Showing posts with label Cisco. Show all posts
Showing posts with label Cisco. Show all posts

Monday, 3 August 2026

AI Planning Strategies Explained for Network Engineers: From ReAct to Tree of Thoughts

 Artificial Intelligence is rapidly becoming a key part of modern network operations. Whether you are managing a Cisco ACI fabric, troubleshooting Nexus switches, automating configuration changes, or investigating performance issues across multiple sites, understanding how AI agents think and execute tasks can help you work more efficiently.

In this article, we will explore some popular AI planning strategies and how they relate to real-world networking scenarios. These concepts are becoming increasingly important as AI-powered network automation tools continue to evolve.


Why AI Planning Matters in Networking

Network engineers often deal with complex tasks that require investigation, decision-making, and execution across multiple systems.

Consider the following situations:

  • Investigating latency between data centers
  • Validating a network migration plan
  • Automating configuration deployment
  • Troubleshooting application connectivity issues
  • Reviewing security policy changes

A simple AI response is often not enough. The AI needs a structured approach to analyze, plan, execute, and validate actions.

This is where AI planning architectures come into play.


Single-Step ReAct: Best for Simple Questions

Single-Step ReAct is designed for straightforward tasks that require a single action or response.

Example

Question: What is the CPU utilization on Router R1?

The AI simply gathers the required information and returns the answer.

Networking Use Cases

  • Checking interface status
  • Displaying CPU utilization
  • Viewing BGP neighbor state
  • Finding VLAN information
  • Retrieving device inventory

For routine operational checks, Single-Step ReAct provides quick and efficient results.


Multi-Step ReAct: Structured Task Execution

Some networking tasks involve multiple actions performed in a predefined sequence.

Multi-Step ReAct breaks the task into several actions and executes them one after another.

Example

A network engineer needs to:

  1. Restart a network service
  2. Verify successful recovery
  3. Collect logs
  4. Document the change

The AI follows each step until the complete workflow is finished.

Networking Use Cases

  • Change validation procedures
  • Device onboarding workflows
  • Backup and restore operations
  • Configuration compliance checks
  • Regular maintenance activities

This approach is particularly useful when procedures are well-defined and repeatable.


Plan-and-Execute: Ideal for Complex Troubleshooting

One of the most powerful AI architectures is the Plan-and-Execute model.

Instead of jumping directly into action, the AI first creates a detailed execution plan.

Only after the plan is reviewed and approved does it begin execution.

Benefits of Plan-and-Execute

BenefitDescription
VisibilityReview the complete plan before execution
ControlPause or modify actions when needed
ReusabilitySave plans for future use
Easier TroubleshootingQuickly identify failed steps

Networking Example

Imagine users across three global regions report application slowness.

Rather than randomly checking devices, the AI may create a plan such as:

  1. Validate WAN connectivity
  2. Review routing changes
  3. Analyze interface errors
  4. Check data center fabric health
  5. Verify application path latency
  6. Correlate logs and events

This approach reduces wasted effort and improves troubleshooting efficiency.


Tree of Thoughts: Exploring Multiple Solutions

Experienced network engineers rarely stop at the first possible solution.

The Tree of Thoughts methodology follows the same principle.

Instead of selecting a single path immediately, the AI evaluates several possible approaches before choosing the best one.

Example

A company wants to design a new data center network.

Possible options include:

  • Cisco ACI
  • EVPN-VXLAN
  • Traditional Three-Tier Architecture
  • Spine-Leaf Architecture

The AI analyzes each approach, compares advantages and disadvantages, and recommends the most suitable design.

Networking Use Cases

  • Data center design decisions
  • Cloud migration planning
  • Security architecture reviews
  • SD-WAN deployment strategies
  • Technology evaluation exercises

This method improves decision quality by considering multiple possibilities.


Self-Reflection: Continuous Improvement

Self-Reflection enables AI to review and evaluate its own progress.

After completing a task, the AI asks questions such as:

  • Did the action solve the issue?
  • Is there enough evidence?
  • Are additional checks required?
  • Can the result be improved?

Networking Example

An AI agent generates a firewall security policy.

Before presenting the final output, it reviews the policy for:

  • Missing rules
  • Security gaps
  • Business requirements
  • Compliance standards

The result is often more accurate and reliable.

Networking Use Cases

  • Security policy generation
  • Compliance reporting
  • Network design reviews
  • Migration planning
  • Automation script validation

Which AI Strategy Should You Use?

