Cisco 300-540 SPCNI Cloud Network Infrastructure Practice Exam
Cover all five SPCNI v1.0 domains — Virtualized Architecture, Cloud Interconnect, High Availability, Security, and Service Assurance & Optimization — with objective-mapped questions, instant feedback in Learn mode, and a full timed simulation in Exam mode.
Start 24-hour free trial →300-540 SPCNI exam at a glance
- Vendor
- Cisco
- Exam code
- 300-540
- Exam name
- Designing and Implementing Cisco Service Provider Cloud Network Infrastructure (SPCNI)
- Blueprint
- Cisco exam topics v1.0 — five domains weighted 25 / 25 / 20 / 15 / 15
- Certification earned
- Cisco Certified Specialist – Service Provider Cloud Network Infrastructure
- Counts toward
- CCNP Service Provider (satisfies the concentration-exam requirement alongside the 350-501 SPCOR core)
- Duration
- 90 minutes
- Question count
- Cisco does not publish a fixed item count for this exam
- Passing score
- Cisco does not publish a fixed passing score; cut scores are set by psychometric analysis and are not disclosed
- Prerequisites
- None formally required. Cisco recommends hands-on experience with NFV, virtualization platforms, cloud interconnect, and service provider automation.
- Cost (USD)
- $300 USD, or redeem Cisco Learning Credits (regional pricing varies)
- Delivery
- Pearson VUE test center or online proctored; scheduled through the Cisco certification portal
- Languages
- English
- Validity
- 3 years (CCNP-level); recertify by exam or by earning 80 Continuing Education credits
Sources: Cisco — 300-540 SPCNI exam page · Cisco — SPCNI v1.0 exam topics (PDF). Verify current details with Cisco before scheduling.
About the Cisco 300-540 SPCNI certification
SPCNI is the newest and least conventional of the four CCNP Service Provider concentration exams. Pass it and you earn the standalone Cisco Certified Specialist – Service Provider Cloud Network Infrastructure credential; pair it with the 350-501 SPCOR core exam and you complete the full CCNP Service Provider certification. What makes it unusual is how far it sits from traditional routing and switching: a large share of the blueprint is virtualization, orchestration, and API-driven automation rather than protocol configuration.
The blueprint verbs tell the story. SPCNI asks you to describe cloud service models and carrier-neutral facilities, implement virtualization functions and high-availability designs, deploy NFV using automation, and troubleshoot data-center-interconnect solutions. That means real fluency with NFV and VNF concepts, Cisco NSO, NETCONF, RESTCONF and REST APIs, YANG models, gNMI and gRPC, and OpenStack — alongside the interconnect and security material a service provider engineer would expect. Candidates who arrive from a pure routing background are usually surprised by how much of the exam is orchestration and telemetry rather than CLI.
Every PowerKram question maps to one of the five v1.0 domains and cites the Cisco document it was derived from, so a weak score turns into a specific reading list instead of a vague instruction to study harder. For the broader context on how vendor certification tracks fit together, see our guide to how IT certification tracks are structured.
300-540 SPCNI exam domains and weights
Cisco publishes five weighted domains in the v1.0 exam topics document. The weights sum to 100%. Virtualized Architecture and Cloud Interconnect are tied as the heaviest areas at 25% each, and together account for half the exam.
IaaS constraints such as VLAN scale and segmentation; determining the cloud service model (IaaS, PaaS, SaaS, FaaS) for private, public, or hybrid deployments; container orchestration and virtual machines; implementing NFV, VNF, NSO, and virtualized Cisco platforms; deploying NFV with automation including VNF onboarding, NSO orchestration, NETCONF/RESTCONF/REST APIs, YANG models with gNMI and gRPC, and OpenStack.
Carrier-neutral facilities including connectivity options to cloud providers, to other carrier-neutral facilities or customer locations, and cloud edge interconnections; evaluating WAN infrastructure connectivity across direct connect, MPLS and segment routing, and IPsec VPN; troubleshooting DCI solutions covering EVPN VXLAN, EVPN over SR/MPLS, ACI, and pseudowires.
VNF data plane redundancy through placement and network resiliency; control plane high availability within a single VIM; data plane high availability across compute, vNIC, and TOR; multi-homing; EVLAG; virtual private cloud; ECMP from NFVI to physical infrastructure using BGP multi-path, OSPF, and IS-IS; recommending HA design models for DNS, routing, and load balancers.
Infrastructure security using ACLs, uRPF, RTBH and router hardening, BGP FlowSpec, TACACS, and MACsec; DoS mitigation techniques; NFVI security covering API security, securing the NFVI control and management plane, network segmentation in a provider cloud, and TLS and mTLS; cloud security solutions such as DNS security, zero-day exploit protection, and virus detection.
Network assurance across NFVI MANO, VNF workloads, VIM control plane KPIs, and streaming telemetry with gRPC and gNMI; cloud infrastructure and performance monitoring using SR-PM, NetFlow and IPFIX, syslog, SNMP traps and RMON, cloud agents, and automatic fault management; diagnosing NFVI errors and events; VNF optimization with SR-IOV and software accelerated virtual switching (DPDK and VPP).
Source: Cisco — Designing and Implementing Cisco Service Provider Cloud Network Infrastructure v1.0 (300-540) exam topics. Cisco notes that other related topics may appear on any specific delivery of the exam.
Who the 300-540 SPCNI exam is for
SPCNI targets engineers working where the service provider network meets the cloud. Cisco sets no formal prerequisite, but the blueprint assumes you have actually deployed virtualized network functions and worked with an orchestration stack rather than only read about them.
- Service provider cloud and NFV engineers who build and operate NFVI, onboard VNFs, and manage the virtualized infrastructure layer.
- Network automation engineers working with NSO, NETCONF/RESTCONF, YANG models, and telemetry pipelines in a carrier environment.
- Cloud interconnect and peering specialists designing connectivity into carrier-neutral facilities, hyperscaler direct connects, and DCI over EVPN VXLAN or SR/MPLS.
- CCNP Service Provider candidates choosing a concentration after the 350-501 SPCOR core — SPCNI suits cloud and virtualization work, while 300-515 SPVI covers customer VPN services and 300-510 SPRI covers advanced routing.
If the automation half of the blueprint is your weak side, 200-901 DEVASC is a useful on-ramp to APIs and data models before attempting SPCNI. To see where cloud-facing infrastructure work leads in terms of roles and progression, review the cloud engineering career paths this certification supports.
What this 300-540 SPCNI practice exam delivers
Learn mode
Get the correct answer, why each distractor fails, and a direct link to the Cisco document behind it — immediately after each question. Most useful across the Virtualized Architecture domain, where MANO component roles are easy to confuse.
Exam mode
A full 90-minute timed simulation matching the real SPCNI sitting, so you build pacing on design-judgement questions that reward reading the scenario constraints carefully.
Source-linked explanations
Every answer cites the Cisco documentation it derives from — ESC and NFV MANO guides, IOS XR routing and telemetry guides, NFVIS networking, and the SPCNI exam topics — so you can verify rather than memorise.
Score by SPCNI domain
Results break down across the five real blueprint domains, so you know whether to revisit NFV orchestration, DCI troubleshooting, HA design, infrastructure security, or telemetry before your next attempt.
Sample 300-540 SPCNI practice questions
Ten free questions spread across the five current SPCNI domains, each with a full explanation and a source link to the Cisco documentation it was built from. The complete bank is available with the 24-hour trial.
Within the ETSI NFV MANO framework, which component is responsible for the lifecycle management of an individual VNF instance, including instantiation, scaling, healing, and termination?
- The Virtualized Infrastructure Manager
- The VNF Manager
- The Element Manager
- The Operations Support System
Show answer & explanation
Correct: B — the VNF Manager. The VNFM owns VNF lifecycle management operations. Cisco Elastic Services Controller performs this role, providing a single point of control for the full VNF lifecycle and exposing ETSI-compliant lifecycle management operations over its northbound API.
Why not the others: The VIM (A) manages the underlying compute, storage, and network resources such as OpenStack or vCenter, not the VNF lifecycle itself. The Element Manager (C) handles fault and configuration management of the running function, not instantiation and scaling. The OSS (D) sits above MANO in the operator's business and operations stack.
Source: Cisco — Elastic Services Controller and VNF lifecycle management → Further reading: PowerKram — How IT certification tracks are structured →An operator wants a single protocol that can both push configuration to routers and stream operational telemetry from them, using a gRPC-based transport. Which interface fits?
- SNMP version 3
- NETCONF over SSH
- gNMI
- Syslog with structured formatting
Show answer & explanation
Correct: C — gNMI. The gRPC Network Management Interface is a gRPC-based protocol used to modify, install, or delete configuration on network devices and also to view operational data and generate telemetry streams — a single protocol covering both configuration management and telemetry.
Why not the others: SNMPv3 (A) is a polling-oriented management protocol without a gRPC transport or model-driven streaming. NETCONF over SSH (B) handles configuration well but is not the gRPC-based streaming telemetry interface described. Syslog (D) is one-way event logging with no configuration capability.
Source: Cisco — Model-driven telemetry, gRPC and gNMI →Two VXLAN EVPN fabrics in separate data centres must be interconnected over an IP-only network, with failure containment so that a problem in one fabric does not propagate to the other. Which element terminates and interconnects the sites?
- A border gateway operating in anycast or vPC mode
- A spine switch peering directly with the remote spine
- A route reflector placed in the transit network
- A leaf switch with a direct VTEP tunnel to the remote leaf
Show answer & explanation
Correct: A — a border gateway in anycast or vPC mode. VXLAN EVPN Multi-Site interconnects two or more EVPN sites over an IP-only network using BGWs to terminate and interconnect sites, and it is the BGW that provides the control boundary delivering traffic enforcement and failure containment.
Why not the others: Direct spine-to-spine peering (B) or a direct leaf-to-leaf VTEP tunnel (D) bypasses the BGW boundary, which forfeits the failure containment the design exists to provide. A route reflector (C) scales BGP peering but performs no next-hop rewrite or site termination.
Source: Cisco — Configure VXLAN EVPN Multi-Site → Further reading: PowerKram — Network engineer role and career path →A provider needs to reach several hyperscale cloud providers and multiple customer networks from one physical location without building dedicated long-haul circuits to each. Which facility type supports this?
- A single-tenant enterprise data centre
- A regional aggregation point-of-presence serving one carrier
- A customer premises equipment installation
- A carrier-neutral facility
Show answer & explanation
Correct: D — a carrier-neutral facility. Carrier-neutral facilities are exactly the blueprint's framing for cloud interconnect: they provide connectivity options to cloud providers, to other carrier-neutral facilities or customer locations, and to cloud edge interconnections, all from a shared, operator-independent location.
Why not the others: A single-tenant enterprise data centre (A) serves one organisation and offers no shared interconnect fabric. A single-carrier PoP (B) is by definition not neutral and limits reach to that carrier's footprint. CPE (C) sits at the customer edge and is not an interconnection venue.
Source: Cisco — SPCNI exam topics, Cloud Interconnect →An operator wants traffic from the NFVI to the physical network distributed across several equal-cost uplinks so that a single link failure removes only part of the capacity rather than all of it. Which approach delivers this?
- A single high-bandwidth uplink sized for peak load
- An active-standby pair where the standby carries no traffic
- Manual failover triggered by the monitoring system
- ECMP using BGP multi-path, OSPF, or IS-IS toward the physical infrastructure
Show answer & explanation
Correct: D — ECMP from NFVI to physical infrastructure. The blueprint calls out implementing ECMP from NFVI to the physical infrastructure using BGP multi-path, OSPF, and IS-IS. Equal-cost paths share the load, so losing one path degrades capacity proportionally instead of causing a full outage.
Why not the others: A single uplink (A) is a textbook single point of failure regardless of its bandwidth. Active-standby (B) provides redundancy but wastes the standby capacity and does not distribute load. Manual failover (C) introduces human reaction time into the recovery path.
Source: Cisco — SPCNI exam topics, High Availability →A VNF must survive the loss of a single compute node without dropping subscriber sessions. Which design consideration most directly addresses this requirement?
- Increasing the vCPU allocation of the existing VNF instance
- Enabling a larger MTU on the tenant network
- VNF data plane redundancy achieved through placement and network resiliency
- Scheduling more frequent snapshots of the VNF disk image
Show answer & explanation
Correct: C — data plane redundancy through placement and network resiliency. Surviving a node failure depends on where instances are placed relative to one another and on resilient network paths between them, which is precisely how the blueprint frames VNF data plane redundancy.
Why not the others: More vCPU (A) scales a single instance vertically and does nothing when the node hosting it fails. A larger MTU (B) is a throughput and fragmentation concern, unrelated to availability. Disk snapshots (D) aid recovery after the fact but do not preserve live sessions.
Source: Cisco — SPCNI exam topics, VNF redundancy and placement →During a DDoS event, an operator needs to filter traffic by source, destination, protocol, and Layer 4 ports across many edge routers at once, without blackholing the victim address entirely. Which mechanism fits?
- Destination-based remotely triggered blackhole filtering
- BGP FlowSpec
- Loose-mode unicast reverse path forwarding
- MACsec on the peering links
Show answer & explanation
Correct: B — BGP FlowSpec. FlowSpec propagates filtering and policing rules across many BGP peers rapidly, matching on source, destination, Layer 4 parameters, and packet specifics. Cisco contrasts it directly with RTBH, which protects the network but leaves the targeted server completely unreachable.
Why not the others: Destination-based RTBH (A) drops all traffic to the victim address, which is the outcome the question rules out. Loose uRPF (C) validates source reachability and supports source-based RTBH but offers no granular port or protocol matching. MACsec (D) encrypts a link and has no role in volumetric attack filtering.
Source: Cisco — Implementing BGP FlowSpec → Further reading: PowerKram — Enterprise security practices →An operator implements source-based RTBH filtering on IOS XR edge routers. Besides the route policy that discards the next hop, what must be enabled on the external-facing interfaces for source-based dropping to take effect?
- Unicast reverse path forwarding
- Bidirectional Forwarding Detection
- Storm control on the physical ports
- TACACS command authorization
Show answer & explanation
Correct: A — unicast reverse path forwarding. Source-based RTBH works by setting the next hop for an attacking source to discard, but the drop only happens where uRPF is checking the source address. Cisco's IOS XR guidance configures loose-mode uRPF on the border interfaces for exactly this reason.
Why not the others: BFD (B) accelerates failure detection between peers and has no role in source validation. Storm control (C) rate-limits broadcast and multicast on a port rather than filtering by source prefix. TACACS (D) governs administrative access to the device, not data-plane forwarding.
Source: Cisco — Source-based RTBH filtering with uRPF on ASR 9000 →A VNF requires the lowest achievable packet-processing latency, and the design accepts that the VNF will bind directly to a NIC virtual function rather than traversing the host virtual switch. Which technology is being described?
- A standard Open vSwitch bridge in kernel mode
- VLAN trunking to the virtual machine
- Nested virtualization of the guest
- SR-IOV
Show answer & explanation
Correct: D — SR-IOV. Single Root I/O Virtualization allocates dedicated NIC resources to a specific VNF, delivering high performance and low latency by allowing direct memory access of network packets into the virtual machine's memory, bypassing the host software switch.
Why not the others: A kernel-mode OVS bridge (A) is the software path SR-IOV is chosen to avoid, and it incurs the context switching that limits throughput. VLAN trunking (B) is a segmentation mechanism with no bearing on packet-processing latency. Nested virtualization (C) adds a hypervisor layer and typically increases overhead.
Source: Cisco — NFVIS virtual networks: OVS, DPDK and SR-IOV → Further reading: PowerKram — Cloud engineer role and career path →An operator configures the router to initiate the telemetry session outward to a collector rather than waiting for the collector to connect inbound. Which mode is in use, and what is its practical advantage?
- Dial-in mode, because the collector controls subscription lifetime
- Polling mode, because it reduces device CPU load
- Dial-out mode, because the router initiates the connection so inbound ports need not be opened
- Trap mode, because events are sent only on threshold breach
Show answer & explanation
Correct: C — dial-out mode. In dial-out mode the router dials out to the receiver to establish a subscription-based telemetry session. Because the router initiates the connection, there is no need to manage ports for inbound traffic, and this is the default mode of operation.
Why not the others: Dial-in mode (A) reverses the roles, with the collector connecting to a gRPC server on the router, which does require inbound port management. Polling (B) describes the pull-based SNMP style that model-driven telemetry replaces. Trap mode (D) is SNMP terminology and is not how streaming telemetry subscriptions are described.
