Courseiva

CCNA Security Questions

75 of 161 questions · Page 2/3 · Security · Answers revealed

76
MCQhard

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect against DoS attacks. The router has a management plane that must remain accessible via SSH and SNMP, and a control plane that must process BGP and OSPF routing updates. The administrator applies a CoPP policy that rate-limits all traffic destined to the control plane to 1000 pps, except for traffic from trusted management subnets. After applying the policy, BGP sessions flap intermittently. What is the most likely cause?

A.The CoPP policy is rate-limiting BGP keepalives and updates, causing session timeouts.
B.The CoPP policy is applied to the data plane instead of the control plane, causing routing updates to be dropped.
C.The CoPP policy is incorrectly classifying SSH traffic as BGP, leading to rate limiting of SSH.
D.The CoPP policy is dropping SNMP traps, causing BGP to lose its peer state.
AnswerA

CoPP policies that apply a blanket rate limit to all control plane traffic can inadvertently throttle essential routing protocol messages like BGP keepalives and updates. If the rate limit is too low or not exempting BGP, sessions may flap due to missed keepalives or delayed updates. The policy must be fine-tuned to allow sufficient bandwidth for routing protocols.

Why this answer

CoPP policies must be carefully designed to avoid throttling critical control plane protocols. A blanket rate limit of 1000 pps may be insufficient for BGP, especially if there are many peers or frequent updates. BGP keepalives are sent every 60 seconds by default, but updates and other messages can burst.

If the policer drops these, sessions can flap. The correct approach is to create granular class-maps that match BGP and other routing protocols, and assign appropriate rates or exempt them from policing.

Exam trap

The trap here is assuming that a single rate limit for all control plane traffic is safe, without considering the specific needs of routing protocols like BGP.

77
MCQmedium

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive traffic. The router has a single physical interface Gi0/0/0 that carries both management SSH traffic and transit data traffic. The administrator wants the CoPP policy to apply only to traffic destined to the router's control plane, not to transit traffic. Which CoPP configuration element must be applied to achieve this?

A.Apply the policy-map to the Gi0/0/0 interface in the input direction using the service-policy command.
B.Apply the policy-map to the control-plane global configuration using the service-policy command under control-plane.
C.Apply the policy-map to the Gi0/0/0 interface in the output direction using the service-policy command.
D.Apply the policy-map to the management VRF using the service-policy command under vrf definition.
AnswerB

CoPP is implemented by attaching a policy-map to the control-plane interface using the service-policy command under the control-plane global configuration mode. This causes the policy to inspect only packets that are punted to the route processor, thereby protecting the control plane without affecting transit traffic on physical interfaces.

Why this answer

CoPP protects the route processor by policing traffic that is punted to the control plane. The policy-map must be attached to the control-plane interface with the service-policy command under the control-plane global configuration. Applying a policy to a physical interface or in the output direction would affect transit or outbound traffic, not the control-plane path.

Exam trap

The trap here is confusing interface-level service-policy application with the specialized control-plane interface used by CoPP.

78
Multi-Selectmedium

A network engineer is deploying 802.1X on Catalyst access switches with Cisco ISE as the RADIUS server. Some endpoints, such as printers and badge readers, do not support 802.1X supplicants. The design must allow these devices onto a restricted VLAN while still requiring authentication for laptops. Which TWO mechanisms should the engineer configure to achieve this? (Choose two.)

Select 2 answers
A.Configure MAB (MAC Authentication Bypass) on the switch ports to authenticate non-supplicant devices using their MAC address against ISE.
B.Apply an ACL that permits only MAC addresses in the OUI range of the printer vendor.
C.Configure the switch to use TACACS+ for endpoint authentication instead of RADIUS.
D.Disable 802.1X on the ports used by non-supplicant devices and assign them to a static VLAN.
E.Enable authentication order dot1x mab on the switch ports so the switch tries 802.1X first and falls back to MAB.
AnswersA, E

MAB allows devices without an 802.1X supplicant to be authenticated by their MAC address, which ISE validates against its identity store or profiling database. This lets printers and badge readers obtain limited access through the same port configuration that serves supplicant-capable laptops. MAB is the standard fallback for non-supplicant endpoints in Cisco 802.1X deployments.

Why this answer

The design needs one port configuration that serves both endpoint types. MAB authenticates non-supplicant devices by MAC address through ISE, and the authentication order of dot1x followed by mab ensures supplicant-capable laptops use 802.1X while printers and badge readers fall back to MAB. Together these provide differentiated, authenticated access without per-port manual reconfiguration.

Exam trap

The trap here is disabling 802.1X on ports used by non-supplicant devices, which removes authentication instead of adding a fallback method.

79
MCQeasy

A network administrator needs to securely manage a Cisco Catalyst switch remotely. The requirement is to encrypt all management traffic, including username and password, between the administrator's workstation and the switch. Which management protocol should be enabled on the switch to meet this requirement?

A.Telnet
B.HTTP
C.SNMPv2c
D.SSH version 2
AnswerD

SSH version 2 encrypts the entire management session, including authentication credentials and command output, using strong cryptography. Enabling SSHv2 on the switch and disabling Telnet ensures that remote CLI administration is confidential and integrity-protected. This directly satisfies the requirement that all management traffic between the administrator's workstation and the switch be encrypted, making SSHv2 the correct management protocol.

Why this answer

SSH version 2 encrypts the full management session, protecting credentials and commands in transit, which is exactly what the policy requires. Telnet and HTTP send data in cleartext, and SNMPv2c is neither encrypted nor intended for interactive CLI management. Enabling SSHv2 and disabling insecure protocols satisfies the encrypted remote administration requirement.

Exam trap

The trap here is overlooking that SNMPv2c management traffic is cleartext, so only SSHv2 among the choices provides encrypted interactive administration.

80
MCQhard

A security team is deploying Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. They notice that after applying a CoPP policy, OSPF adjacency with a directly connected neighbor flaps intermittently. Which action should the engineer take to resolve the issue while maintaining control plane protection?

A.Add a class-map matching OSPF traffic and associate it with a policer that has a higher committed information rate.
B.Configure OSPF authentication on the interface to reduce the volume of OSPF packets processed.
C.Remove the CoPP policy from the control plane and rely on ACLs on the management interface.
D.Change the CoPP policy to use a police rate of 8000 pps for all traffic classes.
AnswerA

OSPF hello and LSA traffic to the route processor must be permitted at a sufficient rate to maintain adjacency. Creating a class-map for OSPF and assigning a policer with an adequate CIR ensures control plane protection remains in place while allowing legitimate routing protocol traffic, which resolves the flapping caused by the default policer dropping OSPF packets.

Why this answer

CoPP uses class-maps and policy-maps to rate-limit traffic destined to the control plane. If the default policer for routing protocols is too low, OSPF hellos can be dropped, causing adjacency flaps. Creating a dedicated class for OSPF and assigning a policer with a higher committed information rate allows legitimate routing traffic while still protecting the route processor.

Exam trap

The trap here is assuming that removing CoPP or applying a blanket high rate is acceptable, rather than tuning the specific class that is being dropped.

81
MCQmedium

A company runs a Cisco IOS router as the WAN edge. The security team wants to detect and log traffic that matches a set of known malicious signatures without blocking legitimate traffic, while still dropping clearly malformed packets. Which technology should be deployed on the router?

A.Zone-Based Policy Firewall with inspect actions
B.IPsec VPN with AES-256 encryption between peers
C.Cisco IOS Intrusion Prevention System with signature categories set to alert
D.Control Plane Policing with a rate limit on management traffic
AnswerC

Cisco IOS IPS uses signatures to inspect traffic for known attack patterns and can be configured per signature or category to produce alerts rather than drops. This supports detection and logging of malicious traffic without blocking legitimate sessions, while malformed packets can still be dropped by specific signatures or by the IPS engine itself.

Why this answer

Cisco IOS IPS inspects packets against a signature database and can be tuned to alert on matching traffic instead of dropping it, which meets the detection-and-logging requirement while preserving legitimate flows. Malformed packets can be handled by specific drop signatures, giving the security team both visibility and selective enforcement on the WAN edge router.

Exam trap

The trap here is assuming any stateful or encrypted feature provides signature-based detection, when only IPS matches known attack patterns.

82
MCQhard

An engineer is configuring 802.1X on a Cisco Catalyst switch port where a PC is connected. The requirement is that if the authentication server becomes unreachable, the port should still allow the PC to send traffic in a restricted VLAN rather than being shut down. Which configuration meets this requirement?

A.authentication open
B.authentication host-mode multi-auth
C.authentication event server dead action authorize vlan 999
D.authentication event fail action authorize vlan 999
AnswerC

The authentication event server dead action authorize vlan command places the port into the specified restricted VLAN when the RADIUS server becomes unreachable. This allows the connected endpoint to send limited traffic instead of the port being placed in an unauthorized state, directly satisfying the requirement of continued but restricted access during a server outage.

Why this answer

When RADIUS becomes unreachable, the switch needs an explicit policy for the resulting dead-server condition. The authentication event server dead action authorize vlan command places the port into a designated restricted VLAN, allowing limited connectivity while the outage persists. Other commands address failed credentials, host count, or pre-authentication access, none of which provide the required restricted-VLAN fallback.

Exam trap

The trap here is mixing up the fail action, which reacts to rejected credentials, with the server dead action, which reacts to an unreachable authentication server.

83
MCQhard

A network security team is hardening a Cisco IOS-XE router that terminates IPsec VPN tunnels. They want to protect the control plane from CPU-intensive IKE and management traffic without dropping legitimate tunnel establishment packets. They decide to apply a Control Plane Policing (CoPP) policy. Which statement best describes how CoPP interacts with the forwarding plane and the control plane on this router?

A.CoPP can only classify traffic using NBAR2 deep packet inspection, so it cannot match IKE or SSH and requires a separate Zone-Based Firewall policy to protect the control plane.
B.CoPP uses MQC to classify traffic destined to the route processor and applies a policer in the control-plane host path, so it can rate-limit IKE and SSH without affecting transit traffic that is forwarded in hardware.
C.CoPP requires enabling 'ip cef distributed' and a PFC on the supervisor to offload policed control traffic to hardware, otherwise it cannot rate-limit IKE packets.
D.CoPP classifies and polices all packets entering any interface, including transit traffic, so it must be applied with 'service-policy input' on every physical interface to be effective.
AnswerB

CoPP leverages Modular QoS CLI to classify packets punted to the route processor, including IKE, SSH, and SNMP, and polices them in a dedicated control-plane host path. Because the policy is applied with 'service-policy input' under 'control-plane', it only affects traffic destined to the device itself, leaving hardware-forwarded transit traffic untouched. This matches the requirement to protect the CPU while preserving legitimate tunnel establishment.

Why this answer

CoPP applies MQC classification and policing to packets destined for the route processor via the control-plane host path, protecting the CPU from floods of IKE, SSH, or SNMP without touching hardware-forwarded transit traffic. It is configured once under 'control-plane', not per interface, and does not require distributed CEF or NBAR2 to match common control-plane protocols.

Exam trap

The trap here is assuming CoPP is an interface-level QoS policy that filters transit traffic instead of a control-plane host-path policer targeting only packets destined to the route processor.

84
MCQeasy

A network administrator is configuring a Cisco IOS XE router to protect against spoofed source addresses on an internal interface facing user subnets. The requirement is to drop packets whose source address does not match the routing table entry for the incoming interface. Which feature should be enabled?

A.Access Control List with the log keyword applied to the interface
B.IP Source Guard on the interface
C.Unicast Reverse Path Forwarding (uRPF) in strict mode on the interface
D.Dynamic ARP Inspection on the interface
AnswerC

Strict uRPF checks that the source address of an incoming packet is reachable via the same interface the packet arrived on, using the routing table. If the source is not reachable through that interface, the packet is dropped, which directly blocks spoofed source addresses from user subnets. This matches the requirement to validate source addresses against the routing table for the incoming interface.

Why this answer

Unicast RPF in strict mode checks the routing table for the source address of each incoming packet and verifies that the source is reachable via the same interface the packet arrived on. If not, the packet is dropped, which prevents source address spoofing. This is the standard IOS XE feature for validating source addresses on an interface against the routing table.

Exam trap

The trap here is confusing Layer 2 anti-spoofing features like IP Source Guard and Dynamic ARP Inspection with Layer 3 uRPF, which uses the routing table to validate sources on routed interfaces.

85
MCQhard

A security engineer is configuring CoPP (Control Plane Policing) on a Cisco router to protect the control plane from DoS attacks. The policy must rate-limit SSH traffic to 1 Mbps with a burst of 2000 bytes, and drop all other traffic destined to the control plane that exceeds a default rate. Which class-map and policy-map configuration is correct?

A.class-map match-all SSH match protocol ssh policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop
B.class-map match-all SSH match access-group name SSH_ACL policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop
C.class-map match-all SSH match protocol ssh policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop
D.class-map match-all SSH match protocol ssh policy-map COPP class SSH police 2000 1000000 conform-action transmit exceed-action drop
AnswerC

This is the correct CoPP configuration: `class-map match-all SSH` with `match protocol ssh` classifies SSH control-plane traffic, and the policy map `COPP` applies a police rate of 1,000,000 bps with a burst of 2000 bytes, dropping exceeding traffic. The `class-default` then polices all other control-plane traffic at 8000 bps, ensuring that no unclassified protocol can flood the CPU. The syntax and parameters are correctly ordered (rate in bps, burst in bytes), providing comprehensive control-plane protection.

Why this answer

It uses the 'match protocol ssh' class-map to identify SSH traffic, applies a police rate of 1,000,000 bps (1 Mbps) with a burst of 2000 bytes, and includes a class-default with a police rate of 8000 bps to drop all other control-plane traffic exceeding a default rate. This matches the requirement to rate-limit SSH and drop other traffic that exceeds a default rate, which is a common CoPP best practice to protect the control plane.

Exam trap

Cisco often tests the requirement for a class-default policy in CoPP to drop all other traffic, and the trap here is that candidates may forget that without it, unmatched traffic is permitted by default, or they may confuse the order of police parameters (rate vs. burst).

How to eliminate wrong answers

Option A is wrong because it lacks a class-default policy; without it, any traffic not matching the SSH class is implicitly permitted, failing to drop other traffic exceeding a default rate. Option B is wrong because it uses 'match access-group name SSH_ACL' instead of 'match protocol ssh', which is less efficient and not the direct method for matching SSH protocol traffic; also, the class-default police rate of 8000 is correct, but the match method is incorrect for the requirement. Option D is wrong because it swaps the police parameters: the first value (2000) is the burst size and the second (1000000) is the rate, but the correct syntax is 'police rate burst', so this would apply a rate of 2000 bps and a burst of 1,000,000 bytes, which does not meet the 1 Mbps rate requirement.

86
MCQeasy

A security team wants to protect a web application hosted behind a Cisco IOS router from cross-site scripting and SQL injection attacks without modifying the application itself. Which Cisco IOS feature is designed for this purpose?

A.Zone-Based Policy Firewall
B.IPsec VPN with AES encryption
C.Cisco IOS IPS with signature-based inspection
D.Control Plane Policing
AnswerC

Cisco IOS Intrusion Prevention System inspects packet payloads against signatures and can detect and drop application-layer attacks such as cross-site scripting and SQL injection. Because it examines the content of HTTP requests, it can block malicious patterns without any change to the hosted application, matching the requirement to protect the web app transparently.

Why this answer

Detecting and blocking application-layer attacks like cross-site scripting and SQL injection requires payload inspection, which is what Cisco IOS IPS provides through its signature set. Firewalls, CoPP, and IPsec operate at other layers and cannot identify malicious HTTP content, so signature-based IPS is the appropriate feature when the application itself cannot be modified.

Exam trap

The trap here is confusing stateful firewall policy, which permits or denies flows, with intrusion prevention, which inspects payload content for attack signatures.

87
MCQmedium

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and NTP. The requirement is to protect the route processor from excessive BGP keepalive traffic while still allowing all legitimate BGP peering. Which CoPP module should the administrator use to classify and police this traffic before the policy is applied to the control plane?

A.A class map that matches BGP traffic using an ACL or NBAR, referenced by a policy map, which is then applied with the service-policy command under control-plane configuration mode.
B.A route map applied inbound on the BGP neighbor session that sets a lower precedence for keepalive packets.
C.A class map referenced by a policy map that is applied outbound on the WAN interface toward the BGP peer.
D.An access list applied directly to the physical interface facing the BGP peer using the ip access-group command.
AnswerA

CoPP on IOS XE uses a modular QoS CLI structure: class maps identify control-plane traffic, a policy map defines policing actions, and the policy is attached to the control plane with service-policy under control-plane mode. Matching BGP via ACL or NBAR lets the administrator police keepalives while permitting other BGP flows, which satisfies the stated requirement.

Why this answer

Control Plane Policing requires a modular QoS configuration: class maps to identify traffic, a policy map to define policer actions, and the service-policy command applied under control-plane configuration mode. This structure allows BGP keepalives to be matched and policed while other traffic is handled separately, directly protecting the route processor as the scenario requires.

Exam trap

The trap here is assuming a route map or interface ACL can police traffic destined to the route processor, when CoPP specifically requires a policy map attached to the control plane.

88
MCQmedium

An engineer is configuring a Cisco IOS XE switch to secure the management plane. The requirement is to allow SSH only from the management subnet 10.10.10.0/24 and block all other management protocols such as Telnet and HTTP. Which configuration approach best meets this requirement?

A.Configure an ACL on the management VLAN SVI to deny Telnet and HTTP, and rely on the default transport input all on the VTY lines.
B.Enable AAA with a local database and configure privilege levels so that only users from 10.10.10.0/24 can log in.
C.Apply an ACL to the VTY lines with transport input ssh and configure the ACL to permit 10.10.10.0/24 only.
D.Configure ip http secure-server, disable ip http server, and apply an ACL to the VTY lines that permits any source using SSH.
AnswerC

Combining transport input ssh on the VTY lines with an access-class ACL that permits only 10.10.10.0/24 restricts remote management to SSH from the management subnet. Telnet and other line-based protocols are refused because transport input is limited to ssh, and non-permitted source addresses are dropped by the ACL before they reach the VTY lines, satisfying both requirements.

Why this answer

The VTY lines control remote management access. Setting transport input ssh disables Telnet and other line protocols, while an access-class ACL applied to the VTY lines filters source addresses before login. Permitting only 10.10.10.0/24 satisfies the subnet restriction.

Together these settings secure the management plane by limiting both the protocol and the source of administrative connections.

Exam trap

The trap here is assuming that disabling HTTP and Telnet on the web server alone secures management access, when VTY line transport and access-class controls are what actually restrict SSH sources.

89
MCQmedium

A network administrator is configuring a Cisco IOS router to terminate a site-to-site IPsec VPN with a remote peer that uses dynamic public IP addressing. The administrator wants the router to accept IKE negotiations from any peer that presents a valid pre-shared key and matches a specific protected subnet. Which configuration element is required to support this?

A.A dynamic crypto map entry referenced by a static crypto map, with the remote peer address set to 0.0.0.0.
B.A static crypto map with set peer 0.0.0.0 and a wildcard pre-shared key on the local router.
C.An IKEv2 profile with match identity remote address 0.0.0.0 and a certificate map for peer authentication.
D.A GRE tunnel with IPsec transport mode protecting the tunnel endpoints and dynamic routing over the tunnel.
AnswerA

When the remote peer has an unknown or changing IP address, the headend uses a dynamic crypto map entry with no set peer address so it can accept IKE proposals from any source. A static crypto map references the dynamic map with the set crypto map dynamic command, allowing the router to learn the peer address from the incoming negotiation and apply the correct transform set and ACL.

Why this answer

To accept IPsec negotiations from a peer whose IP address is not known in advance, the headend uses a dynamic crypto map entry that has no configured peer address. A static crypto map references it, so incoming IKE negotiations can be matched, the peer address learned, and the appropriate transform set and ACL applied to build the tunnel.

Exam trap

The trap here is thinking that a wildcard pre-shared key alone allows any peer, when the crypto map must also be dynamic to learn the unknown peer address.

90
Multi-Selecthard

A network security engineer is deploying Cisco TrustSec in a campus network. The engineer wants to implement Security Group Tagging (SGT) and enforce policies based on SGTs. Which two mechanisms can be used to propagate SGTs between network devices? (Choose two.)

Select 2 answers
A.RADIUS Change of Authorization (CoA) with SGT attributes
B.Inline tagging using Cisco Metadata (CMD) in the Ethernet frame
C.Native tagging (inline tagging) within the Ethernet frame
D.SGT Exchange Protocol (SXP)
E.IPsec Encapsulating Security Payload (ESP) with SGT extension
AnswersC, D

Native tagging, also known as inline tagging, inserts the SGT into the Ethernet frame using the Cisco TrustSec header. This allows switches and routers that support TrustSec hardware to read the SGT directly from the frame and enforce policies without needing an external mapping protocol. It is the preferred method for high-performance SGT propagation in the campus.

Why this answer

SGTs can be propagated between network devices using two primary mechanisms: native tagging (inline tagging) where the SGT is embedded in the Ethernet frame, and SXP where the SGT bindings are exchanged via a control-plane protocol. These methods allow enforcement points to apply Security Group ACLs based on the source SGT.

Exam trap

The trap here is confusing RADIUS CoA with SGT propagation, when CoA is only for session authorization changes.

91
MCQeasy

A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote access using SSL VPN. The requirement is to allow users to connect via a web browser and access internal web applications without installing a client. Which feature should the administrator configure?

A.Configure 'ip http server' and 'ip http secure-server' to allow web access to internal applications.
B.Configure 'webvpn' with 'enable' and set up a context with a gateway and a port-forward or URL list.
C.Configure 'crypto ssl server' and 'crypto ssl client' policies for the SSL VPN.
D.Configure 'crypto isakmp policy' and 'crypto ipsec transform-set' for remote access.
AnswerB

Cisco SSL VPN (WebVPN) allows clientless access through a browser. Enabling 'webvpn' and configuring a context with a gateway provides the entry point, while URL lists or port-forwarding define accessible resources. This meets the requirement for browser-based access without a client. It is the standard configuration for clientless SSL VPN on Cisco IOS.

Why this answer

Clientless SSL VPN on Cisco IOS is configured using the 'webvpn' feature. Enabling 'webvpn' and creating a context with a gateway, along with URL lists or port-forwarding, allows users to access internal web applications through a browser without a client. Other options either require a client or do not provide VPN functionality.

Exam trap

The trap here is confusing the router's HTTP management server with the WebVPN feature, or assuming IPsec can provide clientless access.

92
Multi-Selectmedium

A network engineer is implementing MACsec on a Cisco Catalyst switch to secure Layer 2 traffic between two campus distribution switches. Which two statements accurately describe MACsec operation on Cisco platforms? (Choose two.)

Select 2 answers
A.MACsec can secure traffic end-to-end between two hosts separated by multiple Layer 3 hops.
B.MACsec uses the MACsec Key Agreement (MKA) protocol to negotiate and distribute session keys between peers.
C.MACsec requires the use of IKEv2 to establish the security association between switches.
D.MACsec encrypts the entire IP packet including the original source and destination IP addresses.
E.MACsec provides hop-by-hop encryption and integrity checking on Ethernet frames between directly connected devices.
AnswersB, E

MKA is the control protocol that establishes the secure association between MACsec peers, electing a key server and distributing the secure association key used for encryption. It runs over EAPOL frames and is fundamental to how MACsec maintains and refreshes cryptographic material on a link.

Why this answer

MACsec is a Layer 2 hop-by-hop security standard that encrypts Ethernet frames and validates integrity between directly connected devices. The MKA protocol handles key negotiation and distribution, electing a key server and refreshing keys. It does not provide end-to-end protection across Layer 3 hops and does not rely on IKEv2, which belongs to the IPsec suite.

Exam trap

The trap here is conflating MACsec with IPsec by assuming MACsec provides end-to-end protection or uses IKEv2 for key negotiation.

93
MCQhard

A network security team is deploying Cisco TrustSec in a data center environment. They want to assign Security Group Tags (SGTs) to traffic based on user identity and device type without relying on IP addresses or VLANs. The team plans to use inline tagging on Cisco Nexus switches that support hardware-based SGACL enforcement. Which statement correctly describes how inline tagging propagates SGT information?

A.The SGT is inserted into the Layer 2 frame using Cisco Metadata (CMD) fields, allowing downstream devices to enforce SGACLs without reclassification.
B.The SGT is encoded in the DSCP field of the IP header, enabling enforcement at any Layer 3 device along the path.
C.The SGT is stored in the ARP cache of each device, and devices query a central server to resolve SGTs for enforcement decisions.
D.The SGT is propagated through a proprietary GRE tunnel between all TrustSec-capable devices, encapsulating the original frame.
AnswerA

Inline tagging uses Cisco Metadata to carry the SGT value within the Ethernet frame itself. Downstream devices that support CMD can read the tag and enforce SGACLs directly, eliminating the need to reclassify traffic based on IP or user identity at each hop, which preserves the original classification throughout the path.

Why this answer

Inline tagging in Cisco TrustSec inserts the SGT directly into the Ethernet frame using Cisco Metadata fields. This allows downstream devices to enforce SGACLs based on the original classification without needing to reclassify traffic, preserving security group integrity across the network path.

Exam trap

The trap here is assuming SGTs are carried in IP headers like DSCP, when in reality they are embedded in Layer 2 frames using Cisco Metadata.

94
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive CPU utilization due to malicious traffic. The engineer wants to ensure that BGP, SSH, and SNMP traffic are rate-limited appropriately. After applying the CoPP policy, the engineer notices that BGP sessions are flapping. Which action should the engineer take to resolve the issue while maintaining protection?

A.Remove the CoPP policy from the control plane and apply it only to the data plane.
B.Configure a separate class-map for BGP and assign it to a higher priority queue in the policy-map.
C.Enable BGP graceful restart to prevent session flapping during CoPP drops.
D.Increase the rate limit for the class-map that matches BGP traffic.
AnswerD

BGP sessions flapping indicate that the CoPP policy is dropping legitimate BGP keepalives or updates due to an overly restrictive rate limit. Increasing the rate limit for the BGP class-map allows sufficient BGP control traffic to reach the route processor while still protecting against excessive traffic. This balances protection with operational stability.

Why this answer

BGP session flapping after applying CoPP typically occurs because the policer is dropping legitimate BGP control packets. The correct fix is to increase the rate limit for the BGP traffic class so that keepalives and updates are not dropped, while still protecting the control plane from excessive traffic. Other options either do not address the rate limit or suggest inappropriate mechanisms.

Exam trap

The trap here is thinking that CoPP uses queuing or that BGP graceful restart can prevent flapping caused by policer drops, when the real issue is an insufficient rate limit.

95
MCQeasy

A network engineer is configuring a Cisco Catalyst switch to mitigate VLAN hopping attacks. The switch has multiple access ports assigned to VLAN 10 and trunk ports connecting to other switches. The engineer wants to ensure that an attacker cannot send double-tagged frames to hop into another VLAN. Which action should the engineer take on all access ports?

A.Configure the access ports with the switchport mode access command and enable BPDU Guard.
B.Configure the access ports with the switchport mode trunk command and set the native VLAN to an unused VLAN.
C.Configure the access ports with the switchport mode access command and disable Dynamic Trunking Protocol (DTP) on them.
D.Configure the access ports with the switchport mode access command and assign them to the native VLAN.
AnswerC

Setting access ports to access mode and disabling DTP prevents the port from negotiating a trunk, which is a primary vector for VLAN hopping attacks. Attackers can exploit DTP to form a trunk and gain access to all VLANs. By explicitly configuring the port as access and disabling DTP with 'switchport nonegotiate', the port will not trunk. This is a recommended best practice.

Why this answer

To mitigate VLAN hopping, access ports should be explicitly configured as access ports and DTP should be disabled to prevent trunk negotiation. Attackers can use DTP to negotiate a trunk and then send tagged frames to access other VLANs. Disabling DTP with 'switchport nonegotiate' on access ports prevents this.

The other options either do not address the attack or are misconfigurations.

Exam trap

The trap here is thinking that BPDU Guard or native VLAN changes on access ports prevent VLAN hopping, when the primary mitigation is disabling DTP and forcing access mode.

96
MCQmedium

A network engineer is deploying Cisco TrustSec in a campus network. The security team requires that the Security Group Tag (SGT) be carried inside the Ethernet frame so that switches in the path can enforce group-based policy without inline tagging. Which Cisco-proprietary protocol should be enabled on the uplinks between the access and distribution switches to achieve this?

A.Layer 2 Tunneling Protocol (L2TP)
B.Cisco TrustSec CMD (Cisco Meta Data)
C.802.1AE MACsec
D.Cisco TrustSec SXP
AnswerB

Cisco Meta Data (CMD) is the TrustSec inline tagging mechanism that inserts the SGT into a reserved field of the Ethernet frame. Enabling CMD on the inter-switch uplinks allows each hop to read the tag and apply Security Group ACLs without re-classifying based on IP address, which is exactly the inline tagging behaviour the scenario requires.

Why this answer

Inline SGT tagging between TrustSec-capable switches is accomplished with Cisco Meta Data, which places the Security Group Tag into the Ethernet frame so each hop can enforce Security Group ACLs. MACsec provides encryption rather than tag transport, SXP propagates IP-to-SGT mappings across non-TrustSec hops, and L2TP is unrelated to TrustSec tagging.

Exam trap

The trap here is assuming that any Layer 2 security feature on the uplink, such as MACsec, will also carry the SGT for TrustSec policy enforcement.

97
MCQhard

A network engineer is configuring a Zone-Based Firewall on a Cisco IOS XE router. The design requires that traffic from the inside zone to the outside zone be inspected, that return traffic be permitted, and that traffic from the outside zone to the inside zone be dropped unless it matches an existing session. Which configuration element is required to achieve this behavior?

A.A class map that matches on the outside interface and an ACL that permits established sessions
B.A zone pair with a service policy that applies inspect to inside-to-outside traffic
C.A policy map with the pass action applied to the outside-to-inside zone pair
D.A zone pair with a service policy that applies drop to the outside-to-inside zone pair
AnswerB

Zone-Based Firewall uses zone pairs to define directional policy between zones. Applying a service policy with the inspect action on the inside-to-outside zone pair creates stateful inspection, so return traffic from the outside zone is automatically permitted. Without this inspect action, the router treats the zones as separate and return traffic would be dropped by the default inter-zone deny.

Why this answer

Zone-Based Firewall policies are applied to zone pairs and are directional. Inspecting traffic from the inside zone to the outside zone creates session state, which allows return traffic from outside to inside automatically. Without the inspect action on that zone pair, the default inter-zone deny would block return traffic, so the inspect policy is the essential element.

Exam trap

The trap here is thinking that a drop policy on the outside-to-inside zone pair is needed, when in ZBF the inspect action on the reverse direction handles return traffic automatically.

98
MCQhard

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router. The router runs OSPF, BGP, SSH management, and SNMP polling. After applying a CoPP policy, the administrator notices that OSPF adjacencies flap intermittently while BGP and SSH remain stable. Which action should the administrator take to resolve the flapping while maintaining control plane protection?

A.Remove the CoPP policy entirely and rely on interface ACLs for control plane protection.
B.Increase the committed information rate (CIR) for the OSPF class in the CoPP policy.
C.Apply the CoPP policy only to the BGP and SSH classes, leaving OSPF unpoliced.
D.Configure OSPF authentication to reduce the number of OSPF packets processed by the route processor.
AnswerB

OSPF hellos and LSAs are being dropped because the policer for the OSPF class is too restrictive. Increasing the CIR for that class allows more OSPF control traffic to reach the route processor, stabilizing adjacencies. This maintains protection for other protocols while addressing the specific queue that is over-policing legitimate OSPF packets during normal adjacency formation and maintenance.

Why this answer

OSPF adjacency flapping after applying CoPP indicates that the policer for the OSPF control plane class is dropping legitimate hello or LSA packets. Increasing the CIR for that class allows the required OSPF traffic to be punted to the route processor. This preserves control plane protection for other protocols while resolving the flapping, which is a common tuning step in CoPP deployments.

Exam trap

The trap here is thinking that CoPP either works or does not, when in reality each class needs to be tuned to match the protocol's legitimate traffic profile.

99
MCQhard

A network administrator must protect the control plane of a Cisco IOS XE router that peers BGP with an ISP. The requirement is to rate-limit specifically ARP and IPv4 TTL-expired packets destined to the route processor while allowing all other transit traffic to be forwarded normally. Which CoPP implementation step is required to achieve this?

A.Enable Control Plane Protection with a port-filter policy that drops ARP and TTL-expired packets before they reach the route processor.
B.Apply an ACL directly to the BGP peer interface inbound to deny ARP and TTL-expired packets, then rely on uRPF to drop remaining control-plane traffic.
C.Configure an MQC service policy with service-policy type control-plane on the BGP-facing interface to rate-limit ARP and TTL-expired packets.
D.Create an ACL matching ARP and TTL-expired traffic, reference it in a class-map of type control-plane, define a policy-map with police actions, and attach it with service-policy type control-plane in global configuration.
AnswerD

CoPP on IOS XE requires classifying control-plane-bound traffic with a class-map of type control-plane, then applying policing in a policy-map that is attached globally with service-policy type control-plane. An ACL matching ARP and TTL-expired packets provides the specific match, and transit traffic is unaffected because CoPP only inspects packets punted to the route processor.

Why this answer

CoPP uses MQC with a class-map of type control-plane to identify traffic punted to the route processor, a policy-map to police that class, and a global service-policy type control-plane attachment. Matching ARP and TTL-expired packets with an ACL inside the class-map isolates exactly the traffic to be rate-limited, while transit traffic continues to be forwarded in hardware and is never inspected by CoPP.

Exam trap

The trap here is attaching the control-plane service policy to an interface instead of globally, which would police forwarded traffic rather than packets punted to the route processor.

100
MCQhard

A network engineer is configuring a Cisco ASA firewall with a site-to-site VPN to a remote peer. The engineer wants to ensure that only specific subnets are encrypted and that traffic from other subnets is not sent through the tunnel. Which configuration element defines the traffic that will be protected by the VPN?

A.The IKEv2 proposal and policy settings.
B.The crypto ACL (access list) referenced in the crypto map.
C.The tunnel-group configuration for the remote peer.
D.The group-policy applied to the VPN connection.
AnswerB

The crypto ACL defines the interesting traffic that will be encrypted and sent through the VPN tunnel. It specifies source and destination subnets that are permitted, and only matching traffic is protected. On Cisco ASA, this ACL is referenced in the crypto map entry. It is the correct element to control which subnets are encrypted, as required by the scenario.

Why this answer

In a site-to-site VPN on Cisco ASA, the crypto ACL (also called the interesting traffic ACL) defines which source and destination subnets are encrypted and sent through the tunnel. Only traffic matching this ACL is protected; other traffic is sent in clear text or dropped based on interface ACLs. The tunnel-group, group-policy, and IKEv2 proposals handle peer authentication and encryption parameters, but not traffic selection.

Exam trap

The trap here is assuming that the tunnel-group or IKEv2 proposals define the traffic to be encrypted, when in fact the crypto ACL is the sole determinant of interesting traffic.

101
MCQhard

A security team wants to protect a campus network from MAC flooding attacks that could overflow the CAM table on access switches. The requirement is to limit the number of source MAC addresses learned per switch port and to automatically err-disable a port when the limit is exceeded, while still allowing a VoIP phone and a PC on the same port. Which configuration approach meets these requirements?

A.Configure port security with the maximum parameter, sticky learning, and violation shutdown on each access port.
B.Configure storm control for unicast traffic at a low threshold on each access port.
C.Configure port security with the maximum parameter, sticky learning, and violation restrict on each access port.
D.Enable BPDU Guard and Root Guard on all access ports to block MAC flooding attempts.
AnswerA

Port security with a maximum MAC count enforces the learning limit, sticky learning dynamically records MACs into the running configuration, and the shutdown violation mode err-disables the port when the limit is exceeded. This directly satisfies the requirement to cap learned MAC addresses and automatically disable offending ports.

Why this answer

Port security limits the source MAC addresses that can be learned on a switch port. Setting a maximum value caps how many MACs are accepted, sticky learning stores dynamically learned addresses in the configuration, and the shutdown violation mode err-disables the port upon violation. Together these features neutralize MAC flooding while permitting a phone and PC by allowing at least two MACs.

Exam trap

The trap here is selecting the restrict violation mode, which logs and drops but never err-disables the port, failing the explicit requirement for automatic shutdown.

102
MCQmedium

A network engineer is implementing a Zone-Based Firewall (ZBFW) on a Cisco IOS XE router. The router has three interfaces: inside (GigabitEthernet0/0), outside (GigabitEthernet0/1), and DMZ (GigabitEthernet0/2). The security policy requires that traffic from the inside zone to the outside zone be inspected, traffic from the outside zone to the DMZ be allowed only for HTTP and HTTPS, and all other traffic between zones be denied by default. Which configuration step is essential to achieve this policy?

A.Configure a single zone pair from inside to outside with an inspect policy and rely on implicit permit for other traffic.
B.Create a class map that matches HTTP and HTTPS traffic and apply it as a policy to the outside interface.
C.Apply an ACL to the outside interface to permit HTTP and HTTPS to the DMZ and deny all other traffic.
D.Assign interfaces to zones and create zone pairs with inspect policies for inside-to-outside and outside-to-DMZ.
AnswerD

This is the fundamental ZBFW configuration. Interfaces must be assigned to zones, and zone pairs define the direction of traffic flow. For traffic to be allowed, a zone pair must exist with a policy that inspects or passes traffic. The default action for inter-zone traffic is drop, so explicit policies are needed. This step is essential to meet the requirements of inspecting inside-to-outside and allowing only HTTP/HTTPS from outside to DMZ.

Why this answer

Zone-Based Firewall requires interfaces to be assigned to zones, and traffic between zones is controlled by zone pairs. Each zone pair has a policy that defines actions like inspect, pass, or drop. By default, inter-zone traffic is dropped, so explicit policies are needed for allowed traffic.

The correct configuration involves creating zones, assigning interfaces, and defining zone pairs with appropriate inspect policies for inside-to-outside and outside-to-DMZ, ensuring the default deny posture.

Exam trap

The trap here is thinking that an ACL or a single zone pair can satisfy all requirements, but ZBFW requires explicit zone pairs for each direction and default deny between zones.

103
MCQhard

A security architect is designing a network where endpoint identity and group membership must follow users and devices across both wired and wireless networks, and policy enforcement must be consistent regardless of VLAN or IP subnet. Which Cisco solution provides this identity-based, group-based access control?

A.Cisco AnyConnect with posture assessment only
B.Cisco Umbrella with DNS-layer security and SIG
C.Cisco TrustSec with Security Group Tags and Cisco ISE
D.Cisco Stealthwatch with NetFlow analytics
AnswerC

Cisco TrustSec assigns Security Group Tags to users and devices based on identity and group membership determined by Cisco ISE, and enforcement uses those tags rather than IP addresses or VLANs. This allows consistent policy across wired and wireless domains. Because tags travel with the traffic, access control remains intact even when subnets or VLANs change.

Why this answer

Cisco TrustSec uses Security Group Tags derived from identity and group information, typically populated by Cisco ISE, to enforce policy independent of IP addresses and VLANs. Because the tags travel with the traffic, consistent access control is maintained across wired and wireless networks, which matches the architect's requirements.

Exam trap

The trap here is confusing visibility and analytics products with enforcement technologies that actually tag and control traffic by identity.

104
MCQmedium

A company has deployed a Cisco ASA firewall in transparent mode. The internal network uses VLAN 10 and the external network uses VLAN 20. The ASA is configured with two bridge groups: BVI 10 for inside and BVI 20 for outside. The security policy must allow HTTPS traffic from inside to outside. Which access-list entry is correct?

A.access-list INSIDE extended permit tcp 192.168.1.0 255.255.255.0 any eq 443 access-group INSIDE in interface inside
B.access-list GLOBAL extended permit ip 192.168.1.0 255.255.255.0 any
C.access-list GLOBAL extended permit tcp any any eq 443
D.access-list GLOBAL extended permit tcp 192.168.1.0 255.255.255.0 any eq 443
AnswerD

This is the correct configuration for transparent mode. The global access-list is the only ACL applied to a transparent ASA, and it evaluates all traffic crossing the Layer 2 bridge. The rule precisely matches the requirement: source is the inside subnet 192.168.1.0/24, destination is any, and service is TCP 443 (HTTPS), thus permitting only outbound HTTPS from the inside network while implicitly denying everything else. This adheres to least-privilege access control and is applied globally so that traffic from any interface, including the inside, is filtered consistently.

Why this answer

In transparent mode, the ASA acts as a Layer 2 bridge, so traffic must be permitted by a global access list applied to the bridge group virtual interface (BVI). Option D correctly uses the GLOBAL access list to permit TCP traffic from the inside subnet (192.168.1.0/24) to any destination on port 443 (HTTPS), which satisfies the security policy.

Exam trap

Cisco often tests the misconception that transparent mode uses interface-based ACLs like routed mode, when in fact transparent mode requires global ACLs applied to the BVI, and the 'GLOBAL' keyword is mandatory for Layer 2 traffic filtering.

How to eliminate wrong answers

Option A is wrong because in transparent mode, access lists are applied globally to the BVI, not per interface; the 'access-group INSIDE in interface inside' command is invalid in transparent mode. Option B is wrong because it permits all IP traffic (including non-HTTPS) and uses the 'ip' protocol instead of 'tcp', which violates the requirement to allow only HTTPS. Option C is wrong because it permits any source (including untrusted external hosts) to initiate HTTPS traffic, which does not restrict traffic from inside to outside as required.

105
MCQhard

A network engineer is configuring control plane policing (CoPP) on a Cisco IOS XE router that peers BGP with two service providers and is managed over SSH from a jump host. After applying a new policy-map, the engineer notices that BGP sessions remain up but SSH logins intermittently time out during traffic spikes. Which action should the engineer take to resolve the SSH timeouts while preserving the CoPP protection model?

A.Add a class-map matching TCP port 22 traffic and attach it to the policy-map with an appropriate rate and conform/exceed actions.
B.Remove the service-policy from the control plane and rely on QoS on the data plane instead.
C.Increase the BGP class rate and move the SSH class into the BGP class-map.
D.Configure an ACL that permits only the jump host's IP and apply it as the match for the class-default class.
AnswerA

SSH traffic must be explicitly classified so CoPP can rate-limit it separately instead of letting it fall into a default or catch-all class that may be policed aggressively. Adding a TCP port 22 class with a suitable rate and transmit action preserves protection while guaranteeing management access. This is the standard CoPP design practice for management protocols.

Why this answer

CoPP works by classifying punted control-plane traffic into classes and applying per-class policers. If SSH is not explicitly matched, it is handled by class-default, which is often policed conservatively. Creating a dedicated class matching TCP port 22 with an adequate rate and a conform action of transmit ensures interactive management traffic survives bursts while BGP and other protocols stay protected.

Exam trap

The trap here is treating CoPP as an all-or-nothing filter and removing it, rather than recognizing that unclassified management traffic is the real cause of the timeouts.

106
MCQmedium

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The administrator wants to protect the route processor from excessive control-plane traffic while still allowing legitimate routing protocol and management traffic. The administrator creates a class map that matches BGP, OSPF, and SSH traffic and applies a police action with a committed information rate. Which additional configuration element is required to complete the CoPP implementation?

A.Configure a route map that matches the control-plane protocols and reference it in the policy map.
B.Apply the policy map to all physical interfaces using the service-policy input command under interface configuration mode.
C.Apply the policy map to the control plane using the service-policy input command under control-plane configuration mode.
D.Enable NetFlow on the router to export control-plane traffic statistics to a collector.
AnswerC

CoPP requires a policy map to be attached to the control plane with service-policy input under control-plane configuration mode. Without this attachment, the class maps and policy map exist but are not enforced on control-plane traffic, leaving the route processor unprotected.

Why this answer

CoPP is implemented by defining class maps to identify control-plane traffic, a policy map to apply actions such as police, and then attaching the policy map to the control plane with service-policy input under control-plane configuration mode. Without that attachment, the policy is never applied to control-plane traffic, so the route processor remains vulnerable to excessive protocol or management packets.

Exam trap

The trap here is assuming that applying a policy map to physical interfaces protects the control plane, when CoPP specifically requires attachment under control-plane configuration mode.

107
Multi-Selectmedium

A network architect is designing a Cisco SD-Access fabric. The security team requires that endpoint traffic be segmented into separate virtual networks and that group-based policy be enforced without using traditional VLANs or ACLs between fabric edge nodes. Which two Cisco SD-Access fabric components or features support these requirements? (Choose two.)

Select 2 answers
A.Cisco TrustSec Security Group Tags (SGTs) enforced by the fabric
B.Virtual Extensible LAN (VXLAN) data plane encapsulation with fabric VNIs
C.Private VLANs configured on every fabric edge switch port
D.Dynamic ARP Inspection on all fabric underlay links
E.Extended ACLs applied inbound on every fabric edge uplink
AnswersA, B

SGTs carry group-based policy information in the VXLAN header, allowing the fabric to enforce scalable group-based access control across edge nodes without hop-by-hop ACLs. This satisfies the requirement for group-based policy enforcement that is independent of VLAN or IP subnet boundaries in the SD-Access fabric.

Why this answer

SD-Access uses VXLAN encapsulation with a fabric VNI per virtual network to provide data-plane segmentation, and it carries Security Group Tags so that group-based policy can be enforced consistently across fabric edge nodes. Together these deliver segmentation and policy without depending on VLANs or hop-by-hop ACLs between edge switches.

Exam trap

The trap here is assuming that legacy Layer 2 isolation tools such as private VLANs or extended ACLs can deliver fabric-wide segmentation and group policy in SD-Access.

108
MCQhard

A network administrator is configuring a Cisco IOS XE router to act as a VPN headend with IKEv2. The security policy requires that the router authenticate to peers using a certificate from a corporate PKI, and that peers authenticate using EAP-MSCHAPv2. Which IKEv2 authentication configuration on the headend meets these requirements?

A.Configure 'authentication local rsa-sig' and 'authentication remote eap query-identity' under the IKEv2 profile.
B.Configure 'authentication local pre-share' and 'authentication remote pre-share' under the IKEv2 profile.
C.Configure 'authentication local eap query-identity' and 'authentication remote rsa-sig' under the IKEv2 profile.
D.Configure 'authentication local rsa-sig' and 'authentication remote rsa-sig' under the IKEv2 profile.
AnswerA

The 'authentication local rsa-sig' command specifies that the local router uses RSA signatures, which are derived from a certificate, for its own authentication. The 'authentication remote eap query-identity' command instructs the router to request the peer's identity and use EAP for remote authentication, which supports EAP-MSCHAPv2. This combination matches the policy requirements for certificate-based local auth and EAP-based remote auth.

Why this answer

IKEv2 profiles separate local and remote authentication methods. To use a certificate for the headend, 'authentication local rsa-sig' is required. To authenticate peers with EAP-MSCHAPv2, 'authentication remote eap query-identity' is used, which triggers EAP negotiation and allows the peer to respond with EAP-MSCHAPv2 credentials.

Exam trap

The trap here is mixing up local and remote authentication keywords, or assuming that RSA signatures on both sides would satisfy an EAP requirement for peers.

109
MCQeasy

A network administrator is configuring a Cisco Catalyst switch to prevent unauthorized devices from connecting to an access port. The administrator wants to ensure that only one MAC address is allowed on the port, and if a violation occurs, the port should be shut down and an SNMP trap sent. Which port security violation mode should be configured?

A.protect
B.restrict
C.errdisable
D.shutdown
AnswerD

Shutdown mode places the port into an error-disabled state when a violation occurs, effectively shutting it down. It also sends an SNMP trap and syslog message. This matches the requirement to shut down the port and send an SNMP trap. The port can be recovered manually or via errdisable recovery. This is the correct violation mode for the described policy.

Why this answer

The shutdown violation mode meets both requirements: it shuts down the port (error-disabled) and sends an SNMP trap. Protect mode only drops traffic, restrict mode drops and sends traps but does not shut down the port. Errdisable is a state, not a mode.

Thus, shutdown is the correct configuration for this security policy.

Exam trap

The trap here is confusing the errdisable state with a configurable violation mode, or assuming restrict mode also shuts down the port.

110
MCQhard

A network engineer is configuring MACsec on a point-to-point link between two Cisco Catalyst switches to provide Layer 2 encryption. The engineer wants to use a pre-shared key for authentication and ensure that the key is rotated periodically. Which MACsec component must be configured to specify the pre-shared key and the key rotation timer?

A.An IKEv2 profile with a preshared key and a rekey timer applied to the interface.
B.A RADIUS server configuration with a shared secret and a session timeout applied to the interface.
C.A MACsec key chain with a key string and a lifetime configured under the interface.
D.A crypto map with a preshared key and a lifetime applied to the switch port.
AnswerC

MACsec on Cisco switches uses a key chain to store the connectivity association key (CAK) and its lifetime. The key chain is referenced under the interface with the mka key-chain command, and the lifetime controls key rotation. This satisfies the requirement for a preshared key and periodic rotation.

Why this answer

MACsec on Cisco switches uses a key chain to store the connectivity association key and its lifetime, which controls key rotation. The key chain is referenced under the interface with the mka key-chain command. This configuration provides the preshared key and periodic rotation required by the scenario, unlike IPsec mechanisms such as IKEv2 or crypto maps.

Exam trap

The trap here is confusing MACsec key management with IPsec mechanisms like IKEv2 or crypto maps, when MACsec specifically uses MKA and a key chain for preshared keys and rotation.

111
MCQmedium

A network administrator is implementing IP Source Guard (IPSG) on a Cisco Catalyst 3850 switch to prevent IP spoofing. The administrator enables DHCP snooping and IPSG on VLAN 10. A user connects a laptop with a statically assigned IP address 10.10.10.50/24 and gateway 10.10.10.1. The laptop cannot reach any network resources. What is the most likely reason?

A.DHCP snooping must be disabled for IP Source Guard to function with static addresses.
B.IP Source Guard requires that the IP address be learned via DHCP snooping or be statically configured in an IP source binding.
C.IP Source Guard only works with IPv6 addresses, so IPv4 static addresses are not supported.
D.The laptop must be configured with a DHCP address even if a static IP is desired, because IPSG blocks all non-DHCP traffic.
AnswerB

IP Source Guard uses the DHCP snooping database to validate source IP and MAC addresses. For static IP addresses, an IP source binding must be manually configured using the ip source binding command. Without this binding, the switch drops all traffic from the laptop because it cannot verify the source, causing complete loss of connectivity.

Why this answer

IP Source Guard relies on the DHCP snooping binding table to validate source IP and MAC addresses. When a device uses a static IP address, no dynamic binding exists, so the switch drops its traffic. To allow the static address, an IP source binding must be manually configured with the ip source binding command, which populates the binding table.

Exam trap

The trap here is assuming that IP Source Guard automatically permits statically assigned IP addresses, when it actually requires either a DHCP-learned binding or a manual static binding.

112
MCQeasy

A network administrator is configuring a Cisco Wireless LAN Controller (WLC) to secure wireless client traffic. The requirement is to encrypt all wireless traffic between the client and the access point using a pre-shared key, without requiring a separate authentication server. Which security policy should the administrator configure on the WLC?

A.WPA2 Enterprise with 802.1X
B.WPA2 Personal with AES
C.Open authentication with Web Policy
D.WPA3 Enterprise with 192-bit mode
AnswerB

WPA2 Personal uses a pre-shared key (PSK) for authentication and AES for encryption. It does not require an external authentication server, meeting the requirement. This is suitable for small to medium networks where a shared key is acceptable and simplifies deployment.

Why this answer

WPA2 Personal with AES uses a pre-shared key for authentication and AES for encryption, providing strong security without the need for an external RADIUS server. This aligns with the requirement to encrypt traffic using a PSK and no separate authentication server. Enterprise modes require a server, and open authentication lacks encryption.

Exam trap

The trap here is assuming that Enterprise modes can be used without a server, or that open authentication provides encryption.

