Cisco 350-401 Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) Online Training
Cisco 350-401 Online Training
The questions for 350-401 were last updated at Nov 03,2025.
- Exam Code: 350-401
- Exam Name: Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR)
- Certification Provider: Cisco
- Latest update: Nov 03,2025
DRAG DROP
Drag and drop the LISP components from the left onto the function they perform on the right. Not all options are used.

An engineer has deployed a single Cisco 5520 WLC with a management IP address of 172.16.50.5/24. The engineer must register 50 new Cisco AIR-CAP2802I-E-K9 access points to the WLC using DHCP option 43. The access points are connected to a switch in VLAN 100 that uses the 172.16.100.0/24 subnet.
The engineer has configured the DHCP scope on the switch as follows:
![]()
The access points are failing to join the wireless LAN controller.
Which action resolves the issue?
- A . configure option 43 Hex F104.AC10.3205
- B . configure option 43 Hex F104.CA10.3205
- C . configure dns-server 172.16.50.5
- D . configure dns-server 172.16.100.1
Refer to the exhibit.

A network engineer must simplify the IPsec configuration by enabling IPsec over GRE using IPsec profiles.
Which two configuration changes accomplish this? (Choose two).
- A . Create an IPsec profile, associate the transform-set ACL, and apply the profile to the tunnel interface.
- B . Apply the crypto map to the tunnel interface and change the tunnel mode to tunnel mode ipsec ipv4.
- C . Remove all configuration related to crypto map from R1 and R2 and eliminate the ACL.
- D . Create an IPsec profile, associate the transform-set, and apply the profile to the tunnel interface.
- E . Remove the crypto map and modify the ACL to allow traffic between 10.10.0.0/24 to 10.20.0.0/24.
Refer to the exhibit.

Which action resolves the EtherChannel issue between SW2 and SW3?
- A . Configure switchport mode trunk on SW2.
- B . Configure switchport nonegotiate on SW3
- C . Configure channel-group 1 mode desirable on both interfaces.
- D . Configure channel-group 1 mode active on both interfaces.
Refer to the exhibit.

Router 1 is currently operating as the HSRP primary with a priority of 110 router1 fails and router2 take over the forwarding role.
Which command on router1 causes it to take over the forwarding role when it return to service?
- A . standby 2 priority
- B . standby 2 preempt
- C . standby 2 track
- D . standby 2 timers
Which component of the Cisco Cyber Threat Defense solution provides user and flow context analysis?
- A . Cisco Firepower and FireSIGHT
- B . Cisco Stealth watch system
- C . Advanced Malware Protection
- D . Cisco Web Security Appliance
Refer to the Exhibit.

An engineer configures CoPP and enters the show command to verify the implementation.
What is the result of the configuration?
- A . All traffic will be policed based on access-list 120.
- B . If traffic exceeds the specified rate, it will be transmitted and remarked.
- C . Class-default traffic will be dropped.
- D . ICMP will be denied based on this configuration.
Refer to the exhibit.

What is the result when a switch that is running PVST+ is added to this network?
- A . DSW2 operates in Rapid PVST+ and the new switch operates in PVST+
- B . Both switches operate in the PVST+ mode
- C . Spanning tree is disabled automatically on the network
- D . Both switches operate in the Rapid PVST+ mode.
Refer to the exhibit.

PC-1 must access the web server on port 8080.
To allow this traffic, which statement must be added to an access control list that is applied on SW2 port G0/0 in the inbound direction?
- A . permit host 172.16.0.2 host 192.168.0.5 eq 8080
- B . permit host 192.168.0.5 host 172.16.0.2 eq 8080
- C . permit host 192.168.0.5 eq 8080 host 172.16.0.2
- D . permit host 192.168.0.5 it 8080 host 172.16.0.2
DRAG DROP
Drag and drop the REST API authentication methods from the left onto their descriptions on the right.


Question 91 has a wrong answer marked s correct. The answer is B.
BPDU filter is the only option to block BPDUs while not going inte err disabled when a BPDU is received.
https://www.exam4training.com/which-command-set-must-be-configured-on-switch1-to-achieve-the-following-results-on-port-fa0-1/
https://www.cisco.com/en/US/docs/switches/metro/me3600x_3800x/trash/swstpopt.html#:~:text=The%20BPDU%20filtering%20feature%20can,bpdufilter%20default%20global%20configuration%20command.