Weekend Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Cisco 300-415 Dumps

Page: 1 / 44
Total 441 questions

Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Questions and Answers

Question 1

An engineer modifies a data policy for DIA in VPN 200 to meet the requirements for traffic destined to these locations:

* external networks; must be translated

* external networks; must use a public TLOC color

* syslog servers, must use a private TLOC color

Here is the existing data policy configuration:

as

Which policy configuration sequence set meets the requirements?

Options:

A.

B.

C.

Question 3

Which two services are critical for zero touch provisioning on-boarding? (Choose two)

Options:

A.

SNMP

B.

DNS

C.

DHCP

D.

AAA

E.

EMAIL

Question 4

Which protocol advertises WAN edge routes on the service side?

Options:

A.

EIGRP

B.

OSPF

C.

BGP

D.

ISIS

Question 5

as

Refer to the exhibit. Which configuration extends the INET interface on R1 to be used by R2 for control and data connections?

A)

as

B)

as

C)

as

Options:

A.

Option A

B.

Option B

C.

Option C

Question 6

as

Refer to the exhibit. A network administrator is configuring OSPF advanced configuration parameters from a template using the vManager GUI for a branch WAN Edge router to calculate the cost of summary routes to an ASBR. Which action achieves this configuration?

Options:

A.

Enable Originate.

B.

Disable Originate.

C.

Enable RFC 1583 Compatible.

D.

Disable RFC 1583 Compatible.

Question 7

Which Cloud OnRamp solution is used by partners and vendors without Cisco SD-WAN but still needs connectivity to their customers without installing SD-WAN routing appliances on their sites?

Options:

A.

Cloud OnRamp for IaaS

B.

Cloud OnRamp for SaaS

C.

Cloud OnRamp for Multicloud

D.

Cloud OnRamp for Colocation

Question 8

Which Cisco SD-WAN configuration provides the advantages of day-zero deployment and reusable configuration components?

Options:

A.

CLI-based templates

B.

configuration groups

C.

configuration via the vBond controller

D.

configuration through a Cisco Prime server

Question 9

An engineer must improve video quality by limiting HTTP traffic to the Internet without any failover. Which configuration in vManage achieves this goal?

as

as

as

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 10

Which application list is preconfigured?

Options:

A.

Google_Apps

B.

Cisco Apps

C.

Microsoft_Office365

D.

P2P_Apps

Question 11

Which VManage dashboard is used to monitor the next-hop reachability between two devices traversing through OMP for a service VPN’

Options:

A.

Troubleshooting > App Route Visualization

B.

Troubleshooting > Tunnel Health

C.

Troubleshooting > Simulate Flows

D.

Troubleshooting > Packet Capture

Question 12

Refer to the exhibit.

as

An engineer configured OMP with an overlay-as of 10666. What is the AS-PATH for prefix 104.104.104.104/32 on R100?

Options:

A.

100 10666

B.

100 20 104

C.

100 10666 20 104

D.

100 10666 104

Question 13

Which two REST API functions are performed for Cisco devices in an overlay network? (Choose two)

Options:

A.

distributing a Snort image among devices

B.

attaching a device configuration template

C.

managing connections for smart licensing

D.

monitoring device certificates

E.

querying a device and aggregating statistics

Question 14

How is TLOC defined?

Options:

A.

It is represented by a unique identifier to specify a site in as SD-WAN architecture.

B.

It specifies a Cisco SD-WAN overlay in a multitenant vSMART deployment.

C.

It is a unique collection of GRE or iPsec encapsulation, link color, and system IP address.

D.

It is represented by group of QoS policies applied to a WAN Edge router.

Question 15

What does forward error correction addresses in Cisco SO-WAN?

Options:

A.

inefficient traffic forwarding caused oy inbound shapers

B.

reduced application performance degradation rotated to service degradation

C.

applications with occasional invalid data input and poor performance

D.

traffic flows with increased delay over a particular transport

Question 16

A network administrator is tasked to make sure that an OMP peer session is closed after missing three consecutive keepalive messages in 3 minutes. Additionally, route updates must be sent every minute. If a WAN Edge router becomes unavailable, the peer must use last known information to forward packets for 12 hours. Which set of configuration commands accomplishes this task?

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 17

Refer to the exhibit.

as

Customer XYZ cannot provision dual connectivity on both of its routers due to budget constraints but wants to use both R1 and R2 interlaces for users behind them for load balancing toward the hub site. Which configuration achieves this objective?

as

as

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 18

What is the purpose of ‘’vpn 0’’ in the configuration template when onboarding a WAN edge node?

Options:

A.

It carries control traffic over secure DTLS or TLS connections between vSmart controllers and vEdge routers, and between vSmart and vBond

B.

It carries control out-of-band network management traffic among the Viptela devices in the overlay network.

C.

It carries control traffic over secure IPsec connections between vSmart controllers and vEdge routers, and between vSmart and vManager

D.

It carries control traffic over secure IPsec connections between vSmart controllers and vEdge routers, and between vSmart and vBond

Question 19

Which VPN must be present on at least one interface to install Cisco vManage and integrate it with WAN Edge devices in an overlay network site ID:S4307T7E78F29?

Options:

A.

VPN 512

B.

any VPN number selected

C.

services VPN range 0-511

D.

VPNO

Question 20

An engineer must create a QoS policy by creating a class map and assigning it to the LLQ queue on a WAN Edge router Which configuration accomplishes the task?

A)

asB)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 21

What is the role of the Session Traversal Utilities for NAT server provided by the vBond orchestrator?

Options:

A.

It facilitates SD-WAN toners and controllers to discover their own mapped or translated IP addresses and port numbers

B.

It prevents SD-WAN Edge routers from forming sessions with public transports among different service providers

C.

It facilitates SD-WAN Edge routers to stay behind a NAT-enabled firewall while the transport addresses of the SD-WAN controller are unNAT-ed

D.

It allows WAN Edge routers to form sessions among MPLS TLOCs using only public IP addresses

Question 22

Refer to the exhibit.

as

Which command-line configuration on a WAN Edge device achieves these results?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 23

How is the software managed in Cisco SD-WAN?

Options:

A.

Software images must be uploaded to vManage through HTTP or FTP

B.

Software downgrades are unsupported for vManage

C.

Software images must be transferred through VPN 512 or VPN 0 of vManage

D.

Software upgrade operation in the group must include vManage. vBond, and vSmart.

Question 24

Refer to the exhibit.

as

Which configuration change is needed to configure the tloc-extention on Branch1-Edge1?

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 25

In which device state does the WAN edge router create control connections, but data tunnels are not created?

Options:

A.

valid

B.

backup

C.

active

D.

staging

Question 26

Refer to the exhibit.

as

A customer wants to implement primary and secondary Cisco SD-WAN overlay routing for prefixes that are advertised for both data centers. The east data center (TLOC 101.101.101.101) is primary for east sites, and the west data center (TLOC 100.100.100.100) is primary for west sites. Which configuration change achieves this objective?

as

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 27

Which multicast component is irrelevant when defining a multicast replicator outside the local network without any multicast sources or receivers?

Options:

A.

PIM interfaces

B.

TLOC

C.

overlay BFD

D.

OMP

Question 28

Which VPN connects the transport-side WAN Edge interface to the underlay/WAN network?

Options:

A.

VPN 1

B.

VPN 511

C.

VPN 0

D.

VPN 512

Question 29

Drag and drop the vManage policy configuration procedures from the left onto the correct definitions on the right.

as

Options:

Question 30

What is the order of operations for software upgrades of Cisco SD-WAN nodes'?

Options:

A.

vBond vManage vSmart WAN Edge

B.

vManage vBond WAN Edge. vSmart

C.

vManage vSmart, vBond, WAN Edge

D.

vManage vBond vSraart WAN Edge

Question 31

Which protocol runs between the vSmart controllers and WAN Edge routers when the vSmart controller acts like a route reflector?

Options:

A.

OMP outside the DTLS/TLS control connection

B.

BGP inside the DTLS/TLS

C.

IPsec inside the DTLS/TLS control connection

D.

OMP inside the DTLS/TLS control connection

Question 32

An engineer is troubleshooting a vEdge router and identifies a “DCONFAIL – DTLS connection failure” message. What is the problem?

Options:

A.

certificate mismatch

B.

organization mismatch

C.

memory issue

D.

connectivity issue

Question 33

In a Cisco SD-WAN network, which component is responsible for distributing route and policy information via the OMP?

Options:

A.

vManage

B.

vSmart Controler

C.

vBond Orchestrator

D.

WAN Edge Router

Question 34

A network administrator is configuring VRRP to avoid a traffic black hole when the transport side of the network is down on the primary device. What must be configured to get the fastest failover to standby?

Options:

A.

prefix-list tracking

B.

lower timer interval

C.

higher group ID number

D.

OMP tracking

Question 35

Which configuration component is used in a firewall security policy?

Options:

A.

numbered sequences of match-action pairs

B.

application match parameters

C.

URL filtering policy

D.

intrusion prevention policy

Question 36

An engineer is configuring a data policy for packets that must be captured through the policy. Which command accomplishes this task?

Options:

A.

policy > data-policy > vpn-list > sequence > default-action > drop

B.

policy > data-policy > vpn-list > sequence > action

C.

policy > data-policy > vpn-list > sequence > default-action > accept

D.

policy > data-policy > vpn-list > sequence > match

Question 37

Which controller is used for provisioning and configuration in a Cisco SD-WAN solution?

Options:

A.

vBond

B.

Manage

C.

WAN Edge router

D.

vSmart

Question 38

What is a benefit of using REST APIs?

Options:

A.

predefined automation and orchestration platform for event management and logging

B.

user-defined automation and integration into other orchestration systems or tools

C.

vAnalytics to simplify operational services integration and real-time event monitoring

D.

predefined SD-WAN controller with other platform integration for event management and logging

Question 39

How should the IP addresses be assigned for all members of a Cisco vManage cluster located in the same data center?

Options:

A.

in the same subnet

B.

in overlapping IPs

C.

in each controller with a /32 subnet

D.

in different subnets

Question 40

Which two advanced security features are available on the Cisco SD-WAN WAN Edge (vEdge) device? (Choose two.)

Options:

A.

URL filtering

B.

snort intrusion prevention system

C.

Cisco Umbrella DNS Security

D.

Cisco AMP and AMP Threat Grid

E.

Enterprise Firewall

Question 41

Which TCP Optimization feature is used by WAN Edge to prevent unnecessary retransmissions and large initial TCP window sizes to maximize throughput and achieve a better quality?

Options:

A.

SEQ

B.

SYN

C.

RTT

D.

SACK

Question 42

Which pathway under Monitor > Network > Select Device is used to verify service insertion configuration?

Options:

A.

Real Time

B.

System Status

C.

ACL Logs

D.

Events

Question 43

as

Refer to the exhibit. A user in the branch is connecting to Office 365 for the first time. Over which path does the branch WAN Edge router traffic follow?

Options:

A.

routing table of the branch WAN Edge router

B.

DIA exit of the branch WAN Edge router

C.

forwarded to the gateway site

D.

dropped because the minimum vQoE score has not been met

Question 44

Which secure connection should be used to access the REST APIs through the Cisco vManage web server?

Options:

A.

HTTP inspector interface

B.

authenticated HTTPS

C.

authenticated DTLS

D.

JSON Inspector interface

Question 45

What are two benefits of installing Cisco SD-WAN controllers on cloud-hosted services? (Choose two.)

Options:

A.

utilizes well-known cloud services such as Azure. AWS. and GCP

B.

accelerates Cisco SD-WAN deployment

C.

allows integration of the WAN Edge devices In the cloud

D.

installs the controllers in two cloud regions in a primary and backup setup

E.

automatically Implements zone-based firewalling on the controllers

Question 46

What do receivers request to join multicast streams in a Cisco SO-WAN network?

Options:

A.

IGMP membership reports directly with a multicast router.

B.

Multicast service routes with the vSmart controller

C.

IGMP membership reports directly with the vBond orchestrator.

D.

PIM messages with the nearest neighboring multicast router.

Question 47

Which component of the Cisco SD-WAN secure extensible network provides a single pane of glass approach to network monitoring and configuration?

Options:

A.

APIC-EM

B.

vSmart

C.

vManage

D.

vBond

Question 48

Which set of platforms must he in separate VMS as of release 16.1?

Options:

A.

vSmart and WAN Edge

B.

WAN Edge and vBond

C.

vManagc and vSmart

D.

vBond and vSmart

Question 49

Which component of the Cisco SD-WAN control plane architecture facilitates the storage of certificates and configurations for network components?

Options:

A.

vSmart

B.

vBond

C.

WAN Edge

D.

vManage

Question 50

Refer to the exhibit.

as

The Cisco SD-WAN network is configured with a default full-mesh topology. An engineer wants Paris WAN Edge to use the Internet HOC as the preferred TLOC for MSN Messenger and AOL Messenger traffic. Which policy achieves this goal?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 51

as

Refer to the exhibit The network team must configure application-aware routing for the Service VPN 50.0.0.0/16 The SLA must prefer MPLS for video traffic but the remaining traffic must use a public network What must be defined other than applications before the application-aware policy is create?

Options:

A.

SLA Class, Site VPN. Prefix

B.

Data Prefix, Site VPN TLOC

C.

Application, SLA VPN. Prefix

D.

Color, SLA Class, Sue, VPN

Question 52

Which policy configures an application-aware routing policy under Configuration > Policies?

Options:

A.

Localized policy

B.

Centralized policy

C.

Data policy

D.

Control policy

Question 53

An administrator wants to create a policy to add a traffic policer called "politer-ccnp" to police data traffic on the WAN Edge. Which configuration accomplishes this task in vSmart?

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 54

A voice packet requires a latency of 50 msec. Which policy is configured to ensure that a voice packet is always sent on the link with less than a 50 msec delay?

Options:

A.

centralized control

B.

localized data

C.

localized control

D.

centralized data

Question 55

Which cloud based component in cisco SD-WAN is responsible for establishing a secure connection to each WAN edge router and distributes routers and policy information via omp?

Options:

A.

vBond

B.

vManage

C.

vSmart

D.

WAN Edge

Question 56

as

An engineer is creating a policy for VPN1 users. Their scavenger traffic at site 101 must pass through a firewall. Which two match conditions must be selected to enable this policy? (Choose two.)

Options:

A.

destination port

B.

source data prefix

C.

packet length

D.

protocol

E.

application/application family list

Question 57

An engineer must deploy a QoS policy with these requirements:

• policy name: App-police

• police rate: 1000000

• burst: 1000000

• exceed: drop

Which configuration meets the requirements?

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 58

What are the default username and password for vSmart Controller when it is installed on a VMware ESXi hypervisor'?

Options:

A.

username Cisco password admin

B.

username admin password Cisco

C.

username Cisco password Cisco

D.

username admin password admin

Question 59

How many network interface cards are needed to add in virtual machine settings when installing vSmart controller on VMware vSphere ESXi Hypervisor software?

Options:

A.

1

B.

2

C.

3

D.

4

Question 60

as

Refer to the exhibit An engineer is getting a CTORGNMMIS error on a controller connection Which action resolves this issue?

Options:

A.

Configure a valid serial number on the WAN Edge

B.

Configure a valid organization name

C.

Configure a valid certificate on vSMART

D.

Configure a valid product ID

Question 61

Which port is used for vBond under controller certificates if no alternate port is configured?

Options:

A.

12345

B.

12347

C.

12346

D.

12344

Question 62

An engineer must configure egress QoS for voice traffic. Which queue must the engineer configure on the WAN Edge router to accomplish the task?

Options:

A.

queue 0

B.

queue 1

C.

queue 3

D.

queue 7

Question 63

Drag and drop the attributes from the left that make each transport location unique onto the right. Not all options are used.

as

Options:

Question 64

Which value of the IPsec rekey timer must be set by the engineer for an OMP graceful restart value set for 24 hours?

Options:

A.

6 hours

B.

12 hours

C.

36 hours

D.

48 hours

Question 65

An engineer modifies a data policy for DIA in VPN 67. The location has two Internet-bound circuits. Only the web browsing traffic must be admitted for DIA. without further discrimination about which transport to use.

Here is the existing data policy configuration:

as

Which policy configuration sequence meets the requirements?

as

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 66

WAN Edge routers are configured manually to use UDP port offset to use nondefault offset values when IPsec tunnels are created. What is the offse range?

Options:

A.

1-19

B.

0-18

C.

0-19

D.

1-18

Question 67

An engineer is configuring a centralized policy to influence network route advertisement. Which controller delivers this policy to the fabric?

Options:

A.

vSmart

B.

vManage

C.

WAN Edge

D.

vBond

Question 68

An organization wants to discover monitor and track the applications running on the WAN Edge device on the LAN Which configuration achieves this goal?

as

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 69

Which action is performed during the onboarding process when a WAN Edge router is connected to ZTP server ztp.viptela com?

Options:

A.

The router is connected to WAN Edge Cloud Center

B.

The router is synced with vSmart Controller via an IPsec tunnel

C.

The router receives its vBond Orchestrator information

D.

The router is connected 10 vSmart Controller via a DTLSTLS tunnel

Question 70

Which policy allows communication between TLOCs of data centers and spokes and blocks communication between spokes?

Options:

A.

centralized data policy

B.

centralized control policy

C.

localized control policy

D.

localized data policy

Question 71

as

Refer to the exhibit Which NAT types must the engineer configure for the vEdge router to bring up the data plane tunnels?

Options:

A.

Enable Full Cone NAT on the vEdge interface

B.

Use public color on the TLOC

C.

Use private color on the TLOC

D.

Enable Symmetric MAT on the vEdge interface

Question 72

An enterprise is continuously adding new sites to its Cisco SD-WAN network. It must configure any cached routes flushed when OMP peers have lost adjacency Which configuration allows the cached OMP routes to be flushed after every 24 hours from its routing table?

as

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 73

An administrator is configuring the severity level on the vManage NMS for events that indicate that an action must be taken immediately. Which severity level must be configured?

Options:

A.

warning

B.

error

C.

critical

D.

alert

Question 74

Which command on a WAN Edge device displays the information about the colors present in the fabric that are learned from vSmart via OMP?

Options:

A.

show omp tlocs

B.

show omp sessions

C.

show omp peers

D.

show omp route

Question 75

In a customer retail network with multiple data centers, what does the network administrator use to create a regional hub topology?

Options:

A.

control policy on vManage

B.

control policy on vSmart

C.

data policy on vSmart

D.

app route policy on vSmart

Question 76

Which command disables the logging of syslog messages to the local disk?

Options:

A.

no system logging disk enable

B.

no system logging disk local

C.

system logging disk disable

D.

system logging server remote

Question 77

Which two criteria ate supported to filter traffic on a Cisco Umbrella Cloud-delivered firewall? (Choose two )

Options:

A.

tunnels

B.

site ID

C.

URL

D.

geolocation

E.

protocol

Question 78

An enterprise has these three WAN connections:

public Internet

business internet

MPLS

An engineer must configure two available links to route traffic via both links. Which configuration achieves this objective?

as

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Question 79

What is the main purpose of using TLOC extensions in WAN Edge router configuration?

Options:

A.

creates hardware-level transport redundancy at the local site

B.

creates an IPsec tunnel from WAN Edge to vBond Orchestrator

C.

transports control traffic to a redundant vSmart Controller

D.

transports control traffic w remote-site WAN Edge routers

Question 80

as

Refer to the exhibit. A customer wants to deploy service insertion at site1. Which traffic from VPN 10 must route to this site through a firewall. A policy must be in place to route VPN 10 traffic from all sites toward this firewall. Which configuration must be on the vSmart controller to meet this requirement?

Options:

A.

B.

C.

D.

Question 81

as

Refer to the exhibit. An engineer is troubleshooting a control connection issue on a WAN Edge device that shows socket errors. The packet capture shows some ICMP packets dropped between the two devices. Which action resolves the issue?

Options:

A.

Recover the vManage controller that is down m a high availability cluster

B.

Change the system IP or restart the VWN Edge 4 the system IP is changed

C.

Remove IP duplication in the network and configure a unique IP address

D.

Recover vBond or wart for the controller to reload which could be caused by a reset

Question 82

Which attributes are configured to uniquely Identify and represent a TLOC route?

Options:

A.

system IP address, link color, and encapsulation

B.

firewall, IPS, and application optimization

C.

site ID, tag, and VPN

D.

origin, originator, and preference

Question 83

as

as

as

Refer to the exhibit A small company was acquired by a large organization As a result, the new organization decided to update information on their Enterprise RootCA and generated a new certificate using openssl Which configuration updates the new certificate and issues an alert in vManage Monitor | Events Dashboard?

as

as

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 84

Which protocol detects path status (up/down), measures loss/latency/jitter, and measures the quality of the IPsec tunnel MTU?

Options:

A.

OMP

B.

IP-SLA

C.

BFD

D.

DTLS

Question 85

The network administrator is configuring a QoS scheduling policy on traffic received from transport side tunnels on WAN Edge 5000 routers at location 406141498 Which command must be configured on these devices?

Options:

A.

cloud-qos

B.

service qos

C.

cloud-mis qos

D.

mis qos

Question 86

as

Refer to the exhibit. An ongineer configured OMP with an ovorlay-as of 10666. What is tho AS-PATH for prefix 104.104.104.104/32 on R1007?

Options:

A.

100 10666 104

B.

100 10666

C.

100 10666 20 104

D.

100 20 104

Question 87

Which storage format Is used when vManage Is deployed as a virtual machine on a KVM hypervisor?

Options:

A.

.iso

B.

.qcow2

C.

.ova

D.

.tgz

Question 88

A large retail organization decided to move some of the branch applications to the AWS cloud. How does the network architect extend the in-house Cisco SD-WAN branch to cloud network into AWS?

Options:

A.

Create virtual WAN Edge devices Cloud through the AWS online software store

B.

Create virtual instances of vSmart Cloud through the AWS online software store

C.

Create GRE tunnels to AWS from each branch over the Internet

D.

Install the AWS Cloud Router in the main data center and provide the connectivity from each branch

Question 89

What is the behaviour of vBond orchestrator?

Options:

A.

It maintains vSmart and WAN Edge routers secure connectivity state

B.

it builds permanent connections with vSmart controllers

C.

it updates vSmart of WAN Edge routers behind NAT devices using OMP.

D.

It builds permanent connections with WAN Edge routers

Question 90

Which feature template configures OMP?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 91

An engineer must configure VRRP for redundancy on WAN Edge router1 running an earlier version than 20.6, considering WAN Edge router2 is configured correctly. Which configuration meets the requirement?

Options:

A.

B.

C.

D.

Question 92

What is a benefit of the application-aware firewall?

Options:

A.

It blocks traffic by MAC address

B.

It blocks traffic by MTU of the packet.

C.

It blocks traffic by application.

D.

It blocks encrypted traffic

Question 93

An organization wants to use the cisco SD-WAN regionalized service-chaining feature to optimize cost and user experience with application in the network, which allows branch routers to analyze and steer traffic toward the required network function. Which feature meets this requirement?

Options:

A.

Cloud Services Platform

B.

VNF Service Chaning

C.

Cloud onRamp for Colocation

D.

Cloud onRamp for laaS

Question 94

Which two actions are necessary to set the Controller Certificate Authorization mode to indicate a root certificate? (Choose two)

Options:

A.

Select the Controller Certificate Authorization mode that is recommended by Cisco

B.

Change the organization name of the Cisco SO-WAN fabric.

C.

Upload an SSL certificate to vManape,

D.

Select a private certificate signing authority instead of a public certificate signing authority

E.

Select a validity period from the drop-down menu

Question 95

When redistribution is configured between OMP and BGP at two Data Center sites that have Direct Connection interlink, which step avoids learning the same routes on WAN Edge routers of the DCs from LAN?

Options:

A.

Define different VRFs on both DCs

B.

Set same overlay AS on both DC WAN Edge routers

C.

Set down-bit on Edge routers on DC1

D.

Set OMP admin distance lower than BGP admin distance

Question 96

What is the default value for the Multiplier field of the BFD basic configuration in vManage?

Options:

A.

3

B.

4

C.

5

D.

6

Question 97

Which OSPF command makes the WAN Edge router a less preferred exit from a site with a dual WAN Edge design?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 98

A network administrator is configuring Qos on a vEdge 5000 router and needs to enable it on the transport side interface. Which policy setting must be selected to accomplish this goal?

Options:

A.

Cloud QoS Service side

B.

Cloud QoS

C.

NetFlow

D.

Application

Question 99

An engineer must advertise OSPF-learned routes and modify the update interval for route filtering by TLOC color to 300 on an SD-WAN device. Which configuration accomplishes this

task?

as

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 100

as

Refer to the exhibit. Which configuration ensures that OSPP routes learned from Site2 are reachable at Stein and vice-versa?

Options:

A.

B.

C.

Question 101

Which two mechanisms are used by vManage to ensure that the certificate serial number of the WAN Edge router that is needed to authenticate is listed in the WAN Edge Authorized Señal Number Hst’ (Choose two)

Options:

A.

Synchronize to the PnP

B.

Manually upload it to vManage

C.

The devices register to vManage directly as the devices come online

D.

The vManage is shipped with the list

E.

Synchronize to the Smart Account

Question 102

An engineer must create a QoS policy by creating a class map and assigning it to the LLQ queue on a WAN Edge router Which configuration accomplishes the task?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 103

Which destination UDP port is used by WAN Edge router to make a DTLS connection with vBond Orchestrator?

Options:

A.

12343

B.

12345

C.

12346

D.

12347

Question 104

Refer to the exhibit.

as

as

vManage and vBond have an issue establishing a connection to each other. Which configuration resolves the issue?

Options:

A.

Configure the timezone on vBond to Europe/London.

B.

Configure the encapsulation ipsec command under the tunnel interface on vManage.

C.

Configure a default route on vBond pointing to 172.16.2.254.

D.

Remove the encapsulation ipsec command under the tunnel interface of vBond.

Question 105

How is multicast routing enabled on devices in the Cisco SD-WAN overlay network?

Options:

A.

The WAN Edge routers originate multicast service routes to the vSmart controller via OMP, which then forwards joins for requested multicast groups based on IGMP v1 or v2 toward the source or PIM-RP as specified m the original PIM join message.

B.

The vSmart controller originates multicast service routes to the WAN Edge routers via OMP, which then forwards joins for requested multicast groups cased on IGMP v1 or v2 toward the source or PlM-RP as specified m the original PIM join message

C.

The vSmart controller originates multicast service routes to the WAN Edge routers via OMP, which then forwards joins (or requested multicast groups based on IGMP v2 or v3 toward the source or PIM-RP as specified in the original PIM join message

D.

The WAN Edge routers originate multicast service routes to the vSmart controller via OMP. which then forwards joins for requested multicast groups based on iGMP v2 or v3 toward the source or PIM-RP as specified in the original PIM join message

Question 106

Which type of lists are used to group related items via an application-aware routing policy under the policy lists command hierarchy on vSmart controllers?

Options:

A.

data prefix, she. and VPN

B.

OSCP value, application, and VPN

C.

data prefix, application, and SLA class

D.

DSCP value, site, and VPN

Question 107

Which protocol Is used by the REST API to communicate with network services in the Cisco SO-WAN network?

Options:

A.

SSL

B.

HTTP

C.

iPsec

D.

SSM

Question 108

Refer to the exhibit.

as

The engineer must assign community tags to 3 of its 74 critical server networks as soon as that are advertised to BGP peers. These server networks must not be advertised outside AS. Which configuration fulfill this requirement?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 109

Which SD-WAN component is configured to enforce a policy to redirect branch-to-branch traffic toward a network service such as a firewall or IPS?

Options:

A.

vBond

B.

WAN Edge

C.

vSmart

D.

Firewall

Question 110

Exhibit.

as

The SD-WAN network Is configured with a default full-mesh topology. The network engineer wants the Rome WAN Edge to use the MPLS TLOC as the preferred TLOC when ….. Telnet traffic as long as me MPLS Ink has these, characteristics:

Loss: 5%

Latency: 100ms

Jitter: 100 ms

Which configuration must the network engineer use to create a list that that classifies the MPLS link characteristics?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Question 111

An engineer must use data prefixes to configure centralized data policies using the vManage policy configuration wizard. What is the first step to accomplish this task?

Options:

A.

Create groups of interest

B.

Configure network topology.

C.

Configure traffic rules.

D.

Apply policies to sites and VPNs.

Question 112

In which VPN is the NAT operation on an outgoing interface configured for direct Interne! access?

Options:

A.

1

B.

10

C.

512

D.

0

Question 113

A WAN Edge device has several service VPNs with no routing protocol configured in the service VPNs The device must be configured so that all connected routes are visible in OMP for VPN 10 Which configuration meets the requirement?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 114

as

Refer to the exhibit. An engineer configures a hub-and-spoke SD-WAN topology with the requirement that traffic from router A branch to router B branch is guaranteed to flow through the network hub, router C. Which configuration meets the requirement for router A?

as

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 115

Which policy blocks TLOCs from remotes and allows TLOCs from the data center to form hub-and-spoke peering?

Options:

A.

localized control policy

B.

localized data policy

C.

centralized data policy

D.

centralized control policy

Question 116

Which two different states of a WAN Edge certificate are shown on vManage? (Choose two.)

Options:

A.

inactive

B.

active

C.

staging

D.

invalid

E.

provisioned

Question 117

Which encryption algorithm is used for encrypting SD-WAN data plane traffic?

