350-401 · topic practice

Enterprise Network Design practice questions

Practise ENCOR 350-401 Enterprise Network Design practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Enterprise Network Design

What the exam tests

What to know about Enterprise Network Design

Enterprise Network Design questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Enterprise Network Design exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Enterprise Network Design questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Open the full STP breakdown →

A large enterprise is redesigning its campus network to support 5000 users across three buildings. The design must provide high availability and fast convergence in case of a link failure. The network engineer is considering using Spanning Tree Protocol (STP) in the access layer. What is the primary design concern with using STP in this scenario?

Question 2mediummultiple choice
Study the full virtualization explanation →

A company is deploying a new data center and needs to choose between a three-tier (core, aggregation, access) and a spine-leaf architecture. The network engineer is concerned about east-west traffic patterns for server virtualization. Which architecture is most suitable and why?

Question 3hardmultiple choice
Open the full VLAN trunking answer →

An enterprise network is experiencing high CPU utilization on the distribution layer switches. The design uses VLANs with SVIs for inter-VLAN routing, and HSRP for first-hop redundancy. The engineer notices that the standby switch is also experiencing high CPU. What is the most likely cause?

A network engineer is designing a WAN connection for a branch office that requires high availability and bandwidth aggregation. The branch has two internet connections from different ISPs. The engineer wants to use both links actively for load balancing and failover. Which design approach should be used?

A campus network uses a collapsed core design with two distribution switches and multiple access switches. The engineer wants to ensure that if one distribution switch fails, the access switches can still reach the core. The access switches are connected to both distribution switches. What additional configuration is required on the access switches?

Question 6hardmultiple choice
Read the full wireless explanation →

An enterprise is migrating from a traditional three-tier campus design to a software-defined access (SD-Access) fabric. The engineer needs to ensure that the existing wireless infrastructure integrates seamlessly. Which component of SD-Access is responsible for integrating wireless and wired policies?

A network engineer is designing a data center network using Cisco ACI. The design must support multiple tenants with isolated policies. The engineer needs to ensure that traffic between endpoints in different tenants is blocked by default. Which ACI construct provides this isolation?

Question 8easymultiple choice
Review the full routing breakdown →

A company is deploying a new branch office with 50 users. The branch needs to connect to the headquarters via a WAN link. The engineer wants to use a design that minimizes the need for routing protocol configuration at the branch while still providing redundancy. Which design is most appropriate?

Question 9easymultiple choice
Review the full OSPF breakdown →

An enterprise network uses OSPF in the core and EIGRP in the campus distribution layer. The engineer needs to redistribute routes between the two protocols. Which design consideration is most important to prevent routing loops?

Question 10mediummultiple choice
Study the full SD-Access breakdown →

An architect is designing an SD-Access fabric for a campus network that must support dynamic endpoint grouping based on user identity and device type. The design must minimize manual policy configuration and allow the fabric to enforce access policies at the edge. Which combination of components and protocols is required to meet these requirements?

Question 11mediummultiple choice
Read the full VPN explanation →

A network team is designing an SD-WAN overlay for a multinational enterprise with 500+ branch sites. The design must ensure that control plane traffic (e.g., OMP updates) is encrypted and authenticated between all vSmart controllers and vEdge routers, while allowing data plane traffic to use IPsec tunnels between branch sites directly. Which architectural element is responsible for orchestrating the initial authentication and certificate enrollment of all SD-WAN devices?

Question 12mediummultiple choice
Study the full QoS explanation →

An enterprise is redesigning its WAN QoS architecture to support real-time voice, video, and critical data applications over a limited bandwidth link. The architect must ensure that voice traffic receives strict priority queuing and that video traffic is guaranteed a minimum bandwidth, while allowing best-effort traffic to use remaining capacity. Which queuing strategy should be deployed on the WAN edge routers?

Question 13mediummultiple choice
Study the full virtualization explanation →

A service provider is deploying NFV to host virtual network functions (VNFs) such as firewalls, routers, and WAN optimizers on a single server. The design must support service chaining, where traffic flows through multiple VNFs in a specific order, and must allow dynamic insertion of new VNFs without re-cabling. Which technology should be used to implement the service chain?

Question 14mediummultiple choice
Study the full virtualization explanation →

A data center architect is designing a virtualized environment to host critical applications. The design must maximize performance by allowing virtual machines (VMs) to directly access physical CPU cores and memory without hypervisor overhead for latency-sensitive workloads. Which hypervisor configuration should be used?

A network architect is designing a campus network for a large university with 10,000+ users. The design must provide high availability, minimize failure domains, and allow for easy scaling of the access layer. The core layer should be resilient and support fast convergence. Which hierarchical design model best meets these requirements?

Question 16mediummultiple choice
Read the full VPN explanation →

An enterprise is deploying Cisco SD-WAN and must ensure that data plane traffic between branch sites is encrypted and authenticated. The design must also allow the use of application-aware routing to steer traffic based on real-time performance metrics. Which component is responsible for establishing and managing the IPsec tunnels between branch routers?

Question 17mediummultiple choice
Study the full QoS explanation →

A network architect is designing QoS for a converged network carrying voice, video, and data. The design must use the DiffServ model and ensure that voice traffic is marked with the highest priority and that video traffic is marked with a lower priority but still above data. Which DSCP markings should be assigned to voice and video traffic, respectively, to comply with the standard Per-Hop Behavior (PHB) definitions?

An enterprise is migrating its data center to a leaf-spine architecture to support high east-west traffic between servers. The design must provide non-blocking forwarding and allow for easy scaling by adding more spines. Which characteristic is essential for the spine switches in this design?

Question 19mediummultiple choice
Review the full OSPF breakdown →

Examine the following configuration snippet:

interface GigabitEthernet0/1
 ip address 192.168.1.1 255.255.255.0
 ip ospf network point-to-point
 ip ospf hello-interval 10
 ip ospf dead-interval 40

!

router ospf 1
 network 192.168.1.0 0.0.0.255 area 0

What is the effect of this configuration?

Question 20mediummultiple choice
Open the full VLAN trunking answer →

Consider this configuration:

interface GigabitEthernet0/2
 switchport mode trunk
 switchport trunk native vlan 10
 switchport trunk allowed vlan 10,20,30

!

interface Vlan10
 ip address 192.168.10.1 255.255.255.0

Which statement is true about this configuration?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Enterprise Network Design sessions

Start a Enterprise Network Design only practice session

Every question in these sessions is drawn from the Enterprise Network Design domain — nothing else.

Related practice questions

Related 350-401 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 350-401 exam test about Enterprise Network Design?
Enterprise Network Design questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Enterprise Network Design questions in a focused session?
Yes — the session launcher on this page draws every question from the Enterprise Network Design domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 350-401 topics?
Use the topic links above to move to related areas, or go back to the 350-401 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 350-401 exam covers. They are not copied from any real exam or dump site.