Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Question and Answers

Implementing Cisco SD-WAN Solutions (300-415 ENSDWI)

Last Update Oct 18, 2025
Total Questions : 441

We are offering FREE 300-415 Cisco exam questions. All you do is to just go and sign up. Give your details, prepare 300-415 free exam questions and then go for complete pool of Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) test questions that will help you more.

300-415 pdf

300-415 PDF

$40.25  $114.99
300-415 Engine

300-415 Testing Engine

$47.25  $134.99
300-415 PDF + Engine

300-415 PDF + Testing Engine

$61.25  $174.99
Questions 1

Refer to the exhibit.

Which configuration change is needed to configure the tloc-extention on Branch1-Edge1?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 2

Which Cisco SD-WAN component the initial communication between WAN Edge devices to join the fabric?

Options:

A.  

WAN Edge Router

B.  

vSmart Controller

C.  

vManage

D.  

vBond Orchestrator

Discussion 0
Questions 3

Where on vManage does an engineer find the details of control node failure?

Options:

A.  

Alarms

B.  

Events

C.  

Audit log

D.  

Network

Discussion 0
Questions 4

What are the two advantages of deploying cloud-based Cisco SD-WAN controllers? (Choose two.)

Options:

A.  

centralized control and data plane

B.  

distributed authentication policies

C.  

management of SLA

D.  

infrastructure as a service

E.  

centralized raid storage of data

Discussion 0
Questions 5

Which percentage for total memory or total CPU usage for a device is classified as normal in the WAN Edge Health pane?

Options:

A.  

more than 80 percent usage

B.  

less than 70 percent usage

C.  

between 70 to 90 percent usage

D.  

more than 90 percent usage

Discussion 0
Questions 6

Refer to the exhibit. Which configuration extends the INET interface on R1 to be used by R2 for control and data connections?

A)

B)

C)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

Discussion 0
Questions 7

An engineer configured a data policy called ROME-POLICY. Which configuration allows traffic flow from the Rome internal network toward other sites?

Options:

A.  

apply-policy site-list Rome data-policy ROME-POLICY from-tunnel

B.  

apply-policy site-list Rome data-policy ROME-POLICY from-service

C.  

site-list Rome control-policy ROME-POLICY in

D.  

site-list Rome control-policy ROME-POLICY out

Discussion 0
Questions 8

An engineer must improve video quality by limiting HTTP traffic to the Internet without any failover. Which configuration in vManage achieves this goal?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 9

Which attributes are configured to uniquely Identify and represent a TLOC route?

Options:

A.  

system IP address, link color, and encapsulation

B.  

firewall, IPS, and application optimization

C.  

site ID, tag, and VPN

D.  

origin, originator, and preference

Discussion 0
Questions 10

A policy is created to influence routing path in the network using a group of prefixes. What policy application will achieve this goal when applied to a site List?

Options:

A.  

vpn-membership policy

B.  

cflowd-template

C.  

app-route policy

D.  

control-policy

Discussion 0
Questions 11

What is a requirement for a WAN Edge to reach vManage, vBond, and vSmart controllers in a data center?

Options:

A.  

IGP

B.  

QoS

C.  

TLS

D.  

OMP

Discussion 0
Questions 12

When redistribution is configured between OMP and BGP at two Data Center sites that have Direct Connection interlink, which step avoids learning the same routes on WAN Edge routers of the DCs from LAN?

Options:

A.  

Define different VRFs on both DCs

B.  

Set same overlay AS on both DC WAN Edge routers

C.  

Set down-bit on Edge routers on DC1

D.  

Set OMP admin distance lower than BGP admin distance

Discussion 0
Questions 13

Which pathway under Monitor > Network > Select Device is used to verify service insertion configuration?

Options:

A.  

System Status

B.  

Troubleshooting

C.  

Real Time

D.  

Events

Discussion 0
Questions 14

Which device information is required on PNP/ZTP to support the zero-touch onboarding process?

Options:

A.  

interface IP address

B.  

system IP address

C.  

public DNS entry

D.  

serial and chassis numbers

Discussion 0
Questions 15

Which multicast component is irrelevant when defining a multicast replicator outside the local network without any multicast sources or receivers?

Options:

A.  

PIM interfaces

B.  

TLOC

C.  

overlay BFD

D.  

OMP

Discussion 0
Questions 16

An engineer must apply the configuration for certificate installation to vBond Orchestrator and vSmart Controller. Which configuration accomplishes this task?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 17

Company ABC has decided to deploy the controllers using the On-Prem method. How does the administrator upload the WAN Edge list to the vManage?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 18

Drag and drop the security terminologies from the left onto the PCI-compliant network features and devices on the right.

Options:

Discussion 0
Questions 19

Which configuration step is taken on vManage after WAN Edge list is uploaded?

Options:

A.  

Send the list to controllers

B.  

Enable the ZTP process

C.  

Verify the device certificate

D.  

Set the device as valid

Discussion 0
Questions 20

Which API call retrieves a list of all devices in the network?

Options:

A.  

https://vmanage_IP_address/dataservice/system/device/{{model}}

B.  

http://vmanage_IP_address/dataservice/system/device/{{model}}

C.  

http://vmanage_IP_address/api-call/system/device/{{model}}

D.  

https://vmanage_IP_address/api-call/system/device/{{model}}

Discussion 0
Questions 21

A voice packet requires a latency of 50 msec. Which policy is configured to ensure that a voice packet is always sent on the link with less than a 50 msec delay?

Options:

A.  

centralized control

B.  

localized data

C.  

localized control

D.  

centralized data

Discussion 0
Questions 22

Which Cisco SD-WAN feature propagates packets with SGTs through the network?

Options:

A.  

TrustSec Inline Tagging

B.  

SGT Enforcement

C.  

QoE

D.  

SXP

Discussion 0
Questions 23

Which combination of platforms are managed by vManage?

Options:

A.  

ISR4321, ASR1001, ENCS, lSRv

B.  

ISR4351, ASR1002HX, vEdge2000, vEdge Cloud

C.  

ISR4321, ASR1001, Nexus, ENCS

D.  

lSR435l, ASRl009, vEdge2000, CSR1000v

Discussion 0
Questions 24

Which two different states of a WAN Edge certificate are shown on vManage? (Choose two.)

Options:

A.  

inactive

B.  

active

C.  

staging

D.  

invalid

E.  

provisioned

Discussion 0
Questions 25

The network administrator is configuring a QoS scheduling policy on traffic received from transport side tunnels on WAN Edge 5000 routers at location 406141498 Which command must be configured on these devices?

Options:

A.  

cloud-qos

B.  

service qos

C.  

cloud-mis qos

D.  

mis qos

Discussion 0
Questions 26

Refer to the exhibit. Which configuration ensures that OSPP routes learned from Site2 are reachable at Stein and vice-versa?

Options:

A.  

B.  

C.  

Discussion 0
Questions 27

An engineer is modifying an existing data policy for VPN 115 to meet these additional requirements:

    When browsing government websites, the traffic must use direct internet access.

    The source address of the traffic leaving the site toward the government websites must be set to an IP range associated with the country itself, a particular TLOC.

The policy configuration is as follows:

Which policy sequence meets the requirements without interfering with other destinations?

Options:

A.  

sequence 30

match

destination-data-prefix-list GOVERNMENT-WEBSITES

!

action accept

set

local-tloc-list

color biz-internet

B.  

sequence 25

match

destination-data-prefix-list GOVERNMENT-WEBSITES

action accept

nat use-vpn 0

C.  

sequence 15

match

source-data-prefix-list GOVERNMENT-WEBSITES

action accept

set

local-tloc-list

color private1

D.  

sequence 15

match

destination-data-prefix-list GOVERNMENT-WEBSITES

!

action accept

set

local-tloc-list

color biz-internet

Discussion 0
Questions 28

I

In which file format is a critical severity report downloaded from the MONITOR I ALARM tab in the vManage GUI?

Options:

A.  

.txt

B.  

.pdf

C.  

csv

D.  

xIsx

Discussion 0
Questions 29

A customer has 1 to 100 service VPNs and wants to restrict outbound updates for VPN1 Which control policy configuration restricts these updates?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 30

Which component is used for stateful inspection of TCP, UDP. and ICMP flows in Cisco SD-WAN firewall policies?

Options:

A.  

zones

B.  

sites

C.  

subnets

D.  

interfaces

Discussion 0
Questions 31

Which two advanced security features are available on the Cisco SD-WAN WAN Edge (vEdge) device? (Choose two.)

Options:

A.  

URL filtering

B.  

snort intrusion prevention system

C.  

Cisco Umbrella DNS Security

D.  

Cisco AMP and AMP Threat Grid

E.  

Enterprise Firewall

Discussion 0
Questions 32

WAN Edge routers are configured manually to use UDP port offset to use nondefault offset values when IPsec tunnels are created. What is the offse range?

Options:

A.  

1-19

B.  

0-18

C.  

0-19

D.  

