hardMultiple Choice
350-401 Practice Question: An engineer configures IP SLA 30 to monitor the…
An engineer configures IP SLA 30 to monitor the one-way delay to a remote site using UDP jitter. The operation is used to adjust routing metrics via route maps. The engineer notices that the IP SLA operation shows 'State: Active' but the one-way delay values are inconsistent, sometimes showing negative values. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the concept that one-way delay measurements require synchronized clocks, while round-trip time (RTT) does not, leading candidates to overlook the NTP requirement when they see negative delay values.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The source and destination routers do not have synchronized clocks via NTP, causing one-way delay calculations to be inaccurate.
IP SLA UDP jitter measures one-way delay by timestamping packets at both the source and destination. If the clocks on the two routers are not synchronized via NTP, the timestamps will be offset, leading to inaccurate (and sometimes negative) one-way delay values. Negative delay occurs when the destination timestamp appears earlier than the source timestamp due to clock skew.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IP SLA operation is not configured with a 'request-data-size' that matches the remote router's MTU, causing fragmentation and delay variations.
Why it's wrong here
Configuring a 'request-data-size' that exceeds the path MTU between the source and destination would cause IP fragmentation, possibly increasing delay and jitter or causing packet drops, but it cannot produce a negative one-way delay value. One-way delay is calculated as receive timestamp minus send timestamp; fragmentation only adds transit time, so the result would remain positive (or the probe would fail). Thus, this misconfiguration explains performance degradation, not the reported negative delay.
- ✓
The source and destination routers do not have synchronized clocks via NTP, causing one-way delay calculations to be inaccurate.
Why this is correct
The one-way delay measurement in an IP SLA UDP jitter operation is computed by subtracting the source router's send timestamp from the destination router's receive timestamp. If the two routers' clocks are not synchronized via NTP (or an equivalent time source), the calculated difference will be offset by the clock skew, which can easily produce a negative value. Without NTP, the timestamps are meaningless for absolute one-way delay, even though round-trip time would still be valid.
- ✗
The IP SLA operation is using a 'frequency' that is too high, causing the probes to overlap and corrupt the statistics.
Why it's wrong here
Setting the IP SLA 'frequency' to a value shorter than the operation's actual execution time can cause probes to overlap or be skipped, which may corrupt the statistics or cause false timeouts. However, overlapping probes would affect packet timing, loss, and jitter metrics, not the sign of the computed one-way delay. A negative delay is a mathematically impossible result under normal timing and is specifically a symptom of clock desynchronization, not probe scheduling.
- ✗
The remote router's IP SLA responder is not configured, so the source is using a different method to estimate delay.
Why it's wrong here
If the remote router did not have an IP SLA responder configured, the UDP jitter operation would fail entirely because it relies on the responder to process and timestamp the probe packets and return control messages. There is no fallback 'different method' for estimating one-way delay; the operation would report an error or no data. Consequently, a missing responder could not yield a negative delay value, as the measurement would never complete.
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
Route Redistribution and Filtering
Key term
IP SLA
IP SLA (Service-Level Agreement) is a Cisco feature that actively monitors network performance by generating and measuring synthetic traffic between devices.
Key term
Network Time Protocol
Network Time Protocol (NTP) is a networking protocol that synchronizes the clocks of computers and devices over a network to a common reference time source, typically Coordinated Universal Time (UTC).
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.