100% Free Real Updated 300-420 Questions & Answers Pass Your Exam Easily
Easily To Pass New 300-420 Verified & Correct Answers
Cisco 300-420 exam covers a wide range of topics related to network design, including advanced routing and switching technologies, security, virtualization, automation, and network assurance. Candidates are expected to have a deep understanding of network design principles and best practices, as well as the ability to apply this knowledge to real-world scenarios. Passing 300-420 exam demonstrates that the candidate has the skills and knowledge necessary to design and implement complex, scalable, and secure enterprise networks using Cisco technologies.
NEW QUESTION # 149
Refer to the exhibit. An engineer must design a WAN solution so that ISP-1 is always preferred over ISP-2. The path via ISP-2 is considered as a backup and must be used only when the path to ISP-1 is down. Which solution must the engineer choose?
- A. R1:
- Routes advertised to ISP-1: 0x AS-path prepend
- Routes received from ISP-1: HIGH local-preference
- Routes advertised to R2: no action
- Routes received from R2: community NO-EXPORT
R2:
- Routes advertised to ISP-2:5x AS-path prepend
- Routes received from ISP-2: LOW local-preference
- Routes advertised to R1: community NO-ADVERTISE
- Routes received from R1: no action - B. R1:
- Routes advertised to ISP-1: 0x AS-path prepend
- Routes received from ISP-1: LOW local-preference
- Routes advertised to R2: community NO-ADVERTISE
- Routes received from R2: no action
R2:
- Routes advertised to ISP-2: 5x AS-path prepend
- Routes received from ISP-2: HIGH local-preference
- Routes advertised to R1: no action
- Routes received from R1: community NO-ADVERTISE - C. R1:
- Routes advertised to ISP-1: 5x AS-path prepend
- Routes received from ISP-1: LOW local-preference
- Routes advertised to R2: community NO-ADVERTISE
- Routes received from R2: no action
R2:
- Routes advertised to ISP-2: 0x AS-path prepend
- Routes received from ISP-2: HIGH local-preference
- Routes advertised to R1: community NO-EXPORT
- Routes received from R1: no action - D. R1:
- Routes advertised to ISP-1: 0x AS-path prepend
- Routes received from ISP-1: HIGH local-preference
- Routes advertised to R2: community NO-EXPORT
- Routes received from R2: no action
R2:
- Routes advertised to ISP-2: 5x AS-path prepend
- Routes received from ISP-2: LOW local-preference
- Routes advertised to R1: no action
- Routes received from R1: no action
Answer: D
NEW QUESTION # 150
Refer to the exhibit.
An architect is designing a routing solution for a company. The new design will add a circuit routers C and D to protect against loss of connectivity to 10.0.4.0/24 during a link failure between routers B and D. Which solution must the architect choose?
- A. Stub leak-map
- B. Stub redistributed
- C. Stub receive-only
- D. Stub connected
Answer: D
NEW QUESTION # 151
Refer to the exhibit.
A network engineer is designing a network for AS100. The design should ensure that all traffic enters AS100 via link 1 unless there is a network failure. In the event of a failure, link 2 should function as the path for incoming traffic. Which solution should the design include?
- A. Modify the next-hop attribute on R4.
- B. Modify the next-hop attribute on R3.
- C. Use AS-Path prepending on R4.
- D. Use AS-Path prepending on R3.
Answer: C
NEW QUESTION # 152
What are the three foundational elements required for the new operational paradigm? (Choose three.)
- A. assurance
- B. centralization
- C. policy-based automated provisioning of network
- D. application QoS
- E. fabric
- F. multiple technologies at multiple OSI layers
Answer: A,C,E
NEW QUESTION # 153
Refer to the exhibit.
EIGRP has been configured on all links. The spoke nodes have been configured as EIGRP stubs, and the WAN links to R3 have higher bandwidth and lower delay than the links to R4. When a link failure occurs at the R1-R2 link, what happens to traffic on R1 that is destined for a subnet attached to R2?
- A. R1 forwards the traffic to R3, but R3 drops the traffic
- B. R1 forwards the traffic to R3 in order to reach R2
- C. R1 has no route to R2 and drops the traffic
- D. R1 load-balances across the paths through R3 and R4 to reach R2
Answer: C
Explanation:
Explanation
The EIGRP stub routing feature will prevent the remote device from advertising core routes back to the distribution devices. Routes learned by the remote device from Distribution 1 will not be advertised to Distribution 2. Therefore, Distribution 2 will not use the remote device as a transit for traffic destined to the network corehttps://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_eigrp/configuration/15-mt/ire-15-mt-book/ire-eig
NEW QUESTION # 154
A network engineer must design a multicast solution to prevent the spoofing of multicast streams and ensure efficient bandwidth utilization. The network will be merged with another multicast domain in the future, and the merge must require minimum effort. Which two solutions meet the customer requirements? (Choose two.)
- A. IGMPv3
- B. MSDP
- C. IGMPv2
- D. PIM-SSM
- E. PIM-SM
Answer: B,E
Explanation:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipmulti_pim/configuration/xe-16/imc-pim-xe-16-book/imc-msdp-im-pim-sim.html#GUID-4B201DB3-2C27-4F98-977A-A1AE9DC39C21 MSDP is a mechanism to connect multiple PIM-SM domains. The purpose of MSDP is to discover multicast sources in other PIM domains. The main advantage of MSDP is that it reduces the complexity of interconnecting multiple PIM-SM domains by allowing PIM-SM domains to use an interdomain source tree (rather than a common shared tree).
NEW QUESTION # 155
Drag and drop the characteristics from the left onto the telemetry mode they apply to on the right.
Answer:
Explanation:
Explanation:
Dial-In: collector initiates a session to the device; supports gRPC only. Dial-Out: device initiates a session to the collector; supports TCP, UDP, and gRPC.
Model-driven telemetry can be deployed in dial-in or dial-out mode, and the difference is which side initiates the session and where the subscription is controlled. In dial-in mode, the collector initiates the session to the network device and requests the telemetry subscription. This makes the collector responsible for establishing the session and asking for the data stream. In the context of the provided options, dial-in is paired with support for gRPC only. In dial-out mode, the network device initiates the session toward the collector according to a configured subscription. This is useful when devices sit behind NAT or when the operational model requires devices to push telemetry to a known collector. In the provided choices, dial-out is paired with support for TCP, UDP, and gRPC. The mapping is not arbitrary; it follows Cisco telemetry terminology, where dial-in is collector-initiated and dial-out is device-initiated. This distinction is important in network automation designs because firewall policy, collector scaling, and subscription lifecycle management differ between the two modes.
NEW QUESTION # 156 
Refer to the exhibit. An engineer Is designing a redistribution solution for a customer. The customer recently acquired another company and decided to integrate the new network running RlPv1 with the company's existing network. Which redistribution technique must the engineer select to ensure the multipoint two-way redistribution does not cause routing loops?
- A. distribute-lists outbound under the RIPv1 process denying EIGRP learned prefixes
- B. distribute-lists inbound under the RIPv1 process denying EIGRP learned prefixes
- C. distribute-lists inbound under the EIGRP process denying RIPv1 learned prefixes
- D. distribute-lists outbound under the EIGRP process denying RIPv1 learned prefixes
Answer: A
NEW QUESTION # 157
Which two primary categories are displayed on the overall health page of the assurance component in the Cisco DNA Center? (Choose two.)
- A. Access-Distribution
- B. Server
- C. Network
- D. Core
- E. Wired
- F. Client
Answer: C,F
NEW QUESTION # 158
When vEdge router redundancy is designed, which FHRP is supported?
- A. HSRP
- B. OMP
- C. VRRP
- D. GLBP
Answer: C
NEW QUESTION # 159
Which feature of Cisco SD-WAN Secure Direct Cloud Access divides user traffic into different zones and VPNs or VRFs?
- A. perimeter control
- B. application-awareness routing
- C. secure segmentation
- D. centralized data policy
Answer: C
Explanation:
Secure segmentation is the Cisco SD-WAN Secure Direct Cloud Access function that separates user traffic into different zones and VPNs or VRFs. In Cisco SD-WAN, VPNs provide logical segmentation that is comparable to VRF separation in traditional routing. Secure Direct Cloud Access extends this segmentation model when users access internet and cloud applications directly from the branch. The design can keep corporate, guest, payment, voice, IoT, and other traffic classes isolated, with policy and security controls applied per segment or zone. Centralized data policy controls forwarding behavior, but the feature that divides traffic into separate zones and VPN or VRF contexts is secure segmentation. Perimeter control and application-aware routing are useful security and performance functions, but they do not describe the core segmentation mechanism. Segmentation is a fundamental SD-WAN design requirement because direct cloud access must not collapse trust boundaries simply because traffic no longer hairpins through a central data center. Reference topics: Cisco SD-WAN secure segmentation, VPNs, VRFs, direct cloud access, zone-based policy.
NEW QUESTION # 160
Refer to the exhibit. A company designed a new WAN connectivity plan and asked an engineer to review the design. The company wants to increase overall resiliency and minimize costs. Which configuration meets these requirements?
- A. router with dual power supplies
- B. WAN circuit that is monitored with SNMPv3
- C. dynamic routing protocol on the WAN connection
- D. chassis-based router with dual supervisor engines
Answer: C
Explanation:
A dynamic routing protocol on the WAN connection improves resiliency by allowing routing updates and path changes to occur automatically when reachability changes. It also minimizes cost because it uses existing WAN infrastructure rather than requiring additional hardware such as redundant chassis components or power supplies.
NEW QUESTION # 161
An engineer must design a multicast network for a financial application. Most of the multicast sources also receive multicast traffic (many-to-many deployment model). To better scale routing tables, the design must not use source trees. Which multicast protocol satisfies these requirements?
- A. MSDP
- B. BIDIR-PIM
- C. PIM-SM
- D. PIM-SSM
Answer: B
Explanation:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipmulti_pim/configuration/xe-16/imc-pim-xe-16-book/imc-tech-oview.html Bidir-PIM is designed to be used for many-to-many applications within individual PIM domains. Multicast groups in bidirectional PIM mode can scale to an arbitrary number of sources without incurring overhead due to the number of sources.
NEW QUESTION # 162
What is the purpose of the RPF check in multicast routing?
- A. to ensure that multicast packets are forwarded if they arrived on the interface used to route traffic to the destination address
- B. to ensure that multicast packets are forwarded if they arrived on the interface used to route traffic back to the source address
- C. to ensure that multicast packets are dropped if they arrived on the interface used to route traffic back to the source address
- D. to ensure that multicast packets, no matter the interface they arrived on, are forwarded out all interfaces
- E. to ensure that multicast packets are dropped if they arrived on the interface used to route traffic to the destination address
Answer: B
NEW QUESTION # 163
Which two border nodes are available in the Cisco SD-Access architecture? (Choose two.)
- A. edge border
- B. extended border
- C. intermediate border
- D. anywhere border
- E. internal border
Answer: B,D
Explanation:
Section: Advanced Enterprise Campus Networks
NEW QUESTION # 164
When designing interdomain multicast, which two protocols are deployed to achieve communication between multicast sources and receivers? (Choose two.)
- A. MP-BGP
- B. BIDIR-PIM
- C. MLD
- D. MSDP
- E. IGMPv2
Answer: A,D
Explanation:
MSDP (Multicast interdomain discovery protocol) should exchange routing information using BGP.
NEW QUESTION # 165
Refer to the exhibit.
A customer is running HSRP on the core routers. Over time the company has grown and requires more network capacity. In the current environment, some of the downstream interfaces are almost fully utilized, but others are not. Which solution improves the situation?
- A. Add more interfaces to R1 and R2.
- B. Enable RSTP on the downstream switches.
- C. Make router R2 active for half of the VLANs.
- D. Configure port channel toward downstream switches.
Answer: C
NEW QUESTION # 166
Drag and drop the descriptions from the left onto the Cisco SD-WAN component they describe on the right.
Answer:
Explanation:
NEW QUESTION # 167
Refer to the exhibit.
Refer to the exhibit. The connection between SW2 and SW3 is fiber and occasionally experiences unidirectional link failure. An architect must optimize the network to reduce the change of layer2 forwarding loops when the link fails. Which solution should the architect include?
- A. Utilize loop guard on SW2
- B. Utilize 8PDU filter on SW3.
- C. Utilize BPDU guard on SW1
- D. Utilize root guard on SW1.
Answer: A
NEW QUESTION # 168
Drag and drop the description from the left onto the corresponding WAN connectivity types and categories on the right.
Answer:
Explanation:
NEW QUESTION # 169
Which encoding languages are supported in NETCONF compared to RESTCONF?
- A. NETCONF supports XML and JSON, and RESTCONF supports XML.
- B. NETCONF supports XML, and RESTCONF supports JSON.
- C. NETCONF supports XML, and RESTCONF supports XML and JSON.