ScenarioRecommended Approach
Checking router CPU usageSingle-Step ReAct
Running operational workflowMulti-Step ReAct
Investigating network-wide performance issuesPlan-and-Execute
Designing a new network architectureTree of Thoughts
Creating security policies or reportsSelf-Reflection

Selecting the appropriate strategy improves efficiency, reduces errors, and delivers more reliable results.


Final Thoughts

AI is becoming an essential tool for network engineers. Understanding how AI agents plan, reason, and execute tasks can help organizations build smarter automation workflows and improve operational efficiency.

Whether you are managing enterprise campuses, data centers, cloud networks, Cisco ACI fabrics, or network automation platforms, these AI planning strategies provide a framework for solving problems more effectively.

The future of networking will not just involve automation. It will involve intelligent systems capable of planning, reasoning, and continuously improving their decisions.

Friday, 24 July 2026

Understanding AI Agents for Network Engineers: LLMs, Prompts, Tokens and Context Explained

Artificial Intelligence is rapidly becoming part of modern network operations. From troubleshooting assistants to automated change management, AI agents are beginning to work alongside network engineers.

But what exactly powers these agents?

If you've configured routing protocols, built automation scripts, or managed network monitoring systems, understanding AI agents isn't as complicated as it might seem. This guide walks through the core building blocks of AI agents using networking analogies that any network engineer will recognize.

What Is an AI Agent?

An AI agent is a software system that can understand a goal, make decisions, and take actions to achieve that goal.

Compare it to a traditional network automation script. A Python script might be programmed to check interface status, detect a down link, and send an alert — it follows predefined instructions, nothing more.

An AI agent works differently. Instead of following a fixed set of rules, it can:

  • Understand a request written in natural language
  • Analyze available information
  • Decide which action to perform
  • Adapt when unexpected situations occur

That flexibility is what makes AI agents powerful.

Traditional Automation vs. AI Agents

Traditional automation follows rigid logic, such as IF Interface Down → Send Email. It's predictable, easy to troubleshoot, and great for repetitive tasks — but it cannot handle unknown scenarios and lacks contextual understanding.

AI-powered agents focus on outcomes rather than rigid instructions. Given a prompt like "Analyze this network outage and suggest possible root causes," an agent can review logs, analyze symptoms, identify possible issues, and recommend troubleshooting steps. It understands natural language, adapts to new situations, and can handle partially known problems.

The LLM: The Brain Behind Every AI Agent

At the center of every AI agent is a Large Language Model (LLM) — think of it as the control plane of the system. Just as a network's control plane makes routing decisions, the LLM makes reasoning decisions: understanding requests, processing information, choosing tools, and generating responses. Without the LLM, an AI agent is just a collection of disconnected tools.

Why the System Prompt Matters

The System Prompt is like a design document combined with operating procedures. It tells the AI who it is, what it should do, what to avoid, and which tools it can use — for example: "You are a Network Operations Assistant. Help engineers troubleshoot enterprise networks. Explain reasoning clearly. Use available monitoring tools when necessary." Without a solid system prompt, an AI agent can produce inconsistent or irrelevant responses.

Understanding Temperature: The Creativity Dial

Temperature controls how predictable or creative an AI's output is.

  • Temperature = 0 — the model always picks the most likely answer. Best for troubleshooting, configuration validation, and change management, where consistency and accuracy matter most.
  • Higher temperature — more creative and exploratory output, useful for brainstorming and content generation, but with a higher risk of inconsistent answers and hallucinations.

For network operations, a range of 0 to 0.3 is generally preferred.

What Are Tokens?

A token is a small unit of text processed by an LLM. As a rough rule of thumb, one token is about 4 English characters, and 100 words is roughly 130 tokens. Tokens directly affect processing cost, response speed, and context limits.

The Context Window: AI's Working Memory

The context window is effectively the RAM of an AI agent — it holds the system prompt, tool definitions, conversation history, and the current request. The larger the window, the more the AI can "remember" during a session.

Just as troubleshooting gets harder if a monitoring system forgets earlier alerts mid-investigation, an AI agent's performance can degrade once its context window fills up: older details get dropped, and accuracy can suffer. Efficient context management is essential for enterprise AI solutions.

