Big Cyber Monday Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

300-540 Questions and Answers

Question # 6

An engineer must create a new VPC and deploy several Amazon EC2 instances in AWS. Only SSH connections originating from IP address 20.20.20.20 must be allowed to reach the EC2 instances. What must be configured?

A.

Access control list

B.

Security group

C.

Web application firewall

D.

Resource group

Full Access
Question # 7

Refer to the exhibit. An engineer must configure dual-homing with single active redundancy in a BGP EVPN VXLAN fabric. Which command must be run on the leaf router to complete the EVPN Ethernet segment configuration?

A.

redundancy single-active

B.

default-gateway advertise

C.

replication-type static

D.

vlan configuration 101

Full Access
Question # 8

Which command must be run on a Cisco IOS device to configure six parallel iBGP and eBGP routes that can be installed into a routing table?

A.

maximum paths bgp 6

B.

multipath eibgp 6

C.

maximum paths bgp routers 6

D.

maximum-paths eibgp 6

Full Access
Question # 9

Refer to the exhibit. An engineer must stop DDoS attacks on web and mail servers by using an ACL. Which two commands must be run on router R17? (Choose two.)

A.

access-list 101 deny ip 10.10.10.2 255.255.255.255 10.20.10.2 255.255.255.255

B.

access-list 101 deny ip 10.0.0.0 0.255.255.255 10.10.0.2 0.0.0.0

C.

access-list 101 deny ip 10.10.10.2 255.255.255.255 10.30.10.2 255.255.255.255

D.

access-list 101 deny ip 10.10.10.2 0.0.0.0 10.20.10.2 0.0.0.0

E.

access-list 101 deny ip 10.10.10.2 0.0.0.0 10.30.10.2 0.0.0.0

Full Access
Question # 10

A network architect must design a solution for implementing virtualization functions. The main goal is to ensure network reliability and reduce downtime by considering the network operational team's requirements:

    The solution must providereal-time network-state visibility.

    The solution must supportautomated rollback in the event of configuration errors.

    The solution must allowefficient troubleshooting and diagnostics.

Which action must the team take to achieve the goal?

A.

Implement CLI NED to monitor the network state and manually rollback configurations in case of errors.

B.

Implement virtualization service modeling to provide network automation for the service lifecycle and NSO CLI to provide real-time network-state visibility.

C.

Implement service modeling to define network services and NSO CLI for troubleshooting and diagnostics.

D.

Implement CLI NED to define network-virtualization template and package templates to automate the service lifecycle.

Full Access
Question # 11

Refer to the exhibit. An engineer must design a solution that allows a user to choose which private Cisco Catalyst SD-WAN network they want to connect to AWS. The solution must automatically identify the AWS VPC and other cloud services based on the user credentials. What must be used?

A.

AWS Direct Connect

B.

Transit VPC for AWS

C.

IPsec VPN

D.

Segment routing

Full Access
Question # 12

Refer to the exhibit. An engineer is troubleshooting a physical configuration issue in Cisco NFVI. Which two observations should be made? (Choose two.)

A.

The node allows two disks to fail.

B.

One RAID 1 disk failed.

C.

The node is still functional.

D.

The node is no longer functional.

E.

Two RAID 1 disks failed.

Full Access
Question # 13

Which format is used by Cisco Container Platform for configuration files?

A.

HTML

B.

YAML

C.

XHTML

D.

XML

Full Access
Question # 14

An engineer must design a high-availability solution that provides path redundancy for IP by allowing redundant gateways to share MAC protocols and addresses. A group of Layer 3 routers must be allowed to share the default gateway on a LAN, load balance, and seamlessly take over the traffic transfer role if a router in the group fails. What must be used?

A.

GLBP

B.

Load balancer

C.

Routed network core

D.

BFD

Full Access
Question # 15

What is a valid connection method between carrier-neutral facilities within the same metro area?

A.

OSPF backbone area adjacency

B.

private wireless connection

C.

DWDM ring

D.

CAT6e connection

Full Access
Question # 16

Refer to the exhibit. An engineer is troubleshooting an issue where switch LEAF-SW-1 and switch LEAF-SW-2 receive corrupted forwarding and learning information about each other. LEAF-SW-1 and LEAF-SW-2 are configured with BGP EVPN VTEP. Which action resolves the issue?

A.

On each switch, run the delete suppress-arp command against interface nve1.

B.

On each switch, configure a different secondary IP address against interface loopback0.

C.

On LEAF-SW-1, run the host-reachability protocol bgp command against interface nve1.

D.

On each switch, ensure the same BGP router ID is configured.

Full Access
Question # 17

Which two tools should be used to manage container orchestration? (Choose two.)

A.

Docker

B.

VMware vCenter

C.

Cisco vManage

D.

Kubernetes

E.

Cisco vSmart

Full Access
Question # 18

Refer to the exhibit. An engineer is troubleshooting an issue with switch LEAF-SW-11. The engineer observes that several main servers on the VXLAN BGP EVPN Multi-Site network experience 50–60% packet loss inbound and outbound, and all the DCI tracking interfaces are down. Which two actions must be taken to resolve the issue? (Choose two.)

A.

On the Nexus switch, run the inner ipv4 dst_ip 172.16.2.200 command against module-1.

B.

On LEAF-SW-11, run the inner ipv4 src_ip 172.16.2.200 command against module-1.

C.

On LEAF-SW-11, run the evpn multisite dci-tracking command against interface Eth1/1.

D.

On LEAF-SW-11, enable the multisite ingress-replication command for the L2VNI of VLAN 11.

E.

On the Nexus switch, run the ip access-list permit ip address 172.16.2.200 command.

Full Access