Question 1:

Refer to the exhibit. P3 and PE4 are at the edge of the service provider core and serve as ABR routers. Aggregation areas are on either side of the core. Which statement about the architecture is true?

A. To support seamless MPLS, the BGP route reflector feature must be disabled.

B. If each area is running its own IGP, BGP must provide an end-to-end MPLS LSP.

C. If each area is running its own IGP, the ABR routers must redistribute the IGP routing table into BGP.

D. To support seamless MPLS, TDP must be used as the label protocol.

Correct Answer: B

Reference: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9600/software/release/16-12/configuration_guide/mpls/b_1612_mpls_9600_cg/configuring_seamless_mpls.html

Question 2:

Which component is similar to an EVPN instance?

A. router distinguisher

B. MPLS label

C. IGP router ID


Correct Answer: D

Question 3:

Why do Cisco MPLS TE tunnels require a link-state routing protocol?

A. The link-state database provides segmentation by area, which improves the path-selection process.

B. The link-state database provides a data repository from which the tunnel endpoints can dynamically select a source ID.

C. Link-state routing protocols use SPF calculations that the tunnel endpoints leverage to implement the tunnel.

D. The tunnel endpoints use the link-state database to evaluate the entire topology and determine the best path.

Correct Answer: D

Question 4:

Refer to the exhibit. BGPsec is implemented on R1, R2, R3, and R4. BGP peering is established between neighboring autonomous systems.

Which statement about implementation is true?

A. BGP updates from the iBGP peers are appended with a community of local-as.

B. BGP updates from the all BGP peers are appended with a community of no-export.

C. BGP updates from the eBGP peers are appended with an additional AS path value that is statically set by the domain administrator.

D. BGP updates from the eBGP peers are appended with a BGPsec attribute sequence that includes a public key hash and digital signature.

Correct Answer: D

Question 5:

You are configuring MPLS traffic-engineering tunnels in the core. Which two ways exist for the tunnel path across the core? (Choose two.)

A. The dynamic path option is supported only with IS-IS.

B. Tunnels can be configured with dynamic path or explicitly defined path.

C. A zero bandwidth tunnel is not a valid option.

D. The bandwidth statement creates a “hard” reservation on the link.

E. Tunnel links inherit IGP metrics by default unless overridden.

Correct Answer: BE

Question 6:

Which statement about the Cisco MPLS TE forwarding adjacency feature is true?

A. It enables the MPLS core to use EIGRP as the routing protocol.

B. It enables the Cisco MPLS TE tunnel to be advertised into the running IGP.

C. It enables the tailend router to advertise routes to the headend router over the tunnel.

D. It enables the headend and tailend routers to establish a bidirectional tunnel.

Correct Answer: B

Reference: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/mp_te_path_setup/configuration/xe-16/mp-te-path-setup-xe-16-book/mpls-traffic-engineering-forwarding-adjacency.pdf

Question 7:

While implementing TTL security, you issue the PE(config-router-af)#neighbor ttl-security hops 2 command. After you issue this command, which BGP packets does the PE accept?

A. to, with a TTL of 2 or more

B. from, with a TTL of less than 2

C. to, with a TTL of less than 253

D. from, with a TTL of 253 or more

Correct Answer: D

Reference: https://www.cisco.com/c/en/us/td/docs/ios/12_2sx/feature/guide/fsxebtsh.html#wp1059215

Question 8:

Refer to the exhibits. Which information is provided for traceback analysis when this configuration is applied?

A. source interface

B. packet size distribution

C. IP sub flow cache

D. BGP version

Correct Answer: C

Question 9:

Refer to the exhibit. R1 is connected to two service providers and is under a DDoS attack.

Which statement about this design is true if URPF in strict mode is configured on both interfaces?

A. R1 drops all traffic that ingresses either interface that has a FIB entry that exits a different interface.

B. R1 drops destination addresses that are routed to a null interface on the router.

C. R1 permits asymmetric routing as long as the AS-PATH attribute entry matches the connected AS.

D. R1 accepts source addresses on interface gigabitethernet0/1 that are private addresses.

Correct Answer: A

Question 10:

Refer to the exhibit. Router 1 was experiencing a DDoS attack that was traced to interface gigabitethernet0/1. Which statement about this configuration is true?

A. Router 1 accepts all traffic that ingresses and egresses interface gigabitethernet0/1.

B. Router 1 drops all traffic that ingresses interface gigabitethernet0/1 that has a FIB entry that exits a different interface.

C. Router 1 accepts source addresses that have a match in the FIB that indicates it is reachable through a real interface.

D. Router 1 accepts source addresses on interface gigabitethernet0/1 that are private addresses.

Correct Answer: C

Reference: https://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/4_1/nx-os/security/configuration/guide/sec_nx-os-cfg/sec_urpf.html

Question 11:

Refer to the exhibit. An engineer is preparing to implement data plane security configuration. Which statement about this configuration is true?

A. Router 2 is the router receiving the DDoS attack.

B. Router 1 must be configured with uRPF for the RTBH implementation to be effective.

C. Router 1 is the trigger router in a RTBH implementation.

D. Router 2 must configure a route to null 0 for network for the RTBH implementation to be complete.

Correct Answer: D

Question 12:

Which additional feature does MPLS DiffServ tunneling support?

A. matching EXP and DSCP values

B. PHB layer management

C. using GRE tunnels to hide markings

D. interaction between MPLS and IGP

Correct Answer: B

Reference: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/mp_te_diffserv/configuration/15-mt/mp-te-diffserv-15-mt-book/mp-diffserv-tun-mode.html

Question 13:

You are creating new Cisco MPLS TE tunnels. Which type of RSVP message does the headend router send to reserve bandwidth on the path to the tailend router?

A. path

B. tear

C. error

D. reservation

Correct Answer: A

Reference: https://packetpushers.net/rsvp-te-protocol-deep-dive/

Question 14:

Which statement describes the advantage of a Multi-Layer control plane?

A. It provides multivendor configuration capabilities for Layer 3 to Layer 1.

B. It automatically provisions, monitors, and manages traffic across Layer 0 to Layer 3.

C. It supports dynamic wavelength restoration in Layer 0.

D. It minimizes human error configuring converged networks.

Correct Answer: C

Question 15:

An engineer is setting up overlapping VPNs to allow VRF ABC and XYZ to communicate with VRF CENTRAL but wants to make sure that VRF ABC and XYZ cannot communicate. Which configuration accomplishes these objectives?

A. Option A

B. Option B

C. Option C

D. Option D

Correct Answer: B

