{"id":23212,"date":"2026-09-26T12:16:45","date_gmt":"2026-09-26T12:16:45","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23212"},"modified":"2026-09-26T12:16:45","modified_gmt":"2026-09-26T12:16:45","slug":"cisco-ccnp-enterprise-300-440-practice-test-questions-and-exam-dumps-part-7-q121-140","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-enterprise-300-440-practice-test-questions-and-exam-dumps-part-7-q121-140\/","title":{"rendered":"Cisco CCNP Enterprise 300-440 Practice Test Questions and Exam Dumps Part 7 Q121-140"},"content":{"rendered":"<h1><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-440-exam-dumps\"><b>Cisco CCNP Enterprise 300-440 Exam Dumps <\/b><\/a><b>\u00a0and Practice Test Dumps<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><b>Question 121. A company needs to connect its enterprise network to a cloud provider and requires predictable bandwidth with minimal dependence on Internet conditions. Which connectivity characteristic best addresses this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dynamic DNS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Shared public connectivity without SLA<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dedicated connectivity with defined service commitments<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Best-effort Internet access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Dedicated connectivity with defined service commitments<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When an organization requires predictable bandwidth and consistent service characteristics, dedicated connectivity with defined service commitments is generally more appropriate than best-effort Internet access. A dedicated connection can provide a more controlled path between the enterprise and cloud environment, while an SLA can establish measurable expectations for availability and performance. Internet VPN connectivity may still be suitable for many workloads, particularly where cost and flexibility are priorities, but it can experience variable Internet-path conditions. The final choice should be based on application requirements, resiliency, cost, and provider capabilities.<\/span><\/p>\n<p><b>Question 122. An engineer configures an IPsec cloud connection, but traffic from the enterprise LAN does not enter the tunnel. The security association is established. Which configuration should be checked next?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic selectors and encryption-domain definitions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NTP server configuration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Switch spanning-tree priority<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Syslog severity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Traffic selectors and encryption-domain definitions<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An established IPsec security association indicates that the security negotiation has completed, but traffic can still fail to match the policies that determine what should be encrypted. Traffic selectors, crypto ACLs, or equivalent encryption-domain definitions should therefore be verified. The local and remote networks must correspond correctly to the intended tunnel policy. NTP, spanning-tree, and syslog settings do not normally determine whether enterprise application traffic matches an IPsec encryption policy. This distinction between control-plane tunnel establishment and data-plane traffic matching is important when troubleshooting IPsec connectivity.<\/span><\/p>\n<p><b>Question 123. A cloud provider advertises several prefixes through BGP, but the enterprise wants to accept only prefixes belonging to the provider&#8217;s documented cloud address range. Which mechanism is appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF passive-interface configuration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP snooping<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An inbound BGP prefix filter<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> STP root guard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. An inbound BGP prefix filter<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An inbound BGP prefix filter can restrict which routes are accepted from a cloud provider. A prefix list, route policy, or equivalent BGP filtering mechanism can permit the expected cloud prefixes while rejecting unexpected routes. This helps prevent accidental route propagation and keeps the enterprise routing table aligned with the intended connectivity design. OSPF passive interfaces, DHCP snooping, and STP root guard serve different functions and do not provide BGP route filtering. The exact syntax depends on the Cisco IOS XE release and the routing policy structure.<\/span><\/p>\n<p><b>Question 124. A cloud-connected enterprise router has two valid routes to the same destination. One route has a longer prefix length than the other. Which route-selection principle is applied first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Administrative distance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP MED<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF cost<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Longest-prefix match<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Longest-prefix match<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">For IP forwarding, the router first selects the route with the longest matching prefix. A more specific route therefore takes precedence over a less specific route, even when the less specific route may have been learned through a different routing protocol. Administrative distance becomes relevant when comparing routes to the same destination prefix learned from different sources. BGP attributes and OSPF cost are considered within their respective routing-protocol processes. Understanding longest-prefix matching is fundamental when troubleshooting unexpected forwarding toward cloud networks.<\/span><\/p>\n<p><b>Question 125. An enterprise uses a private cloud connection as the primary path and an IPsec VPN over the Internet as backup. Which design characteristic should be verified before deployment?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the routing policy clearly establishes primary and backup paths<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether both paths have the same IP address<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether both paths use identical interface descriptions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether DNS uses the same TTL<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Whether the routing policy clearly establishes primary and backup paths<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A primary-and-backup design requires explicit routing behavior so that the private connection is preferred during normal operation while the VPN becomes usable when the primary path fails. The engineer should verify route preference, failure detection, tracking, and convergence behavior. Merely having two physical or logical connections does not guarantee correct failover. The paths do not need identical interface descriptions, DNS settings, or IP addresses. The important design objective is predictable route selection and automated transition between the primary and backup connectivity options.<\/span><\/p>\n<p><b>Question 126. A company experiences intermittent cloud application failures only when traffic traverses one WAN provider. Testing shows that the provider path has excessive packet loss. Which cloud-connectivity requirement is directly affected?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> VLAN naming<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MAC address learning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application availability and performance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Device inventory labeling<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Application availability and performance<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The scenario describes a direct impact on application performance and potentially availability because excessive packet loss can cause retransmissions, reduced throughput, timeouts, and application failures. Provider path quality is therefore an important factor when evaluating cloud connectivity against application requirements. VLAN names, MAC learning, and inventory labels do not determine whether a WAN path meets application performance objectives. Engineers should measure relevant service characteristics such as loss, latency, jitter where applicable, and availability when evaluating cloud connectivity.<\/span><\/p>\n<p><b>Question 127. A network architect wants branch users to reach SaaS applications directly over the local Internet connection while maintaining centralized control over application-aware forwarding decisions. Which technology should be evaluated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> HSRP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cisco Catalyst SD-WAN<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> STP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> CDP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Cisco Catalyst SD-WAN<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco Catalyst SD-WAN provides centralized policy and application-aware networking capabilities that can help organizations determine how application traffic should use available WAN transports. For suitable SaaS applications, SD-WAN can support direct Internet connectivity and path optimization rather than requiring all traffic to traverse a central data center. STP provides Layer 2 loop prevention, CDP provides neighbor discovery, and HSRP provides first-hop gateway redundancy. None of those technologies provides the centralized application-aware WAN policy capabilities described in the scenario.<\/span><\/p>\n<p><b>Question 128. A cloud BGP neighbor is reachable, but the BGP session repeatedly resets after several minutes. Which information is most useful for identifying the cause?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The router&#8217;s console baud rate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The access point&#8217;s SSID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The switch&#8217;s VLAN database<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP neighbor status, timers, logs, and TCP connectivity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. BGP neighbor status, timers, logs, and TCP connectivity<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeated BGP session resets require examination of the control-plane relationship between the two peers. Neighbor state information, BGP timers, system logs, TCP connectivity, interface stability, and potentially routing-policy or authentication configuration can reveal why the session is being terminated. A reachable peer does not necessarily guarantee a stable BGP session. VLAN databases, wireless SSIDs, and console baud rates are unrelated to the operation of the BGP TCP session. Troubleshooting should identify whether the reset originates from transport instability, timer expiration, configuration mismatch, or another control-plane condition.<\/span><\/p>\n<p><b>Question 129. An enterprise wants cloud routes learned through BGP to be prevented from becoming transit routes for unrelated external networks. What should the architect emphasize?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing all route policies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Explicit route filtering and controlled advertisements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Advertising every learned prefix<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Unrestricted route redistribution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Explicit route filtering and controlled advertisements<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud connectivity should normally advertise and accept only the routes required for the intended communication model. Explicit route filtering helps prevent unintended transit routing, excessive prefix propagation, and accidental exposure of networks. Both inbound and outbound policies may be necessary depending on the design. Unrestricted redistribution or advertising every learned prefix can create unnecessary dependencies and security or routing risks. Removing route policies would also reduce control over the routing domain. Prefix lists, route policies, and appropriate BGP attributes can be combined to implement the required routing behavior.<\/span><\/p>\n<p><b>Question 130. An engineer must determine whether a cloud IPsec tunnel is actually carrying application traffic. Which observation provides the strongest evidence?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increasing encrypted and decrypted packet or byte counters<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A configured IKE policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A successful DNS lookup<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A configured tunnel interface description<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Increasing encrypted and decrypted packet or byte counters<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPsec counters provide direct evidence that packets are being processed by the encryption and decryption mechanisms. If application traffic is generated and the relevant counters increase, the tunnel is actively processing data-plane traffic. A configured IKE policy only describes negotiation parameters, while a tunnel description is administrative information. DNS resolution can confirm name resolution but does not prove that application packets are traversing the IPsec tunnel. When troubleshooting a seemingly operational VPN, comparing counters before and after generating test traffic can be particularly useful.<\/span><\/p>\n<p><b>Question 131. A cloud provider requires the enterprise to use OSPF for route exchange over a private cloud connection. Which OSPF characteristic should be considered when integrating it with the enterprise routing design?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP MED<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP lease duration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Area boundaries and route summarization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ethernet MAC address aging<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Area boundaries and route summarization<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The technically relevant OSPF considerations in such a design include areas, adjacencies, network types, costs, authentication where applicable, summarization, and route filtering. DHCP lease duration does not control OSPF route exchange. BGP MED applies to BGP path selection, while MAC address aging is a Layer 2 switching behavior. When integrating cloud connectivity with OSPF, engineers should ensure that the cloud-facing adjacency and area design align with the enterprise routing architecture and that routes are propagated only as intended.<\/span><\/p>\n<p><b>Question 132. An organization has a compliance requirement that cloud traffic must remain on private connectivity and must not use a public Internet path during normal operation. Which requirement should be reflected in the design?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removal of all routing policies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Explicit path-selection policy that prefers and enforces private connectivity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet breakout for all cloud traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Unrestricted default-route advertisement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Explicit path-selection policy that prefers and enforces private connectivity<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Compliance requirements should be translated into explicit network design and policy controls. If cloud traffic must remain on private connectivity, the architecture should ensure that routing and security policies direct the required traffic through approved private paths and do not unintentionally permit Internet fallback. Simply preferring a private route may not be sufficient if compliance prohibits public-path use altogether; appropriate filtering and policy controls may also be required. Unrestricted Internet breakout or broad default-route advertisements can undermine the requirement.<\/span><\/p>\n<p><b>Question 133. A cloud-connected router advertises an enterprise summary route, but some addresses within that summary are not actually reachable. What potential issue should the engineer consider?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec cannot encrypt summarized prefixes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF cannot advertise aggregate routes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route summarization may create a blackhole for nonexistent or unavailable more-specific destinations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP always rejects summary routes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Route summarization may create a blackhole for nonexistent or unavailable more-specific destinations<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A summary route represents a larger address block and can attract traffic for addresses that do not have an active more-specific route. If the summarizing router does not have an appropriate forwarding or discard strategy, traffic toward unavailable addresses can be misdirected or blackholed. Summarization is supported by routing protocols and does not inherently prevent IPsec from carrying traffic for summarized networks. The architect should ensure that the summary accurately represents reachable address space and understand how traffic to unused addresses will be handled.<\/span><\/p>\n<p><b>Question 134. An engineer notices that a cloud application&#8217;s traffic takes the Internet path even though a private cloud connection is operational. Which item should be checked first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The switch&#8217;s MAC address table<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The device&#8217;s login banner<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The console line password<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application-aware routing and path-selection policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Application-aware routing and path-selection policy<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The actual issue described is primarily related to route or application policy determining which transport the traffic uses. Therefore, application-aware routing, route preference, and policy configuration should be examined rather than unrelated Layer 2 or management information. A MAC address table does not determine the preferred Layer 3 WAN transport for an application. In an SD-WAN environment, the engineer should inspect the relevant application policy, SLA conditions, available transports, and routing decisions to understand why Internet connectivity is being selected.<\/span><\/p>\n<p><b>Question 135. A company wants to ensure that a cloud route learned from one provider is not redistributed into a second provider&#8217;s routing domain. Which approach is appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Use route filtering at the redistribution boundary<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable all BGP sessions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove all routing policies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Advertise all routes to both providers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Use route filtering at the redistribution boundary<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route filtering at redistribution boundaries allows an organization to control which prefixes are permitted to move between routing domains or providers. This is particularly important when multiple providers or routing protocols are involved because unrestricted redistribution can unintentionally create transit paths or routing loops. Prefix lists, route policies, tags, and other policy mechanisms can be used according to the routing architecture. Disabling all BGP sessions would remove connectivity rather than selectively controlling route propagation.