nerdexam
Cisco

300-415 · Question #107

Refer to the exhibit. Which two configurations are needed to get the WAN Edges registered with the controllers when certificates are used? (Choose two)

The correct answer is A. Generate a CSR manually within vManage server E. Install the certificate received from the CA server manually on the vManage. For WAN Edges to register with controllers using certificates, the vManage controller must first establish its own certificate identity and trust chain, which is a foundational step for the entire SD-WAN fabric's security.

Controller Deployment

Question

Refer to the exhibit. Which two configurations are needed to get the WAN Edges registered with the controllers when certificates are used? (Choose two)

Options

  • AGenerate a CSR manually within vManage server
  • BGenerate a CSR manually on the WAN Edge
  • CRequest a certificate manually from the Enterprise CA server
  • DInstall the certificate received from the CA server manually on the WAN Edge
  • EInstall the certificate received from the CA server manually on the vManage

How the community answered

(16 responses)
  • A
    75% (12)
  • B
    6% (1)
  • C
    13% (2)
  • D
    6% (1)

Why each option

For WAN Edges to register with controllers using certificates, the vManage controller must first establish its own certificate identity and trust chain, which is a foundational step for the entire SD-WAN fabric's security.

AGenerate a CSR manually within vManage serverCorrect

Generating a Certificate Signing Request (CSR) within the vManage server is the initial step for vManage to obtain its own certificate from an Enterprise CA, establishing its identity as a trusted orchestrator.

BGenerate a CSR manually on the WAN Edge

Generating a CSR on the WAN Edge is part of the individual WAN Edge's certificate process, but not a primary configuration action needed on the *controllers* to prepare for registration.

CRequest a certificate manually from the Enterprise CA server

Requesting a certificate manually from the Enterprise CA server is an action performed on the CA, not a configuration step on the SD-WAN components themselves.

DInstall the certificate received from the CA server manually on the WAN Edge

Installing the certificate on the WAN Edge is necessary for the WAN Edge to present its identity, but the question asks for configurations to get WAN Edges registered *with the controllers*, emphasizing the controllers' readiness.

EInstall the certificate received from the CA server manually on the vManageCorrect

Installing the certificate received from the CA server manually on vManage is crucial, as it enables vManage to secure its own control connections and act as a trusted entity that can validate and register WAN Edges within the SD-WAN overlay.

Concept tested: SD-WAN controller certificate management

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/m-sdwan-basic-config.html#Cisco_Concept.dita_b5b5c9b4-b903-49d7-83d7-e070d6a2a514

Topics

#Certificate Management#SD-WAN Onboarding#Enterprise CA#Controller Configuration

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice