Cisco CCNP Enterprise 350-401 ENCOR Enterprise Design and High Availability Practice Test

 

Topic 01 covers enterprise design and high availability for the Cisco Certified Specialist – Enterprise Core certification. These original practice questions apply the verified 350-401 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the Cisco 350-401 ENCOR Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.

Question 1

A two-building campus has one distribution block, independent power for its redundant distribution switches, and ample routing and port capacity for the next five years. All access switches have diverse links to that pair. A proposal adds two core switches solely because the campus has two buildings. Which recommendation best fits the stated requirements?

  1. Deploy separate distribution pairs on every floor immediately.
  2. Retain the redundant collapsed core.
  3. Add the core pair before connecting any interbuilding links.
  4. Replace the pair with one larger chassis to simplify routing.
  5. Extend the building access VLANs to a new central aggregation pair.

Correct Answer: B

 

Correct Answer

Answer B is correct because the existing block already provides aggregation and interconnection at the required scale. Building count alone does not justify an extra tier when projected capacity and resilience requirements are met.

Incorrect Answers

Answer A is incorrect because additional blocks may support future scale, but no floor-level capacity or maintenance requirement justifies that complexity in this design.

Answer C is incorrect because a dedicated core can help larger modular campuses, but the scenario supplies neither multiple distribution blocks nor a capacity constraint requiring it now.

Answer D is incorrect because capacity is already sufficient, and removing a separate failure domain weakens the stated redundancy without addressing an identified limitation.

Answer E is incorrect because centralizing those VLANs is a possible topology change, but it introduces a broader dependency without solving a stated capacity or resilience limitation.

 

Question 2

A campus will expand from two to six distribution blocks. Direct links between blocks require repeated routing-policy changes on every existing block whenever another is added. The team wants a repeatable expansion pattern while retaining building-level policy boundaries. Which design change most directly addresses the problem?

  1. Move every building-specific policy into the access ports.
  2. Interconnect the distribution blocks through a simple redundant Layer 3 core.
  3. Connect each new block only through the nearest existing block.
  4. Increase the bandwidth of each existing interdistribution link.
  5. Combine all building access switches into one campus-wide Layer 2 domain.

Correct Answer: B

 

Correct Answer

Answer B is correct because a core supplies a common transport layer between modular distribution blocks. New blocks attach to that layer while their local policy boundaries remain at distribution.

Incorrect Answers

Answer A is incorrect because redistributing policy alone does not provide a scalable interconnection pattern and would multiply places requiring changes.

Answer C is incorrect because chaining blocks creates transit dependencies on individual buildings and fails to supply the stable campus backbone requested.

Answer D is incorrect because faster links can relieve load, but they do not reduce the number of interblock relationships that must change during expansion.

Answer E is incorrect because this expands the shared fault domain and removes the modular boundaries the team explicitly wants to retain.

 

Question 3

An error in a building distribution change interrupted four other buildings because all depended on that pair for transit. The replacement design must remove this transit dependency and keep building-specific policy changes from altering shared campus transport policy. Which TWO choices jointly meet those requirements? Choose TWO.

  1. Add a second power supply to the original transit pair.
  2. Keep building-specific policy and fault boundaries within their distribution blocks.
  3. Use a campus-wide access VLAN as the interbuilding transport.
  4. Connect each distribution block independently to a redundant routed core.
  5. Place all campus routing interfaces on the original distribution pair.

Correct Answers: B, D

 

Correct Answers

Answer B is correct because modular boundaries limit the scope of local changes rather than letting one building policy govern all campus transit.

Answer D is correct because independent core attachments remove the need for unrelated buildings to transit the distribution pair being maintained.

Incorrect Answers

Answer A is incorrect because power redundancy addresses a hardware power failure, whereas the reported outage came from a configuration dependency.

Answer C is incorrect because a shared Layer 2 domain broadens the affected topology and does not isolate distribution maintenance.

Answer E is incorrect because this preserves the shared dependency that caused the outage, even if the interfaces use different VLAN numbers.

 

Question 4

In a proposed twelve-building campus, access switches enforce endpoint admission, but all user and server VLAN gateways reside in the core; distribution switches only bridge those VLANs. The business requires user-to-server routing within each building to survive complete loss of the core, while retaining one routing-policy boundary per building. Distribution switches have the required Layer 3 capacity. Which redesign meets the requirement?

  1. Retain core gateways and add a second distribution switch that bridges the same VLANs.
  2. Keep the gateways in the core and add another link from each distribution block to it.
  3. Move all local VLAN gateways to one central WAN firewall with redundant core attachments.
  4. Keep gateways in the core and place an additional access list on each access switch.
  5. Move local VLAN gateways and routing policy to each distribution block; retain admission at access.

Correct Answer: E

 

Correct Answer

Answer E is correct because local inter-VLAN traffic can then be routed inside its building without traversing the unavailable core. Admission remains near endpoints, while distribution provides the required building routing boundary.

Incorrect Answers

Answer A is incorrect because a redundant Layer 2 distribution pair can preserve local bridging, but traffic between user and server VLANs still needs the unavailable core gateway. Distribution must supply the local routing function.

Answer B is incorrect because additional links can protect against a link failure, but all local inter-VLAN routing still depends on core devices. Complete loss of the core removes the gateways regardless of link count.

Answer C is incorrect because the local user-to-server path would still traverse the core to reach its gateway. A separate central routing device does not meet the requirement to route within a building during complete core loss.

Answer D is incorrect because local access lists can enforce policy, but they do not relocate the inter-VLAN forwarding decision. The user-to-server route still depends on the core gateway.

 

Question 5

A building uses a modular access chassis with two empty line-card slots, and all installed endpoint ports are committed. Compatible cards can add the required ports; the supervisor, uplinks, cooling and redundant power have verified headroom after expansion. Rack space cannot accommodate another chassis, and existing endpoints must not be moved. Which change best satisfies the immediate growth requirement?

  1. Install supported access line cards in the available slots.
  2. Replace occupied access cards with higher-density cards and migrate their endpoints.
  3. Upgrade the existing uplinks before expanding the endpoint cards.
  4. Install a fixed access switch after removing a distribution switch to free rack space.
  5. Replace the supervisor before adding any endpoint cards.

Correct Answer: A

 

Correct Answer

Answer A is correct because the verified chassis resources and empty slots allow the required port growth without consuming unavailable rack space or changing the building topology.

Incorrect Answers

Answer B is incorrect because higher-density replacements can increase port count, but this option requires moving existing endpoint connections. Empty compatible slots meet the expansion requirement without violating that constraint.

Answer C is incorrect because the existing uplinks already have verified capacity for the expanded load. Upgrading them first adds an unnecessary step without supplying the endpoint ports that are immediately required.

Answer D is incorrect because this removes an existing distribution redundancy element to obtain ports that the current access chassis can already supply without that availability tradeoff.

Answer E is incorrect because the supervisor has already been verified to support the expanded load, so replacing it does not resolve the limiting port count more directly.

 

Question 6

A company must apply the same departmental segmentation policy in 30 campus buildings. Manual changes require coordinated edits to many configurations and frequently drift. A supported fabric pilot reduced configuration mismatches, while traffic paths, link utilization and policy-validation effort remained unchanged. The team can operate the controller and identity dependencies. Which benefit is supported by this pilot when preparing the adoption case?

  1. Lower change-validation effort from using one policy workflow for every building.
  2. Less configuration drift when deploying departmental policy across buildings.
  3. Fewer infrastructure dependencies to operate after controller-based deployment.
  4. Shorter application paths between departments because policy is centrally managed.
  5. Additional capacity headroom on the campus links from automated policy distribution.

Correct Answer: B

 

Correct Answer

Answer B is correct because fewer configuration mismatches directly address the observed coordination problem. The supported workflow and operating capability justify this consistency benefit without claiming unmeasured effort, capacity or performance gains.

Incorrect Answers

Answer A is incorrect because the pilot left validation effort unchanged. Consistent deployment does not establish that a policy is correct or justify reducing the checks before distributing it.

Answer C is incorrect because the team can support the new controller and identity dependencies, but supportability is different from reducing their number. That claim is not established by the observed reduction in configuration drift.

Answer D is incorrect because the measured traffic paths did not change. Centralized policy management is not evidence that the forwarding topology has become shorter.

Answer E is incorrect because link utilization remained unchanged, so this pilot does not support a capacity benefit. Automated configuration does not itself add physical bandwidth.

 

Question 7

A plant proposes moving its only production-control server to a public cloud. The application must continue operating for four hours after both WAN circuits are unavailable, and it currently has no local execution or caching capability. Which conclusion follows from that requirement?

  1. Keep the server off-site and deploy a second instance in another cloud region.
  2. Keep the server off-site and diversify the two existing WAN circuits across providers.
  3. Keep the server off-site and shorten WAN failure-detection and route-convergence timers.
  4. Retain local execution for the required disconnected operation.
  5. Keep the server off-site and retain local DNS records for its cloud address.

Correct Answer: D

 

Correct Answer

Answer D is correct because cloud placement would make this application depend on WAN reachability. The required disconnected operation needs a local capability that the present application does not have.

Incorrect Answers

Answer A is incorrect because a regional replica can address a cloud-region failure, but both remote instances still require a WAN path from the plant. It does not supply disconnected local execution.

Answer B is incorrect because provider diversity can reduce some outages, but the required event explicitly removes both circuits. The sole remote execution environment is still unreachable in that event.

Answer C is incorrect because faster convergence helps when an alternate usable path exists. Here both available circuits are down, so faster routing cannot satisfy four hours of disconnected operation.

Answer E is incorrect because local name resolution may preserve the address lookup, but it neither runs the application nor provides transport to the off-site server after both WAN circuits fail.

 

Question 8

Traffic measurements show that 85% of a research building’s load moves between local compute racks. The campus Internet edge is lightly used, but uplinks between those racks and the building aggregation point remain saturated for sustained intervals during experiments. Which investment should the architect evaluate first?

  1. Upgrade endpoint links while leaving the shared aggregation uplinks unchanged.
  2. Increase or redesign the constrained local paths used by the measured rack-to-rack flows.
  3. Centralize rack-to-rack traffic through the remote WAN hub.
  4. Increase the Internet circuit while leaving local aggregation unchanged.
  5. Expand buffers on the saturated aggregation ports as the sole long-term fix.

Correct Answer: B

 

Correct Answer

Answer B is correct because the measured east-west traffic crosses the local bottleneck. Capacity planning should follow that path rather than an unrelated lightly used external edge.

Incorrect Answers

Answer A is incorrect because faster endpoint attachment can increase offered load but does not relieve the shared uplink bottleneck identified by the traffic measurements.

Answer C is incorrect because hairpinning the traffic introduces additional dependencies and does not increase the saturated local capacity.

Answer D is incorrect because the dominant flows do not use the Internet circuit, so that upgrade does not relieve their measured bottleneck.

Answer E is incorrect because larger buffers may absorb bursts but do not increase service rate for sustained experimental traffic; the measurements call for evaluating path capacity or topology.

 

Question 9

Two departments must remain in separate routing domains. Both currently share one access chassis, and the architect proposes a second physical chassis for availability. Which TWO conclusions correctly distinguish the two design concerns? Choose TWO.

  1. A second chassis can reduce exposure to a chassis failure when connectivity is also redundant.
  2. Placing the departments on different chassis makes a shared routing table sufficient for isolation.
  3. Separate departmental VLANs within one shared routing table satisfy the separate-routing-domain requirement.
  4. Implementing separate logical routing domains on the existing chassis also covers loss of its power feed.
  5. The routing-domain separation must still be implemented and verified on the chosen topology.

Correct Answers: A, E

 

Correct Answers

Answer A is correct because physical distribution can address a component failure, but the remaining paths must also be arranged to preserve service.

Answer E is correct because adding hardware does not automatically create or preserve the logical separation required between departments.

Incorrect Answers

Answer B is incorrect because separate hardware can improve failure independence, but using a shared routing table does not establish the required logical routing-domain separation.

Answer C is incorrect because VLANs separate Layer 2 broadcast domains, but interfaces in the same routing table still share one routing domain. The requirement needs a corresponding Layer 3 separation design.

Answer D is incorrect because both logical domains still depend on the same powered hardware. Segmentation does not supply a surviving physical execution or forwarding path.

 

Question 10

A campus centralizes DNS and authentication at one services distribution block. Every building has two working core paths. Maintenance disconnects the only services block: interbuilding pings continue, but DNS and authentication are unreachable and new user sessions fail. Which design issue should the architect correct?

  1. New-session failures should be treated as an endpoint issue because interbuilding pings succeed.
  2. The services can remain singly attached if default-gateway preemption is enabled.
  3. Core failure-detection timers are too slow to recover the authentication path.
  4. The services attachment remains a shared availability dependency despite redundant campus transport.
  5. The DNS service needs more replicas attached through the same services block.

Correct Answer: D

 

Correct Answer

Answer D is correct because successful interbuilding traffic shows that transport redundancy survived, while the sole services block explains the broad loss of new-session dependencies.

Incorrect Answers

Answer A is incorrect because a successful ping tests a surviving transport path, not DNS or authentication reachability. The explicit loss of those dependencies explains why new sessions fail despite working backbone connectivity.

Answer B is incorrect because preemption changes gateway preference; it does not recreate unavailable DNS or authentication services behind the maintained block.

Answer C is incorrect because the core still carries interbuilding traffic, while the maintenance removes the only service attachment. Faster detection cannot select a service path that no longer exists.

Answer E is incorrect because additional replicas can protect against individual server failures, but all replicas would remain unreachable when their shared attachment block is disconnected.

 

Question 11

An access block has 48 active 1-Gb/s endpoint ports and two active 10-Gb/s uplinks on separate line cards. The design rule is a maximum potential oversubscription of 3:1 after either uplink fails. Ignore protocol overhead and evaluate traffic toward the uplinks in one direction, with all endpoint ports transmitting concurrently. Which assessment is correct?

  1. The design fails normally at 4.8:1 and improves to 2.4:1 after a failure.
  2. The design passes after failure because 10 Gb/s exceeds each individual endpoint speed.
  3. The design passes normally at 2.4:1 but fails the single-uplink-loss requirement at 4.8:1.
  4. The failure-state ratio is 2.4:1 because one full-duplex 10-Gb/s uplink provides 20 Gb/s.
  5. The design passes in both states because the normal 2.4:1 ratio remains unchanged.

Correct Answer: C

 

Correct Answer

Answer C is correct because 48 Gb/s divided by 20 Gb/s is 2.4 in normal operation; after one uplink fails, 48 divided by 10 is 4.8, exceeding the stated 3:1 limit.

Incorrect Answers

Answer A is incorrect because this reverses the available uplink capacities; losing a link cannot improve the ratio with endpoint demand unchanged.

Answer B is incorrect because the requirement concerns aggregate potential demand from 48 ports, not just whether one endpoint fits on the surviving uplink.

Answer D is incorrect because full duplex supplies 10 Gb/s in each direction, not 20 Gb/s in the direction being evaluated. Surviving egress is 10 Gb/s, producing 48/10 = 4.8:1.

Answer E is incorrect because endpoint capacity remains 48 Gb/s while surviving uplink capacity halves, so the failure-state ratio cannot remain 2.4:1.

 

Question 12

An access block must survive failure of either distribution switch. It has two identical uplinks and two independent distribution switches, each capable of carrying the entire measured load. Routing and service reachability have been validated through either switch, but both access uplinks currently terminate on the same switch. Which change meets the requirement without adding equipment?

  1. Replace the two links with one faster link to the original switch.
  2. Move one uplink to the other distribution switch.
  3. Reserve half of each uplink for critical traffic without moving either link.
  4. Bundle both existing uplinks while retaining their current endpoints.
  5. Increase the priority of the unused distribution switch in the gateway election.

Correct Answer: B

 

Correct Answer

Answer B is correct because the links then have separate switch failure domains. With the stated capacity and forwarding behavior already validated through either switch, one usable access path remains after either distribution switch fails.

Incorrect Answers

Answer A is incorrect because a faster single path may provide capacity but retains the switch failure dependency and removes link redundancy.

Answer C is incorrect because traffic allocation cannot preserve connectivity when both links lose their shared terminating switch.

Answer D is incorrect because aggregation can tolerate one link failure but both members still disappear when their common distribution switch fails.

Answer E is incorrect because gateway preference cannot provide an access-to-distribution link that is not physically present.

 

Question 13

Two distribution chassis each draw 1.5 kW under the stated operating load. Each chassis has two power supplies, either one capable of powering that chassis, with one supply on panel A and one on independent panel B. The normal total load is split equally between the panels. Each panel can continuously supply 2.4 kW and serves no other equipment. The design must survive loss of either panel without reducing the chassis load. Which assessment is correct?

  1. The design passes because the two panels provide 4.8 kW in total.
  2. Replace the chassis power supplies with higher-rated units while keeping both 2.4-kW panels.
  3. The design passes because each panel normally supplies only 1.5 kW.
  4. Raise only panel A to 3 kW and retain panel B at 2.4 kW.
  5. Each panel needs at least 3 kW of usable capacity to support the specified single-panel failure.

Correct Answer: E

 

Correct Answer

Answer E is correct because the surviving panel must supply both 1.5-kW chassis: 1.5 + 1.5 = 3 kW. Independent feeds remove the shared-panel dependency, but a 2.4-kW survivor is still 0.6 kW short for the stipulated load.

Incorrect Answers

Answer A is incorrect because adding both panel ratings evaluates normal installed capacity. The required failure removes one panel, leaving 2.4 kW rather than 4.8 kW for the 3-kW load.

Answer B is incorrect because each existing supply can already power its chassis. Larger supplies do not increase the 2.4-kW input capacity of the surviving panel, which is the stated limiting resource.

Answer C is incorrect because 1.5 kW is the normal share when both panels are available. After one fails, the other must supply the full 3 kW, so the normal operating load is not the acceptance value.

Answer D is incorrect because that would cover failure of panel B, but failure of panel A would still leave an undersized 2.4-kW source. The requirement includes loss of either panel, so either survivor needs sufficient usable capacity.

 

Question 14

A branch has six access switches, stable departmental boundaries, and an operations team experienced with its routed design. Its growth projection fits existing platform capacity. A fabric proposal offers useful automation but requires new controller, identity and troubleshooting skills. Which assessment should guide the decision?

  1. Approve deployment after a pilot demonstrates faster provisioning, then train the operations team.
  2. Retain the routed design solely to avoid purchasing a controller.
  3. Prioritize faster automated provisioning over the existing operating model.
  4. Compare the expected automation benefit with the deployment dependencies and ongoing operational capability.
  5. Select the fabric from its feature comparison and defer the operating model until rollout.

Correct Answer: D

 

Correct Answer

Answer D is correct because the existing design meets scale requirements, so adopting a fabric should be justified by operational benefits that outweigh its lifecycle complexity for this team.

Incorrect Answers

Answer A is incorrect because a provisioning demonstration establishes one benefit, but the decision also requires evidence that the team can sustain controller, identity and troubleshooting dependencies. Training and operating readiness must be part of the adoption assessment.

Answer B is incorrect because avoiding an initial purchase can matter, but the assessment must also weigh ongoing policy consistency and operational cost rather than use one expense as the entire decision.

Answer C is incorrect because provisioning speed is a potential benefit, but the stem reports stable requirements and new operating dependencies; speed alone does not establish a better lifecycle outcome.

Answer E is incorrect because the new controller, identity and troubleshooting dependencies affect whether the design is supportable; leaving that evaluation until rollout misses a decisive requirement.

 

Question 15

Three distribution blocks share one campus core. Each block currently requires a change to the same central policy whenever its local VLANs change. The core has spare capacity, but the business wants local maintenance to have a smaller blast radius. Which change is most appropriate?

  1. Move every building policy into one core access list.
  2. Move local routing-policy changes to their distribution modules.
  3. Extend all local VLANs through every distribution block.
  4. Increase core interface speed and leave the shared policy dependencies unchanged.
  5. Schedule all distribution changes in one simultaneous maintenance event.

Correct Answer: B

 

Correct Answer

Answer B is correct because the principal risk is the coupling of local changes to shared transport policy. Modular boundaries reduce that operational exposure without requiring more core bandwidth.

Incorrect Answers

Answer A is incorrect because consolidating the policy further preserves the same shared change dependency the business wants to reduce.

Answer C is incorrect because broader Layer 2 scope makes local changes less isolated and does not preserve the intended modularity.

Answer D is incorrect because capacity is not the constraint, and faster links do not reduce the scope of a central configuration error.

Answer E is incorrect because a common window may simplify scheduling but increases simultaneous exposure and does not create independent change boundaries.

 

Question 16

A modular gateway chassis has two functioning supervisors with synchronized state. Replacing its power enclosure requires shutting down the entire chassis. Hosts must retain their current default-gateway IP. A second independently powered gateway reaches both the host subnet and onward networks; the approved preparation can transfer ownership of the existing gateway address. Which design element should be established before the shutdown?

  1. Another standby supervisor inside the chassis being shut down.
  2. More forwarding capacity on the original gateway line cards.
  3. A longer host ARP cache lifetime for the original physical gateway address.
  4. A first-hop redundancy arrangement across the two independent gateway chassis.
  5. A faster state-synchronization link between the existing supervisors.

Correct Answer: D

 

Correct Answer

Answer D is correct because a shared gateway service on the separate surviving chassis can preserve the hosts’ configured gateway while the entire original chassis is unavailable.

Incorrect Answers

Answer A is incorrect because all internal supervisors lose service with the chassis, so adding one does not create an independent maintenance path.

Answer B is incorrect because additional capacity in the chassis does not provide a powered forwarding path during enclosure maintenance.

Answer C is incorrect because retaining an address mapping does not move that gateway service to a surviving device.

Answer E is incorrect because state synchronization helps supervisor transitions but cannot keep the chassis operating during its complete shutdown.

 

Question 17

A chassis with supported stateful switchover reports an active supervisor and a standby supervisor in a hot, synchronized state. During a planned active-supervisor removal, the line cards remain powered. Which behavior is the design specifically intended to improve?

  1. Routing-peer continuity based only on the standby supervisor being hot.
  2. A stateful control-role transfer to the prepared standby.
  3. Protection against a faulty policy deliberately synchronized to both supervisors.
  4. Availability during removal of power from the complete chassis.
  5. A forwarding-role transfer that restarts all powered line cards from the startup configuration.

Correct Answer: B

 

Correct Answer

Answer B is correct because SSO maintains relevant state and configuration on the standby so it can take over the active role; this directly addresses an active-supervisor transition.

Incorrect Answers

Answer A is incorrect because hot standby readiness supports the supervisor handoff, but routing restart behavior also depends on the applicable protocol and supported NSF or graceful-restart design. Readiness alone does not establish peer-state continuity.

Answer C is incorrect because synchronization can propagate a configuration error; SSO is not an independent policy-correctness check.

Answer D is incorrect because both supervisors and line cards share the chassis shutdown in that event, which requires a separate system-level path.

Answer E is incorrect because that describes a disruptive restart rather than the benefit of retaining supported state on a prepared standby. Powered line cards need not be treated as newly booting devices simply because the active supervisor changes.

 

Question 18

A building has two routed uplinks to separate core switches. Both optical cables pass through the same underground conduit. A single conduit cut is part of the required survivability test. Which THREE observations correctly evaluate the current design? Choose THREE.

  1. Separate core switches protect against a failure of one core endpoint.
  2. Equal-cost routing alone proves the two paths have independent physical risks.
  3. Faster routing convergence makes the shared conduit cut survivable.
  4. The shared conduit can remove both uplinks in one physical event.
  5. A physically diverse cable route is needed to remove this shared-path exposure.
  6. Using separate fiber pairs inside the existing conduit satisfies the conduit-cut requirement.

Correct Answers: A, D, E

 

Correct Answers

Answer A is correct because the two uplinks terminate on different devices, providing a surviving endpoint for that particular failure when the rest of the path remains available.

Answer D is correct because logical and device diversity do not eliminate the common cable route, which is the precise failure named in the test.

Answer E is correct because routing one uplink outside the affected conduit supplies a path that can survive the specified cut.

Incorrect Answers

Answer B is incorrect because equal route cost concerns forwarding preference and provides no evidence about shared ducts or facilities.

Answer C is incorrect because convergence can use only surviving paths; both uplinks are physically removed by the stipulated event.

Answer F is incorrect because fiber-pair diversity may help with a single strand fault, but separate pairs in the same cut conduit can still fail together. The stipulated risk requires a surviving physical route.

 

Question 19

A supervisor failover test preserves hardware forwarding to known destinations, but routing adjacencies must be re-established. The design team wants to minimize disruption while the new active supervisor restores routing state. Which assessment is most accurate?

  1. Evaluate NSF support and neighbor compatibility in addition to SSO.
  2. Enable a second FHRP group and assume the routing restart is eliminated.
  3. Conclude that any need to rebuild adjacencies proves SSO did not operate.
  4. Increase routing hold timers and treat delayed neighbor expiry as evidence of stateful routing restart.
  5. Accept the result once the local standby reports hot, without checking the routing peers.

Correct Answer: A

 

Correct Answer

Answer A is correct because SSO prepares the control-role handoff; NSF supports continued forwarding during routing restart. Neighbor behavior and platform support matter to that combined outcome.

Incorrect Answers

Answer B is incorrect because another virtual gateway group does not preserve the chassis routing adjacency state during the supervisor transition.

Answer C is incorrect because control-role takeover and protocol reconvergence are related but distinct; a successful SSO transition can still require routing peers to be restored.

Answer D is incorrect because longer timers can delay a failure declaration, but that is not evidence that peers support the required routing restart and state reconstruction. Those capabilities must be checked directly.

Answer E is incorrect because a ready standby verifies a local takeover prerequisite. It does not establish that neighboring routers support the restart behavior needed while routing state is rebuilt.

 

Question 20

A maintenance test transfers the active roles of both a redundant gateway pair and a separate Cisco ASA firewall pair. Afterward, forward and return traffic use the new active firewall, and new TCP connections succeed, but established TCP sessions are lost. Both firewalls have matching policy, but connection-state replication is disabled. Which design issue should the architect address?

  1. Shorten gateway failover timers to correct loss of established firewall sessions.
  2. Resynchronize the firewall access policy instead of replicating connection state.
  3. Provide supported firewall connection-state replication and validate TCP session continuity.
  4. Change route metrics so forward and return traffic use the same active firewall.
  5. Increase TCP idle timeouts on the new active firewall before repeating the test.

Correct Answer: C

 

Correct Answer

Answer C is correct because gateway recovery supplies reachability, but the new active firewall also needs the existing connection state. ASA stateful failover addresses supported TCP state; application continuity still needs verification in the actual design.

Incorrect Answers

Answer A is incorrect because faster gateway takeover may reduce reachability interruption, but the observed new connections already succeed. It does not supply missing TCP session records to the newly active firewall.

Answer B is incorrect because matching policy already determines which new connections are permitted. It does not populate the per-connection state needed to continue established sessions after the firewall role transfer.

Answer D is incorrect because asymmetric forwarding can affect stateful inspection, but the test already confirms a symmetric path through the new active firewall. Changing route preference does not address its absent connection state.

Answer E is incorrect because an idle timeout governs how long an existing connection record is retained. It cannot retain records that were never transferred to the new active firewall.

 

Question 21

A campus has aggregation switches A and B, edge routers R1 and R2, and separate providers P1 and P2. A connects only to R1/P1; B connects only to R2/P2. The campus can reach either aggregation switch. Capacity and routing behavior are validated for any surviving connected path. The requirement is to retain connectivity after any one aggregation-switch failure combined with loss of either provider. Which change closes the remaining gap?

  1. Connect each aggregation switch to both edge routers.
  2. Add a second parallel link from A to R1 and another from B to R2.
  3. Change routing metrics to prefer P1 and retain the existing attachments.
  4. Add redundant supervisors inside A and B without changing their edge attachments.
  5. Add an A-to-R2 link while leaving B connected only to R2.

Correct Answer: A

 

Correct Answer

Answer A is correct because the cross-connections let either surviving aggregation switch use either surviving provider. In the original design, loss of A plus P2, or B plus P1, removes both complete end-to-end paths.

Incorrect Answers

Answer B is incorrect because extra links preserve the same pairing. They cannot connect the surviving aggregation switch to the other provider when an opposite aggregation/provider combination fails.

Answer C is incorrect because preference affects selection among connected usable paths. It cannot create an A-to-R2 or B-to-R1 attachment when a paired path is broken by the specified combined failures.

Answer D is incorrect because supervisor redundancy addresses an internal control-module failure. It neither covers complete aggregation-switch loss nor changes the provider paths available to the surviving switch.

Answer E is incorrect because this covers loss of B with either provider, but loss of A together with P2 still leaves B unable to reach the surviving P1 path. Both required cross-connections matter.

 

Question 22

A campus is replacing an old gateway whose physical IP address is statically configured on thousands of endpoints. Two new gateways attach to those hosts and reach the server networks. The existing gateway IP can be retained during migration. Later replacement of either new gateway must trigger automatic takeover, with the same host-configured address and no manual address transfer; brief convergence is acceptable. Which architectural choice meets that requirement?

  1. Use a supported shared virtual gateway identity on the redundant gateway pair.
  2. Configure two physical default gateways on every endpoint and rely on host failover behavior.
  3. Assign different physical gateway addresses to endpoint groups and keep both routers active.
  4. Use the preferred physical router address and prepare a manual address-transfer runbook.
  5. Add equal-cost routes on the gateways but keep a nonredundant host gateway address.

Correct Answer: A

 

Correct Answer

Answer A is correct because the hosts depend on the logical gateway service rather than a particular physical router, allowing the forwarding role to move while the configured identity remains stable.

Incorrect Answers

Answer B is incorrect because this requires endpoint configuration and depends on host-specific behavior; a shared redundant first-hop identity meets the stated long-term constraint more directly.

Answer C is incorrect because splitting hosts between physical gateway identities distributes load but leaves each group tied to one gateway unless a redundant identity is separately provided.

Answer D is incorrect because the runbook could restore the address after operator intervention, but the requirement explicitly calls for automatic takeover without a manual transfer. It therefore fails a material constraint even if hosts keep the same configured IP.

