nerdexam
Cisco

300-420 · Question #359

Refer to the exhibit. An architect must design a resilient gateway solution based on these requirements: - VLAN 10 and VLAN 11 support voice and video applications. - Link and node failures must…

The correct answer is B. HSRP version 2 with MD5 authentication. To design a resilient gateway solution supporting voice/video, minimal impact from failures, protection against false hello packets, and IPv6, HSRP version 2 with MD5 authentication is the appropriate choice.

Advanced Enterprise Campus Networks

Question

Refer to the exhibit. An architect must design a resilient gateway solution based on these requirements:

  • VLAN 10 and VLAN 11 support voice and video applications.
  • Link and node failures must have minimal impact on traffic.
  • Provide protection against false hello packets.
  • Support IPv6.

Which solution must the architect choose?

Exhibit

300-420 question #359 exhibit

Options

  • AGLBP with IP SLA tracking
  • BHSRP version 2 with MD5 authentication
  • CVRRP version 2 with object tracking
  • DVRRP version 2 with authentication

How the community answered

(44 responses)
  • A
    5% (2)
  • B
    66% (29)
  • C
    9% (4)
  • D
    20% (9)

Why each option

To design a resilient gateway solution supporting voice/video, minimal impact from failures, protection against false hello packets, and IPv6, HSRP version 2 with MD5 authentication is the appropriate choice.

AGLBP with IP SLA tracking

GLBP (Gateway Load Balancing Protocol) is primarily an IPv4-only protocol for load balancing, though an IPv6 version exists; it is not the most direct solution when IPv6 support with authentication is a key specific requirement without explicit mention of GLBPv6.

BHSRP version 2 with MD5 authenticationCorrect

HSRP version 2 (HSRPv2) fully supports both IPv4 and IPv6, which is critical for the stated requirement. It provides fast failover for link and node failures, especially when combined with object tracking (implied for minimal impact). Crucially, HSRPv2 offers MD5 authentication, which effectively protects against unauthorized or false hello packets, securing the gateway redundancy protocol against malicious interference.

CVRRP version 2 with object tracking

VRRP version 2 (VRRPv2) only supports IPv4, failing the essential requirement for IPv6 support.

DVRRP version 2 with authentication

VRRP version 2 (VRRPv2) only supports IPv4, failing the essential requirement for IPv6 support, even though it supports authentication.

Concept tested: HSRPv2 with authentication and IPv6

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipapp_fhrp/configuration/xe-3s/fhrp-xe-3s-book/fhrp-hsrpv2.html

Topics

#First Hop Redundancy Protocols (FHRP)#HSRP#IPv6 Gateway Redundancy#MD5 Authentication

Community Discussion

No community discussion yet for this question.

Full 300-420 Practice