DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Free Cisco 350-501 SPCOR Practice Questions 2026 Part2

Are you preparing for the Cisco 350-501 certification exam? SPOTO offers the Cisco 350-501 Premium File; all questions are aligned with the latest exam content and come with expert-provided answers. Our question banks cover the latest question types, core concepts, and detailed explanations, helping you familiarize yourself with the exam format and difficulty level. Whether you are reviewing core concepts or simulating a real exam environment, these resources will rapidly boost your confidence and readiness.
For over two decades, SPOTO has successfully helped numerous IT professionals secure their ideal positions at Fortune 500 companies. Download now to start practicing efficiently and ensure a high score on the actual exam. Don't miss this opportunity to pass your certification exam with ease!
Take other online exams

Question #1
Which type of attack is a protocol attack?
A. HTTP flood
B. TFTP flood
C. SYN flood
D. Slowloris
View answer
Correct Answer: C

View The Updated 350-501 Exam Questions

SPOTO Provides 100% Real 350-501 Exam Questions for You to Pass Your 350-501 Exam!

Question #2
Refer to the exhibit. The USER that is connecting an application on an Internet connection in AS100 is facing these issues:- The USER lost the connection to the application during a failurebetween IG and R2.- Router R2 configuration is lost due to a power outage.- The application the USER is connecting to is hosted behind CE2.What action resolves the issues on R3 and R4 routers?
A. et R3 as a route reflector for R4 and CE1
B. pply low Local Preference on R4 toward R2
C. et R4 as a route reflector for R3 and CE2
D. pply high Local Preference on R3 toward R1
View answer
Correct Answer: B
Question #3
Refer to the exhibit. P3 and PE4 are at the edge of the service provider core and serve as ABR routers. Aggregation areas are on either side of the core.Which statement about the architecture is true?
A. To support seamless MPLS, the BGP route reflector feature must be disabled
B. If each area is running its own IGP, BGP must provide an end-to-end MPLS LSP
C. If each area is running its own IGP, the ABR routers must redistribute the IGP routing table into BGP
D. To support seamless MPLS, TDP must be used as the label protocol
View answer
Correct Answer: B
Question #4
Refer to the exhibit. Which effect of this configuration is true?
A. It enables MPLS on the interface
B. It creates a pseudowire class named cisco
C. It enables AToM on interface gigabitethernet1/0
D. It enables tagging for VLAN 12 on the interface
View answer
Correct Answer: C
Question #5
Which BGP attribute is used first when determining the best path?
A. origin
B. AS path
C. local preference
D. weight
View answer
Correct Answer: D
Question #6
How much must the MTU be increased when configuring the 802.1q VLAN tag?
A. bytes
B. bytes
C. bytes
D. 2 bytes
View answer
Correct Answer: B
Question #7
Which component is similar to an EVPN instance?
A. outer distinguisher
B. PLS label
C. GP router ID
D. RF
View answer
Correct Answer: D
Question #8
Refer to the exhibit. A network operator needs to shut down interface Gi0/0/0/2 for maintenance. What occurs to the interface states of Gi0/0/0/0 and Gi0/0/0/1?
A. Gi0/0/0/1 and Gi0/0/0/0 become active
B. Gi0/0/0/1 and Gi0/0/0/0 remain standby
C. Gi0/0/0/0 becomes active; Gi0/0/0/1 remains standby
D. Gi0/0/0/1 becomes active; Gi0/0/0/0 remains standby
View answer
Correct Answer: D
Question #9
Refer to the exhibit Router R1 and its peer R2 reside on the same subnet in the network. If an engineer implements this configuration to R1, how does it make connections to R2?
A. R1 establishes TCP connections that are authenticated with a clear-text password
B. R1 establishes UDP connections that are authenticated with an MD5 password
C. R1 establishes UDP connections that are authenticated with a clear-text password
D. R1 establishes TCP connections that are authenticated with an MD5 password
View answer
Correct Answer: D
Question #10
Refer to the exihibit.Refer to the exhibit. A large enterprise has multiple branch offices that span several geographic regions. The enterprise runs MPLS within the core to propagate VPNv4 routes using BGP. After a recent series of DDoS attacks disrupted the network, a network engineer has been asked to reconfigure BGP to help mitigate future attacks. Which configuration must the engineer apply?A)B)C)D)
A. Option A
B. Option B
C. Option C
D. Option D
View answer
Correct Answer: B
Question #11
Which two features will be used when defining SR-TE explicit path hops if the devices are using IP unnumbered interfaces? (Choose two.)
A. router ID
B. labels
C. node address
D. next hop address
E. output interface
F. Reveal Answer
View answer
Correct Answer: BC
Question #12
Refer to the exhibit. BGPsec is implemented on R1, R2, R3, and R4. BGP peering is established between neighboring autonomous systems.Which statement about implementation is true?
A. GP updates from the iBGP peers are appended with a community of local-as
B. GP updates from the all BGP peers are appended with a community of no-export
C. GP updates from the eBGP peers are appended with an additional AS path value that is statically set by the domain administrator
D. GP updates from the eBGP peers are appended with a BGPsec attribute sequence that includes a public key hash and digital signature
View answer
Correct Answer: D
Question #13
A network engineer must enable the helper router to terminate the OSPF graceful restart process if it detects any changes in the LSA.Which command enables this feature?
A. nsf ietf helper disable
B. nsf cisco helper disable
C. nsf ietf helper strict-lsa-checking
D. nsf cisco enforce global
View answer
Correct Answer: C
Question #14
Which two PHY modes are available to implement an IOS XR 10 Gigabit Ethernet interface? (Choose two.)
A. LAN
B. SONET
C. MAN
D. WAN
E. WDWM
View answer
Correct Answer: AD
Question #15
Refer to the exhibit. R1 is connected to two service providers and is under a DDoS attack.Which statement about this design is true if URPF in strict mode is configured on both interfaces?
A. R1 drops all traffic that ingresses either interface that has a FIB entry that exits a different interface
B. R1 drops destination addresses that are routed to a null interface on the router
C. R1 permits asymmetric routing as long as the AS-PATH attribute entry matches the connected AS
D. R1 accepts source addresses on interface gigabitethernet0/1 that are private addresses
View answer
Correct Answer: A
Question #16
Refer to the exhibit. A network operator needs to shut down interface Gi0/0/0/2 for maintenance. What occurs to the interface states of Gi0/0/0/0 and Gi0/0/0/1?
A. Gi0/0/0/1 and Gi0/0/0/0 become active
B. Gi0/0/0/1 and Gi0/0/0/0 remain standby
C. Gi0/0/0/0 becomes active; Gi0/0/0/1 remains standby
D. Gi0/0/0/1 becomes active; Gi0/0/0/0 remains standby
View answer
Correct Answer: D
Question #17
After you analyze your network environment, you decide to implement a full separation model for Internet access and MPLS L3VPN services.For which reason do you make this decision?
A. t enables EGP and IGP to operate independently
B. t enables you to choose whether to separate or centralize each individual service
C. t is easier to manage a system in which services are mixed
D. t requires only one edge router
View answer
Correct Answer: B
Question #18
Why do Cisco MPLS TE tunnels require a link-state routing protocol?
A. he link-state database provides segmentation by area, which improves the path-selection process
B. he link-state database provides a data repository from which the tunnel endpoints can dynamically select a source ID
C. ink-state routing protocols use SPF calculations that the tunnel endpoints leverage to implement the tunnel
D. he tunnel endpoints use the link-state database to evaluate the entire topology and determine the best path
View answer
Correct Answer: D
Question #19
Which CLI mode must be used to configure the BGP keychain in Cisco IOS XR Software?
A. routing configuration mode
B. BGP neighbor configuration mode
C. global configuration mode
D. BGP address-family configuration mode
View answer
Correct Answer: B
Question #20
Refer to the exhibit. A network support engineer for ASN 65502 receives a technical support ticket from a customer in ASN 65503 who reports that an eBGP session is down. The engineer determines that the peering failed after a recent change to the device at 192.168.26.2. EDGE- GW-1 must establish an eBGP session with the peering router 192.168.26.2. Which configuration establishes this session?
A. onfigure terminalno router bgp 65502router bgp 65503neighbor 192
B. onfigure terminalrouter bgp 65502no neighbor 192
C. onfigure terminalrouter bgp 65502address-family ipv4neighbor 192
D. onfigure terminalno router bgp 65502router bgp 65503neighbor 192
View answer
Correct Answer: B
Question #21
Refer to the exhibit. An engineer is securing a customer's network. Which command must the engineer use to complete this configuration to prevent a DoS attack?
A. neighbor ttl-security
B. ebgp-multihop
C. neighbor ebgp-multihop
D. ttl-security
View answer
Correct Answer: D
Question #22
Refer to the exhibit. Which configuration prevents the OSPF neighbor from establishing?
A. default-metric
B. duplex
C. network statement
D. mtu
View answer
Correct Answer: D
Question #23
Refer to the exhibit. What is the result of this configuration?
A. Router 1 opens and closes a TCP connection to the TACACS+ server every time a user requires authorization
B. Router 1 and the TACACS+ server maintain one open connection between them only when network administrator is accessing the router with password ciscotest
C. Router 1 and the TACACS+ server maintain one open connection between them
D. Router 1 opens and closes a TCP connection to the TACACS+ server every time a user requires authentication
View answer
Correct Answer: C
Question #24
Refer to the exhibit. To protect in-band management access to CPE-R7, an engineer wants to allow only SSH management and provisioning traffic from management network 192.168.0.0/16. Which infrastructure ACL change must be applied to router PE-R9 to complete this task?
A. ip access-list extended INFRA-ACL15 permit tcp 192
B. ip access-list extended INFRA-ACLno 1015 permit tcp 192
C. ip access-list extended INFRA-ACL15 permit tcp 192
D. ip access-list extended INFRA-ACLno 1015 permit tcp 192
View answer
Correct Answer: B
Question #25
Refer to the exhibit. An engineer is preparing to implement data plane security configuration.Which statement about this configuration is true?
A. Router 2 is the router receiving the DDoS attack
B. Router 1 must be configured with uRPF for the RTBH implementation to be effective
C. Router 1 is the trigger router in a RTBH implementation
D. Router 2 must configure a route to null 0 for network 192
View answer
Correct Answer: C
Question #26
Refer to the exhibit
A. Router 2 is the router receiving the DDoS attack
B. Router 1 must be configured with uRPF for the RTBH implementation to be effective
C. Router 1 is the trigger router in a RTBH implementation
D. Router 2 must configure a route to null 0 for network 192
View answer
Correct Answer: C
Question #27
What does DWDM use to combine multiple optical signals?
A. IP protocols
B. wavelength
C. time slots
D. frequency
View answer
Correct Answer: B
Question #28
Refer to the exhibit. A network engineer must implement SNMPv3 on a Cisco IOS XR router running BGP. The engineer configures SNMPv3 to use SHA for authentication and AES for privacy on the routers, which are in a different data center in the same exchange as other routers.The engineer must also verify the associated MIB view family name, storage type, and status.Which set of actions meets these requirements?
A. dd configuration snmp-server user AuthUser group2 remote 10
B. dd configuration snmp-server user UserJustMe GrpMonitoring v3 auth sha AuthPass1 priv aes128 PrivPass2 and use show snmp view to verify the configuration
C. dd configuration snmp-server user UserJustMe GrpMonitoring v3 auth sha AuthPass1 priv 3des128 PrivPass2 and use show snmp interface to verify the configuration
D. dd configuration snmp-server user AuthUser group2 remote 10
View answer
Correct Answer: B
Question #29
Why is the keyword none needed when implementing management plane security using TACACS?
A. It aItovSWMB6ter to query a RADIUS server when the TACACS+ server is unreachable
B. It allows the local database to authenticate when the TACACS^ server is unreachable
C. It allows authentication to succeed when the TACACS+ server is unreachable
D. It prevents all users from accessing router 1 unless the TACACS+ server is reachable,
E. Reveal Answer
View answer
Correct Answer: C
Question #30
Refer to the exhibit. A network engineer is implementing an OSPF configuration. Based on the output, which statement is true?
A. OSPFv3 does not run for IPv4 on FastEthernet0/0 until IPv6 routing is enabled on the router and IPv6 is enabled on interface FastEthernet0/0
B. In the ospfv3 1 area 1 ipv4 command, area 0 must be configured instead of area 1
C. OSPFv3 cannot be configured for IPv4; OSPFv3 works only for IPv6
D. "IPv6 routing not enabled" is just an informational message and OSPFv3 runs for IPv4 on interface FastEthernet0/0 anyway
View answer
Correct Answer: A
Question #31
Refer to the exhibit. An engineer is preparing to implement data plane security configuration.Which statement about this configuration is true?
A. Router 1 and Router 2 advertise the route to 192
B. All traffic to 192
C. All traffic is dropped
D. Router 1 drops all traffic with a local-preference set to 150
View answer
Correct Answer: B
Question #32
Which statement describes the advantage of a Multi-Layer control plane?
A. t automatically provisions monitors, and manages traffic across Layer 0 to Layer 3
B. t minimizes human error configuring converged networks
C. t supports dynamic wavelength restoration in Layer 0
D. t provides multivendor configuration capabilities for Layer 3 to Layer 1
View answer
Correct Answer: A
Question #33
Which configuration mode do you use to apply the mpls ldp graceful-restart command in IOS XE Software?
A. MPLS LDP neighbor
B. interface
C. MPLS
D. global
View answer
Correct Answer: D
Question #34
Refer to the exhibit. Refer to the exhibit. Router R13 is operating in Level 1 / Level 2 mode. A network engineer with an employee ID: 5209:82:636 must change the IS-IS cost of the route IP address 10.212.124.1 to 90. The metric update must be carried over in TLV 128. Which configuration must be implemented to complete the task?
A. Ametric-style isis wide 90 under interface loopback1 on R13
B. Bmetric cost 90 under interface Gi1/1/1 on R12
C. Cisis metric 80 under interface loopback1 on R13
D. DIsis metric 90 under interface Gi1/1/1 on R12
View answer
Correct Answer: D
Question #35
A network architect at ISP must implement a loop-avoidance mechanism in the organization's ring network topology. The architect decided to implement ITU-T G.8032. Intermittent link flaps within two seconds should be ignored.
A. ring-protection g8032 profile vlan port-channel none
B. link-protection group management vlan 1
C. timer hold-off 2
D. continuity-check direction down 2
E. ethernet ring g8032 profile ethernet
View answer
Correct Answer: CE
Question #36
Refer to the exhibit. P3 and PE4 are at the edge of the service provider core and serve as ABR routers. Aggregation areas are on either side of the core.Which statement about the architecture is true?
A. o support seamless MPLS, the BGP route reflector feature must be disabled
B. f each area is running its own IGP, BGP must provide an end-to-end MPLS LSP
C. f each area is running its own IGP, the ABR routers must redistribute the IGP routing table into BGP
D. o support seamless MPLS, TDP must be used as the label protocol
View answer
Correct Answer: B
Question #37
Refer to the exhibit. Which show command shows statistics for the control plane policy and is used totroubleshoot?
A. show control-plane CoPP
B. show policy control-plane
C. show control-plane
D. show policy-map control-plane
View answer
Correct Answer: D
Question #38
Refer to the exhibit. What reestablishes the OSPF neighbor relationship between Router 1 and Router 2?
A. OSPF process IDs match
B. authentication is added to the configuration
C. correct wildcard mask is used on Router 2
D. hello intervals match
View answer
Correct Answer: D
Question #39
What is a constraint of Cisco MPLS TE tunnel configurations?
A. QoS-aware tunneling is not supported
B. Tunnels cannot be configured over IP unnumbered links
C. With ISIS as an IGP, only older-style metrics are used
D. Tunnels cannot span multiple OSPF areas
View answer
Correct Answer: B
Question #40
Refer to the exihibit.Refer to the exhibit. The link between Office A and Office B is running at 90% load, and occasionally the CPU on router R1 is overloaded. The company implemented QoS for business-critical applications at both offices as a temporary solution. A network engineer must update the R1 configuration to 600 ms to reduce CPU load and limit downtime after connection failure to avoid data loss. Which action meets this requirement?
A. Configure the fast-hello feature for OSPF with the command ip ospf dead-interval minimal hello-multiplier 3
B. Configure BFD demand mode with the command bfd-demand timer 150 interval 250 retransmit 5
C. Configure BFD non-echo mode with the command echo interval 250 minimal 300 echo-multiplier 2
D. Configure BFD echo mode with the command bfd interval 150 min_rx 200 multiplier 3
View answer
Correct Answer: D
Question #41
Refer to the exhibit. An engineer has started to configure a router for secure remote access as shown. All users who require network access need to be authenticated by the SSH protocol. Which two actions must the engineer implement to complete the SSH configuration? (Choose two.)
A. Configure an IP domain name
B. Configure ACL 100 to permit access to port 22
C. Configure a password under the vty lines
D. Configure crypto keys
E. Configure service password encryption
View answer
Correct Answer: AD
Question #42
Which Cisco Software OS uses microkernel architecture?
A. AIOS 12
B. BIOS XR
C. CIOS
D. DIOS 15
View answer
Correct Answer: B
Question #43
Which configuration mode do you use to apply the mpls ldp graceful-restart command in IOS XE Software?
A. MPLS LDP neighbor
B. interface
C. MPLS
D. global
View answer
Correct Answer: D
Question #44
Refer to the exhibit. To protect in-band management access to CPE-R7, an engineer wants to allow only SSH management and provisioning traffic from management network 192.168.0.0/16.Which infrastructure ACL change must be applied to router PE-R9 to complete this task?
A. p access-list extended INFRA-ACL15 permit tcp 192
B. p access-list extended INFRA-ACLno 1015 permit tcp 192
C. p access-list extended INFRA-ACLno 1015 permit tcp 192
D. p access-list extended INFRA-ACL15 permit tcp 192
View answer
Correct Answer: B

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number:
Contact Us