Labour Day Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Cisco 300-415 Implementing Cisco SD-WAN Solutions (ENSDWI) Exam Practice Test

Page: 1 / 36
Total 359 questions

Implementing Cisco SD-WAN Solutions (ENSDWI) Questions and Answers

Question 1

Refer to the exhibit.

Question # 1

The tunnel interface configuration on both WAN Edge routers is:

Question # 1

Which configuration for WAN Edge routers will connect to the Internet?

Question # 1

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 2

Which combination of platforms are managed by vManage?

Options:

A.

ISR4321, ASR1001, ENCS, lSRv

B.

ISR4351, ASR1002HX, vEdge2000, vEdge Cloud

C.

ISR4321, ASR1001, Nexus, ENCS

D.

lSR435l, ASRl009, vEdge2000, CSR1000v

Question 3

An administrator must deploy the controllers using the On-Prem method while vManage can access the PnP portal from inside How are the two WAN Edge authorized allowed lists to be made available to vManage? (Choose two)

Question # 3

Question # 3

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 4

If Smart Account Sync is not used, which Cisco SD-WAN component is used to upload an authorized serial number file?

Options:

A.

WAN Edge

B.

vManage

C.

vSmart

D.

vBond

Question 5

Which device should be configured with the service chain IP address to route intersite traffic through a firewall?

Options:

A.

vSmart

B.

firewall

C.

spoke WAN Edge

D.

hub WAREdge

Question 6

Which feature template configures OMP?

A)

Question # 6

B)

Question # 6

C)

Question # 6

D)

Question # 6

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 7

Which policy is configured to ensure that a voice packet is always sent on the link with less than a 50 msec delay?

Options:

A.

localized data policy

B.

localized control policy

C.

centralized data policy

D.

centralized control policy

Question 8

Drag and drop the BFD parameters from the left onto the BFD configurations on the right.

Question # 8

Options:

Question 9

How do WAN Edge devices operate when vSmart is inaccessible or fails to be reached by the WAN Edge?

Options:

A.

They cease to forward traffic in the data plane.

B.

They continue operation normally.

C.

They continue to receive reachability updates.

D.

They continue operating normally for a configurable time.

Question 10

Which two actions are necessary to set the Controller Certificate Authorization mode to indicate a root certificate? (Choose two)

Options:

A.

Select the Controller Certificate Authorization mode that is recommended by Cisco

B.

Change the organization name of the Cisco SO-WAN fabric.

C.

Upload an SSL certificate to vManape,

D.

Select a private certificate signing authority instead of a public certificate signing authority

E.

Select a validity period from the drop-down menu

Question 11

An engineer must configure two branch WAN Edge devices where an Internet connection is available and the controllers are in the headquarters. The requirement is to have IPsec VPN tunnels established between the same colors. Which configuration meets the requirement on both WAN Edge devices?

Question # 11

Question # 11

Question # 11

Question # 11

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 12

A Cisco SD-WAN customer has a requirement to calculate the SHA value for files as they pass through the device to see the returned disposition and determine if the file is good, unknown or malicious. The customer also wants to perform real-time traffic analysis and generate alerts when threats are detected Which two Cisco SD-WAN solutions meet the requirements? (Choose two.)

Options:

A.

Cisco Trust Anchor Module

B.

Cisco Threat Grid

C.

Cisco Snort IPS

D.

Cisco AMP

E.

Cisco Secure Endpoint

Question 13

An engineer must configure local redundancy on a site. Which configuration accomplish this task?

Options:

A.

vpn 0

interface interface-name

B.

tloc extension interlace name

tloc extension interface interface name

C.

vpn 0

tloc extension interface

D.

interface-flame

interface interface-name tloc-extension

Question 14

Which set of platforms must he in separate VMS as of release 16.1?

Options:

A.

vSmart and WAN Edge

B.

WAN Edge and vBond

C.

vManagc and vSmart

D.

vBond and vSmart

Question 15

An engineer must configure the SD-WAN Edge router to identify DSCP 26 traffic coming from the router's local site and then change the DSCP value to DSCP 18 before sending it over to the SD-WAN fabric. What are the two ways to create the required configuration? (Choose two).

Question # 15

Question # 15

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Question 16

What is the threshold to generate a warning alert about CPU or memory usage on a WAN Edge router?

Options:

A.

70 to 85 percent

B.

70 to 90 percent

C.

75 to 85 percent

D.

75 to 90 percent

Question 17

Refer to the exhibit.

Question # 17

The control connection is failing. Which action resolves the issue?

Options:

A.

import vSmart in vManager

B.

Validate the certificates authenticity on vSmart

C.

Upload the WAN Edge list on vManage.

D.

Restore the reachability to the vSmart

Question 18

How is a TLOC uniquely identified from a WAN Edge router to the SD-WAN transport network?

Options:

A.

system IP address

B.

VPN ID

C.

OMP

D.

SD-WAN site ID

Question 19

What is the purpose of ‘’vpn 0’’ in the configuration template when onboarding a WAN edge node?

Options:

A.

It carries control traffic over secure DTLS or TLS connections between vSmart controllers and vEdge routers, and between vSmart and vBond

B.

It carries control out-of-band network management traffic among the Viptela devices in the overlay network.

C.

It carries control traffic over secure IPsec connections between vSmart controllers and vEdge routers, and between vSmart and vManager

D.

It carries control traffic over secure IPsec connections between vSmart controllers and vEdge routers, and between vSmart and vBond

Question 20

A policy is created to influence routing path in the network using a group of prefixes. What policy application will achieve this goal when applied to a site List?

Options:

A.

vpn-membership policy

B.

cflowd-template

C.

app-route policy

D.

control-policy

Question 21

Which protocol is configured on tunnels by default to detect loss, latency, jitter, and path failures in Cisco SD-WAN?

Options:

A.

TLS

B.

BFD

C.

OMP

D.

BGP

Question 22

Which feature delivers traffic to the Cisco Umbrella SIG cloud from a Cisco SD-WAN domain?

Options:

A.

L2TPv3 tunnel

B.

IPsec tunnel

C.

local umbrella agent

D.

source NAT

Question 23

Which Cisco SD-WAN WAN Edge platform supports LTE and Wi-Fi?

Options:

A.

vEdge2000

B.

ASR1001

C.

CSR 1000v

D.

ISR 1101

Question 24

Which device information is required on PNP/ZTP to support the zero-touch onboarding process?

Options:

A.

interface IP address

B.

system IP address

C.

public DNS entry

D.

serial and chassis numbers

Question 25

Which type of certificate is installed on vManage for a user to access vManage via a web browser?

Options:

A.

SD-AVC Certificate

B.

WAN Edge Certificate

C.

Controller Certificate

D.

Web Server Certificate

Question 26

An engineering team must prepare a traffic engineering policy where an MPLS circuit is preferred for traffic coming from the Admin VLAN Internet should be used as a backup only. Which configuration fulfill this requirement?

A)

Question # 26

B)

Question # 26

C)

Question # 26

D)

Question # 26

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 27

Refer to the exhibit.

Question # 27

A customer wants to implement primary and secondary Cisco SD-WAN overlay routing for prefixes that are advertised for both data centers. The east data center (TLOC 101.101.101.101) is primary for east sites, and the west data center (TLOC 100.100.100.100) is primary for west sites. Which configuration change achieves this objective?

Question # 27

Question # 27

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 28

Which protocol Is used by the REST API to communicate with network services in the Cisco SO-WAN network?

Options:

A.

SSL

B.

HTTP

C.

iPsec

D.

SSM

Question 29

Which attributes are configured to uniquely Identify and represent a TLOC route?

Options:

A.

system IP address, link color, and encapsulation

B.

firewall, IPS, and application optimization

C.

site ID, tag, and VPN

D.

origin, originator, and preference

Question 30

In the Cisco SD_WAN solution, vSmart controller is responsible for which two actions? (Choose two.)

Options:

A.

Distribute crypto key information among vEdge routers

B.

Configure and monitor vEdge routers.

C.

Authenticate and authorize vEdge routers.

D.

Distribute the IP address from DHCP server to vEdge routers.

E.

Distribute route and policy information via OMP.

Question 31

Which protocol is used to propagate multicast join requests over the Cisco SD-WAN fabric?

Options:

A.

ARP

B.

Auto-RP

C.

OMP

D.

IGMP

Question 32

Which controller is excluded from the process of checking against the authorized, allowed list?

Options:

A.

vBond

B.

PnP

C.

vSmart

D.

vManage

Question 33

A large retail organization decided to move some of the branch applications to the AWS cloud. How does the network architect extend the in-house Cisco SD-WAN branch to cloud network into AWS?

Options:

A.

Create virtual WAN Edge devices Cloud through the AWS online software store

B.

Create virtual instances of vSmart Cloud through the AWS online software store

C.

Create GRE tunnels to AWS from each branch over the Internet

D.

Install the AWS Cloud Router in the main data center and provide the connectivity from each branch

Question 34

Which two products that perform lifecycle management for virtual instances are supported by WAN Edge cloud routers? (Choose two.)

Options:

A.

OpenStack

B.

AWS

C.

VMware vCenter

D.

Azure

E.

IBM Cloud

Question 35

Refer to exhibit.

Question # 35

An engineer is troubleshooting tear down of control connections even though a valid Certificate Serial Number is entered Which two actions resolve the Issue? (Choose two)

Options:

A.

Enter a valid serial number on the controllers for a given device

B.

Remove the duplicate IP in the network.

C.

Enter a valid product ID (model) on the PNP portal

D.

Match the serial number file between the controllers

E.

Restore network reachability for the controller

Question 36

What are two benefits of installing Cisco SD-WAN controllers on cloud-hosted services? (Choose two.)

Options:

A.

utilizes well-known cloud services such as Azure. AWS. and GCP

B.

accelerates Cisco SD-WAN deployment

C.

allows integration of the WAN Edge devices In the cloud

D.

installs the controllers in two cloud regions in a primary and backup setup

E.

automatically Implements zone-based firewalling on the controllers

Question 37

Which protocol advertises WAN edge routes on the service side?

Options:

A.

EIGRP

B.

OSPF

C.

BGP

D.

ISIS

Question 38

Which two protocols are supported for software image delivery when images are hosted on a remote server? (Choose two.)

Options:

A.

HTTPS

B.

SSL

C.

HTTP

D.

TFTP

E.

FTP

Question 39

A customer is receiving routes via OMP from vSmart controller for a specific VPN. The customer must provide access to the W2 loopback received via OMP to the OSPF neighbor on the service-side VPN, which configuration fulfils these requirements?

Question # 39

Question # 39

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Question 40

Which component of the Cisco SD-WAN control plane architecture facilitates the storage of certificates and configurations for network components?

Options:

A.

vSmart

B.

vBond

C.

WAN Edge

D.

vManage

Question 41

Which timer specifies information in the cache after all OMP sessions are lost at location S0123T4E56F78?

Options:

A.

advertisement interval

B.

EOR timer

C.

graceful restart timer

D.

hold time

Question 42

In a Cisco SD-WAN architecture, what is the role of the WAN Edge?

Options:

A.

It provides orchestration to assist in automatic provisioning of WAN Edge routers and overlay

B.

It is the management plane responsible for centralized configuration and monitoring

C.

It is the control plane that builds and maintains network topology

D.

It is the data plane that is responsible for forwarding traffic

Question 43

Which port is used for vBond under controller certificates if no alternate port is configured?

Options:

A.

12345

B.

12347

C.

12346

D.

