350-401 Practice Questions
Prepare for 350-401 with more than an answer.
- Exam fee
- $400 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 6
- Architecture15%
- Virtualization10%
- Infrastructure30%
- Network Assurance10%
- Security20%
- Automation and Artificial Intelligence15%
- 1
Which of the following would be displayed when you issue the show ip eigrp interfacescommand? (Select the best answer.)
Show answer details
Correct answer: A
Area 0 (the backbone area) is mandatory in OSPF networks and must be present for proper routing between non-backbone areas. The backbone area serves as the central hub through which all inter-area traffic must pass. Without Area 0, non-backbone areas cannot exchange routing information, making it essential for scalable OSPF network design. Virtual links, Area 1, and external routes are not mandatory components and depend on specific network topology requirements.
- 2
You issue the show ip ospf neighbor command on a Cisco router. The router’s OSPF neighbor state is FULL/DR.
Which of the following is most likely true about the OSPF router? (Select the best answer.)
Show answer details
Correct answer: C
The show spanning-tree command displays comprehensive Spanning Tree Protocol information including root bridge ID, port states, and topology details. This command provides essential STP troubleshooting data including bridge priorities, port roles, path costs, and the current STP topology state. The show vlan, show interface, and show mac-address-table commands provide different network information but not the specific STP operational details needed for spanning tree troubleshooting.
- 3
Which of the following would not be displayed in the output of the show ip eigrp interfaces command?(Select the best answer.)
Show answer details
Correct answer: D
Router-on-a-stick configuration uses subinterfaces on a single router interface to route between VLANs. This method allows one physical router interface to handle traffic for multiple VLANs by creating virtual subinterfaces, each configured with a different VLAN ID and IP subnet. The router connects to a switch trunk port that carries multiple VLAN traffic. This solution is cost-effective for smaller networks requiring inter-VLAN routing without needing multiple physical router interfaces or a Layer 3 switch.
- 4
Which of the following cannot be exchanged between spoke sites in a DMVPN design? (Select 2 choices.)
Show answer details
Correct answer: B, D
B, D -- Multicast traffic and dynamic routing traffic cannot be exchanged between spoke sites in a Dynamic Multipoint virtual private network (DMVPN) design. Multicast traffic and dynamic routing traffic must be sent from spoke to hub.
DMVPN enables an administrator to easily configure scalable IP Security (IPSec) virtual private networks (VPNs) using a hubandspoke design. The hub router or routers are typically assigned a static IP address? the spoke routers can be dynamically addressed. DMVPN requires Generic Routing Encapsulation (GRE), Next Hop Resolution Protocol (NHRP), and a dynamic routing protocol such as Enhanced Interior Gateway Routing Protocol (EIGRP) or Open Shortest Path First (OSPF). A multipoint GRE (mGRE) tunnel is used to carry multiple IPSec or GRE tunnels.
NHRP is used to create a database of tunnel addresstoreal address mappings.
Unicast traffic and Voice over IP (VoIP) traffic can be exchanged between spoke sites. However, only limited Quality of Service (QoS) mechanisms can be provided between spokes, thereby preventing VoIP and video traffic from being properly prioritized. -- Reference: Cisco: Multicast over IPSec VPN Design Guide: OverviewCisco: Dynamic Multipoint VPN (DMVPN) Design Guide (Version 1.1): Known Limitations Summary for SpoketoSpoke Deployment Model (PDF)B, D -- Multicast traffic and dynamic routing traffic cannot be exchanged between spoke sites in a Dynamic Multipoint virtual private network (DMVPN) design. Multicast traffic and dynamic routing traffic must be sent from spoke to hub.
DMVPN enables an administrator to easily configure scalable IP Security (IPSec) virtual private networks (VPNs) using a hubandspoke design. The hub router or routers are typically assigned a static IP address? the spoke routers can be dynamically addressed. DMVPN requires Generic Routing Encapsulation (GRE), Next Hop Resolution Protocol (NHRP), and a dynamic routing protocol such as Enhanced Interior Gateway Routing Protocol (EIGRP) or Open Shortest Path First (OSPF). A multipoint GRE (mGRE) tunnel is used to carry multiple IPSec or GRE tunnels.
NHRP is used to create a database of tunnel addresstoreal address mappings.
Unicast traffic and Voice over IP (VoIP) traffic can be exchanged between spoke sites. However, only limited Quality of Service (QoS) mechanisms can be provided between spokes, thereby preventing VoIP and video traffic from being properly prioritized. -- Reference: Cisco: Multicast over IPSec VPN Design Guide: OverviewCisco: Dynamic Multipoint VPN (DMVPN) Design Guide (Version 1.1): Known Limitations Summary for SpoketoSpoke Deployment Model (PDF) - 5
RouterA and RouterB are connected routers.
