Latest exam question analyses
Every time a question is re-reviewed — answer verified, explanation rewritten, official references checked — it appears here. 2,817 analyses published so far, newest first.
-
300-420
Dedicated Control-Plane Nodes for Frequent Endpoint Roaming
Cisco SD-Access recommends dedicated control-plane (CP) nodes when the design needs to scale the host-to-location mapping database and support features like frequent endpoint roaming across fabric edge nodes. In small, stable deployments the edge nodes can hold the CP function.
-
300-420
AES-CBC for Multicast in Cisco SD-WAN (GCM for Unicast)
Cisco SD-WAN prefers AES-256-GCM for unicast encryption, but for multicast applications it uses AES-CBC with an HMAC because GCM's counter/nonce handling does not fit multicast distribution. Newer releases use GCM for unicast; CBC remains the multicast mode.
-
300-420
Full Mesh WAN: Informed Decisions and Always-On Backup Paths
A full-mesh WAN connects every site to every other site. Each device has full routing knowledge (informed decisions), a backup path to every peer always exists, and traffic only takes a suboptimal path when a primary link fails. Partial mesh/hub-and-spoke have single points of failure.
-
300-420
WoL Across VLANs: Directed Broadcast and WoL-Server Helpers
To wake clients across subnets, enable IP directed-broadcast and ip forward-protocol on the routed/SVI interfaces where the client subnets reside (so the subnet broadcast is forwarded), and enable IP helper-addresses pointing to the WoL server on those client-subnet interfaces so the server's magic packets are relayed into each client VLAN.
-
200-301
Using Digital Certificates for Enterprise Device Authentication
Certificates are a credential type used as a password alternative: a device presents a machine certificate to prove identity, commonly via 802.1X EAP-TLS. One-time passwords and magic links are still knowledge/possession factors, and renewal policies are just password hygiene.
-
200-301
Biometric Authentication Uses a Physical Attribute
Biometrics are an inherence factor: something the user physically is. Passwords are knowledge, certificates are possession, and multifactor combines types. Only biometrics require a physical/biological attribute.
-
200-301
How a Switch Performs Frame Switching
A Layer 2 switch forwards frames by looking up the destination MAC in the MAC address table (CAM table) to select the egress port. It does not rewrite MAC addresses, does not request retransmission (that is TCP), and floods—not drops—unknown destinations.
-
200-301
How a Switch Performs Frame Switching
A Layer 2 switch forwards frames by looking up the destination MAC in the MAC address table (CAM table) to select the egress port. It does not rewrite MAC addresses, is not disabled by default, and floods—not drops—unknown destinations.
-
350-601
PowerOn Auto Provisioning (POAP) Required Network Infrastructure
POAP boots a new switch with no startup config, finds a DHCP server, downloads a configuration script from a TFTP server, and pulls software images and config from a file server (SCP/FTP/SFTP/HTTP). Beyond DHCP/DNS, you must provide a TFTP script server and a file repository (e.g., SCP).
-
350-601
PIM Sparse Mode with BSR for Automatic RP Discovery
For multicast that reaches only requesting clients with automatic RP-set discovery, enable PIM sparse mode and BSR; dense mode floods and incomplete commands break RP discovery.
-
350-601
FCoE FC-Map Configuration to Prevent Cross-Fabric Talk
On a converged Nexus link, fcoe fcmap sets the FC-Map that identifies the fabric and discards FCoE frames from foreign fabrics, preventing cross-fabric data corruption while preserving QoS.
-
350-601
Terraform ACI Provider Authentication and APIC DOS Threshold Counting
For ACI Terraform automation where APIC must count auth requests against the DOS threshold, configure the provider with user ID and password rather than signature-based auth.
-
300-425
Optimizing Roaming for Shopping Center Shops with Unique WLANs
Optimizing client roaming in a multi-WLAN shopping center requires mapping each shop's WLAN to a dedicated interface on the Cisco 9800 controller. This page explains why creating an interface per shop (D) is the correct answer and why the other options fail to improve roaming.
-
300-425
WLC AP Fallback Design for N+1 Redundancy
This question addresses the design requirements for ensuring Access Points return to their primary Wireless LAN Controller after a failover event in an N+1 redundancy architecture. It establishes that both the fallback feature and correct primary controller configuration are essential for proper behavior.
-
300-425
How Does a Single 9800-40 WLC Achieve Cable-Failure High Availability?
Cisco 9800-40 WLC high availability with a single controller relies on a Link Aggregation Group (LAG) that bundles distribution ports into an 802.3ad EtherChannel. The correct design is LAG (A), which provides cable-failure redundancy and transparent AP load balancing without LACP or PAgP negotiation.
-
300-425
Seamless Layer 3 Roaming Configuration
Seamless Layer 3 roaming between Cisco WLCs requires clients to maintain their wireless connection across different subnets. This page establishes that for Layer 3 roaming to occur, the SSIDs must be identical while the VLANs and subnets must differ.
-
DP-600
What Implements Calculation Groups for Direct Lake Semantic Models?
Contoso's Research division semantic models must run in Direct Lake mode, so calculation groups must be authored with an XMLA modeling tool rather than Power BI Desktop. This page establishes that Tabular Editor (D) is the tool to implement calculation groups, and explains why the Power BI service and DAX Studio are not the expected answer.
-
DP-600
How Do You Access the Productline1 Lakehouse Shortcut from a Fabric Notebook?
This DP-600 case-study question asks which notebook syntax reads the Productline1 data that Contoso exposes through a shortcut named ResearchProduct in Lakehouse1. The answer is the Spark SQL query against Lakehouse1.ResearchProduct, because the shortcut is registered as a table in the lakehouse rather than under a productline1 folder.
-
DP-600
How to Implement a Date Dimension in a Fabric Lakehouse?
In Microsoft Fabric, a date dimension can be implemented either by populating a table with a dataflow or by creating a T-SQL view in a lakehouse. This page establishes that stored procedures and Copy activities are not valid for a lakehouse date dimension, confirming the correct answers are A and C.
-
DP-600
How to Convert CSV to Delta with V-Order in Fabric Lakehouse?
In Microsoft Fabric, the Load to Tables feature from Lakehouse explorer converts CSV files in a subfolder into Delta tables with V-Order optimization enabled by default. This page confirms option A is the correct action for the DP-600 scenario.
-
350-701
Why Does IKEv1 IPsec Tunnel Show 'Proxy Identities Not Supported'?
The Cisco debug 'proxy identities not supported' means the IPsec traffic-selector ACLs on the two peers do not reverse each other, so the tunnel fails even when IKEv1, AES, SHA-256, and the preshared key are correctly configured. This 350-701 page establishes that the correct configuration check is D, with official Cisco debug references and community consensus.
-
350-701
Which Two Methods Belong in an AAA Authentication Method List?
This Cisco 350-701 question tests which keywords are valid methods inside a Cisco IOS AAA authentication method list. The page confirms that line and enable (D, E) are the correct choices, while default, login, and console are not methods.
-
350-701
Modifying Cisco AnyConnect Split Tunnel via Group Policy
This page explains how to configure split tunneling for a remote access VPN on Cisco Secure Firewall (FTD) and Cisco AnyConnect clients by modifying the group policy.
-
350-701
Configuring Malware Quarantine on Cisco Secure Email Gateway
This question tests the configuration of incoming mail policies in Cisco Secure Email Gateway (SEG) to quarantine malware instead of dropping them. It establishes that policy order determines which rule applies first, making the specific user policy the correct override for the default behavior.
-
SC-400
eDiscovery Case Mailbox Search Permissions
This question tests the capability of Microsoft Purview eDiscovery (Standard) to search mailbox content using legal hold and privilege controls rather than direct mailbox permissions. It establishes that creating an eDiscovery case allows Admin1 to search User5's mailbox without needing explicit send-as rights.
-
SC-400
First Step for Insider Risk Management Policy in Microsoft Purview
To detect data theft from SharePoint Online by users near termination, you must first configure an HR data connector to import resignation and termination events into Microsoft Purview.
-
SC-400
Microsoft Purview Activity Explorer for DLP and Label Reports
Activity Explorer is the correct tool to monitor and report on DLP policy matches and sensitivity label changes within Microsoft 365. This solution provides a centralized dashboard for tracking content-related activities without requiring eDiscovery or content search procedures.
-
SC-400
KQL Query for Content Search Recipients
Determines the correct Kusto Query Language (KQL) syntax to filter email recipients in Microsoft Purview Content Search using logical operators.
-
MS-102
Does a Strict Preset Security Policy Meet the Balanced Baseline Goal?
In Microsoft Defender for Office 365, preset security policies come in two flavors — Standard and Strict — and only the Standard preset delivers the balanced baseline protection profile described in the scenario. Because the solution creates a Strict preset policy instead, it does not meet the stated goal.
-
MS-102
Does a Standard Preset Security Policy Meet a Balanced Baseline Goal?
This MS-102 scenario asks whether creating a Standard preset security policy in Microsoft Defender for Office 365 satisfies a requirement for a balanced baseline profile against spam, phishing, and malware. Yes — Standard is the built-in balanced profile, while Strict is the more aggressive quarantine-heavy option.
-
MS-102
Does an Intune EDR Policy Auto-Onboard Devices to Defender for Endpoint?
When Microsoft Defender for Endpoint is integrated with Intune, an endpoint detection and response (EDR) policy is a supported way to push the Defender for Endpoint onboarding configuration so enrolled devices onboard automatically. This page confirms that creating an EDR policy does meet the stated goal.
-
MS-102
Does Co-management Auto-Onboard Devices to Defender for Endpoint?
This MS-102 case-study item asks whether simply enabling Intune co-management causes enrolled devices to onboard automatically to Microsoft Defender for Endpoint. It establishes that the answer is No — co-management governs joint Configuration Manager and Intune device management, not Defender for Endpoint onboarding, which requires an Endpoint Detection and Response (EDR) policy in Intune.
-
SC-300
How Does WebApp1 Read and Write to storage1 with Its Managed Identity?
Granting a web app's system-assigned managed identity read/write access to an Azure storage account is done from the storage account's Access control (IAM) blade, where the identity receives a data-plane RBAC role such as Storage Blob Data Contributor. This page confirms option C and explains why SAS tokens, access keys, and file share settings do not satisfy the managed identity requirement.
-
SC-300
How to Assess Privilege Assignment Risks Across Azure, GCP, and AWS?
Microsoft Entra Permissions Management is a multicloud permissions and privilege-risk assessment service for Azure, GCP, and AWS. This SC-300 guide establishes why it is the recommended answer (D) for minimizing administrative effort when assessing privilege assignments across all three clouds.
-
SC-300
Which Two Credentials Let App1 Access App2 Across Tenants?
App1 is an app registration in your Microsoft Entra tenant that must reach App2 in a partner organization's tenant, which requires app-only, cross-tenant authentication through the OAuth 2.0 client credentials flow. This page establishes that the two valid credential types App1 can present are a certificate and a client secret.
-
SC-300
How to Remove Unused Managed Identity Permissions in Entra Permissions Management
Microsoft Entra Permissions Management can automatically detect and revoke permissions that managed identities have not used for 90 days. This page confirms that an Autopilot rule is the correct, low-effort mechanism, while reports and audit queries only surface the data.
-
MD-102
Automatic Intune Enrollment via MDM User Scope
This question addresses the configuration required to automatically enroll Windows devices in Microsoft Intune upon joining a Microsoft Entra tenant. It establishes that configuring the MDM user scope is the correct mechanism for this automation.
-
MD-102
Capabilities of a User-Registered Device in Microsoft Entra ID
This question evaluates the specific capabilities granted to a Windows 11 device when registered as a user-owned device in a Microsoft Entra tenant. It establishes that registration primarily enables Single Sign-On (SSO) for cloud resources, distinct from full management features.
-
MD-102
Register Android Device in Entra ID via Company Portal
This question tests the correct method for registering an Android device in Microsoft Entra ID using the Microsoft Intune Company Portal app. It establishes that Company Portal is the standard user-facing tool for BYOD registration and enrollment.
-
MD-102
Registering Android Device in Microsoft Entra ID
This question tests the correct method for registering an Android device with Microsoft Entra ID. The solution using Microsoft Entra Connect is incorrect because it is designed for on-premises directory synchronization, not device registration.
-
AI-102
Optimize Content Safety Filters with Moderate Text Feature
This question addresses how to optimize content filter configurations in Azure AI Content Safety using the Moderate text content feature. It establishes that running tests on sample questions via Content Safety Studio is the correct approach for validation.
-
AI-102
Question Answering Alternative Phrasing vs Entities
Creating an entity for a term like cost does not resolve question phrasing mismatches in Azure Cognitive Service for Language. This page establishes that adding alternative phrasing to the question and answer pair is the correct method to handle varied user queries.
-
AI-102
Optimize Content Safety Filters with Sample Questions
Using the Monitor online activity feature in Azure AI Content Safety Studio does not meet the requirement to run tests on sample questions to optimize content filter configurations. The correct approach involves using the Test or Analyze features specifically designed for offline testing and tuning.
-
AI-102
Azure OpenAI Fine-Tuning Training Data Format
Azure OpenAI requires fine-tuning training data to be formatted as JSON Lines (JSONL). This page confirms that prompt-completion pairs must be structured using this specific file format for successful model fine-tuning.
-
300-415
SD-WAN TLOC Selection with SLA and Application-Aware Routing
Determines the correct TLOC path when SLA thresholds are met by both options but no preferred color is configured, relying on application-aware routing metrics.
-
300-415
Cisco SD-WAN Multi-Region Fabric Capability
This page explains the primary security capability of Cisco Catalyst SD-WAN Multi-Region Fabric, which is end-to-end encryption for inter-region traffic. It clarifies why this feature distinguishes Multi-Region from standard single-region deployments.
-
300-415
Cisco SD-WAN Controller for Provisioning and Configuration
This question tests the specific role of the Cisco Catalyst SD-WAN controllers, identifying vManage as the component responsible for centralized provisioning and configuration.
-
300-415
Cisco SD-WAN Packet Duplication Process
Packet duplication in Cisco Catalyst SD-WAN ensures reliability by sending copies of packets over multiple WAN circuits to overcome packet loss, maintaining application performance.
-
MB-820
The Non-conformity Number field uses the Code data type because it is populated by the No. Series table, and the Non-conformity Date field uses the Date data type because it stores only the creation date
When modeling table fields in Business Central, the data type must match how the value is generated and stored. A number produced by the standard No. Series functionality must be a Code field (typically Code[20]), and a field that stores only a calendar date uses the Date data type rather than DateTime.
-
MB-820
An extension can disappear from the tenant because it was published as a DEV extension or because it was not made compatible with the new major version within 90 days of the first notification
After a major version upgrade, Business Central applies lifecycle rules to extensions. A DEV extension is meant only for development and testing and is not a production artifact, so it can vanish after an upgrade. Separately, Microsoft deletes any extension that is not compatible with the new major version within 90 days of the first notification.
-
MB-820
Snapshot debugging only fires on the next session of the configured user, so a session that never occurs means debugging never starts
Snapshot debugging is configured by specifying the target user (userId) and a breakOnNext scope such as WebServiceClient. The snapshot is not captured immediately; it triggers the next time the specified user starts a session that matches the breakOnNext setting.
-
MB-820
A bound action exposed through OData is called with a lowercase action name prefixed by Microsoft.NAV. in the request URL
When you expose a bound action in Business Central and call it through OData v4, the first letter of the action name is automatically converted to lowercase and the call must be prefixed with Microsoft.NAV. Therefore an action named Copy is invoked as Microsoft.NAV.copy.
-
MB-335
Determine Which Plastic Outputs Are Reported as Finished in Dynamics 365 SCM
For the plastic molding process, the machined plastic pieces (the finished good) and the excess plastic (a recycled by-product) must be manually reported as finished, while unmachined pieces and mold tooling are not.
-
MB-335
Block Sales to California Using Restricted Product Lists in Dynamics 365 SCM
To prevent motorcycles from being sold to California while allowing sales elsewhere in the US, create an inclusive restricted product list for the United States (without adding the item) and an exclusive restricted product list for California that includes the motorcycle part.
-
MB-335
Prevent Deletion and Editing of Approved Formulas in Dynamics 365 SCM
To ensure approved formulas cannot be deleted or edited while still allowing deactivation, enable the Block editing parameter on the formula, used either alone or together with approving the formula. Block editing stops users from editing or deleting the formula record.
-
MB-335
Protect Approved Formulas from Deletion and Editing in Dynamics 365 SCM
To guarantee that approved formulas cannot be deleted or edited (while deactivation remains allowed), turn on Block editing for the formula, applied on its own or together with approving the formula. Block editing blocks both edits and deletions.
-
DP-700
OneLake availability for an eventhouse copies only newly ingested data by default
When you turn on OneLake availability for an eventhouse in Microsoft Fabric, only data added to the eventhouse after the feature is enabled is made available in OneLake; existing tables are not copied unless you explicitly select 'Apply to existing tables'.
-
DP-700
Grant analysts gold-layer access by sharing the lakehouse with Read all SQL Endpoint data
Sharing the gold-layer lakehouse with the DataAnalysts group and granting Read all SQL Endpoint data gives T-SQL read access to its Delta tables without exposing the bronze and silver layers or the rest of WorkspaceA.
-
DP-700
Disable high concurrency so bronze and silver notebook runs get isolated Spark sessions
High concurrency mode lets multiple notebook workloads share one running Spark session. To ensure the bronze and silver layer processes run in isolation in Workspace1, disable the high concurrency setting so each notebook run starts its own session.
-
DP-700
An S3 shortcut makes the book reviews available without copying the data
Creating a shortcut that points to the Amazon S3 bucket references the book review files in place, satisfying the Litware requirement to make the reviews available in the lakehouse without making a copy of the data.