CCNA 2026 Practice Exam Questions and Answers – Part 13/14

Practice for the CCNA exam with 23 exam-style practice questions, instant answer reveals, and concise explanations of every correct answer. Topics include: What is used to identify spurious DHCP servers?. Follow @CertPunch and visit certpunch.com for more certification practice exams and study content.

Prefer hands-on? Take this round as an interactive practice test — answer every question, get instant feedback, and see your score: Start the CCNA 2026 practice test →

What you will practice

  • What is used to identify spurious DHCP servers?
  • What is a function of a northbound API in an SDN environment?
  • What is a characteristic of cloud-based network topology?
  • A company has decided to require multifactor authentication for all systems. Which set of parameters meets th…
  • In a CDP environment, what happens when the adjacent device interface connected to the local device does not…
  • What differentiates the Cisco OfficeExtend AP mode from the Cisco FlexConnect AP mode?

Answers and explanations

Tap a question to expand the answer and the exam reasoning. Try to commit to your own pick first.

Q1. What is used to identify spurious DHCP servers?

Answer: C. C. DHCPOFFER

A Dynamic Host Configuration Protocol Offer is sent by a server in response to a client's Discover message. If multiple Offer messages are received from different sources, it indicates the presence of a spurious rogue server on the network.

Q2. What is a function of a northbound API in an SDN environment?

Answer: D. D. It provides orchestration and network automation services.

A northbound Application Programming Interface provides the interface between the Software Defined Networking controller and higher-level applications. This interface enables programmability by exposing controller capabilities to external orchestration and automation services.

Q3. What is a characteristic of cloud-based network topology?

Answer: D. D. services are provided by a public, private, or hybrid deployment

Cloud-based network topologies deliver services through public, private, or hybrid cloud deployments. The other options describe on-premises physical hardware or specific access methods rather than true cloud deployment models.

Q4. A company has decided to require multifactor authentication for all systems. Which set of parameters meets the requirement?

Answer: A. A. personal 10-digit PIN and RSA certificate

Multifactor authentication requires combining two different factor categories, such as something you know and something you have. A personal identification number and a digital RSA certificate perfectly satisfy this requirement.

Q5. In a CDP environment, what happens when the adjacent device interface connected to the local device does not have an IP address configured?

Answer: B. B. CDP can still operate and may advertise another IP address configured on the neighboring device

Cisco Discovery Protocol operates at Layer 2 and does not require an IP address on the connected interface to function. If the neighboring device has another Layer 3 address configured elsewhere, the protocol can still advertise it.

Q6. What differentiates the Cisco OfficeExtend AP mode from the Cisco FlexConnect AP mode?

Answer: A. A. OfficeExtend allows a personal SSID to be configured on the AP, and FlexConnect does not provide this capability

OfficeExtend mode supports a personal SSID for teleworkers to separate home and corporate traffic. FlexConnect is designed for branch offices to locally switch traffic, but it does not provide this personal SSID capability.

Q7. What is a function of spine-and-leaf architecture?

Answer: A. A. offers predictable latency of the traffic path between end devices

Spine-and-leaf architecture provides predictable latency between endpoints because every leaf connects to every spine. This consistent hop count eliminates the variable latency found in traditional three-tier designs.

Q8. Which function is performed by DHCP snooping?

Answer: B. B. filters and rate-limits DHCP messages on untrusted ports

DHCP snooping filters DHCP messages and applies rate limits on untrusted ports to prevent rogue servers and starvation attacks. The other options describe unrelated functions like VLAN propagation or packet forwarding.

Q9. An administrator must use the password complexity not manufacturer-name command to prevent users from adding Cisco as a password. Which command must be issued before this command?

Answer: C. C. password complexity enable

The password complexity enable command must be issued first to activate password enforcement rules on a Cisco device. Only after this global feature is enabled can you configure specific restrictions like blocking manufacturer names.

Q10. Which device feature limits the number of MAC addresses learned on a switch port?

Answer: A. A. Port security

Port security is the feature used to restrict exactly how many MAC addresses can be dynamically learned or statically configured on a switch port. BPDU Guard and Dynamic ARP Inspection mitigate different threats but do not limit MAC address learning.

Q11. What does an SDN controller use as a communication protocol to relay forwarding changes to a southbound API?

Answer: C. C. OpenFlow

OpenFlow is the primary southbound protocol used by a software-defined networking controller to communicate directly with underlying infrastructure. While REST APIs are heavily used for northbound communication, OpenFlow specifically handles programming the data plane.

Q12. What criteria is used first during the root port selection process? A. local port ID B. lowest path cost to the root bridge C. lowest neighbor's bridge ID D. lowest neighbor's port ID

Answer: B. B. lowest path cost to the toot bridge

During root port selection, every non-root switch first looks for the path with the lowest total cost to the root bridge. Tiebreakers like the neighbor bridge ID are only evaluated when multiple paths share the exact same cumulative cost.

Q13. Which command implies the use of SNMPv3?

Answer: A. A. snmp-server user

The correct answer proves that SNMP version three relies on the User-based Security Model. The other commands are generic to older versions or merely enable notifications, whereas defining a specific user implies authentication and encryption.

Q14. What is the authoritative source for an address lookup?

Answer: A. A. an authoritative DNS server

The authoritative DNS server is the definitive source that holds the actual records for a specific domain. Local caches might provide previously resolved answers, but the authoritative server gives the final and trusted response.

Q15. What is the advantage of separating the control plane from the data plane within an SDN network?

Answer: C. C. decreases overall network complexity

Centralizing the control plane in software-defined networking decreases overall network complexity by allowing centralized management and consistent policy enforcement. Offloading virtual machines is a server concept, and cost reduction is a secondary benefit.

Q16. Which switch technology establishes a network connection immediately when it is plugged in?

Answer: A. A. PortFast

PortFast allows an access port to bypass the listening and learning states, transitioning immediately to forwarding. BackboneFast and UplinkFast handle indirect and direct link failures, not initial device connections.

Q17. Which factor must be considered during the implementation of an IPsec VPN?

Answer: A. A. In IPsec tunnel mode, the entire original IP datagram is encrypted.

In IPsec tunnel mode, the entire original IP packet is encapsulated and encrypted. Transport mode only encrypts the payload, making the other options incorrect for site-to-site VPN design.

Q18. Which interface enables communication between a program on the controller and a program on the networking device?

Answer: D. D. southbound interface

The southbound interface enables communication between the SDN controller and network devices to program forwarding behavior. Northbound interfaces connect the controller to upper-level applications and management programs.

Q19. Which value is used to determine the active router in an HSRP default configuration?

Answer: B. B. Router IP address

HSRP default elections are decided by the highest IP address because all routers share the default priority of one hundred. If priorities are manually changed, the highest priority wins.

Q20. An engineering team asks an implementer to configure syslog to ensure that notification messages and all higher-severity messages are sent to the syslog server. Which command should be configured?

Answer: A. A. logging trap 5

Syslog severity level five includes notification messages and all higher-severity levels down to zero. The logging trap command sets this threshold, ensuring warnings, errors, and emergencies are forwarded to the server.

Q21. What is a reason why a company would choose to use network automation in an enterprise?

Answer: A. A. Provide data services faster.

Network automation deploys configurations and provisions services faster by reducing manual intervention and repetitive tasks. While other options provide technical features, accelerating service delivery is the primary business driver for adopting automation.

Q22. How do TCP and UDP fit into a query-response model?

Answer: B. B. TCP establishes a connection prior to sending data, and UDP sends immediately

Transmission Control Protocol establishes a session using a three-way handshake before sending data, whereas User Datagram Protocol sends data immediately without a connection. This connection state difference distinguishes reliable from best-effort delivery.

More CCNA 2026 drills and other practice exams are on @CertPunch. New rounds drop every few days at certpunch.com.

Scroll to Top