Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Free Practice Questions for the Cisco CCNP Service Provider 350-501 Exam (2026 Updated)

At Marks4sure, we are dedicated to providing IT professionals with the most accurate and reliable preparation materials for the Cisco 350-501 exam. To support your certification journey, we have made a selection of our premium 2026 CCNP Service Provider practice questions and answers available completely free. You can take this practice test as many times as you need. Every question includes a detailed, expertly verified explanation to ensure you fully grasp the core security concepts before test day.

Questions 4

350-501 Question 4

Refer to the exhibit. OSPF is running in the given network. R1 was previously running EIGRP on a standalone network, and a network engineer just migrated it to OSPF. The R1 peering with R2 has come up.

Which additional action must the engineer take so that R2 receives routes from Area 1 and Area 0 but is prevented from receiving routes from Area 2?

Options:

A.

Implement a route map that matches R2 ' s interface to R3 and R4, and then attach the route map to an inbound distribute list on R2.

B.

Implement a route map that matches the routes in an ACL from Area 2, and then attach the route map to an inbound distribute list on R2.

C.

Implement a route map that matches the routes from Area 2 in a prefix list, and then attach the route map to an outbound distribute list on R2.

D.

Implement a route map that matches R1 ' s next-hop address, and then attach the route map to an outbound distribute list on R2.

Buy Now
Questions 5

Which MPLS design attribute can you use to provide Internet access to a major customer through a separate dedicated VPN?

Options:

A.

The customer that needs the Internet access service is assigned to the same RTs as the Internet gateway

B.

The Internet gateway inserts the full Internet BGP routing table into the Internet access VPN

C.

The Internet gateway router is connected as a PE router to the MPLS backbone.

D.

The CE router supports VRF-Ute and the full BGP routing table.

Buy Now
Questions 6

Refer to the exhibit:

350-501 Question 6

An engineer is preparing to implement link aggregation configuration.

Which statement al about this configuration is true?

Options:

A.

The switch port actively sends packets to negotiate an EtherChannel using PAgP

B.

The switch port accepts LACP and PAgP packets from a connected peer and negotiate an EtherChannel using the common EtherChannel mode.

C.

The switch port passively negotiates an EtherChannel if it receives PAgP packets from a connected peer

D.

The switch port negotiates an EtherChannel if it receives LACP packets from a connected peer

Buy Now
Questions 7

What is an enhancement that Cisco IOS XE Software has over Cisco IOS Software?

Options:

A.

It support symmetric multiprocessing

B.

It allows all processes to use the same pool of memory.

C.

It runs on a 32-bit operating system.

D.

It is built on a GNX Neutrino Microkernel.

Buy Now
Questions 8

A regional MPLS VPN provider operates m two regions and wants to provide MPLS L 3VPN service for a customer with two sites in these separate locations. The VPN provider approaches another organization to provide backbone carrier services so that the provider can connect to these two locations.

Which statement about this scenario is true?

Options:

A.

When edge routers at different regional sites are connected over the global carrier backbone, MP-eBGP must run between the routers to exchange the customer VPNv4 routes

B.

When eBGP is used for label exchange using the send label option, MPLS-BGP forwarding is configured under the global ABC CSC PE-to CE interface

C.

When IGP is used for route exchange and LDP for label exchange, MPLS is enabled only on the VRF interface on the backbone-earner PE side.

D.

When BGP is used for both route and label exchange, the neighbor a.b.c.d send-lable command is used under the address family VPNv4 command mode.

Buy Now
Questions 9

Refer to the exhibit:

350-501 Question 9

R1 is connected to two service providers and is under a DDoS attack Which statement about this design is true if uRPF in strict mode is configured on both interfaces ' ?

Options:

A.

R1 accepts source addresses on interface gigabitethernet0/1 that are private addresses

B.

R1 permits asymmetric routing as long as the AS-RATH attribute entry matches the connected AS

C.

R1 drops destination addresses that are routed to a null interface on the router

D.

R1 drops all traffic that ingresses either interface that has a FIB entry that exits a different interface

Buy Now
Questions 10

Drag and drop the SG KAN architecture types from the bottom next to the corresponding topologies on the right.

350-501 Question 10

Options:

Buy Now
Questions 11

An ISP that provides private network services across the country has recently migrated their infrastructure to support MPLS technology. A network engineer configured mpls ip on all routers and implemented the OSPF routing protocol with TE extensions in the backbone area. The ISP wants to ensure that label exchange is performed only on MPLS-enabled interfaces that are associated with the IGP instance.

Which action must the engineer take to accomplish the goal?

Options:

A.

Enable Cisco Express Forwarding on all routers in the backbone area.

B.

Implement mpls Idp sync on all routers in the segment.

C.

Update the routers in the segment to use RSVP-TE for label distribution.

D.

Implement mpls Idp autoconfig on all routers in the segment.

Buy Now
Questions 12

What is a constraint of Cisco MPLS TE tunnel configurations?

Options:

A.

Tunnels cannot span multiple OSPF areas.

B.

With ISIS as an IGP. only older-style metrics are used.

C.

Tunnels cannot be configured over IP unnumbered links.

D.

QoS-aware tunneling is not supported.

Buy Now
Questions 13

350-501 Question 13

Refer to the exhibit. A network engineer with an employee ID: 5086:72:817 is configuring a connection to manage CE1 from the OAM server on VLAN 100. PE1 must push S-VLAN tag 10 toward PE2 while forwarding traffic from CE1 to the OAM server. PE1 must push S-VLAN tag 20 toward PE2 while forwarding traffic from CE2 to the data traffic gateway. Which configuration must the engineer implement on PE2?

Options:

A.

interface GigE0/1

encapsulation dot1q 100

rewrite ingress tag pop 10

rewrite ingress tag push 20

B.

interface Ge0/0

encapsulation dot1q 100

rewrite ingress tag push dot1q 10 symmetric

interface Ge0/1

encapsulation dot1q 200

rewrite ingress tag push dot1q 20 symmetric

C.

interface GigE0/1

encapsulation dot1q 10

rewrite ingress tag push dot1q 10 symmetric

Interface Ge0/0

encapsulation dot1q 20

rewrite ingress tag push dot1q 20 symmetric

D.

Interface Ge0/1

encapsulation dot1q 100

Buy Now
Questions 14

Refer to the exhibit. After a networking team configured this MPLS topology, the supervisor wants to view MPLS labels to verify the path that packets take from router R1 to router R7 The team already Issued an ICMP ping to verify connectivity between the devices. Which task must the team perform to allow the supervisor to view the label switch path?

350-501 Question 14

Options:

A.

Configure MPLS TE to display the labels in the stack between the head and tail-end routers

B.

Implement MPLS LDP to assign labels to all the routes in the transit path.

C.

Configure MPLS LDP Sync to sync labels from the routing table to the MPLS forwarding table.

D.

Implement MPLS OAM to display the labels for each hop along the path

Buy Now
Questions 15

350-501 Question 15

Refer to the exhibit. A network engineer is configuring an SNMP community on router RB with these requirements:

    Allow read-only access for all objects to members of Access-List 10 that use the comaccess community string.

    Other SNMP managers must not have access to objects.

    SNMP authentication failure traps must be sent to SNMPv2c and then to the host using SNMPv2c with the public community string.

Which configuration meets these requirements?

350-501 Question 15

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 16

A network architect at ISP must implement a loop-avoidance mechanism in the organization ' s ring network topology. The architect decided to implement ITU-T G.8032. Intermittent link flaps within two seconds should be ignored. Which two configurations must the architect apply? (Choose two.)

Options:

A.

ring-protection g8032 profile vlan port-channel none

B.

link-protection group management vlan 1

C.

timer hold-off 2

D.

continuity-check direction down 2

E.

ethernet ring g8032 profile ethernet

Buy Now
Questions 17

350-501 Question 17

Refer to the exhibit. A large organization is merging the network assets of a recently acquired competitor with one of its own satellite offices in the same geographic area. The newly acquired network is running different routing protocol than the company ' s primary network. As part of the merger a network engineer implemented this route map Which task must the engineer perform to complete the Implementation?

Options:

A.

Attach the route map to an IS-IS network statement to advertise the routes learned on this interface to IS-IS

B.

Enable metric style wide to allow the use of extended metrics from the protocols

C.

Attach the route map to the redistribution command to manipulate the routes as they are shared

D.

Configure an additional route map sequence to override the implicit deny at the end of the route map

Buy Now
Questions 18

Which type of attack is an application attack?

Options:

A.

ping of death

B.

ICMP (ping) flood

C.

HTTP flood

D.

SYN flood

Buy Now
Questions 19

350-501 Question 19

Refer to the exhibit. An Ethernet access provider is configuring routers PE-1 and PE-2 to provide E-Access EVPL service between UNI and ENNI. ENNI service multiplexing is based on 802.1ad tag 150, and service-multiplexed UNI is based on 802.1q tag 10. Which EFP configurations must the provider implement on PE-1 and PE-2 to establish end-to-end connectivity between CE-1 and CE-2?

Options:

A.

On PE-1:

interface GigabitEthernet2

service instance 100 ethernet

encapsulation dot1ad 150

rewrite ingress tag pop 1 symmetric

On PE-2:

interface GigabitEthernet2

service instance 2 ethernet

encapsulation dot1q 10

B.

On PE-1:

interface GigabitEthernet2

service instance 100 ethernet

encapsulation dot1q 150

rewrite ingress tag pop 1 symmetric

On PE-2:

interface GigabitEthernet2

service instance 2 ethernet

encapsulation dot1q 10

C.

On PE-1:

interface GigabitEthernet2

service instance 100 ethernet

encapsulation dot1ad 150 dot1q 10

rewrite ingress tag pop 2 symmetric

On PE-2:

interface GigabitEthernet2

service instance 2 ethernet

encapsulation dot1q 10

D.

On PE-1:

interface GigabitEthernet2

service instance 100 ethernet

encapsulation dot1ad 150

rewrite ingress tag pop 1 symmetric

On PE-2:

interface GigabitEthernet2

service instance 2 ethernet

encapsulation dot1q 10

rewrite ingress tag pop 1 symmetric

Buy Now
Questions 20

What is a characteristics of the Pipe model for MPLS QoS?

Options:

A.

The same QoS policy is applied to all customer traffic on the egress PE.

B.

If the outer EXP is changed, it is copied to the DSCP value.

C.

The MPLS EXP bits are set by the CE.

D.

The DSCP value determines how the packet is forwarded

Buy Now
Questions 21

How does SR policy operate in Segment Routing Traffic Engineering?

Options:

A.

An SR policy for color and endpoint is deactivated at the headend as soon as the headend learns a valid candidate path for the policy.

B.

When " invalidation drop " behavior occurs, the SR policy forwarding entry is removed and the router drops all traffic that is steered into the SR policy.

C.

When a set of SID lists is associated with the SR policy designated path, traffic steering is ECMP-based according to the qualified cost of each SID-list.

D.

An active SR policy installs a BSID-keyed entry in the forwarding table to steer the packets that match the entry to the SR policy SID-list.

Buy Now
Questions 22

Refer to the exhibit:

350-501 Question 22

After implementing a new design for the network, a technician reviews the pictured CLI output as part of the MOP.

Which two statements describe what the technician can ascertain from the ImpNull output? (Choose two.)

Options:

A.

Label 0 is used for the prefix displayed but will not be part of the MPLS label stack for packets destined for 192 168.10.10.

B.

Ultimate Hop Popping is in use for the prefix displayed.

C.

Label 0 is used for the prefix displayed and will be part of the MPLS label stack for packets destined for 192.168.10.10

D.

Penultimate Hop Popping is in use for the prefix displayed

E.

Label 3 is in use for the prefix displayed and will be part of the MPLS label stack for packets destined for 192.168.10.10

Buy Now
Questions 23

Refer to the exhibit:

350-501 Question 23

Which statement about the status of the neighbor relationship between R1 and R2 is true?

Options:

A.

The neighbor relationship is down because the two routers are configured with different area types

B.

The neighbor relationship is down because the two routers are in the same subnet.

C.

The neighbor relationship is up because R2 is level 1 and level 2 router.

D.

The neighbor relationship is down because R2 is operating as a Level 1 router and the two routers are in different area

Buy Now
Questions 24

350-501 Question 24

Refer to the exhibit. PE1 is a router connected to a major ISP that provides connectivity for multiple enterprises in several different geographic locations. The ISP networking team uses REST APIs to configure the network devices. A senior engineer retrieved the given script from the library and provided it to a junior engineer to deploy. What effect does the script produce when deployed?

Options:

A.

It configures an interface on PE1.

B.

It configures an interface on Switch 1.

C.

It limits PE1 to exactly one configured interface.

D.

It sets the router name, location, and interface on PE1 and Switch-1.

Buy Now
Questions 25

What are two features of stateful NAT64? (Choose two.)

Options:

A.

It uses address overloading.

B.

It provides 1:N translations, so it supports an unlimited number of endpoints.

C.

It requires IPv4-translatable IPv6 address assignments.

D.

It requires the IPv6 hosts to use either DHCPv6-based address assignments or manual address assignments.

E.

It provides 1:1 translation, so it supports a limited number of endpoints.

Buy Now
Questions 26

The NOC engineer in a service provider network must configure an SNMP community on switch SW with these security attributes:

* Event messages must be authenticated with the MD5 algorithm and encrypted.

* The remote user name for the SNMP server at 172.16.10.1 is AuthNocUser.

Which configuration must the engineer apply to the switch?

Options:

A.

SW(config)# snmp-server group group2 v3 auth

SW(config)# snmp-server user AuthNocUser group2 remote 172.16.10.1 v3 auth md5 password1

B.

SW(config)# snmp-server group group3 v3 priv

SW(config)# snmp-server user AuthNocUser group3 remote 172.16.10.1 v3 auth md5 Cisco@123 priv des 56

C.

SW(config)# snmp-server group group1 v3 noauth

SW(config)# snmp-server user AuthNocUser group1 remote 172.16.10.1

SW(config)# snmp-server host 172.16.10.1 informs version 3 noauth remoteuser config

D.

SW(config)# snmp-server community comaccess ro 4

SW(config)# snmp-server enable traps snmp authentication

SW(config)# snmp-server host cisco.com version 2c public

Buy Now
Questions 27

Refer to the exhibit.

350-501 Question 27

What is the effect of this configuration?

Options:

A.

R1 supports a graceful restart operation on the peer, even if graceful restart is disabled on the peer.

B.

R1 supports a peer that is configured for LDP SSO/NSF as the peer recovers from an outage.

C.

R1 failovers only to a peer that is configured for LDP SSO/NSF.

D.

R1 failovers to any peer.

Buy Now
Questions 28

Refer to the exhibit.

350-501 Question 28

A network administrator is implementing IGMP to enable multicast feed transmission to the receiver. Which configuration must the administrator deploy on GW1 to permit IGMP Joins only to the assigned (S, G) feed?

A)

350-501 Question 28

B)

350-501 Question 28

C)

350-501 Question 28

D)

350-501 Question 28

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 29

350-501 Question 29

Refer to the exhibit. A network engineer with an employee ID 4379:43:595 is setting up an IS-IS network with these requirements:

    Routes with a tag of 80 and IP prefixes other than 192.168.10.20/24 must be redistributed from Level 1 into Level 2.

    Route leaking must be configured from Level 2 into the Level 1 domain for routes that are tagged with only 50 or 40.

Which configuration must be implemented on RB to meet the requirements?

Options:

A.

Add match tag 80 in route-map Ieak2-1

B.

DUMPS Add match ip address 152 in route-map redist1-2

C.

Remove match tag 40 from route-map Ieak2-1

D.

Change match tag 80 to match tag 50 in route-map redist1-2.

Buy Now
Questions 30

In MPLS traffic engineering, which FRR operation swaps the label and pushes the backup label?

Options:

A.

Merge Point

B.

Point of Local Repair

C.

Branch Point

D.

Mid-Point

Buy Now
Questions 31

350-501 Question 31

Refer to the exhibit. This enterprise configured MPLS within its network to connect offices that span different geographic areas, with LDP running between connected neighbors. At each office, including headquarters, the networks are running OSPF with a similar configuration.

Which additional action must the engineering team take to support a more reliable connection between MPLS and OSPF?

Options:

A.

Implement targeted LDP sessions between the peers connected to interface g0/1 and g0/2.

B.

Implement MD5 authentication between LDP and OSPF neighbors to secure the connection.

C.

Implement LDP session protection to maintain uptime during outages.

D.

Implement MPLS LDP sync to synchronize OSPF and LDP.

Buy Now
Questions 32

What must a network engineer consider when designing a Cisco MPLS TE solution with OSPF?

Options:

A.

The OSPF extensions and RSVP-TE must be enabled on all routers in the network.

B.

OSPF extensions for RSVP-TE are supported in Area 1.

C.

The OSPF extensions and RSVP-TE must be enabled on the egress routers.

D.

OSPF extensions for RSVP-TE are implemented in Type 6, 7, and 8 LSAs.

Buy Now
Questions 33

350-501 Question 33

Refer to the exhibit. AS 65517 is running OSPF within the core. BGP is running between all four autonomous systems, interconnecting several ISPs that provide intranet and extranet services. All of the PE routers are connected, and eBGP peering relationships have been established. A network engineer also configured an iBGP peering between PE3 and P1, and the peering is up. However, P1 cannot reach routes outside of AS 65517. Which action must the engineer take so that P1 reaches external routes?)

Options:

A.

Synchronize BGP and OSPF with AS 65517.

B.

Add the next-hop-self attribute under the BGP neighbor configuration for P1 on PE3.

C.

Install route targets on all PE routers under the VRF configuration for intranet services.

Buy Now
Questions 34

While an engineer deploys a new Cisco device to redistribute routes from OSPF to BGP, they notice that not all OSPF routes are getting advertised into BGP. Which action must the engineer perform so that the device allows O, OIA, OE1, and OE2 OSPF routes into other protocols?

Options:

A.

Configure the device to pass only O and E2 routes through it.

B.

Configure the synchronization keyword in the global BGP configuration.

C.

Configure the keyword nssa in the redistribution entry.

D.

Configure the keywords internal and external in the redistribution entry.

Buy Now
Questions 35

You are writing an RPL script to accept routes only from certain autonomous systems Consider this code.

350-501 Question 35

If you apply this code to BGP filters, which effect does the code have on your router?

Options:

A.

denies routes from AS 7070

B.

allows routes from AS 7077

C.

denies routes from AS 7007

D.

allows routes from AS 770

Buy Now
Questions 36

Refer to the exhibit.

350-501 Question 36

A network operator working for a telecommunication company with an employee 3994:37:650 is implementing a cisco Unified MPLS solution. What is the effect of this implementation?

Options:

A.

EIGRP is deployed between the PEs and ABRs with RFC 3107.

B.

OSPF is deployed between the PEs and ABRs with RFC 3107.

C.

IS-IS is deployed between the PEs and ABRs with RFC 3107.

D.

BGP is deployed between the PEs and ABRs with RFC 3107.

Buy Now
Questions 37

Which is the benefit of implementing model-driven telemetry in a service provider environment?

Options:

A.

It reduces the number of network monitoring tools that are necessary to verify device statistics.

B.

It increases the efficiency of SNMP by pulling system data to requesting servers.

C.

It reduces or eliminates the need to monitor Layer 2 traffic between switches.

D.

It uses reliable transport to push Information to network monitoring tools

Buy Now
Questions 38

350-501 Question 38

Refer to the exhibit. A network engineer configures CPE-1 for QoS with these requirements:

IPv4 and IPv6 traffic originated by the CPE-1 WAN IP address must be marked with DSCP CS3.

IPv4 LAN traffic must be marked with DSCP CS1.

IPv6 LAN traffic must be marked with DSCP default.

Which configuration must the engineer implement on CPE-1?

Options:

A.

class-map match-any SELF_TRAFFIC

match access-group name SELF_V4

match access-group name SELF_V6

class-map match-all V4_ TRAFFIC

match protocol ip

class-map match-all V6_TRAFFIC

match protocol ipv6

class-map match-all QG_4

match qos-group 4

class-map match-all QG_6

match qos-group 6

!

policy-map LAN-INPUT

class V4_TRAFFIC

set qos-group 4

class V

B.

class-map match-all SELF_TRAFFIC

match access-group name SELF_V4

match access-group name SELF_V6

class-map match-all V4_ TRAFFIC

match protocol ip

class-map match-all V6_TRAFFIC

match protocol ipv6

class-map match-all QG_4

match qos-group 4

class-map match-all QG_6

match qos-group 6

!

policy-map LAN-INPUT

class V4_TRAFFIC

set qos-group 4

class V

C.

class-map match-all SELF_TRAFFIC

match access-group name SELF_V4

match access-group name SELF_V6

class-map match-all V4_ TRAFFIC

match protocol ip

class-map match-all V6_TRAFFIC

match protocol ipv6

class-map match-all QG_4

match qos-group 4

class-map match-all QG_6

match qos-group 6

!

policy-map LAN-INPUT

class V4_TRAFFIC

set qos-group 4

class V

D.

class-map match-any SELF_TRAFFIC

match access-group name SELF_V4

match access-group name SELF_V6

class-map match-all V4_ TRAFFIC

match protocol ip

class-map match-all V6_TRAFFIC

match protocol ipv6

class-map match-all QG_4

match qos-group 4

class-map match-all QG_6

match qos-group 6

!

policy-map LAN-INPUT

class V4_TRAFFIC

set qos-group 4

class V

Buy Now
Questions 39

Refer to the exhibit.

350-501 Question 39

A network engineer is implementing OSPF multiarea. Which command on interface GO/1 resolves adjacency issues in the new area?

Options:

A.

ip ospf network broadcast

B.

ip ospf network point-to-point

C.

ip ospf network non-broadcast

D.

ip ospf network point-to-multipoint

Buy Now
Questions 40

Refer to the exhibit.

350-501 Question 40

A network engineer must configure an LDP neighborship between two newly installed routers that are located in two different offices. Router 1 is the core router in the network and it has already established OSPF adjacency with router 2. On router 1 and router 2. interface fa0/0 is configured for BFD. Which additional configuration must the engineer apply to the two devices to meet the requirement?

Options:

A.

Router1(config)#int fa0/0 -

Router1(config-if)#mpls ldp autoconfig

Router2(config)#router ospf 1 -

Router2(config-router)#mpls ip

B.

Router1(config)#int fa0/0 -

Router1(config-if)#mpls ip -

Router1(config-if)#mpls ldp discovery transport-address interface

Router2(config)#int fa0/0 -

Router2(config-if)#mpls ip -

Router2(config-if)#mpls ldp discovery transport-address interface

C.

Route1(config)#int fa0/0 -

Router1(config-if)#mpls ldp autoconfig

Router1(config-if)#mpls ldp discovery interface

Router2(config)#router ospf 1 -

Router2(config-router)#mpls ldp autoconfig

Router2(config-if)#mpls ldp discovery interface

D.

Router1(config)#int fa0/0 -

Router1(config-if)#mpls ip -

Router2(config)#router ospf 1 -

Router2(config-router)#mpls ldp autoconfig

Buy Now
Questions 41

Drag and drop the functions from the path computation element protocol roles on the right.

350-501 Question 41

Options:

Buy Now
Questions 42

A network operator needs to implement PIM-SSM multicast configuration on customer ' s network so that users in different domains are able to access and stream live traffic. Which two actions must the engineer perform on the network

to make the streaming work? (Choose two.)

Options:

A.

Configure at least one MSDP peer on the network

B.

Enable IGMP version 2 at the interface lever.

C.

Enable PIM sparse mode on the device.

D.

Enable IGMP version 3 at the interface level.

E.

Enable PM dense mode on the device.

Buy Now
Questions 43

An engineer needs to implement QOS mechanism on customer ' s network as some applications going over the internet are slower than others are. Which two actions must the engineer perform when implementing traffic shaping on the network in order to accomplish this task? (Choose two)

Options:

A.

Configure a queue with sufficient memory to buffer excess packets.

B.

Configure the token values in bytes.

C.

Implement packet remarking for excess traffic.

D.

Implement a scheduling function to handle delayed packets.

E.

Configure a threshold over which excess packets are discarded.

Buy Now
Questions 44

Refer to me exhibit.

350-501 Question 44

A network operator recently configured BGP FlowSpec for me internal IT network What will be inferred from the configuration deployed on me network?

Options:

A.

The policy is configured locally on CSRl and drops all traffic for TCP ports 80 and 443

B.

The policy is learned via BGP FlowSpec and drops all traffic for TCP ports 80 and 443

C.

The policy is warned via BC FlowSpec aid has active traffic

D.

The policy is configured locally on CSR1 and currently has no active traffic

Buy Now
Questions 45

350-501 Question 45

Refer to the exhibit. Router BRDR-1 is configured to receive the 0.0.0.0/0 and 172.17.1.0/24 network via BGP and advertise then into OSPF area 0. An engineer has noticed that the OSPF domain is receiving only the 172.17.1.0/24 route and default router 0.0.0.0/0 is still missing. Which configuration must an engineer apply to resolve this problem?

350-501 Question 45

      Option A

      Option B

      Option C

Options:

A.

Option D

Buy Now
Questions 46

After implement MPLS protocol for multiple VRFs on a single Cisco device, the engineer notices all VRFs on the router still do to not LDP session protection feature enabled. Which configuration must the engineer apply to enable the LDP session protection feature FOR LDP neighbors within each VRF?

Options:

A.

Configure LDP session protection globally on the device only.

B.

Configure LDP session protection globally on the device and on each neighbor that requires session protection.

C.

Configure LDP session authentication on the device to enable LDP session protection on each VRF automatically.

D.

Configure LDP session protection within the individual VRFs.

Buy Now
Questions 47

An engineer implemented LDP protocol on the ISP network. The engineer must ensure that there are no packet loss issues when IGP and LDP protocols are not synchronized. Which configuring must the engineer implement so that the IGP routing protocol will wait until LDP convergence is completed?

Options:

A.

Disable IP CEF routers running LDP and enable LDP protocol.

B.

Configure MPLS LDP IGP synchronization on the network.

C.

Configure LDP sessions protection on the network.

D.

Disable MPLS LDP IGP synchronization on the network.

Buy Now
Questions 48

A network engineer is configuring RIP as the routing protocol between multiple PEs and CEs. The engineer must avoid advertising the same routes back to their sources. Which action should be performed on the routers to accomplish this task?

Options:

A.

Configure a different route distinguisher for each prefix.

B.

Define the site of origin on each interface.

C.

Define VRFs on each device to separate the traffic.

D.

Enable bidirectional forwarding detection on each device.

Buy Now
Questions 49

Which statement about the Cisco MPLS TE forwarding adjacency feature is true?

Options:

A.

It enables the headend and tailend routers to establish a bidirectional tunnel

B.

It enables the tailend router to advertise routes to the headend router over the tunnel

C.

It enables the MPLS core to use EIGRP as the routing protocol

D.

It enables the Cisco MPLS TE tunnel to be advertised into the running IGP.

Buy Now
Questions 50

Which feature will an operator use while implementing MPLS TE on customer ' s network, to prevent an LSP from using any overseas inks?

Options:

A.

bandwidth

B.

affinity

C.

explicit path

D.

SLRG

Buy Now
Questions 51

Refer to the exhibit:

350-501 Question 51

Router R1 and its peer R2 reside on the same subnet in the network, If does it make connections to R27

Options:

A.

R1 establishes UDP connections that are authenticated with an MD5 password

B.

R1 establishes TCP connections that are authenticated with a clear-text password

C.

R1 establishes UDP connections that are authenticated with a clear-text password

D.

R1 establishes TCP connections that are authenticated with an MD5 password

Buy Now
Questions 52

How can a network administrator secure rest APIs?

Options:

A.

They can allow read and write privileges to all users

B.

They can ensure that user sessions are authenticated using TACACS+ only

C.

They can have a general administrator login for multiple users to access that has command entries logged

D.

They can authenticate user sessions and provide the appropriate privilege level

Buy Now
Questions 53

Drag and drop the methods of Cisco MPLS TE tunnel traffic assignment from the left onto their characteristics on the right.

350-501 Question 53

Options:

Buy Now
Questions 54

Refer to the exhibit:

350-501 Question 54

Which statement about the neighbor statements for 192.168.1.1 is true?

Options:

A.

The router must have TDP configured for the send-label command to operate

B.

The neighbor router receives at least four labels from this router

C.

The router sends BGP labels for its prefixes to this peer

D.

The router sends only a label for the prefix for LoopbackO.

Buy Now
Questions 55

Refer to the exhibit:

350-501 Question 55

This configuration is being applied on an IOS XR router.

Which statement about this configuration is true?

Options:

A.

It is used to set up configuration to poll network data

B.

It is used to enable gRPC

C.

It is used to create a streaming subscription with a 60-second interval

D.

It is used to create a streaming subscription with a 600-second interval

Buy Now
Questions 56

350-501 Question 56

Refer to the exhibit. A network operator working for a private telecommunication company with an employee id: 7138: 13:414 just added new users to the network, which resides in VLANs connected to routers R1 and R4. The engineer now must configure the network so that routers R1 and R4 share routes to the VLANs, but routers R2 and R3 are prevented from including the routes in their routing tables. Which configuration must the engineer apply to R4 to begin implementing the request?

Options:

A.

pseudowire -class ciscotest

encapsulation mpls

interface gigabitethernet 1/0/1

connect neighbor 192.168.1.1 101 pw-class cisco

B.

pseudowire -class ciscotest

encapsulation mpls

interface gigabitethernet 1/0/1

xconnect 192.168.1.1 101 pw-class ciscotest

C.

pseudowire-class ciscotest

encapsulation mpls

service-policy output ciscotest

D.

interface serial 2/0/0

frame-relay encapsulation

ip address 192.168.1.4 255.255.255.0

service-policy output ciscotest

Buy Now
Questions 57

350-501 Question 57

Refer to the exhibit. An engineer started to configure a router for OSPF. Which configuration must the engineer perform on the router without changing any interface configuration so that the router establishes an OSPF neighbor relationship with its peer?

Options:

A.

router(config)# router ospf 11router(config-if)# no passive-interface ethernet 1/1

B.

router(config)# interface ethernet 1/1router(config-if)# no shutdown

C.

router(config)# interface ethernet 1/1router(config-if)# ip ospf hello-interval

D.

router(config)# interface ethernet 1/1router(config-if)# ip ospf priority 0

Buy Now
Questions 58

Which Cisco software OS uses monolithic architecture?

Options:

A.

NX-OS

B.

IOS XE

C.

IOS XR

D.

IOS

Buy Now
Questions 59

What occurs when a high bandwidth multicast stream is sent over an MVPN using Cisco hardware?

Options:

A.

The traffic uses the default MDT transmit the data Only if it is a (S, G) multicast route entry.

B.

A data MDT is created if is a Multicast route entries

C.

A data and default MDT are created to flood the multicast stream of all PIM-SM neighbors.

D.

A data MDT is created to allow for the best transmit through the core for multicast route entries.

Buy Now
Questions 60

350-501 Question 60

Refer to the exhibit. A large enterprise is migrating its network to use MPLS VPNs between different business divisions. Within the core, routes are shared between the routers using OSPF, and each connected link maintains an MPLS neighbor relationship.

Which action must the migration team take so that LDP neighbor relationships are maintained if a directly-connected link goes down?

Options:

A.

Implement targeted LDP sessions between directly connected routers and between routers that are one hop away.

B.

Implement LDP session protection between each directly connected LDP neighbor.

C.

Implement LDP sync between routers that are directly connected to each business division.

D.

Implement targeted LDP sessions between routers that are directly connected to each business division.

Buy Now
Questions 61

Refer to the exhibit.

350-501 Question 61

A network engineer with an employee id: 3812:12:993 has started to configure router R1 for IS-IS as shown. Which additional configuration must be applied to configure the IS-IS instance to advertise only network prefixes associated to passive interfaces?

350-501 Question 61

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 62

350-501 Question 62

Refer to the exhibit. A junior engineer must update a group of scripts to use on a newly deployed subnet. However, one of the scripts is not documented or commented. What are the two effects of this script? (Choose two.)

Options:

A.

The script configures a loopback interface.

B.

The script stores output with leading or trailing spaces.

C.

The script calls a Telnet process to connect to a network device.

D.

The script stores output in the cli.txt file.

Buy Now
Questions 63

Refer to the exhibit.