<\/span><\/p>\n<p><b>Question 136. A cloud VPN design uses multiple IPsec tunnels for redundancy. During testing, both tunnels carry traffic simultaneously when the intention was to use one as backup. What should be reviewed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> NTP authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route preference and failover policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Interface descriptions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Route preference and failover policy<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If two redundant tunnels are forwarding traffic simultaneously when one should be primary and the other backup, the routing design may not establish the intended preference. The engineer should review route metrics, administrative distance, tracking, routing policy, and any load-sharing mechanisms that could cause both paths to be selected. DNS, interface descriptions, and NTP authentication do not normally determine which IPsec path carries routed traffic. The desired operational model\u2014active\/standby or active\/active\u2014must be explicitly reflected in the routing design.<\/span><\/p>\n<p><b>Question 137. A cloud application requires high availability, but both enterprise connectivity paths terminate through the same physical provider facility. Which design concern remains?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP router ID length<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Excessive DNS TTL<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Lack of physical-path diversity<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Lack of physical-path diversity<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The scenario contains a physical resiliency concern: two logical or provider paths that share the same physical facility can be affected by the same facility failure. True high availability requires consideration of common failure domains, not simply the number of logical connections. Independent facilities, diverse physical routes, or appropriately separated provider infrastructure may be required depending on the application&#8217;s availability objective. DNS TTL and BGP router ID characteristics do not address the shared physical failure domain described in the scenario.<\/span><\/p>\n<p><b>Question 138. A network engineer wants to verify that a cloud BGP neighbor is advertising a particular prefix before investigating local route selection. Which information should be examined?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The access-layer STP topology<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The router&#8217;s NTP configuration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The local switch&#8217;s ARP aging timer<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The received BGP routes from the neighbor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The received BGP routes from the neighbor<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">To verify whether a BGP neighbor is advertising a particular prefix, the engineer should inspect the BGP routes received from that neighbor. This distinguishes a remote advertisement problem from a local route-selection or policy problem. If the prefix is absent from received BGP information, attention should shift toward the neighbor&#8217;s advertisement policy, route availability, or session behavior. ARP aging, NTP, and STP do not provide information about which prefixes a BGP neighbor is advertising.<\/span><\/p>\n<p><b>Question 139. A company uses SD-WAN policies to select paths for cloud applications based on performance. One WAN circuit becomes unavailable. What should the network do if a qualified alternate transport is configured?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Select the alternate transport according to the configured policy and SLA conditions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Continue forwarding packets to the failed transport indefinitely<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove the cloud routes permanently<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable all application policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Select the alternate transport according to the configured policy and SLA conditions<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An SD-WAN design with application-aware path selection should be able to use an alternate qualified transport when the preferred path becomes unavailable, provided that the policy and SLA configuration permit the alternate path. The decision can depend on transport availability and measured performance against configured thresholds. The objective is controlled convergence rather than permanently removing routes or disabling policies. Exact behavior depends on the configured Catalyst SD-WAN architecture and policy, but the alternate path must be available and eligible for selection.<\/span><\/p>\n<p><b>Question 140. During a cloud-connectivity incident, users can reach the cloud gateway but cannot reach a specific application subnet. The cloud gateway has a route toward the enterprise, but the enterprise lacks a route back to that application subnet. What is the most likely issue?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Incorrect DNS TTL<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Missing return-path routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Excessive STP convergence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Incorrect NTP stratum<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Missing return-path routing<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Successful reachability to a gateway does not prove that the complete end-to-end route exists. If the enterprise lacks a route back to the application&#8217;s subnet, return traffic cannot reach the originating users, resulting in an asymmetric or incomplete forwarding path. The engineer should inspect the enterprise routing table, cloud route advertisements, static routes, BGP or OSPF policies, and any relevant route filtering. DNS, STP, and NTP settings do not explain the missing Layer 3 return path described in the scenario.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Enterprise 300-440 Exam Dumps \u00a0and Practice Test Dumps &nbsp; Question 121. A company needs to connect its enterprise network to a cloud provider and requires predictable bandwidth with minimal dependence on Internet conditions. Which connectivity characteristic best addresses this requirement? Dynamic DNS Shared public connectivity without SLA Dedicated connectivity with defined [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23212"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23212"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23212\/revisions"}],"predecessor-version":[{"id":23213,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23212\/revisions\/23213"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}