Topic 11 Practice Test 1 covers NTP/PTP, NAT/PAT, HSRP, and VRRP for Cisco 350-401 ENCOR. For broader exam preparation, review the Cisco 350-401 ENCOR Exam Dumps. Every option includes focused technical reasoning explaining both the Cisco enterprise networking concept and its fit to the scenario.
Question 1
A change request will be accepted only if it can synchronize a branch router to the approved 10.10.10.20 time server using ordinary NTP. Which mechanism is the most appropriate? Choose ONE.
- NTP authentication
- static inside source NAT
- NTP client association
- show ip nat translations
Correct Answer(s)
C
Rationale
- NTP authentication lacks the needed control effect; it provides authenticated time synchronization for NTP security situations. Here the team must synchronize a branch router to the approved 10.10.10.20 time server using ordinary NTP, which NTP client association enables directly.
- Static inside source NAT controls a fixed private-to-public address mapping and is useful for NAT work. This case requires the team to synchronize a branch router to the approved 10.10.10.20 time server using ordinary NTP. Because NTP client association supplies that behavior, this option acts on the wrong requirement.
- NTP client association provides time synchronization from a designated NTP source. That matches the requirement to synchronize a branch router to the approved 10.10.10.20 time server using ordinary NTP. It directly controls the relevant NTP behavior, so the alternatives would change a different condition. This makes NTP client association the direct fit for this case.
- Show ip nat translations targets direct inspection of active NAT mappings, so it fits another NAT verification condition. The question requires the team to synchronize a branch router to the approved 10.10.10.20 time server using ordinary NTP. Since NTP client association produces the needed behavior, this choice would not fix the root requirement.
Question 2
During a maintenance window, the team must accept time only from an NTP source that proves knowledge of the configured trusted key. Which option is the best fit for this exact constraint? Choose ONE.
- NTP preferred server
- dynamic NAT pool
- NTP authentication
- HSRP virtual IP
Correct Answer(s)
C
Rationale
- NTP preferred server is plausible because it delivers deterministic preference among valid NTP sources for NTP selection cases. Here the team must accept time only from an NTP source that proves knowledge of the configured trusted key. NTP authentication directly controls that state, while this option does not.
- Dynamic NAT pool does not match the evidence because it provides temporary one-to-one mappings from a public pool. That is a NAT function, whereas the stem requires engineers to accept time only from an NTP source that proves knowledge of the configured trusted key. NTP authentication is the option tied to that task.
- The best answer is NTP authentication, which supplies authenticated time synchronization. Because the requirement is to accept time only from an NTP source that proves knowledge of the configured trusted key, this option matches the NTP security decision and leaves adjacent functions untouched. This makes NTP authentication the direct fit for this case.
- HSRP virtual IP has a different role: it supplies a resilient shared default gateway in HSRP scenarios. The engineer must accept time only from an NTP source that proves knowledge of the configured trusted key here. That makes NTP authentication the direct answer and this option unsuitable.
Question 3
A troubleshooting ticket states that engineers must favor the primary NTP source whenever both the primary and backup sources are healthy and valid. Which action addresses the root requirement most directly? Choose ONE.
- NTP preferred server
- PAT overload
- NTP source interface
- HSRP priority
Correct Answer(s)
A
Rationale
- NTP preferred server matches the desired state by providing deterministic preference among valid NTP sources. Since engineers must favor the primary NTP source whenever both the primary and backup sources are healthy and valid, this selection acts on the relevant NTP selection behavior and directly satisfies the requirement. This makes NTP preferred server the direct fit for this case.
- PAT overload would be useful when many-to-one address conservation for outbound sessions is needed for PAT work. This question instead asks the team to favor the primary NTP source whenever both the primary and backup sources are healthy and valid. The correct control is NTP preferred server, so this alternative fails scenario fit.
