New 2020 CCNP 300-410 ENARSI exam questions from PassLeader 300-410 dumps! Welcome to download the newest PassLeader 300-410 VCE and PDF dumps: https://www.passleader.com/300-410.html (350 Q&As –> 406 Q&As –> 689 Q&As –> 740 Q&As) [Lab Simulations Available]
P.S. Free 2020 CCNP 300-410 ENARSI dumps are available on Google Drive shared by PassLeader: https://drive.google.com/open?id=1AR525EpkM4rOj60-INeVcfoGkNJfT8PY
NEW QUESTION 331
Which IPv6 first hop security feature controls the traffic necessary for proper discovery of neighbor device operation and performance?
A. RA Throttling
B. Source or Destination Guard
C. ND Multicast Suppression
D. IPv6 Snooping
Answer: D
NEW QUESTION 332
A customer requested a GRE tunnel through the provider network between two customer sites using loopback to hide internal networks. Which configuration on R2 establishes the tunnel with R1?
A. R2(config)# interface Tunnel 1
R2(config-if)# ip address 172.20.1.2 255.255.255.0
R2(config-if)# ip mtu 1400
R2(config-if)# ip tcp adjust-mss 1360
R2(config-if)# tunnel source 192.168.20.1
R2(config-if)# tunnel destination 192.168.10.1
B. R2(config)# interface Tunnel 1
R2(config-if)# ip address 172.20.1.2 255.255.255.0
R2(config-if)# ip mtu 1400
R2(config-if)# ip tcp adjust-mss 1360
R2(config-if)# tunnel source 10.10.2.2
R2(config-if)# tunnel destination 10.10.1.1
C. R2(config)# interface Tunnel 1
R2(config-if)# ip address 172.20.1.2 255.255.255.0
R2(config-if)# ip mtu 1500
R2(config-if)# ip tcp adjust-mss 1360
R2(config-if)# tunnel source 192.168.20.1
R2(config-if)# tunnel destination 10.10.1.1
D. R2(config)# interface Tunnel 1
R2(config-if)# ip address 172.20.1.2 255.255.255.0
R2(config-if)# ip mtu 1500
R2(config-if)# ip tcp adjust-mss 1360
R2(config-if)# tunnel source 10.10.2.2
R2(config-if)# tunnel destination 10.10.1.1
Answer: D
NEW QUESTION 333
A network administrator added a new spoke site with dynamic IP on the DMVPN network. Which configuration command passes traffic on the DMVPN tunnel from the spoke router?
A. ip nhrp registration ignore
B. ip nhrp registration no-registration
C. ip nhrp registration dynamic
D. ip nhrp registration no-unique
Answer: D
NEW QUESTION 334
Which IPv6 feature enables a device to reject traffic when it is originated from an address that is not stored in the device binding table?
A. IPv6 Snooping
B. IPv6 Source Guard
C. IPv6 DAD Proxy
D. IPv6 RA Guard
Answer: B
Explanation:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-3s/ip6f-xe-3s-book/ip6-src-guard.html
NEW QUESTION 335
An engineer failed to run diagnostic commands on devices using Cisco DNA Center. Which action in Cisco DNA Center resolves the issue?
A. Enable Command Runner
B. Enable APIs
C. Enable CDP
D. Enable Secure Shell
Answer: A
NEW QUESTION 336
Which two solutions are used to overcome a flapping link that causes a frequent label binding exchange between MPLS routers? (Choose two.)
A. Create link dampening on links to protect the session.
B. Increase input queue on links to protect the session.
C. Create targeted hellos to protect the session.
D. Increase a hold-timer to protect the session.
E. Increase a session delay to protect the session.
Answer: AC
Explanation:
To avoid having to rebuild the LDP session altogether, you can protect it. When the LDP session between two directly connected LSRs is protected, a targeted LDP session is built between the two LSRs. When the directly connected link does go down between the two LSRs, the targeted LDP session is kept up as long as an alternative path exists between the two LSRs. For the protection to work, you need to enable it on both the LSRs. If this is not possible, you can enable it on one LSR, and the other LSR can accept the targeted LDP Hellos by configuring the command mpls ldp discovery targeted-hello accept.
https://www.ccexpert.us/mpls-network/mpls-ldp-session-protection.html
https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2019/pdf/5eU6DfQV/TECMPL-3201.pdf
NEW QUESTION 337
What is a function of an end device configured with DHCPv6 guard?
A. If it is configured as a server, only prefix assignments are permitted.
B. If it is configured as a relay agent, only prefix assignments are permitted.
C. If it is configured as a client, messages are switched regardless of the assigned role.
D. If it is configured as a client, only DHCP requests are permitted.
Answer: C
NEW QUESTION 338
Which two components are required for MPLS Layer 3 VPN configuration? (Choose two.)