1-18

Discussion 0
Questions 33

Drag and drop the vManage policy configuration procedures from the left onto the correct definitions on the right.

Options:

Discussion 0
Questions 34

Which controller is used for provisioning and configuration in a Cisco SD-WAN solution?

Options:

A.  

vBond

B.  

Manage

C.  

WAN Edge router

D.  

vSmart

Discussion 0
Questions 35

Which VPN must be present on at least one interface to install Cisco vManage and integrate it with WAN Edge devices in an overlay network site ID:S4307T7E78F29?

Options:

A.  

VPN 512

B.  

any VPN number selected

C.  

services VPN range 0-511

D.  

VPNO

Discussion 0
Questions 36

A large retail organization decided to move some of the branch applications to the AWS cloud. How does the network architect extend the in-house Cisco SD-WAN branch to cloud network into AWS?

Options:

A.  

Create virtual WAN Edge devices Cloud through the AWS online software store

B.  

Create virtual instances of vSmart Cloud through the AWS online software store

C.  

Create GRE tunnels to AWS from each branch over the Internet

D.  

Install the AWS Cloud Router in the main data center and provide the connectivity from each branch

Discussion 0
Questions 37

How many subnets are necessary in Azure VNet for a WAN Edge device to function in the cloud deployment?

Options:

A.  

CSR is the WAN Edge device that is supported in the Microsoft cloud. The Microsoft underlay cloud fabric performs the management function.

B.  

There must be three subnets in VNet: management, public, and services.

C.  

One public subnet is required in VNet. The Microsoft underlay cloud fabric performs all of the routing functions for WAN Edge.

D.  

Public and services subnets are required in VNet. The Microsoft underlay cloud fabric performs the management function.

Discussion 0
Questions 38

When software is upgraded on a vManage NMS, which two image-adding options store images in a local vManage software repository? (Choose two.)

Options:

A.  

To be downloaded over a SMTP connection

B.  

To be downloaded over a SNMP connection

C.  

To be downloaded over an out-of-band connection

D.  

To be downloaded over a control plane connection

E.  

To be downloaded over an ICMP connection

Discussion 0
Questions 39

What is the advantage of instating the controller on-premises?

Options:

A.  

ease of deployment and management

B.  

full control of the data piano and the control plane

C.  

automatic geographical redundancy and security

D.  

scalability and a cost-saving

Discussion 0
Questions 40

Which on-the-box security feature supported by the Cisco ISR 4451 SD-WAN device and not on vEdge?

Options:

A.  

Cloud Express service

B.  

Enterprise Firewall with Application Awareness

C.  

reverse proxy

D.  

IPsec/GRE cloud proxy

Discussion 0
Questions 41

For data plane resiliency, what does the Cisco SD-WAN software implement?

Options:

A.  

BFD

B.  

establishing affinity between vSmart controllers and WAN Edge routers

C.  

multiple vBond orchestrators

D.  

OMP

Discussion 0
Questions 42

Which two performance data details are provided by Cisco SO-WAN vAnalytics? (Choose two)

Options:

A.  

jitter loss and latency for data tunnels

B.  

application quality of experience score from zero to ten

C.  

detail on total cost of ownership for the fabric

D.  

certificate authority status (health and expiration dates) for all controllers

E.  

view devices connected to a vManage NMS

Discussion 0
Questions 43

An engineer must configure a centralized policy on a site in which all HTTP traffic should use the Public Internet circuit if the loss on this circuit is below 10%. otherwise MPLS should be used Which configuration wizard fulfils this requirement?

Options:

A.  

Create Applications or Groups of Interest > Configure Traffic Rules > Apply Policies to Sites and VPNs

B.  

Configure VPN Membership > Apply Policies to Sites and VPNs

C.  

Create Applications or Groups of interest > Configure Traffic Data > Apply Policies to Sites and VPNs

D.  

Configure Topology > Apply Policies to Sites and VPNs

Discussion 0
Questions 44

What is a benefit of using REST APIs?

Options:

A.  

predefined automation and orchestration platform for event management and logging

B.  

user-defined automation and integration into other orchestration systems or tools

C.  

vAnalytics to simplify operational services integration and real-time event monitoring

D.  

predefined SD-WAN controller with other platform integration for event management and logging

Discussion 0
Questions 45

An SD-WAN customer must ensure that its network operations team can monitor and update the NTP server if needed on a WAN Edge in HQ. Which configuration meets this requirement?

Options:

A.  

system

usergroup operator

task interface write

B.  

system

aaa

usergroup operator

task policy write

C.  

system

aaa

usergroup operator

task system write

D.  

system

aaa

usergroup operator

task security write

Discussion 0
Questions 46

Exhibit.

The SD-WAN network is configured with a default full-mash topology. An engineer wants Barcelona and Paris to communicate to each other through the London site using a control Which control policy configuration accomplishes the task?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 47

How is TLOC defined?

Options:

A.  

It is represented by a unique identifier to specify a site in as SD-WAN architecture.

B.  

It specifies a Cisco SD-WAN overlay in a multitenant vSMART deployment.

C.  

It is a unique collection of GRE or iPsec encapsulation, link color, and system IP address.

D.  

It is represented by group of QoS policies applied to a WAN Edge router.

Discussion 0
Questions 48

Refer to the exhibit. The Cisco SD-WAN is deployed using the default topology. The engineer wants to configure a service insertion policy such that all data traffic between Rome to Paris is forwarded through the NGFW located in London. Which configuration fulfills this requirement, assuming that the Service VPN ID is 1?

Options:

A.  

B.  

C.  

D.  

Discussion 0
Questions 49

A network administrator is configuring an application-aware firewall between inside zones to an outside zone on a WAN edge router using vManage GUI. What kind of Inspection is performed when the ‘’inspect’’ action is used?

Options:

A.  

stateful inspection for TCP and UDP

B.  

stateful inspection for TCP and stateless inspection of UDP

C.  

IPS inspection for TCP and-Layer 4 inspection for UDP

D.  

Layer 7 inspection for TCP and Layer 4 inspection for UDP

Discussion 0
Questions 50

Which policy is configured to ensure that a voice packet is always sent on the link with less than a 50 msec delay?

Options:

A.  

localized data policy

B.  

localized control policy

C.  

centralized data policy

D.  

centralized control policy

Discussion 0
Questions 51

Which configuration allows users to reach YouTube from a local Internet breakout?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 52

Drag and drop the route verification output from show omp tlocs from the left onto the correct explanations on the right.

Options:

Discussion 0
Questions 53

Drag and drop the BFD parameters from the left onto the BFD configurations on the right.

Options:

Discussion 0
Questions 54

Which protocol runs between the vSmart controllers and WAN Edge routers when the vSmart controller acts like a route reflector?

Options:

A.  

OMP outside the DTLS/TLS control connection

B.  

BGP inside the DTLS/TLS

C.  

IPsec inside the DTLS/TLS control connection

D.  

OMP inside the DTLS/TLS control connection

Discussion 0
Questions 55

What is the function of the AppNav Controller in the Cisco SD-WAN AppNav solution?

Options:

A.  

It accelerates specific traffic based on preconfigured policies.

B.  

It provides information about configured optimization policies on SD-WAN edge devices.

C.  

It provides configuration and monitoring for WAAS nodes.

D.  

It intercepts and distributes network traffic based on configured policies.

Discussion 0
Questions 56

How does the Cisco SD-WAN Cloud OnRamp solution rate the performance of a SaaS application from a branch office to the cloud via a given path?

Options:

A.  

It computes a quality-of-experience score.

B.  

It monitors the packet loss of priority queues.

C.  

It counts the number of interface errors.

D.  

It measures the delay and jitter of the path.

Discussion 0
Questions 57

Which two vRoute attributes should be matched or set in vSmart policies and modified by data policies? (Choose two.)

Options:

A.  

site ID

B.  

preference

C.  

VPN

D.  

TLOC

E.  

origin

Discussion 0
Questions 58

Refer to the exhibit The engineering must assign tags to 3 Of its 74 server networks as soon as they are advertised to peers These server network must not be advertised AS which configuration fulfil the requirement?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 59

Which queue must an engineer configure for control and BFD traffic for convergence on a WAN Edge router?

Options:

A.  

queue 0

B.  

queue 1

C.  

queue 2

D.  

queue 7

Discussion 0
Questions 60

An engineer is configuring a centralized policy to influence network route advertisement. Which controller delivers this policy to the fabric?

Options:

A.  

vSmart

B.  

vManage

C.  

WAN Edge

D.  

vBond

Discussion 0
Questions 61

Drag and drop the definitions from the left to the configuration on the right.

Options:

Discussion 0
Questions 62

Drag and drop the functions from the left onto the correct templates on the right.

Options:

Discussion 0
Questions 63

How many cloud gateway instance(s) can be created per region when provisioning Cloud OnRamp for Multicloud from AWS in a multiregion environment?

Options:

A.  

one

B.  

two

C.  

three

D.  

four

Discussion 0
Questions 64

An administrator wants to create a policy to add a traffic policer called "politer-ccnp" to police data traffic on the WAN Edge. Which configuration accomplishes this task in vSmart?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 65

What are two attributes of vRoute? (Choose two)

Options:

A.  

originator

B.  

service

C.  

encapsulation

D.  

carrier

E.  

domain ID

Discussion 0
Questions 66

When a WAN Edge device joins the SD-WAN overlay, which Cisco SD-WAN components orchestrates the connection between the WAN Edge device and a vSmart controller?

Options:

A.  

vManage

B.  

vBond

C.  

OMP

D.  

APIC-EM

Discussion 0
Questions 67

What is the default value for the Multiplier field of the BFD basic configuration in vManage?

Options:

A.  

3

B.  

4

C.  

5

D.  

6

Discussion 0
Questions 68

In which Cisco SD-WAN deployment scenario does Cisco Umbrella SIG deliver the most value?

Options:

A.  

when a centralized Internet breakout solution is implemented

B.  

when resource-intensive security operations are offloaded from entry-level WAN Edge devices

C.  

when the identity of several WAN Edge devices is verified throughout the networkthroughout the network

Discussion 0
Questions 69

Drag and drop the policies from the left onto the correct policy types on the right.

Options:

Discussion 0
Questions 70

Refer to the exhibit A user has selected the options while configuring a VPN Interface Ethernet feature template What is the required configuration parameter the user must set in this template for this feature to function?

Options:

A.  

The "IP MTU" field must be increased from the default value of 1500 to support the additional overhead.

B.  

The "Shaping Rate (Kbps)" field must be configured with a value

C.  

The "Adaptive QoS" field must be set to "on"

D.  

The "Bandwidth Downstream" field must be configured with a value

Discussion 0
Questions 71

How must the application-aware enterprise firewall policies be applied within the same WAN Edge router?

Options:

A.  

within and between zones

B.  

between two VPN tunnels

C.  

within zone pair

D.  

between two VRFs

Discussion 0
Questions 72

Refer to the exhibit.

Which shaping-rate does the engineer use to shape traffic at 9 Mbps?

Options:

A.  

9

B.  

9000

C.  

90000

D.  

9000000

Discussion 0
Questions 73

An organization requires the use of integrated preventative engines, exploit protection, and the most updated and advanced signature-based antivirus with sandboxing and threat intelligence to stop malicious attachments before they reach users and get executed. Which Cisco SD-WAN solution meets the requirements?

Options:

A.  

Cisco Trust Anchor module

B.  

URL filtering and Umbrella DNS security

C.  

Cisco AMP and Threat Grid

D.  

Snort IPS

Discussion 0
Questions 74

Which OMP route is selected for equal OMP route preference values on WAN Edge routers?

Options:

A.  

route with higher TLOC preference value

B.  

route with origin type of connected

C.  

route with origin type of static

D.  

route with lower TLOC preference value

Discussion 0
Questions 75

Which component is responsible for creating and maintaining the secure DTLS/TLS connection on the vSmart controller?

Options:

A.  

SNMP

B.  

vdaemon

C.  

NETCONF

D.  

OMP

Discussion 0
Questions 76

Which protocol is configured on tunnels by default to detect loss, latency, jitter, and path failures in Cisco SD-WAN?

Options:

A.  

TLS

B.  

BFD

C.  

OMP

D.  

BGP

Discussion 0
Questions 77

Drag and drop the Cisco SD-WAN components from the left onto their functions on the right.

Options:

Discussion 0
Questions 78

What is the ZTP workflow for Cisco IOS XE-based devices?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 79

The branch users of an organization must be prevented from accessing malicious destinations, and the local files on users' systems must be protected from malware. Which two Cisco products must the organization deploy? (Choose two.)

Options:

A.  

Cisco Stealthwatch

B.  

Cisco Umbrella

C.  

Cisco AMP

D.  

Cisco Cloudlock

E.  

Cisco SecureX

Discussion 0
Questions 80

What is the size of SGT data in the metadata header?

Options:

A.  

8 bits

B.  

16 bits

C.  

24 bits

D.  

32 bits

Discussion 0
Questions 81

What is a description of vManage NMS?

Options:

A.  

It is accessible only from VPN 512 (the management VPN).

B.  

A cluster requires device templates to be created on and attached to the same server

C.  

It is a software process on a dedicated WAN Edge router in the network.

D.  

A cluster consists of a minimum of two vManage NMSs

Discussion 0
Questions 82

Configure individual VRFs for each customer according to the topology to achieve these goals :

R1

R2

SW1

SW2

SW3

Options:

Discussion 0
Questions 83

A customer has MPLS and Internet as the TLOC colors An engineer must configure conlroJIers with the Internet and not with MPLS Which configuration achieves this requirement on vManage?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 84

Refer to the exhibit The network team must configure El GRP peering at HQ with devices in the service VPN connected to WAN Edge CSRv. CSRv is currently configured with

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 85

Refer to the exhibit. A network administrator is configuring OSPF advanced configuration parameters from a template using the vManager GUI for a branch WAN Edge router to calculate the cost of summary routes to an ASBR. Which action achieves this configuration?

Options:

A.  

Enable Originate.

B.  

Disable Originate.

C.  

Enable RFC 1583 Compatible.

D.  

Disable RFC 1583 Compatible.

Discussion 0
Questions 86

What are the two components of an application-aware firewall? (Choose two.)

Options:

A.  

zone pair

B.  

sequence

C.  

lists

D.  

default action

E.  

sequence action

F.  

firewall policy

Discussion 0
Questions 87

Which component of the Cisco SD-WAN secure extensible network provides a single pane of glass approach to network monitoring and configuration?

Options:

A.  

APIC-EM

B.  

vSmart

C.  

vManage

D.  

vBond

Discussion 0
Questions 88

Refer to the exhibit. The network administrator has configured a centralized topology policy that results in the displayed routing table at a branch office. Which two configurations are verified by the output? [Choose two.)

Options:

A.  

The routing table is for the transport VPN.

B.  

The default route is learned via OMP.

C.  

This routing table is from a cEdge router.

D.  

The default route is configured locally.

E.  

The configured policy is adding a route tag of 300 to learned routes.

Discussion 0
Questions 89

Refer to the exhibit.

What binding is created using the tloc-extension command?

Options:

A.  

between ge 0/2.101 of port-type service and ge 0/0 of port-type service

B.  

between ge 0/2.101 of port-type transport and ge 0/0 of port-type service

C.  

between ge 0/2.101 of port-type service and ge 0/0 of port-type transport

D.  

between ge 0/2.101 of port-type transport and ge 0/0 of port-type transport

Discussion 0
Questions 90

What is the result during a WAN Edge software upgrade process if the version of the WAN Edge software is higher than the one running on a controller device?

Options:

A.  

The upgrade button is greyed out

B.  

The upgrade proceeds with no warning message.

C.  

The upgrade fails with a warning message

D.  

The upgrade proceeds with a warning message

Discussion 0
Questions 91

An engineer is configuring a list that matches all IP prefixes with lengths from /1 to /16 in a centralized control policy. Which list accomplishes this task?

Options:

A.  

0.0.0.0/1 le 16

B.  

0.0.0.0/0 ge 1

C.  

0.0.0.0/0 le l6

D.  

0.0.0.0/16 ge 1

Discussion 0
Questions 92

An enterprise has several sites with multiple VPNs that are isolated from each other A new requirement came where users in VPN 73 must be able to talk to users in VPN 50 Which configuration meets this requirement?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 93

Refer to the exhibit vManage and vBond have an issue establishing a connection to vSmart Which two actions does the administrator take to fix the issue? (Choose two)

Options:

A.  

Install the certificate received from the certificate server.

B.  

Manually resync vManage and vBond

C.  

Reconfigure the vSmart from CLI with the proper Hostname & System IP

D.  

Delete and re-add vSmart Click Generate and validate CSR

E.  

Request a certificate from the certificate server based on the CSR for the vSmart

Discussion 0
Questions 94

Which type of policy must be applied on a WAN Edge application-aware firewall to control traffic between two or more VPNs?

Options:

A.  

service-insertion policy

B.  

data policy

C.  

firewall policy

D.  

control policy

Discussion 0
Questions 95

Refer to the exhibit.

The control connection is failing. Which action resolves the issue?

Options:

A.  

import vSmart in vManager

B.  

Validate the certificates authenticity on vSmart

C.  

Upload the WAN Edge list on vManage.

D.  

Restore the reachability to the vSmart

Discussion 0
Questions 96

What are the two advantages of configuration groups in a Cisco SD-WAN deployment? (Choose two.)

Options:

A.  

Individual devices are associated with a configuration group and a device template.

B.  

Individual devices are added to multiple groups.

C.  

Individual devices are grouped based on a shared configuration.

D.  

A subset of devices is identified with tags.

E.  

An individual device has multiple tag rules.

Discussion 0
Questions 97

What is a benefit of the application-aware firewall?

Options:

A.  

It blocks traffic by MAC address

B.  

It blocks traffic by MTU of the packet.

C.  

It blocks traffic by application.

D.  

It blocks encrypted traffic

Discussion 0
Questions 98

What is a benefit of the application aware firewall feature in the Cisco SD-WAN solution?

Options:

A.  

application monitoring

B.  

application malware protection

C.  

application visibility

D.  

control policy enforcement

Discussion 0
Questions 99

Which OSPF command makes the WAN Edge router a less preferred exit from a site with a dual WAN Edge design?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 100

Which two features does the application firewall provide? (Choose two.)

Options:

A.  

classification of 1400+ layer 7 applications

B.  

blocks traffic by application or application-family

C.  

numbered sequences of match-action pairs

D.  

classification of 1000+ layer 4 applications

E.  

application match parameters

Discussion 0
Questions 101

Which pathway under Monitor > Network > Select Device is used to verify service insertion configuration?

Options:

A.  

Real Time

B.  

System Status

C.  

ACL Logs

D.  

Events

Discussion 0
Questions 102

Which protocol is used to measure loss latency, Jitter, and liveliness of the tunnel between WAN Edge router peers?

Options:

A.  

OMP

B.  

IP SLA

C.  

NetFlow

D.  

BFD

Discussion 0
Questions 103

Which two REST API functions are performed for Cisco devices in an overlay network? (Choose two)

Options:

A.  

distributing a Snort image among devices

B.  

attaching a device configuration template

C.  

managing connections for smart licensing

D.  

monitoring device certificates

E.  

querying a device and aggregating statistics

Discussion 0
Questions 104

Refer to the exhibit. vManage logs are available for the past few months. A device name change deployed mistakenly at a critical site. How is the device name change tracked by operation and design teams?

A)

B)

C)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 105

Refer to the exhibit.

Which QoS treatment results from this configuration after the access list acl-guest is applied inbound on the vpn1 interface?

Options:

A.  

A UDP packet sourcing from 172.16.20.1 and destined to 172.16.10.1 is accepted

B.  

A TCP packet sourcing from 172.16.10.1 and destined to 172.16.20.1 is dropped

C.  

A UDP packet souring from 172.16.10.1 and destined to 172.16.20.1 is dropped.

D.  

A TCP packet sourcing from 172.16.20.1 and destined to 172.16.10.1 is accepted

Discussion 0
Questions 106

Which feature builds transport redundancy by using the cross link between two redundant WAN Edge routers?

Options:

A.  

OMP

B.  

zero-touch provisioning

C.  

quality of service

D.  

TLOC extension

Discussion 0
Questions 107

Refer to the exhibit.

Customer XYZ cannot provison dual connectivity on both Its routers due to budget constratnts but wants to use tnth RI and R2 interface for users behind them for load toward the hub site Which configurauon achieves this objectives?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 108

Which two image formats are supported for controller codes? (Choose two.)

Options:

A.  

.nxos

B.  

.qcow2

C.  

.ova

D.  

.bin

E.  

Tgz

Discussion 0
Questions 109

In an AWS cloud, which feature provision WAN Edge routers automatically in Cisco SD-WAN?

Options:

A.  

Cloud app

B.  

Cloud OnRamp

C.  

vAnalytics

D.  

Network Designer

Discussion 0
Questions 110

Drag and drop the alarm slates from the left onto the corresponding alarm descriptions on the right.

Options:

Discussion 0
Questions 111

An engineer is configuring a data policy IPv4 prefixes for a site WAN edge device on a site with edge devices. How is this policy added using the policy configuration wizard?

Options:

A.  

In vManage NMS select (he configure ► policies screen, select the centralized policy tab and click add policy

B.  

In vBood orchestrator. select the configure > policies screen select the localized policy tab. and click add policy

C.  

In vManage NMS. select the configure ► policies screen. select the localized policy tab- and click add policy

D.  

In vSmart controller select tie configure ► policies screen, select the localized policy tab, and click add policy

Discussion 0
Questions 112

What is the default value for the number of paths advertised per prefix in the OMP feature template?

Options:

A.  

4

B.  

8

C.  

12

D.  

16

Discussion 0
Questions 113

Which plane builds and maintains the network topology and makes decisions on traffic flows?

Options:

A.  

orchestration

B.  

management

C.  

control

D.  

data

Discussion 0
Questions 114

An engineer must configure VRRP for redundancy on WAN Edge router1 running an earlier version than 20.6, considering WAN Edge router2 is configured correctly. Which configuration meets the requirement?

Options:

A.  

B.  

C.  

D.  

Discussion 0
Questions 115

Drag and drop the attributes from the left that make each transport location unique onto the right. Not all options are used.

Options:

Discussion 0
Questions 116

Drag and drop the components from the left onto the corresponding Cisco NFV infrastructure Building Blocks on the right. Not all options are used.

Options:

Discussion 0
Questions 117

REST applications communicate over HTTP or HTTPS to make calls between network devices. Which two HTTPS standard methods are included? (Choose two.)

Options:

A.  

Array

B.  

DELETE

C.  

POST

D.  

Scalar

E.  

Object

Discussion 0
Questions 118

What do receivers request to join multicast streams in a Cisco SO-WAN network?

Options:

A.  

IGMP membership reports directly with a multicast router.

B.  

Multicast service routes with the vSmart controller

C.  

IGMP membership reports directly with the vBond orchestrator.

D.  

PIM messages with the nearest neighboring multicast router.

Discussion 0
Questions 119

A bank is looking for improved customer experience for applications and reduce overhead related to compliance and security. Which key feature or features of the Cisco SD-WAN solution will help the bank to achieve their goals?

Options:

A.  

Integration with PaaS providers to offer the best possible application experience

B.  

QoS including application prioritization and meeting critical applications SLA for selecting optimal path.

C.  

implementation of a modem age core banking system

D.  

implementation of BGP across the enterprise routing for selecting optimal path

Discussion 0
Questions 120

Refer to the exhibit.

An engineer configured OMP with an overlay-as of 10666. What is the AS-PATH for prefix 104.104.104.104/32 on R100?

Options:

A.  

100 10666

B.  

100 20 104

C.  

100 10666 20 104

D.  

100 10666 104

Discussion 0
Questions 121

Which issue triggers the Cisco Umbrella resolver to toward DNS requests to the intelligent proxy?

Which issue triggers the Cisco Umbrella resolver to toward DNS requests to the intelligent proxy?

Options:

A.  

A domain is nonexistent.

B.  

A domain is block-listed.

C.  

A domain is locally reachable.

D.  

A domain is grey-listed.

Discussion 0
Questions 122

Refer to the exhibit. An engineer is enabling command line access via MPLS for in-band management. Which command completes the partial SD-WAN interface configuration with the highest degree of security?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 123

Which configuration change allows direct internet access at the branch site for YouTube traffic?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 124

Which policy tracks path characteristics such as loss, latency, and jitter in vManage?

Options:

A.  

VPN

B.  

control

C.  

app-route

D.  

data

Discussion 0
Questions 125

An engineer is configuring the branch office with a 172.16.0.0/16 subnet to use DIA for Internet traffic. All other traffic must flow to the central site or branches using the MPLS circuit Which configuration meets the requirement?

A)

B)

C)

D)

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 126

When VPNs are grouped to create destination zone in Zone-Based Firewall, how many zones can a single VPN be part of?

Options:

A.  

two

B.  

four

C.  

one

D.  

three

Discussion 0
Questions 127

Refer to the exhibit. An engineer configures a hub-and-spoke SD-WAN topology with the requirement that traffic from router A branch to router B branch is guaranteed to flow through the network hub, router C. Which configuration meets the requirement for router A?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 128

How many concurrent sessions does a vManage REST API have before it invalidates the least recently used session if the maximum concurrent session number is reached?

Options:

A.  

150

B.  

200

C.  

250

D.  

300

Discussion 0
Questions 129

Which device in the SD- WAN solution receives and categorizes event reports, and generates alarms?

Options:

A.  

WAN Edge routers

B.  

vSmart controllers

C.  

vManage NMS

D.  

vBond controllers

Discussion 0
Questions 130

What is a restriction when configuring a tunnel interface?

Options:

A.  

Up to six tunnel interfaces are configurable on a vSmart.

B.  

it is manually assigned when using vWanage feature template.

C.  

It must be configured for the interface under aft VPNs

D.  

Up to six tunnel interfaces are configurable on a WAN Edge

Discussion 0
Questions 131

A network administrator is tasked to make sure that an OMP peer session is closed after missing three consecutive keepalive messages in 3 minutes. Additionally, route updates must be sent every minute. If a WAN Edge router becomes unavailable, the peer must use last known information to forward packets for 12 hours. Which set of configuration commands accomplishes this task?

Options:

A.  

Option A

B.  

Option B

C.  

Option C

D.  

Option D

Discussion 0
Questions 132

Which command displays BFD session summary information per TLOC on vEdge routers?

Options:

A.  

show bfd history

B.  

show bfd summary

C.  

show bfd sessions

D.  

show bfd tloc-summary-list

Discussion 0