Cisco · CCNP Service Provider concentration · Practice Exam · SPCNI v1.0 blueprint

Cisco 300-540 SPCNI Cloud Network Infrastructure Practice Exam

Cover all five SPCNI v1.0 domains — Virtualized Architecture, Cloud Interconnect, High Availability, Security, and Service Assurance & Optimization — with objective-mapped questions, instant feedback in Learn mode, and a full timed simulation in Exam mode.

Start 24-hour free trial →
500+
Practice questions
5
Objective domains
2
Study modes
24h
Free trial

300-540 SPCNI exam at a glance

Vendor
Cisco
Exam code
300-540
Exam name
Designing and Implementing Cisco Service Provider Cloud Network Infrastructure (SPCNI)
Blueprint
Cisco exam topics v1.0 — five domains weighted 25 / 25 / 20 / 15 / 15
Certification earned
Cisco Certified Specialist – Service Provider Cloud Network Infrastructure
Counts toward
CCNP Service Provider (satisfies the concentration-exam requirement alongside the 350-501 SPCOR core)
Duration
90 minutes
Question count
Cisco does not publish a fixed item count for this exam
Passing score
Cisco does not publish a fixed passing score; cut scores are set by psychometric analysis and are not disclosed
Prerequisites
None formally required. Cisco recommends hands-on experience with NFV, virtualization platforms, cloud interconnect, and service provider automation.
Cost (USD)
$300 USD, or redeem Cisco Learning Credits (regional pricing varies)
Delivery
Pearson VUE test center or online proctored; scheduled through the Cisco certification portal
Languages
English
Validity
3 years (CCNP-level); recertify by exam or by earning 80 Continuing Education credits

Sources: Cisco — 300-540 SPCNI exam page · Cisco — SPCNI v1.0 exam topics (PDF). Verify current details with Cisco before scheduling.

About the Cisco 300-540 SPCNI certification

SPCNI is the newest and least conventional of the four CCNP Service Provider concentration exams. Pass it and you earn the standalone Cisco Certified Specialist – Service Provider Cloud Network Infrastructure credential; pair it with the 350-501 SPCOR core exam and you complete the full CCNP Service Provider certification. What makes it unusual is how far it sits from traditional routing and switching: a large share of the blueprint is virtualization, orchestration, and API-driven automation rather than protocol configuration.

The blueprint verbs tell the story. SPCNI asks you to describe cloud service models and carrier-neutral facilities, implement virtualization functions and high-availability designs, deploy NFV using automation, and troubleshoot data-center-interconnect solutions. That means real fluency with NFV and VNF concepts, Cisco NSO, NETCONF, RESTCONF and REST APIs, YANG models, gNMI and gRPC, and OpenStack — alongside the interconnect and security material a service provider engineer would expect. Candidates who arrive from a pure routing background are usually surprised by how much of the exam is orchestration and telemetry rather than CLI.

Every PowerKram question maps to one of the five v1.0 domains and cites the Cisco document it was derived from, so a weak score turns into a specific reading list instead of a vague instruction to study harder. For the broader context on how vendor certification tracks fit together, see our guide to how IT certification tracks are structured.

300-540 SPCNI exam domains and weights

Cisco publishes five weighted domains in the v1.0 exam topics document. The weights sum to 100%. Virtualized Architecture and Cloud Interconnect are tied as the heaviest areas at 25% each, and together account for half the exam.

1.0 Virtualized Architecture

IaaS constraints such as VLAN scale and segmentation; determining the cloud service model (IaaS, PaaS, SaaS, FaaS) for private, public, or hybrid deployments; container orchestration and virtual machines; implementing NFV, VNF, NSO, and virtualized Cisco platforms; deploying NFV with automation including VNF onboarding, NSO orchestration, NETCONF/RESTCONF/REST APIs, YANG models with gNMI and gRPC, and OpenStack.

25%Joint heaviest
2.0 Cloud Interconnect

Carrier-neutral facilities including connectivity options to cloud providers, to other carrier-neutral facilities or customer locations, and cloud edge interconnections; evaluating WAN infrastructure connectivity across direct connect, MPLS and segment routing, and IPsec VPN; troubleshooting DCI solutions covering EVPN VXLAN, EVPN over SR/MPLS, ACI, and pseudowires.

25%Joint heaviest
3.0 High Availability

VNF data plane redundancy through placement and network resiliency; control plane high availability within a single VIM; data plane high availability across compute, vNIC, and TOR; multi-homing; EVLAG; virtual private cloud; ECMP from NFVI to physical infrastructure using BGP multi-path, OSPF, and IS-IS; recommending HA design models for DNS, routing, and load balancers.

20%
4.0 Security

Infrastructure security using ACLs, uRPF, RTBH and router hardening, BGP FlowSpec, TACACS, and MACsec; DoS mitigation techniques; NFVI security covering API security, securing the NFVI control and management plane, network segmentation in a provider cloud, and TLS and mTLS; cloud security solutions such as DNS security, zero-day exploit protection, and virus detection.

15%
5.0 Service Assurance and Optimization

Network assurance across NFVI MANO, VNF workloads, VIM control plane KPIs, and streaming telemetry with gRPC and gNMI; cloud infrastructure and performance monitoring using SR-PM, NetFlow and IPFIX, syslog, SNMP traps and RMON, cloud agents, and automatic fault management; diagnosing NFVI errors and events; VNF optimization with SR-IOV and software accelerated virtual switching (DPDK and VPP).

15%

Source: Cisco — Designing and Implementing Cisco Service Provider Cloud Network Infrastructure v1.0 (300-540) exam topics. Cisco notes that other related topics may appear on any specific delivery of the exam.

Who the 300-540 SPCNI exam is for

SPCNI targets engineers working where the service provider network meets the cloud. Cisco sets no formal prerequisite, but the blueprint assumes you have actually deployed virtualized network functions and worked with an orchestration stack rather than only read about them.

  • Service provider cloud and NFV engineers who build and operate NFVI, onboard VNFs, and manage the virtualized infrastructure layer.
  • Network automation engineers working with NSO, NETCONF/RESTCONF, YANG models, and telemetry pipelines in a carrier environment.
  • Cloud interconnect and peering specialists designing connectivity into carrier-neutral facilities, hyperscaler direct connects, and DCI over EVPN VXLAN or SR/MPLS.
  • CCNP Service Provider candidates choosing a concentration after the 350-501 SPCOR core — SPCNI suits cloud and virtualization work, while 300-515 SPVI covers customer VPN services and 300-510 SPRI covers advanced routing.

If the automation half of the blueprint is your weak side, 200-901 DEVASC is a useful on-ramp to APIs and data models before attempting SPCNI. To see where cloud-facing infrastructure work leads in terms of roles and progression, review the cloud engineering career paths this certification supports.

What this 300-540 SPCNI practice exam delivers

Learn mode

Get the correct answer, why each distractor fails, and a direct link to the Cisco document behind it — immediately after each question. Most useful across the Virtualized Architecture domain, where MANO component roles are easy to confuse.

Exam mode

A full 90-minute timed simulation matching the real SPCNI sitting, so you build pacing on design-judgement questions that reward reading the scenario constraints carefully.

Source-linked explanations

Every answer cites the Cisco documentation it derives from — ESC and NFV MANO guides, IOS XR routing and telemetry guides, NFVIS networking, and the SPCNI exam topics — so you can verify rather than memorise.

Score by SPCNI domain

Results break down across the five real blueprint domains, so you know whether to revisit NFV orchestration, DCI troubleshooting, HA design, infrastructure security, or telemetry before your next attempt.

Sample 300-540 SPCNI practice questions

Ten free questions spread across the five current SPCNI domains, each with a full explanation and a source link to the Cisco documentation it was built from. The complete bank is available with the 24-hour trial.

Question 1 · Virtualized Architecture (25%)

Within the ETSI NFV MANO framework, which component is responsible for the lifecycle management of an individual VNF instance, including instantiation, scaling, healing, and termination?

  1. The Virtualized Infrastructure Manager
  2. The VNF Manager
  3. The Element Manager
  4. The Operations Support System
Show answer & explanation

Correct: B — the VNF Manager. The VNFM owns VNF lifecycle management operations. Cisco Elastic Services Controller performs this role, providing a single point of control for the full VNF lifecycle and exposing ETSI-compliant lifecycle management operations over its northbound API.

Why not the others: The VIM (A) manages the underlying compute, storage, and network resources such as OpenStack or vCenter, not the VNF lifecycle itself. The Element Manager (C) handles fault and configuration management of the running function, not instantiation and scaling. The OSS (D) sits above MANO in the operator's business and operations stack.

Source: Cisco — Elastic Services Controller and VNF lifecycle management → Further reading: PowerKram — How IT certification tracks are structured →
Question 2 · Virtualized Architecture (25%)

An operator wants a single protocol that can both push configuration to routers and stream operational telemetry from them, using a gRPC-based transport. Which interface fits?

  1. SNMP version 3
  2. NETCONF over SSH
  3. gNMI
  4. Syslog with structured formatting
Show answer & explanation

Correct: C — gNMI. The gRPC Network Management Interface is a gRPC-based protocol used to modify, install, or delete configuration on network devices and also to view operational data and generate telemetry streams — a single protocol covering both configuration management and telemetry.

Why not the others: SNMPv3 (A) is a polling-oriented management protocol without a gRPC transport or model-driven streaming. NETCONF over SSH (B) handles configuration well but is not the gRPC-based streaming telemetry interface described. Syslog (D) is one-way event logging with no configuration capability.

Source: Cisco — Model-driven telemetry, gRPC and gNMI →
Question 3 · Cloud Interconnect (25%)

Two VXLAN EVPN fabrics in separate data centres must be interconnected over an IP-only network, with failure containment so that a problem in one fabric does not propagate to the other. Which element terminates and interconnects the sites?

  1. A border gateway operating in anycast or vPC mode
  2. A spine switch peering directly with the remote spine
  3. A route reflector placed in the transit network
  4. A leaf switch with a direct VTEP tunnel to the remote leaf
Show answer & explanation

Correct: A — a border gateway in anycast or vPC mode. VXLAN EVPN Multi-Site interconnects two or more EVPN sites over an IP-only network using BGWs to terminate and interconnect sites, and it is the BGW that provides the control boundary delivering traffic enforcement and failure containment.

Why not the others: Direct spine-to-spine peering (B) or a direct leaf-to-leaf VTEP tunnel (D) bypasses the BGW boundary, which forfeits the failure containment the design exists to provide. A route reflector (C) scales BGP peering but performs no next-hop rewrite or site termination.

Source: Cisco — Configure VXLAN EVPN Multi-Site → Further reading: PowerKram — Network engineer role and career path →
Question 4 · Cloud Interconnect (25%)

A provider needs to reach several hyperscale cloud providers and multiple customer networks from one physical location without building dedicated long-haul circuits to each. Which facility type supports this?

  1. A single-tenant enterprise data centre
  2. A regional aggregation point-of-presence serving one carrier
  3. A customer premises equipment installation
  4. A carrier-neutral facility
Show answer & explanation

Correct: D — a carrier-neutral facility. Carrier-neutral facilities are exactly the blueprint's framing for cloud interconnect: they provide connectivity options to cloud providers, to other carrier-neutral facilities or customer locations, and to cloud edge interconnections, all from a shared, operator-independent location.

Why not the others: A single-tenant enterprise data centre (A) serves one organisation and offers no shared interconnect fabric. A single-carrier PoP (B) is by definition not neutral and limits reach to that carrier's footprint. CPE (C) sits at the customer edge and is not an interconnection venue.

Source: Cisco — SPCNI exam topics, Cloud Interconnect →
Question 5 · High Availability (20%)

An operator wants traffic from the NFVI to the physical network distributed across several equal-cost uplinks so that a single link failure removes only part of the capacity rather than all of it. Which approach delivers this?

  1. A single high-bandwidth uplink sized for peak load
  2. An active-standby pair where the standby carries no traffic
  3. Manual failover triggered by the monitoring system
  4. ECMP using BGP multi-path, OSPF, or IS-IS toward the physical infrastructure
Show answer & explanation

Correct: D — ECMP from NFVI to physical infrastructure. The blueprint calls out implementing ECMP from NFVI to the physical infrastructure using BGP multi-path, OSPF, and IS-IS. Equal-cost paths share the load, so losing one path degrades capacity proportionally instead of causing a full outage.

Why not the others: A single uplink (A) is a textbook single point of failure regardless of its bandwidth. Active-standby (B) provides redundancy but wastes the standby capacity and does not distribute load. Manual failover (C) introduces human reaction time into the recovery path.

Source: Cisco — SPCNI exam topics, High Availability →
Question 6 · High Availability (20%)

A VNF must survive the loss of a single compute node without dropping subscriber sessions. Which design consideration most directly addresses this requirement?

  1. Increasing the vCPU allocation of the existing VNF instance
  2. Enabling a larger MTU on the tenant network
  3. VNF data plane redundancy achieved through placement and network resiliency
  4. Scheduling more frequent snapshots of the VNF disk image
Show answer & explanation

Correct: C — data plane redundancy through placement and network resiliency. Surviving a node failure depends on where instances are placed relative to one another and on resilient network paths between them, which is precisely how the blueprint frames VNF data plane redundancy.

Why not the others: More vCPU (A) scales a single instance vertically and does nothing when the node hosting it fails. A larger MTU (B) is a throughput and fragmentation concern, unrelated to availability. Disk snapshots (D) aid recovery after the fact but do not preserve live sessions.

Source: Cisco — SPCNI exam topics, VNF redundancy and placement →
Question 7 · Security (15%)

During a DDoS event, an operator needs to filter traffic by source, destination, protocol, and Layer 4 ports across many edge routers at once, without blackholing the victim address entirely. Which mechanism fits?

  1. Destination-based remotely triggered blackhole filtering
  2. BGP FlowSpec
  3. Loose-mode unicast reverse path forwarding
  4. MACsec on the peering links
Show answer & explanation

Correct: B — BGP FlowSpec. FlowSpec propagates filtering and policing rules across many BGP peers rapidly, matching on source, destination, Layer 4 parameters, and packet specifics. Cisco contrasts it directly with RTBH, which protects the network but leaves the targeted server completely unreachable.

Why not the others: Destination-based RTBH (A) drops all traffic to the victim address, which is the outcome the question rules out. Loose uRPF (C) validates source reachability and supports source-based RTBH but offers no granular port or protocol matching. MACsec (D) encrypts a link and has no role in volumetric attack filtering.

Source: Cisco — Implementing BGP FlowSpec → Further reading: PowerKram — Enterprise security practices →
Question 8 · Security (15%)

An operator implements source-based RTBH filtering on IOS XR edge routers. Besides the route policy that discards the next hop, what must be enabled on the external-facing interfaces for source-based dropping to take effect?

  1. Unicast reverse path forwarding
  2. Bidirectional Forwarding Detection
  3. Storm control on the physical ports
  4. TACACS command authorization
Show answer & explanation

Correct: A — unicast reverse path forwarding. Source-based RTBH works by setting the next hop for an attacking source to discard, but the drop only happens where uRPF is checking the source address. Cisco's IOS XR guidance configures loose-mode uRPF on the border interfaces for exactly this reason.

Why not the others: BFD (B) accelerates failure detection between peers and has no role in source validation. Storm control (C) rate-limits broadcast and multicast on a port rather than filtering by source prefix. TACACS (D) governs administrative access to the device, not data-plane forwarding.

