Cisco CCNP Service Provider SPCOR (350-501) · Difficulty

Medium 350-501 practice questions

Applied — put a concept to work in a realistic situation. 105 medium questions available — no sign-up, always free.

Question 1 of 25

A service provider automation team is choosing between Ansible and Terraform to manage the running configuration of hundreds of Cisco IOS XR routers. A key requirement is that re-running the same automation job repeatedly must not create duplicate or conflicting configuration if the device is already in the desired state. Which characteristic of Ansible directly satisfies this requirement?

Reviewed for accuracy · Report an issue
Question 2 of 25

An SP operator peers with a customer over EBGP. The customer wants certain prefixes learned by the SP's PE to be usable within the SP's IBGP mesh but never advertised to any of the SP's upstream or peer EBGP neighbors. The customer sets a BGP community on these prefixes. Which well-known community achieves exactly this behavior?

Reviewed for accuracy · Report an issue
Question 3 of 25

A service provider establishes an EBGP session between two routers, R1 (AS 65001) and R2 (AS 65002), that are directly connected via a single physical link. The engineer configures the peering using each router's loopback interface address as the neighbor and update source. Static routes to reach the remote loopbacks are in place, and the loopbacks are reachable via ping. However, the EBGP session remains stuck in Active/Idle. What must be configured to bring this session up?

Reviewed for accuracy · Report an issue
Question 4 of 25

A service provider runs a single AS with 12 IBGP-speaking PE routers configured in a full mesh. The network team plans to grow to 40 PEs and wants to reduce IBGP peering overhead without splitting the AS or introducing loops. A senior engineer proposes deploying two route reflectors in the core. When a route reflector receives an IBGP prefix from one of its clients, how will it advertise that prefix, and what loop-prevention attribute is used?

Reviewed for accuracy · Report an issue
Question 5 of 25

An ISP running IOS XR peers with a customer over an EBGP IPv6 session. The operator wants all IPv6 prefixes received from this customer to be tagged with community 65001:100 so downstream route-policies can match them, while leaving all other attributes unchanged. Which routing policy configuration applied inbound on the neighbor achieves this?

Reviewed for accuracy · Report an issue
Question 6 of 25

A service provider is migrating a customer's eBGP peering from legacy AS 65010 to a new AS 65020 after a network merger. The customer's CPE is still configured to peer with AS 65010 and cannot be reconfigured during the maintenance window. On the PE router (now in AS 65020), which BGP feature allows the PE to present itself to the customer as if it still belongs to AS 65010, so the existing eBGP session comes up without customer-side changes?

Reviewed for accuracy · Report an issue
Question 7 of 25

A service provider runs IBGP between PE1 and PE2 (both in AS 65100) over an internal /30 link. PE1 has an EBGP session to a customer router in AS 65200 over the subnet 203.0.113.0/30. After the customer advertises 198.51.100.0/24, PE2 receives the prefix in its BGP table but marks it as inaccessible, and the route never enters the RIB. The IGP on the provider core does not carry the 203.0.113.0/30 subnet. Which configuration on PE1 resolves the issue?

Reviewed for accuracy · Report an issue
Question 8 of 25

An SP network engineer is troubleshooting outbound path selection on an IOS XR PE router. The router receives two eBGP advertisements for prefix 203.0.113.0/24. Both paths have equal weight (0), equal local preference (100), neither is locally originated, both are non-aggregate routes, and MED is not being compared because the paths come from different neighboring autonomous systems. Path 1 has an AS_PATH of '65010 65020 65030' and Path 2 has an AS_PATH of '65040 65030'. All other attributes up to this decision point are equal. Based on the BGP best-path algorithm, which path will the router select and why?

Reviewed for accuracy · Report an issue
Question 9 of 25

An SP operates AS 65000 and receives the same prefix 203.0.113.0/24 from a single neighboring AS 65100 over two separate EBGP sessions. Both received paths have identical weight, local preference, AS-path length, and origin type. The path via session A carries MED 50, and the path via session B carries MED 100. All other attributes up to MED are equal. Assuming default BGP behavior, which path does the router install as best, and why?

Reviewed for accuracy · Report an issue
Question 10 of 25

An SP network engineer is troubleshooting inconsistent path selection for prefix 203.0.113.0/24 on an IOS-XR router. Two eBGP paths are received. Both paths have identical weight, local preference, AS_PATH length, and are not locally originated (no AS_PATH via aggregation). The MED values are also equal. Path 1 has an origin code of 'incomplete' (learned via redistribution), while Path 2 has an origin code of 'IGP' (learned via the network statement). Assuming all preceding BGP best-path attributes are tied, which path will the router select and why?

Reviewed for accuracy · Report an issue
Question 11 of 25

An ISP peers with two upstream providers, ISP-A and ISP-B, and receives the prefix 203.0.113.0/24 from both. On router R1 (IOS XR), the operator wants all traffic to this prefix to prefer ISP-A but needs the preference to remain local to R1 only, without influencing any other IBGP router in the AS. Both received routes are otherwise identical (same AS-path length, origin, and MED). Which attribute should the operator set inbound from ISP-A to accomplish this?

Reviewed for accuracy · Report an issue
Question 12 of 25

A service provider is running out of public IPv4 addresses as its residential subscriber base grows. Management wants to continue offering IPv4 connectivity to subscribers while conserving the provider's dwindling public IPv4 pool, without requiring changes to customer premises equipment (CPE). Which service provider architecture element should the network architect deploy to meet this requirement?

Reviewed for accuracy · Report an issue
Question 13 of 25

A service provider engineer notices that a PE router's route processor CPU spikes to 95% whenever a customer misconfigures a routing peer and floods the router with excessive BGP and ICMP traffic destined to the router itself. The engineer wants to protect the route processor by rate-limiting traffic punted to the control plane, while still permitting legitimate protocol sessions to establish. Which mechanism should be configured to achieve this?

Reviewed for accuracy · Report an issue
Question 14 of 25

A service provider peers with an external BGP neighbor across a single-hop link. The security team is concerned about spoofed BGP packets originating from remote, multi-hop sources on the Internet that could be used to attack the router's control plane. They want a lightweight mechanism that validates the packets were sourced from a directly connected peer without relying on ACLs or cryptographic overhead. Which control plane protection mechanism should be configured on the eBGP session?

Reviewed for accuracy · Report an issue
Question 15 of 25

A service provider is designing the QoS architecture for its MPLS core. The design team wants a scalable model where traffic is classified and marked once at the network edge, and each core router then applies forwarding treatment based solely on the marking in each packet, without maintaining per-flow state. Which QoS architecture model satisfies these requirements?

Reviewed for accuracy · Report an issue
Question 16 of 25

An ISP is deploying DS-Lite to allow residential subscribers with IPv6-only access networks to reach the legacy IPv4 Internet. The subscriber CPE receives only an IPv6 prefix from the access network. During design review, an engineer must explain how a subscriber's IPv4 traffic actually traverses the network to reach IPv4 destinations. Which statement correctly describes the DS-Lite data plane behavior?

Reviewed for accuracy · Report an issue
Question 17 of 25

A network engineer is bringing a new IOS XR router into a streaming telemetry platform. Before subscribing to any paths, the engineer wants the collector to programmatically discover which YANG models, gNMI version, and data encodings (JSON, JSON_IETF, PROTO) the router supports so the collector can select a compatible encoding. Which gNMI RPC should the collector issue to obtain this information?

Reviewed for accuracy · Report an issue
Question 18 of 25

A service provider is deploying model-driven telemetry from an IOS XR router to a centralized collector. The network team wants the collector to initiate a persistent gNMI session to the router, and the router should stream operational data continuously as counters change, rather than at fixed intervals. Which combination of gNMI transport model and subscription mode should be configured to meet this requirement?

Reviewed for accuracy · Report an issue
Question 19 of 25

A service provider is deploying model-driven telemetry from an IOS XR router to a collector. Security policy requires that both the router and the collector mutually authenticate each other using X.509 certificates before any telemetry data is streamed, and the router must initiate the connection to the collector. Which combination of gRPC/gNMI settings satisfies these requirements?

Reviewed for accuracy · Report an issue
Question 20 of 25

A network engineer is configuring gNMI dial-out (target-initiated) telemetry on an IOS-XR router toward a collector that is reachable only across a fully trusted, isolated out-of-band management network. Management insists on the simplest possible transport configuration for a lab validation, so the engineer configures the gRPC session without any certificate trustpoint or TLS parameters. After committing, the router attempts to establish the session but the collector, which is listening for plaintext gRPC on port 57400, never receives a connection. What is the most likely reason the session fails to come up?

Reviewed for accuracy · Report an issue
Question 21 of 25

A network engineer configures a gNMI dial-in subscription over TLS between a Cisco IOS XR router and a telemetry collector. The router presents a server certificate whose Common Name and Subject Alternative Name contain only the router's loopback IP address (10.0.0.1), but the collector initiates the session using the router's DNS hostname (rtr1.example.com). SNMP and NETCONF over SSH work fine. The gNMI session fails during the TLS handshake with a certificate validation error on the collector. Which action resolves the failure while keeping TLS validation enabled?

Reviewed for accuracy · Report an issue
Question 22 of 25

A service provider offers a business-grade Ethernet service to a customer whose CE connects at 1 Gbps physically, but the customer purchased only a 300 Mbps subscription tier. Within that 300 Mbps, voice traffic must receive strict low-latency treatment while remaining data classes share the leftover bandwidth proportionally. On the PE egress interface toward the customer, which QoS mechanism correctly enforces this design?

Reviewed for accuracy · Report an issue
Question 23 of 25

A service provider's PE router receives the same prefix 10.50.0.0/16 from two different route reflectors, each advertising a distinct next-hop. The network engineer wants the PE to install both paths into the RIB for load balancing. All BGP attributes for both paths are identical up to and including the IGP metric to the next-hop, but by default only one path is being used. Which configuration change enables the PE to install both IBGP paths?

Reviewed for accuracy · Report an issue
Question 24 of 25

A service provider runs IBGP with two route reflectors (RR1 and RR2) serving the same set of clients for redundancy. To avoid unnecessary route storage and ensure loop prevention within the redundant reflector design, both RRs are configured with the same cluster-id. A network engineer troubleshooting missing paths observes that when an RR receives a reflected route, it silently discards updates that contain its own cluster identifier. Which attribute is responsible for this loop-prevention behavior among route reflectors sharing a cluster-id?

Reviewed for accuracy · Report an issue
Question 25 of 25

A service provider operates an IOS XR PE router that establishes a multihop eBGP session with a customer's router located two Layer 3 hops away. The security team wants to ensure that spoofed BGP packets originating from remote parts of the internet cannot reach and attack the BGP process on the PE, while still permitting the legitimate two-hop peer. Which control plane protection mechanism should be configured on the eBGP neighbor to meet this requirement most effectively?

Reviewed for accuracy · Report an issue