You issue the show clns neighbors command on RouterA and receive the following Output:
[Image]. System Id Interface SNPA State Holdtime ….. Type Protocol
RouterB Et0/0 0000.0000.000b Up 23 L1 IS-IS
Which of the following statements must be true? (Select the best answer.)
Show answer details
Correct answer: A
The ip helper-address command configured on RouterA will forward DHCP broadcast requests from VLAN 10 clients to the DHCP server. When clients send DHCP Discover broadcasts, RouterA receives these broadcasts and converts them to unicast packets directed to the configured helper address (DHCP server). This enables DHCP service across VLAN boundaries since broadcast traffic normally does not cross router boundaries. The DHCP server then responds with offers that RouterA forwards back to the requesting clients.
- 6
You issue the following commands on a Cisco router:
RouterA#debug condition interface serial 0/0
RouterA#debug condition interface serial 0/1
RouterA#debug condition username RouterB
RouterA#debug ppp authenticationWhich of the following PPP authentication debugging messages will be displayed on RouterA? (Select the best answer.)
Show answer details
Correct answer: D
Debug conditions are combined with an OR logic. When multiple debug conditions are configured (interface serial 0/0, interface serial 0/1, and username RouterB), the debug output will display messages that match ANY of these conditions. The debug ppp authentication command will show messages that contain the RouterB username OR arrive on either Serial 0/0 OR Serial 0/1 interface. The other options are incorrect because they suggest only one specific condition would be met, ignoring the OR logic of multiple debug conditions.
- 7
Which of the following ping command options should be enabled if you want to determine the MTU size that a given connection supports? (Select the best answer.)
Show answer details
Correct answer: A
The IPv4 do-not-fragment bit (DF bit) is essential for MTU discovery because it prevents fragmentation of the ping packets. When the DF bit is set and a packet is too large for a link, an ICMP "fragmentation needed" message is returned, allowing you to determine the maximum transmission unit size. The other options are incorrect: increasing ping count, datagram size, or timeout values do not directly help determine MTU size - you need the DF bit to force MTU discovery through fragmentation prevention.
- 8
You issue the debug ppp authentication command on RouterA, RouterA’s Serial 0/0 interface is connected to RouterB, RouterA’s Serial 0/1 interface is connected to RouterC, You issue the no shutdown command on all interfaces and note that every interface has entered the up state.
Next, you issue the show debug condition command on RouterA and receive the following Output: [Image]. Which of the following statements is true? (Select the best answer.)

Show answer details
Correct answer: B
Based on the image showing debug output, the debug condition has been met on the Serial 0/1 interface. The debug output displays PPP authentication messages specifically from the Serial 0/1 connection to RouterC, indicating that this interface condition triggered the debug display. The other options are incorrect because the output specifically shows Serial 0/1 interface activity, not Serial 0/0, username-based conditions, or all/no conditions being met.
- 9
You issue the ping 192.168.1.1 size 1501 dfbit command on a Cisco device. You notice a message indicating that the DF bit has been set. However, the ping fails.
You want to determine the largest datagram that the connection supports without fragmentation.
Which of the following should you do next? (Select the best answer.)
Show answer details
Correct answer: C
When a ping with DF bit set fails because the datagram is too large (1501 bytes), you should issue the command with a lower size parameter value to find the maximum MTU. This process of gradually reducing the size until pings succeed determines the largest unfragmented packet size the path supports. The other options are incorrect: removing the dfbit parameter defeats MTU discovery purpose, removing size parameter uses default small size, and removing both parameters provides no MTU information.
- 10
RouterA’s Serial 0/0 interface is connected to RouterA, RouterA’s Serial 0/1 interface is connected to RouterA, You issue the debug ppp authentication on RouterA and then transition all connected interfaces to the up state.
Next, you issue the show debug condition command on RouterA and receive the Output below.
Using the least amount of administrative effort, which of the following should you issue to receive PPP authentication debug output from both RouterB and RouterC? (Select the best answer.)

Show answer details
Correct answer: B
You should issue the debug condition interface serial 0/1 command on RouterA to receive Point-to-Point Protocol (PPP) authentication debug output from both RouterB and RouterC with the least administrative effort. The debug condition interface command filters debug output to show only messages from the specified interface. Since both routers connect through different serial interfaces, adding the Serial 0/1 condition will enable debug output from both connections. The other options either disable debugging entirely or use incorrect syntax for interface conditions.
