Step2Study
IT & Technology350-401100% Free

Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2

Practice bank
237 Qs
Real exam
90 Qs
Time limit
120 min
Passing
Varies by exam form. The passing score is not published.

Exam blueprint

Architecture
15%
Virtualization
10%
Infrastructure
30%
Network Assurance
10%
Security
20%
Automation
15%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 120 min · pass 82% · 237 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2 practice test questions

Sample questions from the 237-question bank, with answers and explanations.

All questions
  1. 1. A network administrator needs to automate a recurring task on a Cisco router: every Sunday at 3:00 AM, the router should clear its BGP neighbor statistics and then send an email notification to the network operations team upon completion. This automation needs to be performed directly on the router without external scripting servers. Which Cisco feature allows for this type of on-device automation and event-driven scripting?

    Infrastructure

    • A. Cron jobs
    • B. Embedded Event Manager (EEM)
    • C. Python scripting
    • D. Guest Shell
    Show answer

    B. Embedded Event Manager (EEM)

    Embedded Event Manager (EEM) is a Cisco IOS feature that allows for on-device event detection and automation. It can monitor various events (like time-of-day, syslog messages, interface status) and trigger predefined actions, including executing CLI commands, sending email notifications, or running Tcl/Python scripts, directly on the router.

  2. 2. A network engineer is designing a new branch office network. Due to budget constraints, the branch will use a single internet connection, and all internal users need to access external resources. The design specifies that internal hosts use private IP addresses. Which network service must be configured on the branch router to allow these internal hosts to communicate with the internet?

    Infrastructure

    • A. DNS
    • B. DHCP
    • C. PTP
    • D. NAT
    Show answer

    D. NAT

    Network Address Translation (NAT) is essential when internal hosts use private IP addresses and need to communicate with the internet, which uses public IP addresses. NAT translates the private IP addresses of internal hosts into one or more public IP addresses, allowing them to access external resources.

  3. 3. A company has implemented a new VoIP system, and users are reporting dropped calls and poor audio quality, characterized by choppiness and delays. The network administrator suspects network congestion is causing these issues. Which QoS mechanism should be configured on the network devices to prioritize VoIP traffic and ensure its quality?

    Infrastructure

    • A. Traffic Shaping
    • B. Congestion Management (Queuing)
    • C. Link Fragmentation and Interleaving (LFI)
    • D. Traffic Policing
    Show answer

    B. Congestion Management (Queuing)

    Congestion Management, specifically queuing mechanisms like Low Latency Queuing (LLQ) or Weighted Fair Queuing (WFQ), is designed to prioritize critical traffic like VoIP during periods of congestion, ensuring it gets preferential treatment and reducing delay and jitter.

  4. 4. A network engineer is configuring a new Layer 3 switch to support inter-VLAN routing. The switch has several VLANs configured, and hosts in each VLAN need to communicate with hosts in other VLANs. The engineer wants to ensure that the routing process on the switch is efficient and uses the most appropriate Layer 3 forwarding mechanism for directly connected networks. Which mechanism is used by Cisco switches to perform high-speed Layer 3 forwarding between directly connected VLANs?

    Infrastructure

    • A. Fast Switching
    • B. Process Switching
    • C. Software Switching
    • D. Cisco Express Forwarding (CEF)
    Show answer

    D. Cisco Express Forwarding (CEF)

    Cisco Express Forwarding (CEF) is the most advanced and efficient Layer 3 IP forwarding mechanism used by Cisco routers and multilayer switches. It uses a Forwarding Information Base (FIB) and an adjacency table to make forwarding decisions, enabling hardware-based, high-speed routing without CPU involvement for every packet, which is crucial for inter-VLAN routing performance.

  5. 5. A network administrator is configuring a new Cisco router and needs to ensure that all internal hosts can access the internet using a single public IP address. Which NAT configuration type should be implemented?

    Infrastructure

    • A. NAT Overload (PAT)
    • B. Policy NAT
    • C. Dynamic NAT
    • D. Static NAT
    Show answer

    A. NAT Overload (PAT)

    NAT Overload, also known as Port Address Translation (PAT), allows multiple private IP addresses to be translated to a single public IP address by using different port numbers. This is the most common method for enabling internet access for an entire internal network with a limited number of public IP addresses.

