Pass Cisco 350-601 exam questions - convert Test Engine to PDF
Pass Your 350-601 Exam Easily - Real 350-601 Practice Dump Updated Jan 07, 2025
NEW QUESTION # 246
A network engineer must restore the running configuration on a Cisco Nexus 5000 Series Switch to an existing snapshot called "stable1". The restore procedure should proceed only if no errors occur. Which configuration should be used to accomplish this goal?
- A. Option B
- B. Option D
- C. Option C
- D. Option A
Answer: B
NEW QUESTION # 247
An engineer must configure the HSRP protocol to implement redundancy using two Cisco Nexus Series Switches In addition, the HSRP must meet these requirements Switch1 must retain the primary role if switch2 goes offline Switch1 must retain the primary role until normal conditions are restored.
Switch1 and switch2 must ensure that the routing tables are converged before taking the active role switch2 must retain the primary role if the default gateway is not reachable Drag and drop the configuration commands from the right to the left to meet the requirements. The commands are used more than once Not all commands are used
Answer:
Explanation:
NEW QUESTION # 248
Refer to the exhibit.
Which type of backup is required to restore a Cisco UCS configuration?
- A. full state
- B. all configuration
- C. system configuration
- D. logical configuration
Answer: A
NEW QUESTION # 249
An engineer is implementing Cisco Intersight in a secure environment. The environment must use LDAP directory service and ensure information integrity and confidentiality. Which two steps must be taken to implement the solution? (Choose two.)
- A. Add a trusted OAuth token to Cisco Intersight
- B. Enable Encryption for LDAP
- C. Add a self-signed LDAP certificate to Cisco Intersight.
- D. Add a trusted root LDAP certificate to Cisco Intersight
- E. Enable Certificate Signing Request in Cisco Intersight.
Answer: B,D
Explanation:
https://www.cisco.com/c/en/us/td/docs/unified_computing/Intersight/
b_Cisco_Intersight_Appliance_Getting_Started_Guide/
b_Cisco_Intersight_Appliance_Install_and_Upgrade_Guide_chapter_0110.html
NEW QUESTION # 250
Refer to the exhibit. A network engineer requires remote access via SSH to a Cisco MDS 9000 Series Switch. The solution must support secure access using the local user database when the RADIUS servers are unreachable from the switches. Which command meets these requirements?
- A. aaa authentication login default group local
- B. aaa authentication login default fallback error local
- C. aaa authentication login default group radius
- D. aaa authentication none
Answer: B
Explanation:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/sw/6- x/security/configuration/guide/b_Cisco_Nexus_9000_Series_NX- OS_Security_Configuration_Guide/b_Cisco_Nexus_9000_Series_NX- OS_Security_Configuration_Guide_chapter_0111.html
NEW QUESTION # 251
An engineer must configure multiple EPGs on a single access port in a large Cisco ACI fabric without using VMM integration. The relevant access policies and tenant policies have been created. A single AAEP is used to configure the access port in the fabric. Which two additional steps must be taken to complete the configuration? (Choose two.)
- A. The EPGs must be linked to the correct physical domain
- B. The corresponding bridge domains must be configured in legacy mode
- C. The EPGs must link directly to the corresponding AAEP
- D. A contract must be defined between the EPGs
- E. The EPGs must be configured as static ports
Answer: A,E
Explanation:
To configure multiple EPGs on a single access port in a large Cisco ACI fabric without using VMM integration, the EPGs must be linked to the correct physical domain (Option B) and configured as static ports (Option E). The physical domain is associated with VLAN namespaces and determines the VLAN encapsulation at the interface level. The static ports are used to manually assign the EPGs to the access port.
The other options are not required for this configuration. A contract is used to define the communication policy between EPGs, but it is not necessary to create one for this scenario. The EPGs do not link directly to the AAEP, but rather to the interface policy group that is associated with the AAEP. The bridge domains do not need to be configured in legacy mode, which is a mode that allows communication with non-ACI networks. References:
* Cisco Application Centric Infrastructure Fundamentals, Release 4.x - Endpoint Groups (EPGs) [Cisco Application Centric Infrastructure], Endpoint Groups (EPGs), Physical Domain
* Cisco Application Centric Infrastructure Fundamentals, Release 4.x - Endpoint Groups (EPGs) [Cisco Application Centric Infrastructure], Endpoint Groups (EPGs), Static Ports
* Cisco Application Centric Infrastructure Fundamentals, Release 4.x - Endpoint Groups (EPGs) [Cisco Application Centric Infrastructure], Endpoint Groups (EPGs), Contracts
* Cisco Application Centric Infrastructure Fundamentals, Release 4.x - Endpoint Groups (EPGs) [Cisco Application Centric Infrastructure], Endpoint Groups (EPGs), Attachable Access Entity Profile
* Cisco Application Centric Infrastructure Fundamentals, Release 4.x - Bridge Domains [Cisco Application Centric Infrastructure], Bridge Domains, Legacy Mode
NEW QUESTION # 252
Which two authentication types does Cisco UCS Manager support when configuration authentication?
(Choose two.)
- A. PAM
- B. local
- C. LDAP
- D. Kerberos
- E. 802.1X
Answer: B,C
Explanation:
Cisco UCS Manager supports various types of authentication mechanisms for enhanced security. Option A (local) refers to the use of locally stored user credentials within the UCS Manager for authentication. Option B (LDAP) indicates that UCS Manager can integrate with LDAP (Lightweight Directory Access Protocol) directories for user authentication, allowing centralized management of user credentials. References: Cisco Data Center Core Technologies source documents or study guide
NEW QUESTION # 253 
Refer to the exhibit. An engineer must schedule the firmware upgrade of the Red1 and Red2 leaf switches. The requirement is to keep the upgrade time to the minimum, avoid any service impact, and perform the parallel upgrade Which set of scheduler attributes must be used to meet these requirements?
- A. Option B
- B. Option D
- C. Option C
- D. Option A
Answer: A
Explanation:
To schedule the firmware upgrade of the Red1 and Red2 leaf switches with the requirements of minimal upgrade time, no service impact, and parallel upgrade, SchedulerPolicy1 and SchedulerPolicy2 with a one-time window trigger that has maximum concurrent nodes 2 should be used. This allows both Red1 and Red2 to upgrade simultaneously within the same maintenance window, thus minimizing the time and avoiding any service disruption.
References := Further details can be found in the Cisco Data Center Core Technologies documentation
NEW QUESTION # 254
Which adjacency server configuration makes two OTV edge devices located in the same site bring up the dual-site adjacency?
- A.

