Big Halloween Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Cisco 300-415 Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Exam Practice Test

Page: 1 / 44
Total 441 questions

Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Questions and Answers

Question 1

Question # 1

Refer to the exhibit. An engineer is troubleshooting a control connection issue on a WAN Edge device that shows socket errors. The packet capture shows some ICMP packets dropped between the two devices. Which action resolves the issue?

Options:

A.

Recover the vManage controller that is down m a high availability cluster

B.

Change the system IP or restart the VWN Edge 4 the system IP is changed

C.

Remove IP duplication in the network and configure a unique IP address

D.

Recover vBond or wart for the controller to reload which could be caused by a reset

Question 2

Which protocol is configured on tunnels by default to detect loss, latency, jitter, and path failures in Cisco SD-WAN?

Options:

A.

TLS

B.

BFD

C.

OMP

D.

BGP

Question 3

What are the two advantages of deploying cloud-based Cisco SD-WAN controllers? (Choose two.)

Options:

A.

centralized control and data plane

B.

distributed authentication policies

C.

management of SLA

D.

infrastructure as a service

E.

centralized raid storage of data

Question 4

Question # 4

Refer to the exhibit. An engineer configures a hub-and-spoke SD-WAN topology with the requirement that traffic from router A branch to router B branch is guaranteed to flow through the network hub, router C. Which configuration meets the requirement for router A?

Question # 4

Question # 4

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 5

An engineer is configuring the branch office with a 172.16.0.0/16 subnet to use DIA for Internet traffic. All other traffic must flow to the central site or branches using the MPLS circuit Which configuration meets the requirement?

A)

Question # 5

B)

Question # 5

C)

Question # 5

D)

Question # 5

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 6

How many vManage NMSs should be installed in each domain to achieve scalability and redundancy?

Options:

A.

two instances

B.

two clusters

C.

three or more in a cluster

D.

two or more in a cluster

Question 7

Drag and drop the route verification output from show omp tlocs from the left onto the correct explanations on the right.

Question # 7

Options:

Question 8

In a Cisco SD-WAN network, which component is responsible for distributing route and policy information via the OMP?

Options:

A.

vManage

B.

vSmart Controler

C.

vBond Orchestrator

D.

WAN Edge Router

Question 9

Question # 9

Refer to the exhibit. An administrator is configuring a policy in addition to an existing hub-and-spoke policy for two sites that should directly communicate with each other. How is this policy configured?

Options:

A.

hub-and-spoke

B.

mesh

C.

import existing topology

D.

custom control (route and TLOC)

Question 10

Which component is used for stateful inspection of TCP, UDP. and ICMP flows in Cisco SD-WAN firewall policies?

Options:

A.

zones

B.

sites

C.

subnets

D.

interfaces

Question 11

An engineer must configure egress QoS for voice traffic. Which queue must the engineer configure on the WAN Edge router to accomplish the task?

Options:

A.

queue 0

B.

queue 1

C.

queue 3

D.

queue 7

Question 12

Which feature builds transport redundancy by using the cross link between two redundant WAN Edge routers?

Options:

A.

OMP

B.

zero-touch provisioning

C.

quality of service

D.

TLOC extension

Question 13

Which configuration change allows direct internet access at the branch site for YouTube traffic?

Question # 13

Question # 13

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 14

What are the two functions of vSmart? (Choose two)

Options:

A.

It orchestrates connectivity between WAN Edge routers using policies to create network topology

B.

It ensures that valid WAN Edge routers can build the control pane connectivity

C.

It uses TLOCs to uniquely identify the circuit interface to control plane and data plane information

D.

It validates that the WAN Edge trying to join the overlay is authorized to join.

E.

It builds control plane connections with WAN Edge routers using ILS or UILS

Question 15

Which two performance data details are provided by Cisco SO-WAN vAnalytics? (Choose two)

Options:

A.

jitter loss and latency for data tunnels

B.

application quality of experience score from zero to ten

C.

detail on total cost of ownership for the fabric

D.

certificate authority status (health and expiration dates) for all controllers

E.

view devices connected to a vManage NMS

Question 16

Which value of the IPsec rekey timer must be set by the engineer for an OMP graceful restart value set for 24 hours?

Options:

A.

6 hours

B.

12 hours

C.

36 hours

D.

48 hours

Question 17

Which type of route represents prefixes received from a local site via an SD-WAN Edge router in a Cisco SD-WAN architecture?

Options:

A.

TLOC routes

B.

Service routes

C.

Multicast routes

D.

vRoutes

Question 18

The SD-WAN network is configured ­­­with a default full-mesh topology. The SD-WAN engineer wants the Barcelona WAN Edge to use the MPLS TLOC when forwarding Telnet traffic based on a configured SLA class list. Which configured must the engineer use to create a policy to call the SLA class and set the preferred color to MPLS?

