easyMultiple Choice
350-401 Practice Question: An engineer configures IP SLA 50 to monitor the…
An engineer configures IP SLA 50 to monitor the response time of a TCP connection to a server at 10.1.1.1 on port 80. The operation is used to trigger a backup path. The engineer notices that the IP SLA operation shows 'State: Active' and 'Latest RTT: 100 ms', but the server is actually down and not responding to TCP SYN packets. What is the most likely reason?
⚠ Common exam trap
Cisco often tests the misconception that IP SLA TCP connect only checks if the port is open (like a port scan), when in reality it performs a full TCP handshake, and the trap here is that candidates overlook how middleboxes can spoof successful handshakes, leading them to incorrectly choose option B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A stateful firewall or load balancer is responding to the TCP SYN on behalf of the server, causing the probe to succeed.
A stateful firewall or load balancer can intercept the TCP SYN packet sent by the IP SLA probe and respond with a SYN-ACK on behalf of the actual server, even if the server is down. This causes the IP SLA TCP connect operation to complete the three-way handshake and report a successful state with a valid RTT, misleading the engineer into thinking the server is reachable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A stateful firewall or load balancer is responding to the TCP SYN on behalf of the server, causing the probe to succeed.
Why this is correct
A stateful firewall or load balancer that performs TCP proxy or stateful inspection can intercept the inbound SYN and reply with a SYN-ACK on behalf of the backend server. The IP SLA TCP connect operation only confirms that it received a SYN-ACK, so the handshake appears successful even if the actual server is down or unreachable. Because the intermediary completes the three-way handshake, the probe incorrectly reports an RTT of 100 ms while real application traffic still fails.
- ✗
The IP SLA TCP connect probe does not actually verify that the server responds; it only checks if the port is open.
Why it's wrong here
The IP SLA TCP connect probe does execute a real three-way handshake: it transmits a SYN, waits for a SYN-ACK, and then sends an ACK to complete the connection. This means the probe does verify that some device is responding to TCP port 25, not merely that the port is open in a firewall rule. The limitation is that the response could come from an intermediary rather than the actual destination server, so a successful handshake does not prove the server is up.
- ✗
The IP SLA operation must be configured with a 'timeout' value lower than 100 ms to detect the failure.
Why it's wrong here
Incorrect because the RTT is 100 ms, so a timeout lower than that would cause a false failure; the issue is that the probe is getting a response from a device other than the server.
- ✗
The server is actually responding to the probe but not to other traffic because the probe uses a different source IP.
Why it's wrong here
The router's IP address is a legitimate, routable source address, and TCP servers do not discriminate against particular client IPs when processing connection requests. If the destination server were actually up and reachable, it would respond to the probe's SYN with a SYN-ACK regardless of the source address. Moreover, the probe's source IP is the same router that has been experiencing user-facing mail failures, so the server's inability to serve other traffic is not explained by a different source IP. The false success is instead caused by an intermediary like a stateful firewall or load balancer.
Visual reference
Go deeper
Related to this question
Learn chapter
BGP Fundamentals and Path Selection
Key term
Zone Based Firewall
A Cisco security feature that controls traffic between different parts of a network by grouping interfaces into zones and applying policies.
Key term
IP SLA
IP SLA (Service-Level Agreement) is a Cisco feature that actively monitors network performance by generating and measuring synthetic traffic between devices.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.