- B.

- C.

- D.
Answer: B
Explanation:
Option C is the correct adjacency server configuration to make two OTV edge devices located in the same site bring up the dual-site adjacency. The adjacency server is a logical entity that maintains the control plane information for the OTV overlay network. The adjacency server can be configured in unicast-only mode, which means that the OTV edge devices use unicast packets to exchange control plane information. To enable dual-site adjacency, which means that the OTV edge devices can form adjacencies with devices in the same site as well as devices in different sites, the adjacency server must be configured with the same IP address on both devices in the same site. The other options have incorrect configurations or IP addresses. For example, option A uses different IP addresses for the adjacency server on the same site, option B uses the same IP address for the adjacency server on different sites, and option D uses an invalid IP address for the adjacency server. References:
* Cisco Nexus 7000 Series NX-OS OTV Configuration Guide, Release 6.x - Configuring Basic OTV
[Cisco Nexus 7000 Series Switches], Configuring Basic OTV, Configuring the OTV Adjacency Server
* Cisco Nexus 7000 Series NX-OS OTV Configuration Guide, Release 6.x - Configuring Basic OTV
[Cisco Nexus 7000 Series Switches], Configuring Basic OTV, Configuring Dual-Site Adjacency
* Cisco Nexus 7000 Series NX-OS OTV Configuration Guide, Release 6.x - Configuring Basic OTV
[Cisco Nexus 7000 Series Switches], Configuring Basic OTV, Configuring the OTV Adjacency Server IP Address
NEW QUESTION # 255
An engineer needs to make an XML backup of Cisco UCS Manager. The backup should be transferred using an authenticated and encrypted tunnel and it should contain all system and service profiles configuration.
Which command must be implemented to meet these requirements?
- A. copy running-config scp://user@host35/backups/all-config9.bak all-configuration
- B. create file scp://user@host35/backups/all-config9.bak all-configuration
- C. copy startup-config scp://user@host35/backups/all-config9.bak all-configuration
- D. create backup scp://user@host35/backups/all-config9.bak all-configuration
Answer: D
Explanation:
https://www.cisco.com/en/US/docs/unified_computing/ucs/sw/cli/config/guide/1.4.1/CLI_Config_G uide_1_4_1_chapter40.html
NEW QUESTION # 256
Due to a domain name change at a customer site, a Cisco UCS cluster must be renamed. An engineer must recommend a solution to ensure that the Cisco UCS Manager is available over HTTPS. Which action accomplishes this goal?
- A. Generate a new default key ring certificate from the Cisco UCS Manager
- B. Reboot the SSO component of the Cisco UCS Manager
- C. Reinstall the cluster to generate the default key ring certificate
- D. Regenerate the default key ring certificate manually
Answer: A
Explanation:
When there is a domain name change, and the Cisco UCS Manager needs to be available over HTTPS, generating a new default key ring certificate from the Cisco UCS Manager (B) is typically the recommended action. This ensures that the HTTPS service has a valid certificate that matches the new domain name.
https://www.cisco.com/c/en/us/td/docs/unified_computing/ucs/ucs-manager/GUI-User-Guides/Admin-Managem
NEW QUESTION # 257
Refer to the exhibit.
An engineer needs to implement a monitoring session that should meet the following requirements:
* Monitor traffic from leaf to leaf switches on a Cisco ACI network
* Support filtering traffic from Bridge Domain or VRF
Which configuration must be added to meet these requirements?
- A. application epg epg1 app1
- B. filter tenant t1 application app1 epg epg1
- C. interface eth 1/2 switch 101
- D. interface eth 1/2 leaf 101
Answer: B
NEW QUESTION # 258
A network engineer must deploy a configuration backup policy to the cisco UCS manager. The file generated from this backup must have a snapshot of the entire system that should be used to restore the system during disaster recovery. The backup file must be transferred insecurely by using the TCP protocol. Which configuration backup settings meet these requirements?
- A. Option B
- B. Option D
- C. Option C
- D. Option A
Answer: A
NEW QUESTION # 259
A network engineer is deploying a cisco ALL-flash hyperflex solution. Which local storage configuration is required for the operating system and persistent logging?
- A. One solid state drive
- B. Two solid state drives
- C. Two SATA drives
- D. One SATA drive
Answer: A
NEW QUESTION # 260 
Refer to the exhibit. An engineer needs to implement streaming telemetry on a cisco MDS 9000 series switch.
The requirement is for the show command data to be collected every 30 seconds and sent to receivers. Which command must be added to the configuration meet this requirement?
- A. Snsr-grp 200 sample-interval 30000
- B. Snsr-grp 200 sample-interval 30
- C. Sensor-grp 200 sample-period 30
- D. Sensor-grp 200 sample-period 30000
Answer: A
Explanation:
Explanation
snsr-grp <id> sample-interval <interval> Currently, sensor group ID supports only numeric ID values. Specify the streaming sample interval value; the value must be in milliseconds. The minimum streaming sample interval that is supported is 30000 milliseconds.
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/mds9000/sw/8_x/config/san_analytics/cisco-mds900
NEW QUESTION # 261
An engineer installed a new Nexus switch with the mgm0 interface in vrf management. Connectivity to the rest of the network needs to be tested from the guest shell of the NX-OS. Which command tests connectivity from the guest shell of the NX-OS?
- A. [guestshell@guestshell ~]$ dohost ''ping vrf management 173.37.145.84''
- B. [guestshell@guestshell ~$ ping 173.37.145.84 vrf management
- C. [guestshell@guestshell ~]$ chvrf management ping 173.37.145.84
- D. [guestshell@guestshell ~]$ iping vrf management ip 173.37.145.84
Answer: C
Explanation:
Section: Network
Explanation/Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/sw/7-x/programmability/guide/ b_Cisco_Nexus_9000_Series_NX-OS_Programmability_Guide_7x/Guest_Shell.html
NEW QUESTION # 262
An engineer has a primary fabric that is named UCS-A and a secondary fabric that is named UCS-B. A certificate request that has a subject name of sjc2016 for a keyring that is named kr2016 needs to be created.
The cluster IP address is 10.68.68.68.
Which command set creates this certificate request?
- A. UCS-B# scope security
UCS-B /security # scope keyring kr2016
UCS-B /security/keyring # set certreq 10.68.68.68 sjc2016
UCS-B /security/keyring* # commit-both - B. UCS-A# scope security
UCS-A /security # scope keyring kr2016
UCS-A /security/keyring # create certreq ip 10.68.68.68 subject-name sjc2016 UCS-A /security/keyring* # commit-buffer - C. UCS-B # scope keyring kr2016
UCS-B /keyring # create certreq ip 10.68.68.68 subject-name sjc2016
UCS-B /keyring* # commit-both - D. UCS-A # scope keyring kr2016
UCS-A /keyring # create certreq 10.68.68.68 sjc2016
UCS-A /keyring* # commit-buffer
Answer: B
NEW QUESTION # 263
Which server policy is used to install new Cisco IMC software on a server?
- A. Option A
- B. Option D
- C. Option B
- D. Option C
Answer: A
NEW QUESTION # 264
An engineer has a primary fabric that is named UCS-A and a secondary fabric that is named UCS-B. A certificate request that has a subject name of sjc2016 for a keyring that is named kr2016 needs to be created.
The cluster IP address is 10.68.68.68. Which command set creates this certificate request?
A)
B)
C)
D)
- A. Option D
- B. Option B
- C. Option C
- D. Option A
Answer: C
NEW QUESTION # 265
An engineer is automating a Cisco Nexus 9000 Series Switch using the NX-OS API. Which code snippet creates a local user called "tacuser" with an expiration date of 22 November?
- A.

- B.

- C.

- D.

Answer: D
NEW QUESTION # 266
An engineer needs a utility to translate traditional Nexus CLI inputs and generate Python code using XML and JSON message formats. The solution needs to be available on a Nexus 7700 series switch. Which utility should be used?
- A. Open NX-OS
- B. NX-OS JSON-RPC
- C. NX-API Sandbox
- D. Guest Shell for NX-OS
Answer: C
Explanation:
Section: Automation
Explanation/Reference:
https://developer.cisco.com/docs/nx-os/#!nx-api-cli-developer-sandbox
NEW QUESTION # 267
......
350-601 Real Exam Questions and Answers FREE: https://www.real4prep.com/350-601-exam.html
2025 Realistic Verified Free Cisco 350-601 Exam Questions: https://drive.google.com/open?id=1WZMaQ_2Tfa3Wo-E8bbbm4PXalbOnoZSg