Cisco CCNP Enterprise 350-401 ENCOR Direct eBGP and Policy-Based Routing Practice Test
Topic 09 covers direct ebgp and policy-based routing for the Cisco Certified Specialist – Enterprise Core certification. These original practice questions apply the verified 350-401 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the Cisco 350-401 ENCOR Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.
Question 1
R1 is in AS 65010 and R2 is in AS 65020 on 192.0.2.0/30. R1 has `neighbor 192.0.2.2 remote-as 65020`; R2 has `neighbor 192.0.2.1 remote-as 65030`. IP connectivity works, but the BGP session never establishes. What is the most direct correction?
Correct Answer: A
Correct Answer
Answer A is correct because R2 must identify the AS of its configured neighbor, which is R1 AS 65010.
Incorrect Answers
Answer B is incorrect because that would tell R1 the neighbor is in its own AS, contrary to the stated R2 AS 65020.
Answer C is incorrect because the link is already directly connected and IP connectivity is confirmed.
Answer D is incorrect because timer tuning does not resolve a remote-AS mismatch during session establishment.
Answer E is incorrect because the stated design places R2 in 65020; changing the local AS would alter the intended topology rather than fix the neighbor expectation.
Question 2
R1 and R2 are directly connected on 198.51.100.8/30. R1 is 198.51.100.9 and R2 is 198.51.100.10. R1 is configured with `neighbor 198.51.100.11 remote-as 65100`, while R2 correctly points to 198.51.100.9. Which defect prevents the intended direct peering?
Correct Answer: C
Correct Answer
Answer C is correct because 198.51.100.11 is not the stated R2 interface address; the peer should be 198.51.100.10.
Incorrect Answers
Answer A is incorrect because direct interface addresses can be used for eBGP peering.
Answer B is incorrect because the broadcast address is not a peer endpoint.
Answer D is incorrect because a /30 provides two usable addresses and is common for point-to-point peering.
Answer E is incorrect because BGP neighbors are configured to peer addresses, not the subnet identifier.
Question 3
A ping from R1 to the directly connected R2 peer address succeeds, but `show bgp ipv4 unicast summary` shows the neighbor in Active and TCP/179 connection attempts reset. Which conclusion is best?
Correct Answer: C
Correct Answer
Answer C is correct because ICMP success proves some IP connectivity, not successful TCP/179 establishment or correct BGP parameters.
Incorrect Answers
Answer A is incorrect because ICMP operation does not prohibit direct eBGP. It does not satisfy the stem’s governing point: Separate IP reachability from successful BGP TCP session establishment.
Answer B is incorrect because many transport and peer configuration causes remain possible before the session is established.
Answer D is incorrect because peer-address reachability does not establish route advertisement or best-path eligibility.
Answer E is incorrect because ICMP reachability and a BGP TCP session are separate conditions.
Question 4
The two directly connected eBGP routers have matching AS numbers and neighbor addresses. `show running-config | section router bgp` shows the neighbor statement, but under `address-family ipv4` the neighbor is explicitly `shutdown`. What should be changed first?
Correct Answer: D
Correct Answer
Answer D is correct because an administratively shut neighbor cannot establish or exchange IPv4 routes in that address family.
Incorrect Answers
Answer A is incorrect because PBR is unrelated to activating a BGP neighbor.
Answer B is incorrect because BGP requires IP connectivity, not a Layer 2 trunk by definition.
Answer C is incorrect because route reflection addresses iBGP scaling and does not activate a direct eBGP neighbor.
Answer E is incorrect because local preference affects best-path choice after routes are learned, not an administratively disabled neighbor.
Question 5
A direct eBGP peer is not exchanging routes. Which TWO observations best separate a transport/session problem from an established session with no accepted prefixes? Choose TWO.
Correct Answers: A, C
Correct Answers
Answer A is correct because this points to transport/session establishment rather than route policy after establishment.
Answer C is correct because Established indicates the TCP/BGP session completed and shifts the investigation toward policy/advertisement if prefixes are missing.
Incorrect Answers
Answer B is incorrect because router-ID magnitude is not the primary distinction between transport failure and an established-but-empty session.
Answer D is incorrect because a default route does not by itself distinguish BGP session state from route-policy behavior.
Answer E is incorrect because default local preference does not tell whether the session has established.
Answer F is incorrect because that addressing choice is compatible with direct peering and does not identify the failure class.
Question 6
R1 has `network 10.50.0.0 mask 255.255.0.0` under BGP, but its routing table contains only 10.50.1.0/24 and 10.50.2.0/24. No 10.50.0.0/16 route exists. Why is the /16 not originated by that network statement?
Correct Answer: A
Correct Answer
Answer A is correct because the BGP network statement requires a matching route for the specified prefix and mask.
Incorrect Answers
Answer B is incorrect because PBR is not a prerequisite for BGP network origination.
Answer C is incorrect because the matching route can come from other valid local routing sources; it need not be directly connected.
Answer D is incorrect because more-specific routes do not inherently block a valid exact /16 if that /16 also exists.
Answer E is incorrect because BGP can carry private prefixes inside an enterprise; policy determines whether they should be propagated externally.
Question 7
R1 is Established with an eBGP peer. `show bgp ipv4 unicast 203.0.113.0/24` shows a valid locally originated route, and outbound policy permits it. The peer still does not show the prefix. Which verification most directly confirms whether R1 is actually advertising it to that neighbor?
Correct Answer: B
Correct Answer
Answer B is correct because neighbor-specific advertised-route evidence directly answers whether the prefix is being sent after policy.
Incorrect Answers
Answer A is incorrect because host ARP entries do not prove a BGP UPDATE was advertised.
Answer C is incorrect because spanning-tree information does not directly show BGP advertisements.
Answer D is incorrect because a healthy Established session makes route advertisement policy/state more direct evidence than generic link settings.
Answer E is incorrect because changing the route alters the test and does not verify the current advertisement.
Question 8
The BGP session is Established. R1 receives no IPv4 prefixes from R2. On R2, the neighbor exists globally, but under `address-family ipv4 unicast` the neighbor is not activated on a platform/configuration that requires explicit AF activation. Which fix addresses the stated condition?
Correct Answer: C
Correct Answer
Answer C is correct because route exchange for that AF requires the neighbor to be active in the address family.
Incorrect Answers
Answer A is incorrect because weight affects local best-path selection, not whether the AF sends routes.
Answer B is incorrect because router IDs should be unique; matching them is not the remedy.
Answer D is incorrect because the intended peers are in different ASes and the missing AF activation is already identified.
Answer E is incorrect because HSRP is unrelated to BGP AF activation. It does not satisfy the stem’s governing point: A configured neighbor can still fail to exchange an address family if that AF is not activated as required.
Question 9
R1 receives 198.18.10.0/24 from an eBGP neighbor and displays it in the BGP table, but the path is not installed in the IP routing table because its BGP next hop is unreachable. Which statement is correct?
Correct Answer: E
Correct Answer
Answer E is correct because BGP can retain a received path that is not eligible for best-path installation when its next hop cannot be resolved.
Incorrect Answers
Answer A is incorrect because eBGP-learned routes normally contain AS-path information. It does not satisfy the stem’s governing point: A received BGP path must be valid and have a reachable next hop before it can become usable in the RIB.
Answer B is incorrect because BGP path validity and best-path selection determine installation.
Answer C is incorrect because address purpose may matter operationally, but the stem explicitly identifies next-hop reachability as the installation issue.
Answer D is incorrect because PBR is not a prerequisite for normal BGP route installation.
Question 10
R1 learns a BGP path whose next hop is 192.0.2.6. The routing table has no route covering 192.0.2.6, although the BGP peer itself is reachable at 198.51.100.2. What should the engineer address first if that path is expected to become usable?
Correct Answer: D
Correct Answer
Answer D is correct because BGP path eligibility depends on recursive reachability of the path next hop, which can differ from the peer address.
Incorrect Answers
Answer A is incorrect because BGP next-hop resolution requires routing information; disabling forwarding optimization is not the fix.
Answer B is incorrect because PBR on data packets does not create control-plane reachability to a BGP next hop.
Answer C is incorrect because MED is not evaluated usefully if the path is invalid due to an unreachable next hop.
Answer E is incorrect because that would change the session type and does not solve the explicitly unreachable route next hop.
Question 11
A Cisco router has two otherwise equal valid BGP paths to the same prefix. Path A has weight 200 and Path B has weight 50. Which path is selected on this router?
Correct Answer: E
Correct Answer
Answer E is correct because weight is evaluated early and higher is preferred locally on the router.
Incorrect Answers
Answer A is incorrect because Cisco BGP prefers the higher weight value. It does not satisfy the stem’s governing point: When other validity conditions are met, higher Cisco weight is preferred locally.
Answer B is incorrect because neighbor address is a much later tie-breaker after weight.
Answer C is incorrect because AS-path length is considered after earlier attributes tie and shorter is normally preferred.
Answer D is incorrect because weight can influence local best-path selection for BGP paths.
Question 12
Two valid paths have equal weight and are otherwise eligible. Path A has LOCAL_PREF 150; Path B has LOCAL_PREF 100. Which path is preferred?
Correct Answer: E
Correct Answer
Answer E is correct because local preference expresses the AS-wide preference for outbound path selection and higher wins.
Incorrect Answers
Answer A is incorrect because community count is not a generic best-path criterion.
Answer B is incorrect because BGP prefers the higher local preference. It does not satisfy the stem’s governing point: With equal weight, higher local preference is preferred before later attributes.
Answer C is incorrect because local preference is considered before MED. It does not satisfy the stem’s governing point: With equal weight, higher local preference is preferred before later attributes.
Answer D is incorrect because neighbor IP is a later tie-breaker. It does not satisfy the stem’s governing point: With equal weight, higher local preference is preferred before later attributes.
Question 13
Two valid eBGP paths tie on weight, local preference, and local-origination status. Path A has AS path `65100 65200`; Path B has `65300 65400 65500`. No feature changes AS-path handling. Which path is preferred at the AS-path step?
Correct Answer: E
Correct Answer
Answer E is correct because after earlier attributes tie, the shorter AS-path length is normally preferred.
Incorrect Answers
Answer A is incorrect because the path length considers the sequence of AS hops under the normal rule.
Answer B is incorrect because BGP best-path selection normally prefers the shorter AS path, not the longer one.
Answer C is incorrect because MED is evaluated later under applicable comparison rules, after AS-path length.
Answer D is incorrect because the numeric magnitude of an AS number is not the AS-path preference rule.
Question 14
Two paths tie through AS-path length. Path A has origin IGP (`i`), while Path B has origin incomplete (`?`). Which path is preferred at the origin step?
Correct Answer: D
Correct Answer
Answer D is correct because the normal origin preference is IGP before EGP before incomplete.
Incorrect Answers
Answer A is incorrect because origin can participate in best-path selection after earlier attributes tie.
Answer B is incorrect because router ID is a later tie-breaker. It does not satisfy the stem’s governing point: BGP origin type can break a tie after earlier attributes, with IGP preferred over incomplete.
Answer C is incorrect because origin code is not prefix specificity and incomplete is less preferred.
Answer E is incorrect because lexical character ordering is not how BGP origin is compared.
Question 15
Two candidate routes to the same prefix tie through origin. Both were received from different peers in the same neighboring AS 65200. Path A MED is 50; Path B MED is 120. Default comparison behavior is assumed. Which path is preferred at the MED step?
Correct Answer: E
Correct Answer
Answer E is correct because under the stated same-neighboring-AS condition, lower MED is the preferred value.
Incorrect Answers
Answer A is incorrect because MED is normally lower-is-better. It does not satisfy the stem’s governing point: Compare MED only when the stated comparison conditions apply; lower MED is preferred.
Answer B is incorrect because equal-cost multipath requires additional configuration and matching conditions; differing MED values prevent a simple tie here.
Answer C is incorrect because local preference is evaluated earlier. It does not satisfy the stem’s governing point: Compare MED only when the stated comparison conditions apply; lower MED is preferred.
Answer D is incorrect because MED can influence BGP best path, subject to comparison rules.
Question 16
R1 has two BGP paths to 203.0.113.0/24. Path A has higher weight, but its next hop is unreachable. Path B has lower weight and a reachable next hop. Which path can participate in best-path selection?
Correct Answer: D
Correct Answer
Answer D is correct because path validity is checked before comparing normal preference attributes.
Incorrect Answers
Answer A is incorrect because invalid paths are not installed as usable best paths.
Answer B is incorrect because weight is compared among valid paths; it does not make an unreachable next hop valid.
Answer C is incorrect because neighbor IP is a late tie-breaker among valid paths.
Answer E is incorrect because BGP is designed to compare multiple candidate paths.
Question 17
A Cisco router compares two otherwise equal BGP paths. Path A is locally originated by a `network` statement; Path B is learned from an eBGP neighbor. Weight and local preference tie. Which path is preferred at the local-origination step?
Correct Answer: E
Correct Answer
Answer E is correct because local origination is considered before AS-path length when earlier attributes tie.
Incorrect Answers
Answer A is incorrect because IGP cost to BGP next hop is evaluated later in the decision process.
Answer B is incorrect because the local-origination comparison occurs before AS-path length under the stated tie.
Answer C is incorrect because local origination is a recognized preference step. It does not satisfy the stem’s governing point: Local origination is a best-path preference considered before several later attributes.
Answer D is incorrect because the eBGP-over-iBGP criterion is later; local origination is considered earlier.
Question 18
Two eBGP paths remain tied through the preceding criteria in the stated platform algorithm. They were received from peers with router IDs 10.0.0.9 and 10.0.0.5, and no route-reflector attributes apply. Which peer wins at the router-ID tie-break?
Correct Answer: A
Correct Answer
Answer A is correct because when the decision reaches the router-ID tie-break, the lower router ID is preferred.
Incorrect Answers
Answer B is incorrect because AS numeric magnitude is not a late tie-break rule.
Answer C is incorrect because the normal tie-break favors the lower, not higher, router ID.
Answer D is incorrect because BGP also uses router ID in late tie-breaking.
Answer E is incorrect because arrival order is not the specified tie-break in this scenario.
Question 19
R1 has two equal BGP paths after all normal best-path criteria relevant to the pair. Only one route is installed. The engineer expected both links to forward traffic. What distinction should be checked?
Correct Answer: A
Correct Answer
Answer A is correct because a tied best-path comparison does not automatically mean multiple paths are installed for forwarding.
Incorrect Answers
Answer B is incorrect because they are candidates for the same prefix, so prefix length does not explain single-path installation.
Answer C is incorrect because BGP ECMP does not require physical links to be bundled.
Answer D is incorrect because HSRP gateway election is unrelated to BGP multipath installation.
Answer E is incorrect because different AS numbers do not automatically enable multiple-path installation.
Question 20
R1 has two direct eBGP peers advertising the same prefix. The current best path is through Peer A. Peer A link fails; Peer B session remains Established and its path is valid. What should the engineer verify first after convergence?
Correct Answer: E
Correct Answer
Answer E is correct because the surviving valid path should become eligible, but verification should confirm control-plane and forwarding installation.
Incorrect Answers
Answer A is incorrect because the operational requirement is surviving route selection, not preserving an attribute for a withdrawn path.
Answer B is incorrect because that would oppose convergence to the surviving peer.
Answer C is incorrect because AS identity should not be dynamically changed to perform ordinary path failover.
Answer D is incorrect because a failed direct link should not be expected to retain the same established session.
Question 21
A router normally sends all internet traffic to ISP-A. Finance clients in 10.20.20.0/24 must instead use ISP-B for outbound traffic while all other sources follow normal routing. Which feature most directly expresses this requirement on the ingress interface?
Correct Answer: E
Correct Answer
Answer E is correct because PBR can choose forwarding based on source/policy criteria rather than only the destination route.
Incorrect Answers
Answer A is incorrect because advertising the source prefix does not make transit packets use a different next hop.
Answer B is incorrect because gateway redundancy does not provide source-sensitive upstream forwarding by itself.
Answer C is incorrect because OSPF cost changes destination routing and does not directly select a path based on packet source subnet.
Answer D is incorrect because link-bundle hashing does not select a distinct routed next hop based on policy.
Question 22
A branch has two WAN exits. Traffic from a backup server source address must use the high-bandwidth circuit, while interactive users continue using the routing table best path. What PBR design element is decisive?
Correct Answer: C
Correct Answer
Answer C is correct because source-sensitive route-map matching expresses the stated policy without changing all destination routes.
Incorrect Answers
Answer A is incorrect because VRRP priority elects a gateway and does not classify transit traffic by source.
Answer B is incorrect because source prefix advertisement does not directly select an egress path for its outbound packets.
Answer D is incorrect because that affects all traffic rather than only the stated source class.
Answer E is incorrect because address translation does not by itself choose the required WAN path.
Question 23
An ingress interface has PBR route-map `BRANCH permit 10` matching ACL 110. ACL 110 permits source 10.30.0.0/16 to destination any. The route-map sets next-hop 192.0.2.1. A packet from 10.30.5.10 to 8.8.8.8 arrives on that interface. Which behavior is expected if the next hop is usable?
Correct Answer: B
Correct Answer
Answer B is correct because the ACL match selects the packet and the set action supplies the PBR next hop.
Incorrect Answers
Answer A is incorrect because PBR route maps applied to interfaces control forwarding, not BGP advertisement by themselves.
Answer C is incorrect because set ip next-hop changes forwarding, not the packet source address.
Answer D is incorrect because the ACL matches the source 10.30.0.0/16 with destination any.
Answer E is incorrect because a permit match in the referenced ACL selects traffic for the route-map statement.
Question 24
A PBR route map is correctly defined but is applied with `ip policy route-map BRANCH` on Gi0/2. The target client traffic enters the router on Gi0/1 and exits Gi0/2. Why is the traffic not policy-routed?
Correct Answer: A
Correct Answer
Answer A is correct because the route map must be applied on the interface where the target transit packets enter.
Incorrect Answers
Answer B is incorrect because the forwarding decision must occur before egress. It does not satisfy the stem’s governing point: Apply interface PBR where the target transit traffic enters the router.
Answer C is incorrect because interface PBR is applied to arriving traffic. It does not satisfy the stem’s governing point: Apply interface PBR where the target transit traffic enters the router.
Answer D is incorrect because only the relevant ingress interface needs the policy for those transit packets.
Answer E is incorrect because this is a packet-forwarding policy, not a BGP route policy.
Question 25
Which TWO statements correctly distinguish PBR from BGP route advertisement? Choose TWO.
Correct Answers: C, E
Correct Answers
Answer C is correct because BGP route policy and packet-by-packet PBR operate at different control/forwarding scopes.
Answer E is correct because PBR is a forwarding-policy mechanism for matched traffic.
Incorrect Answers
Answer A is incorrect because PBR can coexist with routes from many sources and does not require BGP.
Answer B is incorrect because BGP-selected routes can absolutely influence normal destination-based forwarding.
Answer D is incorrect because local preference is a route-selection attribute, not source NAT.
Answer F is incorrect because an interface PBR route map does not become a BGP advertisement policy automatically.
Question 26
An interface PBR route map has one permit sequence matching source 10.10.0.0/16. A packet from 10.20.5.5 does not match any route-map sequence. What normally happens to that unmatched transit packet?
