Sign In
Home/Cisco/Designing and Implementing Cisco Service Provider Cloud Network Infrastructure/Free questions

Designing and Implementing Cisco Service Provider Cloud Network Infrastructure — Free Practice Questions

10 free sample questions from a bank of 95, with the correct answers and explanations. No signup required — start practising right now.

1Refer to the exhibit. An engineer must configure iBGP multipath load sharing across three paths. Which two commands must be run on router R2? (Choose two.)
  • router bgp 100
  • ip load-sharing ibgp 3
  • maximum-paths ibgp 3
  • router bgp 101
  • ip load-sharing per-destination
Answer: A, C

The short version

A and C — Enter BGP 100 and raise the iBGP multipath limit to three. The router bgp 100 command reaches the correct process and maximum-paths ibgp 3 installs three parallel iBGP paths for load sharing.

Key concepts in this question

  • iBGP multipath: installing several equal-cost iBGP paths for one prefix in the RIB.
  • router bgp ASN: selects the local BGP process whose policy is being changed.
  • maximum-paths ibgp: sets how many parallel iBGP paths may be installed.

Why A and C are correct

Load sharing across three iBGP paths is configured inside the BGP process that owns those peers, which the exhibit shows as AS 100, so the engineer must first enter router bgp 100. Within that process, the default installs a single best path, and maximum-paths ibgp 3 raises the limit so three equal-cost iBGP paths enter the routing table together. The two commands combine into one workflow: reach the right AS, then widen the parallel-path limit.

Why the others are wrong

  • B. No ip load-sharing ibgp command exists in IOS; load sharing follows automatically once multiple paths are installed.
  • D. AS 101 is a different autonomous system, so configuring there would touch the wrong BGP process.
  • E. Per-destination load sharing describes CEF forwarding behavior, not the BGP multipath installation limit.

300-540 exam tip

Multipath is a two-step thought: get into the right ASN, then raise maximum-paths to the number of links.

2What does NFV stand for?
  • Network Function Visualization
  • Network File Versioning
  • Network Function Virtualization
  • New Function Virtualization
Answer: C

The short version

C — NFV means Network Function Virtualization. It is the architecture that decouples network functions such as routers and firewalls from dedicated hardware and runs them as software instances.

Key concepts in this question

  • Network Function Virtualization: running firewalls, load balancers, and routers as virtual machines or containers.
  • Decoupling: separating the network function software from proprietary hardware.
  • Orchestration context: NFV pairs with managers and virtualized infrastructure to deploy functions on demand.

Why C is correct

The industry term standardized by ETSI is Network Function Virtualization: the word Function refers to virtualized network functions (VNFs) like virtual routers, and Virtualization refers to hosting them on shared compute instead of fixed appliances. That definition matches option C exactly and is the foundation vocabulary for every later NFV question on this exam.

Why the others are wrong

  • A. Visualization means rendering images or dashboards; it describes no network architecture.
  • B. File versioning belongs to storage and source control, not to network function delivery.
  • D. New Function Virtualization is not a recognized term and drops the word Network that scopes the concept.

300-540 exam tip

Expand every acronym literally on this exam: Function plus Virtualization points straight at VNFs on shared servers.

3RTBH is effective in mitigating what kind of traffic?
  • Legitimate traffic
  • Malicious traffic
  • Incoming legitimate requests
  • Outgoing traffic
Answer: B

The short version

B — RTBH discards malicious traffic before it reaches the victim. Remotely Triggered Black Hole routing diverts attack traffic, typically DDoS floods, into a null interface at the network edge.

Key concepts in this question

  • Remotely Triggered Black Hole (RTBH): a BGP-signaled discard route, usually to Null0, applied near ingress points.
  • Trigger mechanism: a static or BGP update redirects the victim destination into the black hole.
  • DDoS scrubbing role: RTBH sacrifices the targeted prefix to protect the rest of the infrastructure.

Why B is correct

RTBH exists to mitigate hostile floods: when an attack is detected, the operator triggers a route that pulls traffic destined for the victim into a discard interface at upstream ingress routers. Because the trigger matches the attacked destination, legitimate traffic to other destinations keeps flowing while the malicious volume dies at the edge. That discard-the-attack behavior is precisely what option B describes.

Why the others are wrong

  • A. Legitimate traffic is what RTBH tries to preserve, not what it drops.
  • C. Incoming legitimate requests must keep working; dropping them would turn the defense into self-inflicted denial of service.
  • D. RTBH acts on inbound traffic toward the victim and is not an egress filtering tool for outbound flows.

300-540 exam tip

Hear black hole and think attack sink: RTBH drops the bad flood at the edge so the good traffic survives.

4Which of the following best describes the relationship between OpenStack and NFV?
  • OpenStack provides the physical infrastructure for NFV.
  • NFV can be deployed on top of OpenStack to virtualize network functions.
  • NFV is a component of OpenStack.
  • OpenStack and NFV cannot be used together.
Answer: B

The short version

B — NFV runs on top of OpenStack as its cloud platform. OpenStack supplies compute, storage, and networking services, and NFV uses them to host virtualized network functions.

Key concepts in this question

  • OpenStack: an open-source cloud manager providing virtualized infrastructure (VIM layer).
  • NFV infrastructure: the compute and virtualization resources that VNFs execute on.
  • Layered relationship: cloud platform below, virtual network functions above.

Why B is correct

In the ETSI NFV framework, OpenStack most often plays the role of the Virtualized Infrastructure Manager: Nova, Neutron, and Cinder provide the VMs, networks, and volumes. NFV then deploys on top of that foundation, instantiating routers, firewalls, and load balancers as VNFs using the resources OpenStack exposes. The two are complementary layers, not competitors or parts of each other, which is exactly the relationship option B states.

Why the others are wrong

  • A. OpenStack manages virtual resources; the physical servers underneath are ordinary data-center hardware, not something OpenStack itself provides.
  • C. NFV is an independent ETSI architecture, not a subcomponent bundled inside the OpenStack project.
  • D. The combination is one of the most common production designs, so claiming incompatibility is backwards.

300-540 exam tip

Stack the layers mentally: hardware at the bottom, OpenStack in the middle, VNFs on top.

5Which type of cyberattack does Cisco Umbrella DNS-layer security effectively help mitigate?
  • Phishing and malware-based attacks
  • DDoS attacks targeting specific servers
  • Brute force attacks on user accounts
  • Advanced persistent threats and zero-day exploits
Answer: A

The short version

A — Umbrella stops phishing and malware at the DNS layer. By resolving or blocking malicious domains before a connection is built, it cuts off the delivery and command-and-control paths those attacks need.

Key concepts in this question

  • DNS-layer security: enforcing policy when a hostname is resolved, ahead of any HTTP or payload transfer.
  • Phishing kill chain: lures victims to malicious domains hosting credential theft or malware drops.
  • Umbrella enforcement: global threat intelligence drives allow and block verdicts at resolution time.

Why A is correct

Phishing and malware campaigns depend on victims resolving attacker domains for fake login pages, payload downloads, and botnet callbacks. Cisco Umbrella inspects each DNS request against live threat intelligence and returns a block page or sinkhole instead of the malicious address, so the browser never reaches the trap. Because the decision happens at lookup time, a single policy protects every device behind it without waiting for file analysis, which is the DNS-layer value option A captures.

Why the others are wrong

  • B. Volumetric DDoS against servers is absorbed by scrubbing and rate-limiting infrastructure, not by DNS resolution policy.
  • C. Brute-force logins are countered with MFA, lockouts, and strong credentials rather than domain filtering.
  • D. APT and zero-day payload behavior is handled by EDR, sandboxing, and segmentation; DNS blocking helps but is not their dedicated control.

300-540 exam tip

Tie each Cisco security tool to its layer: Umbrella owns DNS, so pair it with domain-based threats like phishing.

6EVPN over SR/MPLS provides advantages over traditional MPLS in terms of:
  • Scalability and flexibility
  • Speed of deployment
  • Security vulnerabilities
  • Cost only
Answer: A, B

The short version

A and B — EVPN over SR-MPLS scales better and deploys faster. It inherits EVPN control-plane flexibility for many tenants and replaces RSVP-TE signaling with source routing, which simplifies provisioning.

Key concepts in this question

  • EVPN control plane: BGP-based MAC and IP advertisement supporting many isolated services.
  • Segment Routing data plane: labels encode the explicit path, removing per-flow core signaling state.
  • Traditional MPLS contrast: LDP and RSVP-TE require more signaling and manual tunnel setup.

Why A and B are correct

EVPN contributes the scalability and flexibility half: one BGP family carries L2 and L3 services for many tenants with built-in multihoming. Segment Routing contributes the deployment half: because the ingress imposes the label stack, transit nodes keep no tunnel state and operators avoid RSVP-TE configuration, so new services come up faster. Together the pair delivers the scaling and agility advantages that options A and B claim over legacy MPLS transport.

Why the others are wrong

  • C. Security vulnerabilities are not an advantage of any transport; the option mistakes a drawback category for a benefit.
  • D. Cost-only is far too narrow since the question asks about technical transport advantages, and cost alone never captures the control-plane gains.
  • (Combined note). Only the scalability-plus-deployment pair reflects the documented SR-MPLS value proposition.

300-540 exam tip

Pair each half of the label: EVPN brings the services scale, Segment Routing removes the signaling toil.

7An engineer must add VNF implementation definitions and VNF service definitions to an OpenStack deployment data model to deploy virtual routers and firewalls to an enterprise network. After the virtual machine resources are prepared, which action must be taken next?
  • Specify the operational characteristics.
  • Create the initial configuration for day zero.
  • Configure key performance indicator monitoring.
  • Define the NFV network.
Answer: D

The short version

D — Define the NFV network after the compute is ready. With VNF definitions loaded and VM resources prepared, the next step is modeling the networks that interconnect the virtual routers and firewalls.

Key concepts in this question

  • VNF implementation and service definitions: descriptors stating what each function is and how it is composed.
  • Data-model order: descriptors first, virtual resources second, networking third, then configuration.
  • NFV network definition: the virtual links, subnets, and attachment points between VNFs.

Why D is correct

Deployment follows a dependency chain: descriptors declare the functions, the cloud prepares the VM resources to host them, and only then can the functions be wired together. Defining the NFV network at this point creates the links, IP scopes, and connection points the virtual routers and firewalls will attach to. Skipping ahead to day-zero configuration or KPI monitoring would configure interfaces and alarms for networks that do not yet exist, so the network definition is the mandatory next action.

Why the others are wrong

  • A. Operational characteristics and policies are tuned once the topology they govern is actually modeled.
  • B. Day-zero bootstrapping applies after each VNF has networks to attach its interfaces to.
  • C. KPI monitoring needs live interfaces and traffic, which only exist after the NFV network is defined and instantiated.

300-540 exam tip

Follow the build order: describe it, resource it, network it, then configure and monitor it.

8Direct Connect offers which of the following advantages over traditional internet connections?
  • Higher latency
  • Increased security
  • Reduced bandwidth
  • More consistent network performance
Answer: B, D

The short version

B and D — Direct Connect adds security and consistent performance. A private dedicated link bypasses the public Internet, cutting exposure and removing Internet jitter and contention.

Key concepts in this question

  • Direct Connect: a private dedicated circuit between on-premises networks and the cloud provider edge.
  • Security gain: traffic never traverses the public Internet, shrinking the attack surface.
  • Performance gain: dedicated capacity yields predictable throughput and latency.

Why B and D are correct

A traditional Internet path shares congested peering with unpredictable routing, while Direct Connect provisions reserved bandwidth over an isolated connection. Isolation is the security half: fewer Internet hops mean less interception and spoofing exposure, which is option B. Reservation is the performance half: steady capacity without best-effort contention gives the consistent behavior option D describes. Both properties flow directly from the dedicated private-link design.

Why the others are wrong

  • A. Higher latency is a drawback, and Direct Connect is adopted precisely to lower and stabilize latency.
  • C. Reduced bandwidth is likewise a drawback; dedicated links are bought to guarantee capacity, not shrink it.
  • (Combined note). Only the security-plus-consistency pair states genuine advantages of a private connection.

300-540 exam tip

Private link means two wins: off the Internet for safety, reserved capacity for steady speed.

9TLS and mTLS are protocols used for:
  • Traffic shaping
  • Access control
  • Encryption and secure communication
  • Routing
Answer: C

The short version

C — TLS and mTLS provide encryption and secure communication. TLS protects data in transit with authenticated encryption, and mTLS extends that authentication to both endpoints.

Key concepts in this question

  • TLS: the standard protocol for confidential, integrity-checked sessions with server authentication.
  • mTLS: mutual TLS, where client and server each present certificates.
  • Handshake role: cipher negotiation plus identity verification before application data flows.

Why C is correct

TLS negotiates ciphers, authenticates at least the server, and then encrypts the session so traffic cannot be read or altered in transit. Mutual TLS adds client-certificate authentication, giving bidirectional trust for service-to-service calls. Both variants therefore belong to the encryption and secure-communication family, which is exactly option C, and neither performs any other network function.

Why the others are wrong

  • A. Traffic shaping uses policing, queuing, and scheduling, which operate on rates rather than encryption.
  • B. Access control uses AAA, ACLs, and policy engines; certificates may feed identity, but TLS itself is a transport protector.
  • D. Routing uses IGPs and BGP to select paths, a control-plane job unrelated to session encryption.

300-540 exam tip

See TLS on the exam and answer communication protection first; m is just the mutual-authentication upgrade.

10What are the key benefits of automatic fault management in service assurance? (Select two)
  • Reduced need for real-time monitoring
  • Enhanced network reliability and uptime
  • Quick identification and mitigation of network issues
  • Increasing manual intervention
Answer: B, C

The short version

B and C — Automatic fault management raises uptime and speeds repair. Continuous detection plus triggered remediation keeps services reliable and shortens the find-and-fix cycle.

Key concepts in this question

  • Automatic fault management: alarm correlation, root-cause analysis, and policy-driven recovery without waiting on humans.
  • Reliability effect: fewer and shorter outages through instant reaction.
  • MTTR effect: faster identification and mitigation of each incident.

Why B and C are correct

Service assurance watches the network around the clock, so when a fault appears the system correlates alarms, pinpoints the cause, and launches corrective actions within seconds. That always-on reaction directly increases reliability and uptime, which is option B, and it compresses detection-to-recovery time, which is option C. Both benefits are the textbook promises of automating fault handling rather than paging engineers first.

Why the others are wrong

  • A. Automation depends on continuous real-time monitoring; it expands telemetry use rather than reducing the need for it.
  • D. Increasing manual intervention is the opposite of automation, whose goal is fewer human touchpoints per incident.
  • (Combined note). Only the reliability-plus-speed pair describes outcomes automation is designed to deliver.

300-540 exam tip

Automation answers always pair uptime with speed: more reliability, faster fixes, fewer hands.

Want the full bank of 95 questions for Designing and Implementing Cisco Service Provider Cloud Network Infrastructure? See all practice exams.