Pre-Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Cisco Certified Design Expert (CCDE v3.1) Question and Answers

Cisco Certified Design Expert (CCDE v3.1)

Last Update May 30, 2026
Total Questions : 503

We are offering FREE 400-007 Cisco exam questions. All you do is to just go and sign up. Give your details, prepare 400-007 free exam questions and then go for complete pool of Cisco Certified Design Expert (CCDE v3.1) test questions that will help you more.

400-007 pdf

400-007 PDF

$139.65  $399
400-007 Engine

400-007 Testing Engine

$157.15  $449
400-007 PDF + Engine

400-007 PDF + Testing Engine

$209.65  $599
Questions 1

While reviewing an existing network design, you are discussing the characteristics of different STP versions. Which protocol minimizes unicast flooding during a Topology Change Notification in a Layer 2 switched network with many VLANs?

Options:

A.  

PVRSTP

B.  

MST

C.  

STP

D.  

PVSTP+

Discussion 0
Questions 2

Which two statements describe network automation and network orchestration? (Choose two.)

Options:

A.  

Network automation does not provide governance or policy management.

B.  

Network automation spans multiple network services, vendors, and environments.

C.  

Network orchestration is done through programmatic REST APIs enabling automation across devices and management platforms.

D.  

Provisioning network services is an example of network automation.

E.  

Network orchestration is used to run single, low-level tasks without human intervention.

Discussion 0
Questions 3

Company XYZ has 30 sites using MPLS L3 VPN and is concerned about data integrity. They want a centralized configuration model and minimal overhead. Which technology can be used?

Options:

A.  

S-VTI

B.  

DMVPN

C.  

MGRE

D.  

GET VPN

Discussion 0
Questions 4

An enterprise requires MPLS-connected branches to access cloud-based Microsoft 365 services over an SD-WAN solution. Internet access is available only at dual regional hub sites that are connected to the MPLS network. Which connectivity method provides an optimum access method to the cloud-based services if one ISP suffers loss or latency?

Options:

A.  

Cloud onRamp gateway site

B.  

Cloud onRamp SWG

C.  

Cloud onRamp

D.  

Cloud onRamp SaaS

Discussion 0
Questions 5

As network designer, which option is your main concern with regards to virtualizing multiple network zones into a single hardware device?

Options:

A.  

Fate sharing

B.  

CPU resource allocation

C.  

Congestion control

D.  

Security

E.  

Bandwidth allocation

Discussion 0
Questions 6

A large enterprise cloud design team is evaluating cloud consumption models. What is an example of a typical PaaS limitation or concern?

Options:

A.  

Vendor lock-in

B.  

Runtime issues

C.  

Lack of control

D.  

Multi-tenant security

Discussion 0
Questions 7

What is a disadvantage of the traditional three-tier architecture model when east-west traffic between different pods must go through the distribution and core layers?

Options:

A.  

Low bandwidth

B.  

Security

C.  

Scalability

D.  

High latency

Discussion 0
Questions 8

A European national bank considers migrating its on-premises systems to a private cloud offering in a non-European location to significantly reduce IT costs. What is a primary factor prior to migration?

Options:

A.  

data governance

B.  

additional latency

C.  

security

D.  

cloud connectivity

Discussion 0
Questions 9

A product manufacturing organization is integrating cloud services into their IT solution. The IT team is working on the preparation phase of the implementation approach, which includes the Define Strategy step. This step defines the scope of IT, the application, and the service. What is one topic that should be considered in the Define Strategy step?

Options:

A.  

Financial and governance models

B.  

Innovate and align with business according to volume

C.  

Due diligence and financial scenarios

D.  

Contingency exit strategy steps

Discussion 0
Questions 10

Drag lhe components that are part of the CIA triad to the correct target on the right. Not all components are used.

Options:

Discussion 0
Questions 11

Network orchestration enables network administrators to focus on strategic initiatives, innovation, and value-added tasks rather than spending time on manual and repetitive network management activities. Drag and drop the orchestration types from the left onto the corresponding functions on the right. Not all options are used.

Options:

Discussion 0
Questions 12

Which two control plane policer designs must be considered to achieve high availability? (Choose two.)

Options:

A.  

Control plane policers are enforced in hardware to protect the software path, but they are hardware platform dependent in terms of classification ability.

B.  

Control plane policers are really needed only on externally facing devices.

C.  

Control plane policers can cause the network management systems to create false alarms.

D.  

Control plane policers must be processed before a forwarding decision is made.

E.  

Control plane policers require that adequate protocol overheads are factored in to allow protocol convergence.

Discussion 0
Questions 13

What is the primary benefit for an organization that dynamically can expand their private cloud capacity by allocating additional compute and/or storage resources using a third-party service provider or partner?

Options:

A.  

traffic engineering

B.  

business agility

C.  

policy enforcement

D.  

traffic encapsulation

Discussion 0
Questions 14

Refer to the exhibit.

This network is running EIGRP as the routing protocol and the internal networks are being advertised in EIGRP. Based on the link speeds, all traffic between London and Rome is getting propagated via Barcelona and the direct link between London and Rome is not being utilized under normal working circumstances. The EIGRP design should allow for efficiency in the routing table by minimizing the routes being exchanged. The link between London and Rome should be utilized for specific routes. Which two steps accomplish this task? (Choose two.)

Options:

A.  

Configure EIGRP route summarization on all the interfaces to summarize the internal LAN routes

B.  

Filter the routes on the link between London and Barcelona

C.  

Filter the routes on the link between London and Rome

D.  

Configure route leaking of summary routes on the link between London and Rome

Discussion 0
Questions 15

You are designing a network for a branch office. In order to improve convergence time, you are required to use the BFD feature. Which four routing protocols can you use to facilitate this? (Choose four.)

Options:

A.  

IS-IS

B.  

static

C.  

RIP

D.  

EIGRP

E.  

BGP

Discussion 0
Questions 16

Drag and drop the high-level descriptions of network automation and network orchestration on the left to the corresponding category on the right in no particular order.

Options:

Discussion 0
Questions 17

Refer to the exhibit.

An engineer is designing the traffic flow for AS 111. Traffic from AS 111 should be preferred via AS 100 for all external routes. A method must be used that only affects AS 111. Which BGP attributes are best suited to control outbound traffic?

Options:

A.  

community

B.  

MED

C.  

local preference

D.  

AS path

Discussion 0
Questions 18

With virtualization applied throughout the network, every physical link may carry one or more virtual links. What is a key drawback of this?

Options:

A.  

Unneeded tunneling

B.  

Fate sharing

C.  

Bandwidth utilization

D.  

Serialization delay

Discussion 0
Questions 19

What is a web-based model in which a third-party provider hosts applications that are available to customers over the Internet?

Options:

A.  

PaaS

B.  

SaaS

C.  

IaaS

D.  

WaaS

Discussion 0
Questions 20

You are designing a large-scale DMVPN network with more than 500 spokes using EIGRP as the IGP protocol. Which design option eliminates potential tunnel down events on the spoke routers due to the holding time expiration?

Options:

A.  

Increase the hold queue on the physical interface of the hub router

B.  

Increase the hold queue on the tunnel interface of the spoke routers

C.  

Increase the hold queue on the tunnel interface of the hub router

D.  

Apply QoS for pak_priority class

E.  

Increase the hold queue on the physical interface of the spoke routers

Discussion 0
Questions 21

Router R1 is a BGP speaker with one peering neighbor over link " A " . When link " A " fails, routing announcements are terminated, which results in the tearing down of the state for all BGP routes at each end of the link. What is this a good example of?

Options:

A.  

Fault isolation

B.  

Resiliency

C.  

Redundancy

D.  

Fate sharing

Discussion 0
Questions 22

When constraint-based routing is under consideration to be added to a network design, what are two inherent characteristics or impacts that must be considered? (Choose two)

Options:

A.  

better network utilization

B.  

stability in the route table

C.  

high computation overhead

D.  

smaller routing table size

E.  

less resources than the shortest path

Discussion 0
Questions 23

A customer migrates from a traditional Layer 2 data center network into a new SDN-based spine-and-leaf VXLAN EVPN data center within the same location. The networks are joined to enable host migration at Layer 2. What is the final migration step after hosts have physically migrated to have traffic flowing through the new network without changing any host configuration?

Options:

A.  

Shut down legacy Layer 3 SVIs, clear ARP caches on all hosts being migrated, and then configure the legacy VRRP address onto new VXLAN core switches

B.  

Increase VRRP priorities on new infrastructure over legacy VRRP values, then shut down legacy SVIs

C.  

Shut down legacy infrastructure to allow VXLAN gateways to become active

D.  

Shut down legacy Layer 3 SVIs and activate new preconfigured Layer 3 SVIs on VXLAN

Discussion 0
Questions 24

Which best practice ensures data security in the private cloud?

Options:

A.  

Use IPsec for communication between unsecured network connection

B.  

Encrypt data at rest and in transition.

C.  

Use the same vendor for consistent encryption.

D.  

Anonymize data ownership to comply with privacy rules.

Discussion 0
Questions 25

Which three tools are used for ongoing monitoring and maintenance of a voice and video environment? (Choose three.)

Options:

A.  

Flow-based analysis to measure bandwidth mix of applications and their flows

B.  

Call management analysis to identify network convergence-related failures

C.  

Call management analysis to identify CAC failures and call quality issues

D.  

Active monitoring via synthetic probes to measure loss, latency, and jitter

E.  

Passive monitoring via synthetic probes to measure loss, latency, and jitter

F.  

Flow-based analysis with PTP time-stamping to measure loss, latency, and jitter

Discussion 0
Questions 26

: 477

An organization is working on a design solution for a new Internet-based remote access virtual private network that has 1000 remote sites. A network administrator recommends GETVPN as the model What is a potential problem of using GETVPN in this situation?

Options:

A.  

GETVPN is not scalable to a large number of remote sites

B.  

GETVPN key servers would be on public hacker-reachable space and need higher security

C.  

GETVPN and DMVPN do not interoperate

D.  

GETVPN requires a high level of background traffic to maintain its IPsec SAs

Discussion 0
Questions 27

Which solution component helps to achieve rapid migration to the cloud for SaaS and public cloud leveraging SD-WAN capabilities?

Options:

A.  

Service-oriented cloud architecture

B.  

Cloud OnRamp

C.  

Cloud registry

D.  

Microservices in the cloud

Discussion 0
Questions 28

Company XYZ wants to redesign the Layer 2 part of their network and wants to use all available uplinks for increased performance They also want to have end host reachability supporting conversational learning However, due to design constraints, they cannot implement port-channel on the uplinks Which other technique can be used to make sure the uplinks are in active/active state?

Options:

A.  

switch stack

B.  

LISP

C.  

MSTP

D.  

TRILL

Discussion 0
Questions 29

Refer to the exhibit.

Refer to the exhibit. A new high availability DB server cluster is installed in the network. These two servers require high bandwidth and low latency Layer 2 connectivity for database replication.

Which solution supports these requirements?

Options:

A.  

Add two new links between SW1 and SW2 configured as LACP trunk with STP

B.  

Add secondary links to REP segments 1 and 2

C.  

Add two new links between SW1 and SW2 configured as REP segment 3

D.  

Add two new links between SW1 and SW2 configured as REP segments 1 and 2 respectively

Discussion 0
Questions 30

Which hybrid cloud environment enables businesses to more readily stage data-intensive and time-sensitive tasks closer to the source, which reduces latency, eases networking requirements, and improves data protection?

Options:

A.  

edge computing

B.  

application migration

C.  

digital transformation

D.  

distributed data processing

Discussion 0
Questions 31

A customer has a functional requirement that states HR systems within a data center should be segmented from other systems that reside in the same data center and same VLAN. The systems run legacy applications by using hard-coded IP addresses. Which segmentation method is suitable and scalable for the customer?

Options:

A.  

Data center perimeter firewalling

B.  

VACLs on data center switches

C.  

Transparent firewalling

D.  

Routed firewalls

Discussion 0
Questions 32

Which two protocols are used by SDN controllers to communicate with switches and routers? (Choose two.)

Options:

A.  

OpenFlash

B.  

OpenFlow

C.  

NetFlash

D.  

Open vSwitch Database

E.  

NetFlow

Discussion 0
Questions 33

SDN emerged as a technology trend that attracted many industries to move from traditional networks to SDN. Which challenge is solved by SDN for cloud service providers?

Options:

A.  

Need for intelligent traffic monitoring

B.  

Exponential growth of resource-intensive applications

C.  

Complex and distributed management flow

D.  

Higher operating expense and capital expenditure

Discussion 0
Questions 34

Which main IoT migration aspect should be reviewed for a manufacturing plant?

Options:

A.  

Sensors

B.  

Security

C.  

Applications

D.  

Wi-Fi Infrastructure

E.  

Ethernet Switches

Discussion 0
Questions 35

In the wake of a security compromise incident where the internal networks were breached by an outside attacker at the perimeter of the infrastructure, an enterprise is now evaluating potential measures that can help protect against the same type of incident in the future. What are two design options that can be employed? (Choose two)

Options:

A.  

microzoning

B.  

segmentation

C.  

domain fencing

D.  

virtualization

E.  

microperimeters

Discussion 0
Questions 36

Company XYZ allows employees to use any open desk and plug their laptops in. They want authentication using domain credentials and future capability for segmentation within the same subnet. Which protocol can be recommended?

Options:

A.  

LDAP

B.  

EAP

C.  

TACACS+

D.  

RADIUS

Discussion 0
Questions 37

Which aspect of BGP-LS makes it scalable in large network when multiarea topology information must be gathered?

Options:

A.  

transmit flow control

B.  

TCP-based flow control

C.  

open-loop flow control

D.  

hardware flow control

Discussion 0
Questions 38

A business requirement stating that failure of WAN access for dual circuits into an MPLS provider for a Data Centre cannot happen due to related service credits that would need to be paid has led to diversely routed circuits to different points of presence on the provider’s network. What should a network designer also consider as part of the requirement?

Options:

A.  

Provision of an additional MPLS provider

B.  

Out of band access to the MPLS routers

C.  

Ensuring all related remote branches are dual-homed to the MPLS network

D.  

Dual PSUs and Supervisors on each MPLS router

Discussion 0
Questions 39

Which two benefits can software-defined networks provide to businesses? (Choose two.)

Options:

A.  

Provides additional redundancy

B.  

Decentralized management

C.  

Reduced latency

D.  

Enables innovation

E.  

Reduction of OpEx/CapEx

F.  

Meets high traffic demands

Discussion 0
Questions 40

You are designing a network running both IPv4 and IPv6 to deploy QoS. Which consideration is correct about the QoS for IPv4 and IPv6?

Options:

A.  

IPv4 and IPv6 traffic types can use queuing mechanisms such as LLQ, PQ, and CQ.

B.  

IPv6 packet classification is only available with process switching, whereas IPv4 packet classification is available with both process switching and CEF.

C.  

IPv6 and IPv4 traffic types can use a single QoS policy to match both protocols.

D.  

Different congestion management mechanisms need to be used for IPv4 and IPv6 traffic types.

Discussion 0
Questions 41

Which two compliance audit functions are useful to meet business requirements? (Choose two.)

Options:

A.  

risk prevention

B.  

advise auditing

C.  

audit monitoring

D.  

risk identification audit resolution

Discussion 0
Questions 42

Which function is performed at the access layer of the three-layer hierarchical network design model?

Options:

A.  

Fault isolation

B.  

QoS classification and marking boundary

C.  

Reliability

D.  

Fast transport

E.  

Redundancy and load balancing

Discussion 0
Questions 43

: 504

To facilitate true end-to-end QoS on an IP-network, the IETF has defined two models: IntServ and DiffServ Which protocol is used by both models?

Options:

A.  

Common Open Policy Service

B.  

Resource Quality Service Planning

C.  

Service Code Point Policy

D.  

Resource Reservation and Distribution

Discussion 0
Questions 44

A consultant needs to evaluate project management methodologies for a new service deployment on the existing network of a customer. The customer wants to be involved in the end-to-end project progress and be provided with frequent updates. The customer also wants the ability to change the requirements if needed, as the project progresses. Which project management methodology should be used?

Options:

A.  

Three principles

B.  

Phased

C.  

Agile

D.  

Waterfall

Discussion 0
Questions 45

An architect receives a business requirement from a CTO that states the RTO and RPO for a new system should be as close as possible to zero. Which replication method and data center technology should be used?

Options:

A.  

asynchronous replication over dual data centers via DWDM

B.  

synchronous replication over geographically dispersed dual data centers via MPLS

C.  

synchronous replication over dual data centers via Metro Ethernet

D.  

asynchronous replication over geographically dispersed dual data centers via CWDM

Discussion 0
Questions 46

What are two parameters that can be leveraged by SAML in mixed private/public cloud environments by using identity and asset management? (Choose two)

Options:

A.  

unified directories

B.  

policy-based tokens

C.  

link federations

D.  

identity federations

E.  

multifactor hard tokens

Discussion 0
Questions 47

Which architecture does not require an explicit multicast signaling protocol, such as PIM or P2MP, to signal the multicast state hop-by-hop, but instead uses a link state protocol to advertise the multicast forwarding state?

Options:

A.  

Binary indexed explicit routing

B.  

Binary intermediate enhanced routing

C.  

Bit indexed explicit replication

D.  

Bi-directional implicit replication

Discussion 0
Questions 48

Which two advantages of using DWDM over traditional optical networks are true? (Choose two.)

Options:

A.  

inherent topology flexibility and service protection provided without penalty through intelligent oversubscription of bandwidth reservation

B.  

ability to expand bandwidth over existing optical infrastructure

C.  

inherent topology flexibility with built-in service protection

D.  

inherent topology flexibility with intelligent chromatic dispersion

E.  

inherent topology flexibility with service protection provided through a direct integration with an upper layer protocol

Discussion 0
Questions 49

Company XYZ plans to run OSPF on a DMVPN network. They want to use spoke-to-spoke tunnels in the design. What is a drawback or concern in this type of design?

Options:

A.  

Additional host routes will be inserted into the routing tables

B.  

Manual configuration of the spokes with the appropriate priority will be needed

C.  

There will be split-horizon issue at the hub

D.  

Manual configuration of the spoke IP address on the hub will be needed

Discussion 0
Questions 50

During initial preparations to deploy 802 1x for wired access to their network, a company must ensure that the solution complies with existing internal security policies These policies mandate that every Auth C/Auth Z request must be protected by a tunnel which authenticates both server and clients using their PKI AI the same time, the user authentication phase must be independent of the tunnel Which scheme meets the requirements?

Options:

A.  

EAP-MDS

B.  

EAP-Fast

C.  

EAP-MSCHAPv2

D.  

PEAP

Discussion 0
Questions 51

How can EIGRP topologies be designed to converge as fast as possible in the event of a point-to-point link failure?

Options:

A.  

Limit the query domain by use of distribute lists.

B.  

Build neighbor adjacencies in a triangulated fashion.

C.  

Build neighbor adjacencies in squared fashion.

D.  

Limit the query domain by use of summarization.

E.  

Limit the query domain by use of default routes.

Discussion 0
Questions 52

The CIA triad is foundational to information security, and one can be certain that one or more of the principles within the CIA triad has been violated when data is leaked or a system is attacked Drag and drop the countermeasures on the left to the appropriate principle section on the right in any order

Options:

Discussion 0
Questions 53

When a detection system for protecting a network from threats sourced from the Internet is designed there are two common deployment methods, where the system is placed differently relative to the perimeter firewall

•An unfiltered detection system examines the raw Internet data streams before it reaches the firewall

•A screened detection solution which monitors traffic that is allowed through the firewall Both have its advantages and disadvantages drag and drop the characteristics on the left to the corresponding category on the right in no particular order.

Options:

Discussion 0
Questions 54

The controller has a global view of the network, and it can easily ensure that the network is in a consistent and optimal configuration. Which two statements describe a centralized SDN control path? (Choose two.)

Options:

A.  

Scaling of the centralized controller cluster is challenging for services like DHCP and load-balancing.

B.  

It is highly-available by design with no single-point-of-failure risks present.

C.  

Integrating smart NIC capabilities on the local host level is made easier through REST APIs.

D.  

It significantly improves the latency when performing reactive handling of PACKET_IN events.

E.  

The centralized controller can support all southbound APIs, which allows for easy integration with legacy equipment.

Discussion 0
Questions 55

A global e-commerce company is expanding its operations and planning to migrate its entire infrastructure to a hybrid cloud solution. They are concerned about data governance and want to ensure that their customers ' data is treated with utmost respect to sovereignty and privacy. What is an appropriate approach?

Options:

A.  

Replicate customer data across all data centers globally to ensure data redundancy and compliance with local data regulations.

B.  

Utilize a cloud provider that offers region-specific data centers to store customer data within the same geographic region.

C.  

Encrypt all customer data and store it in a public cloud environment to benefit from advanced security measures.

D.  

Implement strict access controls for customer data and store it in a single central data center to maintain data sovereignty.

Discussion 0
Questions 56

Which two types of planning approaches are used to develop business-driven network designs and to facilitate the design decisions? (Choose two)

Options:

A.  

cost optimization approach

B.  

strategic planning approach

C.  

modular approach

D.  

tactical planning approach

E.  

business optimization approach

Discussion 0
Questions 57

Refer to the exhibit.

There are multiple trees in the Cisco FabricPath. All switches in the Layer 2 fabric share the same view of each tree. Which two concepts describe how the multicast traffic is load-balanced across this topology? (Choose two.)

Options:

A.  

A specific (S,G) traffic is not load-balanced

B.  

All trees are utilized at the same level of the traffic rate

C.  

Every leaf node assigns the specific (S,G) to the same tree

D.  

A specific (S,G) multicast traffic is load-balanced across all trees due to better link utilization efficiency

E.  

The multicast traffic is generally load-balanced across all trees

Discussion 0
Questions 58

Which action must be taken before new VoIP systems are implemented on a network to ensure that the network is ready to handle the traffic?

Options:

A.  

Evaluate bandwidth utilization and connection quality

B.  

Enable special requirements such as direct DID lines on pickup

C.  

Make recommendations to limit the size of the half-open session table on routers

D.  

Check if anomaly detection is enabled for SIP and H.323 on Layer 3 devices

Discussion 0
Questions 59

SDN is still maturing. Throughout the evolution of SDN, which two things will play a key role in enabling a successful deployment and avoiding performance visibility gaps in the infrastructure? (Choose two.)

Options:

A.  

Rapid on-demand growth

B.  

Dynamic real-time change

C.  

Falling back to old behaviors

D.  

Peer-to-peer controller infrastructure

E.  

Integration of device context

Discussion 0
Questions 60

Company XYZ, a global content provider, owns data centers on different continents. Their data center design involves a standard three-layer design with a Layer 3-only core. VRRP is used as the FHRP. They require VLAN extension across access switches in all data centers and plan to purchase a Layer 2 interconnection between two of their data centers in Europe. In the absence of other business or technical constraints, which termination point is optimal for the Layer 2 interconnection?

Options:

A.  

At the core layer, to offer the possibility to isolate STP domains

B.  

At the access layer because the STP root bridge does not need to align with the VRRP active node

C.  

At the core layer because all external connections must terminate there for security reasons

D.  

At the aggregation layer because it is the Layer 2 to Layer 3 demarcation point

Discussion 0
Questions 61

Refer to the exhibit.

Company XYZ must design a DMVPN tunnel between the three sites. Chicago is going to act as the NHS, and the company wants DMVPN to detect peer endpoint failures. Which technology should be used in the design?

Options:

A.  

VPLS

B.  

IP SLA

C.  

GRE

D.  

L2TPv3

Discussion 0
Questions 62

: 484

Traditionally networks handled static web pages e-mail and routine client/server traffic Today enterprise networks must handle more sophisticated types of network applications that include voice and video Applications place increasing demands on IT infrastructures as they evolve into highly visible services that represent the face of the business to internal and external audiences The large amount and variety of data requires that the modern network be aware of the content earned across it to optimally handle that content. Which service provide this intelligence?

Options:

A.  

centralized network services

B.  

application networking services

C.  

network infrastructure services

D.  

modular infrastructure services

Discussion 0
Questions 63

Hybrid cloud computing allows organizations to take advantage of public and private cloud models. Which best practice should organizations follow to ensure data security in the private cloud?

Options:

A.  

Use standard protocols for data transmission over the network.

B.  

Encrypt data when it is at rest and in motion.

C.  

Communicate all data security risks to customers and end users.

D.  

Use standard network protocols for data communication between unsecured network connections.

Discussion 0
Questions 64

You are designing a new Ethernet-based metro-area network for an enterprise customer to connect 50 sites within the same city. OSPF will be the routing protocol used. The customer is primarily concerned with IPv4 address conservation and convergence time. Which two combined actions do you recommend? (Choose two)

Options:

A.  

Use a multipoint Metro-E service for router connections

B.  

Use a single address per router for all P2P links

C.  

Use P2P links between routers in a hub-and-spoke design

D.  

Configure address aggregation at each site router

E.  

Determine which OSPF routers will be DR/BDR

Discussion 0
Questions 65

: 491

Budget is one of the important factors when you design a network Regardless of who controls the budget, one common network design goal is to contain costs Reduced budgets or limited resources often force network designers to select the most affordable solution instead of the best solution Which two elements must be considered when you do ROI analysis for the network design that explains how quickly the new network w ill pay for itself’ (Choose two. )

Options:

A.  

improved employee productivity

B.  

market segmentation

C.  

reduced operational costs

D.  

limiting higher revenue potential

E.  

state-of-the art technologies

Discussion 0
Questions 66

Refer to the exhibit.

Traffic was equally balanced between Layer 3 links on core switches SW1 and SW2 before an introduction of the new video server in the network. This video server uses multicast to send video streams to hosts and now one of the links between core switches is overutilized. Which design solution solves this issue?

Options:

A.  

Add more links between core switches.

B.  

Aggregate links Layer 2 link aggregation.

C.  

Apply a more granular load-balancing method on SW1.

D.  

Apply a more granular load-balancing method on SW2.

E.  

Filter IGMP joins on an overutilized link.

Discussion 0
Questions 67

What is a characteristic of a secure cloud architecture model?

Options:

A.  

limited access to job function

B.  

dedicated and restricted workstations

C.  

multi-factor authentication

D.  

software-defined network segmentation

Discussion 0
Questions 68

Company XYZ asks for design recommendations for Layer 2 redundancy. The company wants to prioritize fast convergence and resiliency elements. In the design, which two technologies are recommended? (Choose two.)

Options:

A.  

Design MLAG/MC-LAG into the network wherever possible.

B.  

Configure DHCP snooping on the switches.

C.  

Use root guard.

D.  

Use BPDU guard.

E.  

Use UniDirectional Link Detection.

Discussion 0
Questions 69

Most security monitoring systems use a signature-based approach to detect threats. In which two instances are systems based on Network Behavior Anomaly Detection better than signature-based systems when it comes to detecting security threat vectors? (Choose two.)

Options:

A.  

encrypted threat traffic

B.  

spyware detection

C.  

malware detection

D.  

new zero-day attacks

E.  

intrusion threat detection

Discussion 0
Questions 70

Drag and drop the FCAPS network management reference models from the left onto the correct definitions on the right.

Options:

Discussion 0
Questions 71

A lead network architect is tasked with designing the optimal cloud-based solution for a rapidty growing e-commerce company that heavily relies on its online platform for sales and customer interactions The company’s business critical operations induce real time inventory management, order processing, and payment processing The executive team has decided to migrate their infrastructure to the cloud to improve scalability and recoce operational costs Which cloud service model(s) needs to considered?

Options:

A.  

SaaS and PaaS

B.  

SaaS

C.  

laaS and PaaS

D.  

laaS

Discussion 0
Questions 72

Company XYZ has 30 sites running a legacy private WAN architecture that connects to the Internet via multiple high-speed connections. The company is now redesigning their network and must comply with these design requirements:

Use a private WAN strategy that allows the sites to connect to each other directly and caters for future expansion.

Use the Internet as the underlay for the private WAN.

Securely transfer the corporate data over the private WAN.

Which two technologies should be incorporated into the design of this network? (Choose two.)

Options:

A.  

S-VTI

B.  

IPsec

C.  

DMVPN

D.  

GET VPN

E.  

PPTP

Discussion 0
Questions 73

Which feature is supported by NETCONF but is not supported by SNMP?

Options:

A.  

Distinguishing between configuration data and operational data

B.  

Taking administrative actions

C.  

Collecting the status of specific fields

D.  

Changing the configuration of specific fields

Discussion 0
Questions 74

A software-defined network exposes an API to the RIB and forwarding engine, allowing off-box control of routing—what SDN model is used?

Options:

A.  

Replace

B.  

Augmented

C.  

Hybrid

D.  

Distributed

Discussion 0
Questions 75

Which DCI technology utilizes a “flood and learn” technique to populate the Layer 2 forwarding table?

Options:

A.  

LISP

B.  

OTV

C.  

VPLS

D.  

EVPN

Discussion 0
Questions 76

When an SDN-based model is used to transmit multimedia traffic, which aspect should an architect consider while designing the network?

Options:

A.  

QoE estimation

B.  

Security

C.  

Traffic patterns

D.  

Flow forwarding

Discussion 0
Questions 77

An IT service provider is upgrading network infrastructure to comply with PCI security standards. The network team finds that 802.1X and VPN authentication based on locally-significant certificates are not available on some legacy phones. Which workaround solution meets the requirement?

Options:

A.  

Replace legacy phones with new phones because the legacy phones will lose trust if the certificate is renewed.

B.  

Enable phone VPN authentication based on end-user username and password.

C.  

Temporarily allow fallback to TLS 1.0 when using certificates and then upgrade the software on legacy phones.

D.  

Use authentication-based clear text password with no EAP-MD5 on the legacy phones.

Discussion 0
Questions 78

The Agile Manifesto is a document that defines the key values and principles behind the Agile philosophy and helps development teams work more efficiently and sustainably. Each of the four key values is split into two sections—a left-hand side and a right-hand side. In other words, though there is value in the items on the right, we value the items on the left more. What is one of the key values of the Agile Manifesto?

Options:

A.  

Comprehensive documentation over working software

B.  

Contract negotiation over customer collaboration

C.  

Individuals and interactions over processes and tools

D.  

Following a plan over responding to change

Discussion 0
Questions 79

Company XYZ is designing the network for IPv6 security and they have these design requirements:

A switch or router must deny access to traffic from sources with addresses that are correct but topologically incorrect.

