CiscoProfessional level350-401Page 4 of 7

350-401 exam dumps: questions 301 to 400 of 629

Page 4 of the free 350-401 question bank for the Implementing Cisco Enterprise Network Core Technologies exam. Questions 301 to 400 are listed below, the first 5 in full with answers and explanations. Back to page 1 for the exam overview and FAQ.

Question bank last updated February 2025

Free 350-401 practice questions

Questions 301 to 305 of 629

Pick an answer before you open the explanation. Each question also has its own page with a permalink.

350-401 Question 301

Select 3

An enterprise network is deploying Cisco TrustSec to ensure secure communication between devices across their network. The network administrator wants to classify traffic based on Security Group Tags (SGTs) and enforce policy-based access controls. Additionally, the administrator is considering deploying MACsec to secure communication at Layer 2. Which of the following statements are correct about TrustSec and MACsec in this scenario?

  1. A

    Cisco TrustSec uses SGTs to classify traffic and enforce access control policies.

  2. B

    MACsec provides end-to-end encryption at the IP layer across the network.

  3. C

    Cisco TrustSec can operate without requiring 802.1X for SGT propagation.

  4. D

    MACsec encrypts Layer 2 traffic and protects against eavesdropping and tampering.

  5. E

    Cisco TrustSec and MACsec are mutually exclusive and cannot be deployed together.

Show answer and explanation

Correct answers: A, C, D

Explanation

Cisco TrustSec and MACsec are complementary technologies that enhance network security. TrustSec uses SGTs to classify and control traffic, while MACsec provides encryption and integrity at Layer 2. TrustSec does not strictly require 802.1X for SGT propagation, making it flexible for different deployment scenarios. Together, these technologies provide a robust security framework for enterprise networks.

  • A. Correct.

    Correct: Cisco TrustSec uses SGTs to classify traffic and enforce security policies. SGTs allow for scalable and flexible policy management in the network.

  • B. Incorrect.

    Incorrect: MACsec operates at Layer 2 and does not provide encryption at the IP layer. It secures Ethernet frames between directly connected devices.

  • C. Correct.

    Correct: While 802.1X is often used for SGT propagation, Cisco TrustSec can also use alternative methods such as inline tagging or manual configuration.

  • D. Correct.

    Correct: MACsec secures Layer 2 communication by encrypting Ethernet frames, providing protection against eavesdropping and tampering.

  • E. Incorrect.

    Incorrect: Cisco TrustSec and MACsec are complementary technologies and can be deployed together. TrustSec adds policy-based access control while MACsec provides Layer 2 encryption.

350-401 Question 302

Select 3

An enterprise network administrator is tasked with ensuring data integrity and confidentiality between switches in the campus network. The network is configured with TrustSec for scalable security policies and uses MACsec for link-layer encryption. During implementation, the administrator encounters a situation where TrustSec works as expected, but MACsec fails to establish. Which of the following could be the reason for MACsec failure?

  1. A

    The switches do not support IEEE 802.1AE (MACsec) on the physical interfaces.

  2. B

    The TrustSec Security Group Tag (SGT) is not properly assigned to the devices.

  3. C

    The key agreement protocol (MKA) is not enabled on the interfaces.

  4. D

    The physical link between the switches is not configured as a trunk.

  5. E

    The switches are configured in different MACsec key agreement (MKA) policy modes.

Show answer and explanation

Correct answers: A, C, E

Explanation

MACsec relies on specific hardware and software configurations to function. For MACsec to successfully establish, the physical interfaces must support IEEE 802.1AE, the MACsec Key Agreement (MKA) protocol must be enabled to negotiate encryption keys, and the MKA policy modes on both switches must match. TrustSec and trunk configurations, while related to broader network functionality, are not directly responsible for MACsec encryption failures.

  • A. Correct.

    If the switches' physical interfaces do not support IEEE 802.1AE (MACsec), MACsec encryption cannot be established. This is a hardware feature that must be supported on the interfaces.

  • B. Incorrect.

    TrustSec Security Group Tags (SGTs) are used for policy enforcement and segmentation, but they do not affect the establishment of MACsec encryption. This is not a reason for MACsec failure.

