Courseiva
Back to ENCOR 350-401 questions

Scenario-based practice

Hard Difficulty Questions

Practise ENCOR 350-401 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
350-401
exam code
Cisco
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related 350-401 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Which three statements about using Python for device inventory and data serialization in network automation are true? (Choose three.)

Question 2hardmultiple choice
Open the full VLAN trunking answer →

A network engineer runs the following command on Switch SW1:

SW1# show vlan id 10

VLAN ID: 10
VLAN Name: Sales
VLAN Type: Ethernet
VLAN State: active

MTU: 1500

Remote SPAN VLAN: No

Primary VLAN ID: 10

Private VLAN Type: Primary

Associated Secondary VLAN IDs: 100, 200

Based on this output, what can be concluded?

Question 3hardmultiple choice
Review the full OSPF breakdown →

A large enterprise has a campus network with a collapsed core design. The core switch connects to two distribution switches, each serving several access switches. The network uses OSPF as the IGP. Recently, after a link failure between the core and distribution switch A, the network experienced a 30-second outage before converging. The engineer wants to improve convergence time to under 5 seconds. The budget is limited, so hardware upgrades are not an option. The engineer is considering the following actions: A. Enable OSPF Fast Hello on all interfaces. B. Reduce OSPF dead timer to 1 second and hello timer to 333 milliseconds. C. Implement OSPF LSA throttling with a minimum interval of 0 ms. D. Use OSPF incremental SPF (iSPF).

Which action will provide the most significant improvement in convergence time for this scenario?

Question 4hardmultiple choice
Read the full MPLS explanation →

An engineer is deploying QoS on a WAN link between two sites using a Cisco ISR 4451 router. The link is a 10 Mbps MPLS circuit. The engineer wants to ensure that voice traffic (EF) is never dropped, even during congestion. The current policy uses a single class map for voice with a policer that drops excess traffic. During peak hours, users report choppy voice calls. What change should the engineer make?

Question 5hardmultiple choice
Open the full STP breakdown →

A network engineer is troubleshooting an STP issue in a network that uses Rapid PVST+. The network has a root bridge (SW1) and a secondary root bridge (SW2). The engineer notices that after a link failure between SW1 and SW2, the network takes longer than expected to converge. The engineer checks the configuration and finds that SW2 has the 'spanning-tree uplinkfast' command enabled. The engineer also notices that SW2 has a lower priority than SW1. What is the most likely cause of the slow convergence?

Question 6hardmultiple choice
Study the full EIGRP explanation →

A network engineer is configuring EIGRP on a router that connects to a service provider network. The engineer wants to advertise a default route to internal routers. The engineer configures 'ip default-network 0.0.0.0' and redistributes a static default route into EIGRP. However, internal routers are not receiving the default route. The engineer checks the EIGRP topology table and sees the default route with a metric of 1. What is the most likely reason?

Question 7hardmultiple choice
Read the full NAT/PAT explanation →

A network engineer is configuring NAT overload (PAT) on a Cisco router to allow multiple internal hosts to share a single public IP address. The engineer uses the command ip nat inside source list 1 interface GigabitEthernet0/0 overload. After testing, internal hosts can access the internet, but some applications fail intermittently. The engineer suspects a NAT issue. What is the most likely cause?

Which three statements about gRPC and gNMI in the context of model-driven telemetry are true? (Choose three.)

Question 9hardmulti select
Full question →

Which three statements about 802.1X port-based authentication are true? (Choose three.)

Question 10hardmultiple choice
Open the full VLAN trunking answer →

A network engineer runs the following command on Switch SW1:

SW1# show interfaces trunk

Port Mode Encapsulation Status Native vlan Gi0/1 on 802.1q trunking 1 Gi0/2 on 802.1q trunking 1

Port Vlans allowed on trunk Gi0/1 1-1005 Gi0/2 1-1005

Port Vlans allowed and active in management domain Gi0/1 1,10,20 Gi0/2 1,10,20

Port Vlans in spanning tree forwarding state and not pruned Gi0/1 1,10,20 Gi0/2 1,10,20

Based on this output, what can be concluded?

Question 11hardmultiple choice
Full question →

A network engineer runs the following command on Switch SW7:

SW7# show monitor session 7

Session 7 --------- Type : Local Session Source Ports : Both : Gi1/0/1 Destination Ports : Gi1/0/20

Encapsulation      : Native

Ingress : Enabled

Based on this output, what can be concluded?

Question 12hardmultiple choice
Open the full VLAN trunking answer →

An enterprise uses VRF-lite to isolate guest Wi-Fi traffic from corporate traffic on a Cisco Catalyst 9300 switch. The guest VRF (GUEST) is configured on VLAN 100, and the corporate VRF (CORP) on VLAN 200. Both VRFs use the same default gateway router connected via a trunk. The engineer notices that guest devices can reach the internet but cannot access the guest captive portal hosted on a server in VLAN 100. The server's IP is reachable from the switch itself. What is the issue?

Question 13hardmulti select
Read the full REST/YANG explanation →

Which three statements about YANG data models are true? (Choose three.)

Question 14hardmulti select
Read the full REST/YANG explanation →

Which three statements about YANG data models are true? (Choose three.)

Drag and drop each RESTCONF method on the left to its equivalent NETCONF operation on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

get-config (retrieves data)

edit-config with operation create

edit-config with operation replace

edit-config with operation merge

edit-config with operation delete

Question 16hardmultiple choice
Study the full SD-Access breakdown →

A network engineer is deploying Cisco SD-Access in a large enterprise campus. The design requires that all user traffic be segmented by Virtual Network (VN) and that the fabric edge nodes perform SGT-based enforcement. The engineer notices that traffic between two endpoints in the same IP subnet but different VNs is being forwarded directly at the fabric edge without any SGT inspection. What is the most likely cause?

Question 17hardmultiple choice
Read the full wireless explanation →

A company is deploying a new Cisco wireless LAN controller (WLC) and wants to use RADIUS for authenticating wireless users. The WLC is configured with the RADIUS server IP, shared secret, and authentication port 1812. However, users are unable to authenticate. The network engineer checks the RADIUS server logs and sees that the server is receiving authentication requests from the WLC but is responding with an 'Access-Reject' message. The WLC logs show 'RADIUS server not responding' for the same server. What is the most likely cause?

Question 18hardmultiple choice
Review the full routing breakdown →

An engineer configures IP SLA 100 to monitor the jitter and latency of a VoIP call path between two branch routers. The configuration uses UDP jitter with a target of 192.168.2.2 on port 16384. The engineer notices that the IP SLA operation shows 'State: Active' but no jitter or latency statistics are collected. The router is generating the probe packets, but the remote router does not respond. What is the most likely reason?

Question 19hardmultiple choice
Open the full VLAN trunking answer →

An engineer is configuring RSPAN to monitor traffic from multiple switches in a data center. The monitoring station is connected to a central switch. The engineer has configured an RSPAN VLAN (VLAN 999) on all switches and set up the source sessions on the remote switches. However, the monitoring station receives no traffic. On the central switch, the engineer verifies that the RSPAN VLAN is active and that the destination session is configured. What is a likely missing configuration?

Question 20hardmulti select
Read the full VPN explanation →

Which two statements about DMVPN Phase 3 are true? (Choose two.)

These 350-401 practice questions are part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style 350-401 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.