400-007 Cisco Certified Design Expert V3.0 Practice Questions
Prepare for 400-007 with more than an answer.
- Exam fee
- $450 USD
- Level
- Expert
Domains covered on the exam 5
- Business Strategy Design15%
- Control, Data, Management Plane and Operational Design25%
- Network Design30%
- Service Design15%
- Security Design15%
- 1
A systems administrator is configuring a new Cisco switch and needs to set the management IP address. The desired IP address is 192.168.10.5 with a subnet mask of 255.255.255.0. This IP address should be assigned to the default management logical interface. What is the correct command to enter in global configuration mode to create this interface if it does not exist?
Switch(config)# ___________Show answer details
Correct answer: C
On Cisco IOS switches, logical Layer 3 interfaces for VLANs are called Switched Virtual Interfaces (SVIs). The default management SVI is typically associated with VLAN 1. The command
interface Vlan1is used to enter the configuration mode for this SVI, where the IP address can then be assigned. - 2
True or False: When designing a network that uses OSPF, configuring all routers in a single, large Area 0 is a scalable design for an enterprise network with over 500 routers.
Show answer details
Correct answer: B
This statement is false. A single OSPF area design does not scale well to 500 routers. In OSPF, all routers within an area must maintain an identical Link-State Database (LSDB). A large number of routers and links in one area leads to a large LSDB, high CPU utilization during SPF calculations, and increased routing protocol overhead. Best practice is to use a hierarchical, multi-area design to segment the network, summarize routes at Area Border Routers (ABRs), and limit the scope of link-state changes, thereby improving stability and scalability.
- 3
A multinational corporation is designing a global WAN. The business has adopted an 'agile' project management methodology for deploying new applications and services. This means that network requirements, such as bandwidth and QoS for new applications, can change frequently with short notice. Which characteristic of the WAN design is most important to support this agile approach?
Show answer details
Correct answer: C
An agile methodology demands flexibility and rapid adaptation to change. A WAN design that is highly programmable and automated (such as one based on SD-WAN) allows network policies, like QoS and traffic steering, to be changed and deployed quickly from a central controller. This enables the network team to keep pace with the fast-changing requirements of agile application development sprints. Fixed contracts and static configurations are antithetical to agility, and while low latency is desirable, it is the ability to rapidly change policy that is most critical.
- 4
A network designer is creating a zero-trust architecture for an enterprise. A core principle of this design is micro-segmentation, where workloads can only communicate on an as-needed basis, regardless of their location in the network. Which technology is fundamental to enforcing this policy by tagging traffic at the ingress point and making enforcement decisions based on those tags throughout the network?
Show answer details
Correct answer: B
Cisco TrustSec is a technology designed for micro-segmentation. It decouples access control from network topology (IP addresses and VLANs). When a user or device authenticates, it is assigned a Security Group Tag (SGT). This tag is carried with the traffic (e.g., in a special header) and used by network devices to enforce policies defined in a central matrix. This allows for dynamic, attribute-based policy enforcement, which is a cornerstone of zero-trust and micro-segmentation. VRF-Lite provides macro-segmentation at Layer 3, and ACLs are static and difficult to manage at scale for this purpose.
- 5
A company has two data centers (DC1 and DC2) connected by dark fiber. They are running a VXLAN EVPN fabric and need to extend several Layer 2 segments between the two sites for VM mobility. The design must provide active/active multipathing and a loop-free topology. Which DCI (Data Center Interconnect) design is most appropriate for this scenario?
DC1 VXLAN Fabric DC2 VXLAN Fabric +--------------------+ Dark Fiber +--------------------+ | VTEP1 --- VTEP2 |================| VTEP3 --- VTEP4 | | | | |================| | | | | Spine1 -- Spine2 | | Spine3 -- Spine4 | +--------------------+ +--------------------+Show answer details
Correct answer: C
VXLAN EVPN Multi-Site is the standard architecture for interconnecting separate VXLAN EVPN fabrics. It introduces a new component, the Border Gateway (BGW), which connects to the DCI. The BGWs use EVPN to exchange reachability information between sites, effectively extending the L2/L3 overlay. This design maintains separate underlay and control planes for each site, creating distinct failure domains, while providing active/active forwarding and loop prevention for stretched segments. Stretching the underlay or using back-to-back vPC would merge the failure domains and is not a recommended scalable design.
- 6
A financial institution is designing a new data center network using Cisco ACI. A key requirement is to provide shared L3Out connectivity for multiple tenants while maintaining strict traffic isolation between them. The design must also ensure that routing tables are not shared between tenants using the common L3Out. Which ACI construct and configuration is required to meet these requirements?
