Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

300-420 Designing Cisco Enterprise Networks (ENSLD) Questions and Answers

Questions 4

An architect must create a QoS solution for a customer to ensure that a 40 Mbps Internet connection is shared between four subnets based on these requirements:

* Each subnet must receive no less than 10 Mbps of download bandwidth during peak traffic times.

* A subnet can use up to 40 Mbps during nonpeak traffic times if the other subnets are idle.

* Download traffic must never experience a delay.

Which solution must the architect choose?

Options:

A.

rate-limiting and shaping

B.

bandwidth percentage and policing

C.

shaping and policing

D.

bandwidth percentage and rate-limiting

Buy Now
Questions 5

When a first hop redundancy solution is designed, which protocol ensures that load balancing occurs over multiple routers using a single virtual IP address and multiple virtual MAC addresses?

Options:

A.

GLBP

B.

IRDP

C.

VRRP

D.

HSRP

Buy Now
Questions 6

An engineer must peer with an ISP for internet connectivity using BGP, initially, the engineer wants to receive only specific prefixes from the ISP and a default route. However, the solution must provide the flexibility to add prefixes in the future at short notice. The ISP has a two-week change process in place. Which route filtering solution must the engineer employ?

Options:

A.

Request a limited internet routing table and a default route from the ISP and configure the BGP max-limit to 1 with an access list that permits only the specific internet prefixes and blocked networks

B.

Request only the required prefixes and default route be advertised from the ISO with whitelisted networks

C.

Request a full internet routing table and a default route from the ISP and configure inbound route filtering with a prefix list that permits the default route and required prefixes

D.

Configure outbound route filtering on the enterprise and ISP so that the enterprise tell the ISP which prefixes are required

Buy Now
Questions 7

Which two border nodes are available in the Cisco SD-Access architecture? (Choose two.)

Options:

A.

extended border

B.

edge border

C.

internal border

D.

anywhere border

E.

intermediate border

Buy Now
Questions 8

An architect must design an IPv6 migration solution for a corporation with remote offices to support:

* The customer has IPv4 peering with their service provider.

* IPv6 users need access to IPv4 and IPv6 resources.

* Existing content providers will migrate to IPv6 in the next two years.

* Users will be migrated in a phase-by-phase approach.

Which migration solution must the architect choose?

Options:

A.

NAT46

B.

tunneling

C.

NAT64

D.

dual-stack

Buy Now
Questions 9

Which function do reverse path forwarding mechanisms perform in a multicast deployment?

Options:

A.

They notify the upstream router of multicast traffic.

B.

They send PIM prune message toward multicast sources.

C.

They eliminate overlapping multicast addresses

D.

They prevent loops and duplicate packets.

Buy Now
Questions 10

Refer to the exhibit. A network engineer must design a BGP solution based on:

    The route reflector must have one or more direct physical connections to the core routers (R3 and R4).

    The route reflector must have full redundancy and avoid a single point of failure.

    R2 to R1 link utilization is 90%. and the remaining links are less than 50% utilized.

Which two solutions must the design Include? (Choose two.)

Options:

A.

Configure R1 to be a client of R2 and R4.

B.

Configure R2 to be a client of R1 and R4.

C.

Configure R3 to be a client of R2 and R4.

D.

Configure R4 to be a client of R1 and R3.

E.

Configure R5 to be a client of R3 and R4.

Buy Now
Questions 11

What is the purpose of a control plane node in a Cisco SD-Access network fabric?

Options:

A.

to maintain the endpoint database and mapping between endpoints and edge nodes

B.

to detect endpoints in the fabric and inform the host tracking database of EID-to-fabric-edge node bindings

C.

to identify and authenticate endpoints within the network fabric

D.

to act as the network gateway between the network fabric and outside networks

Buy Now
Questions 12

What is a benefit of using VRRPv3 as compared to VRRPv2?

Options:

A.

VRRPv3 supports IPv4 and IPv6

B.

VRRPv3 supports authentication

C.

VRRPv3 supports preemption

D.

VRRPv3 supports stateful switchover

Buy Now
Questions 13

A customer requires QoS to support multimedia conferencing over MPLS. The network architect chooses to use per-hop behavior. Which solution must the architect use to classify and mark traffic traveling between branch sites?

Options:

A.

BW Queue and DSCP WRED with DSCP AF3

B.

BW Queue with DSCP AF3

C.

BW Queue and DSCP WRED with DSCP AF4

D.

BW Queue with DSCP AF4

Buy Now
Questions 14

What is the purpose of a TLOC extension in a Cisco SD-WAN network fabric?

Options:

A.

to facilitate WAN Edge router redundancy within a site

B.

to identify the physical interface where a WAN Edge router connects to the WAN transport network

C.

to expand the number of colors that are potentially applied to a network transport interface

D.

to aggregate multiple physical interfaces into a single logical Interface

Buy Now
Questions 15

In Cisco SD-Access. virtual networks create segmentation that allows for separation of users and resources. How is this type of segmentation described?

Options:

A.

macro

B.

inter-VN

C.

micro

D.

stretctied

Buy Now
Questions 16

Which encoding languages are supported in NETCONF compared to RESTCONF?

Options:

A.

NETCONF supports XML and JSON, and RESTCONF supports XML.

B.

NETCONF supports XML, and RESTCONF supports JSON.

C.

NETCONF supports JSON, and RESTCONF supports XML.

D.

NETCONF supports XML, and RESTCONF supports XML and JSON.

Buy Now
Questions 17

What is an advantage of designing an out-of-band network management solution?

Options:

A.

In the event of a production network outage, network devices can still be managed.

B.

There is no separation between the production network and the management network.

C.

In the event of a production network outage, it can be used as a backup network path.

D.

It is less expensive than an in-band management solution

Buy Now
Questions 18

Refer to the exhibit. Which method must an architect use to provide connectivity between the mail servers?

Options:

A.

ISATAP

B.

6to4

C.

IPv4 compaliDie

D.

6rd

Buy Now
Questions 19

A company requested that an architect propose a new IPv4 and IPv6 deployment strategy. The company wants a solution that is straightforward, with no information hiding or forwarding overhead. Which solution meets these requirements?

Options:

A.

LISP

B.

NAT64

C.

dual-stack

D.

GRE tunnels

Buy Now
Questions 20

An architect must design a plan to manage the enterprise network devices. The design must accommodate that:

    not all network devices have a dedicated management interface

    all IP-enabled interfaces on all devices must be reachable

    encryption must be used with all devices which have support

Which solution must the architect choose?

Options:

A.

KVM server

B.

in-band

C.

out-of-band

D.

terminal server

Buy Now
Questions 21

Refer to the exhibit. An architect is developing a solution to consolidate networks while retaining device redundancy. The routing protocol for the WAN routers must be open standard, ensure high availability, and provide the fastest convergence time. Which solution must the design include?

Options:

A.

both routers running EIGRP

B.

one router running OSPFv2 and other OSPF v3

C.

one router running ISIS and other OSPF v3

D.

both routers running OSPFv2

Buy Now
Questions 22

What is the main purpose of the Cisco SD-Access overlay design?

Options:

A.

To simplify network management and troubleshooting for support teams

B.

To ensure high availability and fault tolerance for user services

C.

To enable seamless integration with SD-Access overlay services

D.

To enhance network visibility and monitoring for infrastructure

Buy Now
Questions 23

Refer to the exhibit. An engineer is designing an OSPF network for a client. Requirements dictate that the routers in Area 1 should receive all routes belonging to the network, including EIGRP, except the ones originated in the RIP domain. Which action should the engineer take?

Options:

A.

Make area 1 a NSSA.

B.

Make area 1 a stub.

C.

Make area 1 a standard OSPF area.

D.

Make the area 1 routers part of area 0.

Buy Now
Questions 24

Refer to the exhibit.

An engineer must design a WAN solution so that ISP-1 is always preferred over ISP-2. The path via ISP-2 is

considered as a backup and must be used only when the path to ISP-1 is down. Which

solution must the engineer choose?

Options:

A.

R1:

- Routes advertised to ISP-1: 0x AS-path prepend

- Routes received from ISP-1: HIGH local-preference

- Routes advertised to R2: no action

- Routes received from R2: community NO-EXPORT

R2:

- Routes advertised to ISP-2:5x AS-path prepend

- Routes received from ISP-2: LOW local-preference

- Routes advertised to R1: community NO-ADVERTISE

- Routes received from R1: no action

B.

R1:

- Routes advertised to ISP-1: 0x AS-path prepend

- Routes received from ISP-1: HIGH local-preference

- Routes advertised to R2: community NO-EXPORT

- Routes received from R2: no action

R2:

- Routes advertised to ISP-2: 5x AS-path prepend

- Routes received from ISP-2: LOW local-preference

- Routes advertised to R1: no action

- Routes received from R1: no action

C.

R1:

- Routes advertised to ISP-1: 0x AS-path prepend

- Routes received from ISP-1: LOW local-preference

- Routes advertised to R2: community NO-ADVERTISE

- Routes received from R2: no action

R2:

- Routes advertised to ISP-2: 5x AS-path prepend

- Routes received from ISP-2: HIGH local-preference

- Routes advertised to R1: no action

- Routes received from R1: community NO-ADVERTISE

D.

R1:

- Routes advertised to ISP-1: 5x AS-path prepend

- Routes received from ISP-1: LOW local-preference

- Routes advertised to R2: community NO-ADVERTISE

- Routes received from R2: no action

R2:

- Routes advertised to ISP-2: 0x AS-path prepend

- Routes received from ISP-2: HIGH local-preference

- Routes advertised to R1: community NO-EXPORT

- Routes received from R1: no action

Buy Now
Questions 25

An engineer must design a multicast network for a financial application. Most of the multicast sources also receive multicast traffic (many-to-many deployment model). To better scale routing tables, the design must not use source trees. Which multicast protocol satisfies these requirements?

Options:

A.

PIM-SSM

B.

PIM-SM

C.

MSDP

D.

BIDIR-PIM

Buy Now
Questions 26

Refer to the exhibit. An engineer is planning an IPv4 to IPv6 migration solution for a customer. The routers in the network can support IPv4 and IPv6, except for the DWDM routers. The DWDM routers provide a Layer 2 link in which the routers peer directly with each other across a DWDM circuit. The circuit also provides connectivity between the mail servers. Which IPv6 migration technique must the engineer deploy?

Options:

A.

dual-stack

B.

6to4

C.

ISATAP

D.

6rd

Buy Now
Questions 27

A customer has several remote sites connected with their headquarters through microwave links. An engineer must propose a backup WAN solution based on these conditions:

Which backup WAN link type the engineer recommend?

Options:

A.

LTE

B.

802.16 WiMAX

C.

Laser link

D.

802.15.1 Bluetooth

Buy Now
Questions 28

Which design consideration should be observed when EIGRP is configured on Data Center switches?

Options:

A.

Perform manual summarization on all Layer 3 interfaces to minimize the size of the routing table.

B.

Prevent unnecessary EIGRP neighborships from forming across switch virtual interfaces.

C.

Lower EIGRP hello and hold timers to their minimum settings to ensure rapid route reconvergence.

D.

Configure multiple EIGRP autonomous systems to segment Data Center services and applications.

Buy Now
Questions 29

Which security functionality does gRPC provide?

Options:

A.

implementing secure server-client tunnels with RSA 20*8 cipher encryption

B.

mandatory encryption of data at rest using the AES and RSA protocols

C.

enabling RC6 data-level encryption with CRC check

D.

supporting secure communication between network devices and control systems using TLS

Buy Now
Questions 30

When differentiating between IETF. OpenConfig. and Cisco native YANG models, how does the use of containers differ?

Options:

A.

OpenConfig uses one container for operational data and another container for configuration data, and IETF and Cisco native models use a single container for operational data and configuration data.

B.

IETF and Cisco native models use a single container for operational data and configuration data, and OpenConfig uses one container for operational data and another container for configuration data.

C.

IETF and Cisco native models use one container for operational data and another container for configuration data, and OpenConfig uses a single container for operational data and configuration data.

D.

Cisco native models use one container for operational data and another container for configuration data, and OpenConfig and IETF use a single container for operational data and configuration data.

Buy Now
Questions 31

Prior to establishing full-mesh iPsec tunnels in a typical Cisco SD-WAN deployment, which mechanism do WAN Edge routers use to exchange Key information for data plane encryption?

Options:

A.

They use vSmart controllers as key exchange servers.

B.

They use vManage as a key exchange server.

C.

They use IKEv2 when exchanging keys with each other.

D.

They use vBond as a key exchange server.

Buy Now
Questions 32

Refer to the exhibit. A company specializing in VoD content creation has two offices in a separate multicast domain connected by a WAN link. BGP communication has been established between the offices. Clients are inside the LAN in each office. In AS5373. R2 has been selected as RP. What must the network architect design to deliver VoD content to clients in AS65773?

Options:

A.

MSDP

B.

PIM ASM with Auto-RP

C.

PIM SSM

D.

PIM ASM with BSR

Buy Now
Questions 33

In a cisco SD-Access brownfield deployment scenario, which configuration deployment must be taken with Cisco DNA center?

Options:

A.

Subnet stretching

B.

LAN automation

C.

Automated UNDERLAY

D.

Manual underlay

Buy Now
Questions 34

Which design achieves SD-WAN control plane redundancy?

Options:

A.

Configuring BFD on the WAN Edge routers

B.

Using multiple instances of vManage in clusters

C.

Deploying using a virtual platform like UCS or CSP

D.

Managing the underlay network with OMP

Buy Now
Questions 35

Refer to the exhibit.

The failover time of ISP-2 is significantly shorter than ISP-1 when an interface on the ISP router toward the campus network fails. Which solution minimizes the downtime to the sub-second?

Options:

A.

Aggressive timers

B.

Next-hop address tracking

C.

Graceful-restart

D.

BFD

Buy Now
Questions 36

An architect is designing a network for an enterprise site. The design must use an active/backup design for the WAN. It must guarantee the SLA for several applications regardless of which connection is used. Which deployment model should the architect choose?

Options:

A.

MPLS WAN from two separate ISPs

B.

hybrid WAN using MPLS VPN and internet VPN from a single ISP

C.

hybrid WAN using MPLS VPN and internet VPN from two separate ISPs

D.

internet WAN from two separate ISPs

Buy Now
Questions 37

Since installing a cisco TelePresence system, the company is experiencing other application having response issues when the system in use. As a result, the company asked an architect to recommend a QoS solution. The customer is currently using a CBWFQ policy to manage traffic on an internet connection with a speed of 100 Mbps. Which link-capacity limit must the architect choose for strict-priority for the real-time traffic?

Options:

A.

25 Mbps

B.

50 Mbps

C.

33 Mbps

D.

75 Mbps

Buy Now
Questions 38

What is the purpose of the fabric control plane in a Cisco SD-Access architecture?

Options:

A.

create, propagate, and enforce G6AC policies in the fabric

B.

create a transit node with BGP route reflector functionality

C.

extend multiple subnets to one RLOC

D.

create and resolve endpoint-to-location mapping

Buy Now
Questions 39

An engineer working for a service provider with an employee ID 4598.48.606 prepared several designs for a traditional campus network. The design must allow the deployment on the same VXLAN to any switch at the access layer and must support:

    Fast convergence

    High availability

    Resilience

Which design must be selected?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 40

How is internet access provided to a WAN edge router that is connected to a MPLS transport link?

Options:

A.

OMP advertises a default route from a WAN Edge router that is connected to the MPLS and internet transport networks

B.

Internet access must be provided at the WAN Edge router through either a 4G/5G link or local Internet circuit

C.

An extranet must be provided in the MPLS transport network to allow private traffic to reach the public internet

D.

TLOC extensions are used to route traffic to a WAN Edge router that is connected to the Internet transport network

Buy Now
Questions 41

Refer to the exhibit. An engineer is designing an OSPF solution for a customer. The design must take into consideration:

    Application load balancers D. E. and F are in different geographical locations and are OSPF-enabled.

    Hosts A, B. and C connect to an application through the load balancers using IP address 10.1.1.1/32.

    In the event of a failure of one of the load balancers, hosts must still have access to the application.

Which solution must the engineer choose?

Options:

A.

All load balancers to be co-located in area 0.

B.

X, Y, and Z to be configured as different areas

C.

At least one load balancer to be in area 0.

D.

X, Y and Z to be configured as the same area

Buy Now
Questions 42

Which two statements describe source trees in a multicast environment? (Choose two.)

Options:

A.

Source trees guarantee the minimum amount of network latency for forwarding multicast traffic

B.

Source trees create an optimal path between the source and the receivers

C.

Source trees use a single common root placed at some chosen point in the network

D.

Source trees can introduce latency in packet delivery

E.

Source trees can create suboptimal paths between the source and the receivers

Buy Now
Questions 43

Refer to the exhibit.

