This exam tests a candidate’s knowledge of the latest development in network design and technologies, including L2 and L3 infrastructures for the enterprise, WAN technologies, data center integration, network security, and network services.

Which option is correct when using Virtual Switching System?
A. Both control planes forward traffic simultaneously
B. Only the active switch forward traffic
C. Both data planes forward traffic simultaneously
D. Only the active switch handle the control plane
Correct Answer: C


An engineer must design a Cisco VSS-based configuration within a customer campus network. The two VSS switches
are provisioned for the campus distribution layer… Which option is the primary reason to avoid plugging both VSL links
into the supervisor ports?
A. The implementation creates a loop
B. The design lacks optimal hardware diversity
C. Limited bandwidth is available for VSS convergence
D. QoS is required on the VSL links
Correct Answer: B
The best-practice recommendation for VSL link resiliency is to bundle two 10-Gbps ports from different sources. Doing
this might require having one port from the supervisor and other from a Cisco 6708 line card.
When configuring the VSL, note the following guidelines and restrictions:
For line redundancy, we recommend configuring at least two ports per switch for the VSL. For module redundancy, the
two ports can be on different switching modules in each chassis.


Which feature can be used in the Cisco Nexus 7000 to create a snapshot of the current configuration?
A. Cisco FabricPath
C. Rollback
D. vPC
Correct Answer: C


After an incident caused by a DDOS attack on a router, an engineer must ensure that the router is accessible and
protected from future attacks without making any changes to traffic passing through the router. Which security function
can be utilized to protect the router?
A. zone-based policy firewall
B. access control lists
C. class maps
D. control plane policing
Correct Answer: D


A company wants to configure BGP on a router so that other BGP neighbors cannot influence the path of a particular
route .which action must be taken to accomplish this configuration ?
A. Configure a low router ID for the route
B. Configure a high local preference for the route
C. Configure a high weight for the route
D. Configure a low MED for the route
Correct Answer: B


Which of these statements is correct regarding Stateful Switchover and Cisco Nonstop Forwarding?
A. Utilizing Cisco NSF in Layer 2 environments can reduce outages to one to three seconds.
B. Utilizing SSO in Layer 3 environments can reduce outages to one to three seconds.
C. Distribution switches are single points of failure causing outages for the end devices.
D. Utilizing Cisco NSF and SSO in a Layer 2 environment can reduce outages to less than one second.
E. NSF and SSO with redundant supervisors have the most impact on outages at the access layer.
Correct Answer: E

Which QoS mechanism uses RSVP?
A. IntServ
B. DiffServ
C. CoS
D. ToS
Correct Answer: A


At a certain customer\\’s site, a NAS is both physically and logically in the traffic path. The NAS identifies clients solely
based on their MAC addresses. In which access mode has this NAS been configured to operate?
A. Layer 2 mode
B. Layer 3 Edge mode
C. Layer 3 Central mode
D. Layer 3 In-Band mode
Correct Answer: A


Which two statements correctly describe an IPS device? (Choose two.)
A. It resembles a Layer 2 bridge.
B. Traffic flow through the IPS resembles traffic flow through a Layer 3 router.
C. Inline interfaces which have no IP addresses cannot be detected.
D. Malicious packets that have been detected are allowed to pass through, but all subsequent traffic is blocked.
E. Traffic arrives on the detection interface, is inspected, and exits via the same interface.
Correct Answer: AC


A network engineer must create a Layer 2 switch block design that has deterministic convergence and is loop-free at
Layer 2. Which two switch block elements are needed to meet the requirements? (Choose two.)
A. Layer 3 link between distribution switches
B. HSRP with interface tracking on uplinks to core switches
C. RPVST with equal bridge priority on distribution switches
D. VLANs that do not span access switches
E. Layer 2 link between distribution switches
Correct Answer: AD


When adding an IPSec headend termination device to your network design, which two performance indicators are the
most accurate to determine device scalability? (Choose two.)
A. CPU capabilities
B. bandwidth capabilities
C. packets per second capabilities
D. maximum tunnel termination capabilities
Correct Answer: CD


Which two of these are correct regarding the recommended practice for distribution layer design? (Choose two.)
A. use a redundant link to the core
B. use a Layer 2 link between distribution switches
C. never use a redundant link to the core because of convergence issues
D. use a Layer 3 link between distribution switches with route summarization
E. use a Layer 3 link between distribution switches without route summarization
Correct Answer: AE
We need to summarize from distribution to core but not between distribution switches.


When a router has to make a rate transition from LAN to WAN, what type of congestion needs should be considered in
the network design?
A. RX-queue deferred
B. TX-queue deferred
C. RX-queue saturation
D. TX-queue saturation
E. RX-queue starvation
F. TX-queue starvation
Correct Answer: F

