350-401 — 350-401 ENCOR: Implementing Cisco Enterprise Network Core Technologies v1.2
Cisco

350-401 ENCOR: Implementing Cisco Enterprise Network Core Technologies v1.2 (350-401) Practice Questions

★★★★★ 5.0 122 verified reviews
218 questions
June 19, 2026 updated
✓ Online quiz simulator

Sample Questions (22 of 218 shown)

Q1
What is the difference between a RIB and a FIB?
  1. The FIB is populated based on RIB content.
  2. The RIB maintains a mirror image of the FIB.
  3. The RIB is used to make IP source prefix-based switching decisions.
  4. The FIB is where all IP routing information is stored.
✓ Correct Answer: A
The Routing Information Base (RIB) contains all routing protocol learned routes. The Forwarding Information Base (FIB) is derived from the RIB and contains only the best paths. CEF uses the FIB in the data plane for high-speed switching.
Q2
Which QoS component alters a packet to change how traffic is treated in the network?
  1. policing
  2. classification
  3. marking
  4. shaping
✓ Correct Answer: C
Marking changes the QoS fields (DSCP or CoS) in a packet header to influence how downstream devices treat the traffic.
Q3
How does QoS traffic shaping alleviate network congestion?
  1. It drops packets when traffic exceeds a certain bitrate.
  2. It buffers and queues packets above the committed rate.
  3. It fragments large packets and queues them for delivery.
  4. It drops packets randomly from lower priority queues.
✓ Correct Answer: B
Traffic shaping buffers excess packets and queues them for later transmission at a configured rate. Unlike policing which drops, shaping smooths traffic bursts by holding packets in queues.
Q4
Which two facts apply to traffic policing? (Choose two.)
  1. Policing should be performed as close to the source as possible.
  2. Policing adapts to network congestion by queuing excess traffic.
  3. Policing should be performed as close to the destination as possible.
  4. Policing drops traffic that exceeds the defined rate.
  5. Policing typically delays the traffic rather than drops it.
✓ Correct Answer: A, D
Policing drops traffic exceeding the configured rate. It should be applied as close to the source as possible to drop unwanted traffic early.
Q5
Which component handles the orchestration plane of the Cisco SD-WAN?
  1. vBond
  2. vSmart
  3. vManage
  4. WAN Edge
✓ Correct Answer: A
vBond is the orchestrator in Cisco SD-WAN. It authenticates all components, learns public/private IP addresses, and orchestrates initial control connections.
Q6
What are two device roles in Cisco SD-Access fabric? (Choose two.)
  1. edge node
  2. vBond controller
  3. access switch
  4. core switch
  5. border node
✓ Correct Answer: A, E
SD-Access fabric has three main roles: edge node (connects endpoints), border node (connects fabric to external networks), and control plane node (maintains endpoint database via LISP).
Q7
Which two layers are collapsed into one in a 2-tier (collapsed core) enterprise campus design?
  1. Access and distribution
  2. Distribution and core
  3. Access and core
  4. Edge and access
✓ Correct Answer: B
In a collapsed core design, the distribution and core layers are merged into a single layer while the access layer remains separate.
Q8
Which Cisco high-availability technology synchronizes active and standby supervisors so a switchover does not disrupt forwarding?
  1. FHRP
  2. SSO
  3. GLBP
  4. BFD
✓ Correct Answer: B
Stateful Switchover (SSO) synchronizes protocol state and forwarding info between supervisors. When the active fails, the standby takes over with minimal disruption.
Q9
In a Cisco Catalyst SD-WAN fabric, which controller authenticates WAN edges and orchestrates initial control connections?
  1. vManage
  2. vSmart
  3. vBond
  4. vAnalytics
✓ Correct Answer: C
vBond authenticates vEdge/cEdge routers and other controllers, learns transport-side addresses, and helps WAN edges find vManage and vSmart.
Q10
Which protocol distributes routing, TLOC, and service information between Cisco Catalyst SD-WAN edges and vSmart?
  1. BGP
  2. EIGRP
  3. OMP
  4. LISP
✓ Correct Answer: C
Overlay Management Protocol (OMP) is the SD-WAN control-plane protocol running over DTLS/TLS between WAN edges and vSmart, advertising routes, TLOCs, and service routes.
Q11
What do TLOCs represent in a Cisco Catalyst SD-WAN deployment?
  1. TCP listening offsets used by vManage for management
  2. Transport locators identifying a WAN edge color, system IP, and encapsulation
  3. Encryption keys distributed by vBond
  4. Tag-based segmentation labels for VPN traffic
✓ Correct Answer: B
A TLOC (transport locator) is a tuple of system IP, color, and encapsulation (IPsec/GRE). vSmart uses TLOCs to advertise reachable transports.
Q12
Which protocol is used as the control plane for a Cisco SD-Access fabric?
  1. OSPF
  2. LISP
  3. VXLAN
  4. BGP-LS
✓ Correct Answer: B
SD-Access uses LISP as its control plane. The control-plane node holds host-to-edge mappings (EID-to-RLOC) and edge nodes query the map server.
Q13
Which encapsulation does the SD-Access data plane use to carry user traffic across the fabric?
  1. GRE
  2. MPLS
  3. VXLAN with a Group Policy Object header
  4. IPsec ESP
✓ Correct Answer: C
SD-Access uses VXLAN with a Group Policy Object (Cisco TrustSec SGT) in the VXLAN-GPO header. The VNI maps a virtual network.
Q14
Which device type in an SD-Access fabric is the policy enforcement point for endpoints?
  1. Border node
  2. Control plane node
  3. Edge node
  4. Intermediate node
✓ Correct Answer: C
Edge nodes are access switches where endpoints connect. They encapsulate traffic into VXLAN, register hosts with the control plane, and apply SGT-based policy.
Q15
Which design choice allows a traditional non-fabric campus to interoperate with an SD-Access fabric?
  1. Configure VTP transparent on all switches
  2. Deploy a fabric border node integrating via Layer 2 or Layer 3 handoff
  3. Disable LISP on the edge nodes
  4. Set the campus core to vlan dot1q tag native
✓ Correct Answer: B
Cisco supports Layer 2 and Layer 3 handoff at the fabric border. The border node bridges or routes between SD-Access fabric and the traditional network.
Q16
In a typical enterprise QoS design, which DSCP value is recommended for voice (VoIP bearer) traffic?
  1. EF (DSCP 46)
  2. AF11 (DSCP 10)
  3. CS6 (DSCP 48)
  4. AF41 (DSCP 34)
✓ Correct Answer: A
Voice bearer traffic is marked Expedited Forwarding (EF / DSCP 46) and serviced from a strict-priority low-latency queue.
Q17
What is a benefit of on-premises infrastructure versus cloud infrastructure?
  1. ability to quickly increase compute power without additional hardware
  2. less power and cooling resources needed
  3. faster deployment times
  4. lower latency between systems physically located near each other
✓ Correct Answer: D
On-premises provides lower latency for co-located systems. Cloud offers elasticity and rapid provisioning.
Q18
In the Cisco Enterprise Architecture, which layer aggregates traffic from access layer switches?
  1. Core layer
  2. Distribution layer
  3. Access layer
  4. Data Center layer
✓ Correct Answer: B
The distribution layer aggregates traffic from access switches, providing policy-based connectivity and serving as the Layer 2/Layer 3 boundary.
Q19
What is the primary advantage of SD-WAN over traditional WAN technologies?
  1. Lower cost and increased bandwidth utilization through multiple transport options
  2. Guaranteed zero packet loss
  3. Built-in encryption that cannot be disabled
  4. Elimination of routing protocols
✓ Correct Answer: A
SD-WAN reduces costs by using multiple transports (broadband, LTE, MPLS) simultaneously, intelligently routing traffic based on application requirements.
Q20
What is the primary function of Cisco DNA Center?
  1. Replaces physical switches
  2. Provides centralized network management, automation, and assurance
  3. Functions only as a WLC
  4. Only monitors traffic for security threats
✓ Correct Answer: B
Cisco DNA Center provides network design, provisioning, policy management, and assurance. It enables intent-based networking.
Q21
Which design principle places services like load balancers and firewalls close to their applications?
  1. Hierarchical design
  2. Collapsed core design
  3. Service-centric design
  4. End-to-end design
✓ Correct Answer: C
Service-centric design places network services close to applications, reducing latency and enabling more granular policy enforcement.
Q22
What is the main difference between traditional campus and SD-Access fabric?
  1. SD-Access eliminates physical switches
  2. SD-Access separates control and data planes using LISP and VXLAN
  3. SD-Access only supports wireless
  4. Traditional provides better security
✓ Correct Answer: B
SD-Access separates the control plane (LISP) from the data plane (VXLAN), enabling network virtualization, micro-segmentation, and seamless mobility.

