Cisco
300-415 · Question #107
300-415 Question #107: Real Exam Question with Answer & Explanation
The correct answer is A: Generate a CSR manually within vManage server. For WAN Edges to register with controllers using certificates, the vManage controller must first establish its own certificate identity and trust chain, which is a foundational step for the entire SD-WAN fabric's security.
Controller Deployment
Question
Refer to the exhibit. Which two configurations are needed to get the WAN Edges registered with the controllers when certificates are used? (Choose two)
Options
- AGenerate a CSR manually within vManage server
- BGenerate a CSR manually on the WAN Edge
- CRequest a certificate manually from the Enterprise CA server
- DInstall the certificate received from the CA server manually on the WAN Edge
- EInstall the certificate received from the CA server manually on the vManage
Explanation
For WAN Edges to register with controllers using certificates, the vManage controller must first establish its own certificate identity and trust chain, which is a foundational step for the entire SD-WAN fabric's security.
Common mistakes.
- B. Generating a CSR on the WAN Edge is part of the individual WAN Edge's certificate process, but not a primary configuration action needed on the controllers to prepare for registration.
- C. Requesting a certificate manually from the Enterprise CA server is an action performed on the CA, not a configuration step on the SD-WAN components themselves.
- D. Installing the certificate on the WAN Edge is necessary for the WAN Edge to present its identity, but the question asks for configurations to get WAN Edges registered with the controllers, emphasizing the controllers' readiness.
Concept tested. SD-WAN controller certificate management
Topics
#Certificate Management#SD-WAN Onboarding#Enterprise CA#Controller Configuration
Community Discussion
No community discussion yet for this question.