About the Exam

Cisco’s 300-410 ENARSI exam covers implementation and troubleshooting of advanced enterprise routing technologies and services, including Layer 3 routing, VPN services, infrastructure security, infrastructure services, and automation. It is intended for CCNP Enterprise candidates and network professionals working with enterprise routing and services. Passing demonstrates readiness for the Cisco Certified Specialist - Enterprise Advanced Infrastructure Implementation certification and contributes toward the CCNP Enterprise certification path.

Exam Topics

  • Layer 3 Technologies35%
  • VPN Technologies20%
  • Infrastructure Security20%
  • Infrastructure Services25%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 9, 2026 at 1:05 AM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

VPN Technologies

Question Image

Refer to the exhibit. The network administrator has configured VRF Lite for customer A. The technician at the remote site incorrectly configured VRF on the router.

Which configuration resolves connectivity for customer_a at both sites?

Explanation

Both sites must use route target 1:1 for importing and exporting customer_a routes so each VRF accepts the other site's routes. The remote VRF needs a distinct route distinguisher, 1:2, to keep VPN route identities unique; route-target both 1:1 supplies the required symmetric import and export policy. Cisco documents rd as the VRF route distinguisher and route-target both as configuring both import and export route-target communities.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Infrastructure Services

Refer to the exhibit. ISP 1 and ISP 2 are directly connected to the Internet. A customer is monitoring both ISP links to provide redundancy but cannot view the Cisco IOS IP SLA tracking output on the router console.

Which command is absent from the IP SLA configuration?

Question Image

Explanation

Cisco IOS IP SLA operations remain in the pending state and collect no data until they are scheduled. The ip sla schedule command accepts start-time now to start an operation immediately, allowing tracking output to be generated.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Infrastructure Security

Question Image

Refer to the exhibit. A network administrator successfully logs in to a switch through SSH from a RADIUS server. When the administrator accesses the switch through the console port, the RADIUS server returns shell:priv-lvl=15, but the switch prompts for the enable command. When entered, the command is rejected.

Which command set is used to troubleshoot and resolve this issue?

Explanation

Cisco IOS disables AAA authorization on the console by default, so the RADIUS shell:priv-lvl=15 attribute does not apply to console sessions. Enabling aaa authorization console followed by authorization exec on the line con 0 allows the console to leverage RADIUS authorization. Option D includes both commands, enabling the console to respect the RADIUS privilege level.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Layer 3 Technologies

What are the two benefits of using BFD?

Choose two
Explanation

BFD's two core benefits are subsecond (typically sub-50ms) failure detection between adjacent forwarding devices and the ability to detect forwarding-path failures directly, independent of and much faster than routing-protocol hello/dead timers. It is not universally supported by every routing protocol and has no relationship to UDLD.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Layer 3 Technologies

Which protocol must use MD-5 authentication across the MPLS cloud to stop hackers from adding bogus routers?

Explanation

Label Distribution Protocol (LDP) forms label-distribution peer sessions in an MPLS network. MD5 authentication verifies the integrity and origin of LDP peer communications, and a session cannot be established unless both peers use the matching authentication configuration. This prevents unauthorized routers from participating in LDP.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home