You've viewed 3 of 218 questions. Start the free practice exam to answer all questions with instant feedback.

What Our Customers Say 122 verified reviews

5.0 ★★★★★ Based on 122 reviews
★★★★★★
Amazing resource for 350-401! The unlimited practice attempts and detailed tracking helped me focus my study time effectively.
— Thomas B.
★★★★★★
I studied for 350-401 with this bank and passed comfortably. The questions are well-organized and the UI is clean.
— Lauren C.
★★★★★★
The review mode for 350-401 is awesome. Being able to see all questions and explanations at once really helps with last-minute cramming.
— Ezra J.
★★★★★★
My boss asked me to get the 350-401 cert for work. This was the best study tool I found. Passed in three weeks.
— Austin P.
★★★★★★
Passed the 350-401 certification exam after studying this material for three weekends. Very efficient way to prepare.
— Xavier H.
★★★★★★
Lifetime access was the selling point for me. Got sidetracked for a few months and came back — everything was still there for 350-401.
— Layla S.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

The Cisco 350-401 ENCOR: Implementing Cisco Enterprise Network Core Technologies v1.2 certification validates expertise across multiple domains. Our question bank contains 218 high-quality questions with detailed explanations.

The 350-401 practice question bank contains 218 high-quality questions covering all official exam domains.

Yes. Our question bank is compiled as of June 19, 2026 and is regularly reviewed.

We recommend combining our practice question bank with official documentation and hands-on practice.

The 350-401 ENCOR: Implementing Cisco Enterprise Network Core Technologies v1.2 certification is designed for professionals who work with Cisco technologies and want to validate their skills.

Free Study Resources

Community-verified analysis of 100 topics from real test-taker discussions — 45 deep analyses and 20 FAQs.