Spring Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Question and Answers

Implementing Cisco SD-WAN Solutions (300-415 ENSDWI)

Last Update Mar 10, 2026
Total Questions : 446

We are offering FREE 300-415 Cisco exam questions. All you do is to just go and sign up. Give your details, prepare 300-415 free exam questions and then go for complete pool of Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) test questions that will help you more.

300-415 pdf

300-415 PDF

$40.25  $114.99
300-415 Engine

300-415 Testing Engine

$47.25  $134.99
300-415 PDF + Engine

300-415 PDF + Testing Engine

$61.25  $174.99
Questions 1

A network administrator is configuring Qos on a vEdge 5000 router and needs to enable it on the transport side interface. Which policy setting must be selected to accomplish this goal?

Options:

A.  

Cloud QoS Service side

B.  

Cloud QoS

C.  

NetFlow

D.  

Application

Discussion 0
Questions 2

An engineer wants to track tunnel characteristics within an SLA-based policy for convergence. Which policy configuration will achieve this goal?

Options:

A.  

App-route policy

B.  

VPN membership policy

C.  

Control policy

D.  

Data policy

Discussion 0
Questions 3

Which port is used for vBond under controller certificates if no alternate port is configured?

Options:

A.  

12345

B.  

12347

C.  

12346

D.  

12344

Discussion 0
Questions 4

Which configuration allows VPN 10 traffic to have direct internet access locally from the WAN Edge device?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 5

Which two requirements must be met for DNS inspection when integrating with cisco umbrella? (Choose two)

Options:

A.  

Upload the WAN Edge serial allow list to the Umbrella portal.

B.  

Attach security policy to the device template.

C.  

Configure the Umbrella token on the vManage

D.  

Create and attach a System feature template with the Umbrella registration credentials.

E.  

Register and configure the vManage public IP and serial number in the Umbrella portal.

Discussion 0
Questions 6

Which two protocols are supported for software image delivery when images are hosted on a remote server? (Choose two.)

Options:

A.  

HTTPS

B.  

SSL

C.  

HTTP

D.  

TFTP

E.  

FTP

Discussion 0
Questions 7

Which component of the Cisco SD-WAN architecture oversees the control plane of overlay network to establish, adjust, and maintain the connections between the WAN Edge devices that form the Cisco SD-WAN fabric?

Options:

A.  

APIC-EM

B.  

vManage

C.  

vSmart

D.  

vBond

Discussion 0
Questions 8

Which component of the Cisco SD-WAN control plane architecture facilitates the storage of certificates and configurations for network components?

Options:

A.  

vSmart

B.  

vBond

C.  

WAN Edge

D.  

vManage

Discussion 0
Questions 9

Which device information is requited on PNP/ZTP to support the zero-touch onboarding process?

Options:

A.  

serial and chassis numbers

B.  

interface IP address

C.  

public DNS entry

D.  

system IP address

Discussion 0
Questions 10

An enterprise has several sites with multiple VPNs that are isolated from each other A new requirement came where users in VPN 73 must be able to talk to users in VPN 50 Which configuration meets this requirement?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 11

A customer wants to use AWS for Cisco SD-WAN laaS services by deploying virtual SD-WAN routers in a transit AWS VPC The transit VPC then connects via site-to-site IPsec tunnels to an AWS transit gateway Which transit VPC connects via site-to-site IPsec tunnels to an AWS transit gateway?

Options:

A.  

Cisco Cloud onRamp for Multicloud

B.  

Cisco Cloud onRamp for SaaS

C.  

Cisco Cloud onRamp for Colocation

D.  

Cisco Cloud onRamp for laaS

Discussion 0
Questions 12

Which component of the Cisco SD-WAN secure extensible network provides a single pane of glass approach to network monitoring and configuration?

Options:

A.  

APIC-EM

B.  

vSmart

C.  

vManage

D.  

vBond

Discussion 0
Questions 13

WAN Edge routers are configured manually to use UDP port offset to use nondefault offset values when IPsec tunnels are created. What is the offse range?

Options:

A.  

1-19

B.  

0-18

C.  

0-19

D.  

1-18

Discussion 0
Questions 14

Refer to the exhibit. An engineer must configure the Overlay Management Protocol route preference so that when B2 tries to reach host routes advertised by B1 it always chooses the MPLS circuit. Which two match conditions must be configured to accomplish this task? (Choose two.)

Options:

A.  

VPN

B.  

prefix list

C.  

originator

D.  

color list

E.  

path type

Discussion 0
Questions 15

When redistribution is configured between OMP and BGP at two Data Center sites that have Direct Connection interlink, which step avoids learning the same routes on WAN Edge routers of the DCs from LAN?

Options:

A.  

Define different VRFs on both DCs

B.  

Set same overlay AS on both DC WAN Edge routers

C.  

Set down-bit on Edge routers on DC1

D.  

Set OMP admin distance lower than BGP admin distance

Discussion 0
Questions 16

A company deploys a Cisco SD-WAN solution but has an unstable Internet connection. When the link to vSmart comes back up, the WAN Edge router routing table is not refreshed, and some traffic to the destination network is dropped. The headquarters is the hub site, and it continuously adds new sites to the SD-WAN network. An engineer must configure route refresh between WAN Edge and vSmart within 2 minutes. Which configuration meets this requirement?

Options:

A.  

Option A

B.  

B

C.  

Option B

D.  

E.  

Option C

F.  

Option D

Discussion 0
Questions 17

Refer to the exhibit Which configuration ensures that OSPF routes learned from Site2 are reachable at Sitel and vice-versa?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 18

Which type of connection is created between a host VNet and a transit VNet when configuring Cloud OnRamp for laaS?

Options:

A.  

Azure private endpoint

B.  

GRE tunnel

C.  

IPsec tunnel

D.  

Azure peer link

Discussion 0
Questions 19

Refer to the exhibit. Which issue is shown, and which action must an engineer take to resolve the issue?

Options:

A.  

An IPsec issue; verify and resolve the tunnel configurations on devices.

B.  

An organization name issue; verify and correct the configuration on the devices.

C.  

A certificate issue; verify and correct the certificate attributes.

D.  

A connectivity issue; verify and resolve the reachability to the controller.

Discussion 0
Questions 20

Which attributes are configured to uniquely Identify and represent a TLOC route?

Options:

A.  

system IP address, link color, and encapsulation

B.  

firewall, IPS, and application optimization

C.  

site ID, tag, and VPN

D.  

origin, originator, and preference

Discussion 0
Questions 21

Which cloud based component in cisco SD-WAN is responsible for establishing a secure connection to each WAN edge router and distributes routers and policy information via omp?

Options:

A.  

vBond

B.  

vManage

C.  

vSmart

D.  

WAN Edge

Discussion 0
Questions 22

Drag and drop the security terminologies from the left onto the PCI-compliant network features and devices on the right.

Options:

Discussion 0
Questions 23

Which feature template configures OMP?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 24

Which two sets of identifiers does OMP carry when it advertises TLOC routes between WAN Edge routers? (Choose two.)

Options:

A.  

TLOC public and private address, carrier, and preference

B.  

source and destination IP address, MAC, and site ID

C.  

system IP address, link color, and encapsulation

D.  

VPN ID, local site network, and BGP next-hop IP address

E.  

TLOC public and private address, tunnel ID, and performance

Discussion 0
Questions 25

Refer to the exhibit. A network administrator is setting the queueing value for voice traffic for one of the WAN Edge routers using vManager GUI. Which queue value must be set to accomplish this task?

Options:

A.  

0

B.  

1

C.  

2

D.  

3

Discussion 0
Questions 26

Refer to the exhibit. An enterprise network is connected with an ISP network on an 80 Mbps bandwidth link. The network operation team observes 100 Mbps traffic on the 1Gig-ISP link during peak hours Which configuration provides bandwidth control to avoid traffic congestion during peak hours?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 27

What is the function of the AppNav Controller in the Cisco SD-WAN AppNav solution?

Options:

A.  

It accelerates specific traffic based on preconfigured policies.

B.  

It provides information about configured optimization policies on SD-WAN edge devices.

C.  

It provides configuration and monitoring for WAAS nodes.

D.  

It intercepts and distributes network traffic based on configured policies.

Discussion 0
Questions 28

An engineer modifies a data policy for DIA in VPN 67. The location has two Internet-bound circuits. Only the web browsing traffic must be admitted for DIA. without further discrimination about which transport to use.

Here is the existing data policy configuration:

Which policy configuration sequence meets the requirements?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 29

Refer to the exhibit.

Which shaping-rate does the engineer use to shape traffic at 9 Mbps?

Options:

A.  

9

B.  

9000

C.  

90000

D.  

9000000

Discussion 0
Questions 30

Refer to the exhibit.

An enterprise has hub and spoke topology where it has several VPNs. An engineer must allow users in VPN91 to reach users in VPN92 and VPN10 to reach VPN91 and VPN92. Which configuration meets these requirements?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 31

Which plane assists in the automatic onboarding of the SD-WAN routers into the SD-WAN overlay?

Options:

A.  

Data

B.  

Orchestration

C.  

Management

D.  

Control

Discussion 0
Questions 32

Which two platforms for the Cisco SD-WAN architecture are deployable in a hypervisor on-premises or in IAAS Cloud? (Choose two.)

Options:

A.  

