CiscoProfessional level350-401Page 6 of 7

350-401 exam dumps: questions 501 to 600 of 629

Page 6 of the free 350-401 question bank for the Implementing Cisco Enterprise Network Core Technologies exam. Questions 501 to 600 are listed below, the first 5 in full with answers and explanations. Back to page 1 for the exam overview and FAQ.

Question bank last updated February 2025

Free 350-401 practice questions

Questions 502 to 506 of 629

Pick an answer before you open the explanation. Each question also has its own page with a permalink.

350-401 Question 502

Select 3

A service provider is implementing an MPLS Layer 3 VPN for a customer with multiple sites. The customer requires routing information to remain isolated between their VPN and other customers' VPNs. Which two mechanisms are used in MPLS Layer 3 VPNs to ensure this isolation and proper routing?

  1. A

    Multiprotocol BGP (MP-BGP) to exchange VPN routing information

  2. B

    Route Distinguisher (RD) to uniquely identify overlapping routes in different VPNs

  3. C

    Label Distribution Protocol (LDP) to direct VPN traffic to the correct site

  4. D

    Route Target (RT) to control route import/export between VRFs

  5. E

    Interior Gateway Protocol (IGP) to propagate VPN routes within the MPLS network

Show answer and explanation

Correct answers: A, B, D

Explanation

MPLS Layer 3 VPNs rely on MP-BGP for advertising VPN-specific routes, RDs for ensuring unique identification of overlapping routes, and RTs for controlling import/export of routes between VRFs. These mechanisms collectively ensure routing isolation and correct traffic forwarding for multiple customer VPNs. LDP and IGPs are used in different contexts within the MPLS network but are not directly responsible for VPN route isolation.

  • A. Correct.

    Correct. MP-BGP is the protocol used to distribute VPNv4 or VPNv6 routing information between PE routers while keeping VPNs isolated.

  • B. Correct.

    Correct. RDs allow overlapping IP addresses in different VPNs to be uniquely identified, ensuring routing table isolation.

  • C. Incorrect.

    Incorrect. LDP is used for label distribution but does not directly handle VPN traffic isolation or routing information exchange.

  • D. Correct.

    Correct. RTs are used to control which routes are imported/exported between VRFs, enabling route segregation and policy enforcement.

  • E. Incorrect.

    Incorrect. IGPs like OSPF or EIGRP are not used for propagating VPN-specific routes; MP-BGP handles this function in MPLS Layer 3 VPNs.

350-401 Question 503

Single answer

A service provider is deploying an MPLS Layer 3 VPN to provide secure connectivity between multiple customer sites. The provider uses MP-BGP to distribute VPN routing information. Which of the following is a key characteristic of MPLS Layer 3 VPNs that enables the segregation of customer traffic?

  1. A

    The use of VRFs (Virtual Routing and Forwarding) on the provider edge routers

  2. B

    The use of VLAN tags to differentiate customer traffic

  3. C

    The use of RSVP-TE tunnels to ensure traffic separation

  4. D

    The use of GRE tunnels for customer traffic encapsulation

Show answer and explanation

Correct answer: A

Explanation

MPLS Layer 3 VPNs achieve customer traffic segregation through the use of VRFs on PE routers. Each customer is assigned a unique VRF, which isolates their routing information from other customers. MP-BGP is used to exchange VPN route information between PE routers, and MPLS labels are used to forward packets through the provider's MPLS backbone. This ensures secure and efficient connectivity for each customer.

  • A. Correct.

    Correct: VRFs are used on provider edge (PE) routers to maintain separate routing tables for each customer's traffic, ensuring traffic segregation and privacy.

  • B. Incorrect.

    Incorrect: VLAN tags are commonly used in Layer 2 networks, not MPLS Layer 3 VPNs. MPLS Layer 3 VPNs rely on VRFs and MPLS labels for traffic segregation.

  • C. Incorrect.

    Incorrect: RSVP-TE is a mechanism for traffic engineering and does not inherently provide the traffic segregation functionality required in MPLS Layer 3 VPNs.

  • D. Incorrect.