Source: Cisco — Source-based RTBH filtering with uRPF on ASR 9000 →
Question 9 · Service Assurance and Optimization (15%)

A VNF requires the lowest achievable packet-processing latency, and the design accepts that the VNF will bind directly to a NIC virtual function rather than traversing the host virtual switch. Which technology is being described?

  1. A standard Open vSwitch bridge in kernel mode
  2. VLAN trunking to the virtual machine
  3. Nested virtualization of the guest
  4. SR-IOV
Show answer & explanation

Correct: D — SR-IOV. Single Root I/O Virtualization allocates dedicated NIC resources to a specific VNF, delivering high performance and low latency by allowing direct memory access of network packets into the virtual machine's memory, bypassing the host software switch.

Why not the others: A kernel-mode OVS bridge (A) is the software path SR-IOV is chosen to avoid, and it incurs the context switching that limits throughput. VLAN trunking (B) is a segmentation mechanism with no bearing on packet-processing latency. Nested virtualization (C) adds a hypervisor layer and typically increases overhead.

Source: Cisco — NFVIS virtual networks: OVS, DPDK and SR-IOV → Further reading: PowerKram — Cloud engineer role and career path →
Question 10 · Service Assurance and Optimization (15%)

An operator configures the router to initiate the telemetry session outward to a collector rather than waiting for the collector to connect inbound. Which mode is in use, and what is its practical advantage?

  1. Dial-in mode, because the collector controls subscription lifetime
  2. Polling mode, because it reduces device CPU load
  3. Dial-out mode, because the router initiates the connection so inbound ports need not be opened
  4. Trap mode, because events are sent only on threshold breach
Show answer & explanation

Correct: C — dial-out mode. In dial-out mode the router dials out to the receiver to establish a subscription-based telemetry session. Because the router initiates the connection, there is no need to manage ports for inbound traffic, and this is the default mode of operation.

Why not the others: Dial-in mode (A) reverses the roles, with the collector connecting to a gRPC server on the router, which does require inbound port management. Polling (B) describes the pull-based SNMP style that model-driven telemetry replaces. Trap mode (D) is SNMP terminology and is not how streaming telemetry subscriptions are described.

Source: Cisco — Telemetry dial-out and dial-in modes →

Keep going: Learning & Career resources

Cloud infrastructure work rewards depth in both the networking and the automation half of the job. Two PowerKram hubs back this exam.

Deep dive: SPCNI format, scoring, study path, and how it fits CCNP Service Provider

Exam format and how it is scored

SPCNI is a 90-minute exam delivered in English through Pearson VUE, at a test centre or online with a proctor. Cisco does not publish a fixed item count or a fixed passing score; cut scores are established through psychometric analysis and are not disclosed, so any specific pass percentage or question count quoted on a third-party site is an estimate rather than a published figure. Expect multiple choice and multiple response items, with a strong design-judgement flavour given how many blueprint sub-topics begin with describe, determine, evaluate, or recommend. See how certification exams are structured →

How SPCNI fits the CCNP Service Provider track

CCNP Service Provider requires two exams: the 350-501 SPCOR core plus one concentration. SPCNI is one of four concentration choices alongside 300-510 SPRI (advanced routing), 300-515 SPVI (VPN services), and 300-535 SPAUTO (automation). Passing SPCNI alone still earns the standalone Cisco Certified Specialist – Service Provider Cloud Network Infrastructure credential, which is useful if you want a milestone before committing to the core exam. Of the four, SPCNI overlaps most with SPAUTO on the automation side, so candidates already strong in NSO and model-driven interfaces often find those two mutually reinforcing. Compare the SPVI concentration →

Where candidates lose marks

Three patterns recur. First, underestimating the automation content: NSO, NETCONF, RESTCONF, YANG, gNMI, gRPC, and OpenStack are all named explicitly in domain 1, and a routing-only background leaves a quarter of the exam exposed. Second, blurring the MANO components — VIM, VNFM, and NFVO have distinct responsibilities, and questions are written to test exactly that boundary. Third, treating the security domain as generic cybersecurity when it is specifically provider infrastructure security: uRPF, RTBH, BGP FlowSpec, MACsec, and NFVI control-plane protection. Virtualized Architecture and Cloud Interconnect together are half the exam, so a gap in either is costly.

Realistic study path

Most candidates with provider cloud exposure need eight to twelve weeks. A workable sequence: read the v1.0 exam topics document and mark every sub-topic you have not personally implemented; close the virtualization gaps with the Cisco ESC and NFV MANO documentation and hands-on time in an OpenStack or NFVIS environment; work the interconnect material against the VXLAN EVPN and DCI guides; then build a telemetry pipeline end to end, because configuring dial-out subscriptions once teaches more than reading about them repeatedly. Cisco publishes a guided learning path for this exam. Cisco SPCNI exam page and training options →

Cost, scheduling, and recertification

The exam is $300 USD, or you can redeem Cisco Learning Credits; regional pricing varies. Scheduling runs through the Cisco certification portal into Pearson VUE. CCNP-level certifications are valid for three years, and Cisco offers several recertification routes: pass one technology core exam, pass any two professional concentration exams, pass a CCIE lab, or earn 80 Continuing Education credits. The requirement must be met before the expiry date — letting a certification lapse means repeating the full process. Cisco CCNP Service Provider certification page →

Career outlook for SPCNI-credentialed engineers

SPCNI signals something increasingly scarce: an engineer who understands both carrier networking and the virtualization and automation stack running on top of it. That combination maps to telecom cloud and NFV teams, hyperscaler interconnect and peering roles, managed service providers building cloud-adjacent offerings, and platform teams at operators moving toward disaggregated infrastructure. It pairs naturally with automation credentials and with hands-on Kubernetes or OpenStack experience, since the blueprint's orchestration content is where most of the day-to-day work now sits. Cloud engineering career paths →

Frequently asked questions about the 300-540 SPCNI exam

What are the 300-540 SPCNI exam domains and their weights?
Cisco's v1.0 exam topics list five domains: Virtualized Architecture at 25%, Cloud Interconnect at 25%, High Availability at 20%, Security at 15%, and Service Assurance and Optimization at 15%. Virtualized Architecture and Cloud Interconnect are tied as the heaviest areas and together make up half the exam.
What is the passing score for the 300-540 SPCNI exam?
Cisco does not publish a fixed passing score for SPCNI. Cut scores are set through psychometric analysis and are not disclosed, and Cisco likewise does not publish a fixed question count for this exam. Any specific number quoted elsewhere is an estimate rather than a published figure.
How much automation and programmability is on the 300-540 SPCNI exam?
A substantial amount. The Virtualized Architecture domain alone names NFV, VNF, NSO, NETCONF, RESTCONF and REST APIs, YANG models with gNMI and gRPC, and OpenStack, and the Service Assurance domain adds streaming telemetry. Candidates from a routing-only background usually need dedicated preparation here.
Are there prerequisites for the 300-540 SPCNI exam?
There is no formal prerequisite. In practice the blueprint assumes hands-on experience with NFV and virtualization platforms, cloud interconnect design, and service provider automation tooling, so the exam targets practising engineers rather than newcomers.
How much does 300-540 SPCNI cost and how long is it?
The exam is 90 minutes and costs $300 USD, or you can redeem Cisco Learning Credits. Regional pricing varies. It is delivered in English through Pearson VUE, at a test centre or online with a proctor.
What certification do I earn by passing 300-540 SPCNI?
Passing SPCNI earns the Cisco Certified Specialist – Service Provider Cloud Network Infrastructure certification. It also satisfies the concentration-exam requirement for CCNP Service Provider when combined with the 350-501 SPCOR core exam, and can be applied toward recertification.

Start your free 24-hour 300-540 SPCNI practice trial

Full access to the question bank, both study modes, source-linked explanations, and score-by-domain reporting. No credit card required.

Start free trial →