300-420 exam dumps

300-420 practice question 21 of 323

Designing Cisco Enterprise Networks. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-420 Question 21

Select 3

An enterprise network is deploying BGP to interconnect with multiple ISPs for redundancy and scalability. The design requires ensuring stability, preventing route flapping from external peers, and maintaining a secure routing environment. Which of the following design considerations should be implemented to achieve these goals?

  1. A

    Implement BGP route dampening to suppress unstable routes.

  2. B

    Use prefix lists and route filtering to control inbound and outbound routes.

  3. C

    Allow all BGP attributes from external peers to ensure full route visibility.

  4. D

    Configure authentication using MD5 or TCP-AO for BGP sessions.

  5. E

    Disable AS path filtering for better performance.

Show answer and explanation

Correct answers: A, B, D

Explanation

To create a stable, secure, and scalable BGP routing design, the enterprise should implement route dampening to handle route flapping, use prefix lists and route filtering for precise control of routing information, and secure BGP sessions using authentication mechanisms like MD5 or TCP-AO. Allowing all BGP attributes and disabling AS path filtering would expose the network to unnecessary risks, defeating the goals of stability and security.

  • A. Correct.

    Implementing BGP route dampening is a best practice to suppress unstable routes and improve overall routing stability. It helps to mitigate the impact of frequent route flapping.

  • B. Correct.

    Using prefix lists and route filtering is critical to control the routes being advertised or received, ensuring that only valid and relevant routes are shared. This helps to avoid propagation of incorrect or unnecessary routes.

  • C. Incorrect.

    Allowing all BGP attributes from external peers is not a secure practice. It may expose the network to malicious or incorrect routing information, leading to instability and security risks.

  • D. Correct.

    Configuring authentication using MD5 or TCP-AO secures BGP sessions against unauthorized access and spoofing, enhancing the security of the routing design.

  • E. Incorrect.

    Disabling AS path filtering is not recommended as it removes an important mechanism to validate and filter routes based on their AS path attributes, which could lead to instability or incorrect route propagation.

Timed practice exam

Take a 300-420 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam