Cisco CCNP Service Provider SPCOR (350-501) · Difficulty

Hard 350-501 practice questions

Challenge — multi-step scenarios, trade-offs, and subtle distinctions. 35 hard questions available — no sign-up, always free.

Question 1 of 25

An SP engineer on an IOS XR ASBR must advertise a single summary prefix 203.0.113.0/22 to an eBGP peer instead of the four contributing /24 routes currently in the BGP table. However, the more-specific 203.0.113.0/24 must still be advertised to the same peer for a downstream customer failover requirement, while the other three /24s remain hidden. Which configuration approach achieves this?

Reviewed for accuracy · Report an issue
Question 2 of 25

A service provider running IOS XR has a large IBGP domain with over 200 routers. To reduce the full-mesh requirement without deploying route reflectors, the design team implements BGP confederations, dividing AS 65000 into sub-ASes 65001, 65002, and 65003. After configuration, an operator notices that when routes are advertised between the sub-ASes, the AS_PATH shows sub-AS numbers in parentheses but external neighbors in AS 100 never see these sub-AS numbers. When these routes reach the external EBGP peer, how does the confederation affect BGP path selection and loop prevention?

Reviewed for accuracy · Report an issue
Question 3 of 25

An IBGP-enabled PE router in AS 65000 receives two paths to the same external prefix 203.0.113.0/24 from two different route reflectors. Both paths have identical weight, local preference, AS-path length, origin code, and MED. Both are learned via IBGP (neither is locally originated or EBGP). The BGP next-hop of path 1 (10.0.0.5) is reachable via an IGP metric of 30, while the BGP next-hop of path 2 (10.0.0.9) is reachable via an IGP metric of 20. Assuming 'bgp bestpath compare-routerid' is NOT configured and both paths are still valid, which path will BGP select as best and why?

Reviewed for accuracy · Report an issue
Question 4 of 25

A service provider deploys EVPN with a dual-homed CE connected to two PE routers (PE1 and PE2) using the same Ethernet Segment Identifier (ESI) in all-active redundancy mode. Remote PE3 learns a customer MAC address via an EVPN Type 2 route advertised only by PE1. Operators observe that PE3 load-balances traffic toward the CE across both PE1 and PE2, even though only PE1 advertised the MAC. Which EVPN mechanism enables PE3 to forward toward PE2 for a MAC it never received from PE2?

Reviewed for accuracy · Report an issue
Question 5 of 25

A service provider deploys EVPN to offer a multi-tenant Ethernet service on their IOS XR PEs. The design team wants a single EVPN Instance (EVI) to carry multiple customer VLANs, where each VLAN maps to its own broadcast domain but all share the same EVI and route targets to conserve control-plane resources. Which EVPN service type must be configured to meet this requirement?

Reviewed for accuracy · Report an issue
Question 6 of 25

Two IOS-XR routers, PE1 and PE2, are directly connected over a point-to-point link and configured for IS-IS Level-2. The adjacency repeatedly cycles between INIT and DOWN, never reaching UP. Logs on PE1 show IIH packets received from PE2, but PE2 never sees PE1's hellos acknowledged. PE1's interface MTU is 1500; PE2's interface MTU was recently changed to 1400 during a maintenance window. What is the most likely cause of the failure?

Reviewed for accuracy · Report an issue
Question 7 of 25

A service provider runs a two-level IS-IS domain. Branch routers in a Level 1 area only receive a default route toward the nearest L1/L2 router via the ATT bit, which causes suboptimal exit selection when a specific prefix in another area is actually best reached through a different L1/L2 router. The network engineer wants the L1 routers to make optimal forwarding decisions for a set of important L2 prefixes without converting the entire area to Level 1-2. Which action achieves this?

Reviewed for accuracy · Report an issue
Question 8 of 25

A service provider runs IS-IS on all IOS XR core routers for both IPv4 and IPv6. Historically the network used a single topology (default) for both address families. An engineer enables 'address-family ipv6 unicast' under a new router's IS-IS process and configures 'multi-topology' on that router only. After the change, IPv6 routes learned via IS-IS from that new router are missing on adjacent routers, although IPv4 routing and the IS-IS adjacency itself remain fully up. What is the most likely cause?

