Design MCQ - 1-39-Practice - v1.1.15
Design MCQ - 1-39-Practice - v1.1.15
Design MCQ - 1-39-Practice - v1.1.15
Which action must be taken in addition to enabling Rapid PVST+ on all switches in the HQ to guarantee
that the user experience is improved?
Answer:
QUESTION 3
a) Rapid PVST+ requires the use of LACP fast rate to support rapid convergence on EtherChannels.
b) Trunk ports are not considered as edge ports unless explicitly configured to.
c) The MAC aging time needs to be set to a value shorter than max_age+forward_delay.
d) PortFast is not enabled globally on the switches
Answer:
QUESTION 4
Based on the diagram, what design change can be made to address the flapping EIGRP neighbor
between r24 and r70 without impacting the network connectivity to any other DMVPN location?
Answer:
QUESTION 5
QUESTION 6:
What is the appropriate way to ensure that VXLAN-encapsulated traffic is properly load-balanced across
physical member links of an EtherChannel, and what is the rationale to do so?
a) Use L2+L3+L4-based hash, VXLAN VTEPs randomize the source UDP port
b) Use VXLAN deep packet inspection hash, load balancing is not possible otherwise
c) Use L2+L3-based hash, VXLAN VTEPs randomize the source IP address
d) Use L2-based hash, VXLAN VTEPs randomize the source MAC address
Answer:
QUESTION 7:
QUESTION 8:
Refer to the new resource(s) available.
This item consists of multiple questions, you may need to scroll down to be able to see all questions.
8.1 Which two solutions for decreasing the utilization of routing tables in HQ and DC locations are
applicable in FABD2’s current OSPF design? (Choose two.)
Answer:
8.3 What are the two disadvantages of using distribute list to control the routing table contents in
FABD2 HQ and DC? (Choose two.)
Answer:
QUESTION 9:
This item consists of multiple questions, You may need to scroll down to be able to see all questions.
9.1 Based on current FABD2 design, which switch or switches must perform DHCP Snooping to avoid
DHCP-related incidents in the HQ?
9.2 If DHCP Snooping was activated on sw110, what interfaces would need to operate as trusted
interfaces?
9.3 Which of the following two approaches can be used to avoid breaking DHCP functionally when the
DHCP server runs on a different device than the DHCP snooping device? (Choose two)
a) On IOS based DHCP servers and relay agents, accept DHCP messages containing Option 82 having all-
zero giaddr
b) On switches performing DHCP Snooping, disable Option 82 insertion
c) On DHCP servers, allocate IP addresses to clients based on Option 82 remote-id and circuit-id values
instead of client MAC addresses
d) On DHCP clients, preconfigure customized Option 82 contents
e) On IOS-based DHCP relay agents, change the relay policy to replace Option 82
Answer:
QUESTION 10:
What are two parallel reasons for the direct spoke-to-spoke DMVPN tunnel coming up between r62 and
r70? (Choose two)
Answer:
QUESTION 11:
Based on the requirements for the security hardening in Branch #3, what is a viable solution?
a) Protected ports
b) VLAN ACLs
c) Private VLANs with two independent community secondary VLANs
d) Private VLANs with an isolated secondary VLAN
e) Port ACLs
f) Private VLANs with an isolated and a community secondary VLAN
Answer:
QUESTION 12:
QUESTION 13:
Refer to the new resource(s) available. What change is required to the BGP configuration in the
environment of Global SP #1 so that r4 learns about multiple paths to networks at Branch #3?
a) On r5 and r6, activate the route reflector function
b) On r5 and r6, unique RDs need to be configured
c) On r3 as the route reflector, BGP Multipath feature must be enabled
d) On each PE, unique RTs need to be configured
e) On r4 the BGP maximum paths setting needs to be increased
Answer:
QUESTION 14:
Which two addresses are the best choices for the Connected FABD2 and RapidStreaming multicast
groups? (Choose two.)
a) 232.2.1.1
b) 232.1.1.1
c) 239.129.1.2
d) 239.2.1.1
e) 232.129.1.1
f) 239.1.1.2
g) 239.1.1.1
Answer:
QUESTION 15:
Considering the intended RP design for the High Bandwith multicast range, drag and drop the
appropriate Loop1 configuration on the left to each switch in the diagram. Any Loop1 configuration can
be dropped to multiple switches. Not all options are used
QUESTION 16:
Considering correct FABD2 design, which two devices are the best choices for placement of the RP for
Low Bandwidth multicast streams? (Choose two.)
a) sw101
b) r11
c) sw102
d) r21
Answer:
QUESTION 17:
What prefixes, along with their label bindings must be advertised by LDP in the MPLS mock lab to enable
MPLS L3VPN services?
Answer:
QUESTION 18:
What mechanism and type of deployment would be the most appropriate to accomplish the label
filtering goals as requested?
What is the proper approach to prevent the MPLS cloud from revealing its internal infrastructure to the
attached endpoints?
Given the description of the issue, which of the following statements would explain the symptoms
described in the e-mail from Travis?
Given the description of the issue, what are the two reasons for the absence of RAs breaking the IPv6
connectivity? (Choose two.)
What would be the proper approach to meet the security requirement as stated by Travis?
