350-501 Sample Questions & Answers
L2VPN, L3VPN and multicast service delivery carry real weight here, alongside IS-IS, OSPF and BGP routing protocols, engineering traffic across MPLS with segment routing, core and transport architecture concepts, and automation tooling for assurance.
Launch the full 350-501 simulator →Showing 9 of 19 free samples.
- Question 1Intermediate
Services · E-VPN (Ethernet VPN)
A financial services company, 'FinSecure', is migrating its legacy VPLS services to a more scalable EVPN-MPLS solution. A key requirement is to prevent Layer 2 loops and control broadcast, unknown unicast, and multicast (BUM) traffic flooding between different segments of the same EVI. The network topology consists of a central hub site and multiple spoke sites. Spoke sites should be able to communicate with the hub but not directly with each other at Layer 2. Which EVPN feature must be implemented to meet this specific requirement?
Show answer & explanation
Correct answer: B
EVPN E-Tree is a service specifically designed for hub-and-spoke Layer 2 topologies. It categorizes attachment circuits as either 'root' (hub) or 'leaf' (spoke). The forwarding logic of E-Tree allows root-to-leaf, leaf-to-root, and root-to-root communication, but explicitly blocks leaf-to-leaf communication at Layer 2. This perfectly matches the requirement to allow spokes to talk to the hub but not to each other, effectively preventing loops and controlling BUM traffic between spoke sites.
- Question 2Intermediate
Architecture · Quality of Service (QoS) architecture
A consultant is designing a QoS policy for a service provider network that uses MPLS. The provider wants to ensure that customer IP Precedence markings are preserved and used for queuing decisions within the MPLS core, but they do not want to trust the full DSCP value. The provider has standardized on mapping IP Precedence values directly to MPLS EXP bits. Which QoS configuration model should be implemented on the ingress PE routers?
Show answer & explanation
Correct answer: B
The Pipe Model (also known as the Uniform Model) in MPLS DiffServ provides a single, consistent QoS treatment from end-to-end. In this model, the IP Precedence or DSCP value is mapped to the MPLS EXP bits at the ingress PE. This EXP value is then used for queuing and scheduling decisions across the MPLS core. Crucially, at the egress PE, the EXP value is mapped back to the IP header's ToS byte. This ensures that any QoS remarking done in the core (if any) is reflected in the IP packet, maintaining a uniform QoS policy. The requirement to map IP Precedence to EXP and use it throughout the core is the definition of the Pipe/Uniform model.
- Question 3Advanced
Networking · BGP implementation
During the implementation of BGP FlowSpec on an IOS-XR router to mitigate a DDoS attack, a network operator defines a FlowSpec rule to drop traffic destined for a specific victim IP. The operator applies the service policy to the BGP process. However, the malicious traffic is still reaching the destination. What is a critical missing configuration step required to activate BGP FlowSpec traffic filtering on the router's data plane?
Show answer & explanation
Correct answer: B
In IOS-XR, BGP FlowSpec has a separate control plane and data plane component. While the rules are received and programmed into BGP via the address-family configuration, they are not enforced in the data plane until a specific
flowspecservice policy is attached to the physical or logical ingress interfaces. This action instructs the forwarding plane (FIB) to program the dynamic ACLs generated by the FlowSpec rules onto the interface hardware. Without this step, the router knows about the rule but does not actively filter traffic based on it. - Question 4Intermediate
Networking · IS-IS implementation
A service provider is configuring IS-IS in a large, multi-level network. To improve scalability and reduce the size of the Link-State Database (LSDB) on Level 1 routers, the network architect decides to use route summarization at the L1/L2 border. The following command is configured on the L1/L2 router:
summary-address 10.10.0.0 255.255.0.0 level-1What is the effect of this command on the IS-IS operation?
Show answer & explanation
Correct answer: D
In IS-IS, summarization is performed as routes are advertised into an area or level. The command
summary-address 10.10.0.0 255.255.0.0 level-1on an L1/L2 router instructs it to advertise a single summary route (10.10.0.0/16) down into the Level 1 area. This summary represents routes that the L1/L2 router has learned from other sources, such as the Level 2 backbone or redistributed routes. This prevents the more specific prefixes from being flooded into the Level 1 area, thus reducing the LSDB size on L1-only routers. - Question 5Advanced
MPLS and Segment Routing · Segment Routing
Case Study: GlobalTrans Logistics MPLS Network Upgrade
Company Background:
GlobalTrans Logistics is a worldwide shipping and logistics company that operates a large private MPLS network connecting its regional headquarters, distribution centers, and major port facilities. The network is built on Cisco hardware and currently uses LDP for label distribution and OSPF as the IGP. The network is divided into three major geographical regions: North America (NA), Europe (EU), and Asia-Pacific (APAC), each running as a separate OSPF Area 0, interconnected via an Inter-AS MPLS backbone.Current Situation:
The company is experiencing significant growth, leading to increased traffic and more complex application requirements. The current network design is facing challenges with traffic engineering and meeting strict SLAs for latency-sensitive applications like real-time cargo tracking and automated port machinery control. The network operations team finds it difficult to steer specific traffic types over non-default paths to avoid congestion. They are also preparing to deploy 5G services at their smart port facilities, which will require network slicing capabilities.Requirements:
- Traffic Engineering: Implement a solution that allows for granular, policy-based traffic steering for critical applications without the complexity of a full-mesh of RSVP-TE tunnels.
