Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Cisco 300-420 Dumps Questions Answers

Page: 1 / 28
Total 379 questions

Designing Cisco Enterprise Networks (ENSLD) v1.1 Questions and Answers

Question 1

An engineer must propose a QoS architecture model that allows an application to inform the network of its traffic profile and to request a particular type of service to support its bandwidth and delay requirements. The application requires consistent and dedicated bandwidth end to end. Which QoS architecture model meets these requirements?

Options:

A.

DiffServ

B.

LLQ

C.

WRED

D.

IntServ

Buy Now
Question 2

A company is running BGP on a single router, which has two connections to the same ISP. Which BGP

feature ensures traffic is load balanced across the two links to the ISP?

Options:

A.

Multihop

B.

Multipath Load Sharing

C.

Next-Hop Address Tracking

D.

AS-Path Prepending

Question 3

An engineer is tasked with designing a dual BGP peering solution with a service provider. The design must meet these conditions:

    The routers will not learn any prefix with a subnet mask greater than /24.

    The routers will determine the routes to include in the routing table based on the length of the mask alone.

    The routers will make this selection regardless of the service provider configuration.

Which solution should the engineer include in the design?

Options:

A.

Use a route map and access list to block the desired networks, and apply the route map to BGP neighbors inbound.

B.

Use a route map and prefix list to block the desired networks, and apply the route map to BGP neighbors outbound.

C.

Use an IP prefix list to block the desired networks and apply the IP prefix list to BGP neighbors outbound.

D.

Use an IP prefix list to block the desired networks and apply the IP prefix list to BGP neighbors inbound.

Question 4

Refer to the exhibit. Which two points in the network must an engineer configure the ports for explicit trust when using a DiffServ model?

Options:

A.

B and E

B.

F and G

C.

A and D

D.

C and D

Question 5

Which two statements about VRRP object tracking are true? (Choose two)

Options:

A.

The priority of a VRRP device can change in accordance with the up or down status of a VRRP object

B.

The VRRP interface priority must be manually configured by the administrator

C.

A VRRP group can track only one object at a time

D.

VRRP can track the status of interfaces and routes

E.

VRRP supports only interface tracking

Question 6

An engineer needs to design a management network for the company. The solution has these requirements:

    overlay network does not cause routing issues

    ease of troubleshooting for the operations team

    devices are accessed securely

Which solution meets these requirements?

Options:

A.

VRF for management traffic and SSH keys for device access

B.

Private VLANs for management traffic and TACACS+ for device access

C.

Separate physical interfaces for management traffic and TACACS+ for device access

D.

VLANs for management traffic and RADIUS for device access

Question 7

An engineer is designing a BGP solution supporting a VXLAN environment over a Layer 3 IPv4 network fabric with these requirements

    provide Layer 2 adjacency

    allow VM migration of workloads between sites

    IGP is OSPF

Which BGP address family must the engineer choose?

Options:

A.

VPNv4

B.

IPv4 unicast

C.

L2VPN VPLS-VPWS

D.

L2VPNEVPN

Question 8

A customer is discussing QoS requirements with a network consultant. The customer has specified that end-to-end path verification is a requirement. Which QoS solution meets this requirement?

Options:

A.

IntServ model with RSVP to support the traffic flows

B.

DiffServ model with PHB to support the traffic flows

C.

marking traffic at the access layer with DSCP to support the traffic flows

D.

marking traffic at the access layer with CoS to support the traffic flows

Question 9

Which feature minimizes TLOC connections and reduces strain on the vSmart controller in an SD-WAN architecture?

Options:

A.

control-direction

B.

affinity

C.

color

D.

control-connections

Question 10

Which protocol is the Cisco SD-Access data plane based on?

Options:

A.

OMP

B.

VXLAN

C.

NHRP

D.

LISP

Question 11

In an SD-WAN architecture, which methods are used to bootstrap a vEdge router?

Options:

A.

DHCP options or manual configuration

B.

vManage or DNS records

C.

ZTP or manual configuration

D.

DNS records or DHCP options

Question 12

Refer to the exhibit. An architect must create a stable and scalable EIGRP solution for a customer. The design must:

•conserve bandwidth, memory, and CPU processing

•prevent suboptimal routing

•avoid any unnecessary queries

Which two solutions must the architect select? (Choose two.)

Options:

A.

route summarization

B.

prefix lists

C.

distribute lists

D.

stub routing

E.

static redistribution

Question 13

Refer to the exhibit. An architect must ensure a convergence time of 200 ms or less during a link failure within area 0. In addition, the solution must not impact the overall performance of the network. Which solution must the architect select?

Options:

A.

UDLD

B.

BFD

C.

fast hellos

D.

carrier delay

Question 14

A customer requested that a guaranteed service line be enabled for a manufacturing business in different countries. On the customer side, the QoS-aware application is used to process large data chunks. The application cannot tolerate drops and latency should be as low as possible. Which QoS model must an engineer employ to use the minimum required resources on the ISP network nodes?

Options:

A.

Implement a group-based QoS strategy with FECs enabled

B.

Enable a flow-based QoS strategy with queuing elements.

C.

Implement an end-to-end QoS strategy with SLA.

D.

Configure a domain-based QoS strategy with PHB behavior.

Question 15

Which function are fabric intermediate nodes responsible for in an SD-Access Architecture?

Options:

A.

mapping EIDs to RLOCs

B.

encapsulating user traffic in a VXLAN header including the SGT

C.

registering new endpoints in the HTDB

D.

transporting IP packets between edge nodes and border nodes

Question 16

An engineer must peer with an ISP for internet connectivity using BGP, initially, the engineer wants to receive only specific prefixes from the ISP and a default route. However, the solution must provide the flexibility to add prefixes in the future at short notice. The ISP has a two-week change process in place. Which route filtering solution must the engineer employ?

Options:

A.

Request a limited internet routing table and a default route from the ISP and configure the BGP max-limit to 1 with an access list that permits only the specific internet prefixes and blocked networks

B.

Request only the required prefixes and default route be advertised from the ISO with whitelisted networks

C.

Request a full internet routing table and a default route from the ISP and configure inbound route filtering with a prefix list that permits the default route and required prefixes

D.

Configure outbound route filtering on the enterprise and ISP so that the enterprise tell the ISP which prefixes are required

Question 17

Refer to the exhibit. As part of a design review of redistribution, a client requested that R2 be preferred over R3 for traffic passing toward the EIGRP domain. Which method meets this design requirement?

Options:

A.

Redistribute EIGRP into OSPF with metric-type E1 on R2 and metric-type E2 on R3.

B.

Remove the mutual redistribution on R3.

C.

Redistribute OSPF into EIGRP with metric 10000 100 255 1 1500 on R2 and metric 10 1000 255 1 1500 on R3.

D.

Redistribute EIGRP into OSPF with metric-type E2 on R2 and metric-type E1 on R3.

Question 18

Refer to the exhibit A customer wants to adopt a dynamic site-to-site VPN solution to secure communication for VoIP, video, and FTP traffic between the remote branches and the headquarters. The customer also wants the branches to communicate directly, thereby reducing traffic at the headquarters location. The solution must consider that the branch routers are limited in available memory. Which VPN solution meets these requirements?

Options:

A.

DMVPN Phase 2 Hub and Spoke design

B.

DMVPN Phase 3 Hub and Spoke design

C.

DMVPN Phase 1 Hub and Spoke design

D.

DMVPN Phase 3 Hierarchical design

Question 19

An engineer must design a scalable QoS architecture that allows the separation of the traffic into classes on predefined business requirements. The design must also utilize the differentiated services code points as the QoS priority descriptor value and support at least 10 levels of classification. Which QoS technology should the engineer include in the design?

Options:

A.

RSVP

B.

Diffserv

C.

Best effort

D.

Interserv

Question 20

The customer solution requires QoS to support streaming multimedia over a WAN. An architect chooses to use Per-Hop Behavior. Which solution should the engineer use to of mark traffic traveling between branch sites?

Options:

A.

LLQ with DSCP EF

B.

CBWFQ with DSCP AF3

C.

CBWFQ with DSCP AF2

D.

LLQ with DSCP AF4

Question 21

Refer to the exhibit. A Cisco Catalyst switch is configured to.. only one MAC address to be learned manually on interface gkjO/2. Which command must be run to dynamically learn the devices that are connected to the switch port?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 22

A customer is undergoing a WAN re-architecture and wants to design QoS policies for remote sites that have low bandwidth. What must be considered to have CBWFQ configured in the parent and child policies in an end-to-end QoS design?

Options:

A.

CBWFQ is only supported in the child policy.

B.

CBWFQ is only supported in the parent policy.

C.

Traffic shaping is required in the parent policy.

D.

Traffic policing is required in the child policy.

Question 23

Refer to the exhibit.

An architect must design an IGP solution for an enterprise customer. The design must support:

Physical link flaps should have minimal impact.

Access routers should converge quickly after a link failure.

Which two ISIS solutions should the architect include in the design? (Choose two.)

Options:

A.

Use BGP to IS-IS redistribution to advertise all Internet routes in the Level 1 area.

B.

Advertise the IS-IS interface and loopback IP address toward the Internet and data center.

C.

Reduce SPF and PRC intervals to improve convergence time.

D.

Configure all access and aggregate routers to establish Level 1 / Level 2 adjacencies across the network.

E.

Configure access routers to establish a Level 1 adjacency and aggregate routers to establish a Level 1 /

Level 2 adjacency.

Question 24

Refer to the exhibit. Which method must an architect use to provide connectivity between the mail servers?

Options:

A.

ISATAP

B.

6to4

C.

IPv4 compaliDie

D.

6rd

Question 25

Drag and drop the steps WAN Edge performs when on-boarded into the Cisco SD-WAN overlay from the left into the order they are completed on the right.

Options:

Question 26

An organization is designing a detailed QoS plan that limits bandwidth to specific rates. Which two parameters are supported be the traffic policing feature? (Choose two.)

Options:

A.

violating

B.

marking

C.

shaping

D.

bursting

E.

conforming

Question 27

Drag and drop the components in a Cisco SD-Access architecture from the left onto their descriptions on the right.

Options:

Question 28

Drag and drop the properties from the left onto the protocols they describe on the right.

Options:

Question 29

An engineer working for a service provider with an employee ID: 4863:43:939 must design a solution to provide remote connectivity over the public internet. The design must:

    securely connect multiple remote sites to the central site

    provide redundant paths to the central site

    allow auto path selection based on failure and connection quality

    support IP multicast

    minimal configuration at remote sites

Which solution must the engineer choose?

Options:

A.

MPLS provided service with BGP

B.

dual DMVPN with EIGRP routing

C.

full mesh OSPF with IPsec tunnels

D.

full mesh ISIS with GRE tunnels and IPsec

Question 30

Which node performs the LISP Map-Server and Map-Resolver functions in the Cisco SD-Access network architecture?

Options:

A.

control plane node

B.

fabric edge node

C.

border node

D.

intermediate node

Question 31

Options:

Question 32

Refer to the exhibit. An engineer must ensure that the QoS design guarantees bandwidth for the applications, and an application can request a particular type of service to support its delay requirements. Which solution must the engineer select?

Options:

A.

Diffserv with RSVP

B.

IntServ with RSVP

C.

Diffserv with DSCP

D.

IntServ with DSCP

Question 33

A company ' s security policy requires that all connections between sites be encrypted in a manner that does not

require maintenance of permanent tunnels. The sites are connected through a private MPLS-based service that

uses a dynamically changing key and spoke-to-spoke communication. Which type of transport encryption must

be used in this environment?

Options:

A.

GETVPN

B.

DMVPN

C.

GRE VPN

D.

standard IPsec VPN

Question 34

An engineer must connect a new remote site to an existing OSPF network. The new site consists of two low-end routers, one for WAN, and one for LAN. There is no demand for traffic to pass through this area. Which area type does the engineer choose to provide minimal router resources utilization, while still allowing for full connectivity to the rest of the network?

Options:

A.

not so stubby

B.

totally not so stubby

C.

totally stubby area

D.

stubby area

Question 35

At which layer does Cisco Express Forwarding use adjacency tables to populate addressing information?

Options:

A.

    Layer4

B.

    Layer 2

C.

    Layer 1

D.

    Layer 3

Question 36

Refer to the exhibit. The full EIGRP routing table is advertised throughout the network. Currently, users experience data loss when any one link in the network fails. An architect optimizes the network to reduce the impact when a link fails. Which solution should the architect include in the design?

Options:

A.

Run BFD on the inter links between EIGRP neighbors.

B.

Summarize the access layer networks from each access layer switch toward the aggregation layer.

C.

Reduce the default EIGRP hello interval and hold time.

D.

Summarize the access layer networks from the aggregation layer toward the core layer.

Question 37

Refer to the exhibit. An engineer Is designing a redistribution solution for a customer. The customer recently acquired another company and decided to integrate the new network running RlPv1 with the company ' s existing network. Which redistribution technique must the engineer select to ensure the multipoint two-way redistribution does not cause routing loops?

Options:

A.

distribute-lists inbound under the EIGRP process denying RIPv1 learned prefixes

B.

distribute-lists outbound under the EIGRP process denying RIPv1 learned prefixes

C.

distribute-lists outbound under the RIPv1 process denying EIGRP learned prefixes

D.

distribute-lists inbound under the RIPv1 process denying EIGRP learned prefixes

Question 38

What is one function of the vSmart controller in an SD-WAN deployment?

Options:

A.

orchestrates vEdge and cEdge connectivity

B.

responsible for the centralized control plane of the SD-WAN network

C.

provides centralized network management and a GUI to monitor and operate the SD-WAN overlay

D.

provides a data-plane at branch offices to pass traffic through the SD-WAN network

Question 39

An architect must design a network solution for a regional medical center that will provide interconnectivity between regionally dispersed data centers and a new colocation. The design must:

    utilize point-to-point connectivity

    utilize existing VLAN infrastructure

    increase performance for data center synchronization and backup processes

    reduce configuration complexity

Which solution must the engineer choose?

Options:

A.

L3VPN

B.

GRE

C.

DMVPN

D.

L2VPN

Question 40

A network engineer must design an MSDP multicast solution to provide RP resilience in a network with two separate domains. Also, multicast sources and receivers must register with the local RP. Which solution must the engineer choose?

Options:

A.

Configure the RP has value to 0, and traffic will route to the closest RP

B.

Configure the RP loopback interface with the same IP address/32, and traffic will route to the closest RP

C.

Configure the RP group ranges to split the multicast traffic, and traffic will route to the longest match

D.

Configure the RP priority with the same value, and traffic will route to the closest RP

Question 41

An engineer must establish a direct connection between two remote offices. The new connection must be established using a logical path, share a common broadcast domain, connect over private WAN, and have as little overhead as possible. Which technology must the engineer choose?

Options:

A.

L2VPN

B.

GET VPN

C.

IPsec

D.

GRE

Question 42

Refer to the exhibit. An architect is designing an ISIS network for a customer migrating from IPv4 to IPv6. The current network uses narrow metrics, and the IPv6 areas will increase to 10 within the next two years. Also, IPv6 traffic must not blackhole in IPv4 network during the migration. Which two solutions must the architect choose? (Choose two.)

Options:

A.

multi-topology enabled under address-family ipv6 on C1 and C2

B.

metric-style transition enabled on all routers

C.

multi-topology enabled under address-family ipv6 on E1 and E2

D.

metric-style transition enabled on C1 and C2

E.

metric-style transition enabled on E1 and E2

Question 43

In a Cisco SD-Access fabric, which node facilities connectivity between the fabric and networks external to the fabric?

Options:

A.

intermediate

B.

edge

C.

control plane

D.

border

Question 44

An engineer is designing a QoS solution for a campus. The design must guarantee real-time traffic delivery during congestion, minimize the bandwidth consumption for possible virus or worm attacks, and reduce flooding of excessive traffic during times of congestion. Which two solutions must the engineer select? (Choose two.)

Options:

A.

Create a shaping policy to drop excessive traffic and a strict queue for real-time traffic.

B.

Apply queuing on the distribution to core links

C.

Create a policing policy to drop excessive traffic and a strict queue for real-time traffic.

D.

Create a scavenger queue for excessive traffic and a strict queue for real-time traffic

E.

Apply queuing on the access to distribution links.

Question 45

When vEdge router redundancy is designed, which FHRP is supported?

Options:

A.

HSRP

B.

OMP

C.

GLBP

D.

VRRP

Question 46

Which feature is required for graceful restart to recover from a processor failure?

Options:

A.

Cisco Express Forwarding

B.

Virtual Switch System

C.

Stateful Switchover

D.

Bidirectional Forwarding Detection

Question 47

Which type of rendezvous point deployment is standards-based and supports dynamic RP discovery?

Options:

A.

bootstrap router

B.

Anycast-RP

C.

Auto-RP

D.

static RP

Question 48

Refer to the exhibit. Which process does the Ethernet LMI protocol follow that is defined by the MEF 16 Technical Specification?

Options:

A.

communicates ENI and EVC attributes to the CE

B.

notifies the CE of the availability state of a configured EVC

C.

broadcasts multicast network routes from the CE to the PE

D.

broadcasts to all subnets from the CE when an EVC is added

Question 49

Refer to the exhibit. An architect reviews the low-level design of a company ' s enterprise network and advises optimizing the STP convergence time. Which functionality must be to Gi1/0/1-10 to follow the architect ' s recommendation?

Options:

A.

PortFast

B.

root guard

C.

UplinkFast

D.

BPDU guard

Question 50

What is the purpose of service routes in OMP updates?

Options:

A.

specify routes toward a centralized orchestration plane

B.

describe underlay transport Information

C.

define the remote management Information

D.

indicate services that are enabled for service insertion

Question 51

An engineer working for a service provider with an employee ID 4598.48.606 prepared several designs for a traditional campus network. The design must allow the deployment on the same VXLAN to any switch at the access layer and must support:

    Fast convergence

    High availability

    Resilience

Which design must be selected?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 52

Which two functions are provided by the Cisco SD-WAN orchestration plane? (Choose two.)

Options:

A.

centralized provisioning

B.

primary authentication point

C.

NAT traversal facilitation

D.

Zero Touch Provisioning

E.

troubleshooting and monitoring

Question 53

An enterprise needs to enhance its WAN availability after a recent outage with its only MPLS provider. The proposed solution must have a quick deployment, be affordable, be reliable, and work as a backup for the enterprise ' s primary MPLS connection. Which solution meets these requirements?

Options:

A.

Contract an internet connection and deploy DMVPN.

B.

Deploy BFD echo mode and probe provider PE

C.

Deploy an additional WAN router and use a floating static route

D.

Contract another MPLS provider and deploy GET VPN.

Question 54

What are two characteristics of a migration from an IP-VPN service to a Cisco SD-WAN architecture? (Choose two.)

Options:

A.

increased solution complexity

B.

increased security

C.

increased scalability

D.

centralized application policies

E.

distributed control plane

Question 55

An architect is designing a network for an enterprise site. The design must use an active/backup design for the WAN. It must guarantee the SLA for several applications regardless of which connection is used. Which deployment model should the architect choose?

Options:

A.

MPLS WAN from two separate ISPs

B.

hybrid WAN using MPLS VPN and internet VPN from a single ISP

C.

hybrid WAN using MPLS VPN and internet VPN from two separate ISPs

D.

internet WAN from two separate ISPs

Question 56

Refer to the exhibit. An architect is designing a Layer 3 routed network using point-to-point fiber links between the topology layers. BFD is supported on the software that runs within the infrastructure. Is BFD required within the design to provide sub-second convergence in the event of a fiber breakage?

Options:

A.

No, the OSPF hello and dead intervals must be tuned instead.

B.

Yes, but BFD requires tuning to provide fault detection and sub-second convergence.

C.

No, the topology converges sub-second without the use of BFD.

D.

Yes, it automatically provides the required fault detection and sub-second convergence.

Question 57

Refer to the exhibit An engineer with an employee ID: 1234 56:789 must design a WoL deployment for a client, and the design must ensure that the Windows PCs are responsive to the WoL magic packets with no delays when the server-side initiates the instruction Which action must the engineer choose?

Options:

A.

Spanning-tree PortFast must be enabled on all interfaces where clients reside.

B.

WoL must be enabled on the networking card and disabled in the Windows PCs BIOS.

C.

IP-directed broadcast must be disabled on all interfaces where clients reside.

D.

IP forward protocol must be disabled on all interfaces where clients reside

Question 58

A network engineer prepares a script to configure a loopback interface with IP address 172.16.15.12/32. To comply with the company security policies, ' Content-type ' :

‘application/yang-data+json‘ is added to the script. Connection to the network devices must be secured. Which code snippet must the network engineer use to meet this requirement?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 59

Drag and drop the characteristics from the left onto the configuration protocols they describe on the right.

Options:

Question 60

Which method does Cisco SD-WAN use to avoid fragmentation issues?

Options:

A.

PMTUD is used.

B.

Traffic is marked with the DF bit set.

C.

Jumbo frames are enabled.

D.

Access circuits are configured with 1600 byte MTU settings.

Question 61

An architect is creating a migration strategy for a large organization in which the choice made by the application between IPv6 and IPv4 is based on the DNS request. Which migration strategy does the architect choose?

Options:

A.

AFT for public web presence

B.

host-initiated tunnels

C.

dual stack

D.

site-to-site IPv6 over IPv4 tunnels

Question 62

Refer to the exhibit. A company has some offices that are connected via dark fiber in New York. A network architect must optimize the network design based on the EIGRP routing protocol. The network has hierarchical addressing between 10 and 12 routers in each office. Routing convergence time must be at the minimum. What must the network architect do to reduce the query range?

Options:

A.

Configure stub areas on non-edge routers.

B.

Implement network summarization on edge routers.

C.

Use different EIGRP processes on edge routers.

D.

Configure route filtering on non-edge routers.

Question 63

Company A recently acquired another company. Users of the newly acquired company must be able to access a server that exists on Company A’s network, both companies use overlapping IP address ranges. Which action conserves IP address space and provides access to the server?

Options:

A.

Use a single IP address to create overload NAT

B.

Use a single IP address to create a static NAT entry

C.

Build one-to-one NAT translation for every user that needs access

D.

Re-IP overlapping address space in the acquired company

Question 64

Which component is part of the Cisco SD-Access overlay architecture?

Options:

A.

border node

B.

spine node

C.

leaf node

D.

Cisco DNA Center

Question 65

A network engineer must design a multicast solution based on these requirements:

    interactive communication

    must not use source trees

    users must register

    100 multicast sources

Which solution must the company choose?

Options:

A.

MSDP

B.

PIM-DM

C.

any-source multicast

D.

BIDIR PIM

Question 66

What is the purpose of Cisco vBond as a Session Traversal Utilities for NAT server?

Options:

A.

allow Cisco Catalyst SD-WAN routers to locate their own mapped IP addresses

B.

integrate Cisco SD-Access Wireless into the fabric

C.

secure data traffic between Cisco Catalyst SD-WAN edge routers that use IPsec

D.

provide Zero-Touch Provisioning to Cisco Catalyst SD-WAN vEdge devices

Question 67

Which encoding languages are supported in NETCONF compared to RESTCONF?

Options:

A.

NETCONF supports XML and JSON, and RESTCONF supports XML.

B.

NETCONF supports XML, and RESTCONF supports JSON.

C.

NETCONF supports JSON, and RESTCONF supports XML.

D.

NETCONF supports XML, and RESTCONF supports XML and JSON.

Question 68

An architect is designing how the company will manage the infrastructure of a large data center. The company wants to group device types for security reasons and mitigate DoS attacks. The company also wants to ensure that access to the rest of the production network is not possible if one device is compromised on the management plane. Which solution must the architect choose?

Options:

A.

in-band dial-up circuit

B.

in-band Ethernet

C.

out-of-band Ethernet

D.

out-of-band dial-up circuit

Question 69

What is a challenge of the SaaS model?

Options:

A.

higher initial costs

B.

lack of application and infrastructure control

C.

requires upgrades to individual computers to meet performance requirements

D.

higher application and data integration complexity

Question 70

Refer to the exhibit. A customer is planning to onboard three new VPN partner connections in the data center. The new subnets must not overlap with the existing data center network, and the subnet size must not be bigger than necessary. The customer dedicated 10.1.8.0/21 for this design. Ho 1 // must the subnets be divided to meet these requirements?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 71

Exhibit:

Options:

A.

Make R3 an L1L2 router.

B.

Make R31 an L1 router.

C.

Make Area 0 L2-only.

D.

Make R11 an L2 router.

Question 72

Which feature provides the capability for intra-VN traffic filtering and control within the Cisco SO-Access architecture?

Options:

A.

scalable groups

B.

MAC ACL

C.

prefix list

D.

service policy

Question 73

How is redundancy achieved among Cisco vBond Orchestrators in a Cisco SD-WAN deployment?

Options:

A.

The IP addresses of all Orchestrators are mapped to a single DNS name.

B.

The closest Orchestrator to each Cisco WAN Edge router is selected.

C.

Cisco WAN Edge routers are configured with all Orchestrators using their IP addresses and priority.

D.

A single Cisco Orchestrator is deployed in each network.

Question 74

A company plans to transition to IPv6. They will link their IPv4 addresses to the lowest significant bits of the new Ipv6 addresses. A network administrator with an employee id: 4264:42:116 is preparing a mapping schema for the new IPv6 addresses. Which address does the 172.16.10.0/24 network translate to?

Options:

A.

2001:db8:abcd::ac10:a00/120

B.

2001:db8:abcd:172:16:10::/96

C.

2001:db8:abcd:11d8:a00/120

D.

2001:db8:ac10:0a00::/64

Question 75

Refer to the exhibit.

An engineer must optimize the traffic flow of the network. Which change provides a more

efficient design between the access and the distribution layer?

Options:

A.

Add a link between access switch A and access switch B

B.

Reconfigure the distribution switch A to become the HSRP Active

C.

Change the link between distribution switch A and distribution switch B to be a routed link

D.

Create an EtherChannel link between distribution switch A and distribution switch B

Question 76

How is internet access provided to a WAN edge router that is connected to a MPLS transport link?

Options:

A.

OMP advertises a default route from a WAN Edge router that is connected to the MPLS and internet transport networks

B.

Internet access must be provided at the WAN Edge router through either a 4G/5G link or local Internet circuit

C.

An extranet must be provided in the MPLS transport network to allow private traffic to reach the public internet

D.

TLOC extensions are used to route traffic to a WAN Edge router that is connected to the Internet transport network

Question 77

Which two techniques improve the application experience in a Cisco SD-WAN design? (Choose two.)

Options:

A.

utilizing forward error correction

B.

implementing a stateful application firewall

C.

implementing AMP

D.

utilizing quality of service

E.

implementing Cisco Umbrella

Question 78

An architect is designing a network that will utilize the spanning tree protocol to ensure a loop-free topology. The network will support an engineering environment where it is necessary for end users to connect their own network switches for testing purposes. Which feature should the architect include in the design to ensure the spanning tree topology is not affected by these rogue switches?

Options:

A.

BPDU Skew Detection

B.

BPDU guard

C.

loop guard

D.

root guard

Question 79

Refer to the exhibit. An architect must design a solution to connect the two ASs. To optimize bandwidth, the design will implement load sharing between router R6 and router R4. Which solution should the design include?

Options:

A.

Use update-source to specify the Loopback interface.

B.

Use next-hop-serf attributes only for routes that are learned from eBGP peers.

C.

Configure the eBGP TTL to support eBGP multihop.

D.

Use maximum-paths to install multiple paths in the routing table.

Question 80

What is the function of the multicast Reverse Path Forwarding check?

Options:

A.

It allows for a loop-free distribution tree from the source to receivers.

B.

It serves as an Auto RP Mapping agent.

C.

It prevents bootstrap messages from reaching all routers.

D.

It is used to discover and announce RP-set information.

Question 81

An engineer must use YANG with an XML representation to configure a Cisco IOS XE switch with these specifications:

    IP address 10.10.10.10/27 configured on the interface GigabitEthernet2/1/0

    connectivity from a directly connected host 10.10.10.1/27

Which YANG data model set must the engineer choose?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 82

Refer to the exhibit An architect is designing an IPv4 plan using the 172 20 0.0/16 network The design must maximize the number of subnets and minimize the number of wasted IP addresses In addition, the plan must allocate a subnet to these customers and links

    Customer A, which supports 125 hosts

    Customer D, which supports 62 hosts

    Links B C. and E

Which two configuration sets meet these requirements ' ? (Choose two)

A)

B)

C)

D)

E)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 83

Refer to the exhibit. A company is expanding and decides to use a DMVPN solution to connect the branches. The network uses the EIGRP routing protocol. All remote branch routers must be configured with the normal EIGRP area. Auto-summary is not allowed on the routers in the network. Which solution must the company implement on R1 to achieve this goal?

Options:

A.

Disable the stuck-in-active timer.

B.

Configure a multipoint interface.

C.

Disable split horizon.

D.

Configure a summary route.

Question 84

An engineer is designing a multicast network for a financial application Most of the multicast sources also receive multicast traffic (many-to-many deployment model). To better routing tables, the design must not use source trees. Which multicast protocol satisfies these requirements?

Options:

A.

BIRDIR-PIM

B.

PIM-SM

C.

MSDP

D.

PIM-SSM

Question 85

Prior to establishing full-mesh iPsec tunnels in a typical Cisco SD-WAN deployment, which mechanism do WAN Edge routers use to exchange Key information for data plane encryption?

Options:

A.

They use vSmart controllers as key exchange servers.

B.

They use vManage as a key exchange server.

C.

They use IKEv2 when exchanging keys with each other.

D.

They use vBond as a key exchange server.

Question 86

Drag and drop the Cisco SD-WAN components from the left onto their definitions on the right.

Options:

Question 87

A network engineer must segregate three interconnected campus networks using IS-IS routing. A two-layer hierarchy must be used to support large routing domains and to avoid more specific routes from each campus network being advertised to other campus network routers automatically. Which two actions does the engineer take to accomplish this segregation? (Choose two.)

Options:

A.

Designate two IS-IS routers as BDR routers at the edge of each campus, and configure one BDR for all Level 1 routers and one BDR for all Level 2 routers.

B.

Designate two IS-IS routers from each campus to act as Level 1/Level 2 backbone routers at the edge of each campus network.

C.

Assign the same IS-IS NET value for each campus, and configure internal campus routers with Level 1/ Level 2 routing.

D.

Utilize different MTU values for each campus network segment. Level 2 backbone routers must utilize a larger MTU size of 9216.

E.

Assign a unique IS-IS NET value for each campus, and configure internal campus routers with Level 1 routing.

Question 88

Which two considerations must be made regarding the overlay network for a Cisco SD-Access architecture? (Choose two.)

Options:

A.

Virtual networks should be used for microsegmentation

B.

SGTs should be used for data plane isolation and microsegmentation

C.

Virtual networks should be used for data plane isolation only

D.

Overlapping IP addresses across different overlay networks should be used to conserve IP addresses

E.

Overlapping IP addresses across different overlay networks should be avoided for operational simplicity

Question 89

An engineer must use YANG with an XML representation to configure a Cisco IOS XE switch with these specifications:

    IP address 10.10.10.10/27 configured on the interface GigabitEthernet2/1/0

    connectivity from a directly connected host 10.10.10.1/27

Which YANG data model set must the engineer choose?

Options:

A.

B.

C.

D.

Question 90

An engineer uses Postman and YANG to configure a router with:

    OSPF process ID 400

    network 192.168.128.128/25 enabled for Area 0

Which get-config reply verifies that the model set was designed correctly?

Options:

A.

B.

C.

D.

Question 91

Refer to the exhibit. A customer has two eBGP peerings from a single CE router toward two service providers. The customer has hired an architect to design a solution to ensure certain traffic enters the customer ' s network through interface g¡g0/0. Which solution must the architect include in the design?

Options:

A.

Advertise a lower MED value toward the less preferred service provider.

B.

Prepend additional AS on the AS path toward the preferred service provider.

C.

Break aggregated routes into longer prefixes and advertise to the preferred service provider.

D.

Set a higher local preference to the preferred service provider path.

Question 92

Refer to the exhibit. An architect is designing a Layer 3 campus network. The design must hide network instability, reduce network overhead, and conserve critical device memory. Which route summarization solution must the architect select?

Options:

A.

The aggregation layer must advertise a default route toward the access layer. The VLAN subnets must be summarized into 10.0.0.0/16 at the aggregation layer and advertised to the core layer.

B.

The core layer must advertise a default route toward the aggregation layer. The VLAN subnets must be summarized into 10.0.0.0/16 at the access layer and advertised to the aggregation layer.

C.

The aggregation layer must advertise a default route toward the core layer. The VLAN subnets must be summarized into 10.0.0.0/16 at the aggregation layer and advertised to the access layer.

D.

The core layer must advertise a default route toward the aggregation layer. The VLAN subnets must be summarized into 10.0.0.0/16 at the aggregation layer and advertised to the core layer.

Question 93

Which two overlay network design considerations must be made for a Cisco SD-Access network? (Choose two.)

Options:

A.

LAN automation for deployment

B.

Layer 3 to the access design

C.

Reduce subnets and simplify DHCP management

D.

Dedicated IGP process for the fabric

E.

Avoid overlapping IP subnets

Question 94

Refer to the exhibit. An architect is designing a BGP solution to connect a remote branch to a service provider. There are several prefixes within the branch that the company does not want to be advertised to the internet. Which solution should the architect use to accomplish this?

Options:

A.

Set the BGP Internet community for all prefixes.

B.

Implement the NOPEER community.

C.

Use the BGP No-Advertise community for the prefixes to exclude.

D.

Attach the No-Export community with the prefixes to exclude

Question 95

Refer to the exhibit. An architect needs to ensure that network traffic from the New Office network can access the server with the least network latency. All links within the network infrastructure currently have the same link cost. Which configuration meets the requirement?

Options:

A.

metric-style wide on R8

B.

static route on R8 toward R7

C.

route leaking on R13 and R9

D.

Level 1-2 (L1/L2) mode on R8

Question 96

Refer to the exhibit. The connection between SW2 and SW3 is fiber and occasionally experiences unidirectional link failure. An architect must optimize the network to reduce the change of layer2 forwarding loops when the link fails. Which solution should the architect include?

Options:

A.

Utilize 8PDU filter on SW3.

B.

Utilize loop guard on SW2

C.

Utilize BPDU guard on SW1

D.

Utilize root guard on SW1.

Question 97

Which solution allows overlay VNs to communicate with each other in an SD-WAN Architecture?

Options:

A.

External fusion routers can be used to map VNs to VRFs and selectively route traffic between VRFs.

B.

GRE tunneling can be configured between fabric edges to connect one VN to another.

C.

SGTs can be used to permit traffic from one VN to another.

D.

Route leaking can be used on the fabric border nodes to inject routes from one VN to another.

Question 98

A client is moving to Model-Driven Telemetry and requires periodic updates. What must the network architect consider with this design?

Options:

A.

Updates that contain changes within the data are sent only when changes occur.

B.

Empty data subscriptions do not generate empty update notifications.

C.

Periodic updates include a full copy of the data that is subscribed to.

D.

The primary push update is sent immediately and cannot be delayed.

Question 99

What is a primary capability of the cloud-based services model in an IaaS deployment?

Options:

A.

It provides workload-migration capabilities, which allows seamless movement of virtual machines and applications between on-premises infrastructure and the cloud.

B.

It reduces operational costs and increases flexibility by allowing organizations to pay for only the resources they consume.

C.

It provides the ability to scale resources up or down based on demand, which enables an organization to adjust its computing capacity dynamically.

D.

It leverages advanced orchestration and automation tools to streamline resource provisioning and management, which reduces manual effort and improves operational efficiency.

Question 100

Which feature of Cisco SD-WAN Secure Direct Cloud Access divides user traffic into different zones and VPNs or VRFs?

Options:

A.

centralized data policy

B.

secure segmentation

C.

perimeter control

D.

application-awareness routing

Question 101

A company is planning to open two new branches and allocate the 2a01:c30:16:7009::3800/118 IPv6 network for the region. Each branch should have the capacity to accommodate maximum of 200 hosts. Which two networks should the company use? (Choose two.)