A. Use pseudowire for Layer 2 routes.
B. Use MP-BGP for customer routes.
C. Use OSPF between PE and CE.
D. Use a unique RD per customer VRF.
E. Use LDP for customer routes.
Answer: CD
NEW QUESTION 339
Which method provides failure detection in BFD?
A. short duration, high overhead
B. short duration, low overhead
C. long duration, high overhead
D. long duration, low overhead
Answer: B
NEW QUESTION 340
A newly installed spoke router is configured for DMVPN with the ip mtu 1400 command. Which configuration allows the spoke to use fragmentation with the maximum negotiated TCP MTU over GRE?
A. ip tcp adjust-mss 1360
crypto ipsec fragmentation after-encryption
B. ip tcp adjust-mtu 1360
crypto ipsec fragmentation after-encryption
C. ip tcp adjust-mss 1360
crypto ipsec fragmentation mtu-discovery
D. ip tcp adjust-mtu 1360
crypto ipsec fragmentation mtu-discovery
Answer: A
Explanation:
https://www.cisco.com/c/en/us/support/docs/security/dynamic-multipoint-vpn-dmvpn/111976-dmvpn-troubleshoot-00.html
NEW QUESTION 341
What are the two goals of micro BFD sessions? (Choose two.)
A. The high bandwidth member link of a link aggregation group must run BFD.
B. Run the BFD session with 3×3 ms hello timer.
C. Continuity for each member link of a link aggregation group must be verified.
D. Eny member link on a link aggregation group must run BFD.
E. Each member link of a link aggregation group must run BFD.
Answer: CE
Explanation:
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_bfd/configuration/xe-16-8/irb-xe-16-8-book/irb-micro-bfd.html
NEW QUESTION 342
Which feature minimizes DoS attacks on an IPv6 network?
A. IPv6 Binding Security Table
B. IPv6 Router Advertisement Guard
C. IPv6 Prefix Guard
D. IPv6 Destination Guard
Answer: D
Explanation:
The Destination Guard feature helps in minimizing denial-of-service (DoS) attacks. It performs address resolutions only for those addresses that are active on the link, and requires the FHS binding table to be populated with the help of the IPv6 snooping feature.The feature enables the filtering of IPv6 traffic based on the destination address, and blocks the NDP resolution for destination addresses that are not found in the binding table. By default, the policy drops traffic coming for an unknown destination.
https://www.cisco.com/c/en/us/td/docs/routers/7600/ios/15S/configuration/guide/7600_15_0s_book/IPv6_Security.pdf
NEW QUESTION 343
A CoPP policy is applied for receiving SSH traffic from the WAN interface on a Cisco ISR4321 router. However, the SSH response from the router is abnormal and stuck during the high link utilization. The problem is identified as SSH traffic does not match in the ACL. Which action resolves the issue?
A. Rate-limit SSH traffic to ensure dedicated bandwidth.
B. Apply CoPP on the control plane interface.
C. Increase the IP precedence value of SSH traffic to 6.
D. Apply CoPP on the WAN interface inbound direction.
Answer: B
NEW QUESTION 344
Refer to the exhibit:
R4 is experiencing packet drop when trying to reach 172.16.2.7 behind R2. Which action resolves the issue?
A. Insert a /16 floating static route on R2 toward R3 with metric 254.
B. Insert a /24 floating static route on R2 toward R3 with metric 254.
C. Enable auto summarization on all three routers R1, R2, and R3.
D. Disable auto summarization on R2.
Answer: D
NEW QUESTION 345
Refer to exhibit:
PC2 is directly connected to R1. A user at PC2 cannot Telnet to 2001:db8:a:b::10. The user can ping 2001:db8:a:b::10 and receive DHCP-related information from the DHCP server. Which action resolves the issue?
A. Remove sequence 10 and put it back as sequence 25.
B. Remove sequence 20 and put it back as sequence 45.
C. Remove sequence 30 and put it back as sequence 5.
D. Remove sequence 40 and put it back as sequence 15.
Answer: A
NEW QUESTION 346
Refer to the exhibit:
An engineer configured BGP and wants to select the path from 10.77.255.57 as the best path instead of current best path. Which action resolves the issue?
A. Configure AS_PATH prepend for the current best path.
B. Configure higher MED to select as the best path.
C. Configure AS_PATH prepend for the desired best path.
D. Configure lower LOCAL_PREF to select as the best path.
Answer: D
NEW QUESTION 347
……
New 2020 CCNP 300-410 ENARSI exam questions from PassLeader 300-410 dumps! Welcome to download the newest PassLeader 300-410 VCE and PDF dumps: https://www.passleader.com/300-410.html (350 Q&As –> 406 Q&As –> 689 Q&As –> 740 Q&As) [Lab Simulations Available]
P.S. Free 2020 CCNP 300-410 ENARSI dumps are available on Google Drive shared by PassLeader: https://drive.google.com/open?id=1AR525EpkM4rOj60-INeVcfoGkNJfT8PY