nerdexam
Cisco

300-415 · Question #453

A company is deploying a new policy that restricts access to Cisco Catalyst SD-WAN Manager features based on VPN groups, segments, and users. Which configuration accomplishes this task?

The correct answer is A. Image showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" checked, and "netadmin" as the User Group. Restricting SD-WAN Manager access by VPN group and user requires creating a VPN group with 'Enable User Group access' checked and assigning a specific authorized user group such as 'netadmin'.

Management and Operations

Question

A company is deploying a new policy that restricts access to Cisco Catalyst SD-WAN Manager features based on VPN groups, segments, and users. Which configuration accomplishes this task?

Options

  • AImage showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" checked, and "netadmin" as the User Group.
  • BImage showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" checked, and "operator" as the User Group.
  • CImage showing "Add VPN Group" with "New_Group", "Enable User Group access" checked, and an empty User Group field.
  • DImage showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" checked, and "admin" as the User Group.
  • EImage showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" unchecked.

How the community answered

(31 responses)
  • A
    71% (22)
  • B
    6% (2)
  • C
    3% (1)
  • D
    3% (1)
  • E
    16% (5)

Why each option

Restricting SD-WAN Manager access by VPN group and user requires creating a VPN group with 'Enable User Group access' checked and assigning a specific authorized user group such as 'netadmin'.

AImage showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" checked, and "netadmin" as the User Group.Correct

Assigning 'netadmin' as the user group for VPN_Group_10 with 'Enable User Group access' enabled correctly implements VPN-based role access control - the 'netadmin' built-in group has the appropriate network administration privileges for managing VPN segment resources. This configuration scopes which user groups can access or manage the resources tied to that specific VPN group, fulfilling the policy requirement of segmenting access by VPN group and user.

BImage showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" checked, and "operator" as the User Group.

The 'operator' user group has read-only or limited operational access and is not the correct role for administering VPN group-based access restrictions in this context.

CImage showing "Add VPN Group" with "New_Group", "Enable User Group access" checked, and an empty User Group field.

Leaving the User Group field empty produces an incomplete configuration that does not associate any users with the VPN group, so no user-level access restriction is actually enforced.

DImage showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" checked, and "admin" as the User Group.

The 'admin' user group has unrestricted system-wide access and assigning it to a VPN group does not meaningfully restrict access - it defeats the purpose of the segmented policy.

EImage showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" unchecked.

With 'Enable User Group access' unchecked, the VPN group configuration ignores user group membership entirely, leaving user-level access restrictions disabled.

Concept tested: SD-WAN Manager VPN group role-based access control configuration

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/rbac.html

Topics

#SD-WAN Manager#Access Control#VPN Groups#User Groups

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice