Big Cyber Monday Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Cisco 300-540 Dumps

Page: 1 / 6
Total 61 questions

Designing and Implementing Cisco Service Provider Cloud Network Infrastructure (SPCNI v1.0) Questions and Answers

Question 1

as

Refer to the exhibit. An engineer working for a private service provider with an employee ID 5207:22:409 must configure iBGP multipath load sharing across the three paths. Which two commands must be run on the PE router? (Choose two.)

Options:

A.

maximum-paths ibgp 3

B.

ip load-sharing per-destination

C.

ip load-sharing ibgp 3

D.

router bgp 101

E.

router bgp 100

Question 2

What should be used to protect against lateral movements during a Cisco NFVI security breach?

Options:

A.

Wi-Fi Protected Access

B.

Web application firewall

C.

Network segmentation

D.

Data encryption

Question 3

How does log management assist in meeting the requirements of cloud security regulatory compliance?

Options:

A.

by supporting documentation and reporting processes

B.

by streamlining resource allocation across cloud environments

C.

by providing enhanced interoperability between cloud platforms

D.

by boosting the security of cloud-based applications

Question 4

An engineer attempts to kill a NETCONF session. The session ID is equal to the current session. What is the effect of this action?

Options:

A.

An invalid-value error is returned, and the current user is not logged out.

B.

The session is terminated, and all the connected users are logged out.

C.

The configuration is saved, and the current user is logged out.

D.

The configuration is removed, and the current user is logged out.

Question 5

A network architect must design a solution for implementing virtualization functions. The main goal is to ensure network reliability and reduce downtime by considering the network operational team's requirements:

    The solution must providereal-time network-state visibility.

    The solution must supportautomated rollback in the event of configuration errors.

    The solution must allowefficient troubleshooting and diagnostics.

Which action must the team take to achieve the goal?

Options:

A.

Implement CLI NED to monitor the network state and manually rollback configurations in case of errors.

B.

Implement virtualization service modeling to provide network automation for the service lifecycle and NSO CLI to provide real-time network-state visibility.

C.

Implement service modeling to define network services and NSO CLI for troubleshooting and diagnostics.

D.

Implement CLI NED to define network-virtualization template and package templates to automate the service lifecycle.

Question 6

What does Cisco Always-On Cloud DDoS use to protect against DDoS attacks?

Options:

A.

Load balancing

B.

Botnet zombies

C.

Traffic mirroring

D.

Scrubbing centers

Question 7

as

as

Refer to the exhibit. An engineer is troubleshooting an issue with switch LEAF-SW-11. The engineer observes that several main servers on the VXLAN BGP EVPN Multi-Site network experience 50–60% packet loss inbound and outbound, and all the DCI tracking interfaces are down. Which two actions must be taken to resolve the issue? (Choose two.)

Options:

A.

On the Nexus switch, run the inner ipv4 dst_ip 172.16.2.200 command against module-1.

B.

On LEAF-SW-11, run the inner ipv4 src_ip 172.16.2.200 command against module-1.

C.

On LEAF-SW-11, run the evpn multisite dci-tracking command against interface Eth1/1.

D.

On LEAF-SW-11, enable the multisite ingress-replication command for the L2VNI of VLAN 11.

E.

On the Nexus switch, run the ip access-list permit ip address 172.16.2.200 command.

Question 8

How does log management assist in meeting the requirements of cloud security regulatory compliance?

Options:

A.

by supporting documentation and reporting processes

B.

by streamlining resource allocation across cloud environments

C.

by providing enhanced interoperability between cloud platforms

D.

by boosting the security of cloud-based applications

Question 9

Which command must be run on a Cisco IOS device to configure six parallel iBGP and eBGP routes that can be installed into a routing table?

Options:

A.

maximum paths bgp 6

B.

multipath eibgp 6

C.

maximum paths bgp routers 6

D.

maximum-paths eibgp 6

Question 10

An engineer must implement a solution on a Cisco ASR 1000 Series router to protect against DDoS attacks. DDoS traffic must be dropped by transmitting Flowspec attributes to edge routers, instructing them to generate an ACL via class-maps and policy-maps. The engineer already configured BGP neighbors. Which action must be taken next?

Options:

A.

Configure Flowspec for the BGP address-family

B.

Set the BGP routing process

C.

Activate the BGP neighbors

D.

Configure the route reflector

Question 11

Which two network segments are needed to support Cisco VIM? (Choose two.)

Options:

A.

Provisioning

B.

Data plane

C.

Heartbeat

D.

Host

E.

Storage

Question 12

What is a capability of a Cisco NFVIS SNMP trap?

Options:

A.

Monitors the activities of a network host

B.

Controls the activities of a network host

C.

Sends an unsolicited notification to the SNMP manager

D.

Retrieves an SNMP object variable from the MIB

Question 13

What does enabling gRPC allow in Cisco NFVI Assurance and Monitoring?

Options:

A.

telemetry streaming

B.

IPFIX monitoring

C.

Cisco IOS NetFlow monitoring

D.

system logging

Question 14

An engineer must create a new VPC and deploy several Amazon EC2 instances in AWS. Only SSH connections originating from IP address 20.20.20.20 must be allowed to reach the EC2 instances. What must be configured?

Options:

A.

Access control list

B.

Security group

C.

Web application firewall

D.

Resource group

Question 15

What is a capability of a Cisco NFVIS SNMP trap?

Options:

A.

Monitors the activities of a network host

B.

Controls the activities of a network host

C.

Sends an unsolicited notification to the SNMP manager

D.

Retrieves an SNMP object variable from the MIB

Question 16

as

as

Refer to the exhibit. The indicated configuration was applied to a Cisco switch Switch_A located in the Los Angeles DC data center; however, Switch_A fails to establish OTV connectivity to Cisco switch Switch_C. Which overlay interface command must be run on Switch_A to resolve the issue?

Options:

A.

otv extend-vlan 101-111

B.

otv isis authentication-type md5

C.

otv isis authentication-check

D.

otv join-interface vlan 101-111

Question 17

What is a benefit of using VXLANs in a cloud-scale environment?

Options:

A.

extends Layer 2 segments across the underlying Layer 3 infrastructure

B.

extends Layer 3 segments across the underlying Layer 2 infrastructure

C.

reduces spanning-tree complexity across the Layer 2 infrastructure

D.

eliminates the need for a Layer 3 underlay in the service provider infrastructure

Question 18

What is a valid connection method between carrier-neutral facilities that are more than 20 miles away from each other?

Options:

A.

Carrier access Ethernet ring

B.

Private wireless connection

C.

CAT6e connection

D.

Multimode fiber connection

Page: 1 / 6
Total 61 questions