113
MCQhard

A Cisco Catalyst 9500 switch is configured for 802.1X with MAC Authentication Bypass (MAB) fallback on a port connected to an IP phone that has a PC daisy-chained behind it. The phone authenticates successfully using 802.1X, but the PC behind the phone fails authentication and is placed in the guest VLAN. The requirement is that the PC be authenticated individually and placed in the data VLAN, while the phone remains in the voice VLAN. Which feature should be configured on the switch port to meet this requirement?

A.Web Authentication (WebAuth) fallback
B.Multi-authentication
C.Multi-host authentication
D.Multi-domain authentication
AnswerB

Multi-authentication (also called multi-auth) allows multiple devices on a single port to be authenticated independently, each receiving its own authorization result. With a phone and a daisy-chained PC, the phone can authenticate via 802.1X into the voice VLAN and the PC can authenticate via MAB or 802.1X into the data VLAN. This is the Cisco feature designed for this exact topology.

Why this answer

The daisy-chained PC must be authenticated separately from the phone so it can be placed in the data VLAN while the phone uses the voice VLAN. Cisco multi-authentication (multi-auth) supports multiple independent authentications on one port, including a mix of 802.1X and MAB. Multi-domain supports only one device per domain and multi-host applies the first result to all hosts, so neither meets the requirement.

Exam trap

The trap here is confusing multi-domain, multi-host, and multi-auth; multi-domain supports only one device per domain, while multi-auth is required for multiple independently authenticated devices on the same port.

114
Multi-Selectmedium

A network engineer is implementing Cisco TrustSec in a campus network. The engineer needs to configure the enforcement of security group tags (SGTs) on Cisco Catalyst switches. Which two statements are true regarding SGT enforcement and propagation? (Choose two.)

Select 2 answers
A.SGTs are only supported on Cisco ASA firewalls and not on Cisco Catalyst switches.
B.SGTs are assigned to endpoints by Cisco ISE during authentication and can be used for role-based access control.
C.SGT enforcement is performed by security group ACLs (SGACLs) on Cisco ISE, which pushes them to switches.
D.SGTs are encrypted in the packet to prevent tampering, and only Cisco ISE can decrypt them.
E.SGTs can be propagated through a network using inline tagging or SXP.
AnswersB, E

Cisco ISE assigns an SGT to an endpoint as part of the authorization policy after successful authentication. This SGT represents the endpoint's role or group. The switch then uses this SGT in conjunction with SGACLs to enforce role-based access control. This is a fundamental part of Cisco TrustSec.

Why this answer

SGTs can be propagated via inline tagging or SXP, allowing enforcement across devices that may not support inline tagging. Cisco ISE assigns SGTs to endpoints during authentication, enabling role-based access control. Enforcement is performed on network devices using SGACLs, not on ISE itself.

Exam trap

The trap here is thinking that SGACL enforcement happens on Cisco ISE, when in fact ISE only defines and distributes the policies; enforcement is on the network device.

115
Multi-Selectmedium

A network administrator is implementing Dynamic ARP Inspection (DAI) on a Cisco Catalyst switch. The network uses DHCP for most endpoints, but a few servers have static IP addresses. Which two actions are required to ensure DAI allows legitimate traffic while blocking ARP spoofing? (Choose two.)

Select 2 answers
A.Configure static ARP ACLs for hosts with statically assigned IP addresses.
B.Enable port security with sticky MAC addresses on all access ports.
C.Configure DAI to trust all access ports.
D.Disable IP Source Guard on all access ports.
E.Enable DHCP snooping on the VLANs where DAI is enabled.
AnswersA, E

Hosts with static IP addresses do not appear in the DHCP snooping binding table, so DAI would drop their ARP packets. Creating a static ARP ACL and applying it to the DAI configuration with the arp access-list command allows those specific IP-to-MAC mappings to be validated. This ensures legitimate static hosts are not blocked while spoofing remains prevented.

Why this answer

DAI validates ARP packets against the DHCP snooping binding table, so DHCP snooping must be enabled on the same VLANs. Static hosts are not in that table, so an ARP ACL must be configured to permit their specific IP-to-MAC bindings. Together, these actions allow legitimate DHCP and static traffic while blocking spoofed ARP packets.

Exam trap

The trap here is forgetting that DAI depends on DHCP snooping bindings, so static hosts require an ARP ACL or they will be dropped.

116
MCQmedium

A network engineer is configuring port security on a Cisco switch to prevent unauthorized devices from connecting. The requirement is to allow only the first two MAC addresses learned on an interface, and to disable the interface if a violation occurs. Which configuration achieves this?

A.switchport port-security maximum 2 switchport port-security violation err-disable
B.switchport port-security maximum 2 switchport port-security violation shutdown
C.switchport port-security maximum 2 switchport port-security violation protect
D.switchport port-security maximum 2 switchport port-security violation restrict
AnswerB

This is the correct configuration. It sets the maximum number of secure MAC addresses to 2 and also specifies the violation action as 'shutdown'. When a third MAC address attempts to use the port, the switch places the interface in an err-disabled state, which completely disables the port and blocks all traffic, satisfying the requirement to disable the interface upon a violation.

Why this answer

The 'shutdown' violation mode places the interface into an err-disabled state when a port security violation occurs, which matches the requirement to disable the interface. The 'maximum 2' command limits the number of allowed MAC addresses to two, and the first two learned MAC addresses are dynamically secured. This combination ensures that any additional MAC address triggers a violation and disables the port.

Exam trap

Cisco often tests the distinction between 'shutdown' (disables the interface) and 'restrict' (drops traffic but keeps the interface up), leading candidates to confuse the two when the requirement explicitly calls for disabling the interface.

How to eliminate wrong answers

Option A is wrong because 'err-disable' is not a valid violation mode; the correct keyword is 'shutdown' to disable the interface. Option C is wrong because 'protect' drops packets from unknown MAC addresses but does not disable the interface or generate a syslog message, failing the requirement to disable the interface. Option D is wrong because 'restrict' drops packets from unknown MAC addresses and generates a syslog message but does not disable the interface, also failing the requirement.

117
Multi-Selecthard

A network security team is hardening a Cisco IOS-XE router that terminates a site-to-site VPN to the internet. They want to ensure that the router itself cannot be managed from untrusted networks and that its management protocols are protected. Which two configuration actions achieve these goals? (Choose two.)

Select 2 answers
A.Enable the exec-timeout 0 0 command on all VTY lines to prevent session lockouts during maintenance
B.Apply an access list to the VTY lines that permits only trusted management subnets and add the transport input ssh command
C.Configure a local username with privilege level 15 and no password to ensure emergency access is always available
D.Enable the ip http server command to allow web-based management as a backup access method
E.Configure an ACL on the WAN interface that denies SNMP and NETCONF from untrusted sources while permitting VPN traffic
AnswersB, E

Restricting VTY access with an ACL to trusted management subnets and disabling Telnet via transport input ssh prevents unauthenticated or cleartext management from untrusted networks. This directly addresses the goal of protecting the router's management plane from the internet and is a standard hardening step on Cisco IOS-XE edge devices.

Why this answer

Hardening the management plane requires restricting who can reach the management interfaces and how. Limiting VTY access with an ACL to trusted subnets and forcing SSH eliminates cleartext and unauthorized remote logins, while an interface ACL that blocks SNMP and NETCONF from untrusted sources prevents those services from being exploited from the internet. Together these actions protect the router's management plane without disrupting the site-to-site VPN traffic.

Exam trap

The trap here is treating convenience measures such as disabling exec-timeout, enabling plain HTTP, or creating passwordless privileged accounts as acceptable hardening, when they actually increase exposure on an internet-facing router.

118
MCQmedium

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs. After applying a policer to the control plane, the BGP sessions tear down repeatedly while OSPF adjacencies stay stable. The administrator confirms CPU utilization is low. Which action should be taken to resolve the issue?

A.Apply the CoPP policy to the data plane interfaces using the service-policy input command.
B.Increase the CIR of the policer class matching BGP traffic and permit the BGP class in the control-plane service policy.
C.Disable CEF switching on the router so BGP packets are process-switched and bypass the policer.
D.Enable NetFlow on the WAN interfaces and export records to a collector for BGP traffic analysis.
AnswerB

BGP session teardown with low CPU indicates the policer is dropping BGP keepalives before they reach the control plane. Raising the committed information rate for the BGP class and explicitly permitting that class in the control-plane policy allows the protocol traffic to pass at the required rate, restoring adjacency stability without disabling CoPP for other traffic.

Why this answer

CoPP policies inspect and police traffic punted to the route processor. When a policer for a critical routing protocol is too restrictive, protocol hellos and keepalives are dropped, causing peering failures even though CPU load is low. Adjusting the policer rate and ensuring the protocol class is permitted restores the required control-plane traffic while retaining protection against abuse.

Exam trap

The trap here is assuming that low CPU utilization proves CoPP is working correctly, when in fact a too-strict policer silently discards essential routing protocol keepalives.

119
MCQmedium

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS-XE router that also runs OSPF, BGP, and SSH management. The engineer needs to protect the control plane while ensuring that routing protocol traffic and management sessions are not disrupted. Which CoPP design approach best meets these requirements?

A.Configure a CoPP policy that only rate-limits ICMP and Telnet, leaving all other control plane traffic unclassified and unpolished.
B.Apply a single CoPP policy that classifies all control plane traffic into one class and rate-limits it to a conservative value.
C.Apply the CoPP policy to all data plane interfaces in the inbound direction, which will indirectly protect the control plane.
D.Create multiple granular classes (for example, routing protocols, management, and exception traffic) and apply class-specific policers, while ensuring control plane traffic is not dropped by the default class.
AnswerD

Granular classification lets the engineer allocate adequate bandwidth to OSPF, BGP, and SSH while policing less critical or malicious traffic more aggressively. The default class should be configured to not drop, or to drop only after all classified traffic is serviced, so that unclassified but legitimate control plane packets are not silently discarded and routing or management sessions remain stable.

Why this answer

CoPP protects the route processor by classifying and policing traffic destined to the control plane. Granular classes allow routing protocols and management traffic to receive enough bandwidth, while the default class should be configured not to drop so that legitimate unclassified traffic survives. This design balances protection with operational stability for OSPF, BGP, and SSH.

Exam trap

The trap here is assuming a single conservative CoPP policer is sufficient, when it actually throttles legitimate routing and management traffic along with attacks.

120
MCQeasy

A network administrator is hardening a Cisco IOS switch that connects to user workstations. The security policy requires that when an unauthorized MAC address appears on an access port, the port must drop only the offending frames, generate a syslog message, and increment a counter, without shutting down the port or requiring administrative intervention. Which port security violation mode meets these requirements?

A.restrict
B.shutdown
C.protect
D.drop-and-log
AnswerA

Restrict mode drops the offending frames, sends a syslog message, and increments the violation counter, while keeping the port up. This matches every requirement: no shutdown, no admin intervention, and full auditing. It is the standard choice when visibility into violations is needed without disrupting the port.

Why this answer

Port security offers three violation modes. Restrict drops unauthorized frames while sending SNMP traps, syslog messages, and incrementing the violation counter, and it leaves the port operational. Because the policy forbids err-disable and requires logging plus counters, restrict is the only mode that satisfies all conditions simultaneously.

Exam trap

The trap here is confusing protect with restrict, forgetting that only restrict generates syslog messages and increments the violation counter.

121
Multi-Selectmedium

A network engineer is implementing 802.1X authentication on a Cisco switch. The engineer wants to ensure that the switch dynamically assigns a VLAN to the port based on the user's identity, and that the VLAN assignment is enforced by the authentication server. Which two components are required to achieve this? (Choose two.)

Select 2 answers
A.Enable MACsec on the switch port to encrypt the authentication exchange.
B.Enable DHCP snooping on the switch to validate the user's IP address.
C.Configure the authentication server to return the appropriate RADIUS attributes, such as Tunnel-Type and Tunnel-Private-Group-ID.
D.Configure the switch to use RADIUS for authentication and authorization.
E.Configure the switch port as a trunk port to allow multiple VLANs.
AnswersC, D

For dynamic VLAN assignment, the RADIUS server must send specific attributes in the Access-Accept message: Tunnel-Type (VLAN), Tunnel-Medium-Type (802), and Tunnel-Private-Group-ID (the VLAN ID). These attributes tell the switch which VLAN to assign to the port. Without these attributes, the switch cannot dynamically place the user into the correct VLAN.

Why this answer

Dynamic VLAN assignment requires the switch to authenticate users via RADIUS and receive VLAN information from the RADIUS server. The server must return the appropriate tunnel attributes (Tunnel-Type, Tunnel-Medium-Type, Tunnel-Private-Group-ID) in the Access-Accept message. These two components together allow the switch to place the user into the correct VLAN automatically.

Exam trap

The trap here is assuming that any security feature like MACsec or DHCP snooping contributes to dynamic VLAN assignment, when only RADIUS and its attributes are relevant.

122
MCQhard

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP. After applying a CoPP policy, BGP peering drops intermittently during route churn, but SSH and SNMP remain reachable. Which action should be taken to correct the issue while preserving control plane protection?

A.Increase the policer rate for the BGP class-map in the CoPP policy.
B.Change the BGP class-map match to include only SSH and SNMP traffic.
C.Remove the CoPP policy from the control plane and reapply it after convergence.
D.Disable BGP route churn by setting the BGP scanner interval to a higher value.
AnswerA

BGP peering drops during route churn because the policer for the BGP class is too aggressive and is dropping legitimate control plane traffic. Adjusting the rate for the BGP class preserves protection for other traffic while allowing BGP keepalives and updates to pass. SSH and SNMP are unaffected because their classes have separate policers, so the fix should target the BGP class specifically.

