Big 11.11 Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

Cisco 300-415 Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Exam Practice Test

Page: 1 / 44
Total 441 questions

Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$42  $139.99

PDF Study Guide

  • Product Type: PDF Study Guide
$36  $119.99
Question 1

An engineer is modifying an existing data policy for VPN 115 to meet these additional requirements:

    When browsing government websites, the traffic must use direct internet access.

    The source address of the traffic leaving the site toward the government websites must be set to an IP range associated with the country itself, a particular TLOC.

The policy configuration is as follows:

Which policy sequence meets the requirements without interfering with other destinations?

Options:

A.

sequence 30

match

destination-data-prefix-list GOVERNMENT-WEBSITES

!

action accept

set

local-tloc-list

color biz-internet

B.

sequence 25

match

destination-data-prefix-list GOVERNMENT-WEBSITES

action accept

nat use-vpn 0

C.

sequence 15

match

source-data-prefix-list GOVERNMENT-WEBSITES

action accept

set

local-tloc-list

color private1

D.

sequence 15

match

destination-data-prefix-list GOVERNMENT-WEBSITES

!

action accept

set

local-tloc-list

color biz-internet

Question 2

The branch users of an organization must be prevented from accessing malicious destinations, and the local files on users' systems must be protected from malware. Which two Cisco products must the organization deploy? (Choose two.)

Options:

A.

Cisco Stealthwatch

B.

Cisco Umbrella

C.

Cisco AMP

D.

Cisco Cloudlock

E.

Cisco SecureX

Question 3

Which component of the Cisco SD-WAN control plane architecture should be located in a public Internet address space and facilitates NAT-traversal?

Options:

A.

vBond

B.

WAN Edge

C.

vSmart

D.

vManage

Question 4

An engineer wants to automate the onboarding process for a WAN Edge router with vManage. Which command will accomplish this?

Options:

A.

request vedge-cloud activate chassis-number serial

B.

request vedge-cloud activate chassis-number token

C.

request vedge-cloud activate serial token

D.

request vedge-cloud activate chassis-number organization

Question 5

Refer to the exhibit.

An organization is testing a Cisco SD-WAN solution and decided to have the control plane established first and not the data plane at the time of migration. Which configuration achieves this goal?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 6

Which feature allows reachability to an organization’s internally hosted application for an active DNS security policy on a device?

Options:

A.

local domain bypass

B.

DHCP option 6

C.

DNSCrypt configurator

D.

data pokey with redirect

Question 7

Which configuration change allows direct internet access at the branch site for YouTube traffic?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 8

What do receivers request to join multicast streams in a Cisco SO-WAN network?

Options:

A.

IGMP membership reports directly with a multicast router.

B.

Multicast service routes with the vSmart controller

C.

IGMP membership reports directly with the vBond orchestrator.

D.

PIM messages with the nearest neighboring multicast router.

Question 9

Refer to the exhibit. Company ABC has a hub-and-spoke topology in place and currently is load balancing their data traffic at the hub site over MPLS and the public Internet. The leased circuit must be preferred over the shared circuit. Which configuration meets the requirement?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 10

Refer to the exhibit An engineer is configuring a QoS policy to shape traffic for VLAN 100 on a subinterface Which policy configuration accomplishes the task?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 11

Which two platforms for the Cisco SD-WAN architecture are deployable in a hypervisor on-premises or in IAAS Cloud? (Choose two.)

Options:

A.

CSR 1000v

B.

vEdge 100c

C.

vEdge Cloud

D.

vEdge 2000

E.

ISR 4431

Question 12

Which two WAN Edge devices should be deployed in a cloud? (Choose two.)

Options:

A.

vEdge 5000v

B.

ASR 1000v

C.

CSR 1000v

D.

vEdge 100wm

E.

vEdge cloud

Question 13

Refer to the exhibit. The Cisco SD-WAN is deployed using the default topology. The engineer wants to configure a service insertion policy such that all data traffic between Rome to Paris is forwarded through the NGFW located in London. Which configuration fulfills this requirement, assuming that the Service VPN ID is 1?

Options:

A.

B.

C.

D.

Question 14

What is the threshold to generate a warning alert about CPU or memory usage on a WAN Edge router?

Options:

A.

70 to 85 percent

B.

70 to 90 percent

C.

75 to 85 percent

D.

75 to 90 percent

Question 15

Refer to the exhibit.

What does the BFD value of 8 represent?

Options:

A.

number of BFD sessions

B.

hello timer of BFD session

C.

poll-interval of BFD session.

D.

dead timer of BFD session

Question 16

Refer to the exhibit.

The network team must configure branch B WAN Edge device 103 to establish dynamic full-mesh IPsec tunnels between all colors with branches over MPLS and Internet circuits. The branch ts configured with:

Which configuration meets the requirement?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 17

What is the maximum number of IPsec that are temporarily created and converged on a new set if IPsec Sas in the pairwise keys process during a simultaneous rekey?

Options:

A.

2

B.

4

C.

6

D.

8

Question 18

Which data policy configuration influences BGP routing traffic flow from LAN to WAN?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 19

Refer to the exhibit. An administrator is configuring a policy in addition to an existing hub-and-spoke policy for two sites that should directly communicate with each other. How is this policy configured?

Options:

A.

hub-and-spoke

B.

mesh

C.

import existing topology

D.

custom control (route and TLOC)

Question 20

What is the default value for the number of paths advertised per prefix in the OMP feature template?

Options:

A.

4

B.

8

C.

12

D.

16

Question 21

Which protocol is used by the REST API to communicate with network devices in the Cisco SD-WAN network?

Options:

A.

SSL

B.

IPsec

C.

SSH

D.

HTTP

Question 22

A network administrator is configuring an application-aware firewall between inside zones to an outside zone on a WAN edge router using vManage GUI. What kind of Inspection is performed when the ‘’inspect’’ action is used?

Options:

A.

stateful inspection for TCP and UDP

B.

stateful inspection for TCP and stateless inspection of UDP

C.

IPS inspection for TCP and-Layer 4 inspection for UDP

D.

Layer 7 inspection for TCP and Layer 4 inspection for UDP

Question 23

Refer to the exhibit. An engineer must configure the Overlay Management Protocol route preference so that when B2 tries to reach host routes advertised by B1 it always chooses the MPLS circuit. Which two match conditions must be configured to accomplish this task? (Choose two.)

Options:

A.

VPN

B.

prefix list

C.

originator

D.

color list

E.

path type

Question 24

A network administrator is configuring a tunnel interface on a branch Cisco IOS XE router to run TLOC extensions. Which configuration will extend a TLOC over a GRE tunnel to another router in the branch?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 25

Which two mechanisms are used by vManage to ensure that the certificate serial number of the WAN Edge router that is needed to authenticate is listed in the WAN Edge Authorized Señal Number Hst’ (Choose two)

Options:

A.

Synchronize to the PnP

B.

Manually upload it to vManage

C.

The devices register to vManage directly as the devices come online

D.

The vManage is shipped with the list

E.

Synchronize to the Smart Account

Question 26

Which protocol Is used by the REST API to communicate with network services in the Cisco SO-WAN network?

Options:

A.

SSL

B.

HTTP

C.

iPsec

D.

SSM

Question 27

An administrator wants to create a policy to add a traffic policer called "politer-ccnp" to police data traffic on the WAN Edge. Which configuration accomplishes this task in vSmart?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 28

What prohibits deleting a VNF image from the software repository?

Options:

A.

if the image is stored by vManage

B.

if the image is referenced by a service chain

C.

if the image is uploaded by a WAN Edge device

D.

if the image is included in a configured policy

Question 29

What is the result during a WAN Edge software upgrade process if the version of the WAN Edge software is higher than the one running on a controller device?

Options:

A.

The upgrade button is greyed out

B.

The upgrade proceeds with no warning message.

C.

The upgrade fails with a warning message

D.

The upgrade proceeds with a warning message

Question 30

How does the replicator role function in cisco SD-WAN?

Options:

A.

WAN Edge devices advertise the rendezvous point to all the receivers through the underlay network.

B.

vSmart Controllers advertise the rendezvous point to all the receivers through the overlay network.

C.

WAN Edge devices advertise the rendezvous point to all receivers through the overlay network.

D.

vSmart Controllers advertise the rendezvous point to all the receivers through the underlay network.

Question 31

Which cloud based component in cisco SD-WAN is responsible for establishing a secure connection to each WAN edge router and distributes routers and policy information via omp?

Options:

A.

vBond

B.

vManage

C.

vSmart

D.

WAN Edge

Question 32

An organization wants to discover monitor and track the applications running on the WAN Edge device on the LAN Which configuration achieves this goal?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 33

An engineer must apply the configuration for certificate installation to vBond Orchestrator and vSmart Controller. Which configuration accomplishes this task?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 34

Which TCP Optimization feature is used by WAN Edge to prevent unnecessary retransmissions and large initial TCP window sizes to maximize throughput and achieve a better quality?

Options:

A.

SEQ

B.

SYN

C.

RTT

D.

SACK

Question 35

WAN Edge routers are configured manually to use UDP port offset to use nondefault offset values when IPsec tunnels are created. What is the offse range?

Options:

A.

1-19

B.

0-18

C.

0-19

D.

1-18

Question 36

What is the size of SGT data in the metadata header?

Options:

A.

8 bits

B.

16 bits

C.

24 bits

D.

32 bits

Question 37

How is a TLOC uniquely identified from a WAN Edge router to the SD-WAN transport network?

Options:

A.

system IP address

B.

VPN ID

C.

OMP

D.

SD-WAN site ID

Question 38

Which protocol is used for the vManage to connect to the vSmart Controller hosted in Cloud?

Options:

A.

PnP Server

B.

ZTP

C.

NETCONF

D.

HTTP

Question 39

Which Cisco SD-WAN configuration provides the advantages of day-zero deployment and reusable configuration components?

Options:

A.

CLI-based templates

B.

configuration groups

C.

configuration via the vBond controller

D.

configuration through a Cisco Prime server

Question 40

How is the scalability of the vManage increased in Cisco SD-WAN Fabric?

Options:

A.

Increase licensing on the vManage

B.

Deploy multiple vManage controllers in a cluster

C.

Deploy more than one vManage controllers on different physical server.

D.

Increase the bandwidth of the WAN link connected to the vManage

Question 41

Refer to the exhibit. A network administrator is setting the queueing value for voice traffic for one of the WAN Edge routers using vManager GUI. Which queue value must be set to accomplish this task?

Options:

A.

0

B.

1

C.

2

D.

3

Question 42

How many concurrent sessions does a vManage REST API have before it invalidates the least recently used session if the maximum concurrent session number is reached?

Options:

A.

150

B.

200

C.

250

D.

300

Question 43

Which routing protocol is used to exchange control plane information between vSmart controllers and WAN Edge routers in the Cisco SD-WAN secure extensible network?

Options:

A.

BGP

B.

OSPF

C.

BFD

D.

OMP

Question 44

Refer to the exhibit. Which configuration extends the INET interface on R1 to be used by R2 for control and data connections?

A)

B)

C)

Options:

A.

Option A

B.

Option B

C.

Option C

Question 45

A customer must upgrade the cisco SD-WAN devices and controllers from version 19.2 to version 20.3. The devices include WAN Edge cloud, vManage, vSmart, and vBond. Which types of image types of image files are needed for this upgrade?

Options:

A.

one file for vManage and one file for all other devices with extension tar.gz

B.

one file for vManage, one for vSmart and one for vBond + WAN Edge Cloud with extension.bin

C.

one file for vManaga, one for vSmart and one for vBond + WAN Edge Cloud with extension tar.gz

D.

one file for vManaga and one file for all other devices with extension .bin

Question 46

In which Cisco SD-WAN deployment scenario does Cisco Umbrella SIG deliver the most value?

Options:

A.

when a centralized Internet breakout solution is implemented

B.

when resource-intensive security operations are offloaded from entry-level WAN Edge devices

C.

when the identity of several WAN Edge devices is verified throughout the networkthroughout the network

Question 47

Which port is used for vBond under controller certificates if no alternate port is configured?

Options:

A.

12345

B.

12347

C.

12346

D.

12344

Question 48

Which policy configures an application-aware routing policy under Configuration > Policies?

Options:

A.

Localized policy

B.

Centralized policy

C.

Data policy

D.

Control policy

Question 49

What are the default username and password for vSmart Controller when it is installed on a VMware ESXi hypervisor'?

