Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Cisco Certified Design Expert 400-007 Exam Questions

Page: 1 / 37 Total 551 questions

Want more questions? Get Premium Access.

Question 1

A network architect is tasked to develop a design where it is a requirement to group resources according to their security and trust level in the network. Which tool can be leveraged to achieve this?

Correct Answer: B. application firewalls

Question 2

An enterprise has identified these causes for inefficient CAPEX spending:

CAPEX planning is driven by technology and not by business objectives.

The CAPEX planning team lacks the data it needs to perform due diligence tasks.

The organizational structure lacks sufficient accountability and incentives.

Which corporate cultural change contributes to improving the effectiveness of CAPEX spending?

Correct Answer: C. Adopt new organizational models that promote real accountability for ROI, not just revenue, EBITDA, and cash.
Explanation:

C (Accountability for ROI):Shifting focus toward ROI ensures that capital investment is evaluated based on business impact rather than just financial outputs like revenue and EBITDA, aligning technology spending with business value.

Other options explained:

A: Financial reporting doesn't address accountability.

B: Misrepresents leadership responsibility.

D: Budget cuts don't address the structural root cause.


Question 3

What is a key benefit of Infrastructure as Code (IaC)?

Correct Answer: D. Repeatable deployments
Explanation:

D: Repeatable deployments are one of the core benefits of IaC. It allows infrastructure to be provisioned consistently every time using version-controlled templates.

Incorrect options:

A: Declarative pipelines relate more to CI/CD processes than directly to IaC.

B: IaC helps prevent configuration drift, but drift itself is a problem---not a benefit.

C: Agent monitoring is a function of monitoring tools, not IaC.


Question 4

It is often seen that companies pick a cloud vendor solely based on technical preferences without putting enough weight on the business strategies that are driving the cloud initiatives Which strategic requirement may come into play where it is more likely that the decision makers will look to leverage laaS over SaaS or PaaS?

Correct Answer: C. control over the underlying infrastructure

Question 5

Company XYZ connects its sites over a private WAN. Their overlay network is running a DMVPN setup where the headquarters site is the hub. The company is planning on implementing multicast routing on the network. What should be used in the multicast routing design?

Correct Answer: C. PIM sparse mode with RP located at the hub
Explanation:

C (PIM Sparse Mode with RP located at the hub):DMVPN networks typically leverage sparse mode multicast due to their efficiency in dynamic topologies. Locating the Rendezvous Point (RP) at the hub simplifies multicast state management, since the hub serves as the central aggregation point and ensures optimal rendezvous functionality without requiring complex RP placement across spokes.

Other options explained:

A: Dense mode is inefficient and generates unnecessary flooding, especially in WAN environments.

B/D: Placing RPs at remote sites introduces unnecessary complexity and operational challenges.


Question 6

Before migrating anything to the cloud, what are three cloud readiness assessment steps that are required to perform? (Choose three.)

Correct Answer: C. Identify the scope and business cases for migration.; D. Assess infrastructure requirements.; E. Evaluate available in-house resources

Question 7

What are two primary design constraints when a robust infrastructure solution is created? (Choose two.)

Correct Answer: D. Component availability; E. Total cost
Explanation:

In infrastructure design, primary constraints are:

D (Component availability): If hardware or software components are not readily available, designs may need to adapt.

E (Total cost): Budget limitations always influence design decisions regarding redundancy, scalability, and technology selection.

Why other options are not primary constraints:

A: Monitoring is a design consideration, but not a core constraint.

B: Time frame impacts project delivery, not necessarily the design robustness.

C: Staff experience affects operations but is not a primary technical design constraint.

---


Question 8

Refer to the exhibit.

As part of a redesign project, you must predict multicast behavior. What happens to the multicast traffic received on the shared tree (*,G), if it is received on the LHR interface indicated?

Correct Answer: C. It is switched due to a successful RPF check against the routing table
Explanation:

In PIM Sparse Mode, when the Last-Hop Router (LHR) receives multicast traffic on the shared tree (*,G), it performs an RPF check based on the RP address, not the multicast source address. In the diagram:

The LHR has IGP cost 10 towards the RP.

The shared tree (*,G) uses RP as the RPF target.

Since multicast traffic on (*,G) arrives on the interface toward RP (correct RPF interface), the RPF check succeeds.

Therefore, the multicast traffic is successfully switched toward the receivers.

This behavior is fully aligned with CCDE v3.1 multicast design principles, which emphasize clear understanding of RPF behavior both on shared trees (*,G) and source trees (S,G).

Why other options are incorrect:

A: The RPF check is not performed against the source in (*,G); it uses RP.

B: RPF checks are always performed, even on (*,G).

D: RPF is unrelated to the receiver address.


Question 9

Reter to the exhibit This network is running OSPF and EIGRP as the routing protocols Mutual redistribution of the routing protocols has been contoured on the appropriate ASBRs The OSPF network must be designed so that flapping routes m EIGRP domains do not affect the SPF runs within OSPF The design solution must not affect the way EIGRP routes are propagated into the EIGRP domains Which technique accomplishes the requirement?

Correct Answer: D. route summarization on EIGRP routers connecting toward the ASBR

Question 10

Router R1 is a BGP speaker with one peering neighbor over link "A". When link "A" fails, routing announcements are terminated, which results in the tearing down of the state for all BGP routes at each end of the link. What is this a good example of?

Correct Answer: D. Fate sharing
Explanation:

D (Fate sharing):Fate sharing refers to a design where multiple dependent states fail together (i.e., when physical link fails, BGP session and its routes fail too).

Other options explained:

A: Fault isolation refers to containing failures, not dependent failure.

B: Resiliency is the ability to recover, not simultaneous failure.

C: Redundancy would prevent total loss if implemented.


Question 11

Refer to the exhibit.

For Company XYZ, Bangkok is using ECMP to reach the 172.20.2.0/24 network. The company wants a design that would allow them to forward traffic from 172.16.2.0/24 toward 172.20.2.0/24 via the Singapore router as the preferred route. The rest of the traffic should continue to use ECMP. Which technology fulfills this design requirement?

Correct Answer: A. policy-based routing
Explanation:

Policy-Based Routing (PBR) allows traffic from a specific source (172.16.2.0/24) to follow a user-defined path (via Singapore), overriding the default ECMP behavior.

This solution is optimal for traffic steering when granular control is required for specific prefixes while leaving the rest of the traffic to use default ECMP routes.

Why other options are incorrect:

B: Route summarization affects route advertisements, not traffic forwarding paths for specific prefixes.

C: Unequal-cost load balancing influences overall ECMP behavior, not source-based forwarding control.

D: Loop-Free Alternate (LFA) is for fast failover, not policy-based forwarding decisions.

---


Question 12

Company XYZ network runs IPv4 and IPv6 and they want to introduce a multidomain, multicast-based network. The new design should use a flavor of PIM that forwards traffic using SPT. Which technology meets this requirement?

Correct Answer: C. PIM-SSM
Explanation:

PIM-SSM (Source-Specific Multicast) is optimized for multicast delivery directly via Shortest Path Tree (SPT) only.

SSM eliminates the need for shared trees (RPs), simplifies the control plane, and avoids rendezvous points altogether.

This design is highly scalable in multidomain and IPv6 environments, fully aligned with CCDE v3.1 best practices for modern multicast deployments.

Why other options are incorrect:

A: PIM-DM floods traffic initially, not SPT-based.

B: PIM-SM uses shared trees first and may switch to SPT later.

D: Bidir-PIM uses shared trees exclusively, not SPT.

---


Question 13

Organizations that embrace Zero Trust initiatives ranging from business policies to technology infrastructure can reap business and security benefits. Which two domains should be covered under Zero Trust initiatives? (Choose two)

Correct Answer: A. workload; C. workplace
Explanation:

Zero Trust principles cover multiple domains:

A (Workload): Securing application workloads regardless of location.

C (Workplace): Securing user access to services across office, remote, or hybrid work models.

Zero Trust design ensures authentication, authorization, and policy enforcement at every access point for both users and applications.

Why other options are incorrect:

B, D, E: These terms are not recognized Zero Trust domains in CCDE or industry frameworks.

---


Question 14

A network engineering team is in the process of designing a lab network for a customer demonstration. The design engineer wants to show that the resiliency of the MPLS Traffic Engineering Fast Reroute solution has the same failover/failback times as a traditional SONET/SDH network (around 50 msec). In order to address both link failure and node failure within the lab topology network, which type of the MPLS TE tunnels must be considered for this demonstration?

Correct Answer: D. Next-next-hop (NNHop) tunnel
Explanation:

To achieve sub-50ms protection against both link and node failures, MPLS TE Fast Reroute (FRR) with Next-Next-Hop (NNHop) protection is used:

Next-Next-Hop tunnels provide node protection by pre-establishing a detour that bypasses not only the immediate next-hop link but also the entire next node.

This ensures protection for both link and node failures, matching SONET/SDH resiliency targets.

Other options explained:

A & C: TE backup and FRR backup tunnels may only provide link protection depending on deployment.

B: Next-Hop tunnels address only link failures, not node failures.


Question 15

The administrator of a small branch office wants to implement the Layer 2 network without running STP. The office has some redundant paths. Which mechanism can the administrator use to allow redundancy without creating Layer 2 loops?

Correct Answer: B. Use two port channels as Flex links
Explanation:

B (Flex Links): Flex Links provide an alternative to Spanning Tree in simple Layer 2 designs. One link is active while the other is backup, preventing loops while maintaining redundancy without running STP.

Other options explained:

A: vPC requires more advanced hardware and configuration.

C: FabricPath is typically used in data centers, not small branches.

D: 802.3ad is link aggregation, not redundant path management.