2023 Latest 350-501 DUMPS Q&As with Explanations Verified & Correct Answers
350-501 dumps Exam Material with 373 Questions
Cisco 350-501 certification exam is a challenging test that requires a deep understanding of service provider networking concepts and technologies. It is intended for individuals who have hands-on experience in implementing and operating service provider networks, and who are looking to validate their skills and knowledge in this area. Successful completion of 350-501 exam leads to the award of the Cisco Certified Network Professional Service Provider (CCNP Service Provider) certification, which is highly respected in the industry and recognized globally.
NEW QUESTION # 35
Refer to the exhibit.
To protect in-band management access to CPE-R7, an engineer wants to allow only SSH management and provisioning traffic from management network 192.168.0.0/16. Which infrastructure ACL change must be applied to router PE-R9 to complete this task?
A)
B)

D)
- A. Option B
- B. Option C
- C. Option D
- D. Option A
Answer: A
NEW QUESTION # 36
An engineer working for telecommunication company with an employee id: 3715 15 021 needs to secure the LAN network using a prefix list.
Which best practice should the engineer follow when he implements a prefix list?
- A. The final entry in a prefix list must be /32
- B. An engineer must identity the prefix list with a number only
- C. An engineer must use non sequential sequence numbers in the prefix list so that he can insert additional entries later.
- D. An engineer must include only the prefixes for which he needs to log activity.
Answer: C
NEW QUESTION # 37
A customer of an ISP requests support to setup a BGP routing policy.
Which BGP attribute should be configured to choose specific BGP speakers as preferred points for the customer AS?
- A. highest local preference outbound
- B. highest local preference inbound
- C. lowest local preference inbound
- D. lowest multi-exit discriminator
Answer: A
NEW QUESTION # 38
Refer to the exhibit:
Based on the show/ command output, which result m true after BGP session is established?
- A. The IOS XR router does not advertise any routes to the neighbor 192.168.2.2,but it accepts all routes from 192.168.2.2.
- B. The IOS XR router advertises and accepts all routes to and from eBGP neighbor 192.168.2.2 C. No routes are accepted from the neighbor 192.168.2.2, nor are any routes advertised to it
- C. The IOS XR router advertises all routes to the neighbor 192.168.2.2, but it does not accept any routes from 192.168.2.2
Answer: B
NEW QUESTION # 39
Refer to the exhibit:
With which router does IOSXRV-1 have LDP session protection capability enabled but session hold up is not active?
- A. 192.168.0.5
- B. 192.168.0.3
- C. 192.168.0.1
- D. 192.168.0.4
Answer: B
NEW QUESTION # 40
DRAG DROP
Drag and drop the multicast concepts from the left onto the correct descriptions on the right.
Select and Place:
Answer:
Explanation:
Section: Services
NEW QUESTION # 41
An engineer is setting up overlapping VPNs to allow VRF ABC and XYZ to communicate with VRF CENTRAL but wants to make sure that VRF ABC and XYZ cannot communicate. Which configuration accomplishes these objectives?



- A. Option B
- B. Option C
- C. Option D
- D. Option A
Answer: A
NEW QUESTION # 42
Refer to the exhibit.
Router 1 and router 2 are running OSPF Area 0. The router logs on both routers show that the LDP link has flapped. Which configuration must the engineer apply to the two routers to implement session protection on the link?
- A. Option B
- B. Option D
- C. Option C
- D. Option A
Answer: B
NEW QUESTION # 43
What does DWDM use to combine multiple optical signals?
- A. IP protocols
- B. wavelength
- C. time slots
- D. frequency
Answer: B
NEW QUESTION # 44
Refer to the exhibit. If router RA is configured as shown, which IPv4 multicast address space does it use?
- A. 239.0.0.0/8
- B. 224.0.0.0/8
- C. 232.0.0.0/8
- D. 225.0.0.0/8
Answer: C
Explanation:
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/3se/multicast/c onfiguration_guide/b_mc_3se_3850_cg/b_mc_3se_3850_cg_chapter_01011.html
NEW QUESTION # 45
Drag and Drop Question
Drag and drop the methods of Cisco MPLS TE tunnel traffic assignment from the left onto their characteristics on the right.
Answer:
Explanation:
NEW QUESTION # 46
Why do Cisco MPLS TE tunnels require a link-state routing protocol?
- A. The tunnel endpoints use the link-state database to evaluate the entire topology and determine the best path.
- B. The link-state database provides a data repository from which the tunnel endpoints can dynamically select a source ID.
- C. The link-state database provides segmentation by area, which improves the path-selection process.
- D. Link-state routing protocols use SPF calculations that the tunnel endpoints leverage to implement the tunnel.
Answer: A
Explanation:
Section: Architecture
NEW QUESTION # 47
Refer to the exhibit.
A network engineer is configuring customer edge routers to finalize a L2VPN over MPLS deployment Assume that the AToM L2VPN service that connects the two CEs is configured correctly on the service provider network Which action causes the solution to fail?
- A. The x connect statement has not been defined
- B. OSPF does not work with L2VPN services
- C. The routing protocol network types are not compatible
- D. A loopback with a /32 IP address has not been used
Answer: A
NEW QUESTION # 48
Refer to the exhibit.
A network engineer is deploying SNMP configuration on client's routers. Encrypted authentication must be included on router 1 to provide security and protect message confidentiality. Which action should the engineer perform on the routers to accomplish this task?
- A. snmp-server group group1 v3 auth
- B. snmp-server user testuser remote 192.168.0254 v3 md5 testpassword
- C. snmp-server host 192.168.0.254 informs version 3 auth testuser config
- D. snmp-server community public
Answer: B
NEW QUESTION # 49
Refer to the exhibit. A network operator working for a telecommunication company with an employee 3994:37:650 is implementing a cisco Unified MPLS solution.
What is the effect of this implementation?
- A. OSPF is deployed between the PEs and ABRs with RFC 3107.
- B. EIGRP is deployed between the PEs and ABRs with RFC 3107.
- C. BGP is deployed between the PEs and ABRs with RFC 3107.
- D. IS-IS is deployed between the PEs and ABRs with RFC 3107.
Answer: C
Explanation:
NEW QUESTION # 50 
Refer to the exhibit. A network engineer is implementing QoS services. Which two statements about the qos- group keyword on Cisco IOS XR are true? (Choose two.)
- A. QoS group can be used in fabric QoS policy as match criteria.
- B. It cannot be used with priority traffic class.
- C. The QoS group numbering corresponds to priority level.
- D. It marks packets for end-to-end QoS policy enforcement across the network.
- E. QoS group marking occurs on the ingress.
Answer: A,E
Explanation:
Section: Services
Explanation/Reference:
NEW QUESTION # 51
Refer to the exhibit.
An engineer is securing a customer's network. Which command completes this configuration and the engineer must use to prevent a DoS attack?
- A. neighbor-ttl-security
- B. ttl-security
- C. ebgp-multihop
- D. neighbor ebgp-multihop
Answer: B
NEW QUESTION # 52
Refer to the exhibit.

