New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Cisco 350-501 Practice Exam with Questions & Answers | Set: 6

Questions 76

350-501 Question 76

Refer to the exhibit. Routers R1 and R2 support traffic between multiple departments at a company's remote office and exchange routes using OSPF. The link between R1 and R2 has been providing inconsistent performance, particularly during times of peak usage. To help identify the cause, an engineer was asked to implement BFD to detect failures on the link. Which task must the engineer perform?

Options:
A.

Configure the session parameters individually on each interface.

B.

Configure IS-IS to share routes between the routers.

C.

Change the network between R1 and R2 to a /30 prefix.

D.

Configure echo mode on both devices to support asymmetry.

Cisco 350-501 Premium Access
Questions 77

350-501 Question 77

Refer to the exhibit an engineer working for a private telecommunication company with an employee Id: 4065:96:080 upgrades the WAN link between routers ASBR-101 and ASBR-201 to 1Gb by Installing a new physical connection between the Gi3 Interfaces. Which BGP attribute must the engineer configure on ASBR-201 so that the existing WAN link on Gi2 Is maintained as a backup?

350-501 Question 77

350-501 Question 77

Options:
A.

Option A

B.

Option B

C.

Option C

D.

Option D

Questions 78

Refer to the exhibit.

350-501 Question 78

Refer to the exhibit. An ISP provides shared VoIP Extranet services to a customer in VRF-100 with these settings:

The VoIP services are hosted in the 198.19.100.0/24 space.

The customer has been assigned the 198.18.1.0/29 IP address block.

VRF-100 is assigned import and export route target 65010:100.

Which configuration must the engineer apply to PE-1 to provision VRF-100 and provide access to the shared services?

Options:
A.

vrf definition VRF-100

rd 172.17.255.1:100

!

address-family ipv4

export map VRF-100-EXPORT

import map VRF-100-IMPORT

exit-address-family

!

route-map VRF-100-EXPORT permit 10

match ip address prefix-list VRF-100-ALLOWED-EXPORT

set extcommunity rt 65010:100 65010:2999

route-map VRF-100-EXPORT permit 20

set extcommunity rt 65010:100

!

route-map VRF-100-I

B.

vrf definition VRF-100

rd 172.17.255.1:100

!

address-family ipv4

export map VRF-100-EXPORT

route-target import 65010:100

route-target import 65010:2999

exit-address-family

!

route-map VRF-100-EXPORT permit 10

match ip address prefix-list VRF-100-ALLOWED-EXPORT

set extcommunity rt 65010:100 65010:1999

route-map VRF-100-EXPORT permit 20

set extcommunity rt 65

C.

vrf definition VRF-100

rd 172.17.255.1:100

!

address-family ipv4

export map VRF-100-EXPORT

route-target import 65010:100

route-target import 65010:1999

exit address-family

!

route-map VRF-100-EXPORT permit 10

match ip address prefix-list VRF-100-ALLOWED-EXPORT

set extcommunity rt 65010:100 65010:2999

route-map VRF-100-EXPORT permit 20

set extcommunity r 650

D.

vrf definition VRF-100

rd 172.17.255.1:100

!

address-family ipv4

route-target export 65010:100

route-target export 65010:1999

route-target import 65010:100

route-target import 65010:2999

exit-address-family

Questions 79

350-501 Question 79

Refer to the exhibit. An ISP is providing online registration services for a new social program. OSPF is being used as an interior routing protocol with TE capabilities. A network engineer with an employee ID: 5209:82:636 must provide faster MPLS-enabled convergence in case of failure. The ip cef distributed command has already been configured on all MPLS-enabled routers, and connectivity between the core routers has been verified following IETF RFC 4379. Which additional task must the engineer perform to complete the implementation?

Options:
A.

Implement LDP session protection on all PE routers.

B.

Implement MPLS TE fast reroute node protection on all MPLS-enabled routers.

C.

Implement MPLS TE fast reroute link protection on routers R2 and R3.

D.

Implement OSPF loop-free alternate fast reroute on core routers only.

Questions 80

350-501 Question 80

Refer to the exhibit. The network is configured with OSPF. A networking team just connected a streaming multicast server to router R7, and they now must enable access for users throughout the network to stream video from the server.

Which action must the team take so that users can stream video without overloading the network?

Options:
A.

Implement PIM-DM on the link between the server and R7.

B.

Implement PIM-SM on the LAN network connecting R5, R6, R3, and R4.

C.

Implement PIM-SM on all routers and connected links.

D.

Implement PIM-DM on all interfaces in the network except the LAN connection between R5, R6, R3, and R4.

Questions 81

A network engineer is testing an automation platform that interacts with Cisco networking devices via NETCONF over SSH. In accordance with internal security requirements:

NETCONF sessions are permitted only from trusted sources in the 172.16.20.0/24 subnet.

CLI SSH access is permitted from any source.

Which configuration must the engineer apply on R1?

Options:
A.

configure terminal

hostname R1

ip domain-name mydomain.com

crypto key generate rsa

ip ssh version 1

access-list 1 permit 172.16.20.0 0.0.0.255

netconf ssh acl 1

line vty 0 4

transport input ssh

end

B.

configure terminal

hostname R1

ip domain-name mydomain.com

crypto key generate rsa

ip ssh version 2

access-list 1 permit 172.16.20.0 0.0.0.255

access-list 1 permit any

netconf ssh

line vty 0 4

access-class 1 in

transport input ssh

end

C.

configure terminal

hostname R1

ip domain-name mydomain.com

crypto key generate rsa

ip ssh version 1

access-list 1 permit 172.16.20.0 0.0.0.255

access-list 2 permit any

netconf ssh

line vty 0 4

access-class 2 in

transport input ssh

end

D.

configure terminal

hostname R1

ip domain-name mydomain.com

crypto key generate rsa

ip ssh version 2

access-list 1 permit 172.16.20.0 0.0.0.255

netconf ssh acl 1

line vty 0 4

transport input ssh

end

Questions 82

Refer to the exhibit:

350-501 Question 82

A network engineer is implementing a BGP routing policy.

Which effect of this configuration is true?

Options:
A.

All traffic that matches acl10 is allowed without any change to its local-preference

B.

All traffic that matches acl10 is dropped without any change to its local-preference

C.

If traffic matches acl10, it is allowed and its local-preference is set to 300

D.

All traffic is assigned a local-preference of 30O regardless of its destination

Questions 83

350-501 Question 83

Refer to the exhibit. A multinational corporation with a Cisco-based network wants to leverage Cisco security features to enhance the security of their LAN and protect against eavesdropping and man-in-the-middle attacks. The solution must comply with the IEEE 802.1AE standard. A network engineer must implement the new security configurations on a pair of interconnected Cisco switches. The engineer already completed the configuration to enable AAA new-model and set up a basic AAA configuration for user authentication. Management VLAN 10 is in place for network administration. Which action must the engineer take to meet the requirements?

Options:
A.

Implement CTS for role-based access control on both switches.

B.

Implement MACsec on both switches with encryption mode GCM and a shared key.

C.

Implement open authentication via the management VLAN on both switches.

D.

Implement IPsec on both switches to secure data transmissions.

Questions 84

Which CLI mode must be used to configure the BGP keychain in Cisco IOS XR software?

Options:
A.

global configuration mode

B.

routing configuration mode

C.

BGP neighbor configuration

D.

mode BGP address-family configuration mode

Questions 85

350-501 Question 85

Refer to the exhibit. A network support engineer for ASN 65502 receives a technical support ticket from a customer in ASN 65503 who reports that an eBGP session is down. The engineer determines that the peering failed after a recent change to the device at 192.168.26.2. EDGE-GW-1 must establish an eBGP session with the peering router 192.168.26.2. Which configuration establishes this session?

Options:
A.

configure terminal

no router bgp 65502

router bgp 65503

neighbor 192.168.26.2 remote-as 65503

address-family ipv4

neighbor 192.168.26.2 activate

end

B.

configure terminal

router bgp 65502

address-family ipv4

neighbor 192.168.26.2 activate

end

C.

configure terminal

no router bgp 65502

router bgp 65503

neighbor 192.168.26.2 remote-as 65123

address-family ipv4

neighbor 192.168.26.2 activate

end

D.

configure terminal

router bgp 65502

no neighbor 192.168.26.2 remote-as 65503

neighbor 192.168.26.2 remote-as 65123

address-family ipv4

neighbor 192.168.26.2 activate

end

Questions 86

Refer to the exhibit:

350-501 Question 86

An engineer is preparing to implement data plane security configuration.

Which statement about this configuration is true?

Options:
A.

Router 1 drops all traffic with a local-preference set to 150

B.

All traffic is dropped

C.

All traffic to 192.168.1.0/24 is dropped

D.

Router 1 and Router 2 advertise the route to 192.0.2.0/24 to all BGFD peers.

Questions 87

Refer to the exhibit:

350-501 Question 87

P3 and PE4 are at the edge of the service provider core and serve as ABR routers Aggregation areas are on either side of the core.

Which statement about the architecture is true?

Options:
A.

If each area is running its own IGP. the ABR routers must redistribute the IGP routing table into BGP

B.

To support seamless MPLS. TDP must be used as the label protocol

C.

If each area is running its own IGP. BGP must provide an end-to-end MPLS LSP

D.

To support seamless MPLS, the BGP route reflector feature must be disabled

Questions 88

Drag and drop the LDP features from the left onto the correct usages on the right.

350-501 Question 88

Options:
Questions 89

Refer to the exhibit:

350-501 Question 89

R1 is connected to two service providers and is under a DDoS attack Which statement about this design is true if uRPF in strict mode is configured on both interfaces'?

Options:
A.

R1 accepts source addresses on interface gigabitethernet0/1 that are private addresses

B.

R1 permits asymmetric routing as long as the AS-RATH attribute entry matches the connected AS

C.

R1 drops destination addresses that are routed to a null interface on the router

D.

R1 drops all traffic that ingresses either interface that has a FIB entry that exits a different interface

Questions 90

How can shared services in an MPLS Layer 3 VPN provide Internet access to the customers of a central service provider?

Options:
A.

The CE router can establish a BGP peering to a PE router and use the PE device to reach the Internet

B.

Route distinguishes are used to identify the routes that CEs can use to reach the Internet

C.

The customer VRF uses route targets to import and export routes to and from a shared services VRF

D.

Static routes on CE routers allow route leakage from a PE global routing table

Exam Code: 350-501
Certification Provider: Cisco
Exam Name: Implementing and Operating Cisco Service Provider Network Core Technologies (350-501 SPCOR)
Last Update: Dec 15, 2025
Questions: 547