Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2 practice questions

237 free questions with answers and explanations.

Practice test
  1. 151.A network engineer is troubleshooting intermittent connectivity issues for users connecting remotely to the corporate network via a VPN. Users report slow application response times and occasional disconnections, particularly when transferring large files. The engineer needs to identify potential bottlenecks and packet loss across the VPN tunnel and the underlying internet path. Which network assurance tool or technique would provide the MOST relevant insights?Architecture
  2. 152.A multinational corporation is expanding its network infrastructure into several new regions, requiring segregated network environments for different business units while reusing the same IP address space in each region to simplify design and conserve addresses. The network team needs a solution that provides full routing table isolation between these environments without deploying separate physical routers or VLANs for each. Which network virtualization technology is best suited for this requirement?Architecture
  3. 153.A company is implementing a new wireless network and requires strong authentication for all users connecting to the Wi-Fi. The solution must integrate with the existing corporate Active Directory for user credentials and provide dynamic VLAN assignment based on user groups. Which IEEE 802.1X component is responsible for authenticating the client device against the authentication server?Security
  4. 154.A network security team is implementing a solution to prevent lateral movement of threats within its campus network. The goal is to isolate different user groups and critical servers from each other, even if they reside on the same subnet, without requiring extensive VLAN reconfigurations or physical network changes. Which technology is most effective for achieving this granular level of isolation?Architecture
  5. 155.A network engineer is troubleshooting a site-to-site IPsec VPN tunnel between two Cisco routers. Users at the remote site are unable to access resources at the main site, but the phase 1 IKEv2 security association (SA) is established. Upon checking the crypto isakmp sa command output, the engineer notices that the phase 2 IPsec SAs are not being established. Which component is most likely misconfigured, preventing the phase 2 SA establishment?Security
  6. 156.A network engineer is configuring a Cisco Catalyst switch to implement MACsec (802.1AE) between two switches to provide hop-by-hop encryption and integrity for all traffic on the link. After configuring the necessary MKA (MACsec Key Agreement) and enabling MACsec on the interfaces, the engineer notices that the MACsec secure channel is not establishing. Which of the following is a common reason for MACsec failure between two switches?Security
  7. 157.A large e-commerce company is experiencing inconsistent application performance during peak shopping seasons. The network team suspects that the issue stems from inefficient traffic management and lack of granular visibility into application flows across its distributed data centers and public cloud infrastructure. Which network architecture principle, when properly implemented, would most effectively address these challenges?Architecture
  8. 158.A company is integrating its custom-built internal applications with a new identity management system using REST APIs. The security team requires a mechanism to ensure that API requests are tamper-proof and that the identity of the client making the request can be verified without needing a direct database lookup for every request. Which security token standard is best suited for this requirement, providing a digitally signed, self-contained token?Security
  9. 159.A network operations team is tasked with implementing a network assurance solution that can proactively identify performance degradation, detect security threats, and provide comprehensive visibility across the entire enterprise network, including both on-premises and cloud resources. Which of the following best describes the capabilities required from this solution?Architecture
  10. 160.A network security engineer is implementing Control Plane Policing (CoPP) on a Cisco router to protect the router's CPU from excessive traffic destined for the control plane. Which type of traffic should be classified and rate-limited to mitigate reconnaissance attacks like port scans or excessive SSH connection attempts?Security
  11. 161.A network administrator is configuring a new enterprise campus network that needs to support both wired and wireless clients. The design requires a consolidated management platform that can automate device provisioning, enforce consistent access policies, and provide unified troubleshooting for all connected devices. Which Cisco solution is purpose-built to deliver these capabilities?Architecture
  12. 162.A network engineer is configuring a site-to-site IPsec VPN tunnel between two Cisco routers. The engineer wants to ensure that the integrity of the data is maintained and that the data is encrypted during transit. Which two components are essential to achieve these goals within the IPsec transform set?Security
  13. 163.A network architect is designing a new branch office network that needs to securely connect to the corporate data center over the public internet. The design requires a solution that can dynamically establish secure tunnels between multiple spoke sites and a central hub, as well as directly between spoke sites if needed, without requiring pre-configuration of every possible spoke-to-spoke tunnel. Which VPN technology best fits these requirements?Security
  14. 164.A network administrator is configuring a new switch to enhance network security. The administrator wants to prevent unauthorized devices from connecting to specific switch ports and ensure that only devices with known MAC addresses can access the network. Which security feature should be implemented on the switch ports to achieve this goal?Security
  15. 165.A network architect is designing a new campus fabric using Cisco SD-Access. The design specifies that the control plane for the fabric should maintain a mapping system for all endpoints within the fabric, allowing for location-independent addressing and efficient routing. Which specific SD-Access node role is responsible for this function?Architecture
  16. 166.A network engineer is deploying a new Wi-Fi 6 (802.11ax) network for a high-density office building. The design requires centralized control, seamless roaming for users across floors, and efficient spectrum management. Which WLAN deployment model best fits these requirements?Architecture
  17. 167.A network security administrator is configuring AAA for device administration on a Cisco router. The administrator wants to ensure that all commands executed by an authenticated user are logged for audit purposes, including the command itself, the user who executed it, and the time of execution. Which AAA component is responsible for collecting and reporting this type of granular command execution information?Security
  18. 168.A network security team is implementing infrastructure security measures on a Cisco router. They want to protect the router's CPU from excessive traffic during a denial-of-service (DoS) attack, specifically targeting management protocols like Telnet, SSH, and SNMP. Which security mechanism should be configured to rate-limit and filter these types of packets destined for the router's control plane?Security
  19. 169.A company is implementing a Zero Trust architecture for its internal network. Which core principle of Zero Trust mandates that all network traffic, regardless of its source or destination within the network, must be authenticated and authorized before access is granted?Security
  20. 170.A network architect is designing a secure remote access solution for mobile users that need to access internal resources. The solution must support various client operating systems, be easy to configure for end-users, and provide full network layer connectivity. Which VPN technology is best suited for this requirement, leveraging standard web browsers for initial access and then establishing a full tunnel?Security
  21. 171.A network architect is designing a new campus network for a large university. The design requires a highly scalable and resilient solution that can support thousands of wired and wireless endpoints, provide consistent policy enforcement, and simplify network operations across multiple buildings. Which architectural model best meets these requirements?Architecture
  22. 172.A network security team is designing a network segmentation strategy for a university campus. The goal is to isolate student, faculty, and guest traffic, and to prevent lateral movement of threats between these groups, even if a compromise occurs within one segment. Which network security concept is most effective for achieving this granular isolation?Architecture
  23. 173.A network engineer is configuring a FlexVPN solution to provide secure remote access for mobile users. The design requires that remote users authenticate using username and password against an external RADIUS server, and that the VPN client automatically receives an IP address from a pool on the headend router. Which IKEv2 configuration element is primarily responsible for defining the authentication method and addressing parameters for these remote access clients?Security
  24. 174.A global enterprise is evaluating options for connecting its branch offices to its data centers and cloud resources. The company needs to ensure optimal application performance, improve security, and reduce operational costs. Which solution provides intelligent path selection, centralized management, and application-aware routing capabilities to meet these goals?Architecture
  25. 175.A network architect is designing a network for a new branch office that will host a small number of users and critical IoT devices. The design requires robust security for both wired and wireless access, simplified management, and the ability to integrate with the corporate network's Identity Services Engine (ISE) for centralized authentication. Which network security and access control mechanism is best suited for this scenario?Architecture
  26. 176.A network engineer is configuring a FlexVPN solution on a Cisco ASR router. The design requires dynamic spoke-to-spoke tunnel establishment and support for multiple authentication methods. Which IKEv2 profile component is responsible for defining the authentication method used by the IKEv2 peers, such as pre-shared keys or digital certificates?Security
  27. 177.A network security team is deploying MACsec (802.1AE) between two switches to provide hop-by-hop encryption and integrity protection for all traffic traversing the link. Which key management protocol is typically used with MACsec to establish and maintain the secure session keys?Security
  28. 178.A network administrator is configuring AAA (Authentication, Authorization, and Accounting) on a Cisco router. The administrator wants to ensure that all administrative access attempts (Telnet, SSH, console) are logged to a central server, including who logged in, when, and what commands they executed. Which AAA component is responsible for collecting and sending this operational data?Security
  29. 179.A network architect is designing a wireless LAN for a new high-rise office building. The design must support high-density user environments, provide seamless roaming, and ensure robust security for corporate and guest access. Which WLAN deployment model is most appropriate for these requirements?Architecture
  30. 180.A network administrator is configuring a new Cisco switch and wants to ensure that only authorized devices can connect to specific switch ports. The goal is to prevent unauthorized devices from gaining network access by spoofing MAC addresses, even if they are known. Which feature should be implemented to achieve this, specifically tying a device's MAC address to its first learned port and preventing it from being used on other ports?Security
  31. 181.A network engineer is designing a new campus network for a university. The design requires a scalable and flexible solution that can segment student, faculty, and guest traffic while providing automated policy enforcement and simplified network management. Which network architecture best meets these requirements?Architecture
  32. 182.A network engineer is implementing a REST API security strategy for a new application hosted on a Cisco API Gateway. The goal is to ensure that only authorized clients can access specific API endpoints and that the integrity of the API requests is maintained. The solution must leverage industry-standard tokens for client authentication and authorization. Which security mechanism is most appropriate for authenticating clients accessing the REST API?Security
  33. 183.A network engineer is analyzing performance degradation on specific network links. They need to monitor one-way delay, one-way jitter, and one-way packet loss for UDP traffic between two routers. Which IP SLA operation type, along with its specific configuration, would provide these detailed one-way metrics?Network Assurance
  34. 184.A network engineer configures an Embedded Event Manager (EEM) applet to automatically restart a process if it fails. The applet is triggered when a syslog message containing 'PROCESS_FAILURE' is detected. Which EEM event detector type should be used?Network Assurance
  35. 185.A network engineer is troubleshooting intermittent connectivity issues for a critical application server. The engineer suspects packet loss or excessive latency between the server and its gateway. Which IP SLA operation type would be most effective for continuously monitoring these specific metrics?Network Assurance
  36. 186.A network operations team uses Cisco DNA Center Assurance to monitor the health of their enterprise network. They observe a sudden drop in the 'Client Health Score' for a specific building, accompanied by alerts indicating high retransmission rates and low signal-to-noise ratio (SNR) for wireless clients in that area. Which specific DNA Center Assurance capability allows the team to quickly identify clients experiencing these issues and view their detailed connectivity metrics?Network Assurance
  37. 187.A network engineer needs to monitor the network for unauthorized access attempts and security policy violations. The requirement is to collect detailed records of every IP conversation, including source/destination IP addresses, ports, protocols, and byte/packet counts, to feed into a security information and event management (SIEM) system. Which technology provides this type of data?Network Assurance
  38. 188.A network engineer wants to automatically execute a series of commands on a router whenever a specific syslog message indicating an interface flapping event is detected. The commands should disable the interface, wait 10 seconds, and then re-enable it. Which feature allows for this automated, event-driven response?Network Assurance
  39. 189.A network technician is troubleshooting a client's inability to connect to a specific internal server. The technician suspects a potential firewall issue blocking the traffic. Which troubleshooting step is generally the LEAST effective for quickly diagnosing a firewall blocking issue in this scenario?Network Assurance
  40. 190.A network engineer wants to capture all traffic between two specific hosts connected to different access layer switches (Switch A and Switch B) in the same building. The captured traffic needs to be sent to a dedicated analysis port on a third switch (Switch C) in the data center for deep packet inspection. All switches are Cisco Catalyst 9300 series. Which SPAN variant is the most appropriate for this scenario?Network Assurance
  41. 191.A network administrator needs to capture traffic on a Cisco Catalyst 9300 switch to analyze a performance issue affecting a server connected to an access port. The server's traffic must be mirrored to a monitoring station connected to a different port on the same switch, without impacting the switch's forwarding performance. Which feature should the administrator configure?Network Assurance
  42. 192.A network operations team uses Cisco DNA Center Assurance to monitor the health of their enterprise network. They notice a 'Client Experience' score for a specific location is consistently low, indicating poor Wi-Fi performance for users. Which of the following is NOT a direct metric or factor DNA Center Assurance typically uses to calculate the Client Experience score?Network Assurance
  43. 193.A network engineer wants to monitor the CPU utilization of a Cisco router over time and receive an alert if it exceeds 80% for more than 5 minutes. Which SNMP operation is best suited for setting up this proactive monitoring and alerting mechanism?Network Assurance
  44. 194.A network administrator needs to monitor the real-time resource utilization (CPU, memory) of several Cisco routers and switches across the enterprise network and wants to receive immediate alerts if any device exceeds predefined thresholds. Which network assurance technology is best suited for this requirement?Network Assurance
  45. 195.A network engineer is troubleshooting a persistent issue where users in a specific VLAN intermittently experience slow application performance when accessing a server in another VLAN. The engineer suspects a routing loop or asymmetric routing. Which network assurance technology can provide the necessary hop-by-hop path visibility and latency measurements to pinpoint the problem?Network Assurance
  46. 196.A network security team requires detailed visibility into all network conversations to detect anomalous traffic patterns and potential security breaches. They need to analyze source/destination IP addresses, ports, protocols, and byte/packet counts for every flow. Which network assurance technology is best suited for this requirement?Network Assurance
  47. 197.A network engineer wants to implement RSPAN to monitor traffic flowing between two switches, SwitchA and SwitchB, located in different wiring closets. The monitoring station is connected to SwitchC. Which of the following is a mandatory requirement for RSPAN to function correctly across multiple switches?Network Assurance
  48. 198.A network technician is troubleshooting a client's inability to connect to a specific internal application server. The client reports that other network resources are accessible, but this particular application consistently times out. The technician suspects a firewall in the path might be blocking the connection. Which troubleshooting step should the technician perform first to confirm or deny the firewall as the cause?Network Assurance
  49. 199.A network operations team uses Cisco DNA Center Assurance to monitor wireless network health. They receive an alert indicating 'High Interference' for an access point in a specific area. Which troubleshooting action should the team prioritize first based on this alert?Network Assurance
  50. 200.A network security analyst needs to capture traffic from a specific VLAN on a Cisco Catalyst 9300 switch and send it to an intrusion detection system (IDS) connected to another port on the *same* switch. The goal is to monitor all traffic entering and leaving that VLAN. Which SPAN configuration is required?Network Assurance