Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

300-415 Implementing Cisco SD-WAN Solutions (300-415 ENSDWI) Questions and Answers

Questions 4

Refer to the exhibit Which command allows traffic through the IPsec tunnel configured in VPN 0?

Options:

A.

service local

B.

service FW address 1.1.1.1

C.

service netsvc1 vpn 1

D.

service netsvc1 address 1.1.1.1

Buy Now
Questions 5

What problem happens on a device with two serial numbers, a unique device identifier (UDI), and secure unique device identifier (SUDI) when an engineer provisions ISR 4000 by PnP using only a UDI?

Options:

A.

It encounters spanning tree issues

B.

It faces interface buffer overflow patterns

C.

It encounters redirection problems.

D.

It encounters memory overload problems

Buy Now
Questions 6

Refer to the exhibit.

An SD-WAN customer has 23 sites connected to its hub site, where a pair of WAN Edge devices and controllers are placed. All other branches have a single WAN Edge device connected to multiprotocol label switching (MPLS) and public internet circuits. An engineer must configure application-aware routing for a branch that has MPLS and public internet circuits provisioned using feature templates. The requirements for application-aware routing are:

    All types of traffic prefers using public-internet circuit.

    If the average latency reaches 100 ms, jitter 85 ms, and packet loss 5%, then video and voice traffic switches to the MPLS circuit.

Which feature template must be configured or modified in addition to configuring a centralized policy?

Options:

A.

OMP

B.

VPN interface ethernet

C.

BFD

D.

VPN

Buy Now
Questions 7

A large retail organization decided to move some of the branch applications to the AWS cloud. How does the network architect extend the in-house Cisco SD-WAN branch to cloud network into AWS?

Options:

A.

Create virtual WAN Edge devices Cloud through the AWS online software store

B.

Create virtual instances of vSmart Cloud through the AWS online software store

C.

Create GRE tunnels to AWS from each branch over the Internet

D.

Install the AWS Cloud Router in the main data center and provide the connectivity from each branch

Buy Now
Questions 8

Which command displays BFD session summary information per TLOC on vEdge routers?

Options:

A.

show bfd history

B.

show bfd summary

C.

show bfd sessions

D.

show bfd tloc-summary-list

Buy Now
Questions 9

Which command verifies a policy that has been pushed to the vEdge router?

Options:

A.

vEdge# show running-config data policy

B.

vEdge# show policy from-vsmart

C.

vSmart# show running-config policy

D.

vSmart# show running-config apply-policy

Buy Now
Questions 10

Which type of connection is created between a host VNet and a transit VNet when configuring Cloud OnRamp for laaS?

Options:

A.

Azure private endpoint

B.

GRE tunnel

C.

IPsec tunnel

D.

Azure peer link

Buy Now
Questions 11

Which type of policy must be applied on a WAN Edge application-aware firewall to control traffic between two or more VPNs?

Options:

A.

service-insertion policy

B.

data policy

C.

firewall policy

D.

control policy

Buy Now
Questions 12

Which two virtualized environments are available for a company to install the controllers using the on-premises model? (Choose two )

Options:

A.

VMware vSphere ESXi

B.

VMware Workstation

C.

kernel-based virtual machine

D.

OpenStack

E.

Microsoft Hyper-V

Buy Now
Questions 13

How is an event monitored and reported for an individual device in the overlay network at site ID:S4300T6E43F36?

Options:

A.

The device sends event notifications to vManage.

B.

The device sends notifications to vSmart that sends them to vManage.

C.

The device sends a critical alarm of events to vManage.

D.

The device sends a critical alarm to vSmart that sends it to vManage.

Buy Now
Questions 14

An enterprise deployed a Cisco SD-WAN solution with hub-and-spoke topology using MPLS as the preferred network over the Internet. A network engineer must implement an application-aware routing policy to allow ICMP traffic to be load-balanced over both the available links. Which configuration meets the requirement?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 15

What is a benefit of the application-aware firewall?

Options:

A.

It blocks traffic by MAC address

B.

It blocks traffic by MTU of the packet.

C.

It blocks traffic by application.

D.

It blocks encrypted traffic

Buy Now
Questions 16

In which VPN is the NAT operation on an outgoing interface configured for direct Interne! access?

Options:

A.

1

B.

10

C.

512

D.

0

Buy Now
Questions 17

Which VPN connects the transport-side WAN Edge interface to the underlay/WAN network?

Options:

A.

VPN 1

B.

VPN 511

C.

VPN 0

D.

VPN 512

Buy Now
Questions 18

What are the two components of an application-aware firewall? (Choose two.)

Options:

A.

zone pair

B.

sequence

C.

lists

D.

default action

E.

sequence action

F.

firewall policy

Buy Now
Questions 19

An engineer provisions a WAN Edge router. Which command should be used from the WAN Edge router to activate it with vManage?