Source: Cisco — Telemetry dial-out and dial-in modes →Keep going: Learning & Career resources
Cloud infrastructure work rewards depth in both the networking and the automation half of the job. Two PowerKram hubs back this exam.
Deep dive: SPCNI format, scoring, study path, and how it fits CCNP Service Provider
Exam format and how it is scored
SPCNI is a 90-minute exam delivered in English through Pearson VUE, at a test centre or online with a proctor. Cisco does not publish a fixed item count or a fixed passing score; cut scores are established through psychometric analysis and are not disclosed, so any specific pass percentage or question count quoted on a third-party site is an estimate rather than a published figure. Expect multiple choice and multiple response items, with a strong design-judgement flavour given how many blueprint sub-topics begin with describe, determine, evaluate, or recommend. See how certification exams are structured →
How SPCNI fits the CCNP Service Provider track
CCNP Service Provider requires two exams: the 350-501 SPCOR core plus one concentration. SPCNI is one of four concentration choices alongside 300-510 SPRI (advanced routing), 300-515 SPVI (VPN services), and 300-535 SPAUTO (automation). Passing SPCNI alone still earns the standalone Cisco Certified Specialist – Service Provider Cloud Network Infrastructure credential, which is useful if you want a milestone before committing to the core exam. Of the four, SPCNI overlaps most with SPAUTO on the automation side, so candidates already strong in NSO and model-driven interfaces often find those two mutually reinforcing. Compare the SPVI concentration →
Where candidates lose marks
Three patterns recur. First, underestimating the automation content: NSO, NETCONF, RESTCONF, YANG, gNMI, gRPC, and OpenStack are all named explicitly in domain 1, and a routing-only background leaves a quarter of the exam exposed. Second, blurring the MANO components — VIM, VNFM, and NFVO have distinct responsibilities, and questions are written to test exactly that boundary. Third, treating the security domain as generic cybersecurity when it is specifically provider infrastructure security: uRPF, RTBH, BGP FlowSpec, MACsec, and NFVI control-plane protection. Virtualized Architecture and Cloud Interconnect together are half the exam, so a gap in either is costly.
Realistic study path
Most candidates with provider cloud exposure need eight to twelve weeks. A workable sequence: read the v1.0 exam topics document and mark every sub-topic you have not personally implemented; close the virtualization gaps with the Cisco ESC and NFV MANO documentation and hands-on time in an OpenStack or NFVIS environment; work the interconnect material against the VXLAN EVPN and DCI guides; then build a telemetry pipeline end to end, because configuring dial-out subscriptions once teaches more than reading about them repeatedly. Cisco publishes a guided learning path for this exam. Cisco SPCNI exam page and training options →
Cost, scheduling, and recertification
The exam is $300 USD, or you can redeem Cisco Learning Credits; regional pricing varies. Scheduling runs through the Cisco certification portal into Pearson VUE. CCNP-level certifications are valid for three years, and Cisco offers several recertification routes: pass one technology core exam, pass any two professional concentration exams, pass a CCIE lab, or earn 80 Continuing Education credits. The requirement must be met before the expiry date — letting a certification lapse means repeating the full process. Cisco CCNP Service Provider certification page →
Career outlook for SPCNI-credentialed engineers
SPCNI signals something increasingly scarce: an engineer who understands both carrier networking and the virtualization and automation stack running on top of it. That combination maps to telecom cloud and NFV teams, hyperscaler interconnect and peering roles, managed service providers building cloud-adjacent offerings, and platform teams at operators moving toward disaggregated infrastructure. It pairs naturally with automation credentials and with hands-on Kubernetes or OpenStack experience, since the blueprint's orchestration content is where most of the day-to-day work now sits. Cloud engineering career paths →
Frequently asked questions about the 300-540 SPCNI exam
What are the 300-540 SPCNI exam domains and their weights?
What is the passing score for the 300-540 SPCNI exam?
How much automation and programmability is on the 300-540 SPCNI exam?
Are there prerequisites for the 300-540 SPCNI exam?
How much does 300-540 SPCNI cost and how long is it?
What certification do I earn by passing 300-540 SPCNI?
Start your free 24-hour 300-540 SPCNI practice trial
Full access to the question bank, both study modes, source-linked explanations, and score-by-domain reporting. No credit card required.
Start free trial →