CCIE Enterprise Infrastructure Quiz 2

Welcome to CCIE Enterprise Infrastructure Quiz 2! In this quiz, you will find CCIE Enterprise Infrastructure practice questions on routing protocols, switching, MPLS, QoS, multicast, IPv6 and Cisco configurations. With these CCIE practice questions, you can test your knowledge, review important networking topics and prepare for your CCIE Enterprise Infrastructure certification.

CCIE Enterprise Infrastructure Practice Test 2

  CONGRATULATIONS! YOU HAVE COMPLETED CCIE Enterprise Infrastructure Practice Test 2. YOU HAVE %%SCORE%% TRUE ANSWERS OUT OF %%TOTAL%% QUESTIONS. YOUR SCORE IS %%PERCENTAGE%%. %%RATING%%  
Your answers are highlighted below.
Question 1
A network engineer suspects physical-layer problems on several interfaces of a Cisco Catalyst switch. Which command provides a summary of interface error counters, including CRC and input errors?
A
show mac address-table
B
show interfaces trunk
C
show spanning-tree summary
D
show ip interface brief
E
show interfaces counters errors
Question 1 Explanation: 
On supported Cisco Catalyst switches, show interfaces counters errors displays interface error counters and helps identify physical-layer problems such as CRC errors.
Question 2
Two Cisco routers participate in HSRP Group 10. Both routers have a priority of 110. R1 uses interface IP address 192.168.10.2, while R2 uses 192.168.10.3. Assuming both routers are eligible and no other election conditions differ, which router becomes Active?
A
The router with the lower MAC address
B
The router with the lower interface bandwidth
C
R2 because it has the higher IP address
D
Both routers become Active
E
R1 because it has the lower IP address
Question 2 Explanation: 
When HSRP priorities are equal, the router with the higher interface IP address wins the Active Router election.
Question 3
A company has two eBGP connections to different ISPs. The network administrator wants all internal BGP routers to prefer ISP-A for outbound traffic. Which BGP attribute should be increased on routes learned from ISP-A?
A
Local Preference
B
Router ID
C
MED
D
Origin code
E
AS_PATH length
Question 3 Explanation: 
Local Preference influences outbound path selection within an autonomous system. Routes with a higher Local Preference are preferred by internal BGP routers.
Question 4
A Cisco router receives two eligible eBGP paths to the same prefix. Both paths satisfy the BGP multipath requirements, but only one path is installed for forwarding. Which configuration feature allows multiple eligible eBGP paths to be installed?
A
BGP Next-Hop Self
B
BGP AS_PATH Prepending
C
BGP Graceful Restart
D
BGP Maximum Paths
E
BGP Route Refresh
Question 4 Explanation: 
The BGP maximum-paths feature allows multiple eligible BGP paths to be installed for multipath forwarding when the required path-selection conditions are satisfied.
Question 5
A branch site has two Cisco SD-WAN WAN Edge routers. Edge1 has an MPLS transport connection, while Edge2 has an Internet transport connection. The administrator wants both routers to use both transport networks without adding separate physical WAN connections to each router. Which Cisco SD-WAN feature supports this design? ccie-enterprise-infrastructure-Cisco-SD-WAN-example-question
A
TLOC Extension
B
Application-Aware Routing
C
BFD Echo Mode
D
OMP Route Redistribution
E
Centralized Control Policy
Question 5 Explanation: 
Cisco SD-WAN TLOC Extension allows WAN Edge routers at the same site to share transport connectivity. Each router can use a transport network connected to the other router through a TLOC extension interface.
Question 6
A Cisco SD-WAN network uses two transport paths between branch offices: MPLS and Internet. A business-critical application requires low latency and packet loss. Which Cisco SD-WAN feature dynamically selects a transport path based on measured SLA performance? Cisco-SD-WAN-path-selection-ccie-enterprise-infrastructure
A
TLOC Extension
B
OMP Route Aggregation
C
Control Policy Route Filtering
D
Application-Aware Routing
E
BGP AS_PATH Prepending
Question 6 Explanation: 
Cisco SD-WAN Application-Aware Routing uses performance measurements such as latency, loss and jitter to select transport paths that satisfy an application's configured SLA requirements.