Correct Answer: D
Correct Answer
Answer D is correct because traffic not policy-routed by the route map proceeds through the normal routing decision.
Incorrect Answers
Answer A is incorrect because the route-map nonmatch in interface PBR does not mean the packet is automatically discarded; it falls back to normal routing.
Answer B is incorrect because packet forwarding and route advertisement are separate. It does not satisfy the stem’s governing point: Unmatched interface-PBR traffic normally continues with the ordinary routing table.
Answer C is incorrect because nonmatching transit traffic remains transit traffic. It does not satisfy the stem’s governing point: Unmatched interface-PBR traffic normally continues with the ordinary routing table.
Answer E is incorrect because set actions apply only to matching permit policy entries.
Question 27
A route map uses `set ip next-hop 192.0.2.9`. The next hop is currently unusable and there is a valid normal route to the destination. Which statement is safest for an exam scenario?
Correct Answer: B
Correct Answer
Answer B is correct because PBR next-hop actions still depend on usable forwarding resolution and exact set-command semantics; the route map does not manufacture a working adjacency.
Incorrect Answers
Answer A is incorrect because a configured address does not make an unusable next hop forwardable.
Answer C is incorrect because BGP AS configuration is unrelated to automatic PBR next-hop repair.
Answer D is incorrect because PBR does not create interface addressing. It does not satisfy the stem’s governing point: A PBR set action does not create underlying next-hop reachability; interpret fallback according to the actual command/platform behavior.
Answer E is incorrect because normal routing information remains present even when PBR is configured.
Question 28
A router has `ip policy route-map BRANCH` on an ingress LAN interface. A locally generated ping sourced by the router itself does not follow the policy even though its source address matches the route-map ACL. Why?
Correct Answer: B
Correct Answer
Answer B is correct because local-origin packets do not enter through the interface policy path and use `ip local policy route-map` when local PBR is required.
Incorrect Answers
Answer A is incorrect because HSRP is unrelated to local PBR. It does not satisfy the stem’s governing point: Interface PBR and local PBR apply to different packet origins.
Answer C is incorrect because locally generated packets use the routing/forwarding system and are not inherently forced to BGP.
Answer D is incorrect because PBR ACLs can classify source and destination information.
Answer E is incorrect because PBR can influence IP traffic; the issue is local generation versus interface ingress.
Question 29
PBR sends outbound traffic from an application subnet over ISP-B, but return traffic from the internet continues entering through ISP-A because external routing was not changed. A stateful firewall on each edge rejects many sessions. What design issue does this illustrate?
Correct Answer: D
Correct Answer
Answer D is correct because the outbound policy does not automatically control how remote networks return traffic.
Incorrect Answers
Answer A is incorrect because interface PBR does not rewrite external BGP policy by itself.
Answer B is incorrect because the stem directly describes asymmetric edge selection. It does not satisfy the stem’s governing point: Evaluate reverse-path and stateful-flow consequences when PBR deliberately overrides normal outbound routing.
Answer C is incorrect because stateful inspection can be affected when opposite directions traverse different state tables.
Answer E is incorrect because removing routing does not solve the policy/return-path design problem.
Question 30
A branch uses PBR to send selected traffic to WAN Router B. Router B has no route toward the ultimate destination network. Which statement is correct?
Correct Answer: B
Correct Answer
Answer B is correct because PBR selects a next hop for matched packets but does not install end-to-end routes on other routers.
Incorrect Answers
Answer A is incorrect because a next-hop decision is only one stage; the downstream router must continue forwarding.
Answer C is incorrect because PBR and routing protocols can operate together. It does not satisfy the stem’s governing point: Policy routing chooses a forwarding next hop but does not replace downstream routing reachability.
Answer D is incorrect because PBR does not distribute routes. It does not satisfy the stem’s governing point: Policy routing chooses a forwarding next hop but does not replace downstream routing reachability.
Answer E is incorrect because ordinary PBR is not an overlay tunnel mechanism.
Popular posts
Recent Posts