Options:

A.

Triple DES

B.

IPsec

C.

AES-128

D.

AES-256 GCM

Question 118

How many concurrent sessions does a vManage REST API have before it invalidates the least recently used session if the maximum concurrent session number is reached?

Options:

A.

150

B.

200

C.

250

D.

300

Question 119

Which set of elements are verified by the controller to confirm the identity of edge devices?

Options:

A.

certificates, organization name and serial number of the device

B.

organization name serial number and system IP of the device

C.

certificates, organization name, and vBond domain

D.

certificates, system IP, and vBond domain

Question 120

How many subnets are necessary in Azure VNet for a WAN Edge device to function in the cloud deployment?

Options:

A.

CSR is the WAN Edge device that is supported in the Microsoft cloud. The Microsoft underlay cloud fabric performs the management function.

B.

There must be three subnets in VNet: management, public, and services.

C.

One public subnet is required in VNet. The Microsoft underlay cloud fabric performs all of the routing functions for WAN Edge.

D.

Public and services subnets are required in VNet. The Microsoft underlay cloud fabric performs the management function.

Question 121

Drag and drop the functions from the left onto the correct templates on the right.

as

Options:

Question 122

Which protocol is used to propagate multicast join requests over the Cisco SD-WAN fabric?

Options:

A.

ARP

B.

Auto-RP

C.

OMP

D.

IGMP

Question 123

What two functions describe the TCP optimization tool used in the Cisco SD-WAN? (Choose two.)

Options:

A.

It uses TCP acknowledgment (ACK).

B.

It is used to take care of high packet loss for control traffic.

C.

It terminates TCP connections locally at the WAN edge.

D.

It uses TCP selective acknowledgment (SACK).

E.

It terminates TCP connections at the remote WAN edge.

Question 124

as

Refer to the exhibit A vBond controller was added to the controller list with the same Enterprise Root CA certificate as vManage. The two controllers can reach each other via VPNO and share the same organization name, but the control connection is not initiated- Which action resolves the issue?

Options:

A.

Synchronize the WAN Edge list on vManage with controllers.

B.

Configure NTP on both controllers to establish a connection.

C.

Configure a valid systom IP on the vBond controller.

D.

Configure a valid vBond IP on vManage.

Question 125

Which configuration changes the packet loss priority from low to highly?

A)

as

B)

as

C)

as

D)

as

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 126

Which service VPN must be reachable from all WAN Edge devices and the controllers?

Options:

A.

VPN0

B.

VPN10

C.

VPN215

D.

VPN512

Question 127

On which device is a service FW address configured to Insert firewall service at the hub?

Options:

A.

vEdge at the branch

B.

vSmart at the hub

C.

vEdge at the hub

D.

vSmart at the branch

Question 128

Which feature allows reachability to an organization’s internally hosted application for an active DNS security policy on a device?

Options:

A.

local domain bypass

B.

DHCP option 6

C.

DNSCrypt configurator

D.

data pokey with redirect

Question 129

How is the scalability of the vManage increased in Cisco SD-WAN Fabric?

Options:

A.

Increase licensing on the vManage

B.

Deploy multiple vManage controllers in a cluster

C.

Deploy more than one vManage controllers on different physical server.

D.

Increase the bandwidth of the WAN link connected to the vManage

Question 130

Which attribute identifies the type of a vRoute?

Options:

A.

tag

B.

encapsulation

C.

originator

D.

origin

Question 131

Refer to the exhibit.

as

as

An engineer is troubleshooting an issue where vManage and vSmart have a problem establishing a connection to vBond. Which action fixes the issue?

Options:

A.

Reconfigure the vBond command on the vBond as vBond 150.5.1.3 local

B.

Configure the tunnel interface on all three controllers with a color of transport

C.

Remove the encapsulation IPsec command under the tunnel interface of vBond.

D.

Configure encapsulation as IPsec under the tunnel interface of vManage and vSmart

Question 132

as

Refer to the exhibit. The network administrator has configured a centralized topology policy that results in the displayed routing table at a branch office. Which two configurations are verified by the output? [Choose two.)

Options:

A.

The routing table is for the transport VPN.

B.

The default route is learned via OMP.

C.

This routing table is from a cEdge router.

D.

The default route is configured locally.

E.

The configured policy is adding a route tag of 300 to learned routes.

Page: 1 / 44
Total 441 questions