Pre-Summer Special Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: spcl70

Practice Free 300-420 Designing Cisco Enterprise Networks (ENSLD) v1.1 Exam Questions Answers With Explanation

We at Crack4sure are committed to giving students who are preparing for the Cisco 300-420 Exam the most current and reliable questions . To help people study, we've made some of our Designing Cisco Enterprise Networks (ENSLD) v1.1 exam materials available for free to everyone. You can take the Free 300-420 Practice Test as many times as you want. The answers to the practice questions are given, and each answer is explained.

Question # 6

An engineer is designing a WAN solution for a customer with teams in different branch locations that need to communicate The teams also need to access enterprise applications hosted in the data center and the cloud The customer also must provide guests with connectivity to the internet only, and the internet gateway is located in the data center Which solution must the engineer choose?

A.

WAN connectivity from a different service provider for guests

B.

firewall placed in data center that fitters any traffic from guests

C.

MPLS Layer 3 VPN with one VRF for corporate access and a separate VRF for guests

D.

MPLS Layer 3 VPN with a separate VRF for each branch location

Question # 7

An engineer is upgrading a company’s main site to include a connection to a second ISP. The company will receive full Internet routing tables from both ISPs via BGP. The engineer must ensure that the company does not become a transit autonomous system. Which solution should be included in this design?

A.

Tag incoming routes from both ISPs with BGP community no-export.

B.

Lower the MED for updates sent to the secondary ISP.

C.

Use a route-map to prevent all prefixes from being advertised to either ISP.

D.

Modify the local-preference for routes incoming from the primary ISP.

Question # 8

Which method does Cisco SD-WAN use to avoid fragmentation issues?

A.

PMTUD is used.

B.

Traffic is marked with the DF bit set.

C.

Jumbo frames are enabled.

D.

Access circuits are configured with 1600 byte MTU settings.

Question # 9

When expanding an existing Cisco SD-Access network, in addition to the control plane, which two device roles are needed to create an additional fabric site? (Choose two.)

A.

leaf

B.

cEdge

C.

WLC

D.

edge

E.

border

Question # 10

An engineer must design a routing solution for a company that is single-homed to an ISP. The company ' s goal is to run BGP between the CE and the PE devices. To support running BGP, the company obtained a public AS number and IP subnet from ARIN. Which solution must the engineer select?

A.

• The customer announces the public IP subnet to the ISP

• The ISP announces the default route to the customer.

B.

• The customer announces the public IP subnet to the ISP

• The ISP announces the BGP table to the customer

C.

• The ISP announces the customer public IP subnet.

• The ISP announces the partial BGP table to the customer.

D.

• The customer announces the default route to the ISP

• The ISP announces the default route to the customer

Question # 11

300-420 question answer

Refer to the exhibit. An architect reviews the low-level design of a company ' s enterprise network and advises optimizing the STP convergence time. Which functionality must be to Gi1/0/1-10 to follow the architect ' s recommendation?

A.

PortFast

B.

root guard

C.

UplinkFast

D.

BPDU guard

Question # 12

How are wireless endpoints registered in the HTDB in a Cisco SD-Access architecture?

A.

Fabric edge nodes update the HTDB based on CAPPWAP messaging from the AP

B.

Fabric WLCs update the HTDB as new clients connect to the wireless network

C.

Border nodes first register endpoints and then update the HTDB

D.

Fabric APs update the HTDB with the clients ' ElD and RLOC

Question # 13

Drag and drop the characteristics from the left onto the Yang model they describe on the right.

Select and Place:

300-420 question answer

Question # 14

Which consideration must be taken into account when using the DHCP relay feature in a Cisco SD-Access Architecture?

A.

DHCP-relay must be enabled on fabric edge nodes to provide the correct mapping of DHCP scope to the local anycast gateway.

B.

A DHCP server must be enabled on the border nodes to allow subnets to span multiple fabric edges.

C.

DHCP servers must support Cisco SD-Access extensions to correctly assign IPs to endpoints in an SD-Access fabric with anycast gateway.

D.

DHCP Option-82 must be enabled to map the circuit IP option to the access fabric node where the DHCP discover originated.

Question # 15

300-420 question answer

Refer to the exhibit. An architect is designing a network that requires route redistribution. The design must prevent route feedback and the creation of routing loops. The OSPF domain is using default metrics, and the IS-IS domain is using narrow metrics. Which solution must the architect select?

A.

Change the IS-IS administrative distance to 105.

B.

Change the OSPF area to a nonbackbone stub area

C.

Use route filtering with an ACL or prefix list.

D.

Use route tagging with a route map.

Question # 16

An engineer must establish a direct connection between two remote offices. The new connection must be established using a logical path, share a common broadcast domain, connect over private WAN, and have as little overhead as possible. Which technology must the engineer choose?

A.

L2VPN

B.

GET VPN

C.

IPsec

D.

GRE

Question # 17

300-420 question answer

Refer to the exhibit. These requirements must be met:

    VLANs span multiple access switches.

    All VLANs are trunked on all access switch uplinks to distribution switches.

    The STP version is Rapid PVST+.

Which design provides the fastest spanning-tree convergence?

A.

Switch D configured as VLAN 10 secondary root, Switch C configured as VLAN 10 primary root, link A configured as Layer 2 trunk

B.

Switch D configured as VLAN 10 primary root, Switch C configured as VLAN 10 secondary root, link A configured as Layer 2 trunk

C.

Switch D configured as VLAN 10 primary root, Switch C configured as VLAN 10 secondary root, link A configured as Layer 3 routed link

D.

Switch D configured as VLAN 10 secondary root, Switch C configured as VLAN 10 primary root, link A configured as Layer 3 routed link

Question # 18

In a cisco SD-Access brownfield deployment scenario, which configuration deployment must be taken with Cisco DNA center?

A.

Subnet stretching

B.

LAN automation

C.

Automated UNDERLAY

D.

Manual underlay

Question # 19

300-420 question answer

Refer to the exhibit. An engineer proposed this solution for a company that requires a loop-free. Layer 2 network design. The network will run 802.1W, and all links will be 1 Gbps. If all interfaces are up as point- to-point adjacencies, what are the expected port end states based on the design?

A.

Eth1/2 on SW2 and SW3 will be in a Desg FWD state

B.

Eth1/3 on SW2 and SW3 will be m an Attn BLK state

C.

Eth1/2 on SW3 and SW4 will be m an Attn BLKbtate.

D.

Eth1/1 on SW1 and SW2 will be in a Root FWD state.

Question # 20

A client is moving to Model-Driven Telemetry and requires periodic updates. What must the network architect consider with this design?

A.

Updates that contain changes within the data are sent only when changes occur.

B.

Empty data subscriptions do not generate empty update notifications.

C.

Periodic updates include a full copy of the data that is subscribed to.

D.

The primary push update is sent immediately and cannot be delayed.

Question # 21

How is sub-second failure of a transport link detected in a Cisco SD-WAN network?

A.

Hellos are sent between the WAN Edge routers and the vSmart controller.

B.

BFD runs on the IPsec tunnels between WAN Edge routers.

C.

BGP is used between WAN Edge routers and the vSmart controller.

D.

Link state change messages are sent between vSmart controllers.

Question # 22

What is the purpose of a TLOC extension in a Cisco SD-WAN network fabric?

A.

to facilitate WAN Edge router redundancy within a site

B.

to identify the physical interface where a WAN Edge router connects to the WAN transport network

C.

to expand the number of colors that are potentially applied to a network transport interface

D.

to aggregate multiple physical interfaces into a single logical Interface

Question # 23

An engineer must design a QoS solution for a customer. The network currently supports data only, but the

customer will roll out VoIP and IP video in conjunction with the new QoS solution. The engineer plans to use

DiffServ. To ensure priority for voice services, which model must the design include?

A.

8-class model

B.

4-class model

C.

6-class model

D.

12-class model

Question # 24

300-420 question answer

Refer to the exhibit. An architect must create a stable and scalable EIGRP solution for a customer. The design must:

•conserve bandwidth, memory, and CPU processing

•prevent suboptimal routing

•avoid any unnecessary queries

Which two solutions must the architect select? (Choose two.)

A.

route summarization

B.

prefix lists

C.

distribute lists

D.

stub routing

E.

static redistribution

Question # 25

300-420 question answer

Refer to the exhibit. Where must an architect plan for route summarization for the topology?

A.

from the core toward the aggregation and the access toward the aggregation

B.

from the core toward the aggregation and the aggregation toward the core

C.

from the aggregation toward the access and the access toward the aggregation

D.

from the aggregation toward the core and the aggregation toward the access

Question # 26

300-420 question answer

Refer to the exhibit. Which process does the Ethernet LMI protocol follow that is defined by the MEF 16 Technical Specification?

A.

communicates ENI and EVC attributes to the CE

B.

notifies the CE of the availability state of a configured EVC

C.

broadcasts multicast network routes from the CE to the PE

D.

broadcasts to all subnets from the CE when an EVC is added

Question # 27

300-420 question answer

Refer to the exhibit. An engineer is designing an OSPF solution for a customer. The design must take into consideration:

    Application load balancers D. E. and F are in different geographical locations and are OSPF-enabled.

    Hosts A, B. and C connect to an application through the load balancers using IP address 10.1.1.1/32.

    In the event of a failure of one of the load balancers, hosts must still have access to the application.

Which solution must the engineer choose?

A.

All load balancers to be co-located in area 0.

B.

X, Y, and Z to be configured as different areas

C.

At least one load balancer to be in area 0.

D.

X, Y and Z to be configured as the same area

Question # 28

Drag and drop the Cisco Catalyst SD-WAN components from the left to their definitions on the nght

300-420 question answer

Question # 29

What does the fabric data plane leverage in SD-Access Architecture?

A.

LISP protocol to resolve endpoint-to-location mapping

B.

IS-IS protocol to exchange link-state routing information

C.

MAC-in-IP encapsulation method to transport of the Layer 2 frame

D.

BGP protocol to advertise endpoint prefixes outside of the fabric

Question # 30

A company with multiple service providers wants to speed up BGP convergence time in the event a failure occurs with their primary link. Which approach achieves this goal and does not impact router CPU utilization?

A.

Utilize BFD and tune the multiplier to 50

B.

Lower the BGP hello interval

C.

Decrease the BGP keepalive timer

D.

Utilize BFD and keep the default BGP timers

Question # 31

What is the purpose of the fabric control plane in a Cisco SD-Access architecture?

A.

create, propagate, and enforce G6AC policies in the fabric

B.

create a transit node with BGP route reflector functionality

C.

extend multiple subnets to one RLOC

D.

create and resolve endpoint-to-location mapping

Question # 32

How is redundancy achieved among Cisco vBond Orchestrators in a Cisco SD-WAN deployment?

A.

The IP addresses of all Orchestrators are mapped to a single DNS name.

B.

The closest Orchestrator to each Cisco WAN Edge router is selected.

C.

Cisco WAN Edge routers are configured with all Orchestrators using their IP addresses and priority.

D.

A single Cisco Orchestrator is deployed in each network.

Question # 33

When differentiating between IETF. OpenConfig. and Cisco native YANG models, how does the use of containers differ?

A.

OpenConfig uses one container for operational data and another container for configuration data, and IETF and Cisco native models use a single container for operational data and configuration data.

B.

IETF and Cisco native models use a single container for operational data and configuration data, and OpenConfig uses one container for operational data and another container for configuration data.

C.

IETF and Cisco native models use one container for operational data and another container for configuration data, and OpenConfig uses a single container for operational data and configuration data.

D.

Cisco native models use one container for operational data and another container for configuration data, and OpenConfig and IETF use a single container for operational data and configuration data.

Question # 34

300-420 question answer

Refer to the exhibit. An architect must design a solution to connect bank site A with bank site B and support:

    network operation center monitoring end-to-end L3VPN and L2VPN traffic

    company adding thousands of routes in the next two years

Which two BGP solutions must the design include? (Choose two.)

A.

Establish full mesh IBGP peering with ail routers in different IGP domains.

B.

Redistribute different IGP domain routes in a BGP IPv4 routing instance.

C.

Transport site routes using a BGP VPNv4 address family on the PE routers.

D.

Apply BGP policies on all routers to filter out ABR and PE loopback IP addresses.

E.

Connect multiple IGP ' LDP domains using a BGP IPv4 unicast family on the ABR.

Question # 35

300-420 question answer

Refer to the exhibit. Area 10 is a regular OSPF area and networks 10.1.1.0/24 and 172.16.1.0/24 are internal. Which design provides optimal routing between both networks when the link between routers C and E fails?

A.

Move the link between routers C and D to area 10.

B.

Create an OSPF virtual link between routers E and F.

C.

Create a tunnel between routers E and F in area 10.

D.

Make area 10 a not-so-stubby area.

Question # 36

Which feature provides the capability for intra-VN traffic filtering and control within the Cisco SO-Access architecture?

A.

scalable groups

B.

MAC ACL

C.

prefix list

D.

service policy

Question # 37

Which common issue causes intermittent DMVPN tunnel flaps?

A.

    a routing neighbor reachability issue

B.

    a suboptimal routing table

C.

    interface bandwidth congestion

D.

    that the GRE tunnel to hub router is not encrypted

Question # 38

300-420 question answer

Refer to the exhibit An architect is designing an IPv4 plan using the 172 20 0.0/16 network The design must maximize the number of subnets and minimize the number of wasted IP addresses In addition, the plan must allocate a subnet to these customers and links

    Customer A, which supports 125 hosts

    Customer D, which supports 62 hosts

    Links B C. and E

Which two configuration sets meet these requirements ' ? (Choose two)

A)

300-420 question answer

B)

300-420 question answer

C)

300-420 question answer

D)

300-420 question answer

E)

300-420 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 39

Which function does the Cisco SD-Access intermediate node perform?

A.

Act as LISP proxy tunnel router.

B.

Route and transport IP traffic.

C.

Act as an anycast Layer 3 gateway.

D.

Map users to a virtual network.

Question # 40

Refer to the exhibit. ISP_C is enabling IPTV services to ISP_A and ISP_B. IPTV services are launched with GLOP IP address range 233.3.1.0/24. PIM-SM already has been enabled globally in each ISP network. RP functions have been configured on edge routers in each autonomous system. ISP_C must implement a connection based on RFC 3618. Which solution achieves this goal?

A.

Configure MSDP.

B.

Set PIM SSM.

C.

Enable MP-BGP.

D.

Enable BIDIR-PIM.

Question # 41

300-420 question answer

Refer to the exhibit. A network engineer must design a highly available OSPF solution based on these requirements:

    Traffic disruptions caused by link or node failures in Area-1 must be resolved in milliseconds.

    In the event of a failure, traffic must switch to another path without waiting for the OSPF dead interval.

Which fault detection solution must the engineer choose?

A.

Utilize BFD and tune the BFD timers to 100 ms.

B.

Tune the SPF delay and the OSPF LSA interval timers to 100 ms.

C.

Enable IP SLA tracking for each OSPF peer.

D.

Decrease SPF timers to 100 ms.

Question # 42

Which two statements describe source trees in a multicast environment? (Choose two.)

A.

Source trees guarantee the minimum amount of network latency for forwarding multicast traffic

B.

Source trees create an optimal path between the source and the receivers

C.

Source trees use a single common root placed at some chosen point in the network

D.

Source trees can introduce latency in packet delivery

E.

Source trees can create suboptimal paths between the source and the receivers

Question # 43

An engineer is designing a QoS solution for a campus. The design must guarantee real-time traffic delivery during congestion, minimize the bandwidth consumption for possible virus or worm attacks, and reduce flooding of excessive traffic during times of congestion. Which two solutions must the engineer select? (Choose two.)

A.

Create a shaping policy to drop excessive traffic and a strict queue for real-time traffic.

B.

Apply queuing on the distribution to core links

C.

Create a policing policy to drop excessive traffic and a strict queue for real-time traffic.

D.

Create a scavenger queue for excessive traffic and a strict queue for real-time traffic

E.

Apply queuing on the access to distribution links.

Question # 44

An engineer must design a VPN solution for a company that has multiple branches connecting to a main office. What are two advantages of using DMVPN instead of IPsec tunnels to accomplish this task? (Choose

two.)

A.

support for AES 256-bit encryption

B.

greater scalability

C.

support for anycast gateway

D.

lower traffic overhead

E.

dynamic spoke-to-spoke tunnels

Question # 45

What is the purpose of service routes in OMP updates?

A.

specify routes toward a centralized orchestration plane

B.

describe underlay transport Information

C.

define the remote management Information

D.

indicate services that are enabled for service insertion

Question # 46

An engineer is designing a multicast network for a company specializing in VoD content. Receivers are across the Internet, and for performance reasons, the multicast framework close to the receivers within each AS. For high availability, if the sources in one AS are no longer available, the receivers of that AS must be able to receive the VoD content from sources in another AS. Which feature must the design include?

A.

Bidirectional PIM

B.

SSM

C.

Anycast RP

D.

MSDP

Question # 47

Drag and drop the elements from the left onto the protocols where they are used on the right.

300-420 question answer

Question # 48

A router running ISIS is showing high CPU and bandwidth utilization. An engineer discovers that the router is configured as L1/L2 and has L1 and L2 neighbors. Which step optimizes the design to address the issue?

A.

Make this router a DIS for each of the interfaces

B.

Disable the default behavior of advertising the default route on the L1/L2 router

C.

Configure the router to be either L1 or L2

D.

Configure each interface as either L1 or L2 circuit type

Question # 49

How does OMP behave in a Cisco Catalyst SD-WAN architecture if no policy is defined?

A.

