300-415 · Question #133
Which two requirements must be met for DNS inspection when integrating with cisco umbrella? (Choose two)
The correct answer is B. Attach security policy to the device template. C. Configure the Umbrella token on the vManage. For Cisco SD-WAN DNS inspection with Umbrella, a security policy must be attached to the device template, and the Umbrella token needs to be configured on vManage to establish the integration.
Question
Options
- AUpload the WAN Edge serial allow list to the Umbrella portal.
- BAttach security policy to the device template.
- CConfigure the Umbrella token on the vManage.
- DCreate and attach a System feature template with the Umbrella registration credentials.
- ERegister and configure the vManage public IP and serial number in the Umbrella portal.
How the community answered
(36 responses)- A8% (3)
- B78% (28)
- D11% (4)
- E3% (1)
Why each option
For Cisco SD-WAN DNS inspection with Umbrella, a security policy must be attached to the device template, and the Umbrella token needs to be configured on vManage to establish the integration.
While device registration is part of the process, there is no specific 'WAN Edge serial allow list' upload to the Umbrella portal; devices are typically registered through the vManage integration.
Attaching a security policy to the device template is crucial as this policy contains the DNS security rules that direct traffic to Umbrella for inspection, defining what DNS traffic to intercept and redirect.
Configuring the Umbrella token on vManage is a mandatory step for authentication and integration, allowing vManage to securely communicate with the Umbrella cloud and register the SD-WAN fabric, linking the SD-WAN deployment to the specific Umbrella organization.
While a System feature template is used for general device configuration, the primary Umbrella registration credentials (like the token) are configured directly on vManage for the overall integration, not typically in a separate system feature template specific to Umbrella registration itself.
While vManage's public IP and serial number are involved in device identification, the specific action of 'register and configure' these elements manually in the Umbrella portal isn't the primary integration mechanism; the vManage controller handles registration using the Umbrella token.
Concept tested: Cisco SD-WAN Umbrella DNS security integration
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/m-security.html#concept_z51_3fh_h2b
Topics
Community Discussion
No community discussion yet for this question.