    Incorrect: GRE tunnels are used for general tunneling purposes, but MPLS Layer 3 VPNs use MPLS labels and VRFs for traffic segregation.

350-401 Question 504

Select 3

An enterprise customer has multiple branch offices connected via a service provider MPLS Layer 3 VPN. The customer requires that traffic between branches is isolated from other customers using the same service provider network, while still allowing each branch to communicate directly with other branches. Which two characteristics of MPLS Layer 3 VPNs support this requirement?

  1. A

    Each customer's routing information is stored in a separate Virtual Routing and Forwarding (VRF) table.

  2. B

    The service provider uses MPLS labels to segregate traffic between different customers.

  3. C

    The customer must use the same IP addressing scheme as the service provider.

  4. D

    BGP is used to exchange VPN routing information between the provider edge (PE) routers.

  5. E

    Traffic between customer branches is encrypted using IPSec tunnels by default.

Show answer and explanation

Correct answers: A, B, D

Explanation

MPLS Layer 3 VPNs enable the service provider to isolate customer traffic by using VRF tables and MPLS labels, ensuring that traffic from one customer does not interfere with another. BGP is utilized to exchange routing information between PE routers, facilitating branch-to-branch communication. These mechanisms fulfill the requirements of traffic isolation and inter-branch communication without requiring the use of IPSec or IP scheme integration with the service provider.

  • A. Correct.

    Correct: VRF tables ensure routing information is isolated for each customer, providing traffic segregation.

  • B. Correct.

    Correct: MPLS labels are used by the service provider to segregate and forward traffic uniquely for each customer.

  • C. Incorrect.

    Incorrect: MPLS Layer 3 VPNs do not require customers to use the same IP addressing scheme as the service provider. Customers can maintain their own addressing.

  • D. Correct.

    Correct: BGP is used to exchange VPN routing information between PE routers, ensuring that branch offices can communicate.

  • E. Incorrect.

    Incorrect: MPLS Layer 3 VPNs do not rely on IPSec for traffic encryption by default. Traffic isolation is achieved using MPLS labels and VRFs.

350-401 Question 505

Select 3

A service provider is implementing MPLS Layer 3 VPN to provide connectivity between two customer sites. The provider wants to ensure traffic separation between customers and allow for overlapping IP address spaces. Which mechanisms in MPLS Layer 3 VPN ensure these requirements are met?

  1. A

    Route Distinguishers (RDs)

  2. B

    Route Targets (RTs)

  3. C

    Label Distribution Protocol (LDP)

  4. D

    Multiprotocol BGP (MP-BGP)

  5. E

    Provider Edge (PE) routers enabling OSPF between customer sites

Show answer and explanation

Correct answers: A, B, D

Explanation

MPLS Layer 3 VPN achieves traffic separation and support for overlapping IP address spaces by leveraging Route Distinguishers (RDs) to make prefixes unique, Route Targets (RTs) to control route distribution between VRFs, and Multiprotocol BGP (MP-BGP) to exchange VPNv4 routes between PE routers. While LDP is essential for label switching in the MPLS core, it does not directly address these specific requirements. Similarly, enabling OSPF between customer sites is not necessary in MPLS Layer 3 VPN, as the PE routers use VRFs and MPLS protocols for traffic isolation.

  • A. Correct.

    Route Distinguishers (RDs) are used to make identical IP address prefixes unique in the MPLS VPN environment, ensuring traffic separation for overlapping IP spaces.

  • B. Correct.

    Route Targets (RTs) are used to control the import and export of routes between VRFs, which is critical for maintaining traffic separation in MPLS Layer 3 VPNs.

  • C. Incorrect.

    Label Distribution Protocol (LDP) is used for label switching in the MPLS core, but it does not directly address traffic separation or overlapping IP spaces.

  • D. Correct.

    Multiprotocol BGP (MP-BGP) is used to exchange VPNv4 routes between PE routers, ensuring proper route propagation for each VPN and enabling traffic separation.

  • E. Incorrect.

    Provider Edge (PE) routers do not require enabling OSPF between customer sites; instead, they use VRFs and MPLS protocols to maintain separation.

350-401 Question 506

Single answer

A service provider is tasked with deploying an MPLS Layer 3 VPN to interconnect multiple customer sites. The service provider needs to ensure that customer traffic is isolated while allowing for overlapping IP address spaces between different customers. Which component of the MPLS Layer 3 VPN architecture is responsible for maintaining this isolation?

  1. A

    Route Distinguisher (RD)

  2. B

    Route Target (RT)

  3. C

    VRF (Virtual Routing and Forwarding)

  4. D

    Label Distribution Protocol (LDP)

Show answer and explanation

Correct answer: C

Explanation

In MPLS Layer 3 VPNs, VRFs are a fundamental component that provide customer traffic isolation by maintaining separate routing tables for each customer. This logical separation allows multiple customers to use overlapping IP address spaces without interference. While other components like Route Distinguisher (RD) and Route Target (RT) play important roles in route identification and route policy control, VRFs are specifically responsible for traffic isolation.

  • A. Incorrect.

    Route Distinguisher (RD) is used to make routes globally unique by appending a unique identifier to the customer's IP prefix, but it does not directly handle traffic isolation.

  • B. Incorrect.

    Route Target (RT) is used to control the import and export of routes between VRFs but does not provide traffic isolation by itself.

  • C. Correct.

    VRF (Virtual Routing and Forwarding) is the correct answer. VRFs allow for the segregation of routing tables on a per-customer basis, ensuring traffic isolation and enabling support for overlapping IP address spaces.

  • D. Incorrect.

    Label Distribution Protocol (LDP) is used for label distribution in the MPLS domain but does not handle the logical isolation of customer traffic.

Timed practice exam

Take a 350-401 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam

350-401 practice questions 501 to 600 of 629

Every question has a page with the answer and explanation. Numbers are stable, so you can bookmark or share them. The bank is split into 7 pages of up to 100 questions.

  1. 502.A service provider is implementing an MPLS Layer 3 VPN for a customer with multiple sites. The customer...
  2. 503.A service provider is deploying an MPLS Layer 3 VPN to provide secure connectivity between multiple customer...
  3. 504.An enterprise customer has multiple branch offices connected via a service provider MPLS Layer 3 VPN. The...
  4. 505.A service provider is implementing MPLS Layer 3 VPN to provide connectivity between two customer sites. The...
  5. 506.A service provider is tasked with deploying an MPLS Layer 3 VPN to interconnect multiple customer sites. The...
  6. 507.You are tasked with configuring a single-hub DMVPN topology for a company with multiple branch offices. The...
  7. 508.An enterprise is deploying a single-hub DMVPN configuration. The hub router is configured with the...
  8. 509.An enterprise is configuring a DMVPN single-hub topology to connect its branch offices. The hub router is...
  9. 510.An organization is deploying a DMVPN solution with a single hub. The hub router is configured with a static...
  10. 511.A network engineer is tasked with configuring a DMVPN (Dynamic Multipoint Virtual Private Network) using a...
  11. 512.A network engineer is tasked with deploying a secure, scalable GRE-based solution to interconnect multiple...
  12. 513.An enterprise network requires a secure and scalable solution to connect multiple branch offices over the...
  13. 514.An enterprise network engineer is tasked with deploying a point-to-multipoint VPN solution using GRE tunnels....
  14. 515.A network engineer is configuring a GRE tunnel between two branch offices. However, during testing, the...
  15. 516.An organization is implementing a multipoint GRE (mGRE) tunnel on a hub-and-spoke topology to enable dynamic...
  16. 517.In a DMVPN Phase 2 network, you are configuring NHRP on a spoke router. The spoke router is not able to...
  17. 518.A network engineer is deploying a DMVPN Phase 2 topology and needs to ensure that spoke-to-spoke...
  18. 519.You are configuring a DMVPN Phase 2 deployment using NHRP. After the initial setup, you notice that...
  19. 520.An enterprise network is deploying DMVPN with NHRP to support dynamic spoke-to-spoke communication. The...
  20. 521.Your organization is implementing a DMVPN (Dynamic Multipoint VPN) solution for secure communication between...
  21. 522.A network administrator is tasked with configuring a site-to-site IPsec VPN between two routers to securely...
  22. 523.Your company is implementing a site-to-site IPsec VPN between two branch locations, and you are tasked with...
  23. 524.An enterprise network administrator is configuring an IPsec VPN between two branch offices. The administrator...
  24. 525.You are configuring a site-to-site IPsec VPN between two branch offices. During testing, you notice that...
  25. 526.An organization has deployed site-to-site IPsec VPN between two branch offices using Cisco routers. During...
  26. 527.A network engineer is configuring an EIGRP domain using IPv6 on a network with a large number of routers. To...
  27. 528.A network engineer has configured a BGP dynamic neighbor feature on a router. The engineer notices that the...
  28. 529.An enterprise network is using EIGRP for internal routing. The network administrator needs to dynamically...
  29. 530.A network engineer is configuring EIGRP for IPv6 on a router in a dynamic environment. They want to simplify...
  30. 531.An enterprise network is using EIGRP for its internal routing. The network administrator wants to configure...
  31. 532.In a DMVPN Phase 2 deployment, a network engineer observes that spoke-to-spoke communication is not occurring...
  32. 533.A company has deployed a DMVPN hub-and-spoke topology to connect its branch offices. The network engineer...
  33. 534.An enterprise network uses a DMVPN design with multiple branch offices connected to a central hub router. Due...
  34. 535.An enterprise network is configured with a DMVPN topology. The hub router is successfully facilitating...
  35. 536.You are configuring a DMVPN network to enable spoke-to-spoke communication without requiring all traffic to...
  36. 537.You are configuring infrastructure security for a Cisco Enterprise network. The network requires protection...
  37. 538.A company has deployed multiple branch routers connected to the headquarters over the internet. Security...
  38. 539.You are tasked with enhancing the security of a branch office's network. The branch router is experiencing...
  39. 540.A network engineer is tasked with securing an OSPF routing domain in a multi-area network. The engineer must...
  40. 541.An organization has deployed an OSPF-based routing environment. To improve infrastructure security, the...
  41. 542.A network administrator has configured AAA on a Cisco router to use a TACACS+ server for authentication....
  42. 543.A network administrator is troubleshooting an authentication issue on a Cisco router configured with AAA...
  43. 544.A network engineer has configured AAA on a Cisco router to authenticate administrative access using a RADIUS...
  44. 545.A network administrator has configured AAA on a Cisco router to authenticate administrative access using...
  45. 546.A network engineer has configured AAA on a Cisco router to use a TACACS+ server for authentication. However,...
  46. 547.A network engineer is troubleshooting a router where SSH access has suddenly stopped working. The router is...
  47. 548.A network administrator has implemented Control Plane Policing (CoPP) on a router to protect it from attacks...
  48. 549.An enterprise network administrator is troubleshooting a router's security configuration. The router is...
  49. 550.A network engineer is troubleshooting issues with SSH access to a router. The router is configured with an...
  50. 551.You are troubleshooting a network issue where users are unable to access a sensitive server behind a router....
  51. 552.Your network consists of multiple branch offices connected to the headquarters via a WAN. You need to...
  52. 553.A network administrator is tasked with configuring an access control list (ACL) to block HTTP traffic (TCP...
  53. 554.A network administrator has configured the following time-based IPv4 ACL on a Cisco router: The administrator...
  54. 555.A network administrator has configured an extended IPv4 access control list (ACL) to block HTTP traffic from...
  55. 556.A network administrator is tasked with configuring an extended IPv4 ACL to allow HTTP and HTTPS traffic from...
  56. 557.A network engineer is tasked with configuring an IPv6 traffic filter on a router to block all incoming ICMPv6...
  57. 558.A network engineer is tasked with configuring an IPv6 traffic filter to block incoming ICMPv6 echo requests...
  58. 559.You are configuring IPv6 traffic filtering on a router to restrict access to a specific server in your...
  59. 560.You are tasked with implementing an IPv6 traffic filter on a router to prevent traffic from a specific IPv6...
  60. 561.You are configuring an IPv6 traffic filter on a Cisco router to block all inbound traffic to the router's...
  61. 562.A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco router to prevent IP...
  62. 563.An enterprise network engineer has enabled Unicast Reverse Path Forwarding (uRPF) on a router to mitigate...
  63. 564.A network administrator has implemented Unicast Reverse Path Forwarding (uRPF) on a border router to prevent...
  64. 565.A network administrator has configured Unicast Reverse Path Forwarding (uRPF) on a router using the 'strict...
  65. 566.A network engineer is tasked with implementing unicast reverse path forwarding (uRPF) on a corporate router...
  66. 567.A network engineer is troubleshooting an issue where legitimate SSH traffic to a router is being dropped...
  67. 568.A network administrator notices that OSPF neighbor relationships are not forming between routers after...
  68. 569.A network engineer implemented Control Plane Policing (CoPP) on a router to prioritize management traffic...
  69. 570.A network administrator has implemented Control Plane Policing (CoPP) on a Cisco router to protect the...
  70. 571.A network administrator is troubleshooting an issue in an IPv6-enabled network where rogue Router...
  71. 572.A network administrator is tasked with securing an IPv6-enabled network from malicious activities such as...
  72. 573.You are configuring IPv6 security features on an enterprise network. A rogue device is attempting to send...
  73. 574.An enterprise network administrator is tasked with securing an IPv6-enabled network against threats such as...
  74. 575.An enterprise network administrator wants to secure the IPv6 First-Hop environment against potential threats...
  75. 576.A network engineer is tasked with implementing a DHCP server on a Cisco router to provide IP addresses to...
  76. 577.A network engineer is configuring DHCP services on a Cisco router to assign IP addresses to clients in a...
  77. 578.A network administrator is tasked with configuring DHCP services for a large enterprise network. The network...
  78. 579.An enterprise network is experiencing inconsistent network performance across multiple branch offices. Upon...
  79. 580.A network engineer is tasked with configuring a DHCP server on a Cisco router to serve IP addresses for a new...
  80. 581.You are managing a Cisco ISR router in a branch office that has recently been configured for remote access...
  81. 582.A network administrator is unable to remotely manage a Cisco router through SSH. Upon investigating, they...
  82. 583.A network administrator is unable to access a Cisco router via SSH after making recent configuration changes....
  83. 584.A network administrator is unable to access a Cisco router via SSH and suspects an issue with the...
  84. 585.A network engineer is attempting to manage a Cisco router via SSH, but they are unable to establish a...
  85. 586.A network administrator is configuring secure remote access to a Cisco router using VTY lines. They want to...
  86. 587.A network administrator is configuring secure remote access to a Cisco router. They want to ensure that both...
  87. 588.A network administrator wants to secure remote and local access to a Cisco router. They have configured the...
  88. 589.You are configuring a Cisco router to ensure secure remote access for administrators. The requirement is to...
  89. 590.You are configuring a new Cisco router for remote and local access. To provide secure remote management and...
  90. 591.A network engineer is configuring remote access to a Cisco router. The engineer wants to ensure secure...
  91. 592.You are configuring secure remote access for network administrators to manage routers in your enterprise...
  92. 593.A network administrator is tasked with securing remote management access to a Cisco router. The administrator...
  93. 594.A network administrator is tasked with securely copying configuration files from a Cisco router to a remote...
  94. 595.A network engineer is tasked with securely transferring a configuration file from a local workstation to a...
  95. 596.An enterprise network engineer needs to transfer a Cisco IOS image to a router using TFTP. The TFTP server is...
  96. 597.A network administrator is tasked with transferring a new router configuration file to a remote Cisco router...
  97. 598.A network engineer is tasked with configuring a Cisco router to act as a TFTP server for storing backup...
  98. 599.An enterprise network administrator needs to back up the running configuration of a Cisco router to a...
  99. 600.A network administrator is configuring a Cisco router to act as an FTP server for IOS image transfers. After...
  100. 601.A network administrator is troubleshooting SNMP communication between a monitoring server and a router. The...