Devices must block Neighbor Discovery Protocol resolution for destination addresses not found in the binding table.

Which two IPv4 security features are recommended for this company? (Choose two)

Options:

A.  

IPv6 DHCP Guard

B.  

IPv6 Source Guard

C.  

IPv6 Destination Guard

D.  

IPv6 Prefix Guard

E.  

IPv6 RA Guard

Discussion 0
Questions 80

Refer to the exhibit.

This network is running legacy STP 802.1d. Assuming " hello_timer " is fixed to 2 seconds, which parameters can be modified to speed up convergence times after single link/node failure?

Options:

A.  

The transit_delay=5 and bpdu_delay=20 are recommended values, considering hello_timer=2 and specified.

B.  

Only the maximum_transmission_halt_delay and diameter parameters are configurable parameters in 802.1d to speed up STP convergence process.

C.  

The max_age and forward delay parameters can be adjusted to speed up STP convergence process.

D.  

Only the transit_delay and bpdu_delay timers are configurable parameters in 802.1d to speed up STP convergence process.

Discussion 0
Questions 81

Company XYZ needs advice in redesigning their legacy Layer 2 infrastructure. Which technology should be included in the design to minimize or avoid convergence delays due to STP or FHRP and provide a loop-free topology?

Options:

A.  

Use switch clustering in the access layer.

B.  

Use switch clustering in the core/distribution layer.

C.  

Use spanning-tree PortFast.

D.  

Use BF

D.  

Discussion 0
Questions 82

Refer to the exhibit. A service provider has a requirement to use Ethernet OAM to detect end-to-end connectivity failures between SP-SW1 and SP-SW2. Which two ways to design this solution are true? (Choose two)

Options:

A.  

Enable unicast heartbeat messages to be periodically exchanged between MEPs

B.  

Enable Connectivity Fault Management on the SP switches

C.  

Use upward maintenance endpoints on the SP switches

D.  

Forward E-LMI PDUs over VPLS

E.  

Forward LLDP PDUs over the VPLS

Discussion 0
Questions 83

Refer to the exhibit.

A customer runs OSPF with Area 5 between its aggregation router and an internal router. When a network change occurs in the backbone, Area 5 starts having connectivity issues due to the SPF algorithm recalculating an abnormal number of times in Area 5. You are tasked to redesign this network to increase resiliency on the customer network with the caveat that Router B does not support the stub area. How can you accomplish this task?

Options:

A.  

Increase the bandwidth on the connection between Router A and Router B

B.  

Implement LSA filtering on the ABR, allowing summary routes and preventing more specific routes into Area 5

C.  

Create a virtual link to Area 0 from Router B to the ABR

D.  

Turn on LSA throttling on all devices in Area 5

E.  

Set Area 5 to stubby at the ABR anyway

Discussion 0
Questions 84

While designing a switched topology, in which two options is UplinkFast recommended? (Choose two.)

Options:

A.  

when switches of different spanning-tree types are connected (for example. 802.1d connecting to 802.1w)

B.  

on distribution layer switches

C.  

when hello timers are changed to more aggressive values

D.  

on access layer switches

E.  

on the core switches

Discussion 0
Questions 85

Refer to the exhibit: A customer is migrating from a TDM-based Layer 2 VPN (L2VPN) to an MPLS Layer 3 VPN (L3VPN) in phases. The backbone OSPF connection between HUB A and HUB B will be replaced by eBGP. During the migration, some spokes (A2 and B1) are already moved to the L3VPN. The goal is to avoid routing loops during this hybrid transition.

Which design choice helps prevent routing loops during the backbone link migration?

Options:

A.  

Enable route filtering on OSPF backbone routers for spoke traffic

B.  

Advertise low AD value for transit traffic on hub sites

C.  

OSPF backbone area advertises summarized routes to hub

D.  

Redistribute EIGRP 200 and 300 with low cost into BGP

Discussion 0
Questions 86

Company XYZ is designing their network using the three-layer hierarchical model. At which layer must the QoS design classify or mark the traffic?

Options:

A.  

Access

B.  

Core

C.  

Collapsed core

D.  

Distribution

Discussion 0
Questions 87

: 486

An aerospace firm is considering implementing AI and ML systems to boost output while decreasing line downtime Optimal maintenance schedules and failure prediction of equipment are the end goals

To meet this business demand, which AI/ML solution would be the most effective in boosting productivity and decreasing downtime?

Options:

A.  

lessening the need for human workers by automating production with Al

B.  

optimizing maintenance schedules and predicting equipment failures with the use of predictive maintenance algorithms

C.  

automating production-related employee training with chatbots driven by artificial intelligence

D.  

using ML models to improve logistics in the company supply chain

Discussion 0
Questions 88

SDN controllers need to sustain healthy operation under the pressure of different objectives from the applications they host. High availability can be achieved through improved southbound APIs and controller placement heuristics and formal models. Which two implementation strategy help to maximize resilience and scalability? (Choose two.)

Options:

A.  

Efficient implementation by connecting forwarding devices to multiple controller.

B.  

Cost-effective implementation by connecting forwarding devices to single controller.

C.  

Controller deployment planning is more dependent on network size than on the topology.

D.  

Controller deployment planning is more dependent on network type than application need

E.  

Controller deployment planning is more dependent on the topology than on network size.

Discussion 0
Questions 89

In a controller-based network architecture, between which of the two elements the southbound interface does the communication happen with a goal to program the data plane forwarding tables? (Choose two)

Options:

A.  

core components

B.  

forwarding lane

C.  

layer interface

D.  

networking device

E.  

controller

Discussion 0
Questions 90

Drag and drop the right functional descriptions from the left onto the corresponding protocols on the right.

Options:

Discussion 0
Questions 91

You are designing an Out of Band Cisco Network Admission Control Layer 3 Real-IP Gateway deployment for a customer. Which VLAN must be trunked back to the Clean Access Server from the access switch?

Options:

A.  

authentication VLAN

B.  

user VLAN

C.  

untrusted VLAN

D.  

management VLAN

Discussion 0
Questions 92

An existing wireless network was designed to support data traffic only. You must now install context-aware services for location tracking. What changes must be applied to the existing wireless network to increase the location accuracy? (Choose two)

Options:

A.  

Add access points along the perimeter of the coverage area.

B.  

Increase the access point density to create an average inter-access point distance of less than 40 feet or 12.2 meters.

C.  

Use directional antennas to provide more cell overlapping.

D.  

Install additional access points in monitor mode where the co-channel interference would otherwise be affected.

E.  

Fine tune the radio configuration of the access point to have a higher average transmission power to achieve better coverage.

Discussion 0
Questions 93

Which three items do you recommend for control plane hardening of an infrastructure device? (Choose three.)

Options:

A.  

Routing protocol authentication

B.  

SNMPv3

C.  

Control Plane Policing

D.  

Redundant AAA servers

E.  

Warning banners

F.  

To enable unused services

Discussion 0
Questions 94

You are designing the QoS policy for a company that is running many TCP-based applications. The company is experiencing tail drops for these applications. The company wants to use a congestion avoidance technique for these applications. Which QoS strategy can be used?

Options:

A.  

Weighted fair queuing

B.  

Weighted random early detection

C.  

Low-latency queuing

D.  

First-in first-out

Discussion 0
Questions 95

Setting a specific goal for throughput based on per-second data rates between end hosts does not identify the requirements for specific applications When specifying throughput goals for applications, it is important to understand the throughput requirements for each application Which two factors that can constrain application layer throughput? (Choose two.)

Options:

A.  

protocol parameters, such as frame size and retransmission timers

B.  

sent packets or cells at networking devices

C.  

the pps or cps rate of networking devices

D.  

workstation and server availability

E.  

end-to-end throughput rates

Discussion 0
Questions 96

The network designer needs to use GLOP IP addresses in order to make them unique within their ASN. Which multicast address range should be used?

Options:

A.  

232.0.0.0 to 232.255.255.255

B.  

233.0.0.0 to 233.255.255.255

C.  

239.0.0.0 to 239.255.255.255

D.  

224.0.0.0 to 224.0.0.255

Discussion 0
Questions 97

Company XYZ is designing the IS-IS deployment strategy for their multiarea IS-IS domain. They want IS-IS neighbor relationships minimized on each segment and the LSDB size optimized. Which design can be used?

Options:

A.  

Design all routers as Level 2 routers. Set the links between the routers as Level 1 with the area

B.  

Design the network so that the routers connecting to other areas are Level 2 routers and internal routers are Level 1

C.  

Design the network so that all routers are Level 1 routers

D.  

Design the network so that the routers connecting to other areas are Level 1/Level 2 routers and internal routers are Level 1

Discussion 0
Questions 98

: 497 DRAG DROP

Data residency and sovereignty requirements are based on regional and industry-specific regulations, and different organizations have different data sovereignty requirements. Implementation of a mechanism that provides control over all access to data by cloud providers and the ability to inspect changes to cloud infrastructure and services is required. Drag and drop the descriptions from the left onto the corresponding categories on the right in no particular order. Not all options are used.

Options:

Discussion 0
Questions 99

As more links are added to the network, information and attributes related to the link is added to the control plane, meaning every link that gets added will slow down the convergence of the control plane by some measurable amount of time As a result when additional redundancy is built or added the MTTR will increase too Which risk increases along with the increased MTTR?

Options:

A.  

management visibility

B.  

slower data plane convergence

C.  

overlapping outages

D.  

topology change detection

Discussion 0
Questions 100

A service provider hires you to design its new managed CE offering to meet these requirements:

The CEs cannot run a routing protocol with the PE.

Provide the ability for equal or unequal ingress load balancing in dual-homed CE scenarios.

Provide support for IPv6 customer routes.

Scale up to 250,000 CE devices per customer.

Provide low operational management to scale customer growth.

Utilize low-end (inexpensive) routing platforms for CE functionality.

Which tunneling technology do you recommend?

Options:

A.  

FlexVPN

B.  

point-to-point GRE

C.  

DMVPN

D.  

LISP

Discussion 0
Questions 101

Company XYZ has implemented policy-based routing in their network. Which potential problem must be kept in mind about network reconvergence and PBR?

Options:

A.  

It can limit network scalability

B.  

It can create microloops during reconvergence

C.  

It increases convergence time.

D.  

It reduces convergence time.

Discussion 0
Questions 102

Which Interconnectivity method offers the fastest convergence in the event of a unidirectional issue between three Layer 3 switches connected together with routed links in the same rack in a data center?

Options:

A.  

Copper Ethernet connectivity with BFD enabled

B.  

Copper Ethernet connectivity with UDLD enabled

C.  

Fiber Ethernet connectivity with BFD enabled

D.  

Fiber Ethernet connectivity with UDLD enabled

Discussion 0
Questions 103

Which technique facilitates analytics and knowledge discovery in big data systems to recognize hidden and complex patterns?

Options:

A.  

predictive monitoring

B.  

deep learning

C.  

traffic classification

D.  

network mobility

Discussion 0
Questions 104

Modem IT departments are more service oriented than they used to be To meet the needs oí their customers. IT departments are spending more time analyzing and documenting their processes for delivering services A focus on processes helps to ensure effective service delivery and to avoid wasted expenditures on technology that doesn ' t provide a needed service What defines frameworks and processes that can help an organization match the delivery of IT services with the business needs of the organization?

Options:

A.  

IT Service Management

B.  

remedy management

C.  

IT helpdesk

D.  

service desk monitoring

Discussion 0
Questions 105

How must the queue sizes be designed to ensure that an application functions correctly?

Options:

A.  

Each individual device queuing delay in the chain must be less than or equal to the application required delay.

B.  

The queuing delay on every device in the chain must be exactly the same to the application required delay.

C.  

The default queue sizes are good for any deployment as it compensates the serialization delay.

D.  

The sum of the queuing delay of all devices plus serialization delay in the chain must be less than or equal to the application required delay.

Discussion 0
Questions 106

A customer with two 10 Mbps Internet links (active-active) experiences degraded performance when one fails. Static routing is used, and bandwidth upgrades aren ' t possible. The design must be failure-resistant without increasing CAPEX.

Which solution should be proposed?

Options:

A.  

Implement quality of service on the current links

B.  

Add a third link to the current router

C.  

Add an additional edge router connected to a second ISP

D.  

Use dynamic routing for equal-cost multipath

Discussion 0
Questions 107

A Service Provider is designing a solution for a managed CE service to a number of local customers using a single CE platform and wants to have logical separation on the CE platform using Virtual Routing and Forwarding (VRF) based on IP address ranges or packet length. Which is the most scalable solution to provide this type of VRF Selection process on the CE edge device?

Options:

A.  

Static Routes for Route Leaking

B.  

Policy Based Routing

C.  

OSPF per VRF Instance

D.  

Multi-Protocol BGP

Discussion 0
Questions 108

Which three items do you recommend for control plane hardening of an infrastructure device? (Choose three.)

Options:

A.  

redundant AAA servers

B.  

Control Plane Policing

C.  

warning banners

D.  

to enable unused services

E.  

SNMPv3

F.  

routing protocol authentication

Discussion 0
Questions 109

An enterprise wants to migrate an on-premises network to a cloud network, and the design team is finalizing the overall migration process. Drag and drop the options from the left into the correct order on the right.

Options:

Discussion 0
Questions 110

Company XYZ branch offices connect to headquarters using two links, MPLS and Internet. The company wants to design traffic flow so voice traffic uses MPLS and all other traffic uses either link, avoiding process switching. Which technique can be used?

Options:

A.  

Policy-based routing

B.  

Virtual links

C.  

Visualization

D.  

Floating static route

Discussion 0
Questions 111

What best describes the difference between Automation and Orchestration?

Options:

A.  

Automation refers to an automatic process for completing a single task and Orchestration refers to assembling and coordinating a set of tasks and conditions.

B.  

Automation describes a hands-off configuration process while Orchestration refers to sets of automation tasks that require the network administrator to coordinate.

C.  

Automation refers to an automatic process for completing multiple tasks with conditions and Orchestration refers to executing tasks in parallel.

D.  

Automation refers to scripting languages (Python, Ansible etc.) and Orchestration refers to commercial products that control configuration deployment.

Discussion 0
Questions 112

You are tasked with the design of a high available network. Which two features provide fail closed environments? (Choose two.)

Options:

A.  

EIGRP

B.  

RPVST+

C.  

MST

D.  

L2MP

Discussion 0
Questions 113

Company XYZ is migrating their existing network to IPv6. Some access layer switches do not support IPv6, while core and distribution switches fully support unicast and multicast routing. The company wants to minimize cost of the migration. Which migration strategy should be used?

Options:

A.  

The access layer switches must support IGMP snooping at a minimum. Any switches that do not support IGMP snooping must be replaced.

B.  

Upgrade the non-supporting switches. Otherwise, it will cause an issue with the migration.

C.  

Layer 2 switches will not affect the implementation of IPv6. They can be included in the design in their current state.

D.  

The access layer switches must support DHCPv6. Any switches that do not support DHCPv6 must be replaced.

Discussion 0
Questions 114

When consumers that leverage IaaS reach 100% resource capacity, what can be used to redirect the overflow of traffic to the public cloud so there is no disruption to service?

Options:

A.  

Cloud policing

B.  

Cloud spill

C.  

Cloud bursting

D.  

Cloud shaping

Discussion 0
Questions 115

A legacy enterprise is using a Service Provider MPLS network to connect its head office and branches. They want to extend the existing IP CCTV network to a new branch without routing changes or IP address changes. What is the best approach?

Options:

A.  

GRE

B.  

L2TPv3

C.  

VXLAN

D.  

EoMPLS

Discussion 0
Questions 116

Which two technologies enable multilayer segmentation? (Choose two.)

Options:

A.  

policy-based routing

B.  

segment routing

C.  

data plane markings

D.  

firewalls

E.  

filter lists

Discussion 0
Questions 117

Flexibility, scalability, resiliency, and security are all chrematistics of a services-ready network An architecture featuring a modular design enables technologies and services to be added when the organization is ready to deploy. Drag and drop the design considerations on the left to the to type of service on the right Not all options are used

Options:

Discussion 0
Questions 118

Company XYZ must design a strategy to protect their routers from DoS attacks, such as traffic destined to the router ' s own route processor, using separate control plane categories. Which two capabilities can be used to achieve this requirement? (Choose two.)

Options:

A.  

Control Plane Protection using queue thresholding on the transit subinterface

B.  

Control Plane Protection using port filtering on the transit subinterface

C.  

Control Plane Protection using port filtering on the main interface

D.  

Control Plane Protection using queue thresholding on the host subinterface

E.  

Control Plane Protection using port filtering on the host subinterface

Discussion 0
Questions 119

Two routers R1 and R2 are directly connected through an Ethernet link Both routers are running OSPF. OSPF has been registered with BFD and BFD is running in asynchronous mode with the echo function enabled Which two actions occur that are related to the echo function? (Choose two)

Options:

A.  

DFD sent at a slower pace because the echo function is enabled

B.  

BFD echo packets are sent from forwarding engines along the Layer 2 path to perform detection

C.  

BFD control packets are sent at a higher pace because the echo function is enabled

D.  

Only BFD control packets are sent from forwarding engines along the Layer 2 path to perform detection

E.  

DUMPS BFD sessions at either end actively participate in the forwarding of echo packets

Discussion 0
Questions 120

What are the two benefits of using northbound APIs in SDN architecture? (Choose two.)

Options:

A.  

They provide a way to manage the SDN and configure network policies

B.  

They connect the SDN controller to the underlying network devices.

C.  

They provide a way for the SDN controller to communicate with network devices

D.  

They provide, a way for the SDN to control change management

E.  

They connective SDN controller to higher-level management, systems

Discussion 0
Questions 121

Refer to the exhibit.

Which impact of using three or more ABRs between the backbone area and area 1 is true?

Options:

A.  

In a large-scale network LSA replication by all ABRs can cause serious scalability issues

B.  

Multiple ABRs reduce the CPU processing on each ABR due to splitting prefix advertisement

C.  

In a large-scale network multiple ABRs can create microloops

D.  

Prefixes from the non-backbone area are advertised by one ABR to the backbone

Discussion 0
Questions 122

Which two statements describe the hierarchical LAN design model? (Choose two)

Options:

A.  

It is a well-understood architecture that provides scalability

B.  

It is the best design for modern data centers

C.  

It is the most optimal design but is highly complex

D.  

It provides a simplified design

E.  

Changes, upgrades, and new services can be introduced in a controlled and staged manner

Discussion 0
Questions 123

Which two features describe controller-based networking solutions compared to traditional networking solutions? (Choose two.)

Options:

A.  

Inflate licensing costs

B.  

Reduce network configuration complexity

C.  

Provide centralization of primary IT functions

D.  

Allow for fewer network failures

E.  

Increase network bandwidth usage

Discussion 0
Questions 124

Which protocol does an SD-Access wireless Access Point use for its fabric data plane?

Options:

A.  

GRE

B.  

MPLS

C.  

VXLAN

D.  

LISP

E.  

CAPWAP

Discussion 0
Questions 125

There are varying requirements and motivations for improving the scalability and resilience of an enterprise application. The relative importance of these requirements and constraints varies depending on the type of app. the profile of the users, and the scale and maturity of the organization in which it is deployed. What are two common business drivers that deals with these aspects? (Choose two.)

Options:

A.  

Minimize time spent investigating failures.

B.  

Build apps using the latest industry patterns and practices.

C.  

Ensure that user demand can be met during periods of high usage.

D.  

Reduce the frequency of failures requiring human intervention.

E.  

Increase flexibility and agility to handle changing market demands.

Discussion 0
Questions 126

The SD-WAN architecture is composed of separate orchestration, management, control, and data planes. Which activity happens at the orchestration plane?

Options:

A.  

Automatic onboarding of the SD-WAN routers into the SD-WAN overlay

B.  

Decision-making process on where traffic flows

C.  

Packet forwarding

D.  

Central configuration and monitoring

Discussion 0
Questions 127

Which methodology is the leading lifecycle approach to network design and implementation?

Options:

A.  

PPDIOO

B.  

Waterfall model

C.  

Spiral model

D.  

V model

Discussion 0
Questions 128

You have been asked to design a high-density wireless network for a university campus. Which two principles would you apply in order to maximize the wireless network capacity? (Choose two.)

Options:

A.  

Implement a four-channel design on 2.4 GHz to increase the number of available channels

B.  

Choose a high minimum data rate to reduce the duty cycle.

C.  

Increases the number of SSIDs to load-balance the client traffic.

D.  

Make use of the 5-GHz band to reduce the spectrum utilization on 2.4 GHz when dual-band clients are used.

E.  

Enable 802.11n channel bonding on both 2.4 GHz and 5 GHz to increase the maximum aggregated cell throughput.

Discussion 0
Questions 129

Which two features are advantages of SD-WAN compared to MPLS-based connectivity? (Choose two.)

Options:

A.  

Uses FEC constructs for traffic forwarding, thereby improving efficiency

B.  

Separates infrastructure and policy

C.  

Uses policy-based forwarding of real-time traffic with less complexity

D.  

Unifies the WAN backbone

E.  

Manages failures through backup links

Discussion 0
Questions 130

Which effect of using ingress filtering to prevent spoofed addresses on a network design is true?

Options:

A.  

It reduces the effectiveness of DDoS attacks when associated with DSCP remarking to Scavenger.

B.  

It protects the network infrastructure against spoofed DDoS attacks.

C.  

It classifies bogon traffic and remarks it with DSCP bulk.

D.  

It filters RFC 1918 IP addresses.

Discussion 0
Questions 131

Which SDN architecture component is used by the application layer to communicate with the control plane layer to provide instructions about the resources required by applications?

Options:

A.  

Southbound APIs

B.  

Northbound APIs

C.  

Orchestration layer

D.  

SDN controller

Discussion 0
Questions 132

A senior network designer suggests that you should improve network convergence times by reducing BGP timers between your CE router and the PE router of the service provider. Which two factors should you consider to adjust the timer values? (Choose two.)

Options:

A.  

service provider agreement to support tuned timers

B.  

manual updates to the peer groups

C.  

service provider scheduling of changes to the PE

D.  

number of routes on the CE router

E.  

number of VRFs on the PE router

Discussion 0
Questions 133

PaaS provides a cloud-based platform for developing, running, managing applications. Users access the PaaS through a GUI, where development or DevOps teams can collaborate on all their work across the entire application lifecycle including coding, integration, testing, delivery, deployment, and feedback. Which benefit does an organization get by using PaaS?

Options:

A.  

improved access

B.  

comprehensive security

C.  

improved responsiveness

D.  

faster time to market

Discussion 0
Questions 134

An external edge router provides connectivity from a service provider to an enterprise. Which two Internet edge best practices meet compliance regulations? (Choose two)

Options:

A.  

Implement filtering to control traffic that is sourced from the infrastructure IP space.

B.  

Enable and use only secure protocols.

C.  

Send logs to a centralized logging collection server.

D.  

Implement EBGP to advertise all owned IP blocks.

E.  

Use login banners and interface access lists to restrict administrative access to the system.

Discussion 0
Questions 135

The network team in XYZ Corp wants to modernize their infrastructure and is evaluating an implementation and migration plan to allow integration MPLS-based, Layer 2 Ethernet services managed by a service provider to connect branches and remote offices. To decrease OpEx and improve

response times when network components fail, XYZ Corp decided to acquire and deploy new routers. The network currently is operated over E1 leased lines (2 Mbps) with a managed CE service provided by the telco.

Drag and drop the implementation steps from the left onto the corresponding targets on the right in the correct order.

Options:

Discussion 0
Questions 136

Refer to the exhibit.

Refer to the exhibit. Two data center sites (X and Y) connect to the Internet and each other using a backdoor link. Both advertise the same IP prefix (100.75.10.0/23) to the Internet. Firewalls are behind R1 and R2.

Problem: When users attempt to reach 100.75.10.0/23, the return traffic is routed to Site-Y, regardless of where the session originated. This results in asymmetric traffic and potentially broken sessions due to firewall behavior.

Which design resolves the issue?

Options:

A.  

Use BGP MED to influence Site-X return traffic. Change the IP address scheme of both sites.

B.  

Change the Site-Y firewall configuration to replicate the Site-X configuration. Advertise the low MED attribute on Site-X to the Internet.

C.  

Add a static route toward the Internet on Site-X. Change the DNS policy on Site-Y to block traffic.

D.  

Establish control plane peering between edge routers. Have Site-X advertise an IP pool with a longer prefix.

Discussion 0
Questions 137

A key to maintaining a highly available network is building in the appropriate redundancy to protect against failure. This redundancy is carefully balanced with the inherent complexity of redundant systems. Which design consideration is relevant for enterprise WAN use cases when it comes to resiliency?

Options:

A.  

Design in a way that expects outages and attacks on the network and its protected resources

B.  

The design approach should consider simple and centralized management aspect

C.  

Design in a way that it simplifies and improves ease of deployment

D.  

Design automation tools wherever it is appropriate for greater visibility

Discussion 0
Questions 138

Which design method is achieved by layering the network control plane above a redundant physical infrastructure?

Options:

A.  

scalability

B.  

manageability

C.  

resilience

D.  

modulanty

Discussion 0
Questions 139

IPFIX data collection via standalone IPFIX probes is an alternative to flow collection from routers and switches. Which use case is suitable for using IPFIX probes?

Options:

A.  

performance monitoring

B.  

security

C.  

observation of critical links

D.  

capacity planning

Discussion 0
Questions 140

A centralized control plane generally means one or more controllers gather the reachability and topology information from each switching device and calculate some part of the forwarding information at some place. How can a centralized control plane be defined or described?

Options:

A.  

ability to detect and react to changes remotely at each device

B.  

set of processes running in a virtual or physical machine

C.  

protocol running on each device

D.  

set of algorithms implemented on all devices

Discussion 0
Questions 141

Refer to the exhibit. An architect must design an enterprise WAN that connects the headquarters with 22 branch offices. The number of remote sites is expected to triple in the next three years. The final solution must comply with these requirements:

Only the loopback address of each of the enterprise CE X and Y routers must be advertised to the interconnecting service provider cloud network.

The transport layer must carry the VPNv4 label and VPN payload over the MP-BGP control plane.

The transport layer must not be under service provider control.

Which enterprise WAN transport virtualization technique meets the requirements?

Options:

A.  

EIGRP Over the Top

B.  

MPLS over BGP over multipoint GRE

C.  

DMVPN per VRF

D.  

Point-to-point GRE per VRF

Discussion 0
Questions 142

An enterprise plans to evolve from a traditional WAN network to a software-defined WAN network. The existing devices have limited capability when it comes to virtualization. As the migration is carried out, enterprise applications and services must not experience any traffic impact. Which implementation plan can be used to accommodate this during the migration phase?

Options:

A.  

Deploy controllers, deploy SD-WAN edge routers in the data center, and migrate branch sites.

B.  

Migrate data center WAN routers, migrate branch sites, and deploy SD-WAN edge routers.

C.  

Migrate branch sites, migrate data center WAN routers, and deploy controllers.

D.  

Deploy SD-WAN edge routers in the data center, deploy controllers, and migrate branch sites.

Discussion 0
Questions 143

A financial company requires that a custom TCP-based stock-trading application be prioritized over all other traffic for the business due to the associated revenue. The company also requires that VoIP be prioritized for manual trades. Which directive should be followed when a QoS strategy is developed for the business?

Options:

A.  

Allow VoIP and the custom application to share the same priority queue.

B.  

The custom application and VoIP must be assigned their own separate priority queue.

C.  

Interleave the custom application with other TCP applications in the same CBWFQ.

D.  

Avoid placing the custom application in a CBWFQ queue that contains other traffic.

Discussion 0
Questions 144

In outsourced IT services, the RTO is defined within the SLA. Which two support terms are often included in the SLA by IT and other service providers? (Choose two.)

Options:

A.  

Network size and cost

B.  

Support availability

C.  

Network sustainability

D.  

Network reliability

E.  

Resolution time

Discussion 0
Questions 145

Which two actions ensure voice quality in a branch location with a low-speed, high-latency WAN connection? (Choose two.)

Options:

A.  

Increase WAN bandwidth

B.  

Increase memory branch switch.

C.  

Fragment data packets.

D.  

Replace any electrical links with optical links

E.  

Prioritize voice packets

Discussion 0
Questions 146

Refer to the exhibit.

A customer has two eBGP internet links: one primary high-speed (10 Mbps) and one backup low-speed (1 Mbps). The requirement is to use the 10M link (ISP 1) for all inbound/outbound traffic and only use the 1M link (ISP 2) during failure.

What is the correct BGP-based design solution?

Options:

A.  

Advertise a higher local preference to ISP 2. Increase the AS PATH inbound from ISP 1

B.  

Advertise a longer AS PATH to ISP 2. Increase the MED to ISP 2

C.  

Advertise more specific routes to ISP 1. Increase the local preference attribute of inbound BGP from ISP1

D.  

Advertise less specific routes to ISP 2. Increase the AS PATH inbound from ISP 1

Discussion 0
Questions 147

You have been tasked with designing a data center interconnect as part of business continuity. You want to use FCoE over this DCI to support synchronous replication. Which two technologies allow for FCoE via lossless Ethernet or data center bridging? (Choose two.)

Options:

A.  

DWDM

B.  

EoMPLS

C.  

SONET/SDH

D.  

Multichassis EtherChannel over Pseudowire

E.  

VPLS

Discussion 0
Questions 148

Which two design options are available to dynamically discover the RP in an IPv6 multicast network? (Choose two)

Options:

A.  

Embedded RP

B.  

MSDP

C.  

BSR

D.  

Auto-RP

E.  

MLD

Discussion 0
Questions 149

Which option is a fate-sharing characteristic in regards to network design?

Options:

A.  

A failure of a single element causes the entire service to fail

B.  

It protects the network against failures in the distribution layer

C.  

It acts as a stateful forwarding device

D.  

It provides data sequencing and acknowledgment mechanisms

Discussion 0
Questions 150

What advantage of placing the IS-IS Layer 2 flooding domain boundary at the core layer in a three-layer hierarchical network is true?

Options:

A.  

The Layer 1 and Layer 2 domains can easily overlap

B.  

It reduces the complexity of the Layer 1 domains

C.  

It can be applied to any kind of topology

D.  

The Layer 2 domain is contained and more stable

Discussion 0