nerdexam
Cisco

300-415 · Question #276

Which two actions must be taken to allow certain department to require firewall protection when interacting with data center networks without including other departments? (Choose two.)

The correct answer is B. Advertise to vSmart controllers. To allow specific departments to use firewall protection when interacting with data center networks, a service-chained firewall must be deployed per VPN and its availability advertised to vSmart controllers.

Policies

Question

Which two actions must be taken to allow certain department to require firewall protection when interacting with data center networks without including other departments? (Choose two.)

Options

  • AUse classification, policing, and marking
  • BAdvertise to vSmart controllers.
  • CThe regional hub advertises the availability of the firewall service.
  • DApply data policies at vEdge.
  • EDeploy a service-chained firewall service per VPN.

How the community answered

(63 responses)
  • A
    8% (5)
  • B
    84% (53)
  • C
    2% (1)
  • D
    2% (1)
  • E
    5% (3)

Why each option

To allow specific departments to use firewall protection when interacting with data center networks, a service-chained firewall must be deployed per VPN and its availability advertised to vSmart controllers.

AUse classification, policing, and marking

Using classification, policing, and marking are QoS mechanisms that control traffic flow and priority, but they do not directly enable or provision a firewall service for specific departments.

BAdvertise to vSmart controllers.Correct

The firewall service must be advertised to vSmart controllers so that the vSmart controllers can build a topology that includes the firewall service and inform the relevant vEdge routers about its availability for service chaining. This allows the vSmart to intelligently direct traffic through the firewall.

CThe regional hub advertises the availability of the firewall service.

While a regional hub might host the firewall, simply stating "The regional hub advertises the availability of the firewall service" is not precise enough; it is the vSmart that learns of the service from the devices providing it.

DApply data policies at vEdge.

Applying data policies at vEdge is a mechanism to enforce traffic flow, but it does not describe the prerequisite steps of deploying the service and making it known to the control plane, which are covered by B and E.

EDeploy a service-chained firewall service per VPN.

Concept tested: Cisco SD-WAN service chaining and VPN segregation

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-cr-book/secure-sdwan-multitenant.html

Topics

#SD-WAN Service Chaining#Service Advertisement#vSmart Controller#Traffic Steering

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice