Courseiva

CCNA Infrastructure Questions

75 of 179 questions · Page 2/3 · Infrastructure · Answers revealed

76
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP relay agent for a subnet that has no local DHCP server. The DHCP server is at 10.10.10.5, and the router interface facing the clients is GigabitEthernet0/1 with IP address 10.20.20.1. Which command must be applied to the interface so that client DHCP broadcasts are forwarded to the server?

A.ip helper-address 10.10.10.5
B.ip dhcp relay 10.10.10.5
C.ip forward-protocol udp 67
D.ip dhcp pool CLIENT relay 10.10.10.5
AnswerA

The ip helper-address command is configured on the client-facing interface and instructs the router to forward UDP broadcasts, including DHCP DISCOVER and REQUEST, to the specified server as unicast packets. It also inserts the giaddr field with the interface IP so the server can select the correct pool. This directly satisfies the scenario.

Why this answer

DHCP relay is enabled by placing ip helper-address on the interface receiving client broadcasts. The router then converts those broadcasts into unicast packets toward the specified server and populates the giaddr field so the server can identify the correct subnet. The other commands either do not exist, do not specify a server, or configure the router as a server rather than a relay, so they do not meet the requirement.

Exam trap

The trap here is confusing DHCP server pool configuration with DHCP relay configuration, which are separate features applied in different configuration modes.

77
MCQmedium

A network engineer is configuring a new Cisco Catalyst 9300 switch stack. The design requires that if the active switch fails, the standby switch takes over the active role, and the member switch that was formerly standby becomes the new standby. The engineer needs to verify and influence the election order. Which mechanism determines the active and standby switch election in a switch stack?

A.The switch that is powered on first becomes active, and the switch that is powered on last becomes standby.
B.The switch with the lowest MAC address is always active, and the switch with the highest MAC address is always standby.
C.The switch with the highest serial number becomes active, and the switch with the second-highest serial number becomes standby.
D.The switch with the highest priority value becomes active, and the switch with the second-highest priority becomes standby.
AnswerD

In a Cisco switch stack, the active and standby switches are elected based on the stack priority value. If priorities are equal, the switch with the lowest MAC address wins. This priority can be configured with the 'switch X priority Y' command, allowing deterministic control over which member becomes active and which becomes standby.

Why this answer

Stack priority is the primary factor in electing the active and standby switches. A higher priority wins; if priorities are equal, the lower MAC address wins. This allows administrators to design deterministic failover by setting priorities appropriately.

The other options incorrectly cite MAC address, serial number, or power-on order as the primary election criteria.

Exam trap

The trap here is assuming that the first switch powered on or the one with the lowest MAC address always becomes active, overlooking the configurable stack priority that can override these factors.

78
MCQeasy

A network administrator is configuring a Cisco IOS switch and needs to verify the current VLAN configuration, including VLAN IDs, names, and status. Which command should be used?

A.show vlan brief
B.show interfaces switchport
C.show vlan id 1
D.show vlan summary
AnswerA

The show vlan brief command displays a concise summary of all VLANs, including VLAN ID, name, status, and the ports assigned to each VLAN. This provides exactly the information needed to verify the current VLAN configuration on the switch.

Why this answer

The show vlan brief command is the standard way to display all VLANs on a switch, including their IDs, names, status, and associated ports. It gives a comprehensive overview that allows an administrator to quickly verify the VLAN configuration. Other commands either filter to a single VLAN or provide only summary counts.

Exam trap

The trap here is selecting a command that shows VLAN information but not the complete list, such as show vlan id or show vlan summary.

79
MCQmedium

A network engineer is troubleshooting an EIGRP adjacency issue between two routers. The engineer verifies that both routers have the same K-values and autonomous system number. However, the adjacency does not form. Which configuration issue is most likely the cause?

A.Authentication is configured on one router but not on the other.
B.The network statement uses an incorrect subnet mask.
C.One router has a loopback interface that is not advertised.
D.The hello and hold timers do not match.
AnswerA

EIGRP authenticates each hello packet and every routing update using a configured key, typically MD5 or SHA-2. If one router has authentication enabled (e.g., 'ip authentication mode eigrp' and 'ip authentication key-chain eigrp') while the peer does not, the receiving router fails the authentication check and silently discards the hello, so no adjacency can ever form. Even a key mismatch or different key-chain name on both sides produces the same failure, making this a classic common cause of missing EIGRP neighbor relationships.

Why this answer

In EIGRP, authentication (MD5 or SHA) must be configured identically on both peers. If one router has authentication enabled and the other does not, the routers will reject each other's hello packets, preventing adjacency formation even if K-values and AS numbers match. This is a common misconfiguration that breaks neighbor relationships silently.

Exam trap

Cisco often tests the misconception that EIGRP requires matching hello and hold timers (like OSPF), but EIGRP is more tolerant; the real adjacency blocker is authentication mismatch, which is frequently overlooked when K-values and AS numbers are correct.

How to eliminate wrong answers

Option B is wrong because the network statement in EIGRP uses a wildcard mask, not a subnet mask; an incorrect subnet mask in the network statement would affect which interfaces participate in EIGRP but would not prevent adjacency if both routers have matching interfaces and AS numbers. Option C is wrong because a loopback interface that is not advertised does not affect EIGRP adjacency; adjacency forms on directly connected interfaces, and a non-advertised loopback has no impact on hello packet exchange. Option D is wrong because EIGRP does not require hello and hold timers to match; EIGRP uses a graceful restart mechanism where mismatched timers still allow adjacency (though hold time must be greater than hello interval to avoid flapping).

80
MCQhard

A network engineer is configuring a Cisco IOS router to establish a site-to-site VPN with a remote peer using IKEv2. The engineer wants to ensure that the router uses a pre-shared key for authentication and that the IKEv2 proposal uses AES-256 for encryption and SHA-256 for integrity. Which configuration sequence correctly sets up the IKEv2 proposal and keyring?

A.crypto ikev2 proposal PROPOSAL1; encryption aes-cbc-256; integrity sha256; group 14; crypto ikev2 keyring KEYRING1; peer PEER1; address 203.0.113.1; pre-shared-key local Cisco123; pre-shared-key remote Cisco123
B.crypto ikev2 proposal PROPOSAL1; encryption aes-cbc-256; integrity sha256; group 14; crypto ikev2 keyring KEYRING1; peer PEER1; address 203.0.113.1; pre-shared-key local Cisco123
C.crypto ikev2 policy POLICY1; encryption aes-cbc-256; integrity sha256; group 14; crypto ikev2 keyring KEYRING1; peer PEER1; address 203.0.113.1; pre-shared-key local Cisco123; pre-shared-key remote Cisco123
D.crypto ikev2 proposal PROPOSAL1; encryption aes-256; integrity sha-256; group 14; crypto ikev2 keyring KEYRING1; peer PEER1; address 203.0.113.1; pre-shared-key Cisco123
AnswerA

This sequence correctly defines an IKEv2 proposal with AES-256 encryption, SHA-256 integrity, and DH group 14. It then creates a keyring with a peer address and matching local and remote pre-shared keys. This is the proper syntax for IKEv2 configuration on Cisco IOS, ensuring the proposal and keyring are correctly associated for the VPN.

Why this answer

The correct configuration includes the proper IKEv2 proposal with encryption aes-cbc-256 and integrity sha256, and a keyring with both local and remote pre-shared keys. This ensures the router can authenticate with the remote peer using the correct cryptographic parameters.

Exam trap

The trap here is using incorrect keywords like aes-256 instead of aes-cbc-256, or omitting the remote pre-shared key, which are common syntax errors in IKEv2 configuration.

81
MCQeasy

A network administrator is configuring a new Cisco IOS router and needs to enable OSPFv2 on an interface with the correct area and network type. The interface is a broadcast multi-access network. Which command should be used to enable OSPF on the interface and set the area to 0?

A.router ospf 1: area 0 interface GigabitEthernet0/0
B.interface GigabitEthernet0/0: ip ospf 1 area 0
C.interface GigabitEthernet0/0: ip ospf area 0
D.router ospf 1: network 10.0.0.0 0.0.0.255 area 0
AnswerB

This command enables OSPF process 1 on the interface and assigns it to area 0. It is the interface-level method for enabling OSPF, which is precise and avoids the need for network statements. This is the recommended practice in modern Cisco IOS because it directly associates the interface with the OSPF process and area, reducing configuration errors.

Why this answer

The interface-level command 'ip ospf 1 area 0' enables OSPF process 1 on the interface and assigns it to area 0. This method is preferred over network statements because it is explicit and avoids unintended OSPF activation on other interfaces. The other options are either invalid syntax or less precise methods.

Exam trap

The trap here is assuming that OSPF must be enabled via the 'network' command under router configuration, overlooking the interface-level command.

82
MCQeasy

A network administrator is configuring a new Cisco IOS router and needs to enable OSPFv3 for IPv6 on an interface. The interface is already configured with an IPv6 address. Which command must be entered in interface configuration mode to enable OSPFv3 on that interface?

A.ipv6 ospf 1 area 0
B.ospfv3 1 ipv6 area 0
C.ipv6 router ospf 1
D.ip ospf 1 area 0
AnswerA

This command enables OSPFv3 on the interface and associates it with OSPF process 1 and area 0. It is the correct way to enable OSPFv3 for IPv6 on an interface in Cisco IOS. The process ID must match the one configured in the global 'ipv6 router ospf' command. This command is essential for OSPFv3 operation on a per-interface basis.

Why this answer

To enable OSPFv3 for IPv6 on an interface in Cisco IOS, the correct interface configuration command is 'ipv6 ospf <process-id> area <area-id>'. This command activates OSPFv3 on the interface and links it to the specified OSPFv3 process and area. The process ID must match the one defined in the global 'ipv6 router ospf' command.

Without this command, the interface will not participate in OSPFv3 routing.

Exam trap

The trap here is confusing OSPFv2 for IPv4 with OSPFv3 for IPv6, leading to the use of 'ip ospf' instead of 'ipv6 ospf'.

83
MCQmedium

A network engineer is configuring a Cisco IOS router to support a site-to-site VPN using IPsec. The engineer wants to ensure that traffic from the local subnet 10.1.1.0/24 to the remote subnet 10.2.2.0/24 is encrypted. Which configuration is required to define the interesting traffic?

A.crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 deny ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
B.crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip any any
C.crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255
D.crypto map MYMAP 10 ipsec-isakmp; set peer 203.0.113.2; set transform-set MYSET; match address 101; access-list 101 permit ip 10.2.2.0 0.0.0.255 10.1.1.0 0.0.0.255
AnswerC

This configuration defines an access list (101) that matches traffic from 10.1.1.0/24 to 10.2.2.0/24, and references it in the crypto map with the 'match address' command. This access list identifies the interesting traffic that will be encrypted by IPsec. The crypto map also sets the peer and transform set, completing the IPsec configuration.

Why this answer

The correct configuration uses an access list that permits IP traffic from the local subnet to the remote subnet and references it in the crypto map with 'match address'. This defines the interesting traffic that triggers the IPsec tunnel. The other options either deny the traffic, permit all traffic, or reverse the source and destination, which do not precisely meet the requirement.

Exam trap

The trap here is using a deny statement or 'any any' in the access list, which either excludes the desired traffic or includes too much, leading to incorrect encryption behavior.

84
MCQmedium

A network administrator is implementing a VXLAN EVPN fabric in a data center. The requirement is to provide Layer 2 connectivity between two leaf switches for a VLAN that must be stretched across the fabric. Which EVPN route type is used to advertise MAC address reachability information?

A.Type 1 - Ethernet Auto-Discovery route
B.Type 3 - Inclusive Multicast Ethernet Tag route
C.Type 4 - Ethernet Segment route
D.Type 2 - MAC/IP Advertisement route
AnswerD

Type 2 EVPN routes are used to advertise MAC address and optionally IP address reachability. In a VXLAN EVPN fabric, leaf switches advertise their locally learned MAC addresses using Type 2 routes. This allows other leaf switches to learn remote MAC addresses and forward traffic accordingly. Type 2 routes are essential for Layer 2 connectivity and are the correct choice for advertising MAC address reachability.

Why this answer

In a VXLAN EVPN fabric, MAC address reachability is advertised using Type 2 EVPN routes, also known as MAC/IP Advertisement routes. These routes allow leaf switches to learn remote MAC addresses and provide Layer 2 connectivity across the fabric. Type 2 routes are fundamental for the operation of EVPN-based VXLAN networks.

Exam trap

The trap here is confusing the different EVPN route types, especially Type 2 with Type 3, which is used for BUM traffic distribution.

85
MCQeasy

A network administrator is configuring a new Cisco IOS switch and wants to ensure that the management VLAN is isolated from user traffic. The administrator needs to assign an IP address to VLAN 1 for management access. Which command should be used to enter the interface configuration mode for VLAN 1?

