The Cisco 350-401 ENCOR certification exam is specifically designed to assess your expertise in implementing core enterprise networking technologies at Cisco.

Question 1:

Refer to the exhibit. An engineer configures the BGP adjacency between R1 and R2, however, it fails to establish Which action resolves the issue?

latest 350-401 exam questions 1

A. Change the network statement on R1 to 172.16 10.0

B. Change the remote-as number to 192 168.100.11.

C. Enable synchronization on R1 and R2

D. Change the remote-as number on R1 to 6500.

Verify answer

The EBGP neighbor for R1 is in the AS 6500, and not the same AS 5500

Question 2:

Which controller is the single plane of management for Cisco SD-WAN?

A. vBond

B. vEdge

C. vSmart

D. vManange

Verify answer

The primary components for the Cisco SD-WAN solution consist of the vManage network management system (management plane), the vSmart controller (control plane), the vBond orchestrator (orchestration plane), and the vEdge router (data plane).


vManage -This centralized network management system provides a GUI interface to easily monitor, configure, and maintain all Cisco SD-WAN devices and links in the underlay and overlay network.


vSmart controller -This software-based component is responsible for the centralized control plane of the SD-WAN network. It establishes a secure connection to each vEdge router and distributes routes and policy information via the Overlay Management Protocol (OMP), acting as a route reflector. It also orchestrates the secure data plane connectivity between the vEdge routers by distributing crypto key information, allowing for a very scalable, IKE-less architecture.


vBond orchestrator -This software-based component performs the initial authentication of vEdge devices and orchestrates vSmart and vEdge connectivity. It also has an important role in enabling the communication of devices that sit behind Network Address Translation (NAT).


vEdge router -This device, available as either a hardware appliance or software-based router, sits at a physical site or in the cloud and provides secure data plane connectivity among the sites over one or more WAN transports. It is responsible for traffic forwarding, security, encryption, Quality of Service (QoS), routing protocols such as Border Gateway Protocol (BGP) and Open Shortest Path First (OSPF), and more.


Question 3:

Which configuration creates a CoPP policy that provides unlimited SSH access from diet and denies access from all other SSH clients\’?

latest 350-401 exam questions 3

A. Option A

B. Option B

C. Option C

D. Option D

Verify answer

Question 4:

An engineer has deployed a single Cisco 5520 WLC with a management IP address of The engineer must register 50 new Cisco AIR-CAP2802I-E-K9 access points to the WLC using DHCP option 43. The access points are connected to a switch in VLAN 100 that uses the subnet. The engineer has configured the DHCP scope on the switch as follows:

latest 350-401 exam questions 4

The access points are failing to join the wireless LAN controller. Which action resolves the issue?

A. configure option 43 Hex F104.AC10.3205

B. configure option 43 Hex F104.CA10.3205

C. configure dns-server

D. configure dns-server

Verify answer in hex is We will have the answer from this paragraph: “TLV values for the Option 43 suboption: Type + Length + Value. The type is always the suboption code 0xf1. Length is the number of controller management IP addresses times

4 in hex. Value is the IP address of the controller listed sequentially in hex. For example, suppose there are two controllers with management interface IP addresses, and The type is 0xf1. The length is 2 * 4 = 8 =

0x08. The IP addresses translate to c0a80a05 ( and c0a80a14 ( When the string is assembled, it yields f108c0a80a05c0a80a14. The Cisco IOS IT Certification Guaranteed, The Easy Way! 81command that is added to the DHCP scope is option 43 hex f108c0a80a05c0a80a14.”

Reference: Click

Therefore in this question, option 43 in hex should be “F104.AC10.3205 (the management IP address of in hex is AC.10.32.05).

Question 5:

In a wireless network environment, what is calculated using the numerical values of the transmitter power level, cable loss, and antenna gain?


B. dBi



Verify answer

Once you know the complete combination of the transmitter power level, the length of cable, and the antenna gain, you can figure out the actual power level that will be radiated from the antenna. This is known as the effective isotropic radiated power (EIRP), measured in dBm. EIRP is a very important parameter because it is regulated by governmental agencies in most countries. In those cases, a system cannot radiate signals higher than a maximum allowable EIRP. To find the EIRP of a system, simply add the transmitter power level to the antenna gain and subtract the cable loss.

