CCNP Enterprise 300-410 Real Exam Questions and Answers FREE Updated on Oct 08, 2021
300-410 Ultimate Study Guide - ExamsReviews
NEW QUESTION 113
Refer to the exhibit. Users report that IP addresses cannot be acquired from the DHCP server. The DHCP server is configured as shown. About 300 total nonconcurrent users are using this DHCP server, but none of them are active for more than two hours per day.
Which action fixes the issue within the current resources?
- A. Configure the DHCP lease time to a smaller value
- B. Modify the subnet mask to the network 192.168.1.0 255.255.254.0 command in the DHCP pool
- C. Add the network 192.168.2.0 255.255.255.0 command to the DHCP pool
- D. Configure the DHCP lease time to a bigger value
Answer: A
Explanation:
Section: Infrastructure Services
Explanation
NEW QUESTION 114
Which statement about IPv6 ND inspection is true?
- A. It learns and secures bindings for stateless autoconfiguration addresses in Layer 2 neighbor tables.
- B. It learns and secures bindings for stateful autoconfiguration addresses in Layer 3 neighbor tables.
- C. It learns and secures bindings for stateless autoconfiguration addresses in Layer 3 neighbor tables.
- D. It learns and secures bindings for stateful autoconfiguration addresses in Layer 2 neighbor tables.
Answer: A
Explanation:
Explanation
IPv6 ND inspection learns and secures bindings for stateless autoconfiguration addresses in Layer 2 neighbor tables. IPv6 ND inspection analyzes neighbor discovery messages in order to build a trusted binding table database, and IPv6 neighbor discovery messages that do not have valid bindings are dropped. A neighbor discovery message is considered trustworthy if its IPv6-to-MAC mapping is verifiable.
This feature mitigates some of the inherent vulnerabilities for the neighbor discovery mechanism, such as attacks on duplicate address detection (DAD), address resolution, device discovery, and the neighbor cache.
NEW QUESTION 115
Refer to the exhibit.
A network administrator is discovering a Cisco Catalyst 9300 and a Cisco WLC 3504 in Cisco DNA Center. The Catalyst 9300 is added successfully However the WLC is showing [ error "uncontactable" when the administrator tries to add it in Cisco DNA Center. Which action discovers WLC in Cisco DNA Center successfully?
- A. Copy the .cert file from the Cisco DNA Center on the USB and upload it to the WLC 3504.
- B. Delete the WLC 3504 from Cisco DNA Center and add it to Cisco DNA Center again.
- C. Copy the .pern file from the Cisco DNA Center on the USB and upload it to the WLC 3504.
- D. Add the WLC 3504 under the hierarchy of the Catalyst 9300 connected devices.
Answer: C
NEW QUESTION 116
Refer to the exhibit.
The ACL is placed on the inbound Gigabit 0/1 interface of the router. Host
192.168.10.10cannot SSH to host 192.168.100.10 even though the flow is permitted. Which action resolves the issue without opening full access to this router?
- A. Temporarily remove the ACL from the interface to see if the flow works
- B. Temporarily move the permit ip any any line to the beginning of the ACL to see if the flow works
- C. Run the show access-list FILTER command to view if the SSH entry has any hit statistic associated with it
- D. Move the SSH entry to the beginning of the ACL
Answer: D
NEW QUESTION 117
Refer to the exhibit.
An engineer wanted to set a tag of 30 to route 10 1.80.65/32 but it failed How is the issue fixed?
- A. Modify prefix-list ccnp3 to add 10.1.64.0/20 ge 32
- B. Modify route-map ospf-to-eigrp permit 30 and match prefix-list ccnp2.
- C. Modify prefix-list ccnp3 to add 10.1.64.0/20 le 24
- D. Modify route-map ospf-to-eigrp permit 10 and match prefix-list ccnp2.
Answer: D
NEW QUESTION 118 
Refer to the exhibit. The network administrator has configured the Customer Edge router (AS 64511) to send only summarized routes toward ISP-1 (AS 100) and ISP-2 (AS 200).
router bgp 64511
network 172.16.20.0 mask 255.255.255.0
network 172.16.21.0 mask 255.255.255.0
network 172.16.22.0 mask 255.255.255.0
network 172.16.23.0 mask 255.255.255.0
aggregate-address 172.16.20.0 255.255.252.0
After this configuration. ISP-1 and ISP-2 continue to receive the specific routes and the summary route. Which configuration resolves the issue?
- A. ip prefix-list PL_BLOCK_SPECIFIC deny 172.16.20.0/22 ge 22
ip prefix-list PL BLOCK SPECIFIC permit 172.16.20.0/22
!
route-map BLOCK_SPECIFIC permit 10
match ip address prefix-list PL_BLOCK_SPECIFIC
!
router bgp 64511
aggregate-address 172.16.20.0 255 255.252.0 suppress-map BLOCKSPECIFIC - B. router bgp 64511
aggregate-address 172.16.20.0 255.255.252.0 summary-only - C. interface E 0/0
ip bgp suppress-map BLOCK_SPECIFIC
!
interface E 0/1
ip bgp suppress-map BLOCK_SPECIFIC
!
ip prefix-list PL_BLOCK_SPECIFIC permit 172.16.20.0/22 ge 24
!
route-map BLOCK_SPECIFIC permit 10
match ip address prefix-list PL_BLOCK_SPECIFIC - D. router bgp 64511
neighbor 192.168.100.1 summary-only
neighbor 192.168.200.2 summary-only
Answer: B
Explanation:
Explanation
When the aggregate-address command is used within BGP routing, the aggregated address is advertised, along with the more specific routes. The exception to this rule is through the use of the summary-only command. The "summary-only" keyword suppresses the more specific routes and announces only the summarized route.
NEW QUESTION 119
An engineer configured a leak-map command to summarize EIGRP routes and advertise specifically loopback 0 with an IP of 10.1.1.1.255.255.255.252 along with the summary route. After finishing configuration, the customer complained not receiving summary route with specific loopback address. Which two configurations will fix it? (Choose two.)
- A. Configure route-map Leak-Route permit 20.
- B. Configure access-list 1 and match under route-map Leak-Route.
- C. Configure access-list 1 permit 10.1.1.0.0.0.0.3.
- D. Configure access-list 1 permit 10.1.1.1.0.0.0.252.
- E. Configure route-map Leak-Route permit 10 and match access-list 1.
Answer: D,E
NEW QUESTION 120
Refer to the exhibit.
An engineer is troubleshooting BGP on a device but discovers that the clock on the device does not correspond to the time stamp of the log entries. Which action ensures consistency between the two times?
- A. Configure the service timestamps log uptime command in global configuration mode.
- B. Configure the logging clock synchronize command in global configuration mode.
- C. Make sure that the clock on the device is synchronized with an NTP server.
- D. Configure the service timestamps log datetime localtime command in global configuration mode.
Answer: C
NEW QUESTION 121
What are two MPLS label characteristics? (Choose two.)
- A. Labels are imposed in packets after the Layer 3 header.
- B. An MPLS label is a short identifier that identifies a forwarding equivalence class.
- C. LDP uses TCP for reliable delivery of information.
- D. A maximum of two labels can be imposed on an MPLS packet.
- E. The label edge router swaps labels on the received packets.
Answer: B,C
NEW QUESTION 122
How are MPLS Layer 3 VPN services deployed?
- A. The import and export RT values under a VRF must always be the same.
- B. The RD and RT values under a VRF must match on the remote PE router
- C. The label switch path must be available between the local and remote PE routers.
- D. The RD and RT values must match under the VRR
Answer: C
Explanation:
Explanation
https://www.cisco.com/c/en/us/td/docs/iosxr/ncs5500/vpn/65x/b-l3vpn-cg-ncs5500-65x/b-l3vpn-cg-ncs5500-
NEW QUESTION 123
What does the PE router convert the Ipv4 prefix to within an MPLS VPN?
- A. It advertises labels per Forwarding Equivalence Class.
- B. It requires MPLS Traffic Engineering.
- C. It must use Resource Reservation Protocol.
- D. It is defined in RFC 3038 and 3039.
Answer: B
NEW QUESTION 124
Drag and drop the OSPF adjacency states from the left onto the correct descriptions on the right.
Answer:
Explanation:
Explanation:
Down
This is the first OSPF neighbor state. It means that no information (hellos) has been received from this neighbor, but hello packets can still be sent to the neighbor in this state.
During the fully adjacent neighbor state, if a router doesn't receive hello packet from a neighbor within the Router Dead Interval time (RouterDeadInterval = 4*HelloInterval by default) or if the manually configured neighbor is being removed from the configuration, then the neighbor state changes from Full to Down.
Attempt
This state is only valid for manually configured neighbors in an NBMA environment. In Attempt state, the router sends unicast hello packets every poll interval to the neighbor, from which hellos have not been received within the dead interval.
Init
This state specifies that the router has received a hello packet from its neighbor, but the receiving router's ID was not included in the hello packet. When a router receives a hello packet from a neighbor, it should list the sender's router ID in its hello packet as an acknowledgment that it received a valid hello packet.
2-Way
This state designates that bi-directional communication has been established between two routers. Bi-directional means that each router has seen the other's hello packet. This state is attained when the router receiving the hello packet sees its own Router ID within the received hello packet's neighbor field. At this state, a router decides whether to become adjacent with this neighbor. On broadcast media and non-broadcast multiaccess networks, a router becomes full only with the designated router (DR) and the backup designated router (BDR); it stays in the 2-way state with all other neighbors. On Point-to-point and Point-to-multipoint networks, a router becomes full with all connected routers.
At the end of this stage, the DR and BDR for broadcast and non-broadcast multiacess networks are elected. For more information on the DR election process, refer to DR Election.
Note: Receiving a Database Descriptor (DBD) packet from a neighbor in the init state will also a cause a transition to 2-way state.
Exstart
Once the DR and BDR are elected, the actual process of exchanging link state information can start between the routers and their DR and BDR. (ie. Shared or NBMA networks).
In this state, the routers and their DR and BDR establish a master-slave relationship and choose the initial sequence number for adjacency formation. The router with the higher router ID becomes the master and starts the exchange, and as such, is the only router that can increment the sequence number. Note that one would logically conclude that the DR/BDR with the highest router ID will become the master during this process of master-slave relation. Remember that the DR/BDR election might be purely by virtue of a higher priority configured on the router instead of highest router ID. Thus, it is possible that a DR plays the role of slave. And also note that master/slave election is on a per-neighbor basis.
Exchange
In the exchange state, OSPF routers exchange database descriptor (DBD) packets. Database descriptors contain link-state advertisement (LSA) headers only and describe the contents of the entire link-state database. Each DBD packet has a sequence number which can be incremented only by master which is explicitly acknowledged by slave. Routers also send link-state request packets and link-state update packets (which contain the entire LSA) in this state. The contents of the DBD received are compared to the information contained in the routers link-state database to check if new or more current link-state information is available with the neighbor.
Loading
In this state, the actual exchange of link state information occurs. Based on the information provided by the DBDs, routers send link-state request packets. The neighbor then provides the requested link-state information in link-state update packets. During the adjacency, if a router receives an outdated or missing LSA, it requests that LSA by sending a link-state request packet. All link-state update packets are acknowledged.
Full
In this state, routers are fully adjacent with each other. All the router and network LSAs are exchanged and the routers' databases are fully synchronized.
Full is the normal state for an OSPF router. If a router is stuck in another state, it is an indication that there are problems in forming adjacencies. The only exception to this is the 2-way state, which is normal in a broadcast network. Routers achieve the FULL state with their DR and BDR in NBMA/broadcast media and FULL state with every neighbor in the remaining media such as point-to-point and point-to-multipoint.
Note: The DR and BDR that achieve FULL state with every router on the segment will display FULL/DROTHER when you enter the show ip ospf neighbor command on either a DR or BDR. This simply means that the neighbor is not a DR or BDR, but since the router on which the command was entered is either a DR or BDR, this shows the neighbor as FULL/DROTHER.
Reference:
https://www.cisco.com/c/en/us/support/docs/ip/open-shortest-path-first-ospf/13685-13.html When OSPF adjacency is formed, a router goes through several state changes before it becomes fully adjacent with its neighbor. The states are Down -> Attempt (optional) -> Init -> 2-Way -> Exstart -> Exchange -> Loading -> Full. Short descriptions about these states are listed below:
Down: no information (hellos) has been received from this neighbor.
Attempt: only valid for manually configured neighbors in an NBMA environment. In Attempt state, the router sends unicast hello packets every poll interval to the neighbor, from which hellos have not been received within the dead interval.
Init: specifies that the router has received a hello packet from its neighbor, but the receiving router's ID was not included in the hello packet
2-Way: indicates bi-directional communication has been established between two routers.
Exstart: Once the DR and BDR are elected, the actual process of exchanging link state information can start between the routers and their DR and BDR.
Exchange: OSPF routers exchange and compare database descriptor (DBD) packets Loading: In this state, the actual exchange of link state information occurs. Outdated or missing entries are also requested to be resent.
Full: routers are fully adjacent with each other
(Reference:
http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a0080093f0e.shtml)
https://www.cisco.com/c/en/us/support/docs/ip/open-shortest-path-first-ospf/13685-13.html
NEW QUESTION 125 
Refer to the exhibit. The DHCP client is unable to receive an IP address from the DHCP server RouterB is configured as follows:
Interface fastethernet 0/0
description Client DHCP ID 394482431
Ip address 172 31 11 255 255.255 0
!
ip route 172.16.1.0 255 255 255.0 10.1.1.2
Which command is required on the fastethernet 0/0 interface of RouterB to resolve this issue?
- A. RouterB(config-if)#lp helper-address 172.16.1.1
- B. RouterB(config-if)#lp helper-address 172.16.1.2
- C. RouterBiconfig-ififclp helper-address 255.255 255 255
- D. RouterB(config-if)#lp helper-address 172.31.1.1
Answer: B
NEW QUESTION 126
Drag and drop the actions from the left into the correct order on the right to configure a policy to avoid following packet forwarding based on the normal routing path.
Answer:
Explanation:
Explanation
https://community.cisco.com/t5/networking-documents/how-to-configure-pbr/ta-p/3122774
NEW QUESTION 127
Refer to the exhibit.
A user cannot SSH to the router. What action must be taken to resolve this issue?
- A. Configure ip ssh source-interface loopback0
- B. Configure transport input ssh
- C. Configure ip ssh version 2
- D. Configure transport output ssh
Answer: B
Explanation:
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960x/software/15-0_2_EX/security/configuration_guide/b_sec_152ex_2960-x_cg/b_sec_152ex_2960-x_cg_chapter_01001.html
NEW QUESTION 128
......
Ultimate Guide to Prepare 300-410 Certification Exam for CCNP Enterprise: https://www.examsreviews.com/300-410-pass4sure-exam-review.html
Use Real 300-410 Dumps - Cisco Correct Answers: https://drive.google.com/open?id=1Gg4CtGOl1kRMc5UCK2-tem3-V9J4ktFy