350-501 Question 63

An engineer is configuring two routers to support MPLS LDP sessions between them. The R1 configuration is complete, and work has started on R2 as shown. Which additional configuration must the engineer apply to R2 to complete the task?

350-501 Question 63

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 64

Refer to the exhibit.

350-501 Question 64

Refer to the exhibit. An ISP provides shared VoIP Extranet services to a customer in VRF-100 with these settings:

The VoIP services are hosted in the 198.19.100.0/24 space.

The customer has been assigned the 198.18.1.0/29 IP address block.

VRF-100 is assigned import and export route target 65010:100.

Which configuration must the engineer apply to PE-1 to provision VRF-100 and provide access to the shared services?

Options:

A.

vrf definition VRF-100

rd 172.17.255.1:100

!

address-family ipv4

export map VRF-100-EXPORT

import map VRF-100-IMPORT

exit-address-family

!

route-map VRF-100-EXPORT permit 10

match ip address prefix-list VRF-100-ALLOWED-EXPORT

set extcommunity rt 65010:100 65010:2999

route-map VRF-100-EXPORT permit 20

set extcommunity rt 65010:100

!

route-map VRF-100-I

B.

vrf definition VRF-100

rd 172.17.255.1:100

!

address-family ipv4

export map VRF-100-EXPORT

route-target import 65010:100

route-target import 65010:2999

exit-address-family

!

route-map VRF-100-EXPORT permit 10

match ip address prefix-list VRF-100-ALLOWED-EXPORT

set extcommunity rt 65010:100 65010:1999

route-map VRF-100-EXPORT permit 20

set extcommunity rt 65

C.

vrf definition VRF-100

rd 172.17.255.1:100

!

address-family ipv4

export map VRF-100-EXPORT

route-target import 65010:100

route-target import 65010:1999

exit address-family

!

route-map VRF-100-EXPORT permit 10

match ip address prefix-list VRF-100-ALLOWED-EXPORT

set extcommunity rt 65010:100 65010:2999

route-map VRF-100-EXPORT permit 20

set extcommunity r 650

D.

vrf definition VRF-100

rd 172.17.255.1:100

!

address-family ipv4

route-target export 65010:100

route-target export 65010:1999

route-target import 65010:100

route-target import 65010:2999

exit-address-family

Buy Now
Questions 65

350-501 Question 65

Refer to the exhibit. ISP_A is a Tier-1 ISP that provides private Layer 2 and Layer 3 VPN services across the globe using an MPLS-enabled backbone network. Routers R1, R2, R13, and R14 are PE devices. ASRs R3 and R4 and ASBRs R11 and R12 are acting as route reflectors with preconfigured next-hop-self for all BGP neighbors. After the network experienced IGP RIB overflow with multiple routes, a network engineer is working on a more scalable network design to minimize the impact on local RIBs. The solution should be based on RFC 3107 and maintain existing QoS capabilities.

Which task must the engineer perform to achieve the goal?

Options:

A.

Implement Seamless Segment Routing on the ABR routers.

B.

Implement MPLS Traffic Engineering on PE routes only.

C.

Implement Hierarchical MPLS VPLS across all LDP-enabled routers.

D.

Implement Unified MPLS on all MPLS-enabled routers.

Buy Now
Questions 66

350-501 Question 66

Refer to the exhibit. A global company plans to implement BGP at its newest location to provide connectivity to other offices. The global infrastructure of the company is a multivendor environment. An engineer must review the BGP core configurations at headquarters to determine if they can be repurposed at the new location. The engineer copied this JSON script for review. What is the effect of the script?

Options:

A.

It configures BGP with neighbor 192.168.1.2 residing in AS 65514.

B.

It sets the BGP router-ID to 192.168.1.2 and sets the AS of the router to 65514.

C.

It configures BGP on the device and inserts 192.168.1.0/24 into the BGP table using the origin AS 65514.

D.

It configures a VRF named cisconode1 and a BGP instance using the VPNv4 address family.

Buy Now
Questions 67

Drag and drop the message types from the left onto the target field of the message originator on the right.

350-501 Question 67

Options:

Buy Now
Questions 68

A service provider is in the process of implementing Unified MPLS on an enterprise network with many nodes. After the migration, several new customers will be added to the environment. RFC 3107 is used to build BGP LSPs across the domains. Which action must the networking team take to reduce the full-mesh requirement for IBGP?

Options:

A.

Implement route reflectors on all ABRs.

B.

Implement a confederation with the network segmented according to business units.

C.

Implement route reflectors on all P routers.

D.

Implement a confederation with each ABR serving as a gateway between secondary AS numbers.

Buy Now
Questions 69

Drag and drop the functions from the left onto the correct Path Computation Element Protocol roles on the right

350-501 Question 69

Options:

Buy Now
Questions 70

A company needs to improve the use of the network resources that is used to deploy internet access service to customers on separate backbone and internet access network. Which two major design models should be used to configure MPLS L3VPNs and internet service in the same MPLS backbone? (Choose two.)

Options:

A.

Carriage of full internet routes in a VPN, in the case of internet access VPNS

B.

Internet routing through global routing on a PE router.

C.

Internet access routing as another VPN in the ISP network.

D.

Internet access through leaking of internet routed from the global table into the L3VPN VRF

E.

Internet access for global routing via a separate interface in a VRF

Buy Now
Questions 71

Drag and drop the characteristics from the left onto the automation tool on the right.

350-501 Question 71

Options:

Buy Now
Questions 72

Refer to the exhibit.

350-501 Question 72

The network engineer who manages ASN 65010 is provisioning a customer VRF named CUSTOMER-ABC on PE-2. The PE-CE routing protocol is OSPF Internet reachability is available via the OSPF 0 0 0.0/0 route advertised by CE-1 to PE-1 In the customer VRF Which configuration must the network engineer Implement on PE-2 so that CE-2 has connectivity to the Internet?

A)

350-501 Question 72

B)

350-501 Question 72

C)

350-501 Question 72

D)

350-501 Question 72

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 73

A remote operation center is deploying a set of l-BGP and E-BGP connections for multiple IOS-XR platforms using the same template. The l-BGP sessions exchange prefixes with no apparent issues, but the E-BGP sessions do not exchange routes. What causes this issue?

Options:

A.

A PASS ALL policy has no! been implemented for the l-BGP neighbors.

B.

The next-hop-self command is not implemented on both E-BGP neighbors.

C.

The E-BGP neighbors are not allowed to exchange information doe to the customer platforms default policy.

D.

The l-BGP neighbors are mistyped and HELLO packets cannot be exchanged successfully between routers.

Buy Now
Questions 74

A mid-size service provider uses L2VPN as its standard for connectivity between offices. A small company wants the service provider to connect the company ' s two sites across the service provider core. To meet service requirements, the service provider must extend the Layer 2 domain between the company ' s two locations.

Which configuration must the engineer apply to implement an attachment circuit between the two sites using a VLAN tag of 12?

Options:

A.

interface TenGigE0/0/0/1.0 12transport

  encapsulation dot1q 12

B.

interface TenGigE0/0/0/1.0 12transport

  encapsulation dot1q 12

  rewrite ingress tag push dot1q 21 symmetric

C.

interface TenGigE0/0/0/1.0 12transport

  encapsulation dot1q 12

  rewrite ingress tag pop 13

D.

interface TenGigE0/0/0/1.0 12transport

 encapsulation dot1q 12

 rewrite ingress tag translate 1-to-1 dot1q 2

Buy Now
Questions 75

350-501 Question 75

Refer to the exhibit. A network engineer is configuring Ethernet Layer 2 service to connect CE2 and CE3 for video and data application sharing with these requirements:

    A point-to-point cross-connect service must be established between 10.10.10.10 and 20.20.20.20.

    PE1 and PE2 must learn neighbors dynamically in PW 10.

Which configuration must be implemented on PE1 to meet the requirements?

Options:

A.

xconnect group XCON1

 p2p XCON1_PE1PE2

 interface GigE 0/0

 pw-class Path1

 backup neighbor 20.20.20.20 pw-id 10

B.

12vpn

 xconnect group XCON1

 interface GigE 0/0

 interface GigE 0/1

C.

12vpn

 xconnect group XCON1

 p2p XCON1_PE1PE2

 interface GigE 0/0

 neighbor 20.20.20.20 pw-id 10

 mpls static label local 699 remote 890

D.

12vpn

 p2p XCON1_PE1PE2

 interface GigE 0/1

 neighbor 20.20.20.20 pw-id 10

Buy Now
Questions 76

What is the primary purpose of containers in a service-provider virtualization environment?

Options:

A.

to simplify the integration of various hardware components

B.

to enable secure communication between individual network devices

C.

to provide an isolated environment for applications and services

D.

to improve the redundancy of network components

Buy Now
Questions 77

350-501 Question 77

Guidelines

-

This is a lab item in which tasks will be performed on virtual devices.

• Refer to the Tasks tab to view the tasks for this lab item.

• Refer to the Topology tab to access the device console(s) and perform the tasks.

• Console access is available for all required devices by clicking the device icon or using the tab(s) above the console window.

• All necessary preconfigurations have been applied.

• Do not change the enable password or hostname for any device.

• Save your configurations to NVRAM before moving to the next item.

• Click Next at the bottom of the screen to submit this lab and move to the next question.

• When Next is clicked, the lab closes and cannot be reopened.

Topology

350-501 Question 77

Tasks

-

Configure and verify the OSPF neighbor adjacency between R1 and R2 in OSPF area 0 according to the topology to achieve these goals:

1. Establish R1 and R2 OSPF adjacency. All interfaces must be advertised in OSPF by using the OSPF interface command method. Use Loopback0 as the OSPF ID.

2. There must be no DR/BDR elections in OSPF Area 0 when establishing the neighbor relationship between R1 and R2. OSPF must not generate the host entries /32 for the adjacent interfaces.

3. Enable OSPF MD5 Authentication between both routers at the interface level with password C1sc0!.

Options:

Buy Now
Questions 78

Refer to the exhibit. An organization s network recently experienced several significant outages due to device failures. The network administrator just moved the network devices to a new central data center, and packets are switched using labels. The administrator Is now implementing NSF on the network to reduce potential risk factors in the event of another outage. Which task must the administrator perform on each router as part of the process?

350-501 Question 78

Options:

A.

Remove route filtering to speed repopulation of the link-state database

B.

Copy the router s existing state information and share the file with its peers to enable BGP soft resets

C.

Implement MPLS to forward packets while the RIB updates after a faliover.

D.

Implement Graceful Restart to mitigate the delay in MPLS LDP synchronization when the IGP starts up.

Buy Now
Questions 79

Which task must be performed first to Implement BFD in an IS-IS environment?

Options:

A.

Disable Cisco Express Forward.ng on all interfaces running routing protocols other than IS-IS

B.

Configure BFD under the IS-IS process

C.

Configure all ISIS routers as Level 2 devices

D.

Configure BFD in an interface configuration mode

Buy Now
Questions 80

An engineer is setting up overlapping VPNs to allow VRF ABC and XYZ to communicate with VRF CENTRAL but wants to make sure that VRF ABC and XYZ cannot communicate. Which configuration accomplishes these objectives?

350-501 Question 80

350-501 Question 80

350-501 Question 80

350-501 Question 80

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 81

Simulation 8

350-501 Question 81350-501 Question 81

350-501 Question 81

Options:

Buy Now
Questions 82

A network engineer is testing an automation platform that interacts with Cisco networking devices via NETCONF over SSH. In accordance with internal security requirements:

NETCONF sessions are permitted only from trusted sources in the 172.16.20.0/24 subnet.

CLI SSH access is permitted from any source.

Which configuration must the engineer apply on R1?

Options:

A.

configure terminal

hostname R1

ip domain-name mydomain.com

crypto key generate rsa

ip ssh version 1

access-list 1 permit 172.16.20.0 0.0.0.255

netconf ssh acl 1

line vty 0 4

transport input ssh

end

B.

configure terminal

hostname R1

ip domain-name mydomain.com

crypto key generate rsa

ip ssh version 2

access-list 1 permit 172.16.20.0 0.0.0.255

access-list 1 permit any

netconf ssh

line vty 0 4

access-class 1 in

transport input ssh

end

C.

configure terminal

hostname R1

ip domain-name mydomain.com

crypto key generate rsa

ip ssh version 1

access-list 1 permit 172.16.20.0 0.0.0.255

access-list 2 permit any

netconf ssh

line vty 0 4

access-class 2 in

transport input ssh

end

D.

configure terminal

hostname R1

ip domain-name mydomain.com

crypto key generate rsa

ip ssh version 2

access-list 1 permit 172.16.20.0 0.0.0.255

netconf ssh acl 1

line vty 0 4

transport input ssh

end

Buy Now
Questions 83

Refer to the exhibit:

350-501 Question 83

Which statement describes the effect of this configuration?

Options:

A.

It applies a service policy to all interfaces remarking HTTP traffic

B.

It creates an ACL named WEB that filters HTTP traffic.

C.

It matches HTTP traffic for use in a policy map

D.

It modifies the default policy map to allow all HTTP traffic through the router

Buy Now
Questions 84

Refer to the exhibit.

350-501 Question 84

A network engineer is configuring MPLS LDP synchronization on router R1. Which additional configuration must an engineer apply to R1 so that it will synchronize to OSPF process 1?

350-501 Question 84

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 85

Which two tasks must an engineer perform when implementing LDP NSF on the network? (Choose two.)

Options:

A.

Disable Cisco Express Forwarding.

B.

Enable NSF for EIGRP.

C.

Enable NSF for the link-state routing protocol that is in use on the network.

D.

Implement direct connections for LDP peers.

E.

Enable NSF for BGP.

Buy Now
Questions 86

Refer to the exhibit.

350-501 Question 86

A network engineer is deploying SNMP configuration on client ' s routers. Encrypted authentication must be included on router 1 to provide security and protect message confidentially. Which action should the engineer perform on the routers to accomplish this task?

Options:

A.

snmp-server host 192.168.0.254 informs version 3 auth testuser config.

B.

snmp-server user testuser group 1 remote 192.168.0.254 v3 auth md5 testpassword

C.

snmp-server group group 1 v3 auth.

D.

snmp-server community public

Buy Now
Questions 87

350-501 Question 87

Refer to the exhibit. A client wants to filter routes to a BGP peer to limit access to restricted areas within the network. The engineer configures the route map ciscotest to filter routes from the BGP neighbor. The engineer also sets a tag that will be used for QoS in the future. Which task must be performed to complete the Implementation?

Options:

A.

Attach the new route map to the BGP neighbor statement in the inbound direction.

B.

Create a policy map named ciscotest and apply It to inbound traffic on the link that is directly connected to the BGP neighbor.

C.

Create a route map, configure BGP with an IPv4 address family, and activate the neighbor.

D.

Add a route map statement with sequence 40 that links a BGP community to the routing protocol

Buy Now
Questions 88

What causes multicast traffic to permanently stay on the shared tree and not switch to the source tree?

Options:

A.

The SPT threshold is set to infinity.

B.

The RP IP address is configured incorrectly.

C.

The RP announcements are being filtered.

D.

SSM range is being used.

Buy Now
Questions 89

Refer to the exhibit:

350-501 Question 89

Which statement about this configuration is true " ?

Options:

A.

It requires an explicit Cisco MPLS TE path to be configured for the tunnel to run

B.

It requires OSPF to also be running to have optimized Cisco MPLS TE tunnels

C.

It requires a dynamic Cisco MPLS TE path to be configured for the tunnel to run

D.

It is the configuration for the head-end router of a Cisco MPLS TE tunnel with segment routing

Buy Now
Questions 90

Refer to the exhibit: 350-501 Question 90

BGPsec is implemented on R1. R2. R3. and R4 BGP peering is established between neighboring autonomous systems Which statement about implementation is true?

Options:

A.

BGP updates from the eBGP peers are appended with an additional AS path value that is statically set by the domain administrator

B.

BGP updates from the iBGP peers are appended with a community of local-as

C.

BGP updates from the all BGP peers are appended with a community of no export

D.

BGP updates from the eBGP peers are appended with a BGPsec attribute sequence that includes a public key hash and digital signature

Buy Now
Questions 91

Refer to the exhibit.

350-501 Question 91

A network operator working for a telecommunication company with an employee ID: 4350:47:853 must implement an IGP solution based on these requirements:

• Subnet 10.50.10.0 traffic must exit through the R1 router to connect with the Syslog server.

• Subnet 10.50.20.0 traffic must exit through the R2 router to connect with the NTP server.

• In case of link failure between R2 and R4, traffic must be routed via R1 and R3.

Which two configurations must be implemented on R5 to meet these requirements? (Choose two.)

Options:

A.

Apply a route policy to redistribute 10.50.0.0 prefixes in OSPF to ISIS and ISIS to OSPF.

B.

Apply a route policy to redistribute 10.50.20.0 from ISIS-L2 to OSPF Area 0 at a higher cost.

C.

Enable a route policy to advertise 10.50.20.0 in ISIS-L2 at a higher cost.

D.

Apply a route policy to redistribute 10.50.10.0 from OSPF Area 0 to ISIS-L2 at a lower cost.

E.

Enable a route policy to advertise 10.50.10.0 In OSPF Area 0 at a low cost.

Buy Now
Questions 92

A network engineer must configure a router for Flexible NetFlow IPFIX export. The IP address of the destination server is 172.17.12.1. The source address must be set to the Loopback0 IPv4 address and exported packets must be set to DSCP CS3. The TTL must be 64 and the transport protocol must be set to UDP with destination port 4739. Which configuration must the engineer apply to the router?

Options:

A.

configure terminal

flow exporter EXPORTER-1

destination 172.17.12.1

source Loopback0

dscp 3

ttl 64

export-protocol netflow-v9

transport udp 4739

end

B.

configure terminal

flow exporter EXPORTER-1

destination 172.17.12.1

source Loopback0

dscp 24

ttl 64

export-protocol ipfix

end

C.

configure terminal

flow exporter EXPORTER-1

destination 172.17.12.1

source Loopback0

dscp 24

ttl 64

export-protocol netflow-v9

transport udp 4739

end

D.

configure terminal

flow exporter EXPORTER-1

destination 172.17.12.1

source Loopback0

dscp 3

ttl 64

export-protocol ipfix

end

Buy Now
Questions 93

Refer to the exhibit.

350-501 Question 93

An engineer configured multicast routing on client ' s network. What is the effect of this multicast implementation?

Options:

A.

R2 floods information about R1 throughout the multicast domain.

B.

R2 is unable to share information because the ip pirn autorp listener command is missing.

C.

R1 floods information about R2 throughout the multicast domain.

D.

R2 is elected as the RP for this domain.

Buy Now
Questions 94

A company uses PIM-SM multicast with IGMPv2 to stream training videos from a server in one network to hosts in a different network. As the company has grown, the networking team decided to implement SSM to improve efficiency for multicast within Layer 2. Which action must the team take to begin the process?

Options:

A.

Configure an IGMP querier and implement Cisco Express Forwarding across the network.

B.

Implement PIM-DM to enable the routers on the LAN to identify SSM-capable multicast hosts.

C.

Implement IGMPv3 and deprecate IGMPv2.

D.

Implement IGMPv3 simultaneously with IGMPv2 on the individual links that must support SSM and PIM-DM.

Buy Now
Questions 95

Drag and drop the functionalities from the left onto the target fields on the right.

350-501 Question 95

Options:

Buy Now
Questions 96

Refer to the exhibit:

350-501 Question 96

P3 and PE4 are at the edge of the service provider core and serve as ABR routers Aggregation areas are on either side of the core.

Which statement about the architecture is true?

Options:

A.

If each area is running its own IGP. the ABR routers must redistribute the IGP routing table into BGP

B.

To support seamless MPLS. TDP must be used as the label protocol

C.

If each area is running its own IGP. BGP must provide an end-to-end MPLS LSP

D.

To support seamless MPLS, the BGP route reflector feature must be disabled

Buy Now
Questions 97

Which component is similar to an EVPN instance?

Options:

A.

MPLS label

B.

IGP router ID

C.

VRF

D.

router distinguisher

Buy Now
Questions 98

Which type of attack is a Protocol attack?

Options:

A.

HTTP flood

B.

TFTP flood

C.

SYN flood

D.

Slowlorls

Buy Now
Questions 99

How does Cisco MPLS TE use OSPF extensions to allow for optimized transit between a headend router and a destination router?

Options:

A.

Router LSAs share router link advertisements to each router within the MPLS environment so that tunnels can be built bidirectionally.

B.

ASBR Summary LSAs share OSPF domain information so that the two routers know how to reach each other during tunnel setup.

C.

Network LSAs share RSVP information to build the tunnel between the two routers.

D.

Opaque LSAs calculate and establish unidirectional tunnels that are set according to the network constraint.

Buy Now
Questions 100

Refer To the exhibit.

350-501 Question 100

Which BGP attribute should be manipulated to have CE1 use PE1 as the primary path to the Internet?

Options:

A.

The weight attribute should be manipulated on PE1 on outbound routes advertised to CE1.

B.

The MED should be manipulated on CE1 on inbound routes from PE1.

C.

The local preference attribute should be manipulated on PE2 on inbound routes advertised to CE1.

D.

The origin of all routes should be modified on each router on inbound and outbound routes advertised to CE1.

Buy Now
Questions 101

Simulation2

TOPOLOGY

350-501 Question 101

350-501 Question 101

350-501 Question 101

Options:

Buy Now
Questions 102

Which programmable API allows the service provider to plan and optimize the automation of network operations and achieve closed-loop operations?

Options:

A.

Network Services Orchestrator

B.

WAN Automation Engine

C.

Evolved Programmable Network Manager

D.

Crosswork Network Automation

Buy Now
Questions 103

A network administrator is planning a new network with a segment-routing architecture using a distributed control plane. How is routing information distributed on such a network?

Options:

A.

Each segment is signaled by a compatible routing protocol, and each segment makes its own steering decisions based on SR policy.

B.

Each segment is signaled by MPLS, and each segment makes steering decisions based on the routing policy pushed by BGP.

C.

Each segment is signaled by an SR controller, but each segment makes its own steering decisions based on SR policy.

D.

Each segment is signaled by an SR controller that makes the steering decisions for each node.

Buy Now
Questions 104

350-501 Question 104

Refer to the exhibit. An operations team recently located an archive of scripts for deploying routine network changes with an error-free approach. A junior network engineer, who is working to modify the scripts to support RESTCONF, has been asked to document the purpose of each updated script. Which two actions does the given script take? (Choose two.)

Options:

A.

Send a patch request to the API endpoint.

B.

Print a fail message when the response code is 204.

C.

Pass an XML data-format request in the API header.

D.

Print a success message when the device receives a full-content response code.

E.

Ignore SSL certificate verification.

Buy Now
Questions 105

350-501 Question 105

Refer to the exhibit. The network is running OSPF, and access to the internet is provided through router RB. Router RA connects to several servers that provide services to users connected to RC and RF. User traffic is growing, and the engineering team wants to mitigate the future potential for congestion when the servers are experiencing heavy use.

Which action must the team take to maintain better network performance?

Options:

A.

Implement MPLS and install a Cisco MPLS TE tunnel to route high-priority traffic via a preferred path.

B.

Implement ACLs to manage traffic flowing over individual links.

C.

Implement class maps to categorize traffic and apply them to policies to manage traffic flow.

D.

Implement OSPF point-to-point links to eliminate the need for DR election and the associated traffic.

Buy Now
Questions 106

Why do Cisco MPLS TE tunnels require a link-state routing protocol?

Options:

A.

Link-state routing protocols use SPF calculations that the tunnel endpoints leverage to implement the tunnel

B.

The link-state database provides a data repository from which the tunnel endpoints can dynamically select a source ID

C.

The tunnel endpoints can use the link-state database to evaluate the entire topology and determine the best path

D.

The link state database provides segmentation by area, which improves the path-selection process

Buy Now
Questions 107

Which Cisco Software OS uses microkernel architecture?

Options:

A.

IOS 12.2

B.

IOS XR

C.

IOS

D.

IOS 15.1

Buy Now
Questions 108

A network engineer is configuring a newly installed PE router at the regional gateway location. The new PE router must use MPLS core routing protocols with the existing P router, and LDP sessions between the two routers must be protected to provide faster MPLS convergence. Which configuration must the engineer perform on the network so that LDP sessions are established?

Options:

A.

Enable communication over TCP port 646 for T-LDP hello messages.

B.

Enable RSVP-TE FRR on the LDP interface to protect the LDP session between routers.

C.

Enable LDP session protection on either one of the routers, which allows them to autonegotiate.

D.

Set the LDP session protection timer on each router to the same value.

Buy Now
Questions 109

350-501 Question 109

Refer to the exhibit. Router R1 is configured with class map CE with match Ip precedence critical to align with customer contract SLAs. The customer is sending all traffic from CE1 toward the FTP server with IP precedence 5 A network engineer must allow 10% of interface capacity on router R3 Which two actions must the engineer take to accomplish the task ? (Choose two )

Options:

A.

lmptem4Dt4M$§ map on R1 to match all packets with QoS IP precedence value 100.

B.

Implement a class map on R3 to match all packets with QoS IP precedence value 101.

C.

Apply a policy map to R1 to reserve the remaining 10% of interface bandwidth.

D.

Apply a policy map to R3 to reserve 10% of interface bandwidth.

E.

Implement a class map on R3 to match all packets with QoS IP precedence.

Buy Now
Questions 110

While implementing TTL security, an engineer issues the PE(config-router-af)#neighbor 2.2.2.2 ttl-security hops 2 command. After issuing this command, which BGP packets does the PE accept?

Options:

A.

from 2.2.2.2, with a TTL of less than 2

B.

to 2.2.2.2, with a TTL of less than 253

C.

from 2.2.2.2, with a TTL of 253 or more

D.

to 2.2.2.2, with a TTL of 2 or more

Buy Now
Questions 111

350-501 Question 111

Refer to the exhibit. An engineering team must update the network configuration so that data traffic from router A to router D continues in case of a network outage between routers B and C. During a recent outage on the B-C link, the IGP traffic path was switched to the alternate path via routers E and F. but label forwarding did not occur on the new path. Which action ensures that traffic on the end-to-end path continues?

Options:

A.

Configure the same hello timer values for IGP and LDP

B.

Bind the BFD protocol with IGP on all routers

C.

Enable LDP Session Protection on routers A and D.

D.

Enable MPLS LDP IGP Synchronization on all routers

Buy Now
Questions 112

Refer to the exhibit:

350-501 Question 112

What does this value mean when it is received in XML?

Options:

A.

It shows the ending of the script

B.

It indicates a break in a sequence

C.

It indicates a value assigned by a network administrator to tag a route

D.

It means a data field is blank

Buy Now
Questions 113

350-501 Question 113

350-501 Question 113

Refer to the exhibit. EIGRP a running across the core lo exchange Internal routes, and each router maintains 6GP adjacency with the other routers on the network. An operator has configured static routes on the edge routers R1 and R2 for IP address 10.0.1.1. which is used as a black hole route as shown. Which configuration should the operator Implement to me management rouler to create a route map that will redistribute lagged static routes into BGP and create a static route to blackhole traffic with tag 777 that Is destined to server at 192.168.10.100?

350-501 Question 113

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 114

Drag and drop the BGP Best Path Algorithm rules from the left into the corresponding order of importance on the right.

350-501 Question 114

Options:

Buy Now
Questions 115

Refer to the exhibit.

350-501 Question 115

An engineer is updating this network to meet these conditions:

• Area 10 will receive inter-area routes and support mutual redistribution of external routes with the extranet.

• The ::/0 route is prohibited in Area 10.

• Area 11 will receive only the ::/0 route from the ABR.

• External route redistribution is not supported in Area 11.

• The ABR in Area 11 will advertise no interarea routes.

Which two configurations must be performed to meet the requirements? (Choose two.)

Options:

A.

Configure area 11 as nssa no-summary on R7 and as nssa on XR31.

B.

Configure area 10 as stub on R9 and XR32.

C.

Configure area 11 as stub no-summary on R7 and as stub on XR31.

D.

Configure area 11 as nssa default-information-originate on R7 and as nssa on XR31.

E.

Configure area 10 as nssa on R9 and XR32.

Buy Now
Questions 116

Which two tasks must you perform when you implement LDP NSF on your network? (Choose two.)

Options:

A.

Enable NSF for EIGRP

B.

Enable NSF for the link-state routing protocol that is in use on the network.

C.

Disable Cisco Express Forwarding

D.

Implement direct connections for LDP peers

E.

Enable NSF for BGP

Buy Now
Questions 117

Refer to the exhibit.

350-501 Question 117

An engineer is configuring router R1 for OSPFv3 as shown. Which additional configuration must be performed so that the three active interfaces on the router will advertise routes and participate in OSPF IPv6 processes?

A)

350-501 Question 117

B)

350-501 Question 117

C)

350-501 Question 117

Options:

A.

Option A

B.

Option B

C.

Option C

Buy Now
Questions 118

Simulation 7

350-501 Question 118

350-501 Question 118

Options:

Buy Now
Questions 119

What is the purpose of microsegments in the SRv6 architecture?

Options:

A.

They ensure that routers in the path sufficiently examine the indexed mapping tables.

B.

They support a scalable control plane.

C.

They reduce fragmentation as packets traverse the network.

D.

They allow for configuration changes in the SRv6 data plane without requiring the device to reboot.

Buy Now
Questions 120

A network engineer is implementing NetFlow to observe traffic patterns on the network. The engineer is planning to review the patterns to help plan future strategies for monitoring and preventing congestion as the network grows. If the captures must include BGP next-hop flows, which configuration must the engineer apply to the router?

Options:

A.

ip cef

ip flow-export version 5 bgp-nexthop

ip flow-export destination 192.168.1.1 9995

interface gigabitethernet 1/0/1

ip flow egress

B.

ip cef

ip flow-export version 9 bgp-nexthop

ip flow-export destination 192.168.1.1 9996

interface gigabitethernet 1/0/1

ip flow ingress

C.

ip cef

ip flow-export version 5

ip flow-export destination 192.168.1.1 9995

interface gigabitethernet 1/0/1

ip flow ingress

cdp enable

D.

no ip cef

ip flow-export version 9

ip flow-export destination 192.168.1.1 9996

interface gigabitethernet 1/0/1

ip flow ingress

ip flow egress

Buy Now
Questions 121

350-501 Question 121

Refer to the exhibit. Routers P4 and P5 receive the 0.0.0.0/0 route from the ISP via eBGP peering. P4 is the primary Internet gateway router, and P5 is its backup. P5 is already advertising a default route into the OSPF domain. Which configuration must be applied to P4 so that it advertises a default route into OSPF and becomes the primary Internet gateway for the network?

Options:

A.

configure terminal

router ospfv3 100

address-family ipv4 unicast

default-information originate metric 40 metric-type 2

end

B.

configure terminal

router ospfv3 100

address-family ipv4 unicast

default-information originate metric 40 metric-type 1

end

C.

configure terminal

router ospfv3 100

address-family ipv4 unicast

redistribute bgp 65500 metric 40 metric-type 1

end

D.

configure terminal

router ospfv3 100

address-family ipv4 unicast

default-information originate always metric 40 metric-type 1

end

Buy Now
Questions 122

Refer to the exhibit.

350-501 Question 122

350-501 Question 122

A NOC engineer is configuring label-based forwarding from CSR to the EPC gateway. Cell-site operation and maintenance for IPv4 traffic between 10.20.10.1 and 192.168.10.10 is already up. CR1 and CR2 are configured as route reflectors for AG1 and AG2. Which action completes the configuration?

Options:

A.

Remove address-family labeled-unicast from the BGP session-group infra on AG1 for neighbor-group core.

B.

Apply the BGP_Egress_Filter route policy to the BGP neighbor-group packet core on AG1.

C.

Configure AG1 to allocate a label to the BGP routes that are received in the BGP session group transport.

D.

Configure AG1 to allow the 300:100 and 200:100 communities in the BGP_Egress_Filter route policy.

Buy Now
Questions 123

A router is advertising multiple networks to its BGP neighbor in AS 5200 with peer IP address 1.1.1.1. Which configuration must be applied so that the router permits updates only for networks with a prefix mask length less than or equal to 21?

350-501 Question 123

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 124

What Is one of the differences between Ansible and Chef?

Options:

A.

Ansible uses YAML and Chef uses Ruby.

B.

Chef requires the use of Windows in the environment and Ansible requires Linux.

C.

Chef is highly scalable and Ansible is highly secure.

D.

