mesh topology
D.Cisco StackWise with a ring topology
AnswerD

Cisco StackWise uses a ring topology to connect stack members. This provides redundancy because if one stack cable fails, the ring can still forward traffic in the opposite direction. StackWise-480 and StackWise-1T are common on Catalyst 9000 switches, offering high bandwidth (480 Gbps or 1 Tbps) and efficient use of stack ports. A ring topology is the standard and most efficient for StackWise.

Why this answer

Cisco StackWise uses a ring topology to connect stack members, providing high bandwidth and redundancy. If a cable fails, the ring can still function. StackWise-480 and StackWise-1T are used on Catalyst 9000 switches, offering up to 480 Gbps or 1 Tbps of stacking bandwidth.

StackPower is for power sharing, not data stacking.

Exam trap

The trap here is confusing StackPower with StackWise; StackPower is for power redundancy, while StackWise is for data stacking.

26
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate management users via TACACS+. The TACACS+ server is reachable at 10.1.1.100. The administrator wants to ensure that if the TACACS+ server becomes unreachable, the router will fall back to local authentication using the local username 'admin' with password 'Cisco123'. Which configuration should be applied?

A.aaa new-model aaa authentication login default group tacacs+ local tacacs server TAC1 address ipv4 10.1.1.100 key SecretKey username admin privilege 15 secret Cisco123
B.aaa new-model aaa authentication login default group tacacs+ local tacacs-server host 10.1.1.100 key SecretKey username admin privilege 15 secret Cisco123
C.aaa new-model aaa authentication login default group tacacs+ tacacs server TAC1 address ipv4 10.1.1.100 key SecretKey username admin privilege 15 secret Cisco123
D.aaa new-model aaa authentication login default group tacacs+ local tacacs server TAC1 address ipv4 10.1.1.100 key SecretKey username admin privilege 15 password Cisco123
AnswerA

This configuration enables AAA, sets the default login authentication method list to use TACACS+ first and then local as fallback, defines the TACACS+ server, and creates a local username. This ensures that if the TACACS+ server is unreachable, the router will use the local database for authentication.

Why this answer

The correct configuration enables AAA, specifies TACACS+ with local fallback in the authentication method list, defines the TACACS+ server using the modern 'tacacs server' command, and creates a local username with a secret. This ensures authentication works even if the TACACS+ server is down.

Exam trap

The trap here is forgetting to include the 'local' keyword as a fallback method, which would cause authentication to fail if the TACACS+ server is unreachable.

27
MCQmedium

A network engineer is configuring a VXLAN overlay. The underlay is an IP-routed network, and the engineer needs to ensure that the VXLAN tunnel endpoints can discover each other's VTEP IP addresses dynamically. Which technology should be used?

A.PIM sparse mode
B.MP-BGP EVPN
C.OSPFv3
D.LISP
AnswerB

MP-BGP EVPN is the control plane that distributes MAC and IP reachability information, including VTEP IP addresses, between VXLAN tunnel endpoints. It allows dynamic discovery of remote VTEPs and their associated MAC addresses, eliminating the need for flood-and-learn. This is the standard Cisco SD-Access and data center VXLAN control plane.

Why this answer

MP-BGP EVPN acts as the VXLAN control plane, allowing VTEPs to exchange reachability information for MAC and IP addresses. This enables dynamic discovery of remote VTEPs and their endpoints, avoiding the inefficiencies of flood-and-learn. PIM, OSPFv3, and LISP do not provide the required EVPN address family for VXLAN tunnel endpoint discovery.

Exam trap

The trap here is confusing underlay routing protocols like OSPFv3 or multicast PIM with the overlay control plane needed for VTEP and MAC discovery.

28
MCQeasy

A network engineer is configuring a Cisco IOS switch and needs to ensure that a port connected to a server is placed into the forwarding state immediately when the link comes up, without going through the listening and learning states. The engineer also wants to protect against accidental loops if a switch is connected to that port. Which feature should be configured on the port?

A.UplinkFast
B.BackboneFast
C.PortFast with BPDU Guard
D.Root Guard
AnswerC

PortFast allows a port to transition immediately to the forwarding state when the link comes up, bypassing listening and learning. BPDU Guard disables the port if it receives a BPDU, protecting against accidental loops if a switch is connected. Together, they meet the requirements for fast server connectivity and loop protection.

Why this answer

PortFast transitions a port immediately to forwarding, which is ideal for server connections. BPDU Guard disables the port if a BPDU is received, preventing loops if a switch is mistakenly connected. The combination provides both fast connectivity and loop protection, making it the correct choice for this scenario.

Exam trap

The trap here is confusing PortFast with other spanning-tree enhancements like UplinkFast or BackboneFast, which serve different purposes and do not provide immediate forwarding on access ports.

29
MCQhard

A network engineer is implementing VXLAN with a Cisco Nexus 9000 series switch acting as a VTEP. The engineer needs to ensure that the VXLAN overlay can carry traffic for multiple tenants while maintaining isolation. Which component is responsible for identifying the VXLAN segment and providing tenant isolation?

A.Destination IP address in the outer IP header
B.VXLAN Network Identifier (VNI)
C.UDP source port number
D.VLAN ID in the outer Ethernet header
AnswerB

The VNI is a 24-bit identifier that uniquely identifies a VXLAN segment. It provides isolation for tenants by separating traffic into distinct logical networks. Each VNI maps to a specific Layer 2 or Layer 3 domain, ensuring that traffic from different tenants remains isolated even when using the same underlay.

Why this answer

The VXLAN Network Identifier (VNI) is a 24-bit field in the VXLAN header that uniquely identifies each VXLAN segment. It allows up to 16 million segments, enabling massive multi-tenancy. Tenant isolation is achieved because each VNI represents a separate logical network, and traffic from different VNIs is not mixed.

The VNI is the key component for identifying the segment and ensuring isolation.

Exam trap

The trap here is assuming that the outer VLAN ID or IP addresses provide tenant isolation, when in fact the VNI is the sole identifier for the VXLAN segment.

30
MCQhard

A network engineer is configuring a Cisco IOS XE router to support NETCONF over SSH for automated configuration. The management application requires that the router expose a standards-based data model and that configuration changes be applied as complete, atomic transactions. Which action must the engineer take?

A.Configure SNMPv3 with authPriv and use SET operations to push the configuration
B.Enable the NETCONF-YANG feature with the netconf-yang command and use the candidate datastore with the commit operation
C.Enable the guest shell and run Python scripts that call the CLI parser for configuration
D.Enable the RESTCONF API with the ip http secure-server command and use the YANG models exposed there
AnswerB

The netconf-yang command enables NETCONF over SSH on port 830 and activates the Cisco IOS XE YANG data models. Using the candidate datastore allows a client to stage edits and then apply them with a commit, which provides atomic transaction semantics: either all changes apply or none do. This directly satisfies the standards-based model and atomic commit requirements described.

Why this answer

NETCONF over SSH is enabled on Cisco IOS XE with the netconf-yang command, which starts the NETCONF server on TCP 830 and loads the YANG models. The candidate datastore plus commit gives transactional behavior: changes are staged, validated, and applied atomically, with rollback possible on failure. This is the standards-based, model-driven approach the automation application requires.

Exam trap

The trap here is confusing model-driven programmability transports, assuming that enabling RESTCONF or the guest shell provides the same atomic NETCONF transaction behavior over SSH.

31
MCQmedium

A network engineer is implementing VXLAN on a Cisco Nexus 9000 series switch running NX-OS. The underlay network uses OSPF and the loopback0 interface of each VTEP is advertised. The engineer wants to verify that the VXLAN tunnel endpoints can communicate. Which command should be used to check the VXLAN tunnel status?

A.show interface tunnel
B.show vxlan interface
C.show nve peers
D.show ip ospf neighbor
AnswerC

The 'show nve peers' command displays the state of VXLAN tunnel endpoints (VTEPs) and their peer relationships. It shows the IP address of each peer, the VNI, and the state (Up/Down). This directly verifies if VTEPs can communicate over the underlay, which is essential for VXLAN operation.

Why this answer

The 'show nve peers' command is the correct way to verify VXLAN tunnel endpoint communication. It provides details about peer VTEPs, including their IP addresses and state. This command is essential for troubleshooting VXLAN overlay connectivity, as it directly shows whether tunnels are established and operational.

Exam trap

The trap here is assuming that OSPF neighbor adjacency guarantees VXLAN tunnel establishment, but underlay routing and overlay tunnels are separate and must be verified independently.

32
MCQmedium

A network engineer is configuring a new Cisco Catalyst switch that will participate in a VTP domain. The switch must not be able to create, modify, or delete VLANs, but it must synchronize its VLAN database with the current VTP server. Which VTP mode should be configured on this switch?

A.VTP transparent mode
B.VTP off mode
C.VTP server mode
D.VTP client mode
AnswerD

VTP client mode allows the switch to receive and synchronize VLAN information from VTP servers but prevents it from creating, modifying, or deleting VLANs. This exactly matches the requirement: the switch cannot make VLAN changes but will stay synchronized with the VTP server.

Why this answer

VTP client mode is designed for switches that should receive VLAN configuration from VTP servers but not modify it. The switch will synchronize its VLAN database with advertisements from the server, ensuring consistency, while its configuration interface prevents local VLAN creation or deletion. This satisfies both constraints: no VLAN changes and synchronization with the server.

Exam trap

The trap here is confusing VTP transparent mode with client mode, thinking that transparent mode prevents VLAN changes while still synchronizing.

33
MCQhard

A network engineer is implementing VXLAN with a Cisco Nexus 9000 series switch acting as a VTEP. The engineer wants to ensure that the VXLAN traffic is encapsulated and forwarded correctly over the underlay network. Which statement describes the VXLAN encapsulation and forwarding process?

A.VXLAN encapsulates Layer 2 frames in UDP packets with a destination port of 4789, and the VTEP uses the overlay routing table to forward the encapsulated packet to the remote VTEP.
B.VXLAN encapsulates Layer 3 packets in UDP packets with a destination port of 4789, and the VTEP performs a lookup in the underlay routing table to forward the encapsulated packet to the remote VTEP.
C.VXLAN encapsulates Layer 2 frames in GRE tunnels, and the VTEP uses the underlay routing table to forward the encapsulated packet to the remote VTEP.
D.VXLAN encapsulates Layer 2 frames in UDP packets with a destination port of 4789, and the VTEP performs a lookup in the underlay routing table to forward the encapsulated packet to the remote VTEP.
AnswerD

VXLAN uses MAC-in-UDP encapsulation, with the outer UDP destination port typically set to 4789 (IANA-assigned). The VTEP encapsulates the original Layer 2 frame, adds an outer IP header with the source and destination VTEP addresses, and forwards the packet based on the underlay routing table. This allows Layer 2 segments to be stretched over a Layer 3 underlay.

Why this answer

VXLAN encapsulates original Layer 2 frames into UDP packets, with the outer UDP destination port typically 4789. The VTEP adds an outer IP header and forwards the packet based on the underlay network's routing table. This allows the overlay Layer 2 network to span across a Layer 3 underlay.

The encapsulation process preserves the original frame, and the underlay routing ensures the packet reaches the remote VTEP.

Exam trap

The trap here is confusing the overlay and underlay forwarding tables, or assuming VXLAN uses GRE encapsulation instead of UDP.

34
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP server for a subnet that also contains a DHCP relay agent. The router must ensure that DHCP clients receive the correct default gateway address of 10.1.1.1, which is the router's own interface on that subnet. Which command is required to accomplish this?

A.ip dhcp excluded-address 10.1.1.1
B.ip dhcp pool POOL1 followed by default-router 10.1.1.1
C.ip default-gateway 10.1.1.1 in global configuration mode
D.ip helper-address 10.1.1.1 under the router's interface
AnswerB

The default-router command inside the DHCP pool configuration specifies the default gateway address that clients receive. Since the router's interface on the subnet is 10.1.1.1, this command ensures clients are configured with that address as their gateway, which is essential for proper routing.

Why this answer

To provide DHCP clients with a default gateway, the network engineer must configure the default-router command within the DHCP pool. This command specifies the IP address of the gateway that clients will use to reach other networks. The other options are either for different purposes or do not configure the DHCP server to supply gateway information.

Exam trap

The trap here is confusing the ip helper-address command, which is used for DHCP relay, with the default-router command, which sets the gateway for DHCP clients.

35
Multi-Selecthard

A network engineer is configuring VXLAN on a Cisco Nexus switch. The engineer needs to ensure that the VXLAN tunnel endpoint (VTEP) can forward traffic between hosts in the same VXLAN segment across the Layer 3 underlay. Which two statements are true about VXLAN operation? (Choose two.)

Select 2 answers
A.VXLAN tunnel endpoints must be directly connected at Layer 2.
B.VXLAN requires a multicast underlay for all deployments.
C.VXLAN encapsulates original Ethernet frames in UDP.
D.VXLAN uses a 12-bit identifier to maintain compatibility with VLANs.
E.VXLAN uses a 24-bit VNI to identify Layer 2 segments.
AnswersC, E

VXLAN encapsulates original Layer 2 Ethernet frames within UDP packets, typically using UDP port 4789. This allows Layer 2 segments to be extended over a Layer 3 underlay network. The encapsulation includes a VXLAN header with the VNI, and the outer IP header enables routing across the underlay. This is the core mechanism of VXLAN.

Why this answer

VXLAN uses a 24-bit VNI to identify Layer 2 segments, supporting up to 16 million segments, and encapsulates original Ethernet frames in UDP (port 4789) to extend Layer 2 over a Layer 3 underlay. Multicast is not mandatory, and VTEPs do not require Layer 2 adjacency. The 12-bit identifier is for VLANs, not VXLAN.

Exam trap

The trap here is assuming VXLAN requires multicast or Layer 2 adjacency, when it is designed to operate over Layer 3 with unicast or multicast replication.

36
MCQeasy

A network administrator is configuring a Cisco Catalyst switch to assign a voice VLAN to IP phones. The phones will tag voice traffic with VLAN 200, and data traffic from attached PCs should be untagged in VLAN 10. Which interface configuration correctly implements this?

A.Switchport mode trunk, switchport trunk native vlan 10, switchport trunk allowed vlan 200
B.Switchport mode trunk, switchport trunk encapsulation dot1q, switchport trunk native vlan 200
C.Switchport mode access, switchport access vlan 200, switchport voice vlan 10
D.Switchport mode access, switchport access vlan 10, switchport voice vlan 200
AnswerD

This configuration sets the port as an access port for data VLAN 10 and enables voice VLAN 200 for tagged voice traffic. The switchport voice vlan command instructs the switch to use 802.1Q tagging for voice frames while data frames remain untagged. This is the standard Cisco configuration for connecting an IP phone with a PC attached, meeting the requirements.

Why this answer

The correct configuration uses an access port for data VLAN 10 and the switchport voice vlan command for voice VLAN 200. This enables the switch to send CDP/LLDP-MED instructions to the phone to tag voice traffic in VLAN 200 while data remains untagged in VLAN 10. It is the standard Cisco IP telephony deployment.

Exam trap

The trap here is confusing voice VLAN configuration with trunk configuration; voice VLAN is enabled on an access port, not by making the port a trunk.

37
Multi-Selecthard

A network engineer is implementing VXLAN with an EVPN control plane in a data center. The engineer must ensure that the underlay network supports the required traffic and that the overlay provides optimal forwarding. Which two statements are true regarding this implementation? (Choose two.)

Select 2 answers
A.The underlay network must be a Layer 2 network to carry VXLAN traffic.
B.EVPN requires that all VTEPs be in the same subnet.
C.The underlay network must support multicast for BUM traffic replication.
D.EVPN uses MP-BGP to distribute MAC and IP address reachability information.
E.VXLAN with EVPN supports ARP suppression to reduce broadcast traffic.
AnswersD, E

EVPN uses MP-BGP with the EVPN address family to distribute MAC and IP reachability information among VTEPs. This provides a control plane for VXLAN, enabling features like ARP suppression, optimal forwarding, and multi-homing. The BGP EVPN routes include MAC/IP advertisement routes, IMET routes for multicast, and Ethernet segment routes. This is a fundamental aspect of EVPN-based VXLAN.

Why this answer

EVPN uses MP-BGP to distribute MAC and IP reachability, enabling control-plane learning and features like ARP suppression. ARP suppression reduces broadcast traffic by allowing VTEPs to answer ARP requests locally. Multicast is not required in the underlay because EVPN uses ingress replication for BUM traffic.

The underlay must be Layer 3, and VTEPs can be in different subnets as long as they are reachable.

Exam trap

The trap here is assuming that VXLAN always requires multicast in the underlay, but EVPN eliminates that requirement by using BGP and ingress replication.

38
MCQmedium

A network engineer is implementing VXLAN on a Cisco Nexus switch. The engineer wants to ensure that the VXLAN tunnel endpoint (VTEP) can forward traffic between VLANs by mapping them to VNIs. Which component is responsible for the mapping of VLANs to VNIs on the VTEP?

A.The VXLAN Network Identifier (VNI) to VLAN mapping table
B.The MAC address table
C.The ARP table
D.The underlay routing protocol
AnswerA

On a VTEP, the mapping of VLANs to VNIs is configured in the VNI-to-VLAN mapping table. When a frame enters an access port on a VLAN, the VTEP looks up the corresponding VNI and encapsulates the frame with a VXLAN header containing that VNI. This mapping is essential for bridging VLANs across the VXLAN overlay. Thus, this component is responsible for the mapping.

Why this answer

In VXLAN, each VLAN that needs to be extended across the overlay is mapped to a unique VNI. This mapping is configured on the VTEP, typically in a VLAN-to-VNI mapping table. When a frame from a VLAN enters the VTEP, the switch uses this mapping to determine the VNI and encapsulates the frame accordingly.

Therefore, the VNI-to-VLAN mapping table is the component responsible for this function.

Exam trap

The trap here is confusing the MAC address table or ARP table with the VLAN-to-VNI mapping, which is a separate configuration on the VTEP.

39
MCQhard

A company is implementing QoS in a campus network. Voice traffic must be prioritized over data traffic, and all traffic should be marked at Layer 2 and Layer 3. Which combination of marking values should be used on access ports to achieve this?

A.CoS 5, DSCP AF41
B.CoS 5, DSCP CS3
C.CoS 5, DSCP EF
D.CoS 4, DSCP EF
AnswerC

CoS 5 combined with DSCP EF (Expedited Forwarding, DSCP 46) is the industry-standard marking for voice bearer traffic in a campus network. This dual marking ensures that voice frames are placed in the strict-priority queue at both Layer 2 and Layer 3, providing the low latency, low jitter, and minimal packet loss that real-time audio requires. The EF PHB (Per-Hop Behavior) is designed to guarantee a configured bandwidth and queue service, while CoS 5 aligns with the Cisco-recommended voice VLAN and switch port trust settings, making this the only correct answer.

Why this answer

Voice traffic requires strict priority queuing, which is achieved by marking with CoS 5 at Layer 2 and DSCP EF (46) at Layer 3. CoS 5 maps to the priority queue in Cisco switches, and DSCP EF is the standard per-hop behavior for Expedited Forwarding (RFC 3246), ensuring low latency and jitter for voice. Access ports must trust these markings to prioritize voice over data traffic.

Exam trap

The trap here is that candidates confuse CoS 5 with DSCP EF for voice but may pick CoS 4 (used for video) or DSCP AF41 (used for premium data), failing to recognize that voice requires both strict priority marking (CoS 5) and the Expedited Forwarding PHB (DSCP EF) to guarantee low-latency treatment.

How to eliminate wrong answers

Option A is wrong because DSCP AF41 (Assured Forwarding 4, low drop) is designed for premium data traffic, not real-time voice; it does not provide strict priority queuing and can be subject to congestion management. Option B is wrong because DSCP CS3 (Class Selector 3) is typically used for broadcast video or signaling, not voice; it lacks the strict priority treatment required for real-time audio. Option D is wrong because CoS 4 is used for video conferencing (e.g., CoS 4, DSCP AF41) or streaming video, not voice; voice requires CoS 5 to map to the priority queue, and using CoS 4 would place voice in a lower-priority queue.

40
MCQmedium

An engineer is configuring a new switch stack using Cisco StackWise technology. The stack must be resilient to the failure of the active switch, and the engineer wants to ensure that the standby switch takes over with minimal disruption. The engineer has four switches in the stack. Which statement describes the role of the standby switch in a StackWise stack?

A.The standby switch is responsible for managing the stack and is the primary switch for forwarding traffic.
B.The standby switch is elected based on the highest priority value, and it only becomes active if the current active switch fails.
C.The standby switch actively forwards traffic and maintains a synchronized copy of the active switch's configuration and state.
D.The standby switch takes over as the active switch if the active switch fails, and it is kept synchronized with the active switch's configuration and state.
AnswerD

In a StackWise stack, the standby switch is a hot-standby that continuously synchronizes its configuration and state with the active switch. If the active switch fails, the standby switch quickly becomes the new active switch, minimizing disruption. This is the correct description of the standby switch's role, ensuring high availability and rapid failover.

Why this answer

The standby switch in a StackWise stack is a hot-standby that maintains a synchronized copy of the active switch's configuration and state. Upon failure of the active switch, the standby switch assumes the active role, providing redundancy and minimal downtime. This mechanism is critical for stack resilience, allowing the stack to continue operating seamlessly.

Exam trap

The trap here is assuming that the standby switch forwards traffic or participates in management, when in fact it remains in a passive hot-standby state until a failover occurs.

41
MCQhard

A network engineer is configuring OSPF on a Cisco router. The router is connected to a broadcast network with multiple OSPF neighbors. The engineer wants to ensure that this router does not become the Designated Router (DR) or Backup Designated Router (BDR) on this network. Which configuration achieves this goal?

A.Set the OSPF priority to 0 on the interface.
B.Set the OSPF network type to point-to-point.
C.Configure the interface as passive.
D.Configure the router as a stub router.
AnswerA

Setting the OSPF priority to 0 on an interface prevents that router from being elected as DR or BDR. The priority value is used in the DR election process; routers with priority 0 are ineligible. This is the correct method to ensure the router does not become DR or BDR while still participating in OSPF on that network.

Why this answer

The OSPF priority is an 8-bit field in the Hello packet used in DR/BDR election. A router with priority 0 is never elected as DR or BDR. Setting the interface priority to 0 achieves the goal while allowing the router to remain a DROTHER and fully participate in OSPF.

Other methods like changing network type or making the interface passive have side effects that are not desired.

Exam trap

The trap here is confusing DR election manipulation with other OSPF features like stub routing or passive interfaces, which have different purposes.

42
MCQmedium

A network engineer is deploying a new branch office with a single Cisco Catalyst switch that will connect to the corporate network via a routed uplink. The switch must be able to forward traffic for VLANs 10, 20, and 30 over that single uplink to a router. The router interface is configured with subinterfaces and dot1Q encapsulation. Which switchport configuration should be applied to the uplink port?

A.switchport mode access switchport access vlan 10
B.switchport mode dynamic desirable switchport trunk allowed vlan 10,20,30
C.switchport mode trunk switchport trunk encapsulation dot1q switchport trunk allowed vlan 10,20,30
D.switchport mode trunk switchport trunk native vlan 10 switchport trunk allowed vlan 20,30
AnswerC

A trunk port with 802.1Q encapsulation carries multiple VLANs over one physical link, tagging frames with the appropriate VLAN ID. Restricting allowed VLANs to 10, 20, and 30 matches the router's subinterfaces and prevents unnecessary broadcast flooding. This is the standard router-on-a-stick configuration and satisfies the multi-VLAN uplink requirement.

Why this answer

The uplink must be a trunk to carry multiple VLANs to the router's subinterfaces. Configuring the port as a static trunk with 802.1Q encapsulation and limiting allowed VLANs to the ones in use ensures tagged frames reach the correct router subinterfaces. Dynamic trunking or access mode would not reliably support multiple VLANs over a single physical link.

Exam trap

The trap here is assuming that a trunk port must be configured with dynamic desirable to form a trunk with a router, when routers do not typically participate in DTP and require a static trunk configuration.

43
MCQeasy

A network administrator is configuring a new Cisco IOS switch. The administrator needs to assign switch port GigabitEthernet0/1 to VLAN 20 and ensure that the port is in access mode. Which command sequence is correct?

A.interface GigabitEthernet0/1; switchport mode access; switchport access vlan 20
B.interface GigabitEthernet0/1; switchport mode trunk; switchport trunk allowed vlan 20
C.interface GigabitEthernet0/1; switchport mode dynamic auto; switchport access vlan 20
D.interface GigabitEthernet0/1; switchport access vlan 20; switchport mode access
AnswerA

This sequence enters interface configuration mode, sets the port to access mode, and assigns it to VLAN 20. The 'switchport mode access' command forces the port to operate as an access port, and 'switchport access vlan 20' associates it with VLAN 20. This is the standard method to configure an access port on a Cisco switch.

Why this answer

To assign a switch port to a VLAN and set it as an access port, the correct commands are 'switchport mode access' followed by 'switchport access vlan 20'. This ensures the port operates in access mode and carries traffic for VLAN 20. The other options either configure trunking or dynamic negotiation, which do not meet the access mode requirement.

Exam trap

The trap here is thinking that assigning a VLAN automatically sets the port to access mode, or confusing access and trunk configuration commands.

44
Multi-Selecthard

A network engineer is deploying a new Cisco SD-Access fabric. The design includes underlay and overlay networks. Which two statements accurately describe the underlay network in a Cisco SD-Access fabric? (Choose two.)

Select 2 answers
A.The underlay encapsulates user traffic in VXLAN to provide overlay connectivity.
B.The underlay provides a loop-free topology using a routing protocol and does not rely on Spanning Tree Protocol.
C.The underlay is responsible for mapping endpoint IP addresses to fabric locators (RLOCs).
D.The underlay uses a static routing protocol to simplify configuration and reduce overhead.
E.The underlay uses a routing protocol such as IS-IS or OSPF to provide reachability between fabric nodes.
AnswersB, E

The underlay is typically a Layer 3 routed network that uses a routing protocol to ensure loop-free paths. It does not rely on Spanning Tree Protocol, which is a Layer 2 loop prevention mechanism. This is a correct characteristic of the SD-Access underlay.

Why this answer

In Cisco SD-Access, the underlay provides IP reachability between fabric nodes using a routing protocol such as IS-IS or OSPF, and it is a loop-free Layer 3 network that does not rely on Spanning Tree Protocol. VXLAN encapsulation and LISP mapping are overlay functions. Static routing is not the typical underlay approach.

Exam trap

The trap here is confusing underlay and overlay responsibilities; VXLAN encapsulation and LISP mapping are overlay functions, not underlay.

45
MCQeasy

A network administrator is configuring a Cisco IOS router to act as a DHCP server for the 10.10.10.0/24 subnet. The router interface GigabitEthernet0/0 is configured with IP address 10.10.10.1/24. Which command is required to specify the DNS server address that will be provided to DHCP clients?

A.domain-name-server 8.8.8.8
B.dns-server 8.8.8.8
C.ip name-server 8.8.8.8
D.ip dhcp dns 8.8.8.8
AnswerB

Within the DHCP pool configuration mode, the 'dns-server' command specifies the DNS server IP address that DHCP clients will receive. This is the correct command to provide DNS information to clients. It is configured under 'ip dhcp pool' and can list multiple DNS servers. This ensures clients can resolve domain names. The command is essential for proper network operation when DHCP is used for address assignment.

Why this answer

The correct command to specify DNS servers for DHCP clients is 'dns-server' within the DHCP pool configuration mode. This command directly populates the DNS option in DHCP offers. The other options are either global router DNS settings or invalid commands.

Proper configuration ensures that clients receive the necessary DNS information to resolve hostnames, which is critical for network functionality.

Exam trap

The trap here is confusing the router's own DNS configuration ('ip name-server') with the DHCP pool option ('dns-server') that is sent to clients.

46
MCQhard

A network engineer is configuring QoS on a Cisco IOS router. The engineer needs to ensure that packets marked with DSCP AF31 are placed into a queue that guarantees at least 30% of the interface bandwidth during congestion, while allowing other traffic to use any remaining bandwidth. Which configuration should be used?

A.policy-map QOS class AF31 shape average percent 30
B.policy-map QOS class AF31 bandwidth remaining percent 30
C.policy-map QOS class AF31 bandwidth percent 30
D.policy-map QOS class AF31 priority percent 30
AnswerC

The 'bandwidth percent 30' command guarantees that the class AF31 receives at least 30% of the interface bandwidth during congestion. This is a CBWFQ configuration that provides a minimum bandwidth guarantee, ensuring that AF31 traffic is prioritized while allowing other classes to use the remaining bandwidth. It directly satisfies the requirement.

Why this answer

The 'bandwidth percent 30' command in a policy map class guarantees that the class receives at least 30% of the interface bandwidth during congestion. This is part of CBWFQ and provides a minimum bandwidth guarantee, meeting the requirement while allowing other traffic to utilize remaining bandwidth.

Exam trap

The trap here is confusing bandwidth guarantee commands like 'bandwidth percent' with priority or shaping commands that limit or prioritize traffic differently.

47
MCQmedium

A network engineer is configuring VXLAN on a Cisco Nexus 9000 series switch. The underlay network is a routed Layer 3 network using OSPF. The engineer needs to ensure that the VXLAN tunnel endpoint (VTEP) IP addresses are reachable across the underlay. Which statement describes the correct configuration for the VTEP source interface?

A.The VTEP source interface must be a VLAN interface (SVI) on the switch, and the VLAN must be allowed on all trunk links.
B.The VTEP source interface must be a loopback interface with an IP address advertised into the underlay routing protocol.
C.The VTEP source interface must be a subinterface configured with 802.1Q encapsulation.
D.The VTEP source interface must be a physical interface that is directly connected to the underlay network.
AnswerB

Using a loopback interface as the VTEP source ensures high availability because it remains up as long as any path to the underlay exists. Advertising the loopback IP into OSPF makes it reachable by remote VTEPs, enabling VXLAN tunnels to form. This is the recommended design for VXLAN in Cisco Nexus environments.

Why this answer

For VXLAN, the VTEP source interface should be a loopback interface with an IP address advertised into the underlay routing protocol. This ensures that the VTEP IP remains reachable even if a physical link fails, providing redundancy. The underlay network must route the loopback IP so that remote VTEPs can establish VXLAN tunnels.

Exam trap

The trap here is assuming that any interface with an IP address can serve as the VTEP source, but the best practice is to use a loopback for stability and redundancy.

48
Multi-Selecthard

A network engineer is implementing VXLAN with Cisco SD-Access. The engineer must ensure that the underlay network provides the necessary transport for VXLAN traffic. Which two statements about VXLAN and its underlay are true? (Choose two.)

Select 2 answers
A.VXLAN uses a 24-bit VNID, allowing over 16 million unique segments.
B.VXLAN tunnels are established between VTEPs, which can be physical or virtual switches.
C.VXLAN requires the underlay to be a Layer 2 network with STP.
D.VXLAN uses a 12-bit VNID, similar to VLAN IDs.
E.VXLAN requires a multicast-enabled underlay for BUM traffic replication.
AnswersA, B

VXLAN encapsulates Layer 2 frames in UDP and uses a 24-bit VXLAN Network Identifier (VNID), which provides up to 16,777,216 unique segments. This scalability is a key advantage over VLANs, which are limited to 4094. The large VNID space supports multi-tenant data centers and large-scale segmentation in SD-Access.

Why this answer

VXLAN uses a 24-bit VNID for large-scale segmentation and relies on VTEPs to encapsulate traffic. The underlay is typically Layer 3, not Layer 2, and BUM traffic can be handled via multicast or unicast control-plane replication. The two correct statements are the 24-bit VNID and the role of VTEPs.

Exam trap

The trap here is assuming VXLAN requires multicast or a Layer 2 underlay, when in fact modern implementations use unicast replication over a Layer 3 underlay.

49
Multi-Selectmedium

A company has a requirement to provide redundancy for the default gateway on a subnet. Two switches are configured with HSRP. Which requirement must be met for the interfaces on the switches to form the HSRP group?

Select 1 answer
A.The interfaces must be on the same physical switch.
B.The interfaces must be Layer 2 switchports.
C.The interfaces must have the same IP address.
D.The interfaces must be in the same VLAN.
AnswersD

HSRP requires all participants to be in the same Layer 2 broadcast domain because hello messages are multicast onto the local VLAN. The multicast destination is 224.0.0.2 (HSRPv1) or 224.0.0.102 (HSRPv2) with a TTL of 1; if the interfaces reside in different VLANs, the broadcast domains are isolated, so the hellos never reach the peer and no HSRP adjacency forms. The virtual IP must also belong to the same IP subnet as the real interface IPs, and that subnet maps to exactly one VLAN; different VLANs imply different subnets and break the redundant gateway function.

Why this answer

HSRP is a First Hop Redundancy Protocol that provides a virtual gateway for hosts. To form an HSRP group, the participating interfaces must be Layer 3 interfaces (either SVIs on switches or routed ports on multilayer switches) that are configured with IP addresses and belong to the same VLAN. Option B is incorrect because HSRP does not run on Layer 2 switchports; those ports do not have IP addresses and cannot send HSRP messages.

Option D is correct because being in the same VLAN ensures the switches share the same broadcast domain, allowing HSRP multicast hello messages to reach each other.

Exam trap

A common misconception is that HSRP interfaces must be Layer 2 switchports. In reality, HSRP requires Layer 3 interfaces (SVIs or routed ports) that are in the same VLAN to exchange multicast hellos and maintain the virtual IP and MAC address.

50
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP server for a subnet. The engineer wants to exclude a range of addresses from being assigned dynamically. Which command should be used?

A.ip dhcp pool
B.ip dhcp snooping
C.ip dhcp excluded-address
D.ip dhcp relay information
AnswerC

The 'ip dhcp excluded-address' command is used to specify a range of IP addresses that the DHCP server should not assign to clients. This is typically used for addresses that are statically assigned to servers, printers, or other network devices. It ensures that the DHCP server does not hand out these addresses, preventing conflicts.

Why this answer

The 'ip dhcp excluded-address' command is specifically designed to prevent the DHCP server from assigning certain IP addresses. The other commands serve different purposes: creating a pool, enabling snooping, or configuring relay information. Thus, 'ip dhcp excluded-address' is the correct choice.

Exam trap

The trap here is confusing the DHCP pool configuration with address exclusion, when exclusion is configured globally, not within the pool.

51
MCQeasy

A network administrator is configuring a switch port to support a VoIP phone and a PC connected to the phone's internal switch. The phone must be placed in VLAN 50 and the PC in VLAN 60. Which configuration on the switch port achieves this?

A.switchport mode access switchport access vlan 50 switchport trunk allowed vlan 60
B.switchport mode access switchport access vlan 50 switchport voice vlan 60
C.switchport mode access switchport access vlan 60 switchport voice vlan 50
D.switchport mode trunk switchport trunk native vlan 60 switchport trunk allowed vlan 50
AnswerC

This configuration sets the access VLAN to 60 for the PC and the voice VLAN to 50 for the phone. The phone will use VLAN 50 for voice traffic and pass untagged PC traffic to VLAN 60. This is the standard Cisco configuration for a phone with a PC attached.

Why this answer

The correct configuration uses access VLAN 60 for the PC and voice VLAN 50 for the phone. Cisco voice VLAN allows the switch to instruct the phone to use a specific VLAN for voice traffic while the PC remains on the access VLAN. This provides proper segmentation and QoS for voice.

Exam trap

The trap here is confusing the access VLAN and voice VLAN assignments, or using trunk mode instead of the dedicated voice VLAN feature.

52
MCQhard

A network engineer is implementing VXLAN with an EVPN control plane. The underlay is a routed Layer 3 network. Which statement describes the role of the VXLAN Tunnel Endpoint (VTEP)?

A.The VTEP acts as a Layer 3 gateway for inter-subnet routing.
B.The VTEP is responsible for advertising MAC addresses to the EVPN control plane.
C.The VTEP maps VLAN IDs to VXLAN Network Identifiers (VNIs).
D.The VTEP encapsulates Layer 2 frames into VXLAN packets and forwards them over the IP underlay.
AnswerD

The VTEP is responsible for encapsulating original Layer 2 frames into VXLAN UDP packets, adding a VXLAN header, and forwarding them across the IP underlay network. It also decapsulates received VXLAN packets, making it the core component for overlay connectivity.

Why this answer

The VTEP encapsulates Layer 2 frames into VXLAN packets and forwards them over the IP underlay. It is the device that provides the overlay encapsulation and decapsulation, enabling Layer 2 connectivity across a Layer 3 network.

Exam trap

The trap here is confusing the VTEP's data plane encapsulation role with control plane functions like MAC address advertisement or additional features like inter-subnet routing.

53
MCQeasy

A network administrator is configuring a Cisco switch to support a new wireless LAN controller (WLC) that requires the switch port to carry traffic for multiple VLANs. The WLC will be connected to a trunk port. Which command must be used to configure the switch port as a trunk?

A.switchport nonegotiate
B.switchport mode trunk
C.switchport trunk encapsulation dot1q
D.switchport mode access
AnswerB

The command 'switchport mode trunk' configures the interface to operate as a trunk, allowing it to carry traffic for multiple VLANs. This is necessary for connecting a WLC that needs to support multiple VLANs. It is the standard command to set a port to trunk mode on Cisco switches, enabling 802.1Q encapsulation.

Why this answer

To configure a switch port as a trunk, the command 'switchport mode trunk' must be used. This enables the port to carry traffic for multiple VLANs using 802.1Q encapsulation. While other commands like 'switchport trunk encapsulation dot1q' may be required on some platforms, the essential command to set the mode is 'switchport mode trunk'.

This is a fundamental configuration for connecting devices that need multiple VLANs, such as a WLC.

Exam trap

The trap here is confusing the command that sets the encapsulation with the command that actually enables trunking mode, or thinking that disabling DTP is sufficient.

54
MCQmedium

A network engineer is deploying a new branch office that uses Cisco SD-Access. The fabric must support both wired and wireless clients, with a single control plane that provides host tracking, location, and policy enforcement. Which fabric component is responsible for these functions?

A.Cisco Identity Services Engine (ISE)
B.Fabric control plane node
C.Fabric edge node
D.Cisco DNA Center
AnswerB

In Cisco SD-Access, the fabric control plane node runs the LISP map-server and map-resolver functions, maintaining the endpoint identifier (EID) to routing locator (RLOC) mappings for all fabric endpoints. This provides host tracking, location, and a unified control plane for both wired and wireless clients. The control plane node is essential for scalable fabric operations and policy enforcement through group-based policies.

Why this answer

The fabric control plane node in Cisco SD-Access runs LISP map-server and map-resolver, providing a centralized database for endpoint-to-RLOC mappings. This enables host tracking, location services, and a single control plane for both wired and wireless clients. DNA Center and ISE are supporting components for management and policy, but they do not provide the runtime control-plane functions described in the scenario.

Exam trap

The trap here is assuming that DNA Center or ISE provides the fabric control plane, when in fact they are management and policy components that rely on the control plane node for endpoint tracking.

55
MCQeasy

A network engineer is configuring a Cisco IOS router to support NAT for a small office. The inside network uses the 192.168.1.0/24 subnet, and the outside interface is GigabitEthernet0/0 with IP address 203.0.113.5. The engineer wants to translate all inside addresses to the outside interface address. Which command is required to define the NAT source list?

A.ip nat pool POOL 203.0.113.5 203.0.113.5 netmask 255.255.255.0
B.ip nat inside source list 1 interface GigabitEthernet0/0 overload
C.access-list 1 permit 192.168.1.0 0.0.0.255
D.ip nat inside source static 192.168.1.1 203.0.113.5
AnswerC

This access list defines the inside local addresses that will be translated. The wildcard mask 0.0.0.255 matches the entire 192.168.1.0/24 subnet. The access list is then referenced in the ip nat inside source list command to specify which traffic should be translated.

Why this answer

To define the NAT source list, an access list must be created that matches the inside local addresses. The command access-list 1 permit 192.168.1.0 0.0.0.255 accomplishes this by permitting the entire 192.168.1.0/24 subnet. This list is then referenced in the ip nat inside source list command to enable translation.

Exam trap

The trap here is confusing the access list that defines the source addresses with the NAT translation command that references it, leading to selecting the latter as the answer.

56
MCQhard

A network engineer is configuring QoS on a Cisco IOS XE router. The router must mark all ingress traffic from a specific subnet with DSCP AF31 and ensure that this marking is trusted throughout the network. Which configuration step is required to achieve this?

A.Apply a policy map that sets DSCP AF31 as an output service policy on the router's uplink interface.
B.Create a class map matching the subnet, then a policy map that sets DSCP AF31, and apply it as a service policy on the ingress interface.
C.Configure 'mls qos trust dscp' on the ingress interface and rely on the subnet's existing markings.
D.Use a route map to set DSCP AF31 for all routes matching the subnet and redistribute into OSPF.
AnswerB

To mark traffic from a subnet, you must classify it with a class map, define the marking action in a policy map using 'set dscp af31', and attach the policy to the ingress interface with 'service-policy input'. This ensures packets are marked at ingress, and subsequent devices can trust the DSCP if configured to do so.

Why this answer

To mark traffic from a specific subnet with DSCP AF31, you need a class map to identify the traffic, a policy map to set the DSCP, and the policy applied as an ingress service policy. This ensures packets are marked before any queuing or forwarding decisions, allowing downstream devices to trust and act on the marking.

Exam trap

The trap here is confusing QoS marking with trusting markings; trusting DSCP only preserves existing values and does not mark unmarked traffic.

57
MCQeasy

A network administrator is configuring a Cisco IOS router to use VRRP. The router should be the master for the virtual IP 192.168.1.1 on interface GigabitEthernet0/0. The administrator wants to ensure that if this router fails, another router takes over with minimal delay. Which command should be used to set the priority to 150?

A.vrrp 1 priority 150 preempt
B.vrrp 1 preempt priority 150
C.standby 1 priority 150
D.vrrp 1 priority 150
AnswerD

The command vrrp 1 priority 150 sets the VRRP priority to 150 for group 1 on the interface. A higher priority makes the router more likely to become the master. The default priority is 100, and the range is 1–254. Priority 150 is higher than default, so this router will become master if it is the highest priority in the group. This command is entered in interface configuration mode.

Why this answer

The command vrrp 1 priority 150 correctly sets the VRRP priority to 150 for group 1. A higher priority increases the chance of becoming the master. The default priority is 100, and the range is 1–254.

Preemption is enabled by default, so no additional command is needed. This ensures the router becomes master and takes over quickly if needed.

Exam trap

The trap here is mixing up VRRP and HSRP commands; the standby command is for HSRP, while VRRP uses the vrrp command.

58
MCQmedium

An engineer is configuring a Cisco Catalyst switch with VXLAN to extend Layer 2 connectivity between two data centers. The switch will act as a VXLAN Tunnel Endpoint (VTEP) and must encapsulate traffic from VLAN 10 into VXLAN VNI 10010. Which command is required to map the VLAN to the VNI?

A.vxlan vlan 10 vni 10010
B.interface vlan 10: vxlan vni 10010
C.vlan configuration 10: vn-segment 10010
D.vxlan vni 10010 vlan 10
AnswerC

This is the correct command to map a VLAN to a VXLAN VNI on a Cisco Catalyst switch. Under 'vlan configuration 10', the 'vn-segment 10010' command associates VLAN 10 with VNI 10010. This enables the VTEP to encapsulate frames from VLAN 10 into VXLAN packets with VNI 10010, allowing Layer 2 extension across the IP network.

Why this answer

To map a VLAN to a VXLAN VNI on a Cisco Catalyst switch, the engineer must enter VLAN configuration mode for the specific VLAN and use the 'vn-segment' command. This creates the association that allows the VTEP to encapsulate traffic from that VLAN into VXLAN packets with the specified VNI. Other command forms are invalid or apply to different platforms.

Exam trap

The trap here is confusing the SVI configuration with VXLAN VLAN-to-VNI mapping, or using syntax from other vendors or platforms.

59
MCQmedium

A network engineer is configuring OSPF on a multiaccess network. The engineer wants to ensure that only two specific routers become DR and BDR, and that other routers do not participate in the election. Which OSPF interface setting should be configured on the routers that should not become DR or BDR?

A.ip ospf database-filter all out
B.ip ospf network point-to-point
C.ip ospf priority 1
D.ip ospf priority 0
AnswerD

Setting the OSPF priority to 0 on an interface makes that router ineligible to become DR or BDR. This is the correct way to prevent a router from participating in the DR/BDR election. The router will still form adjacencies and exchange routing information, but it will remain a DROTHER. This setting is commonly used on routers that should not be DR/BDR, such as those with lower processing power or at the edge of the network.

Why this answer

Setting OSPF priority to 0 on an interface makes the router ineligible to become DR or BDR. This is the standard method to exclude routers from the election while still allowing them to participate in OSPF as DROTHERs. Other options either do not affect eligibility or change the network type entirely.

Exam trap

The trap here is thinking that any priority value other than 0 can exclude a router, when only 0 makes it ineligible.

60
MCQhard

A network engineer is implementing QoS on a Cisco IOS router. The engineer wants to ensure that VoIP traffic is marked with DSCP EF and that the router prioritizes this traffic during congestion. Which mechanism should be used to provide priority queuing for VoIP?

A.Class-Based Weighted Fair Queuing (CBWFQ)
B.Weighted Random Early Detection (WRED)
C.Traffic Shaping
D.Low Latency Queuing (LLQ)
AnswerD

LLQ combines CBWFQ with a strict priority queue. It allows VoIP traffic to be placed in a priority queue that is serviced before other queues, ensuring minimal delay and jitter. LLQ is the recommended mechanism for prioritizing real-time traffic like VoIP during congestion.

Why this answer

LLQ is the QoS mechanism that provides strict priority queuing, ensuring that VoIP traffic marked with DSCP EF is serviced before other traffic during congestion. This minimizes latency and jitter, which are critical for voice quality. LLQ is configured using the 'priority' command within a policy map.

Exam trap

The trap here is assuming that CBWFQ alone can provide priority, when it only guarantees bandwidth without strict priority.

61
MCQhard

A network engineer is implementing VXLAN with BGP EVPN on Cisco Nexus switches. The underlay network is OSPF, and the overlay uses MP-BGP EVPN. The engineer wants to ensure that the VXLAN tunnel endpoints (VTEPs) can discover each other and exchange MAC and IP address information. Which statement correctly describes the role of the BGP EVPN address family in this scenario?

A.It provides a routing underlay for the VXLAN tunnels by advertising VTEP loopback addresses.
B.It synchronizes the MAC address tables of all VTEPs by flooding unknown unicast traffic.
C.It encapsulates the original Ethernet frames into VXLAN packets and forwards them across the underlay.
D.It distributes MAC and IP address reachability information for hosts and enables VTEP peer discovery.
AnswerD

The BGP EVPN address family carries MAC and IP address reachability information in the form of EVPN routes, such as Type 2 and Type 5 routes. This allows VTEPs to learn about remote hosts and VTEPs, facilitating the creation of VXLAN tunnels and enabling efficient forwarding without flooding.

Why this answer

The BGP EVPN address family is used to distribute MAC and IP address reachability information across VTEPs. This enables control plane learning, reducing flooding and allowing VTEPs to discover remote hosts and VTEPs. The other options incorrectly attribute underlay routing, data plane encapsulation, or flooding-based learning to BGP EVPN.

Exam trap

The trap here is assuming that BGP EVPN handles encapsulation or underlay routing, when it is actually an overlay control plane protocol for distributing host reachability.

62
MCQmedium

A network engineer is configuring a pair of Catalyst switches to run VRRP on VLAN 10 (10.10.10.0/24). The virtual IP must be 10.10.10.1 with a priority of 110 on the primary switch and 100 on the standby. The primary switch is currently active. Which configuration on the primary switch correctly sets the VRRP priority and virtual IP?

A.interface vlan 10 ip address 10.10.10.2 255.255.255.0 vrrp 10 ip 10.10.10.1 vrrp 10 priority 110
B.interface vlan 10 ip address 10.10.10.2 255.255.255.0 vrrp 10 ip 10.10.10.1 255.255.255.0 vrrp 10 priority 110
C.interface vlan 10 ip address 10.10.10.2 255.255.255.0 vrrp 10 ip 10.10.10.1 vrrp 10 priority 100
D.interface vlan 10 ip address 10.10.10.2 255.255.255.0 vrrp 10 virtual-ip 10.10.10.1 vrrp 10 priority 110
AnswerA

This configuration enters VLAN 10 SVI, assigns the physical IP 10.10.10.2, then enables VRRP group 10 with virtual IP 10.10.10.1 and priority 110. In VRRP, the highest priority becomes the master; 110 exceeds the default 100, making this switch the master. The syntax matches Cisco IOS VRRP commands exactly.

Why this answer

VRRP on Cisco IOS uses the `vrrp <group> ip <address>` command to define the virtual IP, and `vrrp <group> priority <value>` to set priority. The highest priority becomes the master. The correct configuration assigns the physical IP, defines the virtual IP 10.10.10.1, and sets priority 110, ensuring this switch becomes the master.

Other options contain invalid syntax or set the wrong priority.

Exam trap

The trap here is confusing VRRP command syntax with HSRP, such as using `virtual-ip` or including a subnet mask, which are not valid for VRRP.