12344

Question 44

Company E wants to deploy Cisco SD-WAN with controllers in AWS The company's existing WAN is on private MPLS without Internet access to controllers m AWS An Internet circuit is added to a site in addition to the existing MPLS circuit. Which interface template establishes BFD neighbors over both transports?

A)

Question # 44

B)

Question # 44

C)

Miss

D)

Question # 44

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 45

A company must avoid downtime at the remote sites and data plane to continue forwarding traffic between WAN Edge devices if the branch router loses connectivity to its OMP peers Which configuration meets the requirement?

A)

Question # 45

B)

Question # 45

C)

Question # 45

D)

Question # 45

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 46

A company deploys a Cisco SD-WAN solution but has an unstable Internet connection. When the link to vSmart comes back up, the WAN Edge router routing table is not refreshed, and some traffic to the destination network is dropped. The headquarters is the hub site, and it continuously adds new sites to the SD-WAN network. An engineer must configure route refresh between WAN Edge and vSmart within 2 minutes. Which configuration meets this requirement?

Question # 46

Options:

A.

Option A

B.

B

C.

Option B

D.

E.

Option C

F.

Option D

Question 47

A voice packet requires a latency of 50 msec. Which policy is configured to ensure that a voice packet is always sent on the link with less than a 50 msec delay?

Options:

A.

centralized control

B.

localized data

C.

localized control

D.

centralized data

Question 48

Which encryption algorithm is used for encrypting SD-WAN data plane traffic?

Options:

A.

Triple DES

B.

IPsec

C.

AES-128

D.

AES-256 GCM

Question 49

Question # 49

Question # 49

Refer to the exhibit vManage and vBond have an issue establishing a connection with each other Which action resolves the issue?

Options:

A.

Reconfigure the system IPs to belong to the same subnet

B.

Change the organization name on both controllers to match vipteta.com.

C.

Remove the encapsulation ipsec command under the tunnel interface of vBond

D.

Configure the encapsulation ipsec command under the tunnel interface on vManage

Question 50

Question # 50

Refer to the exhibit The network team must configure ElGRP peering at HQ with devices in the service VPN connected to WAN Edge CSRv. CSRv is currently configured with

Question # 50

Which configuration on the WAN Edge meets the requiremnet

A)

Question # 50

B)

Question # 50

C)

Question # 50

D)

Question # 50

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 51

Question # 51

Refer to the exhibit. Which configuration stops Netconf CLI logging on WAN Edge devices during migration?

Question # 51

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 52

Refer to the exhibit.

Question # 52

An MPLS connection on R2 must extend to R1 Users behind R1 must have dual connectivity for data traffic Which configuration provides R1 control connectivity over the MPLS connection?

A)

Question # 52

B)

Question # 52

C)

Question # 52

D)

Question # 52

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 53

A customer must upgrade the cisco SD-WAN devices and controllers from version 19.2 to version 20.3. The devices include WAN Edge cloud, vManage, vSmart, and vBond. Which types of image types of image files are needed for this upgrade?

Options:

A.

one file for vManage and one file for all other devices with extension tar.gz

B.

one file for vManage, one for vSmart and one for vBond + WAN Edge Cloud with extension.bin

C.

one file for vManaga, one for vSmart and one for vBond + WAN Edge Cloud with extension tar.gz

D.

one file for vManaga and one file for all other devices with extension .bin

Question 54

A network administrator is bringing up one WAN Edge for branch connectivity. Which types of tunnels form when the WAN edge router connects to the SD-WAN fabric?

Options:

A.

DTLS or TLS tunnel with vBond controller and IPsec tunnel with vManage controller.

B.

DTLS or TLS tunnel with vBond controller and IPsec tunnel with other WAN Edge routers.

C.

DTLS or TLS tunnel with vSmart controller and IPsec tunnel with other Edge routers.

D.

DTLS or TLS tunnel with vSmart controller and IPsec tunnel with vBond controller.

Question 55

How many subnets are necessary in Azure VNet for a WAN Edge device to function in the cloud deployment?

