Designing Cisco Enterprise Networks — Free Practice Questions
10 free sample questions from a bank of 459, with the correct answers and explanations. No signup required — start practising right now.
1Which are two advantages of a "one switch at a time" approach to integrating SD-Access into an existing brown field environment? (Choose two.)
opens up many new design and deployment opportunities
appropriate for campus and remote site environments
allows simplified roll back
involves the least risk of all approaches
ideal for protecting recent investments while upgrading legacy hardware
allows simplified testing prior to cutover
Answer: B, E
The short version
B and E — One-switch-at-a-time fits campuses and remote sites while protecting recent investments. Swapping a single switch limits blast radius and reuses the surrounding plant, which suits distributed brownfield estates with newer gear worth keeping.
Key concepts in this question
Brownfield SD-Access: layering fabric on an existing live network.
Incremental migration: convert one switch, validate, then move to the next.
Investment protection: keep recent purchases in service during modernization.
Why B and E are correct
A single-switch cutover is small enough to schedule per closet or per remote site, so it suits campus and branch environments in B, and because neighboring gear stays untouched, recently bought hardware keeps earning its keep, which is E. Together they describe the low-disruption, budget-friendly appeal of the approach.
Why the others are wrong
A. Wide-open redesign belongs to greenfield or full replacements, not a one-box swap.
C. Rollback still means reverting that switch's config and cables; parallel or lab-first methods simplify it more.
D. Least-risk titles go to approaches with full parallel fallback, not to touching the live box.
F. Testing is easiest in an isolated lab or parallel block, not on the single production switch.
300-420 exam tip
One switch at a time equals one site at a time on a budget: campus-friendly and investment-friendly.
2Refer to the exhibit. A customer requires maximum uptime for the data plane between R1 and R3 running OSPF. Which solution must the design include for high availability if the routing process on R2 requires maintenance?
BFD on all routers
nonstop forwarding on R3 only
graceful restart on all routers
nonstop forwarding on R1 and R3
Answer: C
The short version
C — Graceful restart on all routers keeps traffic flowing during the R2 maintenance. The restarting router asks its neighbors to preserve forwarding state while OSPF rebuilds, so the R1 to R3 data plane never drops.
Key concepts in this question
Graceful restart: control plane restarts while the forwarding plane keeps passing traffic.
Helper mode: neighbors hold adjacencies and LSAs stable during the restart window.
Data-plane uptime: forwarding continues even though OSPF is reconverging.
Why C is correct
When the OSPF process on R2 restarts, graceful restart lets R2 signal R1 and R3 to act as helpers that maintain their forwarding entries and adjacency state. The restart completes without tearing down the path, so R1-to-R3 traffic survives the maintenance — but only if every participant speaks graceful restart, hence all routers in C.
Why the others are wrong
A. BFD detects failures faster, which triggers reconvergence rather than preventing it.
B. Nonstop forwarding on R3 alone cannot help an R2 restart; helpers must surround the restarting box.
D. Forwarding resilience on R1 and R3 still leaves R2 unable to request or coordinate the hitless restart.
300-420 exam tip
Restarting router plus helpers equals hitless: graceful restart must be on all of them.
3Which two LISP components are required in the Cisco SD-Access fabric control plane node?(Choose two.)
Engress Tunnel Router
Proxy ETR
Map-Resolver
Ingres Tunnel Router
Map-Server
Answer: C, E
The short version
C and E — The fabric control-plane node runs the Map-Resolver and Map-Server. These two LISP services form the mapping database that edge nodes query, while tunnel routers handle encapsulation.
Key concepts in this question
Map-Server: accepts registrations and holds endpoint-to-locator mappings.
Map-Resolver: answers mapping queries from edge tunnel routers.
Control vs data plane: mapping services versus encapsulation boxes.
Why C and E are correct
In SD-Access the control-plane node implements the LISP mapping system: the Map-Server learns and stores which endpoint sits behind which edge node, and the Map-Resolver replies when an ingress node asks where to send traffic. Both roles live on the control-plane node, so C and E are required together.
Why the others are wrong
A. Egress tunnel router decapsulates at the destination edge — a data-plane role.
B. Proxy ETR bridges LISP and non-LISP sites, not the mapping database.
D. Ingress tunnel router encapsulates at the source edge — again data plane.
300-420 exam tip
Mapping questions want MR and MS; tunneling questions want ITR and ETR.
4An engineer is designing a networking solution to allow two hosts to communicate-one host located within the company A network and the other within the company B network. The two companies have no other plans for future additional connections. Both companies want to use a single secure and encrypted internet connection, and the configuration must be as simple as possible. Which network solution must the engineer choose?
MPLS VPN provided service with BGP routing
policy-based IPsec tunnel with static routing
single DMVPN with EIGRP routing
routed IPsec tunnel with OSPF routing
Answer: B
The short version
B — Two companies with one simple encrypted link want policy-based IPsec with static routing. One tunnel, one peer, no future growth: static crypto plus a static route is the fewest moving parts.
Key concepts in this question
Policy-based IPsec: interesting traffic selected by ACL, encrypted to a single peer.
Static routing: one route pointing the remote subnet at the tunnel.
Simplicity rule: no dynamic multipoint or provider service for a single pair.
Why B is correct
With exactly two endpoints and no expansion plans, there is nothing for DMVPN, EIGRP, OSPF, or MPLS to optimize. A policy-based IPsec tunnel gives the required encryption over the internet and a static route aims the remote host subnet at it, satisfying every requirement with the simplest configuration, so B is correct.
Why the others are wrong
A. MPLS VPN with BGP needs a provider and suits many sites, not one internet tunnel.
C. DMVPN with EIGRP adds hub, NHRP, and dynamic routing for growth that was ruled out.
D. Routed IPsec with OSPF fits complex topologies; it is overkill for one host pair.
300-420 exam tip
One tunnel and no growth means static and simple: policy IPsec plus a static route.
5In Cisco SD-Access, virtual networks create segmentation that allows for separation of users and resources. How is this type of segmentation described?
inter-VN
micro
macro
stretched
Answer: C
The short version
C — Virtual-network separation is macro-segmentation. VNs carve the fabric into isolated routing domains, while micro-segmentation with group tags refines policy inside a VN.
Key concepts in this question
Macro-segmentation: coarse isolation via virtual networks.
Micro-segmentation: fine policy via scalable group tags within a VN.
Inter-VN: controlled leaking between macro segments, not the segments themselves.
Why C is correct
SD-Access virtual networks give each user or resource group its own address space and routing table, so traffic cannot cross without explicit fusion — the textbook definition of macro-segmentation. The question describes that VN-level separation of users and resources, making C the exact term.
Why the others are wrong
A. Inter-VN names traffic shared between segments, not the segmentation itself.
B. Micro-segmentation is group-based policy inside a segment, finer than a VN.
D. Stretched describes extending a segment across sites, not creating it.
300-420 exam tip
VN equals macro, tag equals micro: the size of the boundary tells you the term.
6Refer to the exhibit. An engineer is designing a routing solution for a customer. The design must ensure that a failure of network 10.1.0.0/24, 10.1.2.0/24, 10.2.1.0/24, or 10.2.3.0/24 does not impact the core. It also requires fast convergence time during any link failover in the core or access networks.Which solution must the engineer select?
Enable FRR for the connected networks of routers A and C.
Enable summarization on routers A and C.
Enable graceful restart on routers A and C.
Add aggregation layer between core and access networks.
Answer: A
The short version
A — Fast Reroute on routers A and C protects the core with instant backup paths. Precomputed alternates for the access prefixes fail over immediately, so core and access link failures converge without waiting on full SPF.
Key concepts in this question
FRR: precomputed loop-free alternate ready before the failure.
Summarization: hides detail and shrinks tables at boundaries.
Convergence vs isolation: speed of failover versus hiding of churn.
Why A is correct
The design demands both containment and speed, and FRR on the boundary routers A and C delivers the speed: backup next hops for the listed access networks are installed ahead of time, so any core or access link failure switches in milliseconds. That fast-failover behavior is what the key tests, making A correct.
Why the others are wrong
B. Summarization isolates prefixes nicely but does not itself accelerate failover.
C. Graceful restart survives control-plane restarts, not link failures in core or access.
D. Adding an aggregation layer is a redesign, not the targeted fast-convergence mechanism.
300-420 exam tip
Fast failover means precomputed: link-failure speed questions want FRR.
7A company wants to deploy IPv6 within its existing network infrastructure. All current infrastructure equipment supports IPv6, and the company wants a migration strategy that must not require purchasing additional equipment. The plan must keep operational management costs low, support IPv6 multicast, and allow applications to migrate using DNS. Which strategy must the company choose?
hybrid ISATAP tunnel model
dual-stack model
hybrid manual tunnel model
service block model
Answer: B
The short version
B — Native dual-stack is the no-new-gear IPv6 migration. Running both protocols on existing boxes keeps management simple, supports multicast, and lets DNS move applications one name at a time.
Key concepts in this question
Dual-stack: IPv4 and IPv6 routing side by side on the same interfaces.
Multicast parity: IPv6 multicast runs natively instead of through tunnels.
DNS-driven migration: A and AAAA records steer each application independently.
Why B is correct
Since every device already supports IPv6, enabling it alongside IPv4 needs no purchases, adds no tunnel overlays to operate, carries IPv6 multicast natively, and lets each application cut over by publishing AAAA records when ready. No other option meets all four constraints at once, so B is correct.
Why the others are wrong
A. ISATAP tunnels add overlay operations and weaken native multicast support.
C. Manual tunnels mean per-link configuration and scaling overhead.
D. A service block segments new gear or services apart instead of migrating in place.
300-420 exam tip
No new boxes plus multicast plus DNS equals dual-stack every time.
8Refer to the exhibit. Which route filtering technique is required within AS64514 to ensure that BGP prefixes originating locally are not accepted from AS64512 or AS64513?
an as-path access-list matching the originating AS number attached to a deny route-map statement, with route-map applied to each neighbor inbound
no prefix-list or as-path access-list filtering technique is to be applied to each neighbor, either inbound or outbound
a prefix-list matching the locally originated prefixes attached to a deny route-map statement, with the route-map applied to each neighbor inbound
an as-path access-list matching the originating AS number attached to a deny route-map statement, with route-map applied to each neighbor outbound
Answer: A
The short version
A — Block your own prefixes inbound with an AS-path filter on every neighbor. An AS-path access list matching the local AS in a deny route-map entry drops looped or leaked advertisements before they enter the table.
Key concepts in this question
AS-path filtering: match the AS sequence rather than enumerating prefixes.
Inbound direction: inspect routes as they arrive from each eBGP peer.
Local origination: prefixes born locally must never be relearned from outside.
Why A is correct
Any locally originated prefix that reappears from a neighboring AS carries an AS path containing the local AS — the signature of a loop or leak. Denying that pattern inbound on each neighbor with an AS-path access list kills all such advertisements with one rule regardless of how many prefixes exist, which is exactly the required technique in A.
Why the others are wrong
B. No filtering leaves the door open to accepting the looped prefixes.
C. A prefix-list of local prefixes could work but needs constant upkeep; the keyed design matches on origin AS instead.
D. Outbound filtering polices what you advertise, not what you accept from peers.
300-420 exam tip
Stop your own routes coming back by filtering your own AS number on the way in.
9Refer to the exhibit. Due to budget constraints, a customer decided to purchase WAN routers with one LAN and one WAN interface per device. There is a requirement to connect the three sites to ensure high availability without buying additional WAN links. Which design deployment must the customer choose?
single-homed hub-and-spoke
single-homed full mesh
dual-homed hub-and-spoke
dual-homed full mesh
Answer: A
The short version
A — One LAN plus one WAN per box with no new links means single-homed hub-and-spoke. Spokes use their single WAN uplink to the hub, which relays between sites and needs no extra interfaces or circuits.
Key concepts in this question
Single-homed: one uplink per device toward the WAN.
Hub-and-spoke: branches reach each other through a central hub.
Budget fit: no second link and no added ports.
Why A is correct
Each router can only offer one WAN circuit, so branches cannot mesh directly without more links. Pointing every spoke's lone uplink at a hub uses exactly the available ports, and the hub relays spoke-to-spoke traffic, delivering any-to-any reachability through the hub — the only topology the hardware budget allows, so A is correct.
Why the others are wrong
B. Full mesh needs a link or tunnel per pair, exceeding one WAN interface per box.
C. Dual-homed designs need a second uplink or provider per site, which the budget forbids.
D. Dual-homed full mesh doubles the shortfall with extra links everywhere.
300-420 exam tip
Count the WAN ports first: one uplink each forces single-homed, and no extra links force hub-and-spoke.
10Which is a benefit of a cloud-based SD-WAN deployment?
security never an issue
controller availability never an issue
might be required for compliance with industry standards
instant scale
agility of change dependent only on your own internal IT processes
Answer: D
The short version
D — The honest cloud SD-WAN benefit is instant scale. Elastic controllers and gateways spin up on demand, while security, availability, and compliance still need real design work.
Key concepts in this question
Elasticity: consume controller and gateway capacity as needed.
Shared responsibility: the provider hosts, you still secure and govern.
Absolute answers: options promising never are classic exam traps.
Why D is correct
Cloud-hosted SD-WAN lets an enterprise add regions, branches, and bandwidth without procuring and racking controllers, because the platform scales out on demand. That on-tap growth is the genuine, defensible advantage in D, unlike the absolute guarantees in the distractors.
Why the others are wrong
A. Security is shared, never automatic; policy and segmentation remain yours.
B. Controller availability still depends on design, regions, and SLAs.
C. Compliance may actually force on-premises control instead of cloud.
E. Change agility depends on provider processes and windows, not only internal IT.
300-420 exam tip
Distrust never in cloud options; the safe cloud win is scale on demand.