首页 > 题库 > 400-007
« 返回题库列表

2026 Cisco CCDE 400-007历年真题与考试题库解析|最新CCDE设计考试备考资料

问题 #1
You want to mitigate failures that are caused by STP loops that occur before UDLD detects the failure or that are caused by a device that is no longer sending BPDUs. Which mechanism do you use along with UDLD?
A. root guard
B. BPDU filtering
C. loop guard
D. BPDU guard
正确答案:C
问题 #2
Organizations that embrace Zero Trust initiatives ranging from business policies to technology infrastructure can reap business and security benefits. Which two domains should be covered under Zero Trust initiatives? (Choose two.)
A. workspace
B. workplace
C. work domain
D. workgroup
E. workload
正确答案:BE
问题 #3
Company XYZ is redesigning their QoS policy. Some of the applications used by the company are real-time applications. The QoS design must give these applications preference in terms of transmission. Which QoS strategy can be used to fulfill the requiremen
A. weighted random early detection
B. first-in first-out
C. low-latency queuing
D. weighted fair queuing
正确答案:C
问题 #4
Company XYZ, a global content provider, owns data centers on different continents. Their data center design involves a standard three-layer design with a Layer 3-only core. HSRP is used as the FHRP. They require VLAN extension across access switches in al
A. at the access layer because the STP root bridge does not need to align with the HSRP active node
B. at the core layer, to offer the possibility to isolate STP domains
C. at the core layer because all external connections must terminate there for security reasons
D. at the aggregation layer because it is the Layer 2 to Layer 3 demarcation point
正确答案:D
问题 #5
Which three items do you recommend for control plane hardening of an infrastructure device? (Choose three.)
A. SNMPv3
B. to enable unused services
C. redundant AAA servers
D. Control Plane Policing
E. routing protocol authentication
F. warning banners
正确答案:ADE
问题 #6
Company XYZ wants to use the FCAPS ISO standard for network management design. The focus of the design should be to monitor and keep track of any performance issues by continuously collecting and analyzing statistical information to monitor, correct, and
A. security management
B. performance management
C. fault management
D. accounting management
正确答案:B
问题 #7
SD-WAN can be used to provide secure connectivity to remote offices, branch offices, campus networks, data centers, and the cloud over any type of IP-based underlay transport network. Which two statements describe SD-WAN solutions? (Choose two.)
A. Solutions allow for variations of commodity and specialized switching hardware.
B. Solutions include centralized orchestration, control, and zero-touch provisioning
C. Control and data forwarding planes are kept separate.
D. Improved operational efficiencies result in cost savings.
E. SD-WAN networks are inherently protected against slow performance.
正确答案:BC
问题 #8
Which best practice ensures data security in the private cloud?
A. Use IPsec for communication between unsecured network connections.
B. Anonymize data ownership to comply with privacy rules.
C. Use the same vendor for consistent encryption.
D. Encrypt data at rest and in transition.
正确答案:D
问题 #9
Which two conditions must be met for EIGRP to maintain an alternate loop-free path to a remote network? (Choose two.)
A. The Feasible Distance from a successor is lower than the local Reported Distance.
B. The feasibility condition does not need to be met.
C. The Reported Distance from a successor is lower than the local Feasible Distance.
D. The Reported Distance from a successor is higher than the local Feasible Distance.
E. A feasible successor must be present.
正确答案:CE
问题 #10
A European government passport agency considers upgrading its IT systems to increase performance and workload flexibility in response to constantly changing requirements. The budget manager wants to reduce capital expenses and IT staff and must adopt the
A. public cloud
B. hybrid cloud
C. on premises
D. private cloud
正确答案:A
问题 #11
Which two control plane policer designs must be considered to achieve high availability? (Choose two.)
A. Control plane policers require that adequate protocols overhead are factored in to allow protocol convergence.
B. Control plane policers must be processed before a forwarding decision is made.
C. Control plane policers can cause the network management systems to create false alarms.
D. Control plane policers are enforced in hardware to protect the software path, but they are hardware platform-dependent in terms of classification ability.
E. Control plane policers are really needed only on externally facing devices.
正确答案:BD
问题 #12
Which two application requirements are mandatory for traffic to receive proper treatment when placed in the priority queue? (Choose two.)
A. tolerance to packet loss
B. TCP-based application
C. small transactions (HTTP-like behavior)
D. WRED drop treatment
E. intolerance to jitter
正确答案:CE
问题 #13
Company XYZ wants to improve the security design of their network to include protection from reconnaissance and DoS attacks on their subinterfaces destined toward next hop routers. Which technology can be used to prevent these types of attacks?
A. DPP
B. CoPP
C. MPP
D. CPPr
正确答案:D
问题 #14
An architect designs a multi-controller network architecture with these requirements: Achieve fast failover to control traffic when controllers fail. Yield a short distance and high resiliency in the connection between the switches and the controller. Red
A. controller state consistency
B. controller clustering
C. control path reliability
D. control node reliability
正确答案:A
问题 #15
A healthcare customer requested that SNMP traps must be sent over the MPLS Layer 3 VPN service. Which protocol must be enabled?
A. SNMPv2
B. SSH
C. SNMPv3
D. syslog
E. syslog TLS
正确答案:C
问题 #16
How must the queue sizes be designed to ensure that an application functions correctly?
A. The sum of the queuing delay of all devices plus serialization delay in the chain must be less than or equal to the application required delay.
B. The queuing delay on every device in the chain must be exactly the same to the application required delay.
C. The default queue sizes are good for any deployment as it compensates the serialization delay.
D. Each individual device queuing delay in the chain must be less than or equal to the application required delay.
正确答案:A
问题 #17
In an OSPF network with routers connected together with Ethernet cabling, which topology typically takes the longest to converge?
A. ring
B. partial mesh
C. triangulated
D. squared
E. full mesh
正确答案:A
问题 #18
A multicast network is using Bidirectional PIM. Which two combined actions achieve high availability so that two RPRs within the same network can act in a redundant manner? (Choose two.)
A. Advertise the two RP addresses in the routing protocol.
B. Use two phantom RP addresses.
C. Control routing to the two RPs through a longest match prefix.
D. Use Anycast RP based on MSDP peering between the two RPs.
E. Manipulate the administrative distance of the unicast routes to the two RPs.
F. Manipulate the multicast routing table by creating static mroutes to the two RPs.
正确答案:BC
问题 #19
Company XYZ has 30 sites running a legacy private WAN architecture that connects to the Internet via multiple high-speed connections. The company is now redesigning their network and must comply with these design requirements: Use a private WAN strategy t
A. S-VTI
B. PPTP
C. IPsec
D. GET VPN
E. DMVPN
正确答案:DE
问题 #20
A small organization of 20 employees is looking to deliver a network design service for modernizing customer networks to support advanced solutions. Project scope and weekly progress should be visualized by the management. Always consider feedback and mak
A. Scrum
B. LEAN
C. Six-Sigma
D. Kanban
正确答案:D
问题 #21
IPFIX data collection via standalone IPFIX probes is an alternative to flow collection from routers and switches. Which use case is suitable for using IPFIX probes?
A. observation of critical links
B. performance monitoring
C. capacity planning
D. security
正确答案:B
问题 #22
Company XYZ needs advice in redesigning their legacy Layer 2 infrastructure. Which technology should be included in the design to minimize or avoid convergence delays due to STP or FHRP and provide a loop-free topology?
A. Use spanning-tree PortFast.
B. Use BFD.
C. Use switch clustering in the access layer.
D. Use switch clustering in the core/distribution layer.
正确答案:D
问题 #23
SDWAN networks capitalize the usage of broadband Internet links over traditional MPLS links to offer more cost benefits to enterprise customers. However, due to the insecure nature of the public Internet it is mandatory to use encryption of traffic betwee
A. TLS
B. IPsec
C. DTLS
D. GRE
正确答案:B
问题 #24
Which interconnectivity method offers the fastest convergence in the event of a unidirectional issue between three layer 3 switches connected together with routed links in the same rack in a data center?
A. Copper Ethernet connectivity with BFD enabled
B. Fiber Ethernet connectivity with BFD enabled
C. Copper Ethernet connectivity with UDLD enabled
D. Fiber Ethernet connectivity with UDLD enabled
正确答案:B
问题 #25
The Company XYZ network is experiencing attacks against their router. Which type of Control Plane Protection must be used on the router to protect all control plane IP traffic that is destined directly for one of the router interfaces?
A. Control Plane Protection main interface
B. Control Plane Protection CEF-exception subinterface
C. Control Plane Protection host subinterface
D. Control Plane Protection transit subinterface
正确答案:C
问题 #26
What is a characteristic of a secure cloud architecture model?
A. multi-factor authentication
B. limited access to job function
C. dedicated and restricted workstations
D. software-defined network segmentation
正确答案:D
问题 #27
A BGP route reflector in the network is taking longer than expected to converge during large network changes. Troubleshooting shows that the router cannot handle all the TCP acknowledgements during route updates. Which action can be performed to tune the
A. Increase the size of the hold queue.
B. Increase the keepalive timers for each BGP neighbor.
C. Increase the size of the large buffers.
D. Decrease the size of the small buffers.
正确答案:A
问题 #28
Which three elements help network designers to construct secure systems that protect information and resources (such as devices, communication, and data) from unauthorized access, modification, inspection, or destruction? (Choose three.)
A. serviceability
B. confidentiality
C. scalability
D. integrity
E. reliability
F. availability
正确答案:BDF
问题 #29
How can EIGRP topologies be designed to converge as fast as possible in the event of a point-to-point link failure?
A. Build neighbor adjacencies in a squared fashion.
B. Build neighbor adjacencies in a triangulated fashion.
C. Limit the query domain by use of distribute lists.
D. Limit the query domain by use of default routes.
E. Limit the query domain by use of summarization.
正确答案:E
问题 #30
Which undesired effect of increasing the jitter compensation buffer is true?
A. The overall transport delay increases and quality issues can occur.
B. The overall transport delay decreases and quality improves.
C. The overall transport jitter decreases and quality improves.
D. The overall transport jitter increases and quality issues can occur.
正确答案:A
问题 #31
Which optimal use of interface dampening on a fast convergence network design is true?
A. when occasional flaps of long duration occur
B. when numerous adjacent flaps of very short duration occur
C. when the switch hardware is faster than the debounce timer down detection
D. when the router hardware is slower than the carrier delay down detection
正确答案:B
问题 #32
Which two mechanisms avoid suboptimal routing in a network with dynamic mutual redistribution between multiple OSPFv2 and EIGRP boundaries? (Choose two.)
A. AD manipulation
B. matching OSPF external routes
C. matching EIGRP process ID
D. route tagging
E. route filtering
正确答案:DE
问题 #33
Company XYZ is in the process of identifying which transport mechanism(s) to use as their WAN technology. Their main two requirements are 1.a technology that could offer DPI, SLA, secure tunnels, privacy, QoS, scalability, reliability, and ease of managem
A. Software-defined WAN should be the preferred choice because it complements both technologies, covers all the required features, and it is the most cost-effective solution.
B. Internet should be the preferred option because it is cost effective and supports BFD, IP SLA, and IPsec for secure transport over the public Internet.
C. Both technologies should be used. Each should be used to back up the other one, where the primary links are MPLS, the Internet should be used as a backup link with IPsec (and vice versa).
D. MPLS meets all these requirements and it is more reliable than using the Internet. It is widely used with clearly defined best practices and an industry standard.
正确答案:A
问题 #34
What is the most important operational driver in building a resilient and secure modular network design?
A. Increase time spent on developing new features
B. Dependencies on hardware or software that is difficult to scale
C. Minimize app downtime
D. Reduce the frequency of failures requiring human intervention
正确答案:D
问题 #35
Which two actions ensure voice quality in a branch location with a low-speed, high-latency WAN connection? (Choose two.)
