nerdexam
Cisco

300-415 · Question #309

Which two actions are necessary to set the Controller Certificate Authorization mode to indicate a root certificate? (Choose two.)

The correct answer is A. Select a private certificate signing authority instead of a public certificate signing authority. D. Upload an SSL certificate to vManage. To set the Controller Certificate Authorization mode to use a root certificate, you must select a private certificate signing authority and upload the necessary SSL certificate to vManage.

Controller Deployment

Question

Which two actions are necessary to set the Controller Certificate Authorization mode to indicate a root certificate? (Choose two.)

Options

  • ASelect a private certificate signing authority instead of a public certificate signing authority.
  • BChange the organization name of the Cisco SD-WAN fabric.
  • CSelect the Controller Certificate Authorization mode that is recommended by Cisco.
  • DUpload an SSL certificate to vManage.
  • ESelect a validity period from the drop-down menu.

How the community answered

(24 responses)
  • A
    71% (17)
  • B
    17% (4)
  • C
    4% (1)
  • E
    8% (2)

Why each option

To set the Controller Certificate Authorization mode to use a root certificate, you must select a private certificate signing authority and upload the necessary SSL certificate to vManage.

ASelect a private certificate signing authority instead of a public certificate signing authority.Correct

Choosing a private certificate signing authority indicates that you are using an internal or self-signed certificate infrastructure, where a specific root certificate needs to be trusted by vManage.

BChange the organization name of the Cisco SD-WAN fabric.

Changing the organization name of the Cisco SD-WAN fabric is a fabric-wide identifier and does not directly configure the certificate authorization mode for controller trust.

CSelect the Controller Certificate Authorization mode that is recommended by Cisco.

Simply selecting a Cisco-recommended Controller Certificate Authorization mode does not, by itself, indicate or establish trust for a specific root certificate without the underlying certificate management actions.

DUpload an SSL certificate to vManage.Correct

To enable vManage to trust and authorize controllers using a private or enterprise root certificate, that specific SSL certificate, or its chain, must be explicitly uploaded to vManage.

ESelect a validity period from the drop-down menu.

Selecting a validity period is part of certificate generation, but it is not one of the two primary actions required to set the authorization mode to indicate the use of a root certificate.

Concept tested: Cisco SD-WAN controller certificate authorization

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/sdwan-security-book/sdwan-certs-whitelist.html

Topics

#Controller security#Certificate management#PKI#vManage configuration

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice