CCNP Enarsi
CCNP Enarsi
CCNP Enarsi
Number: 300-410
Passing Score: 825
Time Limit: 90 min
File Version: 1.3
CCNP ENTERPRISE
v1.1 Re-organized
v1.2 September Update Added
v1.3 November Update Added
Sections
1. New Enarsi Questions (September Update)
2. New Enarsi Questions 2 (November Update)
3. OSPF & EIGRP Questions
4. BGP Questions
5. Route-map Questions
6. Redistribution Questions
7. MPLS Questions
8. VRF-Lite Questions
9. DMVPN Questions
10. AAA Questions
11. NTP Questions
12. Access-list Questions
13. Control Plane Questions
14. IPv6 Questions
15. IP SLA Questions
16. SNMP Questions
17. DHCP Questions
18. DNA Center Questions
19. Drag Drop Questions
20. Miscellaneous Questions
ENARSI September
QUESTION 1
Refer to the exhibit. AAA server 10.1.1.1 is configured with the default authentication and accounting settings, but the switch cannot communicate with the
server. Which action resolves this issue?
Correct Answer: B
Section: New Enarsi Questions (September Update)
QUESTION 2
Refer to the exhibit. A company is evaluating multiple network management system tools. Trending graphs generated by SNMP data are returned by the
NMS and appear to have multiple gaps. While troubleshooting the issue, an engineer noticed the relevant output. What solves the gaps in the graphs?
A. Remove the class map NMS from being part of control plane policing
B. Remove the exceed-rate command in the class map
C. Configure the CIR rate to a lower value that accommodates all the NMS tools
D. Separate the NMS class map in multiple class maps based on the specific protocols with appropriate CoPP actions
Correct Answer: D
Section: New Enarsi Questions (September Update)
QUESTION 3
Drag and drop the credentials from the left onto the remote login information on the right to resolve a failed login attempt to vtys. Not all credentials are used.
Select and Place:
Correct Answer:
Section: New Enarsi Questions (September Update)
QUESTION 4
Refer to the exhibit. An engineer is monitoring reachability of the configured default routes to ISP1 and ISP2. The default route from ISP1 is preferred if
available. How is this issue resolved?
A. Use the icmp-echo command to track both default routes
B. Start IP SLA by matching numbers for track and ip sla commands
C. Start IP SLA by defining frequency and scheduling it
D. Use the same AD for both default routes
Correct Answer: C
Section: New Enarsi Questions (September Update)
QUESTION 5
Refer to the exhibit. Redistribution is enabled between the routing protocols, and now PC2 PC3, and PC4 cannot reach PC1. What are the two solutions to fix
the problem? (Choose two)
A. Filter RIP and OSPF routes back into OSPF from EIGRP when redistributing into OSPF in R2
B. Filter all routes except EIGRP routes when redistributing into OSPF in R3
C. Filter OSPF routes into RIP from EIGRP when redistributing into RIP in R2
D. Filter all routes except RIP routes when redistributing into EIGRP in R2
E. Filter RIP routes back into RIP when redistributing into RIP in R2
Correct Answer: CE
Section: New Enarsi Questions (September Update)
QUESTION 6
Which label operations are performed by a label edge router?
QUESTION 7
Refer to the exhibit. The network administrator configured VRF lite for customer A. The technician at the remote site misconfigured VRF on the router. Which
configuration will resolve connectivity for both sites of customer A?
A. ip vrf customer_a
rd 1:2
route-target both 1:1
B. ip vrf customer_a
rd 1:2
route-target both 1:2
C. ip vrf customer_a
rd 1:1
router-target import 1:1
router-target export 1:2
D. ip vrf customer_a
rd 1:1
route-target export 1:2
router-target import 1:2
Correct Answer: A
Section: New Enarsi Questions (September Update)
QUESTION 8
Drag and drop the operations from the left onto the locations where the operations are performed on the right.
QUESTION 9
After some changes in the routing policy, it is noticed that the router in AS 45123 is being used as a transit AS router for several service providers. Which
configuration ensures that the branch router in AS 45123 advertises only the local networks to all SP neighbors?
Correct Answer: C
Section: New Enarsi Questions (September Update)
QUESTION 10
Refer to the exhibit. An engineer is trying to get a packet destined for 192.168.32.100 forwarded through 10.1.1.1, but it was forwarded through 10.1.1.2.
What action forwards the packets through 10.1.1.1?
Correct Answer: C
Section: New Enarsi Questions (September Update)
QUESTION 11
Refer to the exhibit. A junior engineer updated a branch router configuration. Immediately after the change, the engineer receives calls from the help desk
that branch personnel cannot reach any network destinations. Which configuration restores service and continues to block 10.1.1.100/32?
Correct Answer: B
Section: New Enarsi Questions (September Update)
QUESTION 12
An engineer configured a leak-map command to summarize EIGRP routes and advertise specifically loopback 0 with an IP of 10.1.1.1 255.255.255.252
along with the summary route. After finishing configuration, the customer complained not receiving summary route with specific loopback address. Which two
configurations will fix it? (Choose two)
A. Configure route-map Leak-Route permit 10 and match access-list 1
B. Configure access-list 1 permit 10.1.1.1 0.0.0.252
C. Configure access-list 1 and match under route-map Leak-Route
D. Configure route-map Leak-Route permit 20
E. Configure access-list 1 permit 10.1.1.0 0.0.0.3
Correct Answer: AE
Section: New Enarsi Questions (September Update)
QUESTION 13
Refer to the exhibit. An IP SLA is configured to use the backup default route when the primary
is down, but it is not working as desired. Which command fixes the issue?
A. R1(config)# ip route 0.0.0.0 0.0.0.0 1.1.1.1 track 1
B. R1 (config)# ip route 0.0.0 0 0.0.0 0 2.2.2 2
C. R1 (config)# ip route 0.0.0.0 0.0.0.0 2.2.2.2 10 track 1
D. R1(config)# ip sla track 1
Correct Answer: A
Section: New Enarsi Questions (September Update)
QUESTION 14
What is an advantage of using BFD?
Correct Answer: C
Section: New Enarsi Questions (September Update)
QUESTION 15
Refer to the exhibit. The ACL is placed on the inbound GigabitEthernet 0/1 interface of the router. Host 192.168.10.10 cannot SSH to host 192.168.100.1
even though the flow is permitted. Which action resolves the issue without opening full access to this router?
A. Temporarily move the permit ip any any line to the beginning of the ACL to see if it the flow works
B. Run the show access-list FILTER command to view if the SSH entry has any hit statistics associated with it
C. Move the SSH entry to the beginning of the ACL
D. Temporarily remove the ACL from the interface to see if the flow works
Correct Answer: C
Section: New Enarsi Questions (September Update)
QUESTION 16
Which component of MPLS VPN is used to extend the IP address so that an engineer is able to identify to which VPN it belongs?
A. RD
B. VPNv4 address family
C. RT
D. LDP
Correct Answer: A
Section: New Enarsi Questions (September Update)
QUESTION 17
Refer to the exhibit. BGP is flapping after the CoPP policy is applied. What are the two solutions to fix the issue? (Choose two)
Correct Answer: AB
Section: New Enarsi Questions (September Update)
QUESTION 18
During the maintenance window, an administrator accidentally deleted the telnet-related configuration that permits a Telnet connection from the inside
network (Eth 0/0) to the outside of the network between Friday-Sunday night hours only. Which configuration resolves the issue?
A. interface Ethernet0/0
ip address 10.1.1.1 255.255.255.0
ip access-group 101 in
!
access-list 101 permit tcp 10.1.1.0 0.0.0.255 172.16.1.0 0.0.0.255 eq telnet time-range
changewindow
!
time-range changewindow
periodic 22:00 to 05:00
B. interface Ethernet0/0
ip address 10.1.1.1 255.255.255.0
ip access-group 101 in
!
access-list 101 permit tcp 10.1.1.0 0.0.0.255 172.16.1.0 0.0.0.255 eq telnet time-range
changewindow
!
time-range changewindow
periodic Friday Saturday Sunday 22:00 to 05:00
C. interface Ethernet0/0
ip address 10.1.1.1 255.255.255.0
ip access-group 101 in
!
access-list 101 permit udp 10.1.1.0 0.0.0.255 172.16.1.0 0.0.0.255 eq telnet time-range
changewindow
!
time-range changewindow
periodic Friday Saturday Sunday 22:00 to 05:00
D. interface Ethernet0/0
ip address 10.1.1.1 255.255.255.0
ip access-group 101 in
!
access-list 101 permit udp 10.1.1.0 0.0.0.255 172.16.1.0 0.0.0.255 eq telnet time-range
changewindow
!
time-range changewindow
periodic Friday Saturday Sunday
Correct Answer: B
Section: New Enarsi Questions (September Update)
QUESTION 19
Refer to the exhibit. Which action resolve intermittent connectivity observed with the SNMP trap packets?
A. Add a new class map to match TCP traffic
B. Add one new entry in the ACL 120 to permit the UDP port 161
C. Increase the CIR of the mgmt class map
D. Decrease the committed burst size of the mgmt class map
Correct Answer: C
Section: New Enarsi Questions (September Update)
QUESTION 20
An engineer configured a company’s multiple area OSPF head office router and Site A cisco routers with VRF lite. Each site router is connected to a PE
router of an MPLS backbone. After finishing both site router configurations, none of the LSA 3,4 5, and 7 are installed at Site A router.
A. configure capability vrf-lite on Site A and its connected PE router under router ospf 1 vrf abc
B. configure capability vrf-lite on Head Office and its connected PE router under router ospf 1 vrf abc
C. configure capability vrf-lite on both PE routers connected to Head Office and Site A routers under router ospf 1 vrf abc
D. configure capability vrf-lite on Head Office and Site A routers under router ospf 1 vrf abc
Correct Answer: D
Section: New Enarsi Questions (September Update)
QUESTION 21
Which configuration adds an IPv4 interface to an OSPFv3 process in OSPFv3 address family configuration?
A. router ospfv3 1
address-family ipv4
B. Router(config-router)#ospfv3 1 ipv4 area 0
C. Router(config-if)#ospfv3 1 ipv4 area 0
D. router ospfv3 1
address-family ipv4 unicast
Correct Answer: C
Section: OSPF & EIGRP Questions
QUESTION 22
Refer to the exhibit. User in the branch network of 2001:db8:0:4 report they cannot access the internet. Which command is issued in IPv6 router EIGRP 100
configuration mode to solve this issue?
A. Issue the eigrp stub command on R1
B. Issue the no eigrp stub command on R1
C. Issue the eigrp stub command on R2
D. Issue the no eigrp stub command on R2
Correct Answer: B
Section: OSPF & EIGRP Questions
QUESTION 23
Refer to the exhibit. An engineer configuration a static route on a router, but when the engineer checks the route to the destination, a different next hop is
chosen. What is the reason for this?
A. The configured AD for the static route is higher than the AD of OSPF
B. The metric of the OSPF route is lower than the metric of the static route
C. Dynamic routing protocol always have priority over static routes
D. The syntax of the static route is not valid do the route is not considered
Correct Answer: A
Section: OSPF & EIGRP Questions
QUESTION 24
Refer to the exhibit. An engineer is trying to generate a summary route in OSPF for network 10.0.0.0/8, but the summary route does not show up in the
routing table. Why is the summary route missing?
A. The summary route is not visible on this router, but it is visible on other OSPF routers in the same area
B. The summary-address command is used only for summary prefixes between areas
C. The summary route is visible only in the OSPF database not in the routing table
D. There is no route for a subnet inside 10.0.0.0/8, so the summary route is not generated
Correct Answer: D
Section: OSPF & EIGRP Questions
QUESTION 25
Refer to the exhibit. Which option describes why the EIGRP neighbors of this router are not learning routes that are received from OSPF?
Correct Answer: B
Section: OSPF & EIGRP Questions
QUESTION 26
Refer to the exhibit. R2 is a route reflector, and R1 and R3 are route reflector clients. The router R2 learns the route to 172.16.25.0/24 from R1, but it does
not advertise to R3. What is the reason the route is not advertised?
A. Route reflector setup requires full BGP mesh between the routers
B. In route reflector setup only classification prefix are advertised from one client to another
C. In route reflector setup only classful prefix are advertised to other clients
D. R2 does not have a route to the next hop, so R2 does not advertise the prefix to the clients
Correct Answer: D
Section: BGP Questions
QUESTION 27
Refer to the exhibit. Which control plan policy limits BGP traffic that is destined to the CPU to 1 Mbps and ignores BGP traffic that is higher rate?
A. policy-map SHAPE_BGP
B. policy-map LIMIT_BGP
C. policy-map POLICE_BGP
D. policy-map COPP
Correct Answer: D
Section: BGP Questions
QUESTION 28
Refer to the exhibit. A router receiving BGP routing updates from multiple neighbors for routers in AS 690. What is the reason that the router still sends traffic
that is destined to AS 690 to a neighbor other than 10.222.10.1?
A. The local preference value in another neighbor statement is higher than 250
B. The local preference value should be set to the same value as the weight in the route map
C. The route map is applied in the wrong direction
D. The weight value in another statement is higher than 200
Correct Answer: D
Section: BGP Questions
QUESTION 29
Refer to the exhibit. What is the result if applying this configuration?
A. The router can form BGP neighborships with any other device
B. The router can form BGP neighborships with any device that matched by the access list named "BGP"
C. The router cannot form BGP neighborships with any other device
D. The router cannot form BGP neighborships with any device that is matched by the access list named "BGP"
Correct Answer: D
Section: BGP Questions
QUESTION 30
Refer to the exhibit, in which circumstance does the BGP neighbor remain in the idle condition?
A. if prefixes are not received from the BGP peer
B. if prefixes reach the maximum limit
C. if a prefix list is applied on the inbound direction
D. if prefixes exceed the maximum limit
Correct Answer: D
Section: BGP Questions
QUESTION 31
R2 has a locally originated prefix 192.168.130.0/24 and has these configurations:
What is the result when the route-map OUT command is applied toward an eBGP neighbor R1 (1.1.1.1) by using the "neighbor 1.1.1.1 route-map OUT out"
command?
Correct Answer: A
Section: Route-map Questions
QUESTION 32
Refer to the exhibit. An engineer is trying to block the route to 192.168.2.2 from the routing table by using the configuration that is shown. The route is still
present in the routing table as an OSPF route. Which action blocks the route?
A. Add this statement to the route map "route-map RM-OSPF-DL deny 20"
B. Use a prefix list instead of an access list in the route map
C. Change sequence 10 in the route-map command from permit to deny
D. Use an extended access list instead of a standard access list
Correct Answer: C
Section: Route-map Questions
QUESTION 33
Refer to the exhibit. Which configuration configures a policy on R1 to forward any traffic that is sourced from the 192.168.130.0/24 network to R2?
A. access-list 1 permit 192.168.130.0 0.0.0.255
!
interface Gi0/2
ip policy route-map test
!
route-map test permit 10
match ip address 1
set ip next-hop 172.20.20.2
B. access-list 1 permit 192.168.130.0 0.0.0.255
!
interface Gi0/2
ip policy route-map test
!
route-map test permit 10
match ip address 1
set ip next-hop 172.20.20.1
C. access-list 1 permit 192.168.130.0 0.0.0.255
!
interface Gi0/1
ip policy route-map test
!
route-map test permit 10
match ip address 1
set ip next-hop 172.20.40.2
D. access-list 1 permit 192.168.130.0 0.0.0.255
!
interface Gi0/1
ip policy route-map test
!
route-map test permit 10
match ip address 1
set ip next-hop 172.20.40.1
E. access-list 1 permit 192.168.130.0 0.0.0.255
!
interface Gi0/1
ip policy route-map test
!
route-map test permit 10
match ip address 1
set ip next-hop 172.20.20.1
Correct Answer: D
Section: Route-map Questions
QUESTION 34
Refer to the exhibit. Which statement about R1 is true?
QUESTION 35
Refer to the exhibit. Which routes from OSPF process 5 are redistributed into EIGRP?
Correct Answer: A
Section: Redistribution Questions
QUESTION 36
Refer to Exhibit. Which statement about redistribution from BGP into OSPF process 10 is true?
A. Network 172.16.1.0/24 is not redistributed into OSPF
B. Network 10.10 10.0/24 is not redistributed into OSPF
C. Network 172.16.1.0/24 is redistributed with administrative distance of 1
D. Network 10.10.10.0/24 is redistributed with administrative distance of 20
Correct Answer: A
Section: Redistribution Questions
QUESTION 37
Which two statements about redistributing EIGRP into OSPF are true? (Choose two)
A. The redistributed EIGRP routes appear as type 3 LSAs in the OSPF database
B. The redistributed EIGRP routes appear as type 5 LSAs in the OSPF database
C. The administrative distance of the redistributed routes is 170
D. The redistributed EIGRP routes appear as OSPF external type 1
E. The redistributed EIGRP routes as placed into an OSPF area whose area ID matches the EIGRP autonomous system number
F. The redistributed EIGRP routes appear as OSPF external type 2 routes in the routing table
Correct Answer: BF
Section: Redistribution Questions
QUESTION 38
Refer to the exhibit. After redistribution is enabled between the routing protocols, PC2, PC3, and PC4 cannot reach PC1. Which action can the engineer take
to solve the issue so that all the PCs are reachable?
Correct Answer: A
Section: Redistribution Questions
QUESTION 39
Refer to the exhibit. Which subnet is redistributed from EIGRP to OSPF routing protocols?
A. 10.2.2.0/24
B. 10.1.4.0/24
C. 10.1.2.0/24
D. 10.2.3.0/26
Correct Answer: A
Section: Redistribution Questions
QUESTION 40
Refer to the exhibit. An engineer is trying to redistribute OSPF to BGP, but not all of the routes are redistributed. What is the reason for this issue?
Correct Answer: A
Section: Redistribution Questions
QUESTION 41
Refer to the exhibit The output of the trace from R5 shows a loop in the network.
Which configuration prevents this loop?
A. R3
router ospf 1
redistribute eigrp 1 subnets route-map SETTAG
!
route-map SET-TAG permit 10
set tag 1
R4
router eigrp 1
redistribute ospf 1 metric 2000000 1 255 1
1500 route-map FILTER-TAG
!
route-map FILTER-TAG deny 10
match tag 1
!
route-map FILTER-TAG permit 20
B. R3
router eigrp 1
redistribute ospf 1 subnets route-map SETTAG
!
route-map SET-TAG permit 10
set tag 1
R4
router eigrp 1
redistribute ospf 1 metric 2000000 1 255 1
1500 route-map FILTER-TAG
network 10.1.24.4 0.0.0.0
!
route-map FILTER-TAG deny 10
match tag 1
!
route-map FILTER-TAG permit 20
C. R3
router ospf 1
redistribute eigrp 1 subnets route-map SETTAG
!
route-map SET-TAG permit 10
set tag 1
R4
router eigrp 1
redistribute ospf 1 metric 2000000 1 255 1
1500 route-map FILTER-TAG
!
route-map FILTER-TAG permit 10
match tag 1
D. R3
router ospf 1
redistribute eigrp 1 subnets route-map SETTAG
!
route-map SET-TAG deny 10
set tag 1
R4
router eigrp 1
redistribute ospf 1 metric 2000000 1 255 1
1500 route-map FILTER-TAG
!
route-map FILTER-TAG deny 10
match tag 1
Correct Answer: A
Section: Redistribution Questions
QUESTION 42
Which transport layer protocol is used to form LDP sessions?
A. UDP
B. SCTP
C. TCP
D. RDP
Correct Answer: C
Section: MPLS Questions
QUESTION 43
Which statement about MPLS LDP router ID is true?
A. The force keyword changes the router ID to the specific address causing any impact
B. The loopback with the highest IP address is selected as the router ID
C. If not configured, the operational physical interface is chosen as the router ID even if a loopback is configured
D. If MPLS LDP router ID must match the IGP router ID
Correct Answer: B
Section: MPLS Questions
QUESTION 44
Which command allows traffic to load-balance in an MPLS Layer 3 VPN configuration?
A. Multi-paths eibgp 2
B. Maximum-paths ibgp 2
C. Multi-paths 2
D. Maximum-paths 2
Correct Answer: D
Section: MPLS Questions
QUESTION 45
Refer to the exhibit. What does the imp-null tag represent in the MPLS VPN cloud?
A. Include the EXP bit
B. Exclude the EXP bit
C. Impose the label
D. Pop the label
Correct Answer: D
Section: MPLS Questions
QUESTION 46
Which list defines the contents of an MPLS label?
A. 20-bit label; 3-bit traffic class; 1 -bit bottom stack; 8-bit TTL
B. 32-bit label; 3-bit flow label; 1-bit bottom stack; 8-bit hop limit
C. 20-bit label; 3-bit flow label; 1-bit bottom stack; 8-bit hop limit
D. 32-bit label; 3-bit traffic class; 1 -bit bottom stack; 8-bit TTL
Correct Answer: A
Section: MPLS Questions
QUESTION 47
What statement about route distinguishes in an MPLS network is true?
A. Route distinguishers make a unique VPNv4 address across the MPLS network
B. Route distinguishers allow multiple instances of a routing table to coexist within the edge router
C. Route distinguishers are used for label bindings
D. Route distinguishers define which prefixes are imported and exported on the edge router
Correct Answer: A
Section: MPLS Questions
QUESTION 48
What is the output of the following command:
Correct Answer: A
Section: VRF-Lite Questions
QUESTION 49
Which protocol does VRF-Lite support?
A. IS-IS
B. ODR
C. EIGRP
D. IGRP
Correct Answer: C
Section: VRF-Lite Questions
QUESTION 50
Which two statements about VRF-Lite configurations are true? (Choose two)
Correct Answer: BE
Section: VRF-Lite Questions
QUESTION 51
What is the role of a route distinguisher via a VRF-Lite setup implementation?
Correct Answer: A
Section: VRF-Lite Questions
QUESTION 52
Which command displays the IP routing table information that is associated with VRF-Lite?
A. show ip vrf
B. show ip route vrf
C. show run vrf
D. show ip protocols vrf
Correct Answer: B
Section: VRF-Lite Questions
QUESTION 53
Which configuration enables the VRF that is labeled "inet" on FastEthernet0/0?
A. R1(config)# ip vrf Inet
R1(config-vrf)#ip vrf FastEthernet0/0
B. R1 (conflg)#ip vrf Inet FastEthernet0/0
C. R1(config)# ip vrf Inet
R1(config-vrf)#interface FastEthernet0/0
R1(config-if)#ip vrf forwarding Inet
D. R1 (config)#router ospf 1 vrf Inet
R1 (config-router)#ip vrf forwarding FastEthernet0/0
Correct Answer: C
Section: VRF-Lite Questions
QUESTION 54
Which protocol is used to determine the NBMA address on the other end of a tunnel when mGRE is used?
A. NHRP
B. IPsec
C. MP-BGP
D. OSPF
Correct Answer: A
Section: DMVPN Questions
QUESTION 55
Refer to the exhibits. Phase-3 tunnels cannot be established between spoke-to-spoke in DMWN. Which two commands are missing? (Choose two)
A. The ip nhrp redirect command is missing on the spoke routers.
B. The ip nhrp shortcut command is missing on the spoke routers.
C. The ip redirect commands is missing on the hub router.
D. The ip shortcut commands is missing on the hub router.
E. The ip nhrp command is missing on the hub router.
Correct Answer: BC
Section: DMVPN Questions
QUESTION 56
Refer to the following output:
What does the authoritative flag mean in regards to the NHRP information?
Correct Answer: A
Section: DMVPN Questions
QUESTION 57
Which Cisco VPN technology can use multipoint tunnel, resulting in a single GRE tunnel interface on the hub, to support multiple connections from multiple
spoke devices?
A. DMVPN
B. GETVPN
C. Cisco Easy VPN
D. FlexVPN
Correct Answer: A
Section: DMVPN Questions
QUESTION 58
Which protocol is used in a DMVPN network to map physical IP addresses to logical IP addresses?
A. BGP
B. LLDP
C. EIGRP
D. NHRP
Correct Answer: D
Section: DMVPN Questions
QUESTION 59
Which two methods use IPsec to provide secure connectivity from the branch office to the headquarters office? (Choose two)
A. DMVPN
B. MPLS VPN
C. Virtual Tunnel Interface (VTI)
D. SSL VPN
E. PPPoE
Correct Answer: AC
Section: DMVPN Questions
QUESTION 60
Refer to the exhibit. Which interface configuration must be configured on the spoke A to enable a dynamic DMVPN tunnel with the spoke B router?
A. interface Tunnel0
description mGRE – DMVPN Tunnel
ip address 10.0.0.11 255.255.255.0
ip nhrp map multicast dynamic
ip nhrp network-id 1
tunnel source 10.0.0.1
tunnel destination FastEthernet0/0
tunnel mode gre multipoint
B. interface Tunnel0
ip address 10.1.0.11 255.255.255.0
ip nhrp network-id 1
tunnel source 1.1.1.10
ip nhrp map 10.0.0.11 172.17.0.2
tunnel mode gre
C. interface Tunnel0
ip address 10.0.0.11 255.255.255.0
ip nhrp map multicast static
ip nhrp network-id 1
tunnel source 10.0.0.1
tunnel mode gre multipoint
D. interface Tunnel0
ip address 10.0.0.11 255.255.255.0
ip nhrp network-id 1
tunnel source FastEthernet0/0
tunnel mode gre multipoint
ip nhrp nhs 10.0.0.1
ip nhrp map 10.0.0.1 172.17.0.1
Correct Answer: D
Section: DMVPN Questions
QUESTION 61
Which security feature can protect DMVPN tunnels?
A. IPsec
B. TACACS+
C. RTBH
D. RADIUS
Correct Answer: A
Section: DMVPN Questions
QUESTION 62
Refer to the exhibit. After applying IPsec, the engineer observed that the DMVPN tunnel went down, and both spoke-to-spoke and hub were not establishing.
Which two actions resolved the issue? (Choose two)
A. Configure the crypto isakmp key cisco address 0.0.0.0 on R2 and R3
B. Remove the crypto isakmp key cisco address 10.1.1.1 on R2 and R3
C. Change the mode from mode transport to mode tunnel on R2
D. Configure the mode from mode tunnel to mode transport on R3
E. Configure the crypto isakmp key cisco address 192.1.1.1 on R2 and R3.
Correct Answer: AD
Section: DMVPN Questions
QUESTION 63
Refer to the exhibit. An engineer is trying to configure local authentication on the console line, but the device is trying to authenticate using TACACS+. Which
action produces the desired configuration?
A. Add the aaa authentication login default group tacacs+ local-case command to the global configuration
B. Add the login authentication Console command to the line configuration
C. Replace the capital "C" with a lowercase "c" in the aaa authentication login Console local command
D. Add the aaa authentication login default none command to the global configuration
Correct Answer: B
Section: AAA Questions
QUESTION 64
Refer to the exhibit. Why is user authentication being rejected?
A. The TACACS+ server expects "user" but the NT client sends "domain\user"
B. The TACACS+ server refuses the user because the user is set up for CHAP
C. The TACACS+ server is down and the user is in the local database
D. The TACACS+ server is down and the user is not in the local database
Correct Answer: D
Section: AAA Questions
QUESTION 65
Refer to the exhibit. An administrator noticed that after a change was made on R1, the timestamps on the system logs did not match the clock. What is the
reasons for this error?
A. The keyword localtime is not defined on the timestamp service command
B. The NTP server is in an different time zone
C. An authentication error with the NTP server results in an incorrect timestamp
D. The system clock is set incorrectly to summer-time hours
Correct Answer: A
Section: NTP Questions
QUESTION 66
Refer to the exhibit An engineer is troubleshooting BGP on a device but discovers that the clock on the device does not correspond to the time stamp of the
log entries. Which action ensures consistency between the two times?
A. Configure the logging clock synchronize command in global configuration mode
B. Configure the service timestamps log uptime command in global configuration mode
C. Configure the service timestamps log datetime localtime command in global configuration mode
D. Make sure that the clock on the device is synchronized with an NTP server
Correct Answer: C
Section: NTP Questions
QUESTION 67
A network engineer is investigating a flapping (up/down) interface issue on a core switch that is synchronized to an NTP server. Log output does not show the
time of the flap.
Which command allows on the switch the time of the flap according to the dock on the device?
A. clock calendar-valid
B. service timestamps log datetime localtime show-timezone
C. service timestamps log uptime
D. dock summer-time mst recurring 2 Sunday mar 2:00 1 Sunday nov 2:00
Correct Answer: B
Section: NTP Questions
QUESTION 68
Refer to the exhibit. During troubleshooting it was discovered that the device is not reachable using a secure web browser. What is needed to fix the
problem?
A. permit tcp port 465
B. permit tcp port 443
C. permit udp port 465
D. permit tcp port 22
Correct Answer: B
Section: Access-list Questions
QUESTION 69
Refer to the exhibit. Which configuration denies Telnet traffic to router 2 from 198A:0:200C::1/64?
Correct Answer: D
Section: Access-list Questions
QUESTION 70
While troubleshooting connectivity issues to a router, these details are noticed:
Correct Answer: A
Section: Control Plane Questions
QUESTION 71
Refer to the exhibit. An engineer is trying to connect to a device with SSH but cannot connect. The engineer connects by using the console and find the
displayed output when troubleshooting. Which command must be used in configuration mode to enable SSH on the device?
Correct Answer: A
Section: Control Plane Questions
QUESTION 72
Which option is the best for protecting CPU utilization on a device?
A. fragmentation
B. COPP
C. ICMP redirects
D. ICMP unreachable messages
Correct Answer: B
Section: Control Plane Questions
QUESTION 73
An engineer is trying to copy an IOS file from one router to another router by using TFTP. Which two actions are needed to allow the file to copy? (Choose
two)
A. Configure the TFTP authentication on the source router with the "tftp-server authentication local" command.
B. Configure a user on the source router with the username tftp password tftp command.
C. Enable the TFTP server on the source router with the tftp-server flash:<filename> command.
D. TFTP is not supported in recent IOS versions, so an alternative method must be used.
E. Copy the file to the destination router with the copy tftp: flash: command
Correct Answer: CE
Section: Control Plane Questions
QUESTION 74
Which is statement about IPv6 inspection is true?
A. It learns and secures bindings for stateless autoconfiguration addresses in Layer 3 neighbor tables
B. It learns and secures bindings for stateful autoconfiguration addresses in Layer 3 neighbor tables
C. It learns and secures bindings for stateful autoconfiguration addresses in Layer 2 neighbor tables
D. It learns and secures binding for stateless autoconfiguration addresses in Layer 2 neighbor tables
Correct Answer: D
Section: IPv6 Questions
QUESTION 75
Which statement about IPv6 RA Guard is true?
Correct Answer: A
Section: IPv6 Questions
QUESTION 76
Which command is used to check IP SLA when an interface is suspected to receive lots of traffic with options?
A. show track
B. show threshold
C. show timer
D. show delay
Correct Answer: A
Section: IP SLA Questions
QUESTION 77
Refer to the exhibit. ISP 1 and ISP 2 directly connect to the internet. A customer is tracking both ISP links to achieve redundancy and cannot see the Cisco IP
SLA tracking output on the router console. Which command is missing from the IP SLA configuration?
A. Start-time now
B. Start-time 00:00
C. Start-time 0
D. Start-time immediately
Correct Answer: A
Section: IP SLA Questions
QUESTION 78
A network engineer needs to verify IP SLA operations on an interface that shows on indication of excessive traffic. Which command should the engineer use
to complete this action?
A. show frequency
B. show track
C. show reachability
D. show threshold
Correct Answer: B
Section: IP SLA Questions
QUESTION 79
Refer to the exhibit. An IP SLA was configured on router R1 that allows the default route to be modified in the event that Fa0/0 losses reachability with the
router R3 Fa0/0 interface. The route has changed to flow through route R2.
Correct Answer: C
Section: IP SLA Questions
QUESTION 80
Which SNMP verification command shows the encryption and authentication protocols that are used in SNMPv3?
Correct Answer: B
Section: SNMP Questions
QUESTION 81
Refer to the exhibit. Network operations cannot read or write an configuration on the device with this configuration from the operation subnet. Which two
configuration fix the issue? (Choose two)
A. Configure SNMP rw permission in addition to community ciscotest
B. Modify access list 1 and allow operations subnet in the access list
C. Modify access list 1 and allow SNMP in the access list
D. Configure SNMP rw permission in addition to version 1
E. Configure SNMP rw permission in addition to community ciscotest 1
Correct Answer: AB
Section: SNMP Questions
QUESTION 82
Users were moved from the local DHCP server to the remote corporate DHCP server. After the move, none of the users were able to use the network. Which
two issues will prevent this setup from working property? (Choose two)
Correct Answer: BE
Section: DHCP Questions
QUESTION 83
Refer to the exhibit. Users report that IP addresses cannot be acquired from the DHCP server. The DHCP server is configured as shown. About 300 total
nonconcurrent users are using this DHCP server, but none of them are active for more than two hours per day.
Correct Answer: D
Section: DHCP Questions
QUESTION 84
An engineer configured the wrong default gateway for the Cisco DNA center enterprise interface during the install. Which command must the engineer run to
correct the configuration?
Correct Answer: C
Section: DNA Center Questions
QUESTION 85
When provisioning a device in Cisco DNA Center, the engineer sees the error message "Cannot select the device. Not compatible with template.". What is
the reason for the error?
A. The software version of the template is different from the software version of the device
B. The changes to the template were not committed
C. The template has an incorrect configuration
D. The tag that was used to filter the templates does not match the device tag
Correct Answer: D
Section: DNA Center Questions
QUESTION 86
While working with software images, an engineer observes that Cisco DNA Center cannot upload its software image directly from the device. Why is the
image not uploading?
Correct Answer: C
Section: DNA Center Questions
QUESTION 87
Drag and drop the MPLS VPN concepts from the left onto the correct descriptions on the right.
QUESTION 88
Drag and drop the address from the left onto the correct IPv6 filter purposes on the right.
Select and Place:
Correct Answer:
Section: Drag Drop Questions
QUESTION 89
Drag and drop the packet from the left onto the correct descriptions on the right.
Select and Place:
Correct Answer:
Section: Drag Drop Questions
QUESTION 90
Drag and drop the SNMP attributes in Cisco IOS devices from the onto the correct SNMPv2c or SNMPv3 categories on the right.
Select and Place:
Correct Answer:
Section: Drag Drop Questions
QUESTION 91
Drag and drop the MPLS terms from the left onto the correct definitions on the right.
Select and Place:
Correct Answer:
Section: Drag Drop Questions
QUESTION 92
Drag and drop the OSPF adjacency states from the left onto the correct descriptions on the right
Select and Place:
Correct Answer:
Section: Drag Drop Questions
QUESTION 93
Drag and drop the DHCP messages from the left onto the correct uses on the right.
Select and Place:
Correct Answer:
Section: Drag Drop Questions
QUESTION 94
What is a prerequisite for configuring BFD?
A. All routers in the path between two BFD endpoints must have BFD enabled
B. Jumbo frame support must be configured on the router that is using BFD
C. Cisco Express Forwarding must be enabled on all participating BFD endpoints
D. To use BFD with BGP, the timers 3 9 command must first be configured in the BGP routing process
Correct Answer: C
Section: Miscellaneous Questions
QUESTION 95
Which two protocols can cause TCP starvation? (Choose two)
A. TFTP
B. SNMP
C. SMTP
D. HTTPS
E. FTP
Correct Answer: AB
Section: Miscellaneous Questions
QUESTION 96
Which method changes the forwarding decision that a router makes without first changing the routing table or influencing the IP data plane?
A. Policy-based routing
B. Nonbroadcast multi-access
C. Packet switching
D. Forwarding information base
Correct Answer: A
Section: Miscellaneous Questions
QUESTION 97
Which attribute eliminates LFAs that belong to protected paths in situations where links in a network are connected through a common fiber?
A. Interface-dispoint
B. Shared risk link group-disjoint
C. Linecard-disjoint
D. Lowest-repair-path-metric
Correct Answer: B
Section: Miscellaneous Questions
QUESTION 98
Refer to the exhibit. An administrator that is connected to the console does not see debug messages when remote users log in. Which action ensures that
debug messages are displayed for remote loggings?
A. Enter the transport input ssh configuration command
B. Enter the terminal monitor exec command
C. Enter the logging console debugging configuration command
D. Enter the aaa new-model configuration command
Correct Answer: C
Section: Miscellaneous Questions
QUESTION 99
Refer to the exhibit. Why is the remote NetFlow server failing to receive the NetFlow data?
A. The flow exporter is configured but is not used.
B. The flow monitor is applied in the wrong direction.
C. The flow monitor is applied to the wrong interface.
D. The destination of the flow exporter is not reachable.
Correct Answer: A
Section: Miscellaneous Questions
QUESTION 100
Given the network diagram, which address would successfully summarize only the networks seen?
A. 192.168.0.0/24
B. 192.168.8.0/20
C. 192.168.8.0/21
D. 192.168.12.0/20
E. 192.168.16.0/21
F. These networks cannot be summarized.
Correct Answer: C
Section: Miscellaneous Questions
QUESTION 101
Drag and drop the MPLS VPN device types from me left onto the definitions on the right.
QUESTION 102
To provide reachability to network 10.1.1.0/24 from R5, the network administrator redistributes EIGRP into OSPF on R3 but notices that R4 is now taking a
suboptimal path through R5 to reach 10.1.1.0/24 network. Which action fixes the issue while keeping the reachability from R5 to 10.1.1.0/24 network?
A. Change the administrative distance of OSPF to 200 on R5.
B. Change the administrative distance of the external EIGRP to 90.
C. Apply the outbound distribution list on R5 toward R4 in OSPF.
Correct Answer: B
Section: New Enarsi Questions 2 (November Update)
QUESTION 103
An engineer is configuring a network and needs packets to be forwarded to an interface for any destination address that is not in the routing table. What
should be configured to accomplish this task?
A. set ip next-hop
B. set ip default next-hop
C. set ip next-hop recursive
D. set ip next-hop verify-availability
Correct Answer: B
Section: New Enarsi Questions 2 (November Update)
QUESTION 104
Refer to the exhibit.
An engineer has configured DMVPN on a spoke router. What is the WAN IP address of another spoke router within the DMVPN network?
A. 192.168.1.1
B. 172.18.16.2
C. 192.168.1.4
D. 172.18.46.2
Correct Answer: D
Section: New Enarsi Questions 2 (November Update)
QUESTION 105
Refer to the exhibit.
R1 is connected with R2 via GigabitEthernet0/0, and R2 cannot ping R1. What action will fix the issue?
Correct Answer: C
Section: New Enarsi Questions 2 (November Update)
QUESTION 106
Refer to the exhibit.
The server for the finance department is not reachable consistently on the 200.30.40.0/24 network and after every second month it gets a new IP address.
Which two actions must be taken to resolve this issue? (Choose two)
Correct Answer: AC
Section: New Enarsi Questions 2 (November Update)
QUESTION 107
Which protocol does MPLS use to support traffic engineering?
Correct Answer: D
Section: New Enarsi Questions 2 (November Update)
QUESTION 108
Drag and Drop the IPv6 First-Hop Security features from the left onto the definitions on the right.
Select and Place:
Correct Answer:
QUESTION 109
Refer to the exhibit.
R1 is being monitored using SNMP and monitoring devices are getting only partial information. What action should be taken to resolve this issue?
Correct Answer: A
Section: New Enarsi Questions 2 (November Update)
QUESTION 110
Refer to the exhibit.
A network engineer for AS64512 must remove the inbound and outbound traffic from link A during maintenance without closing the BGP session. Traffic
should flow via the backup link toward the ASN. Which BGP configuration on R1 accomplishes this goal?
Correct Answer: D
Section: New Enarsi Questions 2 (November Update)
QUESTION 111
Refer to the exhibit. A client is concerned that passwords are visible when running this show archive log config all.
A. MASS-RTR(config-archive-log-cfg)#hidekeys
B. MASS-RTR(config-archive-log-cfg)#password encryption aes
C. MASS-RTR(config)#service password-encryption
D. MASS-RTR(config)#aaa authentication arap
Correct Answer: A
Section: New Enarsi Questions 2 (November Update)
QUESTION 112
Which IGPs are supported by the MPLS LDP autoconfiguration feature?
Correct Answer: C
Section: New Enarsi Questions 2 (November Update)
QUESTION 113
What does the PE router convert the IPv4 prefix to within an MPLS VPN?
Correct Answer: B
Section: New Enarsi Questions 2 (November Update)
QUESTION 114
Refer to the exhibit.
Which two actions should be taken to access the server? (Choose two)
A. Modify the access list to add a second line of permit ip any any
B. Modify the access list to deny the route to 192.168.2.2
C. Modify distribute list seq 10 to permit the route to 192.168.2.2
D. Add a sequence 20 in the route map to permit access list 1
E. Add a floating static route to reach to 192.168.2.2 with administrative distance higher than OSPF
Correct Answer: BE
Section: New Enarsi Questions 2 (November Update)
QUESTION 115
Refer to the exhibit.
An engineer wanted to set a tag of 30 to route 10.1.80.65/32 but it failed. How is the issue fixed?
Correct Answer: B
Section: New Enarsi Questions 2 (November Update)
QUESTION 116
What does IPv6 Source Guard utilize to determine if IPv6 source addresses should be forwarded?
A. Binding Table
B. ACLS
C. ACE
D. DHCP
Correct Answer: A
Section: New Enarsi Questions 2 (November Update)
QUESTION 117
An engineer needs dynamic routing between two routers and is unable to establish OSPF adjacency. The output of the show ip ospf neighbor command
shows that the neighbor state is EXSTART/EXCHANGE. Which action should be taken to resolve this issue?
Correct Answer: C
Section: New Enarsi Questions 2 (November Update)
QUESTION 118
A network administrator configured an IPv6 access list to allow TCP return frame only, but it is not working as expected. Which changes resolve this issue?
Correct Answer: C
Section: New Enarsi Questions 2 (November Update)
QUESTION 119
Refer to the exhibit.
A user cannot SSH to the router. What action must be taken to resolve this issue?
Correct Answer: A
Section: New Enarsi Questions 2 (November Update)
QUESTION 120
Refer to the exhibit. Which interface configuration must be configured on the HUB router to enable DMVPN with mGRE mode?
A. Option A
B. Option B
C. Option C
D. Option D
Correct Answer:
Section: New Enarsi Questions 2 (November Update)
QUESTION 121
Refer to the exhibit.
An IT staff member comes into the office during normal office hours and cannot access devices through SSH. Which action should be taken to resolve this
issue?
Correct Answer: A
Section: New Enarsi Questions 2 (November Update)
QUESTION 122
Refer to the exhibit.
An engineer receives this error message when trying to access another router m-band from the serial interface connected to the console of R1. Which
configuration is needed on R1 to resolve this issue?
A. R1(config)#line console 0
R1(config-line)#transport preferred ssh
B. R1(config)#line vty 0
R1(config-line)#transport output ssh
C. R1(config)#line vty 0
R1(config-line)#transport output ssh
R1(config-line)#transport preferred ssh
D. R1(config)#line console 0
R1(config-line)#transport output ssh
Correct Answer:
Section: New Enarsi Questions 2 (November Update)