A.interface vlan 1
B.ip address 192.168.1.1 255.255.255.0
C.interface fastethernet 0/1
D.vlan 1
AnswerA

The command 'interface vlan 1' enters the configuration mode for the switched virtual interface (SVI) associated with VLAN 1. This allows the administrator to assign an IP address to the management VLAN. This is the correct method to configure Layer 3 connectivity on a switch for management purposes. It is a fundamental step in setting up in-band management on Cisco switches.

Why this answer

To assign an IP address to a VLAN for management, you must enter the SVI configuration using 'interface vlan 1'. This creates a logical Layer 3 interface for that VLAN. The other options either configure physical interfaces, create the VLAN without Layer 3, or are incomplete without entering the interface mode first.

Exam trap

The trap here is confusing VLAN creation with SVI configuration, thinking that creating a VLAN automatically allows IP assignment.

86
MCQmedium

A network engineer is deploying a new branch office router that must obtain its WAN interface IP address dynamically from the ISP while also advertising its LAN prefix into OSPF. The engineer configures the WAN interface with the ip address dhcp command. Which additional configuration is required on the router to ensure the LAN prefix is advertised into OSPF with the correct network statement when the WAN IP changes?

A.Enable OSPF on the WAN interface and rely on connected route redistribution.
B.Use the network command with a wildcard mask that matches the LAN subnet under router ospf.
C.Configure a static route to the ISP and redistribute it into OSPF.
D.Configure OSPF to use the interface's DHCP-assigned IP address as the router ID.
AnswerB

The network command under router ospf with a wildcard mask matching the LAN subnet will advertise the LAN prefix into OSPF regardless of the WAN IP address. This is the standard method to enable OSPF on an interface and advertise its connected network. It does not depend on the WAN IP, so it remains stable when the DHCP lease changes.

Why this answer

The network command under router ospf with a wildcard mask matching the LAN subnet is the correct way to advertise the LAN prefix into OSPF. It is independent of the WAN interface's DHCP-assigned IP address, so the advertisement remains stable even if the WAN IP changes. Other options either advertise the wrong prefix or introduce unnecessary complexity.

Exam trap

The trap here is assuming that because the WAN interface uses DHCP, the OSPF configuration must also be dynamic, but the LAN advertisement is separate and should use a static network statement.

87
MCQeasy

A network engineer is configuring a Cisco Wireless LAN Controller (WLC) for a new wireless network. The engineer wants to ensure that client traffic is tunneled back to the WLC and that the WLC is the single point of management for the access points. Which mode should the access points be configured in?

A.Sniffer mode
B.FlexConnect mode
C.Monitor mode
D.Local mode
AnswerD

In local mode, access points establish a Control and Provisioning of Wireless Access Points (CAPWAP) tunnel to the WLC for both management and client data traffic. This allows the WLC to be the single point of management and ensures client traffic is tunneled back to the WLC. Local mode is the default and most common deployment mode for centralized wireless networks.

Why this answer

Local mode is the standard mode for access points in a centralized wireless deployment. It creates a CAPWAP tunnel to the WLC, carrying both management and client data traffic. This ensures that the WLC is the single point of management and that all client traffic is tunneled back to the WLC, meeting the engineer's requirements.

Other modes either do not serve clients or switch traffic locally.

Exam trap

The trap here is confusing FlexConnect mode, which can also be managed by the WLC but does not tunnel client traffic by default, with Local mode.

88
MCQmedium

A network engineer is configuring a Cisco IOS router to support VRF-lite for a customer. The engineer creates a VRF named CUST_A and assigns an interface to it using the command ip vrf forwarding CUST_A. After assigning the interface, the engineer notices that the interface IP address is removed. Which action must the engineer take to restore connectivity?

A.Reapply the IP address to the interface after assigning it to the VRF.
B.Configure a global IP address and then assign the interface to the VRF.
C.Enable OSPF within the VRF to automatically restore the IP address.
D.Remove the VRF from the interface and then reassign it to reset the IP address.
AnswerA

When an interface is assigned to a VRF using the ip vrf forwarding command, any existing IP address is removed because the interface's IP address is now part of the VRF's routing table. The engineer must re-enter the IP address configuration after the VRF assignment. This is a common operational step when configuring VRF-lite.

Why this answer

Assigning an interface to a VRF with ip vrf forwarding removes any existing IP address because the interface's addressing is now scoped to the VRF. The engineer must reapply the IP address after the VRF assignment. This is a standard step in VRF-lite configuration.

The other options either suggest incorrect order or misunderstand the behavior of VRF assignment.

Exam trap

The trap here is assuming that the IP address remains configured when an interface is assigned to a VRF, when in fact it is removed and must be reconfigured.

89
MCQmedium

A network engineer is configuring a GRE tunnel between two sites to transport IPv6 traffic over an IPv4-only underlay. The engineer wants to ensure that the tunnel interface supports IPv6 and that traffic is encrypted. Which technology should be combined with GRE to provide encryption?

A.IPsec in tunnel mode
B.MACsec
C.TLS
D.IPsec in transport mode
AnswerA

IPsec in tunnel mode encrypts the entire original IP packet, including the GRE header and payload, and encapsulates it within a new IPsec packet. This provides confidentiality and integrity for the GRE tunnel, making it suitable for transporting IPv6 over an IPv4 underlay securely. It is the standard method for protecting GRE tunnels.

Why this answer

To encrypt a GRE tunnel, IPsec in tunnel mode is used. It encrypts the entire original packet, including the GRE header, and encapsulates it in a new IPsec packet. This provides confidentiality and integrity for the tunneled traffic.

Transport mode does not encapsulate the original packet, MACsec is Layer 2 only, and TLS is application-layer, so they are not suitable for this scenario.

Exam trap

The trap here is confusing IPsec transport mode with tunnel mode; transport mode does not encrypt the GRE header, so it is not appropriate for protecting GRE tunnels.

90
MCQmedium

A network engineer is deploying a new branch office switch and needs to configure a switched virtual interface (SVI) to act as the default gateway for VLAN 10. The VLAN has been created and ports have been assigned. Which additional step is required for the SVI to become operational and pass traffic?

A.Configure a physical port as a trunk and allow VLAN 10 on it.
B.Enable IP routing globally with the ip routing command.
C.Assign the SVI to a port-channel for redundancy.
D.Assign an IP address to the SVI with the interface vlan 10 command, then issue no shutdown.
AnswerD

An SVI is created with the interface vlan 10 command. To make it operational, you must assign an IP address and enable it with no shutdown. The SVI will remain down until at least one access port in VLAN 10 is up and the VLAN exists in the VLAN database. Once these conditions are met, the SVI can route traffic for the subnet.

Why this answer

An SVI requires an IP address and must be enabled with no shutdown. The VLAN must exist and have at least one active access port for the SVI to come up. Global IP routing is needed for inter-VLAN routing but does not affect the SVI's operational state.

Trunking or port-channels are unrelated to bringing up an SVI for a single VLAN.

Exam trap

The trap here is assuming that creating the VLAN and assigning ports is sufficient to bring up the SVI, but the SVI also needs an IP address and no shutdown, and at least one active port.

91
MCQhard

An engineer is implementing a QoS policy on a Cisco IOS XE router. The requirement is to prioritize voice traffic (marked DSCP EF) and ensure that it receives strict priority scheduling with a guaranteed bandwidth of 30% of the interface capacity. Which queuing mechanism should be configured on the interface?

A.First-In, First-Out (FIFO) queuing with a rate limit for voice traffic.
B.Low Latency Queuing (LLQ) with a priority statement for the voice class.
C.Weighted Random Early Detection (WRED) with a precedence-based drop policy for voice.
D.Class-Based Weighted Fair Queuing (CBWFQ) with a bandwidth guarantee for the voice class.
AnswerB

LLQ is an extension of CBWFQ that adds a strict priority queue for delay-sensitive traffic such as voice. Configuring a priority statement for the voice class ensures that packets marked DSCP EF are dequeued first, up to the specified bandwidth (30%). This provides strict priority scheduling and guarantees bandwidth, meeting both requirements for voice traffic.

Why this answer

Low Latency Queuing (LLQ) combines the bandwidth guarantees of CBWFQ with a strict priority queue. By configuring a priority statement for the voice class, packets marked DSCP EF are placed in a low-latency queue that is serviced before other queues, ensuring minimal delay and jitter. The priority bandwidth allocation of 30% guarantees that voice traffic receives the necessary bandwidth even during congestion.

Exam trap

The trap here is assuming that CBWFQ alone can provide strict priority for voice; in reality, only LLQ (CBWFQ with a priority queue) offers strict priority scheduling.

92
MCQmedium

A network engineer is implementing QoS on a Cisco IOS router. The requirement is to classify traffic based on the DSCP value in the IP header and then mark it with a new DSCP value. Which QoS mechanism should be used to accomplish this?

A.Class-based weighted fair queueing (CBWFQ)
B.Policy-based routing (PBR)
C.Low latency queueing (LLQ)
D.Modular QoS CLI (MQC)
AnswerD

MQC is the framework for configuring QoS on Cisco IOS. It uses class-maps to classify traffic (e.g., matching DSCP) and policy-maps to define actions such as marking with a new DSCP value. The service-policy command applies the policy to an interface. This is the standard and correct method to classify and mark traffic based on DSCP.

Why this answer

The Modular QoS CLI (MQC) is the correct framework for classifying traffic based on DSCP and marking it with a new DSCP value. It involves creating a class-map to match the desired DSCP, a policy-map to set the new DSCP, and applying the service-policy to an interface. This provides a flexible and standardized way to implement QoS policies.

Exam trap

The trap here is confusing QoS mechanisms that use MQC (like CBWFQ and LLQ) with MQC itself. CBWFQ and LLQ are queuing actions within a policy-map, but the classification and marking is done by the MQC framework.

93
MCQmedium

A network engineer is deploying a new branch office with a single Cisco Catalyst switch. The branch requires that all access ports automatically authenticate devices using 802.1X with RADIUS, but also allow unauthenticated devices to be placed into a guest VLAN. Which feature must be configured on the switch to meet this requirement?

A.Configure 802.1X authentication with a guest VLAN on the access ports.
B.Configure Web Authentication (WebAuth) with a guest VLAN on the access ports.
C.Configure MAC authentication bypass (MAB) with a guest VLAN on the access ports.
D.Configure port security with a guest VLAN on the access ports.
AnswerA

Configuring 802.1X with a guest VLAN allows authenticated devices to be placed into a VLAN after successful RADIUS authentication, while unauthenticated devices are assigned to a separate guest VLAN. This meets the branch requirement exactly. The guest VLAN feature is specifically designed for this scenario and is supported on Cisco Catalyst switches.

Why this answer

The requirement is to authenticate devices using 802.1X with RADIUS and also provide a guest VLAN for unauthenticated devices. The 802.1X with guest VLAN feature on Cisco switches accomplishes this by assigning authenticated users to a VLAN and unauthenticated users to a guest VLAN. This is a standard implementation for branch offices needing both secure and guest access.

Exam trap

The trap here is confusing 802.1X with MAC authentication bypass or web authentication, which serve different purposes and do not provide the exact combination of 802.1X and guest VLAN.

94
MCQmedium

A company has a campus network with two distribution switches (DSW1 and DSW2) connected via a Layer 2 trunk. Each distribution switch connects to two access switches. Spanning Tree Protocol (STP) is running with default settings. Recently, a network administrator added a new access switch (ASW3) and connected it to both distribution switches. After the connection, network performance degraded significantly, and users in VLAN 10 reported intermittent connectivity. The administrator checked the logs and saw multiple TCN notifications. What is the most likely cause of the issue?

A.The new switch is causing a Layer 2 loop due to redundant links without proper STP configuration.
B.The new switch is not configured with the same VLANs as the distribution switches.
C.The new switch has a lower bridge priority than the current root bridge.
D.The new switch has become the root bridge and is sending inferior BPDUs.
AnswerA

A Layer 2 loop occurs when redundant paths exist without Spanning Tree Protocol actively blocking one of them. The new switch, if connected with multiple links to the distribution switches and STP disabled or misconfigured, will forward broadcast frames out all ports, causing a broadcast storm. This leads to severe symptoms such as high CPU utilization on all switches, MAC address table flapping, and complete network unavailability.

Why this answer

When ASW3 is connected to both DSW1 and DSW2 via Layer 2 trunk links, it creates a physical loop in the network. With default STP settings, the new switch will participate in the spanning tree algorithm, but the sudden addition of redundant links can cause a temporary loop or instability until STP converges. The multiple TCN (Topology Change Notification) messages indicate that the spanning tree topology is flapping, leading to MAC address table flushes and intermittent connectivity for VLAN 10 users.

This is the classic symptom of a Layer 2 loop caused by redundant links without proper STP configuration or before convergence completes.

Exam trap

Cisco often tests the distinction between a Layer 2 loop causing TCN flapping and a root bridge election, where candidates mistakenly think a new root bridge is the primary problem rather than the redundant physical loop itself.

How to eliminate wrong answers

Option B is wrong because mismatched VLANs would cause traffic to be dropped or not forwarded, but would not generate TCN notifications or cause a Layer 2 loop; TCNs are triggered by changes in the spanning tree topology, not by VLAN mismatches. Option C is wrong because a lower bridge priority would make the new switch more likely to become the root bridge, but that alone does not cause a loop or performance degradation; STP would still converge and block redundant ports. Option D is wrong because if the new switch becomes the root bridge, it sends superior BPDUs (not inferior), and while this would cause a topology change, it would not inherently create a loop or cause the severe performance degradation described; the issue is the physical loop, not the root bridge election.

95
MCQmedium

A network engineer is implementing a VXLAN overlay over an existing Layer 3 campus network. The requirement is to carry Layer 2 frames across the Layer 3 underlay. Which protocol is used to encapsulate the original Layer 2 frame for transport across the IP network?

A.802.1Q tagging on the underlay
B.MPLS label stack with a Layer 2 VPN
C.VXLAN with a UDP header
D.GRE with a protocol type of 0x6558
AnswerC

VXLAN encapsulates the original Layer 2 frame inside a MAC-in-UDP header. The 8-byte VXLAN header, UDP header, and outer IP header allow the frame to be routed across a Layer 3 underlay. This directly satisfies the scenario requirement to carry Layer 2 frames over an IP network.

Why this answer

VXLAN encapsulates the original Layer 2 frame in a MAC-in-UDP format. The outer IP and UDP headers allow the encapsulated frame to be routed across a Layer 3 underlay, which is exactly what the scenario requires. Other encapsulation methods either need a different underlay or do not provide the VXLAN VNI and VTEP behavior.

Exam trap

The trap here is assuming that any tunneling protocol can carry Layer 2 over Layer 3, when VXLAN specifically uses UDP encapsulation and a VNI, not GRE or MPLS.

96
MCQmedium

A network engineer is configuring a Cisco Catalyst switch port that connects to an IP phone. The phone must place voice traffic in VLAN 200 and data traffic from a daisy-chained PC in VLAN 100. The switch port is currently configured as a static access port in VLAN 100. Which configuration must the engineer apply to meet these requirements?

A.Configure the interface as a dynamic auto trunk and set the voice VLAN to 200 with the switchport voice vlan command.
B.Configure the interface as a trunk, set the native VLAN to 200, and allow VLANs 100 and 200 on the trunk.
C.Configure the interface with the switchport voice vlan 200 command while leaving the access VLAN as 100.
D.Configure the interface as a trunk, set the native VLAN to 100, and allow only VLAN 200 on the trunk.
AnswerC

The switchport voice vlan command enables the voice VLAN feature on an access port. Data frames from the PC remain untagged in the access VLAN (100), while voice frames from the phone are tagged with VLAN 200. The phone can also receive the voice VLAN assignment through LLDP-MED or CDP, making this the correct and simplest solution for a phone-plus-PC topology.

Why this answer

The voice VLAN feature on a Cisco access port allows a phone to send tagged voice frames while data frames from a daisy-chained PC remain untagged in the access VLAN. Configuring the port with switchport voice vlan 200 and leaving it as an access port in VLAN 100 provides the required separation without manual trunk configuration.

Exam trap

The trap here is assuming that a trunk must be configured to separate voice and data traffic, when the voice VLAN feature on an access port already handles this automatically.

97
Multi-Selectmedium

A network administrator is deploying a Cisco SD-Access fabric and needs to ensure that the underlay network is properly configured. Which two statements about the underlay network in SD-Access are true? (Choose two.)

Select 2 answers
A.The underlay can be configured as a Layer 2 network with VLANs to simplify deployment.
B.The underlay network carries endpoint subnet information and is used for endpoint-to-endpoint communication.
C.The underlay must support MTU sizes large enough to accommodate VXLAN encapsulation overhead.
D.The underlay uses a routing protocol such as IS-IS or OSPF to provide IP connectivity between fabric nodes.
E.The underlay uses VXLAN to encapsulate traffic between fabric nodes.
AnswersC, D

VXLAN adds 50 bytes of overhead (outer IP, UDP, VXLAN header). The underlay must support an MTU of at least 1550 bytes (typically 1600 or higher) to avoid fragmentation of VXLAN-encapsulated packets. If the underlay MTU is too small, large packets may be dropped or fragmented, causing performance issues. Therefore, configuring jumbo frames on the underlay is a best practice for SD-Access.

Why this answer

The underlay in SD-Access provides IP connectivity between fabric nodes using a routing protocol like IS-IS or OSPF, and it must support a larger MTU to accommodate VXLAN encapsulation overhead. The underlay does not carry endpoint subnet information; that is the role of the overlay. It is a Layer 3 network, not Layer 2, and it does not use VXLAN for encapsulation.

Exam trap

The trap here is conflating the underlay with the overlay, assuming the underlay carries endpoint prefixes or uses VXLAN, when it only provides IP transport.

98
MCQhard

A network engineer is configuring a new switch stack using Cisco StackWise technology. The engineer wants to ensure that if the stack master fails, another switch takes over with minimal disruption. Which statement accurately describes the failover behavior in a StackWise stack?

A.All switches in the stack must be rebooted to elect a new master, causing a network outage.
B.The stack master election is based on the highest MAC address, and failover requires a reboot of all stack members.
C.The standby switch becomes the new master without reloading, and other members continue forwarding traffic.
D.The failed master must be physically replaced before the stack can resume normal operations.
AnswerC

In a StackWise stack, the standby switch automatically takes over as master if the active master fails. The failover is designed to be hitless or near-hitless, with other stack members continuing to forward traffic without reloading. This provides high availability and minimal disruption, which is a key benefit of StackWise technology.

Why this answer

Cisco StackWise provides high availability by allowing a standby switch to take over as master if the active master fails. This failover is designed to be hitless or near-hitless, with other stack members continuing to forward traffic. No reboot of all switches is required, and the failed master does not need immediate replacement.

This ensures minimal disruption to network operations.

Exam trap

The trap here is assuming that StackWise failover requires a full stack reboot or that the failed master must be replaced immediately, when in fact the standby takes over seamlessly.

99
Multi-Selecthard

A network engineer is configuring a Cisco IOS router for QoS and wants to ensure that voice traffic is prioritized and that excess traffic is dropped rather than buffered when congestion occurs. The engineer decides to use Low Latency Queueing (LLQ). Which two statements accurately describe the behavior of LLQ? (Choose two.)

Select 2 answers
A.LLQ provides a strict priority queue that is serviced before other queues, ensuring low latency for voice traffic.
B.LLQ can be configured only on interfaces that support hardware queuing, such as serial interfaces.
C.LLQ buffers all excess traffic in the priority queue until bandwidth becomes available, ensuring no packets are dropped.
D.LLQ uses a policer to limit the amount of traffic that can enter the priority queue, dropping excess packets.
E.LLQ allows multiple priority queues to be configured, each with its own bandwidth guarantee.
AnswersA, D

LLQ includes a strict priority queue that is always serviced first when packets are present, which minimizes delay and jitter for voice. This is a key characteristic of LLQ, making it suitable for real-time traffic. The priority queue is typically configured with a bandwidth guarantee and a policer to limit its maximum rate, preventing starvation of other queues.

Why this answer

LLQ provides a single strict priority queue that is serviced before other queues, ensuring low latency for voice. It uses a policer to cap the priority queue's bandwidth, dropping excess packets to prevent starvation of other queues. These two characteristics are fundamental to LLQ's operation and make it suitable for real-time traffic while maintaining fairness.

Exam trap

The trap here is assuming that LLQ allows multiple priority queues or that it buffers excess priority traffic, when in fact it supports only one priority queue and drops excess packets via a policer.

100
MCQhard

A network engineer is designing a new data center network using Cisco ACI. The engineer needs to ensure that traffic between two endpoints in different EPGs is allowed only if a contract permits it. Which ACI construct is used to define the rules that permit or deny traffic between EPGs?

A.Tenant
B.Contract
C.Application Profile
D.Bridge Domain
AnswerB

In Cisco ACI, a contract defines the rules that permit or deny traffic between EPGs. It consists of subjects and filters that specify the protocols and ports allowed. Contracts are applied to EPGs as providers or consumers. When an EPG provides a contract and another consumes it, traffic is allowed according to the contract's filters. This is the fundamental mechanism for enforcing policy in ACI, making it the correct answer.

Why this answer

In Cisco ACI, contracts are the constructs that define the rules for permitting or denying traffic between EPGs. A contract contains subjects and filters that specify the allowed protocols and ports. EPGs can be providers or consumers of contracts, and traffic is only allowed if a contract is in place.

This policy-based approach ensures that communication between endpoints is explicitly permitted, aligning with a zero-trust security model.

Exam trap

The trap here is confusing the logical grouping constructs like tenants, application profiles, and bridge domains with the policy enforcement construct, which is the contract.

101
MCQmedium

A network administrator is configuring a Cisco IOS router to authenticate management users via TACACS+. The requirement is to allow fallback to the local database if all TACACS+ servers are unreachable. Which AAA configuration achieves this?

A.aaa authentication login default group tacacs+ none
B.aaa authentication login default local group tacacs+
C.aaa authentication login default group tacacs+ enable
D.aaa authentication login default group tacacs+ local
AnswerD

This command configures the default login authentication method list to try TACACS+ first, then fall back to the local username database if the TACACS+ servers do not respond. The 'local' keyword ensures that local authentication is used as a backup, providing administrative access even when the AAA server is unreachable.

Why this answer

The correct configuration uses the default method list with TACACS+ first and local fallback. The 'group tacacs+' keyword specifies TACACS+ servers, and 'local' ensures the router's local username database is used if all TACACS+ servers are unreachable. This provides centralized authentication with a resilient backup.

Exam trap

The trap here is confusing the order of authentication methods or using 'none' or 'enable' instead of 'local' for fallback, which either compromises security or fails to use the local database.

102
MCQmedium

A network engineer is configuring a Cisco IOS router to act as a DHCP server for a subnet. The router must provide IP addresses, default gateway, and DNS server information to clients. Which configuration is required?

A.ip dhcp pool POOL1, network 192.168.1.0 255.255.255.0, default-router 192.168.1.1, dns-server 8.8.8.8
B.ip dhcp pool POOL1, network 192.168.1.0 255.255.255.0, default-router 192.168.1.1, dns-server 8.8.8.8, lease 0 8
C.ip dhcp excluded-address 192.168.1.1 192.168.1.10, then ip dhcp pool POOL1 with network 192.168.1.0 255.255.255.0 and default-router 192.168.1.1
D.ip dhcp pool POOL1, host 192.168.1.100 255.255.255.0, hardware-address 0000.1111.2222
AnswerA

This configuration creates a DHCP pool named POOL1, defines the network and subnet mask, and provides the default gateway and DNS server. The ip dhcp pool command enters DHCP pool configuration mode, where network, default-router, and dns-server are valid commands. This fully satisfies the requirement to provide IP addresses, gateway, and DNS information to clients. It is the correct and standard way to configure a Cisco IOS DHCP server.

Why this answer

A Cisco IOS DHCP server requires a pool with network, default-router, and dns-server commands to provide IP addresses, gateway, and DNS information. The excluded-address command is optional but often used. The lease command is optional and not required for basic operation.

Manual bindings are for specific hosts and do not serve a subnet. Therefore, the configuration that includes network, default-router, and dns-server is the correct choice.

Exam trap

The trap here is focusing on excluded addresses or lease times as required, when the essential DHCP options for client configuration are network, default-router, and dns-server.

103
MCQhard

A network engineer is implementing VXLAN with a Layer 2 gateway on a Cisco Nexus 9000 series switch. The design uses a distributed anycast gateway to provide optimal forwarding for hosts in the same subnet across different leaf switches. The engineer needs to ensure that all leaf switches use the same virtual MAC address for the gateway. Which feature must be configured to achieve this?

A.HSRP
B.VRRP
C.Anycast gateway
D.GLBP
AnswerC

The anycast gateway feature allows multiple leaf switches to share the same virtual IP and MAC address for a subnet's default gateway. This enables hosts to use a consistent gateway regardless of their location, and ensures optimal forwarding without traffic tromboning. Configuring the same virtual MAC on all leaf switches achieves the requirement.

Why this answer

The anycast gateway feature in Cisco VXLAN allows all leaf switches to share the same virtual IP and MAC address for a subnet's default gateway. This provides active-active gateway functionality, ensuring that hosts always use the optimal path and avoiding traffic tromboning. Configuring the same virtual MAC on all leaf switches is part of the anycast gateway configuration.

Exam trap

The trap here is assuming that traditional first-hop redundancy protocols like HSRP, VRRP, or GLBP can provide a distributed anycast gateway, when they actually elect a single active gateway.

104
MCQeasy

A network administrator is configuring a Cisco Catalyst switch to allow management access only from the subnet 10.10.10.0/24. The administrator wants to apply an ACL to the VTY lines. Which command correctly applies the ACL named MGMT to the VTY lines?

A.ip access-group MGMT in
B.access-class MGMT in
C.ip access-class MGMT in
D.access-list MGMT in
AnswerB

The access-class command is used under line configuration mode to restrict incoming VTY connections based on an ACL. The in keyword specifies that the ACL filters traffic entering the VTY lines. This is the correct way to apply an ACL to management access, ensuring only hosts from permitted subnets can establish SSH or Telnet sessions.

Why this answer

To restrict management access to a Cisco device, an ACL is defined globally and then applied to the VTY lines using the access-class command in line configuration mode. The in keyword filters incoming connections. This ensures that only hosts matching the ACL's permit statements can establish remote management sessions, effectively limiting access to the specified subnet.

Exam trap

The trap here is confusing interface ACL application with VTY ACL application; many candidates mistakenly use ip access-group on VTY lines, but the correct command is access-class.

105
MCQmedium

A network engineer is configuring a Cisco Catalyst switch port that connects to an IP phone and a PC. The phone must tag its voice traffic with VLAN 200, and the PC must send untagged traffic that the switch places into VLAN 10. Which interface configuration accomplishes this?

A.switchport mode access switchport access vlan 10 switchport voice vlan 200
B.switchport mode trunk switchport trunk native vlan 10 switchport trunk allowed vlan 200
C.switchport mode access switchport access vlan 200 switchport voice vlan 10
D.switchport mode trunk switchport trunk encapsulation dot1q switchport trunk native vlan 200
AnswerA

This is the correct configuration. Setting the port to access mode with access VLAN 10 handles the untagged PC traffic, while the switchport voice vlan 200 command tells the switch to recognize 802.1Q-tagged frames for VLAN 200 as voice traffic from the attached IP phone. This is the standard Cisco IP telephony deployment model for a single physical port supporting both a phone and a PC.

Why this answer

The access-plus-voice configuration is the standard way to support an IP phone and a PC on one switch port. The access VLAN carries untagged PC traffic, and the voice VLAN carries 802.1Q-tagged phone traffic. This allows the phone to tag its own traffic while the PC sends untagged frames, and the switch classifies them into the correct VLANs without needing a trunk on the port.

Exam trap

The trap here is assuming that a trunk is required to support a voice VLAN on an access port, when the switchport voice vlan command already handles the tagging.

106
Multi-Selectmedium

A network engineer is configuring a GRE tunnel between two Cisco IOS routers to transport multicast traffic and routing protocols across an IP network. Which two statements about GRE tunnel configuration and operation are true? (Choose two.)

Select 2 answers
A.GRE tunnel interfaces must be assigned an IP address from the same subnet as the physical interfaces.
B.GRE tunnels support multicast and broadcast traffic by default.
C.GRE tunnels can only carry unicast IP traffic.
D.The tunnel source and tunnel destination must be reachable via the underlay network.
E.GRE tunnels automatically encrypt all traffic passing through them.
AnswersB, D

GRE is designed to encapsulate a wide variety of protocols, including multicast and broadcast. When you configure a GRE tunnel, it acts like a virtual point-to-point link that can carry multicast traffic, which is essential for routing protocols like OSPF and EIGRP that use multicast hellos. This is a key advantage over IPsec tunnels, which typically only support unicast unless specifically configured with GRE.

Why this answer

GRE tunnels support multicast and broadcast traffic, making them suitable for carrying routing protocol hellos and other multicast applications. Additionally, the tunnel source and destination must be reachable via the underlay network for the tunnel to come up. GRE does not provide encryption, and tunnel interfaces are typically assigned IP addresses from a separate subnet, not the same as physical interfaces.

Exam trap

The trap here is assuming that GRE provides encryption or that it only supports unicast traffic, when in fact it supports multicast and broadcast but lacks encryption.

107
MCQhard

A network engineer is deploying a new Cisco Catalyst switch and needs to implement a loop prevention mechanism that allows rapid convergence and supports multiple VLANs. The engineer decides to use Rapid PVST+. Which statement accurately describes a characteristic of Rapid PVST+ operation?

A.It requires all switches in the network to be configured with the same bridge priority to ensure consistent root election.
B.It uses a single spanning-tree instance for all VLANs, which simplifies configuration but reduces flexibility.
C.It provides separate spanning-tree instances for each VLAN and uses Rapid Spanning Tree Protocol (RSTP) enhancements for faster convergence.
D.It is compatible only with switches running IEEE 802.1D STP and cannot interoperate with RSTP devices.
AnswerC

Rapid PVST+ is Cisco's implementation of RSTP that runs a separate instance per VLAN. It incorporates RSTP mechanisms such as edge ports, link-type point-to-point, and proposal/agreement to achieve rapid convergence. This allows per-VLAN topology optimization and fast failover, making it suitable for modern switched networks with multiple VLANs.

Why this answer

Rapid PVST+ is a Cisco enhancement that runs a separate RSTP instance per VLAN. It uses RSTP's rapid convergence features like edge ports and proposal/agreement, while maintaining per-VLAN topology. This allows for fast failover and load balancing across VLANs.

The other options mischaracterize its operation, such as claiming a single instance or lack of interoperability.

Exam trap

The trap here is confusing Rapid PVST+ with MSTP or single-instance STP, or assuming it lacks per-VLAN capabilities or RSTP interoperability.

108
MCQeasy

A network administrator is configuring a Cisco IOS router to provide DHCP services to a remote subnet. The router's interface on that subnet is configured with the address 10.1.1.1/24. Which command is required to exclude the router's own address from the DHCP pool?

A.ip dhcp pool 10.1.1.1
B.ip dhcp relay information option
C.ip dhcp excluded-address 10.1.1.1
D.ip dhcp excluded-address 10.1.1.0 10.1.1.255
AnswerC

The 'ip dhcp excluded-address' command prevents the router from assigning specific addresses, such as its own interface address, to DHCP clients. It is configured in global configuration mode and can specify a single address or a range. This ensures the router's IP is not leased to other devices.

Why this answer

The 'ip dhcp excluded-address' command is used to prevent specific IP addresses from being assigned by the DHCP server. In this scenario, excluding the router's interface address 10.1.1.1 ensures it remains available for the router itself and is not leased to a client.

Exam trap

The trap here is confusing the command to exclude addresses with the command to create a pool; excluding the entire subnet would break DHCP service.

109
MCQhard

A network administrator is deploying a new Cisco Catalyst switch in a data center. The switch must support a protocol that allows multiple physical links to be bundled into a single logical link, providing increased bandwidth and redundancy. The administrator wants to ensure that the protocol can dynamically negotiate the bundle formation with the connected device. Which protocol should be configured?

A.UniDirectional Link Detection (UDLD)
B.Link Aggregation Control Protocol (LACP)
C.Spanning Tree Protocol (STP)
D.Port Aggregation Protocol (PAgP)
AnswerB

LACP is an IEEE 802.3ad standard protocol that dynamically negotiates EtherChannel formation between devices from different vendors. It provides increased bandwidth and redundancy by bundling multiple physical links into a single logical link. This meets the requirement for dynamic negotiation and interoperability.

Why this answer

LACP is the IEEE standard for dynamic link aggregation, allowing switches from different vendors to negotiate an EtherChannel. It bundles multiple physical links into one logical link for increased bandwidth and redundancy. PAgP is Cisco-proprietary, while UDLD and STP serve entirely different purposes.

Exam trap

The trap here is confusing link aggregation protocols with loop prevention or link monitoring protocols, or assuming PAgP is universally supported.

110
MCQhard

A network engineer is configuring a Cisco Catalyst switch to authenticate users via 802.1X. The switch must place authenticated users into a specific VLAN based on the RADIUS server's response, and unauthenticated users should have no network access. Which configuration element is required on the switch to support dynamic VLAN assignment?

A.Configure the switch to use MAC authentication bypass (MAB) and assign a static VLAN to the interface.
B.Configure the interface as a trunk port and allow all VLANs.
C.Configure the switch to use RADIUS Change of Authorization (CoA) and enable dynamic VLAN assignment on the interface.
D.Configure the RADIUS server to return the IETF attributes Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID, and ensure the switch interface is in access mode with 802.1X enabled.
AnswerD

For dynamic VLAN assignment, the RADIUS server must return the standard IETF attributes: Tunnel-Type set to VLAN, Tunnel-Medium-Type set to IEEE-802, and Tunnel-Private-Group-ID containing the VLAN ID or name. The switch interface must be configured for 802.1X and typically in access mode so that the port can be moved to the assigned VLAN upon authentication. This is the correct combination to meet the requirement.

Why this answer

Dynamic VLAN assignment in 802.1X requires the RADIUS server to return specific tunnel attributes that the switch interprets to place the authenticated user into a designated VLAN. The switch port must be configured for 802.1X and usually in access mode. The combination of the correct RADIUS attributes and the proper switch configuration enables the switch to move the port to the VLAN specified by the server after successful authentication, providing the required access control.

Exam trap

The trap here is confusing RADIUS Change of Authorization with the initial dynamic VLAN assignment mechanism, which relies on tunnel attributes in the Access-Accept message, not on CoA.

111
Multi-Selecthard

A network engineer is deploying a Cisco SD-WAN solution using vManage, vSmart, and vBond controllers. The engineer must ensure that the control plane and data plane are secure and that routers can authenticate to the controllers. Which two statements are true regarding the Cisco SD-WAN controller components? (Choose two.)

Select 2 answers
A.vSmart stores the full configuration and acts as the CA for certificate management.
B.vManage is responsible for forwarding data plane traffic between branches.
C.vBond establishes IPsec tunnels for data plane traffic between vEdge routers.
D.vSmart distributes control plane policies and routes to vEdge routers using OMP.
E.vBond orchestrates the initial authentication and allows vEdge routers to locate vSmart and vManage controllers.
AnswersD, E

vSmart is the controller that implements control plane policies and distributes routing information via the Overlay Management Protocol (OMP). It maintains the centralized control plane and pushes policies to vEdge devices. This is essential for SD-WAN fabric operation.

Why this answer

In Cisco SD-WAN, vBond orchestrates initial authentication and helps routers find other controllers. vSmart distributes control plane policies and routes using OMP. These two components are essential for establishing the secure overlay and enabling centralized control. The management plane (vManage) and data plane (vEdge routers) have different roles.

Exam trap

The trap here is confusing the management plane, control plane, and data plane responsibilities among vManage, vSmart, and vBond.

112
MCQhard

A network engineer is implementing a Cisco TrustSec solution. The engineer needs to classify traffic based on user identity and apply security policies accordingly. Which component is responsible for tagging packets with a Security Group Tag (SGT) at the ingress point?

A.Policy Enforcement Point (PEP)
B.Policy Decision Point (PDP)
C.Network Device Admission Control (NDAC)
D.Ingress Policy Enforcement Point (Ingress PEP)
AnswerD

The Ingress Policy Enforcement Point (Ingress PEP) is the device where traffic enters the TrustSec domain. It is responsible for classifying the traffic and tagging the packet with the appropriate Security Group Tag (SGT). This tagging allows subsequent devices to enforce policies based on the SGT without reclassifying the traffic. The Ingress PEP is typically a switch or router that supports TrustSec.

Why this answer

In Cisco TrustSec, the Ingress Policy Enforcement Point (Ingress PEP) is the device that first receives traffic into the TrustSec domain. It classifies the traffic, determines the source Security Group Tag (SGT), and inserts the SGT into the packet. This tag is then used by other enforcement points to apply security policies.

The PDP (ISE) provides the policy, but the Ingress PEP performs the tagging.

Exam trap

The trap here is confusing the roles of the PDP and PEP, or assuming that the PDP tags packets, when in fact the tagging is done at the ingress point.

113
MCQmedium

A network engineer is deploying a new WLAN and needs to ensure that client traffic is encrypted using AES with a pre-shared key. Which security configuration should be applied to the wireless SSID?

A.WPA2-PSK with AES
B.WPA3-PSK with AES
C.WPA2-PSK with TKIP
D.WEP with AES
AnswerA

WPA2-PSK with AES-CCMP is the appropriate choice because it offers robust wireless encryption (AES in counter mode with CBC-MAC) and uses a pre-shared key for straightforward authentication. This configuration is widely supported, passes PCI DSS requirements for strong encryption, and fulfills the stated requirement of using AES-based security. It balances compatibility with strong protection.

Why this answer

WPA2-PSK with AES is the correct choice because the requirement specifies AES encryption with a pre-shared key. WPA2-PSK (Wi-Fi Protected Access 2 – Pre-Shared Key) mandates AES-CCMP (Counter Mode Cipher Block Chaining Message Authentication Code Protocol) as the encryption protocol, providing strong, standards-compliant security for client traffic. This configuration directly satisfies the need for both AES encryption and PSK authentication.

Exam trap

Candidates may mistakenly think that WPA3-PSK is a valid term because WPA3 uses AES and a pre-shared key (password). However, the industry-standard name is WPA3-Personal (which uses SAE for key exchange), not WPA3-PSK. The option 'WPA3-PSK with AES' is incorrect due to non-standard terminology, while WPA2-PSK with AES fully meets the need for AES encryption and PSK authentication.

How to eliminate wrong answers

Option B is wrong because WPA3-PSK uses AES encryption but introduces Simultaneous Authentication of Equals (SAE) instead of a traditional pre-shared key handshake; while it supports PSK, the question explicitly asks for a configuration that ensures AES with a pre-shared key, and WPA3-PSK is not the only or most direct answer given the options. Option C is wrong because WPA2-PSK with TKIP uses the RC4-based Temporal Key Integrity Protocol, not AES, which violates the requirement for AES encryption. Option D is wrong because WEP (Wired Equivalent Privacy) does not support AES; it uses RC4 encryption and is deprecated due to severe security vulnerabilities, making it incompatible with the AES requirement.

114
MCQeasy

A network engineer is configuring a Cisco IOS switch to use 802.1X authentication for endpoints connected to interface GigabitEthernet1/0/1. The engineer wants to ensure that if the RADIUS server is unreachable, the port will be placed in a restricted VLAN. Which command should be used?

A.authentication host-mode multi-auth
B.authentication event fail action authorize vlan 10
C.authentication event no-response action authorize vlan 10
D.authentication event server dead action authorize vlan 10
AnswerD

This command specifies that if the RADIUS server becomes unreachable, the port will be authorized into VLAN 10, providing restricted access. It is used within 802.1X configuration to define fallback behavior when the authentication server is dead, ensuring that endpoints can still gain limited network access according to policy.

Why this answer

The command 'authentication event server dead action authorize vlan 10' is specifically designed to handle the case where the RADIUS server is unreachable, placing the port into VLAN 10 as a fallback. This ensures that endpoints can still access limited network resources according to policy when the authentication server is down.

Exam trap

The trap here is confusing the server dead event with fail or no-response events, which handle different failure conditions.

115
MCQhard

A network engineer is configuring a Cisco IOS router to support OSPFv3 for IPv6. The router is connected to two OSPFv3 areas: area 0 and area 1. The engineer wants to summarize the IPv6 routes from area 1 into area 0 using the prefix 2001:DB8:1::/48. Which command should be used on the area border router (ABR)?

A.area 1 range 2001:DB8:1::/48
B.summary-address 2001:DB8:1::/48
C.ipv6 ospf summary-prefix 2001:DB8:1::/48
D.area 0 range 2001:DB8:1::/48
AnswerA

This command configures inter-area route summarization for OSPFv3 on the ABR. The 'area 1 range' command tells the ABR to advertise a single summary route for the specified prefix into other areas. It must be configured under IPv6 router OSPF configuration mode. This is the correct way to summarize OSPFv3 routes between areas.

Why this answer

In OSPFv3, inter-area route summarization is configured on an ABR using the 'area <area-id> range <prefix>' command. The area ID specifies the source area whose routes are to be summarized. Here, routes from area 1 are summarized into area 0 using the prefix 2001:DB8:1::/48.

The other commands either do not exist, are for external summarization, or specify the wrong area.

Exam trap

The trap here is confusing inter-area summarization with external summarization, or using the wrong area ID in the command.

116
MCQhard

A network engineer is implementing Cisco TrustSec in a campus network. The security team wants to assign a security group tag to traffic based on the identity of the user authenticated via 802.1X, and then enforce policy based on that tag in the data center. Which Cisco TrustSec component is responsible for classifying the traffic with the appropriate security group tag at the access layer?

A.Identity Services Engine (ISE) as the policy server combined with the access switch enforcing the authorization result
B.Security Group ACLs (SGACLs) on the destination device
C.Security Group Tag Exchange Protocol (SXP)
D.MACsec encryption on the uplink between access and distribution switches
AnswerA

In Cisco TrustSec, ISE authenticates the user via 802.1X and returns an authorization result that includes the SGT. The access switch enforces that result by tagging the user's traffic with the assigned SGT. This classification at the access layer is what allows downstream devices to enforce group-based policies. ISE provides the identity-to-SGT mapping, and the switch applies it.

Why this answer

Cisco TrustSec classification begins with authentication. ISE authenticates the user and returns an authorization profile containing the SGT, and the access switch applies that tag to the user's traffic. This inline tagging at the access layer allows enforcement devices to apply group-based policies.

SXP propagates mappings, SGACLs enforce policy, and MACsec protects links, but none of them assign the tag based on identity.

Exam trap

The trap here is confusing the propagation of SGT mappings via SXP or the enforcement via SGACLs with the actual classification step, which happens on the access device using the ISE authorization result.

117
MCQhard

A network engineer is configuring a Cisco IOS router to authenticate OSPF neighbors using MD5. The engineer enters the following commands under the OSPF process: area 0 authentication message-digest, and under the interface: ip ospf message-digest-key 1 md5 Cisco123. However, the neighbor relationship does not form. What is the most likely cause?

A.The area authentication command must be configured on all routers in the area, but the interface command is optional.
B.The key ID must match on both routers, but the key string can be different.
C.The key ID and key string must match on both routers, and the area authentication command must be consistent.
D.The router must be reloaded for the MD5 key to take effect.
AnswerC

For OSPF MD5 authentication to succeed, both routers must have the same key ID, the same key string, and the same authentication type configured for the area or interface. The area authentication command enables MD5 for the area, and the interface command provides the key. If any of these parameters differ, the neighbor relationship will not form.

Why this answer

OSPF MD5 authentication requires consistent configuration on both neighbors: the same key ID, the same key string, and the same authentication mode (area or interface). The area authentication command enables MD5 for the area, and the interface command provides the key. If any of these differ, OSPF authentication fails, and the routers will not become adjacent.

Exam trap

The trap here is assuming that only the key string matters, when in fact the key ID and the area authentication mode must also match.

118
MCQmedium

A network architect is designing a data center fabric that must support Layer 2 extension over a Layer 3 underlay while using a control-plane protocol that advertises MAC reachability. The design requires the use of a protocol that encapsulates Layer 2 frames in IP packets and uses an EVPN address family for MAC/IP advertisement. Which technology best meets these requirements?

A.VXLAN with BGP EVPN control plane
B.OTV with IS-IS as the control plane
C.LISP with a Map-Server/Map-Resolver
D.MPLS L2VPN with BGP for label distribution
AnswerA

VXLAN provides Layer 2 extension over a Layer 3 underlay by encapsulating Ethernet frames in UDP/IP. BGP EVPN is used as the control plane to advertise MAC and IP reachability, enabling efficient forwarding and multi-tenancy. This matches the requirement for a protocol that encapsulates Layer 2 frames in IP and uses EVPN for MAC/IP advertisement.

Why this answer

VXLAN with BGP EVPN is the correct choice because it encapsulates Layer 2 frames in UDP/IP and uses BGP EVPN as the control plane to advertise MAC and IP reachability. This provides a scalable and efficient solution for Layer 2 extension over a Layer 3 underlay, meeting the design requirements for a data center fabric.

Exam trap

The trap here is assuming that any Layer 2 extension technology uses BGP EVPN for MAC advertisement, overlooking that OTV and MPLS L2VPN use different control planes.

119
Multi-Selectmedium

A network engineer is configuring a GRE tunnel between two Cisco IOS routers to transport multicast traffic over an IP network that does not support multicast. The engineer must ensure the tunnel is operational and multicast is forwarded correctly. Which two statements are true about GRE tunnel configuration and operation? (Choose two.)

Select 2 answers
A.The tunnel interface must be configured with the 'tunnel mode gre multipoint' command to support multicast.
B.The tunnel interface must be configured with an IP address from the same subnet as the physical interface.
C.GRE tunnels automatically encrypt all traffic, so no additional security configuration is required.
D.Multicast routing must be enabled on the tunnel interface and the underlying physical interface.
E.The tunnel source and destination must be reachable via the underlay routing table.
AnswersD, E

To forward multicast traffic over a GRE tunnel, multicast routing must be enabled on both the tunnel interface and the physical interface that carries the tunnel. The tunnel interface must be included in the multicast routing configuration (e.g., 'ip pim sparse-mode'). Otherwise, multicast packets will not be forwarded into or out of the tunnel.

Why this answer

A GRE tunnel requires that the tunnel source and destination be reachable via the underlay. Additionally, to carry multicast, multicast routing must be enabled on both the tunnel and the physical interface. These two conditions ensure the tunnel is up and multicast is forwarded.

The other options describe incorrect or unnecessary configurations.

Exam trap

The trap here is assuming GRE provides encryption or that multipoint mode is needed for multicast, when point-to-point GRE can carry multicast if multicast routing is enabled.

120
MCQmedium

A network engineer is deploying a new Cisco Catalyst 9000 switch stack and wants to protect the control plane from excessive ARP traffic that could overwhelm the CPU during a broadcast storm. The engineer needs to limit the rate of ARP packets sent to the CPU to 500 packets per second and drop the excess. Which feature should be configured on the switch?

A.Dynamic ARP Inspection (DAI) on all VLANs
B.Control Plane Policing (CoPP) with a class-map matching ARP
C.IP Source Guard on all access ports
D.Storm control configured on all access ports
AnswerB

CoPP allows the engineer to police traffic destined to the control plane, including ARP packets. By creating a class-map that matches ARP and a policy-map that sets a rate limit of 500 pps with a drop action, the switch CPU is protected from excessive ARP. This is the correct feature for rate-limiting control-plane traffic.

Why this answer

Control Plane Policing (CoPP) is designed to protect the CPU by rate-limiting traffic destined to the control plane. In this scenario, the engineer needs to limit ARP packets to 500 pps, which is exactly what CoPP can do by matching ARP in a class-map and applying a policer. Other features like storm control or DAI do not provide this granular control-plane protection.

Exam trap

The trap here is assuming that storm control or DAI can rate-limit ARP traffic to the CPU, when they actually operate at the data plane or for security validation.

121
MCQhard

A network engineer is configuring a Cisco IOS switch with 802.1X authentication. The switch is connected to a Cisco IP phone, and a PC is connected to the phone's PC port. The engineer wants to authenticate both the phone and the PC using 802.1X. Which feature should be configured to allow both devices to authenticate on the same switch port?

A.MAC Authentication Bypass (MAB)
B.Multi-Auth
C.Multi-Domain Authentication (MDA)
D.Web Authentication (WebAuth)
AnswerC

Multi-Domain Authentication (MDA) allows both a data device (PC) and a voice device (IP phone) to authenticate on the same switch port. The phone authenticates in the voice domain, and the PC authenticates in the data domain. This is the correct feature for this scenario because it separates the authentication domains and supports the typical IP phone with a PC attached.

Why this answer

Multi-Domain Authentication (MDA) is designed for scenarios where an IP phone and a PC are connected to the same switch port. It allows the phone to authenticate in the voice domain and the PC in the data domain, each with its own authentication method. This provides the necessary separation of traffic and authentication.

Exam trap

The trap here is confusing Multi-Auth with Multi-Domain Authentication; Multi-Auth allows multiple devices but does not separate voice and data domains, which is required for IP phones.

122
MCQmedium

A network administrator is configuring a Cisco wireless LAN controller (WLC) to support a new employee SSID. The SSID must use WPA2-Enterprise with 802.1X authentication against an external RADIUS server. The administrator has already configured the RADIUS server on the WLC. Which additional step is required to complete the configuration?

A.Create a new WLAN and set the Layer 2 Security to WPA2 with 802.1X, and set the Layer 3 Security to None.
B.Create a new WLAN and set the Layer 2 Security to WPA2 with PSK, and set the Layer 3 Security to Web Policy.
C.Create a new WLAN and set the Layer 2 Security to None, and set the Layer 3 Security to Web Policy with RADIUS authentication.
D.Create a new WLAN and set the Layer 2 Security to WPA2 with 802.1X, and set the Layer 3 Security to Web Policy.
AnswerA

For WPA2-Enterprise with 802.1X, the WLAN's Layer 2 Security must be set to WPA2 with 802.1X. Layer 3 Security should be set to None because 802.1X handles authentication at Layer 2. This configuration enables the WLC to use the RADIUS server for authentication.

Why this answer

For WPA2-Enterprise with 802.1X, the WLAN must use Layer 2 Security set to WPA2 with 802.1X, which leverages the configured RADIUS server for authentication. Layer 3 Security should remain None to avoid additional web authentication. This setup ensures that clients authenticate via 802.1X and receive AES encryption.

Exam trap

The trap here is adding Layer 3 Web Policy in addition to 802.1X, which would cause double authentication and is not required for WPA2-Enterprise.

123
MCQmedium

A network engineer is configuring a Cisco Catalyst switch to authenticate users via 802.1X. The RADIUS server is reachable at 10.10.10.5 using the key 'Cisco123'. The switch must dynamically assign VLANs based on the RADIUS attributes returned. Which configuration is required on the switch to enable dynamic VLAN assignment?

A.aaa new-model aaa authentication dot1x default group radius aaa accounting network default start-stop group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control
B.aaa new-model aaa authentication dot1x default group radius aaa authorization network default group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control
C.aaa new-model aaa authentication dot1x default group radius aaa authorization network default group radius radius-server host 10.10.10.5 key Cisco123 no dot1x system-auth-control
D.aaa new-model aaa authentication dot1x default group radius radius-server host 10.10.10.5 key Cisco123 dot1x system-auth-control
AnswerB

This configuration includes 'aaa authorization network default group radius', which is necessary for the switch to authorize the user and apply VLAN assignment from the RADIUS server. The authentication command verifies credentials, while authorization processes the returned attributes such as tunnel-type, tunnel-medium, and tunnel-private-group-id to assign the VLAN. The RADIUS server and dot1x system-auth-control are also correctly configured.

Why this answer

For dynamic VLAN assignment with 802.1X, the switch must authenticate the user and authorize the session to receive VLAN attributes from the RADIUS server. The 'aaa authorization network default group radius' command enables the switch to process these attributes. Without it, the switch will not apply the VLAN, even if authentication succeeds.

The RADIUS server and global 802.1X configuration are also required.

Exam trap

The trap here is assuming that authentication alone is sufficient for dynamic VLAN assignment, but authorization is required to process and apply the RADIUS attributes.

124
Multi-Selectmedium

A network engineer is deploying Cisco TrustSec in a campus network. The engineer needs to implement Security Group Tag (SGT) propagation and enforcement. Which two methods can be used to propagate SGTs? (Choose two.)

Select 2 answers
A.802.1X supplicant tagging
B.RADIUS Change of Authorization (CoA) tagging
C.SGT Exchange Protocol (SXP)
D.IPsec tunnel tagging
E.Inline tagging using Cisco Metadata (CMD)
AnswersC, E

SXP is a control-plane protocol that propagates IP-to-SGT mappings to devices that cannot perform inline tagging, such as older switches or firewalls. It allows SGTs to be shared across network boundaries, enabling enforcement on devices that lack hardware support for inline tagging. This is a standard method for SGT propagation in TrustSec.

Why this answer

SGTs can be propagated using inline tagging with Cisco Metadata (CMD), which embeds tags in the frame, or using SXP, which shares IP-to-SGT mappings with devices that cannot perform inline tagging. These two methods are standard in Cisco TrustSec deployments, enabling enforcement across diverse network devices.

Exam trap

The trap here is confusing authentication protocols like 802.1X or RADIUS CoA with SGT propagation methods, which are specifically inline tagging and SXP.

125
MCQmedium

A network engineer needs to configure a switch port to authenticate end hosts against a RADIUS server. The requirement is that if the RADIUS server becomes unreachable, the port should place the host on a guest VLAN instead of shutting down. Which command must be added to the interface configuration?

A.authentication host-mode multi-auth
B.authentication event server dead action authorize vlan 10
C.authentication event fail action authorize vlan 10
D.authentication open
AnswerB

This command instructs the switch to place the port into the specified guest VLAN when the RADIUS server fails to respond to authentication requests, satisfying the requirement to avoid shutting the port down. It is part of Cisco IOS 802.1X authentication event configuration and directly addresses the server-dead condition by authorizing a fallback VLAN rather than a critical VLAN.

Why this answer

When a RADIUS server becomes unreachable, the switch can be configured to authorize the port into a specific VLAN rather than shutting it down. The 'authentication event server dead action authorize vlan' command implements this by defining the VLAN to assign. The other options either handle different authentication events or alter port behaviour in ways that do not match the requirement.

Exam trap

The trap here is confusing authentication failure actions with server-dead actions, where a server-dead event requires a distinct command to handle unreachable RADIUS servers.

126
MCQhard

A network administrator is troubleshooting an issue where OSPF routes are not being learned from a neighbor. The administrator checks the OSPF configuration and sees that both routers are in the same area. The neighbor state is stuck in EXSTART. What is the most likely cause?

A.The router ID is the same on both routers.
B.The area ID is different.
C.The hello timer is set to 30 seconds on one router.
D.The interface MTU does not match.
AnswerD

An MTU mismatch is the classic cause of an OSPF neighbor being stuck in EXSTART; during the Database Description exchange, each router advertises its outgoing interface MTU in the DBD packet header. If one router's interface has a lower MTU, it discards DBD packets that declare a larger MTU, so the neighboring router never receives a valid acknowledgment and remains in EXSTART. Because OSPF does not initialize the DBD exchange until both MTUs are verified equal, the adjacency stalls at the point where the Master/Slave election occurs, exactly matching the reported symptom.

Why this answer

When OSPF neighbors are stuck in the EXSTART state, it typically indicates a problem with the Database Description (DBD) packet exchange process. The most common cause is an MTU mismatch between the interfaces, because OSPF will not proceed to the Exchange state if the DBD packet is larger than the interface MTU and gets silently dropped. This prevents the routers from agreeing on the master/slave relationship and exchanging link-state information.

Exam trap

The trap here is that candidates often confuse the EXSTART state with issues like hello/dead timer mismatches or area mismatches, which actually prevent the adjacency from reaching the 2-WAY state, not the EXSTART state.

How to eliminate wrong answers

Option A is wrong because duplicate router IDs would cause a neighbor state of DOWN or a conflict that prevents adjacency formation entirely, not a state stuck in EXSTART. Option B is wrong because if the area ID were different, the routers would not even reach the 2-WAY state, let alone EXSTART; they would remain in INIT or DOWN. Option C is wrong because mismatched hello timers would prevent the routers from reaching the 2-WAY state (they would stay in INIT), not cause them to get stuck in EXSTART.

127
Multi-Selecthard

A network engineer is deploying VXLAN with an EVPN control plane in a data center. The underlay is a routed Layer 3 network using OSPF. The engineer must ensure that the VXLAN data plane and EVPN control plane operate correctly. Which two statements about this deployment are true? (Choose two.)

Select 2 answers
A.EVPN uses BGP as its control plane to distribute MAC and IP address reachability information among VTEPs.
B.The VXLAN Tunnel Endpoint (VTEP) must have a unique IP address in the underlay, and this address is used as the source for VXLAN encapsulated traffic.
C.EVPN requires the underlay to be a Layer 2 network so that BGP peering can be established without routing.
D.The VTEP must be configured with the same IP address on all leaf switches to allow anycast tunneling.
E.VXLAN requires the underlay network to run a multicast routing protocol such as PIM to replicate broadcast, unknown unicast, and multicast traffic.
AnswersA, B

EVPN is a BGP address family (L2VPN EVPN) that carries MAC and IP reachability information. VTEPs peer with each other or with route reflectors using MP-BGP and advertise EVPN routes. This replaces flood-and-learn for MAC learning and provides control-plane learning, making the statement correct for an EVPN deployment.

Why this answer

In a VXLAN-EVPN deployment, each VTEP needs a unique underlay IP address used as the source for encapsulated traffic, and EVPN relies on MP-BGP to distribute MAC and IP reachability. Multicast is optional and typically replaced by ingress replication, anycast VTEP is a design choice, and the underlay must be Layer 3 for scalability. These two statements accurately describe the core requirements.

Exam trap

The trap here is assuming VXLAN always requires multicast in the underlay, which is only true for flood-and-learn without a control plane.

128
MCQeasy

A network administrator is configuring a Cisco IOS switch to support a new voice VLAN. The administrator wants to ensure that voice traffic is tagged with CoS 5 and data traffic is untagged. Which command should be applied to the interface connected to an IP phone?

A.switchport voice vlan 10
B.switchport trunk encapsulation dot1q
C.mls qos trust cos
D.switchport mode access
AnswerA

This command enables the voice VLAN on the interface, allowing the switch to send Cisco Discovery Protocol (CDP) or Link Layer Discovery Protocol (LLDP) information to the IP phone. The phone can then tag voice traffic with the appropriate VLAN and CoS. It also allows data traffic from the PC to be untagged. This is the correct configuration for a voice VLAN.

Why this answer

The switchport voice vlan command enables the voice VLAN on an access port, allowing the switch to advertise the voice VLAN to the IP phone via CDP or LLDP. The phone then tags voice frames with the voice VLAN and CoS, while data from the attached PC remains untagged. Other commands like trunk encapsulation or access mode do not provide voice VLAN functionality.

QoS trust may be needed but is not the primary configuration.

Exam trap

The trap here is confusing voice VLAN configuration with trunk configuration or QoS trust, which are related but do not by themselves enable voice VLAN separation.

129
MCQhard

A network engineer is troubleshooting a Cisco Wireless LAN Controller (WLC) deployment where clients cannot associate to an SSID. The SSID is configured with WPA2-Enterprise and uses a RADIUS server for authentication. The engineer verifies that the RADIUS server is reachable and the shared secret is correct. Which additional configuration on the WLC is required for clients to successfully authenticate?

A.Configure the WLC management interface with a static IP address.
B.Set the WLAN to use PSK instead of Enterprise.
C.Configure the WLC as a RADIUS client on the RADIUS server.
D.Enable 802.1X on the WLAN and specify the RADIUS server.
AnswerD

For WPA2-Enterprise, the WLAN must be configured to use 802.1X authentication and point to the correct RADIUS server. If 802.1X is not enabled or the RADIUS server is not specified on the WLAN, clients cannot authenticate. This is a common oversight when configuring enterprise SSIDs on a WLC.

Why this answer

For WPA2-Enterprise authentication, the WLAN on the WLC must be configured to use 802.1X and reference the RADIUS server. Even if the RADIUS server is reachable and the shared secret is correct, the WLAN will not trigger authentication unless 802.1X is enabled and the server is specified in the WLAN's security settings.

Exam trap

The trap here is focusing on RADIUS server-side configuration when the missing piece is often the 802.1X setting on the WLAN itself.

130
MCQmedium

A network engineer is implementing VRF-Lite on a Cisco IOS router to separate traffic from two different departments. The router has two interfaces, GigabitEthernet0/0 and GigabitEthernet0/1, each assigned to a different VRF. The engineer wants to verify that the VRFs are properly configured and that routes are being populated. Which command displays the routing table for a specific VRF?

A.show ip vrf
B.show vrf interface
C.show ip route
D.show ip route vrf DEPARTMENT1
AnswerD

This command displays the IP routing table for the VRF named DEPARTMENT1. It is the correct way to verify routes within a specific VRF. Without specifying the VRF, the global routing table is shown, which does not include VRF routes. This command is essential for troubleshooting VRF-Lite configurations.

Why this answer

To view the routing table for a specific VRF, the show ip route vrf command must be used. The global show ip route only displays the global table. Commands like show vrf interface and show ip vrf provide VRF configuration information but not the routes themselves.

Verifying VRF routes is critical in VRF-Lite deployments to ensure proper traffic separation.

Exam trap

The trap here is using show ip route without the vrf keyword, which only shows the global routing table and misses VRF-specific routes.

131
MCQhard

A network engineer is implementing a first-hop redundancy protocol on a pair of Cisco switches. The design requires that the standby router take over if the active router fails, and that the virtual MAC address be 0000.0c07.ac0a. Which protocol and group number are being used?

A.HSRP group 10
B.HSRP group 170
C.VRRP group 10
D.GLBP group 10
AnswerA

HSRP uses a virtual MAC address in the format 0000.0c07.acXX, where XX is the group number in hexadecimal. The address 0000.0c07.ac0a corresponds to group 10 (0a in hex equals 10 in decimal). HSRP provides redundancy with an active and standby router.

Why this answer

The virtual MAC address 0000.0c07.ac0a indicates HSRP with group 10 because the last two hex digits (0a) represent the group number in hexadecimal. HSRP uses this MAC format, while VRRP and GLBP use different formats.

Exam trap

The trap here is misinterpreting the hexadecimal group number or confusing the MAC address formats of different first-hop redundancy protocols.

132
MCQhard

A network engineer is configuring a Cisco Catalyst switch to support 802.1X authentication for wired users. The company requires that if the RADIUS server becomes unreachable, devices on a critical VLAN should be allowed access to the network without authentication. Which feature should be configured on the switch to meet this requirement?

A.Inaccessible Authentication Bypass
B.Guest VLAN
C.Critical VLAN
D.MAC Authentication Bypass
AnswerA

Inaccessible Authentication Bypass (IAB) is a Cisco feature that allows a port to be authorized and placed into a configurable critical VLAN when the RADIUS server is unreachable. This ensures that critical devices can still access the network without authentication during a server outage, meeting the requirement exactly.