Why this answer

CoPP policers are applied per class, so a too-low rate for the BGP class causes legitimate BGP traffic to be dropped during churn while other classes remain unaffected. Raising the BGP policer rate restores BGP stability without removing control plane protection, whereas disabling CoPP or altering class-maps would either expose the router or misclassify traffic.

Exam trap

The trap here is assuming that CoPP failures require disabling the policy, when the correct fix is to tune the specific class policer that is dropping legitimate traffic.

123
MCQmedium

A network administrator is implementing Control Plane Policing on a Cisco IOS-XE router to protect the route processor from excessive BGP, SSH, and SNMP traffic. After applying the policy, legitimate BGP keepalives are being dropped, causing peer resets. Which action should the administrator take to resolve this while still protecting the control plane?

A.Remove the BGP class from the policy map so BGP is not policed at all
B.Apply the policy to the data plane interfaces instead of the control plane
C.Change the policy map to use priority queuing instead of policing for the BGP class
D.Raise the conform-action rate for the BGP class and verify BGP is classified before the default class
AnswerD

BGP keepalives are small but time-sensitive; if the policed rate for the BGP class is too low, drops cause peer resets. Increasing the conform rate for that class and ensuring BGP traffic matches its dedicated class before falling into the default class restores keepalive delivery while still rate-limiting other unwanted traffic. This preserves control-plane protection without harming BGP.

Why this answer

CoPP classifies control-plane traffic and applies policers per class. BGP keepalives are small and periodic; if the BGP class rate is too low or BGP is not matched before the default class, keepalives get dropped and peers reset. Increasing the conform rate for the BGP class and ensuring correct classification order restores keepalive delivery while continuing to protect the route processor from abusive traffic in other classes.

Exam trap

The trap here is assuming that removing the BGP class or switching to queuing solves the problem, when the actual fix is to tune the policer rate and verify classification order so BGP matches its dedicated class before the default class.

124
MCQhard

A network security team is deploying MACsec on a Cisco Catalyst 9300 switch connecting to a partner's Catalyst 9200 over a metro Ethernet link. The team wants to encrypt all traffic on the link and ensure that the switches mutually authenticate before any frames are forwarded. Which IEEE standard defines the key agreement and encryption used by MACsec, and which component performs the key exchange?

A.IEEE 802.1AE for encryption and IKEv2 for key agreement
B.IEEE 802.1X for encryption and IEEE 802.1AE for key agreement
C.IEEE 802.1AE for encryption and IEEE 802.1X-2010 with MKA for key agreement
D.IEEE 802.1Q for tagging and IEEE 802.1AE for key agreement
AnswerC

MACsec encryption is defined by IEEE 802.1AE, which specifies hop-by-hop encryption of Ethernet frames. Key agreement and mutual authentication are provided by MACsec Key Agreement (MKA), which is defined in IEEE 802.1X-2010. The two switches exchange MKPDUs to negotiate a secure association key, so no frames are forwarded in the clear before the session is established, satisfying the mutual authentication requirement.

Why this answer

MACsec encryption is standardized in IEEE 802.1AE, while the key agreement and mutual authentication between peers are handled by MACsec Key Agreement as defined in IEEE 802.1X-2010. Together they ensure that the Catalyst 9300 and 9200 mutually authenticate and encrypt every frame before any user traffic is forwarded across the metro Ethernet link.

Exam trap

The trap here is assuming that 802.1X itself provides MACsec encryption, when in fact 802.1X-2010 contributes the MKA key agreement and 802.1AE provides the actual frame encryption.

125
MCQmedium

A network engineer is implementing IPsec VPN on a Cisco IOS XE router. The design requires that traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet be encrypted, while all other traffic should be sent unencrypted. The engineer creates a crypto ACL. Which action must be taken to ensure the crypto ACL correctly identifies the traffic to protect?

A.Configure the crypto ACL with 'permit ip any any' to ensure all traffic is encrypted, then use a route-map to exclude the non-interesting traffic.
B.Configure the crypto ACL with 'permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255' and ensure there is an implicit deny or an explicit deny for other traffic.
C.Configure the crypto ACL with 'deny ip any any' followed by 'permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255'.
D.Configure the crypto ACL with 'permit ip 10.1.1.0 0.0.0.255 any' to cover all destinations from the source subnet, then rely on the VPN peer to filter.
AnswerB

The crypto ACL defines interesting traffic by permitting the specific source and destination subnets. Only traffic matching a permit statement is encrypted. An implicit deny at the end means other traffic is not matched and therefore not encrypted, which aligns with the requirement to send other traffic unencrypted. This is the correct way to define the VPN traffic selector.

Why this answer

The crypto ACL must permit only the specific source and destination subnets that require encryption. Because ACLs have an implicit deny, traffic not matching the permit is not considered interesting and is sent unencrypted. This precisely implements the requirement to encrypt only traffic between 10.1.1.0/24 and 10.2.2.0/24.

Exam trap

The trap here is misunderstanding the implicit deny in a crypto ACL: placing an explicit deny before the permit would block the desired traffic from being encrypted.

126
MCQmedium

A network administrator is deploying a Cisco Catalyst switch with DHCP snooping. The switch is configured with DHCP snooping globally and on VLAN 10. A DHCP server is connected to GigabitEthernet1/0/5, and client devices are connected to GigabitEthernet1/0/6 through 1/0/20. The administrator notices that DHCP offers from the server are being dropped. What is the most likely cause?

A.The DHCP snooping database agent is not configured.
B.The client ports are configured as trusted.
C.DHCP snooping is not enabled on the VLAN of the client ports.
D.The DHCP server port is not configured as trusted.
AnswerD

DHCP snooping drops DHCP server messages (OFFER, ACK) received on untrusted ports. By default, all ports are untrusted. The port connected to the DHCP server must be explicitly configured with 'ip dhcp snooping trust' to allow server responses. Since the server is on GigabitEthernet1/0/5 and is not trusted, its offers are dropped, matching the symptom.

Why this answer

DHCP snooping treats all ports as untrusted by default and drops DHCP server messages received on untrusted ports. To allow legitimate DHCP server responses, the port connected to the DHCP server must be configured with 'ip dhcp snooping trust'. In this scenario, the server port GigabitEthernet1/0/5 is untrusted, so offers are dropped.

Trusting the server port resolves the issue while maintaining protection against rogue DHCP servers on client ports.

Exam trap

The trap here is assuming that enabling DHCP snooping globally and on the VLAN is sufficient, when in fact the server-facing port must also be explicitly trusted.

127
MCQmedium

A network administrator is configuring 802.1X authentication on a Cisco switch port. The port is connected to a VoIP phone that then connects to a PC. The administrator wants to authenticate both the phone and the PC separately, with the phone using MAB and the PC using 802.1X. Which feature should be configured on the switch port to support this?

A.Web Authentication (WebAuth)
B.Multi-Domain Authentication (MDA)
C.Multi-Host
D.Multi-Auth
AnswerB

MDA allows both a data device and a voice device to authenticate independently on the same switch port. It places the phone in the voice VLAN and the PC in the data VLAN, each with its own authentication session. This matches the requirement to authenticate the phone via MAB and the PC via 802.1X. MDA is designed for this exact scenario.

Why this answer

MDA is specifically designed to allow a voice device and a data device to authenticate separately on the same switch port. The phone can use MAB while the PC uses 802.1X, and they are placed in different VLANs. Multi-Auth and Multi-Host do not provide this voice/data separation, and WebAuth is a different authentication method.

Thus, MDA is the correct feature.

Exam trap

The trap here is confusing Multi-Auth with MDA; Multi-Auth allows multiple devices but does not separate voice and data domains as required for a VoIP phone and PC.

128
MCQeasy

A network administrator is configuring a Cisco IOS router to act as a VPN headend for remote users. The requirement is to use a protocol that supports both IKEv2 and native IPv6 transport, and that can provide per-user policy enforcement. Which technology should the administrator implement?

A.Dynamic Multipoint VPN (DMVPN) with mGRE and NHRP.
B.FlexVPN with IKEv2 and per-user attributes.
C.GET VPN with Group Domain of Interpretation (GDOI).
D.SSL VPN with Cisco AnyConnect.
AnswerB

FlexVPN is a Cisco IOS framework that uses IKEv2 and supports IPv6 transport. It allows per-user policy enforcement through authorization attributes such as IP address, DNS, and split tunnel ACLs. It is well suited for remote access VPN headends and can scale to many users while maintaining granular policy control.

Why this answer

FlexVPN is the correct choice because it is built on IKEv2 and supports IPv6 transport. It also provides per-user policy enforcement through authorization attributes, making it ideal for a remote access VPN headend. Other options either do not support IKEv2, are designed for site-to-site topologies, or lack per-user policy enforcement.

Exam trap

The trap here is equating remote access VPN with SSL VPN only, overlooking that FlexVPN also supports remote access with IKEv2 and per-user policies.

129
MCQeasy

A network engineer is configuring an IPsec site-to-site VPN between two Cisco IOS-XE routers. The design requires that the data payload be encrypted and that the two peers authenticate each other using pre-shared keys without any certificate infrastructure. Which combination of IKEv2 parameters must be configured on both peers to establish the tunnel?

A.An IKEv2 profile alone with inline pre-shared-key configuration
B.An IKEv2 proposal, a transform set, and a dynamic crypto map
C.An IKEv2 proposal, an IKEv2 policy, an IKEv2 keyring, and an IKEv2 profile
D.An ISAKMP policy, a crypto keyring with RSA signatures, and a crypto map
AnswerC

In IKEv2 on Cisco IOS-XE, a proposal defines the encryption, integrity, and PRF algorithms, a policy binds proposals to a match criterion, a keyring holds the pre-shared keys, and a profile ties the keyring to the peer and local identities and references the policy. All four components are needed to negotiate the IKEv2 SA using PSK authentication, making this the correct set.

Why this answer

IKEv2 on Cisco IOS-XE separates concerns: proposals define algorithms, policies select proposals based on match criteria, keyrings store pre-shared keys, and profiles bind identities, keyrings, and policies together. All four are required to negotiate the IKEv2 security association using PSK authentication with no PKI. The data-plane IPsec configuration (transform set and profile or map) is separate and layered on top of this control-plane configuration.

Exam trap

The trap here is confusing IKEv1 constructs such as ISAKMP policies and crypto maps with the IKEv2 building blocks, or assuming a profile alone can hold the pre-shared key without a keyring.

130
MCQeasy

A network engineer is configuring a site-to-site VPN between two Cisco IOS routers. The engineer wants to ensure that only traffic from the 10.1.1.0/24 subnet to the 10.2.2.0/24 subnet is encrypted, while all other traffic is sent unencrypted. Which IPsec configuration component defines this traffic?

A.Transform set
B.Crypto map
C.Access control list (ACL)
D.IKE policy
AnswerC

The ACL in an IPsec configuration defines the interesting traffic that will be encrypted. In this scenario, an ACL permitting IP from 10.1.1.0/24 to 10.2.2.0/24 would ensure only that traffic is encrypted. The crypto map references this ACL to match traffic. Other traffic not matching the ACL is sent unencrypted.

Why this answer

In Cisco IPsec configuration, the ACL (often called the crypto ACL) specifies the traffic that should be protected. The crypto map then references this ACL. Traffic that matches the ACL is encrypted; traffic that does not match is sent in clear text.

Therefore, the ACL is the component that defines the interesting traffic.

Exam trap

The trap here is confusing the role of the crypto map (which binds components) with the ACL (which actually defines the traffic).

131
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive control-plane traffic. The engineer wants to rate-limit ARP and DHCP snooping-related traffic destined to the control plane while allowing routing protocol traffic without restriction. Which CoPP component must the engineer configure to classify and match this traffic before applying the policy?

A.A policy map that references the control-plane host and matches all IP traffic by default.
B.An access list applied directly to the control-plane interface with the ip access-group command.
C.A class map that matches traffic using ACLs and/or match protocol commands.
D.A route map applied to the control-plane interface with the service-policy command.
AnswerC

CoPP uses a modular QoS CLI structure: class maps define the traffic to be matched, policy maps define the actions, and the service-policy is applied to the control-plane interface. To rate-limit ARP and DHCP snooping traffic, the engineer must first create class maps that identify those protocols using ACLs or match protocol statements, then reference them in a policy map.

Why this answer

CoPP relies on the modular QoS CLI, where class maps classify control-plane traffic, policy maps apply policing actions, and the service-policy is attached to the control-plane interface. To rate-limit ARP and DHCP snooping traffic while leaving routing protocols unrestricted, the engineer must create class maps that match those specific protocols and reference them in a policy map, which is then applied to the control plane.

Exam trap

The trap here is confusing CoPP with ACL-based control-plane filtering, when CoPP specifically requires class maps and a policy map applied via service-policy on the control-plane interface.

132
MCQeasy

A network administrator is configuring a site-to-site VPN between two Cisco IOS routers using IPsec. The security policy requires that the VPN use IKEv2 with certificate-based authentication. Which command must be configured on both routers to specify the trustpoint that will be used for IKEv2 authentication?