Question 7
Two Cisco routers are connected through an Ethernet link and run OSPF in Area 0. Their Hello and Dead intervals, Area IDs, and authentication settings match. However, the OSPF adjacency remains stuck in the ExStart/Exchange state. R1 has an interface MTU of 1500 bytes, while R2 has an interface MTU of 1400 bytes. What is the recommended solution? OSPF-MTU-missmatch-ccie-question
A
Increase the OSPF Hello interval on R2.
B
Configure both routers with the same OSPF Router ID.
C
Configure matching interface MTU values on both routers.
D
Configure both routers as OSPF DRs.
E
Disable OSPF authentication on both routers.
Question 7 Explanation: 
An MTU mismatch can prevent OSPF neighbors from progressing beyond the ExStart/Exchange states because of the MTU field in Database Description packets. Configuring compatible interface MTU values resolves the mismatch. The ip ospf mtu-ignore command can bypass the OSPF MTU check, but correcting the underlying MTU mismatch is generally preferred.
Question 8
An enterprise uses private BGP AS numbers internally and connects to an external ISP. The ISP wants to remove private AS numbers from the AS_PATH before advertising routes to the public Internet. Which BGP feature is used for this purpose?
A
AS_PATH Prepending
B
Remove Private AS
C
BGP Multipath
D
BGP Route Reflection
E
Local Preference
Question 8 Explanation: 
The BGP remove-private-as feature removes eligible private AS numbers from the AS_PATH when advertising routes to an external BGP neighbor. Its exact behavior depends on the configuration and AS_PATH contents.
Question 9
Two Cisco switches are connected through two Ethernet interfaces. Both interfaces are configured with LACP passive mode on both switches. Why does the EtherChannel fail to form? LACP-modes-EtherChannel-ccie-enterprise-infrastructure
A
LACP requires both interfaces to use static mode
B
LACP supports only Layer 3 EtherChannels
C
LACP passive mode does not initiate negotiation
D
LACP requires PAgP to be enabled
E
Both switches must use different VLAN IDs
Question 9 Explanation: 
LACP passive mode responds to LACP negotiation but does not initiate it. At least one side must use active mode for the EtherChannel to form.
Question 10
A Cisco router receives an IP packet marked with DSCP value 0 (CS0). Which forwarding behavior does this marking represent?
A
Network Control (CS6)
B
Best Effort
C
Assured Forwarding (AF31)
D
Assured Forwarding (AF11)
E
Expedited Forwarding (EF)
Question 11
Two routers participate in VRRP Group 10. R1 has priority 120 and R2 has priority 150. R2 fails, and R1 becomes Master. When R2 returns with preemption enabled, what happens?
A
R1 and R2 begin load balancing automatically
B
R1 remains Master permanently
C
Both routers become Master
D
R2 becomes Master because it has the higher priority
E
VRRP disables the virtual IP address
Question 11 Explanation: 
VRRP uses router priority to elect the Master. When the higher-priority router returns and preemption is enabled, it can take over the Master role.
Question 12
An MPLS router receives label bindings from its LDP neighbors. Which table stores the label bindings learned through label distribution protocols?
A
ARP Table
B
FIB
C
LFIB
D
MAC Address Table
E
LIB
Question 12 Explanation: 
The Label Information Base (LIB) stores label bindings learned through protocols such as LDP. The LFIB is used for MPLS packet forwarding.
Question 13
An EIGRP router loses its successor route and has no feasible successor. It sends Queries to its neighbors but does not receive a required Reply within the expected time. What problem can occur?
A
The route enters a Stuck-in-Active condition
B
EIGRP automatically changes to OSPF
C
The router disables all EIGRP interfaces
D
The router immediately resets its configuration
E
The route becomes an external BGP route
Question 13 Explanation: 
EIGRP can enter a Stuck-in-Active (SIA) condition when a router does not receive required Replies during the active route computation process. Query boundaries and EIGRP stub configurations can help reduce query propagation.
Question 14
Which Cisco IOS BGP configuration command sets the Keepalive timer to 40 seconds and the Hold timer to 120 seconds for neighbor 142.10.1.2?
A
timers 40 120 neighbor 142.10.1.2
B
bgp timers 40 120 neighbor 142.10.1.2
C
neighbor 142.10.1.2 timers 120 40
D
neighbor 142.10.1.2 timers 40 120
E
neighbor 142.10.1.2 set timers 40 120
Question 14 Explanation: 
The neighbor 142.10.1.2 timers 40 120 command configures a 40-second Keepalive interval and a 120-second Hold Time for the specified BGP neighbor.
Question 15
An EIGRP router has a successor route with a Feasible Distance (FD) of 1500. A neighboring router advertises an alternate route with a Reported Distance (RD) of 1400 and a total calculated distance of 1800. How does EIGRP classify the alternate route? EIGRP-route-ccie-enterprise-infrastructure
A
It is rejected because its total distance exceeds 1500
B
It is the successor because its RD is lower
C
It qualifies as a feasible successor
D
It becomes an external EIGRP route
E
It automatically replaces the successor
Question 15 Explanation: 
EIGRP's feasibility condition requires the neighbor's Reported Distance to be lower than the current successor's Feasible Distance. Since 1400 is less than 1500, the alternate route qualifies as a feasible successor.
Question 16
A Cisco switch running Rapid PVST+ detects a topology change when a non-edge port transitions to the Forwarding state. What action does the switch take regarding its MAC address table?
A
Disables all trunk interfaces
B
Increases the STP bridge priority
C
Converts all ports to edge ports
D
Flushes affected dynamically learned MAC entries
E
Clears all VLAN configurations
Question 16 Explanation: 
Rapid STP topology changes trigger MAC address table updates so traffic can be relearned along the new active topology. Edge-port transitions do not normally trigger topology changes.
Question 17
A BGP neighbor remains in the Active state and repeatedly fails to establish a session. Which issue is a likely cause?
A
A lower MED on advertised routes
B
An AS_PATH containing multiple AS numbers
C
A successfully established TCP connection
D
A missing route to the neighbor's IP address
E
A higher Local Preference on received routes
Question 17 Explanation: 
A BGP neighbor in the Active state is attempting to establish a TCP connection. IP reachability problems, incorrect neighbor configuration or TCP port 179 filtering can prevent the session from forming.
Question 18
In Cisco SD-WAN, which protocol distributes routing information, TLOC information and service routes between WAN Edge routers through the control plane?
A
LDP
B
PIM
C
HSRP
D
LACP
E
OMP
Question 18 Explanation: 
Overlay Management Protocol (OMP) is the control-plane protocol used in Cisco SD-WAN to exchange routing, TLOC and service information through SD-WAN controllers.
Question 19
A network automation script uses NETCONF to modify the configuration of a Cisco IOS XE router. Which data encoding format is used by NETCONF for its RPC messages?
A
YAML
B
XML
C
CSV
D
JSON
E
Protocol Buffers
Question 19 Explanation: 
NETCONF uses XML-encoded Remote Procedure Call (RPC) messages to retrieve, modify and manage network device configurations.
Question 20
A network engineer is configuring EIGRP Named Mode on a Cisco IOS XE router. Under which configuration hierarchy are interface-specific EIGRP settings, such as Hello intervals and authentication, configured?
A
Address-Family Interface
B
Address-Family Topology
C
EIGRP Neighbor Configuration
D
Route-Map Configuration
E
Global Routing Table
Question 20 Explanation: 
In EIGRP Named Mode, interface-specific settings are configured under the address-family interface configuration hierarchy, using af-interface. This includes Hello intervals, authentication and other interface-level EIGRP parameters.
Question 21
A network engineer notices increasing CRC errors on a Cisco switch interface. The interface is operating at the expected speed and duplex settings. Which issue is a likely cause?
A
Incorrect OSPF Router ID
B
Incorrect DNS server address
C
Incorrect BGP Local Preference
D
Missing default route
E
Damaged Ethernet cable or physical interference
Question 21 Explanation: 
CRC errors indicate that received Ethernet frames have failed integrity checks. Common causes include damaged cables, faulty transceivers and physical-layer interference.
Question 22
A Cisco router experiences frequent OSPF topology changes, causing repeated SPF calculations and increased CPU utilization. Which OSPF feature can be configured to control the timing of SPF calculations and reduce unnecessary processing during rapid topology changes?