To allow a hub-and-spoke topology for WAN Edge routers to communicate via the central location

B.

To allow a point-to-point topology for WAN Edge routers to communicate from the central location to remote locations

C.

To allow all WAN Edge routers to communicate using a full mesh topology

D.

To block all communication between WAN Edge routers

Question # 50

An engineer uses Postman and YANG to configure a router with:

    OSPF process ID 400

    network 192.168.128.128/25 enabled for Area 0

Which get-config reply verifies that the model set was designed correctly?

A.

300-420 question answer

B.

300-420 question answer

C.

300-420 question answer

D.

300-420 question answer

Question # 51

Which consideration must be made when designing a Cisco SD-Access fabric underlay?

A.

Subnets must be reduced to decrease latency.

B.

Up to six control planes are supported.

C.

The default MTU should be increased.

D.

A unified policy must be used.

Question # 52

300-420 question answer

Refer to the exhibit. An architect must design a resilient gateway solution based on these requirements:

    VLAN 10 and VLAN 11 support voice and video applications.

    Link and node failures must have minimal impact on traffic.

    Provide protection against false hello packets.

    Support IPv6.

Which solution must the architect choose?

A.

GLBP with IP SLA tracking

B.

VRRP version 2 with authentication

C.

HSRP version 2 with MD5 authentication

D.

VRRP version 2 with object tracking

Question # 53

300-420 question answer

Refer to the exhibit. A network engineer working for a private service provider with an employee ID: 4670:71:451 must design a BGP solution based on:

    All traffic originating from AS100 must pass through AS200 to reach the NTP and DHCP server

    When a link failure occurs between R3 and R4, traffic must follow the R2-R9 link to reach the NTP and DHCP server.

Which solution must the design include?

A.

Routers R3 and R10 advertise an IGP metric into BGP during redistribution in both directions.

B.

Router R6 influences the paths of R9 and R11 to the DC with a higher AS-PATH value.

C.

Routers R3 and R10 advertise a lower local preference for outgoing traffic and a higher AS-PATH value for incoming traffic.

D.

Router R3 applies a local preference of 200 for R1. R2. R9. and R11 routers to reach the data center.

Question # 54

Exhibit:

300-420 question answer

Refer to the exhibit. An engineer is designing a Layer 2 campus network. The design must support fast convergence and leverage as much bandwidth as possible between layers. Distribution switches do support VSS; unfortunately, not all routing protocols are available for use due to license limitations. Which solution must the engineer choose?

A.

EtherChannel

B.

MEC

C.

RSTP

D.

ECMP

Question # 55

Which component of Cisco SD-Access integrates with Cisco DNA Center to perform policy segmentation and enforcement through the use of security group access control lists and security group tags?

A.

Cisco Application Policy Infrastructure Controller Enterprise Module

B.

Cisco Network Data Platform

C.

Cisco Identity Services Engine

D.

Cisco TrustSec

Question # 56

An existing network solution is using BFD in echo mode. Several of the network devices are experiencing high CPU utilization which an engineer has determined is related to the BFD feature. Which solution should the engineer leverage to reduce the CPU load?

A.

Implement slow timers between peers with low CPU resources.

B.

Implement BED asynchronous mode between peers with low CPU resources.

C.

Enable BFD multi-hop on the devices with low CPU resources.

D.

Utilize carrier delay on all routers in the network.

Question # 57

An engineer must configure EIGRP to ensure that all WAN routes are not advertised to the routers in a data center. Which action must be taken?

A.

Configure the stub router in receive-only mode.

B.

Advertise only the default route.

C.

Summarize the local subnets.

D.

Configure the stub router in distributed mode.

Question # 58

300-420 question answer

Refer to the exhibit. A company developed an application to offer its customers and now it must be deployed. The application deployment must meet these requirements:

A.

Connect the two firewalls. Deploy the application in DC1 and DC2. Use IP SLA to control advertisements from DC2.

B.

Connect the two firewalls. Deploy the application in DC1 and DC2. Advertise the same prefix from DC1 and DC2.

C.

Deploy the application in DC1 and DC2. Advertise the prefix from DC1 with /32. Advertise the prefix from DC2 with /24.

D.

Deploy the application in DC1 and DC2. Advertise the same prefix from DC1 and DC2. Distribute traffic flows.

Question # 59

An engineer must design a management network for a customer ' s enterprise network. The design must:

    provide the ability to grant and revoke access privileges

    allow only protocols SSH, NTP, FTP, and SNMP

    restrict access to management Interfaces

Which solution must the engineer choose to meet the requirements?

A.

in-band

B.

enterprise internal private

C.

out-of-band

D.

mGRE

Question # 60

Refer to the exhibit. An architect is designing a Layer 3 routed network using point-to-point fiber links between the topology layers. BFD is supported on the software that runs within the infrastructure. Is BFD required within the design to provide sub-second convergence in the event of a fiber breakage?

A.

No, the OSPF hello and dead intervals must be tuned instead.

B.

Yes, but BFD requires tuning to provide fault detection and sub-second convergence.

C.

No, the topology converges sub-second without the use of BFD.

D.

Yes, it automatically provides the required fault detection and sub-second convergence.

Question # 61

What is the purpose of Cisco vBond as a Session Traversal Utilities for NAT server?

A.

allow Cisco Catalyst SD-WAN routers to locate their own mapped IP addresses

B.

integrate Cisco SD-Access Wireless into the fabric

C.

secure data traffic between Cisco Catalyst SD-WAN edge routers that use IPsec

D.

provide Zero-Touch Provisioning to Cisco Catalyst SD-WAN vEdge devices

Question # 62

An architect must design a plan to manage the enterprise network devices. The design must accommodate that:

    not all network devices have a dedicated management interface

    all IP-enabled interfaces on all devices must be reachable

    encryption must be used with all devices which have support

Which solution must the architect choose?

A.

KVM server

B.

in-band

C.

out-of-band

D.

terminal server

Question # 63

An engineer is designing a BGP network for a large customer. To permit efficient scaling, the BGP domain is split into clusters. Which peering solution should be used between the route reflectors in different clusters for the BGP routes to be propagated appropriately?

A.

The route reflectors should be made dents of each other.

B.

The route reflectors should be nonclients with regards to each other.

C.

The route reflectors should not have any kind of BGP peering.

D.

The route reflectors should have peering through another nonclient router.

Question # 64

In a multicast network, which condition must be met for an RPF check to be performed on the RP address ' ?

A.

The PIM DM device receives a multicast packet and has no directly connected members

B.

The PIM router or multilayer switch has a shared-tree state

C.

The PIM router or multilayer switch has a source-tree state

D.

The PIM DM device receives a multicast packet and has no directly connected PIM neighbor

Question # 65

An engineer is designing a QoS policy that queues excess packets for later transmission. Which mechanism must be included in the design?

A.

shaping

B.

WRED

C.

policing

D.

RED

Question # 66

A)

300-420 question answer

B)

300-420 question answer

C)

300-420 question answer

D)

300-420 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 67

300-420 question answer

Refer to the exhibit. Which two technologies must an engineer include in the design to prevent Layer 2 loops in this topology? Choose two.

A.

loop guard on uplink

B.

root guard on downlink

C.

BPDU guard on downlink

D.

root guard on uplink

E.

BPDU guard on uplink

Question # 68

A company needs to increase access port capacity on one floor of a building. They want to leverage the existing catalyst access switch. There is no problem with uplink bandwidth capacity. However, no additional uplinks can be added because no ports are available on the distribution switches. Which solution must the company choose to provide additional access ports?

A.

VDC

B.

VSS

C.

Etherchannel

D.

Stackwise

Question # 69

How is internet access provided to a WAN edge router that is connected to a MPLS transport link?

A.

OMP advertises a default route from a WAN Edge router that is connected to the MPLS and internet transport networks

B.

Internet access must be provided at the WAN Edge router through either a 4G/5G link or local Internet circuit

C.

An extranet must be provided in the MPLS transport network to allow private traffic to reach the public internet

D.

TLOC extensions are used to route traffic to a WAN Edge router that is connected to the Internet transport network

Question # 70

Refer to the exhibit.

300-420 question answer

An engineer must design a WAN solution so that ISP-1 is always preferred over ISP-2. The path via ISP-2 is

considered as a backup and must be used only when the path to ISP-1 is down. Which

solution must the engineer choose?

A.

R1:

- Routes advertised to ISP-1: 0x AS-path prepend

- Routes received from ISP-1: HIGH local-preference

- Routes advertised to R2: no action

- Routes received from R2: community NO-EXPORT

R2:

- Routes advertised to ISP-2:5x AS-path prepend

- Routes received from ISP-2: LOW local-preference

- Routes advertised to R1: community NO-ADVERTISE

- Routes received from R1: no action

B.

R1:

- Routes advertised to ISP-1: 0x AS-path prepend

- Routes received from ISP-1: HIGH local-preference

- Routes advertised to R2: community NO-EXPORT

- Routes received from R2: no action

R2:

- Routes advertised to ISP-2: 5x AS-path prepend

- Routes received from ISP-2: LOW local-preference

- Routes advertised to R1: no action

- Routes received from R1: no action

C.

R1:

- Routes advertised to ISP-1: 0x AS-path prepend

- Routes received from ISP-1: LOW local-preference

- Routes advertised to R2: community NO-ADVERTISE

- Routes received from R2: no action

R2:

- Routes advertised to ISP-2: 5x AS-path prepend

- Routes received from ISP-2: HIGH local-preference

- Routes advertised to R1: no action

- Routes received from R1: community NO-ADVERTISE

D.

R1:

- Routes advertised to ISP-1: 5x AS-path prepend

- Routes received from ISP-1: LOW local-preference

- Routes advertised to R2: community NO-ADVERTISE

- Routes received from R2: no action

R2:

- Routes advertised to ISP-2: 0x AS-path prepend

- Routes received from ISP-2: HIGH local-preference

- Routes advertised to R1: community NO-EXPORT

- Routes received from R1: no action

Question # 71

An architect must design a QoS model for a business-critical application that Is delay-sensitive and requires high bandwidth. The company ' s head office hosts the application, and DMVPN tunnels protected with IPsec provide connectivity between the head office and branches. Which solution must the architect choose?

A.

RSVP

B.

IntServ

C.

WRED

D.

DiffServ

Question # 72

When designing interdomain multicast, which two protocols are deployed to achieve communication between multicast sources and receivers? (Choose two.)

A.

IGMPv2

B.

BIDIR-PIM

C.

MP-BGP

D.

MSDP

E.

MLD

Question # 73

Refer to the exhibit.

300-420 question answer

EIGRP has been configured on all links. The spoke nodes have been configured as EIGRP stubs, and the WAN links to R3 have higher bandwidth and lower delay than the links to R4. When a link failure occurs at the R1-R2 link, what happens to traffic on R1 that is destined for a subnet attached to R2?

A.

R1 has no route to R2 and drops the traffic

B.

R1 load-balances across the paths through R3 and R4 to reach R2

C.

R1 forwards the traffic to R3, but R3 drops the traffic

D.

R1 forwards the traffic to R3 in order to reach R2

Question # 74

Which design consideration must be made when using IPv6 overlay tunnels?

A.

Overlay tunnels that connect isolated IPv6 networks can be considered a final IPv6 network architecture.

B.

Overlay tunnels should only be considered as a transition technique toward a permanent solution.

C.

Overlay tunnels can be configured only between border devices and require only the IPv6 protocol stack.

D.

Overlay tunneling encapsulates IPv4 packets in IPv6 packets for delivery across an IPv6 infrastructure.

Question # 75

An engineer is looking for a standards-driven YANG model to manage a multivendor network environment. Which model must the engineer choose?

A.

Native

B.

OpenConfig

C.

IETF

D.

IEEE NETCONF

Question # 76

A company wants to switch from static routing to a dynamic routing protocol to ease the administrative and operational overhead. The network topology is hub and spoke, and the branches use DMVPN back to the hub using two 100 Mbps internet connections. Both links must be used due to spikes in traffic, and routing must take traffic utilization of the links into account. Also, the branch routers have limited memory and CPU resources. Which routing protocol and design solution must the company choose?

A.

iBGP with the hub routers set up as route reflectors and branches set up as clients

B.

OSPF deployed in area 0 with branch routers connecting from area 1

C.

ISIS with the hub and spoke routers configured in two different areas

D.

EIGRP with branch routers as stub routers using ECMP

Question # 77

What is one function of the vSmart controller in an SD-WAN deployment?

A.

orchestrates vEdge and cEdge connectivity

B.

responsible for the centralized control plane of the SD-WAN network

C.

provides centralized network management and a GUI to monitor and operate the SD-WAN overlay

D.

provides a data-plane at branch offices to pass traffic through the SD-WAN network

Question # 78

A network solution is being designed for a company that connects to multiple Internet service providers. Which Cisco proprietary BGP path attribute will influence outbound traffic flow?

A.

Local Preference

B.

MED

C.

Weight

D.

AS Path

E.

Community

Question # 79

An engineer is designing a QoS solution for a customer The customer ' s internet connection has a bandwidth of 10 Mbps. The design must ensure that traffic bursts of data do not exceed the bandwidth of the connection and that received traffic does not starve out business-critical traffic Which solution must the engineer choose?

A.

Configure the queuing default queue for shaping inbound and policing outbound.

B.

Configure the queuing default queue for shaping inbound and policing inbound.

C.

Configure the queuing default queue for shaping outbound and policing inbound.

D.

Configure the queuing default queue for shaping outbound and policing outbound.

Question # 80

How does a model-driven telemetry dial-out approach function?

A.

The device initiates a session to the collector based on the subscription.

B.

The collector initiates a session to the device and subscribes to data to be streamed.

C.

The collector Initiates a session to the device and gets the data of a previously defined subscription.

D.

The device initiates a session to the collector and negotiates a subscription.

Question # 81

300-420 question answer

Refer to the exhibit. An engineer is designing a BGP solution for a client that peers with ISP1 for full Internet connectivity and with ISP2 for direct exchange of routes for several third parties. Which action, when implemented on the edge routers, enables the client network to reach the Internet through ISP1?

A.

Run an eBGP session within different VRFs for each ISP.

B.

Advertise a default route for downstream routers within the client network.

C.

Apply the AS-path prepend feature for ISP2.

D.

Apply route filtering such that the client advertises only routes originated from its own AS.

Question # 82

Refer to the exhibit.

300-420 question answer

An engineer must optimize the traffic flow of the network. Which change provides a more

efficient design between the access and the distribution layer?

A.

Add a link between access switch A and access switch B

B.

Reconfigure the distribution switch A to become the HSRP Active

C.

Change the link between distribution switch A and distribution switch B to be a routed link

D.

Create an EtherChannel link between distribution switch A and distribution switch B

Question # 83

A customer ' s current Layer 2 infrastructure is running Spanning Tree 802.1d, and all configuration changes are manually implemented on each switch. An architect must redesign the Layer 2 domain to achieve these goals:

    reduce the impact of topology changes

    reduce the time spent on network administration

    reduce manual configuration errors

Which two solutions should the architect include in the new design? (Choose two.)

A.

Implement Rapid PVST+ instead of STP.

B.

Implement MST instead of STP.

C.

Use VTP to propagate VLAN information and to prune unused VLANs.

D.

Configure broadcast and multicast storm control on all switches.

E.

Configure dynamic trunking protocol to propagate VLAN information.

Question # 84

An engineer is creating a design to enable IPv6 to run on an existing IPv4 IS-IS network. The IPv4 and IPv6 topologies will match exactly, and the engineer plans to use the same router levels for each protocol per interface. Which IS-IS design is required?

A.

single topology without enabling transition feature

B.

single topology with transition feature enabled

C.

multi topology with transition feature enabled

D.

multi topology without enabling transition feature

Question # 85

300-420 question answer

Refer to the exhibit. A customer needs to apply QoS to the network management traffic passing through the GigabitEthernet0/2 interface. All eight queuing classes are in use, so the new requirement must be integrated into the existing policy. Which solution must the customer choose?

A.

Mark traffic to DSCP CS5 and assign it to the SIGNALLING class. Then, baseline existing queue sizes to determine if additional bandwidth can be provisioned to the SIGNALLING class.

B.

Mark the traffic to DSCP CS4 and assign it to the SIGNALLING class. Then, prioritize traffic within the class.

C.

Mark the traffic to DSCP CS6 and assign it to the ROUTING class Then, prioritize traffic within the class.

D.

Mark the traffic to DSCP CS2 and assign it to the ROUTING class Then, baseline existing queue sizes to determine if additional bandwidth can be provisioned to the ROUTING class

Question # 86

Which feature of Cisco SD-WAN Secure Direct Cloud Access divides user traffic into different zones and VPNs or VRFs?

A.

centralized data policy

B.

secure segmentation

C.

perimeter control

D.

application-awareness routing

Question # 87

What is the purpose of a control plane node in a Cisco SD-Access network fabric?

A.

to maintain the endpoint database and mapping between endpoints and edge nodes

B.

to detect endpoints in the fabric and inform the host tracking database of EID-to-fabric-edge node bindings

C.

to identify and authenticate endpoints within the network fabric

D.

to act as the network gateway between the network fabric and outside networks

Question # 88

300-420 question answer

Refer to the exhibit. The distribution switches serve as the layer 3 boundary. HSRP preemption is enabled. When the primary switch comes back after a failure, traffic is initially dropped. Which solution must be implemented to improve the design?

A.

Increase the hello timers on both HSRP devices

B.

Use the preempt delay feature on the primary HSRP device.

C.

Use the preempt delay feature on the backup HSRP device

D.

Configure a higher mac-refresh interval on both HSRP devices

Question # 89

300-420 question answer

Refer to the exhibit. An architect is designing a Layer 3 campus network. The design must hide network instability, reduce network overhead, and conserve critical device memory. Which route summarization solution must the architect select?

A.

The aggregation layer must advertise a default route toward the access layer. The VLAN subnets must be summarized into 10.0.0.0/16 at the aggregation layer and advertised to the core layer.

B.

The core layer must advertise a default route toward the aggregation layer. The VLAN subnets must be summarized into 10.0.0.0/16 at the access layer and advertised to the aggregation layer.

C.

The aggregation layer must advertise a default route toward the core layer. The VLAN subnets must be summarized into 10.0.0.0/16 at the aggregation layer and advertised to the access layer.

D.

The core layer must advertise a default route toward the aggregation layer. The VLAN subnets must be summarized into 10.0.0.0/16 at the aggregation layer and advertised to the core layer.

Question # 90

300-420 question answer

Refer to the exhibit. A company has some offices that are connected via dark fiber in New York. A network architect must optimize the network design based on the EIGRP routing protocol. The network has hierarchical addressing between 10 and 12 routers in each office. Routing convergence time must be at the minimum. What must the network architect do to reduce the query range?

A.

Configure stub areas on non-edge routers.

B.

Implement network summarization on edge routers.

C.

Use different EIGRP processes on edge routers.

D.

Configure route filtering on non-edge routers.

Question # 91

300-420 question answer

Refer to the exhibit. An architect is designing an IPv4 plan using the 172.16.0.0/16. The design must maximize the number of subnets while meeting these requirements:

    500 hosts within the server room

    100 hosts at the remote site

    25 hosts at the access site

Which plan must the architect choose?

A)

300-420 question answer

B)

300-420 question answer

C)

300-420 question answer

D)

300-420 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 92

Which element in a Cisco SD-WAN architecture maintains a centralized routing table?

A.

WAN Edge router

B.

vSmart Controller

C.

vManage NMS

D.

vBond Orchestrator

Question # 93

300-420 question answer

Refer to the exhibit. A network engineer with an employee ID: 4384:99:754 must design a BGP solution based on these conditions:

    Traffic sessions occur between the branches and the data center.

    Branch B has limited resources to process routing updates.

    HQ must filter out all prefixes from branch A to R4.

Which outbound route filtering (ORF) solution must the engineer choose?

A.

Use a prefix list with the 192.168.10.0/24 subnet for ORF on R4.

B.

Use a prefix list with the 10.10.10.0/24 subnet for ORF on R2

C.

Use a prefix list with the 10.10.10.0/24 subnet for ORF on R5.

D.

Use a prefix list with the 192.168.10.0/24 subnet for ORF on R2.

Question # 94

A branch office has a primary L3VPN MPLS connection back to the main office and an IPSEC VPN tunnel that serves as backup. Which design ensures that data is sent over the backup connection only if the primary MPLS circuit is down?

A.

Use EIGRP to establish a neighbor relationship with the main office via

B.

L3VPN MPLS and the IPSEC VPN tunnel.

C.

Use BGP with the multipath feature enabled to force traffic via the primary path when available.

D.

Use static routes tied to an IP SLA to prefer the primary path while a floating static route points to the backup connection.

E.

Use OSPF with a passive-interface command on the backup connection.

Question # 95

An enterprise customer has these requirements:

    end-to-end QoS for the business-critical applications and VoIP services based on CoS marking.

    flexibility to offer services such as IPv6 and multicast without any reliance on the service provider.

    support for full-mesh connectivity at Layer 2.

Which WAN connectivity option meets these requirements?

A.

VPWS

B.

MPLS VPN

C.

DMVPN

D.

VPLS

Question # 96

300-420 question answer

Refer to the exhibit An engineer is designing a hierarchical ISIS solution for an enterprise customer with these requirements

    Users in areas 25 and 55 send and receive traffic from both backbone areas

    Link flaps in areas 35 and 45 must not impact other areas

    Routers will double within the next 12 months in areas 35 and 45

Which design must the engineer select?

A.

A series routers Level 2, B series routers Level 2, and C series routers Level 1

B.

A series routers Level 1/2 B series routers Level 2 and C series routers Level 2

C.

A series routers Level 1. B series routers Level 1/2. and C series routers Level 2

D.

A series routers Level 1.2 B series routers Level 1/2 and C series routers Level 1/2

Question # 97

A company requires a private WAN design that allows remote sites to connect to HQ. The design must ensure that:

    traffic is always encrypted

    forwarding overhead is reduced

    management of security Is centralized

    multicast traffic is supported

Which technology must the company select?

A.

iPiac P2P

B.

GET VPN

C.

DMVPN Phase 3

D.

mGRE

Question # 98

An infrastructure team is concerned about the shared memory utilization of a device, and for this reason, they need to monitor the device state. Which solution limits impact on the device and provides the required data?

A.

IPFIX

B.

static telemetry

C.

on-change subscription

D.

periodic subscription

Question # 99

Which protocol is deployed through LAN automation to build node-to-node underlay adjacencies in SDA?

A.

IS-IS

B.

OLISP

C.

OSPF

D.

VXLAN

Question # 100

Which QoS feature responds to network congestion by dropping lower priority packets?

A.

CBWFQ

B.

tail drop

C.

WRED

D.

strict priority

Question # 101

What is the main purpose of the Cisco SD-Access underlay design?

A.

to enable automated network provisioning and configuration

B.

to support advanced firewall and IPS features

C.

to optimize network traffic routing and load-balancing

D.

to provide network segmentation and isolation for security

Question # 102

Refer to the exhibit. A company is expanding and decides to use a DMVPN solution to connect the branches. The network uses the EIGRP routing protocol. All remote branch routers must be configured with the normal EIGRP area. Auto-summary is not allowed on the routers in the network. Which solution must the company implement on R1 to achieve this goal?

A.

Disable the stuck-in-active timer.

B.

Configure a multipoint interface.

C.

