Cisco 350-401 Online Practice
Questions and Exam Preparation
350-401 Exam Details
Exam Code
:350-401
Exam Name
:Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR)
Certification
:CCIE Enterprise Wireless
Vendor
:Cisco
Total Questions
:1493 Q&As
Last Updated
:Jun 01, 2026
Cisco 350-401 Online Questions &
Answers
Question 1161:
Refer to the exhibit.
A network administrator configured RSPAN to troubleshoot an issue between switchl and switch2. The switches are connected using interface GigabitEthernet 1/1 An external packet capture device is connected to swich2 interface GigabitEthernet1/2 Which two commands must be added to complete this configuration? (Choose two)
Which single security feature is recommended to provide Network Access Control m the enterprise?
A. MAB B. 802.1X C. WebAuth D. port security sticky MAC
B. 802.1X
Question 1163:
A network administrator added a new spoke site with dynamic IP on the DMVPN network. Which configuration command passes traffic on the DMVPN tunnel from the spoke router?
A. ip nhrp registration dynamic B. ip nhrp registration ignore C. ip nhrp registration no-registration D. ip nhrp registration no-unique
D. ip nhrp registration no-unique
Explanation
"ip nhrp registration no-unique": allow the client to not set the unique flag in the NHRP packets. This is useful when a station has a dynamic IP address that could change over time.
Question 1164:
A customer has deployed an environment with shared storage to allow for the migration of virtual machines between servers with dedicated operating systems that provide the virtualization platform.
What is this operating system described as?
A. hosted virtualization B. type 1 hypervisor C. container oriented D. decoupled
B. type 1 hypervisor
Question 1165:
Refer to the exhibit.R4 is experiencing packet drop when trying to reach 172.16.2.7 behind R2. Which action resolves the issue?
A. Insert a /24 floating static route on R2 toward R3 with metric 254. B. Disable auto summarization on R2. C. Insert a /16 floating static route on R2 toward R3 with metric 254. D. Enable auto summarization on all three routers R1, R2, and R3.
B. Disable auto summarization on R2.
Question 1166:
A network engineer is enabling HTTPS access to the core switch, which requires a certificate to be installed on the switch signed by the corporate certificate authority
Which configuration commands are required to issue a certificate signing request from the core switch?
A. Core-Switch(config)#crypto pki enroll Core-SwitchCore-Switch(config)#ip http secure-trustpoint Core-Switch B. Core-Switch(config)#crypto pki trustpoint Core-SwitchCore-Switch(ca-trustpoint)#enrollment terminalCore-Switch(config)#crypto pki enroll Core-Switch C. Core-Switch(config)#crypto pki trustpoint Core-SwitchCore-Switch(ca-trustpoint)#enrollment terminalCore-Switch(config)#ip http secure-trustpoint Core-Switch D. Core-Switch(config)#ip http secure-trustpoint Core-SwitchCore-Switch(config)#crypto pki enroll Core-Switch
B. Core-Switch(config)#crypto pki trustpoint Core-SwitchCore-Switch(ca-trustpoint)#enrollment terminalCore-Switch(config)#crypto pki enroll Core-Switch
Which benefit is offered by a cloud infrastructure deployment but is lacking in an on-premises deployment?
A. efficient scalability B. virtualization C. storage capacity D. supported systems
A. efficient scalability
Question 1168:
What is the difference between the enable password and the enable secret password when password encryption is enable on an IOS device?
A. The enable password is encrypted with a stronger encryption method. B. There is no difference and both passwords are encrypted identically. C. The enable password cannot be decrypted. D. The enable secret password is protected via stronger cryptography mechanisms.
D. The enable secret password is protected via stronger cryptography mechanisms.
Explanation
The "enable secret" password is always encrypted (independent of the "service passwordencryption" command) using MD5 hash algorithm. The "enable password" does not encrypt the password and can be view in clear text in the running- config. In order to encrypt the "enable password", use the "service password-encryption" command. This command will encrypt the passwords by using the Vigenere encryption algorithm. Unfortunately, the Vigenere encryption method is cryptographically weak and trivial to reverse. The MD5 hash is a stronger algorithm than Vigenere so answer 'The enable secret password is protected via stronger cryptography mechanisms' is correct.
Question 1169:
Which solution supports end-to-end line-rate encryption between two sites?
A. TrustSec B. MACsec C. IPsec D. GRE
C. IPsec
Question 1170:
Refer to the exhibit.
Which two commands are needed to allow for full reachability between AS 1000 and AS 2000? (Choose two.)
A. R2#no network 10.0.0.0 255.255.255.0 B. R2#network 209.165.201.0 mask 255.255.192.0 C. R2#network 192.168.0.0 mask 255.255.0.0 D. R1#no network 10.0.0.0 255.255.255.0 E. R1#network 192.168.0.0 mask 255.255.0.0
A. R2#no network 10.0.0.0 255.255.255.0 C. R2#network 192.168.0.0 mask 255.255.0.0
Explanation
A and C are correct. Need to negate the 10.0.0.0 /24 network on R2 and then add the 192.168.0.0 /16 network on R2. Hence, A and C, although I think to be exact the answer on A should be "no network 10.0.0.0 mask 255.255.255.0" vs. the "no network 10.0.0.0 255.255.255.0".
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Cisco exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your 350-401 exam preparations
and Cisco certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.