{"id":23234,"date":"2026-09-26T12:20:36","date_gmt":"2026-09-26T12:20:36","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23234"},"modified":"2026-09-26T12:20:36","modified_gmt":"2026-09-26T12:20:36","slug":"cisco-ccnp-enterprise-300-440-practice-test-questions-and-exam-dumps-part-18-q341-360","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-enterprise-300-440-practice-test-questions-and-exam-dumps-part-18-q341-360\/","title":{"rendered":"Cisco CCNP Enterprise 300-440 Practice Test Questions and Exam Dumps Part 18 Q341-360"},"content":{"rendered":"<h1><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-440-exam-dumps\"><b>Cisco CCNP Enterprise 300-440 Exam Dumps <\/b><\/a><b>\u00a0and Practice Test Dumps<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><b>Question 341. An enterprise needs to connect a private data center to a cloud environment while keeping traffic isolated from the public Internet. Which connectivity characteristic is most relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Public DNS resolution<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Private connectivity with appropriate security controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increased OSPF hello frequency<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Larger DNS records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Private connectivity with appropriate security controls<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Private cloud connectivity is appropriate when an organization requires traffic to remain on controlled private paths rather than traversing the public Internet. Depending on the provider and architecture, this can involve dedicated connectivity, private virtual connections, or encrypted tunnels combined with appropriate routing and security controls. The design should evaluate isolation, bandwidth, resiliency, compliance, and security requirements. DNS configuration and OSPF hello frequency do not establish private connectivity. Even when a private circuit is used, organizations should still define routing policies and security controls to restrict which enterprise and cloud networks can communicate.<\/span><\/p>\n<p><b>Question 342. A cloud-connected enterprise has two eBGP sessions to different cloud edge routers. The administrator wants one session to carry normal traffic while the other remains available as a backup. Which policy can influence outbound path selection?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS TTL<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF area type<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec transform set<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local preference<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Local preference<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Local preference is commonly used within an autonomous system to influence outbound BGP path selection. By assigning a higher local-preference value to the preferred cloud path, the enterprise can cause internal routers to favor that path while retaining the second path as an alternative. DNS TTL, OSPF area type, and IPsec transform settings do not provide the same BGP outbound-path selection function. The engineer should also verify that the backup path is operational and that failure detection and routing convergence are appropriate for the application&#8217;s requirements.<\/span><\/p>\n<p><b>Question 343. A network engineer discovers that a cloud prefix is being learned through BGP but is not present in the enterprise routing table. Which two areas should be examined?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP path selection and local routing policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS forwarding and DHCP scope<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec encryption algorithm and NTP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Interface naming and console speed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. BGP path selection and local routing policy<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A BGP route can be received but still fail to become the active routing-table entry because of local policy, route selection, next-hop reachability, or competition from another route. The engineer should inspect the BGP route details, selection status, administrative distance, next-hop reachability, and applicable policies. DNS, DHCP, interface naming, and console settings do not directly determine whether a received BGP prefix is installed. IPsec parameters may matter for tunnel connectivity, but once the route is known to be received, routing-policy and path-selection analysis is the more direct troubleshooting area.<\/span><\/p>\n<p><b>Question 344. An enterprise uses an IPsec tunnel to a cloud provider. The tunnel is established, but only one direction of application traffic works. Which issue should be investigated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS cache expiration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF process ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Return-path routing and matching IPsec selectors<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP router ID format<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Return-path routing and matching IPsec selectors<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Bidirectional application communication requires both a valid forward path and a valid return path. In an IPsec design, the traffic must also match the expected encryption and decryption selectors on both sides. If one direction works but the reverse direction fails, the engineer should verify cloud and enterprise routing, security policies, and local and remote traffic selectors. DNS cache expiration and OSPF process IDs do not directly explain a directional IPsec data-plane problem. BGP router IDs identify BGP speakers but do not by themselves establish bidirectional application reachability.<\/span><\/p>\n<p><b>Question 345. A cloud application experiences degraded performance only during periods of heavy WAN utilization. Which design factor should be evaluated first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS hostname length<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF router ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP community format<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Bandwidth capacity and QoS behavior<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Bandwidth capacity and QoS behavior<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Performance degradation during high utilization commonly indicates that available bandwidth or traffic scheduling is insufficient for the application&#8217;s requirements. The engineer should evaluate peak utilization, committed bandwidth, queueing, packet loss, latency, jitter, and QoS policies. Critical applications may require prioritization or guaranteed resources during congestion. DNS hostname length, OSPF router IDs, and BGP community formatting do not directly control WAN capacity. The investigation should compare measured traffic demand with the service&#8217;s capacity and determine whether QoS policies correctly classify and handle important application traffic.<\/span><\/p>\n<p><b>Question 346. A company receives a default route from a cloud provider but wants to accept only specific cloud application prefixes. What should the enterprise configure?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Inbound BGP prefix filtering<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> TCP MSS adjustment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec replay protection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. TCP MSS adjustment<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The appropriate control for this requirement is inbound BGP prefix filtering, not TCP MSS adjustment. A prefix list or equivalent routing policy can explicitly permit the required cloud application prefixes and deny the default route or other unwanted advertisements. TCP MSS controls TCP segment sizing and does not determine which BGP routes are accepted. OSPF authentication applies to OSPF adjacencies, while IPsec replay protection is a security mechanism for encrypted traffic. Route filtering should be tested carefully so that required cloud prefixes remain reachable after policy changes.<\/span><\/p>\n<p><b>Question 347. An enterprise wants to determine whether its cloud-facing router is actually advertising a newly added internal subnet to the cloud provider. Which verification is most direct?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Inspect the OSPF database<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Check DNS resolution<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Inspect BGP advertised routes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Check the IPsec encryption algorithm<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Inspect BGP advertised routes<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BGP advertised-route information directly shows which prefixes the enterprise router is sending toward a specific BGP neighbor. If the new internal subnet is missing, the engineer can investigate whether the route exists in the local routing table and whether outbound prefix lists, route maps, redistribution policies, or other filters prevent its advertisement. OSPF database information may help establish internal route knowledge but does not prove BGP advertisement. DNS resolution and IPsec encryption settings do not provide direct evidence about BGP route propagation.<\/span><\/p>\n<p><b>Question 348. An organization uses Cisco Catalyst SD-WAN and wants SaaS traffic to use the Internet connection at the branch rather than being backhauled to a hub. Which capability aligns with this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local Internet breakout<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF route summarization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP route reflection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static ARP inspection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Local Internet breakout<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Local Internet breakout allows selected Internet or SaaS traffic to exit directly from the branch rather than traveling through a centralized hub before reaching the Internet. SD-WAN application-aware policies can be used to identify traffic and determine an appropriate local-egress path. This approach can reduce backhaul bandwidth consumption and latency, but security controls must be designed for the branch&#8217;s direct Internet access. OSPF summarization and BGP route reflection serve routing-control purposes and do not provide the Internet-egress architecture described. Static ARP inspection is unrelated to application-based Internet breakout.<\/span><\/p>\n<p><b>Question 349. An administrator sees that an IPsec tunnel is up, but the IPsec byte counters do not increase during an application test. What does this most strongly indicate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP local preference is incorrect<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The security association may be established without matching application traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF has selected the wrong router ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS is using an excessive TTL<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The security association may be established without matching application traffic<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IPsec tunnel can have an established security association even when application packets are not being matched to the encryption policy. If packet or byte counters do not change during a controlled traffic test, the engineer should examine traffic selectors, crypto ACLs, routing, forwarding, and security policies. BGP local preference and OSPF router IDs do not directly explain unchanged IPsec traffic counters. DNS TTL is also unrelated. Comparing counters before and after generating known traffic can help determine whether packets are entering the encrypted path and whether the problem occurs before or after IPsec processing.<\/span><\/p>\n<p><b>Question 350. A cloud provider requires the enterprise to advertise only summarized internal networks rather than individual host routes. Which routing technique can reduce the number of advertised prefixes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increasing BGP keepalive frequency<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route summarization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Changing IPsec lifetimes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increasing DNS TTL<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Route summarization<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Route summarization combines multiple contiguous or logically related prefixes into a larger aggregate prefix, reducing the number of individual routes that need to be advertised. This can simplify routing tables and reduce routing-policy complexity. The summary must accurately represent reachable networks, and the design should consider the consequences of advertising an aggregate when some component networks are unavailable. BGP keepalive timers, IPsec lifetimes, and DNS TTL values do not reduce the number of routing prefixes. Summarization should be implemented carefully to avoid creating unintended reachability or blackholing traffic.<\/span><\/p>\n<p><b>Question 351. An enterprise cloud connection uses eBGP, but the BGP session repeatedly resets when the WAN path experiences brief interruptions. Which design consideration is most relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS search suffix<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF process number<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP failure detection and convergence behavior<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec cipher name length<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. BGP failure detection and convergence behavior<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Brief connectivity interruptions can cause BGP sessions to reset, withdraw routes, and reconverge. The engineer should evaluate BGP timers, failure-detection mechanisms, interface tracking, tunnel state, and the desired convergence behavior. The goal is to ensure that routing responds appropriately to real failures without causing unnecessary instability from transient conditions. DNS search suffixes and OSPF process numbers do not directly control an eBGP session. IPsec cipher naming has no relationship to BGP session stability. The design should also consider whether faster failure detection or appropriate dampening and redundancy mechanisms are required.<\/span><\/p>\n<p><b>Question 352. A company wants to ensure that cloud traffic entering the enterprise is inspected before reaching internal application networks. Which security design concept applies most directly?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Inbound north-south security inspection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local DNS caching<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF metric tuning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP route aggregation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Inbound north-south security inspection<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Traffic entering an enterprise from a cloud environment is generally north-south inbound traffic. If policy requires inspection before internal applications are reached, the architecture should place appropriate firewalls or security controls along the traffic path. The design should identify permitted flows, inspection capacity, return-path behavior, failure handling, and logging requirements. DNS caching and OSPF metrics do not provide the required security enforcement. BGP aggregation can reduce routing-table size but does not determine whether inbound traffic is inspected. The inspection point must also be capable of handling expected peak traffic.<\/span><\/p>\n<p><b>Question 353. An administrator wants to determine whether a cloud route is being rejected by an inbound prefix list. Which information should be correlated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS records and DHCP leases<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF LSAs and NTP status<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP received routes and the applied inbound policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec cipher and tunnel lifetime<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. BGP received routes and the applied inbound policy<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Correlating the routes received from the BGP neighbor with the inbound policy can reveal whether a prefix was received and then filtered. The engineer should inspect the neighbor&#8217;s routing information and identify the prefix-list or route-policy applied in the inbound direction. This distinguishes a route that was never advertised from one that was received but rejected. DNS records, DHCP leases, OSPF LSAs, NTP status, and IPsec parameters do not directly show BGP inbound filtering behavior. Policy verification should include both the expected prefix and the exact direction in which the filter is applied.<\/span><\/p>\n<p><b>Question 354. A cloud connectivity design must continue operating if a single physical link fails. Which validation activity provides the strongest evidence that the redundancy works as designed?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Verify DNS resolution only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Change the router hostname<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase BGP keepalive values<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Perform a controlled link-failure test<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Change the router hostname<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The relevant validation activity would actually be a controlled link-failure test. Intentionally failing the primary connection during an approved maintenance window allows the engineer to verify failure detection, route withdrawal, alternate-path selection, convergence time, packet loss, and application recovery. Changing the router hostname does not exercise the redundancy mechanism. Similarly, modifying BGP keepalive values changes configuration but does not demonstrate that the complete failover path works. A useful validation plan should define expected recovery behavior before the test and document observed results afterward.<\/span><\/p>\n<p><b>Question 355. A cloud service uses two paths, but both paths traverse the same upstream provider before reaching the cloud. What risk remains?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A shared upstream failure can affect both paths<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS will always fail<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP cannot operate over multiple links<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec becomes impossible<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. A shared upstream failure can affect both paths<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multiple logical paths do not necessarily provide full resiliency if they share an upstream provider or infrastructure component. A failure affecting that common dependency could interrupt both paths simultaneously. The architect should identify shared failure domains such as carriers, buildings, conduits, power systems, exchange points, or provider infrastructure. BGP can operate over multiple links, and IPsec can also use redundant paths when properly designed. DNS failure is not an inherent consequence of shared upstream infrastructure. True resiliency requires meaningful diversity in addition to route-level redundancy.<\/span><\/p>\n<p><b>Question 356. An engineer observes that cloud-to-enterprise traffic uses a different path from enterprise-to-cloud traffic. Which consequence should be investigated when stateful firewalls are present?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS TTL expiration<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Potential asymmetric-flow drops<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF router ID collision<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP origin-code changes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. DNS TTL expiration<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The relevant consequence would actually be potential asymmetric-flow drops. Stateful firewalls track connection state and may expect packets from both directions to traverse the same or an appropriate security path. If return traffic follows a different path and bypasses the stateful device, packets can be dropped because the expected session state is missing. DNS TTL does not determine whether packet flows are symmetric. OSPF router IDs and BGP origin codes may affect routing in specific circumstances, but they are not the direct consequence being described. The engineer should trace both directions of the application flow and inspect firewall state.<\/span><\/p>\n<p><b>Question 357. An enterprise needs to protect cloud traffic over an untrusted network. Which technology provides confidentiality and integrity for the traffic while establishing secure peer relationships?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. BGP<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The technology designed to provide confidentiality and integrity for traffic across an untrusted network is IPsec. IPsec can use authenticated security associations and encryption to protect data between peers. BGP is a routing protocol and does not inherently provide data confidentiality for application traffic. OSPF is also a routing protocol, while DNS provides name-resolution services. In cloud-connectivity designs, IPsec is commonly used to secure traffic between enterprise and cloud endpoints when the underlying transport cannot itself be considered trusted or private. Routing protocols can operate over the resulting connectivity but serve different purposes.<\/span><\/p>\n<p><b>Question 358. A cloud application requires a backup path that becomes active only when the primary path is unavailable. Which design characteristic should be verified?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Active\/standby path behavior and failure detection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS record formatting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF area-name length<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP community description text<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Active\/standby path behavior and failure detection<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An active\/standby design depends on reliable failure detection and predictable path-selection behavior. The engineer should verify that the primary path is preferred during normal operation, that the backup path remains available, and that the routing system detects primary-path failure and selects the standby path within the required timeframe. DNS formatting, OSPF area-name length, and BGP community description text do not determine failover behavior. Testing should include controlled failures and restoration of the primary path to confirm both failover and recovery behavior.<\/span><\/p>\n<p><b>Question 359. An organization wants to prevent internal infrastructure prefixes from being advertised to a cloud provider. Which policy direction should be examined?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Inbound toward the enterprise<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Outbound toward the cloud provider<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS recursion<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. DNS recursion<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The relevant policy direction would actually be outbound toward the cloud provider. When an enterprise wants to prevent its own prefixes from being advertised to a BGP neighbor, the engineer should examine outbound route filtering or policy on that neighbor relationship. Inbound filtering controls routes coming into the enterprise rather than routes leaving it. DNS recursion and OSPF authentication do not determine which enterprise prefixes are advertised through BGP. The engineer should verify the intended prefix policy and inspect BGP advertised-route information to confirm the actual result.<\/span><\/p>\n<p><b>Question 360. A cloud-connected application remains reachable after a primary-path failure, but users experience several seconds of interruption during convergence. Which measurement is most useful for determining whether the design meets its availability requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Router hostname length<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DNS cache size<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP community count<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Measured failover and application recovery time<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Measured failover and application recovery time<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Measured failover and application recovery time provides direct evidence of whether the redundancy design meets its availability objective. Network convergence may complete quickly while applications take longer to recover, so both routing behavior and actual service restoration should be measured. The engineer should record failure-detection time, route-convergence time, packet loss, and application recovery time, then compare the results with documented requirements. Router hostname length, DNS cache size, and BGP community count do not provide meaningful measurements of service recovery. Controlled testing under representative conditions is essential for validating the design.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Enterprise 300-440 Exam Dumps \u00a0and Practice Test Dumps &nbsp; Question 341. An enterprise needs to connect a private data center to a cloud environment while keeping traffic isolated from the public Internet. Which connectivity characteristic is most relevant? Public DNS resolution Private connectivity with appropriate security controls Increased OSPF hello frequency [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23234"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23234"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23234\/revisions"}],"predecessor-version":[{"id":23235,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23234\/revisions\/23235"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23234"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23234"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23234"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}