Courseiva

CCNA OSPF Questions

75 of 129 questions · Page 1/2 · OSPF topic · Answers revealed

1
MCQmedium

interface GigabitEthernet0/1 ip address 10.1.1.1 255.255.255.0 mpls ip ! interface GigabitEthernet0/2 ip address 10.2.2.1 255.255.255.0 mpls ip ! router ospf 1 network 10.0.0.0 0.255.255.255 area 0 ! router ldp interface GigabitEthernet0/1 ! What is the effect of this configuration?

A.LDP will only form an adjacency over GigabitEthernet0/1; no label exchange occurs on GigabitEthernet0/2.
B.LDP will automatically enable on GigabitEthernet0/2 because MPLS is enabled there.
C.The configuration will fail because LDP must be enabled on all MPLS interfaces.
D.OSPF will automatically enable LDP on all interfaces in area 0.
AnswerA

LDP hello messages are multicast on interfaces where LDP is explicitly enabled, typically via the 'mpls ldp' configuration. Because GigabitEthernet0/2 lacks this LDP configuration, it does not participate in LDP neighbor discovery or label binding exchange. Consequently, the LDP adjacency is confined to GigabitEthernet0/1, and only that interface exchanges label mappings; MPLS forwarding may still occur on Gi0/2 using labels learned from other sources, but no dynamic LDP labels are exchanged there.

Why this answer

LDP is explicitly enabled only on GigabitEthernet0/1 under the 'router ldp' configuration. Although MPLS IP is enabled on GigabitEthernet0/2, LDP does not automatically form an adjacency or exchange labels on that interface unless it is explicitly configured under the LDP router process. LDP adjacencies are interface-specific and require the 'interface' command under 'router ldp' to be activated.

Exam trap

Cisco often tests the distinction between 'mpls ip' (which enables MPLS forwarding) and LDP configuration (which controls label distribution adjacencies), trapping candidates who assume that enabling MPLS on an interface automatically activates LDP.

How to eliminate wrong answers

Option B is wrong because enabling 'mpls ip' on an interface does not automatically enable LDP; LDP must be explicitly configured under 'router ldp' with the specific interface. Option C is wrong because the configuration will not fail; LDP can be selectively enabled on a subset of MPLS-enabled interfaces, and MPLS forwarding can still occur on other interfaces via static labels or other label distribution protocols. Option D is wrong because OSPF has no mechanism to automatically enable LDP; LDP is a separate protocol that must be configured independently, regardless of the IGP.

2
MCQhard

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using SHA-256 HMAC cryptographic authentication on an interface. Which command sequence correctly enables this authentication?

A.ip ospf authentication key-chain <name> and configure a key chain with key 1 using cryptographic-algorithm hmac-sha-256
B.ip ospf authentication followed by ip ospf authentication-key <password>
C.ip ospf authentication null
D.ip ospf authentication message-digest followed by ip ospf message-digest-key 1 md5 <key>
AnswerA

This sequence correctly enables OSPFv2 SHA-256 HMAC authentication. The interface command ip ospf authentication key-chain references a key chain, which must be defined globally with a key that specifies the cryptographic algorithm hmac-sha-256 and a password. This provides stronger security than MD5. The key chain allows for key rollover and multiple keys with different lifetimes, which is essential for operational flexibility.

Why this answer

OSPFv2 supports SHA-256 HMAC authentication through key chains. The interface command ip ospf authentication key-chain <name> references a key chain configured with key 1 and cryptographic-algorithm hmac-sha-256. This provides cryptographic authentication with stronger hashing than MD5.

Simple authentication and MD5 do not meet the SHA-256 requirement, and null disables authentication.

Exam trap

The trap here is assuming that MD5 message-digest authentication is equivalent to SHA-256 HMAC, when MD5 uses a different and weaker algorithm.

3
Matchingmedium

Drag and drop each OSPF packet type on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Discovers neighbors and maintains adjacency state

Contains a list of LSA headers for database synchronization

Requests specific LSAs from a neighbor

Sends one or more complete LSAs to a neighbor

Confirms receipt of LSU packets

Why these pairings

Hello packets discover and maintain neighbor relationships; DBD packets contain a summary of the LSDB; LSR packets request specific LSAs; LSU packets send full LSAs in response to LSRs; LSAck packets acknowledge receipt of LSUs.

4
MCQmedium

A network engineer configures VRF-lite on a router with the following snippet: vrf definition GREEN rd 200:1 ! interface GigabitEthernet0/3 vrf forwarding GREEN ip address 172.16.1.1 255.255.255.0 ! router ospf 10 vrf GREEN network 172.16.1.0 0.0.0.255 area 0 What is missing from this configuration to enable proper OSPF routing within VRF GREEN?

A.The configuration is complete and OSPF will operate correctly within VRF GREEN.
B.The 'network' command should specify the interface instead of the subnet.
C.The 'vrf definition GREEN' must include a 'route-target' command.
D.The OSPF process must be configured under the global VRF context, not using 'vrf GREEN'.
AnswerA

The configuration is complete because the 'router ospf <pid> vrf GREEN' command correctly creates an OSPF process bound to VRF GREEN, and the 'network' statement uses a wildcard mask to advertise the appropriate subnet into OSPF. The router-id is automatically selected from the highest loopback or active interface address in the VRF, so no explicit router-id is required. Thus, OSPF will operate correctly within the VRF.

Why this answer

The configuration is complete for VRF-lite OSPF routing. In VRF-lite, the 'vrf definition GREEN' with an RD, the interface assignment via 'vrf forwarding GREEN', and the OSPF process with 'vrf GREEN' and the network statement are all that is required. OSPF will operate correctly within VRF GREEN using the specified network in area 0.

Exam trap

Cisco often tests the misconception that VRF-lite requires 'route-target' commands, which are actually only necessary for MPLS VPNs, not for simple VRF-lite configurations.

How to eliminate wrong answers

Option B is wrong because the 'network' command in OSPF can specify a subnet with a wildcard mask, which is the standard method; it does not need to specify the interface directly. Option C is wrong because 'route-target' commands are required for MPLS VPN (VRF-lite does not use MPLS), not for VRF-lite where only the RD is needed for route distinguishment. Option D is wrong because the OSPF process can be configured under the global VRF context using the 'vrf GREEN' keyword after the process ID, which is the correct syntax for associating an OSPF process with a VRF.

5
Drag & Dropmedium

Drag and drop the steps of OSPF virtual link configuration into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

A virtual link connects a non-backbone area to Area 0 through a transit area. First, identify the ABR with the transit area, then configure the virtual link on both ABRs using the router ID of the neighbor, ensure the transit area has full OSPF adjacency, and finally verify the virtual link is operational.

6
MCQeasy

A network engineer is configuring a Cisco IOS router to support OSPFv3 for IPv6. The router must form adjacencies on its GigabitEthernet0/0 interface, which is assigned to area 0. Which command is required to enable OSPFv3 on the interface?

A.ospf ipv6 1 area 0
B.router ospfv3 1 area 0
C.ipv6 router ospf 1 area 0
D.ipv6 ospf 1 area 0
AnswerD

The command 'ipv6 ospf 1 area 0' is used in interface configuration mode to enable OSPFv3 on that interface and assign it to area 0. The process ID '1' must match the OSPFv3 process configured globally with 'ipv6 router ospf 1'. This command allows the interface to form adjacencies and participate in OSPFv3. Without it, OSPFv3 will not run on the interface, even if the global process is configured.

Why this answer

To enable OSPFv3 on an interface, you use the interface configuration command 'ipv6 ospf <process-id> area <area-id>'. This command activates OSPFv3 on the interface and assigns it to the specified area. The process ID must match the one configured globally with 'ipv6 router ospf <process-id>'.

The other options are invalid commands or incorrect syntax.

Exam trap

The trap here is mixing up the global OSPFv3 command with the interface-level command, or reversing the keyword order.

7
MCQhard

An engineer is writing an Ansible playbook to configure OSPF on a fleet of Cisco Nexus 9000 switches. The playbook uses the nxos_ospf module. When executed, the playbook reports 'changed' for every switch, even on subsequent runs when no configuration changes are made. The engineer wants to achieve idempotent behavior. What is the most likely cause of the non-idempotent results?

A.The Ansible control node is using an outdated version of the nxos_ospf module that does not support idempotency.
B.The playbook does not specify all OSPF parameters, such as 'router-id', causing the module to detect a difference with the running configuration.
C.The switches have different NX-OS versions, causing the module to behave inconsistently.
D.The engineer forgot to use the '--check' flag to verify idempotency.
AnswerB

The playbook is likely omitting OSPF attributes that the nxos_ospf module tracks, such as 'router-id'. When a parameter is not specified, the module may treat the desired value as empty or default (e.g., the router-id derived from the loopback address), while the running configuration contains an explicit value, causing the module to detect a difference and report 'changed'. This is a classic idempotency issue: the module does not ignore unspecified parameters; it attempts to reconcile the configuration to the playbook's declared state, and every run sees the same mismatch.

Why this answer

The nxos_ospf module requires all mandatory OSPF parameters to be explicitly defined in the playbook to achieve idempotency. If parameters such as 'router-id' are omitted, the module compares the current running configuration (which may have a default or previously configured router-id) against the playbook's parameters. Since the playbook does not specify the router-id, the module interprets this as a missing parameter and attempts to reconfigure OSPF, resulting in a 'changed' status on every run.

Specifying all OSPF parameters ensures the module can accurately detect that the desired state matches the current state.

Exam trap

Cisco often tests the misconception that omitting optional parameters in Ansible modules will be ignored, when in fact the module treats missing parameters as a mismatch, causing non-idempotent behavior.

How to eliminate wrong answers

Option A is wrong because the nxos_ospf module has supported idempotency for many releases; an outdated version would typically cause errors or missing features, not a persistent 'changed' status on every run. Option C is wrong because different NX-OS versions may affect module behavior, but the core issue is parameter specification, not version inconsistency; the module is designed to work across versions with proper parameters. Option D is wrong because the '--check' flag is used to simulate changes and verify idempotency, not to cause or fix idempotency issues; forgetting it does not cause non-idempotent results.

8
MCQhard

A network engineer is troubleshooting an OSPF issue where a router is not learning a route to a network that is advertised via a type 5 LSA from an ASBR. The engineer checks the OSPF database and sees the type 5 LSA, but the route is not in the routing table. The forwarding address in the LSA is 0.0.0.0. What is the most likely cause?

A.The ASBR is not reachable via an OSPF internal route.
B.The type 5 LSA has a metric of 16777215.
C.The OSPF process ID on the ASBR is different from the other routers.
D.The type 5 LSA is being filtered by an outbound route filter.
AnswerA

OSPF computes external routes from type 5 LSAs only if the originating ASBR is reachable through an intra-area or inter-area route. The SPF algorithm builds a shortest-path tree to the ASBR first; if the ASBR's router LSA is missing or the resulting next hop has no valid OSPF route, the external prefix is left in the LSDB but never installed in the RIB. This is a fundamental adjacency-dependent rule for external route installation.

Why this answer

When a Type 5 LSA has a forwarding address of 0.0.0.0, OSPF routers will use the ASBR as the next hop for the external route. For the route to be installed in the routing table, the ASBR must be reachable via an OSPF intra-area or inter-area route. If the ASBR is not reachable (e.g., no valid OSPF route to the ASBR's router ID), the Type 5 LSA is considered unreachable and is not installed, even though it exists in the OSPF database.

Exam trap

Cisco often tests the misconception that a Type 5 LSA present in the database automatically guarantees the route is installed, but the trap here is that the forwarding address of 0.0.0.0 requires the ASBR to be reachable via an OSPF internal route, which is a common oversight.

How to eliminate wrong answers

Option B is wrong because a metric of 16777215 (the maximum OSPF metric) would cause the route to be considered unreachable, but the question states the LSA is present in the database and the forwarding address is 0.0.0.0, not that the metric is invalid. Option C is wrong because OSPF process IDs are locally significant and do not affect the exchange of LSAs or route installation between routers; different process IDs on different routers do not prevent route learning. Option D is wrong because an outbound route filter would prevent the LSA from being sent or received, but the engineer confirms the Type 5 LSA is present in the database, meaning it was not filtered.

9
Drag & Dropmedium

Drag and drop the steps of OSPF SPF calculation steps (Dijkstra) into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

The Dijkstra algorithm first initializes the candidate list with the root node, then iteratively moves the lowest-cost candidate to the tree, updating neighbor costs, and finally builds the routing table from the shortest-path tree.

10
MCQhard

A network engineer is configuring OSPF on a multiaccess segment. The design requires that the DR/BDR election be deterministic, with Router A always becoming the DR and Router B always becoming the BDR. Both routers are Cisco IOS devices. Which configuration on Router A ensures it wins the DR election?

A.Set the OSPF priority to 0 on Router A's interface.
B.Configure a higher Router ID on Router B.
C.Set the OSPF priority to 255 on Router A's interface.
D.Set the OSPF network type to point-to-point on Router A's interface.
AnswerC

OSPF DR/BDR election is based first on interface priority, then on Router ID. The highest priority wins. Priority 255 is the maximum value and ensures Router A has the highest priority on the segment, making it the DR provided no other router has the same priority with a higher Router ID. This is the standard way to force a router to become DR.

Why this answer

To ensure a router becomes DR, its OSPF interface priority must be higher than all other routers on the segment. Priority 255 is the maximum and guarantees victory unless another router also has 255 and a higher Router ID. Setting priority to 0 makes a router ineligible, a higher Router ID on another router would favor that router, and point-to-point network type removes DR/BDR election altogether.

Exam trap

The trap here is thinking that Router ID is the primary factor in DR election, when priority takes precedence.

11
MCQmedium

Examine the following OSPF configuration on a Cisco IOS-XE router: router ospf 1 router-id 1.1.1.1 network 10.0.0.0 0.255.255.255 area 0 network 192.168.1.0 0.0.0.255 area 1 default-information originate always metric 10 metric-type 1 What is the effect of the 'default-information originate always' command?

A.A default route is advertised into OSPF only if the router has a default route in its routing table.
B.A default route is unconditionally advertised into OSPF with metric 10 and type E1.
C.The router will redistribute static default routes into OSPF.
D.The router will generate a default route only for area 1.
AnswerB

The always keyword removes the dependency on a local default route, so the router advertises 0.0.0.0/0 into OSPF regardless of its own routing table. The metric 10 and metric-type 1 arguments set the advertised cost and mark it as an E1 external route.

Why this answer

The 'default-information originate always' command unconditionally injects a default route (0.0.0.0/0) into OSPF, regardless of whether the router itself has a default route. The metric 10 and metric-type 1 set the cost and external type to E1, meaning the cost is the sum of external and internal costs.

Exam trap

350-401 often tests the 'always' keyword's effect, causing candidates to think it requires a default route in the routing table or that it redistributes static routes.

How to eliminate wrong answers

Option A is wrong because without the 'always' keyword, the router only advertises a default route if it has one in its routing table. Option C is wrong because the command does not redistribute static default routes; it originates a default route into OSPF. Option D is wrong because the command originates the default route into all areas the router is connected to, not just area 1.

12
MCQmedium

Examine this OSPF configuration on router R4: interface GigabitEthernet0/0 ip address 172.16.1.4 255.255.255.0 ip ospf 1 area 0 ip ospf cost 50 ! router ospf 1 router-id 4.4.4.4 network 172.16.0.0 0.0.255.255 area 0 What is the OSPF cost of the GigabitEthernet0/0 interface?

A.50
B.1 (default for GigabitEthernet)
C.100 (derived from reference bandwidth 100 Mbps / 1 Gbps)
D.10 (derived from reference bandwidth 1000 Mbps / 100 Mbps)
AnswerA

The OSPF cost on this interface is explicitly configured to 50 using the 'ip ospf cost' command. This manual assignment takes absolute precedence over any automatically derived cost, so the router uses exactly 50 when computing the SPF metric for routes learned via this interface. Because the configured value is 50, it is the correct answer.

Why this answer

The OSPF cost of an interface is determined by the `ip ospf cost` command, which explicitly overrides the default cost calculation based on reference bandwidth. Since R4's GigabitEthernet0/0 interface has `ip ospf cost 50` configured under it, the cost is set to 50 regardless of the interface bandwidth or reference bandwidth settings.

Exam trap

Cisco often tests the precedence of the `ip ospf cost` command over the default cost calculation, trapping candidates who assume the default cost for GigabitEthernet (1) or who incorrectly calculate the cost using the reference bandwidth formula without considering the explicit configuration.

How to eliminate wrong answers

Option B is wrong because the default OSPF cost for a GigabitEthernet interface is not 1; the default cost is calculated as reference bandwidth (default 100 Mbps) divided by interface bandwidth (1000 Mbps), which equals 1 only if the reference bandwidth is set to 1000 Mbps. Option C is wrong because the cost derived from the default reference bandwidth (100 Mbps) divided by 1 Gbps would be 0.1, which is not a valid OSPF cost (costs are integers, and Cisco rounds up to 1). Option D is wrong because the calculation of 1000 Mbps / 100 Mbps equals 10, but this would only apply if the reference bandwidth were changed to 1000 Mbps and the interface bandwidth were 100 Mbps, which does not match the GigabitEthernet interface's actual bandwidth of 1 Gbps.

13
MCQmedium

Examine the following partial configuration on a Cisco IOS-XE device: interface GigabitEthernet0/1 ip address 10.1.1.1 255.255.255.0 ip ospf hello-interval 5 ip ospf dead-interval 20 ! What is the effect of this configuration?

A.The router will send OSPF hello packets every 5 seconds and declare a neighbor dead after 20 seconds of no hello.
B.The router will send OSPF hello packets every 10 seconds and declare a neighbor dead after 40 seconds, overriding the configuration.
C.The configuration is invalid because the dead interval must be exactly four times the hello interval.
D.The router will not form OSPF adjacencies because the hello and dead intervals are not default.
AnswerA

This is correct because OSPF hello and dead intervals are configurable per interface, and once configured with 5 and 20 seconds, the router will use those exact values for sending hello packets and for declaring a neighbor unreachable. The dead interval of 20 seconds is four times the hello interval, maintaining the recommended ratio for OSPF stability and fast convergence. This configuration is valid and commonly used to tune OSPF convergence times on point-to-point links.

Why this answer

The `ip ospf hello-interval 5` command sets the OSPF hello interval to 5 seconds, and the `ip ospf dead-interval 20` command sets the dead interval to 20 seconds. These per-interface commands override the default hello interval of 10 seconds and dead interval of 40 seconds for broadcast networks, allowing the router to send hello packets every 5 seconds and declare a neighbor dead after 20 seconds of no hello reception.

Exam trap

Cisco often tests the misconception that the dead interval must always be exactly four times the hello interval, but in reality, while the default ratio is 4:1, you can configure any values as long as they match on neighboring routers.

How to eliminate wrong answers

Option B is wrong because it incorrectly states that the router will send hello packets every 10 seconds and use a dead interval of 40 seconds, which would only occur if the default intervals were used; the explicit configuration overrides these defaults. Option C is wrong because while the dead interval is typically four times the hello interval by default, Cisco IOS-XE allows manual configuration of any hello and dead intervals, and the configuration is valid as long as both intervals are set consistently on neighboring routers. Option D is wrong because the router can still form OSPF adjacencies with non-default hello and dead intervals, provided that the neighboring routers are configured with matching hello and dead intervals; mismatched intervals prevent adjacency formation, not the fact that they are non-default.

14
Multi-Selecthard

Which three statements about OSPF LSA types are true? (Choose three.)

Select 3 answers
A.Type 1 LSAs are generated by every OSPF router to describe its own interfaces and neighbors.
B.Type 2 LSAs are generated by the Designated Router on multiaccess networks.
C.Type 5 LSAs are generated by ASBRs to advertise routes from other routing domains.
D.Type 3 LSAs are generated by ASBRs to summarize routes between areas.
E.Type 4 LSAs are generated by the ASBR to advertise its presence to other areas.
AnswersA, B, C

Every OSPF router originates a Type 1 Router LSA describing its own interfaces, neighbours and link costs, flooded within its area only. This satisfies the requirement that each router advertises its local topology, forming the basis of the area's shortest-path tree.

Why this answer

Option A is correct because Type 1 Router LSAs are originated by every OSPF router (in each area it belongs to) to describe its own links, interfaces, and neighbor relationships within that area. Option B is correct because Type 2 Network LSAs are generated only by the Designated Router (DR) on multiaccess segments such as Ethernet, representing the subnet and the routers attached to it. Option C is correct because Type 5 AS External LSAs are originated by ASBRs to advertise routes redistributed from outside the OSPF autonomous system (other routing domains) throughout the OSPF domain.

Option D is wrong because Type 3 Summary LSAs are generated by ABRs, not ASBRs, to advertise inter-area routes. Option E is wrong because Type 4 Summary ASBR LSAs are generated by ABRs to advertise the location of an ASBR to other areas, not by the ASBR itself.

Exam trap

350-401 often tests the ABR vs. ASBR responsibility split for Type 3, 4, and 5 LSAs — the trap is assuming the ASBR generates Type 4 (it does not; the ABR does) or that Type 3 comes from the ASBR (it comes from the ABR).

15
MCQmedium

An engineer configures a VXLAN tunnel between two Nexus switches acting as VTEPs. The underlay is a routed Layer 3 network using OSPF, and the loopback interfaces of the VTEPs are reachable. However, hosts in the same VXLAN VNI on different VTEPs cannot communicate. Which action should the engineer take to resolve the issue?

A.Configure static VXLAN tunnels between the VTEPs using the destination-udp-port command.
B.Enable OSPF on the loopback interfaces and advertise them into the underlay.
C.Enable PIM sparse mode on the underlay and configure a rendezvous point for multicast replication.
D.Configure the NVE interface with the correct source-interface and ensure the VNI is mapped to the VLAN.
AnswerD

The NVE interface must be configured with a source-interface (typically a loopback) and the VNI must be associated with the correct VLAN. Without this mapping, VXLAN encapsulation or decapsulation fails, preventing communication between hosts on different VTEPs. This is a common misconfiguration that directly causes the described symptom, making this the correct action to resolve the issue.

Why this answer

The NVE interface on a Cisco Nexus VTEP must have a source-interface configured, usually a loopback, and each VNI must be mapped to a VLAN. Without these, VXLAN encapsulation and decapsulation fail, so hosts in the same VNI on different VTEPs cannot communicate. The underlay is already operational, so the fix is to correct the NVE and VNI configuration.

Exam trap

The trap here is assuming the underlay routing is at fault when the loopbacks are already reachable, leading to unnecessary OSPF or PIM changes instead of checking the NVE interface and VNI mapping.

16
MCQmedium

interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip ospf network non-broadcast ip ospf priority 1 ! router ospf 1 network 192.168.1.0 0.0.0.255 area 0 neighbor 192.168.1.2 What is the effect of this configuration?

A.OSPF will form an adjacency with 192.168.1.2 and elect a DR/BDR based on priority.
B.OSPF will form an adjacency with 192.168.1.2 without DR/BDR election.
C.OSPF will automatically discover neighbors via multicast and form adjacencies.
D.OSPF will use a 30-second hello interval and suppress DR/BDR election.
AnswerA

On a non-broadcast (NBMA) OSPF network type, the link is treated as a multi-access segment, so after the neighbor 192.168.1.2 is manually configured, OSPF forms a full adjacency and performs a DR/BDR election. The router with the highest interface priority (then highest router ID) becomes DR, and election occurs only among routers with priority greater than 0. This is correct because non-broadcast network type requires unicast neighbor configuration and still has multi-access semantics.

Why this answer

The configuration sets the OSPF network type to non-broadcast on the interface, which requires manual neighbor statements (neighbor 192.168.1.2) to form adjacencies. In non-broadcast mode, OSPF uses unicast instead of multicast, but it still performs DR/BDR election because the network type is considered multi-access (like Frame Relay). The ip ospf priority 1 command influences the election, so the correct answer is that OSPF will form an adjacency with 192.168.1.2 and elect a DR/BDR based on priority.

Exam trap

Cisco often tests the misconception that 'non-broadcast' means 'no DR/BDR election,' but the trap here is that non-broadcast is still a multi-access network type and requires DR/BDR election, unlike point-to-point or point-to-multipoint network types.

How to eliminate wrong answers

Option B is wrong because non-broadcast OSPF networks are multi-access and do require DR/BDR election; only point-to-point or point-to-multipoint network types suppress the election. Option C is wrong because non-broadcast networks do not use multicast (224.0.0.5/224.0.0.6) for neighbor discovery; they rely on manually configured neighbor statements. Option D is wrong because the hello interval for non-broadcast networks is 30 seconds by default, but DR/BDR election is not suppressed; it is still performed, and the 30-second hello is not the primary effect described in the question.

17
Drag & Dropmedium

Drag and drop the steps to configure OSPF on a Cisco router in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

OSPF configuration starts with enabling the OSPF process, then defining networks and areas.

18
MCQhard

A network engineer is troubleshooting a Cisco Nexus 9000 switch configured with VXLAN EVPN. The engineer notices that the switch is not learning remote MAC addresses from the EVPN control plane. The underlay is OSPF, and BGP EVPN peering is established with the spine switches. Which command should the engineer use to verify that the switch is receiving EVPN Type-2 routes?

A.show ip route vrf all
B.show l2route evpn mac all
C.show nve peers
D.show bgp l2vpn evpn
AnswerD

The command 'show bgp l2vpn evpn' displays the BGP EVPN table, including Type-2 routes (MAC/IP advertisement routes). If the switch is not receiving Type-2 routes, this command will show an empty table or missing entries for the expected MAC addresses. It is the primary command to verify EVPN route reception and is essential for troubleshooting control-plane learning.

Why this answer

To verify that the switch is receiving EVPN Type-2 routes, the engineer should use 'show bgp l2vpn evpn'. This command displays the BGP EVPN table, where Type-2 routes appear as '[2]:[MAC/IP]' entries. If these routes are missing, the switch will not learn remote MAC addresses via EVPN.

Checking the BGP EVPN table is the first step in troubleshooting control-plane learning issues.

Exam trap

The trap here is confusing data-plane verification commands like 'show nve peers' with control-plane verification commands like 'show bgp l2vpn evpn', or looking at the L2 route table instead of the BGP table.

19
Multi-Selectmedium

Which three statements about OSPF route summarization are true? (Choose three.)

Select 3 answers
A.Inter-area route summarization is configured on ABRs using the "area range" command.
B.External route summarization is configured on ASBRs using the "summary-address" command.
C.Route summarization reduces the size of the LSDB and improves network convergence.
D.Route summarization can be configured on any OSPF router to reduce Type 1 LSAs.
E.Summarization in OSPF can be applied to Type 1 and Type 2 LSAs to reduce flooding.
AnswersA, B, C

Inter-area summarisation is configured on area border routers with the **area** *range* command, which consolidates Type 3 summary LSAs for networks within a specified area. This satisfies the stem's requirement for a true OSPF summarisation statement, since ABRs generate inter-area prefixes and can suppress individual component routes.

Why this answer

Option A is correct because inter-area summarization is performed on Area Border Routers (ABRs) with the "area <area-id> range <ip> <mask>" command, which aggregates Type 3 summary LSAs advertised into other areas. Option B is correct because external route summarization is configured on Autonomous System Boundary Routers (ASBRs) using the "summary-address <ip> <mask>" command, which aggregates Type 5 (or Type 7) external LSAs. Option C is correct because summarization shrinks the link-state database and routing tables by replacing many specific prefixes with one aggregate, which reduces SPF computation overhead and speeds convergence.

Option D is wrong because Type 1 router LSAs describe a router's own links and cannot be summarized, and summarization is not performed on arbitrary routers. Option E is wrong because OSPF summarization applies to Type 3 and Type 5/7 LSAs, not to Type 1 and Type 2 LSAs, which must remain intact within an area for topology accuracy.

Exam trap

The trap is assuming OSPF can summarize any LSA type; candidates forget that Type 1 and Type 2 LSAs are intra-area and cannot be summarized, and that summarization is only performed on ABRs and ASBRs.

20
MCQmedium

Refer to the exhibit. Which OSPF route type is the default route?

A.External type 2 (E2)
B.Inter-area (IA)
C.NSSA external type 2 (N2)
D.External type 1 (E1)
AnswerA

When OSPF redistributes a default route, the default metric-type is 2 (E2), which means the route's metric remains fixed at the ASBR-advertised value (20) and does not include the internal cost of reaching that ASBR. This is why a default route injected via redistribute or default-information originate is normally seen as an E2 route unless metric-type 1 is explicitly selected.

Why this answer

The exhibit shows a default route (0.0.0.0/0) being redistributed into OSPF from another routing protocol or static route. By default, OSPF redistributes routes as External Type 2 (E2), meaning the metric does not include the internal cost to the ASBR. The route is not an NSSA type because the area is not configured as a not-so-stubby area, and it is not an inter-area route because it originates outside the OSPF domain.

Exam trap

Cisco often tests the default OSPF metric type for redistributed routes (E2) and the fact that a default route can be an external route, not just an inter-area or NSSA type, leading candidates to confuse it with N2 or IA when the area type is not explicitly stated.

How to eliminate wrong answers

Option B is wrong because Inter-area (IA) routes are prefixes learned from another OSPF area, not redistributed external routes; a default route redistributed into OSPF is external, not inter-area. Option C is wrong because NSSA external type 2 (N2) routes only appear in not-so-stubby areas (NSSA) and are translated to type 5 LSAs by the ABR; the exhibit does not indicate an NSSA configuration. Option D is wrong because External type 1 (E1) routes include the internal cost to the ASBR in their metric, but OSPF defaults to E2 for redistributed routes unless explicitly configured with the 'metric-type 1' keyword.

21
MCQmedium

Examine the following configuration snippet: interface GigabitEthernet0/1 ip address 192.168.1.1 255.255.255.0 ip ospf hello-interval 20 ip ospf dead-interval 80 What is the effect of this configuration?

A.The OSPF hello interval is changed to 20 seconds, and the dead interval is changed to 80 seconds, maintaining the default 4:1 ratio.
B.The OSPF hello interval is changed to 20 seconds, but the dead interval remains at the default of 40 seconds.
C.The OSPF hello interval is changed to 20 seconds, and the dead interval is automatically set to 60 seconds.
D.This configuration will cause OSPF adjacency failure because the dead interval must be exactly 4 times the hello interval.
AnswerA

The OSPF configuration in the scenario explicitly sets the hello interval to 20 seconds and the dead interval to 80 seconds, which preserves OSPF's default dead-to-hello ratio of 4:1 (80/20 = 4). Because both neighbors are configured with these same values, the OSPF dead interval timer remains consistent, and adjacency formation occurs normally. This matches the requirement that neighbors must agree on timer values, not that a strict 4:1 ratio is mandated.

Why this answer

The configuration explicitly sets the OSPF hello interval to 20 seconds and the dead interval to 80 seconds, which maintains the default 4:1 ratio (dead = hello × 4). OSPF allows manual configuration of these timers, and as long as both sides of the adjacency match, the ratio can be any value; the 4:1 default is not enforced by the protocol.

Exam trap

Cisco often tests the misconception that the dead interval must always be exactly 4 times the hello interval, but the actual requirement is that the timers must match between neighbors, not that a specific ratio must be maintained.

How to eliminate wrong answers

Option B is wrong because the 'ip ospf dead-interval 80' command explicitly overrides the default dead interval (40 seconds for a 10-second hello), so it does not remain at 40. Option C is wrong because OSPF does not automatically set the dead interval to 60 seconds when the hello interval is changed; the dead interval must be explicitly configured or it stays at the default (which would be 80 seconds if the hello were 20, but here it is explicitly set to 80). Option D is wrong because OSPF does not require the dead interval to be exactly 4 times the hello interval; the only requirement is that the timers match on both OSPF neighbors for adjacency to form, and any ratio is acceptable as long as it is consistent.

22
Matchingmedium

Drag and drop each OSPF area type on the left to its matching characteristic on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Must connect all other areas; area 0

Blocks Type 5 LSAs; allows Type 3 summary LSAs

Blocks Type 5 and Type 3 LSAs; uses default route only

Allows Type 7 LSAs for external routes; blocks Type 5 LSAs

Blocks Type 5 and Type 3; allows Type 7 for external routes

Why these pairings

Backbone area (0) connects all other areas; Stub area blocks Type 5 LSAs but allows Type 3; Totally stubby area blocks both Type 5 and Type 3 (default route only); NSSA allows Type 7 LSAs for external routes but blocks Type 5; NSSA totally stubby blocks Type 5 and Type 3 but allows Type 7.

23
MCQmedium

A network engineer is implementing VXLAN on a Cisco Nexus 9000 series switch running NX-OS. The underlay network uses OSPF and the loopback0 interface of each VTEP is advertised. The engineer wants to verify that the VXLAN tunnel endpoints can communicate. Which command should be used to check the VXLAN tunnel status?

A.show interface tunnel
B.show vxlan interface
C.show nve peers
D.show ip ospf neighbor
AnswerC

The 'show nve peers' command displays the state of VXLAN tunnel endpoints (VTEPs) and their peer relationships. It shows the IP address of each peer, the VNI, and the state (Up/Down). This directly verifies if VTEPs can communicate over the underlay, which is essential for VXLAN operation.

Why this answer

The 'show nve peers' command is the correct way to verify VXLAN tunnel endpoint communication. It provides details about peer VTEPs, including their IP addresses and state. This command is essential for troubleshooting VXLAN overlay connectivity, as it directly shows whether tunnels are established and operational.

Exam trap

The trap here is assuming that OSPF neighbor adjacency guarantees VXLAN tunnel establishment, but underlay routing and overlay tunnels are separate and must be verified independently.

24
MCQmedium

Router R3 has the following OSPF configuration: router ospf 1 router-id 3.3.3.3 network 10.0.0.0 0.255.255.255 area 0 default-information originate always metric 20 metric-type 2 What is the effect of the 'default-information originate always' command?

A.It redistributes all connected routes into OSPF.
B.It injects a default route into OSPF only if a default route is present in the routing table.
C.It injects a default route into OSPF unconditionally, with metric 20 and type E2.
D.It sets the OSPF router ID to 3.3.3.3 and enables default route filtering.
AnswerC

This is correct because the command uses the 'always' keyword to unconditionally originate a default route into the OSPF domain, and the explicit 'metric 20' and 'metric-type 2' keywords dictate the cost and external type of that route. The resulting LSA is an external type 2 (E2) route with a metric of 20, which will be advertised to all OSPF neighbors. No default route needs to exist in the local routing table for this advertisement to occur.

Why this answer

The 'default-information originate always' command injects a default route (0.0.0.0/0) into the OSPF link-state database unconditionally, regardless of whether the router itself has a default route in its routing table. The 'always' keyword overrides the default behavior, which requires a pre-existing default route. The metric 20 and metric-type 2 (E2) are explicitly set in the command, making the injected route an external type 2 route with a seed metric of 20.

Exam trap

Cisco often tests the distinction between the default behavior (inject only if a default route exists) and the 'always' keyword (unconditional injection), leading candidates to mistakenly think 'always' is required for any default route injection or that it modifies the metric behavior.

How to eliminate wrong answers

Option A is wrong because 'default-information originate' injects a default route, not all connected routes; redistributing connected routes requires the 'redistribute connected' command under OSPF. Option B is wrong because the 'always' keyword makes the injection unconditional; without 'always', the command would require a default route in the routing table, but with 'always' it does not. Option D is wrong because the 'router-id 3.3.3.3' is a separate configuration line that sets the OSPF router ID, and the 'default-information originate' command does not enable any filtering; it injects a default route.

25
MCQhard

A network engineer runs the following command on Router R5: R5# show ip route vrf CUSTOMER-A Routing Table: CUSTOMER-A Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2 i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route Gateway of last resort is 10.1.1.1 to network 0.0.0.0 10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks C 10.1.1.0/24 is directly connected, GigabitEthernet0/0 B 10.2.2.0/24 [20/0] via 10.1.1.1, 00:10:20 Based on this output, what can be concluded?

A.The VRF has no routes and is not functional.
B.The route 10.2.2.0/24 is learned via OSPF.
C.The VRF has a default route pointing to 10.1.1.1.
D.The BGP route is sourced from an internal BGP peer.
AnswerC

The VRF routing table shows a 'Gateway of last resort is 10.1.1.1' line, which indicates a default route of 0.0.0.0/0 is installed with next hop 10.1.1.1. This S* route means any destination not matching a more specific prefix will be sent to 10.1.1.1. Thus, the correct statement is that the VRF has a default route pointing to 10.1.1.1.

Why this answer

The output shows a VRF routing table with a gateway of last resort set to 10.1.1.1 for network 0.0.0.0, which is a default route. This indicates that the VRF has a default route pointing to 10.1.1.1, making option C correct. The presence of a connected route and a BGP-learned route further confirms the VRF is functional.

Exam trap

Cisco often tests the distinction between eBGP and iBGP by using administrative distance values; the trap here is that candidates may assume any BGP route is from an internal peer without checking the AD value, which for eBGP is 20 and for iBGP is 200.

How to eliminate wrong answers

Option A is wrong because the VRF has both a connected route (10.1.1.0/24) and a BGP-learned route (10.2.2.0/24), so it is functional. Option B is wrong because the route 10.2.2.0/24 is marked with 'B' in the routing table, which indicates it is learned via BGP, not OSPF. Option D is wrong because the BGP route shows an administrative distance of 20 and a metric of 0, which are typical for eBGP (external BGP) routes, not iBGP (internal BGP) routes; iBGP routes typically have an administrative distance of 200.

26
MCQmedium

A network engineer must protect the OSPF adjacency between two Cisco routers from spoofed hello packets injected by a rogue device on the same broadcast segment. The engineer wants to use a cryptographic authentication method that is natively supported by OSPFv2 and does not rely on plain-text key exchange. Which configuration should be applied to the interfaces?

A.ip ospf authentication-key <key>
B.ip ospf authentication key-chain <name>
C.ip ospf authentication message-digest and ip ospf message-digest-key 1 md5 <key>
D.ip ospf authentication null
AnswerC

OSPFv2 message-digest authentication uses MD5 to hash the key and packet contents, so the key is never sent in cleartext. Configuring ip ospf authentication message-digest enables cryptographic authentication on the interface, and ip ospf message-digest-key 1 md5 supplies the key material. Neighbors must share the same key ID and key string for the adjacency to form, which satisfies the requirement to protect against spoofed hellos.

Why this answer

OSPFv2 supports two authentication types: simple password and message-digest (MD5). Only message-digest provides cryptographic protection, because it hashes the packet with a shared key rather than transmitting the key. Enabling ip ospf authentication message-digest on the interface plus defining ip ospf message-digest-key with an MD5 key ensures hellos are authenticated and spoofed packets from a rogue host are rejected before the adjacency can be affected.

Exam trap

The trap here is assuming that any OSPF authentication command provides cryptographic protection, when simple password authentication transmits the key in cleartext and offers no real defense.

27
MCQhard

A network engineer runs the following command on Router R7: R7# show ip ospf virtual-links Virtual Link OSPF_VL0 to router 2.2.2.2 is up Run as demand circuit DoNotAge LSA allowed. Transit area 1, via interface GigabitEthernet0/1, Cost of using 10 Transmit Delay is 1 sec, State POINT_TO_POINT, Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5 Hello due in 00:00:07 Adjacency State FULL Based on this output, what can be concluded?

A.The virtual link is used to connect area 0 to a non-backbone area.
B.Router 2.2.2.2 is the other endpoint of the virtual link.
C.The virtual link is down.
D.The virtual link uses area 0 as the transit area.
AnswerB

The virtual link is identified by the router ID of its remote endpoint, and in the displayed output 'ospf 2a54f7' (likely from 'show ip ospf virtual-links'), the destination is 'router 2.2.2.2'. This means 2.2.2.2 is the neighboring ABR that, together with the local router, forms the virtual adjacency across the transit area. Therefore, stating that 2.2.2.2 is the other endpoint is accurate.

Why this answer

The output shows that the virtual link OSPF_VL0 to router 2.2.2.2 is up and the adjacency state is FULL. This confirms that router 2.2.2.2 is the remote endpoint of the virtual link, as the command displays the router ID of the neighbor at the other end of the virtual link.

Exam trap

Cisco often tests the misconception that the router ID shown in the virtual link output is the local router's ID, when in fact it is the remote endpoint's router ID, as confirmed by the 'to router' syntax in the command output.

How to eliminate wrong answers

Option A is wrong because the virtual link is used to connect a non-backbone area to area 0, not to connect area 0 to a non-backbone area; the virtual link extends area 0 into a transit area. Option C is wrong because the output explicitly states 'Virtual Link ... is up' and 'Adjacency State FULL', indicating the link is operational. Option D is wrong because the transit area is area 1, not area 0; the output shows 'Transit area 1'.

28
MCQmedium

Router R5 has the following OSPF configuration: router ospf 1 router-id 5.5.5.5 network 10.0.0.0 0.255.255.255 area 0 area 0 authentication message-digest ! interface GigabitEthernet0/0 ip address 10.1.1.5 255.255.255.0 ip ospf message-digest-key 1 md5 cisco123 What is missing from this OSPF authentication configuration?

A.The configuration is complete and correct.
B.The interface needs the 'ip ospf authentication message-digest' command.
C.The 'area 0 authentication' command should be 'area 0 authentication md5'.
D.The 'network' command should include the area authentication keyword.
AnswerB

Area 0 already enables MD5 authentication, but the interface itself lacks the enabling command, so no digest is sent. Adding 'ip ospf authentication message-digest' on GigabitEthernet0/0 activates authentication, allowing the configured key 1 to be used.

Why this answer

OSPF authentication configuration requires two components: an area-level authentication type (configured via `area 0 authentication message-digest`) and an interface-level authentication mode (configured via `ip ospf authentication message-digest`). The interface command tells the OSPF process to actually use the key defined with `ip ospf message-digest-key`. Without it, the interface defaults to no authentication, even though the area is configured for authentication.

Exam trap

The trap here is that candidates assume configuring the area authentication and the key is sufficient, overlooking the mandatory interface-level `ip ospf authentication message-digest` command that activates authentication on the specific interface.

How to eliminate wrong answers

Option A is wrong because the configuration is incomplete; the interface lacks the `ip ospf authentication message-digest` command, so OSPF packets on GigabitEthernet0/0 will not be authenticated. Option C is wrong because `area 0 authentication md5` is not a valid Cisco IOS command; the correct syntax is `area 0 authentication message-digest`. Option D is wrong because the `network` command does not support an area authentication keyword; area authentication is configured separately under the OSPF process or on the interface.

29
MCQmedium

interface GigabitEthernet0/1 ip address 10.1.1.1 255.255.255.0 mpls ip mpls label protocol tdp ! router ospf 1 network 10.1.1.0 0.0.0.255 area 0 ! router ldp interface GigabitEthernet0/1 ! Which statement about this configuration is true?

A.The interface will use TDP for label distribution, ignoring the LDP configuration under router ldp.
B.The router will use LDP because the global configuration overrides the interface command.
C.Both TDP and LDP will be used simultaneously on the interface.
D.The configuration will fail because TDP is not supported on this platform.
AnswerA

The interface-level command 'mpls label protocol tdp' takes precedence over any global or routing-protocol-level LDP configuration. On Cisco IOS, interface-specific configuration is applied after global settings and thus overrides them, so the interface uses TDP exclusively for label distribution. Even though 'router ldp' enables LDP globally, the interface's explicit TDP directive forces TDP on that interface. This is the standard precedence behavior for MPLS label protocol selection.

Why this answer

The interface-level command `mpls label protocol tdp` explicitly sets TDP (Tag Distribution Protocol) for that interface. When both an interface-specific `mpls label protocol` command and a global `router ldp` configuration exist, the interface-level command takes precedence. Therefore, GigabitEthernet0/1 will use TDP for label distribution, and the LDP configuration under `router ldp` is effectively ignored for that interface.

Exam trap

The trap here is that candidates often assume the global `router ldp` configuration overrides an interface-level `mpls label protocol tdp` command, but Cisco explicitly tests that the interface-level command takes precedence.

How to eliminate wrong answers

Option B is wrong because the interface-level command overrides the global LDP configuration, not the other way around. Option C is wrong because TDP and LDP are mutually exclusive on a single interface; a router cannot run both simultaneously on the same interface. Option D is wrong because TDP is supported on Cisco IOS platforms that support MPLS, and the configuration will not fail due to TDP being unsupported.

30
MCQeasy

Refer to the exhibit. An administrator needs to ensure that traffic to 192.168.1.0/24 is forwarded via a different path than traffic to 192.168.2.0/24, even though both routes are learned via OSPF with the same metric. Which action should the administrator take?

A.Configure policy-based routing to match 192.168.1.0/24 and set the next hop to 10.0.0.1.
B.Add a static route for 192.168.1.0/24 with a lower administrative distance than OSPF.
C.Use the 'distance ospf' command to change the OSPF administrative distance for all routes.
D.Adjust the OSPF cost on the interface to 10.0.0.2.
AnswerB

A static route to 192.168.1.0/24 with administrative distance 1 creates a more trustworthy entry than OSPF's default AD of 110, so the router prefers the static route for that exact prefix. This is the precise, surgical fix: it overrides OSPF only for this subnet while leaving all other OSPF-learned routes untouched, and it does not depend on the metrics of the two equal-cost OSPF paths.

Why this answer

Adding a static route for 192.168.1.0/24 with a lower administrative distance (e.g., 1) than OSPF (default 110) forces the router to prefer the static route over the OSPF-learned route, even though the OSPF metric is the same. This allows traffic to 192.168.1.0/24 to use a different next-hop (e.g., 10.0.0.1) while traffic to 192.168.2.0/24 continues using the OSPF-learned path via 10.0.0.2, achieving the desired path differentiation without altering OSPF metrics or using complex PBR.

Exam trap

Cisco often tests the misconception that policy-based routing (PBR) is the only way to force traffic to a different next-hop, when in fact a simple static route with a lower administrative distance can achieve the same result more efficiently and is a common technique for path selection without altering routing protocol metrics.

How to eliminate wrong answers

Option A is wrong because policy-based routing (PBR) matches traffic based on source/destination and sets the next hop, but it does not change the routing table; it overrides the forwarding decision for matched packets, which is unnecessary complexity when a simple static route can achieve the same result with less overhead. Option C is wrong because using the 'distance ospf' command changes the administrative distance for all OSPF routes globally, affecting both 192.168.1.0/24 and 192.168.2.0/24 equally, so it cannot differentiate the path for only one prefix. Option D is wrong because adjusting the OSPF cost on the interface to 10.0.0.2 would change the metric for all routes learned via that interface, potentially altering the path for both prefixes and not specifically isolating 192.168.1.0/24 to a different next-hop.

31
MCQhard

A network administrator is configuring IPsec VPN on a Cisco IOS router. The requirement is that the tunnel must support multicast traffic for OSPF neighbor adjacency across the VPN. Which IPsec configuration element is required to meet this requirement?

A.Use a dynamic VTI with IKEv1.
B.Use transport mode instead of tunnel mode.
C.Configure GRE over IPsec.
D.Enable IKEv2 with MOBIKE.
AnswerC

GRE tunnels can carry multicast traffic, and when combined with IPsec, the GRE packets are encrypted. This allows OSPF to form neighbor adjacencies over the tunnel because OSPF uses multicast (224.0.0.5/224.0.0.6). Native IPsec cannot carry multicast, so GRE over IPsec is the standard solution for dynamic routing protocols requiring multicast over a VPN.

Why this answer

IPsec security associations are inherently unicast and cannot carry multicast or broadcast traffic. To support OSPF, which relies on multicast hellos, the design must encapsulate multicast inside a GRE tunnel and then protect that GRE tunnel with IPsec. This is commonly called GRE over IPsec or IPsec profile applied to a GRE tunnel interface.

Exam trap

The trap here is believing that IPsec itself can carry multicast, when in fact IPsec SAs are point-to-point unicast and require GRE encapsulation for multicast support.

32
Multi-Selectmedium

A network engineer is hardening a Cisco IOS XE router against control plane attacks. The router runs OSPF, BGP, and SSH management. The engineer wants to apply Control Plane Policing (CoPP) to rate-limit nonessential traffic while ensuring routing protocols are not disrupted. Which two actions should the engineer take? (Choose two.)

Select 2 answers
A.Configure a single class map that matches all IP traffic and police it to a low rate to simplify the policy.
B.Use a route map to classify traffic and attach it to the control plane with the service-policy command.
C.Create class maps that match routing protocol traffic, such as OSPF and BGP, and assign them a higher policing rate than nonessential traffic.
D.Apply the CoPP policy map under control-plane configuration mode using the service-policy command.
E.Apply the CoPP policy map inbound on all WAN interfaces to filter traffic before it reaches the route processor.
AnswersC, D

Routing protocols are essential for network stability, so they should be matched in dedicated class maps and given sufficient policing rates to avoid dropping legitimate updates. This allows CoPP to protect the CPU while preventing disruption to OSPF and BGP adjacencies, which is a key requirement in the scenario.

Why this answer

Effective CoPP requires class maps that separate essential traffic, such as OSPF and BGP, from nonessential traffic, with appropriate policing rates for each. The policy map is then applied under control-plane configuration mode. This structure protects the route processor without disrupting routing protocols or management access.

Exam trap

The trap here is applying CoPP to data interfaces or using a single blanket policer, which would either miss CPU-bound traffic or throttle essential routing and management protocols.

33
MCQmedium

A network engineer is deploying Control Plane Policing on a Cisco IOS XE router that carries eBGP, OSPF, SSH management, and SNMP traffic. The engineer wants to ensure that BGP and OSPF routing updates are never dropped while still rate-limiting SSH and SNMP. Which CoPP configuration approach best meets this requirement?

A.Apply a single class-map matching all control-plane traffic and set a single police rate that is high enough for routing protocols.
B.Create separate class-maps for BGP, OSPF, SSH, and SNMP, then apply a policy-map where routing classes use police with a high conform rate and management classes use a lower police rate.
C.Use MQC with a single class-default and configure a priority queue for BGP and OSPF packets.
D.Configure an ACL that denies SSH and SNMP to the control plane and apply it inbound on all interfaces.
AnswerB

Separate class-maps allow granular classification, and the policy-map can apply different police actions per class. Routing classes can be policed generously (or with conform-action transmit and exceed-action transmit for critical control traffic), while SSH and SNMP are rate-limited. This is the standard CoPP design pattern for differentiated control-plane protection.

Why this answer

CoPP is designed to classify control-plane traffic into distinct classes and apply independent policers. Separating routing protocols from management protocols allows the engineer to protect BGP and OSPF adjacencies while still enforcing limits on SSH and SNMP. A single class-map or class-default cannot provide this granularity, and an ACL would block rather than rate-limit management traffic.

Exam trap

The trap here is assuming that a single high-rate policer can protect all control-plane traffic without distinguishing routing protocols from management protocols.

34
MCQhard

A network engineer issues the following command on Router R2: R2# show ip ospf interface GigabitEthernet0/0 GigabitEthernet0/0 is up, line protocol is up Internet Address 192.168.1.2/24, Area 0 Process ID 1, Router ID 2.2.2.2, Network Type BROADCAST, Cost: 10 Transmit Delay is 1 sec, State DR, Priority 1 Designated Router (ID) 2.2.2.2, Interface address 192.168.1.2 Backup Designated router (ID) 1.1.1.1, Interface address 192.168.1.1 Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5 Hello due in 00:00:03 Index 1/1/1, flood queue length 0 Next 0x0(0)/0x0(0)/0x0(0) Last flood scan length is 1, maximum is 1 Last flood scan time is 0 msec, maximum is 0 msec Neighbor Count is 2, Adjacent neighbor count is 2 Adjacent with neighbor 1.1.1.1 (Backup Designated Router) Adjacent with neighbor 3.3.3.3 Based on this output, what can be concluded?

A.R2 has a full OSPF adjacency with all neighbors on this segment.
B.R2 is the Backup Designated Router on this segment.
C.The OSPF cost to reach the network 192.168.1.0/24 is 20.
D.R2 will send hello packets every 40 seconds.
AnswerA

The 'adjacent neighbor count' of 2 is equal to the total neighbor count, which in OSPF terminology means every discovered neighbor has reached the full state after completing database exchange. On a multi-access broadcast segment, only the DR and BDR form full adjacencies with all routers, so this equality confirms that R2 has fully synchronized its LSDB with both neighbors and no neighbor is stuck in two-way or exstart state.

Why this answer

The output shows that R2 is the Designated Router (DR) on this broadcast segment, with two neighbors listed: 1.1.1.1 (BDR) and 3.3.3.3. The 'Adjacent neighbor count is 2' and both neighbors are listed as 'Adjacent with neighbor', confirming that R2 has formed full OSPF adjacencies with all neighbors on this segment. In OSPF broadcast networks, only the DR and BDR form full adjacencies with all routers, while non-DR/BDR routers only form full adjacencies with the DR and BDR.

Exam trap

Cisco often tests the distinction between 'neighbor count' and 'adjacent neighbor count' — candidates may incorrectly assume that all neighbors are fully adjacent, but in broadcast networks, only the DR and BDR have full adjacencies with all routers, while other routers only have full adjacency with the DR and BDR.

How to eliminate wrong answers

Option B is wrong because R2 is the Designated Router (State DR, Priority 1), not the Backup Designated Router; the BDR is 1.1.1.1. Option C is wrong because the cost shown (Cost: 10) is the OSPF cost of the GigabitEthernet0/0 interface on R2, not the cost to reach the network 192.168.1.0/24; the cost to reach that network would be the sum of outgoing interface costs along the path. Option D is wrong because the Hello timer is configured as 10 seconds (Hello 10), not 40 seconds; the Dead timer is 40 seconds.

35
MCQhard

A network engineer is configuring OSPF on a Cisco router. The router is connected to a broadcast network with multiple OSPF neighbors. The engineer wants to ensure that this router does not become the Designated Router (DR) or Backup Designated Router (BDR) on this network. Which configuration achieves this goal?

A.Set the OSPF priority to 0 on the interface.
B.Set the OSPF network type to point-to-point.
C.Configure the interface as passive.
D.Configure the router as a stub router.
AnswerA

Setting the OSPF priority to 0 on an interface prevents that router from being elected as DR or BDR. The priority value is used in the DR election process; routers with priority 0 are ineligible. This is the correct method to ensure the router does not become DR or BDR while still participating in OSPF on that network.

Why this answer

The OSPF priority is an 8-bit field in the Hello packet used in DR/BDR election. A router with priority 0 is never elected as DR or BDR. Setting the interface priority to 0 achieves the goal while allowing the router to remain a DROTHER and fully participate in OSPF.

Other methods like changing network type or making the interface passive have side effects that are not desired.

Exam trap

The trap here is confusing DR election manipulation with other OSPF features like stub routing or passive interfaces, which have different purposes.

36
MCQmedium

A network engineer is configuring a Cisco CSR 1000v router to support a virtual routing and forwarding (VRF) instance for a customer. The engineer wants to enable OSPFv2 within the VRF and ensure that OSPF routes are installed in the VRF's routing table. Which command is required to start the OSPF process for the VRF?

A.router ospf 1 vrf CUSTOMER
B.ip router ospf 1 vrf CUSTOMER
C.router ospf 1 address-family ipv4 vrf CUSTOMER
D.router ospf 1 vrf CUSTOMER
AnswerA

The command 'router ospf 1 vrf CUSTOMER' starts an OSPF process with process ID 1 and associates it with the VRF named CUSTOMER. This is the correct syntax to enable OSPF within a specific VRF on Cisco IOS-XE. Once configured, OSPF will run in the context of that VRF, and routes will be installed in the VRF's routing table.

Why this answer

The correct command to enable OSPFv2 in a VRF on Cisco IOS-XE is 'router ospf <process-id> vrf <vrf-name>'. This associates the OSPF process with the specified VRF, allowing it to run in that VRF's routing context. The other options either use incorrect syntax or are appropriate for different platforms or protocols.

Exam trap

The trap here is mixing up IOS-XE and NX-OS syntax, or incorrectly placing the VRF parameter on a separate line instead of on the router ospf command itself.

37
MCQmedium

A network engineer runs the following command on Router R3: R3# show ip route ospf Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2 E1 - OSPF external type 1, E2 - OSPF external type 2 i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2 ia - IS-IS inter area, * - candidate default, U - per-user static route o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP a - application route + - replicated route, % - next hop override Gateway of last resort is not set 10.0.0.0/8 is variably subnetted, 5 subnets, 3 masks O IA 10.1.1.0/24 [110/20] via 192.168.1.1, 00:12:34, GigabitEthernet0/0 O 10.2.2.0/24 [110/10] via 192.168.1.2, 00:15:22, GigabitEthernet0/0 O E2 10.3.3.0/24 [110/20] via 192.168.1.3, 00:08:11, GigabitEthernet0/0 Based on this output, what can be concluded?

A.The route to 10.3.3.0/24 is an external route redistributed into OSPF.
B.The route to 10.1.1.0/24 is in the same OSPF area as R3.
C.The metric for 10.3.3.0/24 includes the internal cost to the ASBR.
D.R3 is an ASBR.
AnswerA

The route to 10.3.3.0/24 is an external route redistributed into OSPF. In the routing table, the code 'O E2' explicitly marks this as an OSPF external route of type 2. Type 2 (E2) routes are routes that originated outside the OSPF domain and were redistributed into OSPF, typically from another routing protocol such as EIGRP or BGP. The external cost is carried as configured on the ASBR, and in this case the metric of 20 is the default external cost for redistributed routes, confirming the redistributed origin.

Why this answer

The route to 10.3.3.0/24 is marked as 'O E2' in the output, which stands for OSPF external type 2. This indicates that the route was redistributed into OSPF from another routing protocol or a different OSPF process, making it an external route. The 'E2' designation confirms it is an external route with a fixed metric that does not include the internal cost to the ASBR.

Exam trap

Cisco often tests the difference between OSPF external type 1 (E1) and type 2 (E2) routes, specifically that E2 routes do not include the internal cost to the ASBR, which is a common misconception that leads candidates to incorrectly select option C.

How to eliminate wrong answers

Option B is wrong because the route to 10.1.1.0/24 is marked as 'O IA' (OSPF inter-area), which means it originates from a different OSPF area than R3, not the same area. Option C is wrong because for an OSPF external type 2 (E2) route, the metric shown (20) is the external metric only and does not include the internal cost to the ASBR; that behavior is specific to external type 1 (E1) routes. Option D is wrong because R3 is simply receiving these OSPF routes; there is no indication in the output that R3 is redistributing routes into OSPF, which would be required for it to be an ASBR.

38
Multi-Selecthard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The router runs OSPF, BGP, SSH management, and NTP. The engineer wants to ensure that OSPF hello packets are always prioritized and that SSH traffic from the management subnet is rate-limited. Which two statements about the CoPP configuration are true? (Choose two.)

Select 2 answers
A.CoPP is applied to individual data plane interfaces using the 'service-policy input' command on each physical interface.
B.CoPP uses a modular QoS CLI policy map applied globally with the 'service-policy' command under control-plane configuration mode.
C.The default CoPP policy that ships with Cisco IOS XE already rate-limits SSH and OSPF traffic without any custom configuration.
D.CoPP policies can differentiate OSPF and SSH traffic by using ACLs referenced in class maps to match specific protocols and source addresses.
E.CoPP can only police traffic; it cannot mark or prioritize specific control plane protocols such as OSPF.
AnswersB, D

CoPP is implemented using MQC constructs where a class map matches control plane traffic and a policy map defines policing actions. The policy map is then applied under the control-plane configuration mode using the service-policy command, which directs the policy to the route processor's traffic rather than to data plane interfaces.

Why this answer

CoPP uses MQC class maps and policy maps applied under control-plane configuration mode. Class maps reference ACLs to distinguish protocols like OSPF and SSH, allowing differentiated policing and prioritization actions. Applying the policy to physical interfaces or assuming default policies meet custom requirements are common misconceptions.

Exam trap

The trap here is confusing CoPP with interface-level QoS by assuming the service-policy is applied to data plane interfaces rather than the control plane.

39
MCQmedium

A network engineer is configuring VXLAN on a Cisco Nexus 9000 series switch. The underlay network is a routed Layer 3 network using OSPF. The engineer needs to ensure that the VXLAN tunnel endpoint (VTEP) IP addresses are reachable across the underlay. Which statement describes the correct configuration for the VTEP source interface?

A.The VTEP source interface must be a VLAN interface (SVI) on the switch, and the VLAN must be allowed on all trunk links.
B.The VTEP source interface must be a loopback interface with an IP address advertised into the underlay routing protocol.
C.The VTEP source interface must be a subinterface configured with 802.1Q encapsulation.
D.The VTEP source interface must be a physical interface that is directly connected to the underlay network.
AnswerB

Using a loopback interface as the VTEP source ensures high availability because it remains up as long as any path to the underlay exists. Advertising the loopback IP into OSPF makes it reachable by remote VTEPs, enabling VXLAN tunnels to form. This is the recommended design for VXLAN in Cisco Nexus environments.

Why this answer

For VXLAN, the VTEP source interface should be a loopback interface with an IP address advertised into the underlay routing protocol. This ensures that the VTEP IP remains reachable even if a physical link fails, providing redundancy. The underlay network must route the loopback IP so that remote VTEPs can establish VXLAN tunnels.

Exam trap

The trap here is assuming that any interface with an IP address can serve as the VTEP source, but the best practice is to use a loopback for stability and redundancy.

40
MCQhard

A network engineer is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router. The router runs BGP, OSPF, SSH management, and SNMP. After applying a CoPP policy that rate-limits all control-plane traffic to 1000 pps, BGP sessions flap and OSPF adjacencies reset during peak traffic. Which action should the engineer take to resolve the problem while maintaining control-plane protection?

A.Create separate class-maps for BGP, OSPF, SSH, and SNMP, and apply protocol-specific rate limits within the policy-map.
B.Enable Control Plane Protection (CPPr) with the aggregate option to automatically prioritize routing protocols.
C.Increase the global CoPP rate limit to 5000 pps to accommodate all control-plane protocols.
D.Remove the CoPP policy from the control plane and rely on QoS policies on data interfaces instead.
AnswerA

CoPP works by classifying traffic into distinct classes and applying individual policers. Creating separate class-maps for each protocol allows the engineer to set appropriate rates for BGP and OSPF while still policing SSH and SNMP. This targeted approach protects the control plane without starving routing protocols, resolving the flapping while maintaining security.

Why this answer

CoPP uses a modular QoS CLI (MQC) structure with class-maps to identify traffic types and a policy-map to apply policers per class. A single policer for all control-plane traffic causes legitimate routing protocol updates to compete with management and monitoring traffic, leading to drops and session resets. The correct solution is to define separate class-maps for BGP, OSPF, SSH, and SNMP, then assign differentiated rate limits in the policy-map.

This preserves control-plane protection while ensuring routing protocols receive adequate bandwidth.

Exam trap

The trap here is treating CoPP as a single-rate mechanism and either removing it or inflating the global limit instead of using granular per-protocol classification, which is the intended design.

41
MCQmedium

Given this OSPF configuration: router ospf 1 router-id 1.1.1.1 network 192.168.1.0 0.0.0.255 area 0 network 10.0.0.0 0.255.255.255 area 1 default-information originate always What is the effect of the 'default-information originate always' command?

A.OSPF will advertise a default route into all OSPF areas even if no default route is present in the routing table.
B.OSPF will only advertise a default route if a default route is already in the routing table.
C.OSPF will redistribute all connected routes as type 5 LSAs.
D.OSPF will generate a default route only for area 0.
AnswerA

The 'always' keyword in the 'default-information originate' command forces OSPF to generate and advertise a default route (0.0.0.0/0) throughout the entire OSPF domain, irrespective of whether a default route exists in the routing table. This guarantees connectivity to external networks via the advertising router even when it has no default route of its own, preventing blackholing in certain topologies.

Why this answer

The 'default-information originate always' command instructs OSPF to generate and advertise a default route (0.0.0.0/0) into the OSPF domain as a Type 5 External LSA, regardless of whether a default route exists in the router's own routing table. This ensures that all OSPF routers in every area receive the default route, making the advertising router a gateway of last resort.

Exam trap

Cisco often tests the distinction between 'default-information originate' (which requires a default route in the routing table) and 'default-information originate always' (which does not), leading candidates to mistakenly think the 'always' keyword is optional or that the command only affects area 0.

How to eliminate wrong answers

Option B is wrong because the 'always' keyword explicitly overrides the default behavior, which would require a default route in the routing table; without 'always', OSPF only originates the default if one is present. Option C is wrong because the command does not redistribute connected routes; it only generates a single default route, and Type 5 LSAs are used for external routes, not for all connected routes. Option D is wrong because the default route is advertised into the entire OSPF domain (all areas), not restricted to area 0; OSPF floods Type 5 LSAs throughout the autonomous system.

42
MCQmedium

Examine this configuration: interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ipv6 address 2001:db8::1/64 ipv6 ospf 1 area 0 What is the effect of the 'ipv6 ospf 1 area 0' command?

A.It enables OSPFv3 process 1 on this interface and assigns it to area 0.
B.It enables OSPFv2 process 1 on this interface and assigns it to area 0.
C.It enables OSPFv3 on this interface but the process ID must match the router ospf process ID; if not, it will be ignored.
D.It enables OSPFv3 on this interface but area 0 is invalid for IPv6; OSPFv3 uses area 0.0.0.0.
AnswerA

The command 'ipv6 ospf 1 area 0' is the correct IOS interface subcommand to enable OSPFv3, the IPv6-capable version of OSPF, on that link. It starts OSPFv3 process 1 for that interface and places the interface in backbone area 0, which is the mandatory area that interconnects all other areas. The process ID is locally significant, and the area ID is a 32-bit value, with '0' being shorthand for 0.0.0.0.

Why this answer

The 'ipv6 ospf 1 area 0' command enables OSPFv3 (the IPv6 version of OSPF) on the specified interface, assigns it to OSPFv3 process 1, and places the interface in area 0 (the backbone area). This is the correct syntax for activating OSPFv3 on an interface under a specific process and area, independent of any global OSPFv3 process configuration.

Exam trap

Cisco often tests the distinction between OSPFv2 and OSPFv3 interface commands, and the trap here is that candidates confuse 'ip ospf' (OSPFv2) with 'ipv6 ospf' (OSPFv3) or assume the process ID must match a pre-existing global process, when in fact the interface command can auto-create the process.

How to eliminate wrong answers

Option B is wrong because 'ipv6 ospf' is specific to OSPFv3, not OSPFv2; OSPFv2 uses the 'ip ospf' command for IPv4. Option C is wrong because the process ID in the interface command does not need to match a global 'router ospf' process ID; OSPFv3 can be configured directly on the interface, and if no global process exists, one is automatically created. Option D is wrong because area 0 is perfectly valid for OSPFv3; OSPFv3 uses the same area numbering (including decimal 0 for the backbone) as OSPFv2, not area 0.0.0.0 as a required format.

43
MCQhard

A large enterprise has a campus network with a collapsed core design. The core switch connects to two distribution switches, each serving several access switches. The network uses OSPF as the IGP. Recently, after a link failure between the core and distribution switch A, the network experienced a 30-second outage before converging. The engineer wants to improve convergence time to under 5 seconds. The budget is limited, so hardware upgrades are not an option. The engineer is considering the following actions: A. Enable OSPF Fast Hello on all interfaces. B. Reduce OSPF dead timer to 1 second and hello timer to 333 milliseconds. C. Implement OSPF LSA throttling with a minimum interval of 0 ms. D. Use OSPF incremental SPF (iSPF). Which action will provide the most significant improvement in convergence time for this scenario?

A.Enable OSPF Fast Hello on all interfaces.
B.Reduce OSPF dead timer to 1 second and hello timer to 333 milliseconds.
C.Implement OSPF LSA throttling with a minimum interval of 0 ms.
D.Use OSPF incremental SPF (iSPF).
AnswerB

The OSPF dead timer is the primary factor in convergence delay because it dictates how long a router waits for a missing hello before marking the neighbor unavailable. Setting the dead timer to 1 second ensures that a link failure is detected within roughly one second, and a hello interval of 333 milliseconds satisfies the standard three-hello requirement while maintaining a stable neighbor state. This direct reduction of the detection timer cuts the outage from tens of seconds to about one second, whereas other mechanisms only optimize post-detection processing.

Why this answer

Reducing the OSPF dead timer to 1 second and hello timer to 333 milliseconds directly addresses the 30-second outage caused by the link failure. The default dead timer (40 seconds on broadcast networks) is the primary contributor to convergence delay, as OSPF must wait for the dead interval to expire before declaring a neighbor down. By lowering these timers, failure detection drops from 40 seconds to approximately 1 second, which is the most impactful single change for convergence under budget constraints.

Exam trap

Cisco often tests the misconception that Fast Hello (Option A) is the best way to speed convergence, but the trap is that Fast Hello alone does not reduce the dead timer below 1 second unless explicitly configured with a multiplier, and the dead timer is the dominant factor in failure detection time.

How to eliminate wrong answers

Option A is wrong because OSPF Fast Hello (using the 'ip ospf dead-interval minimal hello-multiplier' command) sends hellos at sub-second intervals but still relies on the dead timer for failure detection; it does not inherently reduce the dead timer below 1 second, so it may not achieve the sub-5-second convergence goal without also adjusting the dead interval. Option C is wrong because OSPF LSA throttling (with 'timers throttle lsa all') controls the rate at which LSAs are generated and retransmitted, not failure detection; it helps with network stability during flapping but does not reduce the time to detect a link failure. Option D is wrong because incremental SPF (iSPF) optimizes SPF computation by only recalculating affected routes, but it does not address the primary bottleneck of neighbor failure detection; the 30-second outage is dominated by the dead timer, not SPF calculation time.

44
MCQmedium

Given the following Ansible playbook snippet: --- - name: Configure OSPF hosts: routers gather_facts: no tasks: - name: OSPF config ios_config: lines: - router ospf 1 - network 10.0.0.0 0.255.255.255 area 0 parents: router ospf 1 What is wrong with this playbook?

A.The 'parents' parameter should not be used with 'router ospf 1' in lines; it causes a configuration error.
B.The network statement uses a wildcard mask instead of subnet mask, which is incorrect.
C.The OSPF process ID must be 1, but it can be any number.
D.There is no error; the playbook works correctly.
AnswerA

In Ansible's ios_config module, the `parents` parameter specifies the configuration mode to enter before applying `lines`. When `parents` is set to 'router ospf 1', the module already issues that command to navigate into OSPF configuration mode. Adding `router ospf 1` again inside the `lines` list results in a nested command that the Cisco IOS parser does not accept in this context, producing a configuration error. The correct usage is to place only OSPF subcommands, such as network statements, in `lines` and let `parents` handle the mode entry.

Why this answer

The `parents` parameter in the `ios_config` module specifies the parent configuration mode under which the `lines` should be applied. When `lines` already includes `router ospf 1`, using `parents: router ospf 1` causes Ansible to attempt entering the OSPF router configuration mode twice, leading to a configuration error. The correct approach is to either omit the `parents` parameter or include only the network statement in `lines` with the appropriate parent.

Exam trap

Cisco often tests the misconception that the `parents` parameter is optional or redundant when the mode entry command is already in `lines`, but in reality, it causes a duplicate command error because the module enters the parent mode first.

How to eliminate wrong answers

Option B is wrong because Cisco IOS uses wildcard masks in OSPF network statements (e.g., `network 10.0.0.0 0.255.255.255 area 0`), which is correct syntax; a subnet mask would be invalid. Option C is wrong because the OSPF process ID can be any number, but the playbook does not enforce a specific value; the issue is not about the process ID being 1. Option D is wrong because the playbook contains a logical error in the use of the `parents` parameter, as explained in the correct answer.

45
MCQmedium

Router R6 has the following OSPF configuration: router ospf 1 router-id 6.6.6.6 network 192.168.0.0 0.0.255.255 area 0 passive-interface default no passive-interface GigabitEthernet0/0 ! interface GigabitEthernet0/0 ip address 192.168.1.6 255.255.255.0 ip ospf 1 area 0 What is the effect of the 'passive-interface default' command?

A.All OSPF interfaces become passive, including GigabitEthernet0/0.
B.Only GigabitEthernet0/0 is active; all other OSPF interfaces are passive.
C.OSPF adjacencies are formed on all interfaces.
D.The 'passive-interface default' command is ignored because the 'network' command is used.
AnswerB

The passive-interface default directive makes every OSPF-enabled interface passive unless a specific interface is later excluded. The no passive-interface GigabitEthernet0/0 command removes that default for Gi0/0, permitting OSPF hello packets and adjacency formation on that link. All other OSPF interfaces remain passive and silent, so only GigabitEthernet0/0 is active in OSPF terms. This precisely matches the configuration, making it the correct answer.

Why this answer

The 'passive-interface default' command sets all OSPF interfaces to passive by default, meaning they will not send or receive OSPF hello packets and thus cannot form adjacencies. The subsequent 'no passive-interface GigabitEthernet0/0' overrides this for that specific interface, making it the only active OSPF interface. This matches option B.

Exam trap

Cisco often tests the interaction between 'passive-interface default' and 'no passive-interface' to see if candidates understand that the default command applies to all interfaces and must be explicitly overridden per interface, rather than assuming the 'network' command alone controls adjacency formation.

How to eliminate wrong answers

Option A is wrong because the 'no passive-interface GigabitEthernet0/0' command explicitly overrides the default passive setting for that interface, so not all interfaces become passive. Option C is wrong because OSPF adjacencies are only formed on interfaces that are not passive; with 'passive-interface default', only GigabitEthernet0/0 is active, so adjacencies form only on that interface. Option D is wrong because the 'passive-interface default' command is not ignored; it works in conjunction with the 'network' command, which defines which interfaces participate in OSPF, but the passive setting controls whether hellos are sent and adjacencies are formed on those interfaces.

46
MCQmedium

A network engineer is configuring OSPF on a multiaccess network. The engineer wants to ensure that only two specific routers become DR and BDR, and that other routers do not participate in the election. Which OSPF interface setting should be configured on the routers that should not become DR or BDR?

A.ip ospf database-filter all out
B.ip ospf network point-to-point
C.ip ospf priority 1
D.ip ospf priority 0
AnswerD

Setting the OSPF priority to 0 on an interface makes that router ineligible to become DR or BDR. This is the correct way to prevent a router from participating in the DR/BDR election. The router will still form adjacencies and exchange routing information, but it will remain a DROTHER. This setting is commonly used on routers that should not be DR/BDR, such as those with lower processing power or at the edge of the network.

Why this answer

Setting OSPF priority to 0 on an interface makes the router ineligible to become DR or BDR. This is the standard method to exclude routers from the election while still allowing them to participate in OSPF as DROTHERs. Other options either do not affect eligibility or change the network type entirely.

Exam trap

The trap here is thinking that any priority value other than 0 can exclude a router, when only 0 makes it ineligible.

47
MCQmedium

interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip ospf network broadcast ip ospf priority 0 ! router ospf 1 network 192.168.1.0 0.0.0.255 area 0 What is the effect of setting the OSPF priority to 0 on this interface?

A.The router will never become the DR or BDR on this segment.
B.The router will have a higher chance of becoming the DR.
C.The router will only form adjacencies with other routers that have priority 0.
D.The router will use a longer hello interval.
AnswerA

In OSPF broadcast multiaccess networks, the DR/BDR election is governed by the interface priority field, which ranges from 0 to 255. Setting a priority of 0 explicitly marks the router as ineligible to participate in the election, so it can never be selected as the DR or BDR, regardless of its Router ID or any other factor. The router remains fully operational as a DROther and still establishes adjacencies with the DR and BDR.

Why this answer

Setting the OSPF priority to 0 on an interface prevents the router from participating in the Designated Router (DR) and Backup Designated Router (BDR) election process. This means the router will never become the DR or BDR on that broadcast segment, as per RFC 2328. It will instead remain a DROTHER and only form full adjacencies with the DR and BDR, not with other DROTHER routers.

Exam trap

Cisco often tests the misconception that priority 0 means 'lowest priority' or 'least likely to become DR,' when in fact it means 'ineligible to become DR or BDR' — a binary disqualification, not a comparative value.

How to eliminate wrong answers

Option B is wrong because a priority of 0 eliminates the chance of becoming DR, not increases it; higher priority values (1-255) increase the chance. Option C is wrong because OSPF routers with priority 0 still form adjacencies with the DR and BDR, not only with other priority 0 routers; DROTHER routers do not form full adjacencies with each other. Option D is wrong because the hello interval is configured independently via the 'ip ospf hello-interval' command and is not affected by the priority setting.

48
MCQhard

A network engineer is implementing VXLAN with BGP EVPN on Cisco Nexus switches. The underlay network is OSPF, and the overlay uses MP-BGP EVPN. The engineer wants to ensure that the VXLAN tunnel endpoints (VTEPs) can discover each other and exchange MAC and IP address information. Which statement correctly describes the role of the BGP EVPN address family in this scenario?

A.It provides a routing underlay for the VXLAN tunnels by advertising VTEP loopback addresses.
B.It synchronizes the MAC address tables of all VTEPs by flooding unknown unicast traffic.
C.It encapsulates the original Ethernet frames into VXLAN packets and forwards them across the underlay.
D.It distributes MAC and IP address reachability information for hosts and enables VTEP peer discovery.
AnswerD

The BGP EVPN address family carries MAC and IP address reachability information in the form of EVPN routes, such as Type 2 and Type 5 routes. This allows VTEPs to learn about remote hosts and VTEPs, facilitating the creation of VXLAN tunnels and enabling efficient forwarding without flooding.

Why this answer

The BGP EVPN address family is used to distribute MAC and IP address reachability information across VTEPs. This enables control plane learning, reducing flooding and allowing VTEPs to discover remote hosts and VTEPs. The other options incorrectly attribute underlay routing, data plane encapsulation, or flooding-based learning to BGP EVPN.

Exam trap

The trap here is assuming that BGP EVPN handles encapsulation or underlay routing, when it is actually an overlay control plane protocol for distributing host reachability.

49
MCQmedium

A network engineer runs the following command on Router R1: R1# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 10.0.0.2 1 FULL/DR 00:00:32 192.168.1.2 GigabitEthernet0/0 10.0.0.3 1 2WAY/DROTHER 00:00:35 192.168.1.3 GigabitEthernet0/0 Based on this output, what can be concluded?

A.R1 is the Backup Designated Router (BDR) on this segment.
B.R1 has a full OSPF adjacency with the neighbor 10.0.0.3.
C.R1 is a DROTHER on this segment.
D.The OSPF network type is point-to-point.
AnswerC

R1's interface shows 2WAY/DROTHER with neighbour 10.0.0.3, and FULL/DR with 10.0.0.2, meaning R1 formed full adjacency only with the DR. On a broadcast segment, DROTHERs stay in 2WAY with each other, so R1 itself is a DROTHER, not the DR or BDR.

Why this answer

The output shows R1 has a neighbor with state 2WAY/DROTHER (10.0.0.3), which indicates that R1 is also a DROTHER on this broadcast multiaccess segment. The FULL/DR neighbor (10.0.0.2) is the Designated Router, and since R1 is not the BDR (no FULL/BDR state), it must be a DROTHER.

Exam trap

Cisco often tests the misconception that 2WAY state means a full adjacency, but in OSPF, 2WAY is a normal neighbor state on broadcast networks between DROTHERs, not a full adjacency (which requires FULL state).

How to eliminate wrong answers

Option A is wrong because R1 is not the BDR; the BDR would appear with state FULL/BDR, but the only FULL neighbor is the DR (10.0.0.2). Option B is wrong because the neighbor 10.0.0.3 is in the 2WAY state, not FULL, meaning they have an established neighbor relationship but not a full adjacency (they exchange Hellos but not LSAs directly). Option D is wrong because the presence of DR/BDR states (FULL/DR, 2WAY/DROTHER) indicates a broadcast multiaccess network type, not point-to-point.

50
MCQmedium

A network engineer is deploying Control Plane Policing on a Cisco IOS-XE router that runs OSPF, BGP, and SSH management. The engineer wants to rate-limit routing protocol traffic while ensuring that SSH management traffic is never dropped, even during a routing protocol flood. The router uses a single physical interface for all control plane traffic. Which CoPP design approach best meets these requirements?

A.Create separate class-maps for OSPF, BGP, and SSH, then apply individual policers to each class in the policy-map, with SSH assigned a higher rate or set to conform-action transmit.
B.Use a single class-map for OSPF and BGP, and rely on SSH being exempt because it is TCP-based and not subject to CoPP.
C.Configure CoPP only on the management interface and leave the data interfaces unprotected.
D.Apply a single class-map matching all control plane traffic and set a single policer with a high rate limit.
AnswerA

Creating separate class-maps allows the engineer to apply distinct policers to each traffic type. By giving SSH a higher rate limit or configuring it to always transmit, management access is protected. OSPF and BGP can be rate-limited independently to prevent control plane overload. This granular approach is the recommended CoPP design for protecting critical management traffic.

Why this answer

Separate class-maps for OSPF, BGP, and SSH allow individual policing actions. Assigning SSH a higher rate or conform-action transmit ensures management access is preserved during routing protocol floods. This granular CoPP design protects both routing stability and administrative access, which is the core goal of control plane policing.

Exam trap

The trap here is assuming that SSH management traffic is automatically exempt from CoPP because it is TCP-based, when in fact all control plane traffic is subject to the policy-map.

51
Multi-Selecthard

Which three statements about OSPF LSA types are correct? (Choose three.)

Select 3 answers
A.Type 1 LSAs (Router LSAs) are generated by every OSPF router and describe the router's interfaces and neighbors within an area.
B.Type 2 LSAs (Network LSAs) are generated by the DR on broadcast and NBMA networks to list all routers attached to the segment.
C.Type 3 LSAs (Summary LSAs) are generated by ASBRs to advertise external routes into the OSPF domain.
D.Type 4 LSAs (ASBR Summary LSAs) are generated by ABRs to advertise the location of an ASBR to routers in other areas.
E.Type 5 LSAs (AS External LSAs) are flooded only within the area where they originate.
AnswersA, B, D

Every OSPF router originates a Type 1 Router LSA describing its own links, interface states and costs, flooded only within its area. This satisfies the requirement that each router advertises its local topology, forming the basis of the area's shortest-path tree.

Why this answer

Option A is correct because Type 1 Router LSAs are originated by every OSPF-enabled router, are scoped to a single area, and describe that router's links (interfaces, IP addresses, metrics) and its neighbors on those links. Option B is correct because Type 2 Network LSAs are generated only by the Designated Router on multi-access segments such as broadcast and NBMA networks, and they list the DR, the BDR, and all attached routers to represent the transit network. Option D is correct because Type 4 ASBR Summary LSAs are produced by Area Border Routers to tell routers in other areas how to reach an Autonomous System Boundary Router located in a different area.

Option C is wrong because Type 3 Summary LSAs are generated by ABRs to advertise inter-area routes, not by ASBRs to advertise external routes. Option E is wrong because Type 5 AS External LSAs are flooded throughout the entire OSPF autonomous system (except stub/NSSA areas), not confined to the originating area.

Exam trap

350-401 often tests the confusion between ABRs and ASBRs — candidates wrongly attribute Type 3 Summary LSAs to ASBRs, when ABRs generate Type 3 and ASBRs generate Type 5, and they forget Type 5 LSAs flood domain-wide rather than staying area-local.

52
MCQhard

A network administrator is configuring a Cisco IOS router to authenticate OSPF neighbors using MD5. The router must use key 1 with the password 'Cisco123' on interface GigabitEthernet0/0. Which configuration is correct?

A.interface GigabitEthernet0/0 ip ospf authentication-key Cisco123 ip ospf authentication
B.router ospf 1 area 0 authentication message-digest ip ospf message-digest-key 1 md5 Cisco123
C.interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 Cisco123
D.router ospf 1 authentication message-digest message-digest-key 1 md5 Cisco123
AnswerC

This configuration enables OSPF MD5 authentication on the interface and defines the key with ID 1 and password 'Cisco123'. The 'ip ospf authentication message-digest' command activates MD5 authentication for OSPF on that interface, and the 'ip ospf message-digest-key' command specifies the key. This is the correct method to configure MD5 authentication on a per-interface basis in Cisco IOS.

Why this answer

To enable OSPF MD5 authentication on a specific interface, you must enter interface configuration mode, enable MD5 authentication with 'ip ospf authentication message-digest', and define the key with 'ip ospf message-digest-key 1 md5 Cisco123'. This ensures that OSPF packets on that interface are authenticated using MD5, meeting the security requirement.

Exam trap

The trap here is confusing area-wide authentication with interface-level key configuration, leading to placing the key under the OSPF process instead of the interface.

53
MCQmedium

A network engineer is configuring a new Cisco IOS router and wants to ensure that OSPFv2 adjacencies form only on the interface that connects to the trusted internal network. The router has three interfaces: GigabitEthernet0/0 (internal), GigabitEthernet0/1 (DMZ), and GigabitEthernet0/2 (Internet). The engineer enables OSPF process 1 and wants to advertise the internal network 10.1.1.0/24 while preventing OSPF from sending or receiving hello packets on the other interfaces. Which configuration accomplishes this goal?

A.router ospf 1 network 10.1.1.0 0.0.0.255 area 0 passive-interface default no passive-interface GigabitEthernet0/0
B.router ospf 1 network 10.1.1.0 0.0.0.255 area 0 passive-interface GigabitEthernet0/1 passive-interface GigabitEthernet0/2
C.router ospf 1 network 10.1.1.0 0.0.0.255 area 0 ip ospf passive-interface GigabitEthernet0/1 ip ospf passive-interface GigabitEthernet0/2
D.router ospf 1 network 10.1.1.0 0.0.0.255 area 0 passive-interface GigabitEthernet0/0
AnswerA

This configuration enables OSPF on the router, advertises the internal subnet, and sets all interfaces to passive by default. The 'no passive-interface GigabitEthernet0/0' command re-enables OSPF hello processing only on the internal interface, allowing adjacencies to form there while suppressing them on the DMZ and Internet interfaces. This matches the requirement exactly.

Why this answer

The requirement is to allow OSPF adjacencies only on the internal interface while suppressing them on all others. Setting 'passive-interface default' disables OSPF hello processing on every interface, and then 'no passive-interface GigabitEthernet0/0' re-enables it only on the internal interface. This ensures that OSPF runs exclusively where intended and prevents unintended adjacencies on the DMZ and Internet links.

Exam trap

The trap here is assuming that the network command alone controls which interfaces run OSPF, when in fact OSPF can run on any interface whose IP matches the network statement, and passive-interface is needed to suppress hellos on specific interfaces.

54
MCQhard

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against DoS attacks. The router has a management plane that includes SSH and SNMP, and a control plane that includes routing protocols like OSPF and BGP. The engineer wants to rate-limit traffic destined to the route processor while ensuring that management traffic is not dropped during high CPU load. Which CoPP configuration approach is most appropriate?

A.Configure separate classes for management traffic (SSH, SNMP) and control plane traffic (OSPF, BGP), and assign higher rate limits to management traffic.
B.Use a single class that matches all IP traffic and set a high rate limit to avoid dropping any packets.
C.Apply a single CoPP policy that classifies all traffic to the route processor and sets a low rate limit for all classes.
D.Configure CoPP only for routing protocols and rely on QoS for management traffic.
AnswerA

This is the best practice. By creating separate classes, the engineer can apply different rate limits. Management traffic should have a higher rate limit to ensure administrators can always access the device, while control plane protocols can have lower limits to protect the route processor. This granularity ensures that critical management access is not starved during an attack, and routing protocols are still protected but not at the expense of management access.

Why this answer

CoPP allows granular control over traffic destined to the route processor. By separating management and control plane traffic into different classes, the engineer can assign higher rate limits to management traffic to ensure administrative access is maintained, while still protecting the route processor from excessive control plane traffic. This approach balances security and availability, preventing both DoS attacks and administrator lockout.

Exam trap

The trap here is assuming that a single CoPP policy with a uniform rate limit is sufficient, overlooking the need to prioritize management traffic to prevent lockout during an attack.

55
MCQmedium

Given the following SD-WAN configuration on a Cisco IOS-XE router: router ospf 1 redistribute bgp 65000 subnets network 192.168.1.0 0.0.0.255 area 0 ! interface GigabitEthernet0/0/0 ip address 192.168.1.1 255.255.255.0 ip ospf network point-to-point ! Which statement is true?

A.The OSPF network type is point-to-point, so the hello interval defaults to 10 seconds on this interface.
B.The OSPF network type is point-to-point, so the dead interval defaults to 120 seconds.
C.The redistribution of BGP into OSPF will cause OSPF to advertise all BGP routes, including those learned via SD-WAN overlay.
D.The configuration is incomplete because OSPF requires a router-id to be manually configured.
AnswerA

On a point-to-point OSPF network type, Cisco's default hello interval is 10 seconds, identical to the default on broadcast networks. This is because both network types use the same timer defaults on Cisco IOS, and the dead interval is then calculated as 4 × 10 = 40 seconds. Since the option specifically addresses the hello interval, it is correct.