A.crypto ikev2 proposal <name> and then encryption aes-cbc-256 under the proposal.
B.crypto ikev2 profile <name> and then pki trustpoint <trustpoint-name> under the profile.
C.crypto ikev2 profile <name> and then match certificate <map-name> under the profile.
D.crypto ikev2 keyring <name> and then pre-shared-key <key> under the keyring.
AnswerB

Within an IKEv2 profile, the 'pki trustpoint' command specifies which PKI trustpoint the router will use for certificate-based authentication. This is the correct way to bind a trustpoint to an IKEv2 profile. Both routers must have this configured to present and validate certificates during IKEv2 negotiation, satisfying the certificate-based authentication requirement.

Why this answer

IKEv2 certificate-based authentication requires a PKI trustpoint to be associated with the IKEv2 profile. The 'pki trustpoint' command under the IKEv2 profile binds the trustpoint, enabling the router to use certificates for authentication. This must be configured on both peers.

Other commands like 'match certificate' are used for certificate map matching, and keyrings are for PSK authentication, neither of which satisfies the certificate requirement.

Exam trap

The trap here is confusing the command that binds a trustpoint to an IKEv2 profile with the command that matches certificate fields or configures PSK authentication, leading to an incomplete or incorrect configuration.

133
MCQmedium

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP monitoring. After applying a new CoPP policy, BGP sessions flap intermittently while SSH and SNMP continue to work. The engineer wants to confirm which traffic class is being dropped. Which action should the engineer take?

A.Run show ip bgp summary to check the BGP neighbor state and reset the sessions.
B.Capture traffic on the control plane interface using an Embedded Packet Capture with a BGP filter.
C.Enable debug ip ssh and debug snmp packets to compare with BGP debugs.
D.Review CoPP class-map and policy-map statistics with show policy-map control-plane to identify the class with drops.
AnswerD

The show policy-map control-plane command displays per-class packet and byte counters, including dropped packets, for the control plane policy. Since BGP is flapping while SSH and SNMP work, inspecting these counters reveals which class is exceeding its rate and dropping traffic, directly identifying the misconfigured class.

Why this answer

CoPP applies a policy-map to the control plane and maintains per-class statistics. Because SSH and SNMP still function while BGP flaps, the BGP class is likely exceeding its configured rate. Viewing the control-plane policy-map counters shows which class has drops, pinpointing the class that needs a higher rate or burst value.

Exam trap

The trap here is troubleshooting the BGP neighbor state instead of inspecting the CoPP policy-map counters that actually reveal which traffic class is being policed and dropped.

134
MCQmedium

A network security team deploys Cisco TrustSec on a Catalyst 9500 fabric. The team wants to enforce a policy where a user authenticated into the 'Contractor' security group tag (SGT) is denied access to servers tagged with the 'Finance' SGT, while remaining able to reach the 'Printers' SGT. Which enforcement mechanism applies the SGACL to traffic between the tagging devices?

A.802.1X with downloadable ACLs pushed from Cisco ISE to the access switch on the user's port.
B.SGT Exchange Protocol (SXP) on the enforcement device, mapping IP addresses to SGTs at the egress point.
C.MACsec encryption with MKA on the fabric uplinks, which implicitly denies unauthorized SGT combinations.
D.SGACL enforcement applied on the egress enforcement device using the SGT carried in the Cisco Metadata (CMD) header.
AnswerD

SGACLs are evaluated on the enforcement device using the source and destination SGTs carried in the Cisco Metadata header. This allows the fabric to deny Contractor-to-Finance while permitting Contractor-to-Printers based on the policy matrix defined on Cisco ISE, satisfying the requirement precisely.

Why this answer

Cisco TrustSec enforces group-based policy by inserting the source SGT into the Cisco Metadata header and evaluating SGACLs on the egress enforcement device against the destination SGT. The policy matrix authored on ISE defines deny Contractor-to-Finance and permit Contractor-to-Printers, and the enforcement device applies it inline. SXP only propagates bindings, dACLs only filter at the port, and MACsec only secures the link.

Exam trap

The trap here is confusing SXP, which propagates SGT bindings, with SGACL enforcement, which actually denies the traffic.

135
MCQmedium

A network engineer is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The engineer applies a CoPP policy-map to the control plane with a class that matches BGP traffic and sets police rate 8000 conform-action transmit exceed-action drop. After applying the policy, BGP sessions intermittently flap during route convergence. Which action should the engineer take to resolve the issue while maintaining control plane protection?

A.Apply the CoPP policy to all router interfaces as an input service policy instead of to the control plane.
B.Remove the CoPP policy from the control plane interface and rely on interface ACLs instead.
C.Increase the police rate for the BGP class or change the exceed-action to transmit, after verifying the offered rate.
D.Change the CoPP policy to use priority queuing instead of policing for the BGP class.
AnswerC

The intermittent BGP flaps during convergence indicate that legitimate BGP control traffic is exceeding the 8,000 pps police rate and being dropped by the exceed-action. Increasing the police rate or changing the exceed-action to transmit for the BGP class restores session stability while still policing other control plane traffic. Verification of the offered rate is essential to size the policer correctly.

Why this answer

BGP session flapping immediately after applying a policer that drops exceeded traffic points to legitimate BGP control packets being dropped because the configured rate is too low for convergence bursts. The correct remediation is to right-size the policer for the BGP class, either by raising the rate or by permitting excess traffic, after confirming the actual offered rate from the control plane.

Exam trap

The trap here is assuming that any control plane drops must be caused by an attack rather than by an undersized policer that drops legitimate routing protocol traffic.

136
MCQmedium

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that peers BGP with two ISPs and runs SSH for management. The administrator wants to ensure that a sudden flood of BGP updates from a misbehaving peer does not starve the SSH management plane, while still allowing legitimate BGP traffic. Which CoPP configuration approach best meets this requirement?

A.Apply an ACL that denies TCP port 179 from the ISP peer addresses directly to the BGP router process using the neighbor command.
B.Define a class-map matching BGP (TCP port 179) and SSH (TCP port 22) in a single class, then apply a single policer with a low rate to that combined class.
C.Define separate class-maps for BGP and SSH, assign each to its own policy-map class with independent policers, then apply the policy-map globally with the service-policy command under control-plane.
D.Configure a QoS policy-map with a priority queue for SSH and apply it outbound on the ISP-facing interfaces.
AnswerC

Separating BGP and SSH into distinct classes with independent policers allows the administrator to rate-limit BGP traffic tightly while guaranteeing SSH a separate, protected bandwidth allocation. Applying the policy-map globally under the control-plane configuration mode enforces policing on all control-plane traffic destined to the route processor, satisfying the requirement to prevent BGP floods from starving management access.

Why this answer

Effective CoPP design uses granular classification so that different control-plane protocols are policed independently. BGP and SSH have very different traffic profiles, so placing them in separate classes with separate policers lets the administrator tightly limit BGP while reserving bandwidth for SSH. The policy-map must then be attached under the control-plane configuration to affect traffic punted to the route processor.

Exam trap

The trap here is assuming that combining related control-plane protocols into one class simplifies CoPP without sacrificing protection for management traffic.

137
Multi-Selecthard

A network engineer is deploying MACsec on a Catalyst switch uplink between two buildings to protect Layer 2 traffic. Which two statements about MACsec operation on Cisco Catalyst switches are true? (Choose two.)

Select 2 answers
A.MACsec encrypts traffic end to end from the originating host to the final destination host across all intermediate routers.
B.MACsec requires an MKA session and a connectivity association key to establish secure associations between peers.
C.MACsec replaces 802.1X and removes the need for any authentication server in the network.
D.MACsec provides hop-by-hop encryption and integrity for Ethernet frames using the 802.1AE standard.
E.MACsec can be deployed only on routed ports and is incompatible with switch access ports.
AnswersB, D

The MACsec Key Agreement protocol negotiates session keys between peers using a connectivity association key, which can be provided statically or derived through 802.1X. Without a successful MKA session, the link will not pass protected traffic. This key management layer distinguishes MACsec from simple link encryption and ensures both ends agree on cipher suites and key material.

Why this answer

MACsec secures individual Ethernet links using 802.1AE encryption and integrity, and it relies on MKA with a connectivity association key to negotiate secure associations between peers. Because it operates hop by hop, each device along the path must participate, and it does not replace 802.1X or provide end-to-end encryption across a routed network.

Exam trap

The trap here is treating MACsec as end-to-end encryption when it actually protects each Layer 2 hop independently.

138
MCQmedium

A network administrator is configuring a Cisco IOS router to support IPsec VPN for remote workers. The security policy requires that the router authenticate users via digital certificates issued by a corporate PKI. The administrator has already configured the CA trustpoint and obtained a certificate. Which command must be used in the ISAKMP policy to specify that RSA signatures (digital certificates) should be used for authentication?

A.authentication rsa-sig
B.authentication rsa-encr
C.authentication eap
D.authentication pre-share
AnswerA

The 'authentication rsa-sig' command within the ISAKMP policy specifies that RSA signatures should be used for authentication. This means the router will use digital certificates obtained from a CA to authenticate peers. This matches the requirement to use digital certificates issued by a corporate PKI. The command is configured under 'crypto isakmp policy' configuration mode.

Why this answer

In an ISAKMP policy for IKEv1, the 'authentication rsa-sig' command enables RSA signature authentication, which relies on digital certificates. The other options are incorrect: pre-share uses pre-shared keys, rsa-encr uses encrypted nonces, and eap is used for EAP authentication, typically in IKEv2. The policy requires certificate-based authentication, so rsa-sig is the correct command.

Exam trap

The trap here is confusing rsa-sig with rsa-encr; rsa-sig uses digital certificates for authentication, while rsa-encr uses RSA encrypted nonces without certificates.

139
MCQeasy

A network administrator must secure management access to a Cisco Catalyst 9300 switch so that only encrypted sessions are accepted and any Telnet attempt is refused. The administrator wants to enforce this with the fewest configuration lines on the VTY lines. Which configuration accomplishes this?

A.line vty 0 15 followed by transport output ssh
B.line vty 0 15 followed by login local and transport input telnet ssh
C.line vty 0 15 followed by transport input all then access-class 10 in with an ACL denying TCP port 23
D.line vty 0 15 followed by transport input ssh
AnswerD

The transport input ssh command on the VTY lines permits only SSH and implicitly rejects Telnet, so no additional access-class or ACL is required. This satisfies the requirement with a single line inside line configuration mode, assuming the device already has a hostname, domain name, and RSA key pair generated for SSH to function.

Why this answer

Restricting inbound VTY access to SSH is done by entering line configuration mode and issuing transport input ssh, which permits only SSH and denies Telnet by default. Because Telnet is implicitly excluded, no ACL is needed, making this the most concise and reliable way to enforce encrypted-only management access on the switch.

Exam trap

The trap here is confusing transport input with transport output, which control opposite directions of the management session.

140
MCQmedium

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP polling. A class-map named CLASS-MGMT matches SNMP and SSH traffic, and a policy-map named COPP-POLICY applies a police rate of 8000 bps with a conform-action transmit and exceed-action drop for that class. After the policy is attached to the control plane, SNMP polling intermittently fails while BGP remains stable. Which action should the engineer take to resolve the SNMP failures while still protecting the route processor?

A.Move the policy-map from the control plane to the data plane interface facing the SNMP server.
B.Add a new class-map that matches BGP and apply a lower police rate to it, then reattach the policy.
C.Increase the police rate in the CLASS-MGMT class to a value that accommodates the normal SNMP and SSH burst rate.
D.Change the exceed-action from drop to transmit so that SNMP packets are never discarded.
AnswerC

SNMP polling and SSH generate bursty traffic to the route processor. An 8000 bps police rate is far below the normal management traffic rate, so conforming packets are transmitted but excess packets are dropped, causing intermittent SNMP failures. Raising the rate for that class to match observed management traffic preserves CoPP protection while allowing legitimate management polling to reach the control plane.

Why this answer

SNMP polling is bursty and can briefly exceed a very low police rate. When the exceed-action drops packets, polling becomes intermittent. The correct fix is to raise the police rate for the management class to a value that reflects real SNMP and SSH traffic while keeping CoPP in place to protect the route processor from abuse.

Disabling enforcement or moving the policy to the data plane is not appropriate.

Exam trap

The trap here is assuming that any CoPP drop means the policy should be removed or the exceed-action changed to transmit, rather than tuning the rate to match legitimate control-plane traffic.

141
MCQmedium

A security architect is designing a campus network where all access-layer switch ports must authenticate endpoints before granting any Layer 2 connectivity. The design requires the switch to communicate with Cisco ISE using EAP over RADIUS, and the endpoint must be validated before any VLAN assignment occurs. Which 802.1X component role must the access-layer switch perform in this design?

A.Authentication server
B.RADIUS proxy
C.Authenticator
D.Supplicant
AnswerC

The switch acts as the authenticator, controlling access to the port based on the outcome of EAP exchanges with the endpoint and RADIUS decisions from Cisco ISE. It relays EAP frames between the supplicant and authentication server, enforces port authorization state, and applies VLAN or ACL results. This matches the requirement that endpoints be authenticated before any Layer 2 connectivity is granted.