Options:

A.

username Cisco password admin

B.

username admin password Cisco

C.

username Cisco password Cisco

D.

username admin password admin

Question 50

Which component of the Cisco SD-WAN secure extensible network provides a single pane of glass approach to network monitoring and configuration?

Options:

A.

APIC-EM

B.

vSmart

C.

vManage

D.

vBond

Question 51

An engineer is configuring a data policy IPv4 prefixes for a site WAN edge device on a site with edge devices. How is this policy added using the policy configuration wizard?

Options:

A.

In vManage NMS select (he configure ► policies screen, select the centralized policy tab and click add policy

B.

In vBood orchestrator. select the configure > policies screen select the localized policy tab. and click add policy

C.

In vManage NMS. select the configure ► policies screen. select the localized policy tab- and click add policy

D.

In vSmart controller select tie configure ► policies screen, select the localized policy tab, and click add policy

Question 52

What is a requirement for a WAN Edge to reach vManage, vBond, and vSmart controllers in a data center?

Options:

A.

IGP

B.

QoS

C.

TLS

D.

OMP

Question 53

Which configuration component is used in a firewall security policy?

Options:

A.

numbered sequences of match-action pairs

B.

application match parameters

C.

URL filtering policy

D.

intrusion prevention policy

Question 54

Refer to the exhibit The network team must configure El GRP peering at HQ with devices in the service VPN connected to WAN Edge CSRv. CSRv is currently configured with

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 55

Drag and drop the alarm states from the left onto the corresponding alarm descriptions on the right.

Options:

Question 56

Which two performance data details are provided by Cisco SO-WAN vAnalytics? (Choose two)

Options:

A.

jitter loss and latency for data tunnels

B.

application quality of experience score from zero to ten

C.

detail on total cost of ownership for the fabric

D.

certificate authority status (health and expiration dates) for all controllers

E.

view devices connected to a vManage NMS

Question 57

Where on vManage does an engineer find the details of control node failure?

Options:

A.

Alarms

B.

Events

C.

Audit log

D.

Network

Question 58

A company is using Catalyst SD-WAN Manager as its root certificate authority server and must generate a root certificate using the vShell (Linux) built into the CLI of Catalyst SD-WAN Manager. Which command must be issued to generate the root certificate?

Options:

A.

openssl req -x509 -new-nodes -key XYZ.pem -sha256 -days 365 \subj "/C=US/ST=DC/L=DC/O=Cisco/CN=device.lab"-out ABC.key

B.

openssl genrsa -out ROOTCA.pem 2048

C.

openssl req -x509 -new-nodes -key XYZ.key -sha256 -days 365 Isubj "/C-US/ST-DC/L-DC/O-Cisco/CN-device.lab" 1-out ABC.pem

D.

openssl genrsa -out ROOTCA.key 2048

Question 59

A voice packet requires a latency of 50 msec. Which policy is configured to ensure that a voice packet is always sent on the link with less than a 50 msec delay?

Options:

A.

centralized control

B.

localized data

C.

localized control

D.

centralized data

Question 60

For data plane resiliency, what does the Cisco SD-WAN software implement?

Options:

A.

BFD

B.

establishing affinity between vSmart controllers and WAN Edge routers

C.

multiple vBond orchestrators

D.

OMP

Question 61

An engineer must advertise OSPF-learned routes and modify the update interval for route filtering by TLOC color to 300 on an SD-WAN device. Which configuration accomplishes this

task?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 62

Which device in the SD- WAN solution receives and categorizes event reports, and generates alarms?

Options:

A.

WAN Edge routers

B.

vSmart controllers

C.

vManage NMS

D.

vBond controllers

Question 63

In which VPN is the NAT operation on an outgoing interface configured for direct Interne! access?

Options:

A.

1

B.

10

C.

512

D.

0

Question 64

What problem happens on a device with two serial numbers, a unique device identifier (UDI), and secure unique device identifier (SUDI) when an engineer provisions ISR 4000 by PnP using only a UDI?

Options:

A.

It encounters spanning tree issues

B.

It faces interface buffer overflow patterns

C.

It encounters redirection problems.

D.

It encounters memory overload problems

Question 65

Which set of platforms must he in separate VMS as of release 16.1?

Options:

A.

vSmart and WAN Edge

B.

WAN Edge and vBond

C.

vManagc and vSmart

D.

vBond and vSmart

Question 66

What is an advantage of using auto mode versus static mode of power allocation when an access point is connected to a PoE switch port?

Options:

A.

It detects the device is a powered device

B.

All four pairs of the cable are used

C.

Power policing is enabled at the same time

D.

The default level is used for the access point

Question 67

Drag and drop the components from the left onto the corresponding Cisco NFV infrastructure Building Blocks on the right. Not all options are used.

Options:

Question 68

Configure individual VRFs for each customer according to the topology to achieve these goals :

R1

R2

SW1

SW2

SW3

Options:

Question 69

An engineer must configure two branch WAN Edge devices where an Internet connection is available and the controllers are in the headquarters. The requirement is to have IPsec VPN tunnels established between the same colors. Which configuration meets the requirement on both WAN Edge devices?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 70

What are the two advantages of configuration groups in a Cisco SD-WAN deployment? (Choose two.)

Options:

A.

Individual devices are associated with a configuration group and a device template.

B.

Individual devices are added to multiple groups.

C.

Individual devices are grouped based on a shared configuration.

D.

A subset of devices is identified with tags.

E.

An individual device has multiple tag rules.

Question 71

Drag and drop the actions from the left into the correct sequence on the right to create a data policy to direct traffic to the Internet exit.

Options:

Question 72

Drag and drop the attributes from the left that make each transport location unique onto the right. Not all options are used.

Options:

Question 73

A vEdge platform is sending VRRP advertisement messages every 10 seconds. Which value configures the router back to the default timer?

Options:

A.

2 seconds

B.

3 seconds

C.

1 second

D.

5 seconds

Question 74

Refer to the exhibit. Which issue is shown, and which action must an engineer take to resolve the issue?

Options:

A.

An IPsec issue; verify and resolve the tunnel configurations on devices.

B.

An organization name issue; verify and correct the configuration on the devices.

C.

A certificate issue; verify and correct the certificate attributes.

D.

A connectivity issue; verify and resolve the reachability to the controller.

Question 75

Which OSPF command makes the WAN Edge router a less preferred exit from a site with a dual WAN Edge design?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 76

Which third-party Enterprise CA server must be used (or a cloud-based vSmart controller?

Options:

A.

RootCert

B.

Microsoft

C.

RADIUS

D.

VeriSign

Question 77

At which layer does the application-aware firewall block applications on a WAN Edge?

Options:

A.

3

B.

7

C.

5

D.

2

Question 78

What is the function of colocation in Cloud OnRamp SaaS?

Options:

A.

Cloud OnRamp incorporates regional colocation facilities by choosing between cloud access points at the remote site and regional cloud access points at the colocation facilities.

B.

The Cloud OnRamp for colocation solution restricts the creation of different VNF service chains orchestrated in Cisco vManage and deployed on a cluster in a colocation facility.

C.

In Cloud OnRamp. colocation supports the capability of virtualizing access-only locations and using colocation centers that require the customer to extend to the cloud.

D.

With colocation facility in Cloud OnRamp. the customer faces challenges to virtualize the security and optimization infrastructure that influence traffic through network elements.

Question 79

A network is configured with CoPP to protect the CORE router route processor for stability and DDoS protection. As a company policy, a class named class-default is preconfigured and must not be modified or deleted. Troubleshoot CoPP to resolve the issues introduced during the maintenance window to ensure that:

WAN

CORE

MGMT

Options:

Question 80

Which platform cannot provide IPS and URL filtering capabilities?

Options:

A.

Cisco CSR 1000V

B.

Cisco ISR 1000

C.

Cisco Catalyst 8300

D.

Cisco ISR 4000

Question 81

Refer to the exhibit. Which configuration ensures that OSPP routes learned from Site2 are reachable at Stein and vice-versa?

Options:

A.

B.

C.

Question 82

Which alarm setting is configured to monitor serious events that affect but do not shut down, the operation of a network function?

Options:

A.

Minor

B.

Major

C.

Medium

D.

Critical

Question 83

An enterprise needs DIA on some of its branches with a common location ID: A041:B70C: D78E::18 Which WAN Edge configuration meets the requirement?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 84

Which protocol runs between the vSmart controllers and WAN Edge routers when the vSmart controller acts like a route reflector?

Options:

A.

OMP outside the DTLS/TLS control connection

B.

