Architecture
Drill 16 practice questions focused entirely on Architecture for the Cisco 350-501 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A service provider engineer notices that a PE router's route processor CPU spikes to 95% whenever a customer misconfigures a routing peer and floods the router with excessive BGP and ICMP traffic destined to the router itself. The engineer wants to protect the route processor by rate-limiting traffic punted to the control plane, while still permitting legitimate protocol sessions to establish. Which mechanism should be configured to achieve this?
A service provider peers with an external BGP neighbor across a single-hop link. The security team is concerned about spoofed BGP packets originating from remote, multi-hop sources on the Internet that could be used to attack the router's control plane. They want a lightweight mechanism that validates the packets were sourced from a directly connected peer without relying on ACLs or cryptographic overhead. Which control plane protection mechanism should be configured on the eBGP session?
A service provider is designing the QoS architecture for its MPLS core. The design team wants a scalable model where traffic is classified and marked once at the network edge, and each core router then applies forwarding treatment based solely on the marking in each packet, without maintaining per-flow state. Which QoS architecture model satisfies these requirements?
A service provider operates an IOS XR PE router that establishes a multihop eBGP session with a customer's router located two Layer 3 hops away. The security team wants to ensure that spoofed BGP packets originating from remote parts of the internet cannot reach and attack the BGP process on the PE, while still permitting the legitimate two-hop peer. Which control plane protection mechanism should be configured on the eBGP neighbor to meet this requirement most effectively?
A service provider operates IOS XR routers and must delegate operational access to a NOC team. The NOC engineers should be able to view interface counters, run show commands, and clear counters, but must NOT be able to modify routing protocol configuration or system settings. Following the management plane security model in IOS XR, what is the correct approach to enforce this least-privilege access?
A service provider is standardizing on Cisco IOS XR routers and wants to host a lightweight third-party monitoring agent and custom Python telemetry scripts directly on the router without impacting the core routing processes. The network architect needs the hosted application to run in an isolated environment with its own file system and libraries, while sharing the router's Linux kernel for efficiency. Which IOS XR software architecture capability should the architect leverage to meet this requirement?
A service provider is designing its IOS XR software architecture on a distributed platform. The network operations team wants to understand how a routing protocol process (such as BGP) obtains forwarding-related state and interacts with the underlying line card hardware without being written for a specific ASIC. Which component of the IOS XR software architecture provides this abstraction so that upper-layer processes remain independent of the specific forwarding hardware?
A service provider runs Cisco IOS XR on its core routers. During a maintenance window, an engineer must patch the BGP process to fix a defect. Management insists that the router must NOT reload and that OSPF, LDP, and interface forwarding must remain unaffected while BGP is updated. Which characteristic of the IOS XR software architecture makes this possible?
A service provider runs Cisco IOS XR on its aggregation routers. The security team wants to protect the router from being overwhelmed by high rates of exception and for-us packets (such as ARP, ICMP, and routing protocol traffic) punted to the CPU, without manually configuring a policy for every protocol. Which built-in IOS XR mechanism automatically polices these locally destined packet flows in hardware to protect the control and management planes?
A service provider security engineer must harden the management plane of a Cisco IOS XE PE router. The requirement is to ensure that in-band management protocols such as SSH and SNMP can only be received on a single designated loopback-facing interface (GigabitEthernet0/0/3), while all other data-carrying interfaces silently reject management traffic destined to the router itself. Which feature directly satisfies this requirement?
A service provider is deploying a virtualized CPE offering where customer firewall and router functions run as virtual network functions (VNFs) on standard x86 servers. The operations team needs a framework component responsible for onboarding VNF packages, instantiating and scaling VNFs, and coordinating with the virtualized infrastructure resources. Which ETSI NFV architectural component performs this VNF lifecycle management role?
A service provider runs an MPLS core and offers a DiffServ-based QoS service. A customer complains that when their DSCP-marked traffic transits the provider's MPLS network, any re-marking the provider performs on the outer MPLS EXP bits (for example, during congestion at the P routers) is being copied back onto the customer's IP DSCP field when the packet exits at the egress PE. The customer wants their original IP DSCP values preserved end-to-end regardless of any provider MPLS EXP changes. Which MPLS DiffServ tunneling mode should the provider configure to meet this requirement?
A large service provider is redesigning its backbone to scale beyond the limits of a single flat IGP/LDP domain. The design team wants to divide the network into separate access, aggregation, and core IGP domains while still providing end-to-end MPLS label switched paths for VPN services across all domains, without redistributing LSP endpoint loopbacks between IGPs. Which service provider transport architecture best meets these requirements?
A service provider is designing the QoS architecture for its MPLS backbone. At the ingress PE, customer traffic arrives with untrusted DSCP markings that the SP does not wish to honor. The design team wants to enforce the SP's own traffic classes at the network edge while ensuring core routers can make forwarding decisions quickly without re-inspecting deep packet fields. Which QoS architecture approach best meets these requirements?
A service provider security engineer is hardening the management plane of an IOS XE PE router. Remote administrators must reach the device only via SSH from the 10.50.0.0/24 NOC subnet, and all Telnet access must be refused. The engineer configures an access-class on the VTY lines and disables Telnet as a transport. Which combination of configuration steps correctly enforces this management plane security requirement?
A service provider connects a single-homed customer edge (CE) router to a provider edge (PE) router on a dedicated interface. The security team wants to implement data plane protection that drops packets whose source address is not reachable via the exact interface on which they arrive, mitigating source-address spoofing from that customer. Which feature and mode should be configured on the PE interface?
More 350-501 practice
Keep going with the other Cisco CCNP Service Provider SPCOR (350-501) domains, or take a full timed mock exam.
← Back to 350-501 overview