Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: geek65

300-420 Designing Cisco Enterprise Networks (ENSLD) Questions and Answers

Questions 4

When a first hop redundancy solution is designed, which protocol ensures that load balancing occurs over multiple routers using a single virtual IP address and multiple virtual MAC addresses?

Options:

A.

GLBP

B.

IRDP

C.

VRRP

D.

HSRP

Buy Now
Questions 5

What does the fabric data plane leverage in SD-Access Architecture?

Options:

A.

LISP protocol to resolve endpoint-to-location mapping

B.

IS-IS protocol to exchange link-state routing information

C.

MAC-in-IP encapsulation method to transport of the Layer 2 frame

D.

BGP protocol to advertise endpoint prefixes outside of the fabric

Buy Now
Questions 6

Refer to the exhibit. An architect with an employee ID: 4542:60:170 is designing a campus Layer 2 infrastructure. The design requires a PoE power budget that varies from 30-60 W. In addition, power must be provided continuously to some endpoints and must be supported even during the reloading of edge switches. Which solution must the architect select?

Options:

A.

PoE Plus

B.

Fast PoE

C.

Universal PoE

D.

Perpetual PoE

Buy Now
Questions 7

Which function does the Cisco SD-Access intermediate node perform?

Options:

A.

Act as LISP proxy tunnel router.

B.

Route and transport IP traffic.

C.

Act as an anycast Layer 3 gateway.

D.

Map users to a virtual network.

Buy Now
Questions 8

In an SD-WAN architecture, which methods are used to bootstrap a vEdge router?

Options:

A.

DHCP options or manual configuration

B.

vManage or DNS records

C.

ZTP or manual configuration

D.

DNS records or DHCP options

Buy Now
Questions 9

Refer to the exhibit. A customer needs to apply QoS to the network management traffic passing through the GigabitEthernet0/2 interface. All eight queuing classes are in use, so the new requirement must be integrated into the existing policy. Which solution must the customer choose?

Options:

A.

Mark traffic to DSCP CS5 and assign it to the SIGNALLING class. Then, baseline existing queue sizes to determine if additional bandwidth can be provisioned to the SIGNALLING class.

B.

Mark the traffic to DSCP CS4 and assign it to the SIGNALLING class. Then, prioritize traffic within the class.

C.

Mark the traffic to DSCP CS6 and assign it to the ROUTING class Then, prioritize traffic within the class.

D.

Mark the traffic to DSCP CS2 and assign it to the ROUTING class Then, baseline existing queue sizes to determine if additional bandwidth can be provisioned to the ROUTING class

Buy Now
Questions 10

A customer's current Layer 2 infrastructure is running Spanning Tree 802.1d, and all configuration changes are manually implemented on each switch. An architect must redesign the Layer 2 domain to achieve these goals:

    reduce the impact of topology changes

    reduce the time spent on network administration

    reduce manual configuration errors

Which two solutions should the architect include in the new design? (Choose two.)

Options:

A.

Implement Rapid PVST+ instead of STP.

B.

Implement MST instead of STP.

C.

Use VTP to propagate VLAN information and to prune unused VLANs.

D.

Configure broadcast and multicast storm control on all switches.

E.

Configure dynamic trunking protocol to propagate VLAN information.

Buy Now
Questions 11

Which method will filter routes between EIGRP neighbors within the same autonomous system?

Options:

A.

distribute-list

B.

policy-based routing

C.

leak-map

D.

route tagging

Buy Now
Questions 12

What is the purpose of an edge node in an SD-Access network fabric?

Options:

A.

Edge nodes identify and authenticate endpoints and register endpoint information with control plane nodes.

B.

Edge nodes track endpoint IDs to location mappings, along with IPv4, IPv6, or MAC addresses.

C.

Edge nodes are the gateway between the fabric domain and network outside of the fabric.

D.

Edge nodes resolve lookup requests from edge and border nodes to locate destination endpoint IDs.

Buy Now
Questions 13

Which design element should an engineer consider when multicast is included in a Cisco SD-Access architecture?

Options:

A.

PIM SSM must run in the underlay.

B.

Multicast clients reside in the underlay, and the multicast source is outside the fabric or

in the overlay.

C.

Rendezvous points must be used in a PIM SSM deployment.

D.

Multicast traffic is transported in the overlay and the EID space for wired and wireless clients.

Buy Now
Questions 14

Refer to the exhibit An engineer is designing an OSPF solution with these requirements:

    NMS server will manage R5 and R6.

    Upon failure of R1. all NMS traffic should be routed through R4.

    Upon failure of the link between R5 and R6. all traffic destined for 10.6.6.6 should be routed through R4

Which solution must the engineer choose?

Options:

A.

Advertise 172.16.1.1 into OSPF process 1 with high cost on R1.

B.

Apply static routes on R2 and R3 with IP SLA tracking toward R5 and R6.

C.

Enable the default-Information originate command with a higher metric on R2 to R1.

D.

Redistribute OSPF process 1 into process 2 on R1 and R4.

Buy Now
Questions 15

What is the purpose of a border node in a Cisco SD-Access fabric?

Options:

A.

connect devices to a network

B.

perform traffic encapsulation and de-encapsulation

C.

perform network virtualization

D.

expand a network

Buy Now
Questions 16

A client is moving to Model-Driven Telemetry and requires periodic updates. What must the network architect consider with this design?

Options:

A.

Updates that contain changes within the data are sent only when changes occur.

B.

Empty data subscriptions do not generate empty update notifications.

C.

Periodic updates include a full copy of the data that is subscribed to.

D.

The primary push update is sent immediately and cannot be delayed.

Buy Now
Questions 17

A company plans to transition to IPv6. They will link their IPv4 addresses to the lowest significant bits of the new Ipv6 addresses. A network administrator with an employee id: 4264:42:116 is preparing a mapping schema for the new IPv6 addresses. Which address does the 172.16.10.0/24 network translate to?

Options:

A.

2001:db8:abcd::ac10:a00/120

B.

2001:db8:abcd:172:16:10::/96

C.

2001:db8:abcd:11d8:a00/120

D.

2001:db8:ac10:0a00::/64

Buy Now
Questions 18

Refer to the exhibit. Which two points in the network must an engineer configure the ports for explicit trust when using a DiffServ model?

Options:

A.

B and E

B.

F and G

C.

A and D

D.

C and D

Buy Now
Questions 19

A company’s branch location uses redundant routers and links for connectivity to the headquarters. Also, to use the entire available bandwidth, the branch uses a dynamic routing protocol. An architect must design a multicast streaming solution to avoid RPF check failures because of the current network design. Which deployment model must the architect choose?

Options:

A.

PIM-SM

B.

BIDIR-PIM

C.

PIM-BSR

D.

PIM-SSM

Buy Now
Questions 20

Drag and drop the types of WAN connectivity from the left onto the connectivity use cases on the right.

Options:

Buy Now
Questions 21

Refer to the exhibit. An architect reviews the low-level design of a company's enterprise network and advises optimizing the STP convergence time. Which functionality must be to Gi1/0/1-10 to follow the architect's recommendation?

Options:

A.

PortFast

B.

root guard

C.

UplinkFast

D.

BPDU guard

Buy Now
Questions 22

Which design consideration should be observed when EIGRP is configured on Data Center switches?

Options:

A.

Perform manual summarization on all Layer 3 interfaces to minimize the size of the routing table.

B.

Prevent unnecessary EIGRP neighborships from forming across switch virtual interfaces.

C.

Lower EIGRP hello and hold timers to their minimum settings to ensure rapid route reconvergence.

D.

Configure multiple EIGRP autonomous systems to segment Data Center services and applications.

Buy Now
Questions 23

An engineer is designing an EIGRP network for a small branch site where there is only one Layer 3 router. The engineer wants the router to advertise the local LAN network to remote EIGRP neighbors without sending any unnecessary multicast messages on the local LAN. Which action should the engineer take?

Options:

A.

Use a static default route for this site instead of EIGRP

B.

Advertise the local LAN using the network command and the passive-interface feature

C.

Redistribute the local LAN network using the redistribute connected command

D.

Advertise the local LAN subnet as a stub network

Buy Now
Questions 24

Drag and drop the descriptions from the left onto the categories they apply to on the right.

Options:

Buy Now
Questions 25

What is a logical topology in a Cisco SD-Access architecture considered to be when it is used to virtually connect devices that are built on an arbitrary physical network?

Options:

A.

data plane

B.

control plane

C.

underlay

D.

overlay

Buy Now
Questions 26

Refer to the exhibit. An architect designs a BGP policy for a customer that requires load sharing of the links that connect with the upstream service provider. The customer has these requirements: • The inbound traffic destined to network 10.1.1.0/24 must transit the R3-R1 link, and if the link fails, all inbound traffic must transit the R4-R2 link.

• The inbound traffic destined to network 10.1.2.0/24 must transit the R4-R2 link, and if the link fails, all inbound traffic should transit the R3-R1 link.

Which solution must the architect choose?

Options:

A.

• R1 must announce prefix 10.1.2.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512

• R2 must announce prefix 10.1.1.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512.

B.

• R1 must announce prefix 10.1 2.0/24 with a community attribute 64513:300 and prefix 10.1.1.0/24 with a community attribute 64513:200.

• R2 must announce prefix 10.1.2.0/24 with a community attribute 64513:200 and prefix 10.1.1.0/24 with a community attribute 64513:300.

C.

• R1 must announce prefix 10.1.1.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512.

• R2 must announce prefix 10.1.2.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512.

D.

• R1 must announce prefix 10.1.2.0/24 with a community attribute 64513:200 and prefix 10.1.1.0/24 with a community attribute 64513:300.

• R2 must announce prefix 10.1.2.0/24 with a community attribute 64513:300 and prefix 10.1.1.0/24 with a community attribute 64513:200.

Buy Now
Questions 27

A network engineer must design a multicast solution to prevent the spoofing of multicast streams and ensure efficient bandwidth utilization. The network will be merged with another multicast domain in the future, and the merge must require minimum effort. Which two solutions meet the customer requirements? (Choose two.)

Options:

A.

PIM-SSM

B.

IGMPv3

C.

IGMPv2

D.

PIM-SM

E.

MSDP

Buy Now
Questions 28

An architect must design an IPv6 migration solution for a corporation with remote offices to support:

* The customer has IPv4 peering with their service provider.

* IPv6 users need access to IPv4 and IPv6 resources.

* Existing content providers will migrate to IPv6 in the next two years.

* Users will be migrated in a phase-by-phase approach.

Which migration solution must the architect choose?

Options:

A.

NAT46

B.

tunneling

C.

NAT64

D.

dual-stack

Buy Now
Questions 29

Refer to the exhibit.

C0FD9 F48C9ACDC725EA850EC2476EE1E

An architect must design a solution that uses the direct link between R1 and R2 for traffic from 10.10.10.0/24

toward network 10.10.20.0/24. Which solution should the architect include in the design?

Options:

A.

Configure the OSPF cost of the link to a value lower than 30.

B.

Lower the Administrative Distance for OSPF area 0.

C.

Place the link into area 2 and install a new link between R1 and R2 in area 0.

D.

Configure the link to provide multiarea adjacency.

Buy Now
Questions 30

A global organization with several branches hired a network architect to design an overlay VPN solution. The branches communicate with each other frequently. The customer expects to add more branches in the future. To meet the customer's security requirements, the architect plans to provide traffic protection using dynamic IPsec tunnels. Which solution should the architect choose?

Options:

A.

DMVPN

B.

EasyVPN

C.

GETVPN

D.

L2TP

Buy Now
Questions 31

Refer to the exhibit. All routers currently reside in OSPF area 0. The network manager recently used R1 and R2 as aggregation routers for remote branch locations and R3 and R4 for aggregation routers for remote office locations. The network has since been suffering from outages, which are causing frequent SPF runs. To enhance stability and introduce areas to the OSPF network with the minimal number of ABRs possible, which two solutions should the network manager recommend? (Choose two.)

Options:

A.

a new OSPF area for R1 and R2 connections,with R1 and R2as ABRs

B.

a new OSPF area for R3 and R4 connections,with R5 and R6as ABRs

C.

a new OSPF area for R3 and R4 connections,with R3 and R4as ABRs

D.

a new OSPF area for R1, R2, R3, and R4 connections, with R1, R2, R3, and R4 as

ABRs

E.

a new OSPF area for R1 and R2 connections, with R5 and R6 as ABRs

Buy Now
Questions 32

Which two routing protocols allow for unequal cost load balancing? (Choose two.)

Options:

A.

EIGRP

B.

IS-IS

C.

BGP

D.

OSPF

E.

RIPng

Buy Now
Questions 33

An architect is designing a network for an enterprise site. The design must use an active/backup design for the WAN. It must guarantee the SLA for several applications regardless of which connection is used. Which deployment model should the architect choose?

Options:

A.

MPLS WAN from two separate ISPs

B.

hybrid WAN using MPLS VPN and internet VPN from a single ISP

C.

hybrid WAN using MPLS VPN and internet VPN from two separate ISPs

D.

internet WAN from two separate ISPs

Buy Now
Questions 34

What are two advantages of the Cisco SD-WAN technology9 (Choose two)

Options:

A.

Improved application experience

B.

Easier deployment

C.

Optimized cloud connectivity

D.

Proactive network management

E.

Consistent connectivity

Buy Now
Questions 35

An enterprise needs to enhance its WAN availability after a recent outage with its only MPLS provider. The proposed solution must have a quick deployment, be affordable, be reliable, and work as a backup for the enterprise's primary MPLS connection. Which solution meets these requirements?

Options:

A.

Contract an internet connection and deploy DMVPN.

B.

Deploy BFD echo mode and probe provider PE

C.

Deploy an additional WAN router and use a floating static route

D.

Contract another MPLS provider and deploy GET VPN.

Buy Now
Questions 36

What is the purpose of a TLOC extension in a Cisco SD-WAN network fabric?

Options:

A.

to facilitate WAN Edge router redundancy within a site

B.

to identify the physical interface where a WAN Edge router connects to the WAN transport network

C.

to expand the number of colors that are potentially applied to a network transport interface

D.

to aggregate multiple physical interfaces into a single logical Interface

Buy Now
Questions 37

Which security functionality does gRPC provide?

Options:

A.

implementing secure server-client tunnels with RSA 20*8 cipher encryption

B.

mandatory encryption of data at rest using the AES and RSA protocols

C.

enabling RC6 data-level encryption with CRC check

D.

supporting secure communication between network devices and control systems using TLS

Buy Now
Questions 38

An enterprise customer has these requirements:

    end-to-end QoS for the business-critical applications and VoIP services based on CoS marking.

    flexibility to offer services such as IPv6 and multicast without any reliance on the service provider.

    support for full-mesh connectivity at Layer 2.

Which WAN connectivity option meets these requirements?

Options:

A.

VPWS

B.

MPLS VPN

C.

DMVPN

D.

VPLS

Buy Now
Questions 39

An engineer is designing a campus network with Cisco Catalyst 95CO switches in the aggression layer. The design requires running nonblocking Layer 2 MEC from the aggregation layer to the access layer. The Catalyst switches are located on different campus floors for availability reasons, and each access switch veil contam a single VLAN. Which technology must the engineer choose for the aggregation switches in the design?

Options:

A.

VPC

B.

VSS

C.

StackWise Virtual

D.

StackWise-180

Buy Now
Questions 40

At which layer does Cisco Express Forwarding use adjacency tables to populate addressing information?

Options:

A.

    Layer4

B.

    Layer 2

C.

    Layer 1

D.

    Layer 3

Buy Now
Questions 41

Refer to the exhibit. An engineer is designing an OSPF network for a client. Requirements dictate that the routers in Area 1 should receive all routes belonging to the network, including EIGRP, except the ones originated in the RIP domain. Which action should the engineer take?

Options:

A.

Make area 1 a NSSA.

B.

Make area 1 a stub.

C.

Make area 1 a standard OSPF area.

D.

Make the area 1 routers part of area 0.

Buy Now
Questions 42

What are two valid scaling techniques when an EIGRP network is designed that consists of more than 1000 routers? (Choose two.)

Options:

A.

Use structured hierarchical topology with route summarization

B.

Used sub-second timers

C.

Use the distribute-list command to filter routes

D.

Modify delay parameters on the links

E.

Implement multiple EIGRP autonomous systems

Buy Now
Questions 43

What is a benefit of using VRRPv3 as compared to VRRPv2?

Options:

A.

VRRPv3 supports IPv4 and IPv6

B.

VRRPv3 supports authentication

C.

VRRPv3 supports preemption

D.

VRRPv3 supports stateful switchover

Buy Now
Questions 44

A network engineer prepares a script to configure a loopback interface with IP address 172.16.15.12/32. To comply with the company security policies, 'Content-type':

‘application/yang-data+json‘ is added to the script. Connection to the network devices must be secured. Which code snippet must the network engineer use to meet this requirement?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 45

A large chain of stores currently uses MPLS-based T1 lines to connect their stores to their data center. An architect must design a new solution to improve availability and reduce costs while keeping these considerations in mind:

» The company uses multicast to deliver training to the stores.

» The company uses dynamic routing protocols and has implemented QoS.

» To simplify deployments, tunnels should be created dynamically on the hub when additional stores open.

Which solution should be included in this design?

Options:

A.

VPLS

B.

GET VPN

C.

DMVPN

D.

IPsec

Buy Now
Questions 46

What is the purpose of the fabric control plane in a Cisco SD-Access architecture?

Options:

A.

create, propagate, and enforce G6AC policies in the fabric

B.

create a transit node with BGP route reflector functionality

C.

extend multiple subnets to one RLOC

D.

create and resolve endpoint-to-location mapping

Buy Now
Questions 47

A company requested that an architect propose a new IPv4 and IPv6 deployment strategy. The company wants a solution that is straightforward, with no information hiding or forwarding overhead. Which solution meets these requirements?

Options:

A.

LISP

B.

NAT64

C.

dual-stack

D.

GRE tunnels

Buy Now
Questions 48

Refer to the exhibit. An engineer Is designing a redistribution solution for a customer. The customer recently acquired another company and decided to integrate the new network running RlPv1 with the company's existing network. Which redistribution technique must the engineer select to ensure the multipoint two-way redistribution does not cause routing loops?

Options:

A.

distribute-lists inbound under the EIGRP process denying RIPv1 learned prefixes

B.

distribute-lists outbound under the EIGRP process denying RIPv1 learned prefixes

C.

distribute-lists outbound under the RIPv1 process denying EIGRP learned prefixes

D.

distribute-lists inbound under the RIPv1 process denying EIGRP learned prefixes

Buy Now
Questions 49

Refer to the exhibit.

An architect is designing a network for a customer supporting a Wake-on-LAN application. Which solution must the architect choose?

Options:

A.

IP directed-broadcasts on R1

B.

spanning-tree uplinkfast on SW1

C.

spanning-tree uplinkfast on SW2

D.

IP directed-broadcasts on R2

Buy Now
Questions 50

An engineer must design an addressing plan for a small business using a single /24 network. Each department must have its own subnet. Drag and drop the subnets from the left onto the departments requirements that they fulfill on the right. Not all options are used.

Options:

Buy Now
Questions 51

Refer to the exhibit.

An engineer must optimize the traffic flow of the network. Which change provides a more

efficient design between the access and the distribution layer?

Options:

A.

Add a link between access switch A and access switch B

B.

Reconfigure the distribution switch A to become the HSRP Active

C.

Change the link between distribution switch A and distribution switch B to be a routed link

D.

Create an EtherChannel link between distribution switch A and distribution switch B

Buy Now
Questions 52

Refer to the exhibit.

The failover time of ISP-2 is significantly shorter than ISP-1 when an interface on the ISP router toward the campus network fails. Which solution minimizes the downtime to the sub-second?

Options:

A.

Aggressive timers

B.

Next-hop address tracking

C.

Graceful-restart

D.

BFD

Buy Now
Questions 53

An engineer is designing a Layer 3 campus network running EIGRP between the core, aggregation, and access layers. The access layer switches will be connected to the aggregation layer using Layer 3 copper connections. The engineer wants to improve convergence time for access layer switch failures. Which technique must the design include?

Options:

A.

enabling BFD for EIGRP on the access layer uplinks

B.

reducing the EIGRP Hello / Hold timer values

C.

EIGRP summarization from core to aggregation layer

D.

EIGRP summarization from access to aggregation layer

Buy Now
Questions 54

Drag and drop the elements from the left onto the functions they perform in the Cisco SD-WAN architecture on the right.

Options:

Buy Now
Questions 55

Drag and drop the description from the left onto the corresponding WAN connectivity types and categories on the right.

Options:

Buy Now
Questions 56

An engineer is designing a QoS solution for a customer The customer's internet connection has a bandwidth of 10 Mbps. The design must ensure that traffic bursts of data do not exceed the bandwidth of the connection and that received traffic does not starve out business-critical traffic Which solution must the engineer choose?

Options:

A.

Configure the queuing default queue for shaping inbound and policing outbound.

B.

Configure the queuing default queue for shaping inbound and policing inbound.

C.

Configure the queuing default queue for shaping outbound and policing inbound.

D.

Configure the queuing default queue for shaping outbound and policing outbound.

Buy Now
Questions 57

An architect must develop a campus network solution that includes:

logically segmented and isolated networks

ability to communicate between network segments when required

support for overlapping IP addresses

widely available technologies to avoid purchasing specialized equipment

Which solution must the architect select?

Options:

A.

VSS with IGP

B.

802.1Q with HSRP

C.

vPC with HSRP

D.

VRF-Lite with OSPF

Buy Now
Questions 58

An engineer working for a service provider with an employee ID 4598.48.606 prepared several designs for a traditional campus network. The design must allow the deployment on the same VXLAN to any switch at the access layer and must support:

    Fast convergence

    High availability

    Resilience

Which design must be selected?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 59

Which two best practices must be followed when designing an out-of-band management network? (Choose two.)

Options:

A.

    Enforce access control

B.

    Facilitate network integration

C.

    Back up data using the management network

D.

    Ensure that the management network is a backup to the data network

E.

    Ensure network isolation

Buy Now
Questions 60

Which component is part of the Cisco SD-Access overlay architecture?

Options:

A.

border node

B.

spine node

C.

leaf node

D.

Cisco DNA Center

Buy Now
Questions 61

A customer plans to deploy WoL in the enterprise with these high-level design requirements:

Which two solutions must the customer select to have a successful deployment? (Choose two.) 3 A. IP directed broadcast and forward-protocol must be enabled on all the SVI or routed interlaces where the client subnets reside.

B. IP helper-addresses for the client ranges must be enabled on the SVI or routed interface where the WoL server subnet resides.

C. IP helper-addresses for the client ranges must be disabled on the SVI or routed interface where the WoL server subnet resides

D. IP helper-addresses for the WoL server must be enabled on the SVI or routed interface where the client subnets reside

E. IP directed broadcast and forward-protocol must be disabled on all the SVI or routed interfaces where the client subnets reside.

Options:

A.

DHCP services must be available.

B.

Clients BIOS settings must be set for WoL.

C.

Clients get IP addresses once online.

D.

Spanning-tree PortFast is enabled on the Layer 2 switches.

Buy Now
Questions 62

Exhibit:

Refer to the exhibit. An engineer is designing a Layer 2 campus network. The design must support fast convergence and leverage as much bandwidth as possible between layers. Distribution switches do support VSS; unfortunately, not all routing protocols are available for use due to license limitations. Which solution must the engineer choose?

Options:

A.

EtherChannel

B.

MEC

C.

RSTP

D.

ECMP

Buy Now
Questions 63

Refer to the exhibit. An architect is developing a solution to consolidate networks while retaining device redundancy. The routing protocol for the WAN routers must be open standard, ensure high availability, and provide the fastest convergence time. Which solution must the design include?

Options:

A.

both routers running EIGRP

B.

one router running OSPFv2 and other OSPF v3

C.

one router running ISIS and other OSPF v3

D.

both routers running OSPFv2

Buy Now
Questions 64

Prior to establishing full-mesh iPsec tunnels in a typical Cisco SD-WAN deployment, which mechanism do WAN Edge routers use to exchange Key information for data plane encryption?

Options:

A.

They use vSmart controllers as key exchange servers.

B.

They use vManage as a key exchange server.

C.

They use IKEv2 when exchanging keys with each other.

D.

They use vBond as a key exchange server.

Buy Now
Questions 65

Refer to the exhibit. An architect must design a solution to connect the network behind R3 with the EIGRP network. Which mechanism should be included to avoid routing loops?

Options:

A.

split-horizon

B.

summarization

C.

down bit

D.

route tags

Buy Now
Questions 66

A company with multiple service providers wants to speed up BGP convergence time in the event a failure occurs with their primary link. Which approach achieves this goal and does not impact router CPU utilization?

Options:

A.

Utilize BFD and tune the multiplier to 50

B.

Lower the BGP hello interval

C.

Decrease the BGP keepalive timer

D.

Utilize BFD and keep the default BGP timers

Buy Now
Questions 67

Refer to the exhibits. An engineer is troubleshooting an issue in which the Gig0/2 interface on a Cisco switch named SW2 fails to become the root port. Which two commands must be run on SW2 to resolve this issue? (Choose two.)

A)

B)

C)

D)

E)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Buy Now
Questions 68

Refer to the exhibit.

An architect is designing a routing solution for a company. The new design will add a circuit routers C and D to protect against loss of connectivity to 10.0.4.0/24 during a link failure between routers B and D. Which solution must the architect choose?

Options:

A.

Stub connected

B.

Stub redistributed

C.

Stub receive-only

D.

Stub leak-map

Buy Now
Questions 69

A network engineer must connect two sites across a public network using a secure tunneling technology that

supports multicast traffic. Which technology must be chosen?

Options:

A.

IPsec

B.

GRE

C.

PPTP

D.

GRE over IPsec

Buy Now
Questions 70

What is the purpose of the fabric management plane in a Cisco SD-Access architecture?

Options:

A.

create LISP-based EID for the end-to-end solution that is offered by SD-Access

B.

enable EID-to-RLOC mapping that is based on the BGP protocol

C.

create an underlay network that is based on the IS-IS routing protocol

D.

enable automation techniques for device deployments and configurations

Buy Now
Questions 71

When designing interdomain multicast, which two protocols are deployed to achieve communication between multicast sources and receivers? (Choose two.)

Options:

A.

IGMPv2

B.

BIDIR-PIM

C.

MP-BGP

D.

MSDP

E.

MLD

Buy Now
Questions 72

Which feature minimizes TLOC connections and reduces strain on the vSmart controller in an SD-WAN architecture?

Options:

A.

control-direction

B.

affinity

C.

color

D.

control-connections

Buy Now
Questions 73

Refer to the exhibit. An architect must design a resilient gateway solution based on these requirements:

    VLAN 10 and VLAN 11 support voice and video applications.

    Link and node failures must have minimal impact on traffic.

    Provide protection against false hello packets.

    Support IPv6.

Which solution must the architect choose?

Options:

A.

GLBP with IP SLA tracking

B.

VRRP version 2 with authentication

C.

HSRP version 2 with MD5 authentication

D.

VRRP version 2 with object tracking

Buy Now
Questions 74

Refer to the exhibit. An engineer is designing an OSPF solution for a customer. The design must take into consideration:

    Application load balancers D. E. and F are in different geographical locations and are OSPF-enabled.

    Hosts A, B. and C connect to an application through the load balancers using IP address 10.1.1.1/32.

    In the event of a failure of one of the load balancers, hosts must still have access to the application.

Which solution must the engineer choose?

Options:

A.

All load balancers to be co-located in area 0.

B.

X, Y, and Z to be configured as different areas

C.

At least one load balancer to be in area 0.

D.

X, Y and Z to be configured as the same area

Buy Now
Questions 75

An existing network solution is using BFD in echo mode. Several of the network devices are experiencing high CPU utilization which an engineer has determined is related to the BFD feature. Which solution should the engineer leverage to reduce the CPU load?

Options:

A.

Implement slow timers between peers with low CPU resources.

B.

Implement BED asynchronous mode between peers with low CPU resources.

C.

Enable BFD multi-hop on the devices with low CPU resources.

D.

Utilize carrier delay on all routers in the network.

Buy Now
Questions 76

How are wireless endpoints registered in the HTDB in a Cisco SD-Access architecture?

Options:

A.

Fabric edge nodes update the HTDB based on CAPPWAP messaging from the AP

B.

Fabric WLCs update the HTDB as new clients connect to the wireless network

C.

Border nodes first register endpoints and then update the HTDB

D.

Fabric APs update the HTDB with the clients' ElD and RLOC

Buy Now
Questions 77

A network engineer is redesigning a company's QoS solution. The company is currently using IP Precedence, but the engineer plans to move to DiffServ. It is important that the new solution provide backward compatibility with the current solution. Which technology should the design include?

Options:

A.

expedited forwarding

B.

assured forwarding

C.

class selector code points

D.

default per hop behavior

Buy Now
Questions 78

Which consideration must be taken into account when using the DHCP relay feature in a Cisco SD-Access Architecture?

Options:

A.

DHCP-relay must be enabled on fabric edge nodes to provide the correct mapping of DHCP scope to the local anycast gateway.

B.

A DHCP server must be enabled on the border nodes to allow subnets to span multiple fabric edges.

C.

DHCP servers must support Cisco SD-Access extensions to correctly assign IPs to endpoints in an SD-Access fabric with anycast gateway.

D.

DHCP Option-82 must be enabled to map the circuit IP option to the access fabric node where the DHCP discover originated.

Buy Now
Questions 79

In a Cisco SD-Access fabric, switch node Is equivalent to an access layer switch In a traditional three-tier campus network design?

Options:

A.

edge node

B.

border node

C.

intermediate node

D.

control plane node

Buy Now
Questions 80

Which two overlay network design considerations must be made for a Cisco SD-Access network? (Choose two.)

Options:

A.

LAN automation for deployment

B.

Layer 3 to the access design

C.

Reduce subnets and simplify DHCP management

D.

Dedicated IGP process for the fabric

E.

Avoid overlapping IP subnets

Buy Now
Questions 81

Since installing a cisco TelePresence system, the company is experiencing other application having response issues when the system in use. As a result, the company asked an architect to recommend a QoS solution. The customer is currently using a CBWFQ policy to manage traffic on an internet connection with a speed of 100 Mbps. Which link-capacity limit must the architect choose for strict-priority for the real-time traffic?

Options:

A.

25 Mbps

B.

50 Mbps

C.

33 Mbps

D.

75 Mbps

Buy Now
Questions 82

Which type of rendezvous point deployment is standards-based and support dynamic RP discovery?

Options:

A.

Auto-RP

B.

Anycast-RP

C.

bootstrap router

D.

static RP

Buy Now
Questions 83

Refer to the exhibit. An architect must design a solution to connect the two ASs. To optimize bandwidth, the design will implement load sharing between router R6 and router R4. Which solution should the design include?

Options:

A.

Use update-source to specify the Loopback interface.

B.

Use next-hop-serf attributes only for routes that are learned from eBGP peers.

C.

Configure the eBGP TTL to support eBGP multihop.

D.

Use maximum-paths to install multiple paths in the routing table.

Buy Now
Questions 84

What is the role of a control-plane node in a Cisco SD-Access architecture?

Options:

A.

fabric device that connects wired endpoints to the SD-Access fabric

B.

map system that manages endpoint to device relationships

C.

fabric device that connects APs and wireless endpoints to the SD-Access fabric

D.

map system that manages External Layer 3 networks

Buy Now
Questions 85

An engineer is looking for a standards-driven YANG model to manage a multivendor network environment. Which model must the engineer choose?

Options:

A.

Native

B.

OpenConfig

C.

IETF

D.

IEEE NETCONF

Buy Now
Questions 86

Refer to the exhibit. An architect is designing an IPv4 plan using the 172.16.0.0/16. The design must maximize the number of subnets while meeting these requirements:

    500 hosts within the server room

    100 hosts at the remote site

    25 hosts at the access site

Which plan must the architect choose?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 87

A company wants to switch from static routing to a dynamic routing protocol to ease the administrative and operational overhead. The network topology is hub and spoke, and the branches use DM VPN back to the hub with two 10-Mbps internet connections. The branch routers are multivendor and have limited memory and CPU resources. Which routing protocol and design solution meets the requirements?

Options:

A.

eBGP with the hub routers set up as route reflectors

B.

ISIS with the hub and spoke routers configured in two different areas

C.

EIGRP with branch routers as stub routers and variance enabled

D.

OSPF with the hub in area 0 and branch routers in stub areas with ECMP

Buy Now
Questions 88

A company wants to switch from static to dynamic routing. The branches use DMVPN back to the hub using two internet connections. One internet connection speed is 10 Mbps, and the other is 100 Mbps. All locations use Cisco routers; however, the branch routers have limited memory and CPU resources. Which routing protocol and design solution must the company choose for optimal traffic forwarding during peak traffic times?

Options:

A.

iBGP with the hub routers set up as route reflectors

B.

OSPF deployed in area 0 with branch routers connected back via virtual links

C.

EIGRP with branch routers as stub routers and variance enabled

D.

ISIS with the hub and spoke routers configured in two different areas

Buy Now
Questions 89

A company's security policy requires that all connections between sites be encrypted in a manner that does not

require maintenance of permanent tunnels. The sites are connected through a private MPLS-based service that

uses a dynamically changing key and spoke-to-spoke communication. Which type of transport encryption must

be used in this environment?

Options:

A.

GETVPN

B.

DMVPN

C.

GRE VPN

D.

standard IPsec VPN

Buy Now
Questions 90

An architect must address sustained congestion on the access and distribution uplink of network. QoS has already been implemented and optimized, but it is no longer effective in ensuring optimal network performance. Which two solutions should the architect use to improver network performance? (Choose two)

Options:

A.

Reconfigure QoS based on the IntServ model

B.

Utilize random early detection to manage queues

C.

Implement higher-speed uplink interfaces

D.

Bundle additional uplinks into logical EtherChannels

E.

Configure selective packet discard to drop noncritical network traffic.

Buy Now
Questions 91

How is end-to-end microsegmentation enforced in a Cisco SD-Access architecture?

Options:

A.

VLANs are used to segment traffic at Layer 2.

B.

5-tuples and ACLs are used to permit or deny traffic.

C.

SGTs and SGTACLs are used to control access to various resources.

D.

VRFs are used to segment traffic at Layer 3.

Buy Now
Questions 92

Drag and drop the descriptions from the left onto the corresponding VPN types on the rights.

Options:

Buy Now
Questions 93

An engineer uses Postman and YANG to configure a router with:

    OSPF process ID 200

    network 172.16.10.128/26 enabled for Area 0

Which get-config reply verifies that the model set was designed correctly?

Options:

A.

Text, letter Description automatically generated

B.

Graphical user interface, text, letter, email Description automatically generated

C.

Text, letter Description automatically generated

D.

Text, letter Description automatically generated

Buy Now
Questions 94

When a network is designed using IS-IS protocol, which two circuit types are supported? (Choose two.)

Options:

A.

nonbroadcast multiaccess

B.

multiaccess

C.

point-to-multipoint

D.

nonbroadcast

E.

point-to-point

Buy Now
Questions 95

A company must automate a set of complex changes aligned with DR testing in the network. These changes are specific, and the DR playbook will be adjusted in the future. The playbook has diverse routing and switching assets in scope as well as multiple vendor and hardware platforms. A developer will create a thin, web front-end microservice and integrate with an Open daylight controller to push changes to the network. Which YANG model should be used?

Options:

A.

Use a single native vendor YANG model to minimize development time

B.

Use an open YANG model to allow the reuse of code and standardize the implementation across platforms

C.

Use multiple native vendor YANG models to provide code consistency.

D.

Develop an individualized YANG model to minimize development resources and time to market.

Buy Now
Questions 96

Which design achieves SD-WAN control plane redundancy?

Options:

A.

Configuring BFD on the WAN Edge routers

B.

Using multiple instances of vManage in clusters

C.

Deploying using a virtual platform like UCS or CSP

D.

Managing the underlay network with OMP

Buy Now
Questions 97

Which type of rendezvous point deployment is standards-based and supports dynamic RP discovery?

Options:

A.

bootstrap router

B.

Anycast-RP

C.

Auto-RP

D.

static RP

Buy Now
Questions 98

Which two options can you use to configure an EIGRP stub router? (Choose two)

Options:

A.

    summary-only

B.

    receive-only

C.

    external

D.

    summary

E.

    totally-stubby

F.

    not-so-stubby

Buy Now
Questions 99

An engineer must design a management network for a customer's enterprise network. The design must:

    provide the ability to grant and revoke access privileges

    allow only protocols SSH, NTP, FTP, and SNMP

    restrict access to management Interfaces

Which solution must the engineer choose to meet the requirements?

Options:

A.

in-band

B.

enterprise internal private

C.

out-of-band

D.

mGRE

Buy Now
Questions 100

Refer to the exhibit. An engineer must design an automatic failover solution. The solution should allow HSRP to detect a WAN 1 failure and initiate an automatic failover, making router R2 the active HSRP router. Which two solutions should the engineer choose? (Choose two.)

Options:

A.

Implement Enhanced Object Tracking on router R1

B.

use a floating static route

C.

Implement IP SLA on router R1

D.

Implement PBR on router R1

E.

use IP source routing

Buy Now
Questions 101

Which two functions does the control plane node provide in a Cisco SD-Access architecture? (Choose two.)

Options:

A.

LISP proxy ETR

B.

host tracking database

C.

policy mapping

D.

map server

E.

endpoint registration

Buy Now
Exam Code: 300-420
Exam Name: Designing Cisco Enterprise Networks (ENSLD)
Last Update: Aug 17, 2025
Questions: 339
300-420 pdf

300-420 PDF

$33.25  $94.99
300-420 Engine

300-420 Testing Engine

$38.5  $109.99
300-420 PDF + Engine

300-420 PDF + Testing Engine

$50.75  $144.99