A. Increase memory on the branch switch.
B. Prioritize voice packets.
C. Fragment data packets.
D. Increase WAN bandwidth.
E. Replace any electrical links with optical links.
正确答案:BC
问题 #36
Which three tools are used for ongoing monitoring and maintenance of a voice and video environment? (Choose three.)
A. flow-based analysis with PTP time-stamping to measure loss, agency, and jitter
B. passive monitoring via synthetic probes to measure loss, latency, and jitter
C. active monitoring via synthetic probes to measure loss, latency, and jitter
D. call management analysis to identify network convergence-related failures
E. call management analysis to identify CAC failures and call quality issues
F. flow-based analysis to measure bandwidth mix of applications and their flows
正确答案:ACE
问题 #37
Which two features control multicast traffic in a VLAN environment? (Choose two.)
A. PIM snooping
B. MLD snooping
C. RGMP
D. pruning
E. IGMP snooping
正确答案:BE
问题 #38
According to the CIA triad principles for network security design, which principle should be priority for a Zero Trust network?
A. requirement for data-at-rest encryption for user identification within the VPN termination hardware
B. categorization of systems, data, and enterprise BYOD assets that are connected to network zones based on individual privacy needs
C. requirement for data-in-motion encryption and 2FA authentication
D. ensuring that authorized users have high-availability system access from defined zones to defined systems or zones
正确答案:C
问题 #39
Which relationship between iBGP and the underlying physical topology is true?
A. iBGP can work only on a ring network topology with a link-state protocol like OSPF or IS-IS.
B. iBGP full mesh requires an underlying fully meshed network topology.
C. iBGP full mesh requirement does not dictate any specific network topology.
D. iBGP does not work on a ring network topology even with an underlying IGP.
正确答案:C
问题 #40
Company XYZ is running a redundant private WAN network using OSPF as the underlay protocol. The current design accommodates for redundancy in the network, but it is taking over 30 seconds for the network to reconverge upon failure. Which technique can be
A. STP
B. OSPF LFA
C. fate sharing
D. flex links
E. BFD
正确答案:E
问题 #41
What are two primary design constraints when a robust infrastructure solution is created? (Choose two.)
A. project time frame
B. component availability
C. staff experience
D. total cost
E. monitoring capabilities
正确答案:AD
问题 #42
Which architecture does not require an explicit multicast signaling protocol such as PIM or P2MP, to signal the multicast state hop-by-hop, but instead uses a link state protocol to advertise the multicast forwarding state?
A. Bit Indexed Explicit Replication
B. Binary Indexed Explicit Routing
C. Bi-Directional Implicit Replication
D. Binary Intermediate Enhanced Routing
正确答案:A
问题 #43
Which two points must network designers consider when designing a new network design or when evaluating an existing network design to help them understand the high-level design direction with regards to the security aspects? (Choose two.)
A. Consider for only complex networks
B. Consider Business objectives and goals
C. Consider for only multi-site networks
D. Consider organization's security policy standards
E. Consider for only new network technologies and components
正确答案:BD
问题 #44
An enterprise network has two core routers that connect to 200 distribution routers and uses full-mesh iBGP peering between these routers as routing method. The distribution routers are experiencing high CPU utilization due to the BGP process. Which desig
A. Implement route reflectors on the two core routers.
B. Increase the memory on the distribution routers.
C. Implement eBGP between the core and distribution routers.
D. Increase bandwidth between the core routers.
E. Increase the memory on the core routers.
正确答案:A
问题 #45
Which function is performed at the access layer of the three-layer hierarchical network design model?
A. reliability
B. QoS classification and marking boundary
C. fast transport
D. redundancy and load balancing
E. fault isolation
正确答案:B
问题 #46
What are two common approaches to analyzing and designing networks? (Choose two.)
A. high-low security approach
B. top-down approach
C. three-tier approach
D. bottom-up approach
E. left-right approach
正确答案:BD
问题 #47
Company XYZ network runs IPv4 and IPv6 and they want to introduce a multidomain, multicast-based network. The new design should use flavor of PIM that forwards traffic using SPT. Which technology meets this requirement?
A. PIM-DM
B. BIDIR-PIM
C. PIM-SM
D. PIM-SSM
正确答案:D
问题 #48
Company XYZ is planning to deploy primary and secondary (disaster recovery) data center sites. Each of these sites will have redundant SAN fabrics and data protection is expected between the data center sites. The sites are 100 miles (160 km) apart and ta
A. Asynchronous data replication should be used in this scenario to avoid performance impact in the primary site.
B. VSANs must be extended from the primary to the secondary site to improve performance and availability.
C. Target RPO/RTO requirements cannot be met due to the one-way delay introduced by the distance between sites.
D. Synchronous data replication must be used to meet the business requirements.
E. VSANs must be routed between sites to isolate fault domains and increase overall availability.
正确答案:AE
问题 #49
An enterprise requires MPLS connected branches to access cloud-based Microsoft 365 services over an SD-WAN solution. Internet access is available only at dual regional hub sites that are connected to the MPLS network. Which connectivity method provides an
A. Cloud onRamp gateway site
B. Cloud onRamp SWG
C. Cloud onRamp SaaS
D. Cloud onRamp
正确答案:C
问题 #50
Company XYZ has implemented policy-based routing in their network. Which potential problem must be kept in mind about network reconvergence and PBR?
A. It increases convergence time.
B. It can limit network scalability.
C. It reduces convergence time.
D. It can create microloops during reconvergence.
正确答案:D
问题 #51
Company XYZ wants to secure the data plane of their network. Which two technologies can be included in the security design? (Choose two.)
A. MPP
B. BEEP
C. IP Source Guard
D. CPPr
E. DAI
正确答案:CE
问题 #52
As part of workspace digitization, a large enterprise has migrated all their users to Desktop as a Service (DaaS), by hosting the backend system in their on-premises data center. Some of the branches have started to experience disconnections to the DaaS a
A. traffic shaping
B. traffic policing
C. WRED
D. tail drop
正确答案:A
问题 #53
What are two examples of business goals to be considered when a network design is built? (Choose two.)
A. integrate endpoint posture
B. minimize operational costs
C. ensure faster obsolescence
D. reduce complexity
E. standardize resiliency
正确答案:BD
问题 #54
A European national bank considers migrating its on-premises systems to a private cloud offering in a non-European location to significantly reduce IT costs. What is a primary factor prior to migration?
A. data governance
B. security
C. cloud connectivity
D. additional latency
正确答案:A
问题 #55
A healthcare provider discovers that protected health information of patients was altered without patient consent. The healthcare provider is subject to HIPAA compliance and is required to protect PHI data. Which type of security safeguard should be imple
A. technical and physical access control
B. technical integrity and transmission security
C. physical device and media control
D. administrative security management processes
正确答案:D
问题 #56
Which purpose of a dynamically created tunnel interface on the design of IPv6 multicast services is true?
A. first-hop router registration to the RP
B. multicast client registration to the RP
C. multicast source registration to the RP
D. transport of all IPv6 multicast traffic
正确答案:D
问题 #57
Which BGP feature provides fast convergence?
A. BGP-LS
B. BGP PIC
C. BGP FlowSpec
D. BGP-EVPN
正确答案:B
问题 #58
You have been asked to design a high-density wireless network for a university campus. Which two principles would you apply in order to maximize the wireless network capacity? (Choose two.)
A. Enable 802.11n channel bonding on both 2.4 GHz and 5 GHz to increase the maximum aggregated cell throughput.
B. Increase the number of SSIDs to load-balance the client traffic.
C. Implement a four-channel design on 2.4 GHz to increase the number of available channels.
D. Choose a high minimum data rate to reduce the duty cycle.
E. Make use of the 5-GHz band to reduce the spectrum utilization on 2.4 GHz when dual-band clients are used.
正确答案:DE

即刻预约

免费试听-咨询课程-获取免费资料