Updated Mar-2025 300-410 Exam Practice Test Questions [Q310-Q335] | TestBraindump

Updated Mar-2025 300-410 Exam Practice Test Questions [Q310-Q335]

Share

Updated Mar-2025 300-410 Exam Practice Test Questions

Verified 300-410 dumps Q&As 100% Pass in First Attempt Guaranteed Updated Dump

NEW QUESTION # 310


Refer to the exhibit. The IT router has been configured with the Science VRF and the interfaces have been assigned to the VRF. Which set of configurations advertises Science-1 and Science-2 routes using EIGRPAS
111?

  • A. Option A
  • B. Option C
  • C. Option D
  • D. Option B

Answer: C


NEW QUESTION # 311
Refer to the exhibit.

An administrator configured a Cisco router for TACACS authentication, but the router is using the local enable password instead Which action resolves the issue?

  • A. Option A
  • B. Option C
  • C. Option D
  • D. Option B

Answer: B


NEW QUESTION # 312
Drag and drop the packet types from the left onto the correct descriptions on the right.

Answer:

Explanation:


NEW QUESTION # 313
A network administrator is trying to access a branch router using TACACS+ username and password credentials, but the administrator cannot log in to the router because the WAN connectivity is down. The branch router has following AAA configuration:

Which command will resolve this problem when WAN connectivity is down?

  • A. aaa authentication login console group tacacs+ enable
  • B. aaa authentication login default group tacacs+ console
  • C. aaa authentication login default group tacacs+ local
  • D. aaa authentication login default group tacacs+ enable

Answer: C


NEW QUESTION # 314
Refer to the exhibit.

A network administrator logs into the router using TACACS+ username and password credentials, but the administrator cannot run any privileged commands Which action resolves the issue?

  • A. Configure TACACS+ synchronization with the Active Directory admin group
  • B. Configure an authorized IP address for this user to access this router
  • C. Configure the username from a local database
  • D. Configure full access for the username from TACACS+ server

Answer: D


NEW QUESTION # 315
While troubleshooting connectivity issues to a router, these details are noticed:
* Standard pings to all router interfaces, including loopbacks, are successful.
* Data traffic is unaffected.
* SNMP connectivity is intermittent.
* SSH is either or disconnects frequently.
Which command must be configured first to troubleshoot this issue?

  • A. Show policy-map
  • B. Show interface inc drop
  • C. Show policy-map control-plane
  • D. Show ip route

Answer: C


NEW QUESTION # 316

Refer to the exhibit. an engineer is trying to get 192.168.32.100 forwarded through 10.1.1.1, but it was forwarded through 10.1.1.2. What action forwards the packets through 10.1.1.1?

  • A. Configure EIGRP to receive 192.168.32.0 route with lower admin distance.
  • B. Configure EIGRP to receive 192.168.32.0 route with lower metric.
  • C. Configure EIGRP to receive 192.168.32.0 route with longer prefix than /19.
  • D. Configure EIGRP to receive 192.168.32.0 route with equal or longer prefix than /24.

Answer: D


NEW QUESTION # 317
Refer to the exhibit.

Refer to the exhibit. An engineer configured route exchange between two different companies for a migration project EIGRP routes were learned in router C but no OSPF routes were learned in router A.
Which configuration allows router A to receive OSPF routes?

  • A. Option A
  • B. Option C
  • C. Option D
    .
  • D. Option B

Answer: D


NEW QUESTION # 318
Which statement about IPv6 RA Guard is true?

  • A. Packets that are dropped by IPv6 RA Guard cannot be spanned.
  • B. It cannot be configured on a switch port interface in the ingress direction.
  • C. It does not offer protection in environments where IPv6 traffic is tunneled
  • D. It is not supported in hardware when TCAM is programmed.

Answer: C

Explanation:
Restrictions for IPv6 RA Guard
+ The IPv6 RA Guard feature does not offer protection in environments where IPv6 traffic is tunneled.
+ This feature is supported only in hardware when the ternary content addressable memory (TCAM) is programmed.
+ This feature can be configured on a switch port interface in the ingress direction.
+ This feature supports host mode and router mode.
+ This feature is supported only in the ingress direction; it is not supported in the egress direction.
+ This feature is not supported on EtherChannel and EtherChannel port members.
+ This feature is not supported on trunk ports with merge mode.
+ This feature is supported on auxiliary VLANs and private VLANs (PVLANs). In the case of PVLANs, primary VLAN features are inherited and merged with port features.
+ Packets dropped by the IPv6 RA Guard feature can be spanned.
+ If the platform ipv6 acl icmp optimize neighbor-discovery command is configured, the IPv6 RA Guard feature cannot be configured and an error message will be displayed. This command adds default global Internet Control Message Protocol (ICMP) entries that will override the RA guard ICMP entries.
Reference: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-3s/ip6f- xe-3s-book/ip6-ra-guard.html


NEW QUESTION # 319
Refer to the exhibit. The network administrator configured the Chicago router to mutually redistribute the LA and NewYork routes with OSPF routes to be summarized as a single route in EIGRP using the longest summary mask:

router eigrp 100
redistribute ospf 1 metric 10 10 10 10 10
router ospf 1 redistribute eigrp 100 subnets
!
interface E 0/0
ip summary-address eigrp 100 172.16.0.0 255.255.0.0
After the configuration, the New York router receives all the specific LA routes but the summary route.
Which set of configurations resolves the issue on the Chicago router?

  • A. interface E 0/1
    ip summary-address eigrp 100 172.16.0.0 255.255.0.0
  • B. router eigrp 100
    summary-address 172.16.8.0 255.255.252.0
  • C. router eigrp 100
    summary-address 172.16.0.0 255.255.0.0
  • D. interface E 0/1
    ip summary-address eigrp 100 172.16.8.0 255.255.252.0

Answer: D


NEW QUESTION # 320
Refer to the exhibit.

An engineer must configure DMVPN Phase 3 hub-and-spoke topology to enable a spoke-to-spoke tunnel.
Which NHRP configuration meets the requirement on R6?

  • A. Option A
  • B. Option C
  • C. Option D
  • D. Option B

Answer: D


NEW QUESTION # 321
Refer to the exhibit.

After a security audit, the administrator implemented an ACL in the route reflector. The RR became unreachable from any router in the network. Which two actions resolve the issue? (Choose two.)

  • A. Permit ICMPv6 neighbor discovery traffic in the ACL.
  • B. Enable the ND proxy feature on the default gateway.
  • C. Configure a link-local address on the Ethernet0/1 interface.
  • D. Remove the ACL entry 80.
  • E. Change the next hop of the default route to the link-local address of the default gateway.

Answer: A,C


NEW QUESTION # 322
Which method changes the forwarding decision that a router makes first changing the routing table or influencing the IP data plane?

  • A. Policy-based routing
  • B. Nonbroadcast multi-access
  • C. Forwarding information base
  • D. Packet switching

Answer: C


NEW QUESTION # 323
Refer to the exhibit.

An engineer is trying to generate a summary route in OSPF for network 10.0.0.0/8, but the summary route does not show up in the routing table. Why is the summary route missing?

  • A. The summary route is not visible on this router, but it is visible on other OSPF routers in the same area.
  • B. The summary route is visible only in the OSPF database, not in the routing table.
  • C. The summary-address command is used only for summarizing prefixes between areas.
  • D. There is no route for a subnet inside 10.0.0.0/8, so the summary route is not generated.

Answer: D

Explanation:
Explanation
The summary-address is only used to create aggregate addresses for OSPF at an autonomous system boundary.
It means this command should only be used on the ASBR when you are trying to summarize externally redistributed routes from another protocol domain or you have a NSSA area. But a requirement to create a summarized route is:
The ASBR compares the summary route's range of addresses with all routes redistributed into OSPF on that ASBR to find any subordinate subnets (subnets that sit inside the summary route range). If at least one subordinate subnet exists, the ASBR advertises the summary route.


NEW QUESTION # 324
Drag and drop the MPLS concepts from the left onto the descriptions on the right.

Answer:

Explanation:

Explanation:
+ allows an LSR to remove the label before forwarding the packet: penultimate hop popping
+ accepts unlabeled packets and imposes labels: label edge router
+ group of packets that are forwarded in the same manner: forwarding equivalence class
+ receives labeled packets and swaps labels: label switch router
Explanation:
A label edge router (LER, also known as edge LSR) is a router that operates at the edge of an MPLS network and acts as the entry and exit points for the network. LERspush an MPLS label onto an incoming packet and pop it off an outgoing packet.
A forwarding equivalence class (FEC) is a term


NEW QUESTION # 325

Refer to the exhibit. A network engineer cannot remote access R3 using Telnet from switch S1. Which action resolves the issue?

  • A. Allow the inbound connection via the exec command on R3.
  • B. Add the login admin command on the switch.
  • C. Add the transport input telnet command on R3.
  • D. Allow to use the ssh -I admin 10.0.0.1 command on the switch.

Answer: A


NEW QUESTION # 326
Refer to the exhibit.

What is the result of applying this configuration?

  • A. The router can form BGP neighborships with any device that is matched by the access list named
    "BGP".
  • B. The router cannot form BGP neighborships with any device that is matched by the access list named
    "BGP".
  • C. The router can form BGP neighborships with any other device.
  • D. The router cannot form BGP neighborships with any other device.

Answer: B


NEW QUESTION # 327
Refer to the exhibit.

The security department recently installed a monitoring device between routers R3 and R5, which a loss of network connectivity for users connected to R5. Troubleshooting revealed that the monitoring device cannot forward multicast packets. The team already updated R5 with the correct configuration. Which configuration must be implemented on R3 to resolve the problem by ensuring R3 as the DR for the R3-R5 segment?
A)

B)

C)

D)

  • A. Option A
  • B. Option C
  • C. Option D
  • D. Option B

Answer: B


NEW QUESTION # 328
A customer reports to the support desk that they cannot pnnt from their PC to the local printer id:401987778. Which tool must be used to diagnose the issue using Cisco DNA Center Assurance?

  • A. path trace
  • B. device trace
  • C. ACL trace
  • D. application trace

Answer: A


NEW QUESTION # 329
Refer to the exhibit.

Refer to the exhibit. A network administrator configured mutual redistribution on R1 and R2 routers, which caused instability in the network. Which action resolves the issue?

  • A. Advertise summary routes of EIGRP to OSPF and deny specific EIGRP routes when redistributing into OSPF.
  • B. Set a tag in the route map when redistributing EIGRP into OSPF on R1. and match the same tag on R2 to deny when redistributing OSPF into EIGRP.
  • C. Set a tag in the route map when redistributing EIGRP into OSPF on R1. and match the same tag on R2 to allow when redistributing OSPF into EIGRP.
  • D. Apply a prefix list of EIGRP network routes in OSPF domain on R1 to propagate back into the EIGRP routing domain.

Answer: B

Explanation:
When doing mutual redistribution at multiple points (between OSPF and EIGRP on R1 & R2), we may create routing loops so we should use route-map to prevent redistributed routes from redistributing again into the original domain.
In the below example, the route-map "SET-TAG" is used to prevent any routes that have been redistributed into EIGRP from redistributed again into OSPF domain by tagging these routes with tag 1:


NEW QUESTION # 330
Drag and drop the DHCP messages from the left onto the correct uses on the right.

Answer:

Explanation:


NEW QUESTION # 331
A network is configured with CoPP to protect the CORE router route processor for stability and DDoS protection. As a company policy, a class named class-default is preconfigured and must not be modified or deleted. Troubleshoot CoPP to resolve the issues introduced during the maintenance window to ensure that:


WAN



CORE




MGMT

Answer:

Explanation:
See the solution below in Explanation.
Explanation:
CORE
policy-mao CoPP
class CoPP-CRITICAL
police 1000000 50000 50000 conform-action transmit exceed-action transmit Text Description automatically generated with medium confidence

CORE# Copy run start
TESTING: -
CORE
Graphical user interface Description automatically generated with medium confidence

MGMT
Graphical user interface, text Description automatically generated


NEW QUESTION # 332
Drag and drop the ICMPv6 neighbor discovery messages from the left onto the correct packet types on the right.

Answer:

Explanation:


NEW QUESTION # 333
An engineer configures PBR on R5 and wants to create a policy that matches traffic destined toward 10.10.10.0/24 and forward 10.1.1.1. The traffic must also have its IP precedence set to 5.
All other traffic should be forward toward 10.1.1.2 and have its IP precedence set to 0.
Which configuration meets the requirements?

  • A. access-list 1 permit 10.10.10.0 0.0.0.255
    route-map CCNP
    permit 10 match ip address 1
    set ipnext- hop 10.1.1.1
    set ip precedence 5
    !
    route-map CCNP permit 20
    set ip next-hop 10.1.1.2
    set ip precedence 0
  • B. access-list 1 permit 10.10.10.0 0.0.0.255
    access-list 2 permit any
    route-map CCNP permit 10
    match ip address 1
    set ip next-hop 10.1.1.1
    set ip precedence 5
    !
    route-map CCNP permit 20
    match ip address 2
    set ip next-hop 10.1.1.2
    set ip precedence 0
    route-map CCNP permit 30
  • C. access-list 100 permit ip any 10.10.10.0 0.0.0.255
    route-map CCNP permit 10
    match ip address 100
    set ip next-hop 10.1.1.1
    set ip precedence 5
    ! route-map CCNP permit 20
    set ip next-hop 10.1.1.2
    set ip precedence 0
  • D. access-list 100 permit ip any 10.10.10.0 0.0.0.255
    route-map CCNP
    permit 10 match ip address 100
    set ip next-hop 10.1.1.1
    set ip precedence 0
    !
    route-map CCNP permit 20
    set ip next-hop 10.1.1.2
    set ip precedence 5
    !
    route-map CCNP permit 30

Answer: C


NEW QUESTION # 334
The network administrator is tasked to configure R1 to authenticate telnet connections based on Cisco ISE using RADIUS. ISE has been configured with an IP address of 192.168.1.5 and with a network device pointing towards R1 (192.168.1.1) with a shared secret password of Cisco123. If ISE is down, the administrator should be able to connect using the local database with a username and password combination of admin/cisco123.
The administrator has configured the following on R1:

ISE has gone down. The Network Administrator is not able to Telnet to R1 when ISE went down. Which two configuration changes will fix the issue? (Choose two.)

  • A. Option E
  • B. Option A
  • C. Option C
  • D. Option D
  • E. Option B

Answer: A,C


NEW QUESTION # 335
......

Pass CCNP Enterprise 300-410 Exam With 740 Questions: https://actualtests.testbraindump.com/300-410-exam-prep.html