RCNI Sample Questions & Answers
Pulls together implementing ICX switches with Layer 2/3 protocols, PoE and IPv4/IPv6 addressing, by far the biggest weight, plus spanning tree and PoE basics alongside VLAN design, the ICX product line itself, and recovering and troubleshooting ICX switches.
Launch the full RCNI simulator →Free RCNI Sample Questions with Answers
Real questions from the Ruckus Certified Networking Implementer practice test — answers and explanations included. Showing 10 of 20 free samples.
- Question 1AdvancedSelect 2
ICX Solution Implementation · Configuring multicase and security features
A network team is deploying 802.1X port-based authentication in a mixed-vendor environment. They want to ensure that if a user successfully authenticates on an ICX switch port, the RADIUS server can assign them to a specific VLAN for their user role. Which two RADIUS attributes are commonly used to achieve this dynamic VLAN assignment? (Select TWO).
Show answer & explanation
Correct answers: A, B
Tunnel-Type must be set to 'VLAN' (value 13) to indicate that the tunnel attributes are for VLAN assignment.
Tunnel-Private-Group-ID contains the VLAN ID (as a string) to which the user should be assigned.
- Question 2Intermediate
ICX Solution Implementation · Configuring multicase and security features
A retail company is setting up a new warehouse using ICX 7150-C12P compact switches. To prevent unauthorized devices from connecting and gaining network access, the administrator implements port security with a
mac-address-table staticentry and theport-security maximum 1command on an interface. What happens when a second, unknown device is connected to this secured port?Show answer & explanation
Correct answer: B
By default, the violation action for port security on ICX switches is
shutdown. When a second device connects to a port configured withport-security maximum 1, it triggers a security violation. The switch will then place the port into an error-disabled (err-disabled) state, blocking all traffic. An administrator must manually intervene by issuingno shutdownon the interface to re-enable it after the unauthorized device is removed. - Question 3Intermediate
Foundational Networking Concepts · STP or loop prevention protocols
A consultant is reviewing the Spanning Tree Protocol (STP) configuration on a campus network. They notice that a specific access layer switch unexpectedly becomes the root bridge for a VLAN, causing suboptimal traffic paths. To prevent this switch from ever becoming the root bridge, which STP feature should be enabled on its designated ports that connect to the distribution layer?
graph TD subgraph Core/Distribution Core1[ICX 7750 - Root] Core2[ICX 7750 - Secondary] end subgraph Access Layer Acc1[ICX 7250] Acc2[ICX 7250 - Rogue Root] Acc3[ICX 7150] end Core1 -- "Trunk" --> Acc1 Core2 -- "Trunk" --> Acc1 Core1 -- "Trunk" --> Acc2 Core2 -- "Trunk" --> Acc2 Core1 -- "Trunk" --> Acc3 Core2 -- "Trunk" --> Acc3Show answer & explanation
Correct answer: D
Root Guard is the correct feature for this scenario. It is enabled on designated ports (typically uplinks towards the core/distribution layer) to enforce the STP topology. If a superior BPDU (one that would cause the local switch to become root) is received on a Root Guard-enabled port, the port is put into a 'root-inconsistent' state, effectively ignoring the superior BPDU and preventing the downstream switch from becoming the root.
- Question 4Beginner
ICX Solution Implementation · Methods to manage an ICX switch
A systems administrator is configuring a new ICX 7450 switch. They need to set up a syslog server to collect critical event logs. The command
logging __________is used to specify the destination for these logs. What should be entered in the blank to send logs to a server with the IP address 192.168.10.25?Show answer & explanation
Correct answer: B
The correct command to specify a remote syslog server is
logging. Therefore, to send logs to the server at 192.168.10.25, the administrator would enterlogging 192.168.10.25in the global configuration mode. - Question 5Beginner
RUCKUS Products & Solutions · ICX product line
A university is deploying RUCKUS access points that require PoE+ (802.3at) power. An ICX 7150-48PF switch is selected. According to the product specifications, what is the total PoE power budget available on this specific switch model?
Show answer & explanation
Correct answer: C
The 'P' in the ICX 7150-48P model indicates PoE/PoE+ support, while the 'F' in ICX 7150-48PF indicates a full power budget. The ICX 7150-48PF model provides a total PoE power budget of 740 Watts, which is sufficient to deliver 15.4W (PoE) to all 48 ports or 30W (PoE+) to 24 ports.
- Question 6Intermediate
Foundational Networking Concepts · Layer 3 routing configurations
A network engineer is configuring two geographically separate data centers connected by a WAN link. They are using OSPF as the routing protocol on their ICX 7850 routers. To optimize routing and reduce the size of the routing table, they want to summarize routes from several /24 networks within Data Center A before advertising them to Data Center B. Which type of OSPF router is responsible for performing this route summarization between areas?
Show answer & explanation
Correct answer: B
In OSPF, an Area Border Router (ABR) is a router that connects one or more OSPF areas to the backbone area (Area 0). A primary function of the ABR is to summarize routes from its attached non-backbone areas before advertising them into the backbone. This process, known as inter-area route summarization, is configured on the ABR using the
area rangecommand. - Question 7Intermediate
ICX Solution Implementation · Configuring multicase and security features
During a network audit, a security analyst discovers that DHCP starvation attacks are possible on the guest VLAN. To mitigate this, the network administrator decides to implement DHCP Snooping. Which of the following describes the primary function of a trusted port in a DHCP Snooping configuration?
Show answer & explanation
Correct answer: B
In a DHCP Snooping deployment, ports are categorized as either trusted or untrusted. Untrusted ports (the default) are where end-user devices connect; they are not allowed to send DHCP server messages like DHCPOFFER or DHCPACK. A trusted port is explicitly configured to connect to a legitimate DHCP server. The switch will permit DHCP server messages to be received on these trusted ports, while blocking them on all untrusted ports, thus preventing rogue DHCP servers.
- Question 8Advanced
ICX Solution Implementation · Using Layer 2/3 protocols and ICX services
Case Study: Global Logistics Firm Network Upgrade
Company Background:
Global Transport Inc. (GTI) is a logistics company with a central headquarters (HQ) and multiple large distribution centers. They are undertaking a major network refresh to improve performance and security. The core of their network at HQ is being upgraded to a pair of ICX 7850 switches configured for redundancy. The distribution centers use ICX 7450 stacks as their local core/aggregation layer.Current Situation:
GTI's network has grown organically and suffers from slow convergence times during link failures, leading to disruptions in their critical package tracking system. The current routing is managed by a legacy EIGRP implementation, which is not supported on the new ICX switches. All inter-site connectivity is handled via private MPLS links provided by a carrier.Technical Requirements:
- Implement a standards-based, fast-converging interior gateway protocol (IGP) across the entire enterprise.
- Ensure high availability for the default gateway at all distribution centers. The solution should provide sub-second failover.
- Prevent routing loops and ensure that routes learned from the MPLS carrier do not interfere with the internal routing domain.
- All network management must be performed from a dedicated, out-of-band management VLAN (VLAN 99).
Problem:
An implementation engineer at GTI needs to select the most appropriate protocols and features to meet the technical requirements on the new RUCKUS ICX infrastructure. Which of the following solution proposals BEST addresses all the specified requirements?Show answer & explanation
Correct answer: B
This solution correctly addresses all requirements. OSPF is a standards-based, fast-converging IGP suitable for enterprise networks. VRRP provides sub-second gateway failover. Using a separate VRF (Virtual Routing and Forwarding) instance for the MPLS connection is a best practice to isolate the external carrier routing table from the internal IGP, preventing route leaks and potential loops. Finally, it correctly places the management interface in the required VLAN 99.
- Question 9Intermediate
ICX Solution Troubleshooting · Basic Networking Troubleshooting
A technician is troubleshooting a link between two ICX switches that is not passing traffic. The
show interfacecommand on Switch A shows the port isUp, Line protocol is down (err-disabled). Further investigation reveals the error isbpdu-guard-shutdown. What is the most likely cause of this issue?Show answer & explanation
Correct answer: A
BPDU Guard is a security feature that is typically enabled on PortFast-enabled ports (access ports). Its purpose is to shut down the port if it ever receives a Spanning Tree Protocol (STP) Bridge Protocol Data Unit (BPDU). The reception of a BPDU on an access port indicates a potential misconfiguration or an unauthorized switch being connected. In this case, Switch B is sending BPDUs, which are being received by the BPDU Guard-enabled port on Switch A, causing it to go into an err-disabled state.
- Question 10Beginner
RUCKUS Products & Solutions · ICX product line
A network administrator needs to select an appropriate RUCKUS ICX switch for a new office building's access layer. The requirements are: support for at least 24 PoE+ devices, 10GbE uplinks to the core, and stacking capabilities for simplified management. Which ICX product family is specifically designed for this campus edge role?
Show answer & explanation
Correct answer: C
The ICX 7150 and ICX 7250 series are designed as entry-level and mid-range stackable campus access switches. They meet all the requirements: various models offer 24 or 48 ports with PoE/PoE+, they feature 10GbE SFP+ uplink ports, and they support RUCKUS stacking technology. The ICX 7750 and 7850 are high-performance core and data center switches.
Ready for the real thing?
The full RCNI simulator has every exam-style question, timed mode, and instant scoring.