{"id":12916,"date":"2026-09-15T13:12:21","date_gmt":"2026-09-15T13:12:21","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=12916"},"modified":"2026-09-15T13:12:21","modified_gmt":"2026-09-15T13:12:21","slug":"cisco-ccie-350-401-practice-test-questions-and-exam-dumps-part11-q201-220","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccie-350-401-practice-test-questions-and-exam-dumps-part11-q201-220\/","title":{"rendered":"Cisco CCIE 350-401 Practice Test Questions and Exam Dumps Part11 Q201-220"},"content":{"rendered":"<h2><b>View Full <a href=\"https:\/\/www.examlabs.com\/350-401-exam-dumps\">Cisco 350-401 Exam Dumps<\/a> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 201<\/b><\/h3>\n<p><b>Which protocol is used to establish a secure neighbor relationship for BGP route exchange?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ICMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRE<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BGP uses TCP as its transport protocol and establishes peer sessions using TCP port 179. TCP provides reliable, connection-oriented delivery, which allows BGP routers to exchange routing information without requiring BGP itself to implement packet retransmission. Before exchanging routing updates, BGP peers establish a TCP connection and then use OPEN messages to negotiate session parameters. UDP, ICMP, and GRE are not the standard transport mechanisms for BGP. Understanding BGP&#8217;s TCP dependency is important when troubleshooting failed peering sessions and connectivity between neighboring autonomous systems.<\/span><\/p>\n<h3><b>Question 202<\/b><\/h3>\n<p><b>Which OSPF component is responsible for connecting different OSPF areas?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ASBR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Internal router<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ABR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Area Border Router (ABR) connects one OSPF area to another and maintains interfaces in multiple OSPF areas. ABRs play an important role in inter-area routing by generating Summary LSAs that advertise networks from one area into another. They can also perform route summarization at area boundaries, helping reduce routing information. A Designated Router manages adjacency relationships on certain multiaccess networks, while an ASBR introduces external routes into OSPF. An ABR is therefore specifically responsible for connecting and exchanging routing information between OSPF areas.<\/span><\/p>\n<h3><b>Question 203<\/b><\/h3>\n<p><b>Which command can be used to verify the status of interfaces and their assigned IP addresses on a Cisco router?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">show ip interface brief<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">show mac address-table<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">show vlan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">show spanning-tree<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">show ip interface brief<\/span><span style=\"font-weight: 400;\"> command provides a concise overview of interfaces, their assigned IP addresses, and their administrative and operational status. It is one of the most frequently used Cisco troubleshooting commands because it quickly identifies interfaces that are administratively down or operationally down. The command is useful for verifying whether an interface has the expected Layer 3 address and whether the interface is functioning. Other commands focus on Layer 2 MAC learning, VLAN information, or spanning-tree operation.<\/span><\/p>\n<h3><b>Question 204<\/b><\/h3>\n<p><b>Which BGP attribute is used to indicate how a route entered the BGP system?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local Preference<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Origin<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weight<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MED<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The BGP Origin attribute indicates how a route was introduced into BGP. Its values include IGP, EGP, and incomplete, with IGP generally preferred over EGP and incomplete during the relevant stage of BGP path selection. Routes introduced through commands such as network can receive an IGP origin, while redistributed routes may receive an incomplete origin. Origin is only one factor in the BGP decision process and is considered after several higher-priority attributes. Understanding origin values can help explain why one BGP path is selected over another.<\/span><\/p>\n<h3><b>Question 205<\/b><\/h3>\n<p><b>Which technology allows a Cisco switch to use multiple physical interfaces as one logical Layer 3 interface?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EtherChannel<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPAN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EtherChannel combines multiple physical interfaces into one logical port-channel interface. When configured as a Layer 3 EtherChannel, the logical port-channel can have an IP address and participate in routing as a single logical interface. This provides increased bandwidth and redundancy while simplifying routing configuration. Protocols such as LACP can dynamically negotiate the aggregation. VLANs provide Layer 2 segmentation, VRFs separate routing tables, and SPAN mirrors traffic for monitoring. EtherChannel is therefore the appropriate technology for logically combining multiple physical links.<\/span><\/p>\n<h3><b>Question 206<\/b><\/h3>\n<p><b>Which IPv6 prefix is reserved for link-local unicast addresses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FE80::\/10<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FF00::\/8<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">2000::\/3<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FC00::\/7<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The IPv6 prefix FE80::\/10 is reserved for link-local unicast addresses. Link-local addresses are automatically available on IPv6-enabled interfaces and are used for communication on the local network segment. They are essential for Neighbor Discovery and other local IPv6 operations. Routers do not normally forward link-local traffic between interfaces. FF00::\/8 is used for multicast, 2000::\/3 represents global unicast space, and FC00::\/7 is associated with unique local addresses. Link-local addressing is therefore fundamental to normal IPv6 operation.<\/span><\/p>\n<h3><b>Question 207<\/b><\/h3>\n<p><b>Which BGP attribute can be used to identify a group of routes and apply a common routing policy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MED<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Community<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weight<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Router ID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The BGP Community attribute allows routes to be grouped logically so that routing policies can be applied consistently. Communities are carried with BGP route advertisements and can represent characteristics such as customer type, geographic region, or preferred routing treatment. Administrators can configure policies that match specific community values and then modify or filter routes accordingly. Standard communities include well-known values such as no-export, while extended and large communities provide additional policy options. Communities are particularly useful in large networks where individual prefix-based policies would become difficult to manage.<\/span><\/p>\n<h3><b>Question 208<\/b><\/h3>\n<p><b>Which protocol is commonly used to provide automatic IPv4 address assignment to clients through a four-step exchange?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Dynamic Host Configuration Protocol (DHCP) can automatically assign IPv4 addressing information to clients. The traditional DHCP process is commonly described as DORA: Discover, Offer, Request, and Acknowledgment. The client initially broadcasts a Discover message, and a DHCP server responds with an Offer. The client then requests the offered configuration, and the server confirms the lease with an Acknowledgment. DHCP can provide an IP address, subnet mask, default gateway, DNS server information, and other options, reducing the need for manual configuration.<\/span><\/p>\n<h3><b>Question 209<\/b><\/h3>\n<p><b>Which Cisco feature allows a router to provide a backup default route with a higher administrative distance?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Floating static route<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Route reflector<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ECMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policy-based routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A floating static route is a static route configured with a higher administrative distance than the primary route. Because the floating route is less preferred, it normally remains unused while the primary route is available. If the primary route disappears from the routing table, the floating static route can become active and provide an alternate path. This technique is commonly used for simple WAN redundancy and Internet failover. Unlike ECMP, it does not normally distribute traffic across paths simultaneously; instead, it provides a standby route.<\/span><\/p>\n<h3><b>Question 210<\/b><\/h3>\n<p><b>Which OSPF packet is used to request specific missing LSAs from a neighboring router?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hello<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database Description<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Link-State Request<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Link-State Acknowledgment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The OSPF Link-State Request (LSR) packet is used when a router needs specific Link-State Advertisements from a neighbor during database synchronization. After comparing database information, a router can use an LSR to request LSAs that are missing or more recent on the neighboring device. The neighbor responds with Link-State Update packets containing the requested information. Hello packets discover and maintain neighbors, Database Description packets summarize database contents, and Link-State Acknowledgment packets confirm receipt of LSAs. LSR is therefore important during OSPF database synchronization.<\/span><\/p>\n<h3><b>Question 211<\/b><\/h3>\n<p><b>Which technology provides a virtual IP address that can be shared by multiple routers for gateway redundancy?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VXLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRE<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hot Standby Router Protocol (HSRP) provides first-hop gateway redundancy by allowing multiple routers to share a virtual IP address. End hosts use the virtual address as their default gateway rather than depending on the physical address of a single router. One router typically operates as active while another is standby. If the active router becomes unavailable, the standby router can assume the active role and continue forwarding traffic. This improves default-gateway availability without requiring changes to the host configurations.<\/span><\/p>\n<h3><b>Question 212<\/b><\/h3>\n<p><b>Which QoS mechanism determines the order in which packets are transmitted during congestion?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Classification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Marking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Policing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Queuing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">QoS queuing determines how packets are scheduled for transmission when network resources are congested. Different queuing mechanisms can prioritize certain traffic classes, allocate bandwidth, or provide fair access to the interface. For example, voice traffic may receive preferential treatment because it is sensitive to delay and jitter. Classification identifies traffic, marking assigns QoS values, and policing enforces traffic-rate limits. Queuing becomes particularly important when the offered traffic exceeds the available interface capacity and packets must compete for transmission resources.<\/span><\/p>\n<h3><b>Question 213<\/b><\/h3>\n<p><b>Which protocol is used to synchronize network device clocks with a centralized time source?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Syslog<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Network Time Protocol (NTP) synchronizes the clocks of network devices with reliable time sources. Accurate clock synchronization is important for troubleshooting, authentication, event correlation, certificate validation, and security investigations. Network administrators can configure devices to obtain time from trusted NTP servers and, in some designs, allow devices to provide time to downstream systems. Syslog records events but does not synchronize clocks. DHCP provides host configuration, and RADIUS provides AAA services. NTP is therefore the appropriate protocol for maintaining consistent time across network infrastructure.<\/span><\/p>\n<h3><b>Question 214<\/b><\/h3>\n<p><b>Which protocol allows an administrator to discover basic information about directly connected devices in a multivendor network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLDP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Link Layer Discovery Protocol (LLDP) is an open standard that allows network devices from different vendors to advertise and learn information about directly connected neighbors. Information can include device identity, interface details, capabilities, and other operational attributes. LLDP is particularly useful in multivendor environments because it is not restricted to Cisco devices. CDP provides similar neighbor-discovery functionality but is Cisco proprietary. VTP distributes VLAN information, while DTP is associated with Cisco trunk negotiation. LLDP is therefore the preferred standard-based neighbor-discovery protocol.