Ansible uses Ruby and Chef uses Python.

Buy Now
Questions 125

350-501 Question 125

router(config)# route-map blackhole-trigger

router(config-route-map)# match tag 777

router(config-route-map)# set ip next-hop 10.0.1.1

router(config-route-map)# set origin igp

router{config-route-map)# set community no-export

Refer to the exhibit. EIGRP is running across the core to exchange internal routes, and each router maintains iBGP adjacency with the other routers on the network. An operator has configured static routes on the edge routers R1 and R2 for IP address 10.0.1.1, which is used as a black hole route as shown. Which configuration should the operator implement to the management router to create a route map that will redistribute tagged static routes into BGP and create a static route to blackhole traffic with tag 777 that is destined to the server at 192.168.10.100?

Options:

A.

router(config)# router bgp 55100

router(config-router)# redistribute static route-map blackhole-trigger

router(config)# ip route 10.0.1.1 255.255.255.255 Null0 tag 777

B.

router(config)# router bgp 55100

router(config-router)# redistribute static route-map blackhole-trigger

router(config)# ip route 192.168.10.100 255.255.255.255 Null0 tag 777

C.

router(config)# router bgp 55100

router(config-router)# redistribute connected

router(config)# ip route 192.168.10.100 255.255.255.255 tag 777

D.

router(config)# router bgp 55100

router(config-router)# redistribute connected route-map blackhole-trigger

router(config)# ip route 192.168.10.100 255.255.255.255 Null0 tag 777

Buy Now
Questions 126

Which statement about Network Services Orchestrator (NSO) is true?

Options:

A.

It is used only in service provider environments

B.

It can be used only with XML coding

C.

It uses YANG modeling language to automate devices

D.

It must use SDN as an overlay for addressing

Buy Now
Questions 127

Refer to the exhibit:

350-501 Question 127

A network administrator wants to enhance the security for SNMP for this configuration.

Which action can the network administrator implement?

Options:

A.

Re-configure to use SNMPv2 with MD5 authentication

B.

Add a community string to the existing entry

C.

Re-configure to use SNMPv3.

D.

Maintain the configuration but switch to an encrypted password for device access through SSH

Buy Now
Questions 128

How does Inter-AS Option-A function when two PE routers in different autonomous systems are directly connected?

Options:

A.

The two routers share all Inter-AS VPNv4 routes and redistribute routes within an IBGP session to provide end-to-end reach.

B.

The two routers establish an MP-EBGP session to share their customers ' respective VPNv4 routes.

C.

The two routers treat one another as CE routers and advertise unlabeled IPv4 routes through an EBGP session.

D.

The two routers share VPNv4 routes over a multihop EBGP session and set up an Inter-AS tunnel using one another ' s label.

Buy Now
Questions 129

What is the role of NSO?

Options:

A.

Provides public cloud services for customers that need Internet access.

B.

Controls the turn-up of a device.

C.

Provides network monitoring services for Layer 3 devices.

D.

Maintains data storage.

Buy Now
Questions 130

350-501 Question 130

Refer to the exhibit. A network engineer is implementing multicast services on CPE-1 and CPE-2. CPE-1 must be configured as the preferred IGMP querier for the LAN segment. PIM-SM must be implemented on the LAN interfaces with an IGMP version that supports (*, G) joins only. Which configurations must the engineer implement on CPE-1 and CPE-2?

Options:

A.

On CPE-1:

interface GigabitEthernet0/1

ip address 10.0.12.129 255.255.255.128

ip pim sparse-mode

ip igmp version 2

On CPE-2:

interface GigabitEthernet0/1

ip address 10.0.12.130 255.255.255.128

ip pim sparse-mode

ip igmp version 2

B.

On CPE-1:

interface GigabitEthernet0/1

ip address 10.0.12.130 255.255.255.128

ip pim sparse-mode

ip igmp version 3

On CPE-2:

interface GigabitEthernet0/1

ip address 10.0.12.129 255.255.255. 128

ip pim sparse-mode

ip igmp version 3

C.

On CPE-1:

interface GigabitEthernet0/1

ip address 10.0.12.130 255.255.255.128

ip pim sparse-mode

ip igmp version 2

On CPE-2:

interface GigabitEthernet0/1

ip address 10.0.12.129 255.255.255.128

ip pim sparse-mode

ip igmp version 2

D.

On CPE-1:

interface GigabitEthernet0/1

ip address 10.0.12.129 255.255.255.128

ip pim sparse-mode

ip igmp version 3

On CPE-2:

interface GigabitEthernet0/1

ip address 10.0.12.130 255.255.255.128

ip pim sparse-mode

ip igmp version 3

Buy Now
Questions 131

Drag and drop the technologies from the left onto the correct definitions on the right.

350-501 Question 131

Options:

Buy Now
Questions 132

Refer to the exhibit.

350-501 Question 132

A network engineer notices that router R2 is failing to install network 172.16.33.1/32 in the routing table. Which configuration must the engineer apply to R2 to fix the problem?

Options:

A.

R2(config)# access-Iist 1 permit 172.16.33.0 255.0.0.0

B.

R2(config)# access-list 1 permit 172,16,33.0 255,255,255,0

C.

R2(config)# access-list 1 permit 172.16.33.0 0.0.0.255

D.

R2(config)# access-list 1 permit 172,16,33.0 255.255,0,0

Buy Now
Questions 133

A network administrator is planning a new network with a segment-routing architecture using a distributed control plane. How is routing information distributed on such a network?

Options:

A.

Each segment is signalled by an SR controller, but each segment makes Its own steering decisions based on SR policy.

B.

Each segment is signalled by MPLS, and each segment makes steering decisions based on the routing policy pushed by BGP.

C.

Each segment is signalled by an SR controller that makes the steering decisions for each node.

D.

Each segment is signalled by a compatible routing protocol and each segment makes its own steering decisions based on SR policy.

Buy Now
Questions 134

Refer to the exhibit:

350-501 Question 134

Which statement describes this configuration?

Options:

A.

Router 1 has its running configuration locked so changes can be made only when the administrator issues a kill session

B.

Router 1 can be remotely managed by the CLI using Telnet

C.

Router 1 has a new data store to collect SNMP information, but configuration must still be done at the CLI only

D.

Router 1 has a temporary data store where a copy of the running configuration can be manipulated and verified before committing the configuration

Buy Now
Questions 135

Refer to the exhibits:

350-501 Question 135

R1 and R2 are directly connected and IS-IS routing has been enabled between R1 and R2 R1 message periodically Based on this output, which statement is true?

Options:

A.

IS-IS neighbor authentication is failing for Level 2 first and then for Level 1 PDUs

B.

1S-1S neighbor authentication is failing for Level 1 and Level 2 PDUs .

C.

IS-IS neighbor authentication is failing for Level 1 PDUs only

D.

IS-IS neighbor authentication is failing for Level 2 PDUs only.

Buy Now
Questions 136

Refer to the exhibit:

350-501 Question 136

What does the REST API command do?

Options:

A.

It retrieves the information requested by Descriptions xml

B.

It removes the information identified by Descriptions xml

C.

It executes the commands specified in Descriptions xml

D.

It displays the information identified by Descriptions xml

Buy Now
Questions 137

In an MPLS network, which protocol can be used to distribute a Segment Prefix?

Options:

A.

OSPF

B.

LDP

C.

RSVP-TE

D.

EIGRP

Buy Now
Questions 138

Refer to the exhibit.

350-501 Question 138

To protect in-band management access to CPE-R7, an engineer wants to allow only SSH management and provisioning traffic from management network 192.168.0.0/16. Which infrastructure ACL change must be applied to router PE-R9 to complete this task?

A)

350-501 Question 138

B)

350-501 Question 138

C)

350-501 Question 138

D)

350-501 Question 138

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 139

350-501 Question 139

350-501 Question 139

Refer to the exhibit. LDP peering between routers R1 and R2 is dropped when the link between R1 and R2 is taken offline. However, LDP peering between R2 and R3 stays up when the link between R2 and R3 is taken offline. Which action allows MPLS traffic forwarding to continue normally if the link between R1 and R2 goes down?

Options:

A.

Enable IGP and LDP Synchronization on R1.

B.

Implement LDP Session Protection on R1.

C.

Enable IGP and LDP Synchronization on R2.

D.

Implement LDP Session Protection on R2.

Buy Now
Questions 140

How can shared services in an MPLS Layer 3 VPN provide Internet access to the customers of a central service provider?

Options:

A.

The CE router can establish a BGP peering to a PE router and use the PE device to reach the Internet

B.

Route distinguishes are used to identify the routes that CEs can use to reach the Internet

C.

The customer VRF uses route targets to import and export routes to and from a shared services VRF

D.

Static routes on CE routers allow route leakage from a PE global routing table

Buy Now
Questions 141

350-501 Question 141

Refer to the exhibit. ISP A provides VPLS services and DDoS protection to Company XYZ to connect their branches across the North America and Europe regions. The uplink from the data center to the ISP is Mbps. The company XYZ security team asked the ISP to redirect ICMP requests which are currently going to the web server to a new local security appliance which configuration must an ISPP engineer apply to router R2 to redirect the ICMP traffic?

A)

350-501 Question 141

B)

350-501 Question 141

C)

350-501 Question 141

D)

350-501 Question 141

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 142

350-501 Question 142

Refer to the exhibit. A host connected to R3 must connect with a server on R1 that provides critical, time-sensitive data. Traffic between the host and server must always be given bandwidth to traverse the links when they are congested, with other traffic being dropped. How must the network engineer implement a QoS strategy with classification to ensure that the traffic is given the appropriate bandwidth?

Options:

A.

Implement FIFO to guarantee that the server traffic is sent first while other traffic is queued.

B.

Implement policing to rate-limit noncritical traffic that exceeds designated thresholds.

C.

Implement traffic shaping to delay noncritical traffic when the link is congested.

D.

Implement strict priority to guarantee bandwidth for the server traffic.

Buy Now
Questions 143

An engineer must implement QoS to prioritize traffic that requires better service throughout the network. The engineer started by configuring a class map to identify the high-priority traffic. Which additional tasks must the engineer perform to implement the new QoS policy?

Options:

A.

Attach the class map to a policy map that sets the minimum bandwidth allocated to the classified traffic and designates the action to be taken on the traffic.

B.

Attach the class map to a policy map that designates the action to be taken on the classified traffic and then attach the policy map to an interface using a service policy.

C.

Attach the class map to a policy map within a VRF to segregate the high-priority traffic and then attach the policy map to an interface in another VRF.

D.

Create a route map to manipulate the routes that are entered into the routing table and then attach the route map to an interface using a service policy.

Buy Now
Questions 144

350-501 Question 144

Refer to the exhibit. Company A is running OSPF within its network, comprised of routers R2, R3, R4, and R5 and consisting of two areas. Company A just acquired Company B, which uses EIGRP on its own R1. R1 has several routes in its routing table. The network engineering team at Company A needs access to the Company B network to manage network devices there, but each company will otherwise operate independently. R2 will serve as the ASBR between the two networks. Which action must the team take to reduce the number of EIGRP routes received on R2 and include only the necessary routes in the routing table?

Options:

A.

Apply an outbound distribute list on R3 and R4 to filter unnecessary intra-area routes from reaching the rest of the OSPF domain.

B.

Apply an inbound distribute list on R2 with a route map that permits only the necessary networks.

C.

Implement an offset list on R1 for the necessary networks.

D.

Attach an access list to the R2 interface connected to R1 that denies all traffic except for the necessary engineering team traffic.

Buy Now
Questions 145

What is a role of NSO?

Options:

A.

It automates the deployment of access points with its built-in wireless LAN controller.

B.

It manages WAN infrastructure using a virtual switch.

C.

It provides full lifecycle management of a device.

D.

It resides on a hypervisor that runs the Windows OS.

Buy Now
Questions 146

350-501 Question 146

Refer to the exhibit. Router R13 is operating in Level 1 / Level 2 mode. A network engineer with an employee ID: 5209:82:636 must change the IS-IS cost of the route IP address 10.212.124.1 to 90. The metric update must be carried over in TLV 128. Which configuration must be implemented to complete the task?

Options:

A.

metric-style isis wide 90 under interface loopback1 on R13

B.

metric cost 90 under interface Gi1/1/1 on R12

C.

isis metric 80 under interface loopback1 on R13

D.

Isis metric 90 under interface Gi1/1/1 on R12

Buy Now
Questions 147

350-501 Question 147

Refer to the exhibit. A growing company wants to ensure high availability and redundancy for its critical web servers, which are located in an offsite data center. The network architect decided to implement BGP so that the network can use redundant paths for outbound traffic toward the destination subnet 10.2.2.0/24. A network engineer already configured basic BGP settings on edge router R1, which is a Cisco ASR-1001X router. The engineer also confirmed loopback reachability to routers R2 and R3, and the AS path length toward the destination is the same via R2 and R3. Which action must the engineer take on R1 to complete the implementation?

Options:

A.

Implement as-path multipath under the BGP neighbor configuration.

B.

Implement maximum-paths ibgp 2 under the BGP neighbor configuration.

C.

Implement maximum-paths 2 under the BGP global configuration.

D.

Implement bestpath as-path multipath-relax under the BGP global configuration.

Buy Now
Questions 148

Refer to the exhibit:

350-501 Question 148

Router 1 was experiencing a DDoS attack that was traced to interface gjgabitethernet0/1.

Which statement about this configuration is true?

Options:

A.

Router 1 drops all traffic that ingresses interface gigabitethernet0/1 that has a FIB entry that exits a different interface

B.

Router 1 accepts source addresses on interface gigabitethemet0/1 that are private addresses

C.

Router 1 accepts all traffic that ingresses and egresses interface gigabitethernet0/1

D.

Router 1 accepts source addresses that have a match in the FIB that indicates it is reachable through a real interface

Buy Now
Questions 149

350-501 Question 149

Refer to the exhibit. The network is configured with OSPF. A networking team just connected a streaming multicast server to router R7, and they now must enable access for users throughout the network to stream video from the server.

Which action must the team take so that users can stream video without overloading the network?

Options:

A.

Implement PIM-DM on the link between the server and R7.

B.

Implement PIM-SM on the LAN network connecting R5, R6, R3, and R4.

C.

Implement PIM-SM on all routers and connected links.

D.

Implement PIM-DM on all interfaces in the network except the LAN connection between R5, R6, R3, and R4.

Buy Now
Questions 150

Refer to the exhibit.

350-501 Question 150

Which configuration must be implemented on router R8 so that it will establish OSPF adjacency with R5?

A)

350-501 Question 150

B)

350-501 Question 150

C)

350-501 Question 150

D)

350-501 Question 150

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 151

How is a telemetry session established for data analytics?

Options:

A.

A router initiates a session using the dial-out to a destination.

B.

A destination initiate a session to a router.

C.

The destination initiate a session using the dial-out more to the router.

D.

A router requests the data using Teinet.

Buy Now
Questions 152

You are testing the capabilities of MPLS OAM ping.

Which statement is true?

Options:

A.

MPLS OAM ping works solely with Cisco MPLS TE

B.

MPLS OAM ping works solely with P2P LSPs

C.

An LSP breakage results in the ingress MPLS router never receiving any reply

D.

An LSP is not required for the reply to reach the ingress MPLS router

Buy Now
Questions 153

Refer to the exhibit. Which additional configuration must an engineer to the adge router to inject a default router into the MP-BGP address family for the internet_Shared_Services dedicated VRF?

A)

350-501 Question 153

B)

350-501 Question 153

C)

350-501 Question 153

D)

350-501 Question 153

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 154

Refer to the exhibit.

350-501 Question 154

A network administrator implemented MPLS LDP changes on PE-A LSR device. The engineer must ensure there are no LDP peer are fully operational. Which LDP feature must the engineer apply to the existing configuration to eliminate the problem?

Options:

A.

Configure MPLS LDP IGP synchronization on the network.

B.

Configure MPLS LDP NSR for all LDP sessions.

C.

Enable LDP session protection under the routing protocol.

D.

Disable IP CEF on routers running LDP and enable LDP.

Buy Now
Questions 155

How does TI-LFA reduce packet loss in Segment routing?

Options:

A.

It determines which link to use when load balancing to prevent packet fragmentation loss.

B.

It establishes multiple labels per path using more than one IGP.

C.

It calculates loop-free backup paths that are rapidly implemented in case of a link failure.

D.

It enables path selection in SR-TE to support MPLS label allocation.

Buy Now
Questions 156

What is the function of Cisco NFV infrastructure platform?

Options:

A.

It does not have a security audit feature.

B.

It does not offer high availability.

C.

It offers consistent performance.

D.

It offers decentralized logging.

Buy Now
Questions 157

350-501 Question 157

Refer to the exhibit. Customer_A asked ISP_A to connect two offices via an MPLS L3 VPN. Customer_A is currently using only the default route toward ISP_A. The engineer at ISP_A already configured the ip route vrf Customer_A 172.16.10.0 255.255.255.0 10.10.10.1 command on R1. Which action completes the configuration?

Options:

A.

Configure the network 172.16.10.0 and redistribute-internal static commands under the BGP address family for Customer_A in the global BGP configuration on R1.

B.

Enable the bgp default route-target filter and default-Information originate commands under the global BGP configuration on R2.

C.

Configure the route-target both 200:1 and route-replicate vrf Customer_A commands under the lp vrf configuration on R2.

D.

Configure the redistribute static and redistribute connected commands on R1.

Buy Now
Questions 158

Refer to the exhibit.

350-501 Question 158

A Cisco engineer is implementing gRPC dial-out on an ASR. Receiver 192.168 1.1 will be assigned one of the subscriptions, and it will manage the ASR. Which command is needed to complete the router configuration?

Options:

A.

protocol grpc

B.

protocol all

C.

protocol tcp

D.

protocol any

Buy Now
Questions 159

An engineer working for a telecommunication company with an employee ID: 4460:35:466 must configure an OSPF router in a multivendor network so that it performs NSF in the event of a route processor switchover. Which configuration must the engineer apply?

Options:

A.

router ospf 1 nsf Cisco

B.

router ospf 1 nsf ietf

C.

router ospf 1 nsf ietf helper

D.

router ospf 1 nsf Cisco helper

Buy Now
Questions 160

350-501 Question 160

Refer to the exhibit. Tier 1 ISP A purchased several Tier 2 ISPs to increase their customer base and provide more regional coverage. ISP A plans to implement MPLS services in the access layer, with scalability up to 100.000 devices In one packet network and service recovery up to 50 ms. The network architect decided to use different independent IGP and LDP domains and interconnect LSPs that are based on RFC 3107. Which two actions must the network engineer perform to meet the requirements? (Choose two.)

Options:

A.

Implement BGP PIC core functionality on routers R2 and R3.

B.

Configure three OSPF areas, with Area 0 In the core domain, and Areas 2 and 3 in the aggregation domain.

C.

Implement BGP connectivity between routers R1 and R4 with VPNv4 address family enabled.

D.

Implement BGP inline RR functionality with next-hop-self capabilities on routers R2 and R3.

E.

Implement the IS-IS routing protocol on the access domain.

Buy Now
Questions 161

Refer to the exhibit.

350-501 Question 161

An engineer is configuring an administrative domain in the given multi-vendor environment with PIM-SM. Which feature must the engineer implement so that devices will dynamically learn the RP?

Options:

A.

Auto-RP

B.

BIDIR-PIM

C.

SSM

D.

BSR

Buy Now
Questions 162

Refer to the exhibit:

350-501 Question 162

If router RA is configured as shown, which IPv4 multicast address space does it use?

Options:

A.

224.0. 0.0/8

B.

225.0. 0.0/8

C.

232.0. 0.0/8

D.

239.0. 0.0/8

Buy Now
Questions 163

Refer to the exhibit.

350-501 Question 163

350-501 Question 163

The engineering team wants to limit control traffic on router RX with the following IP address assignments:

• Accepted traffic for router: 10.0.0.0/24

• NOC users IP allocation: 192.168.10.0/24

Which additional configuration must be applied to RX to apply the policy for MSDP?

Options:

A.

RX(config)#access-list 151 permit tcp any gt 1024 10.10.0.0 0.0.0.255 eq 639

RX(config)#access-list 151 permit tcp any eq 639 10.10.0.0 0.0.0.255 gt 1024 established

B.

RX(config)#access-list 150 permit tcp any gt 1024 10.0.0.0 0.0.0.255 eq 639

RX(config)#access-list 150 permit tcp any eq 639 10.0.0.0 0.0.0.255 gt 1024 established

C.

RX(config)#access-list 151 permit tcp any 10.0.0.0 0.0.0.255 eq 639

RX(config)#access-list 151 permit udp any 10.0.0.0 0.0.0.255 eq 639

D.

RX(config)#access-list 150 permit tcp any 10.0.0.0 0.0.0.255 eq 639

RX(config)#access-list 150 permit udp any 10.0.0.0 0.0.0.255 eq 639

Buy Now
Questions 164

Refer to the exhibit A network engineer is in the process of implementing IS-IS Area 1 and Area 2 on this network to segregate traffic between different segments of the network The hosts in the two new areas must maintain the ability to communicate with one another In both directions. Which additional change must be applied?

350-501 Question 164

Options:

A.

Reconfigure either R3 or R4 as a Level 1/Level 2 router.

B.

Reconfigure routers R1, R2 R5. and R6 as Level 1/Level 2 routers.

C.

Reconfigure routers R2 and R5 as Level 1/Level 2 routers.

D.

Reconfigure routers R4, R5 and R6 as Level 1 routers

Buy Now
Exam Code: 350-501
Exam Name: Implementing and Operating Cisco Service Provider Network Core Technologies (350-501 SPCOR)
Last Update: Oct 4, 2026
Questions: 547

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11