Month End Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Cisco 350-501 Practice Exam with Questions & Answers | Set: 13

Questions 121

Refer to the exhibit.

350-501 Question 121

Which type of DDoS attack will be mitigated by this configuration?

Options:
A.

SYN flood

B.

smurf attack

C.

SIP INVITE flood attacks

D.

teardrop attack

Cisco 350-501 Premium Access
Questions 122

Refer to the exhibit.

350-501 Question 122

To protect in-band management access to CPE-R7, an engineer wants to allow only SSH management and provisioning traffic from management network 192.168.0.0/16. Which infrastructure ACL change must be applied to router PE-R9 to complete this task?

A)

350-501 Question 122

B)

350-501 Question 122

C)

350-501 Question 122

D)

350-501 Question 122

Options:
A.

Option A

B.

Option B

C.

Option C

D.

Option D

Questions 123

You are creating new Cisco MPLS TE tunnels. Which type of RSVP message does the headend router send to reserve bandwidth on the path to the tunnel’s router?

Options:
A.

error

B.

reservation

C.

path

D.

tear

Questions 124

Which two actions describe ISP delegation to PCE servers? (Choose two)

Options:
A.

adding a new PCE server with lower precedence than the primary PCE

B.

changing the precedence of any of the PCE servers

C.

removing TE re-optimization timer timeouts

D.

entering the mpls traffic-eng reoptimize command

E.

adding a new PCE server with higher precedence than the primary PCE

Questions 125

A network architect plans to implement MPLS OAM to provide additional troubleshooting functionality for the NOC team. After analyzing the configuration on the MPLS P/PE nodes, the architect decides to revise the CoPP policies. Which two actions ensure that the new solution is secure? (Choose two.)

Options:
A.

Allow port 3505 in the outbound direction only.

B.

Allow the ICMP protocol only.

C.

Allow the TCP and UDP protocols.

D.

Allow the UDP protocol only.

E.

Allow port 3503 in the inbound direction only.

Questions 126

Refer to me exhibit.

350-501 Question 126

A network operator recently configured BGP FlowSpec for me internal IT network What will be inferred from the configuration deployed on me network?

Options:
A.

The policy is configured locally on CSRl and drops all traffic for TCP ports 80 and 443

B.

The policy is learned via BGP FlowSpec and drops all traffic for TCP ports 80 and 443

C.

The policy is warned via BC FlowSpec aid has active traffic

D.

The policy is configured locally on CSR1 and currently has no active traffic

Questions 127

350-501 Question 127

Refer to the exhibit. Tier 2 ISP A on AS 653 is connected to two Tier 1 ISPs on AS 321 and AS 51 respectively. The network architect at ISP A is planning traffic flow inside the network to provide predictable network services. Cisco Express Forwarding is disabled on the edge router. How should the architect implement BGP to direct all traffic via the Tier 1 ISP with next-hop 7.4.5.2?

Options:
A.

Implement the BGP routing protocol and run the bgp deterministic-med command.

B.

Implement MP-BGP with a 4-byte AS number with the bgp best path compare-routerid command.

C.

Implement the BGP routing protocol and the maximum-paths 2 configuration.

D.

Implement BGP route-reflector functionality with the bgp always-compare-med configuration.

Questions 128

Simulation 5

350-501 Question 128

350-501 Question 128

Options:
Questions 129

A service provider requires continuous real-time network monitoring to provide reliable SLAs to its customers. To satisfy this requirement, a network administrator is implementing gRPC dial out on an ASR with TLS. Receiver 192.168.10.2 will be assigned one of the subscriptions, and it will manage the ASR. Which configuration must the engineer apply to the router as part of the configuration process?

Options:
A.

snmp-server community public

snmp-server enable traps

snmp-server host 192.168.10.2 version 2c public.

B.

telemetry model-driven

destination-group DGroup1

address family ipv4 192.168.10.2 1 port 10

encoding self-describing-gpb

C.

snmp-server community public

snmp-server enable traps

snmp-server enable traps snmp authentication

snmp-server manager

snmp-server manager session-timeout 1000

D.

telemetry model-driven

destination-group ciscotest

address family ipv4 192.168.10.2 port 10

encoding self-describing-gpb

protocol grpc tis-hostname ciscotest.com

Questions 130

Refer to the exhibit:

350-501 Question 130

Which configuration prevents the OSPF neighbor from establishing?

Options:
A.

mtu

B.

duplex

C.

network statement

D.

default-metric