Exam Code: 400 101 vce (Practice Exam Latest Test Questions VCE PDF)
Exam Name: CCIE Routing and Switching (v5.0)
Certification Provider: Cisco
Free Today! Guaranteed Training- Pass 400 101 vce Exam.

Q1. Refer to the exhibit. 

Why is network 172.16.1.0/24 not installed in the routing table? 

A. There is no ARP entry for 192.168.1.1. 

B. The router cannot ping 192.168.1.1. 

C. The neighbor 192.168.1.1 just timed out and BGP will flush this prefix the next time that the BGP scanner runs. 

D. There is no route for 192.168.1.1 in the routing table. 

Answer:

Explanation: 

Here we see that the next hop IP address to reach the 172.16.1.0 network advertised by the BGP peer is 192.168.1.1. However, the 192.168.1.1 IP is not in the routing table of R3 so it adds the route to the BGP table but marks it as inaccessible, as shown. 


Q2. For which feature is the address family "rtfilter" used? 

A. Enhanced Route Refresh 

B. MPLS VPN filtering 

C. Route Target Constraint 

D. Unified MPLS 

Answer:

Explanation: 

With Multiprotocol Label Switching (MPLS) VPN, the internal Border Gateway Protocol (iBGP) peer or Route Reflector (RR) sends all VPN4 and/or VPN6 prefixes to the PE routers. The PE router drops the VPN4/6 prefixes for which there is no importing VPN routing and forwarding (VRF). This is a behavior where the RR sends VPN4/6 prefixes to the PE router, which it does not need. This is a waste of processing power on the RR and the PE and a waste of bandwidth. With Route Target Constraint (RTC), the RR sends only wanted VPN4/6 prefixes to the PE. 'Wanted' means that the PE has VRF importing the specific prefixes. RFC 4684 specifies Route Target Constraint (RTC). The support is through a new address family rtfilter for both VPNv4 and VPNv6. 

Reference: http://www.cisco.com/c/en/us/support/docs/multiprotocol-label-switching-mpls/mpls/116062-technologies-technote-restraint-00.html 


Q3. DRAG DROP 

Drag and drop the multiprotocol BGP feature on the left to the corresponding description on the right. 

Answer: 


Q4. When you configure the ip pmtu command under an L2TPv3 pseudowire class, which two things can happen when a packet exceeds the L2TP path MTU? (Choose two.) 

A. The router drops the packet. 

B. The router always fragments the packet after L2TP/IP encapsulation. 

C. The router drops the packet and sends an ICMP unreachable message back to the sender only if the DF bit is set to 1. 

D. The router always fragments the packet before L2TP/IP encapsulation. 

E. The router fragments the packet after L2TP/IP encapsulation only if the DF bit is set to 0. 

F. The router fragments the packet before L2TP/IP encapsulation only if the DF bit is set to 

0. 

Answer: C,F 

Explanation: 

If you enable the ip pmtu command in the pseudowire class, the L2TPv3 control channel participates in the path MTU discovery. When you enable this feature, the following processing is performed: 

– ICMP unreachable messages sent back to the L2TPv3 router are deciphered and the tunnel MTU is updated accordingly. In order to receive ICMP unreachable messages for fragmentation errors, the DF bit in the tunnel header is set according to the DF bit value received from the CE, or statically if the ip dfbit set option is enabled. The tunnel MTU is periodically reset to the default value based on a periodic timer. 

– ICMP unreachable messages are sent back to the clients on the CE side. ICMP unreachable messages are sent to the CE whenever IP packets arrive on the CE-PE interface and have a packet size greater than the tunnel MTU. A Layer 2 header calculationis performed before the ICMP unreachable message is sent to the CE. 

Reference: http://www.cisco.com/c/en/us/td/docs/ios/12_0s/feature/guide/l2tpv325.html 


Q5. Which two statements about IPv4 and IPv6 networks are true? (Choose two.) 