- Scalability: The new solution must be highly scalable and simplify the control plane, reducing the protocol state that needs to be maintained on core routers.
- Future-Proofing: The architecture must provide a clear path towards network slicing and service function chaining for future 5G and IoT deployments.
- Simplified Operations: Reduce the operational overhead associated with path management and provisioning.
Problem:
As the lead network architect, you are tasked with recommending a core technology upgrade to meet these requirements. The solution must integrate with the existing MPLS data plane and OSPF IGP with minimal disruption. Which solution best addresses all of GlobalTrans's requirements?Show answer & explanation
Correct answer: B
Segment Routing (SR-MPLS) is the ideal solution. 1) It provides powerful source-based traffic engineering by allowing the headend router to specify an explicit path as a stack of labels (SIDs), meeting the granular steering requirement without the state and complexity of RSVP-TE. 2) It simplifies the control plane by removing LDP and RSVP, relying only on IGP extensions (in this case, for OSPF), which significantly improves scalability. 3) SR is the foundational technology for network slicing and service function chaining, directly addressing the future-proofing requirement for 5G. 4) By centralizing path control at the source or a controller, it simplifies operations compared to hop-by-hop provisioning.
- Question 6Beginner
Automation and Assurance · Streaming telemetry
A service provider is using model-driven telemetry to stream network state information from IOS-XR routers to a central collector. An operator wants to subscribe to a data stream that provides updates on interface counters only when their values change. Which type of telemetry subscription model should be used to achieve this?
Show answer & explanation
Correct answer: B
The event-driven or on-change subscription model is designed for this exact purpose. In this model, the router (or telemetry agent) monitors the state of the subscribed data (e.g., interface counters defined by a YANG path). It only streams an update to the collector when the value of that data actually changes. This is highly efficient as it avoids sending redundant data, reducing both network bandwidth and collector processing load, which is ideal for high-frequency state changes like counters.
- Question 7Beginner
Networking · OSPF implementation
A network engineer is troubleshooting an OSPFv2 adjacency issue between two routers, R1 and R2, on a point-to-point serial link. The
show ip ospf neighborcommand on R1 shows the neighbor R2 stuck in the EXSTART/EXCHANGE state. Both routers are in the same area, and their hello/dead timers match. What is the most common cause for this issue?Show answer & explanation
Correct answer: B
When OSPF neighbors are stuck in the EXSTART/EXCHANGE state, it indicates that they have successfully exchanged Hello packets and agreed on a master/slave relationship but are failing to exchange Database Descriptor (DBD) packets. The most common reason for this failure is a mismatched IP MTU on the connecting interfaces. If the master router sends a DBD packet that is larger than the MTU of the slave router's interface, the slave will drop the packet and the exchange process will stall, continuously restarting.
- Question 8Intermediate
Services · 6PE/6VPE for IPv6 VPN
A service provider is deploying 6VPE to offer IPv6 VPN services to customers over its existing IPv4/MPLS core. The PE routers are dual-stack. How does the ingress PE router signal the correct egress PE router for a given customer's IPv6 prefix?
Show answer & explanation
Correct answer: C
6VPE leverages the existing L3VPN architecture. The customer's IPv6 prefixes are placed into a VRF. The ingress PE uses MP-BGP with the VPNv6 address family (AFI 2, SAFI 128) to advertise these prefixes to other PE routers. The BGP update includes the IPv6 prefix, a route distinguisher to make it unique, a route target to control VPN membership, and an MPLS label. Critically, the BGP next-hop attribute for this VPNv6 route is set to the IPv4 address of the advertising PE router. This allows the remote PEs to resolve the next-hop via the IPv4/MPLS core and establish the correct transport LSP.
- Question 9Beginner
Networking · High availability
A network architect is designing a high-availability solution for a BGP peering session between two critical routers. The physical connection is a 10Gbps Ethernet link. The requirement is to detect a link or neighbor failure in under 150 milliseconds to trigger a fast routing reconvergence. Which technology is best suited to meet this strict requirement?
Show answer & explanation
Correct answer: C
Bidirectional Forwarding Detection (BFD) is a lightweight, low-overhead protocol specifically designed for fast failure detection of the forwarding path between routers. It can operate with timers in the tens of milliseconds, far more aggressively than protocol-native keepalives like BGP's. When BFD is enabled for a BGP neighbor, BGP registers with the BFD process. If BFD detects a failure in the forwarding path, it immediately notifies the BGP process, which then tears down the peering session, allowing for sub-second failover. This is the industry-standard method for achieving fast convergence for BGP and other routing protocols.
Ready for the real thing?
The full 350-501 simulator has every exam-style question, timed mode, and instant scoring.