Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Questions and Answers
Which encryption algorithm secures binding exchanges Between Cisco TrustSec SXP peers?
Drag and drop the policies from the left onto the correct policy types on the right.
Which protocol is used for the vManage to connect to the vSmart Controller hosted in Cloud?
Refer to the exhibit An engineer must configure a QoS policy between me hub and site A (spoke) over a standard internet circuit where traffic shaping is adjusted automatically based on evaiiabk» bandwidth Which configuration meets the requirement?
An administrator must deploy the controllers using the On-Prem method while vManage can access the PnP portal from inside How are the two WAN Edge authorized allowed lists to be made available to vManage? (Choose two)
A network is configured with IP connectivity, and the routing protocol between devices started having problems right after the maintenance window to implement network changes. Troubleshoot and resolve to a fully functional network to ensure that:
R4
R5
Refer to the exhibit A user has selected the options while configuring a VPN Interface Ethernet feature template What is the required configuration parameter the user must set in this template for this feature to function?
Drag and drop the definitions from the left to the configuration on the right.
How many subnets are necessary in Azure VNet for a WAN Edge device to function in the cloud deployment?
Which two advanced security features are available on the Cisco SD-WAN WAN Edge (vEdge) device? (Choose two.)
In which device state does the WAN edge router create control connections, but data tunnels are not created?
Which protocol is used to measure loss latency, Jitter, and liveliness of the tunnel between WAN Edge router peers?
Refer to the exhibit vManage and vBond have an issue establishing a connection with each other Which action resolves the issue?
Which type of policy must be applied on a WAN Edge application-aware firewall to control traffic between two or more VPNs?
Which capability does Cisco SD-WAN Multi-Region Fabric provide?
Refer to the exhibit.
An enterprise has hub and spoke topology where it has several VPNs. An engineer must allow users in VPN91 to reach users in VPN92 and VPN10 to reach VPN91 and VPN92. Which configuration meets these requirements?
An engineer is configuring a list that matches all IP prefixes with lengths from /1 to /16 in a centralized control policy. Which list accomplishes this task?
An engineer must apply the configuration for certificate installation to vBond Orchestrator and vSmart Controller. Which configuration accomplishes this task?
An administrator must configure an ACL for traffic coming in from the service-side VPN on a specific WAN device with circuit ID 391897770. Which policy must be used to configure this ACL?
An engineer is tasked to improve throughput for connection-oriented traffic by decreasing round-trip latency. Which configuration will achieve this goal?
Which command verifies a policy that has been pushed to the vEdge router?
How is lhe software managed in Cisco SD-WAN?
When software is upgraded on a vManage NMS, which two image-adding options store images in a local vManage software repository? (Choose two.)
What is an advantage of using auto mode versus static mode of power allocation when an access point is connected to a PoE switch port?
What is a requirement for deployment of on-premises vBond controllers through the Cisco Plug and Play Connect process?
Which two criteria ate supported to filter traffic on a Cisco Umbrella Cloud-delivered firewall? (Choose two )
Which VPNs must be configured outside the workflow to complete the SD-WAN overlay setup when using the Quick Connect workflow?
Refer to the exhibit.
The Cisco SD-WAN network is configured with a default full-mesh topology. An engineer wants Paris WAN Edge to use the Internet HOC as the preferred TLOC for MSN Messenger and AOL Messenger traffic. Which policy achieves this goal?
A)
B)
C)
D)
An application team is getting ready to deploy a new business-critical application to the network. To protect the traffic, the network team must add another queue to the QoS map and then deploy the map to fabric Which configuration slop must be completed prior to adding the queue to the QoS map and applying If
A network administrator is configuring an application-aware firewall between inside zones to an outside zone on a WAN edge router using vManage GUI. What kind of Inspection is performed when the ‘’inspect’’ action is used?
Drag and drop the functions from the left onto the correct templates on the right.
What happens if the intelligent proxy is unreachable in the Cisco SD-WAN network?
What is the default value (in milliseconds) set tor the poll interval in the BFD basic configuration?
Which destination UDP port is used by WAN Edge router to make a DTLS connection with vBond Orchestrator?
Refer to the exhibit.
Which QoS treatment results from this configuration after the access list acl-guest is applied inbound on the vpn1 interface?
Which two mechanisms are used to guarantee the integrity of data packets in the Cisco SD-WAN architecture data plane? {Choose two)
An engineer configures policing with a rate of 125 Bps and a burst rate of 8000 bits, as shown here:
Which configuration completes this task?
What is a benefit of the application aware firewall feature in the Cisco SD-WAN solution?
An engineer must create a QoS policy by creating a class map and assigning it to the LLQ queue on a WAN Edge router Which configuration accomplishes the task?
A)
B)
C)
D)
Refer to the exhibit.
What does the BFD value of 8 represent?
Refer to the exhibit Which configuration ensures that OSPF routes learned from Site2 are reachable at Sitel and vice-versa?
Refer to the exhibit.
The control connection is failing. Which action resolves the issue?
Which Cisco SD-WAN configuration provides the advantages of day-zero deployment and reusable configuration components?
An engineer is adding a tenant with location JD 306432373 in vManage. What is the maximum number of alphanumeric characters that are accepted in the tenant name field?
Which TLOC color is used for site-to-site communication in a Google Cloud integration with Cisco SD-WAN?
Which policy blocks TLOCs from remotes and allows TLOCs from the data center to form hub-and-spoke peering?
An organization wants to discover monitor and track the applications running on the WAN Edge device on the LAN Which configuration achieves this goal?
Refer to the exhibit. The Cisco SD-VYAN is deployed using the default topology. The engineer v/ants to configure a service insertion policy such that all data traffic between Rome to Paris is forwarded through the NGFW located in London. Which configuration fulfills this requirement, assuming that the Sen/ice VPN ID is 1?
A)
B)
C)
D)
Which Cisco SD-WAN component the initial communication between WAN Edge devices to join the fabric?
In a Cisco SD-WAN architecture, what is the role of the WAN Edge?
Refer to the exhibit.
An organization is testing a Cisco SD-WAN solution and decided to have the control plane established first and not the data plane at the time of migration. Which configuration achieves this goal?
An engineer wants to track tunnel characteristics within an SLA-based policy for convergence. Which policy configuration will achieve this goal?
A customer must upgrade the cisco SD-WAN devices and controllers from version 19.2 to version 20.3. The devices include WAN Edge cloud, vManage, vSmart, and vBond. Which types of image types of image files are needed for this upgrade?
How are policies deployed on cloud-tiosted Cisco SD-WAN controllers?
Which platforms are managed by a single vManage dashboard?
What is the order of operations for software upgrades of Cisco SD-WAN nodes'?
What is a key element used in a vBond Orchestrator redundancy topology?
Refer to the exhibit The engineering must assign tags to 3 Of its 74 server networks as soon as they are advertised to peers These server network must not be advertised AS which configuration fulfil the requirement?
A)
B)
C)
D)
An engineer is troubleshooting a certificate issue on vEdge. Which command is used to verify the validity of the certificates?
Which two vRoute attributes should be matched or set in vSmart policies and modified by data policies? (Choose two.)
Which set of platforms must he in separate VMS as of release 16.1?
Which action is performed during the onboarding process when a WAN Edge router is connected to ZTP server ztp.viptela com?
An engineer is configuring a data policy IPv4 prefixes for a site WAN edge device on a site with edge devices. How is this policy added using the policy configuration wizard?
What problem happens on a device with two serial numbers, a unique device identifier (UDI), and secure unique device identifier (SUDI) when an engineer provisions ISR 4000 by PnP using only a UDI?
A customer wants to use AWS for Cisco SD-WAN laaS services by deploying virtual SD-WAN routers in a transit AWS VPC The transit VPC then connects via site-to-site IPsec tunnels to an AWS transit gateway Which transit VPC connects via site-to-site IPsec tunnels to an AWS transit gateway?
An organization wants to use the cisco SD-WAN regionalized service-chaining feature to optimize cost and user experience with application in the network, which allows branch routers to analyze and steer traffic toward the required network function. Which feature meets this requirement?
When a WAN Edge device joins the SD-WAN overlay, which Cisco SD-WAN components orchestrates the connection between the WAN Edge device and a vSmart controller?
Which set of elements are verified by the controller to confirm the identity of edge devices?
Refer to the exhibit.
Customer XYZ cannot provison dual connectivity on both Its routers due to budget constratnts but wants to use tnth RI and R2 interface for users behind them for load toward the hub site Which configurauon achieves this objectives?
A)
B)
C)
D)
Which pathway under Monitor > Network > Select Device is used to verify service insertion configuration?
Which protocol is used to propagate multicast join requests over the Cisco SD-WAN fabric?
How many concurrent sessions does a vManage REST API have before it invalidates the least recently used session if the maximum concurrent session number is reached?
Which percentage for total memory or total CPU usage for a device is classified as normal in the WAN Edge Health pane?
Which plane builds and maintains the network topology and makes decisions on traffic flows?
Drag and drop the devices from the left onto the correct functions on the right.
How does the replicator role function in cisco SD-WAN?
Which controller is excluded from the process of checking against the authorized, allowed list?
A policy is created to influence routing path in the network using a group of prefixes. What policy application will achieve this goal when applied to a site List?
An engineer must deploy a QoS policy with these requirements:
• policy name: App-police
• police rate: 1000000
• burst: 1000000
• exceed: drop
Which configuration meets the requirements?
Which application list is preconfigured?
Drag and drop the attributes from the left that make each transport location unique onto the right. Not all options are used.
In Cisco SD-WAN, what protocol is used for control connections between SD-WAN devices?
Which policy tracks path characteristics such as loss, latency, and jitter in vManage?
The network administrator is configuring a QoS scheduling policy on traffic received from transport side tunnels on WAN Edge 5000 routers at location 406141498 Which command must be configured on these devices?
Which protocol is used between redundant vSmart controllers to establish a permanent communication channel?
Which two metrics must a cloud Edge router use to pick the optimal path for a SaaS application reachable via a gateway site? (Choose two.)
Which two platforms for the Cisco SD-WAN architecture are deployable in a hypervisor on-premises or in IAAS Cloud? (Choose two.)
Which protocol is configured on tunnels by default to detect loss, latency, jitter, and path failures in Cisco SD-WAN?
An engineer is applying QoS policy for the transport-side tunnel interfaces to enable scheduling and shaping for a WAN Edge cloud router Which command accomplishes the task?
Refer to the exhibit Which NAT types must the engineer configure for the vEdge router to bring up the data plane tunnels?
Where on vManage does an engineer find the details of control node failure?
Drag and drop the BFD parameters from the left onto the BFD configurations on the right.
A voice packet requires a latency of 50 msec. Which policy is configured to ensure that a voice packet is always sent on the link with less than a 50 msec delay?
Which SD-WAN component allows an administrator to manage and store software images for SD-WAN network elements?
An engineer must improve video quality by limiting HTTP traffic to the Internet without any failover. Which configuration in vManage achieves this goal?
Drag and drop the security terminologies from the left onto the PCI-compliant network features and devices on the right.
Which routes are similar to the IP route advertisements when the routing information of WAN Edge routers is learned from the local site and local routing protocols?
Refer to the exhibit. An enterprise decides to use the Cisco SD-WAN Cloud onRamp for SaaS feature and utilize H.Q site Biz iNET to reach SaaS Cloud for branch C. currently reaching SaaS Cloud directly. Which role must be assigned to devices at both sites in vManage Cloud Express for this solution to work?
Which secure tunnel type should be used to connect one WAN Edge router to other WAN Edge routers?
Which two hardware platforms support Cisco IOS XE SD-WAN images'' (Choose two)
What is the size of SGT data in the metadata header?
Refer to the exhibit The network team must configure El GRP peering at HQ with devices in the service VPN connected to WAN Edge CSRv. CSRv is currently configured with
A)
B)
C)
D)
Which component is used for stateful inspection of TCP, UDP. and ICMP flows in Cisco SD-WAN firewall policies?
Which two sets of identifiers does OMP carry when it advertises TLOC routes between WAN Edge routers? (Choose two.)
How is multicast routing enabled on devices in the Cisco SD-WAN overlay network?
On which device is a service FW address configured to Insert firewall service at the hub?
An engineer configures an application-aware routing policy for a group of sites The locations depend on public and private transports The policy does not work as expected when one of the transports does not perform properly This policy is configured:
which configuration completes the policy so that it works for all locations?
A)
B)
C)
D)
Which protocol runs between the vSmart controllers and WAN Edge routers when the vSmart controller acts like a route reflector?
Refer to the exhibit.
Which shaping-rate does the engineer use to shape traffic at 9 Mbps?
Which queue must an engineer configure for control and BFD traffic for convergence on a WAN Edge router?
Which configuration component is used in a firewall security policy?
Which two REST API functions are performed for Cisco devices in an overlay network? (Choose two)
How is the software managed in Cisco SD-WAN?
Refer to the exhibit An engineer is configuring a QoS policy to shape traffic for VLAN 100 on a subinterface Which policy configuration accomplishes the task?
A)
B)
C)
D)
Which SD-WAN component detects path performance information in the organization to report the issue to the service provider at site ID:S4288T5E44F04?
Refer to the exhibit Cisco SD-WAN is deployed with controllers hosted in a data center All branches have WAN Edge devices with dual connections to the data center one via Internet and the other using MPLS Three branches out of 20 have issues with their control connections on MPLS circuit The local error refers to Control Connection Failure Which action resolves the issue*?
Which Cisco SD-WAN component facilitates the initial communication between WAN Edge devices to join the fabric?
What is the default value for the Multiplier field of the BFD basic configuration in vManage?
An enterprise has these three WAN connections:
public Internet
business internet
MPLS
An engineer must configure two available links to route traffic via both links. Which configuration achieves this objective?
What is a default protocol for control plane connection?
Refer to the exhibit.
The engineer must assign community tags to 3 of its 74 critical server networks as soon as that are advertised to BGP peers. These server networks must not be advertised outside AS. Which configuration fulfill this requirement?
A)
B)
C)
D)