Reviewed for accuracy · Report an issue
Question 9 of 25

A service provider offers an EVPL service to a customer using an IOS XR PE router. The customer sends frames tagged with an outer VLAN 100 and inner VLAN 200 (QinQ). The PE must match these double-tagged frames on the access interface, remove the outer service-delimiting VLAN 100 before forwarding across the VPWS pseudowire, and re-impose VLAN 100 toward the customer on egress. Which Ethernet flow point (EFP) configuration on the ingress attachment circuit achieves this behavior?

Reviewed for accuracy · Report an issue
Question 10 of 25

A service provider runs an EVPN-based L2VPN across its IOS XR core. A dual-homed customer VM is migrated from a server behind PE1 to a server behind PE2. After the move, PE1 continues to advertise the VM's MAC as a local route while PE2 also advertises the same MAC, causing intermittent Layer 2 reachability and MAC flapping between the two PEs. Which EVPN mechanism resolves this by determining which PE currently owns the MAC?

Reviewed for accuracy · Report an issue
Question 11 of 25

A service provider runs a VPLS instance across three PE routers (PE1, PE2, PE3) in a full mesh of pseudowires. A dual-homed customer site connects to PE1 (active) and PE2 (standby) using MST for loop prevention. When the active uplink to PE1 fails and traffic shifts to PE2, remote PE3 continues black-holing customer traffic for the affected MAC addresses until they naturally age out. Which mechanism should be enabled to force PE3 to immediately relearn the MAC addresses on the correct pseudowire?

Reviewed for accuracy · Report an issue
Question 12 of 25

You are deploying an EoMPLS point-to-point pseudowire (VPWS) between two IOS XR PE routers across a core that performs equal-cost load balancing based on a deep packet hash. Customers report intermittent packet reordering and dropped frames on the emulated Ethernet circuit, though the pseudowire is up on both ends. What should you configure on the pseudowire to resolve this issue?

Reviewed for accuracy · Report an issue
Question 13 of 25

A service provider offers a shared central-services VRF (hosting DNS and NTP servers) that all customer VRFs must reach, but individual customers must NOT be able to reach each other through the central-services VRF. Customer VRFs use RT 65000:100 (customer A) and 65000:200 (customer B). The central-services VRF uses RT 65000:999. Which route-target configuration on the central-services PE VRF achieves the required any-to-central but not customer-to-customer reachability?

Reviewed for accuracy · Report an issue
Question 14 of 25

Two service providers operate separate MPLS L3VPN backbones and must interconnect a customer VPN across their ASBRs. The design team chooses Inter-AS Option B (VPNv4 exchange between ASBRs). On the ASBR of AS 100, VPNv4 routes are being received from the peer ASBR in AS 200, but the customer PE devices in AS 100 cannot forward traffic toward the remote prefixes even though the VPNv4 routes appear in BGP. What must be verified on the AS 100 ASBR for Option B to forward customer traffic correctly?

Reviewed for accuracy · Report an issue
Question 15 of 25

A service provider runs an MPLS L3VPN for a customer that uses OSPF as the PE-CE routing protocol at two sites, Site A and Site B. Both sites also have a direct backdoor OSPF link between them within the same OSPF area. The customer complains that traffic between the two sites always takes the low-speed backdoor link instead of the high-speed MPLS backbone. The PEs redistribute customer routes into MP-BGP and back into OSPF as type-3 inter-area routes. What must the SP engineer configure to make the MPLS backbone the preferred path?

Reviewed for accuracy · Report an issue
Question 16 of 25

A service provider runs MPLS L3VPN with OSPF as the PE-CE routing protocol for customer ACME. Routes learned from a remote CE via MP-BGP are redistributed back into OSPF on the local PE toward the CE. The customer complains that these VPN routes appear on their CE routers as OSPF external Type 5 (E2) LSAs, but they require the routes to be seen as inter-area (Type 3) summary LSAs so that internal SPF metric behavior is preserved end-to-end. Both customer sites use the same OSPF process and are in different, non-zero areas connected through the MPLS backbone. What must be configured on the PEs to achieve this?