Show answer details
Correct answer: B
To provide shared L3Out services while maintaining tenant isolation, the L3Out is configured in the 'common' tenant. The key step is to define the external network (External EPG) subnets with the scope set to 'Shared between VRFs'. This allows routes to be leaked from the common VRF to tenant VRFs without merging the VRFs themselves, thus maintaining routing table isolation. The other options either fail to share the L3Out, merge routing tables, or are not standard ACI practice.
- 7
A global enterprise is deploying a Cisco SD-WAN solution. They have two main data centers (DC1, DC2) and multiple regional hubs. For business-critical applications, they require that traffic from branch sites prefers DC1, but fails over to DC2 if DC1 becomes unreachable. Additionally, if the preferred path to DC1 experiences a 20% packet loss, traffic should also be rerouted to DC2. Which two SD-WAN policies are required to implement this design? (Select TWO)
Show answer details
Correct answer: A, C
This design requires two policies. First, a centralized control policy is used to influence the routing path, setting a higher preference for TLOCs at DC1 for the specific application prefixes. This handles the primary path selection. Second, an application-aware routing (AAR) policy is needed to monitor path performance. This policy defines an SLA class (e.g., loss > 20%) and specifies that if the preferred path (to DC1) violates this SLA, traffic should be moved to an alternate path (to DC2). Data policies are for packet manipulation, and localized policies would not be efficient for this global requirement.
- 8
True or False: In a Cisco SD-Access fabric, the LISP (Locator/ID Separation Protocol) control plane is primarily responsible for tracking the location of endpoints (EIDs) by mapping them to their current physical location (RLOCs) on the fabric edge nodes.
Show answer details
Correct answer: A
This statement is true. LISP is the fundamental control plane protocol in the SD-Access fabric. It separates the endpoint identity (EID), which is the IP or MAC address, from its location (RLOC), which is the loopback address of the fabric edge switch where the endpoint is connected. The LISP Map-Server/Map-Resolver functionality, running on the control plane nodes, maintains this dynamic EID-to-RLOC mapping database.
- 9
A large university is redesigning its campus network to support increasing BYOD and IoT device onboarding while enforcing strict security segmentation. The current network relies on multiple SSIDs and complex ACLs, which has become an operational burden. The primary business goals are to simplify network operations, automate policy enforcement, and ensure that a compromised IoT device cannot access sensitive research data.
The proposed solution is a Cisco SD-Access fabric. The design includes fabric edge nodes, intermediate nodes, border nodes, and control plane nodes (running on Cisco DNA Center). Wireless connectivity will be provided by fabric-enabled Access Points.
To achieve the security goals, all devices will be profiled upon connection. User-owned devices (BYOD) will be placed in a 'BYOD_Users' group. University-owned research computers will be in the 'Research_Computers' group, and IoT devices like security cameras will be in the 'IoT_Devices' group. The security policy dictates that IoT_Devices should only be able to communicate with the central video management server and should be completely isolated from all other groups.
Which SD-Access components are most critical for dynamically assigning devices to groups and enforcing this access policy between groups?
Show answer details
Correct answer: C
In an SD-Access solution, Cisco Identity Services Engine (ISE) is the component responsible for device profiling, authentication, and authorization. Upon successful authentication, ISE assigns a Security Group Tag (SGT) to the endpoint (e.g., SGT for IoT_Devices). Cisco TrustSec technology, which is integrated into the fabric, uses these SGTs to enforce security policies. A matrix-based policy in ISE/DNA Center would define that the 'IoT_Devices' SGT can only talk to the 'Video_Server' SGT, and this policy is enforced at the ingress fabric edge node. LISP/VXLAN are control/data plane protocols, while DNA Center is the orchestrator; they are part of the solution but not the primary components for dynamic policy assignment and enforcement.
- 10
A network architect is designing a BGP solution for a large enterprise with two internet connections from different service providers (AS 65100 and AS 65200). The enterprise uses its own public AS (AS 65300). The primary business requirement is to use the link to AS 65100 as the primary path for all outbound traffic. The link to AS 65200 should only be used if the primary link fails. Which BGP attribute should be manipulated on the enterprise edge routers to influence outbound traffic path selection and meet this requirement?
! Router R1 (connected to AS 65100 - Primary) router bgp 65300 neighbor 198.51.100.1 remote-as 65100 ! ! Router R2 (connected to AS 65200 - Backup) router bgp 65300 neighbor 203.0.113.1 remote-as 65200Show answer details
Correct answer: C
Local Preference is the correct attribute for influencing outbound traffic path selection within an autonomous system. It is a well-known, discretionary attribute that is exchanged between iBGP peers. By setting a higher Local Preference (default is 100) on routes learned from the primary provider (AS 65100), all routers within AS 65300 will prefer that path to exit the network. AS-Path prepending influences inbound traffic, and MED is considered after Local Preference and is typically used to influence how a neighboring AS enters your network.
