300-415 · Question #453
A company is deploying a new policy that restricts access to Cisco Catalyst SD-WAN Manager features based on VPN groups, segments, and users. Which configuration accomplishes this task?
The correct answer is A. Image showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" checked, and "netadmin" as the User Group. Restricting SD-WAN Manager access by VPN group and user requires creating a VPN group with 'Enable User Group access' checked and assigning a specific authorized user group such as 'netadmin'.
Question
Options
- AImage showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" checked, and "netadmin" as the User Group.
- BImage showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" checked, and "operator" as the User Group.
- CImage showing "Add VPN Group" with "New_Group", "Enable User Group access" checked, and an empty User Group field.
- DImage showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" checked, and "admin" as the User Group.
- EImage showing "Add VPN Group" with "VPN_Group_10", "Enable User Group access" unchecked.
How the community answered
(31 responses)- A71% (22)
- B6% (2)
- C3% (1)
- D3% (1)
- E16% (5)
Why each option
Restricting SD-WAN Manager access by VPN group and user requires creating a VPN group with 'Enable User Group access' checked and assigning a specific authorized user group such as 'netadmin'.
Assigning 'netadmin' as the user group for VPN_Group_10 with 'Enable User Group access' enabled correctly implements VPN-based role access control - the 'netadmin' built-in group has the appropriate network administration privileges for managing VPN segment resources. This configuration scopes which user groups can access or manage the resources tied to that specific VPN group, fulfilling the policy requirement of segmenting access by VPN group and user.
The 'operator' user group has read-only or limited operational access and is not the correct role for administering VPN group-based access restrictions in this context.
Leaving the User Group field empty produces an incomplete configuration that does not associate any users with the VPN group, so no user-level access restriction is actually enforced.
The 'admin' user group has unrestricted system-wide access and assigning it to a VPN group does not meaningfully restrict access - it defeats the purpose of the segmented policy.
With 'Enable User Group access' unchecked, the VPN group configuration ignores user group membership entirely, leaving user-level access restrictions disabled.
Concept tested: SD-WAN Manager VPN group role-based access control configuration
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/ios-xe-17/security-book-xe/rbac.html
Topics
Community Discussion
No community discussion yet for this question.