BGP inside the DTLS/TLS

C.

IPsec inside the DTLS/TLS control connection

D.

OMP inside the DTLS/TLS control connection

Question 85

What is a benefit of the application aware firewall feature in the Cisco SD-WAN solution?

Options:

A.

application monitoring

B.

application malware protection

C.

application visibility

D.

control policy enforcement

Question 86

An engineer must avoid routing loops on the SD-WAN fabric for routes advertised between data center sites Which BGP loop prevention attribute must be configured on the routers to meet this requirement?

Options:

A.

same OMP overlay-as on WAN Edge routers of all data centers

B.

static routing on al WAN Edge routers instead of BGP

C.

same BGP AS between all WAN Edge routers and CE routers

D.

same BGP AS between all CE and PE routers

Question 87

Refer to the exhibit.

An engineer configured OMP with an overlay-as of 10666. What is the AS-PATH for prefix 104.104.104.104/32 on R100?

Options:

A.

100 10666

B.

100 20 104

C.

100 10666 20 104

D.

100 10666 104

Question 88

In a Cisco SD-WAN network, which component is responsible for distributing route and policy information via the OMP?

Options:

A.

vManage

B.

vSmart Controler

C.

vBond Orchestrator

D.

WAN Edge Router

Question 89

What is the behaviour of vBond orchestrator?

Options:

A.

It maintains vSmart and WAN Edge routers secure connectivity state

B.

it builds permanent connections with vSmart controllers

C.

it updates vSmart of WAN Edge routers behind NAT devices using OMP.

D.

It builds permanent connections with WAN Edge routers

Question 90

Refer to the exhibit.

The network design team has advised to use private IP addresses and private colors over the SP circuit for the data plane connections. The Public IP should be used for control connections. Which configuration should be applied at SiteA to achieve this task?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 91

Which secure tunnel type should be used to connect one WAN Edge router to other WAN Edge routers?

Options:

A.

TLS

B.

DTLS

C.

SSL VPN

D.

IPsec

Question 92

Which two image formats are supported for controller codes? (Choose two.)

Options:

A.

.nxos

B.

.qcow2

C.

.ova

D.

.bin

E.

Tgz

Question 93

How many cloud gateway instance(s) can be created per region when provisioning Cloud OnRamp for Multicloud from AWS in a multiregion environment?

Options:

A.

one

B.

two

C.

three

D.

four

Question 94

An engineer is configuring a WAN Edge router for DIA based on matching QoS parameters. Which two actions accomplish this task? (Choose two.)

Options:

A.

Apply a QoS map policy.

B.

Configure a control policy.

C.

Configure a centralized data policy.

D.

Configure NAT on the transport interface.

E.

Apply a data policy on WAN interface.

Question 95

Which two algorithms authenticate a user when configuring SNMPv3 monitoring on a WAN Edge router? (Choose two.)

Options:

A.

AES-256

B.

SHA-1

C.

AES-128

D.

MD5

E.

SHA-2

Question 96

Which pathway under Monitor > Network > Select Device is used to verify service insertion configuration?

Options:

A.

Real Time

B.

System Status

C.

ACL Logs

D.

Events

Question 97

Refer to the exhibit.

The tunnel interface configuration on both WAN Edge routers is:

Which configuration for WAN Edge routers will connect to the Internet?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 98

Which two protocols are supported for software image delivery when images are hosted on a remote server? (Choose two.)

Options:

A.

HTTPS

B.

SSL

C.

HTTP

D.

TFTP

E.

FTP

Question 99

Which OMP route is selected for equal OMP route preference values on WAN Edge routers?

Options:

A.

route with higher TLOC preference value

B.

route with origin type of connected

C.

route with origin type of static

D.

route with lower TLOC preference value

Question 100

Which two metrics must a cloud Edge router use to pick the optimal path for a SaaS application reachable via a gateway site? (Choose two.)

Options:

A.

HTTP loss and latency metrics to the SaaS application

B.

ICMP loss and latency metrics to the SaaS application

C.

BFD loss and latency metrics to the gateway site

D.

BFD loss and latency metrics to the SaaS application

E.

HTTP loss and latency metrics to the gateway site

Question 101

Which two different states of a WAN Edge certificate are shown on vManage? (Choose two.)

