Sign In
Home/Cisco/Designing and Implementing Enterprise Network Assurance/Free questions

Designing and Implementing Enterprise Network Assurance — Free Practice Questions

10 free sample questions from a bank of 64, with the correct answers and explanations. No signup required — start practising right now.

1Drag and Drop QuestionAn engineer must set up maximum rate throughput testing between two Cisco ThousandEyes agents. Drag and drop the ThousandEyes test options from the bottom onto the boxes in the configuration screen, which allows for maximum rate throughput testing. Some options may be used more than once. Not all options are used.
    Answer:

    Answer

    MATCH — Agent-to-agent TCP maximum-rate mapping. Test type plus agent pair plus TCP maximum-rate measurement gives maximum throughput between two agents.

    Key concepts in this question

    Throughput needs agent pair plus TCP maximum rate. Agent-to-agent test type measures between Enterprise Agents; source plus destination defines the path; TCP maximum-rate reports the ceiling.

    Why this mapping is correct

    Each box matches its throughput role. Agent-to-agent test type enables agent-pair measurement, source plus destination agents fix both ends of the path, and TCP maximum-rate throughput measures the ceiling; HTTP and ICMP options cannot report bulk TCP throughput.

    300-445 exam tip

    Two agents plus maximum rate equals agent-to-agent TCP throughput.

    2Which type of test are we using for these dashboards (Executive and IT Operations)?
    • HTTP server
    • Page Load
    • Agent to server
    • FTP
    Answer: B

    The short version

    B — Executive and IT Operations views come from Page Load tests. Those dashboards need full browser timing, element waterfall, and user-experience metrics, not just reachability.

    Key concepts in this question

    • Page Load test: loads a URL in a real browser and records navigation, DOM, and asset timing.
    • Executive dashboard: business-level availability and experience trends.
    • IT Operations dashboard: deeper page-component breakdown for triage.

    Why B is correct

    Both dashboards visualize end-user web experience: availability, load time, and where time is spent. Only the Page Load test type renders the page and collects those browser metrics, so it is the feed behind the Executive and IT Operations views described.

    Why the others are wrong

    • A. HTTP server tests check status code and response time without rendering, so they cannot populate page-component experience widgets.
    • C. Agent-to-server tests measure network path to a ThousandEyes server, not application page rendering.
    • D. FTP tests monitor file-transfer service health, which is unrelated to web dashboard experience data.

    300-445 exam tip

    Dashboard says user experience and page breakdown equals Page Load; uptime-only equals HTTP server.

    3Your organization wants to be notified of an event as soon as it is triggered by an alert threshold.This notification should be sent to your ITSM and generate an incident so it can be responded to appropriately. What kind of integration should you use?
    • ServiceNow Integration
    • DNA Center Integration
    • Custom Webhooks
    • Alerts API
    Answer: A

    The short version

    A — ITSM incident creation means ServiceNow Integration. It turns an alert-threshold event directly into an ITSM incident for response.

    Key concepts in this question

    • Alert threshold: fires when a ThousandEyes condition is met.
    • ITSM workflow: auto-open, update, and close incidents in the ticketing system.
    • Native integration: ServiceNow mapping is built for incident lifecycle, unlike generic hooks.

    Why A is correct

    The requirement is immediate notification into ITSM that generates an incident. The ServiceNow Integration does exactly that: on alert it creates and synchronizes an incident so operators can respond, without custom parsing or polling code.

    Why the others are wrong

    • B. DNA Center integration shares network-device context, not ITSM incident creation.
    • C. Custom webhooks can forward JSON anywhere but require extra ITSM-side work; they are not the purpose-built incident integration.
    • D. The Alerts API lets scripts poll or fetch alert data, which is slower and manual compared with automatic incident generation.

    300-445 exam tip

    Stem says ITSM plus generate an incident equals ServiceNow; webhook or API equals custom or pull.

    4Drag and Drop QuestionDrag and drop the commands from the bottom onto the boxes in the configuration to modify the DNS servers on an Enterprise Agent running on a Cisco Catalyst 9300 Switch.
      Answer:

      Answer

      MATCH — Catalyst app-hosting DNS mapping. Config mode plus agent app selection plus name-server addresses changes Enterprise Agent DNS on the switch.

      Key concepts in this question

      On-switch agent DNS lives under app-hosting. configure terminal enters config; app-hosting appid selects the ThousandEyes agent; name-server lines set resolver IPs.

      Why this mapping is correct

      Each command matches its configuration role. configure terminal opens global config, app-hosting appid scopes edits to the ThousandEyes agent instance, and the name-server entries replace the DNS resolvers; no shutdown only controls app state and does not set DNS.

      300-445 exam tip

      Catalyst agent DNS equals app-hosting appid plus name-server.

      5You are tasked with creating a ThousandEyes transaction test to monitor the login process of a web application that uses SAML-based SSO with MFA. The MFA step involves a one-time password (OTP) generated by a mobile app. How can you configure the ThousandEyes test to successfully navigate this login process?
      • Configure the test to automatically enter the OTP from the mobile app.
      • Manually enter the OTP in the test configuration each time it changes.
      • Use a ThousandEyes webhook to retrieve the OTP from a third-party service.
      • Exclude the MFA step from the transaction test and focus only on the SAML login.
      Answer: D

      The short version

      D — Skip the mobile-app OTP step and test only the SAML login. A rotating one-time password cannot be scripted reliably, so scope the transaction to what automation can cover.

      Key concepts in this question

      • Transaction test: scripted browser steps that replay a user flow.
      • SAML SSO: redirect-based login that can be scripted up to credential submit.
      • MFA OTP: time-based code from a separate device that changes every cycle.

      Why D is correct

      ThousandEyes transaction scripts cannot fetch a fresh OTP from a mobile authenticator app. Trying to hardcode or auto-enter it fails on the next rotation. The supported pattern is to exclude the MFA step and monitor the SAML login flow itself, keeping the test stable and still catching app and IdP failures.

      Why the others are wrong

      • A. Automatically entering the mobile-app OTP is not possible; the script has no access to the authenticator seed.
      • B. Manually entering the OTP per change breaks continuous monitoring and expires within seconds.
      • C. A webhook cannot retrieve the OTP either; webhooks deliver alert data outward and do not bridge authenticator secrets.

      300-445 exam tip

      MFA with mobile OTP in a transaction question means exclude it; automation stops where the rotating secret starts.

      6What is a primary advantage of passive monitoring over active monitoring?
      • Passive monitoring can measure the network's performance under synthetic conditions.
      • Passive monitoring can provide real-time data on network performance without adding traffic to the network.
      • Passive monitoring allows for the generation of test traffic to simulate user behavior.
      • Passive monitoring can directly measure the performance of specific network services or protocols.
      Answer: B

      The short version

      B — Passive monitoring watches real traffic without adding any. It observes existing flows, so there is no synthetic load on the network.

      Key concepts in this question

      • Passive monitoring: captures and analyzes live user traffic.
      • Active monitoring: injects synthetic probes to test paths on demand.
      • Overhead: passive adds none; active adds probe packets by design.

      Why B is correct

      The defining advantage of passive monitoring is zero extra traffic: it derives latency, loss, and throughput insight from real packets already crossing the wire, delivered in near real time. That contrasts directly with active methods that must generate test traffic to measure.

      Why the others are wrong

      • A. Measuring under synthetic conditions is active monitoring, not passive.
      • C. Generating test traffic to simulate users is the textbook definition of active monitoring.
      • D. Directly probing a specific service or protocol with crafted requests is active testing, not passive observation.

      300-445 exam tip

      No extra traffic equals passive; synthetic traffic equals active — that single split answers most concept questions.

      7Refer to the exhibit. An engineer set the default alert condition for the network alert rule, but NOC operators report that they are getting too many false-positive alerts. Which action reduces the noise while adhering to the company's operational requirements?
      • Apply suppression window to the tests.
      • Change severity from Info to Critical.
      • Decrease the latency value to 50 ms.
      • Use dynamic baselines.
      Answer: D

      The short version

      D — Switch fixed thresholds to dynamic baselines. Baselines learn normal latency bands per test and time, cutting false positives without hiding real degradations.

      Key concepts in this question

      • Static threshold: one fixed latency number that ignores diurnal variation.
      • Dynamic baseline: learned mean and deviation that adapts to history.
      • Alert noise: false positives from a rigid default condition.

      Why D is correct

      The NOC gets flooded because a default fixed condition treats normal jitter and peak-hour shifts as violations. Dynamic baselines compare current results against learned behavior, so only genuine deviations fire while the company's operational coverage stays intact.

      Why the others are wrong

      • A. A suppression window mutes alerts on a schedule, which can hide real issues rather than tuning sensitivity.
      • B. Raising severity to Critical changes labeling and routing, not how often the condition triggers.
      • C. Lowering latency to 50 ms tightens the threshold and would increase, not reduce, false positives.

      300-445 exam tip

      Too many false positives with default static limits means dynamic baselines; severity and suppression only relabel or mute.

      8A network engineer is investigating widespread reports of poor performance for a data center- hosted web application. Which ThousandEyes agent type would be most effective for quickly identifying the root cause?
      • Synthetic Agent
      • Enterprise Agent
      • Endpoint Agent
      • Cloud Agent
      Answer: D

      The short version

      D — Use Cloud Agents for fast outside-in triage of a hosted app. Globally distributed probes quickly show whether the problem is the data center or the internet reaching it.

      Key concepts in this question

      • Cloud Agent: ThousandEyes-hosted vantage points in ISPs and cloud regions.
      • Enterprise Agent: customer-hosted inside branches or data centers.
      • Widespread reports: many users and paths affected, needing broad comparison.

      Why D is correct

      For a data-center-hosted web app with widespread complaints, Cloud Agents give instant diverse ingress paths without deploying anything. Comparing many external results isolates a server-side or data-center-edge fault from last-mile noise far faster than waiting on local agents.

      Why the others are wrong

      • A. Synthetic Agent is a generic label here; the cloud-hosted fleet is the specific fast option for external perspective.
      • B. Enterprise Agents are valuable for inside-out views but require local deployment and lack instant global diversity.
      • C. Endpoint Agents show individual user devices, which is slow and noisy for confirming a centralized hosting fault.

      300-445 exam tip

      Hosted app plus widespread plus quickly equals Cloud Agents outside-in; single-user experience equals Endpoint.

      9Refer to the exhibit. An engineer works for a logistics company with branch offices worldwide and uses Cisco ThousandEyes to monitor employee digital experience of applications hosted in AWS.The engineer is configuring an alert rule to fire whenever the application does not respond in a reasonable time. The engineer configured the alert rule; however, despite multiple issues observed in branch office connectivity in the past week, no alerts were triggered. Which change is needed in the configuration to trigger the alert?
      • Change "the same" 1 agent to "any of" 1 agent.
      • Change "All" conditions to "Any" conditions.
      • Change "1 agent" to "10% of agents".
      • Remove "Error is present" alerting condition.
      Answer: D

      The short version

      D — Drop the Error is present condition that blocks the alert. Slow responses without hard errors never satisfy an AND with error-required, so branch issues stay silent.

      Key concepts in this question

      • Alert conditions: Any versus All logic across metrics.
      • Error is present: only true on HTTP errors, timeouts, or failed assertions.
      • Slow but reachable: high latency with no hard error is the branch complaint here.

      Why D is correct

      The rule as configured demands both slowness and a hard error at once. Branch connectivity produced poor response times but the application still answered, so the error clause stayed false and suppressed every firing. Removing it lets the response-time condition trigger on degraded experience as intended.

      Why the others are wrong

      • A. Changing agent-count phrasing does not fix a metric clause that can never go true on slow-but-successful loads.
      • B. Switching All to Any is broader surgery; the identified blocker is specifically the error-required term.
      • C. Moving from 1 agent to 10 percent only changes quorum and still requires the impossible error condition.

      300-445 exam tip

      No alerts despite slowness with Error is present in the rule means remove it; slow does not equal error.

      10What is the primary purpose of integrating ThousandEyes with Meraki?
      • To deploy Endpoint Agents for VPN connectivity monitoring
      • To monitor external applications and services from SD-WAN sites
      • To enhance cloud security and compliance
      • To manage user access policies and permissions
      Answer: B

      The short version

      B — Meraki plus ThousandEyes watches external apps from SD-WAN sites. The integration embeds ThousandEyes vantage points into Meraki fabrics for branch-to-cloud visibility.

      Key concepts in this question

      • Meraki MX/Z: SD-WAN and branch security edge.
      • ThousandEyes on Meraki: runs tests directly from the branch appliance outward.
      • External monitoring: SaaS and internet service health as seen by each site.

      Why B is correct

      The primary purpose is to extend ThousandEyes testing to Meraki-managed SD-WAN sites without separate appliances. Each site can then monitor external applications and services from its own perspective, tying WAN performance to SaaS experience.

      Why the others are wrong

      • A. VPN connectivity from endpoints is an Endpoint Agent use case, not the Meraki appliance integration.
      • C. Cloud security and compliance enforcement belongs to SSE and policy products, not ThousandEyes measurement.
      • D. User access policies and permissions are managed in Meraki dashboard and identity systems, not by adding ThousandEyes.

      300-445 exam tip

      ThousandEyes plus Meraki always points to branch-perspective SaaS monitoring, not endpoint, security, or identity.

      Want the full bank of 64 questions for Designing and Implementing Enterprise Network Assurance? See all practice exams.