Courseiva
easyMultiple Select

350-401 Practice Question: Which two statements about network design for…

Which two statements about network design for high availability are true? (Choose two.)

⚠ Common exam trap

The trap here is assuming HSRP load-balances by default; candidates who confuse HSRP with GLBP pick option B, but HSRP is active/standby only.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HSRP allows two or more routers to share a virtual IP address, providing default gateway redundancy.

Option A is correct because HSRP (Hot Standby Router Protocol) lets two or more routers form a group that shares a single virtual IP address and virtual MAC address, so hosts use that virtual IP as their default gateway and failover to a standby router occurs transparently if the active router fails. Option C is correct because StackWise Virtual (Cisco StackWise Virtual / VSS-style technology) combines two physical switches into one logical switch with a single control plane and management interface, so if one chassis fails the other continues forwarding, providing device-level redundancy. Option B is wrong because HSRP is active/standby by design and does not load-balance traffic across all group members (that requires GLBP or MHSRP). Option D is wrong because a single uplink is a single point of failure; high availability requires redundant uplinks or an EtherChannel. Option E is wrong because redundant links between switches create Layer 2 loops, so STP (or a loop-prevention mechanism like RSTP/MSTP) is required to block redundant paths.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    HSRP allows two or more routers to share a virtual IP address, providing default gateway redundancy.

    Why this is correct

    HSRP satisfies the default gateway redundancy constraint by having routers share a virtual IP and MAC address, so hosts keep one gateway address. The active router forwards traffic; if it fails, the standby assumes the virtual address, preserving gateway availability without host reconfiguration.

  • ✗

    HSRP automatically load-balances traffic across all routers in the group.

    Why it's wrong here

    HSRP elects one active and one standby router; it does not distribute traffic across the group. It is tempting because GLBP provides gateway load balancing, and HSRP is often assumed to behave the same way since both are first-hop redundancy protocols.

  • ✓

    StackWise Virtual allows two physical switches to operate as a single logical switch for redundancy.

    Why this is correct

    StackWise Virtual combines two physical switches into one logical entity, so a single control plane manages both and failover occurs without protocol reconvergence. This satisfies the high-availability requirement by removing spanning-tree blocking and enabling active-active forwarding across both chassis, eliminating the single points of failure inherent in standalone switch designs.

  • ✗

    A single uplink from an access switch to the distribution layer is sufficient for high availability.

    Why it's wrong here

    A single uplink creates a lone path, so its failure severs the access switch entirely; high availability requires redundant links or stacked switches. It is tempting because single uplinks are common in small or budget-constrained access designs where resilience is not the requirement.

  • ✗

    Redundant links between switches do not require Spanning Tree Protocol to prevent loops.

    Why it's wrong here

    Redundant links between switches form Layer 2 loops, so STP (or an alternative such as FabricPath or VXLAN) must block them; without it, broadcast storms occur. It is tempting because loop prevention is sometimes offloaded to routing or MLAG designs, but plain redundant links still need STP.

Visual reference

SW1 Root Bridge SW2 SW3 BLK DP DP RP RP STP blocks one link to prevent loops DP = Designated Port RP = Root Port BLK = Blocked

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.