  6. 6. A network engineer is troubleshooting a recently deployed application that uses UDP for real-time video streaming. Users are reporting occasional video stuttering and pixelation, indicating potential packet loss or out-of-order delivery. The engineer suspects that the network's QoS policy might not be correctly prioritizing this traffic. Which QoS mechanism is specifically designed to ensure that critical traffic, like real-time video, receives preferential treatment and is transmitted before other less critical traffic?

    Infrastructure

    • A. Weighted Fair Queuing (WFQ)
    • B. Traffic Policing
    • C. Low Latency Queuing (LLQ)
    • D. Traffic Shaping
    Show answer

    C. Low Latency Queuing (LLQ)

    Low Latency Queuing (LLQ) combines the benefits of Class-Based Weighted Fair Queuing (CBWFQ) with strict priority queuing for specific traffic classes. This ensures that delay-sensitive traffic, such as real-time video and voice, is dequeued and transmitted first, minimizing latency and jitter.

  7. 7. A network engineer is configuring a new Layer 3 routing switch to act as the default gateway for multiple VLANs. The requirement is to provide redundant default gateway functionality for end-user devices, ensuring high availability in case of a single device failure. Which First Hop Redundancy Protocol (FHRP) should be configured to meet this requirement, allowing for active/standby redundancy?

    Infrastructure

    • A. OSPF (Open Shortest Path First)
    • B. GLBP (Gateway Load Balancing Protocol)
    • C. PIM (Protocol Independent Multicast)
    • D. VRRP (Virtual Router Redundancy Protocol)
    Show answer

    D. VRRP (Virtual Router Redundancy Protocol)

    VRRP provides active/standby redundancy for default gateways, where one router acts as the master and forwards traffic, while others remain in a standby state, taking over if the master fails. This fits the requirement for high availability through active/standby operation.

  8. 8. A network engineer is troubleshooting a performance issue where a specific application's traffic experiences high latency and packet loss when traversing a congested WAN link. The application uses UDP on port 5000. The engineer needs to apply a QoS policy that marks this application's traffic with a specific DSCP value (e.g., EF for Expedited Forwarding) so that downstream devices can prioritize it. Which QoS component is responsible for identifying and marking specific traffic flows?

    Infrastructure

    • A. Classification and Marking
    • B. Congestion Avoidance
    • C. Traffic Shaping
    • D. Congestion Management
    Show answer

    A. Classification and Marking

    Classification and Marking are the initial QoS components responsible for identifying specific traffic flows (e.g., UDP port 5000) and then assigning them a QoS label, such as a DSCP value. This marking allows subsequent QoS mechanisms (like queuing) to treat the traffic appropriately according to its priority.

  9. 9. A network engineer is configuring a Layer 3 switch to act as a default gateway for multiple VLANs in a campus network. To provide high availability, the engineer wants to ensure that if the primary switch fails, another redundant Layer 3 switch can automatically take over the default gateway role with minimal disruption. Which protocol should be configured?

    Infrastructure

    • A. Border Gateway Protocol (BGP)
    • B. Link Aggregation Control Protocol (LACP)
    • C. Spanning Tree Protocol (STP)
    • D. Virtual Router Redundancy Protocol (VRRP)
    Show answer

    D. Virtual Router Redundancy Protocol (VRRP)

    Virtual Router Redundancy Protocol (VRRP) is a First Hop Redundancy Protocol (FHRP) that provides automatic default gateway failover. It allows multiple routers/switches to share a single virtual IP address and MAC address, ensuring continuous connectivity even if the primary device fails.

  10. 10. A network technician is configuring an NTP server on a Cisco router. The router needs to synchronize its clock with a reliable external time source. Which of the following commands correctly configures the router to act as an NTP client and synchronize with a server at 203.0.113.10?

    Infrastructure

    • A. ntp master 203.0.113.10
    • B. clock set 10:00:00 1 Jan 2024
    • C. ntp authenticate 203.0.113.10
    • D. ntp server 203.0.113.10
    Show answer

    D. ntp server 203.0.113.10

    The `ntp server <IP_address>` command configures a Cisco device to act as an NTP client and synchronize its clock with the specified NTP server. This is the standard and correct way to point a device to a time source.

  11. 11. A network architect is designing a wireless network for a large university campus with thousands of users and a high density of devices. The design requires centralized management, seamless roaming between access points (APs) across multiple buildings, and dynamic RF management to optimize coverage and capacity. Which wireless architecture is best suited for these requirements?

    Infrastructure

    • A. Mesh AP architecture
    • B. Controller-based AP architecture
    • C. Autonomous AP architecture
    • D. Cloud-managed AP architecture
    Show answer

    B. Controller-based AP architecture

    A controller-based AP architecture provides centralized management, seamless roaming, and dynamic RF management by offloading intelligence from individual access points to a centralized Wireless LAN Controller (WLC). This is ideal for large, dense deployments like a university campus.

  12. 12. A network engineer is configuring a new Cisco Catalyst 9300 switch. The switch needs to support multiple VLANs and ensure that all inter-VLAN routing is performed efficiently in hardware. Which technology is crucial for achieving high-performance inter-VLAN routing on this switch?

    Infrastructure

    • A. Hot Standby Router Protocol (HSRP)
    • B. Spanning Tree Protocol (STP)
    • C. Cisco Express Forwarding (CEF)
    • D. VLAN Trunking Protocol (VTP)
    Show answer

    C. Cisco Express Forwarding (CEF)

    Cisco Express Forwarding (CEF) is an advanced Layer 3 IP switching technology that enables faster packet forwarding by storing forwarding information (FIB) and adjacency tables in hardware (ASICs), significantly improving inter-VLAN routing performance.

  13. 13. A network engineer is configuring a Cisco Catalyst 9300 switch and needs to ensure that all directly connected Cisco IP phones receive their configuration and firmware updates from a specific TFTP server. The engineer wants the switch to automatically provide the TFTP server IP address and other voice-related parameters to the phones upon connection. Which feature should be configured on the switch?

    Infrastructure

    • A. IP Helper Address
    • B. CDP with LLDP-MED
    • C. Voice VLAN with DHCP Option 150
    • D. DHCP Relay
    Show answer

    C. Voice VLAN with DHCP Option 150

    Configuring a Voice VLAN with DHCP Option 150 allows the switch to inform IP phones about the TFTP server's IP address. When an IP phone connects, the switch places it into the voice VLAN, and the DHCP server configured for that VLAN provides the necessary voice-specific options, including Option 150 for the TFTP server.

  14. 14. A network administrator is troubleshooting an intermittent connectivity issue for several devices in a specific VLAN. The devices are connected to a Cisco Catalyst 9300 switch. The administrator suspects a broadcast storm might be occurring. Which Layer 2 feature, when enabled, can help mitigate the impact of excessive broadcast traffic?

    Infrastructure

    • A. BPDU Guard
    • B. PortFast
    • C. VLAN Tagging (802.1Q)
    • D. Storm Control
    Show answer

    D. Storm Control

    Storm Control is a Layer 2 feature that monitors incoming traffic levels on a port and drops packets when a configured threshold for broadcast, multicast, or unknown unicast traffic is exceeded. This directly mitigates broadcast storms.

  15. 15. A network engineer needs to configure a Cisco router to translate internal private IP addresses to a single public IP address when accessing the internet. This setup should allow multiple internal hosts to share the same public IP. Which NAT type should be configured?

    Infrastructure

    • A. PAT (Port Address Translation)
    • B. Dynamic NAT
    • C. NAT64
    • D. Static NAT
    Show answer

    A. PAT (Port Address Translation)

    PAT (Port Address Translation), also known as NAT Overload, allows multiple internal private IP addresses to share a single public IP address by using different source port numbers. This is the most common form of NAT used for internet access in small to medium-sized networks.

  16. 16. A large-scale data center network uses OSPF as its interior gateway protocol. Due to an increase in multicast video streaming services, the network team needs to ensure efficient delivery of multicast traffic to specific receivers across the OSPF domain. The receivers dynamically join and leave multicast groups. Which multicast routing protocol should be configured to support this sparse mode multicast environment?