Answer E is incorrect because route redundancy beyond a gateway does not independently preserve the host’s first-hop identity when that gateway disappears.

 

Question 23

During a controlled link failure, an application experiences a 1.4-second interruption. Logs show 0.9 seconds to detect the failure and 0.5 seconds to install the surviving path. Replacing the failed optic later takes 40 minutes, but traffic remains on the alternate path. Which measurement should be compared with a two-second failover objective?

  1. The 40-minute repair time plus both convergence intervals.
  2. The 40-minute optic replacement time.
  3. Only the 0.5-second path-installation interval.
  4. Only the 0.9-second failure-detection interval.
  5. The 1.4-second detection-plus-reconvergence interruption.

Correct Answer: E

 

Correct Answer

Answer E is correct because service returns after detection and path installation, so that observed interruption is the relevant failover measure; physical repair occurs later while service is already restored.

Incorrect Answers

Answer A is incorrect because adding a period during which traffic already uses the alternate path confuses restoration of redundancy with restoration of service.

Answer B is incorrect because that measures repair duration rather than the interruption experienced while the alternate path took over.

Answer C is incorrect because excluding detection understates the actual service interruption and could make an unacceptable failover appear compliant.

Answer D is incorrect because detection is not sufficient for forwarding recovery because installing the surviving path consumes another 0.5 seconds.

 

Question 24

Two laboratories configure SSO on the same supported chassis model. Lab A reports a hot standby with synchronized state; Lab B reports a standby still initializing and not ready for stateful takeover, although its configured redundancy mode is SSO. Both remove the active supervisor. Which comparison is justified before measuring the results?

  1. Matching running configurations are sufficient to treat both standby states as ready.
  2. The configured SSO mode is sufficient to treat the two tests as equivalent.
  3. Lab B cannot assume the same stateful recovery behavior until standby readiness is achieved.
  4. Lab A can omit application measurements once the standby reports hot.
  5. Average repeated Lab B results obtained during initialization to estimate ready-state recovery.

Correct Answer: C

 

Correct Answer

Answer C is correct because a prepared standby is a prerequisite for the SSO behavior being evaluated. The common hardware model does not make different readiness states equivalent.

Incorrect Answers

Answer A is incorrect because configuration agreement is only part of preparation. The explicitly initializing standby is not yet ready to assume the stateful control role.

Answer B is incorrect because configured mode records the intended redundancy behavior. It does not establish that the standby has reached the operational state required to provide that behavior.

Answer D is incorrect because readiness establishes a prerequisite for the takeover mechanism. It does not measure the application interruption or verify all protocol behavior after the transition.

Answer E is incorrect because repeating a test in an unready state measures that state, not the behavior of a prepared standby. Averaging cannot remove the operational-state difference between the laboratories.

 

Question 25

A planned maintenance event will remove one of two distribution chassis. Each currently carries 8 Gb/s of user traffic, and the survivor has 20 Gb/s of verified usable capacity for the combined traffic. Demand will not increase during the window, and forwarding paths can converge to the survivor. However, the only uplink to the DNS service needed during maintenance terminates on the chassis being removed. Which TWO decisions follow from this validation? Choose TWO.

  1. Rely on SSO inside the chassis that will be entirely powered off.
  2. Approve maintenance because the successful capacity check also validates DNS availability.
  3. Accept the supplied capacity check: the survivor has 4 Gb/s of headroom at the combined load.
  4. Increase the default gateway priority without checking service attachments.
  5. Require a surviving DNS attachment before approving the maintenance event.

Correct Answers: C, E

 

Correct Answers

Answer C is correct because the combined demand is 8 + 8 = 16 Gb/s. Against 20 Gb/s of verified usable capacity, that leaves 4 Gb/s of headroom, so capacity is not the unresolved blocker under the stated fixed-demand assumption.

Answer E is correct because the capacity check does not preserve a service whose only attachment will be removed. A surviving, verified DNS path is necessary for the service requirement during the window.

Incorrect Answers

Answer A is incorrect because an internal control-role handoff cannot retain the only DNS uplink after the whole chassis is removed.

Answer B is incorrect because 16 Gb/s fitting within 20 Gb/s establishes a forwarding-capacity result, not service reachability. The only DNS attachment is still lost in the proposed event.

Answer D is incorrect because a preferred gateway role does not create a surviving path to a service that is physically disconnected.

img