CiscoProfessional level350-401Page 3 of 7

350-401 exam dumps: questions 201 to 300 of 629

Page 3 of the free 350-401 question bank for the Implementing Cisco Enterprise Network Core Technologies exam. Questions 201 to 300 are listed below, the first 5 in full with answers and explanations. Back to page 1 for the exam overview and FAQ.

Question bank last updated February 2025

Free 350-401 practice questions

Questions 201 to 205 of 629

Pick an answer before you open the explanation. Each question also has its own page with a permalink.

350-401 Question 201

Select 3

A network engineer is configuring multicast routing in a network. They observe that multicast traffic is not reaching the intended receivers. Upon investigation, they find that Reverse Path Forwarding (RPF) failures are occurring. Which of the following actions can help resolve the issue?

  1. A

    Ensure that the multicast source traffic is routed through the same interface as the RPF check.

  2. B

    Configure a static multicast route to override the RPF check.

  3. C

    Enable IGMP snooping on all Layer 2 switches in the path.

  4. D

    Verify that the unicast routing table has the correct source address entry.

  5. E

    Switch from PIM Sparse Mode to PIM Dense Mode.

Show answer and explanation

Correct answers: A, B, D

Explanation

Reverse Path Forwarding (RPF) is a fundamental check performed by multicast routers to ensure packets are arriving on the correct interface based on the source IP address. RPF failures occur when this check fails, often due to misaligned unicast routing or incorrect interface usage. Ensuring proper unicast routing, configuring static multicast routes if necessary, and verifying the multicast path alignment with the RPF check are effective ways to resolve such issues. IGMP snooping and switching PIM modes do not directly address RPF failures.

  • A. Correct.

    Ensuring that the multicast source traffic is routed through the same interface as the RPF check is necessary for the RPF check to succeed. If the traffic arrives on a different interface, the router will drop the packets.

  • B. Correct.

    A static multicast route can be configured to override the RPF check, allowing the traffic to pass even if the default unicast routing table does not align with the multicast path.

  • C. Incorrect.

    Enabling IGMP snooping on Layer 2 switches improves multicast efficiency by limiting traffic to only relevant ports, but it does not directly address RPF failures.

  • D. Correct.

    The RPF check uses the unicast routing table to determine the best path back to the source. If the unicast routing table is incorrect, it can cause RPF failures, so verifying the table is critical.

  • E. Incorrect.

    Switching to PIM Dense Mode changes how multicast traffic is forwarded but does not resolve RPF failures, as they pertain to the underlying unicast routing and RPF logic.

350-401 Question 202

Select 2

A network engineer is implementing multicast routing in an enterprise network that uses Protocol Independent Multicast (PIM) in Sparse Mode. During troubleshooting, the engineer observes that multicast traffic is not being forwarded correctly. Upon investigation, they discover that the Reverse Path Forwarding (RPF) check is failing. What could be the possible reasons for the RPF check failure?

  1. A

    The multicast routing table does not have a route to the source of the multicast traffic.

  2. B

    A unicast routing table entry for the source points to a different interface than the one receiving the multicast traffic.

  3. C

    The router does not have an IGMP membership report for the multicast group.

  4. D

    The source of the multicast traffic is in a different autonomous system, and BGP is not configured to propagate multicast routes.

  5. E

    The designated router (DR) has not been elected on the local segment.

Show answer and explanation

Correct answers: A, B

Explanation

The Reverse Path Forwarding (RPF) check is a key mechanism in multicast routing to ensure that multicast traffic flows along the correct path back to the source. For the RPF check to succeed, the router must have a valid route to the source in its unicast or multicast routing table, and the interface receiving the multicast traffic must match the interface used to reach the source. Failures in either of these conditions will cause the RPF check to fail, leading to dropped multicast packets.

  • A. Correct.

    Correct - The RPF check ensures that the router has a route to the source of the multicast traffic in its multicast routing table. If this route is missing, the RPF check will fail.

  • B. Correct.

    Correct - The RPF check verifies that the interface receiving the multicast traffic matches the interface used to reach the source in the unicast routing table. A mismatch will cause the RPF check to fail.

  • C. Incorrect.

    Incorrect - IGMP is used to manage group membership on a subnet but does not impact the RPF check, which focuses on source reachability and interface consistency.

  • D. Incorrect.

    Incorrect - While BGP can propagate multicast routes in certain scenarios, RPF check failures are not directly caused by the lack of BGP configuration across autonomous systems.

  • E. Incorrect.

    Incorrect - The election of a designated router (DR) is important for PIM operations on a segment but does not influence the RPF check.

350-401 Question 203

Single answer

A network engineer is troubleshooting a multicast routing issue in a campus network running PIM-SM (Protocol Independent Multicast - Sparse Mode). Hosts in one subnet report that they are unable to join a multicast group. The engineer verifies that the multicast group is active and that the appropriate traffic is being sent by the source. After inspecting the router's configuration, the engineer notices that the Reverse Path Forwarding (RPF) check is failing for the multicast traffic. What is the most likely reason for the RPF check failure?

  1. A

    The multicast source's route is missing from the unicast routing table.

  2. B

    The IGMP snooping feature is disabled on the switches.

  3. C

    The rendezvous point (RP) is not configured for the multicast group.

  4. D

    The multicast traffic is being forwarded through a non-designated router.

Show answer and explanation

Correct answer: A

Explanation

The RPF check ensures multicast traffic is received on the interface that aligns with the shortest path to the source, as determined by the unicast routing table. If the multicast source's route is missing from the unicast routing table, the router cannot verify the correct incoming interface, causing the RPF check to fail and the multicast traffic to be dropped.

  • A. Correct.

    The RPF check relies on the unicast routing table to determine the correct interface and path to the multicast source. If the source's route is missing, the RPF check will fail, causing multicast traffic to be dropped.

  • B. Incorrect.

    IGMP snooping is used by switches to limit multicast traffic to only interested receivers. While disabling IGMP snooping could cause unnecessary flooding, it does not directly cause RPF check failures.

  • C. Incorrect.

    The RP is necessary for building multicast distribution trees in PIM-SM. However, the absence of an RP does not lead to RPF check failures, as RPF is based on unicast routing rather than RP configuration.

  • D. Incorrect.

    The designated router (DR) is responsible for forwarding multicast traffic to the RP in a PIM-SM environment. However, traffic originating from a source does not rely on the DR for RPF checks, so this would not cause an RPF check failure.

350-401 Question 204

Select 3

A network engineer has configured multicast routing on a network using PIM-SM (Protocol Independent Multicast - Sparse Mode). During troubleshooting, they observe that multicast traffic is not being forwarded to a specific receiver. Upon investigation, they find that the Reverse Path Forwarding (RPF) check is failing. Which of the following could be causing the RPF check to fail?

  1. A

    The multicast source is not reachable through the interface used by the unicast routing table.

  2. B

    The multicast group address used is not registered with the Rendezvous Point (RP).

  3. C

    A unicast routing loop exists in the network topology.

  4. D

    The router does not have an entry for the multicast group in its IGMP membership table.

  5. E

    The router is using a different incoming interface for the source traffic than what the unicast routing table indicates.

Show answer and explanation

Correct answers: A, C, E

Explanation

RPF checks are a critical part of multicast routing to ensure that multicast traffic is received on the correct interface, as determined by the unicast routing table. Failures can occur if the source is unreachable, a unicast routing loop exists, or the multicast traffic arrives on an unexpected interface. Understanding these failure scenarios helps ensure proper multicast traffic forwarding.

  • A. Correct.

    RPF checks verify that the multicast source is reachable via the interface that the unicast routing table specifies. If the source is not reachable, the RPF check will fail.

  • B. Incorrect.

    PIM-SM requires the multicast group to be registered with the Rendezvous Point (RP), but this is unrelated to RPF checks. The RPF check is focused on verifying the source's reachability.