Refer to the exhibit. The USER mat is connecting an application on an Internet connection in AS 100 is facing these issues:
The USER lost the connection to the application during a failure Between IG and R2.
Router R2 configuration a lost due to a power outage.
The application the USER is connecting to a hosted behind CE2.
What action resolves the issues on R3 and R4 routers?
- A. Apply low Local Preference on R4 toward R2.
- B. Set R3 as a route reflector for R4 and CE1
- C. Set R4 as a route reflector for R3 and CE2
- D. Apply high Local Preference on R3 toward R1
Answer: A
NEW QUESTION # 53
How can a network administrator secure rest APIs?
- A. They can ensure that user sessions are authenticated using TACACS+ only.
- B. They can have a general administrator login for multiple users to access that has command entries logged.
- C. They can authenticate user sessions and provide the appropriate privilege level.
- D. They can allow read and write privileges to all users.
Answer: C
Explanation:
Section: Automation and Assurance
NEW QUESTION # 54
A router RP is configured to perform MPLS LDP graceful restart.
Which three steps are included when the RP sends an LDP initialization message to a neighbor to establish an LDP session? (Choose three.)
- A. Recovery Time field
- B. Type-9 LSA
- C. Graceful restart capability in OPEN message
- D. Learn from Neighbor (N) flag, set to 1
- E. Reconnect Timeout field
- F. Learn from Network (L) flag, set to 1
Answer: A,E,F
Explanation:
Section: MPLS and Segment Routing
Explanation/Reference: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/mp_ha/configuration/xe-16-8/mp-ha-xe-16-8- book/nsf-sso-mpls-ldp-and-ldp-graceful-restart.html
NEW QUESTION # 55
An engineer is configuring IEEE 802. 1ad on the access port on a new Cisco router. The access port handles traffic from multiple customer VLANs, and it is expected to mark allcustomer traffic to the same VLAN without dropping any traffic. Which configuration must the engineer apply?
- A. interface gigabitethernet0/0/1 ethernet dot1ad uni c-port
- B. interface gigabitethernet0/0/1 ethernet dot1ad uni s-port
- C. interface gigabitethernet0/0/1 ethernet dot1ad uni nni
- D. interface gigabitethernet0/0/1 encapsulation dot1q 10
Answer: B
NEW QUESTION # 56
A network engineer must enable the helper router to terminate the OSPF graceful restart process if it detects any changes in the LS A.
Which command enables this feature?
- A. nsf Cisco helper disable
- B. nsf ietf helper disable
- C. nsf ietf helper strict-lsa-checking
- D. nsf cisco enforce global
Answer: C
NEW QUESTION # 57
Refer to the exhibit:
Router R1 and its peer R2 reside on the same subnet in the network, If does it make connections to R27
- A. R1 establishes TCP connections that are authenticated with an MD5 password
- B. R1 establishes TCP connections that are authenticated with a clear-text password
- C. R1 establishes UDP connections that are authenticated with a clear-text password
- D. R1 establishes UDP connections that are authenticated with an MD5 password
Answer: A
NEW QUESTION # 58
Which two IS-IS parameters must match before two Level 2 peers can form an adjacency? (Choose two )
- A. authentication settings
- B. area ID
- C. system ID
- D. hello timer setting
- E. MTU
Answer: A,E
NEW QUESTION # 59
Refer to the exhibit:
When implementing an LDP protocol, an engineer experienced an issue between two directly connected routers and noticed that no LDP neighbor exists for 1.1.1.1.
Which factor should be the reason for this situation?
- A. LDP needs to be enabled on the R2 physical interface
- B. R2 sees the wrong type of hellos from R1
- C. R2 does not see any hellos from R1
- D. LDP needs to be enabled on the R2 loopback interface
Answer: C
NEW QUESTION # 60
......
Cisco 350-501 Certification Exam is an essential validation of a candidate's skills and knowledge in implementing and operating Cisco Service Provider Network Core Technologies. With a strong foundation in networking concepts and hands-on experience with Cisco equipment, candidates can prepare for the exam and earn a valuable credential that can help advance their careers in the service provider industry.
Share Latest 350-501 DUMP Questions and Answers: https://actualtests.crampdf.com/350-501-exam-prep-dumps.html