400-007 Sample Questions & Answers
Resilient, scalable and secure modular network design is the heaviest topic, alongside management-plane, data-plane and control-plane technologies, how business strategy shapes design choices, application service design, and overall security design.
Launch the full 400-007 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Service Design · Cloud Connectivity Design
A retail company is migrating its e-commerce application to a hybrid cloud environment. The on-premises data center hosts the product database, while the front-end web servers are deployed in AWS. For PCI compliance, the connection between AWS and the on-premises data center must be private and encrypted, with a minimum bandwidth of 1 Gbps. The business requires a solution that minimizes latency and provides consistent performance. Which connectivity model best satisfies these business and technical requirements?
Show answer & explanation
Correct answer: B
AWS Direct Connect provides a dedicated, private network connection from on-premises to AWS, which bypasses the public internet. This directly addresses the requirements for privacy, low latency, and consistent performance. Using a private Virtual Interface (VIF) connects to the VPC. To meet the encryption requirement for PCI, MACsec can be enabled on the Direct Connect link (for 10Gbps and higher connections) to provide Layer 2 encryption. This combination is superior to a VPN over the internet, which would have variable performance and higher latency, and is more direct than solutions involving SD-WAN or transit gateways for this point-to-point requirement.
- Question 2Beginner
Business Strategy Design · Business Continuity
A project manager is defining the requirements for a new network deployment. The business stakeholders have specified a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of 1 hour. What do these two metrics imply for the network design?
Show answer & explanation
Correct answer: A
RTO (Recovery Time Objective) is the target time within which a business process must be restored after a disaster or disruption to avoid unacceptable consequences associated with a break in business continuity. An RTO of 15 minutes means the network must be operational within that timeframe. RPO (Recovery Point Objective) is the maximum targeted period in which data might be lost from an IT service due to a major incident. An RPO of 1 hour means that backups or replications must be frequent enough that no more than one hour of data is lost.
- Question 3Beginner
Network Design · Multicast Design
When designing a multicast network using PIM-SM (Protocol Independent Multicast - Sparse Mode), what is the primary function of the Rendezvous Point (RP)?
Show answer & explanation
Correct answer: C
In PIM-SM, the Rendezvous Point (RP) serves as a shared root for a shared multicast distribution tree (*,G). New multicast sources register with the RP, and new receivers send their IGMP joins towards the RP. This allows receivers to learn about active sources without the sources needing to know about all receivers, which is the core principle of sparse mode. Once a receiver begins pulling a stream from a source via the RP, its local router may switch to a source-based Shortest Path Tree (SPT) for a more optimal path.
- Question 4Intermediate
Service Design · QoS Design
An architect is designing a QoS policy for a converged enterprise network that carries voice, video, and data traffic. The business requires that voice traffic receive the highest priority to ensure call quality. According to Cisco best practices, which Per-Hop Behavior (PHB) and DSCP value should be assigned to voice bearer traffic (RTP)?
┌──────────┬───────────────────────┬──────────┐ │ Traffic │ Description │ Priority │ ├──────────┼───────────────────────┼──────────┤ │ Voice │ RTP Voice Bearer │ Highest │ │ Video │ Video Conferencing │ High │ │ Data │ Best Effort │ Low │ └──────────┴───────────────────────┴──────────┘Show answer & explanation
Correct answer: B
Cisco's QoS best practice recommends marking voice bearer traffic (RTP) with DSCP 46, which corresponds to the Expedited Forwarding (EF) Per-Hop Behavior. The EF PHB is designed for low-loss, low-latency, low-jitter traffic and is typically serviced by a priority queue (LLQ) across the network. AF41 is commonly used for interactive video, CS3 for call signaling, and BE (or CS0) for default data traffic.
- Question 5BeginnerSelect 2
Business Strategy Design · CAPEX/OPEX Cost Analysis
A network designer is evaluating WAN connectivity options for a new branch office. The project manager has stated that the decision must be based on a Total Cost of Ownership (TCO) analysis over a 3-year period. Which two factors are components of Operational Expenditure (OPEX) in this TCO analysis? (Select TWO)
Show answer & explanation
Correct answers: B, D
Operational Expenditure (OPEX) refers to the ongoing costs required for the day-to-day functioning of a business. In network design, this includes recurring costs like monthly circuit fees and annual support contracts. Capital Expenditure (CAPEX) refers to one-time purchases of physical goods or services, such as the initial purchase price of a router and the one-time installation fee.
- Question 6Intermediate
Security Design · Network Access Control
A hospital is deploying a secure wireless network. To comply with HIPAA regulations, they need to implement strong access control for all devices connecting to the network. The security policy requires that corporate-owned laptops are authenticated using EAP-TLS with machine certificates, while employee-owned mobile devices (BYOD) must use PEAP with Active Directory credentials. Which technology is best suited to enforce these differentiated authentication policies?
