Summer Special Sale Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 713PS592

300-410 Implementing Cisco Enterprise Advanced Routing and Services (300-410 ENARSI) Questions and Answers

Questions 4

Refer to the exhibit.

300-410 Question 4

A network administrator configured an IPv6 access list to allow TCP return frame only, but it is not working as expected. Which changes resolve this issue?

300-410 Question 4

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 5

Refer to the exhibit.

300-410 Question 5

R1 is being monitored using SNMP and monitoring devices are getting only partial information. What action should be taken to resolve this issue?

Options:

A.

Modify the CoPP policy to increase the configured exceeded limit for SNMP.

B.

Modify the access list to include snmptrap.

C.

Modify the CoPP policy to increase the configured CIR limit for SNMP.

D.

Modify the access list to add a second line to allow udp any any eq snmp

Buy Now
Questions 6

Refer to the exhibit.

300-410 Question 6

A network administrator logs into the router using TACACS+ username and password credentials, but the administrator cannot run any privileged commands Which action resolves the issue?

Options:

A.

Configure TACACS+ synchronization with the Active Directory admin group

B.

Configure the username from a local database

C.

Configure full access for the username from TACACS+ server

D.

Configure an authorized IP address for this user to access this router

Buy Now
Questions 7

Refer to the exhibit.

300-410 Question 7

The neighbor relationship is not coming up Which two configurations bring the adjacency up? (Choose two)

Options:

A.

NYrouter ospf 1area 0 authentication message-digest

B.

LAinterface E 0/0ip ospf message-digest-key 1 md5 Cisco123

C.

NYinterface E 0/0no ip ospf message-digest-key 1 md5 Cisco123ip ospf authentication-key Cisco123

D.

LAinterface E 0/0ip ospf authentication-key Cisco123

E.

LArouter ospf 1area 0 authentication message-digest

Buy Now
Questions 8

Refer to the exhibit.

300-410 Question 8

The network administrator can see the DHCP discovery packet in R1. but R2 is not replying to the DHCP request. The R1 related interface is configured with the DHCP helper address. If the PC is directly connected to the FaO/1 interface on R2, the DHCP server assigns as IP address from the DHCP pool to the PC. Which two commands resolve this issue? (Choose two.)

Options:

A.

service dhcp-relay command on R1

B.

ip dhcp option 82 command on R2

C.

service dhcp command on R1

D.

ip dhcp relay information enable command on R1

E.

ip dhcp relay information trust-all command on R2

Buy Now
Questions 9

What are two MPLS label characteristics? (Choose two.)

Options:

A.

The label edge router swaps labels on the received packets.

B.

Labels are imposed in packets after the Layer 3 header.

C.

LDP uses TCP for reliable delivery of information.

D.

An MPLS label is a short identifier that identifies a forwarding equivalence class.

E.

A maximum of two labels can be imposed on an MPLS packet.

Buy Now
Questions 10

Refer to the exhibit.

300-410 Question 10

An IT staff member comes into the office during normal office hours and cannot access devices through SSH Which action should be taken to resolve this issue?

Options:

A.

Modify the access list to use the correct IP address.

B.

Configure the correct time range.

C.

Modify the access list to correct the subnet mask

D.

Configure the access list in the outbound direction.

Buy Now
Questions 11

Refer to the exhibit.

300-410 Question 11

An IPv6 network was newly deployed in the environment and the help desk reports that R3 cannot SSH to the R2s Loopback interface. Which action resolves the issue?

Options:

A.

Modify line 10 of the access list to permit instead of deny.

B.

Remove line 60 from the access list.

C.

Modify line 30 of the access list to permit instead of deny.

D.

Remove line 70 from the access list.

Buy Now
Questions 12

Refer to the exhibits.

300-410 Question 12

When DMVPN is configured, which configuration allows spoke-to-spoke communication using loopback as a tunnel source?

Options:

A.

Configure crypto isakmp key cisco address 0.0.0.0 on the hub.

B.

Configure crypto isakmp key Cisco address 200.1.0.0 255.255.0.0 on the hub.

C.

Configure crypto isakmp key cisco address 200.1.0.0 255.255.0.0 on the spokes.

D.

Configure crypto isakmp key cisco address 0.0.0.0 on the spokes.

Buy Now
Questions 13

Refer to the exhibit.

300-410 Question 13

300-410 Question 13

An engineer identifier a Layer 2 loop using DNAC. Which command fixes the problem in the SF-D9300-1 switch?

Options:

A.

no spanning-tree uplinkfast

B.

spanning-tree loopguard default

C.

spanning-tree backbonesfast

D.

spanning-tree portfast bpduguard

Buy Now
Questions 14

What are two functions of MPLS Layer 3 VPNs? (Choose two.)

Options:

A.

LDP and BGP can be used for Pseudowire signaling.

B.

It is used for transparent point-to-multipoint connectivity between Ethernet links/sites.

C.

BGP is used for signaling customer VPNv4 routes between PE nodes.

D.

A packet with node segment ID is forwarded along with shortest path to destination.

E.

Customer traffic is encapsulated in a VPN label when it is forwarded in MPLS network.

Buy Now
Questions 15

Refer to the exhibit.

300-410 Question 15

The administrator is trying to overwrite an existing file on the TFTP server that was previously uploaded by another router. However, the attempt to update the file fails. Which action resolves this issue?

Options:

A.

Make the packages.conf file executable by all on the TFTP server

B.

Make the packages.conf file writable by all on the TFTP server

C.

Make sure to run the TFTP service on the TFTP server

D.

Make the TFTP folder writable by all on the TFTP server

Buy Now
Questions 16

300-410 Question 16

Refer to the exhibit The SNMP server with IP address 172.16 4 4 cannot access host router A Which configuration command on router A resolves the issue?

Options:

A.

snmp-server community ccnp

B.

access-list 4 permit 172.16.4.0 0.0.0.3

C.

access-list 4 permit host 172.16.4.4

D.

snmp-server host 172.16.4.4 ccnp

Buy Now
Questions 17

300-410 Question 17

300-410 Question 17

300-410 Question 17

Options:

Buy Now
Questions 18

Refer to the exhibit.

300-410 Question 18

An administrator is attempting to disable the automatic logout after a period of inactivity. After logging out the console stopped responding to all keyword inputs. Remote access through SSH still work resolves the issue?

Options:

A.

Configure the exec command on line con 0.

B.

Configure the absolute-timeout command on line con 0.

C.

Configure the default exec-timeout command on line con 0.

D.

Configure the no exec-timeout command on line con 0.

Buy Now
Questions 19

An engineer configured a DHCP server for Cisco IP phones to download its configuration from a TFTP server, but the IP phones failed to toad the configuration What must be configured to resolve the issue?

Options:

A.

BOOTP port 67

B.

DHCP option 66

C.

BOOTP port 68

D.

DHCP option 69

Buy Now
Questions 20

A customer reports to the support desk that they cannot print from their PC to the local printer id:401987778. Which tool must be used to diagnose the issue using Cisco DNA Center Assurance?

Options:

A.

application trace

B.

path trace

C.

ACL trace

D.

device trace

Buy Now
Questions 21

300-410 Question 21

Refer to the exhibit. The authentication is not working as desired and the user drops into user-exec mode. Which configuration resolves the issue?

300-410 Question 21

300-410 Question 21

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 22

300-410 Question 22

Refer to the exhibit The enterprise users fail to authenticate with the TACACS server when a direct fiber link fails between RB and RD The NOC team observes

Users connected on AS65201 fail to authenticate with TACACS server 192 168 1 1

Users connected on AS65101 successfully authenticate with TACACS server 192 168 1 1

All AS65101 and AS65201 users are configured to authenticate with the TACACS server

Which configuration resolves the issue?

A)

300-410 Question 22

B)

300-410 Question 22

C)

300-410 Question 22

D)

300-410 Question 22

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 23

What statement about route distinguishes in an MPLS network is true?

Options:

A.

Route distinguishes make a unique VPNv4 address across the MPLS network.

B.

Route distinguishers allow multiple instances of a routing table to coexist within the edge router.

C.

Route distinguishes are used for label bindings

D.

Route distinguishes define which prefixes are imported and exported on the edge router

Buy Now
Questions 24

Refer to the exhibit.

300-410 Question 24

When monitoring an IPv6 access list, an engineer notices that the ACL does not have any hits and is causing unnecessary traffic to pass through the interface Which command must be configured to resolve the issue?

Options:

A.

access-class INTERNET in

B.

ipv6 traffic-filter INTERNET in

C.

ipv6 access-class INTERNET in

D.

ip access-group INTERNET in

Buy Now
Questions 25

Refer to the exhibit.

300-410 Question 25

To provide reachability to network 10.1.1.0 /24 from R5, the network administrator redistributes EIGRP into OSPF on R3 but notices that R4 is now taking a ........... path through R5 to reach 10.1.1.0/24 network. Which action fixes the issue while keeping the reachability from R5 to 10.1.1.0/24 network?

Options:

A.

Change the administrative distance of the external EIGRP to 90.

B.

Apply the outbound distribution list on R5 toward R4 in OSPF.

C.

Change the administrative distance of OSPF to 200 on R5.

D.

Redistribute OSPF into EIGRP on R4

Buy Now
Questions 26

Which two protocols work in the control plane of P routers across the MPLS cloud? (choose two)

Options:

A.

LSP

B.

RSVP

C.

ECMP

D.

LDP

E.

MPLS OAM

Buy Now
Questions 27

An engineer configured access list NON-CISCO in a policy to influence routes

300-410 Question 27

What are the two effects of this route map configuration? (Choose two.)

Options:

A.

Packets are not evaluated by sequence 10.

B.

Packets are evaluated by sequence 10.

C.

Packets are forwarded to the default gateway.

D.

Packets are forwarded using normal route lookup.

E.

Packets are dropped by the access list.

Buy Now
Questions 28

What are two functions of LDP? (Choose two.)

Options:

A.

It is defined in RFC 3038 and 3039.

B.

It requires MPLS Traffic Engineering.

C.

It advertises labels per Forwarding Equivalence Class.

D.

It must use Resource Reservation Protocol.

E.

It uses Forwarding Equivalence Class

Buy Now
Questions 29

Refer to the exhibit.

300-410 Question 29

BGP and EIGRP are mutually redistributed on R3, and EIGRP and OSPF are mutually redistributed on R1. Users report packet loss and interruption of service to applications hosted onthe 10.1.1.0724 prefix. An engineer tested the link from R3 to R4 with no packet loss present but has noticed frequent routing changes on R3 when running the debug ip route command. Which action stabilizes the service?

Options:

A.

Tag the 10.1.1.0/24 prefix and deny the prefix from being redistributed into OSPF on R1.

B.

Repeat the test from R4 using ICMP ping on the local 10.1.1.0/24 prefix, and fix any Layer 2 errors on the host or switch side of the subnet. ^ C. Place an OSPF distribute-list outbound on R3 to block the 10.1.10/24 prefix from being advertised back to R3.

C.

Reduce frequent OSPF SPF calculations on R3 that cause a high CPU and packet loss on traffic traversing R3.

Buy Now
Questions 30

Refer to the exhibit.

300-410 Question 30

An engineer receives this error message when trying to access another router in-band from the serial interface connected to the console of R1. Which configuration is needed on R1 to resolve this issue?

300-410 Question 30

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 31

300-410 Question 31

Refer to the exhibit. The engineer configured and connected Router2 to Router1. The link came up but could not establish a Telnet connection to Router1 IPv6 address of 2001:DB8::1. Which configuration allows Router2 to establish a Telnet connection to Router1?

Options:

A.

jpv6 unicast-routing

B.

permit ICMPv6 on access list INGRESS for Router2 to obtain IPv6 address

C.

permit ip any any on access list EGRESS2 on Router1

D.

IPv6 address on GigabitEthernet0/0

Buy Now
Questions 32

300-410 Question 32

Refer to the exhibit. An engineer has successfully set up a floating static route from the BRANCH router to the HQ network using HQ_R1 as the primary default gateway When the g0/0 goes down on HQ_R1, the branch network cannot reach the HQ network 192.168.20.0/24. Which set of configurations resolves the issue?

Options:

A.

HQ_R3(config)# ip sla responderHQ_R3(config)# ip sla responder icmp-echo 172.16.35.1

B.

BRANCH(config)# ip sla 1BRANCH(config-ip-sla)# icmp-echo 192.168.100.2

C.

HQ R3(config)# Ip sla responderHQ R3(config)# Ip sla responder Icmp-echo 172.16.35.5

D.

BRANCH(config)# Ip sla 1BRANCH(config-ip-sta)# Icmp-echo 192.168.100.1

Buy Now
Questions 33

What are two characteristics of VRF instance? (Choose two.)

Options:

A.

All VRFs share customers routing and CEF tables .

B.

An interface must be associated to one VRF.

C.

Each VRF has a different set of routing and CEF tables

D.

It is defined by the VPN membership of a customer site attached to a P device.

E.

A customer site can be associated to different VRFs

Buy Now
Questions 34

Refer to the exhibit.

300-410 Question 34

R1 is connected with R2 via GigabitEthernet0/0, and R2 cannot ping R1. What action will fix the issue?

Options:

A.

Fix route dampening configured on the router.

B.

Replace the SFP module because it is not supported.

C.

Fix IP Event Dampening configured on the interface.

D.

Correct the IP SLA probe that failed.

Buy Now
Questions 35

Refer to the exhibits.

300-410 Question 35

A user on the 192.168.1.0/24 network can successfully ping 192.168.3.1, but the administrator cannot ping 192.168.3.1 from the LA router. Which set of configurations fixes the issue?

A)

300-410 Question 35

B)

300-410 Question 35

C)

300-410 Question 35

D)

300-410 Question 35

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 36

Refer to the exhibit.

300-410 Question 36

A network administrator configured mutual redistribution on R1 and R2 routers, which caused instability in the network. Which action resolves the issue?

Options:

A.

Set a tag in the route map when redistributing EIGRP into OSPF on R1. and match the same tag on R2 to allow when redistributing OSPF into EIGRP.

B.

Apply a prefix list of EIGRP network routes in OSPF domain on R1 to propagate back into the EIGRP routing domain.

C.

Set a tag in the route map when redistributing EIGRP into OSPF on R1, and match the same tag on R2 to deny when redistributing OSPF into EIGRP.

D.

Advertise summary routes of EIGRP to OSPF and deny specific EIGRP routes when redistributing into OSPF.

Buy Now
Questions 37

300-410 Question 37

300-410 Question 37

Refer to the exhibit. R2 has two paths to reach 192.168.13.0/24. but traffic is sent only through R3. Which action allows traffic to use both paths?

Options:

A.

Configure the bandwidth 2000 command under interface FastEthernet0/0 on R2.

B.

Configure the variance 4 command under the EIGRP process on R2.

C.

Configure the delay 1 command under interface FastEthernet0/0 on R2.

D.

Configure the variance 2 command under the EIGRP process on R2

Buy Now
Questions 38

300-410 Question 38

Refer to the exhibit. The network administrator has configured the Customer Edge router (AS 64511) to send only summarized routes toward ISP-1 (AS 100) and ISP-2 (AS 200).

router bgp 64511

network 172.16.20.0 mask 255.255.255.0

network 172.16.21.0 mask 255.255.255.0

network 172.16.22.0 mask 255.255.255.0

network 172.16.23.0 mask 255.255.255.0

aggregate-address 172.16.20.0 255.255.252.0

After this configuration. ISP-1 and ISP-2 continue to receive the specific routes and the summary route. Which configuration resolves the issue?

Options:

A.

router bgp 64511aggregate-address 172.16.20.0 255.255.252.0 summary-only

B.

router bgp 64511neighbor 192.168.100.1 summary-onlyneighbor 192.168.200.2 summary-only

C.

interface E 0/0ip bgp suppress-map BLOCK_SPECIFIC!interface E 0/1ip bgp suppress-map BLOCK_SPECIFIC!ip prefix-list PL_BLOCK_SPECIFIC permit 172.16.20.0/22 ge 24!route-map BLOCK_SPECIFIC permit 10match ip address prefix-list PL_BLOCK_SPECIFIC

D.

ip prefix-list PL_BLOCK_SPECIFIC deny 172.16.20.0/22 ge 22ip prefix-list PL BLOCK SPECIFIC permit 172.16.20.0/22!route-map BLOCK_SPECIFIC permit 10match ip address prefix-list PL_BLOCK_SPECIFIC!router bgp 64511aggregate-address 172.16.20.0 255 255.252.0 suppress-map BLOCKSPECIFIC

Buy Now
Questions 39

Refer to the exhibit.

300-410 Question 39

R1 test its directly connected EIGRP peer 172.16.33.2 (SW1). Which configuration resolves the issue1?

Options:

A.

key chain EIGRP key 1 key-string Cisco!interface Gigabit Ethernet 2 IP authentication mode elgrp 88 md5 IP authentication key-chain elgrp 88 EIGRP

B.

key chain EIGRP key1 key-string Cisco!interface Gigabit Ethernet 2.10 IP authentication mode eigrp 88 md5 IP authentication key-chain eigrp 88 Cisco

C.

key chain EIGRP key 1 key-string Cisco !interface Gigabit Ethernet 2.10 IP authentication mode elgrp 88 md5 IP authentication key-chain eigrp 88 EIGRP

D.

key chain EIGRP key1 key-string Cisco !interface Gigabit Ethernet 2 IP authentication mode eigrp 88 md5 IP authentication key-chain elgrp 88 Cisco

Buy Now
Questions 40

What are two characteristics of IPv6 Source Guard? (Choose two.)

Options:

A.

requires IPv6 snooping on Layer 2 access or trunk ports

B.

used in service provider deployments to protect DDoS attacks

C.

requires the user to configure a static binding

D.

requires that validate prefix be enabled

E.

recovers missing binding table entries

Buy Now
Questions 41

300-410 Question 41

300-410 Question 41

Refer to the exhibit Users from the 192 168.2.0/24 network cannot connect to the 172.16 2 32/28 network Which configuration resolves the issue'?

A)

300-410 Question 41

B)

300-410 Question 41C)

300-410 Question 41

D)

300-410 Question 41

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Buy Now
Questions 42

300-410 Question 42

300-410 Question 42

Refer to the exhibit. An engineer applied filter on R1 The interface flapped between R1 and R2 and cleaning the BGP session did not restore the BGP session and failed Which action must the engineer take to restore the BGP session from R2 to R1?

Options:

A.

Apply the IPv6 traffic filter in the outbound direction on the interface

B.

ICMPv6 must be permitted by the IPv6 traffic filter

C.

Enable the BGP session, which went down when the session was cleared.

D.

Swap the source and destination IP addresses in the IPv6 traffic filter

Buy Now
Questions 43

Refer to the exhibit.

300-410 Question 43

Packets arriving from source 209.165.200.215 must be sent with the precedence bit set to 1, and packets arriving from source 209.165.200.216 must be sent with the precedence bit set to 5. Which action resolves the issue?

Options:

A.

set ip precedence critical in route-map Texas permit 10

B.

set ip precedence critical in route-map Texas permit 20

C.

set ip precedence immediate in route-map Texas permit 10

D.

set ip precedence priority in route-map Texas permit 20

Buy Now
Questions 44

Refer to the exhibit.

300-410 Question 44

An engineer configures SW101 to send OSPFv3 interfaces state change messages to the server. However, only some OSPFv3 errors are being recorded. which organization resolves the ..?

Options:

A.

snmp-server enable traps ospfv3 state-change if-state-change

B.

snmp-server-enable traps ospfv3 state-change restart-status-change

C.

snmp-server-enable traps ospfv3 state-change neighbor-state-change.

D.

snmp-server-enable traps ospfv3 state-change if-state-change neighbor-state-change

Buy Now
Questions 45

300-410 Question 45

Refer to the exhibit. An engineer must configure a per VRF for TACACS+ for company A. Which configuration on RTG-1 accomplishes the task?

300-410 Question 45

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 46

300-410 Question 46

Refer to the exhibit EIGRP adjacency between router A and router C is not working as expected Which two configurations resolve the issue? (Choose two )

A)

300-410 Question 46

B)

300-410 Question 46

C)

300-410 Question 46

D)

300-410 Question 46

E)

300-410 Question 46

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Buy Now
Questions 47

An engineer received a ticket about a router that has reloaded. The monitoring system graphs show different traffic patterns between logical and physical interfaces when the router is rebooted. Which action resolves the issue?

Options:

A.

Configure the snmp ifindex persist command globally.

B.

Clear the logical interfaces with snmp ifindex clear command

C.

Configure the snmp ifindex persist command on the physical interfaces.

D.

Trigger a new snmpwalk from the monitoring system to synchronize interface OlDs

Buy Now
Questions 48

Refer to the exhibit.

300-410 Question 48

A network administrator is using the DNA Assurance Dashboard panel to troubleshoot an OSPF adjacency that failed between Edge_NYC interface GigabitEthernet1/3 with Neighbor Edge_SNJ. The administrator observes that the neighborship is stuck in exstart state. How does the administrator fix this issue?

Options:

A.

Configure to match the OSPF interface speed and duplex settings on both routers.

B.

Configure to match the OSPF interface MTU settings on both routers.

C.

Configure to match the OSPF interface unique IP address and subnet mask on both routers.

D.

Configure to match the OSPF interface network types on both routers.

Buy Now
Questions 49

300-410 Question 49

Refer to the exhibit. A network administrator redistributed the default static route into OSPF toward all internal routers to reach to Internet. Which set of commands restores reachability to the Internet by internal routers?

Options:

A.

router ospf 1default-information originate

B.

router ospf 1network 0.0.0.0 0.0.0.0 area 0

C.

router ospf 1redistribute connected 0.0.0.0

D.

router ospf 1redistribute static subnets

Buy Now
Questions 50

Refer to the exhibit.

300-410 Question 50

The Math and Science departments connect through the corporate. IT router but users in the Math department must not be able to reach the Science department and vice versa Which configuration accomplishes this task?

Options:

A.

vrf definition Science!interface E 0/2ip address 192.168.1.1 255.255.255.0no shut!interface E 0/3ip address 192.168.2.1 255.255.255.0no shut

B.

vrf definition Scienceaddress-family ipv4!interface E 0/2ip address 192.168.1.1 255.255.255.0vrf forwarding Scienceno shut!interface E 0/3ip address 192.168.2.1 255.255.255.0vrf forwarding Scienceno shut

C.

vrf definition Scienceaddress-family ipv4!interface E 0/2ip address 192.168.1.1 255.255.255.0no shut!interface E 0/3ip address 192.168.2.1 255.255.255.0no shut

D.

vrf definition Scienceaddress-family ipv4!interface E 0/2vrf forwarding Scienceip address 192.168.1.1 255.255.255.0no shut!interface E 0/3vrf forwarding Scienceip address 192.168.2.1

Buy Now
Questions 51

When configuring Control Plane Policing on a router to protect it from malicious traffic, an engineer observes that the configured routing protocols start flapping on

that device. Which action in the Control Plane Policy prevents this problem in a production environment while achieving the security objective?

Options:

A.

Set the conform-action and exceed-action to transmit initially to test the ACLs and transmit rates and apply the Control Plane Policy in the output direction

B.

Set the conform-action and exceed-action to transmit initially to test the ACLs and transmit rates and apply the Control Plane Policy in the input direction

C.

Set the conform-action to transmit and exceed-action to drop to test the ACLs and transmit rates and apply the Control Plane Policy m the input direction

D.

Set the conform-action to transmit and exceed-action to drop to test the ACLs and transmit rates and apply the Control Plane Policy m the output direction

Buy Now
Questions 52

Drag and drop the MPLS VPN device types from the left onto the definitions on the right.

300-410 Question 52

Options:

Buy Now
Questions 53

An engineer configured two routers connected to two different service providers using BGP with default attributes. One of the links is presenting high delay, which causes slowness in the network. Which BGP attribute must the engineer configure to avoid using the high-delay ISP link if the second ISP link is up?

Options:

A.

LOCAL_PREF

B.

MED

C.

WEIGHT

D.

AS-PATH

Buy Now
Questions 54

Refer to the exhibit.

300-410 Question 54

The administrator successfully logs into R1 but cannot access privileged mode commands. What should be configured to resolve the issue?

Options:

A.

aaa authorization reverse-access

B.

secret cisco123! at the end of the username command instead of password cisco123!

C.

matching password on vty lines as cisco123!

D.

enable secret or enable password commands to enter into privileged mode

Buy Now
Questions 55

Refer to the exhibit.

300-410 Question 55

The R1 and R2 configurations are:

300-410 Question 55

The neighbor is not coming up. Which two sets of configurations bring the neighbors up? (Choose two.)

Options:

A.

R2ip route 10.1.1.1 255.255.255.255 192.168.1.1!router bgp 200neighbor 10.1.1.1 tti-security hops 1neighbor 10.1.1.1 update-source loopback 0

B.

R2ip route 10.1.1.1 255.255.255.255 192.168.1.1!router bgp 200neighbor 10.1.1.1 disable-connected-checkneighbor 10.1.1.1 update-source loopback 0

C.

R2ip route 10.1.1.2 255.255.255.255 192.168.1.2!router bgp 100neighbor 10.1.1.2 ttl-security hops 1neighbor 10.1.1.2 update-source loopback 0

D.

R1ip route 10.1.1.2 255.255.255.255 192.168.1.2!router bgp 100neighbor 10.1.1.1 ttl-security hops 1neighbor 10.1.1.2 update-source loopback 0

E.

R1ip route 10.1.1.2 255.255.255.255 192.168.1.2!router bgp 100neighbor 10.1.1.2 disable-connected-checkneighbor 10.1.1.2 update-source Loopback0

Buy Now
Questions 56

Refer to Exhibit.

300-410 Question 56

A network administrator enables DHCP snooping on the Cisco Catalyst 3750-X switch and configures the uplink port (Port-channel2) as a trusted port. Clients are not receiving an IP address, but when DHCP snooping is disabled, clients start receiving IP addresses. Which global command resolves the issue?

Options:

A.

No ip dhcp snooping information option

B.

ip dhcp snooping

C.

ip dhcp relay information trust portchannel2

D.

ip dhcp snooping trust

Buy Now
Questions 57

300-410 Question 57

Refer to the exhibit. Which action restores the routes from neighbors while still filtering 1.1.1.0/24?

Options:

A.

Add a second line in the access list to permit any.

B.

Modify the route map to permit the access list instead of deny it

C.

Modify the access list to deny instead of permit it.

D.

Add a second sequence in the route map permit 20

Buy Now
Questions 58

Exhibit:

300-410 Question 58

Which action resolves the authentication problem?

Options:

A.

Configure the user name on the TACACS+ server

B.

Configure the UDP port 1812 to be allowed on the TACACS+ server

C.

Configure the TCP port 49 to be reachable by the router

D.

Configure the same password between the TACACS+ server and router.

Buy Now
Questions 59

300-410 Question 59

300-410 Question 59

Refer to the exhibit. The IT router has been configured with the Science VRF and the interfaces have been assigned to the VRF. Which set of configurations advertises Science-1 and Science-2 routes using EIGRPAS 111?

300-410 Question 59

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 60

300-410 Question 60

Refer to the exhibit Which action resolves the issue?

Options:

A.

Configure host IP address in access-list 16

B.

Configure SNMPv3 on the router

C.

Configure SNMP authentication on the router

D.

Configure a valid SNMP community string

Buy Now
Questions 61

Refer to the exhibit.

300-410 Question 61

A user cannot SSH to the router. What action must be taken to resolve this issue?

Options:

A.

Configure transport input ssh

B.

Configure transport output ssh

C.

Configure ip ssh version 2

D.

Configure ip ssh source-interface loopback0

Buy Now
Questions 62

The network administrator must implement IPv6 in the network to allow only devices that not only have registered IP addresses but are also connecting from assigned locations. Which security feature must be implemented?

Options:

A.

IPv6 Snooping

B.

IPv6 Destination Guard

C.

IPv6 Prefix Guard

D.

IPv6 Router Advertisement Guard

Buy Now
Questions 63

Refer to the exhibit.

300-410 Question 63

An engineer recently implemented uRPF by configuring the ip verify unicast source reachable-via rx command on interface gi0/3 The engineer noticed right after implementing F that an inbound packet on the giO-3 interface with a source address of 172 16 3 251 was dropped. Which action resolves the issue?

Options:

A.

Configure uRPF loose mode to forward the packet.

B.

Permit the 172.16.3.251 in the inbound ACL on interface gi0/3.

C.

Permit the 172.16.3.251 in the inbound ACL on interface gi0/3 to allow 172.16.3.251.

D.

Configure uRPF strict mode to forward the packet

Buy Now
Questions 64

Refer to the Exhibit.

300-410 Question 64

R1 and R2 use IGP protocol to route traffic between AS 100 and AS 200 despite being configured to use BGP. Which action resolves the issue and ensures the use of BGP?

Options:

A.

Configure distance to 100 under the EIGRP process of R1 and R2.

B.

Remove distance commands under BGP AS 100 and AS 200.

C.

Remove distance commands under BGP AS 100.

D.

Configure distance to 100 under the OSPF process of R1 and R2

Buy Now
Questions 65

The network administrator configured R1 for Control Plane Policing so that the inbound Telnet traffic is policed to 100 kbps. This policy must not apply to traffic coming in from 10.1.1.1/32 and 172.16.1.1/32. The administrator has configured this:

300-410 Question 65

The network administrator is not getting the desired results. Which set of configurations resolves this issue?

Options:

A.

control-planeno service-policy input PM-CoPP!interface Ethernet 0/0service-policy input PM-CoPP

B.

control-planeno service-policy input PM-CoPPservice-policy input PM-CoPP

C.

no access-list 101access-list 101 deny tcp host 10,1,1.1 any eq 23access-list 101 deny tcp host 172,16.1.1 any eq 23access-list 101 permit ip any any

D.

no access-list 101access-list 101 deny tcp host 10,1.1.1 any eq 23access-list 101 deny tcp host 172.16.1.1 any eq 23access-list 101 permit ip any any!interface E0/0service-policy input PM-CoPP

Buy Now
Questions 66

How do devices operate in MPLS L3VPN topology?

Options:

A.

P and associated PE routers with IGP populate the VRF table in different VPNs.

B.

CE routers connect to the provider network and perform LSP functionality

C.

P routers provide connectivity between PE devices with MPLS switching.

D.

P routers support PE to PE VPN tunnel without LSP functionality

Buy Now
Questions 67

Refer to the exhibit.

300-410 Question 67

R1 is configured with IP SLA to check the availability of the server behind R6 but it kept failing. Which configuration resolves the issue?

Options:

A.

R6(config)# ip sla responder

B.

R6(config)# ip sla responder udp-echo ip address 10.10.10.1 port 5000

C.

R6(config)# ip access-list extended DDOSR6(config ext-nac)# 5 permit icmp host 10.66 66.66 host 10.10.10.1

D.

R6(config)# ip access-list extended DDOSR6(confg ext-nac)# 5 permit icmp host 10.10.10.1 host 10.66.66.66

Buy Now
Questions 68

Refer to the exhibit.

300-410 Question 68

300-410 Question 68

The network administrator must configure Cape Town to reach Dubai via Tokyo based on the speeds provided by the service provider. It was noticed that Cape Town is reaching Dubai directly and failed to meet the requirement. Which configuration fixes the issue?

A)

300-410 Question 68

B)

300-410 Question 68

C)

300-410 Question 68

D)

300-410 Question 68

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Buy Now
Questions 69

What is a function of BFD?

Options:

A.

peer recovery after a Layer 3 protocol adjacency failure

B.

peer recovery after a Layer 2 adjacency failure

C.

failure detection independent of routing protocols and media types

D.

failure detection dependent on routing protocols and media types

Buy Now
Questions 70

300-410 Question 70

Refer to the exhibit. A network engineer lost remote access to the router due to a network problem. The engineer used the console to access the router and noticed continuous logs on the console terminal. Which configuration limits the number of log messages on the console to critical and higher seventy level messages?

Options:

A.

term no monitor

B.

logging console 2

C.

no logging console

D.

logging console 5

Buy Now
Questions 71

:586

While BGP internet routes are redistributed to a lower class of router via RIP. packets are being dropped and routes are failing to be distributed in RIP. Which action resolves the issue?

Options:

A.

Use OSPF instead of RIP to accept all BGP routes.

B.

Use the input-queue command to prevent the loss of packets.

C.

Use WFQ in the output queue of the high-performance router.

D.

Use RIP V2 to be able to use classless networks from BGP

Buy Now
Questions 72

Refer to the exhibit.

300-410 Question 72

Router R2 should be learning the route for 10.123.187.0/24 via EIGRP. Which action resolves the issue without introducing more issues?

Options:

A.

Use distribute-list to modify the route as an internal EIGRP route

B.

Redistribute the route in EIGRP with metric, delay, and reliability

C.

Use distribute-list to filter the external router in OSPF

D.

Remove route redistribution in R2 for this route in OSPF

Buy Now
Questions 73

300-410 Question 73

300-410 Question 73

Refer to the exhibit. Which configuration resolves the route filtering issue on R1 to redistribute all the routes except 172.16.2.48/28?

A)

300-410 Question 73

B)

300-410 Question 73

C)

300-410 Question 73

D)

300-410 Question 73

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 74

When determining if a system is capable of support, what is the minimum time spacing required for a BFD control packet to receive once a control packet is arrived?

Options:

A.

Desired Min TX Interval

B.

Detect Mult

C.

Required Min RX Interval

D.

Required Min Echo RX Interval

Buy Now
Questions 75

Refer to the exhibit.

300-410 Question 75

300-410 Question 75

AS111 is receiving its own routes from AS200 causing a loop in the network. Which configuration provides loop prevention?

A)

300-410 Question 75

B)

300-410 Question 75

C)

300-410 Question 75

D)

300-410 Question 75

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 76

300-410 Question 76

Refer to the exhibit.

A shoe retail company implemented the uRPF solution for an antispoofing attack. A network engineer received the call that the branch A server is under an IP spoofing attack. Which configuration must be implemented to resolve the attack?

A)

300-410 Question 76

B)

300-410 Question 76

C)

300-410 Question 76

D)

300-410 Question 76

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 77

Refer to the exhibit.

300-410 Question 77

The AP status from Cisco DNA Center Assurance Dashboard shows some physical connectivity issues from access switch interface G1/0/14. Which command generates the diagnostic data to resolve the physical connectivity issues?

Options:

A.

test cable diagnostics tdr interface GigabitEthernet1/0/14

B.

Check cable-diagnostics tdr interface GigabitEthernet1/0/14

C.

show cable-diagnostics tdr interface GigabitEthernet1/0/14

D.

Verify cable-diagnostics tdr interface GigabitEthernet1/0/14

Buy Now
Questions 78

Refer to the exhibit.

300-410 Question 78

The none area 0 routers in OSPF still receive more specific routes of 10.1.1.0.10.1.2.0.10.1.3.0 from area 0. Which action resolves the issue?

Options:

A.

Configure route summarization on OSPF-enabled interfaces.

B.

Summarize by using the summary-address 10.1.0.0 255.255.252.0 command.

C.

Summarize by using the area range command on ABRs

D.

Configure the summary-address 10.1.0.0 255.255.252.0 command under OSPF process.

Buy Now
Questions 79

The network administrator configured CoPP so that all HTTP and HTTPS traffic from the administrator device located at 172.16 1.99 toward the router CPU is limited to 500 kbps. Any traffic that exceeds this limit must be dropped.

access-list 100 permit ip host 172.16.1.99 any

!

class-map CM-ADMIN

match access-group 100

!

policy-map PM-COPP

class CM-ADMIN

police 500000 conform-action transmit

!

interface E0/0

service-policy input PM-COPP

CoPP failed to capture the desired traffic and the CPU load is getting higher.

Which two configurations resolve the issue? (Choose two.)

Options:

A.

interface E0/0no service-policy input PM-COPP!control-planeservice-policy input PM-COPP

B.

policy-map PM-COPPclass CM-ADMINno police 500000 conform-action transmitpolice 500 conform-action transmit!control-planeservice-policy input PM-COPP

C.

no access-list 100access-list 100 permit tcp host 172.16.1.99 any eq 80

D.

no access-list 100access-list 100 permit tcp host 172.16.1.99 any eq 80access-list 100 permit tcp host 172.16.1.99 any eq 443

E.

policy-map PM-COPPclass CM-ADMINno police 500000 conform-action transmitpolice 500 conform-action transmit

Buy Now
Questions 80

Refer to the exhibit.

300-410 Question 80

An engineer is troubleshooting BGP on a device but discovers that the clock on the device does not correspond to the time stamp of the log entries. Which action ensures consistency between the two times?

Options:

A.

Configure the service timestamps log uptime command in global configuration mode.

B.

Configure the logging clock synchronize command in global configuration mode.

C.

Configure the service timestamps log datetime localtime command in global configuration mode.

D.

Make sure that the clock on the device is synchronized with an NTP server.

Buy Now
Questions 81

:579

300-410 Question 81

Refer to the exhibit. Router ABR-Rtr is not propagating the internet routes in OSPF area 10. which causes internet reachability problems in the area. Which action resolves the issue?

Options:

A.

ABR-Rtr must configure the default-information originate always command.

B.

ABR-Rtr must configure the area 10 stub no-summary command.

C.

ABR-Rtr network type must be broadcast network.

D.

ABR-Rtr must advertise the 0.0.0.0/0 default route in area 10.

Buy Now
Questions 82

Refer to the exhibit.

300-410 Question 82

A prefix list is created to filter routes inbound to an EIGRP process except for network 10 prefixes After the prefix list is applied no network 10 prefixes are visible in the routing table from EIGRP. Which configuration resolves the issue?

Options:

A.

ip prefix-list EIGRP seq 20 permit 10.0.0.0/8 ge 9.

B.

ip prefix-list EIGRP seq 10 permit 0.0.0.0/0 le 32

C.

ip prefix-list EIGRP seq 5 permit 10.0.0.0/8 ge 9 no ip prefix-list EIGRP seq 20 permit 10.0.0.0/8

D.

ip prefix-list EIGRP seq 20 permit 10.0.0.0/8 ge 9 ip prefix-list EIGRP seq 10 permit 0.0.0.0/0 le 32

Buy Now
Questions 83

Refer to the exhibit.

300-410 Question 83

Users in VLAN46 cannot get the IP from the DHCP server. Assume that all the parameters are configured properly in VLAN 10 and on the DHCP server Which command on interlace VLAN46 allows users to receive IP from the DHCP server?

Options:

A.

ip dhcp-addreos 10.221.10.10

B.

ip dhcp server 10.221.10.10

C.

ip helper-addrets 10.221.10.10

D.

ip dhcp relay information trust-all

Buy Now
Questions 84

What is a limitation of IPv6 RA Guard?

Options:

A.

It is not supported in hardware when TCAM is programmed

B.

It does not offer protection in environments where IPv6 traffic is tunneled.

C.

It cannot be configured on a switch port interface in the ingress direction

D.

Packets that are dropped by IPv6 RA Guard cannot be spanned

Buy Now
Questions 85

Drag and drop the MPLS VPN concepts from the left onto the correct descriptions on the right.

300-410 Question 85

Options:

Buy Now
Questions 86

Refer to the exhibit.

300-410 Question 86

The server for the finance department is not reachable consistently on the 200.30.40.0/24 network and after every second month it gets a new IP address. Which two actions must be taken to resolve this Issue? (Choose two.)

Options:

A.

Configure the server to use DHCP on the network with default gateway 200 30.40.100.

B.

Configure the server with a static IP address and default gateway.

C.

Configure the router to exclude a server IP address.

D.

Configure the server to use DHCP on the network with default gateway 200 30.30.100.

E.

Configure the router to exclude a server IP address and default gateway.

Buy Now
Questions 87

Refer to the exhibit.

300-410 Question 87

An engineer is trying to connect to a device with SSH but cannot connect. The engineer connects by using the console and finds the displayed output when troubleshooting. Which command must be used in configuration mode to enable SSH on the device?

Options:

A.

no ip ssh disable

B.

ip ssh enable

C.

ip ssh version 2

D.

crypto key generate rsa

Buy Now
Questions 88

Refer to the exhibit.

300-410 Question 88

A router receiving BGP routing updates from multiple neighbors for routers in AS 690. What is the reason that the router still sends traffic that is destined to AS 690 to a neighbor other than 10.222.1.1?

Options:

A.

The local preference value in another neighbor statement is higher than 250.

B.

The local preference value should be set to the same value as the weight in the route map.

C.

The route map is applied in the wrong direction.

D.

The weight value in another neighbor statement is higher than 200.

Buy Now
Questions 89

Which statement about route distinguishers in an MPLS network is true?

Options:

A.

Route distinguishers allow multiple instances of a routing table to coexist within the edge router.

B.

Route distinguishers are used for label bindings.

C.

Route distinguishers make a unique VPNv4 address across the MPLS network.

D.

Route distinguishers define which prefixes are imported and exported on the edge router.

Buy Now
Questions 90

Refer to the exhibit.

300-410 Question 90

Redistribution is enabled between the routing protocols, and nowPC2 PC3, and PC4 cannot reach PC1. What are the two solutions to fix the problem? (Choose two.)

Options:

A.

Filter RIP routes back into RIP when redistributing into RIP in R2

B.

Filter OSPF routes into RIP FROM EIGRP when redistributing into RIP in R2.

C.

Filter all routes except RIP routes when redistributing into EIGRP in R2.

D.

Filter RIP AND OSPF routes back into OSPF from EIGRP when redistributing into OSPF in R2

E.

Filter all routes except EIGRP routes when redistributing into OSPF in R3.

Buy Now
Questions 91

Users were moved from the local DHCP server to the remote corporate DHCP server. After the move,

none of the users were able to use the network.

Which two issues will prevent this setup from working properly? (Choose two)

Options:

A.

Auto-QoS is blocking DHCP traffic.

B.

The DHCP server IP address configuration is missing locally

C.

802.1X is blocking DHCP traffic

D.

The broadcast domain is too large for proper DHCP propagation

E.

The route to the new DHCP server is missing

Buy Now
Questions 92

Refer to the exhibit.

300-410 Question 92

Users in the branch network of 2001:db8:0:4::/64 report that they cannot access the Internet. Which command is issued in IPv6 router EIGRP 100 configuration mode to solve this issue?

Options:

A.

Issue the eigrp stub command on R1

B.

Issue the no neighbor stub command on R2.

C.

Issue the eigrp command on R2.

D.

Issue the no eigrp stub command on R1.

Buy Now
Questions 93

Refer to the exhibit.

300-410 Question 93

An engineer is trying to redistribute OSPF to BGP, but not all of the routes are

redistributed. What is the reason for this issue?

Options:

A.

By default, only internal routes and external type 1 routes are redistributed into BGP

B.

Only classful networks are redistributed from OSPF to BGP

C.

BGP convergence is slow, so the route will eventually be present in the BGP table

D.

By default, only internal OSPF routes are redistributed into BGP

Buy Now
Questions 94

Refer to the exhibit.

300-410 Question 94

An engineer is trying to configure local authentication on the console line, but the device is trying to authenticate using TACACS+. Which action produces the desired configuration?

Options:

A.

Add the aaa authentication login default none command to the global configuration.

B.

Replace the capital “C” with a lowercase “c” in the aaa authentication login Console local command.

C.

Add the aaa authentication login default group tacacs+ local-case command to the globalconfiguration.

D.

Add the login authentication Console command to the line configuration

Buy Now
Questions 95

An engineer configured a company’s multiple area OSPF head office router and Site A cisco

routers with VRF lite. Each site router is connected to a PE router of an MPLS backbone.

300-410 Question 95

After finishing both site router configurations, none of the LSA 3,4 5, and 7 are installed at Site A router. Which configuration resolves this issue?

Options:

A.

configure capability vrf-lite on Site A and its connected PE router under router ospf 1 vrf abc

B.

configure capability vrf-lite on Head Office and its connected PE router under router ospf 1 vrf abc

C.

configure capability vrf-lite on both PE routers connected to Head Office and Site A routers under routtr ospf 1 vrf abc

D.

configure capability vrf-lite on Head Office and Site A routers under router ospf 1 vrf abc

Buy Now
Questions 96

Which is statement about IPv6 inspection is true?

Options:

A.

It teams and secures bindings for stateless autoconfiguration addresses in Layer 3 neighbor tables

B.

It learns and secures bindings for stateful autoconfiguration addresses in Layer 3 neighbor tables

C.

It teams and secures bindings for stateful autoconfiguration addresses in Layer 2 neighbor tables

D.

It team and secures binding for stateless autoconfiguration addresses in Layer 2 neighbor tables.

Buy Now
Questions 97

What is the role of a route distinguisher via a VRF-Lite setup implementation?

Options:

A.

It extends the IP address to identify which VFP instance it belongs to.

B.

It manages the import and export of routes between two or more VRF instances

C.

It enables multicast distribution for VRF-Lite setups to enhance EGP routing protocol capabilities

D.

It enables multicast distribution for VRF-Lite setups to enhance IGP routing protocol capabilities

Buy Now
Questions 98

Refer to the exhibit.

300-410 Question 98

Which interface configuration must be configured on the spoke A router to enable a dynamic DMVPN tunnel with the spoke B router?

300-410 Question 98

300-410 Question 98

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 99

Which protocol is used in a DMVPN network to map physical IP addresses to logical IP addresses?

Options:

A.

BGP

B.

LLDP

C.

EIGRP

D.

NHRP

Buy Now
Questions 100

Which command allows traffic to load-balance in an MPLS Layer 3 VPN configuration?

Options:

A.

multi-paths eibgp 2

B.

maximum-paths 2

C.

Maximum-paths ibgp 2

D.

multi-paths 2

Buy Now
Questions 101

What is a role of route distinguishers in an MPLS network?

Options:

A.

Route distinguishers define which prefixes are imported and exported on the edge router

B.

Route distinguishers allow multiple instances of a routing table to coexist within the edge router.

C.

Route distinguishers are used for label bindings.

D.

Route distinguishers make a unique VPNv4 address across the MPLS network

Buy Now
Questions 102

Refer to the exhibit.

300-410 Question 102

An engineer is trying to generate a summary route in OSPF for network 10.0.0.0/8, but the

summary route does not show up in the routing table. Why is the summary route missing?

Options:

A.

The summary-address command is used only for summarizing prefixes between areas.

B.

The summary route is visible only in the OSPF database, not in the routing table.

C.

There is no route for a subnet inside 10.0.0.0/8, so the summary route is not generated.

D.

The summary route is not visible on this router, but it is visible on other OSPF routers in the same area.

Buy Now
Questions 103

Which statement about IPv6 RA Guard is true?

Options:

A.

It does not offer protection in environments where IPv6 traffic is tunneled.

B.

It cannot be configured on a switch port interface in the ingress direction.

C.

Packets that are dropped by IPv6 RA Guard cannot be spanned.

D.

It is not supported in hardware when TCAM is programmed.

Buy Now
Questions 104

Refer to the exhibit.

300-410 Question 104

Users report that IP addresses cannot be acquired from the DHCP server. The DHCP

server is configured as shown. About 300 total nonconcurrent users are using this DHCP server, but none of them are active for more than two hours per day. Which action fixes the issue within the current resources?

Options:

A.

Modify the subnet mask to the network 192.168.1.0 255.255.254.0 command in the DHCP pool

B.

Configure the DHCP lease time to a smaller value

C.

Configure the DHCP lease time to a bigger value

D.

Add the network 192.168.2.0 255.255.255.0 command to the DHCP pool

Buy Now
Questions 105

Refer to the exhibit.

300-410 Question 105

A network engineer for AS64512 must remove the inbound and outbound traffic from link A during maintenance without closing the BGP session so that there ............ a backup link over link A toward the ASN. Which BGP configuration on R1 accomplishes this goal?

A)

300-410 Question 105

B)

300-410 Question 105

C)

300-410 Question 105

D)

300-410 Question 105

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 106

Refer to the exhibit.

300-410 Question 106

AAA server 10.1.1.1 is configured with the default authentication and accounting settings, but the switch cannot communicate with the server Which action resolves this issue?

Options:

A.

Match the authentication port

B.

Match the accounting port

C.

Correct the timeout value.

D.

Correct the shared secret.

Buy Now
Questions 107

Which protocol is used to determine the NBMA address on the other end of a tunnel when mGRE is used?

Options:

A.

NHRP

B.

IPsec

C.

MP-BGP

D.

OSPF

Buy Now
Questions 108

A CoPP policy is applied for receiving SSH traffic from the WAN interface on a Cisco ISR4321 router.

However, the SSH response from the router is abnormal and stuck during the high link utilization. The problem is identified as SSH traffic does not match in the ACL. Which action resolves the issue?

