350-401 Exam Details

  • Exam Code
    :350-401
  • Exam Name
    :Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR)
  • Certification
    :CCIE Enterprise Wireless
  • Vendor
    :Cisco
  • Total Questions
    :1524 Q&As
  • Last Updated
    :Jul 18, 2026

Cisco 350-401 Online Questions & Answers

  • Question 581:

    Refer to the exhibit. An engineer is troubleshooting a newly configured BGP peering that does not establish.

    What is the reason for the failure?

    A. BGP peer 10 255 255 3 is not configured for peenng wth R1
    B. Mandatory BOP parameters between R1 and 10 255 255 3 are mismatched
    C. A firewall is blocking access to TCP port 179 on the BGP peer 10 255 255.3
    D. Both BGP pern are configured for passive TCP transport

  • Question 582:

    A corporate policy mandates that a certificate-based authentication system must be implemented on the wireless infrastructure. All corporate clients will contain a certificate that will be used in conjunction with ISE and user credentials to perform authentication before the clients are allowed to connect to the corporate Wi-Fi.

    Which authentication key option must be selected to ensure that this authentication can take place?

    A. none
    B. PSK
    C. 802.1x
    D. CCKM

  • Question 583:

    Refer to the exhibit.

    An engineer must deny Telnet traffic from the loopback interface of router R3 to the loopback interface of router R2 during the weekend hours. All other traffic between the loopback interfaces of routers R3 and R2 must be allowed at all times.

    Which command set accomplishes this task?

    A. R3(config)#time-range WEEKEND R3(config-time-range)#periodic Saturday Sunday 00:00 to 23:59 R3(config)#access-list 150 deny tcp host 10.3.3.3 host 10.2.2.2 eq 23 time-range WEEKEND R3(config)#access-list 150 permit ip any any time-range WEEKEND R3(config)#interface G0/1 R3(config-if)#ip access-group 150 out
    B. R1(config)#time-range WEEKEND R1(config-time-range)#periodic weekend 00:00 to 23:59 R1(config)#access-list 150 deny tcp host 10.3.3.3 host 10.2.2.2 eq 23 time-range WEEKEND R1(config)#access-list 150 permit ip any any R1(config)#interface G0/1 R1(config-if)#ip access-group 150 in
    C. R3(config)#time-range WEEKEND R3(config-time-range)#periodic weekend 00:00 to 23:59 R3(config)#access-list 150 permit tcp host 10.3.3.3 host 10.2.2.2 eq 23 time-range WEEKEND R3(config)#access-list 150 permit ip any any time-range WEEKEND R3(config)#interface G0/1 R3(config-if)#ip access-group 150 out
    D. R1(config)#time-range WEEKEND R1(config-time-range)#periodic Friday Sunday 00:00 to 00:00 R1(config)#access-list 150 deny tcp host 10.3.3.3 host 10.2.2.2 eq 23 time-range WEEKEND R1(config)#access-list 150 permit ip any any R1(config)#interface G0/1 R1(config-if)#ip access-group 150 in

  • Question 584:

    Which collection contains the resources to obtain a list of fabric nodes through the vManage API?

    A. device management
    B. administration
    C. device inventory
    D. monitoring

  • Question 585:

    DRAG DROP

    Drag and drop the NTP elements from the left onto the correct descriptions on the right.

    Select and Place:

  • Question 586:

    Two Cisco switches are logically configured as a single switch using Cisco Stackwise technology.

    This will result in virtually combining which two planes? (Choose two.)

    A. Data Plane
    B. Control Plane
    C. Forwarding Plane
    D. Management Plane
    E. Bearer Plane

  • Question 587:

    Refer to the exhibit.

    Link 1 uses a copper connection and link 2 uses a fiber connection. The fiber port must be the primary port for all forwarding. The output of the show spanning-tree command on SW2 shows that the fiber port is blocked by Spanning Tree.

    After entering the spanning-tree port-priority 32 command on G0/1 on SW2, the port remains blocked.

    Which command should be entered on the ports connected to Link 2 is resolve the issue?

    A. Enter spanning-tree port-priority 64 on SW2
    B. Enter spanning-tree port-priority 224 on SW1.
    C. Enter spanning-tree port-priority 4 on SW2.
    D. Enter spanning-tree port-priority 32 on SW1.

  • Question 588:

    Refer to the exhibit.

    R1#show ip route

    1.0.0.0/32 is subnetted, 1 subnets

    C 1.1.1.1/32 is directly connected, Loopback0

    2.0.0.0/32 is subnetted, 1 subnets

    O 2.2.2.2/32 [110/2] via 10.10.10.2, 00:09:30, GigabitEthernet0/0/0

    10.0.0.0/8 is variably subnetted, 7 subnets, 2 masks

    C 10.10.10.0/30 is directly connected, GigabitEthernet0/0/0

    L 10.10.10.1/32 is directly connected, GigabitEthernet0/0/0

    C 10.10.20.0/30 is directly connected, GigabitEthernet0/0/1

    L 10.10.20.1/32 is directly connected, GigabitEthernet0/0/1

    D 10.20.10.0/30 [90/3072] via 10.10.10.2, 00:09:30, GigabitEthernet0/0/0

    O 10.30.10.0/30 [90/3328] via 10.10.10.2, 00:05:48, GigabitEthernet0/0/0

    S 10.40.10.0/30 [1/0] via 10.10.20.2

    Routers R1, R2, R3, and R4 use EIGRP. However, traffic always prefers R1 to R5 backup links in non failure scenarios.

    Which configuration resolves the issue?

    A. R1(config)#no ip route 10.40.10.0 255.255.255.252 10.10.20.2 R1(config)#ip route 10.40.10.0 255.255.255.252 10.10.20.2 115
    B. R1(config)#int gigabitEthernet 0/0/0 R1 (config-if)#bandwidth 10000000
    C. R1(config-if)#int gigabitEthernet 0/0/0 R1(config-if)#bandwidth 10000
    D. R1(config)#no ip route 10.40.10.0 255.255.255.252 10.10.20.2 R1(config)#ip route 0.0.0.0 0.0.0.0 10.10.10.2

  • Question 589:

    What are the main components of Cisco TrustSec?

    A. Cisco ISE and Enterprise Directory Services
    B. Cisco ISE. network switches, firewalls, and routers
    C. Cisco ISE and TACACS+
    D. Cisco ASA and Cisco Firepower Threat Defense

  • Question 590:

    Refer to the exhibit.

    Which action automatically enables privilege exec mode when logging in via SSH?

    A. Configure a password under the line configuration.
    B. Configure the enable secret to be the same as the secret for user "Cisco".
    C. Configure privilege level 15 under the line configuration.
    D. Configure user "cisco" with privilege level 15.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cisco exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 350-401 exam preparations and Cisco certification application, do not hesitate to visit our Vcedump.com to find your solutions here.