Options:

A.

CSR is the WAN Edge device that is supported in the Microsoft cloud. The Microsoft underlay cloud fabric performs the management function.

B.

There must be three subnets in VNet: management, public, and services.

C.

One public subnet is required in VNet. The Microsoft underlay cloud fabric performs all of the routing functions for WAN Edge.

D.

Public and services subnets are required in VNet. The Microsoft underlay cloud fabric performs the management function.

Question 56

Which configuration step is taken on vManage after WAN Edge list is uploaded?

Options:

A.

Send the list to controllers

B.

Enable the ZTP process

C.

Verify the device certificate

D.

Set the device as valid

Question 57

Which type of route advertisement of OMP can be verified?

Options:

A.

OMP, VPN. and origin

B.

Origin, TLOC, and VPN

C.

Origin, TLOC, and service

D.

OMP, TLOC and service

Question 58

A network administrator is configuring a tunnel interface on a branch Cisco IOS XE router to run TLOC extensions. Which configuration will extend a TLOC over a GRE tunnel to another router in the branch?

Question # 58

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 59

Which protocol is used to measure jitter, loss, and latency on SD-WAN overlay tunnels?

Options:

A.

QoE

B.

OMP

C.

BGP

D.

BFD

Question 60

An engineer must avoid routing loops on the SD-WAN fabric for routes advertised between data center sites Which BGP loop prevention attribute must be configured on the routers to meet this requirement?

Options:

A.

same OMP overlay-as on WAN Edge routers of all data centers

B.

static routing on al WAN Edge routers instead of BGP

C.

same BGP AS between all WAN Edge routers and CE routers

D.

same BGP AS between all CE and PE routers

Question 61

What is the procedure to upgrade all Cisco SD-WAN devices to a recent version?

Options:

A.

The upgrade is performed for a group of WAN Edge devices first to ensure data-plabe availability when other controllers are updated.

B.

The upgrade is performed first on vManage, then on WAN Edge devices, then on vBond and finally on vSmart The reboot must start from WAN Edge devices.

C.

Upgrade and reboot are performed first on vManage then on vBond then on vSmart. and finally on the Cisco WAN Edge devices.

D.

Upgrade and reboot are performed first on vBond. then on vSmart. and finally on the Cisco WAN Edge devices.

Question 62

A network administrator configures SNMPv3 on a Cisco WAN Edge router from CLI for monitoring purposes How many characters are supported by the snmp user command?

Options:

A.

from 1 to 8

B.

from 1 to 16

C.

from 1 to 32

D.

from 1 to 48

Question 63

How is an event monitored and reported for an individual device in the overlay network at site ID:S4300T6E43F36?

Options:

A.

The device sends event notifications to vManage.

B.

The device sends notifications to vSmart that sends them to vManage.

C.

The device sends a critical alarm of events to vManage.

D.

The device sends a critical alarm to vSmart that sends it to vManage.

Question 64

Which two mechanisms are used by vManage to ensure that the certificate serial number of the WAN Edge router that is needed to authenticate is listed in the WAN Edge Authorized Señal Number Hst’ (Choose two)

Options:

A.

Synchronize to the PnP

B.

Manually upload it to vManage

C.

The devices register to vManage directly as the devices come online

D.

The vManage is shipped with the list

E.

Synchronize to the Smart Account

Question 65

How is the software managed in Cisco SD-WAN?

Options:

A.

Software images must be uploaded to vManage through HTTP or FTP

B.

Software downgrades are unsupported for vManage

C.

Software images must be transferred through VPN 512 or VPN 0 of vManage

D.

Software upgrade operation in the group must include vManage. vBond, and vSmart.

Question 66

Question # 66

Refer to the exhibit Cisco SD-WAN is deployed with controllers hosted in a data center All branches have WAN Edge devices with dual connections to the data center one via Internet and the other using MPLS Three branches out of 20 have issues with their control connections on MPLS circuit The local error refers to Control Connection Failure Which action resolves the issue*?

Options:

A.

Rectify any issues with the underlay routing configuration

B.

Match the TLOC color on the controllers and all WAN Edge devices

C.

Match certificates for the DTLS connection and Root CA must be installed first on WAN Edge devices

D.

Update the system IP on vManage and then resend it to the controllers

Question 67

Which policy configuration must be used to classify traffic as it enters the branch WAN Edge router to be put into the desired output queue?

A)

Question # 67

B)

Question # 67

C)

Question # 67

D)

Question # 67

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 68

Refer to the exhibit.

Question # 68

vManage and vSmart have an issue establishing a connection to vBond. Which configuration resolves the issue?

Options:

A.

Configure the tunnel interface on all three controllers with a color of transport.

B.

Change the timezone on the vSmart to Europe/London.

C.

Configure the (11.1.1.X/24) IP addresses on the elhO interfaces on vManage and vSmart.

D.

Reconfigure the system-ip parameter on vSmart to 11.1.1.2.

Question 69

An engineer must improve video quality by limiting HTTP traffic to the Internet without any failover. Which configuration in vManage achieves this goal?

Question # 69

Question # 69

Question # 69

Question # 69

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 70

Which protocol runs between the vSmart controllers and WAN Edge routers when the vSmart controller acts like a route reflector?

Options:

A.

OMP outside the DTLS/TLS control connection

B.

BGP inside the DTLS/TLS

C.

IPsec inside the DTLS/TLS control connection

D.

OMP inside the DTLS/TLS control connection

Question 71

Question # 71

Refer to the exhibit. The ge0/0 interface connects to a 30-MB link. A network administrator wants to always have 10 MB available for high priority traffic. When lower-priority traffic busts exceed 20 MB. Traffic should be redirected to the second WAN interface ge0/1. Which set of configurations accomplishes this task?

A)

Question # 71

B)

Question # 71

C)

Question # 71

D)

Question # 71

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 72

Which policy blocks TLOCs from remotes and allows TLOCs from the data center to form hub-and-spoke peering?

Options:

A.

localized control policy

B.

localized data policy

C.

centralized data policy

D.

centralized control policy

Question 73

Which actions must be taken to allow certain departments to require firewall protection when interacting with data center network without including other departments? (Choose two.)

Options:

A.

Use classification policing and marking

B.

Apply data policies at vEdge.

C.

Deploy a service-chained firewall service per VPN

D.

The regional hub advertises the availability of the firewall service

E.

Advertise lo vSmart controllers

Question 74

An engineer is tasked to improve throughput for connection-oriented traffic by decreasing round-trip latency. Which configuration will achieve this goal?

Options:

A.

turn on "Enable TCP Optimization"

B.

turn off "Enhance ECMP Keying"

C.

turn off "Enable TCP Optimization"

D.

turn on "Enhance ECMP Keying"

Question 75

Question # 75

Refer to the exhibit Which command allows traffic through the IPsec tunnel configured in VPN 0?

Options:

A.

service local

B.

service FW address 1.1.1.1

C.

service netsvc1 vpn 1

D.

service netsvc1 address 1.1.1.1

Question 76

In Cisco SD-WAN, what protocol is used for control connections between SD-WAN devices?

Options:

A.

DTLS

B.

OMP

C.

BGP

D.

OSPF

Question 77

Which on-the-box security feature supported by the Cisco ISR 4451 SD-WAN device and not on vEdge?

Options:

A.

Cloud Express service

B.

Enterprise Firewall with Application Awareness

C.

reverse proxy

D.

IPsec/GRE cloud proxy

Question 78

Which VPN connects the transport-side WAN Edge interface to the underlay/WAN network?

Options:

A.

VPN 1

B.

VPN 511

C.

VPN 0

D.

VPN 512

Question 79

Drag and drop the steps from the left into the order on the right to upload software on vManage repository that is accessible from maintenance > Software Repository.

Question # 79

Options:

Question 80

Which pathway under Monitor > Network > Select Device is used to verify service insertion configuration?

Options:

A.

Real Time

B.

System Status

C.

ACL Logs

D.

Events

Question 81

What is the result during a WAN Edge software upgrade process if the version of the WAN Edge software is higher than the one running on a controller device?

Options:

A.

The upgrade button is greyed out

B.

The upgrade proceeds with no warning message.

C.

The upgrade fails with a warning message

D.

The upgrade proceeds with a warning message

Question 82

Which two algorithms authenticate a user when configuring SNMPv3 monitoring on a WAN Edge router? (Choose two.)

Options:

A.

AES-256

B.

SHA-1

C.

AES-128

D.

MD5

E.

SHA-2

Question 83

The network administrator is configuring a QoS scheduling policy on traffic received from transport side tunnels on WAN Edge 5000 routers at location 406141498 Which command must be configured on these devices?

Options:

A.

cloud-qos

B.

service qos

C.

cloud-mis qos

D.

mis qos

Question 84

Which controller is used for provisioning and configuration in a Cisco SD-WAN solution?

Options:

A.

vBond

B.

Manage

C.

WAN Edge router

D.

vSmart

Question 85

Question # 85

Refer to the exhibit Which NAT types must the engineer configure for the vEdge router to bring up the data plane tunnels?

Options:

A.

Enable Full Cone NAT on the vEdge interface

B.

Use public color on the TLOC

C.

Use private color on the TLOC

D.

Enable Symmetric MAT on the vEdge interface

Question 86

A network administrator is configuring Qos on a vEdge 5000 router and needs to enable it on the transport side interface. Which policy setting must be selected to accomplish this goal?

Options:

A.

Cloud QoS Service side

B.

Cloud QoS

C.

NetFlow

D.

Application

Question 87

A network engineer must configure all branches to communicate with each other through the Service Chain Firewall located at the headquarters site. Which configuration allows the engineer to accomplish this task?

A)

Question # 87

B)

Question # 87

C)

Question # 87

D)

Question # 87

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 88

After deploying Cisco SD-WAN the company realized that by default, all sites built direct IPsec VPN tunnels to each other In their previous topology all spoke sites used the head office as their next hop for the LAN segment that belongs to network 40.0.0.0/16 The company wants to deploy its previous policy, which allows the 40.0.0.0/16 network that originates at the hub to advertise to the spokes. Which configuration meets the requirement'?

A)

Question # 88

B)

Question # 88

C)

Question # 88

D)

Question # 88

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 89

Which platform cannot provide IPS and URL filtering capabilities?

Options:

A.

Cisco CSR 1000V

B.

Cisco ISR 1000

C.

Cisco Catalyst 8300

D.

Cisco ISR 4000

Question 90

How are policies deployed on cloud-tiosted Cisco SD-WAN controllers?

Options:

A.

Policies are created on vSmart and enforced by vSmart

B.

Policies are created on vSmart and enforced by vManage

C.

Policies are created on vManage and enforced by vManage.

D.

Policies are created on vManage and enforced by vSman

Question 91

Which pathway under Monitor > Network > Select Device is used to verify service insertion configuration?

Options:

A.

System Status

B.

Troubleshooting

C.

Real Time

D.

Events

Question 92

What are two attributes of vRoute? (Choose two)

Options:

A.

originator

B.

service

C.

encapsulation

D.

carrier

E.

domain ID

Question 93

An engineer is configuring a data policy for packets that must be captured through the policy. Which command accomplishes this task?

Options:

A.

policy > data-policy > vpn-list > sequence > default-action > drop

B.

policy > data-policy > vpn-list > sequence > action

C.

policy > data-policy > vpn-list > sequence > default-action > accept

D.

policy > data-policy > vpn-list > sequence > match

Question 94

Which API call retrieves a list of all devices in the network?

Options:

A.

https://vmanage_IP_address/dataservice/system/device/{{model}}

B.

http://vmanage_IP_address/dataservice/system/device/{{model}}

C.

http://vmanage_IP_address/api-call/system/device/{{model}}

D.

https://vmanage_IP_address/api-call/system/device/{{model}}

Question 95

Which two platforms for the Cisco SD-WAN architecture are deployable in a hypervisor on-premises or in IAAS Cloud? (Choose two.)

Options:

A.

CSR 1000v

B.

vEdge 100c

C.

vEdge Cloud

D.

vEdge 2000

E.

ISR 4431

Question 96

In which device state does the WAN edge router create control connections, but data tunnels are not created?

Options:

A.

valid

B.

backup

C.

active

D.

staging

Question 97

An administrator must configure an ACL for traffic coming in from the service-side VPN on a specific WAN device with circuit ID 391897770. Which policy must be used to configure this ACL?

Options:

A.

local data policy

B.

central data policy

C.

app-aware policy

D.

central control policy

Question 98

An enterprise has several sites with multiple VPNs that are isolated from each other A new requirement came where users in VPN 73 must be able to talk to users in VPN 50 Which configuration meets this requirement?

Question # 98

Question # 98

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 99

Question # 99

Refer to the exhibit. The network administrator has configured a centralized topology policy that results in the displayed routing table at a branch office. Which two configurations are verified by the output? [Choose two.)

Options:

A.

The routing table is for the transport VPN.

B.

The default route is learned via OMP.

C.

This routing table is from a cEdge router.

D.

The default route is configured locally.

E.

The configured policy is adding a route tag of 300 to learned routes.

Question 100

An engineer is configuring a list that matches all IP prefixes with lengths from /1 to /16 in a centralized control policy. Which list accomplishes this task?

Options:

A.

0.0.0.0/1 le 16

B.

0.0.0.0/0 ge 1

C.

0.0.0.0/0 le l6

D.

0.0.0.0/16 ge 1

Question 101

Which destination UDP port is used by WAN Edge router to make a DTLS connection with vBond Orchestrator?

Options:

A.

12343

B.

12345

C.

12346

D.

12347

Question 102

An enterprise has these three WAN connections:

  • public Internet
  • business internet
  • MPLS

An engineer must configure two available links to route traffic via both links. Which configuration achieves this objective?

Question # 102

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Question 103

Refer to the exhibit.

Question # 103

An engineer is configuring service chaining. Which set of configurations is required for all traffic from Site ID 1 going toward Site ID 2 to get filtered through the firewall on the hub site?

A)

Question # 103

B)

Question # 103

C)

Question # 103

D)

Question # 103

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 104

Question # 104

Refer to the exhibit. The Cisco SD-VYAN is deployed using the default topology. The engineer v/ants to configure a service insertion policy such that all data traffic between Rome to Paris is forwarded through the NGFW located in London. Which configuration fulfills this requirement, assuming that the Sen/ice VPN ID is 1?

A)

Question # 104

B)

Question # 104

C)

Question # 104

D)

Question # 104

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 105

Question # 105

Refer to the exhibit A WAN Edge device was recently added to vManage but a control connection could not be established Which action resolves this issue?

Options:

A.

Rectify the Rod CA certificate mismatch on WAN Edge devices

B.

Install the bootstrap code on WAN Edge and check for CSR

C.

Send the serial number to vBond from the vManage controller.

D.

Resolve the ZTP reachability and rectify smart account credentials issue

Question 106

Which secure tunnel type should be used to connect one WAN Edge router to other WAN Edge routers?

Options:

A.

TLS

B.

DTLS

C.

SSL VPN

D.

IPsec

Question 107

A network administrator is configuring VRRP to avoid a traffic black hole when the transport side of the network is down on the master device. What must be configured to get the fastest failover to standby?

Options:

A.

lower timer interval

B.

prefix-list tracking

C.

higher group ID number

D.

OMP tracking

Page: 1 / 36
Total 359 questions