  • C. Correct.

    The MACsec Key Agreement (MKA) protocol is essential for negotiating and managing encryption keys for MACsec. If MKA is not enabled, MACsec will fail to establish.

  • D. Incorrect.

    While trunk links are commonly used between switches, MACsec can also operate on access links. The link not being a trunk is not a cause for MACsec failure.

  • E. Correct.

    If the switches are configured with different MKA policy modes (e.g., static vs. dynamic), they cannot successfully negotiate encryption keys, causing MACsec to fail.

350-401 Question 303

Select 2

An enterprise network is implementing network access control on its wired switches. The goal is to ensure only authenticated devices can gain network access using 802.1X, but some legacy devices do not support 802.1X. The network administrator has configured fallback mechanisms to provide controlled access for these legacy devices. Which combination of mechanisms should the administrator use to achieve this?

  1. A

    Configure 802.1X for devices that support it, and use MAC Authentication Bypass (MAB) for legacy devices.

  2. B

    Use WebAuth as the sole authentication mechanism for all devices.

  3. C

    Enable 802.1X for capable devices and configure WebAuth as a fallback for legacy devices.

  4. D

    Rely solely on MAC Authentication Bypass (MAB) for all devices, including 802.1X-capable ones.

  5. E

    Combine 802.1X for authentication and implement WebAuth for guest access.

Show answer and explanation

Correct answers: A, C

Explanation

802.1X is the most secure method for authenticating devices and should be used wherever possible. For devices that do not support 802.1X, fallback mechanisms such as MAB or WebAuth can be configured to provide controlled access. Using both 802.1X and a fallback mechanism like WebAuth ensures a secure and flexible approach that accommodates a variety of device capabilities in the network.

  • A. Correct.

    This is correct because 802.1X is the primary mechanism for capable devices, while MAB can provide fallback for devices unable to use 802.1X.

  • B. Incorrect.

    This is incorrect because WebAuth is not suitable as the sole mechanism for network access control in environments where 802.1X can be utilized. It is better suited for guest networks or fallback scenarios.

  • C. Correct.

    This is correct because combining 802.1X for capable devices and WebAuth for legacy devices provides a flexible approach to network access control.

  • D. Incorrect.

    This is incorrect because relying solely on MAB does not leverage the stronger security provided by 802.1X for capable devices.

  • E. Incorrect.

    This is partially correct conceptually, but it does not address the use of WebAuth as a fallback specifically for legacy devices that cannot use 802.1X.

350-401 Question 304

Select 3

A network administrator is configuring access control on a switch for a corporate office. The goal is to authenticate users connecting to the network via wired connections by requiring them to provide valid credentials. However, some legacy devices, such as printers, do not support 802.1X authentication. The administrator also wants to enable guest access for non-employee devices using a web portal. Which combination of network access control methods should the administrator implement to meet these requirements?

  1. A

    802.1X for user authentication

  2. B

    MAC Authentication Bypass (MAB) for legacy devices

  3. C

    WebAuth for guest access

  4. D

    Port security with static MAC addresses for all devices

  5. E

    802.1X for guest access instead of WebAuth

Show answer and explanation

Correct answers: A, B, C

Explanation

To meet the requirements, the administrator should use 802.1X to authenticate users with valid credentials, MAB for legacy devices that cannot perform 802.1X authentication, and WebAuth to enable guest access via a web portal. This combination ensures secure access for employees, support for legacy devices, and a simple onboarding process for guest users. Port security is too rigid for this environment, and 802.1X is not appropriate for guest access.

  • A. Correct.

    802.1X is the preferred method for authenticating users connecting to the network with valid credentials, such as employees using laptops or desktops.

  • B. Correct.

    MAC Authentication Bypass (MAB) allows devices that do not support 802.1X (e.g., printers or other legacy devices) to authenticate based on their MAC address.

  • C. Correct.

    WebAuth is typically used to provide guest access through a web portal, allowing non-employees to connect to the network after providing appropriate details.

  • D. Incorrect.

    Port security with static MAC addresses is not scalable or flexible in this scenario, as it would require manual configuration of MAC addresses for all devices, including guest devices and legacy devices.