Show answer & explanation
Correct answer: C
IEEE 802.1X is the standard for port-based Network Access Control (NAC). It provides a framework for authenticating devices as they connect. A RADIUS server, such as Cisco Identity Services Engine (ISE), acts as the authentication server. ISE can be configured with complex policy sets that differentiate devices based on various attributes (e.g., certificate presence, user group) and enforce different EAP methods (EAP-TLS for corporate, PEAP for BYOD) accordingly. This provides the granular control needed for HIPAA compliance. WPA2-Personal and MAC filtering are not secure enough for this environment.
- Question 7Intermediate
Network Design · MPLS L3 VPN Design
A service provider is designing an MPLS Layer 3 VPN service for a customer. The customer has two sites, A and B, connected to the provider's network. The provider needs to ensure that the customer's routes from Site A are correctly advertised to Site B, while remaining isolated from other customers. What is the function of the Route Distinguisher (RD) in this design?
Customer Site A Provider Network (MPLS Core) Customer Site B +-------------+ +--------------------------------------+ +-------------+ | CE1 |---------| PE1 (vrf CUST1) --- (MP-BGP) --- PE2 (vrf CUST1) |---------| CE2 | +-------------+ +--------------------------------------+ +-------------+Show answer & explanation
Correct answer: B
The primary purpose of the Route Distinguisher (RD) is to make a customer's non-unique IPv4 prefix (like 192.168.1.0/24) unique within the service provider's BGP table. The RD is a 64-bit value that is prepended to the customer's 32-bit IPv4 prefix, creating a unique 96-bit VPNv4 prefix. This allows the provider to carry routes for multiple customers who might be using the same private IP address space, without conflicts. Route Targets (RTs) are used to control the import/export of routes between VRFs.
- Question 8Intermediate
Network Design · Data Center Overlay Networks
During the design of a data center network, an engineer must provide Layer 2 adjacency between servers located in different racks, which are connected to different Top-of-Rack (ToR) switches. The design must be highly scalable, support multi-tenancy, and avoid the limitations of Spanning Tree Protocol (STP). Which technology is most suitable for this data center overlay network?
Show answer & explanation
Correct answer: C
VXLAN is an overlay technology that allows for the extension of Layer 2 segments over a Layer 3 underlay network. It encapsulates Layer 2 frames in UDP packets, effectively tunneling them across the IP fabric. This avoids STP by relying on the underlay's L3 routing (like ECMP) for loop-free paths. VXLAN supports up to 16 million logical networks (using the 24-bit VNI), making it highly scalable and ideal for multi-tenancy. vPC provides device-level redundancy but doesn't solve the larger STP scaling issue. FabricPath is an older L2 multipathing technology that has largely been superseded by VXLAN EVPN.
- Question 9Intermediate
Network Design · First-Hop Redundancy Protocols (FHRP)
A design requires a first-hop redundancy protocol (FHRP) that allows for active-active forwarding of traffic from hosts in a subnet, provides sub-second failover, and is an open standard. Which FHRP best meets all these requirements?
Show answer & explanation
Correct answer: C
Of the options listed, only VRRP is an open IETF standard (RFC 5798). HSRP and GLBP are Cisco proprietary. While GLBP provides active-active forwarding, it is not an open standard. HSRP operates in an active-standby model. VRRP operates in an active-standby model per group, but you can configure multiple VRRP groups with different masters to achieve load balancing (an active-active design from the hosts' perspective). VRRP version 3 supports IPv4 and IPv6 and can achieve sub-second failover with aggressive timer tuning. Therefore, it is the only option that meets all criteria: active-active (via multiple groups), sub-second failover, and open standard.
- Question 10Advanced
Network Design · Layer 2 Extension
A manufacturing company uses a legacy application that communicates using broadcast frames on a specific Layer 2 segment. The company is expanding and needs to extend this application's reach to a new building across a Layer 3 campus core. The network architect must provide a solution that tunnels this specific Layer 2 broadcast domain across the routed core without redesigning the application. Which tunneling technology is designed for this specific purpose?
Show answer & explanation
Correct answer: C
L2TPv3 is an IETF standard specifically designed to tunnel various Layer 2 protocols (like Ethernet) over an IP network. It can encapsulate entire Ethernet frames, including broadcast frames, and transport them across a Layer 3 infrastructure. This makes it ideal for extending a Layer 2 domain for legacy applications. While GRE can tunnel IP packets and IPsec provides encryption, neither is purpose-built for transparently extending a Layer 2 broadcast domain in the way L2TPv3 is. OTV is a more complex data center interconnect technology.
Ready for the real thing?
The full 400-007 simulator has every exam-style question, timed mode, and instant scoring.