- NTP source interface would affect stable NTP packet sourcing, a legitimate NTP reachability purpose. The stem instead depends on engineers being able to favor the primary NTP source whenever both the primary and backup sources are healthy and valid. NTP preferred server provides that exact behavior, leaving this option operationally wrong.
- HSRP priority lacks the needed control effect; it provides intentional HSRP active-router preference for HSRP election situations. Here the team must favor the primary NTP source whenever both the primary and backup sources are healthy and valid, which NTP preferred server enables directly.
Question 4
While comparing the running configuration with the intended state, the team needs to make NTP requests consistently originate from Loopback0 so upstream ACLs match one stable source address. Which choice is correct? Choose ONE.
- PTP grandmaster clock
- NTP source interface
- HSRP preempt
- NAT inside interface role
Correct Answer(s)
B
Rationale
- PTP grandmaster clock is not selected because it governs an authoritative precision-time origin. That function belongs to PTP work. The required task is to make NTP requests consistently originate from Loopback0 so upstream ACLs match one stable source address, and that task is handled by NTP source interface.
- Choose NTP source interface. It creates stable NTP packet sourcing, while the stem requires engineers to make NTP requests consistently originate from Loopback0 so upstream ACLs match one stable source address. This directly satisfies the NTP reachability condition and avoids changing a feature that is not implicated. This makes NTP source interface the direct fit for this case.
- HSRP preempt is plausible because it delivers restoration of the preferred HSRP active router for HSRP election cases. Here the team must make NTP requests consistently originate from Loopback0 so upstream ACLs match one stable source address. NTP source interface directly controls that state, while this option does not.
- NAT inside interface role would be an unnecessary change because it controls correct identification of the private-side NAT boundary. That is relevant to NAT direction requirements, while the current task is to make NTP requests consistently originate from Loopback0 so upstream ACLs match one stable source address using NTP source interface.
Question 5
A change request will be accepted only if it can provide the authoritative precision-time source for a new PTP timing domain. Which mechanism is the most appropriate? Choose ONE.
- PTP boundary clock
- HSRP object tracking
- NAT outside interface role
- PTP grandmaster clock
Correct Answer(s)
D
Rationale
- PTP boundary clock provides segmented PTP timing distribution, which belongs to PTP decisions. The stem instead requires engineers to provide the authoritative precision-time source for a new PTP timing domain. That result comes from PTP grandmaster clock; selecting PTP boundary clock would leave the tested condition unresolved.
- HSRP object tracking would affect gateway failover based on upstream health, a legitimate HSRP tracking purpose. The stem instead depends on engineers being able to provide the authoritative precision-time source for a new PTP timing domain. PTP grandmaster clock provides that exact behavior, leaving this option operationally wrong.
- NAT outside interface role solves a different problem by providing correct identification of the public-side NAT boundary. That matters for NAT direction decisions, but this case requires engineers to provide the authoritative precision-time source for a new PTP timing domain. PTP grandmaster clock matches the evidence more precisely.
- PTP grandmaster clock fits because it delivers an authoritative precision-time origin. The scenario specifically asks engineers to provide the authoritative precision-time source for a new PTP timing domain. This is the PTP control that changes the tested behavior directly. This makes PTP grandmaster clock the direct fit for this case.
Question 6
During a maintenance window, the team must redistribute precise PTP time across a network boundary while terminating one timing relationship and serving another. Which option is the best fit for this exact constraint? Choose ONE.
- PTP boundary clock
- PTP transparent clock
- VRRP priority and preemption
- NAT match ACL
Correct Answer(s)
A
Rationale
- For this case, PTP boundary clock supplies segmented PTP timing distribution. The operational need is to redistribute precise PTP time across a network boundary while terminating one timing relationship and serving another. That correspondence makes it the correct PTP mechanism for the scenario. This makes PTP boundary clock the direct fit for this case.
- PTP transparent clock is technically useful for forwarding-delay compensation for PTP in PTP work. The tested task is to redistribute precise PTP time across a network boundary while terminating one timing relationship and serving another, however. That behavior is governed by PTP boundary clock, making this option a distractor.
- VRRP priority and preemption is not selected because it governs preferred VRRP primary selection. That function belongs to VRRP election work. The required task is to redistribute precise PTP time across a network boundary while terminating one timing relationship and serving another, and that task is handled by PTP boundary clock.
- NAT match ACL misses the controlling requirement because its result is correct selection of addresses that should be translated. That fits NAT policy tasks. Here, the network needs engineers to redistribute precise PTP time across a network boundary while terminating one timing relationship and serving another, so PTP boundary clock is the relevant mechanism.
Question 7
A troubleshooting ticket states that engineers must compensate for residence time added by an intermediate switch to PTP event messages. Which action addresses the root requirement most directly? Choose ONE.
- static inside source NAT
- show ip nat translations
- PTP transparent clock
- VRRP object tracking
Correct Answer(s)
C
Rationale
- Static inside source NAT is not an equivalent substitute because it creates a fixed private-to-public address mapping. That serves NAT needs, not the requirement to compensate for residence time added by an intermediate switch to PTP event messages. PTP transparent clock acts on the condition described in the stem.
- Show ip nat translations solves the wrong problem by producing direct inspection of active NAT mappings. It fits NAT verification needs, but the tested task is to compensate for residence time added by an intermediate switch to PTP event messages. That requirement maps directly to PTP transparent clock.
- PTP transparent clock is the functional match: it provides forwarding-delay compensation for PTP. The question requires the network to compensate for residence time added by an intermediate switch to PTP event messages. That makes this the relevant PTP choice for the stated evidence. This makes PTP transparent clock the direct fit for this case.
- VRRP object tracking provides VRRP failover tied to path health, which belongs to VRRP tracking decisions. The stem instead requires engineers to compensate for residence time added by an intermediate switch to PTP event messages. That result comes from PTP transparent clock; selecting VRRP object tracking would leave the tested condition unresolved.
Question 8
While comparing the running configuration with the intended state, the team needs to publish an internal application server through the same public IPv4 address at all times. Which choice is correct? Choose ONE.
- NTP client association
- static inside source NAT
- dynamic NAT pool
- HSRP virtual IP
Correct Answer(s)
B
Rationale
- NTP client association is technically useful for time synchronization from a designated NTP source in NTP work. The tested task is to publish an internal application server through the same public IPv4 address at all times, however. That behavior is governed by static inside source NAT, making this option a distractor.
- Use static inside source NAT; its operational effect is a fixed private-to-public address mapping. The stated task is to publish an internal application server through the same public IPv4 address at all times. That mechanism addresses the NAT requirement without altering an unrelated control. This makes static inside source NAT the direct fit for this case.
- Dynamic NAT pool is related but operationally wrong because it yields temporary one-to-one mappings from a public pool. That supports NAT work. This case requires engineers to publish an internal application server through the same public IPv4 address at all times, so static inside source NAT fits the stated condition.
- Do not select HSRP virtual IP; its effect is a resilient shared default gateway, a valid HSRP function. The scenario requires engineers to publish an internal application server through the same public IPv4 address at all times. That requirement maps to static inside source NAT, not to this alternative.
Question 9
A change request will be accepted only if it can let eligible inside hosts borrow one-to-one public addresses from a finite pool only while translations are needed. Which mechanism is the most appropriate? Choose ONE.
- NTP authentication
- HSRP priority
- PAT overload
- dynamic NAT pool
Correct Answer(s)
D
Rationale
- NTP authentication is not an equivalent substitute because it creates authenticated time synchronization. That serves NTP security needs, not the requirement to let eligible inside hosts borrow one-to-one public addresses from a finite pool only while translations are needed. dynamic NAT pool acts on the condition described in the stem.
- HSRP priority is a neighboring feature that yields intentional HSRP active-router preference for HSRP election needs. This scenario requires the team to let eligible inside hosts borrow one-to-one public addresses from a finite pool only while translations are needed. The required behavior belongs to dynamic NAT pool, so this alternative is mismatched.
- PAT overload would change many-to-one address conservation for outbound sessions, which is appropriate in PAT scenarios. The present stem asks engineers to let eligible inside hosts borrow one-to-one public addresses from a finite pool only while translations are needed. That is why dynamic NAT pool is the correct mechanism instead.
- Dynamic NAT pool is the precise choice because it yields temporary one-to-one mappings from a public pool. Here, the network must let eligible inside hosts borrow one-to-one public addresses from a finite pool only while translations are needed. The feature therefore resolves the tested NAT condition instead of a different issue. This makes dynamic NAT pool the direct fit for this case.
Question 10
During a maintenance window, the team must give 600 branch clients Internet access through one public interface address by differentiating sessions with ports. Which option is the best fit for this exact constraint? Choose ONE.
- NTP preferred server
- PAT overload
- HSRP preempt
- NAT inside interface role
Correct Answer(s)
B
Rationale
- NTP preferred server is related but operationally wrong because it yields deterministic preference among valid NTP sources. That supports NTP selection work. This case requires engineers to give 600 branch clients Internet access through one public interface address by differentiating sessions with ports, so PAT overload fits the stated condition.
- Use PAT overload to obtain many-to-one address conservation for outbound sessions. That is exactly what the team needs when it must give 600 branch clients Internet access through one public interface address by differentiating sessions with ports. The PAT decision is therefore resolved by this mechanism, not the alternatives. This makes PAT overload the direct fit for this case.
- HSRP preempt does not resolve the requirement; it provides restoration of the preferred HSRP active router for HSRP election decisions. Because the stem requires engineers to give 600 branch clients Internet access through one public interface address by differentiating sessions with ports, PAT overload is the mechanism that should be selected.
- NAT inside interface role should not be changed for this issue; it provides correct identification of the private-side NAT boundary for NAT direction cases. The actual requirement is to give 600 branch clients Internet access through one public interface address by differentiating sessions with ports, which is handled by PAT overload.
Question 11
A troubleshooting ticket states that engineers must mark the LAN-facing interface as the private side of an inside-source NAT design. Which action addresses the root requirement most directly? Choose ONE.
- NAT inside interface role
- NTP source interface
- HSRP object tracking
- NAT outside interface role
Correct Answer(s)
A
Rationale
- NAT inside interface role is correct because it creates correct identification of the private-side NAT boundary. In this scenario, engineers must mark the LAN-facing interface as the private side of an inside-source NAT design. The option acts on the exact NAT direction decision described in the stem. This makes NAT inside interface role the direct fit for this case.
- NTP source interface would change stable NTP packet sourcing, which is appropriate in NTP reachability scenarios. The present stem asks engineers to mark the LAN-facing interface as the private side of an inside-source NAT design. That is why NAT inside interface role is the correct mechanism instead.
- HSRP object tracking fails on scenario fit: it gives gateway failover based on upstream health for HSRP tracking decisions. The evidence says engineers must mark the LAN-facing interface as the private side of an inside-source NAT design, and NAT inside interface role is the option that provides the needed behavior.
- NAT outside interface role would leave the key condition unchanged because it supplies correct identification of the public-side NAT boundary. That is useful for NAT direction tasks, while this scenario requires the team to mark the LAN-facing interface as the private side of an inside-source NAT design using NAT inside interface role.
Question 12
While comparing the running configuration with the intended state, the team needs to mark the ISP-facing interface as the public side of an inside-source NAT design. Which choice is correct? Choose ONE.
- NAT match ACL
- PTP grandmaster clock
- NAT outside interface role
- VRRP priority and preemption
Correct Answer(s)
C
Rationale
- NAT match ACL controls correct selection of addresses that should be translated and is useful for NAT policy work. This case requires the team to mark the ISP-facing interface as the public side of an inside-source NAT design. Because NAT outside interface role supplies that behavior, this option acts on the wrong requirement.
- PTP grandmaster clock should not be changed for this issue; it provides an authoritative precision-time origin for PTP cases. The actual requirement is to mark the ISP-facing interface as the public side of an inside-source NAT design, which is handled by NAT outside interface role.
- Select NAT outside interface role for correct identification of the public-side NAT boundary. The stem makes the requirement explicit: mark the ISP-facing interface as the public side of an inside-source NAT design. That result is governed by this NAT direction mechanism rather than by the neighboring options. This makes NAT outside interface role the direct fit for this case.
- VRRP priority and preemption targets preferred VRRP primary selection, so it fits another VRRP election condition. The question requires the team to mark the ISP-facing interface as the public side of an inside-source NAT design. Since NAT outside interface role produces the needed behavior, this choice would not fix the root requirement.
Question 13
A change request will be accepted only if it can select only 10.44.0.0/16 clients for a dynamic NAT rule while excluding other inside networks. Which mechanism is the most appropriate? Choose ONE.
- PTP boundary clock
- NAT match ACL
- VRRP object tracking
- show ip nat translations
Correct Answer(s)
B
Rationale
- PTP boundary clock would leave the key condition unchanged because it supplies segmented PTP timing distribution. That is useful for PTP tasks, while this scenario requires the team to select only 10.44.0.0/16 clients for a dynamic NAT rule while excluding other inside networks using NAT match ACL.
- NAT match ACL is appropriate because the result is correct selection of addresses that should be translated. The scenario requires engineers to select only 10.44.0.0/16 clients for a dynamic NAT rule while excluding other inside networks. This feature controls that NAT policy behavior specifically, so it is the best fit. This makes NAT match ACL the direct fit for this case.
- VRRP object tracking has a different role: it supplies VRRP failover tied to path health in VRRP tracking scenarios. The engineer must select only 10.44.0.0/16 clients for a dynamic NAT rule while excluding other inside networks here. That makes NAT match ACL the direct answer and this option unsuitable.
- Show ip nat translations does not match the evidence because it provides direct inspection of active NAT mappings. That is a NAT verification function, whereas the stem requires engineers to select only 10.44.0.0/16 clients for a dynamic NAT rule while excluding other inside networks. NAT match ACL is the option tied to that task.
Question 14
During a maintenance window, the team must confirm whether host 10.44.8.9 currently has an inside-local to inside-global translation. Which option is the best fit for this exact constraint? Choose ONE.
- HSRP virtual IP
- NTP client association
- PTP transparent clock
- show ip nat translations
Correct Answer(s)
D
Rationale
- HSRP virtual IP would be useful when a resilient shared default gateway is needed for HSRP work. This question instead asks the team to confirm whether host 10.44.8.9 currently has an inside-local to inside-global translation. The correct control is show ip nat translations, so this alternative fails scenario fit.
- NTP client association lacks the needed control effect; it provides time synchronization from a designated NTP source for NTP situations. Here the team must confirm whether host 10.44.8.9 currently has an inside-local to inside-global translation, which show ip nat translations enables directly.
- PTP transparent clock controls forwarding-delay compensation for PTP and is useful for PTP work. This case requires the team to confirm whether host 10.44.8.9 currently has an inside-local to inside-global translation. Because show ip nat translations supplies that behavior, this option acts on the wrong requirement.
- Choose show ip nat translations because its result is direct inspection of active NAT mappings. The stem requires the team to confirm whether host 10.44.8.9 currently has an inside-local to inside-global translation. That is a direct NAT verification match, not merely a related feature. This makes show ip nat translations the direct fit for this case.
Question 15
A troubleshooting ticket states that engineers must present hosts with one stable default-gateway address even when the active first-hop router changes. Which action addresses the root requirement most directly? Choose ONE.
