Cisco 350-401 Online Practice
Questions and Exam Preparation
350-401 Exam Details
Exam Code
:350-401
Exam Name
:Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR)
Certification
:CCIE Enterprise Wireless
Vendor
:Cisco
Total Questions
:1524 Q&As
Last Updated
:Jul 18, 2026
Cisco 350-401 Online Questions &
Answers
Question 171:
Refer to the exhibit.
Extended access-list 100 is configured on interface GigabitEthernet 0/0 in an inbound direction, but it does not have the expected behavior of allowing only packets to or from 192 168 0.0/16.
Which command set properly configures the access list?
A. R1(config)#no access-list 100 deny ip any any B. R1(config)#no access-list 100 seq 10 R1(config)#access-list 100 seq 40 deny ip any any C. R1(config)#ip access-list extended 100 R1(config-ext-nacl)#5 permit ip any any D. R1(config)#ip access-list extended 100 R1(config-ext-nacl)#no 10
D. R1(config)#ip access-list extended 100 R1(config-ext-nacl)#no 10
Explanation
The first ACL statement of "10 deny ip any any" will match and drop all traffic so we have to remove this statement.
Question 172:
In a Cisco Mobility Express wireless deployment, which AP takes over if the primary AP fails?
A. AP with highest IP address B. AP with the lowest IP address C. AP with highest MAC address D. AP with highest controller up time
C. AP with highest MAC address
Question 173:
DRAG DROP
Drag and drop the characteristics from the left onto the routing protocols they describe on the right
Select and Place:
Question 174:
Which of the following protocols has a default administrative distance value of 90?
A. RIP B. EIGRP C. OSPF D. BGP
B. EIGRP
Question 175:
A network engineer must configure the VTY lines on a router to achieve these results:
1. Remote access should be permitted only for secure protocols.
2. Only a password should be required for device authentication.
3. All idle EXEC sessions must be terminated in 60 minutes.
Which configuration should be applied?
A. line vty 0 15 password Cisco123 transport input ssh exec-timeout 60 B. line vty 0 15 login password Cisco123 transport input ssh exec-timeout 60 C. line vty 0 15 password Cisco123 transport input telnet ssh exec-timeout 60 D. line vty 0 15 password Cisco123 transport input all session-timeout 60
B. line vty 0 15 login password Cisco123 transport input ssh exec-timeout 60
Question 176:
What is the output of this code?
A. username: cisco B. get_credentials C. username D. cisco
D. cisco
Question 177:
Refer to the exhibit.
The IP SLA is configured in a router. An engineer must configure an EEM applet to shut down the interface and bring it back up when there is a problem with the IP SLA.
Which configuration should the engineer use?
A. event manager applet EEM_IP_SLA event track 10 state down B. event manager applet EEM_IP_SLA event track 10 state unreachable C. event manager applet EEM_IP_SLA event sla 10 state unreachable D. event manager applet EEM_IP_SLA event sla 10 state down
A. event manager applet EEM_IP_SLA event track 10 state down
Explanation
The ip sla 10 will ping the IP 192.168.10.20 every 3 seconds to make sure the connection is still up. We can configure an EEM applet if there is any problem with this IP SLA via the command event track 10 state down.
A. responding to map-request messages B. forwarding user data traffic C. finding EID-to-RLOC mappings D. accepting registration requests from ETRs
C. finding EID-to-RLOC mappings
Explanation
LISP Ingress Tunnel Router (ITR)
An ITR is responsible for finding EID-to-RLOC mappings for all traffic destined for LISP-capable sites. When the ITR receives a packet destined for an EID, it first looks for the EID in its mapping cache. If the ITR finds a match, it encapsulates the packet inside a LISP header with one of its RLOCs as the IP source address
Which two statements about EIGRP load balancing are true? (Choose two)
A. Cisco Express Forwarding is required to load-balance across interfaces B. A path can be used for load balancing only if it is a feasible successor C. EIGRP supports unequal-cost paths by default D. Any path in the EIGRP topology table can be used for unequal-cost load balancing E. EIGRP supports 6 unequal-cost paths
B. A path can be used for load balancing only if it is a feasible successor E. EIGRP supports 6 unequal-cost paths
Explanation
EIGRP provides a mechanism to load balance over unequal cost paths (or called unequal cost load balancing) through the "variance" command. In other words, EIGRP will install all paths with metric < variance * best metric into the local routing table, provided that it meets the feasibility condition to prevent routing loop. The path that meets this requirement is called a feasible successor. If a path is not a feasible successor, it is not used in load balancing.
Note: The feasibility condition states that, the Advertised Distance (AD) of a route must be lower than the feasible distance of the current successor route.
Question 180:
Which solution should be used in a high-density wireless environment to increase bandwidth for each user?
A. Increase antenna size B. Increase the mandatory minimum data rate. C. Increase the cell size of each AP. D. Increase TX power.
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Cisco exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your 350-401 exam preparations
and Cisco certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.