CSR 1000v

B.  

vEdge 100c

C.  

vEdge Cloud

D.  

vEdge 2000

E.  

ISR 4431

Discussion 0
Questions 33

An engineer is configuring a WAN Edge router for DIA based on matching QoS parameters. Which two actions accomplish this task? (Choose two.)

Options:

A.  

Apply a QoS map policy.

B.  

Configure a control policy.

C.  

Configure a centralized data policy.

D.  

Configure NAT on the transport interface.

E.  

Apply a data policy on WAN interface.

Discussion 0
Questions 34

Refer to the exhibit.

An SD-WAN customer has 23 sites connected to its hub site, where a pair of WAN Edge devices and controllers are placed. All other branches have a single WAN Edge device connected to multiprotocol label switching (MPLS) and public internet circuits. An engineer must configure application-aware routing for a branch that has MPLS and public internet circuits provisioned using feature templates. The requirements for application-aware routing are:

    All types of traffic prefers using public-internet circuit.

    If the average latency reaches 100 ms, jitter 85 ms, and packet loss 5%, then video and voice traffic switches to the MPLS circuit.

Which feature template must be configured or modified in addition to configuring a centralized policy?

Options:

A.  

OMP

B.  

VPN interface ethernet

C.  

BFD

D.  

VPN

Discussion 0
Questions 35

An engineer wants to change the configuration of the certificate authorization mode from manual to automated. Which GUI selection will accomplish this?

Options:

A.  

Maintenance > Security

B.  

Configuration > Certificates

C.  

Administration > Settings

D.  

Tools > Operational Commands

Discussion 0
Questions 36

What is the minimum Red Hat Enterprise Linux operating system requirement for a Cisco SD-WAN controller deployment via KVM?

Options:

A.  

RHEL7.5

B.  

RHEL 6.5

C.  

RHEL4.4

D.  

RHEL 6.7

Discussion 0
Questions 37

Which two products are used to deploy Cisco WAN Edge Router virtual platforms? (Choose two.)

Options:

A.  

HP ProLiant DL360 Generatton10 running HP-UX

B.  

Cisco ENCS 5000 Series

C.  

Sun SPARC Node running AIX

D.  

Cisco UCS

E.  

Sun Enterprise M4000 Server running Sun Solans

Discussion 0
Questions 38

Which Cisco router provides a distributed multicore architecture optimized for SD-WAN branch support?

Options:

A.  

Cisco 1000 ISR series

B.  

Cisco 2900 ISR series

C.  

Cisco Catalyst 3850 series

D.  

Cisco 3900 ISR series

Discussion 0
Questions 39

Which feature delivers traffic to the Cisco Umbrella SIG cloud from a Cisco SD-WAN domain?

Options:

A.  

L2TPv3 tunnel

B.  

IPsec tunnel

C.  

local umbrella agent

D.  

source NAT

Discussion 0
Questions 40

Refer to the exhibit. vManage logs are available for the past few months. A device name change deployed mistakenly at a critical site. How is the device name change tracked by operation and design teams?

A)

B)

C)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 41

How is vBond reachability resolved by vManage?

Options:

A.  

OMP

B.  

DNS

C.  

BGP

D.  

IPsec

Discussion 0
Questions 42

An engineer must improve video quality by limiting HTTP traffic to the Internet without any failover. Which configuration in vManage achieves this goal?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 43

An administrator needs to configure SD-WAN to divert traffic from the company's private network to an ISP network. What action should be taken to accomplish this goal?

Options:

A.  

configure the control policy

B.  

configure the data policy

C.  

configure the data security policy

D.  

configure the application aware policy

Discussion 0
Questions 44

Drag and drop the steps from the left Into the order on the right to delete a software image for a WAN Edge router starting with Maintenance > Software Upgrade > Device list on vManage.

Options:

Discussion 0
Questions 45

An engineer must configure the SD-WAN Edge router to identify DSCP 26 traffic coming from the router's local site and then change the DSCP value to DSCP 18 before sending it over to the SD-WAN fabric. What are the two ways to create the required configuration? (Choose two).

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

E.  

Option E

Discussion 0
Questions 46

Which OMP route is selected for equal OMP route preference values on WAN Edge routers?

Options:

A.  

route with higher TLOC preference value

B.  

route with origin type of connected

C.  

route with origin type of static

D.  

route with lower TLOC preference value

Discussion 0
Questions 47

What is the default value for the number of paths advertised per prefix in the OMP feature template?

Options:

A.  

4

B.  

8

C.  

12

D.  

16

Discussion 0
Questions 48

A network administrator is bringing up one WAN Edge for branch connectivity. Which types of tunnels form when the WAN edge router connects to the SD-WAN fabric?

Options:

A.  

DTLS or TLS tunnel with vBond controller and IPsec tunnel with vManage controller.

B.  

DTLS or TLS tunnel with vBond controller and IPsec tunnel with other WAN Edge routers.

C.  

DTLS or TLS tunnel with vSmart controller and IPsec tunnel with other Edge routers.

D.  

DTLS or TLS tunnel with vSmart controller and IPsec tunnel with vBond controller.

Discussion 0
Questions 49

Which type of route represents prefixes received from a local site via an SD-WAN Edge router in a Cisco SD-WAN architecture?

Options:

A.  

TLOC routes

B.  

Service routes

C.  

Multicast routes

D.  

vRoutes

Discussion 0
Questions 50

Which SD-WAN component is configured to enforce a policy to redirect branch-to-branch traffic toward a network service such as a firewall or IPS?

Options:

A.  

vBond

B.  

WAN Edge

C.  

vSmart

D.  

Firewall

Discussion 0
Questions 51

How many vCPUs and how much RAM are recommended to run the vSmart controller on the KVM server for 251 to 1000 devices in software version 20.4.x?

Options:

A.  

4vCPUs. 16 GB

B.  

4 vCPUs. 8 GB

C.  

8vCPUs. 16 GB

D.  

2vCPUs.4GB

Discussion 0
Questions 52

Which component of the Cisco SD-WAN control plane architecture should be located in a public Internet address space and facilitates NAT-traversal?

Options:

A.  

vBond

B.  

WAN Edge

C.  

vSmart

D.  

vManage

Discussion 0
Questions 53

A network administrator configures SNMFV3 on a Cisco WAN Edge router from CL I for monitoring purposes How many characters are supported by the snmp user username command?

Options:

A.  

from 1 to 8

B.  

from 1 to 16

C.  

from 1 to 32

D.  

from 1 to 48

Discussion 0
Questions 54

Which IP address must be reachable by a WAN Edge device for the ZIP process to work?

Options:

A.  

10.1.1.1

B.  

4.4 4.4

C.  

172.16.1.1

D.  

8.8.8.8

Discussion 0
Questions 55

Refer to the exhibit A small company was acquired by a large organization As a result, the new organization decided to update information on their Enterprise RootCA and generated a new certificate using openssl Which configuration updates the new certificate and issues an alert in vManage Monitor | Events Dashboard?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 56

Refer to the exhibit. An engineer is troubleshooting a control connection issue on a WAN Edge device that shows socket errors. The packet capture shows some ICMP packets dropped between the two devices. Which action resolves the issue?

Options:

A.  

Recover the vManage controller that is down m a high availability cluster

B.  

Change the system IP or restart the VWN Edge 4 the system IP is changed

C.  

Remove IP duplication in the network and configure a unique IP address

D.  

Recover vBond or wart for the controller to reload which could be caused by a reset

Discussion 0
Questions 57

What does forward error correction addresses in Cisco SO-WAN?

Options:

A.  

inefficient traffic forwarding caused oy inbound shapers

B.  

reduced application performance degradation rotated to service degradation

C.  

applications with occasional invalid data input and poor performance

D.  

traffic flows with increased delay over a particular transport

Discussion 0
Questions 58

An enterprise needs DIA on some of its branches with a common location ID: A041:B70C: D78E::18 Which WAN Edge configuration meets the requirement?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 59

Refer to the exhibit.

The SD-WAN network is configured with a default full-mesh topology. The SD-WAN engineer wants the Barcelona WAN Edge to use MPLS TLOC as the preferred TLOC when communicating with Rome site. Which configuration must the engineer use to create a list to select MPLS color toward the Rome TLOC?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 60

Which policy allows communication between TLOCs of data centers and spokes and blocks communication between spokes?

Options:

A.  

centralized data policy

B.  

centralized control policy

C.  

localized control policy

D.  

localized data policy

Discussion 0
Questions 61

Which two mechanisms are used by vManage to ensure that the certificate serial number of the WAN Edge router that is needed to authenticate is listed in the WAN Edge Authorized Señal Number Hst’ (Choose two)

Options:

A.  

Synchronize to the PnP

B.  

Manually upload it to vManage

C.  

The devices register to vManage directly as the devices come online

D.  

The vManage is shipped with the list

E.  

Synchronize to the Smart Account

Discussion 0
Questions 62

What is the advantage of instating the controller on-premises?

Options:

A.  

ease of deployment and management

B.  

full control of the data piano and the control plane

C.  

automatic geographical redundancy and security

D.  

scalability and a cost-saving

Discussion 0
Questions 63

How many subnets are necessary in Azure VNet for a WAN Edge device to function in the cloud deployment?

Options:

A.  

CSR is the WAN Edge device that is supported in the Microsoft cloud. The Microsoft underlay cloud fabric performs the management function.

B.  

There must be three subnets in VNet: management, public, and services.

C.  

One public subnet is required in VNet. The Microsoft underlay cloud fabric performs all of the routing functions for WAN Edge.

D.  

Public and services subnets are required in VNet. The Microsoft underlay cloud fabric performs the management function.

Discussion 0
Questions 64

Refer to the exhibit.

Which configuration change is needed to configure the tloc-extention on Branch1-Edge1?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 65

Which VPNs must be configured outside the workflow to complete the SD-WAN overlay setup when using the Quick Connect workflow?

Options:

A.  

service and transport VPNs

B.  

service VPNs

C.  

transport VPNs

D.  

management VPNs

Discussion 0
Questions 66

Which two actions are necessary to set the Controller Certificate Authorization mode to indicate a root certificate? (Choose two)

Options:

A.  

Select the Controller Certificate Authorization mode that is recommended by Cisco

B.  

Change the organization name of the Cisco SO-WAN fabric.

C.  

Upload an SSL certificate to vManape,

D.  

Select a private certificate signing authority instead of a public certificate signing authority

E.  

Select a validity period from the drop-down menu

Discussion 0
Questions 67

What two functions describe the TCP optimization tool used in the Cisco SD-WAN? (Choose two.)

Options:

A.  

It uses TCP acknowledgment (ACK).

B.  

It is used to take care of high packet loss for control traffic.

C.  

It terminates TCP connections locally at the WAN edge.

D.  

It uses TCP selective acknowledgment (SACK).

E.  

It terminates TCP connections at the remote WAN edge.

Discussion 0
Questions 68

What is the behaviour of vBond orchestrator?

Options:

A.  

It maintains vSmart and WAN Edge routers secure connectivity state

B.  

it builds permanent connections with vSmart controllers

C.  

it updates vSmart of WAN Edge routers behind NAT devices using OMP.

D.  

It builds permanent connections with WAN Edge routers

Discussion 0
Questions 69

An engineer must use data prefixes to configure centralized data policies using the vManage policy configuration wizard. What is the first step to accomplish this task?

Options:

A.  

Create groups of interest

B.  

Configure network topology.

C.  

Configure traffic rules.

D.  

Apply policies to sites and VPNs.

Discussion 0
Questions 70

What is a benefit of the application aware firewall feature in the Cisco SD-WAN solution?

Options:

A.  

application monitoring

B.  

application malware protection

C.  

application visibility

D.  

control policy enforcement

Discussion 0
Questions 71

Which on-the-box security feature supported by the Cisco ISR 4451 SD-WAN device and not on vEdge?

Options:

A.  

Cloud Express service

B.  

Enterprise Firewall with Application Awareness

C.  

reverse proxy

D.  

IPsec/GRE cloud proxy

Discussion 0
Questions 72

A network is configured with IP connectivity, and the routing protocol between devices started having problems right after the maintenance window to implement network changes. Troubleshoot and resolve to a fully functional network to ensure that:

R4

R5

Options:

Discussion 0
Questions 73

Which policy tracks path characteristics such as loss, latency, and jitter in vManage?

Options:

A.  

VPN

B.  

control

C.  

app-route

D.  

data

Discussion 0
Questions 74

Which platform cannot provide IPS and URL filtering capabilities?

Options:

A.  

Cisco CSR 1000V

B.  

Cisco ISR 1000

C.  

Cisco Catalyst 8300

D.  

Cisco ISR 4000

Discussion 0
Questions 75

Which configuration step is taken on vManage after WAN Edge list is uploaded?

Options:

A.  

Send the list to controllers

B.  

Enable the ZTP process

C.  

Verify the device certificate

D.  

Set the device as valid

Discussion 0
Questions 76

Refer to the exhibit. Which configuration ensures that OSPP routes learned from Site2 are reachable at Stein and vice-versa?

Options:

A.  

B.  

C.  

Discussion 0
Questions 77

Refer to the exhibit An engineer must configure a QoS policy between me hub and site A (spoke) over a standard internet circuit where traffic shaping is adjusted automatically based on evaiiabk» bandwidth Which configuration meets the requirement?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 78

Refer to the exhibit The network team must configure ElGRP peering at HQ with devices in the service VPN connected to WAN Edge CSRv. CSRv is currently configured with

Which configuration on the WAN Edge meets the requiremnet

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 79

How is a TLOC uniquely identified from a WAN Edge router to the SD-WAN transport network?

Options:

A.  

system IP address

B.  

VPN ID

C.  

OMP

D.  

SD-WAN site ID

Discussion 0
Questions 80

Refer to the exhibit.

Customer XYZ cannot provision dual connectivity on both of its routers due to budget constraints but wants to use both R1 and R2 interlaces for users behind them for load balancing toward the hub site. Which configuration achieves this objective?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 81

Which protocol is used between redundant vSmart controllers to establish a permanent communication channel?