A)

Question # 18

B)

Question # 18

C)

Question # 18

D)

Question # 18

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 19

How is multicast routing enabled on devices in the Cisco SD-WAN overlay network?

Options:

A.

The WAN Edge routers originate multicast service routes to the vSmart controller via OMP, which then forwards joins for requested multicast groups based on IGMP v1 or v2 toward the source or PIM-RP as specified m the original PIM join message.

B.

The vSmart controller originates multicast service routes to the WAN Edge routers via OMP, which then forwards joins for requested multicast groups cased on IGMP v1 or v2 toward the source or PlM-RP as specified m the original PIM join message

C.

The vSmart controller originates multicast service routes to the WAN Edge routers via OMP, which then forwards joins (or requested multicast groups based on IGMP v2 or v3 toward the source or PIM-RP as specified in the original PIM join message

D.

The WAN Edge routers originate multicast service routes to the vSmart controller via OMP. which then forwards joins for requested multicast groups based on iGMP v2 or v3 toward the source or PIM-RP as specified in the original PIM join message

Question 20

Question # 20

Refer to the exhibit A user has selected the options while configuring a VPN Interface Ethernet feature template What is the required configuration parameter the user must set in this template for this feature to function?

Options:

A.

The "IP MTU" field must be increased from the default value of 1500 to support the additional overhead.

B.

The "Shaping Rate (Kbps)" field must be configured with a value

C.

The "Adaptive QoS" field must be set to "on"

D.

The "Bandwidth Downstream" field must be configured with a value

Question 21

Which OMP route is selected for equal OMP route preference values on WAN Edge routers?

Options:

A.

route with higher TLOC preference value

B.

route with origin type of connected

C.

route with origin type of static

D.

route with lower TLOC preference value

Question 22

Which two protocols are supported for software image delivery when images are hosted on a remote server? (Choose two.)

Options:

A.

HTTPS

B.

SSL

C.

HTTP

D.

TFTP

E.

FTP

Question 23

An enterprise has these three WAN connections:

public Internet

business internet

MPLS

An engineer must configure two available links to route traffic via both links. Which configuration achieves this objective?

Question # 23

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Question 24

Which TCP Optimization feature is used by WAN Edge to prevent unnecessary retransmissions and large initial TCP window sizes to maximize throughput and achieve a better quality?

Options:

A.

SEQ

B.

SYN

C.

RTT

D.

SACK

Question 25

An enterprise is continuously adding new sites to its Cisco SD-WAN network. It must configure any cached routes flushed when OMP peers have lost adjacency Which configuration allows the cached OMP routes to be flushed after every 24 hours from its routing table?

Question # 25

Question # 25

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 26

What is a key element used in a vBond Orchestrator redundancy topology?

Options:

A.

fully qualified domain name

B.

DHCP server

C.

load-balancer with health probes

D.

stun server

Question 27

Which service VPN must be reachable from all WAN Edge devices and the controllers?

Options:

A.

VPN0

B.

VPN10

C.

VPN215

D.

VPN512

Question 28

Question # 28

Refer to the exhibit. A customer wants to deploy service insertion at site1. Which traffic from VPN 10 must route to this site through a firewall. A policy must be in place to route VPN 10 traffic from all sites toward this firewall. Which configuration must be on the vSmart controller to meet this requirement?

Options:

A.

B.

C.

D.

Question 29

Question # 29

Refer to the exhibit. A network administrator is configuring OSPF advanced configuration parameters from a template using the vManager GUI for a branch WAN Edge router to calculate the cost of summary routes to an ASBR. Which action achieves this configuration?

Options:

A.

Enable Originate.

B.

Disable Originate.

C.

Enable RFC 1583 Compatible.

D.

Disable RFC 1583 Compatible.

Question 30

Question # 30

An engineer is creating a policy for VPN1 users. Their scavenger traffic at site 101 must pass through a firewall. Which two match conditions must be selected to enable this policy? (Choose two.)

Options:

A.

destination port

B.

source data prefix

C.

packet length

D.

protocol

E.

application/application family list

Question 31

Which statement describes the requirement of integrating a secure internet gateway (SIG) with a Cisco SD-WAN Edge device?

Options:

A.

Attached to SIG tunnels, trackers monitor the respective SIG endpoints.

B.

Credentials for a smart account are required.

C.

A Cisco umbrella organization ID is needed to establish the SIG.

D.

Based on routing or policy, all customer internet traffic must be forwarded to the SIG.

Question 32

Drag and drop the security terminologies from the left onto the PCI-compliant network features and devices on the right.

Question # 32

Options:

Question 33

Refer to the exhibit.

Question # 33

A network administrator is configuring OMP in vManage to advertise all the paths for the same prefix from a site that has two WAN Edge devices Each WAN Edge device is connected to three ISPs and two private MPLS transports. What is the minimum value for 'Number of Paths advertised per Prefix" that should be configured?

Options:

A.

2

B.

3

C.

5

D.

10

Question 34

Which table is used by the vSmart controller to maintain service routes of the WAN Edge routers in the hub and local branches?

Options:

A.

RIB

B.

FIB

C.

OMP

D.

TLOC

Question 35

How does the Cisco SD-WAN Cloud OnRamp solution rate the performance of a SaaS application from a branch office to the cloud via a given path?

Options:

A.

It computes a quality-of-experience score.

B.

It monitors the packet loss of priority queues.

C.

It counts the number of interface errors.

D.

It measures the delay and jitter of the path.

Question 36

Which two products that perform lifecycle management for virtual instances are supported by WAN Edge cloud routers? (Choose two.)

Options:

A.

OpenStack

B.

AWS

C.

VMware vCenter

D.

Azure

E.

IBM Cloud

Question 37

An engineer must deploy a QoS policy with these requirements:

• policy name: App-police

• police rate: 1000000

• burst: 1000000

• exceed: drop

Which configuration meets the requirements?

Question # 37

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 38

Which device information is required on PNP/ZTP to support the zero-touch onboarding process?

Options:

A.

interface IP address

B.

system IP address

C.

public DNS entry

D.

serial and chassis numbers

Question 39

Drag and drop the Cisco SD-WAN components from the left onto their functions on the right.

Question # 39

Options:

Question 40

An engineer wants to change the configuration of the certificate authorization mode from manual to automated. Which GUI selection will accomplish this?

Options:

A.

Maintenance > Security

B.

Configuration > Certificates

C.

Administration > Settings

D.

Tools > Operational Commands

Question 41

How many subnets are necessary in Azure VNet for a WAN Edge device to function in the cloud deployment?

Options:

A.

CSR is the WAN Edge device that is supported in the Microsoft cloud. The Microsoft underlay cloud fabric performs the management function.

B.

There must be three subnets in VNet: management, public, and services.

C.

One public subnet is required in VNet. The Microsoft underlay cloud fabric performs all of the routing functions for WAN Edge.

D.

Public and services subnets are required in VNet. The Microsoft underlay cloud fabric performs the management function.

Question 42

Question # 42

Refer to the exhibit Cisco SD-WAN is deployed with controllers hosted in a data center All branches have WAN Edge devices with dual connections to the data center one via Internet and the other using MPLS Three branches out of 20 have issues with their control connections on MPLS circuit The local error refers to Control Connection Failure Which action resolves the issue*?

Options:

A.

Rectify any issues with the underlay routing configuration

B.

Match the TLOC color on the controllers and all WAN Edge devices

C.

Match certificates for the DTLS connection and Root CA must be installed first on WAN Edge devices

D.

Update the system IP on vManage and then resend it to the controllers

Question 43

What is the minimum Red Hat Enterprise Linux operating system requirement for a Cisco SD-WAN controller deployment via KVM?

Options:

A.

RHEL7.5

B.

RHEL 6.5

C.

RHEL4.4

D.

RHEL 6.7

Question 44

Drag and drop the alarm slates from the left onto the corresponding alarm descriptions on the right.

Question # 44

Options:

Question 45

Which Cloud OnRamp solution is used by partners and vendors without Cisco SD-WAN but still needs connectivity to their customers without installing SD-WAN routing appliances on their sites?

Options:

A.

Cloud OnRamp for IaaS

B.

Cloud OnRamp for SaaS

C.

Cloud OnRamp for Multicloud

D.

Cloud OnRamp for Colocation

Question 46

Which Cisco SD-WAN WAN Edge platform supports LTE and Wi-Fi?

Options:

A.

vEdge2000

B.

ASR1001

C.

CSR 1000v

D.

ISR 1101

Question 47

What is a restriction when configuring a tunnel interface?

Options:

A.

Up to six tunnel interfaces are configurable on a vSmart.

B.

it is manually assigned when using vWanage feature template.

C.

It must be configured for the interface under aft VPNs

D.

Up to six tunnel interfaces are configurable on a WAN Edge

Question 48

An engineer is tasked to improve throughput for connection-oriented traffic by decreasing round-trip latency. Which configuration will achieve this goal?

Options:

A.

turn on "Enable TCP Optimization"

B.

turn off "Enhance ECMP Keying"

C.

turn off "Enable TCP Optimization"

D.

turn on "Enhance ECMP Keying"

Question 49

Which protocol runs between the vSmart controllers and WAN Edge routers when the vSmart controller acts like a route reflector?

Options:

A.

OMP outside the DTLS/TLS control connection

B.

BGP inside the DTLS/TLS

C.

IPsec inside the DTLS/TLS control connection

D.

OMP inside the DTLS/TLS control connection

Question 50

An engineer configures an application-aware routing policy for a group of sites The locations depend on public and private transports The policy does not work as expected when one of the transports does not perform properly This policy is configured:

Question # 50

which configuration completes the policy so that it works for all locations?

A)

Question # 50

B)

Question # 50

C)

Question # 50

D)

Question # 50

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 51

Question # 51

Refer to the exhibit. The Cisco SD-VYAN is deployed using the default topology. The engineer v/ants to configure a service insertion policy such that all data traffic between Rome to Paris is forwarded through the NGFW located in London. Which configuration fulfills this requirement, assuming that the Sen/ice VPN ID is 1?

A)

Question # 51

B)

Question # 51

C)

Question # 51

D)

Question # 51

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 52

An enterprise deployed a Cisco SD-WAN solution with hub-and-spoke topology using MPLS as the preferred network over the Internet. A network engineer must implement an application-aware routing policy to allow ICMP traffic to be load-balanced over both the available links. Which configuration meets the requirement?

A)

Question # 52

B)

Question # 52

C)

Question # 52

D)

Question # 52

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 53

What does forward error correction addresses in Cisco SO-WAN?

Options:

A.

inefficient traffic forwarding caused oy inbound shapers

B.

reduced application performance degradation rotated to service degradation

C.

applications with occasional invalid data input and poor performance

D.

traffic flows with increased delay over a particular transport

Question 54

What are two benefits of installing Cisco SD-WAN controllers on cloud-hosted services? (Choose two.)

Options:

A.

utilizes well-known cloud services such as Azure. AWS. and GCP

B.

accelerates Cisco SD-WAN deployment

C.

allows integration of the WAN Edge devices In the cloud

D.

installs the controllers in two cloud regions in a primary and backup setup

E.

automatically Implements zone-based firewalling on the controllers

Question 55

Which device should be configured with the service chain IP address to route intersite traffic through a firewall?

Options:

A.

vSmart

B.

firewall

C.

spoke WAN Edge

D.

hub WAREdge

Question 56

An engineer must configure the SD-WAN Edge router to identify DSCP 26 traffic coming from the router's local site and then change the DSCP value to DSCP 18 before sending it over to the SD-WAN fabric. What are the two ways to create the required configuration? (Choose two).

Question # 56

Question # 56

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Question 57

Question # 57

Refer to the exhibit. An engineer must configure the Overlay Management Protocol route preference so that when B2 tries to reach host routes advertised by B1 it always chooses the MPLS circuit. Which two match conditions must be configured to accomplish this task? (Choose two.)

Options:

A.

VPN

B.

prefix list

C.

originator

D.

color list

E.

path type

Question 58

An engineer must configure two branch WAN Edge devices where an Internet connection is available and the controllers are in the headquarters. The requirement is to have IPsec VPN tunnels established between the same colors. Which configuration meets the requirement on both WAN Edge devices?

Question # 58

Question # 58

Question # 58

Question # 58

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 59

What is the default value for the number of paths advertised per prefix in the OMP feature template?

Options:

A.

4

B.

8

C.

12

D.

16

Question 60

When software is upgraded on a vManage NMS, which two image-adding options store images in a local vManage software repository? (Choose two.)

Options:

A.

To be downloaded over a SMTP connection

B.

To be downloaded over a SNMP connection

C.

To be downloaded over an out-of-band connection

D.

To be downloaded over a control plane connection

E.

To be downloaded over an ICMP connection

Question 61

Question # 61

Refer to the exhibit Which NAT types must the engineer configure for the vEdge router to bring up the data plane tunnels?

Options:

A.

Enable Full Cone NAT on the vEdge interface

B.

Use public color on the TLOC

C.

Use private color on the TLOC

D.

Enable Symmetric MAT on the vEdge interface

Question 62

A company must avoid downtime at the remote sites and data plane to continue forwarding traffic between WAN Edge devices if the branch router loses connectivity to its OMP peers Which configuration meets the requirement?

A)

Question # 62

B)

Question # 62

C)

Question # 62

D)

Question # 62

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 63

A customer wants to use AWS for Cisco SD-WAN laaS services by deploying virtual SD-WAN routers in a transit AWS VPC The transit VPC then connects via site-to-site IPsec tunnels to an AWS transit gateway Which transit VPC connects via site-to-site IPsec tunnels to an AWS transit gateway?

Options:

A.

Cisco Cloud onRamp for Multicloud

B.

Cisco Cloud onRamp for SaaS

C.

Cisco Cloud onRamp for Colocation

D.

Cisco Cloud onRamp for laaS

Question 64

Which plane builds and maintains the network topology and makes decisions on traffic flows?

Options:

A.

orchestration

B.

management

C.

control

D.

data

Question 65

Refer to the exhibit.

Question # 65

What does the BFD value of 8 represent?

Options:

A.

number of BFD sessions

B.

hello timer of BFD session

C.

poll-interval of BFD session.

D.

dead timer of BFD session

Question 66

Which two features does the application firewall provide? (Choose two.)

Options:

A.

classification of 1400+ layer 7 applications

B.

blocks traffic by application or application-family

C.

numbered sequences of match-action pairs

D.

classification of 1000+ layer 4 applications

E.

application match parameters

Question 67

Which Cisco SD-WAN feature propagates packets with SGTs through the network?

Options:

A.

TrustSec Inline Tagging

B.

SGT Enforcement

C.

QoE

D.

SXP

Question 68

Refer to the exhibit.

Question # 68

vManage and vSmart have an issue establishing a connection to vBond. Which configuration resolves the issue?

Options:

A.

Configure the tunnel interface on all three controllers with a color of transport.

B.

Change the timezone on the vSmart to Europe/London.

C.

Configure the (11.1.1.X/24) IP addresses on the elhO interfaces on vManage and vSmart.

D.

Reconfigure the system-ip parameter on vSmart to 11.1.1.2.

Question 69

Which encryption algorithm is used for encrypting SD-WAN data plane traffic?

Options:

A.

Triple DES

B.

IPsec

C.

AES-128

D.

AES-256 GCM

Question 70

A company is using Catalyst SD-WAN Manager as its root certificate authority server and must generate a root certificate using the vShell (Linux) built into the CLI of Catalyst SD-WAN Manager. Which command must be issued to generate the root certificate?

Options:

A.

openssl req -x509 -new-nodes -key XYZ.pem -sha256 -days 365 \subj "/C=US/ST=DC/L=DC/O=Cisco/CN=device.lab"-out ABC.key

B.

openssl genrsa -out ROOTCA.pem 2048

C.

openssl req -x509 -new-nodes -key XYZ.key -sha256 -days 365 Isubj "/C-US/ST-DC/L-DC/O-Cisco/CN-device.lab" 1-out ABC.pem

D.

openssl genrsa -out ROOTCA.key 2048

Question 71

An engineer builds a three-node vManage cluster and then realizes that multiple nodes are unnecessary for the size of the company. How should the engineer revert the setup to a single vManage?

Options:

A.

Remove two rode from the three-node vManage duster

B.

Use the cluster conversion utility lo convert to standalone vManage

C.

Restore vManage from the backup VM snapshot

D.

Leave the duller as & and point to one vManage

Question 72

Question # 72

Refer to the exhibit. An ongineer configured OMP with an ovorlay-as of 10666. What is tho AS-PATH for prefix 104.104.104.104/32 on R1007?

Options:

A.

100 10666 104

B.

100 10666

C.

100 10666 20 104

D.

100 20 104

Question 73

Which timer specifies information in the cache after all OMP sessions are lost at location S0123T4E56F78?

Options:

A.

advertisement interval

B.

EOR timer

C.

graceful restart timer

D.

hold time

Question 74

What is the main purpose of using TLOC extensions in WAN Edge router configuration?

Options:

A.

creates hardware-level transport redundancy at the local site

B.

creates an IPsec tunnel from WAN Edge to vBond Orchestrator

C.

transports control traffic to a redundant vSmart Controller

D.

transports control traffic w remote-site WAN Edge routers

Question 75

Drag and drop the components from the left onto the corresponding Cisco NFV infrastructure Building Blocks on the right. Not all options are used.

Question # 75

Options:

Question 76

Which two criteria ate supported to filter traffic on a Cisco Umbrella Cloud-delivered firewall? (Choose two )

Options:

A.

tunnels

B.

site ID

C.

URL

D.

geolocation

E.

protocol

Question 77

Exhibit.

Question # 77

The SD-WAN network is configured with a default full-mash topology. An engineer wants Barcelona and Paris to communicate to each other through the London site using a control Which control policy configuration accomplishes the task?

A)

Question # 77

B)

Question # 77

C)

Question # 77

D)

Question # 77

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 78

Which SD-WAN devices require multicast PIM and IGMP configurations when setting up SD-WAN multicast?

Options:

A.

branch devices with multicast receivers

B.

branch devices with unicast traffic

C.

data center replicator devices

D.

data center devices with multicast sources

Question 79

An engineer is configuring a data policy for packets that must be captured through the policy. Which command accomplishes this task?

Options:

A.

policy > data-policy > vpn-list > sequence > default-action > drop

B.

policy > data-policy > vpn-list > sequence > action

C.

policy > data-policy > vpn-list > sequence > default-action > accept

D.

policy > data-policy > vpn-list > sequence > match

Question 80

An engineer is configuring a data policy for IPv4 prefixes for a single WAN Edge device on a site with multiple WAN Edge devices How is this policy added using the policy configuration wizard?

Options:

A.

ln vManage NMS, select the configure ► policies screen, select the localized policy tab and click add policy

B.

In vSmart controller, select the configure ► policies screen, select the localized policy tab. and click add policy

C.

In vManage NMS. select the configure ► policies screen select the centralized policy tab and click add policy

D.

In vBond orchestrator. select the configure ► policies screen, select the localized policy tab. and click add policy

Question 81

Refer to the exhibit.

Question # 81

The control connection is failing. Which action resolves the issue?

Options:

A.

import vSmart in vManager

B.

Validate the certificates authenticity on vSmart

C.

Upload the WAN Edge list on vManage.

D.

Restore the reachability to the vSmart

Question 82

Which platform is a Cisco SD-WAN virtual platform?

Options:

A.

Cisco ISR 4000

B.

Cisco Nexus 1000V

C.

Cisco CSR 1000V

D.

Cisco ASR 1000

Question 83

Which two hardware platforms support Cisco IOS XE SD-WAN images'' (Choose two)

Options:

A.

ASR1000 series

B.

ISR9300 series

C.

vEdge-1000 series

D.

ASR9000 series

E.

ISR4000 series

Question 84

Question # 84

Refer to the exhibit. Which issue is shown, and which action must an engineer take to resolve the issue?

Options:

A.

An IPsec issue; verify and resolve the tunnel configurations on devices.

B.

An organization name issue; verify and correct the configuration on the devices.

C.

A certificate issue; verify and correct the certificate attributes.

D.

A connectivity issue; verify and resolve the reachability to the controller.

Question 85

Which protocol is used to measure loss latency, Jitter, and liveliness of the tunnel between WAN Edge router peers?

Options:

A.

OMP

B.

IP SLA

C.

NetFlow

D.

BFD

Question 86

A network engineer must configure all branches to communicate with each other through the Service Chain Firewall located at the headquarters site. Which configuration allows the engineer to accomplish this task?

A)

Question # 86

B)

Question # 86

C)

Question # 86

D)

Question # 86

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 87

Which SD-WAN component is configured to enforce a policy to redirect branch-to-branch traffic toward a network service such as a firewall or IPS?

Options:

A.

vBond

B.

WAN Edge

C.

vSmart

D.

Firewall

Question 88

In Cisco SD-WAN, what protocol is used for control connections between SD-WAN devices?

Options:

A.

DTLS

B.

OMP

C.

BGP

D.

OSPF

Question 89

Which component of the Cisco SD-WAN secure extensible network provides a single pane of glass approach to network monitoring and configuration?

Options:

A.

APIC-EM

B.

vSmart

C.

vManage

D.

vBond

Question 90

Question # 90

Refer to the exhibit An engineer must configure a QoS policy between me hub and site A (spoke) over a standard internet circuit where traffic shaping is adjusted automatically based on evaiiabk» bandwidth Which configuration meets the requirement?

Question # 90

Question # 90

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 91

An engineer is configuring a WAN Edge router for DIA based on matching QoS parameters. Which two actions accomplish this task? (Choose two.)

Options:

A.

Apply a QoS map policy.

B.

Configure a control policy.

C.

Configure a centralized data policy.

D.

Configure NAT on the transport interface.

E.

Apply a data policy on WAN interface.

Question 92

Which capability does Cisco SD-WAN Multi-Region Fabric provide?

Options:

A.

end-to-end SLA-aware routing

B.

overlay support for IP multicast

C.

end-to-end encryption for inter-region traffic

D.

assignment of a single vSmart controller to handle region 0 and noncore regions

Question 93

Which protocol is used to propagate multicast join requests over the Cisco SD-WAN fabric?

Options:

A.

ARP

B.

Auto-RP

C.

OMP

D.

IGMP

Question 94

Which API call retrieves a list of all devices in the network?

Options:

A.

https://vmanage_IP_address/dataservice/system/device/{{model}}

B.

http://vmanage_IP_address/dataservice/system/device/{{model}}

C.

http://vmanage_IP_address/api-call/system/device/{{model}}

D.

https://vmanage_IP_address/api-call/system/device/{{model}}

Question 95

Which two algorithms authenticate a user when configuring SNMPv3 monitoring on a WAN Edge router? (Choose two.)

Options:

A.

AES-256

B.

SHA-1

C.

AES-128

D.

MD5

E.

SHA-2

Question 96

Which value is verified in the certificates to confirm the identity of the physical WAN Edge device?

Options:

A.

Serial Number

B.

OTP

C.

System-IP

D.

Chassis-ID

Question 97

What are the two impacts of losing vManage connectivity to fabric in the Cisco SD-WAN network? (Choose two)

Options:

A.

Policy changes propagation stops

B.

Statistics collection stops

C.

BFD peering between WAN Edge devices are unestablished

D.

Creation of templates is impossible

E.

IPsec tunnels tear down for WAN Edge devices.

Question 98

Which third-party Enterprise CA server must be used (or a cloud-based vSmart controller?

Options:

A.

RootCert

B.

Microsoft

C.

RADIUS

D.

VeriSign

Question 99

An administrator must configure an ACL for traffic coming in from the service-side VPN on a specific WAN device with circuit ID 391897770. Which policy must be used to configure this ACL?

Options:

A.

local data policy

B.

central data policy

C.

app-aware policy

D.

central control policy

Question 100

Which policy configuration must be used to classify traffic as it enters the branch WAN Edge router to be put into the desired output queue?

A)

Question # 100

B)

Question # 100

C)

Question # 100

D)

Question # 100

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 101

Which issue triggers the Cisco Umbrella resolver to toward DNS requests to the intelligent proxy?

Which issue triggers the Cisco Umbrella resolver to toward DNS requests to the intelligent proxy?

Options:

A.

A domain is nonexistent.

B.

A domain is block-listed.

C.

A domain is locally reachable.

D.

A domain is grey-listed.

Question 102

Two sites have one WAN Edge each WAN Edge has two public TLOCs with no restriction configured. There is full reachability between the TLOCs. How many data tunnels are formed on each Edge router?

Options:

A.

2

B.

8

C.

6

D.

4

Question 103

WAN Edge routers are configured manually to use UDP port offset to use nondefault offset values when IPsec tunnels are created. What is the offse range?

Options:

A.

1-19

B.

0-18

C.

0-19

D.

1-18

Question 104

Which command verifies a policy that has been pushed to the vEdge router?

Options:

A.

vEdge# show running-config data policy

B.

vEdge# show policy from-vsmart

C.

vSmart# show running-config policy

D.

vSmart# show running-config apply-policy

Question 105

Drag and drop the alarm states from the left onto the corresponding alarm descriptions on the right.

Question # 105

Options:

Question 106

An engineer must improve video quality by limiting HTTP traffic to the Internet without any failover. Which configuration in vManage achieves this goal?

Question # 106

Question # 106

Question # 106

Question # 106

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 107

Question # 107

Refer to the exhibit. A network administrator is configuring OSPF advanced configuration pararmeters from a template using the vManager GUI for a branch WAN Edge router to calculate the cost of summary routes to an ASBR. Which action achieves this configuration?

Options:

A.

Disable RFC 1583 Compatiblt

B.

Enable Originate

C.

Enable RFC 1M3 Compatible

D.

Disable Original

Question 108

What must an engineer conewef when decoying an SD-WAN on-pfemlses architecture based on ESXi hypervisor?

Options:

A.

Cisco must provision the backup and snapshots platform lor ihe SD-WAN arctoecture

B.

The managed service provider must provision controllars with their appropriate cerHwcatsi

C.

The IT team a required to provision the SO-WAN controllers and Is responsAte lor backups and disaster recovery implementation

D.

The IT team will be given access by Cisco to a vManage for configuration If templates and policies coeigmalim

Question 109

An enterprise has several sites with multiple VPNs that are isolated from each other A new requirement came where users in VPN 73 must be able to talk to users in VPN 50 Which configuration meets this requirement?

Question # 109

Question # 109

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 110

Which template configures the out-of-band management VPN?

A)

Question # 110

B)

Question # 110

C)

Question # 110

D)

Question # 110

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 111

An engineer is adding a tenant with location JD 306432373 in vManage. What is the maximum number of alphanumeric characters that are accepted in the tenant name field?

Options:

A.

64

B.

128

C.

256

D.

8

Question 112

An engineer must advertise OSPF-learned routes and modify the update interval for route filtering by TLOC color to 300 on an SD-WAN device. Which configuration accomplishes this

task?

Question # 112

Question # 112

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 113

Question # 113

Refer to the exhibit. The Cisco SD-WAN is deployed using the default topology. The engineer wants to configure a service insertion policy such that all data traffic between Rome to Paris is forwarded through the NGFW located in London. Which configuration fulfills this requirement, assuming that the Service VPN ID is 1?

Options:

A.

Option A113

B.

Option B113

C.

Option C113

D.

Option D113

Question 114

Which secure connection should be used to access the REST APIs through the Cisco vManage web server?

Options:

A.