  • E. Incorrect.

    802.1X is not suitable for guest access because guest devices often do not have the necessary credentials or configuration required for 802.1X authentication.

350-401 Question 305

Select 2

A network administrator is configuring network access control on a Cisco switch to provide secure authentication for endpoints. The requirement is to authenticate corporate devices using certificates, while allowing guest devices with no 802.1X capability to access a web-based authentication portal. What combination of methods should the administrator configure?

  1. A

    802.1X for corporate devices and MAB for guest devices

  2. B

    MAB for corporate devices and WebAuth for guest devices

  3. C

    802.1X for corporate devices and WebAuth for guest devices

  4. D

    802.1X for corporate devices only, with no authentication for guest devices

  5. E

    WebAuth for both corporate and guest devices

Show answer and explanation

Correct answers: A, C

Explanation

In this scenario, 802.1X is the best solution for corporate devices as it provides secure, certificate-based authentication. However, guest devices often lack 802.1X capabilities, making WebAuth a suitable option to redirect them to a portal for authentication. Combining these two methods ensures secure and flexible access control for both corporate and guest devices.

  • A. Correct.

    Correct. 802.1X is suitable for authenticating corporate devices using certificates, and MAB (MAC Authentication Bypass) can serve as a fallback mechanism. However, in this scenario, WebAuth is preferred for guest devices as it provides a user-friendly portal for access.

  • B. Incorrect.

    Incorrect. MAB is not typically used for corporate devices as it does not provide strong authentication. WebAuth is better suited for guest devices.

  • C. Correct.

    Correct. 802.1X is ideal for corporate devices leveraging certificates, while WebAuth provides a convenient method for guest devices without 802.1X support to authenticate via a web portal.

  • D. Incorrect.

    Incorrect. Not authenticating guest devices would pose a security risk. A mechanism like WebAuth should be implemented for guest access control.

  • E. Incorrect.

    Incorrect. Using WebAuth for corporate devices does not meet the requirement of certificate-based authentication for secure corporate access.

Timed practice exam

Take a 350-401 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam

350-401 practice questions 301 to 400 of 629

Every question has a page with the answer and explanation. Numbers are stable, so you can bookmark or share them. The bank is split into 7 pages of up to 100 questions.

  1. 301.An enterprise network is deploying Cisco TrustSec to ensure secure communication between devices across their...
  2. 302.An enterprise network administrator is tasked with ensuring data integrity and confidentiality between...
  3. 303.An enterprise network is implementing network access control on its wired switches. The goal is to ensure...
  4. 304.A network administrator is configuring access control on a switch for a corporate office. The goal is to...
  5. 305.A network administrator is configuring network access control on a Cisco switch to provide secure...
  6. 306.A company is configuring network access control to secure its wired and wireless network. They want to use...
  7. 307.A network engineer is tasked with automating device configuration updates across an enterprise network. The...
  8. 308.A network engineer has been tasked with automating the configuration of multiple VLANs across a large...
  9. 309.A network engineer is tasked with automating the configuration of multiple Cisco devices in the enterprise...
  10. 310.You are tasked with creating a Python script that interacts with a network device using a REST API. The...
  11. 311.A network engineer has written the following Python script to retrieve the hostname of a Cisco device via...
  12. 312.A network engineer is tasked with automating the retrieval of interface status from a Cisco switch using a...
  13. 313.A network engineer is tasked with writing a Python script to automate the retrieval of interface status from...
  14. 314.You are configuring a network automation script, and the script requires a valid JSON-encoded file to define...
  15. 315.You are tasked with creating a JSON-encoded configuration file to define a VLAN and its properties for a...
  16. 316.You are tasked with creating a JSON configuration file for a network automation tool. The file needs to...
  17. 317.You are tasked with creating a JSON-encoded file that will be used to configure a network device. The file...
  18. 318.A network engineer is tasked with configuring a network automation solution for a multi-vendor environment....
  19. 319.An enterprise network engineer is tasked with implementing a network automation solution. The engineer...
  20. 320.A network engineer is tasked with implementing a network automation solution to simplify device...
  21. 321.A network engineer is tasked with automating the configuration of multiple network devices in a way that...
  22. 322.An enterprise network engineer is tasked with automating the deployment of new branch sites using Cisco...
  23. 323.A network engineer wants to automate the provisioning of devices and monitor network health using Cisco DNA...
  24. 324.An organization is using Cisco DNA Center to automate their network operations and wants to integrate a...
  25. 325.A network administrator wants to automate the deployment of new policies across the network using Cisco DNA...
  26. 326.You are using Cisco DNA Center's REST API to retrieve a list of network devices in your organization. The API...
  27. 327.You are using Cisco DNA Center's REST API to retrieve network device information. Upon making a GET request...
  28. 328.You are using the Cisco DNA Center REST API to retrieve information about network devices. When you send a...
  29. 329.A network engineer is using Cisco DNA Center's REST API to retrieve device information. The API request...
  30. 330.A network engineer needs to automate the collection of interface error statistics on a Cisco router every...
  31. 331.A network engineer is tasked with automating the process of collecting interface status data on a Cisco...
  32. 332.You are tasked with automating the collection of interface status on a Cisco router every time an interface...
  33. 333.A network administrator wants to automate the collection of interface error statistics on a Cisco router...
  34. 334.An enterprise network engineer is tasked with automating configuration management across a large-scale...
  35. 335.A network engineer is tasked with automating the configuration of multiple network devices in a large...
  36. 336.You are tasked with deploying configuration management for a new network infrastructure. Your team requires a...
  37. 337.A network engineer is tasked with automating the configuration of hundreds of Cisco devices in a data center....
  38. 339.An enterprise network engineer is configuring OSPF in a multi-area environment. The network consists of...
  39. 340.A network engineer is configuring OSPF between two routers, R1 and R2, in the same area (Area 0). After...
  40. 341.You are configuring OSPF on a network with multiple routers. Router R1 has two interfaces: GigabitEthernet0/0...
  41. 342.An enterprise network is running OSPF as its routing protocol. The network administrator notices that a...
  42. 343.A network administrator is tasked with implementing a new routing protocol in a multi-vendor environment. The...
  43. 344.A network engineer notices that a router is preferring routes from OSPF over EIGRP, even though EIGRP should...
  44. 345.A network engineer is troubleshooting a route selection issue in a multi-protocol environment. OSPF, EIGRP,...
  45. 346.A network engineer is troubleshooting a routing issue in a multi-protocol environment. The network consists...
  46. 347.A network engineer observes that a router is selecting OSPF routes over EIGRP routes in the routing table,...
  47. 348.A network engineer has configured a router that is connected to two upstream routers. OSPF is running on one...
  48. 349.A network engineer has configured a route map to filter specific routes advertised from one OSPF area to...
  49. 350.A network engineer has configured a route map to filter prefixes being redistributed from OSPF into BGP....
  50. 351.A network engineer is troubleshooting a route-map applied to a BGP neighbor in an enterprise network. The...
  51. 352.A network engineer configured a route map named 'TAGGING' to tag specific routes before redistributing them...
  52. 353.A network engineer is troubleshooting a route map applied to an OSPF process to filter specific routes. The...
  53. 354.A network engineer is troubleshooting routing issues in an OSPF-based network. Upon inspection, it is...
  54. 355.A network engineer is troubleshooting a routing issue in a multi-vendor network. They observe that a route is...
  55. 356.A network engineer is troubleshooting a routing loop issue in a small enterprise network. The network uses...
  56. 357.A network engineer is troubleshooting a routing issue in their OSPF network. A specific route is not being...
  57. 358.You have a network where OSPF and EIGRP are running on different parts of the network. Redistribution between...
  58. 359.A network engineer has configured route redistribution between OSPF and BGP on a Cisco router. However, the...
  59. 360.A network engineer is troubleshooting route redistribution between OSPF and EIGRP on a dual-protocol network....
  60. 361.A network engineer is troubleshooting an issue where OSPF routes are not being redistributed into the EIGRP...
  61. 362.A network engineer is troubleshooting a redistribution issue between OSPF and EIGRP. The OSPF routes are not...
  62. 363.A network engineer is troubleshooting a routing issue in an OSPF environment. The engineer notices that...
  63. 364.A network engineer has configured manual summarization on Router A for EIGRP. However, some routes in the...
  64. 365.A network engineer has configured EIGRP on multiple routers in an enterprise network. The engineer notices...
  65. 366.A network administrator is troubleshooting a routing issue in a network using EIGRP. The administrator...
  66. 367.A network administrator is troubleshooting an OSPF network where manual summarization was configured on an...
  67. 368.A network engineer is tasked with configuring policy-based routing (PBR) on a Cisco router to force traffic...
  68. 369.A network administrator needs to implement policy-based routing (PBR) on a router to ensure that all HTTP...
  69. 370.A network engineer is tasked with configuring policy-based routing (PBR) on a Cisco router. The goal is to...
  70. 371.A network engineer is tasked with configuring policy-based routing (PBR) to direct traffic from a specific...
  71. 372.A network engineer is tasked with implementing Policy-Based Routing (PBR) on a Cisco router to ensure that...
  72. 373.A network engineer is tasked with segmenting a network into multiple virtual routing domains using VRF-Lite....
  73. 374.You are tasked with configuring VRF-Lite on a Cisco router to segment traffic between two departments: HR and...
  74. 375.You are tasked with segmenting traffic for two different departments, HR and Finance, on a single router...
  75. 376.An enterprise network engineer is tasked with segmenting traffic for different departments using VRF-Lite....
  76. 377.An enterprise network administrator has configured VRF-Lite on a router to separate traffic for two different...
  77. 378.An enterprise network engineer is configuring Bidirectional Forwarding Detection (BFD) to monitor the...
  78. 379.A network engineer has configured Bidirectional Forwarding Detection (BFD) on an OSPF-enabled router to...
  79. 380.A network engineer is tasked with implementing Bidirectional Forwarding Detection (BFD) to improve failure...
  80. 381.An enterprise network administrator is troubleshooting a routing issue between two devices connected over a...
  81. 382.An enterprise network is using Bidirectional Forwarding Detection (BFD) to monitor the health of a critical...
  82. 383.A network engineer is troubleshooting EIGRP in a multi-VRF environment on a router configured with EIGRP...
  83. 384.A network engineer is troubleshooting an EIGRP (classic mode) routing issue. OSPF and EIGRP are running on...
  84. 385.A network engineer is troubleshooting an EIGRP issue in a multi-VRF environment. The EIGRP process in the VRF...
  85. 386.A network engineer is troubleshooting an EIGRP issue where an EIGRP neighbor relationship between two routers...
  86. 387.A network engineer is troubleshooting an EIGRP issue between two routers, R1 and R2, which are directly...
  87. 388.A network engineer is configuring a BGP session between two routers to exchange both IPv4 and IPv6 routes....
  88. 389.You are configuring a network that uses both IPv4 and IPv6 address families. To optimize routing exchange...
  89. 390.A network engineer is configuring a BGP session between two routers to exchange both IPv4 and IPv6 routes....
  90. 391.A network engineer is configuring BGP on a router to support both IPv4 and IPv6 address families. Which...
  91. 392.A network engineer is configuring MP-BGP to support both IPv4 and IPv6 address families on a router. After...
  92. 393.You are configuring OSPF between two routers in your network. Despite matching configurations, the OSPF...
  93. 394.A network engineer is configuring OSPF between two routers, R1 and R2. Both routers are directly connected,...
  94. 395.A network administrator is configuring OSPF between two routers, R1 and R2. Despite having matching OSPF...
  95. 396.A network engineer is configuring OSPF authentication between two routers, RouterA and RouterB. After...
  96. 397.You are configuring OSPF between two routers, R1 and R2, in Area 0. Despite ensuring that both routers use...
  97. 398.A network engineer is configuring EIGRP in a network and needs to ensure that a backup route is available in...
  98. 399.A network engineer is troubleshooting an EIGRP network. A route to the 192.168.10.0/24 network is not being...
  99. 400.A network engineer is troubleshooting an EIGRP-enabled network. Router R1 has multiple paths to reach a...
  100. 401.A network engineer is troubleshooting EIGRP routing in a network and notices that a specific route is not...