EIGRP has been configured on all links. The spoke nodes have been configured as EIGRP stubs, and the WAN links to R3 have higher bandwidth and lower delay than the links to R4. When a link failure occurs at the R1-R2 link, what happens to traffic on R1 that is destined for a subnet attached to R2?

Options:

A.

R1 has no route to R2 and drops the traffic

B.

R1 load-balances across the paths through R3 and R4 to reach R2

C.

R1 forwards the traffic to R3, but R3 drops the traffic

D.

R1 forwards the traffic to R3 in order to reach R2

Buy Now
Questions 44

Which element in a Cisco SD-WAN architecture maintains a centralized routing table?

Options:

A.

WAN Edge router

B.

vSmart Controller

C.

vManage NMS

D.

vBond Orchestrator

Buy Now
Questions 45

Which NETCONF operation creates filtering that is specific to the session notifications?

Options:

A.

< create-subscription >

B.

< commit >

C.

< notification >

D.

< logging >

Buy Now
Questions 46

A company must automate a set of complex changes aligned with DR testing in the network. These changes are specific, and the DR playbook will be adjusted in the future. The playbook has diverse routing and switching assets in scope as well as multiple vendor and hardware platforms. A developer will create a thin, web front-end microservice and integrate with an Open daylight controller to push changes to the network. Which YANG model should be used?

Options:

A.

Use a single native vendor YANG model to minimize development time

B.

Use an open YANG model to allow the reuse of code and standardize the implementation across platforms

C.

Use multiple native vendor YANG models to provide code consistency.

D.

Develop an individualized YANG model to minimize development resources and time to market.

Buy Now
Questions 47

An enterprise needs to enhance its WAN availability after a recent outage with its only MPLS provider. The proposed solution must have a quick deployment, be affordable, be reliable, and work as a backup for the enterprise ' s primary MPLS connection. Which solution meets these requirements?

Options:

A.

Contract an internet connection and deploy DMVPN.

B.

Deploy BFD echo mode and probe provider PE

C.

Deploy an additional WAN router and use a floating static route

D.

Contract another MPLS provider and deploy GET VPN.

Buy Now
Questions 48

Which information update is carried by OMP and enables the Cisco SD-WAN to build a secure overlay fabric on top of any public or private transport without regard for the actual link IP?

Options:

A.

TLOC

B.

RLOC

C.

LISP PITR

D.

DTLS

Buy Now
Questions 49

A company is working with a service provider to design a BGP policy. The company is dual-homed with the provider and wants to control which link inbound traffic transits. Also, the company will advertise several networks to the provider and needs propagation to go no further. Which BGP attribute meet these requirements?

Options:

A.

AS-path

B.

MED

C.

community

D.

local preference

Buy Now
Questions 50

Refer to the exhibit. An engineer is designing a BGP solution for a client that peers with ISP1 for full Internet connectivity and with ISP2 for direct exchange of routes for several third parties. Which action, when implemented on the edge routers, enables the client network to reach the Internet through ISP1?

Options:

A.

Run an eBGP session within different VRFs for each ISP.

B.

Advertise a default route for downstream routers within the client network.

C.

Apply the AS-path prepend feature for ISP2.

D.

Apply route filtering such that the client advertises only routes originated from its own AS.

Buy Now
Questions 51

Which two options can you use to configure an EIGRP stub router? (Choose two)

Options:

A.

    summary-only

B.

    receive-only

C.

    external

D.

    summary

E.

    totally-stubby

F.

    not-so-stubby

Buy Now
Questions 52

An architect must design a topology for a WAN network that satisfies these requirements:

    Devices must be able to make informed decisions.

    Suboptimal paths are allowed only In case of a failure.

    Backup paths must always be available.

Which topology must the architect select?

Options:

A.

partial mesh

B.

hub and spoke

C.

full mesh

D.

Clos

Buy Now
Questions 53

An engineer must configure EIGRP to ensure that all WAN routes are not advertised to the routers in a data center. Which action must be taken?

Options:

A.

Configure the stub router in receive-only mode.

B.

Advertise only the default route.

C.

Summarize the local subnets.

D.

Configure the stub router in distributed mode.

Buy Now
Questions 54

Refer to the exhibit. A network engineer is designing an OSPF solution to connect a company ' s remote to a newly provisioned MPLS VPN backbone. Some of the branches have a direct dark fiber connection between each other. The engineer wants to ensure that the dark fibers are used only when the MPLS core is unavailable. Which solution must the engineer choose?

Options:

A.

Stub area

B.

Sham link

C.

Virtual link

D.

NSSA

Buy Now
Questions 55

Refer to the exhibit.

C0FD9F48 C9ACDC725EA850EC2476EE1E

A network engineer is designing a network for AS100. The design should ensure that all traffic enters AS100

via link 1 unless there is a network failure. In the event of a failure, link 2 should function as the path for

incoming traffic. Which solution should the design include?

Options:

A.

Modify the next-hop attribute on R3.

B.

Use AS-Path prepending on R3.

C.

Modify the next-hop attribute on R4.

D.

Use AS-Path prepending on R4.

Buy Now
Questions 56

Drag and drop the descriptions from the left onto the Cisco SD-WAN component they describe on the right.

Options:

Buy Now
Questions 57

Which two LISP components are required in the Cisco SD-Access fabric control plane node? (Choose two.)

Options:

A.

Engross Tunnel Router

B.

Ingres Tunnel Router

C.

Map-Resolver

D.

Map-Server Proxy

E.

ETR

Buy Now
Questions 58

A network engineer must design a multicast solution to prevent the spoofing of multicast streams and ensure efficient bandwidth utilization. The network will be merged with another multicast domain in the future, and the merge must require minimum effort. Which two solutions meet the customer requirements? (Choose two.)

Options:

A.

PIM-SSM

B.

IGMPv3

C.

IGMPv2

D.

PIM-SM

E.

MSDP

Buy Now
Questions 59

Refer to the exhibit. An architect must design a solution to connect the two ASs. To optimize bandwidth, the design will implement load sharing between router R6 and router R4. Which solution should the design include?

Options:

A.

Use update-source to specify the Loopback interface.

B.

Use next-hop-serf attributes only for routes that are learned from eBGP peers.

C.

Configure the eBGP TTL to support eBGP multihop.

D.

Use maximum-paths to install multiple paths in the routing table.

Buy Now
Questions 60

Drag and drop the characteristics from the left onto the configuration protocols they describe on the right.

Options:

Buy Now
Questions 61

Refer to the exhibit. Where must an architect plan for route summarization for the topology?

Options:

A.

from the core toward the aggregation and the access toward the aggregation

B.

from the core toward the aggregation and the aggregation toward the core

C.

from the aggregation toward the access and the access toward the aggregation

D.

from the aggregation toward the core and the aggregation toward the access

Buy Now
Questions 62

Drag and drop the model- driven telemetry considerations from the left onto the modes they apply to on the right.

Options:

Buy Now
Questions 63

Which component is part of the Cisco SD-Access overlay architecture?

Options:

A.

border node

B.

spine node

C.

leaf node

D.

Cisco DNA Center

Buy Now
Questions 64

What is a primary capability of the cloud-based services model in an IaaS deployment?

Options:

A.

It provides workload-migration capabilities, which allows seamless movement of virtual machines and applications between on-premises infrastructure and the cloud.

B.

It reduces operational costs and increases flexibility by allowing organizations to pay for only the resources they consume.

C.

It provides the ability to scale resources up or down based on demand, which enables an organization to adjust its computing capacity dynamically.

D.

It leverages advanced orchestration and automation tools to streamline resource provisioning and management, which reduces manual effort and improves operational efficiency.

Buy Now
Questions 65

Refer to the exhibit An architect is designing an IPv4 plan using the 172 20 0.0/16 network The design must maximize the number of subnets and minimize the number of wasted IP addresses In addition, the plan must allocate a subnet to these customers and links

    Customer A, which supports 125 hosts

    Customer D, which supports 62 hosts

    Links B C. and E

Which two configuration sets meet these requirements ' ? (Choose two)

A)

B)

C)

D)

E)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 66

Drag and drop the Cisco Catalyst SD-WAN components from the left to their definitions on the nght

Options:

Buy Now
Questions 67

A customer requests a VPN solution to connect multiple sites with the company headquarters. All the sites use the same IP subnet. The engineer plans to use VPLS. Which solutions must the engineer include in the design?

Options:

A.

802.1Q connectivity on the LAN side of the CE

B.

route exchange with the service provider

C.

address translation to hide overlapping subnets

D.

different VLANs on each site

Buy Now
Questions 68

An engineer is designing a campus network with Cisco Catalyst 95CO switches in the aggression layer. The design requires running nonblocking Layer 2 MEC from the aggregation layer to the access layer. The Catalyst switches are located on different campus floors for availability reasons, and each access switch veil contam a single VLAN. Which technology must the engineer choose for the aggregation switches in the design?

Options:

A.

VPC

B.

VSS

C.

StackWise Virtual

D.

StackWise-180

Buy Now
Questions 69

Which two best practices must be followed when designing an out-of-band management network? (Choose two.)

Options:

A.

    Enforce access control

B.

    Facilitate network integration

C.

    Back up data using the management network

D.

    Ensure that the management network is a backup to the data network

E.

    Ensure network isolation

Buy Now
Questions 70

What is the purpose of an edge node in an SD-Access network fabric?

Options:

A.

Edge nodes identify and authenticate endpoints and register endpoint information with control plane nodes.

B.

Edge nodes track endpoint IDs to location mappings, along with IPv4, IPv6, or MAC addresses.

C.

Edge nodes are the gateway between the fabric domain and network outside of the fabric.

D.

Edge nodes resolve lookup requests from edge and border nodes to locate destination endpoint IDs.

Buy Now
Questions 71

An architect is designing a connectivity solution for a customer ' s two small branch offices. The customer wants a cost-effective design, no routing overload, and some down time during the year is acceptable. Which connectivity solution must the architect choose?

Options:

A.

dual multihomed

B.

single-homed

C.

single multihomed

D.

dual-homed

Buy Now
Questions 72

Refer to the exhibit. An architect is designing an ISIS solution with these requirements:

    The backbone area will grow to 50 routers in the next 12 months.

    Routers A1 and A2 must avoid suboptimal routing.

    Summarization and route-leaking should be allowed in areas 49.002 and 49.003.

Which solution must the architect select?

Options:

A.

area 49.000 L1, area 49.001 L2, area 49.002 L2, and area 49.003 L2

B.

area 49.000 L1, area 49.001 L1, area 49.002 L2, and area 49.003 L2

C.

area 49.000 L2. area 49.001 L1, area 49.002 L1, and area 49.003 L1

D.

area 49.000 L2. area 49.001 L2, area 49.002 L1, and area 49.003 L1

Buy Now
Questions 73

A client is moving to Model-Driven Telemetry and requires periodic updates. What must the network architect consider with this design?

Options:

A.

Updates that contain changes within the data are sent only when changes occur.

B.

Empty data subscriptions do not generate empty update notifications.

C.

Periodic updates include a full copy of the data that is subscribed to.

D.

The primary push update is sent immediately and cannot be delayed.

Buy Now
Questions 74

Drag and drop the elements from the left onto the protocols where they are used on the right.

Options:

Buy Now
Questions 75

Refer to the exhibit.

An architect is designing an EIGRP solution based on these requirements:

* Traffic forwarding should use the best two paths while all links are available

* Single path failure must not impact traffic between branch and HQ

Which solution must the architect select?

Options:

A.

Maximum-paths 2

B.

Add-paths 2

C.

Metric weights 010100

D.

Variance 2

Buy Now
Questions 76

An engineer must use YANG with an XML representation to configure a Cisco IOS XE switch with these specifications:

    IP address 10.10.10.10/27 configured on the interface GigabitEthernet2/1/0

    connectivity from a directly connected host 10.10.10.1/27

Which YANG data model set must the engineer choose?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 77

Which two statements about VRRP object tracking are true? (Choose two)

Options:

A.

The priority of a VRRP device can change in accordance with the up or down status of a VRRP object

B.

The VRRP interface priority must be manually configured by the administrator

C.

A VRRP group can track only one object at a time

D.

VRRP can track the status of interfaces and routes

E.

VRRP supports only interface tracking

Buy Now
Questions 78

When a network is designed using IS-IS protocol, which two circuit types are supported? (Choose two.)

Options:

A.

nonbroadcast multiaccess

B.

multiaccess

C.

point-to-multipoint

D.

nonbroadcast

E.

point-to-point

Buy Now
Questions 79

An existing network solution is using BFD in echo mode. Several of the network devices are experiencing high CPU utilization which an engineer has determined is related to the BFD feature. Which solution should the engineer leverage to reduce the CPU load?

Options:

A.

Implement slow timers between peers with low CPU resources.

B.

Implement BED asynchronous mode between peers with low CPU resources.

C.

Enable BFD multi-hop on the devices with low CPU resources.

D.

Utilize carrier delay on all routers in the network.

Buy Now
Questions 80

An engineer uses Postman and YANG to configure a router with:

Which get-config replay verifies that the model set was designed correctly?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 81

What is the purpose of a border node in a Cisco SD-Access fabric?

Options:

A.

connect devices to a network

B.

perform traffic encapsulation and de-encapsulation

C.

perform network virtualization

D.

expand a network

Buy Now
Questions 82

Which two techniques improve the application experience in a Cisco SD-WAN design? (Choose two.)

Options:

A.

utilizing forward error correction

B.

implementing a stateful application firewall

C.

implementing AMP

D.

utilizing quality of service

E.

implementing Cisco Umbrella

Buy Now
Questions 83

Which nonproprietary mechanism can be used to automate rendezvous point distribution in a large PIM domain?

Options:

A.

Embedded RP

B.

BSR

C.

Auto-RP

D.

Static RP

Buy Now
Questions 84

Which feature minimizes HOC connections and reduces strain on the vSmart controller m an SO-WAN architecture?

Options:

A.

control-connections

B.

corrtroWirection

C.

color

D.

affinity

Buy Now
Questions 85

Which two considerations must be made regarding the overlay network for a Cisco SD-Access architecture? (Choose two.)

Options:

A.

Virtual networks should be used for microsegmentation

B.

SGTs should be used for data plane isolation and microsegmentation

C.

Virtual networks should be used for data plane isolation only

D.

Overlapping IP addresses across different overlay networks should be used to conserve IP addresses

E.

Overlapping IP addresses across different overlay networks should be avoided for operational simplicity

Buy Now
Questions 86

Refer to the exhibit. An architect must design a solution to connect bank site A with bank site B and support:

    network operation center monitoring end-to-end L3VPN and L2VPN traffic

    company adding thousands of routes in the next two years

Which two BGP solutions must the design include? (Choose two.)

Options:

A.

Establish full mesh IBGP peering with ail routers in different IGP domains.

B.

Redistribute different IGP domain routes in a BGP IPv4 routing instance.

C.

Transport site routes using a BGP VPNv4 address family on the PE routers.

D.

Apply BGP policies on all routers to filter out ABR and PE loopback IP addresses.

E.

Connect multiple IGP ' LDP domains using a BGP IPv4 unicast family on the ABR.

Buy Now
Questions 87

An architect is working on a design to connect a company ' s main site to several small to medium-sized remote branches. The solution must include redundant WAN links, but the customer has a limited budget and wants the ability to increase the link speed easily in the future. QoS will not on the branch routers so there is no need for consistent end-to-end QoS. Which solution does the architect propose?

Options:

A.

dual-homed WAN MPLS with single edge router

B.

dual-homed Internet with a single edge router running a site-to-site VPN topology

C.

dual-homed WAN MPLS and Internet links via dual edge routers

D.

dual-homed Internet with dual edge routers running a hub-and-spoke VPN topology

Buy Now
Questions 88

Refer to the exhibit. An architect reviews the low-level design of a company ' s enterprise network and advises optimizing the STP convergence time. Which functionality must be to Gi1/0/1-10 to follow the architect ' s recommendation?

Options:

A.

PortFast

B.

root guard

C.

UplinkFast

D.

BPDU guard

Buy Now
Questions 89

An engineer is working for a large cable TV provider that requires multiple sources streaming video on different channels using multicast with no rendezvous point. Which multicast protocol meets these requirements?

Options:

A.

PIM-SM

B.

PIM-SSM

C.

any-source multicast

D.

BIDIR-PIM

Buy Now
Questions 90

Refer to the exhibit.

An engineer is designing a routing solution for a customer. The design must ensure that a failure of network

10.1.0.0/24, 10.1.2.0/24, 10.2.1.0/24, or 10.2.3.0/24 does not impact the core. It also requires fast convergence

time during any link failover in the core or access networks. Which solution must the engineer select?

Options:

A.

Add aggregation layer between core and access networks.

B.

Enable graceful restart on routers A and C.

C.

Enable FRR for the connected networks of routers A and C.

D.

Enable summarization on routers A and C.

Buy Now
Questions 91

How is end-to-end microsegmentation enforced in a Cisco SD-Access architecture?

Options:

A.

VLANs are used to segment traffic at Layer 2.

B.

5-tuples and ACLs are used to permit or deny traffic.

C.

SGTs and SGTACLs are used to control access to various resources.

D.

VRFs are used to segment traffic at Layer 3.

Buy Now
Questions 92

Which two BGP features will result in successful route exchanges between eBGP neighbors sharing the same

AS number? (Choose two.)

Options:

A.

advertise-best-external

B.

bestpath as-path ignore

C.

client-to-client reflection

D.

as-override

E.

allow-as-in

Buy Now
Questions 93

Which integration capability does gRPC provide?

Options:

A.

leveraging the LDAP protocol for authentication and directory services ensuring secure access control in RPC communications

B.

leveraging the XMPP protocol for real-time messaging and collaboration between client and server applications

C.

leveraging protocol buffers to provide efficient serialization and deserialization of structured data over the network

D.

leveraging GRAPH-API for network monitoring and management providing comprehensive visibility into RPC-related metrics and performance statistics

Buy Now
Questions 94

Refer to the exhibit.

Which solution decreases the EIGRP convergence time?

Options:

A.

Enable subsecond timers

B.

Increase the hold time value

C.

Increase the dead timer value

D.

Enable stub routing on the spokes

Buy Now
Questions 95

Refer to the exhibit. An architect designs a BGP policy for a customer that requires load sharing of the links that connect with the upstream service provider. The customer has these requirements: • The inbound traffic destined to network 10.1.1.0/24 must transit the R3-R1 link, and if the link fails, all inbound traffic must transit the R4-R2 link.

• The inbound traffic destined to network 10.1.2.0/24 must transit the R4-R2 link, and if the link fails, all inbound traffic should transit the R3-R1 link.

Which solution must the architect choose?

Options:

A.

• R1 must announce prefix 10.1.2.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512

• R2 must announce prefix 10.1.1.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512.

B.

• R1 must announce prefix 10.1 2.0/24 with a community attribute 64513:300 and prefix 10.1.1.0/24 with a community attribute 64513:200.

• R2 must announce prefix 10.1.2.0/24 with a community attribute 64513:200 and prefix 10.1.1.0/24 with a community attribute 64513:300.

C.

• R1 must announce prefix 10.1.1.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512.

• R2 must announce prefix 10.1.2.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512.

D.

• R1 must announce prefix 10.1.2.0/24 with a community attribute 64513:200 and prefix 10.1.1.0/24 with a community attribute 64513:300.

• R2 must announce prefix 10.1.2.0/24 with a community attribute 64513:300 and prefix 10.1.1.0/24 with a community attribute 64513:200.

Buy Now
Questions 96

An engineer is designing a multicast network for a financial application Most of the multicast sources also receive multicast traffic (many-to-many deployment model). To better routing tables, the design must not use source trees. Which multicast protocol satisfies these requirements?

Options:

A.

BIRDIR-PIM

B.

PIM-SM

C.

MSDP

D.

PIM-SSM

Buy Now
Questions 97

Refer to the exhibit. An architect must design an IP addressing scheme for a multisite network connected via a WAN transit. The campus site must accommodate 12,000 devices and the branch sites must accommodate 1,000 devices. Which address scheme optimizes network device resources, contains convergence events to the different blocks of the network, and ensures future growth of the network?

Options:

A.

Campus: 10.0.0.0/18

• Branch1: 10.0.192.0/21

• Branch2: 10.0.200.0/21

B.

• Campus: 10.0.0.0/16

• Branchi: 10.255.0.0/20

• Branch2: 10.255.16.0/20

C.

• Campus: 10.0.0.0/10

• Branch1: 10.64.0.0/10

• Branch2: 10.128.0.0/10

D.

• Campus: 10.0.0.0/20

• Branch1: 10.0.64.0/21

Branch2: 10.0.128.0/21

Buy Now
Questions 98

A customer ' s current Layer 2 infrastructure is running Spanning Tree 802.1d, and all configuration changes are manually implemented on each switch. An architect must redesign the Layer 2 domain to achieve these goals:

    reduce the impact of topology changes

    reduce the time spent on network administration

    reduce manual configuration errors

Which two solutions should the architect include in the new design? (Choose two.)

Options:

A.

Implement Rapid PVST+ instead of STP.

B.

Implement MST instead of STP.

C.

Use VTP to propagate VLAN information and to prune unused VLANs.

D.

Configure broadcast and multicast storm control on all switches.

E.

Configure dynamic trunking protocol to propagate VLAN information.

Buy Now
Questions 99

Refer to the exhibit. Which two solutions maximize the use of the links between the core and distribution layers? (Choose two.)

Options:

A.

use multiple equal-cost links

B.

use an IGP

C.

use HSRP

D.

use R-PVSTP+

E.

use multiple unequal-cost links

Buy Now
Questions 100

A customer reports that each time a networking component fails, OSPF recalculates the backup path, with causes a short outage. Which solution must the customer implement to improve this situation?

Options:

A.

Aggressive OSPF timers

B.

LFA FRR

C.

Incremental SPF

D.

BFD

Buy Now
Questions 101

A customer plans to deploy WoL in the enterprise with these high-level design requirements:

DHCP services must be available.

Clients BIOS settings must be set for WoL.

Clients get IP addresses once online.

Spanning-tree PortFast is enabled on the Layer 2 switches.

Which two solutions must the customer select to have a successful deployment? (Choose two.)

Options:

A.

IP directed broadcast and forward-protocol must be enabled on all the SVI or routed interlaces where the client subnets reside.

B.

IP helper-addresses for the client ranges must be enabled on the SVI or routed interface where the WoL server subnet resides.

C.

IP helper-addresses for the client ranges must be disabled on the SVI or routed interface where the WoL server subnet resides

D.

IP helper-addresses for the WoL server must be enabled on the SVI or routed interface where the client subnets reside

E.

IP directed broadcast and forward-protocol must be disabled on all the SVI or routed interfaces where the client subnets reside.

Buy Now
Questions 102

What is the purpose of Cisco vBond as a Session Traversal Utilities for NAT server?

Options:

A.

allow Cisco Catalyst SD-WAN routers to locate their own mapped IP addresses

B.

integrate Cisco SD-Access Wireless into the fabric

C.

secure data traffic between Cisco Catalyst SD-WAN edge routers that use IPsec

D.

provide Zero-Touch Provisioning to Cisco Catalyst SD-WAN vEdge devices

Buy Now
Questions 103

A network engineer prepares a script to configure a loopback interface with IP address 172.16.15.12/32. To comply with the company security policies, ' Content-type ' :

‘application/yang-data+json‘ is added to the script. Connection to the network devices must be secured. Which code snippet must the network engineer use to meet this requirement?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 104

What is a logical topology in a Cisco SD-Access architecture considered to be when it is used to virtually connect devices that are built on an arbitrary physical network?

Options:

A.

data plane

B.

control plane

C.

underlay

D.

overlay

Buy Now
Questions 105

Which two functions are provided by the Cisco SD-WAN orchestration plane? (Choose two.)

Options:

A.

centralized provisioning

B.

primary authentication point

C.

NAT traversal facilitation

D.

Zero Touch Provisioning

E.

troubleshooting and monitoring

Buy Now
Questions 106

Refer to the exhibit. These requirements must be met:

    VLANs span multiple access switches.

    All VLANs are trunked on all access switch uplinks to distribution switches.

    The STP version is Rapid PVST+.

Which design provides the fastest spanning-tree convergence?

Options:

A.

Switch D configured as VLAN 10 secondary root, Switch C configured as VLAN 10 primary root, link A configured as Layer 2 trunk

B.

Switch D configured as VLAN 10 primary root, Switch C configured as VLAN 10 secondary root, link A configured as Layer 2 trunk

C.

Switch D configured as VLAN 10 primary root, Switch C configured as VLAN 10 secondary root, link A configured as Layer 3 routed link

D.

Switch D configured as VLAN 10 secondary root, Switch C configured as VLAN 10 primary root, link A configured as Layer 3 routed link

Buy Now
Questions 107

An engineer is tasked with designing a dual BGP peering solution with a service provider. The design must meet these conditions:

    The routers will not learn any prefix with a subnet mask greater than /24.

    The routers will determine the routes to include in the routing table based on the length of the mask alone.

    The routers will make this selection regardless of the service provider configuration.

Which solution should the engineer include in the design?

Options:

A.

Use a route map and access list to block the desired networks, and apply the route map to BGP neighbors inbound.

B.

Use a route map and prefix list to block the desired networks, and apply the route map to BGP neighbors outbound.

C.

Use an IP prefix list to block the desired networks and apply the IP prefix list to BGP neighbors outbound.

D.

Use an IP prefix list to block the desired networks and apply the IP prefix list to BGP neighbors inbound.

Buy Now
Questions 108

What is the purpose of service routes in OMP updates?

Options:

A.

specify routes toward a centralized orchestration plane

B.

describe underlay transport Information

C.

define the remote management Information

D.

indicate services that are enabled for service insertion

Buy Now
Questions 109

An architect must design a QoS model for a business-critical application that Is delay-sensitive and requires high bandwidth. The company ' s head office hosts the application, and DMVPN tunnels protected with IPsec provide connectivity between the head office and branches. Which solution must the architect choose?

Options:

A.

RSVP

B.

IntServ

C.

WRED

D.

DiffServ

Buy Now
Questions 110

A company with multiple service providers wants to speed up BGP convergence time in the event a failure occurs with their primary link. Which approach achieves this goal and does not impact router CPU utilization?

Options:

A.

Utilize BFD and tune the multiplier to 50

B.

Lower the BGP hello interval

C.

Decrease the BGP keepalive timer

D.

Utilize BFD and keep the default BGP timers

Buy Now
Questions 111

A company wants to switch from static to dynamic routing. The branches use DMVPN back to the hub using two internet connections. One internet connection speed is 10 Mbps, and the other is 100 Mbps. All locations use Cisco routers; however, the branch routers have limited memory and CPU resources. Which routing protocol and design solution must the company choose for optimal traffic forwarding during peak traffic times?

Options:

A.

iBGP with the hub routers set up as route reflectors

B.

OSPF deployed in area 0 with branch routers connected back via virtual links

C.

EIGRP with branch routers as stub routers and variance enabled

D.

ISIS with the hub and spoke routers configured in two different areas

Buy Now
Questions 112

Options:

Buy Now
Questions 113

A company is using OSPF between its HQ location and a branch office. HQ is assigned area 0 and the branch office is assigned area 1. The company purchases a second branch office, but due to circuit delays to HQ, it

decides to connect the new branch office to the creating branch office as a temporary measure. The new branch office is assigned area 2. Which OSPF configuration enables all three locations to exchange routes?

Options:

A.

The existing branch office must be configured as a stub area

B.

A virtual link must be configured between the new branch office and HQ

C.

A sham link must be configured between the new branch office and HQ

D.

The new branch office must be configured as a stub area

Buy Now
Exam Code: 300-420
Exam Name: Designing Cisco Enterprise Networks (ENSLD)
Last Update: Jun 25, 2026
Questions: 339
300-420 pdf

300-420 PDF

$28.5  $94.99
300-420 Engine

300-420 Testing Engine

$33  $109.99
300-420 PDF + Engine

300-420 PDF + Testing Engine

$43.5  $144.99