Answer:
QUESTION 23:
23.2 Given Travis preference, what would be the first hop redundancy mechanism of choice?
a) HSRP or VRRP
b) VRRP or IPv6 RAs
c) HSRP only
d) VRRP only
e) IPv6 RAs only
f) HSRP or IPv6 Ras
Answer:
QUESTION 24:
When building the overall SD-WAN policy to meet the Payment Card Industry requirements for the Point
Of Sale (POS) terminals at Branch #1 and Branch #2, what three steps must be accomplished in
vManager? (Choose three.)
a) Create an ACL at Branch #1 and Branch #2 blocking their direct mutual communication
b) Create POS VPN and VPN interface feature templates and apply them to Branch #1 and Branch #2
device templates
c) Apply the policy outbound to the Site IDs of Branch #1 and Branch #2
d) Apply the policy outbound to the Site ID of the DC
e) Create a policy to set the TLOCs for Branch #1 and Branch #2 POS OMP routers to the DC TLOC(s)
f) Block Branch #1 and Branch #2 from learning each other’s TLOC routers
Answer:
QUESTION 25:
Based on the given constraints and existing design, which two steps can be performed to provide WAN
transport redundancy at Branch #2 (Choose two.)
a) On the link between vedge51 and vedge52, create 802.1Q subinterfaces as necessary and use them as
TLOC extensions for each vEdge’s transport
b) Add a second physical link between vedge51 and vedge52 and use the links as TLOC extensions for
each extensions for each vEdge’s transport
c) Configure a backup default route on each vEdge pointing to the address of the neighboring vEdge’s
TLOC extension interface
d) Configure an outbound localized policy on each vEdge to add the TLOC of the neighboring vEdge to
the advertised OMP routes
e) Run OMP between vedge51 and vedge52
Answer:
QUESTION 26:
Based on the given constraints and existing design, which two steps can be performed to ensure that
internet-bound traffic from Branch #2 is not sent via the data center?(Choose two.)
a) On Vedge52, configure NAT to VPN 0 on the interface connected to the vedge51 TLOC extension
interface for the internet transport.
b) On vedge51, configure NAT to VPN 512 on the interfaces toward the ISP.
c) On vedge51, configure NAT to VPN 0 on the interface toward the ISP.
d) On vedge52, configure NAT to VPN 0 on the interface toward SP #2.
e) On vedge51, configure NAT to VPN 0 on the TLOC extension interface for the internet transport.
Answer:
QUESTION 27:
Which two steps are required to implement the desired Guest VPN design? (Choose two)
a) Implement a localized data policy that blocks Guest VPN traffic between SD-WAN branches.
b) Configure a centralized VPN membership policy that only allows Guest VPN prefix to be advertised in
OMP.
c) Configure a centralized VPN membership policy that restricts the Guest VPN prefix from being
advertised in OMP.
d) Configure centralized data policy that perform NAT of Guest VPN traffic to VPN 0.
e) Configure a localized control policy that rewrites the TLOC of Guest VPN routes in OMP to 0.0.0.0
Answer:
QUESTION 28:
Given the intended scope of SDA fabric deployment on Branch #2, which option represent the smallest
applicable IP pool in DNA Center to support LAN Automation on Branch #2?
Which option represents the smallest applicable IP pool in DNA Center to support the planned Layer3
VN handoffs on Branch #2?
Which two design options are applicable to provide transit between planned SDA fabrics in Branch #1
and #2, considering the future plans? (Choose two)
What are two possible ways of ensuring that authorized local administrators in the Employee VN on
Branch #1 or Branch #2 can still access the local SDA border nodes using their loopback addresses
through in-band SSH access? (Choose two.)
What are the two valid design options for deploying QoS on the SDA branches that will meet FABD2
requirement? (Choose two.)
a) Extend the existing queuing model into a new 4/5 class model.
b) Use the DNA Center templates to rebuild the QoS policy.
c) Leverage the SGT-based QoS.
d) Use the DNA Center to define business-irrelevant application sets.
e) Use the DNA Center application policy to rebuild the QoS policy.
Answer:
QUESTION 34:
Given the requirement, what would be the best way to implement the logging on r21?
Given the circumstances, what is the best option for Anna to develop and debug her scripts before
deploying them on FABD2 production network?
a) Use the production network while executing REST API calls bundled in a transaction and rolled back at
the end without a commit
b) Perform the development and debugging on the production network during dedicated maintenance
windows
c) Create a lab repro for development purposes
d) Use DevNet SD-WAN sandbox labs
Answer:
QUESTION 37:
This item consists of multiple questions you may need to scroll down to be able to see all questions
a) hostname
b) license number
c) device chassis/channel number
d) certificate serial number
Answer:
37.3 What is the purpose of enclosing the deviceIP / deviceId object into square brackets in the JSON call
template?
Which two of the following changes to the script would shorten its running time without impacting its
functionality? (Choose two.)
a) Construct the JSON body of the request manually instead of using the json.dumps0 method.
b) Execute the login API0 only once and reuse the session for multiple API calls.
c) Use the put0 method instead of post0 to pass the reboot API call.
d) Combine device IP/ID pairs into a list and pass them all in a single API call.
e) Refer to the vManage by its DNS FQDN instead of its IP address.
Answer:
QUESTION 39:
BONUS
Answer: