Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Cisco Implementing Cisco Enterprise Network Core Technologies 350-401 Exam Questions

Page: 1 / 25 Total 372 questions

Want more questions? Get Premium Access.

Question 1

Refer to the exhibit. An engineer must adjust the configuration so that Router A becomes the active router. Which commands should be applied to router A? (Choose two)

Correct Answer: C. vrrp lip 10.1.0.11; E. vrrp 1 priority 120
Explanation:

To make Router A the active router in an HSRP (Hot Standby Routing Protocol) or similar redundancy scenario, the configuration should be adjusted with commands such as:

  • Increase Priority: Apply standby [group] priority [value > current active] to give Router A higher priority than the current active router
  • Set Preemption: Apply standby [group] preempt to enable preemption, allowing Router A to become active immediately when it has higher priority

With these two commands, Router A will transition from standby to active state, assuming its priority becomes higher than the active router's priority and preemption is enabled.

Question 2

With IGMPv2, which multicast group address does the IGMP querier use to send query messages to all hosts on the LAN?

Correct Answer: B. 224.0.0.1
Explanation:

In IGMPv2 (Internet Group Management Protocol version 2), the IGMP querier uses the multicast address 224.0.0.1 to send query messages to all hosts on the LAN.

  • Destination Address: 224.0.0.1 is the all-hosts multicast address reserved for general IGMP queries
  • Function: The querier sends periodic queries to this address to discover which multicast groups have active listeners on the local network segment
  • Hosts Response: Hosts listening to any multicast group respond with IGMP membership reports indicating their group memberships
  • Scope: This address is link-local and does not route beyond the local network segment

This mechanism allows the IGMP querier to maintain accurate group membership information for multicast forwarding decisions.

Question 3

What is used to validate the authenticity of the client and is sent in HTTP requests as a JSON object?

Correct Answer: D. JWT
Explanation:

A JWT (JSON Web Token) is used to validate the authenticity of the client and is sent in HTTP requests as a JSON object. JWTs are commonly used for authentication and authorization in REST APIs. They contain encoded claims about the user identity and are digitally signed to ensure authenticity. The token is typically sent in the Authorization header of HTTP requests and allows stateless authentication in distributed systems.

Question 4

SIMULATION

Correct Answer: A. See the solution below in Explanation
Explanation:

Solution:

Sw10

config t

no int po2

int et0/0

channel-group 2 mode active

no shut

spanning-tree vlan 10a pri 0


Question 5

Which two components function together in a Cisco SD-Access solution?

Correct Answer: D. Cisco ISE and Cisco Catalyst Center (formerly DNA Center)
Explanation:

Cisco Identity Services Engine (ISE) and Cisco Catalyst Center function together as major control and policy components of an SD-Access deployment. Catalyst Center supplies centralized design, provisioning, automation, management, assurance, and policy orchestration for the fabric. Cisco ISE provides identity-based policy services, endpoint classification, authentication, authorization, Security Group Tags, and Group-Based Policy information.

Cisco's current validated SD-Access deployment documentation identifies Catalyst Center, Cisco ISE, and the supported wired/wireless fabric platforms as the fundamental pillars of the solution. It also states that integration between Catalyst Center and ISE allows the platforms to exchange device and group information and is mandatory where SD-Access microsegmentation is required.

Options B and C combine SD-WAN components with Catalyst Center. vBond/SD-WAN Validator and vSmart/SD-WAN Controller belong to the Cisco Catalyst SD-WAN architecture rather than the SD-Access fabric. Cisco vManage, now SD-WAN Manager, likewise belongs to SD-WAN, making option A invalid.

ENCOR candidates must distinguish the controller and policy components of SD-Access from those of Catalyst SD-WAN rather than treating the architectures as interchangeable.


Question 6

SIMULATION

Correct Answer: A. See the solution below in Explanation
Explanation:

Solution:

R22

int tun0

vrf forwarding FINANCE

ip add 10.10.10.2 255.255.255.0

tunn source e0/0

tunnel dest 209.165.200.230

no shut

ip route vrf FINANCE 10.10.111.0 255.255.255.0 tunn0

int et0/1

vrf forwarding FINANCE

ip address 10.22.22.1 255.255.255.252

wr

Verification:-


Question 7

How is the OAuth framework used in REST API?

Correct Answer: A. by providing the external application a token that authorizes access to the account
Explanation:

The correct answer is A. by providing the external application a token that authorizes access to the account.

Why A is correct:

In REST APIs, OAuth is used as an authorization framework. Instead of giving the external application the user's actual username and password, the user or authorization server provides the application with an access token. That token allows the application to access specific resources based on the permissions granted.

This is the main purpose of OAuth:

Authorize access

Use tokens instead of exposing credentials

Allow controlled, limited access to resources

Why the other options are incorrect:

B . as a framework to hide the security information in the REST URL

OAuth does not work by hiding information in the URL. It is an authorization framework based on tokens.

C . as a framework to hash the security information in the REST URL

OAuth is not a URL-hashing mechanism. Hashing and OAuth are different concepts.

D . by providing the user credentials to the external application

This is the opposite of OAuth's purpose. OAuth is designed so that the external application does not need the user's credentials.

ENCOR Exam Point:

Remember this difference:

Basic Authentication sends username/password

OAuth uses token-based authorization

OAuth = token-based delegated access


Question 8

What does a next-generation firewall that is deployed at the data center protect against?

Correct Answer: A. signature-based malware
Explanation:

A next-generation firewall (NGFW) deployed at the data center protects against:

  • Advanced threats including malware, ransomware, and sophisticated attacks
  • Zero-day exploits using threat intelligence and behavioral analysis
  • Intrusion attempts through IPS (Intrusion Prevention System) capabilities
  • Application-layer attacks by performing deep packet inspection (DPI)
  • Data exfiltration through advanced content filtering and monitoring
  • Lateral movement by enforcing micro-segmentation and granular policies

NGFWs provide more comprehensive threat protection compared to traditional firewalls by combining firewall, IPS, antimalware, and advanced threat prevention capabilities with full-stack visibility and control.

Question 9

Which security feature does stateless authentication and authorization use for REST API calls?

Correct Answer: A. OAuth 2 tokens

Question 10

Why would an architect use an OSPF virtual link?

Correct Answer: D. to connect a nonbackbone area to Area 0 through another nonbackbone area

Question 11

Refer to the exhibit.

Which EEM script generates a critical-level syslog message and saves a copy of the running configuration to the bootflash when an administrator saves the running configuration to the startup configuration?

Correct Answer: B. Option B

Question 12

SIMULATION

Correct Answer: A. See the solution below in Explanation
Explanation:

Solution:

Sw10

config t

no int po20

int et0/0

channel-group 20 mode active

no shut

spanning-tree vlan 20 pri 0

wr

Verification:-


Question 13

Which two actions are recommended as security best practices to protect REST API? (Choose two.)

Correct Answer: A. Use SSL for encryption.; C. Enable dual authentication of the session.
Explanation:

Security best practices for REST API protection include:

  • Use HTTPS/TLS - Encrypt all API communications in transit to prevent eavesdropping and man-in-the-middle attacks
  • Strong authentication - Implement robust authentication methods:
    • OAuth 2.0 for delegated authorization
    • API keys with rotation policies
    • Mutual TLS (mTLS) for certificate-based authentication
    • JWT tokens with appropriate expiration
  • Rate limiting - Restrict number of requests to prevent abuse and DoS attacks
  • Input validation - Validate and sanitize all API inputs to prevent injection attacks
  • Authorization/RBAC - Implement role-based access control for API operations
  • Logging and monitoring - Log all API access and monitor for suspicious patterns
  • Versioning - Maintain API versions to enable secure updates

These practices create defense-in-depth against common API security threats.

Question 14

Which First Hop Redundancy Protocol should be used to meet a design requirements for more efficient default bandwidth usage across multiple devices?

Correct Answer: A. GLBP
Explanation:

GLBP (Gateway Load Balancing Protocol) should be used to meet design requirements for more efficient default bandwidth usage across multiple devices.

  • Load distribution: GLBP uniquely allows multiple routers to act as default gateways simultaneously, distributing traffic across all active routers
  • Bandwidth efficiency: Unlike HSRP or VRRP where only one device is active, GLBP enables all routers to participate in forwarding, utilizing the full bandwidth of all devices
  • Better resource utilization: Traffic is load-balanced in a round-robin fashion across the available gateways

HSRP and VRRP provide redundancy but keep backup routers standby, wasting bandwidth. GLBP maximizes efficiency by having all devices actively forward traffic.

Question 15

Refer to the exhibit.

Refer to the exhibit. Which HTTP request produced the REST API response that was returned by the Cisco Catalyst Center (formerly DNA Center) platform?

Correct Answer: B. GET /network-device
Explanation:

Without the exhibit showing both the HTTP request and the REST API response, a specific answer cannot be determined. However, this question typically presents a response and asks to identify which HTTP method and endpoint combination would produce it. The answer would involve analyzing the response structure, status code, and data format to reverse-engineer the likely request. Common answers involve GET requests to specific API endpoints like /api/v1/networks, /api/v1/devices, etc.