352-001 Exam - CCDE Written Exam

certleader.com

Q1. You are hired to design a solution that will improve network availability for users on a campus network with routed access. If the budget limits you to three components, which three components would you recommend in your design proposal? (Choose three.) 

A. redundant power supplies in the access routers 

B. standby route processors for SSO in the core routers 

C. standby route processors for SSO in the distribution routers 

D. standby route processors for SSO in the access routers 

E. replace copper links between devices with fiber links 

Answer: ADE 

Q2. You are the lead IP network designer for a new service provider called XYZ, and you are working closely with the CTO to finalize design requirements. The CTO informs you that they want to transport IPv6 prefixes of customers through the XYZ network at this time; however, they need your advice on whether to deploy dual stack or MPLS 6PE/6VPE. Which two options do you recommend? (Choose two.) 

A. Build a dual-stack network. Enable BGP in the core. Redistribute EBGP routes into IGP. 

B. Use MPLS 6PE to simplify the operation and keep a BGP-free core. When the LDPv6 becomes available, change to 4PE or keep the core using both IPv4 and IPv6. The main goal is to keep the core BGP-free and ensure that IPv4, IPv6, VPNv4, and VPNv6 are all label-switched. 

C. Use MPLS 6VPE to simplify the operation and keep a BGP-free core. When the LDPv6 becomes available, change to 4PE or keep the core using both IPv4 and IPv6. The main goal is to keep the core BGP-free and ensure that IPv4, IPv6, VPNv4, and VPNv6 are all label-switched. 

D. Prepare the dual-stack infrastructure from the beginning, even if BGP prefixes would have to be announced via IPv4 in case you decide to maintain the BGP-free core. 

Answer: BD 

Q3. A Service Provider is designing a solution for a managed CE service to a number of local customers using a single CE platform and wants to have logical separation on the CE platform using Virtual Routing and Forwarding (VRF) based on IP address ranges or packet length. Which is the most scalable solution to provide this type of VRF Selection process on the CE edge device? 

A. Static Routes for Route Leaking 

B. Policy Based Routing 

C. Multi-Protocol BGP 

D. OSPF per VRF Instance 

Answer:

Q4. An MPLS service provider is offering a standard EoMPLS-based VPLS service to Customer A, providing Layer 2 connectivity between a central site and approximately 100 remote sites. Customer A wants to use the VPLS network to carry its internal multicast video feeds, which are sourced at the central site and consist of 20 groups at 5 Mb/s each. Which service provider recommendation is the most scalable? 

A. EoMPLS-based VPLS already carries multicast traffic in a scalable manner. 

B. Replicate the multicast traffic on the P routers. 

C. Replace VPLS with a Layer 3 MVPN solution to carry the streams between sites. 

D. Use GRE tunnels to carry the streams between sites. 

Answer:

Q5. You are designing an Out of Band Cisco Network Admission Control, Layer 3 Real-IP Gateway deployment for a customer. Which VLAN must be trunked back to the Clean Access Server from the access switch? 

A. untrusted VLAN 

B. user VLAN 

C. management VLAN 

D. authentication VLAN 

Answer:

Q6. A company wants a design that would support OSPF through a service provider ATM network. Which two OSPF network types should the designer use to establish OSPF neighborship between OSPF routers through the ATM network? (Choose two.) 

A. A broadcast network will always work through ATM networks. 

B. A broadcast network will work when the broadcast support is explicitly configured at the ATM network. 

C. Explicit neighbor statements are required when a nonbroadcast network is configured. 

D. Explicit neighbor statements are required when a point-to-multipoint network is configured. 

E. A nonbroadcast network does not require DR selection. 

Answer: BC 

Q7. You are designing a Group Encrypted Transport Virtual Private Network solution consisting of 30 group members. Which measure helps protect encrypted user traffic from replay attacks? 

A. counter-based anti-replay 

B. time-based anti-replay 

C. nonce payload 

D. RSA-encrypted nonce 

E. digital certificates 

Answer:

Q8. What is a key role for the access layer in a hierarchical network design? 

A. The access layer provides a security, QoS, and policy trust boundary. 

B. The access layer provides an aggregation point for services and applications. 

C. The access layer serves as a distribution point for services and applications. 

D. The access layer can be used to aggregate remote users. 

Answer:

Q9. Refer to the exhibit. 

A new IPv4 multicast-based video-streaming service is being provisioned. During the design-validation tests, you realize that the link between the two buildings is carrying multicast traffic even when there are no receivers connected to the switch in Building B and despite IGMP snooping being enabled on both Layer 2 switches and IGMPv2 runs on the hosts. Which design change will prevent the multicast traffic from being unnecessarily flooded throughout the campus network? 

A. Enable PIM snooping on both Layer 2 switches. 

B. Enable multicast storm control on the link between Switch 1 and Switch 2. 

C. Use static Layer 2 MAC forwarding entries on Switch 1. 

D. Change the IPv4 multicast group address such that it excludes the usage of link-local MAC addresses. 

E. Ensure that Switch 1 is an IGMP querier. 

Answer:

Q10. A network designer is redesigning an enterprise campus network to ensure that Ethernet switches proactively attempt to reconnect after a fiber cut. In the design, they will have to address areas where fiber cuts exist on campus from past troubleshooting, where a single fiber is disconnected in the fiber pair, leading to looping. Which feature could be implemented in the design to allow the Spanning Tree Protocol on the switches to be protected? 

A. loop guard 

B. UniDirectional Link Detection 

C. UniDirectional Link Detection aggressive mode 

D. root guard 

Answer: