01. On a Nexus switch using TACACS+, one administrator authenticates and works normally. A second administrator authenticates successfully but then cannot enter configuration mode or run privileged commands.
Which cause best isolates this behavior?
a) The second user's server profile omits the cisco-av-pair role mapping
b) The shared secret configured for the switch server pair is misconfigured
c) The TACACS+ server is unreachable over the switch management network
d) The switch has fallen back to local authentication for this user
02. A Nexus switch fails to complete Smart Licensing registration. DNS resolves the licensing hostname and other management HTTPS sessions from the same interface succeed, but the registration attempt times out.
Which cause best isolates the failure?
a) The reserved license count on the switch fell below its minimum
b) The registration token expired before the licensing handshake could complete
c) The CoPP policy is silently dropping the outbound registration traffic
d) The SNMP v3 privacy password used for licensing polls is incorrect
03. During a traffic storm on a busy Nexus switch, OSPF adjacencies flap repeatedly. The interfaces stay up, the neighbor configuration is confirmed correct, and Ethanalyzer shows the neighbor's hello packets arriving at the switch.
Which cause best isolates the adjacency loss?
a) The OSPF hello timer is mismatched with the neighbor's dead interval
b) The interface MTU was raised above the neighbor's configured interface value
c) CoPP is dropping the punted OSPF control packets that exceed the policed rate during the storm
d) The OSPF process was placed into the wrong VRF routing table instance
04. Under heavy load, administrators report that SSH sessions to a Nexus switch time out intermittently, yet data-plane traffic transiting the same switch is unaffected.
Which mechanism most likely explains the management drops?
a) CoPP is policing the management traffic class beyond its permitted rate
b) A SPAN session is mirroring the entire management VLAN into the CPU
c) The NTP peer is rate-limiting the switch management control plane
d) The syslog server is throttling the inbound management SSH sessions
05. Before a risky change, an operator wants to use NX-OS checkpoint and rollback so the switch can be returned to a known good state.
Which statements about checkpoint and rollback are correct?
(Choose two.)
a) Rollback can return the running configuration to a previously saved checkpoint that undoes later changes
b) Creating a checkpoint first requires disabling the active control-plane policy
c) A checkpoint captures a point-in-time snapshot of the running configuration
d) Rollback permanently erases the entire startup configuration file from flash
e) A checkpoint automatically uploads the running configuration to a TACACS+ server
06. Over an established NX-API session to a Nexus switch, show commands succeed but a configuration command is rejected.
Which two causes best explain this selective failure?
(Choose two.)
a) The TLS certificate for the NX-API session is untrusted so the connection never opens
b) The config command was sent with the wrong NX-API command type
c) The feature nxapi is disabled so no session can be established
d) The Nexus switch has no DNS entry for its management hostname
e) The user's RBAC role grants read access but not configuration rights
07. A model-driven telemetry subscription on a Nexus switch is configured with a valid sensor path, but the off-box collector receives no data.
Which is the most likely cause?
a) The subscription needs feature nxapi enabled to stream its data
b) The telemetry cadence timer has not yet elapsed for the first push
c) The RBAC role blocks the collector from reading the sensor path
d) The destination collector for the subscription is unreachable so the pushed data never arrives
08. Two independently managed fabrics are joined by a new ISL. The E-ports negotiate, but the link isolates and the previously working zonesets on each side stop distributing across it.
What is the most likely cause of the isolation?
a) A zone-merge conflict from incompatible zonesets isolated the ISL
b) The default zone policy on one fabric silently dropped the ISL frames
c) The upstream core disabled NPIV for the newly joined fabric edge
d) The two peer fabric switches negotiated mismatched F-port roles across the new ISL
09. A Python script using requests posts to a Nexus NX-API endpoint, and the TCP connection is refused before any HTTP response is returned.
What is the most likely cause?
a) The switch returned an HTTP 401 because the NX-API credentials are wrong
b) The payload sends XML where the NX-API device expects JSON encoding
c) The account lacks the RBAC role and cannot run the NX-API command
d) The feature nxapi is not enabled so no process binds the port and the connection is refused
10. Most blades associate normally, but one profile repeatedly fails association on a specific blade. The pools are confirmed full and every referenced policy exists. The profile pins a host-firmware package, and the target blade's adapter runs a level that package cannot apply.
Among these, what is the most likely cause?
a) The MAC and WWN pools for that profile have already been exhausted.
b) The host-firmware package cannot be applied to that blade's adapter level.
c) The chassis IOM links for that blade were cabled to uplink ports.
d) The fabric interconnect for the blade runs switching rather than end-host mode.