500-230 Practice Questions
Prepare for 500-230 with more than an answer.
- Exam fee
- $300 USD
- Level
- Specialist
- Valid for
- 3 years
Domains covered on the exam 2
- Cisco Fundamental IOS XR Concepts50%
- Cisco Advanced IOS XR Concepts50%
- 1
A field engineer is performing initial setup on a Cisco ASR 9000 router running IOS-XR. The network security policy requires that management plane access (e.g., SSH, SNMP) be configured in a separate, isolated administrative instance from the data plane routing protocols. Which IOS-XR feature is specifically designed to provide this level of administrative and resource partitioning on a single physical router?
Show answer details
Correct answer: C
Secure Domain Routers (SDRs) are the correct feature for this requirement. An SDR creates a logical router with its own set of administrators, configurations, and resources, completely isolated from the default SDR and any other non-default SDRs. This allows for the separation of management and data plane administration as required by the policy. VRF-lite provides routing table separation but not administrative isolation. MPP is a security feature to protect the control plane from DoS attacks, not for administrative partitioning.
- 2
A service provider needs to implement granular command authorization for its network operations team on an IOS-XR platform using TACACS+. The requirement is to allow Tier 1 engineers to execute all
showcommands but deny them from entering configuration mode. Which TACACS+ attribute-value pair must be configured on the TACACS+ server and associated with the Tier 1 user group to achieve this?Show answer details
Correct answer: D
IOS-XR uses a task-based security model for command authorization. The
task-idattribute on the TACACS+ server is used to map user groups to specific tasks. To meet the requirement, the server profile for Tier 1 users should explicitly permit the 'show' task-id while denying the 'config' task-id. Usingpriv-lvlis a legacy IOS concept and less granular. Usingcmdandcmd-argis possible but defining permissions bytask-idis the native and recommended IOS-XR method for role-based authorization. - 3
An administrator has staged a series of complex changes in the candidate configuration of an IOS-XR router. Before committing the changes, they need to review only the differences between the candidate configuration and the currently active running configuration. Which TWO commands will display this delta? (Select TWO)
Show answer details
Correct answer: C, E
The
show configurationcommand, when issued from configuration mode, displays the staged changes (the delta) that will be applied upon commit.The
show commit configuration diffcommand provides a detailed, formatted difference between the candidate and running configuration, highlighting additions and deletions. - 4
Company Background:
Global ISP Inc. provides L3VPN services to various enterprise customers. They have a well-established Intra-AS MPLS core running on Cisco IOS-XR. Two of their major customers, 'Alpha Corp' and 'Beta Corp', require connectivity to a new shared service, 'DataAnalytics', which is hosted in its own VRF within the Global ISP network. The security policy is strict and mandates a hub-and-spoke topology for this access.Current Situation:
Alpha Corp is in VRFALPHA_CORPand Beta Corp is in VRFBETA_CORP. The shared service is in VRFSHARED_ANALYTICS. The Route Target (RT) scheme usesASN:VRF_ID. Alpha Corp uses RT65000:100, Beta Corp uses RT65000:200, and the shared service uses RT65000:300.Requirements:
- Both Alpha Corp and Beta Corp must be able to reach the services in the
SHARED_ANALYTICSVRF. - The
SHARED_ANALYTICSVRF must be able to reach back to both Alpha Corp and Beta Corp. - Alpha Corp and Beta Corp must remain completely isolated from each other; no traffic should pass directly between them.
- The solution must be scalable and adhere to the hub-and-spoke design principle, with
SHARED_ANALYTICSas the hub.
Which route-target configuration on the PE routers correctly implements this secure hub-and-spoke extranet?
graph TD subgraph "Global ISP Core" VRF_ALPHA["VRF: ALPHA_CORP RT: 65000:100"] -- Spoke --- VRF_SHARED["VRF: SHARED_ANALYTICS RT: 65000:300"] VRF_BETA["VRF: BETA_CORP RT: 65000:200"] -- Spoke --- VRF_SHARED end VRF_ALPHA -.->|X| VRF_BETA style VRF_SHARED fill:#f9f,stroke:#333,stroke-width:2pxShow answer details
Correct answer: A
This configuration correctly establishes the hub-and-spoke extranet. The spoke VRFs (ALPHA_CORP, BETA_CORP) export their own unique RTs and import only the hub's RT (65000:300). This allows them to send routes to the hub and receive routes from the hub. The hub VRF (SHARED_ANALYTICS) exports its own RT and imports the RTs from both spokes (65000:100, 65000:200). This allows it to learn routes from both customers and advertise its shared service routes to them. Crucially, neither spoke imports the other's RT, ensuring they remain isolated.
- Both Alpha Corp and Beta Corp must be able to reach the services in the
- 5
True or False: In Cisco IOS-XR, applying a Software Maintenance Upgrade (SMU) is an atomic operation. If any part of the SMU activation fails, the system automatically rolls back all changes associated with that SMU, leaving the system in its original state.
Show answer details
Correct answer: A
This statement is true. The IOS-XR installation process for SMUs is designed to be atomic. The system first performs a series of checks. If all checks pass, it proceeds with the activation. If any step during the activation process fails, the entire operation is aborted, and the system is automatically rolled back to its pre-SMU state, ensuring system stability.
- 6
A field engineer is troubleshooting a newly configured Inter-AS L3VPN Option B link between two service providers. The MP-eBGP session between the ASBRs is up, but customer VPN routes are not being exchanged. The engineer confirms that the
neighbor send-community bothcommand is configured. Which of the following is the most probable cause for the failure?Show answer details
Correct answer: B
In an Inter-AS L3VPN Option B scenario, the ASBRs exchange VPNv4 routes via MP-eBGP. The next-hop for these routes is typically the PE router in the originating AS. Without the
next-hop-selfcommand, the receiving ASBR will not change the next-hop attribute, making the route unreachable for PEs in its own AS. Whilesend-communityis required for route-targets, the lack ofnext-hop-selfis a common and critical error that directly prevents route propagation. An IGP does not run between ASBRs of different providers, and LDP is not required directly between ASBRs in Option B. - 7
A junior engineer has applied a complex BGP policy change on a production IOS-XR router. To mitigate risk, the senior engineer wants to ensure the configuration automatically reverts if connectivity is lost. Which command sequence correctly applies the new configuration with a 5-minute automatic rollback timer?
Show answer details
Correct answer: D
The
commit confirmedcommand in IOS-XR is a safety mechanism that applies a configuration change but requires a second, confirmingcommitcommand within the specified time. If the confirmation is not received (e.g., because the change caused a loss of management access), the router automatically rolls back to the previous configuration. The value is specified in minutes, socommit confirmed 5sets a 5-minute timer. - 8
Following a recent link flap in an MPLS core, an engineer notices that LDP convergence is taking longer than expected, causing a brief service outage. The engineer needs to investigate why LDP is slow to re-establish its session and re-learn labels from its neighbor. Which TWO commands are most effective for diagnosing LDP session establishment issues and label exchange timing on an IOS-XR router? (Select TWO)
Show answer details
Correct answer: A, C
This command is crucial for viewing the LDP discovery process, including hello intervals and the state of adjacency with neighbors. It helps determine if the routers can even see each other at the LDP level, which is the first step in session establishment.
This debug command provides real-time information about the LDP TCP transport session events. It allows the engineer to see the session setup, keepalives, and any errors that might be occurring during the TCP handshake, which is a common point of failure or delay.
- 9
Within the Cisco IOS-XR architecture, which core process is responsible for managing the lifecycle (starting, stopping, and monitoring) of all other processes running on a Route Processor?
Show answer details
Correct answer: D
The System Manager (
sysmgr) is a critical mandatory process in the IOS-XR operating system. Its primary function is to manage the lifecycle of all other processes. It reads the system configuration to determine which processes should be running, starts them, monitors their health, and restarts them if they fail. - 10
A service provider, 'GlobalNet', is designing an MPLS L3VPN service for two enterprise clients, 'AlphaCorp' and 'BetaLogistics'. AlphaCorp requires access to a shared logging server hosted within a separate VRF called 'SHARED_SERVICES'. BetaLogistics needs standard internet access and must be completely isolated from AlphaCorp and the shared services. Both clients have multiple sites that need full mesh connectivity amongst themselves.
The lead architect has proposed the following high-level design:
- AlphaCorp sites will be in the 'ALPHA_VRF'.
- BetaLogistics sites will be in the 'BETA_VRF'.
- The logging server is in the 'SHARED_SERVICES_VRF'.
To meet these specific requirements, what is the optimal route-target (RT) import/export strategy that should be configured on the PE routers?
graph TD subgraph GlobalNet MPLS Core PE1 PE2 P1[P Router] P2[P Router] end subgraph AlphaCorp SiteA --- PE1 SiteB --- PE2 end subgraph BetaLogistics SiteX --- PE1 SiteY --- PE2 end subgraph Shared Services LoggingServer --- PE1 end PE1 --- P1 --- PE2 PE1 --- P2 --- PE2Show answer details
Correct answer: C
This configuration correctly implements the requirements. 1)
ALPHA_VRFimports its own RT (RT_ALPHA) for full mesh connectivity and importsRT_SHAREDto learn the route to the logging server. 2)BETA_VRFonly imports its own RT (RT_BETA), ensuring complete isolation. 3)SHARED_SERVICES_VRFexports its routes withRT_SHAREDand critically, only needs toimport RT_ALPHAto learn the return path to AlphaCorp clients. It does not need to import its own routes or Beta's routes, ensuring one-way access initiation from AlphaCorp.