HTTP inspector interface

B.

authenticated HTTPS

C.

authenticated DTLS

D.

JSON Inspector interface

Question 115

The network administrator is configuring a QoS scheduling policy on traffic received from transport side tunnels on WAN Edge 5000 routers at location 406141498 Which command must be configured on these devices?

Options:

A.

cloud-qos

B.

service qos

C.

cloud-mis qos

D.

mis qos

Question 116

Which actions must be taken to allow certain departments to require firewall protection when interacting with data center network without including other departments? (Choose two.)

Options:

A.

Use classification policing and marking

B.

Apply data policies at vEdge.

C.

Deploy a service-chained firewall service per VPN

D.

The regional hub advertises the availability of the firewall service

E.

Advertise lo vSmart controllers

Question 117

An engineer is applying QoS policy for the transport-side tunnel interfaces to enable scheduling and shaping for a WAN Edge cloud router Which command accomplishes the task?

Options:

A.

cloud-qos-service-side

B.

qos-scheduler QOS_0

C.

qos-map QOS

D.

rewrite-rule QOS-REWRITE

Question 118

Drag and drop the functions from the left onto the correct templates on the right.

Question # 118

Options:

Question 119

Question # 119

Refer to the exhibit, Which configuration routes Site 2 through the firewall in Site 1?

Question # 119

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 120

Question # 120

Question # 120

Refer to the exhibit. Company ABC has a hub-and-spoke topology in place and currently is load balancing their data traffic at the hub site over MPLS and the public Internet. The leased circuit must be preferred over the shared circuit. Which configuration meets the requirement?

Question # 120

Question # 120

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 121

Which port is used for vBond under controller certificates if no alternate port is configured?

Options:

A.

12345

B.

12347

C.

12346

D.

12344

Question 122

Drag and drop the policies from the left onto the correct policy types on the right.

Question # 122

Options:

Question 123

Company E wants to deploy Cisco SD-WAN with controllers in AWS The company's existing WAN is on private MPLS without Internet access to controllers m AWS An Internet circuit is added to a site in addition to the existing MPLS circuit. Which interface template establishes BFD neighbors over both transports?

A)

Question # 123

B)

Question # 123

C)

Miss

D)

Question # 123

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 124

Drag and drop the REST API calls from the left onto the functions on the right.

Question # 124

Options:

Question 125

Question # 125

Question # 125

Refer to the exhibit vManage and vBond have an issue establishing a connection with each other Which action resolves the issue?

Options:

A.

Reconfigure the system IPs to belong to the same subnet

B.

Change the organization name on both controllers to match vipteta.com.

C.

Remove the encapsulation ipsec command under the tunnel interface of vBond

D.

Configure the encapsulation ipsec command under the tunnel interface on vManage

Question 126

Which routing protocol is used to exchange control plane information between vSmart controllers and WAN Edge routers in the Cisco SD-WAN secure extensible network?

Options:

A.

BGP

B.

OSPF

C.

BFD

D.

OMP

Question 127

Which two services are critical for zero touch provisioning on-boarding? (Choose two)

Options:

A.

SNMP

B.

DNS

C.

DHCP

D.

AAA

E.

EMAIL

Question 128

In which Cisco SD-WAN deployment scenario does Cisco Umbrella SIG deliver the most value?

Options:

A.

when a centralized Internet breakout solution is implemented

B.

when resource-intensive security operations are offloaded from entry-level WAN Edge devices

C.

when the identity of several WAN Edge devices is verified throughout the networkthroughout the network

Question 129

Refer to the exhibit.

Question # 129

An MPLS connection on R2 must extend to R1 Users behind R1 must have dual connectivity for data traffic Which configuration provides R1 control connectivity over the MPLS connection?

A)

Question # 129

B)

Question # 129

C)

Question # 129

D)

Question # 129

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 130

An organization wants to use the cisco SD-WAN regionalized service-chaining feature to optimize cost and user experience with application in the network, which allows branch routers to analyze and steer traffic toward the required network function. Which feature meets this requirement?

Options:

A.

Cloud Services Platform

B.

VNF Service Chaning

C.

Cloud onRamp for Colocation

D.

Cloud onRamp for laaS

Question 131

What is a description of vManage NMS?

Options:

A.

It is accessible only from VPN 512 (the management VPN).

B.

A cluster requires device templates to be created on and attached to the same server

C.

It is a software process on a dedicated WAN Edge router in the network.

D.

A cluster consists of a minimum of two vManage NMSs

Question 132

Which two architectural components are part of an SD-WAN high availability vManage cluster? (Choose two.)

Options:

A.

WAN Edge router

B.

network configuration system

C.

NAT router

D.

messaging server

E.

application server

Page: 1 / 44
Total 441 questions