CiscoProfessional level350-401Page 2 of 7

350-401 exam dumps: questions 101 to 200 of 629

Page 2 of the free 350-401 question bank for the Implementing Cisco Enterprise Network Core Technologies exam. Questions 101 to 200 are listed below, the first 5 in full with answers and explanations. Back to page 1 for the exam overview and FAQ.

Question bank last updated February 2025

Free 350-401 practice questions

Questions 101 to 105 of 629

Pick an answer before you open the explanation. Each question also has its own page with a permalink.

350-401 Question 101

Single answer

An organization has set up a GRE tunnel between two branch offices to allow for the transmission of non-IP traffic. However, the network team notices that the data being transmitted over the GRE tunnel lacks encryption and is subject to interception. Which configuration should be implemented to secure the traffic while maintaining the existing GRE tunnel?

  1. A

    Configure IPsec in tunnel mode to encapsulate and encrypt the GRE traffic.

  2. B

    Replace the GRE tunnel with an IPsec tunnel, as they cannot coexist.

  3. C

    Enable IPsec in transport mode to encrypt the GRE payload.

  4. D

    Use a dynamic GRE tunnel with built-in encryption to secure the traffic.

Show answer and explanation

Correct answer: A

Explanation

A GRE tunnel is capable of encapsulating a variety of traffic types, but it does not provide encryption. To secure GRE traffic, IPsec can be applied in tunnel mode. This ensures that the GRE traffic is encapsulated and encrypted, securing it from potential interception while maintaining the benefits of GRE tunneling.

  • A. Correct.

    Correct: Configuring IPsec in tunnel mode allows the GRE traffic to be encapsulated and encrypted, ensuring confidentiality and security over the public network.

  • B. Incorrect.

    Incorrect: GRE and IPsec can coexist. You do not need to replace the GRE tunnel; instead, you can secure it with IPsec.

  • C. Incorrect.

    Incorrect: IPsec in transport mode only encrypts the payload but does not encapsulate the GRE tunnel itself. This would leave the GRE header exposed.

  • D. Incorrect.

    Incorrect: GRE itself does not have built-in encryption capabilities. Dynamic GRE refers to automatic tunnel creation but does not inherently secure traffic.

350-401 Question 102

Select 3

A network engineer is tasked with configuring secure communication between two branch offices over the internet. The engineer decides to use GRE over IPsec tunneling. Which of the following steps are required to successfully set up the GRE over IPsec tunnel?

  1. A

    Configure the GRE tunnel interface with source and destination IP addresses.

  2. B

    Enable IPsec encryption directly on the physical interface without using a crypto map.

  3. C

    Apply a crypto map to the GRE tunnel interface to secure the GRE traffic.

  4. D

    Define an IPsec transform set and specify the encryption and authentication methods.

  5. E

    Ensure the GRE tunnel traffic matches the crypto map's access control list (ACL).

Show answer and explanation

Correct answers: A, D, E

Explanation

When configuring GRE over IPsec, the GRE tunnel must first be established with source and destination IP addresses. To secure the GRE traffic, IPsec must be configured with an appropriate transform set and a crypto map applied to the physical interface. Additionally, the crypto map's ACL must match the GRE traffic to ensure it is encrypted. Misconfigurations, such as applying the crypto map to the GRE interface or skipping the ACL, will prevent the tunnel from functioning properly.

  • A. Correct.

    Correct. GRE tunnels require configuration of source and destination IP addresses to establish the logical tunnel interface.

  • B. Incorrect.

    Incorrect. IPsec encryption is applied using a crypto map configuration, not directly on the physical interface without a crypto map.

  • C. Incorrect.

    Incorrect. Crypto maps are applied to physical interfaces, not the GRE tunnel interface itself.

  • D. Correct.

    Correct. Defining an IPsec transform set is necessary to specify the encryption and authentication methods for securing the tunnel.

  • E. Correct.

    Correct. The crypto map's ACL must match the GRE tunnel traffic to ensure that the GRE packets are secured by IPsec.

350-401 Question 103

Single answer

Your organization needs to establish a secure site-to-site connection between two remote offices using GRE over IPsec. The network team has configured the GRE tunnel, but it is observed that the tunnel is not encrypted. What step is required to ensure that the GRE traffic is encrypted using IPsec?

  1. A

    Apply an IPsec profile to the GRE tunnel interface.

  2. B

    Enable IPsec encryption directly on the GRE tunnel.

  3. C

    Configure a crypto ACL to match GRE traffic and apply it to the IPsec policy.

  4. D

    Use dynamic IPsec instead of GRE to simplify the configuration.