Options:

A.  

IPsec

B.  

HTTPs

C.  

DTLS

D.  

SSL

Discussion 0
Questions 82

What must an engineer conewef when decoying an SD-WAN on-pfemlses architecture based on ESXi hypervisor?

Options:

A.  

Cisco must provision the backup and snapshots platform lor ihe SD-WAN arctoecture

B.  

The managed service provider must provision controllars with their appropriate cerHwcatsi

C.  

The IT team a required to provision the SO-WAN controllers and Is responsAte lor backups and disaster recovery implementation

D.  

The IT team will be given access by Cisco to a vManage for configuration If templates and policies coeigmalim

Discussion 0
Questions 83

Drag and drop the alarm states from the left onto the corresponding alarm descriptions on the right.

Options:

Discussion 0
Questions 84

An administrator must configure an ACL for traffic coming in from the service-side VPN on a specific WAN device with circuit ID 391897770. Which policy must be used to configure this ACL?

Options:

A.  

local data policy

B.  

central data policy

C.  

app-aware policy

D.  

central control policy

Discussion 0
Questions 85

In which device state does the WAN edge router create control connections, but data tunnels are not created?

Options:

A.  

valid

B.  

backup

C.  

active

D.  

staging

Discussion 0
Questions 86

Which third-party Enterprise CA server must be used (or a cloud-based vSmart controller?

Options:

A.  

RootCert

B.  

Microsoft

C.  

RADIUS

D.  

VeriSign

Discussion 0
Questions 87

Refer to the exhibit. A Cisco SD-WAN network carries traffic for several departments and over 1200 users with several applications at site A and site B branches over the MPLS1 circuit. An engineer is provisioning a higher bandwidth on-demand metro circuit as a backup connection. Which two configurations must the engineer apply to implement the on-demand tunnels? (Choose two.)

Options:

A.  

B.  

C.  

D.  

E.  

Discussion 0
Questions 88

Which two different states of a WAN Edge certificate are shown on vManage? (Choose two.)

Options:

A.  

inactive

B.  

active

C.  

staging

D.  

invalid

E.  

provisioned

Discussion 0
Questions 89

An engineer provisions a WAN Edge router. Which command should be used from the WAN Edge router to activate it with vManage?

Options:

A.  

request vedge-cloud activate serial token

B.  

request vedge-cloud activate chassis-number organization

C.  

request vedge-cloud activate chassis-number token

D.  

request vedge-cloud activate chassis-number serial <:serial>

Discussion 0
Questions 90

Which pathway under Monitor > Network > Select Device is used to verify service insertion configuration?

Options:

A.  

System Status

B.  

Troubleshooting

C.  

Real Time

D.  

Events

Discussion 0
Questions 91

How are policies deployed on cloud-tiosted Cisco SD-WAN controllers?

Options:

A.  

Policies are created on vSmart and enforced by vSmart

B.  

Policies are created on vSmart and enforced by vManage

C.  

Policies are created on vManage and enforced by vManage.

D.  

Policies are created on vManage and enforced by vSman

Discussion 0
Questions 92

Which statement describes the requirement of integrating a secure internet gateway (SIG) with a Cisco SD-WAN Edge device?

Options:

A.  

Attached to SIG tunnels, trackers monitor the respective SIG endpoints.

B.  

Credentials for a smart account are required.

C.  

A Cisco umbrella organization ID is needed to establish the SIG.

D.  

Based on routing or policy, all customer internet traffic must be forwarded to the SIG.

Discussion 0
Questions 93

At which layer does the application-aware firewall block applications on a WAN Edge?

Options:

A.  

3

B.  

7

C.  

5

D.  

2

Discussion 0
Questions 94

An engineer is adding a tenant with location ID 399533345 in vManage. What is the maximum number of alphanumeric characters that is accepted in the tenant name filed?

Options:

A.  

64

B.  

128

C.  

256

D.  

8

Discussion 0
Questions 95

An engineer must configure local redundancy on a site. Which configuration accomplish this task?

Options:

A.  

vpn 0interface interface-name

B.  

tloc extension interlace nametloc extension interface interface name

C.  

vpn 0tloc extension interface

D.  

interface-flameinterface interface-name tloc-extension

Discussion 0
Questions 96

Which pathway under Monitor > Network > Select Device is used to verify service insertion configuration?

Options:

A.  

Real Time

B.  

System Status

C.  

ACL Logs

D.  

Events

Discussion 0
Questions 97

An engineer is configuring a centralized policy to influence network route advertisement. Which controller delivers this policy to the fabric?

Options:

A.  

vSmart

B.  

vManage

C.  

WAN Edge

D.  

vBond

Discussion 0
Questions 98

What are the two components of an application-aware firewall? (Choose two.)

Options:

A.  

zone pair

B.  

sequence

C.  

lists

D.  

default action

E.  

sequence action

F.  

firewall policy

Discussion 0
Questions 99

An organization wants to use the cisco SD-WAN regionalized service-chaining feature to optimize cost and user experience with application in the network, which allows branch routers to analyze and steer traffic toward the required network function. Which feature meets this requirement?

Options:

A.  

Cloud Services Platform

B.  

VNF Service Chaning

C.  

Cloud onRamp for Colocation

D.  

Cloud onRamp for laaS

Discussion 0
Questions 100

In which VPN is the NAT operation on an outgoing interface configured for direct Interne! access?

Options:

A.  

1

B.  

10

C.  

512

D.  

0

Discussion 0
Questions 101

A bank is looking for improved customer experience for applications and reduce overhead related to compliance and security. Which key feature or features of the Cisco SD-WAN solution will help the bank to achieve their goals?

Options:

A.  

Integration with PaaS providers to offer the best possible application experience

B.  

QoS including application prioritization and meeting critical applications SLA for selecting optimal path.

C.  

implementation of a modem age core banking system

D.  

implementation of BGP across the enterprise routing for selecting optimal path

Discussion 0
Questions 102

What is an advantage of using auto mode versus static mode of power allocation when an access point is connected to a PoE switch port?

Options:

A.  

It detects the device is a powered device

B.  

All four pairs of the cable are used

C.  

Power policing is enabled at the same time

D.  

The default level is used for the access point

Discussion 0
Questions 103

Refer to the exhibit.

A network administrator is configuring OMP in vManage to advertise all the paths for the same prefix from a site that has two WAN Edge devices Each WAN Edge device is connected to three ISPs and two private MPLS transports. What is the minimum value for 'Number of Paths advertised per Prefix" that should be configured?

Options:

A.  

2

B.  

3

C.  

5

D.  

10

Discussion 0
Questions 104

Which device information is required on PNP/ZTP to support the zero-touch onboarding process?

Options:

A.  

interface IP address

B.  

system IP address

C.  

public DNS entry

D.  

serial and chassis numbers

Discussion 0
Questions 105

Which two services are critical for zero touch provisioning on-boarding? (Choose two)

Options:

A.  

SNMP

B.  

DNS

C.  

DHCP

D.  

AAA

E.  

EMAIL

Discussion 0
Questions 106

In which Cisco SD-WAN deployment scenario does Cisco Umbrella SIG deliver the most value?

Options:

A.  

when a centralized Internet breakout solution is implemented

B.  

when resource-intensive security operations are offloaded from entry-level WAN Edge devices

C.  

when the identity of several WAN Edge devices is verified throughout the networkthroughout the network

Discussion 0
Questions 107

A network engineer sets tags in OMP for routes that were originated in the Service VPN. Which monitoring tab must be used to verify tags on the next hop?

Options:

A.  

Realtime > OMP Received TLOCs

B.  

Troubleshooting > Simulate Flows

C.  

Realtime > OMP Received Routes

D.  

Troubleshooting > Tunnel Health

Discussion 0
Questions 108

Which two WAN Edge devices should be deployed in a cloud? (Choose two.)

Options:

A.  

vEdge 5000v

B.  

ASR 1000v

C.  

CSR 1000v

D.  

vEdge 100wm

E.  

vEdge cloud

Discussion 0
Questions 109

What is a key element used in a vBond Orchestrator redundancy topology?

Options:

A.  

fully qualified domain name

B.  

DHCP server

C.  

load-balancer with health probes

D.  

stun server

Discussion 0
Questions 110

The branch users of an organization must be prevented from accessing malicious destinations, and the local files on users' systems must be protected from malware. Which two Cisco products must the organization deploy? (Choose two.)

Options:

A.  

Cisco Stealthwatch

B.  

Cisco Umbrella

C.  

Cisco AMP

D.  

Cisco Cloudlock

E.  

Cisco SecureX

Discussion 0
Questions 111

Which controller is excluded from the process of checking against the authorized, allowed list?

Options:

A.  

vBond

B.  

PnP

C.  

vSmart

D.  

vManage

Discussion 0
Questions 112

An organization requires the use of integrated preventative engines, exploit protection, and the most updated and advanced signature-based antivirus with sandboxing and threat intelligence to stop malicious attachments before they reach users and get executed. Which Cisco SD-WAN solution meets the requirements?

Options:

A.  

Cisco Trust Anchor module

B.  

URL filtering and Umbrella DNS security

C.  

Cisco AMP and Threat Grid

D.  

Snort IPS

Discussion 0
Questions 113

What do receivers request to join multicast streams in a Cisco SO-WAN network?

Options:

A.  

IGMP membership reports directly with a multicast router.

B.  

Multicast service routes with the vSmart controller

C.  

IGMP membership reports directly with the vBond orchestrator.

D.  

PIM messages with the nearest neighboring multicast router.

Discussion 0
Questions 114

What is the maximum number of IPsec that are temporarily created and converged on a new set if IPsec Sas in the pairwise keys process during a simultaneous rekey?

Options:

A.  

2

B.  

4

C.  

6

D.  

8

Discussion 0
Questions 115

Which hardware component is involved in the Cisco SD-WAN authentication process for ISR platforms?

Options:

A.  

TPMD

B.  

ZTP

C.  

TPC

D.  

SUDI

Discussion 0
Questions 116

What is an attribute of TLOC’?

Options:

A.  

encryption

B.  

local preference

C.  

tag

D.  

service

Discussion 0
Questions 117

Drag and drop the REST API calls from the left onto the functions on the right.

Options:

Discussion 0
Questions 118

Drag and drop the vManage policy configuration procedures from the left onto the correct definitions on the right.

Options:

Discussion 0
Questions 119

Refer to the exhibit The network team must configure application-aware routing for the Service VPN 50.0.0.0/16 The SLA must prefer MPLS for video traffic but the remaining traffic must use a public network What must be defined other than applications before the application-aware policy is create?

Options:

A.  

SLA Class, Site VPN. Prefix

B.  

Data Prefix, Site VPN TLOC

C.  

Application, SLA VPN. Prefix

D.  

Color, SLA Class, Sue, VPN

Discussion 0
Questions 120

Refer to the exhibit, which configuration configures IPsec tunnels in active and standby?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 121

An enterprise deployed a Cisco SD-WAN solution with hub-and-spoke topology using MPLS as the preferred network over the Internet. A network engineer must implement an application-aware routing policy to allow ICMP traffic to be load-balanced over both the available links. Which configuration meets the requirement?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 122

An engineer must configure egress QoS for voice traffic. Which queue must the engineer configure on the WAN Edge router to accomplish the task?

Options:

A.  

queue 0

B.  

queue 1

C.  

queue 3

D.  

queue 7

Discussion 0
Questions 123

Refer to the exhibit An engineer is configuring a QoS policy to shape traffic for VLAN 100 on a subinterface Which policy configuration accomplishes the task?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 124

Drag and drop the attributes from the left that make each transport location unique onto the right. Not all options are used.

Options:

Discussion 0
Questions 125

Which service VPN must be reachable from all WAN Edge devices and the controllers?

Options:

A.  

VPN0

B.  

VPN10

C.  

VPN215

D.  

VPN512

Discussion 0
Questions 126

REST applications communicate over HTTP or HTTPS to make calls between network devices. Which two HTTPS standard methods are included? (Choose two.)

Options:

A.  

Array

B.  

DELETE

C.  

POST

D.  

Scalar

E.  

Object

Discussion 0
Questions 127

Which component is used to optimize the multicast distribution tree enabled through the multicast network?

Options:

A.  

IGMP client

B.  

vManage controllers

C.  

VPN concentrator

D.  

OMP replicator

Discussion 0
Questions 128

What problem happens on a device with two serial numbers, a unique device identifier (UDI), and secure unique device identifier (SUDI) when an engineer provisions ISR 4000 by PnP using only a UDI?

Options:

A.  

It encounters spanning tree issues

B.  

It faces interface buffer overflow patterns

C.  

It encounters redirection problems.

D.  

It encounters memory overload problems

Discussion 0
Questions 129

Which command disables the logging of syslog messages to the local disk?

Options:

A.  

no system logging disk enable

B.  

no system logging disk local

C.  

system logging disk disable

D.  

system logging server remote

Discussion 0
Questions 130

Which timer specifies information in the cache after all OMP sessions are lost at location S0123T4E56F78?

Options:

A.  

advertisement interval

B.  

EOR timer

C.  

graceful restart timer

D.  

hold time

Discussion 0
Questions 131

Refer to the exhibit.

Customer XYZ cannot provison dual connectivity on both Its routers due to budget constratnts but wants to use tnth RI and R2 interface for users behind them for load toward the hub site Which configurauon achieves this objectives?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 132

In a Cisco SD-WAN network, which component is responsible for distributing route and policy information via the OMP?

Options:

A.  

vManage

B.  

vSmart Controler

C.  

vBond Orchestrator

D.  

WAN Edge Router

Discussion 0
Questions 133

How many vManage NMSs should be installed in each domain to achieve scalability and redundancy?

Options:

A.  

two instances

B.  

two clusters

C.  

three or more in a cluster

D.  

two or more in a cluster

Discussion 0