Latest Cisco 350-401 PDF and Dumps (2022) Free Exam Questions Answers [Q75-Q92]

Share

Latest Cisco 350-401 PDF and Dumps (2022) Free Exam Questions Answers

Pass Your CCNP Enterprise 350-401 Exam on Jan 24, 2022 with 305 Questions


Further Certification Path After Passing 350-401

The Cisco 350-401 ENCOR certification exam is the starting point for different certifications. If you want to go further than being a certified Specialist for Enterprise Core, then you should know that it is also a core exam for the CCNP Enterprise certificate. From here, you will need to take a concentration test to get accredited.

If CCNP accreditation is not the final target point for you, then use Cisco 350-401 ENCOR as the qualifying exam to obtain CCIE Enterprise Infrastructure or Enterprise Wireless accreditation. These will require you to ace one more test as well.

 

NEW QUESTION 75
Drag and drop the REST API authentication method from the left to the description on the right.

Answer:

Explanation:

Explanation

 

NEW QUESTION 76
Refer to the exhibit.

An engineer must ensure that all traffic leaving AS 200 will choose Link 2 as an entry point. Assuming that all BGP neighbor relationships have been formed and that the attributes have not been changed on any of the routers, which configuration accomplish task?

  • A. Option D
  • B. Option B
  • C. Option A
  • D. Option C

Answer: C

 

NEW QUESTION 77
Refer to the exhibit.

An engineer reconfigures the pot-channel between SW1 and SW2 from an access port to a trunk and immediately notices this error in SW1's log.
Which command set resolves this error?

  • A. Option D
  • B. Option A
  • C. Option C
  • D. Option B

Answer: D

 

NEW QUESTION 78
Which DNS lookup does an access point perform when attempting CAPWAP discovery?

  • A. CISCO-CONTROLLER.local
  • B. CISCO-DNA-CONTROLLER.local
  • C. CAPWAP-CONTROLLER.local
  • D. CISCO-CAPWAP-CONTROLLER.local

Answer: D

Explanation:
Explanation/Reference: http://www.revolutionwifi.net/revolutionwifi/2010/11/capwap-controller-discovery-process_23.html

 

NEW QUESTION 79
Refer to the exhibit.

Which IPv6 OSPF network type is applied to interface Fa0/0 of R2
by default?

  • A. broadcast
  • B. Ethernet
  • C. point-to-point
  • D. multipoint

Answer: A

Explanation:
Explanation
The Broadcast network type is the default for an OSPF enabled ethernet interface (while Point-to- Point is the default OSPF network type for Serial interface with HDLC and PPP encapsulation).
Reference: https://www.oreilly.com/library/view/cisco-ios-cookbook/0596527225/ch08s15.html

 

NEW QUESTION 80
Which statement about a fabric access point is true?

  • A. It is in local mode and must connected directly to the fabric edge switch.
  • B. It is in local mode an must be connected directly to the fabric border node.
  • C. It is in FlexConnect mode and must be connected directly to the fabric edge switch.
  • D. It is in FlexConnect mode and must be connected directly to the fabric border node.

Answer: A

 

NEW QUESTION 81
Drag and drop the threat defense solutions from the left onto their descriptions on the right.

Answer:

Explanation:

Explanation

 

NEW QUESTION 82
Refer to the exhibit.

Which configuration establishes EBGP neighborship between these two directly connected neighbors and exchanges the loopback network of the two routers through BGP?
A)

B)

C)

D)

  • A. Option D
  • B. Option B
  • C. Option A
  • D. Option C

Answer: C

Explanation:
Explanation
With BGP, we must advertise the correct network and subnet mask in the "network" command (in this case network 10.1.1.0/24 on R1 and network 10.2.2.0/24 on R2). BGP is very strict in the routing advertisements. In other words, BGP only advertises the network which exists exactly in the routing table. In this case, if you put the command "network x.x.0.0 mask 255.255.0.0" or
"network x.0.0.0 mask 255.0.0.0" or "network x.x.x.x mask 255.255.255.255" then BGP will not advertise anything.
It is easy to establish eBGP neighborship via the direct link. But let's see what are required when we want to establish eBGP neighborship via their loopback interfaces. We will need two commands:
+ the command "neighbor 10.1.1.1 ebgp-multihop 2" on R1 and "neighbor 10.2.2.2 ebgpmultihop
2" on R1. This command increases the TTL value to 2 so that BGP updates can reach the BGP neighbor which is two hops away.
+ Answer 'R1 (config) #router bgp 1
R1 (config-router) #neighbor 192.168.10.2 remote-as 2
R1 (config-router) #network 10.1.1.0 mask 255.255.255.0
R2 (config) #router bgp 2
R2 (config-router) #neighbor 192.168.10.1 remote-as 1
R2 (config-router) #network 10.2.2.0 mask 255.255.255.0
Quick Wireless Summary
Cisco Access Points (APs) can operate in one of two modes: autonomous or lightweight
+ Autonomous: self-sufficient and standalone. Used for small wireless networks.
+ Lightweight: A Cisco lightweight AP (LAP) has to join a Wireless LAN Controller (WLC) to function.
LAP and WLC communicate with each other via a logical pair of CAPWAP tunnels.
- Control and Provisioning for Wireless Access Point (CAPWAP) is an IETF standard for control messaging for setup, authentication and operations between APs and WLCs. CAPWAP is similar to LWAPP except the following differences:
+CAPWAP uses Datagram Transport Layer Security (DTLS) for authentication and encryption to protect traffic between APs and controllers. LWAPP uses AES.
+ CAPWAP has a dynamic maximum transmission unit (MTU) discovery mechanism.
+ CAPWAP runs on UDP ports 5246 (control messages) and 5247 (data messages) An LAP operates in one of six different modes:
+ Local mode (default mode): measures noise floor and interference, and scans for intrusion detection (IDS) events every 180 seconds on unused channels
+ FlexConnect, formerly known as Hybrid Remote Edge AP (H-REAP), mode: allows data traffic to be switched locally and not go back to the controller. The FlexConnect AP can perform standalone client authentication and switch VLAN traffic locally even when it's disconnected to the WLC (Local Switched). FlexConnect AP can also tunnel (via CAPWAP) both user wireless data and control traffic to a centralized WLC (Central Switched).
+ Monitor mode: does not handle data traffic between clients and the infrastructure. It acts like a sensor for location-based services (LBS), rogue AP detection, and IDS
+ Rogue detector mode: monitor for rogue APs. It does not handle data at all.
+ Sniffer mode: run as a sniffer and captures and forwards all the packets on a particular channel to a remote machine where you can use protocol analysis tool (Wireshark, Airopeek, etc) to review the packets and diagnose issues. Strictly used for troubleshooting purposes.
+ Bridge mode: bridge together the WLAN and the wired infrastructure together.
Mobility Express is the ability to use an access point (AP) as a controller instead of a real WLAN controller. But this solution is only suitable for small to midsize, or multi-site branch locations where you might not want to invest in a dedicated WLC. A Mobility Express WLC can support up to 100 Aps

 

NEW QUESTION 83
Which statement about VXLAN is true?

  • A. VXLAN uses TCP 35 the transport protocol over the physical data cento network
  • B. VXLAN extends the Layer 2 Segment ID field to 24-bits. which allows up to 4094 unique Layer 2 segments over the same network.
  • C. VXLAN encapsulates a Layer 2 frame in an IP-UDP header, which allows Layer 2 adjacency across router boundaries.
  • D. VXLAN uses the Spanning Tree Protocol for loop prevention.

Answer: C

Explanation:
Explanation
802.1Q VLAN identifier space is only 12 bits. The VXLAN identifier space is 24 bits.
This doubling in size allows the VXLAN ID space to support 16 million Layer 2 segments -> Answer 'VXLAN extends the Layer 2 Segment ID field to 24-bits, which allows up to 4094 unique Layer 2 segments over the same network' is not correct.
VXLAN is a MAC-in-UDP encapsulation method that is used in order to extend a Layer 2 or Layer 3 overlay network over a Layer 3 infrastructure that already exists.
Reference: https://www.cisco.com/c/en/us/support/docs/lan-switching/vlan/212682-virtualextensible-lan-and-ethernet-virt.html

 

NEW QUESTION 84
Drag and drop the LISP components from the left onto the function they perform on the right. Not all options are used.

Answer:

Explanation:

Explanation

+ accepts LISP encapsulated map requests: LISP map resolver
+ learns of EID prefix mapping entries from an ETR: LISP map server
+ receives traffic from LISP sites and sends it to non-LISP sites: LISP proxy ETR
+ receives packets from site-facing interfaces: LISP ITR
Explanation
ITR is the function that maps the destination EID to a destination RLOC and then encapsulates the original packet with an additional header that has the source IP address of the ITR RLOC and the destination IP address of the RLOC of an Egress Tunnel Router (ETR).
After the encapsulation, the original packet become a LISP packet.
ETR is the function that receives LISP encapsulated packets, decapsulates them and forwards to its local EIDs. This function also requires EID-to-RLOC mappings so we need to point out an "map-server" IP address and the key (password) for authentication.
A LISP proxy ETR (PETR) implements ETR functions on behalf of non-LISP sites. A PETR is typically used when a LISP site needs to send traffic to non-LISP sites but the LISP site is connected through a service provider that does not accept no routable EIDs as packet sources. PETRs act just like ETRs but for EIDs that send traffic to destinations at non-LISP sites.
Map Server (MS) processes the registration of authentication keys and EID-to-RLOC mappings. ETRs sends periodic Map-Register messages to all its configured Map Servers.
Map Resolver (MR): a LISP component which accepts LISP Encapsulated Map Requests, typically from an ITR, quickly determines whether or not the destination IP address is part of the EID namespace

 

NEW QUESTION 85
Which LISP infrastructure device provides connectivity between non-sites and LISP sites by receiving non-LISP traffic with a LISP site destination?

  • A. map server
  • B. map resolver
  • C. PITR
  • D. PETR

Answer: C

Explanation:
Proxy ingress tunnel router (PITR): answer 'PETR' PITR is an infrastructure LISP network entity
that receives packets from non-LISP sites and encapsulates the packets to LISP sites or natively
forwards them to non-LISP sites.

 

NEW QUESTION 86
How is MSDP used to interconnect multiple PIM-SM domains?

  • A. MSDP SA request messages are used to request a list of active sources for a specific group
  • B. MSDP depends on BGP or multiprotocol BGP for mterdomam operation
  • C. MSDP messages are used to advertise active sources in a domain
  • D. SDP allows a rendezvous point to dynamically discover active sources outside of its domain

Answer: B

 

NEW QUESTION 87
Refer to the exhibit.

Which command set must be added to the configuration to analyze 50 packets out of every 100?

  • A. Option D
  • B. Option B
  • C. Option A
  • D. Option C

Answer: A

 

NEW QUESTION 88
Refer to the exhibit.

Which type of antenna is show on the radiation patterns?

  • A. Patch
  • B. Dipole
  • C. Yagi
  • D. Omnidirectional

Answer: B

 

NEW QUESTION 89
Drag and drop the DHCP messages that are exchanged between a client and an AP into the order they are exchanged on the right.

There are four messages sent between the DHCP Client and DHCP Server: DHCPDISCOVER, DHCPOFFER, DHCPREQUEST and DHCPACKNOWLEDGEMENT.
This process is often abbreviated as DORA (for Discover, Offer, Request, Acknowledgement).

Answer:

Explanation:

 

NEW QUESTION 90
Which statement explains why Type 1 hypervisor is considered more efficient than Type 2 hypervisor?

  • A. Type 1 hypervisor relics on the existing OS of the host machine to access CPU, memory, storage, and network resources.
  • B. Type 1 hypervisor is the only type of hypervisor that supports hardware acceleration techniques.
  • C. Type 1 hypervisor enables other operating systems to run on it.
  • D. Type 1 hypervisor runs directly on the physical hardware of the host machine without relying on the underlying OS.

Answer: D

Explanation:
Explanation
There are two types of hypervisors: type 1 and type 2 hypervisor.
In type 1 hypervisor (or native hypervisor), the hypervisor is installed directly on the physical server. Then instances of an operating system (OS) are installed on the hypervisor. Type 1 hypervisor has direct access to the hardware resources. Therefore they are more efficient than hosted architectures. Some examples of type 1 hypervisor are VMware vSphere/ESXi, Oracle VM Server, KVM and Microsoft Hyper-V.
In contrast to type 1 hypervisor, a type 2 hypervisor (or hosted hypervisor) runs on top of an operating system and not the physical hardware directly. answer 'Type 1 hypervisor runs directly on the physical hardware of the host machine without relying on the underlying OS' big advantage of Type 2 hypervisors is that management console software is not required. Examples of type 2 hypervisor are VMware Workstation (which can run on Windows, Mac and Linux) or Microsoft Virtual PC (only runs on Windows).

 

NEW QUESTION 91
Refer to the exhibit.

A network engineer must simplify the IPsec configuration by enabling IPsec over GRE using IPsec profiles. Which two configuration changes accomplish this? (Choose two).

  • A. Apply the crypto map to the tunnel interface and change the tunnel mode to tunnel mode ipsec ipv4.
  • B. Remove all configuration related to crypto map from R1 and R2 and eliminate the ACL |>]
  • C. Create an IPsec profile, associate the transform-set. and apply the profile to the tunnel interface.
  • D. Remove the crypto map and modify the ACL to allow traffic between 10.10.0.0/24 to 10.20.0.0/24.
  • E. Create an IPsec profile, associate the transform-set ACL. and apply the profile to the tunnel interface

Answer: A,E

 

NEW QUESTION 92
......

350-401 Dumps for CCNP Enterprise Certified Exam Questions & Answer: https://www.realexamfree.com/350-401-real-exam-dumps.html

350-401 Free Exam Study Guide! (Updated 305 Questions): https://drive.google.com/open?id=1jLPJ_ixjNbF5SCSG7RBygos9c92dE0Fg