Implementing Cisco Enterprise Advanced Routing and Services — Free Practice Questions
10 free sample questions from a bank of 961, with the correct answers and explanations. No signup required — start practising right now.
1Refer to the exhibit. R1 is configured with IP SLA to check the availability of the server behind R6but it kept failing.Which configuration resolves the issue?
D — Permit the ICMP echo-request from R1 source to server destination on R6. The ACL was dropping the probes.
Key concepts in this question
IP SLA icmp-echo: active probe from source-ip 10.10.10.1 to destination 10.66.66.66; does not require the IP SLA responder.
DDOS ACL on R6: applied inbound on E0/0 and E0/1 with deny icmp any any, blocking the echo-request.
Direction matters: the permit must match source 10.10.10.1 toward destination 10.66.66.66.
Why D is correct
Exhibit shows R1 probing icmp-echo 10.66.66.66 source-ip 10.10.10.1 with Timeout, R6 responder Disabled, and R6 interfaces filtering inbound with deny icmp any any. Cisco documents ICMP echo operation does not require the responder, while UDP jitter does, so enabling the responder cannot fix this probe. Permitting icmp host 10.10.10.1 to host 10.66.66.66 opens exactly the echo-request direction R1 to server and lets tracking come up.
Why the others are wrong
A. Enabling ip sla responder helps udp-jitter/tcp/udp-echo targets, not icmp-echo, which the exhibit already uses.
B. This permits the reverse direction destination to source, matching the echo-reply path, not the blocked echo-request from 10.10.10.1.
C. Configuring a udp-echo responder port answers a different operation type and leaves the denied icmp-echo untouched.
300-410 exam tip
icmp-echo needs no responder — when it times out behind an ACL, check the source-to-destination permit direction.
2Which label operations are performed by a label edge router?
SWAP and POP
SWAP and PUSH
PUSH and PHP
PUSH and POP
Answer: D
The short version
D — Edge (PE) routers PUSH on ingress and POP on egress. They are the MPLS boundary.
Key concepts in this question
Label edge router (LER/PE): sits at the MPLS domain edge facing IP networks.
PUSH: adds a label when an unlabeled packet enters MPLS.
POP: removes the label when the packet leaves MPLS toward IP.
Why D is correct
The edge router is the translation point: on ingress it classifies the IP packet into a forwarding equivalence class and PUSHes the label, and on egress it POPs the final label and hands plain IP to the customer or next domain. SWAP and PHP belong to core (LSR/P) routers in between, not the edge boundary function.
Why the others are wrong
A. SWAP and POP mixes a core transit operation with egress; edge ingress must PUSH.
B. SWAP and PUSH omits the required egress POP back to IP.
C. PUSH plus PHP pairs ingress correctly but assigns penultimate-hop popping, a core-router behavior, to the edge.
300-410 exam tip
Edge means in-and-out of MPLS — PUSH going in, POP going out.
3Refer to the exhibit. A network engineer is troubleshooting a failed link between R2 and R3. Notraffic loss is reported from router R5 to HQ. Which command fixes the separated backbone?
A — Remove the stub flag from transit Area 21 on R3. A virtual link cannot come up through a stub area.
Key concepts in this question
Partitioned backbone: Area 0 exists on both sides (R3 side and R2/R1/HQ side) and must be stitched through Area 21.
Virtual link: configured on both ABRs with area 21 virtual-link <neighbor-RID>; exhibit already shows R2 to 3.3.3.3 and R3 to 2.2.2.2.
Transit restriction: Cisco requires the transit area to have full routing info and explicitly forbids stub areas as transit.
Why A is correct
The log complains the backbone packet arrived but no virtual link was found, while the configs show both virtual-link ends already entered. The remaining blocker is R3 area 21 stub in the exhibit. Because a stub area carries no external routes, Cisco will not bring a virtual link through it, so the partitioned backbone stays split. Removing the stub flag from Area 21 on R3 (and consistently across Area 21) lets the already-configured virtual link establish and heals Area 0 continuity without touching R5/HQ, matching the no-loss report elsewhere.
Why the others are wrong
B. Re-adding area 21 virtual-link on R2 duplicates what the exhibit already has, and uses 192.168.125.5 from the log source field instead of the 3.3.3.3/2.2.2.2 RID pair.
C. R3 already has area 21 virtual-link 2.2.2.2 in the exhibit, so entering it again changes nothing while stub remains.
D. No exhibit evidence shows stub configured on R2; the stub line appears under R3, so clearing it on R2 misses the actual blocker.
300-410 exam tip
Virtual link already there plus stub equals still down — transit areas can never be stub.
4Refer to the exhibit. After a security hardening was performed on a router, the administratorcannot access the command line of any remote device. Which action resolves the issue?
Move Telnet and SSH commands to a nonzero privilege level.
Remove the egress ACL blocking Telnet and SSH on the router interfaces.
Remove the transport output none command from the line con 0 section.
Modify the AAA policy to allow the user to run the Telnet and SSH commands.
Answer: B
The short version
B — Strip the egress ACL that hardening left blocking outbound Telnet and SSH. Management initiation is filtered at the interfaces.
Key concepts in this question
Security hardening: interface ACLs applied in the outbound direction to restrict what the router itself may initiate.
Egress ACL effect: telnet/ssh attempts from the router toward any remote device are denied at every interface, so no remote CLI is reachable.
Exhibit scope: the captured output shows failed outbound attempts with no line-configuration section implicating a specific line.
Why B is correct
After hardening, the administrator cannot reach the command line of any remote device from this router — a uniform outbound failure consistent with an egress interface ACL denying tcp/22 and tcp/23 in the outward direction. Removing that blocking ACL restores the router's ability to initiate Telnet and SSH. The banked answer is additionally confirmed by an independent second source answering the identical stem with the egress-ACL text.
Why the others are wrong
A. Moving commands to a nonzero privilege level changes who may run them, not whether packets leave the interfaces; all devices failing uniformly points at the path, not privilege.
C. Transport output none is line-scoped (con 0 covers console-originated sessions only) and the exhibit presents no line con 0 section; it cannot explain failure from every access path.
D. AAA governs authentication/authorization of the session itself, which is already established on the local device; the failure is reaching outward, not logging in.
300-410 exam tip
Hardening broke all outbound management at once — look at the interfaces, not the lines.
5Which three IP SLA performance metrics can you use to monitor enterprise-class networks?(Choose three.)
Packet loss
Delay
bandwidth
Connectivity
Reliability
traps
Answer: A, B, D
The short version
A, B and D — IP SLA monitors packet loss, delay, and connectivity. Those are its core enterprise performance signals.
Key concepts in this question
IP SLA: Cisco active-measurement feature generating synthetic traffic between source and responder.
Loss/delay/reachability: the classic SLA triple for voice, video, and application health.
Distractors: bandwidth estimation, reliability counters, and SNMP traps are adjacent concepts, not SLA metrics.
Why A, B and D are correct
IP SLA operations (icmp-echo, udp-jitter, tcp-connect) directly measure whether the path is reachable (connectivity), how many probes vanish (packet loss), and how long they take (delay/jitter). Enterprises threshold exactly these three to validate SLAs, trigger tracking and failover, and troubleshoot user experience.
Why the others are wrong
C. Raw bandwidth is measured by other tools (e.g., throughput tests); IP SLA characterizes quality of the path, not capacity.
E. Reliability is a generic interface counter concept, not an IP SLA operation metric.
F. Traps are an SNMP notification mechanism for Threshold violations, not a measured performance metric.
300-410 exam tip
IP SLA answers three questions — can I reach it, how much is lost, how slow is it.
6After some changes in the routing policy, it is noticed that the router in AS 45123 is being used asa transit AS router for several service provides. Which configuration ensures that the branchrouter in AS 45123 advertises only the local networks to all SP neighbors?
ip as-path access-list 1 permit ^45123 | router bgp 45123 | neighbor SP-Neighbors filter-list 1 out
ip as-path access-list 1 permit ^$ | router bgp 45123 | neighbor SP-Neighbors filter-list 1 out
ip as-path access-list 1 permit .* | router bgp 45123 | neighbor SP-Neighbors filter-list 1 out
ip as-path access-list 1 permit ^45123$ | router bgp 45123 | neighbor SP-Neighbors filter-list 1 out
Answer: B
The short version
B — Filter outbound with permit ^$ so only locally originated prefixes leave AS 45123. Empty path means local.
Key concepts in this question
Transit AS: a multihomed router re-advertising one SP's routes to another SP, carrying чужой traffic.
AS-path ACL regex: ^$ matches the empty AS_PATH, which is exactly how locally originated prefixes look to an outbound filter.
filter-list out: applies the AS-path ACL to advertisements toward the SP neighbors.
Why B is correct
Cisco's transit-prevention recipe is precisely ip as-path access-list 1 permit ^$ plus neighbor SP-Neighbors filter-list 1 out: the ^$ expression admits only locally originated prefixes and suppresses everything learned from other providers, so the branch router stops offering transit while its own networks stay advertised. The exhibit options share the same router/filter-list skeleton and differ only in the regex, making B the unique fix.
Why the others are wrong
A. ^45123 admits only paths beginning with 45123, which at outbound-filter time matches neither local (empty path) nor received routes usefully, breaking local advertisements.
C. .* permits every AS_PATH, which is the unfiltered behavior causing the transit problem in the first place.
D. ^45123$ demands a path of exactly one occurrence of 45123; locally originated prefixes present an empty path to the outbound filter, so locals would be suppressed too.
300-410 exam tip
Stop transit with caret-dollar — ^$ means born here, everything else stays inside.
7Which statement about MPLS LDP router ID is true?
The force keyword changes the router ID to the specific address causing any impact.
The loopback with the highest IP address is selected as the router ID.
If not configured, the operational physical interface is chosen as the router ID even if a loopbackis configured.
If MPLS LDP router ID must match the IGP router ID.
Answer: B
The short version
B — LDP picks the highest-IP loopback as router ID by default. Stable loopbacks beat flapping physical interfaces.
