Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Cisco Designing Cisco Enterprise Networks Exam 300-420 Exam Questions

Page: 1 / 26 Total 379 questions

Want more questions? Get Premium Access.

Question 1

Refer to the exhibit.

Refer to the exhibit. An architect designs a BGP policy for a customer that requires load sharing of the links that connect with the upstream service provider. The customer has these requirements: * The inbound traffic destined to network 10.1.1.0/24 must transit the R3-R1 link, and if the link fails, all inbound traffic must transit the R4-R2 link.

* The inbound traffic destined to network 10.1.2.0/24 must transit the R4-R2 link, and if the link fails, all inbound traffic should transit the R3-R1 link.

Which solution must the architect choose?

Correct Answer: A. * R1 must announce prefix 10.1.2.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512 * R2 must announce prefix 10.1.1.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512.
Explanation:

The correct policy is to prepend the AS path on the nonpreferred advertisement for each prefix. For inbound BGP traffic engineering, the enterprise normally influences remote autonomous systems by changing attributes that those systems see when selecting a path. AS-path prepending makes a route appear less attractive by adding repeated instances of the local AS number to the AS path. In this design, network 10.1.1.0/24 should enter through R3-R1, so R2 must advertise that prefix with a prepended AS path to make the R4-R2 path less preferred unless the primary path fails. Conversely, network 10.1.2.0/24 should enter through R4-R2, so R1 must advertise that prefix with prepending to make the R3-R1 path less preferred. This creates inbound load sharing while preserving failover because the prepended route remains available as a backup. Local preference affects outbound path selection inside the local AS, not inbound selection by the provider. Reference topics: BGP traffic engineering, AS-path prepending, inbound path control, prefix-specific policy, multihomed WAN design.


Question 2

Refer to the exhibit.

Refer to the exhibit A customer wants to adopt a dynamic site-to-site VPN solution to secure communication for VoIP, video, and FTP traffic between the remote branches and the headquarters. The customer also wants the branches to communicate directly, thereby reducing traffic at the headquarters location. The solution must consider that the branch routers are limited in available memory. Which VPN solution meets these requirements?

Correct Answer: B. DMVPN Phase 3 Hub and Spoke design
Explanation:

DMVPN Phase 3 hub-and-spoke is the best design for this requirement. The customer wants secure dynamic site-to-site VPN connectivity for voice, video, and FTP, and also wants branches to communicate directly instead of hairpinning all traffic through headquarters. DMVPN supports dynamic spoke-to-spoke tunnels using multipoint GRE, NHRP, and IPsec protection. Phase 3 is more scalable than Phase 2 because the hub can send NHRP redirect messages and spokes can install shortcut routes, reducing the need for every spoke to maintain detailed next-hop information for every other spoke. That is important because the branch routers have limited memory. Phase 1 is hub-and-spoke only and does not provide dynamic spoke-to-spoke forwarding. A hierarchical Phase 3 design can be useful at very large scale, but the question describes a headquarters and remote branch design rather than multiple tiers of hubs. Phase 3 hub-and-spoke satisfies direct branch communication, security, and scale. Reference topics: DMVPN Phase 3, NHRP redirect, spoke-to-spoke tunnels, IPsec encryption, branch WAN scalability.


Question 3

A customer requested that a guaranteed service line be enabled for a manufacturing business in different countries. On the customer side, the QoS-aware application is used to process large data chunks. The application cannot tolerate drops and latency should be as low as possible. Which QoS model must an engineer employ to use the minimum required resources on the ISP network nodes?

Correct Answer: C. Implement an end-to-end QoS strategy with SLA.
Explanation:

An end-to-end QoS strategy with an SLA is the best fit for an application that cannot tolerate drops and requires very low latency across countries. The customer is asking for guaranteed service behavior, not just local classification on one router. A service line with an SLA defines the expected treatment across the provider network, including bandwidth, delay, jitter, and loss commitments. This is especially important for industrial or manufacturing applications that process large data chunks and are sensitive to packet loss. A purely domain-based PHB design can mark and forward traffic differently at each hop, but it does not by itself guarantee the business outcome unless backed by an end-to-end service agreement. A flow-based approach with per-flow queuing on every ISP node would consume more provider resources and scale poorly. FEC can help selected traffic but does not replace a QoS service model. Reference topics: QoS design, service-level agreements, end-to-end QoS, low-latency applications, loss-sensitive traffic, provider WAN services.


Question 4

An engineer is designing a QoS policy that queues excess packets for later transmission. Which mechanism must be included in the design?

Correct Answer: A. shaping
Explanation:

Traffic shaping is the QoS mechanism that queues excess packets and transmits them later to conform to a configured rate. In Cisco QoS design, shaping smooths bursts by buffering traffic instead of immediately discarding it when the offered rate exceeds the configured rate. This makes shaping appropriate on egress interfaces where the enterprise router has a higher physical interface speed than the actual provider committed information rate. WRED and RED are congestion-avoidance mechanisms that drop packets probabilistically to prevent full queue exhaustion, especially for TCP traffic. They do not intentionally hold excess packets for later transmission as the primary behavior. Policing enforces a traffic rate by dropping or remarking traffic that exceeds the configured contract; it does not buffer traffic to smooth bursts. Therefore, when the design requirement says excess packets must be queued for later transmission, the mechanism must be shaping. In WAN edge QoS, shaping is often paired with child queuing policies so latency-sensitive and business-critical classes receive correct treatment inside the shaped parent rate.


Question 5

Refer to the exhibit.

Correct Answer: C. Deploy the application in DC1 and DC2. Advertise the prefix from DC1 with /32. Advertise the prefix from DC2 with /24.
Explanation:

The correct design is to deploy the application in both data centers, advertise the application prefix from DC1 as a /32, and advertise a broader /24 from DC2. This uses longest-prefix-match behavior to create deterministic primary and backup routing. Cisco routing logic prefers the most specific matching route in the routing table, regardless of administrative distance or metric comparisons among less specific covering routes. As long as the DC1 /32 is present, traffic for that exact application address follows DC1. If DC1, its edge path, or the /32 advertisement fails, the /32 is withdrawn and the remaining /24 covering route from DC2 provides backup reachability. Advertising the same prefix from both locations may result in load sharing or provider-dependent selection, which does not guarantee DC1 primary behavior. IP SLA could be used in some route-tracking designs, but the clean routing solution tested here is prefix specificity. Reference topics: longest-prefix match, BGP advertisement, active/standby data center routing, covering routes, route failover.


Question 6

Which protocol is the Cisco SD-Access data plane based on?

Correct Answer: B. VXLAN
Explanation:

The Cisco SD-Access data plane is based on VXLAN. Cisco SD-Access separates the fabric into functional planes: the underlay provides IP reachability, the control plane uses LISP to map endpoints to locations, and the data plane uses VXLAN encapsulation to carry user traffic across the routed underlay. VXLAN allows the fabric edge node to encapsulate endpoint traffic and forward it through the fabric while preserving virtual network and segmentation information. This is what enables SD-Access to provide Layer 2 and Layer 3 overlay services over a Layer 3 routed transport. OMP is the control-plane protocol for Cisco SD-WAN, not SD-Access. NHRP is associated with DMVPN tunnel resolution. LISP is essential in SD-Access, but its role is endpoint ID to routing locator mapping, not packet encapsulation in the data plane. Therefore, VXLAN is the correct protocol for the SD-Access data plane. Reference topics: SD-Access fabric, VXLAN data plane, LISP control plane, overlay encapsulation, routed underlay.


Question 7

An architect is designing a multicast solution for a network that contains over 100 routers. The architect plans to create several multicast domains and balance the PIM-SM traffic within the network. Which technology should the architect include in the design?

Correct Answer: D. MSDP
Explanation:

MSDP is the correct technology when a large multicast design uses multiple PIM Sparse Mode domains and needs to exchange active source information between those domains. Cisco describes Multicast Source Discovery Protocol as the mechanism used by RPs in different PIM-SM domains to learn about multicast sources outside their own domain. When a source becomes active, the local RP can advertise Source-Active information to MSDP peers, allowing receivers in other domains to discover and join that source. This supports domain separation and can help balance multicast control-plane scope in large networks. DVMRP and MOSPF are legacy multicast routing approaches and are not the design mechanism for modern PIM-SM domain interconnection. IGMP is used between hosts and local multicast routers for receiver membership signaling; it does not exchange source information between multicast domains. Therefore, a design with more than 100 routers, several multicast domains, and PIM-SM traffic balancing should include MSDP. The architect should also design RP placement, Anycast RP behavior, peer mesh scaling, and source filtering. Reference topics: MSDP, PIM-SM domains, Source-Active messages, interdomain multicast.


Question 8

Which security functionality does gRPC provide?

Correct Answer: D. supporting secure communication between network devices and control systems using TLS
Explanation:

gRPC provides secure communication between network devices and control systems by supporting TLS. In Cisco programmability and model-driven telemetry designs, gRPC is commonly used as a high-performance remote procedure call framework that carries structured data encoded with Protocol Buffers. Security is provided through TLS so that the client and server can authenticate and protect the session in transit. The question asks for security functionality, so TLS support is the correct selection. The other options describe incorrect or misleading cryptographic behavior. gRPC does not implement generic RSA tunnel encryption as described in option A, and it does not provide mandatory encryption of data at rest. RC6 with CRC is not the security model used for Cisco gRPC telemetry or programmability. In a secure management design, gRPC should be deployed with certificates, TLS verification, controlled access lists, and appropriate AAA integration so only authorized collectors or controllers can communicate with infrastructure devices. Reference topics: gRPC, TLS, model-driven telemetry, Protocol Buffers, secure automation transport.


Question 9

An engineer uses Postman and YANG to configure a router with:

Which get-config replay verifies that the model set was designed correctly?

Correct Answer: D. Option D
Explanation:

The verifying get-config reply must reflect the same YANG model hierarchy and configured values that were pushed by the Postman request. In model-driven automation, a successful transport response is not enough; the engineer must confirm that the intended datastore contains the exact interface, routing, or protocol objects described by the model. Option D is the selected reply because it matches the expected YANG structure for the configuration operation shown in the exhibit. The key principle is that get-config returns configuration data from a specified datastore, such as running or candidate, using the schema-defined XML hierarchy. If the returned XML uses the wrong container, wrong namespace, incorrect key value, or an unexpected leaf, the model set was not designed or addressed correctly. Cisco NETCONF/YANG workflows rely on strict namespace and path accuracy, so even a small mismatch can result in configuration being placed in the wrong subtree or not applied. A clean validation checks the model namespace, parent containers, list keys, leaf names, and actual configured value. Reference topics: NETCONF get-config, YANG XML encoding, datastore validation, Postman automation workflow.


Question 10

Refer to the exhibit.

Refer to the exhibit. Currently, the network uses a single-homed solution for connecting to the internet. An engineer must design a more resilient WAN using the internet circuits at each site. The design must provide failover connectivity, support load-sharing of traffic, and QoS. Which solution must the engineer choose?

Correct Answer: C. SD-WAN
Explanation:

Cisco SD-WAN is the correct solution when the design must use internet circuits at each site while providing failover, load sharing, and QoS. Basic IPsec tunnels can encrypt traffic, but they do not by themselves provide a complete WAN architecture for path measurement, dynamic traffic steering, centralized policy, application-aware routing, or scalable operational control. Cisco SD-WAN builds secure overlay tunnels across available transports and continuously measures path characteristics such as loss, latency, and jitter. It can then steer applications according to SLA policy, use multiple circuits for active/active forwarding, and fail traffic over when a path degrades or fails. QoS can be applied consistently through templates and policy across the WAN Edge routers. GET VPN is best suited to private MPLS-style networks and does not address internet-circuit overlay orchestration in the same way. Traditional DMVPN is a valid dynamic VPN technology, but SD-WAN is the more complete resilient internet-WAN design for these requirements. Reference topics: Cisco SD-WAN, internet transport, application-aware routing, failover, load sharing, QoS.


Question 11

What is an advantage of using model-driven telemetry in the network?

Correct Answer: B. It uses JSON encoding and is compatible with a wide variety of tools on the market.
Explanation:

A practical advantage of model-driven telemetry is that it sends structured data in machine-readable encodings, including JSON in supported implementations, making the data easier to consume with modern collectors and automation tools. Model-driven telemetry uses data models, commonly YANG, to define exactly which operational or configuration data is streamed. This is a major improvement over legacy monitoring approaches that repeatedly poll devices or parse human-oriented CLI output. The question option that points to structured JSON compatibility is the best available answer. Telemetry is not based on interrupt-driven polling; it is normally subscription based, either periodic or on-change. It also does not rely on MIB models as its primary structure in the way SNMP does. Parsing show command output is the older, brittle method that model-driven telemetry is intended to replace. The design benefit is cleaner, more predictable, and more programmable network state collection. Reference topics: model-driven telemetry, YANG data models, JSON encoding, subscription-based monitoring, network programmability.


Question 12

Refer to the exhibit. A company is expanding and decides to use a DMVPN solution to connect the branches. The network uses the EIGRP routing protocol. All remote branch routers must be configured with the normal EIGRP area. Auto-summary is not allowed on the routers in the network. Which solution must the company implement on R1 to achieve this goal?

Correct Answer: D. Configure a summary route.
Explanation:

The company must configure a summary route on R1. The branch routers must remain normal EIGRP routers, and auto-summary is not allowed, so the scalable design choice is manual summarization at the hub. Cisco EIGRP documentation states that manual summarization can be configured on an interface using the ip summary-address eigrp command and can summarize routes on almost any bit boundary. In a DMVPN hub-and-spoke topology, a hub summary reduces the number of individual routes advertised to branches, limits routing-table growth, and helps contain EIGRP queries. It also keeps branch configuration simple because the branches do not need to be converted to stub routers to meet this specific requirement. Disabling split horizon is a common DMVPN Phase 2 consideration when the hub must advertise spoke routes back out the same multipoint tunnel interface, but it does not summarize HQ routes. A multipoint interface is already implied by DMVPN, and disabling the SIA timer is not a design solution. Reference topics: EIGRP manual summarization, DMVPN hub design, no auto-summary, query containment.


Question 13

Which two statements about VRRP advertisements are true? (Choose two.)

Correct Answer: C. They are sent only from the master router.; D. They include priority information.
Explanation:

VRRP advertisements are sent by the current master router and include priority information used by the backup routers to evaluate mastership. In VRRP, the master is the router actively forwarding for the virtual IP address. Backups listen for advertisements; if advertisements stop, the backup with the highest effective priority can become master. This is why the statement that advertisements are sent only from the master router is correct. The advertisement also carries priority information, which is used in election behavior and failover decisions. Standby or backup routers do not normally send VRRP advertisements while a master is active, so option A is incorrect. The default advertisement interval is not three seconds in standard VRRP behavior; three seconds is commonly associated with other first-hop redundancy defaults such as HSRP hellos. Although timer fields exist in protocol operation, the exam focus here is the master-only advertisement behavior and the priority carried in those advertisements. In campus gateway redundancy design, VRRP advertisements must be protected from loss or filtering because missed advertisements can cause unnecessary master transitions.


Question 14

Refer to the exhibit.

Refer to the exhibit. A customer is planning to deploy a new branch in New York. The new office will not exceed 1024 users. Which subnet must be used to provide maximum number of host addresses while not providing more than necessary?

Correct Answer: D. 192.168.8.0/22
Explanation:

A /22 subnet is the smallest IPv4 block in the answer set that closely fits a branch expected not to exceed roughly one thousand users while avoiding unnecessary address waste. A /22 contains 1024 total addresses and 1022 usable host addresses after the network and broadcast addresses are reserved. That aligns with the requirement to provide the maximum number of host addresses without selecting a larger block than necessary. A /21 provides 2048 total addresses and 2046 usable hosts, which is materially larger than the stated requirement and wastes address space. The specific 192.168.8.0/22 block also aligns on a valid /22 boundary because /22 networks increment by four in the third octet. A 192.168.16.0/22 is also mathematically valid, but the exhibit determines the available address range; the selected option uses the appropriate block from the displayed plan. Reference topics: IPv4 subnet sizing, CIDR, usable host calculation, branch address planning, VLSM.


Question 15

Refer to the exhibit.

Refer to the exhibit. An engineer must design an address translation solution to provide Internet connectivity for the corporate network. The design Is restricted to the 172.16.168.0/22 subnet. Which solution must the engineer choose?

Correct Answer: A. stateful NAT64
Explanation:

Stateful NAT64 is the correct translation solution when IPv6-only corporate hosts need Internet connectivity to IPv4 resources using a limited IPv4 address pool. NAT64 translates IPv6 client addresses to IPv4 addresses and maintains state for each session, allowing many IPv6 hosts to share a smaller set of IPv4 addresses through port multiplexing. The design is restricted to the 172.16.168.0/22 subnet, which provides an IPv4 pool that can be used for stateful translation. Stateless NAT64 requires algorithmic one-to-one address mapping and normally needs enough IPv4 address space to represent IPv6 hosts deterministically; it is not suitable when many clients must share a restricted IPv4 block. NAT66 translates IPv6 to IPv6 and does not provide access to IPv4 Internet resources. In a production design, stateful NAT64 is often paired with DNS64 so IPv6-only clients can resolve IPv4-only destinations through synthesized AAAA records. Reference topics: stateful NAT64, DNS64, IPv6-to-IPv4 translation, address conservation, Internet access migration.