Other Important AI Agent Parameters

  • Max Tokens — the output limit for a single response, like a bandwidth cap.
  • Stop Sequences — signals that tell the model when to stop generating, often used when calling external tools or handing control back to a user or system.
  • Top-P — controls how many candidate next-words the model considers; lower values are more focused, higher values more diverse.
  • Frequency Penalty — reduces repetitive language, useful when generating reports, documentation, and troubleshooting guides.

Real-World Network Engineering Use Cases

  • Network troubleshooting — log analysis, root cause identification, incident summaries
  • Configuration assistance — config review, error detection, best-practice recommendations
  • Documentation generation — design docs, change records, runbooks
  • Knowledge management — searching engineering documentation, answering technical questions, step-by-step procedures

Key Takeaways

  • LLMs act as the reasoning engine of AI agents
  • System prompts define behavior and scope
  • Temperature controls creativity and consistency
  • Tokens are the building blocks of AI processing
  • Context windows determine what the agent can remember
  • Proper configuration leads to more reliable AI agents

Final Thoughts

Just as networking evolved from manual CLI configuration to automation, the industry is now entering an era of intelligent, AI-assisted operations. Understanding LLMs, prompts, temperature, and context windows gives network engineers the foundation to work with this next generation of tools — and you don't need to become a data scientist to get there. If you already understand how networks make decisions, you're closer to understanding AI than you might think.

FAQ

What is an AI agent?

A software system that uses an LLM to understand goals, make decisions, and perform tasks — adapting to new situations rather than following fixed rules.

How is it different from traditional network automation?

Traditional automation follows fixed rules ("if interface down, alert"). An AI agent can handle open-ended requests ("investigate why Branch A is slow") by analyzing logs and configs and reasoning about likely causes.

Can AI agents replace network engineers? 

No. They're force multipliers for troubleshooting, documentation, and automation — but engineers remain responsible for design, security, governance, and business decisions.

What is hallucination? 

When an AI generates plausible-sounding but inaccurate or fabricated information (e.g., a command or error message that doesn't exist). Always verify AI output before acting on it.

Which AI skills should network engineers learn first? 

Prompt engineering, AI agents, generative AI fundamentals, basic Python, REST APIs, network automation, retrieval-augmented generation (RAG), and agentic AI workflows.

Related Reading on Networklearner

Need help with Cisco ACI, Nexus, data center networking, or network automation?
I am a CCIE Data Center engineer with 18+ years of enterprise networking experience.
Contact me for consulting, troubleshooting, design reviews, and project support.

Thursday, 23 July 2026

Why BGP Maximum-Paths Wasn't the Problem: Understanding Port-Channel Load Balancing and Traffic Imbalance

Recently, we investigated a case where traffic utilization across port-channel member interfaces was significantly unbalanced. One of the links was carrying the majority of the traffic while the other link remained underutilized. Since the environment was already configured with BGP maximum-paths 8, the initial assumption was that BGP load balancing might not be functioning correctly.

After reviewing the configuration, we confirmed that BGP ECMP was operating as expected and that multiple equal-cost paths were available. This shifted our focus from the routing layer to the port-channel load-balancing mechanism.

Why BGP Was Not the Problem

The configuration already included BGP maximum-paths 8, which allows the router to install and use multiple equal-cost paths. This means the network was capable of leveraging several routes simultaneously, eliminating BGP as the primary suspect.

It is important to understand that BGP ECMP and port-channel load balancing serve different purposes. BGP decides which routing path should be used, while the port-channel hashing algorithm determines which physical member link will carry the traffic.

Even when ECMP is working perfectly, traffic can still become concentrated on a single port-channel member if the hashing algorithm maps large flows to the same interface.

Current Hashing Algorithm Analysis

The port-channel was configured with the src-dst-ip enhanced load-balancing algorithm.

This algorithm uses only the source and destination IP addresses to calculate the hash. If a traffic flow continuously uses the same source and destination IP addresses, all packets belonging to that flow will be forwarded through the same member interface.

For example, a database replication stream between two servers will always generate the same hash result. As a result, the entire flow remains pinned to a single physical link regardless of how much unused bandwidth exists on other members of the port-channel.

This behavior is normal because Cisco port-channel load balancing is flow-based rather than packet-based. The objective is to avoid packet reordering and maintain application performance.

Considering src-dst-mixed-ip-port

To improve traffic distribution, we evaluated changing the load-balancing algorithm from src-dst-ip enhanced to src-dst-mixed-ip-port.

Unlike the current configuration, this method includes both Layer 3 and Layer 4 information in the hash calculation. In addition to source and destination IP addresses, it also considers source and destination TCP or UDP port numbers.

