Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Cisco 352-011 Practice Exam with Questions & Answers

Questions 1

Refer to the exhibit

352-011 Question 1

company xyz has 150 branch location across the U.S. Each branch is connected to two aggregation router one router in each data center The network is configured with Multiple OSPF with multiple OSPF areas and the aggregation router are ABRs A requirement is to keep an optimal path to the data centers and at the same time reduce the LSA propagation and SPF recomputation during a change in any part of the network

Which design elements should be included on the aggregation router?

Options:
A.

OSPF NSSA

B.

distribute lists

C.

OSPF summarization

D.

OSPF totally stubby area

Cisco 352-011 Premium Access
Questions 2

Your customer recently acquired a company with a national WAN of 750 locations consisting of MPLS VPN-based sales, Internet-based sites and sites with direct links to regional hub sites. The existing network has MPLS VPN-based sites. Which solution ensure security and encryption across all sites to meet an audit requirement?

Options:
A.

Implement a hierarchical DMVPN-based hub-and-spoke network with IPsec encryption

B.

Migrate newly acquired sites to the MPLS VPN-based service of the parent company

C.

Implement a GETVPN-based solution across all sites with selective traffic encryption

D.

Implement a GETVPN-based solution across all sites with redundant key servers

Questions 3

An enterprise customer has a national WAN network based on DMVPN over the Internet, with sites located throughout the country. The customer has recently deployed VoIP throughout the entire network , and users report that it takes up to 2 seconds to establish a telephone call to an IP telephone at another office network. Drag and drop the root cause and the corresponding design solution from the left onto the correct targets on the right Not all options are used

352-011 Question 3

Options:
Questions 4

You are designing dual-homed active/active ISP connections from an enterprise customer for internet services, and you have recommended BGP between the customer and ISP. When three security mechanisms do you enable to secure the connection? (Choose three)

Options:
A.

uRPF is strict mode

B.

remote triggered black holes

C.

IDS

D.

GTSM

E.

Routing protocol authentication

F.

uRPF in loose mode

Questions 5

Refer to the exhibit.

352-011 Question 5

Which solution must be used to send traffic from the foreign wireless LAN controller to the anchor wireless LAN controller?

Options:
A.

Encapsulate packets into an EoIP tunnel and send them to the anchor controller

B.

Send packets from the foreign controller to the anchor controller via Layer 3 MPLS VPN or VRF-Lite

C.

Send packets from the foreign controller to the anchor controller via IPinIP or IPsec tunnel

D.

Send packets without encapsulation to the anchor controller over the routed network

Questions 6

Refer to the exhibit.

352-011 Question 6

A customer interconnected hundreds of branch offices into a single DMVPN network, with the HUB in the main data center. Due to security policies, the customer requires that the default route for all Internet traffic from the users at the branches must go through the tunnel and the only connections that are allowed to and from the branch router over the local internet circuit are the DMVPN tunnels. Which two combined actions must you take on the branch router to address these security requirements and keep the solution scalable? (Choose two)

Options:
A.

Place the WAN interface in a front-door VRF, leaving the tunnel interface in the default routing instance

B.

Protect the WAN interface by an inbound ACL that permits only IPsec-related traffic

C.

Implement a zone-based firewall that allows only IPsec-related traffic from zone UNTRUSTED to zone TRUSTED

D.

Add a host route for the public IP address of each remote branch and HUB routers that points directly to the local ISP, and add a default route that points to the tunnel

E.

Use a floating default route with the preferred path over the tunnel and a backup path over the Internet natively

Questions 7

Drag and drop the NETCONF layers on the left onto their appropriate description on the left.

352-011 Question 7

Options:
Questions 8

You are consultant network designer for a large GET VPN deployment for a large bank with International coverage. Between 1800 and 2000 remote locations connect to the central location through four hubs using an MPLS backbone and using two keys servers. The bank is concerned with security and replay attacks. Which two actions should you use to tune the GET VPN to meet the bank requirements? (Choose two)

Options:
A.

Increase the cryptographic key size.

B.

Replace unicast rekey with multicast rekey.

C.

Reduce the SAR clock interval duration

D.

Increase the TEK and KEK lifetime.

E.

Reduce the Dead Peer Detection periodic timer.

Questions 9

Refer to the exhibit.

352-011 Question 9

You are a network designer who is given these design requirements:

 Multicast services must be provided for Layer 3 VPN customers

 The same forwarding technology must be used as Layer 3 VPN unicast packets

 Replication of multicast traffic is not allowed on the ingress PE

Which multicast VPN technology conforms to the design requirements?

Options:
A.

Multipoint-to-point LDP

B.

MSDP

C.

MLDP VPN

D.

Rosen Draft using LDP

Questions 10

Which two techniques are used in an OSPF network design to slow down the distribution of topology information caused by a rapidly flapping link? (Choose two)

Options:
A.

LSA throttling

B.

SPF throttling

C.

IP event dampening

D.

Link-state incremental SPF

E.

Link-state partial SPF

Exam Code: 352-011
Certification Provider: Cisco
Exam Name: Cisco Certified Design Expert Practical Exam
Last Update: Jul 12, 2025
Questions: 249