Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Designing Cisco Enterprise Networks (ENSLD) Question and Answers

Designing Cisco Enterprise Networks (ENSLD)

Last Update Oct 19, 2025
Total Questions : 339

We are offering FREE 300-420 Cisco exam questions. All you do is to just go and sign up. Give your details, prepare 300-420 free exam questions and then go for complete pool of Designing Cisco Enterprise Networks (ENSLD) test questions that will help you more.

300-420 pdf

300-420 PDF

$40.25  $114.99
300-420 Engine

300-420 Testing Engine

$47.25  $134.99
300-420 PDF + Engine

300-420 PDF + Testing Engine

$61.25  $174.99
Questions 1

Refer to the exhibit A customer requires maximum uptime for the data plane between R1 and R3 running OSPF Which solution must the design include for high availability if the routing process on R2 requires maintenance?

Options:

A.  

BFD on all routers

B.  

nonstop forwarding on R1 and R3

C.  

nonstop forwarding on R3 only

D.  

graceful restart on all routers

Discussion 0
Questions 2

An engineer is designing a Layer 3 campus network running EIGRP between the core, aggregation, and access layers. The access layer switches will be connected to the aggregation layer using Layer 3 copper connections. The engineer wants to improve convergence time for access layer switch failures. Which technique must the design include?

Options:

A.  

enabling BFD for EIGRP on the access layer uplinks

B.  

reducing the EIGRP Hello / Hold timer values

C.  

EIGRP summarization from core to aggregation layer

D.  

EIGRP summarization from access to aggregation layer

Discussion 0
Questions 3

What is the main purpose of the Cisco SD-Access underlay design?

Options:

A.  

to enable automated network provisioning and configuration

B.  

to support advanced firewall and IPS features

C.  

to optimize network traffic routing and load-balancing

D.  

to provide network segmentation and isolation for security

Discussion 0
Questions 4

Refer to the exhibit. A customer is planning to onboard three new VPN partner connections in the data center. The new subnets must not overlap with the existing data center network, and the subnet size must not be bigger than necessary. The customer dedicated 10.1.8.0/21 for this design. Ho1// must the subnets be divided to meet these requirements?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 5

A customer requires QoS to support multimedia conferencing over MPLS. The network architect chooses to use per-hop behavior. Which solution must the architect use to classify and mark traffic traveling between branch sites?

Options:

A.  

BW Queue and DSCP WRED with DSCP AF3

B.  

BW Queue with DSCP AF3

C.  

BW Queue and DSCP WRED with DSCP AF4

D.  

BW Queue with DSCP AF4

Discussion 0
Questions 6

Refer to the exhibit An architect is designing an IPv4 plan using the 172 20 0.0/16 network The design must maximize the number of subnets and minimize the number of wasted IP addresses In addition, the plan must allocate a subnet to these customers and links

    Customer A, which supports 125 hosts

    Customer D, which supports 62 hosts

    Links B C. and E

Which two configuration sets meet these requirements'? (Choose two)

A)

B)

C)

D)

E)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 7

An engineer is tasked with designing a dual BGP peering solution with a service provider. The design must meet these conditions:

    The routers will not learn any prefix with a subnet mask greater than /24.

    The routers will determine the routes to include in the routing table based on the length of the mask alone.

    The routers will make this selection regardless of the service provider configuration.

Which solution should the engineer include in the design?

Options:

A.  

Use a route map and access list to block the desired networks, and apply the route map to BGP neighbors inbound.

B.  

Use a route map and prefix list to block the desired networks, and apply the route map to BGP neighbors outbound.

C.  

Use an IP prefix list to block the desired networks and apply the IP prefix list to BGP neighbors outbound.

D.  

Use an IP prefix list to block the desired networks and apply the IP prefix list to BGP neighbors inbound.

Discussion 0
Questions 8

An architect is working on a design to connect a company's main site to several small to medium-sized remote branches. The solution must include redundant WAN links, but the customer has a limited budget and wants the ability to increase the link speed easily in the future. QoS will not on the branch routers so there is no need for consistent end-to-end QoS. Which solution does the architect propose?

Options:

A.  

dual-homed WAN MPLS with single edge router

B.  

dual-homed Internet with a single edge router running a site-to-site VPN topology

C.  

dual-homed WAN MPLS and Internet links via dual edge routers

D.  

dual-homed Internet with dual edge routers running a hub-and-spoke VPN topology

Discussion 0
Questions 9

Refer to the exhibit. An architect is designing a BGP solution to connect a remote branch to a service provider. There are several prefixes within the branch that the company does not want to be advertised to the internet. Which solution should the architect use to accomplish this?

Options:

A.  

Set the BGP Internet community for all prefixes.

B.  

Implement the NOPEER community.

C.  

Use the BGP No-Advertise community for the prefixes to exclude.

D.  

Attach the No-Export community with the prefixes to exclude

Discussion 0
Questions 10

Currently, inter-VRF routing between the global routing table and VRF-A is accomplished on the client firewall, but the customer wants to do this on the core network layer. The customer does not want to run BGP, VRF-Lite: or static routing Which mechanism meets the requirements?

Options:

A.  

policy-based routing with the global set statement in a route map

B.  

route map that matches access lists and prefix lists with the import feature

C.  

inter-VRF can only be used on an external device with a link in each VRF

D.  

VRF receive feature under the global routing interfaces

Discussion 0
Questions 11

What is the role of a control-plane node in a Cisco SD-Access architecture?

Options:

A.  

fabric device that connects wired endpoints to the SD-Access fabric

B.  

map system that manages endpoint to device relationships

C.  

fabric device that connects APs and wireless endpoints to the SD-Access fabric

D.  

map system that manages External Layer 3 networks

Discussion 0
Questions 12

An engineer uses Postman and YANG to configure a router with:

    OSPF process ID 400

    network 192.168.128.128/25 enabled for Area 0

Which get-config reply verifies that the model set was designed correctly?

Options:

A.  

Text Description automatically generated

B.  

Text Description automatically generated

C.  

Text Description automatically generated

D.  

Text Description automatically generated with medium confidence

Discussion 0
Questions 13

What is the purpose of service routes in OMP updates?

Options:

A.  

specify routes toward a centralized orchestration plane

B.  

describe underlay transport Information

C.  

define the remote management Information

D.  

indicate services that are enabled for service insertion

Discussion 0
Questions 14

How do IETF. OpenConfig and Cisco nativo YANG models differ when used to configuro the same feature on an infrastructure device?

Options:

A.  

OpenConfig models are more comprehensive than IETF.

B.  

Cisco native models are less comprehensive than OpenConfig.

C.  

Cisco native models are less comprehensive than IETF.

D.  

IETF models are more comprehensive than OpenConfig.

Discussion 0
Questions 15

What is one function of the vSmart controller in an SD-WAN deployment?

Options:

A.  

orchestrates vEdge and cEdge connectivity

B.  

responsible for the centralized control plane of the SD-WAN network

C.  

provides centralized network management and a GUI to monitor and operate the SD-WAN overlay

D.  

provides a data-plane at branch offices to pass traffic through the SD-WAN network

Discussion 0
Questions 16

Refer to the exhibit. A company has some offices that are connected via dark fiber in New York. A network architect must optimize the network design based on the EIGRP routing protocol. The network has hierarchical addressing between 10 and 12 routers in each office. Routing convergence time must be at the minimum. What must the network architect do to reduce the query range?

Options:

A.  

Configure stub areas on non-edge routers.

B.  

Implement network summarization on edge routers.

C.  

Use different EIGRP processes on edge routers.

D.  

Configure route filtering on non-edge routers.

Discussion 0
Questions 17

A company wants to switch from static to dynamic routing. The branches use DMVPN back to the hub using two internet connections. One internet connection speed is 10 Mbps, and the other is 100 Mbps. All locations use Cisco routers; however, the branch routers have limited memory and CPU resources. Which routing protocol and design solution must the company choose for optimal traffic forwarding during peak traffic times?

Options:

A.  

iBGP with the hub routers set up as route reflectors

B.  

OSPF deployed in area 0 with branch routers connected back via virtual links

C.  

EIGRP with branch routers as stub routers and variance enabled

D.  

ISIS with the hub and spoke routers configured in two different areas

Discussion 0
Questions 18

Since installing a cisco TelePresence system, the company is experiencing other application having response issues when the system in use. As a result, the company asked an architect to recommend a QoS solution. The customer is currently using a CBWFQ policy to manage traffic on an internet connection with a speed of 100 Mbps. Which link-capacity limit must the architect choose for strict-priority for the real-time traffic?

Options:

A.  

25 Mbps

B.  

50 Mbps

C.  

33 Mbps

D.  

75 Mbps

Discussion 0
Questions 19

An engineer must design a management network for a customer's enterprise network. The design must:

    provide the ability to grant and revoke access privileges

    allow only protocols SSH, NTP, FTP, and SNMP

    restrict access to management Interfaces

Which solution must the engineer choose to meet the requirements?

Options:

A.  

in-band

B.  

enterprise internal private

C.  

out-of-band

D.  

mGRE

Discussion 0
Questions 20

A company needs to increase access port capacity on one floor of a building. They want to leverage the existing catalyst access switch. There is no problem with uplink bandwidth capacity. However, no additional uplinks can be added because no ports are available on the distribution switches. Which solution must the company choose to provide additional access ports?

Options:

A.  

VDC

B.  

VSS

C.  

Etherchannel

D.  

Stackwise

Discussion 0
Questions 21

Which common issue causes intermittent DMVPN tunnel flaps?

Options:

A.  

    a routing neighbor reachability issue

B.  

    a suboptimal routing table

C.  

    interface bandwidth congestion

D.  

    that the GRE tunnel to hub router is not encrypted

Discussion 0
Questions 22

A company requested that an architect propose a new IPv4 and IPv6 deployment strategy. The company wants a solution that is straightforward, with no information hiding or forwarding overhead. Which solution meets these requirements?

Options:

A.  

LISP

B.  

NAT64

C.  

dual-stack

D.  