  • C. Correct.

    A unicast routing loop can cause the RPF check to fail because the router might receive the multicast traffic on an unexpected interface, violating the RPF rule.

  • D. Incorrect.

    IGMP membership tables are used to track multicast group memberships on the last-hop router. A missing IGMP entry does not directly impact the RPF check.

  • E. Correct.

    An RPF check fails if the multicast traffic arrives on an interface that does not match the interface specified by the unicast routing table for reaching the source.

350-401 Question 205

Single answer

A network administrator is using Cisco DNA Center to monitor their enterprise network. The administrator notices an unexpected increase in latency for several critical applications. Which tool or feature within Cisco DNA Center should the administrator use to identify the root cause of the issue?

  1. A

    Path Trace

  2. B

    Application Experience Analytics

  3. C

    Assurance Issues Dashboard

  4. D

    Network Hierarchy Management

Show answer and explanation

Correct answer: C

Explanation

The Assurance Issues Dashboard in Cisco DNA Center provides valuable insights into network health and performance. It highlights problems such as latency, packet loss, and device issues, helping administrators pinpoint the root cause and take corrective actions. This makes it the most appropriate tool for troubleshooting unexpected latency in critical applications.

  • A. Incorrect.

    Path Trace helps visualize the traffic path through the network but is not directly used for identifying latency-related issues.

  • B. Incorrect.

    Application Experience Analytics provides insights into application performance but is more focused on end-user experiences rather than diagnosing network latency.

  • C. Correct.

    The Assurance Issues Dashboard in Cisco DNA Center is specifically designed to help administrators identify and troubleshoot network issues, including latency problems.

  • D. Incorrect.

    Network Hierarchy Management is used for organizing and managing the network topology but does not assist in diagnosing performance issues.

Timed practice exam

Take a 350-401 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam

350-401 practice questions 201 to 300 of 629

Every question has a page with the answer and explanation. Numbers are stable, so you can bookmark or share them. The bank is split into 7 pages of up to 100 questions.

  1. 201.A network engineer is configuring multicast routing in a network. They observe that multicast traffic is not...
  2. 202.A network engineer is implementing multicast routing in an enterprise network that uses Protocol Independent...
  3. 203.A network engineer is troubleshooting a multicast routing issue in a campus network running PIM-SM (Protocol...
  4. 204.A network engineer has configured multicast routing on a network using PIM-SM (Protocol Independent Multicast...
  5. 205.A network administrator is using Cisco DNA Center to monitor their enterprise network. The administrator...
  6. 206.A network engineer is using Cisco DNA Center to monitor a corporate network. They notice that certain...
  7. 207.An enterprise network engineer is using Cisco DNA Center to troubleshoot a client connectivity issue. The...
  8. 208.A network engineer is troubleshooting an application performance issue in a Cisco DNA Center-enabled network....
  9. 209.A network engineer is troubleshooting a connectivity issue between two routers in an enterprise network. The...
  10. 210.A network administrator is troubleshooting a connectivity issue between two routers on different subnets. The...
  11. 211.A network administrator is troubleshooting a connectivity issue between two routers, R1 and R2, in a large...
  12. 212.A network administrator is troubleshooting a connectivity issue where a specific user cannot access a web...
  13. 213.You are tasked to configure Flexible NetFlow (FNF) on a Cisco router to monitor specific traffic patterns in...
  14. 214.An enterprise network engineer is tasked with configuring Flexible NetFlow on a Cisco router to monitor...
  15. 215.You are tasked with configuring Flexible NetFlow on a Cisco router to monitor network traffic. The...
  16. 216.You are tasked with monitoring traffic patterns on a network by using Cisco Flexible NetFlow. You want to...
  17. 217.A network administrator is tasked with configuring a switch to monitor traffic from multiple VLANs and send...
  18. 218.A network engineer needs to monitor traffic on a specific VLAN across multiple switches in a network. The...
  19. 219.You are tasked with monitoring traffic from multiple interfaces on a switch and sending the mirrored traffic...
  20. 220.A network administrator wants to monitor traffic from specific VLANs on multiple switches in a network and...
  21. 221.A network engineer is tasked with monitoring the performance of a critical WAN link between two branch...
  22. 222.An enterprise network administrator is tasked with monitoring the response time of a critical application...
  23. 223.An enterprise network engineer is tasked with monitoring network performance between two routers using IPSLA....
  24. 224.A network engineer is tasked with ensuring reliable connectivity between two branch locations. They decide to...
  25. 225.A network administrator is tasked with configuring a new VLAN across multiple network devices using Cisco DNA...
  26. 226.An organization is using Cisco DNA Center to manage their network. The network administrator needs to deploy...
  27. 227.An organization is using Cisco DNA Center to manage its network. The IT administrator needs to deploy a new...
  28. 228.You are configuring a Cisco router to interact with a network management system (NMS) that uses RESTCONF to...
  29. 229.You are tasked with configuring RESTCONF on a Cisco IOS XE device to enable network programmability. After...
  30. 230.A network engineer is tasked with configuring RESTCONF on a Cisco IOS XE device to enable programmatic access...
  31. 231.You are tasked with configuring a Cisco device to use RESTCONF for network automation. You have already...
  32. 232.A network administrator is tasked with securing a branch office connected to the corporate network over a...
  33. 233.A network administrator is tasked with securing the enterprise network by implementing a solution that...
  34. 234.A network administrator is tasked with implementing secure access to network devices across an enterprise...
  35. 235.You are tasked with securing a branch office network that uses Cisco devices. The organization requires...
  36. 236.An administrator is configuring device access control on a Cisco router to ensure secure remote management....
  37. 237.A network administrator wants to restrict access to a Cisco device such that only users from a specific...
  38. 238.A network administrator is tasked with securing access to a Cisco router. The administrator wants to ensure...
  39. 239.A network administrator needs to restrict access to a Cisco router to certain administrative users. The...
  40. 240.An administrator is configuring a Cisco router to allow local user authentication for remote management using...
  41. 241.A network administrator is configuring a Cisco router's line console for local user authentication. The...
  42. 242.You are configuring a Cisco router to allow administrative access using local user authentication. The goal...
  43. 243.A network administrator is configuring a Cisco router for local user authentication on the console line. They...
  44. 244.A network administrator has configured AAA on a Cisco router to authenticate users accessing the network...
  45. 245.A network engineer is configuring AAA authentication and authorization on a Cisco router to ensure secure...
  46. 246.A network engineer is configuring centralized authentication and authorization for a group of network devices...
  47. 247.An enterprise network administrator is configuring a Cisco network device to use a centralized authentication...
  48. 248.A network administrator is tasked with securing access to network devices in an enterprise environment. They...
  49. 249.You are tasked with securing a Layer 2 network that is vulnerable to attacks such as MAC address spoofing and...
  50. 250.An enterprise network administrator is tasked with securing the network infrastructure. The administrator...
  51. 251.An enterprise network administrator is tasked with securing the infrastructure by limiting the risk of...
  52. 252.A network administrator is tasked with configuring an ACL to allow only HTTP traffic from the 192.168.10.0/24...
  53. 253.A network administrator is tasked with securing a network by creating an Access Control List (ACL) to prevent...
  54. 254.A network administrator is tasked with implementing an ACL on a router to allow HTTP and HTTPS traffic from a...
  55. 255.A network administrator observes that excessive ARP requests and ICMP traffic directed at the control plane...
  56. 256.An enterprise network administrator has noticed high CPU utilization on a Cisco router due to excessive...
  57. 257.An organization has been experiencing intermittent network outages due to high CPU utilization on their edge...
  58. 258.A network administrator notices excessive CPU utilization on a Cisco router due to a high volume of malicious...
  59. 259.An enterprise network engineer is tasked with designing a secure REST API implementation for a network...
  60. 260.A network administrator is designing a REST API-based solution to manage network devices. They are concerned...
  61. 261.An organization is designing a REST API to manage network devices. To ensure secure communication and...
  62. 262.A network engineer is implementing a REST API solution for a Cisco network device. To ensure secure...
  63. 263.A network administrator is tasked with securing the wireless network in a corporate environment. The company...
  64. 264.A company is deploying a new wireless network and wants to ensure that only authorized devices can connect to...
  65. 265.Your organization is deploying a new wireless network, and you are tasked with ensuring that it is secured...
  66. 266.A network administrator is tasked with securing a wireless network in a corporate environment. The security...
  67. 267.A network administrator is configuring 802.1X authentication on a Cisco switch to secure access to the...
  68. 268.A network administrator is configuring 802.1X authentication on a Cisco switch to secure access to the...
  69. 269.A network engineer is configuring 802.1X authentication on a corporate network. The engineer needs to ensure...
  70. 270.A network engineer is configuring 802.1X on a Cisco switch to secure port access. The engineer notices that...
  71. 271.A network engineer is configuring WebAuth on a Cisco Wireless LAN Controller (WLC) to provide guest access....
  72. 272.An enterprise network administrator has configured WebAuth for guest users on a WLAN. However, users are...
  73. 273.A network engineer is implementing WebAuth on a Cisco Wireless LAN Controller (WLC) to provide guest access....
  74. 274.A network administrator is configuring WebAuth on a Cisco wireless LAN controller (WLC) to allow guest users...
  75. 275.A network administrator is configuring a wireless network for a branch office. The administrator decides to...
  76. 276.A network engineer is configuring a wireless network for a small branch office. The network must use a...
  77. 277.A network engineer is configuring a wireless network for a small office. The engineer decides to use a...
  78. 278.A network engineer is tasked with configuring a wireless network for a remote branch office. The branch...
  79. 279.A network administrator is troubleshooting a wireless network where clients are unable to connect to a...
  80. 280.An enterprise network uses WPA3-Enterprise for wireless authentication. During a packet capture, you observe...
  81. 281.A network administrator is troubleshooting a wireless connectivity issue between a client device and a...
  82. 282.A network engineer is troubleshooting a WPA2-Enterprise wireless network where some clients are failing to...
  83. 283.An organization is designing a new network security solution for its enterprise network. The design must...
  84. 284.A company is designing a secure enterprise network for its headquarters. The IT team wants to ensure that...
  85. 285.An enterprise network is undergoing a security redesign to better protect against external threats and ensure...
  86. 286.A company is designing its enterprise network security architecture. The requirements include segmenting the...
  87. 287.Your organization has deployed Cisco Firepower Threat Defense (FTD) to enhance network security. During an...
  88. 288.A network administrator is tasked with implementing threat defense mechanisms to protect an enterprise...
  89. 289.An enterprise network administrator is tasked with implementing threat defense mechanisms on the company’s...
  90. 290.A network administrator has deployed Cisco Firepower Threat Defense (FTD) to protect their enterprise...
  91. 291.An organization is deploying endpoint security measures to protect its enterprise network. Which of the...
  92. 292.An organization is deploying endpoint security to protect its devices, including laptops and mobile phones,...
  93. 293.An organization has deployed Cisco Identity Services Engine (ISE) to enforce endpoint security policies. The...
  94. 294.A network administrator is tasked with implementing endpoint security to reduce the risk of malware and...
  95. 295.A network administrator has deployed a Next-Generation Firewall (NGFW) to secure their enterprise network....
  96. 296.An enterprise network administrator is configuring a next-generation firewall (NGFW) to secure the network...
  97. 297.A network administrator is deploying a next-generation firewall (NGFW) in a corporate environment to improve...
  98. 298.An organization has implemented a next-generation firewall (NGFW) to enhance its network security. The...
  99. 299.A network engineer is tasked with implementing a secure communication strategy for a Cisco campus network....
  100. 300.A network administrator is tasked with implementing enhanced security for sensitive traffic between switches...