Why this answer

Inaccessible Authentication Bypass (IAB) is designed to handle the exact situation where the RADIUS server becomes unreachable. When enabled, the switch places the port into a critical VLAN, allowing devices to gain network access without authentication. This feature is essential for maintaining connectivity for critical devices during an authentication server outage.

Exam trap

The trap here is confusing Inaccessible Authentication Bypass with Critical VLAN; while related, IAB is the feature that enables the bypass behavior when the server is down, whereas Critical VLAN is the VLAN assignment used by IAB.

133
Multi-Selecthard

A network engineer is deploying a Cisco SD-WAN solution using vManage, vSmart, and vBond controllers. Which two statements accurately describe the roles of these controllers in the SD-WAN overlay? (Choose two.)

Select 2 answers
A.vBond controllers are responsible for distributing routing information and policies to vEdge routers.
B.vSmart controllers are responsible for the data plane forwarding and encryption of traffic between vEdge routers.
C.vBond orchestrates the initial authentication and brings up the control plane connections between vEdge routers and vSmart controllers.
D.vSmart controllers establish permanent data plane tunnels with each vEdge router for traffic forwarding.
E.vManage provides a centralized management plane for configuration, monitoring, and troubleshooting of the SD-WAN fabric.
AnswersC, E

vBond acts as the orchestrator in Cisco SD-WAN. It is the first point of contact for vEdge routers. It authenticates the routers and provides them with the IP addresses of the vSmart controllers and vManage. vBond also facilitates the establishment of control plane connections (DTLS) between vEdge routers and vSmart controllers. It does not participate in the data plane or routing decisions. Its primary role is onboarding and orchestration.

Why this answer

In Cisco SD-WAN, vBond orchestrates initial authentication and control plane connectivity, while vManage provides centralized management. vSmart handles control plane routing and policy distribution, and vEdge routers handle data plane forwarding. The correct statements are about vBond's orchestration role and vManage's management role.

Exam trap

The trap here is confusing the control plane and data plane responsibilities of vSmart and vBond, or assuming that vSmart handles data forwarding.

134
MCQeasy

A network administrator needs to configure a Cisco IOS switch to authenticate users against a RADIUS server before granting access to a switchport. The requirement is that if the RADIUS server becomes unreachable, the port should fall back to the configured access VLAN and not shut down. Which set of commands accomplishes this?

A.aaa new-model aaa authentication dot1x default group radius dot1x system-auth-control interface GigabitEthernet1/0/1 authentication port-control auto authentication host-mode multi-auth authentication event server dead action authorize vlan 10
B.aaa new-model aaa authentication dot1x default group radius dot1x system-auth-control interface GigabitEthernet1/0/1 authentication port-control auto
C.aaa new-model aaa authentication dot1x default group radius dot1x system-auth-control interface GigabitEthernet1/0/1 authentication port-control auto authentication open authentication event fail action authorize vlan 20
D.aaa new-model aaa authentication login default group radius local dot1x system-auth-control interface GigabitEthernet1/0/1 authentication port-control force-authorized
AnswerA

This configuration enables 802.1X with RADIUS authentication, sets the port to auto mode, allows multiple authenticated hosts, and uses the authentication event server dead action authorize vlan 10 command. When the RADIUS server is unreachable, the port is placed in the specified access VLAN (10) rather than shutting down or remaining unauthorized, exactly matching the fallback requirement.

Why this answer

To authenticate users against RADIUS and fall back to a specific access VLAN when the server is unreachable, the switch needs 802.1X enabled globally, RADIUS as the authentication method, port-control auto on the interface, and the authentication event server dead action authorize vlan command. That command keeps the port usable in the designated VLAN during server outages.

Exam trap

The trap here is assuming that enabling 802.1X with port-control auto alone provides fallback behavior, when a server-dead action must be explicitly configured to authorize the port into an access VLAN.

135
Multi-Selecthard

A network engineer is configuring a new Cisco IOS router for OSPFv2 in a multi-area OSPF domain. The router will be an Area Border Router (ABR) connecting Area 0 and Area 10. The engineer must ensure that the router correctly summarizes routes from Area 10 into Area 0 and that it does not become a designated router (DR) on any broadcast network. Which two configuration steps are required to meet these requirements? (Choose two.)

Select 2 answers
A.Set the OSPF interface priority to 0 on all interfaces that participate in OSPF.
B.Configure the router with the 'area 10 stub' command under the OSPF routing process.
C.Configure the router with the 'auto-cost reference-bandwidth 100000' command under the OSPF routing process.
D.Configure the router with the 'area 10 range 10.10.0.0 255.255.0.0' command under the OSPF routing process.
E.Configure the router with the 'passive-interface default' command under the OSPF routing process.
AnswersA, D

Setting the OSPF interface priority to 0 prevents the router from being elected as a designated router (DR) or backup designated router (BDR) on broadcast networks. This meets the requirement that the router does not become a DR. The priority is configured per interface with the 'ip ospf priority 0' command under the interface configuration.

Why this answer

To summarize routes from Area 10 into Area 0, the ABR must use the 'area 10 range' command. To prevent the router from becoming a DR, the OSPF interface priority must be set to 0 on all participating interfaces. These two steps directly satisfy the requirements.

The other options either configure stub areas, alter cost calculations, or suppress OSPF on interfaces, none of which meet the stated goals.

Exam trap

The trap here is assuming that configuring an area as stub or changing the reference bandwidth will influence summarization or DR election, when these are unrelated OSPF features.

136
MCQeasy

A network technician is configuring a new Cisco switch and needs to assign the management IP address to VLAN 1. Which command sequence is correct?

A.interface vlan 1; ip address 10.1.1.1 255.255.255.0; no shutdown
B.ip address 10.1.1.1 255.255.255.0; interface vlan 1; no shutdown
C.vlan 1; ip address 10.1.1.1 255.255.255.0; no shutdown
D.interface gigabitethernet0/1; ip address 10.1.1.1 255.255.255.0; no shutdown
AnswerA

To assign an IP address to the management VLAN, you enter interface configuration mode for VLAN 1 using 'interface vlan 1', then assign the IP address with 'ip address', and ensure the interface is up with 'no shutdown'. This is the standard method for configuring a management IP on a Cisco switch. VLAN 1 is the default management VLAN.

Why this answer

The correct method to assign a management IP address on a Cisco switch is to create or use the VLAN 1 interface (SVI) and assign the IP address there. The sequence 'interface vlan 1', then 'ip address', then 'no shutdown' is standard. Other options either target physical interfaces or use incorrect command modes.

Exam trap

The trap here is confusing VLAN configuration mode with VLAN interface configuration mode; IP addresses are assigned to the SVI, not the VLAN database.

137
MCQmedium

A network engineer is configuring a new Cisco Catalyst 9300 switch stack. The company requires that the native VLAN for all 802.1Q trunk ports be changed from the default to VLAN 99. The engineer enters the global configuration command vlan dot1q tag native and then configures the trunk ports with switchport trunk native vlan 99. After applying the configuration, the engineer notices that untagged frames received on the trunk are being dropped. What is the most likely cause?

A.The vlan dot1q tag native command must be configured on all switches in the topology, not just the local switch.
B.The native VLAN must be the same on both ends of the trunk; otherwise, untagged frames are dropped.
C.The switchport trunk native vlan 99 command is only valid if the native VLAN is VLAN 1.
D.The vlan dot1q tag native command causes all native VLAN frames to be tagged, so untagged frames are dropped.
AnswerD

With vlan dot1q tag native enabled, the switch tags all frames on the native VLAN. Any untagged frames arriving on the trunk are considered invalid and dropped. This is the expected behavior when this global command is used, and it explains why untagged frames are being dropped.

Why this answer

Enabling vlan dot1q tag native globally causes the switch to tag all frames on the native VLAN for 802.1Q trunks. As a result, any untagged frames received on those trunks are dropped because they are not expected. This behavior is by design and explains the observed frame drops.

Exam trap

The trap here is assuming that vlan dot1q tag native only affects outbound tagging and not inbound frame processing.

138
MCQeasy

A network engineer is configuring a switch to support 802.1X authentication for wired clients. The requirement is to authenticate users against a centralized RADIUS server and assign dynamic VLANs based on the user's role. Which command must be configured on the switch to enable 802.1X authentication globally?

A.aaa authentication dot1x default group radius
B.dot1x system-auth-control
C.authentication port-control auto
D.dot1x pae authenticator
AnswerB

The command 'dot1x system-auth-control' enables 802.1X authentication globally on a Cisco switch. It is a prerequisite for configuring 802.1X on individual interfaces. Without this command, 802.1X authentication will not function, even if interface-level commands are configured. This command allows the switch to act as an authenticator and communicate with the RADIUS server to authenticate supplicants.

Why this answer

To enable 802.1X authentication globally on a Cisco switch, the 'dot1x system-auth-control' command must be configured. This command activates the 802.1X process and allows the switch to act as an authenticator. Other commands, such as those for RADIUS or interface-level settings, are necessary but do not globally enable 802.1X.

Exam trap

The trap here is confusing the global enablement command with interface-level or AAA commands that are also part of 802.1X configuration.

139
MCQmedium

A network engineer is configuring a Cisco Catalyst switch to support a new wireless access point that will carry management traffic on VLAN 10 and client traffic on VLAN 20. The AP connects to a single switchport and requires both VLANs to be trunked with 802.1Q tagging, with VLAN 10 as the native VLAN. Which configuration on the switchport will meet these requirements?

A.switchport mode trunk switchport trunk native vlan 10 switchport trunk allowed vlan 10,20
B.switchport mode dynamic auto switchport trunk native vlan 10 switchport trunk allowed vlan 10,20
C.switchport mode access switchport access vlan 10 switchport trunk allowed vlan 20
D.switchport mode trunk switchport trunk encapsulation dot1q switchport trunk native vlan 20 switchport trunk allowed vlan 10,20
AnswerA

This correctly configures the port as an 802.1Q trunk, sets VLAN 10 as the native VLAN (untagged), and allows both VLAN 10 and VLAN 20 on the trunk. The AP can send management traffic untagged on VLAN 10 and tag client traffic for VLAN 20, exactly matching the requirements for the wireless deployment.

Why this answer

The switchport must be configured as a trunk to carry multiple VLANs. Setting the native VLAN to 10 ensures untagged management traffic uses VLAN 10, and allowing VLANs 10 and 20 permits both management and client traffic. The other options either do not enable trunking, set the wrong native VLAN, or use a dynamic mode that may not form a trunk with an access point.

Exam trap

The trap here is assuming that an access point always uses an access port for management, but in this scenario, multiple VLANs require a trunk with a specific native VLAN.

140
MCQhard

A network engineer is troubleshooting a Cisco SD-WAN deployment where a branch router (vEdge) is not forming a control connection with the vSmart controller. The engineer verifies that the vEdge has IP reachability to the vSmart controller's public IP address on port 12346. Which additional step is required for the control connection to be established?

A.The vEdge must have OSPF configured to advertise its loopback interface to the vSmart controller.
B.The vEdge must have a valid certificate installed and be authenticated by the vBond orchestrator.
C.The vEdge must be configured with a static route to the vSmart controller's private IP address.
D.The vEdge must be configured with the vSmart controller's IP address as its default gateway.
AnswerB

In Cisco SD-WAN, the vEdge router must authenticate with the vBond orchestrator to obtain the list of vSmart controllers and establish control connections. This requires a valid certificate installed during onboarding. Without proper authentication, the vEdge cannot join the overlay network, even if IP reachability exists.

Why this answer

For a vEdge to establish a control connection with a vSmart controller, it must first authenticate with the vBond orchestrator using its certificate. This process provides the vEdge with the necessary information, including the vSmart's IP address and credentials to establish the DTLS control connection. IP reachability alone is insufficient.

Exam trap

The trap here is assuming that IP reachability to the vSmart controller is enough for the control connection, overlooking the mandatory authentication and certificate exchange with the vBond orchestrator.

141
MCQeasy

An engineer is configuring a new VLAN 100 on a switch. Which command must be used to create the VLAN?

A.vlan 100
B.switchport access vlan 100
C.vlan database
D.interface vlan 100
AnswerA

The global configuration command 'vlan 100' creates VLAN 100 and enters VLAN configuration mode, allowing optional parameters such as a name or MTU to be applied. This is the standard and correct method to create a VLAN on modern Cisco IOS switches, as it directly adds the VLAN to the switch's VLAN database and running configuration. Without this command, other VLAN-related commands have no VLAN to act upon.

Why this answer

The correct command to create a new VLAN on a Cisco IOS switch is 'vlan 100' entered in global configuration mode. This command creates VLAN 100 and enters VLAN configuration mode, allowing you to assign a name or other parameters. The other options either apply an existing VLAN to an interface, use a deprecated method, or create a switched virtual interface (SVI) for Layer 3 routing, none of which actually create the VLAN itself.

