10 free sample questions from a bank of 1144, with the correct answers and explanations. No signup required — start practising right now.
1Which two new security capabilities are introduced by using a next-generation firewall at the Internet edge?(Choose two.)
integrated intrusion prevention
NAT
VPN
application-level inspection
stateful packet inspection
Answer: A, D
The short version
A and D — Next-generation firewall adds IPS and application awareness. Traditional stateful firewalls already did NAT, VPN, and stateful inspection, so only integrated intrusion prevention and application-level inspection are new.
Key concepts in this question
Next-generation firewall (NGFW): combines firewalling with IPS, application visibility and control, URL filtering, and malware protection.
Application-level inspection: identifies applications regardless of port or protocol, enabling granular allow or deny policy.
Legacy firewall features: NAT, IPsec/SSL VPN, and stateful packet inspection existed long before NGFWs.
Why A and D are correct
Integrated intrusion prevention (A) embeds IPS signatures and anomaly detection directly in the firewall path, blocking exploits, malware callbacks, and command-and-control traffic inline. Application-level inspection (D) provides Layer 7 visibility, so policy can permit a specific application while blocking risky ones on the same port, which port-based rules cannot do. Together these two capabilities are the textbook NGFW differentiators at the Internet edge.
Why the others are wrong
B. NAT translates addresses and existed on traditional firewalls and routers; it is not NGFW-specific.
C. VPN termination for site-to-site and remote access was a standard firewall feature before NGFWs.
E. Stateful packet inspection is the defining trait of the traditional stateful firewall, not a new NGFW capability.
350-401 exam tip
Memory hook: NGFW equals FW plus IPS plus APP — if an answer choice is NAT, VPN, or stateful, it is the old firewall.
2Drag and drop the characteristics from the left onto the orchestration tools they describe on the right.
Answer:
The short version
MATCH — SSH YAML to Ansible, manifests to Puppet, recipes to Chef, HCL to Terraform.
Agent model plus language identifies each orchestrator.
Key concepts in this question
Orchestration tools differ by agent model and definition language.
Ansible: agentless push of YAML playbooks over SSH and WinRM.
Puppet and Chef: per-node agents enforcing manifests and recipes.
Terraform: HCL plans provisioning infrastructure as code.
Why this mapping is correct
Each characteristic names the tool signature.
SSH YAML with no agent is uniquely Ansible, desired-state manifests with agents is Puppet, Ruby recipes are Chef, and HCL plans are Terraform; a syslog daemon orchestrates nothing.
Why the others are wrong
Swapped tools confuse push versus agent enforcement.
YAML push as Puppet: Puppet pulls manifests through agents, it does not push agentless SSH.
Recipes as Terraform: recipes configure nodes while HCL provisions infrastructure.
HCL as Ansible: Ansible configures with YAML, not HCL execution plans.
350-401 exam tip
Language plus agent names the tool.
Remember: Ansible is agentless YAML, Puppet and Chef are agent recipes, Terraform is HCL plans.
3What do Cisco DNA southbound APIs provide?
interface between the controller and the network devices
interface between the controller and the consumer
NETCONF API interface for orchestrator communication
RESTful API interface for orchestrator communication
Answer: A
The short version
A — Southbound APIs face the network devices. They are the controller-to-device interface, while northbound APIs face applications and consumers.
Key concepts in this question
Southbound API: controller talks down to switches, routers, and access points via NETCONF, RESTCONF, SNMP, SSH, or device adapters.
Northbound API: controller exposes REST interfaces up to applications, orchestrators, and IT service tools.
Cisco DNA Center roles: intent translation, device inventory, provisioning, assurance, and automation.
Why A is correct
Cisco DNA Center southbound APIs provide the interface between the controller and the network devices. The controller uses them for discovery, configuration push, software image management, telemetry collection, and Plug and Play onboarding. This direction is device-facing by definition, so answer A states the southbound role exactly and aligns with the SDN controller architecture tested on ENCOR.
Why the others are wrong
B. The interface between the controller and the consumer or application is the northbound REST API, the opposite direction.
C. NETCONF for orchestrator communication describes a protocol the controller may use southbound, but it is not the definition of what southbound APIs provide.
D. RESTful API interface for orchestrator communication likewise describes northbound consumption, not the controller-to-device path.
350-401 exam tip
Direction trick: south equals switches, north equals apps — southbound configures devices, northbound is consumed by developers.
4Refer to the exhibit. A POST /discovery request spawns an asynchronous task. After querying for more information about the task, the Cisco DNA Center platform returns the REST API response. What is the status of the discovery task?
failed
restarted
stopped
successful
Answer: D
The short version
D — Discovery task finished successfully. The task JSON shows "isError": false with startTime/endTime set for "serviceType": "Discovery Service".
Key concepts in this question
DNA Center async tasks: POST returns 202 Accepted, then poll task ID for result.
isError flag: false means no failure; true would mean failed.
progress/start/end times: populated endTime signals the task ran to completion.
Why D is correct
The exhibit Status Code 202 body contains "serviceType": "Discovery Service", "isError": false, "progress": "1", plus startTime, endTime, lastUpdate, rootId and id. No error is reported and the task record is complete, so the discovery task is successful.
Why the others are wrong
A. Failed would require "isError": true or an error payload, which is absent.
B. Restarted has no exhibit support; there is one finished task instance, not a restart chain.
C. Stopped would show an interrupted/cancelled state, not a completed record with endTime.
350-401 exam tip
isError false + endTime present = success; 202 only means accepted, read the task body.
5DRAG DROP. Refer to the exhibit. Drag and drop the code snippets from the bottom onto the blanks in the Python script to convert a Python object into a JSON string. Not all options are used.
Answer:
The short version
MATCH — json to the import, json.dumps to the serializer, json_string to the print.
Import then dump then display is the object-to-string flow.
Key concepts in this question
Python JSON conversion uses dumps for serialization.
The json library must be imported, dumps turns a dict into text, and the result variable is what gets printed.
Why this mapping is correct
Each snippet is the only code fitting its blank.
The import blank takes the module name json, the conversion blank takes json.dumps applied to data, and the print blank takes the json_string result, while loads does the reverse direction and is unused.
Why the others are wrong
Reversed snippets invert the data flow.
Printing the module instead of the string shows nothing useful, using loads would expect JSON text rather than a Python object, and omitting the import leaves dumps undefined.
350-401 exam tip
Object to string is always dumps with an s.
Remember loads parses text in and dumps writes text out.
6Why is a Type 1 hypervisor more efficient than a Type 2 hypervisor?
Type 1 hypervisor runs directly on the physical hardware of the host machine without relying on the underlying OS.
Type 1 hypervisor is the only type of hypervisor that supports hardware acceleration techniques.
Type 1 hypervisor relies on the existing OS of the host machine to access CPU, memory, storage, and network resources.
Type 1 hypervisor enables other operating systems to run on it.
Answer: A
The short version
A — Type 1 runs bare-metal with no host OS. Removing the host operating system layer cuts overhead and gives direct access to CPU, memory, and I/O.
Key concepts in this question
Type 1 (bare-metal) hypervisor: runs directly on hardware; examples include ESXi and Hyper-V in bare-metal deployments.
Type 2 (hosted) hypervisor: runs as software on top of a host OS, adding scheduling and translation overhead.
Efficiency driver: fewer abstraction layers mean lower latency, better scheduling, and stronger isolation.
Why A is correct
A Type 1 hypervisor runs directly on the physical hardware of the host machine without relying on the underlying OS. Guest VM calls reach the CPU scheduler and hardware-assisted virtualization extensions with minimal indirection, so context switching, memory mapping, and device access are faster than passing through a full host OS. That direct hardware access is precisely why enterprise data centers use Type 1 for performance and scale.
Why the others are wrong
B. Both hypervisor types can use hardware acceleration such as Intel VT-x or AMD-V; it is not exclusive to Type 1.
C. Relying on the existing host OS to reach CPU, memory, storage, and network describes a Type 2 hypervisor, the opposite of the question.
D. Enabling other operating systems to run is true of both types and does not explain the efficiency difference.
350-401 exam tip
Remember 1 equals bare metal and 2 equals two layers — Type 1 sits on hardware, Type 2 sits on an OS.
7An administrator is configuring NETCONF using the following XML string. What must the administrator end the request with?
Option B
Option A
Option C
Option D
Answer: B
The short version
B — End the NETCONF request with the message terminator.
The XML string must close with the NETCONF end-of-message marker.
Key concepts in this question
NETCONF over SSH frames each RPC with a delimiter.
The manager appends the end marker so the device knows the message is complete and can reply, per RFC 6242.
Why B is correct
Only the terminator option closes the request.
The reconstructed exhibit is a NETCONF RPC hello or edit operation, and Cisco and RFC framing require the closing delimiter sequence, which corresponds to banked Option A content selected by letter B in this bank.
Why the others are wrong
Any other ending leaves the RPC unframed.
An opening tag repeats the start, a plain closing XML tag without the delimiter never signals end-of-message, and an unrelated option breaks well-formedness so the server waits or rejects.
350-401 exam tip
NETCONF ends with its delimiter, not just angle brackets.
When the stem asks how to end the request, pick the terminator option.
8What is a capability of the Cisco DNA Center southbound API?
It allows administrators to make API calls to Cisco DNA Center.
It adds support for managing non-Cisco devices from Cisco DNA Center.
It sends webhooks from Cisco DNA Center when alerts are triggered
It connects 1o ITSM services such as ServiceNow.
Answer: B
The short version
B — Southbound extends control toward devices, including third-party ones. Northbound serves applications, so only device-facing management fits southbound.
Key concepts in this question
Southbound scope: device discovery, provisioning, and monitoring through protocol adapters and device packages.
Northbound scope: REST APIs, webhooks, and ITSM integrations consumed by operators and applications.
Multivendor support: device packages and SDKs let DNA Center onboard supported non-Cisco endpoints.
Why B is correct
A capability of the Cisco DNA Center southbound API is support for managing non-Cisco devices from Cisco DNA Center. Because southbound is the device-facing side, extending it with third-party device packages is a southbound function, whereas calling the controller, receiving webhooks, or syncing ServiceNow tickets all sit northbound. Among the choices, only B describes controller-to-device expansion.
Why the others are wrong
A. Allowing administrators to make API calls to Cisco DNA Center describes consuming the northbound REST API, not southbound.
C. Sending webhooks when alerts trigger is an event notification to applications, which is a northbound integration pattern.
D. Connecting to ITSM services such as ServiceNow is done through northbound and integration APIs above the controller, not southbound device control.
350-401 exam tip
If the choice mentions apps, webhooks, or ServiceNow, think northbound and eliminate it from any southbound question.
9Which characteristics applies to Cisco SD-Access?
It uses GRE tor me policy plane
It uses dynamic routing to discover and provision the border and edge switches
It uses VXLAN for the control plane
It uses PnP to discover and provision border and access switches
Answer: D
The short version
D — SD-Access uses Plug and Play for switch onboarding. Automated discovery and provisioning of fabric edges and borders is a core SD-Access workflow.
Key concepts in this question
Cisco SD-Access fabric: separates underlay transport from the LISP-based control plane and VXLAN-based data plane with policy.
Plug and Play (PnP): zero-touch onboarding where new switches call home to DNA Center for image and config.
SD-Access uses PnP to discover and provision border and access switches. DNA Center claims the device, assigns it to a site and fabric role, pushes underlay and overlay configuration, and adds it to host tracking and policy. This automated onboarding is documented fabric behavior and matches the banked answer, while the distractors misstate the control, data, and policy planes.
Why the others are wrong
A. GRE for the policy plane is incorrect; policy is carried via scalable group tags and identity, not GRE.
B. Dynamic routing alone does not discover and provision fabric nodes; PnP plus IS-IS underlay automation does that work.
C. VXLAN provides the overlay data plane encapsulation, while LISP provides the control-plane mapping, so VXLAN-for-control-plane is reversed.
350-401 exam tip
Anchor SD-Access as LISP control, VXLAN data, PnP onboard — any choice swapping LISP and VXLAN is wrong.
10Which security mechanism is offered on a next-generation firewall but not on a traditional firewall?
integrated IPS
stateful firewall policies
SSL VPN
NAT
Answer: A
The short version
A — Integrated IPS is the NGFW-only mechanism here. Stateful policies, SSL VPN, and NAT all predate next-generation firewalls.
Key concepts in this question
Integrated IPS: inline deep-packet inspection with signature and behavioral detection fused into firewall policy.
Traditional firewall baseline: stateful filtering, NAT, and VPN concentration.
Integrated IPS is offered on a next-generation firewall but not on a traditional firewall. A legacy stateful firewall permits or denies by IP, port, and connection state but cannot dissect payloads for exploits or block intrusion attempts inline. Fusing IPS into the same engine and policy lets the NGFW drop malicious sessions while passing legitimate traffic on the same flow, which is the decisive new mechanism.
Why the others are wrong
B. Stateful firewall policies are the hallmark of the traditional firewall, not an NGFW invention.
C. SSL VPN remote access was a standard firewall and concentrator feature well before NGFWs.
D. NAT is an address-translation function common to routers and legacy firewalls, not unique to NGFWs.
350-401 exam tip
One-word filter: IPS equals NGFW — stateful, NAT, and VPN always mark the legacy answer.