Key concepts in this question
LDP router ID: stable identifier for the LDP entity and its TCP session.
Default election: highest IP among operational loopbacks, else highest operational physical interface.
Force keyword: changes the ID but tears down LDP sessions in the process.
Why B is correct
Without an explicitly configured mpls ldp router-id, Cisco LDP follows the documented election: prefer loopback interfaces for stability and choose the numerically highest IP among them. That guarantees a persistent, reachable ID that survives individual link flaps, unlike a physical interface address.
Why the others are wrong
A. The force keyword does change the ID but it disrupts LDP adjacencies and sessions — it is not impact-free.
C. Physical interfaces are only chosen when no loopback exists; loopbacks win whenever present.
D. LDP and IGP router IDs are independent; matching them is good practice, not a requirement.
300-410 exam tip
No LDP ID configured means highest loopback — loopbacks first, biggest address wins.
8Refer to the exhibit. A network engineer for AS64512 must remove the inbound and outboundtraffic from link A during maintenance without closing the BGP session so that there is still abackup link over link A toward the ASN.Which BGP configuration on R1 accomplishes this goal?
Answer:
The short version
A — Prefer outbound via link B and de-prefer inbound on link A. Only A moves both directions without touching the session.
Key concepts in this question
Outbound from R1: chosen by R1 itself; weight wins first, then local-preference. Raising link-b-in above link-a-in shifts R1's egress to link B.
Inbound to R1: chosen by the neighbor AS, influenced from R1 by making the link-A advertisement less attractive, classically with AS-path prepend on link-a-out.
Session stays up: all options are route-maps, so no shutdown is involved; correctness is purely which direction each policy pushes.
Why A is correct
Exhibit topology has R1 multihomed to AS64513 over link A (R1-R2) and link B (R1-R3) with per-link route-maps. Option A (freecram block image 187, labeled A) sets local-preference 200 on link-b-in, so R1 prefers link B for outbound, and prepends 64512 on link-a-out, so the neighbor prefers link B for inbound. Nothing is prepended on link B and no weight pulls traffic to A, making A a quiet backup while the session stays established.
Why the others are wrong
B. Sets weight 200 on link-a-in against 100 on link-b-in, pinning outbound on A, and prepends on link-b-out, pushing inbound onto A too — the opposite of the goal.
C. Sets local-preference 200 on link-a-in, pinning outbound on A, and prepends on link-b-out, de-preferring the very link that should carry traffic.
D. The prepend on link-a-out helps inbound, but weight 200 on link-a-in keeps outbound on A, so traffic is not removed from link A as required.
300-410 exam tip
Move outbound with local-pref on the good link, move inbound with prepend on the bad link — never both on the same link.
9Drag and Drop QuestionDrag and drop the MPLS concepts from the left onto the descriptions on the right.
Answer:
The short version
Edge imposes, core swaps, FEC groups, PHP pops early. Four standard MPLS definitions.
Label switch router (LSR): core box that receives labeled packets and SWAPs labels.
Forwarding equivalence class (FEC): group of packets forwarded the same manner and bound to one label.
Penultimate hop popping (PHP): lets the LSR before the egress remove the label early.
Why this mapping is correct
The edge router is where unlabeled IP enters MPLS, so it accepts unlabeled packets and imposes labels. Core LSRs never see IP — they receive labeled packets and swap labels. A FEC is by definition the equivalence grouping that shares forwarding treatment. PHP exists so the second-to-last hop pops, sparing the egress an extra lookup, which is exactly what the remove-before-forwarding description states.
Why the others are wrong
Edge as swapper confuses boundary PUSH/POP with core SWAP.
LSR as imposer assigns the ingress function to a transit box.
FEC as a device mistakes a packet grouping for a router role.
PHP as ingress PUSH inverts early removal into label imposition.
300-410 exam tip
Edge touches IP, core touches labels, FEC is the group, PHP pops one hop early.
10Which BGP attribute can be used to influence the path that outgoing traffic takes from your AS toother Autonomous Systems? (Choose two.)
Local Preference
Weight
AS_Path
MED
Answer: A, B
The short version
A and B — Local Preference and Weight steer outbound path selection. Both prefer one exit over another.
Key concepts in this question
Outbound influence: control which exit your AS uses toward other autonomous systems.
Weight: Cisco-local, per-router, highest wins, never advertised.
Local Preference: AS-wide BGP attribute, highest wins, advertised iBGP-only.
Why A and B are correct
For traffic leaving the AS, the local router first compares Weight and then Local Preference before any AS-path or MED logic, so raising either on the desired exit deterministically pulls outbound flows that way. Weight scopes the policy to one router while Local Preference applies it consistently across the AS — together they are the standard outbound traffic-engineering pair.
Why the others are wrong
C. AS_Path length primarily helps others choose how to reach you (inbound) and acts later in best-path for outbound.
D. MED is advertised outward to influence how neighbors send traffic back in — an inbound knob, not outbound.
300-410 exam tip
Leaving your AS means Weight then Local Pref — remember outbound is local-first, MED is for inbound.