{"id":23238,"date":"2026-09-26T12:21:16","date_gmt":"2026-09-26T12:21:16","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23238"},"modified":"2026-09-26T12:21:16","modified_gmt":"2026-09-26T12:21:16","slug":"cisco-ccnp-enterprise-300-440-practice-test-questions-and-exam-dumps-part-20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-enterprise-300-440-practice-test-questions-and-exam-dumps-part-20-q381-400\/","title":{"rendered":"Cisco CCNP Enterprise 300-440 Practice Test Questions and Exam Dumps Part 20 Q381-400"},"content":{"rendered":"<h1><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-440-exam-dumps\"><b>Cisco CCNP Enterprise 300-440 Exam Dumps <\/b><\/a><b>\u00a0and Practice Test Dumps<\/b><\/h1>\n<p>&nbsp;<\/p>\n<p><b>Question 381. A network engineer is integrating an enterprise branch with a cloud provider using BGP.\u00a0<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> MED<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local preference<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Origin code<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AS-path length<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Local preference<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Local preference is used within a BGP autonomous system to influence which exit path routers should prefer for outbound traffic. A higher local-preference value is preferred and is propagated to other iBGP peers within the same AS. This makes it appropriate when an enterprise has multiple cloud connectivity paths and wants consistent outbound path selection across its internal routers. MED serves a different purpose and is generally used to influence how a neighboring AS selects among multiple entry points. AS-path length and origin code are also BGP path-selection attributes, but they are not the primary mechanism for setting an organization&#8217;s preferred outbound exit path.<\/span><\/p>\n<p><b>Question 382. A company connects its data center to a cloud provider through two Internet circuits. During testing, both IPsec tunnels remain established, but applications intermittently fail when sending large packets. Small ping packets work normally. Which issue should the engineer investigate first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP router ID duplication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Incorrect local preference<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Missing NTP synchronization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MTU or TCP MSS problems<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. MTU or TCP MSS problems<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IPsec encapsulation adds overhead to packets, reducing the effective payload size that can traverse the tunnel without fragmentation. When MTU handling is incorrect, small packets can succeed while larger application packets fail or experience retransmissions. TCP MSS adjustment can help ensure that TCP segments remain small enough to account for tunnel overhead. This symptom is therefore strongly associated with MTU or MSS problems. BGP router ID duplication, local preference, and NTP synchronization can affect routing or control-plane behavior, but they do not directly explain a pattern in which small packets succeed while larger packets fail across an established IPsec tunnel.<\/span><\/p>\n<p><b>Question 383. An enterprise uses a Cisco IOS XE router to connect to a cloud network. The cloud routes are learned through BGP, while internal routes are learned through OSPF. The engineer needs the cloud prefixes to be available to internal OSPF routers. Which configuration concept is required?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Route redistribution between BGP and OSPF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increasing the OSPF hello interval<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Changing the BGP router ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disabling OSPF authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Route redistribution between BGP and OSPF<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When routes are learned by one routing protocol and need to be advertised through another routing protocol, route redistribution is required. In this scenario, BGP learns the cloud prefixes, while OSPF provides internal routing information. Redistributing appropriate BGP routes into OSPF allows internal OSPF routers to learn those cloud destinations. The redistribution policy should be carefully controlled with route maps, prefix lists, tags, or other filtering mechanisms to prevent unwanted route exchange or routing loops. Changing hello timers, router IDs, or authentication settings does not by itself transfer BGP-learned routes into the OSPF domain.<\/span><\/p>\n<p><b>Question 384. A cloud-connected branch receives several BGP routes for the same destination. The engineer wants to prevent a specific cloud prefix from being installed because it is not permitted by the enterprise routing policy. Which mechanism is most appropriate for filtering routes received from the BGP neighbor?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP advertisement toward the neighbor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF distribute-list on another router<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An inbound BGP route policy or prefix list<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Changing the IPsec encryption algorithm<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. An inbound BGP route policy or prefix list<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An inbound BGP policy controls routes received from a BGP neighbor before they are accepted into the local BGP routing process. Prefix lists, route maps, or route-policy mechanisms can identify permitted or denied prefixes and apply additional attributes where required. This is appropriate when an enterprise needs to reject a particular cloud prefix based on its routing policy. An outbound advertisement policy controls what the local router sends to the neighbor instead, so it does not directly solve the problem of filtering received routes. IPsec encryption settings and OSPF filtering are unrelated to the requested BGP inbound control.<\/span><\/p>\n<p><b>Question 385. A company requires cloud connectivity to remain available if the primary WAN circuit fails. The secondary circuit uses a different provider and terminates on another enterprise router. Which design characteristic most directly provides this resilience?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A single IPsec tunnel over the primary circuit<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A single default route with no tracking<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A larger BGP AS number<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Diverse physical connectivity with redundant paths<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Diverse physical connectivity with redundant paths<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Resilient cloud connectivity requires more than simply configuring multiple logical tunnels over the same underlying failure domain. Using diverse physical circuits, preferably through different providers or paths, reduces the chance that one physical or provider failure will interrupt all connectivity. Redundant routers and appropriately designed routing or tunnel failover mechanisms can then select the surviving path. A single tunnel or untracked default route does not provide equivalent resilience. The BGP AS number has no direct relationship to physical path diversity. Therefore, diverse physical connectivity combined with redundant routing paths is the key design characteristic for maintaining cloud reachability after a primary WAN failure.<\/span><\/p>\n<p><b>Question 386. An enterprise has multiple cloud connectivity links and wants internal routers to consistently select the same preferred exit toward the cloud. The engineer configures a higher local-preference value on routes learned through the preferred link. What behavior should result?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internal BGP routers prefer the path with the higher local preference<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The cloud provider automatically changes its MED values<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF routers ignore all BGP routes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec tunnels automatically change encryption algorithms<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Internal BGP routers prefer the path with the higher local preference<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Local preference is a BGP attribute used within an autonomous system to influence outbound route selection. When multiple paths to the same destination are available, the path with the higher local-preference value is preferred, assuming the relevant earlier path-selection criteria do not override the comparison. This allows an organization to establish a consistent preferred cloud exit across its internal BGP infrastructure. The attribute does not directly modify the cloud provider&#8217;s MED values, alter OSPF behavior, or change IPsec encryption. Local preference is therefore particularly useful when the enterprise controls multiple exits and wants internal routers to favor one cloud connectivity path.<\/span><\/p>\n<p><b>Question 387. A cloud application is hosted outside the enterprise network, while users inside the enterprise access the application through a cloud-connected router. The traffic travels from the enterprise toward the cloud and ultimately to the external application. How should this traffic direction generally be classified?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> East-west traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Management-plane traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> North-south traffic<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Control-plane traffic<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. North-south traffic<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">North-south traffic generally refers to traffic entering or leaving an environment, such as communication between an enterprise network and an external cloud, Internet, or service-provider network. In this scenario, users inside the enterprise are accessing an application hosted outside the enterprise environment, so the traffic crosses the network boundary and is considered north-south. East-west traffic instead describes communication between workloads, segments, or services within the broader environment. Management-plane and control-plane classifications describe different types of network functions and do not describe the directional relationship between internal users and an externally hosted cloud application.<\/span><\/p>\n<p><b>Question 388. A network engineer is troubleshooting an IPsec cloud connection. The tunnel status indicates that the security associations are established, but the IPsec packet counters do not increase when application traffic is generated. What should the engineer investigate next?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The BGP origin code only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Traffic selectors, crypto ACLs, and forwarding paths<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The OSPF process ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The router&#8217;s console speed<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Traffic selectors, crypto ACLs, and forwarding paths<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An established IPsec security association confirms that the control-plane negotiation has succeeded, but it does not guarantee that user traffic is actually matching the protected traffic definitions. If packet counters remain unchanged, the engineer should verify that the source and destination traffic matches the configured traffic selectors or crypto ACLs and that routing sends the packets toward the tunnel. Incorrect selectors, missing routes, or an unexpected forwarding path can prevent traffic from entering IPsec processing. BGP origin codes and OSPF process IDs do not directly explain the lack of IPsec packet-counter activity, and console speed has no relationship to data-plane forwarding.<\/span><\/p>\n<p><b>Question 389. An organization wants cloud traffic to use a centralized security stack rather than allowing every branch to send traffic directly to the Internet. Which design approach aligns with this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet backhaul through a centralized security location<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing all default routes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Using only OSPF stub areas<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disabling security inspection for cloud-bound traffic<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Internet backhaul through a centralized security location<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Internet backhaul routes branch Internet-bound traffic through a centralized location where security controls such as firewalls, intrusion prevention, URL filtering, or other inspection services can be applied. This design is useful when an organization requires centralized policy enforcement rather than independent local Internet breakout at every branch. It may introduce additional latency and bandwidth requirements, so the architecture should consider capacity and application performance. Removing default routes would prevent normal Internet reachability, while OSPF stub areas do not provide centralized security enforcement. Disabling inspection would have the opposite effect of the stated requirement.<\/span><\/p>\n<p><b>Question 390. A cloud provider advertises a set of prefixes to an enterprise router. The engineer wants to confirm exactly which routes were received from the BGP neighbor before applying any outbound advertisement changes. Which information is most directly relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The router&#8217;s IPsec encryption transform<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The local OSPF neighbor state<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The interface duplex setting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The BGP routes received from the neighbor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The BGP routes received from the neighbor<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When troubleshooting which cloud prefixes have been learned from a BGP neighbor, the most direct information is the set of routes received from that neighbor. This allows the engineer to determine whether the cloud is advertising the expected prefixes and whether inbound filtering or other policy has affected route acceptance. Outbound advertisements represent what the enterprise sends to the cloud provider and answer a different troubleshooting question. IPsec transforms, OSPF adjacency information, and interface duplex settings may be relevant to other problems, but they do not directly identify the BGP prefixes received from the cloud neighbor.<\/span><\/p>\n<p><b>Question 391. An enterprise has two cloud paths. One path has significantly higher bandwidth but is more expensive, while the second path has lower bandwidth and lower cost. The organization wants applications with strict performance requirements to use the high-bandwidth path. Which design consideration should be evaluated first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application requirements and traffic characteristics<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The number of characters in the router hostname<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The OSPF process ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The BGP router ID format<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Application requirements and traffic characteristics<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud connectivity design should begin with understanding application requirements and traffic characteristics. Bandwidth requirements, latency sensitivity, burst behavior, availability objectives, and application criticality help determine whether a high-capacity path is necessary for particular workloads. A more expensive circuit may be justified for applications that require predictable performance, but that decision should be tied to measurable requirements rather than bandwidth alone. Router hostname length, OSPF process ID, and BGP router ID format do not determine application connectivity requirements. Once application characteristics are understood, routing and QoS policies can be designed to steer appropriate traffic over the available cloud paths.<\/span><\/p>\n<p><b>Question 392. A cloud-connected router has an eBGP session established with the provider. The provider&#8217;s prefix is also learned through OSPF after route redistribution. Assuming default administrative distances and otherwise comparable routes, which route source normally has the lower administrative distance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> External BGP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static routing learned dynamically<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Both have identical administrative distance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. External BGP<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">By default, external BGP has an administrative distance of 20, while OSPF has an administrative distance of 110. Therefore, when the same destination is available through both eBGP and OSPF and no other route-selection mechanism changes the result, the eBGP route normally has the lower administrative distance and is preferred for installation in the routing table. This distinction is important when troubleshooting cloud connectivity involving redistribution because engineers may incorrectly assume that OSPF automatically takes precedence due to its internal routing role. Administrative distance is considered after a route has been selected by a routing protocol and is used to choose among routes from different sources.<\/span><\/p>\n<p><b>Question 393. A Cisco Catalyst SD-WAN deployment needs to identify SaaS applications and select appropriate paths based on application performance. Which capability is most relevant to this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> OnRamp for SaaS<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Static ARP inspection<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF passive-interface mode<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DHCP relay<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. OnRamp for SaaS<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco Catalyst SD-WAN OnRamp for SaaS is designed to optimize connectivity to SaaS applications by providing application-aware path selection and visibility into available transport paths. It can use performance measurements and policy to select an appropriate path for supported applications rather than relying only on destination-prefix routing. This is particularly useful when multiple WAN transports are available and application performance varies between them. Static ARP inspection, OSPF passive-interface mode, and DHCP relay perform different network functions and do not provide the application-aware SaaS path-selection capability described in the scenario.<\/span><\/p>\n<p><b>Question 394. A company is designing connectivity between two cloud environments where workloads communicate directly with each other without traversing the enterprise&#8217;s Internet edge. What traffic classification best describes this communication?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> North-south<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Internet backhaul<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> East-west<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Management-plane<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. East-west<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">East-west traffic describes communication between workloads, services, or network segments within an interconnected environment. When workloads in two cloud environments communicate directly without the traffic leaving through a traditional enterprise Internet edge, the communication can be treated as east-west from the perspective of the cloud-connected architecture. North-south traffic generally crosses the boundary between internal resources and external networks or services. Internet backhaul specifically describes routing Internet traffic through a centralized location, while management-plane traffic concerns network administration and control rather than workload communication.<\/span><\/p>\n<p><b>Question 395. An enterprise advertises a default route toward a cloud-connected BGP neighbor. The engineer wants to verify what the enterprise router is actually sending to that neighbor. Which troubleshooting information should be examined?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP advertised routes toward the neighbor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec replay counters only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF database sequence numbers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> TCP MSS values only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. BGP advertised routes toward the neighbor<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BGP advertised-route information shows the routes that the local router is sending to a specific neighbor after outbound policy is applied. This is the appropriate information when verifying whether a default route or other enterprise prefixes are actually being advertised to the cloud provider. Looking only at routes received from the neighbor answers the opposite question. IPsec replay counters can help troubleshoot encrypted traffic, while OSPF database information relates to an internal routing protocol. TCP MSS is relevant to packet-size troubleshooting. For BGP advertisement verification, the engineer should inspect the routes advertised to the specific neighbor.<\/span><\/p>\n<p><b>Question 396. During a cloud VPN outage, the IPsec tunnel is established again, but users still cannot reach the cloud application. The routing table shows a valid cloud prefix, but return traffic appears to use a different path. Which condition should the engineer investigate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Duplicate OSPF process IDs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Asymmetric routing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Incorrect console authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> BGP origin-code preference only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Asymmetric routing<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Asymmetric routing occurs when traffic travels through different paths in the forward and return directions. This can cause problems with stateful firewalls, security appliances, NAT, or other devices that expect flows to follow a consistent path. In the scenario, the local router has a valid route to the cloud application, but return traffic follows a different path, making asymmetric routing an important troubleshooting target. The engineer should inspect routing decisions in both directions, security-policy behavior, NAT, and cloud-side return routes. OSPF process IDs and console authentication do not directly explain this forwarding condition.<\/span><\/p>\n<p><b>Question 397. An organization needs predictable performance for critical cloud applications and has a documented SLA requiring specific availability and latency characteristics. Which cloud-connectivity design factor should be explicitly evaluated when selecting the transport?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Router hostname length<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Number of VLAN names<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> SLA and service-performance requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OSPF process ID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. SLA and service-performance requirements<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud connectivity should be selected according to documented application and business requirements, including availability, latency, jitter, packet loss, and service-level commitments. If critical applications depend on predictable performance, the transport&#8217;s SLA should be compared with the organization&#8217;s requirements before deployment. A shared Internet service and a dedicated connectivity option may provide different performance characteristics and contractual guarantees. Router hostname length, VLAN naming, and OSPF process identifiers do not establish service quality. Evaluating the SLA ensures that the chosen connectivity method can support the required operational objectives rather than simply providing basic network reachability.<\/span><\/p>\n<p><b>Question 398. A network engineer configures a cloud BGP session and receives the expected prefixes, but the enterprise router does not advertise its internal prefixes to the cloud provider. Which area should be checked first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Inbound policy applied to routes received from the cloud<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> IPsec encryption key lifetime only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Outbound BGP policy and the local routing table<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NTP stratum on an unrelated server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Outbound BGP policy and the local routing table<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">If the router receives cloud prefixes but does not advertise internal prefixes to the provider, the engineer should verify that the desired internal routes exist in the local routing table and that outbound BGP policy permits them. Route maps, prefix lists, route policies, network statements, redistribution, and other advertisement controls can determine whether a prefix is sent to the neighbor. Inbound policy affects routes received from the cloud and therefore does not directly control the enterprise&#8217;s outbound advertisements. IPsec key lifetime and NTP stratum do not normally determine which BGP prefixes are advertised.<\/span><\/p>\n<p><b>Question 399. A cloud VPN is operational, but users experience poor performance only during periods of high traffic. Monitoring shows that the physical WAN circuit is approaching its committed capacity. Which design issue is most directly indicated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Insufficient bandwidth capacity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Incorrect BGP router ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Duplicate OSPF area numbers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Incorrect IPsec peer authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Insufficient bandwidth capacity<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When application performance deteriorates during periods of high utilization and the WAN circuit approaches its committed capacity, insufficient bandwidth is a likely design constraint. Capacity planning should account for normal traffic, peak demand, growth, overhead from encryption or encapsulation, and appropriate headroom. Simply confirming that an IPsec tunnel is established does not guarantee sufficient transport capacity for the application workload. BGP router IDs and OSPF area numbers do not explain a utilization-driven performance problem, while incorrect IPsec authentication would generally prevent tunnel establishment rather than cause degradation only during traffic peaks.<\/span><\/p>\n<p><b>Question 400. An engineer must validate a new redundant cloud connection before production traffic is migrated. Which test provides the most meaningful evidence that the design meets its failover objective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Checking only that the standby interface is administratively up<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Measuring failover behavior, convergence, and application recovery during a controlled test<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Verifying only the router hostname<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Confirming that the IPsec encryption algorithm is configured<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Measuring failover behavior, convergence, and application recovery during a controlled test<\/b><\/p>\n<p><b>Explanation :-<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A redundancy design should be validated by testing the actual failure condition and measuring how the network responds. A controlled failover test can reveal whether routing converges as expected, whether IPsec or SD-WAN paths transition correctly, whether security policies permit the new path, and how long applications take to recover. Merely confirming that a standby interface is administratively up does not prove end-to-end resilience. Likewise, checking the encryption algorithm or hostname does not validate failover behavior. Measuring convergence and application recovery provides operational evidence that the redundant cloud-connectivity design performs according to its intended objectives.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP Enterprise 300-440 Exam Dumps \u00a0and Practice Test Dumps &nbsp; Question 381. A network engineer is integrating an enterprise branch with a cloud provider using BGP.\u00a0 MED Local preference Origin code AS-path length Correct Answer: 2. Local preference Explanation :- Local preference is used within a BGP autonomous system to influence which [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23238"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23238"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23238\/revisions"}],"predecessor-version":[{"id":23239,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23238\/revisions\/23239"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}