2021 300-420 exam torrent 300-420 Study Guide
Easily pass 300-420 Exam with our Dumps & PDF Test Engine
Career Opportunities for People Who Pass 300-420 Exam and Get Certified
If you are starting the IT career, earning an intermediate-level Cisco certification can provide a plethora of employment opportunities. There are various positions that you can apply for after passing the Cisco 300-420 exam and obtaining the CCNP Enterprise certificate and they are as follows:
- Network Manager
- Network Architect
- Network Design Engineer
- Network Administrator
Having this certification under your belt can help you get a much higher salary as well. Depending on what position you land, extra skills, and experience, your compensation can vary. According to PayScale.com, as a network engineer, you can earn around $74k, while the salary for a network architect is around $122k annually. If you start working as a network security engineer you can easily get over $82k per year.
NEW QUESTION 26
At which layer does Cisco Express Forwarding use adjacency tables to populate addressing information?
- A. Layer4
- B. Layer 1
- C. Layer 3
- D. Layer 2
Answer: D
NEW QUESTION 27
Drag and drop the characteristics from the left onto the correct telemetry mode on the right.
Answer:
Explanation:
Reference:
https://www.cisco.com/c/en/us/td/docs/iosxr/asr9000/telemetry/b-telemetry-cg-asr9000-61x/b-telemetry-cgasr9000-
61x_chapter_010.html#id_36445
NEW QUESTION 28
Which feature is required for graceful restart to recover from a processor failure?
- A. Virtual Switch System
- B. Cisco Express Forwarding
- C. Bidirectional Forwarding Detection
- D. Stateful Switchover
Answer: B
NEW QUESTION 29
Which design element should an engineer consider when multicast is included in a Cisco SD-Access architecture?
- A. Multicast traffic is transported in the overlay and the EID space for wired and wireless clients.
- B. Rendezvous points must be used in a PIM SSM deployment.
- C. Multicast clients reside in the underlay, and the multicast source is outside the fabric or in the overlay.
- D. PIM SSM must run in the underlay.
Answer: A
Explanation:
Multicast traffic is transported in the overlay, in the EID space, for both wired and wireless clients https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2018/pdf/BRKEWN-2020.pdf
https://www.cisco.com/c/dam/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/deploy-guide/cisco-dna-center-sd-access-wl-dg.pdf
NEW QUESTION 30
Refer to the exhibit.
EIGRP has been configured on all links. The spoke nodes have been configured as EIGRP stubs, and the WAN links to R3 have higher bandwidth and lower delay than the links to R4. When a link failure occurs at the R1-R2 link, what happens to traffic on R1 that is destined for a subnet attached to R2?
- A. R1 forwards the traffic to R3, but R3 drops the traffic
- B. R1 forwards the traffic to R3 in order to reach R2
- C. R1 has no route to R2 and drops the traffic
- D. R1 load-balances across the paths through R3 and R4 to reach R2
Answer: B
NEW QUESTION 31
A company must automate a set of complex changes aligned with DR testing in the network. These changes are specific, and the DR playbook will be adjusted in the future. The playbook has diverse routing and switching assets in scope as well as multiple vendor and hardware platforms. A developer will create a thin, web front-end microservice and integrate with an Open daylight controller to push changes to the network.
Which YANG model should be used?
- A. Use a single native vendor YANG model to minimize development time
- B. Use an open YANG model to allow the reuse of code and standardize the implementation across platforms
- C. Use multiple native vendor YANG models to provide code consistency.
- D. Develop an individualized YANG model to minimize development resources and time to market.
Answer: B
NEW QUESTION 32
Which feature is required for graceful restart to recover from a processor failure?
- A. Virtual Switch System
- B. Cisco Express Forwarding
- C. Bidirectional Forwarding Detection
- D. Stateful Switchover
Answer: B
Explanation:
Section: Advanced Enterprise Campus Networks
NEW QUESTION 33
Refer to the exhibit. An IPv6 network was just deployed in the environment and the help desk has reported that R3 is not able to SSH to R2's Loopback interface. Which sequence number of the filter is preventing access?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION 34
You have executed the following commands on switchA:
What is the result of executing the given commands? (Choose two.)
- A. AAA is not enabled on the switch
- B. The key for the RADIUS server is firstKey111
- C. 802.1X authentication is enabled on the Fa0/1 interface only
- D. Only the listed RADIUS server is used for authentication
Answer: B,D
Explanation:
A default list is used for the RADIUS server for authentication and the key for the RADIUS server is firstKey111. A RADIUS server combines the authentication and authorization processes. Before you configure the RADIUS server, you should enable AAA by using the aaa new-model command in the global configuration mode. Then, you can specify the location of the RADIUS server and the key using the radius-server host command. In this case, the RADIUS server is located at the IP address 192.168.105.67 and requires the key firstKey111 as the encryption key. This key must be mutually agreed upon by the server and the clients.
The aaa authentication dot1x default group radius command creates a method list for 802.1X authentication.
The default group radius keywords specify that the default method will be to use all listed RADIUS servers to authenticate clients. Since only one is listed, it will be the only one used.
It is incorrect to state that 802.1X authentication is enabled on the Fa0/1 interface only. The interface range Fa
0/1 - 11 and the dot1x port-control auto commands specify that 802.1X authentication is enabled on the interfaces Fa0/1 to Fa0/11.
It is incorrect to stat that AAA is not enabled on the switch. The aaa new-model command enables AAA globally on the switch.
Objective:
Infrastructure Security
Sub-Objective:
Describe device security using Cisco IOS AAA with TACACS+ and RADIUS
References:
Catalyst 4500 Series Switch Cisco IOS Software Configuration Guide, 12.2(31)SG > Configuring 802.1X Port- Based Authentication Cisco IOS LAN Switching Command Reference (PDF)
NEW QUESTION 35
Drag and drop the descriptions from the left onto the Cisco SD-WAN component they describe on the right.
Answer:
Explanation:
Explanation
Answer Area
is responsible for traffic forwarding, security, encryption, QoS,and routing protocols distributes routes and policy information via OMP enables centralized provisioning and simplifies network changes enables the communication of devices that sit behind NAT
NEW QUESTION 36
A network engineer must segregate three interconnected campus networks using IS-IS routing. A two-layer hierarchy must be used to support large routing domains and to avoid more specific routes from each campus network being advertised to other campus network routers automatically. Which two actions does the engineer take to accomplish this segregation? (Choose two.)
- A. Assign the same IS-IS NET value for each campus, and configure internal campus routers with Level 1/ Level 2 routing.
- B. Designate two IS-IS routers as BDR routers at the edge of each campus, and configure one BDR for all Level 1 routers and one BDR for all Level 2 routers.
- C. Utilize different MTU values for each campus network segment. Level 2 backbone routers must utilize a larger MTU size of 9216.
- D. Designate two IS-IS routers from each campus to act as Level 1/Level 2 backbone routers at the edge of each campus network.
- E. Assign a unique IS-IS NET value for each campus, and configure internal campus routers with Level 1 routing.
Answer: D,E
Explanation:
Section: Advanced Enterprise Campus Networks
NEW QUESTION 37
Which two options can you use to configure an EIGRP stub router? (Choose two)
- A. receive-only
- B. totally-stubby
- C. summary-only
- D. not-so-stubby
- E. summary
- F. external
Answer: A,E
NEW QUESTION 38
Refer to the exhibit. AS65533 and AS65530 are announcing a partial Internet routing table as well as their IP subnets. An architect must create a design that ensures AS64512 become a transit AS. Which filtering solution must the architect choose?
- A. Maximum-prefix
- B. Next-hop
- C. No Export
- D. No-advertise
Answer: A
NEW QUESTION 39 
Refer to the exhibit. An architect is designing a BGP solution to connect a remote branch to a service provider.
There are several prefixes within the branch that the company does not want to be advertised to the internet.
Which solution should the architect use to accomplish this?
- A. Implement the NOPEER community.
- B. Set the BGP Internet community for all prefixes.
- C. Use the BGP No-Advertise community for the prefixes to exclude.
- D. Attach the No-Export community with the prefixes to exclude
Answer: D
NEW QUESTION 40
How do endpoints inside an SD-Access network reach resources outside the fabric?
- A. SD-Access transit links are used to transport encapsulated traffic from one fabric to another
- B. A fabric edge is used to de-encapsulate VXLAN traffic to normal IP traffic then transported over the outside network
- C. Fabric borders use VRFs to map VNs to VRFs
- D. a VRF fusion router is used to map resources in one VN to another VN
Answer: B
NEW QUESTION 41
Drag and drop the descriptions from the left onto the corresponding VPN types on the rights.
Answer:
Explanation:
NEW QUESTION 42
A branch office has a primary L3VPN MPLS connection back to the main office and an IPSEC VPN tunnel that serves as backup. Which design ensures that data is sent over the backup connection only if the primary MPLS circuit is down?
- A. Use OSPF with a passive-interface command on the backup connection.
- B. Use BGP with the multipath feature enabled to force traffic via the primary path when available.
- C. Use static routes tied to an IP SLA to prefer the primary path while a floating static route points to the backup connection.
- D. Use EIGRP to establish a neighbor relationship with the main office via L3VPN MPLS and the IPSEC VPN tunnel.
Answer: A
NEW QUESTION 43
Which component of Cisco SD-Access integrates with Cisco DNA Center to perform policy segmentation and enforcement through the use of security group access control lists and security group tags?
- A. Cisco Network Data Platform
- B. Cisco TrustSec
- C. Cisco Identity Services Engine
- D. Cisco Application Policy Infrastructure Controller Enterprise Module
Answer: B
Explanation:
Section: Advanced Enterprise Campus Networks
NEW QUESTION 44
Which routes does the overlay management protocol advertise in an SD-WAN overlay?
- A. underlay, MPLS, and overlay
- B. primary, backup, and load-balanced
- C. Internet, MPLS, and backup
- D. prefix, TLOC, and service
Answer: D
NEW QUESTION 45
A network engineer must segregate three interconnected campus networks using IS-IS routing. A two-layer hierarchy must be used to support large routing domains and to avoid more specific routes from each campus network being advertised to other campus network routers automatically. Which two actions does the engineer take to accomplish this segregation? (Choose two.)
- A. Assign the same IS-IS NET value for each campus, and configure internal campus routers with Level 1/ Level 2 routing.
- B. Designate two IS-IS routers as BDR routers at the edge of each campus, and configure one BDR for all Level 1 routers and one BDR for all Level 2 routers.
- C. Utilize different MTU values for each campus network segment. Level 2 backbone routers must utilize a larger MTU size of 9216.
- D. Designate two IS-IS routers from each campus to act as Level 1/Level 2 backbone routers at the edge of each campus network.
- E. Assign a unique IS-IS NET value for each campus, and configure internal campus routers with Level 1 routing.
Answer: D,E
NEW QUESTION 46 
Refer to the exhibit. An engineer must design an automatic failover solution. The solution should allow HSRP to detect a WAN 1 failure and initiate an automatic failover, making router R2 the active HSRP router. Which two solutions should the engineer choose? (Choose two.)
- A. use IP source routing
- B. Implement Enhanced Object Tracking on roster R1
- C. Implement IP SLA on router R1
- D. Implement PBR on router R1
- E. use a floating static route
Answer: B,C
NEW QUESTION 47
......
Career Prospects
The certified professionals have the expertise in configuring and implementing the EIGRP-based solutions. Thus, they can take a prestigious job with a higher salary. Some of the roles that these individuals can explore include a Network Administrator, an IT Security Specialist, a Help Desk Technician, a Cloud Engineer, a Network Manager, a Network Engineer, and many more. The average remuneration for the certificate holders is $109,000 per annum.
Advanced Enterprise Campus Networks
This part makes up 25% of the whole content and measures the professionals’ knowledge of specific technical areas. These include the following:
- Designing the infrastructures for campus Layer 2, such as fast convergence, PoE & WoL, STP scalability, and loop-free technologies;
- Designing the infrastructures for multicampus Layer 3 (route summarization, convergence, VRFs, load sharing, redistribution, route filtering, and optimal topologies);
- Explaining overlay, underlay, security, automation, wireless, control & data plan of SD-Access architecture;
- Explaining the considerations for the SD-Access fabric design for wired and wireless access. These include fabric design, overlay, border design, control plan design, segmentation, as well as scalability, multicast, virtual networks, and over-the-top & fabric for wireless.
- Designing the campus network for high availability, including BFD, first-hop redundancy protocols, Graceful restart, and platform abstraction methods;
300-420 PDF Pass Leader, 300-420 Latest Real Test: https://www.testpassking.com/300-420-exam-testking-pass.html
Valid 300-420 Test Answers & 300-420 Exam PDF: https://drive.google.com/open?id=1Gg6-yvCLhVA3jS70-zn_d5FQ5SYi2L7c