Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Cisco Designing and Implementing Cisco Service Provider Cloud Network Infrastructure v1.0 300-540 Exam Questions

Page: 1 / 7 Total 61 questions

Want more questions? Get Premium Access.

Question 1

An engineer must design a high-availability solution that provides path redundancy for IP by allowing redundant gateways to share MAC protocols and addresses. A group of Layer 3 routers must be allowed to share the default gateway on a LAN, load balance, and seamlessly take over the traffic transfer role if a router in the group fails. What must be used?

Correct Answer: A. GLBP
Explanation:

Comprehensive and Detailed Explanation

In Cisco high-availability LAN gateway designs, the requirement is:

Multiple L3 gateways sharing a virtual MAC and virtual IP

Ability to load balance across multiple active gateways

Capability to seamlessly take over gateway forwarding during a failure

Among Cisco First Hop Redundancy Protocols (FHRPs):

HSRP Active/standby only

VRRP Active/standby only

GLBP (Gateway Load Balancing Protocol) The only FHRP providing active/active load balancing

GLBP allows multiple routers to share:

A common virtual IP

Multiple virtual MAC addresses

Multiple active forwarders that load-balance end hosts

Automatic failover if any gateway fails

Thus, GLBP is the only correct protocol matching the requirement for redundant default gateways with load balancing and shared MAC addressing.


Question 2

An engineer recently deployed a Secure Endpoint VPC in AirGap mode. Which command must be run in the Secure Endpoint Private Cloud portal to update the package to the latest version?

Correct Answer: A. force update -y
Explanation:

Comprehensive and Detailed Explanation

In Cisco Secure Endpoint Private Cloud AirGap mode, Internet access is disabled. Updates must be uploaded manually and then triggered inside the Secure Endpoint console.

The command force update -y initiates the update of the manually uploaded Secure Endpoint package.

Other commands are not used for Secure Endpoint updates:

rpm -qa Lists Linux packages only

jamf-sync all Used for Apple JAMF integrations

genisoimage Used to create ISO files, irrelevant to Secure Endpoint

Therefore, A is correct.


Question 3

What should be used to protect against lateral movements during a Cisco NFVI security breach?

Correct Answer: C. Network segmentation
Explanation:

Comprehensive and Detailed Explanation

In Cisco NFVI security architecture, the primary defense against lateral movement (an attacker moving from one compromised node to another) is network segmentation.

Segmentation:

Separates workloads (compute, storage, management, tenant networks)

Prevents attackers from pivoting inside the NFVI

Reduces blast radius during breaches

Enforces micro-segmented virtual network boundaries

WPA protects Wi-Fi, not NFVI.

WAF protects web apps, not internal movement.

Data encryption protects confidentiality, not lateral movement control.

Thus, network segmentation is the correct solution.


Question 4

Refer to the exhibit.

Refer to the exhibit. An engineer must design a solution that creates a low-latency slice based on a link latency measurement by using the MPLS performance measurement. The solution must create a secure slice that minimizes transport costs and meets transport SLAs beyond best effort. What must be used?

Correct Answer: A. Segment routing
Explanation:

The requirements in the scenario match the capabilities of Segment Routing (SR-MPLS) combined with MPLS Performance Measurement (MPM):

1. Low-latency slice creation

Segment Routing allows deterministic paths using:

SR-TE (Traffic Engineering)

Colored or intent-based policies

Path selection based on link latency, loss, bandwidth, or utilization

MPLS Performance Measurement supplies real-time data such as:

One-way delay

Round-trip delay

Loss metrics

This allows SR-TE to compute paths with minimum latency.

2. Secure slice with minimized transport cost

Segment Routing supports:

Slicing through SR Policies

Steering encrypted traffic (IPsec/GETVPN) through specific SR tunnels

Traffic separation without requiring additional MPLS LSP state in the core

Optimizing transport cost via constraint-based TE computations

3. Transport SLA enforcement beyond best effort

SR-TE + MPM provides:

SLA-aware intent routing

Guaranteed performance paths

Automatic re-optimization if links violate latency or loss SLAs

Why the other options are incorrect

B . IPsec VPN

Provides encryption but does not offer latency-aware or SLA-based path selection. Not a slicing mechanism.

C . AWS Direct Connect

Cloud connectivity service. Not related to MPLS performance monitoring or transport slicing.

D . Transit VPC for AWS

Used for SD-WAN cloud integration. Does not support SR-TE slicing or MPLS SLAs.

Therefore, only Segment Routing provides latency-based path computation, slicing, SLA guarantees, and cost optimization.


Question 5

Refer to the exhibit.

Refer to the exhibit. An engineer is troubleshooting a physical configuration issue in Cisco NFVI. Which two observations should be made? (Choose two.)

A. The node allows two disks to fail. B. One RAID 1 disk failed. C. The node is still functional. D. The node is no longer functional. E. Two RAID 1 disks failed.

Correct Answer: B. One RAID 1 disk failed -- correct.; C. The node is still functional -- correct; RAID1 can tolerate a single disk failure. The other options are incorrect: A and E suggest two disk failures, which is not indicated. D would be true only if both disks failed; with one disk still online, the node continues to function, though in a degraded state.
Explanation:

From the RAID controller output:

The RAID1 virtual drive is shown as ''Dgrd'' (degraded) with a note: ''RAID 1 in degraded state.''

In the PD LIST, one disk (slot 2) is marked ''UGood -- active disk in slot 2 disconnected from drive group 0'', while the other (slot 3) is ''Onln 0'' (online and part of drive group 0).

This means:

In a RAID 1 mirror, only one disk may fail while the array remains available.

Here, one disk has failed/disconnected, the other is still online the array is degraded but operational.

Therefore:


Question 6

What is a valid connection method between carrier-neutral facilities within the same metro area?

Correct Answer: C. DWDM ring
Explanation:

Comprehensive and Detailed Explanation Based on Designing and Implementing Cisco Service Provider Cloud Network Infrastructure Knowledge

When connecting carrier-neutral facilities (CNFs) or data centers within the same metropolitan area, service providers typically use high-bandwidth, low-latency optical transport methods. The most appropriate and commonly deployed interconnection technology is:

DWDM (Dense Wavelength Division Multiplexing) ring, which provides:

High capacity (10G, 40G, 100G, 400G)

Low latency

Redundancy through ring or mesh topologies

Multi-wavelength multiplexing for cost efficiency

Carrier-grade reliability for metro interconnect services

This aligns with cloud interconnect and metro transport design used in service provider environments.

Evaluation of the Options

A . OSPF backbone area adjacency

This is a routing protocol adjacency, not a physical connection method. It requires a transport link underneath but does not represent the physical interconnect itself.

B . Private wireless connection

Not suitable for CNF or metro DC interconnect because it lacks the bandwidth, reliability, and deterministic performance required for large-scale carrier-grade interconnects.

C . DWDM ring

This is the correct method. DWDM-based metro fiber rings are the standard for connecting carrier-neutral facilities in the same metro region.

D . CAT6e connection

This is limited to short-distance copper Ethernet (tens of meters). It is not used for metro-scale interconnects or between CNFs.


Question 7

An engineer must design a cloud platform for event-driven applications. The solution must allow micro-sized atomic components to be built, deployed, and run code on demand. Which solution must be used?

Correct Answer: B. Cisco FaaS
Explanation:

Comprehensive and Detailed Explanation From Cisco Cloud Architecture Knowledge

Event-driven applications require:

Stateless, micro-sized execution units

Automatic scaling

Code that runs only when triggered

No server or VM lifecycle management

This model is known as Function-as-a-Service (FaaS).

Cisco FaaS provides:

Serverless execution

Event-driven triggers

Deployment of atomic micro-functions

Automatic scaling and resource abstraction

Ideal environment for microservices and cloud-native workloads

Why the others are incorrect:

A . Cisco+ Hybrid Cloud for VDI delivers desktops, not serverless compute

C . Cisco+ Hybrid Cloud Virtualization VM-based infrastructure, not event-driven micro-functions

D . Cisco Intersight operational management tool, not a serverless execution platform


Question 8

Refer to the exhibit.

Refer to the exhibit. An engineer must configure dual-homing with single active redundancy in a BGP EVPN VXLAN fabric. Which command must be run on the leaf router to complete the EVPN Ethernet segment configuration?

Correct Answer: A. redundancy single-active
Explanation:

In a BGP EVPN VXLAN multi-homing design, Ethernet Segment Identifiers (ESIs) are used to represent a set of links from one or more leaf switches to the same downstream device (such as a CE, firewall, or aggregation switch). By default, when multiple leafs share the same ESI, the EVPN design supports all-active redundancy, where all participating leafs can forward traffic for that Ethernet segment simultaneously.

However, some use cases---like connecting to devices that do not support multipath forwarding or for strict active/standby redundancy---require single-active multi-homing. In single-active mode, only one leaf in the Ethernet segment forwards traffic at any time; the other leaf(s) act as standby and only take over if the active node fails. This behavior is explicitly controlled in the EVPN Ethernet-segment configuration.

On Cisco platforms for EVPN VXLAN fabrics, this is configured under the l2vpn evpn ethernet-segment stanza using the command:

l2vpn evpn ethernet-segment 1

identifier type 0 01.01.01.10.10.10.10.10.10.10

redundancy single-active

identifier type 0 ... defines the ESI for the multi-homed connection.

redundancy single-active specifies that only one leaf in that ESI is allowed to be active at a time, thus enabling dual-homing with single-active redundancy.

The other options do not relate to Ethernet-segment redundancy mode:

B . default-gateway advertise is used in EVPN anycast gateway configurations to advertise the default gateway MAC/IP, not for ESI redundancy.

C . replication-type static is associated with multicast or ingress replication behavior for VXLAN VTEPs, not Ethernet-segment redundancy.

D . vlan configuration 101 is a VLAN configuration context command and has no effect on EVPN ESI redundancy.


Question 9

What does enabling gRPC allow in Cisco NFVI Assurance and Monitoring?

Correct Answer: A. telemetry streaming
Explanation:

Comprehensive and Detailed Explanation

In Cisco NFV Infrastructure (NFVI) Assurance and Monitoring, enabling gRPC activates the device's ability to support model-driven telemetry streaming.

Key points from Cisco SP Cloud/NFVI design principles:

gRPC is used as the transport protocol for model-driven telemetry.

Telemetry replaces traditional polling methods (SNMP, CLI scraping) with continuous, push-based updates.

It allows NFVI components to stream real-time operational data (CPU, memory, interfaces, VM metrics, fabric state) to collectors such as Cisco Crosswork, InfluxDB, Prometheus, or other analytic systems.

gRPC does not provide NetFlow/IPFIX export or syslog itself; those are separate subsystems.

Evaluation of options:

A . telemetry streaming --- Correct. gRPC enables model-driven streaming telemetry.

B . IPFIX monitoring --- Incorrect; IPFIX uses UDP exports, not gRPC.

C . Cisco IOS NetFlow monitoring --- Incorrect; uses NetFlow export protocols.

D . system logging --- Incorrect; syslog uses UDP/TCP, not gRPC.


Question 10

An engineer must design a solution to provide safe channels between peer-to-peer devices, ensure that unauthorized users cannot break into the network, and ensure that listening devices on the Internet cannot intercept communication transmitted over the network. What must be used?

Correct Answer: C. IPsec VPN
Explanation:

Comprehensive and Detailed Explanation (Cisco SP Cloud Knowledge)

The requirement describes:

Secure communication between sites or devices

Protection from eavesdropping over the Internet

Cryptographic tunnels

End-to-end authentication and encryption

This exactly matches the purpose of an IPsec VPN, which provides:

Encrypted secure tunnels

Authentication and integrity protection

Confidentiality even across untrusted networks such as the Internet

Other options do not provide encrypted peer-to-peer channels:

AWS Direct Connect private link to AWS, not peer-to-peer encryption

Segment Routing traffic engineering, not security

Transit VPC routing architecture, not encryption

Thus the correct answer is IPsec VPN.