Options:

A.

2a01:0c30:0016:7009::3a00/120

B.

2a01:0c30:0016:7009::3b00/121

C.

2a01:0c30:0016:7009::3a80/121

D.

2a01:0c30:0016:7009::3b00/120

E.

2a01:0c30:0016:7009::3c00/120

Question 102

What is the purpose of a TLOC extension in a Cisco SD-WAN network fabric?

Options:

A.

to facilitate WAN Edge router redundancy within a site

B.

to identify the physical interface where a WAN Edge router connects to the WAN transport network

C.

to expand the number of colors that are potentially applied to a network transport interface

D.

to aggregate multiple physical interfaces into a single logical Interface

Question 103

Refer to the exhibit. Where must an architect plan for route summarization for the topology?

Options:

A.

from the core toward the aggregation and the access toward the aggregation

B.

from the core toward the aggregation and the aggregation toward the core

C.

from the aggregation toward the access and the access toward the aggregation

D.

from the aggregation toward the core and the aggregation toward the access

Question 104

Which feature is used to optimize WAN bandwidth of IGMP network traffic among WAN Edge routers in the

same VPN?

Options:

A.

IGMPv2

B.

multicast RP

C.

multicast-replicator

D.

multicast service routes

Question 105

A company needs to increase access port capacity on one floor of a building. They want to leverage the existing catalyst access switch. There is no problem with uplink bandwidth capacity. However, no additional uplinks can be added because no ports are available on the distribution switches. Which solution must the company choose to provide additional access ports?

Options:

A.

VDC

B.

VSS

C.

Etherchannel

D.

Stackwise

Question 106

Which consideration must be taken into account when using the DHCP relay feature in a Cisco SD-Access Architecture?

Options:

A.

DHCP-relay must be enabled on fabric edge nodes to provide the correct mapping of DHCP scope to the local anycast gateway.

B.

A DHCP server must be enabled on the border nodes to allow subnets to span multiple fabric edges.

C.

DHCP servers must support Cisco SD-Access extensions to correctly assign IPs to endpoints in an SD-Access fabric with anycast gateway.

D.

DHCP Option-82 must be enabled to map the circuit IP option to the access fabric node where the DHCP discover originated.

Question 107

Refer to the exhibit.

A network engineer must improve the current IS-IS environment. The Catalyst switch is equipped with dual supervisors. Each time a stateful switchover occurs, the network experiences unnecessary route recomputation. Which solution addresses this issue if the upstream router does not understand graceful restart messaging?

Options:

A.

Enable IS-IS remote LFA FRR on both devices.

B.

Enable NSR on the switch.

C.

Enable NSF on the switch.

D.

Configure ISIS aggressive timers on both devices.

Question 108

Refer to the exhibit. A company developed an application to offer its customers and now it must be deployed. The application deployment must meet these requirements:

Options:

A.

Connect the two firewalls. Deploy the application in DC1 and DC2. Use IP SLA to control advertisements from DC2.

B.

Connect the two firewalls. Deploy the application in DC1 and DC2. Advertise the same prefix from DC1 and DC2.

C.

Deploy the application in DC1 and DC2. Advertise the prefix from DC1 with /32. Advertise the prefix from DC2 with /24.

D.

Deploy the application in DC1 and DC2. Advertise the same prefix from DC1 and DC2. Distribute traffic flows.

Question 109

Refer to the exhibit. A customer is planning to deploy a new branch in New York. The new office will not exceed 1024 users. Which subnet must be used to provide maximum number of host addresses while not providing more than necessary?

Options:

A.

192.168.8.0/21

B.

192.168.16.0/22

C.

192.168.16.0/21

D.

192.168.8.0/22

Question 110

An architect must create a QoS solution for a customer to ensure that a 40 Mbps Internet connection is shared between four subnets based on these requirements:

* Each subnet must receive no less than 10 Mbps of download bandwidth during peak traffic times.

* A subnet can use up to 40 Mbps during nonpeak traffic times if the other subnets are idle.

* Download traffic must never experience a delay.

Which solution must the architect choose?

Options:

A.

rate-limiting and shaping

B.

bandwidth percentage and policing

C.

shaping and policing

D.

bandwidth percentage and rate-limiting

Question 111

Refer to the exhibit A customer requires a Layer 2 network designed to support:

    500 active logical ports

    trunking of 30 VLANs

    convergence of less than 1 second

Which Spanning Tree Protocol must be selected?

Options:

A.

RPVST+

B.

MSTP

C.

CST

D.

PVST+

Question 112

Refer to the exhibit. An engineer is planning an IPv4 to IPv6 migration solution for a customer. The routers in the network can support IPv4 and IPv6, except for the DWDM routers. The DWDM routers provide a Layer 2 link in which the routers peer directly with each other across a DWDM circuit. The circuit also provides connectivity between the mail servers. Which IPv6 migration technique must the engineer deploy?

Options:

A.

dual-stack

B.

6to4

C.

ISATAP

D.

6rd

Question 113

An architect is designing a connectivity solution for a customer. The solution must maintain connectivity in the event of a failure of a:

    CE

    PE

    ISP

    link

Which solution must the architect choose?

Options:

A.

single multihomed

B.

single-homed

C.

dual-homed

D.

dual multihomed

Page: 1 / 28
Total 379 questions