Disable split horizon.

D.

Configure a summary route.

Question # 103

An engineer working for a service provider with an employee ID 4598.48.606 prepared several designs for a traditional campus network. The design must allow the deployment on the same VXLAN to any switch at the access layer and must support:

    Fast convergence

    High availability

    Resilience

Which design must be selected?

300-420 question answer

300-420 question answer

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question # 104

A customer plans to adopt distributed QoS in their enterprise WAN. The policy must allow for individual packet marking according to the type of treatment required and for forwarding based on hop-by-hop treatment locally defined on each device. Which technology must the customer select?

A.

CBWFQ

B.

LLQ

C.

Diffserv

D.

IntServ

Question # 105

300-420 question answer

Refer to the exhibit An engineer working for a telecommunication company with an employee ID 4449:30 959 Is calculating STP scalability for switches to ensure that the numbers are below the maximum supported value for STP logical ports How many logical interfaces are active for switch A?

A.

4

B.

307

C.

202

D.

100

Question # 106

Which encoding languages are supported in NETCONF compared to RESTCONF?

A.

NETCONF supports XML and JSON, and RESTCONF supports XML.

B.

NETCONF supports XML, and RESTCONF supports JSON.

C.

NETCONF supports JSON, and RESTCONF supports XML.

D.

NETCONF supports XML, and RESTCONF supports XML and JSON.

Question # 107

An engineer needs to design a management network for the company. The solution has these requirements:

    overlay network does not cause routing issues

    ease of troubleshooting for the operations team

    devices are accessed securely

Which solution meets these requirements?

A.

VRF for management traffic and SSH keys for device access

B.

Private VLANs for management traffic and TACACS+ for device access

C.

Separate physical interfaces for management traffic and TACACS+ for device access

D.

VLANs for management traffic and RADIUS for device access

Question # 108

A network architect Is enabling TV services In the LAN. The source will be streaming to the 239.1.1.1 group IP address. Dense mode Is not allowed In the network. Multicast has already been enabled on all network devices In the LAN segment. Which action must the architect take to finalize the design?

A.

Enable PIM SSM.

B.

Enable PIM Auto-RP.

C.

Enable PIM Anycast RP

D.

Enable PIM BSR.

Question # 109

300-420 question answer

Refer to the exhibit. An architect designs a BGP policy for a customer that requires load sharing of the links that connect with the upstream service provider. The customer has these requirements: • The inbound traffic destined to network 10.1.1.0/24 must transit the R3-R1 link, and if the link fails, all inbound traffic must transit the R4-R2 link.

• The inbound traffic destined to network 10.1.2.0/24 must transit the R4-R2 link, and if the link fails, all inbound traffic should transit the R3-R1 link.

Which solution must the architect choose?

A.

• R1 must announce prefix 10.1.2.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512

• R2 must announce prefix 10.1.1.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512.

B.

• R1 must announce prefix 10.1 2.0/24 with a community attribute 64513:300 and prefix 10.1.1.0/24 with a community attribute 64513:200.

• R2 must announce prefix 10.1.2.0/24 with a community attribute 64513:200 and prefix 10.1.1.0/24 with a community attribute 64513:300.

C.

• R1 must announce prefix 10.1.1.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512.

• R2 must announce prefix 10.1.2.0/24 with the route map applied to the neighbor using set as-path prepend 64512 64512.

D.

• R1 must announce prefix 10.1.2.0/24 with a community attribute 64513:200 and prefix 10.1.1.0/24 with a community attribute 64513:300.

• R2 must announce prefix 10.1.2.0/24 with a community attribute 64513:300 and prefix 10.1.1.0/24 with a community attribute 64513:200.

Question # 110

Which resource is required for the vBond orchestrator to onboard a WAN Edge router via manual configuration?

A.

vSmart hostname

B.

domain name

C.

NAT

D.

organization name

Question # 111

Which two functions is the Cisco SD-Access Edge Node responsible for? (Choose two.)

A.

Act as anycast layer 3 gateway

B.

Advertise EID subnets

C.

Map users to virtual network

D.

Act as LISP proxy tunnel router

E.

Route and transport IP traffic

Question # 112

300-420 question answer

Refer to the exhibit A customer requires maximum uptime for the data plane between R1 and R3 running OSPF Which solution must the design include for high availability if the routing process on R2 requires maintenance?

A.

BFD on all routers

B.

nonstop forwarding on R1 and R3

C.

nonstop forwarding on R3 only

D.

graceful restart on all routers

Question # 113

An engineer is designing a network for a customer running a wireless network with a common VLAN for all APs. The customer is experiencing unicast flooding in the Layer 2 network between the aggregation and access layers. The customer wants to reduce the flooding and improve convergence time. Which solution meets these requirements?

A.

Migrate all APs to a common Layer 2 access layer switch and run Layer 3 from the aggregation layer to all remaining access layer switches.

B.

Align HSRP primary and STP root bridges and reduce ARP timers to match CAM timers on the aggregation layer switches.

C.

Migrate to a Layer 3 access campus design if the APs can run on separate VLANs.

D.

Align HSRP primary and STP root bridges if the APs cannot run on separate VLANs.

300-420 PDF

$42

$139.99

3 Months Free Update

  • Printable Format
  • Value of Money
  • 100% Pass Assurance
  • Verified Answers
  • Researched by Industry Experts
  • Based on Real Exams Scenarios
  • 100% Real Questions

300-420 PDF + Testing Engine

$57

$189.99

3 Months Free Update

  • Exam Name: Designing Cisco Enterprise Networks (ENSLD) v1.1
  • Last Update: May 26, 2026
  • Questions and Answers: 379
  • Free Real Questions Demo
  • Recommended by Industry Experts
  • Best Economical Package
  • Immediate Access

300-420 Engine

$48

$159.99

3 Months Free Update

  • Best Testing Engine
  • One Click installation
  • Recommended by Teachers
  • Easy to use
  • 3 Modes of Learning
  • State of Art Technology
  • 100% Real Questions included