GRE tunnels

Discussion 0
Questions 23

What is a feature of the SaaS subscription model?

Options:

A.  

web connection not required

B.  

access to industrial-strength storage and computing power

C.  

autonomy and control over hardware

D.  

tower initial costs

Discussion 0
Questions 24

Refer to the exhibit. A company specializing in VoD content creation has two offices in a separate multicast domain connected by a WAN link. BGP communication has been established between the offices. Clients are inside the LAN in each office. In AS5373. R2 has been selected as RP. What must the network architect design to deliver VoD content to clients in AS65773?

Options:

A.  

MSDP

B.  

PIM ASM with Auto-RP

C.  

PIM SSM

D.  

PIM ASM with BSR

Discussion 0
Questions 25

How is sub-second failure of a transport link detected in a Cisco SD-WAN network?

Options:

A.  

Hellos are sent between the WAN Edge routers and the vSmart controller.

B.  

BFD runs on the IPsec tunnels between WAN Edge routers.

C.  

BGP is used between WAN Edge routers and the vSmart controller.

D.  

Link state change messages are sent between vSmart controllers.

Discussion 0
Questions 26

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 27

Refer to the exhibit. A network engineer working for a private service provider with an employee ID: 4670:71:451 must design a BGP solution based on:

    All traffic originating from AS100 must pass through AS200 to reach the NTP and DHCP server

    When a link failure occurs between R3 and R4, traffic must follow the R2-R9 link to reach the NTP and DHCP server.

Which solution must the design include?

Options:

A.  

Routers R3 and R10 advertise an IGP metric into BGP during redistribution in both directions.

B.  

Router R6 influences the paths of R9 and R11 to the DC with a higher AS-PATH value.

C.  

Routers R3 and R10 advertise a lower local preference for outgoing traffic and a higher AS-PATH value for incoming traffic.

D.  

Router R3 applies a local preference of 200 for R1. R2. R9. and R11 routers to reach the data center.

Discussion 0
Questions 28

An engineer is designing a BGP solution supporting a VXLAN environment over a Layer 3 IPv4 network fabric with these requirements

    provide Layer 2 adjacency

    allow VM migration of workloads between sites

    IGP is OSPF

Which BGP address family must the engineer choose?

Options:

A.  

VPNv4

B.  

IPv4 unicast

C.  

L2VPN VPLS-VPWS

D.  

L2VPNEVPN

Discussion 0
Questions 29

Which component is part of the Cisco SD-Access overlay architecture?

Options:

A.  

border node

B.  

spine node

C.  

leaf node

D.  

Cisco DNA Center

Discussion 0
Questions 30

Which two techniques improve the application experience in a Cisco SD-WAN design? (Choose two.)

Options:

A.  

utilizing forward error correction

B.  

implementing a stateful application firewall

C.  

implementing AMP

D.  

utilizing quality of service

E.  

implementing Cisco Umbrella

Discussion 0
Questions 31

Refer to the exhibit. An engineer Is designing a multicampus Layer 3 Infrastructure using EIGRP as the routing protocol. The design must provide quick replies to queries In the event of a downlink, prevent unnecessary queries, and ensure that traffic does not unnecessarily transit the access layer. Which two actions must the engineer take for the network design? (Choose two.)

Options:

A.  

Configure core layer switches as stub routers.

B.  

Configure distribution layer switches to summarize routes to the core layer.

C.  

Configure access layer switches as stub routers.

D.  

Configure access layer and core layer switches as stub routers.

E.  

Configure access layer switches to summarize routes to the distribution layer.

Discussion 0
Questions 32

What is the purpose of Cisco vBond as a Session Traversal Utilities for NAT server?

Options:

A.  

allow Cisco Catalyst SD-WAN routers to locate their own mapped IP addresses

B.  

integrate Cisco SD-Access Wireless into the fabric

C.  

secure data traffic between Cisco Catalyst SD-WAN edge routers that use IPsec

D.  

provide Zero-Touch Provisioning to Cisco Catalyst SD-WAN vEdge devices

Discussion 0
Questions 33

In Cisco SD-Access. virtual networks create segmentation that allows for separation of users and resources. How is this type of segmentation described?

Options:

A.  

macro

B.  

inter-VN

C.  

micro

D.  

stretctied

Discussion 0
Questions 34

An engineer uses Postman and YANG to configure a router with:

Which get-config replay verifies that the model set was designed correctly?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 35

What is the purpose of a TLOC extension in a Cisco SD-WAN network fabric?

Options:

A.  

to facilitate WAN Edge router redundancy within a site

B.  

to identify the physical interface where a WAN Edge router connects to the WAN transport network

C.  

to expand the number of colors that are potentially applied to a network transport interface

D.  

to aggregate multiple physical interfaces into a single logical Interface

Discussion 0
Questions 36

Refer to the exhibit. A Cisco Catalyst switch is configured to.. only one MAC address to be learned manually on interface gkjO/2. Which command must be run to dynamically learn the devices that are connected to the switch port?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 37

An engineer is designing an EIGRP network for a small branch site where there is only one Layer 3 router. The engineer wants the router to advertise the local LAN network to remote EIGRP neighbors without sending any unnecessary multicast messages on the local LAN. Which action should the engineer take?

Options:

A.  

Use a static default route for this site instead of EIGRP

B.  

Advertise the local LAN using the network command and the passive-interface feature

C.  

Redistribute the local LAN network using the redistribute connected command

D.  

Advertise the local LAN subnet as a stub network

Discussion 0
Questions 38

When a network is designed using IS-IS protocol, which two circuit types are supported? (Choose two.)

Options:

A.  

nonbroadcast multiaccess

B.  

multiaccess

C.  

point-to-multipoint

D.  

nonbroadcast

E.  

point-to-point

Discussion 0
Questions 39

Refer to the exhibit. Area 10 is a regular OSPF area and networks 10.1.1.0/24 and 172.16.1.0/24 are internal. Which design provides optimal routing between both networks when the link between routers C and E fails?

Options:

A.  

Move the link between routers C and D to area 10.

B.  

Create an OSPF virtual link between routers E and F.

C.  

Create a tunnel between routers E and F in area 10.

D.  

Make area 10 a not-so-stubby area.

Discussion 0
Questions 40

An engineer must design an addressing plan for a small business using a single /24 network. Each department must have its own subnet. Drag and drop the subnets from the left onto the departments requirements that they fulfill on the right. Not all options are used.

Options:

Discussion 0
Questions 41

A customer with an IPv4 only network topology wants to enable IPv6 connectivity while preserving the IPv4 topology services. The customer plans to migrate IPv4 services to the IPv6 topology, then decommission the IPv4 topology. Which topology supports these requirements?

Options:

A.  

dual stack

B.  

6VPE

C.  

6to4

D.  

NAT64

Discussion 0
Questions 42

Refer to the exhibit. An architect must design a solution to connect the network behind R3 with the EIGRP network. Which mechanism should be included to avoid routing loops?

Options:

A.  

split-horizon

B.  

summarization

C.  

down bit

D.  

route tags

Discussion 0
Questions 43

Refer to the exhibit A customer wants to adopt a dynamic site-to-site VPN solution to secure communication for VoIP, video, and FTP traffic between the remote branches and the headquarters. The customer also wants the branches to communicate directly, thereby reducing traffic at the headquarters location. The solution must consider that the branch routers are limited in available memory. Which VPN solution meets these requirements?

Options:

A.  

DMVPN Phase 2 Hub and Spoke design

B.  

DMVPN Phase 3 Hub and Spoke design

C.  

DMVPN Phase 1 Hub and Spoke design

D.  

DMVPN Phase 3 Hierarchical design

Discussion 0
Questions 44

Refer to the exhibit.

A customer is running HSRP on the core routers. Over time the company has grown and requires more

network capacity. In the current environment, some of the downstream interfaces are almost fully utilized, but

others are not. Which solution improves the situation?

Options:

A.  

Make router R2 active for half of the VLANs.

B.  

Add more interfaces to R1 and R2.

C.  

Configure port channel toward downstream switches.

D.  

Enable RSTP on the downstream switches.

Discussion 0
Questions 45

Which solution allows overlay VNs to communicate with each other in an SD-WAN Architecture?

Options:

A.  

External fusion routers can be used to map VNs to VRFs and selectively route traffic between VRFs.

B.  

GRE tunneling can be configured between fabric edges to connect one VN to another.

C.  

SGTs can be used to permit traffic from one VN to another.

D.  

Route leaking can be used on the fabric border nodes to inject routes from one VN to another.

Discussion 0
Questions 46

Refer to the exhibit. Customers report low video quality and delays when having point-to-point telepresence video calls between the two locations. An architect must optimize a design so that traffic follows the same path for egress and ingress traffic flows. Which technique optimizes the design?

Options:

A.  

Configure route leaking on the router in area 2.

B.  

Configure route leaking on the router in area 1.

C.  

Configure the high metric on the router in area 4.

D.  

Configure route filter on the router in area 4.

Discussion 0
Questions 47

Which type of rendezvous point deployment is standards-based and supports dynamic RP discovery?

Options:

A.  

bootstrap router

B.  

Anycast-RP

C.  

Auto-RP

D.  

static RP

Discussion 0
Questions 48

Drag and drop the characteristics from the left onto the YANG models they describe on the right. Not all options are used.

Options:

Discussion 0
Questions 49

Refer to the exhibit.

An engineer must optimize the traffic flow of the network. Which change provides a more

efficient design between the access and the distribution layer?

Options:

A.  

Add a link between access switch A and access switch B

B.  

Reconfigure the distribution switch A to become the HSRP Active

C.  

Change the link between distribution switch A and distribution switch B to be a routed link

D.  

Create an EtherChannel link between distribution switch A and distribution switch B

Discussion 0
Questions 50

Refer to the exhibit. An engineer is designing a BGP solution for a client that peers with ISP1 for full Internet connectivity and with ISP2 for direct exchange of routes for several third parties. Which action, when implemented on the edge routers, enables the client network to reach the Internet through ISP1?

Options:

A.  

Run an eBGP session within different VRFs for each ISP.

B.  

Advertise a default route for downstream routers within the client network.

C.  

Apply the AS-path prepend feature for ISP2.

D.  

Apply route filtering such that the client advertises only routes originated from its own AS.

Discussion 0
Questions 51

An engineer is designing a campus network with Cisco Catalyst 95CO switches in the aggression layer. The design requires running nonblocking Layer 2 MEC from the aggregation layer to the access layer. The Catalyst switches are located on different campus floors for availability reasons, and each access switch veil contam a single VLAN. Which technology must the engineer choose for the aggregation switches in the design?

Options:

A.  

VPC

B.  

VSS

C.  

StackWise Virtual

D.  

StackWise-180

Discussion 0
Questions 52

Which feature minimizes TLOC connections and reduces strain on the vSmart controller in an SD-WAN architecture?

Options:

A.  

control-direction

B.  

affinity

C.  

color

D.  

control-connections

Discussion 0
Questions 53

An engineer is designing an IPv4 addressing plan for an enterprise with 1000 branches. Each branch requires a prefix for data and a prefix for voice. Each prefix must accommodate up to 128 hosts, and prefixes must facilitate summarization at aggregation points in the network. The security team requires a simple method for identifying voce prefixes. Which allocation does the engineer recommend from the RFC1918 address space?

Options:

A.  

/24 prefixes for data from 10.0.0.0/15 and /24 prefixes for voice from 172.16.0.0/15

B.  

/24 prefixes for data from 10.0.0.0/8 and /24 prefixes for voice from the next contiguous /24 prefix per site

C.  

/25 prefixes for data from 10.0.0.0/8 end /25 prefixes for voice from the next contiguous /25 prefix per branch

D.  

/24 prefixes for data from 10.0.0.0/8 and /24 prefixes for voice from 172.16.0.0/12

Discussion 0
Questions 54

Drag and drop the types of WAN connectivity from the left onto the connectivity use cases on the right.

Options:

Discussion 0
Questions 55

Refer to the exhibit. The full EIGRP routing table is advertised throughout the network. Currently, users experience data loss when any one link in the network fails. An architect optimizes the network to reduce the impact when a link fails. Which solution should the architect include in the design?

Options:

A.  

Run BFD on the inter links between EIGRP neighbors.

B.  

Summarize the access layer networks from each access layer switch toward the aggregation layer.

C.  

Reduce the default EIGRP hello interval and hold time.

D.  

Summarize the access layer networks from the aggregation layer toward the core layer.

Discussion 0
Questions 56

How do endpoints inside an SD-Access network reach resources outside the fabric?

Options:

A.  

a VRF fusion router is used to map resources in one VN to another VN

B.  

Fabric borders use VRFs to map VNs to VRFs

C.  

SD-Access transit links are used to transport encapsulated traffic from one fabric to another

D.  

A fabric edge is used to de-encapsulate VXLAN traffic to normal IP traffic then transported over the outside network

Discussion 0
Questions 57

An engineer must design a QoS solution for a customer. The network currently supports data only, but the

customer will roll out VoIP and IP video in conjunction with the new QoS solution. The engineer plans to use

DiffServ. To ensure priority for voice services, which model must the design include?

Options:

A.  

8-class model

B.  

4-class model

C.  

6-class model

D.  

12-class model

Discussion 0
Questions 58

An engineer is designing a PIM Anycast RP solution between two data centers. The design must ensure that RP1 in DC1 and RP2 in DC2 inform each other about specific sources that have joined locally. Which solution must the engineer choose?

Options:

A.  

Provision the RPs on the same IP subnet and extend the subnet at Layer 2 between data centers

B.  

Enable MSDP between RPs using separate unique loopback interfaces

C.  

Enable MSDP between RPs using the configured Anycast RP address

D.  

No action is required because PIM registers from the source will, by default, reach each RP

Discussion 0
Questions 59

A company is using OSPF between its HQ location and a branch office. HQ is assigned area 0 and the branch office is assigned area 1. The company purchases a second branch office, but due to circuit delays to HQ, it

decides to connect the new branch office to the creating branch office as a temporary measure. The new branch office is assigned area 2. Which OSPF configuration enables all three locations to exchange routes?

Options:

A.  

The existing branch office must be configured as a stub area

B.  

A virtual link must be configured between the new branch office and HQ

C.  

A sham link must be configured between the new branch office and HQ

D.  

The new branch office must be configured as a stub area

Discussion 0
Questions 60

An engineer is looking for a standards-driven YANG model to manage a multivendor network environment. Which model must the engineer choose?

Options:

A.  

Native

B.  

OpenConfig

C.  

IETF

D.  

IEEE NETCONF

Discussion 0
Questions 61

Which feature provides the capability for intra-VN traffic filtering and control within the Cisco SO-Access architecture?

Options:

A.  

scalable groups

B.  

MAC ACL

C.  

prefix list

D.  

service policy

Discussion 0
Questions 62

A network engineer is redesigning a company's QoS solution. The company is currently using IP Precedence, but the engineer plans to move to DiffServ. It is important that the new solution provide backward compatibility with the current solution. Which technology should the design include?

Options:

A.  

expedited forwarding

B.  

assured forwarding

C.  

class selector code points

D.  

default per hop behavior

Discussion 0
Questions 63

Drag and drop the characteristics from the left onto the correct telemetry mode on the right.

Options:

Discussion 0
Questions 64

Which information update is carried by OMP and enables the Cisco SD-WAN to build a secure overlay fabric on top of any public or private transport without regard for the actual link IP?

Options:

A.  

TLOC

B.  

RLOC

C.  

LISP PITR

D.  

DTLS

Discussion 0
Questions 65

Refer to the exhibit. An architect must design an OSPF solution for an enterprise customer. The design must meet these requirements:

·Limit the link flap impact to Area-1 and Area-2.

·Any link failure must have minimal impact on voice and video traffic.

·Which two OSPF solutions must the architect include in the design? (Choose two.)

Options:

A.  

Reduce the frequency of OR and BOR elections.

B.  

increase hello and how timer.

C.  

Tune LSA and SPF throttling timers

D.  

Enable manual route summarization and configure all nonbackbone areas as stub networks.

E.  

Advertise default routes from the backbone to nonbackone areas.

Discussion 0
Questions 66

Refer to the exhibit.

An architect must design an IPv6 migration solution for an enterprise customer to support these requirements:

* Clients will transition to the new IPv6 network, which provides NAT64 and IPv6 DNS resolution services, using the same DNS name that points to the IPv4 address.

* The service provider will create a client-facing IPv6 interface with a new IPv6 virtual address that points to the same IPv4 DNS server.

* The service provider will support clients that use global IPv6 addresses and encapsulate IPv4 packets into IPv6 tunnels.

Which two migration solutions must the architect choose? (Choose two.)

Options:

A.  

Use dual-stack lite from the MPLS network to the IGR.

B.  

Use IPv6 tunneling from the devices to the core MPLS network.

C.  

Use dual-stack lite from the devices to the core MPLS network.

D.  

Use NAT44/64 from the MPLS network to the IGR.

E.  

Use NAT44/64 from the devices to the core MPLS network.

Discussion 0
Questions 67

Refer to the exhibit. An architect must ensure a convergence time of 200 ms or less during a link failure within area 0. In addition, the solution must not impact the overall performance of the network. Which solution must the architect select?

Options:

A.  

UDLD

B.  

BFD

C.  

fast hellos

D.  

carrier delay

Discussion 0
Questions 68

In an SD-WAN architecture, which methods are used to bootstrap a vEdge router?

Options:

A.  

DHCP options or manual configuration

B.  

vManage or DNS records

C.  

ZTP or manual configuration

D.  

DNS records or DHCP options

Discussion 0
Questions 69

Drag and drop the characteristics from the left onto the telemetry mode they apply to on the right.

Options:

Discussion 0
Questions 70

Exhibit:

Options:

A.  

Make R3 an L1L2 router.

B.  

Make R31 an L1 router.

C.  

Make Area 0 L2-only.

D.  

Make R11 an L2 router.

Discussion 0
Questions 71

An engineer is creating a design to enable IPv6 to run on an existing IPv4 IS-IS network. The IPv4 and IPv6 topologies will match exactly, and the engineer plans to use the same router levels for each protocol per interface. Which IS-IS design is required?

Options:

A.  

single topology without enabling transition feature

B.  

single topology with transition feature enabled

C.  

multi topology with transition feature enabled

D.  

multi topology without enabling transition feature

Discussion 0
Questions 72

How does a model-driven telemetry dial-out approach function?

Options:

A.  

The device initiates a session to the collector based on the subscription.

B.  

The collector initiates a session to the device and subscribes to data to be streamed.

C.  

The collector Initiates a session to the device and gets the data of a previously defined subscription.

D.  

The device initiates a session to the collector and negotiates a subscription.

Discussion 0
Questions 73

An engineer must design a solution to connect a customer to the Internet. The solution will include a Layer 3 circuit with a CIR of 50 Mbps from the service provider. The hand-off from the provider's switch to the customer's router is 1Gbps. Which solution should the engineer include to prevent potential issues with choppy voice traffic?

Options:

A.  

Reduce the bandwidth of the connection to the router.

B.  

Implement hierarchical QoS with a parent policing policy.

C.  

Implement hierarchical QoS with a parent shaping policy.

D.  

Add a bandwidth statement to the router interface.

Discussion 0
Questions 74

Refer to the exhibits. An engineer is troubleshooting an issue in which the Gig0/2 interface on a Cisco switch named SW2 fails to become the root port. Which two commands must be run on SW2 to resolve this issue? (Choose two.)

A)

B)

C)

D)

E)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

E.  

Option E

Discussion 0
Questions 75

An engineer is working with NETCONF and Cisco NX-OS based devices. The engineer needs a YANG model that supports a specific feature relevant only to Cisco NX-OS. Which model must the engineer choose?

Options:

A.  

Native

B.  

IEEE

C.  

OpenConfig

D.  

IETF

Discussion 0
Questions 76

An engineer must establish a direct connection between two remote offices. The new connection must be established using a logical path, share a common broadcast domain, connect over private WAN, and have as little overhead as possible. Which technology must the engineer choose?

Options:

A.  

L2VPN

B.  

GET VPN

C.  

IPsec

D.  

GRE

Discussion 0
Questions 77

Which two considerations must be made regarding the overlay network for a Cisco SD-Access architecture? (Choose two.)

Options:

A.  

Virtual networks should be used for microsegmentation

B.  

SGTs should be used for data plane isolation and microsegmentation

C.  

Virtual networks should be used for data plane isolation only

D.  

Overlapping IP addresses across different overlay networks should be used to conserve IP addresses

E.  

Overlapping IP addresses across different overlay networks should be avoided for operational simplicity

Discussion 0
Questions 78

An engineer is upgrading a company’s main site to include a connection to a second ISP. The company will receive full Internet routing tables from both ISPs via BGP. The engineer must ensure that the company does not become a transit autonomous system. Which solution should be included in this design?

Options:

A.  

Tag incoming routes from both ISPs with BGP community no-export.

B.  

Lower the MED for updates sent to the secondary ISP.

C.  

Use a route-map to prevent all prefixes from being advertised to either ISP.

D.  

Modify the local-preference for routes incoming from the primary ISP.

Discussion 0
Questions 79

Refer to the exhibit.

The failover time of ISP-2 is significantly shorter than ISP-1 when an interface on the ISP router toward the campus network fails. Which solution minimizes the downtime to the sub-second?

Options:

A.  

Aggressive timers

B.  

Next-hop address tracking

C.  

Graceful-restart

D.  

BFD

Discussion 0
Questions 80

Company A recently acquired another company. Users of the newly acquired company must be able to access a server that exists on Company A’s network, both companies use overlapping IP address ranges. Which action conserves IP address space and provides access to the server?

Options:

A.  

Use a single IP address to create overload NAT

B.  

Use a single IP address to create a static NAT entry

C.  

Build one-to-one NAT translation for every user that needs access

D.  

Re-IP overlapping address space in the acquired company

Discussion 0
Questions 81

Which protocol is deployed through LAN automation to build node-to-node underlay adjacencies in SDA?

Options:

A.  

IS-IS

B.  

OLISP

C.  

OSPF

D.  

VXLAN

Discussion 0
Questions 82

Refer to the exhibit. An architect working for a service provider with an employee ID: 4763:44:876 must design a Layer 2 VPN solution that supports:

    transparency of service provider devices

    direct communication between CE routers attached to the same VLAN

Which solution must the design include?

Options:

A.  

multiple VPWS

B.  

single VPLS

C.  

single VPWS

D.  

multiple VPLS

Discussion 0
Questions 83

Which OSPF area blocks LSA Type 3, 4 and 5, but allows a default summary route?

Options:

A.  

normal

B.  

stub

C.  

NSSA

D.  

totally stubby

Discussion 0
Questions 84

Which security functionality does gRPC provide?

Options:

A.  

implementing secure server-client tunnels with RSA 20*8 cipher encryption

B.  

mandatory encryption of data at rest using the AES and RSA protocols

C.  

enabling RC6 data-level encryption with CRC check

D.  

supporting secure communication between network devices and control systems using TLS

Discussion 0
Questions 85

What is the purpose of an edge node in an SD-Access network fabric?

Options:

A.  

Edge nodes identify and authenticate endpoints and register endpoint information with control plane nodes.

B.  

Edge nodes track endpoint IDs to location mappings, along with IPv4, IPv6, or MAC addresses.

C.  

Edge nodes are the gateway between the fabric domain and network outside of the fabric.

D.  

Edge nodes resolve lookup requests from edge and border nodes to locate destination endpoint IDs.

Discussion 0
Questions 86

A network administrator is troubleshooting a DMVPN setup between the hub and the spoke. Which action should the administrator take before troubleshooting the IPsec configuration?

Options:

A.  

    Verify the GRE tunnels.

B.  

    Verify ISAKMP.

C.  

    Verify NHRP.

D.  

    Verify crypto maps.

Discussion 0
Questions 87

An engineer is designing a QoS solution for a campus. The design must guarantee real-time traffic delivery during congestion, minimize the bandwidth consumption for possible virus or worm attacks, and reduce flooding of excessive traffic during times of congestion. Which two solutions must the engineer select? (Choose two.)

Options:

A.  

Create a shaping policy to drop excessive traffic and a strict queue for real-time traffic.

B.  

Apply queuing on the distribution to core links

C.  

Create a policing policy to drop excessive traffic and a strict queue for real-time traffic.

D.  

Create a scavenger queue for excessive traffic and a strict queue for real-time traffic

E.  

Apply queuing on the access to distribution links.

Discussion 0
Questions 88

Refer to the exhibit.

An architect is designing a network for a customer supporting a Wake-on-LAN application. Which solution must the architect choose?

Options:

A.  

IP directed-broadcasts on R1

B.  

spanning-tree uplinkfast on SW1

C.  

spanning-tree uplinkfast on SW2

D.  

IP directed-broadcasts on R2

Discussion 0
Questions 89

In a cisco SD-Access brownfield deployment scenario, which configuration deployment must be taken with Cisco DNA center?

Options:

A.  

Subnet stretching

B.  

LAN automation

C.  

Automated UNDERLAY

D.  

Manual underlay

Discussion 0
Questions 90

A customer’s environment includes hosts that support IPv6-only. Several of these hosts must communicate with a public web server that has only IPv4 domain name resolution. Which solution should the customer use in this environment?

Options:

A.  

utilize NAT64 to translate the addresses

B.  

Implement NAT44 at the edge of the customer network

C.  

use 6to4 and a tunnel to translate the addresses

D.  

implement 6PE to resolve hostname resolution

Discussion 0
Questions 91

An architect is creating a migration strategy for a large organization in which the choice made by the application between IPv6 and IPv4 is based on the DNS request. Which migration strategy does the architect choose?

Options:

A.  

AFT for public web presence

B.  

host-initiated tunnels

C.  

dual stack

D.  

site-to-site IPv6 over IPv4 tunnels

Discussion 0
Questions 92

Refer to the exhibit. A network engineer must design a BGP solution based on:

    The route reflector must have one or more direct physical connections to the core routers (R3 and R4).

    The route reflector must have full redundancy and avoid a single point of failure.

    R2 to R1 link utilization is 90%. and the remaining links are less than 50% utilized.

Which two solutions must the design Include? (Choose two.)

Options:

A.  

Configure R1 to be a client of R2 and R4.

B.  

Configure R2 to be a client of R1 and R4.

C.  

Configure R3 to be a client of R2 and R4.

D.  

Configure R4 to be a client of R1 and R3.

E.  

Configure R5 to be a client of R3 and R4.

Discussion 0
Questions 93

A client is moving to Model-Driven Telemetry and requires periodic updates. What must the network architect consider with this design?

Options:

A.  

Updates that contain changes within the data are sent only when changes occur.

B.  

Empty data subscriptions do not generate empty update notifications.

C.  

Periodic updates include a full copy of the data that is subscribed to.

D.  

The primary push update is sent immediately and cannot be delayed.

Discussion 0
Questions 94

An architect is designing a network solution for a customer The network is IPv6-only with 1000 hosts. The design must provide external access to up to 10 concurrent IPv6 hosts to allow communication with legacy IPv4 devices on an adjacent network. The customer set aside 10 IPv4 addresses to allow for one-to-one communication between hosts. Which solution must the architect select?

Options:

A.  

stateful NAT64

B.  

static NAT-PT

C.  

dynamic NPTv6

D.  

dynamic NAT-PT

Discussion 0
Questions 95

Which nonproprietary mechanism can be used to automate rendezvous point distribution in a large PIM domain?

Options:

A.  

Embedded RP

B.  

BSR

C.  

Auto-RP

D.  

Static RP

Discussion 0
Questions 96

Exhibit:

Refer to the exhibit. An engineer is designing a Layer 2 campus network. The design must support fast convergence and leverage as much bandwidth as possible between layers. Distribution switches do support VSS; unfortunately, not all routing protocols are available for use due to license limitations. Which solution must the engineer choose?

Options:

A.  

EtherChannel

B.  

MEC

C.  

RSTP

D.  

ECMP

Discussion 0
Questions 97

Which function does the Cisco SD-Access intermediate node perform?

Options:

A.  

Act as LISP proxy tunnel router.

B.  

Route and transport IP traffic.

C.  

Act as an anycast Layer 3 gateway.

D.  

Map users to a virtual network.

Discussion 0
Questions 98

Refer to the exhibit.

An engineer is designing a routing solution for a customer. The design must ensure that a failure of network

10.1.0.0/24, 10.1.2.0/24, 10.2.1.0/24, or 10.2.3.0/24 does not impact the core. It also requires fast convergence

time during any link failover in the core or access networks. Which solution must the engineer select?

Options:

A.  

Add aggregation layer between core and access networks.

B.  

Enable graceful restart on routers A and C.

C.  

Enable FRR for the connected networks of routers A and

C.  

D.  

Enable summarization on routers A and C.

Discussion 0
Questions 99

Refer to the exhibit. A network engineer is designing an OSPF solution to connect a company's remote to a newly provisioned MPLS VPN backbone. Some of the branches have a direct dark fiber connection between each other. The engineer wants to ensure that the dark fibers are used only when the MPLS core is unavailable. Which solution must the engineer choose?

Options:

A.  

Stub area

B.  

Sham link

C.  

Virtual link

D.  

NSSA

Discussion 0
Questions 100

Which feature minimizes HOC connections and reduces strain on the vSmart controller m an SO-WAN architecture?

Options:

A.  

control-connections

B.  

corrtroWirection

C.  

color

D.  

affinity

Discussion 0
Questions 101

Which two functions does the control plane node provide in a Cisco SD-Access architecture? (Choose two.)

Options:

A.  

LISP proxy ETR

B.  

host tracking database

C.  

policy mapping

D.  

map server

E.  

endpoint registration

Discussion 0