    Infrastructure

    • A. Multicast Source Discovery Protocol (MSDP)
    • B. PIM-Sparse Mode (PIM-SM)
    • C. Distance Vector Multicast Routing Protocol (DVMRP)
    • D. PIM-Dense Mode (PIM-DM)
    Show answer

    B. PIM-Sparse Mode (PIM-SM)

    PIM-Sparse Mode (PIM-SM) is designed for environments where multicast receivers are numerous but sparsely distributed across the network, and they dynamically join and leave groups. It explicitly builds distribution trees from receivers back to the Rendezvous Point (RP) and then to the source, making it efficient for sparse multicast traffic.

  17. 17. A network architect is designing a wireless network for a large university campus with thousands of users. The design requires centralized control over access points, seamless roaming for students and faculty across buildings, and simplified management of wireless policies and security. Which wireless architecture best meets these requirements?

    Infrastructure

    • A. Autonomous AP architecture
    • B. Controller-based architecture
    • C. Cloud-managed AP architecture
    • D. Mesh AP architecture
    Show answer

    B. Controller-based architecture

    A controller-based wireless architecture uses a centralized Wireless LAN Controller (WLC) to manage all access points (APs). This provides centralized control, enables seamless Layer 2 and Layer 3 roaming, and simplifies the deployment and management of wireless policies and security across a large campus.

  18. 18. A network administrator is troubleshooting slow network performance for users connected to a specific access layer switch. They suspect a Layer 2 loop. Which of the following commands would best help identify the MAC addresses being learned on multiple ports of that switch?

    Infrastructure

    • A. show cdp neighbors detail
    • B. show ip route
    • C. show interface status
    • D. show mac address-table
    Show answer

    D. show mac address-table

    The 'show mac address-table' command displays the MAC address table, showing which MAC addresses are learned on which interfaces. This is crucial for identifying duplicate MAC addresses on different ports, which is a strong indicator of a Layer 2 loop.

  19. 19. A network engineer troubleshooting a remote branch office router notices that the router's logs are not being sent to the central syslog server. Upon investigation, they find that the router's clock is significantly out of sync, displaying a date several years in the past. Which of the following is the most likely reason for the syslog messages not being received by the central server, assuming the server has correct time window configurations?

    Infrastructure

    • A. High CPU utilization on the router causing log drops.
    • B. Incorrect logging buffer size on the router.
    • C. The syslog server is configured to drop messages with old timestamps.
    • D. Missing 'logging trap' configuration on the router.
    Show answer

    C. The syslog server is configured to drop messages with old timestamps.

    Many syslog servers are configured with time window filters to prevent processing or storing logs with timestamps significantly outside the current time, especially older than a few minutes or hours. If the router's clock is years out of sync, the syslog server would likely discard these messages as invalid or too old, even if basic connectivity exists and the 'logging trap' is configured.

  20. 20. A network engineer is configuring a new Cisco router that will serve as the default gateway for a critical server farm. To ensure high availability, the engineer needs to implement a solution where two routers can act as a single virtual router, sharing a virtual IP address and MAC address. If the primary router fails, the secondary router should automatically take over the active role without any disruption to the servers. Which Layer 3 redundancy protocol should be configured?

    Infrastructure

    • A. VRF-Lite (Virtual Routing and Forwarding Lite)
    • B. HSRP (Hot Standby Router Protocol)
    • C. BGP (Border Gateway Protocol)
    • D. OSPF (Open Shortest Path First)
    Show answer

    B. HSRP (Hot Standby Router Protocol)

    HSRP (Hot Standby Router Protocol) is a Cisco proprietary FHRP (First Hop Redundancy Protocol) that allows two or more routers to share a single virtual IP address and MAC address, providing transparent failover for end devices when the active router fails.

  21. 21. A network security team needs to monitor traffic traversing a critical server farm for anomalies and potential security threats. The requirement is to capture all ingress and egress traffic for specific VLANs on a core switch without disrupting the normal traffic flow. The captured traffic needs to be sent to an intrusion detection system (IDS) located on a different switch in the same data center. Which monitoring feature should be configured?

    Infrastructure

    • A. IPFIX (IP Flow Information Export)
    • B. RSPAN (Remote SPAN)
    • C. Local SPAN
    • D. ERSPAN (Encapsulated Remote SPAN)
    Show answer

    B. RSPAN (Remote SPAN)

    RSPAN (Remote SPAN) allows traffic from source ports or VLANs on one switch to be mirrored to a destination port on a different switch within the same network. This is achieved by dedicating a VLAN as an RSPAN VLAN to carry the mirrored traffic between switches, making it suitable for sending captured traffic to an IDS on another switch.

  22. 22. A company is experiencing intermittent voice quality issues (jitter and packet loss) on its VoIP calls, especially during peak network usage. The network uses a combination of Cisco Catalyst switches and routers. Which QoS mechanism, when implemented end-to-end, would be most effective in ensuring preferential treatment for voice traffic over other data traffic?

    Infrastructure

    • A. Rate-limiting on all access ports
    • B. Traffic shaping on WAN links
    • C. Implementing a larger MTU size across the network
    • D. Classification and Marking followed by Congestion Management and Avoidance
    Show answer

    D. Classification and Marking followed by Congestion Management and Avoidance

    Effective QoS for VoIP requires a multi-step approach. Classification and Marking identify and tag voice packets. Congestion Management (e.g., queuing mechanisms like LLQ) prioritizes these marked packets, while Congestion Avoidance (e.g., WRED) drops lower-priority traffic proactively to prevent congestion. This end-to-end strategy ensures voice traffic receives preferential treatment.

  23. 23. A network engineer is deploying a new service that requires precise, deterministic measurement of end-to-end delay and jitter between two Cisco routers. The measurements need to be active, synthetic, and scheduled to run periodically to monitor the service level agreement (SLA). Which network service should the engineer configure on the routers to achieve these active performance measurements?

    Infrastructure

    • A. NetFlow
    • B. SNMP Traps
    • C. IP SLA
    • D. Remote SPAN (RSPAN)
    Show answer

    C. IP SLA

    IP SLA (IP Service Level Agreement) is a Cisco IOS feature that allows for active monitoring of network performance by generating and analyzing synthetic traffic. It can measure various metrics, including end-to-end delay, jitter, and packet loss, crucial for verifying SLAs and troubleshooting performance issues.

  24. 24. A network engineer is configuring a new Cisco router to provide Internet access for a small office. The office uses private IPv4 addresses (10.0.0.0/8) internally, and the router has a single public IPv4 address assigned to its WAN interface. The engineer needs to configure a mechanism that allows multiple internal devices to share this single public IP address when accessing the Internet. Which IP service should be configured?

    Infrastructure

    • A. IPv6 Transition Mechanisms
    • B. Dynamic NAT
    • C. PAT (Port Address Translation)
    • D. Static NAT
    Show answer

    C. PAT (Port Address Translation)

    PAT (Port Address Translation), also known as NAT Overload, allows multiple internal private IP addresses to share a single public IP address by translating both the IP address and the port number. This is the most common method for small offices to access the Internet with a single public IP.

  25. 25. A network engineer is configuring a Cisco router to use NTP. The router needs to synchronize its clock with a highly accurate external time source. The engineer wants to ensure that the router not only receives time updates but also actively checks the accuracy and integrity of the time source and uses a fallback mechanism if the primary source becomes unreliable. Which NTP mode should be configured on the router to achieve this robust synchronization?

    Infrastructure

    • A. Client mode
    • B. Server mode
    • C. Symmetric active mode
    • D. Broadcast mode
    Show answer

    C. Symmetric active mode

    Symmetric active mode is the most robust NTP mode for peers. In this mode, both devices (peers) can send and receive NTP messages to each other, allowing them to synchronize with each other and actively check the health and accuracy of their respective time sources. This provides redundancy and better accuracy than simple client/server.

Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2 flashcards

Tap a card to flip it. 163 flashcards in the full deck.

  • Embedded Event Manager (EEM)

    Flip card

    A Cisco IOS feature that provides on-device event detection and automation, allowing network devices to react to events and perform predefined actions without external intervention.

    • Monitors various events (e.g., syslog, interface status, timers, counters).
    • Triggers actions such as executing CLI commands, sending email, or running scripts (Tcl/Python).
    • Enables proactive troubleshooting and self-healing capabilities directly on the device.
    Study this card →
  • Network Address Translation (NAT)

    Flip card

    A method of remapping one IP address space into another by modifying network address information in the IP header of packets while they are in transit across a traffic routing device.

    • Translates private IP addresses to public IP addresses.
    • Enables multiple devices to share a single public IP.
    • Crucial for internet access from private networks.
    Study this card →
  • QoS Congestion Management

    Flip card

    QoS mechanisms that deal with traffic when a link becomes congested, typically by using queuing algorithms to prioritize certain types of traffic over others.

    • Queuing is a primary component.
    • Ensures preferential treatment for critical traffic.
    • Examples: LLQ, WFQ, CBWFQ.
    Study this card →
  • Cisco Express Forwarding (CEF)

    Flip card

    A highly optimized, hardware-accelerated Layer 3 IP forwarding mechanism used by Cisco routers and multilayer switches to achieve high throughput and low latency.

    • Default and most efficient forwarding method.
    • Uses a FIB (Forwarding Information Base) and Adjacency Table.
    • Hardware-based forwarding (ASIC-driven) on many platforms.
    Study this card →
  • NAT Overload (PAT)

    Flip card

    A type of Network Address Translation (NAT) that maps multiple private IP addresses to a single public IP address by using different port numbers for each connection.

    • Also known as Port Address Translation (PAT).
    • Allows many-to-one IP address translation.
    • Uses port numbers to distinguish between internal hosts.
    Study this card →
  • Low Latency Queuing (LLQ)

    Flip card

    A QoS queuing mechanism that provides strict priority to delay-sensitive traffic within an output queue, ensuring it is transmitted before other traffic.

    • Combines CBWFQ with strict priority queue.
    • Ideal for voice and video (real-time applications).
    • Minimizes latency and jitter for prioritized traffic.
    Study this card →
  • First Hop Redundancy Protocol (FHRP)

    Flip card

    A group of protocols used to provide default gateway redundancy for IP hosts on a shared LAN segment.

    • Ensures continuous network access even if the primary gateway fails.
    • Protocols include HSRP, VRRP, and GLBP.
    • Transparent to end-user devices, which see a single virtual gateway address.
    Study this card →
  • QoS Classification and Marking

    Flip card

    The initial steps in a QoS policy where network traffic is identified (classified) based on various criteria and then assigned a QoS label (marked) for preferential treatment.

    • Classification identifies traffic using ACLs, NBAR, etc.
    • Marking applies DSCP, IP Precedence, or CoS.
    • Enables downstream devices to apply QoS policies consistently.
    Study this card →
  • Virtual Router Redundancy Protocol (VRRP)

    Flip card

    A First Hop Redundancy Protocol (FHRP) that provides automatic failover for the default gateway, ensuring high availability for end devices.

    • Creates a virtual router with a virtual IP and MAC address.
    • One router acts as master, others as backups.
    • Standardized protocol, alternative to HSRP.
    Study this card →
  • NTP Client Configuration

    Flip card

    The process of configuring a network device to synchronize its system clock with an external Network Time Protocol (NTP) server.

    • Ensures accurate timekeeping across the network.
    • Crucial for logging, security, and troubleshooting.
    • Uses UDP port 123 for communication.
    Study this card →
  • Controller-based Wireless Architecture

    Flip card

    A wireless network design where lightweight access points (LAPs) are managed and controlled by a centralized Wireless LAN Controller (WLC).

    • Provides centralized management and configuration.
    • Enables seamless Layer 2 and Layer 3 roaming.
    • Offers dynamic RF management for optimal coverage and capacity.
    Study this card →
  • Voice VLAN with DHCP Option 150

    Flip card

    A configuration where a switch automatically assigns IP phones to a dedicated VLAN (Voice VLAN) and provides them with the IP address of a TFTP server via DHCP Option 150.

    • Separates voice traffic from data traffic for QoS and security.
    • DHCP Option 150 is specifically used by Cisco IP phones to find their TFTP server.
    • Simplifies IP phone deployment by automating configuration.
    Study this card →
  • Storm Control

    Flip card

    A Layer 2 feature on Cisco switches that prevents traffic storms by monitoring incoming traffic levels and suppressing excessive broadcast, multicast, or unknown unicast traffic.

    • Mitigates broadcast, multicast, and unicast storms.
    • Configured per interface.
    • Uses thresholds (e.g., percentage or pps) to trigger.
    Study this card →
  • Port Address Translation (PAT)

    Flip card

    A form of Network Address Translation (NAT) that allows multiple devices on a private network to share a single public IP address by using unique source port numbers.

    • Also known as NAT Overload.
    • Most common NAT type for internet access in homes and small businesses.
    • Conserves public IP addresses.
    Study this card →
  • PIM-Sparse Mode (PIM-SM)

    Flip card

    A multicast routing protocol used in IP networks where multicast receivers are sparsely distributed and dynamically join/leave multicast groups, building distribution trees only where necessary.

    • Designed for sparse receiver environments.
    • Uses a Rendezvous Point (RP) to discover sources and receivers.
    • Builds shared trees (RPT) and source trees (SPT).
    Study this card →
  • MAC Address Table

    Flip card

    A table maintained by a network switch that maps MAC addresses to the specific ports on which they were learned.

    • Used by switches to forward frames to specific destinations.
    • Entries are learned dynamically when a frame arrives from a source MAC address.
    • Can be used to identify Layer 2 loops if the same MAC address appears on multiple non-trunk ports.
    Study this card →
  • Syslog Timestamp Filtering

    Flip card

    The practice by syslog servers to discard incoming messages if their timestamps fall outside an acceptable time window, often to prevent processing old or invalid data.

    • Crucial for data integrity and preventing 'log floods' from misconfigured devices.
    • Requires accurate time synchronization (e.g., via NTP) on logging devices.
    • Can lead to legitimate log messages being dropped if the source device's clock is severely out of sync.
    Study this card →
  • First Hop Redundancy Protocols (FHRP)

    Flip card

    Protocols that provide redundant default gateway services for end devices on a LAN, ensuring continuous network access even if a gateway router fails.

    • Includes HSRP, VRRP, GLBP.
    • Uses a virtual IP and MAC address.
    • Transparent failover for end hosts.
    Study this card →
  • Remote SPAN (RSPAN)

    Flip card

    A Cisco feature that allows traffic from source ports or VLANs on one switch to be mirrored to a destination port on a different switch within the same network, using a dedicated RSPAN VLAN.

    • Extends SPAN capabilities across multiple switches.
    • Requires a dedicated RSPAN VLAN to transport mirrored traffic.
    • Destination port must be on a switch participating in the RSPAN VLAN.
    Study this card →
  • QoS Pillars

    Flip card

    The sequential steps involved in implementing an effective Quality of Service (QoS) policy to manage network traffic.

    • Begins with identifying and categorizing different types of traffic.
    • Involves marking traffic to indicate its priority level.
    • Requires mechanisms to manage and avoid congestion based on these priorities.
    Study this card →
  • IP SLA (IP Service Level Agreement)

    Flip card

    A Cisco IOS feature that provides active monitoring of network performance by generating and analyzing traffic to measure metrics like jitter, latency, and packet loss.

    • Generates synthetic traffic (active measurement).
    • Measures end-to-end delay, jitter, packet loss.
    • Configurable operations (e.g., UDP Jitter, ICMP Echo).
    Study this card →
  • PAT (Port Address Translation)

    Flip card

    A form of network address translation where multiple private IP addresses are mapped to a single public IP address using different port numbers.

    • Also known as NAT Overload.
    • Allows many-to-one IP address translation.
    • Conserves public IPv4 addresses.
    Study this card →
  • NTP Symmetric Active Mode

    Flip card

    An NTP operational mode where two peers actively exchange NTP messages with each other, allowing them to synchronize their clocks and provide robust time synchronization and redundancy.

    • Both devices can send and receive NTP packets to each other.
    • Provides redundancy and improved accuracy by allowing peers to validate each other's time.
    • Suitable for mission-critical synchronization where multiple reliable sources are needed.
    Study this card →
  • NetFlow

    Flip card

    A Cisco technology that provides statistics on network traffic flowing through a router or switch, used for network monitoring, security analysis, and accounting.

    • Collects detailed IP traffic flow records (source/destination IP, port, protocol, byte/packet counts).
    • Essential for bandwidth monitoring, accounting, and anomaly detection.
    • Requires a NetFlow collector to store and analyze the data.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.