Question 6:

Which exhibit displays a valid JSON file?

latest 350-401 exam questions 6

A. Option A

B. Option B

C. Option C

D. Option D

Verify answer

Question 7:

If the AP power level is increased from 25 mW to 100 mW. what is the power difference in dBm?

A. 6 dBm

B. 14 dBm

C. 17 dBm

D. 20 dBm

Verify answer


Question 8:

A network engineer wants to configure console access to a router without using AAA so that the privileged exec mode is entered directly after a user provides the correct login credentials. Which action achieves this goal?

A. Configure login authentication privileged on line con 0.

B. Configure a local username with privilege level 15.

C. Configure privilege level 15 on line con 0.

D. Configure a RADIUS or TACACS+ server and use it to send the privilege level.

Verify answer

Question 9:

An engineer must configure a new WLAN that allows a user to enter a passphrase and provides forward secrecy as a security measure. Which Layer 2 WLAN configuration is required on the Cisco WLC?

A. WPA2 Personal

B. WPA3 Enterprise

C. WPA3 Personal

D. WPA2 Enterprise

Verify answer

WPA3-Personal provides the following key advantages:

Creates a shared secret that is different for each SAE authentication.

Protects against brute force “dictionary” attacks and passive attacks.

Provides forward secrecy. <–Reference:

WPA3 Personal provides forward secrecy.


Question 10:

Which two methods are used by an AP that is typing to discover a wireless LAN controller? (Choose two.)

A. Cisco Discovery Protocol neighbor

B. broadcasting on the local subnet

C. DNS lookup cisco-DNA-PRIMARY.local domain

D. DHCP Option 43

E. querying other APs

Verify answer


Question 11:

Refer to the exhibit.

latest 350-401 exam questions 11

A GRE tunnel has been created between HO and BR routers. What is the tunnel IP on the HQ router?





Verify answer

In the above output, the IP address of “” is the tunnel source IP while the IP is the tunnel IP address.

Question 12:

Refer to the exhibit.

latest 350-401 exam questions 12

The EtherChannel between SW2 and SW3 is not operational which action resolves this issue?

A. Configure the channel-group mode on SW2 Gi0/0 and Gi0/1 to on.

B. Configure the channel-group mode on SW3 Gi0/0 and Gi0/1 to active.

C. Configure the mode on SW2 Gi0/0 to the trunk.

D. Configure the mode on SW2 Gi0/1 to access.

Verify answer

TCKOON is right the image is missing the channel-group 1 mode active statement but if you google it you will find the right picture.

Question 13:

How are map-register messages sent in a LISP deployment?

A. egress tunnel routers to map resolvers to determine the appropriate egress tunnel router

B. ingress tunnel routers to map servers to determine the appropriate egress tunnel router

C. egress tunnel routers to map servers to determine the appropriate egress tunnel router

D. ingress tunnel routers to map resolvers to determine the appropriate egress tunnel router

Verify answer

During operation, an Egress Tunnel Router (ETR) sends periodic Map-Register messages to all its configured map servers.

Question 14:

Which authorization framework gives third-party applications limited access to HTTP services?

A. IPsec

B. Basic Auth


D. OAuth 2.0

Verify answer

Question 15:

An engineer must configure a GRE tunnel interface in the default mode. The engineer has assigned an IPv4 address to the tunnel and sourced the tunnel from an ethernet interface. Which additional configuration must be made on the tunnel interface?

A. (config-if)#tunnel destination

B. (config-if)#keepalive

C. (config-if)#ip mtu

D. (config-if)#ip tcp adjust-mss

Verify answer

A GRE interface definition includes:

+ An IPv4 address on the tunnel + A tunnel source + A tunnel destination

Below is an example of how to configure a basic GRE tunnel:

interface Tunnel 0 IP address tunnel source fa0/0 tunnel destination

In this case the “IPv4 address on the tunnel” is and “sourced the tunnel from an Ethernet interface” is the command “tunnel source fa0/0”. Therefore it only needs a tunnel destination, which is

Note: A multiple GRE (mGRE) interface does not require a tunnel destination address.

Verify answer