Why this answer

On a Cisco IOS-XE router, when the OSPF network type is set to point-to-point, the default hello interval is 10 seconds (not 30 seconds as on broadcast networks). The dead interval defaults to 40 seconds (four times the hello interval), not 120 seconds. This configuration is valid and does not require a manually configured router-id, as OSPF can dynamically select one.

The redistribution of BGP into OSPF only injects routes that are in the BGP table; it does not automatically include all SD-WAN overlay routes unless they are present in BGP.

Exam trap

Cisco often tests the default OSPF timer values for different network types, specifically tricking candidates into thinking point-to-point uses 30-second hello or 120-second dead intervals, which are actually defaults for NBMA networks.

How to eliminate wrong answers

Option B is wrong because the OSPF dead interval for a point-to-point network defaults to 40 seconds (4 × hello interval of 10 seconds), not 120 seconds. Option C is wrong because the 'redistribute bgp 65000 subnets' command only redistributes BGP routes that are in the BGP routing table; it does not automatically advertise all SD-WAN overlay routes unless they are learned via BGP and meet redistribution criteria (e.g., subnets keyword includes classless prefixes). Option D is wrong because OSPF does not require a manually configured router-id; if none is configured, OSPF automatically selects the highest IP address on a loopback interface or the highest IP address on any active physical interface.

56
Drag & Dropmedium

Drag and drop the steps of OSPF summarization at ABR configuration steps into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

First, identify the subnets to summarize into a single prefix. Then, configure the area range command on the ABR under the OSPF process, specifying the area and the summary prefix. Optionally, set the 'not-advertise' keyword to suppress the summary.

Verify the summary route in the OSPF database using 'show ip ospf summary-address'. Finally, check that the summary route appears in the routing table of other routers.

57
MCQhard

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect against DoS attacks. The router has a management plane that must remain accessible via SSH and SNMP, and a control plane that must process BGP and OSPF routing updates. The administrator applies a CoPP policy that rate-limits all traffic destined to the control plane to 1000 pps, except for traffic from trusted management subnets. After applying the policy, BGP sessions flap intermittently. What is the most likely cause?

A.The CoPP policy is rate-limiting BGP keepalives and updates, causing session timeouts.
B.The CoPP policy is applied to the data plane instead of the control plane, causing routing updates to be dropped.
C.The CoPP policy is incorrectly classifying SSH traffic as BGP, leading to rate limiting of SSH.
D.The CoPP policy is dropping SNMP traps, causing BGP to lose its peer state.
AnswerA

CoPP policies that apply a blanket rate limit to all control plane traffic can inadvertently throttle essential routing protocol messages like BGP keepalives and updates. If the rate limit is too low or not exempting BGP, sessions may flap due to missed keepalives or delayed updates. The policy must be fine-tuned to allow sufficient bandwidth for routing protocols.

Why this answer

CoPP policies must be carefully designed to avoid throttling critical control plane protocols. A blanket rate limit of 1000 pps may be insufficient for BGP, especially if there are many peers or frequent updates. BGP keepalives are sent every 60 seconds by default, but updates and other messages can burst.

If the policer drops these, sessions can flap. The correct approach is to create granular class-maps that match BGP and other routing protocols, and assign appropriate rates or exempt them from policing.

Exam trap

The trap here is assuming that a single rate limit for all control plane traffic is safe, without considering the specific needs of routing protocols like BGP.

58
MCQeasy

A retail company wants its network engineers to push consistent OSPF configurations to dozens of Cisco IOS XE routers using a declarative, agentless automation tool that connects over SSH and does not require installing software on the managed devices. Which tool best fits these requirements?

A.Ansible, using modules such as ios_config with an inventory of IOS XE devices and SSH credentials.
B.Puppet, using a master-agent architecture with the Puppet agent installed on each IOS XE router.
C.Chef, using a Chef client installed directly on each Cisco IOS XE router to converge configuration.
D.SaltStack, using Salt minions installed locally on every IOS XE device to receive configuration commands.
AnswerA

Ansible is declarative, agentless, and connects to managed nodes over SSH without installing any agent software. Its network modules, including ios_config and ios_ospf, target Cisco IOS and IOS XE devices and push configuration from playbooks. This matches the requirement for consistency across many routers, no on-device agent, and SSH-based transport exactly as described.

Why this answer

Ansible is the agentless, declarative tool that connects over SSH and uses network-specific modules to configure Cisco IOS XE devices. It needs no software installed on the routers, relying instead on SSH and Python executed on the control node. Puppet, Chef, and SaltStack in their default forms require an agent on the managed node, which IOS XE cannot host, so they fail the stated agentless requirement.

Exam trap

The trap here is assuming all configuration-management tools are agentless, when Puppet, Chef, and SaltStack default to agent-based designs.

59
MCQhard

A security team is deploying Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. They notice that after applying a CoPP policy, OSPF adjacency with a directly connected neighbor flaps intermittently. Which action should the engineer take to resolve the issue while maintaining control plane protection?

A.Add a class-map matching OSPF traffic and associate it with a policer that has a higher committed information rate.
B.Configure OSPF authentication on the interface to reduce the volume of OSPF packets processed.
C.Remove the CoPP policy from the control plane and rely on ACLs on the management interface.
D.Change the CoPP policy to use a police rate of 8000 pps for all traffic classes.
AnswerA

OSPF hello and LSA traffic to the route processor must be permitted at a sufficient rate to maintain adjacency. Creating a class-map for OSPF and assigning a policer with an adequate CIR ensures control plane protection remains in place while allowing legitimate routing protocol traffic, which resolves the flapping caused by the default policer dropping OSPF packets.

Why this answer

CoPP uses class-maps and policy-maps to rate-limit traffic destined to the control plane. If the default policer for routing protocols is too low, OSPF hellos can be dropped, causing adjacency flaps. Creating a dedicated class for OSPF and assigning a policer with a higher committed information rate allows legitimate routing traffic while still protecting the route processor.

Exam trap

The trap here is assuming that removing CoPP or applying a blanket high rate is acceptable, rather than tuning the specific class that is being dropped.

60
MCQeasy

What is the default OSPF hello interval on an Ethernet broadcast network?

A.10 seconds
B.30 seconds
C.5 seconds
D.20 seconds
AnswerA

On Ethernet (broadcast) and point-to-point links, OSPF's default hello interval is 10 seconds, as defined in RFC 2328. This 10-second hello is also paired with a default dead interval of 40 seconds (four times the hello), allowing a neighbor to be declared down after missed hellos. This setting balances fast neighbor detection with acceptable control-plane overhead on high-bandwidth LAN segments.

Why this answer

On Ethernet broadcast networks, OSPF defaults to a hello interval of 10 seconds, as specified in RFC 2328. This interval is used to maintain neighbor relationships and detect failures quickly on high-speed multi-access links.

Exam trap

Cisco often tests the OSPF hello interval default by mixing up broadcast and NBMA values, leading candidates to mistakenly choose 30 seconds for Ethernet networks.

How to eliminate wrong answers

Option B is wrong because 30 seconds is the default hello interval for OSPF on non-broadcast multi-access (NBMA) networks, such as Frame Relay, not on Ethernet broadcast networks. Option C is wrong because 5 seconds is not a standard OSPF hello interval; it is sometimes used in proprietary or tuned configurations but not the default. Option D is wrong because 20 seconds is not a default OSPF hello interval; it might be confused with the default dead interval multiplier (4 times the hello interval) which would be 40 seconds for a 10-second hello, not 20.

61
Drag & Drophard

Drag and drop the steps of OSPF redistribution from EIGRP with metric conversion into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Redistribution requires enabling redistribution, setting a seed metric (or using default-metric), optionally matching routes, and then verifying. The order ensures routes are properly injected.

62
Drag & Drophard

Drag and drop the steps of OSPF route redistribution into a different autonomous system into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

Redistribution requires first configuring the routing process that will receive the routes, then defining the source protocol and metric, optionally setting route tags for loop prevention, applying a route map for filtering, and finally verifying the redistributed routes appear in the OSPF database.

63
MCQeasy

A network administrator is configuring a new Cisco IOS router and needs to enable OSPFv2 on an interface with the correct area and network type. The interface is a broadcast multi-access network. Which command should be used to enable OSPF on the interface and set the area to 0?

A.router ospf 1: area 0 interface GigabitEthernet0/0
B.interface GigabitEthernet0/0: ip ospf 1 area 0
C.interface GigabitEthernet0/0: ip ospf area 0
D.router ospf 1: network 10.0.0.0 0.0.0.255 area 0
AnswerB

This command enables OSPF process 1 on the interface and assigns it to area 0. It is the interface-level method for enabling OSPF, which is precise and avoids the need for network statements. This is the recommended practice in modern Cisco IOS because it directly associates the interface with the OSPF process and area, reducing configuration errors.

Why this answer

The interface-level command 'ip ospf 1 area 0' enables OSPF process 1 on the interface and assigns it to area 0. This method is preferred over network statements because it is explicit and avoids unintended OSPF activation on other interfaces. The other options are either invalid syntax or less precise methods.

Exam trap

The trap here is assuming that OSPF must be enabled via the 'network' command under router configuration, overlooking the interface-level command.

64
MCQeasy

A network administrator is configuring a new Cisco IOS router and needs to enable OSPFv3 for IPv6 on an interface. The interface is already configured with an IPv6 address. Which command must be entered in interface configuration mode to enable OSPFv3 on that interface?

A.ipv6 ospf 1 area 0
B.ospfv3 1 ipv6 area 0
C.ipv6 router ospf 1
D.ip ospf 1 area 0
AnswerA

This command enables OSPFv3 on the interface and associates it with OSPF process 1 and area 0. It is the correct way to enable OSPFv3 for IPv6 on an interface in Cisco IOS. The process ID must match the one configured in the global 'ipv6 router ospf' command. This command is essential for OSPFv3 operation on a per-interface basis.

Why this answer

To enable OSPFv3 for IPv6 on an interface in Cisco IOS, the correct interface configuration command is 'ipv6 ospf <process-id> area <area-id>'. This command activates OSPFv3 on the interface and links it to the specified OSPFv3 process and area. The process ID must match the one defined in the global 'ipv6 router ospf' command.

Without this command, the interface will not participate in OSPFv3 routing.

Exam trap

The trap here is confusing OSPFv2 for IPv4 with OSPFv3 for IPv6, leading to the use of 'ip ospf' instead of 'ipv6 ospf'.

65
MCQmedium

A network engineer is deploying a new branch office router that must obtain its WAN interface IP address dynamically from the ISP while also advertising its LAN prefix into OSPF. The engineer configures the WAN interface with the ip address dhcp command. Which additional configuration is required on the router to ensure the LAN prefix is advertised into OSPF with the correct network statement when the WAN IP changes?

A.Enable OSPF on the WAN interface and rely on connected route redistribution.
B.Use the network command with a wildcard mask that matches the LAN subnet under router ospf.
C.Configure a static route to the ISP and redistribute it into OSPF.
D.Configure OSPF to use the interface's DHCP-assigned IP address as the router ID.
AnswerB

The network command under router ospf with a wildcard mask matching the LAN subnet will advertise the LAN prefix into OSPF regardless of the WAN IP address. This is the standard method to enable OSPF on an interface and advertise its connected network. It does not depend on the WAN IP, so it remains stable when the DHCP lease changes.

Why this answer

The network command under router ospf with a wildcard mask matching the LAN subnet is the correct way to advertise the LAN prefix into OSPF. It is independent of the WAN interface's DHCP-assigned IP address, so the advertisement remains stable even if the WAN IP changes. Other options either advertise the wrong prefix or introduce unnecessary complexity.

Exam trap

The trap here is assuming that because the WAN interface uses DHCP, the OSPF configuration must also be dynamic, but the LAN advertisement is separate and should use a static network statement.

66
MCQeasy

What is the default OSPF reference bandwidth used for cost calculation in Cisco IOS?

A.100 Mbps
B.1000 Mbps
C.10 Mbps
D.1 Mbps
AnswerA

100 Mbps is the OSPF default reference bandwidth defined in RFC 2328, and it is used in the formula cost = reference-bandwidth / interface-bandwidth. With this default, a 100 Mbps interface has a cost of 1, and any interface faster than 100 Mbps also receives a cost of 1 because OSPF costs are integer values; this is why network administrators often raise the reference bandwidth in modern high-speed networks.

Why this answer

In Cisco IOS, the default OSPF reference bandwidth is 100 Mbps. OSPF calculates the cost of an interface as the reference bandwidth divided by the interface bandwidth. With the default reference of 100 Mbps, a FastEthernet (100 Mbps) interface gets a cost of 1, which is the minimum cost.

This default was established when FastEthernet was considered high-speed, but it can be changed using the 'auto-cost reference-bandwidth' command to accommodate faster links like GigabitEthernet.

Exam trap

Cisco often tests the default OSPF reference bandwidth as 100 Mbps, and the trap here is that candidates confuse it with the actual interface bandwidth (e.g., 10 Mbps for Ethernet) or assume it matches the fastest common link speed (e.g., 1000 Mbps for GigabitEthernet).

How to eliminate wrong answers

Option B (1000 Mbps) is wrong because 1000 Mbps is not the default; it is a common value set manually to avoid cost rounding issues on GigabitEthernet and faster interfaces. Option C (10 Mbps) is wrong because 10 Mbps is the bandwidth of an Ethernet interface, not the reference bandwidth; using 10 Mbps would make all faster links have fractional costs. Option D (1 Mbps) is wrong because 1 Mbps is the bandwidth of a legacy serial link and would result in extremely high costs for modern interfaces; the default reference bandwidth is 100 Mbps.

67
MCQmedium

A network engineer is troubleshooting OSPF adjacency issues between two routers connected via a Gigabit Ethernet link. The engineer notices that the routers are stuck in the EXSTART state. Both routers have the same MTU of 1500 bytes. What is the most likely cause of this issue?

A.The OSPF network type is point-to-point on one router and broadcast on the other.
B.The OSPF hello and dead intervals are mismatched.
C.One router has a lower IP MTU configured on the interface, causing the DBD packet to be dropped.
D.The OSPF router IDs are the same.
AnswerC

In the EXSTART state, OSPF routers exchange Database Description (DBD) packets to negotiate the master/slave relationship and begin advertising their link-state databases. DBD packets are often the largest OSPF packets sent, and if one router has a lower interface IP MTU, the DBD packet may exceed that MTU and be silently dropped by the receiving router's IP stack. Because the DBD packet never arrives, the routers cannot complete the master/slave negotiation and remain stuck in EXSTART indefinitely. This is a textbook symptom of an MTU mismatch on the OSPF interface.

Why this answer

When OSPF routers are stuck in the EXSTART state, it typically indicates a problem with the Database Description (DBD) packet exchange. Even though both routers have the same configured MTU of 1500 bytes, one router may have a lower IP MTU on its interface (e.g., due to a different interface MTU or encapsulation overhead), causing the DBD packet to be fragmented or dropped. Since OSPF DBD packets are not fragmented, a mismatch in the actual IP MTU prevents the adjacency from progressing beyond EXSTART.

Exam trap

Cisco often tests the nuance that the configured MTU (e.g., 1500 bytes) may not equal the actual IP MTU due to overhead from encapsulation or interface settings, leading to DBD packet drops and a stuck EXSTART state.

How to eliminate wrong answers

Option A is wrong because mismatched OSPF network types (e.g., point-to-point vs. broadcast) would cause the routers to get stuck in the INIT or 2-WAY state, not EXSTART; the DBD exchange process is not even reached. Option B is wrong because mismatched hello and dead intervals prevent the routers from forming a neighbor relationship at all, leaving them stuck in the DOWN or INIT state, not EXSTART. Option D is wrong because duplicate OSPF router IDs would cause a conflict that prevents adjacency formation, typically resulting in a state of DOWN or INIT, not EXSTART.

68
MCQhard

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router. The router runs OSPF, BGP, SSH management, and SNMP polling. After applying a CoPP policy, the administrator notices that OSPF adjacencies flap intermittently while BGP and SSH remain stable. Which action should the administrator take to resolve the flapping while maintaining control plane protection?

A.Remove the CoPP policy entirely and rely on interface ACLs for control plane protection.
B.Increase the committed information rate (CIR) for the OSPF class in the CoPP policy.
C.Apply the CoPP policy only to the BGP and SSH classes, leaving OSPF unpoliced.
D.Configure OSPF authentication to reduce the number of OSPF packets processed by the route processor.
AnswerB

OSPF hellos and LSAs are being dropped because the policer for the OSPF class is too restrictive. Increasing the CIR for that class allows more OSPF control traffic to reach the route processor, stabilizing adjacencies. This maintains protection for other protocols while addressing the specific queue that is over-policing legitimate OSPF packets during normal adjacency formation and maintenance.

Why this answer

OSPF adjacency flapping after applying CoPP indicates that the policer for the OSPF control plane class is dropping legitimate hello or LSA packets. Increasing the CIR for that class allows the required OSPF traffic to be punted to the route processor. This preserves control plane protection for other protocols while resolving the flapping, which is a common tuning step in CoPP deployments.

Exam trap

The trap here is thinking that CoPP either works or does not, when in reality each class needs to be tuned to match the protocol's legitimate traffic profile.

69
MCQmedium

Examine the following configuration: interface GigabitEthernet0/0 ip address 172.16.1.1 255.255.255.0 ipv6 address 2001:db8:1::1/64 ipv6 ospf 100 area 0 ! What is missing from this configuration to enable OSPFv3 on this interface?

A.The configuration is complete; no additional commands are needed.
B.The command 'ipv6 router ospf 100' must be added globally to create the OSPFv3 process.
C.The interface needs the 'ipv6 ospf network point-to-point' command to work.
D.The 'ipv6 unicast-routing' command must be enabled globally.
AnswerB

The global command 'ipv6 router ospf 100' creates the OSPFv3 routing process with process ID 100 and enters router configuration mode. Only after this process exists can interface-level commands like 'ipv6 ospf 100 area 0' become operational. This is the missing required step, making the configuration functional and allowing the router to exchange LSAs with its neighbors.

Why this answer

OSPFv3 requires an active OSPFv3 process on the router before it can be enabled on any interface. The 'ipv6 router ospf 100' global command creates the OSPFv3 process with process ID 100, which is necessary for the interface-level 'ipv6 ospf 100 area 0' command to function. Without this global process, the interface configuration is incomplete and OSPFv3 will not operate.

Exam trap

Cisco often tests the requirement that an OSPFv3 process must be created globally with 'ipv6 router ospf <process-id>' before interface-level OSPFv3 commands will work, leading candidates to mistakenly think the interface configuration alone is sufficient.

How to eliminate wrong answers

Option A is wrong because the configuration is not complete; the OSPFv3 process must be created globally with 'ipv6 router ospf 100' for the interface command to take effect. Option C is wrong because 'ipv6 ospf network point-to-point' is an optional command used to override the default network type (e.g., broadcast) and is not required for basic OSPFv3 operation on this interface. Option D is wrong because 'ipv6 unicast-routing' enables IPv6 routing globally but is not specifically required for OSPFv3; OSPFv3 can run without it as long as IPv6 is configured, though it is commonly enabled for practical routing.

70
MCQmedium

interface GigabitEthernet0/0 ip address 192.168.1.1 255.255.255.0 ip ospf network point-to-point ip ospf hello-interval 10 ! router ospf 1 network 192.168.1.0 0.0.0.255 area 0 What is the effect of this configuration?

A.OSPF will use a 10-second hello interval and suppress DR/BDR election.
B.OSPF will use a 30-second hello interval and elect a DR/BDR.
C.OSPF will use a 10-second hello interval but still elect a DR/BDR.
D.OSPF will use a 30-second hello interval and suppress DR/BDR election.
AnswerA

This is the correct behavior. The `point-to-point` OSPF network type is designed for links that connect exactly two routers, such as serial interfaces using PPP or HDLC. By definition, it eliminates DR/BDR election because there is no need to reduce adjacency flooding on a two-router segment, and it uses the default 10-second hello interval (with a 40-second dead interval). Configuring `ip ospf network point-to-point` is redundant when the interface already defaults to this type, but it is often used to explicitly override an interface's default OSPF network type on platforms like Ethernet or Frame Relay.

Why this answer

The `ip ospf network point-to-point` command changes the OSPF network type on the interface to point-to-point, which suppresses the DR/BDR election process because point-to-point links have only two neighbors. The `ip ospf hello-interval 10` command overrides the default hello interval for point-to-point networks (which is 10 seconds by default anyway, but explicitly setting it ensures consistency). Thus, OSPF uses a 10-second hello interval and does not elect a DR/BDR.

Exam trap

Cisco often tests the misconception that changing the hello interval alone affects DR/BDR election, or that the point-to-point network type still uses a 30-second hello interval like NBMA, when in fact point-to-point suppresses DR/BDR and uses a 10-second hello interval by default.

How to eliminate wrong answers

Option B is wrong because it incorrectly states a 30-second hello interval; the configured hello interval is 10 seconds, and the default for point-to-point is also 10 seconds, not 30. Option C is wrong because it claims DR/BDR election still occurs, but the point-to-point network type explicitly suppresses DR/BDR election. Option D is wrong because it combines both errors: a 30-second hello interval (incorrect) and suppression of DR/BDR election (correct in concept but paired with the wrong interval).

71
MCQmedium

An engineer is troubleshooting an MPLS VPN where CE1 (10.1.1.0/24) cannot reach CE2 (10.2.2.0/24). The PE routers are running OSPF with the CE routers. On PE1, the 'show ip route vrf CUSTOMER' output shows 10.2.2.0/24 as an OSPF route, but the prefix is not present in the global BGP table. What is the most likely cause?

A.Redistribution from OSPF into BGP under the VRF is not configured on PE1.
B.The OSPF adjacency between PE1 and CE1 is down.
C.The VRF forwarding table on PE1 is full.
D.MPLS LDP is not enabled on the PE1-CE1 link.
AnswerA

Within an MPLS L3VPN, simply running OSPF in the VRF does not make a CE route available to the MP-BGP VPNv4 control plane. The PE must explicitly execute a redistribution command, such as 'redistribute ospf 1 vrf CUSTOMER' under 'router bgp AS ... address-family ipv4 vrf CUSTOMER'. Missing this command means the OSPF-installed route stays confined to the VRF RIB; it is never given a route distinguisher, tagged with an export route target, or sent to remote PEs. Consequently, even a healthy OSPF adjacency and populated VRF still result in no VPNv4 prefix.

Why this answer

In an MPLS VPN, the PE router must redistribute OSPF routes learned from the CE into MP-BGP under the VRF to propagate them across the MPLS backbone. Without this redistribution, the prefix 10.2.2.0/24 appears in the VRF routing table as an OSPF route but is never injected into the BGP table, so it cannot be advertised to the remote PE. This explains why CE1 cannot reach CE2 despite the route being present locally on PE1.

Exam trap

Cisco often tests the distinction between a route being present in the VRF routing table versus being present in the BGP table, trapping candidates who assume that OSPF-learned routes are automatically propagated across the MPLS VPN backbone without explicit redistribution into MP-BGP.

How to eliminate wrong answers

Option B is wrong because if the OSPF adjacency between PE1 and CE1 were down, the 10.2.2.0/24 route would not appear in the VRF routing table at all, but the question states it is present. Option C is wrong because a full VRF forwarding table would cause route installation failures or drops, not the specific symptom of a route missing from the global BGP table while present in the VRF. Option D is wrong because MPLS LDP on the PE1-CE1 link is irrelevant for MPLS VPN; LDP is used for label distribution in the core, not on the CE-facing link, and the issue is about BGP route propagation, not label switching.

72
MCQmedium

An enterprise network uses OSPF as its IGP. The network engineer notices that a particular route learned via OSPF is not being installed in the routing table, even though the neighbor adjacency is up and the route appears in the OSPF database. The route is an external route redistributed from EIGRP. What is the most likely cause?

A.The OSPF process ID is different on the routers.
B.The external route has a higher administrative distance than the internal route.
C.The forwarding address in the type 5 LSA is not reachable via an OSPF internal route.
D.The OSPF metric for the external route is too high.
AnswerC

For redistributed external routes, OSPF installs the type 5 LSA only if the forwarding address is reachable through an OSPF internal route. If that address resolves via another protocol or not at all, the route stays in the database but never enters the routing table.

Why this answer

OSPF requires the forwarding address (FA) in a Type 5 LSA to be reachable via an OSPF internal route (intra-area or inter-area) for the external route to be installed in the routing table. If the FA is not reachable, the router will ignore the LSA and not install the route, even though the LSA exists in the OSPF database and the neighbor adjacency is up.

Exam trap

Cisco often tests the forwarding address reachability requirement for Type 5 LSAs, and the trap here is that candidates assume any route in the OSPF database will automatically be installed, ignoring the recursive lookup condition for external routes with a non-zero forwarding address.

How to eliminate wrong answers

Option A is wrong because the OSPF process ID is locally significant and does not affect route installation between routers; different process IDs can still form adjacencies and exchange routes. Option B is wrong because OSPF external routes (type 5) have a default administrative distance of 110, while internal OSPF routes also have 110; the issue is not about AD comparison between internal and external OSPF routes, but about reachability of the forwarding address. Option D is wrong because a high OSPF metric does not prevent route installation; it only influences route selection among multiple paths; the route will still be installed if the metric is valid and the forwarding address is reachable.

73
MCQmedium

A network engineer is deploying a VXLAN EVPN fabric on Cisco Nexus 9000 switches. The underlay is a Layer 3 routed fabric using OSPF. The engineer needs to ensure that multicast replication is not used for BUM (Broadcast, Unknown Unicast, Multicast) traffic. Which VXLAN EVPN configuration is required on the leaf switches?

A.Configure the NVE interface with a multicast group address using the `member vni <vni> mcast-group <group-address>` command.
B.Configure PIM sparse mode on all underlay interfaces and enable multicast routing on the leaf switches.
C.Configure the NVE interface with `ingress-replication protocol bgp` and ensure EVPN is enabled for the VNI.
D.Configure the NVE interface with `source-interface loopback0` and rely on OSPF to flood BUM traffic to all VTEPs.
AnswerC

Ingress replication with BGP EVPN allows the leaf to replicate BUM traffic to all remote VTEPs in the EVPN control plane without using multicast in the underlay. This is the correct approach when multicast replication is not desired. The command `ingress-replication protocol bgp` enables this behavior.

Why this answer

To avoid multicast replication in a VXLAN EVPN fabric, ingress replication must be used. The leaf switches must be configured with `ingress-replication protocol bgp` under the NVE interface, and EVPN must be enabled for the VNI. This allows the leaf to use the EVPN control plane to discover remote VTEPs and replicate BUM traffic to them via unicast.

Multicast replication requires PIM in the underlay, which is not desired here.

Exam trap

The trap here is assuming that VXLAN always requires multicast in the underlay for BUM traffic replication, when in fact ingress replication via BGP EVPN is a common alternative.

74
MCQhard

An enterprise is using OSPF in a multi-area design. Area 1 is a regular area, and Area 2 is a totally stubby area. Which LSA types are present in Area 2?

A.Type 1, Type 2, Type 3 (including default)
B.Type 1, Type 2, Type 3, Type 5
C.Type 1, Type 2, Type 4, Type 5
D.Type 1, Type 2, Type 3 (including default), Type 4
AnswerA

In a totally stubby area, the ABR suppresses Type 4 (ASBR-summary) and Type 5 (AS-external) LSAs, and also replaces all Type 3 inter-area summaries with a single default route. This leaves only Type 1 (router) and Type 2 (network) LSAs for intra-area topology, plus the injected Type 3 default LSA for any traffic leaving the area. Therefore, the allowed LSA set is exactly Type 1, Type 2, and the default Type 3.

Why this answer

In a totally stubby area, the ABR blocks Type 4 and Type 5 LSAs and replaces all Type 3 inter-area routes with a single default route (Type 3 LSA with link-state ID 0.0.0.0). Therefore, only Type 1 (router), Type 2 (network), and the default Type 3 LSAs are present. This matches option A.

Exam trap

Cisco often tests the distinction between a standard stub area (which allows Type 3 summaries but blocks Type 4 and Type 5) and a totally stubby area (which additionally blocks all Type 3 summaries except the default), causing candidates to confuse the LSA types allowed in each.

How to eliminate wrong answers

Option B is wrong because Type 5 (AS-external) LSAs are blocked in a totally stubby area; they are only present in a standard stub area if not using the 'no-summary' keyword. Option C is wrong because Type 4 (ASBR-summary) LSAs are also blocked in a totally stubby area, and Type 5 LSAs are blocked as well. Option D is wrong because Type 4 LSAs are not present in a totally stubby area; the ABR does not advertise the ASBR location into the area.

75
MCQmedium

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The administrator wants to protect the route processor from excessive control-plane traffic while still allowing legitimate routing protocol and management traffic. The administrator creates a class map that matches BGP, OSPF, and SSH traffic and applies a police action with a committed information rate. Which additional configuration element is required to complete the CoPP implementation?

A.Configure a route map that matches the control-plane protocols and reference it in the policy map.
B.Apply the policy map to all physical interfaces using the service-policy input command under interface configuration mode.
C.Apply the policy map to the control plane using the service-policy input command under control-plane configuration mode.
D.Enable NetFlow on the router to export control-plane traffic statistics to a collector.
AnswerC

CoPP requires a policy map to be attached to the control plane with service-policy input under control-plane configuration mode. Without this attachment, the class maps and policy map exist but are not enforced on control-plane traffic, leaving the route processor unprotected.

Why this answer

CoPP is implemented by defining class maps to identify control-plane traffic, a policy map to apply actions such as police, and then attaching the policy map to the control plane with service-policy input under control-plane configuration mode. Without that attachment, the policy is never applied to control-plane traffic, so the route processor remains vulnerable to excessive protocol or management packets.

Exam trap

The trap here is assuming that applying a policy map to physical interfaces protects the control plane, when CoPP specifically requires attachment under control-plane configuration mode.

Page 1 of 2 · 129 questions totalNext →

Ready to test yourself?

Try a timed practice session using only OSPF questions.