Exam trap

Cisco often tests the distinction between creating a VLAN and applying it to an interface, so candidates mistakenly choose 'switchport access vlan 100' thinking it both creates and assigns the VLAN, when in fact it only assigns an existing VLAN.

How to eliminate wrong answers

Option B is wrong because 'switchport access vlan 100' assigns an interface to VLAN 100, but it does not create the VLAN; if VLAN 100 does not exist, the command may fail or the interface will be in an inactive state. Option C is wrong because 'vlan database' is a legacy, deprecated command from older Catalyst OS (CatOS) and is not used in modern IOS-based switches; it does not create VLANs in the running configuration. Option D is wrong because 'interface vlan 100' creates a Layer 3 switched virtual interface (SVI) for routing, but it does not create the VLAN itself; the VLAN must already exist or be created separately before the SVI can be used.

142
MCQhard

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer wants to ensure that only routers with the correct key can form adjacencies, and that the key is not sent in clear text. Which command sequence correctly enables MD5 authentication on an interface?

A.ip ospf authentication-key <key> and ip ospf authentication
B.ip ospf authentication message-digest and ip ospf message-digest-key 1 md5 <key>
C.area 0 authentication message-digest and ip ospf message-digest-key 1 md5 <key>
D.ip ospf authentication null and ip ospf message-digest-key 1 md5 <key>
AnswerB

The interface-level command ip ospf authentication message-digest enables MD5 authentication for OSPF on that interface. The ip ospf message-digest-key command defines the key ID and MD5 key. Together, they satisfy the requirement to authenticate neighbors using MD5 without sending the key in clear text.

Why this answer

To enable MD5 authentication on a specific OSPF interface, you use the interface command ip ospf authentication message-digest and then define the key with ip ospf message-digest-key. This ensures that OSPF packets are authenticated with MD5 and the key is not transmitted in clear text, meeting the scenario's security requirement.

Exam trap

The trap here is confusing plaintext authentication with MD5, or using area-wide authentication when interface-level is required, which can leave other interfaces unprotected or misconfigured.

143
MCQhard

A network engineer is deploying a new Cisco Catalyst switch and must ensure that the management VLAN 50 is the only VLAN allowed on the trunk link to the distribution switch, while also ensuring that the native VLAN matches on both ends. The distribution switch is already configured with switchport trunk native vlan 999 and switchport trunk allowed vlan 50. Which configuration on the new switch will satisfy these requirements?

A.interface GigabitEthernet0/1 switchport mode dynamic desirable switchport trunk native vlan 999 switchport trunk allowed vlan 50
B.interface GigabitEthernet0/1 switchport mode trunk switchport trunk native vlan 999 switchport trunk allowed vlan 50
C.interface GigabitEthernet0/1 switchport mode trunk switchport trunk native vlan 50 switchport trunk allowed vlan 50
D.interface GigabitEthernet0/1 switchport mode trunk switchport trunk allowed vlan 50 switchport trunk native vlan 1
AnswerB

This configuration sets the port as a trunk, matches the native VLAN to 999, and restricts allowed VLANs to 50. It aligns with the distribution switch configuration, ensuring native VLAN consistency and limiting traffic to the management VLAN. This meets both requirements exactly.

Why this answer

To match the distribution switch, the new switch must be configured as a static trunk with native VLAN 999 and allowed VLAN 50. This ensures native VLAN consistency and restricts the trunk to only the management VLAN, preventing unnecessary traffic and security risks.

Exam trap

The trap here is overlooking the native VLAN mismatch that occurs if the native VLAN is not explicitly set to 999, or assuming that dynamic trunking will always form a trunk with a statically configured peer.

144
MCQhard

A network engineer is configuring a Cisco Catalyst switch to support a new wireless access point that will use 802.1X authentication with EAP-TLS. The switch port must be configured to allow multiple hosts, but only one host should be authenticated. Which command should be used to enable this behavior?

A.authentication host-mode multi-host
B.authentication host-mode multi-auth
C.authentication host-mode single-host
D.authentication host-mode multi-domain
AnswerA

Multi-host mode allows multiple hosts to connect to a single port, but only the first host is authenticated. Once that host is authenticated, all other hosts are granted access without individual authentication. This matches the scenario where multiple hosts are allowed but only one host should be authenticated, making it the correct command.

Why this answer

The requirement is to allow multiple hosts on a switch port while authenticating only one host. This is exactly the behavior of multi-host mode, where the first host authenticates and subsequent hosts are allowed without authentication. Multi-auth would authenticate each host individually, multi-domain is for voice and data domains, and single-host denies additional hosts.

Thus, multi-host mode is the correct choice.

Exam trap

The trap here is assuming that allowing multiple hosts always requires multi-auth mode, when multi-host mode is specifically designed for a single authentication for multiple devices.

145
MCQeasy

A network administrator is configuring a Cisco IOS router to support NAT overload for a small office. The inside network is 10.1.1.0/24, and the outside interface is GigabitEthernet0/1 with IP address 203.0.113.5. The administrator wants all inside hosts to share the outside interface address for internet access. Which command is required to define the NAT pool or interface used for translation?

A.ip nat inside destination list 1 interface GigabitEthernet0/1 overload
B.ip nat inside source list 1 pool MYPOOL overload
C.ip nat outside source list 1 interface GigabitEthernet0/1 overload
D.ip nat inside source list 1 interface GigabitEthernet0/1 overload
AnswerD

This command configures NAT overload, also known as Port Address Translation (PAT), using the outside interface's IP address for translation. The 'list 1' refers to an access list that defines the inside local addresses. The 'overload' keyword enables many-to-one translation by multiplexing inside addresses using port numbers. This is the correct way to configure NAT overload when using the interface address rather than a pool.

Why this answer

To configure NAT overload using the outside interface address, the correct command is 'ip nat inside source list 1 interface GigabitEthernet0/1 overload'. This command references an access list that identifies inside local addresses and translates them to the IP address of the specified interface, using port numbers to distinguish sessions. It is the standard method for enabling many inside hosts to share a single public IP address.

Exam trap

The trap here is confusing the direction of NAT (inside source versus outside source) and the use of an interface versus a pool, which can lead to incorrect translation entries.

146
MCQmedium

A network engineer is configuring a new Cisco IOS switch that will be deployed in a data center. The switch must forward traffic for VLAN 10 while ensuring that the native VLAN for all trunk ports is not susceptible to VLAN hopping attacks. The engineer decides to change the native VLAN from the default to an unused VLAN 999. Which command sequence correctly configures the native VLAN on a trunk port?

A.vlan 999 name NATIVE interface GigabitEthernet0/1 switchport mode trunk switchport trunk allowed vlan 999
B.interface GigabitEthernet0/1 switchport trunk encapsulation dot1q switchport trunk native vlan 999 switchport mode trunk
C.interface GigabitEthernet0/1 switchport mode trunk switchport trunk native vlan 999
D.interface GigabitEthernet0/1 switchport mode access switchport access vlan 999
AnswerC

This sequence enters interface configuration mode, sets the port to trunk mode, and assigns VLAN 999 as the native VLAN. This is the correct Cisco IOS syntax to change the native VLAN on a trunk port, mitigating VLAN hopping by using an unused VLAN.

Why this answer

The correct configuration requires entering interface configuration mode, setting the port to trunk mode, and then specifying the native VLAN with 'switchport trunk native vlan 999'. This ensures that untagged traffic is associated with an unused VLAN, reducing VLAN hopping risk. The other options either misconfigure the port mode or do not properly set the native VLAN.

Exam trap

The trap here is confusing the native VLAN with an allowed VLAN or an access VLAN, and forgetting to set the port to trunk mode first.

147
MCQhard

An engineer is deploying VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. Hosts in the same subnet are attached to different edge nodes. Which mechanism ensures that a host's default gateway MAC address is identical on every edge node while still allowing local forwarding?

A.A shared virtual MAC address is configured on the anycast SVI of every edge node in the fabric.
B.Each edge node uses a unique gateway MAC derived from its loopback0 address.
C.Edge nodes learn the gateway MAC from the fabric border node through VXLAN Group Policy Option headers.
D.The fabric control plane assigns a single gateway MAC that is flooded to edge nodes via LISP map-register messages.
AnswerA

The distributed anycast gateway uses the same virtual MAC on the anycast SVI of all edge nodes, so hosts see one consistent gateway identity regardless of attachment point. Each edge node can forward locally for hosts in its own subnet while the shared MAC preserves a stable default gateway, enabling seamless mobility and optimal forwarding without tromboning traffic to a central gateway.

Why this answer

In a Cisco SD-Access fabric, distributed anycast gateway requires the same virtual MAC address configured on the anycast SVI of every edge node. This shared identity lets hosts keep a consistent default gateway while each edge node forwards locally, avoiding hairpinning through a central gateway and supporting host mobility across the fabric.

Exam trap

The trap here is confusing the fabric control plane's LISP endpoint mappings with gateway MAC distribution, when the anycast gateway MAC is simply a locally configured virtual MAC shared across edge nodes.

148
MCQeasy

A network engineer is configuring a new Cisco IOS switch and needs to ensure that the management VLAN is properly secured. The engineer wants to restrict management access to only the IT department subnet 10.10.10.0/24. Which configuration should be applied to the VTY lines?

A.access-class 10 in
B.ip access-class 10 in
C.access-list 10 permit 10.10.10.0 0.0.0.255
D.ip access-group 10 in
AnswerA

The access-class command is used on VTY lines to filter incoming Telnet or SSH connections based on a standard or extended ACL. Applying 'access-class 10 in' with an ACL that permits 10.10.10.0/24 and denies all others restricts management access to the IT subnet. This is the correct configuration to meet the requirement.

Why this answer

To restrict management access to a specific subnet on Cisco IOS devices, you configure an ACL that permits that subnet and denies others, then apply it to the VTY lines using the access-class command. The access-class command filters incoming connections to the VTY lines. The correct syntax is 'access-class 10 in'.

This ensures that only hosts from the IT department subnet can establish management sessions, meeting the security requirement.

Exam trap

The trap here is confusing the interface command 'ip access-group' with the VTY line command 'access-class', which is used to filter management traffic.

149
MCQmedium

A network engineer is deploying a new branch office with a Cisco Catalyst 9300 switch. The switch must participate in the corporate OSPF domain but must not become a designated router (DR) or backup designated router (BDR) on any broadcast segment. Which configuration should the engineer apply to the switch's OSPF interface?

A.ip ospf priority 0
B.ip ospf network point-to-point
C.ip ospf database-filter all out
D.ip ospf cost 65535
AnswerA

Setting the OSPF interface priority to 0 makes the router ineligible to become DR or BDR on that broadcast segment. The priority value is carried in Hello packets and used in the DR election; a priority of 0 explicitly excludes the interface from the election, ensuring the switch remains a DROTHER and only forms adjacencies with the DR and BDR.

Why this answer

The OSPF interface priority determines which routers are eligible to become DR or BDR on a broadcast or non-broadcast multi-access segment. A priority of 0 makes the router ineligible for these roles, so it will remain a DROTHER regardless of its router ID. This is the correct way to ensure the switch never becomes DR or BDR while still participating in OSPF.

Exam trap

The trap here is assuming that any OSPF interface setting that alters adjacency behavior, such as changing the network type, will also prevent DR/BDR election without side effects.

150
Multi-Selecthard

A network engineer is implementing Cisco SD-Access and needs to configure the fabric to support both wired and wireless clients. Which two components are required to enable wireless integration in a Cisco SD-Access fabric? (Choose two.)

Select 2 answers
A.Fabric Border Node
B.Fabric Wireless Controller (WLC)
C.Fabric-enabled Access Point
D.Fabric Edge Node
E.Fabric Control Plane Node
AnswersB, C

The Fabric Wireless Controller (WLC) is essential for integrating wireless access points into the SD-Access fabric. It manages the wireless infrastructure and communicates with the fabric control plane to register wireless clients and their locations. The Fabric WLC uses VXLAN to tunnel client traffic to the fabric edge nodes. Without it, wireless clients cannot be part of the fabric's unified policy and segmentation. Thus, it is a required component for wireless integration.

Why this answer

To integrate wireless clients into a Cisco SD-Access fabric, you need a Fabric Wireless Controller (WLC) to manage the wireless infrastructure and a fabric-enabled Access Point to connect wireless clients to the fabric. The Fabric WLC communicates with the fabric control plane to register client locations, and the APs encapsulate traffic in VXLAN. Other components like Fabric Edge, Border, and Control Plane nodes are part of the fabric but are not specific to enabling wireless integration.

Exam trap

The trap here is assuming that any fabric node (like Edge or Border) is sufficient for wireless integration, when in fact specific wireless components (Fabric WLC and fabric-enabled APs) are required.

← PreviousPage 2 of 3 · 179 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Infrastructure questions.