New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium Cisco 300-415 Dumps Questions Answers

Page: 1 / 33
Total 441 questions

Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Questions and Answers

Question 1

Which two sets of identifiers does OMP carry when it advertises TLOC routes between WAN Edge routers? (Choose two.)

Options:

A.

TLOC public and private address, carrier, and preference

B.

source and destination IP address, MAC, and site ID

C.

system IP address, link color, and encapsulation

D.

VPN ID, local site network, and BGP next-hop IP address

E.

TLOC public and private address, tunnel ID, and performance

Buy Now
Question 2

Which component is responsible for creating and maintaining the secure DTLS/TLS connection on the vSmart controller?

Options:

A.

SNMP

B.

vdaemon

C.

NETCONF

D.

OMP

Question 3

Which protocol is used by the REST API to communicate with network devices in the Cisco SD-WAN network?

Options:

A.

SSL

B.

IPsec

C.

SSH

D.

HTTP

Question 4

Which routing protocol has the highest default administrative distance?

Options:

A.

OMP

B.

external EIGRP

C.

IS-IS

D.

IBGP

Question 5

What is the default value for the Multiplier field of the BFD basic configuration in vManage?

Options:

A.

3

B.

4

C.

5

D.

6

Question 6

Refer to the exhibit. A network administrator is configuring OSPF advanced configuration parameters from a template using the vManager GUI for a branch WAN Edge router to calculate the cost of summary routes to an ASBR. Which action achieves this configuration?

Options:

A.

Enable Originate.

B.

Disable Originate.

C.

Enable RFC 1583 Compatible.

D.

Disable RFC 1583 Compatible.

Question 7

An engineer must configure VRRP for redundancy on WAN Edge router1 running an earlier version than 20.6, considering WAN Edge router2 is configured correctly. Which configuration meets the requirement?

Options:

A.
B.
C.
D.
Question 8

Which two prerequisites must be met before the Cloud onRamp for laaS is initiated on vManage to expand to the AWS cloud? (Choose two)

Options:

A.

Attach the *AmazonCreateVPC* and "Amazon Provision EC2" permission policy to the IAM account

B.

Subscribe to the SD-WAN Edge router AMI in the AWS account

C.

Attach an OSPF feature template to the AWS cloud Edge router template

D.

Attach a device template to the cloud WAN Edge router to be deployed in the AWS

E.

Preprovision the transit VPC in the AWS region

Question 9

Refer to the exhibit. vManage logs are available for the past few months. A device name change deployed mistakenly at a critical site. How is the device name change tracked by operation and design teams?

A)

B)

C)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 10

In Cisco SD-WAN, what protocol is used for control connections between SD-WAN devices?

Options:

A.

DTLS

B.

OMP

C.

BGP

D.

OSPF

Question 11

What are the two protocols redistributed into OMP? (Choose two.)

Options:

A.

OSPF

B.

RIP

C.

LDP

D.

RSVP

E.

EIGRP

Question 12

When VPNs are grouped to create destination zone in Zone-Based Firewall, how many zones can a single VPN be part of?

Options:

A.

two

B.

four

C.

one

D.

three

Question 13

How is multicast routing enabled on devices in the Cisco SD-WAN overlay network?

Options:

A.

The WAN Edge routers originate multicast service routes to the vSmart controller via OMP, which then forwards joins for requested multicast groups based on IGMP v1 or v2 toward the source or PIM-RP as specified m the original PIM join message.

B.

The vSmart controller originates multicast service routes to the WAN Edge routers via OMP, which then forwards joins for requested multicast groups cased on IGMP v1 or v2 toward the source or PlM-RP as specified m the original PIM join message

C.

The vSmart controller originates multicast service routes to the WAN Edge routers via OMP, which then forwards joins (or requested multicast groups based on IGMP v2 or v3 toward the source or PIM-RP as specified in the original PIM join message

D.

The WAN Edge routers originate multicast service routes to the vSmart controller via OMP. which then forwards joins for requested multicast groups based on iGMP v2 or v3 toward the source or PIM-RP as specified in the original PIM join message

Question 14

Drag and drop the attributes from the left that make each transport location unique onto the right. Not all options are used.

Options:

Question 15

A large retail organization decided to move some of the branch applications to the AWS cloud. How does the network architect extend the in-house Cisco SD-WAN branch to cloud network into AWS?

Options:

A.

Create virtual WAN Edge devices Cloud through the AWS online software store

B.

Create virtual instances of vSmart Cloud through the AWS online software store

C.

Create GRE tunnels to AWS from each branch over the Internet

D.

Install the AWS Cloud Router in the main data center and provide the connectivity from each branch

Question 16

What is the OMP graceful restart default value on vSmart controllers and WAN Edge routers?

Options:

A.

21,600 seconds

B.

43,200 seconds

C.

86,400 seconds

D.

604,800 seconds

Question 17

Two sites have one WAN Edge each WAN Edge has two public TLOCs with no restriction configured. There is full reachability between the TLOCs. How many data tunnels are formed on each Edge router?

Options:

A.

2

B.

8

C.

6

D.

4

Question 18

Which IP address must be reachable by a WAN Edge device for the ZIP process to work?

Options:

A.

10.1.1.1

B.

4.4 4.4

C.

172.16.1.1

D.

8.8.8.8

Question 19

Which controller is used for provisioning and configuration in a Cisco SD-WAN solution?

Options:

A.

vBond

B.

Manage

C.

WAN Edge router

D.

vSmart

Question 20

Which VPN connects the transport-side WAN Edge interface to the underlay/WAN network?

Options:

A.

VPN 1

B.

VPN 511

C.

VPN 0

D.

VPN 512

Question 21

Which command disables the logging of syslog messages to the local disk?

Options:

A.

no system logging disk enable

B.

no system logging disk local

C.

system logging disk disable

D.

system logging server remote

Question 22

In an AWS cloud, which feature provision WAN Edge routers automatically in Cisco SD-WAN?

Options:

A.

Cloud app

B.

Cloud OnRamp

C.

vAnalytics

D.

Network Designer

Question 23

Refer to the exhibit.

The network design team has advised to use private IP addresses and private colors over the SP circuit for the data plane connections. The Public IP should be used for control connections. Which configuration should be applied at SiteA to achieve this task?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 24

What does forward error correction addresses in Cisco SO-WAN?

Options:

A.

inefficient traffic forwarding caused oy inbound shapers

B.

reduced application performance degradation rotated to service degradation

C.

applications with occasional invalid data input and poor performance

D.

traffic flows with increased delay over a particular transport

Question 25

Which configuration change allows direct internet access at the branch site for YouTube traffic?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 26

Refer to the exhibit The network team must configure ElGRP peering at HQ with devices in the service VPN connected to WAN Edge CSRv. CSRv is currently configured with

Which configuration on the WAN Edge meets the requiremnet

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 27

An engineer is configuring a shaping rate of 1 Mbps on the WAN link of a WAN Edge router Which configuration accomplishes this task’?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 28

WAN Edge routers are configured manually to use UDP port offset to use nondefault offset values when IPsec tunnels are created. What is the offse range?

Options:

A.

1-19

B.

0-18

C.

0-19

D.

1-18

Question 29

An engineer must deploy a QoS policy with these requirements:

• policy name: App-police

• police rate: 1000000

• burst: 1000000

• exceed: drop

Which configuration meets the requirements?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 30

Refer to the exhibit. A Cisco SD-WAN network carries traffic for several departments and over 1200 users with several applications at site A and site B branches over the MPLS1 circuit. An engineer is provisioning a higher bandwidth on-demand metro circuit as a backup connection. Which two configurations must the engineer apply to implement the on-demand tunnels? (Choose two.)

Options:

A.
B.
C.
D.
E.
Question 31

What is the ZTP workflow for Cisco IOS XE-based devices?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 32

Which component is used for stateful inspection of TCP, UDP. and ICMP flows in Cisco SD-WAN firewall policies?

Options:

A.

zones

B.

sites

C.

subnets

D.

interfaces

Question 33

An engineer is adding a tenant with location ID 399533345 in vManage. What is the maximum number of alphanumeric characters that is accepted in the tenant name filed?

Options:

A.

64

B.

128

C.

256

D.

8

Question 34

What are the default username and password for vSmart Controller when it is installed on a VMware ESXi hypervisor'?

Options:

A.

username Cisco password admin

B.

username admin password Cisco

C.

username Cisco password Cisco

D.

username admin password admin

Question 35

What are the two advantages of configuration groups in a Cisco SD-WAN deployment? (Choose two.)

Options:

A.

Individual devices are associated with a configuration group and a device template.

B.

Individual devices are added to multiple groups.

C.

Individual devices are grouped based on a shared configuration.

D.

A subset of devices is identified with tags.

E.

An individual device has multiple tag rules.

Question 36

Refer to the exhibit.

An organization is testing a Cisco SD-WAN solution and decided to have the control plane established first and not the data plane at the time of migration. Which configuration achieves this goal?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 37

What are two benefits of installing Cisco SD-WAN controllers on cloud-hosted services? (Choose two.)

Options:

A.

utilizes well-known cloud services such as Azure. AWS. and GCP

B.

accelerates Cisco SD-WAN deployment

C.

allows integration of the WAN Edge devices In the cloud

D.

installs the controllers in two cloud regions in a primary and backup setup

E.

automatically Implements zone-based firewalling on the controllers

Question 38

Which policy configures an application-aware routing policy under Configuration > Policies?

Options:

A.

Localized policy

B.

Centralized policy

C.

Data policy

D.

Control policy

Question 39

What is a requirement for a WAN Edge to reach vManage, vBond, and vSmart controllers in a data center?

Options:

A.

IGP

B.

QoS

C.

TLS

D.

OMP

Question 40

Drag and drop the definitions from the left to the configuration on the right.

Options:

Question 41

Configure individual VRFs for each customer according to the topology to achieve these goals :

R1

R2

SW1

SW2

SW3

Options:

Question 42

An administrator wants to create a policy to add a traffic policer called "politer-ccnp" to police data traffic on the WAN Edge. Which configuration accomplishes this task in vSmart?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 43

An engineer is troubleshooting a certificate issue on vEdge. Which command is used to verify the validity of the certificates?

Options:

A.

show control local-properties

B.

show control summary

C.

show certificate installed

D.

show certificate status

Question 44

Which two vRoute attributes should be matched or set in vSmart policies and modified by data policies? (Choose two.)

Options:

A.

site ID

B.

preference

C.

VPN

D.

TLOC

E.

origin

Question 45

What is an attribute of TLOC’?

Options:

A.

encryption

B.

local preference

C.

tag

D.

service

Question 46

A company is using Catalyst SD-WAN Manager as its root certificate authority server and must generate a root certificate using the vShell (Linux) built into the CLI of Catalyst SD-WAN Manager. Which command must be issued to generate the root certificate?

Options:

A.

openssl req -x509 -new-nodes -key XYZ.pem -sha256 -days 365 \subj "/C=US/ST=DC/L=DC/O=Cisco/CN=device.lab"-out ABC.key

B.

openssl genrsa -out ROOTCA.pem 2048

C.

openssl req -x509 -new-nodes -key XYZ.key -sha256 -days 365 Isubj "/C-US/ST-DC/L-DC/O-Cisco/CN-device.lab" 1-out ABC.pem

D.

openssl genrsa -out ROOTCA.key 2048

Question 47

Refer to the exhibit vManage and vBond have an issue establishing a connection to vSmart Which two actions does the administrator take to fix the issue? (Choose two)

Options:

A.

Install the certificate received from the certificate server.

B.

Manually resync vManage and vBond

C.

Reconfigure the vSmart from CLI with the proper Hostname & System IP

D.

Delete and re-add vSmart Click Generate and validate CSR

E.

Request a certificate from the certificate server based on the CSR for the vSmart

Question 48

Drag and drop the functions from the left onto the correct templates on the right.

Options:

Question 49

Which statement describes the requirement of integrating a secure internet gateway (SIG) with a Cisco SD-WAN Edge device?

Options:

A.

Attached to SIG tunnels, trackers monitor the respective SIG endpoints.

B.

Credentials for a smart account are required.

C.

A Cisco umbrella organization ID is needed to establish the SIG.

D.

Based on routing or policy, all customer internet traffic must be forwarded to the SIG.

Question 50

A policy is created to influence routing path in the network using a group of prefixes. What policy application will achieve this goal when applied to a site List?

Options:

A.

vpn-membership policy

B.

cflowd-template

C.

app-route policy

D.

control-policy

Question 51

Which template configures the out-of-band management VPN?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 52

REST applications communicate over HTTP or HTTPS to make calls between network devices. Which two HTTPS standard methods are included? (Choose two.)

Options:

A.

Array

B.

DELETE

C.

POST

D.

Scalar

E.

Object

Question 53

Which component is used to optimize the multicast distribution tree enabled through the multicast network?

Options:

A.

IGMP client

B.

vManage controllers

C.

VPN concentrator

D.

OMP replicator

Question 54

Refer to the exhibit.

The SD-WAN network is configured with a default full-mesh topology. The SD-WAN engineer wants the Barcelona WAN Edge to use MPLS TLOC as the preferred TLOC when communicating with Rome site. Which configuration must the engineer use to create a list to select MPLS color toward the Rome TLOC?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 55

Which protocol is used between redundant vSmart controllers to establish a permanent communication channel?

Options:

A.

IPsec

B.

HTTPs

C.

DTLS

D.

SSL

Question 56

An engineer must create a QoS policy by creating a class map and assigning it to the LLQ queue on a WAN Edge router Which configuration accomplishes the task?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 57

Refer to the exhibit The Cisco SD-WAN network is configured with a default full-mesh topology. Islamabad HQ and Islamabad WAN Edges must be used as the hub sites. Hub sites MPLS TLOC must be preferred when forwarding FTP traffic based on a configured SLA class list. Which policy configuration does the network engineer use to call the SLA class and set the preferred color to MPLS?

Options:

A.

Localized Policy, Route Policy

B.

Centralized Policy, Traffic Policy

C.

Localized Policy, Forwarding Class

D.

Centralized Policy Topology

Question 58

Which configuration allows users to reach YouTube from a local Internet breakout?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 59

Refer to the exhibit.

A network administrator is configuring OMP in vManage to advertise all the paths for the same prefix from a site that has two WAN Edge devices Each WAN Edge device is connected to three ISPs and two private MPLS transports. What is the minimum value for 'Number of Paths advertised per Prefix" that should be configured?

Options:

A.

2

B.

3

C.

5

D.

10

Question 60

Which two advanced security features are available on the Cisco SD-WAN WAN Edge (vEdge) device? (Choose two.)

Options:

A.

URL filtering

B.

snort intrusion prevention system

C.

Cisco Umbrella DNS Security

D.

Cisco AMP and AMP Threat Grid

E.

Enterprise Firewall

Question 61

The SD-WAN network is configured ­­­with a default full-mesh topology. The SD-WAN engineer wants the Barcelona WAN Edge to use the MPLS TLOC when forwarding Telnet traffic based on a configured SLA class list. Which configured must the engineer use to create a policy to call the SLA class and set the preferred color to MPLS?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 62

Refer to the exhibit.

Which QoS treatment results from this configuration after the access list acl-guest is applied inbound on the vpn1 interface?

Options:

A.

A UDP packet sourcing from 172.16.20.1 and destined to 172.16.10.1 is accepted

B.

A TCP packet sourcing from 172.16.10.1 and destined to 172.16.20.1 is dropped

C.

A UDP packet souring from 172.16.10.1 and destined to 172.16.20.1 is dropped.

D.

A TCP packet sourcing from 172.16.20.1 and destined to 172.16.10.1 is accepted

Question 63

Which type of route represents prefixes received from a local site via an SD-WAN Edge router in a Cisco SD-WAN architecture?

Options:

A.

TLOC routes

B.

Service routes

C.

Multicast routes

D.

vRoutes

Question 64

How many vCPUs and how much RAM are recommended to run the vSmart controller on the KVM server for 251 to 1000 devices in software version 20.4.x?

Options:

A.

4vCPUs. 16 GB

B.

4 vCPUs. 8 GB

C.

8vCPUs. 16 GB

D.

2vCPUs.4GB

Question 65

What do receivers request to join multicast streams in a Cisco SO-WAN network?

Options:

A.

IGMP membership reports directly with a multicast router.

B.

Multicast service routes with the vSmart controller

C.

IGMP membership reports directly with the vBond orchestrator.

D.

PIM messages with the nearest neighboring multicast router.

Question 66

An organization requires the use of integrated preventative engines, exploit protection, and the most updated and advanced signature-based antivirus with sandboxing and threat intelligence to stop malicious attachments before they reach users and get executed. Which Cisco SD-WAN solution meets the requirements?

Options:

A.

Cisco Trust Anchor module

B.

URL filtering and Umbrella DNS security

C.

Cisco AMP and Threat Grid

D.

Snort IPS

Question 67

Which action is performed during the onboarding process when a WAN Edge router is connected to ZTP server ztp.viptela com?

Options:

A.

The router is connected to WAN Edge Cloud Center

B.

The router is synced with vSmart Controller via an IPsec tunnel

C.

The router receives its vBond Orchestrator information

D.

The router is connected 10 vSmart Controller via a DTLSTLS tunnel

Question 68

Which configuration allows VPN 10 traffic to have direct internet access locally from the WAN Edge device?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 69

Refer to the exhibit. The Cisco SD-VYAN is deployed using the default topology. The engineer v/ants to configure a service insertion policy such that all data traffic between Rome to Paris is forwarded through the NGFW located in London. Which configuration fulfills this requirement, assuming that the Sen/ice VPN ID is 1?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 70

Refer to the exhibit.

Which two configurations are needed to get the WAN Edges registered with the controllers when certificates are used? (Choose two)

Options:

A.

Generate a CSR manually within vManage server

B.

Generate a CSR manually on the WAN Edge

C.

Request a certificate manually from the Enterprise CA server

D.

Install the certificate received from the CA server manually on the WAN Edge

E.

Install the certificate received from the CA server manually on the vManage

Question 71

What is a benefit of the application aware firewall feature in the Cisco SD-WAN solution?

Options:

A.

application monitoring

B.

application malware protection

C.

application visibility

D.

control policy enforcement

Question 72

What is the main purpose of using TLOC extensions in WAN Edge router configuration?

Options:

A.

creates hardware-level transport redundancy at the local site

B.

creates an IPsec tunnel from WAN Edge to vBond Orchestrator

C.

transports control traffic to a redundant vSmart Controller

D.

transports control traffic w remote-site WAN Edge routers

Question 73

Which two resource data types are used to collect information for monitoring using REST API in Cisco SD-WAN? (Choose two.)

Options:

A.

POST

B.

DELETE

C.

scalar

D.

array

E.

PUT

Question 74

Which protocol is used to measure loss latency, Jitter, and liveliness of the tunnel between WAN Edge router peers?

Options:

A.

OMP

B.

IP SLA

C.

NetFlow

D.

BFD

Question 75

Refer to the exhibit. A network administrator is setting the queueing value for voice traffic for one of the WAN Edge routers using vManager GUI. Which queue value must be set to accomplish this task?

Options:

A.

0

B.

1

C.

2

D.

3

Question 76

An enterprise needs DIA on some of its branches with a common location ID: A041:B70C: D78E::18 Which WAN Edge configuration meets the requirement?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 77

Refer to the exhibit.

The engineer must assign community tags to 3 of its 74 critical server networks as soon as that are advertised to BGP peers. These server networks must not be advertised outside AS. Which configuration fulfill this requirement?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 78

An enterprise has these three WAN connections:

public Internet

business internet

MPLS

An engineer must configure two available links to route traffic via both links. Which configuration achieves this objective?

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Question 79

A customer wants to use AWS for Cisco SD-WAN laaS services by deploying virtual SD-WAN routers in a transit AWS VPC The transit VPC then connects via site-to-site IPsec tunnels to an AWS transit gateway Which transit VPC connects via site-to-site IPsec tunnels to an AWS transit gateway?

Options:

A.

Cisco Cloud onRamp for Multicloud

B.

Cisco Cloud onRamp for SaaS

C.

Cisco Cloud onRamp for Colocation

D.

Cisco Cloud onRamp for laaS

Question 80

An engineer must improve video quality by limiting HTTP traffic to the Internet without any failover. Which configuration in vManage achieves this goal?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 81

What is the minimum Red Hat Enterprise Linux operating system requirement for a Cisco SD-WAN controller deployment via KVM?

Options:

A.

RHEL7.5

B.

RHEL 6.5

C.

RHEL4.4

D.

RHEL 6.7

Question 82

An engineer configures an application-aware routing policy for a group of sites The locations depend on public and private transports The policy does not work as expected when one of the transports does not perform properly This policy is configured:

which configuration completes the policy so that it works for all locations?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 83

What is the result during a WAN Edge software upgrade process if the version of the WAN Edge software is higher than the one running on a controller device?

Options:

A.

The upgrade button is greyed out

B.

The upgrade proceeds with no warning message.

C.

The upgrade fails with a warning message

D.

The upgrade proceeds with a warning message

Question 84

How is an event monitored and reported for an individual device in the overlay network at site ID:S4300T6E43F36?

Options:

A.

The device sends event notifications to vManage.

B.

The device sends notifications to vSmart that sends them to vManage.

C.

The device sends a critical alarm of events to vManage.

D.

The device sends a critical alarm to vSmart that sends it to vManage.

Question 85

Refer to the exhibit.

The tunnel interface configuration on both WAN Edge routers is:

Which configuration for WAN Edge routers will connect to the Internet?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 86

Refer to the exhibit.

An engineer configured OMP with an overlay-as of 10666. What is the AS-PATH for prefix 104.104.104.104/32 on R100?

Options:

A.

100 10666

B.

100 20 104

C.

100 10666 20 104

D.

100 10666 104

Question 87

Refer to the exhibit.

Customer XYZ cannot provision dual connectivity on both of its routers due to budget constraints but wants to use both R1 and R2 interlaces for users behind them for load balancing toward the hub site. Which configuration achieves this objective?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 88

Drag and drop the actions from the left into the correct sequence on the right to create a data policy to direct traffic to the Internet exit.

Options:

Question 89

An engineer is configuring a WAN Edge router for DIA based on matching QoS parameters. Which two actions accomplish this task? (Choose two.)

Options:

A.

Apply a QoS map policy.

B.

Configure a control policy.

C.

Configure a centralized data policy.

D.

Configure NAT on the transport interface.

E.

Apply a data policy on WAN interface.

Question 90

Which type of policy must be applied on a WAN Edge application-aware firewall to control traffic between two or more VPNs?

Options:

A.

service-insertion policy

B.

data policy

C.

firewall policy

D.

control policy

Question 91

Which two mechanisms are used to guarantee the integrity of data packets in the Cisco SD-WAN architecture data plane? {Choose two)

Options:

A.

transport locations

B.

authentication headers

C.

certificates

D.

TPM chip

E.

encapsulation security payload

Question 92

An engineer wants to track tunnel characteristics within an SLA-based policy for convergence. Which policy configuration will achieve this goal?

Options:

A.

App-route policy

B.

VPN membership policy

C.

Control policy

D.

Data policy

Question 93

After deploying Cisco SD-WAN the company realized that by default, all sites built direct IPsec VPN tunnels to each other In their previous topology all spoke sites used the head office as their next hop for the LAN segment that belongs to network 40.0.0.0/16 The company wants to deploy its previous policy, which allows the 40.0.0.0/16 network that originates at the hub to advertise to the spokes. Which configuration meets the requirement'?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 94

How many subnets are necessary in Azure VNet for a WAN Edge device to function in the cloud deployment?

Options:

A.

CSR is the WAN Edge device that is supported in the Microsoft cloud. The Microsoft underlay cloud fabric performs the management function.

B.

There must be three subnets in VNet: management, public, and services.

C.

One public subnet is required in VNet. The Microsoft underlay cloud fabric performs all of the routing functions for WAN Edge.

D.

Public and services subnets are required in VNet. The Microsoft underlay cloud fabric performs the management function.

Question 95

A network engineer sets tags in OMP for routes that were originated in the Service VPN. Which monitoring tab must be used to verify tags on the next hop?

Options:

A.

Realtime > OMP Received TLOCs

B.

Troubleshooting > Simulate Flows

C.

Realtime > OMP Received Routes

D.

Troubleshooting > Tunnel Health

Question 96

Refer to the exhibit.

An engineer is troubleshooting a control connection Issue. What does "connect" mean in this how control connections output?

Options:

A.

Control connection is down

B.

Control connection is connected

C.

Control connection attempt is in progress

D.

Control connection is up

Question 97

The Cisco SD-WAN engineer is configuring service chaining for a next-generation firewall located at the headquarters. Which configuration creates the service?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 98

How must the application-aware enterprise firewall policies be applied within the same WAN Edge router?

Options:

A.

within and between zones

B.

between two VPN tunnels

C.

within zone pair

D.

between two VRFs

Question 99

A network administrator is configuring VRRP to avoid a traffic black hole when the transport side of the network is down on the primary device. What must be configured to get the fastest failover to standby?

Options:

A.

prefix-list tracking

B.

lower timer interval

C.

higher group ID number

D.

OMP tracking

Question 100

Which storage format Is used when vManage Is deployed as a virtual machine on a KVM hypervisor?

Options:

A.

.iso

B.

.qcow2

C.

.ova

D.

.tgz

Question 101

An engineer configures policing with a rate of 125 Bps and a burst rate of 8000 bits, as shown here:

Which configuration completes this task?

Options:

A.

Configure 125 for rate and 1000 for burst.

B.

Configure 1000 for rate and 64000 for burst

C.

Configure 125 for rate and 8000 for burst

D.

Configure 1000 for rate and 1000 for burst

Question 102

Which set of platforms must he in separate VMS as of release 16.1?

Options:

A.

vSmart and WAN Edge

B.

WAN Edge and vBond

C.

vManagc and vSmart

D.

vBond and vSmart

Question 103

An engineer must configure egress QoS for voice traffic. Which queue must the engineer configure on the WAN Edge router to accomplish the task?

Options:

A.

queue 0

B.

queue 1

C.

queue 3

D.

queue 7

Question 104

Refer to the exhibit.

An MPLS connection on R2 must extend to R1 Users behind R1 must have dual connectivity for data traffic Which configuration provides R1 control connectivity over the MPLS connection?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 105

An enterprise has several sites with multiple VPNs that are isolated from each other A new requirement came where users in VPN 73 must be able to talk to users in VPN 50 Which configuration meets this requirement?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 106

An engineer is troubleshooting a vEdge router and identifies a “DCONFAIL – DTLS connection failure” message. What is the problem?

Options:

A.

certificate mismatch

B.

organization mismatch

C.

memory issue

D.

connectivity issue

Question 107

Which two actions are necessary to set the Controller Certificate Authorization mode to indicate a root certificate? (Choose two)

Options:

A.

Select the Controller Certificate Authorization mode that is recommended by Cisco

B.

Change the organization name of the Cisco SO-WAN fabric.

C.

Upload an SSL certificate to vManape,

D.

Select a private certificate signing authority instead of a public certificate signing authority

E.

Select a validity period from the drop-down menu

Question 108

Which two products that perform lifecycle management for virtual instances are supported by WAN Edge cloud routers? (Choose two.)

Options:

A.

OpenStack

B.

AWS

C.

VMware vCenter

D.

Azure

E.

IBM Cloud

Question 109

A network is configured with CoPP to protect the CORE router route processor for stability and DDoS protection. As a company policy, a class named class-default is preconfigured and must not be modified or deleted. Troubleshoot CoPP to resolve the issues introduced during the maintenance window to ensure that:

WAN

CORE

MGMT

Options:

Question 110

Refer to the exhibit. An engineer must configure the Overlay Management Protocol route preference so that when B2 tries to reach host routes advertised by B1 it always chooses the MPLS circuit. Which two match conditions must be configured to accomplish this task? (Choose two.)

Options:

A.

VPN

B.

prefix list

C.

originator

D.

color list

E.

path type

Question 111

In a customer retail network with multiple data centers, what does the network administrator use to create a regional hub topology?

Options:

A.

control policy on vManage

B.

control policy on vSmart

C.

data policy on vSmart

D.

app route policy on vSmart

Question 112

An organization wants to use the cisco SD-WAN regionalized service-chaining feature to optimize cost and user experience with application in the network, which allows branch routers to analyze and steer traffic toward the required network function. Which feature meets this requirement?

Options:

A.

Cloud Services Platform

B.

VNF Service Chaning

C.

Cloud onRamp for Colocation

D.

Cloud onRamp for laaS

Question 113

Which SD-WAN component is configured to enforce a policy to redirect branch-to-branch traffic toward a network service such as a firewall or IPS?

Options:

A.

vBond

B.

WAN Edge

C.

vSmart

D.

Firewall

Question 114

Which two types of SGT propagation are supported by Cisco TrustSec? (Choose two.)

Options:

A.

reconciliation

B.

SXP

C.

offline tagging

D.

key chain

E.

inline tagging

Question 115

What is the procedure to upgrade all Cisco SD-WAN devices to a recent version?

Options:

A.

The upgrade is performed for a group of WAN Edge devices first to ensure data-plabe availability when other controllers are updated.

B.

The upgrade is performed first on vManage, then on WAN Edge devices, then on vBond and finally on vSmart The reboot must start from WAN Edge devices.

C.

Upgrade and reboot are performed first on vManage then on vBond then on vSmart. and finally on the Cisco WAN Edge devices.

D.

Upgrade and reboot are performed first on vBond. then on vSmart. and finally on the Cisco WAN Edge devices.

Question 116

What are the two functions of vSmart? (Choose two)

Options:

A.

It orchestrates connectivity between WAN Edge routers using policies to create network topology

B.

It ensures that valid WAN Edge routers can build the control pane connectivity

C.

It uses TLOCs to uniquely identify the circuit interface to control plane and data plane information

D.

It validates that the WAN Edge trying to join the overlay is authorized to join.

E.

It builds control plane connections with WAN Edge routers using ILS or UILS

Question 117

Which attributes are configured to uniquely Identify and represent a TLOC route?

Options:

A.

system IP address, link color, and encapsulation

B.

firewall, IPS, and application optimization

C.

site ID, tag, and VPN

D.

origin, originator, and preference

Question 118

Refer to the exhibit. Company ABC has a hub-and-spoke topology in place and currently is load balancing their data traffic at the hub site over MPLS and the public Internet. The leased circuit must be preferred over the shared circuit. Which configuration meets the requirement?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 119

What is the behaviour of vBond orchestrator?

Options:

A.

It maintains vSmart and WAN Edge routers secure connectivity state

B.

it builds permanent connections with vSmart controllers

C.

it updates vSmart of WAN Edge routers behind NAT devices using OMP.

D.

It builds permanent connections with WAN Edge routers

Question 120

Refer to the exhibit. The ge0/0 interface connects to a 30-MB link. A network administrator wants to always have 10 MB available for high priority traffic. When lower-priority traffic busts exceed 20 MB. Traffic should be redirected to the second WAN interface ge0/1. Which set of configurations accomplishes this task?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 121

Which issue triggers the Cisco Umbrella resolver to toward DNS requests to the intelligent proxy?

Which issue triggers the Cisco Umbrella resolver to toward DNS requests to the intelligent proxy?

Options:

A.

A domain is nonexistent.

B.

A domain is block-listed.

C.

A domain is locally reachable.

D.

A domain is grey-listed.

Question 122

Which Cloud OnRamp solution is used by partners and vendors without Cisco SD-WAN but still needs connectivity to their customers without installing SD-WAN routing appliances on their sites?

Options:

A.

Cloud OnRamp for IaaS

B.

Cloud OnRamp for SaaS

C.

Cloud OnRamp for Multicloud

D.

Cloud OnRamp for Colocation

Question 123

If Smart Account Sync is not used, which Cisco SD-WAN component is used to upload an authorized serial number file?

Options:

A.

WAN Edge

B.

vManage

C.

vSmart

D.

vBond

Question 124

Which on-the-box security feature supported by the Cisco ISR 4451 SD-WAN device and not on vEdge?

Options:

A.

Cloud Express service

B.

Enterprise Firewall with Application Awareness

C.

reverse proxy

D.

IPsec/GRE cloud proxy

Question 125

An engineer must advertise OSPF-learned routes and modify the update interval for route filtering by TLOC color to 300 on an SD-WAN device. Which configuration accomplishes this

task?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 126

What is the function of the AppNav Controller in the Cisco SD-WAN AppNav solution?

Options:

A.

It accelerates specific traffic based on preconfigured policies.

B.

It provides information about configured optimization policies on SD-WAN edge devices.

C.

It provides configuration and monitoring for WAAS nodes.

D.

It intercepts and distributes network traffic based on configured policies.

Question 127

A WAN Edge device has several service VPNs with no routing protocol configured in the service VPNs The device must be configured so that all connected routes are visible in OMP for VPN 10 Which configuration meets the requirement?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 128

Which two algorithms authenticate a user when configuring SNMPv3 monitoring on a WAN Edge router? (Choose two.)

Options:

A.

AES-256

B.

SHA-1

C.

AES-128

D.

MD5

E.

SHA-2

Question 129

Which logs verify when a device was upgraded?

Options:

A.

Audit

B.

Email

C.

ACL

D.

SNMP

Question 130

A company deploys a Cisco SD-WAN solution but has an unstable Internet connection. When the link to vSmart comes back up, the WAN Edge router routing table is not refreshed, and some traffic to the destination network is dropped. The headquarters is the hub site, and it continuously adds new sites to the SD-WAN network. An engineer must configure route refresh between WAN Edge and vSmart within 2 minutes. Which configuration meets this requirement?

Options:

A.

Option A

B.

B

C.

Option B

D.
E.

Option C

F.

Option D

Question 131

Which OSPF command makes the WAN Edge router a less preferred exit from a site with a dual WAN Edge design?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 132

Refer to the exhibit.

What binding is created using the tloc-extension command?

Options:

A.

between ge 0/2.101 of port-type service and ge 0/0 of port-type service

B.

between ge 0/2.101 of port-type transport and ge 0/0 of port-type service

C.

between ge 0/2.101 of port-type service and ge 0/0 of port-type transport

D.

between ge 0/2.101 of port-type transport and ge 0/0 of port-type transport

Page: 1 / 33
Total 441 questions