63
MCQmedium

A network engineer is deploying Cisco SD-Access and wants to ensure that traffic from employee endpoints is tunneled to a fabric border node for external connectivity. Which component is responsible for encapsulating endpoint traffic into VXLAN and forwarding it to the border?

A.Fabric edge node
B.Fabric border node
C.Fabric intermediate node
D.Fabric control plane node
AnswerA

Fabric edge nodes are responsible for encapsulating endpoint traffic into VXLAN and forwarding it to the border. They act as VTEPs, mapping endpoint IP addresses to fabric locators and tunneling traffic across the underlay. This design provides policy enforcement and segmentation, ensuring that employee traffic destined for external networks is properly encapsulated and sent to the border for routing.

Why this answer

Fabric edge nodes are the VTEPs that encapsulate endpoint traffic into VXLAN and forward it toward the border for external connectivity. They handle the mapping and tunneling of endpoint traffic, ensuring that employee endpoints can reach external networks through the fabric border. Control plane nodes manage mapping, border nodes decapsulate, and intermediate nodes only forward encapsulated packets.

Exam trap

The trap here is assuming that the border node encapsulates traffic, when in fact it decapsulates traffic leaving the fabric and edge nodes perform encapsulation.

64
MCQeasy

A network administrator is configuring a Cisco Catalyst switch and needs to assign a port to VLAN 20 as an access port. The port is currently in VLAN 1. Which command sequence correctly configures the interface?

A.interface GigabitEthernet0/1, then switchport access vlan 20, then switchport mode access
B.interface GigabitEthernet0/1, then switchport trunk allowed vlan 20, then switchport mode trunk
C.interface GigabitEthernet0/1, then switchport mode dynamic auto, then switchport access vlan 20
D.interface GigabitEthernet0/1, then switchport mode access, then switchport access vlan 20
AnswerD

This sequence enters interface configuration mode, sets the port to access mode, and assigns VLAN 20. It is the correct and standard method to configure an access port on a Cisco Catalyst switch. The port will carry untagged traffic for VLAN 20, and any existing VLAN 1 assignment is overridden.

Why this answer

To configure a switch port as an access port in VLAN 20, you enter interface configuration mode, set the mode to access with switchport mode access, and then assign the VLAN with switchport access vlan 20. This ensures the port operates as a static access port and carries untagged traffic for VLAN 20.

Exam trap

The trap here is confusing access and trunk configuration, or using the wrong order of commands that might leave the port in a dynamic state.

65
MCQhard

A network administrator is configuring a Cisco IOS router to authenticate OSPF neighbors using MD5. The router must use key 1 with the password 'Cisco123' on interface GigabitEthernet0/0. Which configuration is correct?

A.interface GigabitEthernet0/0 ip ospf authentication-key Cisco123 ip ospf authentication
B.router ospf 1 area 0 authentication message-digest ip ospf message-digest-key 1 md5 Cisco123
C.interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 Cisco123
D.router ospf 1 authentication message-digest message-digest-key 1 md5 Cisco123
AnswerC

This configuration enables OSPF MD5 authentication on the interface and defines the key with ID 1 and password 'Cisco123'. The 'ip ospf authentication message-digest' command activates MD5 authentication for OSPF on that interface, and the 'ip ospf message-digest-key' command specifies the key. This is the correct method to configure MD5 authentication on a per-interface basis in Cisco IOS.

Why this answer

To enable OSPF MD5 authentication on a specific interface, you must enter interface configuration mode, enable MD5 authentication with 'ip ospf authentication message-digest', and define the key with 'ip ospf message-digest-key 1 md5 Cisco123'. This ensures that OSPF packets on that interface are authenticated using MD5, meeting the security requirement.

Exam trap

The trap here is confusing area-wide authentication with interface-level key configuration, leading to placing the key under the OSPF process instead of the interface.

66
Multi-Selectmedium

A network engineer is implementing VXLAN on Cisco Nexus 9000 switches. The engineer needs to verify the configuration of the VXLAN data plane. Which two statements are true regarding VXLAN operation? (Choose two.)

Select 2 answers
A.VXLAN requires the underlay network to run OSPF for route distribution.
B.VXLAN encapsulates original Ethernet frames in UDP packets with destination port 4789.
C.VXLAN tunnels are established between VTEPs using a control protocol such as LISP.
D.VXLAN uses a 12-bit VLAN ID to identify the overlay network.
E.VXLAN uses a 24-bit VN-Segment ID (VNI) to identify the overlay network.
AnswersB, E

VXLAN encapsulates Layer 2 frames into UDP packets. The standard destination UDP port is 4789, as assigned by IANA. This encapsulation allows Layer 2 segments to be stretched over a Layer 3 network. The source port is dynamically chosen to provide entropy for ECMP hashing.

Why this answer

VXLAN uses a 24-bit VNI to identify overlay segments, enabling massive scalability. It encapsulates original Ethernet frames in UDP packets with destination port 4789. These two facts are fundamental to VXLAN operation and are correct.

The other statements are false: VXLAN does not require OSPF, does not use a 12-bit VLAN ID, and does not inherently use LISP for tunnel establishment.

Exam trap

The trap here is assuming VXLAN uses a 12-bit VLAN ID or requires a specific routing protocol like OSPF in the underlay, but VXLAN's scalability comes from the 24-bit VNI and underlay-agnostic design.

67
MCQhard

A network administrator is configuring a Cisco IOS router to authenticate management users against a TACACS+ server. The administrator wants to ensure that if the TACACS+ server becomes unreachable, a local username and password can still be used to log in. Which configuration accomplishes this requirement?

A.aaa authentication login default local group tacacs+
B.aaa authentication login default group tacacs+ local
C.aaa authentication login default group tacacs+ none
D.aaa authentication login default group tacacs+ enable
AnswerB

This command configures AAA authentication for login using TACACS+ first, then falls back to the local database if the TACACS+ server is unreachable. The 'local' keyword ensures that local authentication is attempted only if the TACACS+ servers do not respond, providing a failover mechanism for management access.

Why this answer

The correct method list must list 'group tacacs+' before 'local' so that TACACS+ is tried first, and local is used only if the server is unreachable. The 'local' keyword ensures that the local username database is used as a fallback. Other keywords like 'enable' or 'none' do not provide the required local username and password fallback.

Exam trap

The trap here is confusing the order of authentication methods; the first method is primary, and subsequent methods are fallbacks. Placing 'local' first would make it primary, which is not desired.

68
MCQmedium

A network engineer is configuring a new Cisco IOS router and wants to ensure that OSPFv2 adjacencies form only on the interface that connects to the trusted internal network. The router has three interfaces: GigabitEthernet0/0 (internal), GigabitEthernet0/1 (DMZ), and GigabitEthernet0/2 (Internet). The engineer enables OSPF process 1 and wants to advertise the internal network 10.1.1.0/24 while preventing OSPF from sending or receiving hello packets on the other interfaces. Which configuration accomplishes this goal?

A.router ospf 1 network 10.1.1.0 0.0.0.255 area 0 passive-interface default no passive-interface GigabitEthernet0/0
B.router ospf 1 network 10.1.1.0 0.0.0.255 area 0 passive-interface GigabitEthernet0/1 passive-interface GigabitEthernet0/2
C.router ospf 1 network 10.1.1.0 0.0.0.255 area 0 ip ospf passive-interface GigabitEthernet0/1 ip ospf passive-interface GigabitEthernet0/2
D.router ospf 1 network 10.1.1.0 0.0.0.255 area 0 passive-interface GigabitEthernet0/0
AnswerA

This configuration enables OSPF on the router, advertises the internal subnet, and sets all interfaces to passive by default. The 'no passive-interface GigabitEthernet0/0' command re-enables OSPF hello processing only on the internal interface, allowing adjacencies to form there while suppressing them on the DMZ and Internet interfaces. This matches the requirement exactly.

Why this answer

The requirement is to allow OSPF adjacencies only on the internal interface while suppressing them on all others. Setting 'passive-interface default' disables OSPF hello processing on every interface, and then 'no passive-interface GigabitEthernet0/0' re-enables it only on the internal interface. This ensures that OSPF runs exclusively where intended and prevents unintended adjacencies on the DMZ and Internet links.

Exam trap

The trap here is assuming that the network command alone controls which interfaces run OSPF, when in fact OSPF can run on any interface whose IP matches the network statement, and passive-interface is needed to suppress hellos on specific interfaces.

69
MCQhard

An engineer is implementing a VXLAN overlay network using Cisco Nexus switches. The engineer needs to ensure that the VXLAN tunnel endpoint (VTEP) can dynamically learn the mapping of remote VTEP IP addresses to MAC addresses. Which protocol should be used to achieve this dynamic learning?

A.OSPF
B.IS-IS
C.MP-BGP EVPN
D.PIM sparse mode
AnswerC

MP-BGP EVPN is a control plane protocol that allows VTEPs to exchange MAC address and IP address reachability information. It provides a scalable way to dynamically learn remote VTEP mappings, eliminating the need for flood-and-learn. In a VXLAN EVPN setup, MP-BGP EVPN is used to distribute MAC/IP bindings, enabling efficient and scalable overlay networks. This is the correct protocol for dynamic learning.

Why this answer

MP-BGP EVPN is the control plane protocol used in VXLAN overlays to dynamically exchange MAC address and IP address reachability information between VTEPs. It replaces flood-and-learn with a scalable, efficient control plane, enabling optimal forwarding and reducing flooding. This is the correct protocol for dynamic VTEP mapping learning.

Exam trap

The trap here is confusing underlay routing protocols like OSPF or IS-IS with overlay control plane protocols, which are responsible for MAC address learning in VXLAN EVPN.

70
MCQmedium

A network engineer is deploying a new branch office and needs to assign IPv6 addresses to hosts on the LAN segment. The engineer wants hosts to automatically configure their own addresses using the MAC address and the network prefix, without relying on a DHCPv6 server. Which IPv6 address assignment method should be configured on the router interface?

A.Static IPv6 addressing
B.SLAAC
C.DHCPv6 prefix delegation
D.Stateful DHCPv6
AnswerB

SLAAC allows hosts to automatically generate their own IPv6 addresses using the network prefix from Router Advertisement messages and their interface identifier (often derived from the MAC address via EUI-64). No DHCPv6 server is needed, satisfying the requirement. The router sends RA messages with the A flag set to 1, instructing hosts to use stateless autoconfiguration. This method is ideal for simple deployments where centralized address management is not required.

Why this answer

SLAAC enables hosts to automatically generate IPv6 addresses using the prefix from Router Advertisements and their interface identifier, without needing a DHCPv6 server. This matches the requirement for self-configuration. Stateful DHCPv6 requires a server, static addressing is manual, and prefix delegation is for router-to-router prefix assignment, not host addressing.

Exam trap

The trap here is confusing SLAAC with DHCPv6, assuming that any automatic address assignment requires a server.

71
MCQmedium

A network engineer is deploying a new branch office that must use dynamic ARP inspection (DAI) on its access switches. The engineer wants to minimize manual configuration while ensuring that only valid IP-to-MAC bindings are permitted. Which feature should be enabled on the switches to provide the required binding information to DAI?

A.802.1X
B.IP Source Guard
C.DHCP snooping
D.Port security
AnswerC

DHCP snooping builds a binding table of IP address, MAC address, VLAN, and interface by snooping DHCP conversations. Dynamic ARP inspection uses this table to validate ARP packets on untrusted ports. Enabling DHCP snooping on the access switches provides the required bindings automatically, minimizing manual configuration while allowing DAI to block ARP spoofing.

Why this answer

Dynamic ARP inspection relies on the DHCP snooping binding table to validate ARP packets on untrusted ports. Without a source of legitimate IP-to-MAC bindings, DAI cannot distinguish spoofed ARP replies from valid ones. Enabling DHCP snooping on the access switches automatically populates that table as clients obtain leases, which satisfies the requirement to minimize manual configuration while protecting the branch office from ARP poisoning.

Exam trap

The trap here is assuming that IP Source Guard or port security can supply the binding table that DAI needs, when in fact DHCP snooping is the feature that builds and maintains those bindings.

72
MCQhard

A network engineer is configuring a Cisco IOS XE router to support NETCONF over SSH. The requirement is to allow a remote management station to retrieve and modify the router's configuration using NETCONF. Which command must be used to enable the NETCONF subsystem on the router?

A.netconf-yang
B.restconf
C.ip http server
D.ssh server netconf
AnswerA

The command 'netconf-yang' enables the NETCONF subsystem on a Cisco IOS XE router. It starts the NETCONF server and allows the router to be managed via NETCONF over SSH. This command is essential for enabling programmatic access to the router's configuration and operational data using YANG models. Without this command, the router will not accept NETCONF sessions, even if SSH is configured.

Why this answer

To enable NETCONF over SSH on a Cisco IOS XE router, the 'netconf-yang' command must be configured. This command starts the NETCONF server and allows the router to be managed using NETCONF. It is a prerequisite for establishing NETCONF sessions and is essential for automated configuration and monitoring.

Exam trap

The trap here is confusing NETCONF with RESTCONF or assuming that enabling the HTTP server is sufficient for NETCONF access.

73
MCQmedium

A network engineer at a branch office needs to configure a Cisco IOS router to obtain its WAN interface IPv4 address dynamically from the ISP using DHCP while also ensuring the ISP can reach a web server hosted on the internal LAN at 10.10.10.50. Which single command on the router's WAN interface accomplishes the address acquisition requirement?

A.ip dhcp pool WAN_POOL
B.ip helper-address 203.0.113.1
C.ip address dhcp
D.ip address negotiated
AnswerC

This command configures the interface as a DHCP client, allowing it to dynamically request an IPv4 address, subnet mask, default gateway, and DNS servers from the ISP's DHCP server. It satisfies the requirement to obtain the WAN address dynamically without manual configuration, and is the standard Cisco IOS method for client-side DHCP on an interface.

Why this answer

The requirement is for the router to dynamically obtain an IPv4 address from the ISP. The ip address dhcp interface command enables DHCP client functionality, which is the correct method for Ethernet WAN interfaces. Other options either configure the router as a DHCP server, forward DHCP requests, or use PPP-based negotiation, none of which meet the scenario's need for standard DHCP client behavior on an Ethernet WAN link.

Exam trap

The trap here is confusing DHCP client and DHCP server roles, or assuming that ip address negotiated works for Ethernet DHCP.

74
MCQhard

A network administrator is configuring a Cisco Catalyst 9000 switch to authenticate users via 802.1X. The authentication server is a Cisco Identity Services Engine (ISE). The administrator wants to ensure that if the ISE server becomes unreachable, the switch will allow devices to connect with limited access. Which feature should be configured?

A.MAC Authentication Bypass
B.Critical VLAN
C.Inaccessible Authentication Bypass
D.Guest VLAN
AnswerC

Inaccessible Authentication Bypass (IAB) allows a port to grant access when the authentication server is unreachable. It can be configured to assign the port to a critical VLAN or apply a specific policy. This matches the requirement to allow devices to connect with limited access when ISE is down.

Why this answer

Inaccessible Authentication Bypass is designed to handle the situation where the RADIUS server is unreachable. It allows the switch to apply a preconfigured access policy, often assigning the port to a critical VLAN, ensuring that devices can still connect with limited access. This meets the requirement of maintaining connectivity during server outages.

Exam trap

The trap here is confusing Guest VLAN with Critical VLAN or Inaccessible Authentication Bypass; Guest VLAN is for non-802.1X devices, while IAB is for server unreachability.

75
MCQeasy

A network administrator is configuring a Cisco IOS switch to authenticate users via 802.1X. The administrator wants to ensure that if the RADIUS server is unreachable, users are placed into a guest VLAN with limited access. Which feature should be configured to achieve this?

A.Configure authentication host-mode multi-auth under the interface.
B.Configure authentication open under the interface.
C.Configure authentication event server dead action authorize vlan 100 under the interface.
D.Configure authentication event fail action authorize vlan 100 under the interface.
AnswerC

The authentication event server dead action authorize vlan 100 command instructs the switch to place the port into VLAN 100 if the RADIUS server is considered dead (unreachable). This provides a fallback for users when the authentication server cannot be contacted, allowing limited access as defined by the guest VLAN. This is the correct feature for the scenario.

Why this answer

To place users into a guest VLAN when the RADIUS server is unreachable, the authentication event server dead action authorize vlan command must be configured on the interface. This command triggers the fallback VLAN when the server is marked dead. The other options address different authentication events or host modes and do not provide the required server-dead fallback.

Exam trap

The trap here is confusing authentication failure (wrong credentials) with server unreachability; the commands for each are different, and only the server dead action provides the guest VLAN when the RADIUS server is down.

Page 1 of 3 · 179 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Infrastructure questions.