Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2 practice questions

237 free questions with answers and explanations.

Practice test
  1. 201.A network engineer needs to monitor the wireless client count, signal strength (RSSI), and data rates on an access point (AP) in real-time. The AP is managed by a Cisco Wireless LAN Controller (WLC). Which Cisco wireless assurance feature, integrated with DNA Center, provides this granular, real-time client-centric data?Network Assurance
  2. 202.An administrator needs to implement Encapsulated Remote SPAN (ERSPAN) to capture traffic from a server connected to a Cisco Catalyst switch in a branch office and send it to a centralized monitoring tool in the data center, across a Layer 3 WAN link. Which of the following is a key characteristic of ERSPAN that enables this functionality?Network Assurance
  3. 203.A network operations team is managing a virtualized data center with numerous virtual machines. They need to analyze network traffic patterns and identify potential bottlenecks or security threats between VMs, even when they reside on the same physical host and communicate via the virtual switch. Which virtual switching feature enables the capture and analysis of this intra-host VM traffic?Virtualization
  4. 204.A multinational corporation is expanding its network infrastructure globally and needs to establish secure, isolated communication channels between its various regional offices over a shared public network. Each regional office requires its own dedicated routing and forwarding policies, and the solution must be highly scalable to accommodate future growth. Which network virtualization technology is best suited for this large-scale, multi-site Layer 3 VPN requirement?Virtualization
  5. 205.A data center administrator is deploying several virtual machines (VMs) that require high bandwidth and low latency connectivity to storage and other VMs. To optimize performance and reduce CPU overhead on the hypervisor, which type of virtual network interface card (vNIC) should be configured for these critical VMs?Virtualization
  6. 206.A network engineer is troubleshooting a connectivity issue between two virtual machines (VMs) that are configured in different subnets but reside on the same hypervisor. The VMs are connected to a standard virtual switch. They can ping other VMs in their respective subnets but cannot ping each other. Which configuration element is most likely missing or incorrect?Virtualization
  7. 207.A data center operator is leveraging network function virtualization (NFV) to deploy various network services as virtual machines (VMs) on commercial off-the-shelf (COTS) servers. The operator needs to ensure that these virtual network functions (VNFs), such as firewalls and load balancers, can dynamically scale up or down based on demand. Which characteristic of NFV enables this elasticity?Virtualization
  8. 208.A cloud provider is offering private cloud services to multiple enterprises, each requiring their own isolated network infrastructure, including dedicated IP address spaces, routing policies, and security controls, all running on a shared physical data center. Which data path virtualization technology provides the necessary isolation and multi-tenancy at a large scale?Virtualization
  9. 209.A network engineer is configuring a Cisco Nexus 1000V distributed virtual switch. Which component is responsible for providing the control plane functionality, centralizing management, and enabling advanced networking features across multiple hypervisors?Virtualization
  10. 210.A network engineer is implementing a virtualized data center using a Cisco Nexus 1000V virtual switch. The engineer needs to configure security policies, QoS settings, and monitoring features consistently across all ESXi hosts where the 1000V is deployed. Which component of the Cisco Nexus 1000V architecture is primarily responsible for centralizing the control plane and management plane functions?Virtualization
  11. 211.A network engineer is designing a new data center network for a multi-tenant environment. Each tenant requires complete isolation of their routing tables and forwarding paths, even if they share the same physical infrastructure. Which virtualization technology is best suited to meet this requirement for Layer 3 isolation?Virtualization
  12. 212.A network engineer is designing a highly available data center network using Cisco Nexus switches. The design requires multiple physical links between two Nexus switches to be aggregated into a single logical channel, providing increased bandwidth and redundancy. Which device virtualization technology allows for this aggregation while ensuring full active-active forwarding and loop prevention?Virtualization
  13. 213.A cloud provider offers multi-tenant services where each tenant requires a dedicated virtual routing instance that is entirely isolated from other tenants, including separate routing tables, interfaces, and forwarding information bases. The provider uses Cisco IOS XE routers. Which feature should be configured to achieve this level of isolation?Virtualization
  14. 214.A network security team is implementing a virtual firewall solution within a data center to segment traffic between different application tiers (e.g., web, application, database). They need to ensure that the virtual firewall can inspect traffic between VMs residing on the same hypervisor without forcing the traffic out to a physical firewall. Which virtual switching capability allows for this 'Hairpinning' or 'Inter-VM' traffic inspection?Virtualization
  15. 215.A network architect is designing a virtualized data center environment where virtual machines (VMs) on different hypervisors need to communicate over a shared Layer 2 segment, but the underlying physical network is routed at Layer 3. Which data path virtualization technology is commonly used to extend Layer 2 domains over a Layer 3 underlay?Virtualization
  16. 216.A network administrator is troubleshooting connectivity issues between virtual machines (VMs) hosted on different hypervisors, all connected to a distributed virtual switch (DVS). The DVS spans multiple physical hosts. Which component of the DVS is responsible for forwarding traffic between VMs on different hosts and connecting them to the external physical network?Virtualization
  17. 217.An enterprise is migrating its legacy physical load balancers to a virtualized environment to reduce hardware costs and increase deployment flexibility. They need to ensure that the new virtual load balancers can distribute traffic efficiently across a pool of web servers, perform health checks, and provide SSL offloading capabilities. Which type of virtualized network function (VNF) fulfills these requirements?Virtualization
  18. 218.A security engineer is tasked with segmenting network traffic for different applications deployed on the same physical server within a virtualized environment. Each application requires its own dedicated firewall policies. Which virtualized network component can provide this granular, per-application firewalling without deploying multiple physical appliances?Virtualization
  19. 219.A network engineer is configuring a Cisco Nexus switch to logically separate network traffic for different tenants while sharing the same physical hardware. Which virtualization technology is most appropriate for this requirement?Virtualization
  20. 220.A company is deploying a new data center and needs to implement a network virtualization solution that allows for overlapping IP addresses between different customer segments, while maintaining full isolation at Layer 3. Which technology best facilitates this requirement?Virtualization
  21. 221.A network architect is deploying a new virtualized firewall cluster that needs to handle high traffic throughput and provide stateful inspection for multiple security zones. To ensure high availability and efficient resource utilization, which virtualization concept should be applied to the firewall instances?Virtualization
  22. 222.A network engineer is configuring a virtual switch on a hypervisor. The goal is to ensure that virtual machines (VMs) connected to this virtual switch can only communicate with other VMs within the same virtual network segment, and cannot access other virtual network segments or the physical network directly, even if they are on the same physical host. Which virtual switching concept describes this type of isolated Layer 2 forwarding?Virtualization
  23. 223.A network administrator is configuring 802.1X on a Cisco switch port connected to an IP phone, which then connects to a PC. The administrator wants both the IP phone and the PC to authenticate independently and receive appropriate network access. Which 802.1X feature should be enabled to support this scenario?Security
  24. 224.A network administrator needs to secure communication between two directly connected switches in a data center to prevent unauthorized devices from intercepting or tampering with traffic on that specific link. Which security protocol is best suited for encrypting and authenticating traffic at Layer 2?Security
  25. 225.A company requires all network device configurations to be backed up nightly. Additionally, they need to track who made what changes and when. This tracking information must be stored on a centralized server for compliance and auditing. Which AAA component is responsible for recording these specific details?Security
  26. 226.A network architect is designing a secure remote access solution for external partners to access specific internal web applications. The solution needs to be clientless, leverage existing web browsers, and provide basic encryption. Which VPN technology best fits these requirements?Security
  27. 227.A network security administrator is analyzing traffic patterns to identify potential threats. They observe a significant increase in UDP traffic on port 161 destined for network devices, originating from an unauthorized internal host. This traffic is indicative of an attempt to gather information about network devices. Which type of threat is most likely occurring?Security
  28. 228.A network engineer is deploying a new site-to-site VPN tunnel between two branch offices using IPsec. The security policy requires that the data integrity of the packets is ensured, but confidentiality is not strictly necessary for all traffic types. Which IPsec component is primarily responsible for providing data integrity without necessarily encrypting the data payload?Security
  29. 229.A company is implementing REST API security for its internal microservices architecture. They decide to use OAuth 2.0 for delegated authorization. After a user successfully authenticates with an Identity Provider (IdP) and grants consent, the client application receives an access token. What is the primary purpose of this access token?Security
  30. 230.A network engineer is troubleshooting a FlexVPN spoke that fails to build a dynamic IPsec tunnel to the hub. The engineer verifies that IKEv2 is enabled, the crypto keyring is correctly configured with the hub's public key, and the IKEv2 profile points to the correct keyring. However, the tunnel still fails to establish. Upon inspection, it is found that the IKEv2 proposal does not match between the spoke and the hub. Which parameter within the IKEv2 proposal is crucial for agreeing on the encryption algorithm?Security
  31. 231.A network security team is implementing a Zero Trust architecture. They are evaluating existing security controls and trying to determine which principle best aligns with the 'never trust, always verify' philosophy. Which statement accurately reflects a core principle of Zero Trust?Security
  32. 232.A network architect is designing a secure remote access solution for employees who need to connect to the corporate network from various locations using their personal devices. The solution must support full network layer access to internal resources, enforce strong authentication, and be highly scalable. Which VPN technology is best suited for this scenario, allowing clients to establish a secure tunnel to the corporate network?Security
  33. 233.A network security engineer is configuring a Cisco router to protect its control plane from denial-of-service attacks by rate-limiting traffic destined for the router's CPU. Which of the following mechanisms should be used to achieve this goal?Security
  34. 234.A network engineer is configuring a DMVPN solution with multiple spokes connecting to a single hub router. The requirement is for spokes to establish direct IPsec tunnels with each other for optimal data path once the initial tunnel to the hub is established. Which NHRP feature enables spoke-to-spoke direct tunnels?Security
  35. 235.A network security engineer is configuring a Cisco router to protect its CPU from excessive traffic destined to the control plane, such as BGP updates, OSPF hellos, and SSH login attempts. The goal is to prevent denial-of-service attacks targeting the router's control plane resources. Which security feature should be implemented?Security
  36. 236.A network security team is implementing a new policy to restrict administrative access to network devices. They want to ensure that only authorized personnel can log in and that their actions are recorded for auditing purposes. Which component of AAA is primarily responsible for determining what an authenticated user is permitted to do?Security
  37. 237.A company is implementing a Zero Trust security model. They are evaluating existing security controls to align with the 'Never Trust, Always Verify' principle. Which of the following best represents an implementation of this principle?Security