<\/span><\/p>\n<h3><b>Question 215<\/b><\/h3>\n<p><b>Which routing protocol uses the DUAL algorithm to provide rapid, loop-free convergence?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">OSPF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RIP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">EIGRP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BGP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">EIGRP uses the Diffusing Update Algorithm (DUAL) to calculate loop-free paths and maintain feasible backup routes. DUAL allows EIGRP to identify successor and feasible successor routes, enabling rapid convergence when topology changes occur. When an appropriate feasible successor is available, EIGRP can use it without performing a full route recalculation. OSPF uses the SPF algorithm, RIP relies on hop count, and BGP uses path attributes and policy-based selection. DUAL is therefore a defining component of EIGRP&#8217;s routing operation.<\/span><\/p>\n<h3><b>Question 216<\/b><\/h3>\n<p><b>Which BGP attribute is generally used to influence how traffic enters an autonomous system through multiple links?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local Preference<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Weight<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MED<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Origin<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multi-Exit Discriminator (MED) can be used to influence how a neighboring autonomous system selects an entry point into an organization when multiple links exist between the networks. A lower MED is generally preferred when the relevant BGP comparison is made. MED is therefore commonly associated with influencing inbound traffic, while Local Preference and Weight are more closely associated with controlling outbound path selection. MED should be used with an understanding of the neighboring network&#8217;s policies because the remote autonomous system ultimately makes its own BGP decision.<\/span><\/p>\n<h3><b>Question 217<\/b><\/h3>\n<p><b>Which security feature uses a trusted database of IP-to-MAC bindings to protect against source address spoofing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IP Source Guard<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SPAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PortFast<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Root Guard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IP Source Guard helps prevent IP address spoofing on switch access ports by validating source IP information against trusted bindings. These bindings are commonly learned through DHCP snooping. When IP Source Guard is enabled, the switch can restrict traffic whose source IP address does not match the expected binding for the interface. This provides protection against hosts attempting to use unauthorized IP addresses. SPAN provides traffic monitoring, PortFast affects spanning-tree convergence, and Root Guard protects the STP topology. IP Source Guard specifically addresses source IP validation.<\/span><\/p>\n<h3><b>Question 218<\/b><\/h3>\n<p><b>Which protocol can provide encrypted authentication and command authorization for Cisco device administrators?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RADIUS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TACACS+<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">TACACS+ is widely used for centralized authentication and authorization of network-device administrators. It supports separation of authentication, authorization, and accounting and can provide detailed command-level authorization. This allows organizations to define what individual administrators are permitted to do after successfully authenticating. TACACS+ encrypts the body of the authentication communication and commonly operates using TCP. RADIUS is another AAA protocol but is frequently used for network-access authentication such as wireless or VPN access. TACACS+ is especially useful when granular device-administration controls are required.<\/span><\/p>\n<h3><b>Question 219<\/b><\/h3>\n<p><b>Which technology provides an overlay network that extends Layer 2 segments across a Layer 3 infrastructure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">STP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VXLAN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HSRP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VXLAN creates Layer 2 overlay networks across a Layer 3 IP underlay by encapsulating Ethernet frames within UDP packets. This allows Layer 2 segments to be extended across routed infrastructure without requiring the entire physical network to operate as one large Layer 2 domain. VXLAN uses a 24-bit VNI, providing a significantly larger logical segmentation space than traditional VLAN IDs. It is commonly deployed in data center architectures and can integrate with control-plane technologies such as BGP EVPN for scalable endpoint learning.<\/span><\/p>\n<h3><b>Question 220<\/b><\/h3>\n<p><b>Which network-management protocol provides a REST-style interface for interacting with YANG-modeled configuration and operational data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NETCONF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RESTCONF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TFTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">RESTCONF provides a REST-style interface for accessing and manipulating YANG-modeled network configuration and operational data. It commonly uses HTTP or HTTPS methods and can exchange structured formats such as JSON or XML. RESTCONF allows automation applications to interact with network devices using familiar web-based APIs while maintaining the structured data models defined by YANG. NETCONF provides similar model-driven management capabilities but uses a different protocol framework, commonly over SSH. SNMP and TFTP provide monitoring and file-transfer functions rather than REST-based configuration management.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco 350-401 Exam Dumps and Practice Test Dumps &nbsp; Question 201 Which protocol is used to establish a secure neighbor relationship for BGP route exchange? UDP ICMP TCP GRE Correct Answer: 3 Explanation BGP uses TCP as its transport protocol and establishes peer sessions using TCP port 179. TCP provides reliable, connection-oriented delivery, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12916"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=12916"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12916\/revisions"}],"predecessor-version":[{"id":12935,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/12916\/revisions\/12935"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=12916"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=12916"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=12916"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}