Latest 350-401 Pass Guaranteed Exam Dumps with Accurate & Updated Questions
350-401 Exam Brain Dumps - Study Notes and Theory
NEW QUESTION 159
Which controller is the single plane of management for Cisco SD-WAN?
- A. vSmart
- B. vEdge
- C. vManage
- D. vBond
Answer: C
NEW QUESTION 160
Drag and drop the characteristics from the left onto the orchestration tools they describe on the right.
Answer:
Explanation:
NEW QUESTION 161
Refer to the exhibit.
A network engineer must simplify the IPsec configuration by enabling IPsec over GRE using IPsec profiles. Which two configuration changes accomplish this? (Choose two).
- A. Apply the crypto map to the tunnel interface and change the tunnel mode to tunnel mode ipsec ipv4.
- B. Remove all configuration related to crypto map from R1 and R2 and eliminate the ACL |>]
- C. Create an IPsec profile, associate the transform-set. and apply the profile to the tunnel interface.
- D. Remove the crypto map and modify the ACL to allow traffic between 10.10.0.0/24 to 10.20.0.0/24.
- E. Create an IPsec profile, associate the transform-set ACL. and apply the profile to the tunnel interface
Answer: A,E
NEW QUESTION 162
Refer to the exhibit.
A network administrator configured RSPAN to troubleshoot an issue between switchl and switch2. The switches are connected using interface GigabitEthernet 1/1 An external packet capture device is connected to swich2 interface GigabitEthernet1/2 Which two commands must be added to complete this configuration?
(Choose two)
- A. switch2(config)# monitor session 1 source remote vlan 70
switch2(config)# monitor session 1 destination interface GigabitEthernet1/2 - B. switch2(config)# monitor session 2 destination vlan 10
- C. switch2(config)# monitor session 1 source remote vlan 70 switch2(config)# monitor session 1 destination interface GigabitEthernet1/1
- D. switch2(config-if)# switchport trunk allowed vlan 10,20,30,40,50,60,70-80
- E. switch1(config)# interface GigabitEthernet 1/1 switch1(config-if)# switchport mode access switch1(config-if)# switchport access vlan 10 switch2(config)# interface GigabitEthernet 1/1 switch2(config-if)# switchport mode access switch2(config-if)# switchport access vlan 10
Answer: A,D
Explanation:
Explanation
Switch2 is not allowing VLAN 70 which is used on Switch1 for RSPAN so we must allow it -> Option B is correct (although it would not allow VLAN 81 to 90 to go through).
"An external packet capture device is connected to switch2 interface GigabitEthernet1/2" so we must configure Gi1/2 as the destination port.
For your information, this is how to configure Remote SPAN (RSPAN) feature on two switches.
Traffic on FastEthernet0/1 of Switch 1 will be sent to Fa0/10 of Switch2 via VLAN 40.
+ Configure on both switchesSwitch1,2(config)#vlan 40Switch1,2(config-vlan)#remote-span
+ Configure on Switch1Switch1(config)# monitor session 1 source interface FastEthernet 0/1Switch1(config)# monitor session 1 destination remote vlan 40
+ Configure on Switch2Switch2(config)#monitor session 5 source remote vlan 40Switch2(config)# monitor session 5 destination interface FastEthernet 0/10
NEW QUESTION 163
Drag the drop the description from the left onto the routing protocol they describe on the right.
Answer:
Explanation:

NEW QUESTION 164
Drag and drop the virtual component from the left onto their descriptions on the right.
Answer:
Explanation:
Explanation
+ configuration file containing settings for a virtual machine such as guest OS: VMX
+ component of a virtual machine responsible for sending packets to the hypervisor: vNIC
+ zip file containing a virtual machine configuration file and a virtual disk: OVA
+ file containing a virtual machine disk drive: VMDK
The VMX file simply holds the virtual machine configuration.
VMDK (short for Virtual Machine Disk) is a file format that describes containers for virtual hard disk drives to be used in virtual machines like VMware Workstation or VirtualBox.
An OVA file is an Open Virtualization Appliance that contains a compressed, "installable" version of a virtual machine. When you open an OVA file it extracts the VM and imports it into whatever virtualization software you have installed on your computer.
NEW QUESTION 165
An engineer is concerned with the deployment of new application that is sensitive to inter-packet delay variance. Which command configures the router to be the destination of jitter measurements?
- A. Router(config)# ip sla responder udp-echo 172.29.139.134 5000
- B. Router(config)# ip sla responder udp-connect 172.29.139.134 5000
- C. Router(config)# ip sla responder tcp-connect 172.29.139.134 5000
- D. Router(config)# ip sla responder tcp-echo 172.29.139.134 5000
Answer: A
NEW QUESTION 166
Refer to the exhibit.
Which type of antenna is show on the radiation patterns?
- A. Patch
- B. Dipole
- C. Yagi
- D. Omnidirectional
Answer: B
Explanation:
Explanation
A dipole antenna most commonly refers to a half-wavelength (/2) dipole. The physical antenna (not the package that it is in) is constructed of conductive elements whose combined length is about half of a wavelength at its intended frequency of operation. This is a simple antenna that radiates its energy out toward the horizon (perpendicular to the antenna). The patterns shown are those resulting from a perfect dipole formed with two thin wires oriented vertically along the z-axis.
Reference:
https://www.cisco.com/c/en/us/products/collateral/wireless/aironet-antennas-accessories/prod_white_paper0900a
NEW QUESTION 167
Which entity is responsible for maintaining Layer 2 isolation between segments In a VXLAN environment?
- A. host switch
- B. switch fabric
- C. VNID
- D. VTEP
Answer: C
Explanation:
Explanation
VXLAN uses an 8-byte VXLAN header that consists of a 24-bit VNID and a few reserved bits. The VXLAN header together with the original Ethernet frame goes in the UDP payload. The 24-bit VNID is used to identify Layer 2 segments and to maintain Layer 2 isolation between the segments.
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/sw/7-x/vxlan/configuration/guide/b_Cisco
NEW QUESTION 168
Refer to the exhibit.
Which command set must be added to the configuration to analyze 50 packets out of every 100?
- A. Option D
- B. Option B
- C. Option A
- D. Option C
Answer: A
NEW QUESTION 169
Which statement about agent-based versus agentless configuration management tools is true?
- A. Agentless tools use proxy nodes to interface with slave nodes.
- B. Agentless tools require no messaging systems between master and slaves.
- C. Agent-based tools do not require installation of additional software packages on the slave nodes.
- D. Agent-based tools do not require a high-level language interpreter such as Python or Ruby on slave nodes.
Answer: C
NEW QUESTION 170
An engineer creates the configuration below. Drag and drop the authentication methods from the left into the order of priority on the right. Not all options are used.

Answer:
Explanation:
NEW QUESTION 171
Drag and drop the Qos mechanisms from the left to the correct descriptions on the right
Answer:
Explanation:
NEW QUESTION 172
Which two descriptions of FlexConnect mode for Cisco APs are true? (Choose two.)
- A. FlexConnect mode is a feature that is designed to allow specified CAPWAP-enabled APs to exclude themselves from managing data traffic between clients and infrastructure.
- B. FlexConnect mode is used when the APs are set up in a mesh environment and used to bridge between each other.
- C. APs that operate in FlexConnect mode cannot detect rogue Aps.
- D. FlexConnect mode is a wireless solution for branch office and remote office deployments.
- E. When connected to the controller, FlexConnect APs can tunnel traffic back to the controller.
Answer: D,E
NEW QUESTION 173
Refer to the exhibit.
The inside and outside interfaces in the NAT configuration of this device have been correctly identified. What is the effect of this configuration?
- A. NAT64
- B. PAT
- C. dynamic NAT
- D. static NAT
Answer: B
NEW QUESTION 174
Refer to the exhibit.
Which command when applied to the Atlanta router reduces type 3 LSA flooding into the backbone area and summarizes the inter-area routes on the Dallas router?
- A. Atlanta(config-route)#area 1 range 192.168.0.0 255.255.248.0
- B. Atlanta(config-route)#area 0 range 192.168.0.0 255.255.248.0
- C. Atlanta(config-route)#area 1 range 192.168.0.0 255.255.252.0
- D. Atlanta(config-route)#area 0 range 192.168.0.0 255.255.252.0
Answer: C
NEW QUESTION 175 
Refer to the exhibit. An engineer must create a configuration that executes the show run command and then terminates the session when user CCNP logs in. Which configuration change is required?
- A. Add the autocommand keyword to the username command.
- B. Add the access-class keyword to the aaa authentication command.
- C. Add the access-class keyword to the username command.
- D. Add the autocommand keyword to the aaa authentication command.
Answer: A
NEW QUESTION 176
An engineer must configure interface GigabitEthernet0/0 for VRRP group 10. When the router has the highest priority in the group, it must assume the master role. Which command set must be added to the initial configuration to accomplish this task?
- A. standby 10 ip 172.16.13.254
standby 10 priority 120 - B. standby 10 ip 172.16.13.254 255.255.255.0
standby 10 preempt - C. vrrp group 10 ip 172.16.13 254.255.255.255.0
vrrp group 10 priority 120 - D. vrrp 10 ip 172.16.13.254
vrrp 10 preempt
Answer: C
Explanation:
Explanation
NEW QUESTION 177
Which PAgP mode combination prevents an Etherchannel from forming?
- A. auto/auto
- B. desirable/desirable
- C. auto/desirable
- D. desirable
Answer: A
Explanation:
Explanation
There are two PAgP modes:
The table below lists if an EtherChannel will be formed or not for PAgP:
NEW QUESTION 178
Refer to the exhibit. An engineer is investigating why guest users are able to access other guest user devices when the users are connected to the customer guest WLAN. What action resolves this issue?
- A. implement P2P blocking
- B. implement split tunneling
- C. implement Wi-Fi direct policy
- D. implement MFP client protection
Answer: B
Explanation:
https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-1/configurationguide
NEW QUESTION 179
Refer to Exhibit.
MTU has been configured on the underlying physical topology, and no MTU command has been configured on the tunnel interfaces. What happens when a 1500-byte IPv4 packet traverses the GRE tunnel from host X to host Y, assuming the DF bit is cleared?
- A. The packet is discarded on router B
- B. The packet arrives on router C without fragmentation.
- C. The packet arrives on router C fragmented.
- D. The packet is discarded on router A
Answer: C
Explanation:
NEW QUESTION 180
Refer to the exhibit.
An engineer must modify the access control list EGRESS to allow all IP traffic from subnet 10.1.10.0/24 to
10.1.2.0/24. The access control list is applied in the outbound direction on router interface GigabitEthemet 0/1.
Which configuration commands can the engineer use to allow this traffic without disrupting existing traffic flows?
A)
B)
C)
D)
- A. Option D
- B. Option A
- C. Option C
- D. Option B
Answer: D
NEW QUESTION 181
Which three methods does Cisco DNA Center use to discover devices? (Choose three.)
- A. specified range of IP addresses
- B. LLDP
- C. SNMP
- D. NETCONF
- E. CDP
- F. Ping
Answer: A,B,E
Explanation:
Explanation
Cisco DNA Center supports three methods for discovery: LLDP, CDP (Cisco Discovery Protocol) and IP Range.
https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2019/pdf/LTRNMS-2500-LG.pdf
NEW QUESTION 182
What is the centralized control policy in a Cisco SD-WAN deployment?
- A. list of ordered statements that define user access policies
- B. set of statements that defines how routing is performed
- C. list of enabled services for all nodes within the cloud
- D. set of rules that governs nodes authentication within the cloud
Answer: B
NEW QUESTION 183
......
Further Certification Path After Passing 350-401
The Cisco 350-401 ENCOR certification exam is the starting point for different certifications. If you want to go further than being a certified Specialist for Enterprise Core, then you should know that it is also a core exam for the CCNP Enterprise certificate. From here, you will need to take a concentration test to get accredited.
If CCNP accreditation is not the final target point for you, then use Cisco 350-401 ENCOR as the qualifying exam to obtain CCIE Enterprise Infrastructure or Enterprise Wireless accreditation. These will require you to ace one more test as well.
Pass Cisco 350-401 Test Practice Test Questions Exam Dumps: https://www.dumptorrent.com/350-401-braindumps-torrent.html
The Best CCNP Enterprise Study Guide for the 350-401 Exam: https://drive.google.com/open?id=1IrEWftef9-soHNXQHkTMIkIPCVYgMbCv