- D. NETCONF supports JSON, and RESTCONF supports XML.
Answer: C
Explanation:
NETCONF supports XML, while RESTCONF supports both XML and JSON. Cisco programmability documentation describes NETCONF as an XML-based protocol that exchanges RPC requests and replies such as get, get-config, and edit-config using XML encoding. NETCONF is tightly aligned with YANG- modeled data, but the protocol message format itself is XML. RESTCONF exposes YANG-modeled data through an HTTP or HTTPS API and can represent payloads in XML or JSON. Cisco DevNet material commonly summarizes the comparison as NETCONF equals XML, while RESTCONF equals XML or JSON. That is why option D is accurate. Option A is wrong because NETCONF does not use JSON in the same way RESTCONF does. Option B is incomplete because RESTCONF is not limited to JSON. Option C reverses the protocol encodings. This distinction matters in automation design because tool selection, content type, parsing, and API workflows differ by protocol. Reference topics: NETCONF, RESTCONF, YANG, XML encoding, JSON encoding, model-driven programmability.
NEW QUESTION # 170
Refer to the exhibit. A company deploying IPv6 in parallel with its already existing IPv4 network must ensure that IPv6-only islands can communicate with each other. The company wants to grow IPv6 islands over time without introducing additional configuration complexity. Which solution must the company choose?
- A. MP-BGP
- B. GRE tunnels
- C. NAT
- D. LISP
Answer: D
Explanation:
LISP (Locator/ID Separation Protocol) allows IPv6-only islands to communicate over an IPv4-only core by encapsulating IPv6 packets, simplifying interconnection and future expansion without increasing configuration complexity.
NEW QUESTION # 171
Refer to the exhibit. Which process does the Ethernet LMI protocol follow that is defined by the MEF 16 Technical Specification?
- A. notifies the CE of the availability state of a configured EVC
- B. communicates ENI and EVC attributes to the CE
- C. broadcasts to all subnets from the CE when an EVC is added
- D. broadcasts multicast network routes from the CE to the PE
Answer: B
NEW QUESTION # 172
Which security functionality does gRPC provide?
- A. supporting secure communication between network devices and control systems using TLS
- B. implementing secure server-client tunnels with RSA 20*8 cipher encryption
- C. mandatory encryption of data at rest using the AES and RSA protocols
- D. enabling RC6 data-level encryption with CRC check
Answer: A
NEW QUESTION # 173
A company wants to switch from static routing to a dynamic routing protocol to ease the administrative and operational overhead. The network topology is hub and spoke, and the branches use DMVPN back to the hub using two 100 Mbps internet connections. Both links must be used due to spikes in traffic, and routing must take traffic utilization of the links into account.
Also, the branch routers have limited memory and CPU resources.
Which routing protocol and design solution must the company choose?
- A. EIGRP with branch routers as stub routers using ECMP
- B. iBGP with the hub routers set up as route reflectors and branches set up as clients
- C. OSPF deployed in area 0 with branch routers connecting from area 1
- D. ISIS with the hub and spoke routers configured in two different areas
Answer: A
NEW QUESTION # 174
......
Read the topics of the Cisco 300-420 Exam
Candidates must know the topics before they start of preparation. Because it will really help them in hitting the core. Our Cisco 300-420 exam dumps will include the following topics:
- WAN for Enterprise Networks 20%
- Advanced Addressing and Routing Solutions 25%
- Automation 10%
- Network Services 20%
- Advanced Enterprise Campus Networks 25%
Topics of Cisco 300-420 Exam
The Cisco 300-420 certification exam validates the students’ knowledge of enterprise design. It covers a wide range of subject areas, such as advanced addressing & routing solutions, security services, WAN, advanced enterprise campus networks, SDA, and network services. The breakdown of these topics into the components of skills to be measured in the test is as follows:
Advanced Routing and Addressing Solutions
About 25% of the exam content is covered in this domain, and the candidates have to perform their skills in the following tasks:
- Developing the scalable, stable, and secure routing design for EIGRP, IS-IS, BGP, OSPF.
- Creating the structured addressing strategies for both IPv6 & IPv4;
Free 300-420 Exam Files Downloaded Instantly: https://www.vceprep.com/300-420-latest-vce-prep.html
Verified & Latest 300-420 Dump Q&As with Correct Answers: https://drive.google.com/open?id=1Zr5loPKSxIEHR2jf9yGIJI_N8XcOXJCP