Reviewed for accuracy · Report an issue
Question 17 of 25

A service provider runs LDP across its core using default Cisco IOS behavior. A network engineer notices that during an IGP convergence event, some LSRs begin advertising a label mapping for a FEC to their upstream neighbors before the downstream label mapping for that same FEC has been received. This creates a brief window where an LSR advertises a label but has no valid downstream label to swap to. Which LDP label distribution control mode explains this behavior, and what is its key characteristic?

Reviewed for accuracy · Report an issue
Question 18 of 25

A service provider is deploying RSVP-TE tunnels and wants a specific tunnel to traverse only links that are colored as 'high-bandwidth' (bit 0x01) while avoiding any link colored as 'satellite' (bit 0x04). The core links have their attribute-flags configured accordingly. Which tunnel configuration correctly enforces this path constraint using affinity and mask values?

Reviewed for accuracy · Report an issue
Question 19 of 25

A service provider deploys an MPLS TE tunnel across a core where every physical link supports a 1500-byte IP MTU. Customers send 1500-byte IP packets with the DF bit set. After the TE tunnel is activated, users report that large TCP transfers fail while small pings succeed. What is the most likely cause and correct remedy?

Reviewed for accuracy · Report an issue
Question 20 of 25

A service provider runs RSVP-TE across its core. Two tunnels traverse a link with 100 Mbps of reservable bandwidth. Tunnel-A (already established) reserves 70 Mbps and was configured with setup priority 7 and hold priority 7. Tunnel-B is now being signaled with a 50 Mbps reservation, setup priority 3 and hold priority 3. The link cannot accommodate both reservations simultaneously. What happens when Tunnel-B is signaled?

Reviewed for accuracy · Report an issue
Question 21 of 25

A service provider offers an MPLS L3VPN hub-and-spoke topology for a customer. All spoke sites must send traffic to the hub site but must not communicate directly with each other. The hub PE has two VRFs: VRF-HUB-IN (receives spoke routes) and VRF-HUB-OUT (advertises hub routes). Each spoke VRF must import hub routes and export its own routes to the hub only. Which route-target configuration correctly enforces this hub-and-spoke behavior?

Reviewed for accuracy · Report an issue
Question 22 of 25

A service provider deploys PIM Bidirectional (Bidir-PIM) in a data-center distribution segment to support a many-to-many financial multicast application where every host is both a source and a receiver. On a multi-access LAN segment that connects to the rendezvous point (RP) tree, the engineer notices that multicast traffic sourced on the segment is being forwarded upstream toward the RP by more than one router, causing duplicate packets. Which Bidir-PIM mechanism is responsible for electing a single router per link to forward traffic toward the RP, and what must the engineer verify?

Reviewed for accuracy · Report an issue
Question 23 of 25

You are troubleshooting an OSPFv2 area 0 that spans four routers on IOS XR. Users report intermittent reachability to prefixes advertised by R3. On R1 you notice the SPF calculation runs repeatedly, and 'show ospf database router' displays two Type-1 LSAs with the same Router ID (10.0.0.3) but originating from different interfaces and with conflicting link information. Adjacencies flap on R3 and R4. What is the most likely root cause of this instability?

Reviewed for accuracy · Report an issue
Question 24 of 25

In a service provider network, area 0 connects to a non-backbone area 10 through an ABR named R2. An ASBR named R5 resides inside area 10 and redistributes external routes into OSPF. A router in area 0 (R1) can see the Type 5 external LSAs in its database but shows the external routes as unreachable. Which condition explains why R1 cannot install these external routes?

Reviewed for accuracy · Report an issue
Question 25 of 25

A service provider runs OSPFv2 with a not-so-stubby area (NSSA) that connects to a customer network redistributing static routes. The customer's routes appear as Type-7 LSAs inside the NSSA. Operations reports that these customer routes are NOT reaching routers in the backbone (area 0) or other regular areas. There are two ABRs attached to the NSSA. Which statement correctly explains the expected behavior and the most likely cause?

Reviewed for accuracy · Report an issue