Show answer and explanation

Correct answer: C

Explanation

To secure GRE traffic with IPsec, a crypto ACL must be configured to identify the GRE-encapsulated traffic that needs to be encrypted. The ACL is then associated with an IPsec transform set and applied to the IPsec policy. Without this step, the GRE traffic will remain unencrypted, as IPsec does not automatically protect GRE traffic unless explicitly configured to do so.

  • A. Incorrect.

    Incorrect. IPsec profiles are not applied directly to GRE tunnel interfaces. IPsec must be configured to match and protect GRE traffic using crypto ACLs and a transform set.

  • B. Incorrect.

    Incorrect. IPsec encryption cannot be enabled directly on a GRE tunnel. GRE encapsulation happens before IPsec encrypts the traffic.

  • C. Correct.

    Correct. A crypto ACL is required to identify the GRE traffic that needs to be encrypted by IPsec. This ACL is then applied to the IPsec policy to protect the traffic.

  • D. Incorrect.

    Incorrect. Dynamic IPsec is not a replacement for GRE over IPsec. GRE over IPsec is used when you need multiprotocol support and additional features like multicast or routing protocols.

350-401 Question 104

Single answer

You are tasked with establishing a secure connection between two branch offices over the internet. The solution must allow for the use of dynamic routing protocols between the sites while also encrypting the data. Which tunneling solution should you implement?

  1. A

    GRE over IPsec

  2. B

    IPsec Tunnel Mode

  3. C

    GRE Tunnel without IPsec

  4. D

    MPLS VPN

Show answer and explanation

Correct answer: A

Explanation

GRE over IPsec is the correct solution because it combines the advantages of both technologies: GRE provides support for dynamic routing protocols and multicast traffic, while IPsec ensures encryption and data security over the public internet. This makes it the ideal choice for securely connecting two branch offices with dynamic routing requirements.

  • A. Correct.

    Correct. GRE over IPsec allows for dynamic routing protocols to function over the tunnel while ensuring data encryption through IPsec.

  • B. Incorrect.

    Incorrect. IPsec Tunnel Mode provides encryption but does not support dynamic routing protocols natively, making it unsuitable for this requirement.

  • C. Incorrect.

    Incorrect. GRE Tunnel without IPsec supports dynamic routing protocols but lacks encryption, which does not meet the security requirement.

  • D. Incorrect.

    Incorrect. MPLS VPN is a separate WAN technology and does not involve GRE or IPsec tunneling. It does not meet the specific requirements of this scenario.

350-401 Question 105

Single answer

A network engineer is tasked with segmenting a single physical network into multiple virtual networks to securely isolate traffic between different departments. Which network virtualization technology should the engineer use?

  1. A

    Virtual LANs (VLANs)

  2. B

    Virtual Extensible LANs (VXLANs)

  3. C

    Software-Defined Networking (SDN)

  4. D

    Virtual Private Network (VPN)

Show answer and explanation

Correct answer: A

Explanation

The correct answer is VLANs because they allow a single physical network to be divided into multiple logical networks, ensuring traffic isolation between departments. This is a fundamental concept in network virtualization and is widely used for segmenting traffic in enterprise environments.

  • A. Correct.

    VLANs are used to segment a physical network into multiple logical networks, providing traffic isolation and improving security and efficiency. This is the correct choice for segmenting traffic between departments.

  • B. Incorrect.

    VXLANs are used to extend Layer 2 networks over Layer 3 infrastructure, typically in data centers. While VXLANs are a virtualization technology, they are not the primary solution for department-level segmentation on a single physical network.

  • C. Incorrect.

    SDN focuses on decoupling the control plane from the data plane in a network to improve programmability and flexibility. While related to network virtualization, it is not directly used for traffic segmentation in this scenario.

  • D. Incorrect.

    VPNs are used to securely connect remote sites or users over an untrusted network, such as the internet. They do not address traffic segmentation within a single physical network.

Timed practice exam

Take a 350-401 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam

350-401 practice questions 101 to 200 of 629

Every question has a page with the answer and explanation. Numbers are stable, so you can bookmark or share them. The bank is split into 7 pages of up to 100 questions.

  1. 101.An organization has set up a GRE tunnel between two branch offices to allow for the transmission of non-IP...
  2. 102.A network engineer is tasked with configuring secure communication between two branch offices over the...
  3. 103.Your organization needs to establish a secure site-to-site connection between two remote offices using GRE...
  4. 104.You are tasked with establishing a secure connection between two branch offices over the internet. The...
  5. 105.A network engineer is tasked with segmenting a single physical network into multiple virtual networks to...
  6. 106.An enterprise network architect is tasked with designing a scalable and isolated network environment to...
  7. 107.A network engineer is tasked with deploying a solution that allows multiple virtual networks to operate on...
  8. 108.A network engineer is tasked with implementing a virtualized network environment to allow multiple customers...
  9. 109.Your organization is deploying a Locator/ID Separation Protocol (LISP) architecture to improve scalability...
  10. 110.An enterprise is implementing LISP (Locator/ID Separation Protocol) in their network to improve scalability...
  11. 111.An enterprise network is deploying LISP to enable efficient communication between branches and datacenters....
  12. 112.An enterprise network is leveraging LISP (Locator/ID Separation Protocol) to optimize routing between its...
  13. 113.An enterprise network is expanding its data center infrastructure and decides to implement VXLAN to address...
  14. 114.An enterprise network engineer is deploying VXLAN in a data center to enable Layer 2 extension over a Layer 3...
  15. 115.An enterprise network engineer is implementing VXLAN to extend Layer 2 networks across data centers. They...
  16. 116.Your organization is deploying VXLAN in its data center to provide network scalability and support...
  17. 117.A network engineer is tasked with configuring a redundant Layer 2 topology between two data centers connected...
  18. 118.A network administrator is configuring a high-availability solution for a critical server farm. The...
  19. 119.An organization has deployed a multi-layer switching infrastructure using Cisco Catalyst switches. The...
  20. 120.A network administrator is tasked with deploying a new branch office and wants to ensure high availability...
  21. 121.An enterprise network administrator reports that a VLAN created on a switch is not propagating to other...
  22. 122.An enterprise network administrator is troubleshooting a Layer 2 issue where traffic is not being forwarded...
  23. 123.You are configuring a Layer 2 switch in your company's network. A colleague reports that traffic from certain...
  24. 124.A network engineer is troubleshooting a Layer 2 issue in a switched network. Hosts in VLAN 10 cannot...
  25. 125.An engineer is troubleshooting a connectivity issue between two Cisco switches connected via an 802.1Q trunk....
  26. 126.A network administrator is troubleshooting connectivity issues between two switches connected via an 802.1Q...
  27. 127.A network engineer is troubleshooting a connectivity issue between two switches connected via an 802.1Q trunk...
  28. 128.A network engineer is troubleshooting a connectivity issue between two switches, SW1 and SW2. Both switches...
  29. 129.A network engineer has configured an EtherChannel between two Cisco switches using LACP. After completing the...
  30. 130.You are troubleshooting an EtherChannel configuration between Switch A and Switch B. The EtherChannel is...
  31. 131.A network administrator is troubleshooting an EtherChannel issue between two switches. The EtherChannel is...
  32. 132.A network engineer is troubleshooting an EtherChannel issue between two switches. The EtherChannel is...
  33. 133.A network administrator is configuring Spanning Tree Protocol (STP) on a network to ensure loop prevention....
  34. 134.A network engineer is configuring Rapid Spanning Tree Protocol (RSTP) on a campus network. To enhance network...
  35. 135.You are configuring a campus network with Rapid Spanning Tree Protocol (RSTP) to ensure fast convergence...
  36. 136.A network administrator is tasked with configuring a switch to prevent a rogue device from becoming the root...
  37. 137.A network engineer is designing a routing solution for a branch office that needs to connect to multiple data...
  38. 138.A network engineer is configuring OSPF (Open Shortest Path First) on a new router in an enterprise network....
  39. 139.You are configuring a Layer 3 network for a branch office. The network requires inter-VLAN routing to allow...
  40. 140.A company is configuring inter-VLAN routing on a Layer 3 switch to allow communication between VLAN 10 and...
  41. 141.A network engineer is tasked with designing a network that includes both EIGRP and OSPF. The engineer needs...
  42. 142.A network administrator is tasked with designing a routing strategy for a large enterprise network. The...
  43. 143.A network administrator is tasked with designing a network that must support both fast convergence and...
  44. 144.A network engineer is designing a network that must support fast convergence, hierarchical segmentation, and...
  45. 145.You are tasked with configuring OSPFv2 in a network with multiple areas. The network includes a...
  46. 146.You are configuring OSPFv2 in a network with multiple normal areas. The network requires area summarization...
  47. 147.A network engineer is tasked with configuring OSPFv2 in a multi-area environment where Area 0 serves as the...
  48. 148.You are tasked with configuring an OSPF network in a multi-area environment. The network consists of Area 0...
  49. 149.An enterprise network engineer configures eBGP between two directly connected routers, R1 (AS 100) and R2 (AS...
  50. 150.You are configuring eBGP between two directly connected routers, R1 and R2, in different autonomous systems...
  51. 151.You are tasked with configuring eBGP between two directly connected routers, R1 and R2. Both routers have...
  52. 152.An enterprise network engineer is tasked with configuring eBGP between two directly connected routers, R1 and...
  53. 153.A network administrator is tasked with configuring policy-based routing (PBR) on a router to ensure that...
  54. 154.A network engineer is tasked with implementing policy-based routing (PBR) to ensure traffic from a specific...
  55. 155.A network engineer is tasked with implementing policy-based routing (PBR) on a router to ensure that specific...
  56. 156.A network engineer is tasked with implementing Policy-Based Routing (PBR) on a Cisco router to ensure that...
  57. 157.A network administrator is troubleshooting a wireless performance issue in a Cisco Enterprise network where...
  58. 158.A network administrator is tasked with designing a wireless network for a multi-story office building. The...
  59. 159.A network engineer is tasked with deploying a wireless network in a corporate environment that requires...
  60. 160.A network engineer is tasked with designing a wireless network for a corporate office. The network must...
  61. 161.You are troubleshooting a wireless network where users are reporting intermittent connectivity issues and...
  62. 162.A network engineer is troubleshooting a wireless connectivity issue in an office environment. Users are...
  63. 163.A network administrator is troubleshooting a wireless performance issue in a high-density office environment....
  64. 164.A network engineer is troubleshooting a wireless network where users are experiencing poor connectivity and...
  65. 165.A network engineer is deploying a wireless network in a large warehouse. The warehouse has high ceilings and...
  66. 166.An enterprise is deploying a Cisco wireless network to optimize coverage and minimize interference in a large...
  67. 167.A network engineer is deploying Cisco Access Points (APs) in a warehouse environment. The APs need to provide...
  68. 168.A network engineer is deploying a Cisco wireless network in a warehouse with high ceilings and large metal...
  69. 169.An enterprise network is deploying new access points (APs) which need to discover and join a Wireless LAN...
  70. 170.A network engineer has deployed a new lightweight access point (AP) in a branch office. The AP needs to...
  71. 171.An IT administrator is deploying new access points (APs) in an enterprise network. The APs must discover and...
  72. 172.A network engineer is deploying a new Cisco wireless network with multiple access points (APs) and wireless...
  73. 173.A large enterprise network has deployed multiple wireless LAN controllers (WLCs) in different locations....
  74. 174.An organization has deployed a wireless network across two buildings using a single SSID. Employees...
  75. 175.An enterprise network has deployed a wireless infrastructure across multiple buildings. Users frequently move...
  76. 176.A large enterprise has implemented a wireless network spanning multiple buildings on its campus. The network...
  77. 177.A network administrator is troubleshooting a wireless client connectivity issue. The client cannot connect to...
  78. 178.You are troubleshooting a wireless connectivity issue in a small office where multiple users are unable to...
  79. 179.A network administrator is troubleshooting a wireless client connectivity issue using the Cisco Wireless LAN...
  80. 180.You are an administrator troubleshooting a wireless client connectivity issue in a corporate WLAN. A user...
  81. 181.A network engineer is deploying a Cisco wireless infrastructure for a large enterprise. The engineer wants to...
  82. 182.A network administrator is designing a wireless network for a large enterprise environment. They want to...
  83. 183.A network administrator is configuring wireless segmentation in a Cisco environment to ensure proper...
  84. 184.A network administrator is configuring a Cisco wireless network to ensure proper segmentation for different...
  85. 185.A network administrator is configuring an enterprise network to ensure that specific traffic is directed to...
  86. 186.A network engineer is tasked with configuring DHCP services on a Cisco router to provide IP addresses to...
  87. 187.An enterprise network is experiencing issues with clients failing to access web applications hosted on a...
  88. 188.A network engineer is tasked with configuring DHCP services on a Cisco router to dynamically assign IP...
  89. 189.A network engineer has configured multiple switches in a network to use NTP for time synchronization....
  90. 190.A network engineer is troubleshooting an issue with time synchronization in a Cisco enterprise network. The...
  91. 191.A network engineer is troubleshooting time synchronization issues in a network using NTP. The following...
  92. 192.A network engineer is troubleshooting an issue where devices on a network are experiencing time...
  93. 193.A network engineer is tasked with configuring Port Address Translation (PAT) on a Cisco router to allow...
  94. 194.A network engineer is tasked with configuring NAT Overload (PAT) on a Cisco router to allow multiple internal...
  95. 195.A network engineer is tasked with configuring NAT on a Cisco router to allow internal hosts to access the...
  96. 196.You are configuring PAT (Port Address Translation) on a Cisco router to allow multiple internal devices to...
  97. 197.You are configuring a network with two routers that need to provide gateway redundancy for a subnet. You...
  98. 198.You are tasked with configuring a highly available gateway for a set of VLANs in your enterprise network. You...
  99. 199.An enterprise network has two routers configured as part of a redundancy group using HSRP. The network...
  100. 200.An enterprise network is deploying a first-hop redundancy protocol (FHRP) to ensure high availability for its...