Cisco Designing Cisco Enterprise Networks Exam 300-420 ENSLD Exam Questions

Page: 1 / 14
Total 379 questions
Question 1

When expanding an existing Cisco SD-Access network, in addition to the control plane, which two device roles are needed to create an additional fabric site? (Choose two.)



Answer : D, E

An additional Cisco SD-Access fabric site requires edge and border roles in addition to the control-plane function. Edge nodes connect wired endpoints, access-layer devices, and sometimes access points into the fabric. They perform endpoint detection, anycast gateway functions, and fabric encapsulation for user traffic. Border nodes provide connectivity between the fabric site and external networks such as the WAN, data center, internet edge, or shared services. Without edge nodes, the site has no practical access-layer fabric attachment for endpoints. Without border nodes, the site cannot properly exchange traffic with resources outside the local fabric. A wireless LAN controller may be needed when fabric wireless is part of the design, but it is not one of the mandatory fabric roles for every additional site. Leaf and cEdge are not Cisco SD-Access fabric roles in this context. Reference topics: Cisco SD-Access fabric roles, edge node, border node, control-plane node, fabric site expansion.


Question 2

Refer to the exhibit.

Refer to the exhibits. An engineer is troubleshooting an issue in which the Gig0/2 interface on a Cisco switch named SW2 fails to become the root port. Which two commands must be run on SW2 to resolve this issue? (Choose two.)

A)

B)

C)

D)

E)



Answer : C, D

The selected command pair is appropriate because the issue is that GigabitEthernet0/2 on SW2 is not becoming the root port as expected. In spanning-tree design, the root port is selected based on the lowest root path cost, then upstream bridge ID, then port ID when necessary. If the wrong port is selected, the engineer must adjust the local spanning-tree parameters on SW2 so that the intended interface has the best path toward the root bridge. Typical corrective commands lower the spanning-tree cost or set the port priority on the desired interface or VLAN instance. The correct answer pair is therefore the combination that changes the STP decision variables for Gig0/2 rather than changing unrelated features such as PortFast, BPDU Guard, or VLAN trunking. PortFast is unsafe on switch-to-switch links, and protection features do not make an interface more attractive as a root port. The fix must influence STP path selection while keeping the topology loop-free. Reference topics: STP root port election, path cost, port priority, root bridge path selection, Catalyst Layer 2 troubleshooting.


Question 3

An engineer is designing a multicast network for a company specializing in VoD content. Receivers are across the Internet, and for performance reasons, the multicast framework close to the receivers within each AS. For high availability, if the sources in one AS are no longer available, the receivers of that AS must be able to receive the VoD content from sources in another AS. Which feature must the design include?



Answer : D

MSDP is the correct feature when multicast receivers in one autonomous system must be able to learn and receive content from sources in another autonomous system. The scenario describes separate multicast frameworks close to the receivers in each AS and requires source resiliency across AS boundaries. In PIM Sparse Mode, a local RP learns about sources registered in its own domain. MSDP allows RPs in different domains to exchange Source-Active information, enabling receivers in one domain to discover and join toward sources that exist in another domain. Anycast RP is primarily a redundancy and load-sharing technique for RPs, often inside a multicast domain, but it does not by itself provide interdomain source discovery for independent ASs. SSM can be efficient when receivers know the source, but the question emphasizes RP-based framework placement and source availability between ASs. BIDIR-PIM is for scalable many-to-many shared-tree forwarding, not interdomain source discovery. Therefore, the design should include MSDP. Reference topics: MSDP, interdomain multicast, PIM-SM, Source-Active exchange, RP resilience across autonomous systems.


Question 4

What is the purpose of a control plane node in a Cisco SD-Access network fabric?