Why this answer

In 802.1X, the three roles are supplicant, authenticator, and authentication server. The access-layer switch controls the physical port and relays EAP messages between the endpoint and Cisco ISE, so it functions as the authenticator. It also enforces the authorization result, such as a dynamic VLAN or downloadable ACL, which satisfies the requirement that the endpoint be validated before Layer 2 access is granted.

Exam trap

The trap here is confusing the switch that enforces port access with the server that validates credentials, which leads candidates to select the authentication server role.

142
Multi-Selecthard

A security architect is designing a Zero Trust access solution for a campus using Cisco Identity Services Engine. The requirement is to enforce dynamic, identity-based segmentation without relying solely on static VLANs, and to support both wired and wireless endpoints. Which two capabilities should be leveraged? (Choose two.)

Select 2 answers
A.Change of Authorization (CoA) from ISE to dynamically reapply authorization policies on session changes
B.Cisco Platform Exchange Grid (pxGrid) to share context between ISE and third-party security tools
C.Security Group Tags (SGTs) applied via ISE and enforced by Cisco TrustSec-capable switches
D.MAC Authentication Bypass (MAB) as the primary authentication method for all endpoints
E.Static VLAN assignment per access switch port to isolate user groups
AnswersA, C

CoA lets ISE push new authorization results, such as a new SGT or VLAN, to the network access device when posture or identity changes. This enables dynamic enforcement without reconnecting the endpoint. Combined with SGTs, CoA ensures segmentation stays current as conditions change, which is essential for a Zero Trust model across wired and wireless.

Why this answer

Security Group Tags assigned by ISE and enforced by TrustSec-capable switches provide identity-based segmentation independent of VLANs, while Change of Authorization allows ISE to dynamically update authorization results as identity or posture changes. Together they deliver dynamic, identity-driven access across wired and wireless, which static VLANs, MAB, or pxGrid alone cannot achieve.

Exam trap

The trap here is selecting pxGrid or MAB as if they enforced segmentation, when in fact SGTs plus CoA are the mechanisms that dynamically tag and reauthorize endpoint traffic.

143
MCQeasy

A network engineer is configuring port security on a Cisco switch to prevent unauthorized devices from connecting. The requirement is to allow only the first two MAC addresses learned on the port and to automatically shut down the port if a violation occurs. Which command set should be used?

A.switchport port-security switchport port-security maximum 2 switchport port-security violation restrict
B.switchport port-security switchport port-security violation protect
C.switchport port-security switchport port-security maximum 1 switchport port-security violation shutdown
D.switchport port-security switchport port-security maximum 2 switchport port-security violation shutdown
AnswerD

This command set enables port security, sets the maximum number of MAC addresses to 2, and configures the violation action to shutdown the port. This meets the requirement of allowing only two MAC addresses and shutting down on violation. The shutdown violation mode places the port in an err-disabled state when a violation occurs.

Why this answer

Port security is configured by enabling it on the interface, setting the maximum number of allowed MAC addresses, and specifying the violation action. To allow two MAC addresses and shut down on violation, the commands switchport port-security, switchport port-security maximum 2, and switchport port-security violation shutdown are required. This ensures that only two devices can connect and any additional device causes the port to enter err-disabled state.

Exam trap

The trap here is confusing the violation modes; restrict and protect do not shut down the port, while shutdown does. Also, forgetting to set the maximum to 2 would default to 1, which is not the requirement.

144
MCQmedium

A network engineer configures Control Plane Policing on a Cisco IOS XE router acting as the BGP speaker for an ISP edge. The policy must protect the route processor from CPU exhaustion while still allowing BGP keepalives, SSH management, and SNMP polling from the NOC. Which CoPP design element is required to ensure BGP, SSH, and SNMP traffic is matched and rate-limited separately from transit traffic?

A.An access list applied outbound on all interfaces using 'ip access-group' to block unwanted traffic before it reaches the route processor.
B.An MQC policy attached to the WAN interface with 'service-policy input' so that all inbound traffic including BGP and SSH is policed at the interface level.
C.A route-map with 'match ip next-hop' applied to the BGP neighbor to limit the number of prefixes received from each peer.
D.A class-map that matches traffic with the 'control-plane' keyword and a policy-map applied with 'service-policy input' under the control-plane configuration mode.
AnswerD

CoPP on IOS XE requires a class-map to identify control-plane-destined traffic, typically using an ACL or 'match protocol', and a policy-map that assigns a policer. The policy-map is attached to the control-plane with 'service-policy input', which is exactly how BGP, SSH, and SNMP destined to the route processor are rate-limited without affecting transit forwarding.

Why this answer

CoPP protects the route processor by classifying traffic destined to the control plane and applying policers through an MQC policy attached under control-plane configuration mode. This allows BGP keepalives, SSH, and SNMP to be individually matched and rate-limited so that a flood of any one protocol cannot exhaust CPU resources while transit traffic is unaffected.

Exam trap

The trap here is confusing interface-level QoS policing with control-plane policing, when only a policy attached under control-plane configuration mode protects the route processor.

145
MCQmedium

A network administrator is deploying a new branch office with a Cisco Catalyst 9200 switch. The security policy requires that any endpoint connecting to access ports must be authenticated before being granted network access, and unauthenticated devices must be placed into a restricted VLAN. The administrator wants to minimize configuration on the switch and rely on the authentication server to assign the VLAN dynamically. Which 802.1X feature should be configured on the switch to meet these requirements?

A.Configure 802.1X with VLAN assignment via RADIUS attributes.
B.Configure port security with sticky MAC addresses and a violation action of restrict.
C.Configure Web Authentication (WebAuth) with a guest VLAN.
D.Configure MAC Authentication Bypass (MAB) with a fallback VLAN.
AnswerA

This is the correct approach. 802.1X authentication allows the switch to authenticate endpoints using credentials (e.g., username/password or certificate) against a RADIUS server like Cisco ISE. The server can return attributes such as Tunnel-Type, Tunnel-Medium-Type, and Tunnel-Private-Group-ID to dynamically assign the endpoint to a specific VLAN. This meets the requirement of authenticating endpoints and placing unauthenticated devices into a restricted VLAN (e.g., a guest VLAN) if configured.

Why this answer

The requirement is to authenticate endpoints and dynamically assign VLANs based on authentication server response. 802.1X with RADIUS attributes allows the switch to act as an authenticator, passing credentials to a RADIUS server, which can then return VLAN assignment attributes. This ensures only authenticated devices gain access, and unauthenticated devices can be placed in a restricted VLAN. Other options either do not authenticate or do not provide dynamic VLAN assignment based on user identity.

Exam trap

The trap here is confusing port security or MAB with 802.1X, which actually provides authentication and dynamic VLAN assignment through RADIUS attributes.

146
MCQhard

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive traffic. The router has management SSH access, BGP peering, and SNMP monitoring. After applying a CoPP policy, the engineer notices that BGP sessions flap intermittently, but SSH and SNMP remain stable. Which action should the engineer take to resolve the BGP flapping while maintaining control plane protection?

A.Remove the CoPP policy from the control plane interface.
B.Reclassify BGP traffic into the SNMP class to share its rate limit.
C.Increase the rate limit for the BGP class in the CoPP policy.
D.Enable QoS pre-classify on the BGP neighbor interface.
AnswerC

BGP flapping indicates that BGP control plane traffic is being dropped due to an overly restrictive policer. Increasing the rate limit for the BGP class allows legitimate BGP keepalives and updates to pass while still protecting the route processor from excessive BGP traffic. This is the targeted fix because SSH and SNMP are stable, confirming that only the BGP class needs adjustment.

Why this answer

When CoPP policers are too strict, protocols like BGP may experience drops leading to session flaps. Since SSH and SNMP are stable, the issue is isolated to the BGP class. Increasing the rate limit for that class allows BGP to operate within acceptable thresholds while still protecting the route processor.

This maintains overall control plane security without sacrificing routing stability.

Exam trap

The trap here is assuming that any CoPP issue requires disabling the policy entirely, rather than tuning the specific class that is causing drops.

147
MCQmedium

A network engineer must protect the Cisco IOS control plane from an excessive volume of ARP traffic generated by a compromised host in VLAN 20. The engineer wants to limit ARP packets that are punted to the CPU, while allowing normal data forwarding to continue unaffected. Which feature should be configured to accomplish this goal?

A.Control Plane Policing (CoPP)
B.Storm control configured for broadcast traffic on the host-facing port
C.IP Source Guard on the host-facing port
D.Dynamic ARP Inspection (DAI) on VLAN 20
AnswerA

CoPP applies a QoS policy to the control plane and can rate-limit specific punted traffic classes, such as ARP, using a class-map matching ARP and a policy-map with a policer. This directly limits how many ARP packets reach the CPU while leaving transit data-plane forwarding untouched. It is the intended tool for protecting the route processor from excessive exception traffic.

Why this answer

Protecting the CPU from excessive punted ARP traffic requires a mechanism that polices traffic destined to the control plane. Control Plane Policing provides exactly this by allowing class-based rate limiting of specific protocols such as ARP. DAI, storm control, and IP Source Guard operate at the access or data plane and address spoofing or broadcast volume, not CPU-bound exception traffic.

Exam trap

The trap here is assuming that any ARP-related security feature, such as DAI, will protect the CPU from ARP floods, when only control plane policing rate-limits traffic punted to the route processor.

148
MCQmedium

A network administrator is deploying a Cisco Catalyst 9300 switch stack at the access layer. The security policy requires that when an endpoint device is connected to a port and later replaced by a different device, the port must automatically learn the new MAC address without administrative intervention, but a violation must generate a syslog message and increment a counter. The administrator configures the interface with the command 'switchport port-security violation restrict'. Which additional command is required to meet the requirement that the new device is learned automatically?

A.switchport port-security aging time 2
B.switchport port-security mac-address sticky
C.switchport port-security maximum 1
D.switchport port-security mac-address 0011.2233.4455
AnswerB

Sticky learning dynamically learns the MAC address of the first device and adds it to the running configuration. When the device is replaced, the old sticky entry can age out or be removed, and the new device is learned. With violation restrict, a syslog and counter increment occur on violation. This meets the requirement without manual intervention, unlike static configuration.

Why this answer

Sticky learning allows the switch to dynamically learn MAC addresses and add them to the running configuration, so when a device is replaced, the new MAC can be learned without manual reconfiguration. Combining sticky with violation restrict ensures a syslog and counter increment on violation. Maximum, static MAC, and aging do not provide the required automatic learning behavior.

Exam trap

The trap here is assuming that setting a maximum or aging time enables automatic learning of a replacement device, when only sticky learning dynamically adds the new MAC to the configuration.

149
MCQhard

A network engineer is configuring IPsec VPN on a Cisco IOS router. The engineer wants to ensure that traffic from a specific subnet is encrypted and sent to a remote peer, while all other traffic is sent unencrypted. The engineer has configured an extended ACL for the crypto map. Which additional configuration is required to ensure that the crypto map is applied to the correct interface and that the VPN tunnel is established?

A.Configure a static route to the remote peer's public IP address pointing to the next-hop router.
B.Enable NAT on the interface to translate the private subnet to a public address before encryption.
C.Configure an ISAKMP policy with a matching pre-shared key on both peers.
D.Apply the crypto map to the outbound interface using the crypto map command under interface configuration.
AnswerD

The crypto map must be applied to the interface that sends traffic to the remote peer, typically the WAN interface, using the crypto map <name> command. This enables the router to evaluate outbound packets against the ACL, match interesting traffic, and initiate the IPsec tunnel. Without applying the crypto map to an interface, the VPN configuration remains inactive.

Why this answer

The crypto map defines the IPsec policy and must be applied to the outbound interface facing the remote peer. This application is what causes the router to inspect outbound packets, match the ACL, and initiate the IPsec tunnel. Other elements like ISAKMP policies and static routes are supporting configurations but do not activate the crypto map.

Exam trap

The trap here is focusing on IKE or NAT details while overlooking that the crypto map must be applied to an interface to become operational.

150
MCQhard

A network security team is implementing Cisco TrustSec in a campus network. The team wants to enforce access based on a tag carried in the packet rather than by IP address, and wants the tag to be propagated across the network without per-hop reclassification. Which Cisco TrustSec component assigns and inserts the Security Group Tag (SGT) at the ingress point?

A.The egress device reclassifying the packet and applying the SGT before forwarding.
B.The Cisco Identity Services Engine (ISE) inserting the SGT into every packet.
C.The Security Group Tag Exchange Protocol (SXP) on the egress device.
D.The ingress device performing classification and tagging of the packet.
AnswerD

In Cisco TrustSec, the ingress device classifies traffic and inserts the Security Group Tag into the packet, either inline in the Layer 2 frame or via a tag in the Ethernet header. This tagging at ingress allows downstream devices to enforce policy based on the SGT without reclassifying by IP. It is the correct component for assigning and inserting the SGT.

Why this answer

Cisco TrustSec relies on the ingress device to classify traffic and insert the Security Group Tag, which is then carried inline so downstream devices can enforce policy without reclassification. ISE defines the tags and policies but does not insert them, SXP propagates mappings to non-inline devices, and egress devices enforce rather than assign tags.

Exam trap

The trap here is assuming that ISE, which defines the security groups, also inserts the SGT into packets, when tagging actually occurs on the ingress network device.

← PreviousPage 2 of 3 · 161 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Security questions.