Options:

A.

inactive

B.

active

C.

staging

D.

invalid

E.

provisioned

Question 102

An organization wants to use the cisco SD-WAN regionalized service-chaining feature to optimize cost and user experience with application in the network, which allows branch routers to analyze and steer traffic toward the required network function. Which feature meets this requirement?

Options:

A.

Cloud Services Platform

B.

VNF Service Chaning

C.

Cloud onRamp for Colocation

D.

Cloud onRamp for laaS

Question 103

Which two actions are necessary to set the Controller Certificate Authorization mode to indicate a root certificate? (Choose two)

Options:

A.

Select the Controller Certificate Authorization mode that is recommended by Cisco

B.

Change the organization name of the Cisco SO-WAN fabric.

C.

Upload an SSL certificate to vManape,

D.

Select a private certificate signing authority instead of a public certificate signing authority

E.

Select a validity period from the drop-down menu

Question 104

An administrator must configure an ACL for traffic coming in from the service-side VPN on a specific WAN device with circuit ID 391897770. Which policy must be used to configure this ACL?

Options:

A.

local data policy

B.

central data policy

C.

app-aware policy

D.

central control policy

Question 105

How many vManage NMSs should be installed in each domain to achieve scalability and redundancy?

Options:

A.

two instances

B.

two clusters

C.

three or more in a cluster

D.

two or more in a cluster

Question 106

Which configuration defines the groups of interest before creation of the access list or route map?

A)

B)

C)

D.

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 107

Which configuration allows users to reach YouTube from a local Internet breakout?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 108

What is the ZTP workflow for Cisco IOS XE-based devices?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 109

A customer is receiving routes via OMP from vSmart controller for a specific VPN. The customer must provide access to the W2 loopback received via OMP to the OSPF neighbor on the service-side VPN, which configuration fulfils these requirements?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Question 110

Which feature delivers traffic to the Cisco Umbrella SIG cloud from a Cisco SD-WAN domain?

Options:

A.

L2TPv3 tunnel

B.

IPsec tunnel

C.

local umbrella agent

D.

source NAT

Question 111

How many subnets are necessary in Azure VNet for a WAN Edge device to function in the cloud deployment?

Options:

A.

CSR is the WAN Edge device that is supported in the Microsoft cloud. The Microsoft underlay cloud fabric performs the management function.

B.

There must be three subnets in VNet: management, public, and services.

C.

One public subnet is required in VNet. The Microsoft underlay cloud fabric performs all of the routing functions for WAN Edge.

D.

Public and services subnets are required in VNet. The Microsoft underlay cloud fabric performs the management function.

Question 112

An administrator is configuring the severity level on the vManage NMS for events that indicate that an action must be taken immediately. Which severity level must be configured?

Options:

A.

warning

B.

error

C.

critical

D.

alert

Question 113

Refer to the exhibit A user has selected the options while configuring a VPN Interface Ethernet feature template What is the required configuration parameter the user must set in this template for this feature to function?

Options:

A.

The "IP MTU" field must be increased from the default value of 1500 to support the additional overhead.

B.

The "Shaping Rate (Kbps)" field must be configured with a value

C.

The "Adaptive QoS" field must be set to "on"

D.

The "Bandwidth Downstream" field must be configured with a value

Question 114

Refer to the exhibit A vBond controller was added to the controller list with the same Enterprise Root CA certificate as vManage. The two controllers can reach each other via VPNO and share the same organization name, but the control connection is not initiated- Which action resolves the issue?

Options:

A.

Synchronize the WAN Edge list on vManage with controllers.

B.

Configure NTP on both controllers to establish a connection.

C.

Configure a valid systom IP on the vBond controller.

D.

Configure a valid vBond IP on vManage.

Question 115

Which SD-WAN component is configured to enforce a policy to redirect branch-to-branch traffic toward a network service such as a firewall or IPS?

Options:

A.

vBond

B.

WAN Edge

C.

vSmart

D.

Firewall

Question 116

A network administrator is tasked to make sure that an OMP peer session is closed after missing three consecutive keepalive messages in 3 minutes. Additionally, route updates must be sent every minute. If a WAN Edge router becomes unavailable, the peer must use last known information to forward packets for 12 hours. Which set of configuration commands accomplishes this task?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 117

Which set of elements are verified by the controller to confirm the identity of edge devices?

Options:

A.

certificates, organization name and serial number of the device

B.

organization name serial number and system IP of the device

C.

certificates, organization name, and vBond domain

D.

certificates, system IP, and vBond domain

Question 118

Which protocol is used to measure jitter, loss, and latency on SD-WAN overlay tunnels?

Options:

A.

QoE

B.

OMP

C.

BGP

D.

BFD

Question 119

Which feature template configures OMP?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 120

Refer to the exhibit An engineer is getting a CTORGNMMIS error on a controller connection Which action resolves this issue?

Options:

A.

Configure a valid serial number on the WAN Edge

B.

Configure a valid organization name

C.

Configure a valid certificate on vSMART

D.

Configure a valid product ID

Question 121

What is a restriction when configuring a tunnel interface?

Options:

A.

Up to six tunnel interfaces are configurable on a vSmart.

B.

it is manually assigned when using vWanage feature template.

C.

It must be configured for the interface under aft VPNs

D.

Up to six tunnel interfaces are configurable on a WAN Edge

Question 122

Which SD-WAN component detects path performance information in the organization to report the issue to the service provider at site ID:S4288T5E44F04?

Options:

A.

vAnalytics

B.

vManage NMS

C.

vBond Orchestrator

D.

Cisco DNA

Question 123

What is the function of the AppNav Controller in the Cisco SD-WAN AppNav solution?

Options:

A.

It accelerates specific traffic based on preconfigured policies.

B.

It provides information about configured optimization policies on SD-WAN edge devices.

C.

It provides configuration and monitoring for WAAS nodes.

D.

It intercepts and distributes network traffic based on configured policies.

Question 124

What is a description of vManage NMS?

Options:

A.

It is accessible only from VPN 512 (the management VPN).

B.

A cluster requires device templates to be created on and attached to the same server

C.

It is a software process on a dedicated WAN Edge router in the network.

D.

A cluster consists of a minimum of two vManage NMSs

Question 125

When redistribution is configured between OMP and BGP at two Data Center sites that have Direct Connection interlink, which step avoids learning the same routes on WAN Edge routers of the DCs from LAN?

Options:

A.

Define different VRFs on both DCs

B.

Set same overlay AS on both DC WAN Edge routers

C.

Set down-bit on Edge routers on DC1

D.

Set OMP admin distance lower than BGP admin distance

Question 126

Refer to the exhibit.

Which QoS treatment results from this configuration after the access list acl-guest is applied inbound on the vpn1 interface?

Options:

A.

A UDP packet sourcing from 172.16.20.1 and destined to 172.16.10.1 is accepted

B.

A TCP packet sourcing from 172.16.10.1 and destined to 172.16.20.1 is dropped

C.

A UDP packet souring from 172.16.10.1 and destined to 172.16.20.1 is dropped.

D.

A TCP packet sourcing from 172.16.20.1 and destined to 172.16.10.1 is accepted

Question 127

How many vCPUs and how much RAM are recommended to run the vSmart controller on the KVM server for 251 to 1000 devices in software version 20.4.x?

Options:

A.

4vCPUs. 16 GB

B.

4 vCPUs. 8 GB

C.

8vCPUs. 16 GB

D.

2vCPUs.4GB

Question 128

Refer to the exhibit.

Which command-line configuration on a WAN Edge device achieves these results?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 129

Drag and drop the devices from the left onto the correct functions on the right.

Options:

Question 130

Which two products are used to deploy Cisco WAN Edge Router virtual platforms? (Choose two.)

Options:

A.

HP ProLiant DL360 Generatton10 running HP-UX

B.

Cisco ENCS 5000 Series

C.

Sun SPARC Node running AIX

D.

Cisco UCS

E.

Sun Enterprise M4000 Server running Sun Solans

Question 131

Drag and drop the route verification output from show omp tlocs from the left onto the correct explanations on the right.

Options:

Question 132

What happens if the intelligent proxy is unreachable in the Cisco SD-WAN network?

Options:

A.

The grey-listed domains are unresolved

B.

The Cisco Umbrella Connector locally resolves the DNS request

C.

The block-listed domains are unresolved

D.

The Cisco Umbrella Connector temporarily redirects HTTPS traffic

Page: 1 / 44
Total 441 questions