ENCOR Training View RSS

A site devoted for learning ENCOR exam
Hide details



ENCOR FAQs & Tips 30 Jun 4:18 PM (2 months ago)

In this article, I will try to summarize all the Frequently Asked Questions in the ENCOR 350-401 v1.2 Exam. Hope it will save you some time searching through the Internet and asking your friends & teachers.

1. Please tell me how many questions in the real ENCOR exam, and how much time to answer them?

You have 120 minutes to solve 6 lab sims and answer 59 questions (updated on Aug 2026), include multiple choice and drag drop questions. All 6 lab sims will appear at the beginning of the exam and you need to solve all of them first.

If your native language is not English, Cisco allows you a 30-minute exam time extension (2 hours and 30 minutes in total). But there are a few requirements to get this extension, so the best way is asking your teacher or mentor before taking the exam.

2. How much does the ENCOR 350-401 cost? And how many points I need to pass the exam?

This exam costs $400. You need at least 825/1000 points to pass this exam. But you will no longer see your exam score after your test. You will only see if you passed or failed as well as details on each section performance (in percent). Sometimes you will see the status remains “Score Pending” and you have to wait for a few days (up to 72 business hours) in order for the PearsonVUE portal to reflect your actual score (“Pass” or “Fail”).

3. I passed the ENCOR exam, will I get a CCNP certificate for it?

No, ENCOR is only the core exam of the CCNP Enterprise certification. In order to get the CCNP Enterprise certification, you need to pass the ENCOR exam and one of the following concentration exams:
– 300-410 ENARSI: Implementing Cisco Enterprise Advanced Routing and Services (ENARSI)
– 300-415 ENSDWI: Implementing Cisco SD-WAN Solutions (ENSDWI)
– 300-420 ENSLD: Designing Cisco Enterprise Networks (ENSLD)
– 300-425 ENWLSD: Designing Cisco Enterprise Wireless Networks (ENWLSD)
– 300-430 ENWLSI: Implementing Cisco Enterprise Wireless Networks (ENWLSI)
– 300-435 ENAUTO: Implementing Automation for Cisco Enterprise Solutions (ENAUTO)

For example, you need to pass the ENCOR and ENARSI exam to get the CCNP Enterprise certificate.

4. So which concentration exam should I choose to complete my CCNP Enterprise cert?

First you should understand each of the concentration exams above:

– In ENARSI exam you will learn more about routing (EIGRP, OSPF, BGP, VPN & VRF-Lite) and services  (DHCP, AAA, SNMP, uRPF, IP SLA, NetFlow), mainly about how to troubleshoot them.
– In ENSDWI exam you will learn mainly about Cisco SD-WAN architecture (about vBond, vSmart, vManage and vEdge) and how they work. If your company is using them or you have a special reason to know about them then you should learn this exam.
– In ENSLD exam you will learn how to design popular routing protocols, WAN; describe SD-Access and SD-WAN.
– Two exams ENWLSD and ENWLSI will teach you about Wireless in detail
– The ENAUTO exam allows you to learn how to program and automate your network with APIs (JSON, XML, YANG; NETCONF and RESTCONF) using Python. The “network” here includes IOS XE devices, Cisco DNA Center, Cisco SD-WAN and Cisco Meraki.

In the above exams, only the ENARSI exam teach you about “traditional” network. If you don’t have any special reason to learn other exams then it is the most suitable exam for you. If you used to learn how to program/code then the ENAUTO is also a recommended exam to take.

If you are still in doubt about any exam then we recommend you to find the syllabus of that exam and have a closer look by yourself before deciding, just google it (with keyword: “syllabus” + that exam name). We don’t post direct links here because the subjects of these exams may change in the future so we wish you to find the latest syllabuses of these exams.

5. In the real exam, I clicked “Next” after choosing the answer, can I go back for reviewing?

No, you can’t go back so you can’t re-check your answers after clicking the “Next” button.

6. What are your recommended materials for ENCOR?

There are many options you can choose, but below are materials used and recommended by many candidates:

Recommended Books

Video training

Simulator (all are free)

7. Are the exam questions the same in all the geographical locations?

Yes, the exam questions are the same in all geographical locations. But notice that Cisco has a pool of questions and each time you take the exam, a number of random questions will show up so you will not see all the same questions as the previous exam.

8. I passed the ENCOR exam. Do you have any site similar for CCNP Enterprise exams?

We have certprepare.com for CCNP Enterprise ENSDWI (a concentration exam of CCNP Enterprise certification) and networktut.com for ENARSI (another concentration exam of CCNP Enterprise certification).

We also have other sites (but only for sharing experience) like voicetut.com for Voice/Collaboration track, securitytut.com for Security track, dctut.com for Data Center track, sptut.com for Service Provider track, wirelesstut.com for Wireless track, opstut.com for DevNet track. Hope you enjoy these sites and find useful information too!

9. How many CCNP tracks does Cisco support now?

Cisco supports 7 CCNP tracks, which are:

1. CCNP Enterprise
2. CCNP Security
3. CCNP Service provider
4. CCNP Collaboration
5. CCNP Data Center
6. Cisco Certified DevNet
7. Cisco Certified CyberOps

In each track, you need to pass a dedicated core exam then pass one concentration exam of that track. Please check the picture below for more detail:

Cisco_Next_Level_Certification_Path.jpg

Note: With these new tracks, CCNA is no longer a prerequisite for CCNP. You can go directly for CCNP certs. But the knowledge of CCNA is highly recommended if you want to reach CCNP.

10. I passed (old) CCNP but my CCNP cert is going to expire and I want to recertify it. Which exam should I get?

According to Cisco Recertification Policy page, you need to complete one of the following things:

– Pass one technology core exam
– Pass any two professional concentration exams
– Pass one CCIE lab exam

Therefore if you only want to take one exam to recertify then you must pass the ENCOR 350-401 exam or any technology core exam of other tracks (for example the DCCOR 350-601 of Data Center track or the SCOR 350-701 of Security track).

Also if you earn 80 CE credits then you can also recertify your CCNP Enterprise cert.

Is there anything you want to ask? Just ask! All of us will help you.

Add post to Blinklist Add post to Blogmarks Add post to del.icio.us Digg this! Add post to My Web 2.0 Add post to Newsvine Add post to Reddit Add post to Simpy Who's linking to this post?

ENCOR Tutorials & Practice Labs 12 Jun 3:30 AM (3 months ago)

We have many tutorials and practice labs on our site to help you understand the concepts of the ENCOR exam. We have summarized them here in one place and categorized them into specific topics to make your learning easier.

================== ENCOR Tutorials ==================

1.0 Architecture
2.0 Virtualization
3.0 Infrastructure
4.0 Network Assurance
5.0 Security
6.0 Automation

 

================= ENCOR Practice Labs =================

Practice labs help individuals and professionals gain practical experience with networking technologies by configuring routers & switches on the emulators.

ENCOR Practice Labs

 

================= ENCOR Lab Challenges =================

Lab Challenges require you to configure or troubleshooting preconfigured labs.

ENCOR Lab Challenges

Add post to Blinklist Add post to Blogmarks Add post to del.icio.us Digg this! Add post to My Web 2.0 Add post to Newsvine Add post to Reddit Add post to Simpy Who's linking to this post?

Media Access Control Security (MACsec) Tutorial 11 Jun 3:30 AM (3 months ago)

We often think Ethernet links with wired cable connection are safe. But in fact when the frames go from one device to another, that connection is not encrypted so they can be intercepted, sniffed, modified or replayed through rogue devices if the attackers gain access to the devices’ room. Therefore MACsec comes into play to mitigate these threats. MACsec works similarly to how WPA2/WPA3 protects wireless traffic, but for wired links. MACsec protects traffic between directly connected devices such as switches, routers, servers, and access points. 

Media Access Control Security (MACsec) is an IEEE standard 802.1AE that provides Layer 2 hop-by-hop encryption. This means the traffic is encrypted only on the wire between two MACsec peers and is unencrypted as it is processed within the devices. If someone gains access to the physical network, MACsec ensures the data on the wire is encrypted and cannot be read or altered.

MACsec.jpg

What are benefits of MACsec?

MACsec provides encryption, data integrity and authentication.

+ For encryption, MACsec uses the Galois/Counter Mode – Advanced Encryption Standard (GCM‑AES) algorithm to encrypt data. MACsec provides high-speed data encryption with minimal impact on network performance. Unlike software-based encryption methods that rely on the CPU, MACsec performs encryption and decryption directly in dedicated hardware components such as ASICs or PHY chips. This hardware-based processing enables bi-directional line-rate, or near line-rate, encryption, allowing traffic to be secured at very high speeds without introducing significant latency or reducing throughput. This is called line-rate encryption.

+ For data integrity, MACsec generates a Message Authentication Code using the Integrity Check Value (ICV). The ICV is used to validate the encrypted MACsec frame to help ensure that data cannot be modified in transit.

+ For authentication, it uses 802.1x EAPOL-EAP to provide access control and generation of Master Secret Key. In the absence of 802.1x, a pre-shared key also can be used as the master key.

Line-rate encryption refers to the practice of encrypting data at the maximum speed or data rate allowed by the communication channel or network infrastructure, without compromising security or performance. In other words, it is a type of encryption that can encrypt and decrypt data as fast as the data can be transmitted over the communication channel or network.

MACsec frame structure

A MACsec packet is formed with an Ethernet frame by adding a Security TAG (SecTAG) and an Integrity Check Value (ICV) as shown in the figure below:

MACsec_frame_structure.jpg

The source and destination MAC addresses are not encrypted but they are included in the ICV calculation using the SAK. Therefore, only authenticated devices can change the ICV.

When a device, such as an switch receives the frame, it validates the source and destination MAC addresses, SecTag and encrypted payload against the ICV. If they match, the frame is processed, and the payload is decrypted. If they do not match, it assume the frame has been tampered and will be dropped.

How MACsec works?

MACsec establishes a link between the two devices to exchange pre-shared keys through the MACsec Key Agreement (MKA) process. The key can be configured manually, or can be generated dynamically, depending on the security mode used to enable MACsec. Once the MKA process is complete, the devices exchange keys to provide the Security Association Keys (SAK) which is then used to encrypt the whole layer-2 ethernet frame.

Note: MKA protocol installed on a device relies on an IEEE 802.1X Extensible Authentication Protocol (EAP) framework to establish communication.

Basic Process
1. Devices authenticate each other.
2. Encryption keys are exchanged.
3. Ethernet frames are encrypted before transmission.
4. Receiving device decrypts the frames.

What are MACsec requirements?

Requires MACsec-supported devices in all the path.

Configuration

//Configure Pre-Shared Key
key chain mka-keys macsec
   key SecretKey
      cryptographic-algorithm aes-256-cmac
      key-string Digitaltut
!
//Configure MKA Policy
mka policy mkapolicy1
   macsec-cipher-suite gcm-aes-128
!
//Enable MACsec on an interface
int g1/0/1
 macsec network-link
 mka policy mkapolicy1
 mka pre-shared-key key-chain mka-keys
!

 

Add post to Blinklist Add post to Blogmarks Add post to del.icio.us Digg this! Add post to My Web 2.0 Add post to Newsvine Add post to Reddit Add post to Simpy Who's linking to this post?

Share your ENCOR v1.2 Experience 18 Mar 4:11 PM (6 months ago)

The new version of the ENCOR v1.2 has come to replace the old ENCOR version so we create the “Share your ENCOR v1.2 Experience” for everyone to share their experience to prepare for this new exam.

Please share with us your experience to prepare for the new version of the ENCOR 350-401 v1.2 exam, your materials, the way you learned, your recommendations… But please DO NOT share any information about the detail of the exam or your personal information, your score, exam date and location, your email…

Note:
+ The ENCOR 350-401 v1.2 exam include lab sims, multiple choice and Drag drop questions.
+ You can use shortcut command (like “int”, “no sh”, “conf t”…), “tab” and “?” in the simulations of the exam.
+ To get the new CCNP Enterprise certificate, you need to pass this ENCOR 350-401 exam (core exam) and one of the concentration exam.

Your posts are warmly welcome! Hope you will find useful information here!

Add post to Blinklist Add post to Blogmarks Add post to del.icio.us Digg this! Add post to My Web 2.0 Add post to Newsvine Add post to Reddit Add post to Simpy Who's linking to this post?

Hypervisor type 1 and 2 Tutorial 11 Apr 2025 7:15 AM (last year)

A virtual machine (VM) is a software emulation of a physical server with an operating system. From an application’s point of view, the VM provides the look and feel of a real physical server, including all its components, such as CPU, memory, and network interface cards (NICs).

A hypervisor, also known as a virtual machine monitor, is a software that creates and manages virtual machines. A hypervisor allows one physical server to support multiple guest VMs by virtually sharing its resources, such as memory and processing.

There are two types of hypervisors: type 1 and type 2 hypervisor.

In type 1 hypervisor (or native hypervisor), the hypervisor is installed directly on the physical server. Then instances of an operating system (OS) are installed on the hypervisor. Type 1 hypervisor has direct access to the hardware resources. Therefore they are more efficient than hosted architectures. Some examples of type 1 hypervisor are VMware vSphere/ESXi, Oracle VM Server, KVM and Microsoft Hyper-V.

In contrast to type 1 hypervisor, a type 2 hypervisor (or hosted hypervisor) runs on top of an operating system and not the physical hardware directly. A big advantage of Type 2 hypervisors is that management console software is not required. Examples of type 2 hypervisor are VMware Workstation (which can run on Windows, Mac and Linux) or Microsoft Virtual PC (only runs on Windows).

Type1_Type2_Hypervisors_detail.jpg

Comparison Type 1 and Type 2 hypervisors

  Type 1 hypervisor Type 2 hypervisor
Other name Bare metal hypervisor Hosted hypervisor
Runs on Underlying physical host machine hardware Underlying operating system (host OS)
Best suited for Large, resource-intensive, or fixed-use workloads Desktop and development environments
Can negotiate dedicated resources? Yes No
Knowledge required System administrator-level knowledge Basic user knowledge
Examples VMware ESXi, Microsoft Hyper-V, KVM Oracle VM VirtualBox, VMware Workstation, Microsoft Virtual PC

Structure of virtualization in a hypervisor

Hypervisors provide virtual switch (vSwitch) that Virtual Machines (VMs) use to communicate with other VMs on the same host. The vSwitch may also be connected to the host’s physical NIC to allow VMs to get layer 2 access to the outside world.

Each VM is provided with a virtual NIC (vNIC) that is connected to the virtual switch. Multiple vNICs can connect to a single vSwitch, allowing VMs on a physical host to communicate with one another at layer 2 without having to go out to a physical switch.

 

Virtual_machine_structure.jpg

Although vSwitch does not run Spanning-tree protocol but vSwitch implements other loop prevention mechanisms. For example, a frame that enters from one VMNIC is not going to go out of the physical host from a different VMNIC card.

Benefits of Virtualizing

Server virtualization and the use of virtual machines is profoundly changing data center dynamics. Most organizations are struggling with the cost and complexity of hosting multiple physical servers in their data centers. The expansion of the data center, a result of both scale-out server architectures and traditional “one application, one server” sprawl, has created problems in housing, powering, and cooling large numbers of underutilized servers. In addition, IT organizations continue to deal with the traditional cost and operational challenges of matching server resources to organizational needs that seem fickle and ever changing.

Virtual machines can significantly mitigate many of these challenges by enabling multiple application and operating system environments to be hosted on a single physical server while maintaining complete isolation between the guest operating systems and their respective applications. Hence, server virtualization facilitates server consolidation by enabling organizations to exchange a number of underutilized servers for a single highly utilized server running multiple virtual machines.

By consolidating multiple physical servers, organizations can gain several benefits:
+ Underutilized servers can be retired or redeployed.
+ Rack space can be reclaimed.
+ Power and cooling loads can be reduced.
+ New virtual servers can be rapidly deployed.
+ CapEx (higher utilization means fewer servers need to be purchased) and OpEx (few servers means a simpler environment and lower maintenance costs) can be reduced.

Para-virtualization

Para-virtualization is an enhancement of virtualization technology in which a guest operating system (guest OS) is modified prior to installation inside a virtual machine. This allows all guest OS within the system to share resources and successfully collaborate, rather than attempt to emulate an entire hardware environment. The modification also decreases the execution time required to complete operations that can be problematic in virtual environments.

Paravirtualization.jpg

By granting the guest OS access to the underlying hardware, Para-virtualization enables communication between the guest OS and the hypervisor (using API calls), thus improving performance and efficiency within the system. This is the main difference between Para-virtualization and (traditional) full-virtualization.

Add post to Blinklist Add post to Blogmarks Add post to del.icio.us Digg this! Add post to My Web 2.0 Add post to Newsvine Add post to Reddit Add post to Simpy Who's linking to this post?