Options:

A.

request vedge-cloud activate serial token

B.

request vedge-cloud activate chassis-number organization

C.

request vedge-cloud activate chassis-number token

D.

request vedge-cloud activate chassis-number serial <:serial>

Buy Now
Questions 20

Refer to the exhibit vManage and vBond have an issue establishing a connection with each other Which action resolves the issue?

Options:

A.

Reconfigure the system IPs to belong to the same subnet

B.

Change the organization name on both controllers to match vipteta.com.

C.

Remove the encapsulation ipsec command under the tunnel interface of vBond

D.

Configure the encapsulation ipsec command under the tunnel interface on vManage

Buy Now
Questions 21

An engineer wants to track tunnel characteristics within an SLA-based policy for convergence. Which policy configuration will achieve this goal?

Options:

A.

App-route policy

B.

VPN membership policy

C.

Control policy

D.

Data policy

Buy Now
Questions 22

Refer to the exhibit. Which configuration value is used to change the administrative distance of iBGP routes to 20?

Options:

A.

Configure internal Routes Distance to 20

B.

Configure Propagate AS Path to off

C.

Configure Local Distance to 20

D.

Configure External routes distance 20

Buy Now
Questions 23

Which two services are critical for zero touch provisioning on-boarding? (Choose two)

Options:

A.

SNMP

B.

DNS

C.

DHCP

D.

AAA

E.

EMAIL

Buy Now
Questions 24

What two functions describe the TCP optimization tool used in the Cisco SD-WAN? (Choose two.)

Options:

A.

It uses TCP acknowledgment (ACK).

B.

It is used to take care of high packet loss for control traffic.

C.

It terminates TCP connections locally at the WAN edge.

D.

It uses TCP selective acknowledgment (SACK).

E.

It terminates TCP connections at the remote WAN edge.

Buy Now
Questions 25

A network administrator is configuring VRRP to avoid a traffic black hole when the transport side of the network is down on the master device. What must be configured to get the fastest failover to standby?

Options:

A.

lower timer interval

B.

prefix-list tracking

C.

higher group ID number

D.

OMP tracking

Buy Now
Questions 26

Drag and drop the attributes from the left that make each transport location unique onto the right. Not all options are used.

Options:

Buy Now
Questions 27

Which two performance data details are provided by Cisco SO-WAN vAnalytics? (Choose two)

Options:

A.

jitter loss and latency for data tunnels

B.

application quality of experience score from zero to ten

C.

detail on total cost of ownership for the fabric

D.

certificate authority status (health and expiration dates) for all controllers

E.

view devices connected to a vManage NMS

Buy Now
Questions 28

An organization requires the use of integrated preventative engines, exploit protection, and the most updated and advanced signature-based antivirus with sandboxing and threat intelligence to stop malicious attachments before they reach users and get executed. Which Cisco SD-WAN solution meets the requirements?

Options:

A.

Cisco Trust Anchor module

B.

URL filtering and Umbrella DNS security

C.

Cisco AMP and Threat Grid

D.

Snort IPS

Buy Now
Questions 29

How are policies deployed on cloud-tiosted Cisco SD-WAN controllers?

Options:

A.

Policies are created on vSmart and enforced by vSmart

B.

Policies are created on vSmart and enforced by vManage

C.

Policies are created on vManage and enforced by vManage.

D.

Policies are created on vManage and enforced by vSman

Buy Now
Questions 30

When software is upgraded on a vManage NMS, which two image-adding options store images in a local vManage software repository? (Choose two.)

Options:

A.

To be downloaded over a SMTP connection

B.

To be downloaded over a SNMP connection

C.

To be downloaded over an out-of-band connection

D.

To be downloaded over a control plane connection

E.

To be downloaded over an ICMP connection

Buy Now
Questions 31

An engineer is tasked to improve throughput for connection-oriented traffic by decreasing round-trip latency. Which configuration will achieve this goal?

Options:

A.

turn on "Enable TCP Optimization"

B.

turn off "Enhance ECMP Keying"

C.

turn off "Enable TCP Optimization"

D.

turn on "Enhance ECMP Keying"

Buy Now
Questions 32

Refer to the exhibit.

Which two configurations are needed to get the WAN Edges registered with the controllers when certificates are used? (Choose two)

Options:

A.

Generate a CSR manually within vManage server

B.

Generate a CSR manually on the WAN Edge

C.

Request a certificate manually from the Enterprise CA server

D.

Install the certificate received from the CA server manually on the WAN Edge

E.

Install the certificate received from the CA server manually on the vManage

Buy Now
Questions 33

Drag and drop the steps from the left into the order on the right to upload software on vManage repository that is accessible from maintenance > Software Repository.

Options:

Buy Now
Questions 34

Drag and drop the devices from the left onto the correct functions on the right.