Options:

A.

Rate-limit SSH traffic to ensure dedicated bandwidth.

B.

Apply CoPP on the control plane interface.

C.

Increase the IP precedence value of SSH traffic to 6.

D.

Apply CoPP on the WAN interface inbound direction.

Buy Now
Questions 109

What is considered the primary advantage of running BFD?

Options:

A.

reduction in time needed to detect Layer 2 switched neighbor failures

B.

reduction in time needed to detect Layer 3 routing neighbor failures

C.

reduction in CPU needed to detect Layer 2 switch neighbor failures

D.

reduction in CPU needed to detect Layer 3 routing neighbor failures

Buy Now
Questions 110

An engineer is configuring a network and needs packets to be forwarded to an interface for any destination address that is not in the routing table. What should be configured to accomplish this task?

Options:

A.

set ip next-hop

B.

set ip default next-hop

C.

set ip next-hop recursive

D.

set ip next-hop verify-availability

Buy Now
Questions 111

300-410 Question 111

A network administrator is trying to access a branch router using TACACS+ username and password credentials, but the administrator cannot log in to the router because the WAN connectivity is down. The branch router has following AAA configuration:

300-410 Question 111

Which command will resolve this problem when WAN connectivity is down?

Options:

A.

aaa authentication login default group tacacs+ local

B.

aaa authentication login default group tacacs+ enable

C.

aaa authentication login default group tacacs+ console

D.

aaa authentication login console group tacacs+ enable

Buy Now
Questions 112

Refer to the exhibit.

300-410 Question 112

The output of the trace route from R5 shows a loop in the network. Which configuration

prevents this loop?

A)

300-410 Question 112

B)

300-410 Question 112

C)

300-410 Question 112

D)

300-410 Question 112

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 113

Refer to the exhibit.

300-410 Question 113

300-410 Question 113

The administrator can see the traps for the failed login attempts, but cannot see the traps of successful login attempts. What command is needed to resolve the issue?

Options:

A.

Configure logging history 2

B.

Configure logging history 3

C.

Configure logging history 4

D.

Configure logging history 5

Buy Now
Questions 114

300-410 Question 114

Refer to the exhibits. An engineer filtered messages based on severity to minimize log messages. After applying the filter, the engineer noticed that it filtered required messages as well. Which action must the engineer take to resolve the issue?

Options:

A.

Configure syslog level 2.

B.

Configure syslog level 3.

C.

Configure syslog level 4.

D.

Configure syslog level 5.

Buy Now
Questions 115

What is the minimum time gap required by the local system before putting a BFD control packet on the wire?

Options:

A.

Detect Mult

B.

Required Min Echo RX Interval

C.

Desired Min TX Interval

D.

Required Min RX Interval

Buy Now
Questions 116

Refer to the exhibit.

300-410 Question 116

A network administrator is discovering a Cisco Catalyst 9300 and a Cisco WLC 3504 in Cisco DNA Center. The Catalyst 9300 is added successfully However the WLC is showing [ error "uncontactable" when the administrator tries to add it in Cisco DNA Center. Which action discovers WLC in Cisco DNA Center successfully?

Options:

A.

Copy the .cert file from the Cisco DNA Center on the USB and upload it to the WLC 3504.

B.

Delete the WLC 3504 from Cisco DNA Center and add it to Cisco DNA Center again.

C.

Add the WLC 3504 under the hierarchy of the Catalyst 9300 connected devices.

D.

Copy the .pern file from the Cisco DNA Center on the USB and upload it to the WLC 3504.

Buy Now
Questions 117

Which transport layer protocol is used to form LDP sessions?

Options:

A.

UDP

B.

SCTP

C.

TCP

D.

RDP

Buy Now
Questions 118

Which command displays the IP routing table information that is associated with VRF-Lite?

Options:

A.

show ip vrf

B.

show ip route vrf

C.

show run vrf

D.

show ip protocols vrf

Buy Now
Questions 119

Which protocol does VRF-Lite support?

Options:

A.

IS-IS

B.

ODR

C.

EIGRP

D.

IGRP

Buy Now
Questions 120

Drag and drop the MPLS terms from the left onto the correct definitions on the right.

300-410 Question 120

Options:

Buy Now
Questions 121

Refer to the exhibit.

300-410 Question 121

Which subnet is redistributed from EIGRP to OSPF routing protocols?

Options:

A.

10.2.2.0/24

B.

10.1.4.0/26

C.

10.1.2.0/24

D.

10.2.3.0/26

Buy Now
Questions 122

Which two statements about VRF-Lite configurations are true? (Choose two.)

Options:

A.

They support the exchange of MPLS labels

B.

Different customers can have overlapping IP addresses on different VPNs

C.

They support a maximum of 512.000 routes

D.

Each customer has its own dedicated TCAM resources

E.

Each customer has its own private routing table.

F.

They support IS-IS

Buy Now
Questions 123

Refer to the exhibit.

300-410 Question 123

Why is user authentication being rejected?

Options:

A.

The TACACS+ server expects “user”, but the NT client sends “domain/user”.

B.

The TACACS+ server refuses the user because the user is set up for CHAP.

C.

The TACACS+ server is down, and the user is in the local database.

D.

The TACACS+ server is down, and the user is not in the local database.

Buy Now
Questions 124

Which option is the best for protecting CPU utilization on a device?

Options:

A.

fragmentation

B.

COPP

C.

ICMP redirects

D.

ICMP unreachable messages

Buy Now
Questions 125

Drag and drop the SNMP attributes in Cisco IOS devices from the left onto the correct SNMPv2c or SNMPV3 categories on the right.

300-410 Question 125

Options:

Buy Now
Questions 126

Which list defines the contents of an MPLS label?

Options:

A.

20-bit label; 3-bit traffic class; 1-bit bottom stack; 8-bit TTL

B.

32-bit label; 3-bit traffic class; 1-bit bottom stack; 8-bit TTL

C.

20-bit label; 3-bit flow label; 1-bit bottom stack; 8-bit hop limit

D.

32-bit label; 3-bit flow label; 1-bit bottom stack; 8-bit hop limit

Buy Now
Questions 127

Refer to the exhibit.

300-410 Question 127

After applying IPsec, the engineer observed that the DMVPN tunnel went down, and both

spoke-to-spoke and hub were not establishing. Which two actions resolve the issue? (Choose two.)

Options:

A.

Configure the crypto isakmp key cisco address 192.1.1.1 on R2 and R3

B.

Configure the crypto isakmp key cisco address 0.0.0.0 on R2 and R3.

C.

Change the mode from mode tunnel to mode transport on R3

D.

Change the mode from mode transport to mode tunnel on R2.

E.

Remove the crypto isakmp key cisco address 10.1.1.1 on R2 and R3

Buy Now
Questions 128

Refer to the exhibit.

300-410 Question 128

What is the result of applying this configuration?

Options:

A.

The router can form BGP neighborships with any other device.

B.

The router cannot form BGP neighborships with any other device.

C.

The router cannot form BGP neighborships with any device that is matched by the access list named “BGP”.

D.

The router can form BGP neighborships with any device that is matched by the access list named “BGP”.

Buy Now
Questions 129

An engineer configured the wrong default gateway for the Cisco DNA Center enterprise interface during the install. Which command must the engineer run to correct the configuration?

Options:

A.

sudo maglev-config update

B.

sudo maglev install config update

C.

sudo maglev reinstall

D.

sudo update config install

Buy Now
Questions 130

Refer to the exhibit.

300-410 Question 130

Which statement about R1 is true?

Options:

A.

OSPF redistributes RIP routes only if they have a tag of one.

B.

RIP learned routes are distributed to OSPF with a tag value of one.

C.

R1 adds one to the metric for RIP learned routes before redistributing to OSPF.

D.

RIP routes are redistributed to OSPF without any changes.

Buy Now
Questions 131

300-410 Question 131

Refer to the exhibit. an engineer is trying to get 192.168.32.100 forwarded through 10.1.1.1, but it was forwarded through 10.1.1.2. What action forwards the packets through 10.1.1.1?

Options:

A.

Configure EIGRP to receive 192.168.32.0 route with lower admin distance.

B.

A. Configure EIGRP to receive 192.168.32.0 route with longer prefix than /19.

C.

A. Configure EIGRP to receive 192.168.32.0 route with lower metric.

D.

A. Configure EIGRP to receive 192.168.32.0 route with equal or longer prefix than /24.

Buy Now
Questions 132

An engineer needs dynamic routing between two routers and is unable to establish OSPF adjacency. The output of the show ip ospf neighbor command shows that the neighbor state is EXSTART/EXCHANGE. Which action should be taken to resolve this issue?

Options:

A.

match the passwords

B.

match the hello timers

C.

match the MTUs

D.

match the network types

Buy Now
Questions 133

Refer to Exhibit.

300-410 Question 133

Which two configurations allow clients to get dynamic ip addresses assigned?

Options:

A.

Configure access-list 100 permit udp any any eq 61 as the first line

B.

Configure access-list 100 permit udp any any eq 86 as the first line

C.

Configure access-list 100 permit udp any any eq 68 as the first line

D.

Configure access-list 100 permit udp any any eq 69 as the first line

E.

Configure access-list 100 permit udp any any eq 67 as the first line

Buy Now
Questions 134

Refer to the exhibit.

300-410 Question 134

A company with autonomous system number AS65401 has obtained IP address block 209.165.200.224/27 fro, ARIN. The company needed more IP addresses and was assigned block209.165.202.128/27 from ISP2. An engineer is ISP1 reports they are receiving ISP2 routes from AS65401. Which configuration onR1 resolves the issue?

A)

300-410 Question 134

B)

300-410 Question 134

C)

300-410 Question 134

D)

300-410 Question 134

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 135

300-410 Question 135

Refer to the exhibit. A network administrator configured NTP on a Cisco router to get synchronized time for system and logs from a unified time source The configuration did not work as desired Which service must be enabled to resolve the issue?

Options:

A.

Enter the service timestamps log datetime localtime global command.

B.

Enter the service timestamps log datetime synchronize global command.

C.

Enter the service timestamps log datetime console global command.

D.

Enter the service timestamps log datetime clock-period global command

Buy Now
Questions 136

Refer to Exhibit.

300-410 Question 136

The network administrator configured the branch router for IPv6 on the E0/0 interface. The neighboring router is fully configured to meet requirements, but the neighbor relationship is not coming up. Which action fixes the problem on the branch router to bring the IPv6 neighbors up?

Options:

A.

Enable the IPv4 address family under the router ospfv3 4 process by using the address-family ipv4 unicast command

B.

Disable IPv6 on the E0/0 interface using the no ipv6 enable command

C.

Enable the IPv4 address family under the E0/0 interface by using the address-family ipv4 unicast command

D.

Disable OSPF for IPv4 using the no ospfv3 4 area 0 ipv4 command under the E0/0 interface

Buy Now
Questions 137

What is an advantage of using BFD?

Options:

A.

It detects local link failure at layer 1 and updates routing table.

B.

It detects local link failure at layer 2 and updates routing protocols.

C.

It has sub-second failure detection for layer 1 and layer 3 problems.

D.

It has sub-second failure detection for layer 1 and layer 2 problems.

Buy Now
Questions 138

Refer to the exhibit.

300-410 Question 138

An engineer wanted to set a tag of 30 to route 10 1.80.65/32 but it failed How is the issue fixed?

Options:

A.

Modify route-map ospf-to-eigrp permit 30 and match prefix-list ccnp2.

B.

Modify route-map ospf-to-eigrp permit 10 and match prefix-list ccnp2.

C.

Modify prefix-list ccnp3 to add 10.1.64.0/20 le 24

D.

Modify prefix-list ccnp3 to add 10.1.64.0/20 ge 32

Buy Now
Questions 139

Refer to Exhibit.

300-410 Question 139

Which statement about redistribution from BGP into OSPF process 10 is true?

Options:

A.

Network 172.16.1.0/24 is not redistributed into OSPF.

B.

Network 10.10 10.0/24 is not redistributed into OSPF

C.

Network 172.16.1.0/24 is redistributed with administrative distance of 1.

D.

Network 10.10.10.0/24 is redistributed with administrative distance of 20.

Buy Now
Questions 140

Which security feature can protect DMVPN tunnels?

Options:

A.

IPsec

B.

TACACS+

C.

RTBH

D.

RADIUS

Buy Now
Questions 141

Refer to the exhibit.

300-410 Question 141

Network operations cannot read or write any configuration on the device with this configuration from the operations subnet. Which two configurations fix the issue? (Choose two.)

Options:

A.

Configure SNMP rw permission in addition to community ciscotest.

B.

Modify access list 1 and allow operations subnet in the access list.

C.

Modify access list 1 and allow SNMP in the access list.

D.

Configure SNMP rw permission in addition to version 1.

E.

Configure SNMP rw permission in addition to community ciscotest 1.

Buy Now
Questions 142

Which method changes the forwarding decision that a router makes without first changing the routing table or influencing the IP data plane?

Options:

A.

nonbroadcast multiaccess

B.

packet switching

C.

policy-based routing

D.

forwarding information base

Buy Now
Questions 143

Which two protocols can cause TCP starvation? (Choose two)

Options:

A.

TFTP

B.

SNMP

C.

SMTP

D.

HTTPS

E.

FTP

Buy Now
Questions 144

Refer to the exhibit.

300-410 Question 144

An engineer is monitoring reachability of the configured default routes to ISP1 and ISP2. The default route from ISP1 is preferred if available. How is this issue resolved?

Options:

A.

Use the icmp-echo command to track both default routes

B.

Use the same AD for both default routes

C.

Start IP SLA by matching numbers for track and ip sla commands

D.

Start IP SLA by defining frequency and scheduling it

Buy Now
Questions 145

Refer to the exhibit.

300-410 Question 145

In which circumstance does the BGP neighbor remain in the idle condition?

Options:

A.

if prefixes are not received from the BGP peer

B.

if prefixes reach the maximum limit

C.

if a prefix list is applied on the inbound direction

D.

if prefixes exceed the maximum limit

Buy Now
Questions 146

Drag and drop the OSPF adjacency states from the left onto the correct descriptions on the right.

300-410 Question 146

Options:

Buy Now
Questions 147

Which two methods use IPsec to provide secure connectivity from the branch office to the headquarters office? (Choose two.)

Options:

A.

DMVPN

B.

MPLS VPN

C.

Virtual Tunnel Interface (VTI)

D.

SSL VPN

E.

PPPoE

Buy Now
Questions 148

Drag and drop the packet types from the left onto the correct descriptions on the right.

300-410 Question 148

Options:

Buy Now
Questions 149

Refer to the exhibit.

300-410 Question 149

R2 is a route reflector, and R1 and R3 are route reflector clients. The route reflector learns the route to 172.16.25.0/24 from R1, but it does not advertise to R3. What is the reason the route is not advertised?

Options:

A.

R2 does not have a route to the next hop, so R2 does not advertise the prefix to other clients.

B.

Route reflector setup requires full IBGP mesh between the routers.

C.

In route reflector setup, only classful prefixes are advertised to other clients.

D.

In route reflector setups, prefixes are not advertised from one client to another.

Buy Now
Questions 150

While working with software images, an engineer observes that Cisco DNA Center cannot upload its software image directly from the device. Why is the image not uploading?

Options:

A.

The device must be resynced to Cisco DNA Center.

B.

The software image for the device is in install mode.

C.

The device has lost connectivity to Cisco DNA Center.

D.

The software image for the device is in bundle mode

Buy Now
Questions 151

Refer to the exhibit.

300-410 Question 151

Which configuration denies Telnet traffic to router 2 from 198A:0:200C::1/64?

A)

300-410 Question 151

B)

300-410 Question 151

C)

300-410 Question 151

D)

300-410 Question 151

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 152

Refer to the exhibit.

300-410 Question 152

R1 is configured with IP SLA to check the availability of the server behind R6 but it kept failing. Which configuration resolves the issue?

Options:

A.

R1(config)# ip sla 700R1(config-track)# delay down 30 up 20

B.

R1(config)# ip sla 700R1(config-track)# delay down 20 up 30

C.

R1(config)# track 700 ip sla 700R1(config-track)# delay down 30 up 20

D.

R1(config)# track 700 ip sla 700R1(config-track)# delay down 20 up 30

Buy Now
Questions 153

Refer to the exhibit.

300-410 Question 153

A network administrator must configure DMVPN tunnels between the hub and spoke with dynamic spoke-to-spoke tunnel capabilities using EIGRP. Which tunnel interface command must the network administrator configure to establish an EIGRP peer?

Options:

A.

no ip next-hop-self eigrp 1

B.

ip next-hop-self eigrp 1

C.

no Ip nhrp ntxt-hop-self

D.

ip nhrp next-hop-self

Buy Now
Questions 154

What is the purpose of the DHCPv6 Guard?

Options:

A.

It messages between a DHCPv6 server and a DHCPv6 client ( or relay agent).

B.

It shows that clients of a DHCPv5 server are affected.

C.

It block DHCPv6 messages from relay agents to a DHCPv6 server.

D.

It allows DHCPv6 replay and advertisements from (rouge) DHCPv6 servers.

Buy Now
Questions 155

Drag and drop the descriptions from the left onto the corresponding MPLS components on the right.

300-410 Question 155

Options:

Buy Now
Questions 156

300-410 Question 156

Refer to the exhibit. An engineer configured user login based on authentication database on the router, but no one can log into the router. Which configuration resolves the issue?

Options:

A.

aaa authentication login default enable

B.

aaa authorization network default local

C.

aaa authentication login default local

D.

aaa authorization exec default local

Buy Now
Questions 157

An administrator attempts to download the pack NBAR2 file using TFTP from the CPE router to another device over the Gi0/0 interface. The CPE is configured as below:

300-410 Question 157

The transfer fails. Which action resolves the issue?

Options:

A.

Change the WAN ACL to permit the UDP port 69 to allow TFTP

B.

Make the permit udp any eq tftp any entry the last entry in the WAN ACL.

C.

Change the WAN ACL to permit the entire UDP destination port range

D.

Shorten the file name to the 8+3 naming convention.

Buy Now
Questions 158

An engineer configured VRF-Lite on a router for VRF blue and VRF red. OSPF must be enabled on each VRF to peer to a directly connected router in each VRF. Which configuration forms OSPF neighbors over the network 10.10.10.0/28 for VRF blue and 192.168.0.0/30 for VRF red?

300-410 Question 158

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 159

300-410 Question 159

300-410 Question 159

Refer to the exhibit. An administrator must harden a router, but the administrator failed to test the SSH access successfully to the router. Which action resolves the issue?

Options:

A.

Configure SSH on the remote device to log m using SSH

B.

SSH syntax must be ssh -I user ip to log in to the remote device

C.

Configure enable secret to log in to the device

D.

SSH must be allowed with the transport output ssh command

Buy Now
Questions 160

300-410 Question 160

Refer to the exhibit. A network engineer configured routers R1 and R2 with MP-BGP. The engineer noticed that the routers cannot exchange any IPv6 routes, however, the IPv4 neighbor relationship is working fine. Which configuration must the engineer apply to router R2 to exchange IPv6 routes?

Options:

A.

Ipv6cef I Interface Loopback100Ipv6 address 2001: DB8:128::2/128 Interface GigabitEthernet1/0Ipv6 address 2001:DB8:1::2/64 I router bgp 65002no bgp default ipv4-unlcastneighbor 2001: DB8:1::1 emote-as 65001Iaddress-family ipv6network 2001:DB8:128::2/128neighbor 2001:DB8:1::1 activate

B.

Ipv6 unicast-routingipv6 cefInterface Loopback100ipv6 address 2001: DB8:12C:2 129Iinterface GigabitEthernet1/0ipv6 address 2001: DB8:1::2 64description AS65001 ID B466:A83D:3D7::1!router bgp 65002no bgp default Ipv4-unicastneighbor 2001: DB8:1::1 remote-as 65001!address-family Ipv4neighbor 2001:DB8:1::1 activate

C.

Ipv6 unicast-routingipvG cefIInterface Loopback100Ipv6 address 2001:DB8:128::2/128 I interface GigabitEthernet1/0ipv6 address 2001:DB8:1::2/64!router bgp 65002 no bgp default ipv4-unicast neighbor 2001: DB8:1::1 remote-as 65001 !address-family ipv6 network 2001:DB8:128::2I128

D.

Ipv6 unicast-routing Ipv6 cef Iinterface Loopback100 ipv6 address 2001: DB8:128::2/128 !interface GigabitEthernet1/0 ipv6 address 2001:DB8:1::2/64 irouter bgp 65002 no bgp default ipv4-unicast neighbor 2001: DB8:1::1 remote-as 65001 !address-family ipv6 network 2001:DB8:128::2/128 neighbor 2001:DB8:1::1 activate

Buy Now
Questions 161

Refer to the exhibit.

300-410 Question 161

An engineer is trying to connect to R1 via Telnet with no success. Which configuration resolves the issue?

300-410 Question 161

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 162

300-410 Question 162

Refer to the exhibit An engineer must connect the Reno and Detroit spokes using DMVPN phase 2 Hub tunnel configuration is

300-410 Question 162

Which configuration accomplishes the task?

300-410 Question 162

300-410 Question 162

300-410 Question 162

300-410 Question 162

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 163

Refer to the exhibit.

300-410 Question 163

Refer to the exhibit R1 cannot authenticate via TACACS Which configuration resolves the issue?

300-410 Question 163

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 164

How does an MPLS Layer 3 VPN differentiate the IP address space used between each VPN?

Options:

A.

by RD

B.

by address family

C.

by MP-BGP

D.

byRT

Buy Now
Questions 165

Refer to the exhibit.

300-410 Question 165

The control plane is heavily impacted after the CoPP configuration is applied to the router. Which command removal lessens the impact on the control plane?

Options:

A.

access-list 120 permit udp any any eq pim-auto-rp

B.

access-list 120 permit eigrp any host 224.0.0.10

C.

access-list 120 permit ospf any

D.

access-list 120 permit tcp any gt 1024 eq bgp log

Buy Now
Questions 166

Which rouler takes an active role between two LDP neighbors when initiating LDP session negotiation and LDP TCP connection establishment?

Options:

A.

with the higher IP address

B.

with the larger number of LDP TCP neighbors

C.

with the lowest IP address

D.

with one interface in the MPLS backbone

Buy Now
Questions 167

A customer is running an mGRE DMVPN tunnel over WAN infrastructure between hub and spoke sites. The existing configuration allows NHRP to add spoke routers automatically to the multicast NHRP mappings. The customer is migrated the network from IPv4 to the IPv6 addressing scheme for those spokes’ routers that support IPv6 and can run DMVPN tunnel over the IPv6 network. Which configuration must be applied to support IPv4 and IPv6 DMVPN tunnel on spoke routers?

Options:

A.

Tunnel mode ipv6ip 6to4

B.

Tunnel mode ipv6ip isatap

C.

Tunnel mode ipv6ip auto-tunnel

D.

Tunnel mode ipv6ip 6rd

Buy Now
Questions 168

A company Is redesigning WAN infrastructure so that all branch sites must communicate via the head office and the head office can directly communicate with each site independently. The network engineer must configure the head office router by considering zero-touch technology when adding new sites in the same WAN infrastructure. Which configuration must be applied to the head office router to meet this requirement?

300-410 Question 168

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 169

Refer to the exhibit.

300-410 Question 169

A NOC team receives a ticket that data traffic from RA to RF is not forwarded when the link between the RC-RE path goes down. All routers learn loopback IP through the IGP protocol. Which configuration resolves?

Options:

A.

RD(config)#router bgp B5201RD(config-router)# neighbor 10.10.10.2 update-source loopback 0

B.

RD(config-router)# neighbor bgp 65101RB(config-router)# neighbor 10.10.10.3 ebgp-multihop 3

C.

RB(config)# router bgp 65101RB(config)#neighbor 10.10.10.3 update-source loopback 0

D.

RD(config)# router bgp 65201RDI(config-router)# neighbor 10.10.10.2 ebgp-multihop 3

Buy Now
Questions 170

Refer to the exhibit.

300-410 Question 170

Spoke routers do not learn about each other's routes in the DMVPN Phase2 network. Which action resolves the issue?

Options:

A.

Remove default route from spoke routers to establish a spoke-to-spoke tunnel.

B.

Configure a static route in each spoke to establish a spoke-to-spoke tunnel.

C.

Rectify incorrect wildcard mask configured on the hub router network command.

D.

Disable EIGRP split horizon on the TunnelO interface of the hub router.

Buy Now
Questions 171

Refer to the exhibit.

300-410 Question 171

An engineer is trying to add an encrypted user password that should not be visible in the router configuration. Which two configuration commands resolve the issue? (Choose two)

Options:

A.

password encryption aes

B.

username Admin password Cisco@maedeh motamedi

C.

username Admin password 5 Cisco@maedeh motamedi

D.

username Admin secret Cisco@maedeh motamedi

E.

no service password-encryption

F.

service password-encryption

Buy Now
Questions 172

Refer to the exhibit.

300-410 Question 172

Which set of commands restore reachability to loopback0?

A)

300-410 Question 172

B)

300-410 Question 172

C)

300-410 Question 172

D)

300-410 Question 172

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 173

300-410 Question 173

Refer to the exhibit. An engineer must troubleshoot an issue with the aaa authentication that affected the user's login to router R1. Which command allows the configured user to authenticate?

Options:

A.

aaa authentication login default group radius local

B.

aaa authentication login default group radius tacacs+

C.

aaa authentication login default group tacacs+

D.

aaa authentication login default group radius

Buy Now
Questions 174

How are MPLS Layer 3 VPN services deployed?

Options:

A.

The RD and RT values must match under the VRR

B.

The RD and RT values under a VRF must match on the remote PE router

C.

The import and export RT values under a VRF must always be the same.

D.

The label switch path must be available between the local and remote PE routers.

Buy Now
Questions 175

Drag and drop the LDP features from the left onto the descriptions on the right

300-410 Question 175

Options:

Buy Now
Questions 176

Drag and drop the MPLS concepts from the left onto the descriptions on the right.

300-410 Question 176

Options:

Buy Now
Questions 177

Refer to the exhibit.

300-410 Question 177

A client is concerned that passwords are visible when running this show archive log config all.

Which router configuration is needed to resolve this issue?

Options:

A.

MASS-RTR(config-archive-log-cfg)#password encryption aes

B.

MASS-RTR(config)#aaa authentication arap

C.

MASS-RTR(config)#service password-encryption

D.

MASS-RTR(config-archive-log-cfg)#hidekeys

Buy Now
Questions 178

300-410 Question 178

Refer to the exhibit. The OSPF neighbor relationship is not coming up What must be configured to restore OSPF neighbor adjacency?

Options:

A.

OSPF on the remote router

B.

matching hello timers

C.

use router ID

D.

matching MTU values

Buy Now
Questions 179

After some changes in the routing policy, it is noticed that the router in AS 45123 is being used as a transit AS router for several service provides. Which configuration ensures that the branch router in AS 45123 advertises only the local networks to all SP neighbors?

A)

300-410 Question 179

B)

300-410 Question 179

C)

300-410 Question 179

D)

300-410 Question 179

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 180

Refer to the exhibit.

300-410 Question 180

An engineer configures a static route on a router, but when the engineer checks the route

to the destination, a different next hop is chosen. What is the reason for this?

Options:

A.

Dynamic routing protocols always have priority over static routes.

B.

The metric of the OSPF route is lower than the metric of the static route.

C.

The configured AD for the static route is higher than the AD of OSPF.

D.

The syntax of the static route is not valid, so the route is not considered.

Buy Now
Questions 181

Which label operations are performed by a label edge router?

Options:

A.

SWAP and POP

B.

SWAP and PUSH

C.

PUSH and PHP

D.

PUSH and POP

Buy Now
Questions 182

Refer the exhibit.

300-410 Question 182

Which action resolves intermittent connectivity observed with the SNMP trap

packets?

Options:

A.

Decrease the committed burst Size of the mgmt class map

B.

Increase the CIR of the mgmt class map

C.

Add a new class map to match TCP traffic

D.

Add one new entry in the ACL 120 to permit the UDP port 161

Buy Now
Questions 183

Refer to the exhibit.

300-410 Question 183

Drag and drop the credentials from the left onto the remote login information on the right to resolve a failed login attempt to vtys. Not all credentials are uf SLA by defining frequency and schedulingsed

300-410 Question 183

Options:

Buy Now
Questions 184

A network engineer is investigating a flapping (up/down) interface issue on a core switch that is synchronized to an NTP server. Log output currently does not show the time of the flap. Which command allows the logging on the switch to show the time of the flap according to the clock on the device?

Options:

A.

service timestamps log uptime

B.

clock summer-time mst recurring 2 Sunday mar 2:00 1 Sunday nov 2:00

C.

service timestamps log datetime localtime show-timezone

D.

clock calendar-valid

Buy Now
Exam Code: 300-410
Exam Name: Implementing Cisco Enterprise Advanced Routing and Services (300-410 ENARSI)
Last Update: Sep 27, 2025
Questions: 615

PDF + Testing Engine

$74.6  $186.49

Testing Engine

$59.8  $149.49
buy now 300-410 testing engine

PDF (Q&A)

$55  $137.49
buy now 300-410 pdf