- HSRP virtual IP
- NTP authentication
- static inside source NAT
- HSRP priority
Correct Answer(s)
A
Rationale
- HSRP virtual IP directly produces a resilient shared default gateway. That is relevant because the team needs to present hosts with one stable default-gateway address even when the active first-hop router changes. For this HSRP decision, the feature changes the condition identified by the evidence. This makes HSRP virtual IP the direct fit for this case.
- NTP authentication is plausible because it delivers authenticated time synchronization for NTP security cases. Here the team must present hosts with one stable default-gateway address even when the active first-hop router changes. HSRP virtual IP directly controls that state, while this option does not.
- Static inside source NAT does not match the evidence because it provides a fixed private-to-public address mapping. That is a NAT function, whereas the stem requires engineers to present hosts with one stable default-gateway address even when the active first-hop router changes. HSRP virtual IP is the option tied to that task.
- HSRP priority would be an unnecessary change because it controls intentional HSRP active-router preference. That is relevant to HSRP election requirements, while the current task is to present hosts with one stable default-gateway address even when the active first-hop router changes using HSRP virtual IP.
Question 16
While comparing the running configuration with the intended state, the team needs to make Router-A win the HSRP active role over Router-B when both are healthy. Which choice is correct? Choose ONE.
- dynamic NAT pool
- HSRP preempt
- HSRP priority
- NTP preferred server
Correct Answer(s)
C
Rationale
- Dynamic NAT pool would be useful when temporary one-to-one mappings from a public pool is needed for NAT work. This question instead asks the team to make Router-A win the HSRP active role over Router-B when both are healthy. The correct control is HSRP priority, so this alternative fails scenario fit.
- HSRP preempt solves a different problem by providing restoration of the preferred HSRP active router. That matters for HSRP election decisions, but this case requires engineers to make Router-A win the HSRP active role over Router-B when both are healthy. HSRP priority matches the evidence more precisely.
- The required mechanism is HSRP priority, which gives intentional HSRP active-router preference. The stem calls for the team to make Router-A win the HSRP active role over Router-B when both are healthy. That makes this the direct HSRP election answer rather than an adjacent workaround. This makes HSRP priority the direct fit for this case.
- NTP preferred server would affect deterministic preference among valid NTP sources, a legitimate NTP selection purpose. The stem instead depends on engineers being able to make Router-A win the HSRP active role over Router-B when both are healthy. HSRP priority provides that exact behavior, leaving this option operationally wrong.
Question 17
A change request will be accepted only if it can allow the higher-priority HSRP router to retake active duty after it returns to service. Which mechanism is the most appropriate? Choose ONE.
- NTP source interface
- PAT overload
- HSRP object tracking
- HSRP preempt
Correct Answer(s)
D
Rationale
- NTP source interface is not selected because it governs stable NTP packet sourcing. That function belongs to NTP reachability work. The required task is to allow the higher-priority HSRP router to retake active duty after it returns to service, and that task is handled by HSRP preempt.
- PAT overload would be an unnecessary change because it controls many-to-one address conservation for outbound sessions. That is relevant to PAT requirements, while the current task is to allow the higher-priority HSRP router to retake active duty after it returns to service using HSRP preempt.
- HSRP object tracking misses the controlling requirement because its result is gateway failover based on upstream health. That fits HSRP tracking tasks. Here, the network needs engineers to allow the higher-priority HSRP router to retake active duty after it returns to service, so HSRP preempt is the relevant mechanism.
- HSRP preempt provides restoration of the preferred HSRP active router. That matches the requirement to allow the higher-priority HSRP router to retake active duty after it returns to service. It directly controls the relevant HSRP election behavior, so the alternatives would change a different condition. This makes HSRP preempt the direct fit for this case.
Question 18
During a maintenance window, the team must make HSRP yield the active role when Router-A loses its WAN uplink even though the LAN interface remains up. Which option is the best fit for this exact constraint? Choose ONE.