Options:

Buy Now
Questions 35

The network administrator is configuring a QoS scheduling policy on traffic received from transport side tunnels on WAN Edge 5000 routers at location 406141498 Which command must be configured on these devices?

Options:

A.

cloud-qos

B.

service qos

C.

cloud-mis qos

D.

mis qos

Buy Now
Questions 36

If Smart Account Sync is not used, which Cisco SD-WAN component is used to upload an authorized serial number file?

Options:

A.

WAN Edge

B.

vManage

C.

vSmart

D.

vBond

Buy Now
Questions 37

What is the minimum Red Hat Enterprise Linux operating system requirement for a Cisco SD-WAN controller deployment via KVM?

Options:

A.

RHEL7.5

B.

RHEL 6.5

C.

RHEL4.4

D.

RHEL 6.7

Buy Now
Questions 38

Refer to the exhibit.

vManage and vSmart have an issue establishing a connection to vBond. Which configuration resolves the issue?

Options:

A.

Configure the tunnel interface on all three controllers with a color of transport.

B.

Change the timezone on the vSmart to Europe/London.

C.

Configure the (11.1.1.X/24) IP addresses on the elhO interfaces on vManage and vSmart.

D.

Reconfigure the system-ip parameter on vSmart to 11.1.1.2.

Buy Now
Questions 39

Which two image formats are supported for controller codes? (Choose two.)

Options:

A.

.nxos

B.

.qcow2

C.

.ova

D.

.bin

E.

Tgz

Buy Now
Questions 40

Refer to the exhibit.

A customer wants to implement primary and secondary Cisco SD-WAN overlay routing for prefixes that are advertised for both data centers. The east data center (TLOC 101.101.101.101) is primary for east sites, and the west data center (TLOC 100.100.100.100) is primary for west sites. Which configuration change achieves this objective?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 41

What is the result during a WAN Edge software upgrade process if the version of the WAN Edge software is higher than the one running on a controller device?

Options:

A.

The upgrade button is greyed out

B.

The upgrade proceeds with no warning message.

C.

The upgrade fails with a warning message

D.

The upgrade proceeds with a warning message

Buy Now
Questions 42

Which statement describes the requirement of integrating a secure internet gateway (SIG) with a Cisco SD-WAN Edge device?

Options:

A.

Attached to SIG tunnels, trackers monitor the respective SIG endpoints.

B.

Credentials for a smart account are required.

C.

A Cisco umbrella organization ID is needed to establish the SIG.

D.

Based on routing or policy, all customer internet traffic must be forwarded to the SIG.

Buy Now
Questions 43

Refer to the exhibit An engineer is configuring a QoS policy to shape traffic for VLAN 100 on a subinterface Which policy configuration accomplishes the task?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 44

Which device in the SD- WAN solution receives and categorizes event reports, and generates alarms?

Options:

A.

WAN Edge routers

B.

vSmart controllers

C.

vManage NMS

D.

vBond controllers

Buy Now
Questions 45

What is the default value for the number of paths advertised per prefix in the OMP feature template?

Options:

A.

4

B.

8

C.

12

D.

16

Buy Now
Questions 46

Which API call retrieves a list of all devices in the network?

Options:

A.

https://vmanage_IP_address/dataservice/system/device/{{model}}

B.

http://vmanage_IP_address/dataservice/system/device/{{model}}

C.

http://vmanage_IP_address/api-call/system/device/{{model}}

D.

https://vmanage_IP_address/api-call/system/device/{{model}}

Buy Now
Questions 47

Refer to the exhibit A small company was acquired by a large organization As a result, the new organization decided to update information on their Enterprise RootCA and generated a new certificate using openssl Which configuration updates the new certificate and issues an alert in vManage Monitor | Events Dashboard?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 48

A customer wants to use AWS for Cisco SD-WAN laaS services by deploying virtual SD-WAN routers in a transit AWS VPC The transit VPC then connects via site-to-site IPsec tunnels to an AWS transit gateway Which transit VPC connects via site-to-site IPsec tunnels to an AWS transit gateway?

Options:

A.

Cisco Cloud onRamp for Multicloud

B.

Cisco Cloud onRamp for SaaS

C.

Cisco Cloud onRamp for Colocation

D.

Cisco Cloud onRamp for laaS

Buy Now
Questions 49

Which protocol Is used by the REST API to communicate with network services in the Cisco SO-WAN network?

Options:

A.

SSL

B.

HTTP

C.

iPsec

D.

SSM

Buy Now
Questions 50

A network administrator is creating an OMP feature template from the vManage GUI to be applied to WAN edge routers. Which configuration attribute will avoid the redistribution of the routes back into the OMP from the LAN side?