A
OSPF Virtual Link
B
OSPF Network Type Broadcast
C
OSPF Default Information Originate
D
OSPF Passive Interface
E
OSPF SPF Throttling
Question 22 Explanation: 
OSPF SPF throttling controls the scheduling of SPF calculations by using configurable initial, hold and maximum delays. This helps reduce CPU utilization during frequent topology changes while maintaining routing convergence.
Question 23
A network engineer wants SW1 to become the Root Bridge for VLAN 10 and SW2 to become the Root Bridge for VLAN 20. Both switches run Rapid PVST+. Which configuration approach achieves this goal?
A
Disable STP on VLAN 20
B
Configure the same bridge priority for all VLANs
C
Change the MAC address of each access port
D
Configure a lower STP bridge priority on SW1 for VLAN 10 and on SW2 for VLAN 20
E
Configure both switches as Root Bridges for every VLAN
Question 23 Explanation: 
Rapid PVST+ maintains a separate STP instance for each VLAN. Administrators can influence Root Bridge election by configuring different bridge priorities for individual VLANs.
Question 24
An MPLS Label Switch Router (LSR) receives a labeled packet. The LFIB entry specifies an outgoing label that differs from the incoming label. Which MPLS operation is performed? MPLS-label-swapping-ccie-enterprise-infrastructure
A
Push
B
Aggregate
C
Pop
D
Untag
E
Swap
Question 24 Explanation: 
MPLS label swapping replaces the incoming label with the outgoing label specified in the LFIB. This operation is commonly performed by intermediate LSRs along a Label Switched Path (LSP).
Question 25
Two MPLS routers have established an LDP session. One router detects a protocol error that must be reported to its peer. Which LDP message type is used to communicate the error?
A
Label Mapping Message
B
Address Message
C
Label Request Message
D
Hello Message
E
Notification Message
Question 25 Explanation: 
LDP Notification messages communicate status information, including protocol errors, between LDP peers. Some errors may cause the LDP session to terminate.
Question 26
A Cisco router receives two valid BGP routes to the same destination. Both routes have equal Weight, Local Preference, locally originated status and AS_PATH length. Route A has an origin code of IGP, while Route B has an origin code of Incomplete. Which route is preferred?
A
Route B because Incomplete origin is preferred
B
Route B because origin codes are ignored
C
The route with the higher Router ID is always preferred
D
Route A because IGP origin is preferred
E
Both routes are automatically load balanced
Question 26 Explanation: 
In BGP best-path selection, IGP origin (i) is preferred over EGP (e) and Incomplete (?) when earlier selection criteria are equal.
Question 27
A router running PIM Sparse Mode receives multicast packets from a source. However, the packets arrive on an interface that is not the expected RPF interface. What will the router do?
A
Convert the packets into unicast traffic
B
Change the incoming interface automatically
C
Forward the packets to all multicast interfaces
D
Forward the packets directly to the Rendezvous Point
E
Drop the packets because the RPF check fails
Question 27 Explanation: 
PIM uses Reverse Path Forwarding (RPF) checks to prevent multicast routing loops. Packets arriving on an incorrect RPF interface are normally dropped.
Question 28
Two Cisco routers are connected over an Ethernet link and configured in OSPF Area 0. R1 uses a Hello interval of 10 seconds and a Dead interval of 40 seconds. R2 uses a Hello interval of 5 seconds and a Dead interval of 20 seconds. What happens?
A
The routers form an adjacency after 40 seconds
B
The routers automatically negotiate matching timers
C
The routers establish a FULL adjacency
D
The routers fail to establish an OSPF neighbor relationship
E
The routers establish an adjacency but do not exchange routes
Question 28 Explanation: 
OSPF neighbors must have matching Hello and Dead intervals. A timer mismatch prevents the routers from establishing a neighbor relationship.
Question 29
In Cisco SD-Access, which technology provides the data-plane encapsulation used to transport traffic between fabric edge nodes across the underlay network?
A
MPLS LDP
B
STP
C
GRE
D
VXLAN
E
PPPoE
Question 29 Explanation: 
Cisco SD-Access uses VXLAN as its overlay data-plane encapsulation. VXLAN carries endpoint traffic across the IP underlay while supporting fabric segmentation.
Question 30
Two Cisco routers run VRRP for the same virtual IP address. R1 is the current Master, and R2 is the Backup. R1 fails, causing R2 to become Master. Which VRRP mechanism allows hosts to continue using the same default gateway IP address without reconfiguration?
A
Virtual IP address shared by the VRRP group
B
OSPF route redistribution
C
DHCP address renewal
D
Dynamic NAT
E
BGP next-hop tracking
Question 30 Explanation: 
VRRP provides a shared virtual IP address that hosts use as their default gateway. When the Master router fails, the Backup router can take over the virtual gateway role without requiring changes to host configurations.
Question 31
A multicast receiver wants to receive traffic for group 232.1.1.1 only from source 10.10.10.10. Which IGMP version supports the source filtering required for this operation? IGMP-source-filtering-ccie-question
A
IGMPv1
B
IGMPv3
C
PIM Dense Mode
D
MLDv1
E
IGMPv2
Question 31 Explanation: 
IGMPv3 supports source filtering, allowing receivers to specify which multicast sources they want to receive traffic from. This capability is required for IPv4 Source-Specific Multicast (SSM).
Question 32
A network engineer has configured IP SLA Operation 50 on a Cisco IOS XE router. Which command schedules the operation to start immediately and run indefinitely?
A
ip sla 50 schedule forever
B
ip sla schedule 50 life 0 start-time now
C
ip sla schedule 50 life forever start-time now
D
ip sla schedule 50 life unlimited start-time now
E
ip sla schedule 50 start-time immediate
Question 32 Explanation: 
The ip sla schedule 50 life forever start-time now command schedules IP SLA Operation 50 to start immediately and continue indefinitely.
Question 33
A network engineer is deploying DMVPN Phase 3 with IPsec protection using IKEv2. The hub and spokes must authenticate each other and negotiate security parameters before establishing IPsec Child SAs. Which IKEv2 exchange performs peer authentication and establishes the first Child SA?
A
IKE_SA_INIT
B
NHRP Registration
C
INFORMATIONAL
D
CREATE_CHILD_SA
E
IKE_AUTH
Question 33 Explanation: 
The IKE_AUTH exchange authenticates IKEv2 peers and normally establishes the first IPsec Child SA. IKE_SA_INIT negotiates the initial cryptographic parameters and establishes keying material, while CREATE_CHILD_SA is used for additional Child SAs or rekeying.
Question 34
A Cisco switch receives traffic from an untrusted endpoint. The endpoint marks all packets with DSCP EF (46), although the traffic is not voice traffic. What is the recommended QoS approach at the trust boundary?
A
Trust all DSCP markings from the endpoint
B
Forward all packets using strict priority queuing
C
Classify and remark traffic according to the configured QoS policy
D
Change all traffic to DSCP CS6
E
Disable QoS on the entire switch
Question 34 Explanation: 
A QoS trust boundary determines where packet markings can be trusted. Traffic from untrusted endpoints should be classified and remarked according to the organization's QoS policy.
Question 35
A Cisco router running classic EIGRP is configured to generate a summary route using the ip summary-address eigrp command. What is the default administrative distance of the locally generated summary route pointing to Null0? ccie-enterprise-infrastructure-EIGRP-summary-route
A
5
B
170
C
200
D
110
E
90
Question 35 Explanation: 
An EIGRP summary route generated locally with ip summary-address eigrp has a default administrative distance of 5. Internal EIGRP routes normally use AD 90, while external EIGRP routes use AD 170.
Question 36
An enterprise network uses OSPFv3 with Area 5 configured as a stub area. Which type of LSA is normally blocked from entering this area?
A
AS-External-LSA (Type 5)
B
Router-LSA (Type 1)
C
Link-LSA (Type 8)
D
Inter-Area-Prefix-LSA (Type 3)
E
Network-LSA (Type 2)
Question 36 Explanation: 
OSPFv3 stub areas block AS-External-LSAs (Type 5). An Area Border Router normally provides a default route so routers in the stub area can reach external destinations.
Question 37
Which Cisco IOS command statically configures the secure MAC address 1111.2222.3333 on a switch interface with port security enabled?
A
port-security mac 1111.2222.3333
B
switchport security static 1111.2222.3333
C
mac-address secure 1111.2222.3333
D
switchport mac-address 1111.2222.3333
E
switchport port-security mac-address 1111.2222.3333
Question 38
A BGP Route Reflector receives a route from one of its iBGP clients. By default, to which peers can the Route Reflector advertise this route?
