Cisco CCNP 300-410 ENARSI Certification Exam
Cisco Certified Network Professional Enterprise Advanced Routing and Services 300-410
The Cisco CCNP 300-410 ENARSI certification validates skills in implementing and troubleshooting advanced enterprise routing and services. The exam covers Layer 3 technologies, VPN technologies, infrastructure security, and infrastructure services. Candidates demonstrate knowledge of EIGRP, OSPF, BGP, redistribution, route maps, policy-based routing, VRF-Lite, BFD, MPLS, MPLS Layer 3 VPN, DMVPN, AAA, ACLs, uRPF, CoPP, IPv6 first-hop security, SNMP, syslog, DHCP, IP SLA, NetFlow, and Catalyst Center Assurance. The exam consists of 100 questions over 90 minutes, with an 80% passing score.
Certification Overview
- Exam name: CCNP 300-410 ENARSI
- Vendor: Cisco
- Exam code: 300-410
- Duration: 90 minutes
- Total questions: 100
- Passing score: 80%
Who Should Take This Exam?
Network Engineer, Network Administrator, Network Support Engineer, Systems Engineer, Network Consultant, NOC Engineer, Enterprise Network Engineer, Network Security Engineer
Prerequisites
Valid Cisco Certified Network Associate (CCNA) certification or equivalent enterprise networking experience with routing, switching, and IP services.
Topics Covered
- Layer 3 Technologies
- VPN Technologies
- Infrastructure Security
- Infrastructure Services
Question Types
- Multiple Choice (Single Answer)
- Multiple Choice (Multiple Answers)
- Drag and Drop
- Scenario-Based
CCNP 300-410 ENARSI Practice Questions
Our question bank contains 857+ practice questions for this certification. Sample questions from each exam chapter. Expand a question to see the answer choices. With a subscription, you get unlimited practice exams with randomized questions from our full question bank.
Layer 3 Technologies
An engineer set up routing between several OSPF domains and created a routing loop that led to network instability. What action will fix the issue?
- Set a tag using the redistribute command toward a domain and deny inbound in the other domain by a matching tag.
- Set a tag using the redistribute command toward a different domain and deny the matching tag when exiting from that domain.
- Set a tag using the network command in a domain and use the route-map command to deny the matching tag when exiting toward a different domain.
- Set a tag using the network command in a domain and use the route-map command to deny the matching tag when entering into a different domain.
Network operations report problems with getting too many external routes, leading to CPU spikes on routers with less memory. What action will fix this?
- Configure the area range command when redistributing on ASBR.
- Configure the summary-address command when redistributing on ABR.
- Configure the area range command when redistributing on ABR.
- Configure the summary-address command when redistributing on ASBR.
What failure detection method is used for BFD?
- consistent rate
- Layer 2 protocol failure
- variable rate
- routing protocol failure
VPN Technologies
What is the function of an OSPF sham-link?
- to allow inter-area routing when OSPF is used as the PE-CE connection protocol in an MPLS VPN network
- to allow intra-area routing when OSPF is used as the PE-CE connection protocol in an MPLS VPN network
- to correct OSPF backdoor routing when OSPF is used as the PE-CE connection protocol in an MPLS VPN network
- to correct OSPF backdoor routing when OSPF is used as the PE-PE connection protocol in an MPLS VPN network
Which MPLS value is merged with the IP prefix to change it into a VPNv4 prefix?
- 8-byte Route Distinguisher
- 8-byte Route Target
- 16-byte Route Target
- 16-byte Route Distinguisher
customer is using an mGRE DMVPN tunnel over WAN infrastructure between hub and spoke sites. The current setup lets NHRP automatically add spoke routers to the multicast NHRP mappings. The customer is moving the network from IPv4 to IPv6 addressing for spokes' routers that support IPv6 and can run DMVPN tunnels over the IPv6 network. What configuration should be applied to support both IPv4 and IPv6 DMVPN tunnels on spoke routers?
- tunnel mode ipv6ip 6to4
- tunnel mode ipv6ip auto-tunnel
- tunnel mode ipv6ip 6rd
- tunnel mode ipv6ip isatap
Infrastructure Security
The IPv6 network is being attacked by an unknown source that isn't in the binding table or learned via neighbor discovery. Which feature helps stop the attack?
- IPv6 Destination Guard
- IPv6 Prefix Guard
- IPv6 Router Advertisement Guard
- IPv6 Snooping
The network administrator needs to deploy IPv6 in the network to permit only devices that have registered IP addresses and are connecting from designated locations. Which security feature should be implemented?
- IPv6 Snooping
- IPv6 Destination Guard
- IPv6 Router Advertisement Guard
- IPv6 Prefix Guard
The network administrator needs to set up R1 to authenticate telnet connections using Cisco ISE with RADIUS. ISE is set up with IP address 192.168.1.5 and has a network device pointing to R1 (192.168.1.1) with a shared secret password of Cisco123. If ISE is unavailable, the admin should be able to connect using the local database with the username and password admin/cisco123. The administrator has configured the following on R1: aaa new-model ! username admin password cisco123 ! radius server ISE1 address ipv4 192.168.1.5 key Cisco123 ! aaa group server tacacs+ RAD-SERV server name ISE1 ! aaa authentication login RAD-LOCAL group RAD-SERV Which two configuration changes will resolve the issue?
- aaa authentication login RAD-SERV group RAD-LOCAL local
- aaa authentication login RAD-LOCAL group RAD-SERV local
- line vty 0 4 login authentication RAD-LOCAL
- line vty 0 4 login authentication default
- line vty 0 4 login authentication RAD-SERV
Infrastructure Services
What are the four steps of obtaining an IP address from a DHCP server that match the acronym DORA?
- Discover, Offer, Release, Addressing
- Discover, Obtain, Request, Acknowledge
- Determine, Offer, Release, Acknowledge
- Discover, Offer, Request, Acknowledge
SNMPv2 has been used across a network to manage all network devices. You have been requested to switch to an SNMPv3 solution instead. What is the main advantage of moving from SNMPv2 to SNMPv3?
- Enhanced security, including encryption of passwords
- Enhanced performance, supporting more messages per minute.
- Enhanced scaling, supporting thousands more devices per network segment than SNMPv2.
- Using a push model instead of pull. SNMPv3 uses telemetry to push data to SNMP management stations in real time.
You are setting up NetFlow on different network devices to see the types of traffic being used. How many export destinations can this network data be sent to?
- Up to 2
- Up to 4
- Up to 8
- There is no limitation on the number of flow data export destinations.
Frequently Asked Questions
How many questions are on the exam?
The CCNP 300-410 ENARSI exam contains 100 questions.
What is the passing score?
You need 80% to pass.
How long is the exam?
You have 90 minutes to complete the exam.
More Cisco Practice Exams
- Cisco CCST 100-150 Networking Certification Exam
- Cisco CCST 100-160 Cybersecurity Certification Exam
- Cisco CCNA 200-201 CCNACBR Certification Exam
- Cisco CCNA 200-301 Certification Exam
- Cisco CCNP 300-710 SNCF Certification Exam
- Cisco CCNP 300-715 SISE Certification Exam
- Cisco CCNP 350-401 ENCOR Certification Exam
- Cisco CCNP 350-501 SPCOR Certification Exam
- Cisco CCNP 350-701 SCOR Certification Exam
Practice with realistic mock exams to prepare for your Cisco certification.