Question 1
A network architect is tasked to develop a design where it is a requirement to group resources according to their security and trust level in the network. Which tool can be leveraged to achieve this?
A network architect is tasked to develop a design where it is a requirement to group resources according to their security and trust level in the network. Which tool can be leveraged to achieve this?
An enterprise has identified these causes for inefficient CAPEX spending:
CAPEX planning is driven by technology and not by business objectives.
The CAPEX planning team lacks the data it needs to perform due diligence tasks.
The organizational structure lacks sufficient accountability and incentives.
Which corporate cultural change contributes to improving the effectiveness of CAPEX spending?
C (Accountability for ROI):Shifting focus toward ROI ensures that capital investment is evaluated based on business impact rather than just financial outputs like revenue and EBITDA, aligning technology spending with business value.
Other options explained:
A: Financial reporting doesn't address accountability.
B: Misrepresents leadership responsibility.
D: Budget cuts don't address the structural root cause.
What is a key benefit of Infrastructure as Code (IaC)?
D: Repeatable deployments are one of the core benefits of IaC. It allows infrastructure to be provisioned consistently every time using version-controlled templates.
Incorrect options:
A: Declarative pipelines relate more to CI/CD processes than directly to IaC.
B: IaC helps prevent configuration drift, but drift itself is a problem---not a benefit.
C: Agent monitoring is a function of monitoring tools, not IaC.
It is often seen that companies pick a cloud vendor solely based on technical preferences without putting enough weight on the business strategies that are driving the cloud initiatives Which strategic requirement may come into play where it is more likely that the decision makers will look to leverage laaS over SaaS or PaaS?
Company XYZ connects its sites over a private WAN. Their overlay network is running a DMVPN setup where the headquarters site is the hub. The company is planning on implementing multicast routing on the network. What should be used in the multicast routing design?
C (PIM Sparse Mode with RP located at the hub):DMVPN networks typically leverage sparse mode multicast due to their efficiency in dynamic topologies. Locating the Rendezvous Point (RP) at the hub simplifies multicast state management, since the hub serves as the central aggregation point and ensures optimal rendezvous functionality without requiring complex RP placement across spokes.
Other options explained:
A: Dense mode is inefficient and generates unnecessary flooding, especially in WAN environments.
B/D: Placing RPs at remote sites introduces unnecessary complexity and operational challenges.
Before migrating anything to the cloud, what are three cloud readiness assessment steps that are required to perform? (Choose three.)
What are two primary design constraints when a robust infrastructure solution is created? (Choose two.)
In infrastructure design, primary constraints are:
D (Component availability): If hardware or software components are not readily available, designs may need to adapt.
E (Total cost): Budget limitations always influence design decisions regarding redundancy, scalability, and technology selection.
Why other options are not primary constraints:
A: Monitoring is a design consideration, but not a core constraint.
B: Time frame impacts project delivery, not necessarily the design robustness.
C: Staff experience affects operations but is not a primary technical design constraint.
---
Refer to the exhibit.

As part of a redesign project, you must predict multicast behavior. What happens to the multicast traffic received on the shared tree (*,G), if it is received on the LHR interface indicated?
In PIM Sparse Mode, when the Last-Hop Router (LHR) receives multicast traffic on the shared tree (*,G), it performs an RPF check based on the RP address, not the multicast source address. In the diagram:
The LHR has IGP cost 10 towards the RP.
The shared tree (*,G) uses RP as the RPF target.
Since multicast traffic on (*,G) arrives on the interface toward RP (correct RPF interface), the RPF check succeeds.
Therefore, the multicast traffic is successfully switched toward the receivers.
This behavior is fully aligned with CCDE v3.1 multicast design principles, which emphasize clear understanding of RPF behavior both on shared trees (*,G) and source trees (S,G).
Why other options are incorrect:
A: The RPF check is not performed against the source in (*,G); it uses RP.
B: RPF checks are always performed, even on (*,G).
D: RPF is unrelated to the receiver address.
Reter to the exhibit This network is running OSPF and EIGRP as the routing protocols Mutual redistribution of the routing protocols has been contoured on the appropriate ASBRs The OSPF network must be designed so that flapping routes m EIGRP domains do not affect the SPF runs within OSPF The design solution must not affect the way EIGRP routes are propagated into the EIGRP domains Which technique accomplishes the requirement?
Router R1 is a BGP speaker with one peering neighbor over link "A". When link "A" fails, routing announcements are terminated, which results in the tearing down of the state for all BGP routes at each end of the link. What is this a good example of?
D (Fate sharing):Fate sharing refers to a design where multiple dependent states fail together (i.e., when physical link fails, BGP session and its routes fail too).
Other options explained:
A: Fault isolation refers to containing failures, not dependent failure.
B: Resiliency is the ability to recover, not simultaneous failure.
C: Redundancy would prevent total loss if implemented.
Refer to the exhibit.

For Company XYZ, Bangkok is using ECMP to reach the 172.20.2.0/24 network. The company wants a design that would allow them to forward traffic from 172.16.2.0/24 toward 172.20.2.0/24 via the Singapore router as the preferred route. The rest of the traffic should continue to use ECMP. Which technology fulfills this design requirement?
Policy-Based Routing (PBR) allows traffic from a specific source (172.16.2.0/24) to follow a user-defined path (via Singapore), overriding the default ECMP behavior.
This solution is optimal for traffic steering when granular control is required for specific prefixes while leaving the rest of the traffic to use default ECMP routes.
Why other options are incorrect:
B: Route summarization affects route advertisements, not traffic forwarding paths for specific prefixes.
C: Unequal-cost load balancing influences overall ECMP behavior, not source-based forwarding control.
D: Loop-Free Alternate (LFA) is for fast failover, not policy-based forwarding decisions.
---
Company XYZ network runs IPv4 and IPv6 and they want to introduce a multidomain, multicast-based network. The new design should use a flavor of PIM that forwards traffic using SPT. Which technology meets this requirement?
PIM-SSM (Source-Specific Multicast) is optimized for multicast delivery directly via Shortest Path Tree (SPT) only.
SSM eliminates the need for shared trees (RPs), simplifies the control plane, and avoids rendezvous points altogether.
This design is highly scalable in multidomain and IPv6 environments, fully aligned with CCDE v3.1 best practices for modern multicast deployments.
Why other options are incorrect:
A: PIM-DM floods traffic initially, not SPT-based.
B: PIM-SM uses shared trees first and may switch to SPT later.
D: Bidir-PIM uses shared trees exclusively, not SPT.
---
Organizations that embrace Zero Trust initiatives ranging from business policies to technology infrastructure can reap business and security benefits. Which two domains should be covered under Zero Trust initiatives? (Choose two)
Zero Trust principles cover multiple domains:
A (Workload): Securing application workloads regardless of location.
C (Workplace): Securing user access to services across office, remote, or hybrid work models.
Zero Trust design ensures authentication, authorization, and policy enforcement at every access point for both users and applications.
Why other options are incorrect:
B, D, E: These terms are not recognized Zero Trust domains in CCDE or industry frameworks.
---
A network engineering team is in the process of designing a lab network for a customer demonstration. The design engineer wants to show that the resiliency of the MPLS Traffic Engineering Fast Reroute solution has the same failover/failback times as a traditional SONET/SDH network (around 50 msec). In order to address both link failure and node failure within the lab topology network, which type of the MPLS TE tunnels must be considered for this demonstration?
To achieve sub-50ms protection against both link and node failures, MPLS TE Fast Reroute (FRR) with Next-Next-Hop (NNHop) protection is used:
Next-Next-Hop tunnels provide node protection by pre-establishing a detour that bypasses not only the immediate next-hop link but also the entire next node.
This ensures protection for both link and node failures, matching SONET/SDH resiliency targets.
Other options explained:
A & C: TE backup and FRR backup tunnels may only provide link protection depending on deployment.
B: Next-Hop tunnels address only link failures, not node failures.
The administrator of a small branch office wants to implement the Layer 2 network without running STP. The office has some redundant paths. Which mechanism can the administrator use to allow redundancy without creating Layer 2 loops?
B (Flex Links): Flex Links provide an alternative to Spanning Tree in simple Layer 2 designs. One link is active while the other is backup, preventing loops while maintaining redundancy without running STP.
Other options explained:
A: vPC requires more advanced hardware and configuration.
C: FabricPath is typically used in data centers, not small branches.
D: 802.3ad is link aggregation, not redundant path management.