- NAT inside interface role
- HSRP object tracking
- VRRP priority and preemption
- PTP grandmaster clock
Correct Answer(s)
B
Rationale
- NAT inside interface role solves a different problem by providing correct identification of the private-side NAT boundary. That matters for NAT direction decisions, but this case requires engineers to make HSRP yield the active role when Router-A loses its WAN uplink even though the LAN interface remains up. HSRP object tracking matches the evidence more precisely.
- The best answer is HSRP object tracking, which supplies gateway failover based on upstream health. Because the requirement is to make HSRP yield the active role when Router-A loses its WAN uplink even though the LAN interface remains up, this option matches the HSRP tracking decision and leaves adjacent functions untouched. This makes HSRP object tracking the direct fit for this case.
- VRRP priority and preemption solves the wrong problem by producing preferred VRRP primary selection. It fits VRRP election needs, but the tested task is to make HSRP yield the active role when Router-A loses its WAN uplink even though the LAN interface remains up. That requirement maps directly to HSRP object tracking.
- PTP grandmaster clock provides an authoritative precision-time origin, which belongs to PTP decisions. The stem instead requires engineers to make HSRP yield the active role when Router-A loses its WAN uplink even though the LAN interface remains up. That result comes from HSRP object tracking; selecting PTP grandmaster clock would leave the tested condition unresolved.
Question 19
A troubleshooting ticket states that engineers must prefer one standards-based VRRP router and allow it to resume primary duty after recovery. Which action addresses the root requirement most directly? Choose ONE.
- VRRP priority and preemption
- VRRP object tracking
- PTP boundary clock
- NAT outside interface role
Correct Answer(s)
A
Rationale
- VRRP priority and preemption matches the desired state by providing preferred VRRP primary selection. Since engineers must prefer one standards-based VRRP router and allow it to resume primary duty after recovery, this selection acts on the relevant VRRP election behavior and directly satisfies the requirement. This makes VRRP priority and preemption the direct fit for this case.
- Do not select VRRP object tracking; its effect is VRRP failover tied to path health, a valid VRRP tracking function. The scenario requires engineers to prefer one standards-based VRRP router and allow it to resume primary duty after recovery. That requirement maps to VRRP priority and preemption, not to this alternative.
- PTP boundary clock is technically useful for segmented PTP timing distribution in PTP work. The tested task is to prefer one standards-based VRRP router and allow it to resume primary duty after recovery, however. That behavior is governed by VRRP priority and preemption, making this option a distractor.
- NAT outside interface role misses the controlling requirement because its result is correct identification of the public-side NAT boundary. That fits NAT direction tasks. Here, the network needs engineers to prefer one standards-based VRRP router and allow it to resume primary duty after recovery, so VRRP priority and preemption is the relevant mechanism.
Question 20
While comparing the running configuration with the intended state, the team needs to make the VRRP primary yield when a tracked upstream route becomes unreachable. Which choice is correct? Choose ONE.
- NTP client association
- NAT match ACL
- PTP transparent clock
- VRRP object tracking
Correct Answer(s)
D
Rationale
- NTP client association is a neighboring feature that yields time synchronization from a designated NTP source for NTP needs. This scenario requires the team to make the VRRP primary yield when a tracked upstream route becomes unreachable. The required behavior belongs to VRRP object tracking, so this alternative is mismatched.
- NAT match ACL solves the wrong problem by producing correct selection of addresses that should be translated. It fits NAT policy needs, but the tested task is to make the VRRP primary yield when a tracked upstream route becomes unreachable. That requirement maps directly to VRRP object tracking.
- PTP transparent clock is not an equivalent substitute because it creates forwarding-delay compensation for PTP. That serves PTP needs, not the requirement to make the VRRP primary yield when a tracked upstream route becomes unreachable. VRRP object tracking acts on the condition described in the stem.
- Choose VRRP object tracking. It creates VRRP failover tied to path health, while the stem requires engineers to make the VRRP primary yield when a tracked upstream route becomes unreachable. This directly satisfies the VRRP tracking condition and avoids changing a feature that is not implicated. This makes VRRP object tracking the direct fit for this case.