A. In IPv6, hosts perform fragmentation. 

B. IPv6 uses a UDP checksum to verify packet integrity. 

C. In IPv6, routers perform fragmentation. 

D. In IPv4, fragmentation is performed by the source of the packet. 

E. IPv4 uses an optional checksum at the transport layer. 

F. IPv6 uses a required checksum at the network layer. 

Answer: A,B 


Q6. Which two statements about class maps are true? (Choose two.) 

A. As many as eight DSCP values can be included in a match dscp statement. 

B. The default parameter on a class map with more than one match command is match-any. 

C. The match class command can nest a class map within another class map. 

D. A policy map can be used to designate a protocol within a class map. 

Answer: A,C 

Explanation: 

Answer A. 

Router(config-cmap)# match [ip] dscp dscp-value [dscp-value dscp-value dscp-value 

dscp-value dscp-value dscp-value dscp-value] 

(Optional) Identifies a specific IP differentiated service code point (DSCP) value as a match criterion. Up to eight DSCP values can be included in one match statement. 

Answer C. 

Router config-cmap)# match class-map class-name (Optional) Specifies the name of a traffic class to be used as a matching criterion (for nesting traffic class [nested class maps] within one another). 

Reference: http://www.cisco.com/c/en/us/td/docs/ios/12_2/qos/configuration/guide/fqos_c/qcfmcli2.html 


Q7. Refer to the exhibit. 

Which statement about the output is true? 

A. The flow is an HTTPS connection to the router, which is initiated by 144.254.10.206. 

B. The flow is an HTTP connection to the router, which is initiated by 144.254.10.206. 

C. The flow is an HTTPS connection that is initiated by the router and that goes to 144.254.10.206. 

D. The flow is an HTTP connection that is initiated by the router and that goes to 144.254.10.206. 

Answer:

Explanation: 

We can see that the connection is initiated by the Source IP address shown as 144.254.10.206. We also see that the destination protocol (DstP) shows 01BB, which is in hex and translates to 443 in decimal. SSL/HTTPS uses port 443. 


Q8. Which two options describe two functions of a neighbor solicitation message? (Choose two.) 

A. It requests the link-layer address of the target. 

B. It provides its own link-layer address to the target. 

C. It requests the site-local address of the target. 

D. It provides its own site-local address to the target. 

E. It requests the admin-local address of the target. 

F. It provides its own admin-local address to the target. 

Answer: A,B 

Explanation: 

Neighbor solicitation messages are sent on the local link when a node wants to determine the link-layer address of another node on the same local link (see the figure below). When a node wants to determine the link-layer address of another node, the source address in a neighbor solicitation message is the IPv6 address of the node sending the neighbor solicitation message. The destination address in the neighbor solicitation message is the solicited-node multicast address that corresponds to the IPv6 address of the destination node. The neighbor solicitation message also includes the link-layer address of the source node. 

Figure 1. IPv6 Neighbor Discovery: Neighbor Solicitation Message 

After receiving the neighbor solicitation message, the destination node replies by sending a neighbor advertisement message, which has a value of 136 in the Type field of the ICMP packet header, on the local link. The source address in the neighbor advertisement message is the IPv6 address of the node (more specifically, the IPv6 address of the node interface) sending the neighbor advertisement message. The destination address in the neighbor advertisement message is the IPv6 address of the node that sent the neighbor solicitation message. The data portion of the neighbor advertisement message includes the link-layer address of the node sending the neighbor advertisement message. After the source node receives the neighbor advertisement, the source node and destination node can communicate. 

Reference: http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_basic/configuration/xe-3s/ip6b-xe-3s-book/ip6-neighb-disc-xe.html 


Q9. You are configuring a DMVPN spoke to use IPsec over a physical interface that is located within a VRF. For which three configuration sections must you specify the VRF name? (Choose three.) 

A. the ISAKMP profile 

B. the crypto keyring 

C. the IPsec profile 

D. the IPsec transform set 

E. the tunnel interface 

F. the physical interface 

Answer: B,E,F 

Explanation: 

ip vrf forwardingvrf-name 

Example: 

Router(config-if)# ip vrf forwarding green 

Associates a virtual private network (VPN) routing and forwarding (VRF) instance with an interface or subinterface. 

. vrf-name is the name assigned to a VRF. 

Router(config-if)# tunnel vrfvrf-name 

Example: 

Router(config-if)# tunnel vrf finance1 

Associates a VPN routing and forwarding (VRF) instance with a specific tunnel destination. vrf-name is the name assigned to a VRF. 

Router(config)# crypto keyringkeyring-name [vrf fvrf-name] 

Defines a crypto keyring to be used during IKE authentication and enters keyring configuration mode. 

. keyring-name—Name of the crypto keyring. 

. fvrf-name—(Optional) Front door virtual routing and forwarding (FVRF) name to which the keyring will be referenced. fvrf-name must match the FVRF name that was defined during virtual routing and forwarding (VRF) configuration 


Q10. Which two statements about BPDU guard are true? (Choose two.) 

A. The global configuration command spanning-tree portfast bpduguard default shuts down interfaces that are in the PortFast-operational state when a BPDU is received on that port. 

B. The interface configuration command spanning-tree portfast bpduguard enable shuts down only interfaces with PortFast enabled when a BPDU is received. 

C. BPDU guard can be used to prevent an access port from participating in the spanning tree in the service provider environment. 

D. BPDU guard can be used to protect the root port. 

E. BPDU guard can be used to prevent an invalid BPDU from propagating throughout the network. 

Answer: A,C 


Q11. Which statement about WAN Ethernet Services is true? 

A. Rate-limiting can be configured per EVC. 

B. Point-to-point processing and encapsulation are performed on the customer network. 

C. Ethernet multipoint services function as a multipoint-to-multipoint VLAN-based connection. 

D. UNIs can perform service multiplexing and all-in-one bundling. 

Answer:

Explanation: 

The MEF has defined a set of bandwidth profiles that can be applied at the UNI or to an EVC. A bandwidth profile is a limit on the rate at which Ethernet frames can traverse the UNI or the EVC. 

Reference: http://www.ciscopress.com/articles/article.asp?p=101367&seqNum=2 


Q12. How many address families can a single OSPFv3 instance support? 

A. 1 

B. 2 

C. 5 

D. 10 

Answer:


Q13. Which two 802.1D port states are expected in a stable Layer 2 network? (Choose two.) 

A. forwarding 

B. learning 

C. listening 

D. blocking 

E. disabled 

Answer: A,D 


Q14. In the DiffServ model, which class represents the lowest priority with the lowest drop probability? 

A. AF11 

B. AF13 

C. AF41 

D. AF43 

Answer:

Explanation: 

Assured Forwarding (AF) Behavior Group 

Class 1 

Class 2 

Class 3 

Class 4 

Low Drop 

AF11 (DSCP 10) 

AF21 (DSCP 18) 

AF31 (DSCP 26) 

AF41 (DSCP 34) 

Med Drop 

AF12 (DSCP 12) 

AF22 (DSCP 20) 

AF32 (DSCP 28) 

AF42 (DSCP 36) 

High Drop 

AF13 (DSCP 14) 

AF23 (DSCP 22) 

AF33 (DSCP 30) 

AF43 (DSCP 38) 

Reference: http://en.wikipedia.org/wiki/Differentiated_services 


Q15. Which statement about the feasible distance in EIGRP is true? 

A. It is the maximum metric that should feasibly be considered for installation in the RIB. 

B. It is the minimum metric to reach the destination as stored in the topology table. 

C. It is the metric that is supplied by the best next hop toward the destination. 

D. It is the maximum metric possible based on the maximum hop count that is allowed. 

Answer:

Explanation: 

An EIGRP router advertises each destination it can reach as a route with an attached metric. This metric is called the route's reported distance (the term advertised distance has also been used in older documentation). A successor route for any given destination is chosen as having the lowest computed feasible distance; that is, the lowest sum of reported distance plus the cost to get to the advertising router. By default, an EIGRP router will store only the route with the best (lowest) feasible distance in the routing table (or, multiple routes with equivalent feasible distances). 

Reference: http://packetlife.net/blog/2010/aug/9/eigrp-feasible-successor-routes/