Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Refer to the exhibit.


Refer to the exhibit. An engineer must configure EVPN port-active multihoming on router R1. Which command must be run against the g1/0 and g1/1 interfaces on R1 to complete the physical Ethernet bundle for multihoming on a host named Host-1?
From Cisco's EVPN VXLAN multihoming design requirements, port-active multihoming uses a single LAG (EtherChannel / Bundle-Ether) between the host/router and the pair of leaf switches. All physical interfaces participating in that bundle must be configured with:
bundle id <number> mode active
This command:
Associates the physical interfaces (g1/0 and g1/1) with Bundle-Ether1.
Uses LACP active mode, which is required for EVPN port-active multihoming.
Enables the host-facing port-channel required to support EVPN multihomed connectivity.
In the exhibit, R1 already has:
interface Bundle-Ether1
description 'Bundle to Leaf-1'
...
interface Bundle-Ether1.10
ip address 192.168.10.1 255.255.255.0
This confirms that the engineer intends to bundle g1/0 and g1/1 together into Bundle-Ether1, and the missing step is adding the interfaces into that bundle.
The correct configuration is:
interface g1/0
bundle id 1 mode active
interface g1/1
bundle id 1 mode active
Why the other options are incorrect
A . evpn ethernet-segment 1
This command is used on EVPN leaf switches (not R1) to define an ESI for multihoming. R1 is not an EVPN VTEP.
B . switchport mode trunk
R1 is a router, not a switch. L3 interfaces do not use switchport.
C . encapsulation dot1q 1
This applies only to subinterfaces, not physical interfaces, and is unrelated to building a LAG for port-active multihoming.
Refer to the exhibit.

Refer to the exhibit. An engineer needs to configure ToR switches for a Cisco NFVI C-series pod. This configuration was performed on the ToR-A switch already:
feature vpc
feature lacp
interface Ethernet1/1-2
channel-group 110 mode active
interface port-channel110
Which command must be run on ToR-A to complete the port-channel configuration?
In a Cisco NFVI C-Series Pod, the Top-of-Rack (ToR) switches are almost always configured as a vPC pair. A vPC domain requires three mandatory components:
vPC domain ID
vPC peer-link
vPC peer-keepalive link ensures dual-active detection
In the exhibit:
The management interfaces are Tor-A Mgmt0: 10.10.10.1 and Tor-B Mgmt0: 10.10.10.2
These IPs are used commonly as the peer-keepalive endpoints
The physical uplinks to NFVI nodes form Port-Channel110
Since the configuration snippet already includes:
feature vpc
feature lacp
channel-group 110 mode active
The next required step in a Cisco NFVI + vPC configuration is to configure the peer-keepalive from ToR-A toward ToR-B:
vpc domain 1
peer-keepalive destination 10.10.10.2
This ensures:
vPC roles sync
Dual-active prevention
Stable operation for the NFVI C-Series rack
Why the Other Options Are Incorrect
A. vpc peer-link This is required but must be configured on the dedicated peer-link interfaces, not on the server-facing port-channel.
C. channel-group 110 mode on The correct mode is already configured: mode active for LACP. mode on disables LACP.
D. switchport mode access NFVI ToR links use trunking, not access mode, because servers carry multiple networks (control, compute, storage, management VLANs).
How does SR-IOV move data directly to and from the network adapter?
Comprehensive and Detailed Explanation (Cisco NFVI / Virtualization Knowledge)
SR-IOV (Single Root I/O Virtualization) allows a VM to access the network interface hardware directly, without going through the hypervisor's virtual switch.
This is achieved by:
Assigning Virtual Functions (VFs) directly to VMs
Allowing high-performance, low-latency packet I/O
Bypassing the hypervisor datapath
Therefore, SR-IOV does not bypass the guest OS; it bypasses the hypervisor I/O virtualization layer, delivering near-native performance.
Thus the correct answer is C.
What does Cisco Always-On Cloud DDoS use to protect against DDoS attacks?
Comprehensive and Detailed Explanation From Cisco SP Security Knowledge
Cisco Always-On Cloud DDoS Protection is a cloud-based, carrier-grade security service used by service providers to protect customers from volumetric and application-layer DDoS attacks.
Its core protection mechanism is the use of global scrubbing centers, which:
Receive diverted attack traffic
Scrub (clean) malicious packets
Forward clean traffic back to the customer
Use behavioral analysis and real-time detection
Protect against volumetric, TCP state-exhaustion, and application-layer attacks
Why other answers are incorrect:
Load balancing (A) does not mitigate DDoS attacks; it distributes traffic across servers.
Botnet zombies (B) are sources of DDoS attacks, not protection.
Traffic mirroring (C) is used for analysis and monitoring, not active DDoS protection.
Which command must be run on a Cisco IOS device to configure six parallel iBGP and eBGP routes that can be installed into a routing table?
Comprehensive and Detailed Explanation From Cisco SP Core Optimization Knowledge
Cisco IOS supports BGP Multipath for installing multiple equal-cost BGP routes (both iBGP and eBGP) into the routing table. The correct global BGP command syntax to set the number of allowable parallel BGP paths is:
maximum-paths <number>
For BGP specifically, the form is:
maximum-paths bgp <number>
This enables the router to install up to the specified number of equal-cost BGP routes (iBGP and eBGP) into the RIB and then potentially into the FIB.
Setting:
maximum-paths bgp 6
allows six parallel ECMP paths learned via BGP---this matches the requirement in the question.
Why the other options are incorrect
B . multipath eibgp 6
Not a valid Cisco IOS command.
C . maximum paths bgp routers 6
Invalid syntax.
D . maximum-paths eibgp 6
The correct keyword is bgp, not eibgp.
Cisco does not use ''eibgp'' in this context; IOS supports BGP multipath across iBGP/eBGP automatically when configured under maximum-paths bgp.
Refer to the exhibit.


Refer to the exhibit. The indicated configuration was applied to a Cisco switch Switch_A located in the Los Angeles DC data center; however, Switch_A fails to establish OTV connectivity to Cisco switch Switch_C. Which overlay interface command must be run on Switch_A to resolve the issue?
Overlay Transport Virtualization (OTV) allows Layer 2 extension across Layer 3 infrastructures. To operate, OTV requires three fundamental components on the overlay interface:
Join interface -- used to reach the OTV control plane over L3 (already configured: otv join-interface g1/0).
Control-group multicast address -- for control-plane advertisement (already configured: otv control-group 224.1.1.1).
Extended VLAN list -- specifies which VLANs will be transported through the OTV overlay.
The configuration shown in the exhibit includes the join-interface, control-group, and data-group, but it does NOT specify which VLANs should be extended. Without the otv extend-vlan command, OTV will form the overlay interface but will not forward any Layer 2 information, preventing adjacency and MAC distribution between sites.
In OTV, the command required to activate VLANs for transport is:
otv extend-vlan <vlan-range>
This enables the VLANs (such as 101--111) to be carried across the OTV overlay, completing the configuration and establishing connectivity.
Why the Other Options Are Incorrect
B . otv isis authentication-type md5
This is optional and only required if ISIS authentication is enabled on both edges. It does not resolve the absence of VLAN extension.
C . otv isis authentication-check
This command enforces authentication verification but does not fix connectivity when VLANs are not extended.
D . otv join-interface vlan 101-111
This is not a valid OTV command. The join-interface must be a routed interface, not a VLAN list.
Exam domains verified against: Official Cisco 300-540 exam guide, last checked October 2026.
Covers cloud service models including IaaS, PaaS, SaaS and FaaS for private, public and hybrid deployments. Describes virtualization functions using NFV, VNF, NSO and Cisco platforms, with emphasis on deploying NFV using NETCONF, RESTCONF, REST APIs, Yang models and gNMI/gRPC through OpenStack orchestration.
Sample question from this domain above: Q3
Evaluates carrier-neutral facility connectivity including direct connect, MPLS and segment routing options. Addresses troubleshooting of data centre interconnect solutions using EVPN VXLAN, EVPN over SR/MPLS, ACI and pseudowires.
Implements infrastructure security using ACL, uRPF, RTBH and BGP flowspec with TACACS and MACSEC. Describes DoS mitigation, NFVI security including API and control plane hardening, network segmentation with TLS and mTLS, plus cloud security solutions for DNS, zero-day exploits and virus detection.
Sample question from this domain above: Q4
Describes network assurance through NFVI MANO and VNF workloads with VIM control plane KPIs monitored by streaming telemetry. Covers cloud infrastructure monitoring using SR-PM, NetFlow, IPFIX, syslog, SNMP and cloud agents alongside VNF optimization with SR-IOV and software accelerators like DPDK and VPP.
Implements VNF data plane redundancy through placement and network resiliency with control plane high availability in single VIM environments. Covers multi-homing, EVLAG, virtual private cloud, ECMP from NFVI and design models using DNS, routing and load balancers.
Common questions about the exam itself