Best Cisco 350-401 Exam Practice Material Updated on Feb 26, 2023
New 350-401 Actual Exam Dumps, Cisco Practice Test
NEW QUESTION 83
Refer to the exhibit.
An engineer is investigating why guest users are able to access other guest user devices when the users are connected to the customer guest WLAN. What action resolves this issue?
- A. implement P2P blocking
- B. implement MFP client protection
- C. implement Wi-Fi direct policy
- D. implement split tunneling
Answer: A
NEW QUESTION 84
Refer to the exhibit.
Which type of antenna do the radiation patterns present?
- A. Patch
- B. Dipole
- C. Yagi
- D. Omnidirectional
Answer: A
NEW QUESTION 85
What the role of a fusion in an SD-Access solution?
- A. provides additional forwarding capacity to the fabric
- B. performs route leaking between user-defined virtual networks and shared services
- C. acts as a DNS server
- D. provides connectivity to external networks
Answer: B
Explanation:
Today the Dynamic Network Architecture Software Defined Access (DNA-SDA) solution requires a
fusion router to perform VRF route leaking between user VRFs and Shared-Services, which may be
in the Global routing table (GRT) or another VRF. Shared Services may consist of DHCP, Domain
Name System (DNS), Network Time Protocol (NTP), Wireless LAN Controller (WLC), Identity
Services Engine (ISE), DNAC components which must be made available to other virtual networks
(VN's) in the Campus.
Reference:
213525-sda-steps-to-configure-fusion-router.html
NEW QUESTION 86
Drag and drop the tools from the left onto the agent types on the right.
Answer:
Explanation:
NEW QUESTION 87
Which cisco DNA center application is responsible for group-based accesss control permissions?
- A. Policy
- B. Assurance
- C. Provision
- D. Design
Answer: A
NEW QUESTION 88
What are two reasons why broadcast radiation is caused in the virtual machine environment? (Choose two.)
- A. Communication between vSwitch and network switch is multicast based.
- B. Communication between vSwitch and network switch is broadcast based.
- C. The Layer 2 domain can be large in virtual machine environments.
- D. Virtual machines communicate primarily through broadcast mode.
- E. vSwitch must interrupt the server CPU to process the broadcast packet.
Answer: C,D
Explanation:
Explanation
Broadcast radiation is the accumulation of broadcast and multicast traffic on a computer network. Extreme amounts of broadcast traffic constitute a broadcast storm.
The amount of broadcast traffic you should see within a broadcast domain is directly proportional to the size of the broadcast domain. Therefore if the layer 2 domain in virtual machine environment is too large, broadcast radiation may occur -> VLANs should be used to reduce broadcast radiation.
Also if virtual machines communicate via broadcast too much, broadcast
radiation may occur.
Another reason for broadcast radiation is using a trunk (to extend VLANs) from the network switch to the physical server.
Note about the structure of virtualization in a hypervisor:
Hypervisors provide virtual switch (vSwitch) that Virtual Machines (VMs) use to communicate with other VMs on the same host. The vSwitch may also be connected to the host's physical NIC to allow VMs to get layer 2 access to the outside world.
Each VM is provided with a virtual NIC (vNIC) that is connected to the
virtual switch. Multiple vNICs can connect to a single vSwitch, allowing VMs on a physical host to communicate with one another at layer 2 without having to go out to a physical switch.
Although vSwitch does not run Spanning-tree protocol but vSwitch
implements other loop prevention mechanisms. For example, a
frame that enters from one VMNIC is not going to go out of the
physical host from a different VMNIC card.
NEW QUESTION 89
Drag and drop the Qos mechanisms from the left to the correct descriptions on the right
Answer:
Explanation:

NEW QUESTION 90
How does EIGRP differ from OSPF?
- A. Option A
- B. Option C
- C. Option D
- D. Option B
Answer: D
NEW QUESTION 91
Drag and drop the characteristics from the left onto the routing protocols they describe on the right.
Answer:
Explanation:
NEW QUESTION 92
Which control plane protocol is used between Cisco SD-WAN routers and vSmart controllers?
- A. BGP
- B. OMP
- C. TCP
- D. UDP
Answer: B
Explanation:
Explanation
Cisco SD-WAN uses Overlay Management Protocol (OMP) which manages the overlay network. OMP runs between the vSmart controllers and WAN Edge routers (and among vSmarts themselves) where control plane information, such as the routing, policy, and management information, is exchanged over a secure connection.
NEW QUESTION 93
Drag and drop the characteristics from the left onto the protocols they apply to on the right?
Answer:
Explanation:
Explanation
Diagram Description automatically generated
NEW QUESTION 94
What are two benefits of virtualizing the server with the use of VMs in data center environment? (Choose two.)
- A. reduced rack space, power, and cooling requirements
- B. speedy deployment
- C. reduced IP and MAC address requirements
- D. smaller Layer 2 domain
- E. Increased security
Answer: A,B
NEW QUESTION 95
What is the difference between the enable password and the enable secret password when service password encryption is enabled on an IOS device?
- A. The enable secret password is protected via stronger cryptography mechanisms.
- B. The enable password is encrypted with a stronger encryption method.
- C. There is no difference and both passwords are encrypted identically.
- D. The enable password cannot be decrypted.
Answer: A
NEW QUESTION 96
Which configuration restricts the amount of SSH that a router accepts 100 kbps?
A)
B)
C)
D)
- A. Option A
- B. Option C
- C. Option D
- D. Option B
Answer: B
NEW QUESTION 97
In a Cisco Catalyst switch equipped with two supervisor modules an administrator must temporally remove the active supervisor from the chassis to perform hardware maintenance on it. Which mechanism ensure that the active supervisor removal is not disruptive to the network operation?
- A. VRRP
- B. NSF/NSR
- C. SSO
- D. HSRP
Answer: D
NEW QUESTION 98
Refer to the Exhibit.
An engineer is installing a new pair of routers in a redundant configuration. When checking on the standby status of each router the engineer notices that the routers are not functioning as expected. Which action will resolve the configuration error?
- A. configure matching hold and delay timers
- B. configure unique virtual IP addresses
- C. configure matching priority values
- D. configure matching key-strings
Answer: D
Explanation:
From the output exhibit, we notice that the key-string of R1 is -Cisco123! (letter -C is in capital) while that of R2 is -cisco123!. This causes a mismatch in the authentication so we have to fix their key-strings.
key-string [encryption-type] text-string: Configures the text string for the key. The text-string argument is alphanumeric, case-sensitive, and supports special characters.
NEW QUESTION 99
Refer to the exhibit.
What are two effect of this configuration? (Choose two.)
- A. Inside source addresses are translated to the 209.165.201.0/27 subnet.
- B. The 10.1.1.0/27 subnet is assigned as the inside local addresses.
- C. The 10.1.1.0/27 subnet is assigned as the inside global address range.
- D. It establishes a one-to-one NAT translation.
- E. The 209.165.201.0/27 subnet is assigned as the outside local address range.
Answer: A,B
NEW QUESTION 100
Refer to the exhibit.
An engineer must ensure that all traffic leaving AS 200 will choose Link 2 as an entry point. Assuming that all BGP neighbor relationships have been formed and that the attributes have not been changed on any of the routers, which configuration accomplish task?
- A. Option A
- B. Option C
- C. Option D
- D. Option B
Answer: A
Explanation:
Explanation
R3 advertises BGP updates to R1 with multiple AS 100 so R3 believes the path to reach AS 200 via R3 is farther than R2 so R3 will choose R2 to forward traffic to AS 200.
NEW QUESTION 101
Drag and drop the characteristics from the left onto the routing protocols they describe on the right.
Answer:
Explanation:
Explanation
Diagram Description automatically generated
NEW QUESTION 102
Drag and drop the virtual components from the left onto their deceptions on the right.
Answer:
Explanation:
NEW QUESTION 103
Drag the drop the description from the left onto the routing protocol they describe on the right.
Answer:
Explanation:
Explanation
Unlike OSPF where we can summarize only on ABR or ASBR, in EIGRP we can summarize anywhere. Manual summarization can be applied anywhere in EIGRP domain, on every router, on every interface via the ip summary-address eigrp asnumber address mask [administrative-distance summary-address eigrp 1 192.168.16.0 255.255.248.0). Summary route will exist in routing table as long as at least one more specific route will exist. If the last specific route will disappear, summary route also will fade out. The metric used by EIGRP manual summary route is the minimum metric of the specific routes.
NEW QUESTION 104
Refer to the exhibit.
Which statement about the OPSF debug output is true?
- A. The output displays all OSPF messages which router R1 has sent to received on interface Fa0/1.
- B. The output displays OSPF hello messages which router R1 has sent received on interface Fa0/1.
- C. The output displays OSPF hello and LSACK messages which router R1 has sent or received.
- D. The output displays all OSPF messages which router R1 has sent or received on all interfaces.
Answer: B
Explanation:
Explanation
This combination of commands is known as "Conditional debug" and will filter the debug output based on your conditions. Each condition added, will behave like an 'And' operator in Boolean logic. Some examples of the "debug ip ospf hello" are shown below:
NEW QUESTION 105
An engineer must configure interface GigabitEthernet0/0 for VRRP group 10. When the router has the highest priority in the group, it must assume the master role. Which command set must be added to the initial configuration to accomplish this task?
- A. vrrp 10 ip 172.16.13.254
vrrp 10 preempt - B. vrrp group 10 ip 172.16.13 254.255.255.255.0
vrrp group 10 priority 120 - C. standby 10 ip 172.16.13.254 255.255.255.0
standby 10 preempt - D. standby 10 ip 172.16.13.254
standby 10 priority 120
Answer: A
Explanation:
Explanation
In fact, VRRP has the preemption enabled by default so we don't need the vrrp 10 preempt command. The default priority is 100 so we don't need to configure it either. But notice that the correct command to configure the virtual IP address for the group is vrrp 10 ip {ip-address} (not vrrp group 10 ip ...) and this command does not include a subnet mask.
NEW QUESTION 106
Which action is the vSmart controller responsible for in a Cisco SD-WAN deployment?
- A. gather telemetry data from WAN Edge routers
- B. distribute policies that govern data forwarding performed within the Cisco SD-WAN fabric
- C. handle, maintain, and gather configuration and status for nodes within the Cisco SD-WAN fabric
- D. onboard WAN Edge nodes into the Cisco SD-WAN fabric
Answer: B
NEW QUESTION 107
What is the data policy in a Cisco SD-WAN deployment?
- A. list of ordered statements that define node configurations and authentication used within the SD-WAN overlay
- B. detailed database mapping several kinds of addresses with their corresponding location
- C. group of services tested to guarantee devices and links liveliness within the SD-WAN overlay
- D. Set of statements that defines how data is forwarded based on IP packet information and specific VPNs
Answer: D
NEW QUESTION 108
......
Study HIGH Quality 350-401 Free Study Guides and Exams Tutorials: https://examcompass.topexamcollection.com/350-401-vce-collection.html