This creates a larger number of unique hash combinations and increases the likelihood that different application sessions between the same endpoints will be distributed across multiple member links.

In environments where users, applications, or servers establish numerous simultaneous connections, this approach often results in significantly improved bandwidth utilization across the port-channel.

Important Considerations Before Making the Change

Changing the load-balancing algorithm is generally considered a non-disruptive operation on most Cisco platforms. However, all existing traffic flows will be immediately re-hashed.

As traffic gets redistributed across available links, there may be a brief period of packet reordering. While this is typically minor and transparent to most applications, implementing the change during a maintenance window or low-utilization period is recommended.

Another important consideration is that even with Layer 4 information included, the load-balancing mechanism remains flow-based. If the imbalance is caused by a single high-bandwidth elephant flow, the entire flow will still be assigned to one member link.

In such cases, changing the hashing algorithm may provide only limited improvement.

Recommended Validation After the Change

After implementing the new load-balancing method, monitor interface utilization and traffic patterns for several hours.

Review the following:

Port-channel member utilization

Top bandwidth-consuming flows

NetFlow or telemetry statistics

Application traffic distribution

Interface counters

If traffic becomes more evenly balanced across the member interfaces, the change has achieved its objective. If the imbalance continues, further investigation should focus on identifying large elephant flows or application-specific traffic patterns.

Conclusion

Based on our analysis, BGP maximum-paths was not contributing to the bandwidth imbalance. The routing layer was functioning correctly and supporting multiple equal-cost paths as designed.

The more likely cause was the src-dst-ip enhanced hashing algorithm, which uses only Layer 3 information and can result in traffic concentration when a small number of large flows dominate bandwidth consumption.

Moving to src-dst-mixed-ip-port is a logical and widely adopted optimization because it introduces Layer 4 awareness into the hashing calculation and generally improves traffic distribution when multiple flows exist between the same source and destination hosts.

While it may not solve scenarios involving a single elephant flow, it represents the most appropriate next step before exploring more advanced traffic-engineering options

Sunday, 21 June 2026

22 Network Security Interview Questions & Answers (TLS, Cloud, Kubernetes, AI & Quantum Security)

 

Network Security Quick Quiz: TLS, Cloud, Containers, AI & Post-Quantum Crypto

A round-up of common cybersecurity concepts — from TLS 1.3 handshakes to Kubernetes network policies to post-quantum cryptography — explained in quick Q&A format.


Q1. In a TLS 1.3 handshake, why is it more difficult for firewalls to make a reliable decrypt/do-not-decrypt decision based solely on the ClientHello message?

  • A. The firewall can only see the SNI extension at that point, which may be spoofed.
  • B. All certificate data is visible at the time of the ClientHello.
  • C. The ClientHello does not contain any information relevant to SSL policy decisions.
  • D. The ClientHello is encrypted in TLS 1.3, preventing any inspection.
  Answer: A — The firewall can only see the SNI extension at that point, which may be spoofed. Why: In TLS 1.3, most handshake fields after the ClientHello are encrypted. The SNI (Server Name Indication) is one of the few visible fields, but it can be forged or omitted (especially with Encrypted Client Hello), so firewalls can't fully trust it for policy decisions.

Q2. Which benefit does AVC provide when securing containerized application environments?

  • A. AVC routes API requests based on geographic location.
  • B. AVC performs static code analysis during development.
  • C. AVC filters what applications can be installed inside a container.
  • D. AVC prevents unauthorized container deployments by validating run-time behavior. 
Answer: D — AVC prevents unauthorized container deployments by validating run-time behavior. Why: Application Visibility and Control monitors what's actually running and how it behaves, flagging anomalies rather than just relying on static rules.

Q3. Which feature of integrated endpoint security platforms directly supports remote workforces?

  • A. Policy enforcement based on geolocation
  • B. Full disk encryption capabilities
  • C. Continuous protection regardless of network connection
  • D. Cloud-based data backup for personal use 
Answer: C — Continuous protection regardless of network connection. Why: Remote workers move between networks (home Wi-Fi, public hotspots, cellular). Endpoint security needs to follow the device, not depend on being inside a corporate perimeter.

Q4. Which Cisco solution provides unified policy enforcement for both real-time data inspection and data at rest in SaaS environments?

  • A. Cisco Secure Network Analytics
  • B. Cisco Umbrella with multimode cloud DLP
  • C. Cisco Secure Endpoint
  • D. Cisco Secure Firewall Threat Defense 
Answer: B — Cisco Umbrella with multimode cloud DLP. Why: Multimode cloud DLP lets Umbrella inspect data in motion (as it's accessed/uploaded) and data at rest (already stored in SaaS apps) under one policy framework.

Q5. Which decryption method allows Cisco Secure Threat Defense to inspect outbound encrypted traffic from internal hosts without access to the server's private key?

  • A. Known Key Decryption
  • B. Certificate Pinning
  • C. Decrypt-Reencrypt
  • D. Decrypt-Resign 
Answer: C — Decrypt-Reencrypt. Why: The firewall acts as a man-in-the-middle: it decrypts traffic using its own cert, inspects it, then re-encrypts it to the destination — no need for the real server's private key (unlike Known Key/Decrypt-Resign scenarios for inbound traffic).

Q6. Which feature of Cisco Secure Email DLP helps reduce false positives by requiring additional contextual information before flagging a message as a violation?

  • A. Sender reputation scoring
  • B. Context Matching
  • C. Outbound mail logging
  • D. Inline web traffic inspection Answer: B — Context Matching. Why: Instead of triggering on a single keyword or pattern, Context Matching looks for supporting contextual signals, cutting down accidental flags.

Q7. Which of the following best describes how Cisco Umbrella provides protection against zero-day DNS threats?

  • A. By using behavioral analysis and threat intelligence to detect and block unknown domains
  • B. By comparing domain names against a static list of blocked sites
  • C. By encrypting DNS queries between endpoints and DNS servers
  • D. By scanning website content before DNS resolution is completed 
Answer: A — By using behavioral analysis and threat intelligence to detect and block unknown domains. Why: Static blocklists can't catch brand-new malicious domains; behavioral/threat-intel models can flag suspicious patterns before a domain is formally categorized.

Q8. How does Application Visibility and Control (AVC) contribute to protecting modern infrastructure from application-layer threats?

  • A. AVC ensures only verified applications and behavior are allowed to execute.
  • B. AVC disables encryption for application monitoring.
  • C. AVC blocks port scans and DoS attacks on web servers.
  • D. AVC passively records application logs for forensic analysis only. 
Answer: A — AVC ensures only verified applications and behavior are allowed to execute. Why: It's about controlling what's permitted at the application layer, not just logging or perimeter-level filtering.

Q9. What role does a Software Bill of Materials (SBOM) play in securing the software supply chain?

  • A. It enables containers to scale automatically based on load.
  • B. It tracks software dependencies and versions for vulnerability management.
  • C. It creates an encrypted communication path between services.
  • D. It manages cloud-native IAM policies across containers. 
Answer: B — It tracks software dependencies and versions for vulnerability management. Why: An SBOM is essentially an ingredient list for software, making it possible to quickly identify if a known-vulnerable component is in use.

Q10. What is one of the primary security risks of using container images sourced from public registries without verification?

  • A. Introduction of malicious or outdated code
  • B. Reduced compatibility across environments
  • C. Decreased deployment speed
  • D. Increased memory utilization in cloud platforms 
Answer: A — Introduction of malicious or outdated code. Why: Unverified images can carry embedded malware, backdoors, or simply outdated/vulnerable packages.

Q11. Which component of a Kubernetes Network Policy defines which pods the policy applies to?

  • A. Namespace
  • B. IP Block
  • C. Ingress Rule
  • D. Pod Selector 
Answer: D — Pod Selector. Why: The Pod Selector field scopes the policy to specific pods using label matching.

Q12. What is the default behavior of Kubernetes regarding pod-to-pod communication?

  • A. All pod traffic is blocked unless allowed by a service mesh.
  • B. All pod-to-pod traffic is allowed until explicitly restricted by network policies.
  • C. Traffic is allowed only within the same namespace.
  • D. Traffic is only permitted through ingress controllers. 
Answer: B — All pod-to-pod traffic is allowed until explicitly restricted by network policies. Why: Kubernetes networking is "default allow" — you must opt in to restrictions via NetworkPolicy objects.

Q13. What is the recommended practice to detect vulnerabilities both at the source code level and during run time in a serverless application?

  • A. Combine SAST and DAST tools
  • B. Use centralized authentication services
  • C. Perform manual reviews of code
  • D. Rely on the cloud provider's built-in libraries 
Answer: A — Combine SAST and DAST tools. Why: SAST (static analysis) catches issues in code before deployment; DAST (dynamic analysis) catches issues that only appear when the app is actually running.

Q14. Which of the following best describes a key reason for enforcing mutual TLS (mTLS) in a microservices architecture?

  • A. It encrypts data faster between services.
  • B. It automates the container build process.
  • C. It accelerates the deployment process across services.
  • D. It ensures that both client and server authenticate each other. 
Answer: D — It ensures that both client and server authenticate each other. Why: Standard TLS only verifies the server. mTLS adds client-side certificates so both ends prove their identity — critical in zero-trust microservice meshes.

Q15. Which risk is most commonly introduced by relying on third-party libraries in serverless applications?

  • A. Difficulty scaling application workloads
  • B. Vulnerabilities from unpatched dependencies
  • C. Reduced system performance
  • D. Increased infrastructure complexity 
Answer: B — Vulnerabilities from unpatched dependencies. Why: Serverless functions often bundle many small dependencies, and unpatched ones become an easy attack surface.

Q16. What is one of the primary cybersecurity concerns associated with quantum computing?

  • A. Quantum computers can break widely used public-key cryptographic systems like RSA and ECC.
  • B. Quantum computers require classical cryptographic algorithms to function efficiently.
  • C. Quantum computers reduce the effectiveness of symmetric encryption by weakening key lengths.
  • D. Quantum computers enable more secure key exchanges using traditional elliptic curve cryptography. 
Answer: A — Quantum computers can break widely used public-key cryptographic systems like RSA and ECC. Why: Quantum algorithms (notably Shor's) can solve the math problems RSA/ECC rely on exponentially faster than classical computers.

Q17. Which benefit of AI most directly contributes to reducing the workload of security teams in large-scale infrastructure environments?

  • A. Its ability to run vulnerability scans more frequently
  • B. Its automation of routine tasks like alert triage and log analysis
  • C. Its integration with firewalls for advanced access control rules
  • D. Its ability to deploy network devices with zero-touch provisioning Answer: B — Its automation of routine tasks like alert triage and log analysis. Why: AI excels at sorting through high-volume, repetitive data so analysts can focus on genuine threats.

Q18. How does predictive security, enabled by AI, support proactive threat mitigation?

  • A. By blocking all external connections not previously authenticated
  • B. By simulating multiple attack paths to predict potential threats
  • C. By running continuous port scans across the infrastructure
  • D. By using historical data and threat trends to anticipate security incidents 
Answer: D — By using historical data and threat trends to anticipate security incidents. Why: Predictive models learn from past attack patterns to flag likely future threats before they materialize.

Q19. Which of the following accurately describes how AI contributes to the design phase of secure network infrastructure?

  • A. AI sets strict access control rules without human oversight.
  • B. AI models and simulates potential threat scenarios to inform architecture decisions.
  • C. AI deploys firewalls in every network segment automatically.
  • D. AI configures routers and switches using a centralized script. 
Answer: B — AI models and simulates potential threat scenarios to inform architecture decisions. Why: Simulation helps architects stress-test designs against likely attack vectors before deployment.

Q20. Which property of quantum bits (qubits) most directly enables quantum computers to evaluate many computational paths simultaneously?

  • A. Superposition
  • B. Entanglement
  • C. Determinism
  • D. Parallel threading 
Answer: A — Superposition. Why: Superposition lets a qubit represent multiple states at once, enabling massive parallelism in computation.

Q21. What role does the National Institute of Standards and Technology (NIST) play in post-quantum cryptography (PQC)?

  • A. Manufacturing quantum-resistant chips for cloud providers
  • B. Standardizing cryptographic algorithms resistant to quantum attacks
  • C. Funding development of quantum computing platforms
  • D. Creating network protocols for classical encryption resilience 
Answer: B — Standardizing cryptographic algorithms resistant to quantum attacks. Why: NIST runs the formal PQC standardization process, evaluating and selecting algorithms designed to resist quantum attacks.

Q22. Which quantum algorithm presents the greatest threat to current public-key encryption schemes such as RSA?

  • A. Grover's Algorithm
  • B. Quantum Fourier Transform
  • C. Shor's Algorithm
  • D. QAOA (Quantum Approximate Optimization Algorithm) 
Answer: C — Shor's Algorithm. Why: Shor's Algorithm efficiently factors large numbers and solves discrete logarithms — the exact hard problems RSA and ECC depend on.