A
Only to the originating client
B
Only to non-client iBGP peers
C
To other clients, non-client iBGP peers and eligible eBGP peers
D
Only to its eBGP neighbors
E
Only to directly connected routers
Question 38 Explanation: 
A BGP Route Reflector can reflect routes learned from a client to other clients and non-client iBGP peers. It can also advertise eligible routes to eBGP peers according to normal BGP export rules.
Question 39
In a Cisco SD-Access fabric that uses LISP for endpoint reachability, a fabric edge node needs to determine the current location of a destination endpoint. Which LISP message does it send to request the endpoint's mapping information? Cisco-SD-Access-LISP-ccie-question
A
Solicit-Map-Request
B
Map-Reply
C
Map-Request
D
Map-Notify
E
Map-Register
Question 39 Explanation: 
A LISP Map-Request is used to obtain the mapping between an Endpoint Identifier (EID) and its Routing Locator (RLOC). This information allows the fabric edge node to determine where to forward traffic toward the destination endpoint.
Question 40
A Cisco router is running OSPF Process 10. The network engineer wants to advertise only the 20.20.20.0/24 subnet in Area 0 using the OSPF network command. Which command is correct?
A
network 20.20.20.0/24 area 0
B
network 20.20.20.0 0.255.255.255 area 0
C
network 20.20.20.0 0.0.0.255 area 0
D
network 20.20.20.0 255.255.255.0 area 0
E
network 20.20.20.0 0.0.0.255 area 10
Question 40 Explanation: 
The OSPF network command uses a wildcard mask. For a /24 subnet, the wildcard mask is 0.0.0.255. The command enables OSPF on matching interfaces in Area 0.
Question 41
A network engineer needs to provide IPv6 connectivity between two sites across an IPv4-only network. Both routers support GRE tunnels. Which tunnel configuration approach can transport IPv6 packets over the IPv4 infrastructure?
A
IPv4 DHCP relay
B
NAT44 translation
C
IPv4 Policy-Based Routing without tunneling
D
GRE tunnel with IPv6 as the passenger protocol
E
Layer 2 EtherChannel
Question 41 Explanation: 
GRE can encapsulate IPv6 packets inside IPv4 packets, allowing IPv6 connectivity across an IPv4-only transport network.
Question 42
A network engineer wants to examine all routes learned through EIGRP, including routes that are not feasible successors. Which Cisco IOS command provides this information?
A
show ip route eigrp
B
show ip eigrp topology all-links
C
show ip protocols
D
show ip eigrp neighbors
E
show ip eigrp topology
Question 42 Explanation: 
The show ip eigrp topology all-links command displays all EIGRP topology entries, including routes that do not satisfy the feasibility condition.
Question 43
Which Cisco IOS extended ACL command permits HTTP traffic from the 192.168.50.0/30 subnet to any destination using ACL 105?
A
access-list 105 permit tcp any 192.168.50.0 0.0.0.3 eq 80
B
access-list 105 permit tcp 192.168.50.0 0.0.0.255 any eq 80
C
access-list 105 permit udp 192.168.50.0 0.0.0.3 any eq 80
D
access-list 105 permit tcp 192.168.50.0 0.0.0.3 any eq 80
E
access-list 105 permit tcp 192.168.50.0 255.255.255.252 any eq 80
Question 43 Explanation: 
Extended ACLs use wildcard masks to match IP subnets. A /30 subnet uses wildcard mask 0.0.0.3, and TCP destination port 80 identifies standard HTTP traffic.
Question 44
An OSPF router has two routes to the same destination prefix: an intra-area route and an inter-area route. The inter-area route has a lower metric. Which route does OSPF prefer?
A
The route with the highest administrative distance
B
The route learned from the router with the higher Router ID
C
The inter-area route because its metric is lower
D
Both routes are installed automatically
E
The intra-area route because OSPF prefers intra-area routes
Question 44 Explanation: 
OSPF prefers intra-area routes over inter-area routes, regardless of their metric values. OSPF route type preference is evaluated before comparing metrics across different route types.
Question 45
A Cisco IOS XE router experiences high CPU utilization caused by excessive routing protocol and management traffic directed to its control plane. The administrator wants to apply different policing rates to different classes of control-plane traffic. Which configuration approach should be used?
A
Apply a class-based policy map under the control-plane configuration
B
Enable storm control on all routed interfaces
C
Apply an interface QoS policy to all outbound interfaces
D
Configure a VLAN Access Control List on the management VLAN
E
Configure an IP SLA operation to monitor CPU utilization
Question 45 Explanation: 
Control Plane Policing (CoPP) uses class maps and policy maps to classify and police traffic destined for the router's control plane. Applying a service policy under the control-plane configuration helps protect CPU resources from excessive traffic.
Question 46
A Layer 2 switch has MLD Snooping enabled. An IPv6 host joins a multicast group by sending an MLD Report. What is the primary purpose of MLD Snooping?
A
Encrypt IPv6 multicast traffic
B
Replace IPv6 Neighbor Discovery
C
Convert IPv6 multicast packets into unicast packets
D
Assign IPv6 addresses to multicast receivers
E
Forward multicast traffic only toward interested receivers
Question 46 Explanation: 
MLD Snooping allows a Layer 2 switch to learn which ports have interested IPv6 multicast receivers and limit multicast forwarding to the appropriate ports.
Question 47
An attacker connects a device to an enterprise access switch and begins sending unauthorized IPv6 Router Advertisement messages. Which Cisco switch security feature is designed to prevent these messages from being accepted on untrusted access ports?
A
DHCP Snooping for IPv4
B
PortFast
C
Dynamic ARP Inspection
D
IP Source Guard for IPv4
E
IPv6 RA Guard
Question 47 Explanation: 
IPv6 RA Guard filters unauthorized Router Advertisement messages on switch ports, helping prevent rogue devices from advertising themselves as IPv6 default gateways.
Question 48
A network engineer configures Flexible NetFlow on a Cisco router. The flow monitor is correctly applied to an interface, but no records are exported to the collector. Which configuration component should be checked to verify the export destination and transport settings?
A
Flow Exporter
B
Routing Table
C
Class Map
D
Flow Sampler
E
Flow Record
Question 48 Explanation: 
A Flexible NetFlow flow exporter defines the collector destination, source interface, transport protocol and export settings. Incorrect exporter configuration can prevent flow records from reaching the collector.
Question 49
An enterprise uses Cisco SD-Access with multiple virtual networks. Two endpoints belong to the same virtual network but different scalable groups. The administrator wants to control communication between these groups without changing the underlying IP addressing. Which technology is used to enforce this policy? Cisco-SD-Access-Policy-Enforcement-ccie-question
A
LISP Map-Register
B
VRF Route Leaking
C
OSPF Area Filtering
D
Cisco TrustSec Security Group ACLs
E
VXLAN Flood-and-Learn
Question 49 Explanation: 
Cisco TrustSec uses Security Group Tags (SGTs) and Security Group ACLs (SGACLs) to enforce group-based access policies. This allows Cisco SD-Access to control communication between scalable groups independently of IP addressing.
Question 50
In a DMVPN Phase 3 network, a spoke router initially forwards traffic to another spoke through the hub. Which NHRP mechanism allows the hub to inform the source spoke about a more direct path?
A
NHRP Registration Request
B
NHRP Purge
C
NHRP Error Indication
D
NHRP Redirect
E
NHRP Registration Reply
Question 50 Explanation: 
In DMVPN Phase 3, the hub sends an NHRP Redirect to inform the source spoke that a more direct path may be available. The spoke can then initiate NHRP resolution to establish direct spoke-to-spoke forwarding.
Once you are finished, click the button below. Any items you have not completed will be marked incorrect. Get Results
There are 50 questions to complete.
gokhan-kosem-instructor-ipcisco

Gokhan Kosem is a Network Engineer, Instructor and the Founder of IPCisco.com with 15+ years of experience in Cisco, Nokia, Huawei, Juniper, Linux, Service Provider Networks, Routing and Switching technologies.

He has worked on the backbone networks of major service providers and network vendors including Nortel, Alcatel-Lucent (Nokia) and has extensive hands-on experience with Cisco, Huawei, Juniper and Nokia networking technologies.

He has trained thousands of networking students worldwide through IPCisco.com, Udemy, books, labs, quizzes, and educational content across multiple social media platforms.

IPCisco.com | Best Route to Your Dreams