Answer : A

The SD-Access control-plane node maintains the endpoint database and resolves mappings between endpoints and the fabric edge nodes where those endpoints are located. Cisco SD-Access uses LISP in the fabric control plane. Edge nodes register endpoint identifiers with the control-plane node, and other fabric nodes query the control plane when they need to locate a destination endpoint. This control-plane function is commonly described through LISP Map-Server and Map-Resolver behavior. Option B is not correct because endpoint detection occurs at the edge node, not at the control-plane node. The edge is the device connected to users, access points, or endpoint-facing networks, so it learns local endpoint presence and registers that information. Option C refers to authentication and identity, which is integrated with Cisco ISE. Option D describes the border-node role, because border nodes connect the fabric to external networks. The corrected answer is therefore A. A stable SD-Access design must provide redundant control-plane reachability and scale the control-plane role according to fabric size, mobility, and endpoint churn. Reference topics: SD-Access control plane, LISP Map-Server, LISP Map-Resolver, endpoint-to-location mapping.


Question 5

A router running ISIS is showing high CPU and bandwidth utilization. An engineer discovers that the router is configured as L1/L2 and has L1 and L2 neighbors. Which step optimizes the design to address the issue?



Answer : D

Cisco IS-IS supports Level 1, Level 2, and Level 1/Level 2 operation, and the design should restrict each link to the level it actually needs. Cisco documentation for the isis circuit-type command states that it ''configures the type of adjacency that is required for neighbors on the specified interface.'' In this case, the router is configured as L1/L2 and has both L1 and L2 neighbors, which causes unnecessary LSP flooding, SPF processing, and database maintenance on links that may not need both levels. Making the entire router only L1 or only L2 would be too blunt, because the router may legitimately need to participate in both domains on different interfaces. Making the router a DIS also does not solve the underlying issue; it only controls designated intermediate system behavior on broadcast networks. The best optimization is to configure each interface with the correct circuit type, such as level-1 for intra-area links and level-2-only for backbone links. This reduces control-plane load while preserving the intended two-level hierarchy.


Question 6

Refer to the exhibit.

Refer to the exhibit A customer wants to adopt a dynamic site-to-site VPN solution to secure communication for VoIP, video, and FTP traffic between the remote branches and the headquarters. The customer also wants the branches to communicate directly, thereby reducing traffic at the headquarters location. The solution must consider that the branch routers are limited in available memory. Which VPN solution meets these requirements?



Answer : B

DMVPN Phase 3 hub-and-spoke is the best design for this requirement. The customer wants secure dynamic site-to-site VPN connectivity for voice, video, and FTP, and also wants branches to communicate directly instead of hairpinning all traffic through headquarters. DMVPN supports dynamic spoke-to-spoke tunnels using multipoint GRE, NHRP, and IPsec protection. Phase 3 is more scalable than Phase 2 because the hub can send NHRP redirect messages and spokes can install shortcut routes, reducing the need for every spoke to maintain detailed next-hop information for every other spoke. That is important because the branch routers have limited memory. Phase 1 is hub-and-spoke only and does not provide dynamic spoke-to-spoke forwarding. A hierarchical Phase 3 design can be useful at very large scale, but the question describes a headquarters and remote branch design rather than multiple tiers of hubs. Phase 3 hub-and-spoke satisfies direct branch communication, security, and scale. Reference topics: DMVPN Phase 3, NHRP redirect, spoke-to-spoke tunnels, IPsec encryption, branch WAN scalability.


Question 7

Refer to the exhibit.

Refer to the exhibit. An engineer must ensure that the QoS design guarantees bandwidth for the applications, and an application can request a particular type of service to support its delay requirements. Which solution must the engineer select?



Answer : B

IntServ with RSVP is the correct model when an application must request a specific service level and receive guaranteed bandwidth or delay treatment. Cisco describes the Integrated Services model as a flow-based QoS architecture in which applications signal their resource requirements to the network. RSVP is the signaling protocol used to reserve resources along the path. This differs from DiffServ, which marks packets and applies per-hop behavior without creating per-flow reservations. The question states that the application can request a particular type of service to support its delay requirements and that bandwidth must be guaranteed. Those are classic IntServ and RSVP characteristics. DiffServ with DSCP is scalable and widely used in enterprise networks, but it cannot guarantee resources end to end unless every hop is engineered and provisioned accordingly. IntServ with DSCP is not the standard model because RSVP is the reservation mechanism. Reference topics: Integrated Services, RSVP, resource reservation, guaranteed service, QoS architecture, delay-sensitive applications.


Page:    1 / 14   
Total 379 questions