Options:

A.

configure "Number of Paths Advertised per Prefix"

B.

configure "Overlay AS Number"

C.

configure "Send Backup Paths"

D.

configure "ECMP limit"

Buy Now
Questions 51

Refer to the exhibit. Company ABC has a hub-and-spoke topology in place and currently is load balancing their data traffic at the hub site over MPLS and the public Internet. The leased circuit must be preferred over the shared circuit. Which configuration meets the requirement?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 52

An engineer wants to change the configuration of the certificate authorization mode from manual to automated. Which GUI selection will accomplish this?

Options:

A.

Maintenance > Security

B.

Configuration > Certificates

C.

Administration > Settings

D.

Tools > Operational Commands

Buy Now
Questions 53

What is the OMP graceful restart default value on vSmart controllers and WAN Edge routers?

Options:

A.

21,600 seconds

B.

43,200 seconds

C.

86,400 seconds

D.

604,800 seconds

Buy Now
Questions 54

Which plane assists in the automatic onboarding of the SD-WAN routers into the SD-WAN overlay?

Options:

A.

Data

B.

Orchestration

C.

Management

D.

Control

Buy Now
Questions 55

An engineer must avoid routing loops on the SD-WAN fabric for routes advertised between data center sites Which BGP loop prevention attribute must be configured on the routers to meet this requirement?

Options:

A.

same OMP overlay-as on WAN Edge routers of all data centers

B.

static routing on al WAN Edge routers instead of BGP

C.

same BGP AS between all WAN Edge routers and CE routers

D.

same BGP AS between all CE and PE routers

Buy Now
Questions 56

An organization wants to use the cisco SD-WAN regionalized service-chaining feature to optimize cost and user experience with application in the network, which allows branch routers to analyze and steer traffic toward the required network function. Which feature meets this requirement?

Options:

A.

Cloud Services Platform

B.

VNF Service Chaning

C.

Cloud onRamp for Colocation

D.

Cloud onRamp for laaS

Buy Now
Questions 57

What is a restriction when configuring a tunnel interface?

Options:

A.

Up to six tunnel interfaces are configurable on a vSmart.

B.

it is manually assigned when using vWanage feature template.

C.

It must be configured for the interface under aft VPNs

D.

Up to six tunnel interfaces are configurable on a WAN Edge

Buy Now
Questions 58

An engineer is configuring a centralized policy to influence network route advertisement. Which controller delivers this policy to the fabric?

Options:

A.

vSmart

B.

vManage

C.

WAN Edge

D.

vBond

Buy Now
Questions 59

A company deploys a Cisco SD-WAN solution but has an unstable Internet connection. When the link to vSmart comes back up, the WAN Edge router routing table is not refreshed, and some traffic to the destination network is dropped. The headquarters is the hub site, and it continuously adds new sites to the SD-WAN network. An engineer must configure route refresh between WAN Edge and vSmart within 2 minutes. Which configuration meets this requirement?

Options:

A.

Option A

B.

B

C.

Option B

D.

E.

Option C

F.

Option D

Buy Now
Questions 60

Which protocol advertises WAN edge routes on the service side?

Options:

A.

EIGRP

B.

OSPF

C.

BGP

D.

ISIS

Buy Now
Questions 61

Refer to the exhibit.

An enterprise has hub and spoke topology where it has several VPNs. An engineer must allow users in VPN91 to reach users in VPN92 and VPN10 to reach VPN91 and VPN92. Which configuration meets these requirements?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 62

Refer to the exhibit The network team must configure application-aware routing for the Service VPN 50.0.0.0/16 The SLA must prefer MPLS for video traffic but the remaining traffic must use a public network What must be defined other than applications before the application-aware policy is create?

Options:

A.

SLA Class, Site VPN. Prefix

B.

Data Prefix, Site VPN TLOC

C.

Application, SLA VPN. Prefix

D.

Color, SLA Class, Sue, VPN

Buy Now
Questions 63

Which Cloud OnRamp solution is used by partners and vendors without Cisco SD-WAN but still needs connectivity to their customers without installing SD-WAN routing appliances on their sites?

Options:

A.

Cloud OnRamp for IaaS

B.

Cloud OnRamp for SaaS

C.

Cloud OnRamp for Multicloud

D.

Cloud OnRamp for Colocation

Buy Now
Questions 64

Which component of the Cisco SD-WAN architecture oversees the control plane of overlay network to establish, adjust, and maintain the connections between the WAN Edge devices that form the Cisco SD-WAN fabric?

Options:

A.

APIC-EM

B.

vManage

C.

vSmart

D.

vBond

Buy Now
Questions 65

Which two prerequisites must be met before the Cloud onRamp for laaS is initiated on vManage to expand to the AWS cloud? (Choose two)

Options:

A.

Attach the *AmazonCreateVPC* and "Amazon Provision EC2" permission policy to the IAM account

B.

Subscribe to the SD-WAN Edge router AMI in the AWS account

C.

Attach an OSPF feature template to the AWS cloud Edge router template

D.

Attach a device template to the cloud WAN Edge router to be deployed in the AWS

E.

Preprovision the transit VPC in the AWS region

Buy Now
Questions 66

A company is using Catalyst SD-WAN Manager as its root certificate authority server and must generate a root certificate using the vShell (Linux) built into the CLI of Catalyst SD-WAN Manager. Which command must be issued to generate the root certificate?

Options:

A.

openssl req -x509 -new-nodes -key XYZ.pem -sha256 -days 365 \subj "/C=US/ST=DC/L=DC/O=Cisco/CN=device.lab"-out ABC.key

B.

openssl genrsa -out ROOTCA.pem 2048

C.

openssl req -x509 -new-nodes -key XYZ.key -sha256 -days 365 Isubj "/C-US/ST-DC/L-DC/O-Cisco/CN-device.lab" 1-out ABC.pem

D.

openssl genrsa -out ROOTCA.key 2048

Buy Now
Questions 67

Which Cisco SD-WAN component the initial communication between WAN Edge devices to join the fabric?

Options:

A.

WAN Edge Router

B.

vSmart Controller

C.

vManage

D.

vBond Orchestrator

Buy Now
Questions 68

In a Cisco SD-WAN architecture, what is the role of the WAN Edge?

Options:

A.

It provides orchestration to assist in automatic provisioning of WAN Edge routers and overlay

B.

It is the management plane responsible for centralized configuration and monitoring

C.

It is the control plane that builds and maintains network topology

D.

It is the data plane that is responsible for forwarding traffic

Buy Now
Questions 69

Which platform is a Cisco SD-WAN virtual platform?

Options:

A.

Cisco ISR 4000

B.

Cisco Nexus 1000V

C.

Cisco CSR 1000V

D.

Cisco ASR 1000

Buy Now
Questions 70

Refer to the exhibit The network team must configure El GRP peering at HQ with devices in the service VPN connected to WAN Edge CSRv. CSRv is currently configured with

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 71

For data plane resiliency, what does the Cisco SD-WAN software implement?

Options:

A.

BFD

B.

establishing affinity between vSmart controllers and WAN Edge routers

C.

multiple vBond orchestrators

D.

OMP

Buy Now
Questions 72

Which two resource data types are used to collect information for monitoring using REST API in Cisco SD-WAN? (Choose two.)

Options:

A.

POST

B.

DELETE

C.

scalar

D.

array

E.

PUT

Buy Now
Questions 73

Which actions must be taken to allow certain departments to require firewall protection when interacting with data center network without including other departments? (Choose two.)

Options:

A.

Use classification policing and marking

B.

Apply data policies at vEdge.

C.

Deploy a service-chained firewall service per VPN

D.

The regional hub advertises the availability of the firewall service

E.

Advertise lo vSmart controllers

Buy Now
Questions 74

Refer to the exhibit. A customer wants to deploy service insertion at site1. Which traffic from VPN 10 must route to this site through a firewall. A policy must be in place to route VPN 10 traffic from all sites toward this firewall. Which configuration must be on the vSmart controller to meet this requirement?

Options:

A.

B.

C.

D.

Buy Now
Questions 75

In which device state does the WAN edge router create control connections, but data tunnels are not created?

Options:

A.

valid

B.

backup

C.

active

D.

staging

Buy Now
Questions 76

Refer to the exhibit. A Cisco SD-WAN network carries traffic for several departments and over 1200 users with several applications at site A and site B branches over the MPLS1 circuit. An engineer is provisioning a higher bandwidth on-demand metro circuit as a backup connection. Which two configurations must the engineer apply to implement the on-demand tunnels? (Choose two.)

Options:

A.

B.

C.

D.

E.

Buy Now
Questions 77

Refer to the exhibit An engineer must configure a QoS policy between me hub and site A (spoke) over a standard internet circuit where traffic shaping is adjusted automatically based on evaiiabk» bandwidth Which configuration meets the requirement?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 78

An engineer is applying QoS policy for the transport-side tunnel interfaces to enable scheduling and shaping for a WAN Edge cloud router Which command accomplishes the task?

Options:

A.

cloud-qos-service-side

B.

qos-scheduler QOS_0

C.

qos-map QOS

D.

rewrite-rule QOS-REWRITE

Buy Now
Questions 79

An administrator is configuring the severity level on the vManage NMS for events that indicate that an action must be taken immediately. Which severity level must be configured?

Options:

A.

warning

B.

error

C.

critical

D.

alert

Buy Now
Questions 80

How must the application-aware enterprise firewall policies be applied within the same WAN Edge router?

Options:

A.

within and between zones

B.

between two VPN tunnels

C.

within zone pair

D.

between two VRFs

Buy Now
Questions 81

What is the default value for the Multiplier field of the BFD basic configuration in vManage?

Options:

A.

3

B.

4

C.

5

D.

6

Buy Now
Questions 82

Refer to the exhibit Cisco SD-WAN is deployed with controllers hosted in a data center All branches have WAN Edge devices with dual connections to the data center one via Internet and the other using MPLS Three branches out of 20 have issues with their control connections on MPLS circuit The local error refers to Control Connection Failure Which action resolves the issue*?

Options:

A.

Rectify any issues with the underlay routing configuration

B.

Match the TLOC color on the controllers and all WAN Edge devices

C.

Match certificates for the DTLS connection and Root CA must be installed first on WAN Edge devices

D.

Update the system IP on vManage and then resend it to the controllers

Buy Now
Questions 83

Which component is used for stateful inspection of TCP, UDP. and ICMP flows in Cisco SD-WAN firewall policies?

Options:

A.

zones

B.

sites

C.

subnets

D.

interfaces

Buy Now
Questions 84

Refer to the exhibit. An engineer must configure the Overlay Management Protocol route preference so that when B2 tries to reach host routes advertised by B1 it always chooses the MPLS circuit. Which two match conditions must be configured to accomplish this task? (Choose two.)

Options:

A.

VPN

B.

prefix list

C.

originator

D.

color list

E.

path type

Buy Now
Questions 85

Refer to the exhibit.

The network team must configure branch B WAN Edge device 103 to establish dynamic full-mesh IPsec tunnels between all colors with branches over MPLS and Internet circuits. The branch ts configured with:

Which configuration meets the requirement?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 86

Refer to the exhibit.

Which configuration change is needed to configure the tloc-extention on Branch1-Edge1?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 87

Refer to the exhibit An engineer is getting a CTORGNMMIS error on a controller connection Which action resolves this issue?

Options:

A.

Configure a valid serial number on the WAN Edge

B.

Configure a valid organization name

C.

Configure a valid certificate on vSMART

D.

Configure a valid product ID

Buy Now
Questions 88

An engineer is troubleshooting a certificate issue on vEdge. Which command is used to verify the validity of the certificates?

Options:

A.

show control local-properties

B.

show control summary

C.

show certificate installed

D.

show certificate status

Buy Now
Questions 89

What are the two impacts of losing vManage connectivity to fabric in the Cisco SD-WAN network? (Choose two)

Options:

A.

Policy changes propagation stops

B.

Statistics collection stops

C.

BFD peering between WAN Edge devices are unestablished

D.

Creation of templates is impossible

E.

IPsec tunnels tear down for WAN Edge devices.

Buy Now
Questions 90

How is the software managed in Cisco SD-WAN?

Options:

A.

Software images must be uploaded to vManage through HTTP or FTP

B.

Software downgrades are unsupported for vManage

C.

Software images must be transferred through VPN 512 or VPN 0 of vManage

D.

Software upgrade operation in the group must include vManage. vBond, and vSmart.

Buy Now
Questions 91

Refer to the exhibit.

An engineer is troubleshooting a control connection Issue. What does "connect" mean in this how control connections output?

Options:

A.

Control connection is down

B.

Control connection is connected

C.

Control connection attempt is in progress

D.

Control connection is up

Buy Now
Questions 92

What is the default value (in milliseconds) set tor the poll interval in the BFD basic configuration?

Options:

A.

300,000

B.

600,000

C.

900,000

D.

1,200,000

Buy Now
Questions 93

Company ABC has decided to deploy the controllers using the On-Prem method. How does the administrator upload the WAN Edge list to the vManage?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 94

A customer has 1 to 100 service VPNs and wants to restrict outbound updates for VPN1 Which control policy configuration restricts these updates?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 95

An engineer is troubleshooting a vEdge router and identifies a “DCONFAIL – DTLS connection failure” message. What is the problem?

Options:

A.

certificate mismatch

B.

organization mismatch

C.

memory issue

D.

connectivity issue

Buy Now
Questions 96

What is the main purpose of using TLOC extensions in WAN Edge router configuration?

Options:

A.

creates hardware-level transport redundancy at the local site

B.

creates an IPsec tunnel from WAN Edge to vBond Orchestrator

C.

transports control traffic to a redundant vSmart Controller

D.

transports control traffic w remote-site WAN Edge routers

Buy Now
Questions 97

Refer to the exhibit A user has selected the options while configuring a VPN Interface Ethernet feature template What is the required configuration parameter the user must set in this template for this feature to function?

Options:

A.

The "IP MTU" field must be increased from the default value of 1500 to support the additional overhead.

B.

The "Shaping Rate (Kbps)" field must be configured with a value

C.

The "Adaptive QoS" field must be set to "on"

D.

The "Bandwidth Downstream" field must be configured with a value

Buy Now
Questions 98

Which control policy assigned to Drenches in the out direction establishes a strict hub-and-spoke topology tor VPN2?

A)

B)

C)

D)

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Buy Now
Questions 99

Refer to the exhibit.

What binding is created using the tloc-extension command?

Options:

A.

between ge 0/2.101 of port-type service and ge 0/0 of port-type service

B.

between ge 0/2.101 of port-type transport and ge 0/0 of port-type service

C.

between ge 0/2.101 of port-type service and ge 0/0 of port-type transport

D.

between ge 0/2.101 of port-type transport and ge 0/0 of port-type transport

Buy Now
Questions 100

Refer to the exhibit. Which configuration stops Netconf CLI logging on WAN Edge devices during migration?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 101

A network administrator configures SNMPv3 on a Cisco WAN Edge router from CLI for monitoring purposes How many characters are supported by the snmp user command?

Options:

A.

from 1 to 8

B.

from 1 to 16

C.

from 1 to 32

D.

from 1 to 48

Buy Now
Questions 102

Drag and drop the functions from the left onto the correct templates on the right.

Options:

Buy Now
Questions 103

An enterprise has these three WAN connections:

public Internet

business internet

MPLS

An engineer must configure two available links to route traffic via both links. Which configuration achieves this objective?

Options:

A.

Option

B.

Option

C.

Option

D.

Option

Buy Now
Questions 104

Which policy tracks path characteristics such as loss, latency, and jitter in vManage?

Options:

A.

VPN

B.

control

C.

app-route

D.

data

Buy Now
Questions 105

Refer to the exhibit.

The engineer must assign community tags to 3 of its 74 critical server networks as soon as that are advertised to BGP peers. These server networks must not be advertised outside AS. Which configuration fulfill this requirement?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 106

Which Cisco router provides a distributed multicore architecture optimized for SD-WAN branch support?

Options:

A.

Cisco 1000 ISR series

B.

Cisco 2900 ISR series

C.

Cisco Catalyst 3850 series

D.

Cisco 3900 ISR series

Buy Now
Questions 107

Customer has two branch silos with overlapping IPs How must the data policy be configured to establish communication between the sites and server to avoid overlapping?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 108

An engineer must configure the SD-WAN Edge router to identify DSCP 26 traffic coming from the router's local site and then change the DSCP value to DSCP 18 before sending it over to the SD-WAN fabric. What are the two ways to create the required configuration? (Choose two).

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

E.

Option E

Buy Now
Questions 109

When VPNs are grouped to create destination zone in Zone-Based Firewall, how many zones can a single VPN be part of?

Options:

A.

two

B.

four

C.

one

D.

three

Buy Now
Questions 110

Refer to the exhibit. Which configuration ensures that OSPP routes learned from Site2 are reachable at Stein and vice-versa?

Options:

A.

B.

C.

Buy Now
Questions 111

The branch users of an organization must be prevented from accessing malicious destinations, and the local files on users' systems must be protected from malware. Which two Cisco products must the organization deploy? (Choose two.)

Options:

A.

Cisco Stealthwatch

B.

Cisco Umbrella

C.

Cisco AMP

D.

Cisco Cloudlock

E.

Cisco SecureX

Buy Now
Questions 112

Which scheduling method is configured by default for the eight queues in the cloud vEdge router1?

Options:

A.

low latency queue

B.

priority queue

C.

weighted random early detection

D.

weighted round robin

Buy Now
Questions 113

Refer to the exhibit.

Which shaping-rate does the engineer use to shape traffic at 9 Mbps?

Options:

A.

9

B.

9000

C.

90000

D.

9000000

Buy Now
Questions 114

Which two types of SGT propagation are supported by Cisco TrustSec? (Choose two.)

Options:

A.

reconciliation

B.

SXP

C.

offline tagging

D.

key chain

E.

inline tagging

Buy Now
Questions 115

Which two vRoute attributes should be matched or set in vSmart policies and modified by data policies? (Choose two.)

Options:

A.

site ID

B.

preference

C.

VPN

D.

TLOC

E.

origin

Buy Now
Questions 116

Which two actions are necessary to set the Controller Certificate Authorization mode to indicate a root certificate? (Choose two)

Options:

A.

Select the Controller Certificate Authorization mode that is recommended by Cisco

B.

Change the organization name of the Cisco SO-WAN fabric.

C.

Upload an SSL certificate to vManape,

D.

Select a private certificate signing authority instead of a public certificate signing authority

E.

Select a validity period from the drop-down menu

Buy Now
Questions 117

Drag and drop the components from the left onto the corresponding Cisco NFV infrastructure Building Blocks on the right. Not all options are used.

Options:

Buy Now
Questions 118

Exhibit.

The SD-WAN network is configured with a default full-mash topology. An engineer wants Barcelona and Paris to communicate to each other through the London site using a control Which control policy configuration accomplishes the task?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 119

Which behavior describes a WAN Edge router running dual DIA when its DPI engine has identified a cloud SaaS application?

Options:

A.

Application traffic flows are routed over best performing DIA circuit, which makes the routing decision based on the best performing path.

B.

The gateway WAN Edge router DPI engine accepts the DNS query for SaaS applications, and DNS queries for noncloud applications follow the explicit path.

C.

Existing flows change the path and drop the traffic when the performance of the chosen path degrades.

D.

The WAN Edge DPI engine never selects a subperforming DIA circuit for the first application, and the WAN Edge router finds the SaaS application.

Buy Now
Questions 120

Which secure tunnel type should be used to connect one WAN Edge router to other WAN Edge routers?

Options:

A.

TLS

B.

DTLS

C.

SSL VPN

D.

IPsec

Buy Now
Questions 121

How does the Cisco SD-WAN Cloud OnRamp solution rate the performance of a SaaS application from a branch office to the cloud via a given path?

Options:

A.

It computes a quality-of-experience score.

B.

It monitors the packet loss of priority queues.

C.

It counts the number of interface errors.

D.

It measures the delay and jitter of the path.

Buy Now
Questions 122

Refer to the exhibit.

The SD-WAN network is configured with a default full-mesh topology. The SD-WAN engineer wants the Barcelona WAN Edge to use MPLS TLOC as the preferred TLOC when communicating with Rome site. Which configuration must the engineer use to create a list to select MPLS color toward the Rome TLOC?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 123

Refer to the exhibit.

Customer XYZ cannot provision dual connectivity on both of its routers due to budget constraints but wants to use both R1 and R2 interlaces for users behind them for load balancing toward the hub site. Which configuration achieves this objective?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 124

A customer has MPLS and Internet as the TLOC colors An engineer must configure conlroJIers with the Internet and not with MPLS Which configuration achieves this requirement on vManage?

A)

B)

C)

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 125

Refer to the exhibit. Which configuration extends the INET interface on R1 to be used by R2 for control and data connections?

A)

B)

C)

Options:

A.

Option A

B.

Option B

C.

Option C

Buy Now
Questions 126

What are two benefits of installing Cisco SD-WAN controllers on cloud-hosted services? (Choose two.)

Options:

A.

utilizes well-known cloud services such as Azure. AWS. and GCP

B.

accelerates Cisco SD-WAN deployment

C.

allows integration of the WAN Edge devices In the cloud

D.

installs the controllers in two cloud regions in a primary and backup setup

E.

automatically Implements zone-based firewalling on the controllers

Buy Now
Questions 127

Company E wants to deploy Cisco SD-WAN with controllers in AWS The company's existing WAN is on private MPLS without Internet access to controllers m AWS An Internet circuit is added to a site in addition to the existing MPLS circuit. Which interface template establishes BFD neighbors over both transports?

A)

B)

C)

Miss

D)

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 128

An engineer must configure local redundancy on a site. Which configuration accomplish this task?

Options:

A.

vpn 0interface interface-name

B.

tloc extension interlace nametloc extension interface interface name

C.

vpn 0tloc extension interface

D.

interface-flameinterface interface-name tloc-extension

Buy Now
Questions 129

An engineer must improve video quality by limiting HTTP traffic to the Internet without any failover. Which configuration in vManage achieves this goal?

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 130

A policy is created to influence routing in the network using a group of prefixes. What policy application will achieve this goal when applied to a site list?

Options:

A.

Vpn-membership policy

B.

Control-policy

C.

cflowd-template

D.

App-route policy

Buy Now
Questions 131

Which two mechanisms are used by vManage to ensure that the certificate serial number of the WAN Edge router that is needed to authenticate is listed in the WAN Edge Authorized Señal Number Hst’ (Choose two)

Options:

A.

Synchronize to the PnP

B.

Manually upload it to vManage

C.

The devices register to vManage directly as the devices come online

D.

The vManage is shipped with the list

E.

Synchronize to the Smart Account

Buy Now
Questions 132

A network administrator is configuring a centralized control policy based on match action pairs for multiple conditions, which order must be configured to prefer Prefix List over TLOC and TLOC over Origin?

Options:

A.

highest to lowest sequence number

B.

nonsequential order

C.

deterministic order

D.

lowest to highest sequence number

Buy Now
Questions 133

Drag and drop the security terminologies from the left onto the PCI-compliant network features and devices on the right.

Options:

Buy Now
Exam Code: 300-415
Exam Name: Implementing Cisco SD-WAN Solutions (300-415 ENSDWI)
Last Update: Apr 7, 2026
Questions: 446
300-415 pdf

300-415 PDF

$28.5  $94.99
300-415 Engine

300-415 Testing Engine

$33  $109.99
300-415 PDF + Engine

300-415 PDF + Testing Engine

$43.5  $144.99